Exploring Lattice-based Post-Quantum Signature for JWT Authentication: Review and Case Study

Abdolmaged Alkhulaifi, El-Sayed M. El-Alfy · 2020

Due to the scalability of the stateless and compact JSON Web Tokens (JWT), they are increasingly used in securing modern applications to support single-sign-on context and establish trust in microservices or connected-devices architectures. However, currently JWT relies on traditional encryption algorithms that are based on integer factorization or discrete logarithm problems; this exposes JWT signatures to vulnerability when quantum computers become available. Recently, NIST has announced new standards which are quantum safe. In this paper, we investigate the usage of two quantum-resistant algorithms, which are NIST candidates of round 2 standardization process in 2019, to create and verify JWT signatures. Namely, we consider lattice-based schemes (DILITHIUM and qTESLA) and compare their performance against RSA for digital signature for different security levels defined by NIST. The results show that lattice-based digital signature schemes have better performance than RSA in terms of request per seconds and average response time. DILITHIUM has demonstrated the best performance while also having smaller performance loss when scaling the security level.

Read the paper · More papers on PaperTik