Studying the security of web services USING JSON web Token with RSA-512 algorithm and comparative analysis of HMAC-HA512, HMAC-256 AND RSA-512 for signing json web token

Zh. Bidakhmet, G.Z. Ziyatbekova, A. K. Rysbayeva, D. K. Darkenbayev, Nurbapa Mekebayev, K. A. Kyzaibek · Bulletin of the National Engineering Academy of the Republic of Kazakhstan · 2024

This article presents an analysis of the load testing results for three cryptographic algorithms: RSA- 512, HMAC-SHA512, and HMAC-SHA256. The RSA-512 algorithm demonstrated the best performance, handling the highest number of requests (78,646) and achieving the highest request rate per second (145.6). The HMAC-SHA512 and HMAC-SHA256 algorithms showed similar performance, processing roughly the same number of requests and having comparable request rates per second. The RSA-512 algorithm had the lowest average and maximum request processing times, whereas the HMAC algorithms had longer processing times. Additionally, the RSA-512 algorithm transmitted a larger volume of data compared to the HMAC algorithms. From a security perspective, RSA-512 uses asymmetric encryption, which is considered more secure than symmetric algorithms like HMAC since the private key is never transmitted over the network. However, RSA-512 has a lower security level compared to modern recommendations due to its 512-bit key length. HMAC-SHA512 and HMAC-SHA256 use symmetric encryption and provide good protection against message tampering, with SHA-512 being considered more secure than SHA-256 due to its longer hash code.

Read the paper · More papers on PaperTik