| FOTO
|
:
|
|
|---|---|---|
| ABSTRAK
|
:
|
JSON Web Tokens (JWT) have become the de facto standard for stateless authentication in modern web applications and microservices architectures. However, improper implementation exposes systems to critical vulnerabilities including algorithm confusion attacks, signature bypass, and key injection exploits. This paper presents a comprehensive resilience analysis of JSON Web Key Set (JWKS)-based authentication mechanisms against known JWT attack vectors through a systematic penetration testing approach. We implemented and evaluated a production-grade courier management system (City Courier) featuring dynamic JWKS key rotation, RFC 7517-compliant public key distribution, and encrypted private key storage. Our penetration testing methodology systematically evaluated the system against 10 critical JWT attack vectors including algorithm confusion (CVE-2022-29217), kid parameter injection, weak secret exploitation, and signature verification bypass. Results demonstrate that proper JWKS implementation with dynamic key rotation, strict algorithm validation, and comprehensive audit logging provides robust defense against all tested attack vectors. The system successfully mitigated algorithm confusion attacks through explicit algorithm whitelisting, prevented kid injection via UUID-based key identifiers, and maintained security during key rotation events. Performance analysis shows minimal overhead (less than 50ms) for JWKS endpoint queries with aggressive caching. This research contributes practical implementation patterns for secure JWT authentication, providing both empirical evidence for JWKS-based security controls and a validated blueprint to neutralize critical vulnerabilities in modern microservices architectures.
|
| SUMBER JURNAL
|
:
|
https://jutif.if.unsoed.ac.id/index.php/jurnal/article/view/5662
|
| JUDUL
|
:
|
Security Assessment of JWKS-Based Authentication: Mitigating JWT Attack Vectors Through Penetration Testing
|
| CIT AUTHOR
|
:
|
Ferry Andhika Pratama Agus Hermanto Geri Kusnanto |
| CIT PUBLISHED
|
:
|
2026-04-18
|
| CIT JOURNAL
|
:
|
Jurnal Teknik Informatika (Jutif)
|
| CIT VOLUME
|
:
|
7
|
| CIT ISSUE
|
:
|
2
|
| CIT PAGES
|
:
|
1834 - 1852
|
| CITATION
|
:
|
In Text Citation(Pratama, 2026) Bibliography CitationPratama, F. ., Hermanto, A. ., Kusnanto, G. ., (2026). Security Assessment of JWKS-Based Authentication: Mitigating JWT Attack Vectors Through Penetration Testing. Jurnal Teknik Informatika (Jutif), 7(2), 1834 - 1852. https://jutif.if.unsoed.ac.id/index.php/jurnal/article/view/5662 In Text Citation1 Bibliography Citation1. Pratama, F. ., Hermanto, A. ., Kusnanto, G. ., Security Assessment of JWKS-Based Authentication: Mitigating JWT Attack Vectors Through Penetration Testing. Jurnal Teknik Informatika (Jutif). 2026;7(2):1834 - 1852. https://jutif.if.unsoed.ac.id/index.php/jurnal/article/view/5662 In Text Citation(Pratama 2026) Bibliography CitationPratama, F. ., Hermanto, A. ., Kusnanto, G. ., 2026. "Security Assessment of JWKS-Based Authentication: Mitigating JWT Attack Vectors Through Penetration Testing". Jurnal Teknik Informatika (Jutif) 7(2), 1834 - 1852. https://jutif.if.unsoed.ac.id/index.php/jurnal/article/view/5662 In Text Citation(Pratama, 2026) Bibliography CitationPratama, F. ., Hermanto, A. ., Kusnanto, G. ., 2026. Security Assessment of JWKS-Based Authentication: Mitigating JWT Attack Vectors Through Penetration Testing. Jurnal Teknik Informatika (Jutif) [online] 7(2), pp.1834 - 1852. Available at: <https://jutif.if.unsoed.ac.id/index.php/jurnal/article/view/5662> [Accessed 22 August 2026]. In Text Citation[1] Bibliography Citation[1]Pratama, F. ., Hermanto, A. ., Kusnanto, G. ., Security Assessment of JWKS-Based Authentication: Mitigating JWT Attack Vectors Through Penetration Testing. Jurnal Teknik Informatika (Jutif), vol. 7, no. 2, pp.1834 - 1852, 2026. Available: https://jutif.if.unsoed.ac.id/index.php/jurnal/article/view/5662. [Accessed 22 August 2026]. |