<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://encyclopediaofcybersecurity.com/index.php?action=history&amp;feed=atom&amp;title=JSON_Web_Signature</id>
	<title>JSON Web Signature - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://encyclopediaofcybersecurity.com/index.php?action=history&amp;feed=atom&amp;title=JSON_Web_Signature"/>
	<link rel="alternate" type="text/html" href="https://encyclopediaofcybersecurity.com/index.php?title=JSON_Web_Signature&amp;action=history"/>
	<updated>2026-05-26T21:19:36Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.41.1</generator>
	<entry>
		<id>https://encyclopediaofcybersecurity.com/index.php?title=JSON_Web_Signature&amp;diff=292&amp;oldid=prev</id>
		<title>Ccocrick: /* Algorithms */</title>
		<link rel="alternate" type="text/html" href="https://encyclopediaofcybersecurity.com/index.php?title=JSON_Web_Signature&amp;diff=292&amp;oldid=prev"/>
		<updated>2024-05-08T14:32:38Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Algorithms&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 14:32, 8 May 2024&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l26&quot;&gt;Line 26:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 26:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;JWS supports a variety of signature algorithms, including:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;JWS supports a variety of signature algorithms, including:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;HMAC&#039;&#039;&#039;: Uses a shared secret key and a cryptographic hash function to create and verify the digital signature, providing symmetric-key authentication and integrity protection.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Hash-Based Message Authentication Code]] (&lt;/ins&gt;HMAC&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;)&lt;/ins&gt;&#039;&#039;&#039;: Uses a shared secret key and a cryptographic hash function to create and verify the digital signature, providing symmetric-key authentication and integrity protection.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;RSA&#039;&#039;&#039;: Uses a pair of public and private keys to create and verify the digital signature, providing asymmetric-key authentication and integrity protection.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Rivest-Shamir-Adleman]] (&lt;/ins&gt;RSA&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;)&lt;/ins&gt;&#039;&#039;&#039;: Uses a pair of public and private keys to create and verify the digital signature, providing asymmetric-key authentication and integrity protection.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;ECDSA&#039;&#039;&#039;: Uses elliptic curve cryptography to create and verify the digital signature, providing efficient and secure authentication and integrity protection.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &#039;&#039;&#039;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Elliptic Curve Digital Signature Algorithm]] (&lt;/ins&gt;ECDSA&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;)&lt;/ins&gt;&#039;&#039;&#039;: Uses elliptic curve cryptography to create and verify the digital signature, providing efficient and secure authentication and integrity protection.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Use Cases ===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Use Cases ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Ccocrick</name></author>
	</entry>
	<entry>
		<id>https://encyclopediaofcybersecurity.com/index.php?title=JSON_Web_Signature&amp;diff=291&amp;oldid=prev</id>
		<title>Ccocrick: Created page with &quot;== JSON Web Signature (JWS) ==  &#039;&#039;&#039;JSON Web Signature&#039;&#039;&#039; (JWS) is a standard for securing content in JSON format by applying digital signatures, enabling message integrity, authentication, and non-repudiation. JWS allows for the creation of compact, URL-safe tokens that can be used to verify the integrity and authenticity of data transmitted between parties.  === Overview ===  JWS is commonly used in web applications and APIs to protect sensitive information, such as aut...&quot;</title>
		<link rel="alternate" type="text/html" href="https://encyclopediaofcybersecurity.com/index.php?title=JSON_Web_Signature&amp;diff=291&amp;oldid=prev"/>
		<updated>2024-05-08T14:30:00Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;== JSON Web Signature (JWS) ==  &amp;#039;&amp;#039;&amp;#039;JSON Web Signature&amp;#039;&amp;#039;&amp;#039; (JWS) is a standard for securing content in JSON format by applying digital signatures, enabling message integrity, authentication, and non-repudiation. JWS allows for the creation of compact, URL-safe tokens that can be used to verify the integrity and authenticity of data transmitted between parties.  === Overview ===  JWS is commonly used in web applications and APIs to protect sensitive information, such as aut...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== JSON Web Signature (JWS) ==&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;JSON Web Signature&amp;#039;&amp;#039;&amp;#039; (JWS) is a standard for securing content in JSON format by applying digital signatures, enabling message integrity, authentication, and non-repudiation. JWS allows for the creation of compact, URL-safe tokens that can be used to verify the integrity and authenticity of data transmitted between parties.&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
JWS is commonly used in web applications and APIs to protect sensitive information, such as authentication tokens, access tokens, and API requests, from tampering and unauthorized modifications. By applying digital signatures to JSON objects, JWS ensures the integrity and authenticity of the data, providing a secure means of communication between parties.&lt;br /&gt;
&lt;br /&gt;
=== Components ===&lt;br /&gt;
&lt;br /&gt;
A JWS consists of the following components:&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Header&amp;#039;&amp;#039;&amp;#039;: Contains metadata about the signature algorithm and key management parameters used to create the signature.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Payload&amp;#039;&amp;#039;&amp;#039;: Contains the content to be signed, such as the plaintext message or JSON object.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Signature&amp;#039;&amp;#039;&amp;#039;: Contains the digital signature created using a cryptographic algorithm and a private key, ensuring the integrity and authenticity of the payload.&lt;br /&gt;
&lt;br /&gt;
=== Key Features ===&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Integrity&amp;#039;&amp;#039;&amp;#039;: JWS ensures the integrity of the signed content by generating a digital signature that can be verified by the recipient, detecting any unauthorized modifications.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Authentication&amp;#039;&amp;#039;&amp;#039;: JWS provides authentication of the sender by including a digital signature that can be verified using the sender&amp;#039;s public key, ensuring that the data originated from a trusted source.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Non-Repudiation&amp;#039;&amp;#039;&amp;#039;: JWS provides non-repudiation by allowing the recipient to prove the authenticity and integrity of the signed data to third parties, preventing the sender from denying their involvement.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Compact Format&amp;#039;&amp;#039;&amp;#039;: JWS tokens are compact and URL-safe, making them suitable for transmission as URL parameters, HTTP headers, or within the body of HTTP requests and responses.&lt;br /&gt;
&lt;br /&gt;
=== Algorithms ===&lt;br /&gt;
&lt;br /&gt;
JWS supports a variety of signature algorithms, including:&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;HMAC&amp;#039;&amp;#039;&amp;#039;: Uses a shared secret key and a cryptographic hash function to create and verify the digital signature, providing symmetric-key authentication and integrity protection.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;RSA&amp;#039;&amp;#039;&amp;#039;: Uses a pair of public and private keys to create and verify the digital signature, providing asymmetric-key authentication and integrity protection.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;ECDSA&amp;#039;&amp;#039;&amp;#039;: Uses elliptic curve cryptography to create and verify the digital signature, providing efficient and secure authentication and integrity protection.&lt;br /&gt;
&lt;br /&gt;
=== Use Cases ===&lt;br /&gt;
&lt;br /&gt;
JWS is commonly used in various scenarios, including:&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Token-Based Authentication&amp;#039;&amp;#039;&amp;#039;: Securing authentication tokens and access tokens used in web applications and APIs to prevent tampering and misuse.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Message Integrity&amp;#039;&amp;#039;&amp;#039;: Ensuring the integrity of JSON objects transmitted over insecure networks, such as the internet, to prevent tampering and unauthorized modifications.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;API Security&amp;#039;&amp;#039;&amp;#039;: Securing API requests and responses with digital signatures to verify the authenticity and integrity of data exchanged between clients and servers.&lt;br /&gt;
&lt;br /&gt;
=== Conclusion ===&lt;br /&gt;
&lt;br /&gt;
JSON Web Signature (JWS) provides a standardized and secure mechanism for securing content in JSON format by applying digital signatures. By ensuring integrity, authentication, and non-repudiation of data, JWS enables secure communication between parties in web applications, APIs, and other digital environments.&lt;/div&gt;</summary>
		<author><name>Ccocrick</name></author>
	</entry>
</feed>