IMPLEMENTASI RESTFULL API MENGGUNAKAN JSON WEB TOKEN PADA WEBSITE MANAJEMEN INFASTRUKTUR

Riski Cahyadi, Denar Regata Akbi

Abstract


Digitalisasi sistem pelaporan infrastruktur kota memerlukan mekanisme autentikasi pengguna yang aman dan efisien. Penelitian ini mem-bandingkan dua metode autentikasi, yaitu JSON Web Token (JWT) dan Session-Based Authentication, dalam konteks implementasi RESTful API berbasis Express.js dan PostgreSQL. Sistem diuji menggunakan beban permintaan bertingkat hingga 10.000 request, dengan metrik pengujian yang meliputi response time, throughput, penggunaan CPU dan memory, serta aspek keamanan. Hasil pengujian menunjukkan bahwa JWT memiliki performa yang lebih baik dalam hal kecepatan respon dan efisiensi sumber daya, dengan throughput yang lebih tinggi serta kon-sumsi CPU dan memory yang lebih rendah dibandingkan dengan metode session. Namun demikian, JWT memerlukan manajemen token yang ketat karena rentan terhadap serangan XSS. Sebaliknya, Session-Based Authentication lebih aman terhadap XSS, namun menunjukkan performa lebih rendah dan konsumsi sumber daya yang lebih tinggi. Hasil pengujian keamanan juga menunjukkan bahwa masing-masing metode memiliki kerentanan tersendiri terhadap serangan seperti CSRF dan session hijacking. Penelitian ini memberikan panduan bagi pengem-bang sistem dalam memilih metode autentikasi yang sesuai berdasarkan kebutuhan keamanan, efisiensi, dan skalabilitas pada sistem pelaporan publik.

Keywords


RESTful API; JSON Web Token; Autentikasi Berbasis Sesi; Pengujian Beban; Keamanan Web

Full Text:

PDF

References


P. Tang and T. Lv, “Design and Implementation of Ship Water Pollution Supervision and Service Information Sys-tem,” Academic Journal of Computing & Information Science, vol. 5, no. 11, 2022, doi: 10.25236/AJCIS.2022.051113.

Yuda Syahidin and Randy Ramadhan, “REST API Architecture Design on Multi-Platform Device Development,” Jurnal E-Komtek (Elektro-Komputer-Teknik), vol. 5, no. 2, pp. 178–189, Dec. 2021, doi: 10.37339/e-komtek.v5i2.762.

R. A. Khan, S. U. Khan, H. U. Khan, and M. Ilyas, “Systematic Literature Review on Security Risks and its Practices in Secure Software Development,” IEEE Access, vol. 10, pp. 5456–5481, 2022, doi: 10.1109/ACCESS.2022.3140181.

M. Zaidan, F. Noeraini, Z. Sari, and D. R. Akbi, “Website Vulnerability Analysis of AB and XY Office in East Ja-va,” Jurnal Ilmiah Teknik Elektro Komputer dan Informatika, vol. 9, no. 2, pp. 455–492, Jun. 2023, doi: 10.26555/jiteki.v9i2.26183.

Mustafa Mohammed Rasheed, Muneera Alsaedi, and Ahmed Al Ibraheemi, “Developing an Electronic Health Rec-ords System Based on the National Identity by Using Angular Web Application Framework,” Applied Data Science and Analysis, vol. 2023, pp. 102–107, Oct. 2023, doi: 10.58496/ADSA/2023/008.

I. Shikhverdiyev, E. Babayev, C. Rahimli, N. Rahimli, and H. Aslanova, “Secure authentication in e-government 2.0: a comparative analysis of traditional session-based and modern jwt-based authentication,” International Science Journal of Engineering & Agriculture, vol. 3, no. 6, pp. 117–129, Dec. 2024, doi: 10.46299/j.isjea.20240306.12.

W. Niewolski, T. W. Nowak, M. Sepczuk, and Z. Kotulski, “Token-Based Authentication Framework for 5G MEC Mobile Networks,” Electronics (Basel), vol. 10, no. 14, p. 1724, Jul. 2021, doi: 10.3390/electronics10141724.

A. Bucko, K. Vishi, B. Krasniqi, and B. Rexha, “Enhancing JWT Authentication and Authorization in Web Applica-tions Based on User Behavior History,” Computers, 2023, doi: 10.3390/computers12040078.

S. Dalimunthe, J. Reza, and A. Marzuki, “Model for Storing Tokens in Local Storage (Cookies) Using JSON Web Token (JWT) With HMAC (Hash-Based Message Authentication Code) in E-Learning Systems,” Journal of Applied Engineering and Technological Science (Jaets), 2022, doi: 10.37385/jaets.v3i2.662.

E. al. Manish Rana, “Enhancing Data Security: A Comprehensive Study on the Efficacy of JSON Web Token (JWT) and HMAC SHA-256 Algorithm for Web Application Security,” International Journal on Recent and Innovation Trends in Computing and Communication, vol. 11, no. 9, pp. 4409–4416, Nov. 2023, doi: 10.17762/ijritcc.v11i9.9930.

N. Xie, “Strategic approaches to API design and management,” Applied and Computational Engineering, vol. 64, no. 1, pp. 230–236, Jun. 2024, doi: 10.54254/2755-2721/64/20241395.

A. Datta and S. Sen, “A Security and Privacy Validation Methodology for E-Health Systems Using Cloud Storage,” 2024, pp. 173–192. doi: 10.4018/979-8-3693-9235-5.ch009.

F. C. Ramdani, S. T. A. Rahmatulloh, and R. N. Shofa, “Implementation of JSON Web Token on Authentication With HMAC SHA-256 Algorithm,” Sistemasi, 2023, doi: 10.32520/stmsi.v12i1.2450.

A. Akanksha and A. Chaturvedi, “Comparison of Different Authentication Techniques and Steps to Implement Ro-bust JWT Authentication,” 2022, doi: 10.1109/icces54183.2022.9835796.

K. Singh and N. Singh, “Multilevel authentication protocol for enabling secure communication in Internet of Things,” Concurr Comput, vol. 34, no. 3, Feb. 2022, doi: 10.1002/cpe.6578.

A. Ehsan, M. A. M. E. Abuhaliqa, C. Catal, and D. Mishra, “RESTful API Testing Methodologies: Rationale, Chal-lenges, and Solution Directions,” Applied Sciences, vol. 12, no. 9, p. 4369, Apr. 2022, doi: 10.3390/app12094369.

S. Alshomrani and S. Li, “PUFDCA: A Zero-Trust-Based IoT Device Continuous Authentication Protocol,” Wirel Commun Mob Comput, vol. 2022, pp. 1–9, Nov. 2022, doi: 10.1155/2022/6367579.

giovanni bartolomeo, “Attribute-Based Encryption for Access Control in Cloud Ecosystems,” Jan. 11, 2022. doi: 10.36227/techrxiv.13546871.

C. Meshram, C.-C. Lee, I. Bahkali, and A. L. Imoize, “An Efficient Fractional Chebyshev Chaotic Map-Based Three-Factor Session Initiation Protocol for the Human-Centered IoT Architecture,” Mathematics, vol. 11, no. 9, p. 2085, Apr. 2023, doi: 10.3390/math11092085.

S. Chatterjee, V. K. Mahor, and R. Padmavathy, “Chebyshev chaotic map-based efficient authentication scheme for secure access of VoIP services through SIP,” International Journal of Security and Networks, vol. 17, no. 1, p. 39, 2022, doi: 10.1504/IJSN.2022.10046977.

U. Achlison, M. Miftahurrohman, and E. Siswanto, “A Robust Authentication Method for Electronic Banking Trans-actions: Two-Way Challenge-Response Approach,” Journal of Technology Informatics and Engineering, vol. 3, no. 2, pp. 249–262, Aug. 2024, doi: 10.51903/jtie.v3i2.195.

S. C. T. -, “The Evolution of Identity and Access Management: Integrating Biometric and Behavioral Authentica-tion,” International Journal For Multidisciplinary Research, vol. 6, no. 6, Nov. 2024, doi: 10.36948/ijfmr.2024.v06i06.29986.

F. J. Carbone, M. A. Marotta, and L. M. Rockenbach Tarouco, “A Solution for Strong Authentication in Sensor-Based Healthcare Environments / Uma Solução De Autenticação Forte Para Ambientes De Saúde Baseados Em Sen-sores,” Brazilian Journal of Development, 2020, doi: 10.34117/bjdv6n9-744.

C. Yadav, R. Dhakad, . A., M. Panchal, and Er. B. Kaur, “Revolutionizing Near-by Accommodation: An in-depth Analysis of React.js, Node.js, MongoDB, and Express.js Integration for Website Development,” SSRN Electronic Journal, Aug. 2024, doi: 10.2139/SSRN.4932790.

R. Scheible, “PostgREST Data Provider for React-Admin: Bootstrap the creation of user interfaces on top of Post-greSQL databases,” Software Impacts, vol. 21, p. 100699, Sep. 2024, doi: 10.1016/J.SIMPA.2024.100699.

A. Bumiller, S. Challita, B. Combemale, O. Barais, N. Aillery, and G. Le Lan, “On Understanding Context Modelling for Adaptive Authentication Systems,” Acm Transactions on Autonomous and Adaptive Systems, 2023, doi: 10.1145/3582696.

A. R. Naseer, V. Neelima, and G. Narsimha, “Swarm Intelligence-Based Bio-Inspired Framework for Wireless Sen-sor Networks,” 2021, doi: 10.5772/intechopen.93516.

T. V. Oktavia, A. Widjajarto, and M. Fathinuddin, “Control Social Engineering Security and Spear Phishing Attacks With Technology Solutions in Organizations,” Jurnal Indonesia Sosial Teknologi, 2025, doi: 10.59141/jist.v6i1.1361.

C. Howard, C. Lockie-Williams, and R. J. Slater, “Applied Barcoding: The Practicalities of DNA Testing for Herb-als,” Plants, 2020, doi: 10.3390/plants9091150.

M. Aldaoud, D. Al‐Abri, F. Kausar, and M. Awadalla, “NDNOTA: NDN One-Time Authentication,” Information, 2024, doi: 10.3390/info15050289.

R. F. Olanrewaju, B. U. Islam Khan, M. A. Morshidi, F. Anwar, and M. L. Mat Kiah, “A Frictionless and Secure User Authentication in Web-Based Premium Applications,” Ieee Access, 2021, doi: 10.1109/access.2021.3110310.

J. J. Díaz Rivera, W. Akbar, T. A. Khan, A. Muhammad, and W. Song, “Secure Enrollment Token Delivery Mecha-nism for Zero Trust Networks Using Blockchain,” Ieice Transactions on Communications, 2023, doi: 10.1587/transcom.2022tmp0005.

X. Guo, D. Sun, and Y. Yang, “An Improved Three-Factor Session Initiation Protocol Using Chebyshev Chaotic Map,” Ieee Access, 2020, doi: 10.1109/access.2020.3002558.

A. Attkan and V. Ranga, “Cyber-Physical Security for IoT Networks: A Comprehensive Review on Traditional, Blockchain and Artificial Intelligence Based Key-Security,” Complex & Intelligent Systems, 2022, doi: 10.1007/s40747-022-00667-z.

C.-F. Hsu, L. Harn, and Z. Xia, “An HSS‐based Robust and Lightweight Multiple Group Authentication for ITS Towards 5G,” Iet Intelligent Transport Systems, 2021, doi: 10.1049/itr2.12113.

D. Upadhyay, M. Zaman, R. Joshi, and S. Sampalli, “An Efficient Key Management and Multi-Layered Security Framework for SCADA Systems,” Ieee Transactions on Network and Service Management, 2022, doi: 10.1109/tnsm.2021.3104531.

F. Wang, G. Xu, G. Xu, Y. Wang, and J. Peng, “A Robust IoT-Based Three-Factor Authentication Scheme for Cloud Computing Resistant to Session Key Exposure,” Wirel Commun Mob Comput, 2020, doi: 10.1155/2020/3805058.




DOI: https://doi.org/10.29100/jipi.v11i2.8202

Refbacks

  • There are currently no refbacks.


Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

JIPI (Jurnal Ilmiah Penelitian dan Pembelajaran Informatika)
ISSN 2540-8984
Published by
Prodi Pendidikan Teknologi Informasi
Universitas Bhinneka PGRI

Website :https://jurnal.stkippgritulungagung.ac.id/index.php/jipi/index
Email: jipistkippti@gmail.com


Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.