Open AccessOpen Access||Research Article

Design and Implementation of Spring Security Framework Using OAuth 2.0 for Spring Boot Applications

Shameer Mohammed1, Ali Ibrahim Mohammed Lassakeur1, P. Rutravigneshwaran2

1 Department of Computing and Information Sciences, University of Technology and Applied Sciences Sur, Ash Sharqiyah Sur, PC-411, Sultanate of Oman

2 Department of Computer Science, Karpagam Academy of Higher Education, Coimbatore, Tamil Nadu, 641021, India

Download PDF</>HTML Version

Abstract

In modern web applications, ensuring secure authentication and authorization has become a critical requirement for protecting sensitive data and maintaining user trust. This research focuses on implementing an enhanced security model using encrypted OAuth 2.0 and JSON Web Tokens (JWT) within Spring Boot applications. The primary objective is to strengthen authentication and authorization mechanisms by integrating encryption techniques to secure tokens and communication channels between clients and servers. This research emphasizes encrypting and decrypting OAuth 2.0 tokens and JWTs to enhance data confidentiality and effectively manage role-based access control (RBAC). It presents the design and implementation of a secure system by enhancing the standard OAuth 2.0 framework with comprehensive JWT encryption. Building on the Spring Boot framework, the system leverages Spring Security to fortify the OAuth 2.0 flow. This approach ensures that confidential user data, claims, and, most importantly, user roles are fully protected within the token payload, preventing exposure even in the event of a token breach. The intended approach was rigorously evaluated through security tests, including unit tests and manual penetration testing, to identify potential vulnerabilities. The results demonstrate that integrating encrypted JWTs with the OAuth 2.0 protocol in Spring Boot applications significantly enhances security by protecting token contents and securing the RBAC mechanism that effectively mitigates risks associated with token interception, replay attacks, and privilege escalation, which confirms the viability and effectiveness of this enhanced security model for modern, secure application development.

Keywords

Spring bootSpring securityOAuth 2.0JSON Web Token (JWT)EncryptionRole-based access control (RBAC)AuthenticationAuthorizationAPI security