Zur Kurzanzeige

dc.contributor.authorFett, Daniel
dc.contributor.editorRoßnagel, Heiko
dc.contributor.editorSchunck, Christian H.
dc.contributor.editorMödersheim, Sebastian
dc.date.accessioned2021-05-20T13:12:14Z
dc.date.available2021-05-20T13:12:14Z
dc.date.issued2021
dc.identifier.isbn978-3-88579-706-7
dc.identifier.issn1617-5468
dc.identifier.urihttp://dl.gi.de/handle/20.500.12116/36503
dc.description.abstractA growing number of APIs, from the financial, health and other sectors, give access to highly sensitive data and resources. With the Financial-grade API (FAPI) Security Profile, the OpenID Foundation has created an interoperable and secure standard to protect such APIs. The first version of FAPI has recently become an official standard and has already been adopted by large ecosystems, such as OpenBanking UK. Meanwhile, the OpenID Foundation’s FAPI Working Group has started the work on a the second version of FAPI, putting a focus on robust interoperability, simplicity, a more structured approach to security, and improved non-repudiation. In this paper, we give an overview of the FAPI profiles, discuss the learnings from practice that influence the development of the latest version of FAPI, and show how formal security analysis helps to shape security decisions.en
dc.language.isoen
dc.publisherGesellschaft für Informatik e.V.
dc.relation.ispartofOpen Identity Summit 2021
dc.relation.ispartofseriesLecture Notes in Informatics (LNI) - Proceedings, Volume P-312
dc.subjectAuthorization
dc.subjectAuthentication
dc.subjectSecurity
dc.subjectInteroperability
dc.titleFAPI 2.0: A High-Security Profile for OAuth and OpenID Connecten
dc.typeText/Conference Paper
dc.pubPlaceBonn
mci.reference.pages71-82
mci.conference.sessiontitleRegular Research Papers
mci.conference.locationCopenhagen, Denmark
mci.conference.date01.-02. June 2021


Dateien zu dieser Ressource

Thumbnail

Zur Kurzanzeige