Security Analysis of the Open Banking Account and Transaction API Protocol

03/28/2020
by   Abdulaziz Almehrej, et al.
0

To counteract the lack of competition and innovation in the financial services industry, the EU has issued the Second Payment Services Directive (PSD2) encouraging account servicing payment service providers to share data. The UK, similarly to other European countries, has promoted a standard API for data sharing: the Open Banking Standard. We present a formal security analysis of its APIs, focusing on the correctness of the Account and Transaction API protocol. The work relies on a previously proposed methodology, which provided a practical approach to protocol modelling and verification.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/22/2021

Transport Services: A Modern API for an Adaptive Internet Transport Layer

Transport services (TAPS) is a working group of the Internet's standardi...
research
09/17/2019

Enterprise API Security and GDPR Compliance: Design and Implementation Perspective

With the advancements in the enterprise-level business development, the ...
research
09/28/2021

A Formally Verified Configuration for Hardware Security Modules in the Cloud

Hardware Security Modules (HSMs) are trusted machines that perform sensi...
research
02/27/2023

Formal Analysis of the API Proxy Problem

Implementing a security mechanism on top of APIs requires clear understa...
research
01/31/2019

An Extensive Formal Security Analysis of the OpenID Financial-grade API

Forced by regulations and industry demand, banks worldwide are working t...
research
06/12/2020

FrugalML: How to Use ML Prediction APIs More Accurately and Cheaply

Prediction APIs offered for a fee are a fast-growing industry and an imp...
research
07/01/2020

DEMO: BTLEmap: Nmap for Bluetooth Low Energy

The market for Bluetooth Low Energy devices is booming and, at the same ...

Please sign up or login with your details

Forgot password? Click here to reset