Jan. 19, 2024, 8:06 a.m. |

IACR News www.iacr.org

ePrint Report: Formal Security Analysis of the OpenID FAPI 2.0: Accompanying a Standardization Process

Pedram Hosseyni, Ralf Kuesters, Tim Würtele


In recent years, the number of third-party services that can access highly-sensitive data has increased steadily, e.g., in the financial sector, in eGovernment applications, or in high-assurance identity services. Protocols that enable this access must provide strong security guarantees.


A prominent and widely employed protocol for this purpose is the OpenID Foundation's FAPI protocol. The FAPI protocol is already in …

access analysis applications assurance can data eprint report financial financial sector high identity openid party process report sector security security analysis sensitive sensitive data services standardization third third-party tim

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)