Formal security analysis of the OpenID FAPI 2.0 Security Profile with FAPI 2.0 Message Signing, FAPI-CIBA, Dynamic Client Registration and Management : technical report

dc.contributor.authorHosseyni, Pedram
dc.contributor.authorKüsters, Ralf
dc.contributor.authorWürtele, Tim
dc.date.accessioned2023-11-02T09:10:00Z
dc.date.available2023-11-02T09:10:00Z
dc.date.issued2023de
dc.description.abstractBuilding on our recent formal security analysis of the FAPI 2.0 Security Profile, we here extend the analysis effort to FAPI 2.0 Message Signing, combined with Dynamic Client Registration, Dynamic Client Management, and FAPI-CIBA. Overall, we model an ecosystem which uses all these profiles and extensions in parallel. Like the previous work on the FAPI 2.0 Security Profile, this analysis is based on the Web Infrastructure Model, a Dolev-Yao style model of the web infrastructure - in fact, it is the most comprehensive and detailed model of the web infrastructure to date. We identify several attacks, propose fixes and prove the fixed protocols secure with respect to authorization, authentication, session integrity for both authorization and authentication, and non-repudiation for the messages covered by FAPI 2.0 Message Signing. The attacks and proposed fixes have been reported to the responsible FAPI Working Group at the OpenID Foundation, and fixes have since been incorporated into the specifications.en
dc.identifier.other1869112326
dc.identifier.urihttp://nbn-resolving.de/urn:nbn:de:bsz:93-opus-ds-137174de
dc.identifier.urihttp://elib.uni-stuttgart.de/handle/11682/13717
dc.identifier.urihttp://dx.doi.org/10.18419/opus-13698
dc.language.isoende
dc.rightsinfo:eu-repo/semantics/openAccessde
dc.subject.ddc004de
dc.titleFormal security analysis of the OpenID FAPI 2.0 Security Profile with FAPI 2.0 Message Signing, FAPI-CIBA, Dynamic Client Registration and Management : technical reporten
dc.typereportde
ubs.fakultaetInformatik, Elektrotechnik und Informationstechnikde
ubs.institutInstitut für Informationssicherheitde
ubs.publikation.seiten124de
ubs.publikation.typVerschiedenartige Textede

Files

Original bundle

Now showing 1 - 1 of 1
Thumbnail Image
Name:
oct23-tr-opus.pdf
Size:
1.26 MB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
3.3 KB
Format:
Item-specific license agreed upon to submission
Description: