Web Hack List

Collected research

A Comprehensive Formal Security Analysis of OAuth 2.0

[1601.01229] A Comprehensive Formal Security Analysis of OAuth 2.0

The first formal analysis of the OAuth 2.0 standard in an expressive model of the web, covering all four grant types with malicious relying parties, identity providers and browsers in scope. It uncovers four attacks that break OAuth's authorization, authentication and session integrity guarantees and carry over to OpenID Connect, proposes fixes, and proves the fixed protocol secure.

Record

Document
[1601.01229] A Comprehensive Formal Security Analysis of OAuth 2.0
Researcher
Daniel Fett, Ralf Kuesters and Guido Schmitz
Published by
arXiv.org
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Daniel Fett, Ralf Kuesters and Guido Schmitz, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .