Collected research
A Comprehensive Formal Security Analysis of OAuth 2.0
[1601.01229] A Comprehensive Formal Security Analysis of OAuth 2.0
The first formal analysis of the OAuth 2.0 standard in an expressive model of the web, covering all four grant types with malicious relying parties, identity providers and browsers in scope. It uncovers four attacks that break OAuth's authorization, authentication and session integrity guarantees and carry over to OpenID Connect, proposes fixes, and proves the fixed protocol secure.
Record
- Document
- [1601.01229] A Comprehensive Formal Security Analysis of OAuth 2.0
- Researcher
- Daniel Fett, Ralf Kuesters and Guido Schmitz
- Published by
- arXiv.org
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Daniel Fett, Ralf Kuesters and Guido Schmitz, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .