OAuth Security Workshop 2017, where I gave a presentation. (2017/7/14)
Since Professor Basin (ETH Zurich) and Professor Cremers (University of Oxford) were both going to be there1, I thought it was a good opportunity and, perhaps recklessly, based my presentation on their paper2 to explain how RFC 6749 could be made secure.

At first, as in the previous year, I was only planning to serve as a paper reviewer. However, Dr. Lodderstedt, the program committee chair, asked me to submit something, so in a few hours I turned the ideas I had been considering while designing FAPI into a position paper and submitted it.
I was not entirely certain how to interpret what the paper calls the BCM Principle, and submitted my paper based on what I thought was probably the correct interpretation. I was relieved to learn that my interpretation was indeed correct.
Incidentally, much of what is discussed here has been incorporated into FAPI Part 2. In fact, reading this should give you some sense of why FAPI is designed the way it is. I am also very excited that researchers from the 2 universities that participated apparently plan to use this as a starting point for proving FAPI’s security. It would be excellent if its security is proven; if any issues emerge, we can address them before Final. I believe this could become a good example of collaboration between academia and standardization.
For the other presentations, Mr. Kudo of NRI Secure (@tkudo) has put together a summary, which you may find useful.
OAuth Security Workshop 2017 is scheduled to be held in Italy.

- —or rather, the reason they came to organize this event in the first place was that I asked Anthony Nadalin, “Have you read this paper?” at last year’s OAuth Security Workshop.
- Basin, D., Cremers, C., Meier, S.: Provably Repairing the ISO/IEC 9798
Standard for Entity Authentication. Journal of Computer Security – Security and Trust Principles archive Volume 21 Issue 6, 817-846 (2013)
Related posts

Another Way to Use “Named” Tokens with OAuth
It has been a while, everyone. Every year on April 1, I try to write a joke specification that might actually be useful, but once again…

OAuth-J Announces OAuth Optical Transport Profile for Network Resilience, Applying Cryptocurrency Technology
【AF Wire, Tokyo】The OAuth Foundation Japan (OAuth-J) announced on April 1, 2018 that it would begin developing the OAuth Optical Transport Profile (OAuth OTP), a new…

I Will Speak at API Days Paris on “Financial Grade OAuth and OpenID Connect”
“Automating IT, Business and Society as a Whole with APIs” is the catchphrase of the 1200-person conference “API Days 2016”, which will be held on December…

You must be logged in to post a comment.