OAuth Security Workshop 2017, where I gave a presentation. (2017/7/14)
Since Professor Basin (ETH Zurich) and Professor Cremers (University of Oxford) were both going to be there1, I thought it was a good opportunity and, perhaps recklessly, based my presentation on their paper2 to explain how RFC 6749 could be made secure.

At first, as in the previous year, I was only planning to serve as a paper reviewer. However, Dr. Lodderstedt, the program committee chair, asked me to submit something, so in a few hours I turned the ideas I had been considering while designing FAPI into a position paper and submitted it.
I was not entirely certain how to interpret what the paper calls the BCM Principle, and submitted my paper based on what I thought was probably the correct interpretation. I was relieved to learn that my interpretation was indeed correct.
Incidentally, much of what is discussed here has been incorporated into FAPI Part 2. In fact, reading this should give you some sense of why FAPI is designed the way it is. I am also very excited that researchers from the 2 universities that participated apparently plan to use this as a starting point for proving FAPI’s security. It would be excellent if its security is proven; if any issues emerge, we can address them before Final. I believe this could become a good example of collaboration between academia and standardization.
For the other presentations, Mr. Kudo of NRI Secure (@tkudo) has put together a summary, which you may find useful.
OAuth Security Workshop 2017 is scheduled to be held in Italy.

Footnotes
- —or rather, the reason they came to organize this event in the first place was that I asked Anthony Nadalin, “Have you read this paper?” at last year’s OAuth Security Workshop.
- Basin, D., Cremers, C., Meier, S.: Provably Repairing the ISO/IEC 9798
Standard for Entity Authentication. Journal of Computer Security – Security and Trust Principles archive Volume 21 Issue 6, 817-846 (2013)
Related posts

I Will Speak at APIDays London (11/13)
This announcement could hardly be any later, but I will appear at APIDays London on the 13th from 11:10 a.m. local time. The APIDays London website…

OpenAI Launches Sign in with ChatGPT (Based on OpenID Connect)
(Work in progress; last updated 2026-10-02 12:39 JST) On September 29, at DevDay 2026, OpenAI officially announced Sign in with ChatGPT (SIWC). I would like to…

I Will Appear on the Okinawa Open Days Panel “Current and Future OSS Initiatives in Economic Security”
It is already the day of the event—in fact, I am writing this now (12/4 9:45) at my desk while preparing for the panel—but I will…

You must be logged in to post a comment.