Web Hack List

Later archive addition

A Comprehensive Formal Security Analysis of OAuth 2.0

The first formal analysis of the OAuth 2.0 standard in an expressive model of the web, covering all four grant types with malicious relying parties, identity providers and browsers in scope. It uncovers four attacks that break OAuth's authorization, authentication and session integrity guarantees and carry over to OpenID Connect, proposes fixes, and proves the fixed protocol secure.

Record

Researcher
Daniel Fett, Ralf Kuesters and Guido Schmitz
Published by
arXiv.org

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Daniel Fett, Ralf Kuesters and Guido Schmitz, first published at the original source. Preserved copies are kept so the citation survives its host.