Security Analysis of the Open Banking Account and Transaction API Protocol

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Modesti, Paolo, Freitas, Leo, Shotomiwa, Qudus, Almehrej, Abdulaziz
Formato: Preprint
Publicado: 2020
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866918007489429504
author Modesti, Paolo
Freitas, Leo
Shotomiwa, Qudus
Almehrej, Abdulaziz
author_facet Modesti, Paolo
Freitas, Leo
Shotomiwa, Qudus
Almehrej, Abdulaziz
contents The Second Payment Services Directive (PSD2) of the European Union aims to create a consumer-friendly financial market by mandating secure and standardised data sharing between banking operators and third parties. Consequently, EU countries and the United Kingdom have adopted Open Banking, a standardised data-sharing API. This paper presents a formal modelling and security analysis of the UK Open Banking Standard's APIs, with a specific focus on the Account and Transaction API protocol. Our methodology employs the extended Alice and Bob notation (AnBx) to create a formal model of the protocol, which is then verified using the OFMC symbolic model checker and the Proverif cryptographic protocol verifier. We extend previous work by enabling verification for unlimited sessions with a strongly typed model. Additionally, we integrate our formal analysis with practical security testing of some necessary conditions to demonstrate verified security-goals in the NatWest Open Banking sandbox, evaluating mechanisms such as authorisation and authentication procedures.
format Preprint
id arxiv_https___arxiv_org_abs_2003_12776
institution arXiv
publishDate 2020
record_format arxiv
spellingShingle Security Analysis of the Open Banking Account and Transaction API Protocol
Modesti, Paolo
Freitas, Leo
Shotomiwa, Qudus
Almehrej, Abdulaziz
Cryptography and Security
The Second Payment Services Directive (PSD2) of the European Union aims to create a consumer-friendly financial market by mandating secure and standardised data sharing between banking operators and third parties. Consequently, EU countries and the United Kingdom have adopted Open Banking, a standardised data-sharing API. This paper presents a formal modelling and security analysis of the UK Open Banking Standard's APIs, with a specific focus on the Account and Transaction API protocol. Our methodology employs the extended Alice and Bob notation (AnBx) to create a formal model of the protocol, which is then verified using the OFMC symbolic model checker and the Proverif cryptographic protocol verifier. We extend previous work by enabling verification for unlimited sessions with a strongly typed model. Additionally, we integrate our formal analysis with practical security testing of some necessary conditions to demonstrate verified security-goals in the NatWest Open Banking sandbox, evaluating mechanisms such as authorisation and authentication procedures.
title Security Analysis of the Open Banking Account and Transaction API Protocol
topic Cryptography and Security
url https://arxiv.org/abs/2003.12776