News Score: Score the News, Sort the News, Rewrite the Headlines

A Comprehensive Formal Security Analysis of OAuth 2.0

View PDF Abstract:The OAuth 2.0 protocol is one of the most widely deployed authorization/single sign-on (SSO) protocols and also serves as the foundation for the new SSO standard OpenID Connect. Despite the popularity of OAuth, so far analysis efforts were mostly targeted at finding bugs in specific implementations and were based on formal models which abstract from many web features or did not provide a formal treatment at all. In this paper, we carry out the first extensive formal analysis of...

Read more at arxiv.org

© News Score  score the news, sort the news, rewrite the headlines