OAuth 2; AML
Facebook X LinkedIn

OAuth 2; AML

Combined Session
Wednesday, May 10, 2023 17:30—18:30
Location: A 03-04

High-security & interoperable OAuth 2: What's the latest?

OAuth is a widely used authorization framework that enables third-party applications to access resources on behalf of a user. However, it has been historically difficult to meet very high security and interoperability requirements when using OAuth. Daniel and Joseph have spent much of the last five years working to improve the state of the art and will present the latest developments in the field.

There are challenges when trying to achieve high security and interoperability with OAuth 2: Many potential threats need to be addressed, some not part of the original OAuth threat model. To seamless authorizations, optionality must be minimized OAuth itself and also in any extensions
used.

Six years ago, the IETF OAuth working group started work on the Security Best Current Practice document and more recently on OAuth 2.1. Meanwhile, the OpenID Foundation has created FAPI1 and FAPI2 security profiles.

We will introduce these specifications and help you understand the focus of each document and when to use which. We show how to achieve on-the-wire interoperability and high security through the use of techniques like asymmetric client authentication and sender-constraining via DPoP and MTLS. We highlight the benefits for implementers and the role of conformance testing tools.

High-security & interoperable OAuth 2: What's the latest?
Event Recording
High-security & interoperable OAuth 2: What's the latest?
Click here to watch the recording of this session. Please note that this video is only available to event participants and subscribers. You'll need to log in to watch it.
High-security & interoperable OAuth 2: What's the latest?
Presentation deck
High-security & interoperable OAuth 2: What's the latest?
Click here to download the slide deck. Please note that downloads are only available for event participants and subscribers. You'll need to log in to download it.
Dr. Daniel Fett
Dr. Daniel Fett
Authlete
Daniel holds a Ph.D. in Computer Science for the development of new methods for analyzing the security of web standards. Leveraging this background, he has worked for the past several years to...
Joseph Heenan
Joseph Heenan
Authlete Inc
Joseph is a software engineer & architect with over 25 years’ experience, who started writing mobile apps before mobile apps existed. He contributes to IETF and OpenID Foundation working...

The AML-Compliant ID-Wallet

AML-compliant customer identification in the finance and banking sector (KYC) in Germany is subject to the requirements of BaFin (the regulatory authority) and the Money Laundering Act. This involves the use of both on-site and online identification procedures, which are often provided by external service providers as “critical outsourcing" and as data order processing. In the age of ID wallets, this KYC process needs to be redeveloped from a regulatory, data protection and technical perspective - especially because the regulatory framework currently does not (yet) explicitly provide for the case of an ID wallet. The presentation describes the challenges for ID wallets and ID issuers in the AML context and shows an exemplary implementation.

The AML-Compliant ID-Wallet
Event Recording
The AML-Compliant ID-Wallet
Click here to watch the recording of this session. Please note that this video is only available to event participants and subscribers. You'll need to log in to watch it.
The AML-Compliant ID-Wallet
Presentation deck
The AML-Compliant ID-Wallet
Click here to download the slide deck. Please note that downloads are only available for event participants and subscribers. You'll need to log in to download it.
Roland Adrian
Roland Adrian
Verimi GmbH
Roland Adrian (50) is Managing Director and CEO of Verimi GmbH in Berlin, a multi-joint venture of 26 shareholders from the German business community. Verimi develops and operates the Verimi ID...
Dr. Dirk Woywod
Dr. Dirk Woywod
Verimi
Dr. Dirk Woywod has been Managing Director and Chief Technical Officer (CTO) at Verimi GmbH since 2018 a leading ID-Wallet provider in Germany. After completing his PhD in theoretical physics at...

The eID Threat Landscape – Stay Ahead of the Fraudsters

Cash grab-robberies are out, online fraud is in. When multinational hacker groups target senior and vulnerable citizens as a business model.

Learn how BankID is fighting fraud and helps you stay on top by identifying, preventing and notifying you of fraudulent usage in real time, while preserving top user experience.

The dream of tomorrows digitalized society is already a reality. Sweden is one of the world’s most digital and innovative societies. The fast and secure digital identification provided by BankID is a corner stone in this, to many, futuristic ecosystems. Many shops and stores do not accept cash and the amount of cash is low, something that inflicts digital threat. Studies shows a steep growth curve of digital fraud in several markets. In some places, fraud has surpassed drugs in turnover and profitability and fraud factories are popping up globally. Talented social engineering fraudsters and patterns with efficient crime-as-a service software, modus and tools. Fraud schemes including native and international fraud clusters targeting Swedish bank customers.

Learn more around the Risk and Anti-fraud toolset in the BankID Identity Platform. Digital identity is an area where the need for innovation is extensive. Whatever future eID scenario you discuss, security is always at the core.

The eID Threat Landscape – Stay Ahead of the Fraudsters
Event Recording
The eID Threat Landscape – Stay Ahead of the Fraudsters
Click here to watch the recording of this session. Please note that this video is only available to event participants and subscribers. You'll need to log in to watch it.
The eID Threat Landscape – Stay Ahead of the Fraudsters
Presentation deck
The eID Threat Landscape – Stay Ahead of the Fraudsters
Click here to download the slide deck. Please note that downloads are only available for event participants and subscribers. You'll need to log in to download it.
Jonas Brännvall
Jonas Brännvall
BankID
Jonas Brannvall, Head of International Business Expansion at BankID, leads the strategic initiative to enable BankID to grow into new markets. BankID is the leading digital identity solution in...

Open Banking and Open Data - Global State of Play. Current Trends and Recent Developments

Open Banking is a true global movement that has already been implemented in many countries and being implemented in many others in the next few years. While the overall objective of Open Banking is the same, every implementation is different. This session will provide an overview of analysis of different ecosystems, different approaches to implementation, industry standards used, best (and worst) practices and potential future developments.

Identity and API security are key building blocks for any trust ecosystem supporting Open Banking. We will explore why every Open Data project becomes an identity initiative.

Open Banking and Open Data - Global State of Play. Current Trends and Recent Developments
Event Recording
Open Banking and Open Data - Global State of Play. Current Trends and Recent Developments
Click here to watch the recording of this session. Please note that this video is only available to event participants and subscribers. You'll need to log in to watch it.
Open Banking and Open Data - Global State of Play. Current Trends and Recent Developments
Presentation deck
Open Banking and Open Data - Global State of Play. Current Trends and Recent Developments
Click here to download the slide deck. Please note that downloads are only available for event participants and subscribers. You'll need to log in to download it.
Dima Postnikov
Dima Postnikov
ConnectID
Experienced Identity Architect focusing on anything identity, privacy, trust ecosystems design and identity standards development. 
Subscribe for updates
Please provide your email address