Katalog Plus
Bibliothek der Frankfurt UAS
Bald neuer Katalog: sichern Sie sich schon vorab Ihre persönlichen Merklisten im Nutzerkonto: Anleitung.
Dieses Ergebnis aus BASE kann Gästen nicht angezeigt werden.  Login für vollen Zugriff.

Security analysis of the open banking account and transaction API protocol

Title: Security analysis of the open banking account and transaction API protocol
Authors: Modesti P; Freitas L; Shotomiwa Q; Almehrej A
Source: Cyber Security and Applications, December 2025
Publisher Information: KeAi Communications Co.
Publication Year: 2025
Collection: Newcastle University Library ePrints Service
Description: © 2025. The Second Payment Services Directive (PSD2) of the European Union aims to create a consumer-friendly financial market by mandating secure and standardised data sharing between banking operators and third parties. Consequently, EU countries and the United Kingdom have adopted Open Banking, a standardised data-sharing API. This paper presents a formal modelling and security analysis of the UK Open Banking Standard's APIs, with a specific focus on the Account and Transaction API protocol. Our methodology employs the extended Alice and Bob notation (AnBx) to create a formal model of the protocol, which is then verified using the OFMC symbolic model checker and the ProVerif cryptographic protocol verifier. We extend previous work by enabling verification for unlimited sessions with a strongly typed model. Additionally, we integrate our formal analysis with practical security testing of some necessary conditions to demonstrate verified security-goals in the NatWest Open Banking sandbox, evaluating mechanisms such as authorisation and authentication procedures.
Document Type: article in journal/newspaper
File Description: application/pdf
Language: unknown
Relation: https://eprints.ncl.ac.uk/306431; https://eprints.ncl.ac.uk/fulltext.aspx?url=306431/E10C9534-2262-47B2-ADA7-81C61B719B86.pdf&pub_id=306431
Availability: https://eprints.ncl.ac.uk/306431
Rights: https://creativecommons.org/licenses/by-nc-nd/4.0/
Accession Number: edsbas.EC6EA995
Database: BASE