English
Related papers

Related papers: An Extensive Formal Security Analysis of the OpenI…

200 papers

We define API Management as an activity that enables organizations to design, publish and deploy their APIs for (external) developers to consume. API Management capabilities such as controlling API lifecycles, access and authentication to…

Software Engineering · Computer Science 2021-05-31 Max Mathijssen , Michiel Overeem , Slinger Jansen

The rise of large language models (LLMs), such as ChatGPT, Gemini, and Grok, has reshaped the AI landscape. As prominent instances of foundational models (FMs), they exhibit remarkable capabilities in generating human-like content, pushing…

Artificial Intelligence · Computer Science 2026-05-19 Yu Qiao , Huy Q. Le , Avi Deb Raha , Phuong-Nam Tran , Apurba Adhikary , Mengchun Zhang , Loc X. Nguyen , Eui-Nam Huh , Dusit Niyato , Choong Seon Hong

Modern web applications make extensive use of API calls to update the UI state in response to user events or server-side changes. For such applications, API-level testing can play an important role, in-between unit-level testing and…

Software Engineering · Computer Science 2023-05-25 Rahulkrishna Yandrapally , Saurabh Sinha , Rachel Tzoref-Brill , Ali Mesbah

As a case study in cryptographic binding, we present a formal-methods analysis of the cryptographic channel binding mechanisms in the Fast IDentity Online (FIDO) Universal Authentication Framework (UAF) authentication protocol, which seeks…

Cryptography and Security · Computer Science 2025-11-11 Enis Golaszewski , Alan T. Sherman , Edward Zieglar , Jonathan D. Fuchs , Sophia Hamer

The rapid advancement of open-source foundation models has brought transparency and accessibility to this groundbreaking technology. However, this openness has also enabled the development of highly-capable, unsafe models, as exemplified by…

Computers and Society · Computer Science 2024-06-18 Terrence Neumann , Bryan Jones

The Huge growth in the usage of web applications has raised concerns regarding their security vulnerabilities, which in turn pushes toward robust security testing tools. This study compares OWASP ZAP, the leading open-source web application…

Cryptography and Security · Computer Science 2025-01-13 Usha-Sri Potti , Hong-Sheng Huang , Hsuan-Tung Chen , Hung-Min Sun

Web applications require access to the file-system for many different tasks. When analyzing the security of a web application, secu- rity analysts should thus consider the impact that file-system operations have on the security of the whole…

Cryptography and Security · Computer Science 2017-05-11 Federico De Meo , Luca Viganò

FIDO2 and the WebAuthn standard offer phishing-resistant, public-key based authentication but traditionally rely on device-bound cryptographic keys that are not naturally portable across user devices. Recent passkey deployments address this…

Cryptography and Security · Computer Science 2026-01-13 Kemal Bicakci , Fatih Mehmet Varli , Muhammet Emir Korkmaz , Yusuf Uzunay

Millions of users routinely use Google to log in to websites supporting OAuth 2.0 or OpenID Connect; the security of OAuth 2.0 and OpenID Connect is therefore of critical importance. As revealed in previous studies, in practice RPs often…

Cryptography and Security · Computer Science 2019-01-28 Wanpeng Li , Chris J Mitchell , Thomas Chen

This paper presents a timing attack on the FIDO2 (Fast IDentity Online) authentication protocol that allows attackers to link user accounts stored in vulnerable authenticators, a serious privacy concern. FIDO2 is a new standard specified by…

Cryptography and Security · Computer Science 2022-05-18 Michal Kepkowski , Lucjan Hanzlik , Ian Wood , Mohamed Ali Kaafar

Fintech provides technological services to increase operational efficiency in financial institutions, but traditional perimeter-based defense mechanisms are insufficient against evolving cyber threats like insider attacks, malware…

Cryptography and Security · Computer Science 2025-07-29 Avinash Singh , Vikas Pareek , Asish Sharma

Prominent AI companies are producing 'safety frameworks' as a type of voluntary self-governance. These statements purport to establish risk thresholds and safety procedures for the development and deployment of highly capable AI.…

Computers and Society · Computer Science 2025-10-14 Sam Coggins , Alexander K. Saeri , Katherine A. Daniell , Lorenn P. Ruster , Jessie Liu , Jenny L. Davis

With challenges and limitations associated with security in the fintech industry, the rise to the need for data protection increases. However, the current existing passwordless and password-based peer to peer transactions in online banking…

Cryptography and Security · Computer Science 2024-08-12 Anisha Ghosh , Aditya Mitra , Sibi Chakkaravarthy Sethuraman , Aswani Kumar Cherukuri

Fast Identity Online 2 (FIDO2), a modern authentication protocol, is gaining popularity as a default strong authentication mechanism. It has been recognized as a leading candidate to overcome limitations (e.g., it is phishing resistant) of…

Cryptography and Security · Computer Science 2023-09-14 Michal Kepkowski , Maciej Machulak , Ian Wood , Dali Kaafar

Implementing a security mechanism on top of APIs requires clear understanding of the semantics of each API, to ensure that security entitlements are enforced consistently and completely across all APIs that could perform the same function…

Cryptography and Security · Computer Science 2023-02-28 Somesh Jha , Mihai Christodorescu , Anh Pham

The use of passwords and the need to protect passwords are not going away. The majority of websites that require authentication continue to support password authentication. Even high-security applications such as Internet Banking portals,…

Networking and Internet Architecture · Computer Science 2020-11-13 Teik Guan Tan , Pawel Szalachowski , Jianying Zhou

Application Programming Interface (API) Injection attacks refer to the unauthorized or malicious use of APIs, which are often exploited to gain access to sensitive data or manipulate online systems for illicit purposes. Identifying actors…

Cryptography and Security · Computer Science 2025-05-16 Udi Aharon , Ran Dubin , Amit Dvir , Chen Hajaj

With the rise of attacks on online accounts in the past years, more and more services offer two-factor authentication for their users. Having factors out of two of the three categories something you know, something you have and something…

Cryptography and Security · Computer Science 2022-07-07 Timon Hackenjos , Benedikt Wagner , Julian Herr , Jochen Rill , Marek Wehmer , Niklas Goerke , Ingmar Baumgart

Unequivocally, a single man in possession of a strong password is not enough to solve the issue of security. Studies indicate that passwords have been subjected to various attacks, regardless of the applied protection mechanisms due to the…

Cryptography and Security · Computer Science 2021-07-02 Anna Angelogianni , Ilias Politis , Christos Xenakis

Increasing number of cyber-attacks demotivate people to use Information and Communication Technology (ICT) for industrial as well as day to day work. A main reason for the increasing number of cyber-attacks is mistakes that programmers make…

Cryptography and Security · Computer Science 2018-10-12 Chamila Wijayarathna , Nalin Asanka Gamagedara Arachchilage