中文
相关论文

相关论文: Security Analysis of the Open Banking Account and …

200 篇论文

In this paper, we consider the problem of verifying anonymity and unlinkability in the symbolic model, where protocols are represented as processes in a variant of the applied pi calculus, notably used in the ProVerif tool. Existing tools…

密码学与安全 · 计算机科学 2019-04-09 Lucca Hirschi , David Baelde , Stéphanie Delaune

The concept of Secure Multi-Party Computation (SMPC) is a cryptographic service that allows generating analysis of sensitive data related to finance under the collaboration of all stakeholders without violating the privacy of the research…

密码学与安全 · 计算机科学 2026-01-05 Brahim Khalil Sedraoui , Abdelmadjid Benmachiche , Amina Makhlouf , Chaouki Chemam

Formal verification of cryptographic protocols typically relies on symbolic models that abstract away compiled code and microarchitectural side channels, leaving a gap between verified specifications and deployed executables. We present a…

密码学与安全 · 计算机科学 2026-05-08 Faezeh Nasrabadi , Robert Künnemann , Hamed Nemati

This paper presents a complete formal specification, protocol description, and mathematical proof structure for Simplified Payment Verification (SPV) as originally defined in the Bitcoin whitepaper \cite{nakamoto2008}. In stark contrast to…

密码学与安全 · 计算机科学 2025-07-02 Craig S Wright

Presently, Bangladesh is expending substantial efforts to digitize its national infrastructure, with a significant emphasis on achieving this goal through mobile applications that facilitate online payments and banking system advancements.…

密码学与安全 · 计算机科学 2024-11-28 Shahriar Hasan Mickey , Muhammad Nur Yanhaona

To prevent password breaches and guessing attacks, banks increasingly turn to two-factor authentication (2FA), requiring users to present at least one more factor, such as a one-time password generated by a hardware token or received via…

密码学与安全 · 计算机科学 2015-01-20 Kat Krol , Eleni Philippou , Emiliano De Cristofaro , M. Angela Sasse

Very recently, Barman et al. proposed a multi-server authentication protocol using fuzzy commitment. The authors claimed that their protocol provides anonymity while resisting all known attacks. In this paper, we analyze that Barman et…

密码学与安全 · 计算机科学 2020-04-17 Hafeez Ur Rehman , Anwar Ghani , Shehzad Ashraf Chaudhry , Mohammed H. Alsharif , Narjes Nabipour

Private Set Intersection (PSI) is a vital cryptographic technique used for securely computing common data of different sets. In PSI protocols, often two parties hope to find their common set elements without needing to disclose their…

密码学与安全 · 计算机科学 2021-02-01 Alireza Kavousi , Javad Mohajeri , Mahmoud Salmasizadeh

Unlike other industries in which intellectual property is patentable, the financial industry relies on trade secrecy to protect its business processes and methods, which can obscure critical financial risk exposures from regulators and the…

风险管理 · 定量金融 2011-11-28 Emmanuel A. Abbe , Amir E. Khandani , Andrew W. Lo

A protocol for two-party secure function evaluation (2P-SFE) aims to allow the parties to learn the output of function $f$ of their private inputs, while leaking nothing more. In a sense, such a protocol realizes a trusted oracle that…

The deployment of autonomous AI agents capable of executing commercial transactions has motivated the adoption of mandate-based payment authorization protocols, including the Universal Commerce Protocol (UCP) and the Agent Payments Protocol…

密码学与安全 · 计算机科学 2026-02-09 Qianlong Lan , Anuj Kaul , Shaun Jones , Stephanie Westrum

Digitalization in many economic sectors drove the financial system to adapt to new paradigms of technological transformation. Moreover, the extant regulatory framework forced the financial system to reconsider its business models and its…

综合金融 · 定量金融 2022-10-18 Valeria Stefanelli , Francesco Manta , Pierluigi Toma

This report provides a detailed comparison between the Safety and Security measures proposed in the EU AI Act's General-Purpose AI (GPAI) Code of Practice (Third Draft) and the current commitments and practices voluntarily adopted by…

计算机与社会 · 计算机科学 2025-07-24 Lily Stelling , Mick Yang , Rokas Gipiškis , Leon Staufer , Ze Shen Chin , Siméon Campos , Ariel Gil , Michael Chen

We propose a privacy-preserving smart wallet with a novel invitation-based private onboarding mechanism. The solution integrates two levels of compliance in concert with an authority party: a proof of innocence mechanism and an ancestral…

密码学与安全 · 计算机科学 2025-09-19 Andrea Rizzini , Marco Esposito , Francesco Bruschi , Donatella Sciuto

Authentication and authorization are two key elements of a software application. In modern day, OAuth 2.0 framework and OpenID Connect protocol are widely adopted standards fulfilling these requirements. These protocols are implemented into…

密码学与安全 · 计算机科学 2018-08-21 Kavindu Dodanduwa , Ishara Kaluthanthri

Blockchain technology has been gaining great interest from a variety of sectors, including healthcare, supply chain and cryptocurrencies. However, Blockchain suffers from its limited ability to scale (i.e. low throughput and high latency).…

密码学与安全 · 计算机科学 2021-08-13 Abdelatif Hafid , Abdelhakim Senhaji Hafid , Adil Senhaji

Fairness monitoring is critical for detecting algorithmic bias, as mandated by the EU AI Act. Since such monitoring requires sensitive user data (e.g., ethnicity), the AI Act permits its processing only with strict privacy measures, such as…

人机交互 · 计算机科学 2026-02-03 Changyang He , Parnian Jahangirirad , Lin Kyi , Asia J. Biega

Implicit authentication consists of a server authenticating a user based on the user's usage profile, instead of/in addition to relying on something the user explicitly knows (passwords, private keys, etc.). While implicit authentication…

密码学与安全 · 计算机科学 2015-03-03 Josep Domingo-Ferrer , Qianhong Wu , Alberto Blanco-Justicia

API economy is driving the digital transformation of business applications across the hybrid Cloud and edge environments. For such transformations to succeed, end-to-end testing of the application API composition is required. Testing of API…

OAuth 2.0 is a popular authorization framework that allows third-party clients such as websites and mobile apps to request limited access to a user's account on another application. The specification classifies clients into different types…

密码学与安全 · 计算机科学 2023-08-03 Jaimandeep Singh , Naveen Kumar Chaudhary