Towards Secure Open Banking Architecture: An Evaluation with OWASP

被引:4
|
作者
Kellezi, Deina [1 ]
Boegelund, Christian [1 ]
Meng, Weizhi [1 ,2 ]
机构
[1] Tech Univ Denmark, Dept Appl Math & Comp Sci, Lyngby, Denmark
[2] Guangzhou Univ, Dept Comp Sci, Guangzhou, Peoples R China
来源
基金
中国国家自然科学基金;
关键词
Web security; Open Banking API; OWASP; Threat and risk; PSD2; regulation; Secure architecture;
D O I
10.1007/978-3-030-36938-5_11
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The European Union passed the PSD2 regulation in 2015, which gives ownership of bank accounts to the private person owning it. As a result, the term Open Banking, allowing third party providers and developers access to bank APIs, has emerged, welcoming a myriad of innovative solutions for the financial sector. However, multiple cyber security issues arise from exposing bank data to third party providers through an API. In this work, we propose an architectural model that ensures clear separation of concern and easy integration with Nordea's Open Banking APIs (sandbox version), and a technological stack, consisting of the micro-framework Flask, the cloud application platform Heroku and persistent data storage layer (using Postgres). We analyze the web application's security threats, and determine whether or not the technological frame provides adequate security protection, by leveraging the OWASP Top 10 list of the Ten Most Critical Web Application Security Risks. Our results can support future developers and industries working on web applications for Open Banking towards security improvement by choosing the right frameworks and considering the most important vulnerabilities, as well as contributing to the documentation and development of Nordea's APIs.
引用
收藏
页码:185 / 198
页数:14
相关论文
共 50 条
  • [31] Is open banking driving the financial industry towards a true electronic market?
    Richard Dratva
    Electronic Markets, 2020, 30 : 65 - 67
  • [32] Is open banking driving the financial industry towards a true electronic market?
    Dratva, Richard
    ELECTRONIC MARKETS, 2020, 30 (01) : 65 - 67
  • [33] TOWARDS OPEN-ARCHITECTURE CONCURRENT ENGINEERING FRAMEWORKS
    MANTYLA, M
    TOWARDS WORLD CLASS MANUFACTURING 1993, 1994, 17 : 135 - 149
  • [34] Towards an open architecture specification language for machine control
    Engels, DW
    Sarma, SE
    SENSORS AND CONTROLS FOR INTELLIGENT MACHINING AND MANUFACTURING MECHATRONICS, 1999, 3832 : 17 - 25
  • [35] Open Process Automation: A standards-based, open, secure, interoperable process control architecture
    Bartusiak, R. Donald
    Bitar, Stephen
    DeBari, David L.
    Houk, Bradley G.
    Stevens, Dennis
    Fitzpatrick, Bridget
    Sloan, Patrick
    CONTROL ENGINEERING PRACTICE, 2022, 121
  • [36] Towards an open architecture for the integration and interoperability of distributed systems
    Rabhi, FA
    2001 ENTERPRISE NETWORKING, APPLICATIONS AND SERVICES CONFERENCE PROCEEDINGS: ENTNET(AT)SUPERCOMM2001, 2001, : 3 - 8
  • [37] In principle: Towards an open architecture for eGovernment identity management
    Katzy, BR
    Van Den Hoven, J
    Igl, G
    EADOPTION AND THE KNOWLEDGE ECONOMY: ISSUES, APPLICATIONS, CASE STUDIES, PTS 1 AND 2, 2004, 1 : 685 - 692
  • [38] VLSI architecture for encryption and watermarking units towards the making of a secure camera
    Adamo, O. B.
    Mohanty, Saraju P.
    Kougianos, E.
    Varanasi, M.
    IEEE INTERNATIONAL SOC CONFERENCE, PROCEEDINGS, 2006, : 141 - +
  • [39] Towards an open service architecture for data mining on the grid
    Brezany, P
    Hofer, R
    Wöhrer, A
    Tjoa, AM
    14TH INTERNATIONAL WORKSHOP ON DATABASE AND EXPERT SYSTEMS APPLICATIONS, PROCEEDINGS, 2003, : 524 - 528
  • [40] Towards an European Open Continuum Reference Stack and Architecture
    Rossini, Rosaria
    Lopez, Lara
    2024 9TH INTERNATIONAL CONFERENCE ON SMART AND SUSTAINABLE TECHNOLOGIES, SPLITECH 2024, 2024,