About

Log in?

DTU users get better search results including licensed content and discounts on order fees.

Anyone can log in and get personalized features such as favorites, tags and feeds.

Log in as DTU user Log in as non-DTU user No thanks

DTU Findit

Conference paper · Book chapter

Towards Secure Open Banking Architecture: An Evaluation with OWASP

From

Technical University of Denmark1

Department of Applied Mathematics and Computer Science, Technical University of Denmark2

Cyber Security, Department of Applied Mathematics and Computer Science, Technical University of Denmark3

The European Union passed the PSD2 regulation in 2015, which gives ownership of bank accounts to the private person owning it. As a result, the term Open Banking, allowing third party providers and developers access to bank APIs, has emerged, welcoming a myriad of innovative solutions for the financial sector.

However, multiple cyber security issues arise from exposing bank data to third party providers through an API. In this work, we propose an architectural model that ensures clear separation of concern and easy integration with Nordea’s Open Banking APIs (sandbox version), and a technological stack, consisting of the micro-framework Flask, the cloud application platform Heroku and persistent data storage layer (using Postgres).

We analyze the web application’s security threats, and determine whether or not the technological frame provides adequate security protection, by leveraging the OWASP Top 10 list of the Ten Most Critical Web Application Security Risks. Our results can support future developers and industries working on web applications for Open Banking towards security improvement by choosing the right frameworks and considering the most important vulnerabilities, as well as contributing to the documentation and development of Nordea’s APIs.

Language: English
Publisher: Springer
Year: 2019
Pages: 185-198
Proceedings: 13th International Conference on Network and System Security
Series: Lecture Notes in Computer Science (including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
ISBN: 3030369374 , 3030369382 , 9783030369378 and 9783030369385
ISSN: 03029743 and 16113349
Types: Conference paper and Book chapter
DOI: 10.1007/978-3-030-36938-5_11
ORCIDs: Meng, Weizhi

DTU users get better search results including licensed content and discounts on order fees.

Log in as DTU user

Access

Analysis