Skip to content

Commit ddd7854

Browse files
authored
Scrubbed references for normative and informative sections
Normative RFCs only
2 parents b96c046 + 338c16b commit ddd7854

File tree

1 file changed

+105
-117
lines changed

1 file changed

+105
-117
lines changed

draft-ietf-oauth-cross-device-security.md

Lines changed: 105 additions & 117 deletions
Original file line numberDiff line numberDiff line change
@@ -27,17 +27,10 @@ author:
2727
normative:
2828
RFC2119: # Key words for use in RFCs to Indicate Requirement Levels
2929
RFC6749: # OAuth 2.0 Authorization Framework
30-
RFC8693: # OAuth 2.0 Token Exchange
31-
RFC7523: # JSON Web Token (JWT) Profile for OAuth 2.0 Client Authentication and Authorization Grants
3230
RFC7636: # Proof Key for Code Exchange by OAuth Public Clients
3331
RFC8174: # Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words
34-
RFC8707: # Resource Indicators for OAuth 2.0
35-
RFC8414: # OAuth 2.0 Authorization Server Metadata
36-
RFC8725: # JSON Web Token Best Current Practices
37-
RFC2046: # Multipurpose Internet Mail Extensions (MIME) Part Two: Media Types
38-
RFC6838: # Media Type Specifications and Registration Procedures
3932
RFC8628: # OAuth 2.0 Device Authorization Grant
40-
RFC9635: # Grant Negotiation and Authorization Protocol (GNAP)
33+
RFC7662: # OAuth 2.0 Token Introspection
4134
CIBA:
4235
title: "OpenID Connect Client-Initiated Backchannel Authentication Flow - Core 1.0"
4336
author:
@@ -53,10 +46,112 @@ normative:
5346
org: Ping Identity
5447
date: 2021-09
5548
target: https://openid.net/specs/openid-client-initiated-backchannel-authentication-core-1_0.html
56-
49+
CAEP:
50+
title: "OpenID Continuous Access Evaluation Profile 1.0 - draft 01"
51+
author:
52+
- initials: "A."
53+
surname: "Tulshibagwale"
54+
fullname: "Atul Tulshibagwale"
55+
organization: "Google"
56+
- initials: "T."
57+
surname: "Cappalli"
58+
fullname: "Tim Cappalli"
59+
organization: "Microsoft"
60+
date: 2021-06
61+
target: "https://openid.net/specs/openid-caep-specification-1_0-01.html"
62+
SSF:
63+
title: "OpenID Shared Signals and Events Framework Specification 1.0"
64+
author:
65+
- initials: "A."
66+
surname: "Tulshibagwale"
67+
fullname: "Atul Tulshibagwale"
68+
organization: "Google"
69+
- initials: "T."
70+
surname: "Cappalli"
71+
fullname: "Tim Cappalli"
72+
organization: "Microsoft"
73+
- initials: "M."
74+
surname: "Scurtescu"
75+
fullname: "Marius Scurtescu"
76+
organization: "Coinbase"
77+
- initials: "A."
78+
surname: "Backman"
79+
fullname: "Annabelle Backman"
80+
organization: "Amazon"
81+
- initials: "J."
82+
surname: "Bradley"
83+
fullname: "John Bradley"
84+
organization: "Yubico"
85+
date: 2021-06
86+
target: "https://openid.net/specs/openid-sse-framework-1_0-01.html"
87+
W3CWebAuthn:
88+
title: "Web Authentication: An API for accessing Public Key Credentials Level 3"
89+
author:
90+
- initials: "T."
91+
surname: "Cappalli"
92+
fullname: "Tim Cappalli"
93+
organization: "Okta"
94+
- initials: "M."
95+
surname: "Jones"
96+
fullname: "Michael B. Jones"
97+
organization: "Microsoft"
98+
- initials: "A."
99+
surname: "Kumar"
100+
fullname: "Akshay Kumar"
101+
organization: "Microsoft"
102+
- initials: "E."
103+
surname: "Lundberg"
104+
fullname: "Emil Lundberg"
105+
organization: "Yubico"
106+
- initials: "M."
107+
surname: "Miller"
108+
fullname: "Matthew Miller"
109+
organization: "Cisco"
110+
date: 2025-01
111+
target: "https://www.w3.org/TR/2025/WD-webauthn-3-20250127/"
112+
FIDOCTAP22:
113+
title: "Client to Authenticator Protocol (CTAP)"
114+
author:
115+
- initials: "J."
116+
surname: "Bradley"
117+
fullname: "John Bradley"
118+
organization: "Yubico"
119+
- initials: "M."
120+
surname: "Jones"
121+
fullname: "Michael B. Jones"
122+
organization: "Microsoft"
123+
- initials: "A."
124+
surname: "Kumar"
125+
fullname: "Akshay Kumar"
126+
organization: "Microsoft"
127+
- initials: "R."
128+
surname: "Lindemann"
129+
fullname: "Rolf Lindemann"
130+
organization: "Nok Nok Labs"
131+
- initials: "S."
132+
surname: "Verrept"
133+
fullname: "Johan Verrept"
134+
organization: "OneSpan"
135+
- initials: "D."
136+
surname: "Waite"
137+
fullname: "David Waite"
138+
organization: "Ping Identity"
139+
date: 2025-02
140+
target: "https://fidoalliance.org/specs/fido-v2.2-ps-20250228/fido-client-to-authenticator-protocol-v2.2-ps-20250228.html"
141+
IEEE802154:
142+
title: "IEEE Std 802.15.4-2020: IEEE Standard for Low-Rate Wireless Networks"
143+
author:
144+
-
145+
organization: "Institute of Electrical and Electronics Engineers"
146+
date: 2020
147+
seriesinfo:
148+
- name: "IEEE"
149+
value: "802.15.4-2020"
150+
target: "https://standards.ieee.org/standard/802_15_4-2020.html"
57151

58152
informative:
59-
RFC7662: # OAuth 2.0 Token Introspection
153+
RFC9635: # Grant Negotiation and Authorization Protocol (GNAP)
154+
60155
Exploit1:
61156
title: "The Art of the Device Code Phish"
62157
author:
@@ -163,73 +258,6 @@ informative:
163258
- ins: B. de Medeiros
164259
- ins: C. Mortimore
165260

166-
IEEE802154:
167-
title: "IEEE Std 802.15.4-2020: IEEE Standard for Low-Rate Wireless Networks"
168-
author:
169-
-
170-
organization: "Institute of Electrical and Electronics Engineers"
171-
date: 2020
172-
seriesinfo:
173-
- name: "IEEE"
174-
value: "802.15.4-2020"
175-
target: "https://standards.ieee.org/standard/802_15_4-2020.html"
176-
177-
W3CWebAuthn:
178-
title: "Web Authentication: An API for accessing Public Key Credentials Level 3"
179-
author:
180-
- initials: "T."
181-
surname: "Cappalli"
182-
fullname: "Tim Cappalli"
183-
organization: "Okta"
184-
- initials: "M."
185-
surname: "Jones"
186-
fullname: "Michael B. Jones"
187-
organization: "Microsoft"
188-
- initials: "A."
189-
surname: "Kumar"
190-
fullname: "Akshay Kumar"
191-
organization: "Microsoft"
192-
- initials: "E."
193-
surname: "Lundberg"
194-
fullname: "Emil Lundberg"
195-
organization: "Yubico"
196-
- initials: "M."
197-
surname: "Miller"
198-
fullname: "Matthew Miller"
199-
organization: "Cisco"
200-
date: 2025-01
201-
target: "https://www.w3.org/TR/2025/WD-webauthn-3-20250127/"
202-
203-
FIDOCTAP22:
204-
title: "Client to Authenticator Protocol (CTAP)"
205-
author:
206-
- initials: "J."
207-
surname: "Bradley"
208-
fullname: "John Bradley"
209-
organization: "Yubico"
210-
- initials: "M."
211-
surname: "Jones"
212-
fullname: "Michael B. Jones"
213-
organization: "Microsoft"
214-
- initials: "A."
215-
surname: "Kumar"
216-
fullname: "Akshay Kumar"
217-
organization: "Microsoft"
218-
- initials: "R."
219-
surname: "Lindemann"
220-
fullname: "Rolf Lindemann"
221-
organization: "Nok Nok Labs"
222-
- initials: "S."
223-
surname: "Verrept"
224-
fullname: "Johan Verrept"
225-
organization: "OneSpan"
226-
- initials: "D."
227-
surname: "Waite"
228-
fullname: "David Waite"
229-
organization: "Ping Identity"
230-
date: 2025-02
231-
target: "https://fidoalliance.org/specs/fido-v2.2-ps-20250228/fido-client-to-authenticator-protocol-v2.2-ps-20250228.html"
232-
233261
PCRSM2023:
234262
title: "An Automated Multi-Layered Methodology to Assist the Secure and Risk-Aware Design of Multi-Factor Authentication Protocols, IEEE Transactions on Dependable and Secure Computing (TDSC)"
235263
author:
@@ -284,46 +312,6 @@ informative:
284312
date: 2023
285313
target: "https://doi.org/10.1109/TDSC.2022.3151103"
286314

287-
CAEP:
288-
title: "OpenID Continuous Access Evaluation Profile 1.0 - draft 01"
289-
author:
290-
- initials: "A."
291-
surname: "Tulshibagwale"
292-
fullname: "Atul Tulshibagwale"
293-
organization: "Google"
294-
- initials: "T."
295-
surname: "Cappalli"
296-
fullname: "Tim Cappalli"
297-
organization: "Microsoft"
298-
date: 2021-06
299-
target: "https://openid.net/specs/openid-caep-specification-1_0-01.html"
300-
301-
SSF:
302-
title: "OpenID Shared Signals and Events Framework Specification 1.0"
303-
author:
304-
- initials: "A."
305-
surname: "Tulshibagwale"
306-
fullname: "Atul Tulshibagwale"
307-
organization: "Google"
308-
- initials: "T."
309-
surname: "Cappalli"
310-
fullname: "Tim Cappalli"
311-
organization: "Microsoft"
312-
- initials: "M."
313-
surname: "Scurtescu"
314-
fullname: "Marius Scurtescu"
315-
organization: "Coinbase"
316-
- initials: "A."
317-
surname: "Backman"
318-
fullname: "Annabelle Backman"
319-
organization: "Amazon"
320-
- initials: "J."
321-
surname: "Bradley"
322-
fullname: "John Bradley"
323-
organization: "Yubico"
324-
date: 2021-06
325-
target: "https://openid.net/specs/openid-sse-framework-1_0-01.html"
326-
327315
--- abstract
328316

329317
This document describes threats against cross-device flows

0 commit comments

Comments
 (0)