@@ -27,17 +27,10 @@ author:
2727normative :
2828 RFC2119 : # Key words for use in RFCs to Indicate Requirement Levels
2929 RFC6749 : # OAuth 2.0 Authorization Framework
30- RFC8693 : # OAuth 2.0 Token Exchange
31- RFC7523 : # JSON Web Token (JWT) Profile for OAuth 2.0 Client Authentication and Authorization Grants
3230 RFC7636 : # Proof Key for Code Exchange by OAuth Public Clients
3331 RFC8174 : # Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words
34- RFC8707 : # Resource Indicators for OAuth 2.0
35- RFC8414 : # OAuth 2.0 Authorization Server Metadata
36- RFC8725 : # JSON Web Token Best Current Practices
37- RFC2046 : # Multipurpose Internet Mail Extensions (MIME) Part Two: Media Types
38- RFC6838 : # Media Type Specifications and Registration Procedures
3932 RFC8628 : # OAuth 2.0 Device Authorization Grant
40- RFC9635 : # Grant Negotiation and Authorization Protocol (GNAP)
33+ RFC7662 : # OAuth 2.0 Token Introspection
4134 CIBA :
4235 title : " OpenID Connect Client-Initiated Backchannel Authentication Flow - Core 1.0"
4336 author :
@@ -53,10 +46,112 @@ normative:
5346 org : Ping Identity
5447 date : 2021-09
5548 target : https://openid.net/specs/openid-client-initiated-backchannel-authentication-core-1_0.html
56-
49+ CAEP :
50+ title : " OpenID Continuous Access Evaluation Profile 1.0 - draft 01"
51+ author :
52+ - initials : " A."
53+ surname : " Tulshibagwale"
54+ fullname : " Atul Tulshibagwale"
55+ organization : " Google"
56+ - initials : " T."
57+ surname : " Cappalli"
58+ fullname : " Tim Cappalli"
59+ organization : " Microsoft"
60+ date : 2021-06
61+ target : " https://openid.net/specs/openid-caep-specification-1_0-01.html"
62+ SSF :
63+ title : " OpenID Shared Signals and Events Framework Specification 1.0"
64+ author :
65+ - initials : " A."
66+ surname : " Tulshibagwale"
67+ fullname : " Atul Tulshibagwale"
68+ organization : " Google"
69+ - initials : " T."
70+ surname : " Cappalli"
71+ fullname : " Tim Cappalli"
72+ organization : " Microsoft"
73+ - initials : " M."
74+ surname : " Scurtescu"
75+ fullname : " Marius Scurtescu"
76+ organization : " Coinbase"
77+ - initials : " A."
78+ surname : " Backman"
79+ fullname : " Annabelle Backman"
80+ organization : " Amazon"
81+ - initials : " J."
82+ surname : " Bradley"
83+ fullname : " John Bradley"
84+ organization : " Yubico"
85+ date : 2021-06
86+ target : " https://openid.net/specs/openid-sse-framework-1_0-01.html"
87+ W3CWebAuthn :
88+ title : " Web Authentication: An API for accessing Public Key Credentials Level 3"
89+ author :
90+ - initials : " T."
91+ surname : " Cappalli"
92+ fullname : " Tim Cappalli"
93+ organization : " Okta"
94+ - initials : " M."
95+ surname : " Jones"
96+ fullname : " Michael B. Jones"
97+ organization : " Microsoft"
98+ - initials : " A."
99+ surname : " Kumar"
100+ fullname : " Akshay Kumar"
101+ organization : " Microsoft"
102+ - initials : " E."
103+ surname : " Lundberg"
104+ fullname : " Emil Lundberg"
105+ organization : " Yubico"
106+ - initials : " M."
107+ surname : " Miller"
108+ fullname : " Matthew Miller"
109+ organization : " Cisco"
110+ date : 2025-01
111+ target : " https://www.w3.org/TR/2025/WD-webauthn-3-20250127/"
112+ FIDOCTAP22 :
113+ title : " Client to Authenticator Protocol (CTAP)"
114+ author :
115+ - initials : " J."
116+ surname : " Bradley"
117+ fullname : " John Bradley"
118+ organization : " Yubico"
119+ - initials : " M."
120+ surname : " Jones"
121+ fullname : " Michael B. Jones"
122+ organization : " Microsoft"
123+ - initials : " A."
124+ surname : " Kumar"
125+ fullname : " Akshay Kumar"
126+ organization : " Microsoft"
127+ - initials : " R."
128+ surname : " Lindemann"
129+ fullname : " Rolf Lindemann"
130+ organization : " Nok Nok Labs"
131+ - initials : " S."
132+ surname : " Verrept"
133+ fullname : " Johan Verrept"
134+ organization : " OneSpan"
135+ - initials : " D."
136+ surname : " Waite"
137+ fullname : " David Waite"
138+ organization : " Ping Identity"
139+ date : 2025-02
140+ target : " https://fidoalliance.org/specs/fido-v2.2-ps-20250228/fido-client-to-authenticator-protocol-v2.2-ps-20250228.html"
141+ IEEE802154 :
142+ title : " IEEE Std 802.15.4-2020: IEEE Standard for Low-Rate Wireless Networks"
143+ author :
144+ -
145+ organization : " Institute of Electrical and Electronics Engineers"
146+ date : 2020
147+ seriesinfo :
148+ - name : " IEEE"
149+ value : " 802.15.4-2020"
150+ target : " https://standards.ieee.org/standard/802_15_4-2020.html"
57151
58152informative :
59- RFC7662 : # OAuth 2.0 Token Introspection
153+ RFC9635 : # Grant Negotiation and Authorization Protocol (GNAP)
154+
60155 Exploit1 :
61156 title : " The Art of the Device Code Phish"
62157 author :
@@ -163,73 +258,6 @@ informative:
163258 - ins : B. de Medeiros
164259 - ins : C. Mortimore
165260
166- IEEE802154 :
167- title : " IEEE Std 802.15.4-2020: IEEE Standard for Low-Rate Wireless Networks"
168- author :
169- -
170- organization : " Institute of Electrical and Electronics Engineers"
171- date : 2020
172- seriesinfo :
173- - name : " IEEE"
174- value : " 802.15.4-2020"
175- target : " https://standards.ieee.org/standard/802_15_4-2020.html"
176-
177- W3CWebAuthn :
178- title : " Web Authentication: An API for accessing Public Key Credentials Level 3"
179- author :
180- - initials : " T."
181- surname : " Cappalli"
182- fullname : " Tim Cappalli"
183- organization : " Okta"
184- - initials : " M."
185- surname : " Jones"
186- fullname : " Michael B. Jones"
187- organization : " Microsoft"
188- - initials : " A."
189- surname : " Kumar"
190- fullname : " Akshay Kumar"
191- organization : " Microsoft"
192- - initials : " E."
193- surname : " Lundberg"
194- fullname : " Emil Lundberg"
195- organization : " Yubico"
196- - initials : " M."
197- surname : " Miller"
198- fullname : " Matthew Miller"
199- organization : " Cisco"
200- date : 2025-01
201- target : " https://www.w3.org/TR/2025/WD-webauthn-3-20250127/"
202-
203- FIDOCTAP22 :
204- title : " Client to Authenticator Protocol (CTAP)"
205- author :
206- - initials : " J."
207- surname : " Bradley"
208- fullname : " John Bradley"
209- organization : " Yubico"
210- - initials : " M."
211- surname : " Jones"
212- fullname : " Michael B. Jones"
213- organization : " Microsoft"
214- - initials : " A."
215- surname : " Kumar"
216- fullname : " Akshay Kumar"
217- organization : " Microsoft"
218- - initials : " R."
219- surname : " Lindemann"
220- fullname : " Rolf Lindemann"
221- organization : " Nok Nok Labs"
222- - initials : " S."
223- surname : " Verrept"
224- fullname : " Johan Verrept"
225- organization : " OneSpan"
226- - initials : " D."
227- surname : " Waite"
228- fullname : " David Waite"
229- organization : " Ping Identity"
230- date : 2025-02
231- target : " https://fidoalliance.org/specs/fido-v2.2-ps-20250228/fido-client-to-authenticator-protocol-v2.2-ps-20250228.html"
232-
233261 PCRSM2023 :
234262 title : " An Automated Multi-Layered Methodology to Assist the Secure and Risk-Aware Design of Multi-Factor Authentication Protocols, IEEE Transactions on Dependable and Secure Computing (TDSC)"
235263 author :
@@ -284,46 +312,6 @@ informative:
284312 date : 2023
285313 target : " https://doi.org/10.1109/TDSC.2022.3151103"
286314
287- CAEP :
288- title : " OpenID Continuous Access Evaluation Profile 1.0 - draft 01"
289- author :
290- - initials : " A."
291- surname : " Tulshibagwale"
292- fullname : " Atul Tulshibagwale"
293- organization : " Google"
294- - initials : " T."
295- surname : " Cappalli"
296- fullname : " Tim Cappalli"
297- organization : " Microsoft"
298- date : 2021-06
299- target : " https://openid.net/specs/openid-caep-specification-1_0-01.html"
300-
301- SSF :
302- title : " OpenID Shared Signals and Events Framework Specification 1.0"
303- author :
304- - initials : " A."
305- surname : " Tulshibagwale"
306- fullname : " Atul Tulshibagwale"
307- organization : " Google"
308- - initials : " T."
309- surname : " Cappalli"
310- fullname : " Tim Cappalli"
311- organization : " Microsoft"
312- - initials : " M."
313- surname : " Scurtescu"
314- fullname : " Marius Scurtescu"
315- organization : " Coinbase"
316- - initials : " A."
317- surname : " Backman"
318- fullname : " Annabelle Backman"
319- organization : " Amazon"
320- - initials : " J."
321- surname : " Bradley"
322- fullname : " John Bradley"
323- organization : " Yubico"
324- date : 2021-06
325- target : " https://openid.net/specs/openid-sse-framework-1_0-01.html"
326-
327315--- abstract
328316
329317This document describes threats against cross-device flows
0 commit comments