Key Insights
In this whitepaper, we describe various aspects of OAuth and OpenID Connect — including proof-of-possession, issuer identification, and phantom tokens — that can be used to conform to the revised Directive on Payment Services (PSD2) and the General Data Protection Regulation (GDPR). Though these regulations are mandated by the European Union (EU), the applicability of the techniques described in this paper transcends regulatory regimes, and readers elsewhere building APIs that expose high-worth data will also find this paper useful.
Much of the content is industry agnostic, but various banking and finance examples are provided. Some of the techniques will be described in the context of PSD2 and GDPR, but an in-depth knowledge of these regulations is not required.
Table of contents
Introduction & Overview — 1
Securely Binding Token Obtainment to Presentation — 3
Certificate-bound Access Tokens — 5
Using a Proof Key to Protect Authorization Codes — 7
Pushing Request Parameters in the Back Channel — 11
Protecting Integrity of Requests and Responses — 12
Issuer Identification — 14
Strong Authentication — 17
Dynamic Registration Vis-à-vis PSD2 — 18
Pairwise Pseudonymous Identifiers — 19
Limiting the Regulatory Space — 20
Summary — 22
