{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T15:50:05Z","timestamp":1780501805843,"version":"3.54.1"},"reference-count":97,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2024,11,11]],"date-time":"2024-11-11T00:00:00Z","timestamp":1731283200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001659","name":"Deutsche Forschungsgemeinschaft","doi-asserted-by":"crossref","award":["443324941"],"award-info":[{"award-number":["443324941"]}],"id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"crossref"}]},{"name":"OpenID Foundation, and the Australian Government"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2025,2,28]]},"abstract":"<jats:p>FAPI 2.0 is a suite of Web protocols developed by the OpenID Foundation\u2019s FAPI Working Group (FAPI WG) for third-party data sharing and digital identity in high-risk environments. Even though the specifications are not completely finished, several important entities have started to adopt the FAPI 2.0 protocols, including Norway\u2019s national HelseID, Australia\u2019s Consumer Data Standards, as well as private companies like Authlete and Australia-based connectID; the predecessor FAPI 1.0 is in widespread use with millions of users.<\/jats:p>\n          <jats:p>The FAPI WG asked us to accompany the standardization of the FAPI 2.0 protocols with a formal security analysis to proactively identify vulnerabilities before widespread deployment and to provide formal security guarantees for the standards. In this paper, we report on our analysis and findings.<\/jats:p>\n          <jats:p>Our analysis is based on a detailed model of the Web infrastructure, the so-called Web Infrastructure Model (WIM), which we extend to be able to carry out our analysis of the FAPI 2.0 protocols including important extensions like FAPI-CIBA. Based on the (extended) WIM and formalizations of the security goals and attacker model laid out in the FAPI 2.0 specifications, we provide a formal model of the protocols and carry out a formal security analysis, revealing several attacks. We have worked with the FAPI WG to fix the protocols, resulting in several amendments to the specifications. With these changes in place, we have adjusted our protocol model and formally proved that the security properties hold true under the strong attacker model defined by the FAPI WG.<\/jats:p>","DOI":"10.1145\/3699716","type":"journal-article","created":{"date-parts":[[2024,10,8]],"date-time":"2024-10-08T15:45:29Z","timestamp":1728402329000},"page":"1-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Formal Security Analysis of the OpenID FAPI 2.0 Family of Protocols: Accompanying a Standardization Process"],"prefix":"10.1145","volume":"28","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5618-5663","authenticated-orcid":false,"given":"Pedram","family":"Hosseyni","sequence":"first","affiliation":[{"name":"Institute of Information Security, University of Stuttgart, Stuttgart, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9071-9312","authenticated-orcid":false,"given":"Ralf","family":"K\u00fcsters","sequence":"additional","affiliation":[{"name":"Institute of Information Security, University of Stuttgart, Stuttgart, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4729-0629","authenticated-orcid":false,"given":"Tim","family":"W\u00fcrtele","sequence":"additional","affiliation":[{"name":"Institute of Information Security, University of Stuttgart, Stuttgart, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,11,11]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"2024. Financial Data Exchange (FDX). https:\/\/financialdataexchange.org\/"},{"key":"e_1_3_2_3_2","unstructured":"2018. Services at Helsenorge. https:\/\/www.helsenorge.no\/om-tjenestene\/slik-brukes-tjenestene-paa-helsenorge"},{"key":"e_1_3_2_4_2","unstructured":"2021. Die elektronische Patientenakte. https:\/\/www.bundesgesundheitsministerium.de\/elektronische-patientenakte"},{"key":"e_1_3_2_5_2","unstructured":"2021. FAPI 2.0 Profile Transition. https:\/\/github.com\/ConsumerDataStandardsAustralia\/future-plan\/issues\/47"},{"key":"e_1_3_2_6_2","unstructured":"2022. Budget Tracker & Planner. https:\/\/mint.intuit.com\/"},{"key":"e_1_3_2_7_2","unstructured":"2022. Electronic Prescription Service - FHIR API. https:\/\/digital.nhs.uk\/developer\/api-catalogue\/electronic-prescription-service-fhir"},{"key":"e_1_3_2_8_2","unstructured":"2022. Open Banking UK. https:\/\/www.openbanking.org.uk\/"},{"key":"e_1_3_2_9_2","unstructured":"2023. verimi. https:\/\/verimi.de\/en\/"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/360204.360213"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2010.27"},{"key":"e_1_3_2_12_2","volume-title":"HTTP Message Signatures","author":"Backman Annabelle","year":"2023","unstructured":"Annabelle Backman, Justin Richer, and Manu Sporny. 2023. HTTP Message Signatures. Internet-Draft draft-ietf-httpbis-message-signatures-19. Internet Engineering Task Force. https:\/\/datatracker.ietf.org\/doc\/draft-ietf-httpbis-message-signatures\/19\/Work in Progress."},{"key":"e_1_3_2_13_2","unstructured":"Banco Central do Brasil. 2024. Open Finance. https:\/\/www.bcb.gov.br\/en\/financialstability\/open_finance"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","unstructured":"Chetan Bansal Karthikeyan Bhargavan Antoine Delignat-Lavaud and Sergio Maffeis. 2014. Discovering concrete attacks on website authorization by formal analysis. Journal of Computer Security 22 4 (2014) 601\u2013657. DOI:10.3233\/jcs-140503","DOI":"10.3233\/jcs-140503"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/csf.2012.27"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC9068"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC8705"},{"key":"e_1_3_2_18_2","article-title":"Universally Composable Security Analysis of OAuth v2.0","author":"Chari Suresh","year":"2011","unstructured":"Suresh Chari, Charanjit Jutla, and Arnab Roy. 2011. Universally Composable Security Analysis of OAuth v2.0. Cryptology ePrint Archive, Paper 2011\/526. (2011). https:\/\/eprint.iacr.org\/2011\/526","journal-title":"Cryptology ePrint Archive, Paper 2011\/526"},{"key":"e_1_3_2_19_2","unstructured":"Commonwealth of Australia. 2022. Consumer Data Standards. (2022). https:\/\/consumerdatastandards.gov.au\/"},{"key":"e_1_3_2_20_2","unstructured":"Bobby Cooke. 2021. The Art of the Device Code Phish. (2021). https:\/\/0xboku.com\/2021\/07\/12\/ArtOfDeviceCodePhish.html"},{"key":"e_1_3_2_21_2","unstructured":"Credit Sense. 2024. Bank Account Aggregation Services. https:\/\/www.creditsense.com.au\/bank-account-aggregation"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC8252"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833681"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1983.1056650"},{"key":"e_1_3_2_25_2","unstructured":"Dropbox Platform Team. 2020. OAuth Guide. (2020). https:\/\/developers.dropbox.com\/oauth-guide"},{"key":"e_1_3_2_26_2","unstructured":"Gonzalo Fernandez Florian Walter Axel Nennker Dave Tonge and Brian Campbell. 2021. OpenID Connect Client-Initiated Backchannel Authentication Flow - Core 1.0. (2021). https:\/\/openid.net\/specs\/openid-client-initiated-backchannel-authentication-core-1_0.html"},{"key":"e_1_3_2_27_2","unstructured":"Daniel Fett. 2022. FAPI 2.0 Attacker Model Commit 209f58a. (2022). https:\/\/bitbucket.org\/openid\/fapi\/src\/209f58afbd41fb20ab3ed65ca4e2f67ffd5dda77\/FAPI_2_0_Attacker_Model.md"},{"key":"e_1_3_2_28_2","unstructured":"Daniel Fett. 2022. Authorization Request Leaks Lead to CSRF. (2022). https:\/\/bitbucket.org\/openid\/fapi\/issues\/534"},{"key":"e_1_3_2_29_2","unstructured":"Daniel Fett. 2022. Improve Attacker Model Description after Introduction of Metadata. (2022). https:\/\/bitbucket.org\/openid\/fapi\/pull-requests\/371"},{"key":"e_1_3_2_30_2","unstructured":"Daniel Fett. 2022. Reduced Attacker Model. (2022). https:\/\/bitbucket.org\/openid\/fapi\/pull-requests\/377"},{"key":"e_1_3_2_31_2","unstructured":"Daniel Fett. 2022. Change Attacker Model to Reflect Formal Model. (2022). https:\/\/bitbucket.org\/openid\/fapi\/pull-requests\/381"},{"key":"e_1_3_2_32_2","unstructured":"Daniel Fett. 2022. FAPI 2.0 Attacker Model. (2022). https:\/\/openid.net\/specs\/fapi-2_0-attacker-model-02.html"},{"key":"e_1_3_2_33_2","unstructured":"Daniel Fett. 2022. FAPI 2.0 Security Profile. (2022). https:\/\/openid.net\/specs\/fapi-2_0-security-profile-ID2.html"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC9449"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00067"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.49"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24174-6_3"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2017.20"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978385"},{"key":"e_1_3_2_40_2","unstructured":"Daniel Fett and Dave Tonge. 2023. FAPI 2.0 Message Signing. (2023). https:\/\/bitbucket.org\/openid\/fapi\/src\/67246ac44d2ee136c184789b9757ba44df57c7b8\/fapi-2_0-message-signing.md"},{"key":"e_1_3_2_41_2","unstructured":"GitHub Inc.2022. Scopes for OAuth Apps. (2022). https:\/\/docs.github.com\/en\/developers\/apps\/building-oauth-apps\/scopes-for-oauth-apps"},{"key":"e_1_3_2_42_2","unstructured":"Google. 2022. OAuth 2.0 Scopes for Google APIs. (2022). https:\/\/developers.google.com\/identity\/protocols\/oauth2\/scopes"},{"key":"e_1_3_2_43_2","unstructured":"Google. 2022. YouTube Data API Overview. (2022). https:\/\/developers.google.com\/youtube\/v3\/getting-started"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1007\/11555827_28"},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2003.1254334"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC6749"},{"key":"e_1_3_2_47_2","volume-title":"The OAuth 2.1 Authorization Framework","author":"Hardt Dick","year":"2024","unstructured":"Dick Hardt, Aaron Parecki, and Torsten Lodderstedt. 2024. The OAuth 2.1 Authorization Framework. Internet-Draft draft-ietf-oauth-v2-1-11. Internet Engineering Task Force. https:\/\/datatracker.ietf.org\/doc\/draft-ietf-oauth-v2-1\/11\/Work in Progress."},{"key":"e_1_3_2_48_2","unstructured":"Joseph Heenan. 2022. DPoP & Resource Leaks. (2022). https:\/\/bitbucket.org\/openid\/fapi\/issues\/533"},{"key":"e_1_3_2_49_2","unstructured":"Joseph Heenan. 2022. Discovery Should be Mandated for Clients. (2022). https:\/\/bitbucket.org\/openid\/fapi\/issues\/536"},{"key":"e_1_3_2_50_2","unstructured":"Joseph Heenan. 2022. FAPI2SP: Add Requirement for RP to Use Discovery. (2022). https:\/\/bitbucket.org\/openid\/fapi\/pull-requests\/363"},{"key":"e_1_3_2_51_2","unstructured":"Joseph Heenan. 2022. FAPI2SP: Add Security Consideration for Cuckoo\u2019s Token Attack. (2022). https:\/\/bitbucket.org\/openid\/fapi\/pull-requests\/364"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-51479-1_12"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF61375.2024.00002"},{"key":"e_1_3_2_54_2","article-title":"Formal Security Analysis of the OpenID FAPI 2.0 Family of Protocols: Accompanying a Standardization Process","author":"Hosseyni Pedram","year":"2024","unstructured":"Pedram Hosseyni, Ralf K\u00fcsters, and Tim W\u00fcrtele. 2024. Formal Security Analysis of the OpenID FAPI 2.0 Family of Protocols: Accompanying a Standardization Process. Cryptology ePrint Archive, Paper 2024\/1540. (2024). https:\/\/eprint.iacr.org\/2024\/1540","journal-title":"Cryptology ePrint Archive, Paper 2024\/1540"},{"key":"e_1_3_2_55_2","unstructured":"Jenko Hwong. 2021. New Phishing Attacks Exploiting OAuth Authentication Flows. (2021). https:\/\/www.youtube.com\/watch?v=9slRYvpKHp4"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC7519"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC7515"},{"key":"e_1_3_2_58_2","volume-title":"OAuth 2.0 Token Binding","author":"Jones Michael","year":"2018","unstructured":"Michael Jones, Brian Campbell, John Bradley, and William Denniss. 2018. OAuth 2.0 Token Binding. Internet-Draft draft-ietf-oauth-token-binding-08. Internet Engineering Task Force. https:\/\/datatracker.ietf.org\/doc\/draft-ietf-oauth-token-binding\/08\/Work in Progress."},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC7523"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC7521"},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC8414"},{"key":"e_1_3_2_62_2","volume-title":"Cross-Device Flows: Security Best Current Practice","author":"Kasselman Pieter","year":"2023","unstructured":"Pieter Kasselman, Daniel Fett, and Filip Skokan. 2023. Cross-Device Flows: Security Best Current Practice. Internet-Draft draft-ietf-oauth-cross-device-security-04. Internet Engineering Task Force. https:\/\/datatracker.ietf.org\/doc\/draft-ietf-oauth-cross-device-security\/04\/Work in Progress."},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420993"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-11379-1_10"},{"key":"e_1_3_2_65_2","volume-title":"The Web Infrastructure Model (WIM)","author":"K\u00fcsters Ralf","year":"2022","unstructured":"Ralf K\u00fcsters, Guido Schmitz, and Daniel Fett. 2022. The Web Infrastructure Model (WIM). Technical Report. https:\/\/www.sec.uni-stuttgart.de\/research\/wim\/WIM_V1.0.pdfVersion 1.0."},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40667-1_18"},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00025"},{"key":"e_1_3_2_68_2","unstructured":"Torsten Lodderstedt John Bradley Andrey Labunets and Daniel Fett. 2019. OAuth 2.0 Security Best Current Practice. (2019). https:\/\/datatracker.ietf.org\/meeting\/105\/materials\/slides-105-oauth-sessa-oauth-security-topics-00.pdf"},{"key":"e_1_3_2_69_2","volume-title":"OAuth 2.0 Security Best Current Practice","author":"Lodderstedt Torsten","year":"2021","unstructured":"Torsten Lodderstedt, John Bradley, Andrey Labunets, and Daniel Fett. 2021. OAuth 2.0 Security Best Current Practice. Internet-Draft. Internet Engineering Task Force. https:\/\/datatracker.ietf.org\/doc\/draft-ietf-oauth-security-topics\/19\/Work in Progress."},{"key":"e_1_3_2_70_2","unstructured":"Thorsten Lodderstedt and Brian Campbell. 2018. Financial-grade API: JWT Secured Authorization Response Mode for OAuth 2.0 (JARM). (2018). https:\/\/openid.net\/specs\/openid-financial-api-jarm.html"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC9126"},{"key":"e_1_3_2_72_2","volume-title":"JWT Response for OAuth Token Introspection","author":"Lodderstedt Torsten","year":"2021","unstructured":"Torsten Lodderstedt and Vladimir Dzhuvinov. 2021. JWT Response for OAuth Token Introspection. Internet-Draft draft-ietf-oauth-jwt-introspection-response-12. Internet Engineering Task Force. https:\/\/datatracker.ietf.org\/doc\/draft-ietf-oauth-jwt-introspection-response\/12\/Work in Progress."},{"key":"e_1_3_2_73_2","unstructured":"Meta. 2022. email \u2013 Graph API. (2022). https:\/\/developers.facebook.com\/docs\/permissions\/reference\/email"},{"key":"e_1_3_2_74_2","unstructured":"Minist\u00e9rio da Economia do Brasil. 2024. Open Finance. https:\/\/www.gov.br\/susep\/pt-br\/assuntos\/open-insurance"},{"key":"e_1_3_2_75_2","article-title":"On the security of modern Single Sign-On Protocols: Second-order vulnerabilities in OpenID connect","volume":"1508","author":"Mladenov Vladislav","year":"2015","unstructured":"Vladislav Mladenov, Christian Mainka, and J\u00f6rg Schwenk. 2015. On the security of modern Single Sign-On Protocols: Second-order vulnerabilities in OpenID connect. CoRR abs\/1508.04324v2 (2015). arXiv:1508.04324v2","journal-title":"CoRR"},{"key":"e_1_3_2_76_2","unstructured":"OWASP Top 10. 2021. Security Misconfiguration. (2021). https:\/\/owasp.org\/Top10\/A05_2021-Security_Misconfiguration\/"},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.1109\/csnt.2011.141"},{"key":"e_1_3_2_78_2","unstructured":"Aaron Parecki. 2020. OAuth 2.0 Simplified: Token Introspection Endpoint. (2020). https:\/\/www.oauth.com\/oauth2-servers\/token-introspection-endpoint\/"},{"key":"e_1_3_2_79_2","unstructured":"Payments NZ. 2024. Governance of NZ Payment Systems. https:\/\/www.paymentsnz.co.nz\/"},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC7662"},{"key":"e_1_3_2_81_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC9635"},{"key":"e_1_3_2_82_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC7591"},{"key":"e_1_3_2_83_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC7592"},{"key":"e_1_3_2_84_2","unstructured":"Nat Sakimura. 2022. Decide on What To Do for A. Cuckoo\u2019s Token Attack. (2022). https:\/\/bitbucket.org\/openid\/fapi\/issues\/525"},{"key":"e_1_3_2_85_2","unstructured":"Nat Sakimura. 2022. Browser Swap Attack Explained on 2022-09-28. (2022). https:\/\/bitbucket.org\/openid\/fapi\/issues\/543"},{"key":"e_1_3_2_86_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC7636"},{"key":"e_1_3_2_87_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC9101"},{"key":"e_1_3_2_88_2","unstructured":"Nat Sakimura John Bradley M. Jones B. de Medeiros and C. Mortimore. 2014. OpenID Connect Core 1.0 Incorporating Errata Set 1. (2014). http:\/\/openid.net\/specs\/openid-connect-core-1_0.html"},{"key":"e_1_3_2_89_2","unstructured":"Nat Sakimura John Bradley M. Jones and E. Jay. 2014. OpenID Connect Discovery 1.0 Incorporating Errata Set 1. (2014). http:\/\/openid.net\/specs\/openid-connect-discovery-1_0.html"},{"key":"e_1_3_2_90_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-20550-2_13"},{"key":"e_1_3_2_91_2","unstructured":"Smartcar. 2022. Car API Platform for Connected Vehicle Data. (2022). https:\/\/smartcar.com\/"},{"key":"e_1_3_2_92_2","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382238"},{"key":"e_1_3_2_93_2","unstructured":"Dave Tonge. 2023. CIBA - Make Clear Limitation of Binding Message. (2023). https:\/\/bitbucket.org\/openid\/fapi\/issues\/609"},{"key":"e_1_3_2_94_2","unstructured":"Dave Tonge. 2023. FAPI Client Initiated Backchannel Authentication Profile. (2023). https:\/\/bitbucket.org\/openid\/fapi\/src\/f3390ad\/Financial_API_WD_CIBA.md"},{"key":"e_1_3_2_95_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179465"},{"key":"e_1_3_2_96_2","doi-asserted-by":"publisher","DOI":"10.1145\/2897845.2897874"},{"key":"e_1_3_2_97_2","first-page":"495","volume-title":"Proceedings of the 23rd USENIX Security Symposium","author":"Zhou Yuchen","year":"2014","unstructured":"Yuchen Zhou and David Evans. 2014. SSOScan: Automated testing of web applications for single sign-on vulnerabilities. In Proceedings of the 23rd USENIX Security Symposium, Kevin Fu and Jaeyeon Jung (Eds.). USENIX Association, 495\u2013510. https:\/\/www.usenix.org\/conference\/usenixsecurity14\/technical-sessions\/presentation\/zhou"},{"key":"e_1_3_2_98_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC9207"}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3699716","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3699716","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:09:53Z","timestamp":1750295393000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3699716"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,11]]},"references-count":97,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,2,28]]}},"alternative-id":["10.1145\/3699716"],"URL":"https:\/\/doi.org\/10.1145\/3699716","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"value":"2471-2566","type":"print"},{"value":"2471-2574","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,11,11]]},"assertion":[{"value":"2024-01-08","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-09-29","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-11-11","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}