SlideShare a Scribd company logo
Copyright© Nomura Research Institute, Ltd. All rights reserved.
Nat Sakimura (@_nat)
Chairman of the Board, OpenID Foundation
Senior Researcher, Nomura Research Institute
Issues towards Open Banking ecosystem and how
OpenID Foundation tackles them with financial-grade
APIs standard
PAST AND FUTURE OF FINANCIAL-GRADE APIS:
• OpenID® is a registered trademark of OpenID Foundation.
• *Unless otherwisenoted, all the photos and vector images are licensed by GraphicStocks.
July 25, 2018
Copyright© Nomura Research Institute, Ltd. All rights reserved.
Do you use Personal
Finance Software?
What are the current problems?
Copyright© Nomura Research Institute, Ltd. All rights reserved.
When NRI started screen scraping in 2001,
we thought it will be a temporally solution.
3
“There was OFX, and SAML was coming. SOAP was gaining
momentum. We should be able to get out of scraping business
in a few years time!”
Copyright© Nomura Research Institute, Ltd. All rights reserved.
WRONG!
4
Copyright© Nomura Research Institute, Ltd. All rights reserved.
After 15 years, we are still screen scraping.
5
(2016)
Copyright© Nomura Research Institute, Ltd. All rights reserved.
But the wind was changing.
6
(2016)
Copyright© Nomura Research Institute, Ltd. All rights reserved.
Fintech was gaining momentum
(SOURCE)GoogleTrends
Copyright© Nomura Research Institute, Ltd. All rights reserved.
API started to gain attention as one of the
three main component of FinTech
8
Use cases for Identity Federation
API in Financial sector
1. Account Opening (incl. KYC)
2. Personal Asset Managment
3. Payment, Sending Money
4. Loan Application
5. AI assisted portfolio management
(Source) Nikkei BP: Fintech Revolution P.4
(Source)Nikkei BP: FinTech Yearbook
Copyright© Nomura Research Institute, Ltd. All rights reserved.
I
9
• JSON , XML + OAuth 2.0
• INDUSTRY PUSH >
US: FS-ISAC Durable Data API
(Source) FS-ISACFSDDA WG
OpenID FinancialAPI
Copyright© Nomura Research Institute, Ltd. All rights reserved.
REGULATORY PUSH> UK CMA Order and EU PSD2
10
(SOURCE) ODI OBWG: The Open Banking Standard (2016)
JSON REST
OAuth
OpenID Connect
Copyright© Nomura Research Institute, Ltd. All rights reserved.
Open Data
in Finance
Conference
15 June,
2016
London
12
http://www.open-data-finance.com/agenda/
Copyright© Nomura Research Institute, Ltd. All rights reserved.
Now is the time!
13
Copyright© Nomura Research Institute, Ltd. All rights reserved.
but what API protection?
14
and what API request/response?
Copyright© Nomura Research Institute, Ltd. All rights reserved.
Solution Time!
15
Copyright© Nomura Research Institute, Ltd. All rights reserved.
OpenID Foundation
Financial API (FAPI) WG
(2016)
16
Copyright© Nomura Research Institute, Ltd. All rights reserved.
II. What is OpenID Foundation
• A WG can be spun up by more than three
members proposing and by the approval by
the Specs Council and the Board review (2
weeks).
• Specs Council is composed by the current
editors of the specs and checks the overlaps
with other WGs or SDOs.
• The board checks that it will not cause IPR
threats to the foundation.
OpenID Foundation is an International Standardization
Organization that specializes on
Internet Identity and API protection
17
Copyright© Nomura Research Institute, Ltd. All rights reserved.
II. What is OpenID Foundation
Working Together
18
OpenID FAPI
(Chair)
(Co-Chair)(Co-Chair)
(UK OBIE Liaison)
Liaison Organizations
TC 68
JTC 1/SC 27/WG 5
Nat Sakimura
Tony NadalinAnoop Saxena
fido 2.0 WG Chair
W3C Web Authn WG Chair
Copyright© Nomura Research Institute, Ltd. All rights reserved.
II. Whatis OpenID Foundation
The work progresses with a weekly tele-conferences, mailing list discussions
and project repository (https://bitbucket.org/openid/fapi/ )
19
Issue Tracker
Meeting notes
Commit History
Pull Requests
Draft Text
Copyright© Nomura Research Institute, Ltd. All rights reserved.
Purpose
The goal of FAPI is to provide JSON data schemas, REST APIs,
and security & privacy recommendations and protocols to:
20
JSON REST
OAuth
OpenID Connect
(SOURCE) ODI OBWG: The Open Banking Standard (2016)
Copyright© Nomura Research Institute, Ltd. All rights reserved.
Enable
• applicationsto utilize the data stored in the financial
account,
• applicationsto interact with the financial account, and
• users to control the security and privacy settings.
Both commercial and investment banking account as well as
insurance, and credit card accounts are to be considered.
(Source) OpenID FoundationFinancial APIWG draft charter
Copyright© Nomura Research Institute, Ltd. All rights reserved.
So that we can finally get rid of
password storing and screen scraping!
22
Copyright© Nomura Research Institute, Ltd. All rights reserved.
It will also help foster
the FinTech companies.
23
Copyright© Nomura Research Institute, Ltd. All rights reserved.
Why OpenID Foundation?
•Authors of OAuth, JWT, JWS, OpenID
Connect are all here.
Right
People
•Loyalty Free, Mutual Non-Assert, so
that everyone can use it freely.
Right IPR
•Free to join WGs. (Sponsors welcome)
•WTO TBT Compliant Process.
Right
Structure
24
Copyright© Nomura Research Institute, Ltd. All rights reserved.
2 Implementer’s Drafts
• Part 1: Read Only Security Profile
• Part 2: Read and Write Security Profile
25
Redirect
Approach
Decoupled
Approach
Embedded
Approach
Copyright© Nomura Research Institute, Ltd. All rights reserved.
OpenID Foundation
Financial-grade API (FAPI) WG
(2018)
26
Copyright© Nomura Research Institute, Ltd. All rights reserved.
But the EC almost requires
PASSWORD SHARING
27
Redirect
Approach
Decoupled
Approach
Embedded
Approach
Though it is illegal in France…
Copyright© Nomura Research Institute, Ltd. All rights reserved.
To combat the situation, we have
• CIBA: The Decoupled Approach
28
Redirect
Approach
Decoupled
Approach
Embedded
Approach
Copyright© Nomura Research Institute, Ltd. All rights reserved.
To combat the situation, we have
• CIBA: The Decoupled Approach
• Manual Per App ”password” to third
party applications.
29
Redirect
Approach
Decoupled
Approach
Embedded
Approach
Copyright© Nomura Research Institute, Ltd. All rights reserved.
Hoping to come up with a solid draft by the end of the
summer
30
Redirect
Approach
Decoupled
Approach
Embedded
Approach
Copyright© Nomura Research Institute, Ltd. All rights reserved.
Join the group!
https://openid.net/wg/fapi/
31

More Related Content

What's hot

BizDay: Trusted Data Exchange for Corp and Supplier Onboarding, Capgemini
BizDay: Trusted Data Exchange for Corp and Supplier Onboarding, CapgeminiBizDay: Trusted Data Exchange for Corp and Supplier Onboarding, Capgemini
BizDay: Trusted Data Exchange for Corp and Supplier Onboarding, Capgemini
R3
 
What’s new in WSO2 Open Banking
What’s new in WSO2 Open BankingWhat’s new in WSO2 Open Banking
What’s new in WSO2 Open Banking
WSO2
 
(FinPort) TrueLayer deck - Connect Ventures 2016
(FinPort) TrueLayer deck - Connect Ventures 2016(FinPort) TrueLayer deck - Connect Ventures 2016
(FinPort) TrueLayer deck - Connect Ventures 2016
Pietro Bezza
 
Webinar materials | PSD2: Ensuring a seamless payments journey - connecting A...
Webinar materials | PSD2: Ensuring a seamless payments journey - connecting A...Webinar materials | PSD2: Ensuring a seamless payments journey - connecting A...
Webinar materials | PSD2: Ensuring a seamless payments journey - connecting A...
XMLdation Ltd
 
PSD2: Implementing APIs that interoperate with ISO 20022
PSD2: Implementing APIs that interoperate with ISO 20022PSD2: Implementing APIs that interoperate with ISO 20022
PSD2: Implementing APIs that interoperate with ISO 20022
XMLdation Ltd
 
Open Banking - Bringing Regulation and Technology together for Digital Trans...
Open Banking - Bringing Regulation and Technology together for  Digital Trans...Open Banking - Bringing Regulation and Technology together for  Digital Trans...
Open Banking - Bringing Regulation and Technology together for Digital Trans...
WSO2
 
The State of Blockchains Q1 2018
The State of Blockchains Q1 2018The State of Blockchains Q1 2018
The State of Blockchains Q1 2018
Outlier Ventures
 
Implementing Open Banking with ForgeRock
Implementing Open Banking with ForgeRockImplementing Open Banking with ForgeRock
Implementing Open Banking with ForgeRock
ForgeRock Identity Tech Talks
 
A4: Kasetsart University | FinTech and Contracts (2018)
A4: Kasetsart University | FinTech and Contracts (2018)A4: Kasetsart University | FinTech and Contracts (2018)
A4: Kasetsart University | FinTech and Contracts (2018)
Kullarat Phongsathaporn
 
Webinar: The Future of FinTech: Insights for 2021 | Intellectsoft
Webinar: The Future of FinTech: Insights for 2021 | IntellectsoftWebinar: The Future of FinTech: Insights for 2021 | Intellectsoft
Webinar: The Future of FinTech: Insights for 2021 | Intellectsoft
Intellectsoft
 
Insurance Round Table
Insurance Round TableInsurance Round Table
Insurance Round Table
R3
 
DevDay: Open Banking and Blockchain, IntellectEU
DevDay: Open Banking and Blockchain, IntellectEUDevDay: Open Banking and Blockchain, IntellectEU
DevDay: Open Banking and Blockchain, IntellectEU
R3
 
Corda for Corporates at Sibos 2019
Corda for Corporates at Sibos 2019Corda for Corporates at Sibos 2019
Corda for Corporates at Sibos 2019
R3
 
The impact of AI and Blockchain technologies in the Legal Industry
The impact of AI and Blockchain technologies in the Legal IndustryThe impact of AI and Blockchain technologies in the Legal Industry
The impact of AI and Blockchain technologies in the Legal Industry
Hunter Thompson
 
BizDay: B3i: A Real Blockchain Solution for a Real Business Problem, Sylvain...
BizDay:  B3i: A Real Blockchain Solution for a Real Business Problem, Sylvain...BizDay:  B3i: A Real Blockchain Solution for a Real Business Problem, Sylvain...
BizDay: B3i: A Real Blockchain Solution for a Real Business Problem, Sylvain...
R3
 
Fintech Belgium - Meetup on Compliance / KYC - Frank Verhaest - Isabel Group
Fintech Belgium - Meetup on Compliance / KYC - Frank Verhaest - Isabel GroupFintech Belgium - Meetup on Compliance / KYC - Frank Verhaest - Isabel Group
Fintech Belgium - Meetup on Compliance / KYC - Frank Verhaest - Isabel Group
FinTech Belgium
 

What's hot (16)

BizDay: Trusted Data Exchange for Corp and Supplier Onboarding, Capgemini
BizDay: Trusted Data Exchange for Corp and Supplier Onboarding, CapgeminiBizDay: Trusted Data Exchange for Corp and Supplier Onboarding, Capgemini
BizDay: Trusted Data Exchange for Corp and Supplier Onboarding, Capgemini
 
What’s new in WSO2 Open Banking
What’s new in WSO2 Open BankingWhat’s new in WSO2 Open Banking
What’s new in WSO2 Open Banking
 
(FinPort) TrueLayer deck - Connect Ventures 2016
(FinPort) TrueLayer deck - Connect Ventures 2016(FinPort) TrueLayer deck - Connect Ventures 2016
(FinPort) TrueLayer deck - Connect Ventures 2016
 
Webinar materials | PSD2: Ensuring a seamless payments journey - connecting A...
Webinar materials | PSD2: Ensuring a seamless payments journey - connecting A...Webinar materials | PSD2: Ensuring a seamless payments journey - connecting A...
Webinar materials | PSD2: Ensuring a seamless payments journey - connecting A...
 
PSD2: Implementing APIs that interoperate with ISO 20022
PSD2: Implementing APIs that interoperate with ISO 20022PSD2: Implementing APIs that interoperate with ISO 20022
PSD2: Implementing APIs that interoperate with ISO 20022
 
Open Banking - Bringing Regulation and Technology together for Digital Trans...
Open Banking - Bringing Regulation and Technology together for  Digital Trans...Open Banking - Bringing Regulation and Technology together for  Digital Trans...
Open Banking - Bringing Regulation and Technology together for Digital Trans...
 
The State of Blockchains Q1 2018
The State of Blockchains Q1 2018The State of Blockchains Q1 2018
The State of Blockchains Q1 2018
 
Implementing Open Banking with ForgeRock
Implementing Open Banking with ForgeRockImplementing Open Banking with ForgeRock
Implementing Open Banking with ForgeRock
 
A4: Kasetsart University | FinTech and Contracts (2018)
A4: Kasetsart University | FinTech and Contracts (2018)A4: Kasetsart University | FinTech and Contracts (2018)
A4: Kasetsart University | FinTech and Contracts (2018)
 
Webinar: The Future of FinTech: Insights for 2021 | Intellectsoft
Webinar: The Future of FinTech: Insights for 2021 | IntellectsoftWebinar: The Future of FinTech: Insights for 2021 | Intellectsoft
Webinar: The Future of FinTech: Insights for 2021 | Intellectsoft
 
Insurance Round Table
Insurance Round TableInsurance Round Table
Insurance Round Table
 
DevDay: Open Banking and Blockchain, IntellectEU
DevDay: Open Banking and Blockchain, IntellectEUDevDay: Open Banking and Blockchain, IntellectEU
DevDay: Open Banking and Blockchain, IntellectEU
 
Corda for Corporates at Sibos 2019
Corda for Corporates at Sibos 2019Corda for Corporates at Sibos 2019
Corda for Corporates at Sibos 2019
 
The impact of AI and Blockchain technologies in the Legal Industry
The impact of AI and Blockchain technologies in the Legal IndustryThe impact of AI and Blockchain technologies in the Legal Industry
The impact of AI and Blockchain technologies in the Legal Industry
 
BizDay: B3i: A Real Blockchain Solution for a Real Business Problem, Sylvain...
BizDay:  B3i: A Real Blockchain Solution for a Real Business Problem, Sylvain...BizDay:  B3i: A Real Blockchain Solution for a Real Business Problem, Sylvain...
BizDay: B3i: A Real Blockchain Solution for a Real Business Problem, Sylvain...
 
Fintech Belgium - Meetup on Compliance / KYC - Frank Verhaest - Isabel Group
Fintech Belgium - Meetup on Compliance / KYC - Frank Verhaest - Isabel GroupFintech Belgium - Meetup on Compliance / KYC - Frank Verhaest - Isabel Group
Fintech Belgium - Meetup on Compliance / KYC - Frank Verhaest - Isabel Group
 

Similar to Issues towards Open Banking ecosystem and how OpenID Foundation tackles them with financial-grade APIs standard #fapisum - Japan/UK Open Banking and APIs Summit 2018 - July 25, 2018

OpenID Foundation Foundation Financial API (FAPI) WG
OpenID Foundation Foundation Financial API (FAPI) WGOpenID Foundation Foundation Financial API (FAPI) WG
OpenID Foundation Foundation Financial API (FAPI) WG
Nat Sakimura
 
Financial Grade OAuth & OpenID Connect
Financial Grade OAuth & OpenID ConnectFinancial Grade OAuth & OpenID Connect
Financial Grade OAuth & OpenID Connect
Nat Sakimura
 
OpenID Foundation Foundation Financial API (FAPI) WG
OpenID Foundation Foundation Financial API (FAPI) WGOpenID Foundation Foundation Financial API (FAPI) WG
OpenID Foundation Foundation Financial API (FAPI) WG
Nat Sakimura
 
API Days 2016 Day 1: OpenID Financial API WG
API Days 2016 Day 1: OpenID Financial API WGAPI Days 2016 Day 1: OpenID Financial API WG
API Days 2016 Day 1: OpenID Financial API WG
Nat Sakimura
 
Introduction to 
the FAPI Read & Write OAuth Profile - Jan 2018 Updates
Introduction to 
the FAPI Read & Write OAuth Profile - Jan 2018 UpdatesIntroduction to 
the FAPI Read & Write OAuth Profile - Jan 2018 Updates
Introduction to 
the FAPI Read & Write OAuth Profile - Jan 2018 Updates
Nat Sakimura
 
Introduction to the FAPI Read & Write OAuth Profile
Introduction to the FAPI Read & Write OAuth ProfileIntroduction to the FAPI Read & Write OAuth Profile
Introduction to the FAPI Read & Write OAuth Profile
Nat Sakimura
 
OpenID Foundation FAPI WG: June 2017 Update
OpenID Foundation FAPI WG: June 2017 UpdateOpenID Foundation FAPI WG: June 2017 Update
OpenID Foundation FAPI WG: June 2017 Update
Nat Sakimura
 
Open Source Basics
Open Source BasicsOpen Source Basics
Open Source Basics
Ross Gardler
 
OpenID Foundation Workshop at EIC 2018 - Introduction to the FAPI Read & Writ...
OpenID Foundation Workshop at EIC 2018 - Introduction to the FAPI Read & Writ...OpenID Foundation Workshop at EIC 2018 - Introduction to the FAPI Read & Writ...
OpenID Foundation Workshop at EIC 2018 - Introduction to the FAPI Read & Writ...
MikeLeszcz
 
Crafting enhanced customer experience through chatbots, beacons and oracle jet
Crafting enhanced customer experience through chatbots, beacons and oracle jetCrafting enhanced customer experience through chatbots, beacons and oracle jet
Crafting enhanced customer experience through chatbots, beacons and oracle jet
Rohit Dhamija
 
CIS13: OpenID Connect: How it Solves your Problems
CIS13: OpenID Connect: How it Solves your ProblemsCIS13: OpenID Connect: How it Solves your Problems
CIS13: OpenID Connect: How it Solves your Problems
CloudIDSummit
 
Commemorating 20 years of open source successes in building awareness and ado...
Commemorating 20 years of open source successes in building awareness and ado...Commemorating 20 years of open source successes in building awareness and ado...
Commemorating 20 years of open source successes in building awareness and ado...
OW2
 
Open Source And the Internet Of Things
Open Source And the Internet Of ThingsOpen Source And the Internet Of Things
Open Source And the Internet Of Things
ProgrammableWeb
 
OMA Open Source Industry Survey Results
OMA Open Source Industry Survey ResultsOMA Open Source Industry Survey Results
OMA Open Source Industry Survey Results
Open Mobile Alliance
 
The leadership in the new digital age carved by the fourth industrial revolu...
The leadership in the new digital age carved by  the fourth industrial revolu...The leadership in the new digital age carved by  the fourth industrial revolu...
The leadership in the new digital age carved by the fourth industrial revolu...
Osaka University
 
SFSCON23 - Simon Phipps - Regulation, AI and the State of Software Freedom in...
SFSCON23 - Simon Phipps - Regulation, AI and the State of Software Freedom in...SFSCON23 - Simon Phipps - Regulation, AI and the State of Software Freedom in...
SFSCON23 - Simon Phipps - Regulation, AI and the State of Software Freedom in...
South Tyrol Free Software Conference
 
apidays LIVE New York 2021 - API Economy in Financial Services by Giovanni Le...
apidays LIVE New York 2021 - API Economy in Financial Services by Giovanni Le...apidays LIVE New York 2021 - API Economy in Financial Services by Giovanni Le...
apidays LIVE New York 2021 - API Economy in Financial Services by Giovanni Le...
apidays
 
FIDO Ecosystem in China
FIDO Ecosystem in ChinaFIDO Ecosystem in China
FIDO Ecosystem in China
FIDO Alliance
 
How can large open source projects be monetized?
How can large open source projects be monetized?How can large open source projects be monetized?
How can large open source projects be monetized?
Bruno Lowagie
 
apidays LIVE LONDON - Open Finance, it's already happening by Dave Tonge
apidays LIVE LONDON - Open Finance, it's already happening by Dave Tongeapidays LIVE LONDON - Open Finance, it's already happening by Dave Tonge
apidays LIVE LONDON - Open Finance, it's already happening by Dave Tonge
apidays
 

Similar to Issues towards Open Banking ecosystem and how OpenID Foundation tackles them with financial-grade APIs standard #fapisum - Japan/UK Open Banking and APIs Summit 2018 - July 25, 2018 (20)

OpenID Foundation Foundation Financial API (FAPI) WG
OpenID Foundation Foundation Financial API (FAPI) WGOpenID Foundation Foundation Financial API (FAPI) WG
OpenID Foundation Foundation Financial API (FAPI) WG
 
Financial Grade OAuth & OpenID Connect
Financial Grade OAuth & OpenID ConnectFinancial Grade OAuth & OpenID Connect
Financial Grade OAuth & OpenID Connect
 
OpenID Foundation Foundation Financial API (FAPI) WG
OpenID Foundation Foundation Financial API (FAPI) WGOpenID Foundation Foundation Financial API (FAPI) WG
OpenID Foundation Foundation Financial API (FAPI) WG
 
API Days 2016 Day 1: OpenID Financial API WG
API Days 2016 Day 1: OpenID Financial API WGAPI Days 2016 Day 1: OpenID Financial API WG
API Days 2016 Day 1: OpenID Financial API WG
 
Introduction to 
the FAPI Read & Write OAuth Profile - Jan 2018 Updates
Introduction to 
the FAPI Read & Write OAuth Profile - Jan 2018 UpdatesIntroduction to 
the FAPI Read & Write OAuth Profile - Jan 2018 Updates
Introduction to 
the FAPI Read & Write OAuth Profile - Jan 2018 Updates
 
Introduction to the FAPI Read & Write OAuth Profile
Introduction to the FAPI Read & Write OAuth ProfileIntroduction to the FAPI Read & Write OAuth Profile
Introduction to the FAPI Read & Write OAuth Profile
 
OpenID Foundation FAPI WG: June 2017 Update
OpenID Foundation FAPI WG: June 2017 UpdateOpenID Foundation FAPI WG: June 2017 Update
OpenID Foundation FAPI WG: June 2017 Update
 
Open Source Basics
Open Source BasicsOpen Source Basics
Open Source Basics
 
OpenID Foundation Workshop at EIC 2018 - Introduction to the FAPI Read & Writ...
OpenID Foundation Workshop at EIC 2018 - Introduction to the FAPI Read & Writ...OpenID Foundation Workshop at EIC 2018 - Introduction to the FAPI Read & Writ...
OpenID Foundation Workshop at EIC 2018 - Introduction to the FAPI Read & Writ...
 
Crafting enhanced customer experience through chatbots, beacons and oracle jet
Crafting enhanced customer experience through chatbots, beacons and oracle jetCrafting enhanced customer experience through chatbots, beacons and oracle jet
Crafting enhanced customer experience through chatbots, beacons and oracle jet
 
CIS13: OpenID Connect: How it Solves your Problems
CIS13: OpenID Connect: How it Solves your ProblemsCIS13: OpenID Connect: How it Solves your Problems
CIS13: OpenID Connect: How it Solves your Problems
 
Commemorating 20 years of open source successes in building awareness and ado...
Commemorating 20 years of open source successes in building awareness and ado...Commemorating 20 years of open source successes in building awareness and ado...
Commemorating 20 years of open source successes in building awareness and ado...
 
Open Source And the Internet Of Things
Open Source And the Internet Of ThingsOpen Source And the Internet Of Things
Open Source And the Internet Of Things
 
OMA Open Source Industry Survey Results
OMA Open Source Industry Survey ResultsOMA Open Source Industry Survey Results
OMA Open Source Industry Survey Results
 
The leadership in the new digital age carved by the fourth industrial revolu...
The leadership in the new digital age carved by  the fourth industrial revolu...The leadership in the new digital age carved by  the fourth industrial revolu...
The leadership in the new digital age carved by the fourth industrial revolu...
 
SFSCON23 - Simon Phipps - Regulation, AI and the State of Software Freedom in...
SFSCON23 - Simon Phipps - Regulation, AI and the State of Software Freedom in...SFSCON23 - Simon Phipps - Regulation, AI and the State of Software Freedom in...
SFSCON23 - Simon Phipps - Regulation, AI and the State of Software Freedom in...
 
apidays LIVE New York 2021 - API Economy in Financial Services by Giovanni Le...
apidays LIVE New York 2021 - API Economy in Financial Services by Giovanni Le...apidays LIVE New York 2021 - API Economy in Financial Services by Giovanni Le...
apidays LIVE New York 2021 - API Economy in Financial Services by Giovanni Le...
 
FIDO Ecosystem in China
FIDO Ecosystem in ChinaFIDO Ecosystem in China
FIDO Ecosystem in China
 
How can large open source projects be monetized?
How can large open source projects be monetized?How can large open source projects be monetized?
How can large open source projects be monetized?
 
apidays LIVE LONDON - Open Finance, it's already happening by Dave Tonge
apidays LIVE LONDON - Open Finance, it's already happening by Dave Tongeapidays LIVE LONDON - Open Finance, it's already happening by Dave Tonge
apidays LIVE LONDON - Open Finance, it's already happening by Dave Tonge
 

More from FinTechLabs.io

Open Banking: The View from a Japanese Startup (Authlete) #fapisum - Japan/UK...
Open Banking: The View from a Japanese Startup (Authlete) #fapisum - Japan/UK...Open Banking: The View from a Japanese Startup (Authlete) #fapisum - Japan/UK...
Open Banking: The View from a Japanese Startup (Authlete) #fapisum - Japan/UK...
FinTechLabs.io
 
FAPI / Open Banking Test Suite #fapisum - Japan/UK Open Banking and APIs Summ...
FAPI / Open Banking Test Suite #fapisum - Japan/UK Open Banking and APIs Summ...FAPI / Open Banking Test Suite #fapisum - Japan/UK Open Banking and APIs Summ...
FAPI / Open Banking Test Suite #fapisum - Japan/UK Open Banking and APIs Summ...
FinTechLabs.io
 
Banking API Trends in Japan #fapisum - Japan/UK Open Banking and APIs Summit ...
Banking API Trends in Japan #fapisum - Japan/UK Open Banking and APIs Summit ...Banking API Trends in Japan #fapisum - Japan/UK Open Banking and APIs Summit ...
Banking API Trends in Japan #fapisum - Japan/UK Open Banking and APIs Summit ...
FinTechLabs.io
 
FAPI / Open Banking Conformance #fapisum - Japan/UK Open Banking and APIs Sum...
FAPI / Open Banking Conformance #fapisum - Japan/UK Open Banking and APIs Sum...FAPI / Open Banking Conformance #fapisum - Japan/UK Open Banking and APIs Sum...
FAPI / Open Banking Conformance #fapisum - Japan/UK Open Banking and APIs Sum...
FinTechLabs.io
 
The Great British API Client Bake Off #fapisum - Japan/UK Open Banking and AP...
The Great British API Client Bake Off #fapisum - Japan/UK Open Banking and AP...The Great British API Client Bake Off #fapisum - Japan/UK Open Banking and AP...
The Great British API Client Bake Off #fapisum - Japan/UK Open Banking and AP...
FinTechLabs.io
 
Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...
Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...
Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...
FinTechLabs.io
 
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
FinTechLabs.io
 
FAPI and Beyond: From an specification author's point of view #fapisum - Japa...
FAPI and Beyond: From an specification author's point of view #fapisum - Japa...FAPI and Beyond: From an specification author's point of view #fapisum - Japa...
FAPI and Beyond: From an specification author's point of view #fapisum - Japa...
FinTechLabs.io
 
Basics: OAuth and OpenID Connect #fapisum - Japan/UK Open Banking and APIs Su...
Basics: OAuth and OpenID Connect #fapisum - Japan/UK Open Banking and APIs Su...Basics: OAuth and OpenID Connect #fapisum - Japan/UK Open Banking and APIs Su...
Basics: OAuth and OpenID Connect #fapisum - Japan/UK Open Banking and APIs Su...
FinTechLabs.io
 
Trends in Banking APIs #fapisum - Japan/UK Open Banking and APIs Summit 2018 ...
Trends in Banking APIs #fapisum - Japan/UK Open Banking and APIs Summit 2018 ...Trends in Banking APIs #fapisum - Japan/UK Open Banking and APIs Summit 2018 ...
Trends in Banking APIs #fapisum - Japan/UK Open Banking and APIs Summit 2018 ...
FinTechLabs.io
 
Open Banking for Developers #fapisum - Japan/UK Open Banking and APIs Summit ...
Open Banking for Developers #fapisum - Japan/UK Open Banking and APIs Summit ...Open Banking for Developers #fapisum - Japan/UK Open Banking and APIs Summit ...
Open Banking for Developers #fapisum - Japan/UK Open Banking and APIs Summit ...
FinTechLabs.io
 

More from FinTechLabs.io (11)

Open Banking: The View from a Japanese Startup (Authlete) #fapisum - Japan/UK...
Open Banking: The View from a Japanese Startup (Authlete) #fapisum - Japan/UK...Open Banking: The View from a Japanese Startup (Authlete) #fapisum - Japan/UK...
Open Banking: The View from a Japanese Startup (Authlete) #fapisum - Japan/UK...
 
FAPI / Open Banking Test Suite #fapisum - Japan/UK Open Banking and APIs Summ...
FAPI / Open Banking Test Suite #fapisum - Japan/UK Open Banking and APIs Summ...FAPI / Open Banking Test Suite #fapisum - Japan/UK Open Banking and APIs Summ...
FAPI / Open Banking Test Suite #fapisum - Japan/UK Open Banking and APIs Summ...
 
Banking API Trends in Japan #fapisum - Japan/UK Open Banking and APIs Summit ...
Banking API Trends in Japan #fapisum - Japan/UK Open Banking and APIs Summit ...Banking API Trends in Japan #fapisum - Japan/UK Open Banking and APIs Summit ...
Banking API Trends in Japan #fapisum - Japan/UK Open Banking and APIs Summit ...
 
FAPI / Open Banking Conformance #fapisum - Japan/UK Open Banking and APIs Sum...
FAPI / Open Banking Conformance #fapisum - Japan/UK Open Banking and APIs Sum...FAPI / Open Banking Conformance #fapisum - Japan/UK Open Banking and APIs Sum...
FAPI / Open Banking Conformance #fapisum - Japan/UK Open Banking and APIs Sum...
 
The Great British API Client Bake Off #fapisum - Japan/UK Open Banking and AP...
The Great British API Client Bake Off #fapisum - Japan/UK Open Banking and AP...The Great British API Client Bake Off #fapisum - Japan/UK Open Banking and AP...
The Great British API Client Bake Off #fapisum - Japan/UK Open Banking and AP...
 
Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...
Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...
Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...
 
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
 
FAPI and Beyond: From an specification author's point of view #fapisum - Japa...
FAPI and Beyond: From an specification author's point of view #fapisum - Japa...FAPI and Beyond: From an specification author's point of view #fapisum - Japa...
FAPI and Beyond: From an specification author's point of view #fapisum - Japa...
 
Basics: OAuth and OpenID Connect #fapisum - Japan/UK Open Banking and APIs Su...
Basics: OAuth and OpenID Connect #fapisum - Japan/UK Open Banking and APIs Su...Basics: OAuth and OpenID Connect #fapisum - Japan/UK Open Banking and APIs Su...
Basics: OAuth and OpenID Connect #fapisum - Japan/UK Open Banking and APIs Su...
 
Trends in Banking APIs #fapisum - Japan/UK Open Banking and APIs Summit 2018 ...
Trends in Banking APIs #fapisum - Japan/UK Open Banking and APIs Summit 2018 ...Trends in Banking APIs #fapisum - Japan/UK Open Banking and APIs Summit 2018 ...
Trends in Banking APIs #fapisum - Japan/UK Open Banking and APIs Summit 2018 ...
 
Open Banking for Developers #fapisum - Japan/UK Open Banking and APIs Summit ...
Open Banking for Developers #fapisum - Japan/UK Open Banking and APIs Summit ...Open Banking for Developers #fapisum - Japan/UK Open Banking and APIs Summit ...
Open Banking for Developers #fapisum - Japan/UK Open Banking and APIs Summit ...
 

Recently uploaded

Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdfMeet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
Florence Consulting
 
留学学历(UoA毕业证)奥克兰大学毕业证成绩单官方原版办理
留学学历(UoA毕业证)奥克兰大学毕业证成绩单官方原版办理留学学历(UoA毕业证)奥克兰大学毕业证成绩单官方原版办理
留学学历(UoA毕业证)奥克兰大学毕业证成绩单官方原版办理
bseovas
 
留学挂科(UofM毕业证)明尼苏达大学毕业证成绩单复刻办理
留学挂科(UofM毕业证)明尼苏达大学毕业证成绩单复刻办理留学挂科(UofM毕业证)明尼苏达大学毕业证成绩单复刻办理
留学挂科(UofM毕业证)明尼苏达大学毕业证成绩单复刻办理
uehowe
 
Design Thinking NETFLIX using all techniques.pptx
Design Thinking NETFLIX using all techniques.pptxDesign Thinking NETFLIX using all techniques.pptx
Design Thinking NETFLIX using all techniques.pptx
saathvikreddy2003
 
manuaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaal
manuaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaalmanuaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaal
manuaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaal
wolfsoftcompanyco
 
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
cuobya
 
国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
zoowe
 
Gen Z and the marketplaces - let's translate their needs
Gen Z and the marketplaces - let's translate their needsGen Z and the marketplaces - let's translate their needs
Gen Z and the marketplaces - let's translate their needs
Laura Szabó
 
办理新西兰奥克兰大学毕业证学位证书范本原版一模一样
办理新西兰奥克兰大学毕业证学位证书范本原版一模一样办理新西兰奥克兰大学毕业证学位证书范本原版一模一样
办理新西兰奥克兰大学毕业证学位证书范本原版一模一样
xjq03c34
 
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
vmemo1
 
Understanding User Behavior with Google Analytics.pdf
Understanding User Behavior with Google Analytics.pdfUnderstanding User Behavior with Google Analytics.pdf
Understanding User Behavior with Google Analytics.pdf
SEO Article Boost
 
办理毕业证(NYU毕业证)纽约大学毕业证成绩单官方原版办理
办理毕业证(NYU毕业证)纽约大学毕业证成绩单官方原版办理办理毕业证(NYU毕业证)纽约大学毕业证成绩单官方原版办理
办理毕业证(NYU毕业证)纽约大学毕业证成绩单官方原版办理
uehowe
 
学位认证网(DU毕业证)迪肯大学毕业证成绩单一比一原版制作
学位认证网(DU毕业证)迪肯大学毕业证成绩单一比一原版制作学位认证网(DU毕业证)迪肯大学毕业证成绩单一比一原版制作
学位认证网(DU毕业证)迪肯大学毕业证成绩单一比一原版制作
zyfovom
 
Azure EA Sponsorship - Customer Guide.pdf
Azure EA Sponsorship - Customer Guide.pdfAzure EA Sponsorship - Customer Guide.pdf
Azure EA Sponsorship - Customer Guide.pdf
AanSulistiyo
 
Search Result Showing My Post is Now Buried
Search Result Showing My Post is Now BuriedSearch Result Showing My Post is Now Buried
Search Result Showing My Post is Now Buried
Trish Parr
 
办理毕业证(UPenn毕业证)宾夕法尼亚大学毕业证成绩单快速办理
办理毕业证(UPenn毕业证)宾夕法尼亚大学毕业证成绩单快速办理办理毕业证(UPenn毕业证)宾夕法尼亚大学毕业证成绩单快速办理
办理毕业证(UPenn毕业证)宾夕法尼亚大学毕业证成绩单快速办理
uehowe
 
存档可查的(USC毕业证)南加利福尼亚大学毕业证成绩单制做办理
存档可查的(USC毕业证)南加利福尼亚大学毕业证成绩单制做办理存档可查的(USC毕业证)南加利福尼亚大学毕业证成绩单制做办理
存档可查的(USC毕业证)南加利福尼亚大学毕业证成绩单制做办理
fovkoyb
 
制作原版1:1(Monash毕业证)莫纳什大学毕业证成绩单办理假
制作原版1:1(Monash毕业证)莫纳什大学毕业证成绩单办理假制作原版1:1(Monash毕业证)莫纳什大学毕业证成绩单办理假
制作原版1:1(Monash毕业证)莫纳什大学毕业证成绩单办理假
ukwwuq
 
[HUN][hackersuli] Red Teaming alapok 2024
[HUN][hackersuli] Red Teaming alapok 2024[HUN][hackersuli] Red Teaming alapok 2024
[HUN][hackersuli] Red Teaming alapok 2024
hackersuli
 
制作毕业证书(ANU毕业证)莫纳什大学毕业证成绩单官方原版办理
制作毕业证书(ANU毕业证)莫纳什大学毕业证成绩单官方原版办理制作毕业证书(ANU毕业证)莫纳什大学毕业证成绩单官方原版办理
制作毕业证书(ANU毕业证)莫纳什大学毕业证成绩单官方原版办理
cuobya
 

Recently uploaded (20)

Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdfMeet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
 
留学学历(UoA毕业证)奥克兰大学毕业证成绩单官方原版办理
留学学历(UoA毕业证)奥克兰大学毕业证成绩单官方原版办理留学学历(UoA毕业证)奥克兰大学毕业证成绩单官方原版办理
留学学历(UoA毕业证)奥克兰大学毕业证成绩单官方原版办理
 
留学挂科(UofM毕业证)明尼苏达大学毕业证成绩单复刻办理
留学挂科(UofM毕业证)明尼苏达大学毕业证成绩单复刻办理留学挂科(UofM毕业证)明尼苏达大学毕业证成绩单复刻办理
留学挂科(UofM毕业证)明尼苏达大学毕业证成绩单复刻办理
 
Design Thinking NETFLIX using all techniques.pptx
Design Thinking NETFLIX using all techniques.pptxDesign Thinking NETFLIX using all techniques.pptx
Design Thinking NETFLIX using all techniques.pptx
 
manuaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaal
manuaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaalmanuaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaal
manuaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaal
 
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
 
国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
 
Gen Z and the marketplaces - let's translate their needs
Gen Z and the marketplaces - let's translate their needsGen Z and the marketplaces - let's translate their needs
Gen Z and the marketplaces - let's translate their needs
 
办理新西兰奥克兰大学毕业证学位证书范本原版一模一样
办理新西兰奥克兰大学毕业证学位证书范本原版一模一样办理新西兰奥克兰大学毕业证学位证书范本原版一模一样
办理新西兰奥克兰大学毕业证学位证书范本原版一模一样
 
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
 
Understanding User Behavior with Google Analytics.pdf
Understanding User Behavior with Google Analytics.pdfUnderstanding User Behavior with Google Analytics.pdf
Understanding User Behavior with Google Analytics.pdf
 
办理毕业证(NYU毕业证)纽约大学毕业证成绩单官方原版办理
办理毕业证(NYU毕业证)纽约大学毕业证成绩单官方原版办理办理毕业证(NYU毕业证)纽约大学毕业证成绩单官方原版办理
办理毕业证(NYU毕业证)纽约大学毕业证成绩单官方原版办理
 
学位认证网(DU毕业证)迪肯大学毕业证成绩单一比一原版制作
学位认证网(DU毕业证)迪肯大学毕业证成绩单一比一原版制作学位认证网(DU毕业证)迪肯大学毕业证成绩单一比一原版制作
学位认证网(DU毕业证)迪肯大学毕业证成绩单一比一原版制作
 
Azure EA Sponsorship - Customer Guide.pdf
Azure EA Sponsorship - Customer Guide.pdfAzure EA Sponsorship - Customer Guide.pdf
Azure EA Sponsorship - Customer Guide.pdf
 
Search Result Showing My Post is Now Buried
Search Result Showing My Post is Now BuriedSearch Result Showing My Post is Now Buried
Search Result Showing My Post is Now Buried
 
办理毕业证(UPenn毕业证)宾夕法尼亚大学毕业证成绩单快速办理
办理毕业证(UPenn毕业证)宾夕法尼亚大学毕业证成绩单快速办理办理毕业证(UPenn毕业证)宾夕法尼亚大学毕业证成绩单快速办理
办理毕业证(UPenn毕业证)宾夕法尼亚大学毕业证成绩单快速办理
 
存档可查的(USC毕业证)南加利福尼亚大学毕业证成绩单制做办理
存档可查的(USC毕业证)南加利福尼亚大学毕业证成绩单制做办理存档可查的(USC毕业证)南加利福尼亚大学毕业证成绩单制做办理
存档可查的(USC毕业证)南加利福尼亚大学毕业证成绩单制做办理
 
制作原版1:1(Monash毕业证)莫纳什大学毕业证成绩单办理假
制作原版1:1(Monash毕业证)莫纳什大学毕业证成绩单办理假制作原版1:1(Monash毕业证)莫纳什大学毕业证成绩单办理假
制作原版1:1(Monash毕业证)莫纳什大学毕业证成绩单办理假
 
[HUN][hackersuli] Red Teaming alapok 2024
[HUN][hackersuli] Red Teaming alapok 2024[HUN][hackersuli] Red Teaming alapok 2024
[HUN][hackersuli] Red Teaming alapok 2024
 
制作毕业证书(ANU毕业证)莫纳什大学毕业证成绩单官方原版办理
制作毕业证书(ANU毕业证)莫纳什大学毕业证成绩单官方原版办理制作毕业证书(ANU毕业证)莫纳什大学毕业证成绩单官方原版办理
制作毕业证书(ANU毕业证)莫纳什大学毕业证成绩单官方原版办理
 

Issues towards Open Banking ecosystem and how OpenID Foundation tackles them with financial-grade APIs standard #fapisum - Japan/UK Open Banking and APIs Summit 2018 - July 25, 2018

  • 1. Copyright© Nomura Research Institute, Ltd. All rights reserved. Nat Sakimura (@_nat) Chairman of the Board, OpenID Foundation Senior Researcher, Nomura Research Institute Issues towards Open Banking ecosystem and how OpenID Foundation tackles them with financial-grade APIs standard PAST AND FUTURE OF FINANCIAL-GRADE APIS: • OpenID® is a registered trademark of OpenID Foundation. • *Unless otherwisenoted, all the photos and vector images are licensed by GraphicStocks. July 25, 2018
  • 2. Copyright© Nomura Research Institute, Ltd. All rights reserved. Do you use Personal Finance Software? What are the current problems?
  • 3. Copyright© Nomura Research Institute, Ltd. All rights reserved. When NRI started screen scraping in 2001, we thought it will be a temporally solution. 3 “There was OFX, and SAML was coming. SOAP was gaining momentum. We should be able to get out of scraping business in a few years time!”
  • 4. Copyright© Nomura Research Institute, Ltd. All rights reserved. WRONG! 4
  • 5. Copyright© Nomura Research Institute, Ltd. All rights reserved. After 15 years, we are still screen scraping. 5 (2016)
  • 6. Copyright© Nomura Research Institute, Ltd. All rights reserved. But the wind was changing. 6 (2016)
  • 7. Copyright© Nomura Research Institute, Ltd. All rights reserved. Fintech was gaining momentum (SOURCE)GoogleTrends
  • 8. Copyright© Nomura Research Institute, Ltd. All rights reserved. API started to gain attention as one of the three main component of FinTech 8 Use cases for Identity Federation API in Financial sector 1. Account Opening (incl. KYC) 2. Personal Asset Managment 3. Payment, Sending Money 4. Loan Application 5. AI assisted portfolio management (Source) Nikkei BP: Fintech Revolution P.4 (Source)Nikkei BP: FinTech Yearbook
  • 9. Copyright© Nomura Research Institute, Ltd. All rights reserved. I 9 • JSON , XML + OAuth 2.0 • INDUSTRY PUSH > US: FS-ISAC Durable Data API (Source) FS-ISACFSDDA WG OpenID FinancialAPI
  • 10. Copyright© Nomura Research Institute, Ltd. All rights reserved. REGULATORY PUSH> UK CMA Order and EU PSD2 10 (SOURCE) ODI OBWG: The Open Banking Standard (2016) JSON REST OAuth OpenID Connect
  • 11. Copyright© Nomura Research Institute, Ltd. All rights reserved. Open Data in Finance Conference 15 June, 2016 London 12 http://www.open-data-finance.com/agenda/
  • 12. Copyright© Nomura Research Institute, Ltd. All rights reserved. Now is the time! 13
  • 13. Copyright© Nomura Research Institute, Ltd. All rights reserved. but what API protection? 14 and what API request/response?
  • 14. Copyright© Nomura Research Institute, Ltd. All rights reserved. Solution Time! 15
  • 15. Copyright© Nomura Research Institute, Ltd. All rights reserved. OpenID Foundation Financial API (FAPI) WG (2016) 16
  • 16. Copyright© Nomura Research Institute, Ltd. All rights reserved. II. What is OpenID Foundation • A WG can be spun up by more than three members proposing and by the approval by the Specs Council and the Board review (2 weeks). • Specs Council is composed by the current editors of the specs and checks the overlaps with other WGs or SDOs. • The board checks that it will not cause IPR threats to the foundation. OpenID Foundation is an International Standardization Organization that specializes on Internet Identity and API protection 17
  • 17. Copyright© Nomura Research Institute, Ltd. All rights reserved. II. What is OpenID Foundation Working Together 18 OpenID FAPI (Chair) (Co-Chair)(Co-Chair) (UK OBIE Liaison) Liaison Organizations TC 68 JTC 1/SC 27/WG 5 Nat Sakimura Tony NadalinAnoop Saxena fido 2.0 WG Chair W3C Web Authn WG Chair
  • 18. Copyright© Nomura Research Institute, Ltd. All rights reserved. II. Whatis OpenID Foundation The work progresses with a weekly tele-conferences, mailing list discussions and project repository (https://bitbucket.org/openid/fapi/ ) 19 Issue Tracker Meeting notes Commit History Pull Requests Draft Text
  • 19. Copyright© Nomura Research Institute, Ltd. All rights reserved. Purpose The goal of FAPI is to provide JSON data schemas, REST APIs, and security & privacy recommendations and protocols to: 20 JSON REST OAuth OpenID Connect (SOURCE) ODI OBWG: The Open Banking Standard (2016)
  • 20. Copyright© Nomura Research Institute, Ltd. All rights reserved. Enable • applicationsto utilize the data stored in the financial account, • applicationsto interact with the financial account, and • users to control the security and privacy settings. Both commercial and investment banking account as well as insurance, and credit card accounts are to be considered. (Source) OpenID FoundationFinancial APIWG draft charter
  • 21. Copyright© Nomura Research Institute, Ltd. All rights reserved. So that we can finally get rid of password storing and screen scraping! 22
  • 22. Copyright© Nomura Research Institute, Ltd. All rights reserved. It will also help foster the FinTech companies. 23
  • 23. Copyright© Nomura Research Institute, Ltd. All rights reserved. Why OpenID Foundation? •Authors of OAuth, JWT, JWS, OpenID Connect are all here. Right People •Loyalty Free, Mutual Non-Assert, so that everyone can use it freely. Right IPR •Free to join WGs. (Sponsors welcome) •WTO TBT Compliant Process. Right Structure 24
  • 24. Copyright© Nomura Research Institute, Ltd. All rights reserved. 2 Implementer’s Drafts • Part 1: Read Only Security Profile • Part 2: Read and Write Security Profile 25 Redirect Approach Decoupled Approach Embedded Approach
  • 25. Copyright© Nomura Research Institute, Ltd. All rights reserved. OpenID Foundation Financial-grade API (FAPI) WG (2018) 26
  • 26. Copyright© Nomura Research Institute, Ltd. All rights reserved. But the EC almost requires PASSWORD SHARING 27 Redirect Approach Decoupled Approach Embedded Approach Though it is illegal in France…
  • 27. Copyright© Nomura Research Institute, Ltd. All rights reserved. To combat the situation, we have • CIBA: The Decoupled Approach 28 Redirect Approach Decoupled Approach Embedded Approach
  • 28. Copyright© Nomura Research Institute, Ltd. All rights reserved. To combat the situation, we have • CIBA: The Decoupled Approach • Manual Per App ”password” to third party applications. 29 Redirect Approach Decoupled Approach Embedded Approach
  • 29. Copyright© Nomura Research Institute, Ltd. All rights reserved. Hoping to come up with a solid draft by the end of the summer 30 Redirect Approach Decoupled Approach Embedded Approach
  • 30. Copyright© Nomura Research Institute, Ltd. All rights reserved. Join the group! https://openid.net/wg/fapi/ 31