MDOI International Journal of Multidisciplinary Studies and Innovative Researchs 110.0386/INT.2026.00360
110.0386/INT.2026.00360
Article

Security analysis of the open banking account and transaction API protocol

Paolo Modesti, Leo Freitas, Qudus Shotomiwa, Abdulaziz Almehrej 2025 International Journal of Multidisciplinary Studies and Innovative Researchs

Abstract

The Second Payment Services Directive (PSD2) of the European Union aims to create a consumer-friendly financial market by mandating secure and standardised data sharing between banking operators and third parties. Consequently, EU countries and the United Kingdom have adopted Open Banking, a standardised data-sharing API. This paper presents a formal modelling and security analysis of the UK Open Banking Standard’s APIs, with a specific focus on the Account and Transaction API protocol. Our methodology employs the extended Alice and Bob notation (AnBx) to create a formal model of the protocol, which is then verified using the OFMC symbolic model checker and the ProVerif cryptographic protocol verifier. We extend previous work by enabling verification for unlimited sessions with a strongly typed model. Additionally, we integrate our formal analysis with practical security testing of some necessary conditions to demonstrate verified security-goals in the NatWest Open Banking sandbox, evaluating mechanisms such as authorisation and authentication procedures.

Identifier Metadata

Identifier 110.0386/INT.2026.00360
Canonical mdoi:110.0386/INT.2026.00360
Resolver URL https://mdoi.org/110.0386/INT.2026.00360
Resource URL Open resource
Document URL Open document
Content Type Article
Authors Paolo Modesti, Leo Freitas, Qudus Shotomiwa, Abdulaziz Almehrej
Year 2025
Depositor International Journal of Multidisciplinary Studies and Innovative Researchs Organisation
Prefix 110.0386
Registered June 24, 2026
Updated June 24, 2026
Status Active
Visibility Public

Cite This Identifier

APA 7th Edition

Click to copy

MLA 9th Edition

Click to copy

Chicago 17th Edition

Click to copy

BibTeX

Click to copy

Persistent Identifier

mdoi:110.0386/INT.2026.00360

Click to copy

About MDOI

MDOI identifiers are permanent and unique identifiers assigned to digital objects to ensure long-term access, tracking, and referencing.

  • MDOI provides a permanent identity for digital objects.
  • Each MDOI is unique and points to one specific resource.
  • The prefix, such as 110.XXXX, identifies the registrant.
  • The suffix identifies the exact digital object.
  • MDOI remains stable even when a website URL changes.
  • It helps prevent broken links in digital publishing.
  • It makes academic and digital resources easier to find and cite.
  • MDOI supports proper tracking and management of digital content.
  • It improves the credibility and visibility of published resources.
  • MDOI ensures digital objects remain accessible, traceable, and reliable over time.
IN
Registered by International Journal of Multidisciplinary Studies and Innovative Researchs