{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:TO46DSL3VN3KJDHAKJDS4CB6C5","short_pith_number":"pith:TO46DSL3","canonical_record":{"source":{"id":"1901.11520","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-01-31T18:42:38Z","cross_cats_sorted":[],"title_canon_sha256":"62d426df21f6774c1eb2bbf33bb35843c829c950a3c1a0eb810699f0be18cb0f","abstract_canon_sha256":"ba8065578d6f6ca808c63372718f404e1e5fdd072071fc95e2f6f081e758b98b"},"schema_version":"1.0"},"canonical_sha256":"9bb9e1c97bab76a48ce052472e083e174149aaf06628b8b5d093631cc6feba08","source":{"kind":"arxiv","id":"1901.11520","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1901.11520","created_at":"2026-05-17T23:55:01Z"},{"alias_kind":"arxiv_version","alias_value":"1901.11520v1","created_at":"2026-05-17T23:55:01Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1901.11520","created_at":"2026-05-17T23:55:01Z"},{"alias_kind":"pith_short_12","alias_value":"TO46DSL3VN3K","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_16","alias_value":"TO46DSL3VN3KJDHA","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_8","alias_value":"TO46DSL3","created_at":"2026-05-18T12:33:30Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:TO46DSL3VN3KJDHAKJDS4CB6C5","target":"record","payload":{"canonical_record":{"source":{"id":"1901.11520","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-01-31T18:42:38Z","cross_cats_sorted":[],"title_canon_sha256":"62d426df21f6774c1eb2bbf33bb35843c829c950a3c1a0eb810699f0be18cb0f","abstract_canon_sha256":"ba8065578d6f6ca808c63372718f404e1e5fdd072071fc95e2f6f081e758b98b"},"schema_version":"1.0"},"canonical_sha256":"9bb9e1c97bab76a48ce052472e083e174149aaf06628b8b5d093631cc6feba08","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:55:01.672259Z","signature_b64":"n+GQWCWySdT6Ii7F8hctk7A0s1jAPr5Ckf56cSzy+RP7osBuNBC1c8B5U5XPDhSp39JVYsDpYAjf1TxhwrdKDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9bb9e1c97bab76a48ce052472e083e174149aaf06628b8b5d093631cc6feba08","last_reissued_at":"2026-05-17T23:55:01.671771Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:55:01.671771Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1901.11520","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:55:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"laSwzPRtwvAcfHJ5QqUUejxqw+HMi1vNF++CQgjyd4+HGZcrVliEpKA8YceWLidD75zLtHCej/hEg3PmKZv4DQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-23T14:55:45.118663Z"},"content_sha256":"9e192eb0a7e6780b555953ca230cea03dd880f4ec7e50569a3c7c2e18abc4e13","schema_version":"1.0","event_id":"sha256:9e192eb0a7e6780b555953ca230cea03dd880f4ec7e50569a3c7c2e18abc4e13"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:TO46DSL3VN3KJDHAKJDS4CB6C5","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"An Extensive Formal Security Analysis of the OpenID Financial-grade API","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Daniel Fett, Pedram Hosseyni, Ralf Kuesters","submitted_at":"2019-01-31T18:42:38Z","abstract_excerpt":"Forced by regulations and industry demand, banks worldwide are working to open their customers' online banking accounts to third-party services via web-based APIs. By using these so-called Open Banking APIs, third-party companies, such as FinTechs, are able to read information about and initiate payments from their users' bank accounts.\n  One of the most promising standards in this segment is the OpenID Financial-grade API (FAPI), currently under development in an open process by the OpenID Foundation and backed by large industry partners. The FAPI is a profile of OAuth 2.0 designed for high-r"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1901.11520","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:55:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"zyJ+dpvBKnkTjiQ3eI+OarXh6gfLFFj5M3CLNbrs5Uazb64dRsBktaG32ERCVQvN/qApTADq7YituogOttihDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-23T14:55:45.119227Z"},"content_sha256":"d2da94a8082eb00d9bdb9ed22c22bc1f21526e67027d7dcedcac3be9fef4a8c8","schema_version":"1.0","event_id":"sha256:d2da94a8082eb00d9bdb9ed22c22bc1f21526e67027d7dcedcac3be9fef4a8c8"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/TO46DSL3VN3KJDHAKJDS4CB6C5/bundle.json","state_url":"https://pith.science/pith/TO46DSL3VN3KJDHAKJDS4CB6C5/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/TO46DSL3VN3KJDHAKJDS4CB6C5/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-23T14:55:45Z","links":{"resolver":"https://pith.science/pith/TO46DSL3VN3KJDHAKJDS4CB6C5","bundle":"https://pith.science/pith/TO46DSL3VN3KJDHAKJDS4CB6C5/bundle.json","state":"https://pith.science/pith/TO46DSL3VN3KJDHAKJDS4CB6C5/state.json","well_known_bundle":"https://pith.science/.well-known/pith/TO46DSL3VN3KJDHAKJDS4CB6C5/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:TO46DSL3VN3KJDHAKJDS4CB6C5","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"ba8065578d6f6ca808c63372718f404e1e5fdd072071fc95e2f6f081e758b98b","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-01-31T18:42:38Z","title_canon_sha256":"62d426df21f6774c1eb2bbf33bb35843c829c950a3c1a0eb810699f0be18cb0f"},"schema_version":"1.0","source":{"id":"1901.11520","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1901.11520","created_at":"2026-05-17T23:55:01Z"},{"alias_kind":"arxiv_version","alias_value":"1901.11520v1","created_at":"2026-05-17T23:55:01Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1901.11520","created_at":"2026-05-17T23:55:01Z"},{"alias_kind":"pith_short_12","alias_value":"TO46DSL3VN3K","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_16","alias_value":"TO46DSL3VN3KJDHA","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_8","alias_value":"TO46DSL3","created_at":"2026-05-18T12:33:30Z"}],"graph_snapshots":[{"event_id":"sha256:d2da94a8082eb00d9bdb9ed22c22bc1f21526e67027d7dcedcac3be9fef4a8c8","target":"graph","created_at":"2026-05-17T23:55:01Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Forced by regulations and industry demand, banks worldwide are working to open their customers' online banking accounts to third-party services via web-based APIs. By using these so-called Open Banking APIs, third-party companies, such as FinTechs, are able to read information about and initiate payments from their users' bank accounts.\n  One of the most promising standards in this segment is the OpenID Financial-grade API (FAPI), currently under development in an open process by the OpenID Foundation and backed by large industry partners. The FAPI is a profile of OAuth 2.0 designed for high-r","authors_text":"Daniel Fett, Pedram Hosseyni, Ralf Kuesters","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-01-31T18:42:38Z","title":"An Extensive Formal Security Analysis of the OpenID Financial-grade API"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1901.11520","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:9e192eb0a7e6780b555953ca230cea03dd880f4ec7e50569a3c7c2e18abc4e13","target":"record","created_at":"2026-05-17T23:55:01Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"ba8065578d6f6ca808c63372718f404e1e5fdd072071fc95e2f6f081e758b98b","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-01-31T18:42:38Z","title_canon_sha256":"62d426df21f6774c1eb2bbf33bb35843c829c950a3c1a0eb810699f0be18cb0f"},"schema_version":"1.0","source":{"id":"1901.11520","kind":"arxiv","version":1}},"canonical_sha256":"9bb9e1c97bab76a48ce052472e083e174149aaf06628b8b5d093631cc6feba08","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"9bb9e1c97bab76a48ce052472e083e174149aaf06628b8b5d093631cc6feba08","first_computed_at":"2026-05-17T23:55:01.671771Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:55:01.671771Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"n+GQWCWySdT6Ii7F8hctk7A0s1jAPr5Ckf56cSzy+RP7osBuNBC1c8B5U5XPDhSp39JVYsDpYAjf1TxhwrdKDg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:55:01.672259Z","signed_message":"canonical_sha256_bytes"},"source_id":"1901.11520","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:9e192eb0a7e6780b555953ca230cea03dd880f4ec7e50569a3c7c2e18abc4e13","sha256:d2da94a8082eb00d9bdb9ed22c22bc1f21526e67027d7dcedcac3be9fef4a8c8"],"state_sha256":"c81d1fa234c43a67ffd395448fd22d2f5c3b7633e7269ebe8291a03d5cc06c46"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"OTw1Wwhe41dCmWGuVrArLcpwalyBoeGv5PX5DIxJ9e5fGhNY0kSk01moRaB4sBmas4fJDcD4DwF6ZqyY6HpNBQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-23T14:55:45.122548Z","bundle_sha256":"2a1d550926b20749e3e4c57148cd913b7b824fac8521294ce18a64942a5a3629"}}