Securing API Ecosystems in Digital Banking Transformation

  • Ashish Hota
N/ACitations
Citations of this article
8Readers
Mendeley users who have this article in their library.

Abstract

Modern banking—including open banking and digital car loan platforms—relies on interconnected APIs across banks, fintech’s, identity providers, credit bureaus, dealerships, and customers. Such ecosystems enable innovation (e.g., real time financial data sharing, streamlined loan origination), but also expand exposure to threats like broken authentication, authorization misconfigurations (e.g., IDOR), injection attacks, data leakage, replay attacks, DoS, and more. Profiles emerging threats across open banking and digital car loan APIs. Presents technical mitigations using OAuth 2.0, OpenID Connect, PKCE, and API Gateways. Offers a refined secure architecture combining gateways, JWT handling, MTLS, RBAC/ABAC, WAFs, encryption, and monitoring. Demonstrates how to secure a car loan API flow—from login to loan issuance—with NFT style nonces, token binding, scope enforcement, and logging. Reviews operations practices: DevSecOps, auditing, incident response, and regulatory compliance. Explores future innovations: DPoP (proof-of-possession), OAuth 2.1 updates, token binding, AI-driven threat detection, SSI, and standards-based API governance.

Cite

CITATION STYLE

APA

Ashish Hota. (2022). Securing API Ecosystems in Digital Banking Transformation. World Journal of Advanced Engineering Technology and Sciences, 7(2), 371–378. https://doi.org/10.30574/wjaets.2022.7.2.0126

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free