Abstract
Modern banking—including open banking and digital car loan platforms—relies on interconnected APIs across banks, fintech’s, identity providers, credit bureaus, dealerships, and customers. Such ecosystems enable innovation (e.g., real time financial data sharing, streamlined loan origination), but also expand exposure to threats like broken authentication, authorization misconfigurations (e.g., IDOR), injection attacks, data leakage, replay attacks, DoS, and more. Profiles emerging threats across open banking and digital car loan APIs. Presents technical mitigations using OAuth 2.0, OpenID Connect, PKCE, and API Gateways. Offers a refined secure architecture combining gateways, JWT handling, MTLS, RBAC/ABAC, WAFs, encryption, and monitoring. Demonstrates how to secure a car loan API flow—from login to loan issuance—with NFT style nonces, token binding, scope enforcement, and logging. Reviews operations practices: DevSecOps, auditing, incident response, and regulatory compliance. Explores future innovations: DPoP (proof-of-possession), OAuth 2.1 updates, token binding, AI-driven threat detection, SSI, and standards-based API governance.
Cite
CITATION STYLE
Ashish Hota. (2022). Securing API Ecosystems in Digital Banking Transformation. World Journal of Advanced Engineering Technology and Sciences, 7(2), 371–378. https://doi.org/10.30574/wjaets.2022.7.2.0126
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.