A pragmatic look at "IAM for AI," showing how familiar tools like OAuth, and emerging work such as CIMD and ID-JAG, can meet AI’s needs without inciting revolution.
This session shares real world lessons learnt and gaps identified from using SPIFFE, OAuth 2.0, and mTLS to automate identity lifecycle management, OAuth client registration, sender-constrain tokens and eradicate secrets.
This team has been implementing and testing VC specification drafts for the last 3-4 years. Come to hear their story about lessons learned and challenges encountered, as I present results from interviewing five individuals with various backgrounds.
Integrating the OIDF conformance suite into GitHub CI sounded easy—until it wasn’t. This talk shares real-world failures, CI-specific pitfalls, and hard-won lessons on turning flaky red tests into meaningful conformance signals.
University of Stuttgart security researchers discovered an actionable security vulnerability in mid-2024 in the audience values used for JWT Client Authentication. This presentation will delve into the details of what happened next and why.
We assemble to plan the unconference slots in the afternoon.
Unconference Sessions
Unconference Sessions
Reception at Lancaster University Leipzig's Rooftop Terrace
A welcome from our main sponsor, Authlete
Discuss an extension to SD-JWTs(RFC9901) to support further delegation from the Holder to a Delegate Holder. This is done by allowing the KB-JWT to also be an SD-JWT, optionally with its own Key Binding.
eIDAS2.0 framework expansion to include ID holders' affiliated autonomous systems could underpin transparency & accountability measures as we integrate Agentic & Embodied Systems into current sectors like banking, logistics, insurance & taxation.
In this talk, we will introduce the two emerging OAuth technologies related to workload identity, namely Transaction Tokens and SPIFFE Client Authentication, and demonstrate them working together.
Extending the definition of the hash algorithm defined in SD-JWT allows zero knowledge proofs to be used on properties. Here we show how sigma protocols with Pedersen commitments could be added with almost no (structural) modifications to RFC-9901.
DPoP adoption is accelerating, but some use-cases are challenging the specification's initial design assumptions and choices. In this session, we will discuss some of the friction points we have experienced, and propose potential solutions.
We assemble to plan the unconference slots in the afternoon.
Unconference Sessions
Unconference Sessions
City Tour
Dinner at Ratskeller
We give an overview of formal methods, including mechanized approaches, and present our prior and ongoing work on finding attacks and carrying out proofs for authentication and authorization protocols.
This session explores the possibility of applying the concept of "Elicitation in URL mode", introduced in MCP, to the OAuth world to make cross-domain multi-hop API calls secure and compares it with the existing token-exchange based method.
The rediscovered Browser Swapping attack threatens modern OAuth 2 and OpenID Connect deployments. This talk demonstrates how attackers exploit the vulnerability and how you can protect your systems in the short and long term.
Building the EUDI Wallet ecosystem means deploying production systems on evolving drafts. This talk shares lessons from OID4VC, interoperability gaps, and the security challenges that arise when standards change faster than deployments.
This talk explains why AI agents should be treated as workloads, not magical new identity subjects. It shows how existing standards such as SPIFFE, WIMSE, OAuth 2.0, and SSF applies to agent systems, while also identifying gaps.
Session fixation attacks affect certain OAuth-related standards but remain unexamined in mainstream OAuth 2.0 deployments. We identify 40+ vulnerable vendors in "connector ecosystems" for app integration and agentic AI, and propose mitigations.
Inmor is an open-source Trust Anchor implementation for OpenID Federation 1.0, it is being developed with keeping performance and easy maintenance in mind, with Rust and Python, splitting the performance and ease of use for operators.
Quant-ID is a project funded by the BMFTR for researching quantum entropy and post-quantum cryptography in OAuth and OIDC, including analyses and implementations by four partner organizations. We would like to share some results with the community.
We assemble to plan the unconference slots in the afternoon.
Unconference Sessions
Unconference Sessions
(not an actual ceremony)