<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.sakimura-oauth-tcse" target="https://datatracker.ietf.org/doc/html/draft-sakimura-oauth-tcse-03">
   <front>
      <title>OAuth Symmetric Proof of Posession for Code Extension</title>
      <author initials="N." surname="Sakimura" fullname="Nat Sakimura">
         <organization>Nomura Research Institute</organization>
      </author>
      <author initials="J." surname="Bradley" fullname="John Bradley">
         <organization>Ping Identity</organization>
      </author>
      <author initials="N." surname="Agarwal" fullname="Naveen Agarwal">
         <organization>Google</organization>
      </author>
      <date month="April" day="21" year="2014" />
      <abstract>
	 <t>   The OAuth 2.0 public client utilizing authorization code grant is
   susceptible to the code interception attack.  This specification
   describe a mechanism that acts as a control against this threat.


	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-sakimura-oauth-tcse-03" />
   
</reference>
