FeIDo: Recoverable FIDO2 Tokens Using Electronic IDs
Fabian Schwarz, Khue Do, Gunnar Heide, Lucjan Hanzlik, Christian Rossow
摘要
Two-factor authentication (2FA) mitigates the security risks of passwords as sole authentication factor. FIDO2-the de facto standard for interoperable web authentication-leverages strong, hardwarebacked second factors. However, practical challenges hinder wider FIDO2 user adoption for 2FA tokens, such as the extra costs (30 per token) or the risk of inaccessible accounts upon token loss/theft. To tackle the above challenges, we propose FeIDo, a virtual FIDO2 token that combines the security and interoperability of FIDO2 2FA authentication with the prevalence of existing eIDs (e.g., electronic passports). Our core idea is to derive FIDO2 credentials based on personally-identifying and verifiable attributes-name, date of birth, and place of birth-that we obtain from the user's eID. As these attributes do not change even for refreshed eID documents, the credentials "survive" token loss. Even though FeIDo operates on privacy-critical data, all personal data and resulting FIDO2 credentials stay unlinkable, are never leaked to third parties, and are securely managed in attestable hardware containers (e.g., SGX enclaves). In contrast to existing FIDO2 tokens, FeIDo can also derive and share verifiable meta attributes (anonymous credentials) with web services. These enable verified but pseudonymous user checks, e.g., for age verification (e.g., "is adult").
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- FIDO2 the Rescue? Platform vs. Roaming Authentication on SmartphonesLeon Würsching, Florentin Putz, Steffen Haesler, Matthias HollickCHI 2023 · 被引用 15 次
- "Make Them Change it Every Week!": A Qualitative Exploration of Online Developer Advice on Usable and Secure AuthenticationJan H. Klemmer, Marco Gutfleisch, Christian Stransky, Yasemin Acar 等CCS 2023 · 被引用 8 次
- Fast IDentity Online with Anonymous Credentials (FIDO-AC)Wei-Zhu Yeoh, Michal Kepkowski, Gunnar Heide, Dali Kaafar 等USENIX Security 2023
它引用的顶会 Paper7
- CURE: A Security Architecture with CUstomizable and Resilient EnclavesRaad Bahmani, Ferdinand Brasser, Ghada Dessouky, Patrick Jauernig 等USENIX Security 2021 · 被引用 150 次
- Is FIDO2 the Kingslayer of User Authentication? A Comparative Usability Study of FIDO2 Passwordless AuthenticationSanam Ghorbani Lyastani, Michael Schilling, Michaela Neumayr, Michael Backes 等S&P 2020 · 被引用 124 次
- simTPM: User-centric TPM for Mobile DevicesDhiman Chakraborty, Lucjan Hanzlik, Sven BugielUSENIX Security 2019 · 被引用 26 次
- On the Insecurity of SMS One-Time Password Messages against Local Attackers in Modern Mobile DevicesZeyu Lei, Yuhong Nan, Yanick Fratantonio, Antonio BianchiNDSS 2021
- SENG, the SGX-Enforcing Network Gateway: Authorizing Communication from Shielded ClientsFabian Schwarz, Christian RossowUSENIX Security 2020
相关 Paper
- Why Aren't We Using Passkeys? Obstacles Companies Face Deploying FIDO2 Passwordless AuthenticationLeona Lassak, Elleen Pan, Blase Ur, Maximilian GollaUSENIX Security 2024 · 被引用 35 次
- Asynchronous Remote Key Generation: An Analysis of Yubico's Proposal for W3C WebAuthnNick Frymann, Daniel Gardham, Franziskus Kiefer, Emil Lundberg 等CCS 2020 · 被引用 25 次
- Breaching Security Keys without Root: FIDO2 Deception Attacks via Overlays exploiting Limited Display AuthenticatorsAhmed Tanvir Mahdad, Mohammed Jubur, Nitesh SaxenaCCS 2024 · 被引用 3 次
- Token meets Wallet: Formalizing Privacy and Revocation for FIDO2Lucjan Hanzlik, Julian Loss, Benedikt WagnerS&P 2023
- Accountable authentication with privacy protection: The Larch system for universal loginEmma Dauterman, Danny Lin, Henry Corrigan-Gibbs, David MazièresOSDI 2023 · 被引用 2 次
