3 ms·
You can actually make it work and still maintain pseudonymity. A primary key could register a backup key by generating a site-specific keypair, encrypting the s
by scott00 7y ago
You can actually make it work and still maintain pseudonymity. A primary key could register a backup key by generating a site-specific keypair, encrypting the site private key using the backup base public key, and then using the encrypted site private key as the key handle. The primary key would need to know the backup key's base public key, but not it's base private key, and each site would still get a unique public key and key handle.
- tialaramex 7y agoHmm. This would need a fairly substantial redesign in FIDO and might make the hardware more expensive, but in outline it sounds viable. The hardware today doesn't have a "base private key" (or public key) in the sense you mean. I feel like you're thinking about this like it's RSA, which it really isn't. RSA is weird because Encrypt and Sign are related operations, that is not how most things work. So you'd have to use key agreement plus symmetric crypto, and you'll struggle to fit everything into the current data structure sizes.
- scott00 7y agoWay late reply you'll probably never see, but I'm fairly sure it's possible with the U2F protocol and existing hardware. I simplified the algo so as not to obscure the big picture, but I have actually worked out all the details and identified hardware I think would work. (I seriously considered trying to build a business around the idea and worked through the feasibility in a lot of detail. In the end I decided it was completely feasible but a crapload of work and limited marketability.) You've correctly identified most of the tricky bits: the real algo involves key agreement plus symmetric crypto, it's a tight fit size-wise, and not all hardware has the necessary capabilities. However I think you're wrong about the conclusion. Can't say for sure though, as I didn't produce a working prototype. If you actually see this and want to discuss it in more detail you can find my email in my profile.
- deleted 7y ago[deleted]