3 ms·
You sign up directly with the relying party and are authenticating to a hardware device which then OKs you to the relying party. Each relying party gets a diffe
by scott00 4y ago
You sign up directly with the relying party and are authenticating to a hardware device which then OKs you to the relying party. Each relying party gets a different public key. The corresponding private keys can be stored inside the secure enclave (this setup is called resident keys), or they can be stored in a "key handle" that the relying party stores and provides every time you attempt a login. The key handle would contain the service-specific private key encrypted with a key held inside the secure enclave.
- lifeisstillgood 4y agoI have not heard of this key handle before - is there any docs on it? Oh wait, example.com sends me a encrypted key, that I decrypt and then use? That sounds ... odd. I mean, why not just keep the same encrypted data on my local phone ? The attack surface seems much smaller.
- scott00 4y agoThe U2F spec https://fidoalliance.org/specs/fido-u2f-v1.2-ps-20170411/fido-u2f-overview-v1.2-ps-20170411.html https://fidoalliance.org/specs/fido-u2f-v1.2-ps-20170411/fid... has a clear description in the "Allowing for Inexpensive U2F Devices" section. For webauthn, they don't use key handle terminology anymore, but the same fuctionality is provided by the "Credential ID": https://www.w3.org/TR/webauthn-2/#credential-id https://www.w3.org/TR/webauthn-2/#credential-id