Web authentication is a critical component of today's Internet and the digital world we interact with. The FIDO2 protocol enables users to leverage common devices to easily authenticate to online services in both mobile and desktop environments following the passwordless authentication approach based on cryptography and biometric verification. However, there is little to no connection between the authentication process and users' attributes. More specifically, the FIDO protocol does not specify methods that could be used to combine trusted attributes with the FIDO authentication process generically and allows users to disclose them to the relying party arbitrarily. In essence, applications requiring attributes verification (e.g. age or expiry date of a driver's license, etc.) still rely on ad-hoc approaches, not satisfying the data minimization principle and not allowing the user to vet the disclosed data. A primary recent example is the data breach on Singtel Optus, one of the major telecommunications providers in Australia, where very personal and sensitive data (e.g. passport numbers) were leaked. This paper introduces FIDO-AC, a novel framework that combines the FIDO2 authentication process with the user's digital and non-shareable identity. We show how to instantiate this framework using off-the-shelf FIDO tokens and any electronic identity document, e.g., the ICAO biometric passport (ePassport). We demonstrate the practicality of our approach by evaluating a prototype implementation of the FIDO-AC system.
翻译:网络认证是当今互联网及我们与之交互的数字世界的关键组成部分。FIDO2协议使用户能够借助常见设备,在移动和桌面环境中基于密码学和生物特征验证的无密码认证方法轻松完成在线服务认证。然而,认证过程与用户属性之间几乎没有任何关联。具体而言,FIDO协议未指定可普遍用于将可信属性与FIDO认证过程相结合的方法,也未允许用户任意向依赖方披露这些属性。实际上,需要属性验证(例如驾照的年龄或有效期等)的应用仍依赖临时性方法,这些方法不满足数据最小化原则,且无法让用户对所披露数据进行审查。近期的一个典型案例是澳大利亚主要电信供应商之一Singtel Optus的数据泄露事件,其中非常个人化和敏感的数据(如护照号码)遭到泄露。本文提出FIDO-AC这一新型框架,它将FIDO2认证过程与用户不可共享的数字身份相结合。我们展示了如何利用现成的FIDO令牌和任意电子身份文档(例如国际民航组织生物特征护照ePassport)来实例化该框架。通过评估FIDO-AC系统的原型实现,我们证明了该方法的实用性。