Fast IDentity Online with Anonymous Credentials (FIDO-AC)

05/26/2023
by   Wei-Zhu Yeoh, et al.
0

Web authentication is a critical component of today's Internet and the digital world we interact with. The FIDO2 protocol enables users to leverage common devices to easily authenticate to online services in both mobile and desktop environments following the passwordless authentication approach based on cryptography and biometric verification. However, there is little to no connection between the authentication process and users' attributes. More specifically, the FIDO protocol does not specify methods that could be used to combine trusted attributes with the FIDO authentication process generically and allows users to disclose them to the relying party arbitrarily. In essence, applications requiring attributes verification (e.g. age or expiry date of a driver's license, etc.) still rely on ad-hoc approaches, not satisfying the data minimization principle and not allowing the user to vet the disclosed data. A primary recent example is the data breach on Singtel Optus, one of the major telecommunications providers in Australia, where very personal and sensitive data (e.g. passport numbers) were leaked. This paper introduces FIDO-AC, a novel framework that combines the FIDO2 authentication process with the user's digital and non-shareable identity. We show how to instantiate this framework using off-the-shelf FIDO tokens and any electronic identity document, e.g., the ICAO biometric passport (ePassport). We demonstrate the practicality of our approach by evaluating a prototype implementation of the FIDO-AC system.

READ FULL TEXT
research
05/20/2021

Combining PIN and Biometric Identifications as Enhancement to User Authentication in Internet Banking

Internet banking (IB) continues to face security concerns arising from i...
research
12/30/2017

Why the Equifax Breach Should Not Have Mattered

Data security, which is concerned with the prevention of unauthorized ac...
research
11/20/2017

The Horcrux Protocol: A Method for Decentralized Biometric-based Self-sovereign Identity

Most user authentication methods and identity proving systems rely on a ...
research
03/07/2019

Dynamic Anonymized Evaluation for Behavioral Continuous Authentication

Emerging technology demands reliable authentication mechanisms, particul...
research
10/08/2022

Study and security analysis of the Spanish identity card

The National Identity Document is a fundamental piece of documentation f...
research
09/06/2021

A Novel Multimodal Biometric Authentication System using Machine Learning and Blockchain

Traditional authentication systems that rely on simple passwords, PIN nu...
research
06/16/2020

A Large-scale Empirical Analysis of Browser Fingerprints Properties for Web Authentication

Modern browsers give access to several attributes that can be collected ...

Please sign up or login with your details

Forgot password? Click here to reset