Beyond the Trust Boundary: A Critical Reassessment of the FIDO2 Threat Model

📅 2026-09-03
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文重新评估了FIDO2威胁模型,通过分析八种攻击向量展示了其在实际部署中的安全假设可能不成立,并指出需采取多层次缓解措施以保障安全。
📝 Abstract
FIDO2/WebAuthn has been widely deployed as a phishing-resistant authentication scheme. Because FIDO2 relies on public-key cryptography and hardware-backed authenticators, its security is often assumed to be guaranteed by design, provided that the cryptographic implementation is correct. In this work, we critically reassess the FIDO2 threat model and show that several commonly assumed security properties do not hold under realistic deployment conditions. We extend the threat model beyond the cryptographic layer to examine eight attack vectors across the FIDO2 stack: malicious browser extensions, platform-handler malware, passive sniffing, virtual device drivers, CTAP2-specific malware, USB/hardware implants, malicious USB hubs/docks/extenders, and NFC relay attacks. Our analysis shows that FIDO2 depends on environmental assumptions that may not hold in practice. We demonstrate how AAGUID and timing information can enable user profiling and targeted attacks, and how compromise of the browser, operating system, or hardware can undermine FIDO2 security even when the underlying cryptographic primitives remain uncompromised. We further show that attack chains spanning multiple layers can bypass the intended security guarantees of FIDO2. These findings indicate that the primary weakness in a FIDO2 deployment is often not the cryptographic layer, but the surrounding trusted environment. We also examine how these attack vectors can undermine device attestation by targeting the FIDO Metadata Service (MDS3), which serves as a root of trust for authenticator metadata. Finally, we characterize the attacks according to privilege, skill, and resource requirements. We conclude that effective FIDO2 security requires layered mitigations covering the browser, operating system, hardware, protocol stack, and metadata infrastructure.
Problem

Research questions and friction points this paper is trying to address.

FIDO2
WebAuthn
threat model
security assumptions
attack vectors
Innovation

Methods, ideas, or system contributions that make the work stand out.

threat model reassessment
attack vectors
environmental assumptions
user profiling
layered mitigations
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
A
Aditya Mitra
CyberMACS, Kadir Has University; DigitalFortress Private Limited & Indominus Labs Private Limited
K
Kolluru Sai Abhiram
Centre of Excellence, Cyber Security, School of Computer Science and Engineering, VIT-AP University, India; DigitalFortress Private Limited
S
Sibi Chakkaravarthy Sethuraman
Centre of Excellence, Artificial Intelligence & Robotics (AIR), School of Computer Science and Engineering, VIT-AP University, India; DigitalFortress Private Limited & Indominus Labs Private Limited
A
Anitha S
Centre of Excellence, Artificial Intelligence and Robotics (AIR), School of Electronics and Communication Engineering, VIT-AP University, India; DigitalFortress Private Limited