arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Vaulted Passkeys:一种用于已认证凭证导出与导入的设备绑定方案

Vaulted Passkeys: A Device-Bound Proposal for Authenticated Credential Export and Import

Pol Henarejos

arXiv 2608.13806首次发表:更新:

AI 中文总结

本文针对设备绑定凭证的恢复缺口,提出Vaulted Passkeys架构,通过导出受保护凭证状态并恢复至后续硬件,解决硬件身份验证器的可移植性需求,原型验证了方案可行性。

AI 中文摘要

硬件身份验证器刻意抵制私钥提取,但设备更换、灾难恢复和受控迁移存在对可移植性的合法需求。现有针对设备绑定凭证的指导通常通过在故障前注册额外的身份验证器来降低恢复风险,这会创建独立的凭证注册,且需要提前存在替换硬件,属于冗余而非原始凭证的备份。本文通过在源设备可用时导出受保护的凭证状态并将其恢复到后续获取的硬件中来解决由此产生的恢复缺口,无需克隆完整的身份验证器,也无需将明文私钥暴露给常规桌面软件。我们提出Vaulted Passkeys,这是一种设备绑定架构,其中随机256位的Kvault通过HKDF分离的密钥和四个显式AEAD配置文件保护已认证的PKV1凭证信封。该设计将注册与导出/导入分离,所需的vault与可选身份分离。我们贡献了角色分离的系统模型、线格式、威胁分析、实现映射和可证伪的评估计划。原型证明了可行性,但既不是正式的安全证明,也不是最终标准提案。

英文摘要

Hardware authenticators deliberately resist private-key extraction, yet replacement, disaster recovery, and controlled migration create a legitimate need for portability. Existing guidance for device-bound credentials commonly reduces recovery risk by registering an additional authenticator before failure. That creates an independent credential registration and requires replacement hardware to exist in advance; it is redundancy, not a backup of the original credential. This paper addresses the resulting recovery gap by exporting protected credential state while the source is available and restoring it to hardware acquired later, without cloning a complete authenticator or exposing plaintext private keys to routine desktop software. We propose Vaulted Passkeys, a device-bound architecture in which a random 256-bit Kvault protects authenticated PKV1 credential envelopes through HKDF-separated keys and four explicit AEAD profiles. The design separates enrollment from export/import and the required vault from optional identity. We contribute a role-separated system model, wire format, threat analysis, implementation mapping, and falsifiable evaluation plan. The prototype demonstrates feasibility but is neither a formal security proof nor a proposed final standard.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑