arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.03789cs.CRcs.ET

超越信任边界:对FIDO2威胁模型的关键重新评估

Beyond the Trust Boundary: A Critical Reassessment of the FIDO2 Threat Model

  • CyberMACS
  • Kadir Has University(卡迪尔·哈斯大学)
  • DigitalFortress Private Limited(DigitalFortress私人有限公司)
  • Indominus Labs Private Limited(Indominus Labs私人有限公司)
  • Centre of Excellence, Cyber Security(网络安全卓越中心)
  • School of Computer Science and Engineering(计算机科学与工程学院)
  • VIT-AP University, India(印度VIT-AP大学)
  • Centre of Excellence, Artificial Intelligence & Robotics (AIR)(人工智能与机器人(AIR)卓越中心)
  • School of Electronics and Communication Engineering(电子与通信工程学院)
  • Centre of Excellence, Artificial Intelligence and Robotics (AIR)(人工智能与机器人(AIR)卓越中心)

机构由 AI 辅助整理,请以论文原文为准。

Aditya Mitra, Kolluru Sai Abhiram, Sibi Chakkaravarthy Sethuraman, Anitha S

AI总结:

本研究重新评估FIDO2威胁模型,发现其依赖的环境假设在实际部署中不成立,8种攻击向量可通过跨层攻击链绕过安全保障,需多层面分层缓解措施保障FIDO2安全。

AI中文摘要:

FIDO2/WebAuthn作为抗网络钓鱼的认证方案已被广泛部署。由于FIDO2依赖公钥密码学和硬件支持的验证器,只要密码实现正确,其安全性通常被认为是设计层面的保障。本研究对FIDO2威胁模型进行了关键重新评估,表明在实际部署条件下,若干普遍认为的安全属性并不成立。我们将威胁模型扩展到密码层之外,研究了FIDO2栈中的8种攻击向量:恶意浏览器扩展、平台处理程序恶意软件、被动嗅探、虚拟设备驱动程序、CTAP2特定恶意软件、USB/硬件植入物、恶意USB集线器/扩展坞/扩展器以及NFC中继攻击。分析显示,FIDO2依赖的环境假设在实践中可能不成立。我们论证了AAGUID和时序信息如何实现用户画像和定向攻击,以及即使底层密码原语未被破坏,浏览器、操作系统或硬件的入侵如何破坏FIDO2的安全性。我们进一步表明,跨多层的攻击链可以绕过FIDO2预期的安全保障。这些发现表明,FIDO2部署中的主要弱点通常不是密码层,而是周围的可信环境。我们还通过针对作为验证器元数据信任根的FIDO元数据服务(MDS3),研究这些攻击向量如何破坏设备认证。最后,我们根据权限、技能和资源需求对攻击进行了特征描述。我们得出结论,有效的FIDO2安全需要覆盖浏览器、操作系统、硬件、协议栈和元数据基础设施的分层缓解措施。

英文摘要:

FIDO2/WebAuthn has been widely deployed as a phishing-resistant authentication scheme. Because FIDO2 relies on public-key cryptography and hardware-backed authenticators, its security is often assumed to be guaranteed by design, provided that the cryptographic implementation is correct. In this work, we critically reassess the FIDO2 threat model and show that several commonly assumed security properties do not hold under realistic deployment conditions. We extend the threat model beyond the cryptographic layer to examine eight attack vectors across the FIDO2 stack: malicious browser extensions, platform-handler malware, passive sniffing, virtual device drivers, CTAP2-specific malware, USB/hardware implants, malicious USB hubs/docks/extenders, and NFC relay attacks. Our analysis shows that FIDO2 depends on environmental assumptions that may not hold in practice. We demonstrate how AAGUID and timing information can enable user profiling and targeted attacks, and how compromise of the browser, operating system, or hardware can undermine FIDO2 security even when the underlying cryptographic primitives remain uncompromised. We further show that attack chains spanning multiple layers can bypass the intended security guarantees of FIDO2. These findings indicate that the primary weakness in a FIDO2 deployment is often not the cryptographic layer, but the surrounding trusted environment. We also examine how these attack vectors can undermine device attestation by targeting the FIDO Metadata Service (MDS3), which serves as a root of trust for authenticator metadata. Finally, we characterize the attacks according to privilege, skill, and resource requirements. We conclude that effective FIDO2 security requires layered mitigations covering the browser, operating system, hardware, protocol stack, and metadata infrastructure.

↑