Digital Forensic Artifacts of FIDO2 Passkeys in Windows 11


연구 분야: Strategies



학회: ARES '24: Proceedings of the 19th International Conference on Availability, Reliability and Security


초록

FIDO2’s passkey aims to provide a passwordless authentication solution. It relies on two main protocols – WebAuthn and CTAP2 – for authentication in computer systems, relieving users from the burden of using and managing passwords. FIDO2’s passkey leverages asymmetric cryptography to create a unique public/private key pair for website authentication. While the public key is kept at the website/application, the private key is created and stored on the authentication device designated as the authenticator. The authenticator can be the computer itself – same-device signing –, or another device – cross-device signing –, such as an Android smartphone that connects to the computer through a short-range communication method (NFC, Bluetooth). Authentication is performed by the user unlocking the authenticator device. In this paper, we report on the digital forensic artifacts left on Windows 11 systems by registering and using passkeys to authenticate on websites. We show that digital artifacts are created in Windows Registry and Windows Event Log. These artifacts enable the precise dating and timing of passkey registration, as well as the usage and identification of the websites on which they have been activated and utilized. We also identify digital artifacts created when Android smartphones are registered and used as authenticators in a Windows system. This can prove useful in detecting the existence of smartphones linked to a given individual.


Author Profile
Patrício Domingues

School of Technology and Management Polytechnic Institute of Leiria Portugal and Instituto de Telecomunicações Portugal

Andorra
Author Profile
Miguel Frade

School of Technology and Management Polytechnic Institute of Leiria Portugal and Computer Science and Communication Research Centre Portugal

Andorra
Author Profile
Miguel Cerdeira Negrão

School of Technology and Management Polytechnic Institute of Leiria Portugal and Computer Science and Communication Research Centre Portugal

Andorra

📄 논문 정보

발행 연도 2024년
인용수 1
출판 국가 Andorra
사이트 ACM
좋아요 수 0

연관 논문 목록 (49건)