• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Our Services
  • Contact Us
  • Newsletter
  • Top Nav Social Icons

Mobile ID World

Mobile ID World

Identification Revolution

  • Mobile ID
    • What Is Mobile ID?
    • Identity Associations
    • Premier Partners
    • FAQ
  • News
  • Solutions
    • Behavioral
    • Facial Recognition
    • Fingerprint Biometrics
    • Iris Biometrics
    • Second Factor
    • Smart Cards
    • Smartphones
    • Vital
    • Voice
    • Wearable Tech
    • Other
  • Applications
    • Access Control
    • Cloud Technology
    • Commerce
    • Enterprise
    • Healthcare
    • Identification
    • Internet of Things
    • Law Enforcement
    • Strong Online Authentication
  • Exclusive
    • Interviews
    • Featured Articles
    • Podcasts
  • Companies
  • Events

Yubico’s Proposed WebAuthn Protocol to Make it Easier to Replace Missing Keys

November 16, 2020

Yubico is trying to make it easier to replace a lost security key. To that end, the company has developed a new technology called “Asynchronous Remote Key Generation” (ARKG), and has pitched it to the World Wide Web Consortium (W3C) Web Authentication Working Group to ask the organization to recognize ARKG as an official protocol extension. Yubico partnered with the Surrey Centre for Cyber Security to demonstrate the cryptographic strength of the technology, and presented its findings at the ACM CCS conference on November 11.

Yubico's Proposed WebAuthn Protocol to Make it Easier to Replace Missing Keys

So how does the proposed protocol work? In plain terms, Yubico’s ARKG tech cryptographically links two security keys. One of those keys can then be used as a primary key to generate public keys on behalf of the other, which becomes the backup.

In practice, that means that the owner of a security key will create two separate public keys every time they use their primary key to create a new account. The website or service would detect that the primary key has been linked to a backup, and would create a key for (and recognize the legitimacy of) that backup even if the user does not have it on hand at the time.

If the user then loses their primary key, they would then be able to switch directly to the security key with minimal disruption. They would simply need to select the “I lost my security key option,” and the service would automatically switch to the backup key and revoke the privileges of the primary key. After that, the backup becomes the primary, and the owner can purchase (and link) a new key to that new primary to repeat the cycle.

The backup private keys are stored on the host server rather than the security key itself, which means that users can set up backups for an unlimited number of services. Yubico acknowledged that interested parties would need to develop universal standards should ARKG become an official protocol extension. They would also need to develop support services, including services that can link two keys, like the YubiKey Manager does for YubiKeys.

Yubico’s proposal would build on its support for FIDO’s WebAuthn standard, which became an official W3C standard in 2019. More recently, the company gave customers a more detailed look at its upcoming biometric security key.

Filed Under: Industry News Tagged With: 2FA, ARKG, Asynchronous Remote Key Generation, second factor devices, security keys, USB security keys, W3C, World Wide Web Consortium, Yubico, YubiKey

Related News & Articles

Tappy Shows Off Wearable Payments Tech at Money20/20 China

Senators Raise Concerns About Smart Car Security

FATF Highlights FIDO Standards in Latest Digital Identity Guidelines

Primary Sidebar

Learn About Mobile ID and Aviation

Tweets

Sponsored Links

facetec logo

FaceTec’s patented, industry-leading 3D Face Authentication software anchors digital identity, creating a chain of trust from user onboarding to ongoing authentication on all modern smart devices and webcams. FaceTec’s 3D FaceMaps™ make trusted, remote identity verification finally possible. As the only technology backed by a persistent spoof bounty program and NIST/iBeta Certified Liveness Detection, FaceTec is the global standard for Liveness and 3D Face Matching with millions of users on six continents in financial services, border security, transportation, blockchain, e-voting, social networks, online dating and more. www.facetec.com

FACEPHI is a global leader in Facial Recognition technology and in Mobile Biometrics technologies. With a strong concentration in the financial sector, FacePhi’s product is rapidly becoming a service used by banks all over the world. Its implementation doesn’t just save money, it is also a way to attract clients and build loyalty, while increasing the security of transactions for both the customer and the business. To learn more about FacePhi, visit https://www.facephi.com/en/

Recent Posts

  • NordPass Enables Biometric, TOTP-secured 2FA for Business Users
  • Mastercard Solution Certified Under UK’s Digital ID Framework
  • Transatlantic Digital Traveler Identity Project Gets High-Profile Tech Partner
  • Digital Identity Tech Demo Online Event
  • Mobile ID Comes to Another US Campus

Footer

  • About Us
  • Company Directory
  • Advertise With Us
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • Archives
  • CCPA: Do not sell my personal info.

Follow Us

Copyright © 2023 MobileIDWorld