Repository logo
 
Publication

Digital Forensic Artifacts of FIDO2 Passkeys in Windows 11

dc.contributor.authorDomingues, Patricio
dc.contributor.authorFrade, Miguel
dc.contributor.authorNegrão, Miguel
dc.date.accessioned2024-08-01T11:19:44Z
dc.date.available2024-08-01T11:19:44Z
dc.date.issued2024-07-30
dc.date.updated2024-07-26T10:27:01Z
dc.descriptionCCS CONCEPTS: Security and privacy → Systems security; Applied computing → Evidence collection, storage and analysis.pt_PT
dc.descriptionThis research was partially supported under the UIDB 04524/2020 project by FCT/MCTES and EU funds under the UIDB/EEA 50008/2020 project and the LA/P/0109/2020 project. The authors thank the anonymous reviewers for their insightful comments and suggestions.pt_PT
dc.description.abstractFIDO2’s passkey aims to provide a passwordless authentication solution. It relies on two main protocols – WebAuthn and CTAP2 – for authentication in computer systems, relieving users from the burden of using and managing passwords. FIDO2’s passkey leverages asymmetric cryptography to create a unique public/private key pair for website authentication. While the public key is kept at the website/application, the private key is created and stored on the authentication device designated as the authenticator. The authenticator can be the computer itself – same-device signing –, or another device – cross-device signing –, such as an Android smartphone that connects to the computer through a short-range communication method (NFC, Bluetooth). Authentication is performed by the user unlocking the authenticator device. In this paper, we report on the digital forensic artifacts left on Windows 11 systems by registering and using passkeys to authenticate on websites. We show that digital artifacts are created in Windows Registry and Windows Event Log. These artifacts enable the precise dating and timing of passkey registration, as well as the usage and identification of the websites on which they have been activated and utilized. We also identify digital artifacts created when Android smartphones are registered and used as authenticators in a Windows system. This can prove useful in detecting the existence of smartphones linked to a given individual.pt_PT
dc.description.versioninfo:eu-repo/semantics/acceptedVersionpt_PT
dc.identifier.citationDomingues, P., Frade, M., & Negrão, M. (2024). Digital Forensic Artifacts of FIDO2 Passkeys in Windows 11. In Availability, Reliability and Security (ARES 2024): The 19th International Conference on Availability, Reliability and Security, 30 July 2024 - 2 August 2024 (Issue 34). Association for Computing Machinery (ACM). https://doi.org/10.1145/3664476.3664496pt_PT
dc.identifier.doihttps://doi.org/10.1145/3664476.3664496pt_PT
dc.identifier.isbn979-8-4007-1718-5
dc.identifier.slugcv-prod-4120421
dc.identifier.urihttp://hdl.handle.net/10400.8/9877
dc.language.isoengpt_PT
dc.peerreviewedyespt_PT
dc.publisherAssociation for Computing Machinery (ACM)pt_PT
dc.relationResearch Center in Informatics and Communications
dc.relationInstituto de Telecomunicações
dc.relationInstitute of Telecommunications
dc.relation.publisherversionhttps://dl.acm.org/doi/10.1145/3664476.3664496pt_PT
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/pt_PT
dc.subjectDigital Forensicspt_PT
dc.subjectPasskeyspt_PT
dc.subjectFIDO2pt_PT
dc.subjectWindows 11pt_PT
dc.subjectWindows Registrypt_PT
dc.subjectWindows Event Logpt_PT
dc.titleDigital Forensic Artifacts of FIDO2 Passkeys in Windows 11pt_PT
dc.typeconference object
dspace.entity.typePublication
oaire.awardTitleResearch Center in Informatics and Communications
oaire.awardTitleInstituto de Telecomunicações
oaire.awardTitleInstitute of Telecommunications
oaire.awardURIinfo:eu-repo/grantAgreement/FCT/6817 - DCRRNI ID/UIDB%2F04524%2F2020/PT
oaire.awardURIinfo:eu-repo/grantAgreement/FCT/6817 - DCRRNI ID/UIDB%2F50008%2F2020/PT
oaire.awardURIinfo:eu-repo/grantAgreement/FCT/6817 - DCRRNI ID/LA%2FP%2F0109%2F2020/PT
oaire.citation.conferencePlaceACM, New York, NY, USApt_PT
oaire.citation.endPage10pt_PT
oaire.citation.issue34pt_PT
oaire.citation.startPage1pt_PT
oaire.citation.titleAvailability, Reliability and Security (ARES 2024): The 19th International Conference on Availability, Reliability and Security, July 30 - August 2, 2024, Vienna, Austria.pt_PT
oaire.fundingStream6817 - DCRRNI ID
oaire.fundingStream6817 - DCRRNI ID
oaire.fundingStream6817 - DCRRNI ID
person.familyNameDomingues
person.familyNameFrade
person.familyNameCerdeira Negrão
person.givenNamePatrício
person.givenNameMiguel
person.givenNameMiguel
person.identifier1234758
person.identifier.ciencia-idAA15-6185-C477
person.identifier.ciencia-idA512-9B28-1CEC
person.identifier.ciencia-id3B1A-36E2-B96B
person.identifier.orcid0000-0002-6207-6292
person.identifier.orcid0000-0002-4405-7696
person.identifier.orcid0000-0002-6540-3164
person.identifier.ridABH-7711-2020
person.identifier.scopus-author-id13411315400
person.identifier.scopus-author-id24468034000
project.funder.identifierhttp://doi.org/10.13039/501100001871
project.funder.identifierhttp://doi.org/10.13039/501100001871
project.funder.identifierhttp://doi.org/10.13039/501100001871
project.funder.nameFundação para a Ciência e a Tecnologia
project.funder.nameFundação para a Ciência e a Tecnologia
project.funder.nameFundação para a Ciência e a Tecnologia
rcaap.cv.cienciaidA512-9B28-1CEC | Miguel Monteiro de Sousa Frade
rcaap.rightsopenAccesspt_PT
rcaap.typeconferenceObjectpt_PT
relation.isAuthorOfPublicationb88ada5f-0d8b-4e55-ab0a-62aa82ea1388
relation.isAuthorOfPublication95a3fa7a-d37e-45e9-9acb-44c083582fea
relation.isAuthorOfPublication27585414-d859-4dc0-9cac-72e03a4407a5
relation.isAuthorOfPublication.latestForDiscovery27585414-d859-4dc0-9cac-72e03a4407a5
relation.isProjectOfPublication67435020-fe0d-4b46-be85-59ee3c6138c7
relation.isProjectOfPublication0836c6a6-afd0-499e-8a16-612dd27ec1dc
relation.isProjectOfPublication43215f6c-bfb6-4829-8e75-6096384ce6db
relation.isProjectOfPublication.latestForDiscovery43215f6c-bfb6-4829-8e75-6096384ce6db

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
2024_digital_forensic_artifacts_FIDO2_.pdf
Size:
877.53 KB
Format:
Adobe Portable Document Format
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.33 KB
Format:
Item-specific license agreed upon to submission
Description: