Passkey-fused credentials: definition, protocols and use cases

In the previous post I described issuance and presentation protocols for a kind of third-party credential that is made available at once to all the browser instances controlled by a user, which I refer to as the user's sync fabric, instead of being issued to one instance and then replicated to other instances upon request by relying parties. The credential comprises a passkey and a certificate, uses the public key of the passkey as the public key in the certificate, and uses an AES key stored in the user.id parameter of the passkey to encrypt the certificate.

Then in this LinkedIn post I referred to the third-party credential as being the result of "fusing" a passkey with a public key certificate.

Here I'm going to formally define the term passkey-fused credential (PFC) to refer to that kind of third-party credential, restate the issuance and presentation protocols of the previous post with reference to that definition, and provide four examples of use cases where PFCs can be used.

Continue reading "Passkey-fused credentials: definition, protocols and use cases"

Making a third-party credential available on multiple devices by issuing it to the user’s sync fabric

Updated on September 27 and October 5 to correct errors as shown below by crossed out text and underlined text.

In the previous post I went over a live demonstration showing how a passkey can be used for replication of a credential comprising a JSON certificate and its associated private key across browser instances on different devices controlled by the same user.

Here I propose a new method, not yet implemented, of using a passkey to make such a credential available on multiple devices. In this method the credential is issued to the user's sync fabric as a whole, instead of being replicated across browser instances after being issued to one particular instance. After being issued to the fabric, it is available on any browser instance with full cryptographic protection, instead of being stored in the clear in each instance where it has been replicated. By the user's sync fabric I mean the set of browser instances to which the passkey can be synced. By full cryptographic protection I mean that the certificate is encrypted and the private key is in protected storage such as the TPM used by Windows Hello.

The new method uses the following issuance and presentation protocols.

Continue reading "Making a third-party credential available on multiple devices by issuing it to the user’s sync fabric"