Enhancing FIDO2 Authentication Security through Markov Decision Process-Based Risk Assessment
摘要
With the continual evolution of network-attack techniques, conventional password-based authentication mechanisms have become increasingly ineffective when countering emerging cyber threats. To improve both security and usability, the FIDO Alliance introduced the FIDO2 authentication standard. As a passwordless solution, FIDO2 leverages public-key cryptography to mitigate risks such as credential leakage and to provide a more secure means of identity verification. Nevertheless, real-world FIDO2 deployments can still be exposed to latent security threats. To address this gap, we propose a FIDO2 security assessment framework grounded in a Markov Decision Process (MDP). By modelling the FIDO2 authentication flow as an MDP, the framework evaluates the in-transit security risk of WebAuthn communications and their associated verification parameters. It dynamically calculates the risk state of each authentication request in real time, adaptively escalates the strength of the FIDO2 authentication mechanism, and thus reinforces the transmission security of FIDO2-based identity verification.