Paper 2025/2067

Cryptographic Binding Should Not Be Optional: A Formal-Methods Analysis of FIDO UAF Channel Binding

Enis Golaszewski, University of Maryland, Baltimore County
Alan T. Sherman, University of Maryland, Baltimore County
Edward Zieglar, National Security Agency
Jonathan D. Fuchs, University of Maryland, Baltimore County
Sophia Hamer, University of Maryland, Baltimore County
Abstract

As a case study in cryptographic binding, we present a formal-methods analysis of the cryptographic channel binding mechanisms in the Fast IDentity Online (FIDO) Universal Authentication Framework (UAF) authentication protocol, which seeks to reduce the use of traditional passwords in favor of authentication devices. First, we show that UAF's channel bindings fail to mitigate protocol interaction by a Dolev-Yao adversary, enabling the adversary to transfer the server's authentication challenge to alternate sessions of the protocol. As a result, in some contexts, the adversary can masquerade as a client and establish an authenticated session with a server (e.g., possibly a bank server). Second, we implement a proof-of-concept man-in-the-middle attack against eBay's open source FIDO UAF implementation. Third, we propose and formally verify improvements to UAF. The weakness we analyze is similar to the vulnerability discovered in the Needham-Schroeder protocol over 25 years ago. That this vulnerability appears in the FIDO UAF standard highlights the strong need for protocol designers to bind messages properly and to analyze their designs with formal-methods tools. To our knowledge, we are first to carry out a formal-methods analysis of channel binding in UAF and first to exhibit details of an attack on UAF that exploits the weaknesses of UAF's channel binding. Our case study illustrates the importance of cryptographically binding context to protocol messages to prevent an adversary from misusing messages out of context.

Note: A shorter version of this paper will appear in the Proceedings of Security Standardisation Research (SSR) 2025, published by Springer in the LNCS series.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
channel bindingFast Identity Online (FIDO)formal-methods analysis of protocolsUniversal Authentication Framework
Contact author(s)
golaszewski @ umbc edu
sherman @ umbc edu
evziegl @ uwe nsa gov
jfuchs2 @ umbc edu
chamer1 @ umbc edu
History
2025-11-13: approved
2025-11-08: received
See all versions
Short URL
https://ia.cr/2025/2067
License
No rights reserved
CC0

BibTeX

@misc{cryptoeprint:2025/2067,
      author = {Enis Golaszewski and Alan T. Sherman and Edward Zieglar and Jonathan D. Fuchs and Sophia Hamer},
      title = {Cryptographic Binding Should Not Be Optional: A Formal-Methods Analysis of {FIDO} {UAF} Channel Binding},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2067},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2067}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.