May 6, 2024, 5:54 a.m. |

IACR News www.iacr.org

ePrint Report: Quantum-Safe Account Recovery for WebAuthn

Douglas Stebila, Spencer Wilson


WebAuthn is a passwordless authentication protocol which allows users to authenticate to online services using public-key cryptography. Users prove their identity by signing a challenge with a private key, which is stored on a device such as a cell phone or a USB security token. This approach avoids many of the common security problems with password-based authentication.


WebAuthn's reliance on proof-of-possession leads to a usability issue, however: a user …

account authenticate authentication cell phone challenge cryptography device douglas eprint report identity key online services passwordless passwordless authentication phone private private key protocol prove public public-key cryptography quantum quantum-safe recovery report safe security services signing spencer usb webauthn

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Sr. Staff Firmware Engineer – Networking & Firewall

@ Axiado | Bengaluru, India

Compliance Architect / Product Security Sr. Engineer/Expert (f/m/d)

@ SAP | Walldorf, DE, 69190

SAP Security Administrator

@ FARO Technologies | EMEA-Portugal