QES-Backed Virtual FIDO2 Authenticators: Architectural Options for Secure, Synchronizable WebAuthn Credentials
Kemal Bicakci, Fatih Mehmet Varli, Muhammet Emir Korkmaz, Yusuf Uzunay

TL;DR
This paper explores architectural options for integrating high-assurance QES hardware tokens with WebAuthn, enabling secure cloud synchronization of FIDO2 credentials while maintaining user privacy and security.
Contribution
It introduces and analyzes two architectures for securing virtual FIDO2 authenticators with QES-grade hardware, including a baseline and a proposed hardened variant with enhanced security features.
Findings
Baseline architecture securely stores ciphertext in the cloud.
Experimental evaluation demonstrates feasibility of the baseline approach.
Hardened variant offers improved security against cross-protocol misuse.
Abstract
FIDO2 and the WebAuthn standard offer phishing-resistant, public-key based authentication but traditionally rely on device-bound cryptographic keys that are not naturally portable across user devices. Recent passkey deployments address this limitation by enabling multi-device credentials synchronized via platform-specific cloud ecosystems. However, these approaches require users and organizations to trust the corresponding cloud or phone providers with the protection and availability of their authentication material. In parallel, qualified electronic signature (QES) tokens and smart-card--based PKCS#11 modules provide high-assurance, hardware-rooted identity, yet they are not directly compatible with WebAuthn flows. This paper explores architectural options for bridging these technologies by securing a virtual FIDO2 authenticator with a QES-grade PKCS#11 key and enabling encrypted…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Authentication Protocols Security · Web Application Security Vulnerabilities · Cloud Data Security Solutions
