You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

YubiKey/FIDO2无限密钥生成机制的原理问询

YubiKey/FIDO2无限密钥生成机制的原理问询

Hey there! I get why this might feel confusing at first—let me walk you through exactly how YubiKey pulls off supporting unlimited credentials without storing each private key on the device itself.

核心思路:不存私钥,存加密后的"密钥句柄"

Instead of saving every private key directly on the YubiKey, the device uses a clever encryption trick to let relying parties (RPs, like websites or services) store the necessary data for you. Here's the step-by-step breakdown:


注册流程(Credential Registration)

  • When you register a new credential (like setting up 2FA with a website), the YubiKey generates a unique, random key pair just for that credential.
  • The private key plus some metadata (like info tied to the RP's AppID) gets encrypted using AES-256 in CCM mode—this is authenticated encryption, meaning it both locks the data and verifies it hasn't been tampered with later.
  • The encryption uses a unique master key that's generated by the YubiKey itself the first time you start it up. This master key never leaves the device, and if you do a FIDO2 reset on your YubiKey, it gets regenerated (which invalidates all old credentials, since they were encrypted with the original master key).
  • The encrypted, authenticated data becomes a 64-byte "key handle"—this is what gets sent to the RP's server to store for future authentication.

认证流程(Authentication)

  • When you log in, the RP sends that stored key handle back to your YubiKey.
  • The YubiKey uses its master key to decrypt the key handle, retrieving the private key and associated metadata.
  • Thanks to the authenticated encryption, the YubiKey can instantly verify two things: the data hasn't been altered, and the credential is being used with the correct RP (matching the AppID tied to it).
  • Finally, the YubiKey uses the private key to sign the authentication challenge from the RP, and sends that signature back to complete the login.

为什么这能支持无限凭据?

Since the YubiKey doesn't store any per-credential data (all that info lives on the RP's server as the encrypted key handle), there's no limit to how many credentials you can register. This works for both U2F credentials and WebAuthn "non-resident keys".

Note: WebAuthn resident keys (sometimes called "discoverable credentials") are the exception here—those do need to be stored on the YubiKey itself, so their number is limited by the device's internal storage.


备注:内容来源于stack exchange,提问作者nojiyi4811

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.22 10:24:28