UEFI环境下YubiKey 5 NFC的FIDO2功能识别及HID报告疑问
在UEFI环境下识别YubiKey FIDO2设备的问题
问题描述
我希望在UEFI环境下使用YubiKey的FIDO2功能。根据FIDO2规范,可通过检查**USB接口(类别3、子类0、协议0)和HID报告描述符(使用页0xF1D0)**来识别FIDO2设备。连接YubiKey后,我找到了符合类别的接口,但其HID报告描述符的使用页为0x01;而另一款Feitian的FIDO2设备同时具备正确的接口与使用页。除了在YubiKey管理器中启用USB FIDO2接口外,是否还需要额外开启YubiKey的FIDO2功能?
Feitian设备输出
Found a possible Fido2 device: 096E:0858 Usb device: Device: Vendor: 096E 'FT' Product: 0858 'FIDO' SerialNumber: 'unkn.' DeviceClass: 00 DeviceSubclass: 00 DeviceProtocol: 00 MaxPacketSize0: 40 Interface #00: AlternateSetting: 00 NumEndpoints: 02 InterfaceClass: 03 InterfaceSubClass: 00 InterfaceProtocol: 00 Interface: 05 Endpoint #0: EndpointAddress: 84 Attributes: 03 MaxPacketSize: 0040 Interval: 02 Endpoint #1: EndpointAddress: 04 Attributes: 03 MaxPacketSize: 0040 Interval: 02 HID report s item (01:00) -> Gobal:Usage Page { D0 F1 } HID report s item (02:00) -> Local:Usage { 01 } HID report s item (00:0A) -> Main:Collection (Application) { 01 } HID report s item (02:00) -> Local:Usage { 20 } HID report s item (01:01) -> Gobal:Logical Minimum { 00 } HID report s item (01:02) -> Gobal:Logical Maximum { FF 00 } HID report s item (01:07) -> Gobal:Report Size { 08 } HID report s item (01:09) -> Gobal:Report Count { 40 } HID report s item (00:08) -> Main:Input { 02 } HID report s item (02:00) -> Local:Usage { 21 } HID report s item (01:01) -> Gobal:Logical Minimum { 00 } HID report s item (01:02) -> Gobal:Logical Maximum { FF 00 } HID report s item (01:07) -> Gobal:Report Size { 08 } HID report s item (01:09) -> Gobal:Report Count { 40 } HID report s item (00:09) -> Main:Output { 02 } HID report s item (00:0C) -> Main:End Collection { }
YubiKey设备输出
Found a possible Fido2 device: 1050:0407 Usb device: Device: Vendor: 1050 'Yubico' Product: 0407 'YubiKey OTP+FIDO+CCID' SerialNumber: 'unkn.' DeviceClass: 00 DeviceSubclass: 00 DeviceProtocol: 00 MaxPacketSize0: 40 Interface #01: AlternateSetting: 00 NumEndpoints: 02 InterfaceClass: 03 InterfaceSubClass: 00 InterfaceProtocol: 00 Interface: 00 Endpoint #0: EndpointAddress: 04 Attributes: 03 MaxPacketSize: 0040 Interval: 02 Endpoint #1: EndpointAddress: 84 Attributes: 03 MaxPacketSize: 0040 Interval: 02 HID report s item (01:00) -> Gobal:Usage Page { 01 } HID report s item (02:00) -> Local:Usage { 06 } HID report s item (00:0A) -> Main:Collection (Application) { 01 } HID report s item (01:00) -> Gobal:Usage Page { 07 } HID report s item (02:01) -> Local:Usage Minimum { E0 } HID report s item (02:02) -> Local:Usage Maximum { E7 } HID report s item (01:01) -> Gobal:Logical Minimum { 00 } HID report s item (01:02) -> Gobal:Logical Maximum { 01 } HID report s item (01:07) -> Gobal:Report Size { 01 } HID report s item (01:09) -> Gobal:Report Count { 08 } HID report s item (00:08) -> Main:Input { 02 } HID report s item (01:09) -> Gobal:Report Count { 01 } HID report s item (01:07) -> Gobal:Report Size { 08 } HID report s item (00:08) -> Main:Input { 01 } HID report s item (01:09) -> Gobal:Report Count { 05 } HID report s item (01:07) -> Gobal:Report Size { 01 } HID report s item (01:00) -> Gobal:Usage Page { 08 } HID report s item (02:01) -> Local:Usage Minimum { 01 } HID report s item (02:02) -> Local:Usage Maximum { 05 } HID report s item (00:09) -> Main:Output { 02 } HID report s item (01:09) -> Gobal:Report Count { 01 } HID report s item (01:07) -> Gobal:Report Size { 03 } HID report s item (00:09) -> Main:Output { 01 } HID report s item (01:09) -> Gobal:Report Count { 06 } HID report s item (01:07) -> Gobal:Report Size { 08 } HID report s item (01:01) -> Gobal:Logical Minimum { 00 } HID report s item (01:02) -> Gobal:Logical Maximum { 65 } HID report s item (01:00) -> Gobal:Usage Page { 07 } HID report s item (02:01) -> Local:Usage Minimum { 00 } HID report s item (02:02) -> Local:Usage Maximum { 65 } HID report s item (00:08) -> Main:Input { 00 } HID report s item (02:00) -> Local:Usage { 03 } HID report s item (01:07) -> Gobal:Report Size { 08 } HID report s item (01:09) -> Gobal:Report Count { 08 } HID report s item (00:0B) -> Main:Feature { 02 } HID report s item (00:0C) -> Main:End Collection { }
解答
不需要额外开启YubiKey的FIDO2功能,问题出在你当前枚举到的是YubiKey的OTP接口,而非FIDO2接口:
- 从YubiKey的输出可以看到,HID报告描述符的使用页是0x01(通用桌面设备),搭配Usage 0x06(键盘),这是YubiKey的OTP功能对应的HID接口,负责模拟键盘输出一次性密码。
- YubiKey是多接口设备(你的设备型号是
YubiKey OTP+FIDO+CCID,包含三个独立接口),FIDO2接口同样是类别3、子类0、协议0的HID接口,但它的HID报告描述符使用页是0xF1D0,和Feitian设备的格式一致。
解决步骤:
- 确认YubiKey管理器中已经启用了FIDO2 USB接口(通常默认是开启的,但建议检查)。
- 在UEFI程序中枚举YubiKey的所有USB接口,找到HID报告描述符使用页为0xF1D0的那个接口,而非当前的OTP接口。
- 对找到的FIDO2接口进行初始化和通信,即可在UEFI环境下使用FIDO2功能。
内容的提问来源于stack exchange,提问作者MiSimon
相关产品推荐
相关产品推荐

