Eliminating PKI Overhead in Kerberos: A FIDO2 Hardware Key Pre-Authentication Framework
ID:49
View protection:Participant Only
Updated time:2026-07-30 14:42:37
Views:21
Online
Abstract
Despite the widespread use of passwordless Fast IDentity Online 2 (FIDO2)-based systems for authentication on contemporary websites, enterprise networks continue to reply on legacy Kerberos V5 mechanisms and the highly vulnerable practice of storing symmetric password hashes. This reliance leaves organizations susceptible to catastrophic credential breaches, including Pass-the-Hash and AS-REP Roasting attacks. While there exist hardware-based defenses, such as the Public Key Cryptography for Initial Authentication (PKINIT) extension, which solve the problem of using passwords but require considerable operational expenditure due to the necessity of setting up a Public Key Infrastructure (PKI). To address this infrastructure bottleneck, a novel ”Zero-PKI” pre-authentication method is proposed, allowing the seamless integration of FIDO hardware tokens into legacy Kerberos environment without additional infrastructure overhead. Running entirely within the RFC 6113 protocol framework, the architecture ensures strict separation of duties. FIDO trust anchors are stored in a lightweight auxiliary database, while the essential Kerberos Database stays completely unaltered. By replacing static passwords with an ephemeral cryptographic challenge-response mechanism, this approach achieves the same level of protection offered by PKINIT without relying on external infrastructure.
Keywords
Kerberos,FIDO2,Passwordless Authentication,Zero-P,Applied Cryptography,Formal Verification
Post comments