Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up
FIDO Alliance CTAP2.1 W3C WebAuthn Level 3 Hardware Key Architecture

FIDO2 CTAP2, WebAuthn & Hardware Security Key Protocol Studio

Architect and audit physical hardware security keys: dissect binary authenticator data (authData) byte layouts, inspect user presence (UP) and user verification (UV) flag bitfields, simulate USB HID 64-byte report frame packetization, trace ECDH P-256 ClientPIN key agreement, and export battle-tested Go, Rust, and TypeScript verification pipelines.

0x45 (UP+UV+AT)
AuthData Flags
104
Monotonic Sign Counter
8 of 8 Left
ClientPIN Retries
3 Frames
USB HID Report Count
YubiKey 5 NFC
Identified AAGUID
ES256 (P-256)
Public Key Algorithm

1. Authenticator Data (authData) Binary Dissector

Paste raw hexadecimal authData from a WebAuthn registration or assertion response

Bit 0: UP (User Present)
Physical Touch
Bit 1: Reserved
Bit 2: UV (User Verified)
Biometric / PIN
Bit 3: BE (Backup Eligible)
Bit 4: BS (Backup State)
Bit 5: Reserved
Bit 6: AT (Attested Data)
CredID + COSE Key
Bit 7: ED (Extension Data)
rpIdHash (SHA-256): a56c78...d84e
Signature Counter (signCount): 104 (Monotonic anti-clone counter)
AAGUID (Hardware Model): 2fc0579f-8113-47ea-b116-bb5a8db9202a
Credential ID Length & Value: 16 bytes (0x3a4f...99bc)
COSE Public Key (CBOR): EC2 P-256 (kty: 2, alg: -7, crv: 1)

2. USB HID 64-Byte Report Packetizer & Channel Arbiter

Simulates packet fragmentation over USB HID endpoints with CID allocation and sequence numbering

3. ClientPIN ECDH P-256 Key Agreement & Encryption Flow

Protects user PIN from host USB sniffing via ephemeral Elliptic Curve Diffie-Hellman and AES-CBC/GCM

Client Platform (Host)
  • 1. Generate ephemeral P-256 keypair: (d_plat, Q_plat)
  • 2. Send getSharedSecret request to device
  • 3. Compute shared secret Z = d_plat * Q_auth
  • 4. Derive K_pin = SHA-256(Z.x)[0..31]
  • 5. Encrypt pinHash with AES-256: C = Enc(K_pin, SHA-256(PIN)[0..15])
  • 6. Send C and Q_plat to device
Hardware Security Key (Device)
  • 1. Generate static/ephemeral P-256 keypair: (d_auth, Q_auth)
  • 2. Return Q_auth in COSE format
  • 3. Receive Q_plat and ciphertext C
  • 4. Compute shared secret Z = d_auth * Q_plat
  • 5. Derive K_pin = SHA-256(Z.x)[0..31]
  • 6. Decrypt pinHash; verify against internal hash
  • 7. Decrement retry counter if failed (Lockout at 0)

4. Production FIDO2 / CTAP2 Code Blueprints


        
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement