Skip to main content

SID-CRYPTO-02 — PRF Extension Key Derivation

PropertyValue
Statusverified
Ownerplatform
Categorytechnical
CSF Functionprotect
GroupCryptography Controls

Description

WebAuthn PRF extension derives encryption keys from authenticator secrets using salt-based HKDF. Provides hardware-backed key material that never leaves the authenticator. Supports both legacy symmetric wrap (AES-KW) and upgraded asymmetric encapsulation (ECDH).

Components

  • Wallet Frontend
  • WSCA / HSM

Source References

Audit Findings

FindingSeverityStatus
EN-S-2 — Partial asset classification and cryptographic documentationmediumin progress
EN-P-5 — Partial user authentication and session controlshighin progress
EN-P-6 — Partial key management and credential operationsmediumin progress
ISO-T-5 — Partial endpoint and privileged access controlsmediumopen