This repository provides an implementation for the FIDO-AC system, an unoptimized proof-of-concept implementation prototype for the framework described in the Fast IDentity Online with Anonymous Credentials (FIDO-AC) paper link.
Elements of the system:
- Mobile application (Android)
- FIDO-AC javascript that intercepts calls to navigator object
- FIDO server
- FIDO-AC server
The diagram below presents the interactions between elements of the system.
- fidoac_androidapp : Android Application implementing the BAC/PACE, the ZK-Proof of the eID attribute and the local mediator.
- fidoac_app_server: Relying Party's FIDO Server, implemenetion based on simplewebauthn server
- fidoac_server: Web server for FIDO-AC verification (ZKProof and mediator).
The fidoac_androidapp implements
- BAC/PACE for the ICAO eID and Mediator in EIDInterface.kt.
- ZKProof of Attribute in lib.rs and zkpmain.rs.
The fido_app_server implements a standard FIDO2 server extended with FIDO-AC functionalities to trigger fido-ac extension and run the verification against FIDO-AC Server The FIDO-AC extension code can be found in fido-ac.ts file
Additionally, the server publishes a fido-ac.js which is responsible for intercepting FIDO calls and forwarding them to FIDO-AC application.
The fidoac_server implements ZKP verification and publishing CRS. The source code for ZKP operations can be found in main.rs. The rust code is wrapped in the HTTP server. The local mediator verification can be found in MediatorVerifier.py.
The fidoac_app_server and fidoac_server applications can be easily started using docker-compose.yml file
docker compose up
The expected mediator signing key for the APK is also provided and already preconfigured in build.gradle.
Prerequisites:
- Android SDK, NDK
- Rust
- Setup for Rust toolchain for Android. See Mozilla - Building and Deploying a Rust library on Android.
- Build Rust Code to lib.so
./gradlew cargoBuild
- Build Android Code to APK
./gradlew assembleDebug
- Install APK
Below, we present the interaction diagram for the FIDO process enchanced with the FIDO-AC elements.