Classification of Implementation-Level Security Vulnerabilities in FIDO Authentication Systems and Design Guidelines Based on Real-World Case Analysis
FIDO 인증 체계의 구현상 보안 취약점의 분류와 실제 사례 분석을 통한 설계 가이드라인 제시
FIDO holds up as a protocol, but falls over in how it is shipped. The paper classifies real deployment failures — including the 0-click account takeover and the authentication signature leak via MITM found in Government24 — and translates each class into a concrete guideline.
paper · Joohyuk Ham1, Haehyun Cho2 · JKIISC 2026 · kci.go.kr