Passkey authentication

Passkey Authentication is a modern, secure authentication method that provides users with a seamless and highly secure way to access their accounts.

Unlike traditional passwords, passkeys use advanced cryptographic technology to create a secure, passwordless authentication experience that works across all devices and platforms. We utilise this technology, predominantly used in web2 systems and expend them into web3 as a users self-custodial wallet.

What are Passkeys?

Passkeys are digital credentials that replace traditional passwords and provide a more secure, user-friendly authentication experience. They use public-key cryptography to create a secure connection between your device and the services you're accessing, eliminating the need to remember complex passwords or worry about password-related security risks.

The key pair provided by the passkey is used with blockchain technology with the ability to hold funds and sign transactions with non-repudiation and without having to trust other systems.

How Passkeys Work

Account Abstraction Technology

Our passkey system leverages account abstraction technology, which provides a sophisticated layer of security and functionality while maintaining simplicity for end users. This technology creates a secure, unified account experience that works seamlessly across different platforms and services.

The Process

  1. Registration: Users create a passkey on their device using biometric authentication (fingerprint, face recognition) or device PIN

  2. Secure Storage: The passkey is securely stored on the user's device and can be synced across their trusted devices. Their smart wallet can be used on chain to hold and secure funds - only their passkey can control it.

  3. Authentication and signing transactions: When accessing services, users simply use their biometric or device authentication.

  4. Cryptographic Verification: The system uses advanced cryptography to verify the user's identity without transmitting sensitive data and directly in the smart wallet on the blockchain.

Security Benefits

Advanced Security Features

  • Biometric Authentication: Uses fingerprint, face recognition, or device PIN for authentication

  • Device Verification: Passkeys are tied to specific devices, adding an extra layer of security

  • Cryptographic Security: Uses industry-standard public-key cryptography for secure authentication

  • Automatic Encryption: All authentication data is automatically encrypted and protected

  • Self Custody: No intermediate services are used that have a hand in holding the users funds or ability to sign transactions.

  • Enhanced Backups: The operating system or device vendor deail with securely backing up and transferring your passkeys between devices, so no requirement for otehr backup services, pins or seed phrases.

Protection Against Common Attacks

  • Man-in-the-Middle Attacks: Cryptographic verification prevents interception, verification within the on chain smart wallet.

  • Brute Force Attacks: No passwords to guess or crack

  • Social Engineering: No passwords to trick users into revealing

  • Credential Stuffing: Unique passkeys for each service prevent reuse attacks

User Experience Benefits

Seamless Use

  • One-Tap Login & Transaction Signing: Users can log in and sign transactions with a single tap or biometric scan

  • Cross-Device Sync: Passkeys automatically sync and are backed up across trusted devices

  • No Secret Management: No need to remember, create, or reset passwords or secret phrases

  • Consistent Experience: Works the same way across all supported platforms

Accessibility and Convenience

  • Universal Access: Works on smartphones, tablets, laptops, and desktop computers

  • Backup Options: Multiple authentication methods available (biometric, PIN, security key)

  • Easy Recovery: Simple process to recover access if device is lost (based on vendor account such as iCloud)

Reduced Friction

  • Minimal Setup: Only one passkey biometric interaction needed.

  • Faster login and transaction signing: No typing required, just biometric scan or device unlock

  • No Password Fatigue: Eliminates the need to create and remember complex passwords

  • Error Prevention: No typos or forgotten codes to deal with

Supported Platforms and Devices

Operating Systems

  • iOS 16+: Native passkey support on iPhone and iPad

  • Android 9+: Built-in passkey functionality on Android devices

  • macOS Ventura+: Native support on Mac computers

  • Windows 11: Integrated passkey support on Windows devices

Browsers

  • Chrome: Full passkey support across all platforms

  • Safari: Native integration on Apple devices

  • Firefox: Comprehensive passkey functionality

  • Edge: Built-in support for Windows and other platforms

Hardware Support

  • Smartphones: All modern smartphones with biometric sensors

  • Tablets: iPads and Android tablets with biometric capabilities

  • Laptops: MacBooks and Windows laptops with fingerprint readers

  • Desktop Computers: Compatible with external security keys

Last updated