Tomás Matos, University of Aveiro, Portugal
Andre Zuquete, University of Aveiro, Portugal
Tomás Silva, University of Aveiro, Portugal
As the digital infrastructure expands, new authen- tication methods have become popular in both enterprises and the research community, innovating and increasing the security of authentication processes. FIDO2 is a standard that aims to replace passwords using asymmetric cryptography through challenge-response mechanisms, keeping private keys stored in secure tokens. As with all technologies, it comes with drawbacks, such as the cost of physical devices and recovery mechanisms that make adoption harder. Due to these problems, this work proposes a centralized credential manager that stores these types of credentials and provides phishing-resilient authentication without requiring hardware investment and with replication mechanisms for fault tolerance. To tackle data breaches in the centralized application, we leverage Intel SGX capabilities, which provide a trusted execution environment and attestation mechanisms to ensure that users get the expected behavior when interacting with their credentials.