---
title: "Hardware-Bound FIDO2/WebAuthn Enterprise IdP | Zero-Trust Architecture Canon"
description: "Zero-password authentication architecture enforcing hardware cryptographic security keys (YubiKey / Secure Enclave) via WebAuthn, mathematically immune to adversary-in-the-middle phishing."
image: "https://tinycto.tv/assets/zero-trust/zero_trust_architectures_og.jpg"
canonicalUrl: "https://tinycto.tv/zero-trust/architectures/sso-fido2-webauthn-phishing-resistant"
locale: "en"
---

# Hardware-Bound FIDO2/WebAuthn Enterprise IdP (`zt-arch-03`)

> **Pillar**: IDENTITY | **Archetype**: IDENTITY_ATTESTATION
> **Blocked MITRE ATT&CK Techniques**: T1539, T1556, T1110, T1078

## Architecture Summary

Zero-password authentication architecture enforcing hardware cryptographic security keys (YubiKey / Secure Enclave) via WebAuthn, mathematically immune to adversary-in-the-middle phishing.

## Adversary Model

Adversary deploys reverse-proxy phishing kits (e.g. Modlishka, Evilginx) capturing usernames, passwords, and TOTP verification codes.

## NIST SP 800-207 Core Tenets

- Access to individual enterprise resources is granted on a per-session basis.
- Authentication and authorization are strictly dynamic and strictly enforced before access is allowed.

## 3-Tier Maturity Configurations

### INITIAL Maturity Target

- **Implementation Scope**: WebAuthn offered as an optional second factor for privileged admin accounts.
- **Authentication Enforcement**: Password + Security Key (FIDO2) fallback to TOTP allowed.
- **Network Isolation**: Standard HTTPS TLS 1.3 edge termination.

### ADVANCED Maturity Target

- **Implementation Scope**: Mandatory FIDO2 WebAuthn across 100% of employees; all password inputs removed from UI.
- **Authentication Enforcement**: Resident Discoverable Credentials (passkeys) with user presence PIN validation.
- **Network Isolation**: Origin validation enforced cryptographically at the browser-token boundary.

### OPTIMAL Maturity Target

- **Implementation Scope**: Enterprise-wide hardware-bound passkeys integrated with ephemeral SSH certificates and cloud IAM.
- **Authentication Enforcement**: Strict AAGUID allowlisting restricted to FIPS 140-3 Level 3 validated hardware modules.
- **Network Isolation**: Cross-origin binding with strict Certificate Transparency monitoring.

## Terraform HCL Manifest

```hcl
resource "keycloak_realm" "realm" {
  realm                = "tinycto"
  enabled              = true
  web_authn_policy_rp_entity_name = "TinyCTO Enterprise"
  web_authn_policy_signature_algorithms = ["ES256", "EdDSA", "RS256"]
  web_authn_policy_attestation_conveyance_preference = "direct"
  web_authn_policy_authenticator_attachment = "cross-platform"
}
```

## Kubernetes / Tetragon Policy Manifest

```yaml
apiVersion: v1
kind: ConfigMap
metadata:
  name: webauthn-config
  namespace: auth
data:
  rp-id: "tinycto.tv"
  rp-name: "TinyCTO Security Plane"
  origin: "https://auth.tinycto.tv"
  user-verification: "required"
```


```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Hardware-Bound FIDO2/WebAuthn Enterprise IdP | Zero-Trust Architecture Canon",
  "description": "Zero-password authentication architecture enforcing hardware cryptographic security keys (YubiKey / Secure Enclave) via WebAuthn, mathematically immune to adversary-in-the-middle phishing.",
  "url": "https://tinycto.tv/zero-trust/architectures/sso-fido2-webauthn-phishing-resistant"
}
```
