Meaning
Signed data structures generated by a client during a challenge response sequence provide cryptographic proof of identity to a relying party. A webauthn assertion contains the signature, the original challenge and the authenticator data required to verify a login attempt. This response proves that a user is in physical possession of a registered security key or biometric sensor.
It is the core mechanism of passwordless authentication on the web.
Client Interaction
Browsers communicate with the hardware authenticator to sign a specific challenge sent by the server. The webauthn assertion is the result of this interaction, formatted as a structured object for transmission. During this phase, the user typically provides a gesture, such as a touch or a PIN, to authorize the signing operation.
This prevents unauthorized applications from using the hardware without the user’s knowledge. The handshake between the browser and the device is strictly governed by security standards.
Signature Verification
Servers receive the data and use a stored public key to check the validity of the response. A webauthn assertion only passes if the signature matches the challenge and the origin of the request is correct. This check prevents replay attacks and phishing because the signature is unique to each session and website.
The server also inspects the signature counter to detect cloned devices.
Hardware Security
Private keys never leave the secure element of the authenticator during the process. Because the webauthn assertion is generated internally, the secret material remains protected from malware on the host computer. Security is hardware based.