Pramaan ID · beat 4 of the twelve-minute demo
One token. Two machines. One of them is refused.
An access token is a bearer token: whoever holds it, holds the session. The industry answer is a shorter lifetime, which narrows the replay window without closing it. Pramaan ID issues the token against a public key the device generated and cannot export, and records that key's RFC 7638 thumbprint inside the token as cnf.jkt. The exchange below is the one the demo walks through on stage.
- 01 The private key never leaves The device generates a P-256 key pair with extractable set to false. There is no API that returns the private half — the browser refuses in its own words. On a phone this is the secure element; the property is identical.
- 02 The token names the key Only the public half is enrolled. The issued token carries cnf.jkt, the thumbprint of that key, so the token says which key is allowed to use it rather than trusting whoever presents it.
- 03 Every request carries a fresh proof A short JWT signed by the private key, bound to the method, the URI and a one-time identifier. Capture one off the wire and reuse it and the second use is refused — it buys an attacker a request they already watched succeed.
- 04 The refusal needs no revocation The broker takes the thumbprint of whoever signed the request and compares it with the one inside the token. On a second machine they do not match, so the token is inert — while remaining perfectly valid, unexpired and unrevoked for the device that holds the key.
The enrolled laptop
device A-
Request from the device the token was issued to
GET /userinfo Authorization: DPoP eyJhbGciOiJFUzI1NiIsInR5cCI6ImF0K2p3dCJ9.eyJzdWIi… DPoP: eyJ0eXAiOiJkcG9wK2p3dCIsImFsZyI6IkVTMjU2Iiwiandr…
200The proof is signed by the key whose thumbprint the token carries.
Any other machine
device B · same token-
Attempt 1 — the same token, presented as an ordinary bearer token
GET /userinfo Authorization: Bearer eyJhbGciOiJFUzI1NiIsInR5cCI6ImF0K2p3dCJ9.eyJzdWIi…
401No proof at all. This is the attack every bearer-token system loses to.
-
Attempt 2 — the same token, with a real DPoP proof from this machine
GET /userinfo Authorization: DPoP eyJhbGciOiJFUzI1NiIsInR5cCI6ImF0K2p3dCJ9.eyJzdWIi… DPoP: eyJ0eXAiOiJkcG9wK2p3dCIsImFsZyI6IkVTMjU2Iiwiandr…
401This proof is valid and correctly signed. It is signed by the wrong key, and
cnf.jktdoes not match.
And stillBack on the enrolled laptop, the same token still answers 200. It was never revoked and it has not expired. It simply does not work anywhere else.