2026-05-13
Recursive Augmented Fernet (RAF) token: Alleviating the pain of stolen tokens
Publication
Publication
Journal of Cybersecurity and Privacy , Volume 6 - Issue 3 p. 88:1- 88:43
A robust authentication and authorization mechanism is imperative in modular system development, where modularity and modular thinking are pivotal. Traditional systems often employ identity modules responsible for authentication and token issuance. Tokens, representing user credentials, offer advantages such as reduced reliance on passwords, limited lifespan, and scoped access. Despite these benefits, the “bearer token” problem persists, leaving systems vulnerable to abuse if tokens are compromised. We propose a token-based authentication mechanism addressing the critical bearer token problem in modular systems. The proposed mechanism includes a novel RAF (Recursive Augmented Fernet) token, a blacklist component, and a policy enforcer component. RAF tokens are one-time-use tokens, like tickets. They carry commands, and the receiver of an RAF token can issue new tokens using the received RAF token. The blacklist component guarantees an RAF token cannot be validated more than once, and the policy enforcer checks the compatibility of commands carried by an RAF token. We introduce two variations of RAF tokens: user-tied RAF, offering simplicity and compatibility, and fully-tied RAF, providing enhanced security through service-specific secret keys. We thoroughly discuss the security guarantees, technical definitions, and construction of RAF tokens backed by game-based proofs. We demonstrate a proof of concept in the context of OpenStack, involving modifications to Keystone and the creation of an RAFT library. The experimental results reveal minimal overhead in typical scenarios, establishing the practicality and effectiveness of RAF. Our experiments show that the RAF mechanism outperforms the use of short-life Fernet tokens while providing much better security.
| Additional Metadata | |
|---|---|
| , , , , | |
| doi.org/10.3390/jcp6030088 | |
| Journal of Cybersecurity and Privacy | |
| creativecommons.org/licenses/by/4.0/ | |
| Organisation | Computer Security |
|
Rahaeimehr, R.& van Dijk, M. (2026). Recursive Augmented Fernet (RAF) token: Alleviating the pain of stolen tokens. Journal of Cybersecurity and Privacy, 6(3), 88:1–88:43.https://doi.org/10.3390/jcp6030088 |
|