Get your free and exclusive +90-page Banking Passkey Report
Back to Overview

What is CTAP (Client-to-Authenticator-Protocol)?

Discover CTAP (Client-to-Authenticator-Protocol), a technology to streamline secure communication between user devices and authenticators.

Vincent Delitz

Vincent

Created: December 20, 2023

Updated: December 11, 2025

What is Client-to-Authenticator-Protocol (CTAP)?- CTAP is a standardized mechanism designed to streamline and secure communication between a userโ€™s device and an authenticator

CTAP (Client-to-Authenticator-Protocol)๋ž€ ๋ฌด์—‡์ธ๊ฐ€์š”?#

CTAP(Client-to-Authenticator-Protocol)๋Š” ์‚ฌ์šฉ์ž์˜ ๊ธฐ๊ธฐ(๋…ธํŠธ๋ถ์ด๋‚˜ ๋ธŒ๋ผ์šฐ์ € ๋“ฑ)์™€ ์ธ์ฆ๊ธฐ(ํ•˜๋“œ์›จ์–ด ๋ณด์•ˆ ํ‚ค๋‚˜ ์Šค๋งˆํŠธํฐ ๋“ฑ) ๊ฐ„์˜ ํ†ต์‹ ์„ ๊ฐ„์†Œํ™”ํ•˜๊ณ  ๋ณด์•ˆ์„ ์œ ์ง€ํ•˜๊ธฐ ์œ„ํ•ด ์„ค๊ณ„๋œ ํ‘œ์ค€ํ™”๋œ ๋ฉ”์ปค๋‹ˆ์ฆ˜์ž…๋‹ˆ๋‹ค. ์ด ํ”„๋กœํ† ์ฝœ์€ ํŠนํžˆ FIDO2 ๋ฐ WebAuthn ํ‘œ์ค€์˜ ๋งฅ๋ฝ์—์„œ ์‚ฌ์šฉ์ž ์ธ์ฆ ๊ณผ์ •์— ํฌํ•จ๋œ ์—ฌ๋Ÿฌ ๊ตฌ์„ฑ ์š”์†Œ๊ฐ€ ํšจ๊ณผ์ ์œผ๋กœ ์ƒํ˜ธ ์ž‘์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•˜๋Š” ๋‹ค๋ฆฌ ์—ญํ• ์„ ํ•ฉ๋‹ˆ๋‹ค.

์ฃผ์š” ๋‚ด์šฉ#

  • CTAP๋Š” FIDO2์—์„œ ํด๋ผ์ด์–ธํŠธ์™€ ์ธ์ฆ๊ธฐ ๊ฐ„์˜ ์›ํ™œํ•œ ํ†ต์‹ ์„ ๋ณด์žฅํ•˜๋Š” ๊ธฐ๋ณธ ํ”„๋กœํ† ์ฝœ์ž…๋‹ˆ๋‹ค.
  • CTAP๋Š” Universal 2nd Factor(U2F) ์ธ์ฆ์—์„œ ๋ฐœ์ „ํ•˜์—ฌ, ๋น„๋ฐ€๋ฒˆํ˜ธ ์—†์ด ๋” ์•ˆ์ „ํ•œ ์‚ฌ์šฉ์ž ์ธ์ฆ์˜ ๊ธธ์„ ์—ด์—ˆ์Šต๋‹ˆ๋‹ค.
  • CTAP๋Š” resident ํ‚ค์™€ non-resident ํ‚ค๋ฅผ ๋ชจ๋‘ ์ง€์›ํ•˜์—ฌ ์‚ฌ์šฉ์ž ์‹๋ณ„ ๋ฐ ์ธ์ฆ์˜ ์œ ์—ฐ์„ฑ์„ ๋”์šฑ ํ–ฅ์ƒ์‹œํ‚ต๋‹ˆ๋‹ค.

CTAP์˜ ๋ฐœ์ „๊ณผ ์ค‘์š”์„ฑ#

ํ•œ๋•Œ ์˜จ๋ผ์ธ ๋ณด์•ˆ์˜ ์ตœ๊ณ  ํ‘œ์ค€์œผ๋กœ ์—ฌ๊ฒจ์กŒ๋˜ ์ „ํ†ต์ ์ธ ์‚ฌ์šฉ์ž ์ด๋ฆ„-๋น„๋ฐ€๋ฒˆํ˜ธ ์‹œ์Šคํ…œ์€ ์‹œ๊ฐ„์ด ์ง€๋‚˜๋ฉด์„œ ์ทจ์•ฝ์ ์„ ๋“œ๋Ÿฌ๋ƒˆ์Šต๋‹ˆ๋‹ค. ์‚ฌ์šฉ์ž๋“ค์ด ๊ธฐ์–ตํ•˜๊ธฐ ์‰ฝ๊ณ (๋”ฐ๋ผ์„œ ํ•ด๋…ํ•˜๊ธฐ๋„ ์‰ฌ์šด) ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์„ ํƒํ•˜๊ฑฐ๋‚˜ ์—ฌ๋Ÿฌ ํ”Œ๋žซํผ์—์„œ ๋™์ผํ•œ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์žฌ์‚ฌ์šฉํ•จ์— ๋”ฐ๋ผ, ๋” ๊ฐ•๋ ฅํ•˜๊ณ  ์•ˆ์ „ํ•œ ๋ฐฉ๋ฒ•์ด ํ•„์ˆ˜์ ์ด ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์‹œ๊ธ‰ํ•œ ํ•„์š”์„ฑ์„ ์ธ์‹ํ•œ FIDO ์–ผ๋ผ์ด์–ธ์Šค๋Š” ์›”๋“œ์™€์ด๋“œ์›น ์ปจ์†Œ์‹œ์—„(W3C)๊ณผ ํ˜‘๋ ฅํ•˜์—ฌ ๋” ๊ฐ•๋ ฅํ•œ ์‹œ์Šคํ…œ์ธ FIDO2์™€ WebAuthn์˜ ๊ฐœ๋ฐœ์„ ์ฃผ๋„ํ–ˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ์ด๋Ÿฌํ•œ ๋ฐœ์ „์˜ ์ค‘์‹ฌ์—๋Š” CTAP๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. โ€

CTAP์˜ ์—ญํ•  ์ดํ•ดํ•˜๊ธฐ#

  • WebAuthn ๋ณด์™„: WebAuthn์ด ์‚ฌ์šฉ์ž ์‹œ์Šคํ…œ๊ณผ ์‹ ์› ํ™•์ธ์ด ํ•„์š”ํ•œ ์›น์‚ฌ์ดํŠธ ๊ฐ„์˜ ์—ฐ๊ฒฐ์— ์ค‘์ ์„ ๋‘๋Š” ๋ฐ˜๋ฉด, CTAP๋Š” ์ธ์ฆ๊ธฐ(USB ์Šคํ‹ฑ์ด๋‚˜ ๋ชจ๋ฐ”์ผ ๊ธฐ๊ธฐ ๋“ฑ)์™€ ์‚ฌ์šฉ์ž์˜ ์ฃผ ๊ธฐ๊ธฐ ๊ฐ„์˜ ํ†ต์‹ ์„ ๊ทœ์ œํ•ฉ๋‹ˆ๋‹ค.
  • ๋ณด์•ˆ ๊ฐ•ํ™”: CTAP ํ”„๋กœํ† ์ฝœ์€ ์ง€๋ฌธ๊ณผ ๊ฐ™์€ ๋ฏผ๊ฐํ•œ ๋ฐ์ดํ„ฐ๊ฐ€ ๊ธฐ๊ธฐ๋ฅผ ์ ˆ๋Œ€ ๋ฒ—์–ด๋‚˜์ง€ ์•Š๋„๋ก ๋ณด์žฅํ•˜์—ฌ ์ถ”๊ฐ€์ ์ธ ๋ณด์•ˆ ๊ณ„์ธต์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ์ด๋Š” ๋ฐ์ดํ„ฐ ์œ ์ถœ ๋ฐ ํ”ผ์‹ฑ ๊ณต๊ฒฉ๊ณผ ๊ด€๋ จ๋œ ์œ„ํ—˜์„ ์ตœ์†Œํ™”ํ•ฉ๋‹ˆ๋‹ค. โ€

CTAP ๋ฒ„์ „#

  • CTAP1 (U2F): ํ˜„์žฌ CTAP์˜ ์ „์‹ ์ธ U2F๋Š” ์ฃผ๋กœ 2๋‹จ๊ณ„ ์ธ์ฆ์„ ๋ชฉํ‘œ๋กœ ํ–ˆ์Šต๋‹ˆ๋‹ค. ์‚ฌ์šฉ์ž ์‹๋ณ„์„ ์œ„ํ•ด ์„œ๋ฒ„ ์ธก ์กฐํšŒ๊ฐ€ ํ•„์š”ํ–ˆ๊ธฐ ๋•Œ๋ฌธ์— ๊ทธ ๋ฒ”์œ„๊ฐ€ ๋‹ค์†Œ ์ œํ•œ์ ์ด์—ˆ์Šต๋‹ˆ๋‹ค.
  • CTAP2: ๋” ๋ฐœ์ „๋œ ๋ฒ„์ „์ธ CTAP2๋Š” resident key๋ผ๋Š” ๊ฐœ๋…์„ ๋„์ž…ํ•˜์—ฌ ๋น„๋ฐ€๋ฒˆํ˜ธ ์—†๋Š”, ์‹ฌ์ง€์–ด "์‚ฌ์šฉ์ž ์ด๋ฆ„ ์—†๋Š”" ์ธ์ฆ์„ ์ด‰์ง„ํ•ฉ๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ๋ณ€ํ™”๋Š” ๋” ์‚ฌ์šฉ์ž ์ค‘์‹ฌ์ ์ธ ์ธ์ฆ ๊ฒฝํ—˜์œผ๋กœ ๋‚˜์•„๊ฐ€๋Š” ์ค‘์š”ํ•œ ๋‹จ๊ณ„๊ฐ€ ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • CTAP2.1: CTAP2์˜ ๊ธฐ๋ฐ˜ ์œ„์— ๊ตฌ์ถ•๋œ CTAP2.1์€ ์ „์ฒด ๊ธฐ๊ธฐ ์žฌ์„ค์ • ์—†์ด ๊ฐœ๋ณ„ ํ‚ค๋ฅผ ์—…๋ฐ์ดํŠธํ•  ์ˆ˜ ์žˆ๋Š” ๊ฐœ์„ ๋œ resident key ๊ด€๋ฆฌ์™€ ์กฐ์ง์˜ ํ†ต์ œ๋ ฅ์„ ๊ฐ•ํ™”ํ•˜๋Š” ์—”ํ„ฐํ”„๋ผ์ด์ฆˆ ์ฆ๋ช…(attestation)๊ณผ ๊ฐ™์€ ํ–ฅ์ƒ๋œ ๊ธฐ๋Šฅ์„ ๋„์ž…ํ•ฉ๋‹ˆ๋‹ค.

CTAP๋ฅผ ์ด์šฉํ•œ ์ธ์ฆ ์ ˆ์ฐจ#

CTAP๋ฅผ ํ†ตํ•œ ํ†ต์‹ ์€ ๊ตฌ์กฐํ™”๋œ ํŒจํ„ด์„ ๋”ฐ๋ฆ…๋‹ˆ๋‹ค. ๋จผ์ €, ํด๋ผ์ด์–ธํŠธ ์†Œํ”„ํŠธ์›จ์–ด(๋ธŒ๋ผ์šฐ์ € ๋“ฑ)๊ฐ€ ์ธ์ฆ๊ธฐ์— ์—ฐ๊ฒฐํ•˜์—ฌ ์ •๋ณด๋ฅผ ์š”์ฒญํ•ฉ๋‹ˆ๋‹ค. ์ˆ˜์‹ ๋œ ๋ฐ์ดํ„ฐ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ์ ์ ˆํ•œ ๋ช…๋ น์„ ์ธ์ฆ๊ธฐ์— ๋ณด๋‚ด๊ณ , ์ธ์ฆ๊ธฐ๋Š” ์ด์— ๋Œ€ํ•œ ์‘๋‹ต์ด๋‚˜ ์˜ค๋ฅ˜ ๋ฉ”์‹œ์ง€๋ฅผ ๋‹ค์‹œ ๋ณด๋ƒ…๋‹ˆ๋‹ค. ์ด ๋ฐ˜๋ณต์ ์ธ ๊ณผ์ •์€ ์ธ์ฆ ์ค‘ ์•ˆ์ „์„ฑ๊ณผ ํšจ์œจ์„ฑ์„ ๋ชจ๋‘ ๋ณด์žฅํ•ฉ๋‹ˆ๋‹ค.


CTAP (Client-to-Authenticator-Protocol) ๊ด€๋ จ ์ž์ฃผ ๋ฌป๋Š” ์งˆ๋ฌธ#

FIDO2 ํ”„๋ ˆ์ž„์›Œํฌ์—์„œ CTAP๋Š” WebAuthn๊ณผ ์–ด๋–ป๊ฒŒ ๋‹ค๋ฅธ๊ฐ€์š”?#

๋‘˜ ๋‹ค FIDO2์˜ ์ค‘์š”ํ•œ ๊ตฌ์„ฑ ์š”์†Œ์ด์ง€๋งŒ, WebAuthn์€ ์‚ฌ์šฉ์ž ์‹œ์Šคํ…œ๊ณผ ์‹ ์› ํ™•์ธ์ด ํ•„์š”ํ•œ ์›น์‚ฌ์ดํŠธ ๊ฐ„์˜ ์—ฐ๊ฒฐ์— ์ค‘์ ์„ ๋‘ก๋‹ˆ๋‹ค. ๋ฐ˜๋ฉด CTAP๋Š” ๋ณด์•ˆ ํ‚ค๋‚˜ ์Šค๋งˆํŠธํฐ๊ณผ ๊ฐ™์€ ์ธ์ฆ๊ธฐ์™€ ์‚ฌ์šฉ์ž์˜ ์ฃผ ๊ธฐ๊ธฐ ๊ฐ„์˜ ์—ฐ๊ฒฐ์„ ๊ทœ์ œํ•ฉ๋‹ˆ๋‹ค.

CTAP๊ฐ€ ํŒจ์Šคํ‚ค์™€ ๊ฐ™์€ ์ตœ์‹  ์ธ์ฆ ๋ฐฉ๋ฒ•์— ์™œ ์ค‘์š”ํ•œ๊ฐ€์š”?#

CTAP๋Š” ๊ธฐ๊ธฐ์™€ ์ธ์ฆ๊ธฐ๊ฐ€ ํšจ๊ณผ์ ์œผ๋กœ ํ†ต์‹ ํ•˜๋„๋ก ๋ณด์žฅํ•˜์—ฌ ํŒจ์Šคํ‚ค์™€ ๊ฐ™์€ ๋น„๋ฐ€๋ฒˆํ˜ธ ์—†๋Š” ๋ฐฉ๋ฒ•์„ ํšจ์œจ์ ์œผ๋กœ ๋งŒ๋“ญ๋‹ˆ๋‹ค. ์ด ํ†ต์‹ ์„ ํ‘œ์ค€ํ™”ํ•จ์œผ๋กœ์จ CTAP๋Š” ๋‹ค์–‘ํ•œ ํ”Œ๋žซํผ๊ณผ ๊ธฐ๊ธฐ์—์„œ ์ผ๊ด€์„ฑ๊ณผ ๋ณด์•ˆ์„ ๋ณด์žฅํ•ฉ๋‹ˆ๋‹ค.

CTAP์—๋Š” ๋‹ค๋ฅธ ๋ฒ„์ „์ด ์žˆ๋‚˜์š”?#

๋„ค, ์ฃผ๋กœ 2๋‹จ๊ณ„ ์ธ์ฆ์„ ๋ชฉํ‘œ๋กœ ํ•˜๋Š” CTAP1์ด ์žˆ์Šต๋‹ˆ๋‹ค. CTAP2๋Š” resident key๋ฅผ ๋„์ž…ํ•˜์—ฌ ๋น„๋ฐ€๋ฒˆํ˜ธ ์—†๋Š” ์ธ์ฆ์„ ์ด‰์ง„ํ–ˆ์Šต๋‹ˆ๋‹ค. ๋” ์ตœ์‹  ๋ฒ„์ „์ธ CTAP2.1์€ ๊ฐœ์„ ๋œ resident key ๊ด€๋ฆฌ ๋ฐ ์—”ํ„ฐํ”„๋ผ์ด์ฆˆ ์ฆ๋ช…(attestation)๊ณผ ๊ฐ™์€ ํ–ฅ์ƒ๋œ ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

CTAP๋Š” ํ”ผ์‹ฑ ๊ณต๊ฒฉ์— ๋Œ€ํ•œ ๋ณด์•ˆ์„ ์–ด๋–ป๊ฒŒ ๊ฐ•ํ™”ํ•˜๋‚˜์š”?#

CTAP๋Š” ์ง€๋ฌธ๊ณผ ๊ฐ™์€ ๋ฏผ๊ฐํ•œ ์ธ์ฆ ๋ฐ์ดํ„ฐ๊ฐ€ ์‚ฌ์šฉ์ž์˜ ๊ธฐ๊ธฐ๋ฅผ ์ ˆ๋Œ€ ๋ฒ—์–ด๋‚˜์ง€ ์•Š๋„๋ก ๋ณด์žฅํ•ฉ๋‹ˆ๋‹ค. ์‚ฌ์šฉ์ž๊ฐ€ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ œ๊ณตํ•  ํ•„์š”๊ฐ€ ์—†์œผ๋ฏ€๋กœ, ์ข…์ข… ์ด๋Ÿฌํ•œ ์ž๊ฒฉ ์ฆ๋ช…์„ ํ›”์น˜๋Š” ํ”ผ์‹ฑ ๊ณต๊ฒฉ์ด ํšจ๊ณผ๊ฐ€ ์—†๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

Add passkeys to your app in <1 hour with our UI components, SDKs & guides.

Start Free Trial

Share this article


LinkedInTwitterFacebook

Related Terms