...
This document defines how a SWAMID member organisation SHOULD implement a Strong Authentication solution in order to be certified by SWAMID for Strong Authentication in a federated environment. A strong authentication Strong Authentication combines the use of multi-factor authentication with a high assurance that the multi-factor authenticator is distributed to the intended Subject.
This strong authentication profile is an Strong Authentication Profile is a Swedish Higher Education Institution extension to REFEDS Multi-Factor Authentication (MFA) Profile [1] and is applicable for Swedish Higher Education.
Guidance: The intended use of this SWAMID profile is when authentication must be done with a high assurance that it is the correct Subject that is accessing a specific service. Please note that it is possible, or even preferred, to use multi-factor authentication without this high level of assurance in a federated environment but that use does not fulfil this strong authentication profile.
...
In a SAML assertion, compliance with this Strong Authentication Profile is communicated by asserting the AuthnContextClassRef: https://refeds.org/profile/mfa
...