Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

This document defines how a SWAMID member organisation SHOULD implement a Strong Authentication solution in order to be certified by SWAMID for Strong Authentication in a federated environment. A strong authentication Strong Authentication combines the use of multi-factor authentication with a high assurance that the multi-factor authenticator is distributed to the intended Subject. 

This strong authentication profile is an Strong Authentication Profile is a Swedish Higher Education Institution extension to REFEDS Multi-Factor Authentication (MFA) Profile [1] and is applicable for Swedish Higher Education.


Guidance: The intended use of this SWAMID profile is when authentication must be done with a high assurance that it is the correct Subject that is accessing a specific service. Please note that it is possible, or even preferred, to use multi-factor authentication without this high level of assurance in a federated environment but that use does not fulfil this strong authentication profile.

...

In a SAML assertion, compliance with this Strong Authentication Profile is communicated by asserting the AuthnContextClassRef: https://refeds.org/profile/mfa

...