Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

*F_SELECTION User Selects Factor

User selects a new factor/authenticator for multi factor authentication.

Typically there are different factor (types), #short description ( e.g. from different factor types and factor realizations/products)something you know/have/are, the user may choose from as well as multiple realization options/products (e.g. Yubikey, Google Authenticator).

REFERENCED FROM: B

*F_AUTHENTICATION

...

generic action. action may be used for 1F, 2F,... authentication

action may have multiple purposes, e.g. serves as intial binding between digitalID and factor (reference to B_DIGITALID ?)

REFERENCED FROM: B


check possession of first factor → include activity, see 3.1

...

Establishment of a binding between the digital identity of the user and factor

AttributeX: Some later detailed attributes could come here.

...

(Optional) F_SELECTION DEFINED AT: F

Selection of a particular factor/authenticator may take place at some later point of time.

token/product takes places after identity vetting. Besides the selection by the user an assignment by of a factor/authenticator e.g. by the registration desk is possible, too.

B_DIGITALID Bind factor to digital ID

Create an initial binding between the newly selected factor and the digitalID of the user.

Typically this binding needs to be verified requiring some user interaction before it is put into effect.

 performed after successful identity vetting. → or with test authN at very beginning#short description

(Optional) *F_AUTHENTICATION DEFINED AT: F

...

B_ACTIVATE Activate Binding Between of Digital ID and New Factor

Activate the binding of the digital ID of the user and the new factor.

This action is triggered by the registration authority.#short description

B_RECORD Create Record of Binding → delete???

...

B_CONFIRMATION Inform User about Factor Activation

Inform the user about the correct or incorrect activation of the factor.

In case the factor activation was successful the user can now authenticate using more than one factor.

This action is triggered by the registration authority.#short description



------------------------------------------------------ Template for providing example realization options ---------------------------------------------------------------------

...