| 认证上下文类标识 | 强度等级 | 适用场景 | 强制元素 |
|---|---|---|---|
| urn:oasis:names:tc:SAML:2.0:ac:classes:Password | 20 | 低敏感度门户登录 | AuthenticationMethod |
| urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport | 30 | HTTPS加密传输认证 | AuthenticationMethod, AuthenticationInstant |
| urn:oasis:names:tc:SAML:2.0:ac:classes:Smartcard | 70 | 政务系统身份核验 | AuthenticationMethod, AuthenticationAuthority, AuthenticationInstant |
| urn:oasis:names:tc:SAML:2.0:ac:classes:MobileOneTimePassword | 80 | 移动金融交易 | AuthenticationMethod, AuthenticationAuthority, AuthenticationInstant, ContextExtension |
ContextExtension扩展机制,允许厂商在不修改核心Schema前提下,自定义认证上下文参数(如设备指纹、地理位置、网络环境),提升对新型认证技术的兼容能力。在电信运营商融合5G+云网业务场景中,该标准使用户在VoLTE通话、云盘访问、电子合同签署等不同服务间切换时,系统可依据上下文强度自动匹配认证策略,无需重复输入凭证,降低用户摩擦同时提升安全基线。
| 标准号 | 标准名称 | 状态 | 发布日期 | 实施日期 |
|---|---|---|---|---|
| YD/T 1600-2007 | 2GHz cdma2000数字蜂窝移动通信网多媒体邮件业务终端技术要求 | 现行 | 2007-05-15 | 2007-05-15 |