Slide 21
Slide 21 text
03 Step-up 認証による実現
追加の認証を求める⽅法は、RFC 9470(Step-up Auth)で標準化されている
前提:クライアントは、通常の認証で取得したアクセストークンにより、普段のリソースを使えている
クライアント
リソースサーバー(RS)
認可サーバー(AS)
① より強い認証が要るリソースを呼ぶ
② acr / auth_time が⾜りないと判断
③ 401 Unauthorized
WWW-Authenticate: Bearer
error="insufficient_user_authentication",
acr_values="…" / max_age=…
④ acr_values / max_age を付けて認可リクエスト
⑤ 認証し直し、新しいトークン(acr / auth_time ⼊り)を返す
⑥ 新しいトークンでやり直す(通る)
acr(Authentication Context Class Reference):満たした認証の種類、auth_time:認証した時刻
acr_values:リソースが求める認証の種類、max_age(Maximum Authentication Age):前回の認証から許容する経過時間(秒)
出典: https://www.rfc-editor.org/rfc/rfc9470.html
© 2026 Loglass Inc.
21