OIDC4AC: Extending OpenID Connect for Structured and Negotiable Authentication Contexts
Resumo
OpenID Connect (OIDC) is a widely adopted authentication protocol on the web. Despite its popularity, it provides limited expressiveness for describing how users are authenticated, constraining its applicability in high-assurance, auditable scenarios. To understand the extent of this gap, a Multivocal Literature Review was conducted, revealing the absence of an integrated, OIDC-native model for representing factors and specifying authentication requirements. To address these gaps, this paper proposes OpenID Connect for Authentication Context (OIDC4AC), a new OIDC protocol extension that enables fine-grained specification and detailed representation of authentication factors, improving interoperability and auditability.
Referências
Basili, V. R., Caldiera, G., and Rombach, H. D. (1994). The Goal Question Metric Approach. In Marciniak, J. J., editor, Encyclopedia of Software Engineering, volume 1, pages 528–532. John Wiley & Sons. ISBN: 1-54004-8.
Bray, T. (2017). The JavaScript Object Notation (JSON) Data Interchange Format. RFC 8259. DOI: 10.17487/RFC8259.
Bray, T., Paoli, J., Sperberg-McQueen, C. M., Maler, E., and Yergeau, F. (2008). Extensible Markup Language (XML) 1.0 (Fifth Edition). W3C Recommendation. [link]. Accessed: 11 May 2026.
Cantor, S., Kemp, J., Philpott, R., and Maler, E. (2005). Assertions and Protocols for the OASIS Security Assertion Markup Language (SAML) V2.0. Technical report, OASIS.
European Commission (2014). Regulation (EU) No 910/2014 on electronic identification and trust services for electronic transactions in the internal market (eidas regulation). Official Journal of the European Union (OJ L 257, 28.8.2014, pp. 73–114). [link]. Accessed: 11 May 2026.
European Commission (2016). Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). [link]. Accessed: 11 May 2026.
Garousi, V., Felderer, M., and Mäntylä, M. V. (2019). Guidelines for including grey literature and conducting multivocal literature reviews in software engineering. Information and Software Technology, 106:101–121. DOI: 10.1016/j.infsof.2018.09.006.
Hardt, D. (2012). The OAuth 2.0 Authorization Framework. RFC 6749. DOI: 10.17487/RFC6749.
Jones, M. B., Bradley, J., and Sakimura, N. (2015). JSON Web Token (JWT). RFC 7519. DOI: 10.17487/RFC7519.
Jones, M. B., Hunt, P., and Nadalin, A. (2017). Authentication Method Reference Values. RFC 8176. DOI: 10.17487/RFC8176.
Kemp, J., Cantor, S., Mishra, P., Philpott, R., Maler, E., Cahill, C., Hughes, J., Lockhart, H., Beach, M., Metz, R., et al. (2005). Authentication Context for the OASIS Security Assertion Markup Language (SAML) V2.0. Technical report, OASIS Security Services (SAML) Technical Committee. [link]. Accessed: 11 May 2026.
Kitchenham, B. A. and Charters, S. (2007). Guidelines for performing Systematic Literature Reviews in Software Engineering. EBSE Technical Report EBSE-2007-01, Keele University and Durham University. Version 2.3.
Lodderstedt, T., Bradley, J., Labunets, A., and Fett, D. (2025). Best Current Practice for OAuth 2.0 Security. RFC 9700. DOI: 10.17487/RFC9700.
Madsen, P., Patel, A., Lockhart, H., and Mishra, P. (2007). SAML 2.0 Protocol Extension for Requested Authentication Context. Technical report, OASIS Security Services (SAML) Technical Committee. [link]. Accessed: 11 May 2026.
M’Raihi, D., Hoornaert, F., Naccache, D., Bellare, M., and Ranen, O. (2005). HOTP: An HMAC-Based One-Time Password Algorithm. RFC 4226. DOI: 10.17487/RFC4226.
M’Raihi, D., Rydell, J., Pei, M., and Machani, S. (2011). TOTP: Time-Based One-Time Password Algorithm. RFC 6238. DOI: 10.17487/RFC6238.
Ometov, A., Bezzateev, S., Mäkitalo, N., Andreev, S., Mikkonen, T., and Koucheryavy, Y. (2018). Multi-factor authentication: A survey. Cryptography, 2(1). DOI: 10.3390/cryptography2010001.
Parecki, A., Hardt, D., and Lodderstedt, T. (2019). OAuth 2.1. Slides, IETF 106, Singapore. [link]. Accessed: 11 May 2026.
Petersen, K., Vakkalanka, S., and Kuzniarz, L. (2015). Guidelines for conducting systematic mapping studies in software engineering: An update. Information and Software Technology, 64:1–18. DOI: 10.1016/j.infsof.2015.03.007.
Rescorla, E. (2000). HTTP Over TLS. RFC 2818. DOI: 10.17487/RFC2818.
Sakimura, N., Bradley, J., Jones, M., De Medeiros, B., and Mortimore, C. (2014). OpenID Connect Core 1.0 incorporating errata set 1. The OpenID Foundation, specification, 335. [link]. Accessed: 11 May 2026.
Sakimura, N., Bradley, J., Jones, M., and Jay, E. (2023). OpenID Connect Discovery 1.0 incorporating errata set 2. [link]. Accessed: 16 October 2025.
Schardong, F., Giron, A. A., Müller, F. L., and Custódio, R. (2022). Post-quantum electronic identity: Adapting openid connect and oauth 2.0 to the post-quantum era. In Beresford, A. R., Patra, A., and Bellini, E., editors, Cryptology and Network Security, pages 371–390, Cham. Springer International Publishing. DOI: 10.1007/978-3-031-20974-1_20.
Temoshok, D., Proud-Madruga, D., Choong, Y.-Y., Galluzzo, R., Gupta, S., LaSalle, C., Lefkovitz, N., and Regenscheid, A. (2025). Digital Identity Guidelines. Technical Report NIST Special Publication (SP) 800-63-4, National Institute of Standards and Technology, Gaithersburg, MD. DOI: 10.6028/NIST.SP.800-63-4.
