Autentikasi Multifaktor (MFA)
Jelajahi cara MFA terintegrasi dengan alur OIDC untuk menambahkan lapisan keamanan ekstra pada autentikasi pengguna.
Autentikasi Multifaktor (MFA) adalah pelajaran OAuth2 & OpenID Connect Deep Dive gratis di CoddyKit. Ini adalah pelajaran 3 dari 4. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar OAuth2 & OpenID Connect Deep Dive, dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus OAuth2 & OpenID Connect Deep Dive mencakup 4 pelajaran total.
Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.
What is Multi-Factor Authentication?
Multi-Factor Authentication (MFA) adds an extra layer of security to user accounts beyond just a password.
Instead of relying on a single piece of evidence (like "something you know"), MFA requires two or more verification methods from different categories.
The "Factors" of MFA
MFA typically combines factors from these categories:
- Something you know: A password or PIN.
- Something you have: A phone, hardware token, or authenticator app.
- Something you are: A fingerprint, face scan, or voice recognition.
Using multiple factors makes it much harder for unauthorized users to gain access.
Why MFA in OIDC?
OpenID Connect (OIDC) itself doesn't perform MFA. Instead, it acts as a secure way for an Identity Provider (IdP) to tell your application whether a user authenticated with MFA.
Your application can then use this information to make informed authorization decisions.
Introducing ACR Values
In OIDC, "Authentication Context Class References" (ACR values) are used to specify how a user was authenticated.
These are unique identifiers that represent different levels or methods of authentication, including whether MFA was used.
Requesting a Specific ACR Level
When your application initiates an OIDC authorization request, it can include the acr_values parameter.
This parameter tells the Identity Provider that your application prefers or requires a specific authentication context, such as MFA.
Example: Requesting MFA
Here's a simplified example of an OIDC authorization URL requesting an MFA context. The specific acr_values like "mfa" or "https://acr.example.com/mfa" depend on the Identity Provider's configuration.
public class Main {
public static void main(String[] args) {
String authUrl = "https://idp.example.com/authorize?"
+ "response_type=code"
+ "&client_id=my_client_app"
+ "&redirect_uri=https://app.example.com/callback"
+ "&scope=openid%20profile"
+ "&acr_values=mfa";
System.out.println("Authorization URL:\n" + authUrl);
}
}Receiving MFA Status in the ID Token
After successful authentication, the Identity Provider returns an ID Token to your application. This token contains various claims about the user and their authentication session.
The acr claim within the ID Token indicates the actual authentication context class reference that was satisfied.
Example: Decoding an ID Token with 'acr'
Let's imagine an ID Token payload after a user authenticated with MFA. The acr claim would be present, confirming the authentication method used.
In a real application, you would decode and validate the JWT to read this claim.
public class Main {
public static void main(String[] args) {
// Example of a decoded ID Token payload
// In a real app, you'd parse a JWT.
String idTokenPayload = "{\n \"iss\": \"https://idp.example.com\",\n \"sub\": \"user123\",\n \"aud\": \"my_client_app\",\n \"exp\": 1678886400,\n \"iat\": 1678882800,\n \"auth_time\": 1678882700,\n \"acr\": \"mfa\",\n \"amr\": [\"pwd\", \"otp\"]\n}";
System.out.println("Simulated ID Token Payload:\n" + idTokenPayload);
}
}Enforcing MFA-Based Policies
Once your application receives and validates the ID Token, it can check the acr claim.
Based on this, you can implement conditional access policies. For example, if a user tries to access sensitive data, and the acr claim doesn't indicate MFA, you might deny access or prompt for re-authentication.
Quick Check
Which OIDC parameter is used by a client application to request that a user authenticates with Multi-Factor Authentication?
Recap: MFA & OIDC
We've learned that MFA adds critical security layers by requiring multiple authentication factors.
OIDC doesn't perform MFA itself, but it provides a standardized way (via acr_values in requests and the acr claim in ID Tokens) for applications to request and receive information about the authentication context, enabling robust, MFA-aware security policies.
Belajar OAuth2 & OpenID Connect Deep Dive dengan tutor AI — gratis
Tulis dan jalankan kode asli di browser kamu, dapatkan bantuan instan dari tutor AI 24/7, dan lanjutkan di mana kamu tinggalkan di web atau aplikasi.
- Kursus
- 12
- Pelajaran
- 48
Pertanyaan yang Sering Diajukan
Apakah pelajaran “Autentikasi Multifaktor (MFA)” gratis?
Ya — teks lengkap “Autentikasi Multifaktor (MFA)” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus OAuth2 & OpenID Connect Deep Dive, upgrade ke CoddyKit PRO. Kursus OAuth2 & OpenID Connect Deep Dive mencakup 4 pelajaran total.
Apa yang akan aku pelajari di “Autentikasi Multifaktor (MFA)”?
Jelajahi cara MFA terintegrasi dengan alur OIDC untuk menambahkan lapisan keamanan ekstra pada autentikasi pengguna. Kamu berlatih OAuth2 & OpenID Connect Deep Dive dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.
Apakah aku perlu pengalaman untuk memulai OAuth2 & OpenID Connect Deep Dive?
Tidak diperlukan pengalaman sebelumnya. OAuth2 & OpenID Connect Deep Dive di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 3 dari 4.
Berapa lama pelajaran “Autentikasi Multifaktor (MFA)” memakan waktu?
Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.
Bisakah aku menulis dan menjalankan kode dalam pelajaran OAuth2 & OpenID Connect Deep Dive ini?
Ya. Setiap pelajaran OAuth2 & OpenID Connect Deep Dive menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.
Semua pelajaran dalam kursus ini
- Integrasi dengan Penyedia Identitas
- Keamanan Layanan Mikro dan Gateway API
- Autentikasi Multifaktor (MFA)
- Single Sign-On di Berbagai Aplikasi