多因素身份验证(MFA)
探索 MFA 如何与 OIDC 流程集成,为用户身份验证增加额外的安全层。
多因素身份验证(MFA) 是 CoddyKit 上的免费 OAuth2 & OpenID Connect Deep Dive 课时。 这是第 3 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 OAuth2 & OpenID Connect Deep Dive 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 OAuth2 & OpenID Connect Deep Dive 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
What is Multi-Factor Authentication?
Multi-Factor Authentication (MFA) adds an extra layer of security to user accounts beyond just a password.
Instead of relying on a single piece of evidence (like "something you know"), MFA requires two or more verification methods from different categories.
The "Factors" of MFA
MFA typically combines factors from these categories:
- Something you know: A password or PIN.
- Something you have: A phone, hardware token, or authenticator app.
- Something you are: A fingerprint, face scan, or voice recognition.
Using multiple factors makes it much harder for unauthorized users to gain access.
Why MFA in OIDC?
OpenID Connect (OIDC) itself doesn't perform MFA. Instead, it acts as a secure way for an Identity Provider (IdP) to tell your application whether a user authenticated with MFA.
Your application can then use this information to make informed authorization decisions.
Introducing ACR Values
In OIDC, "Authentication Context Class References" (ACR values) are used to specify how a user was authenticated.
These are unique identifiers that represent different levels or methods of authentication, including whether MFA was used.
Requesting a Specific ACR Level
When your application initiates an OIDC authorization request, it can include the acr_values parameter.
This parameter tells the Identity Provider that your application prefers or requires a specific authentication context, such as MFA.
Example: Requesting MFA
Here's a simplified example of an OIDC authorization URL requesting an MFA context. The specific acr_values like "mfa" or "https://acr.example.com/mfa" depend on the Identity Provider's configuration.
public class Main {
public static void main(String[] args) {
String authUrl = "https://idp.example.com/authorize?"
+ "response_type=code"
+ "&client_id=my_client_app"
+ "&redirect_uri=https://app.example.com/callback"
+ "&scope=openid%20profile"
+ "&acr_values=mfa";
System.out.println("Authorization URL:\n" + authUrl);
}
}Receiving MFA Status in the ID Token
After successful authentication, the Identity Provider returns an ID Token to your application. This token contains various claims about the user and their authentication session.
The acr claim within the ID Token indicates the actual authentication context class reference that was satisfied.
Example: Decoding an ID Token with 'acr'
Let's imagine an ID Token payload after a user authenticated with MFA. The acr claim would be present, confirming the authentication method used.
In a real application, you would decode and validate the JWT to read this claim.
public class Main {
public static void main(String[] args) {
// Example of a decoded ID Token payload
// In a real app, you'd parse a JWT.
String idTokenPayload = "{\n \"iss\": \"https://idp.example.com\",\n \"sub\": \"user123\",\n \"aud\": \"my_client_app\",\n \"exp\": 1678886400,\n \"iat\": 1678882800,\n \"auth_time\": 1678882700,\n \"acr\": \"mfa\",\n \"amr\": [\"pwd\", \"otp\"]\n}";
System.out.println("Simulated ID Token Payload:\n" + idTokenPayload);
}
}Enforcing MFA-Based Policies
Once your application receives and validates the ID Token, it can check the acr claim.
Based on this, you can implement conditional access policies. For example, if a user tries to access sensitive data, and the acr claim doesn't indicate MFA, you might deny access or prompt for re-authentication.
Quick Check
Which OIDC parameter is used by a client application to request that a user authenticates with Multi-Factor Authentication?
Recap: MFA & OIDC
We've learned that MFA adds critical security layers by requiring multiple authentication factors.
OIDC doesn't perform MFA itself, but it provides a standardized way (via acr_values in requests and the acr claim in ID Tokens) for applications to request and receive information about the authentication context, enabling robust, MFA-aware security policies.
常见问题解答
「多因素身份验证(MFA)」课时是免费的吗?
是的 — 「多因素身份验证(MFA)」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 OAuth2 & OpenID Connect Deep Dive 课程的其余内容,请升级到 CoddyKit PRO。 OAuth2 & OpenID Connect Deep Dive 课程共包含 4 节课。
「多因素身份验证(MFA)」这节课中我会学到什么?
探索 MFA 如何与 OIDC 流程集成,为用户身份验证增加额外的安全层。 你通过在浏览器中直接运行的动手代码来练习 OAuth2 & OpenID Connect Deep Dive,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 OAuth2 & OpenID Connect Deep Dive 需要有经验吗?
无需任何先前经验。CoddyKit 上的 OAuth2 & OpenID Connect Deep Dive 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 3 节课,共 4 节。
「多因素身份验证(MFA)」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 OAuth2 & OpenID Connect Deep Dive 课中编写并运行代码吗?
能。每节 OAuth2 & OpenID Connect Deep Dive 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。
此课程中的所有课时
- 与身份提供商集成
- 微服务与 API 网关安全
- 多因素身份验证(MFA)
- 跨应用单点登录