When requesting authentication from the HIN broker, the client system (service provider) can specify the required authentication security level. This is enforced by the IDP during the end-user's authentication. The desired level can be specified in the SAML authentication request using the “Authentication Context Class Reference.”

 

The highest level is multi-factor authentication. This is based on logging in with a password and a second factor. The second factor is verified using the HIN Client, mTAN (one-time SMS code), or the HIN Authenticator app. Users within an institution with HIN Access Gateway must first have linked their Windows account to their personal HIN identity or a team identity.

 

Example of the authentication context in SAML:

 

<samlp:RequestedAuthnContext Comparison="exact">
  <saml:AuthnContextClassRef>https://hin.ch/profile/mfa</saml:AuthnContextClassRef></samlp:RequestedAuthnContext>

Do you have any further questions?

Please contact us if your question could not be answered.