When requesting authentication from the HIN broker, the client system (service provider) can specify the required authentication security level. This is enforced by the IDP during the end-user's authentication. The desired level can be specified in the SAML authentication request using the “Authentication Context Class Reference.”
The highest level is multi-factor authentication. This is based on logging in with a password and a second factor. The second factor is verified using the HIN Client, mTAN (one-time SMS code), or the HIN Authenticator app. Users within an institution with HIN Access Gateway must first have linked their Windows account to their personal HIN identity or a team identity.
Example of the authentication context in SAML:
<samlp:RequestedAuthnContext Comparison="exact">
<saml:AuthnContextClassRef>https://hin.ch/profile/mfa</saml:AuthnContextClassRef></samlp:RequestedAuthnContext>
Do you have any further questions?
Please contact us if your question could not be answered.