OASIS Security Services TC
Hal Lockhart, BEA Systems, Inc
Prateek Mishra, Oracle
Sharon Boeyen (firstname.lastname@example.org), Entrust
Thomas Wisniewski (email@example.com), Entrust
The current set of standardized SAML V2.0 authentication context definitions cover a subset of challenge/response schemes including those that are based on cryptographic functions and time-based tokens. The notion of text-based challenge/response tokens are not covered by any of the current authentication context definitions.
This document proposes an authentication context class to cover the general case of text-based challenge/response tokens to facilitate signaling their use in SAML. Such schemes include, for example, scratch tokens, numbered list tokens, grid tokens, etc. associated with a challenge/response authentication function. This document also proposes an extension that enables text-based challenge/response token parameters to be specified in relevant authentication contexts. This extension would be included in the <PrincipalAuthenticationMechanism> of such contexts.
This is a Committee Draft approved by the Security Services Technical Committee on 26 September 2006.
Committee members should submit comments and potential errata to the firstname.lastname@example.org/committees/comments/form.php?wg_abbrev=security. The committee will publish on its web page (http://www.oasis-open.org/committees/security) a catalog of any changes made to this document as a result of comments.
For information on whether any patents have been disclosed that may be essential to implementing this specification, and any offers of patent licensing terms, please refer to the Intellectual Property Rights web page for the Security Services TC (http://www.oasis-open.org/committees/security/ipr.php).
Table of Contents
1 Introduction 3
2 Text-Based Challenge/Response Token Extension 4
Element <tcr:TextChallengeResponseToken> 4
3 Text-Based Challenge/Response Authentication Context Class 6
4 References 7
Appendix A. Notices 8
The current set of SAML V2.0 authentication context class definitions covers a subset of challenge/response schemes, including those that are based on cryptographic functions and time-based tokens. Authentication using text-based challenge/response tokens is not covered by any of the current authentication context class specifications.
The SAML Authentication Context schema [SAMLAC-xsd] provides extension points through the <Extension> element so that elements in non-SAML namespaces can be added to declarations and class definitions.
This specification defines an extension to the SAML V2.0 Authentication Context core schema specification that can be optionally used to convey parameters associated with text-based challenge/response tokens. This specification also introduces one new authentication context class for use with text-based challenge/response tokens.
This specification uses normative text.
The keywords "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", “SHOULD NOT”, “RECOMMENDED”, “MAY”, AND “OPTIONAL” in this specification are to be interpreted as described in [RFC 2119].
Conventional XML namespace prefixes are used throughout the listings in this specification to stand for their respective namespaces as follows, whether or not a namespace declaration is present in the example:
This is the SAML V2.0 assertion namespace [SAMLCore].
This is the SAML new core authentication context schema namespace for SAML V2.0 [SAMLAuthnCtx].
This namespace is defined in the W3C XML Schema specification [SAMLCore] .
This is the text-based challenge/response token extension namespace developed herein and in the accompanying schema [TCR-xsd].
In some environments authentication is performed using text-based challenge/response tokens of various types such as scratch tokens, grid tokens and numbered list tokens. These tokens share a common set of parameters that are key to the assessment of the quality of the authentication performed.
This section defines an extension to the SAML V2.0 authentication context schema that can be used to express these parameters in an authentication context. The extension may optionally appear within the <ac:PrincipalAuthenticationMechanismType> element.
The <tcr:TextChallengeResponseToken> element is used to indicate the use of a text-based challenge/response token in authentication.
The following schema fragment defines the <tcr:TextChallengeResponseToken> element:
An overview of the the sub-elements contained within this element is provided below:
<tcr:TokenDescription>: This element is mandatory and contains a URI that points to a description of the type of text-based challenge/response mechanism used in conjunction with the token (for example, scratch, grid, etc.).
<tcr:TokenParameters>: If present, this element provides the necessary information about an authentication to enable a determination of the quality of that authentication. These parameters include an indication of the number of possible challenges (e.g., number of scratch boxes on a scratch token, number of cells on a grid token, etc.), an indication of the number of possible values for each challenge (e.g., the total number of possible images that could be contained in each box on a scratch card) and the number of challenges conducted as part of a specific authentication instance.
<tcr:TokenAuthenticated>: If present, this element indicates whether a check is conducted to ensure the proper token was used (e.g., a serial number check was conducted).
Following is an example of an Authentication Context declaration in which a scratch card challenge/response token was used. In this example, there are 50 spaces on the scratch card, of which 4 were challenged. There are 150 values that could appear in each space. Also, in this example, the identity of the scratch card was verified.
The following Authentication Context class is defined to represent authentication using text-based challenge/response tokens and makes use of the text-based challenge/response token extension.
This class defines a text-based challenge/response token used in authentication.
[RFC 2119] S. Bradner. Key words for use in RFCs to indicate requirement levels. IETF RFC 2119, March 1997. http://www.ietf.org/rfc/rfc2119.txt.
[SAMLAC-xsd] J. Kemp et al. SAML authentication context schema. OASIS SSTC, March 2005. See http://docs.oasis-open.org/security/saml/v2.0/saml-schema-authn-context-2.0.xsd.
[SAMLAuthnCtx] J. Kemp et al. Authentication Context for the OASIS Security Assertion Markup Language (SAML) V2.0. OASIS SSTC, March 2005. Document ID saml-authncontext-2.0-os. http://docs.oasis-open.org/security/saml/v2.0/saml-authn-context-2.0-os.pdf.
[SAMLCore] S. Cantor et al. Assertions and Protocols for the OASIS Security Assertion Markup Language (SAML) V2.0. OASIS SSTC, March 2005. Document ID saml-core-2.0-os. http://docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf .
[TCR-xsd] S. Boeyen and T. Wisniewski. SAML Text-based Challenge/Response Token Authentication Context extension schema. OASIS SSTC, July 2006. Document ID sstc-saml-authncontext-tcr.xsd. See http://www.oasis-open.org/committees/security/.
OASIS takes no position regarding the validity or scope of any intellectual property or other rights that might be claimed to pertain to the implementation or use of the technology described in this document or the extent to which any license under such rights might or might not be available; neither does it represent that it has made any effort to identify any such rights. Information on OASIS's procedures with respect to rights in OASIS specifications can be found at the OASIS website. Copies of claims of rights made available for publication and any assurances of licenses to be made available, or the result of an attempt made to obtain a general license or permission for the use of such proprietary rights by implementors or users of this specification, can be obtained from the OASIS Executive Director.
OASIS invites any interested party to bring to its attention any copyrights, patents or patent applications, or other proprietary rights which may cover technology that may be required to implement this specification. Please address the information to the OASIS Executive Director.
Copyright © OASIS Open 2006. All Rights Reserved.
This document and translations of it may be copied and furnished to others, and derivative works that comment on or otherwise explain it or assist in its implementation may be prepared, copied, published and distributed, in whole or in part, without restriction of any kind, provided that the above copyright notice and this paragraph are included on all such copies and derivative works. However, this document itself does not be modified in any way, such as by removing the copyright notice or references to OASIS, except as needed for the purpose of developing OASIS specifications, in which case the procedures for copyrights defined in the OASIS Intellectual Property Rights document must be followed, or as required to translate it into languages other than English.
The limited permissions granted above are perpetual and will not be revoked by OASIS or its successors or assigns.
This document and the information contained herein is provided on an “AS IS” basis and OASIS DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.
sstc-saml-text-based-challenge-response-authn-context-class-cd-01 26 September 2006
Copyright © OASIS Open
2006. All Rights Reserved. Page