{"id":2198,"date":"2021-10-13T17:22:22","date_gmt":"2021-10-14T00:22:22","guid":{"rendered":"https:\/\/self-issued.info\/?p=2198"},"modified":"2021-10-13T17:29:37","modified_gmt":"2021-10-14T00:29:37","slug":"proof-of-possesion-pop-amr-method-added-to-openid-enhanced-authentication-profile-spec","status":"publish","type":"post","link":"https:\/\/self-issued.info\/?p=2198","title":{"rendered":"Proof-of-possession (pop) AMR method added to OpenID Enhanced Authentication Profile spec"},"content":{"rendered":"<p><span class=\"plain\"><img decoding=\"async\" align=\"right\" src=\"https:\/\/self-issued.info\/images\/openid-logo.png\" alt=\"OpenID logo\"><\/span>I&#8217;ve defined an Authentication Method Reference (AMR) value called &#8220;<code>pop<\/code>&#8221; to indicate that Proof-of-possession of a key was performed.  Unlike the existing &#8220;<code>hwk<\/code>&#8221; (hardware key) and &#8220;<code>swk<\/code>&#8221; (software key) methods, it is intentionally unspecified whether the proof-of-possession key is hardware-secured or software-secured.  Among other use cases, this AMR method is applicable whenever a <a href=\"https:\/\/www.w3.org\/TR\/2021\/REC-webauthn-2-20210408\/\">WebAuthn<\/a> or <a href=\"https:\/\/fidoalliance.org\/specs\/fido-v2.1-ps-20210615\/fido-client-to-authenticator-protocol-v2.1-ps-20210615.html\">FIDO<\/a> authenticator are used.<\/p>\n<p>The specification is available at these locations:<\/p>\n<ul>\n<li><a href=\"https:\/\/openid.net\/specs\/openid-connect-eap-acr-values-1_0-01.html\">https:\/\/openid.net\/specs\/openid-connect-eap-acr-values-1_0-01.html<\/a><\/li>\n<li><a href=\"https:\/\/openid.net\/specs\/openid-connect-eap-acr-values-1_0.html\">https:\/\/openid.net\/specs\/openid-connect-eap-acr-values-1_0.html<\/a><\/li>\n<\/ul>\n<p>Thanks to <a href=\"https:\/\/twitter.com\/christiaanbrand\">Christiaan Brand<\/a> for suggesting this.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#8217;ve defined an Authentication Method Reference (AMR) value called &#8220;pop&#8221; to indicate that Proof-of-possession of a key was performed. Unlike the existing &#8220;hwk&#8221; (hardware key) and &#8220;swk&#8221; (software key) methods, it is intentionally unspecified whether the proof-of-possession key is hardware-secured or software-secured. Among other use cases, this AMR method is applicable whenever a WebAuthn or [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34,14,19,25,33],"tags":[],"class_list":["post-2198","post","type-post","status-publish","format-standard","hentry","category-fido","category-openid","category-phishing-resistance","category-specifications","category-w3c"],"_links":{"self":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2198","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2198"}],"version-history":[{"count":3,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2198\/revisions"}],"predecessor-version":[{"id":2201,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2198\/revisions\/2201"}],"wp:attachment":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2198"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2198"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2198"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}