Bringing Semantics to Authentication: An OpenID Connect Extension

Brendon Vicente R. Silva, Frederico Schardong, Ricardo Felipe Custódio · 2025

OpenID Connect (OIDC) is a widely adopted authentication protocol, yet it offers limited expressiveness when conveying details about how a user was authenticated. The Authentication Methods References (amr) claim used for this purpose lacks structure and semantic clarity, hindering scenarios that require higher assurance. This paper proposes an extension to OIDC that introduces the amr details claim — a structured, interoperable mechanism for describing authentication factors along with relevant metadata, such as assurance levels and trust frameworks. By enhancing the protocol’s expressiveness without compromising compatibility, the extension enables granular access control, thereby contributing to increased trust in distributed identity systems.

Read the paper · More papers on PaperTik