%% You should probably cite rfc9470 instead of this I-D. @techreport{ietf-oauth-step-up-authn-challenge-17, number = {draft-ietf-oauth-step-up-authn-challenge-17}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-oauth-step-up-authn-challenge/17/}, author = {Vittorio Bertocci and Brian Campbell}, title = {{OAuth 2.0 Step Up Authentication Challenge Protocol}}, pagetotal = 14, year = 2023, month = jun, day = 26, abstract = {It is not uncommon for resource servers to require different authentication strengths or recentness according to the characteristics of a request. This document introduces a mechanism that resource servers can use to signal to a client that the authentication event associated with the access token of the current request does not meet its authentication requirements and, further, how to meet them. This document also codifies a mechanism for a client to request that an authorization server achieve a specific authentication strength or recentness when processing an authorization request.}, }