LOGBOOK

HELP

Quiz Entry - updated: 2026.09.17

What does the IdP's authentication service do, step by step, when a subject logs in?

It authenticates the subject promptly by checking the claimed identity: it verifies the presented authentication means against the stored credentials and, on success, issues an authentication confirmation, optionally together with an attribute confirmation.

The subject presents its authentication means, the IdP verifies them against stored credentials and issues an authentication confirmation and optionally an attribute confirmation to the relying party

* The authentication service verifies the presented means against stored credentials and issues confirmations to the relying party. *

The sequence:

  1. The subject presents its authentication means (types the password, presents the certificate, confirms on the phone).
  2. The service verifies these against the credentials it stores for the claimed identity. Credentials are the IdP's side of the binding: a password hash, a public key, a registered device.
  3. On a positive result it issues an authentication confirmation (an assertion or token stating "this subject was authenticated at this time with this strength").
  4. Optionally it adds an attribute confirmation: attested attributes such as name or e-mail that the relying party can trust without verifying them itself.

The relying party only ever sees the confirmations, never the credentials. That separation is the whole point of having an IdP: secrets stay in one well-protected place, and applications consume signed statements instead.

From Quiz: IAM / IAM Fundamentals: Terms, Identity and Actors | Updated: Sep 17, 2026