SESSION VÀ XÁC THỰC PKCS#11
Mô hình vai trò, đăng nhập và đồng thời
Provider xác định trạng thái đăng nhập áp dụng toàn token hay theo session, cách xác thực theo ngữ cảnh hoạt động và hành vi khi failover.
01
Mô hình xác thực
| Area | Required statement |
|---|---|
| Roles | Security Officer, User and context-specific role support |
| Login scope | Token-wide versus session-specific behavior |
| PIN lifecycle | Initialization, change, retry counter and lockout |
| Step-up | Local PIN, remote approval or context login binding |
| Session expiry | Idle/absolute timeout and re-authentication |
| Pooling | Safe reuse rules and application-server guidance |
02
Đồng thời và HA
- RO/RW session limits.
- Multi-thread synchronization requirements.
- Multi-process object visibility.
- Token removal and handle invalidation.
- HA failover and session recreation.
- Long-running signing cancellation behavior.
