Relying Parties must have some means of discovering and verifying various characteristics of authenticators. Relying Parties can learn a subset of verifiable information for authenticators certified by the FIDO Alliance with an Authenticator Metadata statement.
Authenticator metadata statements are used directly by the UAF server at a relying party, but the information contained in the authoritative statement is used in several other places.
This section details the appropriate values for the metadata that the Authenticator provides in getInfo.
authenticatorType - Indicates whether the authenticator is bound or roaming, and whether it is first- or second-factor only.
maxKeyHandle - Indicates the maximum number of key handles this authenticator can receive and process in a single command.
userVerification - Represents a single USER_VERIFY constant.
keyProtection - Represents the bit fields defined by the KEY_PROTECTION constants
matcherProtection - Represents the bit fields defined by the MATCHER_PROTECTION constants.
tcDisplay - Represents the bit fields defined by the TRANSACTION_CONFIRMATIOM_DISPLAY constants.
authenticationAlg - The authentication algorithm supported by the authenticator.
Authenticator AAID
Each authenticator has an AAID to globally identify UAF enabled authenticator models. The AAID uniquely identifies a specific authenticator model within the range of all UAF-enabled authenticator models made by all authenticator vendors. Each AAID must relate to a distinct Authentication Metadata file.
Vendor and Model Codes
The AAID is a string in the format V#M, where
# is a separator, V indicates the authenticator Vendor Code, and M indicates the authenticator Model Code.
The Vendor Code and Model Code consists of 4 hexadecimal digits each, e.g.
AAID = 4(HEXDIG) "#" 4(HEXDIG)
The Vendor Code is assigned by the FIDO Alliance. See the Conformance Self‐Validation Testing page on the FIDO Alliance website for more details.
The Model Code is chosen by the authenticator vendor and may be an arbitrary value.
Authentication Metadata File
If you are developing your own authenticator, you need to generate metadata describing your authenticator. For more information on what goes into the metadata, see the Fido Alliance specification.
Once you generate your custom metadata, you must test it for conformance using the UAF Conformance Tool at https://conformance.fidoalliance.org/metadata (requires registration).