9.1.2 –> 9.1.3 . mode : aareq –> art_req. 署名検証には“assoc_handle”が必要だと思います。
.23. Artifact Authentication Request
When Authentication Request is sent over direct communication, the RP can send the companion Artifact Authentication Request to the OP. Parameters are as follows:
Value: The Artifact value returned by OP on direct authentication request. See Section 9.1.1. This value MUST be sent if this message is used in conjunction with a direct authentication request.
Value: Comma-separated list of signed fields.
Note: Since there is only two parameters, mode and artifact, it will be "mode,artifact".
Value: Base 64 encoded signature calculated as specified in Section 6.
Value:A handle for an association between the Relying Party and the OP that SHOULD be used to sign the response.