Authentication指确认一个在请求服务的用户是这个资源的有效用户.
Authentication是通过identity和credentials的描述实现的. credentials的类型有passwords, one-time tokens, digital certificates, phone numbers (calling/called).