JSON Authentication Response Language for Protocol-Agnostic Flows
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication protocols, such as HTTP-based systems, impose specific markup and user interaction technologies, making it difficult for non-browser agents and mobile devices to handle authentication sequences effectively, and limit the flexibility in user experience and security provider interactions.
Innovation Solution
A JSON-based authentication response language is introduced, allowing server applications to express authentication steps without assuming a browser or specific user interaction, enabling non-browser agents to interpret and control the authentication process, and allowing multiple security providers to participate in the authentication sequence.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If HTTP-based authentication protocols are used, then authentication can be performed with standard web technologies, but non-browser agents and mobile devices cannot handle authentication sequences effectively
Solution Approach 1:
The patent introduces an intermediary authentication response language that mediates between the authentication server and various clients. This language translates authentication steps into a standardized format that can be understood and executed by different types of clients (web browsers, mobile devices, non-browser agents) without requiring protocol-specific handling for each device type.
Solution Approach 2:
The authentication response language is designed to be universal, enabling a single standardized protocol to serve multiple purposes across different platforms. The language can be interpreted by various client types (browsers, mobile applications, automated agents) allowing one authentication mechanism to function universally across diverse devices and environments.
2Adaptability or versatility
If specific markup and user interaction technologies are imposed, then authentication can be controlled precisely, but flexibility in user experience and security provider interactions is limited
Solution Approach 1:
The authentication sequence is segmented into discrete, standardized steps defined in the authentication response language. Each step can be independently controlled and executed, allowing flexible composition of different authentication flows while maintaining manageable complexity through standardization rather than markup-based control.
Solution Approach 2:
The system uses parameter changes within the standardized authentication response language to control different aspects of authentication. Instead of relying on specific markup or interaction technologies, the system varies parameters such as step sequences, timing, and interaction types to achieve different user experiences and security provider interactions.
3Ease of operation
If browser-based authentication is assumed, then user interaction can be simplified, but non-browser agents are excluded from the authentication process
Solution Approach 1:
The authentication response language is designed with universal interpretability that works across multiple agent types. The same standardized language can be executed by web browsers, mobile devices, and non-browser agents (such as automated systems or specialized applications), eliminating the need for separate authentication mechanisms for different platforms.
Data Source
AI summary
An enterprise server is provisioned with an authentication response language, where the authentication response language allows the enterprise server to issue instructions for authentication steps to an enterprise client, which enables the enterprise client to execute a set of instructions for navigating an authentication sequence. The set of instructions installed into and served by the enterprise server varies depending on a protocol inherently used by the authentication topology. The enterprise client, when accessing a protected resource, and not already authenticated, receives a set of authentication instructions from the enterprise server formulated in the authentication response language. The client starts to interpret the provided authentication instructions, but controls the presentation layer and interface of any user interactions. The client follows the sequence by sending requests and receiving responses from one or more servers in the topology until the sequence is complete.


