JSON Authentication Response Language for Protocol-Agnostic Flows

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication protocols, such as HTTP-based systems, impose specific markup and user interaction technologies, making it difficult for non-browser agents and mobile devices to handle authentication sequences effectively, and limit the flexibility in user experience and security provider interactions.

Innovation Solution

A JSON-based authentication response language is introduced, allowing server applications to express authentication steps without assuming a browser or specific user interaction, enabling non-browser agents to interpret and control the authentication process, and allowing multiple security providers to participate in the authentication sequence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If HTTP-based authentication protocols are used, then authentication can be performed with standard web technologies, but non-browser agents and mobile devices cannot handle authentication sequences effectively

Engineering Contradiction:
Improvecompatibility with different devices and agentsVSAvoidauthentication handling capability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary authentication response language that mediates between the authentication server and various clients. This language translates authentication steps into a standardized format that can be understood and executed by different types of clients (web browsers, mobile devices, non-browser agents) without requiring protocol-specific handling for each device type.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication response language is designed to be universal, enabling a single standardized protocol to serve multiple purposes across different platforms. The language can be interpreted by various client types (browsers, mobile applications, automated agents) allowing one authentication mechanism to function universally across diverse devices and environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If specific markup and user interaction technologies are imposed, then authentication can be controlled precisely, but flexibility in user experience and security provider interactions is limited

Engineering Contradiction:
Improveflexibility in user experienceVSAvoidauthentication sequence complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication sequence is segmented into discrete, standardized steps defined in the authentication response language. Each step can be independently controlled and executed, allowing flexible composition of different authentication flows while maintaining manageable complexity through standardization rather than markup-based control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses parameter changes within the standardized authentication response language to control different aspects of authentication. Instead of relying on specific markup or interaction technologies, the system varies parameters such as step sequences, timing, and interaction types to achieve different user experiences and security provider interactions.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If browser-based authentication is assumed, then user interaction can be simplified, but non-browser agents are excluded from the authentication process

Engineering Contradiction:
Improveuser interaction simplicityVSAvoidsupport for multiple agent types
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The authentication response language is designed with universal interpretability that works across multiple agent types. The same standardized language can be executed by web browsers, mobile devices, and non-browser agents (such as automated systems or specialized applications), eliminating the need for separate authentication mechanisms for different platforms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10218690B2Abstracting an authentication sequence using HTTP
Publication Date: 2019.02.26 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10218690B2 patent drawing
  • US10218690B2 patent drawing
  • US10218690B2 patent drawing

AI summary

An enterprise server is provisioned with an authentication response language, where the authentication response language allows the enterprise server to issue instructions for authentication steps to an enterprise client, which enables the enterprise client to execute a set of instructions for navigating an authentication sequence. The set of instructions installed into and served by the enterprise server varies depending on a protocol inherently used by the authentication topology. The enterprise client, when accessing a protected resource, and not already authenticated, receives a set of authentication instructions from the enterprise server formulated in the authentication response language. The client starts to interpret the provided authentication instructions, but controls the presentation layer and interface of any user interactions. The client follows the sequence by sending requests and receiving responses from one or more servers in the topology until the sequence is complete.