A requesting message processor identifies client security input data of a
first format and encapsulates the client security input data within a
client security token. A requesting token processing interface sends the
client security token to a validating message processor. A validating
token processing interface at the validating message processor receives
the client security token. Based on the encapsulated client security
input data, the validating message processor selects client security
output data of a second format. The validating message processor
encapsulates the security output data within a response security token.
The validating token processing interface sends the response security
token to the requesting message processor. The token processing
interfaces can be configured to similarly abstract security input data
and security output data so as to increase the possibility of compatible
communication between the requesting and validating message processor.