+--------+ +----------+ +--------+ | Origin | | Attacker | | Client | +---+----+ +----+-----+ +---+----+ | | | +--- TokenChallenge -->| | | +-- (reflect challenge) -->| | |<-------- Token ----------+ |<-- (reflect token) --+ | | | |