Token exchange between bearer and pop tokens
Techniques are disclosed for exchanging tokens between different identity systems that follow different identity models. A token exchange system of an integrated identity management system of a cloud service can determine that an entity is authorized to access a first identity system based on credentials of the entity entered in the first identity system. The token exchange system can exchange a first token for the first identity system for a second token for the second identity system without requiring entry of credentials to access the second identity system.
1 . A method comprising:
determining, by a token exchange system of an integrated identity management system of a cloud service, that an entity is authorized to access a first identity system, wherein the entity has a first token that is a bearer token of an identity cloud service (IDCS) or a Proof-of-Possession (POP) token of an identity and access management system (IAM);
receiving, by the token exchange system from the entity of the first identity system, a request to access a second identity system;
verifying, by the token exchange system, the first token;
generating, by the token exchange system, a second token for the second identity system based on the first token for the first identity system, wherein when the first token is the bearer token of the identity cloud service (IDCS) then the second token generated by the token exchange system is the Proof-of-Possession token, and when the first token is the Proof-of-Possession token of the identity and access management system (IAM) then the second token generated by the token exchange system is the bearer token,
wherein the second token includes token data for a type of identity system that is different from the first token,
wherein the second identity system for which the second token is generated is a different type of identity management system than the first identity system;
exchanging, by the token exchange system, the first token for the first identity system with the generated second token for the second identity system that is different from the first token for the second identity system;
authenticating, by the token exchange system, the entity to access the second identity system based on the second token; and
authorizing, by the token exchange system, the entity to access an application programming interface (API) of the second identity system using the second token.
2 . The method according to claim 1 , wherein the entity is authorized to access the API of the second identity system using the second token without requiring entry of entity credentials in the second identity system.
3 . The method according to claim 2 , wherein the entity is determined to be authorized to access the first identity system based on credentials of the entity for the first identity system.
4 . The method according to claim 1 , wherein the request is signed by an identity of the entity, and wherein the verifying the first token comprises verifying a signature of the first token.
5 . The method according to claim 1 , further comprising after generating the second token, signing, by the token exchange system, the second token with a private key of the entity to generate a second signed token.
6 . The method according to claim 1 , wherein the first identity system has a first system model, and wherein the second identity system has a second system model that has different specifications from the first system model.
7 . The method according to claim 1 , wherein the entity is an integrated cloud service application,
wherein the integrated cloud service application is a SaaS application, a PaaS application or a fusion application.
8 . The method according to claim 1 , further comprising:
storing, by the token exchange system, the first token for the first identity system and the second token for the second identity system, in a token store; and
maintaining, by the token exchange system, the first token for the first identity system and the second token for the second identity system in the token store during a session of the entity with the first identity system and the second identity system.
9 . The method according to claim 8 , wherein the session is a predetermined period of time, and the method further comprising removing, by the token exchange system, the first token for the first identity system and the second token for the second identity system, in the token store at an end of the session.
10 . The method according to claim 1 , wherein the request to access the second identity system is received on an integration console, and wherein the integration console is configured to call a token exchange.
11 . The method according to claim 1 , wherein the first identity system is an Identity Cloud Service (IDCS) system that follows a first specification comprising first rules, and the second identity system is an Identity and Access Management (IAM) system that follows a second specification comprising second rules, wherein the second specification is different from the first specification.
12 . The method according to claim 1 , further comprising after the entity is authenticated to access the second identity system based on the second token, authorizing the entity to re-access an application programming interface (API) of the first identity system, that is a different type of identity management system from the second identity system, without reauthenticating the entity.
13 . The method according to claim 1 , further comprising after the entity is authenticated to access the second identity system based on the second token, authorizing the entity to re-access an application programming interface (API) of the first identity system by converting the second token to the first token that is compatible with the first identity system,
wherein if the second token is the bearer token of the identity cloud service (IDCS) then the second token is converted back to the first token that is the Proof-of-Possession token, and if the second token is the Proof-of-Possession token of the identity and access management system (IAM) then the second token is converted back to the first token that is the bearer token.
14 . The method according to claim 1 , wherein the first token comprises first privileges associated with accessing the first identity system, wherein the second token comprises second privileges associated with accessing the second identity system, and wherein the first privileges are different from the second privileges.
15 . The method according to claim 1 , wherein when the first identity system is an IAM system, the request to access the second identity system is signed with an IAM PoP/API key.
16 . The method according to claim 1 , wherein the bearer token is associated with a bearer token identity for a SaaS application, a PaaS application or a fusion application (FA), and the token exchange system is configured to exchange the bearer token identity for a resource principal session token (RSPT) identity associated with the POP token that configures an application to act as a resource principal or a service principal.
17 . A computer-program product tangibly embodied in one or more non-transitory machine-readable media, including instructions configured to cause one or more data processors to perform a method comprising:
determining, by a token exchange system of an integrated identity management system of a cloud service, that an entity is authorized to access a first identity system, wherein the entity has a first token that is a bearer token of an identity cloud service (IDCS) or a Proof-of-Possession (POP) token of an identity and access management system (IAM);
receiving, by the token exchange system from the entity of the first identity system, a request to access a second identity system;
verifying, by the token exchange system, the first token;
generating, by the token exchange system, a second token for the second identity system based on the first token for the first identity system, wherein when the first token is the bearer token of the identity cloud service (IDCS) then the second token generated by the token exchange system is the Proof-of-Possession token, and when the first token is the Proof-of-Possession token of the identity and access management system (IAM) then the second token generated by the token exchange system is the bearer token,
wherein the second token includes token data for a type of identity system that is different from the first token,
wherein the second identity system for which the second token is generated is a different type of identity management system than the first identity system;
exchanging, by the token exchange system, the first token for the first identity system with the generated second token for the second identity system that is different from the first token for the second identity system;
authenticating, by the token exchange system, the entity to access the second identity system based on the second token; and
authorizing, by the token exchange system, the entity to access an application programming interface (API) of the second identity system using the second token.
18 . The computer-program product according to claim 17 , wherein the entity is authorized to access the API of the second identity system using the second token without requiring entry of entity credentials in the second identity system.
19 . A system comprising:
one or more data processors; and
one or more non-transitory computer readable media storing instructions which, when executed by the one or more data processors, cause the one or more data processors to perform a method comprising:
determining, by a token exchange system of an integrated identity management system of a cloud service, that an entity is authorized to access a first identity system, wherein the entity has a first token that is a bearer token of an identity cloud service (IDCS) or a Proof-of-Possession (POP) token of an identity and access management system (IAM);
receiving, by the token exchange system from the entity of the first identity system, a request to access a second identity system;
verifying, by the token exchange system, the first token;
generating, by the token exchange system, a second token for the second identity system based on the first token for the first identity system, wherein when the first token is the bearer token of the identity cloud service (IDCS) then the second token generated by the token exchange system is the Proof-of-Possession token, and when the first token is the Proof-of-Possession token of the identity and access management system (IAM) then the second token generated by the token exchange system is the bearer token,
wherein the second token includes token data for a type of identity system that is different from the first token,
wherein the second identity system for which the second token is generated is a different type of identity management system than the first identity system;
exchanging, by the token exchange system, the first token for the first identity system with the generated second token for the second identity system that is different from the first token for the second identity system;
authenticating, by the token exchange system, the entity to access the second identity system based on the second token; and
authorizing, by the token exchange system, the entity to access an application programming interface (API) of the second identity system using the second token.
20 . The system according to claim 19 , wherein the entity is authorized to access the API of the second identity system using the second token without requiring entry of entity credentials in the second identity system.