IP Library › Granted Patent US 12,316,762
Granted Patent B2
US 12,316,762 · App. 17/953,175 · Granted May 27, 2025

Applications as resource principals or service principals

Inventors: Gregg Alan Wilson (Austin, TX); Ayman Mohammed Aly Hassan Elmenshawy (Bellevue, WA); Girish Nagaraja (Sammamish, WA); Venkata Rama Prasad Tammana (Redmond, WA); Gary Philip Cole (Austin, TX)
Assignee: Oracle International Corporation
H04L9/3213H04L9/0861H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,316,762
App. No.
17/953,175
Filed
Sep 26, 2022
Granted
May 27, 2025
Kind
B2
Art Unit
2438
USPC
713/168
Abstract

Techniques are provided for granting an application of a first type of identity system, which uses a first type of identity token, access to a second type of identity system, which uses a second type of identity token. An application can make a request to a token exchange system. The request can include a bearer token and a public key of the application. The token exchange system can exchange the bearer token for a Proof-of-Possession token after performing verification steps. A token exchange system can exchange the first token (e.g., bearer token) for the first identity system for the second token (e.g., Proof-of-Possession token) for the second identity system without requiring entry of credentials to access the second identity system.

Claims (73)

1. A method comprising:

determining, by a token exchange system of an integrated identity management system of a cloud service, that an entity is authorized to access a first identity system,

wherein the entity is an application,

wherein the first identity system is in a first domain;

generating, by the token exchange system, a first request for the entity to access a second identity system,

wherein the first request includes a bearer token and a first public key associated with the entity;

verifying, by the token exchange system, that the bearer token is a valid bearer token;

verifying, by the token exchange system, whether a role of the entity is a role that is authorized to access the second identity system;

generating, by the token exchange system, a second token based on the bearer token and the first public key received in the first request;

sending, by the token exchange system to the entity, the second token that is generated based on the bearer token and the first public key received in the first request;

generating, by the token exchange system, a second request for the entity to access the second identity system, wherein the second request comprises the second token; and

verifying, by the token exchange system, the second token and authorizing the entity to access an application programming interface (API) of the second identity system based upon successfully verifying the second token, wherein authorizing the entity to access the API of the second identity system comprises granting entity privileges of a service principal or a resource principal,

wherein the second token is a Proof-of-Possession (POP) token associated with the second identity system, and the second token includes the first public key of the entity,

wherein the second identity system is in a second domain different from the first domain.

2. The method according to claim 1 , further comprising:

verifying, by the token exchange system, that the entity has an identity that is authorized to access the second identity system; and

authorizing, by the token exchange system, the entity to access the second identity system based upon verifying that the entity has an identity that is authorized to access the second identity system,

wherein the second request is signed by a private key of the entity.

3. The method according to claim 2 , wherein verifying that the entity has the identity that is authorized to access the second identity system comprises:

verifying, by the token exchange system, that the entity is the entity that signed the second request; and

verifying, by the token exchange system, that the second token is authorized to access the second identity system.

4. The method according to claim 1 , wherein authorizing the entity to access the second identity system comprises granting the entity privileges of a resource principal.

5. The method according to claim 1 , wherein authorizing the entity to access the second identity system comprises granting the entity privileges of a service principal.

6. The method according to claim 4 , wherein the resource principal is authorized to access resources of the second identity system.

7. The method according to claim 5 , wherein the service principal is authorized to access services of the second identity system.

8. The method according to claim 1 , wherein the entity is authorized to access the application programming interface (API) of the second identity system using the second token without requiring entry of entity credentials in the second identity system.

9. The method according to claim 2 , wherein the entity is determined to be authorized to access the first identity system based on credentials of the entity for the first identity system.

10. The method according to claim 1 , wherein the first identity system has a first system model, and wherein the second identity system has a second system model that has different specifications from the first system model.

11. The method according to claim 1 , wherein the entity is an integrated cloud service application.

12. The method according to claim 11 , wherein the integrated cloud service application is a SaaS application, a PaaS application or a fusion application.

13. A computer-program product tangibly embodied in one or more non-transitory machine-readable media, including instructions configured to cause one or more data processors to perform a method comprising:

determining, by a token exchange system of an integrated identity management system of a cloud service, that an entity is authorized to access a first identity system,

wherein the entity is an application,

wherein the first identity system is in a first domain;

generating, by the token exchange system, a first request for the entity to access a second identity system, wherein the first request includes a bearer token and a first public key associated with the entity;

verifying, by the token exchange system, that the bearer token is a valid bearer token;

verifying, by the token exchange system, whether a role of the entity is a role that is authorized to access the second identity system;

generating, by the token exchange system, a second token based on the bearer token and the first public key received in the first request;

sending, by the token exchange system to the entity, the second token that is generated based on the bearer token and the first public key received in the first request;

generating, by the token exchange system, a second request for the entity to access the second identity system, wherein the second request comprises the second token; and

verifying, by the token exchange system, the second token and authorizing the entity to access an application programming interface (API) of the second identity system based upon successfully verifying the second token, wherein authorizing the entity to access the API of the second identity system comprises granting entity privileges of a service principal or a resource principal,

wherein the second token is a Proof-of-Possession (POP) token associated with the second identity system, and the second token includes the first public key of the entity,

wherein the second identity system is in a second domain different from the first domain.

14. The computer-program product according to claim 13 , further comprising:

verifying, by the token exchange system, that the entity has an identity that is authorized to access the second identity system; and

authorizing, by the token exchange system, the entity to access the second identity system based upon verifying that the entity has an identity that is authorized to access the second identity system,

wherein the second request is signed by a private key of the entity.

15. The computer-program product according to claim 14 , wherein verifying that the entity has the identity that is authorized to access the second identity system comprises:

verifying, by the token exchange system, that the entity is the entity that signed the second request; and

verifying, by the token exchange system, that the second token is authorized to access the second identity system.

16. A system comprising:

one or more data processors; and

one or more non-transitory computer readable media storing instructions which, when executed by the one or more data processors, cause the one or more data processors to perform a method comprising:

determining, by a token exchange system of an integrated identity management system of a cloud service, that an entity is authorized to access a first identity system,

wherein the entity is an application,

wherein the first identity system is in a first domain;

generating, by the token exchange system, a first request for the entity to access a second identity system, wherein the first request includes a bearer token and a first public key associated with the entity;

verifying, by the token exchange system, that the bearer token is a valid bearer token;

verifying, by the token exchange system, whether a role of the entity is a role that is authorized to access the second identity system;

generating, by the token exchange system, a second token based on the bearer token and the first public key received in the first request;

sending, by the token exchange system to the entity, the second token that is generated based on the bearer token and the first public key received in the first request;

generating, by the token exchange system, a second request for the entity to access the second identity system, wherein the second request comprises the second token; and

verifying, by the token exchange system, the second token and authorizing the entity to access an application programming interface (API) of the second identity system based upon successfully verifying the second token, wherein authorizing the entity to access the API of the second identity system comprises granting entity privileges of a service principal or a resource principal,

wherein the second token is a Proof-of-Possession (POP) token associated with the second identity system, and the second token includes the first public key of the entity,

wherein the second identity system is in a second domain different from the first domain.

17. The system according to claim 16 , further comprising:

verifying, by the token exchange system, that the entity has an identity that is authorized to access the second identity system; and

authorizing, by the token exchange system, the entity to access the second identity system based upon verifying that the entity has an identity that is authorized to access the second identity system,

wherein the second request is signed by a private key of the entity.

18. The system according to claim 17 , wherein verifying that the entity has the identity that is authorized to access the second identity system comprises:

verifying, by the token exchange system, that the entity is the entity that signed the second request; and

verifying, by the token exchange system, that the second token is authorized to access the second identity system.

19. The method according to claim 1 , wherein the first identity system is an Identity Cloud Service (IDCS) system, and wherein the second identity system is an Infrastructure Identity and Access Management (IAM) system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2022
From: WILSON, GREGG ALAN; ELMENSHAWY, AYMAN MOHAMMED ALY HASSAN; NAGARAJA, GIRISH; TAMMANA, VENKATA RAMA PRASAD; COLE, GARY PHILIP
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 061278/0312 →
Continuity (3)
Provisional Application 63250980 · Sep 30, 2021
Provisional Application 63250992 · Sep 30, 2021
Related Publication 20230109109A1 · Apr 6, 2023
References Cited (87)
US 7657639B2 · Hinton · 2010 [cited by applicant]
US 8020007B1 · Zubovsky · 2011 [cited by applicant]
US 8209753B2 · Wen · 2012 [cited by examiner]
US 8434129B2 · Kannappan · 2013 [cited by examiner]
US 8752152B2 · Kol · 2014 [cited by examiner]
US 9602508B1 · Mahaffey · 2017 [cited by examiner]
US 9774581B2 · Leicher · 2017 [cited by examiner]
US 9781122B1 · Wilson et al. · 2017 [cited by applicant]
US 9838376B1 · Lander et al. · 2017 [cited by applicant]
US 10255061B2 · Lander et al. · 2019 [cited by applicant]
US 10275723B2 · Buss · 2019 [cited by examiner]
US 10341410B2 · Lander et al. · 2019 [cited by applicant]
US 10425386B2 · Wardell et al. · 2019 [cited by applicant]
US 10454940B2 · Lander et al. · 2019 [cited by applicant]
US 10455025B2 · Burch · 2019 [cited by examiner]
US 10484243B2 · Cole et al. · 2019 [cited by applicant]
US 10484382B2 · Wilson et al. · 2019 [cited by applicant]
US 10505916B2 · Engan · 2019 [cited by examiner]
US 10511589B2 · Gangawane et al. · 2019 [cited by applicant]
US 10594684B2 · Bansal et al. · 2020 [cited by applicant]
US 10616224B2 · Subramanian et al. · 2020 [cited by applicant]
US 10715564B2 · Mohamad Abdul et al. · 2020 [cited by applicant]
US 10742636B2 · Deshpande et al. · 2020 [cited by applicant]
US 10798165B2 · Srinivasan et al. · 2020 [cited by applicant]
US 10846390B2 · Subramanian et al. · 2020 [cited by applicant]
US 10878079B2 · Vepa et al. · 2020 [cited by applicant]
US 10931656B2 · Carru · 2021 [cited by examiner]
US 11061929B2 · Xu et al. · 2021 [cited by applicant]
US 11121873B2 · Schmaltz · 2021 [cited by examiner]
US 11165634B2 · Medam et al. · 2021 [cited by applicant]
US 11258775B2 · Lander · 2022 [cited by examiner]
US 11303627B2 · Maria · 2022 [cited by examiner]
US 11308132B2 · Srinivasan et al. · 2022 [cited by applicant]
US 11321343B2 · Srinivasan et al. · 2022 [cited by applicant]
US 11509644B2 · Smith · 2022 [cited by examiner]
US 11528262B2 · Carru · 2022 [cited by examiner]
US 11546159B2 · Sugarev · 2023 [cited by examiner]
US 11563580B2 · Sugarev · 2023 [cited by examiner]
US 11595215B1 · Madden · 2023 [cited by examiner]
US 11595389B1 · Madden · 2023 [cited by examiner]
US 11606210B1 · Madden · 2023 [cited by examiner]
US 11736469B2 · Maria · 2023 [cited by examiner]
US 11757645B2 · Sugarev · 2023 [cited by examiner]
US 11997207B2 · Madden · 2024 [cited by examiner]
US 20040143730A1 · Wen · 2004 [cited by examiner]
US 20070179802A1 · Buss · 2007 [cited by examiner]
US 20090064107A1 · Chan et al. · 2009 [cited by applicant]
US 20090089625A1 · Kannappan · 2009 [cited by examiner]
US 20110145565A1 · Kol · 2011 [cited by examiner]
US 20130191884A1 · Leicher · 2013 [cited by examiner]
US 20140189808A1 · Mahaffey · 2014 [cited by examiner]
US 20150150109A1 · Bocanegra et al. · 2015 [cited by applicant]
US 20170063840A1 · Krishnaiah · 2017 [cited by applicant]
US 20180041510A1 · Burch · 2018 [cited by examiner]
US 20190124070A1 · Engan · 2019 [cited by examiner]
US 20190306138A1 · Carru · 2019 [cited by examiner]
US 20190312857A1 · Lander · 2019 [cited by examiner]
US 20190372962A1 · Maria · 2019 [cited by examiner]
US 20200169549A1 · Smith · 2020 [cited by examiner]
US 20200259652A1 · Schmaltz, III · 2020 [cited by examiner]
US 20200264860A1 · Srinivasan et al. · 2020 [cited by applicant]
US 20210081252A1 · Bhargava et al. · 2021 [cited by applicant]
US 20210084031A1 · Lao et al. · 2021 [cited by applicant]
US 20210168128A1 · Carru · 2021 [cited by examiner]
US 20220191188A1 · Maria · 2022 [cited by examiner]
US 20220239483A1 · Sugarev · 2022 [cited by examiner]
US 20230138368A1 · Sugarev · 2023 [cited by examiner]
US 20230336536A1 · Maria · 2023 [cited by examiner]
EP 2761522B1 · 2016 [cited by applicant]
Takahiko Kawasaki, Illustrated DPOP (OAuth Access Token Security Enhancement) 1-23 (Apr. 29, 2020) (https://darutk.medium.com/illustrated-dpop-oauth-access-token-security-enhancement-801680d761ff) (Year: 2020). [cited by examiner]
Danny Shemesh, Service to Service Auth with Azure AD, MSI and OAuth 2.0 (Step by Step) 1-37 (Oct. 21, 2019) (https://medium.com/@dany74q/service-to-service-auth-with-azure-ad-msi-oauth-2-0-step-by-step-a1aed196b1e1) (Ye… [cited by examiner]
Acquire a Token from Azure AD for Authorizing Requests from a Client Application, Microsoft, Available Online at: https://docs.microsoft.com/en-us/azure/storage/common/storage-auth-aad-app?tabs=dotnet, Jul. 12, 2020, 12… [cited by applicant]
Authentication and Token Generation for API usage, Tradelens, Available Online at: https://docs.tradelens.com/how_to/token_generation/, Accessed from Internet on Sep. 27, 2021, 11 pages. [cited by applicant]
Chapter 7. Token Exchange, Redhat, Available Online at: https://access.redhat.com/documentation/en-us/red_hat_single_sign-on/7.2/html/securing_applications_and_services_guide/token-exchange, Accessed from internet on Se… [cited by applicant]
Cloud IAM Authentication and Authorization for Platform Service (Beta), IBM, Available Online at: https://www.ibm.com/docs/en/watson-iot-platform?topic=security-cloud-iam-authentication-authorization, Accessed from Inte… [cited by applicant]
Creating Short-Lived Service Account Credentials, Google Cloud, Available Online at: https://cloud.google.com/iam/docs/creating-short-lived-service-account-credentials, Accessed from Internet on Sep. 27, 2021, 30 pages. [cited by applicant]
Demonstration of Proof-of-Possession Overview, Curity, Available Online at: https://curity.io/resources/learn/dpop-overview/, Accessed from Internet on Sep. 29, 2021, 4 pages. [cited by applicant]
External Identity Providers, Okta Developer, Available Online at: https://developer.okta.com/docs/concepts/identity-providers/, Accessed from Internet on Sep. 29, 2021, pp. 1-6. [cited by applicant]
Federated Identity Blueprint, Decision Framework, Final Version V1.0.0, Available Online at: https://www.qgcio.qld.gov.au/_data/assets/word_doc/0017/4751/6.-Federated-identity-blueprint-Decision-framework-v100.docx, May… [cited by applicant]
How to Convert Bearer Token into Authentication Cookie for MVC App, Stack Overflow, Available Online at: https://stackoverflow.com/questions/38276089/how-to-convert-bearer-token-into-authentication-cookie-for-mvc-app, A… [cited by applicant]
Rashid, Exchange Generic OIDC Credentials for GCP Credentials Using GCP STS Service, Available Online at: https://medium.com/google-cloud/exchange-generic-oidc-credentials-for-gcp-credentials-using-gcp-sts-service-263fb… [cited by applicant]
“Security of the Mission Critical (MC) Service”, 3GPP Standard; Technical. Specification; 3GPP TS 33.180, 3rd Generation Partnership Project (3gpp), Mobile Competence Centre; 650, Route Des Lucioles, Sep. 23, 2021, pp. … [cited by applicant]
Hunt et al., “OAuth 2.0 1-19 Proof-of-Possession (PoP) Security Architecture”, Draft-IETF-Oauth-Pop-Architecture-06.txt, Internet Engineering Task Force, IETF; Standardworkingdraft, Internet Society (Isoc) 4, Rue Des Fa… [cited by applicant]
PCT/US2022/044894, “International Search Report and Written Opinion”, dated Jan. 19, 2023, 14 pages. [cited by applicant]
U.S. Appl. No. 17/953,172, “Non-Final Office Action”, mailed Jul. 18, 2024, 11 pages. [cited by applicant]
OAuth Token Exchange API, Available Online at: https://indigo-iam.github.io/docs/v/current/user-guide/api/oauth-token-exchange.html, Patentability Search Report, downloaded on Sep. 28, 2021, 4 pages. [cited by applicant]
U.S. Appl. No. 17/953,172, “Final Office Action”, dated Nov. 14, 2024, 11 pages. [cited by applicant]
Cited By (1)
US 12,500,889