IP Library › Granted Patent US 12,739,119
Granted Patent B2
US 12,739,119 · App. 17/953,172 · Granted Sep 15, 2026

Token exchange between bearer and pop tokens

Inventors: Venkata Subbarao Evani (Fremont, CA); Girish Nagaraja (Sammamish, WA); Norka Beatriz Lucena Mogollon (Kirkland, WA)
Assignee: Oracle International Corporation
H04L9/3213H04L9/0861H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,119
App. No.
17/953,172
Granted
Sep 15, 2026
Kind
B2
Abstract

Techniques are disclosed for exchanging tokens between different identity systems that follow different identity models. A token exchange system of an integrated identity management system of a cloud service can determine that an entity is authorized to access a first identity system based on credentials of the entity entered in the first identity system. The token exchange system can exchange a first token for the first identity system for a second token for the second identity system without requiring entry of credentials to access the second identity system.

Claims (53)

1 . A method comprising:

determining, by a token exchange system of an integrated identity management system of a cloud service, that an entity is authorized to access a first identity system, wherein the entity has a first token that is a bearer token of an identity cloud service (IDCS) or a Proof-of-Possession (POP) token of an identity and access management system (IAM);

receiving, by the token exchange system from the entity of the first identity system, a request to access a second identity system;

verifying, by the token exchange system, the first token;

generating, by the token exchange system, a second token for the second identity system based on the first token for the first identity system, wherein when the first token is the bearer token of the identity cloud service (IDCS) then the second token generated by the token exchange system is the Proof-of-Possession token, and when the first token is the Proof-of-Possession token of the identity and access management system (IAM) then the second token generated by the token exchange system is the bearer token,

wherein the second token includes token data for a type of identity system that is different from the first token,

wherein the second identity system for which the second token is generated is a different type of identity management system than the first identity system;

exchanging, by the token exchange system, the first token for the first identity system with the generated second token for the second identity system that is different from the first token for the second identity system;

authenticating, by the token exchange system, the entity to access the second identity system based on the second token; and

authorizing, by the token exchange system, the entity to access an application programming interface (API) of the second identity system using the second token.

2 . The method according to claim 1 , wherein the entity is authorized to access the API of the second identity system using the second token without requiring entry of entity credentials in the second identity system.

3 . The method according to claim 2 , wherein the entity is determined to be authorized to access the first identity system based on credentials of the entity for the first identity system.

4 . The method according to claim 1 , wherein the request is signed by an identity of the entity, and wherein the verifying the first token comprises verifying a signature of the first token.

5 . The method according to claim 1 , further comprising after generating the second token, signing, by the token exchange system, the second token with a private key of the entity to generate a second signed token.

6 . The method according to claim 1 , wherein the first identity system has a first system model, and wherein the second identity system has a second system model that has different specifications from the first system model.

7 . The method according to claim 1 , wherein the entity is an integrated cloud service application,

wherein the integrated cloud service application is a SaaS application, a PaaS application or a fusion application.

8 . The method according to claim 1 , further comprising:

storing, by the token exchange system, the first token for the first identity system and the second token for the second identity system, in a token store; and

maintaining, by the token exchange system, the first token for the first identity system and the second token for the second identity system in the token store during a session of the entity with the first identity system and the second identity system.

9 . The method according to claim 8 , wherein the session is a predetermined period of time, and the method further comprising removing, by the token exchange system, the first token for the first identity system and the second token for the second identity system, in the token store at an end of the session.

10 . The method according to claim 1 , wherein the request to access the second identity system is received on an integration console, and wherein the integration console is configured to call a token exchange.

11 . The method according to claim 1 , wherein the first identity system is an Identity Cloud Service (IDCS) system that follows a first specification comprising first rules, and the second identity system is an Identity and Access Management (IAM) system that follows a second specification comprising second rules, wherein the second specification is different from the first specification.

12 . The method according to claim 1 , further comprising after the entity is authenticated to access the second identity system based on the second token, authorizing the entity to re-access an application programming interface (API) of the first identity system, that is a different type of identity management system from the second identity system, without reauthenticating the entity.

13 . The method according to claim 1 , further comprising after the entity is authenticated to access the second identity system based on the second token, authorizing the entity to re-access an application programming interface (API) of the first identity system by converting the second token to the first token that is compatible with the first identity system,

wherein if the second token is the bearer token of the identity cloud service (IDCS) then the second token is converted back to the first token that is the Proof-of-Possession token, and if the second token is the Proof-of-Possession token of the identity and access management system (IAM) then the second token is converted back to the first token that is the bearer token.

14 . The method according to claim 1 , wherein the first token comprises first privileges associated with accessing the first identity system, wherein the second token comprises second privileges associated with accessing the second identity system, and wherein the first privileges are different from the second privileges.

15 . The method according to claim 1 , wherein when the first identity system is an IAM system, the request to access the second identity system is signed with an IAM PoP/API key.

16 . The method according to claim 1 , wherein the bearer token is associated with a bearer token identity for a SaaS application, a PaaS application or a fusion application (FA), and the token exchange system is configured to exchange the bearer token identity for a resource principal session token (RSPT) identity associated with the POP token that configures an application to act as a resource principal or a service principal.

17 . A computer-program product tangibly embodied in one or more non-transitory machine-readable media, including instructions configured to cause one or more data processors to perform a method comprising:

determining, by a token exchange system of an integrated identity management system of a cloud service, that an entity is authorized to access a first identity system, wherein the entity has a first token that is a bearer token of an identity cloud service (IDCS) or a Proof-of-Possession (POP) token of an identity and access management system (IAM);

receiving, by the token exchange system from the entity of the first identity system, a request to access a second identity system;

verifying, by the token exchange system, the first token;

generating, by the token exchange system, a second token for the second identity system based on the first token for the first identity system, wherein when the first token is the bearer token of the identity cloud service (IDCS) then the second token generated by the token exchange system is the Proof-of-Possession token, and when the first token is the Proof-of-Possession token of the identity and access management system (IAM) then the second token generated by the token exchange system is the bearer token,

wherein the second token includes token data for a type of identity system that is different from the first token,

wherein the second identity system for which the second token is generated is a different type of identity management system than the first identity system;

exchanging, by the token exchange system, the first token for the first identity system with the generated second token for the second identity system that is different from the first token for the second identity system;

authenticating, by the token exchange system, the entity to access the second identity system based on the second token; and

authorizing, by the token exchange system, the entity to access an application programming interface (API) of the second identity system using the second token.

18 . The computer-program product according to claim 17 , wherein the entity is authorized to access the API of the second identity system using the second token without requiring entry of entity credentials in the second identity system.

19 . A system comprising:

one or more data processors; and

one or more non-transitory computer readable media storing instructions which, when executed by the one or more data processors, cause the one or more data processors to perform a method comprising:

determining, by a token exchange system of an integrated identity management system of a cloud service, that an entity is authorized to access a first identity system, wherein the entity has a first token that is a bearer token of an identity cloud service (IDCS) or a Proof-of-Possession (POP) token of an identity and access management system (IAM);

receiving, by the token exchange system from the entity of the first identity system, a request to access a second identity system;

verifying, by the token exchange system, the first token;

generating, by the token exchange system, a second token for the second identity system based on the first token for the first identity system, wherein when the first token is the bearer token of the identity cloud service (IDCS) then the second token generated by the token exchange system is the Proof-of-Possession token, and when the first token is the Proof-of-Possession token of the identity and access management system (IAM) then the second token generated by the token exchange system is the bearer token,

wherein the second token includes token data for a type of identity system that is different from the first token,

wherein the second identity system for which the second token is generated is a different type of identity management system than the first identity system;

exchanging, by the token exchange system, the first token for the first identity system with the generated second token for the second identity system that is different from the first token for the second identity system;

authenticating, by the token exchange system, the entity to access the second identity system based on the second token; and

authorizing, by the token exchange system, the entity to access an application programming interface (API) of the second identity system using the second token.

20 . The system according to claim 19 , wherein the entity is authorized to access the API of the second identity system using the second token without requiring entry of entity credentials in the second identity system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2022
From: EVANI, VENKATA SUBBARAO; NAGARAJA, GIRISH; LUCENA MOGOLLON, NORKA BEATRIZ
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 061278/0185 →
Continuity (3)
Provisional Application 63250980 · Sep 30, 2021
Provisional Application 63250992 · Sep 30, 2021
Related Publication 20230100200A1 · Mar 30, 2023
References Cited (93)
US 7657639B2 · Hinton · 2010 [cited by applicant]
US 8020007B1 · Zubovsky · 2011 [cited by applicant]
US 8209753B2 · Wen et al. · 2012 [cited by applicant]
US 8434129B2 · Kannappan et al. · 2013 [cited by applicant]
US 8752152B2 · Kol et al. · 2014 [cited by applicant]
US 9602508B1 · Mahaffey et al. · 2017 [cited by applicant]
US 9774581B2 · Leicher et al. · 2017 [cited by applicant]
US 9781122B1 · Wilson et al. · 2017 [cited by applicant]
US 9838376B1 · Lander et al. · 2017 [cited by applicant]
US 10255061B2 · Lander et al. · 2019 [cited by applicant]
US 10275723B2 · Buss et al. · 2019 [cited by applicant]
US 10341410B2 · Lander et al. · 2019 [cited by applicant]
US 10425386B2 · Wardell et al. · 2019 [cited by applicant]
US 10454940B2 · Lander et al. · 2019 [cited by applicant]
US 10455025B2 · Burch et al. · 2019 [cited by applicant]
US 10484243B2 · Cole et al. · 2019 [cited by applicant]
US 10484382B2 · Wilson et al. · 2019 [cited by applicant]
US 10505916B2 · Engan et al. · 2019 [cited by applicant]
US 10511589B2 · Gangawane et al. · 2019 [cited by applicant]
US 10594684B2 · Bansal et al. · 2020 [cited by applicant]
US 10616224B2 · Subramanian et al. · 2020 [cited by applicant]
US 10715564B2 · Mohamad Abdul et al. · 2020 [cited by applicant]
US 10742636B2 · Deshpande et al. · 2020 [cited by applicant]
US 10798165B2 · Srinivasan et al. · 2020 [cited by applicant]
US 10846390B2 · Subramanian et al. · 2020 [cited by applicant]
US 10878079B2 · Vepa et al. · 2020 [cited by applicant]
US 10931656B2 · Carru · 2021 [cited by examiner]
US 11061929B2 · Xu et al. · 2021 [cited by applicant]
US 11121873B2 · Schmaltz et al. · 2021 [cited by applicant]
US 11165634B2 · Medam et al. · 2021 [cited by applicant]
US 11258775B2 · Lander et al. · 2022 [cited by applicant]
US 11303627B2 · Maria et al. · 2022 [cited by applicant]
US 11308132B2 · Srinivasan et al. · 2022 [cited by applicant]
US 11321343B2 · Srinivasan et al. · 2022 [cited by applicant]
US 11509644B2 · Smith · 2022 [cited by applicant]
US 11528262B2 · Carru et al. · 2022 [cited by applicant]
US 11546159B2 · Sugarev · 2023 [cited by applicant]
US 11563580B2 · Sugarev · 2023 [cited by applicant]
US 11595215B1 · Madden · 2023 [cited by applicant]
US 11595389B1 · Madden · 2023 [cited by applicant]
US 11606210B1 · Madden · 2023 [cited by applicant]
US 11736469B2 · Maria et al. · 2023 [cited by applicant]
US 11757645B2 · Sugarev · 2023 [cited by applicant]
US 11997207B2 · Madden · 2024 [cited by applicant]
US 20040143730A1 · Wen · 2004 [cited by examiner]
US 20070179802A1 · Buss et al. · 2007 [cited by applicant]
US 20090064107A1 · Chan et al. · 2009 [cited by applicant]
US 20090089625A1 · Kannappan et al. · 2009 [cited by applicant]
US 20110145565A1 · Kol et al. · 2011 [cited by applicant]
US 20130191884A1 · Leicher et al. · 2013 [cited by applicant]
US 20140189808A1 · Mahaffey et al. · 2014 [cited by applicant]
US 20150150109A1 · Bocanegra et al. · 2015 [cited by applicant]
US 20170063840A1 · Krishnaiah · 2017 [cited by applicant]
US 20180041510A1 · Burch et al. · 2018 [cited by applicant]
US 20190124070A1 · Engan et al. · 2019 [cited by applicant]
US 20190306138A1 · Carru · 2019 [cited by examiner]
US 20190312857A1 · Lander · 2019 [cited by examiner]
US 20190372962A1 · Maria · 2019 [cited by examiner]
US 20200169549A1 · Smith · 2020 [cited by examiner]
US 20200259652A1 · Schmaltz, III et al. · 2020 [cited by applicant]
US 20200264860A1 · Srinivasan et al. · 2020 [cited by applicant]
US 20210081252A1 · Bhargava et al. · 2021 [cited by applicant]
US 20210084031A1 · Lao et al. · 2021 [cited by applicant]
US 20210168128A1 · Carru et al. · 2021 [cited by applicant]
US 20210226794A1 · Axdorff et al. · 2021 [cited by applicant]
US 20220191188A1 · Maria et al. · 2022 [cited by applicant]
US 20220239483A1 · Sugarev · 2022 [cited by applicant]
US 20230138368A1 · Sugarev · 2023 [cited by applicant]
US 20230336536A1 · Maria et al. · 2023 [cited by applicant]
EP 2761522B1 · 2016 [cited by applicant]
JP 2021516800A · 2021 [cited by applicant]
JP 2023516973A · 2023 [cited by applicant]
WO 2021183186A1 · 2021 [cited by applicant]
Security of the Mission Critical (MC) Service, 3GPP Standard; Technical. Specification; 3GPP TS 33.180, 3rd Generation Partnership Project (3gpp), Mobile Competence Centre; 650, Route Des Lucioles, Sep. 23, 2021, pp. 1-… [cited by applicant]
Hunt et al., OAuth 2.0 1-19 Proof-of-Possession (PoP) Security Architecture, Draft-IETF-Oauth-Pop-Architecture-06.txt, Internet Engineering Task Force, IETF; Standardworkingdraft, Internet Society (Isoc) 4, Rue Des Fala… [cited by applicant]
International Application No. PCT/US2022/044894, International Search Report and Written Opinion mailed on Jan. 19, 2023, 14 pages. [cited by applicant]
Acquire a Token from Azure AD for Authorizing Requests from a Client Application, Microsoft, Available Online at: https://docs.microsoft.com/en-us/azure/storage/common/storage-auth-aad-app?tabs=dotnet, Jul. 12, 2020, 12… [cited by applicant]
Authentication and Token Generation for API usage, Tradelens, Available Online at: https://docs.tradelens.com/how_to/token_generation/, Accessed from Internet on Sep. 27, 2021, 11 pages. [cited by applicant]
Chapter 7. Token Exchange, Redhat, Available Online at: https://access.redhat.com/documentation/en-us/red_hat_single_sign-on/7.2/html/securing_applications_and_services_guide/token-exchange, Accessed from internet on Se… [cited by applicant]
Cloud IAM Authentication and Authorization for Platform Service (Beta), IBM, Available Online at: https://www.ibm.com/docs/en/watson-iot-platform?topic=security-cloud-iam-authentication-authorization, Accessed from Inte… [cited by applicant]
Creating Short-Lived Service Account Credentials, Google Cloud, Available Online at: https://cloud.google.com/iam/docs/creating-short-lived-service-account-credentials, Accessed from Internet on Sep. 27, 2021, 30 pages. [cited by applicant]
Demonstration of Proof-of-Possession Overview, Curity, Available Online at: https://curity.io/resources/learn/dpop-overview/, Accessed from Internet on Sep. 29, 2021, 4 pages. [cited by applicant]
External Identity Providers, Okta Developer, Available Online at: https://developer.okta.com/docs/concepts/identity-providers/, Accessed from Internet on Sep. 29, 2021, pp. 1-6. [cited by applicant]
Federated Identity Blueprint, Decision Framework, Final Version V1.0.0, Available Online at: https://www.qgcio.qld.gov.au/_data/assets/word_doc/0017/4751/6.-Federated-identity-blueprint-Decision-framework-v100.docx, May… [cited by applicant]
How to Convert Bearer Token into Authentication Cookie for MVC App, Stack Overflow, Available Online at: https://stackoverflow.com/questions/38276089/how-to-convert-bearer-token-into-authentication-cookie-for-mvc-app, A… [cited by applicant]
OAuth Token Exchange API, Available Online at: https://indigo-iam.github.io/docs/v/current/user-guide/api/oauth-token-exchange.html, 4 pages. [cited by applicant]
Rashid, Exchange Generic OIDC Credentials for GCP Credentials Using GCP STS Service, Available Online at: https://medium.com/google-cloud/exchange-generic-oidc-credentials-for-gcp-credentials-using-gcp-sts-service- 263f… [cited by applicant]
U.S. Appl. No. 17/953,175, “Non-Final Office Action”, mailed Sep. 10, 2024, 28 pages. [cited by applicant]
U.S. Appl. No. 17/953,175, Notice of Allowance, mailed on Feb. 18, 2025, 19 page. [cited by applicant]
Kawasaki , “Illustrated DPoP (OAuth Access Token Security Enhancement)”, Available online at: https://darutk.medium.com/illustrated-dpop-oauth-access-token-security-enhancement-801680d761ff, Apr. 29, 2020, 23 pages. [cited by applicant]
Shemesh , “Service to Service Auth with Azure AD, MSI & OAuth 2.0 (Step by Step)”, Available online at: https://medium.com/@dany74q/service-to-service-auth-with-azure-ad-msi-oauth-2-0-step-by-step-a1aed196b1e1, Oct. 22,… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security of the Mission Critical (MC) service; (Release 17)”, 3GPP TS 33.180 V17.4.0, Sep. 2021, 204 pages. [cited by applicant]
International Application No. JP2024-519653, “Office Action”, mailed on May 26, 2026, 4 pages. [cited by applicant]