Token Exchange System for Identity Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inefficiencies and burdens in managing different access tokens for various identity management systems, leading to interruptions in workflow and increased complexity in accessing features across different systems.

Innovation Solution

A token exchange system within an integrated identity management system allows for the seamless exchange of bearer tokens for Proof of Possession (PoP) tokens, and vice versa, enabling entities to access features of different identity management systems without requiring separate credentials or login processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If separate access tokens are required for each identity management system, then each system can be accessed with its specific token type, but user workflow is interrupted and management complexity increases

Engineering Contradiction:
Improvecompatibility with different identity systemsVSAvoiduser workflow continuity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

An integrated identity management system acts as an intermediary between entities and multiple identity management systems. The system receives requests from entities, automatically exchanges tokens between different identity systems on behalf of the entity, and returns results. This mediator approach allows entities to interact with any identity system without manually managing multiple tokens, resolving the contradiction between system compatibility and workflow continuity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple access tokens are required for different identity management systems, then each system can be accessed independently, but credential management burden increases

Engineering Contradiction:
Improveaccess to multiple identity systemsVSAvoidcredential management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple identity management systems into a single integrated identity management system. Instead of requiring entities to manage separate credentials for each identity system, the integrated system consolidates token management functionality. The system maintains internal mappings between different token types and automatically performs token exchanges, reducing credential management complexity from multiple separate tokens to a unified management approach.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If applications use bearer tokens, then they can access IDCS systems, but they cannot exchange tokens for PoP tokens to access IAM systems

Engineering Contradiction:
Improvetoken exchange capabilityVSAvoidprivilege requirements
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The integrated identity management system provides universal token exchange functionality that works with both bearer tokens and PoP tokens. Instead of requiring applications to have different privileges for different token exchange scenarios, the system implements a multi-functional token exchange mechanism that automatically determines the appropriate exchange type based on the target identity system. This allows applications to access both IDCS and IAM systems without needing specialized privileges for each token type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12316762B2Applications as resource principals or service principals
Publication Date: 2025.05.27 ORACLE INT CORP
  • US12316762B2 patent drawing
  • US12316762B2 patent drawing
  • US12316762B2 patent drawing

AI summary

Techniques are provided for granting an application of a first type of identity system, which uses a first type of identity token, access to a second type of identity system, which uses a second type of identity token. An application can make a request to a token exchange system. The request can include a bearer token and a public key of the application. The token exchange system can exchange the bearer token for a Proof-of-Possession token after performing verification steps. A token exchange system can exchange the first token (e.g., bearer token) for the first identity system for the second token (e.g., Proof-of-Possession token) for the second identity system without requiring entry of credentials to access the second identity system.