Artificial intelligence only reaches its full potential when it can access the right data. In practice, however, this is often hindered by fragmented IT landscapes, disparate Identity Providers (IdPs), and stringent security requirements. In their article published in IT Spektrum, Detlev Altendorf and Stefan Braun show how the OAuth mechanism Token Exchange helps companies deploy AI agents securely, flexibly and cost-effectively across system and security boundaries.

AI agents need an identity of their own

Companies today hold vast amounts of valuable data, spread across ERP systems, CRM solutions, file servers, collaboration platforms and cloud applications. For AI applications in particular, this information is highly valuable, as it enables well-founded analysis and faster decision-making. The challenge, however, lies in connecting these data sources securely and in a controlled manner.

In this context, AI agents act as so-called Non-Human Identities (NHIs). To be deployed safely, they need a clearly defined identity along with tightly controlled and traceable access rights. The article therefore highlights the importance of modern Machine Identity Management (MIM), which manages identities automatically, grants access rights based on the least-privilege principle, and makes all activity traceable.

When different Identity Providers need to work together

Most companies today rely on a wide range of identity sources – from Microsoft Entra ID to SAP environments, partner portals or specialised IAM systems. Each of these platforms uses its own authentication methodes, token formats and trust models. This creates significant complexity for AI applications that need to access information across systems.

This is where Token Exchange comes in. Specified under RFC 8693, this mechanism acts as an "interpreter" between different security domains. Existing tokens are validated and automatically "translated" into new tokens valid for the respective target system. This allows AI agents to securely access resources across different systems without requiring fundamental changes to existing applications or identity infrastructures. At the same time, security zones remain clearly separated, and authorisations can be verified individually for each access request.

Greater security and flexibility with less integration effort

The key advantage of Token Exchange lies in its combination of security, scalability and cost-effectiveness. Companies don't need to consolidate their existing system landscape onto a single Identity Provider in order to deploy AI applications securely. Instead, a token exchange server enables controlled collaboration between different systems and security domains.

The authors conclude that this approach is particularly relevant for organisations that need to bring together complex information landscapes, multiple Identity Providers, and the growing use of Non-Human Identities as AI tools. Token Exchange lays the foundation for an identity-centric architecture in which AI agents can operate securely, access relevant information flexibly, and meet the highest security requirements – without costly changes to existing applications.

Read the full article here.

Information for you

-Our whitepapers-
White paper: The puzzle pieces of modern authentication

White paper: The puzzle pieces of modern authentication

Identity management is like a puzzle: you have to understand the big picture, identify the relevant pieces and put them together in the right order. This white paper shows how to do that.

 

Request white paper

Whitepaper: How to make cIAM a success

Increasing requirements for security and user-friendliness make Customer Identity and Access Management an essential. Read our whitepaper to find out how you can secure your competitive advantage with the right CIAM strategy.

 

Request whitepaper

Whitepaper: Security for cloud-native applications

You can read about how companies can ensure the security of web applications and APIs in Kubernetes in the white paper "Security for cloud-native applications", which was created in collaboration between heise and Airlock.

 

Request whitepaper

Whitepaper: Zero Trust is a journey

The ongoing digital transformation of the world is progressing and having a profound impact on our personal and professional lives in ways that were difficult to imagine just a few years ago.


This white paper discusses the effects of continuous digitalization and its impact.

Request free of charge

Off to DevSecOps

In this white paper, you will learn the most important insights into how you can implement DevSecOps successfully and efficiently, which security components are required for this and the advantages of a microgateway architecture.

 

Request free of charge

Airlock 2FA - Strong authentication. Simple.

Double security - this is what two-factor authentication offers in the field of IT security.


Find out more about strong authentication and the possibilities offered by Airlock in our white paper.

Download for free

Further whitepapers

We provide you with free white papers on these and other topics:

 

  • Successful IAM projects
  • compliance
  • Data protection (DSGVO)
  • Introduction of PSD2
  • PCI DSS requirementsPCI DSS requirements
Request free of charge