27–29 Oct 2026
Santiago Compostela
Europe/Madrid timezone

An Identity-Aware Proxy Architecture for Integrating Keycloak IAM with External Providers and Services

27 Oct 2026, 15:25
10m
Presentation (15' + 5' for questions) Research applications in advanced Digital Infrastructures Parallel track - II

Speaker

Samuel Bernardo (LIP)

Description

Integrating enterprise Identity and Access Management (IAM) systems with rigid national identity infrastructures and specialised computing environments presents major architectural and security challenges. Modern OAuth specifications have deprecated the Implicit Grant flow due to critical URI query string leakage vectors, including web server access logs, browser histories, and referrer headers. Nevertheless, national identity platforms often use this flow to transmit tokens and query government Attribute Provider services. At the same time, specialised applications require the secure delivery of short-lived tokens for operational computing workloads, including JupyterHub workflows that interact with Slurm REST APIs and Kubernetes job submission endpoints over TLS.

To address these integration vulnerabilities and provider constraints, we propose an Identity Aware Proxy (IAP) architecture based on a contemporary, type-safe, asynchronous API gateway stack. Functioning as an intermediate virtual identity provider (IdP) and protocol broker, the IAP isolates legacy implicit flows at the gateway boundary. It manages user authentication with government attribute providers, retrieves validated identity claims, and executes a back-channel token exchange (urn:ietf:params:oauth:grant-type:token-exchange) to provision or update user profiles in Keycloak just in time. Keycloak acts as the local security token service (STS). To enforce strict security boundaries and govern accounts under distinct identity assurance levels, external attribute providers are isolated within a dedicated Keycloak realm, separate from the primary organisation realm.

Security and token delivery are centralised at the proxy layer using platform-agnostic PASETO security tokens. The IAP delivers custom PASETO v4 tokens to software applications, dynamically tailoring embedded claims and attributes according to the verified assurance level. The architecture implements a hybrid cryptographic model in which client session containers are secured via local symmetric encryption (V4.local), while downstream service assertions are signed asymmetrically (V4.public). Validation is performed using a public JSON Web Key Set (JWKS) endpoint protected against cache-busting denial-of-service attacks. The IAP establishes a cryptographically resilient bridge between external attribute providers, central IAM platforms and high-performance computing services by centralising the entire token lifecycle. This includes proactive background token refreshes, back-channel global single sign-out and brokered token delivery, for example with Slurm REST APIs and Kubernetes.

Author

Co-authors

Presentation materials

There are no materials yet.