IP Library › Granted Patent US 12,432,190
Granted Patent B2
US 12,432,190 · App. 18/389,468 · Granted Sep 30, 2025

Support for concurrent identities in an identity management solution

Inventors: Rod D Waltermann (Rougemont, NC); Igor Stolbikov (Apex, NC); Sergei Rodionov (Plano, TX)
Assignee: Lenovo (Singapore) Pte. Ltd.
H04L63/0807H04L63/105H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,432,190
App. No.
18/389,468
Granted
Sep 30, 2025
Kind
B2
Abstract

An apparatus can include an interface for receiving authentication tokens from a user. The apparatus can include processing circuitry coupled to the interface. The processing circuitry can receive, over the interface, a first authentication token of the user and at least a second authentication token of the user. The processing circuitry can determine whether the first authentication token and at least the second authentication token correspond to an identity associated with the user. The processing circuitry can validate a computing session responsive to determining that the first authentication token and at least the second authentication token can be linked to the identity. Other methods and systems are described.

Claims (39)

1. An apparatus including:

an interface for receiving authentication tokens from a user; and

processing circuitry coupled to the interface, the processing circuitry configured to:

receive, over the interface, a first authentication token of the user and at least a second authentication token of the user;

determine whether the first authentication token and at least the second authentication token correspond to an identity associated with the user; and

validate a computing session responsive to determining that the first authentication token and at least the second authentication token can be linked to the identity.

2. The apparatus of claim 1 , wherein the processing circuitry is configured to set a trust level for the user subsequent to the validating.

3. The apparatus of claim 2 , wherein the processing circuitry is configured to increase the trust level for the user responsive to receiving additional authentication tokens.

4. The apparatus of claim 1 , wherein the first authentication token and at least the second authentication token correspond to authentication information for identity management systems.

5. The apparatus of claim 4 , wherein the processing circuitry is configured to detect a type of the identity management systems and to perform validation based on the type.

6. The apparatus of claim 5 , wherein the first authentication token is one of Open Authorization (OAuth) token, a Kerberos ticket, a Security Assertion Markup Language (SAML) assertion, and an Azure token.

7. The apparatus of claim 6 , wherein the second authentication token is of a different type than the first authentication token.

8. The apparatus of claim 6 , wherein the second authentication token is of a same type as the first authentication token.

9. The apparatus of claim 8 , wherein the second authentication token corresponds to a different account of the user than the first authentication token.

10. The apparatus of claim 1 , wherein the processing circuitry is configured to detect whether at least one of first authentication token and the second authentication token is expired and to re-validate responsive to detecting that at least one of the first authentication token and the second authentication token is expired.

11. The apparatus of claim 10 , wherein expiration is determined based on a security level of an application associated with at least one of first authentication token and the second authentication token.

12. The apparatus of claim 1 , wherein the processing circuitry is further configured to generate a primary token subsequent to validating the computing session.

13. The apparatus of claim 12 , wherein the primary token comprises an aggregation of the first authentication token and at least the second authentication token.

14. A computer-readable medium including instructions that, when executed on processing circuitry cause the processing circuitry to perform operations including:

receiving a first authentication token of a user and at least a second authentication token of the user;

determining whether the first authentication token and at least the second authentication token correspond to an identity associated with the user; and

validating a computing session responsive to determining that the first authentication token and at least the second authentication token can be linked to the identity.

15. The computer-readable medium of claim 14 , wherein the operations further include:

setting a trust level for the user subsequent to the validating; and

increasing the trust level for the user responsive to receiving additional authentication tokens.

16. The computer-readable medium of claim 14 , wherein the first authentication token and at least the second authentication token correspond to authentication information for identity management systems, and wherein the operations further include:

detecting a type of the identity management systems; and

performing validation based on the type.

17. The computer-readable medium of claim 16 , wherein the first authentication token is one of Open Authorization (OAuth) token, a Kerberos ticket, a Security Assertion Markup Language (SAML) assertion, and an Azure token.

18. The computer-readable medium of claim 14 , wherein the operations further include:

detecting whether at least one of first authentication token and the second authentication token is expired; and

re-validating responsive to detecting that at least one of the first authentication token and the second authentication token is expired.

19. A method comprising:

receiving a first authentication token of a user and at least a second authentication token of the user;

determining whether the first authentication token and at least the second authentication token correspond to an identity associated with the user; and

validating a computing session responsive to determining that the first authentication token and at least the second authentication token can be linked to the identity.

20. The method of claim 19 , further comprising:

setting a trust level for the user subsequent to the validating; and

increasing the trust level for the user responsive to receiving additional authentication tokens.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 26, 2023
From: LENOVO (UNITED STATES) INC.
To: LENOVO (SINGAPORE) PTE. LTD.
Reel/Frame 066140/0696 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2023
From: WALTERMANN, ROD D; STOLBIKOV, IGOR; RODIONOV, SERGEI
To: LENOVO (UNITED STATES) INC.
Reel/Frame 065560/0727 →
Continuity (1)
Related Publication 20250158973A1 · May 15, 2025
References Cited (60)
US 8327429B2 · Speyer · 2012 [cited by examiner]
US 8578454B2 · Grim · 2013 [cited by examiner]
US 8955080B2 · Brunswig · 2015 [cited by examiner]
US 9280765B2 · Hammad · 2016 [cited by examiner]
US 10681039B2 · Alzate · 2020 [cited by examiner]
US 11128660B2 · O'Connor · 2021 [cited by examiner]
US 11159511B1 · Geusz · 2021 [cited by examiner]
US 11463426B1 · Wheeler · 2022 [cited by examiner]
US 11736296B2 · Wang · 2023 [cited by examiner]
US 11943215B1 · Nair · 2024 [cited by examiner]
US 11947650B2 · Wang · 2024 [cited by examiner]
US 20050114701A1 · Atkins · 2005 [cited by examiner]
US 20060200424A1 · Cameron · 2006 [cited by examiner]
US 20060236382A1 · Hinton · 2006 [cited by examiner]
US 20080168539A1 · Stein · 2008 [cited by examiner]
US 20090259848A1 · Williams · 2009 [cited by examiner]
US 20100281252A1 · Steeves · 2010 [cited by examiner]
US 20110154465A1 · Kuzin · 2011 [cited by examiner]
US 20110296522A1 · Speyer · 2011 [cited by examiner]
US 20120174198A1 · Gould · 2012 [cited by examiner]
US 20120227098A1 · Obasanjo · 2012 [cited by examiner]
US 20120259782A1 · Hammad · 2012 [cited by examiner]
US 20130104198A1 · Grim · 2013 [cited by examiner]
US 20140068723A1 · Grim · 2014 [cited by examiner]
US 20140165150A1 · Brunswig · 2014 [cited by examiner]
US 20150067813A1 · Cha · 2015 [cited by examiner]
US 20150128242A1 · Hoy · 2015 [cited by examiner]
US 20150244706A1 · Grajek · 2015 [cited by examiner]
US 20150381602A1 · Grim · 2015 [cited by examiner]
US 20150381633A1 · Grim · 2015 [cited by examiner]
US 20150382195A1 · Grim · 2015 [cited by examiner]
US 20160140542A1 · Hammad · 2016 [cited by examiner]
US 20170187708A1 · Moore · 2017 [cited by examiner]
US 20180013763A1 · Wilson · 2018 [cited by examiner]
US 20180075231A1 · Subramanian · 2018 [cited by examiner]
US 20190058706A1 · Feijoo · 2019 [cited by examiner]
US 20190215320A1 · Alzate · 2019 [cited by examiner]
US 20190394232A1 · O'Connor · 2019 [cited by examiner]
US 20200137042A1 · Kannan, III · 2020 [cited by examiner]
US 20200374121A1 · Momchilov · 2020 [cited by examiner]
US 20210021605A1 · Innes · 2021 [cited by examiner]
US 20210037004A1 · Gordon · 2021 [cited by examiner]
US 20210136058A1 · Lopez · 2021 [cited by examiner]
US 20210243029A1 · Wang · 2021 [cited by examiner]
US 20210336946A1 · Cheng · 2021 [cited by examiner]
US 20210385210A1 · Olden · 2021 [cited by examiner]
US 20210390170A1 · Olden · 2021 [cited by examiner]
US 20210392048A1 · Olden · 2021 [cited by examiner]
US 20220191185A1 · Carmon · 2022 [cited by examiner]
US 20220255931A1 · Avetisov · 2022 [cited by examiner]
US 20230075296A1 · Morley, III · 2023 [cited by examiner]
US 20230129824A1 · Hettiarachchi · 2023 [cited by examiner]
US 20230275893A1 · Sharma · 2023 [cited by examiner]
US 20230421583A1 · Olden · 2023 [cited by examiner]
US 20240220968A1 · Pearce · 2024 [cited by examiner]
US 20250080521A1 · Patange · 2025 [cited by examiner]
US 20250112907A1 · McGuinness · 2025 [cited by examiner]
US 20250119417A1 · Doherty · 2025 [cited by examiner]
US 20250175468A1 · Shyamala · 2025 [cited by examiner]
Ahmad, Azeem, Muhammad Mustafa Hassan, and Abdul Aziz. “A multi-token authorization strategy for secure mobile cloud computing.” 2014 2nd IEEE International Conference on Mobile Cloud Computing, Services, and Engineerin… [cited by examiner]