IP Library › Granted Patent US 12,519,769
Granted Patent B2
US 12,519,769 · App. 16/446,063 · Granted Jan 6, 2026

Modifying an identity token based on a trusted service

Inventors: Amit Kapoor (San Francisco, CA); Yogesh Kumar Gowdra Vemadevappa (Sunnyvale, CA)
Assignee: Cryptography Research, Inc.
H04L63/0823H04L63/0853H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,519,769
App. No.
16/446,063
Granted
Jan 6, 2026
Kind
B2
Abstract

An identity token may be received and a service associated with the identity token may be identified. A request may be provided to the service based on the identity token. In response to providing the request, additional information from the service associated with the identity token may be received. The identity token may be modified with the additional information.

Claims (37)

1 . A method comprising:

receiving, by a processing device, an identity token from a first network server;

identifying, by the processing device using information obtained from the identity token, a second network server that provides a first service;

providing a request to the first service provided by the second network server based on the identity token;

receiving, from the second network server, additional information from the first service associated with the identity token in response to providing the request;

modifying, by the processing device, the identity token with the additional information to generate a modified identify token, wherein modifying the identity token comprises identifying a reference to the first service in the identity token and replacing the reference to the first service with the additional information received from the first service; and

providing, to a device, the modified identity token for use in obtaining access to a second service.

2 . The method of claim 1 , wherein identifying the first service associated with the identity token comprises:

identifying a reference to a network location of the first service that is specified in the identity token, wherein the request to the first service is transmitted to the network location.

3 . The method of claim 1 , wherein the additional information specifies a characteristic of a device associated with the identity token.

4 . The method of claim 3 , wherein the characteristic is associated with hardware or software of the device.

5 . The method of claim 1 , wherein the identity token is received from an identity service associated with the first network server and the request for the additional information is provided to the second network server.

6 . A system comprising:

a memory; and

a processing device, operatively coupled with the memory, to:

receive an identity token from a first network server;

identify, using information obtained from the identity token, a second network server that provides a first service associated with the identity token;

provide a request to the first service provided by the second network server based on the identity token;

receive, from the second network server, additional information from the first service associated with the identity token in response to providing the request;

modify the identity token with the additional information to generate a modified identify token, wherein to modify the identity token, the processing device is further to identify a reference to the first service in the identity token and replace the reference to the first service with the additional information received from the first service; and

provide, to a device, the modified identity token for use in obtaining access to a second service provided.

7 . The system of claim 6 , wherein to identify the first service associated with the identity token, the processing device is further to:

identify a reference to a network location of the first service that is specified in the identity token, wherein the request to the first service is transmitted to the network location.

8 . The system of claim 6 , wherein the additional information specifies a characteristic of a device associated with the identity token.

9 . The system of claim 8 , wherein the characteristic is associated with hardware or software of the device.

10 . The system of claim 6 , wherein the identity token is received from an identity service associated with the first network server and the request for the additional information is provided to the second network server.

11 . A non-transitory computer readable medium comprising instructions that, when executed by a processing device, cause the processing device to perform operations comprising:

receiving an identity token from a first network server;

identifying, using information obtained from the identity token, a second network server that provides a first service associated with the identity token;

providing a request to the first service provided by the second network server based on the identity token;

receiving, from the second network server, additional information from the first service associated with the identity token in response to providing the request;

modifying the identity token with the additional information to generate a modified identify token, wherein modifying the identity token comprises identifying a reference to the first service in the identity token and replacing the reference to the first service with the additional information received from the first service; and

providing, to a device, the modified identity token for use in obtaining access to a second service provided.

12 . The non-transitory computer readable medium of claim 11 , wherein to identify the first service associated with the identity token, the operations further comprise:

identifying a reference to a network location of the first service that is specified in the identity token, wherein the request to the first service is transmitted to the network location.

13 . The non-transitory computer readable medium of claim 11 , wherein the additional information specifies a hardware characteristic or a software characteristic of a device associated with the identity token.

14 . The non-transitory computer readable medium of claim 11 , wherein the identity token is received from an identity service associated with the first network server and the request for the additional information is provided to the second network server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2019
From: KAPOOR, AMIT; GOWDRA VEMADEVAPPA, YOGESH KUMAR
To: CRYPTOGRAPHY RESEARCH, INC.
Reel/Frame 051065/0557 →
Continuity (2)
Provisional Application 62721405 · Aug 22, 2018
Related Publication 20200067913A1 · Feb 27, 2020
References Cited (24)
US 7428750B1 · Dunn · 2008 [cited by examiner]
US 7607008B2 · Howard · 2009 [cited by applicant]
US 8522323B1 · Zubovsky · 2013 [cited by examiner]
US 8627424B1 · O'Malley · 2014 [cited by examiner]
US 8627437B2 · Dietrich · 2014 [cited by applicant]
US 9398004B2 · Dietrich et al. · 2016 [cited by applicant]
US 9461990B2 · Dietrich · 2016 [cited by applicant]
US 20080178271A1 · Gajjala · 2008 [cited by examiner]
US 20110239283A1 · Chern · 2011 [cited by examiner]
US 20130191884A1 · Leicher · 2013 [cited by examiner]
US 20140082715A1 · Grajek · 2014 [cited by examiner]
US 20150100788A1 · Chastain · 2015 [cited by examiner]
US 20150237041A1 · Flamini · 2015 [cited by examiner]
US 20160285843A1 · Popovich · 2016 [cited by examiner]
US 20160352717A1 · Shewchuk · 2016 [cited by examiner]
US 20170250967A1 · Martineau · 2017 [cited by examiner]
US 20170374060A1 · Flamini · 2017 [cited by examiner]
US 20180302479A1 · Kolbe · 2018 [cited by examiner]
US 20180367526A1 · Huang · 2018 [cited by examiner]
US 20190188696A1 · Carpenter · 2019 [cited by examiner]
Brian Carrier et al., The Session Token Protocol for Forensics and Traceback, Aug. 1, 2004, ACM, vol. 7, Issue 3, pp. 333-362. (Year: 2004). [cited by examiner]
Bian Yang et al., Towards Standardizing Trusted Evidence of Identity, Nov. 8, 2013, ACM, pp. 63-72. (Year: 2013). [cited by examiner]
Azeem Ahmad et al., A Multi-Token Authorization Strategy for Secure Mobile Cloud Computing, Jun. 16, 2014, IEEE. pp. 136-141. (Year: 2014). [cited by examiner]
Lawrence O'Gorman, Comparing Passwords, Tokens, and Biometrics for User Authentication, Dec. 31, 2003, IEEE, vol. 91, Issue: 12, pp. 2021-2040. (Year: 2003). [cited by examiner]