Computer system geolocation based on client-server response time

By sending challenges and measuring response times between the border server and the client system, a certificate with an coded elapsed time is generated. Trilateral measurements and encrypted signatures are performed using the known physical locations of multiple border servers. This solves the problems of easy forgery and inaccuracy of geographic positioning in existing technologies, and achieves more reliable location verification.

CN121220005APending Publication Date: 2025-12-26INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480036063.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-06-27
Filing Date
2024-06-19
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

Existing computer system geolocation technologies are easily forged. Location data based on IP addresses is not accurate enough and is easily tampered with, making it impossible to effectively verify the true location of a computer system.

Method used

By sending challenges and responses between the border server and the client system, the response time is measured, and a time-encoded certificate is generated to verify the location of the client system. Trilateral measurements are performed using the known physical locations of multiple border servers, and cryptographic signatures are used to ensure the authenticity of the certificate.

Benefits of technology

It provides a more accurate and tamper-proof method for geolocating computer systems, capable of verifying the true location of client systems, and applicable to legal compliance and content access control in different jurisdictions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121220005A_ABST
    Figure CN121220005A_ABST
Patent Text Reader

Abstract

In one embodiment, in response to a challenge request, a challenge is sent from a border server to a client system at a first time, the challenge specifying a computing problem to be solved by the client system, the border server being specified in a list of challenges sent to the client system. One embodiment receives, at a second time, a challenge response from the client system at the border server, the challenge response including a solution to the compute question. One embodiment generates, at a border server, a certificate encoding a time elapsed between a first time and a second time, the certificate being usable by a client system to attestation a location of the client system. In one embodiment, credentials are sent from a border server to a client system.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present invention relates generally to methods, systems, and computer program products for geolocation of computer systems. More specifically, the present invention relates to methods, systems, and computer program products for geolocation of computer systems based on client-server response times. BACKGROUND

[0002] Geolocation is the process of determining or estimating the geographic or physical location of an object on Earth. The determined or estimated location can be expressed in terms of latitude / longitude coordinates, relative to another object with a fixed known location, or using different measurements or coordinate systems. Often, geolocation is performed to collect data for another process. For example, the location of an object at two different times can be used to calculate the speed of the object, or the location of a car relative to road map and street address data can be used to provide driving directions. Depending on the use of the physical location to be determined, geolocation is often performed with a desired accuracy. For example, if the use case is to determine whether an object is located on a particular continent, such as North America, an accuracy of ±100 kilometers can be sufficient. However, as another example, if the use case is to determine the lateral position of an airplane relative to the approach end of an airport runway, an accuracy of ±200 meters can be appropriate.

[0003] Illustrative embodiments recognize a need to geolocate computer systems, and a motivation to fake geolocation. For example, some laws apply to computers or computer users in particular jurisdictions, and to comply with these laws, service providers can adjust the functionality of their products based on the service provider’s knowledge of which jurisdiction a computer system is within. Similarly, because some transactions can only be allowed in certain jurisdictions, and transactions are often taxed differently in different jurisdictions, users can be interested in claiming that the computer system they are using is in a jurisdiction that allows the transaction to be performed, or in a jurisdiction with the lowest tax rate. Some content (e.g., sports or movies) is only licensed to be viewed by audiences in particular countries, but not by audiences in other countries. As another example, the rate of change of user location (measured by the user’s device) is faster than the speed at which the user is actually traveling, which can be an indicator of fraudulent transactions.

[0004] Illustrative embodiments recognize that one geolocation technique for locating a computer system is to rely on the system self-reporting its location, or to rely on the system user self-reporting its location. However, relying on the system self-reporting its location assumes that the system is telling the truth about its location, and the system self-reported location is easily falsifiable. Illustrative embodiments recognize that another geolocation technique is to rely on the location of the system Internet Protocol (IP) address stored in a database. However, IP address based location data is susceptible to database data changes, is not easily verifiable, is not always associated with a single computer system, is often not precise, even at the country / region level, and can be defeated by replacing the source system's real IP address with a fake IP address of a different location. Also, if the system to be geolocated is using a Virtual Private Network (VPN), IP address based location data will provide the location of the VPN, not the system itself. Thus, illustrative embodiments recognize the need for a computer system geolocation technique that can use a data source that is not controlled by the computer system itself for verification. SUMMARY

[0005] Illustrative embodiments provide client-server response time based computer system geolocation. One embodiment includes sending a challenge from a border server to a client system at a first time in response to a challenge request, the challenge specifying a computational problem for the client system to solve, the border server specified in a list of challenges sent to the client system. One embodiment includes receiving a challenge response at the border server from the client system at a second time, the challenge response including a solution to the computational problem. Embodiments include generating at the border server a certificate encoding an elapsed time between the first time and the second time, the certificate usable by the client system to prove a location of the client system. The certificate is sent from the border server to the client system. Thus, embodiments provide a method of implementing client-server response time based computer system geolocation. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the embodiments.

[0006] In another embodiment, the list of challenges includes a plurality of border servers, the plurality of border servers including the border server, each of the plurality of border servers having a known physical location. Thus, this embodiment provides additional detail of implementing client-server response time based computer system geolocation, where each of the plurality of border servers used to perform the geolocation has a known physical location.

[0007] In another embodiment, the known physical location of each of the plurality of border servers is used to select each of the plurality of border servers to include in the list of challenges. Thus, this embodiment provides additional details for implementing computer system geolocation based on client-server response times, where the known physical location of the border servers is used to select each of the plurality of border servers used to perform the geolocation.

[0008] In another embodiment, the elapsed time encoded in the certificate, a second elapsed time encoded in a second certificate generated by a second border server, and a third elapsed time encoded in a third certificate generated by a third border server are used to perform a trilateration of the location of the client system. Thus, this embodiment provides additional details for implementing computer system geolocation based on client-server response times using three certificates, each generated by a border server.

[0009] Another embodiment includes encrypting the certificate at the border server prior to sending the certificate, the signature performed using a key that is unknown to the client system. Thus, this embodiment provides additional details for implementing computer system geolocation based on client-server response times using an encrypted signed certificate.

[0010] Another embodiment includes sending a second challenge from the border server to the client system at a third time in response to a second challenge request, the second challenge specifying a string to be echoed by the client system. The embodiment includes receiving a second challenge response at the border server from the client system at a fourth time, the second challenge response including the string. The embodiment includes generating a fourth certificate at the border server encoding a lesser of the elapsed time and a second elapsed time, the second elapsed time including a difference between the fourth time and the third time, the fourth certificate usable by the client system to prove a location of the client system. Thus, this embodiment provides additional details for implementing computer system geolocation based on client-server response times by determining a second elapsed time and generating a certificate using a lesser of the elapsed time and the second elapsed time.

[0011] An embodiment includes a computer usable program product. The computer usable program product includes a computer readable storage medium and program instructions stored on the storage medium.

[0012] An embodiment includes a computer system. The computer system includes a processor, a computer readable memory, and a computer readable storage medium, and program instructions stored on the storage medium for execution by the processor via the memory. BRIEF DESCRIPTION OF DRAWINGS

[0013] The novel features believed characteristic of the application are set forth in the appended claims. The application itself, however, as well as a preferred mode of use, further objectives and advantages thereof, will best be understood by reference to the following detailed description of illustrative embodiments when read in conjunction with the accompanying drawings, wherein:

[0014] Figure 1 depicts a block diagram of a computing environment in accordance with an illustrative embodiment;

[0015] Figure 2 depicts a flow diagram of an example process for loading process software in accordance with an illustrative embodiment;

[0016] Figure 3 depicts a block diagram of an example configuration for client-server response time based computer system geolocation in accordance with an illustrative embodiment;

[0017] Figure 4 depicts a message sequence of an example configuration for implementing client-server response time based computer system geolocation in accordance with an illustrative embodiment;

[0018] Figure 5 depicts an example of client-server response time based computer system geolocation in accordance with an illustrative embodiment; and

[0019] Figure 6 depicts a flow diagram of an example process for client-server response time based computer system geolocation in accordance with an illustrative embodiment. DETAILED DESCRIPTION

[0020] Illustrative embodiments recognize a need for a computer system geolocation technique that can be verified using a data source that is not controlled by the computer system itself. Illustrative embodiments recognize that currently available tools or solutions do not address or provide adequate solutions for these needs.

[0021] The present disclosure addresses the above-mentioned deficiencies by providing a process (as well as a system, method, machine-readable medium, etc.) that transmits, from a border server to a client system, a challenge specifying a computational problem to be solved by the client system, in response to a challenge request, at a first time; receives, at the border server, a challenge response from the client system, at a second time; and generates, at the border server, a certificate encoding an elapsed time between the first time and the second time.

[0022] Illustrative embodiments provide computer system geolocation based on client-server response times. Illustrative embodiments include an embodiment that requests geolocation (a client embodiment), an embodiment from which the client embodiment requests geolocation (an identification embodiment), and an embodiment that measures response times of the client embodiment (a boundary embodiment). The client, identification, and boundary embodiments can be executed in the same or different systems. The client, identification, and boundary embodiments communicate messages to each other over a communications network, such as the Internet. Some embodiments communicate messages to each other using Hypertext Transfer Protocol Secure (HTTPS), in which messages are encrypted in transit between embodiments.

[0023] A client embodiment executed on a client system initiates a request for geolocation of the client system by sending a service request to an identification embodiment. In some embodiments, the service request includes a physical location that the client embodiment is requesting to be verified or confirmed. For example, the physical location to be verified or confirmed can have been obtained using a Global Positioning System (GPS) receiver, or received as input from a user. In some embodiments, the service request includes a desired geolocation accuracy (e.g., the requested geolocation should be accurate to within 2 km of the requested location) or a geolocation confidence level (e.g., the requested geolocation should have a 90% confidence), or both a desired geolocation accuracy and confidence level. Some non-limiting examples of service requests are requests to verify that the client system is in the continental portion of the United States ± 10 kilometers, within a 10 kilometer radius of a specified latitude and longitude with 90% confidence, or anywhere within the European Union. In other embodiments, the service request does not include a physical location that the client embodiment is requesting to be verified.

[0024] An identity embodiment receives a service request and selects one or more border servers for performing geolocation requested in the service request. Each border server has a fixed physical location known to the identity embodiment. In particular, each selected border server has a different physical location from any other selected border server because the selected border servers are available to determine the location of the client system. One identity embodiment selects one or more border servers based on the physical location included in the service request. For example, if the service request includes a request to verify that the client embodiment is on the continent of the United States, the identity embodiment can select four border servers, one in the northeast, northwest, southeast, and southwest corners of the continental United States. Another identity embodiment selects one or more border servers based on the location of the requesting system's IP address stored in a database. For example, if the service request originated from an IP address that, according to the database, is located in the European Union, the identity embodiment can select border servers distributed near the periphery of the European Union. Another identity embodiment selects one or more border servers based on a desired geolocation accuracy or confidence level, if available, or a default geolocation accuracy or confidence level. Another identity embodiment selects one or more border servers based on the known locations of the border servers. For example, selecting a border server in North America, a border server in Europe, and a border server in Africa can be sufficient to geolocate the system on which the client embodiment is executing to a particular continent. If a border embodiment is not already executing on the selected border server, the identity embodiment causes an instance of the border embodiment to start executing on the selected border server.

[0025] The identity embodiment notifies the selected border embodiments of its selection. The selection notification is also referred to as a reservation. In some embodiments, the notification includes a check of whether the selected border server is available for geolocation purposes, an identification of the client embodiment to be geolocated, a selection of the type of challenge to be used with the client embodiment, a number of times the challenge should be repeated, one or more criteria for determining the validity of elapsed time measurements of the border embodiment, an encryption key for use in communicating between the border embodiment and the client embodiment, or another time measurement or communication parameter.

[0026] The border embodiments respond to the notification of the identity embodiment with an acknowledgement. The acknowledgement indicates that the border embodiments are ready to respond to challenge requests from the client embodiment.

[0027] Once the identification embodiment receives confirmation from the border embodiments executing in each selected border server, the identification embodiment sends a challenge list to the client embodiment requesting geolocation. In embodiments, the challenge list includes communication information for the selected border embodiments, including an identification of each border embodiment, an identification for the client embodiment to use when communicating with the border embodiments (e.g., a message prefix), a number of times the challenge should be repeated, an encryption key or another time measurement or communication parameter to use when communicating between the border embodiments and the client embodiment.

[0028] The client embodiment sends a challenge request to the border embodiments. In some embodiments, the border embodiments are specified in the challenge list sent from the identification embodiment to the client embodiment. The challenge request is a message from the client embodiment to the border embodiments. The challenge request requests geolocation of the system on which the client embodiment is executing, formatted according to the communication parameters specified in the challenge list. For example, if the challenge list includes a message prefix for the client embodiment to use in communications with the border embodiments, the challenge request includes the specified message prefix.

[0029] Border embodiments respond to a challenge request by generating and sending a challenge to the client embodiment that sent the challenge request. The border embodiment records a first time that the challenge is sent, for use in calculating the time that elapses for the client embodiment to respond to the challenge. Since the challenge and the client embodiment's response to the challenge are only used to measure the time for the client embodiment to respond to the challenge, the challenge need not be computationally complex, nor need it take any particular format, but it needs to be something that the client cannot shorten the response time for by sending a response before the actual challenge is received. For example, a ping (sending an Internet Control Message Protocol (ICMP) echo request to a target system and waiting for an ICMP echo reply) can not be used as a challenge, because techniques are currently available to send a ping response before the ping is actually received. Thus, in some embodiments, the challenge specifies a computational problem to be solved by the client embodiment. The border embodiment selects a type of computational problem from a list of possible problem types (e.g., addition, subtraction, multiplication, division), and randomly selects parameters for the problem (e.g., which numbers to add together). One border embodiment randomly selects a type of computational problem from a list of possible problem types. Some non-limiting examples of challenges can be to add two and two, to multiply four and eight, or to perform an image manipulation or text conversion. In other embodiments, the challenge specifies a randomly selected string to be echoed by the client embodiment. In other embodiments, the challenge specifies a randomly selected JSON web token to be echoed by the client embodiment. A JSON web token is a currently available technique for creating a data (token) with optional signature and optional encryption. The payload of the token holds data in JSON (JavaScript Object Notation, a currently available standard data interchange format that uses human-readable text to store and transmit data objects composed of attribute-value pairs and arrays) that asserts one or more statements. Other challenges are possible and expected within the scope of the illustrative embodiments. In embodiments, the random selection is performed using a pseudo-random number generator, which is a currently available technique for generating pseudo-random numbers using a processor.

[0030] The client embodiment receives the challenge from the border embodiment, generates a response to the challenge, and sends the challenge response back to the border embodiment that issued the challenge. If the challenge was a computational problem, the challenge response includes a solution to the computational problem. For example, if the challenge was to add 2 and 2, the client embodiment can generate a challenge response indicating that the answer is 4. If the challenge was something to be echoed, the challenge response is the item to be echoed. Other challenge responses are possible and suitable for the particular challenge received, and are expected within the scope of the illustrative embodiments.

[0031] A border embodiment receives the generated challenge response from the client embodiment at a second time. The border embodiment calculates the elapsed time between the first time (when the challenge was sent) and the second time (when the challenge response was received).

[0032] One border embodiment repeats the challenge, challenge response, and elapsed time calculation one or more times, and uses the best (i.e., the smallest or minimum) elapsed time as the final value for the elapsed time. Because communications can be disrupted or slowed by network conditions, but not sped up, the smallest elapsed time best indicates the physical distance between the border server (with a known physical location) and the client system (with a measured or verified physical location).

[0033] The border embodiment generates a certificate that encodes the elapsed time between the first time and the second time, or the minimum elapsed time if multiple measurements are performed. The certificate and encoding need not be in any particular format. The certificate can be used by the client embodiment to prove the location of the client system. One border embodiment uses currently available technology to cryptographically sign the certificate. Cryptographically signing the certificate using a key known to the border embodiment and the identification embodiment, but not to the client embodiment, provides assurance that the client embodiment did not tamper with the certificate. The border embodiment sends the generated certificate to the client embodiment.

[0034] The client embodiment repeats the challenge request, challenge receipt, challenge response, and certificate receipt sequence described herein using different border embodiments specified in the list of challenges received from the identification embodiment. One client embodiment performs the challenge request, challenge receipt, challenge response, and certificate receipt sequence described herein in parallel with each other for multiple border embodiments. Another client embodiment performs the challenge request, challenge receipt, challenge response, and certificate receipt sequence described herein serially with each other for multiple border embodiments.

[0035] The client embodiment submits the received certificates to the identification embodiment. The identification embodiment receives one or more certificates from the client embodiment, optionally determines whether the certificates are valid using currently available technology, and decodes the elapsed time encoded into each certificate by the border embodiment.

[0036] Embodiments of the identification use elapsed time and currently available trilateration techniques to calculate a physical location of a client system. Trilateration or multilateration is the use of distances to determine an unknown physical location of a point. For example, a GPS receiver works by measuring the signal propagation time (and thus distance) between GPS satellites of known location and a receiver on the surface of the Earth. Measuring the distance to one satellite produces a circle of points at which the receiver can be located. Measuring the distance to a second satellite produces a second circle of points at which the receiver can be located, and thus the receiver can be at the point at which the two circles intersect. Measuring the distance to one or more additional satellites produces additional circles of points at which the receiver can be located, narrowing the possible location of the receiver to the point at which all the circles intersect. Similarly, if a client system is 10 ms away from one border server (the elapsed time between the challenge and the response), 15 ms away from a second border server, and 20 ms away from a third border server, then the client system must be at the point at which the 10 ms radius circle around the first border server, the 15 ms radius circle around the second border server, and the 20 ms radius circle around the third border server all intersect.

[0037] If the calculated physical location of the client system matches the service request of the client embodiment within a threshold amount, then the identification embodiment provides location verification to the client embodiment. In particular, if the service request includes a physical location that the client embodiment is requesting verification of, and the calculated physical location of the client system matches that physical location within a threshold amount, then the identification embodiment provides location verification of the requested physical location. If the service request includes a desired level of accuracy of geolocation or a desired level of confidence of geolocation, and the calculated physical location of the client system has at least the desired level of accuracy or confidence, then the identification embodiment provides location verification to the client embodiment. One identification embodiment uses currently available cryptographic signing techniques to sign the location verification with a key that is not accessible to the client embodiment.

[0038] Another set of embodiments measures and stores the elapsed time between a client system and a border server at an initial measurement time in the manner described herein. For example, the measurement at the initial measurement time can be performed as part of a registration process. At a later time, this set of embodiments re-measures the elapsed time between the same client system and border server in the manner described herein. If the elapsed time has not changed by more than a threshold amount or percentage between the initial measurement time and the later time, then the identification embodiment provides location verification to the client embodiment.

[0039] The client embodiment submits a location verification to a third party, thereby proving to the third party that the client system (on which the client embodiment executes) is in a verified physical location. In response to the submission, the third party allows the client embodiment or the client system to access data or perform operations that are only available to client systems having a verified physical location or an acceptable verified physical location. For example, a client system that has been verified to be in a particular country can be allowed by the third party to access video content that is only available in that country.

[0040] The client-server response time based geo-locating approach described herein is not available in currently available approaches in the technical field relating to computer system geo-locating. When implemented as executing on a device or data processing system, the method of the embodiments described herein include a substantial advance in the functionality of the device or data processing system in that, in response to a challenge request, the device or data processing system sends a challenge from a boundary server to a client system at a first time that specifies a computational problem to be solved by the client system, receives a challenge response from the client system at a second time at the boundary server, and generates a certificate at the boundary server that encodes an elapsed time between the first time and the second time.

[0041] For the sake of clarity, and without implying that any limitation on the scope of an illustrative embodiment, some of the illustrative embodiments are described below using some example configurations. One of ordinary skill in the art will readily understand that the aspects, as described below, can be extended to any of the other illustrative embodiments after reading this description.

[0042] Furthermore, a simplified diagram of a data processing environment is used in the drawings and illustrative embodiments. In a real computing environment, additional structures or components can be present in the data processing environment, or structures or components shown can be different from those shown, but serve the same or a similar function.

[0043] In addition, the illustrative embodiments are described using terminology and nomenclature commonly associated with certain prior art configurations. Any specific naming and / or designation of certain components is not intended to be limiting on the scope of the present disclosure. Any suitable names and / or designations of the components can be used in the illustrative embodiments.

[0044] Examples in the present disclosure are used only for the sake of clarity, and are not intended to limit the scope of the illustrative embodiments. Any advantages listed herein are only examples and are not intended to be limiting on the scope of the illustrative embodiments. Additional or different advantages can be realized by specific illustrative embodiments. Furthermore, a particular illustrative embodiment can have some, all, or none of the advantages listed above.

[0045] Furthermore, the illustrative embodiments can be implemented with respect to any type of data, data source, or access to a data source over a data network. Any type of data storage device can be used within the scope of the present application to provide data to embodiments of the present application, either locally or over a data network, within the scope of the present application. Within the scope of the illustrative embodiments, where embodiments are described using a mobile device, any type of data storage device suitable for use with a mobile device can be used to provide data to such embodiments, either locally or over a data network.

[0046] The illustrative embodiments are described using specific code, computer readable media, high-level features, design, architecture, protocols, layout, schematics, and tools, by way of example only, and are not limited to the illustrative embodiments. In some instances, particular software, tools, and data processing environments are used as examples in describing the illustrative embodiments. The illustrative embodiments can be used in conjunction with other comparable or similarly-purposed structures, systems, applications, or architectures. For example, other comparable mobile devices, structures, systems, applications, or architectures thereof can be used in conjunction with such embodiments of the present application, within the scope of the present application. The illustrative embodiments can be implemented in hardware, software, or a combination thereof.

[0047] The examples in the present disclosure are used only for the sake of clarity in describing the illustrative embodiments, and are not limiting of the present application. Additional data, operations, actions, tasks, activities, and manipulations can be contemplated according to the present disclosure and are within the scope of the illustrative embodiments.

[0048] Various aspects of the present disclosure are described by way of description text, flowcharts, block diagrams of computer systems, and / or block diagrams of machine logic included in computer program product (CPP) embodiments. With respect to any flowcharts, depending on the technology involved, the operations can be performed in a different order than that shown in the given flowcharts. For example, two operations shown in consecutive flowchart blocks can be performed in reverse order, as single integrated steps, concurrently, or in at least partial temporal overlap, again depending on the technology involved.

[0049] A computer program product embodiment ("CPP embodiment" or "CPP") is a term used in this disclosure to describe any collection of one or more storage media (also referred to as "media") collectively including one or more sets of instructions and / or data corresponding to the machine-readable code used to perform the computer operations specified in a given CPP claim. A "storage device" is any tangible device that can retain and store instructions for use by a computer processor. Without limitation, computer-readable storage media can be an electronic storage media, a magnetic storage media, an optical storage media, an electromagnetic storage media, a semiconductor storage media, a mechanical storage media, or any suitable combination of the foregoing. Some known types of storage devices that include these media are a magnetic disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a static random access memory (SRAM), a compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanical encoding device such as punch cards or holes / lands formed in the main surface of a disk, or any suitable combination of the foregoing. The term computer-readable storage media as used in this disclosure should not be construed as storage that is transient in nature, such as a transient signal example forms of radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission media, optical pulses through an optical fiber cable, electronic signals through a wire, and / or other transmission media. As those skilled in the art will appreciate, data is typically moved at certain incidental points in time during the normal operation of a storage device, such as during access, defragmentation, or garbage collection, but this does not make the storage device transitory, as the data is not transitory while stored.

[0050] Reference Figure 1FIG. 1 is a block diagram depicting a computing environment 100. The computing environment 100 contains an example of an environment for executing at least some computer code involved in performing the methods of the present invention, such as the application 200 providing client-server response time based geolocation according to an illustrative embodiment. In particular, the application 200 implements a client, identification, or boundary embodiment as described herein. In addition to the block 200, the computing environment 100 includes, for example, a computer 101, a wide area network (WAN) 102, an end user device (EUD) 103, a remote server 104, a public cloud 105, and a private cloud 106. In this embodiment, the computer 101 includes a processor set 110 (including a processing circuit 120 and a cache 121), a communication fabric 111, a volatile memory 112, a persistent storage 113 (including an operating system 122 and the block 200, as described above), a peripheral device set 114 (including a user interface (UI) device set 123, a storage 124, and an Internet of Things (IoT) sensor set 125), and a network module 115. The remote server 104 includes a remote database 130. The public cloud 105 includes a gateway 140, a cloud orchestration module 141, a host physical machine set 142, a virtual machine set 143, and a container set 144.

[0051] The computer 101 can take the form of a desktop computer, a laptop computer, a tablet computer, a smartphone, a smartwatch or other wearable computer, a mainframe computer, a quantum computer, or any other form of computer or mobile device now known or hereafter developed that is capable of running a program, accessing a network, or querying a database, such as the remote database 130. As is well understood in the computer arts, and depending on the technology, the execution of a computer-implemented method can be distributed among multiple computers and / or among multiple locations. On the other hand, in this presentation of the computing environment 100, the detailed discussion is focused on a single computer, particularly the computer 101, to make the presentation as simple as possible. The computer 101 can be located in the cloud, even though it is not shown in the cloud in FIG. 1. On the other hand, the computer 101 is not required to be in the cloud to any extent that can be positively indicated. Figure 1

[0052] ​The processor set 110 includes one or more computer processors of any type now known or developed in the future. The processing circuitry 120 can be distributed across multiple packages, for example, multiple coordinated integrated circuit chips. The processing circuitry 120 can implement multiple processor threads and / or multiple processor cores. The cache 121 is memory located in the processor chip package(s) and is typically used for data or code that should be quickly accessible to threads or cores running on the processor set 110. Cache memory is typically organized into multiple levels according to relative proximity to the processing circuitry. Alternatively, some or all of the cache for the processor set can be located "off-chip." In some computing environments, the processor set 110 can be designed to work with qubits and perform quantum computations.

[0053] Computer readable program instructions generally be loaded onto the computer 101 to cause the processor set 110 of the computer 101 to perform a series of operational steps to implement the computer-implemented method so that the instructions so executed will instantiate the methods specified in the flow charts and / or narrative descriptions of the computer-implemented methods included in this document (collectively, the "invention methods"). These computer readable program instructions are stored in various types of computer readable storage media such as the cache 121 and other storage media discussed below. The program instructions and related data are accessed by the processor set 110 to control and direct the execution of the invention methods. In the computing environment 100, at least some of the instructions for performing the invention methods can be stored in the persistent storage 113 in the block 200.

[0054] The communication fabric 111 is a signal-conducting pathway that allows the various components of the computer 101 to communicate with each other. Typically, this fabric is constructed of switches and conductive pathways, for example, switches and conductive pathways that make up buses, bridges, physical input / output ports, and the like. Other types of signal communication pathways can be used, such as fiber-optic communication pathways and / or wireless communication pathways.

[0055] The volatile memory 112 is any type of volatile memory now known or developed in the future. Examples include dynamic random access memory (RAM) or static RAM. Typically, the volatile memory 112 is characterized by random access, although this is not required unless affirmatively indicated. In the computer 101, the volatile memory 112 is located in a single package and is internal to the computer 101, although, alternatively or additionally, the volatile memory can be distributed across multiple packages and / or located externally with respect to the computer 101.

[0056] The persistent storage 113 is any form of non-volatile storage for a computer now known or to be developed in the future. The non-volatility of this storage means that stored data is maintained regardless of whether power is supplied to the computer 101 and / or directly to the persistent storage 113. The persistent storage 113 can be read-only memory (ROM), but typically at least a portion of the persistent storage allows writing of data, deletion of data, and rewriting of data. Some common forms of persistent storage include magnetic disks and solid-state storage devices. The operating system 122 can take several forms, such as various known proprietary operating systems or open-source portable operating system interface type operating systems that employ a kernel. The code included in the block 200 typically includes at least some of the computer code involved in performing the methods of the present invention.

[0057] The peripheral set 114 includes a set of peripherals of the computer 101. The data communication connections between the peripherals and other components of the computer 101 can be implemented in various ways, such as a Bluetooth connection, a near-field communication (NFC) connection, a connection by a cable such as a universal serial bus (USB) type cable, a plug-in type connection (e.g., a secure digital (SD) card), a connection over a local area communication network, and even a connection over a wide area network such as the Internet. In various embodiments, the UI device set 123 can include components such as a display screen, a speaker, a microphone, a wearable device (e.g., eyewear and a smartwatch), a keyboard, a mouse, a printer, a touchpad, a game controller, and a haptic device. The storage 124 is an external storage device such as an external hard drive or a pluggable storage device such as an SD card. The storage 124 can be persistent and / or volatile. In some embodiments, the storage 124 can take the form of a quantum computing storage device for storing data in the form of qubits. In embodiments where the computer 101 is required to have a large amount of storage (e.g., in cases where the computer 101 stores and manages a large database locally), then this storage can be provided by a peripheral storage device designed for storing very large amounts of data, such as a storage area network (SAN) shared by multiple geographically distributed computers. The IoT sensor set 125 consists of sensors that can be used in Internet of Things applications. For example, one sensor can be a thermometer, while another sensor can be a motion detector.

[0058] The network module 115 is a collection of computer software, hardware, and firmware that allows the computer 101 to communicate with other computers over the WAN 102. The network module 115 can include hardware such as a modem or Wi-Fi signal transceiver, software for packetizing and / or unpacketing data for communication network transmission, and / or web browser software for transmitting data over the Internet. In some embodiments, the network control functions and network forwarding functions of the network module 115 are performed on the same physical hardware device. In other embodiments, such as embodiments that utilize software defined networking (SDN), the control functions and forwarding functions of the network module 115 are performed on physically separate devices, such that the control functions manage several different network hardware devices. Computer readable program instructions for performing the methods of the present application can generally be downloaded to the computer 101 from an external computer or external storage device through the network adapter card or network interface included in the network module 115.

[0059] The WAN 102 is any wide area network (e.g., the Internet) capable of transmitting computer data over non-local distances through any technology now known or later developed for transmitting computer data. In some embodiments, the WAN 102 can be replaced and / or supplemented by a local area network (LAN) designed to transmit data between devices located in a local area, such as a Wi-Fi network. WANs and / or LANs typically include computer hardware such as copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and edge servers.

[0060] An end user device (EUD) 103 is any computer system used and controlled by an end user (e.g., a customer of the business operating the computer 101), and can take any form discussed above in connection with the computer 101. The EUD 103 typically receives helpful and useful data from the operation of the computer 101. For example, in the hypothetical case where the computer 101 is designed to provide recommendations to end users, the recommendations would typically be transmitted from the network module 115 of the computer 101 to the EUD 103 over the WAN 102. In this way, the EUD 103 can display or otherwise present the recommendations to the end user. In some embodiments, the EUD 103 can be a client device such as a thin client, thick client, mainframe computer, desktop computer, and so on.

[0061] The remote server 104 is any computer system that provides at least some data and / or functionality to the computer 101. The remote server 104 can be controlled and used by the same entity that operates the computer 101. The remote server 104 represents a machine(s) that collects and stores data that is helpful and useful for use by other computers, such as the computer 101. For example, in the case where the computer 101 is designed and programmed to provide recommendations based on historical data, then that historical data can be provided to the computer 101 from a remote database 130 of the remote server 104.

[0062] The public cloud 105 is any computer system that is available for use by multiple entities that provides on-demand availability of computer system resources and / or other computer capabilities, in particular data storage (cloud storage) and computing power, without direct active management by the user. Cloud computing generally utilizes resource sharing to achieve consistency and economies of scale. Direct and active management of the computing resources of the public cloud 105 is performed by computer hardware and / or software of the cloud orchestration module 141. The computing resources provided by the public cloud 105 are generally implemented by virtual computing environments running on various computers that make up the host physical machine set 142, which is the universe of physical computers in and / or available to the public cloud 105. The virtual computing environments are generally in the form of virtual machines from the virtual machine set 143 and / or containers from the container set 144. It will be appreciated that these VCEs can be stored as images and can be transferred as images or after instantiation of the VCEs between various physical machine hosts. The cloud orchestration module 141 manages the transfer and storage of the images, deploys new instantiations of the VCEs and manages the active instantiations of the VCE deployments. The gateway 140 is a collection of computer software, hardware, and firmware that allows the public cloud 105 to communicate over the WAN 102.

[0063] Some further explanation of virtualized computing environments (VCEs) will now be provided. VCEs can be stored as “images”. New active instances of VCEs can be instantiated from images. Two familiar types of VCEs are virtual machines and containers. Containers are VCEs that use operating system-level virtualization. This refers to an operating system feature in which the kernel allows multiple isolated user space instances, called containers, to exist. From the perspective of the programs running in them, these isolated user space instances generally behave as real computers. Computer programs running on an ordinary operating system can utilize all of the resources of that computer, such as connected devices, files and folders, network shares, CPU power, and quantifiable hardware capabilities. However, programs running within a container can only use the contents of the container and the devices allocated to the container, a feature known as containerization.

[0064] The private cloud 106 is similar to the public cloud 105 except that the computing resources are available only for use by a single enterprise. While the private cloud 106 is depicted as being in communication with the WAN 102, in other embodiments, the private cloud can be completely disconnected from the Internet and only accessible through a local / private network. A hybrid cloud is a combination of multiple clouds of different types (e.g., private, community, or public cloud types), often implemented by different vendors respectively. Each of the multiple clouds remains a separate and discrete entity, but the larger hybrid cloud architecture is bound together through standardized or proprietary technologies that enable orchestration, management, and / or data / application portability between the multiple constituent clouds. In this embodiment, the public cloud 105 and the private cloud 106 are both part of a larger hybrid cloud.

[0065] Measured service: cloud systems automatically control and optimize resource use by leveraging a metering capability at some level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, reported, and billed, providing transparency for both the provider and consumer of the utilized service.

[0066] Reference Figure 2 The figure depicts a flowchart of an example process for loading process software, in accordance with an illustrative embodiment. The flowchart can be executed by a device such as the computer 101, the end user device 103, the remote server 104, or a device in the private cloud 106 or the public cloud 105. Figure 1

[0067] While it can be appreciated that the process software that implements the client-server response time based computer system geolocation can be deployed by being manually loaded directly into the client, server, and proxy computers via loading a storage medium such as a CD, DVD, etc., the process software can also be deployed into the computer system automatically or semi-automatically by sending the process software to a central server or a group of central servers. The process software is then downloaded into the client computers that will execute the process software. Alternatively, the process software is sent directly to the client system via email. The process software is then separated into or loaded into a directory by executing a set of program instructions that separates the process software into a directory. Another option is to send the process software directly to a directory on the hard drive of the client computer. When a proxy server is present, the process will select the proxy server code, determine on which computers to place the proxy server's code, send the proxy server code, and then install the proxy server code on the proxy computers. The process software will be sent to the proxy server and then it will be stored on the proxy server.

[0068] ​Step 202 begins the process of deploying the process software. The initial step is to determine if there are any programs that will reside on one or more servers when the process software is executed (203). If this is the case, the server that will contain the executable is identified (229). The process software for the one or more servers is transferred directly to the server's storage via FTP or some other protocol or by using a shared file system (230). The process software is then installed on the server (231).

[0069] Next, it is determined if the process software is to be deployed by having the user access the process software on one or more servers (204). If the user is to access the process software on the server, the server address that will store the process software is identified (205).

[0070] It is determined if a proxy server is to be established to store the process software (220). A proxy server is a server that sits between a client application such as a web browser and the real server. It intercepts all requests to the real server to see if it can satisfy the request itself. If not, it forwards the request to the real server. The two main benefits of a proxy server are to improve performance and to filter requests. If a proxy server is needed, the proxy server is installed (221). The process software is sent to the server(s) via a protocol such as FTP or copied directly from the source file to the server file through file sharing (222). Another embodiment involves sending a transaction to the server(s) that contain the process software and having the server process the transaction and then receiving the process software and copying it to the server's file system. Once the process software is stored on the server, the user accesses the process software on the server via their client computer and copies it to their client computer file system (223). Another embodiment is to have the server automatically copy the process software to each client and then run the process software's installer on each client computer. The user executes the program to install the process software on their client computer (232) and then exits the process (210).

[0071] In step 206, it is determined if the process software is to be deployed by sending the process software to the user via email. The set of users that are to deploy the process software is identified along with the addresses of the users' client computers (207). The process software is sent to each user's client computer via email (224). The user then receives the email (225) and then separates the process software from the email to a directory on their client computer (226). The user executes the program to install the process software on their client computer (232) and then exits the process (210).

[0072] Finally, a determination is made as to whether the processing software is to be sent directly to the user's directory on its client computer (208). If so, the user's directory is identified (209). The processing software is directly transferred to the user's client computer directory (227). This can be accomplished in a variety of ways, such as but not limited to, a shared file system directory, then copied from the sender's file system to the recipient user's file system, or using a transfer protocol such as File Transfer Protocol (FTP). The user accesses the directory on its client file system to prepare for installation of the processing software (228). The user executes the program to install the processing software on its client computer (232), and then exits the process (210).

[0073] Referring to Figure 3 The figure depicts a block diagram of an example configuration for computer system geolocation based on client-server response time, according to an illustrative embodiment. In particular, an identification (ID) server 310, a boundary server 320, and a client 330 are each examples of an application 200 in Figure 1

[0074] In the illustrated embodiment, a service request generation module 332 of the client 330 executing on a client system initiates a geolocation request for the client system by sending a service request to the identification server 310. In some implementations of the module 332, the service request includes a physical location that the client 330 is requesting to be verified or confirmed. For example, the physical location to be verified or confirmed can have been obtained using a GPS receiver, or received as input from a user. In some implementations of the module 332, the service request includes a desired geolocation accuracy (e.g., the requested geolocation should be accurate to within 2 km of the requested location) or a geolocation confidence level (e.g., the requested geolocation should have a 90% confidence), or both a desired geolocation accuracy and confidence level. Some non-limiting examples of service requests are requests to verify that the client 330 is in the continental portion of the United States ± 10 kilometers, within a 10 kilometer radius of a specified latitude and longitude, or anywhere within the European Union with 90% confidence, or anywhere within the European Union. In other implementations of the module 332, the service request does not include a physical location that the client 330 is requesting to be verified.

[0075] ​The border server ID module 312 in the ID server 310 receives the service request and selects one or more instances of the border server 320 for performing the geographic positioning requested in the service request. Each instance of the border server 320 has a fixed physical location known to the module 312. In particular, each selected instance of the border server 320 has a different physical location from any other selected border server because the selected border servers are available to determine the location of the client system 330. One implementation of the module 312 selects one or more instances of the border server 320 based on the physical location included in the service request. For example, if the service request includes a request to verify that the client 330 is on the continental United States, the module 312 can select four border servers, one at the northeast corner, one at the northwest corner, one at the southeast corner, and one at the southwest corner of the continental United States. Another implementation of the module 312 selects one or more border servers based on the location of the IP address of the client 330 stored in a database. For example, if the service request originated from an IP address in the European Union according to the database, the module 312 can select border servers distributed near the periphery of the European Union. Another implementation of the module 312 selects one or more border servers based on a desired geographic positioning accuracy or confidence level, if available, or a default geographic positioning accuracy or confidence level. Another implementation of the module 312 selects one or more border servers based on the known locations of the border servers. For example, selecting a border server in North America, a border server in Europe, and a border server in Africa can be sufficient to geographically locate the system on which the client 330 is executing to a particular continent. If the border server 320 is not already executing on the selected border server, the module 312 causes an instance of the border server 320 to begin executing on the selected border server.

[0076] The module 312 notifies the selected instances of the border server 320 of its selection. The selection notification is also referred to as a reservation. In some implementations of the module 312, the notification includes a check of whether an instance of the border server 320 is available for geographic positioning purposes, an identification of the client 330 to be geographically positioned, a selection of the type of challenge to be used with the client 330, a number of times the challenge should be repeated, one or more criteria for determining the validity of elapsed time measurements of the border server 320, an encryption key for use in communications between the border server 320 and the client 330, or another time measurement or communication parameter.

[0077] The border server 320 responds to the notification with an acknowledgement. The acknowledgement indicates that the border server 320 is ready to respond to challenge requests from the client 330.

[0078] Once the module 312 has received the confirmation from the instances of the border server 320 executing in each of the selected border servers, the module 312 sends the challenge list to the client 330. In implementations of the module 312, the challenge list includes communication information for the selected instance(s) of the border server 320, including one or more of: an identification of each of the instance(s) of the border server 320, an identification (e.g., a message prefix) to be used by the client 330 in communicating with the instances of the border server 320, a number of times the challenge should be repeated, a cryptographic key to be used in communications between the instances of the border server 320 and the client 330, or another time measurement or communication parameter.

[0079] The challenge request generation module 334 sends a challenge request to the instance of the border server 320. In some implementations, the instance is specified in the challenge list sent from the identification server 310 to the client 330. The challenge request is a message from the client 330 to the instance of the border server 320. The challenge request requests a geolocation of the system on which the client 330 is executing, formatted according to the communication parameters specified in the challenge list. For example, if the challenge list includes a message prefix to be used by the client 330 in communications with the instance of the border server 320, the challenge request includes the specified message prefix.

[0080] The challenge generation module 322 responds to the challenge request by generating a challenge and sending it to the client 330. The module 322 records the first time the challenge is sent, for use in calculating the elapsed time of the client's 330 response to the challenge. The challenge need not be computationally complex, and need not be in any particular format, but does need to be something that the message client 330 cannot shorten the response time by sending a response before the actual challenge is received. For example, a ping can not be used as a challenge, because techniques are currently available to send a ping response before the ping is actually received. Thus, in some embodiments of the module 322, the challenge specifies a computational problem to be solved by the client 330, and the module 322 selects a type of computational problem from a list of possible types (e.g., addition, subtraction, multiplication, division), and randomly selects the parameters of the problem (e.g., which numbers to add together). One embodiment of the module 322 randomly selects a type of computational problem from a list of possible types of problems. Some non-limiting examples of challenges can be to add two and two, to multiply four and eight, or to perform an image manipulation or text conversion. In other embodiments of the module 322, the challenge specifies a randomly selected string to be echoed by the client 330. In other embodiments of the module 322, the challenge specifies a randomly selected JSON web token to be echoed by the client 330. Other challenges are also possible. In embodiments of the illustrative embodiments, the random selection is performed using a pseudo-random number generator, which is a currently available technique for generating pseudo-random numbers using a processor.

[0081] The challenge response module 336 receives the challenge from the instance of the border server 320, generates a response to the challenge, and sends the challenge response back to the instance of the border server 320 that issued the challenge. If the challenge was a computational problem, the challenge response includes the solution to the computational problem. For example, if the challenge was to add two and two, the module 336 can generate a challenge response indicating that the answer is four. If the challenge was something to be echoed, the challenge response is the item to be echoed. Other challenge responses are also possible and appropriate for the particular challenge received.

[0082] The elapsed time certificate generation module 324 receives the generated challenge response from the client 330 at a second time. The module 324 calculates the elapsed time between the first time (when the challenge was sent) and the second time (when the challenge response was received).

[0083] One embodiment of the border server 320 repeats the challenge, challenge response, and elapsed time calculation one or more times and uses the best (i.e., smallest or minimum) elapsed time as the final value for the elapsed time. Because communications can be disrupted or slowed by network conditions, but not accelerated, the minimum elapsed time is the best indication of the physical distance between the border server (with a known physical location) and the client system (with a measured or verified physical location).

[0084] The module 324 generates a certificate that encodes the elapsed time between the first time and the second time, or the minimum elapsed time if multiple measurements are performed. The certificate can be used by the client 330 to prove the location of the client system. One embodiment of the module 324 uses currently available techniques to cryptographically sign the certificate. Cryptographically signing the certificate using keys known to the border server 320 and the identification server 310, but not to the client 330, provides assurance that the client 330 did not tamper with the certificate. The module 324 sends the generated certificate to the client 330.

[0085] The client 330 repeats the challenge request, challenge receipt, challenge response, and certificate receipt sequence described herein using different instances of the border server 320 specified in the challenge list received from the identification server 310. One embodiment of the client 330 performs the challenge request, challenge receipt, challenge response, and certificate receipt sequence described herein in parallel with respect to multiple instances of the border server 320. Another embodiment of the client 330 performs the challenge request, challenge receipt, challenge response, and certificate receipt sequence described herein serially with respect to multiple instances of the border server 320.

[0086] The certificate submission module 338 submits the received certificates to the identification server 310. The location verification module 314 receives one or more certificates from the client 330, optionally determines that the certificates are valid using currently available techniques, and decodes the elapsed time encoded into each certificate by an instance of the border server 320.

[0087] Module 314 uses the elapsed times and current available trilateration techniques to calculate the physical location of the client system. Trilateration or multilateration is the use of distances to determine the unknown physical location of a point. For example, if client 330 is 10 ms from one instance of border server 320 (the elapsed time between the challenge and response), 15 ms from a second instance of border server 320, and 20 ms from a third instance of border server 320, then client 330 must be at the point where the 10 ms radius circle around the first instance of border server 320, the 15 ms radius circle around the second instance of border server 320, and the 20 ms radius circle around the third instance of border server 320 all intersect.

[0088] If the calculated physical location of client 330 matches, within a threshold amount, the physical location that client 330 requested service for, then module 314 provides location verification to client 330. Specifically, if the service request includes a physical location that client 330 is requesting verification of, and the calculated physical location of client 330 matches, within a threshold amount, that physical location, then module 314 provides location verification of the requested physical location. If the service request includes a desired level of geographic location accuracy or a geographic location confidence level, and the calculated physical location of client 330 has at least the desired level of accuracy or confidence level, then module 314 provides location verification to client 330. One embodiment of module 314 uses currently available cryptographic signature techniques to sign the location verification that key client 330 does not have access to.

[0089] Another set of embodiments of identification server 310, border server 320, and client 330 measure and store the elapsed times between client systems and border servers at an initial measurement time in the manner described herein. For example, the measurements at the initial measurement time can be performed as part of a registration process. At a later time, this set of embodiments re-measures the elapsed times between the same client systems and border servers in the manner described herein. If the elapsed times have not changed more than a threshold amount or percentage between the initial measurement time and the later time, then identification server 310 provides location verification to client 330.

[0090] Client 330 submits the location verification to a third party, thereby proving to the third party that the client system (on which client 330 executes) is at a verified physical location. In response to the submission, the third party allows client 330 or its system to access data or perform operations that are only available to client systems with a verified physical location or an acceptable verified physical location. For example, a third party that has verified a client system to be in a particular country can allow the client system to access video content that is only available in the country.

[0091] Referring toFigure 4 which depicts a message sequence for an example configuration for implementing client-server response time based computer system geolocation, in accordance with an illustrative embodiment. An identification (ID) server 310 and a client 330 are the same as in Figure 3 B servers 421, 422, and 423 are each an instance of the border server 320 in Figure 3

[0092] As depicted, the client 330 initiates a request for geolocation of the client system by sending an authentication 430 (service request) to the identification server 310. In response, the ID server 310 selects the B servers 421, 422, and 423 for performing the geolocation requested in the service request, and sends a reservation 1 431, a reservation 2 432, and a reservation n 433 to the B servers 421, 422, and 423, respectively, notifying each selected instance of its selection. The B servers 421, 422, and 423 respond with an acknowledgement (not shown). Once the ID server 310 receives the acknowledgements from the B servers 421, 422, and 423, the ID server 310 sends a challenge_list 434 to the client 330.

[0093] The client 330 then sends an ask_challenge1 440 (challenge request) to the B server 421. The B server 421 responds to the ask_challenge1 440 by generating (init_challenge 441) and sending a challenge (challenge 1 442) to the client 330. The B server 421 records the first time the challenge was sent. The client 330 generates a response 1 443 and sends the response 1 443 back to the B server 421. The B server 421 generates and sends a certificate 1 444, encoding the elapsed time between the challenge 1 442 and the response 1 443.

[0094] The client 330 also sends a challenge request ask_challenge2 450 to the B server 422. The B server 422 responds to the ask_challenge2 450 by generating (init_challenge 451) and sending a challenge (challenge 2 452) to the client 330. The B server 422 records the first time the challenge was sent. The client 330 generates a response 2 453 and sends the response 2 453 back to the B server 422. The B server 422 generates and sends a certificate 2 454, encoding the elapsed time between the challenge 2 452 and the response 2 453.

[0095] ​Client 330 also sends a challenge request ask_challenge3 460 to B server 423. B server 423 responds to ask_challenge3 460 by generating (init_challenge 461) and sending a challenge (Challenge 3 462) to client 330. B server 423 records the first time the challenge was sent. Client 330 generates a response 3 463 and sends response 3 463 back to B server 423. B server 423 generates and sends a certificate 3 464 encoding the elapsed time between challenge 3 462 and response 3 463.

[0096] Client 330 then submits the challenge response 470 (received certificate) to identity server 310, which responds to client 330 with an acknowledgement 471 (location verification).

[0097] Reference is made to Figure 5 which depicts an example of client-server response time based computer system geolocation in accordance with an illustrative embodiment. Identity (ID) server 310 is the same as ID server 310 in Figure 3 B servers 521, 522, 523, and 524 are each an instance of boundary server 320 in Figure 3 Client 530 and 531 are each an instance of client 330 in Figure 3

[0098] ID server 310 knows the physical locations of B servers 521, 522, 523, and 524 forming boundary 510. Client 530 reports to ID server 310 a certificate including ti (elapsed time between client 530 and B server 521), t2 (elapsed time between client 530 and B server 524), t3 (elapsed time between client 530 and ID server 310 as a boundary server instance), t4 (elapsed time between client 530 and B server 523), and t5 (elapsed time between client 530 and B server 522). ID server 310 uses ti, t2, t3, t4, and t5 to determine that client 530 is within boundary 510.

[0099] ​The client 531 reports a certificate to the ID server 310 including t9 (elapsed time between the client 531 and the B server 521), t7 (elapsed time between the client 531 and the B server 524), t8 (elapsed time between the client 531 and the ID server 310 as a border server instance), t6 (elapsed time between the client 531 and the B server 523), and t10 (elapsed time between the client 531 and the B server 522). The ID server 310 uses t6, t7, t8, t9, and t10 to determine that the client 5301 is not within the border 510.

[0100] Referring to Figure 6 The figure depicts a flowchart of an example process for computer system geolocation based on client-server response times, according to an illustrative embodiment. The process 600 can be implemented in the border server 320 in Figure 3 The figure depicts a flowchart of an example process for computer system geolocation based on client-server response times, according to an illustrative embodiment. The process 600 can be implemented in the border server 320 in

[0101] In the illustrated embodiment, at block 602, the process sends a challenge from the border server to a client system at a first time in response to a challenge request, the challenge specifying a computational problem for the client system to solve, the border server specifying in a list of challenges sent to the client system. At block 604, the process receives a challenge response at the border server from the client system at a second time, the challenge response including a solution to the computational problem. At block 606, the process generates, at the border server, a certificate encoding an elapsed time between the first time and the second time, the certificate usable by the client system to prove a location of the client system. At block 608, the process sends the certificate from the border server to the client system. The process then ends.

[0102] The following definitions and abbreviations are herewith used for the explanations of the claims and the specification. As used herein, the terms “comprises,” “comprising,” “includes,” “including,” “has,” “having,” “contains,” “containing,” or any other variation thereof, are intended to cover a non-exclusive inclusion. For example, a composition, a mixture, a process, a method, an article, or an apparatus that comprises a list of elements is not necessarily limited to only those elements but can include other elements not expressly listed or inherent to such composition, mixture, process, method, article, or apparatus.

[0103] In addition, the term "illustrative" is used herein to mean "serving as an example, instance, or illustration." Any implementation or design described herein as "illustrative" is not necessarily to be construed as preferred or advantageous over other implementations or designs. The terms "at least one" and "one or more" are understood to include any integer number greater than or equal to one, i.e., one, two, three, four, etc. The terms "a plurality" are understood to include any integer number greater than or equal to one, i.e., two, three, four, five, etc. The term "connection" can include an indirect "connection" and a direct "connection."

[0104] References in the specification to "one embodiment," "an embodiment,” "an example embodiment,” etc., indicate that the embodiment described can include a particular feature, structure, or characteristic, but every embodiment can not necessarily include the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Furthermore, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of those skilled in the art to effect such feature, structure, or characteristic in connection with other

[0105] The terms "approximately," "substantially," "about," and variations thereof, are intended to include the degree of error associated with measurements that naturally occur due to the equipment used in making such measurements. For example, "about" can include a range of ± 8% or 5%, or 2% of a given value.

[0106] The description of various embodiments of the present application is presented for the purpose of illustration and description. It is not intended to be exhaustive or to limit the embodiments to the precise form disclosed. Many modifications and variations are possible in light of the above teaching. The terminology used is for the purpose of describing the embodiments and its intended application, and is not intended to limit the scope of the present application.

[0107] The description of various embodiments of the present application is presented for the purpose of illustration and description. It is not intended to be exhaustive or to limit the embodiments to the precise form disclosed. Many modifications and variations are possible in light of the above teaching. The terminology used is for the purpose of describing the embodiments and its intended application, and is not intended to limit the scope of the present application.

[0108] Accordingly, in an illustrative embodiment, a computer-implemented method, system or apparatus, and computer program product are provided for managing engagement of online communities and other related features, functions or operations. Where an embodiment or a portion thereof is described as being implemented in an application, the computer-implemented method, system or apparatus, computer program product, or a portion thereof, is adapted or configured to be used with a suitable and comparable manifestation of the type of device.

[0109] Where an embodiment is described as implemented in an application, delivery of the application in a software as a service (SaaS) model is contemplated within the scope of the illustrative embodiments. In a SaaS model, a user is provided the ability to implement the application by executing the application in a cloud infrastructure. The user can access the application using a variety of client devices through a thin-client interface such as a web browser (e.g., web-based e-mail) or other light-weight client application. The user does not manage or control the underlying cloud infrastructure including network, servers, operating systems, or storage. In some cases, the user can not even manage or control the capabilities of the SaaS application. In some other cases, the SaaS implementation of the application can allow for limited, specific user- specific application configuration settings.

[0110] Embodiments of the present invention can also be delivered as part of a service agreement with a customer company, non-profit organization, government entity, internal organizational structure, etc. Aspects of these embodiments can include configuring computer systems to perform some or all of the methods described herein, and deploying software, hardware, and web services that implement some or all of the methods described herein. Aspects of these embodiments can also include analyzing the operation of a client, creating recommendations in response to the analysis, building systems that implement portions of the recommendations, integrating the systems into existing processes and infrastructure, metering the use of the systems, allocating costs to users of the systems, and billing for the use of the systems. While the above-described embodiments of the present invention have been described with respect to their respective advantages, the present invention is not limited to the specific combinations described. Rather, these embodiments can also be combined in any manner and in any number, without losing their beneficial effects, in accordance with the intended deployment of the present invention.

Claims

1. A computer-implemented method comprising: in response to a challenge request, sending, from a border server to a client system at a first time, a challenge, the challenge specifying a computational problem for the client system to solve, the border server specified in a list of challenges sent to the client system; receiving, at the border server from the client system at a second time, a challenge response, the challenge response including a solution to the computational problem; generating, at the border server, a certificate encoding an elapsed time between the first time and the second time, the certificate usable by the client system to prove a location of the client system; and sending, from the border server to the client system, the certificate. the list of challenges includes a plurality of border servers, the plurality of border servers including the border server, each of the plurality of border servers having a known physical location.

2. The computer-implemented method of claim 1, wherein, the known physical location of each of the plurality of border servers is used to select each of the plurality of border servers to include in the list of challenges.

3. The computer-implemented method of claim 2, wherein, the elapsed time encoded in the certificate, a second elapsed time encoded in a second certificate generated by a second border server, and a third elapsed time encoded in a third certificate generated by a third border server are usable to perform a trilateration of the location of the client system.

4. The computer-implemented method of any one of claims 1 to 3, wherein, 5. The computer-implemented method of any of claims 1 to 4, further comprising: prior to the sending, cryptographically signing, at the border server, the certificate, the signing performed using a key unknown to the client system.

6. The computer-implemented method of any of claims 1 to 5, further comprising: at a third time, in response to a second challenge request, sending, from the border server to the client system, a second challenge, the second challenge specifying a string of characters to be echoed by the client system; at a fourth time, receiving, at the border server from the client system, a second challenge response, the second challenge response including the string of characters; and generating, at the border server, a fourth certificate, the fourth certificate encoding a lesser of the elapsed time and a second elapsed time, the second elapsed time including a difference between the fourth time and the third time, the fourth certificate usable by the client system to prove the location of the client system.

7. A computer program product comprising one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instructions executable by a processor to cause the processor to perform operations comprising: in response to a challenge request, sending, from a border server to a client system at a first time, a challenge, the challenge specifying a computational problem for the client system to solve, the border server specified in a list of challenges sent to the client system; receiving, at the border server from the client system at a second time, a challenge response, the challenge response including a solution to the computational problem; ​ ​ generating, at the border server, a certificate encoding an elapsed time between the first time and the second time, the certificate usable by the client system to prove a location of the client system; and sending the certificate from the border server to the client system.

8. The computer program product of claim 7, wherein, The stored program instructions are stored in a computer-readable storage device in a data processing system, and wherein the stored program instructions are transferred from a remote data processing system over a network.

9. The computer program product of claim 7, wherein, The stored program instructions are stored in a computer-readable storage device in a server data processing system, and wherein the stored program instructions are downloaded in response to a request over a network to a remote data processing system for use in a computer-readable storage device associated with the remote data processing system, the computer program product further comprising: program instructions to meter usage of the program instructions associated with the request; and program instructions to generate an invoice based on the metered usage.

10. The computer program product of claim 7, wherein, The list of challenges includes a plurality of border servers, the plurality of border servers including the border server, each of the plurality of border servers having a known physical location.

11. The computer program product of claim 10, wherein, The known physical location of each of the plurality of border servers is used to select each of the plurality of border servers to include in the list of challenges.

12. The computer program product of any one of claims 7, 10, 11, wherein, The elapsed time encoded in the certificate, a second elapsed time encoded in a second certificate generated by a second border server, and a third elapsed time encoded in a third certificate generated by a third border server are usable to perform a trilateration of the location of the client system.

13. The computer program product of any of claims 7, 10-12, further comprising: prior to the sending, cryptographically signing the certificate at the border server, the signing performed using a key unknown to the client system.

14. The computer program product of any of claims 7, 10-13, further comprising: at a third time, in response to a second challenge request, sending a second challenge from the border server to the client system, the second challenge specifying a string of characters to be echoed by the client system; at a fourth time, receiving a second challenge response at the border server from the client system, the second challenge response including the string of characters; and generating, at the border server, a fourth certificate, the fourth certificate encoding a lesser of the elapsed time and a second elapsed time, the second elapsed time including a difference between the fourth time and the third time, the fourth certificate usable by the client system to prove the location of the client system.

15. A computer system comprising a processor and one or more computer- readable storage media, and program instructions collectively stored on the one or more computer-readable storage media, the program instructions executable by the processor to cause the processor to perform operations comprising: In response to a challenge request, sending a challenge from a border server to a client system at a first time, the challenge specifying a computational problem to be solved by the client system, the border server specified in a challenge list sent to the client system; At a second time, receiving a challenge response from the client system at the border server, the challenge response including a solution to the computational problem; Generating a certificate at the border server encoding an elapsed time between the first time and the second time, the certificate usable by the client system to prove a location of the client system; And Sending the certificate from the border server to the client system.

16. The computer system of claim 15, wherein, The challenge list includes a plurality of border servers, the plurality of border servers including the border server, each of the plurality of border servers having a known physical location.

17. The computer system of claim 16, wherein, The known physical location of each of the plurality of border servers is used to select each of the plurality of border servers to include in the challenge list.

18. The computer system of any one of claims 15 to 17, wherein, The elapsed time encoded in the certificate, a second elapsed time encoded in a second certificate generated by a second border server, and a third elapsed time encoded in a third certificate generated by a third border server are usable to perform a trilateration of the location of the client system.

19. The computer system of any of claims 15 to 18, further comprising: Before the sending, cryptographically signing the certificate at the border server, the signing performed using a key unknown to the client system.

20. The computer system of any of claims 15 to 19, further comprising: At a third time, in response to a second challenge request, sending a second challenge from the border server to the client system, the second challenge specifying a string to be echoed by the client system; At a fourth time, receiving a second challenge response from the client system at the border server, the second challenge response including the string; And Generating a fourth certificate at the border server, the fourth certificate encoding a lesser of the elapsed time and a second elapsed time, the second elapsed time including a difference between the fourth time and the third time, the fourth certificate usable by the client system to prove the location of the client system.