Account Security via Device Location Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for identifying unauthorized access to online accounts are inadequate, as they often generate false alerts and fail to detect real intrusions, particularly when behavior changes or access comes from individuals close to the legitimate user, such as family or friends, due to reliance on IP addresses and limited login activity data.

Innovation Solution

A computer-implemented method that retrieves and compares login information with usage information from a legitimate user's device, incorporating geographic location and usage patterns to differentiate between authorized and unauthorized access, using GPS, Wi-Fi, or cell triangulation for precise location verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If only recent login activity data is analyzed, then the system is simple to operate, but the accuracy of identifying unauthorized access is insufficient and generates false alerts

Engineering Contradiction:
Improveaccuracy of identifying unauthorized accessVSAvoidcomplexity of security system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent combines multiple data sources including recent login activity, usage information from the legitimate user's device, and geographic location data into a unified security assessment system. This merging of diverse information sources enables more accurate identification of unauthorized access while maintaining system manageability through integrated processing.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system introduces an intermediary comparison mechanism that evaluates login information against usage information from the legitimate user's device. This intermediary layer acts as a mediator to distinguish between legitimate and unauthorized access attempts, reducing false alerts while maintaining operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If behavior changes are detected based on login activity, then unauthorized access can be identified, but false alerts are generated when users voluntarily change behavior such as traveling or logging in from different devices

Engineering Contradiction:
Improvereliability of intrusion detectionVSAvoidfalse alerts
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The system implements feedback mechanisms where usage information from the legitimate user's device continuously updates the baseline for normal behavior. This feedback loop enables the system to adapt to voluntary behavior changes such as traveling or using different devices, thereby reducing false alerts while maintaining reliable intrusion detection.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The security system dynamically adjusts its detection criteria based on real-time usage information from the legitimate user's device. This dynamic adaptation allows the system to accommodate legitimate behavior changes while maintaining sensitivity to actual intrusions, resolving the contradiction between detection reliability and false alert reduction.

Inventive Principle:
Principle #15Dynamics

3Reliability

If access from persons close to the legitimate user is monitored, then security is improved, but it becomes impossible to distinguish these accesses from legitimate user accesses

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoiddifficulty of distinguishing authorized users
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system applies local quality by associating usage information specifically with the legitimate user's device rather than treating all users uniformly. This device-specific association creates a unique security profile for the legitimate user, enabling the system to distinguish between the legitimate user and persons close to them who may have physical access to devices or knowledge of passwords.

Inventive Principle:
Principle #3Local quality

4Measurement precision

If detailed usage information is collected from the user's device, then the accuracy of authentication is improved, but the user loses control over personal information being shared with online services

Engineering Contradiction:
Improveprecision of geographic authenticationVSAvoidloss of user control over personal information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system enables self-service by allowing users to control what usage information is shared with online services. Users can selectively provide geographic location and other usage data to enhance authentication accuracy while maintaining control over their personal information. This self-service approach resolves the contradiction by empowering users to balance security enhancement with information privacy.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10530782B2Method for identifying unauthorized access of an account of an online service
Publication Date: 2020.01.07 PALMASO APS
  • US10530782B2 patent drawing
  • US10530782B2 patent drawing

AI summary

The present disclosure relates to a method for identifying unauthorized access of an account of an online service, such as an email or a social network service, wherein the account is associated with a legitimate user, the method comprising the steps of: retrieving login information from recent login activity of the account corresponding to a geographic location associated with the ongoing or most recent login attempt; retrieving usage information comprising a geographic location of a legitimate user from a device of the legitimate user; comparing the login information and the usage information by comparing the geographic location associated with the ongoing or most recent login attempt and the geographic location of a legitimate user; and identifying potentially unauthorized login(s) by an unauthorized user.