Proximity-Based Network Security with Beacon Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a risk of illegitimate devices accessing user data at service provider systems due to the lack of effective proximity verification, allowing unauthorized access to sensitive information such as IP addresses, device identifiers, and usernames.

Innovation Solution

A computer-implemented method and system that verifies the proximity of computing devices by transmitting an encrypted random nonce, broadcasting it, and authenticating requests for user account information based on matching usernames, passwords, and beacon device codes, ensuring only authorized devices receive data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication methods (username/password) are used without proximity verification, then ease of operation is improved, but security is worsened due to risk of illegitimate device access

Engineering Contradiction:
Improveauthentication processVSAvoiddata access security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a beacon device as an intermediary that broadcasts proximity verification data. This mediator enables the system to verify both authentication credentials and physical proximity simultaneously, resolving the contradiction between ease of operation and security by adding a transparent verification layer without requiring complex user actions

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary proximity verification by checking whether the requesting device has received and can verify the current beacon code before allowing data access. This preliminary action ensures that even if credentials are stolen, illegitimate devices cannot access data without being physically present at the service location

Inventive Principle:
Principle #10Preliminary action

2Reliability

If proximity verification with beacon codes is implemented, then security is improved, but device complexity is worsened due to additional verification components

Engineering Contradiction:
Improvedata access securityVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into separate components: a beacon device that broadcasts verification data, a service computing device that processes requests, and a processing system that validates credentials. This segmentation allows each component to have a specific, simplified function while collectively providing robust security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The beacon device operates autonomously, continuously broadcasting proximity verification data without requiring manual intervention. The requesting device automatically receives and verifies the beacon code, eliminating the need for complex manual verification procedures and reducing overall system complexity

Inventive Principle:
Principle #25Self-service

3Reliability

If frequent beacon code updates are implemented, then security is improved, but loss of time is worsened due to verification overhead

Engineering Contradiction:
Improveproximity verification securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The beacon device continuously broadcasts proximity verification data without interruption, allowing the requesting device to maintain an ongoing verification connection. This continuous action eliminates the need for repeated authentication handshakes, reducing verification overhead time while maintaining security through frequent code updates

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10769609B2Network security based on proximity with IP whitelisting
Publication Date: 2020.09.08 GOOGLE LLC
  • US10769609B2 patent drawing
  • US10769609B2 patent drawing
  • US10769609B2 patent drawing

AI summary

A processing system periodically configures a beacon code and random nonce to transmit to a beacon device at a location. Multiple users enter the location with associated user computing devices and retransmit the beacon code broadcasted by the beacon device to the processing system. A computing device at the location transmits to the processing system a request for account data comprising a hardware identifier and retransmits the beacon code and a random nonce. The processing system verifies the request based on the beacon code and random nonce and transmits, to the computing device at the location, user account identifiers associated with user computing devices that retransmitted the beacon code. Within a threshold period of time, the processing system may verify a subsequent request from the computing device, even without receiving the beacon code and random nonce, if the request comprises the hardware identifier.