Dynamic Broker Device Shuffling for Location Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing location-based services face challenges in ensuring the credibility of device authentication, as conventional attestation procedures can be time-consuming and vulnerable to malicious attacks, allowing unauthorized access through collusion or targeted attacks on broker devices.

Innovation Solution

A method that adapts the set of broker devices by determining credibility scores and shuffling them between subsets to reduce the likelihood of malicious actors identifying and controlling the devices used for attestation, thereby enhancing the security and efficiency of the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If global attestation uses contextual information and location reports from nearby devices to attest requesting device's location, then location verification accuracy is improved, but the system becomes vulnerable to collusion attacks where devices work together to misrepresent location

Engineering Contradiction:
Improvelocation verification accuracyVSAvoidresistance to collusion attacks
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent dynamically adjusts the set of broker devices used for attestation by shuffling devices between subsets based on credibility scores. This dynamic reassignment prevents malicious devices from consistently participating in attestation, thereby resolving the contradiction between using multiple devices for accuracy and preventing collusion attacks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of broker device selection by introducing credibility scores and reassigning devices between subsets. This parameter change allows the system to maintain high location verification accuracy while preventing collusion by excluding low-credibility devices from the attestation process.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If the system uses a fixed set of broker devices for attestation, then the attestation process is efficient and quick, but malicious actors can identify and control these devices to compromise security

Engineering Contradiction:
Improveattestation efficiencyVSAvoidsecurity against targeted attacks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements dynamic shuffling of broker devices between subsets based on credibility scores. This ensures that the attestation process remains efficient by using a predefined set of devices while simultaneously preventing targeted attacks by continuously changing which devices are assigned to which subsets, making it difficult for malicious actors to predict or control the attestation devices.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If the system assigns devices to fixed subsets for attestation, then the attestation process is simplified and faster, but it increases the risk of malicious actors targeting specific device subsets

Engineering Contradiction:
Improveattestation process simplicityVSAvoidvulnerability to targeted attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system maintains simplicity by using predefined subsets of broker devices for attestation, ensuring ease of operation. Simultaneously, it mitigates vulnerability to targeted attacks by dynamically shuffling devices between subsets based on credibility scores, preventing malicious actors from consistently targeting the same devices.

Inventive Principle:
Principle #15Dynamics

4Reliability

If the system continuously monitors and reassigns broker devices based on credibility scores, then security against malicious actors is improved, but the complexity of the attestation system increases

Engineering Contradiction:
Improvesecurity credibilityVSAvoidattestation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-defining subsets of broker devices and establishing credibility score criteria before the attestation process begins. This preliminary setup simplifies the actual attestation operation while maintaining high security, as the dynamic reassignment follows predetermined rules rather than requiring complex real-time decision-making.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10326773B2Ensuring the credibility of devices for global attestation
Publication Date: 2019.06.18 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10326773B2 patent drawing
  • US10326773B2 patent drawing
  • US10326773B2 patent drawing

AI summary

Embodiments disclose systems, methods, and computer program products to perform an operation for adapting a set of devices used to authenticate a client device. The operation generally includes determining a plurality of broker devices available for attesting a location of a client device, and determining, from the available broker devices, a first and second subset of broker devices based on a credibility score determined for each of the available broker devices. The operation also includes attesting the location of the client device based on information received from the first subset of broker devices regarding devices in proximity to each of the broker devices in the first subset. The operation further includes upon determining that a number of responses with the information from at least one of the broker devices in the first subset has reached a threshold, reassigning broker devices in the first and second subsets.