Dynamic Broker Device Shuffling for Location Attestation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing location-based services face challenges in ensuring the credibility of device authentication, as conventional attestation procedures can be time-consuming and vulnerable to malicious attacks, allowing unauthorized access through collusion or targeted attacks on broker devices.
Innovation Solution
A method that adapts the set of broker devices by determining credibility scores and shuffling them between subsets to reduce the likelihood of malicious actors identifying and controlling the devices used for attestation, thereby enhancing the security and efficiency of the authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If global attestation uses contextual information and location reports from nearby devices to attest requesting device's location, then location verification accuracy is improved, but the system becomes vulnerable to collusion attacks where devices work together to misrepresent location
Solution Approach 1:
The patent dynamically adjusts the set of broker devices used for attestation by shuffling devices between subsets based on credibility scores. This dynamic reassignment prevents malicious devices from consistently participating in attestation, thereby resolving the contradiction between using multiple devices for accuracy and preventing collusion attacks.
Solution Approach 2:
The system changes the parameter of broker device selection by introducing credibility scores and reassigning devices between subsets. This parameter change allows the system to maintain high location verification accuracy while preventing collusion by excluding low-credibility devices from the attestation process.
2Productivity
If the system uses a fixed set of broker devices for attestation, then the attestation process is efficient and quick, but malicious actors can identify and control these devices to compromise security
Solution Approach 1:
The patent implements dynamic shuffling of broker devices between subsets based on credibility scores. This ensures that the attestation process remains efficient by using a predefined set of devices while simultaneously preventing targeted attacks by continuously changing which devices are assigned to which subsets, making it difficult for malicious actors to predict or control the attestation devices.
3Ease of operation
If the system assigns devices to fixed subsets for attestation, then the attestation process is simplified and faster, but it increases the risk of malicious actors targeting specific device subsets
Solution Approach 1:
The system maintains simplicity by using predefined subsets of broker devices for attestation, ensuring ease of operation. Simultaneously, it mitigates vulnerability to targeted attacks by dynamically shuffling devices between subsets based on credibility scores, preventing malicious actors from consistently targeting the same devices.
4Reliability
If the system continuously monitors and reassigns broker devices based on credibility scores, then security against malicious actors is improved, but the complexity of the attestation system increases
Solution Approach 1:
The system performs preliminary actions by pre-defining subsets of broker devices and establishing credibility score criteria before the attestation process begins. This preliminary setup simplifies the actual attestation operation while maintaining high security, as the dynamic reassignment follows predetermined rules rather than requiring complex real-time decision-making.
Data Source
AI summary
Embodiments disclose systems, methods, and computer program products to perform an operation for adapting a set of devices used to authenticate a client device. The operation generally includes determining a plurality of broker devices available for attesting a location of a client device, and determining, from the available broker devices, a first and second subset of broker devices based on a credibility score determined for each of the available broker devices. The operation also includes attesting the location of the client device based on information received from the first subset of broker devices regarding devices in proximity to each of the broker devices in the first subset. The operation further includes upon determining that a number of responses with the information from at least one of the broker devices in the first subset has reached a threshold, reassigning broker devices in the first and second subsets.


