Cloud Server Access Management Using Geographic Location Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control methods for private clouds, relying on IP addresses and passwords, are vulnerable to hacking, compromising data security.

Innovation Solution

Implementing a cloud server with an access management system that uses geographic location data, in addition to IP addresses and passwords, to authenticate authorized clients by setting a location data range and validating client access based on geographical coordinates and additional authentication information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control is implemented using only IP addresses and passwords, then the access management system is simple to operate, but data security is compromised due to vulnerability to hacking

Engineering Contradiction:
Improvedata securityVSAvoidaccess management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent adds a spatial dimension to access control by incorporating geographic location data (latitude and longitude coordinates) into the authentication process. This transforms the traditional two-factor authentication (IP address and password) into a three-dimensional verification system that includes geographic location, thereby enhancing security without significantly increasing system complexity

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent changes the authentication parameters by adding geographic location coordinates (latitude and longitude) as additional verification factors. The system defines a geographic range with minimum and maximum latitude/longitude values and verifies that client requests originate within this defined spatial parameter range, thereby strengthening security through parameter expansion

Inventive Principle:
Principle #35Parameter changes

2Reliability

If geographic location data is added to authentication, then data security is enhanced, but the authentication process becomes more complex

Engineering Contradiction:
Improvedata securityVSAvoidauthentication process ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically obtains geographic location data from client devices without requiring manual input from users. The location information is collected through the client's operating system or browser capabilities, and the server automatically verifies this data against the predefined geographic range, making the enhanced security transparent to end users

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-defines the geographic access range (minimum and maximum latitude and longitude values) in advance and stores these parameters on the server. This preliminary configuration allows for rapid authentication decisions without requiring complex real-time calculations, thereby maintaining ease of operation while enhancing security

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8505107B2Cloud server and access management method
Publication Date: 2013.08.06 CLOUD NETWORK TECH SINGAPORE PTE LTD
  • US8505107B2 patent drawing
  • US8505107B2 patent drawing
  • US8505107B2 patent drawing

AI summary

A cloud server stores information, such as a location data range, IP addresses, account names, and passwords of authorized clients. When receiving an access request from a client, the cloud server determines if location data of the client falls within the location data range and an IP address, an account name, and a password of the client matches corresponding information of any authorized client. If the location data of the client falls within the location data range and an IP address, an account name, and a password of the client match information of any authorized client, the cloud server determines that the client is an authorized client and permits the client to access the cloud server.