Connectivity-Based Authentication Against Location Spoofing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multifactor authentication (MFA) systems are vulnerable to spoofing attacks, particularly those relying on static location information, which can be easily manipulated, necessitating enhanced security measures.
Innovation Solution
Implement device connectivity-based authentication that utilizes current and reference connectivity datasets to verify a device's location by comparing communication characteristics with stored datasets, ensuring authenticity and optimizing communication paths without additional probing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If static location information is used for authentication, then authentication process is simple, but security is weakened due to ease of spoofing
Solution Approach 1:
The patent changes the authentication parameter from static location coordinates to dynamic connectivity characteristics. Instead of verifying fixed geographic coordinates that can be spoofed, the system verifies real-time communication parameters such as signal strength, latency, packet loss, and device proximity relationships. This parameter transformation makes spoofing significantly more difficult while maintaining authentication simplicity for legitimate users.
Solution Approach 2:
The patent introduces connectivity characteristics as an intermediary verification layer between the device and authentication system. Rather than directly trusting location data, the system uses communication network properties (signal strength, latency, packet loss) as mediators to indirectly verify device location and authenticity. This intermediary approach adds security without requiring complex changes to the authentication workflow.
2Reliability
If device connectivity-based authentication is implemented, then security against spoofing is improved, but system complexity increases
Solution Approach 1:
The patent implements self-service by having the client device automatically collect and report its own connectivity characteristics without requiring manual configuration or complex client-side authentication logic. The device autonomously measures signal strength, latency, and packet loss, then submits these metrics to the authentication server. This reduces the burden on both the client device and server infrastructure while maintaining high security.
Solution Approach 2:
The patent makes the connectivity verification system universal by leveraging existing communication infrastructure and protocols that are already present in all networked devices. The same connectivity measurements used for authentication can also serve for network optimization, device discovery, and location services, reducing overall system complexity through multi-functionality.
3Use of energy by moving object
If traditional location verification methods are used, then resource consumption is low, but spoofing vulnerability increases
Solution Approach 1:
The patent applies partial action by selectively measuring only the most critical connectivity parameters needed for authentication (signal strength, latency, packet loss) rather than comprehensive network diagnostics. This selective measurement approach provides sufficient security verification while minimizing energy consumption and processing overhead on battery-powered devices.
Data Source
AI summary
Systems, apparatuses, methods, and computer program products are disclosed for device connectivity-based authentication. An example method includes receiving, from a first device, an authorization request associated with a first action. The example method also includes receiving a current connectivity dataset from the first device which indicates one or more devices detected by the first device to be in communication with the first device. The example method also includes comparing the current connectivity dataset with a reference connectivity dataset. The example method also includes determining, based on the comparison, whether the current connectivity dataset and the reference connectivity dataset satisfy a predefined similarity threshold. The example method also includes authorizing, in an instance in which the current connectivity dataset and the reference connectivity dataset satisfy the predefined similarity threshold, the first device to perform the first action.


