Device Location Service Access Control via Biometric Trust Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in preventing unauthorized access to device location services, particularly when an adversary gains control of a device and can access associated accounts, allowing them to track other devices or remove them from the account, thereby disabling location services and remote security features.

Innovation Solution

The implementation of trusted and untrusted device classifications based on multi-factor authentication capabilities, particularly biometric authentication, to differentiate between authorized and unauthorized access attempts. Trusted devices undergo biometric authentication to confirm authorized users, while untrusted devices are restricted from accessing device location services, with measures such as maintaining devices on accounts for cooldown periods or preventing access to location information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If device location services are made accessible to all devices with account credentials, then ease of operation is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveaccess to device location servicesVSAvoidsecurity against unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments devices into trusted and untrusted categories based on biometric authentication capability. Trusted devices have biometric authentication enabled and are granted full access to location services, while untrusted devices without biometric authentication are restricted. This segmentation resolves the contradiction by allowing easy access for authorized users while blocking unauthorized access attempts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary biometric authentication verification before granting access to location services. Devices must undergo biometric authentication in advance to establish trusted status. This preliminary action ensures that only authorized users can access location services, preventing unauthorized access while maintaining ease of operation for legitimate users.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If biometric authentication is required for all device access, then security is improved, but ease of operation deteriorates due to additional authentication steps

Engineering Contradiction:
Improvesecurity of device location servicesVSAvoiddevice access process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies biometric authentication requirements selectively rather than universally. Only untrusted devices (those without biometric authentication capability) are subjected to additional verification steps. Trusted devices with biometric authentication already enabled enjoy seamless access. This local quality approach improves security for vulnerable devices while maintaining ease of operation for most users.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts authentication requirements based on device trust status. Devices transition between trusted and untrusted states depending on whether biometric authentication is detected. This dynamic approach ensures that biometric authentication is only required when necessary, balancing security needs with operational convenience.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250190554A1Preventing unauthorized access to device location
Publication Date: 2025.06.12 APPLE INC
  • US20250190554A1 patent drawing
  • US20250190554A1 patent drawing
  • US20250190554A1 patent drawing

AI summary

Techniques for preventing unauthorized device location information are described herein. A service running on a server devices can receive, from a set of user devices associated with a profile, respective user device tracking information for each device. The set of user devices can include trusted devices and untrusted devices. The service can receive a first signal that a critical operation associated with the profile is being requested. The service can receive, from a first user device of the set of one or more user devices, a request for respective user device tracking information for other devices. The service can determine whether the first user device is untrusted. In accordance with a determination that the first user device is untrusted, the service can determine to not transmit respective user device tracking information for other devices to the first user device.