Mobile Edge Authentication via Location Fingerprinting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In mobile edge-computing systems, there is a need to efficiently manage security credentials and nomadic computing resources across multiple information handling systems while ensuring lightweight client devices and secure access, particularly as users access their data from various locations worldwide.
Innovation Solution
The solution involves estimating a client's future location to pre-provision security credentials at a trusted mobile edge-authentication system, using historical trust reference block chains to determine trusted devices, and optimizing resource allocation for secure access to nomadic computing resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security credentials are stored locally on client devices, then authentication security is improved, but device complexity and storage requirements increase
Solution Approach 1:
The patent extracts security credentials from client devices and stores them on remote authentication servers. The system retrieves credentials only when needed for authentication, keeping client devices lightweight while maintaining security. This is achieved through the authentication server holding the credential store and providing credentials on-demand to authorized clients.
Solution Approach 2:
The patent introduces an authentication server as an intermediary between clients and resources. The server mediates authentication by storing credentials securely and verifying client identities without requiring clients to maintain local credential stores. This intermediary approach centralizes security management while simplifying client device requirements.
2Reliability
If authentication is performed in real-time with remote servers, then security is improved, but authentication time and network dependency increase
Solution Approach 1:
The patent performs preliminary authentication actions by establishing trusted relationships and caching authentication states before actual resource access. The system pre-loads authentication contexts and maintains session states that enable faster subsequent authentication decisions without requiring full real-time verification for every access attempt.
3Device complexity
If security credentials are centralized on remote servers, then device overhead is reduced, but network dependency and access latency increase
Solution Approach 1:
The patent implements local quality by caching authentication contexts and credential data locally at edge locations and client devices. This allows frequently accessed authentication information to be retrieved locally without network delays, while the central server maintains the master credential store. The system optimizes access speed by serving common authentication requests from local caches rather than always querying remote servers.
4Adaptability or versatility
If multiple authentication servers are distributed globally, then access availability is improved, but system complexity and credential synchronization increase
Solution Approach 1:
The patent segments the authentication system into multiple geographically distributed authentication servers that can independently serve local clients. Each server maintains local credential caches and can authenticate clients without requiring constant communication with other servers. This segmentation improves access availability by allowing clients to connect to nearby servers while reducing synchronization complexity through localized credential management.
Data Source
AI summary
A method for secure access to a mobile edge-computing system device based on a subscriber location fingerprint may comprise receiving a request to access the mobile edge-computing system, a first personal authorization credential record, and an encrypted token from a requesting client, associating the first personal authorization credential record with a block chain location fingerprint for the subscribing client, including a plurality of time-stamped records of a plurality of estimated or measured location state variables of the subscribing client and an associated confidence interval representing an accuracy of those variables, decrypting the location fingerprint, receiving a requesting client location measurement, predicting a current location for the subscribing client and an associated current confidence interval based on recent location state variables in the location fingerprint, and allowing the requesting client access to the mobile edge-computing system when the received requesting client location measurement falls within the value of the current confidence interval.


