Mobile Edge Authentication via Location Fingerprinting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In mobile edge-computing systems, there is a need to efficiently manage security credentials and nomadic computing resources across multiple information handling systems while ensuring lightweight client devices and secure access, particularly as users access their data from various locations worldwide.

Innovation Solution

The solution involves estimating a client's future location to pre-provision security credentials at a trusted mobile edge-authentication system, using historical trust reference block chains to determine trusted devices, and optimizing resource allocation for secure access to nomadic computing resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security credentials are stored locally on client devices, then authentication security is improved, but device complexity and storage requirements increase

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts security credentials from client devices and stores them on remote authentication servers. The system retrieves credentials only when needed for authentication, keeping client devices lightweight while maintaining security. This is achieved through the authentication server holding the credential store and providing credentials on-demand to authorized clients.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authentication server as an intermediary between clients and resources. The server mediates authentication by storing credentials securely and verifying client identities without requiring clients to maintain local credential stores. This intermediary approach centralizes security management while simplifying client device requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication is performed in real-time with remote servers, then security is improved, but authentication time and network dependency increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary authentication actions by establishing trusted relationships and caching authentication states before actual resource access. The system pre-loads authentication contexts and maintains session states that enable faster subsequent authentication decisions without requiring full real-time verification for every access attempt.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If security credentials are centralized on remote servers, then device overhead is reduced, but network dependency and access latency increase

Engineering Contradiction:
Improvedevice overheadVSAvoidaccess speed
Core Design Contradiction:
Device complexityVSSpeed

Solution Approach 1:

The patent implements local quality by caching authentication contexts and credential data locally at edge locations and client devices. This allows frequently accessed authentication information to be retrieved locally without network delays, while the central server maintains the master credential store. The system optimizes access speed by serving common authentication requests from local caches rather than always querying remote servers.

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If multiple authentication servers are distributed globally, then access availability is improved, but system complexity and credential synchronization increase

Engineering Contradiction:
Improveaccess availabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into multiple geographically distributed authentication servers that can independently serve local clients. Each server maintains local credential caches and can authenticate clients without requiring constant communication with other servers. This segmentation improves access availability by allowing clients to connect to nearby servers while reducing synchronization complexity through localized credential management.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11347833B2Method and apparatus for optimized access of security credentials via mobile edge-computing systems
Publication Date: 2022.05.31 DELL PROD LP
  • US11347833B2 patent drawing
  • US11347833B2 patent drawing
  • US11347833B2 patent drawing

AI summary

A method for secure access to a mobile edge-computing system device based on a subscriber location fingerprint may comprise receiving a request to access the mobile edge-computing system, a first personal authorization credential record, and an encrypted token from a requesting client, associating the first personal authorization credential record with a block chain location fingerprint for the subscribing client, including a plurality of time-stamped records of a plurality of estimated or measured location state variables of the subscribing client and an associated confidence interval representing an accuracy of those variables, decrypting the location fingerprint, receiving a requesting client location measurement, predicting a current location for the subscribing client and an associated current confidence interval based on recent location state variables in the location fingerprint, and allowing the requesting client access to the mobile edge-computing system when the received requesting client location measurement falls within the value of the current confidence interval.