Geo-Location Reauthorization for Mobile Confidential Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Travelers face challenges in protecting confidential information on their electronic devices from unauthorized access, particularly at border crossings where devices may be inspected by customs agents, as geo-fencing and time-based locks are insufficient to prevent access when devices are held or transferred to other locations.

Innovation Solution

A system that prevents access to confidential information on a mobile computing device by generating a trigger to encrypt the data and remove the decryption key, allowing reauthorization only when the device is physically located at an authorized geo-location associated with the user, ensuring that access is restricted even to parties with user identifiers and passwords.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If geo-fencing is used to block access to confidential data in certain locations, then access protection is improved, but the system becomes vulnerable when devices are transported to locations outside the geo-fence area

Engineering Contradiction:
Improveaccess protectionVSAvoidprotection coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic protection by continuously monitoring device location and automatically adjusting access controls based on real-time geo-location data. The system transitions from static geo-fencing to dynamic location-based reauthorization that adapts to device movement, ensuring protection remains active regardless of where the device is physically located.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where location data is continuously fed back to the access control system. This feedback loop enables the system to detect when a device is in an unauthorized location and automatically trigger reauthorization requirements, creating a responsive protection system that reacts to location changes in real-time.

Inventive Principle:
Principle #23Feedback

2Duration of action of stationary object

If time-based locks are implemented to prevent access for a given period, then protection duration is improved, but the system fails when devices are held indefinitely by authorities

Engineering Contradiction:
Improveprotection durationVSAvoidaccess control
Core Design Contradiction:
Duration of action of stationary objectVSReliability

Solution Approach 1:

The system uses location-based feedback to continuously monitor whether the device is in an authorized location. This replaces time-based protection with location-based reauthorization, where access is continuously evaluated based on real-time location data rather than relying on predetermined time periods.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary location verification before allowing access to confidential data. By checking location authorization in advance and continuously, the system prevents access attempts from unauthorized locations before they can succeed, rather than relying on time-based locks that may expire while the device is still in an unauthorized location.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If users provide passwords and access control mechanisms to border agents, then cooperation with authorities is improved, but confidential information becomes vulnerable to unauthorized access

Engineering Contradiction:
Improvecooperation with authoritiesVSAvoidinformation security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments access control into two distinct layers: location-based reauthorization and data encryption. Location verification handles the authorization question (whether the user should access the data), while encryption handles the security question (how to protect the data). This segmentation allows users to provide location information for reauthorization without exposing their passwords or encryption keys to authorities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces location-based reauthorization as an intermediary mechanism between the user and the confidential data. Instead of directly providing passwords or access mechanisms to authorities, the user first undergoes location verification, which acts as an intermediary check. Only after successful location verification does the system allow access attempts, and even then, the data remains encrypted until proper authentication occurs.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If devices are held by border agents and transported to other agencies, then inspection capability is improved, but the device moves outside protected geo-fence areas

Engineering Contradiction:
Improveinspection capabilityVSAvoiddata protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements dynamic location-based protection that automatically adjusts as the device moves. When a device is held and transported by authorities, the continuous location monitoring detects the change in position and triggers appropriate reauthorization requirements. This dynamic response ensures protection adapts to the device's physical location regardless of whether it is at a border crossing, in transit, or at a destination facility.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8856916B1User associated geo-location based reauthorization to protect confidential information
Publication Date: 2014.10.07 CA TECH INC
  • US8856916B1 patent drawing
  • US8856916B1 patent drawing
  • US8856916B1 patent drawing

AI summary

In response to a trigger indicating to prevent access to confidential information on a specific user's mobile device, access is prevented to all parties, until a successful reauthorization occurs. Preventing access can comprise storing encrypted confidential information and removing the decryption key. In order to subsequently access the confidential information, a reauthorization attempt is made. The current geo-location of the mobile device at the time of the attempt is compared to at least one authorized geo-location associated with the specific user. In response to a) the password and user identifier being correct and to b) the current geo-location of the mobile computing device being an authorized geo-location associated with the specific user, the attempt to reauthorize is successful, whereas otherwise the attempt is unsuccessful. Only in response to a successful attempt is access to the confidential information re-allowed.