Geo-location Security Policy via Proxy Obfuscation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need to balance data security and privacy in modern enterprises, particularly in environments where employee devices are used for both work and personal activities, without infringing on employee privacy or violating union regulations that prohibit location tracking outside work hours.
Innovation Solution
Implementing a geo-location-based security policy system that determines security settings based on the device's actual location using a combination of GPS, Wi-Fi, and cellular signals, while ensuring privacy by not sharing precise location data, and using a proxy to obfuscate the device's location for policy decisions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the enterprise tracks the precise location of employee devices using GPS, Wi-Fi, and cellular signals to enforce security policies, then data security is improved, but employee privacy is violated and union regulations are breached
Solution Approach 1:
The patent introduces a proxy server as an intermediary between the device and the enterprise server. The proxy receives location requests, obtains the device's actual location, and returns an obfuscated location to the enterprise server. This intermediary mechanism allows the enterprise to enforce location-based security policies while preventing direct access to precise employee location data, thus resolving the contradiction between security and privacy.
2Reliability
If the enterprise uses location data to determine security policies for devices, then security policy enforcement is improved, but employee autonomy and personal boundaries are compromised
Solution Approach 1:
The proxy server acts as a mediator that enables security policy enforcement based on location categories without compromising employee autonomy. The system determines whether a device is in a work-related location category (allowing access) or a personal location category (blocking access), while the obfuscation mechanism preserves employee control over their precise location information.
3Reliability
If the enterprise monitors device locations continuously to prevent data breaches, then security monitoring is improved, but regulatory compliance deteriorates due to union contract violations
Solution Approach 1:
The proxy server provides a compliant monitoring solution by obfuscating location data before it reaches the enterprise server. The system can still monitor whether devices are in appropriate location categories for security purposes, but the obfuscation layer ensures compliance with union regulations that prohibit tracking of precise employee locations outside working hours.
Solution Approach 2:
The patent applies different levels of location precision to different purposes. The system determines location categories (work-related vs. personal) using actual location data, but only transmits obfuscated location information to the enterprise server. This local differentiation of data quality allows security monitoring while maintaining regulatory compliance.
Data Source
AI summary
Security policies are made dependent on location of a device and the location of a device is determined and the appropriate security policy applied without providing the device's location to a server. A device determine its location and identifies a security policy identifier mapped to a zone including the location. The device requests the security policy corresponding to the identifier from a server and implements it. The device may also store a database of the security policies and implement them according to its location. Devices registered for a user evaluate whether locations detected for the devices correspond to impossible travel by the user. Objects encoding geolocation data of a device may be encrypted with a private key of the device and the public key of another to prevent access by an intermediary server.


