Geo-location Security Policy via Proxy Obfuscation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need to balance data security and privacy in modern enterprises, particularly in environments where employee devices are used for both work and personal activities, without infringing on employee privacy or violating union regulations that prohibit location tracking outside work hours.

Innovation Solution

Implementing a geo-location-based security policy system that determines security settings based on the device's actual location using a combination of GPS, Wi-Fi, and cellular signals, while ensuring privacy by not sharing precise location data, and using a proxy to obfuscate the device's location for policy decisions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the enterprise tracks the precise location of employee devices using GPS, Wi-Fi, and cellular signals to enforce security policies, then data security is improved, but employee privacy is violated and union regulations are breached

Engineering Contradiction:
Improvedata securityVSAvoidprivacy violation
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces a proxy server as an intermediary between the device and the enterprise server. The proxy receives location requests, obtains the device's actual location, and returns an obfuscated location to the enterprise server. This intermediary mechanism allows the enterprise to enforce location-based security policies while preventing direct access to precise employee location data, thus resolving the contradiction between security and privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the enterprise uses location data to determine security policies for devices, then security policy enforcement is improved, but employee autonomy and personal boundaries are compromised

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidemployee autonomy
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The proxy server acts as a mediator that enables security policy enforcement based on location categories without compromising employee autonomy. The system determines whether a device is in a work-related location category (allowing access) or a personal location category (blocking access), while the obfuscation mechanism preserves employee control over their precise location information.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the enterprise monitors device locations continuously to prevent data breaches, then security monitoring is improved, but regulatory compliance deteriorates due to union contract violations

Engineering Contradiction:
Improvesecurity monitoringVSAvoidregulatory compliance
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The proxy server provides a compliant monitoring solution by obfuscating location data before it reaches the enterprise server. The system can still monitor whether devices are in appropriate location categories for security purposes, but the obfuscation layer ensures compliance with union regulations that prohibit tracking of precise employee locations outside working hours.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different levels of location precision to different purposes. The system determines location categories (work-related vs. personal) using actual location data, but only transmits obfuscated location information to the enterprise server. This local differentiation of data quality allows security monitoring while maintaining regulatory compliance.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12177672B2Use of geolocation to improve security while protecting privacy
Publication Date: 2024.12.24 LOOKOUT INC
  • US12177672B2 patent drawing
  • US12177672B2 patent drawing
  • US12177672B2 patent drawing

AI summary

Security policies are made dependent on location of a device and the location of a device is determined and the appropriate security policy applied without providing the device's location to a server. A device determine its location and identifies a security policy identifier mapped to a zone including the location. The device requests the security policy corresponding to the identifier from a server and implements it. The device may also store a database of the security policies and implement them according to its location. Devices registered for a user evaluate whether locations detected for the devices correspond to impossible travel by the user. Objects encoding geolocation data of a device may be encrypted with a private key of the device and the public key of another to prevent access by an intermediary server.