Geo-fenced Cryptographic Key Material for Location-Based Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems lack effective integration of geographic location with cryptographic key material, leading to vulnerabilities in secure communications, especially when devices move across defined geographic regions, as they do not adequately manage trust relationships based on real-time location changes.

Innovation Solution

The system associates cryptographic key material with a geo-fence attribute set that specifies a geographic region, allowing or suspending authentication based on the client's location, using geo-location updates and delegation mechanisms to ensure secure communication within defined boundaries, and employs encryption and secure protocols to protect location data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic key material is used without geographic restrictions, then authentication is simple and fast, but security is compromised when devices move outside authorized areas

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic authentication by associating cryptographic key material with geographic location data. The authentication system dynamically evaluates the client's current location against stored geographic boundaries (geo-fences) to determine whether to grant access. This allows the system to adapt authentication behavior based on real-time location changes, enhancing security without requiring a completely separate location verification system.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent embeds geographic location information directly within the cryptographic key material structure. The geo-fence attributes are nested inside the authentication credentials, allowing the location verification logic to be integrated within the existing authentication framework rather than requiring a separate external system, thus managing complexity while adding security.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If geographic restrictions are enforced on cryptographic key material, then security is enhanced, but authentication management becomes more complex

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system performs self-service by automatically evaluating location data against embedded geo-fence attributes without requiring manual intervention. The system autonomously determines authentication eligibility based on the client's geographic position, reducing the operational burden on administrators while maintaining enhanced security through location-based controls.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If real-time location monitoring is implemented, then authentication accuracy is improved, but system resources and processing time increase

Engineering Contradiction:
Improvelocation-based authentication accuracyVSAvoiddevice processing resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary action by pre-embedding geographic boundary definitions (geo-fences) within the cryptographic key material during authentication credential issuance. This allows the client device to perform local self-evaluation of its position against these pre-defined boundaries without requiring continuous real-time communication with authentication servers, thereby improving location-based authentication accuracy while minimizing ongoing processing resources and energy consumption.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9680827B2Geo-fencing cryptographic key material
Publication Date: 2017.06.13 CYBERARK SOFTWARE INC
  • US9680827B2 patent drawing
  • US9680827B2 patent drawing
  • US9680827B2 patent drawing

AI summary

In representative embodiments, a geo-fence cryptographic key material comprising a geo-fence description defining a geographic area and associated cryptographic key material is assigned to an entity for use in authenticated communications. The validity of the cryptographic material changes state based on whether the entity is inside or outside the geographic area. This is accomplished in a representative embodiment by suspending the validity of the cryptographic key material when the entity is outside the geographic area and reinstating the validity of the cryptographic key material when the entity is inside the geographic area. A geographic update service determines the validity of the cryptographic material in part using location updates sent by the entity. Entities that are not geo-aware can delegate the location update to a geo-aware device. Encryption can be used to preserve privacy.