Geo-fencing Cryptographic Key Material for Location-Based Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems lack effective integration of geographic location with cryptographic key material management, leading to potential security vulnerabilities and inefficiencies in managing trust relationships between computer systems.

Innovation Solution

The system associates geo-location positioning with cryptographic key material by using a geo-fence attribute set that specifies a geographic region, allowing or suspending authentication based on the client's location, with mechanisms for delegation and obfuscation to ensure secure geo-location updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cryptographic key material is made universally accessible for authentication, then ease of operation is improved, but security is worsened due to lack of geographic restrictions

Engineering Contradiction:
Improveauthentication accessibilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by associating cryptographic key material with specific geographic regions through geo-fence attribute sets. The authentication system checks the client's current location against the geo-fenced region defined in the key material attributes, allowing authentication only when the client is within the authorized geographic area. This creates location-specific access control where the same key material has different validity depending on geographic context.

Inventive Principle:
Principle #3Local quality

2Reliability

If geo-location tracking is implemented continuously for security, then security is improved, but loss of time and energy increases

Engineering Contradiction:
Improveauthentication securityVSAvoidgeo-location update overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic action by requiring geo-location updates at specific intervals or triggered by geo-fence boundary crossings rather than continuous tracking. The system validates the client's location periodically during authentication attempts or when the client enters/exits the geo-fenced region, reducing the frequency of location checks while maintaining security.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent applies preliminary action by obtaining and validating the client's geo-location information before authentication is attempted. The system checks whether the client is within the authorized geo-fenced region prior to allowing authentication proceedings, preventing wasted authentication attempts from unauthorized locations.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If geo-location information is stored and processed openly, then ease of operation is improved, but privacy is worsened

Engineering Contradiction:
Improvegeo-location processingVSAvoidprivacy
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent extracts and processes only the essential geographic boundary information from geo-location data, storing and validating against geo-fence attribute sets rather than retaining detailed client location histories. The system determines whether the client is within the authorized region without necessarily storing or processing the complete geo-location trajectory, minimizing privacy exposure while maintaining authentication security.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9647998B2Geo-fencing cryptographic key material
Publication Date: 2017.05.09 CYBERARK SOFTWARE INC
  • US9647998B2 patent drawing
  • US9647998B2 patent drawing
  • US9647998B2 patent drawing

AI summary

In representative embodiments, a geo-fence cryptographic key material comprising a geo-fence description defining a geographic area and associated cryptographic key material is assigned to an entity for use in authenticated communications. The validity of the cryptographic material changes state based on whether the entity is inside or outside the geographic area. This is accomplished in a representative embodiment by suspending the validity of the cryptographic key material when the entity is outside the geographic area and reinstating the validity of the cryptographic key material when the entity is inside the geographic area. A geographic update service determines the validity of the cryptographic material in part using location updates sent by the entity. Entities that are not geo-aware can delegate the location update to a geo-aware device. Encryption can be used to preserve privacy.