Geolocation-Signed Authentication for AI-Resistant CAPTCHA

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Advances in Artificial Intelligence have degraded the effectiveness of traditional CAPTCHA mechanisms in safeguarding higher value resources, as they can be easily solved by automated tools, necessitating a more robust security measure that incorporates device geolocation to enhance authentication events.

Innovation Solution

Incorporating geolocation data into authentication events by signing it with an obfuscated key stored on the communications device, which is then transmitted to a communications server, ensuring that the authentication challenges require information available only at the user's location, thereby increasing challenge diversity and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional CAPTCHA mechanisms are used, then implementation is simple and cost-effective, but effectiveness is degraded by AI-powered automated solvers

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces geolocation data as a new dimension to authentication challenges. Instead of relying solely on traditional CAPTCHA types (text, image, sound), the system incorporates location-based questions that require knowledge of the user's geographical surroundings, adding a spatial dimension that automated solvers cannot easily access or fabricate.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system dynamically changes the parameters of authentication challenges based on the user's geolocation. By signing location data with obfuscated keys and generating location-specific challenges, the system transforms static CAPTCHA mechanisms into dynamic, context-aware authentication that adapts to the user's physical environment, making AI solvers ineffective.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If geolocation data is incorporated into authentication events, then challenge diversity and security are improved, but device complexity and key management overhead increase

Engineering Contradiction:
Improveauthentication securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-obfuscating cryptographic keys and storing them securely in the device before authentication events occur. This preliminary key preparation and obfuscation process is done in advance, so that during actual authentication, the device can efficiently sign location data without complex real-time key management, reducing operational complexity while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If location-based authentication challenges are implemented, then automated solver development cost increases, but user convenience may be reduced

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system leverages the device's own geolocation capabilities and the user's inherent knowledge of their location to answer authentication challenges. Instead of requiring users to solve complex puzzles or access external resources, the authentication challenges are based on information the user naturally possesses (their location), making the process intuitive and convenient while maintaining high security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12169547B2Communications device, method and communications system for managing an authentication event
Publication Date: 2024.12.17 GRABTAXI HOLDINGS PTE LTD
  • US12169547B2 patent drawing
  • US12169547B2 patent drawing
  • US12169547B2 patent drawing

AI summary

A communications device for managing an authentication event is provided, which is configured to generate location data indicative of a geolocation associated with the communications device, retrieve, from a key that is obfuscated and stored in the communications device, the key, sign the location data with the retrieved key, and transmit request data to a communications server apparatus for requesting the authentication event, the request data comprising the signed location data. A method and a communications system for managing an authentication event are also provided.