Geolocation Two-Factor Authentication Proximity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users are reluctant to enable two-factor authentication due to inconvenience, often disabling it, making their accounts more vulnerable to attacks, as they do not want to carry additional security devices or enter security codes each time they log in.

Innovation Solution

Implementing geolocation-based two-factor authentication, where a mobile device associated with the user's account provides the second authentication factor by verifying the device's location relative to the client device, allowing access if within a specified proximity, thus eliminating the need for manual entry of security codes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional two-factor authentication is implemented requiring users to carry additional security devices or enter security codes, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically performs authentication by detecting the mobile device's presence through geolocation services. The mobile device itself provides authentication credentials (its location data) without requiring user intervention to enter codes or carry additional physical security tokens. The authentication process serves itself by leveraging the device's inherent capabilities and automatic location tracking.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical approach of physical security tokens and manual code entry with an electronic/geolocation-based system. Instead of requiring users to physically handle security devices or type codes, the system uses automated geolocation detection and electronic verification to substitute the mechanical authentication process.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If users disable two-factor authentication to avoid inconvenience, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system operates automatically in the background without requiring user awareness or action. The mobile device continuously provides location data, and the system automatically verifies authentication credentials. This self-service mechanism eliminates the need for users to consciously enable or manage security settings, making security transparent and convenient.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If geolocation-based authentication is implemented, then ease of operation is improved, but measurement precision requirements increase

Engineering Contradiction:
Improveease of operationVSAvoidlocation accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system uses geolocation data with a threshold proximity distance rather than requiring exact location matching. Instead of demanding precise coordinate verification, the system checks whether the mobile device falls within an acceptable geographic radius of the authentication location, allowing for reasonable location inaccuracies while maintaining security.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10206099B1Geolocation-based two-factor authentication
Publication Date: 2019.02.12 GEN DIGITAL INC
  • US10206099B1 patent drawing
  • US10206099B1 patent drawing
  • US10206099B1 patent drawing

AI summary

Techniques disclosed herein provide a geolocation-based two-factor authentication process. An authentication service receives a first authentication factor associated with an account. Upon validating the first authentication factor, the authentication service requests a second authentication factor from an application executing on a mobile device associated with the account. The second authentication factor identifies at least a location of the mobile device. The authentication service determines a location of the client device. Upon determining that the locations of the mobile device and of the client device are within a specified proximity of one another, the authentication service grants access to the account.