Policy-Based Authentication Server for IoT Location Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based services face security challenges due to the inefficiency of traditional multi-factor authentication mechanisms, particularly for IoT devices that require manual input and lack effective location-based verification.

Innovation Solution

Implementing a policy-based authentication system that utilizes a database to store authentication policies, where an authentication server receives location data from devices to verify their authenticity based on specified location parameters, leveraging satellite and short-range radio signals for location determination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional multi-factor authentication mechanisms are used, then security is enhanced, but authentication efficiency deteriorates due to manual input requirements

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables automated authentication where IoT devices self-verify their location using onboard sensors (GPS, accelerometer, barometer) without requiring manual user input. The device autonomously collects location data, compares it against authorized parameters, and completes authentication, eliminating the inefficiency of manual credential entry while maintaining security through multi-factor verification.

Inventive Principle:
Principle #25Self-service

2Reliability

If location-based authentication is implemented, then security against malicious attacks is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system leverages existing multi-functional components in IoT devices - sensors originally designed for environmental monitoring or navigation (GPS, accelerometer, barometer) are repurposed for authentication. This approach adds location-based security without requiring dedicated authentication hardware, as these components already serve other functions in the device, thus minimizing additional complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If automated location verification is implemented, then authentication efficiency is improved, but measurement precision requirements increase

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidlocation data accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system fuses data from multiple independent sensors (GPS coordinates, accelerometer motion patterns, barometric pressure readings) to create a composite location signature. This multi-sensor fusion approach compensates for individual sensor limitations and provides robust location verification with higher effective precision than any single sensor could achieve alone, enabling automated authentication without excessive precision demands on individual components.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS11653200B2Location/things aware cloud services delivery solution
Publication Date: 2023.05.16 CITRIX SYSTEMS INC
  • US11653200B2 patent drawing
  • US11653200B2 patent drawing
  • US11653200B2 patent drawing

AI summary

Described embodiments provide systems and methods for policy-based authentication, where the policy may designate locations and/or forms of proof of locations, for use in authentication. Some embodiments include or utilize a database storing authentication policies. In an example system, an authentication server in communication with the database is configured to receive a request from a device needing authentication. The request may include a credential. The authentication server is configured to retrieve, from the database storing authentication policies, an authentication policy corresponding to the device, the retrieved authentication policy specifying a location parameter. The authentication server is configured to receive location data from the device and resolve the authentication request using the credential and the received location data pursuant to the retrieved authentication policy.