IP Address Distance Map for Authentication Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems using IP addresses are unreliable due to IP address mapping methods like NAT and VPN, leading to incorrect blocking of legitimate authentication requests and potential unauthorized access from attackers in the same location.

Innovation Solution

A computer-implemented method that collects data on IP address changes, creates a virtual IP address distance map using machine learning to determine the likelihood of change, and automatically detects suspicious IP address changes to perform security actions, such as rejecting or challenging authentication requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IP address mapping methods like NAT and VPN are used, then remote access and network flexibility are improved, but IP address reliability as a geographic location indicator deteriorates

Engineering Contradiction:
Improveremote access capabilityVSAvoidIP address location indication
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication system that sits between the user and the service provider. This intermediary collects and analyzes IP address change data, creates a virtual IP address distance map, and determines whether IP changes are suspicious before allowing authentication. This mediator resolves the contradiction by enabling remote access while filtering out unreliable IP address indications through intelligent analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter of IP address evaluation from a static geographic location indicator to a dynamic parameter that considers the history and pattern of IP address changes. By analyzing the sequence of IP addresses and their temporal relationships, the system can distinguish between legitimate remote access (which shows predictable patterns) and suspicious activity (which shows erratic patterns), thus resolving the reliability issue.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If IP address changes are strictly monitored to block suspicious requests, then security is improved, but legitimate authentication requests from mobile devices are incorrectly blocked

Engineering Contradiction:
Improveauthentication securityVSAvoidlegitimate authentication
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs preliminary actions by collecting IP address change data and creating a virtual distance map before actual authentication occurs. This pre-computed baseline of normal IP change patterns allows the system to quickly evaluate new authentication requests without causing delays. Legitimate users with predictable IP change patterns are automatically approved, while suspicious patterns trigger additional verification, thus maintaining both security and ease of operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a dynamic authentication system that adapts to the user's IP address change patterns over time. Instead of using fixed geographic boundaries, the system continuously learns and updates the virtual IP address distance map based on observed user behavior. This dynamic approach allows legitimate users to access services from various locations while automatically blocking anomalous authentication attempts, resolving the contradiction between security and ease of operation.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If traditional authentication using only credentials is used, then ease of access is improved, but vulnerability to stolen credentials increases

Engineering Contradiction:
Improveauthentication simplicityVSAvoidcredential theft impact
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces feedback mechanisms that monitor IP address changes and provide information about the authenticity of authentication requests. The system analyzes the IP address distance map and compares it against the current authentication request's IP address. When the IP address aligns with the user's historical pattern, authentication proceeds smoothly. When there's a mismatch indicating potential credential theft, the system provides feedback by requesting additional verification, thus maintaining simplicity for legitimate users while blocking stolen credential attempts.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10284556B1Systems and methods for verifying authentication requests using internet protocol addresses
Publication Date: 2019.05.07 GEN DIGITAL INC
  • US10284556B1 patent drawing
  • US10284556B1 patent drawing
  • US10284556B1 patent drawing

AI summary

A computer-implemented method for verifying authentication requests using IP addresses may include (i) collecting, by a computing system, data on IP address changes from a set of endpoint devices, (ii) creating, by the computing system using the data on IP address changes, a virtual IP address distance map based on a likelihood of change from at least one origin IP address to at least one destination IP address, (iii) automatically detecting, by the computing system, a change in an IP address of a client device, (iv) determining, by the computing system and based on the virtual IP address distance map, that the change in the IP address of the client device indicates that an authentication request from the client device is suspicious, and (v) performing, by the computing system, a security action to secure the client device. Various other methods, systems, and computer-readable media are also disclosed.