Location Assurance via Shared Secret Modified Indicators
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current location assurance techniques in information processing systems are vulnerable to GPS spoofing, which can compromise the accuracy of user location verification, potentially allowing unauthorized access to protected resources.
Innovation Solution
The method involves negotiating a shared secret between the client and authentication server, using this secret to encrypt or modify virtual object images, which the user must decrypt or alter to authenticate their location, thereby enhancing the trustworthiness of GPS coordinates and mitigating spoofing risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If GPS coordinates are used directly for location verification, then the authentication process is simple and fast, but the system becomes vulnerable to GPS spoofing attacks
Solution Approach 1:
The patent introduces virtual object images as an intermediary between the GPS coordinates and the authentication verification. Instead of directly verifying GPS coordinates, the system uses location indicators (virtual objects) that are rendered based on those coordinates. The client captures images of these virtual objects, which serve as proof of location without exposing the raw GPS data, thus preventing spoofing while maintaining authentication capability
Solution Approach 2:
The patent transforms the location verification parameter from raw GPS coordinates to processed virtual object images. By changing the form of the location indicator from numerical coordinates to visual representations that must be captured and verified, the system increases the difficulty of spoofing while maintaining the ability to verify location authenticity
2Reliability
If location assurance techniques are implemented to prevent GPS spoofing, then the security of authentication is improved, but the complexity of the authentication process increases
Solution Approach 1:
The system uses the client's own camera and image processing capabilities to capture and verify virtual object images. The client device itself performs part of the verification process by capturing the virtual object and generating the location proof, reducing the need for complex server-side verification mechanisms while maintaining security
Solution Approach 2:
Instead of the server directly verifying GPS coordinates from the client, the system inverts the process by having the client capture visual proof (virtual object images) that the server then verifies. This reversal of the verification flow simplifies the client's role while maintaining strong security controls on the server side
Data Source
AI summary
Techniques are provided for user authentication using a location assurance based on a location indicator modified by a shared secret. One method comprises obtaining a shared secret; initiating a challenge in connection with an authentication request by a client from a given location to access a protected resource, wherein the challenge comprises a location indicator selected for the given location; processing a response submitted by the client in response to the challenge, wherein the response comprises the location indicator for the given location modified by the client with the shared secret, and wherein the processing comprises evaluating the response submitted by the client relative to the location indicator selected by the authentication server; and resolving the authentication request based on the evaluating. The client modification of the selected location indicator with the shared secret comprises, for example, decrypting, filtering and/or altering the location indicator based on the shared secret.


