Location Attestation via Trusted Geocoded Beacons

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing location verification methods are inadequate for ensuring accurate user location authentication, particularly when using virtual private networks (VPNs) or GPS spoofing, as they rely on weak location approximations or trust user-provided data, which can lead to unauthorized access to restricted resources.

Innovation Solution

A computer-implemented method that receives user-initiated access requests, collects location data, and corroborates it with a trusted geocoded device to issue an authentication status, using attestation tokens from beacon services to independently verify the user's location without requiring access to sensitive location information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If weak location approximations or user-provided location data are used, then the system is easy to operate and requires minimal infrastructure, but the location verification accuracy deteriorates and unauthorized access can occur

Engineering Contradiction:
Improveease of operationVSAvoidlocation verification accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent introduces beacon services as intermediary trusted geocoded devices that mediate between the user's device and the location verification system. These beacons independently verify the user's physical presence at a location and provide attestation tokens, eliminating the need to trust user-provided location data while maintaining ease of operation through automated verification

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces mechanical/trust-based location verification (relying on user-provided data or IP address approximations) with a cryptographic verification system. Attestation tokens signed by trusted beacons provide mathematically verifiable location proof, substituting trust in user input with cryptographic verification of physical presence

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If trusted geocoded devices and attestation tokens are used, then location verification accuracy improves and unauthorized access is prevented, but the device complexity and infrastructure requirements increase

Engineering Contradiction:
Improvelocation verification accuracyVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements self-service through automated attestation token generation and verification. The beacon services automatically verify user location and generate cryptographic proofs without manual intervention, while the verification system automatically validates tokens and makes access decisions, reducing the perceived complexity for users despite the sophisticated backend infrastructure

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal beacon service infrastructure that can serve multiple location verification purposes and integrate with various access control systems. The attestation token mechanism is designed to be broadly applicable across different services and platforms, amortizing the infrastructure complexity across multiple uses and beneficiaries

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If VPNs or GPS spoofing are used, then user privacy and location flexibility are maintained, but the reliability of location verification deteriorates and restricted resources can be accessed unauthorized

Engineering Contradiction:
Improvelocation flexibilityVSAvoidreliability of location verification
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent requires preliminary action by establishing a network of pre-deployed trusted beacon devices at known geographic locations before verification is needed. These beacons are set up in advance with cryptographic credentials, enabling them to independently verify user presence without relying on user-provided location data that could be spoofed through VPNs or GPS manipulation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces beacon services as intermediary trusted geocoded devices that mediate between the user's device and the location verification system. These beacons independently verify the user's physical presence at a location and provide attestation tokens, eliminating the need to trust user-provided location data while maintaining ease of operation through automated verification

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 3:

The patent replaces mechanical/trust-based location verification (relying on user-provided data or IP address approximations) with a cryptographic verification system. Attestation tokens signed by trusted beacons provide mathematically verifiable location proof, substituting trust in user input with cryptographic verification of physical presence

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20230319775A1Location based attestation
Publication Date: 2023.10.05 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20230319775A1 patent drawing
  • US20230319775A1 patent drawing
  • US20230319775A1 patent drawing

AI summary

A computer implemented method for managing access requests based on user device location includes receiving a user initiated access request from a first device of the user, receiving location data of the first device, requesting attestation of a registered device of the user from a trusted geocoded device, receiving an attestation token for the registered device of the user from the trusted geocoded device, wherein the attestation token includes location data for the registered device, comparing the received location data of the first device to the location data of the registered device, and issuing an authentication status based on the comparison of the received location data of the first device to the determined location data of the second device of the user. A computer program product and computer system corresponding to the method are also disclosed.