Location-Aware Authentication System Using Distance Thresholds
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems lack the ability to effectively verify the location of a user attempting access, which can lead to unauthorized access and identity theft, especially in scenarios where credentials are compromised or stolen.
Innovation Solution
A system that references past user location information and current location information to determine a maximum allowable distance, managing authentication attempts based on this distance, allowing or denying access, and prompting for additional validation if the location is outside the allowable range, using a network system with a client, server, and database to store and communicate user location data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication systems (username/password, PIN, card) are used, then users can access systems and services, but the systems cannot verify the actual location of the user, leading to vulnerability to unauthorized access and identity theft
Solution Approach 1:
The patent combines traditional credential-based authentication with location-based authentication into a unified system. The authentication server integrates multiple verification methods (credentials + geographic location) to provide enhanced security without requiring completely separate systems, thereby improving reliability while controlling complexity through integration.
Solution Approach 2:
The patent introduces a location verification mechanism as an intermediary layer between the user and the authentication system. This intermediary verifies the user's geographic location and provides this information to the authentication server, enabling location-based authentication without directly complicating the core authentication logic.
2Object-affected harmful factors
If location verification is added to authentication systems, then security against unauthorized access is improved, but the system complexity and processing requirements increase
Solution Approach 1:
The patent performs location verification as a preliminary step before completing authentication. By checking the user's location in advance and comparing it with expected location parameters, the system can quickly filter out unauthorized access attempts without requiring complex real-time analysis during the authentication process itself.
Solution Approach 2:
The patent changes the authentication parameters by adding geographic location coordinates as a new verification dimension. Instead of only checking credentials, the system now verifies credential validity plus location match, using configurable parameters like acceptable distance thresholds to control the strictness of verification without requiring complex algorithms.
3Reliability
If strict location verification is enforced, then security is improved by blocking potential unauthorized access, but legitimate users traveling or working remotely may be denied access
Solution Approach 1:
The patent implements dynamic location verification where the acceptable location parameters can change based on user profiles, time of day, and security policies. The system can adjust distance thresholds, allow multiple approved locations, or temporarily modify verification strictness, enabling both high security and flexibility for legitimate users with varying access needs.
Solution Approach 2:
The patent applies different location verification strictness levels to different users, services, or time periods. Instead of a single uniform location policy, the system can configure location tolerance parameters locally for specific user accounts, services, or situations, allowing high security for critical resources while providing flexibility for routine access or traveling users.
Data Source
AI summary
A computer program product, apparatus, and system, are disclosed for user authentication based on authentication credentials and location information. A computer program product performs operations for such authentication. These operations of the computer program product include referencing past user location information in response to an authentication validation request and referencing current user location information. These operations also include determining a maximum allowable distance between an authentication attempt location associated with the authentication attempt location identifier and a past location associated with the past user interaction location identifier, and managing the authentication attempt, in response to determining that the physical authentication attempt location is outside the maximum allowable distance. The computer program product, apparatus, and system thereby reduce the possibility of identity theft by adding an element of location awareness to the authentication process.


