Location-Based Authentication via Geographical Challenge Questions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Access management systems face security vulnerabilities when one-time passwords (OTPs) are compromised, especially if the device is lost or stolen, as attackers can gain access to protected resources and reset passwords, and challenge questions may be easily guessed or forgotten.

Innovation Solution

Implementing location-based authentication, where an access management system determines and stores a user's geographical location and uses user-configured questions associated with past locations to authenticate the user, requiring a correct answer to grant access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If one-time passwords (OTPs) are used for authentication, then security is improved, but the system becomes vulnerable when the device is lost or stolen

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice loss vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent adds a spatial dimension to authentication by incorporating GPS location data. Instead of relying solely on possession of the device (one dimension), the system now verifies both device possession and geographic location (adding a second dimension). This means even if an attacker obtains the device, they cannot authenticate from unauthorized locations, resolving the vulnerability to device loss or theft.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If challenge questions are used for authentication, then security is improved, but the questions become easily guessed or forgotten

Engineering Contradiction:
Improveauthentication securityVSAvoidquestion memorability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent makes challenge questions location-specific rather than generic. Each location has its own unique set of questions and answers tied to that geographic context. This localizes the authentication challenge to the specific place, making questions less predictable and harder to guess, while still being memorable for the legitimate user who experiences them at specific locations.

Inventive Principle:
Principle #3Local quality

3Reliability

If location-based authentication with user-configured questions is implemented, then security against device theft is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component (location-based question generator) that automatically creates and manages location-specific challenge questions. This intermediary handles the complexity of generating, storing, and verifying location-bound questions, shielding users from the underlying system complexity while maintaining enhanced security. The intermediary translates complex location-data into simple, location-specific questions for users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10637871B2Location-based authentication
Publication Date: 2020.04.28 ORACLE INT CORP
  • US10637871B2 patent drawing
  • US10637871B2 patent drawing
  • US10637871B2 patent drawing

AI summary

Location-based authentication may be provided by an access management system on a server. The location-based authentication may determine whether a device should be granted access to a resource. The resource may either be located on or remote from the server. The location-based authentication may provide an additional authentication factor that is based on a past location of a user and/or device associated with the user requesting authentication. The past location may be associated with a user-configured question. The user-configured question may be provided to the device for an additional level of security. An answer received in response to a user-configured question may be compared to a user-configured answer that is associated with the user-configured question. In other examples, the answer may be compared to one or more possible answers that are determined by the access management system.