Location-Based Authentication via Geographical Challenge Questions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Access management systems face security vulnerabilities when one-time passwords (OTPs) are compromised, especially if the device is lost or stolen, as attackers can gain access to protected resources and reset passwords, and challenge questions may be easily guessed or forgotten.
Innovation Solution
Implementing location-based authentication, where an access management system determines and stores a user's geographical location and uses user-configured questions associated with past locations to authenticate the user, requiring a correct answer to grant access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If one-time passwords (OTPs) are used for authentication, then security is improved, but the system becomes vulnerable when the device is lost or stolen
Solution Approach 1:
The patent adds a spatial dimension to authentication by incorporating GPS location data. Instead of relying solely on possession of the device (one dimension), the system now verifies both device possession and geographic location (adding a second dimension). This means even if an attacker obtains the device, they cannot authenticate from unauthorized locations, resolving the vulnerability to device loss or theft.
2Reliability
If challenge questions are used for authentication, then security is improved, but the questions become easily guessed or forgotten
Solution Approach 1:
The patent makes challenge questions location-specific rather than generic. Each location has its own unique set of questions and answers tied to that geographic context. This localizes the authentication challenge to the specific place, making questions less predictable and harder to guess, while still being memorable for the legitimate user who experiences them at specific locations.
3Reliability
If location-based authentication with user-configured questions is implemented, then security against device theft is improved, but system complexity increases
Solution Approach 1:
The patent introduces an intermediary component (location-based question generator) that automatically creates and manages location-specific challenge questions. This intermediary handles the complexity of generating, storing, and verifying location-bound questions, shielding users from the underlying system complexity while maintaining enhanced security. The intermediary translates complex location-data into simple, location-specific questions for users.
Data Source
AI summary
Location-based authentication may be provided by an access management system on a server. The location-based authentication may determine whether a device should be granted access to a resource. The resource may either be located on or remote from the server. The location-based authentication may provide an additional authentication factor that is based on a past location of a user and/or device associated with the user requesting authentication. The past location may be associated with a user-configured question. The user-configured question may be provided to the device for an additional level of security. An answer received in response to a user-configured question may be compared to a user-configured answer that is associated with the user-configured question. In other examples, the answer may be compared to one or more possible answers that are determined by the access management system.


