Location-Based User Authentication Against Man-in-the-Middle Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication methods are susceptible to security breaches such as Man-in-the-Middle attacks and are often inconvenient or unreliable, lacking robustness and user-friendliness.

Innovation Solution

Incorporating a user's trusted location as an additional authentication factor using location-based parameters, such as RF fingerprinting or user input, to enhance the security of the authentication process, particularly aligning with standards like FIDO.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication methods (username-password, biometric, MFA) are used, then authentication functionality is provided, but security against Man-in-the-Middle attacks is compromised

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to MiTM attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces location information as an intermediary factor in the authentication process. The server verifies not only credentials but also the user's physical location through GPS, Wi-Fi, or cellular data, creating an additional layer that prevents MiTM attacks by ensuring the authentication request originates from the user's expected location

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the authentication parameters by adding location-based parameters (geographic coordinates, location accuracy, movement patterns) to the traditional authentication factors. This multi-parameter approach transforms single-factor or two-factor authentication into a more robust multi-dimensional verification system that is resistant to MiTM attacks

Inventive Principle:
Principle #35Parameter changes

2Reliability

If biometric authentication is used, then unique biological verification is achieved, but biometric data can be stolen or replicated and cannot be changed like a password

Engineering Contradiction:
Improveverification accuracyVSAvoidbiometric data theft and replication
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges biometric authentication with location-based authentication, combining two different verification factors. The server requires both biometric verification and location verification to be satisfied simultaneously, creating a compounded security mechanism where compromise of one factor does not lead to full system compromise

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication system uses a composite verification approach, combining multiple authentication factors (biometric data, location information, device identifiers) into a unified authentication decision. This composite security model ensures that no single factor is sufficient for authentication, protecting against biometric theft and replication

Inventive Principle:
Principle #40Composite materials

3Reliability

If Two-factor authentication is used, then security is improved, but user convenience deteriorates due to requiring password and secondary device access

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The location-based authentication leverages the device's existing location services (GPS, Wi-Fi positioning) that users already have enabled for other purposes. The system automatically collects and verifies location data without requiring users to manually input additional information or interact with secondary devices, making the enhanced security transparent to the user

Inventive Principle:
Principle #25Self-service

4Ease of operation

If password-less authentication is used, then password management is simplified, but security is compromised if email or phone access is compromised

Engineering Contradiction:
Improvepassword managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent adds a spatial dimension to authentication by incorporating location verification. Even if an attacker gains access to the user's email or phone for receiving codes, they cannot authenticate from unauthorized locations. This geographic dimension creates a fundamental barrier that protects against compromise of communication channels

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach strengthens security against unauthorized access and Man-in-the-Middle attacks, providing a more secure and user-friendly authentication method that simplifies the process while ensuring greater resilience against threats.

Implementation Method 1

In some examples, the location of the user is determined by RF fingerprinting

Methodology Applied
Scientific EffectRF fingerprinting:

Data Source

PatentEP4730707A1Method and apparatus for authentication of a user based on location of the user
Publication Date: 2026.04.22 INTEL CORP
  • EP4730707A1 patent drawingFigure 1~2
  • EP4730707A1 patent drawingFigure 3
  • EP4730707A1 patent drawingFigure 4

AI summary

A method and apparatus for authentication of a user. A user profile is generated during an initial registration. The user profile may include a trusted location of the user. During a subsequent authentication process for the user, it is determined whether the user is located in the trusted location of the user, and an access to a service for the user may be controlled based on a result of the authentication process and the determination whether the user is located in the trusted location of the user. A location-based parameter of the trusted location of the user may be determined and stored in advance, and it is determined whether the user is located in the trusted location of the user by comparing the location-based parameter of the current location of the user and the location-based parameter of the trusted location of the user.