Location-Aware Mutual Certificate Authentication for Utility Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for mutual certificate authentication between devices in the utility industry do not adequately restrict access based on location, allowing unauthorized access and potential security breaches when devices are operated from unintended locations.
Innovation Solution
Implementing a method and system for mutual certificate authentication between a first device and a second device, where certificates are issued on demand based on the current location of the first device relative to the second device, ensuring that access is limited to a defined distance or time period, thereby preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional public key infrastructure authentication is used, then devices can be authenticated and access can be granted, but devices can access one another from any location for an unlimited duration, compromising security
Solution Approach 1:
The patent implements dynamic certificate validation by continuously monitoring the geographic location of devices during the authentication session. The system dynamically determines whether to grant or revoke access based on real-time location data compared against predefined geographic boundaries, transforming static authentication into an adaptive, location-aware process that maintains security while allowing flexible access within authorized areas
Solution Approach 2:
The patent changes the authentication parameters by incorporating geographic location coordinates and time duration as additional validation criteria beyond traditional digital certificates. The system establishes geographic boundaries and time limits as configurable parameters, and continuously evaluates device location against these parameters to maintain secure access control throughout the authentication session
2Reliability
If location-based access restrictions are implemented, then security is enhanced by limiting access to specific geographic areas, but system complexity increases due to continuous location monitoring and validation
Solution Approach 1:
The patent introduces a certificate authority server as an intermediary that manages the complex location-based authentication logic. The server receives location updates from devices, validates them against stored geographic boundaries, and manages certificate issuance and revocation. This intermediary approach centralizes the computational complexity of continuous location monitoring and validation, keeping the client devices relatively simple while maintaining robust security
Solution Approach 2:
The patent performs preliminary actions by pre-defining geographic boundaries and access policies in the certificate authority server before authentication sessions begin. The system pre-processes location validation rules and stores authorized geographic areas, eliminating the need for complex real-time calculations during active sessions. This preliminary configuration reduces runtime complexity while maintaining comprehensive location-based security control
Data Source
AI summary
In one aspect, a method of mutual certificate authentication between a first device and a second device based on location is described. This embodiment of a method comprises receiving a request from a first device, wherein the request comprises a location of the first device; registering a first public key for the first device in response to the request, wherein the registration associates the first device with the first public key; determining at least one second device that can be accessed by the first device based upon a location of the second device relative to the location of the first device; registering a second public key for the second device, wherein the registration associates the second device with the second public key; sending the second public key to the first device; sending the first public key to the second device; and mutually authenticating the first device to the second device when the first device and the second device are connected.


