Location-Aware Mutual Certificate Authentication for Utility Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for mutual certificate authentication between devices in the utility industry do not adequately restrict access based on location, allowing unauthorized access and potential security breaches when devices are operated from unintended locations.

Innovation Solution

Implementing a method and system for mutual certificate authentication between a first device and a second device, where certificates are issued on demand based on the current location of the first device relative to the second device, ensuring that access is limited to a defined distance or time period, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional public key infrastructure authentication is used, then devices can be authenticated and access can be granted, but devices can access one another from any location for an unlimited duration, compromising security

Engineering Contradiction:
Improveauthentication securityVSAvoidaccess flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic certificate validation by continuously monitoring the geographic location of devices during the authentication session. The system dynamically determines whether to grant or revoke access based on real-time location data compared against predefined geographic boundaries, transforming static authentication into an adaptive, location-aware process that maintains security while allowing flexible access within authorized areas

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the authentication parameters by incorporating geographic location coordinates and time duration as additional validation criteria beyond traditional digital certificates. The system establishes geographic boundaries and time limits as configurable parameters, and continuously evaluates device location against these parameters to maintain secure access control throughout the authentication session

Inventive Principle:
Principle #35Parameter changes

2Reliability

If location-based access restrictions are implemented, then security is enhanced by limiting access to specific geographic areas, but system complexity increases due to continuous location monitoring and validation

Engineering Contradiction:
Improveaccess securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a certificate authority server as an intermediary that manages the complex location-based authentication logic. The server receives location updates from devices, validates them against stored geographic boundaries, and manages certificate issuance and revocation. This intermediary approach centralizes the computational complexity of continuous location monitoring and validation, keeping the client devices relatively simple while maintaining robust security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary actions by pre-defining geographic boundaries and access policies in the certificate authority server before authentication sessions begin. The system pre-processes location validation rules and stores authorized geographic areas, eliminating the need for complex real-time calculations during active sessions. This preliminary configuration reduces runtime complexity while maintaining comprehensive location-based security control

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10068084B2Method and system of location-aware certificate based authentication
Publication Date: 2018.09.04 GE INFRASTRUCTURE TECH LLC
  • US10068084B2 patent drawing
  • US10068084B2 patent drawing
  • US10068084B2 patent drawing

AI summary

In one aspect, a method of mutual certificate authentication between a first device and a second device based on location is described. This embodiment of a method comprises receiving a request from a first device, wherein the request comprises a location of the first device; registering a first public key for the first device in response to the request, wherein the registration associates the first device with the first public key; determining at least one second device that can be accessed by the first device based upon a location of the second device relative to the location of the first device; registering a second public key for the second device, wherein the registration associates the second device with the second public key; sending the second public key to the first device; sending the first public key to the second device; and mutually authenticating the first device to the second device when the first device and the second device are connected.