Location-Based Authentication for Online Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service providers face challenges in controlling access to online services based on location, particularly for services that use packet-switch communications over multiple networks, as existing infrastructure-based controls are inadequate for managing access across different geographical areas.
Innovation Solution
Implementing a system with an Authentication, Authorization, and Accounting (AAA) server and an identity provider (IdP) that issues authentication tokens and assertions, allowing location-based authentication and authorization, enabling service providers to manage access to online services by verifying the location of the accessing device and substituting or blocking content as needed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If infrastructure based controls are used to limit service locations, then location based restraints can be implemented for traditional services, but these controls are ineffective for online services that use packet-switch communications over multiple networks
Solution Approach 1:
The patent introduces an intermediary authentication system that mediates between the service provider and the accessing device. This authentication server acts as a mediator that verifies location information and provides authentication credentials, enabling location-based control for online services without relying on traditional infrastructure controls. The intermediary resolves the contradiction by providing a universal authentication mechanism that works across multiple networks while maintaining location-based restrictions.
2Reliability
If backend infrastructure controls are used to manage service locations, then transmission control can be achieved for fixed signaling paths, but control is lost when services are delivered over packet-switched networks with multiple possible paths
Solution Approach 1:
The authentication system enables self-service location verification where the accessing device itself provides location information and receives authentication credentials based on its location. The service provider does not need to control or monitor the actual service delivery path, as the authentication credential itself enforces location-based access control. This reduces control system complexity while maintaining reliable location-based service management.
3Adaptability or versatility
If location based authentication is implemented for online services, then service providers can enforce location restrictions without infrastructure controls, but additional authentication mechanisms and processing are required
Solution Approach 1:
The system performs preliminary authentication before service delivery, where the accessing device obtains location-based authentication credentials in advance. This preliminary action establishes the location verification and authorization before the actual service transaction occurs, simplifying the service delivery process itself. The authentication complexity is front-loaded and handled once, rather than continuously during service delivery.
Solution Approach 2:
The authentication system creates and distributes authentication credentials (such as certificates or tokens) that copy and encode the location-based authorization information. Once authenticated, the accessing device receives a copy of the authorization credential that can be presented for service access without requiring continuous verification of the original location data, reducing ongoing system complexity.
Data Source
AI summary
Providing access to online services is contemplated. The online services authorized for access may be limited or controlled according to a location of an access point used to facilitate access to the online services. This location based authorization may be useful in providing access to online services that have location dependent restraints.


