Location-Based Authentication for Online Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service providers face challenges in controlling access to online services based on location, particularly for services that use packet-switch communications over multiple networks, as existing infrastructure-based controls are inadequate for managing access across different geographical areas.

Innovation Solution

Implementing a system with an Authentication, Authorization, and Accounting (AAA) server and an identity provider (IdP) that issues authentication tokens and assertions, allowing location-based authentication and authorization, enabling service providers to manage access to online services by verifying the location of the accessing device and substituting or blocking content as needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If infrastructure based controls are used to limit service locations, then location based restraints can be implemented for traditional services, but these controls are ineffective for online services that use packet-switch communications over multiple networks

Engineering Contradiction:
Improvelocation based control effectivenessVSAvoidservice delivery flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary authentication system that mediates between the service provider and the accessing device. This authentication server acts as a mediator that verifies location information and provides authentication credentials, enabling location-based control for online services without relying on traditional infrastructure controls. The intermediary resolves the contradiction by providing a universal authentication mechanism that works across multiple networks while maintaining location-based restrictions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If backend infrastructure controls are used to manage service locations, then transmission control can be achieved for fixed signaling paths, but control is lost when services are delivered over packet-switched networks with multiple possible paths

Engineering Contradiction:
Improveservice location controlVSAvoidcontrol system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system enables self-service location verification where the accessing device itself provides location information and receives authentication credentials based on its location. The service provider does not need to control or monitor the actual service delivery path, as the authentication credential itself enforces location-based access control. This reduces control system complexity while maintaining reliable location-based service management.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If location based authentication is implemented for online services, then service providers can enforce location restrictions without infrastructure controls, but additional authentication mechanisms and processing are required

Engineering Contradiction:
Improveservice delivery flexibilityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system performs preliminary authentication before service delivery, where the accessing device obtains location-based authentication credentials in advance. This preliminary action establishes the location verification and authorization before the actual service transaction occurs, simplifying the service delivery process itself. The authentication complexity is front-loaded and handled once, rather than continuously during service delivery.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system creates and distributes authentication credentials (such as certificates or tokens) that copy and encode the location-based authorization information. Once authenticated, the accessing device receives a copy of the authorization credential that can be presented for service access without requiring continuous verification of the original location data, reducing ongoing system complexity.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8824372B2Location based authentication for online services
Publication Date: 2014.09.02 CABLE TELEVISION LAB INC
  • US8824372B2 patent drawing
  • US8824372B2 patent drawing
  • US8824372B2 patent drawing

AI summary

Providing access to online services is contemplated. The online services authorized for access may be limited or controlled according to a location of an access point used to facilitate access to the online services. This location based authorization may be useful in providing access to online services that have location dependent restraints.