Geographic Location-Based Policy for Access Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing vulnerability of computers and servers in networked communications poses a significant threat, particularly in data centers providing critical computing services, as existing login mechanisms are inadequate in preventing unauthorized access, especially when devices are stolen or accessed improperly, leading to potential disruptions and data security breaches.

Innovation Solution

Implementing a location-based security mechanism that uses geographic information to determine the authenticity of access requests, allowing or denying actions based on the device's location, such as requiring additional verification steps or restricting transactions to specific areas, thereby enhancing security and protecting user data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional username and password login mechanisms are used, then ease of operation is improved, but security is worsened due to vulnerability to guessing attacks and unauthorized access from stolen devices

Engineering Contradiction:
Improvelogin process simplicityVSAvoidaccess security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the security parameter from static credentials (username/password) to dynamic location-based verification. The system determines the geographic location of the computing device and compares it against authorized locations stored in the policy database, creating a new security dimension that is difficult for attackers to compromise.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces location information as an intermediary verification layer between the user and the protected resource. Instead of directly verifying credentials, the system first verifies the device's geographic location through GPS, cell towers, or WiFi positioning, and only then allows access to the credential verification process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If location-based verification is implemented, then security is improved, but device complexity is worsened due to additional verification steps

Engineering Contradiction:
Improveaccess securityVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system leverages the computing device's existing self-service location determination capabilities (GPS, cell tower triangulation, WiFi positioning) to automatically obtain location information without requiring user intervention. The device itself performs the location verification, eliminating the need for external verification hardware or complex user-facing verification processes.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If location-based policies are enforced, then unauthorized access is reduced, but legitimate user access may be disrupted due to location verification requirements

Engineering Contradiction:
Improveunauthorized accessVSAvoidlegitimate user access
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system performs preliminary action by pre-registering authorized locations (home address, workplace, travel destinations) in the policy database before access is needed. When a user attempts to access protected resources, the system simply checks whether the current device location matches any pre-registered authorized location, enabling rapid verification without disrupting legitimate users.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9491183B1Geographic location-based policy
Publication Date: 2016.11.08 AMAZON TECH INC
  • US9491183B1 patent drawing
  • US9491183B1 patent drawing
  • US9491183B1 patent drawing

AI summary

In a computing environment a request is received from a computing device associated with a user, requesting access to one or more computing resources. An approximate geographic location of the computing device is determined based on geographic information associated with the computing device. Access to the requested one or more computing resources is allowed based on the approximate geographic location of the computing device and geographic policy information for the user.