Location-Based Service Authentication Using IMSI Hashing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing location-based services face vulnerabilities that allow illegal access to user location information and personal data, compromising privacy despite advancements in systems like Amazon EC2 and SQL Azure.

Innovation Solution

A location-based service system and method that utilizes a location-based service server and cloud data server with an authentication module to generate and authenticate cloud authentication codes based on international mobile subscriber identity, reducing data leakage by performing secure hash algorithms on service authentication codes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If location-based services store user account information and authentication codes in cloud servers, then service convenience and accessibility are improved, but system security and privacy protection deteriorate due to vulnerabilities allowing illegal access to user data

Engineering Contradiction:
Improveservice convenienceVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into multiple independent components: the location-based service server stores only authentication rules and generates temporary authentication codes, while user account information and personal data remain stored locally in the communication device. This segmentation ensures that even if the cloud server is compromised, attackers cannot access user data stored locally in the device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication code as a mediator between the user and the location-based service server. Instead of directly transmitting or storing sensitive user data in the cloud, the system uses temporary authentication codes that are generated locally, transmitted to the server for verification, and then discarded. This intermediary mechanism enables cloud-based service access while preventing exposure of user data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the system transmits and stores authentication codes in cloud servers, then service accessibility is improved, but data leakage risks increase due to system vulnerabilities

Engineering Contradiction:
Improveservice accessibilityVSAvoiddata leakage
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The system performs preliminary actions by generating authentication codes locally in the communication device before any data transmission occurs. The authentication code is created from local user data using a hash algorithm, and only this code (not the original data) is transmitted to the cloud server. This preliminary local processing prevents the risk of data leakage during transmission and storage in the cloud.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transforms the authentication mechanism by changing the parameter being transmitted and stored. Instead of transmitting and storing original user data (high risk), the system transmits and stores transformed authentication codes derived from user data through cryptographic hashing. This parameter change maintains service accessibility while dramatically reducing information leakage risks.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If the system uses traditional cloud-based authentication storage, then service flexibility is improved, but vulnerability to illegal access and data theft increases

Engineering Contradiction:
Improveservice flexibilityVSAvoiddata theft risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the authentication process into local data processing and cloud verification. User data remains segmented and stored locally in the communication device, while only authentication codes are transmitted to the cloud server. This segmentation maintains service flexibility through cloud-based verification while reducing data theft risk by keeping sensitive data local.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of storing original user data in the cloud, the system creates a copy in the form of an authentication code that can be used for verification purposes. This copy contains sufficient information for authentication but cannot be used to reconstruct the original user data, thus maintaining service flexibility while preventing data theft.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9432801B2Location-based service system and serving method
Publication Date: 2016.08.30 NAT CHIAO TUNG UNIV
  • US9432801B2 patent drawing
  • US9432801B2 patent drawing
  • US9432801B2 patent drawing

AI summary

A location-based service system and method, which allows a location-based service server connected with a communication device and a cloud data server to perform registration authorization procedures and service authorization procedures using an international mobile subscriber identity of the communication device that cannot be easily modified or forged in the registration and service modes, so that a user may obtain a specific location-based service result via the communication device, and this distributed authentication technique reduces the risk of data theft while increasing the flexibility and convenience in obtaining services.