Location-Based Service Authentication Using IMSI Hashing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing location-based services face vulnerabilities that allow illegal access to user location information and personal data, compromising privacy despite advancements in systems like Amazon EC2 and SQL Azure.
Innovation Solution
A location-based service system and method that utilizes a location-based service server and cloud data server with an authentication module to generate and authenticate cloud authentication codes based on international mobile subscriber identity, reducing data leakage by performing secure hash algorithms on service authentication codes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If location-based services store user account information and authentication codes in cloud servers, then service convenience and accessibility are improved, but system security and privacy protection deteriorate due to vulnerabilities allowing illegal access to user data
Solution Approach 1:
The authentication system is segmented into multiple independent components: the location-based service server stores only authentication rules and generates temporary authentication codes, while user account information and personal data remain stored locally in the communication device. This segmentation ensures that even if the cloud server is compromised, attackers cannot access user data stored locally in the device.
Solution Approach 2:
The patent introduces an intermediary authentication code as a mediator between the user and the location-based service server. Instead of directly transmitting or storing sensitive user data in the cloud, the system uses temporary authentication codes that are generated locally, transmitted to the server for verification, and then discarded. This intermediary mechanism enables cloud-based service access while preventing exposure of user data.
2Adaptability or versatility
If the system transmits and stores authentication codes in cloud servers, then service accessibility is improved, but data leakage risks increase due to system vulnerabilities
Solution Approach 1:
The system performs preliminary actions by generating authentication codes locally in the communication device before any data transmission occurs. The authentication code is created from local user data using a hash algorithm, and only this code (not the original data) is transmitted to the cloud server. This preliminary local processing prevents the risk of data leakage during transmission and storage in the cloud.
Solution Approach 2:
The patent transforms the authentication mechanism by changing the parameter being transmitted and stored. Instead of transmitting and storing original user data (high risk), the system transmits and stores transformed authentication codes derived from user data through cryptographic hashing. This parameter change maintains service accessibility while dramatically reducing information leakage risks.
3Adaptability or versatility
If the system uses traditional cloud-based authentication storage, then service flexibility is improved, but vulnerability to illegal access and data theft increases
Solution Approach 1:
The system segments the authentication process into local data processing and cloud verification. User data remains segmented and stored locally in the communication device, while only authentication codes are transmitted to the cloud server. This segmentation maintains service flexibility through cloud-based verification while reducing data theft risk by keeping sensitive data local.
Solution Approach 2:
Instead of storing original user data in the cloud, the system creates a copy in the form of an authentication code that can be used for verification purposes. This copy contains sufficient information for authentication but cannot be used to reconstruct the original user data, thus maintaining service flexibility while preventing data theft.
Data Source
AI summary
A location-based service system and method, which allows a location-based service server connected with a communication device and a cloud data server to perform registration authorization procedures and service authorization procedures using an international mobile subscriber identity of the communication device that cannot be easily modified or forged in the registration and service modes, so that a user may obtain a specific location-based service result via the communication device, and this distributed authentication technique reduces the risk of data theft while increasing the flexibility and convenience in obtaining services.


