Location Token Service for Mobile Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current single sign-on (SSO) mechanisms on mobile devices are insecure due to the use of fixed identifiers like telephone number (TN) and Universal Unique Identifier (UUID), which can be easily spoofed, limiting the ability to use SSO across multiple applications and compromising security.

Innovation Solution

Implementing a location token service (LTS) that requires re-authentication based on the mobile device's location, using a combination of LTS client and server applications to validate the device's location and movement, thereby enhancing authentication security by restricting access based on pre-defined distance and time thresholds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If fixed identifiers (TN, UUID) are used for authentication, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the authentication parameters from static identifiers (TN, UUID) to dynamic parameters that include location information and time-based validation. The authentication token now incorporates device location coordinates and timestamp, making the authentication credentials variable and time-sensitive rather than fixed and permanent.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces a location token service (LTS) server as an intermediary between the mobile device and applications. This server validates authentication tokens by checking location consistency and time validity, adding an intermediate verification layer that enhances security without requiring direct complex validation in each application.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If location-based validation is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mobile device itself performs location determination using its built-in location services (GPS, cellular triangulation, WiFi positioning). The device generates its own authentication token with location data without requiring external location measurement equipment. This self-service approach adds security functionality while minimizing additional hardware or external system complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent leverages the mobile device's existing multi-functional capabilities, particularly the location services that are already present in modern smartphones for navigation and location-based applications. By repurposing this existing functionality for authentication purposes, the system gains security enhancements without requiring dedicated new components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If re-authentication based on location movement is enforced, then security is improved, but productivity deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial re-authentication based on location thresholds rather than requiring authentication at every application access. The system validates location movement against predefined distance thresholds and time intervals, requiring re-authentication only when significant location changes occur. This partial action approach maintains security for suspicious activities while allowing normal usage to proceed without frequent interruptions.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The authentication system performs periodic validation of location consistency based on time intervals and movement thresholds. Instead of continuous authentication checks, the system periodically verifies whether the device has moved beyond acceptable boundaries since last authentication. This periodic action reduces the frequency of user interruptions while maintaining security monitoring.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8437742B2Systems and methods for providing location-based application authentication using a location token service
Publication Date: 2013.05.07 SERVICENOW INC
  • US8437742B2 patent drawing
  • US8437742B2 patent drawing
  • US8437742B2 patent drawing

AI summary

Systems and methods for implementing a location token service (LTS) to enhance the security of mobile device identity tokens by using the location of the mobile device to augment the tokens. The LTS enforces re-authentication (login) of the mobile device to one or more applications if the mobile device moves beyond a threshold distance from the location of the last use of the token within a time period defined in a temporal threshold. The LTS increases authentication strength and drastically reduces the potential for spoofing or otherwise permitting unauthorized access to one or more applications on the mobile device.