Login Validation via Third-Party Location Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional systems for differentiating malicious and legitimate login attempts from unusual locations often frustrate users and fail to prevent unauthorized access, as they rely on increasing login complexity or warnings rather than verifying the user's location.

Innovation Solution

A computer-implemented method that detects login attempts from atypical locations by retrieving location information from third-party Internet resources, such as social networking platforms and calendaring services, to verify if the attempt originates from the user's current location, thereby trusting legitimate login attempts and disabling unnecessary security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional systems increase the complexity of the login sequence to differentiate malicious and legitimate login attempts, then security is improved, but user convenience deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a third-party location service as an intermediary that independently verifies user location. This mediator provides objective location data that the authentication system uses to make trust decisions, eliminating the need for complex login sequences while maintaining security through location-based verification

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical approach of increasing login complexity (multiple authentication steps, security questions, etc.) with an information-based approach using location data from third-party services. This substitution allows the system to differentiate legitimate from malicious attempts through location verification rather than procedural complexity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of information

If traditional systems place warnings in the user's account about unusual login attempts, then user awareness is improved, but security effectiveness deteriorates

Engineering Contradiction:
Improveuser awarenessVSAvoidsecurity effectiveness
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent performs location verification in advance of the login attempt by continuously monitoring user location through third-party services. By knowing the user's current location before the login occurs, the system can proactively authenticate or reject attempts based on location consistency, rather than reactively warning users after the fact

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If the system trusts login attempts from atypical locations without verification, then user convenience is improved, but security deteriorates

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the system continuously monitors user location through third-party services and uses this information to dynamically adjust authentication decisions. The location data provides feedback that helps the system distinguish between legitimate users traveling to new locations and malicious attackers, enabling convenient authentication for legitimate users while blocking threats

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9529990B2Systems and methods for validating login attempts based on user location
Publication Date: 2016.12.27 GEN DIGITAL INC
  • US9529990B2 patent drawing
  • US9529990B2 patent drawing
  • US9529990B2 patent drawing

AI summary

A computer-implemented method for validating login attempts based on user location may include (1) detecting a login attempt by a user to log into a user account, where the login attempt originates from an atypical location, (2) determining that the atypical location is inconsistent with a pattern of past login locations for the user, (3) retrieving location information that indicates a current location of the user from at least one third-party Internet resource, (4) determining, based on the location information, that the atypical location of the login attempt matches the current location of the user, and (5) trusting that the login attempt legitimately originates from the user based at least in part on the atypical location matching the current location of the user. Various other methods, systems, and computer-readable media are also disclosed.