Mobile Device Authentication via Geographic Area Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Remote access to file servers via mobile devices poses a security risk due to the use of weak authentication methods, such as basic user IDs and passwords, leading to potential data breaches by unauthorized users.

Innovation Solution

Implementing an additional layer of security through an 'authorized area of authentication' (AAA) system, where access is granted only if the mobile device is verified to be within a designated geographic area, using a stationary computing device with an AAA generator, validator, and access controller, and a mobile device with a location identifier and connection controller, which dynamically identifies and submits its location for validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If basic user ID and password authentication is used for remote access, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into multiple independent verification stages: first verifying user credentials (user ID and password), then separately verifying the mobile device's geographic location within the authorized area, and finally granting access only if both verifications succeed. This segmentation allows each authentication layer to operate independently, maintaining ease of use while significantly improving security reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a spatial dimension to the traditional authentication process by introducing geographic location verification. Instead of relying solely on credential verification, the system now operates in two dimensions: credential space and geographic space. The mobile device must be physically located within the authorized geographic area to access the file server, creating a new security dimension that does not complicate the user experience.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If geographic location verification is added to authentication, then security reliability is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mobile device automatically performs location verification without requiring user intervention. The device's operating system and communication modules self-manage the geographic verification process by continuously monitoring GPS coordinates and communicating with the file server's authentication system. This self-service approach maintains security reliability while minimizing the perceived complexity for users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The file server is designed with multi-functionality, serving both as a data storage system and an authentication system. The server integrates credential verification and geographic location verification into a single unified authentication process, eliminating the need for separate authentication devices or systems. This universality reduces overall system complexity while maintaining high security reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10623958B2Authorization of authentication
Publication Date: 2020.04.14 FINJAN MOBILE LLC
  • US10623958B2 patent drawing
  • US10623958B2 patent drawing
  • US10623958B2 patent drawing

AI summary

A mobile device including a biometric or passcode scanner, scanning a biometric or passcode of a user of the mobile device, a biometric or passcode validator, validating the biometric data or passcode, a connection controller logging in to a secure network, and an access requestor, submitting to a server computer via a connection over the secure network, an access request for secure data, access to which is controlled by the server, and prompting the user to enter a biometric or to enter a passcode, wherein the biometric or passcode scanner scans the biometric or passcode entered by the user, the biometric or passcode validator validates the scanned biometric or passcode, and contingent upon the validating being affirmative, the access requestor submits to the server over the secure network, a request that the server generate an authentication for the mobile device to access the secure data.