Network Intermediary Detection Using Geolocation and Signal Timing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN detection methods are inadequate for accurately and efficiently identifying intermediary connections, particularly VPNs, due to their ability to obfuscate client locations, leading to security vulnerabilities in geolocation-based services.

Innovation Solution

A method that determines a client-server value based on transmission time of connection signals, using geolocation and expected values to establish if a connection is routed through an intermediary connection by comparing the client-server value to a threshold value, which is calculated using geolocation and propagation speed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing passive VPN detection methods using IP databases and behavioral analysis are used, then VPN detection capability is provided, but detection accuracy and robustness are insufficient for truly sensitive services

Engineering Contradiction:
ImproveVPN detection reliabilityVSAvoidVPN detection precision
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent replaces passive database lookup and behavioral analysis methods with an active physics-based measurement system. Instead of relying on IP databases and heuristic behavioral patterns, the system uses radio wave propagation time measurements to directly detect the physical presence of VPN infrastructure, substituting mechanical/info-based detection with electromagnetic field-based detection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces radio waves as an intermediary medium to detect VPN connections. By measuring the propagation time of radio waves between the user device, VPN server, and target server, the system can infer the existence of intermediary VPN infrastructure without directly observing VPN-specific traffic patterns or relying on IP address databases.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If geolocation-based security measures are implemented, then security protection is provided, but VPN users can circumvent these measures by spoofing their perceived location

Engineering Contradiction:
Improvegeolocation-based security reliabilityVSAvoidlocation spoofing vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary detection of VPN infrastructure by measuring radio wave propagation times before establishing trust in a client's geolocation claims. By pre-characterizing the physical path between the client and server, the system can later verify whether actual connection paths match expected paths, preventing location spoofing attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where propagation time measurements continuously verify whether a client's claimed geolocation matches the actual physical path of their connections. Any discrepancy between expected and measured propagation times triggers security responses, creating a closed-loop system that actively prevents location spoofing.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If transmission time measurement is used to detect VPN connections, then detection accuracy is improved, but additional measurement and calculation steps increase system complexity

Engineering Contradiction:
ImproveVPN detection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent makes the propagation time measurement system universal by having the same measurement infrastructure serve multiple purposes: detecting VPN connections, verifying geolocation claims, and characterizing network paths. This multi-functionality reduces the need for separate specialized detection systems, thereby limiting the increase in overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enhances the accuracy and speed of VPN detection, effectively identifying even private or novel VPNs, ensuring robust security measures without significant user experience impact.

Implementation Method 1

determining a client-server value based on a transmission time of a connection signal transmitted between the client device and the server

Methodology Applied
Scientific EffectSignal propagation time: Speed of Sound

Implementation Method 2

determining an expected value associated with the geolocation; and establishing that a connection between the client device and server is routed through the intermediary connection if the client-server value exceeds a threshold value, the threshold value being at least partly based on the expected value

Methodology Applied
Scientific EffectSignal propagation speed: Speed of Sound

Data Source

PatentUS20260052156A1Method for detecting intermediary connections in a network
Publication Date: 2026.02.19 FUJITSU LTD
  • US20260052156A1 patent drawing
  • US20260052156A1 patent drawing
  • US20260052156A1 patent drawing

AI summary

There is disclosed a computer implemented method for detecting an intermediary connection in a network comprising receiving, at a server, perceived indication information of a client device, obtaining a geolocation associated with the perceived indication information, determining a client-server value based on a transmission time of a connection signal transmitted between the client device and the server, determining an expected value associated with the geolocation, establishing that a connection between the client device and server is routed through the intermediary connection if the client-server value exceeds a threshold value, the threshold value being at least partly based on the expected value.