Power Line Communications for Location-Bound Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems, particularly those using the Internet, are vulnerable to subversion and lack robust mechanisms for ensuring the authenticity and location-based security of communications, especially in scenarios involving remote access and emergency situations, due to reliance on single communication paths and inadequate use of existing electrical grids as side channels.
Innovation Solution
The system leverages the electrical grid as a secure side channel by using power line communications between a utility substation and an end-user's electric meter to provide a physically distinct, bidirectional authentication path, enhancing security through location-binding and entity-tracking mechanisms, and integrating with existing authentication systems to bolster multifactor authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the Internet is used as the primary communication channel for authentication and data transmission, then ease of operation and widespread accessibility are improved, but security and reliability deteriorate due to vulnerability to subversion and lack of location-based verification
Solution Approach 1:
The patent introduces the electrical grid as an intermediary communication channel between the user and the authentication server. This mediator provides a physically distinct path from the Internet, enabling location verification through power line communications while maintaining ease of use through automated authentication processes.
Solution Approach 2:
The patent adds a new dimension to authentication by incorporating spatial location verification through the electrical grid infrastructure. Instead of relying solely on network-based authentication, the system verifies the physical location of users by detecting their connection to specific electrical grid nodes, creating a geographic dimension to security verification.
2Device complexity
If a single communication path (Internet) is used for authentication, then device complexity is reduced, but security and resistance to attacks deteriorate
Solution Approach 1:
The patent segments the authentication system into two independent communication channels: the Internet path for data transmission and the electrical grid path for location verification. This segmentation allows each channel to perform its specialized function while collectively providing enhanced security without significantly increasing overall system complexity.
Solution Approach 2:
The patent changes the communication parameter from purely network-based to include physical infrastructure-based verification. By utilizing the electrical grid's physical infrastructure for location verification, the system introduces a new parameter (physical location) that enhances security without requiring complex additional hardware at the user end.
3Ease of operation
If traditional wireless or GPS signals are used for location verification, then ease of operation is improved, but reliability deteriorates when these signals are compromised or unavailable
Solution Approach 1:
The patent leverages the electrical grid's existing infrastructure to provide location verification services without requiring additional user actions or external signal sources. The system uses the power lines already present in the environment to automatically determine and verify user location, making the service self-sufficient and independent of external signal availability.
Solution Approach 2:
The patent applies the electrical grid infrastructure to a new function beyond power delivery: location verification. By enabling the power line network to serve dual purposes (power distribution and communication/location verification), the system achieves reliable location services using existing universal infrastructure without requiring specialized GPS or wireless signal systems.
4Reliability
If the electrical grid is used as a side channel for authentication, then security and location-based verification are improved, but device complexity and implementation difficulty increase
Solution Approach 1:
The patent introduces the electrical grid as an intermediary communication channel between the user and the authentication server. This mediator provides a physically distinct path from the Internet, enabling location verification through power line communications while maintaining ease of use through automated authentication processes.
Solution Approach 2:
The patent replaces complex wireless communication hardware and GPS receivers with the existing electrical grid infrastructure. By substituting the need for specialized location verification devices with the ubiquitous power line network, the system reduces hardware complexity while enhancing security capabilities.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach provides a robust, location-based authentication mechanism that is resistant to malicious attacks, ensures fine-grained location tracking of devices, and offers a reliable, cost-effective solution for securing communications and preventing unauthorized access, even in scenarios where traditional wireless or GPS signals are compromised.
Implementation Method 1
using power line communications between a utility substation and an end-user's electric meter
Data Source
AI summary
A secure communications and location authorization system using a power line or a potion thereof as a side-channel that mitigates man-in-the-middle attacks on communications networks and devices connected to those networks. The system includes a power grid server associated with a substation, or curb-side distribution structure such as a transformer, an electric meter associated with a structure having electric service and able to communicate with the power grid server, a human authorization detector input device connected to the electric meter and the power grid server. The human authorization detector is able to receive an input from a user physically located at the structure and capable of communicating with the power grid server via the electric meter. The user's physical input into the device causing a request to be sent to the power grid server that then generates a location certificate for the user. Without the location certificate, access to the communications network and devices connected to those networks can be denied.


