Multi-Dimensional Student Access Control via Device and Location Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for online services, such as username/password systems, are inadequate in ensuring that the actual person is accessing the service, particularly in environments like online education, where identity verification is crucial to prevent fraudulent activities.

Innovation Solution

Implementing a multi-layered access control system that combines device/browser-based and location-based authentication mechanisms, allowing for additional verification steps if a user attempts to access an online activity from a different device or location, ensuring that only the registered student can participate and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If username/password authentication is used, then access control is implemented, but security against credential theft is insufficient

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidcredential theft vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent adds spatial and device dimensions to authentication by verifying the user's physical location via GPS coordinates and device/browser identity, transforming authentication from a single-dimensional credential check to a multi-dimensional verification process that includes location and device fingerprinting

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The authentication process is segmented into multiple independent verification layers: credential verification, device fingerprinting, and location verification. Each layer operates independently and contributes to the overall authentication decision, preventing single-point failure

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If access is permitted from multiple devices, then user convenience is improved, but identity verification integrity deteriorates

Engineering Contradiction:
Improveaccess convenienceVSAvoididentity verification integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary device fingerprinting and location verification before granting access. Device identifiers, browser characteristics, and GPS coordinates are captured and stored in advance, creating a baseline for future authentication decisions

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors device and location parameters during access sessions and provides feedback by comparing current session data against previously registered device and location profiles, automatically detecting deviations that indicate potential unauthorized access

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If location-based verification is implemented, then fraud prevention is improved, but system complexity increases

Engineering Contradiction:
Improvefraud preventionVSAvoidauthentication system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent introduces location data and device fingerprinting as intermediary verification elements between the user and the online service. These intermediaries provide objective, hard-to-fake evidence of user identity without requiring complex biometric scanning or hardware tokens

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9565183B2Location and device based student access control
Publication Date: 2017.02.07 UNIVERSITY OF PHOENIX INC
  • US9565183B2 patent drawing
  • US9565183B2 patent drawing
  • US9565183B2 patent drawing

AI summary

Techniques are described for controlling access to an online service by a one or more authentication mechanisms based on device, browser, or location, or a combination of the three. A method comprises receiving a request to access a service, receiving, in association with the request, a first access mechanism, receiving a first and second level of authentication associated with the user requesting the service, updating authenticated-mechanism data to indicate that the first access mechanism is an authenticated access mechanism for the particular user, receiving a second request to access the service, in response to receiving a second request, determining whether the second access mechanism is an authenticated access mechanism for the particular user, upon determining that the second access mechanism is not an authenticated mechanism, requesting a second level of authentication for the particular user, otherwise granting access.