IP Library Granted Patent US 10,237,261
Granted Patent B2
US 10,237,261 · App. 15/827,916 · Granted Mar 19, 2019

Systems and methods for location-based authentication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,237,261
App. No.
15/827,916
Granted
Mar 19, 2019
Kind
B2
Abstract

Systems and methods are disclosed for performing location-based authentication using location-aware devices. One method includes: receiving an access request comprising authentication credentials and a first location from a first location-aware device; receiving a second location from a second location-aware device associated with the authentication credentials; and upon determining that the first location and second location are within a pre-determined distance, authenticating the authentication credentials.

Claims (71)

1. A method, comprising:

receiving, by an authentication server, an access request comprising authentication credentials from a first location-aware user device, wherein the first location-aware user device is associated with a user account, and wherein the access request includes a first timestamp and a first location from the first location-aware user device;

receiving, by the authentication server, a second timestamp and a second location from a second location-aware user device, wherein the second location-aware user device is associated with the user account and the authentication credentials;

receiving, by the authentication server, a third timestamp and a third location from the second location-aware user device;

determining, by the authentication server, the speed and direction of movement of the second location-aware user device based on the second timestamp, second location, third timestamp, and third location;

determining, by the authentication server, a fourth location of the second location-aware user device based on the speed and direction of movement of the second location-aware user device; and

determining, by the authentication server, whether the first location of the first location-aware user device and the fourth location of the second location-aware user device are within a pre-determined threshold distance,

wherein upon determining, by the authentication server, that the first location of the first location-aware user device and the fourth location of the second location-aware user device are within a pre-determined threshold distance of each other, authenticating the authentication credentials.

2. The method of claim 1 , further comprising:

in response to determining that a number of successful authentications within a pre-determined threshold distance of the first location is above a pre-determined threshold, designating the first location as a trusted location.

3. The method of claim 1 , wherein authenticating the authentication credentials further comprises:

upon determining that the first location is not a trusted location, sending an acknowledgement request to the second location-aware user device.

4. The method of claim 3 , further comprising:

upon receiving a confirmation of the acknowledgement request from the second location-aware user device, determining whether the first location and second location are within a pre-determined threshold distance from each other; and

upon determining that the first location and second location are within a pre-determined threshold distance, authenticating the authentication credentials.

5. The method of claim 3 , further comprising:

in response to receiving a denial of the acknowledgment request from the second location-aware user device, denying the access request.

6. The method of claim 3 , further comprising:

in response to receiving a denial of the acknowledgment request from the second location-aware user device, disallowing further access requests from the first location-aware user device.

7. The method of claim 1 , further comprising:

wherein upon determining that the first location and second location are not within a pre-determined threshold distance, receiving, by the authentication server, a fifth timestamp and a fifth location from the first location-aware user device;

determining, by the authentication server, the speed and direction of movement of the first location-aware user device based on the first timestamp, first location, fifth timestamp, and fifth location;

determining, by the authentication server, a sixth location of the first location-aware user device based on the speed and direction of movement of the first location-aware user device; and

determining, by the authentication server, whether the sixth location of the first location-aware user device and the second location of the second location-aware user device are within a pre-determined threshold distance,

wherein upon determining, by the authentication server, that the sixth location of the first location-aware user device and the second location of the second location-aware user device are within a pre-determined threshold distance of each other, authenticating the authentication credentials.

8. A system for performing location-based authentication, the system including:

a storage device storing instructions for managing location-based authentication; and

a processor configured to execute the instructions to perform a method including:

receiving, by an authentication server, an access request comprising authentication credentials from a first location-aware user device, wherein the first location-aware user device is associated with a user account, and wherein the access request includes a first timestamp and a first location from the first location-aware user device;

receiving, by the authentication server, a second timestamp and a second location from a second location-aware user device, wherein the second location-aware user device is associated with the user account and the authentication credentials;

receiving, by the authentication server, a third timestamp and a third location from the second location-aware user device;

determining, by the authentication server, the speed and direction of movement of the second location-aware user device based on the second timestamp, second location, third timestamp, and third location;

determining, by the authentication server, a fourth location of the second location-aware user device based on the speed and direction of movement of the second location-aware user device; and

determining, by the authentication server, whether the first location of the first location-aware user device and the fourth location of the second location-aware user device are within a pre-determined threshold distance,

wherein upon determining, by the authentication server, that the first location of the first location-aware user device and the fourth location of the second location-aware user device are within a pre-determined threshold distance of each other, authenticating the authentication credentials.

9. The system of claim 8 , further comprising:

in response to determining that a number of successful authentications within a pre-determined threshold distance of the first location is above a pre-determined threshold, designating the first location as a trusted location.

10. The system of claim 8 , wherein authenticating the authentication credential comprises, upon determining that the first location is not a trusted location, sending an acknowledgement request to the second location-aware user device.

11. The system of claim 10 , further comprising:

upon receiving a confirmation of the acknowledgement request from the second location-aware user device, determining whether the first location and second location are within a pre-determined threshold distance from each other; and

upon determining that the first location and second location are within a pre-determined threshold distance, authenticating the authentication credentials.

12. The system of claim 10 , further comprising:

in response to receiving a denial of the acknowledgment request from the second location-aware user device, denying the access request.

13. The system of claim 10 , further comprising:

in response to receiving a denial of the acknowledgment request from the second location-aware user device, disallowing further access requests from the first location-aware user device.

14. The system of claim 8 , further comprising:

wherein upon determining that the first location and second location are not within a pre-determined threshold distance, receiving, by the authentication server, a fifth timestamp and a fifth location from the first location-aware user device;

determining, by the authentication server, the speed and direction of movement of the first location-aware user device based on the first timestamp, first location, fifth timestamp, and fifth location;

determining, by the authentication server, a sixth location of the first location-aware user device based on the speed and direction of movement of the first location-aware user device; and

determining, by the authentication server, whether the sixth location of the first location-aware user device and the second location of the second location-aware user device are within a pre-determined threshold distance,

wherein upon determining, by the authentication server, that the sixth location of the first location-aware user device and the second location of the second location-aware user device are within a pre-determined threshold distance of each other, authenticating the authentication credentials.

15. A non-transitory computer-readable medium that, when executed by a computer system, cause the computer system to perform a method for performing location-based authentication, the method including:

receiving, by an authentication server, an access request comprising authentication credentials from a first location-aware user device, wherein the first location-aware user device is associated with a user account, and wherein the access request includes a first timestamp and a first location from the first location-aware user device;

receiving, by the authentication server, a second timestamp and a second location from a second location-aware user device, wherein the second location-aware user device is associated with the user account and the authentication credentials;

receiving, by the authentication server, a third timestamp and a third location from the second location-aware user device;

determining, by the authentication server, the speed and direction of movement of the second location-aware user device based on the second timestamp, second location, third timestamp, and third location;

determining, by the authentication server, a fourth location of the second location-aware user device based on the speed and direction of movement of the second location-aware user device; and

determining, by the authentication server, whether the first location of the first location-aware user device and the fourth location of the second location-aware user device are within a pre-determined threshold distance,

wherein upon determining, by the authentication server, that the first location of the first location-aware user device and the fourth location of the second location-aware user device are within a pre-determined threshold distance of each other, authenticating the authentication credentials.

16. The non-transitory computer-readable medium of claim 15 , further comprising:

in response to determining that a number of successful authentications within a pre-determined threshold distance of the first location is above a pre-determined threshold, designating the first location as a trusted location.

17. The non-transitory computer-readable medium of claim 15 , wherein authenticating the authentication credentials comprises, upon determining that the first location is not a trusted location, sending an acknowledgement request to the second location-aware user device.

18. The non-transitory computer-readable medium of claim 17 , further comprising:

upon receiving a confirmation of the acknowledgement request from the second location-aware user device, determining whether the first location and second location are within a pre-determined threshold distance from each other; and

upon determining that the first location and second location are within a pre-determined threshold distance, authenticating the authentication credentials.

19. The non-transitory computer-readable medium of claim 15 , further comprising:

wherein upon determining that the first location and second location are not within a pre-determined threshold distance, receiving, by the authentication server, a fifth timestamp and a fifth location from the first location-aware user device;

determining, by the authentication server, the speed and direction of movement of the first location-aware user device based on the first timestamp, first location, fifth timestamp, and fifth location;

determining, by the authentication server, a sixth location of the first location-aware user device based on the speed and direction of movement of the first location-aware user device; and

determining, by the authentication server, whether the sixth location of the first location-aware user device and the second location of the second location-aware user device are within a pre-determined threshold distance,

wherein upon determining, by the authentication server, that the sixth location of the first location-aware user device and the second location of the second location-aware user device are within a pre-determined threshold distance of each other, authenticating the authentication credentials.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2021
From: VERIZON MEDIA INC.
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 057453/0431 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2020
From: OATH INC.
To: VERIZON MEDIA INC.
Reel/Frame 054258/0635 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2017
From: RAOUNAK, EL-AMINE M.
To: AOL INC.
Reel/Frame 044274/0242 →
CHANGE OF NAME Recorded Dec 1, 2017
From: AOL INC.
To: OATH INC.
Reel/Frame 044635/0859 →