IP Library Granted Patent US 11,128,638
Granted Patent B2
US 11,128,638 · App. 16/261,941 · Granted Sep 21, 2021

Location assurance using location indicators modified by shared secrets

Inventors: Brian C. Mullins (Burlington, MA); Zulfikar A. Ramzan (Saratoga, CA)
Assignee: RSA Security LLC
H04L63/107H04L9/3271
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,128,638
App. No.
16/261,941
Granted
Sep 21, 2021
Kind
B2
Abstract

Techniques are provided for user authentication using a location assurance based on a location indicator modified by a shared secret. One method comprises obtaining a shared secret; initiating a challenge in connection with an authentication request by a client from a given location to access a protected resource, wherein the challenge comprises a location indicator selected for the given location; processing a response submitted by the client in response to the challenge, wherein the response comprises the location indicator for the given location modified by the client with the shared secret, and wherein the processing comprises evaluating the response submitted by the client relative to the location indicator selected by the authentication server; and resolving the authentication request based on the evaluating. The client modification of the selected location indicator with the shared secret comprises, for example, decrypting, filtering and/or altering the location indicator based on the shared secret.

Claims (39)

1. A method, comprising:

negotiating a shared secret based on a user biometric during an enrollment process;

after negotiating the shared secret, initiating a challenge to a client in connection with an authentication request comprising specified GPS coordinates from the client from a given location to access a protected resource, wherein the challenge comprises a location indicator selected for the given location of the client comprising an encrypted version of an augmented reality image selected by an authentication server for the given location and dynamically generated based, at least in part, on the specified GPS coordinates of the client at the time of the challenge;

processing, using at least one processing device, a response submitted by the client in response to the challenge, wherein:

the response matches a decrypted version of the location indicator comprising the augmented reality image for the given location, wherein the decrypted image is decrypted by the client with the shared secret and the response is captured after receiving the challenge at or near the specified GPS coordinates; and

the processing comprises evaluating the response submitted by the client relative to the location indicator selected by the authentication server; and

resolving, using the at least one processing device, the authentication request based on the evaluating.

2. The method of claim 1 , wherein the location indicator comprises an encrypted version of one of a plurality of virtual object images selected by the authentication server for the given location.

3. The method of claim 1 , wherein the client modifies the augmented reality image using the shared secret, and wherein the response comprises the augmented reality image modified using the shared secret.

4. The method of claim 1 , wherein the modification by the client of the location indicator for the given location with the shared secret comprises one or more of decrypting the encrypted version of the location indicator with the shared secret, filtering the location indicator with the shared secret, and altering the location indicator with the shared secret.

5. The method of claim 1 , wherein the evaluating comprises determining if the client modified the location indicator for the given location with the shared secret in an expected manner based on the shared secret stored by the authentication server.

6. The method of claim 1 , wherein the location indicator is derived from one or more of a set of global positioning system coordinates of the client at the given location, an Internet Protocol address associated with a device of the client at the given location, and an identifier of a predefined location of the client.

7. The method of claim 1 , wherein the client queries the authentication server, at a time of the authentication request by the client to access the protected resource, with the given location of the client to obtain the location indicator from the authentication server.

8. The method of claim 1 , wherein a confidence level of the evaluating required for the client to access the protected resource is configurable based on security requirements of a given protected resource.

9. The method of claim 1 , wherein the shared secret is negotiated between the client and the authentication server using one or more of a biometric assurance, a device assurance and a client-specific cryptographic key assurance.

10. A system, comprising:

a memory; and

at least one processing device, coupled to the memory, operative to implement the following steps:

negotiating a shared secret based on a user biometric during an enrollment process;

after negotiating the shared secret, initiating a challenge to a client in connection with an authentication request comprising specified GPS coordinates from the client from a given location to access a protected resource, wherein the challenge comprises a location indicator selected for the given location of the client comprising an encrypted version of an augmented reality image selected by an authentication server for the given location and dynamically generated based, at least in part, on the specified GPS coordinates of the client at the time of the challenge;

processing a response submitted by the client in response to the challenge, wherein:

the response matches a decrypted version of the location indicator comprising the augmented reality image for the given location, wherein the decrypted image is decrypted by the client with the shared secret and the response is captured after receiving the challenge at or near the specified GPS coordinates; and

the processing comprises evaluating the response submitted by the client relative to the location indicator selected by the authentication server; and

resolving the authentication request based on the evaluating.

11. The system of claim 10 , wherein the location indicator comprises an encrypted version of one of a plurality of virtual object images selected by the authentication server for the given location.

12. The system of claim 10 , wherein the client modifies the augmented reality image using the shared secret, and wherein the response comprises the augmented reality image modified using the shared secret.

13. The system of claim 10 , wherein the modification by the client of the location indicator for the given location with the shared secret comprises one or more of decrypting the encrypted version of the location indicator with the shared secret, filtering the location indicator with the shared secret, and altering the location indicator with the shared secret.

14. The system of claim 10 , wherein the modification by the client of the location indicator for the given location with the shared secret comprises one or more of decrypting the encrypted version of the location indicator with the shared secret, filtering the location indicator with the shared secret, and altering the location indicator with the shared secret.

15. A computer program product, comprising a non-transitory machine-readable storage medium having encoded therein executable code of one or more software programs, wherein the one or more software programs when executed by at least one processing device perform the following steps:

negotiating a shared secret based on a user biometric during an enrollment process;

after negotiating the shared secret, initiating a challenge to a client in connection with an authentication request comprising specified GPS coordinates from the client from a given location to access a protected resource, wherein the challenge comprises a location indicator selected for the given location of the client comprising an encrypted version of an augmented reality image selected by an authentication server for the given location and dynamically generated based, at least in part, on the specified GPS coordinates of the client at the time of the challenge;

processing a response submitted by the client in response to the challenge, wherein:

the response matches a decrypted version of the location indicator comprising the virtual object augmented reality image for the given location, wherein the decrypted image is decrypted by the client with the shared secret and the response is captured after receiving the challenge at or near the specified GPS coordinates; and

the processing comprises evaluating the response submitted by the client relative to the location indicator selected by the authentication server; and

resolving the authentication request based on the evaluating.

16. The computer program product of claim 15 , wherein the location indicator comprises an encrypted version of one of a plurality of virtual object images selected by the authentication server for the given location.

17. The computer program product of claim 15 , wherein the client modifies the augmented reality image using the shared secret, and wherein the response comprises the augmented reality image modified using the shared secret.

18. The computer program product of claim 15 , wherein the modification by the client of the location indicator for the given location with the shared secret comprises one or more of decrypting the encrypted version of the location indicator with the shared secret, filtering the location indicator with the shared secret, and altering the location indicator with the shared secret.

19. The computer program product of claim 15 , wherein the evaluating comprises determining if the client modified the location indicator for the given location with the shared secret in an expected manner based on the shared secret stored by the authentication server.

Assignments (16)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 70587/0885 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075031/0394 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 21, 2025
From: RSA SECURITY LLC; RSA SECURITY USA LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 070587/0885 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2019
From: MULLINS, BRIAN C.; RAMZAN, ZULFIKAR A
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 049422/0963 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →