IP Library › Granted Patent US 12,483,425
Granted Patent B2
US 12,483,425 · App. 18/214,581 · Granted Nov 25, 2025

Client-server response time based computer system geolocation

Inventors: Emanuele Vercalli (Cologno Monzese, IT); Federico Accetta (Milan, IT); Massimo Caprinali (Merate, IT); Roberto Ragusa (Rome, IT)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L9/3263H04L9/3271H04L9/3297H04L67/52
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,483,425
App. No.
18/214,581
Granted
Nov 25, 2025
Kind
B2
Abstract

An embodiment sends, at a first time, from a boundary server to a client system in response to a challenge request, a challenge specifying a computational problem to be solved by the client system, the boundary server specified in a challenge list sent to the client system. An embodiment receives, at a second time, at the boundary server, a challenge response from the client system, the challenge response comprising a solution to the computational problem. An embodiment generates, at the boundary server, a certificate encoding an elapsed time between the first time and the second time, the certificate usable by the client system to prove a location of the client system. An embodiment sends, from the boundary server to the client system, the certificate.

Claims (45)

1 . A computer-implemented method comprising:

sending, at a first time, from a boundary server to a client system, in response to a challenge request, a challenge specifying a computational problem to be solved by the client system, the boundary server specified in a challenge list sent to the client system and selected based on an internet protocol (IP) address of the client system;

receiving, at a second time, at the boundary server, a challenge response from the client system, the challenge response comprising a solution to the computational problem;

generating, at the boundary server, a certificate encoding an elapsed time between the first time and the second time, the certificate usable by the client system to prove a location of the client system; and

sending, from the boundary server to the client system, the certificate.

2 . The computer-implemented method of claim 1 , wherein the challenge list comprises a plurality of boundary servers including the boundary server, each of the plurality of boundary servers having a known physical location.

3 . The computer-implemented method of claim 2 , wherein each of the plurality of boundary servers was selected for inclusion in the challenge list using the known physical location of each of the plurality of boundary servers.

4 . The computer-implemented method of claim 1 , wherein the elapsed time encoded in the certificate, a second elapsed time encoded in a second certificate generated by a second boundary server, and a third elapsed time encoded in a third certificate generated by a third boundary server are usable in performing trilateration of the location of the client system.

5 . The computer-implemented method of claim 1 , further comprising:

cryptographically signing, at the boundary server, prior to the sending, the certificate, the signing performed using a key unknown to the client system.

6 . The computer-implemented method of claim 1 , further comprising:

sending, at a third time, from the boundary server to the client system in response to a second challenge request, a second challenge specifying a string to be echoed by the client system;

receiving, at a fourth time, at the boundary server, a second challenge response from the client system, the second challenge response comprising the string; and

generating, at the boundary server, a fourth certificate encoding the lesser of the elapsed time and a second elapsed time, the second elapsed time comprising a difference between the fourth time and the third time, the fourth certificate usable by the client system to prove the location of the client system.

7 . A computer program product comprising one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, wherein the stored program instructions are stored in a computer readable storage device in a data processing system, wherein the stored program instructions are transferred over a network from a remote data processing system, and wherein stored program instructions are downloaded in response to a request over the network to the remote data processing system for use in the computer readable storage device associated with the remote data processing system, the stored program instructions executable by a processor to cause the processor to perform operations comprising:

sending, at a first time, from a boundary server to a client system in response to a challenge request, a challenge specifying a computational problem to be solved by the client system, the boundary server specified in a challenge list sent to the client system;

receiving, at a second time, at the boundary server, a challenge response from the client system, the challenge response comprising a solution to the computational problem;

generating, at the boundary server, a certificate encoding an elapsed time between the first time and the second time, the certificate usable by the client system to prove a location of the client system; and

sending, from the boundary server to the client system, the certificate;

wherein the stored program instructions further comprise:

program instructions to meter use of the program instructions associated with the request; and

program instructions to generate an invoice based on the metered use.

8 . The computer program product of claim 7 , wherein the challenge list comprises a plurality of boundary servers including the boundary server, each of the plurality of boundary servers having a known physical location.

9 . The computer program product of claim 8 , wherein each of the plurality of boundary servers was selected for inclusion in the challenge list using the known physical location of each of the plurality of boundary servers.

10 . The computer program product of claim 7 , wherein the elapsed time encoded in the certificate, a second elapsed time encoded in a second certificate generated by a second boundary server, and a third elapsed time encoded in a third certificate generated by a third boundary server are usable in performing trilateration of the location of the client system.

11 . The computer program product of claim 7 , further comprising:

cryptographically signing, at the boundary server, prior to the sending, the certificate, the signing performed using a key unknown to the client system.

12 . The computer program product of claim 7 , further comprising:

sending, at a third time, from the boundary server to the client system in response to a second challenge request, a second challenge specifying a string to be echoed by the client system;

receiving, at a fourth time, at the boundary server, a second challenge response from the client system, the second challenge response comprising the string; and

generating, at the boundary server, a fourth certificate encoding the lesser of the elapsed time and a second elapsed time, the second elapsed time comprising a difference between the fourth time and the third time, the fourth certificate usable by the client system to prove the location of the client system.

13 . A computer system comprising a processor and one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instructions executable by the processor to cause the processor to perform operations comprising:

sending, at a first time, from a boundary server to a client system in response to a challenge request, a challenge specifying a computational problem to be solved by the client system, the boundary server specified in a challenge list sent to the client system and selected based on an internet protocol (IP) address of the client system;

receiving, at a second time, at the boundary server, a challenge response from the client system, the challenge response comprising a solution to the computational problem;

generating, at the boundary server, a certificate encoding an elapsed time between the first time and the second time, the certificate usable by the client system to prove a location of the client system; and

sending, from the boundary server to the client system, the certificate.

14 . The computer system of claim 13 , wherein the challenge list comprises a plurality of boundary servers including the boundary server, each of the plurality of boundary servers having a known physical location.

15 . The computer system of claim 14 , wherein each of the plurality of boundary servers was selected for inclusion in the challenge list using the known physical location of each of the plurality of boundary servers.

16 . The computer system of claim 13 , wherein the elapsed time encoded in the certificate, a second elapsed time encoded in a second certificate generated by a second boundary server, and a third elapsed time encoded in a third certificate generated by a third boundary server are usable in performing trilateration of the location of the client system.

17 . The computer system of claim 13 , further comprising:

cryptographically signing, at the boundary server, prior to the sending, the certificate, the signing performed using a key unknown to the client system.

18 . The computer system of claim 13 , further comprising:

sending, at a third time, from the boundary server to the client system in response to a second challenge request, a second challenge specifying a string to be echoed by the client system;

receiving, at a fourth time, at the boundary server, a second challenge response from the client system, the second challenge response comprising the string; and

generating, at the boundary server, a fourth certificate encoding the lesser of the elapsed time and a second elapsed time, the second elapsed time comprising a difference between the fourth time and the third time, the fourth certificate usable by the client system to prove the location of the client system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2023
From: VERCALLI, EMANUELE; ACCETTA, FEDERICO; CAPRINALI, MASSIMO; RAGUSA, ROBERTO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 064069/0901 →
Continuity (1)
Related Publication 20250007730A1 · Jan 2, 2025
References Cited (15)
US 5970414A · Bi · 1999 [cited by examiner]
US 9069052B2 · Hsu et al. · 2015 [cited by applicant]
US 10341335B2 · Thompson · 2019 [cited by applicant]
US 10439820B2 · Egner et al. · 2019 [cited by applicant]
US 11395092B2 · Beauford · 2022 [cited by applicant]
US 20160323261A1 · Thompson · 2016 [cited by applicant]
US 20170289137A1 · Pendarakis · 2017 [cited by examiner]
US 20200403808A1 · Smith · 2020 [cited by examiner]
JP 2003319443A · 2003 [cited by applicant]
WO WO2017108294A1 · 2017 [cited by examiner]
WO 2025002936A1 · 2025 [cited by applicant]
International Searching Authority, PCT/EP2024/067059, Aug. 14, 2024. [cited by applicant]
Zhang et al., Location-based Authentication and Authorization Using Smart Phones, 2012 IEEE 11th International Conference on Trust, Security and Privacy in Computing and Communications, Jun. 2012. [cited by applicant]
Hillmann et al., Modelling of IP Geolocation by use of Latency Measurements, Apr. 16, 2020. [cited by applicant]
Maram et al., GoAT: File Geolocation via Anchor Timestamping, May 31, 2022. [cited by applicant]