Method and system for controlling access for a user equipment to a local device
US-11258804-B2 · Feb 22, 2022 · US
US11486709B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11486709-B2 |
| Application number | US-201916668746-A |
| Country | US |
| Kind code | B2 |
| Filing date | Oct 30, 2019 |
| Priority date | Oct 30, 2019 |
| Publication date | Nov 1, 2022 |
| Grant date | Nov 1, 2022 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Techniques are provided for ground distance calculations using sanitized location data. One method comprises a service provider obtaining: (i) a geographic zone identifier of multiple predefined geographic zones of a first location of a user, and (ii) a first distance between the first location of the user and multiple reference points that define boundaries of the predefined geographic zones; the service provider obtaining: (i) a geographic zone identifier of the multiple predefined geographic zones of a second location of the user, and (ii) a second distance between the first location of the user and the multiple reference points; and computing a ground distance between the first location and the second location by selecting a subset of the multiple reference points based at least in part on the relative geographic zones of the current and second locations. The user may: (i) estimate the first location and calculate the first distance; and/or (ii) compute the first and second distances.
Opening claim text (preview).
What is claimed is: 1. A method, comprising: obtaining, by at least one processing device of a service provider, (i) an identifier of a geographic zone, of a plurality of predefined geographic zones, that comprises a first location of a given remote user, and (ii) a first distance between the first location of the given remote user and multiple reference points that define boundaries of at least a plurality of the predefined geographic zones, wherein the at least one processing device of the service provider does not access the first location of the given remote user; obtaining, by the at least one processing device of the service provider, (i) an identifier of a geographic zone of the plurality of predefined geographic zones of a second location of the given remote user, and (ii) a second distance between the second location of the given remote user and the multiple reference points; computing a ground distance between the first location associated with the first distance and the second location associated with the second distance by selecting a subset of the multiple reference points based at least in part on a relation between the geographic zones of the first location and the second location; and initiating a granting of access of the given remote user to a protected resource based at least in part on the computed ground distance. 2. The method of claim 1 , wherein the multiple reference points are unique to the given remote user using one or more of an encoded user identifier and a salt value. 3. The method of claim 2 , wherein the multiple reference points comprise a central reference point and additional reference points that define the boundaries of the predefined geographic zones, wherein the additional reference points are defined relative to the central reference point. 4. The method of claim 1 , wherein at least one processing device associated with the given remote user estimates the first location of the given remote user and corresponding geographic zone identifier; and calculates the first distance between the first location of the given remote user and each of the multiple reference points. 5. The method of claim 1 , wherein a computation of the first distance and the second distance is performed by at least one processing device associated with the given remote user. 6. The method of claim 1 , wherein the service provider stores the second location of the given remote user only for a predefined time period. 7. The method of claim 1 , wherein the computing the ground distance comprises determining a spherical distance between the first location and the second location. 8. The method of claim 1 , wherein the computing the ground distance comprises determining an angle between a first line from the first location to one of the reference points and a second line from the second location to the one reference point. 9. The method of claim 1 , wherein the ground distance is used for one or more of a risk assessment of the given remote user, user behavior analytics of the given remote user and an identity assurance evaluation of the given remote user. 10. An apparatus comprising: at least one processing device comprising a processor coupled to a memory; the at least one processing device corresponding to a service provider and being configured to perform the following steps: obtaining, by at least one processing device of a service provider, (i) an identifier of a geographic zone, of a plurality of predefined geographic zones, that comprises a first location of a given remote user, and (ii) a first distance between the first location of the given remote user and multiple reference points that define boundaries of at least a plurality of the predefined geographic zones, wherein the at least one processing device of the service provider does not access the first location of the given remote user; obtaining, by the at least one processing device of the service provider, (i) an identifier of a geographic zone of the plurality of predefined geographic zones of a second location of the given remote user, and (ii) a second distance between the second location of the given remote user and the multiple reference points; computing a ground distance between the first location associated with the first distance and the second location associated with the second distance by selecting a subset of the multiple reference points based at least in part on a relation between the geographic zones of the first location and the second location; and initiating a granting of access of the given remote user to a protected resource based at least in part on the computed ground distance. 11. The apparatus of claim 10 , wherein the multiple reference points are unique to the given remote user using one or more of an encoded user identifier and a salt value. 12. The apparatus of claim 10 , wherein at least one second processing device associated with the given remote user estimates the first location of the given remote user and corresponding geographic zone identifier; and calculates the first distance between the first location of the given remote user and each of the multiple reference points. 13. The apparatus of claim 10 , wherein a computation of the first distance and the second distance is performed by at least one second processing device associated with the given remote user. 14. The apparatus of claim 10 , wherein the computing the ground distance comprises determining an angle between a first line from the first location to one of the reference points and a second line from the second location to the one reference point. 15. The apparatus of claim 10 , wherein the ground distance is used for one or more of a risk assessment of the given remote user, user behavior analytics of the given remote user and an identity assurance evaluation of the given remote user. 16. A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device of a service provider causes the at least one processing device of the service provider to perform the following steps: obtaining, by at least one processing device of a service provider, (i) an identifier of a geographic zone, of a plurality of predefined geographic zones, that comprises a first location of a given remote user, and (ii) a first distance between the first location of the given remote user and multiple reference points that define boundaries of at least a plurality of the predefined geographic zones, wherein the at least one processing device of the service provider does not access the first location of the given remote user; obtaining, by the at least one processing device of the service provider, (i) an identifier of a geographic zone of the plurality of predefined geographic zones of a second location of the given remote user, and (ii) a second distance between the second location of the given remote user and the multiple reference points; computing a ground distance between the first location associated with the first distance and the second location associated with the second distance by selecting a subset of the multiple reference points based at least in part on a relation between the geographic zones of the first location and the second location; and initiating a granting of access of the given remote user to a protected resource based at least in part on the computed ground distance. 17. The non-transitory processor-readable storage medium of claim 16 , wherein the multiple reference points are unique to the gi
using geofenced areas · CPC title
for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title
wherein the identity of one or more communicating identities is hidden (cryptographic mechanisms or cryptographic arrangements for anonymous credentials or for identity based cryptographic systems H04L9/00) · CPC title
wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals · CPC title
Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII] · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.