Systems and methods for geolocation-based authentication and authorization

US9622077B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9622077-B2
Application numberUS-201514928553-A
CountryUS
Kind codeB2
Filing dateOct 30, 2015
Priority dateOct 29, 2013
Publication dateApr 11, 2017
Grant dateApr 11, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods are provided for controlling the authentication or authorization of a mobile device user for enabling access to the resources or functionality associated with an application or service executable at the user's mobile device. The user or user's mobile device may be automatically authenticated or authorized to access application or system resources at the device when the current geographic location of the user's mobile device is determined to be within a preauthorized zone, e.g., based on a predetermined geo-fence corresponding to the preauthorized zone. A security level or amount of authorization credentials required to authorize a user for data access may be varied according any of a plurality of security levels, when the current or last known geographic location of the user's mobile device is determined to be outside the preauthorized zone.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method for controlling authorization of mobile device users based on geographic location on a network, the method comprising: responsive to receiving a request for a first data access session from a first mobile device, requesting a current geographic location of the first mobile device; upon receiving a response including the requested current geographic location of the first mobile device, dynamically generating a predetermined authorization zone based on the current geographic location of the first mobile device; responsive to receiving a second request for a second data access session from a second mobile device of a user, requesting a second current geographic location of the second mobile device; upon receiving a response including the requested second current geographic location of the second mobile device, determining whether the second current geographic location of the second mobile device is within the predetermined authorization zone; and upon determining that the second current geographic location of the second mobile device is within the predetermined authorization zone, automatically authorizing the user of the second mobile device for data access in accordance with the second request. 2. The method of claim 1 , further comprising: when the current geographic location of the second mobile device is determined to not be within the predetermined authorization zone: determining a security level, from a plurality of security levels, for the user based on the second current geographic location of the second mobile device, wherein the security level for the user is based at least in part on a determination of whether the second current geographic location is within a predetermined restriction zone, the predetermined restriction zone corresponding to at least one of the plurality of security levels; when the second current geographic location of the second mobile device is determined to be within the predetermined restriction zone and also not within the predetermined authorization zone, prohibiting data access on the network for the user while the current geographic location remains in the predetermined restriction zone; when the current geographic location of the second mobile device is determined to be not within the predetermined restriction zone, requesting authorization information for selective authorization of the user based on the determined security level; and upon receiving the requested authorization information for selective authorization from the second mobile device, authorizing the user of the second mobile device for data access on the network in accordance with the second request based on the received authorization information. 3. The method of claim 1 , wherein automatically authorizing the user of the second mobile device for data access further comprises: receiving authorization information associated with the user and the second mobile device; determining a time of prior successful authorization, associated with the predetermined authorization zone, based on the received authorization information associated with the user and the second mobile device; determining an access time period corresponding to a predetermined duration of time after the time of prior successful authorization during which the predetermined authorization zone remains valid for the user for purposes of automatic authorization; and if the access time period has not yet expired, automatically authorizing the user of the second mobile device for data access while the second mobile device of the user is within the predetermined authorization zone. 4. The method of claim 1 , further comprising: responsive to receiving a third request for data access from the second mobile device following authorization of the user for data access in accordance with the second request, requesting an updated current geographic location for the second mobile device via the network; upon receiving the updated current geographic location of the second mobile device, determining whether the updated current geographic location of the second mobile device is within the predetermined authorization zone; when the updated current geographic location of the second mobile device is determined to not be within the predetermined authorization zone: revoking the user's authorization for data access; and requesting authorization information for selective authorization of the user for data access. 5. The method of claim 2 , wherein the authorization information requested for selective authorization of the user varies between each of the plurality of security levels. 6. The method of claim 5 , wherein the plurality of security levels requires a multi-phase authorization procedure when the current geographic location of the second mobile device is determined to not be within the predetermined restriction zone, and requesting authorization information for selective authorization of the user comprises: requesting authorization information for selective authorization of the user in accordance with the multi-phase authorization procedure involved in the security level. 7. The method of claim 1 , wherein automatically authorizing the user of the second mobile device for data access comprises: identifying the authorization information associated with the user of the second mobile device based on the device identifier; and automatically authorizing the user of the second mobile device for data access based on the identified authorization information. 8. The method of claim 7 , wherein automatically authorizing the user of the second mobile device further comprises: determining whether the predetermined authorization zone is currently valid for automatic authorization based on the authorization information identified for the user of the second mobile device; and automatically authorizing the user of the second mobile device for data access only when the predetermined authorization zone is determined to be currently valid for automatic authorization. 9. The method of claim 8 , wherein the authorization information includes authorization credentials associated with the user and a timestamp associated with a prior successful authorization of the user using the authorization credentials, and the determination of whether the predetermined authorization zone is still valid includes determining whether the prior successful authorization occurred within a predetermined time period based on the timestamp. 10. A computer-implemented method for controlling authorization for mobile device users based on geographic location on a network, the method comprising: responsive to receiving a request for a first data access session from a first mobile device, requesting a current geographic location of the first mobile device; upon receiving a response including the requested current geographic location of the first mobile device, dynamically generating a predetermined authorization zone based on the current geographic location of the first mobile device; responsive to receiving second input from a user requesting access to an application executable at a second mobile device, determining a second current geographic location of the second mobile device; determining whether the second current geographic location of the second mobile device is within the predetermined authorization zone; and upon determining that the second current geographic location of the second mobile device is within the predetermined authorization zone, automatically authorizing the user of the second mobile device for access to the application executable at the second mobile device in accordance with the input received from the user.

Assignees

Inventors

Classifications

  • Multi-level security, e.g. mandatory access control · CPC title

  • Time stamp · CPC title

  • Multiple levels of security · CPC title

  • Location-sensitive, e.g. geographical location, GPS · CPC title

  • Services related to particular areas, e.g. point of interest [POI] services, venue services or geofences · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9622077B2 cover?
Systems and methods are provided for controlling the authentication or authorization of a mobile device user for enabling access to the resources or functionality associated with an application or service executable at the user's mobile device. The user or user's mobile device may be automatically authenticated or authorized to access application or system resources at the device when the curre…
Who is the assignee on this patent?
Mapquest Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/31. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Apr 11 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).