Papers
Topics
Authors
Recent
Search
2000 character limit reached

Proof-of-Location (PoL)

Updated 9 July 2026
  • Proof-of-Location (PoL) is a protocol that enables a prover to generate cryptographically bound location claims, asserting presence at a specific region and time interval.
  • Systems employ diverse architectures—from blockchain-based and infrastructure-assisted to encounter-based—to ensure authenticity, integrity, and privacy in location proofs.
  • Robust threat mitigation is achieved through mechanisms like distance bounding, replay protection, and consensus on event ordering to counter spoofing and collusion.

Proof-of-Location (PoL) denotes a class of protocols that transform a location claim into a verifiable proof that binds an entity, a place or region, and a time interval under explicit security, trust, and privacy assumptions. Across the literature, PoL appears as a cryptographic statement that a prover was present “at region RR at time tt,” as a certificate that a device’s true location ℓd(t)\ell_d(t) lay within a region S⊂R2S\subset\mathbb{R}^2, as an evidence object carrying quorum attestations over a block interval, and as a proof object π\pi checked by a verifier through a Setup\text{Setup}, Prove\text{Prove}, Verify\text{Verify} interface (Brito et al., 19 Aug 2025, Viti et al., 2024, Brito et al., 29 Mar 2026, Brito et al., 15 Apr 2026). The common objective is to replace self-asserted coordinates with evidence-bearing claims that support authenticity, integrity, freshness, and, in many systems, privacy preservation.

1. Definitions and conceptual scope

The most compact formulation in the surveyed literature defines PoL as a protocol enabling a prover P\mathcal{P} to generate a cryptographically bound statement that “P\mathcal{P} was at region tt0 at time tt1” such that a verifier tt2, possibly assisted by witnesses tt3, can check the claim with overwhelming assurance (Brito et al., 19 Aug 2025). A more abstract formulation models PoL as a scheme tt4 with procedures tt5, tt6, and tt7, where tt8 may be a designated region or point and tt9 is a time window (Brito et al., 15 Apr 2026).

The literature distinguishes several semantics for the object being proved. In “precise” formulations, the claim concerns an exact point. In ProLoc, the claim is deliberately relaxed to a “region proof,” asserting that a device’s true location satisfies ℓd(t)\ell_d(t)0, including the common special case ℓd(t)\ell_d(t)1 for a circular region ℓd(t)\ell_d(t)2 (Viti et al., 2024). In secure location provenance, the object of interest is not only a single proof of presence but a chronological history of location proofs that can later be selectively disclosed to an auditor (Hasan et al., 2011). In witnessing-zone architectures, the PoL is an evidence object

ℓd(t)\ell_d(t)3

which binds a claim ℓd(t)\ell_d(t)4, a finalized block hash ℓd(t)\ell_d(t)5, witness commitments ℓd(t)\ell_d(t)6, an aggregated quorum signature ℓd(t)\ell_d(t)7, a policy version ℓd(t)\ell_d(t)8, and a zone identifier ℓd(t)\ell_d(t)9 (Brito et al., 29 Mar 2026).

This diversity indicates that PoL is not a single protocol family but a design space. The taxonomy literature organizes that space along four domains: cryptographic guarantees, spatio-temporal synchronization, trust and witness models, and interaction and overhead (Brito et al., 19 Aug 2025). A plausible implication is that disagreements in the literature about what counts as a “proof of location” often arise from different assumptions about precision, verifiability horizon, and disclosure requirements rather than from incompatible security goals.

2. Threat models and security objectives

PoL systems are typically specified against adversaries that can falsify position, replay stale evidence, collude with witnesses, or exploit protocol asymmetries. In IoT sensor networks, the adversary may compromise a subset of nodes or impersonate identities in Sybil attacks, inject, replay, or modify messages, and flood the network with spurious messages under valid or spoofed IDs (Tschirner et al., 2023). In location-proof services built from user devices, the adversary may control a limited number S⊂R2S\subset\mathbb{R}^20 of physical devices, create unlimited virtual devices, fabricate entire histories, and mount retroactive attacks in which the target region S⊂R2S\subset\mathbb{R}^21 and time S⊂R2S\subset\mathbb{R}^22 are unknown in advance (Viti et al., 2024). In UAV settings, the explicit threat model includes GNSS spoofing, relay attack (“Wormhole”), and identity spoofing (Fu et al., 2023). In cyber-physical witnessing zones, the catalog expands to distance fraud, scene spoofing, sensor spoofing, and collusion compromising at least S⊂R2S\subset\mathbb{R}^23 witnesses (Brito et al., 29 Mar 2026).

Despite these differences, the core security objectives are stable. The taxonomy paper states completeness and soundness in the standard interactive-proof sense, then refines soundness into proximity soundness and temporal soundness, and adds authenticity, integrity, and, in distributed settings, consensus on event ordering (Brito et al., 19 Aug 2025). ProLoc states the same goals operationally as soundness (“no false positives”) and completeness (“no false negatives”), with soundness requiring that an adversarial prover outside S⊂R2S\subset\mathbb{R}^24 cannot pass S⊂R2S\subset\mathbb{R}^25 except through colluding witnesses with plausible trajectories and encounter traces (Viti et al., 2024). In IoT zk-PoL, soundness is phrased as extractability under the Knowledge-of-Exponent Assumption, with zero-knowledge requiring that the proof reveals nothing beyond the exposed public parameters (Wu et al., 2024).

A broader provenance perspective frames these security properties through four integrity axes: claim integrity, evidence integrity, control integrity, and governance integrity. On that view, recurrent failure modes include fabricated locality, replay and re-contextualisation, proxying and delegated control, origin laundering and documentary substitution, signal manipulation and interference, record opacity and asymmetric access, and jurisdiction ambiguity and inference overreach (Brito et al., 15 Apr 2026). This suggests that PoL is increasingly treated not merely as a localization primitive but as part of a larger evidentiary and governance stack.

3. Protocol architectures and witness models

PoL protocols differ sharply in who witnesses location and how attestation is produced.

Family Core mechanism Representative papers
Witness-endorsed and provenance-oriented Authority-issued proof plus third-party endorsement and chronology protection (Hasan et al., 2011)
Blockchain-backed decentralized PoL Peer witnesses, signed proofs, ledger recording, consensus (Brambilla et al., 2016)
Infrastructure-assisted ranging UWB anchors or APs validate proximity and sign proof data (Fu et al., 2023, Darzi et al., 3 Mar 2025)
Encounter- and hindsight-based proofs Short-range encounters plus uploaded histories reconstruct feasible regions (Viti et al., 2024)
Mesh and quorum-based PoL Multiple fixed witnesses form threshold attestations or BFT consensus (Brito et al., 29 Mar 2026)
Delay-based Internet PoL Signed RTT measurements plus Byzantine-resistant geometry (Sheng et al., 2024)

The witness-endorsed architecture for secure location provenance introduces four roles: user S⊂R2S\subset\mathbb{R}^26, location authority S⊂R2S\subset\mathbb{R}^27, witness S⊂R2S\subset\mathbb{R}^28, and auditor S⊂R2S\subset\mathbb{R}^29. The authority signs a location statement π\pi0, and a co-located witness creates an endorsement statement π\pi1, enabling an auditor to check the authority signature, witness endorsement, timestamp consistency, and chronological ordering (Hasan et al., 2011). The design target is collusion resistance together with selective disclosure of arbitrary subsequences of a location history.

The 2016 blockchain design removes central storage and records PoLs in a public ledger. A prover broadcasts a signed request π\pi2, a nearby witness verifies overlay-neighbor and distance conditions, then replies with a signed response that is later propagated and stored in blocks under a Proof-of-Stake variant (Brambilla et al., 2016). This architecture treats the blockchain simultaneously as integrity mechanism, global dissemination substrate, and consensus layer.

In UWB-based PoL for UAVs, witness functionality is transferred to ground anchors at known, pre-surveyed positions. A UAV submits a ProofRequest, engages in double-sided UWB two-way ranging, and a platform submits ProofResponse{ uavID, platformID, nonce, {d_i}, GPSclaim }; chaincode VerifyPoL then checks whether the triangulated UWB position agrees with the claimed GPS within a pre-configured tolerance π\pi3 (Fu et al., 2023). This is a verifier-managed model with strong infrastructure assumptions.

ProLoc occupies a different point in the design space. It collects GPS-derived trajectories and short-range radio encounter histories, then reconstructs feasible regions for the prover from witness trajectories, encounter times, BLE range, and map isochrones. A verifier supplies π\pi4, π\pi5, an anchor set π\pi6, and a threshold π\pi7, and the backend returns “true” only if at least π\pi8 valid witnesses satisfy π\pi9 (Viti et al., 2024). The proof is thus retrospective and computationally reconstructed rather than interaction-timed at the point of presence.

The witnessing-zone architecture advances a threshold model in which Setup\text{Setup}0 fixed-position witness nodes form a fully-connected, non-hierarchical mesh over a zone of radius Setup\text{Setup}1. During each block interval Setup\text{Setup}2, each witness runs distance bounding, optionally samples contextual features Setup\text{Setup}3, evaluates a policy predicate Setup\text{Setup}4, commits local evidence in a Merkle root Setup\text{Setup}5, signs Setup\text{Setup}6, and a Setup\text{Setup}7-of-Setup\text{Setup}8 quorum admits the claim into block Setup\text{Setup}9 (Brito et al., 29 Mar 2026). This architecture explicitly integrates presence proof, policy enforcement, and ledger finalization.

4. Measurement and cryptographic mechanisms

The physical substrate of PoL varies from short-range radio and GPS to Internet delay and, in quantum formulations, position verification.

In lightweight IoT PoL, RSSI is converted into estimated distances through a path-loss model,

Prove\text{Prove}0

and a node reconstructs a claimed sender’s location Prove\text{Prove}1 by multilateration from stored RSSI histories (Tschirner et al., 2023). A location-bound key Prove\text{Prove}2 and signature Prove\text{Prove}3 permit lightweight verification without introducing heavy asymmetric cryptography into low-rate mesh networks (Tschirner et al., 2023).

ProLoc constructs region proofs from short-range radio encounters and trajectory data. If a witness Prove\text{Prove}4 reported locations at times Prove\text{Prove}5 and Prove\text{Prove}6, and encountered the prover at Prove\text{Prove}7 within BLE range Prove\text{Prove}8, the system computes two witness-to-prover feasible regions using isochrones and Minkowski sums, propagates them to time Prove\text{Prove}9, and obtains a feasible region Verify\text{Verify}0. The witness is valid if Verify\text{Verify}1, and the backend requires at least Verify\text{Verify}2 such witnesses whose combined feasible region still lies in Verify\text{Verify}3 (Viti et al., 2024). The essential measurement primitive is therefore encounter evidence plus bounded mobility over a map.

UWB-based systems rely on precise timing rather than signal strength. In the UAV design, double-sided TWR yields a one-way time-of-flight Verify\text{Verify}4, and the distance estimate is Verify\text{Verify}5, where Verify\text{Verify}6 m/s (Fu et al., 2023). Because the protocol binds IDs and nonces to the ranging exchange and stores session data on-chain, the measurement is coupled to both physical timing and authenticated identity (Fu et al., 2023).

Delay-based Internet PoL follows a different strategy. BFT-PoLoc signs ping packets, hashes packet chains for replay resistance, and uses each challenger’s monotone mapping Verify\text{Verify}7 maximum-possible distance to convert measured RTTs into conservative distance upper bounds (Sheng et al., 2024). Byzantine resistance is obtained through ratio-based filtering and low-rank matrix completion solving

Verify\text{Verify}8

followed by Euclidean geometric constraints to bound the deviation Verify\text{Verify}9 between the claimed and true locations (Sheng et al., 2024).

Privacy-preserving PoL replaces or supplements direct coordinate disclosure with commitments and zero-knowledge proofs. The IoT zk-PoL paper defines an NP relation over on-chain digest P\mathcal{P}0 and one-time-use hash P\mathcal{P}1, and instantiates a QAP-based zk-SNARK in the Pinocchio style (Wu et al., 2024). The vehicle-subsidy and taxation work commits a GPS trail P\mathcal{P}2 with Poseidon, has a witness device sign P\mathcal{P}3, and proves policy predicates such as total distance and within-territory covered distance in zero knowledge (Bogdanov et al., 20 Jun 2025). At the far end of the spectrum, “Private Proofs of When and Where” introduces position commitments and zero-knowledge position verification built from quantum position verification and post-quantum one-way functions, allowing proofs of statements such as being or not being near a location at a given time without revealing any other detail about the true location (Girish et al., 26 Jan 2026).

5. Consensus, anti-collusion, and privacy preservation

A persistent difficulty in PoL is that witnesses may be malicious, colluding, or fictitious. The literature therefore develops multiple anti-collusion mechanisms rather than assuming a single trusted verifier.

In IoT PoL, distrust is driven by local trust scores and Byzantine-fault-tolerant challenge messages. A node P\mathcal{P}4 enters distrust toward P\mathcal{P}5 when P\mathcal{P}6 or the number of distinct BFT messages about P\mathcal{P}7 exceeds P\mathcal{P}8. On a valid alert from a trusted node P\mathcal{P}9, P\mathcal{P}0 decrements P\mathcal{P}1 if it accepts the alert, otherwise decrements P\mathcal{P}2, while incrementing trust for witnesses whose BFT messages it has observed (Tschirner et al., 2023). This is a neighborhood-consensus model in which trust emerges from repeated local verification.

ProLoc addresses collusion among attacker-controlled devices through a variant of TrustRank over the encounter graph. Vertices are device IDs, and a directed edge P\mathcal{P}3 of weight P\mathcal{P}4 exists if P\mathcal{P}5 received BLE adverts from P\mathcal{P}6. Edge weights are diluted in overlapping windows so that if device P\mathcal{P}7 receives adverts from P\mathcal{P}8 peers in a window, each contributing peer adds P\mathcal{P}9 with tt00, penalizing Sybil multiplicity (Viti et al., 2024). TrustRank then solves

tt01

with seed set tt02, and witnesses with tt03 are discarded (Viti et al., 2024). The stated effect is that fictitious realms connected only through a small cut of corrupt devices receive negligible TrustRank mass.

The 2016 blockchain design instead uses graph-theoretic betweenness centrality to identify Sybil clusters. Large Sybil groups can accumulate PoLs only if they stay local long enough, but their PoL graph exhibits low betweenness centrality tt04; low-tt05 nodes are flagged and their PoLs discarded (Brambilla et al., 2016). In VANETs, Sybil resistance is obtained through a combination of threshold-signed RSU location tags, proof-of-work puzzles that must be solved between consecutive RSUs, and clique-based trajectory matching that exploits the physical overlap of trajectories created by a single car (Baza et al., 2019).

Privacy preservation is equally diverse. The anonymous proof-of-location algorithm for peer-to-peer energy trading issues a Certificate-of-Location over a Merkle root tt06 of ephemeral public keys, then presents a proof

tt07

so that the location claim is bound to a fresh pseudonym rather than the long-term smart-meter key (Khorasany et al., 2020). The paper states that A-PoL yields tt08-anonymity among the tt09 leaves in tt10 (Khorasany et al., 2020). SLAP combines SPSEQ-UC anonymous credentials, BBS group signatures, distance-bounding, and time-lock puzzles, and supports both AP-based and nearby-device-based location verification while maintaining full user anonymity and location privacy during spectrum access (Darzi et al., 3 Mar 2025). The broader provenance literature accordingly treats “purpose-bound” and “selective disclosure” as baseline requirements for PoL in privacy-sensitive settings (Brito et al., 15 Apr 2026).

6. Evaluation, applications, limitations, and open directions

Empirical evaluation across the literature shows that PoL performance depends strongly on the sensing substrate, witness density, and privacy mechanism.

For lightweight IoT PoL implemented on Particle Xenon boards with Zephyr RTOS and OpenThread, a median-plus-Kalman RSSI filter eliminated false BFTs under static conditions; on each genuine movement, each neighbor emitted 1–2 BFT messages within 5 s; total BFT overhead was tt11 of payload traffic in the test scenario; and no false alerts were observed (Tschirner et al., 2023). This indicates feasibility on resource-constrained hardware, though the same work identifies unfinished tasks such as full alert handling, multi-hop consensus propagation, and formal specification or model checking (Tschirner et al., 2023).

For ProLoc, simulated Copenhagen mobility with 128 k participating users and the SensibleDTU BLE dataset showed that, with 20% adoption and 3 min reporting, median precision radii rise from tt12 m at tt13 to tt14 m at tt15, and even at tt16, the 90%ile radius remains tt17 km in dense areas (Viti et al., 2024). TrustRank on the 850-node graph runs in tt18 min, while isochrone proofs were dominated by map queries at tt19 s per witness on un-optimized Python (Viti et al., 2024). The result is useful for applications that accept bounded regional presence rather than exact point verification, such as ranking citizen reports near an earthquake, protest, or fire by their proof precision (Viti et al., 2024).

The UWB-UAV prototype reports short-range ranging error samples of 0.09 m and 0.045 m at tt20–4 m, and long-range errors of 0.25 m and 0.16 m at tt21–14 m, all within a 1 m tolerance (Fu et al., 2023). Its principal limitations are UWB range constraints, degradation under non-line-of-sight, and the need to scale a Fabric deployment beyond a single channel with two peers (Fu et al., 2023). The witnessing-zone simulation, by contrast, emphasizes robustness: with tt22 m, tt23, tt24, and 1 000 Monte Carlo iterations per scenario, the baseline and valid-visual scenarios achieved precision 1.00, while distance fraud and invalid-visual scenarios admitted tt25 claims (Brito et al., 29 Mar 2026). The trade-off explicitly noted there is that contextual sensing adds latency and compute at witnesses but raises spoofing costs (Brito et al., 29 Mar 2026).

Zero-knowledge PoL systems show a different performance profile. The IoT zk-PoL reports total repeatable time of approximately 2 minutes per service request on a MateBook 13, with proof size fixed at 8 group elements and verifier time tt26 in the number of constraints, and notes that computational efficiency is independent of the hierarchical privacy level selected by the user (Wu et al., 2024). The vehicle-subsidy and taxation system scales linearly in trajectory length and number of shapes, with EV subsidy proof generation times of tt27 s for 200 points, tt28 s for 3600 points, and tt29 s for 43 800 points on a Raspberry Pi 4 in the MnC backend (Bogdanov et al., 20 Jun 2025). These results are consistent with the claim that such protocols are appropriate where verification can be delayed and privacy dominates latency constraints.

Applications span location-based services, access control, spectrum access, UAV remote identification, citizen journalism, peer-to-peer energy trading, VANET Sybil detection, supply-chain auditing, and physical e-voting (Brambilla et al., 2016, Darzi et al., 3 Mar 2025, Fu et al., 2023, Viti et al., 2024, Khorasany et al., 2020, Baza et al., 2019, Brito et al., 19 Aug 2025). The methodological literature therefore recommends selecting PoL architectures by matching application requirements to the four design domains rather than assuming that one protocol shape generalizes across use cases (Brito et al., 19 Aug 2025).

Open research directions recur across the corpus. They include integrating alternative ranging technologies such as UWB time-of-flight, adapting PoL for mobile nodes, analyzing collusion attacks by multiple compromised nodes, studying scalability of witness thresholds under changing density, managing policy versioning and cross-zone interoperability, improving privacy-preserving policy verification, and standardizing interfaces and formats for governance-grade auditability (Tschirner et al., 2023, Brito et al., 29 Mar 2026, Brito et al., 15 Apr 2026, Bogdanov et al., 20 Jun 2025). A plausible implication is that future PoL systems will increasingly combine physical measurement, distributed witness logic, privacy-preserving cryptography, and dispute-oriented evidence management rather than treating location verification as a standalone sensing problem.

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Proof-of-Location (PoL).