What a witness does
A location claim on its own is a device saying “I am here”. A witness adds a second voice. The pattern has three steps:
- The claimant asks. It sends a request naming itself and the place it claims to be.
- The witness observes and checks. It measures something it can see for itself, such as whether the claimant is within radio range, or how long a reply takes.
- The witness signs. It produces a statement about what it observed and signs it with its private key, so anyone can check who made the statement and that nobody altered it. This is an ordinary digital signature.
The paper “Blockchain-based Proof of Location” by Brambilla and colleagues uses exactly these roles. A Prover is a node that wants proofs of location from its neighbours; a Witness is a node that has provided one. Before signing, the witness checks that the request comes from a known peer reachable over the short-range link, that the prover signed it, that the claimed position lies within the distance the short-range technology can reach, and that it refers to the latest block of a shared blockchain. Because every proof references a block, the authors’ scheme discards outdated proofs that a malicious peer tries to replay.
A verifier later checks the signatures and decides whether the statements are enough. The signature authenticates the witness. It does not make the observation correct.
Kinds of witness
- Fixed infrastructure. Saroiu and Wolman proposed that Wi-Fi access points and cell towers hand out location proofs, relying on their short radio range to tie the device to the place.
- Nearby peers. In the Brambilla scheme, mobile nodes in range of each other over short-range links such as Bluetooth, or vehicle-to-vehicle radio, act as witnesses for one another, with no infrastructure required.
- Network measurers. BFT-PoLoc uses challengers that measure Internet delay to a target, attach signatures and hashes to the measurements, and combine them under geometric constraints to estimate where an IP address is.
What a witness can measure
Radio contact. If the witness hears the claimant over a short-range radio, the claimant was probably nearby. Signal strength is a rough guide to distance at best; see RSSI.
Round-trip time. Timing is harder to fake in one direction. Brands and Chaum’s distance-bounding protocols time the delay between a challenge bit and its response bit to give an upper bound on distance. Wi-Fi round-trip-time ranging, specified in IEEE 802.11-2016 and referred to as 802.11mc in Android’s documentation, measures the time a packet takes to make a round trip and multiplies it by the speed of light. Note who learns the result: in Android’s implementation only the requesting device can determine the distance, and the access points do not have this information, so Wi-Fi RTT as shipped helps a device position itself rather than letting the access point witness for it.
Network delay. Over the Internet, delay is a noisy stand-in for distance. The BFT-PoLoc authors note that traditional delay-based geolocation focuses on reducing noise in the measurements and is vulnerable to participants who deliberately depart from the protocol, for example by tampering with delays or using VPNs.
Where witnesses fail
- Collusion. The MobChain paper describes three-way collusion, between the user, the location authority and the witness, as unavoidable in the existing witness-oriented schemes.
- Added delay. Timing gives an upper bound: a device cannot answer faster than its true distance allows, so it cannot appear closer than it is. It can answer slower, though, and appear farther away, which matters whenever a witness checks a claim against a distance rather than a maximum.
- A single point of trust. If one organisation chooses every witness, the evidence is only as independent as that organisation.
- Unchecked inputs. A witness that compares a measurement with a position supplied by the claimant is checking consistency, not discovering where the claimant is.
A documented example
Offline Protocol’s Proof of Location, on the Ethereum Sepolia testnet, uses operator witnesses. Each operator measures network round-trip time and signs its own attestation. There is no final-proof aggregation step, the backend controls the operator list, the current configuration can contain a single witness, and slashing is not implemented. Its documentation tells consumers to verify each attestation’s signer, deployment, task and freshness, and to treat the result as witness-attested evidence rather than proof of presence.