Why a reported position is not enough
A phone that shows its position on a map has worked that position out itself, from satellite signals, Wi-Fi and cell towers. For navigation that is fine. It is a weaker basis for decisions where the person holding the phone gains something by lying, such as a reward for visiting a shop, a payment that depends on being on site, or access limited to one region.
Stefan Saroiu and Alec Wolman made this point in 2009: applications in which users have an incentive to lie about their location cannot rely only on the users’ own devices to discover and report it. They proposed location proofs, a piece of data that certifies a receiver to a geographical location. Satellite signals can also be faked; see GPS spoofing.
Proof of location is the general name for any scheme that adds evidence from someone other than the device. The word “proof” is generous. What these systems produce is evidence of varying strength, and the useful question is always what exactly was measured, and by whom.
The main approaches
Infrastructure that hands out proofs. In the Saroiu and Wolman design, wireless infrastructure such as a Wi-Fi access point or a cell tower hands location proofs to mobile devices. The short range of the radio is what ties the device to the place: only a device close enough to the transmitter can receive one.
Witnesses. Instead of fixed infrastructure, other parties observe the claimant and sign statements about what they saw. A location witness might be a nearby phone, a radio beacon or a server that times a network exchange. The MobChain paper traces how the field moved from two-party systems, which suffered from collusion between the participants, to witness-oriented systems, and then found a new risk: the user, the location authority and the witness colluding together.
Time-synchronised beacons. FOAM’s 2018 whitepaper outlined, on what it called an illustrative and non-promissory basis, a network of radio beacons that would synchronise their clocks and compute a device’s position from signal timing, with operators staking tokens as a deposit they would forfeit for breaking the protocol’s rules.
Distance bounding. Brands and Chaum introduced distance-bounding protocols at EUROCRYPT ‘93. A verifier sends a challenge bit and times how long the response bit takes to come back. Because a signal cannot travel faster than physics allows, the delay gives a practical upper bound on how far away the responder is. The technique can be built into ordinary challenge-response identification.
Authenticated satellite signals. Galileo’s Open Service Navigation Message Authentication (OSNMA) lets a receiver check that the navigation message it received came from Galileo and was not modified. It is free to use. The check runs inside the receiver, so it helps the receiver trust its own position calculation; by itself it gives no one else evidence of where that receiver was.
What it can and cannot establish
A 2025 taxonomy of proof-of-location systems groups the design choices into four areas: cryptographic guarantees, spatio-temporal synchronisation, trust and witness models, and interaction and overhead. It also names the attacks the field is trying to resist: spoofing, replay and collusion.
A few limits hold across approaches:
- Timing bounds distance from above. A responder cannot answer faster than the signal can travel, but it can answer slower. Delay can make a device look farther away than it is, so timing rules claims out more readily than it pins them down.
- Witnesses can be wrong or dishonest. A witness’s signature shows who made a statement, not that the statement is true. Several witnesses run by one party are not independent.
- A device is not a person. Evidence about a phone or a radio does not show who was holding it.
- Location records are sensitive. Whatever a system stores or publishes about where someone was can reveal more than the single claim it was made for.
One deployed example
Offline Protocol’s Proof of Location, which runs on the Ethereum Sepolia testnet, records witness-attested location evidence. Its backend commits a geohash of the claimed location, at precision 5 or approximately a 5 km cell, to an EigenLayer AVS contract, and operator witnesses measure network round-trip time and sign individual attestations. There is no final-proof aggregation step, the current configuration can contain a single witness, and the documentation states that it is not a zero-knowledge proof, a decentralized consensus result, or proof that a person is physically present.
Questions to ask of any system
Before relying on a proof-of-location result, ask:
- Who are the witnesses, and who chooses them? A list controlled by one operator gives different assurance from witnesses chosen at random from independent parties.
- What did each witness actually measure? Radio contact, network timing and satellite data each rule out different lies.
- Can the claimant add delay or relay signals? If so, the evidence narrows the claim rather than fixing it.
- What becomes public, and for how long? Records written to a public ledger cannot be deleted later.
- What happens when witnesses are unavailable? A check that cannot run has to fail safely.
The answers decide whether the evidence is enough for a coupon, an audit trail or an access decision. For anything valuable or safety-critical, proof of location works best as one signal among several rather than the only control.