Beyond IP: Adding Physical Distance Telemetry to Your CAEP Policy Engine

In the evolution of Identity and Access Management (IAM), Zero Trust has moved us away from static perimeter security toward dynamic, risk-based access control. Today, modern Conditional Access engines—powered by frameworks like Microsoft Entra ID, Okta FastPass, and Ping Identity—evaluate a suite of signals before granting access: device compliance, threat intelligence, user risk scores, and IP geolocation.
Furthermore, the adoption of the Continuous Access Evaluation Protocol (CAEP) and the OpenID Shared Signals Framework (SSF) has revolutionized session management. Instead of relying on static token expiration times, identity providers can now adjust, re-evaluate, or revoke active sessions in near-real-time as risk signals change.
However, even the most advanced Zero Trust architectures share a critical blind spot: they lack precise, hyper-local physical context.
Current Conditional Access policies evaluate whether a login originates from a trusted country, a specific IP range, or a managed device. But they cannot answer the most basic physical security question: Is the authorized user actually sitting in front of the laptop right now?
Here is why physical distance is the missing signal in modern CAEP policy engines—and how NearAuth.ai provides the architecture to bridge this gap.
The Physical Context Gap in Modern Zero Trust
Consider two common, high-risk security scenarios that traditional Conditional Access policies struggle to mitigate in real time:
- Post-Authentication Session Hijacking: An employee authenticates successfully on a compliant corporate laptop from a trusted office IP. An hour later, they step away to grab coffee. A malicious actor—or curious insider—walks up to the unattended, unlocked laptop. Because the session token is already active and valid, the policy engine sees no anomaly. Access is granted unrestricted.
- Adversary-in-the-Middle (AiTM) & Remote Token Theft: A threat actor thousands of miles away intercepts a valid session cookie via a reverse-proxy phishing framework. While the initial request triggered an MFA check, the hijacked session cookie is now being replayed. Even if CAEP detects an IP shift, attackers frequently route traffic through residential proxy networks in the victim’s exact city to bypass geographic anomalies.
In both cases, coarse telemetry like IP address and broad GPS/geolocation fail. IP addresses are easily proxied, GPS is imprecise indoors (and easily spoofed), and static device health status remains "compliant" regardless of who is physically touching the keyboard.
To achieve true Zero Trust, policy engines require a fine-grained, un-spoofable signal: real-time physical proximity.
What is Continuous Proximity Telemetry?
Continuous Proximity Telemetry introduces spatial awareness into access control. Rather than relying on a point-in-time check (like scanning a QR code or tapping an MFA button), proximity telemetry measures the real-time physical distance between an authorized identity token (such as a user’s authenticated smartphone or wearable) and the endpoint requesting access.
Instead of asking:
A proximity-aware CAEP policy engine asks:
If the distance suddenly expands to 10 meters, or if the identity token disappears from the endpoint’s local physical environment altogether, the risk profile of that active session changes instantaneously.
NearAuth.ai provides the infrastructure to turn physical proximity into a continuous, real-time security signal. Operating quietly in the background without forcing users to touch buttons or respond to push notifications, NearAuth uses secure, cryptographic distance-bounding and localized environmental checks to determine exact presence.
By acting as a continuous signal provider within the Shared Signals Framework (SSF), NearAuth bridges the physical world with your cloud identity infrastructure.
chris@nearauth.ai