Method and device for access control and method for generating trust decision model

By capturing the CSI matrix of user equipment and using machine learning models to determine its matching with trusted locations, more accurate and convenient access control is achieved, solving the security and user-friendliness issues of traditional systems. It is suitable for access control and data protection in wireless networks.

CN121645249APending Publication Date: 2026-03-10INTEL CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-24
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Traditional access control systems rely on passwords or credentials, are vulnerable to attacks, have poor user-friendliness, and lack reliable location-based access control.

Method used

By capturing the Channel State Information (CSI) matrix of the user equipment, a machine learning model is used to determine whether the CSI matrix matches a trusted location, thereby performing access control and generating a trust decision model to determine the trustworthiness of the location.

Benefits of technology

It improves the accuracy and convenience of access control, reduces complexity, enhances security, is particularly suitable for protecting sensitive data, and reduces reliance on traditional authentication methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure HDA0005515754990000011
    Figure HDA0005515754990000011
  • Figure HDA0005515754990000012
    Figure HDA0005515754990000012
  • Figure HDA0005515754990000021
    Figure HDA0005515754990000021
Patent Text Reader

Abstract

The invention relates to a method and device for access control and a method for generating a trust decision model. A method for location-based access control in a wireless network is provided. The location of the user equipment is determined to be trusted or untrusted based on a channel state information (CSI) matrix of the user equipment. Access control is performed based on the trusted or untrusted trust state of the user equipment. In some examples, in order to determine a trust state of a user equipment, a CSI matrix of the user equipment needs to be input into a machine learning model, or needs to be compared to CSI matrices corresponding to a plurality of trusted locations using similarity metrics. Since the access control is based on the location of the user device, the convenience and accuracy of the access control may be superior to those made by some other security measures, such as password-based mechanisms.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to methods, apparatus, and nontransitory machine-readable storage media for access control, as well as methods for generating trust decision models. Background Technology

[0002] In today's digital age, the increasing reliance on wireless networks and devices for personal, professional, and business purposes has amplified the need for robust and reliable security mechanisms. Traditional access control systems typically rely on passwords or credentials, which can be cumbersome in some cases and vulnerable to hacking, theft, or abuse. Summary of the Invention

[0003] According to one aspect of this disclosure, a system is provided, including apparatus, wherein the apparatus includes an interface, processing circuitry, and machine-readable instructions, wherein the processing circuitry is configured with a trusted execution environment to execute the machine-readable instructions within the trusted execution environment, thereby executing a method for location-based access control in a wireless network, wherein the method includes: capturing a Channel State Information (CSI) matrix based on the location of a user equipment; determining whether the captured CSI matrix matches a trusted location; and performing access control based on whether the captured CSI matrix matches a trusted location.

[0004] According to one aspect of this disclosure, a system is provided, including apparatus, wherein the apparatus includes an interface, processing circuitry, and machine-readable instructions, wherein the processing circuitry is configured with a trusted execution environment to execute the machine-readable instructions within the trusted execution environment, thereby performing a method for generating a trust decision model, wherein the method includes: capturing a CSI matrix associated with one or more user equipments at one or more locations; and generating the trust decision model based on the captured CSI matrix, wherein the trust decision model is used to determine whether the location from which the access request is sent is a trusted location.

[0005] According to one aspect of this disclosure, a non-transitory machine-readable storage medium is provided, including program code that, when executed, causes a machine to perform a method for location-based access control in a wireless network, the method comprising: capturing a CSI matrix based on the location of a user equipment; determining whether the captured CSI matrix matches a trusted location; and performing access control based on whether the captured CSI matrix matches a trusted location.

[0006] According to one aspect of this disclosure, a method for generating a trust decision model is provided, the method comprising: capturing a CSI matrix associated with one or more user equipments at one or more locations; and generating the trust decision model based on the captured CSI matrix, wherein the trust decision model is used to determine whether the location from which the access request is sent is a trusted location. Attached Figure Description

[0007] The following description will use only examples of apparatus and / or methods, with reference to the accompanying drawings, in which:

[0008] Figure 1 A schematic diagram of an example of a system 100 for location-based access control is shown;

[0009] Figure 2 A flowchart illustrating an example of a location-based access control method 200 is shown;

[0010] Figure 3 A flowchart illustrating an example of a method 300 for generating a trust decision model is shown;

[0011] Figure 4 A schematic diagram illustrating an example of a method 400 for generating a trust decision model 430 based on machine learning is shown;

[0012] Figure 5 A flowchart is shown as an example of a method 500 for generating trust decision models based on machine learning;

[0013] Figure 6 A schematic diagram of an example system including a trust decision model 600 is shown;

[0014] Figure 7 A block diagram illustrating an example of a device for access control is shown; and

[0015] Figure 8 A block diagram of an example of device 800 is shown. Detailed Implementation

[0016] Some examples will now be described in more detail with reference to the accompanying drawings. However, other possible examples are not limited to the features of these embodiments described in detail. Other examples may include modifications to these features, as well as equivalents and alternatives to these features. Furthermore, the terminology used herein to describe certain examples should not limit other possible examples.

[0017] Throughout the description of the accompanying drawings, the same or similar reference numerals refer to the same or similar elements and / or features, which may be identical or may be implemented in a modified form while providing the same or similar functions. For clarity, the thickness of lines, layers, and / or regions in the drawings may also be exaggerated.

[0018] When two elements A and B are combined using "or", it should be understood that all possible combinations are disclosed, i.e., only A, only B, and A and B, unless otherwise explicitly defined in individual cases. Alternative wording for the same combination may be "at least one of A and B" or "A and / or B". The same applies to combinations of more than two elements.

[0019] If the singular form, such as "a," "one," and "the," is used, and the use of only a single element is not explicitly or implicitly defined as mandatory, other examples may also use multiple elements to achieve the same functionality. If a functionality is described below as being implemented using multiple elements, other examples may use a single element or a single processing entity to achieve the same functionality. It should also be understood that the terms "including," "containing," "containing," and / or "having," when used, describe the presence of the specified feature, integer, step, operation, process, element, component, and / or combination thereof, but do not preclude the presence or addition of one or more other features, integers, steps, operations, processes, elements, components, and / or combinations thereof.

[0020] Specific details are set forth in the following description, but examples of how the techniques described herein can be practiced without these specific details are provided. Well-known circuits, structures, and techniques are not shown in detail to avoid obscuring the understanding of this description. Terms such as "an example," "various examples," "some examples," etc., may include features, structures, or characteristics, but not every example must include these specific features, structures, or characteristics.

[0021] Some examples may have some, all, or none of the features described for other examples. Terms like “first,” “second,” “third,” etc., describe common elements and indicate different instances of similar elements referred to. Such adjectives do not imply that the element items described must be in a given order, in time or space, in rank, or in any other way. “Connected” may indicate elements in direct physical or electrical contact with each other, and “coupled” may indicate elements cooperating or interacting with each other, but they may or may not be in direct physical or electrical contact.

[0022] As used herein, the terms “operation,” “execution,” or “running” are used interchangeably when they refer to software or firmware in relation to a system, device, platform, or resource, and can refer to software or firmware stored in one or more computer-readable storage media accessible by the system, device, platform, or resource, even if the instructions contained in the software or firmware are not actively executed by the system, device, platform, or resource.

[0023] The description may use phrases such as “in one example,” “in multiple examples,” “in some examples,” and / or “in various examples,” each of which may refer to one or more of the same or different examples. Furthermore, the terms “comprising,” “including,” “having,” etc., used with respect to examples of this disclosure are synonyms.

[0024] Some examples provide the following access control measures.

[0025] Password-based authentication: This is a common method that requires users to enter a unique password that matches the passwords stored in the system.

[0026] Physical tokens or ID cards: These are tangible items that users possess to gain access, such as smart cards, key fobs, or employee ID cards.

[0027] Biometrics: It involves verifying a user's identity based on unique physical or behavioral characteristics (such as fingerprints, facial recognition, retinal scans, or voice recognition).

[0028] Personal Identification Number (PIN): It requires users to enter a numeric password and is usually used in conjunction with a physical token such as a debit card.

[0029] IP-based geolocation: This method enforces access control based on the geographic location of the access request or the user's device's IP address. However, this can be bypassed using VPNs or proxy servers and is considered insecure because it can be easily bypassed in certain situations.

[0030] Security questions: These are personal questions whose answers should only be known to specific users. This method is often used as a supplementary form of authentication or for password recovery.

[0031] Multi-factor authentication (MFA): This involves combining two or more of the methods described above to verify a user's identity; for example, a password and biometric scan may be required to authorize access.

[0032] Virtual Private Network (VPN): VPNs allow remote users to securely connect to a private network, but they typically do not provide location-based access control or hardware fingerprinting.

[0033] While these measures provide a degree of control and security, they each have limitations. For example, they may lack reliable location-based access control. Furthermore, they may require significant user intervention that is not user-friendly.

[0034] Some examples of this disclosure provide a method for location-based access control in a wireless network. The location of a user equipment (UE) is determined to be trusted or untrusted based on the UE's Channel State Information (CSI) matrix. Access control is performed based on the UE's trust state (trusted or untrusted). In some examples, to determine the UE's trust state, the UE's CSI matrix can be fed into a machine learning model, or a similarity metric can be used to compare it with CSI matrices corresponding to multiple trusted locations. Because access control is based directly or indirectly on the UE's location (e.g., via the CSI matrix), its convenience and accuracy can be superior to some other security measures, such as cryptographic mechanisms. Therefore, other security measures can be reduced in some cases, and the method for location-based access control can, in some cases, serve as a supplement to other security measures.

[0035] Figure 1 A schematic diagram of an example system 100 for location-based access control is shown. System 100 includes a building 110, which includes a room 120, an access point 130, and at least one user equipment 140 located in the room 120. To perform access control on the user equipment 140, the access point 130 captures a Channel State Information (CSI) matrix. Those skilled in the art will understand that the CSI matrix depends on the wireless communication channel between the access point 130 and the user equipment 140. Therefore, the wireless channel and the CSI matrix depend on the location of the user equipment 140, such as room 120 or one or more locations within room 120. A controller (which may be the access point 130 or...) then... Figure 1 Another external device (not shown) determines whether the captured CSI matrix matches a trusted location. Based on whether the captured CSI matrix matches a trusted location, access control is performed on user equipment 140.

[0036] In some examples, the CSI matrix can provide a detailed representation of the wireless channel conditions between the transmitter and receiver. This matrix can capture the amplitude and phase shifts occurring on multiple subcarriers in an OFDM (Orthogonal Frequency Division Multiplexing) system, allowing for granular analysis of channel characteristics. Each element of the CSI matrix is ​​a complex number that reflects the channel response between a specific transmit and receive antenna pair on a particular subcarrier, making it an important tool for optimizing wireless communication techniques such as beamforming, MIMO (Multiple-Input Multiple-Output), and adaptive modulation. In other examples, a simplified CSI matrix may include amplitude without phase shift.

[0037] In some examples, access point 130 is a Wi-Fi access point, and in other examples, the access point is a base station according to the 3GPP standard, or another type of access point for wireless user equipment. Therefore, wireless signals, including directional transmission and signal reflection, can be associated with either Wi-Fi signals or 3GPP wireless signals. In some examples, the access point can support both Wi-Fi and 3GPP signals; therefore, wireless signals can be associated with both. In some examples where the controller is not access point 130, the controller can be deployed in a remote server. In some examples, user equipment 140 can be a laptop, smartphone, tablet, personal computer, smartwatch, or another type of smart device. In some examples, the CSI matrix of user equipment 140 represents the wireless channel from user equipment 140 to access point 130. Therefore, the CSI matrix of user equipment 140 can be unique to the location of user equipment 140. When user equipment 140 moves from one location to another, the values ​​of the CSI matrix of user equipment 140 will change accordingly. Since the CSI matrix is ​​unique for the location of user equipment 140, multiple different CSI matrices can each correspond to multiple different locations. Therefore, the CSI matrix can be used as a unique location-based identifier for user equipment 140.

[0038] Figure 2 A flowchart illustrating an example of a location-based access control method 200 according to this disclosure is shown.

[0039] Method 200 for location-based access control includes: capturing (210) a CSI matrix based on the location of a user equipment; determining (220) whether the captured CSI matrix matches a trusted location; and performing (230) access control based on whether the captured CSI matrix matches a trusted location. According to method 200, location-based access control for wireless user equipment can be performed, thereby improving the accuracy of access control and / or reducing its complexity.

[0040] In some examples, capturing (210) the CSI matrix can be performed by access point 130 or a controller. In a more specific example, the wireless signal is a Wi-Fi signal, and capturing 210 can be performed by Wi-Fi firmware installed in access point 130. When capturing 210 is performed by the controller, capturing 210 performed by the controller means that the controller receives the CSI matrix captured by access point 130. In some examples, the CSI matrix of the captured Wi-Fi signal is considered a Wi-Fi signature or a key component of the Wi-Fi signature, unique to the location of user equipment 140.

[0041] In some examples, determining whether the captured CSI matrix (220) matches a trusted location is based on machine learning methods. For example, determining 220 involves inputting the captured CSI matrix or its features into a machine learning model trained to predict the probability that the captured CSI matrix corresponds to one of the trusted locations. The machine learning model can determine whether the captured CSI matrix matches a trusted location based on the input. To achieve the ability to determine or predict, in some examples, the machine learning model may include an artificial neural network (ANN) or a support vector machine (SVM) trained to determine whether a CSI matrix corresponds to a trusted location.

[0042] In some examples, to obtain the aforementioned machine learning model, it is necessary to train the machine learning model. Training can be based on the CSI matrix and corresponding ground truth pairs for trusted or untrusted locations. Both the CSI matrices for trusted and untrusted locations are helpful in training the machine learning model.

[0043] Some examples provide alternative training methods for the machine learning model. In one example, if a user can successfully log in to a wireless network based on the CSI matrix captured by the user device, training may include classifying the user device's location as a trusted location. The machine learning model is then trained using at least one CSI matrix as training input, based on the trusted location. The user device's CSI matrix may refer to a CSI matrix based on the user device's location. In another example, the machine learning model or training controller requests a trusted user to label the user device's location as trusted or untrusted, or requests the trusted user to verify a prediction made by the machine learning model. Based on the trusted user's feedback, the user device's location is labeled as trusted or untrusted, or the machine learning model's prediction is verified as true or false by the trusted user. The machine learning model is incrementally trained when feedback regarding whether the user's location is trusted or whether the machine learning model's prediction is true is used as input. In some examples, training may be implemented by a device or system comprising multiple devices configured to train the model. The trained machine learning model can determine or decide whether the user device is in a trusted location based on the CSI matrix captured by the user device. Therefore, in some examples, the trained machine learning model may be referred to as a trust decision model. In some examples, the CSI matrix of a user equipment refers to a CSI matrix based on the location of the user equipment.

[0044] The CSI matrix can be sensitive to any changes in the wireless channel (e.g., changes caused by walking people and / or changes in the location of the user equipment). Therefore, in some examples, the trust decision model is able to address the challenges posed by changes in the signal channel and can still identify a trusted location's CSI matrix even when some changes in the signal channel exist at that location. In other words, in some examples, some changes in the signal channel at a trusted location should not prevent the trust decision model from correctly identifying the CSI matrix for that location.

[0045] In some examples, when determining whether a captured CSI matrix (220) matches a trusted location, the process may involve capturing the CSI matrix from the user equipment and analyzing the statistical properties of the captured CSI matrix, such as mean, variance, and covariance. These properties can provide a detailed understanding of the wireless channel characteristics associated with the CSI matrix, including the amplitude and phase shift of various subcarriers and antennas. The statistical properties of the captured CSI matrix can then be compared with those of CSI matrices from known trusted locations. Similarity measures, such as Euclidean distance, Mahalanobis distance, and correlation coefficients, can be used to assess the degree of matching. Euclidean distance calculates the straight-line distance in multidimensional space, while Mahalanobis distance takes into account the correlation between variables, and the correlation coefficient measures the linear relationship between attributes.

[0046] In some examples, comparisons can use any combination of mean, variance, and covariance to achieve an accurate match. For instance, in an office environment, a system can capture and analyze the mean, variance, and covariance of a CSI matrix and compare these values ​​with pre-stored statistical properties from trusted office locations. If the similarity metric (such as Mahalanobis distance) indicates a close match, the device or system can conclude that the user's device (which could be a smartphone, laptop, and / or tablet) is located in a trusted location. Otherwise, it can trigger a security alert or initiate further verification or authentication steps.

[0047] In some examples, Method 200 does not need to replace traditional authentication methods. For certain users or according to certain policies, some traditional authentication methods can be abandoned when a user device is identified as being in a trusted location. In some examples, Method 200 can be used to supplement rather than replace other security measures. While Method 200 is a unique and highly secure access control method, it may also acknowledge the practicality and familiarity of password-based security measures in certain situations. Therefore, scalability is provided for selecting the preferred access control method based on the circumstances.

[0048] In some examples, the need for MFA or additional security measures can be waived when the user is at home or in a designated trusted location (e.g., within an IT organization in the case of company equipment). In another example, the user can opt to use Access Point (AP) signing for a seamless and convenient access experience, eliminating the need to enter a password. This convenience is particularly beneficial for those who find it difficult to remember multiple complex passwords. However, when the user is outside these locations or in potentially insecure environments, password-based security measures may be required. This dual system ensures maximum flexibility and security for the user, catering to various situations and needs.

[0049] Enforcing (230) access control may include: authorizing access to the wireless network if the captured CSI matrix matches a trusted location, and denying access if the captured CSI matrix does not match a trusted location. By authorizing access to the wireless network, access control is both secure and concise. In some other examples, certain measures used for access control may be abandoned if the captured CSI matrix matches a trusted location. This means that some additional measures for access control may still be needed to further improve the accuracy of access control and enhance the security of the data to be accessed.

[0050] In some examples, the wireless signal is associated with a Wi-Fi signal and / or a 3GPP (3rd Generation Partnership Project) wireless signal. For example, the Wi-Fi signal could be a Wi-Fi 4 signal, a Wi-Fi 6 signal, and / or a Wi-Fi 7 signal, and the 3GPP signal could be a 5G signal and / or a 6G signal.

[0051] In some examples, method 200, which includes enhanced security measures, can be applied to data protection, particularly for protecting sensitive and critical data such as health documents, top-secret documents, defense documents, encrypted wallets, and cryptographic libraries.

[0052] In some examples, method 200 can be provided to enable or disable system functions based on trusted locations, such as disabling or enabling system cameras based on the trust status (trusted or untrusted) of a specific location.

[0053] Figure 3 A flowchart illustrating an example of a method 300 for generating a trust decision model is shown. The method 300 for generating the trust decision model includes: capturing (310) a CSI matrix based on one or more locations of one or more user devices. The method 300 further includes: generating (320) a trust decision model based on the captured CSI matrix. The trust decision model is used to determine whether the location from which the access request is sent is a trusted location. In some examples, the trust decision model generated by method 300 is... Figure 2 The corresponding examples provide trust decision models.

[0054] In some examples, the trust decision model is generated based on machine learning methods. In other examples, the trust decision model is generated based on statistical methods. In still other examples, the trust decision model is generated based on both machine learning and statistical methods.

[0055] In some examples associated with machine learning methods, a machine learning model (trust decision model) can be trained based on the CSI matrix and ground truth pairs of trusted or untrusted locations to generate a trust decision model.

[0056] Figure 4 A schematic diagram illustrating an example of a method 400 for generating a trust decision model 430 based on machine learning methods is shown. Figure 4 As shown, multiple CSI matrices 410 can be used as input to train a machine learning module to generate a trust decision model 430. As an example diagram, Figure 4 Several 3×3 CSI matrices are shown, which can be associated with a multiple-input multiple-output (MIMO) system with 3 transmit antennas and 3 receive antennas. Figure 4Each of the nine elements in the 3×3 CSI matrix shown can represent a complex channel coefficient for the channel from the transmit antenna to the receive antenna. Complex channel coefficients can include, for example, the amplitude and phase of the signal for each subcarrier in an OFDM (Orthogonal Frequency Division Multiplexing) system. In some other examples, the CSI matrix 410 can be an M×N matrix, where M is not equal to N.

[0057] In some examples, each of the multiple CSI matrices 410 can be marked by a trusted user with a trust state 420. The trust state 420 can indicate whether a location associated with a particular CSI matrix 410 is a trusted or untrusted location. As previously described, a CSI matrix 410 can represent a wireless channel from a user equipment at a location to an access point. Therefore, the location of the user equipment is the location associated with the CSI matrix. In some examples, the wireless signal received at the access point may include line-of-sight components and / or reflected components (echoes), which may interfere with each other constructively or destructively. The trust state 420 (trusted or untrusted) of the CSI matrix 410 and the location associated with the CSI matrix can be considered as a ground truth pair. When a user marks each of the multiple CSI matrices as belonging to a trusted or untrusted location, the multiple CSI matrices represent multiple ground truth pairs of CSI matrix 410 and trust state 420.

[0058] like Figure 4 As shown, multiple ground truth pairs of the CSI matrix 410 and trust states 420 can be used as input to train a machine learning model, which can be an artificial neural network (ANN) or a support vector machine (SVM), to generate a trust decision model 430. After generating the trust decision model 430 through the above training, the trust decision model 430, which is now capable of reasoning, can predict whether the captured CSI matrix 440 is associated with a trustworthy location or an untrustworthy location.

[0059] In some examples, all CSI matrices 410 used as input to generate the trust decision model can be labeled as belonging to trusted locations. The trust decision model generated in these examples is adept at determining the CSI matrices of trusted locations. In other examples, all CSI matrices 410 used as input to generate the trust decision model can be labeled as belonging to untrusted locations. The trust decision model generated in these other examples is adept at determining the CSI matrices of untrusted locations. In still other examples, both CSI matrices labeled as belonging to trusted locations and CSI matrices labeled as belonging to untrusted locations can be used as input to generate the trust decision model, so that the generated trust decision model can be more balanced in its ability to determine whether a CSI matrix belongs to a trusted or untrusted location.

[0060] In some examples, one or more threshold bars can be configured for training. The configuration of one or more threshold bars provides a high probability of correctly identifying a trusted location and a low probability of issuing a "false positive" notification. In some examples, the threshold bars can be configured as needed. For example, a first threshold bar can be configured with a first value for a first requirement of the trust decision model, and a second threshold bar can be configured with a second value for a second requirement of the trust decision model. The first and second requirements are different types of requirements. For example, the first and second requirements can be two of the following requirements: extremely high accuracy of positive predictions, very high accuracy of positive predictions, high accuracy of positive predictions, high accuracy of negative predictions, very high accuracy of negative predictions, and extremely high accuracy of negative predictions. Positive predictions can refer to predicting that the user equipment is in a trusted location, and negative predictions can refer to predicting that the user equipment is in an untrusted location. In some examples, the threshold bars can be signal strength, CSI matrix quality, temporal stability, spatial resolution, frequency, bandwidth, and / or calibration. Signal strength can be used to set a minimum acceptable signal strength to account for the reliability of the CSI matrix. CSI matrix quality can include variance, mean, and other statistical measures to filter out noise. Temporal stability refers to the consistency of CSI measurements over time. Spatial resolution refers to the spatial resolution of CSI data, which can involve the granularity of phase and amplitude information. Frequency and bandwidth can be used independently or in combination to establish wireless communication. Calibration can be used to ensure consistency across different devices and environments. In one example, if one or more threshold bars are properly configured, the trust decision model's judgment on whether a user or their user equipment is in a trustworthy location is very close to the truth or reality.

[0061] Based on the decisions made by the trust decision model, some example applications can make further decisions. For example, further decisions could be about whether to reduce other security controls, and / or whether the application and the trust decision model are running on the same or different hardware devices. If it is determined that other security controls should be reduced, then it can be further determined how to reduce them, what to reduce, and / or when to reduce them. In one example, reducing other security controls includes abandoning multi-factor authentication (MFA).

[0062] By ensuring that access is authorized only in specific, approved locations, the risk of unauthorized access or hacking is significantly reduced. This provides users with an extra layer of security, better protecting their digital assets and sensitive information.

[0063] Figure 5A flowchart illustrating an example of a method 500 for generating a trust decision model based on a machine learning approach is shown. The method 500 for generating the trust decision model includes capturing (510) a CSI matrix based on one or more locations of one or more user devices, wherein one or more locations are marked as trusted or untrusted by one or more trusted users. In some examples, the capture 510 may be performed by an access point such as a Wi-Fi router or a 3GPP base station. In some other examples, the capture 510 may include receiving the CSI matrix captured by one or more access points by a controller. The controller may be coupled to one or more access points via a wired or wireless connection. In some examples, the captured CSI matrix is... Figure 4 The associated CSI matrix 410.

[0064] In some examples, method 500 further includes generating a (520) trust decision model by training a machine learning model based on ground truth pairs of the captured CSI matrix and trust states associated with the CSI matrix. Ground truth pairs may include the CSI matrix and trust states associated with the CSI matrix, where trust states can be trusted or untrustworthy, and the trust states associated with the CSI matrix can indicate whether the CSI matrix is ​​associated with trusted or untrustworthy locations. For example, Figure 4 The CSI matrix 410 in the model can represent ground truth pairs because it includes both the 3×3 CSI matrix and the trust states 420. Based on the ground truth pairs, trust decision models can be generated, such as... Figure 4 Model 430 in the text.

[0065] In some examples, after generating the trust decision model, the trust decision model can perform access control on the user equipment based on the captured CSI matrix associated with the user equipment. Access control can be based on the trust decision model predicting whether the user equipment is in a trusted or untrusted location. The CSI matrix associated with the user equipment refers to a CSI matrix that depends on the location of the user equipment. If the user of the user equipment successfully logs into the wireless network at a location associated with the captured CSI matrix, method 500 further includes classifying (530) the location of the user equipment as a trusted location. Based on this classification, a new ground truth pair is generated, which includes the captured CSI matrix and a trust state indicating the trusted location. The new ground truth pair is then used as input to incrementally train a machine learning model, thereby improving the trust decision model.

[0066] In some examples, method 500 further includes: requiring (540) a trusted user to mark the location of the user's device as a trusted or untrusted location, or requiring (540) a trusted user to verify a prediction made by the machine learning model. In some examples, a trusted user can be a user predicted by the trust decision model to be located at a trusted location, and / or a user who has gained trust based on one or more conventional security measures. Based on the trusted user's marking action, a trust state associated with the location is generated. Therefore, the CSI matrix of this location, identified as trusted or untrusted, can be used to further train the machine learning model. Further training can improve the trust decision model. In another example, where a trusted user is required to verify a prediction made by the machine learning model, the verification made by the trusted user can be used to train the machine learning model. For example, if the verification indicates that the prediction is correct, the machine learning model can be trained to make the same prediction for the same or similar further situations. If the verification indicates that the prediction is incorrect, the machine learning model can be trained to make the opposite prediction for the same or similar further situations. Based on operation 540, the accuracy of the trust decision model can be further improved. Since operations 530 and 540 are not mutually exclusive in many cases, the trust decision-making model can be improved by operations 530 and / or 540.

[0067] Figure 6 A schematic diagram of an example system is shown, which includes a trust decision model 600 generated based on artificial intelligence (AI) and a Wi-Fi CSI matrix. The trust decision model 600 may include an AI engine 610, a training module 620, and a matching engine 630.

[0068] In some examples, AI engine 610 can receive a Wi-Fi CSI matrix captured by Wi-Fi firmware 640 and can receive user login information from trusted location indication module 650. In some examples, it can send the CSI matrix to both training module 620 and matching engine 630, and send the user login information to training module 620. Furthermore, in some examples, AI engine 610 can process indications received from matching engine 630 and send an output signal (OS) to trusted location indication module 650. Trusted location indication module 650 can forward the OS to application 660, which manages connections to users and local assets.

[0069] In some examples, training module 620 can use the CSI matrix received from AI engine 610 to train an AI model based on machine learning. Training involves learning patterns in the CSI data related to user behavior, location, and / or other factors. Training module 620 can continuously update the model with new data, improving its accuracy over time. Furthermore, training module 620 can use user login information from AI engine 610 to enhance the AI ​​model's understanding of trusted locations and / or user behavior. In addition, in some examples, training module 620 can process and store the CSI matrix and user login data for future training iterations.

[0070] In some examples, the matching engine 630 can analyze the CSI matrix received from the AI ​​engine 610 to determine whether it matches patterns of trusted locations and / or authorized user behavior. It can use a trained model to evaluate the CSI data based on known patterns. Furthermore, the matching engine 630 can send instructions back to the AI ​​engine indicating whether the CSI data matches a trusted profile.

[0071] In some examples, the trusted location indication module 650 can receive user login information and CSI matrix analysis results from the AI ​​engine, and determine whether the user logged in from a trusted location based on the received data and indications from the matching engine. Furthermore, it can forward OS received from the AI ​​engine 610 to the application 660.

[0072] In some examples, application 660 can manage connections to both users and local assets, controlling access to sensitive data (e.g., encrypted files, encrypted wallets, and cryptographic libraries) based on received OS and instructions. File encryption can include health documents, top-secret documents, and / or defense documents. Application 660 can ensure that only users logged in from trusted locations or through authorized actions can access sensitive data, and implement necessary security measures based on information received from the trusted location instruction module 650.

[0073] In some examples, this trust decision model 600 can dynamically learn and adapt to new data, while providing secure and efficient access control based on the analysis of Wi-Fi CSI data and / or user behavior.

[0074] In some examples, multiple or all operations associated with access control and / or the generation and use of trust decision models, such as those related to... Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 and / or Figure 6 The associated operations can be performed by a controller, which can be the access point itself or another device separate from the access point.

[0075] Figure 7 A block diagram illustrating an example of device 700 is shown. At some point, application 700 may include interfaces 720, such as 720a and 720b, and processing circuitry 740. Device 700 may be configured to implement the reference based on cooperation between one or more tangible computer-readable (“machine-readable”) non-transitory storage media 750 and one or more processors 760 of processing circuitry 740. Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 and / or Figure 6 The description includes one or more examples, operations, and / or functions, and / or one or more operations associated with location-based access control described herein. The device 700 performs the above-described implementation when, for example, computer-executable instructions implemented by logic or computer program 770 are executed by one or more processors 760. In some examples, interface 720 is an interface device 720, and processing circuitry 740 is a processing device 740. In some examples, device 700 is included in a computer system 700A, which may include other devices.

[0076] In some examples, interface 720 is configured to capture a CSI matrix based on the user equipment's location, and processing circuitry 740 is configured to determine whether the captured CSI matrix matches a trusted location and to perform access control based on whether the captured CSI matrix matches a trusted location. In some examples, to determine whether the captured CSI matrix corresponds to one of the trusted locations, the processing circuitry is configured to input the captured CSI matrix or its features into a machine learning model, wherein the machine learning model is trained to predict the probability that the captured CSI matrix corresponds to one of the trusted locations. The machine learning model can be trained by device 700 or another device. In the example where the machine learning model is trained by device 700, processing circuitry 740 is configured to train the machine learning model based on ground truth pairs of the CSI matrix and trusted or untrusted locations.

[0077] In some examples, to provide input or verification for training, processing circuitry 740 is configured to classify the location of the user equipment as a trusted location if the user successfully logs into the wireless network at a location associated with the captured CSI matrix. Another way for processing circuitry 740 to provide input or verification may include asking the user to label the location of the user equipment as a trusted or untrusted location, or asking the user to verify predictions made by the machine learning model. Another approach may also include using user feedback to incrementally train the machine learning model. The aforementioned input or verification can be used both for initial training of the machine learning model and for incremental training after the machine learning model has been trained.

[0078] In some examples, interface 720 may include one or more wireless interfaces, including antennas such as MIMO antennas, and / or may include wired interfaces such as USB serial interfaces and / or RJ45 interfaces. A wireless interface with a MIMO antenna can be used as a receiver to capture a CSI matrix based on the location of the user equipment. A wired interface can be used as a receiver to capture a CSI matrix by receiving a CSI matrix from another device. The wireless interface is configured to transmit and / or receive Wi-Fi signals, 3GPP signals, and / or other wireless signals.

[0079] In some examples, one or more processors 760 may be a general-purpose CPU, a mobile processor, a server and data center processor, an embedded processor, a graphics processing unit (GPU), a dedicated processor, a microcontroller, a field-programmable gate array (FPGA), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an integrated circuit (IC), and / or other circuits capable of performing the operation of the controller in each example of this disclosure.

[0080] In some examples, the phrase “computer-readable non-transitory storage medium” can be directed to include all machine and / or computer-readable media, with the sole exception of transient propagation signals.

[0081] In some examples, storage medium 750 may include one or more types of computer-readable storage media capable of storing data, including volatile memory, non-volatile memory, removable or non-removable memory, erasable or non-erasable memory, writable or rewritable memory, etc. For example, storage medium 750 may include RAM, DRAM, double data rate DRAM (DDR-DRAM), SDRAM, static RAM (SRAM), ROM, programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), optical disc ROM (CD-ROM), recordable optical disc (CD-R), rewritable optical disc (CD-RW), flash memory (e.g., NOR or NAND flash memory), content addressable memory (CAM), polymer memory, phase change memory, ferroelectric memory, silicon-oxide-nitride-oxide-silicon (SONOS) memory, disk, floppy disk, hard disk drive, optical disc, magnetic disk, card, magnetic card, optical card, magnetic tape, cassette tape, etc. Computer-readable storage media can include any suitable media that involve downloading or transferring a computer program from a remote computer to a requesting computer via a communication link (e.g., a modem, radio, or network connection), the computer program being carried by data signals embodied in a carrier wave or other propagation medium.

[0082] In some examples, the logic or computer program 770 may include instructions, data, and / or code that, if executed by a machine (e.g., a machine implemented by one or more processors in the apparatus), can cause the machine to perform the methods, processes, and / or operations described herein, such as examples, operations, and / or functions, including those related to... Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 and / or Figure 6 Examples, operations, and / or functions of the associated access points, and / or related to Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 and / or Figure 6 Examples, operations, and / or functions of the associated controller. The machine may include, for example, any suitable processing platform, computing platform, computing device, processing device, computing system, processing system, computer, processor, etc., and may be implemented using any suitable combination of hardware, software, firmware, etc.

[0083] In some examples, each of components 720, 740, 750, 760, and 770 in device 700 is implemented by a corresponding means capable of performing the functions of the aforementioned components. In some examples, storage medium 750 is not included in device 700 because processor 760 can read logic or computer program 770 from storage medium outside device 700.

[0084] In some examples, the logic or computer program 770 may include or be implemented as: software, software module, application, program, subroutine, instruction, instruction set, computation code, word, value, symbol, etc. Instructions may include any suitable type of code, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, etc. Instructions may be implemented according to a predefined computer language, method, or syntax to instruct the processor to perform specific functions. Instructions may be implemented using any suitable high-level, low-level, object-oriented, visual, compiled, and / or interpreted programming language, such as C, C++, Java, BASIC, Matlab, Pascal, VisualBASIC, assembly language, machine code, etc.

[0085] In some examples, interface 720, storage medium 750, and processor 760 communicate with each other via a bus, and in some other examples, some of these entities have direct communication connections with each other.

[0086] Figure 8 A block diagram illustrating an example of device 800 is shown. Device 800 may include interfaces 820, such as 820a and 820b, and processing circuitry 840. Device 800 is configured to implement a reference based on cooperation between one or more tangible computer-readable (“machine-readable”) non-transitory storage media 850 and one or more processors 860 of processing circuitry 840. Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 and / or Figure 6 The description includes one or more examples, operations, and / or functions, and / or one or more operations described herein associated with generating and using trust decision models based on machine learning and / or statistical methods. The device 800 performs the above-described implementation when, for example, computer-executable instructions implemented by logic or computer program 870 are executed by one or more processors 860. In some examples, interface 820 is an interface device 820, and processing circuitry 840 is a processing device 840. In some examples, device 800 is included in a computer system 800A, which may include other devices.

[0087] In some examples, interface 820 is configured to capture a CSI matrix associated with one or more user equipments at one or more locations, and processing circuitry 840 is configured to generate a trust decision model based on the captured CSI matrix, wherein the trust decision model is used to determine whether the location from which the access request was sent is a trusted location.

[0088] In some examples, processing circuitry 840 is configured to generate a trust decision model based on machine learning methods. In other examples, processing circuitry 840 is configured to generate a trust decision model based on statistical methods. In still other examples, processing circuitry 840 is configured to generate a trust decision model based on both machine learning and statistical methods. In some examples associated with machine learning methods, the machine learning model is trained based on the CSI matrix and ground truth pairs of trusted or untrusted locations to generate the trust decision model.

[0089] In some examples, device 800 is configured to implement a method associated with method 400 for generating trust decision model 430 based on machine learning methods. Multiple CSI matrices 410 are captured by interface circuitry 820 and used by processing circuitry 840 as input to train the machine learning module to generate trust decision model 430.

[0090] In some examples, processing circuitry 840 is configured to implement method 500 for generating a trust decision model based on machine learning methods. Interface circuitry 820 is configured to capture a CSI matrix 510 based on one or more locations of one or more user devices, wherein one or more locations are marked as trusted or untrusted by one or more trusted users. In some examples, the capture performed by interface circuitry 820 refers to capture performed by an access point (e.g., a Wi-Fi router or a 3GPP base station). In other words, in these examples, device 800 is a Wi-Fi router or a 3GPP. In some other examples, capture refers to the interface circuitry 820 receiving a CSI matrix captured by one or more access points. In these examples, device 800 is a controller coupled to one or more access points via a wired or wireless connection. In some examples, the CSI matrix captured at 510 is... Figure 4 The associated CSI matrix 410.

[0091] In some examples, processing circuitry 840 is configured to generate a trust decision model by training a machine learning model based on ground truth pairs of the captured CSI matrix and the trust states associated with the CSI matrix. The ground truth pairs may include the CSI matrix and the trust states associated with the CSI matrix, where the trust states can be trusted or untrustworthy, and the trust states associated with the CSI matrix indicate whether the CSI matrix is ​​associated with trusted or untrustworthy locations. For example, Figure 4 The CSI matrix 410 in the table represents ground truth pairs because it includes both the 3×3 CSI matrix and the trust states 420. Based on these ground truth pairs, a trust decision model will be generated, for example... Figure 4 Model 430 in the text.

[0092] In some examples, after generating the trust decision model, the trust decision model can perform access control on the user equipment (UE) based on the captured CSI matrix associated with the UE. Access control is based on the trust decision model's prediction of whether the UE is in a trusted or untrusted location. The CSI matrix associated with the UE refers to a CSI matrix based on the UE's location. In some examples, processing circuitry 840 is configured to classify the UE's location as a trusted location when the UE's user successfully logs into the wireless network at a location associated with the captured CSI matrix. Based on this classification, new ground truth pairs are generated, including the captured CSI matrix and a trust state indicating a trusted location. Processing circuitry 840 uses these new ground truth pairs as input to incrementally train a machine learning model, thereby improving the trust decision model.

[0093] In some examples, processing circuitry 840 is configured to either require a trusted user to mark the location of a user device as trusted or untrusted, or require the trusted user to verify a prediction made by a machine learning model. In some examples, the trusted user can be a user predicted by the trust decision model to be located at a trusted location, and / or a user trusted based on one or more conventional security measures. Based on the trusted user's marking action, processing circuitry 840 generates a trust state associated with the location. Therefore, the CSI matrix of this location, identified as trusted or untrusted, can be used by processing circuitry 840 to further train the machine learning model, which will further improve the trust decision model. In another example, where the trusted user is required to verify a prediction made by the machine learning model, the verification made by the trusted user will be used by processing circuitry 840 to train the machine learning model. If the verification indicates the prediction is correct, the machine learning model can be trained by processing circuitry 840 to make the same prediction for the same or similar further situations; if the verification indicates the prediction is incorrect, the machine learning model can be trained by processing circuitry 840 to make the opposite prediction for the same or similar further situations. Based on operation 840, the accuracy of the trust decision model will be further improved. Since operations 530 and 540 are not mutually exclusive in many cases, the trust decision-making model can be improved by operations 530 and / or 540.

[0094] In some examples, interface 820 may include one or more wireless interfaces, including antennas such as MIMO antennas, and / or may include wired interfaces such as USB serial interfaces and / or RJ45 interfaces. A wireless interface with a MIMO antenna can be used as a receiver to capture a CSI matrix based on the location of the user equipment. A wired interface can be used as a receiver to capture a CSI matrix by receiving a CSI matrix from another device. The wireless interface is configured to transmit and / or receive Wi-Fi signals, 3GPP signals, and / or other wireless signals.

[0095] In some examples, one or more processors 860 may be a general-purpose CPU, a mobile processor, a server and data center processor, an embedded processor, a graphics processing unit (GPU), a dedicated processor, a microcontroller, a field-programmable gate array (FPGA), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an integrated circuit (IC), and / or other circuits capable of performing the operation of the controller in each example of this disclosure.

[0096] In some examples, the phrase “computer-readable non-transitory storage medium” can be directed to include all machine and / or computer-readable media, with the sole exception of transient propagation signals.

[0097] In some examples, storage medium 850 may include one or more types of computer-readable storage media capable of storing data, including volatile memory, non-volatile memory, removable or non-removable memory, erasable or non-erasable memory, writable or rewritable memory, etc. For example, storage medium 850 may include RAM, DRAM, double data rate DRAM (DDR-DRAM), SDRAM, static RAM (SRAM), ROM, programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), optical disc ROM (CD-ROM), recordable optical disc (CD-R), rewritable optical disc (CD-RW), flash memory (e.g., NOR or NAND flash memory), content-addressable memory (CAM), polymer memory, phase-change memory, ferroelectric memory, silicon-oxide-nitride-oxide-silicon (SONOS) memory, disk, floppy disk, hard disk drive, optical disc, magnetic disk, card, magnetic card, optical card, magnetic tape, cassette tape, etc. Computer-readable storage media can include any suitable media that involve downloading or transferring a computer program from a remote computer to a requesting computer via a communication link (e.g., a modem, radio, or network connection), the computer program being carried by data signals embodied in a carrier wave or other propagation medium.

[0098] In some examples, the logic or computer program 870 may include instructions, data, and / or code that, if executed by a machine (e.g., a machine implemented by one or more processors in the apparatus), can cause the machine to perform the methods, processes, and / or operations described herein, such as examples, operations, and / or functions, including those related to... Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 and / or Figure 6 Examples, operations, and / or functions of the associated access points, and / or related to Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 and / or Figure 6 Examples, operations, and / or functions of the associated controller. The machine may include, for example, any suitable processing platform, computing platform, computing device, processing device, computing system, processing system, computer, processor, etc., and may be implemented using any suitable combination of hardware, software, firmware, etc.

[0099] In some examples, each of components 820, 840, 850, 860, and 870 in device 800 is implemented by a corresponding means capable of performing the functions of the aforementioned components. In some examples, storage medium 850 is not included in device 800 because processor 860 can read logic or computer program 870 from storage medium outside device 800.

[0100] In some examples, the logic or computer program 870 may include or be implemented as: software, software module, application, program, subroutine, instruction, instruction set, computation code, word, value, symbol, etc. Instructions may include any suitable type of code, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, etc. Instructions may be implemented according to a predefined computer language, method, or syntax to instruct the processor to perform specific functions. Instructions may be implemented using any suitable high-level, low-level, object-oriented, visual, compiled, and / or interpreted programming language, such as C, C++, Java, BASIC, Matlab, Pascal, VisualBASIC, assembly language, machine code, etc.

[0101] In some examples, interface 820, storage medium 850, and processor 860 communicate with each other via a bus, and in some other examples, some of these entities have direct communication connections with each other.

[0102] This disclosure relates to methods and systems for location-based access control in wireless networks. The core idea is to utilize a CSI matrix to determine the location of a device, reflecting the characteristics of the wireless communication channel between the user equipment and the access point. This information is used to assess whether the user equipment is in a "trusted" or "untrusted" location. The system can employ machine learning models or statistical comparisons to match the captured CSI matrix with known matrices from trusted locations. If a match is found, the system authorizes access; otherwise, access is denied or restricted. This method aims to enhance security by leveraging the unique properties of wireless signals associated with a device's specific location, providing a more accurate and convenient alternative to traditional methods such as password-based authentication. The proposed concept can be applied to various scenarios, including secure access to sensitive data, where it can complement or replace other security measures.

[0103] The following text will present some examples of the proposed concepts.

[0104] Example (e.g., Example 1) relates to a method (200) for location-based access control in a wireless network, the method comprising capturing (210) a Channel State Information (CSI) matrix based on the location of a user equipment. The method includes determining (220) whether the captured CSI matrix matches a trusted location. The method further includes performing (230) access control based on whether the captured CSI matrix matches a trusted location.

[0105] Examples (e.g., Example 2) relate to previously described examples (e.g., Example 1) or any examples described herein, wherein determining whether a captured CSI matrix matches a trusted location includes: inputting the captured CSI matrix or features thereof into a machine learning model trained to predict the probability that the captured CSI matrix corresponds to one of the trusted locations.

[0106] Examples (e.g., Example 3) relate to previously described examples (e.g., Example 2) or any of the examples described herein, wherein the machine learning model includes an artificial neural network or a support vector machine (SVM) trained to determine whether the CSI matrix corresponds to a reliable location.

[0107] Examples (e.g., Example 4) refer to previously described examples (e.g., Example 2 or 3) or any examples described herein, and the method further includes training the machine learning model based on the CSI matrix and ground truth pairs of trusted or untrusted locations.

[0108] Examples (e.g., Example 5) relate to previously described examples (e.g., Example 4) or any of the examples described herein, wherein training the machine learning model includes classifying the location of the user device as a trusted location if the user successfully logs into the wireless network at a location associated with the captured CSI matrix.

[0109] Examples (e.g., Example 6) relate to previously described examples (e.g., Example 4 or 5) or any of the examples described herein, wherein training the machine learning model includes: asking a trusted user to mark the location of the user device as a trusted or untrusted location, or asking a trusted user to verify the predictions made by the machine learning model; and using the feedback from the trusted user to incrementally train the machine learning model.

[0110] Examples (e.g., Example 7) relate to previously described examples (e.g., Example 1) or any of the examples described herein, wherein determining whether a captured CSI matrix matches a trusted location includes: determining one or more statistical properties of the captured CSI matrix. The method further includes: comparing the one or more statistical properties with corresponding statistical properties of CSI matrices corresponding to a plurality of trusted locations using a similarity metric.

[0111] Examples (e.g., Example 8) refer to previously described examples (e.g., Example 7) or any examples described herein, wherein the statistical property includes at least one of mean, variance, and covariance.

[0112] Examples (e.g., Example 9) refer to previously described examples (e.g., Example 7 or 8) or any examples described herein, wherein the similarity measure includes one of Euclidean distance, Mahalanobis distance, or correlation coefficient.

[0113] Examples (e.g., Example 10) relate to previously described examples (e.g., one of Examples 2 to 9) or any of the examples described herein, wherein performing access control includes: authorizing access to the wireless network if the captured CSI matrix matches a trusted location. Performing access control also includes: denying access if the captured CSI matrix does not match a trusted location.

[0114] Examples (e.g., Example 11) relate to previously described examples (e.g., one of Examples 2 to 10) or any of the examples described herein, wherein the CSI matrix is ​​associated with Wi-Fi signals and / or 3GPP radio signals.

[0115] Examples (e.g., Example 12) relate to previously described examples (e.g., one of Examples 2 to 10) or any of the examples described herein, wherein capturing (210) the CSI matrix includes: capturing the CSI matrix by the firmware of the access point, or receiving the CSI matrix from the access point by the controller.

[0116] Example (e.g., Example 13) relates to a method (300) for generating a trust decision model. The method includes capturing (310) a CSI matrix associated with one or more user equipments at one or more locations. The method also includes generating (320) the trust decision model based on the captured CSI matrix, wherein the trust decision model is used to determine whether the location from which the access request is sent is a trusted location.

[0117] Examples (e.g., Example 14) relate to previously described examples (e.g., Example 13) or any of the examples described herein, wherein generating the trust decision model includes training a machine learning model (410) based on the CSI matrix and ground truth pairs of trusted or untrusted locations.

[0118] Examples (e.g., Example 15) refer to previously described examples (e.g., Example 14) or any of the examples described herein, wherein training the machine learning model includes classifying the location of the user equipment as a trusted location if the user successfully logs into the wireless network at a location associated with the captured CSI matrix.

[0119] Examples (e.g., Example 16) relate to previously described examples (e.g., Example 14 or 15) or any of the examples described herein, wherein training the machine learning model includes: asking a user to label the location of the user device as a trusted or untrusted location, or asking a user to verify predictions made by the machine learning model. Training the machine learning model also includes: incrementally training the machine learning model using the user's feedback.

[0120] Examples (e.g., Example 17) relate to previously described examples (e.g., Example 13) or any of the examples described herein, wherein generating the trust decision model includes storing one or more statistical properties of the respective CSI matrices corresponding to trusted locations.

[0121] Examples (e.g., Example 18) refer to the previously described examples (e.g., one of Examples 13 to 17) or any of the examples described herein, wherein the trust decision model is based on an artificial neural network or a support vector machine (SVM).

[0122] Examples (e.g., Example 19) relate to previously described examples (e.g., one of Examples 13 to 18) or any of the examples described herein, wherein capturing (310) the CSI matrix includes: capturing the CSI matrix by the firmware of the access point, or receiving the CSI matrix from the access point by the controller.

[0123] An example (e.g., Example 20) relates to an apparatus (700) including an interface (720) and processing circuitry (740). The apparatus (700) includes machine-readable instructions (770). The processing circuitry (740) is configured with a trusted execution environment to execute the machine-readable instructions (770) within the trusted execution environment, thereby performing the method according to one of Examples 1 to 12.

[0124] Examples (e.g., Example 21) relate to an apparatus (800) including an interface (820) and processing circuitry (840). The apparatus (800) includes machine-readable instructions (870). The processing circuitry (840) is configured with a trusted execution environment to execute the machine-readable instructions (870) within the trusted execution environment, thereby performing the method according to any one of Examples 13 to 19.

[0125] An example (e.g., Example 22) relates to an apparatus (700) for access control based on the location of a user equipment. The apparatus includes an interface (720) and processing circuitry (740). The interface (720) is configured to capture a Channel State Information (CSI) matrix based on the location of the user equipment. The processing circuitry (740) is configured to determine whether the captured CSI matrix matches a trusted location. The processing circuitry (740) is also configured to perform access control based on whether the captured CSI matrix matches a trusted location.

[0126] An example (e.g., Example 23) relates to an apparatus (800) for generating a trust decision model. The apparatus includes an interface (820) and processing circuitry (840). The interface (820) is configured to capture a CSI matrix associated with one or more user equipments at one or more locations. The processing circuitry (840) is configured to generate the trust decision model based on the captured CSI matrix, wherein the trust decision model is used to determine whether the location from which the access request was sent is a trusted location.

[0127] Examples (e.g., Example 24) relate to a system including the apparatus (700) according to Example 20 or 22.

[0128] Examples (e.g., Example 25) relate to a system including the apparatus (800) according to Example 21 or 23.

[0129] An example (e.g., Example 26) relates to an apparatus (700) for access control based on the location of a user equipment. The apparatus includes an interface device (720) and a processing device (740). The interface device (720) is used to capture a Channel State Information (CSI) matrix based on the location of the user equipment. The processing device (740) is used to determine whether the captured CSI matrix matches a trusted location. The processing device (740) is also used to perform access control based on whether the captured CSI matrix matches a trusted location.

[0130] An example (e.g., Example 27) relates to an apparatus (800) for access control based on the location of a user equipment. The apparatus includes an interface device (820) and a processing device (840). The interface device (820) is used to capture a CSI matrix associated with one or more user equipments at one or more locations. The processing device (840) is used to generate a trust decision model based on the captured CSI matrix, wherein the trust decision model is used to determine whether the location from which the access request is sent is a trusted location.

[0131] Examples (e.g., Example 28) relate to a system including the apparatus (700) according to Example 26 or any other example.

[0132] Examples (e.g., Example 29) relate to a system including the apparatus (800) according to Example 27 or any other example.

[0133] Examples (e.g., Example 30) relate to a computer system comprising one of the following: the apparatus (700) of Example 20 (or according to any other example), the apparatus (700) of Example 22 (or according to any other example), or the apparatus (700) of Example 26 (or according to any other example).

[0134] Examples (e.g., Example 31) relate to a computer system comprising one of the following: the apparatus (800) of Example 21 (or according to any other example), the apparatus (800) of Example 23 (or according to any other example), or the apparatus (800) of Example 27 (or according to any other example).

[0135] Examples (e.g., Example 32) relate to a computer system configured to perform the methods of one of Examples 1 to 12 (or according to any other example).

[0136] Examples (e.g., Example 33) relate to a computer system configured to perform the methods of one of Examples 13 to 19 (or according to any other example).

[0137] Examples (e.g., Example 34) relate to a non-transitory machine-readable storage medium including program code that, when executed, causes a machine to perform a method of one of Examples 1 to 12 (or according to any other example), or a method of one of Examples 13 to 19 (or according to any other example).

[0138] Examples (e.g., Example 35) relate to a computer program having program code that, when executed on a computer, processor, or programmable hardware component, performs a method of one of Examples 1 to 12 (or according to any other example) or a method of one of Examples 13 to 19 (or according to any other example).

[0139] Examples (e.g., Example 36) relate to a machine-readable storage device that includes machine-readable instructions that, when executed, implement the method or apparatus as claimed in any pending claim or shown in any example.

[0140] The aspects and features described in a particular example from the previous examples can also be combined with one or more further examples to replace the same or similar features of the further examples, or to introduce those features additionally into the further examples.

[0141] The examples may further be or relate to a (computer) program including program code that, when executed on a computer, processor, or other programmable hardware component, performs one or more of the methods described above. Therefore, the steps, operations, or processes of the different methods described above may also be performed by a programmed computer, processor, or other programmable hardware component. The examples may also cover program storage devices, such as digital data storage media, which are machine-, processor-, or computer-readable and encoded and / or contain machine-executable, processor-executable, or computer-executable programs and instructions. For example, a program storage device may include or be a digital storage device, magnetic storage media (e.g., disks and tapes), hard disk drives, or optically readable digital data storage media. Other examples may include computers, processors, control units, (field-programmable arrays) ((F)PLAs), (field-programmable gate arrays) ((F)PGAs), graphics processing units (GPUs), application-specific integrated circuits (ASICs), integrated circuits (ICs), or system-on-a-chip (SoC) systems programmed to perform the steps of the methods described above.

[0142] It should also be understood that the disclosure of several steps, processes, operations, or functions in the specification or claims should not be construed as implying that these operations necessarily depend on the described order, unless explicitly stated in individual cases or necessary for technical reasons. Therefore, the preceding description does not limit the execution of several steps or functions to a specific order. Furthermore, in further examples, a single step, function, process, or operation may include and / or may be decomposed into several sub-steps, sub-functions, sub-processes, or sub-operations.

[0143] If aspects have already been described regarding a device or system, then those aspects should also be understood as descriptions of the corresponding method. For example, a block, device, or functional aspect of a device or system may correspond to a feature of the corresponding method (e.g., method steps). Therefore, aspects described regarding a method should also be understood as descriptions of corresponding blocks, elements, attributes, or functional features of the corresponding device or system.

[0144] As used herein, the term "module" refers to logic implemented in a hardware component or device, software or firmware running on a processing unit, or a combination thereof, for performing one or more operations consistent with this disclosure. Software and firmware may be embodied as instructions and / or data stored on a non-transitory computer-readable storage medium. As used herein, the term "circuit" may, individually or in any combination, include non-programmable (hard-wired) circuitry, programmable circuitry (e.g., a processing unit), state machine circuitry, and / or firmware storing instructions executable by programmable circuitry. Modules described herein may be embodied collectively or individually as circuitry forming part of a computing system. Thus, any module can be implemented as a circuit. A computing system, referred to as being programmed to perform a method, can be programmed to perform that method via software, hardware, firmware, or a combination thereof.

[0145] Any disclosed method (or a portion thereof) may be implemented as computer-executable instructions or a computer program product. Such instructions may cause a computing system or one or more processing units capable of executing computer-executable instructions to perform any disclosed method. As used herein, the term "computer" means any computing system or device described or mentioned herein. Therefore, the term "computer-executable instructions" means instructions that can be executed by any computing system or device described or mentioned herein.

[0146] Computer-executable instructions can be, for example, part of an operating system of a computing system, an application stored locally on the computing system, or a remote application accessible to the computing system (e.g., via a web browser). Any method described herein can be executed by computer-executable instructions, which can be executed by a single computing system or by one or more networked computing systems operating in a network environment. Computer-executable instructions, and updates to them, can be downloaded to the computing system from a remote server.

[0147] Furthermore, it should be understood that the implementation of the disclosed technology is not limited to any particular computer language or program. For example, the disclosed technology can be implemented using software written in programming languages ​​such as C++, C#, Java, Perl, Python, JavaScript, Adobe Flash, assembly language, or any other programming language. Similarly, the disclosed technology is not limited to any particular computer system or hardware type.

[0148] Furthermore, any software-based example (e.g., including computer-executable instructions for causing a computer to perform any of the disclosed methods) can be uploaded, downloaded, or remotely accessed via suitable means of communication. Such suitable means of communication include, for example, the Internet, the World Wide Web, intranets, cable (including fiber optic cables), magnetic communication, electromagnetic communication (including RF, microwave, ultrasonic, and infrared communication), electronic communication, or other such means of communication.

[0149] The disclosed methods, apparatuses, and systems should not be construed as limiting in any way. Rather, this disclosure is directed toward all novel and non-obvious features and aspects of the various disclosed examples, whether individually or in various combinations and sub-combinations with each other. The disclosed methods, apparatuses, and systems are not limited to any particular aspect, feature, or combination thereof, nor are the disclosed examples required to have any one or more particular advantages or to solve any one or more particular problems.

[0150] The operational theories, scientific principles, or other theoretical descriptions presented herein regarding the apparatus or methods of this disclosure are provided for better understanding and are not intended to be limiting. The apparatuses and methods in the appended claims are not limited to those that operate in a manner described by such operational theories.

[0151] The appended claims are hereby incorporated into the detailed description, wherein each claim may stand alone as a separate example. It should also be noted that although in the claims, a dependent claim refers to a specific combination with one or more other claims, other examples may also include combinations of the subject matter of that dependent claim with the subject matter of any other dependent or independent claim. Such combinations are hereby expressly suggested unless it is stated in individual cases that such a combination was not intended. Furthermore, the features of a claim should also be included in any other independent claim, even if that claim is not directly defined as dependent on that other independent claim.

Claims

1. A system comprising a device, wherein, The apparatus comprises an interface, processing circuitry, and machine-readable instructions, wherein the processing circuitry is configured with a trusted execution environment to execute the machine-readable instructions within the trusted execution environment to perform a method for location-based access control in a wireless network, wherein the method comprises: capturing a channel state information, CSI, matrix based on a location of a user equipment; determining whether the captured CSI matrix matches a trusted location; and performing access control based on whether the captured CSI matrix matches a trusted location.

2. The system of claim 1, wherein, Determining whether the captured CSI matrix matches a trusted location comprises: inputting the captured CSI matrix or a feature thereof into a machine learning model trained to predict a likelihood that the captured CSI matrix corresponds to one of the trusted locations.

3. The system of claim 2, wherein, The machine learning model comprises an artificial neural network or a support vector machine, SVM, trained to determine whether a CSI matrix corresponds to a trusted location.

4. The system of claim 2 or 3, further comprising: training the machine learning model based on pairs of CSI matrices and ground truth labels of trusted or untrusted locations.

5. The system of claim 4, wherein, Training the machine learning model comprises: classifying a location of the user equipment as a trusted location if a user successfully logs into the wireless network at the location associated with the captured CSI matrix.

6. The system of claim 4 or 5, wherein, Training the machine learning model comprises: asking a trusted user to label locations of the user equipment as trusted or untrusted locations, or asking the trusted user to verify predictions made by the machine learning model; and incrementally training the machine learning model using feedback from the trusted user.

7. The system of claim 1, wherein, Determining whether the captured CSI matrix matches a trusted location comprises: determining one or more statistical properties of the captured CSI matrix; and comparing the one or more statistical properties to respective statistical properties of CSI matrices corresponding to a plurality of trusted locations using a similarity measure.

8. The system of claim 7, wherein, The statistical properties comprise at least one of a mean, a variance, and a covariance.

9. The system of claim 7 or 8, wherein, The similarity measure comprises one of a Euclidean distance, a Mahalanobis distance, or a correlation coefficient.

10. The system of claim 1, wherein, Performing access control comprises: authorizing access to the wireless network if the captured CSI matrix matches a trusted location; and denying access if the captured CSI matrix does not match a trusted location.

11. The system of claim 1, wherein, The CSI matrix is associated with Wi-Fi signals and / or Third Generation Partnership Project, 3GPP, wireless signals.

12. The system of claim 1, wherein, The capturing the CSI matrix comprises capturing the CSI matrix by firmware of an access point or receiving the CSI matrix from an access point by a controller.

13. A system comprising a device, wherein, The apparatus comprises an interface, processing circuitry, and machine-readable instructions, wherein the processing circuitry is configured with a trusted execution environment to execute the machine-readable instructions within the trusted execution environment to perform a method for generating a trust decision model, wherein the method comprises: capturing CSI matrices associated with one or more user equipments at one or more locations; and training a machine learning model based on the captured CSI matrices and ground truth labels of trusted or untrusted locations. generating the trust decision model based on the captured CSI matrices, wherein the trust decision model is used to determine whether a location from which an access request is sent is a trusted location.

14. The system of claim 13, wherein, generating the trust decision model includes: training a machine learning model based on CSI matrices and ground truth pairs of trusted or untrusted locations.

15. The system of claim 14, wherein, training the machine learning model includes: classifying a location of the user device as a trusted location if a user successfully logs into the wireless network at a location associated with a captured CSI matrix.

16. The system of claim 14 or 15, wherein, training the machine learning model includes: asking the user to label a location of the user device as a trusted or untrusted location, or asking the user to verify a prediction made by the machine learning model; and incrementally training the machine learning model using feedback from the user.

17. The system of any one of claims 13 to 15, wherein, generating the trust decision model includes: storing one or more statistical properties of individual CSI matrices corresponding to trusted locations.

18. The system of any one of claims 13 to 15, wherein, the trust decision model is based on an artificial neural network or a support vector machine (SVM).

19. The system of any one of claims 13 to 15, wherein, the capturing of CSI matrices includes capturing the CSI matrices by firmware of an access point, or receiving the CSI matrices from an access point by a controller.

20. A non-transitory machine-readable storage medium comprising program code, wherein, the program code, when executed, causes a machine to perform a method for location-based access control in a wireless network, the method comprising: capturing a CSI matrix based on a location of a user device; determining whether the captured CSI matrix matches a trusted location; and performing access control based on whether the captured CSI matrix matches a trusted location.

21. A method for generating a trust decision model, the method comprising: capturing CSI matrices associated with one or more user devices at one or more locations; and generating the trust decision model based on the captured CSI matrices, wherein the trust decision model is used to determine whether a location from which an access request is sent is a trusted location.