Secure 802.11 Localization via Desktop Token Power Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless network technologies are unable to accurately determine the location of untrusted users with high granularity, making it difficult to prevent spoofing and collusion.
Innovation Solution
The system uses wireless-capable desktop computers to broadcast tokens at different power levels, allowing an Access Point Controller to determine the location of untrusted users through a two-phase process of macro and pico localization, where tokens are generated and compared against location profiles to refine the user's location.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If wireless networks use traditional location determination methods, then the system is simple to implement, but the location accuracy and granularity are insufficient
Solution Approach 1:
The patent divides location determination into two distinct phases: macro-location phase (using access points) and micro-location phase (using desktop computers). This segmentation allows the system to achieve high location accuracy through multiple measurement points while managing complexity by performing detailed measurements only when necessary, rather than continuously throughout the entire network.
Solution Approach 2:
The patent implements a preliminary macro-location determination phase that uses access points to establish a general location before proceeding to more detailed micro-location measurement. This preliminary action filters out obviously incorrect locations and establishes a search area, thereby reducing the complexity of subsequent detailed measurements and enabling high accuracy without requiring all measurements to be performed simultaneously.
2Measurement precision
If the system uses multiple access points for location determination, then location accuracy improves, but the system becomes more vulnerable to spoofing and collusion attacks
Solution Approach 1:
The patent introduces desktop computers as intermediary devices between the client and the access points. These intermediaries perform the actual location measurements and token generation, creating an additional layer of verification. The controller receives measurements from multiple intermediaries and must determine consistency, making spoofing attempts more difficult while maintaining the benefits of multiple measurement points.
Solution Approach 2:
The patent implements a feedback mechanism where the controller receives location measurements from multiple desktop computers, verifies their consistency, and only accepts measurements that pass validation. This feedback loop allows the system to detect and reject spoofed or collusive measurements while maintaining high location accuracy through the aggregated data from multiple sources.
3Measurement precision
If the system performs detailed location measurements continuously, then location accuracy is maintained, but the network overhead and processing time increase
Solution Approach 1:
The patent segments location determination into macro and micro phases, performing detailed measurements only when necessary. The macro phase provides quick general location information, and only when needed does the system transition to the more time-consuming micro phase with desktop computers. This segmentation significantly reduces average measurement time while maintaining accuracy when required.
Solution Approach 2:
The patent applies partial action by performing detailed micro-location measurements only for clients that require high precision, rather than continuously for all clients. The system uses macro-location data as a baseline and only initiates time-consuming detailed measurements when the macro location indicates potential issues or when high precision is explicitly needed, thereby reducing overall measurement time while maintaining accuracy where necessary.
Data Source
AI summary
A system and method that uses wireless-capable desktop computers in a vicinity such as to enable one to securely determine the location of an untrusted user with office level granularity.


