Location-Based Access Control Lists for Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional access-control techniques face challenges in securely allowing devices to join wireless networks without sharing Wi-Fi credentials and can be vulnerable to unauthorized access when using methods like Wi-Fi Protected Setup (WPS), which temporarily opens the network to all devices within range.

Innovation Solution

The system manages location-based access control lists by identifying and authenticating authorized users within a physical space, using monitoring devices to capture user activity data such as photographs or audio recordings to determine the user's intent and location, and modifying access rights for target devices accordingly, allowing secure addition to the network without sharing credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If Wi-Fi credentials are shared with a new device to enable network access, then the device can join the wireless network, but the user loses control over subsequent access and must change credentials to revoke access

Engineering Contradiction:
Improveease of device additionVSAvoidnetwork security control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the access control process by creating location-specific access control lists for different physical spaces. Each location has its own ACL that can be independently managed, allowing credentials to be shared for network access while maintaining granular control over which devices can access which locations. This resolves the contradiction by enabling easy device addition through location-based ACL modification without compromising overall network security control.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If WPS is enabled to allow devices to connect within a time window, then device joining is simplified, but the network becomes vulnerable to unauthorized access from any device within range

Engineering Contradiction:
Improveease of device connectionVSAvoidunauthorized access vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by implementing location-based access control where different physical spaces have different ACLs with different device permissions. When a device connects through WPS, the system determines its physical location and applies the appropriate location-specific ACL, allowing legitimate devices to access only their designated areas while preventing unauthorized access to other locations. This resolves the vulnerability by making access rights location-dependent rather than network-wide.

Inventive Principle:
Principle #3Local quality

3Productivity

If traditional access control methods are used, then network access can be granted, but the process requires manual credential sharing and updates across multiple devices

Engineering Contradiction:
Improveaccess management efficiencyVSAvoidcredential management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling users to point a monitoring device at a target device to automatically initiate the ACL modification process. The system automatically detects the target device, determines its location, and modifies the appropriate location-based ACL without requiring manual credential sharing or configuration. This resolves the contradiction by automating the access management process, improving productivity while reducing the complexity of credential management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10924496B1Systems and methods for managing location-based access control lists
Publication Date: 2021.02.16 GEN DIGITAL INC
  • US10924496B1 patent drawing
  • US10924496B1 patent drawing
  • US10924496B1 patent drawing

AI summary

The disclosed computer-implemented method for managing location-based access control lists may include (i) identifying a collection of devices that are located within a physical space, (ii) determining, based on user activity data received from the collection of devices, that an authorized user is attempting to modify, on a location-based access control list for a wireless network, the access rights of a target computing device near a location indicated by the authorized user in the physical space, (iii) detecting, based on the user activity data, the target computing device near the location indicated by the authorized user, and (iv) in response to detecting the target computing device indicated by the authorized user, modifying, on the location-based access control list, the access rights of the target computing device. Various other methods, systems, and computer-readable media are also disclosed.