Wi-Fi Access Point Geo-Fencing for Out-of-Bounds Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wi-Fi networks face vulnerabilities due to their broadcast nature, allowing unauthorized access beyond the transmission boundary, which existing security measures like encryption and passwords cannot effectively address.

Innovation Solution

An access point computes the location of stations relative to a geo-fence using sounding data, channel state information, beamforming matrix, or round trip timing, and adjusts network access based on this location to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Area of stationary object

If Wi-Fi networks use broadcast transmission to extend coverage area, then the area of network coverage is improved, but network security deteriorates because devices beyond the transmission boundary can access the network

Engineering Contradiction:
Improvenetwork coverage areaVSAvoidnetwork security
Core Design Contradiction:
Area of stationary objectVSReliability

Solution Approach 1:

The patent segments the network access control into location-based zones using geo-fencing technology. The access point divides the coverage area into authorized and unauthorized zones, granting network access only to devices within the defined geo-fenced area while blocking access from devices outside this boundary, thus maintaining security despite extended coverage

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces location information and geo-fence data as an intermediary layer between the broadcast transmission and network access control. The access point uses sounding data, CSI, beamforming matrix, or RTT to determine device location, and this location information acts as a mediator to decide whether to grant or deny network access, preventing unauthorized devices from accessing the network even when within broadcast range

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If Wi-Fi networks implement traditional security measures like encryption and passwords, then network security is improved to some extent, but vulnerabilities remain due to the broadcast nature of Wi-Fi that allows access beyond transmission boundaries

Engineering Contradiction:
Improvenetwork securityVSAvoidunauthorized access vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary location verification before granting network access. The access point calculates the location of each device relative to the geo-fence using sounding data, CSI, beamforming matrix, or RTT measurements before allowing connection. This preliminary check prevents unauthorized devices from accessing the network in the first place, addressing the vulnerability of traditional security measures that only protect after connection is attempted

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the access control parameter from authentication credentials (passwords, encryption keys) to spatial parameters (location coordinates, geo-fence boundaries). By using location-based parameters to control network access, the system fundamentally changes how security is enforced, making it impossible for devices outside the authorized area to connect regardless of their security credentials

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250317890A1Location-based security for wi-fi networks
Publication Date: 2025.10.09 MAXLINEAR INC
  • US20250317890A1 patent drawing
  • US20250317890A1 patent drawing
  • US20250317890A1 patent drawing

AI summary

An access point (AP) may include a processing device. The processing device may identify, at the AP, one or more of sounding data, channel state information (CSI), beamforming matrix, or round trip timing (RTT) for a station (STA). The processing device may compute, at the AP, a location for the STA based on the one or more of the sounding data, the CSI, the beamforming matrix, or the RTT in which the location may be computed relative to a geo-fence. The processing device may compute, at the AP, a network access for the STA based on the location relative to the geo-fence.