Wireless Access Control via RF Fingerprinting and Location

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless networks face challenges in differentiating between authorized and unauthorized users, as existing security measures cannot flexibly manage access privileges based on user location and credentials, leading to potential unauthorized access.

Innovation Solution

The access point determines network access privileges based on device ID, physical location, and user credentials, dynamically adjusting privileges through a criteria set, which can include access to specific network portions, bandwidth restrictions, and quality of service, using an access server and VLAN tagging to enforce these settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If WEP key encoding is used to enhance wireless network security, then network security is improved, but the system cannot flexibly differentiate between authorized and unauthorized users based on location and credentials

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess privilege differentiation
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by implementing location-specific access privileges where different physical locations within the wireless coverage area have different access policies. The system determines the client's physical location using RF fingerprinting and signal strength comparison, then applies location-appropriate privilege sets that grant or deny access to specific network resources based on where the client is physically situated.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamics by making access privileges dynamic rather than static. The system continuously monitors the wireless client's location and automatically adjusts access privileges in real-time as the client moves between different locations. This dynamic adjustment allows the same client to have different access rights at different times and places, resolving the contradiction between security and adaptability.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If the wireless network allows broad access for simplicity and mobility, then ease of operation is improved, but unauthorized persons can attach to the network

Engineering Contradiction:
Improvewireless connectivityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary access control system that sits between the wireless client and the network resources. This intermediary automatically evaluates the client's location, device ID, and credentials against predefined privilege sets, and enforces appropriate access controls. This intermediary mechanism maintains ease of wireless connectivity for authorized users while automatically blocking unauthorized access without requiring users to manually configure security settings.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If location tracking is implemented to prevent unauthorized access, then network security is improved, but device complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the wireless clients to autonomously determine their own physical location through RF fingerprinting and signal strength comparison with access points. Each client independently compares its received signal characteristics against a pre-stored database of location signatures, allowing the system to implement location-based access control without requiring complex centralized tracking infrastructure or additional hardware on client devices.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7551574B1Method and apparatus for controlling wireless network access privileges based on wireless client location
Publication Date: 2009.06.23 TRAPEZE NETWORKS INC
  • US7551574B1 patent drawing
  • US7551574B1 patent drawing
  • US7551574B1 patent drawing

AI summary

An access point through which a wireless device attaches to a wireless network determines the access privileges that will be accorded to the device based on a criteria set, such as the ID and physical location of the device requesting network access, the access point through which the device is connected to the network and user credentials. The location of the device is determined by a location determination system using the signal strength of the device signal. The location information and ID information is provided to an access server that uses the criteria set to retrieve access privileges from a privilege database. The retrieved access privileges are then applied to the wireless device by means of the access point and other devices in the wireless network.