US2009293106A1PendingUtilityA1

Method and apparatus for controlling wireless network access privileges based on wireless client location

Assignee: TRAPEZE NETWORKS INCPriority: Mar 31, 2005Filed: May 28, 2009Published: Nov 26, 2009
Est. expiryMar 31, 2025(expired)· nominal 20-yr term from priority
H04W 12/08H04W 12/06H04L 12/4641H04L 63/107H04L 63/102H04L 63/108H04L 63/0876H04L 63/0254H04W 12/79
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An access point through which a wireless device attaches to a wireless network determines the access privileges that will be accorded to the device based on a criteria set, such as the ID and physical location of the device requesting network access, the access point through which the device is connected to the network and user credentials. The location of the device is determined by a location determination system using the signal strength of the device signal. The location information and ID information is provided to an access server that uses the criteria set to retrieve access privileges from a privilege database. The retrieved access privileges are then applied to the wireless device by means of the access point and other devices in the wireless network.

Claims

exact text as granted — not AI-modified
1 . A method for controlling access privileges in a wireless network based on the location of a wireless client that is connected to the network via radio-frequency signals sent between the wireless client and an access point, the method comprising:
 (a) computing the location of the wireless client based on measured properties of the radio frequency signals;   (b) receiving information that identifies the wireless client;   (c) generating a set of access privileges based on the location and the identifying information of the wireless client; and   (d) applying the access privileges to the wireless client.   
     
     
         2 . The method of  claim 1  wherein step (a) comprises computing the location of the wireless client using an RF fingerprinting method. 
     
     
         3 . The method of  claim 1  wherein step (b) comprises receiving from the access point a device ID of the wireless client. 
     
     
         4 . The method of  claim 3  wherein the device ID is a device MAC address. 
     
     
         5 . The method of  claim 3  wherein step (b) comprises receiving from the access point an access point ID of the access point. 
     
     
         6 . The method of  claim 1  wherein step (c) comprises retrieving the set of access privileges from a privilege database using the location and the identifying information of the wireless client. 
     
     
         7 . The method of  claim 1  wherein the access point interacts with a RADIUS server to obtain access to the network and wherein step (d) comprises sending the access privileges to the RADIUS server and using the radius server to cause the access point to apply the privileges. 
     
     
         8 . The method of  claim 1  wherein step (d) comprises assigning the wireless client to a virtual LAN, identifying each data packet sent from the wireless client with a tag specifying that the data packet is part of the virtual LAN and using devices that respond to the tag to apply the access privileges. 
     
     
         9 . The method of  claim 8  wherein step (d) further comprises changing the access privileges assigned to the wireless client by changing the virtual LAN to which the wireless client is assigned. 
     
     
         10 . The method of  claim 8  wherein step (d) further comprises changing the access privileges assigned to the wireless client by changing devices that respond to the tag to apply different access privileges to the wireless client. 
     
     
         11 . The method of  claim 1  wherein step (d) comprises using stateful packet filtering to apply the privileges. 
     
     
         12 . The method of  claim 1  wherein step (c) is performed by an access server connected to the wireless network and wherein the access point recurrently polls the access server to cause step (c) to be recurrently performed. 
     
     
         13 . The method of  claim 1  wherein step (c) is recurrently performed and the set of access privileges is recurrently sent to the access point. 
     
     
         14 . The method of  claim 1  wherein step (d) comprises applying the access privileges to the wireless client for a predetermined period of time. 
     
     
         15 . The method of  claim 14  wherein step (d) comprises performing an additional action after the predetermined period of time has expired. 
     
     
         16 . The method of  claim 1  wherein step (d) comprises applying the access privileges to the wireless client based on the time of day. 
     
     
         17 . Apparatus for controlling access privileges in a wireless network based on the location of a wireless client that is connected to the network via radio-frequency signals sent between the wireless client and an access point, the apparatus comprising:
 a location system that computes the location of the wireless client based on measured properties of the radio frequency signals;   an access server that receives information that identifies the wireless client;   a policy server that generates a set of access privileges based on the location and the identifying information of the wireless client; and   a mechanism that applies the access privileges to the wireless client.   
     
     
         18 . The apparatus of  claim 17  wherein the location system comprises means for computing the location of the wireless client using an RF fingerprinting method. 
     
     
         19 . The apparatus of  claim 17  wherein the access server comprises means for receiving from the access point a device ID of the wireless client. 
     
     
         20 . The apparatus of  claim 19  wherein the device ID is a device MAC address. 
     
     
         21 . The apparatus of  claim 19  wherein the access server comprises means for receiving from the access point an access point ID of the access point. 
     
     
         22 . The apparatus of  claim 17  wherein the policy server comprises means for retrieving the set of access privileges from a privilege database using the location and the identifying information of the wireless client. 
     
     
         23 . The apparatus of  claim 17  wherein the access point interacts with a RADIUS server to obtain access to the network and wherein the mechanism that applies the access privileges to the wireless client comprises means for sending the access privileges to the RADIUS server and means for using the radius server to cause the access point to apply the privileges. 
     
     
         24 . The apparatus of  claim 17  wherein the mechanism that applies the access privileges to the wireless client comprises:
 means for assigning the wireless client to a virtual LAN;   means for identifying each data packet sent from the wireless client with a tag specifying that the data packet is part of the virtual LAN; and   means for using devices that respond to the tag to apply the access privileges.   
     
     
         25 . The apparatus of  claim 24  wherein the mechanism that applies the access privileges to the wireless client further comprises means for changing the access privileges assigned to the wireless client by changing the virtual LAN to which the wireless client is assigned. 
     
     
         26 . The apparatus of  claim 24  wherein the mechanism that applies the access privileges to the wireless client further comprises means for changing the access privileges assigned to the wireless client by changing devices that respond to the tag to apply different access privileges to the wireless client. 
     
     
         27 . The apparatus of  claim 17  wherein the mechanism that applies the access privileges to the wireless client comprises means for using stateful packet filtering to apply the privileges. 
     
     
         28 . The apparatus of  claim 17  wherein the access point recurrently polls the access server to recurrently cause the policy server to generate a set of access privileges based on the location and the identifying information of the wireless client. 
     
     
         29 . The apparatus of  claim 17  wherein the policy server recurrently generates a set of access privileges based on the location and the identifying information of the wireless client and the generated set of access privileges is recurrently sent to the access point. 
     
     
         30 . The apparatus of  claim 17  wherein the mechanism that applies the access privileges to the wireless client comprises means for applying the access privileges to the wireless client for a predetermined period of time. 
     
     
         31 . The apparatus of  claim 30  wherein the mechanism that applies the access privileges to the wireless client comprises means for performing an additional action after the predetermined period of time has expired. 
     
     
         32 . The apparatus of  claim 17  wherein the mechanism that applies the access privileges to the wireless client comprises means for applying the access privileges based on the time of day. 
     
     
         33 . Apparatus for controlling access privileges in a wireless network based on the location of a wireless client that is connected to the network via radio-frequency signals sent between the wireless client and an access point, the apparatus comprising:
 means for computing the location of the wireless client based on measured properties of the radio frequency signals;   means for receiving information that identifies the wireless client;   means for generating a set of access privileges based on the location and the identifying information of the wireless client; and   means for applying the access privileges to the wireless client.   
     
     
         34 . The apparatus of  claim 33  wherein the means for computing the location of the wireless client comprises means for computing the location of the wireless client using an RF fingerprinting method. 
     
     
         35 . A computer program product for controlling access privileges in a wireless network based on the location of a wireless client that is connected to the network via radio-frequency signals sent between the wireless client and an access point, the computer program product comprising a computer usable medium having computer readable program code thereon, including:
 program code for computing the location of the wireless client based on measured properties of the radio frequency signals;   program code for receiving information that identifies the wireless client;   program code for generating a set of access privileges based on the location and the identifying information of the wireless client; and   program code for applying the access privileges to the wireless client.   
     
     
         36 . The computer program product of  claim 35  wherein the program code for computing the location of the wireless client comprises program code for computing the location of the wireless client using an RF fingerprinting method.

Join the waitlist — get patent alerts

Track US2009293106A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.