CPE Network Message Aggregation for Device Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current device identification methods in home/office LANs face challenges due to MAC randomization, which anonymizes device MAC addresses, making it difficult to identify connected devices, especially with emerging devices not being noticed and important fingerprinting parameters missed due to limited and periodic data collection.
Innovation Solution
Implementing machine learning algorithms in customer-premises equipment (CPE) to continuously aggregate and process network messages using local and remote state objects, enabling continuous and uninterrupted device information collection and identification, even for indirectly routable devices, by intercepting and analyzing data communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If MAC randomization is implemented to increase privacy, then device identification based on MAC address is hindered, but device identification capability is still needed for cybersecurity
Solution Approach 1:
The patent introduces network messages as an intermediary carrier that contains device fingerprinting parameters. Instead of directly using MAC addresses for identification, the system uses these messages as a mediator to transmit device characteristics, enabling identification without relying on the randomized MAC address alone.
Solution Approach 2:
The patent replaces the mechanical/MAC-based identification system with a machine learning-based system. The ML algorithm processes network messages and extracts device fingerprints, substituting the traditional deterministic MAC address matching with a probabilistic AI-based identification approach that can handle randomized identifiers.
2Quantity of substance
If centralized computing resource is used for device identification, then device information can be collected and processed, but new connected devices may not be noticed and important fingerprinting parameters may be missed due to periodic data collection
Solution Approach 1:
The patent implements continuous data collection by having the CPE continuously monitor and aggregate network messages in local state objects. This continuous action ensures that no device communication is missed, and the system can immediately detect new devices and track their behavior over time without the gaps introduced by periodic collection.
Solution Approach 2:
The patent performs preliminary actions by pre-configuring the CPE with machine learning algorithms and state object structures before device identification is needed. The system is prepared in advance with the necessary processing capabilities, allowing it to immediately and accurately identify new devices upon their connection without requiring post-event analysis.
3Use of energy by moving object
If CPE collects device information for limited time period, then resource consumption is reduced, but device fingerprinting parameters may be missed
Solution Approach 1:
The patent segments the data collection process into two parts: local aggregation at the CPE and centralized processing. The CPE collects and aggregates network messages locally in state objects, segmenting the heavy processing task from the data collection. This allows continuous collection without immediately consuming centralized resources, while the actual fingerprinting analysis is segmented to occur at the appropriate time and location.
Data Source
AI summary
Network messages in a directly routed local area network (LAN) of a customer-premises equipment (CPE) are subscribed to. The CPE is configured to provide the directly routed LAN for data communication, and an access for the data communication to a wide area network (WAN). The network messages in the directly routed LAN are received. The network messages are aggregated to local state objects maintained in the CPE, wherein each local state object contains data of a single connected device. Update data of the local state objects is transmitted via the WAN to remote state objects maintained outside of the CPE.


