Deterministic MAC Address Rotation for Wireless Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network technologies face challenges in accommodating deterministic random MAC address rotation, which improves privacy but disrupts network operations that rely on device addresses as unique identifiers, leading to issues with authentication and resource access.

Innovation Solution

The techniques generate a subsequent device address based on the current device address and cryptographic information, such as a pairwise transient key, allowing for deterministic random MAC address rotation while maintaining compatibility with trusted network infrastructure, ensuring privacy against eavesdroppers without disrupting network operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If device address is changed at random intervals using RCM, then privacy of mobile device user is improved, but network operations that rely on device address as unique identifier are disrupted

Engineering Contradiction:
Improveprivacy protectionVSAvoidnetwork operation reliability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent implements dynamic address rotation where the MAC address changes at random intervals during connected mode operation. The system dynamically selects between current and alternate MAC addresses based on timing conditions, enabling privacy protection while maintaining network connectivity. This dynamic behavior resolves the contradiction by making the address change pattern unpredictable to eavesdroppers yet manageable by the network infrastructure.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of device address (MAC address) from static to dynamically rotating. By implementing address rotation that changes the MAC address parameter at random intervals during connected mode, the system improves privacy protection while the network infrastructure can track the device through alternative identifiers like IP addresses, thus maintaining operational reliability.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If device address is changed frequently, then privacy protection against eavesdroppers is improved, but authentication and resource access are disrupted

Engineering Contradiction:
Improveeavesdropping protectionVSAvoidauthentication ease
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system dynamically rotates between current and alternate MAC addresses during connected mode based on random timing intervals. This dynamic address rotation provides strong eavesdropping protection because the address changes frequently and unpredictably, while authentication ease is maintained because the network infrastructure can correlate address changes with existing session identifiers like IP addresses and authentication credentials.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent uses alternative identifiers such as IP addresses as intermediaries to maintain authentication and resource access continuity. When the MAC address rotates, the network infrastructure uses these intermediary identifiers to track the device and maintain authenticated sessions, thus preventing authentication disruption despite frequent address changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If deterministic address rotation is implemented, then compatibility with trusted network infrastructure is improved, but randomness in address selection is reduced

Engineering Contradiction:
Improvenetwork infrastructure compatibilityVSAvoidaddress generation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent generates an alternate MAC address in advance during the initial association phase, before connected mode operation begins. This preliminary action stores the alternate address for later use during deterministic rotation in connected mode, simplifying the address generation process during operation while maintaining compatibility with network infrastructure that expects predictable address behavior.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the behavior of MAC address rotation based on operational mode: during association phase, it uses random rotation for privacy; during connected mode, it uses deterministic rotation based on timing conditions for infrastructure compatibility. This parameter change in rotation behavior adapts to different network operational contexts, improving overall compatibility while managing complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240163089A1Deterministic address rotation
Publication Date: 2024.05.16 CISCO TECHNOLOGY INC
  • US20240163089A1 patent drawing
  • US20240163089A1 patent drawing
  • US20240163089A1 patent drawing

AI summary

Methods that support deterministic random media access control (MAC) address rotation that allows sharing of an address identity with a trusted wireless network infrastructure by generating a next address based on a previously used address and a seed obtained from a previous association with the trusted network infrastructure. In these methods, a computing device obtains a request for a secure connection of an endpoint device to a wireless network. The computing device performs an access authentication for the secure connection and establishes the secure connection of the endpoint device to the wireless network based on successfully performing the access authentication, in which cryptographic information for encrypting one or more network messages is generated. The computing device further generates a subsequent device address for a subsequent secure connection of the endpoint device to the wireless network, based on a current device address obtained from the request and the cryptographic information.