Dynamic MAC Address Management for Secure IoT Device Discovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computing devices are vulnerable to attacks due to broadcasting static MAC addresses, which can lead to unauthorized connections and data exposure, and using random MAC addresses hinders efficient device discovery and connection establishment.
Innovation Solution
A trusted entity within a domain manages and shares trust information, including public keys, certificates, and hash functions, allowing devices to securely and automatically establish trust and connect without broadcasting their MAC addresses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a device broadcasts its static MAC address for discovery, then device discovery and connection establishment become efficient, but the device becomes vulnerable to attacks and malicious entities
Solution Approach 1:
The patent applies dynamics by transitioning from static MAC addresses to dynamic, temporary identifiers that change over time. Devices use ephemeral identifiers for discovery and communication that are periodically renewed through trust verification with a trusted entity, making it difficult for attackers to track or target devices while maintaining efficient discovery capabilities.
Solution Approach 2:
The patent introduces a trusted entity as an intermediary between devices. This trusted entity issues temporary identifiers and verifies trust relationships, allowing devices to discover and connect securely without directly exposing their permanent MAC addresses. The intermediary mediates the discovery process by providing temporary identifiers that enable efficient device finding while protecting permanent identities.
2Reliability
If a device uses a random MAC address to prevent attacks, then security against malicious entities is improved, but efficient automatic discovery between devices is prevented
Solution Approach 1:
The system uses dynamic temporary identifiers that are generated and renewed periodically through interaction with a trusted entity. These identifiers provide the randomness needed for security while being systematically managed to enable efficient discovery. The dynamic nature allows devices to be found through trusted entity coordination without exposing permanent identifiers.
Solution Approach 2:
The trusted entity performs preliminary actions by pre-establishing trust relationships and issuing temporary identifiers before devices need to discover each other. This preliminary setup enables efficient discovery because devices can use these pre-issued identifiers for communication without needing to broadcast or scan for permanent MAC addresses.
3Stability of the object's composition
If a device uses a static Universal MAC address for data communication after connection, then communication stability is maintained, but attacking entities can expose and exploit this address
Solution Approach 1:
The patent implements dynamics by continuously renewing temporary identifiers even during established communications. While a connection is active, devices periodically update their temporary identifiers through trust verification with the trusted entity, maintaining communication stability through the trusted entity's coordination while preventing attackers from exploiting a single static address.
Solution Approach 2:
The system changes the identifier parameter over time through periodic renewal. Instead of using a fixed MAC address for communication, devices change their temporary identifiers at regular intervals or upon trust verification events, maintaining communication continuity while altering the address parameter to prevent exploitation.
4Reliability
If devices interact with a trusted entity to obtain trust information, then secure and automatic trust establishment is enabled, but communication overhead and interaction requirements increase
Solution Approach 1:
The trusted entity performs preliminary trust verification and issues temporary identifiers before devices need to communicate. This preliminary action reduces ongoing overhead because devices can use these pre-issued identifiers for multiple communications without repeatedly interacting with the trusted entity, establishing trust once rather than continuously.
Solution Approach 2:
The temporary identifiers issued by the trusted entity enable continuous useful communication between devices without requiring continuous trusted entity interaction. Once trust is established and a temporary identifier is issued, devices can communicate freely using this identifier, maintaining the useful action of communication while minimizing the overhead of trusted entity interactions.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Techniques described herein leverage a trusted entity within a domain to enable devices to establish trust with one another so they can securely discover each other and connect to one another. In various examples discussed herein, a device is configured to provide trust information to, and/or receive trust information from, the trusted entity. The trust information may include, for example, a public key of an encryption key pair, a certificate signed by the trusted entity proving authenticity, and/or a hash function and a hash seed used to compute a series of results that form a hash chain. The device may use the trust information to discover another device and to connect to the other device securely and automatically (e.g., with no user involvement or limited user involvement). Moreover, the device may use the trust information to dynamically change a MAC address being used to communicate with the other device.