Dynamic MAC Address Management for Secure IoT Device Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing devices are vulnerable to attacks due to broadcasting static MAC addresses, which can lead to unauthorized connections and data exposure, and using random MAC addresses hinders efficient device discovery and connection establishment.

Innovation Solution

A trusted entity within a domain manages and shares trust information, including public keys, certificates, and hash functions, allowing devices to securely and automatically establish trust and connect without broadcasting their MAC addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a device broadcasts its static MAC address for discovery, then device discovery and connection establishment become efficient, but the device becomes vulnerable to attacks and malicious entities

Engineering Contradiction:
Improvedevice discovery efficiencyVSAvoidvulnerability to attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by transitioning from static MAC addresses to dynamic, temporary identifiers that change over time. Devices use ephemeral identifiers for discovery and communication that are periodically renewed through trust verification with a trusted entity, making it difficult for attackers to track or target devices while maintaining efficient discovery capabilities.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a trusted entity as an intermediary between devices. This trusted entity issues temporary identifiers and verifies trust relationships, allowing devices to discover and connect securely without directly exposing their permanent MAC addresses. The intermediary mediates the discovery process by providing temporary identifiers that enable efficient device finding while protecting permanent identities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a device uses a random MAC address to prevent attacks, then security against malicious entities is improved, but efficient automatic discovery between devices is prevented

Engineering Contradiction:
Improvesecurity against attacksVSAvoiddevice discovery efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system uses dynamic temporary identifiers that are generated and renewed periodically through interaction with a trusted entity. These identifiers provide the randomness needed for security while being systematically managed to enable efficient discovery. The dynamic nature allows devices to be found through trusted entity coordination without exposing permanent identifiers.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The trusted entity performs preliminary actions by pre-establishing trust relationships and issuing temporary identifiers before devices need to discover each other. This preliminary setup enables efficient discovery because devices can use these pre-issued identifiers for communication without needing to broadcast or scan for permanent MAC addresses.

Inventive Principle:
Principle #10Preliminary action

3Stability of the object's composition

If a device uses a static Universal MAC address for data communication after connection, then communication stability is maintained, but attacking entities can expose and exploit this address

Engineering Contradiction:
Improvecommunication stabilityVSAvoidexposure to attacks
Core Design Contradiction:
Stability of the object's compositionVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamics by continuously renewing temporary identifiers even during established communications. While a connection is active, devices periodically update their temporary identifiers through trust verification with the trusted entity, maintaining communication stability through the trusted entity's coordination while preventing attackers from exploiting a single static address.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the identifier parameter over time through periodic renewal. Instead of using a fixed MAC address for communication, devices change their temporary identifiers at regular intervals or upon trust verification events, maintaining communication continuity while altering the address parameter to prevent exploitation.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If devices interact with a trusted entity to obtain trust information, then secure and automatic trust establishment is enabled, but communication overhead and interaction requirements increase

Engineering Contradiction:
Improvetrust establishment securityVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted entity performs preliminary trust verification and issues temporary identifiers before devices need to communicate. This preliminary action reduces ongoing overhead because devices can use these pre-issued identifiers for multiple communications without repeatedly interacting with the trusted entity, establishing trust once rather than continuously.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The temporary identifiers issued by the trusted entity enable continuous useful communication between devices without requiring continuous trusted entity interaction. Once trust is established and a temporary identifier is issued, devices can communicate freely using this identifier, maintaining the useful action of communication while minimizing the overhead of trusted entity interactions.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentEP3860086B1Establishing trust between two devices
Publication Date: 2024.05.29 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3860086B1 patent drawingFigure 1
  • EP3860086B1 patent drawingFigure 2
  • EP3860086B1 patent drawingFigure 3

AI summary

Techniques described herein leverage a trusted entity within a domain to enable devices to establish trust with one another so they can securely discover each other and connect to one another. In various examples discussed herein, a device is configured to provide trust information to, and/or receive trust information from, the trusted entity. The trust information may include, for example, a public key of an encryption key pair, a certificate signed by the trusted entity proving authenticity, and/or a hash function and a hash seed used to compute a series of results that form a hash chain. The device may use the trust information to discover another device and to connect to the other device securely and automatically (e.g., with no user involvement or limited user involvement). Moreover, the device may use the trust information to dynamically change a MAC address being used to communicate with the other device.