Dynamic MAC ID Modification for IPv6 Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The use of static MAC IDs in IPv6 capable devices, such as image forming apparatuses, poses security risks as they do not change unless the physical hardware is altered, making them vulnerable to unauthorized access and potential shutdown by malicious actors.

Innovation Solution

A software module that captures outgoing IPv6 packets, modifies the associated device identifier-based IPv6 address, and returns the packets to the network layer with a new, dynamically generated identifier, which can be based on a timestamp, keyword, or random number, thereby enhancing security by changing the MAC ID.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a static MAC ID is used for IPv6 address generation, then the device can maintain stable network identity and simplify address configuration, but the device becomes vulnerable to security attacks and unauthorized access

Engineering Contradiction:
Improvenetwork identity stabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies the Dynamics principle by transitioning from a static MAC ID to a dynamic identifier that changes periodically or based on specific triggers. The software module generates new identifiers using algorithms that incorporate time stamps, random values, or other changing parameters, making the network identity fluid rather than fixed. This resolves the contradiction by maintaining reliability through consistent identification while eliminating security vulnerabilities through periodic identity changes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements Parameter changes by modifying the identifier parameters themselves - specifically the MAC ID used in IPv6 address generation. Instead of using a fixed manufacturer-assigned MAC address, the system changes the identifier parameters dynamically based on time, random values, or other variables. This allows the device to maintain stable network functionality while continuously updating its identification parameters to prevent security attacks.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If the MAC ID is changed frequently to enhance security, then unauthorized access is prevented, but network connectivity may be disrupted and address autoconfiguration may fail

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidnetwork connectivity stability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent applies Periodic action by implementing scheduled or triggered identifier changes rather than continuous or random changes. The software module can be configured to update the MAC ID-based identifier at specific time intervals, upon network events, or based on security policies. This periodic approach maintains security by regularly changing identifiers while ensuring network connectivity stability by allowing proper propagation and recognition of new addresses between changes.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system implements Feedback mechanisms to monitor network connectivity status and adjust identifier change timing accordingly. If connectivity issues are detected following an identifier change, the system can delay subsequent changes or implement corrective actions. This feedback loop ensures that security enhancements through identifier changes do not compromise overall network reliability and connectivity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8516141B2Method and system for modifying and/or changing a MAC ID utilizing an IPv6 network connection
Publication Date: 2013.08.20 KONICA MINOLTA SYSTEMS LABORATORY INC
  • US8516141B2 patent drawing
  • US8516141B2 patent drawing
  • US8516141B2 patent drawing

AI summary

A system that facilitates enhancing security for a computer device utilizing an IPv6 network connection. The system includes a computer device having a software module, which performs the following steps: capturing outgoing IPv6 packets, the outgoing IPv6 packets having a stateless autoconfiguration IPv6 address, which is configured at least partially based on a computer device identifier; modifying the IPv6 address associated with the computer device identifier to generate a modified IPv6 address; and returning the outgoing IPv6 packet with the modified IPv6 address to a network layer of the Internet Protocol of the computer device. In accordance with an example, the computer device is an image forming apparatus.