Edge Device Fingerprinting for Low-Latency Network Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network management systems face challenges with device fingerprinting due to high latency, bandwidth usage, and cost associated with cloud-based services, especially with the increasing number of devices and the use of MAC randomization, which complicates accurate device identification and security management.
Innovation Solution
Implementing a fingerprint determination model within a network management device to determine device characteristics locally, reducing reliance on cloud-based services by processing messages from user devices to generate device fingerprint data and control network functions based on these characteristics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If cloud-based device fingerprinting services are used, then device identification capability is improved, but latency increases and bandwidth usage increases
Solution Approach 1:
The patent extracts the fingerprint determination model from the cloud-based service and places it locally within the network management device. This extraction eliminates the need to send device messages to external cloud services, thereby reducing latency while maintaining identification accuracy through local processing of device characteristics.
Solution Approach 2:
The network management device acts as an intermediary that locally processes device fingerprinting requests without needing to communicate with external cloud services. By implementing the fingerprint determination model within itself, the network management device mediates between device identification needs and local resource constraints, reducing both latency and bandwidth usage.
2Measurement precision
If cloud-based device fingerprinting services are used, then device identification capability is improved, but bandwidth usage increases
Solution Approach 1:
The patent extracts the fingerprint determination model from external cloud services and embeds it locally in the network management device. This eliminates continuous communication with external services, significantly reducing bandwidth consumption while maintaining accurate device identification through local message processing.
Solution Approach 2:
The network management device performs device fingerprinting autonomously using its own embedded model, without requiring external cloud service communication. This self-service approach processes device messages locally, eliminating bandwidth usage associated with cloud interactions while maintaining identification accuracy.
3Reliability
If MAC randomization is implemented for security, then security is improved, but device identification difficulty increases
Solution Approach 1:
The patent applies preliminary action by collecting multiple device messages over time and using the fingerprint determination model to identify consistent device characteristics despite MAC address changes. The model learns device-specific patterns from initial messages, enabling continuous identification even as devices randomize their MAC addresses for security.
Solution Approach 2:
The fingerprint determination model analyzes changes in message parameters beyond the MAC address, such as timing patterns, message structure, and other device-specific characteristics. By focusing on these invariant parameters rather than the randomizing MAC address, the system maintains identification accuracy while respecting security-enhancing MAC randomization.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method, device, and storage medium are provided and configured control one or more network functions for user devices in a local network. A fingerprint determination model is provided and configured to determine one or more characteristics of user devices based on messages generated by respective user devices. A first message from a user device is received and processed to determine a set of one or more user device message characteristics. Device fingerprint data, representing at least one determined characteristic of the user device, is generated by processing the set of one or more user device message characteristics using the fingerprint determination model. One or more network functions for the user device are controlled based on the at least one determined characteristics of the user device represented in the device fingerprint data.