Encrypted MAC Address Exchange for Stable Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for identifying and mitigating DDoS attacks based on MAC and IP addresses are inadequate, leading to service disruptions and performance degradation due to MAC address renewal, and existing IP-based filters fail to accurately identify malicious devices, affecting legitimate devices and degrading network performance.
Innovation Solution
A method involving a secure connection between devices to transmit encrypted MAC addresses, allowing validation and conflict-free MAC address management, ensuring continuity of service and secure access control without relying on layer 2 security functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If random MAC address generation is used to preserve confidentiality, then user data confidentiality is improved, but service stability and network access reliability deteriorate
Solution Approach 1:
The patent segments the network communication into two distinct channels: an encrypted control channel for MAC address declaration and validation, and a data channel for actual communication. This segmentation allows random MAC addresses to be used for confidentiality while maintaining service stability through reliable encrypted communication for address management.
Solution Approach 2:
The patent introduces an intermediary encrypted communication mechanism between devices and network access points. This intermediary layer (encryption protocol) mediates the conflict by allowing MAC address changes while maintaining authorized access through secure validation, thus preserving both confidentiality and service reliability.
2Object-affected harmful factors
If MAC address filtering is implemented to control network access, then network security is improved, but service continuity deteriorates during MAC address renewal
Solution Approach 1:
The patent implements preliminary action by establishing encrypted control channels and validating MAC addresses before actual network communication begins. This allows the system to pre-configure security filters while ensuring service continuity through prior validation of address changes.
Solution Approach 2:
The patent ensures continuity of useful action by maintaining encrypted control channels that remain active throughout MAC address renewals. The secure communication channel persists continuously, allowing address changes without interrupting authorized network access or service delivery.
3Object-generated harmful factors
If IP-based filtering is used to mitigate DDoS attacks, then attack mitigation capability is improved, but identification precision of malicious devices deteriorates
Solution Approach 1:
The patent applies local quality by implementing MAC address-level filtering at the network access point rather than broad IP-based filtering. This localized approach at the device level (rather than network level) enables precise identification of individual malicious devices while preserving access for legitimate devices on the same network.
4Object-generated harmful factors
If broad IP-based filtering is applied to block attacks, then attack mitigation is improved, but network performance deteriorates due to affecting legitimate devices
Solution Approach 1:
The patent implements local quality by applying security filters at the individual device MAC address level rather than broad IP ranges. This localized filtering approach blocks only the specific malicious device while preserving network performance for all other legitimate devices sharing the same IP network.
Data Source
AI summary
A method for communication between a first device and a second device, implemented by the first device. The method includes: establishing a first secure connection between the first device and the second device, via a first communication interface of the first device; transmitting, using the first secure connection, a message including at least one encrypted MAC address, associated or capable of being associated with the first interface and used to communicate with or via the second device or an intermediate device located on a communication path between the first device and the second device.


