LAN Connection Using Borrowed MAC Addresses Against Targeted Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Wi-Fi technologies in local area networks are vulnerable to attacks that allow unauthorized terminals to gain fraudulent access and exploit terminal addresses for malicious purposes, such as identifying or harming connected devices, due to the static nature of MAC addresses and the complexity and cost of address randomization solutions.

Innovation Solution

A method and device that dynamically use a borrowed MAC address from an inactive terminal on the network, creating a secure connection by acquiring and storing status data, including addresses and types of connected devices, to confuse attackers and protect the actual device's identity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a terminal uses its own static MAC address to connect to the network, then the connection is stable and simple, but the terminal is vulnerable to attacks that allow attackers to identify and target specific devices

Engineering Contradiction:
Improveconnection stabilityVSAvoidvulnerability to targeted attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by making the MAC address dynamic instead of static. The terminal randomly selects a MAC address from a pool of addresses upon each connection attempt, rather than using a fixed assigned address. This dynamic behavior prevents attackers from consistently identifying and targeting specific devices while maintaining connection functionality.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent uses copying by having terminals copy or borrow MAC addresses from other terminals in the network. Instead of using its own unique MAC address, a terminal randomly selects and uses the MAC address of another terminal on the network, creating a form of address sharing that obscures the identity of the actual device and prevents targeted attacks.

Inventive Principle:
Principle #26Copying

2Object-affected harmful factors

If a terminal randomizes its MAC address to protect privacy and security, then the terminal is protected against targeted attacks, but the solution requires modifying firmware which is complex and costly

Engineering Contradiction:
Improveprotection against targeted attacksVSAvoidfirmware modification complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a network-wide address sharing system where any terminal can use any other terminal's MAC address. This multi-functional approach allows the same pool of MAC addresses to serve multiple terminals at different times, eliminating the need for individual firmware modifications on each device while achieving the security goal of address randomization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary mechanism at the network protocol level that handles MAC address selection and management. Instead of requiring firmware changes in each terminal, the system uses an intermediary layer (the network communication protocol) to manage the randomization and sharing of MAC addresses, simplifying implementation across different devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If a terminal uses a borrowed MAC address dynamically, then the terminal protects its identity and confuses attackers, but the terminal must acquire and manage status data from other network terminals

Engineering Contradiction:
Improvedevice identity protectionVSAvoidaddress management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies self-service by having terminals automatically discover and collect MAC addresses from other terminals on the network without requiring manual configuration or complex management systems. The terminal independently monitors network traffic, extracts MAC addresses from observed communications, and maintains its own pool of usable addresses, eliminating the need for centralized management infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12490094B2Method and device for securely connecting to a local area network
Publication Date: 2025.12.02 ORANGE SA
  • US12490094B2 patent drawing
  • US12490094B2 patent drawing
  • US12490094B2 patent drawing

AI summary

A method, a device and a system for secure connection. The method is implemented by a first terminal of a network administered by an access point. The terminal has a first address, called own address. The method includes: acquiring a set of data, called status data, including at least one address of at least one second terminal known to the network; and connecting to the network using the address of the second terminal as a replacement for the own address.