LAN Connection Using Borrowed MAC Addresses Against Targeted Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Wi-Fi technologies in local area networks are vulnerable to attacks that allow unauthorized terminals to gain fraudulent access and exploit terminal addresses for malicious purposes, such as identifying or harming connected devices, due to the static nature of MAC addresses and the complexity and cost of address randomization solutions.
Innovation Solution
A method and device that dynamically use a borrowed MAC address from an inactive terminal on the network, creating a secure connection by acquiring and storing status data, including addresses and types of connected devices, to confuse attackers and protect the actual device's identity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a terminal uses its own static MAC address to connect to the network, then the connection is stable and simple, but the terminal is vulnerable to attacks that allow attackers to identify and target specific devices
Solution Approach 1:
The patent applies dynamics by making the MAC address dynamic instead of static. The terminal randomly selects a MAC address from a pool of addresses upon each connection attempt, rather than using a fixed assigned address. This dynamic behavior prevents attackers from consistently identifying and targeting specific devices while maintaining connection functionality.
Solution Approach 2:
The patent uses copying by having terminals copy or borrow MAC addresses from other terminals in the network. Instead of using its own unique MAC address, a terminal randomly selects and uses the MAC address of another terminal on the network, creating a form of address sharing that obscures the identity of the actual device and prevents targeted attacks.
2Object-affected harmful factors
If a terminal randomizes its MAC address to protect privacy and security, then the terminal is protected against targeted attacks, but the solution requires modifying firmware which is complex and costly
Solution Approach 1:
The patent applies universality by creating a network-wide address sharing system where any terminal can use any other terminal's MAC address. This multi-functional approach allows the same pool of MAC addresses to serve multiple terminals at different times, eliminating the need for individual firmware modifications on each device while achieving the security goal of address randomization.
Solution Approach 2:
The patent introduces an intermediary mechanism at the network protocol level that handles MAC address selection and management. Instead of requiring firmware changes in each terminal, the system uses an intermediary layer (the network communication protocol) to manage the randomization and sharing of MAC addresses, simplifying implementation across different devices.
3Object-affected harmful factors
If a terminal uses a borrowed MAC address dynamically, then the terminal protects its identity and confuses attackers, but the terminal must acquire and manage status data from other network terminals
Solution Approach 1:
The patent applies self-service by having terminals automatically discover and collect MAC addresses from other terminals on the network without requiring manual configuration or complex management systems. The terminal independently monitors network traffic, extracts MAC addresses from observed communications, and maintains its own pool of usable addresses, eliminating the need for centralized management infrastructure.
Data Source
AI summary
A method, a device and a system for secure connection. The method is implemented by a first terminal of a network administered by an access point. The terminal has a first address, called own address. The method includes: acquiring a set of data, called status data, including at least one address of at least one second terminal known to the network; and connecting to the network using the address of the second terminal as a replacement for the own address.


