Wireless Access Point MAC Address Privacy via Dynamic Virtual Identifiers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless access points broadcast their unique MAC addresses, making it possible for attackers to determine their geophysical location, which can compromise personal privacy, especially when combined with publicly accessible databases and malicious software exploits.

Innovation Solution

Configuring wireless access points to use a randomly generated MAC address for SSID broadcasts, which can be periodically or event-drivenly changed, preventing the burned-in MAC address from being used to identify the access point's location.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the burned-in MAC address is broadcast for network identification, then network accessibility and device recognition are improved, but privacy and location security deteriorate

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidprivacy disclosure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies the copying principle by creating a virtual MAC address that copies the functionality of the burned-in MAC address for network identification purposes, while the actual burned-in MAC address remains hidden. The virtual MAC address is generated by combining the burned-in MAC address with random bytes, creating a copy that performs the identification function without exposing the original sensitive information.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent uses an intermediary approach by introducing a virtual MAC address as a mediator between the burned-in MAC address and the network identification process. This virtual MAC address acts as a proxy that allows networks to identify and communicate with the access point without directly exposing the burned-in MAC address, thus protecting privacy while maintaining network functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the MAC address is changed periodically to protect privacy, then location tracking is prevented, but network connectivity stability deteriorates

Engineering Contradiction:
Improvelocation trackingVSAvoidnetwork connectivity
Core Design Contradiction:
Object-affected harmful factorsVSStability of the object's composition

Solution Approach 1:

The patent applies the dynamics principle by making the virtual MAC address changeable over time while maintaining stability during operation. The virtual MAC address can be dynamically updated to prevent location tracking, but during active network communication, the address remains stable to ensure connectivity. This dynamic特性 allows the system to adapt between privacy protection and connectivity stability based on operational context.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9220007B2Wireless access point MAC address privacy
Publication Date: 2015.12.22 CISCO TECHNOLOGY INC
  • US9220007B2 patent drawing
  • US9220007B2 patent drawing
  • US9220007B2 patent drawing

AI summary

The present disclosure describes techniques for using varying MAC addresses to provide wireless access point MAC address privacy. A wireless access point may be configured to generate a random (or pseudo-random) MAC address to use on a wireless-side interface (and SSID broadcast), rather than using the burned-in MAC address. The wireless access point may be further configured to periodically change the wireless-side MAC address with a newly generated one whenever user-configurable triggering conditions are satisfied. As a result, a MAC address learned by a wi-fi sniffing device becomes obsolete shortly after being learned and cannot be used to correlate the actual location of the access point with the MAC address for any significant period of time.