MAC Address Correlation for Enterprise Authentication Under Randomization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Electronic devices using MAC address randomization compromise the ability of enterprise networks to perform security and management actions, as these networks rely on the real MAC address for identification and authentication.
Innovation Solution
A management system generates a correlation between a private network address and a value representing the assigned MAC address, allowing security and management systems to function correctly even when the real MAC address is randomized.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MAC address randomization is enabled in electronic devices, then device privacy is protected, but security systems cannot identify devices for authentication and management
Solution Approach 1:
The patent introduces a management system as an intermediary that maintains correlation information mapping between randomized MAC addresses and original device identifiers. This intermediary enables security systems to authenticate devices through the mapped identifiers without directly exposing or relying on randomized MAC addresses, thus preserving both privacy and security functionality
Solution Approach 2:
The patent segments the network system into two functional parts: devices using randomized MAC addresses for privacy protection, and a management system maintaining the correlation mapping. This segmentation allows the security functionality to operate on mapped identifiers while devices operate with randomized addresses, resolving the contradiction between privacy and security
2Reliability
If MAC address randomization is used, then tracking of device location and network usage is prevented, but security systems relying on real MAC addresses cannot perform authentication
Solution Approach 1:
The management system acts as a mediator that translates between randomized MAC addresses used by devices and the original device identifiers required by security systems. This intermediary layer maintains the correlation information and enables security operations to proceed smoothly without devices needing to change their privacy-protecting behavior
Solution Approach 2:
The patent creates a copy of the device identification functionality through the correlation mapping in the management system. Instead of security systems directly accessing real MAC addresses, they operate on copied identifier information maintained in the correlation database, allowing security management to function as before while devices use randomized addresses
3Object-generated harmful factors
If real MAC addresses are used for security authentication, then network security is maintained, but device privacy is compromised through tracking
Solution Approach 1:
The management system serves as an intermediary that decouples the security authentication process from direct use of real MAC addresses. Security systems authenticate devices through the correlation mapping mechanism rather than directly using real MAC addresses, thereby maintaining security while preventing tracking of device identity
Solution Approach 2:
The patent extracts the device identification functionality from the MAC address itself and relocates it to the management system's correlation database. This extraction allows MAC addresses to be randomized for privacy while the extracted identification capability is preserved and maintained by the management system for security purposes
4Reliability
If MAC address randomization is implemented, then device identity is protected, but management systems cannot perform authenticated IP address assignment
Solution Approach 1:
The management system acts as an intermediary between DHCP services and devices using randomized MAC addresses. It maintains correlation information and translates randomized addresses to original device identifiers during the IP address assignment process, enabling authenticated DHCP while preserving device privacy
Solution Approach 2:
The management system performs preliminary action by pre-establishing the correlation mapping between randomized MAC addresses and original device identifiers before DHCP authentication is needed. This preliminary preparation allows the DHCP process to proceed smoothly with authenticated assignment without adding complexity during the actual address assignment operation
Data Source
AI summary
In some examples, a management system receives, from an electronic device, a message containing a first information element that includes a first address of the electronic device, and a second information element that includes a device identifier of the electronic device, where the first address differs from an assigned network address assigned to the electronic device. In response to the first address extracted from the first information element and the device identifier extracted from the second information element of the message, the management system generates correlation information that associates a private network address of the electronic device with a value that represents the assigned network address. The management system applies a management action for the electronic device based on the correlation information.


