MAC Address Correlation for Enterprise Authentication Under Randomization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electronic devices using MAC address randomization compromise the ability of enterprise networks to perform security and management actions, as these networks rely on the real MAC address for identification and authentication.

Innovation Solution

A management system generates a correlation between a private network address and a value representing the assigned MAC address, allowing security and management systems to function correctly even when the real MAC address is randomized.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MAC address randomization is enabled in electronic devices, then device privacy is protected, but security systems cannot identify devices for authentication and management

Engineering Contradiction:
Improvedevice privacy protectionVSAvoidnetwork security compromise
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces a management system as an intermediary that maintains correlation information mapping between randomized MAC addresses and original device identifiers. This intermediary enables security systems to authenticate devices through the mapped identifiers without directly exposing or relying on randomized MAC addresses, thus preserving both privacy and security functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network system into two functional parts: devices using randomized MAC addresses for privacy protection, and a management system maintaining the correlation mapping. This segmentation allows the security functionality to operate on mapped identifiers while devices operate with randomized addresses, resolving the contradiction between privacy and security

Inventive Principle:
Principle #1Segmentation

2Reliability

If MAC address randomization is used, then tracking of device location and network usage is prevented, but security systems relying on real MAC addresses cannot perform authentication

Engineering Contradiction:
Improvedevice privacy protectionVSAvoidsecurity management operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The management system acts as a mediator that translates between randomized MAC addresses used by devices and the original device identifiers required by security systems. This intermediary layer maintains the correlation information and enables security operations to proceed smoothly without devices needing to change their privacy-protecting behavior

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of the device identification functionality through the correlation mapping in the management system. Instead of security systems directly accessing real MAC addresses, they operate on copied identifier information maintained in the correlation database, allowing security management to function as before while devices use randomized addresses

Inventive Principle:
Principle #26Copying

3Object-generated harmful factors

If real MAC addresses are used for security authentication, then network security is maintained, but device privacy is compromised through tracking

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice privacy
Core Design Contradiction:
Object-generated harmful factorsVSReliability

Solution Approach 1:

The management system serves as an intermediary that decouples the security authentication process from direct use of real MAC addresses. Security systems authenticate devices through the correlation mapping mechanism rather than directly using real MAC addresses, thereby maintaining security while preventing tracking of device identity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the device identification functionality from the MAC address itself and relocates it to the management system's correlation database. This extraction allows MAC addresses to be randomized for privacy while the extracted identification capability is preserved and maintained by the management system for security purposes

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If MAC address randomization is implemented, then device identity is protected, but management systems cannot perform authenticated IP address assignment

Engineering Contradiction:
Improvedevice privacy protectionVSAvoidnetwork management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The management system acts as an intermediary between DHCP services and devices using randomized MAC addresses. It maintains correlation information and translates randomized addresses to original device identifiers during the IP address assignment process, enabling authenticated DHCP while preserving device privacy

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The management system performs preliminary action by pre-establishing the correlation mapping between randomized MAC addresses and original device identifiers before DHCP authentication is needed. This preliminary preparation allows the DHCP process to proceed smoothly with authenticated assignment without adding complexity during the actual address assignment operation

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12621296B2Correlations between private network addresses and assigned network addresses
Publication Date: 2026.05.05 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12621296B2 patent drawing
  • US12621296B2 patent drawing
  • US12621296B2 patent drawing

AI summary

In some examples, a management system receives, from an electronic device, a message containing a first information element that includes a first address of the electronic device, and a second information element that includes a device identifier of the electronic device, where the first address differs from an assigned network address assigned to the electronic device. In response to the first address extracted from the first information element and the device identifier extracted from the second information element of the message, the management system generates correlation information that associates a private network address of the electronic device with a value that represents the assigned network address. The management system applies a management action for the electronic device based on the correlation information.