MAC-Based Public Key Generation for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access solutions are complex, time-consuming, and often not optimized, making it difficult for administrators to manage and secure network access, particularly in detecting unauthorized device spoofing and maintaining up-to-date access rights for users and devices.

Innovation Solution

The Simplified Network Access Control (SNAC) system enables self-registration for users and automated updating of access rights, using a database of authorized users and certificates based on MAC addresses to provide secure network access without requiring expertise in RADIUS servers, directory services, or 802.1X technology, and includes a re-verification process to ensure only authorized users access the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network access control systems are implemented using RADIUS servers, directory services, and 802.1X technology, then network security is improved, but device complexity and administrative overhead increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential authentication function from the complex RADIUS/server/directory service infrastructure and implements it directly in the network switch using a local database of authorized MAC addresses. This removes the dependency on external authentication servers and directory services, significantly simplifying the system architecture while maintaining security through MAC address verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network switch performs authentication autonomously using its built-in database of authorized MAC addresses, without requiring external authentication servers or complex configuration. The switch independently verifies device identities and enforces access policies, eliminating the need for administrators to manage RADIUS servers or directory services.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual management of network access rights is performed, then security control is improved, but loss of time and administrative overhead increase

Engineering Contradiction:
Improveaccess controlVSAvoidadministrative time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically manages network access rights by continuously monitoring which devices are connected to the network and comparing their MAC addresses against the authorized database. Access rights are granted or revoked automatically based on current connection status, eliminating manual intervention and reducing administrative time while maintaining secure access control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous monitoring of network connections with real-time feedback loops. When devices connect or disconnect, the system automatically detects these changes and adjusts access rights accordingly by comparing current MAC addresses with the authorized database, ensuring up-to-date security without manual management.

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive authentication and access monitoring is implemented, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts only the essential authentication function (MAC address verification) from the complex suite of network security protocols and implements it directly in the switch. This eliminates the need for RADIUS servers, directory services, and 802.1X infrastructure, maintaining core security functionality while dramatically reducing system complexity and administrative burden.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9270454B2Public key generation utilizing media access control address
Publication Date: 2016.02.23 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9270454B2 patent drawing
  • US9270454B2 patent drawing
  • US9270454B2 patent drawing

AI summary

In some embodiments, in a registration process where a user device is registering for access to a network, a public/private key pair may be generated based on a media access control (MAC) address of a user device. The generated public/private key pair may be transmitted to the user device for future access to the network. In some embodiments, where a user device is requesting access to a network, a MAC address embedded in a public key may be utilized to determine whether access to the network should be granted.