Wireless Mesh Network MAC Address Spoofing Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless mesh networks are vulnerable to MAC address spoofing attacks, which disrupt communication by allowing unauthorized devices to impersonate trusted subscribers, leading to denial-of-service attacks and unauthorized access.

Innovation Solution

A method that prevents MAC address spoofing by comparing the registering MAC address with reachable MAC addresses within the network, and if it matches, an approval procedure is initiated to ensure only valid, unique MAC addresses are used, either by rejecting the registration or converting the MAC address to a disjoint one, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If devices use MAC addresses for identification in the wireless mesh network, then communication and network access are enabled, but the network becomes vulnerable to MAC address spoofing attacks that disrupt communication and enable unauthorized access

Engineering Contradiction:
Improvenetwork accessVSAvoidMAC address spoofing attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of MAC address ownership during the network registration process. When a device attempts to register with a MAC address, the network checks whether the device is the legitimate owner of that MAC address before granting access. This preliminary action prevents spoofed devices from gaining network access in the first place.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network implements a feedback mechanism where registration attempts with potentially spoofed MAC addresses are detected and rejected. The system provides feedback to the registering device about the authenticity of its MAC address, allowing legitimate devices to register while blocking unauthorized spoofing attempts.

Inventive Principle:
Principle #23Feedback

2Productivity

If the network accepts any device registering with a MAC address, then network registration is simple and fast, but unauthorized devices can impersonate trusted subscribers and cause denial-of-service attacks

Engineering Contradiction:
Improveregistration speedVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary verification of MAC address ownership during the network registration process. When a device attempts to register with a MAC address, the network checks whether the device is the legitimate owner of that MAC address before granting access. This preliminary action prevents spoofed devices from gaining network access in the first place.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network implements a feedback mechanism where registration attempts with potentially spoofed MAC addresses are detected and rejected. The system provides feedback to the registering device about the authenticity of its MAC address, allowing legitimate devices to register while blocking unauthorized spoofing attempts.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If the network implements MAC address spoofing prevention by comparing registering MAC addresses with reachable MAC addresses, then network security against spoofing is improved, but the complexity of the registration process increases due to the approval procedure

Engineering Contradiction:
ImproveMAC address spoofing attacksVSAvoidregistration process
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system performs preliminary verification of MAC address ownership during the network registration process. When a device attempts to register with a MAC address, the network checks whether the device is the legitimate owner of that MAC address before granting access. This preliminary action prevents spoofed devices from gaining network access in the first place.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network implements a feedback mechanism where registration attempts with potentially spoofed MAC addresses are detected and rejected. The system provides feedback to the registering device about the authenticity of its MAC address, allowing legitimate devices to register while blocking unauthorized spoofing attempts.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9820252B2Method and arrangement for providing a wireless mesh network
Publication Date: 2017.11.14 UNIFY BETEILIGUNGSVERWALTUNG GMBH & CO KG
  • US9820252B2 patent drawing
  • US9820252B2 patent drawing
  • US9820252B2 patent drawing

AI summary

A method and an arrangement for providing a wire-free mesh network are provided. An approval procedure is carried out in situations in which a subscriber who is registering on the mesh network transmits an MAC address which already exists in the mesh network, such that two different subscribers within the mesh network never have identical MAC addresses.