Network Element Proxy for Device Location Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
User device applications are restricted from accessing the MAC address or other unique identifiers due to security restrictions, preventing them from utilizing location tracking services, especially in environments where GPS is unavailable.
Innovation Solution
A system that uses a proxy server or network elements to inject the MAC address or location coordinates into web cookies or HTTP responses, allowing applications to access location information without direct OS queries, utilizing HTTP proxies, MSE servers, and access points to triangulate device locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security restrictions are implemented to prevent direct MAC address querying by applications, then device security is improved, but location tracking capability deteriorates
Solution Approach 1:
The patent introduces a network element (proxy server, access point, or location server) as an intermediary between the application and the MAC address. The application sends a location request to this intermediary, which then retrieves the MAC address from the device's network stack and returns it to the application. This mediator architecture maintains security restrictions while enabling location tracking functionality.
Solution Approach 2:
The system separates the location tracking functionality into distinct components: the application layer (which requests location), the network element layer (which intermediates the request), and the operating system layer (which holds the MAC address). This segmentation allows each layer to operate within its security boundaries while achieving the overall goal of location tracking.
2Reliability
If applications are prohibited from querying the operating system for MAC address, then security policy enforcement is improved, but location service functionality deteriorates
Solution Approach 1:
A network element acts as a trusted intermediary that applications can query for location information without directly accessing the operating system's MAC address storage. The intermediary retrieves the MAC address through authorized network protocols and returns it to the application, maintaining security policy enforcement while preserving location service functionality.
Solution Approach 2:
The network element creates a copy of the MAC address information from the device's network stack and provides this copy to the application through the intermediary channel. This copying mechanism allows the application to obtain location data without having direct access to or control over the original MAC address in the operating system.
3Reliability
If direct OS queries for MAC address are blocked, then application security is improved, but network location service capability deteriorates
Solution Approach 1:
The patent employs a network element as an intermediary that bridges the gap between security-restricted applications and location information. The intermediary securely retrieves the MAC address from the network stack and delivers it to the application, preventing direct OS queries while ensuring location information access.
Solution Approach 2:
The system establishes a feedback loop where the application requests location information, the network element retrieves the MAC address through authorized channels, and returns it to the application. This feedback mechanism ensures that location information is provided through a controlled, secure process rather than direct access.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Techniques are presented to enable a network element in a network to receive a request from an application on a device, the request being encapsulated in a packet that includes a header that contains a physical layer identifier of the device to which the application does not have access. The physical layer identifier at the network element may be obtained. A response may be sent to the application on the device, the response containing at least one of the physical layer identifier of the device and location information of the device.