Network Trust via Temporary Device Identifiers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network systems face challenges in maintaining functionality when users employ randomized MAC addresses for privacy, which can break important network features relying on persistent device identification.
Innovation Solution
Implementing a method where a network device, such as a DHCP server, uses digital certificates and temporary device identifiers to establish trust with client devices, allowing for persistent information sharing and identification across sessions, while enabling the use of different identifiers with different networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If randomized MAC addresses are used for privacy protection, then user privacy is improved, but network functionality relying on persistent device identification deteriorates
Solution Approach 1:
The patent segments device identifiers into two distinct types: permanent identifiers (for trusted networks requiring persistent identification) and temporary/randomized identifiers (for untrusted networks requiring privacy). This segmentation allows each identifier type to serve its specific purpose without compromising the other, resolving the contradiction between privacy protection and network functionality.
Solution Approach 2:
The patent implements dynamic identifier selection where the device can switch between permanent and temporary identifiers based on network trust status. The system dynamically determines whether to use a permanent MAC address or generate a randomized one, allowing adaptability to different network environments and resolving the fixed contradiction between privacy and functionality.
2Reliability
If permanent device identifiers are used for network functionality, then network service reliability is improved, but user privacy protection deteriorates
Solution Approach 1:
The patent applies different identifier qualities to different network contexts: permanent identifiers are used locally in trusted networks where functionality is prioritized, while temporary identifiers are used in untrusted networks where privacy is prioritized. This local quality differentiation resolves the contradiction by optimizing for the appropriate concern in each context.
Solution Approach 2:
The patent changes the identifier parameter (from permanent to temporary) based on network trust evaluation. When a network is deemed untrusted, the system changes the identifier parameter to temporary/randomized mode, and vice versa. This parameter change mechanism allows the system to balance privacy and functionality based on external conditions.
3Loss of information
If temporary randomized identifiers are used, then user tracking protection is improved, but persistent network service access deteriorates
Solution Approach 1:
The system dynamically adjusts identifier persistence based on service requirements and network context. For services requiring persistent access, the system maintains permanent identifiers; for services where privacy is paramount, it uses temporary identifiers. This dynamic adjustment resolves the contradiction between tracking protection and service access productivity.
Solution Approach 2:
The patent performs preliminary evaluation of network trust status before establishing connection, and pre-configures the appropriate identifier type accordingly. This preliminary action ensures that the correct identifier (permanent or temporary) is in place before network services are accessed, avoiding subsequent functionality issues while maintaining privacy where appropriate.
Data Source
AI summary
Methods and systems are described for managing communication in a network. A computing device may send a request to a network device for network address. The request may comprise a temporary device identifier associated with the computing device. The network device may send data indicating an option to trust the network device. If the computing device indicates acceptance of the option to trust the network device, additional information may be sent to the network device to allow identification of the computing device from one session to another.


