On-Network Device Identification via Mediated Address Disclosure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service providers face challenges in determining the address of user devices connected to their network due to masking by network devices, hindering authorization and service provision.
Innovation Solution
User devices make API calls to network devices, allowing the network devices to generate and communicate indications of their addresses, enabling service providers to determine device attachment and authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network devices use masking to prevent service provider computing devices from determining user device addresses, then network security and privacy are improved, but the ability of service providers to identify and authorize user devices deteriorates
Solution Approach 1:
The patent introduces an intermediary mechanism where the network device itself acts as a mediator to reveal address information. Instead of direct access being blocked, the network device receives a prompt message, generates an indication message containing the user device address based on its local information, and sends this indication to the service provider computing device. This intermediary approach maintains security while enabling necessary information flow.
Solution Approach 2:
The system performs preliminary action by having the network device generate and store the indication message containing user device address information in advance, before the service provider needs to query it. When a prompt message is received, the network device can quickly retrieve or generate the pre-prepared address information, enabling efficient authorization without real-time complex processing.
2Loss of information
If network devices mask user device addresses to protect privacy, then user privacy is improved, but service provision capability deteriorates
Solution Approach 1:
The system implements a feedback mechanism where the service provider computing device sends a prompt message to the network device when address information is needed. The network device responds by generating and sending back an indication message containing the user device address. This feedback loop enables on-demand information retrieval, balancing privacy protection with service provision needs.
Solution Approach 2:
The network device serves as an intermediary that selectively discloses address information to service providers through a controlled message exchange process. This intermediary role allows the system to maintain privacy defaults while enabling service provision when legitimately needed, resolving the contradiction between privacy protection and service capability.
3Reliability
If service providers cannot determine user device addresses due to masking, then network security is improved, but authorization capability deteriorates
Solution Approach 1:
The network device acts as an intermediary that facilitates the authorization process by generating indication messages containing user device address information. This intermediary mechanism maintains security protocols while enabling the authorization capability, as the service provider can now receive the necessary address information through the controlled message exchange process.
Solution Approach 2:
The system prepares address information in advance at the network device level, so when authorization is needed, the information is already available or can be quickly generated. This preliminary preparation eliminates the need for complex real-time address determination processes, improving authorization capability while maintaining security.
Data Source
AI summary
Systems and methods are described for on-network device identification. A user device may make an application programming interface (API) call to an address associated with a network device. The API call may comprise an indication of an address associated with the user device. Based on the API call, the network device may send an indication of the address to a computing device associated with an on-network service. The computing device associated with the on-network service may determine that the user device is authorized to connect to a network or to access an on-network service.


