Permanent MAC Address Retrieval for Privacy-Compatible Wi-Fi Roaming
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The randomization of media access control (MAC) addresses by devices for privacy purposes hinders Wi-Fi features and inter-operator roaming, leading to issues such as bloated association records, impaired security, and ineffective policy enforcement.
Innovation Solution
Implementing a network server that receives and authenticates user devices using both randomized and real MAC addresses, with methods like new EAP types, ciphered tunnels, and extended 802.11 frames to ensure consistent MAC address usage for authentication and access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If devices randomize MAC addresses for privacy purposes, then user privacy is protected, but Wi-Fi features and inter-operator roaming are hindered
Solution Approach 1:
The patent segments the MAC address usage into two distinct parts: a randomized MAC address for privacy protection during general Wi-Fi operations, and a stable real MAC address reserved for authentication and inter-operator roaming scenarios. This segmentation allows both privacy protection and feature compatibility to coexist by using different MAC addresses for different purposes.
Solution Approach 2:
The patent introduces an intermediary mechanism (authentication server or network infrastructure) that mediates between the randomized MAC address and the stable real MAC address. During authentication, the intermediary facilitates the transition from randomized MAC to stable MAC, enabling inter-operator roaming while maintaining privacy during normal operations.
2Object-affected harmful factors
If devices randomize MAC addresses, then tracking by unauthorized entities is prevented, but association records become bloated
Solution Approach 1:
The patent segments MAC address functionality to use randomized MAC addresses only for initial association and privacy-protected operations, while reserving stable real MAC addresses for authentication and record-keeping purposes. This reduces association record bloat by limiting the use of randomized MAC addresses to specific scenarios rather than all operations.
Solution Approach 2:
The patent implements a mechanism where randomized MAC addresses are discarded after initial association, and the stable real MAC address is recovered and used for subsequent authentication and record maintenance. This cycle of discarding and recovering MAC addresses prevents accumulation of bloated association records while maintaining tracking prevention.
3Object-affected harmful factors
If devices randomize MAC addresses, then user privacy is protected, but security is impaired
Solution Approach 1:
The patent segments MAC address usage by function: randomized MAC addresses are used for privacy protection during general communication, while stable real MAC addresses are reserved for security-critical authentication operations. This segmentation ensures that security is not impaired by randomization, as the stable MAC address provides a reliable identifier for authentication and authorization.
Solution Approach 2:
The patent implements preliminary action by establishing the stable real MAC address as the foundation for authentication before any randomized MAC address operations occur. This preliminary establishment of a stable identifier ensures that security protocols can function reliably while still allowing privacy protection through randomization in non-authentication contexts.
4Object-affected harmful factors
If devices randomize MAC addresses, then privacy is protected, but policy enforcement becomes ineffective
Solution Approach 1:
The patent segments MAC address functionality to use stable real MAC addresses specifically for policy enforcement and authorization operations, while allowing randomized MAC addresses for general communication. This segmentation enables effective policy enforcement by providing network administrators with a stable identifier to apply and enforce policies, while still maintaining privacy protection through randomization in other contexts.
Data Source
AI summary
A network server is provided. The network server includes at least one processor in communication with at least one memory device. The network server is programmed to receive an access request originating from a user device, perform an authentication process for connecting with the user device, transmit, to the user device, a request message for a media access control (MAC) address of the user device, receive, from the user device, a response message including the MAC address of the user device, and determine whether to grant the access request based on the MAC address of the user device.


