Roaming MAC Address Mapping for Seamless Wi‑Fi Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The introduction of MAC address randomization in EDP mode in IEEE 802.11bi complicates seamless roaming within a Seamless Mobility Domain (SMD) by making it difficult for target APs to recognize and authenticate stations (STAs) due to frequent changes in their MAC addresses, leading to increased latency and reauthentication overhead.
Innovation Solution
The use of roaming-specific MAC addresses (RMAs) and PTK mappings allows target APs to correctly identify and authenticate STAs during roaming, even when primary MAC addresses change, by associating RMAs with PTKs and optionally using a distribution system (DS) MAC address as an intermediate identifier.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MAC address randomization is implemented in EDP mode, then security and privacy are improved, but seamless roaming capability deteriorates due to target APs unable to recognize STAs with changed MAC addresses
Solution Approach 1:
The patent introduces a roaming-specific MAC address (RMA) as an intermediary identifier that remains consistent across roaming events. The RMA acts as a mediator between the randomized MAC address (which changes for security) and the PTK mapping system (which needs consistent identification). This allows target APs to recognize STAs during roaming while maintaining MAC address randomization for security purposes.
2Reliability
If MAC address changes frequently for security purposes, then security is improved, but authentication latency increases due to reauthentication overhead
Solution Approach 1:
The patent establishes PTK mappings with RMAs in advance during initial association. When roaming occurs, the target AP can immediately use the pre-established RMA-PTK mapping to authenticate the STA without requiring time-consuming reauthentication. This preliminary setup eliminates authentication latency during roaming while maintaining security through MAC address randomization.
3Reliability
If primary MAC addresses are randomized frequently, then privacy is improved, but target APs cannot correctly identify STAs leading to reauthentication overhead
Solution Approach 1:
The patent segments the MAC address functionality into two distinct components: the primary MAC address (which is randomized for privacy) and the roaming-specific MAC address (RMA, which remains consistent for identification). This segmentation allows the system to maintain privacy through randomization while simplifying identification during roaming using the stable RMA, thereby reducing the complexity of STA identification.
Data Source
AI summary
The present disclosure provides techniques for client device roaming using randomized media access control (MAC) addresses in enhanced data privacy (EDP) operation. A first access point (AP) in a seamless mobility domain (SMD) receives a message as part of an initial association process with a station (STA). The first AP establishes one or more roaming-specific media access control (MAC) addresses (RMAs) for the STA as part of message exchange during the initial association process. The first AP establishes a first pairwise transient key (PTK) with the STA and generates a PTK mapping that associates the first PTK with the one or more RMAs of the STA.


