Roaming MAC Address Mapping for Seamless Wi‑Fi Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The introduction of MAC address randomization in EDP mode in IEEE 802.11bi complicates seamless roaming within a Seamless Mobility Domain (SMD) by making it difficult for target APs to recognize and authenticate stations (STAs) due to frequent changes in their MAC addresses, leading to increased latency and reauthentication overhead.

Innovation Solution

The use of roaming-specific MAC addresses (RMAs) and PTK mappings allows target APs to correctly identify and authenticate STAs during roaming, even when primary MAC addresses change, by associating RMAs with PTKs and optionally using a distribution system (DS) MAC address as an intermediate identifier.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MAC address randomization is implemented in EDP mode, then security and privacy are improved, but seamless roaming capability deteriorates due to target APs unable to recognize STAs with changed MAC addresses

Engineering Contradiction:
ImprovesecurityVSAvoidroaming capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a roaming-specific MAC address (RMA) as an intermediary identifier that remains consistent across roaming events. The RMA acts as a mediator between the randomized MAC address (which changes for security) and the PTK mapping system (which needs consistent identification). This allows target APs to recognize STAs during roaming while maintaining MAC address randomization for security purposes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If MAC address changes frequently for security purposes, then security is improved, but authentication latency increases due to reauthentication overhead

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent establishes PTK mappings with RMAs in advance during initial association. When roaming occurs, the target AP can immediately use the pre-established RMA-PTK mapping to authenticate the STA without requiring time-consuming reauthentication. This preliminary setup eliminates authentication latency during roaming while maintaining security through MAC address randomization.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If primary MAC addresses are randomized frequently, then privacy is improved, but target APs cannot correctly identify STAs leading to reauthentication overhead

Engineering Contradiction:
ImproveprivacyVSAvoididentification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the MAC address functionality into two distinct components: the primary MAC address (which is randomized for privacy) and the roaming-specific MAC address (RMA, which remains consistent for identification). This segmentation allows the system to maintain privacy through randomization while simplifying identification during roaming using the stable RMA, thereby reducing the complexity of STA identification.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20260082202A1Random media access control (MAC) address for roaming
Publication Date: 2026.03.19 CISCO TECHNOLOGY INC
  • US20260082202A1 patent drawing
  • US20260082202A1 patent drawing
  • US20260082202A1 patent drawing

AI summary

The present disclosure provides techniques for client device roaming using randomized media access control (MAC) addresses in enhanced data privacy (EDP) operation. A first access point (AP) in a seamless mobility domain (SMD) receives a message as part of an initial association process with a station (STA). The first AP establishes one or more roaming-specific media access control (MAC) addresses (RMAs) for the STA as part of message exchange during the initial association process. The first AP establishes a first pairwise transient key (PTK) with the STA and generates a PTK mapping that associates the first PTK with the one or more RMAs of the STA.