Terminal Virtual MAC Address for WLAN Privacy Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Wi-Fi technologies allow third parties to track a terminal's device MAC address through a local area network, enabling them to associate data such as the terminal's model, price, and user location, thereby compromising user privacy.

Innovation Solution

The method involves using a virtual MAC address that is different from the device MAC address to identify a terminal device when accessing a wireless local area network, thereby preventing third parties from tracking the device MAC address.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a terminal sends its real device MAC address to Wi-Fi access points for connection establishment, then the terminal can be properly identified and connected to the network, but third parties can obtain the device MAC address through the access points and track the terminal's location and associate it with purchase information

Engineering Contradiction:
Improvenetwork connection reliabilityVSAvoiduser privacy leakage
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates a virtual MAC address that copies the format and structure of a real MAC address but uses randomized or modified values. This virtual address serves as a substitute that maintains network functionality while protecting the real device identifier. The virtual MAC address is generated by modifying the real MAC address (e.g., changing the OUI portion or individual bytes) to create a plausible but fake identifier that third parties cannot trace back to the user.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The virtual MAC address acts as an intermediary between the terminal and the external network environment. Instead of the real device MAC address directly interacting with access points and being exposed to third parties, the virtual address serves as a buffer that protects the real identifier while still enabling network communication and identification functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If a virtual MAC address is used to replace the device MAC address for terminal identification, then third parties cannot track the device MAC address and associate user information, but the terminal must implement additional logic to generate and manage virtual addresses

Engineering Contradiction:
Improveuser privacy protectionVSAvoidaddress management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent modifies specific parameters of the real MAC address to generate the virtual address. This includes changing the OUI (Organizationally Unique Identifier) portion, modifying individual bytes, or applying randomized transformations to specific fields while maintaining the overall MAC address structure. These parameter changes create a new identifier that is functionally equivalent but privacy-protecting.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The terminal device itself generates and manages its own virtual MAC address without requiring external services or complex infrastructure. The device autonomously creates the virtual address by processing its real MAC address through the virtualization logic, and manages the address lifecycle including generation, usage, and updates independently, reducing system complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12219470B2Method for accessing wireless local area network and terminal
Publication Date: 2025.02.04 NOKIA TECHNOLOGIES OY
  • US12219470B2 patent drawing
  • US12219470B2 patent drawing
  • US12219470B2 patent drawing

AI summary

A method for accessing a wireless local area network (WLAN) includes a terminal receiving type information of the WLAN and identification information of the WLAN from an access point. The terminal determines a type of the WLAN based on the type information. The terminal sends, to the access point when the terminal determines that the type is a type I, a message requesting to access the WLAN. The message carries a virtual media access control (MAC) address, where the virtual MAC address identifies the terminal, and where the virtual MAC address is different from a device MAC address of the terminal.