UDN Authentication via Cloud Passcode for MAC Rotation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

User Defined Networks (UDNs) face challenges with MAC address rotation, where the uniqueness of MAC addresses as device identities is lost, leading to authentication issues and difficulties in enforcing traffic containment policies, especially when operating systems restrict access to MAC addresses through APIs.

Innovation Solution

Generating a unique passcode associated with the UDN identifier, which allows endpoint devices to authenticate and connect to the network independently of their MAC addresses, using techniques such as pre-shared key (PSK) and simultaneous authentication of equals (SAE) based authentication mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MAC address rotation is implemented to enhance security and privacy, then device anonymity and security are improved, but authentication reliability and network policy enforcement deteriorate

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidMAC address stability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a cloud-based authentication service as an intermediary between endpoint devices and the network. This service maintains persistent device profiles and generates dynamic passcodes, mediating between the rotating MAC addresses and the network's authentication requirements. The intermediary preserves authentication reliability by decoupling device identity from the transient MAC address.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the authentication parameter from static MAC address to dynamic passcode generated through cloud-based authentication. This parameter transformation allows the system to accommodate MAC address rotation while maintaining secure authentication, as the passcode remains valid regardless of MAC address changes.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If MAC address rotation is implemented, then security against tracking and unauthorized access is improved, but device identification and traffic policy enforcement become difficult

Engineering Contradiction:
Improvedevice tracking vulnerabilityVSAvoiddevice identification
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The cloud authentication service acts as an intermediary that tracks devices through persistent cloud profiles rather than through MAC addresses. This allows the system to maintain device identification capabilities for policy enforcement while the actual MAC addresses remain rotating and invisible to the network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtual copy of device identity in the cloud that persists across MAC address changes. This digital twin or profile copy maintains the device's identity, permissions, and policy associations, allowing the network to identify and manage devices based on their cloud profile rather than their physical MAC address.

Inventive Principle:
Principle #26Copying

3Reliability

If operating systems restrict MAC address access through APIs, then device security is improved, but network authentication and device registration become complex

Engineering Contradiction:
Improvedevice securityVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service authentication where endpoint devices autonomously generate authentication requests and receive passcodes through the cloud authentication service without requiring manual MAC address configuration or complex user intervention. The device's authentication client handles the entire process automatically, simplifying the user experience despite the underlying complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The cloud authentication service mediates between the operating system's restricted MAC address access and the network's authentication requirements. It provides alternative authentication pathways that do not require direct MAC address access, thereby maintaining device security while enabling seamless network authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If traditional MAC address-based authentication is used, then device identification is simple and direct, but security and control over shared networks are weakened

Engineering Contradiction:
Improvedevice identificationVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The cloud authentication service introduces an intermediary layer that maintains simple device identification through cloud profiles while enhancing network security through centralized authentication, authorization, and account management. This intermediary enables both ease of device identification and strong security controls simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cloud-based authentication system provides multiple functions: device identification, security authentication, policy enforcement, and account management. This universal system replaces the simple but insecure MAC address-based identification with a multi-functional security framework that maintains ease of operation while dramatically improving network security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240388581A1User defined network access that supports address rotation
Publication Date: 2024.11.21 CISCO TECHNOLOGY INC
  • US20240388581A1 patent drawing
  • US20240388581A1 patent drawing
  • US20240388581A1 patent drawing

AI summary

Methods are provided that support media access control (MAC) address rotation (RCM) by generating a passcode for associating a user defined network by one or more endpoint devices instead of using MAC addresses for their respective device identity. In these methods, a computing device obtains a registration request for establishing a user defined network (UDN) and generates a unique UDN identifier and a unique passcode associated with the unique UDN identifier. The unique passcode enables an authentication of one or more endpoint devices to connect to the UDN. The authentication is independent of the MAC address of a respective endpoint device. The computing device provides the UDN identifier and the unique passcode such that the UDN identifier and the unique passcode are for connecting the one or more endpoint devices to the UDN.