UDN Authentication via Cloud Passcode for MAC Rotation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
User Defined Networks (UDNs) face challenges with MAC address rotation, where the uniqueness of MAC addresses as device identities is lost, leading to authentication issues and difficulties in enforcing traffic containment policies, especially when operating systems restrict access to MAC addresses through APIs.
Innovation Solution
Generating a unique passcode associated with the UDN identifier, which allows endpoint devices to authenticate and connect to the network independently of their MAC addresses, using techniques such as pre-shared key (PSK) and simultaneous authentication of equals (SAE) based authentication mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MAC address rotation is implemented to enhance security and privacy, then device anonymity and security are improved, but authentication reliability and network policy enforcement deteriorate
Solution Approach 1:
The patent introduces a cloud-based authentication service as an intermediary between endpoint devices and the network. This service maintains persistent device profiles and generates dynamic passcodes, mediating between the rotating MAC addresses and the network's authentication requirements. The intermediary preserves authentication reliability by decoupling device identity from the transient MAC address.
Solution Approach 2:
The patent changes the authentication parameter from static MAC address to dynamic passcode generated through cloud-based authentication. This parameter transformation allows the system to accommodate MAC address rotation while maintaining secure authentication, as the passcode remains valid regardless of MAC address changes.
2Object-affected harmful factors
If MAC address rotation is implemented, then security against tracking and unauthorized access is improved, but device identification and traffic policy enforcement become difficult
Solution Approach 1:
The cloud authentication service acts as an intermediary that tracks devices through persistent cloud profiles rather than through MAC addresses. This allows the system to maintain device identification capabilities for policy enforcement while the actual MAC addresses remain rotating and invisible to the network infrastructure.
Solution Approach 2:
The patent creates a virtual copy of device identity in the cloud that persists across MAC address changes. This digital twin or profile copy maintains the device's identity, permissions, and policy associations, allowing the network to identify and manage devices based on their cloud profile rather than their physical MAC address.
3Reliability
If operating systems restrict MAC address access through APIs, then device security is improved, but network authentication and device registration become complex
Solution Approach 1:
The system implements self-service authentication where endpoint devices autonomously generate authentication requests and receive passcodes through the cloud authentication service without requiring manual MAC address configuration or complex user intervention. The device's authentication client handles the entire process automatically, simplifying the user experience despite the underlying complexity.
Solution Approach 2:
The cloud authentication service mediates between the operating system's restricted MAC address access and the network's authentication requirements. It provides alternative authentication pathways that do not require direct MAC address access, thereby maintaining device security while enabling seamless network authentication.
4Ease of operation
If traditional MAC address-based authentication is used, then device identification is simple and direct, but security and control over shared networks are weakened
Solution Approach 1:
The cloud authentication service introduces an intermediary layer that maintains simple device identification through cloud profiles while enhancing network security through centralized authentication, authorization, and account management. This intermediary enables both ease of device identification and strong security controls simultaneously.
Solution Approach 2:
The cloud-based authentication system provides multiple functions: device identification, security authentication, policy enforcement, and account management. This universal system replaces the simple but insecure MAC address-based identification with a multi-functional security framework that maintains ease of operation while dramatically improving network security.
Data Source
AI summary
Methods are provided that support media access control (MAC) address rotation (RCM) by generating a passcode for associating a user defined network by one or more endpoint devices instead of using MAC addresses for their respective device identity. In these methods, a computing device obtains a registration request for establishing a user defined network (UDN) and generates a unique UDN identifier and a unique passcode associated with the unique UDN identifier. The unique passcode enables an authentication of one or more endpoint devices to connect to the UDN. The authentication is independent of the MAC address of a respective endpoint device. The computing device provides the UDN identifier and the unique passcode such that the UDN identifier and the unique passcode are for connecting the one or more endpoint devices to the UDN.


