Virtual MAC Address Segmentation for Wi-Fi Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wi-Fi communication networks lack effective privacy protection schemes, exposing users to privacy leaks due to the exposure of hardware identifiers like MAC addresses, which can be exploited by attackers to infer personal information, especially with the increasing use of IoT devices.
Innovation Solution
Implementing content-based identifier randomization and adaptation in user equipment, where software-defined virtual identifiers are created based on content categories, decoupling different content types to prevent the creation of a user's Point-of-Interest profile, ensuring that even if an attacker filters traffic by MAC address, they only see traffic related to one category, making it impossible to aggregate multiple points-of-interest.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MAC address is used for traffic identification in Wi-Fi networks, then data communication is enabled, but user privacy is exposed to attackers who can filter and aggregate traffic to create user profiles
Solution Approach 1:
The patent segments the single MAC address into multiple virtual MAC addresses, each associated with a specific content category. This segmentation allows traffic to be divided into category-specific streams, preventing attackers from aggregating complete user profiles while maintaining communication functionality for each category.
Solution Approach 2:
The patent applies local quality by assigning different privacy protection characteristics to different content categories. Each category receives a dedicated virtual MAC address with specific randomization properties, allowing tailored privacy protection for sensitive categories while maintaining standard communication for non-sensitive categories.
2Object-affected harmful factors
If MAC address randomization is implemented to protect privacy, then user privacy is improved, but service quality deteriorates due to session interruptions and connection drops
Solution Approach 1:
The patent implements dynamic virtual MAC address selection based on content category rather than random changes during sessions. The system dynamically assigns appropriate virtual MAC addresses according to the category of content being accessed, providing continuous privacy protection without causing session interruptions or connection drops.
Solution Approach 2:
The patent introduces virtual MAC addresses as intermediaries between the user equipment and the network. These virtual addresses act as a privacy-preserving layer that maintains stable connections while preventing direct exposure of the real MAC address, thus serving as a mediator that protects privacy without disrupting service quality.
3Object-affected harmful factors
If content-based identifier randomization is implemented, then user privacy is fully protected by preventing profile creation, but device complexity increases due to multiple virtual identifiers
Solution Approach 1:
The patent makes the network interface controller multi-functional by enabling it to handle multiple virtual MAC addresses simultaneously. This universal capability allows the same hardware interface to manage different content categories and their associated virtual identifiers, reducing the need for separate hardware components for each category.
Solution Approach 2:
The patent changes the parameter of MAC address from a single fixed value to multiple virtual values that can be changed based on content category. This parameter change allows the system to maintain a manageable number of virtual addresses by changing only the selected address based on category, rather than managing separate identifiers for every possible variation.
Data Source
Figure 1~2
Figure 3
AI summary
The invention relates to a user equipment 100 and a method for communication with an access point 200 in a communication network, with a view of protecting user privacy, and finding an application particularly in wireless communication networks such as Wi-Fi communication network. The user equipment 100 comprises a processing unit, a memory unit 102, 104, and a communication interface 101, 103 for data communication with said access point 200 under control of said processing unit, said communication interface being configured to use an identifier 300 stored in the memory such that any data communication sent by the communication interface to the access point, is associated with said identifier. The memory unit further comprises a category-to-identifier database 102 in which one or more virtual identifiers 300i are stored each associated with a specific content category Ci. The communication interface is further configured to determine which specific content category a determined data to be sent to the access point belongs to, to obtain from the category-to-identifier database the virtual identifier corresponding to the specific content category which the determined data belongs to, and to allocate to said determined data said virtual identifier as identifier to be used for transmission of said determined data to the access point.