IP Library › Granted Patent US 10,972,430
Granted Patent B2
US 10,972,430 · App. 16/552,202 · Granted Apr 6, 2021

Allocation of local MAC addresses to client devices

Inventors: Brian Eliot Weis (San Jose, CA); Peter Geoffrey Jones (Campbell, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L61/6022H04L61/2038H04L63/0428H04L63/061H04L63/08H04L63/123H04L63/162
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,972,430
App. No.
16/552,202
Granted
Apr 6, 2021
Kind
B2
Abstract

At a network device configured to control access to a network, a client device authentication request is received from a client device. The request includes identity credentials and a temporary media access control (MAC) address of the client device. The client device is successfully authenticated based on the identity credentials. After authentication, a new MAC address is established in the client device. A data frame is received from at the network device. It is determined whether the client device is using the new MAC address based on the received data frame. If it is determined that the client device is using the new MAC address, the client device is permitted access the network.

Claims (50)

1. A method comprising:

at a network device connected with a network:

obtaining from a client device an authentication request including identity credentials and a temporary media access control (MAC) address of the client device; and

in response to successfully authenticating the client device based on the identity credentials:

selecting a new MAC address of the client device from among a plurality of available MAC addresses stored in a MAC address server in the network;

providing the new MAC address to the client device in an address allocation frame;

obtaining a data frame;

determining whether the client device is using the new MAC address based on the data frame; and

if it is determined that the client device is using the new MAC address:

granting the client device access to the network; and

generating a record including the new MAC address, a time at which the new MAC address was selected, and a time at which the new MAC address became available for reselection.

2. The method of claim 1 , wherein the record further includes the identity credentials.

3. The method of claim 1 , wherein the record further includes a time at which the client device was successfully authenticated based on the identity credentials.

4. The method of claim 1 , wherein the record further includes a flag indicating whether the new MAC address is currently selected.

5. The method of claim 4 , wherein the record further includes a time at which the flag was set to indicate whether the new MAC address is currently selected.

6. The method of claim 1 , wherein the record further includes the temporary MAC address.

7. The method of claim 1 , wherein the record further includes a time at which the temporary MAC address was obtained.

8. An apparatus comprising:

a network interface unit configured to communicate with a client device and a network; and

a processor coupled to the network interface unit, and configured to:

obtain from the client device an authentication request including identity credentials and a temporary media access control (MAC) address of the client device; and

in response to successfully authenticating the client device based on the identity credentials:

select a new MAC address of the client device from among a plurality of available MAC addresses stored in a MAC address server in the network;

provide the new MAC address to the client device in an address allocation frame;

obtain a data frame;

determine whether the client device is using the new MAC address based on the data frame; and

if it is determined that the client device is using the new MAC address:

grant the client device access to the network; and

generate a record including the new MAC address, a time at which the new MAC address was selected, and a time at which the new MAC address became available for reselection.

9. The apparatus of claim 8 , wherein the record further includes the identity credentials.

10. The apparatus of claim 8 , wherein the record further includes a time at which the client device was successfully authenticated based on the identity credentials.

11. The apparatus of claim 8 , wherein the record further includes a flag indicating whether the new MAC address is currently selected.

12. The apparatus of claim 11 , wherein the record further includes a time at which the flag was set to indicate whether the new MAC address is currently selected.

13. The apparatus of claim 8 , wherein the record further includes the temporary MAC address.

14. The apparatus of claim 8 , wherein the record further includes a time at which the temporary MAC address was obtained.

15. A tangible processor readable medium storing instructions that, when executed by a processor, cause the processor to:

obtain from a client device an authentication request including identity credentials and a temporary media access control (MAC) address of the client device; and

in response to successfully authenticating the client device based on the identity credentials:

select a new MAC address of the client device from among a plurality of available MAC addresses stored in a MAC address server in a network;

provide the new MAC address to the client device in an address allocation frame;

obtain a data frame;

determine whether the client device is using the new MAC address based on the data frame; and

if it is determined that the client device is using the new MAC address:

grant the client device access to the network; and

generate a record including the new MAC address, a time at which the new MAC address was selected, and a time at which the new MAC address became available for reselection.

16. The tangible processor readable medium of claim 15 , wherein the record further includes the identity credentials.

17. The tangible processor readable medium of claim 15 , wherein the record further includes a time at which the client device was successfully authenticated based on the identity credentials.

18. The tangible processor readable medium of claim 15 , wherein the record further includes a flag indicating whether the new MAC address is currently selected and a time at which the flag was set to indicate whether the new MAC address is currently selected.

19. The tangible processor readable medium of claim 15 , wherein the record further includes the temporary MAC address.

20. The tangible processor readable medium of claim 15 , wherein the record further includes a time at which the temporary MAC address was obtained.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2020
From: WEIS, BRIAN ELIOT; JONES, PETER GEOFFREY
To: CISCO TECHNOLOGY, INC.
Reel/Frame 054579/0079 →
Continuity (2)
Continuation 14944743 · Nov 18, 2015
Related Publication 20190386955A1 · Dec 19, 2019