IP Library › Granted Patent US 12,267,915
Granted Patent B2
US 12,267,915 · App. 17/355,686 · Granted Apr 1, 2025

Device address rotation method to protect against unconsented tracking

Inventors: Shankar Ramanathan (Richardson, TX); Nagendra Kumar Nainar (Morrisville, NC); Robert E. Barton (Richmond, CA); Jerome Henry (Pittsboro, NC)
Assignee: CISCO TECHNOLOGY, INC.
H04W8/26H04W4/023H04W12/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,267,915
App. No.
17/355,686
Granted
Apr 1, 2025
Kind
B2
Abstract

A network infrastructure component determines a risk measurement associated with a wireless client device's use of a device address, and provides an advisory with respect to an address rotation strategy of the wireless client device based on the risk measurement. In some embodiments, the risk measurement is based on one or more of an exposure, by the wireless client device, of information on the wireless network that identifies the wireless client device and/or a characterization of a security of the wireless network environment in which the wireless client device operates.

Claims (32)

1. A method, comprising:

analyzing wireless communication of a wireless client device on a wireless network;

generating, based on the analyzing, a risk measurement associated with the wireless communication, wherein the risk measurement is generated based, at least in part, on determining a density of other wireless client devices on the wireless network that are an equivalent device type as a device type of the wireless client device and that are located within a predefined threshold distance from the wireless client device; and

transmitting to the wireless client device, based on the risk measurement, an advisory on rotation of a device address of the wireless client device, wherein the advisory comprises one or more attributes indicating a recommended address rotation strategy for the wireless client device that indicates a recommended timing for which the wireless client device is recommended to perform at least one next device address rotation.

2. The method of claim 1 , further comprising determining one or more of: a use of unprotected identifiers in the wireless communication, a correlation between device addresses of multiple radios of the wireless client device, a frequency of probe traffic on the wireless network, and/or a correlation between signatures of a plurality of communications of the wireless client device, wherein the generating of the risk measurement is further based on the determining.

3. The method of claim 2 , further comprising identifying a transmission of vendor specific information elements, a sleep/wake pattern, block acknowledgment pattern, or packet transmission pattern of the wireless client device, wherein the signatures are based on the identifying.

4. The method of claim 1 , wherein at least one attribute of the one or more attributes indicated by the recommended address rotation strategy indicates a delay for the recommended timing of a next device address rotation for the wireless client device.

5. The method of claim 1 , wherein at least one attribute of the one or more attributes indicated by the recommended address rotation strategy indicates a rate for the recommended timing of a plurality of next device address rotations for the wireless client device.

6. The method of claim 1 , wherein at least one attribute of the one or more attributes indicated by the recommended address rotation strategy indicates a maximum time interval between device address rotations for the recommended timing of a plurality of next device address rotations of the wireless client device.

7. The method of claim 1 , further comprising determining a transmission power of the wireless client device, wherein the risk measurement is further based on the transmission power.

8. An apparatus, comprising:

a network interface configured to enable network communications;

one or more processors; and

one or more memories storing instructions that when executed configure the one or more processors to perform operations comprising:

analyzing wireless communication of a wireless client device on a wireless network;

generating, based on the analyzing, a risk measurement associated with the wireless communication, wherein the risk measurement is generated based, at least in part, on determining a density of other wireless client devices on the wireless network that are an equivalent device type as a device type of the wireless client device and that are located within a predefined threshold distance from the wireless client device; and

transmitting to the wireless client device, based on the risk measurement, an advisory on rotation of a device address of the wireless client device, wherein the advisory comprises one or more attributes indicating a recommended address rotation strategy for the wireless client device that indicates a recommended timing for which the wireless client device is recommended to perform at least one next device address rotation.

9. The apparatus of claim 8 , the operations further comprising determining one or more of: a use of unprotected identifiers in the wireless communication, a correlation between device addresses of multiple radios of the wireless client device, a frequency of probe traffic on the wireless network, and/or a correlation between signatures of a plurality of communications of the wireless client device, wherein the generating of the risk measurement is further based on the determining.

10. The apparatus of claim 9 , the operations further comprising identifying a transmission of vendor specific information elements, a sleep/wake pattern, block acknowledgment pattern, or packet transmission pattern of the wireless client device, wherein the signatures are based on the identifying.

11. The apparatus of claim 8 , wherein at least one attribute of the one or more attributes indicated by the recommended address rotation strategy indicates a delay for the recommended timing of a next device address rotation for the wireless client device.

12. The apparatus of claim 8 , wherein at least one attribute of the one or more attributes indicated by the recommended address rotation strategy indicates a rate for the recommended timing of a plurality of next device address rotations for the wireless client device.

13. A non-transitory computer readable storage medium comprising instructions that when executed configure one or more processors to perform operations comprising:

analyzing wireless communication of a wireless client device on a wireless network;

generating, based on the analyzing, a risk measurement associated with the wireless communication, wherein the risk measurement is generated based, at least in part, on determining a density of other wireless client devices on the wireless network that are an equivalent device type as a device type of the wireless client device and that are located within a predefined threshold distance from the wireless client device; and

transmitting to the wireless client device, based on the risk measurement, an advisory on rotation of a device address of the wireless client device, wherein the advisory comprises one or more attributes indicating a recommended address rotation strategy for the wireless client device that indicates a recommended timing for which the wireless client device is recommended to perform at least one next device address rotation.

14. The non-transitory computer readable storage medium of claim 13 , the operations further comprising determining one or more of: a use of unprotected identifiers in the wireless communication, a correlation between device addresses of multiple radios of the wireless client device, a frequency of probe traffic on the wireless network, and/or a correlation between signatures of a plurality of communications of the wireless client device, wherein the generating of the risk measurement is further based on the determining.

15. The non-transitory computer readable storage medium of claim 14 , the operations further comprising identifying a transmission of vendor specific information elements, a sleep/wake pattern, block acknowledgment pattern, or packet transmission pattern of the wireless client device, wherein the signatures are based on the identifying.

16. The method of claim 1 , wherein the device address of the wireless client device is a Media Access Control (MAC) address of the wireless client device.

17. The method of claim 1 , wherein the advisory further comprises an acceptable use policy that defines a maximum time interval that the wireless client device can operate without performing the at least one next device address rotation and the wireless client device is to acknowledge the acceptable use policy.

18. The method of claim 17 , wherein the acceptable use policy further defines a minimum time between each of a plurality of next device address rotations to be performed by the wireless client device.

19. The method of claim 1 , wherein determining the density includes determining the density based on a density weight function that is based on a number of a plurality of wireless client devices on the wireless network within an area and on a number of the other wireless client devices on the wireless network that are an equivalent device type as the wireless client device within the area.

20. The non-transitory computer readable storage medium of claim 13 , wherein determining the density includes determining the density based on a density weight function that is based on a number of a plurality of wireless client devices on the wireless network within an area and on a number of the other wireless client devices on the wireless network that are an equivalent device type as the wireless client device within the area.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2021
From: RAMANATHAN, SHANKAR; NAINAR, NAGENDRA KUMAR; BARTON, ROBERT E.; HENRY, JEROME
To: CISCO TECHNOLOGY, INC.
Reel/Frame 056639/0355 →
Continuity (1)
Related Publication 20220417734A1 · Dec 29, 2022
References Cited (60)
US 9385911B2 · Vermani et al. · 2016 [cited by applicant]
US 10212583B1 · Hooda et al. · 2019 [cited by applicant]
US 10805982B1 · Buckley et al. · 2020 [cited by applicant]
US 11722369B2 · Zhou et al. · 2023 [cited by applicant]
US 11855960B2 · Henry et al. · 2023 [cited by applicant]
US 11877334B2 · Ficara et al. · 2024 [cited by applicant]
US 11962588B2 · Fang · 2024 [cited by applicant]
US 20030177267A1 · Orava et al. · 2003 [cited by applicant]
US 20040059909A1 · Le Pennec · 2004 [cited by examiner]
US 20050050352A1 · Narayanaswami et al. · 2005 [cited by applicant]
US 20060120317A1 · Zheng · 2006 [cited by applicant]
US 20100093378A1 · Chin et al. · 2010 [cited by applicant]
US 20140007236A1 · Krueger · 2014 [cited by examiner]
US 20150381565A1 · Thaler et al. · 2015 [cited by applicant]
US 20160135041A1 · Lee et al. · 2016 [cited by applicant]
US 20160135053A1 · Lee et al. · 2016 [cited by applicant]
US 20160344681A1 · Lambert et al. · 2016 [cited by applicant]
US 20170201930A1 · Chen et al. · 2017 [cited by applicant]
US 20180115982A1 · Reddy et al. · 2018 [cited by applicant]
US 20180324142A1 · Adrangi et al. · 2018 [cited by applicant]
US 20190037390A1 · Hooda et al. · 2019 [cited by applicant]
US 20190357143A1 · Wang et al. · 2019 [cited by applicant]
US 20200107213A1 · Park et al. · 2020 [cited by applicant]
US 20200107273A1 · Park et al. · 2020 [cited by applicant]
US 20200351648A1 · Fang · 2020 [cited by applicant]
US 20210068172A1 · Jeong et al. · 2021 [cited by applicant]
US 20210168115A1 · De La Oliva et al. · 2021 [cited by applicant]
US 20220086627A1 · Montemurro et al. · 2022 [cited by applicant]
US 20220167256A1 · Kneckt et al. · 2022 [cited by applicant]
US 20220200950A1 · Sekar et al. · 2022 [cited by applicant]
US 20220224671A1 · De La Oliva et al. · 2022 [cited by applicant]
US 20220264668A1 · Lumbatis · 2022 [cited by applicant]
US 20230292315A1 · Li et al. · 2023 [cited by applicant]
WO 2020010126A1 · 2020 [cited by applicant]
WO 2020148062A1 · 2020 [cited by applicant]
WO 2020221465A1 · 2020 [cited by applicant]
WO 2020229409A1 · 2020 [cited by applicant]
Alibaba Cloud, “The Principle of Arp-nat (MAC Address Translation)”, Alibaba Cloud, Nov. 9, 2017, Retrieved from https://topic.alibabacloud.com/a/the-principle-of-arp-nat-mac-address-translation_8_8_30147619.html on Dec… [cited by applicant]
Andersdotter A., et al., “IEEE. 802.11 Randomized and Changing MAC Addresses Topic Interest Group Report”, IEEE P802.11 Wireless LANs, IEEE 802.11-19/1442r9, Retrieved from https://mentor.ieee.org/802.11/dcn/19/11-19-14… [cited by applicant]
Andersdotter A., “Summary of Discussions on Randomized and Changing MAC Addresses 2014-2019”, IEEE P802.11, Wireless LANs, IEEE 802.11-19/588r2, Article 19, May 13, 2019, pp. 1-6. [cited by applicant]
Ansley C., et al., “Proposal for New Action Frame to Aid Mac Randomization Handling”, IEEE 802.11-19/0179r3, Retrieved from https://mentor.ieee.org/802.11/dcn/19/11-19-0179-03-0arc-idquery-query-message-proposal.pptx, J… [cited by applicant]
Ansley C., et al., “Proposed Text for ID Query Action Frame”, IEEE P802.11, Wireless LANs, 11-19-0496-01-000m11-19-0496-01-000m, CommScope, Jul. 2019, pp. 1-4. [cited by applicant]
Ansley C., “Status of IEEE 802.11 Randomized and Changing MAC Address Study Group”, IEEE, P802.11—Randomized and Changing MAC Address (RCM) Study Group (SG)—Meeting Update, Jan. 29, 2021, Retrieved from https://www.ieee… [cited by applicant]
Aosp, “Privacy: MAC Randomization”, Android Open Source Project, Retrieved from https://source.android.com/devices/tech/connect/wifi-mac-randomization on Dec. 4, 2020, 4 Pages. [cited by applicant]
Bellovin S.M., et al., “Privacy-Enhanced Searches Using Encrypted Bloom Filters”, Columbia University Computer Science Technical Reports, CUCS-034-07, Apr. 27, 2011, pp. 1-16. [cited by applicant]
CISCO: “802.11w Management Frame Protection MFP”, Cisco Meraki, Retrieved from https://documentation.meraki.com/MR/WiFi_Basics_and_Best_Practices/802.11w_Management_Frame_Protection_MFP, Oct. 5, 2020, pp. 1-2. [cited by applicant]
CISCO: “Configure 802.11w Management Frame Protection on WLC”, Cisco, Retrieved from https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/212576-configure-802-11w-management-frame-prote.html on… [cited by applicant]
David, “Did MacOS Stop Allowing Changes to Wifi MAC Addresses?”, Slashdot, Retrieved from https://mobile.slashdot.org/story/19/10/06/177216/did-macos-stop-allowing-changes-to-wifi-mac-addresses Oct. 6, 2019, 8 Pages. [cited by applicant]
Henry J., et al., “Parental Control Examples”, IEEE 802.11-21/0804r1, Retrieved from https://mentor.ieee.org/802.11/dcn/21/11-21-0804-01-00bh-rcm-parental-control-examples.pptx, May 10, 2021, pp. 1-12. [cited by applicant]
Henry J., et al., “Randomized and Changing MAC Address Use Cases”, Draft-henry-madinas-framework-02, Internet Engineering Task Force, Internet-Draft, May 3, 2021, pp. 1-18. [cited by applicant]
IEEE: “IEEE Standard for Information Technology—Telecommunications and Information Exchange between Systems—Local and Metropolitan Area Networks—Specific Requirements, Part 11: Wireless LAN Medium Access Control (MAC) a… [cited by applicant]
Lee Y., et al., “Problem Statements for MAC Address Randomization”, Draft-Lee-Randomized-Macaddr-ps-01, Internet Engineering Task Force, Internet-Draft, Sep. 22, 2020, pp. 1-6. [cited by applicant]
Marks R., “IEEE Std 802c: What's New and Useful in the Overview and Architecture”, IEEE 802.1 Contribution, Sep. 2017, 42 Pages. [cited by applicant]
Razaque A., et al., “Restoring the Privacy and Confidentiality of Users Over Mobile Collaborative Learning (MCL) Environment”, IEEE Transaction Latin America, vol. 9, No. 7, Dec. 2011, 13 Pages. [cited by applicant]
Stretch, “MAC Address Aggregation and Translation as an Alternative to L2 Overlays”, PacketLife, Nov. 18, 2014, Retrieved from https://packetlife.net/blog/2014/nov/18/mac-address-aggregation-and-translation/ on Dec. 2, … [cited by applicant]
Volz B., et al., “Link-Layer Addresses Assignment Mechanism for DHCPv6”, draft-bvtm-dhc-mac-assign-02, Dynamic Host Configuration (DHC), Oct. 20, 2018, pp. 1-18. [cited by applicant]
Wang P-C., et al., “MAC Address Translation for Enabling Scalable Virtual Private LAN Services”, 21st International Conference on Advanced Information Networking and Applications Workshops (AINAW'07), May 2007, 6 Pages. [cited by applicant]
Wi-Fi: “WPA3 Specification”, WiFi Alliance, Version 3, Retrieved from https://www.wi-fi.org/file/wpa3-specification, Dec. 20, 2019, 30 Pages. [cited by applicant]
Wikipedia: “CCMP (Cryptography)”, Wikipedia The Free Encyclopedia, Jun. 2021, Retrieved from https://en.wikipedia.org/wiki/CCMP_(cryptography) on Jul. 12, 2021, 3 Pages. [cited by applicant]
Zuniga J.C., et al., “MAC Address Randomization,” draft-zuniga-mac-address-randomization-01, IETF, Network Working Group, Internet-Draft, Jul. 12, 2021, pp. 1-14. [cited by applicant]