Deterministic address rotation
Methods that support deterministic random media access control (MAC) address rotation that allows sharing of an address identity with a trusted wireless network infrastructure by generating a next address based on a previously used address and a seed obtained from a previous association with the trusted network infrastructure. In these methods, a computing device obtains a request for a secure connection of an endpoint device to a wireless network. The computing device performs an access authentication for the secure connection and establishes the secure connection of the endpoint device to the wireless network based on successfully performing the access authentication, in which cryptographic information for encrypting one or more network messages is generated. The computing device further generates a subsequent device address for a subsequent secure connection of the endpoint device to the wireless network, based on a current device address obtained from the request and the cryptographic information.
1 . A method comprising:
obtaining, by a computing device, a request for a secure connection of an endpoint device to a wireless network;
performing an access authentication for the secure connection of the endpoint device to the wireless network and establishing the secure connection of the endpoint device to the wireless network based on successfully performing the access authentication, in which cryptographic information for encrypting one or more network messages is generated;
generating a temporal key for encrypting the one or more network messages based on the cryptographic information;
generating, by the computing device, a subsequent device address for a subsequent secure connection of the endpoint device to the wireless network, based on a current device address obtained from the request and the temporal key;
storing the subsequent device address in association with the current device address of the endpoint device; and
upon determining that the current device address does not match one of a plurality of subsequent device addresses stored in association with the endpoint device providing the request, providing an authentication failure notification to the endpoint device.
2 . The method of claim 1 , further comprising:
establishing, by the computing device, the subsequent secure connection of the endpoint device to the wireless network;
obtaining, by the computing device, the one or more network messages; and
determining, by the computing device, whether the one or more network messages originated from the endpoint device by comparing a source address in the one or more network messages with the subsequent device address.
3 . The method of claim 1 , wherein generating the temporal key includes:
generating, by the computing device, a pairwise transient key (PTK) for encrypting the one or more network messages, based on the cryptographic information, wherein the subsequent device address is generated based on the PTK.
4 . The method of claim 3 , further comprising:
computing a hash value based on the PTK and the current device address, wherein the hash value is the subsequent device address.
5 . The method of claim 4 , further comprising:
determining whether the hash value is one of a plurality of device addresses for other endpoint devices; and
based on determining that the hash value is one of the plurality of device addresses:
notifying the endpoint device that the hash value is invalid to trigger the endpoint device to generate another hash value for the subsequent device address, and
computing, by the computing device, a new hash value for the subsequent device address of the endpoint device.
6 . The method of claim 1 , wherein performing the access authentication includes:
exchanging one or more Extensible Authentication Protocol (EAP) messages in which the cryptographic information is generated for the secure connection of the endpoint device to the wireless network.
7 . The method of claim 1 , wherein the request for the secure connection includes the current device address and a flag, and further comprising:
based on the flag being set, determining that the endpoint device had at least one previous secure connection to the wireless network, and
based on the flag not being set, determining that the endpoint device is new to the wireless network.
8 . The method of claim 7 , further comprising:
based on determining that the endpoint device had the at least one previous secure connection to the wireless network, obtaining the current device address from the request for the secure connection and comparing the current device address to a plurality of subsequent device addresses stored in association with a plurality of endpoint devices; and
establishing, by the computing device, the secure connection of the endpoint device to the wireless network based on determining that the current device address matches one of the plurality of subsequent device addresses.
9 . The method of claim 8 , further comprising:
based on the flag being set and the current device address not matching one of the plurality of subsequent device addresses, providing, to the endpoint device, an authentication failure notification such that the endpoint device resets the flag for a subsequent connection request.
10 . The method of claim 1 , wherein the current device address and the subsequent device address are stored in a connection profile for the endpoint device such that the subsequent device address for the subsequent secure connection of the endpoint device to the wireless network is known.
11 . The method of claim 1 , wherein the request for the secure connection includes the current device address and a flag, the method further comprising:
based on the flag being set, determining that the endpoint device had at least one previous secure connection to the wireless network, and
based on the flag being set and the current device address not matching one of a plurality of subsequent device addresses, providing, to the endpoint device, an authentication failure notification such that the endpoint device resets the flag for a subsequent connection request.
12 . The method of claim 1 , further comprising:
establishing the subsequent secure connection using the subsequent device address;
generating a new device address for the endpoint device for a next connection; and
adding the new device address to a connection profile for the endpoint device, wherein the new device address is stored in association with the subsequent device address.
13 . The method of claim 1 , further comprising:
upon determining that the current device address does not match one of the plurality of subsequent device addresses stored in association with the endpoint device providing the request, generating, by the computing device, a new subsequent device address for the subsequent secure connection of the endpoint device to the wireless network.
14 . An apparatus comprising:
a network interface to receive and send packets in a network; and
a processor, wherein the processor is configured to perform operations comprising:
obtaining a request for a secure connection of an endpoint device to a wireless network;
performing an access authentication for the secure connection of the endpoint device to the wireless network and establishing the secure connection of the endpoint device to the wireless network based on successfully performing the access authentication, in which cryptographic information for encrypting one or more network messages is generated;
generating a temporal key for encrypting the one or more network messages based on the cryptographic information; and generating a subsequent device address for a subsequent secure connection of the endpoint device to the wireless network, based on a current device address obtained from the request and the temporal key;
storing the subsequent device address in association with the current device address of the endpoint device; and
upon determining that the current device address does not match one of a plurality of subsequent device addresses stored in association with the endpoint device providing the request, providing an authentication failure notification to the endpoint device.
15 . The apparatus of claim 14 , wherein the processor is further configured to perform:
establishing the subsequent secure connection of the endpoint device to the wireless network;
obtaining the one or more network messages; and
determining whether the one or more network messages originated from the endpoint device by comparing a source address in the one or more network messages with the subsequent device address.
16 . The apparatus of claim 14 , wherein the processor is configured to generate the temporal key by:
generating a pairwise transient key (PTK) for encrypting the one or more network messages, based on the cryptographic information, wherein the subsequent device address is generated based on the PTK.
17 . The apparatus of claim 16 , wherein the processor is further configured to perform:
computing a hash value based on the PTK and the current device address, wherein the hash value is the subsequent device address.
18 . The apparatus of claim 17 , wherein the processor is further configured to perform:
determining whether the hash value is one of a plurality of device addresses for other endpoint devices; and
based on determining that the hash value is one of the plurality of device addresses:
notifying the endpoint device that the hash value is invalid to trigger the endpoint device to generate another hash value for the subsequent device address, and
computing a new hash value for the subsequent device address of the endpoint device.
19 . The apparatus of claim 14 , wherein the processor is configured to perform the access authentication by:
exchanging one or more Extensible Authentication Protocol (EAP) messages in which the cryptographic information is generated for the secure connection of the endpoint device to the wireless network.
20 . One or more non-transitory computer readable storage media encoded with software comprising computer executable instructions that, when executed by a processor, cause the processor to perform a method including:
obtaining a request for a secure connection of an endpoint device to a wireless network;
performing an access authentication for the secure connection of the endpoint device to the wireless network and establishing the secure connection of the endpoint device to the wireless network based on successfully performing the access authentication, in which cryptographic information for encrypting one or more network messages is generated;
generating a temporal key for encrypting the one or more network messages based on the cryptographic information;
generating a subsequent device address for a subsequent secure connection of the endpoint device to the wireless network, based on a current device address obtained from the request and the temporal key;
storing the subsequent device address in association with the current device address of the endpoint device; and
upon determining that the current device address does not match one of a plurality of subsequent device addresses stored in association with the endpoint device providing the request, providing an authentication failure notification to the endpoint device.
21 . The one or more non-transitory computer readable storage media according to claim 20 , wherein the computer executable instructions cause the processor to further perform:
establishing the subsequent secure connection of the endpoint device to the wireless network;
obtaining the one or more network messages; and
determining whether the one or more network messages originated from the endpoint device by comparing a source address in the one or more network messages with the subsequent device address.