Chargeable-Device-Identity: A Privacy-Preserving Device Correlation Framework for RADIUS-Based Network Access Control
The widespread adoption of MAC address randomization by modern operating systems has introduced a fundamental tension between user privacy and enterprise network access control (NAC). This paper presents the Chargeable-Device-Identity (CDI) framework, a privacy-preserving device correlation mechanism that resolves this tension using HMAC-SHA-256 keyed with a server-held secret to generate rotating, opaque device correlators transported within existing RADIUS Class attributes. CDI provides six formally analyzed privacy properties: time-bounded correlation, elimination of static identifiers, server-only reversibility, cross-domain unlinkability, epoch-bound replay resistance, and complementarity with MAC randomization. The framework requires no modifications to deployed network access devices and has been specified in an IETF Internet-Draft for standardization.
Authors
- Premanand Seralathan
Institutions
- Cisco Systems (United States) (US)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-17
- DOI
- https://doi.org/10.5281/zenodo.22818695
- Primary Topic
- Internet Traffic Analysis and Secure E-voting
- Type
- preprint