Chargeable-Device-Identity: A Privacy-Preserving Device Correlation Framework for RADIUS-Based Network Access Control

The widespread adoption of MAC address randomization by modern operating systems has introduced a fundamental tension between user privacy and enterprise network access control (NAC). This paper presents the Chargeable-Device-Identity (CDI) framework, a privacy-preserving device correlation mechanism that resolves this tension using HMAC-SHA-256 keyed with a server-held secret to generate rotating, opaque device correlators transported within existing RADIUS Class attributes. CDI provides six formally analyzed privacy properties: time-bounded correlation, elimination of static identifiers, server-only reversibility, cross-domain unlinkability, epoch-bound replay resistance, and complementarity with MAC randomization. The framework requires no modifications to deployed network access devices and has been specified in an IETF Internet-Draft for standardization.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-17
DOI
https://doi.org/10.5281/zenodo.22818696
Primary Topic
Internet Traffic Analysis and Secure E-voting
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
preprint

Chargeable-Device-Identity: A Privacy-Preserving Device Correlation Framework for RADIUS-Based Network Access Control

Premanand Seralathan
Zenodo (CERN European Organization for Nuclear Research)
Internet Traffic Analysis and Secure E-voting
preprint

Chargeable-Device-Identity: A Privacy-Preserving Device Correlation Framework for RADIUS-Based Network Access Control

Premanand Seralathan
preprint en

Abstract

The widespread adoption of MAC address randomization by modern operating systems has introduced a fundamental tension between user privacy and enterprise network access control (NAC). This paper presents the Chargeable-Device-Identity (CDI) framework, a privacy-preserving device correlation mechanism that resolves this tension using HMAC-SHA-256 keyed with a server-held secret to generate rotating, opaque device correlators transported within existing RADIUS Class attributes. CDI provides six formally analyzed privacy properties: time-bounded correlation, elimination of static identifiers, server-only reversibility, cross-domain unlinkability, epoch-bound replay resistance, and complementarity with MAC randomization. The framework requires no modifications to deployed network access devices and has been specified in an IETF Internet-Draft for standardization.

Zenodo (CERN European Organization for Nuclear Research)
Cisco Systems (United States) (US)
Internet Traffic Analysis and Secure E-voting
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Chargeable-Device-Identity: A Privacy-Preserving Device Correlation Framework for RADIUS-Based Network Access Control — Premanand Seralathan · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS