DISPOSITIVO E MÉTODO PARA AUTENTICAÇÃO DE HARDWARE E / OU SOFTWARE EMBARCADO
Patent Information
- Application Number
- BR102022001024
- Authority / Receiving Office
- BR · BR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-01-19
- Publication Date
- 2026-08-04
- Estimated Expiration
- 2042-01-19
Smart Images

Figure 00000048_0000 
Figure 00000048_0001 
Figure 00000049_0000
Abstract
Description
/ 42 Descriptive Report of Invention Patent: Device and Method for Authenticating Embedded Hardware and / or Software Field of Invention
[0001] The present invention is situated in the fields of Computer, Electronic and Electrical Engineering. More specifically, the invention relates to a device and a method for verifying the authenticity of hardware and its embedded software. The method of the invention comprises the steps of: a) obtaining an identified record of each unique hardware and software device; b) subsequently interrogating this same unique hardware and software device to compare the identified record obtained in the interrogation with the one previously recorded; and c) identifying corruption, tampering and / or eavesdropping of the embedded hardware / software assembly when the comparison of the records does not result in a match. The present invention is particularly useful for the authentication of embedded hardware and software, identification of eavesdropping and / or tampering of hardware and / or software, locally or remotely, once, periodically or continuously.The invention is useful, among other things, for ensuring the reliability of data and / or metrics of technical and / or economic relevance measured by an integrated set of hardware and software, including equipment or devices for measuring and documenting quantities of environmental interest, integrity authentication for certifying entities of environmental conservation projects, integrity authentication of electronic voting machines, and integrity authentication of payloads of satellites, space artifacts, and / or the software embedded in these artifacts or satellites. Background of the Invention
[0002] Document US2008005798A1, entitled “Hardware platform Petition 870220040995, dated 11 / 05 / 2022, page 6 / 57 / 42, regarding "authentication and multi-purpose validation," reveals methods and devices that allow the authentication of a hardware platform on a network. The authenticated hardware platform can validate the credentials of virtual machines running on the hardware platform. Authentication of the hardware platform on the network allows network access to the validated virtual machines. Network access for virtual machines is managed by the hardware platform, allowing for differentiated access based, for example, on the security posture of each virtual machine.The aforementioned method comprises the steps of: a) authenticating a device's hardware platform with a network authentication authority from a network of devices to produce a hardware platform network authentication, the network authentication being produced independently of the device's operating system, the hardware platform having multiple partitions running on the hardware platform; b) validating one or more partitions of the authenticated hardware platform; and c) controlling network access to one or more partitions with the authenticated hardware platform based, at least in part, on a result of the partition validation. This document has a purpose similar to that of the present invention, but does not apply to hardware with embedded software that must be moved between a supplier and its customers, and which may have one or more of its components tampered with during transport by third parties.
[0003] Document CN101394276A, entitled “Authentication system and method based on USB hardware token”, discloses an authentication system based on a USB hardware token. Said system comprises: an application system server, an application system terminal, an authentication server and an authentication device; wherein the authentication device is a hardware token having a USB interface, the hardware token has an indicator, a light and a confirmation button to prompt the user's application system terminal to request data exchange, the confirmation button is used for the user to confirm the data exchange between the Petition 870220040995, dated 11 / 05 / 2022, page 7 / 57 / 42 hardware token and the application system terminal; the application system server is used to execute the key on the user. The operation activates the indicator on the hardware token, prompting the user to press the confirmation button on the hardware token to cause the hardware token to execute the algorithm calculation and determine if the user's key operation is successful according to the authentication result finally returned by the authentication server; The application system terminal is configured to forward the result of the data generated by the hardware token by the algorithm to the application system server; the authentication server is configured to calculate the algorithm generated by the hardware token received from the application system server. The data results are authenticated and the certification results are returned to the application system where the Service is located.This invention is limited to authenticating a user in relation to their access to a set of hardware and software, but does not guarantee the authenticity of the set being accessed.
[0004] Document CN 103605919A, entitled “Method and device for generating software authentication files and method and device for authenticating software”, discloses a method and a device for generating software authentication files and a method and a device for authenticating software. The referred method for generating the software authentication files includes acquiring hardware information to be encrypted; performing RSA (Rivest-Shamir-Adleman) encryption on the hardware to be encrypted in order to generate initial encrypted authentication files; performing RC (Rivest Cifer) 4 encryption on the initial encrypted authentication files to generate the encrypted authentication files.The method and device for generating the software authentication files, and the method and device for authenticating the software, have the advantage that the hardware information to be encrypted is doubly encrypted by the method and device for generating the software authentication files, while the encrypted authentication files are doubly decrypted by the same method and device. Petition 870220040995, dated 11 / 05 / 2022, page 8 / 57 / 42 method and by the software authentication device and, consequently, security can be improved in the software authentication procedure.
[0005] Document CN104393997A, entitled “Software and hardware collaborative authentication method of the Kyropoulos Sapphire Technology Center”, discloses a method comprising the following steps: configuring a hardware identity feature authentication algorithm and a software key authentication algorithm on a remote network user client; after accessing the remote network user client on the network via hardware, reading a MAC address of the remote network user client by the software key authentication algorithm and acquiring an encryption key that belongs only to the MAC address of the technology center; communicating data with the encryption key between the remote network client and the technology center; connecting the hardware identity feature authentication algorithm to the technology center via the Internet and reading a hardware identity feature code that is installed internally in the hardware;Send the hardware identity characteristic code to the technology center; establish a task connection with the remote network user client after successfully completing authentication by the technology center. The method described in the aforementioned patent employs identifiers created for the hardware and the use of client MAC addresses.
[0006] Document CN1447269A, entitled “Certificate authentication system and method based on hardware characteristics”, discloses a certificate certification system and method based on hardware characteristics. The system includes: a certification server uses a hardware certificate encrypting a digital certificate containing the client's final hardware character to form the encrypted file sent to the end user who uses the hardware certificate to decrypt the encrypted file to obtain a digital certificate provided on an applied server providing the digital certificate to a certification server to verify the completion of the certification. The system includes a collector of the user's final hardware characters used in the generation Petition 870220040995, dated 11 / 05 / 2022, page 9 / 57 / 42, regarding hardware certification according to the collected hardware character, a certification server, an end client, and an applied server. It includes the following steps: • In the first step, the authentication server encrypts the digital certificate using a hardware certificate containing the client's hardware characteristics, then creates an encrypted file and sends the encrypted file to the client; • In the second step, the client decrypts the received encrypted file using a hardware certificate to obtain a digital certificate and provides the digital certificate to the application server; and • In the third step, the application server provides the digital certificate to the authentication server to verify the completion of the authentication.
[0007] Document CN 106462900A refers to a security token for certifying authentication, and a method for obtaining it. The said security token for certificate authentication comprises a security chip comprising: a key pair generation module to generate a pair of a private key and a public key for an authentication certificate; a digital signature module to generate a digital signature based on the authentication certificate; internal memory to store the authentication certificate, the private key, and the public key; a near-field communication (NFC) module to perform NFC with a wireless terminal; and a controller to control the key pair generation module, digital signature module, internal memory, and NFC module. The said document is based on the concept of a key pair (public, private) and a hardware device that allows for authenticity verification using NFC communication.
[0008] US patent 2020295938A1, entitled “System, method and computer program product for performing hardware-backed password-based authentication”, discloses a system, method and computer program product for performing hardware-backed password-based authentication. In operation, a system receives a request to access the software using. Petition 870220040995, dated 11 / 05 / 2022, page 10 / 57 / 42 password-based authentication. Furthermore, the system receives a password for password-based authentication. The system calculates a hash using the password and a hardware-based authenticator associated with the system hardware. Additionally, the system verifies that the hash computed using the password and the hardware-based authenticator is correct to access the software. The aforementioned method comprises the following steps: • to receive, through a system, a request to access the software using password-based authentication; • The system receives a password for password authentication; • The system will compute a hash using the password and a hardware-based authenticator associated with the system hardware; and • The system will verify whether the hash computed using the password and the hardware-based authenticator is correct for accessing the software.
[0009] The method described in the document aims to authenticate users using software and hardware, without authenticating the hardware and software combination itself.
[0010] Document US10749686B2, entitled “System and method for authenticating multiple separate objects using one signature via chain of trust”, discloses a method for authenticating two distinct objects using a single signature stored in one of the objects. Upon initialization of a hardware system, a valid hash value can be generated based, at least in part, on a root disk file, and a kernel can be modified to contain the valid hash value. In subsequent initializations of the hardware system, the valid hash value stored in the kernel can be compared to a value from a potential root disk file, and if the valid hash value and the root disk hash value match, the hardware system can proceed with the initialization process. The method described comprises the following steps: • Accessing a kernel; • determine a valid hash value associated with the aforementioned kernel; • Access a potential root disk; • determine a potential root disk hash value associated with the aforementioned Petition 870220040995, dated 11 / 05 / 2022, page 11 / 57 / 42 potential root disk, in which the aforementioned step of determining the value of the referred potential root disk is based, at least in part, on a hash table associated with the disk - potential root disk; • Compare the given valid hash value and the given potential root disk hash value; • authenticate said potential root disk, if said valid hash value and said potential root disk hash value are identical x; • reject the said potential root disk if the said valid hash value and the said potential root disk hash value are different; • determine the said valid hash value from a valid root disk, wherein the said step of determining the said valid hash value from the said valid root disk is based, at least in part, on a hash table associated with the said valid root disk; and • encoding a valid hash value within the said kernel.
[0011] The method described in the aforementioned document employs a hash system to verify the integrity of a boot disk through the kernel of its operating system and a root disk.
[0012] Document US2014365755A1, entitled “Firmware authentication in Information Handling Systems (IHSs),” discloses an IHS that may include a controller having memory, the memory configured to store a plurality of firmware volumes, each of the plurality of firmware volumes including a plurality of firmware files. The IHS may also include a Basic Input / Output System (BIOS) operatively coupled to the controller, the BIOS having program instructions stored therein that, upon execution, cause the BIOS to authenticate two or more firmware files within a given plurality of firmware volumes using a single digital signature. In another embodiment, a method may include creating a firmware volume, adding a plurality of firmware files to the firmware volume, and creating a digital signature based on at least one of the plurality of firmware files, where the digital signature, upon Petition 870220040995, dated 11 / 05 / 2022, p. 12 / 57 / 42, to be authenticated, allows a BIOS to load any of several firmware files. This method ensures the authentication of firmware stored on a given hardware.
[0013] Document US2020186523A1, entitled “System and Method for Device and Transaction Authentication”, discloses a system for using unique device and user identifiers to authenticate a user, device, and / or transaction. In particular, the system can use biometric device profiles and / or user identifiers to generate a unique identifiable signature for each user and / or device. The unique signature can then be used to authenticate devices as well as transactions sent by those devices. In this way, the system increases the security of device authentication, helping to prevent the use of device hijacking methods that exploit conventional authentication practices. The document allows authenticating the user by storing their biometric credentials, along with the profile of installed software and hardware response times, both on a blockchain.Over time, it is expected that a unique hardware signature will be obtained by combining its behavior and installed software with its serial number, type, and other manufacturing data.
[0014] Document CN108352989A, entitled “Electronic device and method for authenticating identification information thereof”, discloses an electronic device. The electronic device includes a communication interface; a memory configured to store the first identification information corresponding to an external electronic device and the second identification information corresponding to a communication processor (CP) of the external electronic device and a processor, wherein the processor is configured to generate authentication information based on at least the first identification information and the second identification information generate an electronic signature corresponding to the authentication information by encrypting at least part of the data. Petition 870220040995, dated 11 / 05 / 2022, page 13 / 57 / 42, relates to authentication information and transmits the electronic signature to the external electronic device using the communication interface. The document discloses the aim of registering the electromagnetic signature of the hardware device to be authenticated, as well as the hashes of the software installed on it. However, it is not capable of detecting variations in signature measurement between different signature measurement devices, which leads to false positives indicating a tampered device even with small variations. The present invention solves these problems.
[0015] Document US2014289835A1, entitled “Devices, Systems and Methods for Security Using Magnetic Field Based Identification”, discloses devices, systems, and methods for determining an electromagnetic signature to authenticate a device, a user, and / or a location. A magnetometer captures an electromagnetic signature that is then compared to one or more authorized electromagnetic signatures. If the electromagnetic signature matches an authorized electromagnetic signature, access is granted. The magnetometer is integrated into a communication device that has a processor and logic. The magnetometer captures an electromagnetic signature from a surrounding environment and detects the movement of the communication device through the captured electromagnetic signature. The logic in the communication device blocks or unblocks device features based on the captured electromagnetic signature.In other embodiments, the magnetometer communicates with a server that authenticates a user or communication device to provide access to a remote location. The approach described in the document uses a binary classification of the device's electromagnetic signature ("match" / "mismatch"), not allowing for natural measurement variations and potentially generating false positives. Furthermore, it employs magnetic signatures for locations, which are not immutable and therefore can also generate false positives. The present invention solves these problems.
[0016] Document US2014082720A1, entitled “Method and System for Petition 870220040995, dated 11 / 05 / 2022, page 14 / 57 / 42 "Authentication of Device Using Hardware DNA" reveals methods and systems for authenticating a device. The method includes transmitting energy to the device, including a material, monitoring the device's response to the transmitted energy, generating a device signature based on the device's response to the transmitted energy, comparing the device signature to a signature for the device, and indicating that device authentication was successful when the generated signature matches the registered signature.The system includes a transmitter configured to transmit energy towards the device, a receiver configured to monitor a response from the device, and a processor configured to generate a device signature based on the device's response, compare the device signature with a registered signature for the device, and indicate that device authentication is successful when the generated signature matches the registered signature. The approach in the document does not consider that it is possible to maintain the electrical signature while altering the device's input and / or output, using a device that alters the input, for example, artificially increasing the reading and causing the software to read false data. However, a second device that electrically has the opposite effect in the circuit is installed after the input and processing path, so that the electrical signature is maintained even when the input is altered.
[0017] Document US2013047209A1, entitled “Authentication Processing Method and Apparatus”, discloses a Physical Unclonable Function (PUF) device and a PUF reader that extracts the PUF parameters needed to compute a response output from a challenge input by analyzing an operation of the PUF device. The operating parameters that characterize an operating state are obtained by observing an energy waveform, an electromagnetic waveform, or a processing time of the PUF device at that moment. Authentication of the PUF device is based on the extracted parameters. The PUF reader performs authenticity determination as to whether the PUF device Petition 870220040995, dated 11 / 05 / 2022, page 15 / 57 / 42, determines whether or not a PUF device is valid for monitoring PUF device operation during response generation based on operating parameters. The invention also lacks the capability to detect changes that alter inputs and outputs symmetrically, as previously described.
[0018] The co-pending patent application BR 102019021409-0, entitled “Conservometer, Equipment and System for Signal Transduction in Conservation Credits and for Documenting Conservation or Recovery Metrics of Environmental Assets”, also from the present inventors, constitutes one of the embodiments in which the present invention is advantageously applied.
[0019] None of the methods described above provides a guarantee of authenticity for any hardware and software assembly without making any changes to the hardware or software. Furthermore, the invention described here is also useful when the assembly is moved from a supplier to a customer. None of the known methods are capable of detecting alterations to the hardware assembly made to its printed circuit boards, for example, adding electronic components such as resistors and capacitors that could tamper with inputs or outputs, or installing eavesdropping devices that do not interfere with the processing performed by the hardware but copy information from the target device.
[0020] Additionally, none of the methods listed above is capable of, in addition to storing the hash of the software embedded in the hardware, verifying the authenticity of the inputs and outputs of the embedded software, especially applications with specific purposes, inputs and outputs which may have been altered by added electronic components as described previously. Therefore, none of the listed methods can guarantee that an integrated set of hardware and software, used, for example, but not limited to, tasks of acquiring and measuring physical quantities, has maintained its authenticity after being moved between the sites of a supplier and a client, or even between any two sites without supervision. Petition 870220040995, dated 11 / 05 / 2022, page 16 / 57 / 42 or even during a period of unsupervised field operation. The present invention allows, in addition to basic hash and electromagnetic signature checks, the verification of the hardware and software response through the hardware outputs, thus indirectly detecting small circuits that could be used to tamper with inputs or outputs, thereby altering measured or calculated values, through these tests.
[0021] Based on the literature reviewed, no documents were found that anticipated or suggested the teachings of the present creation / secret / invention. The invention now revealed possesses, in the eyes of the inventors, novelty and inventive activity compared to the state of the art. Summary of the Invention
[0022] The present invention solves a recurring problem in the art relating to the security of digital systems composed of hardware and software, by providing assurance of the authenticity of these systems, that is, that the system being accessed is the one expected and not a corrupted or adulterated version thereof, or even another system that masquerades as the expected system.
[0023] The invention system provides authenticity verification for the hardware / software assembly or separately for the hardware or for the software, ensuring that one, the other, or both are genuine.
[0024] Embedded software is software intrinsically linked to the hardware in which it is encapsulated. Therefore, authenticating embedded systems means authenticating both the software and the hardware that make up such a system. Thus, a secure way to ensure full authentication of an integrated hardware and software system is to define an integrated authentication method for both hardware and software.
[0025] Methods such as those described in the prior art provide only partial authentication or else require that the hardware and / or software Petition 870220040995, dated 11 / 05 / 2022, page 17 / 57 / 42 to be authenticated be modified in order to guarantee authentication, which may lead to undesirable changes in the hardware and / or software design.
[0026] The present invention provides a device and method that guarantees the authenticity of the hardware and software assembly and also: i. It is integrated, providing assurance of the authenticity of both the hardware and its embedded software simultaneously; ii. identifies tampering with the system, whether in the outputs produced by the hardware and software system, or in the form of eavesdropping; iii. it does not require changes to the design or implementation of the hardware or software to be implemented and function correctly; iv. avoids false positives due to small variations, typical of different devices and / or measurement environments, in verifying the electromagnetic signature of the hardware; v. protects against situations in which small electronic components, such as but not limited to capacitors or resistors, may be integrated into the printed circuit board of the hardware in such a way as to tamper with the hardware's inputs or outputs, while maintaining its electromagnetic signature.
[0027] The present invention solves these problems and provides a method of authenticating hardware and its embedded software, identifying whether there has been any tampering with any embedded software and / or the hardware inputs and / or outputs, as well as identifying whether there is any wired or wireless device implanted on the hardware board used to improperly transmit data acquired and / or generated by the hardware and software assembly.
[0028] The inventive concept common to the objects of the invention is a method for authenticating hardware and its embedded software comprising the following steps: - Obtain an identified record of each unique hardware and software device; - subsequently interrogate this same single hardware device Petition 870220040995, dated 11 / 05 / 2022, page 18 / 57 / 42 and software, for comparison of the aforementioned identified record obtained in the interrogation with the one previously recorded; and - Identify corruption, tampering, and / or eavesdropping of the embedded hardware / software when record comparisons do not result in a match.
[0029] In one embodiment of the present invention, the aforementioned unique identifier for each embedded hardware and software is selected from: - one or more hashes; - the correspondence between the input value of one or more signals to an embedded hardware or software system and the output value of said signal(s) and / or the response time of the output signal(s); - an electromagnetic signature, and / or - combinations of these.
[0030] One of the objects of the invention is a method for authenticating hardware and its embedded software comprising the following steps: - Obtain an identified record of each unique hardware and software device, through a record, specific to each unique device, of: - one or more hashes; - the correspondence between the input value of one or more signals to an embedded hardware or software system and the output value of said signal(s) and / or the response time of the output signal(s); and / or - an electromagnetic signature; - to subsequently interrogate this same unique hardware and software device for evaluation: - the identity of the hash(s) with the one(s) previously stored; - the result of the matching test between the input value of one or more signals to a set of embedded hardware and software and the output value of said signal(s) and / or the response time of the output signal(s), with their respective previously stored values; and / or - the degree of similarity of the current electromagnetic signature with the Petition 870220040995, dated 11 / 05 / 2022, p. 19 / 57 / 42 previously stored electromagnetic signature of the device, - Identify corruption, tampering, and / or eavesdropping of the embedded hardware / software when: - if one or more hashes are different; - the signal test indicates a mismatch between the signals and / or their response time; and / or - when the electromagnetic signature falls outside the previously established similarity range.
[0031] Another object of the invention is to provide a method for authenticating the integrity of devices or equipment for measuring physical quantities of environmental interest.
[0032] Another object of the invention is to provide a method for authenticating the integrity of environmental conservation projects for certification bodies.
[0033] Another object of the invention is to provide a method for authenticating the integrity of electronic voting machines.
[0034] Another object of the invention is to provide a method for authenticating the integrity of satellite payloads, including micro or nanosatellites, spacecraft, sounding rocket payloads and / or the software embedded in these artifacts or satellites.
[0035] Another object of the invention is a device for authenticating embedded hardware and software comprising: - Physical input and output interfaces for connecting to the hardware and / or software to be authenticated; - a microprocessor configured for: - Send one or more signals to the embedded hardware and software to be authenticated in order to query it for a uniquely identified record for each embedded hardware and software component; - to receive the aforementioned signals back; - to verify the conformity between the unique record of the embedded hardware and software obtained from the interrogation and the identified unique record and Petition 870220040995, dated 11 / 05 / 2022, page 20 / 57 / 42 previously stored; and - To send a signal to a physical and / or digital medium to report compliance or non-compliance.
[0036] In one embodiment, a device is provided for the authentication of embedded hardware and software comprising: - Physical input and output interfaces for connecting to hardware containing embedded software, to be authenticated; and - a microprocessor configured for: - Send one or more signals to the hardware containing embedded software to be authenticated in order to interrogate it regarding: - to question him regarding one or more hash(s); - testing the signal by matching the input value of one or more signals from the embedded hardware / software assembly with the output value of said signal(s) and / or the response time of the output signal(s); and / or - to question him regarding the electromagnetic signature of the hardware and software system; - to receive the aforementioned signals back; - to verify the identity of the measured hashes with previously stored hashes; to compare the signal test result with corresponding previously stored values; and / or to compare the electromagnetic signature obtained from the interrogation with the previously stored electromagnetic signature, linked to the embedded hardware / software to be authenticated; and - To send a signal to a physical and / or digital medium to report compliance or non-compliance.
[0037] In one embodiment, an identified record of the hardware and software assembly consists of: a hash generated from the combination of the hardware device's serial number with the embedded software's binary code integrating the identity of both, photos of the hardware device, and date and time. Petition 870220040995, dated 11 / 05 / 2022, page 21 / 57 / 42 (in milliseconds) obtained at the moment of completion of the hardware assembly. A second hash can be generated by combining the hardware serial number, the embedded software binary code, and the date and time, the latter serving to check if the stored and subsequently read date and time matches the original.
[0038] In one embodiment, the identified record of each unique hardware and software device is stored remotely, in which case the comparison of the respective record (which may include: hashes; photos, date and time, the correspondences between the values of input and output signals and / or the respective response time; and / or the electromagnetic signature of the hardware device) with the record resulting from the interrogation is done remotely.
[0039] These and other objects of the invention will be immediately appreciated by those skilled in the art and by companies with interests in the segment, and will be described in sufficient detail for their reproduction, in the following description. Brief Description of the Figures
[0040] The following figures are presented:
[0041] Figure 1 schematically presents a configuration embodiment in which the present invention performs its function. In Figure 1, element numbered 1 is the Authenticating Device (ADD), element numbered 3 is the Authentication Verification Device (AVD), and elements numbered 2 are the Physical Input / Output Interfaces (PIIs) present in both the ADD and the AVD, which exchange authentication data between them. The ADD is iconically represented by a printed circuit board, although such a device is not limited to just one board and may be a more complex device composed of several boards. The AVD is iconically represented by a personal computer, which may be a personal computer, a microcontroller, or any computer element, provided it has the necessary PIIs for communication with the ADD. The interfaces are iconically represented by lines, and should be Petition 870220040995, dated 11 / 05 / 2022, page 22 / 57 / 42 interpreted as insulated cables, manufactured and installed according to the technique for readings free from electromagnetic, temperature and humidity interference.
[0042] Figure 2 shows a schematic representation of the authentication method flow, which can have two results: SUCCESS, when all authentication conditions are met; or FAILURE when one or more authentication conditions are not met. Although the flow represented in Figure 2 shows FAILURE from the first unmet condition, the authentication test can proceed to identify if more than one condition is not being met, providing a complete audit of the Device Under Authentication.
[0043] Figure 3 shows a tolerance window with two points A and B in R2 space, describing the amplitude and frequency of signals read from some electromagnetic medium. The signals are considered "equal" because they are in the same window. The window is defined by a distance to the amplitude on the x-axis and a distance to the frequency on the y-axis. In the figure, A is the point representing an original reading and B is a point read subsequently and considered "equal" to A within the concept of the tolerance window.
[0044] Figure 4 schematically shows an embodiment of the present invention in which different sources of environmental conservation or recovery data are obtained and / or measured, with such data or signals processed in a conservation meter and the corresponding conservation metrics or credits communicated in different communication environments. As a hardware device with embedded software, the conservation meter is authenticated by the object of the present invention.
[0045] Figure 5 shows details of an embodiment of the invention in which a conservation meter communicates conservation metrics / credits as a metric of CO2 emission reduction by a hybrid vehicle (B1 or B2) equipped with a regenerative kinetic energy recovery system. In A) it is shown Petition 870220040995, dated 11 / 05 / 2022, page 23 / 57 / 42 schematically describes a data acquisition and communication device. In this embodiment, authentication is performed on device A) or on an integrated version thereof embedded in the vehicle's control unit.
[0046] Figure 6 schematically shows an embodiment of the present invention for the authentication of electronic voting machines, which are hardware devices with embedded software. The device of the invention is physically connected to a data input of the electronic voting machine, such as a USB port. The authentication process of the hardware and software assembly is carried out as described in this invention and then, if SUCCESS has been achieved, the USB port is physically sealed, ensuring that the input and output data relating to the electronic votes are as expected. Detailed Description of the Invention
[0047] In the present invention, the term “authentication” refers to verifying that a given object, whether hardware or software, is what it is expected to be and has not been replaced or had its content or composition corrupted in any way. The term “embedded software” refers to code in binary language written specifically to be encapsulated and dedicated to a particular hardware or device that it will control, through a set of predefined tasks that employ specific resources of that hardware.
[0048] In the present invention, the term "authentication" also includes identifying and reporting any corruption, tampering and / or eavesdropping of the embedded hardware / software assembly. In the present invention, eavesdropping is the act of improperly obtaining information read or generated by a hardware and software assembly through a wired or wireless device installed or connected to the target assembly by a third party who does not have the proper authorization to do so.
[0049] Authenticating digital systems composed of hardware and embedded software means authenticating these two elements in an integrated way. Thus, Petition 870220040995, dated 11 / 05 / 2022, page 24 / 57 / 42 a secure way to ensure full authentication of a system composed of hardware and software is by defining an integrated method of hardware and software authentication.
[0050] The present invention is also defined by the following clauses.
[0051] Hardware and embedded software authentication method comprising the following steps: - Obtain an identified record of each unique hardware and software device; - subsequently interrogate this same unique hardware and software device, for comparison of the identified record obtained during the interrogation with the one previously recorded; and - Identify corruption, tampering, and / or eavesdropping of the embedded hardware / software when record comparisons do not result in a match.
[0052] Method as described above in which the aforementioned unique identified record of each embedded hardware and software is selected from: - one or more hashes; - the correspondence between the input value of one or more signals to an embedded hardware or software system and the output value of said signal(s) and / or the response time of the output signal(s); - an electromagnetic signature, and / or combinations thereof.
[0053] Method as described above comprising the following steps: - Obtain an identified record of each unique hardware and software device, through a record, specific to each unique device, of: - one or more hashes; - the correspondence between the input value of one or more signals to an embedded hardware or software system and the output value of said signal(s) and / or the response time of the output signal(s); and / or - an electromagnetic signature; - to subsequently interrogate this same unique hardware and software device for evaluation: Petition 870220040995, dated 11 / 05 / 2022, page 25 / 57 / 42 - the identity of the hash(s) with those previously stored; - the result of the correspondence test between the input value of one or more signals to an embedded hardware / software set and the output value(s) of said signal(s) and / or the response time of the output signal(s), with their respective previously stored values; and / or - the degree of similarity of the electromagnetic signature with the previously stored electromagnetic signature, - Identify corruption, tampering, and / or eavesdropping of the embedded hardware / software when: - if one or more hashes are different; - the signal test indicates a mismatch between the signals and / or their response time; and / or - when the electromagnetic signature is outside the previously established similarity range.
[0054] In one embodiment, the steps of the method described above are implemented by at least one microprocessor, which is capable of operating by means of instructions previously stored or provided by a remote system.
[0055] Method as described above in which the identified record of each unique hardware and software device is stored remotely, with the comparison step being the respective record with the record resulting from the query performed remotely.
[0056] Method for verifying the integrity of hardware and software of equipment or devices for measuring and documenting quantities of environmental interest comprising the steps of the first clause described above.
[0057] Method for verification, by certification bodies, of the integrity of hardware and software of environmental conservation projects comprising the steps of the first clause described above.
[0058] Method for verifying the integrity of hardware and software of Petition 870220040995, dated 11 / 05 / 2022, page 26 / 57 / 42 electronic ballot boxes comprising the steps of the first clause described above.
[0059] Method for verifying the hardware and software integrity of Space Artifact payloads comprising the steps of the first clause described above.
[0060] Device for authentication of embedded hardware and software comprising: - Physical input and output interfaces for connecting to hardware containing embedded software, to be authenticated; and - a microprocessor configured for: - Send one or more signals to the hardware containing embedded software to be authenticated in order to query it for a uniquely identified record for each piece of hardware and embedded software; - to receive the aforementioned signals back; - to verify the conformity between the unique record of the embedded hardware and software obtained from the interrogation and the previously identified and stored unique record; and - To send a signal to a physical and / or digital medium to report compliance or non-compliance.
[0061] Device as described above comprising: - Physical input and output interfaces for connecting to hardware containing embedded software, to be authenticated; and - a microprocessor configured to send one or more signals to the hardware containing embedded software to be authenticated, in order to interrogate it about: - to question him regarding one or more hash(s); - testing the signal by matching the input value of one or more signals from the embedded hardware and software to the output value of said signal(s) and / or the response time of the output signal(s); and / or - to question him regarding the electromagnetic signature of the hardware assembly Petition 870220040995, dated 11 / 05 / 2022, page 27 / 57 / 42 and software; - to receive the aforementioned signals back; - verify the identity of the measured hashes with the identity of previously stored hashes; compare the signal test result with corresponding previously stored values; and / or compare the electromagnetic signature obtained from the interrogation with the previously stored electromagnetic signature linked to the embedded hardware / software to be authenticated; and - To send a signal to a physical and / or digital medium to report compliance or non-compliance.
[0062] Device as described above wherein the said hash(s) comprise(s): the serial number of the hardware device and the binary code of the embedded software.
[0063] Device as described above further comprising a remote communication interface to provide comparison of the identified record of the unique hardware and software device stored remotely with the respective record originating from the interrogation made locally.
[0064] In one embodiment, the present invention starts from a configuration as represented in Figure 1 for its correct operation. In Figure 1, element numbered 1 is the Device Under Authentication (DSA), element numbered 3 is the Authentication Verification Device (DVA), and elements numbered 2 are the Physical Input / Output Interfaces (IFES), present in both the DSA and the DVA, which perform the authentication data exchanges between them.
[0065] In the present invention, the Device Under Authentication (DSA) is the hardware device combined with embedded software whose authenticity is to be verified.
[0066] In the present invention, IFES are input, output, or input and output interfaces that connect the Device Under Authentication to other devices, and are also used to authenticate it. Petition 870220040995, dated 11 / 05 / 2022, page 28 / 57 / 42
[0067] IFES can be connected by physical means, such as wires or cables, such as, but not limited to, Serial, Parallel, USB, RJ45 and / or other ports, as well as by electromagnetic means, such as, but not limited to, antennas for Bluetooth, Wifi, Lora, UHF, VHF, GSM and other means of transmitting signals by electromagnetic waves.
[0068] When connected by physical means, cables must be used that guarantee the quality of the electrical signals that travel through them, avoiding interference created by electromagnetic signals external to the cables, humidity and temperature, ensuring technical test conditions.
[0069] When connected via electromagnetic means (wireless), appropriate communication devices and protocols must be used, and there must be assurance that there is no electromagnetic interference in the test environment, as well as guaranteed technical test conditions.
[0070] In the present invention, the Authenticity Verification Device (AVD) is a computer element, which may be, for example, but not limited to, a personal computer or a microcontroller, used to inject data into the DSA and verify, through a test application, the authenticity of the DSA.
[0071] In one implementation, it is a condition for the method described here to function that both DSA and DVA have the appropriate IFES to perform the authenticity tests.
[0072] In the present invention, “basic software” is considered to be a type of program essential for the operation of a computer element, such as, but not limited to, the operating system, as well as the set of device drivers, which may or may not be contained within an operating system. Basic software is therefore software embedded in the DSA that enables the operation of its basic functions, hence the name, such as reading physical interfaces, sending data, managing primary memory, and other functions.
[0073] A DSA may have one or more basic embedded software programs.
[0074] In the present invention, “target application” is software embedded in the DSA. Petition 870220040995, dated 11 / 05 / 2022, page 29 / 57 / 42, which allows it to have some function beyond the basic ones, performing computations with a specific purpose and intrinsically linked to the hardware on which it is executed.
[0075] A DSA can have one or more embedded target applications.
[0076] Hash record(s)
[0077] In the present invention, a “hash value” or simply “hash” is the transformation of a large amount of data into a small amount of information. A hash is a sequence of bits generated by a hashing algorithm, generally represented in hexadecimal, which allows visualization in letters and numbers (0 to 9 and A to F). This sequence seeks to uniquely identify a file or information.
[0078] Hash values are generated by hash functions, which are algorithms that map variable-length data to fixed-length data. In the present invention, any demonstrably secure hash function can be used to generate hash values, such as, but not limited to, the 128-bit Whirlpool hash function.
[0079] In the present invention, hash values, or simply hashes, are used to uniquely identify files in binary or text format that make up the basic software and target applications, as well as the test application, in order to create unique, or private, keys that uniquely identify the software that is embedded in a given DSA and installed or embedded in the DVA.
[0080] In the present invention, a “remotely accessible database” is a database that is on a medium accessible by multiple computer elements and, consequently, by multiple human or automated users, such as, but not limited to, network or cloud file servers, network or cloud database servers, or even distributed digital ledgers, such as those employing Blockchain technology. Other technologies that make data available remotely in a secure and organized manner may also be employed. Petition 870220040995, dated 11 / 05 / 2022, page 30 / 57 / 42
[0081] In one embodiment, the present invention starts from a setup as shown in Figure 1 for its correct operation. In Figure 1, numbered from 1 to 3, we have the Authentication Device (ADD), the Physical Input / Output Interfaces (PIIs), and the Authentication Verification Device (AVD).
[0082] Test application
[0083] In one embodiment of the present invention, the evaluation of the correspondence between the input value of one or more signals to an embedded hardware and software set and the output value of said signal(s) and / or the response time of the output signal(s) is performed by a “test application”. Said application is software that is installed or embedded in the DVA and its function is to inject inputs through one or more input interfaces of the DSA and read outputs through one or more output interfaces of the DSA. If the DVA is a personal computer, the test application is said to be installed in the DVA; if it is a microcontroller, the test application is said to be embedded in the DVA. The authentication process is independent of the type of DVA.
[0084] The Test Application implements a Functional Authentication Method (FAM) via computer program, described by a set of generic steps independent of the DSA and DVA, and which are based on the functionalities of the Target Application(s). In this implementation, the aforementioned test application is described according to the following steps: 1. Organize the set of input IFES for the DSA represented by E = {Ei, E2, ..., En} and the set of output IFES for the DSA represented by S = {Si, S2, ..., Sm}; 2. For each target application, do the following: I. Create the authentication test set A such that for each pair (Ei, j), where Ei and Ej are singular or multiple input values, there is an assertion represented by the tuple (Sk, l, t), where Sk and S, l is an expected output value, singular or multiple, and t is the expected time to obtain the output l in Sk. The test set A can be Petition 870220040995, dated 11 / 05 / 2022, p. 31 / 57 / 42 alternatively represented by a function that receives a value at a designated physical input and expects an output at a designated physical output, that is, f(Ei, j) ^ (Sk, l, t). (Sk, l, t) is said to be the assertion of (Ei, j). II. For every test {(Ei, j), (Sk, l, t)}, inject input data through the IFES, i.e., inject j through Ei, which must be processed by the Target Application and check the output data and execution time, i.e., whether the value l was read in Sk and whether the elapsed time was t or close to t. If the output data is l and the elapsed time is close to t, then the assertion (Sk, l, t) worked, and the next assertion should be checked until these are exhausted. If the output data is not l or if the elapsed time is much greater or much less than t, then the assertion (Sk, l, t) failed, generating FAILURE in authentication.
[0085] As an example of an authentication test case {(Ei, j), (Sk, l, t)}, we have the high-level description {(Serial0, 10), (Wifi, 5, 100)}, that is, an input value of 10 in Serial0 should generate an output value of 5 on the Wifi antenna, in about 100ms. If an output value is different from 5 or the response time is much greater or much less than 100ms, the assertion will have failed, indicating some corruption in the DSA composition.
[0086] The concept of “much longer” or “much shorter” response time must be embedded in the Test Application, and must be calibrated according to the types of hardware, underlying software, and Target Application(s) that make up the DSA. It is up to the programmer who develops the Test Application to technically evaluate the acceptable range for the variation in response time.
[0087] Test Suite A can be based on the test suite that is defined to test the functional and non-functional requirements of the Target Application(s). In fact, if there are automated tests that cover the requirements of the Target Application(s), these can be directly employed as a test suite for authentication, forming the Test Application. Petition 870220040995, dated 11 / 05 / 2022, page 32 / 57 / 42
[0088] In the present invention, the “supplier” is considered to be the organization or individual responsible for manufacturing or integrating the hardware and software that comprise the DSA.
[0089] In the present invention, the “user” is considered to be the organization or individual that employs the DSA and owns the DVA.
[0090] Electromagnetic signature
[0091] The “electromagnetic signature” of a device is the spectrum generated by its electromagnetic emissions, or collection of signals emitted periodically. Such a spectrum can be represented by a collection of pairs, peaks or points (x, y), where x is the amplitude and y the frequency of the electromagnetic signal.
[0092] In the present invention, two electromagnetic signatures are considered identical if all the peaks (x, y) that compose them are equal, and are similar if a percentage value of Similarity Limit between the peaks is reached. This Similarity Limit must consider the characteristics of the measurement process at the supplier and the user.
[0093] As an example of the Similarity Limit, if the Electromagnetic Signature of a device is characterized by 50 peaks (x, y), and when compared with another signature only 01 peak with a different x and / or y value is observed, then the similarity between the two signatures is said to be 98%. If the Similarity Limit is 95%, for example, the two signatures are then similar, since 98% is greater than 95%.
[0094] In the present invention, the concept of “equality” between peaks (x, y) of an electromagnetic signature can be defined through a two-dimensional window, called a “tolerance window,” used to define whether two peaks are “equal,” as shown in Figure 3. In this way, it is possible to deal with the inaccuracies inherent in the signal reading process, whether at the supplier's site or at the user's site, preventing similar signatures from being classified as dissimilar due to reading problems and not because the DSA was corrupted. Thus, the present invention also defines a method for determining similarity between two electromagnetic signatures. Petition 870220040995, dated 11 / 05 / 2022, page 33 / 57 / 42
[0095] Thus, the present invention defines “strict equality” as the usual, mathematical equality, and “equality by proximity” as defined using the amplitude and frequency tolerance window.
[0096] As described in Figure 3, starting from a point A, which is a peak of an electromagnetic signature obtained at the supplier's site, distances are defined on the x-axis (frequency) and the y-axis (amplitude), creating the tolerance window. All points that fall within this defined window during the reading of the electromagnetic signature made at the user's site will be considered "similar" or equivalent. For example, in Figure 3, point B is within the tolerance window of A and is therefore "similar" or equivalent to A, while point C is outside the tolerance window and is therefore not similar or equivalent to A.
[0097] Electromagnetic Signature Verification Method
[0098] The present invention defines an Electromagnetic Signature Verification Method (EMSVM), implemented by a computer program and described by the following steps: 1. Define the Similarity Limit; 2. If using equality by proximity: I. Define distance for amplitude; II. Define distance for frequency; 3. Obtain the reading of the Electromagnetic Signature performed on the supplier's website and store it as a vector; 4. Obtain the reading of the Electromagnetic Signature performed on the user's site and store it as a vector; 5. For each point of the Electromagnetic Signature obtained from the supplier's website: I. If strict equality is being employed: a. Verify if it is equal to the point in the same position in the Electromagnetic Signature vector obtained from the user's website; b. If different, increment the dissimilar peak counter; Petition 870220040995, dated 11 / 05 / 2022, pages 34 / 57 / 42 II. If equality by tolerance window is being used: a. Verify if the point of the same position in the Electromagnetic Signature vector obtained from the user's website is contained within the tolerance window; b. If different, increment the dissimilar peak counter; 6. Calculate the Percentage of Dissimilar Peaks by dividing the dissimilar peak counter by the size of the vector created to store the electromagnetic signature obtained from the provider's website; 7. If the percentage of different peaks is equal to zero, the signatures are identical; if it is less than the Similarity Limit, then the signatures are similar; if it is greater, the signatures are dissimilar.
[0099] Distances for Amplitude and for Frequency are MVAE parameters and can be defined in percentage or absolute terms.
[0100] The Test Method for Authentication (MTA), described in this invention, provides for the establishment of more stringent Similarity Limits when both the signature measurement conditions at the supplier and the user are technically ideal, or less stringent when these conditions are not.
[0101] The present invention discloses an Integrated Hardware and Embedded Software Authentication Method (MAIHSE), as described in Figure 2, considering a target hardware device to be authenticated, the DSA, a data injection device, the DVA, and describing the method as follows: i. On the supplier's website: 1. Install Basic Software on DSA. 2. Install Target Application(s) on the DSA. 3. Generate individual hashes for the DSA Basic Software, for the DSA target application(s), and for the DVA Test Application. 4. Determine the Electromagnetic Signature of the DSA when it is switched on and off, emitting signals from its wireless devices. Petition 870220040995, dated 11 / 05 / 2022, page 35 / 57 / 42 5. Determine the Electromagnetic Signature of each wireless device in the DSA. 6. Photograph the DSA with the focal axis perpendicular to the plane of the DSA's printed circuit board (PCB) and at a distance that allows for perfect framing, both from the front and back. 7. Assemble an identified record of the unique hardware and software device containing: hashes generated in (a.3), signature generated in (a.4), signature(s) generated in (a.5), front and back photos of the device obtained in (a.6), serial number of the hardware device, established Similarity Limit, and date and time in milliseconds obtained at the final moment of hardware assembly. The unique record identifier is a combination of the DSA serial number and the date and time. 8. Store the unique device's identified record in a remotely accessible database. 9. Send DSA to the user's website. ii. On the user's website: 1. Receive DSA sent in a.9. 2. Obtain the unique device-identified record from the remote database generated in a.7 and stored in a.8. 3. Verify device photos, generated in a.6: verify, by human (visual) or automated (computational) means, if the device is in the same state and with the same components as those present in the photographs. If not, return FAILURE. 4. Verify the hash of the Basic Software. If it is not identical to the one obtained from the identified record, return FAILURE. 5. Verify the hash(s) of the Target Application(s). If it / they are not identical to the one(s) obtained from the identified record, return FAILURE. 6. Verify the hash of the DVA Test Application. If it is not identical to the one obtained from the identified record, return FAILURE. Petition 870220040995, dated 11 / 05 / 2022, pages 36 / 57 / 42 7. Physically connect the DVA to the DSA, using the appropriate IFES, with the appropriate cables according to the technical specifications, or providing wireless connections when applicable. 8. Using the DVA Test Application, activate the Target Application(s) in the DSA. 9. Using the DVA Test Application, test the DSA according to the Test Method for Authentication (MTA).
[0102] A FAILURE in ii.3 means that visual inspection, manual or automated, has identified some tampering with the DSA hardware.
[0103] A FAILURE in ii.4 means that some tampering was identified in the DSA's basic software.
[0104] A FAILURE in ii.5 means that some tampering was identified in the DSA Target Application(s).
[0105] A FAILURE in ii.6 means that some tampering was identified in the DVA Test Application.
[0106] To determine SUCCESS OR FAILURE in step ii.9, the Test Method for Authentication (MTA) is followed.
[0107] The MTA is described as follows: i. Isolate the DSA and DVA in an environment where they are the only two possible devices emitting electromagnetic waves; ii. Turn on the DSA and measure its electromagnetic signature; 1. Use the Electromagnetic Signature Verification Method; 2. If the Electromagnetic Signature is identical or similar, proceed to the next step; if it is not identical or similar, return FAILURE. iii. Turn on the DVA and measure its electromagnetic signature; iv. Run the Test Application in the DVA: 1. If the Test Application runs all assertions successfully, verify the electromagnetic signature of the DSA. If the Test Application returns any failed assertion, return FAILURE. 2. If all electromagnetic signatures during testing are identical or Petition 870220040995, dated 11 / 05 / 2022, page 37 / 57 / 42, similar to expected, return SUCCESS, otherwise, return FAILURE due to signature corruption.
[0108] The most likely cause of the electromagnetic signature corruption identified in ii.1 is the existence of an unidentified hardware component upon visual inspection (comparison with front and back photographs), which is emitting electromagnetic signals, usually using an illegitimate data transmission channel to send data to an equally illegitimate receiver (eavesdropping).
[0109] The electromagnetic signature of the DVA is measured in iii in order to assess any interference of this on the electromagnetic signature of the DSA, considering that both are the only emitters in the environment in which the test is being carried out, as described in i.
[0110] The most likely cause of any assertion failure in iv.1, given that the embedded software has been previously verified via hash comparison, is the existence of an unidentified hardware component in the visual inspection (comparison with front and back photographs) that is causing variation in the outputs generated by one or more Target Application(s).
[0111] The most likely cause of the electromagnetic signature corruption identified in iv.2 is the existence of an unidentified hardware component, not detected in the visual inspection (verification of front and back photographs) nor in the assertion tests, that is emitting electromagnetic signals, usually using an illegitimate data transmission channel to send data to an equally illegitimate receiver (eavesdropping).
[0112] The application of the Integrated Hardware and Embedded Software Authentication Method (MAIHSE) to the conservometer (DSA) is as described in Figure 2, the method comprising the following steps: a) On the supplier's website for the conservation meter: 1. Install Basic Software on the Conservometer. 2. Install Target Application(s) in the Conservometer. 3. Generate individual hashes for the Basic Conservometer Software. Petition 870220040995, dated 11 / 05 / 2022, pages 38 / 57 / 42 for the target application(s) of the Conservometer and for the DVA Test Application. 4. Determine the Electromagnetic Signature of the Conservometer when switched on and off, using its wireless devices. 5. Determine the Electromagnetic Signature of each wireless device in the conservation meter. 6. Photograph the conservation meter with the focal axis perpendicular to the plane of the conservation meter's printed circuit board (PCB) and at a distance that allows for perfect framing, both from the front and the back. 7. Assemble an identified record of the conservometer containing: hashes generated in (a.3), signature generated in (a.4), signature(s) generated in (a.5), photos of the front and back of the device obtained in (a.6), serial number of the hardware device, established Similarity Limit and date-time in milliseconds obtained at the final moment of assembly. The unique record identifier is a combination of the serial number and the date-time. 8. Store the unique device's identified record in a remotely accessible database. 9. Send data from the conservator to the user's website. b) On the user's website: 1. Receive data from the conservator sent in a.9. 2. Obtain the unique device-identified record from the remote database generated in a.7 and stored in a.8. 3. Verify device photos, generated in a.6: verify, by human (visual) or automated (computational) means, if the device is in the same state and with the same components as those present in the photographs. If not, return FAILURE. 4. Verify the hash of the Basic Software. If it is not identical to the one obtained from the identified record, return FAILURE. 5. Verify the hash(s) of the target application(s). If it / they are not identical to the... Petition 870220040995, dated 11 / 05 / 2022, page 39 / 57 35 / 42 obtained from the identified record return FAILURE. 6. Verify the hash of the DVA Test Application. If it is not identical to the one obtained from the identified record, return FAILURE. 7. Physically connect the DVA to the conservation meter, using the appropriate IFES, with the appropriate cables according to the technical specifications, or providing wireless connections when applicable. 8. Using the DVA Test Application, activate the Target Application(s) in the DSA. 9. Using the DVA Test Application, test the conservometer according to the Test Method for Authentication (MTA).
[0113] Example 1 - Using MAIHSE to authenticate the Conservometer
[0114] In this embodiment, MAIHSE is used to authenticate a conservation meter as described in co-pending patent application BR 102019021409-0, incorporated herein by reference, the conservation meter being the DSA. The authentication of a conservation meter ensures that this device is correctly performing: the readings of input signals, the proper computations, and the writing of output signals. Thus, in one embodiment, the use of MAIHSE in a conservation meter ensures that there is no tampering, either increasing or decreasing, in the computation of environmental conservation metrics or Conservation Credits, as well as that no information is being improperly diverted to a third party through any illegitimate communication channel inserted by this or another third party.
[0115] Example 2 - Application in conjunction with the conservaometer
[0116] In this embodiment, a Target Application performs computations for the conservation meter device, obtaining from primary memory the physical quantities read from the environment and performing computation of environmental conservation metrics or Conservation Credits according to their origin.
[0117] Figure 4 schematically shows an embodiment of the present invention in which different sources of environmental conservation or recovery data are obtained and / or measured. Petition 870220040995, dated 11 / 05 / 2022, page 40 / 57 / 42 conservation or recovery of environmental assets, with such data or signals being processed in a conservation meter and the corresponding conservation metrics or credits communicated in different communication environments. As a hardware device with embedded software, the conservation meter is authenticated by the object of the present invention.
[0118] In this embodiment, the conservation meter is installed in a vehicle equipped with a hybrid energy / propulsion system using liquid fuel and an electric motor powered by regenerative energy. In this context, the source of Conservation Credit generation is the vehicle itself, and the objective metric is that resulting from the reduction in fuel consumption and consequent reduction in CO2 emissions. Figure 5 shows details of an embodiment in which a conservation meter communicates conservation metrics / credits as a metric of CO2 emission reduction by a hybrid vehicle (B1 a passenger car, or B2 a truck) equipped with a regenerative kinetic energy recovery system. In A), a data acquisition and communication device is shown schematically. In this embodiment, authentication is performed on device A) or on an integrated version thereof embedded in the vehicle's control unit.
[0119] In this embodiment, the conservation meter, that is, the system for measuring and computing environmental conservation metrics or conservation credits, is installed in the on-board computer or entertainment system of the hybrid vehicle, or through a device connected to a standard OBD (On Board Diagnostics) port of the vehicle.
[0120] The use of the present invention in conjunction with the conservation meter provides real-time measurement, processing, and communication of the environmental service provided by the vehicle in the form of reduced greenhouse gas emissions. The corresponding conservation credits can be used by the vehicle owner, or fleet owners, for: communication of social or environmental responsibility actions; use of said conservation credits in environmental compensation measures; an open market of Petition 870220040995, dated 11 / 05 / 2022, page 41 / 57 / 42 negotiation of credits; or combinations thereof.
[0121] Example 3 - Electronic Ballot Box Authentication
[0122] Figure 6 schematically shows an embodiment of the present invention for the authentication of electronic voting machines, which are hardware devices with embedded software. The device of the invention is physically connected to a data input of the electronic voting machine, such as a USB port. The authentication process of the hardware and software assembly is performed, and then the USB port is sealed.
[0123] The device of this embodiment of the invention comprises: - Physical input and output interfaces for connection to the electronic voting machine to be authenticated, integrated into a USB interface; - a microprocessor or other computer element configured to: - Send one or more signals to the electronic voting machine to be authenticated in order to interrogate it regarding a unique identified record of the machine; - to receive back the aforementioned signals obtained from the ballot box; - to verify the conformity between the unique ballot box record obtained from the interrogation and the previously identified and stored unique record; and - to send a signal to a physical and / or digital medium to report conformity or non-conformity.
[0124] In an alternative embodiment, the authentication device comprises a remote communication interface to provide comparison of the remotely stored identified ballot box record with the corresponding record resulting from the locally performed interrogation.
[0125] Example 4 - Authentication of Satellite Payloads and other Space Artifacts
[0126] In one embodiment, the invention can be used to authenticate satellite payloads, including micro or nanosatellites, or other space artifacts, such as, but not limited to, space experiments and sounding rocket payloads and / or the basic software that commands and controls these artifacts or satellites. It will Petition 870220040995, dated 11 / 05 / 2022, page 42 / 57 / 42 employed to follow the term “artifact” to represent the listed categories and their similar / equivalent counterparts.
[0127] Due to the complexity of manufacturing, assembly, configuration, and launch operations for space artifacts, it is common for an artifact to be prepared at one site, stored, and then transported to the launch site and stored again awaiting launch.
[0128] Because batteries can discharge, causing loss of configuration, and sensors can become miscalibrated during these waiting periods in storage until launch, tests are carried out before launch to verify the basic state of the spacecraft's hardware and software. These tests, however, do not assess the integrity of the spacecraft regarding the possibility of its hardware and / or software having been tampered with by third parties during transport or storage.
[0129] The situation of improper tampering with space artifacts is a typical concern for countries that do not have their own launchers, due to the possibilities of industrial espionage or even sabotage of the artifacts.
[0130] In this embodiment of the invention, the Target Applications in the case of space artifacts are the software that controls their payloads and have already been installed during the assembly and configuration activities of the artifact.
[0131] In one embodiment, the parameters of the Electromagnetic Signature Test are more stringent when the artifact is tested in an Anechoic Chamber, a facility found in space artifact assemblers.
[0132] In one embodiment, the application of the Integrated Hardware and Embedded Software Authentication Method (MAIHSE) to a space artifact (DSA) comprises the following steps: a) On the site of the artifact owner or of the assembly and / or configuration: 1. Generate individual hashes for the artifact's Basic Software, for the target Application(s), and for the DVA Test Application. Petition 870220040995, dated 11 / 05 / 2022, page 43 / 57 / 42 2. Determine the Electromagnetic Signature of the device when it is switched on and off, using its wireless devices. 3. Determine the Electromagnetic Signature of each wireless device in the artifact. 4. Photograph the artifact from each of its sides, which may be top, bottom, port side, starboard side, front, and back, at a distance and angle that allows for perfect framing. 5. Assemble an identified record of the device containing: hashes generated in (a.1), signature generated in (a.2), signature(s) generated in (a.3), photos obtained in (a.4), serial number or flight identifier of the artifact, established Similarity Limit, and date and time in milliseconds obtained at the final moment of assembly. The unique record identifier is a combination of the serial number or flight identifier and the date and time. 6. Store the unique device's identified record in a remotely accessible database. 7. Send artifact data to the user's site. b) At the launch site, immediately before its installation on the launch vehicle: 8. Receive artifact data sent in a.7. 9. Obtain an identified record of the unique remote database artifact generated in a.5 and stored in a.6. 10. Verify photos of the artifact, generated in a.4: verify, by human (visual) or automated (computational) means, if the artifact is in the same state and with the same components as those present in the photographs. If not, return FAILURE. 11. Verify the hash of the Basic Software. If it is not identical to the one obtained from the identified record, return FAILURE. 12. Verify the hash(s) of the Target Application(s). If it / they are not identical to the one(s) obtained from the identified record, return FAILURE. Petition 870220040995, dated 11 / 05 / 2022, page 44 / 57 / 42 13. Verify the hash of the DVA Test Application. If it is not identical to the one obtained from the identified record, return FAILURE. 14. Physically connect the DVA to the device, using the appropriate IFES, with the appropriate cables according to the technical specifications, or providing wireless connections when applicable. 15. Using the DVA Test Application, activate the Target Application(s) in the DSA. 16. Using the DVA Test Application, test the artifact according to the Test Method for Authentication (MTA). c) If it is possible to access the device once it is installed on the launch vehicle, at the last moment before this vehicle becomes inaccessible, repeat steps 8, 9, 11, 12, 13, 14, 15, and 16. Step 10 is usually compromised due to the installation; electromagnetic signature verification activities are also compromised due to the presence of other artifacts, as well as the electromagnetic noise of the launcher itself, and are therefore not performed.
[0133] Example 5 - Dual Authentication of Hardware and Software Embedded by an External Certification Authority
[0134] In another embodiment, the method described here can be employed in parallel by an External Certification Authority (ECA). This ECA acts as an “honest broker” in a device authentication process. An honest broker is an entity that is accepted by all parties involved in a given transaction as being impartial and trustworthy to those parties.
[0135] In this embodiment, the supplier of a device to be authenticated provides it to a third party as a form of, for example, but not limited to, a physical quantity measurement system. The installation of the device is carried out by the third party and an ECE, acting as an honest broker, certifies that the installation was appropriate and the device has not been tampered with, thus ensuring that both the device supplier and the device user will have to expect from Petition 870220040995, dated 11 / 05 / 2022, page 45 / 57 / 42 measurements.
[0136] In one embodiment, the supplier installs a Conservometer for a user who wishes to measure environmental recovery and / or conservation metrics. The invention's system verifies the installation of the Conservometer through the ECE, which then ensures that both the supplier, through the Conservometer, and the user, through the installation of the Conservometer in an environmental asset conservation or recovery system, are delivering what is expected, in terms of the measuring device and the system to be measured. In this embodiment, MAIHSE is employed by both the supplier and the ECE, a situation in which the hardware / software authentication is dual – which provides increased confidence for the parties involved in the operation in which the target device is employed.
[0137] The technical dimension, which also includes a number of confidential details, includes the deployment of proprietary systems and / or technologies for which patent applications have not yet been disclosed.
[0138] By filing this application with the competent / guarantor body, the applicant seeks and intends to: (i) name the authors / inventors in respect of their respective moral, copyright and patrimonial rights related to their works; (ii) unequivocally indicate that they possess the trade or industrial secret and hold any form of intellectual property derived therefrom and desired by the applicant; (iii) describe in detail the content of the creations and the secret, proving their existence in physical and legal terms; (iv) obtain protection for their intellectual creations, as provided for in the Copyright Law; (v) establish the relationship between the examples / implements and the creative, ornamental, distinctive or inventive concept according to the applicant's understanding and context, to clearly demonstrate the scope of their protected and / or protectable intangible asset;(vi) to request and obtain the additional rights provided for in patents, if the applicant chooses to proceed with the administrative procedure to the end.;
[0139] Any future disclosure or publication of this document not Petition 870220040995, dated 11 / 05 / 2022, pp. 46 / 57 / 42, constitutes, in itself, authorization for commercial use by third parties. Even if the content becomes part of the physical world accessible to third parties, the disclosure / publication of this document under the terms of the law does not eliminate its legal status as a secret, serving only and solely the spirit of the Law to: (i) serve as proof that the creator created the objects described herein and expressed them in physical form, which is this report itself; (ii) unequivocally indicate its possessor / owner and authors / inventor(s); (iii) inform third parties of the existence of the creations and the aforementioned industrial secret, of the content for which intellectual property protection is requested or will be requested under the terms of the Law, including patent protection, and of the date of its filing, from which it will have priority rights and the term of validity of the patent exclusivity may begin, if applicable;and (iv) assist in the technological and economic development of the Country, from the disclosure of the creation, if this occurs, and the authorization of the use of the secret solely and exceptionally for the purposes of studies and / or development of new improvements, thereby avoiding parallel reinvestment by third parties in the development of the same asset.
[0140] It is hereby warned that any commercial use requires authorization from the authors or the owner / holder and that unauthorized use will result in sanctions as provided by law. In this context, given the extensive detail with which the creation, concept and examples have been revealed by the applicant, those skilled in the art may, without much effort, consider other ways of realizing the present creation and / or invention in ways not identical to those merely exemplified above. However, such ways are or may be considered as within the scope of one or more of the appended claims. Petition 870220040995, dated 11 / 05 / 2022, pp. 47 / 57
Claims
1 / 5 Claims 1. A method for authenticating hardware and its embedded software, characterized by comprising the following steps: a) obtaining an identified record from each unique hardware and software device, the selected record from the group consisting of: at least one hash with a correspondence between an input value of at least one signal for a set of embedded hardware and software and an output value of said at least one signal and / or a response time of said at least one output signal, an electromagnetic signature, and combinations thereof; b) subsequently interrogating this same unique hardware and software device, for comparison of said identified record obtained in the interrogation with that previously recorded; c) identifying corruption,adulteration and / or invasion / eavesdropping of the embedded hardware / software when the comparison of records does not result in a match; d) perform a parameterized electromagnetic signature verification (MVAE) comprising the steps of: i) defining a Similarity Threshold, ii) determining when to use proximity matching by at least one of the following options: defining distance for amplitude and defining distance for frequency, iii) obtaining the Electromagnetic Signature reading performed at a supplier's site and storing an Electromagnetic Signature reading performed at a supplier's site in a vector, iv) obtaining the Electromagnetic Signature reading performed at a user's site and storing the Electromagnetic Signature reading performed at a user's site in a vector, Petition 870260009430, dated 01 / 30 / 2026, page 40 / 55 2 / 5v) For each point of the Electromagnetic Signature obtained from the supplier's site: determine when strict equality is being used, verifying if each point of the Electromagnetic Signature obtained from the supplier's site is equal to a point at the same position in a vector of the Electromagnetic Signature obtained from the user's site and, if different, increment a dissimilar peak counter; and determine when equality by tolerance window is being used, verifying if the point at the same position in the vector of the Electromagnetic Signature obtained from the user's site is contained within the tolerance window and, if different, increment the dissimilar peak counter; vi) calculate the Percentage of Dissimilar Peaks by dividing the dissimilar peak counter by the size of the vector created to store the Electromagnetic Signature obtained from the supplier's site; and vii) if the percentage of different peaks is equal to zero,The signatures are identical; if less than the Similarity Threshold, then the signatures are similar; if greater, the signatures are dissimilar.
2. Method according to claim 1 characterized by comprising the following steps: e) obtaining an identified record of each unique hardware and software device, through the recording, specific to each unique device, of at least one of: - at least one hash; - the correspondence between the input value of at least one signal to the embedded hardware and software set and the output value of said at least one signal and / or the response time of the at least one output signal; and / or Petition 870260009430, dated 01 / 30 / 2026, page 41 / 55 3 / 5 - an electromagnetic signature; f) subsequently interrogating this same unique hardware and software device, for the evaluation of at least one of: - an identity of at least one hash with another at least one hash previously stored;- a result of the correspondence test between the input value of at least one signal to the embedded hardware / software set and the output value of said at least one signal and / or the response time of at least one output signal, with the respective values previously stored; and - compare the degree of similarity of the electromagnetic signature with the previously stored electromagnetic signature; g) identify corruption, adulteration and / or intrusion / eavesdropping of the embedded hardware / software set when at least one of the following occurs: - at least one hash is different from another at least one hash; - the signal test indicates a non-match between at least one signal and / or the response time of at least one signal; and - when the electromagnetic signature is outside the previously established similarity range.
3. Method according to claim 1 characterized in that the identified record of each unique hardware and software device is stored remotely, with the comparison step of the respective record with the record resulting from the interrogation being performed remotely.
4. Method according to claim 1 characterized by being used for verifying the integrity of hardware and software of equipment or devices for measuring and documenting quantities of environmental interest.
5. Method according to claim 1 characterized by being used for verifying the integrity of hardware and software of environmental conservation projects by certifying entities. Petition 870260009430, dated 01 / 30 / 2026, page 42 / 55 4 / 5 6. Method according to claim 1 characterized by being used for verifying the integrity of hardware and software of electronic voting machines.
7. Method according to claim 1 characterized by being used for verifying the hardware and software integrity of Space Artifact payloads.
8. Device for authenticating embedded hardware and software characterized by comprising: - physical input and output interfaces for connection to the hardware containing embedded software to be authenticated; - a microprocessor configured to: a) send one or more signals to the hardware containing embedded software to be authenticated to query it regarding a unique identified record of each embedded hardware and software; b) receive back said signals; c) verify the conformity between the unique record of the embedded hardware and software obtained from the query and the previously identified and stored unique record; d) send a signal to a physical and / or digital medium to report conformity or non-conformity; ee) perform a parameterized verification of the electromagnetic signature (MVAE) comprising the steps of: i) defining a Similarity Limit,ii) determine when to use proximity equality by at least one of the following options: define distance for amplitude and define distance for frequency, iii) obtain the Electromagnetic Signature reading performed on the site of Petition 870260009430, dated 01 / 30 / 2026, page 43 / 55 5 / 5 from a supplier and store an Electromagnetic Signature reading performed on a supplier's site in a vector, iv) obtain the Electromagnetic Signature reading performed on a user's site and store the Electromagnetic Signature reading performed on a user's site in a vector, v) for each point of the electromagnetic signature obtained on the supplier's site: determine when strict equality is being used, verifying if each point of the Electromagnetic Signature obtained on the supplier's site is equal to a point in the same position in a vector of the Electromagnetic Signature obtained on the user's site and, if different,increment a counter of dissimilar peaks; and determine when equality by tolerance window is being used, checking if the point of the same position in the Electromagnetic Signature vector obtained from the user's site is contained within the tolerance window and, if different, increment the dissimilar peak counter; vi) calculate the Percentage of Dissimilar Peaks by dividing the dissimilar peak counter by the size of the vector created to store the Electromagnetic Signature obtained from the supplier's site; and vii) if the percentage of different peaks is equal to zero, the Signatures are equal; if less than the Similarity Limit, then the Signatures are similar; if greater, the signatures are dissimilar. Petition 870260009430, dated 01 / 30 / 2026, pp. 44 / 55,