Counterfeit detection using EMI fingerprinting

By generating and analyzing the fingerprints of electromagnetic interference (EMI) signals, pattern recognition technology is used to automatically identify genuine and counterfeit components in power systems, solving the problem of difficulty in identifying counterfeit components in power systems in existing technologies, and improving the accuracy and efficiency of identification.

CN114945830BActive Publication Date: 2025-10-28ORACLE INT CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202180008521.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-02-07
Filing Date
2021-01-15
Publication Date
2025-10-28
Estimated Expiration
2041-01-15

AI Technical Summary

Technical Problem

Existing technologies make it difficult to quickly and accurately identify genuine and counterfeit electronic components in power systems, leading to potential safety risks and substantial losses.

Method used

By collecting and analyzing electromagnetic interference (EMI) signals to generate EMI fingerprints, and using pattern recognition technology to compare the EMI fingerprints of target devices with a reference EMI fingerprint database, the brand, model and internal component configuration of the devices are automatically identified, and a similarity metric is generated to distinguish genuine products from suspected counterfeits.

Benefits of technology

It enables rapid, non-human-intervention-free counterfeit identification, reduces the human error rate, and improves the safety and reliability of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114945830B_ABST
    Figure CN114945830B_ABST
Patent Text Reader

Abstract

The following steps are performed to determine whether a target utility device, comprising multiple electronic components, is genuine or a suspected counterfeit: A test sequence is executed to power on and off the target device and electromagnetic interference (EMI) signals emitted by the target device are collected; a target EMI fingerprint is generated from the collected EMI signals; multiple reference EMI fingerprints are retrieved from a database, each reference EMI fingerprint corresponding to a different configuration of electronic components of a genuine device of the same brand and model as the target device; the target EMI fingerprint is iteratively compared with the retrieved reference EMI fingerprints, and a similarity metric is generated between each compared set; and the target device is indicated to be (i) a genuine device, wherein the similarity metric of any single reference EMI fingerprint satisfies a threshold test, and (ii) a suspected counterfeit device, wherein the similarity metric of any single reference EMI fingerprint does not satisfy the test.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] It is estimated that counterfeit electronic components in the international supply chain cause $200 billion in losses annually across all industries that use electronics, including information technology, medical, military, gaming, transportation, and utilities. Counterfeit systems often look so realistic that service engineers cannot distinguish them from genuine systems with a simple visual inspection. However, counterfeit systems often contain scrap components from obsolete systems, cheaply manufactured components, or old components from recycled vintage systems, which are repackaged to resemble genuine systems.

[0002] These systems are then integrated into the supply chain through brokerage channels. When counterfeit systems are shipped to customers, they often fail upon arrival or within a very short timeframe, resulting in significant warranty losses, shortened mean time between failures (MTBF), and customer dissatisfaction. In some cases, counterfeit systems even include spy chips that can grant unauthorized access or control over the system. In the utility sector, the use of counterfeit electronic components is not only costly but also a major security concern. Failures in utility components can lead to life-threatening situations such as power outages and fires.

[0003] The North American Electric Reliability Corporation (North American utility regulator) has issued Supply Chain Risk Management Regulation (No. CIP-013-1) to mitigate risks to the reliable operation of large-capacity power systems. This regulation requires all utilities in North America to implement technologies for detecting counterfeit components in all power system assets used in generation facilities, Supervisory and Data Acquisition (SCADA) subsystems, and distribution network assets by July 2020. Summary of the Invention

[0004] In one embodiment, a method for detecting whether a target utility device comprising multiple electronic components is genuine or a suspected counterfeit includes: performing a test sequence of powering on and off a target device of a specific model and collecting electromagnetic interference (EMI) signals emitted by the target device during power-on and power-off; generating a target EMI fingerprint from the EMI signals collected during power-on and power-off of the target device; retrieving multiple reference EMI fingerprints from a library of a database, wherein each reference EMI fingerprint corresponds to a different configuration of electronic components of a genuine device having the same specific model as the target device, and wherein each reference EMI fingerprint is generated from reference EMI signals collected during the power-on and power-off sequence performed on the corresponding configuration of the genuine device; iteratively comparing the target EMI fingerprint with individual reference EMI fingerprints among the multiple reference EMI fingerprints and generating a similarity metric between each set of compared target EMI fingerprints and individual reference EMI fingerprints; and generating a signal indicating that the target device (i) is a genuine device, wherein the similarity metric of any individual reference EMI fingerprint satisfies a threshold test, and (ii) is a suspected counterfeit device, wherein the similarity metric of any individual reference EMI fingerprint does not satisfy the threshold test.

[0005] In one embodiment, a method for detecting whether a target utility device comprising multiple electronic components is genuine or a suspected counterfeit includes collecting EMI signals emitted from the target device during power-on and power-off periods, comprising collecting a first set of EMI signals when the target device is powered on and a second set of EMI signals when the target device is powered off; and wherein a target EMI fingerprint is generated from a combination of the first set of EMI signals and the second set of EMI signals.

[0006] In one embodiment, a method for detecting whether a target utility device comprising multiple electronic components is genuine or a suspected counterfeit includes a test sequence of powering on and off the target device, wherein the test sequence of powering on and off the target device includes multiple power-on or power-off cycles.

[0007] In one embodiment, a method for detecting whether a target utility device comprising multiple electronic components is genuine or a suspected counterfeit further includes: receiving telemetry signals from sensor components of the target device; classifying the target device into a specific model based on the telemetry signals; wherein retrieving multiple reference EMI fingerprints from a database is based on the classification of the target device.

[0008] In one embodiment, a method for detecting whether a target utility device comprising multiple electronic components is genuine or a suspected counterfeit further includes generating a similarity metric by: generating, for each specific frequency in a reference EMI fingerprint, a residual between a reference amplitude-time series signal at that specific frequency in the reference EMI fingerprint and a multivariate state estimation technique (MSET) estimate of a target amplitude-time series signal at that specific frequency in the target EMI fingerprint; and combining the generated residuals to generate a similarity metric.

[0009] In one embodiment, a method for detecting whether a target utility device comprising multiple electronic components is genuine or a suspected counterfeit is provided, wherein the similarity measure is based on the mean absolute error at a set of specific frequencies between a reference EMI fingerprint and a target EMI fingerprint.

[0010] In one embodiment, a method for detecting whether a target utility device comprising multiple electronic components is genuine or a suspected counterfeit is provided, wherein the similarity measure is the surface mean absolute error.

[0011] In one embodiment, a method for detecting whether a target utility device comprising multiple electronic components is genuine or a suspected counterfeit further includes at least one of: (i) trimming a collected EMI signal to an optimal length for comparison with one or more reference EMI fingerprints, or (ii) synchronizing a first phase of the collected EMI signal with a second phase of one of the reference EMI fingerprints.

[0012] In one embodiment, a method for detecting whether a target utility device comprising multiple electronic components is genuine or a suspected counterfeit further includes: generating and displaying a visualization of a 3D residual surface on a graphical user interface based on one of reference EMI fingerprints and a target EMI fingerprint; (i) displaying a visual indication that the target device is genuine on the graphical user interface and displaying a description of the brand, model, and component configuration on the graphical user interface when a signal indicates that the target device is genuine; and (ii) displaying a visual indication that the target device is suspected or counterfeit on the graphical user interface when a signal indicates that the target device is a suspected counterfeit.

[0013] In one embodiment, a non-transitory computer-readable medium storing computer-executable instructions, which, when executed by at least a computer's processor, cause the computer to: collect electromagnetic interference (EMI) signals emitted by the target device while it is powered on and off in a repeatable test sequence using a software-defined radio device and antenna; generate a target EMI fingerprint from the EMI signals collected while the target device is powered on and off; retrieve a plurality of reference EMI fingerprints from a library of databases, wherein each reference EMI fingerprint corresponds to a different configuration of electronic components of a genuine device having the same specific model as the target device, and wherein each reference EMI fingerprint is generated from reference EMI signals collected while the genuine device is powered on and off in a repeatable test sequence; iteratively compare the target EMI fingerprint with individual reference EMI fingerprints among the plurality of reference EMI fingerprints, and generate a similarity metric between each set of compared target EMI fingerprints and individual reference EMI fingerprints; and generate and display on a graphical user interface a visual indication that the target device is: genuine, wherein the similarity metric of any individual reference EMI fingerprint satisfies a threshold test; and suspicious or counterfeit, wherein the similarity metric of any individual reference EMI fingerprint does not satisfy a threshold test.

[0014] In one embodiment, a non-transitory computer-readable medium, wherein collecting EMI signals emitted from a target device during power-on and power-off periods includes collecting a first set of EMI signals when the target device is powered on and a second set of EMI signals when the target device is powered off; and wherein a target EMI fingerprint is generated from a combination of the first set of EMI signals and the second set of EMI signals.

[0015] In one embodiment, a non-transitory computer-readable medium is used, wherein the test sequence of powering on and off the target device includes multiple power-on or power-off operations.

[0016] In one embodiment, the non-transitory computer-readable medium further includes instructions that, when executed by at least a processor, cause the computer to: receive telemetry signals from sensor components of the target device; classify the target device into a specific model based on the telemetry signals; wherein retrieving multiple reference EMI fingerprints from a library of a database is based on the classification of the target device.

[0017] In one embodiment, the non-transitory computer-readable medium further includes instructions that, when executed by at least a processor, cause the computer to perform at least one of the following operations: (i) trim the collected EMI signal to an optimal length for comparison with one or more of a reference EMI fingerprint, or (ii) synchronize a first phase of the collected EMI signal with a second phase of one of the reference EMI fingerprints.

[0018] In one embodiment, a system for detecting whether a target utility device of a specific model, comprising multiple electronic components, is genuine or a suspected counterfeit includes: a test sequence generator configured to automatically control a power supply to alternately power on and off the target device in a repeatable test sequence; and an EMI fingerprint counterfeit scanner configured to (i) collect electromagnetic interference (EMI) signals emitted by the target device while it is powered on and then off, (ii) generate a target EMI fingerprint from the EMI signals collected while the target device is powered on and off, and (iii) retrieve multiple reference EMI fingerprints from a data repository, wherein each reference EMI fingerprint is associated with a specific... The model corresponds to a genuine reference device and also to different configurations of electronic components for a specific model of genuine reference device. (iv) The target EMI fingerprint is iteratively compared with individual reference EMI fingerprints among a plurality of reference EMI fingerprints, and a similarity metric is generated between each set of compared target EMI fingerprints and individual reference EMI fingerprints. (v) A visual indication is generated and displayed on a graphical user interface that the target device is: genuine, wherein the similarity metric of any individual reference EMI fingerprint satisfies a threshold test; and suspected or counterfeit, wherein the similarity metric of any individual reference EMI fingerprint does not satisfy a threshold test. Attached Figure Description

[0019] Various systems, methods, and other embodiments of this disclosure are illustrated in conjunction with the accompanying drawings, which form a part of this specification. It will be appreciated that the element boundaries (e.g., boxes, groups of boxes, or other shapes) illustrated in the figures represent one embodiment of a boundary. In some embodiments, one element may be implemented as multiple elements, or multiple elements may be implemented as one element. In some embodiments, an element shown as an inner component of another element may be implemented as an outer component, and vice versa. Furthermore, elements may not be drawn to scale.

[0020] Figure 1 The illustration shows an embodiment of an EMI fingerprint counterfeit scanner and an example target utility device.

[0021] Figure 2 The illustration shows an embodiment of an environment in which an EMI fingerprint counterfeit scanner is operated.

[0022] Figure 3 The illustration shows an example of a method associated with utility asset allocation discovery and counterfeit detection.

[0023] Figure 4 An embodiment of a method associated with generating an EMI fingerprint from EMI signals collected during the energization and de-energization of utility equipment is illustrated.

[0024] Figure 5The illustration shows example utility equipment with different brands / models, which are pre-classified into similar brand and model categories using sensor telemetry signals.

[0025] Figure 6 An embodiment of a method associated with pre-classifying target utility equipment based on sensor telemetry readings is illustrated.

[0026] Figure 7 The diagram illustrates a reference waveform (“Gold System” or “GS”) and a target waveform (“Unit Under Test” or “UUT”) as an example of using the EMI fingerprint of the corresponding GS to distinguish the target EMI fingerprint.

[0027] Figure 8 The illustration shows the signature frequency of the same EMI fingerprint in both the reference EMI fingerprint and the target EMI fingerprint after applying automatic edge detection to trim the signal vector to the optimal length.

[0028] Figure 9 The illustration shows the impact of optimized synchronization using the analysis resampling process on the reference (GS) and target (UUT) signals.

[0029] Figure 10 An example EMI residual is shown, using untrimmed and trimmed EMI signals as example raw signals to compare the signal comparison metric.

[0030] Figure 11(a) illustrates an embodiment of a schematic diagram and process for automated brand-model configuration discovery for counterfeit detection technology.

[0031] Figure 11(b) illustrates an embodiment of a method for performing MSET-based MAE characterization.

[0032] Figure 12 The illustration shows an example 3D EMI residual surface generated by comparing two different utility equipment.

[0033] Figure 13 The illustration shows an example 3DEMI residual surface generated by comparing two similar (or identical) utility devices.

[0034] Figure 14 The illustration shows an example EMI residual between two different utility devices across one of the frequency bands, which triggered an MSET alarm.

[0035] Figure 15 The illustration shows an example EMI residual between two similar (or identical) utility devices across one of the frequency ranges, which does not trigger an MSET alarm.

[0036] Figure 16Two views of an embodiment of a graphical user interface are illustrated, which is used in conjunction with the display of an EMI fingerprint counterfeit scanner to visually present the results of an EMI fingerprint scan of a target utility device.

[0037] Figure 17 The illustration shows an embodiment of a computing system configured with the example systems, methods and / or special equipment disclosed herein. Detailed Implementation

[0038] This paper describes a system and method for providing automated asset configuration discovery and counterfeit detection in critical utility assets through electromagnetic interference (EMI) fingerprinting.

[0039] EMI signals are generated by power utility equipment (such as transformers, generators, inverters, meters, or other power grid systems) during operation. These EMI signals are generally considered noise, but they can also carry information that can be used to generate a unique EMI fingerprint (EMIF) for the utility equipment. For example, the EMI emitted by a target utility equipment with an unknown configuration of components can be scanned to generate a target EMI fingerprint for the target utility equipment. The generated target EMI fingerprint can be compared with a reference EMI fingerprint of a reference utility equipment with a known configuration to confirm that the target utility equipment has a known brand, model, and configuration, or to indicate that the target utility equipment does not have a known brand, model, and configuration, and therefore may contain one or more suspected counterfeit components, or may be suspected of being entirely counterfeit.

[0040] Counterfeit detection for power utility equipment is most conveniently performed at points in the supply chain before final installation, such as loading or receiving docks, or at ports of entry or exit or other government borders. Personnel performing EMI fingerprinting at these locations have little time to focus on the scan. However, requiring the personnel performing the scan to determine the exact brand, model, and internal component configuration of the target utility equipment before scanning is a labor-intensive and error-prone process.

[0041] It's important to note that there are actually many more permissible replacements for the actual internal component configurations, not just the number of brands and models of utility equipment. The brand and model assigned to a utility equipment don't necessarily change with each upgrade of internal components during a new production run (this is especially true for complex and / or high-cost utilities). Therefore, while the brand and model may remain unchanged for many years, the internal components can change with the "year" of the utility equipment's shipment or production run. For example, internal components can change because they are produced or purchased incrementally in batches. While batches may meet all quality and performance specifications, they can have different EMI characteristics. Depending on the year of shipment or production, these multiple internal component updates can result in multiple different EMI fingerprints for genuine utility equipment of the same brand and model, but this information may not be readily available to someone performing an EMI fingerprint scan. Therefore, it is impossible for someone performing an EMI fingerprint scan to fully identify the internal configuration of the target equipment through a simple inspection.

[0042] However, selecting the wrong brand, model, and internal component configuration for EMI fingerprinting is likely to result in false positives for the target utility equipment, misidentifying it as a potential counterfeit. Therefore, requiring the scanning personnel to identify the exact brand, model, and internal component configuration of the utility equipment being scanned and input this information into the scanning instrument is neither feasible nor desirable.

[0043] Instead, the scanning process needs to be fast, as easy as possible, and completely agnostic to any brand, model, and component configuration of the target utility equipment being scanned. Furthermore, the personnel performing EMI fingerprinting at these locations need to be able to perform the scans without requiring advanced data science degrees to interpret the results.

[0044] In one embodiment, the brand / model and internal component manufacturer of each target utility device scanned is automatically detected by a novel autonomous utility asset brand, model, and component configuration discovery pattern recognition framework. In one embodiment, a reference EMI fingerprint is taken from a reference utility device for the brand, model, and configuration (or “type”) of the utility device. The reference utility device for the brand, model, and configuration is a device identified as a genuine example (“Gold System”) of the utility device’s brand, model, and configuration. In one embodiment, the target utility device undergoes an iterative pattern recognition process that compares the target EMI fingerprint to a reference EMI fingerprint database using a configuration similarity metric called EMI fingerprint surface mean absolute error (EMIF SMAE). The recognition process quickly infers the configuration of the target utility device (or unit under test (UUT)) and then alerts to potential for counterfeits or presents proof that the scanned asset is genuine, authentic, has an permitted configuration, and is free of counterfeits.

[0045] Although we describe the invention in the context of power utility equipment, the general principles and techniques of the invention can be applied to any electronic system that includes at least one electronic component.

[0046] —Example EMI fingerprint counterfeit detector—

[0047] Figure 1 The illustration shows an embodiment of an EMI fingerprint counterfeit scanner 100 and an example target utility device 105. The EMI fingerprint counterfeit scanner 100 includes an antenna (or other EMI signal sensor) 115 connected to a radio device 120, such as a software-defined radio. In one embodiment, the EMI fingerprint counterfeit scanner 100 also includes a telemetry collector 125 connected to a sensor assembly 130 of the target utility device 105 via a telemetry bus 135 or alternatively via radio frequency transmission between transceivers 140 and 145. The EMI fingerprint counterfeit scanner 100 also includes a local data storage device 150 connected to the radio device 120 and the telemetry collector 125. The EMI fingerprint counterfeit scanner 100 also includes utility device configuration discovery and counterfeit detection logic 155. The EMI fingerprint counterfeit scanner 100 also includes a network interface 160 and a display 165.

[0048] Note that when power is supplied to utility device 105, utility device 105 generates EMI signal 110. Further note that after power to utility device 105 is cut off, utility device 105 may continue to generate EMI signal 110 for at least a period of time. The EMI signal is generated by one or more internal components of utility device 105, which may include, but are not limited to, controllers, switches, motors, inductor / transformer windings, capacitors, sensors, and other components. In some cases, the EMI signal may be generated by interaction between multiple components. In one embodiment, antenna 115 is configured to sense EMI signal 110 and apply the EMI signal to radio device 120 coupled to antenna 115. Depending on the configuration of antenna 115 and radio device 120, the EMI signal is sensed over a wide frequency spectrum (e.g., from approximately 1 MHz to approximately 4 GHz).

[0049] In one embodiment, antenna 115 may include: a dipole antenna, a Yagi-Uda antenna, a loop antenna, an electrically short antenna (e.g., an open-end wire with a length less than a quarter wavelength), a fractal antenna, a parabolic antenna, a microstrip antenna, a quadrilateral antenna, a random wire antenna (e.g., an open-end wire with a length greater than one wavelength), a Beveridge antenna, a helical antenna, a phased array antenna, and any other type of antenna now known or developed in the future. In a simple and inexpensive embodiment, antenna 115 may be an insulated wire with a fixed length of insulation stripped away. In one embodiment, the type and length of the antenna can be selected to achieve optimal discrimination sensitivity and robustness.

[0050] Antenna 115 can be positioned close to or far from target utility device 105. A smaller distance between the target utility device 105 and antenna 115 is preferred to achieve better sensitivity in antenna 115 and thus a higher signal-to-noise ratio (SNR) in the EMI fingerprint scanner 100. In addition to distance, the sensitivity of antenna 115 can also be affected by its orientation relative to target utility device 105.

[0051] In one embodiment, antenna 115 is positioned at a predetermined distance and orientation relative to target utility device 105 during scanning. This predetermined distance and orientation may be the same distance and orientation used for detecting reference EMI signals from a reference utility device having the same brand and model as target utility device 105. Consistency in antenna placement relative to the scanned utility device increases the EMI fingerprint counterfeit scanner 100's ability to match and distinguish between target EMI fingerprints and reference EMI fingerprints.

[0052] In one embodiment, antenna 115 may be fixed to EMI fingerprint scanner 100. In one embodiment, antenna 115 may be in a fixed position (distance and orientation) relative to target utility device 105 during scanning of target utility device 105 by EMI fingerprint scanner 100. For example, antenna 115 may be placed close to target utility device 105 and remain stationary during scanning. Antenna 115 may be fixed to or within the housing of target utility device 105. In one embodiment, multiple antennas and / or radio devices (not shown) may be positioned at different locations and orientations relative to target utility device 105 during scanning. In one embodiment, antenna 115 may move to multiple different locations and orientations relative to target utility device 105 during scanning. These various antenna positions and configurations, as well as other implementations of positions and configurations, may be selected as desired to improve the signal-to-noise ratio (SNR) of the detected EMI signal across target utility device 105, or to emphasize EMI signals emitted by specific components of target utility device 105.

[0053] In one embodiment, the radio device 120 is configured to convert received EMI signals from analog signals to digital signals and record the power amplitude and frequency of the signals at defined time intervals. In one embodiment, the radio device 120 may store the recorded signals as a data structure in a local data storage device 150, or provide them directly to the utility asset configuration discovery and counterfeit detection logic 155 for analysis.

[0054] Utility equipment such as target utility 105 is typically manufactured with sensor assembly 130, which provides sensor telemetry signals describing the state of various aspects of the utility equipment, such as temperature, current, voltage, or other detectable information. For example, sensor assembly 130 may be configured to interface with a remote terminal unit (RTU) of SCADA or other distributed control systems. In one embodiment, telemetry collector 125 is configured to present an RTU interface to sensor assembly 130.

[0055] In one embodiment, telemetry collector 125 receives and processes sensor telemetry signals. For example, telemetry collector 125 can parse sensor telemetry signals received via telemetry bus 135 to extract status information. Telemetry collector 125 can then store that status information as a data structure in local data storage device 150, or provide it directly to utility asset configuration discovery and counterfeit detection logic 155 for analysis.

[0056] In one embodiment, local data storage device 150 is a local data repository for a mobile device or computer. In one embodiment, utility asset configuration discovery and counterfeit detection logic 155 is a processor of a mobile device or computer specifically configured with instructions to perform one or more of the functions of the system described herein.

[0057] —Example environment for EMI fingerprinting—

[0058] Figure 2 An embodiment of an environment 200 in which an EMI fingerprint counterfeit scanner 100 is operated is illustrated.

[0059] In one embodiment, the EMI fingerprint counterfeit scanner 100 is a mobile device 205 or a computer 210 coupled to a software-defined radio device 120 and an antenna 115. In one embodiment, a network interface 160 is configured to enable the EMI fingerprint counterfeit scanner 100 to interact with one or more remote computers via a communication network 215. In one embodiment, the EMI fingerprint counterfeit scanner 100 can send requests to and receive responses from a web server, such as a web interface server 220. These communications can take the form of Remote State Transfer (REST) ​​requests using JavaScript Object Notation (JSON) as the data exchange format, or simple object access protocol (SOAP) requests to and from an XML server.

[0060] In one embodiment, web interface server 220 is configured to enable EMI fingerprint counterfeit scanner 100 to access resources provided by cloud application infrastructure 225. In addition to web interface server 220, cloud application infrastructure 225 includes server-side utility asset configuration discovery and counterfeit detection system 230 and one or more data storage devices 235. Web interface server 220, system 230, and data storage devices 235 are interconnected via local network 240. In one embodiment, server-side utility asset configuration discovery and counterfeit detection system 230 is one or more computing devices specifically configured with instructions to perform one or more functions of the system described herein. In one embodiment, analysis of a target EMI fingerprint is performed by server-side utility asset configuration discovery and counterfeit detection system 230 in response to a request from EMI fingerprint counterfeit scanner 100, and the results are returned to EMI fingerprint counterfeit scanner 100 for display to a user. In another embodiment, analysis of a target EMI fingerprint is performed by EMI fingerprint counterfeit scanner 100.

[0061] In one embodiment, a test sequence generator 245 is also provided. The test sequence generator 245 operates via one or more components in the target utility equipment 105 to control power. In operation, the test sequence generator 245 can create a square wave with a power amplitude via components of the target utility equipment 105. Instructions for the test sequence, including the amplitude and duration of the square wave, can be pre-programmed in the test sequence generator 245 and / or controlled by the EMI fingerprint scanner 100.

[0062] In one embodiment, for some types of utility equipment, an appropriate square wave can be generated by switching the power supply supplied to the target utility equipment 105 between high-power and low-power supply states to place the target utility equipment 105 into a "power-on" operating state (high power supply) and a "power-off" operating state (low power supply). In one embodiment, the power-on state can be a full-power supply state. In one embodiment, the power-on state can be a power supply state relatively higher than the low power supply state, and the power-off state is a power supply state relatively lower than the high power supply state. In one embodiment, the power-off state can be a power supply state where the power supply is completely cut off—a "no power" power supply state. In one embodiment, the power-off state can be an "idle" power supply state, wherein the power supplied to the target utility equipment 105 is the minimum power required to maintain the operation of the target utility equipment 105 at the lowest possible power level. In this configuration, a test sequence generator 245 is placed in series between the power supply 250 and the target utility equipment 105 and controls the delivery of power from the power supply 250 to the target utility equipment 105. The test sequence generator is configured to provide high-power and low-power test sequences to the target utility equipment 105 according to instructions for test sequences used to power on and power off the target utility equipment 105.

[0063] In another embodiment, for some types of utility equipment, an appropriate square wave can be generated by switching the load on the target utility equipment 105 between high-power and low-power draw states to place the target utility equipment 105 into a powered-on operating state (high-power draw) and a powered-off operating state (low-power draw). In one embodiment, the powered-on state can be a full-power draw state. In one embodiment, the powered-on state can be a power draw state relatively higher than the low-power draw state, while the powered-off state is a power draw state relatively lower than the high-power draw state. In one embodiment, the powered-off state can be a power draw state with the load completely disconnected—a “no-power” power draw state. In one embodiment, the powered-off state can be an “idle” power draw state, wherein the power drawn from the target utility equipment 105 is the minimum power required to maintain the operation of the target utility equipment 105 at the lowest possible power level. In this alternative configuration, a test sequence generator 245 is placed in series between the target utility equipment 105 and ground 255 and controls the power load drawn from the target utility equipment 105. The test sequence generator is configured to provide high-power and low-power power extraction (load) test sequences to the target utility equipment 105 according to instructions for test sequences used to power on and power off the target utility equipment 105.

[0064] In one embodiment, a test sequence generator 245 may be added to a buffer for initial power-on self-test (POST). Utility assets are typically unpacked, then powered on first in a POST test before being installed into a production system. Therefore, performing an EMI fingerprint forgery scan is a convenient time when setting up the target utility for POST testing. In one embodiment, the test sequence is applied to the target utility while it is being set up for testing in the buffer.

[0065] —Example configuration for discovery and counterfeit detection methods—

[0066] In one embodiment, one or more steps of the method described herein may be performed by a processor of one or more computing devices (such as reference numerals). Figure 17 The processor 1710 shown and described executes the process, which (i) accesses memory (such as memory 1715 and / or reference memory). Figure 17 (ii) Other computing device components shown and described) and configured with logic (such as references) Figure 17The utility asset allocation discovery and counterfeit detection logic 1730 shown and described herein (to enable the system to perform the steps of the method) is as follows. For example, the steps of a processor accessing and reading from or writing to memory to perform the computer-implemented method described herein. These steps may include (i) retrieving any necessary information, (ii) calculating, determining, generating, classifying, or otherwise creating any data, and (iii) storing any data calculated, determined, generated, classified, or otherwise created. References to storage (or storing) indicate memory or storage devices / disks stored as computing devices (such as references). Figure 17 The data structures in the memory 1715 or storage device / disk 1735 or remote computer 1765 of the computing device 1705 shown and described. In one embodiment, subsequent steps of the method may begin in response to parsing a received signal or retrieved stored data indicating that the previous step has been performed at least to the extent necessary to begin the subsequent step. Generally, the received signal or retrieved stored data indicates the completion of the previous step.

[0067] Figure 3 An embodiment of method 300 associated with utility asset allocation discovery and counterfeit detection is illustrated. Method 300 is a method for detecting whether a target utility device comprising multiple electronic components is genuine or a suspected counterfeit (e.g., containing at least one counterfeit component).

[0068] Method 300 can be initiated based on various triggers, such as receiving a signal over a network or parsing stored data, which indicates that: (i) the user (or administrator) of the EMI fingerprint scanner has initiated method 300, or (i) other triggers. Method 300 is initiated at start block 305 in response to parsing the received signal or retrieving the stored data and determining that the signal or stored data indicates that method 300 should begin. Processing continues to process block 310.

[0069] At process block 310, the system executes a test sequence that powers on and off a specific model of target device, and collects electromagnetic interference (EMI) signals emitted by the target device during power-on and power-off. The processing at process block 310 is then complete, and processing continues to process block 315.

[0070] At process block 315, the system generates a target EMI fingerprint from the EMI signals collected during the power-on and power-off cycles of the target device. Processing at process block 315 is complete, and processing continues to process block 320.

[0071] At process block 320, the system retrieves multiple reference EMI fingerprints from the database. Each reference EMI fingerprint corresponds to a different configuration of the electronic components of a genuine device with the same specific model as the target device. Moreover, each reference EMI fingerprint is generated based on reference EMI signals collected during a power-on and power-off sequence performed on the corresponding configuration of the genuine device. The processing at process block 320 is complete, and processing continues to process block 325.

[0072] At process block 325, the system iteratively compares the target EMI fingerprint with individual reference EMI fingerprints from a plurality of reference EMI fingerprints, and generates a similarity measure between each set of the target EMI fingerprint and the individual reference EMI fingerprints. Processing at process block 325 is complete, and processing continues to decision block 330.

[0073] At decision box 330, the system determines whether the similarity metric of any individual reference EMI fingerprint satisfies a threshold test. If the similarity metric of any individual reference EMI fingerprint satisfies the threshold test (Yes), then the processing at decision box 330 is complete and the processing continues to process box 335. If the similarity metric of any individual reference EMI fingerprint does not satisfy the threshold test (No), then the processing at decision box 330 is complete and the processing continues to process box 340.

[0074] At process box 335, the system generates a signal indicating that the target device is a genuine device. The processing at process box 335 is complete, and processing continues to end box 345, where process 300 ends.

[0075] At process box 340, the system generates a signal indicating that the target device is a suspected counterfeit device. Processing at process box 335 is complete, and processing continues to end box 345, where process 300 ends.

[0076] Each of the aforementioned process boxes of method 300 is described in more detail below.

[0077] —Execute test sequences and collect signals—

[0078] Referring again to process block 310, in one embodiment, a test sequence for powering on and off a target device of a specific model is executed, for example, by a test sequence generator 245. In one embodiment, the test sequence for powering on and off the target device includes multiple power-on or power-off cycles. In one embodiment, the test sequence cycles between approximately equal portions of: (i) providing a high power supply or load to power on the target device, and (ii) providing a low power supply or load to power off the target device. In one embodiment, a test sequence with a 30-second cycle for high power supply or load (power on) and a 30-second cycle for low power supply or load (power off) to the target device may be appropriate. In other embodiments, other test sequences may be appropriate, such as those with shorter or longer power-on / power-off periods, or with unequal power-on / power-off periods. In one embodiment, the test sequence generator is configured to automatically control the power or load to alternately power on and off the target device in a repeatable test sequence.

[0079] In one embodiment, where the test sequence generator 245 controls the power supply to the target device, the test sequence generator 245 provides high and low power from the power supply 250 to its input terminals (such as one of the primary terminals of a transformer) to energize and de-energize the target device separately in the test sequence. For example, power to the target device is alternately supplied and interrupted in a repetitive cycle. In another embodiment, where the test sequence generator 245 controls the power load drawn from the target device, the test sequence generator 245 provides high and low power loads respectively at its output terminals (such as one of the secondary terminals of a transformer) to energize and de-energize the target device separately in the test sequence. For example, the load on the target device is alternately applied and stopped in a repetitive cycle.

[0080] In one embodiment, the test sequence executed on the target device at process block 310 is the same as the test sequence initially executed on the reference device to generate their respective reference EMI fingerprints. In other words, the same test sequence is used to generate both the reference EMI fingerprint and the target EMI fingerprint.

[0081] Referring again to process block 310, in one embodiment, antenna 115 and radio device 120 collect electromagnetic interference (EMI) signals emitted by the target device during power-on and power-off cycles implemented by test sequence generator 245. In one embodiment, the EMI fingerprint counterfeit scanner 100 is configured to collect EMI signals emitted by the target device using software-defined radio device 120 and antenna 115 while the target device is powered on and off in a repeatable test sequence. During EMI signal collection, one or more antennas may be used as described above. Figure 1As described, the target device is located. The collection of EMI signals from the target device can be referred to as “scanning” the target device. EMI signals are collected from the target device both when it is powered on and off. For example, collecting EMI signals emitted from the target device during power-on and power-off includes a first set of EMI signals collected when the target device is powered on and a second set of EMI signals collected when the target device is powered off. In other words, it is a continuous time sequence of signals including the “top” of a square wave (representing a high-power or powered-on state) and the “bottom” of a square wave (representing a low-power or powered-off state). When the target utility is off, the bottom of the square wave is zero. When the target utility is switched to “idle,” the bottom of the square wave is not zero but is in some low-power state. However, regardless of the nature of the EMI signals collected for the bottom of the square wave, the entire collected square wave sequence of the target EMI signals, including the top and bottom, is included in the target EMI fingerprint. The target EMI fingerprint is generated by the combination of the first set and the second set of EMI signals. Even when the target utility is shut down in a low-power state, the second set of EMI signals can still be useful for generating an EMI fingerprint, because the target device can continue to generate EMI signals even after the power to the utility is cut off. Therefore, the processing of the bottom of the square wave is no different from the processing of the top of the square wave when generating the target EMI fingerprint. All periodic repetitions of the top and bottom are included in a long sequence within the test sequence.

[0082] —Generate fingerprint—

[0083] Referring again to process block 315, in one embodiment, the system generates a target EMI fingerprint from EMI signals collected during the power-on and power-off states of the target device. As discussed above, in one embodiment, the collected signals include EMI signals collected when the target device is powered on and when the target device is powered off.

[0084] Figure 4 An embodiment of method 400 is illustrated, which is associated with generating an EMI fingerprint from EMI signals collected during power-on and power-off of a utility device, such as at process block 315 of method 300. Note that both the target EMI fingerprint of the target utility device and the reference EMI fingerprint of a reference (confirmed to be authentic) utility device can be generated from the collected EMI signals in a similar manner. Method 400 begins at start block 405 in response to parsing a received signal or retrieved stored data indicating that method 400 should begin. Processing continues to process block 410.

[0085] At process block 410, the system divides the frequency range associated with the collected EMI signal into multiple "intervals" and represents each discrete interval with a representative frequency value. In one embodiment, these frequency intervals and associated frequency values ​​are equidistant. In one embodiment, the intervals and representative frequencies are stored in local data storage device 150 or data repository 235. The processing at process block 410 is complete, and processing continues to process block 415.

[0086] At process block 415, the system extracts amplitude-time pairs for each representative frequency value at regular time intervals (such as once per second) to form an amplitude-time series for that representative frequency. In one embodiment, amplitude-time pairs can be retrieved from a data structure of the recorded signal stored in local data storage device 150, and the resulting sequence can be stored in local data storage device 150 or data repository 235. The processing at process block 415 is complete, and processing continues to process block 420.

[0087] At process block 420, the system selects a subset of N representative frequency values ​​associated with the strongest power spectral density frequency. The signal with the highest signal-to-noise ratio typically has the highest peak on the power spectral density (PSD) plot. In one embodiment, a transform such as a Fast Fourier Transform (FFT) is performed on the amplitude-time series of each representative frequency. The representative frequencies are ranked according to the order of the transform results, thereby ranking them according to the peak height. The top N representative frequencies with the highest peaks are selected. In one embodiment of the invention, N is typically less than or equal to 20. These N selected frequencies may be referred to as "signature frequencies." In one embodiment, the indicator of the signature frequencies may be stored in local data storage device 150 or data repository 235. The processing at process block 420 is complete, and processing continues to process block 425.

[0088] At process block 425, the system uses an amplitude-time series associated with the signature frequency to generate an EMI fingerprint. In one embodiment, the generated EMI fingerprint is stored in a local data storage device 150 or a data repository 235. Processing at process block 425 is complete, and processing continues to end block 430, where process 400 ends.

[0089] —Retrieve Reference EMI Fingerprint—

[0090] Referring again to method 300, at process block 320, the system retrieves multiple reference EMI fingerprints from a database repository. In one embodiment, the database repository is a storehouse of reference EMI fingerprints for all possible valid replacement component configurations of all genuine brands and models of reference utility equipment. For each brand, model, and configuration, the reference EMI fingerprint is created by performing a test sequence on a genuine example of the utility equipment of that brand, model, and configuration that is certified, verified, or otherwise known to have the utility equipment and collecting the EMI signals emitted from that utility equipment. The resulting EMI fingerprint is then stored in the database repository for the brand, model, and configuration of the reference utility equipment. In one embodiment, the database repository is maintained remotely, such as on a cloud server, for example in a data repository 235. The EMI fingerprint counterfeit scanner 100 initiates a retrieval using a request (such as a REST request) to the web interface server 220 to retrieve the reference EMI fingerprints from the data repository 235. Web interface server 220 retrieves a reference EMI fingerprint from data repository 235 and returns the reference EMI fingerprint along with a REST request transmitted to network interface 160 of EMI fingerprint counterfeit scanner 100. In another embodiment, the database is maintained in local data storage device 150 of EMI fingerprint counterfeit scanner 100. EMI fingerprint counterfeit scanner 100 generates and executes a command to retrieve a reference EMI fingerprint from local data storage device 150. The locally maintained database can be updated from time to time based on a database maintained in the cloud.

[0091] In one embodiment, the EMI fingerprint counterfeit scanner 100 is configured to retrieve a plurality of reference EMI fingerprints from a data repository. In one embodiment, the reference EMI fingerprints correspond to a specific model of genuine reference device and also to different configurations of electronic components for that specific model of genuine reference device.

[0092] —Pre-classification of target utility equipment—

[0093] In one embodiment, similar utility equipment may exhibit similar characteristics detectable by sensor assembly 130. As discussed above, many component configurations of a given brand-model utility equipment may exist. While various brands, models, and component configurations of utility equipment may have completely different transducer sets and different numbers of sensors, what is relevant to configuration discovery is the general pattern exhibited by the utility equipment. The information detected by sensor assembly 130 and provided to telemetry collector 125 enables the EMI fingerprint counterfeit scanner to identify one or more of the following:

[0094] 1. (i) the rate of change of gas by external ambient temperature, and (ii) the rate of change of gas by load signature (from winding current);

[0095] 2. The increment of the temperature signal, for example, the reading of the internal temperature sensor minus the ambient external temperature for each load characteristic;

[0096] 3. The moving window partial discharge correlation coefficient of the partial discharge signal (if available) compared to a bivariate function of ambient temperature and load signature; and

[0097] 4. Normalized ratios of other signals, which show the pre-failure trend of utility equipment experiencing degradation in the field, but do not show the same pattern in any healthy assets.

[0098] For example, utility equipment of the first brand and model can operate between 80 and 100 degrees Celsius, while utility equipment of the second brand and model can operate between 150 and 200 degrees Celsius. These physical characteristics can be detected by sensor assembly 130 and demonstrate that the two types have completely different properties. Therefore, based on sensor telemetry signals and the measurements derived from them, various utility equipment brands, models, and component configurations can be classified, such as... Figure 5 As shown in the image. Figure 5 Example utility equipment 505 with different brands / models is shown. These utility equipment are pre-classified into the same brand and model 510 using sensor telemetry signals.

[0099] In one embodiment, the target utility device can thus be pre-classified based on sensor telemetry readings into a specific brand and model subset within a set of all possible types of brand, model, and component configurations. This reduces the number of reference EMI fingerprints that need to be retrieved and compared with the target EMI fingerprint. The reduction in reference EMI fingerprints for comparison can be very significant. For example, in a database containing tens of thousands of reference EMI fingerprints, the ability to identify the target utility device as belonging to a specific brand and model will reduce the number of reference EMI fingerprints for comparison to a small number of choices associated only with that brand and model. This reduction in the number of comparisons significantly reduces the time required to identify the target utility device as genuine or a suspected counterfeit, and also reduces the retrieval processing load on the cloud application infrastructure 225.

[0100] Figure 6An embodiment of a method 600 associated with pre-classifying target utility equipment based on sensor telemetry readings is illustrated. Method 600 can be initiated based on various triggers, such as receiving a signal via a network or parsing stored data indicating, for example, that a user of an EMI fingerprint counterfeit scanner 100 has initiated method 600. In response to a trigger indicating that method 600 should begin, method 600 begins at start block 605. Processing continues to process block 610.

[0101] At process block 610, the system receives telemetry signals from the sensor assembly of the target device. In one embodiment, the EMI fingerprint counterfeit scanner 100 receives telemetry signals from the sensor assembly 130 via the telemetry collector 125. The processing at process block 610 is complete, and processing continues to process block 615.

[0102] At process block 615, the system classifies the target device into a specific model based on telemetry signals. In one embodiment, the system trains a machine learning model (such as a multivariate state estimation technique, hereinafter referred to as "MSET") on sensor telemetry information of a genuine utility device labeled with the brand and model of the sensed utility device. Sensor telemetry signals received from the target utility device are fed to the trained machine learning model to assign the brand and model. In one embodiment, the reference EMI fingerprints retrieved from a database are limited to fingerprints applicable to the identified brand and model. In other words, (at process block 320 of method 300) retrieving multiple reference EMI fingerprints from the database is based on the classification of the target device. The processing at process block 615 is complete, and processing continues to end block 620, where process 600 ends.

[0103] The aforementioned sensor telemetry pre-classification analysis is a convenient front-end preprocessing method that reduces the time and computational burden required for automated configuration discovery for counterfeit detection by significantly reducing the number of reference EMI fingerprints that need to be iteratively compared with the target EMI fingerprint.

[0104] —Iterative Comparison of EMI Fingerprints—

[0105] Referring again to process blocks 325-340, the system iteratively compares the target EMI fingerprint with individual reference EMI fingerprints from a plurality of reference EMI fingerprints, generating a similarity measure between the target EMI fingerprint and each set of individual reference EMI fingerprints. In one embodiment, each of the M reference EMI fingerprints is compared with the target EMI fingerprint in turn. The comparison process continues until (i) an individual reference EMI fingerprint is found in which the generated similarity measure satisfies a threshold test, or (ii) after comparing the target EMI fingerprint with each of the M reference EMI fingerprints, no similarity measure satisfies the threshold test. Satisfying the threshold test indicates that the target EMI fingerprint matches the reference EMI fingerprint, and not satisfying the threshold test indicates that the target EMI fingerprint and the reference EMI fingerprint do not match.

[0106] In one embodiment, for example, during the EMI fingerprinting of multiple target devices, multiple target EMI fingerprints have been acquired from multiple target utility devices and then stored for later batch processing. M reference EMI fingerprints and N target EMI fingerprints are paired via a permutation operation that systematically considers all possible reference-target pairs. As described above, a similarity metric is generated for each comparison, and a threshold test indicates a match, while a failure indicates a mismatch between the compared EMI fingerprints.

[0107] If any reference EMI fingerprint satisfies the similarity metric, the system generates a signal that the target device is verified as a genuine, authentic device. If none of the reference EMI fingerprints satisfy the similarity metric, the system generates a signal indicating that the target device may be a counterfeit, or at least constructed with a configuration that does not contain an EMI fingerprint in the database.

[0108] It is important to note that the failure to meet similarity metrics and the signal that the target device may be counterfeit does not necessarily imply that the entire target device is composed of counterfeit components. Instead, it indicates that the target device is suspected of containing one or more counterfeit components. While in some cases the entire target device may be counterfeit, it is more likely that the target device has only one or a few internal counterfeit components. This may be especially true when the target device is a large system composed of many components. In this document, the target utility device may be referred to as “suspected / doubtedly counterfeit” as short for “suspected to contain one or more counterfeit components.”

[0109] In one embodiment, the EMI fingerprint counterfeit scanner 100 is configured to generate and display visual indications on a graphical user interface indicating that the target device is: (i) genuine, wherein the similarity measure of any single reference EMI fingerprint satisfies a threshold test, and (ii) suspicious or counterfeit, wherein the similarity measure of any single reference EMI fingerprint does not satisfy a threshold test.

[0110] In one embodiment, visual indication may include the display of a description of the brand, model, and component configuration on a graphical user interface. This can be as simple as displaying the brand, model, and configuration number or year information of the target utility equipment. Alternatively, the description may include additional information about the specific configuration of the target utility equipment.

[0111] In one embodiment, a "green light" notification is issued if each target utility unit (UUT) is proven to be free of internal counterfeit components. Alternatively, a "red light" alert is issued if a target utility unit (UUT) is suspected of having one or more internal counterfeit components. The system can tag target utility units (UUTs) for subsequent detailed analysis by, for example, storing the tags as a data structure in data repository 235 for service and security personnel.

[0112] In one embodiment, when a signal indicates that the target device is genuine, the system displays a visual indication that the target device is genuine on a graphical user interface. For example, the visual indication could be a display of a large green icon indicating that the target utility device is “genuine,” “authentic,” or “verified,” or other language indicating that the target utility device’s EMI fingerprint matches a reference EMI fingerprint used for genuine articles.

[0113] If a system exists that is authentic but does not yet have a corresponding reference (GS) EMI fingerprint in the database, an alarm will also be triggered. The brand / model / configuration scanned from the target utility equipment can then be added to the database for that brand and model's reference (GS) EMI fingerprint. This is typically not expected—because the utility equipment rollout process involves uploading the reference (GS) EMI fingerprint to the database for each new component configuration introduced. Therefore, a red light alarm is more likely to indicate a security issue. However, this system also makes it easy to correct any faults to include the reference (GS) EMI fingerprint in the database. Additionally, if a process or operational fault exists and the permitted configuration is not in the latest updated reference (GS) EMI fingerprint database, it will be detected during this step.

[0114] —Signal alignment for EMI fingerprint comparison—

[0115] When comparing a target EMI fingerprint with a reference EMI fingerprint, the signals being compared should be preprocessed (e.g., cleaned) and aligned to avoid false positives for potentially counterfeit utility equipment. Figure 7 A reference waveform (“Gold System” or “GS”) (top) 705 and a target waveform (“Unit Under Test” or “UUT”) (bottom) 710 for an example signature frequency of an EMI fingerprint are shown. The reference waveform 705 and the target waveform 710 are shown here for comparison prior to any signal cleanup process and alignment. The values ​​on the x-axis of the waveform graph are given in terms of the number of samples obtained from the EMI signal, and the values ​​on the y-axis are given in decibels per milliwatt (dBm). The sampling rates are consistent between the reference EMI fingerprint and the target EMI fingerprint. Figure 7 The approximate square wave pattern of the power signal plotted in the test is due to the on / off, power-on / power-off, high power / low (no) power operation of the reference and target utility equipment according to the test sequence.

[0116] In one embodiment, signal quality and alignment are improved by trimming the target signal to an optimal length. Figure 8 The illustration shows the same EMI fingerprint signature frequency in the reference and target EMI fingerprints after applying automatic edge detection to trim the signal vector to an optimal length, which begins and ends at the major transition of amplitude at the fingerprint signature. This trimming achieves a coarse alignment between the reference and target signals. Alignment prevents unwanted spikes in the residuals between EMI fingerprints near the transition between higher and lower amplitude states. Note that the reference (GS) signal (top) 805 is out of phase with the target (UUT) signal (bottom) 810. The phase shift is visible when examining the sampling point domain (along the x-axis) of both signals. This out-of-phase alignment is unavoidable because the scan is manually triggered by manually scanning the target utility equipment. Therefore, in one embodiment, the system (i) trims the target (collected) EMI signal to an optimal length for comparison with one or more of the reference EMI fingerprints, (ii) trims the reference EMI signal to an optimal length for comparison with the target (collected) EMI signal, or (iii) trims both the target (collected) EMI signal and the reference EMI fingerprint to optimal lengths for comparison with each other.

[0117] In one embodiment, phase alignment is further improved and phase shift is corrected by applying phase shift synchronization, such as OracleLab’s Analysis Resampling Process (ARP). Figure 9The illustration shows the effect of optimized synchronization using ARP on the reference (GS) and target (UUT) signals. The original reference (GS) and target (UUT) signals are shown on the same axis (top) 905 to illustrate how severe the misalignment of the two signals is. After applying ARP, the reference (GS) and target (UUT) signals are also shown on the same axis (bottom) 910, thus showing how the two signals are actually synchronized. Therefore, the time-series EMI signals of the reference (GS) utility equipment and the target (UUT) are optimally synchronized by ARP. Thus, in one embodiment, the system synchronizes a first phase of the target (collected) EMI signal with a second phase of one of the reference EMI fingerprints.

[0118] Recall that each signature frequency is one of the top N frequency intervals with the highest signal-to-noise ratio, selected for inclusion in the EMI fingerprint as the most informative. In one embodiment, N=20 intervals are selected to represent the 3D EMI fingerprint for each system. However, this framework is flexible and scalable to any more or fewer intervals. N=20 intervals work well in practice. The signal cleanup and alignment process, including reference... Figure 8 The described trimmed signal vector and reference Figure 9 The described phase-shift synchronization will be repeated in an iterative loop for all N signature frequencies (top frequency range) of the EMI fingerprint. Each pair of reference (GS) and target (UUT) signals used for the signature frequencies will be trimmed and phase-shifted to ensure a more accurate comparison of the reference and target EMI fingerprints.

[0119] —EMI fingerprint surface mean absolute error—similarity measure—

[0120] This paper introduces an autonomous similarity metric, or “similarity” metric, called EMI fingerprint surface mean absolute error (EMIF SAME or SMAE), to rapidly infer the unknown configuration of a target utility device. In one embodiment, the similarity metric described in Reference Method 300 is the EMI fingerprint surface mean absolute error. SMAE and its component mean absolute error (MAE) are quantitative numerical measures for 3D surface differentiation. SMAE enables the automatic and empirical selection of the accurate true configuration of the scanned target utility device without requiring user interaction / distraction with the system.

[0121] Human visual comparison between two 3D EMI fingerprint surfaces yields only a qualitative comparison of similarity. This qualitative comparison is an inconsistency indicator of whether the reference (GS) utility equipment and the target (UUT) are similar-similar configurations or similar-dissimilar configurations. Furthermore, human visual comparison cannot be scaled up—humans lack the ability to handle an increasing amount of work by adding resources to the system. Here we introduce a quantitative metric, called the Mean Absolute Error (MAE), applied to the individual signals after trimming and phase shift synchronization discussed above, followed by the Surface MAE (SMAE), which is the sum of all N signature frequencies selected to represent the asset's "fingerprint" across the 3D surfaces of the EMI fingerprint.

[0122] In one embodiment, the similarity measure is based on the mean absolute error at a specific set of frequencies between the reference EMI fingerprint and the target EMI fingerprint.

[0123] The mean absolute error (MAE) between the reference signal and the target signal at the signature frequency can be expressed by the following formula.

[0124]

[0125] Where M is the total number of amplitude-time pairs (length of the target signal) that constitute the amplitude-time series used for the signature frequency, i is the index, y is the value of the reference signal at index i, and x is the value of the target signal at index i.

[0126] The surface mean absolute error (SMAE) at each signature frequency of a fingerprint can be expressed by the following formula.

[0127]

[0128] Where N is the total number of signature frequencies in the EMI fingerprint, and j is the index. Therefore, the entire square wave time series for the target (UUT) EMI fingerprint is subtracted from the entire square wave time series for the reference (GS) EMI fingerprint to calculate the surface MAE.

[0129] Figure 10Example untrimmed residual 1005 and trimmed residual 1010 for example unprocessed signals are shown to compare signal comparison metrics. The residuals (top) between the reference (GS) and target (UUT) EMI signals before and after ARP synchronization are measures used to determine the correlation between the signals. MAE is a scalar representation of the residuals for individual time-series signals, while SMAE is a scalar value used to determine the cumulative correlation between groups of signals (bottom). As can be inferred from the figure, phase difference can incorrectly indicate differences between signals; ARP significantly improves the MAE metrics for all individual signals, and now all permutations for the reference (GS) and target (UUT) EMI signals correctly identify the similarity between 3D EMIFs in pairwise comparisons.

[0130] The interval residuals and surface residuals are characterized by the MAE and SMAE before and after the trimming operation and ARP optimization synchronization. Note that the original, pre-trimmed SMAE 1015 is relatively large, close to 560. The trimming signal reduces the SMAE to 272, as shown in the pre-ARP characterization 1020. The final optimized similarity metric 1025 shows an SMAE of only 6. For this example data, the improvement reduces the original SMAE from 560 to 6. This provides an indication of the size of the threshold that can be set for comparison between the target EMI fingerprint and the reference EMI fingerprint.

[0131] —Example of automatic brand-model configuration discovery for counterfeit detection—

[0132] In one embodiment, the similarity measure is generated by performing the following operations for each specific frequency in the reference EMI fingerprint: generating a residual between the MSET estimate of the reference amplitude-time series signal at the specific frequency in the reference EMI fingerprint and the target amplitude-time series signal at the specific frequency in the target EMI fingerprint; and combining the generated residuals to generate the similarity measure.

[0133] Figure 11(a) illustrates a schematic diagram and one embodiment of a process 1100 for automated brand-model configuration discovery for counterfeit detection technology. Figure 11(b) illustrates one embodiment of a method for performing MSET-based MAE characterization. The modules in Figures 11(a) and 11(b) are further described in the following numbered steps.

[0134] 1. By powering on / off utility assets (also referred to herein as “utility equipment”) with different variants of the square wave signature, N 15-minute conventional sensor telemetry signals (1103, 1105 and 1107) can be collected from the different variants of the square wave signature.

[0135] 2. Classify utility asset brands / models by any single scalar-based metric (e.g., MAE) (1109).

[0136] 3. A range scan is performed to analyze the classified systems with M configurations, generating M EMI fingerprints, which are stored in a reference (GS) EMI fingerprint library. To reduce the signal-to-noise ratio (SNR), the fine-grained RF frequencies (4000 fine frequency intervals in a preferred embodiment) for each EMIF are further subdivided into 100 coarse frequency intervals (1111, 1151–1161).

[0137] 4. Twenty optimal frequency intervals are determined from 100 intervals, whose time-series EMI content exhibits significant periodicity in the frequency domain. Significant periodicity reflects the load dynamics on the target utility asset (UUT). In one embodiment, the 20 optimal frequency intervals are those reference frequency intervals that are immutable and invariant during subsequent residual operations (1163).

[0138] 5. Target utility assets (UUTs) were also classified using conventional telemetry, followed by range scanning analysis. The fine frequency ranges (1113, 1115) were then merged again into 100 coarse frequency ranges. The same 20 optimal frequencies previously determined for reference (GS) were then used for each target utility asset (UUT) scanned (1111, 1151-1161). Pre-stored GS libraries containing configuration EMIFs corresponding to the brand / model of the UUT were retrieved from the database.

[0139] 6. M reference (GS) and N target (UUT) EMI fingerprints are paired via a permutation operation that systematically considers all possible reference-target (GS-UUT) pairs. Then, the fingerprints are trained using reference GS... i The MSET model is constructed using 20 frequency ranges, (1163), and then used for the target UUT. j The 20 frequency ranges generate MSET estimates, thus producing MSET-UUT. j (1175).

[0140] 7. For GS i and MSET-UUT j The 20 frequency ranges were then merged again to produce two time-synchronized EMI surfaces (1177).

[0141] 8. The two EMI surfaces are processed by 2D surface subtraction, which produces a 2D noise residual surface in 3D space (1181) (visual example below), and MAE is calculated and recorded based on the residual surface (1183).

[0142] 9. Steps 6-8 in GS i and UUT j Parameterize the iterations of all possible pairs of EMIF. (1157-1189 define the loop).

[0143] 10. A reference (GS) and target (UUT) pair with high MAE values ​​indicates that the two systems are different (e.g., Figure 12 As shown in the figure), while pairs with low MAE values ​​indicate that they are the same (as shown in the figure). Figure 13 (as shown in the image).

[0144] Figure 12 The illustration shows an example 3D EMI residual surface 1200 generated by comparing two different utility devices. Subtraction and merging operations between the EMI fingerprints of the two different utility devices are performed on 20 time-synchronized frequency ranges, resulting in a residual surface with high variability. The MAE or SMAE calculated from this surface will be high.

[0145] Figure 13 The illustration shows an example 3D EMI residual surface 1300 generated by comparing two similar (or identical) utility devices. Subtraction, merging, and synchronization operations between the EMI fingerprints of the two identical (or similar) utility devices are performed interval-by-interval across 20 time-synchronized frequency ranges, then aggregated across the entire surface, resulting in a substantially flat residual surface with low variability. The MAE or SMAE calculated from this surface will be low.

[0146] Figure 14 The illustration shows an example EMI signal residual 1400 between two different utility devices spanning one of the 20 frequency intervals constituting the 3D EMI residual surface 1200. In one embodiment, any anomalies in the residual relative to the corresponding GS frequency interval time series are detected and identified by MSET. MSET anomaly alarms are indicated by all points having a logic value of 1 (see the y-scale on the right), thus indicating an anomaly alarm for this residual. EMI signal residual 1400 is identified by MSET as being in a constant anomalous state, as shown by the continuous line 1405 at the points with logic values ​​of 1.

[0147] For signals without anomalies relative to the corresponding GS frequency interval time series, the MSET result shows no anomalies (logic value 0).

[0148] Figure 15The illustration shows an example EMI signal residual 1500 between two similar (or identical) utility devices spanning one of the 20 frequency ranges constituting the 3D EMI residual surface 1300. No visual anomalies are observed on the 3D residual surface. This is confirmed by MSET—the absence of anomaly alarms is indicated by points where all logic values ​​are 0 (see the y-axis on the right). EMI signal residual 1500 is identified by MSET as consistently non-abnormal (or compliant), as shown by the continuous line of points at logic values ​​of 0.

[0149] —Graphical User Interface—

[0150] Figure 16 Two views are illustrated of an embodiment of a graphical user interface for use with a display 165 of an EMI fingerprint counterfeit scanner 100 to visually present the EMI fingerprint scan results of a target utility device.

[0151] In one embodiment, a "failure" view 1600 may be displayed when signals regarding the results indicate that the target utility equipment is not a known valid configuration. In one embodiment, the "failure" view 1600 includes a large visual indicator 1605, which may be red and octagonal, indicating that the target equipment is a suspected counterfeit (containing at least one counterfeit component). In one embodiment, the "failure" view 1600 may also include a summary of the scan results 1610.

[0152] In one embodiment, a "success" view 1650 may be displayed when a signal regarding the result indicates that the target utility equipment is a known valid configuration. In one embodiment,

[0153] The “success” view 1650 includes a large visual indicator 1655, which may be green and circular, indicating that the target device is a genuine device. In one embodiment, the “success” view 1650 may also include a summary of the scan results 1610, which may include the brand, model, and configuration number or year information of the target utility device.

[0154] In one embodiment, the system also generates and displays a visualization 1675 on a graphical user interface of the 3D residual surface based on one of the reference EMI fingerprint and the target EMI fingerprint. In another embodiment, any type of visualization can be presented on the graphical user interface, including reference EMI fingerprints. Figures 12-15 Visualization of the description. This can provide users with further information about why the target device was confirmed as genuine or failed to be confirmed.

[0155] —Cloud or Enterprise Implementation Examples—

[0156] In one embodiment, the library and / or other system portion of the database shown and described herein is a computing / data processing system comprising a collection of database applications or distributed database applications. The application and data processing system may be configured to operate with or implemented as cloud-based network systems, Software as a Service (SaaS) architectures, Platform as a Service (PaaS) architectures, Infrastructure as a Service (IaaS) architectures, or other types of network computing solutions. In one embodiment, the cloud computing system is a server-side system that provides one or more of the functions disclosed herein, and a number of users can access the system via the EMI fingerprint scanner 100 or other client computing devices communicating with the cloud computing system (acting as a server) via a computer network.

[0157] —Computing Device Examples—

[0158] Figure 17 An example computing device 1700 is illustrated, which is configured and / or programmed with one or more and / or equivalents of the example systems and methods described herein. The example computing device may be a computer 1705, which includes a processor 1710, a memory 1715, and an input / output port 1720 operably connected via a bus 1725. In one example, computer 1705 may include similar... Figures 1 to 16 The utility asset allocation discovery and counterfeit detection logic 1730 shown is configured to facilitate utility asset allocation discovery and counterfeit detection. In various examples, logic 1730 may be implemented in hardware, a non-transitory computer-readable medium with stored instructions, firmware, and / or a combination thereof. Although logic 1730 is shown as a hardware component attached to bus 1725, it should be appreciated that in other embodiments, logic 1730 may be implemented in processor 1710, stored in memory 1715, or stored in disk 1735.

[0159] In one embodiment, logic 1730 or computer is a component (e.g., structure: hardware, non-transitory computer-readable medium, firmware) for performing the described actions. In some embodiments, the computing device may be a server operating in a cloud computing system, a server configured in a Software as a Service (SaaS) architecture, a smartphone, a laptop computer, a tablet computing device, etc.

[0160] This component can be implemented as, for example, an ASIC programmed for utility asset allocation discovery and counterfeit detection. It can also be implemented as stored computer-executable instructions, which are presented as data 1740 to computer 1705, temporarily stored in memory 1715, and then executed by processor 1710.

[0161] The Logic 1730 can also provide components (e.g., hardware, non-transitory computer-readable media storing executable instructions, firmware) for performing utility asset allocation discovery and counterfeit detection.

[0162] Generally describing the example configuration of computer 1705, processor 1710 can be a variety of different processors, including dual-microprocessor and other multiprocessor architectures. Memory 1715 can include volatile memory and / or non-volatile memory. Non-volatile memory can include, for example, ROM, PROM, etc. Volatile memory can include, for example, RAM, SRAM, DRAM, etc.

[0163] Storage disk 1735 can be operatively connected to computer 1700 via, for example, an input / output (I / O) interface (e.g., a card, device) 1745 and an input / output port 1720. Disk 1735 can be, for example, a disk drive, solid-state drive, floppy disk drive, tape drive, Zip drive, flash memory card, memory stick, etc. Furthermore, disk 1735 can be a CD-ROM drive, CD-R drive, CD-RW drive, DVD ROM, etc. For example, memory 1715 can store process 1750 and / or data 1740. Disk 1735 and / or memory 1715 can store an operating system that controls and allocates resources of computer 1705.

[0164] Computer 1705 can interact with input / output (I / O) devices via I / O interface 1745 and input / output port 1720. Input / output devices may include, for example, a keyboard 1780, microphone 1784, pointing and selection device 1782, camera 1786, video card, monitor 1770, scanner 1788, printer 1772, speaker 1774, disk 1735, network device 1755, etc. Input / output port 1720 may include, for example, a serial port, parallel port, and USB port. Input / output devices may include a software-defined radio device 1790 and an associated antenna 1792.

[0165] Computer 1705 can operate in a network environment and therefore can be connected to network device 1755 via I / O interface 1745 and / or I / O port 1720. Through network device 1755, computer 1705 can interact with network 1760. Through network 1760, computer 1705 can logically connect to remote computer 1765. Networks that computer 1705 can interact with include, but are not limited to, LANs, WANs, and other networks.

[0166] —Definitions and Other Examples—

[0167] In another embodiment, the described methods and / or their equivalents may be implemented using computer-executable instructions. Thus, in one embodiment, a non-transient computer-readable / storage medium is configured to have a store of computer-executable instructions for an algorithm / executable application, which, when executed by one or more machines, cause the one or more machines (and / or associated components) to perform the method. Example machines include, but are not limited to, processors, computers, servers operating in cloud computing systems, servers configured with a Software as a Service (SaaS) architecture, smartphones, and the like. In one embodiment, the computing device is implemented using one or more executable algorithms configured to perform any of the disclosed methods.

[0168] In one or more embodiments, the disclosed methods or their equivalents are performed by any of: computer hardware configured to perform the methods; or computer instructions embodied in a module stored in a non-transient computer-readable medium, wherein the instructions are configured to execute an algorithm that is configured to perform the methods when executed at least by a processor of a computing device.

[0169] Although the methods illustrated in the figures are shown and described as a series of boxes for the purpose of illustrative simplicity, it should be understood that these methods are not restricted by the order of the boxes. Some boxes may appear in a different order than those shown and described and / or appear simultaneously with other boxes. Moreover, example methods may be implemented using fewer boxes than are shown in all the figures. Boxes may be combined or divided into multiple actions / components. Furthermore, additional and / or alternative methods may employ additional actions not illustrated in the boxes.

[0170] The following includes definitions of the selected terms used herein. Definitions include various examples and / or forms of components that fall within the scope of the term and can be used to implement it. Examples are not intended to be restrictive. Both singular and plural forms of the terms may be included in the definitions.

[0171] References to "an embodiment," "an embodiment," "an example," "an example," etc., indicate that one or more embodiments or examples as described may include a particular feature, structure, characteristic, property, element, or limitation, but not every embodiment or example must include that particular feature, structure, characteristic, property, element, or limitation. Furthermore, repeated use of the phrase "in one embodiment" does not necessarily refer to the same embodiment, but it can refer to the same embodiment.

[0172] ASIC: Application-Specific Integrated Circuit.

[0173] CD: Optical disc.

[0174] CD-R: CD is recordable.

[0175] CD-RW: CDs are rewritable.

[0176] DVD: Digital multifunction disc and / or digital video disc.

[0177] LAN: Local Area Network.

[0178] RAM: Random Access Memory.

[0179] DRAM: Dynamic RAM.

[0180] SRAM: Synchronous RAM.

[0181] ROM: Read-only memory.

[0182] PROM: Programmable ROM.

[0183] EPROM: Erasable PROM.

[0184] EEPROM: Electrically Erasable Proto-ROM.

[0185] USB: Universal Serial Bus.

[0186] XML: Extensible Markup Language.

[0187] WAN: Wide Area Network.

[0188] As used herein, a “data structure” is an organization of data stored in memory, storage devices, or other computerized systems within a computing system. A data structure can be any of, for example, a data field, a data file, a data array, a data record, a database, a data table, a graph, a tree, a linked list, etc. A data structure can be formed from and contain many other data structures (e.g., a database contains many data records). Other examples of data structures are also possible according to other embodiments.

[0189] As used herein, "computer-readable medium" or "computer storage medium" means a non-transient medium that stores instructions and / or data configured to perform one or more of the disclosed functions when executed. In some embodiments, data may be used as instructions. Computer-readable media may take the form of, but is not limited to, non-volatile and volatile media. Non-volatile media may include, for example, optical discs, magnetic disks, etc. Volatile media may include, for example, semiconductor memory, dynamic memory, etc. Common forms of computer-readable media may include, but are not limited to, floppy disks, flexible disks, hard disks, magnetic tapes, other magnetic media, application-specific integrated circuits (ASICs), programmable logic devices, compact discs (CDs), other optical media, random access memory (RAM), read-only memory (ROM), memory chips or cards, memory sticks, solid-state storage devices (SSDs), flash drives, and other media in which computers, processors, or other electronic devices can operate. If each type of medium is selected for implementation in one embodiment, it may include stored instructions of an algorithm configured to perform one or more of the disclosed and / or claimed functions.

[0190] As used herein, “logic” means a component implemented using computer or electrical hardware, a non-transient medium having stored instructions for executing applications or programs, and / or a combination thereof, to perform any function or action disclosed herein, and / or to cause a function or action from another logic, method, and / or system to be performed as disclosed herein. Equivalent logic may include firmware, a microprocessor programmed with an algorithm, discrete logic (e.g., an ASIC), at least one circuit, analog circuit, digital circuit, programmable logic device, memory device containing instructions for an algorithm, etc., any of which may be configured to perform one or more of the disclosed functions. In one embodiment, logic may include one or more gates, combinations of gates, or other circuit components configured to perform one or more of the disclosed functions. In the case of describing multiple logics, it is possible to combine multiple logics into one logic. Similarly, in the case of describing a single logic, it is possible to distribute that single logic among multiple logics. In one embodiment, one or more of these logics are corresponding structures associated with performing the disclosed and / or claimed functions. The choice of which type of logic to implement may be based on desired system conditions or specifications. For example, hardware implementation of the function would be chosen if higher speed is considered. If lower cost is a consideration, then stored instructions / executable applications will be chosen to implement the functionality.

[0191] An "operable connection," or a connection through which entities are "operably connected," is a connection capable of sending and / or receiving signals, physical communication, and / or logical communication. An operable connection may include physical interfaces, electrical interfaces, and / or data interfaces. An operable connection may include various combinations of interfaces and / or connections sufficient to allow for operable control. For example, two entities may be operably connected to transmit signals to each other directly or through one or more intermediate entities (e.g., processors, operating systems, logic, non-transient computer-readable media). Logical and / or physical communication channels can be used to create an operable connection.

[0192] As used herein, “user” includes, but is not limited to, one or more persons, computers or other devices, or a combination of these.

[0193] While the disclosed embodiments have been illustrated and described in considerable detail, they are not intended to limit the scope of the appended claims or in any way restrict them to such detail. It is certainly impossible to describe every contemplated combination of components or methods in order to describe all aspects of the subject matter. Therefore, this disclosure is not limited to the specific details or illustrative examples shown and described. Consequently, this disclosure is intended to cover changes, modifications, and variations that fall within the scope of the appended claims.

[0194] As to the extent to which the term “comprising” or “including” is used in the specific implementation or claims, it is intended to be inclusive in a manner similar to how it is interpreted when the term “comprising” is used as a transitional word in the claims.

[0195] As far as the term “or” is used in the specific implementation or claims (e.g., A or B), it is intended to mean “A or B or both.” When the applicant intends to indicate “only A or B but not both,” then the phrase “only A or B but not both” will be used. Therefore, the use of the term “or” herein is inclusive, not exclusive.

Claims

1. A method for detecting whether a target device comprising multiple electronic components is genuine or a suspected counterfeit, the method comprising: Perform a test sequence that powers on and off a specific model of target equipment and collect electromagnetic interference (EMI) signals emitted by the target equipment during power-on and power-off. Generate a target EMI fingerprint from EMI signals collected during the power-on and power-off periods of the target device; Retrieve multiple reference EMI fingerprints from the database, where each reference EMI fingerprint corresponds to a different configuration of the electronic components of a genuine device with the same specific model as the target device, and where each reference EMI fingerprint is generated from reference EMI signals collected during a power-on and power-off sequence performed on the corresponding configuration of the genuine device; The target EMI fingerprint is iteratively compared with individual reference EMI fingerprints among the plurality of reference EMI fingerprints, and a similarity measure is generated between each set of compared target EMI fingerprints and individual reference EMI fingerprints; as well as Generate a signal that instructs the target device. (i) is a genuine device, wherein the similarity metric of any single reference EMI fingerprint satisfies the threshold test, and (ii) is a suspected counterfeit device in which the similarity metric of any single reference EMI fingerprint does not meet the threshold test.

2. The method as described in claim 1, The collection of EMI signals emitted from the target device during power-on and power-off periods includes collecting a first set of EMI signals when the target device is powered on and a second set of EMI signals when the target device is powered off; and The target EMI fingerprint is generated from a combination of a first set of EMI signals and a second set of EMI signals.

3. The method of claim 1, wherein the test sequence of powering on and off the target device includes multiple power-on or power-off operations.

4. The method of claim 1, further comprising: Receive telemetry signals from the sensor components of the target device; Classify target equipment into specific models based on telemetry signals; The retrieval of the multiple reference EMI fingerprints from the database is based on the classification of the target device.

5. The method of claim 1, further comprising generating a similarity metric by: For each specific frequency in the reference EMI fingerprint, generate the residual between the reference amplitude-time series signal at that specific frequency in the reference EMI fingerprint and the target amplitude-time series signal at that specific frequency in the target EMI fingerprint using the multivariate state estimation technique MSET; and The generated residuals are combined to generate a similarity measure.

6. The method of claim 1 or 5, wherein the similarity measure is based on the average absolute error at a set of specific frequencies between the reference EMI fingerprint and the target EMI fingerprint.

7. The method of claim 1 or 5, wherein the similarity measure is the surface mean absolute error.

8. The method of any one of claims 1 to 5, further comprising at least one of: (i) trimming the collected EMI signal to an optimal length for comparison with one or more of the reference EMI fingerprints, or (ii) synchronizing a first phase of the collected EMI signal with a second phase of one of the reference EMI fingerprints.

9. The method according to any one of claims 1 to 5, further comprising: A visualization of the 3D residual surface is generated and displayed on a graphical user interface based on one of the reference EMI fingerprints and the target EMI fingerprint; (i) When a signal indicates that the target device is a genuine device, a visual indication that the target device is genuine is displayed on the graphical user interface, along with a description of the brand, model, and component configuration. (ii) When a signal indicates that the target device is a suspected counterfeit device, display a visual indication on the graphical user interface that the target device is suspected or counterfeit.

10. A non-transitory computer-readable medium storing computer-executable instructions, said computer-executable instructions causing the computer to: The software-defined radio device and antenna are used to collect electromagnetic interference (EMI) signals emitted by the target device when it is powered on and then powered off in a repeatable test sequence. Target EMI fingerprint is generated from EMI signals collected when the target device is powered on and off. Multiple reference EMI fingerprints are retrieved from the database, each of which corresponds to a different configuration of the electronic components of a genuine device of the same specific model as the target device, and each reference EMI fingerprint is generated from reference EMI signals collected when the genuine device is powered on and then powered off in a repeatable test sequence. The target EMI fingerprint is iteratively compared with individual reference EMI fingerprints among the plurality of reference EMI fingerprints, and a similarity measure is generated between each set of compared target EMI fingerprints and individual reference EMI fingerprints; as well as The visual indications generated and displayed on the graphical user interface for the target device are the following: Genuine product, wherein the similarity metric of any single reference EMI fingerprint satisfies the threshold test, and Suspicious or counterfeit, where the similarity metric of any single reference EMI fingerprint fails to meet the threshold test.

11. The non-transitory computer-readable medium as claimed in claim 10, The collection of EMI signals emitted from the target device during power-on and power-off periods includes a first set of EMI signals collected when the target device is powered on and a second set of EMI signals collected when the target device is powered off; and The target EMI fingerprint is generated from a combination of a first set of EMI signals and a second set of EMI signals.

12. The non-transitory computer-readable medium of claim 10, wherein the test sequence of energizing and de-energizing the target device includes multiple energizing or de-energizing operations.

13. The non-transitory computer-readable medium of claim 10, further comprising instructions that, when executed by at least a processor, cause the computer to: Receive telemetry signals from the sensor components of the target device; Classify target equipment into specific models based on telemetry signals; The retrieval of the multiple reference EMI fingerprints from the database is based on the classification of the target device.

14. The non-transitory computer-readable medium of any one of claims 10 to 13, further comprising instructions that, when executed by at least a processor, cause the computer to perform at least one of the following operations: (i) trim a collected EMI signal to an optimal length for comparison with one or more reference EMI fingerprints, or (ii) synchronize a first phase of the collected EMI signal with a second phase of one of the reference EMI fingerprints.

15. A system for detecting whether a target device of a specific model, comprising multiple electronic components, is genuine or a suspected counterfeit, the system comprising: The test sequence generator is configured to automatically control the power supply to alternately power on and off the target device according to a repeatable test sequence; The EMI fingerprint counterfeit scanner is configured as follows: (i) Collect electromagnetic interference (EMI) signals emitted by the target device when the target device is powered on and then powered off. (ii) Generate a target EMI fingerprint from the EMI signals collected when the target device is powered on and off. (iii) Retrieve multiple reference EMI fingerprints from the data repository, where each reference EMI fingerprint corresponds to a specific model of genuine reference equipment and also to a different configuration of electronic components for that specific model of genuine reference equipment. (iv) Iteratively compare the target EMI fingerprint with individual reference EMI fingerprints from the plurality of reference EMI fingerprints, and generate a similarity measure between each set of compared target EMI fingerprints and individual reference EMI fingerprints, and (v) Generate and display visual indications on the graphical user interface that the target device is one of the following: Genuine product, wherein the similarity metric of any single reference EMI fingerprint satisfies the threshold test, and Suspicious or counterfeit, where the similarity metric of any single reference EMI fingerprint fails to meet the threshold test.

Citation Information

Patent Citations

  • High sensitivity detection and identification of counterfeit components in utility power system via EMI frequency KIVIAT management

    CN114902221A