Data protection by randomized spatial imaging

By converting the data into three-dimensional mutated images and analyzing their points and vacancy probability, the problem of potential data damage in the prior art is solved, efficient and real-time data integrity verification is achieved, and flexible management of large data sets is supported.

CN120495056APending Publication Date: 2025-08-15HONEYWELL INTERNATIONAL INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510162335.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2025-02-06
Filing Date
2025-02-14
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

The prior art is difficult to effectively detect potential corruption of data files before and after transmission or storage, especially the inability to identify the hidden modifications of malicious actors through decryption and rehashing, resulting in failure of data integrity verification and affecting the progress of digital transformation.

Method used

The data is converted into a three-dimensional mutated image, representing data characteristics through randomly distributed pixels and vacancies, and analyzing points and vacancies in the image using a spatial process, generating and verifying the 3D mutated image of the data to ensure integrity.

Benefits of technology

It realizes efficient and real-time integrity verification of data, can detect potential malicious modifications, reduces the risk of system failure, and supports flexible management and verification of large data sets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120495056A_ABST
    Figure CN120495056A_ABST
Patent Text Reader

Abstract

A method for determining whether data on a device has changed from an original version of the data ("raw data") is provided. The method comprises: converting the data into a first three-dimensional (3D) spatial representation of the data, wherein the first 3D spatial representation uses locations of points and / or vacancies in the first 3D spatial representation to represent a plurality of characteristics of the data; wherein converting the data into the first 3D spatial representation comprises converting the data using the same process for generating a second 3D spatial representation from raw data; analyzing the first 3D spatial representation using one or more spatial processes; and determining whether the data has changed based on the analysis of the first 3D spatial representation.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims the benefit of prior-filed U.S. Provisional Patent Application Serial No. 63 / 553,533, filed February 14, 2024 ('533) and U.S. Provisional Patent Application Serial No. 63 / 728,815, filed December 6, 2024 ('815). The '533 and '815 applications are incorporated herein by reference. Background Art

[0003] The global market is undergoing a digital transformation, with high-performance computing, communications, and software technologies as key enablers of autonomous, intelligent command and control for new business and infrastructure applications. Data and software integrity continue to face attacks from hackers and insiders. Software and data corruption leads to high vulnerability in devices and systems that contain and / or use data and software, with catastrophic consequences. Insider intellectual property theft, reverse engineering, and espionage lead to billions of dollars in lost return on investment and reduced competitiveness annually. To execute digital transformation, global markets and governments will need to apply digital engineering that relies heavily on data and software integrity.

[0004] As mentioned in this article, Digital Field of View (DFoV) refers to the process used to employ continuous digital engineering data / software integrity verification across the entire range of data and software applications. Maintaining integrity in DFoV is challenging for the following reasons:

[0005] 1. A central authority may not be feasible.

[0006] 2. The digital environment is dynamic and constantly changing.

[0007] 3. The environment must maintain interoperability and backward compatibility.

[0008] 4.DFoV may include proprietary commercial software or service elements.

[0009] 5. It is expensive to verify that elements (including open source) are trustworthy.

[0010] Companies are reluctant to subject their supplied hardware and software to independent validation testing because this exposes their critical IP to the risk of theft, malware insertion, or reverse engineering. These and other challenges are slowing progress in digital transformation.

[0011] As data sets grow larger, new approaches are needed to securely manage digital configurations. Digital configurations must allow for verification of the DFoV while accounting for necessary and ongoing changes within the DFoV. The DFoV will change due to updates to software versions, the addition or removal of elements, patches, etc. While traditional methods of cryptographic authentication are fundamental to data verification at the application module level, the use of hash functions becomes unreliable as the DFoV grows larger and more modules are incorporated because some changes will occur before the means to verify them exist due to propagation delays in the corresponding hash digest values. Furthermore, despite cryptographic practices, insider threats to data or software code corruption remain difficult to track. Failure to parse items will result in denial of service and failure of the entire system. A solution to achieve digital transformation is needed. Summary of the Invention

[0012] A method for determining whether data on a device has changed from an original version of the data ("original data") is provided. The method includes: converting the data into a first three-dimensional (3D) spatial representation of the data, wherein the first 3D spatial representation uses positions of points and / or spaces in the first 3D spatial representation to represent multiple characteristics of the data; wherein converting the data into the first 3D spatial representation includes converting the data using the same process used to generate a second 3D spatial representation from the original data; analyzing the first 3D spatial representation using one or more spatial processes; and determining whether the data has changed based on the analysis of the first 3D spatial representation. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Understanding that the drawings depict only some embodiments and are therefore not to be considered limiting in scope, exemplary embodiments will be described with additional specificity and detail using the accompanying drawings, in which:

[0014] Figure 1 is a flow chart of an example method for protecting data;

[0015] Figure 2 It is a flowchart for converting data into watermarked mutant images;

[0016] Figure 2A is an illustration of example data to be protected;

[0017] Figure 2B yes Figure 2A Illustration of example watermarking of the data shown in;

[0018] Figure 2C It is from Figure 2A Illustration of example watermarked mutated data generated from the data shown in ;

[0019] Figure 3is a flow chart of an example method for data validation;

[0020] Figure 4 is a flow chart of another example method of data validation;

[0021] Figure 5A It comes from Figure 2A An example of the data shown in FIG is a randomly distributed pixelated image;

[0022] Figure 5B is an illustration of an example 3D variation image derived from the data;

[0023] Figures 5C to 5D is a graphical representation of an example probability distribution derived from the data;

[0024] Figure 6 is a flow chart of an example method for validating and sharing view information;

[0025] Figure 7A is an illustration of a common digital field of view;

[0026] Figure 7B is a graphic representation of several digital fields of view for different institutions; and

[0027] Figure 8 is a block diagram of an example system.

[0028] Figure 9 is a block diagram of a system for providing data integrity verification for a design environment using a digital field of view according to one embodiment of the present invention.

[0029] According to common practice, the various features described are not necessarily drawn to scale, the emphasis instead being placed on specific features relevant to the example embodiments. DETAILED DESCRIPTION

[0030] In the following detailed description, reference is made to the accompanying drawings, which form a part thereof, and in which specific illustrative embodiments are shown by way of illustration. However, it should be understood that other embodiments may be utilized, and that logical, mechanical, and electrical changes may be made. Furthermore, the methods presented in the drawings and the specification should not be construed as limiting the order in which the various steps may be performed. Therefore, the following detailed description should not be taken in a limiting sense.

[0031] Data protection through randomized spatial imaging

[0032] The global market is undergoing a digital transformation, with high-performance computing, communications, and software technologies as key enablers of autonomous, intelligent command and control for new business and infrastructure applications. Data and software integrity continue to face attacks from hackers and insiders. Software and data corruption leads to high vulnerability in devices and systems that contain and / or use data and software, with catastrophic consequences. Insider intellectual property theft, reverse engineering, and espionage lead to billions of dollars in lost return on investment and reduced competitiveness annually. To execute digital transformation, global markets and governments will need to apply digital engineering that relies heavily on data and software integrity.

[0033] Traditionally, data undergoes multiple processes before being stored in a data file. For example, symmetric and / or asymmetric hashing tools are used to encrypt data files before they are stored or transmitted. However, if a malicious actor were to gain access to a data file (e.g., employed by the company that generated the data file), that person could decrypt the data file and obtain the original data. If this were to occur, that person could alter the data, rehash it, and encrypt it with a timestamp that conceals the modifications. In these cases, when the corrupted data file is used and distributed, it would appear to be a legitimate data file with legitimate encryption. Current data integrity techniques are unable to detect this type of corrupted data file.

[0034] Companies are reluctant to subject their supplied hardware and software to independent validation testing because this puts their critical intellectual property (IP) at risk of theft, malware insertion, or reverse engineering. These and other challenges are slowing progress in digital transformation.

[0035] An example technique for protecting data described herein ensures data integrity by converting the data into a three-dimensional (3D) variant image and analyzing the 3D variant image. The 3D variant image includes randomly distributed pixels and spaces that can be analyzed and used for data verification to ensure that the received data has not been altered from the original version. Some of the randomly distributed pixels may include watermarks that are used to identify strategically important or exploitable data that may be targeted by malicious actors.

[0036] Figure 1 A flow chart of an example method 100 for protecting data is shown. Figure 1 In the examples described, data can include any data that could be a target of an insider threat. For example, data can include, but is not limited to, software code, tools, images, drawings, digitized data, and / or text. Typically, software code is created using a text editor or visual programming tool.

[0037] Method 100 includes converting data into a watermarked mutated image (block 102). The conversion includes adding strategically placed watermarks of one or more types to the original data to be protected, mutating the watermarked data, and converting the watermarked mutated data into an image (watermarked mutated image). In other examples, the conversion includes converting the watermarked data into an image and mutating the watermarked image to generate a watermarked mutated image. In some examples, mutating the data or image includes applying a mutation function to the data or image. In some examples, using a PUF value and / or a TRN to disrupt traditional mutation conditions for the data provides further protection against potential brute force reconstruction of the mutated image by bad actors.

[0038] Figure 2 is a flow chart of an example method 200 for converting data into a watermarked variant image. For ease of explanation, Figure 2 The blocks of the flowchart in FIG. 2 have been arranged in a generally sequential manner; however, it should be understood that this arrangement is merely exemplary, and it should be recognized that the method 200 (and Figure 2 The processing associated with the blocks (shown in FIG. 204 ) may be performed in a different order (or with at least some of the processing associated with the blocks performed in parallel in an event-driven manner). For example, the watermarked data may be converted to an image (block 206) before the mutation function is applied (block 204).

[0039] Method 200 includes watermarking data (block 202). The data is watermarked using one or more different types of watermarks (e.g., watermarks of different colors). In some examples, different types of watermarks are used to mark different characteristics of the data. For example, if the data is software code, a first type of watermark may be used to identify lines of code that are easily exploited, a second type of watermark may be used to identify lines of code that are easily obfuscated, and a third type of watermark may be used to identify lines of code that would cause the most damage if modified. Other selection criteria for watermarking may also be used. Generally speaking, one or more different types of watermarks are strategically placed to enhance the traceability of key characteristics of the data to be tracked for data verification purposes. Figures 2A to 2B An example of the original code and the code after watermarking is shown in . Figure 2B In the example shown, different watermarks are shown as different colors (as identified by a color legend).

[0040] In some examples, watermarking of data is performed automatically using an algorithm. In other examples, watermarking of data is performed manually, which can be less predictable and more random. This will typically be performed by a known individual, one or the only individual from a community of exclusive individuals with access to the data. In some examples, watermarking is performed very close to the time the data is converted into an image. Additional safeguards regarding the individual or algorithm used to watermark the data may also be employed.

[0041] Method 200 includes applying a mutation function (block 204). In some examples, applying the mutation function includes converting the watermarked data into an unattributable object / feature. In some examples, applying the mutation function includes using pseudorandom numbers or using a PUF and / or a TRNG. In some examples, the mutation function is applied to the watermarked data to generate the object / feature. Other techniques may also be used, as long as such processing generates an object / feature that cannot be attributed to the original data. However, the watermark is retained in the unattributable object / feature. Figure 2C Examples of mutated watermarked codes are shown in (the color of the watermark is identified in the included legend).

[0042] Method 200 also includes converting to an image (box 206). The specific mechanism used to convert to an image depends on the specific form of the data being converted. For example, if the data to be protected is Python code, some example steps for converting the Python code to an image may include: installing Aspose.Words for Python via .NET, adding a library reference to the Python project, opening the source text file in Python, calling the "save()" method and passing in the output file name with an image extension, and obtaining the result of converting the text to an image. Techniques known in the art for converting other types of data to images can be used for those corresponding types of data. In some examples, the resolution of the image can be selected based on the amount of content to be inspected, cost, and time considerations.

[0043] Re-reference Figure 1 The method 100 further includes converting the watermarked variant image into a randomly distributed pixelated image (block 104). The randomly distributed pixelated image is two-dimensional and includes dots (or particles) and voids. In some examples, the watermark will be represented by different colors in the 2D randomly distributed pixelated image. For the purposes of this specification, the colors in the 2D randomly distributed pixelated image are represented by grayscale, with appropriate legends included in the accompanying drawings.

[0044] Example 2D randomly distributed pixelated image in Figure 5A As shown in Figures 2A to 2C The data generation shown in the various stages shown in FIG. 5A to 5DThe use of grayscale with a legend to represent colors is continued in the description. For the purposes of this specification, the points of the 2D randomly distributed pixelated image are randomly distributed in the XZ plane. In some examples, a pseudo-random-based algorithm is used to convert the watermarked variant image into a randomly distributed pixelated image. In some examples, the pseudo-random-based algorithm converts bits into point coordinates in the XZ plane so that the bits of data represented by the watermarked variant image are represented by points in the 2D randomly distributed pixelated image. Example algorithms for this conversion can be found in MINITAB or similar programs. In some examples, the PUF function and / or TRN function of the MEMS device are used in combination with the algorithm to generate the random distribution and pixelation. It should be understood that any technique for converting an image into a randomly distributed pixelated image can be used to convert the watermarked variant image into a randomly distributed pixelated image.

[0045] Method 100 also includes converting the randomly distributed pixelated image into a three-dimensional (3D) variant image (block 106). In some examples, points of the 2D randomly distributed pixelated image are randomly shifted to heights / altitudes on the Y-axis such that the points are distributed in the 3D image. In some examples, a pseudo-random numerical algorithm is used to assign heights / amplitudes to the points of the 2D randomly distributed pixelated image. In other examples, a TRNG function is used to assign heights / amplitudes to the points of the 2D randomly distributed pixelated image. In some such examples, the TRNG utilizes at least one MEMS sensor to provide random numbers for use as the heights / amplitudes of the points. Figure 5B It is shown by Figure 5A Example 3D variant images generated from a 2D randomly distributed pixelated image.

[0046] Method 100 also includes analyzing the 3D variant image to determine the probability of finding points and spaces in the 3D variant image (block 108). In some examples, the analysis includes determining the probability of finding pixels of various levels in the three-dimensional image. Figure 5B Some examples of probability distributions of 3D variant images generated by Figures 5C to 5D Shown at.

[0047] In some examples, a 3D variation image is analyzed using a spatial point process (e.g., a Poisson spatial process). In such examples, the process includes selecting a boundary for analysis, selecting an occupancy pattern and a vacancy pattern, selecting a homogeneous pattern, and selecting a spatial model. In some examples, the spatial model can include a time-based sequence that is uniform over a spherical surface. In other words, a point is created at the center of mass. Example spatial point processes are discussed in detail, for example, in A. Baddeley, "Spatial point processes and their applications," Stochastic Geometry Lecture Notes in Mathematics, Springer-Verlag, Berlin, pp. 1-75, 2007, which is incorporated herein by reference.

[0048] In some examples, the density function used in the spatial point process (e.g., a Poisson spatial process) is determined based on the output of the PUF module. For example, the output of the PUF module is used to modify the density function in the Poisson spatial process. Since each PUF module is unique, using the output of the PUF module will produce a range of different probabilities of finding the points and spaces to be generated.

[0049] In other examples, alternative techniques can be used to analyze the 3D variation image to determine the probability of finding points and voids in the 3D variation image. For example, a high-frequency reflection function can be implemented that reflects in a random pattern from the defined boundary walls. Other techniques for identifying points and voids within the boundary can also be used.

[0050] In some examples, techniques for analyzing 3D variation images apply temporal sequencing of point and void detection as part of the analysis. This allows point and void detection to be performed in a specific order around the analysis space, which can be used for validation, as discussed herein.

[0051] In some examples, the boundaries of the analysis of the 3D variant image are limited to less than the total boundaries of the 3D variant image, which can be beneficial in reducing the time spent performing the analysis and subsequent verification. The boundaries can be strategically defined to include at least some watermarked points so that a significant portion of the data can be verified to be unchanged.

[0052] While the above description of block 108 describes the use of a single spatial point process or alternative technique to determine the probability of finding points and voids, it should be understood that multiple spatial point processes or alternative techniques with different boundaries may be used as part of the analysis. In some examples, the different processes or techniques may be performed in parallel so that the overall time required to obtain probabilities for multiple different boundaries can be reduced.

[0053] Method 100 also includes saving the determined probabilities (block 110). In some examples, the probabilities of finding points and spaces are stored. In some examples, the probabilities of different levels of pixels (e.g., points, watermarked points, spaces) are stored for future use in data verification and can be distributed to various devices in a trusted network.

[0054] Figure 3 3 is a flow chart of an example method 300 for verifying whether data stored on a device has been altered. Method 300 may be performed by a device whenever data is called for use or as a condition of using data to ensure that the data image (and thus the data itself) has not been altered.

[0055] Method 300 includes converting data into a 3D variant image (block 302). Techniques for converting data into a 3D variant image are discussed above with respect to blocks 102, 104, and 106. In some examples, the device generates the 3D variant image using the same process, random numbers, and the like used to create the 3D variant image from the original data. In examples where the device generates the original data, information about the process, random numbers, and the like used to generate the 3D variant image from the original data can be stored in a memory of the device after being generated by the device. In other examples where a different device generates the original data, information about the process, random numbers, and the like used to generate the 3D variant image from the original data can be provided to the device by another entity (e.g., a host device) after performing a verification process, and the device can then store the information in a memory of the device.

[0056] Method 300 also includes analyzing the 3D variation image to generate a first probability (block 304). In some examples, analyzing the 3D variation image according to block 304 is similar to the analysis discussed above with respect to block 108. In examples where the device has analyzed the 3D variation image generated from the raw data, information about the process, density function, etc. used to analyze the 3D variation image from the raw data can be stored in the device's memory after being analyzed by the device. In other examples where a different device has analyzed the 3D variation image generated from the raw data, information about the process, density function, probabilities, etc. used to analyze the 3D variation image from the raw data can be provided to the device by another entity (e.g., a host device) after performing a verification process, and the device can then store the information in the device's memory. Furthermore, the probabilities generated from the analysis are stored in the device and are referred to herein as "stored probabilities."

[0057] Method 300 also includes comparing the first probability to the stored probability (block 306) and determining whether the first probability matches the stored probability (block 308). In some examples, determining whether the first probability matches the stored probability exactly indicates that no changes have been made to the original data. In other examples, determining whether the first probability matches the stored probability by more than a threshold amount allows for small deviations from the original data (e.g., due to processing errors, etc.).

[0058] As discussed above, in some examples, there is a temporal order of point and gap detections that causes point and gap detections to occur in a particular order around the space under analysis. In such examples, determining includes determining whether the temporal order of point and gap detections for the first probability matches the temporal order of point and gap detections for the stored probabilities.

[0059] When it is determined that the first probability matches the stored probability, method 300 continues to verify that the data has not changed (block 310). In some examples, the device continues to use the data as intended in response to the determination that the first probability matches the stored probability. In some examples, a user of the device or a system administrator is notified that the data has not changed.

[0060] When it is determined that the first probability does not match the stored probability, method 300 proceeds to provide a notification that the data has been altered (block 312). It is important to note that the lack of a match may be due to a different location of the point in the spatial representation, additional points not found in the 3D variant image generated from the original data (missing gaps), different characteristics of the points included in the spatial representation, etc. In some examples, a notification is provided to a user of the device. In some examples, a notification is provided to a system administrator. The notification may be auditory, visual, or a combination thereof. It should be understood that any mechanism for providing a notification may be used.

[0061] In some examples, when it is determined that the first probability does not match the stored probability, the data ceases to be used by the device for its intended purpose. For example, if the data includes software code, then in response to a determination that the first probability does not match the stored probability, the software code will not be executed by the device. In some examples, the data may be transmitted to a system administrator or other entity for evaluation and analysis to determine changes made to the original code, who made the changes, etc. In some examples, if watermarked points (having a different color than non-watermarked points in the 3D variant image) are missing or modified, it can be more confident that the change was intentional and malicious, rather than accidental or a malfunction.

[0062] Figure 4 is a flow chart of an example method 400 for verifying whether data received by a device has been altered. Method 400 may be performed by a device whenever data is received from another device or as a condition of using the data to ensure that the data image (and therefore the data itself) has not been altered.

[0063] Method 400 includes receiving data and a first 3D variant image from different devices (block 402). The data and the first 3D variant image can be received from the different devices via wired or wireless communication. In some examples, a master device is configured to collect the complete PUF output of a MEMS module (including, for example, a MEMS-based PUF and a TRNG) in each device in the system that is part of a dedicated user community. In such examples, the master device is configured to generate a first 3D variant image for the data using the PUF output or other characteristics unique to the respective device. When data is transmitted to a particular device, the data is transmitted along with the corresponding 3D variant image. In some examples, the first 3D variant image is associated with the specific device to which the data is transmitted. In other examples, the first 3D variant image is associated with the different device that transmitted the data and can also provide or determine the PUF output for analysis in block 406. For example, the PUF output can be provided or determined during machine-to-machine provenance verification. In some examples, the first 3D variant image and / or the PUF output can be encrypted for the dedicated user community using symmetric and / or asymmetric encryption methods.

[0064] Method 400 also includes converting the received data into a second 3D variant image (block 404). Techniques for converting the data into a 3D variant image are discussed above with respect to blocks 102, 104, and 106. In some examples, the device generates the 3D variant image using the same process, random numbers, and the like used to create the first 3D variant image from the original data. In some examples, information about the process, random numbers, and the like used to generate the first 3D variant image from the original data is also provided to the device by another entity (e.g., a host device) after performing the authentication process, and the device may then store the information in a memory of the device.

[0065] Method 400 also includes analyzing the first 3D variation image to generate a first probability and analyzing the second 3D variation image to generate a second probability (block 406). In some examples, analyzing the first 3D variation image and the second 3D variation image according to block 406 is similar to the analysis discussed above with respect to block 108. The device analyzes the first 3D variation image and the second 3D variation image using the same processing, density function, etc.

[0066] Method 400 also includes comparing the first probability to the second probability (block 408) and determining whether the first probability matches the second probability (block 410). In some examples, determining whether the first probability matches the second probability exactly indicates that no changes have been made to the original data. In other examples, determining whether the first probability matches the second probability by more than a threshold amount allows for small deviations from the original data (e.g., due to processing errors, transmission errors, etc.).

[0067] As discussed above, in some examples, there is a temporal order of point and gap detections that causes the point and gap detections to occur in a particular order around the space under analysis. In such examples, determining includes determining whether the temporal order of point and gap detections for a first probability matches the temporal order of point and gap detections for a second probability.

[0068] When it is determined that the first probability matches the second probability, method 400 continues to verify that the data has not changed (block 412). In some examples, the device continues to use the data as intended in response to the determination that the first probability matches the second probability. In some examples, a user of the device or a system administrator is notified that the data has not changed.

[0069] When it is determined that the first probability does not match the second probability, method 400 continues by providing a notification that the data has been changed (block 414). In some examples, the notification is provided to a user of the device. In some examples, the notification is provided to a system administrator. The notification can be auditory, visual, or a combination thereof. It should be understood that any mechanism for providing notification can be used.

[0070] In some examples, when it is determined that the first probability does not match the second probability, the data ceases to be used by the device for its intended purpose. For example, if the data includes an update to firmware, then in response to a determination that the first probability does not match the second probability, the firmware update will not be implemented by the device. In some examples, the data can be transmitted to a system administrator or other entity for recording, evaluation, and analysis to determine the changes made to the original firmware update, who made the changes, etc. In some examples, if watermarked points (having a different color than non-watermarked points in the 3D variant image) are missing or modified, it can be more confident that the change was intentional and malicious, rather than accidental or a malfunction.

[0071] In some examples, in addition to (or as an alternative to) receiving a first 3D variant image from another device, a device may receive a first probability for the first 3D variant image generated from the original data. In some examples, a master device is configured to collect the complete PUF output of a MEMS module (including, for example, a MEMS-based PUF and a TRNG) in each device of the system that is part of a dedicated user community. In such examples, the master device is configured to use the PUF output to generate a 3D variant image for the data, and to use the PUF output or other characteristics unique to the corresponding device to generate a first probability for each device as part of a density function for analysis. When sending data to a specific device, the data is sent along with the corresponding 3D variant image and / or the corresponding first probability associated with the specific device generated from the original data. In some examples, the first 3D variant image and / or the corresponding first probability may be encrypted for the dedicated user community using symmetric and / or asymmetric encryption methods.

[0072] Although the above Figures 3 and 4 Although described as a method for verifying whether data has been altered, it should be understood that similar techniques can also be used to determine whether data stored on or received by a device is the correct version. For example, corresponding variant 3D images and probabilities for each software version can be generated and used in a manner similar to that described above with respect to Figures 3 and 4 The software version on the device is verified in the manner described. If the probability of the 3D variant image generated from the software on the device does not match the probability of the 3D variant image of the correct software version, it can be determined that the software on the device needs to be updated. In some examples, in response to the mismatch, a notification can be transmitted to the user of the device and / or a system administrator to update the software for the device.

[0073] An example use case for data protection techniques through randomized spatial imaging is for network security, particularly for reducing the burden on analysts assigned to determine anomalies in data, such as, for example, software code, images, etc. It should be understood that the specific data that may be represented using spatial mapping is not limited to the examples described herein and may be applied to a wide variety of additional applications and use cases.

[0074] An example application of the above-described techniques is real-time ballot and voting data integrity. In some examples, images generated by voting machines can be imaged and processed using the above-described methods. This can provide the integrity and provenance of ballots used in elections. Furthermore, this can provide a real-time voting record that does not infringe on voter privacy, but rather tracks any unwanted changes or altered votes from the moment the first vote is cast to the moment the full election results are archived. In some examples, the system is configured to immediately track when and where the record has been altered via watermarking, allowing forensics to be applied with high integrity.

[0075] Another example application of the above technology is in medical applications, particularly for mapping the brain. In some examples, an initial high-resolution atlas mapping distribution can be generated, and the above imaging and analysis techniques can be applied. Patients can be tested for various activities in brain regions that may have problems (inflammation, weak blood vessels, thermal dead zones, etc.). Real-time analysis of millions of brain cells can be characterized by very short interleaved assessments, enabling analysis at a level that has not been achieved to date.

[0076] Another example application of this technology is high-density aircraft traffic management. High-resolution, real-time analysis of hundreds of thousands of aircraft (commuter, cargo transport at ports of entry, etc.) is possible, as is high-risk management of the impending high-density commuter air traffic and the distribution of goods and services in port areas. The specialized expertise required for these new and emerging transportation systems is achieved through the use of real-time, frame-by-frame imaging and the application of the aforementioned process.

[0077] Another example application of the above technology is the management and analysis of global financial transactions. Managing all electronic transactions in global financial markets (over $1.4 trillion annually) could be a devastating deterrent to corruption. With complete protection of customer identities, AI could be used to monitor trillions of dollars in daily transactions to identify significant anomalies that require further investigation (for example, preventing the majority of the $283 million in daily losses from electronic fraud). By using instant, frame-by-frame imaging and applying the above process, both expertise and privacy / IP protection can be achieved.

[0078] Other example applications of the techniques described herein may include management of power grid networks (e.g., restoring the last known good balance between transfer stations), food and water resources, supply chains, corporate inventories, U.S. Securities and Exchange Commission (SEC) fairness, and the like.

[0079] While specific use cases and example applications are discussed above, it should be understood that the techniques described above are not limited to the examples described herein and are applicable to a wide variety of additional applications and use cases.

[0080] By using the above-described techniques for randomized spatial imaging and analysis, it is possible to efficiently verify whether data has been altered from the original. These techniques can also enable the detection of specific changes (even if subtle) by using strategic watermarks that identify particularly important or vulnerable portions of the data. The above-described techniques can benefit the global microelectronics and software companies, EDA tool vendors, digital engineering reference architectures, and the overall digital transformation sector.

[0081] By leveraging 3D variant images and probabilistic analysis, the techniques described herein can perform data integrity verification in a manner that is more efficient in terms of execution time, storage requirements, and power requirements compared to previous techniques. The techniques described herein can be used to verify terabytes of data (including software code, images, algorithms, etc.) in an accelerated manner that enables 24 / 7 monitoring and data integrity verification, which was not possible using previous techniques due to the required time, storage, and power requirements.

[0082] Digital Field of View

[0083] Current encryption processes rely on basic building block algorithms that are called upon by operating modes and higher-level processing to address an ever-changing number of unique applications. Prior art encryption methods provide a means of converting digital data between understandable plaintext and incomprehensible cryptographic forms as a means of maintaining data confidentiality and integrity, verifying the authenticity of data, and provide for the use of collision-free one-way functions, such as hash algorithms that use digital data as input and provide an exact number for the data. Collision-free means that no two files give the same number. An example application of a hash function is as follows: If a file (digital file image) is digitally signed, the digital bytes are run through a hash process to generate a hash digest value from the message to be protected. The image is then verified by repeating the hash process and comparing it with the expected hash digest value. An example hash function is the Secure Hash Algorithm (SHA).

[0084] In order to maintain integrity, the party performing the authentication must be able to independently verify the hash digest value. That is, without access to the hash value via a trusted source, the authenticating party will not guarantee that the file is authentic, because the security premise is only that the hash routine can be repeated and compared with the hash digest. The hash-based message authentication code (HMAC) algorithm uses a hash function and a secret variable to verify the integrity and authenticity of the data file. The use of HMAC must work in conjunction with a means of securely sharing secret variables. The exchange of secret variables is typically performed using asymmetric encryption using digital certificates to securely share secret variables between the parties.

[0085] While digital encryption processes are effective for maintaining the integrity and confidentiality of documents, the scale of digital transformation creates additional challenges that cannot be addressed by existing methods alone. In particular, as datasets become larger and larger, new approaches are needed to securely manage digital configurations. Furthermore, maintaining integrity in digital environments is challenging for several reasons, including: a central authority may not be feasible; digital environments are dynamic and constantly changing; environments must maintain interoperability and backward compatibility; digital environments may include proprietary commercial software or service elements; and even in the case of open source, it is costly to verify that the elements are trusted in the first place, and someone must ensure that the open source is free from security threats.

[0086] While traditional methods of cryptographic authentication are fundamental to data verification at the application module level, the use of hash functions becomes unreliable as the amount of information becomes larger and more modules are incorporated because: some changes will occur before the means to verify them (e.g., due to propagation delays in the corresponding hash digest values). Failure to parse an item can result in a denial of service failure for the entire system. The digital environment will change frequently due to updates to software versions, the addition or removal of elements, patches, etc. Methods are needed to manage the ever-increasing amounts of data that are crucial to digital transformation.

[0087] The examples described herein include techniques for organizing and managing large data sets while maintaining data integrity. In particular, the techniques described herein use a spatial representation of data and relationships (referred to herein as a "digital view") to provide an efficient framework for real-time data and asset integrity verification management without sacrificing quality of service. The techniques described herein allow for verification of the digital view while taking into account necessary and ongoing changes within the digital view. The digital view representation can represent data, devices, assets, etc. in a manner that allows the information to be organized, retrievable, and detectable. There is no limit to the type of data that can be spatially represented, analyzed, and managed. The techniques described herein can be used to group, track, and manage large amounts of information while also making it intuitive to analyze. In other words, the techniques described herein enable integrity to be maintained like current encryption techniques, but provide the flexibility needed to manage and analyze larger data sets that current methods do not provide.

[0088] Figure 6 is a flow chart of an example method 600 for verifying and sharing view information for devices in a system. For ease of explanation, Figure 6 The blocks of the flowchart in FIG. 6 have been arranged in a generally sequential manner; however, it should be understood that this arrangement is merely exemplary, and it should be recognized that there are many other methods that may be used in conjunction with method 600 (and Figure 6 The processing associated with the blocks (shown in FIG. 1 ) may be performed in a different order (or with at least some of the processing associated with the blocks performed in parallel in an event-driven manner).

[0089] Method 600 includes validating software and hardware instances (block 602). In some examples, validating the software and hardware instances includes using current techniques. In other examples, the techniques described above for random spatial imaging and analysis can be used to validate the software and hardware instances. A combination of techniques can also be used for a subset of devices.

[0090] Method 600 also includes obtaining a device identifier (block 604). In some examples, obtaining the device identifier includes using a PUF. In some examples, obtaining the device identifier includes using software. In some examples, obtaining the device identifier includes using hardware. In some examples, obtaining the device identifier includes using a hash token. In some examples, obtaining the device identifier includes using version information. Combinations of techniques may also be used for subsets of devices.

[0091] Method 600 also includes generating a spatial representation of the local digital field of view using the confidential variables (block 606). In some examples, generating the spatial representation of the local digital field of view includes generating a spatial representation similar to Figure 7A3D representations of the various views shown in . In other examples, because the spatial representation of the local digital field of view is virtual, the representation can be generated in higher dimensions than 3D (e.g., 4D, 5D, or higher) depending on the resolution and information desired by the application. Local digital field of view ( Figure 7A Vision in Figure 1 ,See Figure 2 ,See Figure 3 )yes Figure 7B . In some examples, the local digital field of view is generated by a single device and provides information related to the device itself and its nearest neighbors or one or more digital landmarks defined in the digital universal field of view. In some examples, the local digital field of view is generated by an agency or entity that receives information about a subset (less than all) of the devices, assets, etc. of the digital environment. In some examples, a secret variable (e.g., the output of a local PUF module generated by the device or entity) is used to generate the spatial representation.

[0092] In some examples, generating a spatial representation of the local digital field of view using the confidential variables further includes analyzing the data using a spatial point process or similar process to provide probabilities of finding points and voids in the 3D representation. This process can be similar to the process described above with respect to blocks 308 and 406. This process can create an abstraction layer that can be used to efficiently form a persistent "blurred" digital field of view representation (similar to Figures 5C to 5D ). Unlike hash values, fuzzy digital field representations can tolerate changes and can then be used by intelligent algorithms trained or programmed to detect anomalies. In some examples, the data verification information description is organized in the form of a special point process map that can be used to represent details such as asset types and correspondences as a spatial map.

[0093] Method 600 also includes generating a spatial representation of the external digital field of view using external confidential variables from one or more external parties (block 608). In some examples, generating the spatial representation of the external digital field of view is similar to the method discussed above with respect to block 606, but the confidential variables used to generate the spatial representation are provided by one or more external parties rather than the device itself.

[0094] The method 600 also includes deriving a local digital field of view based on the local secret variable (block 610). The local secret variable is kept confidential by the device or entity. In some examples, cryptographic techniques such as checksums or hashes can be used to facilitate the exchange of the local digital field of view.

[0095] The method 600 also includes deriving an external digital field of view based on the external confidential variables (block 612). The external confidential variables are provided to a device or entity so that the external confidential variables are known to multiple devices and can be kept confidential between the devices. In some examples, cryptographic techniques such as checksums or hashes can be used to facilitate the exchange of the external digital field of view.

[0096] The method 600 also includes generating a global field of view (block 614). In some examples, the external party is configured to aggregate the local (and external) digital fields of view and combine them into a global field of view similar to Figure 7B In some examples, the external party is configured to combine the local (and external) digital fields of view using digital markers so that the digital fields of view can be oriented on the same axis.

[0097] Method 600 also includes importing the global digital field of view (block 616). In some examples, the external party is configured to output the global (universal) digital field of view to one or more devices in the system so that the devices can access a larger digital field of view on an as-needed basis.

[0098] As mentioned above, 7A to 7B A diagram showing an example digital field of view is shown. In particular, Figure 7A is a graphic representation of several digital fields of view for different institutions, and Figure 7B A graphical representation of a general digital view. Spatial representations provide an efficient means of representing and organizing many objects and giving them meaning. These views can be used to represent a wide variety of different data as spatial maps.

[0099] An example use case for a digital field of view is where a view is used to represent battlefield assets. In such an example, the position of a point on the X-axis, Y-axis, and Z-axis can be used to represent different characteristics of the represented battlefield asset. In some examples, the color of the point, the size of the point, etc. can also be used to convey further characteristics of the asset in the battlefield. In one example, the position of a point on the X-axis and Y-axis can be used to represent the latitude and longitude of the asset in the battlefield, and the position of the position on the Z-axis can be used to represent the type of asset, so that all assets of a particular type are in the same range on the Z-axis. It should be understood that other characteristics of battlefield assets can also be represented using digital fields of view other than the above-mentioned digital fields of view, and specific characteristics can be selected as desired for a particular application.

[0100] Another example use case of a digital field of view is where a view is used to represent equipment at a company. In such an example, the position of a point on the X-axis, Y-axis, and Z-axis can be used to represent different characteristics of the represented equipment. In some examples, the color of the point, the size of the point, etc. can also be used to convey further characteristics of the equipment. In one example, the position of the point on the X-axis can represent the age of the equipment, the position of the point on the Y-axis can represent the version of the software currently installed on the equipment, and the position of the point on the Z-axis can represent the location of the equipment (e.g., building number). It should be understood that other characteristics of the equipment in a company can also be represented using digital fields of view other than those described above, and specific characteristics can be selected as desired for a particular application.

[0101] Another example use case for a digital field of view is where a view is used to represent and track an aircraft. In such an example, the position of a point on the X-axis, Y-axis, and Z-axis can be used to represent different characteristics of the represented aircraft. In some examples, the color of the point, the size of the point, etc. can also be used to convey further characteristics of the aircraft. In one example, the position of a point on the X-axis can represent the fuel level of the aircraft, the position of a point on the Y-axis can represent the flight length, and the position of a point on the Z-axis can represent the altitude of the aircraft. It should be understood that other characteristics of the aircraft can also be represented using digital fields of view other than those described above, and specific characteristics can be selected as desired for a particular application.

[0102] Another example use case for a digital field of view is where a view is used to represent and analyze surveillance and / or security data. In such an example, the location of a point can be used to represent different characteristics of a feature in an image captured using a security camera, satellite, or the like. For example, the location of a point can be used to represent the physical location of the feature as well as identifying information about the feature (e.g., the type of feature, threat level, etc.). It should be understood that other characteristics of a feature can also be represented using digital fields of view other than those described above, and that specific characteristics can be selected as desired for a particular application.

[0103] It should be understood that the specific data that may be represented using spatial mapping is not limited to the examples described herein and may be applicable to a wide variety of additional applications and use cases.

[0104] Figure 8 is a block diagram of an example system that includes five devices. Figure 8 In the example shown in FIG, device 1 is associated with and communicatively coupled to four other devices. Figure 8 In the example shown in FIG, five devices are shown, but it should be understood that any number of devices may be included in the system.

[0105] exist Figure 8In the example shown in , each device is configured to use a cryptographic authentication instance to authenticate content or data on the device. Figure 8 Each device in the example shown in FIG is configured to create a trusted exchange. In some examples, each respective device is configured to create a digital field of view that centers the device, for example, via a digital field of view management function. In such examples, the device is configured to use its digital field of view to verify the health and integrity of its environment.

[0106] In some examples, the digital field of view management functionality is deployed as a module on the device. In some examples, the digital field of view management functionality is a software application whose operations are virtualized to the extent that it is hardware-independent and can be applied to existing hardware and software platforms. The specific hardware and software of the device can depend on the desired application and role of the device in the system.

[0107] If possible, it is desirable to avoid over-installing features on a device. In some examples, the digital view management functionality is deployed as a lightweight core application (e.g., targeted to the device's specific operating system), and the digital view management functionality is configured to determine whether further add-ons are required for a particular device. In some examples, the digital view management functionality is configured to query the environment or network to determine the type of platform (hardware and / or software) included in the device. Based on the type of platform, network, and / or role of the device, the digital view management functionality is configured to download additional features to size the application for the specific device. In some examples, the query is performed in a manner that is transparent to the user.

[0108] In some examples, before the digital view management function is queried and downloaded (or even before the digital view management function itself is installed), one or more authentication processes are performed to verify the credentials of the user or device. The one or more authentication processes may include, but are not limited to, a registration process, logging in using an account profile, entering predefined credentials, entering identification information, providing appropriate PUF output and / or TRNG output, and / or a trusted platform module process.

[0109] In some examples, the installation of the digital field of view management functionality is performed within a high-value or high-level network (e.g., at a headquarters) where the installation of the digital field of view management functionality is performed. In some such examples, other devices or systems (including adjacent devices) may be used to perform further verification. In some examples, further verification includes communicating with the nearest neighbor via Bluetooth or other distance-limited technology, querying the round-trip delay, and verifying the device location based on the round-trip delay. In some examples, further verification includes attempting to communicate with the nearest neighbor via Bluetooth or other distance-limited technology, and verifying that the device is not in close proximity to the nearest neighbor based on the lack of response. In some examples, further verification may include physical contact with the device to verify the device and the user. It should be understood that other additional verification techniques may be used in addition to or in lieu of the above-described techniques.

[0110] In some examples, after installation and authentication of the user / device, the system is configured to provide device-specific rules, boundaries, and behaviors based on the type of platform (or resource) and the role of the device in the system or network. For example, rules, boundaries, and behaviors may include rules about where the device is allowed to go, what the device is to do in the event of a failure or a detected nearest neighbor problem, how to detect status, etc. In some examples, the rules are periodically distributed and updated by at least one organization responsible for the digital field of view utilized by the system. In some examples, different groups / organizations responsible for the digital field of view each provide different rules, boundaries, and behaviors to the devices in the system within the authority of these groups / organizations. In some examples, the rules, boundaries, and / or behaviors of a particular organization can change periodically. For example, the synchronization and timing of communications, the sequence of communications, and / or time-based or event-based behaviors can be periodically modified.

[0111] Using defined rules, boundaries, and behaviors can help the system quickly identify anomalies, safety issues, security concerns, and more by making it easy to identify devices operating in an unauthorized manner. If a device does not follow rules, stay within boundaries, or perform expected behaviors, this can indicate an issue with the device that requires further investigation. If anomalous activity is detected, notifications can be provided to system administrators or other entities for further investigation. For safety and security issues, the detection of anomalies or certain types of violations for specific classes or types of devices can be reported to regulators or law enforcement.

[0112] A shared common digital field of view can be spatially represented, allowing for the formation of composite views encompassing more devices at a higher level. In some examples, to generate the common digital field of view, devices are configured to provide their local field of view information to a central device (e.g., a hub or device 1), which compiles the digital field of view information and combines it into the common digital field of view.

[0113] In some examples, virtual markers are included in the digital field of view to enable the device to orient itself within the environment represented by the common digital field of view. In such examples, the central device can use the virtual markers to help combine digital field of view information from each device in the system.

[0114] In some examples, digital fields of view generated by different organizations can be securely shared and compared with each other to facilitate verification and / or validation of data in the digital fields of view or changes in the digital fields of view. In some examples, different organizations can utilize different types of digital fields of view. For example, the digital fields of view can have different resolutions (3D vs. 4D), different organizations of data, different parameters captured in the digital fields of view, etc. In order for the global network to operate effectively, interoperability between different digital fields of view is required. In some examples, boundaries can be used to define where specific rules and behaviors apply. Central network devices or network centers can be located between organizations or at boundaries and facilitate the secure exchange of digital fields of view and the conversion of digital fields of view across boundaries to accommodate heterogeneous devices, rules, and behaviors of different organizations.

[0115] In some examples, a central network device can be used to match parameters in digital fields of view that organize data differently. The central network device can shift or transform the organization of data from one digital field of view so that it matches the organization of data from another digital field of view. An example of this might be organizing height on the X-axis in one digital field of view and on the Y-axis in another digital field of view.

[0116] In some examples, the central network device may convert a higher-resolution digital field of view to a lower-resolution digital field of view. For example, if a first digital field of view captures data in four or five dimensions, but a second digital field of view captures data in three dimensions, the central network device may convert the first digital field of view to have the lower resolution.

[0117] In some examples, a central network device can use data from multiple digital fields of view to virtually recreate a global (or combined) digital field of view for a device. In such examples, a subset of the data for the global (or combined) digital field of view can be provided by the device (and the mechanism that provides the device with its rules, boundaries, and behavior), and the remainder of the data can be simulated in the digital field of view by the central network device. For example, the global digital field of view may show data for tracking ten assets, but the device (and its mechanism) directly tracks five assets, with the other five assets being tracked via network virtualization using data from other digital fields of view.

[0118] In some examples, when the data set is large enough, it may be difficult and time-consuming to verify and confirm all changes to data points and spaces. To improve efficiency and save resources, differences and inconsistencies between different digital fields of view can be used to focus efforts to further verify and confirm technology (e.g., using traditional technology) to determine which data is correct. For example, if two digital fields of view are compared and there are differences between the characteristics of the same point of a device represented in the different digital fields of view, the system can identify the differences and trigger a more thorough investigation of the device status. In some examples, the presence of differences in the characteristics of the same point can indicate a potential anomaly or problem with the device. In some examples, when the mechanism of the digital fields of view is trusted, changes that are consistent across multiple digital fields of view can be assumed to be valid.

[0119] Figure 8 An example application of the system shown in [1] can be used for economic analysis. For digital currencies (or fiat currencies), global information is used to calculate relative exchange rates, which can change rapidly depending on the environment. In some cases, significant changes may occur, and if actors are made aware of these changes in a timely manner, their behavior may change accordingly. For example, a buyer may not proceed with a purchase due to a change in the exchange rate, or a company may not place an order. Early warning of such changes can be invaluable in such a flexible environment.

[0120] In some examples, the techniques described herein can be used to generate digital views to represent different characteristics of financial conditions, exchange rates, currency rates, economic data, etc. Each institution of the different digital views can be, for example, a different official publication or verified source of economic information, and a verified community of users / devices can be established to securely share economic data captured in the different digital views.

[0121] In some examples, one or more devices in the system include functionality configured to estimate relative exchange rates (or changes in relative exchange rates) based on economic data in the digital field of view. Since data can be quickly distributed and analyzed using the techniques described herein, devices in the system can obtain independent economic data and predict changes in exchange rates, interest rates, and the like based on authenticated data provided in an exclusive user community. This information can be disseminated to devices (e.g., applications operating on cellular phones) and used or reviewed by any device in the system. This type of system is particularly beneficial for point of sale and decision maker reference.

[0122] Figure 8 Another example application of the system shown in

[0014] can be for digital voting. With current voting systems, vote counts can be difficult to verify due to human error, and verification requires a recount of the ballots. With current electronic voting systems, there are concerns about verifying information because the source of the data is not always available.

[0123] In some examples, the techniques described herein can be used to generate digital fields of view to represent votes at various levels of granularity. Each institution used for a different digital field of view can be, for example, a different level of election (e.g., a precinct, region, county, state, country), a different political party, etc. In such examples, each voter is digitally authenticated or verified before being able to cast a vote, and the voting information is retained in the data captured in the digital field of view.

[0124] In some examples, voting systems utilizing digital fields of view can provide tools for independent verification by any device in the user community, eliminating the need for manual recounting of ballots. All data can be obtained through the digital fields of view to tally votes, confirm the absence of voter fraud, and verify the identity of individuals who cast their ballots. If discrepancies are detected between different digital fields of view, this can provide a means to focus resources for further verification and investigation.

[0125] Use Case: Digital Viewfield Applied to Design Environments

[0126] DFoV is a technology used to protect integrated circuit (IC) supply chain objectives (such as microelectronic lifecycle data at rest or in transit, software code, and other early design phase artifacts) and monitor the design environment without interfering with development team activities. To combat persistent threats, including insider threats, the system must continuously monitor changes and identify them. DFoV system implementations detect and monitor changes to design flow artifacts, watermark the material, and develop statistical representations that can be used to evaluate changes and calculate the probability that a given change is malicious. Leveraging autonomy, DFoV system implementations provide a means to transparently track changes as designers and tools generate artifacts, as well as the ability to create remote backups and recreate designs in a remote trusted environment. Design reconstruction in a remote trusted environment provides a means to a) prevent data loss, b) enable design recovery, and c) perform trusted offline independent verification. When linked together to ensure DFoV-compliant connectivity across multiple development parties, it can be used to confirm integrity across the entire development supply chain. DFoV controls third-party inputs through software-implemented controls and verification requirements to control inputs and ensure that intellectual property (IP) introduced into the environment has been independently verified or authenticated by authorized or trusted sources.

[0127] Figure 9is a block diagram of a system 900 that uses a digital field of view (DFoV) to provide data integrity verification for a design environment 902 according to one embodiment of the present invention. In one embodiment, the design environment 902 includes functionality (as described below) that enables a user to design and program a field programmable gate array (FPGA). It should be understood that the use of DFoV in this embodiment to provide data integrity verification for the design environment of the FPGA is provided as an example and not as an implementation. In other embodiments, DFoV can be used to provide data integrity verification for other data that may be subject to insider threats, for example, software code, tools (such as visual programming tools), computer-aided drafting and computer-aided design and drafting (CADD) tools, images (such as images of digitized output from sensors), digitized drawings, digitized data, and text.

[0128] In this embodiment, DFoV has been developed to autonomously establish real-time assessments of digital design achievements and communicate real-time status to a trusted source. DFoV has particular application in evidence-based assurance objectives by providing a quantitative, relevant scoring tool for key achievements produced throughout the design phase of the software, firmware, and microelectronics lifecycle.

[0129] For the purposes of this application, the term "product" as applied to the digital landscape means any data that exists in a static or transmitted state and is associated with a device at a selected point in time. Furthermore, in the context of a design environment, "design product" means any data that exists in a static or transmitted state and is input to, output from, or generated by the design environment at any time during the design process. From a design perspective, "data" includes:

[0130] 1. Content produced at all levels of system design requirements (operational, functional, and architectural), for example, image-based representations of the concept of operations that explain how the system will work and what the system will provide, software system requirements, information technology drawings, etc.

[0131] 2. All forms of software code, application code, configuration management code, and related software expertise / security applications.

[0132] 3. All expected edge sensing data collected for the design of the virtual model in the digital twin. This also includes the test design and the design of the physical part of the digital twin with all code.

[0133] 4. All computer-aided design input, intermediate, or output files used in the design process, including trade-off analysis reports, requirements, source code, source code listings, object code listings, schematics, design specifications, algorithms, procedures, flow charts, formulas, etc.

[0134] 5. A collection of data recorded in a form that can be processed by a computer (a computer database).

[0135] 6. Recorded information of a scientific or technical nature (technical data), regardless of the form or method of recording.

[0136] This data definition also applies to the section above under the heading "Data protection through randomized spatial imaging".

[0137] In an embodiment of system 900, DFoV is achieved through enhanced privileged resources 904. In one embodiment, enhanced privileged resources 904 are software functions running on a computing platform such as a computer, server, etc. Enhanced privileged resources 904 include the following functions:

[0138] 1. Region of Interest (ROI) filter 906, which selects the area, folder, file, user changes, etc. of the design work to be monitored,

[0139] 2. Cryptographic functions 908, which perform tasks such as hashing file and folder contents, encrypting, decrypting, and authenticating key processes, and compressing selected artifacts for archiving and remote verification,

[0140] 3. Change management function 910, which uses file information and hash tags to generate a statistical representation highlighting the changed areas in the design work, and based on the context to mark the threat probability and provide a timeline record,

[0141] 4. Physical Unclonable Function 912 (PUF 912) provides authentication to establish and maintain the identity of the physical location of the design environment.

[0142] In other embodiments, elevated privileged resources 904 also includes a module that implements a threat score, which can be implemented as part of change management function 910. Threat scoring uses statistical representations to detect the probability that an observed change is a legitimate, non-malicious change.

[0143] Embodiments of the system 900 can be implemented on commercial computer hardware. The system 900 is capable of autonomously tracking changes to the design environment throughout the design cycle without requiring input from the design team. The system 900 is adapted to select and monitor specific file directories and files within a development flow, and securely send changes and allow the entire design flow to be remotely rebuilt on a remote trusted system (such as a remote PC 934). The system 900 employs hashing techniques combined with techniques for mapping sets of hashed data into statistical representations that allow high-level identification of system changes and rules that can use such representations to automatically detect anomalies.

[0144] System 900 includes a design environment 902, which in one embodiment is a design environment for an FPGA, where code is written for the programmable device. In other embodiments, design environment 902 is implemented in other tool environments such as an application-specific integrated circuit (ASIC) or a software development tool flow. Design environment 902 includes external input sources. Insiders can use these external inputs to introduce threats into the FPGA design. To combat this, an enhanced privileged resource 904 verifies all external inputs before they are imported into design environment 902.

[0145] exist Figure 9 In the embodiment shown in FIG, the design environment 902 receives two external inputs. First, the design environment 902 receives external design input (with hashes and checksums) from a third party at external design input 914. This can include third-party IP. In addition, the design environment 902 can import updates to tools and verification data for tools 916 (including, for example, licenses, tool versions, and installations) for use by users (designers) of the design environment 902. In addition, when a designer provides input to the tool 916, such as a configuration file, input design file, etc., the tool 916 creates design tool data 918. The tool 916 then processes the input and creates a database and other outputs necessary for the design. In addition to external input, the design environment 902 also allows for local design input 917, such as work products of users of the design environment 902. Each of these inputs (external and internal) provides a basis for design achievements that can be tracked by the system 900.

[0146] As described above, the elevated privilege resources 904 validate all external design inputs before they are entered into the design environment 902. Specifically, the elevated privilege resources 904 include a file validation function 920 that provides data integrity verification, e.g., verifying that a file is from a trusted source and will not introduce any threats into the FPGA design. In one embodiment of the elevated privilege resources 904, the file validation function 920 operates under user control of parties with elevated privileges to set parameters for what external inputs are allowed into the design environment 902. Designers operate in the design environment 902, and users with elevated privileges operate in the elevated privilege resources 904 to access control to update rules for entry, e.g., validation or implementing change management.

[0147] In order to bring a new tool into the design environment 902 , the user must provide authentication information at an elevated privilege level through the change management function 925 to enable the new tool to be installed and run in the design environment 902 .

[0148] Enhanced privileged resources 904 include "region of interest" (ROI) filters 906, which define which design artifacts are to be monitored by enhanced privileged resources 904. ROI filters 906 include directory and file filters 926 for each component in design environment 902. Each directory and file filter 926 receives data from a corresponding portion of design environment 902 and highlights possible design artifacts of interest.

[0149] One challenge with elevated privileged resources 904 is the large amount of data about changes in design environment 902 during the FPGA design process. Consequently, a strategic decision can be made not to monitor aspects of the data that change too frequently and to focus on targeting robust and consistent components. Advantageously, using DFoV, elevated privileged resources 904 can detect malicious behavior by selectively viewing data related to changes in the design environment that have trends indicating malicious behavior. Advantageously, ROI filters 906 define aspects of the design environment that are intended to be monitored. Changes in elements of design environment 902 are filtered into corresponding directory and file filters 926 within ROI filters 906.

[0150] The elevated privileged resource 904 also includes an encryption function 908 that receives output from the corresponding directory and file filter 926 of the ROI filter 906. The encryption function 908 then assigns a hash tag to the data from the directory and file filter 926 and compresses the selected results for archiving and remote verification.

[0151] The change management function 910 receives the encrypted and compressed output of the ROI filter 906. The data from the encryption function 908 enables identification of changed areas in the design effort. The change management function 910 uses the timeline recording function 936 to construct a timeline of changes in the design environment 902 based on the data from the encryption function 908.

[0152] Embodiments of the enhanced privileged resources 904 identify changes in the design environment 902. Similarly, embodiments of the enhanced privileged resources 904 identify specific change areas of interest to enable tracking of changes over time, thereby enabling tracking of the progression and sequence of changes. For example, if a change is made to an external design input after the local design input is complete and the tool has been run, the enhanced privileged resources 904 can mark it as a potential bad action because the design input should not change after the tool has been run. Similarly, if the tool is updated after the final output is produced, the enhanced privileged resources 904 will also mark the tool as a possible bad action because the change in the tool may make it difficult to reproduce the output. By establishing a profile in the change management function 910, the enhanced privileged resources 904 can mark and identify bad actions in the design environment 902.

[0153] Change management function 910 communicates with digital view engine 928 to form a local digital view (relating to system 900's design environment 902 and elevated privileged resources 904) and a global digital view (relating to system 900 in the context of other similar systems interconnected, for example, via a network). Digital view engine 928 enables the generation of a representation highlighting areas of change in design environment 902. In one embodiment, digital view engine 928 generates a representation of changes in design efforts using the teachings described above in the section entitled "Data Protection through Randomized Spatial Imaging." Advantageously, using this technique to represent changes in design efforts can help differentiate threats.

[0154] The elevated privileged resources 904 also include remote health management functions 930. The remote health management functions 930 communicate with other elevated privileged resources associated with other design environments, such as those described in the example embodiment of the present invention. Figure 8 In one embodiment, the remote health management function 930 transmits an encrypted, compressed data stream to the remote DFoV user management interface 932 on the remote PC 934. This enables the design environment 902 to be recreated on the remote PC 934 using the digital field of view platform. This can be used for a secure collaborative environment for incident planning or a secure archiving environment. In addition, the remote trusted environment will have the ability to monitor and verify design operations occurring on the development computer, the ability to access design artifacts, and the ability to recreate the design environment for independent verification.

[0155] In some embodiments, the enhanced privileged resources 904 include a user management dashboard interface for defining directory and file filters 926 for the ROI filters 906, hashing, encryption, and compression aspects of the cryptographic functions 908, filters for change management functions 910, and providing a local DFoV representation for testing and debugging.

[0156] The digital view method described herein allows for distributed participation in system integrity. In the examples described herein, each device has the ability to participate in the digital view according to the rules that apply to its digital view and its role within that view. This view is then represented using spatial points in the view, enabling the use of spatial point processing to verify observed changes in the digital environment to determine if they are real.

[0157] By developing a digital field of view approach using the methods discussed herein, the processing / computational load can be reduced for a device or subsystem and / or operated on low-cost hardware even as the digital field of view grows. The digital field of view approach also allows for scaling data validation and management across spatial dimensions to accommodate nearest-neighbor integrity. For example, instead of understanding the universal view, a device or subsystem only needs to understand its relationship to its nearest neighbors or digital landmarks defined in the digital universal field of view.

[0158] In various aspects, the system elements, method steps, or examples described in this disclosure (such as, for example, systems or components thereof) may be implemented on one or more computer systems including a central processing unit (CPU), a graphics processing unit (GPU), a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), and / or similar devices including hardware execution code for implementing those elements, processes, or examples, the code being stored on a non-transitory data storage device. These devices include or operate using software programs, firmware, or other computer-readable instructions for performing various methods, process tasks, computations, and control functions.

[0159] These instructions are typically stored on any suitable computer storage medium for storing computer-readable instructions or data structures. Computer-readable media can be implemented as any available medium that can be accessed by a general or special-purpose computer or processor or any programmable logic device. Suitable processor-readable media may include storage devices or memory media, such as magnetic media or optical media. For example, storage or memory media may include conventional hard disks, compact disc-read only memories (CD-ROMs), volatile or non-volatile media such as random access memories (RAMs) (including but not limited to synchronous dynamic random access memories (SDRAMs), double data rate (DDR) RAMs, RAMBUS dynamic RAMs (RDRAMs), static RAMs (SRAMs), etc.), read-only memories (ROMs), electrically erasable programmable ROMs (EEPROMs), and flash memories, etc. Suitable processor-readable media may also include transmission media (such as electrical signals, electromagnetic signals, or digital signals) transmitted via communication media (such as networks and / or wireless links).

[0160] The methods and techniques described herein can be implemented in digital electronic circuitry or with a programmable processor (e.g., a special-purpose processor or a general-purpose processor such as a computer) in firmware, software, or a combination thereof. Apparatus embodying these techniques may include appropriate input and output devices, a programmable processor, and a storage medium tangibly embodying program instructions for execution by the programmable processor. Processes embodying these techniques can be performed by the programmable processor executing a program of instructions to perform a desired function by operating on input data and generating appropriate output. These techniques can advantageously be implemented in one or more programs executable on a programmable system comprising at least one programmable processor coupled to receive data and instructions from and transmit data and instructions to a data storage system, at least one input device, and at least one output device. Generally, the processor will receive instructions and data from read-only memory and / or random access memory. Storage devices suitable for tangibly embodying computer program instructions and data include all forms of non-volatile memory, including, by way of example, semiconductor memory devices such as EPROM, EEPROM, and flash memory devices; magnetic disks such as internal hard disks and removable disks; magneto-optical disks; and DVD disks. Any of the foregoing may be supplemented by, or incorporated in, specially designed application specific integrated circuits (ASICs).

[0161] Example Implementation

[0162] Although specific embodiments have been shown and described herein, it will be appreciated by those of ordinary skill in the art that any arrangement calculated to achieve the same purpose may be substituted for the specific embodiments shown. It is manifestly intended that the present invention be limited only by the claims and the equivalents thereof.

[0163] Example 1 includes a method comprising: receiving data from a data source; selectively watermarking the data; mutating the data using a mutation function; converting the data into a watermarked mutated image; converting the watermarked mutated image into a two-dimensional randomly distributed pixelated image; converting the two-dimensional randomly distributed pixelated image into a three-dimensional mutated image; and analyzing the three-dimensional mutated image to determine probabilities of finding points and spaces in the three-dimensional mutated image.

[0164] Example 2 includes the method of Example 1, further comprising verifying that the original data has not been altered based on the analysis of the three-dimensional variant image.

[0165] Example 3 includes the method of any of Examples 1 and 2, wherein converting the data includes converting one or more of software code, a software tool, a digital image, a digital drawing, or digitized text.

[0166] Example 4 includes the method of any one of Examples 1 to 3, wherein mutating the data comprises using a physically unclonable function value or a true random number.

[0167] Example 5 includes the method of any one of Examples 1 to 4, wherein selectively watermarking the data comprises using an algorithm to strategically place watermarks to enhance traceability of features of the data to be tracked for data verification.

[0168] Example 6 includes a method according to any one of Examples 1 to 5, wherein converting the watermarked variant image to the two-dimensional randomly distributed pixelated image includes converting the watermarked variant image using a pseudo-random-based algorithm that converts bits of the image into point coordinates and / or spaces in the XZ plane such that bits of data represented by the watermarked variant image are represented by points in the 2D randomly distributed pixelated image.

[0169] Example 7 includes the method of Example 6, wherein converting the watermarked variant image further comprises using a physically unclonable function (PUF) or a true random number generator function of a microelectromechanical system (MEMS) device with a pseudorandom based algorithm.

[0170] Example 8 includes a method according to any one of Examples 1 to 7, wherein converting the two-dimensional randomly distributed pixelated image into a three-dimensional mutated image includes randomly moving points of the two-dimensional randomly distributed pixelated image to heights on the Y-axis, wherein the heights are determined by random number outputs of the MEMS sensor.

[0171] Example 9 includes the method of any one of Examples 1 to 8, wherein analyzing the three-dimensional variant image comprises analyzing the three-dimensional variant image using a spatial point process.

[0172] Example 10 includes the method of any one of Examples 1 to 9, wherein analyzing the three-dimensional variant image comprises analyzing the three-dimensional variant image using a high-frequency reflectance function that is reflected in a random pattern from defined boundary walls, wherein the boundaries are defined to include at least some watermarked points.

[0173] Example 11 includes a method according to any one of Examples 1 to 19, and further includes: saving the probabilities of finding different levels of points and spaces in the three-dimensional variant image used for data verification, wherein the different levels of points and spaces include points, points with watermarks, and spaces; and sharing these probabilities with devices in a trusted network.

[0174] Example 12 includes a method for determining whether data on a device has changed from an original version of the data ("original data"). The method includes: converting the data into a first three-dimensional (3D) spatial representation of the data, wherein the first 3D spatial representation uses positions of points and / or voids in the first 3D spatial representation to represent multiple characteristics of the data, wherein converting the data into the first 3D spatial representation includes converting the data using the same process used to generate a second 3D spatial representation from the original data; analyzing the first 3D spatial representation using one or more spatial processes; and determining whether the data has changed based on the analysis of the first 3D spatial representation.

[0175] Example 13 includes a method according to Example 12, wherein analyzing the first 3D spatial representation includes generating a first probability, and further includes: storing the probability generated by analyzing the original data by converting the original data into the second 3D spatial representation; analyzing the second 3D spatial representation to determine a second probability of finding points and spaces; and storing the second probability ("stored probability").

[0176] Example 14 includes a method according to Example 13, wherein when the second 3D spatial representation of the analysis raw data is performed by the device, information about the processes used in the second 3D spatial representation of the analysis raw data is stored in the memory of the device; and wherein when the second 3D spatial representation of the analysis raw data is performed by another device, information about the processes used by the other device in the second 3D spatial representation of the analysis raw data is received and stored in the memory of the device.

[0177] Example 15 includes the method of any of Examples 13-14, wherein determining whether the data has changed comprises comparing the first probabilities to the stored probabilities.

[0178] Example 16 includes the method of Example 15, wherein comparing the first probabilities to the second probabilities comprises determining whether a temporal order of point and gap detections for the first probabilities matches a temporal order of point and gap detections for the stored probabilities.

[0179] Example 17 includes the method of any of Examples 15 and 16, and further providing notification that data has been changed when the first probabilities do not match the stored probabilities.

[0180] Example 18 includes the method of Example 17, and further not using the data when the first probabilities do not match the stored probabilities.

[0181] Example 19 includes a method according to any one of Examples 12 to 18, further receiving first probabilities for the first 3D spatial representation from a host device, wherein the host device receives a PUF output for a MEMS device for the device as part of an exclusive community, and uses the PUF output to generate the second 3D spatial representation of the original data and generate these first probabilities.

[0182] Example 20 includes a method according to Examples 12 to 19, wherein: converting the data into a first three-dimensional (3D) spatial representation of the data includes converting the data corresponding to a specific version of the software application into a 3D spatial representation; and determining whether the data has changed includes determining whether the data corresponds to an expected version of the software program.

Claims

1. A method (100), comprising: Receive data from the data source; selectively watermarking the data; mutating the data using a mutation function; Converting the data into a watermarked variant image (102); Converting the watermarked variant image into a two-dimensional randomly distributed pixelated image (104); Converting the two-dimensional randomly distributed pixelated image into a three-dimensional variant image (106); analyzing the three-dimensional variant image to determine probabilities of finding points and spaces in the three-dimensional variant image (108); and It is verified based on the analysis of the three-dimensional variation image that the original data has not been changed. 2 . The method of claim 1 , wherein selectively watermarking the data comprises using an algorithm to strategically place watermarks to enhance traceability of characteristics of the data to be tracked for data verification. 3 . The method of claim 1 , wherein analyzing the three-dimensional variation image comprises analyzing the three-dimensional variation image using a spatial point process.