Sensitive detection and identification of counterfeit components in utility power systems with EMI frequency kiviat tubes

EMI frequency Kiviat tubes generate unique fingerprints for utility devices, enabling precise counterfeit detection by comparing EMI signals, addressing the integration of counterfeit components in utility power systems and ensuring device authenticity.

JP2026004311APending Publication Date: 2026-01-14ORACLE INT CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025146273
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2020-02-28
Filing Date
2025-09-03
Publication Date
2026-01-14

AI Technical Summary

Technical Problem

Counterfeit electronic components, including 'spy chips', are integrated into utility power systems, posing safety risks and high warranty losses, and existing detection methods are ineffective or require invasive inspections.

Method used

A method using EMI frequency Kiviat tubes to generate unique fingerprints for utility devices by analyzing electromagnetic interference signals during power tests, comparing them to reference fingerprints, and applying a cumulative cylindrical error metric for precise counterfeit detection without disassembly.

Benefits of technology

This method provides sensitive and non-invasive detection of counterfeit components, ensuring the authenticity of utility devices and preventing integration of counterfeit parts into power systems, thus enhancing safety and reducing warranty losses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026004311000001_ABST
    Figure 2026004311000001_ABST
Patent Text Reader

Abstract

To provide a method for detecting a counterfeit status of a target utility device.SOLUTION: The method is performed by selecting a set of frequencies that best reflects load dynamics or other information content of a reference utility device while undergoing a power test sequence, obtaining a target electromagnetic interference (EMI) signal emitted by a target utility device, forming a target kiviat tube EMI fingerprint, comparing the target kiviat tube EMI fingerprint to a reference kiviat tube EMI fingerprint for the reference utility device undergoing the power test sequence, and generating a signal to indicate a counterfeit status based at least in part on a result of the comparison.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Background technology]

[0001] background It has been estimated that $200 billion is spent annually on counterfeit electronic components circulating in international supply chains across all industries that use electronics, including information technology, healthcare, military, gaming, transportation, and utilities. Counterfeit systems often appear so authentic that service engineers are unable to distinguish them from genuine systems by simple visual inspection. However, counterfeit systems often contain scrap components from discarded systems, cheaply manufactured components, or older components from recycled older systems that have been repackaged to resemble genuine systems. Summary of the Invention [Problem to be solved by the invention]

[0002] Such systems are then integrated into the supply chain through intermediary channels. When counterfeit systems are shipped to customers, they often fail upon arrival or within a very short period of time, resulting in high warranty losses, low mean time between failures, and customer dissatisfaction. In some situations, counterfeit systems even contain "spy chips" or "modded chips" that can allow unauthorized access to or control the counterfeit systems, posing a significant risk to infrastructure. In the utility sector, the use of counterfeit electronic components is not just costly and cumbersome, but also a major safety concern. Utility component failures can cause life-threatening situations such as power outages and fires.

[0003] The North American Electric Reliability Corporation ( North American utility regulator (NERC) and the United States Federal Energy Reliability Commission The Federal Energy Agency (FERC) has issued the Supply Chain Risk Management Rule (No. CIP-013-1) to reduce risks to the reliable operation of bulk electric systems. The rule requires that by July 2020, all utilities in North America must implement technology to detect counterfeit components for all power system assets used in generating facilities, supervisory control and data acquisition (SCADA) subsystems, and distribution grid assets. [Means for solving the problem]

[0004] overview In one embodiment, a method for detecting counterfeit status of a target utility device is provided, the method comprising the steps of selecting a set of frequencies that reflect load dynamics of a reference utility device while undergoing a power test sequence, acquiring a target electromagnetic interference (EMI) signal radiated by the target utility device while undergoing the power test sequence, creating a sequence of target kiviat plots from the amplitude of the target EMI signal for each set of frequencies observed over the power test sequence to form a target kiviat EMI fingerprint, and performing a power test on the reference utility device undergoing the power test sequence to determine whether the target utility device and the reference utility device are the same type. The method includes comparing the target Kiviat tube EMI fingerprint with a reference Kiviat tube EMI fingerprint for the utility device, and generating a signal to indicate counterfeit status based at least in part on the result of the comparison.

[0005] In one embodiment, a method for detecting counterfeit status of a target utility device, wherein the creating step further includes generating estimates of the amplitudes for each set of the frequencies by a state estimation model trained on the reference Kiviat tube EMI fingerprint, and the target Kiviat plot is a Kiviat plot of the estimates.

[0006] In one embodiment, a method for detecting counterfeit status of a target utility device, wherein the comparing step further includes normalizing each axis of each target Kiviat plot to a unit circle passing through the values ​​plotted on the axis of the corresponding reference Kiviat plot for the same observation in the reference Kiviat tube EMI fingerprint.

[0007] In one embodiment, a method for detecting counterfeit status of a target utility device, wherein the comparing step further includes generating an error metric from circular residuals between the target Kiviat plot and the unit circle on axes normalized to represent a corresponding reference Kiviat plot at the same observation in the reference Kiviat tube EMI fingerprint as a unit circle, wherein the error metric is a cumulative area of ​​circular residuals between the unit circle and the target Kiviat plot across all observations.

[0008] In one embodiment, a method for detecting counterfeit status of a target utility device, wherein the comparing step further includes generating an error metric from circular residuals between the target Kiviat plot and the reference Kiviat plot at the same observation in the reference Kiviat tube EMI fingerprint, the error metric being a cumulative area of ​​circular residuals between the reference Kiviat plot and the target Kiviat plot across all observations.

[0009] In one embodiment, a method for detecting counterfeit status of a target utility device, wherein the reference utility device is an authentic utility device of a particular type, further comprising the steps of: in response to determining (i) that the target utility device and the reference utility device are of the same type, generating a signal to indicate that the target utility device is confirmed as authentic; and in response to determining (ii) that they are not of the same type, generating a signal to indicate that the target utility device is a suspected counterfeit.

[0010] In one embodiment, a method for detecting a counterfeit status of a target utility device further includes transmitting the target Kiviat EMI fingerprint to a counterfeit analysis system in response to the signal that the target utility device is a suspected counterfeit.

[0011] In one embodiment, a method for detecting a counterfeit status of a target utility device further comprises transmitting supply chain information regarding the target device to the counterfeit analysis system.

[0012] In one embodiment, a method for detecting counterfeit status of a target utility device includes: The method further includes receiving additional information regarding the suspected counterfeit configuration from a counterfeit analysis system in response to the signal, the additional information including one or more of: (i) confirmation that the suspected counterfeit is a known type of counterfeit; (ii) prevalence information describing how widespread utility devices with the suspected counterfeit configuration are; (iii) source information describing the origin of utility devices with the suspected counterfeit configuration; and (iv) supply chain information describing how the target device may have entered the supply chain.

[0013] In one embodiment, a method for detecting a counterfeit status of a target utility device, wherein the reference utility device is a known counterfeit utility device of a particular type, further comprising the steps of: in response to determining (i) that the target utility device and the reference utility device are of the same type, generating a signal to indicate that the target utility device is confirmed to be a counterfeit device of the particular type; and in response to determining (ii) that they are not of the same type, generating a signal to indicate that the target utility device is not a counterfeit device of the particular type.

[0014] In one embodiment, the method for detecting counterfeit status of a target utility device further comprises retrieving the reference Kiviat tube EMI fingerprint for the reference utility device from a library database.

[0015] In one embodiment, a method for detecting counterfeit status of a target utility device further comprises displaying information based at least in part on said signal in a graphical user interface.

[0016] In one embodiment, a non-transitory computer-readable medium having stored thereon computer-executable instructions that, when executed by at least a processor of a computer, cause the computer to select a set of frequencies reflective of load dynamics of a reference utility device while undergoing a power test sequence, acquire a target electromagnetic interference (EMI) signal radiated by the target utility device while undergoing the power test sequence, create a sequence of target Kiviat plots from the amplitude of the target EMI signal for each set of frequencies observed over the power test sequence to form a target Kiviat tube EMI fingerprint, compare the target Kiviat tube EMI fingerprint with a reference Kiviat tube EMI fingerprint for the reference utility device undergoing the power test sequence to determine if the target utility device and the reference utility device are of the same type, and generate a signal to indicate counterfeit status based at least in part on a result of the comparison.

[0017] In one embodiment, a non-transitory computer-readable medium, the instructions for causing the computer to create a sequence of target Kiviat plots further comprising instructions for causing the computer to generate estimates of the amplitudes for each set of the frequencies by a state estimation model trained on the reference Kiviat tube EMI fingerprint, the target Kiviat plots being Kiviat plots of the estimates.

[0018] In one embodiment, a computing system includes a processor, a memory operably connected to the processor, a radio operably connected to the processor and the memory, and a non-transitory computer-readable medium operably connected to the processor and the memory and having computer-executable instructions stored thereon, the computer-executable instructions, when executed by at least the processor, and causing the radio to select a set of frequencies that reflect load dynamics of a reference utility device while undergoing a power test sequence, acquire via the radio a target electromagnetic interference (EMI) signal radiated by a target utility device while undergoing the power test sequence, create a sequence of target Kiviat plots from the amplitude of the target EMI signal for each set of frequencies observed over the power test sequence to form a target Kiviat tube EMI fingerprint, compare the target Kiviat tube EMI fingerprint with a reference Kiviat tube EMI fingerprint for the reference utility device undergoing the power test sequence to determine if the target utility device and the reference utility device are of the same type, and generate a signal to indicate counterfeit status based at least in part on a result of the comparison.

[0019] BRIEF DESCRIPTION OF THE DRAWINGS The accompanying drawings, which are incorporated into and constitute a part of this specification, illustrate various systems, methods, and other embodiments of the present disclosure. It will be understood that element boundaries (e.g., boxes, groups of boxes, or other shapes) shown in the figures represent one embodiment of those boundaries. In some embodiments, one element may be implemented as multiple elements, or multiple elements may be implemented as one element. In some embodiments, an element shown as an internal component of another element may be implemented as an external component, and vice versa. Additionally, elements may not be drawn to scale. [Brief explanation of the drawings]

[0020] [Figure 1] FIG. 1 illustrates one embodiment of an EMI fingerprint counterfeit scanner and an exemplary target utility device associated with sensitive detection and identification of counterfeit components in utility power systems using EMI frequency Kiviat tubes. [Figure 2]FIG. 1 illustrates one embodiment of an environment for operating an EMI fingerprint counterfeit scanner associated with sensitive detection and identification of counterfeit components in utility power systems using EMI frequency Kiviat tubes. [Figure 3] FIG. 1 illustrates one embodiment of a method related to sensitive detection and identification of counterfeit components in utility power systems using EMI frequency Kiviat tubes. [Figure 4] FIG. 10 illustrates one embodiment of a graphical user interface associated with verifying to a user that a target utility device is authentic using an EMI frequency Kiviat tube. [Figure 5] 1 illustrates one embodiment of a graphical user interface associated with using an EMI frequency Kiviat tube to alert a user to counterfeit components in a target utility device. [Figure 6] FIG. 1 illustrates one embodiment of a method related to sensitive detection and identification indication of counterfeit components in utility power systems using EMI frequency Kiviat tubes. [Figure 7] FIG. 1 illustrates one embodiment of a computing system configured with the example systems, methods, and / or special-purpose devices disclosed herein. DETAILED DESCRIPTION OF THE INVENTION

[0021] Detailed Description Described herein are systems and methods for sensitive detection and identification of counterfeit components in utility power systems by applying electromagnetic interference (EMI) frequency Kiviat tubes.

[0022] EMI signals are generated by power utility devices, such as transformers, generators, inverters, meters, or other electrical grid systems, during operation. While these EMI signals are typically considered noise, they can also carry information that can be used to generate a unique EMI fingerprint for the utility device. For example, the EMI emitted by a target utility device with components having an unknown configuration can be scanned to generate a target EMI fingerprint for the target utility device. The generated target EMI fingerprint can be compared to a reference EMI fingerprint of a reference utility device with a known configuration to either confirm that the target utility device is of a known make, model, and configuration, or to indicate that the target utility device is not of a known make, model, and configuration and therefore may contain one or more suspected counterfeit components or may be entirely counterfeit.

[0023] This technique for counterfeit detection is “passive” because it does not require disassembly of the target utility device's power system electronics to perform internal inspections, such as visual or photographic inspections. It should be noted that counterfeit detection techniques that require disassembly are ineffective and often result in later problems with inspected utility devices, even if they do not detect counterfeit components. In contrast, this passive technique, in practice, would result in power system devices being inspected periodically within the supply chain, upon entry into the country, or when the system is received by a utility customer during power-on-self-test (POST) operations as part of initial setup preparation. This new technique thus helps ensure that counterfeit components or “spy chips” or “modded chips” are not installed in power system electronics during transportation between component manufacturing and the “assembly plant” or between the assembly plant and the utility system. Furthermore, this new technique does not require hardware modifications in the utility power system and is therefore backward compatible with older power systems commonly used by utilities.

[0024] In one embodiment, a particular form of EMI fingerprinting, the EMI-KT (EMI kiviat tube) fingerprinting, is used to identify counterfeits. This can increase the sensitivity of detecting and identifying components or counterfeit utility devices. In one embodiment, a Kiviat tube is a series of Kiviat plots (also known as spider plots, star charts, or radar charts) for data over a time interval, such as equally spaced time intervals. A Kiviat plot is a multi-vector line graph for displaying multivariate data in two dimensions, with data values ​​represented on axes originating from the same point. Kiviat plots are well suited to showing outliers and commonalities between data sets. In one embodiment, an EMI-KT fingerprint includes the data necessary to describe each Kiviat plot that makes up a Kiviat tube. For example, an EMI-KT fingerprint may include a time series of N-axis Kiviat plots, each axis representing signal strength at one of N frequencies. The N frequencies are determined to best reflect the dynamics of the target device. Therefore, these N frequencies best convey information about the target device's response to a dynamic test sequence.

[0025] It should be noted that, in one embodiment, while Kiviat conduits for the reference EMI-KT fingerprint and / or the target EMI-KT fingerprint may be generated and visually displayed on a graphical user interface (GUI) for user reference, the properties of representing the EMI fingerprint as a Kiviat conduit are more important. Note that this technique significantly improves the ability of EMI counterfeit detection systems to distinguish genuine utility devices from counterfeit utility devices. Forming the EMI fingerprint as a "dynamically scrolling tube" of Kiviat plots along the time axis provides a sufficiently precise fingerprint that is particularly sensitive to differences between the reference and target fingerprints. This is at least partially due to the nature of Kiviat plots. In Kiviat plots, the included area increases proportionally to the square of the linear measurement, thus highlighting even small differences between the signal strengths at a particular time observation as the area between the reference and target plots. Integrating these areas over time to generate a "residual volume" during observation of the EMI-KT fingerprint provides greater sensitivity to deviations than other EMI fingerprinting techniques. The residual volume (i.e., the time integral over a series of time observations of the residual area between the reference (golden system) Kiviat plot and the target (test unit) Kiviat plot of signal strengths at the top N most informative frequencies) forms a new prognostic metric. In one embodiment, the cumulative cylindrical error metric (or CCEM, as defined elsewhere herein) is used. Residual volume (described in further detail below) is a form of residual volume. Residual volume (and its variations, such as CCEM) can be used to contribute substantially improved differential detection (sensitivity) to systematic prognostic algorithms for deterministic and reproducible discrimination between counterfeit and genuine utility systems and components.

[0026] In one embodiment, the reference EMI-KT fingerprint is obtained from a reference utility device for the structure, model, and configuration (or "type") of the utility device. The reference utility device for the structure, model, and configuration is the utility device (which may also be referred to as the "Golden System" or "GS"). A reference utility device is a device that has been verified to be an authentic example of the device's make, model, and configuration. In one embodiment, the reference utility device is further verified to be operating optimally, or at least within accepted parameters. In one embodiment, the target utility device (which may be referred to as a "unit under test" or "UUT") is subjected to a pattern recognition process. The pattern recognition process compares a target EMI-KT fingerprint obtained from a target utility device to a reference EMI-KT fingerprint using a configurational similarity metric called the cumulative cylindrical error metric (CCEM).

[0027] Although the present invention is described in the context of a power utility device, the general principles and techniques of the present invention can be applied to any electronic system comprising at least one electronic component.

[0028] -An exemplary EMI fingerprint forgery detector- 1 illustrates one embodiment of an EMI fingerprint counterfeit scanner 100 and an exemplary target utility device 105 associated with sensitive detection and identification of counterfeit components in utility power systems using EMI frequency Kiviat tubes. EMI fingerprint counterfeit scanner 100 includes an antenna (or other EMI signal sensor) 115 connected to a radio 120, such as a software-defined radio, AM / FM radio, or other radio configured to connect to EMI fingerprint counterfeit scanner 100. EMI fingerprint counterfeit scanner 100 also includes local data storage 150 connected to radio 120. EMI fingerprint counterfeit scanner 100 also includes sensitive EMI Kiviat tube counterfeit component detection and identification logic 155. EMI fingerprint counterfeit scanner 100 also includes a network-based network interface (WAN). The display 165 includes a touch screen interface 160 and a display 165.

[0029] It should be noted that when power is supplied to the utility device 105, the utility device 105 generates the EMI signal 110. The utility device 105 may generate a first type of similar signal while the device is in a high-power, fully loaded, or energized state, and a second type of similar signal while the device is in a low-power, idle, or de-energized state. Furthermore, it should be noted that the utility device 105 may continue to generate the EMI signal 110 for at least a certain period of time after power to the utility device 105 is interrupted (de-energized state). The EMI signal is generated from one or more internal components of the utility device 105. The one or more internal components of the utility device 105 may include a controller, a switch, a motor, an inductor / transformer winding, a capacitor, a sensor, and other components. In some examples, the EMI signal may be generated by interaction between multiple components. In one embodiment, the antenna 115 is configured to detect the EMI signal 110 and provide the EMI signal to a radio 120 coupled to the antenna 115. Depending on the configuration of antenna 115 and radio 120, EMI signals may be detected across a wide frequency spectrum, for example, from about 500 kilohertz up to about 4 gigahertz. Other ranges may be suitable, and the range of frequencies available to EMI fingerprint counterfeit scanner 100 may be controlled by the combination of antenna 115 and radio 120.

[0030] In one embodiment, the antenna 115 may include a dipole antenna, a Yagi-Uda antenna, a loop antenna, an electrically shorted antenna (e.g., an open-ended wire having a length less than a quarter wavelength), a fractal antenna, a parabolic antenna, a microstrip antenna, a quad antenna, a random wire antenna (e.g., an open-ended wire having a length greater than one wavelength), a beverage antenna, a helical antenna, a phased array antenna, and any other type of antenna now known or later developed. In one simple and inexpensive embodiment, the antenna 115 may be an insulated wire with a length of insulation stripped off. In one embodiment, the type and length of the antenna may be selected to achieve optimal discrimination sensitivity and robustness.

[0031] The antenna 115 may be positioned in close proximity to the target utility device 105 or may be positioned further away from the target utility device 105. Greater sensitivity in the antenna 115 and therefore a higher signal-to-noise ratio (SNR) in the EMI fingerprint counterfeit scanner 100 may be achieved. ), a shorter distance between the target utility device 105 and the antenna 115 is preferred. In addition to distance, the sensitivity of the antenna 115 can also be affected by the orientation of the antenna 115 relative to the target utility device 105.

[0032] In one embodiment, antenna 115 is positioned at a predetermined distance and orientation relative to target utility device 105 during scanning. This predetermined distance and orientation may be the same distance and orientation used to detect a reference EMI signal from a reference utility device of the same make and model as target utility device 105. Consistency in antenna placement relative to the utility device being scanned may improve the ability of EMI fingerprint counterfeit scanner 100 to match the target EMI fingerprint with the reference EMI fingerprint and distinguish the target EMI fingerprint from the reference EMI fingerprint.

[0033] In one embodiment, antenna 115 may be attached to EMI fingerprint counterfeit scanner 100. In one embodiment, antenna 115 may be at a fixed position (distance and orientation) relative to target utility device 105 during scanning of target utility device 105 by EMI fingerprint counterfeit scanner 100. For example, antenna 115 may be positioned proximate target utility device 105 and may not move during scanning. Antenna 115 may be attached to or within the housing of target utility device 105. Antenna 115 may be attached mechanically, such as with bolts, screws, or clips, magnetically, or with an adhesive such as sensor wax. In one embodiment, multiple antennas and / or radios (not shown) may be positioned at various positions and orientations relative to target utility device 105 during scanning, and measurements obtained from the multiple antennas and / or radios may be combined. In one embodiment, antenna 115 is moved to multiple different positions and orientations relative to target utility device 105 during scanning. These various antenna positions and configurations, as well as other position and configuration implementations, may be selected as desired to improve the signal-to-noise ratio (SNR) of the detected EMI signal for the entire target utility device 105 or to highlight EMI signals emitted by particular components of the target utility device 105.

[0034] In one embodiment, radio 120 is configured to convert the received EMI signals from analog to digital and record the power amplitude and frequency of the signals at defined time intervals. In one embodiment, radio 120 may store the recorded signals as a data structure in local data storage 150 or may provide the signals directly to high sensitivity EMI Kiviat tube counterfeit component detection and identification logic 155 for analysis.

[0035] In one embodiment, local data storage 150 is a local data store of a mobile device or computer. In one embodiment, high-sensitivity EMI Kiviat tube counterfeit component detection and identification logic 155 is a processor of a mobile device or computer configured with instructions for, among other things, performing one or more of the functions of the system described herein. For example, instructions may be stored in local data storage 150 and retrieved by the processor as needed to execute logic 155.

[0036] -Example environment for EMI fingerprint scanning- FIG. 2 illustrates one embodiment of an environment 200 for operating the EMI fingerprint counterfeit scanner 100 in connection with sensitive detection and identification of counterfeit components in utility power systems that use EMI frequency Kiviat tubes.

[0037] In one embodiment, EMI fingerprint counterfeit scanner 100 is a mobile device 205 or computer 210 coupled to a software-defined radio 120 and antenna 115. In one embodiment, network interface 160 is configured to enable EMI fingerprint counterfeit scanner 100 to interact with one or more remote computers over communication network 215. In one embodiment, EMI fingerprint counterfeit scanner 100 may send requests to and receive responses from a web server, such as web interface server 220. These communications may be in the form of, for example, remote representational state transfer (REST) ​​requests using JavaScript object notation (JSON) as the data exchange format, or, as another example, XML syntax. This may take the form of simple object access protocol (SOAP) requests to and from the XML server.

[0038] In one embodiment, web interface server 220 is configured to enable EMI fingerprint counterfeit scanner 100 to access resources provided by cloud application infrastructure 225. In addition to web interface server 220, cloud application infrastructure 225 also includes server-side sensitive EMI Kiviat tube counterfeit component detection and identification logic (“server-side logic”) 230 and one or more data storage devices 235. Web interface server 220, server-side logic 230, and data storage devices 235 are interconnected by local network 240. In one embodiment, server-side logic 230 is one or more computing devices specially configured with instructions to perform one or more of the functions of the system described herein.

[0039] In one embodiment, the analysis of the target EMI-KT fingerprint is performed by EMI fingerprint counterfeit scanner 100. In one embodiment, the analysis of the target EMI-KT fingerprint is performed by server-side logic 230 in response to a request from EMI fingerprint counterfeit scanner 100, and the results are returned to EMI fingerprint counterfeit scanner 100 for display to the user.

[0040] In one embodiment, cloud application infrastructure 225 is operated as a counterfeit analysis system by at least a portion of server-side logic 230, i.e., counterfeit analysis logic 233. In one embodiment, cloud application infrastructure 225 is a multi-tenant system for storing and processing information related to EMI fingerprint counterfeit detection and identification for one or more operating companies that are tenants of the cloud application infrastructure. The counterfeit analysis system is configured to analyze information related to EMI-KT fingerprints of suspected and confirmed counterfeit utility devices provided by one or more tenants of the counterfeit analysis system with various analysis tools. The analyzed information may be submitted by tenants of the system, by manufacturers of utility devices, or by law enforcement agencies. The analysis may be performed within the scope of information provided by only a single tenant or across information provided by multiple tenants. The analysis may include identifying how widespread or prevalent utility devices with suspected or confirmed counterfeit configurations are. The analysis may provide further granularity to this prevalence information indicating, for example, the prevalence of suspected or confirmed counterfeit configurations in particular geographic regions or locations, in particular tenant systems or facilities, and upon detection at particular ports of entry or other locations in the supply chain. The analysis may also identify commonalities among supply chain information for multiple instances of detected counterfeit utility devices to identify potential sources of counterfeit systems. Generally, analyses useful for identifying the source of counterfeit utility devices or analyses useful for identifying undetected counterfeit utility devices previously installed in a utility system may be included in counterfeit analysis logic 233.

[0041] In one embodiment, environment 200 also includes a test sequence generator 245. Test sequence generator 245 operates to control power through one or more components within target utility device 105. In operation, test sequence generator 245 may generate a square wave of power amplitude through the components of target utility device 105. Instructions for the test sequence, including the amplitude and duration of the square wave, may be pre-programmed in test sequence generator 245 and / or may be controlled by EMI fingerprint counterfeit scanner 100.

[0042] In one embodiment, for some types of utility devices, the target user The appropriate square wave can be generated by switching the power supplied to the utility device 105 between a high power supply state and a low power supply state, placing the target utility device 105 in a "powered" operating state (high power supply) and an "unpowered" operating state (low power supply). In one embodiment, the powered state can be a full output power supply state. In one embodiment, the powered state can be a relatively higher power supply state than the low power supply state, and the unpowered state can be a relatively lower power supply state than the high power supply state. In one embodiment, the unpowered state can be a power supply state in which power is completely removed, i.e., a "no power" power supply state. In one embodiment, the unpowered state can be an "idle" power supply state, in which the power supplied to the target utility device 105 is the minimum power required to maintain operation of the target utility device 105 at the lowest possible power level. In this configuration, the test sequence generator 245 is positioned in line between the power supply 250 and the target utility device 105 and controls the supply of power from the power supply 250 to the target utility device 105. The test sequence generator is configured to provide test sequences of high and low power supplies to the target utility device 105 according to instructions for the test sequences that energize and de-energize the target utility device 105.

[0043] In another embodiment, for some types of utility devices, an appropriate square wave can be generated by switching the load on the target utility device 105 between a high power extraction state and a low power extraction state, placing the target utility device 105 in a powered (high power extraction) and a non-powered (low power extraction) operating state. In one embodiment, the powered state can be a full output power extraction state. In one embodiment, the powered state can be a relatively higher power extraction state than the low power extraction state, and the non-powered state can be a relatively lower power extraction state than the high power extraction state. In one embodiment, the non-powered state can be a power extraction state in which the load is completely disconnected, i.e., a "no power" power extraction state. In one embodiment, the non-powered state can be an "idle" power extraction state, in which the power extracted from the target utility device 105 is the minimum power required to maintain operation of the target utility device 105 at the lowest possible power level. In this alternative configuration, the test sequence generator 245 is positioned in-line between the target utility device 105 and ground 255 to control the power load drawn from the target utility device 105. The test sequence generator is configured to provide test sequences of high and low power power draws (loads) to the target utility device 105 according to instructions for the test sequences that energize and de-energize the target utility device 105.

[0044] In one embodiment, the power-on and power-off test sequence includes multiple power-on or power-off periods. In one embodiment, the test sequence cycles between approximately equal portions of (i) applying a high power supply or load to place the target device in a powered state and (ii) applying a low power supply or load to place the target device in a powered state. In one embodiment, a test sequence that cycles 30 seconds of high power supply or load (powered) to the target device and 30 seconds of low power supply or load (powered) to the target device may be appropriate. In other embodiments, other test sequences may be appropriate, for example, having shorter or longer power-on / power-off periods or unequal power-on / power-off periods. In one embodiment, the test sequence generator is configured to automatically control the power or load to alternately power and power off the target device in a repeatable test sequence.

[0045] In one embodiment, when the test sequence generator 245 controls the power supply of a utility device, the test sequence generator 245 supplies high and low power from the power supply 250 to an input (such as one of the primary terminals of a transformer) to generate a test sequence for the utility device. The test sequence generator 245 applies a high power load and a low power load on an output (such as one of the secondary terminals of a transformer) to energize and de-energize the utility device, respectively, in a test sequence. For example, power to the utility device is alternately applied and removed in a repeated cycle. In another embodiment, if the test sequence generator 245 controls the power load drawn from the utility device, the test sequence generator 245 applies a high power load and a low power load on an output (such as one of the secondary terminals of a transformer) to energize and de-energize the utility device, respectively, in a test sequence. For example, the load on the utility device is alternately applied and removed in a repeated cycle.

[0046] In one embodiment, the test sequence generator may be configured by instructions to generate waveforms other than square waves, which may include gradual transitions between unpowered and powered states, as well as transitions to and from various partially powered states.

[0047] In one embodiment, the test sequence generator 245 can be added to a staging area for power-on self-test (POST). Utility assets are typically unpackaged and then first powered up in a POST test before being installed in a production system. Therefore, it is a convenient time to perform an EMI-KT fingerprint counterfeit scan while the target utility device is being set up for POST testing. In one embodiment, the test sequence is applied to the target utility device while it is being set up in the staging area for testing.

[0048] - Exemplary Configuration Discovery and Forgery Detection Method - In one embodiment, one or more steps of the methods described herein may be performed by one or more computing device processors (such as processor 710 as illustrated and described with reference to FIG. 7 ) configured with (i) accessing memory (such as memory 715 and / or other computing device components illustrated and described with reference to FIG. 7 ) and (ii) logic that causes the system to perform the method steps (such as utility asset configuration discovery and counterfeit detection logic 730 illustrated and described with reference to FIG. 7 ). For example, the processor accesses, reads from, or writes to the memory to perform the computer-implemented method steps described herein. These steps may include (i) retrieving any necessary information, (ii) calculating, determining, generating, classifying, or creating any data, and (iii) storing any calculated, determined, generated, classified, or created data. When referring to storage or storing, this refers to storage as a data structure in the memory or storage / disk of a computing device (such as memory 715 or storage / disk 735 of computing device 705 illustrated and described with reference to FIG. 7, or a remote computer 765).

[0049] In one embodiment, a subsequent step of the method may be initiated in response to analyzing a received signal or stored retrieved data indicating that a preceding step has been performed at least to the extent necessary for initiation of the subsequent step. Generally, the received signal or stored retrieved data indicates completion of the previous step. Each step of the method may include multiple sub-steps, some of which may or may not be described herein.

[0050] In one embodiment, the steps of the method described herein are performed by an EMI fingerprint counterfeit scanner 100 (as illustrated and described with reference to FIGS. 1 and 2). In one embodiment, the EMI fingerprint counterfeit scanner 100 is a dedicated computer configured with highly sensitive EMI Kiviat tube counterfeit component detection and identification logic. In one embodiment, the steps of the method described herein are performed by the EMI fingerprint counterfeit scanner 100 in conjunction with a remote system, such as a cloud application infrastructure 225, configured with server-side sensitive EMI Kiviat tube counterfeit component detection and identification logic 230 and / or counterfeit analysis logic 233. In one embodiment, the steps of the method are performed by a dedicated computing system having at least one processor and configured to perform the steps described above.

[0051] 3 illustrates one embodiment of a method 300 related to sensitive detection and identification of counterfeit components in utility power systems using EMI frequency Kiviat tubes for detecting the counterfeit status (e.g., the status of being genuine or the status of including at least one counterfeit component) of a target utility device.

[0052] Method 300 may be initiated based on various triggers, such as (i) a user (or administrator) of EMI fingerprint counterfeit scanner 100 initiating method 300 by providing a signal indicating the start of a scan using EMI fingerprint counterfeit scanner 100; (ii) method 300 being scheduled to begin at a defined time or time interval; (iii) a target utility device being in place and ready to be scanned; or (iv) some other trigger indicating method 300 should begin. Method 300 begins at start block 305 in response to a determination that the analyzed received signal or stored retrieved data indicates that method 300 should begin. Processing proceeds to process block 310.

[0053] At process block 310, the system selects a set of frequencies that reflect the load dynamics of the reference utility device while undergoing the power test sequence. In one embodiment, the set of frequencies is predetermined and stored in a database library of EMI-KT fingerprints, such as a database library stored in local data storage 150 or data store 235. In one embodiment, selection of specific frequencies within the set may be performed by preprocessing to generate a reference EMI-KT fingerprint for an authentic (verified, "golden system") reference device undergoing the test sequence and storing the resulting fingerprint, including the set of frequencies, in the database library. In one embodiment, the set of frequencies is selected by requesting the reference EMI-KT fingerprint from the database library and, in response to receiving the reference EMI-KT fingerprint from the database library, analyzing the reference EMI-KT fingerprint to identify the set of frequencies. In one embodiment, the determined set of frequencies is selected as part of the process for creating the EMI-KT fingerprint of the reference device.

[0054] In one embodiment, a reference EMI-KT fingerprint is created. The system collects a reference EMI signal radiated by a reference utility device while the reference utility device undergoes a power test sequence. The reference EMI signal is received by an antenna (e.g., antenna 115) and processed by a radio (e.g., radio 120). The collected reference EMI signal is stored in local data storage 150 or data store 235 for further processing. The system converts the reference EMI signal from the time domain to the frequency domain, for example, by performing a fast Fourier transform (FFT) or other suitable transform on the collected reference EMI signal. The system divides or segments the frequency range associated with the collected reference EMI signal into multiple “bins,” with each individual bin represented by a representative frequency value. For example, the entire range of frequencies sensed by antenna 115 and radio 120, such as a range from about 500 kilohertz to about 4 gigahertz, may be divided into, for example, 100 bins. In one embodiment, these frequency bins and associated representative frequency values ​​are equally spaced. In one example, the representative frequency value is a frequency value in the middle of the bin's range, equidistant from the upper and lower frequency limits for the bin. In one embodiment, the bins and representative frequencies are stored in local data storage 150 or data store 235. The system then selects bins from the bins having representative frequencies that reflect the load dynamics resulting from the power test sequence for the reference utility device to form a set of frequencies from the representative frequencies for the bins.

[0055] In one embodiment, the set of frequencies may be the N frequencies among all reference frequencies that exhibit the most significant dynamics caused by the power test sequence, i.e., the "top" N frequencies. For example, the system may select a subset of N representative frequency values ​​associated with the strongest power spectral density peaks. Signals with the highest signal-to-noise ratios typically have the highest peaks on a power spectral density (PSD) plot. In one embodiment, a transform such as a fast Fourier transform (FFT) is performed on the amplitude-time series for each representative frequency. The representative frequencies are then ranked in order of the results of the transform, and the representative frequencies are further ranked in order of peak height. The N representative frequencies with the N highest peaks are selected. The system then sets the N frequencies to be a set of frequencies based on the power spectral frequency analysis.

[0056] It should be noted that while any number N of frequencies can be selected to reflect load dynamics, in one embodiment, the top nine frequencies (N=9) are selected because nine frequencies allow for a wide range of representative frequencies while maintaining a relatively small number of peaks when used to create a Kiviat plot. As the number of selected frequencies increases, the information usefulness benefits diminish, but the complexity of the Kiviat plot of frequency data increases along with the computational load for the operations involved. In practice, N=9 frequencies works well. N=20 bins is also sufficient and works well in practice, but results in a visually dense Kiviat plot when displaying the plot in a graphical user interface.

[0057] In one example of generating a reference EMI-KT fingerprint, the power amplitude values ​​of N frequencies at regular time intervals (observations) over the duration of the test sequence are represented as, for example, a series of tuples (t, value_F1, ..., value_F N ), e.g., as an array structure in a database. In one embodiment, the sequence of such tuples forms the reference EMI-KT fingerprint. In one embodiment, the sequence of plots of the tuples on a Kiviat plot having an axis for each of the N frequencies forms the reference EMI-KT fingerprint. In one embodiment, the axes of the Kiviat plot in the EMI-KT fingerprint are measured in decibels (dB).

[0058] In one embodiment, the highest representative frequency is frequency F NThe top N representative frequencies in terms of power amplitude are selected in ascending order of frequency value, such that the lowest representative frequency is selected as frequency F1, the next lowest representative frequency is selected as frequency F2, and so on, until the highest representative frequency in terms of power amplitude is selected as frequency F1, the next lowest representative frequency is selected as frequency F2, and so on. In one embodiment, conversely, the top N representative frequencies in terms of power amplitude are selected in descending order of frequency value. Note that in both cases, the power amplitude indicates which of the representative frequencies may be selected, and the frequency value indicates the order in which the selected frequencies are assigned. This is for visual clarity when visualizing the Kiviat plot, and the Kiviat plot The axes of may be labeled with their respective frequencies, making it visually meaningful to see them ordered in ascending or descending order.

[0059] Thus, upon completing the selection of a set of frequencies that reflect the load dynamics of the reference utility device while the system is undergoing a power test sequence, processing at process block 310 is complete and processing proceeds to process block 315.

[0060] At process block 315, the system acquires a target electromagnetic interference (EMI) signal emitted by the target utility device while undergoing a power test sequence. In one embodiment, the power test sequence is executed on the target utility device, causing the target utility device (such as device 130) to emit an EMI signal (such as EMI signal 110). In one embodiment, the power test sequence executed on the target device at process block 315 is the same power test sequence originally executed on the reference device to generate the reference EMI-KT fingerprint. In other words, the same test sequence is used to generate both the reference EMI-KT fingerprint and the target EMI-KT fingerprint.

[0061] The target EMI signal is received by an antenna (e.g., antenna 115) and processed by a radio (e.g., radio 120). The collected target EMI signal is stored in local data storage 150 or data store 235 for further processing. In one embodiment, the signal is stored as a tuple of time, frequency, and power amplitude values ​​(t, f, p). In one embodiment, the signal is stored in a flat-file dataset with columns for frequency and rows for observations (time), with power amplitude values ​​stored for each entry in the row-column. In one embodiment, the system converts the target EMI signal from the time domain to the frequency domain, for example, by performing a fast Fourier transform (FFT) or other suitable transform on the collected target EMI signal. In one embodiment, the observation rate may be one observation per second, although higher and lower rates may be selected based on the pace of transitions in the test sequence. In one embodiment, EMI signals are stored across the entire range of frequencies sensed by antenna 115 and radio 120, such as from about 500 kilohertz to about 4 gigahertz. In one embodiment, the EMI signals received for only N frequencies in the set of frequencies that reflect the load dynamics of the reference utility device are stored. Thus, in one embodiment, the EMI "noise" signals emanating from the utility device are processed into digitized multivariate time series data.

[0062] In one embodiment, the collection of the target EMI signals is performed as part of the acquisition step. In one embodiment, the collection of the target EMI signals from the target utility devices is performed before the acquisition step and is stored, for example, in local data storage 150 or data store 235. To acquire the target EMI signals, the stored target EMI signals are requested and then retrieved from local data storage 150 or data store 235.

[0063] Thus, once the system has completed acquiring the target EMI signal radiated by the target utility device while undergoing the power test sequence, processing at process block 315 is complete and processing proceeds to process block 320.

[0064] At process block 320, the system creates a sequence of target Kiviat plots from the amplitude of the target EMI signal for each set of frequencies in observation over the power test sequence to generate a target Kiviat tube EMI fingerprint (EMI -KT fingerprint). In one embodiment, to generate a sequence of target Kiviat plots, raw (observed) power amplitude values ​​of N frequencies for the target EMI signal are recorded at regular time intervals (observations) throughout the test sequence. In one embodiment, the time intervals applied to the target EMI signal should be aligned or synchronized with the time intervals applied to the reference EMI signal, thereby ensuring synchronization between the reference and target waveforms generated by the test sequence.

[0065] Similar to the generation of the reference EMI-KT fingerprint described above, the raw (observed) power amplitude values ​​for each frequency in the set of N frequencies are represented as a series of tuples (t, value_F1, ..., value_F N ), for example, as an array structure in a database (such as may be maintained in local data storage 150 or data store 235). In one embodiment, the sequence of such tuples forms the target EMI-KT fingerprint. In one embodiment, the sequence of plots of the tuples on a Kiviat plot with an axis for each of the N frequencies forms the target EMI-KT fingerprint. The fingerprint is stored, for example, in local data storage 150 or data store 235, for further processing.

[0066] In one embodiment, the creating step described with reference to process block 320 also includes generating amplitude estimates for each set of N frequencies by a state estimation model trained on the reference Kiviat tube EMI fingerprint. The resulting target Kiviat plot is a Kiviat plot of estimated values, rather than a plot of raw (observed) power amplitude values. In one embodiment, the creating step includes generating a state estimation model (e.g., an MSET model, an MSET2 model, or other model generated by a nonparametric pattern recognition algorithm) of the "true" behavior of the utility device, for example, by training an MSET model on the reference Kiviat plot of the reference Kiviat tube. While using MSET for pattern recognition purposes is advantageous, the disclosed embodiments can generally use any nonlinear, nonparametric (NLNP) regression, including neural networks, support vector machines (SVM), auto-associative kernel regression (AAKR), and even simple linear regression (LR). In one embodiment, MSE The T model is further trained with additional amplitude-time series information for frequencies other than those belonging to the selected set of frequencies, such as other frequencies within the bin to which the selected frequency belongs. For each observation, the raw (observed) target power amplitude values ​​at each of the N frequencies are fed into the trained MSET model to generate estimated target power amplitude values ​​for each of those N frequencies. The estimated target amplitude values ​​for each frequency are stored as amplitude values ​​in the target Kiviat plot for that observation, instead of the raw (observed) target amplitude values. Thus, the resulting Kiviat plot is not a series of Kiviat plots of the raw (observed) power amplitudes for each of the N frequencies, but rather a series of Kiviat plots of the MSET estimates of power amplitudes for each of the N frequencies. This raw-to-estimated substitution process has a smoothing effect that helps remove noise from the target EMI-KT fingerprint.

[0067] Once the system has completed creating a sequence of target Kiviat plots from the amplitude of the target EMI signal for each set of frequencies observed over the power test sequence to form the target Kiviat tube EMI fingerprint, processing at process block 320 is complete and processing proceeds to process block 325.

[0068] In process block 325, the system compares the target Kiviat tube EMI fingerprint with the reference Kiviat tube EMI fingerprint for the reference utility device undergoing the power test sequence to determine if the target utility device and the reference utility device are the same type.

[0069] In one embodiment, the reference Kiviat tube EMI fingerprint for the reference utility device is retrieved from a library database (such as may be maintained in local data storage 150 or data store 235). In one embodiment, the library database is maintained remotely, for example by cloud application infrastructure 225, in accordance with server-side logic 230, and REST requests requesting transmission of the reference EMI-KT fingerprint are constructed by EMI fingerprint counterfeit scanner 100 and sent to web interface server 220 via network interface 160. In one embodiment, the library database is maintained locally in accordance with logic 155 in local data storage 150, and requests to retrieve the reference EMI-KT fingerprint are constructed by EMI fingerprint counterfeit scanner 100.

[0070] In one embodiment, the target Kiviat plot values ​​and reference Kiviat plot values ​​for each observation of the target and reference Kiviat tubes are plotted on the same Kiviat plot. In one embodiment, the magnitude of the area between the target and reference plots for each observation is calculated and added to a cumulative sum of this magnitude over each time observation (i.e., the area is integrated along the time (observation) axis). The cumulative sum over all time observations is evaluated to determine whether the threshold test is met. Thus, by comparison, an error metric can be generated from the circular residuals between the target and reference Kiviat plots for the same observation in the reference Kiviat tube EMI fingerprint. In this case, the error metric is the cumulative area of ​​the circular residuals between the reference and target Kiviat plots over all observations. Generally, a match between the target and reference plots indicates that the target and reference devices behave similarly in response to the same test sequence, so an error metric (cumulative area) value below the threshold would indicate that the target and reference devices are the same type. Similarly, differences between the target and reference plots indicate that the target and reference devices behave differently in response to the same test sequence, so an error metric (cumulative area) value higher than the threshold value would indicate that the target and reference devices are of different types.

[0071] Thus, in one embodiment, for each time observation of the Kiviat tube, the residual area between the Kiviat plots of EMI signal strength at optimally selected representative frequencies for the reference (golden system) and the target (unit under test) is integrated over time to generate a residual volume for the Kiviat tube. The residual volume of the target EMI-KT fingerprint can be used as a prognostic metric to determine whether the target EMI-KT fingerprint represents a true or suspect utility device by comparison to a threshold value.

[0072] In one embodiment, the threshold is a pass / fail magnitude generated by comparing the reference EMI-KT fingerprint with target EMI-KT fingerprints obtained from one or more other utility devices certified to be of the same configuration as the reference utility device, or with EMI-KT fingerprints obtained repeatedly from the same reference device. The threshold is a pass / fail magnitude for each of these comparisons within a range of magnitudes that satisfies the threshold test. In one embodiment, the maximum error metric value across multiple fingerprint comparisons may be set as the threshold, where an error metric value above the threshold will not satisfy the threshold test. In one embodiment, a small additional margin, such as 5 or 10 percent of the maximum error metric, may be added to the maximum error metric, and the resulting sum may be set as the threshold.

[0073] In one embodiment, the comparison also includes normalizing each axis of each target Kiviat plot to a unit circle that passes through the values ​​plotted on that axis in the corresponding reference Kiviat plot for the same observation in the reference Kiviat tube EMI fingerprint. In this manner, each of the N frequency axes of the target Kiviat plot is adjusted so that the unit circle can simultaneously pass through each of the N power amplitude values ​​of the reference Kiviat plot. For example, in a three-frequency target plot where the reference plot for the same time has a power amplitude of 20 dB at frequency 1, a power amplitude of 30 dB at frequency 2, and a power amplitude of 10 dB at frequency 3, the axes of the target plot can be adjusted or normalized so that each of these reference power amplitude values ​​falls on the unit circle, and the amplitude values ​​of the target plot would be plotted on these normalized axes.

[0074] In one embodiment, the normalized target Kiviat plot for each observation is compared to a unit circle. In one embodiment, the magnitude of the area between the target Kiviat plot on the normalized axis and the unit circle is calculated and added to a cumulative sum of this magnitude during each observation (i.e., the area is integrated along the time (observation) axis). This area integrated over each observation (time point) during the duration of the test sequence may be referred to as the cumulative cylindrical error metric (CCEM). Thus, the CCEM is a measure of the difference between the reference (golden system) EMI-KT fingerprint and the target (unit under test) EMI-KT fingerprint. The CCEM is evaluated to determine whether it satisfies a threshold test. As described above, a match between the target plot and the unit circle indicates that the target and reference devices behave similarly in response to the same test sequence, and a CCEM value below the threshold indicates that the target and reference devices are the same type. Also, as noted above, differences between the target plot and the unit circle indicate that the target and reference devices behave differently in response to the same test sequence, and CCEM values ​​higher than the threshold indicate that the target and reference devices are of different types.

[0075] Therefore, the comparison also includes generating an error metric, such as CCEM, from the circular residual between the target Kiviat plot and a unit circle on an axis normalized to represent the corresponding reference Kiviat plot at the same observation in the reference Kiviat tube EMI fingerprint as a unit circle. The error metric is the cumulative area of ​​the circular residual between the unit circle and the target Kiviat plot across all observations. Thus, the system generates a cumulative cylindrical error metric across all observations of the target Kiviat tube EMI fingerprint and the reference Kiviat tube EMI fingerprint.

[0076] The CCEM metric allows for the detection of abnormal and true components for utility devices operating at all different types of power levels by normalizing the decibel values ​​of the N reference frequencies for each observation. Thus, thresholds need not be defined based on the configuration of the reference utility device, but can instead be based on deviations from the unit circle. A universal threshold test for CCEM can then be applied to all utility devices, regardless of power level. In one embodiment, a threshold of approximately 10 works well in practice. In another embodiment, a threshold between 10 and 30 (inclusive) works well in practice.

[0077] In one embodiment, this comparison of the target Kiviat tube EMI fingerprint with the reference Kiviat tube EMI fingerprint may be performed locally, for example, on EMI fingerprint counterfeit scanner 100 implementing high sensitivity EMI Kiviat tube counterfeit component detection and identification logic 155. In one embodiment, this comparison may be performed remotely in response to a request (e.g., a REST request) or transmission of the target Kiviat tube by EMI fingerprint counterfeit scanner 100 to a remote system (e.g., cloud application infrastructure 225 implementing server-side high sensitivity EMI Kiviat tube counterfeit component detection and identification logic 230).

[0078] Once the system has completed comparing the target Kiviat tube EMI fingerprint with the reference Kiviat tube EMI fingerprint for the reference utility device undergoing the power test sequence to determine whether the target utility device and the reference utility device are of the same type, processing at process block 325 is complete and processing proceeds to process block 330.

[0079] At process block 330, the system generates a signal to indicate counterfeit status based at least in part on the results of the comparison. In one embodiment, the system determines a reference type of the reference EMI-KT fingerprint. Note that method 300 can be applied to both identifying a target utility device as genuine or a suspected counterfeit, and identifying a target utility device as a confirmed counterfeit for a known or unknown type of device by comparing the target device with the reference EMI-KT fingerprint for an authenticated genuine utility device or for each known configuration of the counterfeit device. Thus, the reference EMI-KT fingerprint of the reference type can be either a reference EMI-KT fingerprint for a “genuine device” or a reference EMI-KT fingerprint for a “known counterfeit.” The system then configures a signal indicating the result of a threshold test of the error metric in the context of the reference EMI-KT fingerprint for the reference type.

[0080] For example, if the reference utility device is a genuine utility device of a particular type, in response to determining (i) (via a threshold test) that the target utility device and the reference utility device are the same type (the threshold test is satisfied), the system can generate a signal to indicate that the target utility device is confirmed to be genuine, and in response to determining (ii) that they are not the same type (the threshold test is satisfied), the system can generate a signal to indicate that the target utility device is a suspected counterfeit. Or, for example, if the reference utility device is a known counterfeit utility device of a particular type, in response to determining (i) (via a threshold test) that the target utility device and the reference utility device are the same type (the threshold test is satisfied), the system can generate a signal to indicate that the target utility device is confirmed to be a counterfeit device of the particular type, and in response to determining (ii) that they are not the same type (the threshold test is not satisfied), the system can generate a signal to indicate that the target utility device is not a counterfeit device of the particular type.

[0081] In one embodiment, the counterfeit status may be displayed as a visual alert presented on a graphical user interface, such as the proof of authenticity 465 illustrated and described with reference to FIG. 4 and the counterfeit alarm 565 illustrated and described with reference to FIG. 5.

[0082] In one embodiment, the system simply generates a signal indicating the result of a threshold test of the error metric. The signal is then stored in local storage or transmitted to a display device or remote system for further use.

[0083] Once the system has completed generating a signal to indicate counterfeit status based at least in part on the results of the comparison, processing at process block 330 is complete and processing proceeds to end block 335 where process 300 ends.

[0084] -Counterfeit Analysis System- In one embodiment, the counterfeit status indication resulting from method 300 may be further enhanced by a counterfeit analysis system, such as cloud application infrastructure 225, as controlled by counterfeit analysis logic 233. For example, in response to a signal that a target utility device is a suspected counterfeit, the system may transmit the target Kiviat EMI fingerprint to the counterfeit analysis system along with a signal indicating that the utility device is a suspected counterfeit. For example, EMI fingerprint counterfeit scanner 100 may construct a request, such as a REST request, indicating that the target Kiviat EMI fingerprint is a suspected counterfeit and transmit the request along with the target Kiviat EMI fingerprint from network interface 160 to web interface server 220. In response to receiving the request, counterfeit analysis logic 233 may further process the target Kiviat EMI fingerprint and associated information.

[0085] In one embodiment, the request sent to the counterfeit analysis system may include additional supply chain information about the target device. The supply chain information may include any information available to the system about how the target utility device was constructed and how it progressed to the testing location. This supply chain information and the target EMI-KT fingerprint may be sent to the counterfeit analysis system for storage (in data store 235), analysis (by counterfeit analysis logic 233), and future reference by scanning other target utility devices (as a reference EMI-KT fingerprint in a library database).

[0086] Analysis of the target EMI-KT fingerprint (and supply chain information, if any) by the counterfeit analysis logic 233 may generate additional information that may be useful to one or more users of the system. For example, after sending a request to the counterfeit analysis system in response to a signal indicating that the target utility device is a suspected counterfeit, the system may receive from the counterfeit analysis system additional information regarding the suspected counterfeit configuration, such as one or more of: (i) confirmation that the suspected counterfeit is a known type of counterfeit; (ii) prevalence information describing how widespread utility devices with the suspected counterfeit configuration are; (iii) source information describing the origin of the utility device with the suspected counterfeit configuration; and / or (iv) supply chain information describing how the target device may have entered the supply chain. Item (i) may be based on performing method 300, which compares the suspected counterfeit target EMI-KT fingerprint with one or more known counterfeit reference EMI-KT fingerprints until a match is found or until the known counterfeit reference EMI-KT fingerprints available to the counterfeit analysis system are exhausted. Items (ii)-(iv) may be based on analyzing information provided by only a single tenant of the counterfeit analysis system or across information provided by multiple tenants. In one embodiment, in response to receiving the additional information, EMI fingerprint counterfeit scanner 100 (or another computing device (not shown) connected to cloud application infrastructure 225) may display some or all of the additional information on a graphical user interface such as those illustrated and described with reference to FIGS. 4 and 5.

[0087] -Graphical user interface for displaying results- In one embodiment, the system further displays information based at least in part on the signal using a graphical user interface. The displayed information may also be based on the reference EMI-KT fingerprint and the target EMI-KT fingerprint.

[0088] 4 illustrates one embodiment of a graphical user interface (GUI) 400 associated with verifying to a user that a target utility device is authentic using an EMI frequency Kiviat tube. In one embodiment, GUI 400 shows a Kiviat tube analysis in which the target device (unit under test) has all real components and the target EMI-KT fingerprint exhibits only minor deviations from perfect roundness.

[0089] The GUI 400 includes a 3D visualization of an exemplary reference (golden system) Kiviat tube 405 and a 3D visualization of an exemplary target (unit under test) Kiviat tube 410. The GUI 400 also includes an instantaneous 2D Kiviat multivariate prognostic health profile visualization, including a 2D visualization of one exemplary reference Kiviat plot 415 (reference (golden sample) Kiviat EMI-authenticity prognosis) from the exemplary reference Kiviat tube 405 and a 2D visualization of one exemplary target Kiviat plot 420 (target (unit under test) Kiviat EMI-authenticity prognosis) from the exemplary target Kiviat tube 410. The exemplary Kiviat plot of the exemplary Kiviat tube is configured to represent power amplitudes at N=9 frequencies F1, F2, F3, F4, F5, F6, F7, F8, and F9 in discrete observations along the time axis of the exemplary Kiviat tube. The location of the exemplary reference Kiviat plot 415 within the exemplary reference Kiviat tube 405 is indicated by the bold reference Kiviat plot 425 at observation t=5. The location of the exemplary target Kiviat plot 420 within the exemplary target Kiviat tube 410 is indicated by the bold target Kiviat plot 430 at observation t=5. The power amplitude values ​​along each frequency axis of the exemplary reference Kiviat plot 415 at observation t=5 are indicated by the vertices of the reference area 435 at the intersections with the axes of the exemplary reference Kiviat plot 415. The power amplitude values ​​along each frequency axis of the exemplary target Kiviat plot 420 at observation t=5 are indicated by the vertices of the target area 440 at the intersections with the axes of the exemplary reference Kiviat plot 420.

[0090] In one embodiment, GUI 400 also includes an anomaly detector Kiviat plot 445. The anomaly detector Kiviat plot shows a normalized unit circle 450, shown in dashed lines, and a normalized target outline 455 of the target area 440, shown in solid lines. As described above with reference to process block 325, the axes of the anomaly detector Kiviat plot 445 are adjusted or normalized so that the power amplitude values ​​along each axis (the vertices of the reference area 435) of the example reference Kiviat plot 415 lie on the intersection of the unit circle 450 with the respective axis. Thus, the target area 440 is normalized to the unit circle 450 in the anomaly detector Kiviat plot 445, as shown by the normalized target outline 455. Note that the normalized target outline 455 and the unit circle 450 closely match, indicating that the target device and the reference device behave similarly for all frequencies at the same time of observation in the test sequence. The area (magnitude or absolute value) of the circular residual between the unit circle for each observation and the normalized target contour for each observation is calculated. The area of ​​the circular residual is integrated from the initial observation (t=0) to the current observation (in the illustrated example, at 425, 430, the current observation is t=5) to determine the cumulative cylindrical error metric (CCEM) 460 at the current observation. The CCEM is calculated by multiplying the area of ​​the circular residual by the reference Kiviat tube and the target Kiviat tube pair for the M total observations. For a Kiviat tube, the observations will grow cumulatively as they progress from observation t=0 to observation t=M. The final CCEM at t=M is ​​the area of ​​the circular residual integrated over all M observations. In one embodiment, while the CCEM continues to satisfy a threshold test indicating that the exemplary reference Kiviat tube 405 and the exemplary target Kiviat tube 410 are for target devices with similar configurations, the GUI 400 receives a signal to display the proof of authenticity 465. In one embodiment, continually displaying the proof of authenticity 465 with the final CCEM at observation t=M indicates that the target device is certified as authentic, genuine, or free of counterfeit components. In one embodiment, the proof of authenticity 465 is not presented on the GUI 400 until observation t=M is ​​reached. In one embodiment, the proof of authenticity 465 may take the form of a large green icon indicating that the target utility device is "genuine," "true," or "verified," or other language indicating that the target EMI-KT fingerprint for the target utility device matches the reference EMI-KT fingerprint for the genuine item.

[0091] In one embodiment, GUI 400 is configured to present a reference Kiviat plot and a target Kiviat plot for each observation location along the Kiviat tube in an animated sequence in response to a user command to present the animated sequence. GUI 400 sequentially displays each pair of reference and target Kiviat plots as the observations progress from observation t=0 to observation t=M for a pair of reference and target Kiviat tubes with M total observations. As each pair of reference and target Kiviat plots is sequentially displayed, the respective locations of the Kiviat plots within the reference and target Kiviat tubes are highlighted, as shown with reference to bolded Kiviat plots 425 and 430. Highlighting may be achieved, for example, by a change in color, transparency, size or shape, border thickness, or border line. In one embodiment, GUI 400 is configured to step forward or backward through the observations in response to a user command to step forward or backward. In response to a command to go forward or backward, respectively, the GUI 400 (i) displays a pair of reference and target Kiviat plots in the healthy outline visualization, and (ii) removes emphasis from the current observation in the exemplary Kiviat canal and highlights the location of the pair of reference and target Kiviat plots in the healthy outline visualization. In one embodiment, the GUI 400 is configured to jump directly to a selected observation in the exemplary Kiviat canal in response to a user command to select an observation. In response to the jump command, a pair of reference and target Kiviat plots at the selected observation is displayed, and the emphasis in the Kiviat canal is transferred to the selected pair. In one embodiment, the user input may include a keystroke or mouse click input.

[0092] 5 illustrates one embodiment of a graphical user interface 500 associated with alerting a user to counterfeit components in a target utility device using an EMI frequency Kiviat tube. In one embodiment, GUI 500 illustrates a Kiviat tube analysis in which a target device (unit under test) has at least one counterfeit component, where the target EMI-KT fingerprint exhibits significant deviation from roundness.

[0093] The GUI 500 includes a 3D visualization of an exemplary reference (golden system) Kiviat tube 405 for a potentially counterfeit target device, and a 3D visualization of an exemplary suspect target (unit under test) Kiviat tube 510. The GUI 500 also includes a 2D visualization of an exemplary reference Kiviat plot 415 (Reference (Golden Sample) Kiviat EMI - Authenticity Prognosis) from the exemplary reference Kiviat tube 405, and an exemplary 5 includes an instantaneous 2D Kiviat multivariate prognostic health profile visualization, including a 2D visualization of one exemplary suspected target Kiviat plot 520 (Target (Unit Under Test) Kiviat EMI - Authenticity Prognosis) from an exemplary suspected target Kiviat tube 510. The location of the exemplary suspected target Kiviat plot 520 within the exemplary suspected target Kiviat tube 510 is indicated by the bold target Kiviat plot 530 at observation t=5. The power amplitude values ​​along each frequency axis of the exemplary suspected target Kiviat plot 520 at observation t=5 are indicated by the vertices of the target area 440 at the intersections with the axes of the exemplary reference Kiviat plot 520.

[0094] In one embodiment, GUI 500 also includes anomaly detector Kiviat plot 545. The anomaly detector Kiviat plot shows a normalized unit circle 450, shown in dashed lines, and a normalized suspect target outline 555 of target area 540, shown in solid lines. As described above with reference to anomaly detector Kiviat plot 445 and process block 325, suspect target area 540 is normalized to unit circle 450 in anomaly detector Kiviat plot 545, as shown by normalized target outline 555. Note that normalized suspect target outline 555 and unit circle 450 diverge, indicating that the target device and reference device behave differently when observed at the same time in a test sequence. The area of ​​the circular residual between the unit circle and the normalized suspect target outline for each observation is integrated from the initial observation (t=0) to the current observation (t=5 as shown in the figure) to determine a cumulative cylindrical error metric (CCEM) 560 at the current observation. The CCEM will grow cumulatively as the observations progress from observation t=0 to observation t=M for a pair of reference and target Kiviat tubes for M total observations. The final CCEM at t=M is ​​the area of ​​the circular residual integrated over all M observations. In one embodiment, if the CCEM does not satisfy a threshold test indicating that the example reference Kiviat tube 405 and the example suspect target Kiviat tube 510 are for target devices with different configurations, the GUI 500 receives a signal to display a counterfeit alarm 565. In one embodiment, displaying a counterfeit alarm 565 at any time prior to the final CCEM at observation t=M indicates that the target device is a potential counterfeit device suspected of having one or more counterfeit components. In one embodiment, the counterfeit alarm 565 is not presented on the GUI 500 until observation t=M is ​​reached.In one embodiment, the counterfeit alarm 565 may take the form of a large red icon, possibly shaped like an octagon, suggesting the form of a stop sign indicating that the target utility device is "counterfeit," "suspect," or "not verified," or may take the form of other language indicating that the target EMI-KT fingerprint for the target utility device does not match the reference EMI-KT fingerprint for the genuine item.

[0095] In this manner, a display device (such as display 160) may be configured to present an icon indicating that the target utility device is (i) genuine in response to a signal indicating a counterfeit status for a genuine item, and (ii) a suspected counterfeit in response to a signal indicating a counterfeit status for a suspected counterfeit item.

[0096] -An exemplary method using a display- 6 illustrates one embodiment of a method 600 related to sensitive detection and identification indication of counterfeit components in utility power systems using EMI frequency Kiviat tubes. Method 600 is a method for indicating the counterfeit status (e.g., the status of being authentic or the status of including at least one counterfeit component) of a target utility device.

[0097] Method 600 may be initiated based on various triggers, such as, for example, (i) a user (or administrator) of EMI fingerprint counterfeit scanner 100 initiating method 600 by providing a signal indicating the start of a scan using EMI fingerprint counterfeit scanner 100, (ii) method 600 being scheduled to begin at a defined time or time interval, (iii) a target utility device being in place and ready to be scanned, or (iv) some other trigger indicating method 600 should begin, such as receiving a signal over a network or analyzing stored data. Method 600 begins at start block 605 in response to a determination that the received analyzed signal or retrieved stored data indicates that method 600 should begin. Processing continues to process block 610.

[0098] At process block 610, the system selects the nine best frequencies for the reference device (golden sample) in ascending order. In one embodiment, the selection of the nine best frequencies is performed by the system as illustrated and described with reference to process block 310 of Figure 3. Processing at process block 610 is then complete and processing proceeds to process block 615. Additionally, processing may proceed to process block 620.

[0099] At process block 615, the system generates a reference device (golden sample) Kiviat tube. In one embodiment, the generation of the reference device Kiviat tube is performed by a system as illustrated and described with reference to process block 310, or in a manner similar to that illustrated and described for the target EMI-KT fingerprint with reference to process blocks 315 and 320. Processing at process block 615 is then complete, and processing proceeds to decision block 625.

[0100] At process block 620, the system selects each frequency for the target device (unit under test) in ascending order. In one embodiment, the system selects the same frequencies as those selected for the reference device at process block 610. In one embodiment, the system analyzes a reference (golden sample) Kiviat tube (reference EMI-KT fingerprint) to extract the frequencies. Processing at process block 620 is then complete and processing proceeds to process block 630.

[0101] At process block 630, the system generates a target device (unit under test) Kiviat tube. In one embodiment, the generation of the target device Kiviat tube is performed by the system in a manner similar to that illustrated and described for the reference EMI-KT fingerprint with reference to process block 310, or as illustrated and described with reference to process blocks 315 and 320. Processing at process block 630 is then complete, and processing proceeds to decision block 625.

[0102] At decision block 625, the system determines whether the current observation is less than or equal to the total number of observations for the Kiviat tube. In one embodiment, a loop is initiated for comparing and GUI displaying the target EMI-KT fingerprint and the reference EMI-KT fingerprint. The current observation is initialized to the value of the first observation in the Kiviat tube for the test sequence (applicable to both the reference and target Kiviat tubes). The initial value is typically 0 or 1, although other values ​​may be appropriate. The total number of observations in the Kiviat tube (applicable to both the reference and target Kiviat tubes) is identified, for example, by analyzing one of the Kiviat tubes to extract the total number of observations. If the current observation is less than or equal to the total number of observations (TRUE), processing at decision block 625 is complete, and processing continues by: (i) determining whether this If a reference device (golden sample) Kiviat plot has not yet been generated for this observation, proceed to process block 635; and (ii) if a reference device Kiviat plot has been generated for this observation, proceed directly to process block 640. If the current observation is greater than the total number of observations (FALSE), processing at decision block 625 is complete and processing proceeds to end block 645.

[0103] At process block 635, the system generates a reference device (golden system) Kiviat plot. In one embodiment, the system retrieves a tuple describing the reference Kiviat plot for the current observation from a data structure in memory. The system parses the tuple to extract the power amplitude values ​​of the plot for each frequency. The system generates a Kiviat plot displaying the extracted power amplitude values ​​on each axis. The system stores the generated Kiviat plot in memory and / or generates instructions to cause display 165 to display the generated Kiviat plot in a GUI, such as GUI 400. In one embodiment, process block 635 may be bypassed if the reference device Kiviat plot has been previously generated and stored in memory for immediate retrieval. Processing at process block 635 is then complete, and processing proceeds to process block 640.

[0104] At process block 640, the system generates a target device (unit under test) Kiviat plot. In one embodiment, the system retrieves from a data structure in memory a tuple describing the target Kiviat plot for the current observation. The system parses the tuple to extract the power amplitude values ​​of the plot for each frequency. The system generates a Kiviat plot displaying the extracted power amplitude values ​​on each axis. The system stores the generated Kiviat plot in memory and / or generates instructions to cause display 165 to display the generated Kiviat plot in a GUI, such as GUI 400. Processing at process block 640 is then complete, and processing proceeds to process block 650.

[0105] At process block 650, the system generates a Kiviat plot with a normalized circle for the reference device (golden sample). In one embodiment, the system retrieves from a data structure in memory a tuple describing the reference Kiviat plot for the current observation. The system parses the tuple to extract a reference power amplitude value for the plot for each frequency. The system calculates an adjustment to the magnitude of each axis of the Kiviat plot to allow the unit circle for the current observation to intersect each axis at the reference power amplitude value extracted along that respective axis. The system plots the unit circle on the adjusted (normalized) Kiviat plot. The system retrieves from a data structure in memory a tuple describing a target Kiviat plot for the current observation. The system parses the tuple to extract a target power amplitude value for the plot for each frequency. The system plots the target power amplitude values ​​on the adjusted (normalized) Kiviat plot to form a normalized target Kiviat plot for the current observation. The system stores the normalized target Kiviat plot along with the unit circle in memory and / or generates instructions to cause display 165 to display the normalized target Kiviat plot along with the unit circle in a GUI such as GUI 400. Processing at process block 650 is complete and processing proceeds to process block 655.

[0106] At process block 655, the system calculates the area of ​​the circular residual between the target device (unit under test) and the reference device (golden sample) integrated along the time axis. In one embodiment, the system calculates the area of ​​the circular residual between the unit circle for the observation at that time and the normalized target Kiviat plot for the observation at that time. The magnitude (absolute value) is calculated. To integrate the area along the time axis, the system adds the calculated area for the current observation to the cumulative sum of the calculated areas for all previous observations to form a cumulative cylindrical error metric (CCEM) for the current observation. The system stores the CCEM in memory and / or generates instructions to cause display 165 to display the CCEM in a GUI, such as GUI 400. Processing at process block 655 is then complete and processing proceeds to decision block 660.

[0107] At process block 660, the system determines whether the cumulative cylindrical error metric (CCEM) is less than or equal to a threshold value. In one embodiment, the determination of whether the CCEM for the current observation satisfies the threshold test is performed as illustrated and described with reference to process block 325. The result of the threshold test may be stored in memory and / or used by the system to generate a signal indicative of the counterfeit status of the target device. If the CCEM is less than or equal to the threshold value (TRUE), processing at decision block 660 is complete and processing proceeds to process block 665. If the CCEM is greater than the threshold value (FALSE), processing at decision block 660 is complete and processing proceeds to process block 670.

[0108] At process block 665, the system causes a graphical user interface to display that the target device (unit under test) has been authenticated as authentic. In one embodiment, the system generates and executes the display as illustrated and described with reference to process block 330. Processing at process block 665 is then complete and processing proceeds to process block 675.

[0109] At process block 670, the system causes a graphical user interface to display an alarm that the target device (unit under test) may be counterfeit. In one embodiment, the system generates and executes the display as illustrated and described with reference to process block 330. Processing at process block 670 is then complete and processing proceeds to process block 675.

[0110] At process block 675, the system increments the observation count. In one embodiment, the system adds one to the current observation count and stores the incremented observation count in memory for future reference. Note that the observations may be, but need not be, evenly spaced and may be in standard time increments such as seconds, milliseconds, or other units. Processing at process block 675 is then complete and processing returns to decision block 625.

[0111] Processing repeats from decision block 625 to process block 675 while the current observation count is less than or equal to the total observation count (TRUE at decision block 625) until the current observation count is incremented to be greater than the total observation count (FALSE at decision block 625). At this point, processing proceeds to end block 645, where processing terminates.

[0112] Each of the items generated by method 600 may be stored in memory for later retrieval and display in a GUI such as GUI 400. The generated items may be stored in local data storage 150 or stored remotely in data store 235. These items may be retrieved for display in response to input to a GUI such as illustrated and described with reference to FIGS.

[0113] -Selected Benefits- In one embodiment, the methods and systems described herein provide highly effective detection tools for counterfeit utility devices. When properly employed, the methods and systems described herein can detect the presence of counterfeit electronic components in utility devices nearly 100% of the time. Furthermore, in one embodiment, the tools are easy to use even for non-experts. The tools enable (i) personnel involved in utility acceptance testing of components from the supply chain and (ii) personnel involved in inspecting systems being shipped at points of entry and other national and multi-national borders to autonomously perform accurate counterfeit detection and identification so that they can quickly identify utility devices with counterfeit components therein or certify utility devices as having all genuine components. These personnel do not need to be experts in EMI emissions, data science, machine learning, or counterfeit detection techniques to receive these benefits from the use of the systems and methods described herein.

[0114] In one embodiment, the methods and systems described herein further enable law enforcement agencies to identify the exact make, model, and / or implementation of counterfeit utility devices using the unique EMI-KT fingerprint, enabling them to trace counterfeit utility devices back through the supply chain to their source. The systems and methods described herein enable accurate and unambiguous identification of internal counterfeit components within utility power devices by persistently and foolproofly identifying the precise lineage specific to the supplier of the counterfeit. Correlation of this data with the EMI-KT fingerprint enables data analysis to accurately (i) assess the prevalence of counterfeit devices within the supply chain (the magnitude of a particular counterfeiting problem) and (ii) trace the lineage of counterfeit devices and components back through the supply chain to identify and shut down suppliers of the counterfeit components.

[0115] The advantages described herein are achieved by the high sensitivity provided by the methods and systems described herein, for example, by EMI-KT fingerprinting. The methods and systems described herein have not been or could be performed by humans before, and thus are not computerized versions of existing human-implemented processes.

[0116] -Cloud or Enterprise Implementation- In one embodiment, the cloud application infrastructure 225 and / or other systems illustrated and described herein are computing / data processing systems that include an application or collection of distributed applications for an enterprise organization. Application and data processing systems include cloud-based networking systems, software as a service (SaaS) systems, and other cloud-based applications. The cloud computing system may be configured to operate with or implemented as a cloud computing architecture, or other type of networked computing solution. In one embodiment, the cloud computing system is a server-side system that provides one or more of the functionality disclosed herein and is accessible by many users via EMI fingerprint counterfeit scanner 100 or other client computing devices that communicate with the cloud computing system (acting as a server) over a computer network.

[0117] -Computing Device Embodiment- 7 illustrates an example computing device 700 configured and / or programmed with one or more of the example systems and methods described herein and / or the like. The example computing device is operated by a bus 725. The computer 705 may include a processor 710, a memory 715, and input / output ports 720 operably connected thereto. In one example, the computer 705 may include high sensitivity EMI Kiviat tube counterfeit component detection and identification logic 730 configured to facilitate high sensitivity detection and identification of counterfeit components in utility power systems employing EMI frequency Kiviat tubes similar to the logic and systems shown in FIGS. 1-6 . In various examples, the logic 730 may be implemented in hardware, a non-transitory computer-readable medium having instructions stored thereon, firmware, and / or combinations thereof. While the logic 730 is shown as a hardware component attached to the bus 725, it should be appreciated that in other embodiments, the logic 730 may be implemented within the processor 710, stored in the memory 715, or stored in the disk 735.

[0118] In one embodiment, the logic 730 or computer is a means (e.g., structure: hardware, non-transitory computer-readable medium, firmware) for performing the described operations. In some embodiments, the computing device may be a server operating in a cloud computing system, a server configured in a Software as a Service (SaaS) architecture, a smartphone, a laptop, a tablet computing device, etc.

[0119] The means may be implemented as an ASIC programmed for sensitive detection and identification of counterfeit components in utility power systems using EMI frequency Kiviat tubes, for example. The means may also be implemented as stored computer-executable instructions presented to computer 705 as data 740 that are temporarily stored in memory 715 and then executed by processor 710.

[0120] The logic 730 may also provide means (e.g., hardware, non-transitory computer-readable media storing executable instructions, firmware) for performing sensitive detection and identification of counterfeit components in utility power systems that use EMI frequency Kiviat tubes.

[0121] Generally describing an exemplary configuration of computer 705, processor 710 may be a wide variety of processors, including dual microprocessors and other multi-processor architectures. Memory 715 may include volatile memory and / or non-volatile memory. Non-volatile memory may include, for example, ROM, PROM, etc. Volatile memory may include, for example, RAM, SRAM, DRAM, etc.

[0122] The storage disk 735 may be operatively connected to the computer 700, for example, via an input / output (I / O) interface (e.g., card, device) 745 and an input / output port 720. The disk 735 may be, for example, a magnetic disk drive, a solid-state disk drive, a floppy disk drive, a tape drive, a Zip drive, a flash memory card, a memory stick, etc. Additionally, the disk 735 may be a CD-ROM drive, a CD-R drive, a CD-RW drive, a DVD ROM, etc. The memory 715 may store, for example, processes 750 and / or data 740. The disk 735 and / or memory 715 may store an operating system that controls and allocates resources of the computer 705.

[0123] The computer 705 can interact with input / output (I / O) devices via an I / O interface 745 and input / output ports 720. Input / output devices include, for example, a keyboard 780, a microphone 784, a pointing and selection device 782, a camera 78 6, video card, display 770, scanner 788, printer 772, speakers 774, disk 735, network device 755, etc. The input / output ports 720 may include, for example, serial ports, parallel ports, and USB ports. The input / output devices may include a software-defined radio 790 and associated antenna 792.

[0124] The computer 705 can operate in a networked environment and, as such, can be connected to a network device 755 via the I / O interface 745 and / or the I / O port 720. The computer 705 can interact with a network 760 through the network device 755. The computer 705 can be logically connected to a remote computer 765 through the network 760. Networks with which the computer 705 can interact include, but are not limited to, a LAN, a WAN, and other networks.

[0125] -Definitions and Other Embodiments- In another embodiment, the described methods and / or their equivalents may be implemented using computer-executable instructions. Thus, in one embodiment, a non-transitory computer-readable / storage medium is configured to store computer-executable instructions for an algorithm / executable application that, when executed by a machine, causes the machine (and / or associated components) to perform the method. Exemplary machines include, but are not limited to, processors, computers, servers operating in a cloud computing system, servers configured in a Software as a Service (SaaS) architecture, smartphones, etc. In one embodiment, a computing device is implemented with one or more executable algorithms configured to perform any of the disclosed methods.

[0126] In one or more embodiments, the disclosed methods or their equivalents are performed by computer hardware configured to perform the methods or by computer instructions embodied in modules stored on a non-transitory computer-readable medium, where the instructions are configured as an executable algorithm configured to perform the methods when executed by at least a processor of a computing device.

[0127] For simplicity of explanation, the example method shown in the figures is illustrated and described as a series of algorithmic blocks, but it should be understood that the method is not limited by the order of the blocks. Some blocks may occur in a different order than illustrated and described and / or concurrently with other blocks. Furthermore, fewer than all of the illustrated blocks may be used to implement the example method. Blocks may be combined or separated into multiple actions / components. Furthermore, additional and / or alternative methods may use additional actions not shown in the blocks.

[0128] The following contains definitions of selected terms used herein. The definitions include various examples and / or forms of components that fall within the scope of the term and that may be used for implementation. These examples are not intended to be limiting. Both singular and plural forms of a term may be within the scope of the definition.

[0129] When referring to "one embodiment," "an embodiment," "an example," "an example," or the like, it is intended to mean that the embodiment or example so described may include a particular feature, structure, characteristic, property, element, or limitation, but not all embodiments or examples necessarily include that particular feature, structure, property, element, or limitation. Furthermore, repeated use of the phrase "in one embodiment" does not necessarily refer to the same embodiment, but may include, but is not limited to, the following:

[0130] ASIC: Application Specific Integrated Circuit CD: Compact Disc CD-R: Recordable CD CD-RW: Rewritable CD DVD: Digital Versatile Disc and / or Digital Video Disc LAN: Local Area Network RAM: Random Access Memory DRAM: Dynamic RAM SRAM: Synchronous RAM ROM: Read-only memory PROM: Programmable ROM EPROM: Erasable PROM EEPROM: Electrically Erasable PROM USB: Universal Serial Bus XML: Extensible Markup Language WAN: Wide Area Network As used herein, a "data structure" is an organization of data within a computing system that is stored in memory, a storage device, or other computerized system. A data structure may be, for example, any one of a data field, a data file, a data array, a data record, a database, a data table, a graph, a tree, a linked list, etc. A data structure may be formed from and may contain many other data structures (e.g., a database contains many data records). Other examples of data structures are possible according to other embodiments.

[0131] As used herein, "computer-readable medium" or "computer storage medium" refers to a non-transitory medium that stores instructions and / or data that, when executed, are configured to perform one or more of the disclosed functions. Data may function as instructions in some embodiments. Computer-readable media may take forms including, but not limited to, non-volatile media and volatile media. Non-volatile media may include, for example, optical disks, magnetic disks, and the like. Volatile media may include, for example, semiconductor memory, dynamic memory, and the like. Common forms of computer-readable media are floppy disks, flexible disks, hard disks, magnetic tape, other magnetic media, application specific integrated circuits (ASICs), Programmable logic devices, compact disks (CDs), other optical media, random access memory (RAM), read-only memory (READ-ONLY MEMORY) These media may include, but are not limited to, read only memory (ROM), memory chips or cards, memory sticks, solid state storage devices (SSDs), flash drives, and other media on which a computer, processor, or other electronic device can function. When selected for implementation in an embodiment, each type of media may include stored instructions for an algorithm configured to perform one or more of the disclosed and / or claimed functions.

[0132] As used herein, "logic" refers to the instructions of computer or electrical hardware, executable applications or program modules to perform any of the functions or actions disclosed herein and / or to cause other logic, methods and / or systems disclosed herein to perform functions or actions. The term "logic" refers to a component embodied in a non-transitory medium having instructions stored thereon, and / or a combination thereof. Equivalent logic may include firmware, an algorithmically programmed microprocessor, discrete logic (e.g., ASIC), at least one circuit, analog circuit, digital circuit, programmed logic device, memory device containing algorithmic instructions, etc., any of which may be configured to perform one or more of the disclosed functions. In one embodiment, logic may include one or more gates, combinations of gates, or other circuit components configured to perform one or more of the disclosed functions. Where multiple logics are described, it may be possible to incorporate the multiple logics into one logic. Similarly, where single logic is described, it may be possible to distribute the single logic among multiple logics. In one embodiment, one or more of these logics are corresponding structures associated with performing the disclosed and / or claimed functions. The selection of which type of logic to implement may be based on desired system requirements or specifications. For example, if higher speed is a consideration, hardware would be selected to achieve the function. If lower cost is a consideration, stored instructions / executable applications would be the choice to implement the functionality.

[0133] An "operable connection," or a connection through which entities are "operably connected," is a connection through which signals, physical communications, and / or logical communications may be sent and / or received. An operable connection may include physical interfaces, electrical interfaces, and / or data interfaces. An operable connection may include various combinations of interfaces and / or connections sufficient to enable operable control. For example, two entities may be operably connected to communicate signals to each other directly or through one or more intermediate entities (e.g., processors, operating systems, logic, non-transitory computer-readable media). Logical and / or physical communication channels may be used to create an operable connection.

[0134] As used herein, a "user" includes, but is not limited to, one or more people, computers or other devices, or combinations thereof.

[0135] Although the disclosed embodiments have been illustrated and described in considerable detail, it is not intended to restrict or in any way limit the scope of the appended claims to such detail. It is, of course, not possible to describe every conceivable combination of components or methodologies for purposes of describing various aspects of the subject matter. Accordingly, the disclosure is not limited to the particular details or specific examples shown and described. The disclosure is therefore intended to embrace changes, modifications, and variations that fall within the scope of the appended claims.

[0136] When the words "includes" or "including" appear in the description or claims, Insofar as this term is used, it is intended to be as inclusive as the term "comprising" as it is interpreted when used as a transitional term in the claims.

[0137] To the extent the word "or" is used in the detailed description or claims (e.g., A or B), it is intended to mean "A or B or both." If applicant intends to indicate "only A or B, but not both," the phrase "only A or B, but not both" would be used. Thus, use of the word "or" herein is inclusive, not exclusive.

Claims

1. 1. A method for detecting counterfeit status of a target utility device, comprising: selecting a set of frequencies that reflects the load dynamics of the reference utility device while undergoing a power test sequence; acquiring a target electromagnetic interference (EMI) signal emitted by the target utility device while undergoing the power test sequence; generating a sequence of target Kiviat plots from the amplitude of the target EMI signal for each set of frequencies observed over the power test sequence to form a target Kiviat tube EMI fingerprint; comparing the target Kiviat tube EMI fingerprint with a reference Kiviat tube EMI fingerprint for the reference utility device subjected to the power test sequence to determine if the target utility device and the reference utility device are the same type; generating a signal to indicate counterfeit status based at least in part on the result of the comparison.

2. 2. The method of claim 1 , wherein the creating step further comprises generating estimates of the amplitudes for each set of the frequencies by a state estimation model trained on the reference Kiviat pipe EMI fingerprint, and wherein the target Kiviat plot is a Kiviat plot of the estimates.

3. 2. The method of claim 1, wherein the comparing step further comprises normalizing each axis of each target Kiviat plot to a unit circle passing through the values ​​plotted on that axis of the corresponding reference Kiviat plot for the same observation in the reference Kiviat tube EMI fingerprint.

4. 2. The method of claim 1, wherein the comparing step further comprises generating an error metric from circular residuals between the target Kiviat plot and the unit circle on axes normalized to represent a corresponding reference Kiviat plot at the same observation in the reference Kiviat tube EMI fingerprint as the unit circle, the error metric being a cumulative area of ​​circular residuals between the unit circle and the target Kiviat plot across all observations.

5. 2. The method of claim 1, wherein the comparing step further comprises generating an error metric from circular residuals between a target Kiviat plot and a reference Kiviat plot at the same observation in the reference Kiviat tube EMI fingerprint, the error metric being a cumulative area of ​​circular residuals between the reference Kiviat plot and the target Kiviat plot across all observations.

6. 2. The method of claim 1, wherein the reference utility device is a genuine utility device of a particular type, the method further comprising the steps of: in response to determining (i) that the target utility device and the reference utility device are of the same type, generating a signal to indicate that the target utility device is confirmed to be genuine; and in response to determining (ii) that they are not of the same type, generating a signal to indicate that the target utility device is a suspected counterfeit.

7. Responding to the signal that the target utility device is a suspected counterfeit.

7. The method of claim 6, further comprising the step of: transmitting the target Kiviat EMI fingerprint to a counterfeit analysis system.

8. The method of claim 7 , further comprising transmitting supply chain information about the target device to the counterfeit analysis system.

9. and receiving, in response to the signal that the target utility device is a suspected counterfeit, additional information regarding the suspected counterfeit configuration from a counterfeit analysis system, the additional information including: (i) confirming that the suspected counterfeit product is a known type of counterfeit product; (ii) prevalence information describing how prevalent utility devices with the suspected counterfeit configuration are; (iii) source information describing the origin of the utility device with the suspected counterfeit configuration; (iv) supply chain information describing how the target device could have entered the supply chain; The method of claim 6, comprising one or more of:

10. 2. The method of claim 1, wherein the reference utility device is a known counterfeit utility device of a particular type, and further comprising the steps of: in response to determining (i) that the target utility device and the reference utility device are of the same type, generating a signal to indicate that the target utility device is confirmed to be a counterfeit device of the particular type; and in response to determining (ii) that they are not of the same type, generating a signal to indicate that the target utility device is not a counterfeit device of the particular type.

11. The method of claim 1 , further comprising retrieving the reference Kiviat tube EMI fingerprint for the reference utility device from a library database.

12. The method of claim 1 , further comprising displaying information based at least in part on the signals in a graphical user interface.

13. A non-transitory computer-readable medium storing computer-executable instructions that, when executed by at least a processor of a computer, cause the computer to: selecting a set of frequencies that reflects the load dynamics of the reference utility device while undergoing a power test sequence; acquiring a target electromagnetic interference (EMI) signal emitted by the target utility device while undergoing the power test sequence; generating a sequence of target Kiviat plots from the amplitude of the target EMI signal for each set of frequencies observed over the power test sequence to form a target Kiviat tube EMI fingerprint; comparing the target Kiviat tube EMI fingerprint with a reference Kiviat tube EMI fingerprint for the reference utility device subjected to the power test sequence to determine if the target utility device and the reference utility device are of the same type; A non-transitory computer-readable medium that causes a signal to be generated to indicate counterfeit status based at least in part on the result of the comparison.

14. 14. The non-transitory computer-readable medium of claim 13, wherein the instructions causing the computer to create a sequence of target Kiviat plots further include instructions causing the computer to generate estimates of the amplitude for each set of frequencies by a state estimation model trained on the reference Kiviat pipe EMI fingerprint, and the target Kiviat plots are Kiviat plots of the estimates.

15. 1. A computing system comprising: a processor; a memory operatively connected to the processor; a radio operatively connected to the processor and the memory; a non-transitory computer-readable medium operatively connected to the processor and the memory and having computer-executable instructions stored thereon, the computer-executable instructions, when executed by at least the processor, causing the computing system to: selecting a set of frequencies that reflects the load dynamics of the reference utility device while undergoing a power test sequence; acquiring, via the radio, a target electromagnetic interference (EMI) signal emitted by a target utility device while undergoing the power test sequence; generating a sequence of target Kiviat plots from the amplitude of the target EMI signal for each set of frequencies observed over the power test sequence to form a target Kiviat tube EMI fingerprint; comparing the target Kiviat tube EMI fingerprint with a reference Kiviat tube EMI fingerprint for the reference utility device subjected to the power test sequence to determine if the target utility device and the reference utility device are of the same type; and generating a signal to indicate counterfeit status based at least in part on the result of the comparison.