Method and system for detecting the unauthorized use of a personal device

A blockchain-based system with smart contracts and device modules detects and alerts unauthorized use of personal devices, addressing the challenge of timely detection without user supervision.

WO2025196281A1PCT designated stage Publication Date: 2025-09-25SONY GROUP CORP +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/057825
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-21
Filing Date
2025-03-21
Publication Date
2025-09-25

AI Technical Summary

Technical Problem

Existing methods fail to detect unauthorized use of personal devices in a timely manner, as users cannot constantly monitor their devices, and existing solutions require the user to notice the unauthorized use first.

Method used

A system utilizing smart contracts on a blockchain registers personal devices, where each device has a software module that detects usage and sends periodic messages to a smart contract, which determines authorization based on location and time information, sending warnings if unauthorized use is detected.

Benefits of technology

The system effectively detects and alerts users to unauthorized use of their personal devices, providing real-time protection without constant supervision.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025057825_25092025_PF_FP_ABST
    Figure EP2025057825_25092025_PF_FP_ABST
Patent Text Reader

Abstract

A method and system for detecting an unauthorized usage of a personal device are provided. A user of a set of personal devices registers the set of personal devices with a smart contract on a blockchain. Each personal device includes a software module configured to detect an activation or usage of a host personal device on which the software module is installed. The software module installed on a personal device detects an activation or usage of the host personal device. The software module invokes the smart contract upon detection of the activation or usage of the first personal device. The smart contract determines whether the activation or usage of the first personal device is authorized or not. A warning is sent to the user if it is determined that the activation or usage of the first personal device is unauthorized.
Need to check novelty before this filing date? Find Prior Art

Description

Method and system for detecting the unauthorized use of a personal device Field

[0001] Examples relate to a method and system for detecting unauthorized use of personaldevices. More particularly, examples relate to a method and system for detecting unauthorized use of personal devices using smart contracts deployed on a blockchain. Background

[0002] Nowadays, people have lots of personal devices like a smartwatch, a mobile phone,a laptop, a tablet, a smart watch, a personal computer (PC), a wearable device, etc. These devices could be stolen and / or used without authorization by the owner or rightful user. These devices could be accessed and used by another person when the owner / rightful user of the devices leaves them unlocked or authentication information for the devices is acquired by another person.

[0003] There are ways for the owner / rightful user to disable the stolen devices from adistance. However, this requires that the owner / rightful user of the devices notice that the device was stolen or activated / used by another person in the first place.

[0004] The problem is that people cannot have all their personal devices under theirsupervision all the time. Therefore, it is desirable to provide a method to detect unauthorized / unwanted use of any personal devices that were left unattended. Summary

[0005] An example relates to a method for detecting an unauthorized usage of a personaldevice. A set of personal devices are registered with a smart contract on a blockchain by a user of the personal devices. Each personal device includes a software module configured to detect an activation or usage of a host personal device on which the software module is installed. A software module installed on a first personal device detects an activation or usage of the first personal device. The software module on the first personal device then invokes the smart contract upon detection of the activation or usage of the first personal device. The smart contract determines whether the activation or usage of the first personal device is authorized or not. Awarning may be sent to the user if it is determined that the activation or usage of the first personal device is unauthorized. One of the set of personal devices may be designated as a reference device. A personal device closest to the user or a personal device that the user is currently using is designated as the reference device. The reference device sends periodic messages at regular intervals to the smart contract. The smart contract may determine whether the activation or usage of the first personal device is authorized or not based on information included in the periodic messages.

[0006] Another example relates to a method implemented by a smart contract deployed ona blockchain for detecting an unauthorized usage of a personal device. The smart contract receives periodic messages at regular intervals from a reference device. The reference device is a personal device designated among a set of personal devices of a user registered with the smart contract. The smart contract receives an invoking message from a first personal device and determines whether an activation or usage of the first personal device is authorized or not based on the invoking message. The smart contract either sends a warning to the user or generates an event on the blockchain if it is determined that the activation or usage of the first personal device is unauthorized.

[0007] Another example relates to a method for detecting an unauthorized usage of apersonal device. A set of personal devices of a user are registered with a smart contract on a blockchain, and each personal device includes a software module configured to detect an activation or usage of a host personal device on which the software module is installed. A software module installed on a personal device detects an activation or usage of the personal device. The software module then invokes the smart contract with which the personal device is registered upon detection of the activation or usage of the personal device.

[0008] Another example relates to a system for detecting an unauthorized usage of apersonal device. The system includes a smart contract deployed on a blockchain and a set of personal devices. The set of personal devices are registered with the smart contract. Each personal device comprises a software module that is configured to detect an activation or usage of a host personal device in which the software module is installed and invoke the smart contract upon detection of the activation or usage of the host personal device. The smart contract is configured to determine whether an activation or usage of a personal device that invokes the smart contract is authorized or not, and either send a warning to a user of the set of personal devices or generate an event on the blockchain if it is determined that the activation or usage of the personal device is unauthorized. One of the set of personal devices may be designated as a reference device. The reference device is configured to send periodic messages at regularintervals to the smart contract, and the smart contract is configured to determine whether the activation or usage of the personal device is authorized or not based on information included in the periodic messages. The software module on the personal device is configured to send a timestamp and / or location information of the personal device to the smart contract when invoking the smart contract. The periodic messages from the reference device include a timestamp of last periodic message and / or location information of the reference device. The smart contract is configured to determine whether the activation or usage of the personal device is authorized or not based on the timestamp of last periodic message and / or the location information of the reference device and the timestamp and / or location information of the personal device.

[0009] Another example relates to a device (personal device). The device includes aprocessor and a storage device including a software module. The software module is configured to, when executed on the processor, detect an activation or usage of the personal device and invoke a smart contract deployed on a blockchain with which the personal device is registered upon detection of the activation or usage of the personal device.

[0010] Another example relates to a machine-readable medium including code, whenexecuted, to cause a machine to perform the method disclosed herein. Brief description of the Figures

[0011] Some examples of apparatuses and / or methods will be described in the followingby way of example only, and with reference to the accompanying figures, in which

[0012] FIG. 1 shows a system for detecting the unauthorized use of a personal device inaccordance with one example;

[0013] FIG. 2 is a flow diagram of a process for detecting an unauthorized usage of apersonal device in accordance with one example;

[0014] FIG. 3 is a flow diagram of an example process implemented by a smart contractdeployed on a blockchain for detecting an unauthorized usage of a personal device;

[0015] FIG. 4 is a flow diagram of an example process implemented by a software moduleinstalled in a personal device for detecting an unauthorized usage of a personal device; and

[0016] FIG. 5 is a block diagram of a personal device in accordance with one example.Detailed Description

[0017] Various examples will now be described more fully with reference to theaccompanying drawings in which some examples are illustrated. In the figures, the thicknesses of lines, layers and / or regions may be exaggerated for clarity.

[0018] Accordingly, while further examples are capable of various modifications andalternative forms, some particular examples thereof are shown in the figures and will subsequently be described in detail. However, this detailed description does not limit further examples to the particular forms described. Further examples may cover all modifications, equivalents, and alternatives falling within the scope of the disclosure. Like numbers refer to like or similar elements throughout the description of the figures, which may be implemented identically or in modified form when compared to one another while providing for the same or a similar functionality.

[0019] It will be understood that when an element is referred to as being “connected” or“coupled” to another element, the elements may be directly connected or coupled or via one or more intervening elements. If two elements A and B are combined using an “or”, this is to be understood to disclose all possible combinations, i.e. only A, only B as well as A and B. An alternative wording for the same combinations is “at least one of A and B”. The same applies for combinations of more than 2 elements.

[0020] The terminology used herein for the purpose of describing particular examples isnot intended to be limiting for further examples. Whenever a singular form such as “a,” “an” and “the” is used and using only a single element is neither explicitly or implicitly defined as being mandatory, further examples may also use plural elements to implement the same functionality. Likewise, when a functionality is subsequently described as being implemented using multiple elements, further examples may implement the same functionality using a single element or processing entity. It will be further understood that the terms “comprises,” “comprising,” “includes” and / or “including,” when used, specify the presence of the stated features, integers, steps, operations, processes, acts, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, processes, acts, elements, components and / or any group thereof.

[0021] Unless otherwise defined, all terms (including technical and scientific terms) areused herein in their ordinary meaning of the art to which the examples belong.

[0022] Examples are disclosed herein for detecting unauthorized / unwanted use of apersonal device of a user. Another person (e.g., a malicious user) may access or use a personal device of a rightful user without authorization or permission. For example, an owner left a laptop in the hotel room with a password on a note nearby. His smartphone is unlocked on hisoffice desk, and he is currently wearing a smartwatch while heading to another place. Now suppose that a hotel employee finds the note and logs into his laptop, or an office worker is using his phone during his absence. There is no way that the owner can notice this. In another example, an owner left his smartwatch unlocked at the office desk and the owner is working on his laptop in his hotel room with his tablet next to him. Now suppose that somebody working late in the office takes his smartwatch and accesses it while walking away. There is no way that the owner can notice this. In still another example, an owner left his smartwatch unlocked on the office desk, and he is sleeping in his hotel room with his mobile phone next to him and his laptop in his briefcase. Now suppose that somebody working late in the office takes his smartwatch and accesses it. There is no way that the owner can notice this.

[0023] Examples discloses herein provide a method and system for detecting unauthorizeduse of personal devices using smart contracts deployed on a blockchain. A user owns or uses a plurality of personal devices. For example, the personal devices may be a laptop, a tablet, a smartphone, a mobile phone, a smartwatch, a personal computer (PC), a desktop computer, or any wearable devices. The personal devices may be mobile or stationary. The user of the personal devices may be an owner of the personal devices or a rightful user of the personal devices. Hereafter, the term “user” will be used to include both the rightful user and the owner of the personal devices. In examples, the system detects an unauthorized / unwanted usage of any personal devices of the user or any suspicious behavior with respect to the personal devices of the user and informs it to the user.

[0024] FIG. 1 shows a system 100 for detecting an unauthorized use of a personal devicein accordance with one example. The system 100 includes a plurality of personal devices 112- 118 and a smart contract 120 deployed on a blockchain 122. In this example, the user 102 uses a set of personal devices including, but not limited to, a laptop 112, a smart watch 114, a mobile phone 116, and a tablet 118.

[0025] The user 102 deploys a smart contract 120 in the blockchain 122 (e.g., Ethereum,etc.). A blockchain 122 is a distributed and decentralized ledger that includes a chain of blocks. Each block contains a set of data. The blockchain data structure is an ordered, back-linked list of blocks of transactions. The blockchain can be stored as a flat file or in a simple database. Each block within the blockchain is identified by a hash, for example generated using the SHA256 cryptographic hash algorithm on the header of the block. Each block references a previous block, known as a parent block, through the “previous block hash” field in the block header. The primary identifier of a block is its cryptographic hash made by hashing the block header through the SHA256 algorithm.

[0026] The user 102 registers the set of personal devices 112-118 of the user 102 with thesmart contract 120 deployed on the blockchain 122. A smart contract is an application deployed / published on a blockchain. A smart contract is a self-executing program that automates the actions required in an agreement or contract. Once completed, the transactions are trackable and irreversible. Smart contracts are a code written into a blockchain that executes the terms of an agreement or contract from outside the blockchain. A smart contract automates the actions that would otherwise be completed by the parties in the agreement. For example, a smart contract could initiate a fund transfer with a third party to verify that the transfer took place. Blockchain-based smart contracts are proposed contracts that can be partially or fully executed or enforced without human interaction. A key feature of smart contracts is that they do not need a trusted third party to act as an intermediary between contracting parties, i.e., the blockchain network executes the contract on its own.

[0027] A software module 132-138 is installed on the personal devices 112-118,respectively. The software module 132-138 is configured to detect a usage of the host personal device 112-118 in which the software module 132-138 is installed. For example, the software module 132 may be configured to measure a power consumption of the host personal device 112 and detect a usage of the host personal device 112 based on the power consumption on the host personal device 112. The personal devices 112-118 may be battery-powered. The battery consumption of a personal device when in a sleep state, a suspended state, a power-saving mode, or a turned-off state will differ significantly from when the personal device is turned on and in use. The software module 132-138 installed on a personal device 112-118 may detect a substantial increase in power consumption of the personal device 112-118, respectively and determine that the host personal device 112-118 is in use if the power consumption of the host personal device 112-118 is substantially higher than in a sleep state, a suspended state, a power- saving mode, or in a turned-off state.

[0028] In some examples, one of the personal devices 112-118 may be designated as areference device. For example, the personal device that is closest to the user 102 or the personal device that the user 102 is currently using / interacting with may be designated as a reference device. In the example shown in FIG. 1, the smart watch 114 is currently designated as a reference device, but the designation of the reference device may change over time, either autonomously or manually. The user 102 may change the designation of the reference device, or the software module 132-138 may designate the host personal device as a reference device. The reference device (e.g., the smart watch 114) may send periodic messages (may be referred to as a heartbeat signal) at regular intervals to the smart contract 120. The information sent bythe reference device in the periodically transmitted messages may be used as a reference against which suspicious activities from other personal devices are measured or determined.

[0029] The reference device can also be misused if it is stolen / taken away from the user.At that point the periodic messages (heartbeat data) sent by the reference device corresponds with that of the person who took the personal device (e.g., a thief). However, that person will not be able to register new devices because that person does not have the rightful user’s / owner’s private key that corresponds with the cryptographic address that is allowed by the smart contract to invoke the “registration” (e.g., updateAccumulator) method for registering new devices. That private key is typically stored in a crypto wallet belonging to the user / owner.

[0030] Same goes for designating a new reference device. The malicious person cannotdesignate a new reference device because he / she does not have the user’s / owner’s private key that corresponds with the cryptographic address that is allowed by the smart contract to invoke the “set reference device” method.

[0031] As long as the user / owner has not noticed the missing reference device it willcontinue to send the periodic messages (heartbeat information) to the smart contract as if it were owned by the rightful user / owner. As soon as the user / owner notices the loss / theft, the user / owner can invoke the smart contract’s “unregister device” (e.g., updateAccumulator) method. This is also an administrative method that is checked by the smart contract to be invoked with the correct cryptographic address and corresponding private key (for signing the transaction).

[0032] The cryptographic address with corresponding private key mentioned above is notkept in the any of the devices. It belongs to the user and allows the user to invoke the administrative methods on the smart contract like assigning a new reference device and registering / unregistering devices.

[0033] Each personal device 112-118 is configured with a pair of cryptographic keys (i.e.,a private key and a public key) and a corresponding crypto address. The software module 132- 138, using the private key and the corresponding crypto address of the host personal device, may invoke methods from the smart contract 120 on the blockchain when a usage of the host personal device is detected (e.g., through detection of an increased power consumption on the host personal device over a certain period of time). When invoking the methods from the smart contract 120, the software module 132-138 may pass certain information of the host personal device (e.g., geographic coordinates of the host personal device, timestamp of activation or usage, etc.) to the smart contract 120. For example, when the software module 138 on the tablet 118 detects that the tablet 118 is activated and being used (e.g., detected through a substantialincrease in power consumption on the tablet 118), the software module 138 invokes the smart contract 120. The smart contract 120 may then compare the information provided from the tablet 118 with the information provided in the periodic messages from the reference device (e.g., the smart watch 114) which is stored in the smart contract 120. The information provided in the periodic messages from the reference device is used to decide whether or not the activation or use of the tablet 118 (or any other personal devices of the user) is legitimate or suspicious.

[0034] In examples, the detection of the unauthorized / unwanted usage of a personal devicemay be based on geographic location information and / or temporal information of the personal device. The personal device 112-118 may be configured to determine the geographic location of the device and the software module 132-138 may provide this geographic location information to the smart contract 120 when invoking the smart contract. For example, the personal device 112-118 may be configured to determine the geographic coordinate of the device by using the satellite-based navigation system signals (e.g., Global Positioning System (GPS) signals) and provide the geographic coordinate of the personal device in an invoking message sent to invoke the smart contract. The software module 132-138 may also provide the timestamp of the activation or usage of the personal device 112-118 when invoking the smart contract 120.

[0035] If the software module 132-138 includes the geographic location information of thehost personal device in the invoking message sent to the smart contract 120 when invoking the smart contract 120, the smart contract 120 may check proximity of this personal device to the reference device to assess the legitimacy of the activation or usage of the personal device. If the personal device 112-118 is not configured to determine the geographic location of the personal device 112-118 or the geographic location information of the personal device 112-118 is not provided when invoking the smart contract 120, the smart contract 120 may rely on other indicators to assess the legitimacy of the activation or usage of the personal device 112-118. For example, the activation or usage time relative to the reference device's status may be used to determine the legitimacy of the activation or usage of the personal device 112-118.

[0036] As shown in FIG. 1, the system 100 includes two main components: a softwaremodule 132-138 that is installed on all the personal devices 112-118 of the user 102 and a smart contract 120 that is deployed in the blockchain 122. The smart contract 120 can be invoked by the software module 132-138. The software module 132-138 is configured to perform numerous functions. The software module 132-138 is configured to detect activation or usage of the host personal device (e.g., by detecting the substantial increase in power consumption of the hostpersonal device). The software module 132-138 may designate the host personal device as a reference device. The software module 132-138 may produce periodic messages to be sent to the smart contract 120 if designated as a reference device. The software module 132-138 may access a private key (e.g., a 256-bit private key) stored in a secure storage on the host personal device for signing messages (e.g., the messages sent to the smart contract 120). The software module 132-138 may hold a cryptocurrency address that corresponds with the private key. The software module 132-138 may hold a cryptocurrency address of the smart contract 120 as well. The software module 132-138 may create a cryptographic accumulator with hashed cryptocurrency addresses of all personal devices 112-118 of the user 102. The software module 132-138 may invoke the smart contract 120 when the usage / activation of the host personal device is detected. The software module 132-138 may sign transactions using the private key of the host personal device stored in a secure storage on the host personal device. The software module 132-138 may have access to the geographic coordinate information of the host personal device and include the geographic coordinates in the invoking message sent for invoking the methods of the smart contract 120. The software module 132-138 may apply isometric transformations on the geographic coordinates. The software module 132-138 may invoke a method on the smart contract to store the periodic message (heartbeat data) and invoke a method on the smart contract when an activation of the host personal device is detected (e.g., an increase in power consumption on the host personal device is detected).

[0037] The smart contract 120 is configured to perform numerous functions. The user mayupdate the smart contract (e.g., add additional personal device to the smart contract or delete an existing personal device from the smart contract). The smart contract 120 is configured to hold a cryptocurrency address of the user 102 and check if the request to update the smart contract is from the rightful user. The smart contract may include a cryptographic structure that provides a privacy-preserving way of membership verification. For example, a cryptographic accumulator or Merkle tree may be used to hold the cryptographic addresses of the set of personal devices of the user and for verification of whether a cryptographic address is part of the set of personal devices without revealing the set's contents. For example, the smart contract 120 may hold a cryptographic accumulator with hashed values of cryptocurrency addresses of all registered personal devices 112-118 of the user 102. The smart contract 120 may check if the cryptocurrency address that invoked smart contract functions is present in the cryptograph accumulator. The smart contract 120 has a protected method “updateAccumulator” to update a cryptographic accumulator containing the registered personal devices. The smart contract 120 has a protected method “recordHeartBeat” to accept heartbeat information from the designatedreference device. The smart contract 120 has a protected method “recordDeviceActivation” to accept device activation information from the personal devices. The smart contract 120 has a method “calculateDistance” to calculate a distance between two geographic data points (e.g., isometric transformed data points). The smart contract 120 has a method “triggerEvent” to emit an event indicating an “unwanted activation.”

[0038] FIG. 2 is a flow diagram of a process for detecting an unauthorized usage of apersonal device in accordance with one example. All personal devices of the user have the software module installed with a cryptographic address of the personal device. Each personal device holds the private key that corresponds with the cryptographic address of the personal device. A smart contract is deployed in a blockchain with the user’s (owner’s) cryptocurrency address.

[0039] A cryptocurrency address is derived from a 256-bit private key (e.g., within thecontext of Ethereum). Generation of a cryptocurrency address starts with a randomly generated 256-bit private key. The private key is used to generate a public key through elliptic curve cryptography (ECC), (e.g., using the secp256k1 curve). The public key is then hashed (e.g., the Keccak-256 hashing algorithm is applied to the public key to create a hash). The last 20 bytes of the Keccak-256 hash is then taken as the cryptocurrency address. This is the Ethereum address, usually represented as a 40-character hexadecimal string, prefixed with "0x".

[0040] The private keys of the personal device may be stored in a secure storage, forexample the device's built-in hardware security module (HSM) or Secure Enclave. Android Keystore or Apple's Keychain may be used to store the private keys. These services provide a secure storage mechanism that isolates the private keys from the application's process space and encrypts them.

[0041] Within the smart contract, a cryptographic address linked to the owner is specifiedto have the exclusive right to update the cryptographic accumulator. This role is separate from the membership checks for regular devices. The user may update the smart contract (e.g., using the cryptographic accumulator or any other cryptographic structure) using the cryptographic address of the user. The smart contract verifies the calls to update the smart contract (e.g., the cryptographic accumulator or other cryptographic structure) come from this cryptographic address.

[0042] The following shows an example of smart contract.e.g.,: contract AccumulatorContract {… address private owner; / / address from where an update of the accumulator is allowed bytes32 public merkleRoot; / / the root of the Merkle Tree / / Struct to hold device activation data struct DeviceActivation { address deviceAddress; uint256 timestamp; } DeviceActivation[] public activations; / / Array to store device activations constructor() { owner = msg.sender; / / Set contract creator as owner merkleRoot = _merkleRoot; } modifier onlyOwner() { require(msg.sender == owner, "Not authorized"); _; } function updateAccumulator(bytes32 newRoot) public onlyOwner { accumulatorRoot = newRoot; } / / Modifier that requires a valid Merkle proof modifier onlyAllowed(bytes32[] calldata _merkleProof) { require( isAllowed(_merkleProof, keccak256(abi.encodePacked(msg.sender))), "Address not allowed" );} / / Simplified Merkle proof verification function function isAllowed(bytes32[] memory _merkleProof, bytes32 _leaf) public view returns (bool) { bytes32 computedHash = _leaf; for (uint256 i = 0; i < _merkleProof.length; i++) { bytes32 proofElement = _merkleProof[i]; if (computedHash <= proofElement) { computedHash = keccak256(abi.encodePacked(computedHash, proofElement)); } else { computedHash = keccak256(abi.encodePacked(proofElement, computedHash)); } } return computedHash == merkleRoot; } / / Function to record a device activation function recordDeviceActivation(bytes32[] calldata _merkleProof) public onlyAllowed(_merkleProof) { activations.push(DeviceActivation({ deviceAddress: msg.sender, timestamp: block.timestamp })); } … }

[0043] Referring to FIG. 2, a user of a set of personal devices registers the set of personaldevices with a smart contract on a blockchain (202). The user deploys the smart contract in the blockchain and registers the set of personal devices with the smart contract. For example, the set of personal devices of the user may be registered with the smart contract by creating a cryptographic structure that is configured to verify whether any personal device belongs to the set of registered personal devices without revealing the membership of the set of personal devices. For example, the cryptographic structure may be a cryptographic accumulator. A new personal device may be added to, or an existing personal device may be deleted from, the smart contract by updating the cryptographic structure (e.g., the cryptographic accumulator).

[0044] A cryptographic accumulator is a one-way membership hash function that allowsusers to certify that potential candidates are a member of a certain set without revealing the individual members of the set. Cryptographic accumulators allow for a compact representation of a set of values (in examples, the cryptocurrency addresses) and enable membership proofs without revealing the individual members or requiring each to be stored individually on the blockchain. There are several types of suitable cryptographic accumulators. For example, for blockchain applications, zero-knowledge accumulators or Merkle trees may be used as they allow for efficient proof of membership without revealing the set's contents.

[0045] A process for deploying a smart contract with a cryptographic accumulator isexplained herein. Step 1 is off-chain accumulation. The hashes of the cryptocurrency addresses of the personal devices to be registered are accumulated off-chain and these hashes are added to the cryptographic accumulator. Step 2 is generation of witness / proof. For each cryptographic address, a proof or witness is generated that can verify that the cryptographic address is part of the accumulated set without needing to compare against the entire set directly. Step 3 is deploying accumulator data. The smart contract may be deployed with the initial state of the cryptographic accumulator and the ability to update it. For dynamic accumulators like Merkle trees, it is only needed to store the root hash in the smart contract. Step 4 is verification function. The smart contract has a function that takes an invoking cryptocurrency address, calculates its hash, and then uses a provided proof or witness to verify whether the cryptocurrency address is part of the cryptographic accumulator. In case of a Merkle tree, a personal device provides a Merkle proof that is checked against the Merkle root. Step 5 is an access control. The smart contract wraps the protected functions with a check that requires passing the accumulator verification to proceed. If using a dynamic accumulator like a Merkle tree, the update process only involves recalculating the root hash whenever a cryptocurrency address from a personal device is added or removed from the set and then updating the smart contract with the new root.

[0046] Referring again to FIG. 2, one of the personal devices may be designated as areference device (204). The software module installed on a personal device may autonomously designate the host personal device as a reference device. Alternatively, the reference device may be designated manually by the user using a user interface or programmatically using an application programming interface (API). The personal device that is closest to the user or the personal device that the user is currently using / interacting with may be designated as a reference device.

[0047] The reference device may send periodic messages (heartbeat) at regular intervals tothe smart contract. The reference device may send the timestamp and / or the geographic coordinates of the reference device in each periodic message. An example of the periodic message is shown below. { "lastActiveTimestamp": "2024-02-02T15:00:00", / / last heartbeat"latitude": abc, / / optional isometric transformed latitude"longitude": def / / optional isometric transformed longitude}

[0048] The smart contract may include protected methods like “recordHeartBeat” and“recordDeviceActivation.” These methods may only be executed if the cryptocurrency address from which the smart contract method is invoked passes the membership proof for the cryptographic accumulator, i.e., if the cryptocurrency address of the reference device sending the messages is determined to be one of the cryptocurrency addresses represented by the cryptographic accumulator.

[0049] The software module on a personal device detects an activation or usage of the hostpersonal device (206). For example, the software module on the personal device may measure a power usage of the host personal device and detect an activation or usage of the host personal device based on the power consumption. The personal devices may be battery-powered. The battery consumption of a personal device when in a sleep state, a suspended mode, a power- saving state, or a turned-off state will differ significantly from when the personal device is turned on or in use. An increase in power consumption on any personal device signifies its activation from a sleep / hibernation state or a low-power state, or it is turned on and being used. The software module may detect a substantial increase in power consumption of the host personal device and determine that the host personal device is activated or in use if the powerconsumption of the host personal device is substantially higher than in a sleep state, a suspended state, a power-saving mode, or in a turned off state.

[0050] The software module on the personal device invokes the smart contract (i.e., sendsan invoking message to the smart contract) upon detection of the activation or usage of the personal device (208). The software module reports the suspicious activity on the host personal device by invoking methods on the smart contract. Invoking a method (or function) on a smart contract and passing parameters to the smart contract on a blockchain (e.g., Ethereum blockchain) requires interacting with the blockchain network through a transaction or call. The personal devices need to have a cryptocurrency address and a private key that corresponds with the cryptocurrency address in order to call the protected methods on the smart contract. The private key is needed to correctly sign the transactions on the smart contract. The software modules on the personal devices also know the cryptocurrency address of the smart contract.

[0051] An example process for invoking a method on a smart contract is explainedhereafter. The process is explained with reference to Ethereum as an example, since Ethereum is one of the most common platforms for smart contracts. The process is applicable to other blockchains as well.

[0052] It is needed to use tools and libraries that allow to connect and interact with theblockchain. For Ethereum, some of the choices are Web3.js / Web3.py (JavaScript / Python libraries for interacting with the Ethereum blockchain) and Ethers.js (an alternative to Web3.js with similar functionality, often praised for its cleaner API). To interact with a blockchain, it is needed to connect to a node on the blockchain. Web3.js / Web3.py and Ethers.js will create and provide with a lightweight object that can be used to connect to the blockchain and invoke methods on a deployed smart contract.

[0053] To invoke a smart contract method that changes the state on the blockchain (suchas updating variables, etc.), it is needed to create and sign a transaction. The transaction includes at least the following: to: the address of the smart contract on the blockchain; and data: the function signature and encoded parameters. The function signature is the first 4 bytes of the Keccak-256 hash of the function's signature (e.g., myFunction(uint256,string)). The parameters are ABI-encoded data representing the arguments passed to the function. One of the arguments is the “from” crypto address. The other arguments are specific to the function that is invoked.

[0054] Before sending the transaction to the blockchain it must be signed with the privatekey of the personal device (or crypto address) initiating the transaction. This step is crucial forauthentication and ensuring that only the rightful user / owner can initiate transactions from their account (or crypto address).

[0055] The signed transaction is then broadcast to the network. It is picked up by minerson the blockchain, executed, and included in a block. Once the transaction is confirmed, the method on the smart contract is considered invoked and the state changes are applied to the blockchain. For methods that do not change a state and only read data from the blockchain, a call may be made instead of sending a transaction.

[0056] When invoking the smart contract method to report suspicious activity on thepersonal device, the software module may send a following message to the smart contract: { "activeTimestamp": "2024-02-02T15:00:00", / / timestamp of the usage / activation "latitude": opq, / / optional isometric transformed latitude"longitude": rst / / optional isometric transformed longitude"powerlevel": xyz / / power level for logging}

[0057] When invoking the methods on the smart contract, the software module may sendthe timestamp of the activation or usage of the host personal device, the geographic coordinate of the host personal device, and / or the power consumption level information of the host personal device. When inserting the geographic coordinates in the message sent to the smart contract, the software module may use one or a series of combined isometric transformations (e.g., rotations, translations, reflections across a line or plane) that preserve distances. The reference geographic coordinates and other device geographic coordinates may undergo these isometric transformations before being uploaded to the smart contract by the software modules. This allows the smart contract to still calculate the distance without revealing their real-world meaning, preventing immediate recognition of the location.

[0058] The smart contract then determines whether the activation or usage of the personaldevice is authorized or not (210). The smart contract may determine unauthorized activation or usage of the personal device based on the timestamp and / or location of the personal device or by comparing the timestamp and / or location of the personal device with those of the reference device. The smart contract analyzes the incoming data (from the reporting personal device or the reference device) and applies the monitoring logic. For example, if a personal device sends information to the smart contract outside of the expected parameters (e.g., in the middle of thenight or from an unexpected location), the smart contract may determine that the activation or use of the personal device is unauthorized.

[0059] The reference device's status may act as a key indicator. If the reference device isinactive (not being used or in a sleep / hibernation / low-power mode), any activation of another device of the user is considered suspicious or potentially unauthorized.

[0060] The "lastActiveTimestamp" of the reference device may be used to detect inactivityof the reference device. If the reference device is currently active (e.g., the periodic messages are received recently), activations of other personal devices of the user might be considered authorized or less suspicious. If the reference device is currently inactive (e.g., no periodic messages have been received or the reference device is in a known sleep / hibernation / low-power state), activations of other personal devices may be flagged as potentially unauthorized or suspicious.

[0061] The location information (e.g., "latitude" and "longitude" coordinates) of thereference device and the personal device may be used to detect unauthorized / unwanted usage of the personal device. The location information of the reference device and the personal device may be used to determine whether the personal device is located near the reference device. If it is determined that the reference device and the personal device are close, the activation or usage of the personal device may be considered authorized and less suspicious. However, if it is determined that the reference device is not near the reporting personal device, the activation or usage of the reporting personal device may be considered suspicious or unauthorized.

[0062] The geographic coordinates of the reference device and other reporting personaldevice may undergo the isometric transformations before being uploaded to the smart contractby the software modules. Given two points A and B with original coordinates (x1,y1) and (x2,y2), respectively, and their transformed points A՛ and B՛ with transformed coordinates (x1′,y1′)and (x2′,y2′), respectively, after applying an isometric transformation T, the distance d′ betweenthe transformed points A′ and B′ can be calculated using the Euclidean distance formula asfollows, the same way as it would be for the original points, because T preserves distances.^^′ = ^ − 2 + − ^ ′ 2.

[0063] A warning is then sent to the user if it is determined that the activation or usage ofthe personal device is unauthorized (212). The warning may be generated and sent to flag an unauthorized / unwanted activation / usage of the personal device. In one example, the smart contract may directly send the warning to the user. Alternatively, the smart contract may launchan event in the blockchain. Events are information that is emitted by transactions taking place on a blockchain. A transaction taking place on a blockchain represents a change of state to the underlying blockchain ledger.

[0064] In examples, an off-chain service (like a server application) may be set up to listenfor these events and send a notification to the user via email, short-messaging service (SMS), a push notification, etc. Alternatively, subscription services may be used. Some blockchain platforms offer subscription services where the user can subscribe to specific events or state changes in a smart contract. Alternatively, a blockchain oracle can trigger a notification based on certain conditions met in the smart contract. Blockchain oracles are entities that connect blockchains to external systems, thereby enabling smart contracts to execute based upon inputs and outputs from the real world.

[0065] Alternatively, decentralized applications (DApps) may be used. A decentralizedapplication is a type of distributed, open-source software application that runs on a peer-to-peer blockchain network. If the user has a DApp associated with the smart contract, the notification functionalities can be integrated within the DApp. The DApp can listen for smart contract events and notify the user through its interface. Alternatively, a script may be developed using Web3 libraries (e.g., Web3.js or Web3.py) that continuously poll the blockchain for specific contract events or state changes and then notify the user. Alternatively, third-party services may be used. There are third-party services that offer monitoring and notification features for smart contract events. These services can watch for specific triggers on the blockchain and notify the user through various channels.

[0066] FIG. 3 is a flow diagram of an example process implemented by a smart contractdeployed on a blockchain for detecting an unauthorized usage of a personal device. A smart contract receives periodic messages at regular intervals from a reference device (302). The reference device is a personal device designated among a set of personal devices of a user registered with the smart contract. The smart contract receives an invoking message from a first personal device (304). A software module running on the first personal device detects an activation or usage of the first personal device and sends an invoking message to the smart contract. The smart contract then determines whether an activation or usage of the first personal device is authorized or not based on the invoking message (306). The smart contract may determine unauthorized use of the first personal device based on time and / or location information of the first personal device and / or the reference device. The smart contract sends a warning to the user or generates an event on the blockchain if it is determined that the activation or usage of the first personal device is unauthorized (308).

[0067] FIG. 4 is a flow diagram of an example process implemented by a software moduleinstalled in a personal device for detecting an unauthorized usage of a personal device. A set of personal devices of a user are registered with a smart contract on a blockchain, and each personal device includes a software module configured to detect an activation or usage of a host personal device on which the software module is installed. The software module installed on a personal device detects an activation or usage of the personal device (402). The software module may detect the activation or usage of the personal device based on power consumption level of the personal device. The software module then invokes the smart contract deployed on the blockchain with which the personal device is registered upon detection of the activation or usage of the personal device (404).

[0068] FIG. 5 is a block diagram of a personal device in accordance with one example. Thepersonal device includes a processor (502) and a storage device (504). The storage device (504) includes a software module (506). The software module (506) is configured to, when executed on the processor (502), detect an activation or usage of the personal device and invoke a smart contract deployed on a blockchain with which the personal device is registered upon detection of the activation or usage of the personal device (500). The software module (506) may be configured to detect activation or usage of the personal device based on power consumption on the personal device (500).

[0069] Another example is a computer program having a program code for performing atleast one of the methods described herein, when the computer program is executed on a computer, a processor, or a programmable hardware component. Another example is a machine-readable storage including machine readable instructions, when executed, to implement a method or realize an apparatus as described herein. A further example is a machine-readable medium including code, when executed, to cause a machine to perform any of the methods described herein.

[0070] The following examples pertain to further embodiments:(1) A method for detecting an unauthorized usage of a personal device, comprising: registering, by a user of a set of personal devices, the set of personal devices with a smart contract on a blockchain, wherein each personal device includes a software module configured to detect an activation or usage of a host personal device on which the software module is installed; detecting, by a software module installed on a first personal device, an activation or usage of the first personal device;invoking, by the software module on the first personal device, the smart contract upon detection of the activation or usage of the first personal device; determining, by the smart contract, whether the activation or usage of the first personal device is authorized or not; and sending a warning to the user if it is determined that the activation or usage of the first personal device is unauthorized. (2) The method of (1), wherein one of the set of personal devices is designated as a reference device, and the reference device sends periodic messages at regular intervals to the smart contract, and it is determined by the smart contract whether the activation or usage of the first personal device is authorized or not based on information included in the periodic messages. (3) The method of (2), wherein a personal device closest to the user or a personal device that the user is currently using is designated as the reference device. (4) The method of (2) or (3), wherein each periodic message includes a timestamp and / or location information of the reference device, and the smart contract determines whether the activation or usage of the first personal device is authorized or not based on the timestamp and / or the location information of the reference device. (5) The method of (4), wherein the software module on the first personal device sends a timestamp and / or location information of the first personal device to the smart contract when invoking the smart contract, and the smart contract determines whether the activation or usage of the first personal device is authorized or not based on the timestamp and / or the location information of the reference device and the timestamp and / or location information of the first personal device. (6) The method of as any one of (1)-(5), wherein the set of personal devices are registered with the smart contract by creating in the smart contract a cryptographic structure that is configured to verify whether a personal device belongs to the set of personal devices without revealing membership of the set of personal devices.(7) The method of any one of (1)-(6), wherein the software module on the first personal device detects the activation or usage of the first personal device based on power consumption on the first personal device. (8) The method of any one of (1)-(7), further comprising: generating, by the smart contract, an event on the blockchain upon detecting that the activation or usage of the first personal device is unauthorized, wherein the warning is sent to the user based on the event. (9) A method implemented by a smart contract deployed on a blockchain for detecting an unauthorized usage of a personal device, comprising: receiving periodic messages at regular intervals from a reference device, wherein the reference device is a personal device designated among a set of personal devices of a user registered with the smart contract; receiving an invoking message from a first personal device; determining whether an activation or usage of the first personal device is authorized or not based on the invoking message; and either sending a warning to the user or generating an event on the blockchain if it is determined that the activation or usage of the first personal device is unauthorized. (10) A method for detecting an unauthorized usage of a personal device, wherein a set of personal devices of a user are registered with a smart contract on a blockchain, and each personal device includes a software module configured to detect an activation or usage of a host personal device on which the software module is installed, the method comprising: detecting, by a software module installed on a personal device, an activation or usage of the personal device; and invoking, by the software module, the smart contract with which the personal device is registered upon detection of the activation or usage of the personal device. (11) A system for detecting an unauthorized usage of a personal device, comprising: a smart contract deployed on a blockchain; and a set of personal devices, wherein the set of personal devices are registered with the smart contract, and each personal device comprising a software module that is configured to detect an activation or usage of a host personal device in which the software module is installedand invoke the smart contract upon detection of the activation or usage of the host personal device, wherein the smart contract is configured to determine whether an activation or usage of a personal device that invokes the smart contract is authorized or not, and either send a warning to a user of the set of personal devices or generate an event on the blockchain if it is determined that the activation or usage of the personal device is unauthorized. (12) The system of (11), wherein one of the set of personal devices is designated as a reference device, and the reference device is configured to send periodic messages at regular intervals to the smart contract, and the smart contract is configured to determine whether the activation or usage of the personal device is authorized or not based on information included in the periodic messages. (13) The system of (12), wherein the software module on the personal device is configured to send a timestamp and / or location information of the personal device to the smart contract when invoking the smart contract, and the periodic messages from the reference device include a timestamp of last periodic message and / or location information of the reference device, and the smart contract is configured to determine whether the activation or usage of the personal device is authorized or not based on the timestamp of last periodic message and / or the location information of the reference device and the timestamp and / or location information of the personal device. (14) A device, comprising: a processor; and a storage device including a software module, wherein the software module is configured to, when executed on the processor, detect an activation or usage of the personal device and invoke a smart contract deployed on a blockchain with which the personal device is registered upon detection of the activation or usage of the personal device. (15) A machine-readable medium including code, when executed, to cause a machine to perform the method of any one of (1)-(10).

[0071] The aspects and features mentioned and described together with one or more of thepreviously detailed examples and figures, may as well be combined with one or more of theother examples in order to replace a like feature of the other example or in order to additionally introduce the feature to the other example.

[0072] Examples may further be or relate to a computer program having a program codefor performing one or more of the above methods, when the computer program is executed on a computer or processor. Steps, operations or processes of various above-described methods may be performed by programmed computers or processors. Examples may also cover program storage devices such as digital data storage media, which are machine, processor or computer readable and encode machine-executable, processor-executable or computer-executable programs of instructions. The instructions perform or cause performing some or all of the acts of the above-described methods. The program storage devices may comprise or be, for instance, digital memories, magnetic storage media such as magnetic disks and magnetic tapes, hard drives, or optically readable digital data storage media. Further examples may also cover computers, processors or control units programmed to perform the acts of the above-described methods or (field) programmable logic arrays ((F)PLAs) or (field) programmable gate arrays ((F)PGAs), programmed to perform the acts of the above-described methods.

[0073] The description and drawings merely illustrate the principles of the disclosure.Furthermore, all examples recited herein are principally intended expressly to be only for pedagogical purposes to aid the reader in understanding the principles of the disclosure and the concepts contributed by the inventor(s) to furthering the art. All statements herein reciting principles, aspects, and examples of the disclosure, as well as specific examples thereof, are intended to encompass equivalents thereof.

[0074] A functional block denoted as “means for …” performing a certain function mayrefer to a circuit that is configured to perform a certain function. Hence, a “means for s.th.” may be implemented as a “means configured to or suited for s.th.”, such as a device or a circuit configured to or suited for the respective task.

[0075] Functions of various elements shown in the figures, including any functional blockslabeled as “means”, “means for providing a sensor signal”, “means for generating a transmit signal.”, etc., may be implemented in the form of dedicated hardware, such as “a signal provider”, “a signal processing unit”, “a processor”, “a controller”, etc. as well as hardware capable of executing software in association with appropriate software. When provided by a processor, the functions may be provided by a single dedicated processor, by a single shared processor, or by a plurality of individual processors, some of which or all of which may be shared. However, the term “processor” or “controller” is by far not limited to hardware exclusively capable of executing software but may include digital signal processor (DSP)hardware, network processor, application specific integrated circuit (ASIC), field programmable gate array (FPGA), read only memory (ROM) for storing software, random access memory (RAM), and non-volatile storage. Other hardware, conventional and / or custom, may also be included.

[0076] A block diagram may, for instance, illustrate a high-level circuit diagramimplementing the principles of the disclosure. Similarly, a flow chart, a flow diagram, a state transition diagram, a pseudo code, and the like may represent various processes, operations or steps, which may, for instance, be substantially represented in computer readable medium and so executed by a computer or processor, whether or not such computer or processor is explicitly shown. Methods disclosed in the specification or in the claims may be implemented by a device having means for performing each of the respective acts of these methods.

[0077] It is to be understood that the disclosure of multiple acts, processes, operations,steps or functions disclosed in the specification or claims may not be construed as to be within the specific order, unless explicitly or implicitly stated otherwise, for instance for technical reasons. Therefore, the disclosure of multiple acts or functions will not limit these to a particular order unless such acts or functions are not interchangeable for technical reasons. Furthermore, in some examples a single act, function, process, operation or step may include or may be broken into multiple sub–acts, -functions, -processes, -operations or –steps, respectively. Such sub acts may be included and part of the disclosure of this single act unless explicitly excluded.

[0078] Furthermore, the following claims are hereby incorporated into the detaileddescription, where each claim may stand on its own as a separate example. While each claim may stand on its own as a separate example, it is to be noted that - although a dependent claim may refer in the claims to a specific combination with one or more other claims - other examples may also include a combination of the dependent claim with the subject matter of each other dependent or independent claim. Such combinations are explicitly proposed herein unless it is stated that a specific combination is not intended. Furthermore, it is intended to include also features of a claim to any other independent claim even if this claim is not directly made dependent to the independent claim.

Claims

Claims1. A method for detecting an unauthorized usage of a personal device, comprising:registering, by a user of a set of personal devices, the set of personal devices with a smart contract on a blockchain, wherein each personal device includes a software module configured to detect an activation or usage of a host personal device on which the software module is installed; detecting, by a software module installed on a first personal device, an activation or usage of the first personal device; invoking, by the software module on the first personal device, the smart contract upon detection of the activation or usage of the first personal device; determining, by the smart contract, whether the activation or usage of the first personal device is authorized or not; and sending a warning to the user if it is determined that the activation or usage of the first personal device is unauthorized.

2. The method of claim 1, wherein one of the set of personal devices is designated as areference device, and the reference device sends periodic messages at regular intervals to the smart contract, and it is determined by the smart contract whether the activation or usage of the first personal device is authorized or not based on information included in the periodic messages.

3. The method of claim 2, wherein a personal device closest to the user or a personal devicethat the user is currently using is designated as the reference device.

4. The method of claim 2, wherein each periodic message includes a timestamp and / orlocation information of the reference device, and the smart contract determines whether the activation or usage of the first personal device is authorized or not based on the timestamp and / or the location information of the reference device.

5. The method of claim 4, wherein the software module on the first personal device sendsa timestamp and / or location information of the first personal device to the smart contract when invoking the smart contract, and the smart contract determines whether the activation or usage of the first personal device is authorized or not based on the timestamp and / or the locationinformation of the reference device and the timestamp and / or location information of the first personal device.

6. The method of claim 1, wherein the set of personal devices are registered with the smartcontract by creating in the smart contract a cryptographic structure that is configured to verify whether a personal device belongs to the set of personal devices without revealing membership of the set of personal devices.

7. The method of claim 1, wherein the software module on the first personal device detectsthe activation or usage of the first personal device based on power consumption on the first personal device.

8. The method of claim 1, further comprising:generating, by the smart contract, an event on the blockchain upon detecting that the activation or usage of the first personal device is unauthorized, wherein the warning is sent to the user based on the event.

9. A method implemented by a smart contract deployed on a blockchain for detecting anunauthorized usage of a personal device, comprising: receiving periodic messages at regular intervals from a reference device, wherein the reference device is a personal device designated among a set of personal devices of a user registered with the smart contract; receiving an invoking message from a first personal device; determining whether an activation or usage of the first personal device is authorized or not based on the invoking message; and either sending a warning to the user or generating an event on the blockchain if it is determined that the activation or usage of the first personal device is unauthorized.

10. A method for detecting an unauthorized usage of a personal device, wherein a set of personal devices of a user are registered with a smart contract on a blockchain, and each personal device includes a software module configured to detect an activation or usage of a host personal device on which the software module is installed, the method comprising: detecting, by a software module installed on a personal device, an activation or usage of the personal device; andinvoking, by the software module, the smart contract with which the personal device is registered upon detection of the activation or usage of the personal device.

11. A system for detecting an unauthorized usage of a personal device, comprising: a smart contract deployed on a blockchain; and a set of personal devices, wherein the set of personal devices are registered with the smart contract, and each personal device comprising a software module that is configured to detect an activation or usage of a host personal device in which the software module is installed and invoke the smart contract upon detection of the activation or usage of the host personal device, wherein the smart contract is configured to determine whether an activation or usage of a personal device that invokes the smart contract is authorized or not, and either send a warning to a user of the set of personal devices or generate an event on the blockchain if it is determined that the activation or usage of the personal device is unauthorized.

12. The system of claim 11, wherein one of the set of personal devices is designated as a reference device, and the reference device is configured to send periodic messages at regular intervals to the smart contract, and the smart contract is configured to determine whether the activation or usage of the personal device is authorized or not based on information included in the periodic messages.

13. The system of claim 12, wherein the software module on the personal device is configured to send a timestamp and / or location information of the personal device to the smart contract when invoking the smart contract, and the periodic messages from the reference device include a timestamp of last periodic message and / or location information of the reference device, and the smart contract is configured to determine whether the activation or usage of the personal device is authorized or not based on the timestamp of last periodic message and / or the location information of the reference device and the timestamp and / or location information of the personal device.

14. A device, comprising: a processor; and a storage device including a software module, wherein the software module is configured to, when executed on the processor, detect an activation or usage of the device andinvoke a smart contract deployed on a blockchain with which the device is registered upon detection of the activation or usage of the device.

15. A machine-readable medium including code, when executed, to cause a machine to perform a method of claim 1.

Citation Information

Patent Citations

  • Collaborating user devices for security

    US20160189134A1

  • Method for identifying unauthorized access of an account of an online service

    US20180288066A1

  • Block chain-based smart alarm method and apparatus, and electronic device

    WO2020114112A1