Apparatus, system and method for authenticating an integrated chip product

The apparatus and method authenticate integrated chip cards by comparing power traces from a card reader and oscilloscope, ensuring only identical products are accepted, addressing the challenge of verifying card authenticity.

WO2026072039A1PCT designated stage Publication Date: 2026-04-02MASTERCARD INT INC
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-26
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Financial institutions face challenges in authenticating integrated chip cards, as they lack a reliable method to verify if the received cards are the same as those that passed security and functional tests, especially when purchasing from third-party suppliers or during transit.

Method used

An apparatus and method using a card reader with a built-in power sensor and oscilloscope to capture power traces from integrated chips, comparing these traces with stored datasets to authenticate the cards.

Benefits of technology

Effectively verifies the authenticity of integrated chip cards by matching power traces, ensuring that only identical products are accepted, reducing the risk of counterfeit or altered cards.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2024048507_02042026_PF_FP_ABST
    Figure US2024048507_02042026_PF_FP_ABST
Patent Text Reader

Abstract

There is provided an apparatus for authenticating an integrated chip within a product. The apparatus comprises a card reader having a built-in power sensor and an oscilloscope in communication with the card reader. The apparatus further comprises one or more processors coupled to the card reader and oscilloscope. A non-transitory computer-readable medium and a database are in communication with the one or more processors. The non-transitory computer-readable medium includes instructions that, when executed by the one or more processors, cause the one or more processors to perform operations including obtain a first power trace from a first product by inserting the first product via the card reader, store the first set of power traces in the database, receive a second set of power traces from a second product and compare the first and second power traces to determine if the second product is considered to be the same as the first product.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] APPARATUS, SYSTEM AND METHOD FOR AUTHENTICATING

[0002] AN INTEGRATED CHIP PRODUCT

[0003] TECHNICAL FIELD

[0004] The present disclosure is generally directed to integrated chips in particular, to authenticating products having integrated chips.

[0005] BACKGROUND

[0006] Financial institutions provide credit cards and debit cards for consumers to make transactions at their convenience. Credit cards, debit cards or the like typically contain several types of identifying information. Printed information on the card can include cardholder name, account information, expiration date, etc. In addition, cards can include an integrated chip (IC) within the card to support a transaction. The IC is a microchip that stores cardholder information similar to the information printed on the card. To initiate a payment transaction using a card having an IC, the IC interacts with a merchant’s point-of-sale (POS) terminal or an automatic teller machine (ATM) by inserting the card and reading the payment data from the IC.

[0007] Problems with such integrated chip cards arise when the financial institution that issues the cards have no way of authenticating if the card received is the same card that passed security and functional tests of the manufacturer. In some cases, the financial institution may be purchasing from a 3rdparty supplier and not directly from the manufacturer. There may be several reasons why the chip card received by the financial institution is different from one that was manufactured. For example, the wrong card may have been sent by accident, the evaluation process at the financial institution may take too long to complete or it is expensive to allocate resources to verify every chip card received, or the product may have been switched in transit to facilitate an attack.

[0008] Therefore, there is a need for providing an apparatus, system and method for authenticating an integrated chip card. The present disclosure has been devised to mitigate or overcome at least some of the above-mentioned problems.

[0009] SUMMARY OF THE DISCLOSURE

[0010] According to a first aspect of the present disclosure, there is provided an apparatus for authenticating an integrated chip within a product. The apparatus comprises a card reader having a built-in power sensor and an oscilloscope in communication with the card reader. The apparatus further comprises one or more processors coupled to the card reader and oscilloscope. A non-transitory computer- readable medium and a database are in communication with the one or more processors. The non-transitory computer-readable medium includes instructions that, when executed by the one or more processors, cause the one or more processors to perform operations including obtaining one or more power traces from a first product by inserting the first product into the card reader, store the first power trace(s) in the database, obtain one or more power traces from a second product and compare the first and second power traces to determine if the second product is considered to be the same as the first product.

[0011] In embodiments, the first and second products each contain a first and second integrated chip such that the oscilloscope outputs a change in power of transistor operations of each respective first and second integrated chips as a first and second dataset, respectively.

[0012] In further embodiments, the step of comparing comprises comparing the first and second datasets such that an exact match of the first and second datasets results in first and second products considered to be the same.

[0013] In additional embodiments, the step of comparing comprises comparing the first and second datasets such that a variation of the first and second datasets within a predetermined range results in first and second products considered to be the same. The step of comparing also comprises comparing the first and second datasets such that a variation of the first and second datasets outside a predetermined range result in the second product being non authenticated.

[0014] According to a second aspect of the present disclosure, there is provided a system for authenticating an integrated chip within a product. The system comprises a database for storing at least one power trace, one or more processors; and a non-transitory computer-readable medium. The computer-readable medium including instructions that, when executed by the one or more processors, cause the one or more processors to perform operations. The instructions include: obtain a first set of power traces from a first integrated chip of a first product by inserting the first product into a card reader having a built-in power sensor, store the first set of power traces in the database, receive a second set of power traces from a second product having a second integrated chip by inserting the second product into the card reader, and compare the first and second power traces to determine if the second product is considered to be the same as the first product.

[0015] In further embodiments, the step of determining comprises comparing a first and second dataset recorded from each of the first and second power traces such that a match of the first and second dataset results in identical first and second products.

[0016] In additional embodiments, a variation of the first and second datasets within a predetermined range results in identical first and second products. In other embodiments, a variation of the first and second datasets outside a predetermined range result in the second transaction device being a non-authenticated product.

[0017] According to a third aspect of the present disclosure, there is provided a method of authenticating an integrated chip within a product. The method comprising obtaining a first set of power traces from a first integrated chip of a first product by inserting the first product into a card reader having a built-in power sensor. Next, the method comprises storing the first set of power traces in a database in communication with a processor and memory coupled to the card reader and receiving a second set of power traces from a second product having a second integrated chip by inserting the second card into the card reader. The first and second power traces are compared to determine if the second product is identical to the first product. The first and second integrated chips are embedded within the respective first and second products.

[0018] In further embodiments, the step of determining comprises comparing a first and second dataset recorded from each of the first and second power traces such that an exact match of the first and second dataset results in 1 first and second products considered to be the same.

[0019] In further embodiments, a variation of the first and second datasets within a predetermined range results in first and second products considered to be the same. A variation of the first and second datasets outside a predetermined range result in the second card being a non-authenticated product.

[0020] In additional embodiments, the card reader is coupled to an oscilloscope for outputting a change in operation of each respective first and second integrated chips as a dataset.

[0021] In further embodiments, the step of receiving a second power trace from a second products occurs an amount of time after obtaining the first power trace. Within the scope of this application, it is expressly intended that the various aspects, embodiments, examples and alternatives set out in the preceding paragraphs, in the claims and / or in the following description and drawings, and in particular the individual features thereof, may be taken independently or in any combination. That is, all embodiments and / or features of any embodiment can be combined in any way and / or combination, unless such features are incompatible. The applicant reserves the right to change any originally filed claim or file any new claim accordingly, including the right to amend any originally filed claim to depend from and / or incorporate any feature of any other claim although not originally claimed in that manner.

[0022] BRIEF DESCRIPTION OF THE DRAWINGS

[0023] One or more embodiments of the disclosure will now be described, by way of example only, with reference to the accompanying drawings, in which:

[0024] FIG. 1 A is a schematic diagram showing the front face of a sample integrated chip card;

[0025] FIG. IB is a schematic diagram showing the back face of the card, shown in Figure 1 A;

[0026] FIG. 1C is an enlarged view of the integrated chip of FIG. 1 A;

[0027] FIG. 2 illustrates an apparatus in accordance with the present disclosure for authenticating a product having an integrated chip;

[0028] FIG. 3 is process flow of a method in accordance with the present disclosure using the apparatus of FIG. 2;

[0029] FIG. 4A is a schematic diagram showing a power trace match using the apparatus of FIG. 2;

[0030] FIG. 4B is a schematic diagram showing a power trace match within a predetermined range using the apparatus of FIG. 2;

[0031] FIG. 4C is a schematic diagram showing power traces outside a predetermined range using the apparatus of FIG. 2;

[0032] FIG. 5 is a process flow illustrating a first scenario for use of the apparatus of FIG. 2; and

[0033] FIG. 6 is a process flow illustrating a second scenario for use of the apparatus of FIG. 2; DETAILED DESCRIPTION

[0034] The following description is not intended to limit the invention to the forms disclosed herein. Consequently, variations and modifications commensurate with the following teachings, skill and knowledge of the relevant art, are within the scope of the present invention. The embodiments described herein are further intended to explain modes known of practicing the invention and to enable others skilled in the art to utilize the invention in such embodiments or other embodiments and with various modifications required by the particular application(s) or use(s) of the present invention.

[0035] FIGS. 1 A and IB are front and back views, respectively, of an integrated chip (IC) card 10a, 10b known in the art. As shown in FIG. 1 A, a front face of card 10a, 10b may include an issuer payment institution identifier 12 (e.g. a name and / or logo) and a payment processing institution identifier 14 (e.g. a name and / or logo). Further, personalization data corresponding with a single specific payment account administered by the issuer payment / financial institution may be provided on the front face of the chip card 10. For example, the personalization data may include payment account identification indicia 16 (e.g. a payment account number or other indicia that may be correlated to a payment account administered by the issuer payment institution), a card holder name 18 (e.g. the name of an individual to whom the transaction device has been issued by the issuer payment institution), and an expiration date 20 associated with the given payment account.

[0036] Additionally, a region 22 may be provided for inclusion of an integrated circuit (IC) chip 24. The IC 24 is an embedded microchip that stores consumer information away from sight view. As shown in FIG. IC, ICs contain an electrical circuit 26 having one or more transistors 28 that amplify the circuit and provide a switch of power within the circuit 26. IC cards are gaining in popularity due to the increased data security when making transactions at stores, POS terminals, or automated teller machines (ATMs). Those skilled in the art will recognize the circuit 26 shown in FIG. IC is exemplary only to illustrate the features an IC circuit may contain. The IC 24 could contain possibly billions of similar circuits. FIG IC is illustrative only showing the concept of power analysis, looking at the transistor 28 leakage model. The detailed circuitry for each IC product will vary and the exact features will not divert from the present disclosure. As shown in FIG. IB a back face of chip card 10a, 10b may include a magnetic stripe 30 comprising magnetically encoded data corresponding with the given payment account associated with the chip card 10. Additionally, a signature block 34 may be provided for receiving a signature by the individual to whom the chip card 10a, 10b is issued for exclusive use. Further, at least one card security code 36 may be provided, wherein the card security code 36 may be required in connection with use of card 10a, 10b to complete a given payment transaction.

[0037] Those skilled in the art will recognize the IC card shown and described in the embodiments herein are standard IC credit and / or debit cards but are not limited to such. Various embodiments exist of IC chip cards including, employee identification cards, SIM’s / eSIM’s, flash memory chips (often used in the automotive industry), or the like, may be used in accordance with the present disclosure.

[0038] As noted above, a unique feature of the IC cards 10a, 10b is that the chip 24 itself is embedded within the card 10a, 10b and therefore not visible from front or back views. Manufacturers of IC cards have several product evaluation programs that exist to make sure all products carrying ICs are evaluated to confirm they work as intended. However, financial institutions such as issuing banks that provide IC cards to consumer have no way of verifying if the card received is the same card that passed functional testing and / or security testing at the manufacturer. Therefore, a product integrity test for a product having an IC is needed.

[0039] The present disclosure provides an apparatus, system and method for allowing authentication of an IC product at two different time intervals. First, to verify if the same IC product that passed security testing also passed functional testing. Second, to authenticate an IC product sent to an issuing bank.

[0040] With reference now to FIG. 2, an apparatus 100 is shown that allows for integrity testing of any products 10a, 10b that contain embedded ICs 24 in accordance with the present disclosure. The apparatus comprises a card reader 102a, 102b having a built-in power sensor. It is envisioned that the sensor can include electromagnetic sensors for contactless cards or any similar sensors which monitor IC operations. The card reader 102 is in communication with an oscilloscope 104 for outputting a change in power of each respective first and second integrated chips 24 as a power trace 120. A credit card or product 10a, 10b having an IC 24 is inserted into the card reader 102 for measuring components of an electrical circuit of the IC 24. More particularly, while the card reader 102 accesses the electronic circuit 26 the oscilloscope 104 measures the electrical switches of transistors 28 on the IC 24 that turn a current on or off. The oscilloscope 104 outputs a power trace 120 in the form of a dataset 122 illustrating a current of switching transistors 28.

[0041] Both card reader 102 and oscilloscope 104 are coupled to a computer 106 in communication with a database 108 for storing at least one power trace, one or more processors 110 and a non-transitory computer-readable medium 112 including instructions that, when executed by the one or more processors 110 perform several functions, including, comparing multiple power traces 120 to authenticate an IC product 10a, 10b.

[0042] Referring now to FIG. 3, a flow diagram 300 of exemplary steps are shown to authenticate whether an IC product 10a presented for authentication is identical to a second IC product 10b using the apparatus of FIG. 2. It will be noted that the products are described herein as a first product and a second product, however, from the front and back views both first and second products will appear to be identical. The apparatus, system and method disclosed herein are designed to verify if indeed the first and second products are in fact considered to be the same by matching the embedded IC chips. More particularly, the system compares known identical cards to learn natural defenses / changes and then compares target cards (that appear identical) by comparing the power traces. A match exists when the target cards fall within the natural changes. On the other hand, if the embedded chips indicate there is not a match, it is noted that, the second product is not authenticated, i.e. not considered the same.

[0043] At step 310, a first product 10a is inserted into the card reader 102 having a built-in power sensor. The card reader 102 (shown herein with a front view 102a and a back view 102b) is in communication with oscilloscope 104 through which various commands are sent to the first product and the power traces 122 are obtained, as shown in step 312. The first power trace set 122 is a dataset 120 measure of the power switch from transistors 28 within the IC 24 of a first product 10a. At step 314, a first set of power traces 410a, 420a, 430a is stored within database 108 coupled to both the oscilloscope 104 and the card reader 102. Next, a second product 10b is inserted into the card reader 102 and a second set of power traces 410b, 420b, 420c is received from a second product 10b at steps 315 and 316. It is envisioned that the product integrity testing can be completed through remote systems in which the second product is inserted into a card reader at a later time during the manufacturing process, during the security evaluation or once the product is received at an issuing bank. Those skilled in the art will recognize that the while along with obtaining a power trace through the oscilloscope several additional operations can be monitored resulting in many power traces (for each card). For example, but not limited to power, EM, light, etc.

[0044] At step 318, the first datasets 412a, 422a, 430a of the first power traces 410a, 420a, 430c are compared with the second frequences 412b, 422b, 432b of the second power traces 410b, 420b, 430b to determine if the second product 20b is identical to the first product 10a. If the comparison indicates an exact match of the first and second datasets then a determination that the first and second products 10a, 10b are identical is made (as shown in FIG. 4A). If the first and second products 10a, 10b are proven identical, as indicated at step 319, with matching power traces then no further action is required as shown in step 320. If the first and second power traces are not identical then, at step 321, the power traces are evaluated to determine if they fall within an acceptable range. If yes, then again no further action is required, step 320. If on the other hand, the power traces are outside an acceptable difference, then manual testing is implemented, at shown in step 322.

[0045] FIGS. 4A-4B illustrate exemplary power trace comparisons 410, 420 and 430. In FIG. 4 A power trace 410a from a first product 10a is compared to power trace 410b from a second product 10b. If the datasets 412a, 412b are compared at two different points of time and illustrate the same values, then the product integrity test shows products 10a, 10b are the same.

[0046] On the other hand, as shown in FIGS. 4B and 4C, variations of comparisons 420 and 430 of power traces 420a, 420b, 430a, 430b that are not identical are shown and therefore may or may not represent authentic products. In FIG. 4B, power traces 420a, 420b are similar, but the variation of datasets 422a, 422b is within a predetermined range, thereby indicating two products are considered to be the same. In this instance, power traces 420a, 420b may look the same but with acceptable security defences. During the step of comparing, countermeasures for similar products are considered. For example, clock jitter, variable operating frequency, random wait states, etc. Each of these countermeasures ensures products considered to be the same but with acceptable different power traces. Whereas in FIG. 4C the variations in datasets 432a, 432b during comparison 430 of power traces 430a, 430b is outside a predetermined acceptable range, thereby indicating that the two products are not considered to be the same. In other words, the apparatus 100 is designed to distinguish between natural defences due to simply to different hardware or software and completely different type of hardware and software. As described in further detail in FIG 5., the apparatus 100 may also be shown to be inconclusive, so it does not know for sure if the differences are natural or relating to a modified product, hence it will report “inconclusive” and request Manual PIT. Due to a chip cards natural defences of timing / operation and power profile differences, the process for determining product differences is not within the scope of this disclosure.

[0047] With reference to FIGS. 5 and 6. two process flow charts 500 and 600 are shown which illustrate two different time occurrences when the apparatus of FIG. 2 and the process flow of FIG. 3 is utilized to authenticate an IC product 10. As noted above, from the front and back views of a standard IC card / product 10 there is no clear indication if the IC is the same as one that either passed security or functional testing and / or the same as that is now in the possession of an issuing bank.

[0048] With respect to FIG. 5 the process flow 500 shown and described can be used to verify if a product submitted for a security evaluation, at step 502, is identical to a product submitted for a functional evaluation, at step 504. Any modifications to a product must be assessed by both security and functional testing. In general, these steps are completed prior to the product being shipped to either a third party or an issuing bank. As shown, two product samples are gathered for testing. One of the products previously passed security testing and the second product has passed functional testing. It is important to note that both products have functioning IC embedded within the products, but from the front and back views (as discussed above) the products appear identical.

[0049] Once the product samples are ready, at step 506, the first step is to complete the automatic product integrity (A-PIT) testing using the apparatus shown and described in FIG. 2. Details of the process steps using the apparatus shown and described above in FIG. 3. If the samples pass the A-PIT then a product match exists, and no further action is required, at shown in step 508.

[0050] If the products do not match, further testing is required. The next step, 512, is for manual product integrity testing (M-PIT) to be performed. If both products are shown to match during M-PIT, no further action is required, as step 508. If both products do not match, the final step, 516, is to contact product development. With reference now to FIG. 6, a similar process flow 600 is envisioned after a product has passed the security and functional testing of FIG. 5. In this instance, the product delivered to the issuing bank must be considered the same as the product as previously evaluated. As shown in steps 602 and 604 a product that has passed security and functional testing and has been sent to an issuing bank, either directly from the manufacturer or from a 3rdparty, is evaluated. Similar to FIG 5, A- PIT is first completed, at step 606, and should products show a match no action is required, as shown in step 608. If the product received at the issuing bank does not match a product previously approved through A-PIT, then at step 612, a M-PIT is conducted. At this point, if during M-PIT the products are shown to be the same then no further action is taken, at step 608. However, as shown in step 616, if the products are not shown to match, the issuing bank is notified as such with a detailed report that the product is not valid, advising the issuing bank should investigate this issue directly with the product supplier.

[0051] Many modifications may be made to the specific embodiments described above without departing from the scope of the invention as defined in the accompanying claims. Features of one embodiment may also be used in other embodiments, either as an addition to such embodiment or as a replacement thereof.

[0052] In some examples, the operations illustrated in the FIGS can be implemented as software instructions encoded on a computer-readable medium, in hardware programmed or designed to perform the operations, or both. For example, aspects of the disclosure can be implemented as a system on a chip or other circuitry including a plurality of interconnected, electrically conductive elements.

[0053] While the aspects of the disclosure have been described in terms of various examples with their associated operations, a person skilled in the art would appreciate that a combination of operations from any number of different examples is also within scope of the aspects of the disclosure.

[0054] The term “comprising” is used in this specification to mean including the feature(s) or act(s) followed thereafter, without excluding the presence of one or more additional features or acts.

[0055] In some examples, the operations illustrated in the figures are implemented as software instructions encoded on a computer readable medium, in hardware programmed or designed to perform the operations, or both. For example, aspects of the disclosure are implemented as a system on a chip or other circuitry including a plurality of interconnected, electrically conductive elements.

[0056] The order of execution or performance of the operations in examples of the disclosure illustrated and described herein is not essential, unless otherwise specified. That is, the operations may be performed in any order, unless otherwise specified, and examples of the disclosure may include additional or fewer operations than those disclosed herein. For example, it is contemplated that executing or performing a particular operation before, contemporaneously with, or after another operation is within the scope of aspects of the disclosure.

[0057] When introducing elements of aspects of the disclosure or the examples thereof, the articles "a," "an," "the," and "said" are intended to mean that there are one or more of the elements. The terms "comprising," "including," and "having" are intended to be inclusive and mean that there may be additional elements other than the listed elements. The term “exemplary” is intended to mean “an example of.” The phrase “one or more of the following: A, B, and C” means “at least one of A and / or at least one of B and / or at least one of C."

[0058] Within the scope of this application, it is expressly intended that the various aspects, embodiments, examples, and alternatives set out in the preceding paragraphs, in the claims and / or in the description and drawings, and in particular the individual features thereof, may be taken independently or in any combination. That is, all embodiments and / or features of any embodiment can be combined in any way and / or combination, unless such features are incompatible. The applicant reserves the right to change any originally filed claim or file any new claim, accordingly, including the right to amend any originally filed claim to depend from and / or incorporate any feature of any other claim although not originally claimed in that manner.

[0059] Having described aspects of the disclosure in detail, it will be apparent that modifications and variations are possible without departing from the scope of aspects of the disclosure as defined in the appended claims. As various changes could be made in the above constructions, products, and methods without departing from the scope of aspects of the disclosure, it is intended that all matter contained in the above description and shown in the accompanying drawings shall be interpreted as illustrative and not in a limiting sense.

Claims

1. CLAIMS1. An apparatus for authenticating an integrated chip within a product, comprising: a card reader having a built-in power sensor; an oscilloscope in communication with the card reader; one or more processors coupled to the card reader and oscilloscope; a non-transitory computer-readable medium; and a database in communication with the one or more processors, wherein the non-transitory computer-readable medium includes instructions that, when executed by the one or more processors, cause the one or more processors to perform operations including: obtain a first set of power traces from a first product by inserting the first product into the card reader; store the first set of power traces in the database; receive a second set of power traces from a second product; and compare the first and second sets of power traces to determine if the second product is the same as the first product.

2. The apparatus of Claim 1, wherein the first and second products each contain a first and second integrated chips such that the oscilloscope outputs a change in operation via electromagnetic field differences of each respective first and second integrated chips as a first and second dataset, respectively.

3. The apparatus of Claim 2, wherein the step of comparing comprises comparing the first and second datasets such that a match of the first and second datasets results in first and second products considered to be the same.

4. The apparatus of Claim 2, wherein the step of comparing comprises comparing the first and second datasets such that a variation of the first and second datasets within a predetermined range results in first and second products considered to be the same.

5. The apparatus of Claim 2, wherein the step of comparing comprises comparing the first and second datasets such that a variation of the first and second datasets outside a predetermined range result in the second product considered not authentic.

6. A system for authenticating an integrated chip within a product, comprising: a database for storing at least one power trace; one or more processors; and a non-transitory computer-readable medium including instructions that, when executed by the one or more processors, cause the one or more processors to perform operations including: obtain a first set of power traces from a first integrated chip of a first product by inserting the first product into a card reader having a built-in power sensor; store the first set of power traces in the database; receive a second set of power traces from a second product having a second integrated chip by inserting the second product into the card reader; and compare the first and second sets of power traces to determine if the second product is the same as the first product.

7. The system of Claim 6, wherein the step of determining comprises comparing a first and second dataset recorded from each of the first and second power traces such that a match of the first and second datasets results in the first and second products considered to be the same.

8. The system of Claim 7, wherein a variation of the first and second datasets within a predetermined range results in the conclusion that the first and second products are considered to be the same.

9. The system of Claim 7, wherein a variation of the first and second datasets outside a predetermined range result in the second transaction device being a non-authenticated product.

10. A method of authenticating an integrated chip within a product, comprising: obtaining a first set of power traces from a first integrated chip of a first product by inserting the first product into a card reader having a built-in power sensor; storing the first set of power traces in a database in communication with a processor and memory in coupled to the card reader; receiving a second set of power traces from a second product having a second integrated chip by inserting the second card into the card reader; and comparing the first and second sets of power traces to determine if the second product is considered to be the same as the first product, wherein the first and second integrated chips are embedded within the respective first and second products.

11. The method of Claim 10, wherein the step of determining comprises comparing a first and second dataset recorded from each of the first and second power traces such that a match of the first and second dataset results in first and second products are considered to be the same.

12. The method of Claim 11, wherein a variation of the first and second datasets within a predetermined range results in the conclusion that the first and second products are considered to be the same.

13. The method of Claim 11, wherein a variation of the first and second datasets outside a predetermined range result in the second card being a nonauthenticated product.

14. The method Claim 11, wherein the card reader is coupled to an oscilloscope for outputting a change in operational power of each respective first and second integrated chips as a dataset.

15. The method of Claim 11, wherein the step of receiving a second power trace from a second products occurs an amount of time after obtaining the first power trace.

Citation Information

Patent Citations

  • Method for manufacturing smart card and identification devices and the like

    US20020186004A1

  • Device for testing smart card and method of testing the smart card

    US20050034028A1

  • Detecting counterfeit magnetic stripe cards using encoding jitter

    US20180314862A1

  • Method for hardware integrity control of an integrated circuit card

    US20210025937A1

  • Method for testing a circuit card assembly

    US8620620B1