Anti-tampering arrangement for computing device
The anti-tampering arrangement with multiple sensors and a processor effectively addresses unauthorized access in computing devices by detecting and responding to tampering attempts, ensuring secure operation and data integrity.
Patent Information
- Application Number
- PCT/IL2025/050905
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-07-17
- Filing Date
- 2025-10-12
- Publication Date
- 2026-04-16
Smart Images

Figure IL2025050905_16042026_PF_FP_ABST
Abstract
Description
[0001] ANTI-TAMPERING ARRANGEMENT FOR COMPUTING DEVICE
[0002] FIELD OF THE INVENTION
[0003] The present invention relates to anti-tampering security systems for computing devices, and more particularly to an anti-tampering arrangement with multiple detection mechanisms and sensors for preventing illegitimate tampering and unauthorized physical access to computing devices with secure remote access capabilities.
[0004] BACKGROUND
[0005] Computing devices used in organizational environments face increasing security challenges as remote work and distributed access become more prevalent. Physical security of computing devices represents a fundamental layer of protection that complements software-based security measures. When computing devices contain sensitive organizational data or provide access to internal networks, protecting against unauthorized physical access becomes a consideration for maintaining overall system security.
[0006] Traditional computing devices may be vulnerable to various forms of physical tampering, including attempts to access internal components, extract stored data, or modify hardware configurations. Such tampering attempts may involve drilling, cutting, heating, or other physical methods to breach device enclosures and gain access to internal electronics. Physical access to computing device components can potentially compromise encryption keys, certificates, or other security credentials stored within the device.
[0007] Anti-tampering technologies have been developed to detect and respond to unauthorized physical access attempts. These technologies may employ various detection mechanisms, including sensors that monitor environmental conditions, mechanical switches that detect enclosure opening, and electronic circuits that can identify physical breaches. The integration of multiple detection methods can provide layered protection against different types of tampering attempts.
[0008] Sensor-based detection systems may monitor parameters such as temperature variations, vibrations, light changes, and other environmental factors that could indicate tampering activities. Heat sensors can detect temperature increases associated with welding or drilling operations. Vibration sensors can identify mechanical disturbances caused by cutting or piercing activities. Light sensors can monitor changes in illumination patterns that may occur during unauthorized access attempts. Electronic detection circuits may be embedded within computing device structures to provide additional protection. These circuits can include conductive traces or pathways that are designed to be disrupted when physical tampering occurs. When such circuits are compromised, the disruption can trigger security responses such as data deletion or system shutdown.
[0009] The management and coordination of multiple anti-tampering detection systems presents technical challenges related to sensor integration, signal processing, and response coordination. Systems may need to differentiate between legitimate environmental changes and those indicative of tampering attempts. False positive detections could disrupt normal device operation, while false negatives could allow unauthorized access to proceed undetected.
[0010] Physical protection layers, such as specialized coatings or barriers, may be incorporated into computing device designs to provide additional resistance to tampering attempts. These layers can include materials that change properties when disturbed, providing another mechanism for detecting unauthorized access attempts.
[0011] SUMMARY
[0012] This summary is provided to introduce a selection of concepts in a simplified form that are further described below in the detailed description. This summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used as an aid in determining the scope of the claimed subject matter.
[0013] According to an aspect of the present disclosure, an anti-tampering arrangement for a computing device is provided. The anti-tampering arrangement includes an intrusion detector configured to detect an infiltration of a printed circuit board of the computing device. The antitampering arrangement includes a sensors layer comprising at least one sensor selected from the group consisting of: a heat sensor configured to detect temperature changes indicative of tampering operations, a vibration sensor configured to detect vibrations associated with tampering operations, a light sensor configured to detect lighting variations indicative of tampering attempts, an internal cell sensor configured to detect tampering of a designated high security region of the computing device containing at least one highly sensitive component, and a device access sensor configured to detect unauthorized opening of a housing of the computing device. The anti-tampering arrangement includes a processor configured to monitor the intrusion detector and the sensors layer, and to trigger a security response upon detection of a tampering attempt.
[0014] According to other aspects of the present disclosure, the anti-tampering arrangement may include one or more of the following features. The anti-tampering arrangement may further include a memory configured to store a digital certificate, wherein the processor may be configured to delete the digital certificate from the memory upon detection of a tampering attempt. The intrusion detector may include a plurality of transmitting controllers and a plurality of receiving controllers communicatively coupled by a plurality of communication traces arranged in an intersecting pattern on the printed circuit board, wherein the communication traces may be configured to convey electrical signals from the transmitting controllers to the receiving controllers, and wherein the communication traces may be configured to be severed upon physical penetration of the printed circuit board. The anti-tampering arrangement may further include a polymer protective lining disposed between the printed circuit board and an exterior casing of the computing device, wherein the polymer protective lining may include conductive material configured to change electrical properties upon contact to detect tampering attempts. The light sensor may include a light emission element configured to emit light according to a predetermined pattern and a light detection element configured to detect changes in the predetermined pattern indicative of unauthorized access to the computing device. The heat sensor may be selected from the group consisting of thermocouples, thermistors, resistance temperature detectors, and semiconductor-based integrated sensors. The vibration sensor may be selected from the group consisting of accelerometers, strain gauges, velocity sensors, pressure sensors, laser displacement sensors, and vibration meters. The processor may be configured to monitor each component of the sensors layer continuously or at predetermined time intervals, and wherein the processor may be configured to issue an alert notification to at least one client device upon detection of a tampering attempt by any component of the sensors layer or the intrusion detector. The alert notification may be sent to the at least one client device using an application program interface. The computing device may be configured to provide secure remote access to an organization network through a remote access server, and wherein the alert notification may be transmitted to the remote access server to enable monitoring of tampering attempts across multiple computing devices in the secure remote access system.
[0015] According to another aspect of the present disclosure, a method for detecting tampering of a computing device is provided. The method includes monitoring an intrusion detector configured to detect infiltration of a printed circuit board of the computing device. The method includes monitoring a sensors layer comprising at least one sensor selected from the group consisting of a heat sensor configured to detect temperature changes indicative of tampering operations, a vibration sensor configured to detect vibrations associated with tampering operations, a light sensor configured to detect lighting variations indicative of tampering attempts, an internal cell sensor configured to detect tampering of a designated high security region of the computing device, and a device access sensor configured to detect unauthorized opening of a housing of the computing device. The method includes determining whether a tampering attempt has occurred based on detection signals from the intrusion detector or the sensors layer. The method includes triggering a security response upon detection of the tampering attempt.
[0016] According to other aspects of the present disclosure, the method may include one or more of the following features. The security response may include deleting a digital certificate stored in memory. Monitoring the intrusion detector may include monitoring electrical signals transmitted through a plurality of communication traces arranged in an intersecting pattern on the printed circuit board, and detecting a disruption in the electrical signals caused by severing of the communication traces during physical penetration of the printed circuit board. The method may further include monitoring electrical properties of a polymer protective lining disposed between the printed circuit board and an exterior casing of the computing device, wherein the polymer protective lining may include conductive material configured to change electrical properties upon contact during tampering attempts. Monitoring the sensors layer may include monitoring a light sensor that emits light according to a predetermined pattern using a light emission element and detects changes in the predetermined pattern using a light detection element, wherein changes in the predetermined pattern may indicate unauthorized access to the computing device. Monitoring the intrusion detector and the sensors layer may be performed continuously or at predetermined time intervals, and the method may further include issuing an alert notification to at least one client device upon detection of a tampering attempt. The computing device may be configured to provide secure remote access to an organization network through a remote access server, and wherein the method may further include transmitting an alert notification to the remote access server to enable monitoring of tampering attempts across multiple computing devices in the secure remote access system.
[0017] According to another aspect of the present disclosure, a computing device is provided. The computing device includes a housing. The computing device includes a printed circuit board disposed within the housing. The computing device includes an anti-tampering arrangement comprising an intrusion detector configured to detect an infiltration of a printed circuit board of the computing device, a sensors layer comprising at least one sensor selected from the group consisting of a heat sensor configured to detect temperature changes indicative of tampering operations, a vibration sensor configured to detect vibrations associated with tampering operations, a light sensor configured to detect lighting variations indicative of tampering attempts, an internal cell sensor configured to detect tampering of a designated high security region of the computing device containing at least one highly sensitive component, and a device access sensor configured to detect unauthorized opening of a housing of the computing device, and a processor configured to monitor the intrusion detector and the sensors layer, and to trigger a security response upon detection of a tampering attempt.
[0018] According to other aspects of the present disclosure, the computing device may include one or more of the following features. The computing device may further include a memory configured to store a digital certificate, wherein the processor may be configured to delete the digital certificate from the memory upon detection of a tampering attempt. The intrusion detector may include a plurality of transmitting controllers and a plurality of receiving controllers communicatively coupled by a plurality of communication traces arranged in an intersecting pattern on the printed circuit board, wherein the communication traces may be configured to convey electrical signals from the transmitting controllers to the receiving controllers, and wherein the communication traces may be configured to be severed upon physical penetration of the printed circuit board. The computing device may further include a polymer protective lining disposed between the printed circuit board and an exterior casing of the computing device, wherein the polymer protective lining may include conductive material configured to change electrical properties upon contact to detect tampering attempts. The light sensor may include a light emission element configured to emit light according to a predetermined pattern and a light detection element configured to detect changes in the predetermined pattern indicative of unauthorized access to the computing device. The heat sensor may be selected from the group consisting of thermocouples, thermistors, resistance temperature detectors, and semiconductor-based integrated sensors. The vibration sensor may be selected from the group consisting of accelerometers, strain gauges, velocity sensors, pressure sensors, laser displacement sensors, and vibration meters. The processor may be configured to monitor each component of the sensors layer continuously or at predetermined time intervals, and wherein the processor may be configured to issue an alert notification to at least one client device upon detection of a tampering attempt by any component of the sensors layer or the intrusion detector. The computing device may be configured to provide secure remote access to an organization network through a remote access server, and wherein the processor may be configured to transmit an alert notification to the remote access server to enable monitoring of tampering attempts across multiple computing devices in the secure remote access system. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The present disclosure will be more fully understood from the following detailed description of the embodiments thereof, taken together with the drawings in which:
[0020] FIG. 1 illustrates a block diagram of a secure remote access system, according to aspects of the present disclosure;
[0021] FIG. 2 illustrates a detailed block diagram of portions of the secure remote access system of FIG. 1, according to aspects of the present disclosure;
[0022] FIG. 3 illustrates a block diagram of a user computing device with secure connectivity components, according to aspects of the present disclosure;
[0023] FIG. 4 illustrates a block diagram of an anti-tampering arrangement, according to aspects of the present disclosure; and
[0024] FIG. 5 illustrates a block diagram of the anti-tampering arrangement of FIG. 4 deployed on the user computing device of FIG. 3, according to aspects of the present disclosure.
[0025] DETAILED DESCRIPTION OF EMBODIMENTS
[0026] The following description sets forth exemplary aspects of the present disclosure. It should be recognized, however, that such description is not intended as a limitation on the scope of the present disclosure. Rather, the description also encompasses combinations and modifications to those exemplary aspects described herein.
[0027] The present disclosure relates to anti-tampering security systems for user computing devices, which may be part of a secure remote access system that enables connectivity between external and internal networks while maintaining physical separation through hardwarelevel isolation. Such a remote access system may provide organizations with elevated security requirements the ability to allow remote access to network resources without compromising the integrity of protected internal networks. A remote access server may be positioned between an external network and an organization network to facilitate secure communications while maintaining complete physical separation between external and internal network segments. Antitampering security features may be integrated into user computing devices to detect and respond to unauthorized access attempts. The anti-tampering arrangements may include multiple detection systems such as intrusion detectors, heat sensors, vibration sensors, light sensors, and device access sensors. The anti-tampering arrangements may include protective polymer layers that provide additional physical barriers against unauthorized access attempts. Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the disclosed subject matter belongs. It will be further understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning that is consistent with their meaning in the context of the specification and claims and should not be interpreted in an idealized or overly formal sense unless expressly so defined herein. Well-known functions or constructions may not be described in detail for brevity and / or clarity.
[0028] It will be understood that, although the terms first, second, etc., may be used herein to describe various elements, components, regions, layers and / or sections, these elements, components, regions, layers and / or sections should not be limited by these terms. Rather, these terms are only used to distinguish one element, component, region, layer and / or section, from another element, component, region, layer and / or section.
[0029] It will be understood that when an element is referred to as being “on”, “attached” to, “operatively coupled” to, “operatively linked” to, “operatively engaged” with, “connected” to, “coupled” with, “contacting”, “added to, another element, it can be directly on, attached to, connected to, operatively coupled to, operatively engaged with, coupled with, added to, and / or contacting the other element or intervening elements can also be present. In contrast, when an element is referred to as being “directly contacting” another element or “directly added” to another element, there are no intervening elements present.
[0030] Whenever the term “about” or “approximately” is used, it is meant to refer to a measurable value such as an amount, a temporal duration, and the like, and is meant to encompass variations (e.g., ±20%, ±10%, ±5%, ±1%, ±0.1%) from the specified value, as such variations are appropriate to perform the disclosed methods.
[0031] Certain features of the disclosure, which are, for clarity, described in the context of separate embodiments, may also be provided in combination in a single embodiment. Conversely, various features of the disclosure, which are, for brevity, described in the context of a single embodiment, may also be provided separately or in any suitable sub-combination or as suitable in any other described embodiment of the disclosure. Certain features described in the context of various embodiments are not to be considered essential features of those embodiments, unless the embodiment is inoperative without those elements.
[0032] Whenever terms “plurality” and “a plurality” are used it is meant to include, for example, “multiple” or “two or more”. The terms “plurality” or “a plurality” may be used throughout the specification to describe two or more components, devices, elements, units, parameters, or the like. The term set when used herein may include one or more items. Unless explicitly stated, the method embodiments described herein are not constrained to a particular order or sequence. Additionally, some of the described method embodiments or elements thereof can occur or be performed simultaneously, at the same point in time, or concurrently.
[0033] Throughout, this disclosure mentions “disclosed embodiments”, “disclosed systems” and “disclosed methods”, which refer to examples of inventive ideas, concepts, and / or manifestations described herein. The fact that some disclosed embodiments are described as exhibiting a feature or characteristic does not mean that other disclosed embodiments necessarily share that feature or characteristic.
[0034] This disclosure employs open-ended permissive language, indicating for example, that some embodiments “may” employ, involve, or include specific features. The use of the term “may” and other open-ended terminology is intended to indicate that although not every embodiment may employ the specific disclosed feature, at least one embodiment employs the specific disclosed feature.
[0035] The terms “user” and “operator” are used interchangeably herein to refer to any individual person or group of persons using or operating a method or system according to a disclosed embodiment, such as, for example, an end user of an organizational network.
[0036] FIG. 1 illustrates a secure remote access system 100 that enables secure connectivity between an external network 160 and an organization (internal) network 180 through a remote access server (RAS) 210. The secure remote access system 100 maintains physical separation between external network 160 and organization network 180 via an air gap 170. A user computing device 120 generates a user device report 125 that includes keyboard and mouse data. User computing device 120 may connect to external network 160 via at least one data communication channel or network, such as the public Internet.
[0037] External network 160 includes a perimeter network group 162, also referred to as a demilitarized zone (DMZ) network group 162. The remote access server 210 contains a unidirectional data transfer module (UDTM) 250 that spans across the air gap 170. RAS 210 includes an external-RAS switch 220 and an extemal-RAS admin panel 224 on the external network side, and further includes an internal -RAS switch 230 and an internal -RAS admin panel 234 on the internal network side. UDTM 250 includes a gap controller 260 on the external side and a jump station 270 on the internal side. Gap controller 260 is communicatively coupled with external-RAS switch 220 and extemal-RAS admin panel 224. Jump station 270 is communicatively coupled with internal-RAS switch 230 and internal-RAS admin panel 234. User device report 125 is received by DMZ network group elements 162 which connects external-RAS switch 220. Gap controller 260 receives data, such as keyboard and mouse (KM) data of user device report 125, from external-RAS switch 220. Internal-RAS switch 230 connects to an internal local area network (LAN) 182 of organization (internal) network 180. Internal network 180 further includes internal network servers 184, and an organization (org) terminal 190. Org terminal 190 connects to internal LAN 182 and generates video data 195 that flows back through a secure remote connection via UDTM 250 and RAS 210 to provide visual output to user computing device 120.
[0038] The remote access system 100 operates by transferring user input data (i.e., user device report 125) unidirectionally from external network 160 through gap controller 260 to jump station 270, then to org terminal 190 via internal-RAS switch 230 and internal LAN 182. Terminal output data (i.e., video data 195) from org terminal 190 is transferred unidirectionally in a reverse direction through jump station 270 to gap controller 260 and received by user device 120 via external-RAS switch 220 and DMZ network group 162. System 100 thus provides secure remote access functionality between user device 120 and org terminal 190 while maintaining a physical air gap 170 separation between the networks.
[0039] FIG. 2 illustrates a detailed block diagram of portions of the secure remote access system of FIG. 1, showing the network architecture and cloud-based components, according to aspects of the present disclosure. System 100 includes a user space 110, a cloud environment 140, and an external network 160.
[0040] User space 110 contains a user computing device 120 that generates user device reports 125 and is operated by an end user. User space 110 is protected by a firewall 116 and includes additional security components such as a certificate 112 and multi-factor authorization 114. User device 120 may be embodied by any type of electronic device with computing and network communication capabilities, including but not limited to: a smartphone; a laptop computer; a mobile computer; a netbook computer; a tablet computer; a wearable computer; or any combination of the above. According to an embodiment, user device 120 is embodied by a “thin client” computer having minimal local resources and configured to utilize resources located externally. For example, user device 120 may be a thin client computer having limited memory, no hard disk, and with reduced interfaces to support peripherals or external devices. In some cases, user device 120 may be implemented as a proprietary laptop-like workstation referred to as a “zero-trust” device, which may serve as an alternative to standard laptops and may integrate seamlessly into the secure remote access system 100 as a dedicated remote client. Such a zero-trust device may provide secure remote connectivity to internal resources without exposing a traditional operating system environment.
[0041] A certificate 112 may be stored within user space 110 to provide user-specific settings and parameters. Certificate 112 may contain a symmetric encryption key and other organizational configuration data. In some cases, certificate 112 may be generated when a new user account is created and may be securely transferred to the user via USB drive transfer or other secure distribution mechanisms.
[0042] A multi-factor authorization 114 may be integrated within user space 110 to provide enhanced security during user authentication processes. Multi -factor authorization 114 may include various authentication components that verify user identity through multiple verification methods. In some cases, multi-factor authorization 114 may operate in conjunction with credential verification to ensure that access is granted to authorized users.
[0043] A first firewall 116 may be included within the user space 110 to control network traffic flow and provide security filtering. Firewall 116 may regulate communications between user device 120 and components of external network 160 while maintaining security controls. User device report 125 may be selectively transmitted through firewall 116 to routers and / or other elements of DMZ network group 162 upon meeting firewall security criteria.
[0044] External network 160 provides selective remote access between the user space 110 and the organization network 180. External network 160 may include various network infrastructure components and may be protected by a second firewall 166 that controls traffic flow into and out of the external network 160. External network 160 includes an external -RAS admin panel 224 of RAS 210 to provide user management and system administration capabilities and for managing external network side operations of UDTM 250. In some cases, administrators may use the external-RAS admin panel 224 to add or remove users, manage permissions, record sessions, and monitor the status of system components. For example, when a new user is created, external-RAS admin panel 224 may provide an encryption key of the user, where the keys for all users may be stored on RAS 210. External-RAS admin panel 224 may be hosted in various locations including cloud environments, an organizational internet networks, or on server hardware (such as a microchip of RAS 210) depending on organizational deployment requirements. Internal -RAS admin panel 234 of RAS 210 may provide system administration and manage internal network side operations of UDTM 250.
[0045] Cloud environment 140 may include multiple specialized server components that facilitate secure communication and connection establishment. Such components may include a reverse proxy for handling TCP communication protocols, and a cloud management server for overseeing cloud operations. Cloud environment 140 may further include: a signaling server 144 for coordinating UDP communication and connection establishment, a load balancing server 145 for managing traffic distribution, TURN / STUN servers 146 for providing fallback connectivity, and an authentication server 148 for validating user credentials. The cloud infrastructure coordinates various aspects of the connection, including initial authentication, NAT traversal, connection establishment, and protocol handling. This design allows for scalable and reliable service delivery while maintaining high security standards for remote access to organizational resources. Cloud 140 may be implemented using distributed computing resources to provide scalable and reliable service delivery.
[0046] A reverse proxy may receive communications from the user space 110 and provide a stable proxy -based solution for TCP traffic routing. The reverse proxy may serve as an intermediary that forwards requests from user device 120 to appropriate destination services while maintaining connection stability. The reverse proxy may handle TCP traffic such as keyboard reports or general messages that are transmitted to system components.
[0047] Signaling server 144 may handle NAT traversal coordination and establish rules for connection establishment between users and system components. In some cases, signaling server 144 may perform hole punching techniques to enable direct peer-to-peer connectivity through network address translation devices. Signaling server 144 may connect to system components after boot processes are completed and may coordinate the establishment of communication channels.
[0048] TURN (Traversal Using Relays around NAT) and STUN (Session Traversal Utilities for NAT) servers 146 may be deployed within cloud 140 to provide fallback connectivity when direct connection establishment fails. TURN / STUN servers 146 may provide relay services when peer- to-peer connectivity is blocked by restrictive NAT configurations or firewall policies. In some cases, TURN / STUN servers 146 may relay data traffic when direct hole punching performed by the signaling server 144 is unsuccessful. TURN / STUN servers 146 may handle UDP traffic routing including mouse reports and video data transmission.
[0049] Authentication server 148 may validate user credentials such as username and password combinations during initial authentication processes. In some cases, authentication server 148 may be dedicated to verifying initial user credentials and may coordinate with other system components to determine user access permissions. Authentication server 148 may work in conjunction with the multi-factor authorization 114 to provide comprehensive user verification. The cloud environment 140 infrastructure may coordinate communication protocols by splitting traffic into UDP and TCP channels handled by the four different server services. In some cases, UDP communication may be routed through signaling server 144 and TURN / STUN servers 146, while TCP communication may be handled by a reverse proxy. Authentication server 148 may provide credential verification services that support both communication protocol types.
[0050] Referring back to FIG. 1, remote access server 210 facilitates secure communications between external network 160 and organization network 180 while maintaining physical separation. Remote access server 210 may serve as a bridge component that enables controlled data transfer between network segments without compromising security isolation. Remote access server 210 may include various architectural components that support scalable deployment configurations. In some cases, remote access server 210 may be provided in form factors that support a plurality of users concurrently, such as between 4 to 128 concurrent users, and may be delivered in two different server chassis sizes to accommodate varying organizational requirements. Remote access server 210 may include a plurality of carrier boards that provide connectivity infrastructure for multiple user connections.
[0051] In one example, each carrier board of remote access server 210 includes connectors for 32 unidirectional data transfer modules (UDTMs), providing a total capacity of up to 128 connections across all four carrier boards. Groups of four UDTMs may connect to RAS switches 220, 230 in a hierarchical configuration within each carrier board. In some cases, each group of four UDTMs may be routed to another switch on the carrier board until each carrier board exposes two registered jack (RJ) connectors, with one connector designated for gap controller 260 side connections and one connector designated for jump station 270 side connections. In another example, remote access server 210 includes a single carrier board configured to support a plurality of unidirectional data transfer modules (UDTMs) 250, such as approximately 200 UDTMs.
[0052] Remote access server 210 may include various components to support secure operations. In some cases, remote access server 210 includes a power supply to provide electrical power to system components. Remote access server 210 may also include a cooling mechanism such as fans to maintain appropriate operating temperatures for electronic components. Additionally, remote access server 210 may include one or more baseboard management controllers (BMCs) for managing server functions of RAS 210, such as activating and deactivating RAS 210, or controlling the cooling fans. The BMC may be realized as a microchip on a carrier board of RAS 210. In some cases, RAS 210 may include two BMCs for external and internal management functions of RAS 210. For example, one BMC may be integrated with extemal-RAS admin panel 224 and may manage external network operations, and another BMC may be integrated with internal-RAS admin panel 234 and may manage internal network operations. For example, external-RAS admin panel 224 and internal-RAS admin panel 234 may be realized as software modules on respective BMC microchips.
[0053] An external-RAS switch 220 may be positioned on the external network side of remote access server 210 to handle external network communications. External-RAS switch 220 may be realized electronically, such as a solid-state switch, and is configured to connect a plurality of gap controllers 260 together with external network 160 (e.g., via an RJ connector of a carrier board of RAS 210). External-RAS switch 220 may receive data from external network 160 and route communications to appropriate system components, such as to a selected gap controller 260. External-RAS switch 220 may communicate with gap controller 260 using an Ethernet channel. In one example, eight Ethernet cables may emerge from each carrier board and may be split into another two four-port switch configuration that routes connections either externally or internally.
[0054] An internal-RAS switch 230 may be positioned on the organization network side of remote access server 210 to manage internal network communications. Internal-RAS switch 230 may be realized electronically, such as a solid-state switch, and is configured to connect a plurality of jump stations 270 together with internal network 180 (e.g., via an RJ connector of a carrier board of RAS 210). Internal-RAS switch 230 may facilitate data transfer between remote access server 210 and organization network resources. Internal-RAS switch 230 may coordinate with internal network infrastructure to provide connectivity to organization terminals 190 and network services. Internal-RAS switch 230 may communicate with jump station 270 using an Ethernet channel.
[0055] RAS 210 may store symmetric encryption keys that are used for securing communications between system components and user devices 120. In some cases, the user keys may be distributed to system components when communication sessions are established with users. External-RAS admin panel 224 may manage the distribution of the keys to unidirectional data transfer modules 250 when communication with specific users is initiated. In some examples, external-RAS admin panel 224 communicates with gap controller 260 using a controller area network with flexible data-rate (CAN-FD) channel.
[0056] Internal-RAS admin panel 234 may configure whether IP addresses of jump station 270 are assigned statically or via Dynamic Host Configuration Protocol (DHCP) protocols. In some examples, internal-RAS admin panel 234 communicates with jump station 270 using a CAN-FD channel. DMZ network elements 162 may coordinate with external-RAS switch 220 to provide network path management and traffic routing capabilities. DMZ network elements 162 may operate in conjunction with firewall components to control data flow between network segments while maintaining security policies.
[0057] The remote access server 210 architecture may support different user roles or types with varying permissions and access capabilities. In some examples, users may be categorized into regular users, smart users, and technicians. Regular users may have predefined permissions to specific internal network resources and may be granted access to predetermined organization terminals or services. Smart users may be provided with enhanced capabilities that allow selection of which internal network resources to connect to and may be able to configure session parameters during connection establishment. Technician users may be provided with limited network credentials and may have connections that are preconfigured with specific machine addresses and login credentials, thereby preventing broader network access while allowing targeted system maintenance or support functions.
[0058] The hierarchical switch configuration within remote access server 210 may enable scalable connectivity management where multiple user connections can be efficiently routed and managed. In some cases, the carrier board architecture may allow for modular expansion or replacement of connectivity components while maintaining system operation for other users.
[0059] FIG. 3 illustrates a block diagram of a user computing device 410 with secure connectivity components, according to aspects of the present disclosure. User computing device 410 may be provided with a secure connection to an organization terminal of an organization network by a secure remote system, such as system 100 shown in FIG. 1 and 2. In some examples, user computing device 120 (FIG. 1 and 2) of remote access system 100 includes at least some of the components of user computing device 410 (FIG. 3).
[0060] User computing device 410 is housed within a secure housing 411. Housing 411 may provide physical protection and containment for various electronic components and security features. Housing 411 may provide a secure enclosure that protects the internal components from environmental factors and may be designed to prevent unauthorized access to the internal components.
[0061] User computing device 410 may include various input and output components to facilitate user interaction. Input peripherals 412 may include keyboards, mice, touchpads, or other input devices that allow users to provide commands and data input. Output peripherals 413 may include displays, speakers, or other output devices that provide visual or audio feedback to users during remote access sessions. These peripherals may be integrated within housing 411 to provide a complete user interface system. A flash drive 414 may be included within user computing device 410 to provide portable data storage capabilities. Flash drive 414 may store user credentials, certificates, configuration data, or other information required for secure authentication and system operation. In some cases, flash drive 414 may contain encryption keys or other security parameters that are used during remote access sessions.
[0062] User computing device 410 may include a biometric authentication device 415 to provide enhanced user verification capabilities. Biometric authentication device 415 may include fingerprint scanners, iris scanners, facial recognition systems, or other biometric verification technologies. Biometric authentication device 415 may operate in conjunction with other authentication mechanisms to provide multi-factor authentication for secure access to organizational resources.
[0063] A zero memory computer 416 may be integrated within user computing device 410 to provide computing capabilities while minimizing data retention risks. Zero memory computer 416 may be configured to operate without persistent local storage, thereby reducing the risk of sensitive data being stored on the user device. In some cases, zero memory computer 416 may load operating systems and applications from remote sources or temporary storage that is cleared after each session.
[0064] User computing device 410 may include encryption modules to provide data security during transmission. A primary encryption module 417 may be configured to perform initial encryption of user data before transmission. Primary encryption module 417 may implement various encryption algorithms and may coordinate with system components to establish secure communication channels. A secondary encryption module 418 may provide additional encryption layers or backup encryption capabilities. Secondary encryption module 418 may work in conjunction with primary encryption module 417 to implement multi-layered encryption schemes that enhance data security.
[0065] A VPN router 419 may be integrated within user computing device 410 to provide virtual private network connectivity. VPN router 419 may establish encrypted tunnels for secure communication with organizational networks. VPN router 419 may be coupled with a transceiver 420 that handles wireless or wired communication with external networks. Transceiver 420 may support various communication protocols and may coordinate with network infrastructure to establish secure connections.
[0066] User computing device 410 may include security features to prevent unauthorized access or tampering. An anti -tampering arrangement 421 may be implemented to detect and respond to attempts to physically compromise the device. Anti -tampering arrangement 421 may include sensors and other detection mechanisms that can identify unauthorized access attempts and may trigger security responses such as data deletion or system shutdown.
[0067] A controller board 422 may be included within user computing device 410 to coordinate various system functions and component interactions. Controller board 422 may manage communication between different components, control system operations, and coordinate security functions. Controller board 422 may include processing capabilities and may execute firmware or software that controls device behavior.
[0068] User computing device 410 may communicate with organizational resources through a communications medium 430. Communications medium 430 may include various network infrastructure components such as internet connections, wireless networks, or other communication pathways. Communications medium 430 may provide the network connectivity required for remote access sessions while supporting the security protocols implemented by a remote access system.
[0069] FIG. 4 illustrates a block diagram of an anti -tampering arrangement 321 for preventing illegitimate tampering and unauthorized access of a computing device, according to aspects of the present disclosure, while FIG. 5 illustrates the deployment of the anti -tampering arrangement 321 on the user computing device 420 of FIG. 3, showing the physical arrangement and integration of security components within the device structure. Anti -tampering arrangement 321 may be configured to detect an attempt to break into, physically access, sabotage, or otherwise tamper with a computing device in an unauthorized manner, such as to prevent access to internal components of the computing device, where the term term “tampering” is used herein broadly to refer to any such attempt. As shown in FIG. 4, Anti -tampering arrangement 321 includes management components 302 and tampering prevention components 304, which includes: an intrusion detector 310, a sensors layer 315, a polymer protective lining 370, and an exterior casing 380. FIG. 5 demonstrates how these components may be integrated within user computing device 410 to provide comprehensive anti-tampering protection.
[0070] Management components 302 includes a processor 306 and a memory 308. Processor 306 is configured to manage and monitor tampering prevention components 304. Memory 308 stores a digital certificate. Processor 306 may be communicatively coupled with one or more client devices 390. Client devices 390 may be an entity that employs services provided by management components 302, such as zero memory computer 416 or primary encryption module 417 and secondary encryption module 418 of user computing device 410. Intrusion detector 310 includes one or more transmitting controllers 312 and one or more receiving controllers 314, which are communicatively coupled by a plurality of communication traces 316. Intrusion detector 310 may be deployed on a printed circuit board (PCB), such as a motherboard or a separate circuit board. For example, intrusion detector 310 may be deployed on controller board 422 of a designated high security region 425 of user computing device 410, as shown in FIG. 5. Transmitting controllers 312 and receiving controllers 314 may be coupled to a PCB of user computing device 410 and communication traces 316 may be densely arranged in an intersecting criss-cross pattern and encompassing a perimeter of the PCB in multiple layers. Communication traces 316 may be configured to convey electrical signals from transmitting controllers 312 and receiving controllers 314, such as signals representing an encrypted digital certificate. If an illegitimate attempt is made to physically infiltrate the outer wall of the PCB, such as by an attempted penetration by drilling into the PCB wall, communication traces 316 may become detached and cease delivering signals such that receiving controllers 314 will fail to receive the requisite certificate. The encryption of the certificate may be sufficiently strong to prevent attempts to bypass intrusion detector 310, such as by sampling the signal information at a previous point in time and conveying the sampled signal when communication traces 316 are disconnected. Intrusion detector 310 may include a plurality of layers, with multiple transmitting controllers 312 and receiving controllers 314 in each layer. As shown in FIG. 5, intrusion detector 310 may be deployed on controller board 422, where the communication traces 316 may be severed if unauthorized drilling or cutting occurs, providing detection capabilities through the disruption of these traces during physical breach attempts.
[0071] Sensors layer 315 may include one or more heat sensors 320, one or more vibration sensors 330, one or more light sensors 340, one or more internal cell sensors 350, and one or more device access sensors 360. Sensors layer 315 may be located on an outer layer of a PCB of user computing device 410, between intrusion detector 310 and polymer protective lining 370. In some cases, antitampering arrangement 321 may include a plurality of each type of sensor of sensors layer 315, such as a plurality of heat sensors 320, vibration sensors 330, light sensors 340, internal cell sensors 350, and device access sensors 360.
[0072] Heat sensor 320 may be configured to detect changes in temperature that may be indicative of an illegitimate attempt to tamper with or infiltrate user computing device 410, such as increased temperature associated with tampering operations such as welding or drilling. Heat sensor 320 may be embodied by suitable temperature detection sensors, including but not limited to: thermocouples, thermistors, resistance temperature detectors, and semiconductor-based integrated sensors. Heat sensor 320 may be configured to differentiate between irregular temperature variations associated with tampering attempts, such as rapid temperature increases, and normal variations in temperature resulting from non-tampering processes, such as relatively gradual temperature changes due to environmental factors or standard heating of device components during regular operation. As shown in FIG. 5, at least one heat sensor 320 may be provided on user computing device 410 to monitor temperature variations that may indicate tampering operations such as drilling or welding.
[0073] Vibration sensor 330 may be configured to detect vibrations that may be indicative of an illegitimate attempt to tamper with or infiltrate user computing device 410, such as vibrations associated with tampering operations such as cutting, piercing, or drilling. Vibration sensor 330 may be embodied by suitable vibration detection sensors, including but not limited to: an accelerometer, a strain gauge, a velocity sensor, a pressure sensor, a laser displacement sensor, and a vibration meter. Vibration sensor 330 may be configured to differentiate between irregular vibrations associated with tampering attempts, such as vibrations characterized by rapid changes in frequency and / or intensity, and normal vibrations resulting from non-tampering processes, such as due to environmental factors or regular device operation. Analysis of vibration patterns and establishment of adaptive thresholds may be employed to differentiate between normal vibrations and irregular vibrations indicative of a tampering attempt. As shown in FIG. 5, at least one vibration sensor 330 may be provided on user computing device 410 to detect mechanical disturbances associated with cutting, piercing, or other physical breach attempts.
[0074] Light sensor 340 may be configured to detect lighting variations that may be indicative of an illegitimate attempt to tamper with or infiltrate user computing device 410. Light sensor 340 may detect changes in light patterns or characteristics in or around user computing device 410, such as the presence or absence of shadow areas or variations in lighting signatures, which may be associated with tampering operations. Light sensor 340 may be embodied by suitable light detection sensors, including but not limited to: photoconductors, photovoltaic devices, phototransistors, and photodiodes. Light sensor 340 may be configured to differentiate between irregular lighting variations associated with tampering attempts, such as changes in the amount of light reflected by housing 411 upon its opening, and normal lighting variations resulting from nontampering processes, such as due to environmental factors or regular device operation. In one example, light sensor 340 includes a light emission element configured to flash or otherwise emit light according to a set pattern, and a light detection element configured to detect the flashing pattern. When housing 411 is opened, the light detection element may detect a change in the flashing pattern of the light emission element due to a changing reflection from housing 411 as well as ambient lighting, signifying a possible unauthorized accessing of user computing device
[0075] 410. As shown in FIG. 5, at least one light sensor 340 may be provided on user computing device 410 to monitor changes in lighting conditions that may occur during unauthorized opening or tampering of the device housing.
[0076] Internal cell sensor 350 may be configured to detect a tampering of a designated high security region 425 of user computing device 410 containing at least one highly sensitive component. For example, the high security region 425 may include one or more of: controller board 422, zero memory computer 416, primary encryption module 417, and secondary encryption module 418. Internal cell sensor 350 may be configured to detect an infiltration or unauthorized opening of such a designated high security region 425 of user computing device 410. For example, internal cell sensor 350 may be embodied by a pressure sensor, disposed on a portion of user computing device 410 containing the high security region 425 such as a bottom portion of a laptop storing the PCB and primary electronics, and configured to detect an opening of the device portion containing the high security region 425.
[0077] Device access sensor 360 may be configured to detect an unauthorized opening of housing
[0078] 411, such as prior to a user authentication. Device access sensor 360 may be embodied by suitable mechanical or magnetic-based sensors, such as a pressure detection sensor. Device access sensor 360 may be located on an inner portion of a PCB of user computing device 410, such as embedded with the motherboard and primary electronics of user computing device 410. As shown in FIG. 5, at least one device access sensor 360 may be provided on user computing device 410 to detect unauthorized opening of the device housing before proper user authentication.
[0079] Polymer protective lining 370 may be disposed between a PCB of user computing device 410 where sensors layer 315 is mounted and casing 380 of user computing device 410, to inhibit tampering and provide an additional barrier to entry. Polymer protective lining 370 may include conductive material operative to change resistance or other electrical properties upon contact, for detecting a tampering of user computing device 410, such as an unauthorized opening of housing 411. Polymer protective lining 370 may be composed of any suitable material, including but not limited to a polymer material. As shown in FIG. 5, polymer protective lining 370 may be positioned beneath the casing 380 and may provide an additional physical barrier that includes conductive materials configured to detect tampering attempts through changes in electrical properties. Casing 380 may be configured to mechanically enclose the device components. Casing 380 may be embodied by an aluminum case or chassis, and may be at least partially integrated with housing 411. Casing 380 may provide structural protection for the internal components and may work in conjunction with polymer protective lining 370 to provide multiple layers of physical security. As shown in FIG. 5, casing 380 may form the outermost protective layer of the user computing device 410 and may house multiple layers of anti -tampering components, providing structural integrity and serving as the first barrier against unauthorized physical access attempts.
[0080] Processor 306 of management components 302 may issue a notification or alert to client devices 390 responsive to a tampering detection from at least one of tampering prevention components 304. For example, processor 306 may issue an alert upon a positive detection of a tampering attempt. Alternatively or additionally, processor 306 may respond to a status query from client devices 390 as to whether a tampering attempt was detected, such as over a recent time period. An alert or notification may be sent to client devices 390 using an application program interface (API).
[0081] Processor 306 may be configured to monitor each of tampering prevention components 304 continuously or at predetermined time intervals, such as examining communication traces 316 of intrusion detector 310 at set time intervals to verify signal transmission is maintained between transmitting controllers 312 and receiving controllers 314. When a potential tampering is detected, such as if a detection characteristic of intrusion detector 310, heat sensor 320, vibration sensor 330, light sensor 340, internal cell sensor 350, and / or device access sensor 360 meets a predefined condition, processor 306 may issue an alert and / or activate one or more anti-tampering countermeasures, such as deleting the digital certificate from memory 308 to prevent access of user computing device 410.
[0082] The integration of anti -tampering arrangement 321 within a user computing device may provide comprehensive physical security protection for internal components and sensitive data. The multi-layered security approach combines various detection mechanisms and protective barriers to create a robust defense against unauthorized access attempts. When tampering is detected by any component of the sensors layer 315 or the intrusion detector 310, the antitampering arrangement 321 may trigger security responses such as data deletion, system shutdown, or alert notifications, such as to prevent compromise of sensitive information stored within a high security region 125 of user computing device 410.
[0083] It will be appreciated that the embodiments described above are cited by way of example, and that the present invention is not limited to what has been particularly shown and described hereinabove. Rather, the scope of the present invention includes both combinations and sub-combinations of the various features described hereinabove, as well as variations and modifications thereof which would occur to persons skilled in the art upon reading the foregoing description and which are not disclosed in the prior art.
Claims
CLAIMS1. An anti-tampering arrangement for a computing device, comprising: an intrusion detector, configured to detect an infiltration of a printed circuit board of the computing device; a sensors layer comprising at least one sensor selected from the group consisting of: a heat sensor, configured to detect temperature changes indicative of tampering operations; a vibration sensor, configured to detect vibrations associated with tampering operations; a light sensor, configured to detect lighting variations indicative of tampering attempts; an internal cell sensor, configured to detect tampering of a designated high security region of the computing device containing at least one highly sensitive component; and a device access sensor, configured to detect unauthorized opening of a housing of the computing device; and a processor configured to monitor the intrusion detector and the sensors layer, and to trigger a security response upon detection of a tampering attempt.
2. The anti -tampering arrangement of claim 1 , further comprising a memory configured to store a digital certificate, wherein the processor is configured to delete the digital certificate from the memory upon detection of a tampering attempt.
3. The anti -tampering arrangement of claim 1, wherein the intrusion detector comprises a plurality of transmitting controllers and a plurality of receiving controllers communicatively coupled by a plurality of communication traces arranged in an intersecting pattern on the printed circuit board, wherein the communication traces are configured to convey electrical signals from the transmitting controllers to the receiving controllers, and wherein the communication traces are configured to be severed upon physical penetration of the printed circuit board.
4. The anti -tampering arrangement of claim 1, further comprising a polymer protective lining disposed between the printed circuit board and an exterior casing of the computing device,wherein the polymer protective lining comprises conductive material configured to change electrical properties upon contact to detect tampering attempts.
5. The anti-tampering arrangement of claim 1, wherein the light sensor comprises a light emission element configured to emit light according to a predetermined pattern and a light detection element configured to detect changes in the predetermined pattern indicative of unauthorized access to the computing device.
6. The anti -tampering arrangement of claim 1, wherein the heat sensor is selected from the group consisting of thermocouples; thermistors; resistance temperature detectors; and semiconductor-based integrated sensors.
7. The anti -tampering arrangement of claim 1, wherein the vibration sensor is selected from the group consisting of accelerometers; strain gauges; velocity sensors; pressure sensors; laser displacement sensors; and vibration meters.
8. The anti-tampering arrangement of claim 1, wherein the processor is configured to monitor each component of the sensors layer continuously or at predetermined time intervals, and wherein the processor is configured to issue an alert notification to at least one client device upon detection of a tampering attempt by any component of the sensors layer or the intrusion detector.
9. The anti-tampering arrangement of claim 8, wherein the alert notification is sent to the client device using an application program interface.
10. The anti -tampering arrangement of claim 1, wherein the computing device is configured to provide secure remote access to an organization network through a remote access server, and wherein the alert notification is transmitted to the remote access server to enable monitoring of tampering attempts across multiple computing devices in the secure remote access system.
11. A method for detecting tampering of a computing device, comprising: monitoring an intrusion detector configured to detect infiltration of a printed circuit board of the computing device;monitoring a sensors layer comprising at least one sensor selected from the group consisting of: a heat sensor configured to detect temperature changes indicative of tampering operations; a vibration sensor configured to detect vibrations associated with tampering operations; a light sensor configured to detect lighting variations indicative of tampering attempts; an internal cell sensor configured to detect tampering of a designated high security region of the computing device; and a device access sensor configured to detect unauthorized opening of a housing of the computing device; determining whether a tampering attempt has occurred based on detection signals from the intrusion detector or the sensors layer; and triggering a security response upon detection of the tampering attempt.
12. The method of claim 11, wherein the security response comprises deleting a digital certificate stored in memory.
13. The method of claim 11, wherein monitoring the intrusion detector comprises monitoring electrical signals transmitted through a plurality of communication traces arranged in an intersecting pattern on the printed circuit board, and detecting a disruption in the electrical signals caused by severing of the communication traces during physical penetration of the printed circuit board.
14. The method of claim 11, further comprising monitoring electrical properties of a polymer protective lining disposed between the printed circuit board and an exterior casing of the computing device, wherein the polymer protective lining comprises conductive material configured to change electrical properties upon contact during tampering attempts.
15. The method of claim 11, wherein monitoring the sensors layer comprises monitoring a light sensor that emits light according to a predetermined pattern using a light emission element and detects changes in the predetermined pattern using a light detection element, wherein changes in the predetermined pattern indicate unauthorized access to the computing device.
16. The method of claim 11, wherein monitoring the intrusion detector and the sensors layer is performed continuously or at predetermined time intervals, and further comprising issuing an alert notification to at least one client device upon detection of a tampering attempt.
17. The method of claim 11, wherein the computing device is configured to provide secure remote access to an organization network through a remote access server, and wherein the method further comprises transmitting an alert notification to the remote access server to enable monitoring of tampering attempts across multiple computing devices in the secure remote access system.
18. A computing device, comprising: a housing; a printed circuit board disposed within the housing; an anti-tampering arrangement, comprising: an intrusion detector, configured to detect an infiltration of a printed circuit board of the computing device; a sensors layer comprising at least one sensor selected from the group consisting of: a heat sensor, configured to detect temperature changes indicative of tampering operations; a vibration sensor, configured to detect vibrations associated with tampering operations; a light sensor, configured to detect lighting variations indicative of tampering attempts; an internal cell sensor, configured to detect tampering of a designated high security region of the computing device containing at least one highly sensitive component; and a device access sensor, configured to detect unauthorized opening of a housing of the computing device; and a processor configured to monitor the intrusion detector and the sensors layer, and to trigger a security response upon detection of a tampering attempt.
19. The computing device of claim 18, further comprising a memory configured to store a digital certificate, wherein the processor is configured to delete the digital certificate from the memory upon detection of a tampering attempt.
20. The computing device of claim 18, wherein the intrusion detector comprises a plurality of transmitting controllers and a plurality of receiving controllers communicatively coupled by a plurality of communication traces arranged in an intersecting pattern on the printed circuit board, wherein the communication traces are configured to convey electrical signals fromthe transmitting controllers to the receiving controllers, and wherein the communication traces are configured to be severed upon physical penetration of the printed circuit board21. The computing device of claim 18, further comprising a polymer protective lining disposed between the printed circuit board and an exterior casing of the computing device, wherein the polymer protective lining comprises conductive material configured to change electrical properties upon contact to detect tampering attempts.
22. The computing device of claim 18, wherein the light sensor comprises a light emission element configured to emit light according to a predetermined pattern and a light detection element configured to detect changes in the predetermined pattern indicative of unauthorized access to the computing device.
23. The computing device of claim 18, wherein the heat sensor is selected from the group consisting of thermocouples, thermistors, resistance temperature detectors, and semiconductor-based integrated sensors24. The computing device of claim 18, wherein the vibration sensor is selected from the group consisting of accelerometers, strain gauges, velocity sensors, pressure sensors, laser displacement sensors, and vibration meters.
25. The computing device of claim 18, wherein the processor is configured to monitor each component of the sensors layer continuously or at predetermined time intervals, and wherein the processor is configured to issue an alert notification to at least one client device upon detection of a tampering attempt by any component of the sensors layer or the intrusion detector.
26. The computing device of claim 18, wherein the computing device is configured to provide secure remote access to an organization network through a remote access server, and wherein the processor is configured to transmit an alert notification to the remote access server to enable monitoring of tampering attempts across multiple computing devices in the secure remote access system.
Citation Information
Patent Citations
Detection device for use in protection device for volatile storage device for detecting access to e.g. personal computer by unauthorized person to protect system against unauthorized access, has connection device contacting two parts
DE102010012851A1
Tamper-proof electronic packages formed with stressed glass
US20180098424A1
Tamper-respondent assemblies with trace regions of increased susceptibility to breaking
US20180124915A1
Enclosure with tamper respondent sensor
US20190384942A1