Cache Latency Signature Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for authenticating computer terminals to restrict access to protected content are vulnerable to manipulation and tampering, as they rely on cookies and software versions that can be easily altered or deleted, making it difficult to securely identify and authorize terminals.

Innovation Solution

A method using a hierarchical cache latency signature vector is generated by measuring elapsed times for different buffer sizes across multiple levels of cache memory, creating a unique identification that is resistant to user manipulation, allowing for secure terminal authentication and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cookies or software versions are used for terminal identification, then terminal authentication can be implemented, but the identification can be easily tampered with or manipulated by users

Engineering Contradiction:
Improveterminal identification reliabilityVSAvoiduser manipulation ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system uses the terminal's own hardware resources (CPU, cache memory, hierarchical memory structure) to generate identification data automatically. The terminal itself performs the authentication function by measuring its own cache access times and generating latency signatures, making the identification process self-service and resistant to external manipulation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces software-based identification mechanisms (cookies, software version strings) with hardware-based physiological measurements (cache access latencies, memory access times). This substitution of mechanical/physical measurement for software-based identification makes the system tamper-resistant because hardware characteristics cannot be easily altered without physically changing the terminal.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If sophisticated fraud techniques are used to impersonate terminals, then unauthorized access can be obtained, but secure authentication becomes more difficult to implement

Engineering Contradiction:
Improveaccess control securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system measures multiple parameters of the terminal's hardware behavior including cache access latencies at different hierarchy levels, memory access times, and CPU performance characteristics. By changing from single-parameter to multi-parameter measurement and combining these into a composite latency signature, the system creates a more robust authentication mechanism that is difficult to replicate.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent adds temporal dimension to terminal identification by measuring time-based characteristics (cache access latencies, memory access times) rather than relying on static identifiers. This temporal dimension creates a dynamic fingerprint that reflects the actual operational characteristics of the terminal's hardware, making impersonation more difficult.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If terminal identification is made tamper-resistant, then secure authentication is achieved, but the identification method becomes more complex

Engineering Contradiction:
Improveidentification tamper-resistanceVSAvoididentification method complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses universal hardware components (CPU, cache memory, hierarchical memory structure) that exist in all modern terminals to generate identification data. By leveraging components that are already present and functioning in every terminal, the system achieves tamper-resistant identification without adding specialized hardware, thus limiting the increase in complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent creates a digital copy or fingerprint of the terminal's hardware behavior characteristics (cache latency signatures, memory access patterns). This copied behavioral signature serves as the identification mechanism, allowing the system to authenticate terminals based on replicated operational patterns rather than requiring complex cryptographic hardware.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10003603B1Computer security based on hierarchical cache latency signature authentication
Publication Date: 2018.06.19 CA TECH INC
  • US10003603B1 patent drawing
  • US10003603B1 patent drawing
  • US10003603B1 patent drawing

AI summary

A processor is coupled to a hierarchical memory structure which includes a plurality of levels of cache memories that hierarchically cache data that is read by the processor from a main memory. The processor is integrated within a computer terminal. The processor performs operations that include generating a hierarchical cache latency signature vector by repeating for each of a plurality of buffer sizes, the following: 1) allocating in the main memory a buffer having the buffer size; 2) measuring elapsed time for the processor to read data from buffer addresses that include upper and lower boundaries of the buffer; and 3) storing the elapsed time and the buffer size as an associated set in the hierarchical cache latency signature vector. The operations further include communicating through a network interface circuit a computer identification message containing computer terminal identification information generated based on the hierarchical cache latency signature vector.