Chassis Intrusion Detection Using Battery-Backed Volatile Memory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud-based server systems face vulnerabilities due to physical access to server components, allowing unauthorized access and tampering, which can compromise data network security.

Innovation Solution

Incorporating an intrusion switch and battery-backed volatile memory in computing devices to detect physical intrusions, modify keys stored in memory, and provide secure indications of intrusion, while requiring authentication before granting access to the data network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If physical access to server components is allowed for maintenance and access purposes, then ease of operation is improved, but security vulnerability increases allowing unauthorized access and tampering

Engineering Contradiction:
Improveaccess to server componentsVSAvoiddata network security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by generating cryptographic keys and creating secure snapshots of hardware components before any physical access occurs. The intrusion detection mechanism is pre-configured to detect tampering, and authentication credentials are established in advance, ensuring that even if physical access is granted, any unauthorized modifications will be detected and reported to the remote operator.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If intrusion detection mechanisms are implemented to detect physical tampering, then security is improved, but device complexity increases due to additional sensors and monitoring systems

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidmonitoring system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex mechanical intrusion detection systems with cryptographic and software-based mechanisms. Instead of using physical sensors, switches, and monitoring hardware to detect tampering, the system uses cryptographic key validation, snapshot comparison, and authentication protocols to detect and report intrusions, significantly reducing device complexity while maintaining or improving detection reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If volatile memory is used to store cryptographic keys for security, then security is improved through power interruption capability, but data loss occurs when power is interrupted or memory is cleared

Engineering Contradiction:
Improvecryptographic key securityVSAvoidcryptographic key data
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system creates and maintains multiple copies of cryptographic keys across different storage locations including volatile memory, non-volatile memory, and remote servers. When the volatile memory is cleared due to power interruption or intrusion detection, the system can retrieve key copies from alternative locations, ensuring key availability while maintaining security through the volatile memory's power-interruption capability.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary key distribution and snapshot creation before operations begin. Cryptographic keys are pre-loaded into volatile memory and corresponding snapshots are stored in secure locations. This preliminary preparation ensures that if the volatile memory is cleared, the system can restore keys from pre-stored snapshots rather than losing them entirely.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12321505B2Systems and methods for chassis intrusion detection
Publication Date: 2025.06.03 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12321505B2 patent drawing
  • US12321505B2 patent drawing
  • US12321505B2 patent drawing

AI summary

A computing device includes an intrusion switch and a battery-backed volatile memory. The battery-backed volatile memory is configured to indicate a physical intrusion when the physical intrusion is detected by the intrusion switch. The triggering of the intrusion switch interrupts a power supply to the battery-backed volatile memory. A method of detecting hardware intrusion in a computing device is also described.