Covert Identifier Network Security for Clone Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems fail to effectively detect cloned client devices that mimic legitimate users, allowing unauthorized access to services, as existing methods rely on easily replicable credentials and lack robust identification mechanisms.
Innovation Solution
Incorporating covert security data into normal messages between client devices and servers, using operational event-based identifiers that change over time, allowing the server to differentiate between authentic and cloned devices by matching stored and received covert identifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional credential-based authentication is used, then ease of operation is improved, but security against cloning is worsened
Solution Approach 1:
The authentication system is segmented into two independent components: traditional credentials (username/password) for authentication and covert operational characteristics for clone detection. This allows the system to maintain ease of operation with standard credentials while adding a separate layer of security that detects cloning without affecting user experience.
Solution Approach 2:
The patent introduces covert operational characteristics as an intermediary element between the client device and server authentication process. These characteristics serve as a hidden mediator that verifies device authenticity without requiring users to change their authentication behavior, thus maintaining ease of operation while improving security.
2Measurement precision
If covert operational characteristics are monitored, then clone detection precision is improved, but device complexity is worsened
Solution Approach 1:
The system automatically collects and monitors covert operational characteristics (power-on time, message timestamps, operational counters) without requiring manual configuration or user intervention. The client device and server self-manage the collection, comparison, and verification of these characteristics, reducing the perceived complexity for users while maintaining high detection precision.
Solution Approach 2:
The patent changes the parameters being monitored from static credentials to dynamic operational characteristics that continuously change over time (timestamps, counters, power-on duration). This dynamic parameter approach improves clone detection precision because cloned devices cannot perfectly replicate time-dependent operational patterns, while the implementation remains relatively simple by leveraging existing system logs and timestamps.
3Reliability
If multiple covert data values are collected and compared, then reliability of clone detection is improved, but loss of information is worsened
Solution Approach 1:
The system performs preliminary collection and storage of covert operational characteristics during normal device operation before clone detection is needed. Timestamps, counters, and operational data are continuously recorded and maintained in both client and server memory, so when detection is required, the comparison can be performed immediately without additional data collection overhead, thus improving reliability while minimizing information loss.
Data Source
Figure 1
Figure 2A~2B
Figure 3
AI summary
In a security system for network communications with client devices, each client device has a communication module for communicating with at least one server over a network, a data storage module for storing one or more covert data values of one or more operational events at the client device, and a covert identifier generating module which creates at least one covert identifier based on the stored covert data values. The covert identifier is provided in one or more network messages to the server, or otherwise sent to the service provider, and may be provided in response to a specific request received over the network, or routinely in one or more messages normally involved in network communications. The server compares covert identifiers received from client devices having the same client identifier in order to detect possible clones.