Covert Identifier Network Security for Clone Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems fail to effectively detect cloned client devices that mimic legitimate users, allowing unauthorized access to services, as existing methods rely on easily replicable credentials and lack robust identification mechanisms.

Innovation Solution

Incorporating covert security data into normal messages between client devices and servers, using operational event-based identifiers that change over time, allowing the server to differentiate between authentic and cloned devices by matching stored and received covert identifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional credential-based authentication is used, then ease of operation is improved, but security against cloning is worsened

Engineering Contradiction:
Improveauthentication processVSAvoidclone detection capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into two independent components: traditional credentials (username/password) for authentication and covert operational characteristics for clone detection. This allows the system to maintain ease of operation with standard credentials while adding a separate layer of security that detects cloning without affecting user experience.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces covert operational characteristics as an intermediary element between the client device and server authentication process. These characteristics serve as a hidden mediator that verifies device authenticity without requiring users to change their authentication behavior, thus maintaining ease of operation while improving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If covert operational characteristics are monitored, then clone detection precision is improved, but device complexity is worsened

Engineering Contradiction:
Improveclone detection accuracyVSAvoidsecurity system architecture
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system automatically collects and monitors covert operational characteristics (power-on time, message timestamps, operational counters) without requiring manual configuration or user intervention. The client device and server self-manage the collection, comparison, and verification of these characteristics, reducing the perceived complexity for users while maintaining high detection precision.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the parameters being monitored from static credentials to dynamic operational characteristics that continuously change over time (timestamps, counters, power-on duration). This dynamic parameter approach improves clone detection precision because cloned devices cannot perfectly replicate time-dependent operational patterns, while the implementation remains relatively simple by leveraging existing system logs and timestamps.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple covert data values are collected and compared, then reliability of clone detection is improved, but loss of information is worsened

Engineering Contradiction:
Improveclone detection confidenceVSAvoidcovert data management overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system performs preliminary collection and storage of covert operational characteristics during normal device operation before clone detection is needed. Timestamps, counters, and operational data are continuously recorded and maintained in both client and server memory, so when detection is required, the comparison can be performed immediately without additional data collection overhead, thus improving reliability while minimizing information loss.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP1977333B1Network security system and method
Publication Date: 2016.08.31 VERIMATRIX INC
  • EP1977333B1 patent drawingFigure 1
  • EP1977333B1 patent drawingFigure 2A~2B
  • EP1977333B1 patent drawingFigure 3

AI summary

In a security system for network communications with client devices, each client device has a communication module for communicating with at least one server over a network, a data storage module for storing one or more covert data values of one or more operational events at the client device, and a covert identifier generating module which creates at least one covert identifier based on the stored covert data values. The covert identifier is provided in one or more network messages to the server, or otherwise sent to the service provider, and may be provided in response to a specific request received over the network, or routinely in one or more messages normally involved in network communications. The server compares covert identifiers received from client devices having the same client identifier in order to detect possible clones.