Electronic Device Suspicious Operation Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Electronic devices, such as microcircuit and integrated circuit cards, face challenges in detecting suspicious operations, particularly in pay television systems where 'card sharing' and fault injection attacks divert them from their normal use, making it difficult to differentiate between legitimate and fraudulent activity.
Innovation Solution
Implementing a method within the device to monitor and count activity sessions of short duration, using binary indicators stored in non-volatile memory, and switching to a degraded mode of operation if the number of short sessions exceeds a threshold, thereby impairing performance and delaying startup sequences to deter attackers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the device operates in normal mode allowing frequent activity sessions, then ease of operation is improved, but reliability deteriorates due to susceptibility to card sharing and fault injection attacks
Solution Approach 1:
The device performs preliminary monitoring of activity session durations and accumulates counts of short-duration sessions before triggering any protective action. This preliminary detection phase allows the system to establish a baseline of normal operation and only intervene when suspicious patterns emerge, thus maintaining ease of operation during legitimate use while protecting against attacks
Solution Approach 2:
The device prepares countermeasures in advance by establishing threshold values for short session counts and duration. When these thresholds are exceeded, the system automatically switches to degraded mode, preventing further exploitation before significant damage can occur. This preliminary anti-action ensures reliability is maintained without compromising normal operational ease
2Reliability
If the device switches to degraded mode to prevent fraudulent use, then reliability is improved, but productivity deteriorates due to impaired performance
Solution Approach 1:
The device dynamically adjusts its operational mode based on real-time monitoring of activity session patterns. Rather than maintaining a fixed state, the system transitions between normal and degraded modes as needed, optimizing the balance between reliability and productivity. This dynamic approach ensures that productivity is maintained during legitimate use while reliability is enhanced when attacks are detected
Solution Approach 2:
The device changes operational parameters by switching between different modes of operation. In normal mode, full performance is available; in degraded mode, performance is impaired to prevent further exploitation. This parameter change allows the system to maintain high productivity during legitimate use while ensuring reliability when suspicious patterns are detected
3Measurement precision
If the device monitors and counts each activity session to detect suspicious operation, then measurement precision is improved, but device complexity increases
Solution Approach 1:
The monitoring function is segmented into distinct components: a timer that tracks individual session durations, a counter that accumulates short session counts, and a comparator that evaluates against thresholds. This segmentation allows each component to perform a simple, well-defined function, reducing overall device complexity while maintaining high measurement precision for detecting suspicious operation patterns
Solution Approach 2:
The patent introduces intermediary elements such as a dedicated timer module and counter register that mediate between the activity session events and the decision-making logic. These intermediaries simplify the main control logic by handling the complex timing and counting operations, thereby improving measurement precision without significantly increasing overall device complexity
4Reliability
If the device prolongs startup sequences to deter attackers, then reliability is improved, but loss of time increases
Solution Approach 1:
The device implements periodic monitoring of activity session patterns rather than continuous intervention. Startup sequences are prolonged only periodically when threshold violations are detected, rather than being continuously extended. This periodic action maintains reliability by deterring attackers while minimizing time loss during normal operations when no attacks are occurring
Data Source
AI summary
A method may be for detecting potentially suspicious operation of an electronic device configured to operate in the course of activity sessions. The method may include within the device, a metering, from an initial instant of the number of activity sessions having a duration below a first threshold, and a comparison of this number with a second threshold.


