Electronic Device Suspicious Operation Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electronic devices, such as microcircuit and integrated circuit cards, face challenges in detecting suspicious operations, particularly in pay television systems where 'card sharing' and fault injection attacks divert them from their normal use, making it difficult to differentiate between legitimate and fraudulent activity.

Innovation Solution

Implementing a method within the device to monitor and count activity sessions of short duration, using binary indicators stored in non-volatile memory, and switching to a degraded mode of operation if the number of short sessions exceeds a threshold, thereby impairing performance and delaying startup sequences to deter attackers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the device operates in normal mode allowing frequent activity sessions, then ease of operation is improved, but reliability deteriorates due to susceptibility to card sharing and fault injection attacks

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The device performs preliminary monitoring of activity session durations and accumulates counts of short-duration sessions before triggering any protective action. This preliminary detection phase allows the system to establish a baseline of normal operation and only intervene when suspicious patterns emerge, thus maintaining ease of operation during legitimate use while protecting against attacks

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device prepares countermeasures in advance by establishing threshold values for short session counts and duration. When these thresholds are exceeded, the system automatically switches to degraded mode, preventing further exploitation before significant damage can occur. This preliminary anti-action ensures reliability is maintained without compromising normal operational ease

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If the device switches to degraded mode to prevent fraudulent use, then reliability is improved, but productivity deteriorates due to impaired performance

Engineering Contradiction:
ImprovereliabilityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The device dynamically adjusts its operational mode based on real-time monitoring of activity session patterns. Rather than maintaining a fixed state, the system transitions between normal and degraded modes as needed, optimizing the balance between reliability and productivity. This dynamic approach ensures that productivity is maintained during legitimate use while reliability is enhanced when attacks are detected

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The device changes operational parameters by switching between different modes of operation. In normal mode, full performance is available; in degraded mode, performance is impaired to prevent further exploitation. This parameter change allows the system to maintain high productivity during legitimate use while ensuring reliability when suspicious patterns are detected

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If the device monitors and counts each activity session to detect suspicious operation, then measurement precision is improved, but device complexity increases

Engineering Contradiction:
Improvemeasurement precisionVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The monitoring function is segmented into distinct components: a timer that tracks individual session durations, a counter that accumulates short session counts, and a comparator that evaluates against thresholds. This segmentation allows each component to perform a simple, well-defined function, reducing overall device complexity while maintaining high measurement precision for detecting suspicious operation patterns

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary elements such as a dedicated timer module and counter register that mediate between the activity session events and the decision-making logic. These intermediaries simplify the main control logic by handling the complex timing and counting operations, thereby improving measurement precision without significantly increasing overall device complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If the device prolongs startup sequences to deter attackers, then reliability is improved, but loss of time increases

Engineering Contradiction:
ImprovereliabilityVSAvoidloss of time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The device implements periodic monitoring of activity session patterns rather than continuous intervention. Startup sequences are prolonged only periodically when threshold violations are detected, rather than being continuously extended. This periodic action maintains reliability by deterring attackers while minimizing time loss during normal operations when no attacks are occurring

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8789165B2Method for detecting potentially suspicious operation of an electronic device and corresponding electronic device
Publication Date: 2014.07.22 STMICROELECTRONICS (ROUSSET) SAS
  • US8789165B2 patent drawing
  • US8789165B2 patent drawing
  • US8789165B2 patent drawing

AI summary

A method may be for detecting potentially suspicious operation of an electronic device configured to operate in the course of activity sessions. The method may include within the device, a metering, from an initial instant of the number of activity sessions having a duration below a first threshold, and a comparison of this number with a second threshold.