Computer Tamper-Proofing via Fastener Sequence Cryptography
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional tamper-proofing methods for computing devices are inadequate in preventing unauthorized physical access and data tampering, as they do not effectively secure the device's structural integrity and data integrity simultaneously.
Innovation Solution
A method and system utilizing a chassis with multiple fasteners and sensors to detect sequence events, generating a cryptographic signature based on these events, and initiating anti-tampering actions if the signature does not match a reference, ensuring secure access and preventing unauthorized tampering.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional tamper-proofing methods are used, then physical access can be detected, but data integrity and structural integrity cannot be secured simultaneously
Solution Approach 1:
The chassis is divided into multiple sections with individual fasteners, each monitored by sensors. This segmentation allows the system to detect specific tampering locations and sequences, providing granular control over security responses while maintaining overall system integrity.
Solution Approach 2:
The system pre-defines correct and incorrect sequences of fastener removal. By establishing these sequences in advance, the system can automatically detect and respond to tampering attempts before data access is achieved, preventing both structural and data integrity violations.
2Reliability
If multiple sensors and fasteners are added to detect tampering sequences, then security against unauthorized access is improved, but device complexity increases
Solution Approach 1:
The fasteners serve dual purposes: mechanically securing the chassis and acting as trigger points for security sensors. This multi-functionality reduces the need for separate sensing mechanisms, thereby limiting the increase in device complexity while enhancing security capabilities.
Solution Approach 2:
The system uses the existing fastener structure and its removal actions to generate security events. The sensors detect the natural mechanical actions of fastener removal without requiring additional active components, allowing the system to leverage existing structural elements for security purposes.
3Reliability
If cryptographic signatures are generated and verified for each sequence, then data integrity is ensured, but processing time and computational resources increase
Solution Approach 1:
Cryptographic signatures and verification criteria are pre-computed and stored during system initialization. This preliminary action allows rapid verification during operation, as the system only needs to compare actual sensor sequences against pre-established correct sequences, significantly reducing real-time processing requirements.
4Reliability
If anti-tampering actions are initiated upon mismatch, then protection against data theft is improved, but ease of operation for authorized users may be reduced
Solution Approach 1:
Different security responses are applied based on the specific tampering detected. The system distingu between correct and incorrect sequences, applying appropriate responses that protect against theft while allowing legitimate access through the correct sequence, thereby maintaining ease of operation for authorized users.
Solution Approach 2:
The system provides feedback through the verification process, comparing actual fastener sequences against predefined correct sequences. This feedback mechanism enables authorized users to understand whether their actions are correct, allowing for correction without triggering anti-tampering responses, thus maintaining operational convenience.
Data Source
AI summary
A technique of proofing against tampering with a computer including a chassis with a plurality of fasteners. The technique includes obtaining by the computer data indicative of a sequence of implication events associated with the fasteners of the plurality of fasteners, generating a pattern corresponding to the sequence of implication events, matching between data corresponding to the generated pattern and a reference data, and initiating one or more anti-tampering actions responsive to a mismatching result. The method can further include generating a cryptographic signature corresponding to the generated pattern, wherein matching between data corresponding to the generated pattern and the reference data includes matching the generated cryptographic signature to a cryptographic reference corresponding to the reference data. Alternatively, or additionally, the generated cryptographic signature can be usable for secure access to information stored on the computer.


