Hardware Fingerprint Tampering Detection via Parameter Change Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hardware fingerprinting systems are vulnerable to tampering attacks, where rogue entities can emulate the hardware fingerprint of a computing environment to deceive protected software into thinking it is running on the original environment, leading to potential unauthorized use of copy-controlled software.

Innovation Solution

A method and apparatus that retrieve and compare parameters from a hardware system during operation with previously stored parameters, detecting a lack of change to identify tampering attempts, and employing device parameters that rarely, sometimes, and always change to differentiate between legitimate and compromised states, allowing for countermeasures to be taken.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware fingerprinting is used to authenticate computing environments, then device identification and software protection are improved, but the system becomes vulnerable to tampering attacks where rogue entities can emulate hardware fingerprints

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidtampering attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system continuously monitors hardware parameters and compares current readings against previously stored values. When a parameter change is detected, the system generates feedback signals to trigger re-authentication or alert security modules, creating a closed-loop security mechanism that actively responds to tampering attempts

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary monitoring layer between the hardware fingerprinting system and the protected software. This intermediary component collects hardware parameters, detects changes, and mediates the authentication process, adding an extra security dimension that prevents direct tampering with hardware fingerprints

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If multiple device parameters are queried to build hardware fingerprints, then identification precision is improved, but the complexity of the detection process increases

Engineering Contradiction:
Improvehardware fingerprint precisionVSAvoiddetection process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments device parameters into different categories (e.g., CPU identifiers, memory addresses, registry values) and monitors them separately. This segmentation allows the system to manage complexity by processing parameter changes in organized groups rather than handling all parameters simultaneously, while maintaining comprehensive monitoring coverage

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If tolerance is implemented to allow small changes in hardware parameters, then system adaptability is improved, but the ability to detect tampering attacks is reduced

Engineering Contradiction:
Improveenvironmental toleranceVSAvoidtampering detection capability
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies different tolerance thresholds to different hardware parameters based on their criticality. Essential authentication parameters have strict tolerance (zero change allowed), while less critical parameters can tolerate minor variations. This local differentiation allows the system to maintain adaptability for legitimate hardware variations while preserving tampering detection capability for critical security parameters

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8087092B2Method and apparatus for detection of tampering attacks
Publication Date: 2011.12.27 DEVICE AUTHORITY LTD
  • US8087092B2 patent drawing
  • US8087092B2 patent drawing
  • US8087092B2 patent drawing

AI summary

A method for detecting an attempted attack on a security system. In one preferred embodiment of the present invention, the method includes the step of retrieving a parameter from a hardware system, wherein the parameter changes during an operation of the hardware system. Then, comparing the retrieved parameter with a previously stored parameter; and, detecting a lack of change between the retrieved parameter and the previously stored parameter. An apparatus and an article of manufacture for detecting an attempted attack on a security system is also disclosed.