Imaging Device Clock Tampering Detection With Dual Timebases

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic systems face challenges in detecting clock tampering, particularly in imaging devices, where non-authentic components manipulate timers to disable or accelerate functions, compromising system integrity and security.

Innovation Solution

A method involving host and security device clocks in imaging devices to compare time intervals, detecting tampering by measuring differences between host and security device clock intervals, and preventing normal operation if the difference exceeds a threshold.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single host firmware clock is used to monitor system time and deploy functions, then the device complexity is reduced, but the reliability of time measurement deteriorates due to susceptibility to tampering

Engineering Contradiction:
Improveclock system complexityVSAvoidtime measurement reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the time measurement function into two independent clock systems: a host firmware clock and a security device clock. Each clock operates independently and maintains its own time measurements. By segmenting the timekeeping function across separate hardware components, the system achieves both simplicity in individual clock design and high reliability through comparative verification, resolving the contradiction between device complexity and time measurement reliability.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If timer-based mechanisms are used to deploy functions at certain times, then the ease of operation is improved, but the security against tampering deteriorates

Engineering Contradiction:
Improvefunction deployment easeVSAvoidclock tampering vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the host firmware clock and security device clock continuously monitor each other's time measurements. The system compares time intervals from both clocks and uses this feedback to detect discrepancies indicating tampering. This feedback loop maintains ease of operation through automatic timer-based function deployment while simultaneously providing security against clock manipulation by detecting anomalies in real-time.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If the timer is allowed to be adjusted for functionality changes, then the adaptability is improved, but the security against malicious manipulation deteriorates

Engineering Contradiction:
Improvefirmware update flexibilityVSAvoidauthentication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary verification mechanism where the security device clock acts as an independent mediator between the host firmware clock and the authentication process. When firmware updates or functionality changes are attempted, the security device clock's time measurement serves as an intermediary check to verify that the host firmware clock has not been maliciously manipulated. This intermediary layer enables legitimate adaptability while maintaining authentication security by providing an independent verification channel.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250278223A1Methods and systems for detection of clock tampering on an electronic device
Publication Date: 2025.09.04 LEXMARK INTERNATIONAL INC
  • US20250278223A1 patent drawing
  • US20250278223A1 patent drawing
  • US20250278223A1 patent drawing

AI summary

A method of detecting clock tampering in an imaging device, comprising: reading a host start time from a host firmware clock of the imaging device, reading a security start time from a security device clock, and reading a host end time from the host firmware clock, reading a security end time, comparing a host interval time between the host start time and the host end time with a security interval time between the security start time and the security end time, and when a difference between the host interval time and the security interval time exceeds a threshold, determining that the host firmware clock has been tampered with. There is further provided an imaging device that similarly determines if the host firmware clock has been tampered with. Finally, there is provided a security device for an imaging device for determining whether the host firmware clock has been tampered with.