Portable Device Sensor Data Filtering to Thwart Keystroke Inference

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Portable electronic devices are vulnerable to attacks that infer keystrokes or touchscreen inputs from device orientation and motion data, as malicious software can analyze hardware sensor output to deduce sensitive information, such as passwords, without explicit user consent.

Innovation Solution

Implementing measures to control and restrict the receipt of hardware sensor output by processes, including preventing receipt, providing fake sensor data, and limiting sampling rates, to prevent unauthorized analysis of touch events and maintain user privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If hardware sensor output is made freely accessible to processes, then device functionality and sensor utilization are improved, but security vulnerability to side-channel attacks increases

Engineering Contradiction:
Improvesensor accessibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary component (sensor driver or operating system mechanism) that sits between the hardware sensors and processes. This intermediary controls and filters sensor data access, determining which processes can receive sensor output and under what conditions. The intermediary prevents direct access to raw sensor data that could be used for side-channel attacks, while still allowing legitimate applications to function properly through controlled data release.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameters of sensor data release by implementing controls over sampling rates, data formatting, and timing. By modifying these parameters, the system can provide sensor data to authorized processes at controlled rates that prevent the high-frequency analysis needed for keystroke inference attacks, while maintaining sufficient data flow for legitimate sensor-based applications.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If sensor data sampling rate is increased, then measurement precision and responsiveness are improved, but attack effectiveness increases

Engineering Contradiction:
Improvesensor measurement precisionVSAvoidattack effectiveness
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic control over the sampling rate parameter of hardware sensors. The system can adjust the sampling frequency based on the requesting process's authorization level and the current security context. Authorized processes receive data at appropriate sampling rates for their functionality, while unauthorized processes receive either no data or data at deliberately reduced sampling rates that render side-channel attacks ineffective.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies partial action by providing sensor data to processes at selectively reduced sampling rates. Instead of completely blocking all sensor access, the system provides partial data access with intentionally limited temporal resolution. This partial provision of sensor output maintains functionality for legitimate applications while removing the high-frequency information needed for precise keystroke timing analysis in attacks.

Inventive Principle:
Principle #16Partial or excessive action

3Object-affected harmful factors

If fake sensor data is provided to processes, then security against side-channel attacks is improved, but loss of legitimate sensor functionality occurs

Engineering Contradiction:
Improveattack preventionVSAvoidsensor functionality
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent applies local quality by providing different data quality levels to different processes based on their authorization. Authorized processes receive authentic, high-quality sensor data with full functionality. Unauthorized or suspicious processes receive either no data, degraded data, or fake data. This localized differentiation ensures that security measures (fake data) are applied only where needed, while legitimate sensor functionality remains intact for authorized applications.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2629220B1Thwarting attacks that involve analyzing hardware sensor output
Publication Date: 2016.01.20 BLACKBERRY LTD
  • EP2629220B1 patent drawingFigure 1~3
  • EP2629220B1 patent drawingFigure 4-1
  • EP2629220B1 patent drawingFigure 4-2

AI summary

A hardware sensor (60,62,64,66) and a hardware user-input component (22,32,42,102,202,302,306) are integrated in a portable electronic device (10,100,200,300). The hardware sensor is operable to produce hardware sensor output indicative of orientation or motion or both of the device within its environment. The hardware user-input component has multiple elements (24,34,44,104,204,304) operable to accept user input through touch. A user-input driver (26,36,46) and the device's operating system (18) are jointly operable to detect touch events involving the elements. A software application (20) is executable by the device's processor (14) as a process. A sensor driver (61,63,65,67) or the operating system or both are configured to control what hardware sensor output, if any, is receivable by the process. This control may thwart an attack based on analysis of the hardware sensor output, the attack designed to deduce what user input has been made via multiple elements of the hardware user-input component.