Software Integrity Monitoring via Physical Side-Effect Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software integrity verification is challenging, especially in limited runtime environments with little or no access to hardware interfaces, and existing methods struggle to detect unauthorized code injection or manipulation.
Innovation Solution
A monitoring device that continuously monitors software integrity by analyzing physical side-effects and internal activities, using sensors to detect power consumption, electromagnetic emissions, and data transmission patterns, and applies a data model to determine compliance with expected control flows.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software is continuously monitored using physical side-effects and sensors, then software integrity detection capability is improved, but device complexity and cost increase
Solution Approach 1:
The patent introduces a monitoring device as an intermediary component that sits between the software execution environment and the external world. This monitoring device includes sensors that detect physical side-effects and a processor that analyzes this data to determine software integrity, effectively mediating the verification process without requiring direct access to the software code or execution environment.
Solution Approach 2:
The patent replaces traditional software-based integrity verification methods with a physics-based approach using sensors to detect physical side-effects (electromagnetic emissions, power consumption, acoustic signals) generated during software execution. This substitution of mechanical/physical measurement for software analysis provides a new dimension of verification that is independent of the software being monitored.
2Measurement precision
If multiple sensors and monitoring mechanisms are deployed, then measurement precision of software behavior is improved, but device complexity increases
Solution Approach 1:
The monitoring device is segmented into distinct functional components: multiple sensors (electromagnetic, power consumption, acoustic) that each detect specific physical side-effects, a processor that receives and analyzes data from all sensors, and a software integrity determination module. This segmentation allows each component to be optimized independently while working together to provide comprehensive verification.
Solution Approach 2:
The monitoring device is designed with multi-functionality, using a single integrated system to detect multiple types of physical side-effects (electromagnetic emissions, power consumption patterns, acoustic signals) through different sensors. This universal approach allows one monitoring device to verify software integrity through multiple independent measurement channels, improving precision without requiring separate dedicated systems for each measurement type.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Effectively detects unauthorized code changes and ensures software operates as expected, reducing the risk of compromise by logging events, blocking execution, or reinstalling non-compromised software when deviations are detected.
Implementation Method 1
the sensor unit is to send information comprising a measurement of the physical side-effect measured to a processor
Implementation Method 2
receive first information on at least one physical side-effect of a computing apparatus as a result of an instruction of a monitored software being executed
Data Source
AI summary
A monitoring device for verifying the integrity of a software of a memory device is disclosed. The monitoring device comprises a processor and a memory, the memory containing instructions executable by the processor, such that the processor is to; receive first information on at least one physical side-effect of a computer apparatus as a result of an instruction of a monitored software being executed by the computing apparatus. The processor is also to receive second information on the monitored software being executed, and based on the first information and the second information, the processor is to determine if the monitored software is compromised.


