Tamper Detection Using Independent RTC Power Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Electronic devices, particularly those handling sensitive data like payment terminals, are vulnerable to physical tampering after they are sold or distributed, especially when they are powered off or out of network range.
Innovation Solution
The implementation of a tamper detection system using a Real-Time Clock (RTC) or a cryptographic authenticator within the electronic device. These components are powered independently and can detect unauthorized access by tracking changes in their operational state when the device is reconnected to a network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Use of energy by moving object
If the device is powered off or out of network range, then energy consumption is reduced and portability is improved, but vulnerability to physical tampering increases
Solution Approach 1:
The system divides the security monitoring function into a separate, always-on RTC module that operates independently from the main device processor. This segmentation allows the RTC to continuously monitor for tampering events even when the main device is powered off, resolving the contradiction between energy savings from powering off and security vulnerability during that state.
Solution Approach 2:
The RTC acts as an intermediary component between the physical tampering event and the main device system. It independently detects tampering through its own power source and trigger mechanism, then communicates the tamper state to the main device upon reconnection, bridging the security gap that exists when the main device is offline or powered down.
2Reliability
If continuous monitoring is implemented, then detection capability is improved, but energy consumption increases
Solution Approach 1:
Instead of continuous monitoring by the main device, the system uses periodic check-ins where the RTC independently monitors continuously but only communicates with the main device when triggered by a tamper event or when the device reconnects to the network. This periodic communication pattern maintains detection capability while minimizing energy consumption from constant data transmission.
Solution Approach 2:
The monitoring function is segmented into two parts: continuous local monitoring by the low-power RTC module, and intermittent remote reporting by the main device. This segmentation allows the system to maintain high detection capability through the RTC's continuous local monitoring while keeping overall energy consumption low by only activating full device communication when necessary.
3Reliability
If tamper detection components are added, then security is improved, but device complexity increases
Solution Approach 1:
The RTC module serves multiple functions: it acts as a real-time clock for time-keeping operations, a tamper detection sensor through its independent power monitoring, and a security authentication component. By making the RTC multi-functional, the system improves security without adding dedicated separate components for each function, thereby limiting the increase in device complexity.
Solution Approach 2:
The RTC module is self-sufficient with its own independent power source and tamper detection logic, requiring minimal integration with the main device system. It autonomously monitors for tampering, maintains its own operational state, and only interacts with the main device when necessary to report tamper events or authenticate, reducing the complexity burden on the overall device architecture.
Data Source
AI summary
Systems and techniques for tamper detection of electronic devices are described. The tamper detection is performed using a tamper circuit that includes an authenticator connected to an auxiliary power source of the electronic device via a switch. The switch is configured to open and break the connection between the authenticator and the auxiliary power source when a housing of the electronic device is opened or tampered with. The authenticator may be evaluated, and a value compared against a server-based value to determine a difference in values and thereby detect tampering.


