Tamper Detection via Secure Storage Update Function
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Ensuring the integrity and security of electronic devices, particularly networked devices like cameras, from tampering during the manufacturing to end-user delivery phase is challenging due to lack of control in the supply chain.
Innovation Solution
A method and system that notify when security-sensitive functionality of an electronic device has been previously enabled by detecting events such as setting root or administrator passwords, and using an updating function to securely update the device's data storage, ensuring that only authorized access can revert the storage content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the manufacturer uses traditional supply chain control methods, then the device can be delivered to the end user, but the device may be tampered with during transit and security sensitive functionality may be enabled without detection
Solution Approach 1:
The patent applies preliminary action by pre-configuring the data storage with original content and establishing the updating function before the device leaves the manufacturer. This allows the security verification mechanism to be in place before any potential tampering occurs, enabling detection of unauthorized changes during supply chain transit without adding complex verification systems at later stages
Solution Approach 2:
The patent implements feedback by creating a verification mechanism where the end user can compare the current data storage content against the expected content derived from the updating function. This feedback loop allows the system to detect whether tampering has occurred and notify the user, resolving the contradiction between maintaining device integrity and avoiding overly complex security systems
2Reliability
If the manufacturer implements comprehensive security monitoring throughout the supply chain, then device tampering can be detected, but the complexity and cost of the system increases significantly
Solution Approach 1:
The patent applies self-service by designing a system where the device itself maintains its own security integrity through the updating function, and the end user performs the verification rather than requiring manufacturer monitoring throughout the supply chain. This reduces the need for complex external security monitoring while maintaining reliable tampering detection
Solution Approach 2:
The patent uses parameter changes by transforming the security verification problem into a mathematical function evaluation. Instead of implementing complex monitoring infrastructure, the system changes the approach to using cryptographic or mathematical functions (the updating function) that can verify integrity through computation, significantly reducing system complexity while maintaining detection capability
3Reliability
If the data storage content is made immutable without privileged access, then unauthorized tampering is prevented, but legitimate security updates and verification become more difficult
Solution Approach 1:
The patent applies segmentation by separating the data storage into two functional aspects: the immutable original content that provides security baseline, and the mutable current content that can be legitimately updated through the controlled updating function. This segmentation allows both protection against unauthorized access and facilitation of legitimate security updates
Data Source
AI summary
Upon detecting an event indicating enabling of security sensitive functionality of an electronic device, a value previously unknown to the electronic device is obtained and the current content of the data storage to a new current content of the data storage is updated according to an updating function based on the current content of the data storage and the value, wherein, without privileged access, the current content of the data storage can only be updated using the updating function. The value is further obtained in a management module and an expected new current content of the data storage is determined in the management module according to the updating function based on known original content of the data storage and the value. Upon determining that the new current content of the data storage differs from the expected new current content of the data storage, a validation module generates a security notification.


