IP Library Granted Patent US 12,406,049
Granted Patent B2
US 12,406,049 · App. 18/261,818 · Granted Sep 2, 2025

Device and method for autheniticating hardware and/or embedded software

Inventor: Ricardo Amaral Remer (Rio de Janeiro, BR)
Assignee: Rogério Atem De Carvalho
G06F21/44
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,406,049
App. No.
18/261,818
Granted
Sep 2, 2025
Kind
B2
Abstract

A device and a method for verifying the authenticity of hardware and its embedded software. The method of the invention includes the steps of: a) obtaining an identified record of each unique hardware and software device; b) subsequently interrogating this same unique hardware and software device to compare said identified record obtained in the interrogation with that previously recorded; and c) identify corruption, tampering and/or intrusion/eavesdropping of the hardware/embedded software set when comparing the records does not result in a match. The device is structured and configured to carry out the method.

Claims (50)

1. A hardware authentication method and its embedded software, the method comprising the following steps:

a) obtaining an identified record of each unique hardware and software device, the record selected from the group consisting of

at least one hash with a correspondence between an input value of at least one signal to a hardware and embedded software set and an output value of said at least one signal and/or a response time of the at least one output signal,

an electromagnetic signature, and

combinations thereof;

b)subsequently interrogating this same unique hardware and software device, for the comparison of said identified record obtained in the interrogation with that previously registered;

c) identifying corruption, tampering and/or intrusion/eavesdropping of the hardware/embedded software set when comparing records does not result in a match;

d) conducting a parameterized verification of electromagnetic signature (MVAE) comprising the steps of

i) defining a limit of similarity,

ii) determining when equality use by proximity by at least one of setting distance to amplitude and setting distance to frequency,

iii) obtaining the reading of the electromagnetic signature performed on a supplier's website and storing a reading of the electromagnetic signature performed on a supplier's website in a vector,

iv) obtaining the reading of the electromagnetic signature performed on a user's website and storing the reading of the electromagnetic signature performed on a user's website in a vector,

V) for each point of the electromagnetic signature obtained on the supplier's website:

determining when strict equality is being used by checking if each point of the electromagnetic signature obtained on the supplier's website is equal to a point of a same position in a vector of the electromagnetic signature obtained on the user's website, and if different, incrementing a counter of dissimilar peaks; and

determining when equality by tolerance window is being used by checking if the point of the same position in the vector of the electromagnetic signature obtained at the user's site is within the tolerance window and if different, incrementing the counter of dissimilar peaks;

vi) calculating the percentage of dissimilar peaks by dividing the counter of dissimilar peaks by the size of the vector created to store the electromagnetic signature obtained on the supplier's website; and

vii) if the percentage of different peaks equals zero the signatures are equal, if less than the limit of similarity then the signatures are similar, if greater the signatures are dissimilar.

2. The method according to claim 1 , further comprising the following steps:

e) obtaining an identified record of each unique hardware and software device by specific recording to each unique device, of at least one of:

the at least one hash;

the correspondence between the input value of the at least one signals to the hardware and embedded software set and the output value of said at least one signal(s) and/or the response time of the at least one output signal, and

the electromagnetic signature;

f) subsequently interrogating this same unique hardware and software device for the assessment of at least one of:

an identity of the at least one hash with the another one of the at least one hash that was previously stored,

a result of a correspondence test between the input value of the at least one signal to the hardware and embedded software set and the output value of said at least one signal and/or the response time of the at least one output signal with the respective previously stored values, and

comparing a similarity degree of the electromagnetic signature with the previously stored electromagnetic signature, and

g) identifying corruption, tampering and/or invasion/eavesdropping of the hardware/embedded software set when at least one of:

the at least one hash is different from another one of the at least one hash;

the signal test points out non-correspondence between the at least one signals and/or the response time of the at least one signal, and

the electromagnetic signature is out of the similarity range previously established.

3. The method according to claim 1 , wherein the identified record of each unique hardware and software device is stored remotely, with the step of comparing the respective record with the record arising from the interrogation being performed remotely.

4. The method according to claim 1 for use in verifying the hardware and software integrity of equipment or devices for measuring and documenting quantities of environmental interest.

5. The method according to claim 1 for use in verifying the hardware and software integrity of environmental conservation projects by certifying entities.

6. The method according to claim 1 for use in verifying the hardware and software integrity of electronic voting machines.

7. The method according to claim 1 for use in verifying the hardware and software payloads integrity of Space Artifacts.

8. A device for hardware and embedded software authentication comprising physical input and output interfaces for connection to hardware containing embedded software, to be authenticated and a microprocessor configured for:

a) sending one or more signals to the hardware containing embedded software to be authenticated to interrogate it for a uniquely identified record of each hardware and embedded software;

b) receiving back said signals;

c)checking the conformity between the unique record of the hardware and embedded software obtained from the interrogation and the unique record previously identified and stored;

d) sending a signal to a physical and/or digital media to report compliance or non-compliance; and

e) conducting a parameterized verification of electromagnetic signature (MVAE) comprising the steps of

i) defining a limit of similarity,

ii) determining when equality use by proximity by at least one of setting distance to amplitude and setting distance to frequency,

iii) obtaining the reading of the electromagnetic signature performed on a supplier's website and storing a reading of the electromagnetic signature performed on a supplier's website in a vector,

iv) obtaining the reading of the electromagnetic signature performed on a user's website and storing the reading of the electromagnetic signature performed on a user's website in a vector,

v) for each point of the electromagnetic signature obtained on the supplier's website:

determining when strict equality is being used by checking if each point of the electromagnetic signature obtained on the supplier's website is equal to a point of a same position in a vector of the electromagnetic signature obtained on the user's website, and if different, incrementing a counter of dissimilar peaks; and

determining when equality by tolerance window is being used by checking if the point of the same position in the vector of the electromagnetic signature obtained at the user's site is within the tolerance window and if different, incrementing the counter of dissimilar peaks;

vi) calculating the percentage of dissimilar peaks by dividing the counter of dissimilar peaks by the size of the vector created to store the electromagnetic signature obtained on the supplier's website; and

vii) if the percentage of different peaks equals zero the signatures are equal, if less than the limit of similarity then the signatures are similar, if greater the signatures are dissimilar.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2025
From: REMER, RICARDO AMARAL; CARVALHO, ROGÉRIO ATEM DE
To: CARVALHO, ROGÉRIO ATEM DE
Reel/Frame 071936/0464 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 8, 2025
From: CARVALHO, ROGÉRIO ATEM DE
To: THINGS GO ONLINE - CONSULTORIA, DESENVOLVIMENTO E TECNOLOGIA EM METRICAS E TOKENS DE IMPACTOS AMBIENTAIS E SOCIAIS LTDA
Reel/Frame 069783/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2023
From: REMER, RICARDO AMARAL
To: CARVALHO, ROGÉRIO ATEM DE
Reel/Frame 064292/0646 →
Priority Claims (1)
BR 102021001278-1 · Jan 22, 2021 · national
Continuity (1)
Related Publication 20240296217A1 · Sep 5, 2024
References Cited (45)
US 8108931B1 · Witten · 2012 [cited by examiner]
US 8667265B1 · Hamlet · 2014 [cited by examiner]
US 10225255B1 · Jampani · 2019 [cited by examiner]
US 10749686B2 · Quach · 2020 [cited by applicant]
US 11201641B2 · Shake · 2021 [cited by examiner]
US 11436340B2 · Freeman · 2022 [cited by examiner]
US 20080005798A1 · Ross · 2008 [cited by applicant]
US 20090025073A1 · Beverly · 2009 [cited by examiner]
US 20110267190A1 · Payson · 2011 [cited by examiner]
US 20120124385A1 · Klasen · 2012 [cited by examiner]
US 20130047209A1 · Satoh · 2013 [cited by applicant]
US 20140082720A1 · Markel · 2014 [cited by examiner]
US 20140223554A1 · Roden, III · 2014 [cited by examiner]
US 20140223580A1 · Neivanov · 2014 [cited by examiner]
US 20140277761A1 · Matsuoka · 2014 [cited by examiner]
US 20140289835A1 · Varshavsky · 2014 [cited by applicant]
US 20140365755A1 · Liu · 2014 [cited by applicant]
US 20150227762A1 · Lee · 2015 [cited by examiner]
US 20160098561A1 · Keller · 2016 [cited by examiner]
US 20160112083A1 · Keller, III · 2016 [cited by examiner]
US 20160124041A1 · Pathak · 2016 [cited by examiner]
US 20160239662A1 · Endoh · 2016 [cited by examiner]
US 20160274162A1 · Freeman · 2016 [cited by examiner]
US 20160330030A1 · Yi et al. · 2016 [cited by applicant]
US 20170323121A1 · Liu · 2017 [cited by examiner]
US 20180025148A1 · Jain · 2018 [cited by examiner]
US 20180336756A1 · MacKinnon · 2018 [cited by examiner]
US 20190228156A1 · Thumati · 2019 [cited by examiner]
US 20200186523A1 · Kursun · 2020 [cited by applicant]
US 20200295938A1 · Matovsky · 2020 [cited by applicant]
US 20200382295A1 · Howells · 2020 [cited by examiner]
US 20210064745A1 · Bouguerra · 2021 [cited by examiner]
US 20210091829A1 · Shake · 2021 [cited by examiner]
US 20210182436A1 · Bennison · 2021 [cited by examiner]
US 20220300612A1 · Yamamoto · 2022 [cited by examiner]
US 20240086534A1 · Yamanaka · 2024 [cited by examiner]
US 20240296217A1 · Remer · 2024 [cited by examiner]
BR 102019021409A2 · 2021 [cited by applicant]
CN 1447269A · 2003 [cited by applicant]
CN 101394276A · 2009 [cited by applicant]
CN 103605919A · 2014 [cited by applicant]
CN 104393997A · 2015 [cited by applicant]
CN 106462900A · 2017 [cited by applicant]
CN 108352989A · 2018 [cited by applicant]
WIPO, International Search Report (in a corresponding application), Mar. 23, 2022. [cited by applicant]