IP Library Granted Patent US 12,468,613
Granted Patent B2
US 12,468,613 · App. 18/165,643 · Granted Nov 11, 2025

Systems and methods for detecting hardware tampering using airflow sensors

Inventors: Harikrishnan Pillai (San Jose, CA); Niels-Peder Mosegard Jensen (Sunnyvale, CA); Jeffrey C. Loo (San Jose, CA); Phong Hoang Ho (Cary, NC)
Assignee: CISCO TECHNOLOGY, INC.
G06F11/3058G06F21/86G06F2221/2151
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,468,613
App. No.
18/165,643
Granted
Nov 11, 2025
Kind
B2
Abstract

In one embodiment, a method includes receiving airflow data from an airflow sensor installed inside of a hardware device and determining an airflow value from the airflow data. The method also includes determining that the airflow value exceeds a predetermined threshold. The method further includes determining a potential tampering event associated with the hardware device.

Claims (73)

1 . A network element, comprising:

one or more processors; and

one or more computer-readable non-transitory storage media coupled to the one or more processors and comprising instructions that, when executed by the one or more processors, cause the network element to perform operations comprising:

receiving airflow data from an airflow sensor installed inside of a hardware device;

determining an airflow value from the airflow data;

determining that the airflow value exceeds a predetermined threshold;

determining a potential tampering event associated with the hardware device;

receiving test airflow data when the hardware device is powered on and when the hardware device is powered off;

analyzing the test airflow data to determine airflow patterns when the hardware device is powered on and when the hardware device is powered off; and

determining the predetermined threshold based on the airflow patterns.

2 . The network element of claim 1 , wherein:

the airflow value is a value above zero; and

the predetermined threshold is a value of zero.

3 . The network element of claim 1 , wherein determining the potential tampering event of the hardware device occurs while the hardware device is powered off, the operations further comprising:

storing information associated with the potential tampering event on a storage unit; and

communicating a notification to a cloud controller when the hardware device is powered on, the notification comprising the information associated with the potential tampering event.

4 . The network element of claim 1 , wherein:

the airflow sensor installed inside of the hardware device is enclosed by a shield; and

the shield is integrated into a cover of the hardware device.

5 . The network element of claim 1 , wherein:

the airflow sensor communicates the airflow data to a microcontroller unit (MCU) located inside of the hardware device;

the MCU communicates information associated with the potential tampering event to a storage unit located inside of the hardware device; and

the MCU, the airflow sensor, and the storage unit are powered by a battery located inside of the hardware device.

6 . The network element of claim 1 , the operations further comprising:

determining, at a current time of day, a current timestamp associated with the hardware device, wherein the current timestamp is stored in a storage unit coupled to the airflow sensor;

comparing the current timestamp to the current time of day; and

determining, in response to comparing the current timestamp to the current time of day, whether a potential battery tampering event associated with a battery coupled to the airflow sensor has occurred.

7 . A method, comprising:

receiving airflow data from an airflow sensor installed inside of a hardware device;

determining an airflow value from the airflow data;

determining that the airflow value exceeds a predetermined threshold;

determining a potential tampering event associated with the hardware device;

receiving test airflow data when the hardware device is powered on and when the hardware device is powered off;

analyzing the test airflow data to determine airflow patterns when the hardware device is powered on and when the hardware device is powered off; and

determining the predetermined threshold based on the airflow patterns.

8 . The method of claim 7 , wherein:

the airflow value is a value above zero; and

the predetermined threshold is a value of zero.

9 . The method of claim 7 , wherein determining the potential tampering event of the hardware device occurs while the hardware device is powered off, further comprising:

storing information associated with the potential tampering event on a storage unit; and

communicating a notification to a cloud controller when the hardware device is powered on, the notification comprising the information associated with the potential tampering event.

10 . The method of claim 7 , wherein:

the airflow sensor installed inside of the hardware device is enclosed by a shield; and

the shield is integrated into a cover of the hardware device.

11 . The method of claim 7 , wherein:

the airflow sensor communicates the airflow data to a microcontroller unit (MCU) located inside of the hardware device;

the MCU communicates information associated with the potential tampering event to a storage unit located inside of the hardware device; and

the MCU, the airflow sensor, and the storage unit are powered by a battery located inside of the hardware device.

12 . The method of claim 7 , further comprising:

determining, at a current time of day, a current timestamp associated with the hardware device, wherein the current timestamp is stored in a storage unit coupled to the airflow sensor;

comparing the current timestamp to the current time of day; and

determining, in response to comparing the current timestamp to the current time of day, whether a potential battery tampering event associated with a battery coupled to the airflow sensor has occurred.

13 . One or more computer-readable non-transitory storage media embodying instructions that, when executed by a processor, cause the processor to perform operations comprising:

receiving airflow data from an airflow sensor installed inside of a hardware device;

determining an airflow value from the airflow data;

determining that the airflow value exceeds a predetermined threshold;

determining a potential tampering event associated with the hardware device;

receiving test airflow data when the hardware device is powered on and when the hardware device is powered off;

analyzing the test airflow data to determine airflow patterns when the hardware device is powered on and when the hardware device is powered off; and

determining the predetermined threshold based on the airflow patterns.

14 . The one or more computer-readable non-transitory storage media of claim 13 , wherein:

the airflow value is a value above zero; and

the predetermined threshold is a value of zero.

15 . The one or more computer-readable non-transitory storage media of claim 13 , wherein determining the potential tampering event of the hardware device occurs while the hardware device is powered off, the operations further comprising:

storing information associated with the potential tampering event on a storage unit; and

communicating a notification to a cloud controller when the hardware device is powered on, the notification comprising the information associated with the potential tampering event.

16 . The one or more computer-readable non-transitory storage media of claim 13 , wherein:

the airflow sensor installed inside of the hardware device is enclosed by a shield; and

the shield is integrated into a cover of the hardware device.

17 . The one or more computer-readable non-transitory storage media of claim 13 , wherein:

the airflow sensor communicates the airflow data to a microcontroller unit (MCU) located inside of the hardware device;

the MCU communicates information associated with the potential tampering event to a storage unit located inside of the hardware device; and

the MCU, the airflow sensor, and the storage unit are powered by a battery located inside of the hardware device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2023
From: PILLAI, HARIKRISHNAN; JENSEN, NIELS-PEDER MOSEGARD; LOO, JEFFREY C.; HO, PHONG HOANG
To: CISCO TECHNOLOGY, INC.
Reel/Frame 062616/0842 →
Continuity (1)
Related Publication 20240264920A1 · Aug 8, 2024
References Cited (28)
US 4197530A · Fletcher · 1980 [cited by examiner]
US 5208587A · Cornman · 1993 [cited by examiner]
US 9740888B1 · Aga et al. · 2017 [cited by applicant]
US 10127409B1 · Wade · 2018 [cited by examiner]
US 20070143462A1 · Venkatachalam · 2007 [cited by examiner]
US 20080252450A1 · Wandel · 2008 [cited by examiner]
US 20090230305A1 · Burke et al. · 2009 [cited by applicant]
US 20090295581A1 · Paananen · 2009 [cited by examiner]
US 20100031368A1 · Park · 2010 [cited by examiner]
US 20110018713A1 · Yehoshua · 2011 [cited by examiner]
US 20130249691A1 · Bertoni · 2013 [cited by examiner]
US 20150269805A1 · Korala · 2015 [cited by examiner]
US 20170032149A1 · Sengupta et al. · 2017 [cited by applicant]
US 20180023989A1 · Droin · 2018 [cited by examiner]
US 20180234266A1 · Rudolph et al. · 2018 [cited by applicant]
US 20180253569A1 · Swierk et al. · 2018 [cited by applicant]
US 20190095657A1 · Norton · 2019 [cited by examiner]
US 20190158789A1 · Snyder et al. · 2019 [cited by applicant]
US 20190362080A1 · Achillopoulos · 2019 [cited by examiner]
US 20200258358A1 · Beck · 2020 [cited by examiner]
US 20210225159A1 · Grobelny · 2021 [cited by examiner]
US 20220114870A1 · Beck · 2022 [cited by examiner]
US 20220192011A1 · Zhang · 2022 [cited by examiner]
US 20230104923A1 · Lu · 2023 [cited by examiner]
US 20230419797A1 · Hollins · 2023 [cited by examiner]
US 20240111912A1 · Wesneski · 2024 [cited by examiner]
Paul Staat, Johannes Tobisch, Christian Zenger, and Christof Paar “Anti-Tamper Radio: System-Level Tamper Detection for Computing Systems”; Max Planck Institute for Security and Privacy; PHYSEC GmbH, Bochum, Germany arX… [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2024/013488, mailed May 14, 2024, 13 Pages. [cited by applicant]