Personal information skimmer detection device
Inventors
Tenaglia, Scott D. • Tanen, Joseph S.
Assignees
Interested in licensing this patent?
MTEC can help explore whether this patent might be available for licensing for your application.
Abstract
A detection device for identification and isolation of unauthorized skimmer/shimmer devices takes the form of a portable electronics package adapted for deployment under or near a point-of-sale (POS) station that may be targeted by such skimmer. The detection device is intended for placement near or adjacent an electronic exchange of personal, financial, and/or sensitive information from a payment card, mobile device, or similar magnetic, optical, or radio frequency medium. Unscrupulous interception devices periodically transmit gathered information for reception. The detection device monitors transmissions for those having characteristics indicative of the unscrupulously gathered information, and renders an output signal alerting to the presence and location of an illicit capture device.
Core Innovation
The invention relates to a portable device for detecting and countering an illicit capture device that covertly gathers personal data by receiving RF signals from the illicit capture device. The RF signals include data indicative of personal information of a user, and the device demodulates the received RF signals into packets of data. The device interprets a transmission profile indicative of an intended use of the received packets and compares the data to characteristics of known malicious devices having a capability for covert gathering of personal data.
Based on the comparison and the transmission profile, the device computes a likelihood that the RF signals emanate from a deployed, illicit capture device. The received packets include captured, sensitive data from the illicit capture device, and the determination further depends on proximity to a point of exchange of the sensitive data. The logic locates fields in the received data packets indicative of circuit components employed for transmitting the received RF signals, and extracts an identity of a manufacturer of the circuit components.
The manufacturer identity is extracted from Bluetooth packet fields, including a BD_ADDR field and references to the Organizationally Unique Identifier (OUI) and device ID fields in the Bluetooth packet. The device compares the extracted identity to manufacturers of components associated with illicit capture devices, computes whether the transmission profile is associated with transmissions from illicit capture devices, and communicates the computed likelihood for manual inspection and intervention. The result is rendered for subsequent inspection and intervention.
Claims Coverage
The independent claims cover a device and corresponding methods or program code that detect and counter illicit capture devices by analyzing demodulated RF packets and computing a likelihood that the packets originate from an unauthorized illicit device, using multiple inventive features including transmission-profile interpretation and manufacturer identity extraction from Bluetooth packet fields, as well as rendering the result for subsequent inspection and intervention.
Detecting and countering an illicit capture device by RF packet demodulation and transmission-profile comparison
An antenna receives RF signals from the illicit capture device, including data indicative of personal information of a user; a modulation circuit demodulates the received RF signals into packets of data; logic receives and interprets a transmission profile indicative of an intended use of the received packets, compares the data to characteristics of known malicious devices having a capability for covert gathering of personal data, and based on the comparison computes whether the transmission profile is associated with transmissions from illicit capture devices and a likelihood that the RF signals emanated from a deployed, illicit capture device.
Extracting transmitter manufacturer identity from Bluetooth packet fields
Locating, in the received data packets, fields indicative of circuit components employed for transmitting the received RF signals; extracting, from the located fields, an identity of a manufacturer of the circuit components based on a BD_ADDR field in a Bluetooth packet, referencing the Organizationally Unique Identifier (OUI) and device ID fields in the Bluetooth packet; and comparing the identity to manufacturers of components associated with illicit capture devices.
Computing likelihood tied to proximity to the point of exchange and enabling inspection and intervention
Comparing the transmission profile to transmissions from illicit capture devices and computing a likelihood whether the received packets include captured, sensitive data from the illicit capture device and based on proximity to a point of exchange of the sensitive data; and an interface for communicating the computed likelihood of an unauthorized device presence for manual inspection and intervention, with the result rendered for subsequent inspection and intervention.
Receiver-side method for detecting spurious communications from an unauthorized device
Gathering, at a receiver disposed in a monitored environment, RF signals suspected of transporting sensitive data; analyzing the RF signals for received packets including an indication that the RF signals emanated from an illicit device; deriving one or more characteristics indicative of RF signals that emanated from a suspect device including periodicity, signal strength, a transmission profile indicative of an intended use of the received packets, and transmitter manufacturer; locating fields indicative of circuit components in the received data packets; extracting a manufacturer identity based on a BD_ADDR field in a Bluetooth packet referencing OUI and device ID fields; comparing the identity to manufacturers of components associated with illicit capture devices; and computing whether the transmission profile is associated with transmissions from illicit capture devices including a likelihood whether the received packets include captured, sensitive data and based on proximity to a point of exchange, and rendering the result for subsequent inspection and intervention.
Computer program implementing spurious communications detection with likelihood computation and inspection rendering
A computer program embodied on a non-transitory medium that, when executed by a processor, performs steps for implementing a method including gathering RF signals suspected of transporting sensitive data at a receiver disposed in a monitored environment; analyzing received packets for an indication that RF signals emanated from an illicit device; deriving characteristics including periodicity, signal strength, a transmission profile indicative of intended use, and transmitter manufacturer; locating fields indicative of circuit components and extracting a manufacturer identity based on Bluetooth BD_ADDR referencing OUI and device ID; comparing the identity to manufacturers of components associated with illicit capture devices; computing whether the transmission profile is associated with transmissions from illicit capture devices including a likelihood whether the received packets include captured, sensitive data based on proximity to a point of exchange; and rendering the result for subsequent inspection and intervention.
Across the independent claims, the core inventive approach is to demodulate RF transmissions into packets, interpret a transmission profile and derive suspect-device characteristics including periodicity, signal strength, and manufacturer identity, extract transmitter manufacturer identity from Bluetooth packet BD_ADDR with OUI and device ID references, compare against characteristics and manufacturer identities associated with illicit capture devices, compute a likelihood tied to proximity to a point of exchange, and render or communicate the result for subsequent inspection and intervention.
Stated Advantages
Provides computed likelihood of unauthorized device presence for manual inspection and intervention.
Enables subsequent inspection and intervention based on rendered results.
Documented Applications
Detecting and countering an illicit capture device adjacent to a point of exchange of sensitive data, including deployments related to point-of-sale (POS) and ATM/card readers in a monitored environment, where captured sensitive data is transmitted via illicit RF communications.
Interested in licensing this patent?