Tamper-evident
   HOME

TheInfoList



OR:

Tamper-evident describes a device or process that makes unauthorized access to the protected object easily detected. Seals, markings, or other techniques may be tamper indicating.


Tampering

Tampering involves the deliberate altering or adulteration of information, a product, a package, or system. Solutions may involve all phases of product production, distribution, logistics, sale, and use. No single solution can be considered as "tamper proof". Often multiple levels of
security" \n\n\nsecurity.txt is a proposed standard for websites' security information that is meant to allow security researchers to easily report security vulnerabilities. The standard prescribes a text file called \"security.txt\" in the well known locat ...
need to be addressed to reduce the risk of tampering. Some considerations might include: *Identify who a potential tamperer might be and what level of knowledge, materials, tools, etc. might they have. *Identify all feasible methods of unauthorized access into a product, package, or system. In addition to the primary means of entry, also consider secondary or "back door" methods. *Control or limit access to products or systems of interest. *Improve the
tamper resistance Tamperproofing, conceptually, is a methodology used to hinder, deter or detect unauthorised access to a device or circumvention of a security system. Since any device or system can be foiled by a person with sufficient knowledge, equipment, and ti ...
by making tampering more difficult, time-consuming, etc. *Add tamper-evident features to help indicate the existence of tampering. *Educate people to watch for evidence of tampering. *Length of time available for tampering. Particularly in transit, anyone intending to tamper with tamper-evident-protected goods, valuables, cash and confidential documents generally only has a window of opportunity of a few minutes before discovery is likely. This makes it both difficult and unlikely that they will have time to open the packaging, examine or remove the items, and restore the packaging to its original untampered condition.


Seals and signatures

Tamper-evident designs have been a feature of
letters Letter, letters, or literature may refer to: Characters typeface * Letter (alphabet), a character representing one or more of the sounds used in speech; any of the symbols of an alphabet. * Letterform, the graphic form of a letter of the alpha ...
since ancient times, often using wax, clay, or metal
seals Seals may refer to: * Pinniped, a diverse group of semi-aquatic marine mammals, many of which are commonly called seals, particularly: ** Earless seal, or "true seal" ** Fur seal * Seal (emblem), a device to impress an emblem, used as a means of a ...
to signify that the letter had not been opened since it was written. *
Ancient Roman In modern historiography, ancient Rome refers to Roman civilisation from the founding of the city of Rome in the 8th century BC to the collapse of the Western Roman Empire in the 5th century AD. It encompasses the Roman Kingdom (753–50 ...
signet ring A seal is a device for making an impression in wax, clay, paper, or some other medium, including an embossment on paper, and is also the impression thus made. The original purpose was to authenticate a document, or to prevent interference with a ...
s, for example, were unique to the person who owned them, and the ring was pressed into the hot wax seal forming a signature which could not be easily duplicated by somebody attempting to re-seal the letter. *
Letterlocking Letterlocking is the act of folding and securing a written message (such as a letter) on papyrus, parchment, or paper, without requiring it to be contained in an envelope or packet. It is a traditional method of document security that utilizes fo ...
, including a type called spiral locking, used intricate folding, slitting, and weaving to create the result that any opening attempt would be evident via rips and tears in addition to the breaking of the wax seals. Similar practices continue today, from examples such as
envelope An envelope is a common packaging item, usually made of thin, flat material. It is designed to contain a flat object, such as a letter or card. Traditional envelopes are made from sheets of paper cut to one of three shapes: a rhombus, a ...
s to carefully designed packaging for payslips. In modern
contract law A contract is a legally enforceable agreement between two or more parties that creates, defines, and governs mutual rights and obligations between them. A contract typically involves the transfer of goods, services, money, or a promise to t ...
, it is common to see each page of a contract individually initialled and numbered, so that any addition or removal of pages can be detected. Meanwhile, most checks have a variety of features to defeat both tampering and duplication (these are often listed on the back of the check). Technicians at the
National Security Agency The National Security Agency (NSA) is a national-level intelligence agency of the United States Department of Defense, under the authority of the Director of National Intelligence (DNI). The NSA is responsible for global monitoring, collecti ...
developed anti-tamper holograph and prism labels that are difficult to duplicate.


Product packaging

Tamper-evident design is perhaps most visible in the process of product
packaging and labeling Packaging is the science, art and technology of enclosing or protecting products for distribution, storage, sale, and use. Packaging also refers to the process of designing, evaluating, and producing packages. Packaging can be described as a ...
, where it can be vital to know that the product has not been altered since it left the manufacturer. Cans of baby food were among the first high-profile cases, where manufacturers were
extorted Extortion is the practice of obtaining benefit through coercion. In most jurisdictions it is likely to constitute a criminal offence; the bulk of this article deals with such cases. Robbery is the simplest and most common form of extortion, al ...
by persons claiming to have added various
poison Poison is a chemical substance that has a detrimental effect to life. The term is used in a wide range of scientific fields and industries, where it is often specifically defined. It may also be applied colloquially or figuratively, with a broa ...
s to baby food and replaced them on supermarket shelves. The amount of stock which needed to be destroyed (because it was impossible to tell if a given item had been tampered with), and the threat of public fear, meant that tamper-evident design principles had the potential to save a lot of money in the future. Jars of food items soon started appearing with a lid with a metal bubble in the center, commonly known as a "safety button", pulled down by vacuum in the top of the container, which—like the lid of a
Mason jar A Mason jar, also known as a canning jar or fruit jar, is a glass jar used in home canning to preserve food. It was named after American tinsmith John Landis Mason, who patented it in 1858. The jar's mouth has a screw thread on its outer perime ...
—popped out if the jar had ever been opened and stayed flat if the jar was in pristine condition. These lids would also pop out if the jar was contaminated by potentially dangerous gas-producing bacteria. Customers were advised to never buy a product with a popped lid. In addition to the visible flat "button", an intact lid makes an audible "pop" when opened. Newer jars of food tend to come with a plastic wrap around the edge of the lid, which is removed when opening, although the springy-cap designs are still in common use. Tamper-evident packaging also extends to protect stores; there are some scale labels for meats and deli products that will tear if removed. The 1982 Chicago Tylenol murders involved over-the-counter medications. Due to FDA regulations, many manufacturers of food and medicine (as well as other products) now use induction sealing and other special means to help provide evidence of tampering. Break-away components which cannot be reattached are useful. Custom
seals Seals may refer to: * Pinniped, a diverse group of semi-aquatic marine mammals, many of which are commonly called seals, particularly: ** Earless seal, or "true seal" ** Fur seal * Seal (emblem), a device to impress an emblem, used as a means of a ...
,
security tape Security tape (or security label) is a type of adhesive tape used to help reduce shipping losses due to pilfering and theft. It helps reduce tampering or product adulteration. Often it is a pressure sensitive tape or label with special tamper ...
s,
label A label (as distinct from signage) is a piece of paper, plastic film, cloth, metal, or other material affixed to a container or product, on which is written or printed information or symbols about the product or item. Information printed ...
s, RFID tags, etc. are sometimes added. The current epidemic of opioid abuse and drug abuse has led to a search for tamper-evident strategies to protect central vascular lines. Drug users who shoot drugs into their veins often acquire infections of the heart valves (endocarditis), liver, bones, lungs, and other organs. Treatment of these infections requires several weeks of intravenous antibiotics. During the treatment period, these patients can use the central intravenous line or peripherally inserted central line (PICC) to inject narcotics or other illicit drugs. Evidence exists that applying a tamper-evident device to the central line can deter illicit use of the line. Security packaging is needed to contain evidence of crimes. Items must be kept in an unaltered state until they are submitted in a legal proceeding. Packaging that tears open raggedly or otherwise cannot readily be resealed is sometimes used to help indicate tampering. Often, multiple layers or redundant indicators are used because no single layer or device is "tamper-proof". Consideration should be given to unique custom indicators (which should be changed regularly because these are subject to counterfeiting). People who open secure packaging can look out for signs of tampering, both at the primary means of entrance and at secondary or "back door" locations on a package.


Credit cards, money, stamps, coupons

In
financial Finance is the study and discipline of money, currency and capital assets. It is related to, but not synonymous with economics, the study of production, distribution, and consumption of money, assets, goods and services (the discipline of f ...
terms, tamper-evident design overlaps a lot with anti-
forgery Forgery is a white-collar crime that generally refers to the false making or material alteration of a legal instrument with the specific intent to defraud anyone (other than themself). Tampering with a certain legal instrument may be forb ...
techniques, as ways to detect monetary tokens which are not what they seem.
Postage stamp A postage stamp is a small piece of paper issued by a post office, postal administration, or other authorized vendors to customers who pay postage (the cost involved in moving, insuring, or registering mail), who then affix the stamp to the f ...
s, for example, may contain a layer of ultraviolet-reflective ink which changes state under pressure. The impact from a
postmark A postmark is a postal marking made on an envelope, parcel, postcard or the like, indicating the place, date and time that the item was delivered into the care of a postal service, or sometimes indicating where and when received or in transit ...
ing machine then leaves a UV-visible mark as well as an ink mark which identifies attempts to reuse stamps. In a similar vein, asset-numbering labels on corporate equipment (PCs and the like) are often designed to leave an imprint of either the serial number, or the word "VOID" if the label is peeled off. However, this can easily be defeated by warming up the label using a blow dryer so it will be more flexible and forgiving to removal (and reapplication). Road tax vignettes and price tags are often tamper-evident in the sense that they cannot be removed in one piece. This makes it difficult to move a vignette from one car to another, or to peel off a price tag from a cheaper article and reapply it to a more expensive one. Money is tamper-evident in the sense that it should be difficult to produce a financial token without authorization, even if starting from a token of lower value. For example, forgers may attempt to clean the ink from a banknote and print the image of a higher-denomination note on it, giving them the carefully guarded "banknote paper" which is otherwise very difficult to obtain. This may be one of the reasons why many countries use banknotes of different size in ascending order of value. A British £5
banknote A banknote—also called a bill (North American English), paper money, or simply a note—is a type of negotiable instrument, negotiable promissory note, made by a bank or other licensed authority, payable to the bearer on demand. Banknotes w ...
issued by
Bank of England The Bank of England is the central bank of the United Kingdom and the model on which most modern central banks have been based. Established in 1694 to act as the English Government's banker, and still one of the bankers for the Government o ...
is much smaller than a £50 banknote, and therefore can't be used to create a £50 note.


Physical security

Tamper-evident physical devices are common in sensitive computer installations, for example
network Network, networking and networked may refer to: Science and technology * Network theory, the study of graphs as a representation of relations between discrete objects * Network science, an academic field that studies complex networks Mathematic ...
cabling is often run down transparent conduit in plain view and switches located in glass-fronted cabinets, where any unusual device attached to the network can easily be seen. Despite the easy availability of miniature key loggers, tamper-evident design is not often used in
personal computer A personal computer (PC) is a multi-purpose microcomputer whose size, capabilities, and price make it feasible for individual use. Personal computers are intended to be operated directly by an end user, rather than by a computer expert or te ...
s. While transparent computer cases and keyboards are common, they are mainly used for the decorative effect rather than security. Many PCs do have a switch to detect opening of the case, and this provides a visual notification when the computer is next turned on that the case has recently been opened. In any case, it has long been possible to complicate the task of tampering with electronic devices by sealing them with tamper-evident tape or
sealing wax Sealing wax is a wax material of a seal which, after melting, hardens quickly (to paper, parchment, ribbons and wire, and other material) forming a bond that is difficult to separate without noticeable tampering. Wax is used to verify something ...
. Alternatively, radio-controlled alarm-devices (which transmit a silent alarm) can be installed, or cases can be glued shut in such a manner that tampering attempts will distort or fracture the casing.
Fire alarm A fire alarm system warns people when smoke, fire, carbon monoxide or other fire-related or general notification emergency, emergencies are detected. These alarms may be activated automatically from smoke detectors and heat detectors or may also ...
s and other emergency switches are typically non-reversible, using a piece of glass which must be broken to activate the alarm. For example, Panic buttons in
burglar alarm A security alarm is a system designed to detect intrusion, such as unauthorized entry, into a building or other areas such as a home or school. Security alarms used in residential, commercial, industrial, and military properties protect against ...
systems might require a plastic key to reset the switch. In very much the same manner as with fire alarms, many emergency handles and levers, or handles that are not meant to be opened regularly, are enclosed in a thin metal or plastic security seal. The seal is thin, so as not to prevent the handle from being used (in due time), but only to alert maintenance/security personnel that the handle was indeed used. Many times, large sea-going shipping containers have such a metal ring or seal attached to them at the source port. After traveling at sea (and perhaps by land as well), the containers reach their destination, where each container is checked to have the seal properly in place (against a list of doublets - container/seal). In
police The police are a Law enforcement organization, constituted body of Law enforcement officer, persons empowered by a State (polity), state, with the aim to law enforcement, enforce the law, to ensure the safety, health and possessions of citize ...
work, tamper-evident techniques must often be used to guard access to evidence, providing means of storing items and samples in a way which can be used to prove that they were not altered after their collection. Special tamper-evident evidence bags are available, to be used following a strict protocol. Video recordings can be protected to some degree against tampering by recording a
timestamp A timestamp is a sequence of characters or encoded information identifying when a certain event occurred, usually giving date and time of day, sometimes accurate to a small fraction of a second. Timestamps do not have to be based on some absolut ...
. Security seals are commonly employed on devices such as
electronic voting Electronic voting (also known as e-voting) is voting that uses electronic means to either aid or take care of casting and counting ballots. Depending on the particular implementation, e-voting may use standalone ''electronic voting machines'' ( ...
machines in an attempt to detect tampering. However, testing by
Argonne National Laboratory Argonne National Laboratory is a science and engineering research national laboratory operated by UChicago Argonne LLC for the United States Department of Energy. The facility is located in Lemont, Illinois, outside of Chicago, and is the l ...
and others demonstrates that existing seals can usually be quickly defeated by a trained person using low-tech methods. They offer ideas on countermeasures, and are exploring the promising option of "anti-evidence" seals. To prevent gas and electricity meters from being interfered with to show lower chargeable readings, they may be sealed with a lead or plastic seal with a government marking, typically fixed to a wire that passes through part of the meter housing. The meter cannot be opened without cutting the wire or damaging the seal.


Computer systems

In
cryptographic Cryptography, or cryptology (from grc, , translit=kryptós "hidden, secret"; and ''graphein'', "to write", or '' -logia'', "study", respectively), is the practice and study of techniques for secure communication in the presence of adv ...
terminology,
cryptographic hash function A cryptographic hash function (CHF) is a hash algorithm (a map of an arbitrary binary string to a binary string with fixed size of n bits) that has special properties desirable for cryptography: * the probability of a particular n-bit output ...
s and cryptographic signatures are used to add a tamper-evident layer of protection to document, often referred to as an
electronic signature An electronic signature, or e-signature, is data that is logically associated with other data and which is used by the signatory to sign the associated data. This type of signature has the same legal standing as a handwritten signature as long as ...
. Hardware-encrypted full disk drives utilise tamper-evident cases, so when it is retrieved the owner can be assured that the data has not been compromised, thus preventing costly further actions such as notifying the data owners.Nationwide wrote to all customers
/ref> The document, email, or file to be protected is used to generate a signed
hash Hash, hashes, hash mark, or hashing may refer to: Substances * Hash (food), a coarse mixture of ingredients * Hash, a nickname for hashish, a cannabis product Hash mark *Hash mark (sports), a marking on hockey rinks and gridiron football fiel ...
, a number generated from the contents of the document. Any change to the document, no matter how trivial, such as changing a single
bit The bit is the most basic unit of information in computing and digital communications. The name is a portmanteau of binary digit. The bit represents a logical state with one of two possible values. These values are most commonly represente ...
from a 1 to a 0, will cause it to have a different hash, which will make the signature invalid. To alter a document while purposely maintaining the same hash, assuming the hash function and the program implementing it are properly designed, is extremely difficult. See
Avalanche effect In cryptography, the avalanche effect is the desirable property of cryptographic algorithms, typically block ciphers and cryptographic hash functions, wherein if an input is changed slightly (for example, flipping a single bit), the output changes ...
and
Hash collision In computer science, a hash collision or hash clash is when two pieces of data in a hash table share the same hash value. The hash value in this case is derived from a hash function which takes a data input and returns a fixed length of bits. ...
.


See also

* Active packaging *
1982 Chicago Tylenol murders The Chicago Tylenol murders were a series of poisoning deaths resulting from drug tampering in the Chicago metropolitan area in 1982. The victims had all taken Tylenol-branded acetaminophen capsules that had been laced with potassium cyanide. S ...
*
Dye pack A dye is a colored substance that chemically bonds to the substrate to which it is being applied. This distinguishes dyes from pigments which do not chemically bind to the material they color. Dye is generally applied in an aqueous solution an ...
* Hardware-based full disk encryption * Ink tag * Package pilferage *
Packaging and labeling Packaging is the science, art and technology of enclosing or protecting products for distribution, storage, sale, and use. Packaging also refers to the process of designing, evaluating, and producing packages. Packaging can be described as a ...
*
Sealing wax Sealing wax is a wax material of a seal which, after melting, hardens quickly (to paper, parchment, ribbons and wire, and other material) forming a bond that is difficult to separate without noticeable tampering. Wax is used to verify something ...
*
Security printing Security printing is the field of the printing industry that deals with the printing of items such as banknotes, cheques, passports, tamper-evident labels, security tapes, product authentication, stock certificates, postage stamps and identity ...
* Security seal * Tamperproofing


References


External links


FDA Compliance Policy Guides – CPG Sec. 450.500 Tamper-Resistant Packaging Requirements for Certain Over-the-Counter Human Drug Products
*"Improving Tamper-Evident Packaging: Problems, Tests and Solutions", Jack L. Rosette, 1992
"Tamper Evident Microprocessors", Adam Waksman and Simha Sethumadhavan, 2010
* {{Packaging Packaging Security