Authorization method and system and an electronic device using the same

TW202636323AActive Publication Date: 2026-09-01GETAC TECH CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
TW114107014
Authority / Receiving Office
TW · TW
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2026-09-01
Estimated Expiration
2045-02-25

AI Technical Summary

Technical Problem

Existing electronic devices face a security risk during power-on verification as the storage device is activated simultaneously, posing a threat of data theft.

Method used

An authorization system and method that delays the startup process upon receiving a power-on command, executes an authorization procedure, and compares user-inputted verification data with a remotely stored encrypted password using an irreversible encryption process, initiating the OS only when both passwords match, and executing a shutdown or data destruction if they do not.

Benefits of technology

Enhances security by preventing unauthorized access and protecting data integrity by ensuring only authorized users can access the device, with an automatic shutdown or data destruction if verification fails.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure TWG2TA001073994_001
    Figure TWG2TA001073994_001
  • Figure TWG2TA001073994_002
    Figure TWG2TA001073994_002
  • Figure TWG2TA001073994_003
    Figure TWG2TA001073994_003
Patent Text Reader

Abstract

The authorization method for an electronic device includes to receive and store a first encrypted password generated by a remote device performing an irreversible operation on a first dynamic password, to receive an input password in response to a boot command, to perform an irreversible operation on the input password to generate a second encrypted password, and to compare the first encrypted password and the second encrypted password. When the first encryption password is consistent with the second encryption password, the electronic device is started to complete a startup procedure and the remote device updates the first dynamic password to a second dynamic password.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This invention relates to an authorization system and method, and more particularly to an authorization method and system for preventing unauthorized access to an electronic device, and to an electronic device using the authorization method and system. [Previous Technology]

[0002] Before a user accesses an electronic device, the electronic device performs a verification procedure to determine the user's access permissions, thereby confirming whether the user has the right to access the electronic device. Specifically, the user enters verification information into the electronic device, such as the user's username and password. Based on the received verification information, the electronic device determines whether the user has access permissions. If so, the electronic device allows the user to access the electronic device.

[0003] Traditionally, an electronic device is activated to receive verification data before the verification process can be executed. However, during the activation of the electronic device, the storage device is also activated simultaneously, posing a risk of data theft from the storage device. In view of this, embodiments of this specification provide an authorization system and method for an electronic device to address the aforementioned problems. [Summary of the Invention]

[0004] One embodiment of the present invention provides an authorization method for an electronic device, comprising: receiving and storing a first encrypted password generated by a remote device performing an irreversible operation on a first dynamic password; receiving an input password in response to a power-on command; performing the irreversible operation on the input password to generate a second encrypted password; comparing the first encrypted password and the second encrypted password; when the first encrypted password matches the second encrypted password, starting the electronic device to complete a startup procedure; and updating the first dynamic password to a second dynamic password by the remote device.

[0005] In some embodiments, the authorization method further includes transmitting the input password from the remote device to an electronic device that is different from the electronic device.

[0006] In some embodiments, the authorization method further includes shutting down the electronic device or destroying the data stored in the electronic device when the first encryption password is inconsistent with the second encryption password.

[0007] In some embodiments, the authorization method further includes counting the number of inconsistencies, and when the number of inconsistencies exceeds a threshold, shutting down the electronic device or destroying the data on the electronic device.

[0008] In some embodiments, the authorization method further includes receiving an updated input password when the number of inconsistencies is less than the threshold value, and performing the irreversible operation on the updated input password to generate a new second encryption password.

[0009] In some embodiments, after the electronic device completes the startup procedure, the method further includes: determining whether the electronic device is connected to the remote device, and when the electronic device is connected to the remote device, receiving and storing an updated first encryption password.

[0010] In some embodiments, the updated first encryption password is generated by the remote device performing the irreversible operation on the second dynamic password.

[0011] In some implementations, the irreversible operation is a hash algorithm.

[0012] In some embodiments, responding to the power-on command further includes delaying the startup procedure of the electronic device.

[0013] Another embodiment of the present invention provides an authorization system for an electronic device, comprising: a remote device and a first electronic device. The remote device is used to generate a first dynamic password and perform an irreversible operation on the first dynamic password to generate a first encrypted password. The first electronic device is communicatively connected to the remote device to receive the first encrypted password. The first electronic device further includes a controller, a memory, and an input / output interface. The memory is coupled to the controller and is used to store the first encrypted password. The input / output interface is coupled to the controller and responds to a power-on command to receive an input password. The controller performs the irreversible operation on the input password to generate a second encrypted password and compares the second encrypted password with the first encrypted password. When the first encrypted password matches the second encrypted password, the controller controls the first electronic device to complete a startup procedure.

[0014] In some embodiments, the authorization system further includes a second electronic device to which the remote device transmits the input password.

[0015] In some embodiments, the memory is an electronically erasable rewritable read-only memory coupled to the controller via a serial communication bus.

[0016] In some implementations, the input / output interface is a keyboard.

[0017] In some embodiments, when the first encryption password is inconsistent with the second encryption password, the controller shuts down the electronic device or destroys the data stored in the electronic device.

[0018] In some implementations, the irreversible operation is a hash algorithm.

[0019] In some embodiments, the controller further responds to the power-on command to delay the startup procedure of the first electronic device.

[0020] Another embodiment of the present invention provides an electronic device, comprising: a controller; a memory coupled to the controller for storing a first encryption password generated by a remote device; and an input / output interface coupled to the controller for receiving an input password in response to a power-on command, wherein the controller performs an irreversible operation on the input password to generate a second encryption password, and compares the second encryption password with the first encryption password, wherein when the first encryption password matches the second encryption password, the controller controls the electronic device to complete a startup procedure.

[0021] In some implementations, the irreversible operation is a hash algorithm.

[0022] In some embodiments, when the first encryption password is inconsistent with the second encryption password, the controller shuts down the electronic device or destroys the data stored in the electronic device.

[0023] In some embodiments, the remote device generates a dynamic password and performs an irreversible operation on the dynamic password to generate the first encryption password.

[0024] The authorization method and system proposed in this case, as well as the electronic device using this authorization method and system, can temporarily delay the electronic device's startup process upon receiving a power-on command through a controller installed within the electronic device. Instead, an authorization procedure is executed, and the user-inputted verification data, such as a password, is encrypted using an irreversible encryption process and compared with an encrypted password transmitted remotely and stored in memory. Only when the two passwords match will the electronic device's operating system be started and the normal power-on process begin. If the two passwords do not match, an automatic shutdown procedure is executed or the data stored on the device is destroyed. This further enhances the security of the electronic device and prevents unauthorized access.

Implementation Method

[0025] The following disclosure provides many different embodiments or examples for implementing various features of the invention. Elements and configurations in specific examples are used in the following discussion to simplify this disclosure. Any examples discussed are for illustrative purposes only and do not in any way limit the scope or meaning of the invention or its examples. Furthermore, numerical symbols and / or letters may be repeatedly referenced in different examples in this disclosure; such repetitions are for simplification and explanation and do not themselves specify the relationship between the different embodiments and / or configurations discussed below.

[0026] Unless otherwise specified, the terms used throughout this specification and the claims generally have their ordinary meaning in the context of the art, the content of this disclosure, and the specific content. Certain terms used to describe this disclosure will be discussed below or elsewhere in this specification to provide additional guidance to those skilled in the art in describing the disclosure.

[0027] The terms "coupled" or "connected" as used herein can refer to two or more components making direct physical or electrical contact with each other, or making indirect physical or electrical contact with each other. "Coupled" or "connected" can also refer to two or more components operating or moving with each other.

[0028] In this document, the terms first, second, third, etc., are used to describe various elements, components, regions, layers, and / or blocks, which is understandable. However, these elements, components, regions, layers, and / or blocks should not be limited by these terms. These terms are limited to identifying a single element, component, region, layer, and / or block. Therefore, a first element, component, region, layer, and / or block in the following text may also be referred to as a second element, component, region, layer, and / or block without departing from the spirit of the invention. As used herein, the term "and / or" includes any combination of one or more of the listed related items. "And / or" as used in this document means any combination of any, all, or at least one of the listed elements.

[0029] In general electronic devices, the power-on verification process requires the device to receive verification data before it can verify the data. During this process, the internal storage device is simultaneously powered on, posing a risk of data theft. To mitigate this risk, this invention provides an authorization system and method to prevent unauthorized access to the electronic device. A controller installed within the device, upon receiving a power-on command, temporarily delays the device's startup process, executes an authorization procedure, and compares the received verification data (e.g., an input password) with an encrypted password transmitted remotely and stored in memory after an irreversible encryption operation. If the two passwords match, the device's operating system is started, and the normal power-on process begins. If the two passwords do not match, an automatic shutdown procedure is executed, or the stored data is destroyed. This further enhances the security of the electronic device and prevents unauthorized access.

[0030] Figure 1 is a schematic diagram of an authorization system for an electronic device according to a preferred embodiment of the present invention. The authorization system 100 includes a remote device 110, a first electronic device 120, and a second electronic device 130. The remote device 110, the first electronic device 120, and the second electronic device 130 are connected via a communication protocol. In some embodiments, the remote device 110 dynamically generates a first dynamic password and a corresponding input password, and uses an irreversible operation to encrypt the first dynamic password to generate a first encrypted password, which is then transmitted to the first electronic device 120. The first electronic device 120 receives and stores this first encrypted password to determine, in subsequent boot procedures, whether the user has access permission to the first electronic device 120 based on the input password and the first encrypted password entered by the user. In some embodiments, the input password is the same as the first dynamic password, and the user uses a second electronic device 130, different from the first electronic device 120, to receive the corresponding input password generated by the remote device 110. The user enters this input password in the verification procedure of the first electronic device 120. The first electronic device 120 determines whether the user has access rights to the first electronic device 120 based on the input password entered by the user and the stored first encrypted password.

[0031] In some embodiments, the irreversible operation may be a hash algorithm. The remote device 110 may be a server. The first electronic device 120 and the second electronic device 130 are selected from a desktop computer, a laptop computer, a tablet computer, and a smartphone. The communication protocols include File Transfer Protocol (FTP), Secure File Transfer Protocol (SFTP), Network File System (NFS), Simple Mail Transfer Protocol (SMTP), Hypertext Transfer Protocol Secure (HTTPS), and the communication protocols under the Windows net use command. However, the above are only some embodiments, and this case is not limited to the above embodiments.

[0032] In some embodiments, the authorization system 100 further includes a controller 122, a memory 124 and an input / output interface 126 disposed in the first electronic device 120.

[0033] The controller 122 is an embedded controller (EC) or a microcontroller disposed in the first electronic device 120. In some embodiments, the controller 122 is coupled to a power button (not shown) of the first electronic device 120 to respond to the power-on command generated after the user presses the power button, delaying the startup procedure of the first electronic device 120 and allowing the first electronic device 120 to execute the authorization method and enter the authorization process. In this authorization process, only the controller 122, memory 124, and input / output interface 126 required to determine whether a user has access rights to the first electronic device 120 are activated. Since the main storage components of the first electronic device 120 storing sensitive data, such as hard drives, are not powered on, the security of the first electronic device 120 can be further enhanced to prevent unauthorized access.

[0034] Memory 124, such as an Electronically Erasable Programmable Read-Only Memory (EEPROM) or a flash memory, is coupled to controller 122 to store the first encrypted password transmitted by remote device 110. Controller 122 can communicate with memory 124 via a serial bus, such as an Inter-Integrated Circuit (I2C).

[0035] Input / output interface 126, such as the keyboard of the first electronic device 120, is coupled to controller 122 and can receive an input password entered by the user in response to a power-on command. In one embodiment, the input password is the same as a first dynamic password dynamically generated by remote device 110. The user uses a second electronic device 130, different from the first electronic device 120, to receive the input password generated by remote device 110. This input password is entered through input / output interface 126 during the verification process of the first electronic device 120. In some embodiments, input / output interface 126 may include a backlight that flashes to remind the user when prompted to enter an input password, or flashes to inform the user when the password verification is incorrect.

[0036] In some embodiments, after the user inputs the input password received by the second electronic device 130 from the remote device 110 at the input / output interface 126 of the first electronic device 120, the controller 122 performs an irreversible operation on the input password to generate a second encrypted password. In some embodiments, this irreversible operation may be a hash algorithm, which may be the same irreversible operation used by the remote device 110 when encrypting the first dynamic password. After the controller 122 generates this second encrypted password, the controller 122 can retrieve the first encrypted password transmitted by the remote device 110 from the memory 124 through the serial communication bus, and compare the first encrypted password and the second encrypted password to determine whether the two encrypted passwords are the same.

[0037] In some embodiments, when the first encryption password is the same as the second encryption password, it indicates that the user is an authorized user, and the controller 122 controls the first electronic device 120 to complete a boot procedure. That is, the controller 122 starts the boot procedure that was previously delayed in response to the user's power-on command to complete the boot of the first electronic device 120, so that the user can access the main storage element, such as a hard drive, in the first electronic device 120 where sensitive data is stored.

[0038] On the other hand, when the first encryption password and the second encryption password are different, it means that the user is not an authorized user. The controller 122 controls the first electronic device 120 to shut down, for example, by cutting off the power to the first electronic device 120, or by directly destroying the main storage element of the first electronic device 120 containing sensitive data, such as a hard drive, to prevent unauthorized access and further enhance overall security. In some embodiments, when the first encryption password and the second encryption password are different, the controller 122 may first control the input / output interface 126 to flash to remind the user, and then control the first electronic device 120 to shut down.

[0039] In some embodiments, the remote device 110 updates the first dynamic password to a second dynamic password and the corresponding input password, and uses irreversible operation to encrypt the second dynamic password to generate a third encrypted password, which is then transmitted to the first electronic device 120. This updates the first encrypted password stored in the memory 124 of the first electronic device 120 to the third encrypted password. Since the encrypted password used in each verification procedure of the first electronic device 120 is a newly generated encrypted password, security can be further improved. In some embodiments, after the first electronic device 120 completes the startup procedure, the controller 122 notifies the remote device 110 to update the first dynamic password. Alternatively, each time the remote device 110 and the first electronic device 120 establish a communication connection, the remote device 110 generates a new dynamic password in real time and generates a new encrypted password accordingly, which is then transmitted to the first electronic device 120. Therefore, the first electronic device 120 receives a new encrypted password each time it connects to the remote device 110. However, this invention is not limited to the above description.

[0040] Figure 2 is a flowchart of a licensing method for an electronic device according to a preferred embodiment of this invention. Referring also to Figures 1 and 2, the method of this embodiment is applicable to the first electronic device 120 in Figure 1. It should be understood that, unless otherwise specified, the order of operations of the licensing method 200 mentioned in this embodiment can be adjusted as needed, and may even be performed simultaneously or partially simultaneously. Furthermore, in different embodiments, these operations can be adaptively added, replaced, and / or omitted.

[0041] In the authorization method 200, firstly, in step 202, a first encrypted password generated by a remote device is received. In some embodiments, when the first electronic device 120 is coupled to the remote device 110 through a communication protocol, the remote device 110 dynamically generates a first dynamic password and a corresponding input password, and uses an irreversible operation to encrypt the first dynamic password to generate a first encrypted password, which is then transmitted to the first electronic device 120 for reception. The irreversible operation is a hash algorithm.

[0042] In step 203, a power-on command is responded to. In some embodiments, the controller 122 in the first electronic device 120 responds to the power-on command generated by the user pressing the power-on button of the first electronic device 120, delays the startup procedure of the first electronic device 120, and allows the first electronic device 120 to enter the authorization process to verify whether the user has access rights to the first electronic device 120.

[0043] In step 204, an input password is received. In some embodiments, the input / output interface 126 of the first electronic device 120 can receive the input password entered by the user. In one embodiment, the input password is the same as the first dynamic password dynamically generated by the remote device 110. The user uses a second electronic device 130, different from the first electronic device 120, to receive the input password generated by the remote device 110 and inputs it on the input / output interface 126 of the first electronic device 120.

[0044] In step 206, a second encrypted password is generated based on the input password. In some embodiments, the controller 122 of the first electronic device 120 performs an irreversible operation on the input password entered by the user to generate a second encrypted password. In some embodiments, this irreversible operation may be a hash algorithm, which may be the same irreversible operation used by the remote device 110 when encrypting the first dynamic password.

[0045] In step 208, it is determined whether the first encryption password and the second encryption password are consistent. In some embodiments, after the controller 122 of the first electronic device 120 generates the second encryption password, the controller 122 can retrieve the first encryption password transmitted by the remote device 110 from the memory 124 through the serial communication bus, and compare the first encryption password and the second encryption password to determine whether the two encryption passwords are the same.

[0046] When the first encryption password and the second encryption password are inconsistent, in step 210, it is determined whether the number of inconsistencies exceeds a threshold value. In some embodiments, to avoid inconsistencies between the first encryption password and the second encryption password caused by the user accidentally entering the wrong password, a threshold value is set in this invention. If the number of inconsistencies between the first encryption password and the second encryption password is less than the threshold value, the user can be allowed to enter a new input password again, and steps 204 to 208 are executed again. The controller 122 of the first electronic device 120 performs an irreversible operation on this new input password to generate a second encryption password for comparison with the first encryption password.

[0047] Conversely, if the number of times the first encryption password and the second encryption password do not match exceeds a threshold value, then in step 212, the first electronic device is shut down or the data on the first electronic device is destroyed. In some embodiments, if the number of times the first encryption password and the second encryption password do not match exceeds a threshold value, it means that the user is not an authorized user. The controller 122 controls the first electronic device 120 to shut down, for example, by cutting off the power to the first electronic device 120, or by directly destroying the main storage element of the first electronic device 120 containing sensitive data, such as a hard drive, to prevent unauthorized access.

[0048] On the other hand, when the first encryption password and the second encryption password are the same, in step 214, the first electronic device is started to complete a startup procedure. In some embodiments, when the first encryption password and the second encryption password are the same, it indicates that the user is an authorized user, and the controller 122 of the first electronic device 120 controls the first electronic device 120 to complete a startup procedure. That is, the controller 122 starts the startup procedure that was previously delayed in response to the user's power-on command to complete the startup of the first electronic device 120.

[0049] In some embodiments, the remote device 110 dynamically updates the first dynamic password so that each time the remote device 110 and the first electronic device 120 establish a communication connection, the remote device 110 transmits the newly generated encryption password to the first electronic device 120. Therefore, in step 216, it is first determined whether the first electronic device is connected to the remote device. When the first electronic device 120 is connected to the remote device 110, in step 218, the first electronic device receives the updated first encryption password from the remote device. In some embodiments, the remote device 110 can dynamically generate a new second dynamic password in real time and generate an updated first encryption password based on this new second dynamic password, which is then transmitted to the first electronic device 120. The first electronic device can then update the first encryption password stored in memory 124 based on this updated first encryption password. In other words, each time the first electronic device 120 connects to the remote device 110, it receives an updated encryption password from the remote device 110 for subsequent user access verification. After updating the encryption password, the user can use the first electronic device 120 normally in step 220. Conversely, when the first electronic device 120 is not connected to the remote device 110, the first electronic device 120 will not perform the update process of the first encryption password in memory 124. The user can use the first electronic device 120 normally in step 222.

[0050] As can be seen from the above embodiments, the authorization method and system provided in this case, as well as the electronic device using this authorization method and system, can temporarily delay the electronic device's startup process upon receiving a power-on command through a controller installed within the electronic device. Instead, an authorization procedure is executed, and the user-inputted verification data, such as a password, is encrypted using an irreversible encryption operation and compared with an encrypted password transmitted remotely and stored in memory. Only when the two passwords match will the electronic device's operating system be started and the normal startup process begin. If the two passwords do not match, an automatic shutdown procedure is executed or the data stored in the storage device is destroyed. This further enhances the security of the electronic device and prevents unauthorized access.

[0051] Furthermore, the above examples include sequential exemplary steps, but these steps need not be performed in the order shown. Performing these steps in different orders is within the scope of this disclosure. Within the spirit and scope of the embodiments of this disclosure, these steps may be added, substituted, changed in order, and / or omitted as appropriate.

[0052] Although the embodiments have been disclosed above, they are not intended to limit the scope of this case. Anyone skilled in the art can make various modifications and alterations without departing from the spirit and scope of this case. Therefore, the scope of protection of this case shall be determined by the appended claims. [Simplified Explanation of the Diagram]

[0053] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments of the invention and, together with the description, serve to explain the technical solutions of the embodiments of the invention. Figure 1 is a schematic diagram of a licensing system for an electronic device according to a preferred embodiment of the present invention. Figure 2 is a flowchart of a licensing method for an electronic device according to a preferred embodiment of the present invention. [Biomaterial Storage]

[0055] Domestic storage information (please note in order of storage institution, date, and number): None. International storage information (please note in order of storage country, institution, date, and number): None.

Claims

1. A method for licensing an electronic device, comprising: The system receives and stores a first encrypted password generated by a remote device performing an irreversible operation on a first dynamic password; the first dynamic password is generated by the remote device; in response to a power-on command, it receives an input password generated by the remote device; it performs the irreversible operation on the input password to generate a second encrypted password; it compares the first encrypted password and the second encrypted password; when the first encrypted password matches the second encrypted password, it starts the electronic device to complete a startup procedure; and the remote device updates the first dynamic password to a second dynamic password.

2. The authorization method as described in claim 1 further includes: The remote device transmits the input password to an electronic device that is different from the electronic device.

3. The authorization method as described in claim 1 further includes: When the first encryption password does not match the second encryption password, the electronic device is turned off or the data stored in the electronic device is destroyed.

4. The authorization method as described in claim 3 further includes: The system counts the number of inconsistencies and, when the number of inconsistencies exceeds a threshold, shuts down the electronic device or destroys the data on the electronic device.

5. The authorization method as described in claim 4 further includes: When the number of inconsistencies is less than the threshold value, an updated input password is received, and the irreversible operation is performed on the updated input password to generate a new second encryption password.

6. The authorization method as described in claim 1, further comprising, after the electronic device is started and the startup procedure is completed: Determine whether the electronic device is connected to the remote device, and when the electronic device is connected to the remote device, receive and store an updated first encryption password.

7. The authorization method as described in claim 6, wherein the updated first encryption password is generated by the remote device performing the irreversible operation on the second dynamic password.

8. The authorization method as described in Request 1, wherein the irreversible operation is a hash algorithm.

9. The authorization method as described in claim 1, wherein responding to the power-on command further includes delaying the startup procedure of the electronic device.

10. An authorization system for an electronic device, comprising: A remote device is used to generate a first dynamic password and to perform an irreversible operation on the first dynamic password to generate a first encrypted password. The remote device is also configured to receive a first encrypted password, wherein the first electronic device further includes: a controller; a memory coupled to the controller for storing the first encrypted password; and an input / output interface coupled to the controller for responding to a power-on command to receive an input password generated by the remote device. The controller performs an irreversible operation on the input password to generate a second encrypted password and compares the second encrypted password with the first encrypted password. When the first encrypted password matches the second encrypted password, the controller controls the first electronic device to complete a startup procedure. After receiving the first encrypted password, the remote device updates the first dynamic password to a second dynamic password.

11. The authorization system as described in claim 10 further includes: A second electronic device, the remote device transmitting the input password to the second electronic device.

12. The authorization system as described in claim 10, wherein the memory is an electronically erasable rewritable read-only memory coupled to the controller via a serial communication bus.

13. The authorization system as described in claim 10, wherein the input / output interface is a keyboard.

14. The authorization system as described in claim 10, wherein when the first encryption password is inconsistent with the second encryption password, the controller shuts down the electronic device or destroys the data stored in the electronic device.

15. The authorization system as described in claim 10, wherein the irreversible operation is a hash algorithm.

16. The authorization system as described in claim 10, wherein the controller further responds to the power-on command to delay the startup procedure of the first electronic device.

17. An electronic device comprising: One controller; A memory, coupled to the controller, is used to store a first encrypted password generated by a remote device, wherein the remote device generates a first dynamic password and performs an irreversible operation on the first dynamic password to generate the first encrypted password; and an input / output interface, coupled to the controller, responds to a power-on command to receive an input password generated by the remote device, wherein the controller performs an irreversible operation on the input password to generate a second encrypted password, and compares the second encrypted password with the first encrypted password, wherein when the first encrypted password matches the second encrypted password, the controller controls the electronic device to complete a startup procedure, wherein after the memory stores the first encrypted password, the remote device updates the first dynamic password to a second dynamic password.

18. The electronic device as claimed in claim 17, wherein the irreversible operation is a hash algorithm.

19. The electronic device as claimed in claim 17, wherein when the first encryption key is inconsistent with the second encryption key, the controller shuts down the electronic device or destroys the data stored in the electronic device.