Secure data processing device
By verifying and recording programming requests in secure data processing devices, OEMs are solved to prevent unauthorized device programming problems, ensuring the security and efficiency of device programming, preventing the generation of cloned devices, and reducing the burden on the support system.
Patent Information
- Application Number
- CN202010110429.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-02-22
- Filing Date
- 2020-02-21
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2040-02-21
AI Technical Summary
In the prior art, it is difficult for OEMs to effectively prevent factory controllers or intermediaries from unauthorized programming of programmable devices that exceed the number of protocols, resulting in the generation of cloned devices, affecting the OEM's support system and reputation, and lacking pre-checking of programming requirements.
Secure data processing equipment, including processors and memory, is used to receive and verify programming requirements in digital documents, ensure programming requests comply with regulations, and record programming history in memory to prevent unauthorized programming operations.
By verifying and recording programming requests, ensuring that only a specified number of devices is programmed, preventing the generation of cloned devices, improving the safety and efficiency of the manufacturing process and reducing the burden on the support system.
Smart Images

Figure CN111611587B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to a secure data processing device for securely programming a programmable device. Background Art
[0002] Hardware Security Modules (HSMs) are typically used to securely deploy software code and cryptographic keys to programmable devices (for use in consumer devices).
[0003] A Hardware Security Module is a device that can securely create and store private and secret keys so that they cannot be extracted. The HSM also provides the ability to perform certain selected cryptographic operations using the keys.
[0004] Generally, HSMs are used to store and use private keys, but there is no concept of restricting key operations to the specific requirements of the original customers of the HSM. In fact, FIPS 140-2 (Levels 1, 2, 3, 4) requirements tend to prevent the concept of retaining contractual information. Approval of FIPS (Federal Information Processing Standards) provides the following government certification: The keys and cryptographic algorithms are strong enough for commercial use to ensure that they are not easily compromised. Summary of the Invention
[0005] In the production chain of such programmable devices, there are usually many parties involved. For example, a silicon chip manufacturer, a factory that programs the device, a manufacturer in the form of an Original Equipment Manufacturer (OEM) that may have commissioned the device, and numerous distributors. The OEM can be referred to as the first party in this context, which includes the possibility of equating a division of the OEM to the first party.
[0006] Generally speaking, an OEM is a party that aims to create a product. For example, the product can be an Internet of Things (IoT) device. Part of the production of IoT devices may include a factory controller (such as a contract manufacturer) subcontracted by the OEM, which is used to program digital information onto an agreed number of programmable devices, where the number of programmable devices to be programmed has been agreed between the OEM and the factory controller. Usually, the agreement will take the form of a contract. After programming the programmable devices, they can form part or all of the IoT device. The OEM can communicate with the factory controller indirectly, for example, through an intermediate agency party. To program the programmable devices, the factory controller may need secret information from the OEM. Usually, the secret information will be programmed onto the programmable devices. The secret information can include digital certificates, encryption keys, and source code for running the IoT device. Usually, the secret information is commercially sensitive information that needs to be programmed onto the programmable devices in order to produce IoT devices. Therefore, the OEM needs to ensure that the factory controller can access the secret information in some form in order to program the agreed number of programmable devices. However, if the OEM allows the factory controller unrestricted access to the secret information, the factory controller may program additional programmable devices beyond the agreed number. The additional devices produced by programming beyond the agreed number are called cloned devices. Therefore, it is very beneficial for the OEM to prevent the factory controller, middleman, or any other intruder from producing cloned devices (ideally, not producing any cloned devices). This is because: cloned devices may be disadvantageous to the OEM for various reasons. For example, cloned devices may require support from the OEM or may use network resources. This may reduce the effectiveness of genuine (i.e., non-cloned) devices because the server designated to communicate with the genuine IoT devices may be overloaded with requests from cloned (i.e., non-genuine) devices. In addition, incorrectly produced cloned devices may damage the reputation of the OEM. Since cloned devices may not be distinguishable from genuine devices, the OEM may waste resources on repairing, updating, or maintaining cloned devices. Therefore, this reduces the efficiency of producing and maintaining products (such as IoT devices). Since there may be intermediate agencies between the OEM and the factory controller, the OEM can effectively contract with multiple parties and requires multi-factor authentication.
[0007] The inventors have realized the desire to create a system and / or method that allows a party (such as an OEM) to provide information to be programmed onto a device to another party without the risk of producing cloned devices.
[0008] The HSM is tamper-proof, which means that if an unauthorized attempt is made to access the data, the design of the HSM will corrupt the data stored on the HSM. The inventors have recognized that although the HSM can securely store and use cryptographic information, the prior art does not teach the concept of the HSM checking the received programming requirements before programming the device. In fact, FIPS (Federal Information Processing Standards) generally prevents the HSM from retaining programming requirements and thus discourages such behavior.
[0009] According to a first aspect of the present invention, there is provided a secure data processing device including a processor and a memory coupled to the processor, the processor being configured to receive a digital document including at least one master programming requirement specified by a first party to program at least one programmable device; determine whether a record corresponding to the digital document is stored in the memory; receive a programming request from a programming module of a programming machine communicating with the processor, the programming request requesting to program at least one programmable device; determine whether the programming request complies with at least one master programming requirement in the digital document; and wherein, if the programming request complies with at least one master programming requirement in the digital document and if no record corresponding to the digital document is stored in the memory, the processor is further configured to: output programming information to the programming module to program the at least one programmable device; and permanently store another record in the memory, wherein the another record corresponds to the digital document. The secure data processing device may be a Hardware Security Module (HSM) or any other processing device. For example, the secure data processing device may be a server having HSM functionality. The digital document may act as a contract since the digital document contains requirements that must be met. Thus, the digital document can be regarded as a contract between the first party and a third party.
[0010] Advantageously, embodiments of the present invention ensure that, for example, only the requested number of devices are programmed, thus preventing a third party from being able to manufacture more devices than specified in a contract between a first party (e.g., an OEM) and another party (e.g., an intermediary or a factory controller). Further advantageously, embodiments of the present invention ensure that other terms of the contract are met, such other terms being related, for example, to time limits for programming the devices or configuring certain options within the programmable devices.
[0011] In an embodiment, the secure data processing device is responsible for ensuring compliance with the terms of the digital document.
[0012] Embodiments of the present invention provide increased security for programming programmable devices and reduce the risk of manufacturing potentially insecure and faulty cloned devices. A clone or cloned device is a device that has been programmed without the permission of the OEM (or first party). A cloned device can be considered a counterfeit or unofficial device, but physically, they may be very similar or identical to the official device. Cloned devices may be insecure because they are typically not officially registered with the OEM. Additionally, if a large number of cloned devices are produced and use the support system, the computing resources of the support system (such as cloud services, software updates) provided by the OEM for the manufactured devices (which can be Internet of Things devices) may be overloaded until they reach a failure point. This is because the support system provided by the OEM (or anyone who commissions the device) will be for a known number of devices. Therefore, if a large number of cloned devices are also accessing the support system, the support system may fail or slow down. Embodiments of the present invention also provide increased efficiency in the device manufacturing process by simplifying the checks performed before programming multiple devices.
[0013] Advantageously, embodiments of the present invention provide increased manufacturing security and efficiency for the first party. This is because embodiments of the present invention prevent other parties (such as factories or intermediaries) other than the first party from programming (or creating) more devices than the number indicated by the first party. Additionally, other parties other than the first party are prevented from using the programming information owned by the first party for any purpose other than programming the device according to the digital document.
[0014] The secure data processing device can be a hardware security module (HSM). The secure data processing device can securely create and / or save encryption keys (including key pairs, public keys, and private keys) such that the stored / created keys cannot be extracted from the secure data processing device. The secure data processing device can also have the ability to perform a series of cryptographic functions, including cryptographic functions that utilize keys. In an embodiment, the secure data processing device retains information related to the digital document that the secure data processing device is processing or has processed in a memory. The secure data processing device can also provide a signed report based on the status of the digital document (i.e., whether programming consistent with the digital document has started or the progress of the programming listed in the digital document). These reports can be used by parties related to the programmable device to indicate that the digital document has been fulfilled.
[0015] Known HSMs do not store information related to the programming history, information related to received programming requests, or information related to received digital documents. Instead, in an embodiment of the present invention, the secure data processing device retains information about each programmed device or about each batch of programmed or supplied devices (i.e., information related to the devices programmed by the programming machine and / or the secure data processing device) to prevent the same supply run from being executed more than once.
[0016] The digital document may include one or more attachments, at least one of the one or more attachments may be specified by one of at least one other party, and may include at least one auxiliary programming requirement for programming at least one programmable device. In other words, the attachment may be specified by the same party that specifies the main programming requirement. Additionally or alternatively, the attachment may be specified by another party different from the party that specifies the main programming requirement. Generally, in an embodiment, the term "attachment" is used to indicate some digital information that can be verified independently of the main programming requirement and forms a specific term of the digital document.
[0017] One or more attachments may contain one or any combination of the following items: an attachment specified by the manufacturer of at least one programmable device; an attachment specified by the provider of the device used by the manufacturer; an attachment specified by the secure data processing device; an attachment specified by the factory provider of the factory where the programming machine is located; an attachment specified by the security system provider; an attachment specified by the security device provider; an attachment specified by the operator of the security device provided by the security device provider; an attachment specified by the provider of the software input to the programmable device; an attachment specified by the certificate provider; and an attachment specified by a government organization. Additionally, each attachment may be digitally signed by the party that specifies or writes the attachment.
[0018] The processor may be configured to: generate a programming report that provides an indication of the programming undertaken by the programming machine; and output the programming report.
[0019] The programming report may be output to one or more of the following: the programming module; the first party; and a database external to the secure data processing device. The programming report may be stored on the secure data processing device or the external database. Advantageously, this means that a record of the programming history can be securely stored such that any party involved in the manufacture of the programmable device can verify or refer to the programming history. The report may be output via the interface of the secure data processing device (wirelessly or via a wired connection).
[0020] One or more of the at least one programming requirement may specify where to output the programming report.
[0021] At least one programming requirement may specify when a programming report is generated.
[0022] One or more of the at least one programming requirement may specify to generate a programming report under the following conditions: within a specified time period; at a specified time; before the programming machine has programmed a specified number of programmable devices; after the programming machine has programmed a programmable device; whenever a defined multiple of the programmable devices has been programmed; when the programming machine has programmed a specified number of programmable devices; if the processor receives an indication to generate a programming report, preferably, wherein the indication is received in response to a suspension of the programmable device; in response to the processor receiving a report request from the first party or the second party, wherein the report request requests a programming report.
[0023] The programming report may be digitally signed by a secure data processing device. Advantageously, this means that it is difficult or impossible for any party to tamper with the programming report. Similarly, this also means that it is difficult or impossible for any party to deny, because there is a valid report that can detail what has been programmed.
[0024] If at least one of the auxiliary programming requirement and the main programming requirement fails to meet the programming request, the processor may be configured to output an indication that the digital document has been rejected. Advantageously, this can warn the involved parties that the programming machine has attempted to program the device in a manner contrary to the protocol. If such an event occurs, the party involved may want to take action. An alert or indication is an effective way to do this.
[0025] The indication that the digital document has been rejected may be output to one or more of the following: the first party; and the party that fails to meet the provisions of the programming requirement in the programming request.
[0026] If a record corresponding to the digital document is stored in the memory, the processor may be configured to send the indication that the digital document has been rejected to the first party.
[0027] The processor may be configured to generate the programming report including one or more of the following items: an indication of the number of programmable devices programmed by the programming machine since any one of the following two times: when the previously generated programming report was generated; or the start time specified by the programming requirement; the programming report time, which indicates the time when the programming report is generated; and a reference to or an indication of the digital document.
[0028] The processor may be configured to output the report.
[0029] The processor can be configured to: independently analyze each of one or more attachments; and determine whether each of the one or more attachments complies with the programming request.
[0030] The digital document can be digitally signed by a first party. The digital signature advantageously provides verification that the digital document has been approved by the first party. Additionally, this means that it is difficult or impossible to tamper with the digital document. This advantageously means that it is difficult for a party to modify a valid digital document to produce (and / or program) a cloned device. Further advantageously, this means that: in cases where the unedited digital document does not originally meet the programming requirements, it is difficult for a party to change the digital document to make it meet the programming request. It further provides an advantage to the party controlling the programming machine because the signed digital document provides evidence that the digital document to be programmed has been effectively written and approved by the first party. Thereby, the party controlling the programming machine can hold the first party responsible for payments, for example, due to programming the device. Advantageously, by using an embodiment of the present invention, this will mean that the first party will find it difficult to claim that they did not instruct the party controlling the programming machine to undertake the task of programming the device.
[0031] One or more of the at least one programming requirement can include at least one of the following items: a threshold number of times that an encryption key stored in the memory can be used in an encryption operation; a time period during which the programming machine is authorized to program the at least one programmable device; a feature that the at least one programmable device must be configured to disable; and the number of programmable devices authorized for the programming module to program.
[0032] The programming information can include at least one of the following items: password information stored in the memory; password information generated by the processor, optionally, where the password information is generated in response to the processor receiving the programming request; password information retrieved by the processor from the digital document, preferably, information retrieved from one or more of at least one attachment; and instructions for the programming machine to obtain password information from a data storage device communicating with the programming machine. The programming information can be programmed onto the programmable device. Advantageously, the programming information is stored on a secure data processing device that prevents access to the programming information by parties other than the first party. The programming information can be intellectual property rights (IPR) held by the first party. IPR has high value and should therefore be protected, but some of the IPR usually also need to be programmed onto the device (e.g., software, keys, etc.).
[0033] The processor can be configured to generate the password information in response to receiving the programming request.
[0034] The processor can be configured to retrieve password information from the digital document.
[0035] The password information may include at least one of the following items: a password; an encryption key; a digital certificate; and password information enabling the programmable device to be authenticated.
[0036] The programming information may include non-password information.
[0037] The non-password information may include at least one of the following items: an application image and a driver image database.
[0038] The processor may be configured to use a priority mechanism to resolve conflicts between multiple requirements.
[0039] Receive a digital document from at least one of the following: the first party; and the programming machine.
[0040] The primary programming requirement and / or the secondary programming requirement may be a reference to a programming requirement; and / or an instruction for obtaining a programming requirement.
[0041] The first party may be an original equipment manufacturer (OEM), optionally a division of the OEM.
[0042] Another record may include an indication that the programmable device has been programmed according to the following: the digital file; and / or the programming request.
[0043] Another record includes at least one of the following: one or more characteristics of the digital document; and a reference to the programmable device that has been programmed by the programming machine.
[0044] At least one of the secondary programming requirement and the primary programming requirement may include an indication of one or more secure data processing devices permitted to output the programming information.
[0045] According to another aspect of the present invention, there is provided a method, including: receiving a digital document including at least one primary programming requirement specified by a first party for programming at least one programmable device; determining whether a record corresponding to the digital document is stored in a memory; receiving a programming request from a programming module of a programming machine communicating with the processor, the programming request requesting programming of the at least one programmable device; determining whether the programming request conforms to at least one primary programming requirement in the digital document; and wherein, if the programming request conforms to at least one primary programming requirement in the digital document and if no record corresponding to the digital document is stored in the memory, the method further includes: outputting programming information to the programming module to program the at least one programmable device; and permanently storing another record in the memory, wherein the another record corresponds to the digital document.
[0046] According to another aspect of the present invention, there is provided a non-transitory computer-readable medium storing instructions which, when executed by a processor, cause the processor to: receive a digital document including at least one main programming requirement specified by a first party for programming at least one programmable device; determine whether a record corresponding to the digital document is stored in a memory; receive a programming request from a programming module of a programming machine communicating with the processor, the programming request requesting programming of at least one programmable device; and determine whether the programming request complies with the at least one main programming requirement in the digital document; wherein, if the programming request complies with the at least one main programming requirement in the digital document and if no record corresponding to the digital document is stored in the memory, the processor is further configured to: output programming information to the programming module to program at least one programmable device; and permanently store another record in the memory, wherein the another record corresponds to the digital document.
[0047] The instructions may be provided on a carrier such as a disk, a CD- or DVD-ROM, in a programmable memory such as a read-only memory (firmware), or on a data carrier such as an optical or electrical signal carrier. The code (and / or data) implementing embodiments of the present invention may include source code, object code or executable code of a conventional programming language such as the C language (interpreted or compiled), or assembly code, code for configuring or controlling an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array), or code for a hardware description language.
[0048] These and other aspects will become apparent from the embodiments described below. The scope of the present disclosure is not intended to be limited to this overview nor to implementations that must address any or all of the noted disadvantages. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] To better understand the present disclosure and to show how embodiments work, reference is made to the accompanying drawings, in which:
[0050] Figure 1 A block diagram of a programming system 100 is shown.
[0051] Figure 2 A block diagram of a programming system 200 is shown.
[0052] Figure 3 A block diagram of the information flow into and out of a secure data processing device is shown.
[0053] Figure 4 A method of verifying the validity of a request to program a device is shown.
[0054] Figure 5Shows a graphical representation of a digital document.
[0055] Figure 6 Shows a block diagram of system 600.
[0056] Figure 7 Shows a flowchart of the registration process. Detailed implementation
[0057] Figure 1 Shows a block diagram of programming system 100.
[0058] Programming system 100 includes a secure data processing device 104, a programming machine 102, a programmable device 126, and optionally includes a first-party device 140.
[0059] The secure data processing device 104 may have physical restrictions to prevent unauthorized parties from tampering with or obtaining information from the secure data processing device 104. The secure data processing device 104 includes a processor 114, an interface 116, a memory 112, and the memory 112 includes a working memory 110 and a digital document memory 108. The secure data processing device 104 optionally includes an interface 106 that communicates with an interface 142 of the first-party device 140. The communication can be wired or wireless.
[0060] The processor 114 is coupled to the interface 116, the interface 106, the working memory, and the digital document memory. The processor 114 is configured to run code stored in the working memory 110. The processor 114 is also configured to retrieve documents stored in the digital document memory 108 and is also configured to store documents in the digital document memory 108. The working memory 110 includes code that, when run, causes the processor to perform the steps described herein. The digital document memory 108 can be a sub-part of the working memory 110, the digital document memory 108 can be a separate database accessible by the processor 114, and can form part of the secure data processing device 104 or can be remote from the secure data processing device 104. The digital document memory 108 is configured to store digital documents. The interface 116 is configured to communicate with an interface 118 of the programming machine 102. The interfaces 116 and 118 can communicate wirelessly or via a wired connection. Generally, the secure data processing device 104 can include processing capabilities that include hardware-based encryption acceleration.
[0061] The programming machine 102 includes an interface 118, a processor 122, a programming module 124, and an interface 120. The programming machine 102 is configured to program programmable devices. In other words, the programming machine inputs or "programs" software and other digital information onto the memory 128 of the programmable device 126. The programming machine is capable of programming many devices, such as 126. The processor 122 is coupled to the interface 118, the programming module 124, and the interface 120. The processor 122 runs code stored on the programming module 124 to program the programmable device via the interface 120 and the interface 132. As part of the method of programming the programmable device 126, the processor 122 of the programming machine may retrieve information stored in the digital document memory 108 and / or the working memory 110 of the secure data processing device 104. Then, the information retrieved from the secure data processing device (and / or information derived from the retrieved information, such as an encrypted copy of the retrieved information) is programmed onto the memory 128 of the programmable device 126 via the interfaces 120 and 132. The processor 122 may be configured to receive instructions from the secure data processing device 104 to obtain information.
[0062] The programmable device 126 includes an interface 132, a memory 128, and a processor 130. The programmable device 126 communicates with the programming machine 102 via an interface 132 that communicates with the interface 120. The programmable device may be, for example, a silicon chip, a microprocessor, or a microcontroller. The processor 130 is coupled to the interface 132 and the memory 128.
[0063] The first-party device 140 may be a device such as a general computing device under OEM control, or a high-level representative of the programmable device and / or a product that includes the programmable device 126. The first-party device includes an interface 142, a processor 146, and a memory 144. The interface 142 may be configured to communicate with the interface 106 of the secure data processing device 102, and further communicate with the interface 118 of the programming machine 102, and further communicate with the user of the first party. In other words, the first-party device 140 may be configured to send digital documents to the secure data processing device 104 directly via the interfaces 142 and 106, or indirectly via the programming machine 102 (i.e., via the interfaces 142 and 118, and then via 118 and 116).
[0064] The communication between the interfaces 106 and 142, 116 and 118, 120 and 132, 142 and 118 may be wired or wireless.
[0065] Figure 2 A block diagram of the programming system 200 is shown.
[0066] The programming system 200 includes a secure data processing device 104.
[0067] As can be seen Figure 2 from Figure 2 , the secure data processing device 104 is part of and / or encapsulated within the programming machine 202. The secure data processing device 104 can be coupled to the programming machine 202.
[0068] The programming machine 202 includes an interface 218, a processor 222, a programming module 224, and an interface 220. The programming machine 202 is configured to program programmable devices.
[0069] Figure 3 Block diagram 300 is shown, which shows the information flow into and out of the secure data processing device 104. The block diagram includes a first party 340 (the first party 340 may include a first party device 140), a programmable device 126, a secure data processing device 104, a programming module 306, and a programming machine 304. The programming module 306 can be the programming module 124 and / or 224. The programming machine 304 can be the programming machine 102 and / or 202.
[0070] The secure data processing device 104 receives a digital document 310. The digital document will be discussed later with reference to Figure 5 The digital document can be received directly from the first party, and in some cases, the first party can be Figure 6 the original equipment manufacturer 602. In other embodiments, the digital document 310 is received indirectly from the first party.
[0071] The secure data processing device 104 receives a programming request (312) from the programming module 306. The programming request is a request to program one or more programmable devices. The programming request requests programming information from the secure data processing device 104, such as cryptographic keys and / or software to be programmed onto the programmable device 126 by the programming machine. The programming information can allow the programmable device to be securely authenticated on the Internet, such that only legitimate products (i.e., devices authorized by the first party for programming) will be allowed to connect (for services, management, and other activities). The secure data processing device 104 checks to see if the programming request conforms to the digital document. If it does, the secure data processing device 104 sends the programming information (314) to the programming module 306. The programming information includes at least the information requested in the programming request.
[0072] Optionally, the secure data processing device 104 outputs a programming report (316). The programming report can be sent to the first party 140. The programming report can be sent directly or indirectly to the first party or another party.
[0073] Figure 4 A method (400) for verifying a programming request is shown.
[0074] Method 400 is executed by processor 114 of secure data processing device 104.
[0075] At step 404, processor 114 receives a digital document. The digital document includes at least one master programming requirement. The at least one master programming requirement is a requirement that must be met and is specified by a first party. The first party can be Figure 6 OEM 602. Processor 114 can receive the digital document directly from the first party via interface 106, or can receive the digital document via interface 106 through an intermediary party 604. The digital document can also be received from the first party via a programming machine through interface 116. However, in this example, the received digital document is sourced from the first party. The digital document is received electronically.
[0076] The digital document can include a requirement that specifies the identity of one or more secure data processing devices that can process the digital document and / or programming requests based on the digital document.
[0077] After processor 114 has received the digital document, processor 114 is configured to determine whether a record corresponding to the received digital document is stored in memory 112. For example, the record can be a previously received digital document. The record can be the entire stored digital document, or can be just a portion of the previously received digital document. For example, the record can be a hash of the previous digital document. The record can be a condensed version of the digital document. For example, the record can be a series of options that, when combined with a digital document template, can create the digital document. The record can only represent a portion of the information of the previously received digital document.
[0078] The main purpose of step 406 is to determine whether an attempt is made to fulfill the same digital document multiple times. Advantageously, this means that in such a scenario, the secure data processing device can ultimately veto the programming of a cloning device by programming machine 102 (and / or 202). If processor 114 determines that a record corresponding to the received digital document is already stored in the memory, processor 114 can optionally output an indication (step 408). However, regardless of whether the indication is output, if processor 114 determines that a record corresponding to the received digital document is already stored in the memory, processor 114 will not output programming information to programming machine 102 (and / or 202). In other words, the secure data processing device will block the fulfillment of the digital document. The indication can be an alert or message sent to another party, such as sent to Figure 6Alarms or messages of the OEM 602 or the intermediate agency 604. This indication can be sent to the first party. The indication can be a log of attempts to fulfill the digital document multiple times. Such an indication can be sent to the first party similarly and / or can be sent to the memory of the secure data processing device for storage. The log is stored in the memory of the secure data processing device so that the authorized party can access the log at a later date and determine how many indications have been made, which will indicate how many unauthorized digital documents the secure data processing device has received. The process can end after step 408. The process can end directly after step 406. When the processor 114 receives another new digital document, the process can start again.
[0079] In step 412, the processor 114 of the secure data processing device receives a programming request. The programming request is received from the programming machine 102 (and / or 202) via the interfaces 118 and 116. The programming request includes a request for the programming machine 102 (and / or 202) to program multiple programmable devices 126. The programming request may also contain additional information, such as specifications of the device types to be programmed (e.g., the memory of the programmable device to be activated, the CPU, the chip manufacturing, the time for programming each device, etc.). The programming request can request to output some information to the programming machine. This information will be used to program the programmable devices 126, and in some cases, the information output by the secure data processing device in response to the programming request will be directly programmed by the programming machine 102 (and / or 202) onto the programmable devices 126.
[0080] In step 414, the processor is configured to determine whether the programming request complies with the requirements set forth in the digital document received in step 404. During step 414, the processor determines whether the primary programming requirements (requirements specified by the first party) are met, and also determines whether the secondary requirements (the secondary requirements may have been specified by any party including the first party) are met.
[0081] Examples of non - compliance with the programming requirements are as follows. The programming requirements can state that only 500 programmable devices can be programmed. The programming request may request to program 1000 devices. In this scenario, the programming request does not comply with the programming requirements of the digital document, and therefore, the programming information will not be output to the programming module.
[0082] Another example of non - compliance with the programming requirements is as follows. The programming requirements can state that programmable devices can only be programmed between January 1, 2018 and June 1, 2018. The programming request may request to program multiple devices during October 2018. In this scenario, the programming request does not comply with the programming requirements of the digital document, and therefore, the programming information will not be output to the programming module.
[0083] Examples that meet the programming requirements are as follows. The programming requirements can state that only 500 programmable devices can be programmed. A programming request may request to program 500 devices. In this case, the programming request meets the programming requirements of the digital document, so if all other programming requirements are met, the programming information will be output to the programming module.
[0084] Another example that meets the programming requirements is as follows. The programming requirements can state that programmable devices can only be programmed between January 1, 2018 and June 1, 2018. A programming request may request to program multiple devices during March 2018. In this case, the programming request meets the programming requirements of the digital document, so if all other programming requirements are met, the programming information will be output to the programming module.
[0085] If the processor of the secure data processing device 114 determines that all requirements that must be met are satisfied, the secure data processing device 104 will only output the information requested in the programming request. The digital document states the requirements that must be met. In some examples, the digital document can list two or more acceptable alternatives, in which case, if the programming request meets any one of the alternatives, the programming request meets the requirement.
[0086] Optionally, if the processor 114 determines that the programming request does not meet all the programming requirements of the received digital document, the processor can output an indication (step 416). The processor 114 can output the indication to a first party. Alternatively, the processor can output the indication to the memory 112 for storage. The processor 114 can output the indication to a third party, where the third party is the party associated with the unmet programming requirement. For example, if the programming request includes a request to program 1000 devices, but the programming requirements (listed in the digital document) state that only 500 devices can be programmed, the processor 114 is configured to determine that part of the programming request does not meet at least one programming requirement. The processor 114 can then output an indication to the first party that the programming machine attempted to program more devices than agreed upon in the digital document. In one example, Figure 6The programmable device manufacturer 610 may have defined secondary programming requirements, i.e., only access to the basic functionality level of the programmable device is allowed. If a programming request requests programming the programmable device to a high functionality level, the programming request does not satisfy the digital document. In this scenario, although the processor 114 may output an indication to the first party, the processor 114 may alternatively or additionally output an indication to the programmable device manufacturer 610 because the requirements of the programmable device manufacturer 610 are not met. In any case, if the programming request does not satisfy the programming requirements, the secure data processing device does not provide the requested information (necessary for programming the device) to the programming machine 102 (and / or 202). If the processor 114 determines that the programming request does not conform to all the programming requirements of the received digital document, the process ends (optionally after step 416).
[0087] As shown, the order of steps 412 and 406 may be reversed. When step 412 is executed before step 406, step 414 may be executed before step 406 or may not be executed before step 406.
[0088] Step 412 may be executed before step 404. Generally, any order is possible, however, step 406 can typically only be executed after step 404 has been executed. Similarly, step 414 can typically only be executed after step 412 has been executed.
[0089] If the processor 114 determines that the programming request does indeed conform to the programming requirements (and the processor 114 has also determined that there is no record stored in the memory corresponding to the digital document, which is optionally received from the first party), the processor outputs the programming information to the programming module 124 (and / or 224) of the programming machine (step 420). The output programming information is typically the information requested in the programming request. The output programming information may be transmitted to the programming module 124 (and / or 224) via interfaces 116 and 118 (and / or 218) and also optionally via the processor 122. The programming machine then uses the programming information to program one or more programmable devices 126.
[0090] In step 422, the processor 114 is configured to store a record of the received digital document in the memory 112 (preferably in the digital document memory 108). Step 422 may occur only when the processor 114 has received an indication that the programming request has been fulfilled or completed. The processor 114 may be configured to receive an indication that the programming request has been fulfilled or completed. Additionally or alternatively, the processor 114 may receive an indication that an item of the digital document has been fulfilled. These indications may be received from the programming machine 102 (and / or 202) via the interfaces 118 and 116 (and / or 218). These indications may be received from a first party. The record of the digital document is stored in the memory of the secure data processing device such that when / if another digital document is received in the future, the processor 114 can check whether the digital document has been fulfilled by comparing it with the previously fulfilled digital document (by using the stored record corresponding to the previously fulfilled digital document). This has the advantage over prior art secure data processing devices because embodiments of the present invention provide a secure data processing device that can determine whether a digital document has been fulfilled previously. Advantageously, the record is stored in a tamper-proof secure data processing device. This is superior to storing the record elsewhere because the record is difficult to tamper with when stored on the secure data processing device.
[0091] Optionally, the processor may be configured to output a programming report 424. This may be done before or after step 422. Generally, the processor may be configured to output a programming report at any time, such as when a request to output a programming report is received. The programming report may be information related to the status of the current programming being performed by the programming machine. The programming report may be information related to the programmable device being programmed by the programming machine.
[0092] Figure 5 A graphical representation of a digital document (500) is shown. In this embodiment, the digital document 502 includes a body 504 and four attachments (510, 516, 520, 522).
[0093] The body 504 includes one or more primary programming requirements. For example, 506 "Programming can only be performed on 1000 devices" and 508 "Programming of devices can only be performed between 13:00 GMT on January 1, 2019 and 13:00 GMT on January 1, 2020".
[0094] Attachment A 510 contains two secondary requirements, namely 512 "Each programmable device can only access 1 billion transistors" and 514 "A record of the enabled features on each programmable device must be stored".
[0095] Appendix B 516 includes a secondary requirement 518, "After programming 500 devices, a programming report shall be sent to the OEM."
[0096] Appendix C 520 includes a secondary requirement 522 "encrypted information".
[0097] Appendix D 526 includes two secondary requirements 528 "HSM identification" and 530 "public key".
[0098] Appendix E 534 includes a secondary requirement 532 "After programming 1000 devices, a programming report shall be sent from the OEM to the intermediary."
[0099] Appendix F 538 includes a secondary requirement 536 "The factory must charge for each programmable device programmed during this month every month."
[0100] The digital document 502 may correspond to Figure 3 the digital document 310 in. The body 504 includes the main programming requirements specified by the first party, which may be the OEM, a branch of the OEM, or another party. The main programming requirements 506 and 508 show examples of the requirements written by the first party in the digital document 502. In other words, the first party may also be composed of separate departments (e.g., first-party security management, first-party procurement), and one of the departments may add some terms (appendices) that it wants other departments to comply with. This may be included as part of the digital document. For example, these terms (appendices) may be the definition of the root certificate for all departments to use.
[0101] Appendix 510 specifies two auxiliary programming requirements (512 and 514). Appendix 510 is a set of two programming requirements specified by the manufacturer of at least one programmable device. Appendix 516 specifies one requirement (518). Appendix 516 is specified by a first party. Appendix 520 contains only encrypted information (522) specified by the first party. For example, this can be an encryption key or encryption software that will be retrieved by a programming machine (if the programming machine is authorized to program the programmable device) and then input into the programmable device. As another example, Appendix 520 can include encryption software that a secure data processing device can use to sign a device certificate. Appendix 520 is specified by the first party. 524 is a signature. It should be understood that this is a graphical representation. In an embodiment, the signature can be a digital signature, including a key-based digital signature. The digital signature can further involve a hash function. The signature can use any of the following: RSA algorithm, EC-DSA algorithm, and GMR signature scheme. Additionally, each appendix (i.e., each set of auxiliary programming requirements 510, 516, 520, 526) is digitally signed by the party that wrote the appendix. Appendix 526 contains a secure data processing device identifier 526 and a public key 528. The secure data processing device identifier identifies the secure data processing device (or set of secure data processing devices) that is needed to program the programming device (in conjunction with a programming machine). Appendix 526 also includes a public key for signing and other cryptographic functions.
[0102] Figure 6 is an example of system 600, which includes an original equipment manufacturer (OEM) 602, an intermediate device 604, a factory 608, and a programmable device manufacturer 610. The original equipment manufacturer (OEM) 602 can be the aforementioned first party. The factory 608 can be the party that programs the programmable device, where the programmable device has been manufactured by the programmable device manufacturer 610.
[0103] The programmable device manufacturer 610 can manufacture silicon chips for use in many different devices. The programmable device manufacturer 610 can produce general-purpose silicon chips (or typically microprocessors) that can execute at different processing levels, depending on which parts (or features) of the chip have been enabled. The programmable device manufacturer 610 may have sold programmable devices in which only certain features (e.g., a certain level of memory or CPU) have been enabled, and thus does not want the factory 608 to program the programmable device in a way that enables features at a higher specification than those agreed to (and / or paid for).
[0104] Factory 608 can input software and password information (received in the programming information) into the programmable device of OEM 602. Factory 608 may wish to prove to OEM 602 that only a specific number of devices have been programmed. In some cases, Factory 608 may want to prove that the programmable devices have been programmed in accordance with an agreement reached with the programmable device manufacturer 610, because Factory 608 may receive payment for programming the programmable devices according to the agreement. The factory is responsible for using the secure data processing device 104 to program the required number of programmable devices (as listed in the digital document). Then, the programmable devices will be placed into the products of the OEM (either through Factory 608 or other manufacturing factories).
[0105] Figure 6 An example of some of the parties involved in the production chain of a product that can be referred to as including programmable devices is shown. The product can be an Internet of Things device, such as a smartwatch, smart sensor, smartphone, or smart speaker. The products produced by the Figure 6 system are usually commissioned by OEM 602. OEM 602 usually cooperates with many parties to bring products (such as Internet of Things devices) to market. Since there may be many parties to communicate with, OEM 602 can cooperate with the intermediary 604 to coordinate and collate information from many parties. In other words, the intermediary 604 can oversee a certain proportion of the production of the product on behalf of OEM 602. OEM 602 may not trust other parties in the production chain that utilize the OEM's intellectual property rights (such as source code and keys). However, for example, Factory 608 usually needs access to some form of OEM IPR (even if encrypted) in order to program the programmable devices with the OEM's IPR. In this example, the IPR can be operating software, digital certificates, or encryption keys, but there are many other examples. Generally speaking, each party in the production chain will have requirements that at least one other party that wants to participate in the production process needs to meet. However, for each party, it may be difficult to oversee, confirm, and / or enforce the at least one other party to meet its requirements. In addition, it is also difficult for the parties to prove or refute to other parties that their requirements (the requirements they stipulate or the requirements they demand) have been met. Embodiments of the present invention provide a system for ensuring that requirements are met and providing evidence to others that the requirements have been met.
[0106] OEM 602 can prepare a digital document regarding the production of programmable devices. OEM 602 writes the main programming requirements, which are also referred to as the body of the digital document. An example of a contract is Figure 5The digital document 502 therein. Examples of parameters set in the digital document can be the technical specifications of the programmable device to be programmed, the information content programmed onto the device, the number of units of the programmable device to be programmed by the device programmer, etc. The main programming requirements (also referred to as the body of the digital document) can be seen in Figure 5 item 504 therein.
[0107] There may also be requirements from other parties (i.e., the intermediary 604, the factory 608, and the programmable device manufacturer 610) that other parties wish to attach to the digital document. These can be regarded as attachments or appendages to the digital document. The attachments or appendages include auxiliary requirements, which are requirements put forward by parties not writing the body of the digital document. Divisions of the OEM 602 may also have their own requirements and thus can add their own attachments to the digital document. The first party (e.g., the OEM 602) can also write attachments, such as Figure 5 520, 526).
[0108] In Figure 6 the dashed lines 630, 632, and 636 respectively represent the links between the intermediary 604, the factory 608, the programmable device manufacturer 610 and attachments E, F, and A. Once the parties 604, 608, and 610 have created their attachments, each of the parties sends the attachment to the OEM 602. The sending of the attachments to the OEM 602 can be seen in arrows 640, 642, and 644. The OEM 602 collates the body and the attachments and signs the completed digital document. Preferably, the first party (e.g., the OEM 602) digitally signs the digital document. In an embodiment, the parties creating the attachments can send the attachments to the intermediary 604, and in this example, the intermediary will collate the attachments and prepare the digital document for signature by the OEM 602 (the first party). In an embodiment, the attachments can be sent to the OEM 602 and then passed to the intermediary 604 for collation. Generally, the attachments can be sent electronically or physically.
[0109] Once the OEM 602 (or more generally, the first party) has signed the digital document 502, the digital document is sent (650) to the secure data processing device 104. This step also corresponds to Figure 3 step 310 therein.
[0110] The components of the factory 608 can be considered as entities distributed in multiple locations or can be contained in one machine or one location (i.e., the factory). The secure data processing device 104 can be a set of secure data processing devices, which can be located at the same location or distributed over multiple locations.
[0111] In some embodiments, the OEM 302 may provide only password-protected information (e.g., keys or certificates), encrypted IPR (e.g., software), and the number of devices to be programmed to the intermediary 304. Then, the intermediary may prepare the rest of the digital document, e.g., the time to program the programmable devices, the exact specifications of the programmable devices required by the programmable device manufacturer 318 (e.g., memory specifications, CPU specifications), etc.
[0112] In an embodiment, the factory 608 and / or the intermediary 604 pass Figure 3 the programming report of 316 in to the OEM 602 to verify that the digital document has been completed or to verify the status of the devices supplied so far at the intermediary stage.
[0113] Figure 7 A flowchart (700) of a subcontracting secure data processing device registration process between a first-party device 140 and a secure data processing device 104 is shown. This process may occur before the methods of Figure 3 and 4 In step 704, the first-party device 140 sends the identity of the first-party device to the secure data processing device 104. In step 702, the secure data processing device 104 sends the identity of the secure data processing device 104 to the first-party device 140. This may be referred to as a handshake between the first-party device and the secure data processing device. The purpose of this process is to allow the two devices to confirm the existence of the other device.
[0114] To ensure that the first party is acceptable to interact with the secure data processing device described herein, the first party may be registered with the secure data processing device before starting to send the digital document to the secure data processing device. This may be regarded as a separate event in which both parties (i.e., the secure data processing device and the first party) exchange signature information. In an embodiment, the information required for registration is part of the digital document from the secure data processing device (e.g., in an attachment).
[0115] For example, to ensure that the OEM corresponding subcontracting is acceptable, the OEM may be registered with the subcontracting HSM before the contract process. This may be regarded as a separate event in which both parties exchange signature information. Alternatively, the HSM identity information may be delivered from the HSM later as part of the contract (e.g., in an attachment).
[0116] Although the inventive concept has been specifically shown and described with reference to the preferred embodiments, those of ordinary skill in the art will understand that various changes may be made in form and detail without departing from the spirit and scope of the present disclosure as defined by the appended claims.
Claims
1. A secure data processing device, including a processor and a memory coupled to the processor, the processor being configured to: Receive a digital document, the digital document including at least one main programming requirement specified by a first party for programming at least one programmable device; Determine whether a record corresponding to the digital document is stored in the memory; Receive a programming request from a programming module of a programming machine communicating with the processor, the programming request requesting programming of the at least one programmable device; Determine whether the programming request complies with the at least one main programming requirement in the digital document; And Wherein, if the programming request complies with the at least one main programming requirement in the digital document, and if no record corresponding to the digital document is stored in the memory, the processor is further configured to: Output programming information to the programming module to program the at least one programmable device; And Permanently store another record in the memory, wherein the another record corresponds to the digital document.
2. The secure data processing device according to claim 1, wherein, The digital document includes one or more attachments, wherein at least one of the one or more attachments is specified by a party among at least one other party and includes at least one auxiliary programming requirement for programming the at least one programmable device.
3. The secure data processing device according to any one of the preceding claims, wherein, The processor is configured to: Generate a programming report, the programming report providing an indication of the programming undertaken by the programming machine; and Output the programming report.
4. The secure data processing device according to claim 3, wherein, The processor is configured to output the programming report to one or more of the following: The programming module; The first party; and A database external to the secure data processing device.
5. The secure data processing device according to claim 2, wherein At least one of the main programming requirement and the auxiliary programming requirement specifies where to output the programming report.
6. The secure data processing device according to claim 2, wherein, At least one of the main programming requirement and the auxiliary programming requirement specifies when to generate the programming report.
7. The secure data processing device according to claim 3, wherein, The processor is configured to digitally sign the programming report.
8. The secure data processing device according to claim 1 or 2, wherein If at least one of the main programming requirements fails to comply with the programming request, the processor is configured to output an indication that the digital document has been rejected.
9. The secure data processing device according to claim 2, wherein, If at least one of the auxiliary programming requirement and the main programming requirement fails to comply with the programming request, the processor is configured to output an indication that the digital document has been rejected.
10. The secure data processing device according to claim 8, wherein, The processor is configured to output the indication that the digital document has been rejected to one or more of the following: The first party; The party that specifies the main programming requirement that fails to comply with the programming request; and The programming machine.
11. The secure data processing device according to claim 1 or 2, wherein, If a record corresponding to the digital document is stored in the memory, the processor is configured to send an indication that the digital document has been rejected to the first party.
12. The secure data processing device according to claim 2, wherein, The processor is configured to generate a programming report including one or more of the following: An indication of the number of programmable devices that the programming machine has programmed since any one of the following two times: when the previously generated programming report was generated; or, a start time specified by at least one of the main programming requirement and the auxiliary programming requirement; The programming report time, which indicates the time when the programming report is generated; and A reference to the digital document or an indication of the digital document.
13. The secure data processing device according to claim 3, wherein, The processor is configured to output the programming report.
14. The secure data processing device according to claim 2, wherein, The processor is configured to: Independently analyze each of the one or more attachments; and Determine whether each of the one or more attachments complies with the programming request.
15. The secure data processing device according to claim 1 or 2, wherein, The digital document is digitally signed by the first party.
16. The secure data processing device according to claim 2, wherein, At least one of the main programming requirements and the auxiliary programming requirements includes at least one of the following items: The threshold number of times the encryption key stored in the memory can be used in an encryption operation; The time period during which the programming machine is authorized to program the at least one programmable device; The features that the at least one programmable device must be configured to disable; and The number of programmable devices authorized for the programming module to program.
17. The secure data processing device according to claim 2, wherein, The programming information includes at least one of the following items: Password information stored in the memory; Password information generated by the processor, optionally, where the password information is generated in response to the processor receiving the programming request; Password information retrieved by the processor from the digital document, preferably, information retrieved from one or more of the at least one attachment; and Instructions for the programming machine to obtain password information from a data storage device communicating with the programming machine.
18. The secure data processing device according to claim 1 or 2, wherein, The processor is configured to generate password information in response to receiving the programming request.
19. The secure data processing device according to claim 1 or 2, wherein, The processor is configured to retrieve password information from the digital document.
20. The secure data processing device according to claim 1 or 2, wherein, The processor is configured to use a priority mechanism to resolve conflicts between multiple requirements.
21. The secure data processing device according to claim 1 or 2, wherein, The processor is configured to receive the digital document from at least one of the following: The first party; and The programming machine.
22. The secure data processing device according to claim 1 or 2, wherein, The further record includes at least one of the following items: One or more characteristics of the digital document; and A reference to the programmable devices that the programming machine has programmed.
23. The secure data processing device according to claim 1 or 2, wherein, At least one of the main programming requirements includes an indication of one or more secure data processing devices that are allowed to output the programming information.
24. The secure data processing device according to claim 2, wherein, At least one of the auxiliary programming requirements and the main programming requirements includes an indication of one or more secure data processing devices that are allowed to output the programming information.
25. A method for secure data processing, the method comprising: Receiving a digital document, the digital document including at least one main programming requirement specified by a first party for programming at least one programmable device; Determining whether a record corresponding to the digital document is stored in a memory; Receiving a programming request from a programming module of a programming machine, the programming request requesting programming of the at least one programmable device; Determining whether the programming request complies with the at least one main programming requirement in the digital document; and wherein, if the programming request complies with the at least one main programming requirement in the digital document, and if no record corresponding to the digital document is stored in the memory, the method further comprises: Outputting programming information to the programming module to program the at least one programmable device; and Permanently store another record in the memory, where the another record corresponds to the digital document.
26. A non-transitory computer-readable medium storing instructions that, when executed by a processor, cause the processor to: Receive a digital document that includes at least one primary programming requirement specified by a first party for programming at least one programmable device; Determine whether a record corresponding to the digital document is stored in the memory; Receive a programming request from a programming module of a programming machine communicating with the processor, the programming request requesting programming of the at least one programmable device; And Determine whether the programming request complies with the at least one primary programming requirement in the digital document; Wherein, if the programming request complies with the at least one primary programming requirement in the digital document and if no record corresponding to the digital document is stored in the memory, the processor is further configured to: Output programming information to the programming module to program the at least one programmable device; And Permanently store another record in the memory, where the another record corresponds to the digital document.
Citation Information
Patent Citations
Information sort-out method and server
CN107291459A
Method and device for programing programmable controller and producing configuration data from central server
CN1409233A