System and method for privacy-preserving data retrieval for connected power tools

By generating encrypted serial numbers in power tools and using hash chain key technology, the problems of user privacy leakage and data protection compliance in networked power tool systems are solved, anonymous data transmission is achieved, and data security and compliance are ensured.

CN111837372BActive Publication Date: 2025-09-19ROBERT BOSCH GMBH
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN201980020287.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2018-10-12
Filing Date
2019-01-09
Publication Date
2025-09-19
Estimated Expiration
2039-01-09

Smart Images

  • Figure CN111837372B_ABST
    Figure CN111837372B_ABST
Patent Text Reader

Abstract

A method for networked tool operation with user anonymity includes generating a first cryptographic key stored in a memory of a power tool; generating a first encrypted serial number for the power tool based on an output of a cryptographic function using the first cryptographic key applied to an unencrypted serial number of the power tool stored in the memory; and generating usage data based on data received from at least one sensor in the power tool during operation of the power tool. The method also includes transmitting usage data associated only with the first encrypted serial number from the power tool to a maintenance system to enable usage data collection that prevents identification of the power tool as associated with the usage data.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Priority claim

[0002] This application claims the benefit of U.S. Provisional Application No. 62 / 619,311, entitled “System And Method For Privacy-Preserving Data Retrieval For Connected Power Tools,” filed on January 19, 2018, which is hereby expressly incorporated herein by reference in its entirety. Technical Field

[0003] The present disclosure relates generally to the field of information security and, more particularly, to systems and methods for maintaining privacy in networked power tools. Background Art

[0004] Recent advances in sensor technology, microelectromechanical systems (MEMS), internet infrastructure, and communication standards have enabled "smart" versions of many common devices to detect information about their internal state and operating environment and communicate with each other as part of the "Internet of Things" (IoT). As a key enabler of a connected world, the increasing number of smart devices is changing how people perform tasks and potentially transforming the world. Estimates of the growth of the IoT ecosystem include predictions of over 28 billion connected autonomous devices by 2020. These devices create "smart" environments such as smart grids, smart buildings, smart transportation, connected healthcare and patient monitoring, environmental monitoring, and connected cars, where individual devices communicate with each other and with centralized monitoring systems to improve these services.

[0005] As with many other industrial sectors, connectivity is seen as a source of growth for traditional manufacturers and their customers. A recent collaborative effort, titled "Track & Trace," demonstrates the development of a testbed for remotely configuring the settings and tolerances of tools and machines used on the production floor. This will ensure that industrial power tools automatically complete their designated tasks with the highest quality and efficiency required for connected manufacturing. In addition to bringing the Industrial Internet to the shop floor, leading power tool manufacturers are also integrating a number of connected power tool solutions into consumer product solutions, including Milwaukee ONE-KEY, DeWalt Tool Connect, and Black & Decker SmartTech. These smart power tools utilize integrated Bluetooth modules and typically offer the following capabilities: 1) customizing the settings of one or more compatible power tools using a smartphone or other mobile device; 2) tracking tool utilization across jobs and user networks and improving safety by remotely disabling misused power tools; 3) creating personalized power tool inventory management systems; and 4) providing real-time status information on power tool usage and performance, as well as tool purchase and warranty information.

[0006] While connected power tool systems offer both benefits to tool manufacturers and a unique user experience for customers, these systems also raise potential security and privacy concerns. For example, manufacturers collect extensive usage data about power tools in order to provide value-added services to customers. During operation, connected power tools transmit usage data at frequent intervals. That data, if not properly processed and protected, could be used to infer sensitive personal and business information about the customers using the power tools. Furthermore, certain regions have mandated specific regulations for businesses to achieve data protection and data security compliance, which creates challenges for deploying connected power tools in practice. Existing systems for collecting user data for connected power tools also expose the privacy of the collected data in a manner that could compromise the privacy of the power tool operator. Therefore, improvements to systems for collecting usage information from connected power tools that increase user privacy while recording usage data from the power tools would be beneficial. Summary of the Invention

[0007] In one embodiment, a method for networked tool operation with user anonymity has been developed. The method includes: generating, with a processor in a power tool, a first cryptographic key stored in a memory in the power tool; generating, with the processor, a first encrypted serial number for the power tool based on an output of a cryptographic function using the first cryptographic key applied to an unencrypted serial number of the power tool stored in the memory; generating, with the processor, usage data based on data received from at least one sensor in the power tool during operation of the power tool; and transmitting, with a network device in the power tool, usage data associated only with the first encrypted serial number to a maintenance system to enable collection of usage data that prevents identification of the power tool as associated with the usage data.

[0008] In another embodiment, a method for networked power tool operation with user anonymity has been developed. The method includes: generating, with a processor in the power tool, a plurality of linked cryptographic keys using a first secret cryptographic key stored in a memory in the power tool and a one-way function. The generating further includes: generating each of the plurality of linked cryptographic keys in a predetermined order starting from the first secret cryptographic key based on an output of a one-way function applied to a previous link cryptographic key in the plurality of linked cryptographic keys until a final link cryptographic key in the plurality of linked cryptographic keys is generated. The method further includes: generating, with the processor, a first encrypted serial number for the power tool based on an output of a cryptographic function using the final link cryptographic key applied to an unencrypted serial number of the power tool stored in the memory; generating, with the processor, usage data based on data received from at least one sensor in the power tool during operation of the power tool; and transmitting, with a network device in the power tool, usage data associated only with the first encrypted serial number to a maintenance system to enable usage data collection, wherein the usage data collection prevents the power tool from being identified as associated with the usage data.

[0009] In another embodiment, a power tool configured for anonymous networked operation has been developed. The power tool includes at least one sensor, a memory, a network device, and a processor. The memory is configured to store an unencrypted serial number, a first cryptographic key, and usage data. The processor is operably connected to the at least one sensor, the memory, and the network device. The processor is configured to generate a first cryptographic key stored in the memory of the power tool; generate a first encrypted serial number for the power tool based on an output of a cryptographic function using the first cryptographic key applied to the unencrypted serial number of the power tool stored in the memory; generate usage data based on data received from at least one sensor in the power tool during operation of the power tool; and transmit, using the network device, only the usage data associated with the first encrypted serial number to a maintenance system to enable usage data collection, wherein the usage data collection prevents the power tool from being identified as associated with the usage data. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] Figure 1 is a schematic diagram of a system for collecting anonymous usage data from power tools.

[0011] Figure 2 is a schematic diagram of a power tool configured to anonymize usage data transmitted to a maintenance system.

[0012] Figure 3 is a block diagram of a process for anonymizing usage data transmitted from a power tool to a maintenance system.

[0013] Figure 4 is a block diagram of another process for anonymizing usage data transmitted from a power tool to a maintenance system.

[0014] Figure 5 is a diagram depicting a hash chain for generating a cryptographic key for an encrypted serial number in a power tool. DETAILED DESCRIPTION

[0015] To promote an understanding of the principles of the embodiments described herein, reference is now made to the drawings and descriptions in the following written specification. These references are not intended to limit the scope of the present subject matter. This patent also encompasses any changes and modifications to the illustrated embodiments, and includes further applications of the principles of the described embodiments, as would normally occur to one skilled in the art to which this document pertains.

[0016] As used herein, the term "one-way function" refers to a data transformation process performed by a computing device that receives a set of input data and uses the one-way function to produce output data in such a way that an observer, when provided with the output data, cannot reproduce the original input data except by brute-force guessing, even if the observer has knowledge of the exact operation of the one-way function. One form of one-way function used in the embodiments described herein is a cryptographically secure hash function, which produces a hash value when provided with input data. As used herein, the term "cryptographically secure hash," or more simply, "hash," refers to the digital output generated by a cryptographically secure hash function based on a set of input data. Depending on the hash function used, the length of the digital output is typically on the order of 224 to 512 bits. A cryptographically secure hash function (H) has numerous properties known in the art. For the purposes of this document, useful characteristics of a cryptographically secure hash function include the one-way property, which prevents an attacker from determining the original input data D to the cryptographically secure hash function when provided with the output H(D), also known as preimage resistance. Other useful properties are second preimage resistance, which prevents an attacker from generating a different dataset D' that would accidentally produce the same hash output H(D') as the original data H(D) even if the attacker is given the original data D, and collision resistance, which prevents an attacker from being able to generate any arbitrary dataset that is different but produces the same hash output value (e.g., for , is impractical). Examples of cryptographically secure hash functions include the Secure Hash Algorithm (SHA) version 2 and version 3 families of hash functions.

[0017] As used herein, the term "hash message authentication code" (HMAC) refers to a set of digital data that is used to authenticate a set of data, D, using a secret cryptographic key. While the actual data outputs of an HMAC and a cryptographically secure hash function are generally similar in nature (e.g., a 256-bit output data set for both the hash function and the MAC), the key difference between the two is that any computing device that implements the predetermined hash function can generate a hash value for a given input data set, but only a device with access to the cryptographic key (referred to herein as K) can generate a hash value for a given input data set. m ) computing device to generate a MAC for a specific input data segment. The HMAC function is also a type of one-way function, but not all one-way functions are HMAC functions. Even if the attacker is given D, the attacker cannot generate a forged data segment D' that will reproduce the same MAC code for the original data D. The attacker cannot generate a different valid MAC for the forged data D' because the attacker does not have access to the secret K m Some HMAC functions incorporate a cryptographically secure hash function into a larger algorithm to generate the MAC (e.g., MAC= H (K m || H(K m || D ))or ), where H is a cryptographically secure hash function, K m is the key, which may be padded or hashed if necessary to fit the data block length used in the hash function, opad and ipad are predetermined padding blocks of data used in some HMAC embodiments, and D is the data for which the MAC is generated. Although the SHA-3 algorithm is considered immune to length extension attacks and can be used simply as , but the more complex scheme given above is used in HMAC to prevent a class of attacks known in the art as length extension attacks.

[0018] As used herein, in some embodiments, the HMAC function also serves as the encryption function used by the power tool to generate an encrypted serial number that anonymizes usage data transmitted from the power tool to the maintenance system. Without access to the secret cryptographic key, an attacker cannot use the encrypted serial number output by the HMAC function to determine the power tool's original, unencrypted serial number, even if the attacker is provided with a list of all valid serial numbers for the power tool used by the maintenance system. During the verification process, the power tool releases the cryptographic key to the maintenance system, which enables the maintenance system to verify the authenticity of the power tool and the anonymized usage data previously transmitted from the power tool to the maintenance system.

[0019] As used herein, the term "cryptographic key," or more simply "key," refers to a set of data that can be used in conjunction with an appropriate encryption and decryption scheme to encrypt or decrypt a set of input data. Common examples of keys include a 128-bit or 256-bit data set generated using, for example, a hardware random number generator (RNG) or a cryptographically secure key generation function such as a cryptographically secure pseudorandom number generator (PRNG), which produces a cryptographic key having random data that cannot be reproduced in a practical manner by an external computing device. As described in more detail below, a processor in a power tool generates one or more cryptographic keys, and as long as the cryptographic keys remain stored only in a memory of the power tool, the power tool can generate encrypted data, such as encrypted serial number data, that cannot be decrypted by the other computing device unless and until the power tool transfers the cryptographic keys to another computing device.

[0020] As used herein, the term "hash chaining" refers to the process of using a one-way function to produce a "hash chain," which is a series of values ​​that are "chained" together using a one-way function. For example, a simple three-element hash chain starts with an initial input value X0 and uses a cryptographically secure hash function H as the one-way function to produce the first chained value To produce the additional linked value X2, the hash chaining process applies a hash function to the previous value X1: Due to the one-way nature of the hash function H, an observer who receives a value in a hash chain can reproduce the values ​​of subsequent links in the chain (e.g., given X1, any computing device can use H to reproduce X2), but the observer cannot reproduce earlier links in the hash chain (e.g., given X1 and the hash function H, an observer has no practical way to reproduce X0 other than brute force guessing). A computing device can reproduce any given value in the hash chain only by reproducing each link in the hash chain starting with an appropriate initial value X0 and repeatedly applying the hash function H to the sequence of output values ​​an appropriate number of times, which requires minimal data storage capacity in the computing device even for hash chains consisting of a large number of values.

[0021] In a hash chain, if the initial value X0 is a cryptographic key K0 generated in a cryptographically secure manner with an appropriate key length, the hash chaining process can produce chained output values, each of which forms the basis of a subsequent cryptographic key in a plurality of chained cryptographic keys. The chained cryptographic key series can be regenerated by a computing device that has access to the initial cryptographic key K0 in the following manner: first generate the key and continue to apply the hash function H repeatedly to the linked hash chain key values ​​(e.g., etc.), until the final link cipher key K among the multiple (L) link cipher keys is generated. L Those skilled in the art will recognize that in certain configurations, a hash function produces an output data bit that has more bits than are required for a cryptographic key, such as a 256-bit hash function output where only 128 bits are required to produce the cryptographic key. A deterministic key generation process can be used to derive a cryptographic key from the output of the hash function, such that each linked cryptographic key can be generated based on the output of the hash function, which is applied to the previous cryptographic key in the linked chain. The hash chaining process can continue to generate an arbitrarily large number of linked cryptographic keys based on the linked hash outputs, generating, for example, thousands or millions of linked hash chain values ​​in some embodiments described herein. As described above, in a hash chain, an observer receiving a given value within the chain can reproduce subsequent values ​​by applying a one-way function (e.g., hash function H), but cannot reproduce earlier values ​​in the chain.

[0022] When a hash chain produces multiple linked cryptographic keys, the hash chain can provide forward privacy when the keys are revealed in reverse order, meaning that even if an external observer has access to later keys in the hash chain, the external observer cannot reconstruct earlier keys in the chain and cannot decrypt any encrypted data generated using one of the earlier keys in the chain. For example, in a hash chain formed from L linked cryptographic keys, a user who is authorized to access the final cryptographic key K L An observer of the previous link cryptographic key K cannot identify L-1 Or decrypt using key K L-1 Any encrypted data generated. During maintenance operations, when necessary, a client computing device, such as a processor in a power tool as described herein, gradually reveals linked cryptographic keys starting with the final key in the chain. The power tool then encrypts data (e.g., the power tool's serial number) using preceding cryptographic keys in the chain in reverse order to preserve the anonymity of the power tool when transmitting additional usage information from the power tool to the maintenance system, even if the maintenance system is authorized to access certain keys in the hash chain starting with the final key in the chain.

[0023] Figure 1 A system 100 is depicted that enables a power tool to share usage data with a maintenance system while enabling at least partial anonymity of the usage data during operation of the power tool. As used herein, the term "usage data" refers to data generated using one or more sensors in a power tool that relates to properties of different components in the power tool or conditions experienced by the power tool during operation of the power tool. The system 100 includes a plurality of power tools 104 in communication with a maintenance system 120. In the system 100, a third-party computing device 180 is granted limited access to retrieve and analyze anonymous usage data transmitted by the power tools 104 to the maintenance system 120. Examples of the third-party computing device 180 include, for example, an analytics system of a component manufacturer that monitors usage data of a large number of power tools 104 to determine failure rates and other performance characteristics of different components in the power tools. As described herein, the system 100 reduces or eliminates the ability of the third-party computing device 180 and computing devices within the maintenance system 120 to track the activity of individual power tools based on the usage data received from the power tools 104.

[0024] The system 100 monitors a plurality of power tools 104, each of which generates usage data during operation and transmits the usage data to a maintenance system 120 during operation. The specific operation of individual power tools 104 is described in more detail below, but the system 100 monitors a plurality of power tools that transmit anonymous usage data to the maintenance system 120. Although Figure 1A plurality of electric hand drills 104 are depicted as examples of power tools, and the system 100 can monitor a wide variety of power tools. Additionally, the term "power tool" as used herein is not strictly limited to drills, saws, nail drivers, hammering equipment, and other tools typically associated with construction; the term power tool also includes a wide variety of devices that generate usage data for use in the maintenance system 120, including, for example, motor vehicles, household appliances, and other devices requiring monitoring and maintenance of usage data. Figure 1 In the embodiment of the present invention, the maintenance system 120 further includes a data collection and indexing server 124, a maintenance data storage and retrieval server 128, and a maintenance data storage server 132, which are embodied as using Figure 1 A separate computing device implemented using general-purpose server hardware.

[0025] The data collection and indexing server 124 receives usage data from the power tools 104, which is transmitted via a data network (not shown). As described below, the power tools 104 transmit the usage data in association with an encrypted serial number to provide anonymity to the individual power tools. The data collection and indexing server 124 receives the anonymized usage data and retransmits the usage data to the maintenance data storage server 132. In some embodiments, the data collection and indexing server 124 acts as an anonymizing proxy that strips any extraneous information from the usage data that could be used to identify the individual power tools 104. For example, each power tool 104 that transmits data using a standard Internet Protocol (IP) network uses an IP address that can be used to track the usage data received from the power tool. The data collection and indexing server 124 removes the IP address and other information that could potentially identify the individual power tools from the usage data before transmitting the usage data to the maintenance data storage server 132.

[0026] Maintenance data storage and retrieval server 128 implements a database 130 that maintains registration information for power tools 104, including the power tool's unencrypted serial number, standard information about the customer who owns the power tool 104, warranty information, and the like. In some embodiments, maintenance data storage and retrieval server 128 is implemented using one or more computing devices physically located at one or more service facilities that physically receive the power tool 104 during maintenance operations. Power tools 104 communicate with the maintenance data storage and retrieval server only during maintenance operations, and not during regular operations. As described in further detail below, during maintenance operations, the power tool 104 reveals one or more cryptographic keys to maintenance data storage and retrieval server 128 to enable maintenance data storage and retrieval server 128 to retrieve usage data from maintenance data storage server 132, the usage data being related to the specific power tool 104 being serviced. Maintenance data storage and retrieval server 128 is authorized to access usage data on a limited basis only during maintenance operations, as the usage data is used to diagnose problems with the power tool during maintenance operations. Additionally, as described below, the embodiments described herein that implement forward privacy prevent the maintenance data storage and retrieval server 128 from being able to identify new usage data generated by a particular power tool 104 after a maintenance operation is completed, even if the maintenance data storage and retrieval server 128 is authorized to access older usage data for the power tool.

[0027] Maintenance data storage server 132 maintains a database 134 that stores anonymous usage data received from power tools 104. The anonymous power tool usage data associates a set of usage data with an encrypted device serial number that corresponds to the actual, unencrypted serial number of power tool 104, but prevents a third-party computing device 180 from being able to identify that any particular set of usage data actually corresponds to a particular power tool 104. The encrypted serial number does enable a third-party computing device 180 to determine that a single power tool using one encrypted serial number generated a set of usage data over a period of time between maintenance operations, which can provide valuable information for tracking the performance of different components in individual power tools over time during power tool operation. However, while a third-party computing device 180 can identify that a set of usage data was generated by one specific power tool 104, during normal operation of maintenance system 120, the third-party device 180 cannot determine which specific power tool 104 generated each set of usage data. As described in further detail below, even if an attacker compromises the maintenance system 120 and removes the anonymity of previously stored usage data by infiltrating the maintenance data storage and retrieval server 128, the embodiments providing forward secrecy described herein prevent the attacker from being able to associate newly generated usage data from a particular power tool 104 with the power tool after the maintenance process is completed.

[0028] Although Figure 1 While depicted as including at least three separate computing devices, alternative embodiments of maintenance system 120 include at least one computing device that implements the functionality of maintenance system 120 described herein. Various techniques known in the art, including clustering, virtualization, containerization, and the like, can provide isolation between servers 124, 128, and 132 of system 100 using multiple computing devices or a single computing device.

[0029] Figure 2 yes Figure 1 Schematic diagram of components in one of the power tools 104. The power tool 104 includes a processor 208 operatively connected to a peripheral device 228, a network device 212, a usage data sensor 216, and a memory 232. The power tool 104 also includes one or more motor and mechanical tool assemblies 220, a power source 224 (such as a battery, a generator, or an alternating current (AC) power adapter), and a serial number tag 250.

[0030] The processor 208 is a digital logic device that includes, for example, one or more microprocessors, microcontrollers, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), and the like. The processor 208 may optionally include a hardware random number generator (RNG) or other hardware for generating cryptographic keys in a secure manner. Although not described in further detail herein, some power tool embodiments incorporate the processor 208 into an electronic control device that also controls the operation of the motor and other mechanical components 220 in the power tool and may further control the operation of a battery or engine 224.

[0031] The usage data sensors 216 generate data relating to properties of different components in the power tool 104 or conditions experienced by the power tool 104 during operation of the power tool 104. Examples of usage data sensors 216 that generate usage data during operation of the power tool 104 include, but are not limited to, motor tachometers and torque sensors, accelerometers that can detect vibration or other movement of the power tool, temperature sensors, and voltage and current sensors that, in some embodiments, draw power from a battery or other power generation source. During operation of the power tool, the usage data sensors record information associated with the encrypted serial number 242 of the power tool 104 that the processor 208 receives and transmits to the data collection and indexing server 124. In the power tool 104, the usage data sensors 216 or the processor 208 incorporate a data interface that converts the analog sensor data into a digital signal using, for example, an analog-to-digital converter, filters, and circuits such as electrical isolation or optoelectronic isolation.

[0032] The network device 212 is a wired or wireless networking device that provides data communication between the power tool 104 and one or more remote computing devices in the maintenance system 120 using, for example, an Internet Protocol (IP)-based data network. For handheld and other portable power tool embodiments, the network device 212 is typically a wireless local area network (WLAN) or wireless wide area network (WWAN) network adapter. For larger power tools that are typically maintained in a fixed location during operation, the network device 212 may be a WLAN or WWAN network adapter or a wired data network interface such as an Ethernet adapter.

[0033] Peripheral device 228 is a wired serial bus port such as RS-232 or RS-485, a universal serial bus (USB) port, a short-range wireless data transceiver such as a Bluetooth or infrared transceiver, or any other suitable short-range peripheral connection device. The peripheral device enables short-range communication between the power tool 104 and an external computing device (e.g., maintenance data storage and retrieval server 130) during maintenance operations, but short-range communication is generally not required to transmit usage data during normal operation of the power tool 104. In some embodiments, processor 208 transmits secret cryptographic key 236 or link cryptographic key 238 via peripheral device 228 only during maintenance operations to release the secret cryptographic key to enable the maintenance system to identify the usage data history of the power tool 104 and verify the authenticity of the power tool 104.

[0034] Memory 232 includes one or more digital data storage devices, including random access memory (RAM) and non-volatile solid-state memory devices (such as NAND or NOR flash memory) or electronically erasable programmable read-only memory (EEPROM). Figure 2 In some embodiments described herein, the memory 232 holds stored program instructions 234 that are executed by the processor 208 to perform the functions described herein in conjunction with the hardware components in the power tool 104. The memory 232 also stores one or more secret encryption keys 236 that the processor 208 uses to encrypt an unencrypted serial number 240 stored in the memory 232 to generate encrypted serial number data 242. In some embodiments described herein, the memory 232 also stores one or more chaining cryptographic keys 238 that are generated using a hash chaining operation that uses the initial secret cryptographic key 236 as input.

[0035] Serial number tag 250 is a physical serial number tag, such as one permanently attached to the housing of power tool 104, that includes a barcode or RFID tag that encodes the unencrypted serial number of power tool 104 to enable an external device, such as maintenance data storage and retrieval server 128, to read the unencrypted serial number of power tool 104 during maintenance operations. Serial number tag 250 stores the same serial number as unencrypted serial number 240 stored in memory 232.

[0036] As described in more detail below, during operation, the power tool 104 uses at least one cryptographic key stored in the memory 232 to generate an encrypted serial number that is based on the unencrypted serial number assigned to the power tool during manufacturing. When the power tool 104 is operated during normal use, the processor 208 collects usage information from the usage data sensor 216 and transmits the usage data to the maintenance system 120 using the network device 212. The processor 208 transmits only the usage data associated with the encrypted serial number, which prevents the maintenance system 120 from being able to determine the user operating the power tool 104 because a large number of power tools 104 transmit usage data associated with the encrypted serial number to the maintenance system 120.

[0037] Figure 3 A process 300 is depicted for operating a power tool in conjunction with a maintenance system to provide anonymity to usage data transmitted from the power tool to the maintenance system during operation of the power tool. In the following description, reference to the process 300 to performing a function or action refers to the operation of a processor in one or more computing devices executing stored program instructions to perform the function or action in conjunction with hardware components. For illustrative purposes, the process 300 is used in conjunction with a maintenance system to provide anonymity to usage data transmitted from the power tool to the maintenance system during operation of the power tool. Figure 1 System 100 and Figure 2 The process 300 is described with reference to a power tool.

[0038] The process 300 begins by initializing the power tool 104 using the unencrypted serial number and the secret encryption key stored in the memory 232 of the power tool 104 (block 304). Figure 2In some embodiments, the processor 208 stores the unencrypted serial number 240 in the memory 232 when the power tool is manufactured, and the unencrypted serial number 240 matches the serial number placed on the serial number tag 250. In some embodiments, the serial number data 240 is stored in a small, non-erasable storage device at the time of manufacture that cannot be erased or altered by the processor 208. In other embodiments, the serial number is included in firmware along with the stored program instructions 234 stored in the memory 232 when the power tool 104 is manufactured. During process 300, the processor 208 generates a secret cryptographic key 236 using a hardware random number generator or a cryptographically secure key generation function as described above, and the secret cryptographic key 236 is not disclosed to any external computing device. During process 300, the processor 208 generates at least one secret cryptographic key 236, but as described in further detail below, in some embodiments, the processor 208 generates multiple cryptographic keys 236, and the memory 232 stores the multiple cryptographic keys 236 for use during operation and maintenance procedures. The processor 208 may generate the secret cryptographic key 236 at the time of manufacture or during initial setup when the power tool is first used by a customer.

[0039] Process 300 continues with the power tool 104 generating an encrypted serial number using the secret cryptographic key (block 316). Within the power tool 104, the processor 208 uses a predetermined encryption function, such as a block or stream symmetric encryption scheme or an HMAC using the serial number and the secret cryptographic key as input, which is otherwise known in the art, to encrypt the unencrypted serial number 240 using the secret cryptographic key 236 to generate an encrypted serial number 242. One example of a block cipher encryption scheme known in the art is the Advanced Encryption System (AES). In another embodiment, the processor 208 generates the encrypted serial number based on the output of an HMAC function applied to the unencrypted serial number data using the secret cryptographic key. This prevents any computing device without access to the encryption key from determining the unencrypted serial number when provided with the HMAC function output as the encrypted serial number. In some embodiments, the HMAC function is also used to verify the authenticity of the power tool during maintenance operations, as described in more detail below. In one embodiment of process 300, the processor 208 generates the encrypted serial number 242 after the power tool 104 is in the possession of the customer, such that the manufacturer or other third party cannot associate the encrypted serial number 242 with the power tool 104 while the power tool is still in the possession of the manufacturer or other third party before being transferred to the customer.

[0040] Process 300 continues with the power tool 104 generating usage data for the power tool and transmitting the usage data, associated only with the encrypted serial number, to the maintenance system 120 to enable the maintenance system to maintain a record of the power tool's usage while preserving the anonymity of the actual power tool generating the usage data (block 320). In the power tool 104, the processor 208 receives usage data from one or more sensors 216 during operation of the power tool 104. As described above, the usage data may include sensor data regarding the operation of the motor and other mechanical components 220 in the power tool. In some embodiments, the usage data also includes sensor data related to the battery, AC power adapter, or motor 224 in the power tool. A non-limiting example of sensor data includes current and voltage data used to monitor the charge status and health of the battery in the power tool 104. In some embodiments, the power tool 104 and the maintenance system 120 establish an authenticated and encrypted communication channel for transmitting the anonymous usage data, such as one using the Transport Layer Security (TLS) protocol or other similar protocols, to prevent third parties from eavesdropping on the usage data during transmission over the data network.

[0041] Processor 208 transmits the usage data to maintenance system 120 via the data network using network device 212. Figure 1 In one embodiment, the power tool 104 transmits usage data to the data collection and indexing server 124, which then stores the usage data in association with the encrypted serial number in the maintenance data storage server 132. The processor 208 transmits the usage data only in association with the encrypted serial number 242, enabling the maintenance system 120 to identify different sets of usage data as being generated by a single power tool, while preserving the anonymity of the power tool, as the maintenance system 120 cannot identify the unencrypted serial number of the power tool 104 based on the encrypted serial number data. In one configuration, the processor 208 transmits a continuous stream of usage data while the power tool 104 is in operation, with minimal delay between generating and transmitting the usage data. In another embodiment, the processor 208 transmits the usage data in batches based on the duration of the power tool 104's operation, either at regular intervals or after a certain amount of usage data has been generated. In some embodiments, the processor 208 temporarily stores the usage data in the memory 232 until the usage data is transmitted to the maintenance system 120.

[0042] Process 300 continues as follows: the power tool 104 connects to the maintenance system 120 during a maintenance procedure, during which the power tool 104 releases the cryptographic key to the maintenance system (block 324). During the maintenance operation, the customer typically transfers ownership of the power tool 104 to the maintenance service provider during the maintenance procedure. Part of the maintenance procedure includes connecting the power tool 104 to the maintenance data storage and retrieval server 128. In one embodiment, the power tool 104 uses the peripheral device 228 to establish a data connection to the maintenance data storage and retrieval server 128 for short-range transmission of the cryptographic key to the maintenance data storage and retrieval server 128. In other embodiments, the processor 208 in the power tool 104 uses the network device 212 to establish a data connection to the maintenance data storage and retrieval server 128 and transmits the cryptographic key to the maintenance data storage and retrieval server 128 via the data network.

[0043] During process 300, the maintenance system 120 optionally verifies the authenticity of the power tool 104 and uses the released cryptographic key received from the power tool 104 to retrieve and analyze the history of usage data as part of a maintenance process based on the cryptographic key received from the power tool, the encrypted serial number of the power tool 104, and the unencrypted serial number (block 328). In the optional verification process, the maintenance data storage and retrieval server 128 uses both the secret cryptographic key retrieved from the power tool 104 and the unencrypted serial number contained on the serial number tag 250 or transmitted from the power tool 104 to regenerate the encrypted serial number received from the power tool 104. If the regenerated encrypted serial number matches the encrypted serial number received from the power tool 104, and if the encrypted serial number matches the encrypted serial number corresponding to the usage data stored in the anonymous power tool usage data database 134 stored on the maintenance data storage server 132, then the maintenance data storage and retrieval server 128 authenticates the power tool 104 as valid. In an actual embodiment of the system 100, only the correct cryptographic key of a legitimate power tool 104 can reproduce the encrypted serial number when applied to the unencrypted serial number, such as by using an HMAC function as follows: a secret cryptographic key applied to the unencrypted serial number is used to generate an encrypted serial number based on the output of the HMAC function. The maintenance data storage and retrieval server 128 also identifies the unencrypted serial number of the power tool 104 in the serial number and customer database 130 to ensure that the power tool is registered with the maintenance system 120 for maintenance. An optional verification process enables the maintenance system 120 to confirm that the power tool 104 is an authentic power tool that generated the usage data used during the maintenance operation. In another configuration, a separate verification process that is not linked to the cryptographic key of the anonymized usage data is used to verify the authenticity of the power tool. If the maintenance system 120 determines that the power tool is not authentic in response to the regenerated encrypted serial number not matching the encrypted serial number received from the power tool 104 or being an invalid unencrypted serial number, the maintenance system 120 stops the maintenance process.

[0044] During the maintenance operation, the maintenance data storage and retrieval server 128 transmits the encrypted serial number received from the power tool 104 to the maintenance data storage server 132 in a search query. The maintenance data storage and retrieval server 128 receives usage data as part of a diagnostic process to identify problems with the power tool or to identify components that should be repaired or replaced during routine maintenance procedures. After the maintenance operation is completed, the power tool 104 is disconnected from the maintenance data storage and retrieval server 128.

[0045] The maintenance data storage and retrieval server 128 deletes the association between the encrypted serial number and the unencrypted serial number of the power tool 104 after each maintenance operation is completed to maintain the anonymity of the previously generated usage data. Figure 1 Within maintenance system 120, maintenance data storage and retrieval server 128 never transmits the cryptographic key received from power tool 104, and never transmits the association between unencrypted serial number 104 and encrypted serial number to maintenance data storage server 132. Thus, during normal operation of maintenance system 120, third-party computing devices 180 authorized to access anonymous usage data in database 134 do not receive information that would enable third-party computing devices 180 to associate encrypted serial numbers stored in maintenance data storage server 132 with the unencrypted serial number of a particular power tool 104. However, if an attacker compromises maintenance system 120, the attacker could speculatively compromise the anonymity of previously recorded usage data stored in database 134 of maintenance storage server 132 by observing the released cryptographic key released to maintenance data storage and retrieval server 128. As described below, in at least some embodiments, process 300 provides forward privacy, which preserves the anonymity of usage data transmitted from power tool 104 after a maintenance operation is complete, even if an attacker is able to compromise the anonymity of previously recorded usage data.

[0046] After the maintenance procedure is complete, process 300 continues with the following operations: processor 208 in power tool 104 generates a new secret cryptographic key (block 332). In one embodiment, processor 208 generates the new secret cryptographic key using the same process used to generate the earlier cryptographic key, as described above with reference to block 304. Process 300 then returns to block 316 where the power tool 104 generates a new encrypted serial number based on the unencrypted serial number by applying an encryption function using the newly generated cryptographic key, and the power tool 104 transmits usage data to maintenance system 120 using the newly encrypted serial number. Because the newly generated encrypted serial number cannot be linked to the previously used encrypted serial number, the newly generated secret cryptographic key is independent of the previously used cryptographic key, maintaining forward privacy. In this embodiment, processor 208 stores all generated cryptographic keys 236 in memory 232 for use in subsequent maintenance operations. During a subsequent maintenance operation, the power tool 104 releases each cryptographic key to enable the maintenance data storage and retrieval server 128 to retrieve the entire history of usage data for the power tool 104 using the multiple encrypted serial numbers associated with the power tool 104 back through multiple maintenance cycles.

[0047] In another embodiment, the processor 208 in the power tool 104 generates an initial cryptographic key K i, and the cryptographic key K i Stored with the cryptographic key data 236, but never using the initial key K i Instead, the processor 208 uses the key K i and a randomly generated one-time number (nonce) as input to a cryptographically secure pseudorandom function (PRF) to generate an initial cryptographic key used in the first cycle of process 300, and processor 208 repeats the process with the newly generated random number to generate all cryptographic keys based on the original cryptographic key K. i For example, in the first cycle of process 300, processor 208 generates a first key , which is used to use K i and a random number 1 (nonce1) as a seed for the PRF to generate a first encrypted serial number. In a subsequent cycle of process 300, processor 208 generates a second key: , which is used to use different seeds K i , random number 2 generates the second encrypted sequence number, different seed K i , random number 2 generates a different key, wherein the random value is never repeated during the generation of the additional cryptographic key. The processor 208 uses the newly generated key to generate a second encrypted serial number and maintain forward privacy. During each maintenance operation, the power tool 104 transmits the complete history of all cryptographic keys to the maintenance data storage and retrieval server 128, which uses the multiple encrypted serial numbers associated with the power tool 104 to look back over multiple maintenance cycles to retrieve the entire history of usage data for the power tool 104. However, the power tool 104 does not need to store the entire history of cryptographic keys in the memory 232. Instead, after starting with random number 1, additional random numbers random number 2, random number 3, etc. can be generated using a pseudo-random function applied to the previous random number value, which enables the power tool 104 to reduce the memory storage requirements for cryptographic data because the processor 208 can use only the initial key K i The initial random number random number 1 is used as input to the pseudo-random function together with a counter that determines the number of cryptographic keys to be regenerated to reproduce all generated cryptographic keys.

[0048] In another embodiment, the processor 208 in the power tool 104 combines the initial cryptographic key K i Indexing using a series of non-repeating but predetermined index values j (index j ), to generate a cryptographic key used to encrypt the serial number in the power tool 104 during each cycle of the process 300 using the following formula: PRF: The index value is, for example, an integer counter that is incremented during each cycle of the process 300 to produce a non-repeating value, or a digital timestamp value corresponding to a time period during which the power tool 104 generates a new encrypted serial number associated with a usage data set generated during that time period. This embodiment only requires the power tool 104 to generate the original cryptographic key during each maintenance operation. and the latest index counter index j and transmit it to the maintenance data storage and retrieval server 128, since the maintenance data storage and retrieval server 128 can then use only , starting from the original index value until the current index value j , and the unencrypted serial number of the power tool 104 as input to regenerate each encryption key and corresponding encrypted serial number for all maintenance cycles of process 300. However, this embodiment does not provide forward privacy because an attacker who has compromised the maintenance system 120 can, after observing at least one released cryptographic key transmitted by the power tool 104 to the maintenance data storage and retrieval server 128, reproduce subsequent cryptographic keys and determine the encrypted serial numbers.

[0049] The process 300 continues over multiple maintenance cycles as described above with reference to the processing of blocks 316-332 to enable each power tool 104 in the system 100 to generate usage data associated with an encrypted serial number and transmit it to the maintenance system 120. As described above, during each maintenance operation, the maintenance system 120 optionally verifies and processes the usage data for a given power tool 104 while maintaining the anonymity of the usage data for each power tool stored in the power tool usage data database 134 in the maintenance data storage server 132.

[0050] Figure 4 Another process 400 for operating a power tool in conjunction with a maintenance system is depicted for providing anonymity to usage data transmitted from the power tool to the maintenance system during operation of the power tool. In the following description, reference to the process 400 to performing a function or action refers to the operation of a processor in one or more computing devices executing stored program instructions to perform the function or action in conjunction with hardware components. For illustrative purposes, the process 400 is used in conjunction with a maintenance system. Figure 1 System 100 and Figure 2 The process 400 is described with reference to a power tool.

[0051] The process 400 begins by initializing the power tool 104 with the unencrypted serial number and the secret encryption key stored in the memory 232 of the power tool 104 (block 404). Figure 2In some embodiments, the processor 208 stores the unencrypted serial number 240 in the memory 232 when the power tool is manufactured, and the unencrypted serial number 240 matches the serial number placed on the serial number tag 250. In some embodiments, the serial number data 240 is stored in a small, non-erasable storage device that cannot be erased or altered by the processor 208 at the time of manufacture. In other embodiments, the serial number is included in the firmware along with the stored program instructions 234 stored in the memory 232 when the power tool 104 is manufactured. During process 400, the processor 208 generates an initial secret cryptographic key 236 using a hardware random number generator or a cryptographically secure key generation function as described above, and the initial secret cryptographic key 236 is not disclosed to any external computing device. The processor 208 can generate the initial secret cryptographic key 236 at the time of manufacture or during initial setup when the power tool is first used by a customer.

[0052] The process 400 continues as follows: the processor 208 generates a predetermined number of linked cryptographic keys in a hash chain starting with an initial secret cryptographic key (also referred to as a first key) as input (block 412). During the process 400, the processor 208 generates the plurality of linked cryptographic keys using the first secret cryptographic key data 236 stored in the memory 232 in the power tool 104 and a one-way function, such as a cryptographically secure hash function, such as SHA-2 or SHA-3. Starting with the first secret cryptographic key, the processor 208 generates each of the plurality of linked cryptographic keys in a predetermined order based on the output of the one-way function applied to the previous link cryptographic key in the plurality of linked cryptographic keys until a final link cryptographic key in the plurality of linked cryptographic keys is generated. As described above, the processor 208 uses the initial secret cryptographic key K i As input the first value of the hash chain, and use the one-way hash function H to generate up to a predetermined number L of additional keys: .

[0053] In generating the hash chain, the value of L can vary based on the power tool, but in at least some embodiments, the value of L is selected to be large enough to meet or exceed the expected number of maintenance operations that will occur over the life of the power tool. For example, given a power tool with an expected life of twenty years and a relatively high weekly maintenance rate (i.e., 52 maintenance operations per year), the processor 208 generates a hash chain with L = 1040 values ​​or slightly more to provide additional margin. Of course, the expected number of lifetime maintenance operations for many residential power tools will be significantly lower, and shorter hash chains can be generated that are appropriate for the expected number of service operations over the life of the power tool (e.g., two per year). Efficient generation of hash chains with at least several thousand linked cryptographic key values ​​is within the capabilities of many commercially available processors for power tools.

[0054] In the power tool 104, the processor 208 not only sets the initial secret cryptographic key K i In addition to being stored in the secret cryptographic key data 236, the L The final cryptographic key K associated with the value L L Stored in the chained cryptographic key data 238. In some embodiments with sufficient memory storage capacity, multiple cryptographic keys in the hash chain or all cryptographic keys in the hash chain are stored in the chained cryptographic key data 238. Figure 2 In the embodiment, the power tool 104 receives the final link cryptographic key K L Initially, only the currently used chain cryptographic key 238 is stored in the memory 232, which greatly reduces the memory storage requirements of the cryptographic key hash chain. The processor 208 can store the chain cryptographic key 238 in the memory 232 by i The initial secret cryptographic key data 236 can be used to begin regenerating any individual cryptographic key or set of cryptographic keys in the hash chain, so the memory 232 is not required to store all linked cryptographic keys in the hash chain.

[0055] Although Figure 2 While an embodiment of the memory 232 storing the currently used link cryptographic key data 238 is depicted, in another embodiment, the memory 232 stores only the counter value starting from L for the current link in the hash chain that is used to generate the encrypted sequence number data 242. In this embodiment, the processor 208 only briefly uses the counter value from L before deleting the cryptographic key. L The hash chain starts with the generated cryptographic key to generate the encrypted serial number.

[0056] Process 400 continues with the following operation: Processor 208 in power tool 104 generates an encrypted serial number (block 416). In power tool 104, processor 208 uses a predetermined cryptographic function, such as a block or stream symmetric encryption scheme or an HMAC using the serial number and a link cryptographic key as input, which is otherwise known in the art, to encrypt unencrypted serial number 240 using the link cryptographic key to generate encrypted serial number 242. As described above with reference to the processing of block 316 in process 300, processor 208 may apply any suitable cryptographic function, including a block cipher, a stream cipher, or an HMAC function, to unencrypted serial number data 240 using the link cryptographic key to generate encrypted serial number data 242. In one embodiment of process 400, processor 208 generates encrypted serial number 242 after power tool 104 comes into the possession of the customer, so that the manufacturer or other third party cannot associate encrypted serial number 242 with power tool 104 while the power tool is still in the possession of the manufacturer or other third party before being transferred to the customer.

[0057] Figure 5 Depicted is a hash chain of a cryptographic key used to generate an encrypted serial number as described above with reference to the processes of blocks 412 and 416. Figure 5 , the processor 208 sends the initial key 504 (K i ) Apply a cryptographically secure one-way function H to generate a hash chain 508A (K l ) to generate a hash chain of linked cryptographic keys, the one-phase function H is Figure 5 The processor 208 continues to generate each of the plurality of linked cryptographic keys in a predetermined order based on the output of the one-way function applied to the previous ones of the plurality of linked cryptographic keys until a final linked cryptographic key 508L (K L ), the plurality of linked cryptographic keys form a hash chain 500. For example, in Figure 5 In the embodiment, the processor 208 uses the key 508A as an input to the hash function 506 to generate another link cryptographic key of the plurality of link cryptographic keys and continues until the penultimate key 508K (K L-1 ) and the final cryptographic key 508L.

[0058] The linked cryptographic keys in the hash chain 500 enable the processor 208 to generate a series of encrypted serial numbers 520. To generate the first encrypted serial number 524A, the processor 208 applies the encryption function ENC shown in reference numeral 512L to the unencrypted serial number using the final cryptographic key 508L as the encryption key. As described in further detail below, during subsequent maintenance cycles of the process 400, the processor 208 either regenerates a different cryptographic key in the hash chain 500 or retrieves a key from the memory 232 to use as a cryptographic key to generate a new encrypted serial number for the power tool 104. For example, after the power tool 104 has applied the final cryptographic key K L After being released to the maintenance system 120, the processor 208 uses the previous linked cryptographic key 508K with the encryption function 512K to generate the second encrypted serial number 524B. The power tool 104 continues to use the previous linked cryptographic keys in the hash chain 500 during additional maintenance cycles until reaching the first linked cryptographic key 508A that the processor 208 uses with the encryption function 512A to generate the final encrypted serial number 524L. Although Figure 5 Not depicted, the initial key K i It can also be used to generate an additional encrypted serial number, although as mentioned above, in many embodiments, the hash chain is generated with a sufficient number of linked cryptographic keys to cover the entire useful life of the power tool 104. If the hash chain is exhausted, the processor 232 can generate a new initial cryptographic key K i ', which forms the basis of a new hash chain.

[0059] Reference again Figure 4 , process 400 continues with the following operation: the power tool 104 generates usage data for the power tool and transmits the usage data associated only with the encrypted serial number to the maintenance system so that the maintenance system can maintain a record of the power tool's usage while maintaining the anonymity of the actual power tool that generated the usage data (block 420). One benefit of this operation occurs in applications where multiple users share a single power tool, and the benefit of providing anonymity for the power tool is that it also provides anonymity for the human user of the power tool because there is no connection between the physical whereabouts of the person using the tool. The power tool 104 performs this operation in substantially the same manner as described above with reference to block 320 in process 300. In particular, the power tool 104 transmits the usage data associated with the encrypted serial number to the data collection and indexing server 124 using the network device 212.

[0060] Process 400 continues with the following operation: the power tool 104 connects to the maintenance system 120 to perform maintenance operations and the power tool 104 releases the secret key to the maintenance system (block 424). In system 100, the power tool 104 establishes a data connection to the maintenance data storage and retrieval server 128 using the peripheral device 228 or the network device 212. The processor 208 transmits the final key K from the plurality of linked cryptographic keys in the first cycle of process 400. L The power tool 104 also transmits the encrypted serial number to the maintenance data storage and retrieval server 128 and optionally transmits the unencrypted serial number of the power tool 104 using a data connection or by scanning the serial number tag 250 .

[0061] During process 400, the maintenance system 120 optionally verifies the authenticity of the power tool 104 and uses the released cryptographic key received from the power tool 104 to retrieve and analyze the history of usage data as part of the maintenance process based on the cryptographic key received from the power tool, the encrypted serial number, and the unencrypted serial number of the power tool 104 (block 428). The verification of the authenticity of the power tool 104 and the retrieval of usage data in process 400 are similar to the processing described above with reference to block 328 in process 300, with the following differences. In process 400, only the processor 208 in the power tool is required to transmit the most recently used link cryptographic key to the maintenance data storage and retrieval server 128, even if the power tool 104 has undergone multiple maintenance cycles in which the maintenance data storage server 134 has multiple usage data sets associated with multiple encrypted serial numbers of the power tool 104. In one example, a power tool 104 that has previously undergone three maintenance cycles releases the cryptographic key K in reverse order relative to the final cryptographic key K. L The fourth secret key K L-4 ,like Figure 5 The maintenance data storage and retrieval server 128 uses the released key K L-4 to perform an optional verification of the authenticity of the power tool 104, and if the power tool 104 is authenticated, the maintenance data storage and retrieval server 128 uses the released key K L-4 and a one-way function, using the same process that the power tool 104 initially performed to generate the cryptographic key in the hash chain, with the final key K at the end of the hash chain. LThe remaining portion of the linked plurality of cryptographic keys is regenerated. The maintenance data storage and retrieval server 128 then uses the key and the unencrypted serial number of the power tool 104 to regenerate all encrypted serial numbers of the power tool 104 and retrieves the entire usage data history of the power tool 104 from the maintenance data storage server 132 using the plurality of regenerated encrypted serial numbers. Thus, during each maintenance cycle of process 400, the processor 208 need only release the most recently used cryptographic key to the maintenance system 120, as the maintenance system 120 can regenerate all previously used cryptographic keys in the hash chain to enable retrieval and analysis of anonymized usage data from the power tool 104 during one or more previous maintenance cycles.

[0062] The process 400 continues after the maintenance operation is completed with the processor 208 in the power tool 104 updating the secret encryption key to use the previous cryptographic key from the plurality of linked cryptographic keys in the hash chain (block 432). In the power tool 104, the processor 208 either updates the secret encryption key from the initial cryptographic key K as described above, or updates the secret encryption key from the initial cryptographic key K as described above. i Start regenerating the next cryptographic key, or retrieve the next cryptographic key from the linked cryptographic key data 238 in the memory 232. Figure 5 As an example, the processor 208 uses the key K to link the cryptographic keys in the hash chain 500. L Then use the key K L-1 The process 400 provides forward privacy because, although the maintenance system 120 can regenerate cryptographic keys that occur after each released cryptographic key in the hash chain, the one-way function H prevents the maintenance system 120 from being able to determine any previous cryptographic key in the hash chain until the power tool 104 releases that cryptographic key during a maintenance operation. Therefore, the maintenance system 120 cannot determine the key K in the hash chain 500. L-1 or any other prior cryptographic key, even if the power tool 104 releases the key K L Process 400 continues with one or more additional maintenance cycles in processing at blocks 416 - 432 , with the power tool 104 generating a new encrypted serial number using an updated cryptographic key that has not yet been released to the maintenance system 120 to enable anonymous transmission of additional usage data to the maintenance system 120 during further operation of the power tool 104 .

[0063] The systems and methods described herein represent improvements over the functionality of computing devices in the prior art. These improvements include, but are not limited to, anonymizing usage data generated by power tools and transmitted to maintenance systems, thereby reducing or eliminating the ability of maintenance system 120 and third-party computing devices 180 to track the users of individual power tools, even if an attacker compromises maintenance system 120. During normal operation of system 100 using one of the aforementioned processes 300 and 400, maintenance system 120 maintains the anonymity of all usage data received from power tools 104. Because the power tool itself stores the key used to anonymize usage data, any maintenance system must possess the power tool to link usage data to the user, and cannot continue to track the power tool and its user after the power tool is returned to field use. During maintenance operations, maintenance data storage and retrieval server 128 retrieves usage data from maintenance data storage server 132 based solely on the encrypted serial number. This prevents third-party computing devices 180 with access to usage data in database 134 from determining the specific power tool 104 associated with any particular usage data set. Maintenance data storage and retrieval server 128 deletes the association between the encrypted serial number and the power tool's actual serial number after each maintenance operation. However, even if an attacker compromises the maintenance system 120 in a manner that enables a third party 180 to identify the association between the encrypted serial number and the individual power tool 104, the system 100 and processes 300 and 400 still protect the anonymity of the usage data of the power tool prior to the maintenance operation that potentially removes the anonymity of the previously recorded usage data. Additionally, in the embodiments implementing forward privacy described above, even if an attacker compromises the maintenance system 120 to remove the anonymity of older usage data generated in earlier maintenance cycles, the attacker still cannot compromise the anonymity of the most recent usage data from the power tool 104 generated after the most recent maintenance operation. Furthermore, the embodiments described herein provide a computationally efficient process that enables usage data from a power tool to be anonymized while enabling power tools with even relatively low-performance processors and small amounts of memory to generate anonymous usage data.

[0064] It will be appreciated that variations of the above-described and other features and functions, or alternatives thereto, may be desirably combined into many other different systems, applications, or methods. Those skilled in the art may subsequently make various currently unforeseen or unanticipated substitutions, modifications, variations, or improvements, which are also intended to be encompassed by the appended claims.

Claims

1. A method for operating a networked tool with user anonymity, comprising: generating, using a processor in the power tool, a first cryptographic key stored in a memory in the power tool; generating, with the processor, a first encrypted serial number for the power tool based on an output of a cryptographic function using a first cryptographic key applied to an unencrypted serial number of the power tool stored in the memory; generating, with the processor, usage data based on data received from at least one sensor in the power tool during operation of the power tool; transmitting, using a network device in the power tool, usage data associated only with the first encrypted serial number to a maintenance system to enable usage data collection that prevents identification of the power tool as associated with the usage data; establishing a data connection between the power tool and the maintenance system during a maintenance operation of the power tool; transmitting, using a processor in the power tool, a first cryptographic key to the maintenance system via a data connection to enable the maintenance computing system to identify tool usage data associated with the power tool only during maintenance operations; generating, using a processor in the power tool, a second cryptographic key stored in a memory in the power tool; generating, with the processor, a second encrypted serial number for the power tool based on an output of a cryptographic function using a second cryptographic key applied to an unencrypted serial number of the power tool stored in the memory; generating, with the processor, additional usage data based on data received from at least one sensor in the power tool during additional operation of the power tool after the maintenance operation; as well as Additional usage data associated only with the second encrypted serial number is transmitted to a maintenance system using a network device in the power tool to enable usage data collection that prevents identification of the power tool as associated with the additional usage data.

2. The method according to claim 1, further comprising: utilizing a processor in the power tool to transmit the unencrypted serial number to a maintenance system via a data connection; regenerating, with the maintenance system, the first encrypted serial number based on another output of the encryption function using the first cryptographic key received from the power tool applied to the unencrypted serial number received from the power tool; as well as The authenticity of the power tool is verified, with the maintenance system, in response to a match between the first encrypted serial number received from the power tool and the regenerated first encrypted serial number.

3. The method according to claim 2, further comprising: With the maintenance system, in response to a mismatch between the first encrypted serial number received from the power tool and the regenerated first encrypted serial number, an alert is generated indicating that the power tool is not authentic.

4. The method according to claim 1, wherein establishing a data connection between the power tool and the maintenance system further comprises: A data connection between the power tool and the maintenance system is established during the maintenance process using peripheral devices in the power tool that are distinct from the network devices.

5. The method according to claim 1, further comprising: Using a processor and a network device in the power tool, an authenticated and encrypted communication channel is established with a maintenance system for transmitting usage data associated only with the first encrypted serial number.

6. A method for networked power tool operation with user anonymity, comprising: generating, with a processor in the power tool, a plurality of linked cryptographic keys using a first secret cryptographic key stored in a memory in the power tool and a one-way function, the generating further comprising: generating each of the plurality of linked cryptographic keys in a predetermined order starting from a first secret cryptographic key based on an output of a one-way function applied to a previous one of the plurality of linked cryptographic keys until a final one of the plurality of linked cryptographic keys is generated; generating, with the processor, a first encrypted serial number for the power tool based on an output of a cryptographic function using a final linked cryptographic key applied to an unencrypted serial number of the power tool stored in the memory; generating, with the processor, usage data based on data received from at least one sensor in the power tool during operation of the power tool; transmitting, using a network device in the power tool, usage data associated only with the first encrypted serial number to a maintenance system to enable usage data collection that prevents identification of the power tool as associated with the usage data; establishing a data connection between the power tool and the maintenance system during a maintenance operation on the power tool; and transmitting, by a processor in the power tool, the final link cryptographic key to the maintenance system via the data connection to enable the maintenance computing system to identify tool usage data associated with the power tool only during maintenance operations; generating, with the processor, a second encrypted serial number for the power tool based on an output of an encryption function using a second linked cryptographic key of a plurality of linked cryptographic keys applied to an unencrypted serial number of the power tool stored in the memory, the second linked cryptographic key preceding a final linked cryptographic key of the plurality of linked cryptographic keys; generating, with the processor, additional usage data based on data received from at least one sensor in the power tool during additional operation of the power tool after the maintenance operation; and Additional usage data associated only with the second encrypted serial number is transmitted to a maintenance system using a network device in the power tool to enable usage data collection that prevents identification of the power tool as associated with the additional usage data.

7. The method according to claim 6, further comprising: utilizing a processor in the power tool to transmit the unencrypted serial number to a maintenance system via a data connection; regenerating, with the maintenance system, the first encrypted serial number based on another output of the encryption function using the final linked cryptographic key received from the power tool applied to the unencrypted serial number received from the power tool; as well as The authenticity of the power tool is verified, with the maintenance system, in response to a match between the first encrypted serial number received from the power tool and the regenerated first encrypted serial number.

8. The method according to claim 7, further comprising: With the maintenance system, in response to a mismatch between the first encrypted serial number received from the power tool and the regenerated first encrypted serial number, an alert is generated indicating that the power tool is not authentic.

9. The method according to claim 6, wherein establishing a data connection between the power tool and the maintenance system further comprises: A data connection between the power tool and the maintenance system is established during the maintenance process using peripheral devices in the power tool that are distinct from the network devices.

10. The method of claim 6, wherein the one-way function is a cryptographically secure hash function.

11. A power tool configured for anonymous network operation, comprising: at least one sensor; A memory configured to store: Unencrypted serial number, a first cryptographic key, and Usage Data; Network equipment; as well as A processor operatively connected to at least one sensor, a memory, and a network device, the processor configured to: generating a first cryptographic key stored in a memory of the power tool; generating a first encrypted serial number for the power tool based on an output of a cryptographic function using a first cryptographic key applied to an unencrypted serial number of the power tool stored in memory; generating usage data based on data received from at least one sensor in the power tool during operation of the power tool; transmitting, using the network device, usage data associated only with the first encrypted serial number to the maintenance system to enable usage data collection that prevents identification of the power tool as associated with the usage data; establishing a data connection between the power tool and the maintenance system during a maintenance operation of the power tool; transmitting a first cryptographic key to the maintenance system via the data connection to enable the maintenance computing system to identify tool usage data associated with the power tool only during maintenance operations; generating a second cryptographic key stored in a memory in the power tool; generating a second encrypted serial number for the power tool based on an output of a cryptographic function using a second cryptographic key applied to an unencrypted serial number of the power tool stored in the memory; generating additional usage data based on data received from at least one sensor in the power tool during additional operation of the power tool after the maintenance operation; as well as Additional usage data associated only with the second encrypted serial number is transmitted to the maintenance system using the network device to enable usage data collection that prevents identification of the power tool as associated with the additional usage data.

12. The power tool according to claim 11, further comprising: Peripheral devices that are distinct from network devices; and The processor is operatively connected to the peripheral device and is further configured to: During the maintenance process, a peripheral device is used to establish a data connection between the power tool and the maintenance system.

13. The power tool of claim 11 , wherein the processor is further configured to: An authenticated and encrypted communication channel is established with the maintenance system using the network device for transmitting usage data associated only with the first encrypted serial number.

14. The electric power tool according to claim 11, wherein The power tool is a motor vehicle.

Citation Information

Patent Citations

  • Privacy protection method for object with identification information in use and analysis

    CN104778422A

  • Vehicle message authentication method and device in Internet of Vehicles

    CN106657021A

  • System and method for automotive diagnostic tool data collection and analysis

    CN107111858A

  • Protecting user identifiable information in the transfer of telemetry data

    CN107533611A

  • System and method for the protection and de-identification of health care data

    US20080147554A1