Method and system for license and key delivery for sensors and receivers

By generating and managing key pairs at a central location, and using asymmetric encryption methods to transmit keys between sensors and receivers, the problem of insufficient security in the key transmission process between sensors and receivers is solved, enabling flexible licensing and secure transmission across multiple devices.

CN114616794BActive Publication Date: 2025-11-04DIEHL METERING SYSTEMS GMBH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080073781.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-10-25
Filing Date
2020-10-12
Publication Date
2025-11-04
Estimated Expiration
2040-10-12

AI Technical Summary

Technical Problem

In existing technologies, sensors and receivers have insufficient security during key transmission, especially when transmitting keys in plaintext, which makes them vulnerable to interception or interception. Furthermore, existing methods cannot flexibly license multiple devices.

Method used

The system generates and manages key pairs at a central location, exchanges public keys between the sensor and receiver manufacturers and the central location, uses asymmetric encryption to transmit keys between the sensors and receivers, and stores a list of keys at the central location to ensure that only authorized devices can decrypt them.

Benefits of technology

It achieves enhanced security while allowing flexible licensing of multiple sensors and receivers, ensuring the security of transmission keys, avoiding the decryption risk when the public key is intercepted, and supporting one-way communication and device registration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114616794B_ABST
    Figure CN114616794B_ABST
Patent Text Reader

Abstract

The invention relates to a method for licensing a sensor (S) at a central location (Z), a method for licensing a receiver (E) at a central location (Z), a method for providing a list (LSS) of sensor keys by a central location (Z), and a method for registering a licensed sensor (S) at a licensed receiver (E), as well as a system for transmitting data from a licensed sensor (S) to a licensed receiver (E). With the method and the system a licensing of sensors and receivers can be realized, wherein in the same process a secure transmission of a transmission key for a communication or data exchange between the sensor and the receiver can also be ensured. The transmission key can be transmitted encrypted and there is no necessity to transmit the transmission key unencrypted. Furthermore, with the secure transmission of the transmission key a licensing model for the sensor and the receiver can be established.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The invention relates to a method for licensing a sensor at a central location according to the invention, a method for licensing a receiver at a central location according to the invention, a method for providing a list of sensor keys by a central location according to the invention, and a method for registering a licensed sensor at a licensed receiver according to the invention, and a system for transmitting data from a licensed sensor to a licensed receiver according to the invention. BACKGROUND

[0002] Some delivery technologies, for example MIOTY, are based on a license related to the device. Participants with individual encryption require a secure key transfer. Here, not only the sensor that acts as a transmitter but also the receiver that takes over the task of data processor is to be licensed. Here, the delivery key for data exchange and message exchange is transmitted as plain text.

[0003] The Elliptic Curve Integrated Encryption Scheme (ECIES) is a hybrid encryption method based on elliptic curves. As a hybrid method, it combines an asymmetric method for sending a symmetric key with a symmetric encryption method that encrypts a message with the symmetric key. For the asymmetric encryption, an encryption method based on Elliptic Curve Cryptography (ECC) can be used. SUMMARY

[0004] The task of the invention is to provide a novel method for the licensing and key transfer of sensors and receivers and a system for transmitting data, in which an increased security is achieved with increased flexibility in the case of simultaneous licensing and key transfer.

[0005] Solution to the problem

[0006] The above task is solved by the entire teaching of the invention and by the system according to the invention. Advantageous design solutions of the invention are claimed in the invention.

[0007] According to the application, a method for licensing a sensor at a central location is proposed, wherein the method comprises a sensor, a central location comprising a computer system and a database, and a manufacturer of the sensor comprising a computer system, wherein there is a data connection between the manufacturer of the sensor and the central location, wherein it is characterized that a list of sensor keys is saved in the database of the central location, wherein a first key pair consisting of a private key and a public key is generated at the manufacturer of the sensor, the public key of the first key pair is transmitted from the manufacturer of the sensor to the central location, a range of serial numbers of the sensor is assigned to the first key pair, a second key pair consisting of a private key and a public key is generated at the central location, the public key of the second key pair is transmitted from the central location to the manufacturer of the sensor, a range of serial numbers of the sensor is assigned to the second key pair, the public key of the first key pair, the private key of the second key pair and the assigned range of serial numbers of the sensor are stored in the list of sensor keys in the central location, the manufacturer of the sensor encrypts a transmission key for data transmission between the sensor and a receiver with the private key of the first key pair and the public key of the second key pair, and stores the encrypted transmission key in the sensor, and the manufacturer of the sensor stores the private key of the first key pair and the public key of the second key pair in the sensor or additionally stores the transmission key unencrypted.

[0008] The method according to the application achieves that the transmission key is stored encrypted in the sensor, so that on the one hand the sensor has access to the transmission key or can decrypt it, and on the other hand there is a key for decrypting the transmission key at the central location, for example used as a licensing location. Based on the method according to the application, for this advantageously only the public keys are exchanged between the parties involved, the manufacturer of the sensor and the central location. Thereby, the method for licensing is particularly secure, because even if the public keys are intercepted or intercepted during transmission by a third party, these intercepted public keys are not sufficient to decrypt the encrypted transmission key. The method for licensing a sensor is not limited to a single sensor, so that a plurality of sensors can be registered at the central location. If a plurality of sensors is licensed at the central location, it is advantageous to save the respective keys and the assigned ranges of serial numbers in a list.

[0009] Advantageously, the sensor can have a unique ID, which comprises a unique serial number of it within the range of serial numbers of the sensor. By means of the ID of the sensor, the sensor can be assigned to the respective entry in the list of sensor keys.

[0010] Preferably, the range of serial numbers of the sensor can be assigned to the manufacturer of the sensor in the process of licensing by the central location. For example, the central location sells a license for a range of serial numbers of the sensor to the manufacturer of the sensor. Sensors whose serial numbers fall within this range of serial numbers of the sensor can be registered in accordance with the method for licensing a sensor at a central location according to the application and are therefore allowed to be commissioned and used accordingly.

[0011] The application claims and claims jointly a method for licensing a receiver at a central location, wherein the method comprises the receiver, the central location (comprising a computer system and a database) and the manufacturer of the receiver (comprising a computer system), wherein there is a data connection between the manufacturer of the receiver and the central location, in particular in connection with the method according to the application, wherein it is characterized in that a third key pair consisting of a private key and a public key is generated at the manufacturer of the receiver, the public key of the third key pair is transmitted from the manufacturer of the receiver to the central location, a range of serial numbers of the receiver is assigned to the third key pair, a fourth key pair consisting of a private key and a public key is generated at the central location, the public key of the fourth key pair is transmitted from the central location to the manufacturer of the receiver, a range of serial numbers of the receiver is assigned to the fourth key pair, the manufacturer of the receiver stores the private key of the third key pair and the public key of the fourth key pair in the receiver.

[0012] In the method for licensing a receiver according to the application, advantageously only the public keys of the key pairs are exchanged between the manufacturer of the receiver and the central location. Thereby, the method for licensing a receiver is likewise particularly secure, since even if the public keys are intercepted or intercepted during transmission by a third party, these intercepted public keys are not sufficient to decrypt the encrypted transmission key.

[0013] Suitably, a list of receiver keys can be saved in the database of the central location, wherein the public key of the third key pair, the private key of the fourth key pair and the assigned range of serial numbers of the receiver are stored in the list of receiver keys in the central location. The method for licensing a receiver is not limited to a single receiver, so that a plurality of receivers can be registered at the central location. If a plurality of receivers is licensed at the central location, it is advantageous to save the respective keys and the assigned range of serial numbers in the list.

[0014] Advantageously, the receiver can have a unique ID, which comprises a unique serial number of it within the range of serial numbers of the receiver. By means of the ID of the receiver, the receiver can be assigned to the respective entry in the list of receiver keys.

[0015] Preferably, the range of serial numbers of the receiver can be assigned to the manufacturer of the receiver in the process of licensing by the central location. For example, the central location can sell a license for a range of serial numbers of the receiver to the manufacturer of the receiver. Receivers whose serial numbers fall within this range of serial numbers of the receiver can be registered in accordance with the method for licensing a receiver at a central location according to the application and are thus allowed to be commissioned and used.

[0016] The application also claims protection for a method for providing a list of sensor keys by a central location, preferably in combination with the method for licensing sensors according to the application and the method for licensing receivers according to the application, wherein it is characterized in that the central location encrypts the list of sensor keys with the public key of a third key pair and the private key of a fourth key pair. The list of sensor keys can thus be obtained by the central location. However, the list of sensor keys can only be decrypted by parties having the respective keys. Receivers licensed according to the method for licensing receivers at a central location according to the application can for example decrypt the encrypted list of sensor keys. In the list of sensor keys are entries of sensors which are for example licensed according to the method for licensing sensors at a central location according to the application.

[0017] It is particularly advantageous if the central location encrypts the list of sensor keys with the public key of a third key pair and the private key of a fourth key pair for each receiver whose key is stored in the list of receiver keys. Since the method for licensing receivers is not limited to a single receiver, the list of sensor keys can advantageously be encrypted for each licensed receiver, for example licensed according to the method for licensing receivers at a central location according to the application. Thus, all licensed receivers can be enabled to decrypt the encrypted list of sensor keys and extract the respective sensor keys. On the other hand, all unlicensed receivers can thereby also be excluded from access to the sensor keys.

[0018] Advantageously, the central location can publish the list of sensor keys. As soon as multiple receivers are licensed, the list of sensor keys can be encrypted with the respective receiver keys and published in multiple versions encrypted with different receiver keys.

[0019] Furthermore, there is the possibility of signing the list of sensor keys by an authentication location. An authentication location (CA, Certificate Authority) is an authority that issues digital certificates. A digital certificate proves the ownership of a public key by the mentioned subject of the certificate. This enables other (trusted parties) to trust the signature or the statement that the private key corresponds to the authenticated public key. The authentication location acts as a trusted third party that trusts the party (owner) of the certificate as well as the party of the certificate.

[0020] Furthermore, the application claims a method for registering a licensed sensor, in particular a sensor licensed according to the application, at a licensed receiver, in particular a receiver licensed according to the application, with inclusion of a central location, wherein the method comprises a sensor, a receiver and a central location, comprising a computer system and a database, wherein a data connection exists between the sensor and the receiver and a data connection exists between the receiver and the central location, wherein it is provided that a list of sensor keys according to the application is made available, wherein the receiver obtains the list of sensor keys from the central location, the receiver decrypts the list of sensor keys by means of the private key of a third key pair and the public key of a fourth key pair, the sensor transmits the stored encrypted transmission key to the receiver, the receiver extracts the public key of a first key pair and the private key of a second key pair corresponding to the sensor from the list of sensor keys, and the receiver decrypts the encrypted transmission key by means of the public key of the first key pair and the private key of the second key pair.

[0021] According to the method for registering a licensed sensor at a licensed receiver according to the application, it is thus possible, on the one hand, for only licensed sensors to be registered on the receiver and, on the other hand, for only licensed receivers to be able to perform the registration of the sensors. It is thus ensured that only licensed receivers have access to the keys of the sensors that are licensed again.

[0022] Advantageously, the sensor can send its ID to the receiver, wherein the receiver extracts the key assigned to the range of serial numbers of the sensor from the list of sensor keys according to the serial number contained in the ID.

[0023] It is particularly advantageous if the sensor sends data encrypted with the transmission key to the receiver and the receiver decrypts the encrypted data by means of the transmission key. By registering the sensor at the receiver, the receiver is able to decrypt the transmitted sensor data by means of the decrypted transmission key.

[0024] Advantageously, the transmission key for the data transmission between the sensor and the receiver can describe a symmetric encryption method. A symmetric key can be used for the transmission of data between the sensor and the receiver.

[0025] Preferably, the ID of the sensor and / or the ID of the receiver can be a MAC address. The ID can thus for example be based on the EUI-64 standard (64-bit Extended Unique Identifier). For example, the first 24 bits can identify the manufacturer. For example, the first 48 bits or 56 bits can identify a range of serial numbers for the sensor and / or a range of serial numbers for the receiver. For example, the last 16 bits or 8 bits can identify a serial number of the sensor and / or a serial number of the receiver. Thus, the range of serial numbers of the sensor can advantageously be determined from the ID or MAC address of the sensor and / or the range of serial numbers of the receiver can be determined from the ID or MAC address of the receiver.

[0026] It is particularly expedient if the first key pair and / or the second key pair and / or the third key pair and / or the fourth key pair describe an asymmetric encryption method. Furthermore, there is the possibility that the public key and the private key belonging to each key pair are respectively distributed independently of one another in reverse. Thus, the respective private key can be the public key and the respective public key can be the private key.

[0027] For the generation of the first key pair and / or the second key pair and / or the third key pair and / or the fourth key pair, a random number can be used. For example, a random number can be generated which forms the private key of the respective key pair and is used accordingly for the generation of the respective public key.

[0028] Thus, the transmission key itself can be a symmetric key which is encrypted with an asymmetric key when it is transmitted between the sensor and the receiver. Furthermore, the key for decrypting the encrypted transmission key can again be transmitted encrypted. In this case, the key for decryption can be stored in a list of sensor keys which is again encrypted. The list of sensor keys is transmitted encrypted between the central location and the receiver. This encryption can also be an asymmetric encryption method.

[0029] Advantageously, the MAC address of the sensor and / or a part of the MAC address can be used to generate the second key pair and / or the MAC address of the receiver and / or a part of the MAC address can be used to generate the fourth key pair. Thus, bits of the MAC address which for example identify a range of serial numbers for the sensor or a range of serial numbers for the receiver can be used to generate the second or fourth key pair. This can for example be the first 48 bits or 56 bits of the MAC address according to the EUI-64 standard. Thus, in the course of the authorization of the sensor or the receiver, a range of serial numbers can be assigned in accordance with the respective MAC address, wherein the respective key is generated by means of these MAC addresses or parts of the MAC address. For example, the MAC address or the part of the MAC address can be used to generate a key in accordance with an asymmetric encryption method such as elliptic curve cryptography.

[0030] Furthermore, the application claims in conjunction a system for the transmission of data from a licensed sensor, in particular a sensor licensed according to the application, to a licensed receiver, in particular a receiver licensed according to the application, with the inclusion of a central location, wherein the system comprises a sensor, a receiver and a central location (comprising a computer system and a database), wherein there is a data connection between the sensor and the receiver and a data connection between the receiver and the central location, which transmits sensor data encrypted with the transmission key to the receiver, which decrypts the data by means of the transmission key, wherein it is characterized that the transmission key is transferred from the sensor to the receiver in the registration process of the sensor at the receiver, in particular according to the method according to the application in the registration process of the sensor at the receiver, in particular according to the application.

[0031] Thus, with the method and the system it is possible to implement the licensing of the sensor and the receiver, wherein, in the same process, it is also possible to ensure the secure transfer of the transmission key for the communication or data exchange between the sensor and the receiver. Thus, the transmission key can advantageously always be transmitted encrypted and there is no necessity for the transmission key to be transmitted unencrypted as plain text. Furthermore, with the secure transfer of the transmission key, the application advantageously enables the establishment of a licensing model for the sensor and the receiver. The coordination between the sensor and the receiver for the authentication of the license is dispensed with, whereby the method according to the application and the system according to the application also function in one-way communication from the sensor to the receiver. BRIEF DESCRIPTION OF DRAWINGS

[0032] A suitable design of the application is explained in more detail below with the aid of the drawings. Shown are:

[0033] Figure 1 Highly simplified schematic diagram showing the licensing of a sensor at a central location;

[0034] Figure 2 Highly simplified schematic diagram showing the licensing of a receiver at a central location and the provision of a list of sensor keys;

[0035] Figure 3 Highly simplified schematic diagram showing the registration of a licensed sensor at a licensed receiver;

[0036] Figure 4 Highly simplified schematic diagram showing a list of sensor keys; and

[0037] Figure 5a - b shows the division of the MAC address into the range of the serial number. DETAILED DESCRIPTION

[0038] In Figure 1A highly simplified schematic diagram shows the licensing of a sensor (S) at a central location (Z). The manufacturer of the sensor (HS) generates a first key pair (SP1) in a first step, which consists of a private key (SP1-P) and a public key (SP1-O). The public key (SP1-O) of the first key pair (SP1) is transmitted by the manufacturer of the sensor (HS) to the central location (Z). The manufacturer of the sensor (HS) purchases from the central location (Z) a license for a range of serial numbers (SNS) for the sensor. The central location (Z) generates a second key pair (SP2) from the purchased range of serial numbers (SNS) for the sensor. Here, the first 48 bits of the MAC address of the sensor (S) define a group, for which the second key pair (SP2) is valid. Next, the public key (SP2-O) of the second key pair (SP2) is transmitted from the central location (Z) to the manufacturer of the sensor (HS). The central location (Z) then stores the public key (SP1-O) of the first key pair (SP1), the private key (SP2-P) of the second key pair (SP2) and the assigned range of serial numbers (SNS) of the sensor in a list (LSS) of sensor keys. The manufacturer of the sensor (HS) encrypts a transmission key (U) for data transmission between the sensor (S) and a receiver (E) with the private key (SP1-P) of the first key pair (SP1) and the public key (SP2-0) of the second key pair (SP2) and stores the encrypted transmission key (U) in the sensor (S).

[0039] In Figure 2 A highly simplified schematic diagram shows the licensing of a receiver at a central location and the provision of a list of sensor keys. In a head-end system (HE), a third key pair (SP3) is generated, which consists of a private key (SP3-P) and a public key (SP3-O). The public key (SP3-O) of the third key pair (SP3) is transmitted by the manufacturer of the receiver (HE) to the central location (Z). The manufacturer of the receiver (HE) purchases from the central location (Z) a license for a range of serial numbers (SNE) for the receiver. The central location (Z) generates a fourth key pair (SP4) from the purchased range of serial numbers (SNE) for the receiver. Here, the first 56 bits of the MAC address of the receiver (E) define a group, for which the fourth key pair (SP4) is valid. Next, the public key (SP4-O) of the fourth key pair (SP4) is transmitted from the central location (Z) to the manufacturer of the receiver (HE). The manufacturer of the receiver (HE) stores the private key (SP3-P) of the third key pair (SP3) and the public key (SP4-O) of the fourth key pair (SP4) in the receiver (E). The list of sensor keys (LSS) is encrypted with the public key (SP3-O) of the third key pair (SP3) and the private key (SP4-P) of the fourth key pair (SP4), signed by the authentication location and published.

[0040] In Figure 3 The registration of a licensed sensor (S) at a licensed receiver (E) is shown in a highly simplified schematic in Fig. 1. In a first step, the receiver (E) obtains an encrypted list (LSS) of sensor keys from a central location (Z). The receiver (E) decrypts the list (LSS) of sensor keys by the private key (SP3-P) of the third key pair (SP3) and the public key (SP4-O) of the fourth key pair (SP4). Then, the sensor (S) transmits the ID of this sensor and an encrypted transmission key (U) to the receiver (E). The receiver (E) extracts the public key (SP1-O) of the first key pair (SP1) and the private key (SP2-P) of the second key pair (SP2) corresponding to the sensor (S) from the list (LSS) of sensor keys according to the ID. The receiver (E) decrypts the encrypted transmission key (U) by the public key (SP1-O) of the first key pair (SP1) and the private key (SP2-P) of the second key pair (SP2). By the transmission key (U), the receiver (E) can decrypt encrypted data sent by the sensor (S).

[0041] In Figure 4 A highly simplified schematic of the list (LSS) of sensor keys is shown in Fig. 2. For a plurality of sensors (A-NC), the respective public key (SP1-O) of the first key pair (SP1) and the private key (SP2-P) corresponding to a range (I-X) of serial numbers (SNS) of sensors are stored in the list (LSS) of sensor keys. Thus, the serial numbers of the sensors (A-C) are in the range (I) of serial numbers (SNS) of sensors. The second key pair (SP2) for this range is identical for these sensors (A-C) in this range. Thus, the private key (SP2-P-I) of the second key pair (SP2) is stored for each of the sensors (A-C). Similarly, the serial numbers of sensors (AA-AC) are in the range (II) of serial numbers (SNS) of sensors, and the serial numbers of sensors (NA-NC) are in the range (X) of serial numbers (SNS) of sensors. The list (LSS) of sensor keys is extended by one entry for each licensed sensor (S).

[0042] Figure 5a - b shows the division of MAC addresses into ranges of serial numbers. According to the EUI-64 standard, a MAC address has a length of 64 bits. The MAC address is divided into three ranges: the range MM represents the manufacturer, the range GG represents the group, and the range SS represents the serial number. Figure 5a The MAC address in Fig. 3 has a prefix consisting of the 48-bit manufacturer range (MM) and the group range (GG). The serial number range (SS) has a length of 16 bits and thus defines 2 16= range of serial numbers (SNS) of sensors (S) of 65536 sensors (S). For this range of serial numbers (SNS) of sensors, one license can be sold from the central location (Z). The second key pair (SP2) can be defined, for example, by this prefix.

[0043] Figure 5b The MAC address in has a prefix, which is composed of a manufacturer range (MM) of 56 bits and a group range (GG).

[0044] The serial number range (SS) has a length of 8 bits and thus defines a range of 2 8 = range of serial numbers (SNE) of receivers (E) of 256 receivers (E). For this range of serial numbers (SNE) of receivers, one license can be sold from the central location (Z). The fourth key pair (SP4) can be defined, for example, by this prefix.

[0045] List of reference signs

[0046] s sensor

[0047] E receiver

[0048] Z central location

[0049] HS manufacturer of sensors

[0050] HE manufacturer of receivers

[0051] SP key pair

[0052] LSS list of sensor keys

[0053] LES list of receiver keys

[0054] SNS range of serial numbers of sensors

[0055] SNE range of serial numbers of receivers

[0056] U transmission key

[0057] P private

[0058] 0 public

[0059] MM manufacturer

[0060] GG group

[0061] SS serial number

Claims

1. A method for permitting a sensor (S) at a central position (Z), comprising: The sensor (S), The central location (Z) includes the computer system and database. The sensor manufacturer (HS) includes computer systems, wherein, A data connection exists between the sensor manufacturer (HS) and the central location (Z). Its features are, A list of sensor keys (LSS) is stored in the database at the central location (Z), wherein, A first key pair (SP1) is generated at the sensor manufacturer (HS), the first key pair consisting of a private key (SP1-P) and a public key (SP1-O). The public key (SP1-O) of the first key pair (SP1) is transmitted from the sensor manufacturer (HS) to the central location (Z). Assign a range of serial numbers (SNS) for the sensor to the first key pair (SP1). A second key pair (SP2) is generated at the central position (Z). The second key pair consists of a private key (SP2-P) and a public key (SP2-O). The public key (SP2-O) of the second key pair (SP2) is transmitted from the central location (Z) to the sensor manufacturer (HS). Configure the second key pair (SP2) with a range for the serial number (SNS) of the sensor. The public key (SP1-O) of the first key pair (SP1), the private key (SP2-P) of the second key pair (SP2), and the configured range for the serial number (SNS) of the sensor are stored in the sensor key list (LSS) at a central position (Z). The sensor manufacturer (HS) uses the private key (SP1-P) of the first key pair (SP1) and the public key (SP2-O) of the second key pair (SP2) to encrypt a transmission key (U) for data transmission between the sensor (S) and the receiver (E), and stores the encrypted transmission key (U) in the sensor (S). The sensor manufacturer (HS) stores the private key (SP1-P) of the first key pair (SP1) and the public key (SP2-O) of the second key pair (SP2) in the sensor (S), or The transmission key (U) is stored unencrypted.

2. The method according to claim 1, characterized in that, The sensor (S) has a unique ID, which includes its unique serial number, which is within the range of serial numbers (SNS) used for the sensor.

3. The method according to claim 1 or 2, characterized in that, The ID of the sensor (S) is its MAC address.

4. The method according to claim 1 or 2, characterized in that, The range of serial numbers (SNS) for the sensor is determined by the ID of the sensor (S).

5. The method according to claim 1 or 2, characterized in that, During the authorization process by the central location (Z), a range of serial numbers (SNS) for the sensor is assigned to the sensor manufacturer (HS).

6. A method for registering a licensed sensor (S) at a licensed receiver (E) with a central location (Z), the method comprising: The sensor (S), The receiver (E), The central location (Z) includes a computer system and a database, wherein, There is a data connection between the sensor (S) and the receiver (E), and A data connection exists between the receiver (E) and the central location (Z). Wherein, the sensor (S) is licensed according to the method for licensing the sensor (S) at a central position (Z) according to any one of claims 1 to 5, and the receiver is licensed according to the method for licensing the receiver (E) at the central position (Z), the method for licensing the receiver (E) at the central position (Z) comprising: A third key pair (SP3) is generated at the receiver manufacturer (HE), consisting of a private key (SP3-P) and a public key (SP3-O). The public key (SP3-O) of the third key pair (SP3) is transmitted from the receiver manufacturer (HE) to the central location (Z). Configure the third key pair (SP3) with a range of serial numbers (SNE) for the receiver. A fourth key pair (SP4) is generated at the central position (Z), the fourth key pair consisting of a private key (SP4-P) and a public key (SP4-O). The public key (SP4-O) of the fourth key pair (SP4) is transmitted from the central location (Z) to the receiver manufacturer (HE). Configure the fourth key pair (SP4) with a range of serial numbers (SNE) for the receiver. The manufacturer (HE) of the receiver stores the private key (SP3-P) of the third key pair (SP3) and the public key (SP4-O) of the fourth key pair (SP4) in the receiver (E). Its features are, The central location (Z) uses the public key (SP3-O) of the third key pair (SP3) and the private key (SP4-P) of the fourth key pair (SP4) to encrypt the list of sensor keys (LSS), wherein, The receiver (E) obtains the list (LSS) of sensor keys from the central location (Z). The receiver (E) decrypts the list of sensor keys (LSS) using the private key (SP3-P) of the third key pair (SP3) and the public key (SP4-O) of the fourth key pair (SP4). The sensor (S) transmits the stored encrypted transmission key (U) to the receiver (E). The receiver (E) extracts the public key (SP1-O) of the first key pair (SP1) corresponding to the sensor (S) and the private key (SP2-P) of the second key pair (SP2) from the list of sensor keys (LSS). The receiver (E) decrypts the encrypted transmission key (U) using the public key (SP1-O) of the first key pair (SP1) and the private key (SP2-P) of the second key pair (SP2).

7. The method according to claim 6, characterized in that, The sensor (S) sends the sensor ID to the receiver (E), wherein the receiver (E) extracts a key from the list of sensor keys (LSS) that is assigned to the range of serial numbers (SNS) used for the sensor, based on the serial number contained in the ID.

8. The method according to claim 6 or 7, characterized in that, The sensor (S) transmits data encrypted using the transmission key (U) to the receiver, and the receiver (E) decrypts the encrypted data using the transmission key (U).

9. The method according to claim 6 or 7, characterized in that, The transmission key (U) describes a symmetric encryption method.

10. The method according to claim 6 or 7, characterized in that, The first key pair (SP1) and / or the second key pair (SP2) and / or the third key pair (SP3) and / or the fourth key pair (SP4) describe an asymmetric encryption method.

11. The method according to claim 6 or 7, characterized in that, The MAC address and / or a portion thereof of the sensor (S) are used to generate the second key pair (SP2), and / or the MAC address and / or a portion thereof of the receiver (E) are used to generate the fourth key pair (SP4).

12. The method according to claim 6 or 7, characterized in that, A list of receiver keys (LES) is stored in the database at the central location (Z), wherein the public key (SP3-O) of the third key pair (SP3), the private key (SP4-P) of the fourth key pair (SP4), and the configured range of the serial number (SNE) for the receiver are stored in the list of receiver keys (LES) at the central location (Z).

13. The method according to claim 6 or 7, characterized in that, The receiver (E) has a unique ID, which includes its unique serial number, which is within the range of serial numbers (SNE) used for receivers.

14. The method according to claim 6 or 7, characterized in that, During the authorization process by the central location (Z), a range of serial numbers (SNE) for the receiver is assigned to the receiver's manufacturer (HE).

15. The method according to claim 13, characterized in that, The ID of the receiver (E) is its MAC address.

16. The method according to claim 13, characterized in that, The range of serial numbers (SNE) for the receiver is determined by the ID of the receiver (S).

17. The method according to claim 6 or 7, characterized in that, The central location (Z) uses the public key (SP3-O) of the third key pair (SP3) and the private key (SP4-P) of the fourth key pair (SP4) of each receiver (E) to encrypt the list of sensor keys (LSS), and the receiver keys are stored in the list of receiver keys (LES).

18. The method according to claim 6 or 7, characterized in that, The central location (Z) discloses the list (LSS) of the sensor keys.

19. The method according to claim 6 or 7, characterized in that, The list of sensor keys (LSS) is signed by the authentication location.

20. A system for transmitting data from a licensed sensor (S) to a licensed receiver (E) at a central position (Z), wherein the sensor (S) is licensed according to the method for licensing the sensor (S) at the central position (Z) according to any one of claims 1 to 5, the system comprising: The sensor (S), The receiver (E), The central location (Z) includes a computer system and a database, wherein, There is a data connection between the sensor (S) and the receiver (E), and A data connection exists between the receiver (E) and the central location (Z). The sensor (S) transmits data encrypted using the transmission key (U) to the receiver (E). The receiver (E) decrypts the data using the transmission key (U). Its features are, The method for registering a licensed sensor (S) at a licensed receiver (E) in the presence of a central location (Z) according to any one of claims 6 to 8, wherein during the registration of the sensor (S) at the receiver (E), the sensor (S) transmits the transmission key (U) to the receiver (E).

Citation Information

Patent Citations

  • Data protection

    GB2570292A

  • Licensing apparatus and method for automatically granting user licenses to sensors

    WO2010026012A1