A configuration control device and method for configuring an electronic device
By configuring the coupling between the control device and the configuration device server, the configuration application code is securely provided and stored, solving the security problem of security-sensitive configuration data in the production process of electronic devices, and realizing secure configuration and data integrity protection of electronic devices.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SAFETY ARTICLES LTD
- Filing Date
- 2022-03-16
- Publication Date
- 2026-05-12
AI Technical Summary
In the existing technology, during the production and assembly of electronic devices, the security-sensitive configuration data of electronic chips or microprocessors are manufactured and configured by different parties in different locations, making it difficult to guarantee security.
The configuration control device is coupled to the configuration device server, and the configuration application code is securely provided through the communication interface and executed by the processor. This ensures that security-sensitive configuration data is stored in the non-volatile memory of the electronic device, including the use of hardware security enclaves and encryption processing.
Secure configuration of electronic devices is implemented to prevent replay attacks, ensure the security and integrity of configuration data, and disable debugging functions to protect key storage.
Smart Images

Figure CN115114629B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the safe production and configuration of electronic devices or electronic device components. More specifically, this invention relates to an apparatus and method for configuring electronic devices or electronic device components. Background Technology
[0002] The production and assembly of state-of-the-art electronic devices (such as smartphones, tablets, and other types of consumer electronics or IoT devices) are typically carried out in a distributed manner because electronic components, including the electronic chips or microprocessors of consumer electronics devices, are manufactured, configured, or personalized and ultimately assembled by different parties at different locations. For example, the electronic chips or microprocessors used in an electronic device may initially be manufactured by a chip manufacturer, with security-sensitive configuration data, such as encryption keys and / or firmware, provided by another party, and then assembled into the finished product by the manufacturer of the electronic device (such as an original equipment manufacturer). A similar issue may arise in in-system programming (ISP), also known as in-circuit serial programming (ICSP), where electronic components can be programmed while they are already installed in the electronic device, i.e., with security-sensitive configuration data provided, rather than requiring programming of the electronic components (such as chips) before they are installed in the electronic device.
[0003] Therefore, there is a need for devices and methods for safely providing electronic devices or components (such as chips or microprocessors) for electronic devices. Summary of the Invention
[0004] Therefore, one object of the present invention is to provide devices and methods that allow for the secure provision of electronic devices or components (e.g., chips or microprocessors) for electronic devices.
[0005] The foregoing and other objectives are apparent from the disclosure and accompanying drawings of this application.
[0006] According to the first aspect, a configuration control device is used to couple with a configuration device server, wherein the configuration device server may be electrically connected to at least one electronic device or component to configure the electronic device using security-sensitive configuration data. The electronic device includes a processor, volatile memory (e.g., RAM), and non-volatile memory (e.g., flash memory). The electronic device may be a component to be installed or already installed in an electronic finished product.
[0007] The configuration control device includes a communication interface for securely providing configuration application code to a configuration device server for storing the configuration application code in the volatile memory of the electronic device.
[0008] Furthermore, the configuration control device includes a processor that triggers (i.e., instructs) the processor of the electronic components to execute configuration application code stored in the volatile memory of the electronic device. The configuration application code stores security-sensitive configuration data in the secure portion of the non-volatile memory of the electronic device when executed by the processor.
[0009] In one embodiment, the communication interface is also used to receive configuration application code from a remote server.
[0010] In one embodiment, the communication interface is further configured to receive configuration application code from a remote server in encrypted form, wherein the processor is configured to decrypt the encrypted configuration application code.
[0011] In one embodiment, the processor of the configuration control device is used to generate configuration application code.
[0012] In one embodiment, the processor of the configuration control device is used to include security-sensitive configuration data in the configuration application code.
[0013] In one embodiment, the configuration application code is configured to, when executed, instruct the processor of the electronic device to remove the configuration application code from the volatile memory of the electronic device.
[0014] In one embodiment, security-sensitive configuration data includes electronic keys, electronic key certificates, and / or configuration data, particularly one or more register settings of the processor of the electronic device.
[0015] In one embodiment, the electronic device further includes a hardware security enclave, wherein configuration application code, when executed, stores at least a portion of security-sensitive configuration data in the hardware security enclave of the electronic device. It can also set an initial configuration for the hardware security enclave. In a further embodiment, the hardware security enclave may be a separate physical device permanently connected to the electronic device.
[0016] In one embodiment, the configuration application code includes at least a portion of security-sensitive configuration data to be stored in the security portion of the non-volatile memory of the electronic device. In other words, at least a portion of the security-sensitive configuration data can be hard-coded into the configuration application code.
[0017] In one embodiment, the communication interface is further configured to provide at least a portion (e.g., a tabular portion) of the security-sensitive configuration data to the configuration device server in a manner separate from the configuration application code, so as to store the at least portion of the security-sensitive configuration data in the volatile memory of the electronic device in a manner separate from the configuration application code. The configuration application code may be configured, when executed, to retrieve the at least portion (e.g., the table) of the security-sensitive configuration data from the volatile memory of the electronic device and store the at least portion of the security-sensitive configuration data in the non-volatile memory of the electronic device.
[0018] In one embodiment, when executed, the configuration application code is used to establish a secure communication channel between the configuration control device and the electronic device, wherein the communication interface is used to provide at least a portion of security-sensitive configuration data to the electronic device through the secure communication channel, such that the at least a portion of the security-sensitive configuration data is stored in a secure portion of the non-volatile memory of the electronic device.
[0019] In one embodiment, the processor is configured to generate at least a portion of security-sensitive configuration data, which is provided to an electronic device via a secure communication channel, such that the at least a portion of the security-sensitive configuration data is stored in a secure portion of the non-volatile memory of the electronic device.
[0020] In one embodiment, the communication interface is used to provide at least a portion of the security-sensitive configuration data, along with one or more random current values, to an electronic device via a secure communication channel to avoid replay attacks.
[0021] In one embodiment, the electronic device further includes a random number generator, particularly a hardware random number generator, wherein, when executed, configuration application code is used to generate at least a portion of security-sensitive configuration data, particularly one or more electronic keys, based on one or more seed values using the random number generator.
[0022] In one embodiment, the configuration application code includes one or more seed values. Additionally or alternatively, when executed, the configuration application code may be used to obtain one or more seed values from a configuration control device.
[0023] In one embodiment, when executed, the configuration application code stores security-sensitive configuration data in a predefined secure portion of the electronic device's non-volatile memory.
[0024] In one embodiment, when executed, the configuration application code is used to provide the configuration control device with information (i.e., metadata) about the storage location of security-sensitive configuration data in the non-volatile memory of the electronic device, wherein the communication interface is used to provide the configuration device server with information about the storage location of security-sensitive configuration data in the non-volatile memory of the electronic device, so as to store information about the storage location of security-sensitive configuration data in the non-volatile memory of the electronic device.
[0025] In one embodiment, when executed, the configuration application code stores information about the location of security-sensitive configuration data in the non-volatile memory of the electronic device in a predefined portion of the non-volatile memory of the electronic device.
[0026] In one embodiment, the communication interface is also used to receive information about the status or results of configuration application code executed by the processor of the electronic device.
[0027] In one embodiment, when executed, configuration application code is used to generate a public-private key pair for generating at least a portion of security-sensitive configuration data, wherein a communication interface is used to receive the public key from the public-private key pair from an electronic device.
[0028] In one embodiment, the processor is further configured to generate a key certificate based on the public key in the public-private key pair, wherein the communication interface is configured to provide the key certificate to a configuration device server for storing the key certificate in the non-volatile memory of the electronic device.
[0029] In one embodiment, when executed, the processing application code is also used to disable or restrict the functionality of one or more hardware components of the electronic device, particularly the debugging functionality of the electronic device's communication interface. Disabling or restricting the debugging functionality of the electronic device allows the key to be stored in a secure area of memory. This is because debugging functions typically have access to all memory portions, so once the device reaches production quality, the debugging functionality that accesses the key must be disabled. For example, this restriction on debugging can be achieved by using a secret password that is only provided to authorized debuggers.
[0030] According to a second aspect, a configuration system is provided, including a configuration control device according to a first aspect and a configuration device server, the configuration device server being electrically connected to at least one electronic device to configure the electronic device using security-sensitive configuration data.
[0031] According to a third aspect, a method is provided for configuring at least one electronic device using security-sensitive configuration data via a configuration control device coupled to a configuration device server, the configuration device server being electrically connected to the electronic device, the electronic device including a processor, volatile memory, and non-volatile memory, wherein the method includes:
[0032] Securely provide the configuration application code to the configuration device server, and store the configuration application code in the volatile memory of the electronic device; and
[0033] The processor of the electronic device is triggered to execute configuration application code, which, when executed by the processor of the electronic device, stores security-sensitive configuration data in the non-volatile memory of the electronic device.
[0034] The configuration method according to the third aspect of the invention can be executed by the configuration control device according to the first aspect of the invention. Further features of the configuration method according to the third aspect of the invention arise directly from the functionality of the configuration control device according to the first aspect of the invention and its various embodiments described above and below.
[0035] Embodiments of the present invention can be implemented in hardware and / or software. Attached Figure Description
[0036] Other embodiments of the invention will be described with reference to the following figures, in which:
[0037] Figure 1 A schematic diagram of a configuration system including a configuration control device according to an embodiment of the present invention is shown;
[0038] Figure 2 A schematic diagram of an exemplary architecture of electronic components configured in a configuration control device according to an embodiment is shown in more detail; and
[0039] Figure 3 A flowchart illustrating the steps of a configuration method according to an embodiment of the present invention is shown.
[0040] In the accompanying drawings, the same reference numerals will be used for the same or at least functionally equivalent features. Detailed Implementation
[0041] In the following detailed description, reference is made to the accompanying drawings, which form a part of this disclosure, and which illustrate, by way of illustration, specific aspects in which the invention may be practiced. It will be understood that other aspects may be utilized and structural or logical changes may be made without departing from the scope of the invention. Therefore, the following detailed description should not be construed as limiting, as the scope of the invention is defined by the appended claims.
[0042] For example, it can be understood that the disclosures related to the described method can also be applied to a corresponding device or system configured to perform the method, and vice versa. For example, if specific method steps are described, the corresponding device may include a unit for performing the described method steps, even if the unit is not explicitly described or illustrated in the figures. Furthermore, it should be understood that features of the various exemplary aspects described herein can be combined with each other unless otherwise specifically indicated.
[0043] Figure 1 A schematic diagram of a configuration system 100 according to an embodiment of the present invention is shown, including a configuration control device 140 according to an embodiment of the present invention. As will be described in more detail below, in addition to including the configuration control device 140, the configuration system 100 may also include a remote server 110, a security server 120, and a configuration device server 160, the configuration device server 160 being used to configure or personalize electronic devices or their components 170, such as chips or microprocessors 170 having security-sensitive configuration data (e.g., electronic keys, certificates, and / or configuration data). Figure 1 As shown, the configuration control device 140, remote server 110, and security server 120 can communicate with each other via a communication network (such as the Internet). Therefore, the configuration control device 140, remote server 110, and security server 120 can be located in different locations and controlled by different parties. Figure 1 As shown, configuration control device 140 and configuration device server 160 may be located within production environment 130 (e.g., customization factory 130). In one embodiment, remote server 110 may be controlled or associated with an electronics manufacturer (e.g., original equipment manufacturer) that assembles electronics devices (e.g., smartphones, tablets, or other types of IoT or consumer electronics devices) that employ electronics devices or components 170 for which security-sensitive configuration data is provided by configuration device server 160.
[0044] In one embodiment, the configuration control device 140, the remote server 110, and the security server 120 are used to securely communicate with each other using one or more cryptographic schemes (e.g., public key infrastructure and / or hybrid cryptographic schemes). In one embodiment, the configuration control device 140 may be remotely controlled by the security server 120.
[0045] Configuration control device 140 is used to couple with configuration device server 160 (e.g., via a wired or wireless connection). In one embodiment, configuration device server 160 may be implemented as a personal computer, and configuration control device 140 may be implemented as a PC card inserted into configuration device server 160. Configuration device server 160 may include electrical and / or mechanical interfaces for direct or indirect interaction with electronic devices or components 170 via configuration devices. For example, configuration device server 160 may include a personalization tray for personalizing a batch of electronic devices or components 170 inserted therein.
[0046] exist Figure 1 In the illustrated embodiment, the configuration control device 140 includes a processor 141, a communication interface 143, and a non-transient memory 145. These will be further referenced below. Figure 2 In more detail, the communication interface 143 of the configuration control device 140 is used to securely provide configuration application code 150 to the configuration device server 160 for storing the configuration application code 150 in the volatile memory (e.g., RAM 175) of the electronic device 170. Furthermore, the processor 141 of the configuration control device 140 is used to trigger the processor 171 of the electronic device 170 to execute the configuration application code 150, wherein the configuration application code 150, when executed by the processor 171 of the electronic device 170, stores security-sensitive configuration data in the non-volatile memory (e.g., flash memory 177) of the electronic device 170.
[0047] In one embodiment, the communication interface 143 of the configuration control device 140 is also used to receive configuration application code 150 from the remote security server 120.
[0048] In one embodiment, the communication interface 143 of the configuration control device 140 is further configured to receive configuration application code 150 from the remote security server 120 in encrypted form, wherein the processor 141 of the configuration control device 140 is configured to decrypt the encrypted configuration application code 150.
[0049] In one embodiment, the processor 141 of the configuration control device 140 is used to generate at least a portion of the configuration application code 150.
[0050] In one embodiment, the processor 141 of the configuration control device 140 is used to include security-sensitive configuration data in the configuration application code 150.
[0051] In one embodiment, configuration application code 150 is used to instruct the processor 171 of electronic device 170 to remove configuration application code 150 from volatile memory 175 of electronic device 170 when executed. For example, configuration application code 150 can be removed from volatile memory 175 of electronic device 170 by simply turning off electronic device 170, or it can modify itself after completion so that it cannot be accidentally executed a second time (and then disappear when RAM 175 is removed).
[0052] In one embodiment, security-sensitive configuration data includes electronic keys, electronic key certificates, and / or configuration data, particularly register settings.
[0053] In one embodiment, such as Figure 2 As shown, electronic device 170 also includes a hardware security enclave 173. The hardware security enclave 173 of electronic device 170 may include or be similar to a security enclave processor disclosed in US 8,832,465, which is fully incorporated herein by reference. Configuration application code 150 is configured, when executed, to store at least a portion of security-sensitive configuration data in the hardware security enclave 173 of electronic device 170. This may include the initial configuration of the security enclave 173. In a further embodiment, the hardware security enclave 173 may be a separate physical device connected to electronic device 170.
[0054] In one embodiment, the configuration application code includes at least a portion of security-sensitive configuration data to be stored in the non-volatile memory of the electronic device.
[0055] In one embodiment, the communication interface 143 of the configuration control device 140 is further configured to provide at least a portion of the security-sensitive configuration data to the configuration device server in a manner separate from the configuration application code, so as to store the at least a portion of the security-sensitive configuration data in the volatile memory 175 of the electronic device 170 in a manner separate from the configuration application code 150, and the configuration application code 150 is configured to, when executed, obtain the at least a portion of the security-sensitive configuration data from the volatile memory 175 of the electronic device 170 and store the at least a portion of the security-sensitive configuration data in the non-volatile memory 177 of the electronic device 170.
[0056] In one embodiment, when executed, configuration application code 150 is used to establish a secure communication channel between configuration control device 140 and electronic device 170, wherein communication interface 143 is used to provide at least a portion of security-sensitive configuration data to electronic device 170 through the secure communication channel, so that at least a portion of the security-sensitive configuration data is stored in non-volatile memory 177 of electronic device 170.
[0057] In one embodiment, the processor 141 of the configuration control device 140 is used to generate at least a portion of security-sensitive configuration data, which is provided to the electronic device 170 via a secure communication channel so that the at least a portion of the security-sensitive configuration data is stored in the non-volatile memory 177 of the electronic device 170.
[0058] In one embodiment, the communication interface 143 of the configuration control device 140 is used to provide at least a portion of the security-sensitive configuration data, together with one or more random nonce values, to the electronic device 170 via a secure communication channel to avoid replay attacks.
[0059] In one embodiment, the electronic device 170 may further include a random number generator, particularly a hardware random number generator, wherein, when executed, the configuration application code 150 is used to generate at least a portion of the security-sensitive configuration data based on one or more seed values using the random number generator. In one embodiment, the configuration application code 150 may include one or more seed values. Alternatively, when executed, the configuration application code may be used to obtain one or more seed values from the configuration control device 140.
[0060] In one embodiment, when executed, configuration application code 150 is used to store security-sensitive configuration data in a predefined security portion of non-volatile memory 177 of electronic device 170. In another embodiment, when executed, configuration application code 150 is used to provide metadata to configuration control device 140, the metadata including information about the storage location of security-sensitive configuration data in non-volatile memory 177 of electronic device 170, wherein communication interface 143 is used to provide information about the storage location of security-sensitive configuration data in non-volatile memory 177 of electronic device 170 to configuration device server 160, for storing information about the storage location of security-sensitive configuration data in non-volatile memory 177 of electronic device 170.
[0061] In one embodiment, when executed, configuration application code 150 is used to store metadata in a predefined portion (e.g., a predefined address range) of the non-volatile memory 177 of the electronic device 170. This metadata includes information about the storage location of security-sensitive configuration data in the non-volatile memory 177 of the electronic device 170.
[0062] In one embodiment, the communication interface 143 of the configuration control device 140 is also used to receive information about the status or result of the configuration application code 150 executed by the processor 171 of the electronic device 170. For example, if the configuration application code 150 is successfully executed, it may send an acknowledgment message to the communication interface 143 of the configuration control device 140.
[0063] In one embodiment, when executed, configuration application code 150 is used to generate a public-private key pair for generating at least a portion of security-sensitive configuration data, wherein the communication interface 143 of configuration control device 140 is used to receive the public key from the public-private key pair from electronic device 170.
[0064] In one embodiment, the processor 141 of the configuration control device 140 is further configured to generate a key certificate based on the public key in the public key-private key pair, wherein the communication interface 143 of the configuration control device 140 is configured to provide the key certificate to the configuration device server 160 so as to store the key certificate in the non-volatile memory 177 of the electronic device 170.
[0065] In one embodiment, when executed, the processing application code 150 is also used to disable or restrict the functionality of one or more hardware components of the electronic device 170, particularly the debugging functionality of the communication interface of the electronic device 170. Disabling or restricting the debugging functionality of the electronic device allows the key to be stored in a secure area of memory. This is because debugging functions typically have access to all memory portions, so once the device reaches production quality, the debugging functionality that accesses the key must be disabled. For example, this restriction on debugging can be achieved by using a secret password that is only provided to authorized debuggers.
[0066] In one embodiment, a portion of the configuration application code 150 may be device type-specific and may contain both general and device identity-specific data. In one embodiment, the configuration application code 150 may be general to the configuration data of a particular chip because it may have registers at different addresses and may have different register structures and commands. If the configuration application code 150 includes a key for an electronic device 170, it will be unique to that particular device 170. If the configuration application code 150 results in the creation of a key within the electronic device 170, it may not need to be specific to that particular device 170, and a general configuration application code 150 can be used for that device type and may be used for multiple device types.
[0067] Figure 3 A flowchart illustrating the steps of a configuration method 300 according to an embodiment of the present invention is shown. The method 300 includes the following steps:
[0068] The configuration application code 150 is securely provided to the configuration device server 160 by 301, so that the configuration application code 150 is stored in the volatile memory 175 of the electronic device 170; and
[0069] The processor 171 of the electronic device 170 is triggered to execute configuration application code 150, wherein the configuration application code 150 is used to store security-sensitive configuration data in the non-volatile memory 177 of the electronic device 170 when executed by the processor 171 of the electronic device 170.
[0070] While certain features or aspects of this disclosure may have been disclosed only for one of several implementations or embodiments, such features or aspects may be combined with one or more other features or aspects of other implementations or embodiments as needed, and may be advantageous for any given or particular application.
[0071] Furthermore, within the scope of the terms “comprising,” “having,” “with,” or other variations thereof used in this disclosure, these terms are intended to resemble the open-ended approach of the term “comprising.” Additionally, the terms “exemplary,” “such as,” and “for example” are meant only as examples, not as best or optimal. The terms “coupled” and “connected,” as well as their derivatives, may be used. It should be understood that these terms may have been used to indicate that two elements cooperate or interact with each other, whether they are in direct physical or electrical contact, or whether they are not in direct contact with each other.
[0072] While specific aspects have been illustrated and described herein, those skilled in the art will understand that various alternatives and / or equivalent embodiments may be used instead of the specific aspects shown and described without departing from the scope of the invention. This application is intended to cover any modifications or variations to the specific aspects discussed herein.
[0073] Although the elements in the following claims are set in a particular order, these elements are not necessarily intended to be limited to being implemented in that particular order unless the claims otherwise imply a particular order for implementing some or all of these elements.
[0074] In view of the foregoing teachings, many alternatives, modifications, and variations will be apparent to those skilled in the art. Of course, those skilled in the art will readily recognize that many applications of the invention extend beyond those described herein. Although the invention has been described with reference to one or more specific embodiments, those skilled in the art will recognize that many changes can be made thereto without departing from the scope of the invention. Therefore, it should be understood that the invention can be practiced in ways other than those specifically described herein within the scope of the appended claims and their equivalents.
Claims
1. A configuration control device (140), characterized in that, For coupling with a configuration device server (160), the configuration device server (160) being electrically connected to at least one electronic device (170) to configure the electronic device (170) using security-sensitive configuration data, the electronic device (170) including a processor (171), volatile memory (175) and non-volatile memory (177), the configuration control device (140) including: A communication interface (143) for securely providing configuration application code (150) to the configuration device server (160) for storing the configuration application code (150) in the volatile memory (175) of the electronic device (170); and A processor (141) is configured to trigger the processor (171) of the electronic device (170) to execute the configuration application code (150) by instructing the processor (171) of the electronic device (170), the configuration application code (150) being configured to, when executed by the processor (171) of the electronic device (170), store the security-sensitive configuration data in the non-volatile memory (177) of the electronic device (170). The processor (141) of the configuration control device (140) is used to generate the configuration application code (150), wherein the processor (141) of the configuration control device (140) is used to include the security-sensitive configuration data in the configuration application code (150).
2. The configuration control device (140) according to claim 1, characterized in that, The communication interface (143) is also used to receive the configuration application code (150) from the remote server (120).
3. The configuration control device (140) according to claim 2, characterized in that, The communication interface (143) is also used to receive the configuration application code (150) from the remote server (120) in encrypted form, and the processor (141) is used to decrypt the encrypted configuration application code (150).
4. The configuration control device (140) according to claim 1, characterized in that, The configuration application code (150) is used, when executed, to instruct the processor (171) of the electronic device (170) to remove the configuration application code (150) from the volatile memory (175) of the electronic device (170).
5. The configuration control device (140) according to claim 1, characterized in that, The security-sensitive configuration data includes electronic keys, electronic key certificates, and / or configuration data.
6. The configuration control device (140) according to claim 1, characterized in that, The electronic device (170) also includes a hardware security enclave (173), and the configuration application code (150) is configured to, when executed, store at least a portion of the security-sensitive configuration data in the hardware security enclave (173) of the electronic device (170).
7. The configuration control device (140) according to claim 1, characterized in that, The configuration application code (150) includes at least a portion of the security-sensitive configuration data to be stored in the non-volatile memory (177) of the electronic device (170).
8. The configuration control device (140) according to claim 1, characterized in that, The communication interface (143) is further configured to provide at least a portion of the security-sensitive configuration data to the configuration device server (160) in a manner separate from the configuration application code (150), so as to store the at least portion of the security-sensitive configuration data in the volatile memory (175) of the electronic device (170) in a manner separate from the configuration application code (150), and the configuration application code (150) is configured to, when executed, obtain the at least portion of the security-sensitive configuration data from the volatile memory (175) of the electronic device (170) and store the at least portion of the security-sensitive configuration data in the non-volatile memory (177) of the electronic device (170).
9. The configuration control device (140) according to claim 1, characterized in that, The configuration application code (150) is used, when executed, to establish a secure communication channel between the configuration control device (140) and the electronic device (170), and the communication interface (143) is used to provide at least a portion of the security-sensitive configuration data to the electronic device (170) through the secure communication channel, so as to store the at least a portion of the security-sensitive configuration data in the non-volatile memory (177) of the electronic device (170).
10. The configuration control device (140) according to claim 9, characterized in that, The processor (141) is configured to generate at least a portion of the security-sensitive configuration data provided to the electronic device (170) via the secure communication channel, and to store at least that portion of the security-sensitive configuration data in the non-volatile memory (177) of the electronic device (170).
11. The configuration control device (140) according to claim 9, characterized in that, The communication interface (143) is used to provide at least a portion of the security-sensitive configuration data, together with one or more random current values, to the electronic device (170) via the secure communication channel.
12. The configuration control device (140) according to claim 1, characterized in that, The electronic device (170) further includes a random number generator, and the configuration application code (150) is configured, when executed, to use the random number generator to generate at least a portion of the security-sensitive configuration data based on one or more seed values.
13. The configuration control device (140) according to claim 12, characterized in that, The random number generator is a hardware random number generator.
14. The configuration control device (140) according to claim 12, characterized in that, The configuration application code (150) includes one or more seed values; and / or The configuration application code (150) is used to obtain the one or more seed values from the configuration control device (140) when executed.
15. The configuration control device (140) according to claim 1, characterized in that, The configuration application code (150) is used, when executed, to store the security-sensitive configuration data in a predefined security portion of the non-volatile memory (177) of the electronic device (170).
16. The configuration control device (140) according to claim 1, characterized in that, The configuration application code (150) is used, when executed, to provide the configuration control device (140) with information about the storage location of the security-sensitive configuration data in the non-volatile memory (177) of the electronic device (170), and the communication interface (143) is used to provide the configuration device server (160) with information about the storage location of the security-sensitive configuration data in the non-volatile memory (177) of the electronic device (170) to store information about the storage location of the security-sensitive configuration data in the non-volatile memory (177) of the electronic device (170).
17. The configuration control device (140) according to claim 1, characterized in that, The configuration application code (150) is used, when executed, to store information about the storage location of the security-sensitive configuration data in the non-volatile memory (177) of the electronic device (170) in a predefined portion of the non-volatile memory (177).
18. The configuration control device (140) according to claim 1, characterized in that, The communication interface (143) is also used to receive information about the status or result of the configuration application code (150) executed by the processor (171) of the electronic device (170).
19. The configuration control device (140) according to claim 1, characterized in that, The configuration application code (150) is used, when executed, to generate a public key-private key pair, which is used to generate at least a portion of the security-sensitive configuration data, and the communication interface (143) is used to receive the public key from the public key-private key pair from the electronic device (170).
20. The configuration control device (140) according to claim 19, characterized in that, The processor (141) is further configured to generate a key certificate based on the public key in the public key-private key pair, and the communication interface (143) is configured to provide the key certificate to the configuration device server (160) so as to store the key certificate in the non-volatile memory (177) of the electronic device (170).
21. The configuration control device (140) according to claim 1, characterized in that, The configuration application code (150) is also used, when executed, to disable or restrict the functionality of one or more hardware components of the electronic device (170).
22. The configuration control device (140) according to claim 21, characterized in that, The configuration application code (150) is also used, when executed, to disable or restrict the debugging function of the communication interface of the electronic device (170).
23. A configuration system, characterized in that, include: Configuration control device (140) according to any one of the preceding claims; and A configuration device server (160) is electrically connected to at least one electronic device (170) to configure the electronic device (170) using security-sensitive configuration data.
24. A method (300) for configuring at least one electronic device (170) using security-sensitive configuration data via a configuration control device (140), characterized in that, The configuration control device (140) is coupled to a configuration device server (160), the configuration device server (160) being electrically connected to the at least one electronic device (170), the electronic device (170) including a processor (171), volatile memory (175), and non-volatile memory (177), the method (300) comprising: The configuration application code (150) is securely provided (301) to the configuration device server (160) for storage in the volatile memory (175) of the electronic device (170); and By instructing the processor (171) of the electronic device (170) to trigger (303) the processor (171) of the electronic device (170) to execute the configuration application code (150), the configuration application code (150) being used to store the security-sensitive configuration data in the non-volatile memory (177) of the electronic device (170) when executed by the processor (171) of the electronic device (170). The processor (141) of the configuration control device (140) is used to generate the configuration application code (150), wherein the processor (141) of the configuration control device (140) is used to include the security-sensitive configuration data in the configuration application code (150).