Configuring systems and methods
Patent Information
- Application Number
- CN202180076540.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-11-13
- Filing Date
- 2021-10-07
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2041-10-07
Smart Images

Figure CN116458112B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the safe production and configuration of electronic devices. More specifically, this invention relates to a system and method for configuring electronic devices. Background Technology
[0002] The production and assembly of existing consumer electronics devices, such as smartphones, tablets, and other types of Internet of Things (IoT) devices, are typically carried out in a distributed manner. This involves the manufacturing, configuration (personalization), and final assembly of various electronic components or devices, including the electronic chips or microprocessors of the consumer electronics, all performed at different locations by different parties. For example, the electronic chips or microprocessors of a consumer electronics device may initially be manufactured by a chip manufacturer, then configured with the corresponding firmware by another party, and finally assembled into the final product by the manufacturer of the consumer electronics device (such as an OEM).
[0003] For such distributed processing chains in electronic devices, there is a need for systems and methods that can configure electronic components or devices such as chips or microprocessors in a safe and controlled manner. Summary of the Invention
[0004] Therefore, the object of the present invention is to provide a system and method for configuring electronic devices such as chips or microprocessors of electronic devices in a safe and controlled manner.
[0005] The above and other objectives are achieved by the technical solutions of the independent claims, and other embodiments are embodied in the dependent claims, the specification and the drawings.
[0006] According to a first aspect of the invention, a production configuration system is provided for configuring a plurality of electronic devices with configuration data, wherein each of the plurality of electronic devices is associated with an electronic device type, such as a certain type of electronic chip or processor. The plurality of electronic devices may include chips, microprocessors, or other programmable electronic devices, such as flash memory, electrically erasable programmable read-only memory (EEPROM), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), or microcontrollers containing non-volatile storage elements or physically unclonable functions (PUFs). The configuration data may include multiple data elements, such as personalized encryption keys, firmware, software applications, or other types of program code. The corresponding configuration data may be digitally signed.
[0007] This configuration system includes a configuration control device configured to acquire device type information regarding the electronic device types of the plurality of electronic devices. Furthermore, the configuration system includes a configuration device configured to electrically connect to at least one of the plurality of electronic devices to configure the at least one electronic device. The configuration system further includes a configuration security module configured to receive device type information from the configuration control device and generate configuration data based on the device type information. The configuration security module is also configured to transmit the configuration data to the configuration device via the configuration control device to configure the at least one electronic device using the configuration data.
[0008] The configuration security module is also configured to maintain a configuration counter that indicates the remaining number of the plurality of electronic devices that can be configured with configuration data.
[0009] In another embodiment, the configuration security module is also configured to update the configuration counter of each of the plurality of electronic devices to obtain an updated configuration counter.
[0010] In another embodiment, the configuration security module is configured to update the configuration counter of each of the plurality of electronic devices by decrementing or incrementing the configuration counter of each of the configured electronic devices to obtain an updated configuration counter.
[0011] In another embodiment, when the updated configuration counter indicates that the remaining number of configurable electronic devices has been reached, the configuration security module is also configured to prevent the configuration of another electronic device among the plurality of electronic devices.
[0012] In another embodiment, the configuration data includes at least a first portion and a second portion, wherein the configuration control device is configured to send the first portion of the configuration data to the configuration device to provide the first portion of the configuration data to the at least one electronic device, and the configuration control device is configured to wait for the configuration device to provide the first portion of the configuration data to the at least one electronic device before sending the second portion of the configuration data to the configuration device to provide the second portion of the configuration data to the at least one electronic device.
[0013] In another embodiment, the configuration device is further configured to determine the electronic device type of the plurality of electronic devices and transmit the device type information to the configuration control device.
[0014] In another embodiment, the configuration data includes at least one of the following: an identifier of the at least one electronic device, one or more encryption keys, and one or more rules for operating and / or updating the at least one electronic device.
[0015] In another embodiment, the configuration control device is configured to obtain device type information about the electronic device types of the plurality of electronic devices in response to receiving a configuration request for configuring the plurality of electronic devices.
[0016] In another embodiment, the configuration system further includes a remote OEM server, wherein the configuration control device is configured to receive configuration requests from the remote OEM server for configuring the plurality of electronic devices.
[0017] In another embodiment, the configuration request for configuring the plurality of electronic devices includes an electronic token, wherein the configuration control device is configured to send the electronic token to the configuration security module, wherein the electronic token includes information indicating the maximum number of the plurality of electronic devices that can be configured with configuration data.
[0018] In another embodiment, the electronic token includes data defining one or more validity periods for the electronic token, wherein the configuration security module is further configured to block the configuration of another electronic device among the plurality of electronic devices outside of the one or more validity periods. In one embodiment, the one or more validity periods may include the period during which the electronic token must first be used to configure the electronic device (i.e., the validity period of token acceptance). In yet another embodiment, the one or more validity periods may include the period defining when the electronic token can be used to configure the electronic device (i.e., the expiration period of the electronic token).
[0019] In another embodiment, the electronic token also includes a token identifier for identifying the electronic token, wherein the configuration security module is further configured to store the token identifier in a list of electronic tokens that have been used or are currently in use.
[0020] In another embodiment, the configuration security module is configured to receive an encrypted electronic token, wherein the configuration security module is further configured to decrypt the encrypted electronic token.
[0021] In another embodiment, the electronic token includes a digital signature based on the private key of the token generation server, wherein the security configuration module is configured to use the public key of the token generation server to verify the digital signature of the electronic token.
[0022] According to a second aspect of the present invention, a method is provided for configuring a plurality of electronic devices using configuration data, wherein each of the plurality of electronic devices is associated with an electronic device type, such as a certain type of electronic chip or processor. This method includes the following steps:
[0023] The configuration control device obtains device type information about the electronic device types of the plurality of electronic devices;
[0024] The configuration security module receives device type information from the configuration control device.
[0025] The configuration security module generates configuration data based on device type information;
[0026] The configuration security module transmits configuration data to the configuration device via a configuration control device. The configuration device is configured to be electrically connected to at least one of the plurality of electronic devices to configure the at least one electronic device using the configuration data; and
[0027] A configuration counter is maintained by the configuration security module, which indicates the remaining number of the plurality of electronic devices that can be configured with configuration data.
[0028] The configuration method according to the second aspect of the invention can be executed by the configuration system according to the first aspect of the invention. Further features of the configuration method according to the second aspect of the invention directly derive from the functionality of the configuration system according to the first aspect of the invention and its various embodiments described above and below.
[0029] The embodiments of the present invention can be implemented by hardware and / or software. Attached Figure Description
[0030] Other embodiments of the present invention will be described below with reference to the accompanying drawings.
[0031] In the attached image:
[0032] Figure 1 This is a configuration system according to an embodiment of the present invention.
[0033] Figure 2 for Figure 1 A schematic diagram illustrating an example of an electronic configuration token used by the configuration system.
[0034] Figure 3 for Figure 1 The signaling diagram of the interaction between multiple components of the configuration system.
[0035] Figure 4 This is a flowchart of the configuration method according to an embodiment of the present invention.
[0036] In the accompanying drawings, identical or at least functionally equivalent components are labeled with the same reference numerals. Detailed Implementation
[0037] The following description will be made with reference to the accompanying drawings, which form part of the invention and illustrate various aspects of the invention by way of illustration. It should be understood that other aspects may be employed and structural or logical changes may be made without departing from the scope of the invention. Therefore, the following detailed description should not be considered as constituting a limitation, and the scope of the invention is defined by the claims of the invention.
[0038] For example, it should be understood that the disclosure in conjunction with the method description can also be applied to the corresponding apparatus or system for implementing the method, and vice versa. For instance, if a specific method step is described below, the corresponding apparatus may include units for performing the described method steps, even if not explicitly stated herein or shown in the accompanying drawings. Furthermore, it should be understood that, unless otherwise specifically indicated, the various illustrative features described herein can be combined with each other.
[0039] Figure 1 The diagram illustrates a system 100 according to an embodiment of the present invention. The system includes a configuration system 130 according to an embodiment of the present invention for configuring or personalizing a plurality of electronic devices 180, 180' (e.g., chips or microprocessors 180, 180') with configuration data 150, wherein each of the plurality of electronic devices 180, 180' is associated with an electronic device type. In one embodiment, the configuration data 150 may include a unique identifier for at least one electronic device 180, 180', one or more encryption keys, rules for operating and / or updating at least one electronic device 180, 180', and / or firmware for the electronic devices 180, 180'.
[0040] like Figure 1 As shown, the configuration system 130 includes a configuration control device 160 configured to acquire device type information regarding the respective electronic device types of the plurality of electronic devices 180, 180'. Furthermore, the configuration system 130 includes a configuration device 170 configured to electrically connect to at least one of the plurality of electronic devices 180, 180' to configure the at least one electronic device 180, 180'. In one embodiment, the configuration device 170 is configured to determine the electronic device type of the plurality of electronic devices 180, 180' and transmit the device type information to the configuration control device 160.
[0041] The configuration system 130 also includes a configuration security module 140, which is configured to receive device type information from the configuration control device 160 and generate configuration data 150 based on the device type information. In other words, the configuration security module 140 can generate different configuration data 150 depending on the type of the electronic devices 180, 180' to be configured.
[0042] The configuration security module 140 is also configured to transmit configuration data 150 generated based on electronic device type information to the configuration device 170 via the configuration control device 160, so as to configure the at least one electronic device 180, 180' with the configuration data 150. The configuration security module 140 is also configured to maintain a configuration counter that indicates the remaining number of electronic devices 180, 180' that can be configured with the configuration data 150.
[0043] As will be described in more detail below, in addition to configuration system 130, system 100 may also include a remote OEM server 110 and a token generation server 120. For example... Figure 1 As shown, configuration system 130, remote server 110, and token generation server 120 can be configured to communicate with each other via a communication network such as the Internet. Therefore, configuration system 130, remote server 110, and token generation server 120 can be located in different locations and under the control of different parties. In one embodiment, remote server 110 may be under the control of or associated with an electronics manufacturer (such as an OEM) that uses electronic devices 180, 180' configured by configuration system 130 with configuration data 150 to assemble electronic devices such as smartphones, tablets, or other types of Internet of Things or consumer electronics devices. In one embodiment, configuration data 150 includes firmware from the electronics manufacturer associated with remote server 110. This allows the electronics manufacturer to control the configuration of electronic devices 180, 180' using its firmware.
[0044] In one embodiment, the configuration system 130, the remote server 110, and the token generation server 120 are configured to communicate securely with each other using one or more cryptographic schemes such as public key infrastructure and / or hybrid cryptographic schemes.
[0045] In one embodiment, the configuration security module 140 is configured to be coupled to the configuration control device 160, for example, via a wired or wireless connection. In one embodiment, the configuration control device 160 may be implemented as a personal computer (PC), and the configuration security module 140 may be implemented as a PC card inserted into the configuration control device 160. The configuration device 170 may include electrical and / or mechanical interfaces for directly or indirectly interacting with one or more of the plurality of electronic devices 180, 180'. For example, the configuration device 170 may include a personalization tray for personalizing a batch of electronic devices 180, 180' inserted therein.
[0046] In one embodiment, the configuration security module 140 is configured to update the configuration counter of each configured electronic device among a plurality of electronic devices 180, 180' to obtain an updated configuration counter. For example, the configuration security module 140 may be configured to update the configuration counter of each configured electronic device among a plurality of electronic devices 180, 180' by decrementing the configuration counter of each configured electronic device among a plurality of electronic devices 180, 180' to obtain an updated configuration counter. In another embodiment, the configuration counter may be incremented until a maximum number of allowed electronic devices 180, 180' has been configured. The configuration security module 140 may also be configured to prevent the configuration of another electronic device among a plurality of electronic devices 180, 180' if the updated configuration counter indicates that the remaining number of configurable electronic devices 180, 180' has been reached, for example, if the updated configuration counter is equal to zero (in the case of decrementing the configuration counter of each device) or equal to the maximum number of allowed electronic devices 180, 180' (in the case of incrementing the configuration counter of each device). In other words, once the total number of electronic devices 180, 180' has been configured, the configuration security module 140 will prevent the configuration device 170 from configuring any other electronic devices 180, 180' with configuration data 150.
[0047] In one embodiment, the configuration control device 160 is configured to obtain device type information about each electronic device type of the plurality of electronic devices 180, 180' in response to receiving a configuration request for configuring a plurality of electronic devices 180, 180'. In another embodiment, the configuration control device 160 is configured to receive the configuration request for configuring the plurality of electronic devices 180, 180' from a remote OEM server 110.
[0048] In one embodiment, the configuration request for configuring multiple electronic devices 180, 180' includes an electronic token 190, wherein the configuration control device 160 is configured to send the electronic token 190 to the configuration security module 140, and the electronic token 190 includes information 192, such as... Figure 2 As shown, it indicates the maximum number of multiple electronic devices 180, 180' that can be configured by configuration device 170 with configuration data 150. In one embodiment, configuration security module 140 is configured to receive an encrypted electronic token 190, wherein configuration security module 140 is further configured to decrypt the encrypted electronic token 190. In one embodiment, electronic token 190 includes a digital signature 198 based on the private key 121a of token generation server 120 (see...). Figure 2 The security module 140 is configured to use the public key 121b of the token generation server 120 to verify the digital signature 198 of the electronic token 190.
[0049] like Figure 2 As shown, the electronic token 190 may further include data 197 defining one or more validity periods for the electronic token 190, wherein the configuration security module 140 is further configured to block the configuration of another electronic device among the plurality of electronic devices 180, 180' outside of one or more validity periods. In one embodiment, the one or more validity periods may include the period during which the electronic token 190 must first be used to configure the electronic device 180, 180' (i.e., the validity period of token acceptance). In another embodiment, the one or more validity periods may include the period defining when the electronic token 190 can be used to configure the electronic device 180, 180' (i.e., the expiration date of the electronic token 190).
[0050] exist Figure 2 In the illustrated embodiment, the electronic token 190 further includes a token identifier 193 for identifying the electronic token 190, wherein the configuration security module 140 is further configured to store the token identifier 193 in a list of electronic tokens that have been used or are currently in use to prevent replay attacks. In one embodiment, the token identifier 193 may be a random number 193.
[0051] like Figure 2 As shown, the electronic token 190 may include other data, such as configuration control data 191 that controls communication between the configuration security module 140 and the configuration control device 160. In one embodiment, this configuration control data 191 may be provided within the header 191 of the electronic token 190. In one embodiment, the configuration control data 191 may identify a secure communication protocol used to protect communication between the configuration security module 140 and the configuration control device 160. Figure 2 As shown, the electronic token 190 may further include an OEM identifier 194, a firmware identifier 195, and an electronic device type identifier 196.
[0052] Figure 3 A signaling diagram illustrating the interaction between components of the configuration system 130 and electronic devices 180, 180' to be configured is shown. Figure 3 The following steps are described above, and some steps have already been described in the text. Figure 1 and Figure 2 This is explained in the description section.
[0053] exist Figure 3 In step 300, the configuration control device 160 receives a request for configuring one or more of a plurality of electronic devices 180, 180'. As described above, in one embodiment, this request may be issued by a remote OEM server 110 and may include an electronic token 190.
[0054] exist Figure 3 In step 301, the configuration device 170 obtains information about the type of electronic device 180, 180' to be configured, such as the electronic device currently inserted into the personalization settings disk of the configuration device 170.
[0055] exist Figure 3 In steps 303 and 305, the configuration device 170 sends the device type information to the configuration control device 160, which then relays the device type information to the configuration security module 140.
[0056] exist Figure 3 In step 307, the configuration security module 140 checks whether the current value of the electronic configuration counter allows the configuration of another electronic device 180, 180'. If so, the configuration security module 140 generates configuration data 150 (step 309) and decrements the electronic configuration counter (step 311). Figure 3 In the illustrated embodiment, the configuration data 150 includes multiple datasets or chunks, including at least a first dataset and a second dataset.
[0057] exist Figure 3 In step 313a, the configuration security module 140 sends the first dataset (dataset A) of the configuration data 150 to the configuration control device 160, and the configuration control device 160 then relays the first dataset (dataset A) of the configuration data 150 to the configuration device 170 (step 315a).
[0058] exist Figure 3 In step 317a, configuration device 170 writes the first dataset of configuration data 150 to electronic devices 180, 180', for example, to the memory of electronic devices 180, 180' (as will be understood, in an embodiment where configuration data 150 only includes the first dataset generated in step 309, the configuration will be transmitted via...). Figure 3 (Step 317a is completed). While or after writing the first dataset (dataset A) of configuration data 150 to electronic devices 180, 180', configuration device 170 sends an acknowledgment message to configuration control device 160 (step 318a), and configuration control device 160 then relays the acknowledgment message to configuration security module 140 to request other datasets of configuration data 150 (step 319a).
[0059] exist Figure 3In step 313b, in response to receiving an acknowledgment message from configuration control device 160, configuration security module 140 sends the next part, such as the second dataset (dataset B) of configuration data 150, to configuration control device 160, and configuration control device 160 then relays the second dataset (dataset B) of configuration data 150 to configuration device 170 (step 315b).
[0060] Other steps 317b, 318b, and 319b are the same as steps 317a, 318a, and 319a already described above. The sequence of steps 313a through 319a will be repeated until all datasets constituting configuration data 150 have been provided to the currently configured electronic devices 180, 180'. Once this is complete, the next electronic device 180, 180' or the next batch of electronic devices 180, 180' can be... Figure 3 Configure as shown.
[0061] Figure 4 A flowchart illustrating the steps of a configuration method 400 according to an embodiment of the present invention is shown. The configuration method 400 according to an embodiment of the present invention includes the following steps:
[0062] Step 401: The configuration control device 160 obtains device type information about the respective electronic device types of the plurality of electronic devices 180, 180'.
[0063] Step 403: The configuration security module 140 receives device type information from the configuration control device 160.
[0064] Step 405: The configuration security module 140 generates configuration data 150 based on the device type information.
[0065] Step 407: The configuration security module 140 transmits configuration data 150 to the configuration device 170 via the configuration control device 160. The configuration device 170 is configured to be electrically connected to at least one of the plurality of electronic devices 180, 180' to configure at least one electronic device 180, 180' using the configuration data 150.
[0066] Step 409: A configuration counter is maintained by the configuration security module 140, which indicates the remaining number of the plurality of electronic devices 180, 180' that can be configured by the configuration data 150.
[0067] While a particular feature or aspect of the invention may have been described above in combination with only one of a variety of implementations or embodiments, such features or aspects may also be combined with one or more other features or aspects of other implementations or embodiments to meet the needs of any given or particular application or to benefit that application.
[0068] Furthermore, for the purposes of this detailed specification and the claims, the words “containing,” “having,” “with,” or other forms of these words are intended to be open-ended terms, similar to the word “comprising.” Additionally, the words “exemplary,” “for example,” and “such as” are intended to be illustrative only and do not indicate best or optimal usage. The words “coupled” and “connected” and their derivatives may have been used above. It should be understood that these words are intended to indicate that two components cooperate or interact with each other, regardless of whether they are in direct physical or electrical contact, or whether they are not in direct contact.
[0069] While specific aspects of the invention are illustrated and described, it will be understood by those skilled in the art that the illustrated and described aspects can be replaced with various alternative and / or equivalent embodiments without departing from the scope of the invention. This application is intended to cover any modifications or variations of the specific aspects described herein.
[0070] Although the elements in the claims are described in a particular order, they are not intended to be limited to being implemented in the described particular order unless the claims imply that some or all of these elements must be implemented in that particular order.
[0071] Based on the above disclosure, many alternatives, modifications, and variations will be readily understood by those skilled in the art. Of course, those skilled in the art will readily recognize that the invention has many other applications besides those described herein. Although the invention has been described above with reference to one or more specific embodiments, those skilled in the art will recognize that many changes can be made without departing from the scope of the invention. Therefore, it should be understood that the invention can be practiced in ways other than those specifically described herein within the scope of the claims and their equivalents.
Claims
1. A configuration system (130) for configuring a plurality of electronic devices (180, 180') with configuration data (150), each of the plurality of electronic devices (180, 180') being associated with an electronic device type, characterized in that, The configuration system (130) includes: Remote server (110); The configuration control device (160) is configured to, in response to a configuration request received from the remote server (110) to configure the plurality of electronic devices (180, 180'), obtain device type information about the types of the electronic devices (180, 180'). A configuration device (170) is configured to be electrically connected to at least one of the plurality of electronic devices (180, 180') to configure the at least one electronic device (180, 180'); and A configuration security module (140) is configured to receive device type information from the configuration control device (160) and generate configuration data (150) based on the device type information. The configuration security module (140) is also configured to transmit the configuration data (150) to the configuration device (170) via the configuration control device (160) to configure the at least one electronic device (180, 180') using the configuration data (150). The configuration security module (140) is further configured to maintain a configuration counter that indicates the remaining number of the plurality of electronic devices (180, 180') that can be configured with configuration data (150). The configuration request for configuring the plurality of electronic devices (180, 180') includes an electronic token (190), wherein the configuration control device (160) is configured to send the electronic token (190) to the configuration security module (140), wherein the electronic token (190) includes information (192) indicating the maximum number of the plurality of electronic devices (180, 180') that can be configured with the configuration data (150). The electronic token (190) includes configuration control data that controls the communication between the configuration security module (140) and the configuration control device (160).
2. The configuration system (130) as described in claim 1, characterized in that, The configuration security module (140) is also configured to update the configuration counter of each of the plurality of electronic devices (180, 180') to obtain an updated configuration counter.
3. The configuration system (130) as described in claim 2, characterized in that, The configuration security module (140) is configured to update the configuration counter of each of the plurality of electronic devices (180, 180') by decrementing or incrementing the configuration counter of each of the configured electronic devices to obtain the updated configuration counter.
4. The configuration system (130) as described in claim 1, characterized in that, When the updated configuration counter indicates that the remaining number of the plurality of electronic devices (180, 180') that can be configured has been reached, the configuration security module (140) is also configured to prevent the configuration of other electronic devices among the plurality of electronic devices (180, 180').
5. The configuration system (130) as described in claim 1, characterized in that, The configuration data (150) includes at least a first part and a second part, wherein the configuration control device (160) is configured to send the first part of the configuration data (150) to the configuration device (170) to provide the first part of the configuration data (150) to the at least one electronic device (180, 180'), and the configuration control device (160) is configured to wait for the plurality of configuration devices (170) to provide the first part of the configuration data (150) to the at least one electronic device (180, 180') before sending the second part of the configuration data (150) to the configuration device (170) to provide the second part of the configuration data (150) to the at least one electronic device (180, 180').
6. The configuration system (130) as described in claim 1, characterized in that, The configuration device (170) is also configured to determine the electronic device type of the plurality of electronic devices (180, 180') and transmit the device type information to the configuration control device (160).
7. The configuration system (130) as described in any one of claims 1-6, characterized in that, The configuration data includes at least one of the following: an identifier of the at least one electronic device (180, 180'), one or more encryption keys, and one or more rules for operating and / or updating the at least one electronic device (180, 180').
8. The configuration system (130) as described in any one of claims 1-6, characterized in that, The electronic token (190) also includes data (197) defining one or more valid time periods for the electronic token (190), wherein the configuration security module (140) is further configured to block other electronic devices among the plurality of electronic devices (180, 180') outside of the one or more valid time periods.
9. The configuration system (130) as described in any one of claims 1-6, characterized in that, The electronic token (190) also includes a token identifier (193) for identifying the electronic token (190), wherein the configuration security module (140) is further configured to store the token identifier (193) in a list of electronic tokens that have been used or are in use.
10. The configuration system (130) as claimed in any one of claims 1-6, characterized in that, The configuration security module (140) is configured to receive the encrypted electronic token (190), wherein the configuration security module (140) is further configured to decrypt the encrypted electronic token (190).
11. The configuration system (130) as claimed in any one of claims 1-6, characterized in that, The electronic token (190) includes a digital signature (198) based on the private key (121a) of the token generation server (120), wherein the configuration security module (140) is configured to use the public key (121b) of the token generation server (120) to verify the digital signature (198) of the electronic token (190).
12. A method (400) for configuring a plurality of electronic devices (180, 180') using configuration data (150), each of the plurality of electronic devices (180, 180') being associated with an electronic device type, characterized in that, The method (400) includes: In response to a configuration request received from a remote server (110) to configure the plurality of electronic devices (180, 180'), the configuration control device (160) obtains (401) device type information about the electronic device types of the plurality of electronic devices (180, 180'); The configuration security module (140) receives (403) the device type information from the configuration control device (160); The configuration security module (140) generates (405) configuration data (150) based on the device type information; The configuration security module (140) transmits (407) the configuration data (150) to the configuration device (170) via the configuration control device (160), the configuration device (170) being configured to be electrically connected to at least one of the plurality of electronic devices (180, 180') to configure the at least one electronic device (180, 180') using the configuration data (150); and The configuration security module (140) maintains (409) a configuration counter, which indicates the remaining number of the plurality of electronic devices (180, 180') that can be configured with configuration data (150). The configuration request for configuring the plurality of electronic devices (180, 180') includes an electronic token (190), wherein the configuration control device (160) is configured to send the electronic token (190) to the configuration security module (140), wherein the electronic token (190) includes information (192) indicating the maximum number of the plurality of electronic devices (180, 180') that can be configured with the configuration data (150). The electronic token (190) includes configuration control data that controls the communication between the configuration security module (140) and the configuration control device (160).
Citation Information
Patent Citations
Provisioning secrets in an unsecured environment
US20090300758A1
Unified programming environment for programmable devices
US20180375666A1
Security Data Processing Device
US20200272745A1