System, device and method for activating identification when security sensitive function has been previously activated

JP2023068635A5Active Publication Date: 2025-10-02AXIS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2022172213
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2021-11-02
Filing Date
2022-10-27
Publication Date
2025-10-02
Estimated Expiration
2042-10-27

AI Technical Summary

Technical Problem

Ensuring the integrity and security of electronic devices, particularly networked devices like networked cameras, is challenging due to the difficulty in verifying that they have not been tampered with during manufacturing and delivery to the end user, as manufacturers lack control over the supply chain.

Method used

A method and system that detects activation of security-sensitive features by updating the device's data storage contents using an irreversible and collision-resistant update function, ensuring that unauthorized changes can be identified by comparing new and expected contents, and generating a security notification if discrepancies are found.

Benefits of technology

This approach effectively identifies and notifies users of potential tampering by ensuring that unauthorized changes to security-sensitive features are detected, maintaining the device's integrity and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To provide a method, electronic device and system that distinguish an alteration possible in an electronic device to be used for the first time.SOLUTION: In a system, an electronic device equipped with data storage having a current content is configured to, upon detecting an event indicative of activation of a security sensitive function of the electronic device, acquire a value previously unknown to the electronic device, and update a current content of the data storage to a new current content of the data storage according to an updating function based on the current content and the value. A management module is configured to further acquire a value, determine an expected new current content of the data storage according to the updating function based on a known original content of the data storage and the value, and upon determining that the new current content of the data storage is different from the expected new current content of the data storage, generate a security notification.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the identification of tampering that can occur in an electronic device when it is first used, and more particularly to the identification when a security-sensitive function has been previously enabled in the electronic device.

Background Art

[0002] When an electronic device is manufactured, it is important to ensure the integrity of the electronic device until it is delivered to the end user so that the end user can reliably confirm that the electronic device has not been tampered with. Since the manufacturer may not be able to fully control the supply chain from manufacturing to the final delivery to the end user, it may be difficult for the manufacturer to guarantee this. Therefore, it may be difficult to guarantee that an external party has not accessed and tampered with the device before the electronic device reaches the end user. This is particularly important for networked electronic devices, such as networked cameras. Because if such an electronic device is tampered with, access to the electronic device by an external party may be enabled after the electronic device is connected to a network such as the Internet, or the integrity and / or security of the electronic device may be otherwise compromised.

Summary of the Invention

[0003] <000,0014>An object of the present invention is to provide a method and system for notifying when a security-sensitive function of an electronic device has been previously enabled, which overcomes or mitigates problems in known methods and systems, and a method and an electronic device for enabling notification when a security-sensitive function of an electronic device has been previously enabled.

[0004] <000001,7>According to the first aspect, a method is provided for notifying when a security-sensitive function of an electronic device has been previously enabled, and the electronic device comprises data storage having current content. An event indicating the activation of the electronic device's security-sensitive function is detected in the electronic device. Upon detection of the event indicating the activation of the electronic device's security-sensitive function, a previously unknown value is obtained in the electronic device, and the current content of the data storage is updated to a new current content in the data storage according to an update function based on the current content and value of the data storage. If privileged access is not available, the current content of the data storage can only be updated using the update function. The new current content of the data storage is then transferred from the electronic device to a verification module. The value is further obtained in the management module, and the expected new current content of the data storage is determined in the management module according to the update function based on the known original content and value of the data storage. The management module then transfers the expected new current content of the data storage to a verification module. In the verification module, the new current content of the data storage is compared to the expected new current content of the data storage. If the validation module determines that the new current content of the data storage differs from the expected new current content of the data storage, it generates a security notification.

[0005] An event indicating the activation of a security-sensitive feature on an electronic device means any event that can be inferred to mean that a security-sensitive feature on an electronic device has been activated. Such a security-sensitive feature may be any type of feature that could compromise the security of the electronic device if activated by an external party.

[0006] The new current content refers to the content of the data storage after it has been updated by the update function. The update function and the retrieved values ​​are such that the new current content is substantially always different from the current content. "Substantially always" means that the probability that the new current content is the same as the updated current content is so small that it has no practical effect. This disclosure is intended to cover update functions that, when it is shown that the new current content after being updated according to the update function is different from the current content, could be the same as the current content, but are very unlikely to have no practical effect.

[0007] Known original content refers to the content of data storage when it can be guaranteed that the security-sensitive features of the electronic device have not been enabled.

[0008] By updating the current content of the data storage according to the update function, based on the current content of the data storage and the value when an event indicating the activation of the electronic device's security-sensitive features is detected, it is impossible to detect an event indicating the activation of the electronic device's security-sensitive features without updating the current content of the data storage according to the update function. Therefore, as soon as an event indicating the activation of the electronic device's security-sensitive features is first detected, the current content of the data storage will be different from the original content. Furthermore, without privileged access, the current content of the data storage can only be updated using the update function, and since the data storage has known original content, the updated current content of the data storage cannot be updated back to the original content without privileged access to the data storage. As a result, from the new current content of the data storage (i.e., the updated content), it is possible to determine whether the detection of an event indicating the activation of security-sensitive features is the first time such an event has been detected, or whether the electronic device's security-sensitive features were previously enabled. Specifically, since the expected new current content is determined according to the update function based on the known original content and value, the new current content will be the same as the expected new current content only if the current content of the data storage was the same as the known original content. This does not apply if an event indicating the activation of security-sensitive features on the electronic device has been previously detected on the electronic device.

[0009] Updating the current content of data storage within an electronic device to the new current content of data storage may include concatenating a value with the current content of data storage and hashing the concatenation of the value with the current content of data storage using a known hash function. The current content of data storage is then updated so that the hashed concatenation of the value with the current content of data storage is the new current content of data storage. Under the condition that the known original content of data storage is "empty", determining the expected new current content of data storage in the management module may then include hashing a value using a known hash function and determining that the expected new current content of data storage is the hashed value. Otherwise, determining the expected new current content of data storage in the management module may include retrieving the known original content of data storage, hashing the concatenation of the value with the known original content of data storage using a known hash function, and determining that the expected new current content of data storage is the hashed concatenation of the value with the known original content of data storage.

[0010] "Empty" means that updating the data storage using the function results in a new current content that is the same as if the function had been performed on values ​​only. Empty can mean, for example, that the current content of the data storage is NULL, such as one or more "0"s (an empty string). Empty may also mean that the current content of the data storage is marked as uninitialized, in which case the function can be configured so that the new current content is the same as if the function had been performed on values ​​only.

[0011] By using an update function that involves concatenating a value with the current content of data storage, hashing the concatenation, and updating data storage so that the new current content is the hashed concatenation, the new current content of data storage will be different from the current content before the update.

[0012] Retrieving a value in a management module may include determining a value in the management module. The value may then be transferred from the management module to an electronic device, and consequently, retrieving a value in the electronic device may include receiving a value from the management module.

[0013] By determining the value within the management module, the determined value can be controlled within the management module, and therefore, it can be guaranteed within the management module that the value is not previously known in the electronic device.

[0014] An event indicating the activation of security-sensitive features on an electronic device may consist of one of the following: setting a root password, setting an administrator password, etc.

[0015] According to a second aspect, a system is provided for notifying when a security-sensitive function of an electronic device has been previously enabled. The system comprises an electronic device, a management module, and a verification module. The electronic device comprises a data storage having current content and a device circuit. The device circuit is configured to perform: a detection function configured to detect an event indicating the activation of a security-sensitive function of the electronic device; a device value acquisition function configured to acquire a previously unknown value for the electronic device when the detection function detects an event indicating the activation of a security-sensitive function of the electronic device; an update function configured to update the current content of the data storage to new current content for the data storage according to an update function based on the current content and value of the data storage when the detection function detects an event indicating the activation of a security-sensitive function of the electronic device, wherein, if there is no privileged access, the current content of the data storage can only be updated using the update function; and a device transfer function configured to transfer the new current content of the data storage to the verification module. The management module comprises management module circuitry configured to perform a management module value acquisition function configured to acquire a value, an expected new current content determination function configured to determine the expected new current content of the data storage according to an update function based on the known original content and value of the data storage, and a management module transfer function configured to transfer the expected new current content of the data storage to the verification module. The verification module comprises verification module circuitry configured to perform a comparison function configured to compare the new current content of the data storage with the expected new current content of the data storage, and a notification generation function configured to generate a security notification when it determines that the new current content of the data storage received from an electronic device is different from the expected new current content of the data storage.

[0016] The features described above of the method according to the first embodiment also apply to this second embodiment, where applicable. The above is referenced to avoid excessive repetition.

[0017] According to a third aspect, a non-temporary computer-readable storage medium is provided that stores instructions for implementing the method according to the first aspect when executed on a system according to the second aspect.

[0018] The features described above of the method according to the first embodiment also apply to this third embodiment, where applicable. The above is referenced to avoid excessive repetition.

[0019] According to a fourth aspect, a method is provided in an electronic device for enabling notification when a security-sensitive feature of the electronic device has been previously enabled, the electronic device comprising data storage having current content. An event indicating the activation of the security-sensitive feature of the electronic device is detected. Upon detection of the event indicating the activation of the security-sensitive feature of the electronic device, a previously unknown value is obtained in the electronic device, and the current content of the data storage is updated to the new current content of the data storage according to an update function based on the current content and value of the data storage, and unless privileged access is available, the current content of the data storage may only be updated using the update function.

[0020] By updating the current content of the data storage according to the update function, based on the current content of the data storage and the value when an event indicating the activation of the electronic device's security-sensitive features is detected, it is impossible to detect an event indicating the activation of the electronic device's security-sensitive features without updating the current content of the data storage according to the update function. Therefore, as soon as an event indicating the activation of the electronic device's security-sensitive features is first detected, the current content of the data storage will be different from the original content. Furthermore, without privileged access, the current content of the data storage can only be updated using the update function, so the updated current content of the data storage cannot be updated back to the original content without privileged access to the data storage. As a result, from the new current content of the data storage (i.e., the updated content), it is possible to determine whether the detection of an event indicating the activation of the security-sensitive features is the first time such an event has been detected, or whether the electronic device's security-sensitive features were previously enabled. Specifically, based on knowledge of the update function and the original content of the data storage, it is possible to determine whether the current content of the data storage was equal to the known original content. This is not the case if an event indicating the activation of the electronic device's security-sensitive features has been previously detected on the electronic device. Alternatively, by examining the current content of the data storage, it is possible to determine whether the detection of an event indicating the activation of security-sensitive features is the first time such an event has been detected, or whether the security-sensitive features of the electronic device were previously enabled. Specifically, it can be determined that an event indicating the activation of security-sensitive features of the electronic device has not been previously detected on the electronic device only if the current content is identical to the known original content.

[0021] The features described above of the method according to the first embodiment also apply to this fourth embodiment, where applicable. The above is referenced to avoid excessive repetition.

[0022] According to a fifth aspect, an electronic device is provided comprising a data storage having current content and a device circuit. The device circuit is configured to perform a detection function configured to detect an event indicating the activation of a security-sensitive function of the electronic device; a value acquisition function configured to obtain a previously unknown value to the electronic device when an event indicating the activation of a security-sensitive function of the electronic device is detected; and an update function configured to update the current content of the data storage to new current content of the data storage according to an update function based on the current content and value of the data storage when an event indicating the activation of a security-sensitive function of the electronic device is detected, wherein, without privileged access, the current content of the data storage can only be updated using the update function.

[0023] The features described above of the method according to the first embodiment also apply to this fifth embodiment, where applicable. The above is referenced to avoid excessive repetition.

[0024] According to the sixth aspect, a non-temporary computer-readable storage medium is provided that stores instructions for implementing the method according to the fourth aspect when executed on an electronic device according to the fifth aspect.

[0025] The features described above of the method according to the first embodiment also apply to this sixth embodiment, where applicable. The above is referenced to avoid excessive repetition.

[0026] According to the seventh aspect, a method is provided for notifying when a security-sensitive function of an electronic device has been previously enabled, the electronic device having data storage with current content. In the electronic device, an event indicating the activation of the electronic device's security-sensitive function is detected. Upon detection of an event indicating the activation of the electronic device's security-sensitive function, the current content of the data storage is transferred to a verification module, a value previously unknown to the electronic device is obtained, and the current content of the data storage is updated to the new current content of the data storage according to an update function based on the current content and value of the data storage. If there is no privileged access, the current content of the data storage can only be updated using the update function. If the verification module determines that the current content of the data storage received from the electronic device is different from the original content of the data storage, it generates a security notification.

[0027] Based on the current content of the data storage and the value when an event indicating the activation of a security-sensitive function of an electronic device is detected, by updating the current content of the data storage according to an update function, an event indicating the activation of a security-sensitive function of an electronic device cannot be detected without updating the current content of the data storage according to the update function. Therefore, as soon as an event indicating the activation of a security-sensitive function of an electronic device is first detected, the current content of the data storage will be different from the original content. Further, without privileged access, the current content of the data storage can only be updated using the update function, so the current content of the data storage after update cannot be updated back to the original content when there is no privileged access to the data storage. Therefore, it is possible to determine from the current content of the data storage whether the detection of an event indicating the activation of a security-sensitive function is the first such event detected, or whether the security-sensitive function of the electronic device has been previously activated. Specifically, it can be determined that an event indicating the activation of a security-sensitive function of an electronic device has not been previously detected in the electronic device only when the current content is equal to the known original content.

[0028] The above-described features of the method according to the first aspect are equally applicable to this seventh aspect, where applicable. To avoid excessive repetition, the above is hereby incorporated by reference.

[0029] The further scope of application of the present invention will become apparent from the detailed description given hereinafter. However, while the detailed description and specific examples show preferred embodiments of the present invention, it is to be understood that various changes and modifications within the scope of the present invention will become apparent to those skilled in the art from this detailed description, and are given by way of illustration only.

[0030] Therefore, it should be understood that the present invention is not limited to the specific component parts of the described system or the acts of the described method, and such devices and methods can vary. It should also be understood that the terms used herein are for the purpose of describing particular embodiments only and are not intended to be limiting. As used herein in the specification and the appended claims, the articles "a," "an," "the," and "said" are intended to mean that there is one or more elements present, unless the context clearly indicates otherwise. Thus, for example, reference to "a unit" or "the unit" can include, among other things, some devices. Further, the words "comprising," "including," "containing," and similar expressions do not exclude other elements or steps.

[0031] Next, the above and other aspects of the present invention will be described in more detail with reference to the accompanying drawings. The drawings should not be considered limiting, but rather are used for explanation and understanding. Like reference numerals refer to like elements throughout.

Brief Description of the Drawings

[0032] [Figure 1] FIG. 1 is a schematic block diagram of an embodiment of a system for notifying when a security-sensitive function of an electronic device has been previously enabled. [Figure 2] FIG. 2 is a flowchart of an embodiment of a method for notifying when a security-sensitive function of an electronic device has been previously enabled. [Figure 3] FIG. 3 is a flowchart of another embodiment of a method for notifying when a security-sensitive function of an electronic device has been previously enabled. [Figure 4] FIG. 4 is a schematic block diagram of an embodiment of an electronic device for enabling notification when a security-sensitive function of an electronic device has been previously enabled. [Figure 5] This is a flowchart of an embodiment of a method for enabling notifications when the security sensitive features of an electronic device have been previously enabled. [Modes for carrying out the invention]

[0033] The present invention is described in its entirety below with reference to the accompanying drawings illustrating currently preferred embodiments of the invention. However, the present invention can be modified into various other forms, and the scope of the invention is not limited to the embodiments described below. Rather, these embodiments are provided for thoroughness and completeness, and to convey the scope of the invention to those skilled in the art.

[0034] The dashed lines in the diagrams related to a feature indicate that the feature is optional.

[0035] Figure 1 is a schematic block diagram of an embodiment of a system 100 for notifying when the security sensitive function of an electronic device 110 has been previously enabled. The system comprises an electronic device 110, a management module 130, and a verification module 150. The electronic device 110 may be a networked electronic device such as a networked camera that is to be connected to a network such as the Internet. The management module 130 and the verification module 150 can be located in the same device or in different devices. For example, the management module 130 and the verification module 150 may be located on the same or different cloud-based servers, or on the electronic device 110.

[0036] Events indicating the activation of security-sensitive features of electronic device 110 may include, for example, setting a root password or an administrator password. Further events indicating the activation of security-sensitive features include enabling debug software features, or enabling hardware debugging features such as JTAG, scan chain, boundary scan, or other DFT logic. Further examples include accessing onboard tokens for network, cloud services, etc.

[0037] The electronic device 110 comprises a data storage 114 having current content and a device circuit 112. The device circuit 112 is configured to perform the functions of the electronic device 110.

[0038] Specifically, the device circuit 112 is configured to perform a detection function 122 that is configured to detect events indicating the activation of security-sensitive functions of the electronic device 110.

[0039] The device circuit 112 is further configured to execute a device value acquisition function 124, which is configured to acquire a previously unknown value for the electronic device 110, when an event detection function 122 detects an event indicating the activation of a security-sensitive function of the electronic device 110.

[0040] The device circuit 112 is further configured to execute an update function 126, which is configured to update the current content of the data storage 114 to the new current content of the data storage 114 when detected by the event detection function 122 indicating the activation of the security-sensitive function of the electronic device 110. The update is performed according to the update function based on the current content and values ​​of the data storage 114. Furthermore, the electronic device 110 and / or the data storage 114 should be configured such that, without privileged access, the current content of the data storage 114 can only be updated using the update function.

[0041] The data storage 114 may be implemented by a persistent (or non-resettable) platform configuration register (PCR), which may be located, for example, in a trusted platform module (TPM) (not shown) of an electronic device 110. The TPM may be a hardware TMP of a so-called firmware TPM (fTPM), which is a software implementation of TPM functionality. Generally, the PCR may be located in a dedicated hardware block (security subsystem). Alternatively, the PCR may be located within other types of secure element hardware.

[0042] The update function should be irreversible; that is, it should not be possible to perform further updates by the update function so that the content of the data storage is the same as before the update. Furthermore, the update function must be collision-tolerant; that is, for a sufficiently long retrieved value, the update function must ensure that the new current content is substantially always different from the current content. "Substantially always" means that the probability that the new current content is the same as the updated current content is small enough to have no practical impact. The retrieved value should not be previously known to the electronic device 110, and when the update follows a collision-tolerant update function, it must be long enough so that the new current content is substantially always different from the current content. For example, 16 bytes is sufficient.

[0043] The update function 126 may be configured to update the current content of the data storage by extending it with a value. In this case, the update function 126 concatenates the value with the current content of the data storage 114 and hashes the concatenation of the value with the current content of the data storage 114 using a known hash function. The data storage 114 is then updated so that the hashed concatenation of the value with the current content of the data storage 114 becomes the new current content of the data storage 114. The known hash function must be collision-resistant and may be, for example, SHA-2, SHA-3, BLAKE2, SM3, or GHOST. Other alternative forms are also included, such as including a counter in the concatenation whose counter is incremented each time the data storage is updated. The order of the arguments to be hashed can be as follows:

[0044] The device circuit 112 is further configured to perform a device transfer function 128, which is configured to transfer the new current content of the data storage 114 to the verification module 150.

[0045] The management module 130 includes a management module circuit 132 configured to perform the functions of the management module 130.

[0046] Specifically, the management module circuit 132 is configured to perform a management module value acquisition function 142 configured to acquire a value. The management module value acquisition function 142 may also be configured to determine a value, i.e., the value is determined in the management module 130. The value may be, for example, a random nonce, i.e., any number that can be used only once in encrypted communication. The management module circuit 132 may then be further configured to perform a value transfer function (not shown) configured to transfer the value to an electronic device 110. The device value acquisition function 124 is then configured to receive a value from the management module 130.

[0047] The management module circuit 132 is further configured to perform an expected new current content determination function 144, which is configured to determine the expected new current content of the data storage 114 according to an update function, based on the known original content and values ​​of the data storage 114.

[0048] The management module circuit 132 may be further configured to perform a known original content retrieval function (not shown) configured to retrieve known original content from the data storage 114.

[0049] The expected new current content determination function may be further configured to hash the concatenation of a value and the known original content of data storage 114 using a known hash function, and to determine that the expected new current content of data storage 114 is the hashed concatenation of a value and the known original content of data storage 114.

[0050] In a scenario where the known original content of data storage 114 is that data storage 114 was initially empty, the expected new current content determination function 144 may be configured to hash the value using a known hash function and determine that the expected new current content of data storage 114 is the hashed value. "Empty" means that updating the data storage using the function results in a new current content that is the same as if the function had been performed on a value only. Empty can mean, for example, that the current content of data storage is NULL, such as "" (an empty string) or one or more "0". Empty may also mean that the current content of data storage is marked as uninitialized, in which case the function can be configured so that the new current content is the same as if the function had been performed on a value only.

[0051] The management module circuit 132 is further configured to perform a management module transfer function 146, which is configured to transfer the expected new current content of the data storage 114 to the verification module 150.

[0052] The verification module 150 includes a verification module circuit 152 configured to perform a comparison function 162 which is configured to compare the new current content of the data storage 114 with the expected new current content of the data storage 114.

[0053] The verification module circuit 152 is further configured to execute a notification generation function 164, which is configured to generate a security notification when it determines that the new current content of the data storage 114 is different from the expected new current content of the data storage 114.

[0054] The device circuit 112, the management module circuit 132, and the verification module circuit 152 may each include a processor (not shown), such as a central processing unit (CPU), a microcontroller, or a microprocessor. The processor may be configured to execute program code. The program code may be configured to execute, for example, the functions of the electronic device 110, the management module 130, and the verification module 150, respectively.

[0055] The electronic device 110, the management module 130, and the verification module 150 may further comprise their respective memories (not shown). The memory may be one or more of a buffer, flash memory, hard drive, removable media, volatile memory, non-volatile memory, random access memory (RAM), or other suitable devices. In a typical configuration, the memory may include non-volatile memory for long-term data storage and volatile memory functioning as system memory. The memory can exchange data with associated circuitry via a data bus. Accompanying control lines and address buses may exist between the memory and associated circuitry.

[0056] The functions of the electronic device 110, the management module 130, and the verification module 150 can each be embodied in the form of executable logic routines (e.g., lines of code, software programs, etc.) that are stored on their respective non-temporary computer-readable media (e.g., memory) and executed by the device circuit 112, the management module circuit 132, and the verification module circuit 152, respectively (e.g., using a processor). Furthermore, the functions of the electronic device 110, the management module circuit 132, and the verification module circuit 152 may be standalone software applications or may form part of a software application that performs additional tasks related to the electronic device 110, the management module 130, and the verification module 150, respectively. The functions described can be considered as methods configured to be executed by a processing unit, such as a processor. While the functions described can be implemented in software, such functions may also be executed via dedicated hardware or firmware, or any combination of hardware, firmware, and / or software.

[0057] Figure 2 is a flowchart of an embodiment of method 200 for notifying when the security-sensitive function of an electronic device 110 has been previously enabled, the electronic device 110 comprising a data storage 114 having current content. This method can be implemented in the system 100 described in relation to Figure 1.

[0058] Method 200 enables unreliable delivery of the electronic device 110 from the manufacturer to the customer. Furthermore, Method 200 is useful, for example, when the electronic device 110 enables a factory default function that results in the erasure of all changes in an insecure writable file system.

[0059] As an example, method 200 may be performed in connection with the initial boot of the electronic device 110 by a customer user to whom the electronic device 110 has been delivered. In such a scenario, the electronic device 110 may be connected to a network such as the Internet. The management client may be implemented on a cloud-based server in, for example, a management module 130, as described in relation to Figure 1, and may retrieve information related to the public key infrastructure (PKI) of the electronic device 110. When the electronic device 110 is connected to the network and started up, it can start up in a state waiting for a root password (or administrator password) to be set. The password management function in the management client prompts the user to set a root password. The user can then set the root password. Setting such a root password is an event that indicates that the security sensitive function of the electronic device 110 has been enabled.

[0060] Method 200 includes a first set of steps performed in the electronic device 110. An event indicating the activation of the security-sensitive function of the electronic device 110 is detected in the electronic device 110 (S210). Upon detecting the event indicating the activation of the security-sensitive function of the electronic device 110 (S210), the electronic device 110 obtains a value previously unknown to the electronic device 110 (S220), updates the current content of the data storage 114 with the new current content of the data storage 114 (S230), and transfers the new current content of the data storage 114 to the verification module 150 (S240). The current content of the data storage 114 is updated with the new current content of the data storage 114 according to the update function based on the current content and value of the data storage 114 (S230). The update (S230) is required in the electronic device 110 when the event is detected (S210). Therefore, if an event indicating the activation of the security-sensitive function of the electronic device 110 is detected (S210), an update (S230) is always performed. Furthermore, without privileged access, the current content of the data storage 114 can only be updated using the update function. Therefore, other updates to the data storage 114 are impossible without privileged access, and the content of the data storage 114 cannot be tampered with by an unauthorized user. Privileged access may be authenticated, for example, by the private key of the electronic device 110.

[0061] Updating the current content of data storage 114 to the new current content of data storage 114 (S230) according to an update function based on the current content and value of data storage 114 may include concatenating the value with the current content of data storage 114 and hashing the concatenation of the value with the current content of data storage 114 using a known hash function. The current content of data storage 114 is then updated so that the hashed concatenation of the value with the current content of data storage 114 becomes the new current content of data storage 114. Of course, alternative methods for updating the current content of data storage 114 to the new current content of data storage 114 (S230) are also possible.

[0062] Method 200 may further include checking in the electronic device 110 that the new current content of the data storage 114 is different from the current content of the data storage 114 before the update, in order to ensure that the update was successful. If the known original content of the data storage 114 was that the data storage 114 was empty, the check may consist of checking that the data storage 114 is not empty after the update, in order to ensure that the update was successful.

[0063] Method 200 further includes a second set of steps performed in the management module 130. The value is retrieved in the management module 130 (S250), the expected new current content of the data storage 114 is determined according to the update function based on the known original content and value of the data storage 114 (S260), and the expected new current content of the data storage 114 is transferred from the management module 130 to the verification module 150. It should be noted that retrieving the value in the management module 130 (S250) does not need to be after the new current content has been transferred from the electronic device 110 (S240). Instead, retrieval (S250) may be performed at any time earlier.

[0064] In the management module 130, determining the expected new current content of the data storage 114 should use the same update function used in the electronic device 110 to update the current content to the new current content. Therefore, determining the expected new current content of the data storage 114 may involve concatenating a value with the known original content of the data storage 114, and then hashing the concatenation using a known hash function. Next, it is determined that the expected new current content of the data storage 114 is the hashed concatenation of the value of the data storage 114 and the known original content.

[0065] The transfer of the new current content of the data storage 114 by the electronic device 110 to the verification module 150 may be preceded by a request from the management module 130. Furthermore, the value obtained by the electronic device 110 may be a value such as a random nonce determined by the management module 130. By determining the value in the management module 130, the determined value can be controlled in the management module 130, and therefore the management module 130 can guarantee that the value is not previously known in the electronic device 110.

[0066] Transferring the new current content of data storage 114 to verification module 150 may further include signing the new current content using the private key of electronic device 110 via the TPM of electronic device 110. The verification module 150 may then have previously received the public key corresponding to the private key of electronic device 110, which is authenticated by a certificate issued by a Certificate Authority (CA). Thus, the verification module 150 can use the private key of electronic device 110 used for signing to verify that the new current content of data storage 114 was indeed received from electronic device 110.

[0067] The previously unknown value to electronic device 110 may also be used to verify that the read of the new current content of data storage 114 received by the verification module 150 is actually a read of data storage 114 made in response to a currently detected (S210) event indicating the activation of security-sensitive features of electronic device 110. This can be done by adding the retrieved value in electronic device 110 to the new current content of data storage 114, having the TPM of electronic device 110 sign the new current content of data storage 114 plus the retrieved value with the private key of electronic device 110, and then forwarding it to the management module 130. For example, the previously unknown value to electronic device 110 may be further forwarded from the management module 130 to the verification module 150 in the form of a nonce determined in the management module 130 and forwarded to electronic device 110. Next, the verification module 150 can check the acquired value received from the management module 130 by comparing it with the acquired value in the newly signed current content of the data storage 114 plus the acquired value received from the electronic device 110.

[0068] In addition to knowing the update function used by the electronic device 110 to update the current content of the data storage 114, the known original content of the data storage 114 of the electronic device 110 needs to be retrieved by the management module 130 to determine the expected new current content. The known original content can be retrieved within the management module 130 in different ways depending on how the original content is known. For example, the original content may be known in that the data storage 114 is always empty at first. The management module 130 can then assume that the data storage 114 is empty at first. The known original content of the data storage 114 may further depend on the hardware type, version, etc. In such cases, the management module 130 may include a table showing the known original content for each hardware type, version, etc., and then retrieve the hardware type, version, etc. of the electronic device 110 and identify the known original content from the table. The hardware type, version, etc. are retrieved from the electronic device 110 within the management module 130 and may preferably be signed by the TPM of the electronic device 110 using the private key of the electronic device 110. If the known original content of the data storage 114 is unique to each individual electronic device 110, the management module 130 may need to retrieve information from the electronic device 110 that identifies each individual electronic device 110, and then retrieve the known original content of the data storage 114 from the database.

[0069] Method 200 further includes a third set of steps performed in the verification module 150. The new current content of the data storage 114 received by the verification module 150 is compared with the expected new current content of the data storage 114 received by the management module 130 (S280). If it is determined that the new current content of the data storage 114 is different from the expected new current content of the data storage 114, a security notification is generated in the verification module 150 (S290). The security notification may then be sent from the verification module 150 to the management module 130, which can then notify the user of the electronic device 110 that the security sensitive function of the electronic device 110 has been previously enabled. Alternatively, the security notification may be sent directly from the verification module 150 to the user.

[0070] Figure 3 is a flowchart of another embodiment of method 300 for notifying when the security sensitive function of an electronic device 110 has been previously enabled, wherein the electronic device 110 includes a data storage 114 with current content.

[0071] Method 300 enables unreliable delivery of the electronic device 110 from the manufacturer to the customer. Furthermore, Method 300 is useful, for example, when the electronic device 110 allows a factory default function to erase all changes in an insecure writable file system.

[0072] Method 300 utilizes the same concepts as Method 200 described in relation to Figure 2, namely, when an event indicating the activation of the security-sensitive function of the electronic device 110 is detected, the current content of the data storage 114 is updated according to the update function, and unless privileged access is available, the current content of the data storage 114 can only be updated using the update function, and previous activations of the security-sensitive function of the electronic device 110 are detectable based on the current state of the data storage 114. Method 300 can be implemented in a system similar to the system 100 described in relation to Figure 1, which may include a management module 130, but does not necessarily have to. Method 300 can also be used in relation to the same scenario as described in relation to Figure 2.

[0073] Method 300 includes a first set of steps in the electronic device 110. An event indicating the activation of the security-sensitive function of the electronic device 110 is detected in the electronic device 110 (S310). Upon detection of the event, the current content of the data storage 114 is transferred to the verification module 150 (S320). Next, an unknown value is obtained in the electronic device 110 (S330), and the current content of the data storage 114 is updated to the new current content of the data storage 114 according to the update function based on the current content and value of the data storage 114 (S340). The update (S340) is required in the electronic device 110 when the event is detected (S310). Therefore, if an event indicating the activation of the security-sensitive function of the electronic device 110 is detected (S310), the update (S340) is always performed. Without privileged access, the current content of the data storage 114 can only be updated using the update function.

[0074] Method 300 further includes a second set of steps within the verification module 150. In step S320, the current content of the data storage 114 received from the electronic device 110 is compared with the known original content (S350). The known original content may be obtained in the verification module 150 in a different way, such as disclosed for Method 200 in relation to Figure 2. If it is determined that the current content of the data storage 114 received from the electronic device 110 is different from the known original content of the data storage 114, a security notification is generated by the verification module 150 (S360). The security notification may then be sent from the verification module 150 to the management module 130, which can then notify the user of the electronic device 110 that the security sensitive function of the electronic device 110 has been previously enabled. Alternatively, the security notification may be sent directly from the verification module 150 to the user.

[0075] The difference between Method 300 and Method 200, as described in relation to Figure 2, is that instead of transferring the new current content of the data storage 114, i.e., the content after updating according to the update function, from the electronic device 110 to the verification module 150 (S240), the current content before updating according to the update function (S340) is transferred to the verification module (S320). Since the update by the update function (S340) must be performed when the electronic device 110 detects an event indicating the activation of the security sensitive function of the electronic device 110 (S310), the current content of the data storage 114 is equal to the known original content only if such an event has not been previously detected. Therefore, the verification module 150 can compare the current content of the data storage 114 received from the electronic device 110 with the known original content of the data storage 114 to determine whether the security sensitive function of the electronic device 110 was previously activated.

[0076] The steps of Method 300 may be further adapted as corresponding steps of Method 200 as described in relation to Figure 2.

[0077] Method 300 may further include checking in the electronic device 110 that the new current content of the data storage 114 is different from the current content of the data storage 114 before the update, in order to ensure that the update was successful. If the known original content of the data storage 114 was that the data storage 114 was empty, the check may consist of checking that the data storage 114 is not empty after the update, in order to ensure that the update was successful.

[0078] The transfer of the current content of the data storage 114 to the verification module 150 (S320) may be preceded by a request from the management module 130. Furthermore, the value obtained in the electronic device 110 may be a value such as a random nonce determined in the management module 130. By determining the value in the management module 130, the determined value can be controlled in the management module 130, and therefore the management module 130 can ensure that the value is not previously known in the electronic device 110.

[0079] Transferring the current content of data storage 114 to verification module 150 (S320) may further include signing the current content using the private key of electronic device 110 by the TPM of electronic device 110. The verification module 150 may then have previously received the public key corresponding to the private key of electronic device 110, and the public key is authenticated by a certificate issued by a Certificate Authority (CA). Thus, the verification module 150 can use the private key of electronic device 110 used for signing to verify that the current content of data storage 114 was actually received from electronic device 110.

[0080] A previously unknown value in electronic device 110 may also be used to verify that the read of the current content of data storage 114 received by the verification module 150 is, in fact, a read of data storage 114 made in response to a currently detected (S310) event indicating the activation of security-sensitive features of electronic device 110. This can be done by adding the retrieved value in electronic device 110 to the current content of data storage 114, having the TPM of electronic device 110 sign the sum of the current content of data storage 114 and the retrieved value with the private key of electronic device 110, and then transferring it to the verification module 150 directly or via the management module 130. The management module 130 can then transfer the retrieved value to the verification module 150. The verification module 150 can then check the retrieved value received from the management module 130 by comparing it with the sum of the retrieved value in the signed current content of data storage 114 and the retrieved value received from electronic device 110.

[0081] The known original content of the data storage 114 of the electronic device 110 needs to be retrieved in the verification module 150 for comparison with the current content received from the electronic device 110. The known original content can be retrieved in the verification module 150 in different ways depending on how the original content is known. For example, the original content may be known in that the data storage 114 is always empty at first. The verification module 150 can then assume that the data storage 114 is empty at first. The known original content of the data storage 114 may further depend on the hardware type, version, etc. In such a case, the verification module 150 may include a table showing the known original content for each hardware type, version, etc., and then retrieve the hardware type, version, etc., of the electronic device 110 and identify the known original content from the table. The hardware type, version, etc., are retrieved from the electronic device 110 in the management module 130 and may preferably be signed by the TPM of the electronic device 110 using the private key of the electronic device 110. If the known original content of the data storage 114 is unique to each individual electronic device 110, the management module 130 may need to retrieve information from the electronic device 110 that identifies each individual electronic device 110, and then retrieve the known original content of the data storage 114 from the database.

[0082] Figure 4 is a schematic block diagram of an embodiment of the electronic device 110 for enabling notification when the security-sensitive functions of the electronic device 110 have been previously enabled. Events indicating the activation of the security-sensitive functions of the electronic device 110 may include, for example, setting a root password or setting an administrator password. Further events indicating the activation of security-sensitive functions include enabling debugging software functions, enabling hardware debugging functions such as JTAG access, scan chain, boundary scan or other DFT logic, and accessing onboard tokens to cloud services. The electronic device 110 comprises a data storage 114 with current content and a device circuit 112. The device circuit 112 is configured to perform the functions of the device 110.

[0083] Specifically, the device circuit 112 is configured to perform a detection function 122 that is configured to detect events indicating the activation of security-sensitive functions of the electronic device 110.

[0084] The device circuit 112 is further configured to execute a device value acquisition function 124, which is configured to acquire a previously unknown value from the electronic device 110 when an event detection function detects that an event indicating the activation of a security-sensitive function of the electronic device 110 is detected. The device value acquisition function 124 may be configured to receive values ​​from, for example, a management module 130.

[0085] The device circuit 112 is further configured to execute an update function 126, which is configured to update the current content of the data storage 114 to the new current content of the data storage 114 when detected by the event detection function 122 indicating the activation of the security-sensitive function of the electronic device 110. The update is performed according to the update function based on the current content and values ​​of the data storage 114. Furthermore, the electronic device 110 and / or the data storage 114 should be configured such that, without privileged access, the current content of the data storage 114 can only be updated using the update function.

[0086] The data storage 114 may be implemented by a persistent (or non-resettable) platform configuration register (PCR), which may be located, for example, in a trusted platform module (TPM) (not shown) of an electronic device 110. The TPM may be a hardware TMP of a so-called firmware TPM (fTPM), which is a software implementation of TPM functionality. Generally, the PCR may be located in a dedicated hardware block (security subsystem). Alternatively, the PCR may be located within other types of secure element hardware.

[0087] The update function 126 may be configured to concatenate the value of the data storage 114 with the current content, hash the concatenation of the data storage value and the current content using a known hash function, and update the data storage 114 so that the hashed concatenation of the data storage value and the current content becomes the new current content of the data storage 114.

[0088] The electronic device 110 generally enables notification that the security-sensitive features of the electronic device have been previously activated. To achieve notification, the device circuit 112 may be further configured to perform a device transfer function 128 configured to transfer the new current contents of the data storage 114 to a separate module, such as the management module 130 described in relation to Figure 1. The management module 130, together with the verification module 150, may include functions for generating notifications as described further in relation to Figure 1.

[0089] The device circuit 112 may include a processor 116, such as a central processing unit (CPU), a microcontroller, or a microprocessor. The processor 116 may be configured to execute program code. The program code may be configured, for example, to perform the functions of the electronic device 110.

[0090] The electronic device 110 may further comprise a memory 120. The memory 120 may be one or more of a buffer, flash memory, hard drive, removable media, volatile memory, non-volatile memory, random access memory (RAM), or another suitable device. In a typical configuration, the memory 120 may include non-volatile memory for long-term data storage and volatile memory serving as system memory for the device circuit 112. The memory 120 can exchange data with the device circuit 112 via a data bus. Accompanying control lines and an address bus may also exist between the memory 120 and the circuit 112.

[0091] The functions of the electronic device 110 may be embodied in the form of executable logic routines (e.g., lines of code, software programs, etc.) that are stored on the non-temporary computer-readable medium of the device 110 (e.g., memory 120) and executed by the device circuit 112 (e.g., using the processor 116). Furthermore, the functions of the electronic device 110 may be standalone software applications or may form part of a software application that performs additional tasks related to the electronic device 110. The functions described can be considered as methods configured to be executed by a processing unit, such as the processor 116 of the device circuit 112. While the functions described may be implemented in software, such functions may also be executed via dedicated hardware or firmware, or any combination of hardware, firmware, and / or software.

[0092] The function of the electronic device 110 can be further adapted to the corresponding function of the electronic device 110 described in relation to Figure 1.

[0093] Figure 5 is a flowchart of an embodiment of method 500 for enabling notifications when the security-sensitive functions of electronic device 110 have been previously enabled. Events indicating the activation of the security-sensitive functions of electronic device 110 may include, for example, setting a root password or setting an administrator password. Further events indicating the activation of security-sensitive functions include enabling debugging software functions, enabling hardware debugging functions such as JTAG access, scan chain, boundary scan or other DFT logic, and accessing onboard tokens to cloud services. Upon detecting an event indicating the activation of the security-sensitive functions of electronic device 110 (S210), electronic device 110 obtains a value previously unknown to electronic device 110 (S520), updates the current content of data storage 114 with the new current content of data storage 114 (S530), and transfers the new current content of data storage 114 to verification module 150 (S540). The current content of data storage 114 is updated to the new current content of data storage 114 according to an update function based on the current content and values ​​of data storage 114 (S530). The update is required in electronic device 110 when an event is detected (S510). Therefore, if an event indicating the activation of the security sensitive function of electronic device 110 is detected (S510), the update is always performed. Furthermore, without privileged access, the current content of data storage 114 can only be updated using the update function. Therefore, other updates to data storage 114 are impossible without privileged access, and the content of data storage 114 cannot be tampered with by an unauthorized user. Privileged access may be authenticated, for example, by the private key of electronic device 110.

[0094] Updating the current content of data storage 114 to the new current content of data storage 114 (S530) according to an update function based on the current content and value of data storage 114 may include concatenating the value with the current content of data storage 114 and hashing the concatenation of the value with the current content of data storage 114 using a known hash function. The current content of data storage 114 is then updated so that the hashed concatenation of the value with the current content of data storage 114 becomes the new current content of data storage 114. Of course, alternative methods for updating the current content of data storage 114 to the new current content of data storage 114 (S530) are also possible.

[0095] Method 500 may further include checking in the electronic device 110 that the new current content of the data storage 114 is different from the current content of the data storage 114 before the update, in order to ensure that the update was successful. If the known original content of the data storage 114 was that the data storage 114 was empty, the check may consist of checking that the data storage 114 is not empty after the update, in order to ensure that the update was successful.

[0096] Method 500 may further include transferring the new current content of the data storage 114 to the verification module 150 (S540). The transfer of the new current content of the data storage 114 to the verification module 150 may be preceded by a request from the management module 130. Furthermore, the value obtained in the electronic device 110 may be a value such as a random nonce determined in the management module 130. By determining the value in the management module 130, the determined value can be controlled in the management module 130, and therefore the management module 130 can ensure that the value is not previously known in the electronic device 110.

[0097] Transferring the new current content of the data storage 114 to the verification module 150 (S540) may further include signing the new current content using the private key of the electronic device 110 by the TPM of the electronic device 110. The verification module 150 may then have previously received the public key corresponding to the private key of the electronic device 110, and the public key is authenticated by a certificate issued by a Certificate Authority (CA). Thus, the verification module 150 can use the private key of the electronic device 110 used for signing to verify that the new current content of the data storage 114 was actually received from the electronic device 110.

[0098] The previously unknown value to electronic device 110 may also be used to verify that the read of the new current content of data storage 114 received by the verification module 150 is, in fact, a read of data storage 114 made in response to a currently detected (S510) event indicating the activation of the security-sensitive function of electronic device 110. This can be done by adding the acquired value in electronic device 110 to the new current content of data storage 114, having the TPM of electronic device 110 sign the new current content of data storage 114 plus the acquired value with the private key of electronic device 110, and then transferring it to the management module 130. For example, the acquired value previously unknown to electronic device 110 may be further transferred from the management module 130 to the verification module 150 in the form of a nonce determined in the management module 130 and transferred to electronic device 110. Next, the verification module 150 can check the acquired value received from the management module 130 by comparing it with the acquired value in the newly signed current content of the data storage 114 plus the acquired value received from the electronic device 110.

[0099] The steps of Method 500 may be further adapted as corresponding steps of Method 200 as described in relation to Figure 2.

[0100] Those skilled in the art will understand that the present invention is not limited to the embodiments described above. Conversely, many modifications and variations are possible within the scope of the appended claims. Such modifications and variations can be understood and achieved by those skilled in the art in carrying out the claimed invention, based on a study of the drawings, disclosures, and the appended claims.

Claims

1. 1. A method (500) for enabling notification if a security-sensitive feature of an electronic device has been previously enabled, the electronic device comprising: In the electronic device, Detecting an event indicative of activation of a security-sensitive feature of the electronic device (S210; S510); upon detecting the event indicative of activation of a security-sensitive feature of the electronic device; Obtaining a value previously unknown to the electronic device (S220; S520); updating the current content of the data storage to a new current content of the data storage according to an update function based on the current content of the data storage and the value (S230; S530), where in the absence of privileged access, the current content of the data storage can only be updated using the update function, and the update function is irreversible and collision-resistant; A method comprising:

2. 10. A method for further notifying if a security-sensitive feature of the electronic device has been previously enabled, the method comprising: In the electronic device, upon detecting the event indicative of activation of a security-sensitive feature of the electronic device; Transferring the new current contents of the data storage to a verification module (S240); In the Administration module: Obtaining the value (S250); determining (S260) the expected new current content of said data storage based on said known original content of said data storage and said value according to said update function; transferring the expected new current content of the data storage to the verification module (S270); In the verification module, comparing the new current content of the data storage with the expected new current content of the data storage (S280); generating a security notification upon determining that the new current content of the data storage differs from the expected new current content of the data storage (S290); The method of claim 1 further comprising:

3. In the electronic device, updating the current content of the data storage with new current content of the data storage (S230; S530) comprises: concatenating said value with said current contents of said data storage; hashing the concatenation of the value and the current contents of the data storage using a known hash function; updating the current contents of the data storage such that the hashed concatenation of the value and the current contents of the data storage is the new current contents of the data storage; The method of claim 2 , comprising:

4. In the management module, determining (S260) the expected new current content of the data storage includes: provided that the known original content of the data storage is that the data storage was initially empty; hashing the value using the known hash function; determining the expected new current contents of the data storage to be hashed to the value; Otherwise, obtaining the known original content of the data storage; hashing the concatenation of the value and the known original contents of the data storage using the known hash function; determining the expected new current contents of the data storage to be the hashed concatenation of the value and the known original contents of the data storage; The method of claim 3, comprising:

5. In the management module, obtaining (250) the value includes determining the value, and further includes, in the management module, transferring the value to the electronic device; The method of claim 2 , wherein, in the electronic device, obtaining the value (S220; S520) comprises receiving the value from the management module.

6. The method of claim 1 , wherein the event indicative of enabling a security-sensitive feature of the electronic device comprises one of setting a root password and setting an administrator password.

7. In the electronic device, upon detecting the event indicative of activation of a security-sensitive feature of the electronic device; Transferring the current contents of the data storage to a verification module (S320); In the verification module, generating a security notification upon determining that the current content of the data storage received from the electronic device differs from the known original content of the data storage (S360); The method of claim 1 , comprising:

8. An electronic device (110), comprising: a data storage (114) with current content; a device circuit (112), the device circuit comprising: a detector (122) configured to detect an event indicative of activation of a security-sensitive feature of the electronic device (110); a device value retrieval function configured to retrieve a value not previously known to the electronic device upon detecting the event indicating activation of a security-sensitive feature of the electronic device; an update function configured, upon detecting the event indicating activation of a security-sensitive feature of the electronic device, to update the current content of the data storage with new current content of the data storage according to an update function based on the current content of the data storage and the value, wherein, in the absence of privileged access, the current content of the data storage can only be updated using the update function, and the update function is irreversible and collision-resistant; 2. An electronic device configured to:

9. A system (100) for notifying if a security-sensitive feature of an electronic device has been previously enabled, comprising: An electronic device (110) according to claim 8; a management module (130); a verification module (150); The device circuit (112) further configured to execute a device transfer function (128) configured to transfer the new current content of the data storage to the verification module; The management module (130) a management module value retrieval function (142) configured to retrieve said value; an expected new current content determination function (144) configured to determine expected new current content of said data storage according to said update function based on said known original content of said data storage and said value; a management module transfer function (146) configured to transfer the expected new current content of the data storage to the verification module; a management module circuit (132) configured to perform The verification module (150) a comparison function (162) configured to compare the new current content of the data storage (114) with the expected new current content of the data storage (114); a notification generator (164) configured to generate a security notification upon determining that the new current content of the data storage (114) differs from the expected new current content of the data storage (114); A system (100) comprising a verification module circuit (152) configured to perform:

10. The update function (126) concatenating said value with said current contents of said data storage (114); hashing the concatenation of the value and the current contents of the data storage (114) using a known hash function; updating the data storage (114) such that the hashed concatenation of the value and the current contents of the data storage (114) is the new current contents of the data storage (114); The system (100) of claim 9, further configured to:

11. The known original content of the data storage (114) is that the data storage (114) was initially empty, and the expected new current content determiner (144) is hashing the value using the known hash function; determining that the expected new current contents of the data storage (114) are the hashed value; The system (100) of claim 10, configured to:

12. The management module circuit (132) further configured to execute a known origin content retrieval function configured to retrieve known origin content of the data storage (114); The anticipated new current content determination function: hashing the concatenation of the value and the known original contents of the data storage (114) using the known hash function; determining the expected new current content of the data storage (114) to be the hashed concatenation of the value and the known original content of the data storage (114); The system (100) of claim 10, configured to:

13. 10. The system of claim 9, wherein the management module value retrieval function is configured to determine the value, the management module circuit is further configured to execute a value transfer function configured to transfer the value to the electronic device, and the device value retrieval function is configured to receive the value from the management module.

14. 10. The system of claim 9, wherein the event indicative of an activation of a security-sensitive feature of the electronic device comprises one of setting a root password and setting an administrator password.

15. A non-transitory computer-readable storage medium storing instructions for implementing the method of claim 2 when executed on the system of claim 9 or the method of claim 1 when executed on the electronic device of claim 8.