Method of resetting communications module
A method using a reset tool and wireless RF protocols securely resets communications modules in utility meter networks, addressing the challenge of reconfiguration by bypassing SCPI commands and enabling efficient, secure remote resets.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- LANDIS GYR TECH INC
- Filing Date
- 2025-10-13
- Publication Date
- 2026-04-23
AI Technical Summary
Existing communications modules in utility meter networks are difficult to reconfigure or reset, especially when securely configured, often requiring vendor-specific SCPI commands and inaccessible to end-users.
A method involving a reset tool that communicates with a network module to obtain data, generate and authenticate a reset indicator, and securely reset the communications module using wireless RF protocols, bypassing the need for SCPI commands.
Enables secure and efficient resetting of communications modules across geographically distributed networks without requiring end-user intervention, ensuring secure configuration changes and facilitating professional on-site operations.
Smart Images

Figure US2025050664_23042026_PF_FP_ABST
Abstract
Description
[0001] METHOD OF RESETTING COMMUNICATIONS MODULE
[0002] FIELD OF INVENTION
[0003] The present disclosure relates to reconfiguring or resetting communications modules, such as those employed in utility meter networks. The present disclosure relates particularly but not exclusively to performing a factory reset of a communications module for a network of endpoint meters using wireless communication, such as radiofrequency (RF).
[0004] BACKGROUND TO INVENTION
[0005] Electronic equipment may be required to be reset from time to time, particularly if transferred from one user to another.
[0006] Endpoint utility meters, such as electrical, gas, water, or other utility meters are often connected within a communications network, such as in advanced metering infrastructure (AMI). Such networks may comprise a head-end system (HES) for communicating with the endpoint meters. It is known to have communications modules at various points in the network to manage data transfer between the meters and the HES.
[0007] In at least some cases, there are problems associated with re-configuring, or resetting, the communications modules.
[0008] There are situations in the field of use where various factors, such as faulty meter communication modules or specific end-user requirements necessitate the removal of existing communication modules. However, because the communication modules remain intact, they must undergo a reset (e.g. to factory mode). This reset can include clearing current configurations and security associated with the previous customer's location. In some examples, if these communication modules are configured securely, customers cannot reset them without accessing SCPI (Standard Commands for Programmable Instruments) securely, a capability typically restricted by vendors once communication modules are shipped.
[0009] In some examples, the reconfiguring or resetting of the communication modules will not typically be achievable by the end-user. The present inventors have appreciated the challenge of reconfiguring or performing factory resets on communication modules at customer sites or other locations.
[0010] It is therefore an aim of at least one embodiment of at least one aspect of the present disclosure to obviate or at least mitigate at least one of the above identified shortcomings of the prior art.
[0011] SUMMARY OF INVENTION
[0012] According to a first aspect of the disclosure, there is provided a method of resetting a communications module, the communications module configured for use with an endpoint meter, the method comprising: obtaining, by a reset tool from a network module, first data associated with the communications module; providing a first reset request from the reset tool to the communications module, the first reset request being based at least in part on the first data; validating, by the communications module, the first reset request; generating, by the communications module, a reset indicator based at least in part on the first reset request; obtaining, by the reset tool from the communications module, the reset indicator; providing the reset indicator from the reset tool to the network module; authenticating, by the network module, the reset indicator; providing, by the reset tool, the authenticated reset indicator to the communications module; validating, by the communications module, the authenticated reset indicator; and resetting the communications module.
[0013] The network module may be at least a part of a head-end system (HES). The network module or HES may be operable to communicate with a plurality of endpoint devices, such as endpoint meters, endpoint electrical power meters, endpoint gas meters, endpoint water meters, or other endpoint utility meters or endpoint devices. The communications module may be configured for transferring and / or receiving datato / from at least one endpoint meter and / or to / from the network module, or HES. The meters may be smart meters, or the like. The communications module may be for an advanced metering infrastructure (AMI) network. The method may be carried out when the network module is geographically remote from the communications module. The method may be carried out when the reset tool is spaced apart from the communications module. The resetting of the communications module may be a full or partial reset. In some examples, the resetting may mean restarting or rebooting the communications module and in other examples the resetting may mean partial resetting of at least one setting of the module, or full resetting of substantially all the settings thereof. The resetting may be to default setting(s), such as a factory reset.
[0014] The reset tool may be configured to communicate with the network module and / or the communications module by a wireless communication method, such as a radiofrequency (RF) protocol. The network module may be configured to communicate with the reset tool by a wireless communication method, such as an RF protocol. The RF protocol may include at least one of amplitude, frequency or phase modulation methods and may include analog and / or digital encoding / decoding.
[0015] Any one or all of the steps of the method involving data transfer between at least two of: the network module, the reset tool and the communications module may be by the wireless communication method, optionally an RF protocol.
[0016] The communications module may be configured to communicate meter data to the network module, which may be through wired and / or wireless communication, optionally using one or more wireless or wired communication protocols, such as cellular / mobile network, Ethernet, a power line communication (PLC) method, or the like.
[0017] The reset tool may comprise one or more computing devices, such as a laptop computer, desktop computer, a distributed computing system, a tablet computer, a cellular / mobile phone (e.g. a smartphone), or any suitable computing device. The reset tool may comprise a communications element. The communications element may be a communications adapter configured to enable communications to / from the computing device to / from the network module and the communications module. The communications element may be configured to transmit / receive data to / from the network module and communication module using a first wireless or wired communication method. The first wireless communication method may be by the RF protocol. The communications element may be configured to transmit / receive data to / from the computing device by way of a second wireless or wired communication method. The second communication method may be a serial communication method, a wireless communication protocol, a short-range wireless communication protocol (e.g. Bluetooth (RTM)), or any suitable method.
[0018] The communications module may be reversibly connectable to the endpoint meter. The communications module may be integrated with, or connectable to, or separately formed from the endpoint meter. The method may comprise the step of removing the communications module from the endpoint meter. The removal step may be carried out before providing the first reset request. The communications module may be configured for a partial reset when connected to the meter. The method may comprise removing the communications module when a full reset is to be performed on the communications module.
[0019] The communications module may be configured to obtain meter data from the meter, optionally through a wired and / or wireless connection.
[0020] The communications module may be configured to communicate meter data to the network module, which may be through wired and / or wireless communication, optionally using one or more wireless or wired communication protocols, such as cellular / mobile network, Ethernet, a power line communication (PLC) method, or the like.
[0021] The communications module may be configured for use between the electrical power meter and the rest of the network. The communications module may be configured to be the final network component before the meter.
[0022] The method may comprise bringing the reset tool in proximity to the communications module, optionally within about 100m, or within about 10m, or within any suitable working distance.
[0023] The step of obtaining the first data may comprise sending a connection request to the network module from the reset tool. A connection request response from the network module to the reset tool may include a network security key to authenticate the connection.
[0024] The first data may comprise parameter data associated with the communication module. At least a part of the first data may be configured to be unique to the communication module.
[0025] The first parameter data may include at least one of: device ID, unique device identification data, time data, such as an expiry date of the current reset request or a date by when the communication module should be maintained, replaced or decommissioned, a reset flag, such as a partial or full reset flag, or any suitable parameter data. The device ID may be a serial number such as a local area network (LAN) ID, or the like.
[0026] The step of providing the first reset request may include establishing a connection from the reset tool to the communications module.
[0027] The first reset request may include at least a part of the first data and / or data based at least in part on the first data. The first reset request may comprise some or all of the first parameter data. The first reset request may be an initial reset request to initialise the resetting of the communications module.
[0028] The step of validating the first reset request may comprise verifying that the communications module is not currently communicating with the endpoint meter. In some examples, this may be when the communications module is not obtaining and / or transmitting meter data from the meter or to the network module, or in other examples, when the communications module is not communicating with the meter. In some examples, this may be when the communications module is removed from the meter.
[0029] The step of validating the first reset request may comprise validating the first data. In some examples the first parameter data may be validated. The step of validating the first reset request may comprise validating the device ID.
[0030] The reset indicator may be a reset token. The reset token may be generated using a cryptographic tokenisation method. The reset token may be a randomized data token. The reset token may be generated through any suitable algorithm. In some examples, this may be by a mathematically reversible cryptographic function or one-way irreversible cryptographic function, or through randomly generated token values, which may be stored in look-up tables. The reset token may be substantially irreversible or substantially reversible. The reset token may be configured to be substantially undecipherable. The reset token may be configured to have or convey no intrinsic information. The reset token may be configured to lack data about the communications module or the meter, or any meaningful data.
[0031] The communications module may be configured, upon receipt of a valid first reset request, to generate the reset indictor.
[0032] The reset indicator may be generated based on the first data or the first parameter data.
[0033] The step of generating the reset indicator may comprise adding integrity thereto. The communications module may comprise a module key for adding the integrity to the reset indicator, or reset token. The network module may comprise a corresponding module key for verifying the integrity of the reset indicator, or reset token. The module key of the network module may be configured for verifying the integrity added by a module key of the communications module.
[0034] The integrity may mitigate or ensure that the reset indicator has not been modified, e.g. by a third party.
[0035] The step of authenticating the reset indicator may be carried out entirely by the network module, optionally entirely by the head-end system. The step of authenticating the reset indicator may be a step of adding authenticity to the reset indictor.
[0036] The step of authenticating the reset indicator may comprise obtaining, by the network module, the first data corresponding to the reset indicator. The step of authenticating the reset indicator may comprise obtaining at least a part of the first data from the reset indicator or stored data associated with the reset request for that communications module.
[0037] The step of authenticating the reset indicator may comprise verifying that the communications module is permitted to be reset. This permission may be included in any suitable manner, such as in data associated with the matching reference reset indicator.
[0038] The step of authenticating the reset indicator may comprise verifying at least some of the first data, or parameter data, to confirm that resetting can occur. The verification of the parameter data may include verifying that the date of resetting is within the expiry date of the reset indicator.
[0039] The step of authenticating the reset indicator may comprise carrying out an integrity check of the reset indicator. The network module may use the module key to carry out the integrity check of the reset indicator.
[0040] The network module may comprise a key for signing the reset indicator, which may be a private key.
[0041] The step of authenticating the reset indicator may comprise signing the reset indicator by the network module. The network module may use the private key to sign the reset indicator. The step of signing the reset indicator may add authenticity thereto. The signature may be an electronic signature, such as a digital signature, which may be a cryptographic digital signature.
[0042] The, or each key at the communications module may be a public key. The signing key and / or the module key at the network module may be private keys. The signing key and the module key may be substantially secure in the network module.
[0043] The step of authenticating the reset indicator may comprise one or more data logging steps (e.g. for auditing). The data logging step may include logging the first reset request.
[0044] The step of authenticating the reset indicator may comprise one or more notification steps. The notification step may include the reset request, and may take any suitable form, such as by email or the like. The notification step may include notifying a security function, such as a security monitoring apparatus or station, with details of the reset request. The step of providing the authenticated reset indicator to the communications module may be a reset complete request step, for commencing the resetting of the communications module.
[0045] The step of validating the authenticated reset indicator by the communications module may comprise verifying the authenticity of the reset indicator, optionally by checking the signature thereof. The communications module may comprise a public key for verifying the signature of the reset indicator.
[0046] The communications module may use a key thereof to verify the authenticity of the reset indicator, which may be the public key.
[0047] The private signing key of the network module and the public key of the communications module may form a public private key pair.
[0048] The step of resetting the communications module may be carried out by the communications module once the authenticated reset indicator has been validated.
[0049] The step of resetting the communications module may be a partial or full reset, optionally a factory reset.
[0050] The method may comprise a step of providing, from the communications module to the reset tool, an indication that the reset operation has or will commence.
[0051] The method may comprise the step of starting the communications module once reset. The method may comprise providing, from the reset tool, to the communications module, a start signal. The step of starting the communications module may include starting the communications module in an unlocked partial, or full, or factory reset configuration.
[0052] The step of resetting the communications module may include restarting the communications module one or more times.
[0053] The steps of the method may be carried out in any order unless the context provides otherwise.
[0054] According to a second aspect of the disclosure, there is provided a method of configuring a communications module from a first configuration to a second configuration, the method comprising: providing a first request to the communications module to transition to the second configuration; receiving, from the communications module, a first identifier associated with the first request; authenticating the first identifier; providing the authenticated first identifier to the communications module; and configuring the communications module in the second configuration.
[0055] The second configuration may be a reset configuration.
[0056] The communication module may be configured for communicating with an endpoint device, or endpoint meter, such as an endpoint utility meter, endpoint electrical power meter, endpoint gas meter, endpoint water meter, or the like.
[0057] The method may comprise providing a reconfiguration tool, which may be a reset tool.
[0058] The steps of the method may be carried out in any order unless the context provides otherwise.
[0059] According to a third aspect of the disclosure, there is provided a system operable to reset a communications module, the communications module configured for use with an endpoint meter, the system comprising: a reset tool; a network module; wherein the reset tool is operable to obtain, from the network module, first data associated with the communications module; wherein the reset tool is operable to provide a first reset request to a communications module, the first reset request being based at least in part on the first data; wherein the reset tool is operable to obtain a reset indicator from the communications module; wherein the reset tool is operable to provide the reset indicator to the network module; wherein the network module is operable to authenticate the reset indicator; and wherein the reset tool is operable to provide the authenticated reset indicator to the communications module.
[0060] According to a fourth aspect of the disclosure, there is provided a communications module configured for use with an endpoint meter, wherein the communications module is configured to validate a first reset request when received from a reset tool; wherein the communications module is configured to generate a reset indicator based at least in part on the first reset request; wherein the communications module is configured or operable to provide the reset indicator to the reset tool; and wherein the communications module is configured to reset when an authenticated reset indicator is received from the reset tool.
[0061] The above summary is intended to provide examples and be non-limiting. The disclosure includes one or more corresponding aspects, embodiments or features in isolation or in various combinations whether or not specifically stated (including claimed) in that combination or in isolation. It should be understood that features defined above in accordance with any aspect of the present disclosure or below relating to any specific embodiment of the disclosure may be utilized, either alone or in combination with any other defined feature, in any other aspect or embodiment or to form a further aspect or embodiment of the disclosure.
[0062] BRIEF DESCRIPTION OF DRAWING
[0063] These and other aspects of the present disclosure will now be described, by way of example only, with reference to the accompanying drawing, wherein:
[0064] Figure 1 depicts a schematic system and method in accordance with an embodiment of the invention.
[0065] DETAILED DESCRIPTION OF DRAWING
[0066] Embodiments of the invention will now be described with reference to Figure 1 , which depicts an example system and method in accordance with at least one embodiment of the invention.
[0067] In Figure 1 , a method of configuring a communications module from a first configuration to a second configuration is shown, the method comprising: providing a first request to the communications module to transition to the second configuration; receiving, from the communications module, a first identifier associated with the first request; authenticating the first identifier; providing the authenticated first identifier to the communications module; and configuring the communications module in the second configuration. In the specific example of Figure 1 , the second configuration is a reset configuration. The steps of the method shown in Figure 1 will be described in more detail once the system components have been described.
[0068] At least one advantage of one or more embodiments of the invention is that the communications module can be reconfigured or reset without requiring the use of instrument programming commands, such as SCPI commands (Standard Commands for Programmable Instruments). Another benefit of one or more examples is that reconfiguring, or resetting can be carried out more securely through sending an initial request, generating an identifier, authenticating the identifier, validating the identifier, and then reconfiguring / restarting the communications module.
[0069] Another benefit of one or more examples is through the use of wireless communication to do the reconfiguring or resetting, as it facilitates a professional travelling with, for example, a reset tool to sites to then efficiently carry out the required steps of the method.
[0070] Another advantage of one or more embodiments is that the method facilitates logging and notifying of requests. Given that meter infrastructure may be associated with the risk of sabotage and the like, the ability to react to malicious reconfiguration or reset requests is thought to be advantageous in at least some scenarios.
[0071] In terms of the system components, in the embodiment of Fig. 1 , the communication module is configured for communicating with, and is reversibly connectable to an endpoint device, such as an electrical power meter, gas meter, water meter (examples of utility meters), or the like. In other embodiments, the communications module may be integrated with, or connectable to, or separately formed from the endpoint device. In some examples, the communications module is configured to obtain meter data from the meter through a wired or wireless connection or combination thereof, depending on the implementation.
[0072] In the example of Fig. 1 , the network module is at least a part of a head-end system (HES). The HES is operable to communicate with a plurality of endpoint devices, which may be electrical power meters or other utility meters or other device, and for brevity of explanation one meter is shown in Figure 1 . The communications module is configured for transferring and / or receiving data to / from at least one endpoint electrical meter and / or to / from the HES, although it will be understood that the communications module may communicate with other endpoint devices whether directly or indirectly and may communicate with other network modules besides a HES. The meters are smart meters. The communications module is for an advanced metering infrastructure (AMI) network formed of a HES, meters, communications modules, and any suitable network infrastructure.
[0073] The communications module is configured to communicate meter data to the network module (e.g. the HES), which may be through any suitable wired and / or wireless communication method, such as cellular / mobile network, Ethernet, a power line communication (PLC) method, or the like. In some embodiments, the communications module is configured for use between the end point device (e.g. the electrical power meter) and the rest of the network. In the example of Figure 1 , the communications module is configured to be the final network component before the meter. However, in other embodiments, the communications module could be designed for use anywhere within the advanced metering infrastructure. The endpoint meter of Fig. 1 need not be the final endpoint of a branch of the network, and the term endpoint will be understood in the context of advanced metering infrastructure as referring to meters at the consumption side of the network for capturing usage data and the like, and it is possible that the endpoint meter may communicate with further endpoint devices.
[0074] In the example of Fig. 1 , the reset tool is configured to communicate with the network module (e.g. the HES) and the communications module by a radiofrequency (RF) protocol. The network module is configured to communicate with the reset tool by an RF protocol. The RF protocol may include at least one of amplitude, frequency or phase modulation methods and may include analog and / or digital encoding / decoding, although any suitable communication method between the parts of the system may be employed, including wired and / or wireless means, and other wireless communication methods either as an alternative to RF or in combination therewith.
[0075] Although the term reset tool is used, it will be appreciated that in some embodiments the tool may be a reconfiguration tool or other such wording, but the term reset tool is used for ease of reference.
[0076] In the example of Fig. 1 , the reset tool comprises a computing device (such as a laptop computer) and a communications adapter configured to enable communications to / from the computing device to / from the network module and the communications module. In other embodiments, the reset tool may be implemented in other ways, and it will be understood that other computing devices could be used, such as a tablet computer, desktop computer, a distributed computing system (e.g. cloud computing), and / or a cellular / mobile phone (e.g. a smartphone), or any suitable computing device, or the like. In various embodiments, the communications adapter transmits / receives data to / from the network module (e.g. HES) and the communications module using a first wireless communication method (e.g. RF) and transmits / receives data to / from the computing device by way of a second wireless or wired communication method, which can be a serial communication method, a wireless communication protocol, a short- range wireless communication protocol (e.g. Bluetooth (RTM)). However, any suitable communication method(s) may be employed.
[0077] Turning now to the steps of the method, Figure 1 shows a method of resetting a communications module, the communications module configured for use with an endpoint meter. Although one meter is shown, the communications module may be operable to communicate with more than one endpoint meter.
[0078] In some examples, the method depicted in Fig. 1 includes bringing the reset tool in proximity to the communications module, for example within about 100m, or within about 10m, or within any suitable working distance. These are purely examples and the skilled person would readily appreciate that this step might be unnecessary depending on the implementation, and the example distances are purely illustrative. In practice, it may not be the end-user of the communications module that carries out the reconfiguring thereof. It is likely in at least some cases to be carried out by another party travelling to the end-user’s site, as the network of meters will typically cover a large geographical area at the municipal, state, country, or larger scale. However, in some cases the reconfiguring may be carried out from one location, such as a central location, depending on the distances and devices involved.
[0079] In some embodiments, the method includes removing the communications module from the endpoint meter. This may be necessary in some examples, if a full reset is to be carried out, or deemed unnecessary in the event of a partial reset, but these are non-limiting examples. The communications module may be configured for a partial reset when connected to the meter. The method may comprise removing the communications module when a full reset is to be performed on the communications module.
[0080] Once the reset tool has been brought on site (if necessary) and the communications module removed (if necessary), the method comprises the step of obtaining, by the reset tool from the network module, first data associated with the communications module. This step includes sending a connection request to the HES from the reset tool. The HES issues a connection request response that includes a network security key to authenticate the connection. It will be understood that the step of obtaining first data may be carried out in other ways, and this method of data transfer is purely an example. The first data comprises parameter data associated with the communication module, and at least a part of the first data is configured to be unique to the communication module, at least in respect of the components of the metering infrastructure.
[0081] In the embodiment of Figure 1 , the first parameter data includes a device ID, unique device identification data, time data, such as an expiry date of the current reset request or a date by when the communication module should be maintained, replaced or decommissioned, a reset flag, such as a partial or full reset flag, or any suitable parameter data. The device ID can be a serial number such as a local area network (LAN) ID or the like.
[0082] Next, a first reset request is provided from the reset tool to the communications module, the first reset request being based at least in part on the first data and the parameter data. The step of separating the communications module from the meter is carried out before providing the first reset request, if required. The step of providing the first reset request includes establishing a connection from the reset tool to the communications module.
[0083] In the embodiment of Figure 1 , the first reset request includes the device ID, unique identifier, expiry date of the request, and data indicating whether a full or partial reset is requested. The first reset request can include some or all of the first parameter data. The first reset request is an initial reset request to initialise the resetting of the communications module, as further steps are used to reconfigure the communications module, as shown in Fig. 1.
[0084] Next, the communications module validates the first reset request, which includes verifying that the communication module is not currently communicating with the endpoint meter. In some examples, this may be when the communication module is not obtaining and / or transmitting meter data from the meter or to the HES, or in other examples, when the communication module is not communicating with the meter. In some examples, this may be when the communications module is removed from the meter.
[0085] The step of validating the first reset request includes validating the first data, and parameter data, that is part of the first reset request. In the embodiment of Fig. 1 the LAN ID is verified, which is the device serial number, as well as the device ID, the expiry date and the type of reset required (full or partial).
[0086] Once the first reset request is validated, the communications module generates a reset token (an example of a reset indicator) based at least in part on the first reset request. The generation of the reset token will now be described in detail before turning back to the main method of Figure 1 .
[0087] The reset token is generated using a cryptographic tokenisation method. The reset token is generated through any suitable algorithm. In some embodiments, this may be by a mathematically reversible cryptographic function or one-way irreversible cryptographic function, or through randomly generated token values, which may be stored in look-up tables. In the embodiment of Figure 1 . The reset token is a byte payload that is substantially reversible by the HES. The reset token is configured to lack data about the communications module or the meter, or any meaningful data. These features of the reset indicator are thought to be advantageous as it keeps sensitive data hidden.
[0088] The communications module is configured, upon receipt of a valid first reset request, to generate the reset token.
[0089] The reset token is generated based on the first data and the first parameter data.
[0090] The use of tokens based on the principles of tokenisation is an example, and other methods are possible, such as encryption and the like. In other embodiments, the reset indicator may take another form, and it may be use an alternative to cryptography or other sophisticated techniques.
[0091] The step of generating the reset token comprises adding integrity thereto. The communications module comprises a module key for adding integrity to the token. The HES comprises a corresponding module key for verifying the integrity of the reset token. The module key of the HES is configured to be substantially secure in the HES. In the network of Fig. 1 , some or all of the communications modules have embedded module keys for generating the reset tokens. The module key of the communications module is kept in a secure location thereof.
[0092] Turning back to the steps of the method of Figure 1 , the reset tool obtains the reset token from the communications module and provides the reset token to the HES where the reset token is authenticated by the HES by verifying the integrity thereof.
[0093] The step of authenticating the reset token is carried out entirely by the HES in the example of Fig. 1.
[0094] The step of authenticating the reset token includes obtaining at least a part of the first data stored against the reset request.
[0095] The step of authenticating the reset token comprises verifying that the communications module is permitted to be reset. In the embodiments illustrated and described here, this permission is included in the data associated with the matching reference reset indicator held at the HES. The step of authenticating the reset token comprises verifying at least some of the first data, or parameter data, to confirm that resetting can occur. The verification of the parameter data may include verifying that the date of resetting is within the expiry date of the reset token. This is to mitigate or prevent replay attacks.
[0096] In the embodiment of Figure 1 , the step of authenticating the reset token comprises carrying out an integrity check of the reset token by using the module key to carry out the integrity check of the reset token.
[0097] The step of authenticating the reset token comprises signing the reset token by the HES using a private key to sign the reset token, which adds authenticity thereto. The addition of the signature may be represented in any suitable manner. The signature is a cryptographic digital signature, but other types and methods of signing can be employed. The private key is held securely at the HES.
[0098] The step of authenticating the reset indicator comprises data logging (e.g. for auditing), including logging the reset request, and one or more notification steps. The notification step includes the reset request, and may take any suitable form, such as notification (e.g. by email or the like) to a security function, such as a security monitoring apparatus or station, with details of the reset request.
[0099] Next, the reset tool provides the authenticated reset indicator to the communications module. This is a reset complete request step, for commencing the resetting of the communications module. The communications module validates the authenticated reset token which comprises verifying the authenticity of the reset token by checking the signature thereof using the public key (of the communications module). The private key of the HES, used for signing, and the public key of the communications module, used for checking the signature, form a public private key pair. These are examples and other methods may be used.
[0100] Next, once the authenticated reset token is validated, the communications module resets. The resetting of the communications module may be a full or partial reset. In some examples, the resetting may mean restarting or rebooting the communications module and other examples the resetting may mean partial resetting of at least one setting of the module, or full resetting of substantially all the settings thereof. The resetting may be to default setting(s), such as a factory reset.
[0101] In the embodiment of Figure 1 , the communications module provides to the reset tool an indication that the reset operation has or will commence.
[0102] Next, the method comprises the step of starting the communications module once reset by providing, from the reset tool to the communications module, a start signal. The step of starting the communications module includes starting the communications module in an unlocked partial, or full, or factory reset configuration.
[0103] The step of resetting the communications module may include restarting the communications module one or more times.
[0104] In the embodiment of Figure 1 , the method can be carried out when the HES is geographically remote from the communications module. The method can be carried out when the reset tool is spaced apart from the communications module. In some embodiments, any one or all of the steps of the method involving data transfer between at least two of: the network module, the reset tool and the communications module may be by the wireless communication method, optionally an RF protocol.
[0105] It will be understood that in other embodiments, there may be a different sequence of steps of the method unless the context provides otherwise.
[0106] Although the disclosure has been described in terms of embodiments as set forth above, it should be understood that these embodiments are illustrative only and that the claims are not limited to those embodiments. Those skilled in the art will be able to make modifications and alternatives in view of the disclosure, which are contemplated as falling within the scope of the appended claims. Each feature disclosed or illustrated in the present specification may be incorporated in any embodiments, whether alone or in any appropriate combination with any other feature disclosed or illustrated herein.
Claims
CLAIMS:
1. A method of resetting a communications module, the communications module configured for use with an endpoint meter, the method comprising: obtaining, by a reset tool from a network module, first data associated with the communications module; providing a first reset request from the reset tool to the communications module, the first reset request being based at least in part on the first data; validating, by the communications module, the first reset request; generating, by the communications module, a reset indicator based at least in part on the first reset request; obtaining, by the reset tool from the communications module, the reset indicator; providing the reset indicator from the reset tool to the network module; authenticating, by the network module, the reset indicator; providing, by the reset tool, the authenticated reset indicator to the communications module; validating, by the communications module, the authenticated reset indicator; and resetting the communications module.
2. The method of claim 1 , wherein the network module is at least a part of a headend system (HES) operable to communicate with a plurality of endpoint meters, and the communications module is configured for transferring and / or receiving data to / from at least one meter and / or to / from the HES.
3. The method of claim 1 or claim 2, wherein the reset tool is configured to communicate with the network module and / or the communications module by a wireless communication method, such as a radiofrequency (RF) protocol.
4. The method of any preceding claim, wherein the method comprises the step of removing the communications module from the meter.
5. The method of any preceding claim, wherein the step of obtaining the first data comprises sending a connection request to the network module from the reset tool.
6. The method of any preceding claim, wherein the first data comprises parameter data associated with the communication module, and includes at least one of: device ID, unique device identification data, time data, such as an expiry date of the current reset request or a date by when the communication module should be maintained, replaced or decommissioned, a reset flag, such as a partial or full reset flag.
7. The method of claim 6, wherein the first reset request comprises some or all of the first parameter data.
8. The method of any preceding claim, wherein the step of validating the first reset request comprises validating the first data.
9. The method of any preceding claim, wherein the reset indicator is a cryptographically generated reset token, generated based on the first data or the first parameter data.
10. The method of any preceding claim, wherein the step of authenticating the reset indicator comprises verifying that the communications module is permitted to be reset.
11. The method of any preceding claim, wherein the step of generating the reset indicator comprises adding integrity thereto, and wherein the step of authenticating the reset indicator comprises carrying out an integrity check of the reset indicator.
12. The method of any preceding claim, wherein the step of authenticating the reset indicator comprises signing the reset indicator by the network module to add authenticity thereto.
13. The method of any preceding claim, wherein the step of validating the authenticated reset indicator by the communications module comprises verifying the authenticity of the reset indicator.
14. The method of claim 13, wherein the step of resetting the communications module is carried out by the communications module once the authenticated reset indicator has been validated.
15. The method of any preceding claim, wherein the resetting of the communications module is a full reset, such as a factory reset, or a partial reset.
16. The method of any preceding claim, wherein the method comprises a step of providing, from the communications module to the reset tool, an indication that the reset operation has or will commence.
17. The method of claim 15 or claim 16, wherein the method comprises providing, from the reset tool, to the communications module, a start signal and wherein the method comprises a step of starting the communications module in an unlocked, partial or full, or factory reset, configuration.
18. A method of configuring a communications module from a first configuration to a second configuration, the method comprising: providing a first request to the communications module to transition to the second configuration; receiving, from the communications module, a first identifier associated with the first request; authenticating the first identifier; providing the authenticated first identifier to the communications module; configuring the communications module in the second configuration.
19. A system operable to reset a communications module, the communications module configured for use with an endpoint meter, the system comprising: a reset tool; a network module;wherein the reset tool is operable to obtain, from the network module, first data associated with the communications module; wherein the reset tool is operable to provide a first reset request to a communications module, the first reset request being based at least in part on the first data; wherein the reset tool is operable to obtain a reset indicator from the communications module; wherein the reset tool is operable to provide the reset indicator to the network module; wherein the network module is operable to authenticate the reset indicator; and wherein the reset tool is operable to provide the authenticated reset indicator to the communications module.
20. A communications module configured for use with an endpoint meter, wherein the communications module is configured to validate a first reset request when received from a reset tool; wherein the communications module is configured to generate a reset indicator based at least in part on the first reset request; wherein the communications module is configured or operable to provide the reset indicator to the reset tool; and wherein the communications module is configured to reset when an authenticated reset indicator is received from the reset tool.
Citation Information
Patent Citations
Router reset methods and devices
CN105530129B
Smart meter device refurbishment
GB2607298A
Smart meter communication device
JP7043239B2
Collecting utility data information and conducting reconfigurations, such as demand resets, in a utility metering system
US20100176967A1