1. In a metering environment configured with devices for executing computer-executable instructions, a method of securely accessing a meter from a mobile meter reader, the method comprising:
issuing a request for authorization to access the meter, the request for authorization being issued from the mobile meter reader to a host computing system;
if the mobile meter reader maintains sufficient rights to access the meter, receiving an authorization from the host computing system having a digital signature that uniquely identifies an authorized entity, the digital signature being provided without distributing a private key used for encoding the digital signature to the mobile meter reader; and
formulating and transmitting an authorization command to the meter from the mobile meter reader, wherein the authorization command includes the digital signature received from the host computing system.
2. The method as recited in claim 1, further comprising decoding the digital signature at the meter, determining whether the digital signature is authentic, and if the digital signature is authentic establishing a secure session between the meter and the mobile meter reader.
3. The method as recited in claim 2, wherein encrypted data is transmitted between the meter and mobile meter reader during the secure session.
4. The method as recited in claim 1, wherein the authorization command is formulated to leverage a public key on the meter used for authenticating communications performed over a fixed network to decode the digital signature.
5. The method as recited in claim 1, wherein issuing a request for authorization to access the meter from the mobile meter reader includes identifying a unique identifier associated with the meter that is scheduled to be accessed from the mobile meter reader.
6. The method as recited in claim 1, wherein the request for authorization is issued to the host computing system dynamically over an IP-based network connection.
7. The method as recited in claim 1, wherein the request for authorization is issued to the host computing system as a batch process that identifies multiple meters scheduled to be accessed.
8. The method as recited in claim 1, wherein the authorization to access the meter provided by the host computing system is configured to terminate after a pre-determined period of time.
9. The method as recited in claim 1, wherein the authorization provided by the host computing system is configured with an access level that defines which procedures on the meter that may be activated by the mobile meter reader.
10. A system to prevent an unauthorized entity from tampering with a meter, the system comprising:
at least one host computing device configured to receive a request for authorization to access the meter from a mobile meter reader and provide a digital signature to the mobile meter reader that uniquely identifies an authorized entity if the mobile meter reader has sufficient rights to access the meter;
a mobile meter reader operative to request authorization to access the meter, receive a digital signature generated by the host computing device, and formulate an authorization command for transmission to the meter to activate a secure procedure of the meter;
a meter configured to decode the digital signature and allow activation of the secure procedure if the digital signature is authentic; and
wherein activation of the secure procedure occurs without providing the mobile meter reader with access to a private key that is used to encode the digital signature.
11. The system as recited in claim 10, wherein the host computing device maintains a centralized data store for tracking which meters may be accessed by the mobile meter reader.
12. The system as recited in claim 10, wherein an access level is defined in the authorization provided by the host computer system and wherein the meter is further configured to determine whether the mobile meter reader has sufficient access rights to activate the secure procedure.
13. The system as recited in claim 10, wherein the authentication command includes a time stamp and wherein the meter is further configured to compare the time stamp provided by the mobile meter reader with a predetermined time window to determine whether the digital signature generated by the host computing system expired.
14. The system as recited in claim 10, wherein the authentication command formulated by the mobile meter reader includes a meter serial number and the meter is further configured to compare an actual serial number with the serial number provided by the mobile meter reader.
15. A mobile meter reader configured to exchange secure communications with a meter, comprising:
a processor;
an interface for communicating data between the mobile meter reader and a host computing system;
a radio-based communication device for communicating data between the mobile meter reader and a meter;
a computer-readable media having computer-executable instructions that, when executed by the processor, cause the mobile meter reader to:
request and receive authorization from the host computing system to access the meter;
formulate an authorization command for transmission to the meter having a digital signature encoded at the host computing system; and
establish a secure session with the meter, wherein a key used by the mobile meter reader to encode data during the secure session is separate from a private key used at the host computing system to encode the digital signature.
16. The mobile meter reader as recited in claim 15, wherein the authentication command formulated by the mobile meter reader is configured to leverage the asymmetric public key used for decoding communications received by the meter over a fixed network to decode the digital signature.
17. The mobile meter reader as recited in claim 15, wherein the digital signature for accessing the meter is obtained dynamically over an IP-based network in response to interacting with the meter in the field.
18. The mobile meter reader as recited in claim 15, wherein the digital signature for accessing the meter is obtained as a batch process that identifies multiple meters scheduled to be accessed.
19. The mobile meter reader as recited in claim 15, wherein to formulate the authorization command includes satisfying a password-protected login procedure with the meter.
20. The mobile meter reader as recited in claim 15, wherein the authorization command includes at least a current time stamp, an authorization level, and a unique identifier associated with the meter being accessed.
The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.
1. A manufacturing method of a semiconductor device comprising the steps of:
forming a first insulating film over a semiconductor substrate;
forming a first conductive film, a dielectric film, and a second conductive film in order on the first insulating film;
forming an upper electrode of a capacitor by patterning the second conductive film;
patterning the dielectric film to leave under the upper electrode;
forming a lower electrode of the capacitor by patterning the first conductive film;
covering the capacitor and the first insulating film with a second insulating film;
annealing at least one of the first insulating film and the second insulating film in an inert-gas atmosphere; and
exposing at least one of the first insulating film and the second insulating film, which is annealed, to an N2O plasma.
2. A manufacturing method of a semiconductor device according to claim 1, wherein the inert-gas atmosphere is an N2 atmosphere.
3. A manufacturing method of a semiconductor device according to claim 1, wherein an annealing temperature in annealing at least one of the first insulating film and the second insulating film in the inert-gas atmosphere is set in a range of 500 to 700\xb0 C.
4. A manufacturing method of a semiconductor device according to claim 1, wherein a pressure in the inert-gas atmosphere is an atmospheric pressure.
5. A manufacturing method of a semiconductor device according to claim 1, wherein the inert-gas atmosphere is formed in a furnace.
6. A manufacturing method of a semiconductor device according to claim 1, further comprising the step of:
planarizing at least one surface of the first insulating film and the second insulating film before annealing is executed in the inert-gas atmosphere.
7. A manufacturing method of a semiconductor device according to claim 6, wherein the surface is planarized by a chemical mechanical polishing method.
8. A manufacturing method of a semiconductor device according to claim 1, wherein an N2 plasma is contained in the N2O plasma.
9. A manufacturing method of a semiconductor device according to claim 1, wherein the semiconductor substrate is heated at 350 to 400\xb0 C. in exposing at least one of the first insulating film and the second insulating film to the N2O plasma.
10. A manufacturing method of a semiconductor device according to claim 1, wherein a pressure of the atmosphere in which the N2O plasma is generated is set in a range of 1 to 5 Torr.
11. A manufacturing method of a semiconductor device according to claim 1, wherein the dielectric film is a film that contains lead zirconate titanate or Bi-layered structure compound.
12. A manufacturing method of a semiconductor device according to claim 1, wherein a titanium film or a titanium oxide film is formed between the lower electrode and the first insulating film.
13. A manufacturing method of a semiconductor device according to claim 1, further comprising the step of:
forming a capacitor protection insulating film to cover the capacitor before the second insulating film is formed.
14. A manufacturing method of a semiconductor device according to claim 13, wherein the capacitor protection insulating film is formed of any one of a lead zirconate titanate film, an alumina film, and a titanium oxide film.
15. A manufacturing method of a semiconductor device according to claim 1, wherein a transistor that is covered with the first insulating film is formed on the semiconductor substrate.