UWB secret key transmission method and related device
The ultra-wideband transmission key is obtained and transmitted through the central processor, which solves the complex and costly connection between UWB chips and security chips, and realizes the flexible combination and secure transmission of security chips and UWB chips.
Patent Information
- Application Number
- CN202410141571.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-31
- Publication Date
- 2025-08-01
AI Technical Summary
In the prior art, hardware bus connection is required between UWB chips and security chips and preset keys or certificates, resulting in high and complex production costs of electronic equipment.
Obtain ultra-wideband transmission keys through the central processor and transmit them securely to the UWB chip, avoiding presetting symmetric keys or digital certificates on the production line, and achieving a flexible combination of security chips and UWB chips.
It reduces the production cost and complexity of electronic devices, and realizes flexible combination and secure transmission of UWB chips and security chips.
Smart Images

Figure CN120416756A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of ultra-wideband communication technology, and in particular, to a UWB key transmission method and related devices. Background Art
[0002] With the application of ultra-wideband (UWB) communication technology, some electronic devices are equipped with UWB chips. The UWB chips can perform ranging and positioning through UWB technology, enabling electronic devices to achieve application scenarios such as automatically unlocking the car door when approaching and automatically starting the vehicle when approaching. In these application scenarios, during the ranging and positioning process of the UWB chips, it is necessary to ensure the security of ranging and positioning. Therefore, UWB needs to use the UWB session key (URSK) to deduce and encrypt the transmission of parameters during the ranging and positioning process. To ensure the security of the URSK, generally, the URSK is generated in the secure chip (SEChip) of the electronic device. During the ranging process of the UWB chip, the secure chip of the electronic device can establish a secure transmission channel on the bus connection between the secure chip and the UWB chip, and transmit the URSK to the UWB chip through the secure transmission channel. However, a hardware bus connection is required between the secure chip and the UWB chip in the electronic device, and certificates or keys used to establish the secure transmission channel need to be prefabricated in the UWB chip and the secure chip respectively before the electronic device leaves the factory, making the implementation of chip software and hardware on the electronic device relatively complex and the production cost of the electronic device relatively high. Summary of the Invention
[0003] This application provides a UWB key transmission method and related devices, which realizes the secure transmission of the URSK from the UWB chip of the electronic device to the UWB chip through the central processing unit, enabling the secure chip and the UWB chip to be flexibly combined without strong binding.
[0004] In a first aspect, this application provides a UWB key transmission method, which is applied to an electronic device. The electronic device includes a central processing unit, a UWB chip, and a secure chip. The processor is connected to the UWB chip, and the processor is connected to the secure chip. The method includes: the central processing unit obtains an ultra-wideband transmission key and stores the ultra-wideband transmission key in the secure chip, where the target ultra-wideband ranging session key URSK is stored in the secure chip; the secure chip encrypts the target URSK into first encrypted data using the ultra-wideband transmission key; the secure chip sends the first encrypted data to the UWB chip through the central processing unit, where the ultra-wideband transmission key is stored in the UWB chip; the UWB chip decrypts the target URSK from the first encrypted data using the ultra-wideband transmission key, and the target URSK is used for ranging of the UWB chip.
[0005] Through a UWB key transmission method provided by this application, a UWB chip can securely transmit the URSK to the UWB chip through a central processing unit, without pre-setting the same symmetric key or the digital certificates of both parties in the UWB chip and the security chip of the electronic device in advance on the production line. Thus, the security chip and the UWB chip in the electronic device can be flexibly combined without strong binding, saving the production cost of the electronic device.
[0006] In a possible implementation manner, the central processing unit obtains the ultra-wideband transmission key, specifically including: the central processing unit obtains the ultra-wideband transmission key sent by the server. In this way, it is not necessary to pre-set the ultra-wideband transmission key in the security chip before the electronic device leaves the factory, but to request the server to issue the ultra-wideband transmission key, thereby reducing the production cost of the electronic device.
[0007] In a possible implementation manner, before the central processing unit obtains the ultra-wideband transmission key sent by the server, the method further includes: the central processing unit obtains the manufacturer identifier of the UWB chip and the chip identifier of the UWB chip from the UWB chip; the central processing unit sends a first request to the server, and the first request carries the manufacturer identifier of the UWB chip and the chip identifier of the UWB chip, and the first request is used to request the server to generate the ultra-wideband transmission key based on the root key, the manufacturer identifier of the UWB chip, and the chip identifier of the UWB chip. In this way, the ultra-wideband transmission key is derived through the manufacturer identifier of the UWB chip, the chip identifier of the UWB, and the root key, which can ensure that different electronic devices use different ultra-wideband transmission keys, guarantee the uniqueness of the ultra-wideband transmission key for the electronic device, and thus ensure the security of the URSK transmission.
[0008] In a possible implementation manner, before the central processing unit obtains the ultra-wideband transmission key, the method further includes: before the electronic device leaves the factory, the UWB chip exports the manufacturer identifier of the UWB chip and the chip identifier of the UWB chip to an encryption machine, and the encryption machine is used to generate the ultra-wideband transmission key based on the root key, the manufacturer identifier of the UWB chip, and the chip identifier of the UWB chip; the UWB chip receives the ultra-wideband transmission key imported by the encryption machine. In this way, it is only necessary to pre-set the ultra-wideband transmission key in the UWB chip on the production line, without pre-setting the ultra-wideband transmission key in the security chip, thereby decoupling the UWB chip and the security chip, and enabling the UWB chip and the security chip not to be forcibly bound.
[0009] In a possible implementation, before the ultra-wideband (UWB) chip stores the ultra-wideband transmission key, the method further includes: the UWB chip generates a first public key and a first private key, and the first public key and the first private key are a pair of public and private keys; the UWB chip sends the first public key to the central processing unit (CPU); after the CPU obtains the ultra-wideband transmission key sent by the server, the CPU encrypts the ultra-wideband transmission key into second encrypted data using the first public key; the CPU sends the second encrypted data to the UWB chip; the UWB chip decrypts the ultra-wideband transmission key from the second encrypted data using the first private key. In this way, it is not necessary to pre-set the ultra-wideband transmission key in the UWB chip before the electronic device leaves the factory. Instead, after the CPU obtains the ultra-wideband transmission key from the server, a secure transmission channel is established between the CPU and the UWB chip, and the ultra-wideband transmission key is securely transmitted to the UWB chip, thereby saving the production cost of the electronic device.
[0010] In a possible implementation, before the UWB chip stores the ultra-wideband transmission key, the method further includes: the UWB chip generates the ultra-wideband transmission key.
[0011] In a possible implementation, before the CPU obtains the ultra-wideband transmission key, the method further includes: the CPU generates a second public key and a second private key, and the second public key and the second private key are a pair of public and private keys; the CPU sends the second public key to the UWB chip; the CPU obtains the ultra-wideband transmission key, specifically including: the UWB chip encrypts the ultra-wideband transmission key into third encrypted data using the second public key; the UWB chip sends the third encrypted data to the CPU; the CPU decrypts the ultra-wideband transmission key from the third encrypted data using the second private key. In this way, the UWB chip can generate the ultra-wideband transmission key and establish a secure transmission channel with the CPU, so that the CPU can securely write the ultra-wideband transmission key into the secure chip, reducing the deployment cost of the server and the production cost of the electronic device.
[0012] In a possible implementation, the UWB chip generates the ultra-wideband transmission key, specifically including: the UWB chip randomly generates the ultra-wideband transmission key. In this way, it can be ensured that the ultra-wideband transmission keys used in the UWB chips of different electronic devices are different, ensuring the uniqueness of the ultra-wideband transmission key for the electronic device, and thus ensuring the security of the URSK transmission.
[0013] In a possible implementation, the UWB chip stores the manufacturer identification of the UWB chip and the chip identification of the UWB chip; the UWB chip generates the ultra-wideband transmission key, specifically including: the UWB chip generates the ultra-wideband transmission key based on the root key, the manufacturer identification of the UWB chip, and the chip identification of the UWB chip. In this way, it can be ensured that the ultra-wideband transmission keys used in the UWB chips of different electronic devices are different, ensuring the uniqueness of the ultra-wideband transmission key for the electronic device, and thus ensuring the security of the URSK transmission.
[0014] In a possible implementation, the UWB chip generates the ultra-wideband transmission key based on the root key, the manufacturer identification of the UWB chip, and the chip identification of the UWB chip, specifically including: the UWB chip generates a pairing key based on the root key and the manufacturer identification of the UWB chip; the UWB chip generates the ultra-wideband transmission key based on the pairing key and the chip identification of the UWB chip.
[0015] In a possible implementation, the security chip stores the target ultra-wideband ranging session key URSK, specifically including: the security chip generates one or more URSKs through the stored vehicle key session key, and the one or more URSKs include the target URSK; the security chip stores the one or more URSKs, where the session identifiers corresponding to different URSKs are different.
[0016] In a possible implementation, before the security chip encrypts the target URSK into the first encrypted data using the ultra-wideband transmission key, the method further includes: the UWB chip sends a URSK acquisition command to the security chip through the central processor, and the first session identifier is carried in the URSK acquisition command; after receiving the URSK acquisition command, the security chip determines the target URSK corresponding to the first session identifier from the one or more URSKs.
[0017] In a possible implementation, before the UWB chip sends a URSK acquisition command to the security chip through the central processor, the method further includes: the UWB chip sends a random number acquisition command to the security chip through the central processor; after receiving the random number acquisition command, the security chip sends a first random number to the UWB chip through the central processor; the UWB chip encrypts the first random number into an authentication ciphertext using the ultra-wideband transmission key and sends the authentication ciphertext to the security chip through the central processor; the security chip decrypts a second random number from the authentication ciphertext using the ultra-wideband transmission key; if the second random number is the same as the first random number, the security chip sends a first response to the UWB chip through the central processor, and the first response is used to indicate that the random number verification has passed; the UWB chip sends a URSK acquisition command to the security chip through the central processor, specifically including: after receiving the first response, the UWB chip sends the URSK command to the security chip through the central processor.
[0018] In a possible implementation, a rich execution environment REE and a trusted execution environment TEE are running in the central processor, and a vehicle key application is running in the REE; the central processor obtains the ultra-wideband transmission key, specifically including: the central processor obtains the ultra-wideband transmission key through the vehicle key application; the central processor stores the ultra-wideband transmission key in the security chip, specifically including: the central processor stores the ultra-wideband transmission key in the security chip through the vehicle key application and the TEE.
[0019] In a possible implementation, the UWB chip is not connected to the security chip. In this way, the UWB chip and the security chip do not need to be forcibly connected, reducing the difficulty and production cost of installing the UWB chip and the security chip into the electronic device.
[0020] In a second aspect, the present application provides a UWB key transmission method, which is applied to an electronic device. The electronic device includes a central processor, a microcontroller, a UWB chip, and a security chip. Among them, the processor is connected to the microcontroller, the processor is connected to the security chip, and the microcontroller is connected to the UWB chip; the method includes: a target URSK is stored in the security chip; the central processor obtains the target URSK from the security chip; the central processor sends the target URSK to the microcontroller; the microcontroller generates a UWB communication message based on the target URSK; the microcontroller sends the UWB communication message to the UWB chip; after receiving the UWB communication message sent by the microcontroller, the UWB chip sends the UWB communication message, and the UWB communication message is used for ranging.
[0021] In a third aspect, the present application provides an electronic device, including one or more processors, one or more memories, a security chip, and a UWB chip. The one or more processors include a central processing unit, which is connected to the UWB chip and the security chip; the one or more memories are used to store computer programs. When the one or more processors execute the computer programs, the first electronic device is caused to execute the methods in any possible implementation manner of any of the above aspects.
[0022] In a fourth aspect, the present application provides a computer storage medium, including a computer program. When the computer program runs on a processor of an electronic device, the electronic device is caused to execute the methods in any possible implementation manner of any of the above aspects.
[0023] In a fifth aspect, the present application provides a computer program product. When the computer program product runs on a processor of an electronic device, the electronic device is caused to execute the methods in any possible implementation manner of any of the above aspects.
[0024] For the beneficial effects of the above second aspect and fifth aspect, reference may be made to the beneficial effects in the above first aspect and any possible implementation manner of the first aspect, which will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 It is a schematic diagram of an application scenario of UWB ranging provided by an embodiment of the present application;
[0026] Figure 2 It is a schematic diagram of the architecture of a digital car key system provided by an embodiment of the present application;
[0027] Figure 3 It is a schematic diagram of the functional modules of the security chip and the UWB chip provided by an embodiment of the present application;
[0028] Figure 4 It is a schematic diagram of the process of a security chip transmitting URSK to a UWB chip provided by an embodiment of the present application;
[0029] Figure 5 It is a schematic diagram of the principle of a UWB key transmission method provided by an embodiment of the present application;
[0030] Figure 6 It is a schematic diagram of a UWB key transmission method provided by an embodiment of the present application;
[0031] Figure 7A It is a schematic diagram of the generation process of a pairing key provided by an embodiment of the present application;
[0032] Figure 7B It is a schematic diagram of the generation process of an ultra-wideband transmission key provided by an embodiment of the present application;
[0033] Figure 7C Schematic diagram of the transmission process of a URSK provided by an embodiment of the present application;
[0034] Figure 8 Schematic diagram of a UWB key transmission method provided by another embodiment of the present application;
[0035] Figure 9 Schematic diagram of a UWB key transmission method provided by another embodiment of the present application;
[0036] Figure 10 Schematic diagram of a UWB key transmission method provided by another embodiment of the present application;
[0037] Figure 11 Schematic diagram of the hardware structure of an electronic device provided by an embodiment of the present application;
[0038] Figure 12 Schematic diagram of the hardware structure of a server provided by an embodiment of the present application. Detailed implementation manners
[0039] The technical solutions in the embodiments of the present application will be clearly and thoroughly described below with reference to the accompanying drawings. Among them, in the description of the embodiments of the present application, unless otherwise specified, " / " means "or", for example, A / B may mean A or B; "and / or" in the text is only a description of the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B may mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of the present application, "a plurality of" means two or more than two.
[0040] Hereinafter, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as implying or suggesting relative importance or implicitly indicating the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the embodiments of the present application, unless otherwise specified, the meaning of "a plurality of" is two or more.
[0041] Figure 1 Shows a schematic diagram of an application scenario of UWB ranging provided by an embodiment of the present application.
[0042] Such as Figure 1As shown, the electronic device 100 can measure the distance between the electronic device 100 and the vehicle 200 through UWB ranging technology. When the electronic device 100 approaches the vehicle 200 and enters the unlocking area, the electronic device 100 can unlock the vehicle door of the vehicle 200 through the digital car key. Optionally, when the electronic device 100 enters the unlocking area, it can also start the vehicle 200 (for example, start the engine or power supply of the vehicle 200, etc.) through the digital car key. When the electronic device 100 gradually moves away from the unlocking area and enters the locking area, the electronic device 100 can automatically lock the vehicle door of the vehicle 200 with the digital car key. Optionally, when the electronic device 100 moves away from the unlocking area and enters the locking area, it can also turn off the engine or power supply of the vehicle 200 through the digital car key.
[0043] In this way, the user does not need to carry a physical car key. When only the electronic device 100 carrying the digital car key secret key is close to the vehicle 200, the vehicle door of the vehicle 200 can be automatically unlocked, and when away from the vehicle 200, the vehicle door of the vehicle 200 can be automatically locked.
[0044] Figure 2 It is a schematic diagram of the architecture of a digital car key system provided in an embodiment of the present application.
[0045] As Figure 2 shown, the digital car key system may include an electronic device 100 and a vehicle 200. Among them, the electronic device 100 may include a central processing unit 101, a secure chip (SE Chip) 102, and a UWB chip 103. Optionally, the electronic device 100 may further include a Bluetooth chip 104 and an NFC chip 105. The vehicle 200 may include a vehicle-end digital key (DK) authentication system 201, a vehicle control module 205, and a UWB chip 206. Optionally, the vehicle 200 may further include a Bluetooth chip 207 and an NFC chip 208.
[0046] The vehicle-end DK authentication system 201 may include an authentication control module 202, a key management module 203, and a key storage module 204. Among them, the vehicle-end DK authentication system 201 can be used to realize the secure interaction between the mobile terminal and the body control module. The key management module 203 can be used to be responsible for functions such as issuing, updating, deleting, and black and white list management. The authentication control module 202 can be used to be responsible for two-way authentication and service information interaction with the electronic device 100, as well as the control function of vehicle-end service logic. The key storage module 204 can be used to be responsible for the secure storage of basic key information. The vehicle control module 205 can be used to be responsible for controlling the vehicle body electronics or power system and executing relevant digital car key service logic.
[0047] The in-vehicle DK authentication system 201 can establish a communication connection with the electronic device 100 through short-range communication modules such as the UWB chip 206, the Bluetooth chip 207, or the NFC chip 208, and receive the authentication information and service data sent by the electronic device 100. The authentication control module 202 can perform two-way authentication on the electronic device 100 based on the security key stored in the key storage module, and perform verification of the key service data, as well as perform verification of ranging or vehicle control instructions, etc.
[0048] In some solutions, the UWB chip 103 on the electronic device 100 is connected to the security chip 102 through a bus. For example, the bus can include a serial peripheral interface (SPI) bus or an inter-integrated circuit (I2C) bus, etc. After the electronic device 100 activates the digital vehicle key of the vehicle 200, it can obtain the vehicle key. The electronic device 100 can store the vehicle key in the security chip 102. Among them, the security chip 102 can derive a vehicle key session key based on the vehicle key. The security chip 102 can generate an ultra-wideband ranging root session key (URSK) based on the vehicle key session key. The security chip 102 can transfer the URSK to the UWB chip 103 through the bus connection. After receiving the URSK, the UWB chip 103 can derive a ranging process key based on the URSK according to the Fira protocol or UWB ranging protocols such as CCC. The UWB chip 103 can perform UWB ranging communication with the UWB chip 206 on the vehicle 200 through the ranging process key, thereby ensuring the security during the UWB ranging process.
[0049] The following combines Figure 3 and Figure 4 to introduce the process of the security chip 102 on the electronic device 100 transferring the URSK to the UWB chip 103.
[0050] Figure 3 Shows a schematic diagram of the functional modules of the security chip 102 and the UWB chip 103 in the embodiment of the present application.
[0051] As Figure 3 shown, the security chip 102 and the UWB chip 103 are connected through a bus. For example, the bus can be an SPI bus or an I2C bus, etc.
[0052] The secure chip 102 may include a digital key application (DK Applet), a secure ultra-wideband service application (SUS Applet), security specifications, a transport protocol (e.g., T1 protocol), and a bus driver (e.g., SPI driver or I2C driver). Among them, the security specifications may include the Global Platform Secure Protocol (GPSecure Protocol) and the Java Card platform.
[0053] Among them, the digital key application may include one or more of the following: the car connectivity consortium digital key applet (CCC DK Applet), the intelligent car connectivity industry ecosystem alliance digital key applet (ICCE DK Applet), or the fine ranging application (FiRa Applet). The digital key application and the SUS Applet may communicate through the secure ultra-wideband service internal application interface (SUS internal API). The digital key application may call the SUS Applet to establish a secure transmission channel between the secure chip 102 and the UWB chip 103, and transmit the URSK to the UWB chip 103 in the secure transmission channel.
[0054] The Global Platform Secure Protocol on the secure chip 102 may include the SCP03 protocol, the SCP11a protocol, etc. The Global Platform Secure Protocol can be used to establish a secure transmission channel between the secure chip 102 and other modules (e.g., the UWB chip 103). Among them, the Java Card platform can be used to run the applications in the secure chip 102 (e.g., the digital key application, the secure ultra-wideband service application, etc.) and ensure the security between these applications. The transport protocol on the secure chip 102 can be used to establish a data link between the UWB chip 103 and other modules (e.g., the secure chip 102).
[0055] The UWB chip 103 may include a ranging module, a GlobalPlatform Secure protocol (GPSecure protocol), a Crypto Service, a transmission protocol (e.g., T1 protocol), a bus driver (e.g., SPI driver or I2C driver), a UWB media access control layer (UWB MAC Layer), and a UWB physical layer (UWB PHY Layer).
[0056] Among them, the ranging module may include one or more of the following: a Fine Ranging (FiRa Ranging) module or a Car Connectivity Consortium Ranging (CCC Ranging) module. The ranging module may send or receive UWB signals to / from other devices (e.g., vehicle 200) through the UWB MAC Layer and the UWB PHY Layer, so as to complete ranging or positioning between the electronic device 100 and other devices (e.g., vehicle 200).
[0057] The GlobalPlatform Secure protocol on the UWB chip 103 can be used to establish a secure transmission channel between the UWB chip 103 and other modules (e.g., the secure chip 102). The Crypto Service can be used to provide encryption or decryption functions inside the UWB chip 103. The transmission protocol on the UWB chip 103 can be used to establish a data link between the UWB chip 103 and other modules (e.g., the secure chip 102).
[0058] Figure 4 Fig. shows a schematic diagram of the process of a secure chip transmitting a URSK to a UWB chip provided in an embodiment of the present application.
[0059] As Figure 4 shown, the process of the secure chip transmitting a URSK to the UWB chip may be as follows:
[0060] 1. The secure chip 102 and the UWB chip 103 may perform bus communication through a bus driver.
[0061] For example, the bus driver may include an SPI driver or an I2C driver. The bus communication may include SPI communication or I2C communication.
[0062] 2. The secure chip 102 and the UWB chip 103 may establish a data link with the UWB chip 103 through a transmission protocol.
[0063] For example, the transmission protocol may be the T1 Protocol.
[0064] 3. The security chip 102 and the UWB chip 103 can establish a secure channel through the GlobalPlatform Secure Protocol (GPSecure Protocol).
[0065] For example, the GPSecure Protocol can include the SCP03 protocol or the SCP11a protocol.
[0066] 4. The SUS Applet of the security chip 102 and the ranging module of the UWB chip 103 can interact through the application protocol data unit (APDU) to transfer the URSK to the UWB chip 103.
[0067] In the solution of establishing a secure transmission channel using the SCP03 protocol, the symmetric keys need to be pre - set in the security chip 102 and the UWB chip 103 on the production line before the electronic device 100 leaves the factory. Therefore, when the electronic device 100 uses the UWB chip 103 for ranging after the digital car key is enabled after leaving the factory, the security chip 102 can encrypt the URSK with the pre - set symmetric key and send the encrypted URSK to the UWB chip 103 through the secure transmission channel established by the SCP03 protocol. The UWB chip 103 decrypts the encrypted URSK to obtain the URSK using the pre - set symmetric key. Different symmetric keys need to be pre - set on different electronic devices, so as to prevent decrypting the URSK encrypted on the electronic device 100 through the symmetric keys pre - set in the security chips or UWB chips of other devices, ensuring the security of the electronic device 100 during the UWB ranging or positioning process.
[0068] In the solution of establishing a secure transmission channel using the SCP11a protocol, before the electronic device 100 leaves the factory, the digital certificates of both parties need to be pre - set in the secure chip 102 and the UWB chip 103 on the production line. When establishing a secure transmission channel, the secure chip 102 and the UWB chip 103 need to verify each other's digital certificates and exchange public keys with each other. The secure chip 102 can derive a symmetric key using the private key of the secure chip 102 and the public key of the UWB chip 103, and the UWB chip 103 can derive the same symmetric key using the private key of the UWB chip 103 and the public key of the secure chip 102. Therefore, after leaving the factory, when the electronic device 100 enables the digital car key and uses the UWB chip 103 for ranging or positioning, the secure chip 102 can encrypt the URSK with the symmetric key and send the encrypted URSK to the UWB chip 103 through the secure transmission channel established by the SCP03 protocol. The UWB chip 103 decrypts the encrypted URSK to obtain the URSK using the symmetric key. And the UWB chip 103 needs to be paired with the secure chip 102 to form a coupling relationship, so as to prevent the symmetric key negotiated by the secure chip and the UWB chip on other devices from decrypting the URSK encrypted on the electronic device 100, ensuring the security of the electronic device 100 during the UWB ranging or positioning process.
[0069] However, in the above - mentioned SCP03 solution or SCP11a solution, since the UWB chip and the secure chip of the electronic device need to be connected through a bus to form a coupling relationship, and on the production line, the same symmetric key or the digital certificates of both parties need to be pre - set in the UWB chip and the secure chip of the electronic device at the same time, it increases the complexity of the hardware and software on the electronic device on the production line, resulting in a relatively high production cost of the electronic device.
[0070] Therefore, as Figure 5 shown, an embodiment of the present application provides a UWB key transmission method, which can enable the secure chip 102 to establish a secure transmission channel with the UWB chip 103 through the central processor 101, and transmit the URSK to the UWB chip 103 through the secure transmission channel established between the central processor 101 and the UWB chip 103.
[0071] Specifically, the central processing unit 101 can obtain the ultra-wideband transmission key and store the ultra-wideband transmission key in the security chip 102, where the target URSK is stored. The security chip 102 encrypts the target URSK into the first encrypted data using the ultra-wideband transmission key. The security chip 102 can send the first encrypted data to the UWB chip 103 through the central processing unit 101, where the ultra-wideband transmission key is stored in the UWB chip 103. The UWB chip 103 decrypts the target URSK from the first encrypted data using the ultra-wideband transmission key, and the target URSK is used for ranging by the UWB chip. In this way, the flexible combination of the security chip 102 and the UWB chip 103 can be realized without strong binding.
[0072] The following introduces a UWB key transmission method provided in the embodiments of the present application.
[0073] In the embodiments of the present application, a UWB key transmission method is provided. Before the electronic device 100 leaves the factory, the ultra-wideband transmission key (UWB transfer key) can be preset in the UWB chip through an encryption machine. The electronic device 100 can request the server to generate the same ultra-wideband transmission key through the vehicle key application running in the central processing unit. After the vehicle key application obtains the ultra-wideband transmission key sent by the server, it can store the ultra-wideband transmission key in the security chip through the trusted execution environment (TEE) in the central processing unit. The security chip can encrypt the URSK required for ranging by the UWB chip using the UWB transfer key to obtain the encrypted data A. The security chip can transfer the encrypted data A to the UWB chip through the TEE and the rich execution environment (REE) in the central processing unit. The UWB chip can decrypt the URSK from the encrypted data A through the prefabricated UWB transfer key. In this way, while ensuring the secure transmission of the URSK from the security chip to the UWB chip, the UWB chip can also be decoupled from the security chip, so that there is no need for a direct connection between the UWB chip and the security chip, and the security chip and the UWB chip can be flexibly combined without strong binding.
[0074] Figure 6 FIG. shows a schematic diagram of a UWB key transmission method provided in the embodiments of the present application.
[0075] As Figure 6As shown, the UWB key transmission method can be applied to a UWB key transmission system. The UWB key transmission system can include an electronic device 100, a server 300, and an encryption machine 400. The electronic device 100 can include a central processing unit (CPU) 101, a secure element (SE) chip 102, and a UWB chip 103. There is no connection between the secure element chip 102 and the UWB chip 103. The secure element chip 102 can be connected to the central processing unit 101, and the UWB chip 103 can be connected to the central processing unit 101. Among them, there can be two application environments running in the central processing unit 101: REE and TEE. Among them, in the REE, there can be a vehicle key application 1011, an ultra-wideband service (UWB Service) 1012, an ultra-wideband protocol stack and kernel (UWBstackandkernal) 1013, and a secure service (Secure Service) 1014 running.
[0076] In a possible implementation, when there is a connection between the secure element chip 102 and the UWB chip 103, the UWB key transmission method provided in the embodiments of the present application can also be adopted.
[0077] The operating system running in the REE can be called a rich execution environment operating system (REE OS), and the operating system running in the TEE can be called a trusted execution environment operating system (TEE OS). Among them, the TEE is a secure operating environment running in the CPU. The secure boot process of the TEE needs to be verified, and its secure boot process is separated from the REE. Each application running under the TEE is independent of each other, and each application cannot access each other without authorization, ensuring that the resource and data processing process of the application under the TEE is executed in a trusted environment, thereby providing security services for the REE operating system. The TEE has its own execution space, has a higher security level than the REE operating system, and is a security architecture that overlaps with the hardware architecture of the currently used CPU. The software and hardware resources that the TEE can access are separated from the REE operating system, providing hardware-supported isolation.
[0078] The secure element chip 102 can include a digital key application (DK Applet) 1021 and a secure ultra-wideband management application (Secure UWB Manage Applet) 1022. Among them, the digital key application 1021 can be any one of a CCC DK Applet, an ICCEDK Applet, or a FiRa Applet. The digital key application 1021 can call the secure ultra-wideband management application 1022 through an internal interface (internalAPI).
[0079] The UWB chip 103 may include a Secure UWB Service 1031.
[0080] Among them, the UWB key transmission method may include the following steps:
[0081] S601. Before the electronic device 100 leaves the factory, the encryption machine 400 derives the manufacturer identification and chip identification (EUI) of the UWB chip 103 from the UWB chip 103.
[0082] Among them, after the UWB chip 103 is produced, the manufacturer identification and chip identification of the UWB chip 103 may be stored in the storage medium inside the UWB chip 103.
[0083] S602. The encryption machine 400 generates a pairing key (Pairkey) based on the root key (Rootkey) and the manufacturer identification of the UWB chip 103.
[0084] Among them, the encryption machine 400 performs operations using the AES128-CBC encryption algorithm based on the root key and the manufacturer identification of the UWB chip 103 to generate a pairing key (Pairkey). Optionally, the encryption machine 400 may also use other encryption algorithms to generate the pairing key (Pairkey), which is not limited in the embodiments of the present application.
[0085] For example, as Figure 7A shown, based on the Rootkey and the manufacturer identification of the UWB chip 103, the process of generating the Pairkey through the AES128-CBC encryption algorithm may be as follows:
[0086] 1. Generate plaintext block A0 and plaintext block A1 based on the manufacturer identification of the UWB chip 103.
[0087] Among them, the data length of the manufacturer identification of the UWB chip 103 may be 8 bytes. The data lengths of plaintext block A0 and plaintext block A1 may both be 16 bytes. Plaintext block A0 may be "manufacturer identification ‖ manufacturer identification with bitwise inversion", where the "‖" symbol represents data concatenation. Plaintext block A1 may be "manufacturer identification ‖ padding value 1 ‖ padding value 2 ‖ the first 4 bytes of the manufacturer identification ‖ padding value 3 ‖ padding value 4". Among them, the data length of each padding value is 1 byte. For example, padding value 1 may be "F2", padding value 2 may be "02", padding value 3 may be "2F", and padding value 4 may be "02".
[0088] 2. Perform an exclusive OR operation on the initialization vector (IV) and plaintext block A0 to obtain input data 1.
[0089] Among them, the data length of the initial vector can be 16 bytes.
[0090] 3. Input the input data 1 and Rootkey into the AES encryptor for encryption operation to obtain the ciphertext block C0.
[0091] 4. Perform an exclusive OR operation on the ciphertext block C0 and the plaintext block A1 to obtain the input data 2.
[0092] 5. Input the input data 2 and Rootkey into the AES encryptor for encryption operation to obtain the ciphertext block C1.
[0093] 6. Concatenate the ciphertext block C0 and the ciphertext block C1 to obtain the pairing key (Pairkey).
[0094] For example, the ciphertext block C1 can be concatenated at the end of the ciphertext block C0.
[0095] S603. The encryptor 400 generates a UWB transmission key (UWB transferkey) based on the Pairkey and the chip identifier of the UWB chip 103.
[0096] For example, as Figure 7B shown, based on the Rootkey and the manufacturer identifier of the UWB chip 103, the process of generating the UWB transmission key (UWB transferkey) through the AES128-CBC encryption algorithm can be as follows:
[0097] 1. Generate the plaintext blocks B0 and B1 based on the chip identifier (EUI) of the UWB chip 103.
[0098] Among them, the data length of the manufacturer identifier of the UWB chip 103 can be 8 bytes. The data lengths of the plaintext blocks B0 and B1 can both be 16 bytes. The plaintext block B0 can be "EUI‖the bitwise inverted EUI". Among them, the "‖" symbol represents the concatenation of data. The plaintext block A1 can be "EUI‖padding value 5‖padding value 6‖the first 4-byte data of the manufacturer identifier‖padding value 7‖padding value 8". Among them, the data length of each padding value is 1 byte. For example, the padding value 5 can be "F1", the padding value 2 can be "01", the padding value 3 can be "1F", and the padding value 4 can be "01".
[0099] 2. Perform an exclusive OR operation on the initialization vector (initialization vector, IV) and the plaintext block B0 to obtain the input data 3.
[0100] 3. Input the input data 3 and the Pairkey into the AES encryptor for encryption operation to obtain the ciphertext block D0.
[0101] 4. Perform an exclusive OR operation on the ciphertext block D0 and the plaintext block B1 to obtain the input data 4.
[0102] 5. Input the input data 4 and the Pairkey into the AES encryptor for encryption operation to obtain the ciphertext block D1.
[0103] 6. Concatenate the ciphertext block D0 and the ciphertext block D1 to obtain the Ultra Wideband Transfer Key (UWB transferkey).
[0104] For example, the ciphertext block D1 can be concatenated at the end of the ciphertext block D0.
[0105] S604. The encryption machine 400 imports the Ultra Wideband Transfer Key to the UWB chip 103.
[0106] Among them, the Secure Ultra Wideband Service 1031 can manage and save the Ultra Wideband Transfer Key imported by the encryption machine 400 to the UWB chip 103.
[0107] S605. The Ultra Wideband protocol stack and the kernel 1013 can obtain the manufacturer identification and chip identification of the UWB chip 103 from the UWB chip 103.
[0108] Among them, after the electronic device 100 leaves the factory, when the Ultra Wideband protocol stack and the kernel 1013 run in the central processing unit 101, they can obtain the manufacturer identification and chip identification of the UWB chip 103 from the UWB chip 103.
[0109] S606. The Ultra Wideband protocol stack and the kernel 1013 can send the manufacturer identification and chip identification (EUI) of the UWB chip 103 to the Ultra Wideband Service 1012.
[0110] S607. The Ultra Wideband Service 1012 can send the manufacturer identification and chip identification (EUI) of the UWB chip 103 to the car key application 1011.
[0111] S608. The car key application 1011 sends a first request to the server 300, and the first request carries the manufacturer identification and chip identification of the UWB chip.
[0112] Among them, the first request is used to request the server 300 to generate the UWB transferkey.
[0113] S609. The server 300 can generate the Pairkey based on the Rootkey and the manufacturer identification of the UWB chip 103.
[0114] Among them, a root key can be stored on the server 300. The root key stored on the server 300 is the same as the root key stored in the encryption machine 400. The process for the server 300 to generate the Pairkey based on the root key and the manufacturer identification of the UWB chip 103 is the same as the process for the above-mentioned encryption machine 400 to generate the Pairkey. Specifically, the process for the server 300 to generate the Pairkey can refer to the process for the encryption machine 400 to generate the Pairkey in the foregoing step S602.
[0115] S610. The server 300 generates a Ultra-Wideband (UWB) transfer key based on the Pairkey and the chip identification of the UWB chip 103.
[0116] Among them, the process for the server 300 to generate the UWB transfer key is the same as the process for the above-mentioned encryption machine 400 to generate the UWB transfer key. Specifically, the process for the server 300 to generate the UWB transfer key can refer to the process for the encryption machine 400 to generate the UWB transfer key in the above step S603, which will not be elaborated here.
[0117] S611. The server 300 sends the UWB transfer key to the vehicle key application 1011.
[0118] Among them, before the server 300 sends the UWB transfer key to the vehicle key application 1011, a secure transmission channel can be established with the vehicle key application 1011, so as to ensure the security of data transmission between the server 300 and the vehicle key application 1011.
[0119] For example, the server 300 and the vehicle key application 1011 can first verify each other's digital certificates. After successfully verifying each other's digital certificates, the server 300 can obtain the public key (PK.applicaition) of the vehicle key application 1011. The vehicle key application 1011 can obtain the public key (PK.server) of the server 300. The server 300 can generate a symmetric key (SYK) using the private key of the server 300 (SK.server) and the public key of the vehicle key application 1011 (PK.applicaition). The vehicle key application 1011 can also generate the same symmetric key (SYK) based on the public key of the server 300 (PK.server) and the private key of the vehicle key application 1011 (SK.applicaition). Here, the public key (PK.applicaition) and the private key (SK.applicaition) of the vehicle key application 1011 form a pair of asymmetric keys, and the public key (PK.server) and the private key (SK.server) of the server 300 form a pair of asymmetric keys. The server 300 can encrypt the ultra-wideband transmission key using the symmetric key (SYK) and send the encrypted ultra-wideband transmission key to the vehicle key application 1011. The vehicle key application 1011 can decrypt the ultra-wideband transmission key from the encrypted ultra-wideband transmission key using the symmetric key (SYK). The above examples are only for explaining this application and should not be construed as limitations. In the embodiments of this application, the secure transmission channel between the server 300 and the vehicle key application 1011 can adopt security specifications such as SCP03 or SCP11a, which are not limited herein.
[0120] S612. The vehicle key application 1011 sends the ultra-wideband transmission key to the security service 1014.
[0121] S613. The security service 1014 sends the ultra-wideband transmission key to the secure ultra-wideband management application 1022 of the secure chip 102 through the TEE.
[0122] Among them, the secure ultra-wideband management application 1022 can manage and store the ultra-wideband transmission key.
[0123] After receiving the ultra-wideband transmission key sent by the server 300, the vehicle key application 1011 can first establish a secure transmission channel with the secure chip 102 through the security service 1014 and the TEE. Then, the vehicle key application 1011 can send the ultra-wideband transmission key to the secure chip 102 over the secure transmission channel established with the secure chip 102 through the security service 1014 and the TEE. In this way, the security of the ultra-wideband transmission key from the vehicle key application 1011 to the secure chip 102 can be ensured.
[0124] The digital key application 1021 can generate a target URSK.
[0125] Among them, when the vehicle key application 1011 activates the digital vehicle key of the vehicle, it can obtain the vehicle key secret key. The vehicle key application 1011 can store the vehicle key secret key in the secure chip 102. Among them, the digital key application 1021 can derive a vehicle key session key based on the vehicle key secret key. The digital key application 1021 can generate one or more URSKs based on the vehicle key session key, and one of the one or more URSKs includes the target URSK.
[0126] S615. The secure ultra-wideband management application 1022 encrypts the target URSK with the ultra-wideband transmission key to obtain encrypted data A.
[0127] Among them, the secure ultra-wideband management application 1022 can obtain the target URSK from the digital key application 1021. Then, the secure ultra-wideband management application 1022 can encrypt the target URSK into encrypted data A using the ultra-wideband transmission key.
[0128] S616. The secure ultra-wideband management application 1022 sends the encrypted data A to the security service 1014 through the TEE.
[0129] S617. The security service 1014 can send the encrypted data A to the ultra-wideband service 1012.
[0130] S618. The ultra-wideband service 1012 sends the encrypted data A to the ultra-wideband protocol stack and kernel 1013.
[0131] S619. The ultra-wideband protocol stack and kernel 1013 send the encrypted data A to the secure ultra-wideband service 1031 in the UWB chip 103.
[0132] S620. The secure ultra-wideband service 1031 can decrypt the target URSK from the encrypted data A using the ultra-wideband transmission key.
[0133] Among them, the specific content of the URSK transmission process shown in the above steps S615 to S620 can refer to Figure 7C The schematic diagram of the URSK transmission process shown.
[0134] As Figure 7C shown, the URSK transmission process may include the following steps:
[0135] 1. The UWB chip 103 sends a selection command to the secure chip 102 through the central processor 101, where the selection command carries the secure ultra-wideband management application identifier (SUM AID).
[0136] Among them, multiple applications (Applets) can run in the security chip 102, and the multiple applications include the secure ultra-wideband management application 1022. The selection command is used to select the secure ultra-wideband management application 1022 in the security chip 102 to communicate with the UWB chip 103.
[0137] In the embodiment of the present application, the UWB chip 103 can perform signaling interaction with the security chip 102 through the ultra-wideband protocol stack and the kernel 1013, the ultra-wideband service 1012, the security service 1014, and the TEE in the central processor 101 in sequence.
[0138] 2. The secure ultra-wideband management application 1022 sends a Select Response to the UWB chip 103 through the central processor 101.
[0139] Among them, the selection response is used to indicate that the security chip 102 enables the secure ultra-wideband management application 1022 to communicate with the UWB chip 103.
[0140] 3. The UWB chip 103 sends a Get Challenge command to the secure ultra-wideband management application 1022 through the central processor 101.
[0141] Among them, the random number acquisition command is used to request the secure ultra-wideband management application 1022 to return a random number to the UWB chip 103.
[0142] 4. The secure ultra-wideband management application 1022 sends a random number 1 to the UWB chip 103 through the central processor 101.
[0143] 5. The UWB chip 103 encrypts the random number 1 using the UWB transfer key to obtain an authentication ciphertext.
[0144] 6. The UWB chip 103 sends the authentication ciphertext to the secure ultra-wideband management application 1022 through the central processor 101.
[0145] 7. The secure ultra-wideband management application 1022 decrypts the random number 2 from the authentication ciphertext using the UWB transfer key.
[0146] 8. The secure ultra-wideband management application 1022 can determine whether the random number 2 is the same as the random number 1.
[0147] 9. If the random number 2 is the same as the random number 1, the security chip 102 can send a response 1 to the UWB chip 103 through the central processor 101. Among them, the response 1 is used to indicate that the random number verification has passed.
[0148] If the random number 2 is different from the random number 1, the secure chip 102 returns a response 2 to the UWB chip 103 via the central processor 101, where the response 2 is used to indicate that the random number verification fails. After receiving the response 2, the secure chip 102 stops performing subsequent steps.
[0149] 10. After receiving the response 1, the UWB chip 103 sends a URSK acquisition command to the secure ultra-wideband management application 1022 via the central processor 101. The URSK acquisition command carries a session identifier (Session ID) A.
[0150] 11. The secure ultra-wideband management application 1022 determines a target URSK from one or more URSKs based on the session identifier A, where different URSKs correspond to different session identifiers.
[0151] Among them, the digital key application 1021 in the secure chip 102 can generate one or more URSKs based on the vehicle key session key (Sessionkey), and different URSKs correspond to different session identifiers. After obtaining the session identifier A, the secure ultra-wideband management application 1022 can obtain the target URSK corresponding to the session identifier A from one or more URSKs managed and stored by the digital key application 1021.
[0152] 12. The secure ultra-wideband management application 1022 encrypts the target URSK using the ultra-wideband transmission key to obtain encrypted data A.
[0153] 13. The secure ultra-wideband management application 1022 sends the encrypted data A to the UWB chip 103 via the central processor 101.
[0154] 14. The UWB chip 103 decrypts the target URSK from the encrypted data A using the ultra-wideband transmission key.
[0155] After decrypting the target URSK through the secure ultra-wideband management application 1022, the UWB chip 103 can derive a ranging process key based on the target URSK. The UWB chip 103 can perform UWB ranging communication with the UWB chip 206 on the vehicle 200 through the ranging process key, thereby ensuring the security during the UWB ranging process.
[0156] In the embodiments of the present application, the encrypted data A can be referred to as the first encrypted data, the random number 1 can be referred to as the first random number, the random number 2 can be referred to as the second random number, the response 1 can be referred to as the first response, and the session identifier A can be referred to as the first session identifier.
[0157] Next, a UWB key transmission method provided in the embodiments of the present application is introduced.
[0158] In an embodiment of the present application, a UWB key transmission method is provided. The UWB chip of the electronic device 100 can generate a public key PK1 and a private key SK1, where the public key PK1 and the private key SK1 are a pair of public-private keys. The UWB chip sends the public key PK1 to the vehicle key application running in the central processor of the electronic device 100. The vehicle key application can request the server to generate an Ultra-Wideband transfer key (UWB transferkey). After obtaining the UWB transferkey sent by the server, the vehicle key application can encrypt the UWB transferkey into encrypted data B using the public key PK1 and send the encrypted data B to the UWB chip. After receiving the encrypted data B, the UWB chip can decrypt the UWB transferkey from the encrypted data B using the private key SK1. After obtaining the UWB transferkey sent by the server, the vehicle key application can also store the UWB transferkey in the secure chip through the TEE. The secure chip can use the UWB transferkey to encrypt the URSK required for ranging by the UWB chip to obtain encrypted data A. The secure chip can transfer the encrypted data A to the UWB chip through the TEE and REE in the central processor. The UWB chip can decrypt the URSK from the encrypted data A using the UWB transferkey issued by the vehicle key application. In this way, it is not necessary to prefabricate the UWB transferkey in the UWB chip before the electronic device 100 leaves the factory. While ensuring the secure transmission of the URSK from the secure chip to the UWB chip, it can also decouple the UWB chip from the secure chip, so that there is no need for a direct connection between the UWB chip and the secure chip 102. The secure chip and the UWB chip can be flexibly combined without strong binding, reducing the cost of producing the electronic device 100 on the production line.
[0159] Figure 8 The figure shows a schematic diagram of a UWB key transmission method provided in another embodiment of the present application.
[0160] As Figure 8As shown in the figure, the UWB key transmission method can be applied to a UWB key transmission system. The UWB key transmission system may include an electronic device 100 and a server 300. Among them, the electronic device 100 may include a central processing unit (CPU) 101, a secure element chip (SE Chip) 102, and a UWB chip 103. There is no connection between the secure element chip 102 and the UWB chip 103. The secure element chip 102 can be connected to the central processing unit 101, and the UWB chip 103 can be connected to the central processing unit 101. Among them, there are two application environments that can run in the central processing unit 101: REE and TEE. Among them, in REE, a vehicle key application 1011, an ultra-wideband service (UWB Service) 1012, an ultra-wideband protocol stack and kernel (UWB stackandkernal) 1013, and a secure service (Secure Service) 1014 can run. The secure element chip 102 may include a digital key application (DK Applet) 1021 and a secure ultra-wideband management application (Secure UWB Manage Applet) 1022. Among them, the digital key application 1021 may be any one of CCC DKApplet, ICCE DK Applet, or FiRa Applet. The digital key application 1021 can call the secure ultra-wideband management application 1022 through an internal interface (internal API). The UWB chip 103 may include a secure ultra-wideband service (Secure UWB Service) 1031.
[0161] In a possible implementation manner, when the secure element chip 102 is connected to the UWB chip 103, the UWB key transmission method provided in the embodiments of the present application may also be adopted.
[0162] Among them, the UWB key transmission method may include the following steps:
[0163] S801. The secure ultra-wideband service 1031 may generate a pair of public and private keys. Among them, the pair of public and private keys generated by the secure ultra-wideband service 1031 includes a public key PK1 and a private key SK1.
[0164] S802. The secure ultra-wideband service 1031 sends the public key PK1 to the ultra-wideband protocol stack and kernel 1013.
[0165] S803. The ultra-wideband protocol stack and kernel 1013 send the public key PK1 to the ultra-wideband service 1012.
[0166] S804. The ultra-wideband service 1012 sends the public key PK1 to the vehicle key application 1011.
[0167] The vehicle key application 1011 may save the public key PK1.
[0168] The vehicle key application 1011 sends a first request to the server 300, and the factory identifier and chip identifier (EUI) of the UWB chip 103 are carried in the first request.
[0169] The first request is used to request the server 300 to generate a UWB transfer key. Among them, after the UWB chip 103 is produced, the factory identifier and chip identifier of the UWB chip 103 can be stored in the storage medium inside the UWB chip 103. After the electronic device 100 leaves the factory, when the ultra-wideband protocol stack and kernel 1013 run in the central processing unit 101, the factory identifier and chip identifier of the UWB chip 103 can be obtained from the UWB chip 103. The ultra-wideband protocol stack and kernel 1013 can send the factory identifier and chip identifier (EUI) of the UWB chip 103 to the ultra-wideband service 1012. The ultra-wideband service 1012 can send the factory identifier and chip identifier (EUI) of the UWB chip 103 to the vehicle key application 1011.
[0170] S806. The server 300 generates a Pair key based on the Root key and the factory identifier of the UWB chip 103.
[0171] Among them, the Root key can be stored on the server 300. For the specific process of the server 300 generating the Pair key, reference can be made to the process of generating the Pair key in the foregoing Figure 7A illustrated embodiment, which will not be elaborated here.
[0172] S807. The server 300 can generate an ultra-wideband transmission key (UWB transfer key) based on the Pair key and the chip identifier of the UWB chip 103.
[0173] For the specific process of the server 300 generating the Pair key, reference can be made to the process of generating the ultra-wideband transmission key in the foregoing Figure 7B illustrated embodiment, which will not be elaborated here.
[0174] S808. The server 300 can send the ultra-wideband transmission key to the vehicle key application 1011.
[0175] For the specific content, reference can be made to step S611 in the foregoing Figure 6 illustrated embodiment, which will not be elaborated here.
[0176] S809. The vehicle key application 1011 can encrypt the ultra-wideband transmission key using the public key PK1 to obtain encrypted data B.
[0177] The vehicle key application 1011 sends the encrypted data B to the Ultra-Wideband Service (UWB Service) 1012.
[0178] The Ultra-Wideband Service 1012 sends the encrypted data B to the Ultra-Wideband protocol stack and kernel 1013.
[0179] The Ultra-Wideband protocol stack and kernel 1013 send the encrypted data B to the Secure Ultra-Wideband Service 1031.
[0180] The Secure Ultra-Wideband Service 1031 can use the private key SK1 to decrypt the Ultra-Wideband transmission key from the encrypted data B.
[0181] The vehicle key application 1011 sends the Ultra-Wideband transmission key to the Secure Service 1014.
[0182] The Secure Service 1014 sends the Ultra-Wideband transmission key to the Secure Ultra-Wideband management application 1022 through the TEE.
[0183] After receiving the Ultra-Wideband transmission key sent by the server 300, the vehicle key application 1011 can first establish a secure transmission channel with the secure chip 102 through the Secure Service 1014 and the TEE. Then, the vehicle key application 1011 can send the Ultra-Wideband transmission key to the secure chip 102 on the secure transmission channel established through the Secure Service 1014 and the TEE. In this way, the security of the Ultra-Wideband transmission key from the vehicle key application 1011 to the secure chip 102 can be ensured.
[0184] The digital key application 1021 can generate the target URSK.
[0185] Among them, when the vehicle key application 1011 activates the digital vehicle key of the vehicle, it can obtain the vehicle key. The vehicle key application 1011 can store the vehicle key in the secure chip 102. Among them, the digital key application 1021 can derive the vehicle key session key based on the vehicle key. The digital key application 1021 can generate one or more URSKs based on the vehicle key session key, and one of the one or more URSKs includes the target URSK.
[0186] The Secure Ultra-Wideband management application 1022 encrypts the URSK with the Ultra-Wideband transmission key to obtain the encrypted data A.
[0187] Among them, the secure ultra-wideband management application 1022 can obtain the target URSK from the digital key application 1021. Then, the secure ultra-wideband management application 1022 can encrypt the target URSK into encrypted data A using the ultra-wideband transmission key.
[0188] S818. The secure ultra-wideband management application 1022 sends the encrypted data A to the security service 1014 through the TEE.
[0189] S819. The security service 1014 sends the encrypted data A to the ultra-wideband service 1012.
[0190] S820. The ultra-wideband service 1012 sends the encrypted data A to the ultra-wideband protocol stack and kernel 1013.
[0191] S821. The ultra-wideband protocol stack and kernel 1013 send the encrypted data A to the secure ultra-wideband service 1031 in the UWB chip 103.
[0192] S822. The secure ultra-wideband service 1031 can decrypt the target URSK from the encrypted data A using the ultra-wideband transmission key.
[0193] Among them, the specific content of the URSK transmission process shown in the above steps S817 to S822 can refer to the Figure 7C schematic diagram of the URSK transmission process shown above.
[0194] Among them, the target URSK can be used for ranging of the UWB chip 103. After the UWB chip 103 decrypts the target URSK through the secure ultra-wideband management application 1022, it can derive a ranging process key based on the target URSK. The UWB chip 103 can perform UWB ranging communication with the UWB chip 206 on the vehicle 200 through the ranging process key, thereby ensuring the security during the UWB ranging process.
[0195] In the embodiment of the present application, the encrypted data A can be referred to as the first encrypted data, the encrypted data B can be referred to as the second encrypted data, the public key PK1 can be referred to as the first public key, and the private key SK1 can be referred to as the first private key.
[0196] Next, a UWB key transmission method provided in another embodiment of the present application is introduced.
[0197] In an embodiment of the present application, a UWB key transmission method is provided. The vehicle key application running in the central processing unit of the electronic device 100 can generate a public key PK2 and a private key SK2, where the public key PK2 and the private key SK1 are a pair of public-private keys. The vehicle key application can send the public key PK2 to the UWB chip of the electronic device 100. The UWB chip can temporarily generate a UWB transfer key. The UWB chip can encrypt the UWB transfer key into encrypted data C using the public key PK2 and send the encrypted data C to the vehicle key application running in the central processing unit. After receiving the encrypted data C, the vehicle key application can decrypt the UWB transfer key from the encrypted data C using the private key SK2. After decrypting the UWB transfer key, the vehicle key application can store the UWB transfer key in the secure chip through the TEE. The secure chip can encrypt the URSK required for ranging the UWB chip using the UWB transfer key to obtain encrypted data A. The secure chip can transfer the encrypted data A to the UWB chip through the TEE and REE in the central processing unit. The UWB chip can decrypt the URSK from the encrypted data A using the UWB transfer key issued by the vehicle key application. In this way, it is not necessary to prefabricate the UWB transfer key in the UWB chip before the electronic device 100 leaves the factory, nor is it necessary for the vehicle key application to request the server to generate the UWB transfer key. While ensuring the secure transmission of the URSK from the secure chip to the UWB chip, it can also decouple the UWB chip from the secure chip, so that there is no need for a direct connection between the UWB chip and the secure chip 102. The secure chip and the UWB chip can be flexibly combined without strong binding, reducing the production cost of the electronic device 100 on the production line and the deployment cost of the server.
[0198] Figure 9 The figure shows a schematic diagram of a UWB key transmission method provided in an embodiment of the present application.
[0199] As Figure 9As shown in the figure, the UWB key transmission method can be applied to the electronic device 100. Among them, the electronic device 100 may include a central processing unit (CPU) 101, a secure element chip (SE Chip) 102, and a UWB chip 103. There is no connection between the secure element chip 102 and the UWB chip 103. The secure element chip 102 can be connected to the central processing unit 101, and the UWB chip 103 can be connected to the central processing unit 101. Among them, there are two application environments that can run in the central processing unit 101: REE and TEE. Among them, in REE, a vehicle key application 1011, an ultra-wideband service (UWB Service) 1012, an ultra-wideband protocol stack and kernel (UWBstackandkernal) 1013, and a secure service (Secure Service) 1014 can run. The secure element chip 102 may include a digital key application (DK Applet) 1021 and a secure ultra-wideband management application (Secure UWB Manage Applet) 1022. Among them, the digital key application 1021 can be any one of CCC DK Applet, ICCE DK Applet, or FiRa Applet. The digital key application 1021 can call the secure ultra-wideband management application 1022 through an internal interface (internal API). The UWB chip 103 may include a secure ultra-wideband service (Secure UWB Service) 1031.
[0200] In a possible implementation, when the secure element chip 102 is connected to the UWB chip 103, the UWB key transmission method provided in the embodiments of the present application can also be used.
[0201] Among them, the UWB key transmission method may include the following steps:
[0202] S901. The vehicle key application 1011 can generate a pair of public and private keys. Among them, the pair of public and private keys generated by the vehicle key application 1011 includes a public key PK2 and a private key SK2.
[0203] S902. The vehicle key application 1011 sends the public key PK2 to the ultra-wideband service 1012.
[0204] S903. The ultra-wideband service 1012 sends the public key PK2 to the ultra-wideband protocol stack and kernel 1013.
[0205] S904. The ultra-wideband protocol stack and kernel 1013 send the public key PK2 to the secure ultra-wideband service 1031.
[0206] S905. The secure ultra-wideband service 1031 generates an ultra-wideband transmission key (UWB transferkey).
[0207] Among them, the secure ultra-wideband service 1031 can randomly generate a temporary ultra-wideband transmission key (UWB transfer key). After decrypting the target URSK using the temporary UWB transfer key, the temporary UWB transfer key can be destroyed.
[0208] In a possible implementation, the secure ultra-wideband service 1031 can generate a UWB transfer key based on the root key, the manufacturer identifier of the UWB chip 103, and the chip identifier of the UWB chip 103. Among them, the secure ultra-wideband service 1031 can first generate a Pairkey based on the root key and the manufacturer identifier of the UWB chip 103. Then, the secure ultra-wideband service 1031 can generate a UWB transfer key based on the Pairkey and the chip identifier of the UWB chip 103. For the specific generation process of the Pairkey and the UWB transfer key, reference can be made to the above Figure 7A 、 Figure 7B illustrated embodiments and will not be elaborated here.
[0209] S906. The secure ultra-wideband service 1031 encrypts the ultra-wideband transmission key using the public key PK2 to obtain the encrypted data C.
[0210] S907. The secure ultra-wideband service 1031 sends the encrypted data C to the ultra-wideband protocol stack and the kernel 1013.
[0211] S908. The ultra-wideband protocol stack and the kernel 1013 send the encrypted data C to the ultra-wideband service 1012.
[0212] S909. The ultra-wideband service 1012 sends the encrypted data C to the car key application 1011.
[0213] S910. The car key application 1011 decrypts the ultra-wideband transmission key from the encrypted data C using the private key SK2.
[0214] S911. The car key application 1011 sends the ultra-wideband transmission key to the Secure Service 1014.
[0215] S912. The Secure Service 1014 sends the ultra-wideband transmission key to the secure ultra-wideband management application 1022 through the TEE.
[0216] Among them, after decrypting the ultra-wideband transmission key, the vehicle key application 1011 can first establish a secure transmission channel with the secure chip 102 through the security service 1014 and the TEE. Then, the vehicle key application 1011 can send the ultra-wideband transmission key to the secure chip 102 over the secure transmission channel established with the secure chip 102 through the security service 1014 and the TEE. In this way, the security of the ultra-wideband transmission key from the vehicle key application 1011 to the secure chip 102 can be ensured.
[0217] S913. The digital key application 1021 generates a target ultra-wideband root session key (URSK).
[0218] Among them, when the vehicle key application 1011 activates the digital vehicle key of the vehicle, it can obtain the vehicle key. The vehicle key application 1011 can store the vehicle key in the secure chip 102. Among them, the digital key application 1021 can derive a vehicle key session key based on the vehicle key. The digital key application 1021 can generate one or more URSKs based on the vehicle key session key, and one of the one or more URSKs includes the target URSK.
[0219] S914. The secure ultra-wideband management application 1022 encrypts the URSK with the ultra-wideband transmission key to obtain encrypted data A.
[0220] Among them, the secure ultra-wideband management application 1022 can obtain the target URSK from the digital key application 1021. Then, the secure ultra-wideband management application 1022 can encrypt the target URSK into encrypted data A using the ultra-wideband transmission key.
[0221] S915. The secure ultra-wideband management application 1022 sends the encrypted data A to the security service 1014 through the TEE.
[0222] S916. The security service 1014 sends the encrypted data A to the ultra-wideband service 1012.
[0223] S917. The ultra-wideband service 1012 sends the encrypted data A to the ultra-wideband protocol stack and kernel 1013.
[0224] S918. The ultra-wideband protocol stack and kernel 1013 send the encrypted data A to the secure ultra-wideband service 1031 in the UWB chip 103.
[0225] S919. The secure ultra-wideband service 1031 can decrypt the target URSK from the encrypted data A using the ultra-wideband transmission key.
[0226] Among them, the specific content of the URSK transmission process shown in the above steps S914 to S919 can be referred to the above Figure 7CSchematic diagram of the URSK transmission process shown
[0227] Among them, the target URSK is used for ranging of the UWB chip 103. After the UWB chip 103 decrypts the target URSK through the secure ultra-wideband management application 1022, it can derive a ranging process key based on the target URSK. The UWB chip 103 can perform UWB ranging communication with the UWB chip 206 on the vehicle 200 through the ranging process key, thereby ensuring the security during the UWB ranging process.
[0228] In the embodiments of the present application, the encrypted data A can be referred to as the first encrypted data, the encrypted data B can be referred to as the second encrypted data, the encrypted data C can be referred to as the third encrypted data, the public key PK2 can be referred to as the second public key, and the private key SK2 can be referred to as the second private key.
[0229] The following introduces a UWB key transmission method provided in another embodiment of the present application.
[0230] In some types of electronic devices 100, such as devices of the types of watches, bracelets, etc., since the UWB chips on the electronic devices 100 have no security capabilities and can only be used as transceivers for UWB communication, they cannot generate UWB communication messages based on the URSK. Therefore, the embodiments of the present application provide a UWB key transmission method, which can enable the TEE of the central processing unit to obtain the vehicle key session key from the security chip of the electronic device 100. After obtaining the vehicle key session key, the TEE can generate the URSK based on the vehicle key session key. Then, the UWB CA in the REE of the central processing unit can obtain the URSK from the TEE and send the URSK to the microcontroller. When performing ranging through the UWB chip, the microcontroller can generate a UWB communication message based on the URSK, and then borrow the signal transceiver capabilities of the UWB chip to send the UWB communication message, or can also parse the UWB communication message received by the UWB chip based on the URSK, thereby completing the UWB ranging. In this way, it is not necessary to prefabricate the UWB transferkey in the UWB chip before the electronic device 100 leaves the factory, nor is it necessary for the vehicle key application to request the server to generate the UWB transferkey. While transmitting the URSK to the UWB chip, it can also decouple the UWB chip from the security chip, so that there is no need for a direct connection between the UWB chip and the security chip 102, and the UWB chip and the security chip can be flexibly combined without strong binding, reducing the production cost of the electronic device 100 on the production line and the deployment cost of the server.
[0231] Figure 10 Schematic diagram of a UWB key transmission method provided in the embodiments of the present application is shown.
[0232] As Figure 10As shown in the figure, the UWB key transmission method can be applied to the electronic device 100. Among them, the electronic device 100 may include a central processing unit (CPU) 101, a secure element (SE) chip 102, a microcontroller unit (MCU) 104, and a UWB chip 103. There is no connection between the secure element chip 102 and the UWB chip 103. The secure element chip 102 can be connected to the central processing unit 101, the UWB chip 103 can be connected to the central processing unit 101, and the microcontroller 104 can be connected to the central processing unit 101 and the UWB chip 103. Among them, there are two application environments that can run in the central processing unit 101: REE and TEE. Among them, a vehicle key application 1011, a Ultra Wideband Service (UWB Service) 1012, a Ultra Wideband stack and kernel (UWB stack and kernal) 1013, and a Secure Service 1014 can run in the REE. The Ultra Wideband Service 1012 may include a Ultra Wideband Client Application (UWB CA) 1016. A Ultra Wideband Trusted Application (UWB TEE application, UWB TA) 1015 can run in the TEE. A Ultra Wideband Service (UWB Service) 1041 can run in the microcontroller 104, and the Ultra Wideband Service 1041 may include a Secure Ultra Wideband Service (Secure UWB Service) 1042.
[0233] The secure element chip 102 may include a Digital Key Applet (DK Applet) 1021 and a Secure Ultra Wideband Management Applet (Secure UWB Manage Applet) 1022. Among them, the Digital Key Applet 1021 may be any one of a CCC DK Applet, an ICCE DK Applet, or a FiRa Applet. The Digital Key Applet 1021 can call the Secure Ultra Wideband Management Applet 1022 through an internal API. The UWB chip 103 has no security capabilities and can only be used as a transceiver for UWB communication and cannot generate UWB communication messages based on the URSK.
[0234] In a possible implementation manner, when the secure element chip 102 is connected to the UWB chip 103, the UWB key transmission method provided in the embodiments of the present application may also be adopted.
[0235] Among them, the UWB key transmission method may include the following steps:
[0236] S1001. The vehicle key application 1011 sends the vehicle key to the Secure Service 1014.
[0237] Among them, when the vehicle key application 1011 activates the digital vehicle key of the vehicle, it can obtain the vehicle key secret key. The vehicle key application 1011 can store the vehicle key secret key in the security chip 102.
[0238] S1002. The security service 1014 sends the vehicle key secret key to the security chip 102 through the TEE.
[0239] Before the vehicle key application 1011 sends the vehicle key secret key to the security chip 102 through the security service 1014 and the TEE, it can establish a secure transmission channel with the security chip 102 through the security service 1014 and the TEE. Among them, in the embodiments of the present application, the security specification used to establish the secure transmission channel can adopt the SCP03 security specification or the SCP11a security specification, etc., which is not limited herein.
[0240] Among them, the digital key application 1021 in the security service 1014 can save the vehicle key secret key.
[0241] S1003. The digital key application 1021 can derive a vehicle key session key based on the vehicle key secret key.
[0242] S1004. The ultra-wideband trusted application 1015 obtains the vehicle key session key from the digital key application 1021.
[0243] S1005. The ultra-wideband trusted application 1015 generates a target URSK according to the vehicle key session key.
[0244] S1006. The ultra-wideband trusted application 1015 sends the target URSK to the security service 1014.
[0245] S1007. The security service 1014 sends the target URSK to the ultra-wideband client application 1016.
[0246] Among them, the ultra-wideband trusted application 1015 can generate one or more URSKs with the vehicle key session key, where one or more URSKs include the target URSK. The session identifiers (Session ID) corresponding to different URSKs are different.
[0247] Specifically, the ultra-wideband service 1041 in the microcontroller 104 can send a URSK acquisition request 1 to the ultra-wideband client application 1016 through the ultra-wideband protocol stack and the kernel 1013. Among them, the URSK acquisition request 1 carries the session identifier A. The ultra-wideband client application 1016 can send a URSK acquisition request 2 to the ultra-wideband trusted application 1015 through the security service 1014. Among them, the URSK acquisition request 2 carries the session identifier A, and the URSK acquisition request 2 is used to request the URSK from the ultra-wideband trusted application 1015. After receiving the URSK acquisition request 2, the ultra-wideband trusted application 1015 can determine the target URSK from one or more URSKs based on the session identifier A. The ultra-wideband trusted application 1015 can send the target URSK to the ultra-wideband client application 1016 through the security service 1014.
[0248] In a possible implementation, the ultra-wideband client application 1016 stores a requester whitelist, where the requester whitelist includes the identifiers of one or more modules that have the permission to request the URSK, and the identifiers of the one or more modules that have the permission to request the URSK include the identifier of the ultra-wideband service 1041. The URSK acquisition request received by the ultra-wideband client application 1016 carries the identifier of the target requester. The ultra-wideband client application 1016 determines whether the requester whitelist includes the identifier of the target requester. If the requester whitelist includes the identifier of the target requester, the ultra-wideband client application 1016 can request the URSK from the ultra-wideband trusted application 1015 through the security service 1014. If the requester whitelist includes the identifier of the target requester, the ultra-wideband client application 1016 does not request the URSK from the ultra-wideband trusted application 1015. Optionally, if the requester whitelist does not have the identifier of the target requester, the ultra-wideband client application 1016 can return a rejection response to the target requester, and the rejection response is used to indicate that the target requester does not have the permission to request the URSK.
[0249] Since the whitelist of requests includes the identifier of the ultra-wideband service 1041, the ultra-wideband service 1041 has the permission to request the URSK. The URSK acquisition request 1 also carries the identifier of the ultra-wideband service 1041. After obtaining the URSK acquisition request 1, the ultra-wideband client application 1016 can obtain the identifier of the ultra-wideband service 1041 from the URSK acquisition request 1. After determining that the whitelist of the requestor includes the identifier of the ultra-wideband service 1041, the ultra-wideband client application 1016 can send the URSK acquisition request 2 to the ultra-wideband trusted application 1015 through the security service 1014. After obtaining the target URSK returned by the ultra-wideband trusted application 1015, the ultra-wideband client application 1016 can send the target URSK to the ultra-wideband service 1041 in the microcontroller 104 through the ultra-wideband protocol stack and the kernel 1013. In this way, the permission to request the URSK can be controlled by the ultra-wideband client application 1016, so as to prevent other modules without permission from obtaining the URSK.
[0250] In a possible implementation, the digital key application 1021 can generate one or more URSKs based on the vehicle key session key, where one or more URSKs include the target URSK. The session identifiers (Session ID) corresponding to different URSKs are different. The ultra-wideband service 1041 in the microcontroller 104 can send the URSK acquisition request 1 to the ultra-wideband client application 1016 through the ultra-wideband protocol stack and the kernel 1013, where the URSK acquisition request 1 carries the session identifier A. The ultra-wideband client application 1016 can send the URSK acquisition request 2 to the ultra-wideband trusted application 1015 through the security service 1014, where the URSK acquisition request 2 carries the session identifier A, and the URSK acquisition request 2 is used to request the URSK from the ultra-wideband trusted application 1015. After receiving the URSK acquisition request 2, the ultra-wideband trusted application 1015 can send the URSK acquisition command to the secure ultra-wideband management application 1022 in the security chip 102, and the URSK acquisition command carries the session identifier A. After obtaining the URSK acquisition command, the secure ultra-wideband management application 1022 can determine the target URSK corresponding to the session identifier A from one or more URSKs saved by the digital key application 1021 through the internal interface (internal API). The secure ultra-wideband management application 1022 can return the target URSK to the ultra-wideband trusted application 1015. After obtaining the target URSK, the ultra-wideband trusted application 1015 can return the target URSK to the ultra-wideband client application 1016 through the security service 1014.
[0251] S1008. The ultra-wideband client application 1016 sends the target URSK to the ultra-wideband protocol stack and the kernel 1013.
[0252] S1009. The ultra-wideband protocol stack and the kernel 1013 send the target URSK to the microcontroller 104.
[0253] S1010. The secure ultra-wideband service 1042 in the microcontroller 104 can store the target URSK.
[0254] S1011. The ultra-wideband service 1041 in the microcontroller 104 can generate a UWB communication message based on the target URSK.
[0255] Among them, the ultra-wideband service 1041 can derive a ranging process key based on the target URSK. Then, the ultra-wideband service 1041 can generate ranging parameters (such as a scrambled timestamp sequence (STS), etc.) based on the ranging process key. The ultra-wideband service 1041 can generate a UWB communication message based on the ranging parameters.
[0256] S1012. The ultra-wideband service 1041 sends the UWB communication message to the ultra-wideband protocol stack and the kernel 1043.
[0257] S1013. The ultra-wideband protocol stack and the kernel 1043 can send the UWB communication message to the UWB chip 103.
[0258] Among them, after receiving the UWB communication message, the UWB chip 103 can send the UWB communication message to the device under test (such as vehicle 200).
[0259] The UWB chip 103 can also receive the UWB communication message sent by the device under test and send the received UWB communication message to the ultra-wideband service 1041 in the microcontroller 104 for parsing, thereby completing UWB secure ranging.
[0260] Next, the hardware structure of an electronic device provided in an embodiment of the present application is introduced.
[0261] Figure 11 A schematic diagram of the hardware structure of the electronic device 100 is shown.
[0262] Next, the embodiment is specifically described by taking the electronic device 100 as an example. It should be understood that Figure 11 The illustrated electronic device 100 is only an example, and the electronic device 100 may have more or fewer components than Figure 11 those shown, may combine two or more components, or may have a different component configuration. Figure 11 The various components shown in
[0263] The electronic device 100 may include: a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headphone interface 170D, a sensor module 180, a key 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and an embedded SIM (eSIM) module 195, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.
[0264] It can be understood that the structure illustrated in the embodiments of the present invention does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include more or fewer components than those illustrated, or combine certain components, or split certain components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0265] The processor 110 may include one or more processing units. For example, the processor 110 may include a central processing unit (CPU), and the central processing unit may also be referred to as an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), a security chip (SE), etc. Among them, different processing units may be independent devices or integrated in one or more processors.
[0266] Among them, the controller may be the nerve center and command center of the electronic device 100. The controller may generate operation control signals according to the instruction operation code and timing signal to complete the control of fetching instructions and executing instructions.
[0267] A memory can also be provided in the processor 110 for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. This memory can hold the instructions or data that the processor 110 has just used or recycled. If the processor 110 needs to use the instruction or data again, it can directly call it from the memory. This avoids repeated accesses, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.
[0268] In some embodiments, the processor 110 may include one or more interfaces. The interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface 130, etc.
[0269] The charging management module 140 is configured to receive a charging input from a charger. The charger can be a wireless charger or a wired charger. In some embodiments of wired charging, the charging management module 140 can receive the charging input from the wired charger through the USB interface 130. In some embodiments of wireless charging, the charging management module 140 can receive the wireless charging input through the wireless charging coil of the electronic device 100. While charging the battery 142, the charging management module 140 can also power the electronic device through the power management module 141.
[0270] The power management module 141 is used to connect the battery 142, the charging management module 140, and the processor 110. The power management module 141 receives inputs from the battery 142 and / or the charging management module 140, and supplies power to the processor 110, the internal memory 121, the external memory, the display screen 194, the camera 193, the wireless communication module 160, etc. The power management module 141 can also be used to monitor parameters such as the battery capacity, the number of battery cycles, and the battery health status (leakage, impedance). In some other embodiments, the power management module 141 can also be disposed in the processor 110. In some other embodiments, the power management module 141 and the charging management module 140 can also be disposed in the same device.
[0271] The wireless communication function of the electronic device 100 can be implemented by the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modulation and demodulation processor, and the baseband processor, etc.
[0272] The antenna 1 and the antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization rate of the antennas. For example: the antenna 1 can be multiplexed as the diversity antenna of the wireless local area network. In some other embodiments, the antenna can be used in combination with a tuning switch.
[0273] The mobile communication module 150 can provide solutions for wireless communications including 2G / 3G / 4G / 5G, etc. applied to the electronic device 100. The mobile communication module 150 can include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves by the antenna 1, filter, amplify, etc. the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves through the antenna 1 and radiate it out. In some embodiments, at least some functional modules of the mobile communication module 150 can be disposed in the processor 110. In some embodiments, at least some functional modules of the mobile communication module 150 and at least some modules of the processor 110 can be disposed in the same device.
[0274] The modulation and demodulation processor may include a modulator and a demodulator. Among them, the modulator is used to modulate the low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. Subsequently, the demodulator transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After being processed by the baseband processor, the low-frequency baseband signal is transmitted to the application processor. The application processor outputs a sound signal through an audio device (not limited to the speaker 170A, the receiver 170B, etc.), or displays an image or video through the display screen 194. In some embodiments, the modulation and demodulation processor may be an independent device. In other embodiments, the modulation and demodulation processor may be independent of the processor 110 and be disposed in the same device as the mobile communication module 150 or other functional modules.
[0275] The wireless communication module 160 may provide solutions for wireless communications applied to the electronic device 100, including ultra-wideband (UWB), wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared technology (IR), etc. The wireless communication module 160 may be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via the antenna 2, performs frequency modulation and filtering processing on the electromagnetic wave signals, and transmits the processed signals to the processor 110. The wireless communication module 160 may also receive the signals to be transmitted from the processor 110, perform frequency modulation and amplification on them, and convert them into electromagnetic waves through the antenna 2 for radiation.
[0276] In some embodiments, antenna 1 of electronic device 100 is coupled to mobile communication module 150, and antenna 2 is coupled to wireless communication module 160, such that electronic device 100 can communicate with a network and other devices through wireless communication technologies. The wireless communication technologies may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technologies, etc. The GNSS may include global positioning system (GPS), global navigation satellite system (GLONASS), beidou navigation satellite system (BDS), quasi-zenith satellite system (QZSS), and / or satellite based augmentation systems (SBAS).
[0277] Electronic device 100 implements a display function through a GPU, display screen 194, and an application processor, etc. The GPU is a microprocessor for image processing, and is connected to display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. Processor 110 may include one or more GPUs, which execute program instructions to generate or change display information.
[0278] The display screen 194 is used to display images, videos, etc. The display screen 194 includes a display panel. The display panel can adopt a liquid crystal display (LCD). The display screen panel can also adopt an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a mini-LED, a micro-LED, a micro-OLED, a quantum dot light-emitting diode (QLED), etc. to manufacture. In some embodiments, the electronic device 100 may include one or N display screens 194, where N is a positive integer greater than 1.
[0279] The electronic device 100 can implement the shooting function through the ISP, the camera 193, the video codec, the GPU, the display screen 194, and the application processor, etc.
[0280] The ISP is used to process the data fed back by the camera 193. For example, when taking a photo, the shutter is opened, and the light passes through the lens and is transmitted to the camera photosensitive element. The optical signal is converted into an electrical signal, and the camera photosensitive element transmits the electrical signal to the ISP for processing and converts it into an image visible to the naked eye. The ISP can also perform algorithm optimization on the noise, brightness, etc. of the image. The ISP can also optimize parameters such as the exposure and color temperature of the shooting scene. In some embodiments, the ISP can be set in the camera 193.
[0281] The camera 193 is used to capture static images or videos. The object generates an optical image through the lens and projects it onto the photosensitive element. The photosensitive element can be a charge-coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the optical signal into an electrical signal, and then transmits the electrical signal to the ISP to convert it into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in standard RGB, YUV, etc. formats. In some embodiments, the electronic device 100 may include one or N cameras 193, where N is a positive integer greater than 1.
[0282] The digital signal processor is used to process digital signals. Besides processing digital image signals, it can also process other digital signals. For example, when the electronic device 100 selects a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy, etc.
[0283] The video codec is used to compress or decompress digital videos. The electronic device 100 can support one or more video codecs. In this way, the electronic device 100 can play or record videos in multiple encoding formats, such as: Moving Picture Experts Group (MPEG) 1, MPEG2, MPEG3, MPEG4, etc.
[0284] The NPU is a neural-network (NN) computing processor. By drawing on the structure of biological neural networks, such as the transmission pattern between human brain neurons, it can quickly process input information and can also continuously self-learn. Through the NPU, applications such as intelligent cognition of the electronic device 100 can be realized, such as: image recognition, face recognition, speech recognition, text understanding, etc.
[0285] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 through the external memory interface 120 to achieve the data storage function. For example, files such as music and videos are saved in the external memory card.
[0286] The internal memory 121 can be used to store computer-executable program code, and the executable program code includes instructions. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 121. The internal memory 121 can include a program storage area and a data storage area. Among them, the program storage area can store the operating system, application programs required for at least one function (such as the sound playback function, image playback function, etc.). The data storage area can store the data created during the use of the electronic device 100 (such as audio data, phone book, etc.). In addition, the internal memory 121 can include high-speed random access memory and can also include non-volatile memory, such as at least one disk storage device, flash memory device, universal flash storage (UFS), etc.
[0287] The electronic device 100 can implement audio functions through the audio module 170, speaker 170A, receiver 170B, microphone 170C, headphone jack 170D, and application processor, etc. For example, music playback, recording, etc. The pressure sensor 180A is used to sense pressure signals and can convert the pressure signals into electrical signals. In some embodiments, the pressure sensor 180A can be disposed on the display screen 194. The gyroscope sensor 180B can be used to determine the motion posture of the electronic device 100. The barometric pressure sensor 180C is used to measure barometric pressure. The magnetic sensor 180D includes a Hall sensor. The electronic device 100 can use the magnetic sensor 180D to detect the opening and closing of the flip leather case. The acceleration sensor 180E can detect the magnitude of the acceleration of the electronic device 100 in various directions (generally three axes). The distance sensor 180F is used to measure distance. The proximity light sensor 180G can include, for example, a light-emitting diode (LED) and a light detector, such as a photodiode. The ambient light sensor 180L is used to sense the ambient light brightness. The fingerprint sensor 180H is used to collect fingerprints. The temperature sensor 180J is used to detect temperature. The touch sensor 180K, also known as the "touch panel". The touch sensor 180K can be disposed on the display screen 194, and the touch sensor 180K and the display screen 194 form a touch screen, also known as the "touch display screen". The touch sensor 180K is used to detect touch operations acting thereon or nearby. The touch sensor can transmit the detected touch operation to the application processor to determine the type of touch event. Visual output related to the touch operation can be provided through the display screen 194. In other embodiments, the touch sensor 180K can also be disposed on the surface of the electronic device 100, at a different position from the display screen 194. The bone conduction sensor 180M can acquire vibration signals. The keys 190 include a power-on key, volume keys, etc. The motor 191 can generate a vibration prompt. The indicator 192 can be an indicator light, which can be used to indicate the charging state, power change, and can also be used to indicate messages, missed calls, notifications, etc.
[0288] In the embodiments of the present application, the security chip and the NFC chip can be integrated into two parts of the same chip, or can be two separate chips, which is not limited herein.
[0289] The structure of the server provided in the embodiments of the present application will be introduced below.
[0290] Figure 12 The schematic diagram of the hardware structure of the server 300 is shown.
[0291] As Figure 12As shown, the server 300 may include one or more processors 301, a communication interface 302, and a memory 303. The processors 301, the communication interface 302, and the memory 303 may be connected by a bus or other means. In this embodiment of the application, it is taken as an example that they are connected by a bus 304. Among them:
[0292] The processor 301 may be composed of one or more general-purpose processors, such as a CPU. The processor 301 may be used to run the program code related to the device control method.
[0293] The communication interface 302 may be a wired interface (such as an Ethernet interface) or a wireless interface (such as a cellular network interface), and is used to communicate with other nodes. In this embodiment of the application, the communication interface 302 may specifically be used to communicate with the electronic device 100, and receive the manufacturer identification and chip identification of the UWB chip sent by the electronic device 100.
[0294] The memory 303 may include a volatile memory, such as a random access memory (RAM); it may also include a non-volatile memory, such as a ROM, a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); the memory 303 may also include a combination of the above types of memories.
[0295] It should be noted that Figure 12 the shown server 300 is only one implementation manner of this embodiment of the application. In actual application, the server 300 may also include more or fewer components, which are not limited here.
[0296] This embodiment of the application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in the above-mentioned various method embodiments can be implemented.
[0297] This embodiment of the application also provides a computer program product. When the computer program product runs on a computer, the computer can implement the steps in the above-mentioned various method embodiments.
[0298] This embodiment of the application also provides a chip system. The chip system includes a central processor, a UWB chip, and a security chip. Among them, the UWB chip is not connected to the security chip, the processor is connected to the UWB chip, and the processor is connected to the security chip. The chip system can implement the steps in any method embodiment of this application. Among them, the chip system may be a single chip or a chip module composed of multiple chips.
[0299] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than limiting them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the various embodiments of the present application.
Claims
1. A method for transmitting ultra-wideband UWB keys, characterized in that, Applied to an electronic device, the electronic device includes a central processing unit, a UWB chip, and a security chip. The processor is connected to the UWB chip, and the processor is connected to the security chip. The method includes: The central processing unit obtains a UWB transmission key and stores the UWB transmission key in the security chip. A target UWB ranging session key URSK is stored in the security chip. The security chip uses the UWB transmission key to encrypt the target URSK into first encrypted data. The security chip sends the first encrypted data to the UWB chip through the central processing unit, where the UWB chip stores a UWB transmission key. The UWB chip decrypts the target URSK from the first encrypted data through the UWB transmission key, and the target URSK is used for ranging by the UWB chip.
2. The method according to claim 1, wherein The central processing unit obtains the UWB transmission key, specifically including: The central processing unit obtains the UWB transmission key sent by the server.
3. The method according to claim 2, wherein Before the central processing unit obtains the UWB transmission key sent by the server, the method further includes: The central processing unit obtains the manufacturer identifier of the UWB chip and the chip identifier of the UWB chip from the UWB chip. The central processing unit sends a first request to the server. The first request carries the manufacturer identifier of the UWB chip and the chip identifier of the UWB chip. The first request is used to request the server to generate the UWB transmission key based on the root key, the manufacturer identifier of the UWB chip, and the chip identifier of the UWB chip.
4. The method according to claim 2 or 3, characterized in that Before the central processing unit obtains the UWB transmission key, the method further includes: Before the electronic device leaves the factory, the UWB chip exports the manufacturer identifier of the UWB chip and the chip identifier of the UWB chip to an encryption machine. The encryption machine is used to generate the UWB transmission key based on the root key, the manufacturer identifier of the UWB chip, and the chip identifier of the UWB chip. The UWB chip receives the UWB transmission key imported by the encryption machine.
5. The method according to claim 2 or 3, characterized in that, Before storing the UWB transmission key in the UWB chip, the method further includes: The UWB chip generates a first public key and a first private key, and the first public key and the first private key are a pair of public and private keys. The UWB chip sends the first public key to the central processing unit. After the central processing unit obtains the UWB transmission key sent by the server, it encrypts the UWB transmission key into second encrypted data using the first public key. The central processing unit sends the second encrypted data to the UWB chip. The UWB chip decrypts the UWB transmission key from the second encrypted data using the first private key.
6. The method according to claim 1, characterized in that Before storing the UWB transmission key in the UWB chip, the method further includes: The UWB chip generates the UWB transmission key.
7. The method according to claim 6, wherein Before the central processing unit obtains the UWB transmission key, the method further includes: The central processing unit generates a second public key and a second private key, and the second public key and the second private key are a pair of public and private keys; The central processing unit sends the second public key to the UWB chip; The central processing unit obtains the ultra-wideband transmission key, specifically including: The UWB chip encrypts the ultra-wideband transmission key into third encrypted data using the second public key; The UWB chip sends the third encrypted data to the central processing unit; The central processing unit decrypts the ultra-wideband transmission key from the third encrypted data using the second private key.
8. The method according to claim 6 or 7, characterized in that, The UWB chip generates the ultra-wideband transmission key, specifically including: The UWB chip randomly generates the ultra-wideband transmission key.
9. The method according to claim 6 or 7, characterized in that, The UWB chip stores the manufacturer identification of the UWB chip and the chip identification of the UWB chip; The UWB chip generates the ultra-wideband transmission key, specifically including: The UWB chip generates the ultra-wideband transmission key based on the root key, the manufacturer identification of the UWB chip, and the chip identification of the UWB chip.
10. The method according to claim 9, wherein The UWB chip generates the ultra-wideband transmission key based on the root key, the manufacturer identification of the UWB chip, and the chip identification of the UWB chip, specifically including: The UWB chip generates a pairing key based on the root key and the manufacturer identification of the UWB chip; The UWB chip generates the ultra-wideband transmission key based on the pairing key and the chip identification of the UWB chip.
11. The method according to any one of claims 1 to 10, characterized in that, The security chip stores the target ultra-wideband ranging session key URSK, specifically including: The security chip generates one or more URSKs through the stored vehicle key session key, and the one or more URSKs include the target URSK; The security chip stores the one or more URSKs, where the session identifiers corresponding to different URSKs are different.
12. The method according to claim 11, wherein Before the security chip encrypts the target URSK into first encrypted data using the ultra-wideband transmission key, the method further includes: The UWB chip sends a URSK acquisition command to the security chip through the central processing unit, and the URSK acquisition command carries a first session identifier; After receiving the URSK acquisition command, the security chip determines the target URSK corresponding to the first session identifier from the one or more URSKs.
13. The method according to claim 12, characterized in that, Before the UWB chip sends a URSK acquisition command to the security chip through the central processing unit, the method further includes: The UWB chip sends a random number acquisition command to the security chip through the central processing unit; After receiving the random number acquisition command, the security chip sends a first random number to the UWB chip through the central processing unit; The UWB chip encrypts the first random number into an authentication ciphertext using the ultra-wideband transmission key and sends the authentication ciphertext to the security chip through the central processing unit; The security chip decrypts a second random number from the authentication ciphertext using the ultra-wideband transmission key; If the second random number is the same as the first random number, the security chip sends a first response to the UWB chip through the central processor, and the first response is used to indicate that the random number verification is passed; The UWB chip sends a URSK acquisition command to the security chip through the central processor, specifically including: After receiving the first response, the UWB chip sends the URSK command to the security chip through the central processor.
14. The method according to any one of claims 1-13, characterized in that, A rich execution environment REE and a trusted execution environment TEE are running in the central processor, and a vehicle key application is running in the REE; The central processor obtains the ultra-wideband transmission key, specifically including: The central processor obtains the ultra-wideband transmission key through the vehicle key application; The central processor stores the ultra-wideband transmission key in the security chip, specifically including: The central processor stores the ultra-wideband transmission key in the security chip through the vehicle key application and the TEE.
15. The method according to any one of claims 1-14, characterized in that, The UWB chip is not connected to the security chip.
16. An electronic device, characterized in that, Including: One or more processors, one or more memories, a security chip and a UWB chip, and the one or more processors include a central processor; wherein, the central processor is connected to the UWB chip, and the central processor is connected to the security chip; the one or more memories are used to store computer programs, and when the one or more processors execute the computer programs, the first electronic device is caused to execute the method according to any one of claims 1-15.
17. A computer storage medium, characterized in that, Including a computer program, when the computer program runs on a processor of an electronic device, the electronic device is caused to execute the method according to any one of claims 1-15.
18. A chip system, characterized in that, Applied to the electronic device, the chip system includes: a central processor, a UWB chip and a security chip, wherein, the UWB chip is not connected to the security chip, the processor is connected to the UWB chip, the processor is connected to the security chip, and the chip system is used to execute the method according to any one of claims 1-15.
Citation Information
Cited By
UWB key transmission method and related apparatus
EP4761298A1
UWB key transmission method and related apparatus
WO2025162042A1