Vehicle service activation method, apparatus, device, storage medium and program product

By using vehicle certificate authentication and a two-way authentication channel, and activating vehicle services using the Vehicle Identification Number (VIN), the problem of narrow authentication scope and security risks in existing technologies is solved, and a simple and secure method for activating vehicle services is achieved.

CN122294092APending Publication Date: 2026-06-26SHANGHAI PATEO ELECTRONIC EQUIPMENT MANUFACTURING CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHANGHAI PATEO ELECTRONIC EQUIPMENT MANUFACTURING CO LTD
Filing Date
2024-12-26
Publication Date
2026-06-26

AI Technical Summary

Technical Problem

In existing technologies, authentication methods based on user tokens cannot activate vehicle services when the user is not logged into the vehicle system, resulting in a narrow scope of application; using fixed authorization codes for access poses security risks and management difficulties.

Method used

Authentication is performed using vehicle certificates. The vehicle identification number (VIN) in the vehicle certificate is used to uniquely identify the vehicle, establish a two-way authentication channel between the vehicle and the cloud, determine the target service and configuration information package, and activate the vehicle service.

Benefits of technology

It enables easy activation of vehicle services without the need for user accounts and passwords, prevents identity fraud, has a wide range of applications, high security, and allows for unified management of vehicle service activation and deactivation in the cloud.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122294092A_ABST
    Figure CN122294092A_ABST
Patent Text Reader

Abstract

This disclosure provides a vehicle service activation method, apparatus, device, storage medium, and program product. The vehicle service activation method includes: in response to a service activation request triggered upon the first ignition of a vehicle, authenticating the vehicle based on a vehicle certificate carried in the service activation request; the vehicle certificate uniquely identifies the vehicle; if vehicle authentication is successful, determining a target service that the vehicle can activate and a configuration information package of the target service based on the vehicle identification code in the vehicle certificate; and returning the configuration information package to the vehicle so that the vehicle can activate the target service based on the configuration information package. Thus, activation authentication is performed directly using the vehicle identification code in the vehicle certificate, resulting in a simple activation method, wide applicability, and high security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to, but is not limited to, the field of vehicle networking technology, and particularly to a vehicle service activation method, apparatus, device, storage medium, and program product. Background Technology

[0002] The rapid development of intelligent in-vehicle software has led to a diversified trend in vehicle services. In related technologies, the vehicle sends a service activation request to the cloud, carrying a token issued upon successful user login. Upon receiving the request, the cloud determines whether to activate the vehicle service based on the token's validity. However, this token-based authentication method relies on the user's account and password, making it impossible to activate the service without the user logging into the vehicle system, thus limiting its applicability. Summary of the Invention

[0003] In view of this, the present disclosure provides at least one vehicle service activation method, apparatus, device, storage medium, and program product.

[0004] The technical solution of this disclosure embodiment is implemented as follows:

[0005] On one hand, this disclosure provides a vehicle service activation method including: in response to a service activation request triggered when the vehicle is first started, authenticating the vehicle based on the vehicle certificate carried in the service activation request; the vehicle certificate is used to uniquely identify the vehicle; if the vehicle authentication is successful, determining the target service that the vehicle can activate and the configuration information package of the target service based on the vehicle identification code in the vehicle certificate; and returning the configuration information package to the vehicle so that the vehicle can activate the target service based on the configuration information package.

[0006] In some embodiments, authenticating a vehicle based on a vehicle certificate carried in a service activation request includes: establishing a two-way authentication channel between the vehicle and the cloud; performing two-way authentication between the vehicle and the cloud based on the vehicle certificate and the cloud certificate; verifying the validity of the vehicle certificate if the two-way authentication is successful; and determining that the vehicle authentication is successful if the validity verification is successful.

[0007] In some embodiments, determining the target service that the vehicle can activate and the configuration information package of the target service based on the vehicle identification code in the vehicle certificate includes: extracting the value of a target field from the vehicle certificate; the value of the target field can uniquely identify the vehicle; using the value of the target field as the vehicle identification code; carrying the vehicle identification code in the request header of the service activation request and forwarding it to the service management module in the cloud; and determining the target service that the vehicle can activate and the configuration information package of the target service based on the vehicle identification code through the service management module.

[0008] In some embodiments, determining the target service that the vehicle can activate and the configuration information package of the target service based on the vehicle identification code includes: searching for the vehicle model in the database based on the vehicle identification code; determining the target service that the vehicle can activate based on the vehicle model; determining the configuration information required for each target service to be activated; and encrypting and packaging the configuration information based on the private key in the cloud to obtain the configuration information package.

[0009] On one hand, this disclosure provides a vehicle service activation method including: when the vehicle is started for the first time, carrying the vehicle certificate obtained from the vehicle's security chip with a service activation request and sending it to the cloud; receiving a configuration information package of the target service that the vehicle can activate, returned by the cloud; the configuration information package is determined based on the vehicle certificate and the vehicle identification code in the vehicle certificate; verifying the security and integrity of the configuration information package; and activating the target service based on the configuration information package if the verification is successful.

[0010] In some embodiments, activating a target service based on a configuration information package includes: in response to a click operation on any service in the target service, determining the configuration information required for activation of any service from the configuration information package; setting service parameters in the configuration information; and activating any service.

[0011] On the other hand, embodiments of this disclosure provide a vehicle service activation device including: an authentication module configured to authenticate the vehicle based on a vehicle certificate carried in the service activation request in response to a service activation request triggered when the vehicle is first started; the vehicle certificate is used to uniquely identify the vehicle; a processing module configured to determine, in the case of successful vehicle authentication, a target service that the vehicle can activate and a configuration information package of the target service based on the vehicle identification code in the vehicle certificate; the processing module is further configured to return the configuration information package to the vehicle so that the vehicle can activate the target service based on the configuration information package.

[0012] On the other hand, this disclosure provides a vehicle service activation device comprising: a sending module configured to send a service activation request along with a vehicle certificate obtained from the vehicle's security chip to the cloud when the vehicle is first started; a receiving module configured to receive a configuration information package of a target service that the vehicle can activate, returned by the cloud; the configuration information package being determined based on the vehicle certificate and the vehicle identification code in the vehicle certificate; a verification module configured to verify the security and integrity of the configuration information package; and an activation module configured to activate the target service based on the configuration information package if the verification is successful.

[0013] In another aspect, embodiments of this disclosure provide a computer device, including a memory and a processor. The memory stores a computer program that can run on the processor, and the processor executes the program to implement some or all of the steps in the above-described method.

[0014] In another aspect, embodiments of this disclosure provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements some or all of the steps in the above-described method.

[0015] In another aspect, embodiments of this disclosure provide a computer program including computer-readable code, which, when executed in a computer device, causes a processor in the computer device to perform some or all of the steps in the above-described method.

[0016] In another aspect, embodiments of this disclosure provide a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program. When the computer program is read and executed by a computer, it implements some or all of the steps in the above-described method.

[0017] In this embodiment, vehicle authentication is performed using the vehicle certificate carried in the service activation request. This effectively identifies the request initiator and prevents other users from impersonating the current user and sending requests to the cloud using their own certificates. By using the Vehicle Identification Number (VIN) in the vehicle certificate, different vehicles have different activation keys, greatly reducing the risk of identity forgery during vehicle-to-cloud connection. Each vehicle does not need to carry a VIN when initiating a request; the VIN is directly extracted from the vehicle certificate, further minimizing the risk of identity forgery. Activation does not rely on the user's account and password; activation authentication is performed directly based on the VIN in the vehicle certificate, making the activation method simple and widely applicable. Furthermore, throughout the activation process, the VIN can be used to determine whether the request initiator's VIN is uniquely associated with the vehicle, preventing other users from using their own certificates to modify the vehicle identification number to match the VIN of the attacked vehicle for identity forgery, thus ensuring high security.

[0018] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and are not intended to limit the technical solutions of this disclosure. Attached Figure Description

[0019] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the specification, serve to illustrate the technical solutions of this disclosure.

[0020] Figure 1 A schematic diagram of the implementation process of a vehicle service activation method provided in this embodiment of the disclosure. Figure 1 ;

[0021] Figure 2 A schematic diagram of the implementation process of a vehicle service activation method provided in this embodiment of the disclosure. Figure 2 ;

[0022] Figure 3 A schematic diagram of the implementation process of a vehicle service activation method provided in this embodiment of the disclosure. Figure 3 ;

[0023] Figure 4 A schematic diagram of the implementation process of a vehicle service activation method provided in this embodiment of the disclosure. Figure 4 ;

[0024] Figure 5 This is a schematic diagram illustrating the implementation of a vehicle certificate in a vehicle service activation method provided in this embodiment of the disclosure;

[0025] Figure 6 A schematic diagram of the implementation process of a vehicle service activation method provided in this embodiment of the disclosure. Figure 5 ;

[0026] Figure 7 A schematic diagram of the composition structure of a vehicle service activation device provided in this embodiment of the present disclosure. Figure 1 ;

[0027] Figure 8 A schematic diagram of the composition structure of a vehicle service activation device provided in this embodiment of the present disclosure. Figure 2 ;

[0028] Figure 9 This is a schematic diagram of the hardware entity of a computer device provided in an embodiment of this disclosure. Detailed Implementation

[0029] To make the objectives, technical solutions, and advantages of this disclosure clearer, the technical solutions of this disclosure are further described in detail below with reference to the accompanying drawings and embodiments. The described embodiments should not be regarded as limitations on this disclosure. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0030] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0031] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains. The terminology used herein is for descriptive purposes only and is not intended to limit the scope of this disclosure.

[0032] To better understand the vehicle service activation method provided in this disclosure, the solutions in related technologies will be described below.

[0033] One related technology is a user token-based authentication method. When the vehicle initiates a service activation request to the cloud, it carries the token issued after the user successfully logs in. The cloud determines whether to activate the vehicle service based on the validity of the user token.

[0034] The second related technology involves access based on a fixed authorization code. For example, when a vehicle is decommissioned, the vehicle's terminal stores a fixed account password or application ID and application key. The vehicle then uses the account password or application ID and application password stored on the vehicle to initiate a service activation request to the cloud platform.

[0035] The above technical solution has the following technical problems:

[0036] 1. The user token-based authentication method relies on the user logging in with an account and password. If the user is not operating the vehicle, the vehicle may not be logged in, and the vehicle does not have the user's token. Furthermore, in-vehicle smart terminals (Telematics Box, T-BOX) themselves do not have the ability to log in with a user account and password. Therefore, user token-based authentication is only suitable for in-vehicle systems or owner applications (APPs), and not for many in-vehicle smart components, such as T-BOX devices, limiting its applicability.

[0037] 2. Using a fixed authorization code for access poses security risks. Storing account passwords inside the vehicle makes them vulnerable to leakage. If every vehicle uses the same account password upon production, and the default account password is leaked, or a device is compromised, all vehicles using the same type of account password will be at security risk.

[0038] 3. Assuming each vehicle uses a different account and password, an account and password need to be generated for each vehicle when it rolls off the production line. The account and password are then linked to the vehicle's VIN and stored in the cloud. While this allows different vehicles to use different account and password, centralized management of account and password in the cloud poses a risk of leakage. Furthermore, according to relevant security requirements, account and password need to be updated every 3 months. It is difficult to update the password fixed on the vehicle regularly. If a vehicle has not been started for 4 months, the password stored on the vehicle will have expired, and the vehicle will be unable to update to a new password, resulting in a failure to connect to the cloud platform.

[0039] Therefore, this disclosure provides a vehicle service activation method, which can be executed by a processor in the cloud (cloud platform). Figure 1 As shown, the method includes the following steps 101 to 103:

[0040] Step 101: In response to the service activation request triggered when the vehicle is first started, authenticate the vehicle based on the vehicle certificate carried in the service activation request; the vehicle certificate is used to uniquely identify the vehicle.

[0041] A service activation request is used to activate vehicle services. Vehicle services refer to the various convenient functions and assistance systems provided to users within the vehicle, designed to enhance the driving experience, safety, and comfort. Vehicle services may include, but are not limited to: navigation services, entertainment services, communication services, driver assistance systems, remote control, vehicle-to-everything (V2X) services, personalization settings, vehicle diagnostics, etc. A vehicle certificate refers to the official certification and documentation of the vehicle.

[0042] In some implementations, obtaining a vehicle certificate can be achieved by having the OEM install a uniquely numbered certificate on each vehicle after it rolls off the production line. The vehicle then stores the certificate's private key and the certificate itself in a secure chip to prevent the private key from being leaked.

[0043] In some implementations, the specific method for "authenticating the vehicle based on the vehicle certificate carried in the service activation request" can be as follows: if the carried vehicle certificate is an encrypted vehicle certificate, then the encrypted vehicle certificate is decrypted using the vehicle's public key; if decryption is successful, then authentication is successful; if decryption fails, then authentication fails.

[0044] In some implementations, the specific way to "authenticate the vehicle based on the vehicle certificate carried in the service activation request" can be: based on the vehicle's identifier, determine the correspondence between the vehicle identifier stored in the cloud and the vehicle certificate identifier; and authenticate the carried vehicle certificate based on the correspondence between the vehicle identifier and the vehicle certificate identifier.

[0045] Specifically, the specific implementation of "authenticating the carried vehicle certificate based on the correspondence between the vehicle identifier and the vehicle certificate identifier" can be as follows: determine the first vehicle identifier that triggers the service activation request; determine the vehicle certificate that matches the first vehicle identifier from the correspondence between the vehicle identifier and the vehicle certificate identifier; if the carried vehicle certificate matches the matched vehicle certificate, the authentication is successful; if the carried vehicle certificate does not match the matched vehicle certificate, the authentication fails.

[0046] Step 102: If the vehicle authentication is successful, determine the target service that the vehicle can activate and the configuration information package of the target service based on the vehicle identification code in the vehicle certificate.

[0047] The Vehicle Identification Number (VIN) is a unique identification code for a vehicle, consisting of 17 characters, including letters and numbers. The VIN not only represents information such as the vehicle's manufacturer, model, and year of manufacture, but is also used in various aspects of vehicle management, fault diagnosis, and insurance registration. For example, the VIN can be the value of the Common Name field on a certificate, and the Common Name field can be the vehicle identification number (VIN).

[0048] The configuration information package is used to activate the corresponding service. The configuration information package may include, but is not limited to: service type, home region, configuration parameters, parameter values, and parameter status. Service type may include, but is not limited to: navigation service, entertainment service, seating adjustment service, and instruction service. The home region defines which module of the vehicle the service belongs to; for example, navigation service belongs to the navigation module. Configuration information includes: Access Point Name (APN), server address (HOST), attribute status (Status), enabled status (Enabled), and license information (License). The APN identifies the data network in the mobile network; in the vehicle system, the APN configuration allows the vehicle terminal to connect to network services provided by the operator. The APN configuration includes: name, APN address, username and password (if needed), proxy server address and port, MMS server address, etc. The HOST is used for communication between the vehicle terminal and the server; this address is used for vehicle diagnostics, software updates, remote monitoring, and other functions. Status indicates the current status of the vehicle attribute, which can be AVAILABLE (attribute available and value valid), UNAVAILABLE (attribute value currently unavailable), or ERROR (attribute has a problem). The Enabled property is typically used to indicate whether a vehicle service or function is enabled. In vehicle configuration, Enabled can be a boolean value used to control whether a specific vehicle function is activated.

[0049] In some implementations, the specific implementation of "determining the target service that the vehicle can activate and the configuration information package of the target service based on the vehicle identification code in the vehicle certificate" can be as follows: determining the correspondence between the vehicle identification code in the vehicle certificate, multiple vehicle identification codes pre-stored in the cloud, and the services that can be activated; determining the service that matches the vehicle identification code from the correspondence between the multiple vehicle identification codes and the services that can be activated; taking the matched service as the target service, and obtaining the configuration information package of the target service.

[0050] In some implementations, during the vehicle service activation process, the vehicle identification number (VIN) can be used to verify vehicle ownership and determine whether the VIN of the requester is associated with a specific vehicle. This prevents other users from using their own certificates to send requests to the cloud and then modifying the VIN to match that of the attacked vehicle.

[0051] Step 103: Return the configuration information package to the vehicle so that the vehicle can activate the target service based on the configuration information package.

[0052] In some implementations, step 301 can be specifically implemented by: encrypting the configuration information package using a private key in the cloud, and then sending the encrypted configuration information package to the vehicle.

[0053] In this embodiment, vehicle authentication is performed using the vehicle certificate carried in the service activation request. This effectively identifies the request initiator and prevents other users from impersonating the current user and sending requests to the cloud using their own certificates. By using the Vehicle Identification Number (VIN) in the vehicle certificate, different vehicles have different activation keys, greatly reducing the risk of identity forgery during vehicle-to-cloud connection. Each vehicle does not need to carry a VIN when initiating a request; the VIN is directly extracted from the vehicle certificate, further minimizing the risk of identity forgery. Activation does not rely on the user's account and password; activation authentication is performed directly based on the VIN in the vehicle certificate, making the activation method simple and widely applicable. Furthermore, throughout the activation process, the VIN can be used to determine whether the request initiator's VIN is uniquely associated with the vehicle, preventing other users from using their own certificates to modify the vehicle identification number to match the VIN of the attacked vehicle for identity forgery, thus ensuring high security.

[0054] This disclosure provides a vehicle service activation method, which can be executed by the vehicle's processor. For example... Figure 2 As shown, the method includes the following steps 201 to 204:

[0055] Step 201: When the vehicle is started for the first time, the vehicle certificate obtained from the vehicle's security chip is carried along with the service activation request and sent to the cloud.

[0056] In some implementations, step 201 can be specifically implemented as follows: when the vehicle is started for the first time, the vehicle certificate is obtained from the vehicle's security chip based on the vehicle identifier; the vehicle certificate is sent to the cloud along with the service activation request.

[0057] Step 202: Receive the configuration information package of the target service that the vehicle can activate, returned by the cloud; the configuration information package is determined based on the vehicle certificate and the vehicle identification code in the vehicle certificate.

[0058] Step 203: Verify the security and integrity of the configuration information package.

[0059] In some implementations, the configuration information packet is decrypted using a public key in the cloud; if decryption is successful, the security verification is considered successful; then, an integrity verification algorithm is used to verify the configuration information packet. Integrity verification algorithms may include, but are not limited to, hash algorithms, cyclic redundancy check (CRC) algorithms, and parity check algorithms.

[0060] For example, the integrity verification algorithm is a hash algorithm. When the cloud returns the configuration information packet to the vehicle, it uses a preset hash algorithm to calculate the configuration information packet and obtains a first hash value; the first hash value and the configuration information packet are then sent to the vehicle together. After receiving the configuration information packet, the vehicle uses the hash algorithm to calculate the configuration information packet and obtains a second hash value; if the first hash value and the second hash value are the same, the integrity verification is considered successful; if the first hash value and the second hash value are different, the integrity verification is considered to have failed.

[0061] Step 204: If the verification is successful, activate the target service based on the configuration information package.

[0062] In some implementations, activating a service can be achieved by: determining the relevant information of the service from the configuration information package; configuring the relevant parameters of the service based on the relevant information of the service; and starting the service.

[0063] For example, if a user wants to use the navigation service, the navigation service extracts the line "navigation service capabilityId="<map navigation>" from the configuration information package, and then obtains information such as APN, host, status, enabled, and license. Among them, host is the cloud interface address of the navigation service, APN is the traffic channel used by the vehicle, status indicates whether the service is online, enabled indicates whether the vehicle has enabled the map navigation service, and license contains the activation date and expiration date of the service.

[0064] In this embodiment, each vehicle does not need to carry a Vehicle Identification Number (VIN) when initiating a request; it only carries a vehicle certificate. Thus, authenticating the vehicle using the vehicle certificate carried in the service activation request effectively identifies the requester's identity, preventing other users from using their own certificates to initiate requests to the cloud. The VIN in the vehicle certificate ensures that different vehicles have different activation keys, greatly reducing the risk of identity forgery during vehicle-to-cloud connection. Activation does not rely on the user's account and password; activation authentication is directly based on the VIN in the vehicle certificate, making the activation method simple and widely applicable. Furthermore, throughout the activation process, the VIN can be used to determine whether the requester's VIN is uniquely associated with the vehicle, preventing other users from using their own certificates to modify the vehicle identification number to match the VIN of an attacked vehicle for identity forgery, ensuring high security. In addition, the cloud provides unified management of vehicle services, allowing for flexible control over the activation and deactivation of vehicle services through this global configuration.

[0065] This disclosure provides a vehicle service activation method, which can be executed by a cloud processor. For example... Figure 3 As shown, the method includes the following steps 301 to 308:

[0066] Step 301: In response to the service activation request triggered when the vehicle is first started, establish a two-way authentication channel between the vehicle and the cloud.

[0067] In some implementations, step 301 can be specifically implemented as follows: in response to a service activation request, a two-way authentication channel based on Hypertext Transfer Protocol (HTTP) is established between the vehicle and the cloud (hereinafter referred to as vehicle-cloud).

[0068] Specifically, the process of establishing a two-way authentication channel based on HTTP is as follows: the vehicle and the cloud each generate their own key pair, including a private key and a public key; the vehicle and the cloud register with a trusted Certificate Authority (CA); and an HTTPS connection is established between the vehicle and the cloud.

[0069] It should be noted that to ensure the authenticity, confidentiality, and integrity of data transmission, a two-way authentication method based on digital certificates can be adopted, along with hash cryptography algorithms (such as SM3) and digital signature algorithms (such as SM2). In remote communication scenarios, vehicles can use their private keys to digitally sign reported messages, and the cloud verifies the signature data to prevent data from being compromised. During vehicle-to-cloud communication, security protocols such as Transport Layer Security (TLS) and Transport Layer Cryptography Protocol (TLCP) can be used to establish a secure link, ensuring the security and traceability of information transmitted between the vehicle-to-everything (V2X) cloud platform and the vehicle.

[0070] Step 302: Perform two-way authentication between the vehicle and the cloud based on the vehicle certificate and the cloud certificate.

[0071] In some implementations, step 302 can be specifically implemented as follows: the vehicle obtains a cloud certificate encrypted with the cloud private key; the cloud certificate is decrypted using the cloud public key; if decryption is successful, the verification is successful; if decryption fails, the verification fails. Alternatively, the cloud can obtain a vehicle certificate encrypted with the vehicle's private key; the vehicle certificate is decrypted using the vehicle's public key; if decryption is successful, the verification is successful; if decryption fails, the verification fails.

[0072] Furthermore, after the vehicle decrypts the cloud certificate, it can also verify any data field in the cloud certificate; conversely, after the cloud decrypts the vehicle certificate, it can also verify any data field in the vehicle certificate. This further enhances the effectiveness of the verification.

[0073] Step 303: If the two-way authentication is successful, verify the validity of the vehicle certificate.

[0074] In some implementations, the specific method for "verifying the validity of the vehicle certificate" can be: verifying the validity of the vehicle certificate based on its expiration date. Specifically, if the expiration date of the vehicle certificate includes the current time, the vehicle certificate is determined to be valid; if the expiration date of the vehicle certificate is before the current time, the vehicle certificate is determined to be invalid.

[0075] Step 304: If the validity verification is successful, determine that the vehicle authentication is successful.

[0076] The vehicle certificate is used to uniquely identify the vehicle.

[0077] Here, steps 301 to 304 correspond to step 101 mentioned above, and can be implemented with reference to the specific implementation of step 101 mentioned above.

[0078] Step 305: If the vehicle authentication is successful, extract the value of the target field from the vehicle certificate; the value of the target field can uniquely identify the vehicle.

[0079] The target field refers to the common name field. The value of the target field is the vehicle identification number (VIN).

[0080] Step 306: Use the value of the target field as the vehicle identification code.

[0081] Step 307: Include the vehicle identification code in the request header of the service activation request and forward it to the service management module in the cloud.

[0082] In some implementations, step 305 can be implemented as follows: if vehicle authentication is successful, the cloud processor sends the vehicle certificate in the HTTP request header to the cloud service management module.

[0083] Step 308: Through the service management module, based on the vehicle identification code, determine the target service that the vehicle can activate and the configuration information package of the target service.

[0084] Here, steps 305 to 308 correspond to step 102 mentioned above, and can be implemented with reference to the specific implementation of step 102 mentioned above.

[0085] In some implementations, step 308 can be specifically implemented as follows: After receiving the HTTP request header, the service management module in the cloud extracts the value of the Common Name field (vehicle identification code) from the HTTP request header; determines the vehicle model based on the vehicle identification code; and determines the target service and configuration information package that the vehicle can activate based on the vehicle model.

[0086] In some implementations, step 307 may be specifically implemented as follows: based on the vehicle identification code, search for the vehicle model in the database; based on the vehicle model, determine the target service that the vehicle can activate; determine the configuration information required for each target service to be activated; and encrypt and package the configuration information based on the private key in the cloud to obtain a configuration information package.

[0087] Step 308: Return the configuration information package to the vehicle so that the vehicle can activate the target service based on the configuration information package.

[0088] In some implementations, step 308 can be specifically implemented as follows: the service management module in the cloud initializes relevant information, activates services for the vehicle, and returns the configuration information package to the vehicle.

[0089] In this embodiment, vehicle authentication is performed using the vehicle certificate carried in the service activation request, effectively identifying the request initiator and preventing other users from impersonating the current user to send requests to the cloud using their own certificates. By using the Vehicle Identification Number (VIN) in the vehicle certificate, different vehicles have different activation keys, greatly reducing the risk of identity forgery during vehicle-to-cloud connection. Each vehicle does not need to carry a VIN when initiating a request; the VIN is directly extracted from the vehicle certificate, minimizing the risk of identity forgery. Activation does not rely on the user's account and password; activation authentication is performed directly based on the VIN in the vehicle certificate, making the activation method simple and widely applicable. Furthermore, throughout the activation process, the VIN can be used to determine whether the request initiator's VIN is one-to-one with the vehicle, preventing other users from using their own certificates to modify the vehicle identification number to the VIN of the attacked vehicle for identity forgery, ensuring high security. In addition, the cloud provides unified management of vehicle services, allowing for flexible control over the activation and deactivation of vehicle services through this global configuration.

[0090] This disclosure provides a vehicle service activation method, which can be executed by the vehicle's processor. For example... Figure 4 As shown, the method includes the following steps 401 to 405:

[0091] Step 401: When the vehicle is started for the first time, the vehicle certificate obtained from the vehicle's security chip is carried along with the service activation request and sent to the cloud.

[0092] Step 402: Receive the configuration information package of the target service that the vehicle can activate, returned by the cloud; the configuration information package is determined based on the vehicle certificate and the vehicle identification code in the vehicle certificate.

[0093] Step 403: Verify the security and integrity of the configuration information package.

[0094] Step 404: If the verification is successful, in response to a click operation on any of the target services, determine the configuration information required for activation of any of the services from the configuration information package.

[0095] Step 405: Set the service parameters in the configuration information and activate any of the services.

[0096] In this embodiment, each vehicle does not need to carry a Vehicle Identification Number (VIN) when initiating a request; it only carries a vehicle certificate. Thus, authenticating the vehicle using the vehicle certificate carried in the service activation request effectively identifies the requester's identity, preventing other users from using their own certificates to initiate requests to the cloud. The VIN in the vehicle certificate ensures that different vehicles have different activation keys, greatly reducing the risk of identity forgery during vehicle-to-cloud connection. Activation does not rely on the user's account and password; activation authentication is directly based on the VIN in the vehicle certificate, making the activation method simple and widely applicable. Furthermore, throughout the activation process, the VIN can be used to determine whether the requester's VIN is uniquely associated with the vehicle, preventing other users from using their own certificates to modify the vehicle identification number to match the VIN of an attacked vehicle for identity forgery, ensuring high security. In addition, the cloud provides unified management of vehicle services, allowing for flexible control over the activation and deactivation of vehicle services through this global configuration.

[0097] The following describes the application of the vehicle service activation method provided in this disclosure in a real-world scenario.

[0098] The application scenario of this disclosure embodiment is as follows: After a smart connected vehicle is sold to a car owner, it first undergoes activation and authentication. The cloud platform verifies the vehicle and then activates the services available on it. For example, a SIM card plan might switch from factory mode to activation mode, and services specific to the vehicle's version might be activated. For instance, higher-version vehicles might have autonomous driving services activated, while lower-version vehicles might have call center services disabled. Completing this initial verification requires two key steps: first, confirming the vehicle's identity; and second, issuing reliable configurations and activating relevant services. Identity authentication must be secure and reliable (one vehicle, one password) and able to be updated regularly. Service activation must ensure the reliability of the configuration file source and maintain configuration differences between different vehicle models.

[0099] The implementation scheme of this disclosure embodiment is as follows:

[0100] 1. After a vehicle rolls off the production line, the OEM will install a uniquely numbered certificate on each vehicle (lifetime: minimum one year). The Common Name field in the certificate is the vehicle identification number (VIN). The vehicle stores the certificate's private key along with the certificate itself in a secure chip to prevent the private key from being leaked.

[0101] like Figure 5As shown, a vehicle certificate may include multiple parts such as: Issued to, Issued by, Validity Period, and fingerprints. Both "Issued to" and "Issued by" can include fields such as Common Name, Organization, and Organization Unit. The Validity Period includes the Issued Date and Expires Date. Fingerprints include fingerprints1 and fingerprints2.

[0102] 2. After the vehicle is sold to the customer, upon the first ignition start, a request is made to the cloud to activate the service. A two-way authentication channel based on HTTPS is established between the vehicle and the cloud, and the vehicle requests the client certificate from the cloud.

[0103] 3. After receiving the request from the vehicle, the cloud verifies the vehicle certificate to check its validity. If the verification fails, an error message will be returned directly. If the verification is successful, the Common Name field will be extracted from the certificate and placed as a parameter in the HTTP request header for forwarding to the vehicle service management module for processing.

[0104] 4. After receiving the request, the cloud service management module first obtains the Common Name from the HTTP request header, and then uses the value of this Common Name to look up the car model and the default allowed service items in the database. Each service involves configuration information, and then this information is packaged.

[0105] 5. The cloud service management module initializes relevant data, activates services for the vehicle, and returns the relevant service configuration information package to the vehicle.

[0106] 6. After receiving the configuration information packet returned by the cloud, the vehicle first verifies the packet's signature to confirm its integrity, and then stores the information packet locally.

[0107] 7. When a user starts a service on the vehicle, the service first looks up relevant information in the configuration information. For example, if the customer wants to use the navigation service, the navigation service extracts the line "navigation service capabilityId="<map navigation>" from the configuration information obtained in the previous step, and then obtains information such as APN, host, status, enabled, and license. The host is the cloud interface address for map navigation, the APN is the SIM card traffic channel used on the device, the status indicates whether the service is online, the enabled indicates whether the map navigation service has been enabled on this vehicle, and the license contains the activation date and expiration date of this service.

[0108] Service configuration information can be flexibly configured on the World Wide Web (WEB) according to business needs. Below is an example of service configuration information:

[0109] JSON

[0110] {"capabilityListVersion":"1.1",

[0111] "capabilityList":[{

[0112]

[0113] like Figure 6 As shown, the interaction flow of this embodiment includes:

[0114] Vehicle: The vehicle is started, the vehicle private key and vehicle certificate are obtained from the security chip, the vehicle certificate is encrypted with the private key, and the encrypted vehicle certificate is carried in the service activation request to trigger the service activation request.

[0115] Cloud Platform (Cloud): Performs two-way authentication based on vehicle certificate and cloud certificate; if authentication is successful, it obtains the Common Name field value of the vehicle certificate, each certificate has a unique Common Name field value; uses the Common Name field value to query vehicle information in the database; activates the service corresponding to this vehicle, and returns a configuration list to the vehicle.

[0116] Afterwards, the vehicle: receives the service activation notification, receives the service configuration information and stores it locally; when the user clicks on a function in the vehicle, it first checks the activation status of that function and the related configuration information.

[0117] The technical effects achievable through the embodiments of this disclosure include at least the following: 1. By placing the VIN of each vehicle into the Common Name of the certificate, different vehicles possess different authentication keys, ensuring that identity forgery is prevented during vehicle-to-cloud connection, effectively verifying vehicle ownership, confirming a one-to-one relationship between the requester's VIN code and the vehicle, and preventing user A from modifying the VIN code to the VIN code of another attacked vehicle when making a request to the cloud with their own valid certificate. 2. The cloud provides unified management of the vehicle's on / off capabilities, flexibly controlling the switching of vehicle functions through global configuration.

[0118] Based on the foregoing embodiments, this disclosure provides a vehicle service activation device, which includes various units and modules included in each unit. It can be implemented by a processor in a computer device (referring to the cloud); of course, it can also be implemented by specific logic circuits. In the implementation process, the processor can be a central processing unit (CPU), a microprocessor unit (MPU), a digital signal processor (DSP), or a field programmable gate array (FPGA), etc.

[0119] Figure 7 A schematic diagram of the composition structure of a vehicle service activation device provided in this embodiment of the present disclosure. Figure 1 ,like Figure 7 The first vehicle service activation device 700 shown includes: an authentication module 710 and a processing module 720, wherein:

[0120] The authentication module 710 is configured to authenticate the vehicle based on the vehicle certificate carried in the service activation request triggered when the vehicle is first started; the vehicle certificate is used to uniquely identify the vehicle.

[0121] The processing module 720 is configured to, upon successful vehicle authentication, determine the target service that the vehicle can activate and the configuration information package of the target service based on the vehicle identification code in the vehicle certificate.

[0122] The processing module 720 is further configured to return the configuration information package to the vehicle so that the vehicle activates the target service based on the configuration information package.

[0123] In some embodiments, the authentication module 710 is further configured to: establish a two-way authentication channel between the vehicle and the cloud; perform two-way authentication between the vehicle and the cloud based on the vehicle certificate and the cloud certificate; verify the validity of the vehicle certificate if the two-way authentication is successful; and determine that the vehicle authentication is successful if the validity verification is successful.

[0124] In some embodiments, the processing module 720 is further configured to: extract the value of a target field from the vehicle certificate; the value of the target field can uniquely identify the vehicle; use the value of the target field as the vehicle identification code; carry the vehicle identification code in the request header of the service activation request and forward it to the service management module in the cloud; and, through the service management module, determine the target service that the vehicle can activate and the configuration information package of the target service based on the vehicle identification code.

[0125] In some embodiments, the processing module 720 is further configured to: search for the vehicle model in the database based on the vehicle identification code; determine the target service that the vehicle can activate based on the vehicle model; determine the configuration information required for each target service to be activated; and encrypt and package the configuration information based on the private key in the cloud to obtain a configuration information package.

[0126] Based on the foregoing embodiments, this disclosure provides another vehicle service activation device, which includes the included units and the modules included in each unit, which can be implemented by a processor in a computer device (referring to a vehicle); of course, it can also be implemented by specific logic circuits; in the implementation process, the processor can be a central processing unit (CPU), a microprocessor unit (MPU), a digital signal processor (DSP), or a field programmable gate array (FPGA), etc.

[0127] Figure 8 A schematic diagram of the composition structure of a vehicle service activation device provided in this embodiment of the present disclosure. Figure 2 ,like Figure 8 The second vehicle service activation device shown, the second vehicle service activation device 800, includes: a sending module 810, a receiving module 820, a verification module 830, and an activation module 840, wherein:

[0128] The sending module 810 is configured to send the vehicle certificate obtained from the vehicle's security chip along with the service activation request to the cloud when the vehicle is first started.

[0129] The receiving module 820 is configured to receive a configuration information package of the target service that the vehicle can activate, returned by the cloud; the configuration information package is determined based on the vehicle certificate and the vehicle identification code in the vehicle certificate.

[0130] The verification module 830 is configured to verify the security and integrity of the configuration information packet;

[0131] The activation module 840 is configured to activate the target service based on the configuration information package if the verification is successful.

[0132] In some embodiments, the activation module 840 is further configured to: in response to a click operation on any of the target services, determine the configuration information required for activation of any of the services from the configuration information package; set the service parameters in the configuration information; and activate any of the services.

[0133] The descriptions of the apparatus embodiments above are similar to those of the method embodiments above, and have similar beneficial effects. In some embodiments, the functions or modules included in the apparatus provided in this disclosure can be used to perform the methods described in the method embodiments above. For technical details not disclosed in the apparatus embodiments of this disclosure, please refer to the descriptions of the method embodiments of this disclosure for understanding.

[0134] It should be noted that, in the embodiments of this disclosure, if the above-described vehicle service activation method is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of this disclosure, or the part that contributes to related technologies, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the methods described in the various embodiments of this disclosure. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, portable hard drive, read-only memory (ROM), magnetic disk, or optical disk. Thus, the embodiments of this disclosure are not limited to any specific hardware, software, or firmware, or any combination of hardware, software, and firmware.

[0135] This disclosure provides a computer device including a memory and a processor. The memory stores a computer program that can run on the processor. When the processor executes the program, it implements some or all of the steps in the above-described method.

[0136] This disclosure provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements some or all of the steps in the above-described method. The computer-readable storage medium may be transient or non-transient.

[0137] This disclosure provides a computer program including computer-readable code, wherein when the computer-readable code is executed in a computer device, a processor in the computer device performs some or all of the steps in the above-described method.

[0138] This disclosure provides a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program. When the computer program is read and executed by a computer, it implements some or all of the steps in the above-described method. This computer program product can be implemented specifically through hardware, software, or a combination thereof. In some embodiments, the computer program product is specifically embodied as a computer storage medium; in other embodiments, the computer program product is specifically embodied as a software product, such as a software development kit (SDK), etc.

[0139] It should be noted that the descriptions of the various embodiments above tend to emphasize the differences between them, while their similarities or commonalities can be referenced interchangeably. The descriptions of the above embodiments of the device, storage medium, computer program, and computer program product are similar to the descriptions of the above method embodiments and have similar beneficial effects. For technical details not disclosed in the embodiments of the device, storage medium, computer program, and computer program product of this disclosure, please refer to the descriptions of the method embodiments of this disclosure for understanding.

[0140] It should be noted that, Figure 9 This is a schematic diagram of a hardware entity of a computer device in an embodiment of this disclosure, such as... Figure 9 As shown, the hardware entity of the computer device 900 includes: a processor 901, a communication interface 902, and a memory 903, wherein:

[0141] Processor 901 typically controls the overall operation of computer device 900.

[0142] Communication interface 902 enables computer devices to communicate with other terminals or servers over a network.

[0143] The memory 903 is configured to store instructions and applications executable by the processor 901, and can also cache data to be processed or already processed (e.g., image data, audio data, voice communication data, and video communication data) in the processor 901 and various modules in the computer device 900. It can be implemented using flash memory or random access memory (RAM). Data transfer between the processor 901, the communication interface 902, and the memory 903 can be performed via bus 904.

[0144] It should be understood that the phrase "an embodiment" or "one embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of this disclosure. Therefore, "in one embodiment" or "one embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It should be understood that in the various embodiments of this disclosure, the sequence numbers of the above steps / processes do not imply a sequential order of execution; the execution order of each step / process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this disclosure. The sequence numbers of the above embodiments of this disclosure are merely descriptive and do not represent the superiority or inferiority of the embodiments.

[0145] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0146] In the several embodiments provided in this disclosure, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components may be combined, or integrated into another system, or some features may be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed may be through some interfaces, and the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0147] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units. They may be located in one place or distributed across multiple network units. Some or all of the units may be selected to achieve the purpose of this embodiment according to actual needs.

[0148] In addition, each functional unit in the various embodiments of this disclosure can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.

[0149] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media that can store program code, such as mobile storage devices, read-only memory (ROM), magnetic disks, or optical disks.

[0150] Alternatively, if the integrated units described above are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this disclosure, or the part that contributes to related technologies, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the methods described in the various embodiments of this disclosure. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROM, magnetic disks, or optical disks.

[0151] The above description is merely an embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A method for activating vehicle services, characterized in that, The vehicle service activation method includes: In response to a service activation request triggered when the vehicle is first started, the vehicle is authenticated based on the vehicle certificate carried in the service activation request; the vehicle certificate is used to uniquely identify the vehicle. If the vehicle authentication is successful, the target service that the vehicle can activate and the configuration information package of the target service are determined based on the vehicle identification code in the vehicle certificate. The configuration information package is returned to the vehicle so that the vehicle can activate the target service based on the configuration information package.

2. The vehicle service activation method according to claim 1, characterized in that, The authentication of the vehicle based on the vehicle certificate carried in the service activation request includes: Establish a two-way authentication channel between the vehicle and the cloud; Perform two-way authentication between the vehicle certificate and the cloud certificate; If the two-way authentication is successful, the validity of the vehicle certificate is verified. If the validity verification is successful, the vehicle is deemed to have been successfully authenticated.

3. The vehicle service activation method according to claim 1 or 2, characterized in that, The step of determining the target service that the vehicle can activate and the configuration information package of the target service based on the vehicle identification number in the vehicle certificate includes: Extract the value of the target field from the vehicle certificate; the value of the target field can uniquely identify the vehicle. The value of the target field is used as the vehicle identification number; The vehicle identification number is included in the request header of the service activation request and forwarded to the service management module in the cloud. Based on the vehicle identification code, the service management module determines the target service that the vehicle can activate and the configuration information package of the target service.

4. The vehicle service activation method according to claim 3, characterized in that, The step of determining the target service that the vehicle can activate and the configuration information package of the target service based on the vehicle identification code includes: Based on the vehicle identification number, the model of the vehicle is retrieved from the database; Based on the vehicle model, determine the target service that the vehicle can activate; Determine the configuration information required for each of the target services to be activated; The configuration information is encrypted and packaged using the private key in the cloud to obtain a configuration information package.

5. A method for activating vehicle services, characterized in that, The vehicle service activation method includes: When the vehicle is started for the first time, the vehicle certificate obtained from the vehicle's security chip is carried in the service activation request and sent to the cloud; Receive the configuration information package of the target service that the vehicle can activate, returned by the cloud; the configuration information package is determined based on the vehicle certificate and the vehicle identification number in the vehicle certificate. The security and integrity of the configuration information package are verified; If the verification is successful, the target service is activated based on the configuration information package.

6. The vehicle service activation method according to claim 5, characterized in that, Activating the target service based on the configuration information package includes: In response to a click operation on any of the target services, the configuration information required for activation of any of the services is determined from the configuration information package; Set the service parameters in the configuration information and activate any of the services.

7. A vehicle service activation device, characterized in that, The vehicle service activation device includes: The authentication module is configured to authenticate the vehicle based on the vehicle certificate carried in the service activation request triggered when the vehicle is first started; the vehicle certificate is used to uniquely identify the vehicle. The processing module is configured to, upon successful vehicle authentication, determine the target service that the vehicle can activate and the configuration information package of the target service based on the vehicle identification code in the vehicle certificate. The processing module is further configured to return the configuration information package to the vehicle, so that the vehicle activates the target service based on the configuration information package.

8. A vehicle service activation device, characterized in that, The vehicle service activation device includes: The sending module is configured to send the vehicle certificate obtained from the vehicle's security chip along with the service activation request to the cloud when the vehicle is first started. The receiving module is configured to receive a configuration information package of the target service that the vehicle can activate, returned by the cloud; the configuration information package is determined based on the vehicle certificate and the vehicle identification code in the vehicle certificate. The verification module is configured to verify the security and integrity of the configuration information package; The activation module is configured to activate the target service based on the configuration information package if the verification is successful.

9. A computer device comprising a memory and a processor, the memory storing a computer program executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method according to any one of claims 1 to 4 or 5 to 6.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program performs the steps of the method as described in any one of claims 1 to 4 or 5 to 6.

11. A computer program product comprising a non-transitory computer-readable storage medium storing a computer program, wherein when read and executed by a computer, the computer program implements the steps of the method according to any one of claims 1 to 4, or 5 to 6.