Access control to a motor vehicle
The cryptographic hash function with a nonce and PIN verification method securely generates new vehicle keys, preventing collisions and unauthorized access in digital vehicle key systems.
Patent Information
- Application Number
- DE102024112709
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-06
- Publication Date
- 2025-11-06
AI Technical Summary
Existing digital vehicle key systems face collisions during key management, leading to unauthorized access and security breaches.
Implementing a cryptographic hash function that incorporates a nonce (random value) on both the owner and friend devices, along with a PIN verification, to securely generate and manage new vehicle keys, ensuring authentication and authorization.
Prevents key collisions by ensuring unique identifications, enhancing security and authorization processes, thereby preventing unauthorized access to motor vehicles.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The present invention relates to access control of a motor vehicle. In particular, the invention relates to access control by means of a digital vehicle key.
[0002] Access to a motor vehicle can be secured using a digital key. This digital key can be stored on a device. The device and the motor vehicle can mutually authenticate each other, and upon successful authentication, a requested, predetermined function of the motor vehicle can be controlled. More precisely, mutual authentication can preferably be based on an asymmetric cryptographic encryption method, in which the device and the motor vehicle are each assigned a pair of private and public cryptographic keys. The digital vehicle key adheres to the specifications of the Car Connectivity Consortium (CCC).
[0003] The owner can grant a friend permission to use the vehicle. To create a new digital vehicle key for the friend, a known procedure can be used, whereby a key management system provides the new vehicle key based on a key request, provided that the first identification of the key request, transmitted by the owner's device, and the second identification of the key request, transmitted by the friend's device, match. These identifications are determined using a predefined cryptographic hash function.
[0004] A new vehicle key can be assigned the authorization to issue another new vehicle key. Key requirements for linked vehicle keys can overlap, creating the possibility of a key requirement conflict from the key management perspective.
[0005] One of the problems underlying the present invention is to provide an improved technique for avoiding such a collision. The invention solves this problem by means of the subject matter of the independent claims. Dependent claims describe preferred embodiments.
[0006] A method for creating a new digital vehicle key for a motor vehicle comprises, on the part of an owner device, the steps of determining a key request for the digital vehicle key; determining a nonce; transmitting the key request and the nonce to a friend device; determining an initial identification of the key request by applying a predetermined cryptographic hash function to the key request and the nonce; and transmitting the initial identification to a key manager. On the part of the friend device, the method comprises the steps of determining a second identification of the key request by applying the predetermined cryptographic hash function to the key request and the nonce; and transmitting the second identification to the key manager.From the key management perspective, the procedure includes steps of determining that the first and second identifications match; and providing the new vehicle key.
[0007] A person with a predetermined authorization regarding the motor vehicle is referred to herein as the owner. The owner acts by means of a device, usually a mobile device, on which a cryptographic key identifying the owner is stored. To use the key, the owner can authenticate themselves to the device, for example, by presenting a biometric feature or by entering a predetermined secret. Optionally, the owner can also be a non-human entity. In this case, it is preferred that the device includes a server, a service, or a similar automated system.
[0008] The new key is to be provided to a person referred to herein as a friend. The friend will act accordingly using a friend device. Here too, a non-human person and the use of a device other than a mobile device are possible.
[0009] Key management is implemented as a central service, for example, in a cloud or on a server. This service is typically operated by the vehicle manufacturer. As described in the aforementioned technical specification, other servers or services may also be involved in managing digital vehicle keys. It should be noted that some key creation processes are simplified or presented without detail. Further information can be readily added by a person skilled in the art from the applicable specification.
[0010] The proposed method is based on a procedure for creating a new digital vehicle key, as described in the CCC's Technical Specification for the Digital Vehicle Key. It proposes extending this known procedure by having the cryptographic hashing process on the owner's device operate not only on the key request but also on a nonce. In other words, it is proposed that the hash include a random value ("salt"), resulting in a "salted hash." By transmitting the nonce to the partner device, the latter can determine the second identifier after receiving the key request. The nonce can also be included as a new field in the key request.
[0011] The owner's device can deposit the key request with a deposit service in a mailbox; and transmit the mailbox address to the friend's device; and the friend's device can then download the key request from the mailbox. The key request can be securely transmitted to the friend's device without requiring identification.
[0012] The key management system can transmit the new vehicle key to the authorized device and send a certificate of authenticity for the new vehicle key to the vehicle. This allows the new vehicle key to be used to control a function of the vehicle.
[0013] In one embodiment, a secure channel is used to transmit data from the owner device to the friend device. In another embodiment, the owner device uses a "Device PIN" method. The owner device generates a PIN and transmits it to the key management system and the friend device. The friend device transmits the received PIN, along with the second identifier, to the key management system. The key management system verifies that the PIN received from the owner device matches the PIN received from the friend device before issuing the new digital vehicle key. The PIN can be a preferably multi-digit number or, more generally, any string of characters. A user of the friend device must typically read the received PIN and re-enter it into the friend device for further processing.
[0014] The PIN can be transmitted from the owner's device to the friend's device via a different transmission channel than the key request. Furthermore, the PIN can be transmitted via a different communication channel than the address of the deposit service.
[0015] The nonce can also be transmitted from the owner's device to the friend's device on a different transmission channel than the PIN. If necessary, the nonce is transmitted on the same channel as the mailbox address.
[0016] The nonce can be transmitted from the owner's device to the friend's device on a different transmission channel than the key request. If necessary, the nonce is transmitted on the same channel as the PIN. Generally, different transmission channels can use different physical media for transmission, at least for part of the transmission path.
[0017] The nonce can generally consist of a random or pseudorandom string. The owning device can, for example, generate a random number or string itself or obtain it from an external source. The nonce can be determined based on a current time, for instance. Due to the use of the cryptographic hash function, two identifications created with respect to the same key request and similar but different nonces are no longer similar to each other. Therefore, it is reliably prevented to trace an identification back to a key request.
[0018] The predetermined cryptographic hash method can, in particular, be from the SHA-2 group. In a preferred embodiment, SHA-256 is used as the hash method. Another hash method is also possible, but does not comply with the current Technical Specification of the Digital Vehicle Key.
[0019] A first mobile device, also referred to herein as the owner device, is configured to determine a key request for a new digital vehicle key; to determine a nonce; to transmit the key request and the nonce to a friend device; to determine an initial identification of the key request by applying a predetermined cryptographic hash function to the key request and the nonce; and to transmit the initial identification to a key management system. For this purpose, the first mobile device preferably comprises a processing unit and at least one communication unit, preferably a wireless communication unit.
[0020] A second mobile device, also referred to herein as a "friend device," is configured to receive a key request and a nonce from a first mobile device; to determine a second identification of the key request by applying the predetermined cryptographic hash function to the key request and the nonce; and to transmit the second identification to a key management system. For this purpose, the second mobile device preferably comprises a processing unit and at least one communication unit, preferably a wireless communication unit. To apply the "Device PIN" method, it should additionally include an interaction unit for a user.
[0021] Both mobile devices preferably include a secure storage area which can preferably only be accessed when an assigned user has authenticated themselves to the device, for example by presenting a biometric feature or by entering a predetermined secret.
[0022] A key management system is set up to receive an initial identification of a key request for a new key for a motor vehicle from an owner's device; to receive a second identification of a key request for a new key for the motor vehicle from a friend's device; to determine that the first and second identifications match; and to provide the new vehicle key.
[0023] Key management is typically implemented as a central service or server. It is usually configured to manage digital vehicle keys for a large number of digital vehicles. In particular, a digital signature from the key management system may be required to provide a working digital vehicle key based on a key request.
[0024] The invention will now be described with reference to the attached figures, wherein Fig. 1. a system; and Fig. 2 shows a flowchart of a process.
[0025] Fig. Figure 1 shows a system 100 for managing digital vehicle keys for a motor vehicle 105. The system is based on a technology described by the CCC as a digital vehicle key. The illustrated system 100 does not include all possible or necessary components, but only those that contribute to the understanding of the present invention.
[0026] A first person 110 is referred to herein as the owner; this person has the power of disposal over the motor vehicle 105. A second person 115 is referred to herein as the friend, for whom a new digital vehicle key is to be issued. The designations are to be understood as non-restrictive and follow the designations ("owner" and "friend") of the aforementioned Technical Specification. The owner 110 acts with regard to cryptographic operations and the sending or receiving of information through an owner device 120. Similarly, the friend 115 acts through a friend device 125 (not visible).
[0027] Actions of the motor vehicle 105 in the present description can be carried out by a control device 130, which can control a predetermined security function of the motor vehicle 105, for example, opening a central locking system, after successful mutual authentication with a device 120, 125, based on a digital vehicle key via a wireless connection. The control device 130 can also communicate with another external service or server, preferably via a wireless connection.
[0028] A deposit service 135 is configured to receive a key request from an owner device 120 and store it in a mailbox. The mailbox is typically created during the deposit process and assigned a unique address, which is then transmitted back to the owner device 120. Based on this address, the partner device 125 can retrieve the key request from the deposit service 135. The mailbox can be deactivated after the key request has been successfully downloaded.
[0029] A key management unit 140 is set up as a central instance to verify a key request and, if the verification is successful, to provide a digital vehicle key based on the key request. The vehicle key can, in particular, be transmitted to an assigned partner device 125. Furthermore, an attestation package can be provided and transmitted to the vehicle 105. Only then can the vehicle 105 accept a digital vehicle key presented or used by the partner device 125.
[0030] Fig. Figure 2 shows a flowchart for a procedure 200 for generating a new digital vehicle key on the system 100 of Fig. 1.
[0031] The method shown is simplified and essentially limited to aspects relevant to the presented technique.
[0032] In step 205, the owner device 110 generates a key request and deposits it in a mailbox at the deposit service 135. In step 210, the deposit service 135 responds with a unique mailbox address. In step 215, the owner device 110 transmits this address to the friend device via a first channel.
[0033] In step 220, the owner device 110 determines a PIN, referred to here as O_PIN (owner pin). In step 225, the O_PIN is transmitted to the friend device 125 on a second channel.
[0034] In step 230, the owner device 120 determines a nonce and transmits it to the friend device 125 in step 235. The nonce can be transmitted alone, using the first, second, or a third channel. Alternatively, the nonce can be transmitted together with the mailbox address in step 215 on the first channel or together with the O_PIN in step 225 on the second channel.
[0035] In step 240, the owner device 110 determines an initial identification based on the key request and the nonce using a predetermined cryptographic hash function. The O_PIN and the initial identification are transmitted to the key management system 140 in step 245.
[0036] The friend device can download the key request in step 250 from the mailbox at the deposit service 135, based on the address received in step 215. A second identification can then be determined in step 255, based on the key request and the nonce received, for example, in step 235, using the same predetermined hash function. The received O_PIN can be displayed to a user of the friend device (friend 115), and an entry by the user can be recorded as F_PIN in step 260. If the entry is successful, F_PIN is identical to O_PIN. Should it turn out during the subsequent process that this is not the case, a mechanism may be provided to repeat part of procedure 200. Usually, only a predetermined maximum number of repetitions is allowed.
[0037] The F_PIN and the second identification can be transmitted to the key management system 140 in one step (265). In one embodiment, both pieces of information must be transmitted together in a single message.
[0038] The key management system 140 now has both PINs and both identifications. In step 270, the PINs and identifications can be compared pairwise. If it is determined that O_PIN = F_PIN and that the first identification matches the second, the new digital vehicle key can be created based on the key request. For this purpose, the key management system 140 can sign the key request with its own private key. In step 275, the created key can be provided to the partner device 125.
[0039] Furthermore, a cryptographic attestation package can be determined and transmitted to the motor vehicle 105 in step 280. In one embodiment, this occurs directly; in another embodiment, the attestation package can be brought to the motor vehicle by means of the companion device 125. In step 285, the companion device can control a predetermined function of the motor vehicle 105 based on the generated digital vehicle key. For this purpose, the companion device 125 typically needs to be in the vicinity of the motor vehicle 105. Communication takes place via a wireless interface. Reference sign 100 System 105 motor vehicles 110 first person, owner 115 second person, friend 120 Owner's device 125 friend device 130 Control device 135 Deposit Service 140 key management 200 procedures 205 Key requirements to be submitted 210 Mailbox address received 215 Send mailbox address to friend's device Determine 220 O_PIN 225 Transmit O_PIN to friend's device Determine 230 nonce Send 235 nonces to a friend's device 240 determine first identification 245 First identification transmitted to key management Download 250 key requests 255 determine second identification Determine 260 F_PIN 265 Transmit second identification and F_PIN to key management Compare 270 identifications and PINs Generate and provide 275 keys 280 Certificate Package 285 Control function
Claims
[1] Method (200) for creating a new digital vehicle key for a motor vehicle (105); wherein the method (200) comprises the following steps: - From an owner's device (120): - Determining a key requirement for the digital vehicle key; - Determining (230) a nonce; - Transmitting (215, 235) the key request and the nonce to a friend device (125); - Determining (240) an initial identification of the key request by applying a predetermined cryptographic hash function to the key request and the nonce; - Transmitting (245) the initial identification to a key management system; - From the friend device (125): - Determining (255) a second identification of the key request by applying the predetermined cryptographic hash function to the key request and the nonce; - Transmitting (265) the second identification to the key management; - From the key management department (140): - Determine (270) that the first and second identifications match; and - Providing (275) the new vehicle key. [2] Method (200) according to claim 1, wherein the owner device (120) deposits the key request with a deposit service (135) in a mailbox (205); transmits an address of the mailbox to the friend device (125) (215); and the friend device (125) downloads the key request from the mailbox (250). [3] Method (200) according to claim 1 or 2, wherein the key management (140) transmits the new vehicle key to the friend device (125) (265); and a certificate of the new vehicle key is transmitted to the motor vehicle (105) (280). [4] Method (200) according to any of the preceding claims, wherein the owner device (120) generates a PIN (220); transmits the PIN to the key management (140) and the friend device (125) (225); wherein the friend device (125) transmits the PIN together with the second identification to the key management (140) (265); and wherein the key management (140) determines (270) that the PIN received by the owner device (120) matches the PIN received by the friend device (125). [5] Method (200) according to claim 4, wherein the PIN is transmitted (225) from the owner device (120) to the friend device (125) on a different transmission channel than the key request. [6] Method (200) according to claim 4 or 5, wherein the nonce is transmitted (235) from the owner device (120) to the friend device (125) on a different transmission channel than the PIN. [7] Method (200) according to one of the preceding claims, wherein the nonce is transmitted (235) from the owner device (120) to the friend device (125) on a different transmission channel than the key request. [8] Method (200) according to any of the preceding claims, wherein the nonce comprises a random or pseudorandom string. [9] Method (200) according to any of the preceding claims, wherein the predetermined cryptographic hash method is comprised of the group SHA-2. [10] First mobile device (120) that is set up for this purpose: - to determine a key requirement for a new digital vehicle key; - to determine a nonce; - to transmit the key request and the nonce to a friend device (125); - to determine an initial identification of the key request by applying a predetermined cryptographic hash function to the key request and the nonce; and - to transmit the initial identification to a key management system (140). [11] Second mobile device (125) that is set up for this purpose: - to receive a key request and a nonce from a first mobile device; - to determine a second identification of the key request by applying the predetermined cryptographic hash function to the key request and the nonce; and - to transmit the second identification to a key management system (140). [12] Key management (140) which is set up for this purpose: - to receive an initial identification of a key request for a new key for a motor vehicle (105) from an owner device (120); - to receive a second identification of a key request for a new key for the motor vehicle (105) from a friend device (125); - to determine that the first and second identifications match; and - to provide the new vehicle key.
Citation Information
Patent Citations
Apparatus and method for providing and managing security information in communication system
US20180213405A1
Friend Key Sharing
US20210250355A1
Method by which device shares digital key
US20220014353A1
A concept for server-based sharing of digital keys
WO2024022629A1