Method and device for controlling a vehicle key
By writing the service key generated by the service provider platform into the NFC encryption chip of the user terminal, the convenience and security control of the virtual key is achieved, and the problems of the existing keys are solved, such as single function, large size, inconvenient portability and poor anti-theft.
Patent Information
- Application Number
- CN201910406847.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-05-16
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2039-05-16
AI Technical Summary
The existing mechanical keys and integrated remote control keys have problems such as single function, large size, inconvenient portability and poor anti-theft.
By writing the service key generated by the service provider platform into the NFC encryption chip of the user terminal, the control of the virtual key is realized, the key creation, update and share can be achieved using secure channel permissions, and key authentication is performed in combination with the AES 128 algorithm.
It improves the convenience and security of virtual keys, and solves the problems of single functions, inconvenient portability and poor anti-theft.
Smart Images

Figure CN110091829B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the automotive field, and in particular to a method and device for controlling a vehicle key. Background Art
[0002] With the development of science and technology, cars have become an indispensable means of transportation in our lives. When using a car, it is necessary to use keys to open / lock the car doors, start / stop the engine, etc. Car keys usually include mechanical keys, integrated remote control keys, etc.
[0003] Mechanical keys, also known as blade keys, can only be used for basic door opening and locking, etc. They have a single function and are inconvenient to carry. Moreover, they are passive devices and have poor anti-theft performance.
[0004] The integrated remote control key is composed of a blade key and a chip key. The addition of the chip key makes up for the anti-theft function of the blade key, and the chip key can also be used for functions such as honking the horn to find the car. However, it also has problems such as single function, large size and inconvenience in carrying. Summary of the Invention
[0005] In view of the above problems, a method and device for controlling a vehicle key is proposed to overcome the above problems or at least partially solve the above problems, including:
[0006] A method for controlling a vehicle key involves a first user terminal, a vehicle terminal, and a service provider platform, wherein the first user terminal is deployed with a first application corresponding to the service provider platform, and the method includes:
[0007] For the first application, obtaining a secure channel permission opened by the first user terminal;
[0008] Sending a virtual key creation request to the service provider platform through the first application; wherein the virtual key creation request includes a vehicle identification;
[0009] Receiving a first business key sent by the service provider platform in response to the virtual key creation request; wherein the first business key is a business key created by the service provider platform based on the first key information corresponding to the first user terminal and the vehicle identification;
[0010] Through the first application, the first business key is written into the NFC encryption chip in the first user terminal according to the secure channel authority.
[0011] Optionally, the step of obtaining, for the first application, a secure channel permission corresponding to the first user terminal includes:
[0012] For the first application, after the first user terminal verifies the first application, the security channel permission opened by the first user terminal is obtained.
[0013] Optionally, the method further includes:
[0014] In response to a delete operation in the first application, the first business key is deleted from the NFC encryption chip according to the secure channel authority.
[0015] Optionally, the method further includes:
[0016] In response to the virtual key update operation, the first service key in the NFC encryption chip is updated according to the secure channel authority through the first application.
[0017] Optionally, the method further involves a second user terminal, wherein the second user terminal is deployed with a second application corresponding to the service provider platform, and the second application has a secure channel permission opened by the second user terminal;
[0018] The method further comprises:
[0019] receiving an input terminal identifier corresponding to the second user terminal, and generating a virtual key sharing request for the vehicle terminal corresponding to the terminal identifier;
[0020] The virtual key sharing request is sent to the service provider platform; wherein, the service provider platform is used to adopt the virtual key sharing request to generate second key information corresponding to the second user terminal, and write the second business key into the NFC encryption chip in the second user terminal through the second application according to the secure channel authority.
[0021] Optionally, the method further includes:
[0022] generating a key control request through the first application;
[0023] The key control request is sent to the service provider platform to control the NFC security module in the vehicle end to update the key information corresponding to the key control request in the whitelist.
[0024] A method for controlling a vehicle key involves a first user terminal, a vehicle terminal, and a service provider platform. The first user terminal is deployed with a first application corresponding to the service provider platform, and the first application has a secure channel permission opened by the first user terminal. The method includes:
[0025] Receiving a virtual key creation request sent by a first application in the first user terminal; wherein the virtual key creation request includes a vehicle identification;
[0026] Determining first key information corresponding to the first user terminal;
[0027] Creating a first business key corresponding to the first key information and the vehicle identification;
[0028] generating first key information corresponding to the first service key;
[0029] The first key information is pushed to the vehicle end corresponding to the vehicle identification to be synchronized to the whitelist of the NFC security module in the vehicle end, and the first business key is written into the NFC encryption chip in the first user terminal through the first application according to the security channel authority.
[0030] Optionally, the method further involves a second user terminal, wherein the second user terminal is deployed with a second application corresponding to the service provider platform, and the second application has a secure channel permission opened by the second user terminal;
[0031] The method further comprises:
[0032] receiving a virtual key sharing request for the vehicle terminal sent by the first application; wherein the virtual key sharing request includes a terminal identifier corresponding to the second user terminal;
[0033] Determining second key information corresponding to the second user terminal;
[0034] Creating a second business key corresponding to the second key information and the vehicle identification;
[0035] generating second key information corresponding to the second service key;
[0036] The second key information is pushed to the vehicle side to be synchronized to the whitelist of the NFC security module in the vehicle side, and the second business key is written into the NFC encryption chip in the second user terminal through the second application according to the security channel authority.
[0037] Optionally, the method further includes:
[0038] receiving a key control request sent by the first application;
[0039] Control the NFC security module in the vehicle end to update the key information corresponding to the key control request in the white list.
[0040] A vehicle key control device, involving a first user terminal, a vehicle terminal, and a service provider platform, wherein the first user terminal is deployed with a first application corresponding to the service provider platform, and the device includes:
[0041] A secure channel permission acquisition module, configured to acquire, for the first application, the secure channel permission opened by the first user terminal;
[0042] A virtual key creation request sending module, configured to send a virtual key creation request to the service provider platform via the first application; wherein the virtual key creation request includes a vehicle identification;
[0043] A first business key receiving module, configured to receive a first business key sent by the service provider platform in response to the virtual key creation request; wherein the first business key is a business key created by the service provider platform based on the first key information corresponding to the first user terminal and the vehicle identification;
[0044] The first business key writing module is used to write the first business key into the NFC encryption chip in the first user terminal through the first application according to the security channel authority.
[0045] A vehicle key control device, including a first user terminal, a vehicle terminal, and a service provider platform, wherein the first user terminal is deployed with a first application corresponding to the service provider platform, and the first application has a secure channel permission opened by the first user terminal. The device includes:
[0046] a virtual key creation request receiving module, configured to receive a virtual key creation request sent by a first application in the first user terminal; wherein the virtual key creation request includes a vehicle identification;
[0047] A first key information determining module, configured to determine first key information corresponding to the first user terminal;
[0048] A first business key creation module, configured to create a first business key corresponding to the first key information and the vehicle identification;
[0049] A first key information generating module, configured to generate first key information corresponding to the first service key;
[0050] The first virtual key activation module is used to push the first key information to the vehicle end corresponding to the vehicle identification to synchronize it to the whitelist of the NFC security module in the vehicle end, and through the first application, write the first business key into the NFC encryption chip in the first user terminal according to the security channel authority.
[0051] A vehicle comprises a processor, a memory and a computer program stored in the memory and capable of running on the processor, wherein the computer program, when executed by the processor, implements the steps of the vehicle key control method as described above.
[0052] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the vehicle key control method described above.
[0053] The embodiments of the present application have the following advantages:
[0054] In the application embodiment, for the first application, the security channel permission opened by the first user terminal is obtained, and a virtual key creation request is sent to the service provider platform through the first application. The virtual key creation request includes a vehicle identification, and the first business key sent by the service provider platform for the virtual key creation request is received. The first business key is a business key created by the service provider platform based on the first key information and vehicle identification corresponding to the first user terminal. Then, through the first application, the first business key is written into the NFC encryption chip in the first user terminal according to the security channel permission, thereby realizing the control of the NFC virtual car key, improving the convenience and security of the virtual key control, and avoiding the problems of existing car keys such as single function, inconvenience in carrying, and poor anti-theft. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] In order to more clearly illustrate the technical solution of the present application, the following is a brief introduction to the drawings required for the description of the present application. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0056] Figure 1 This is a flowchart of a method for controlling a vehicle key provided by an embodiment of the present application;
[0057] Figure 2 This is a structural diagram of a car key control system provided by an embodiment of the present application;
[0058] Figure 3 This is a flowchart of another method for controlling a vehicle key provided by an embodiment of the present application;
[0059] Figure 4 This is a schematic structural diagram of a vehicle key control device provided by an embodiment of the present application;
[0060] Figure 5 This is a schematic structural diagram of another vehicle key control device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0061] To make the above-mentioned purposes, features, and advantages of this application more clearly understood, the present application is further described in detail below with reference to the accompanying drawings and specific embodiments. It is apparent that the embodiments described are only a portion of the embodiments of this application, not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments in this application without inventive effort are also within the scope of protection of this application.
[0062] Reference Figure 1 , shows a step flow chart of a method for controlling a car key provided by an embodiment of the present application, which may involve a first user terminal, a vehicle terminal and a service provider (SP, Service Provider) platform. The method can be applied to the first user terminal side.
[0063] like Figure 2 In the example, the first user terminal 201 can communicate with the service provider 202 , and the service provider platform 202 can also communicate with the vehicle end 203 .
[0064] Among them, the first user terminal is deployed with a first application corresponding to the service provider platform. For example, the first application can be a vehicle management application. The first user terminal can be a terminal that supports NFC (Near Field Communication) function, such as a mobile phone, a smart watch, etc., which can have an NFC encryption chip. The NFC encryption chip can be an embedded security element (eSE, Embedded Secure Element).
[0065] The service provider platform can communicate with the first application in the first user terminal and the vehicle end. It can be equipped with an SP TSM server, an NFC virtual key service server (Virtual Key Management, VKM), a hierarchical storage management (HSM) encryption machine, etc.
[0066] The vehicle side is deployed in the vehicle, which can have an NFC security module. The NFC security module can serve as the vehicle's lock core. A security chip can be integrated inside it, and the NFC security module can be connected to the NFC sensor and communication module deployed on the vehicle side. The NFC security module can communicate with the service provider platform through the communication module. When the user terminal is close to the NFC sensor, the NFC sensor can read the data of the NFC virtual key in the user terminal, and then verify it with the data stored in the NFC security module.
[0067] Specifically, the following steps may be included:
[0068] Step 101: Obtaining, for the first application, a secure channel permission opened by the first user terminal;
[0069] After the first application is installed, the first application can obtain the security channel permission opened by the first user terminal through the authorization of the operating system of the first user terminal to access the NFC encryption chip.
[0070] Among them, secure channel permissions include secure channel permissions implemented using the Open Mobile API (OMAPI) in Android 9, which is used to communicate with the device's secure elements; or secure channel permissions implemented under the Digital Key digital key specification launched by the Car Connectivity Consortium (CCC). Secure channel permissions can be implemented under the digital key specification, and NFC can be used to connect to smart terminals to lock, unlock, start or share vehicle access rights, etc.
[0071] In one embodiment of the present application, step 101 may include the following sub-steps:
[0072] For the first application, after the first user terminal verifies the first application, the security channel permission opened by the first user terminal is obtained.
[0073] In a specific implementation, the first user terminal can load the application whitelist locally for verification, or use the server for network verification. When the first application is in the application whitelist or passes the network verification, it can obtain the security channel permission opened by the first user terminal, and then use the security channel permission to access the security domain created in the NFC encryption chip of the first user terminal.
[0074] Step 102: Sending a virtual key creation request to the service provider platform via the first application; wherein the virtual key creation request includes a vehicle identification;
[0075] After opening the first application in the first user terminal, the user can enter the virtual key creation interface and enter the vehicle identification corresponding to the vehicle for which the virtual key is to be created, such as the vehicle identification number (VIN). The first application can generate a virtual key creation request and send it to the service provider platform.
[0076] Step 103: Receive a first business key sent by the service provider platform in response to the virtual key creation request; wherein the first business key is a business key created by the service provider platform based on the first key information corresponding to the first user terminal and the vehicle identification;
[0077] In actual implementation, the key information stored in each user terminal is unique. Therefore, after receiving the virtual key creation request sent by the first user terminal, the service provider platform can determine the first key information corresponding to the first user terminal.
[0078] Since the key information in the same user terminal is unique, and multiple virtual keys can be created in one user terminal, and each virtual key can correspond to a vehicle, the service provider platform can create a first business key and store the vehicle identification, the first key information, and the correspondence between the first business key, thereby completing the binding of the vehicle, the first user terminal, and the virtual key, and can send the first business key to the first user terminal.
[0079] Specifically, the first business key can be generated by the AES (Advanced Encryption Standard) 128 algorithm in combination with an encryption machine, which can be used to respond to the challenge with the NFC security module on the vehicle side to complete key authentication.
[0080] In one example, the first key information may include a first key identifier. The service provider platform may create a unique first key identifier for the first user terminal, and then send the first key identifier to the first application in the first user terminal. The first application may store the first key identifier in the NFC encryption chip in the first user terminal.
[0081] In one example, the first application can first determine whether the first user terminal supports the NFC function. If it does not support the NFC function, it will prompt "Unable to create virtual key" and will not perform subsequent steps. If it supports the NFC function, it can further determine whether the first user terminal has installed the NFC Applet component.
[0082] If the NFC Applet component is not installed, you can download the latest NFC Applet component and install the NFC Applet component to the terminal system storage area in the background. If the NFC Applet component is already installed, you can compare the local NFC Applet component version with the server version.
[0083] If the local NFC Applet component version is lower than the server's NFC Applet component version, the local NFC Applet component can be updated to the latest version. If the local NFC Applet component is the latest version, subsequent steps can be performed.
[0084] In one example, it is also possible to determine whether the login account in the first application has completed user real-name authentication, and whether the number of NFC virtual keys associated with the login account is less than 10. When both are met, subsequent steps can be performed.
[0085] Step 104: Write the first business key into the NFC encryption chip in the first user terminal through the first application according to the secure channel authority.
[0086] After receiving the first business key, the first user terminal can directly write the first business key into the NFC encryption chip in the first user terminal through the first application according to the secure channel authority, without the need to rely on the secure element provider SEI of the first user terminal and the application corresponding to the Secure Element Issuer platform, which improves efficiency and process reliability.
[0087] In an embodiment of the present application, the method may further include the following steps:
[0088] In response to a delete operation in the first application, the first business key is deleted from the NFC encryption chip according to the secure channel authority.
[0089] When the established NFC virtual key needs to be deleted, the first business key can be directly deleted from the security domain of the NFC encryption chip in response to the user's deletion operation in the first application.
[0090] In an embodiment of the present application, the method may further include the following steps:
[0091] In response to the virtual key update operation, the first service key in the NFC encryption chip is updated according to the secure channel authority through the first application.
[0092] When the virtual key needs to be updated, the first business key in the security domain of the NFC encryption chip can be updated in response to the virtual key update operation.
[0093] In one embodiment of the present application, the method may further involve a second user terminal, where the second user terminal is deployed with a second application corresponding to the service provider platform, and the second application may have a secure channel permission opened by the second user terminal. The method further includes the following steps:
[0094] Receive an input terminal identifier corresponding to the second user terminal, and generate a virtual key sharing request for the vehicle terminal corresponding to the terminal identifier; and send the virtual key sharing request to the service provider platform.
[0095] Among them, the service provider platform can be used to adopt the virtual key sharing request to generate second key information corresponding to the second user terminal, and through the second application, write the second business key into the NFC encryption chip in the second user terminal according to the secure channel authority.
[0096] In actual applications, since the logged-in user in the first application is the car owner or administrator user, when it is necessary to share the virtual key to the second user terminal, the virtual key sharing interface can be accessed, and the terminal identifier corresponding to the second user terminal can be entered, such as the user information of the logged-in user in the second application, and then a virtual key sharing request for the vehicle end can be generated.
[0097] If the second user terminal has previously stored the second key identifier, the service provider platform can directly determine the second key identifier corresponding to the second user terminal. If the second user terminal has not previously stored the second key identifier, the service provider platform can generate a second key identifier corresponding to the second user terminal and then send the second key identifier to the second user terminal so that the second key identifier is stored in the NFC encryption chip in the second user terminal.
[0098] After determining the second key information and vehicle identification, the service provider platform can create a first business key, and can store the vehicle identification, the second key information, and the correspondence between the second business key. The second business key can then be sent to the second user terminal. The second application in the second user terminal can directly write the first business key into the security domain of the NFC encryption chip in the second user terminal.
[0099] Specifically, the second business key can be generated by the AES (Advanced Encryption Standard) 128 algorithm in combination with an encryption machine, which can be used to respond to the challenge with the NFC security module on the vehicle side to complete key authentication.
[0100] In one embodiment of the present application, the method further includes the following steps:
[0101] A key control request is generated through the first application; and the key control request is sent to the service provider platform to control the NFC security module in the vehicle end to update the key information corresponding to the key control request in the whitelist.
[0102] In a specific implementation, the user can select an NFC virtual key in the first application, and then choose the type of key control, such as deletion, locking, etc., generate a key control request, and send it to the service provider platform, which can receive the key control request.
[0103] After receiving the key control request, the service provider platform can determine the key information corresponding to the key control request. For example, the key control request can include a key number. Since the key information is pre-stored on the service provider platform, the key information corresponding to the key number can be searched.
[0104] Of course, the key control request may also directly carry key information, and the key information may be determined directly from the key control request without searching on the platform.
[0105] After determining the key information corresponding to the key control request, the NFC security module in the vehicle can be controlled to update the key information corresponding to the key information in the whitelist according to the control type corresponding to the key control request, such as deletion, lock, unlock, etc.
[0106] In fact, the key information corresponding to the key control request can be the first key information, that is, the car owner user or administrator user controls the key he owns, and the key information corresponding to the key control request can also be the second key information, that is, the car owner user or administrator user controls the key shared with others.
[0107] Reference Figure 3 , shows a flowchart of another method for controlling a car key provided by an embodiment of the present application. The method can be applied to a service provider platform. A first user terminal is deployed with a first application corresponding to the service provider platform. The first application has a secure channel permission opened by the first user terminal. Specifically, the method may include the following steps:
[0108] Step 301: receiving a virtual key creation request sent by a first application in the first user terminal; wherein the virtual key creation request includes a vehicle identification;
[0109] After opening the first application in the first user terminal, the user can enter the virtual key creation interface and enter the vehicle identification corresponding to the vehicle for which the virtual key is to be created, such as the vehicle identification number (VIN). The first application can generate a virtual key creation request and send it to the service provider platform.
[0110] Step 302: Determine first key information corresponding to the first user terminal;
[0111] In actual applications, the key information stored in each user terminal is unique. Therefore, after receiving the virtual key creation request sent by the first user terminal, the service provider platform can determine the first key information corresponding to the first user terminal.
[0112] Specifically, the service provider platform may create a unique first key identifier for the first user terminal, and then send the first key identifier to the first application in the first user terminal. The first application may store the first key identifier in the NFC encryption chip in the first user terminal.
[0113] In one example, the first application can first determine whether the first user terminal supports the NFC function. If it does not support the NFC function, it will prompt "Unable to create virtual key" and will not perform subsequent steps. If it supports the NFC function, it can further determine whether the first user terminal has installed the NFC Applet component.
[0114] If the NFC Applet component is not installed, you can download the latest NFC Applet component and install the NFC Applet component to the terminal system storage area in the background. If the NFC Applet component is already installed, you can compare the local NFC Applet component version with the server version.
[0115] If the local NFC Applet component version is lower than the server's NFC Applet component version, the local NFC Applet component can be updated to the latest version. If the local NFC Applet component is the latest version, subsequent steps can be performed.
[0116] In one example, it is also possible to determine whether the login account in the first application has completed user real-name authentication, and whether the number of NFC virtual keys associated with the login account is less than 10. When both are met, subsequent steps can be performed.
[0117] Step 303: Create a first business key corresponding to the first key information and the vehicle identification;
[0118] Since the key information in the same user terminal is unique, and multiple virtual keys can be created in a user terminal, and each virtual key can correspond to a vehicle, the service provider platform can create a first business key and store the vehicle identification, the first key information, and the correspondence between the first business key, thereby completing the binding of the vehicle, user terminal, and virtual key.
[0119] Specifically, the first business key can be generated by the AES (Advanced Encryption Standard) 128 algorithm in combination with an encryption machine, which can be used to respond to the challenge with the NFC security module on the vehicle side to complete key authentication.
[0120] Step 304: Generate first key information corresponding to the first service key;
[0121] After generating the first business key, the service provider platform may combine the first business key and the first key information to generate first key information.
[0122] Specifically, the first token information corresponding to the first business key can be determined, such as permission information, validity period information, etc., which can be set by the user or adopt default settings, and then the first business key, the first key identifier, and the first token information can be organized into the first key information.
[0123] In one example, before generating the key, the service management platform can verify whether the current user is the owner user or administrator user corresponding to the vehicle identification. If the current user is not the owner user or administrator user, the subsequent key generation process will not be performed. If the current user is the owner user or administrator user, the subsequent key generation process will be allowed.
[0124] For example, a verification code can be sent to the corresponding phone number of the vehicle owner / administrator, and the user can enter the verification code for verification. Alternatively, the user can enter the ID number (last six digits) of the vehicle owner / administrator, and compare the entered ID number with the pre-collected ID number.
[0125] Step 305: Push the first key information to the vehicle end corresponding to the vehicle identification to synchronize it to the whitelist of the NFC security module in the vehicle end, and write the first business key into the NFC encryption chip in the first user terminal through the first application according to the security channel authority.
[0126] After generating the first key information, the service provider platform may write the first service key into the NFC encryption chip in the first user terminal through the first application.
[0127] Correspondingly, the service provider platform can push the first key information to the vehicle side, and the NFC security module in the vehicle side can store the first key information in the whitelist, completing the activation of the NFC virtual key, and the key is in an enabled state.
[0128] In one example, if the vehicle is offline due to network reasons, such as no response for 10 seconds, the key information can be actively synchronized and updated the next time the vehicle is connected to the network.
[0129] After activating the NFC virtual key, when the first user terminal is close to the vehicle, the two can perform near-field communication. The vehicle can then verify the NFC virtual key stored in the NFC encryption chip of the first user terminal. Once the verification is successful, operations such as unlocking and starting the engine can be performed on the vehicle. The specific verification is as follows:
[0130] 1. Verify whether the first key identifier stored in the first user terminal is in the whitelist;
[0131] 2. Verify whether the token information corresponding to the first key identifier in the whitelist is valid;
[0132] 3. Perform a random number challenge response using the temporary session key to verify the first service key stored in the first user terminal.
[0133] When it is verified that the first key identifier stored in the first user terminal is in the whitelist, the token information corresponding to the first key identifier is valid, and the first business key stored in the first user terminal is verified successfully, it is determined that the vehicle end has successfully verified the NFC virtual key in the first user terminal.
[0134] In one embodiment of the present application, the method further involves a second user terminal, where a second application corresponding to the service provider platform is deployed, and the second application has a secure channel permission opened by the second user terminal. The method may further include the following steps:
[0135] Receive a virtual key sharing request for the vehicle end sent by the first application; wherein the virtual key sharing request includes a terminal identifier corresponding to the second user terminal; determine the second key information corresponding to the second user terminal; create a second business key corresponding to the second key information and the vehicle identifier; generate second key information corresponding to the second business key; push the second key information to the vehicle end to synchronize it to the whitelist of the NFC security module in the vehicle end, and write the second business key to the NFC encryption chip in the second user terminal through the second application according to the security channel authority.
[0136] The second key information may include a second key identifier.
[0137] In actual applications, since the user logged in in the first application is the car owner, when the car owner needs to share the virtual key to the second user terminal, he can go to the virtual key sharing interface and enter the terminal identifier corresponding to the second user terminal, such as the user information of the user logged in in the second application, and then generate a virtual key sharing request for the vehicle end.
[0138] If the second user terminal has previously stored the second key identifier, the service provider platform may directly determine the second key identifier corresponding to the second user terminal.
[0139] If the second user terminal has not previously stored the second key identifier, the service provider platform can generate a second key identifier corresponding to the second user terminal, and then send the second key identifier to the second user terminal to store the second key identifier in the NFC encryption chip in the second user terminal.
[0140] After determining the second key information and the vehicle identification, the service provider platform may create a first business key and may store the corresponding relationship between the vehicle identification, the second key information, and the second business key.
[0141] Specifically, the second business key can be generated by the AES (Advanced Encryption Standard) 128 algorithm in combination with an encryption machine, which can be used to respond to the challenge with the NFC security module on the vehicle side to complete key authentication.
[0142] In a specific implementation, the second token information corresponding to the second business key can be determined, such as permission information, validity period information, etc., which can be set by the user or adopt the default setting. Then the second business key, second key identifier, and second token information can be organized into second key information.
[0143] After generating the second key information, the service provider platform can use the second application to directly write the second business key into the NFC encryption chip in the second user terminal, and can push the second key information to the vehicle end. The NFC security module in the vehicle end can store the second key information in the whitelist, completing the activation of the NFC virtual key, and the key is in an enabled state.
[0144] In an embodiment of the present application, the method may further include the following steps:
[0145] Receive the key control request sent by the first application; control the NFC security module in the vehicle end to update the key information corresponding to the key control request in the whitelist
[0146] In a specific implementation, the user can select an NFC virtual key in the first application, and then choose the type of key control, such as deletion, locking, etc., generate a key control request, and send it to the service provider platform, which can receive the key control request.
[0147] After receiving the key control request, the service provider platform can determine the key information corresponding to the key control request. For example, the key control request can include a key number. Since the key information is pre-stored on the service provider platform, the key information corresponding to the key number can be searched.
[0148] Of course, the key control request may also directly carry key information, and the key information may be determined directly from the key control request without searching on the platform.
[0149] After determining the key information corresponding to the key control request, the NFC security module in the vehicle can be controlled to update the key information corresponding to the key information in the whitelist according to the control type corresponding to the key control request, such as deletion, lock, unlock, etc.
[0150] In fact, the key information corresponding to the key control request can be the first key information, that is, the car owner user or administrator user controls the key he owns, and the key information corresponding to the key control request can also be the second key information, that is, the car owner user or administrator user controls the key shared with others.
[0151] In one example, the key control request may include a deletion request, which may generate a deletion instruction that can be recognized by the vehicle side, and then send the deletion instruction to the vehicle side. After receiving the deletion instruction, the vehicle side may delete the key information corresponding to the pre-stored deletion request in the white list of the NFC chip.
[0152] For the virtual key shared with the second user terminal, that is, the key information corresponding to the deletion request is the second key information, a deletion instruction can be sent to the second user terminal. After receiving the deletion instruction, the second user terminal can delete the second key information corresponding to the pre-stored second key information from the NFC encryption chip.
[0153] In one example, the key control request may include a lock request, which may generate a lock instruction that the vehicle side can recognize, and then send the lock instruction to the vehicle side. After receiving the lock instruction, the vehicle side may search for the key information corresponding to the stored lock request in the white list of the NFC chip, and then set a lock flag in the token information of the key information corresponding to the lock request. If the value of the relevant field is updated from "1" to "0", the key is in a locked state. When the lock flag is set, the vehicle control function of the NFC virtual key corresponding to the lock request is restricted.
[0154] Since there are multiple vehicle control permissions, such as unlocking vehicle permission, locking vehicle permission, starting vehicle permission, automatic driving permission, etc., the lock mark can correspond to the vehicle control permission. For example, lock mark A indicates that all vehicle control permissions are restricted, and lock mark B indicates that some vehicle control permissions are restricted, such as automatic driving permission is restricted.
[0155] In one example, the key control request may include an unlock request, which may generate an unlock instruction that the vehicle side can recognize, and then send the unlock instruction to the vehicle side. After receiving the unlock instruction, the vehicle side may search for the key information corresponding to the unlock request stored in the white list of the NFC chip, and then set the unlock flag in the token information of the key information corresponding to the unlock request. If the value of the relevant field is updated from "0" to "1", the key is restored to the enabled state. When the unlock flag is set, the vehicle control function of the NFC virtual key corresponding to the unlock request is restored.
[0156] In one example, the key control request may include a validity period setting request, and the validity period setting request may also include validity period information. After receiving the validity period setting instruction, the vehicle end may search for the key information corresponding to the validity period setting request in the white list of the NFC security module, and then use the validity period information to update the token information of the key information corresponding to the validity period setting request. When the current period exceeds the period in the validity period information, the key is in an expired state and cannot be used further.
[0157] In one example, the key control request may include a permission setting request, and the validity period setting request may also include permission information. After receiving the validity period setting instruction, the vehicle side can search for the key information corresponding to the permission setting request in the white list of the NFC security module, and then use the permission information to update the token information of the key information corresponding to the permission setting request. If the current operation is not within the operation range corresponding to the permission information, it cannot be used further.
[0158] In one example, after the key information is successfully updated on the vehicle side, a response message can be fed back to the service provider platform, and the service provider platform can identify the NFC virtual key as the control state corresponding to the key control request, such as the locked state, the reported lost state, etc.
[0159] After updating the control status, the service provider platform can feedback a control completion notification to the first user terminal, or feedback a control completion notification to the second user terminal, and then update the status information corresponding to the NFC virtual key in the display interface of the first application or the second application, or feedback the control completion notification to the car owner / administrator, etc. through SMS or other means.
[0160] In the application embodiment, for the first application, the security channel permission opened by the first user terminal is obtained, and then a virtual key creation request is sent to the service provider platform through the first application. The virtual key creation request includes a vehicle identification, and the first business key sent by the service provider platform for the virtual key creation request is received. The first business key is a business key created by the service provider platform based on the first key information and vehicle identification corresponding to the first user terminal. Then, through the first application, the first business key is written into the NFC encryption chip in the first user terminal according to the security channel permission, thereby realizing the control of the NFC virtual car key, improving the convenience and security of the virtual key control, and avoiding the problems of existing car keys such as single function, inconvenience in carrying, and poor anti-theft.
[0161] It should be noted that for the method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the embodiments of the present application are not limited by the order of the actions described, because according to the embodiments of the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present application.
[0162] Reference Figure 4 , shows a schematic structural diagram of a vehicle key control device provided by an embodiment of the present application, involving a first user terminal, a vehicle terminal, and a service provider platform. The first user terminal is deployed with a first application corresponding to the service provider platform, which may specifically include the following modules:
[0163] A secure channel permission acquisition module 401 is configured to acquire, for the first application, the secure channel permission opened by the first user terminal;
[0164] A virtual key creation request sending module 402 is configured to send a virtual key creation request to the service provider platform via the first application; wherein the virtual key creation request includes a vehicle identification;
[0165] A first business key receiving module 403 is configured to receive a first business key sent by the service provider platform in response to the virtual key creation request; wherein the first business key is a business key created by the service provider platform based on the first key information corresponding to the first user terminal and the vehicle identification;
[0166] The first service key writing module 404 is configured to write the first service key into the NFC encryption chip in the first user terminal through the first application according to the secure channel authority.
[0167] In one embodiment of the present application, the secure channel authority acquisition module 401 includes:
[0168] The verification submodule is used to obtain the security channel permission opened by the first user terminal after the first user terminal verifies the first application.
[0169] In one embodiment of the present application, the device further includes:
[0170] A deletion operation response module is used to respond to a deletion operation in the first application and delete the first business key from the NFC encryption chip according to the secure channel authority.
[0171] In one embodiment of the present application, the device further includes:
[0172] A virtual key update operation response module is used to respond to the virtual key update operation and update the first business key in the NFC encryption chip through the first application according to the secure channel authority.
[0173] In one embodiment of the present application, the apparatus further relates to a second user terminal, wherein the second user terminal is deployed with a second application corresponding to the service provider platform, and the second application has a secure channel permission opened by the second user terminal;
[0174] The device further comprises:
[0175] a virtual key sharing request generating module, configured to receive an input terminal identifier corresponding to the second user terminal and generate a virtual key sharing request for the vehicle terminal corresponding to the terminal identifier;
[0176] A virtual key sharing request sending module is used to send the virtual key sharing request to the service provider platform; wherein, the service provider platform is used to use the virtual key sharing request to generate second key information corresponding to the second user terminal, and through the second application, write the second business key into the NFC encryption chip in the second user terminal according to the secure channel authority.
[0177] In one embodiment of the present application, the device further includes:
[0178] a key control request generating module, configured to generate a key control request through the first application;
[0179] A key control request sending module is used to send the key control request to the service provider platform to control the NFC security module in the vehicle end to update the key information corresponding to the key control request in the whitelist.
[0180] Reference Figure 5 , shows a schematic structural diagram of another vehicle key control device provided by an embodiment of the present application, involving a first user terminal, a vehicle terminal, and a service provider platform. The first user terminal is deployed with a first application corresponding to the service provider platform. The first application has a secure channel permission opened by the first user terminal, and specifically may include the following modules:
[0181] A virtual key creation request receiving module 501 is configured to receive a virtual key creation request sent by a first application in the first user terminal; wherein the virtual key creation request includes a vehicle identification;
[0182] A first key information determining module 502 is configured to determine first key information corresponding to the first user terminal;
[0183] A first business key creation module 503 is configured to create a first business key corresponding to the first key information and the vehicle identification;
[0184] A first key information generating module 504 is configured to generate first key information corresponding to the first service key;
[0185] The first virtual key activation module 505 is used to push the first key information to the vehicle end corresponding to the vehicle identification to synchronize it to the whitelist of the NFC security module in the vehicle end, and through the first application, write the first business key into the NFC encryption chip in the first user terminal according to the security channel authority.
[0186] In one embodiment of the present application, the apparatus further relates to a second user terminal, wherein the second user terminal is deployed with a second application corresponding to the service provider platform, and the second application has a secure channel permission opened by the second user terminal; the apparatus further includes:
[0187] a virtual key sharing request receiving module, configured to receive a virtual key sharing request sent by the first application to the vehicle terminal; wherein the virtual key sharing request includes a terminal identifier corresponding to the second user terminal;
[0188] A second key information determining module, configured to determine second key information corresponding to the second user terminal;
[0189] A second business key creation module, configured to create a second business key corresponding to the second key information and the vehicle identification;
[0190] A second key information generating module, configured to generate second key information corresponding to the second service key;
[0191] The second virtual key activation module is used to push the second key information to the vehicle end to synchronize it to the whitelist of the NFC security module in the vehicle end, and through the second application, write the second business key into the NFC encryption chip in the second user terminal according to the security channel authority.
[0192] In one embodiment of the present application, the device further includes:
[0193] a key control request receiving module, configured to receive a key control request sent by the first application;
[0194] The key information updating module is used to control the NFC security module in the vehicle end to update the key information corresponding to the key control request in the white list.
[0195] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0196] An embodiment of the present application also provides a vehicle, which may include a processor, a memory, and a computer program stored in the memory and capable of running on the processor. When the computer program is executed by the processor, the steps of the above-mentioned vehicle key control method are implemented.
[0197] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned vehicle key control method are implemented.
[0198] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0199] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, devices, or computer program products. Therefore, the embodiments of the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the embodiments of the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0200] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0201] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0202] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable terminal device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0203] Although preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they become aware of the basic inventive concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.
[0204] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or terminal device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or terminal device that includes the element.
[0205] The above is a detailed introduction to the provided method and device for controlling a car key. Specific examples are used in this article to illustrate the principles and implementation methods of this application. The description of the above embodiments is only used to help understand the method and core idea of this application. At the same time, for general technical personnel in this field, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on this application.
Claims
1. A method for controlling a car key, characterized in that: Involving a first user terminal, a vehicle terminal, and a service provider platform, the first user terminal being deployed with a first application corresponding to the service provider platform, the method comprising: For the first application, obtaining a secure channel permission opened by the first user terminal, wherein the secure channel permission is used to access the NFC encryption chip in the first user terminal and connect to the vehicle terminal using NFC; Sending a virtual key creation request to the service provider platform through the first application; wherein the virtual key creation request includes a vehicle identification; receiving a first business key sent by the service provider platform in response to the virtual key creation request; wherein the first business key is a business key created by the service provider platform based on the first key information corresponding to the first user terminal and the vehicle identification, the first key information including a unique first key identification created by the service provider platform for the first user terminal, and the vehicle identification, the first key information, and the first business key having a corresponding relationship; Through the first application, the first business key is written into the NFC encryption chip in the first user terminal according to the secure channel authority.
2. The method according to claim 1, characterized in that The step of obtaining the secure channel permission corresponding to the first user terminal for the first application includes: For the first application, after the first user terminal verifies the first application, the security channel permission opened by the first user terminal is obtained.
3. The method according to claim 1 or 2, characterized in that The method further comprises: In response to a delete operation in the first application, the first business key is deleted from the NFC encryption chip according to the secure channel authority.
4. The method according to claim 1 or 2, characterized in that The method further comprises: In response to the virtual key update operation, the first service key in the NFC encryption chip is updated according to the secure channel authority through the first application.
5. The method according to claim 1, wherein The method further involves a second user terminal, wherein the second user terminal is deployed with a second application corresponding to the service provider platform, the second application having a secure channel permission opened by the second user terminal; The method further comprises: receiving an input terminal identifier corresponding to the second user terminal, and generating a virtual key sharing request for the vehicle terminal corresponding to the terminal identifier; The virtual key sharing request is sent to the service provider platform; wherein, the service provider platform is used to use the virtual key sharing request to generate second key information corresponding to the second user terminal, and write the second business key into the NFC encryption chip in the second user terminal through the second application according to the secure channel authority.
6. The method according to claim 5, characterized in that The method further comprises: generating a key control request through the first application; The key control request is sent to the service provider platform to control the NFC security module in the vehicle end to update the key information corresponding to the key control request in the whitelist.
7. A method for controlling a car key, characterized in that: Involving a first user terminal, a vehicle terminal, and a service provider platform, the first user terminal is deployed with a first application corresponding to the service provider platform, the first application has a secure channel permission opened by the first user terminal, and the method includes: Receiving a virtual key creation request sent by a first application in the first user terminal; wherein the virtual key creation request includes a vehicle identification; Determining first key information corresponding to the first user terminal, where the first key information includes a unique first key identifier created by the service provider platform for the first user terminal; Creating a first business key corresponding to the first key information and the vehicle identification, wherein the vehicle identification, the first key information, and the first business key have a corresponding relationship; generating first key information corresponding to the first service key; The first key information is pushed to the vehicle end corresponding to the vehicle identification to be synchronized to the whitelist of the NFC security module in the vehicle end, and the first business key is written into the NFC encryption chip in the first user terminal through the first application according to the secure channel authority, wherein the secure channel authority is used to access the NFC encryption chip in the first user terminal and connect to the vehicle end using NFC.
8. The method according to claim 7, characterized in that The method further involves a second user terminal, wherein the second user terminal is deployed with a second application corresponding to the service provider platform, the second application having a secure channel permission opened by the second user terminal; The method further comprises: receiving a virtual key sharing request for the vehicle terminal sent by the first application; wherein the virtual key sharing request includes a terminal identifier corresponding to the second user terminal; Determining second key information corresponding to the second user terminal; Creating a second business key corresponding to the second key information and the vehicle identification; generating second key information corresponding to the second service key; The second key information is pushed to the vehicle side to be synchronized to the whitelist of the NFC security module in the vehicle side, and the second business key is written into the NFC encryption chip in the second user terminal through the second application according to the security channel authority.
9. The method according to claim 8, characterized in that The method further comprises: receiving a key control request sent by the first application; Control the NFC security module in the vehicle end to update the key information corresponding to the key control request in the white list.
10. A control device for a car key, characterized in that: The device relates to a first user terminal, a vehicle terminal, and a service provider platform, wherein the first user terminal is deployed with a first application corresponding to the service provider platform, and the device includes: a secure channel permission acquisition module, configured to acquire, for the first application, a secure channel permission opened by the first user terminal, wherein the secure channel permission is used to access the NFC encryption chip in the first user terminal and connect to the vehicle terminal via NFC; A virtual key creation request sending module, configured to send a virtual key creation request to the service provider platform via the first application; wherein the virtual key creation request includes a vehicle identification; a first business key receiving module, configured to receive a first business key sent by the service provider platform in response to the virtual key creation request; wherein the first business key is a business key created by the service provider platform based on the first key information corresponding to the first user terminal and the vehicle identification, the first key information including a unique first key identification created by the service provider platform for the first user terminal, and the vehicle identification, the first key information, and the first business key having a corresponding relationship; The first business key writing module is used to write the first business key into the NFC encryption chip in the first user terminal through the first application according to the security channel authority.
11. A control device for a car key, characterized in that: The apparatus involves a first user terminal, a vehicle terminal, and a service provider platform, wherein the first user terminal is deployed with a first application corresponding to the service provider platform, and the first application has a secure channel permission opened by the first user terminal. The apparatus includes: a virtual key creation request receiving module, configured to receive a virtual key creation request sent by a first application in the first user terminal; wherein the virtual key creation request includes a vehicle identification; A first key information determining module, configured to determine first key information corresponding to the first user terminal, the first key information including a unique first key identifier created by the service provider platform for the first user terminal; A first business key creation module, configured to create a first business key corresponding to the first key information and the vehicle identification, wherein the vehicle identification, the first key information, and the first business key have a corresponding relationship; A first key information generating module, configured to generate first key information corresponding to the first service key; The first virtual key activation module is used to push the first key information to the vehicle end corresponding to the vehicle identification to synchronize it to the whitelist of the NFC security module in the vehicle end, and through the first application, write the first business key into the NFC encryption chip in the first user terminal according to the security channel authority, wherein the security channel authority is used to access the NFC encryption chip in the first user terminal and connect to the vehicle end using NFC.
12. A vehicle, characterized in that: The invention comprises a processor, a memory and a computer program stored in the memory and capable of running on the processor, wherein when the computer program is executed by the processor, the steps of the vehicle key control method according to any one of claims 1 to 9 are implemented.
13. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the vehicle key control method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Virtual key mutual authentication system and method
CN109067549A
Intelligent IC identifying anti-theft lock device for automobile
CN2513843Y
indication of legitimate authentication media for a vehicle
DE102015206628A1
Key information management device, key information management method, and non-transitory computer-readable recording medium
US20190122470A1
Management method and device for virtual car key, and storage medium
CN107393079A