Method and System for Mobile Terminal and Vehicle Authentication

The authentication key is derived through the cloud server, and the device and the vehicle are temporarily generated and used during authentication, solving the problem of insufficient memory caused by the device and the vehicle storing the keys each other and improving memory utilization efficiency.

CN114286313BActive Publication Date: 2025-07-11SHANGHAI TRUSTKERNEL INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111486564.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-07
Publication Date
2025-07-11
Estimated Expiration
2041-12-07

AI Technical Summary

Technical Problem

In the prior art, equipment and vehicle authentication need to store keys with each other, resulting in an unlimited increase in storage demand and insufficient memory of vehicles and equipment.

Method used

The authentication key is derived through the cloud server using the vehicle root key and authentication factor. The device and the vehicle are temporarily generated and used during authentication, and can be discarded after authentication to avoid storing the key.

Benefits of technology

It solves the problem that vehicles and devices need to store a large number of keys, reduces storage requirements, and improves memory utilization efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114286313B_ABST
    Figure CN114286313B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for mobile terminal and vehicle authentication, including: Step S1: The mobile terminal decrypts the encrypted information of the cloud server using the mobile terminal key to obtain a first authentication key and an authentication factor; Step S2: Send the authentication factor to the vehicle side, and the vehicle side derives a second authentication key by combining the vehicle root key and the authentication factor; Step S3: Use the first authentication key and the second authentication key for authentication. In the present invention, the authentication key is derived from the vehicle root key, and the vehicle side only needs to store the vehicle root key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and more specifically, to a method and system for authenticating a mobile terminal and a vehicle, and even more specifically, to a method and system for distributing symmetric keys between a mobile terminal and a vehicle. Background Art

[0002] In the prior art, when a device authenticates with a vehicle, the device needs to send its own key to the vehicle. The vehicle end needs to store the device key and send its own key to the device. After the device and the vehicle hold each other's keys, a key exchange is performed to achieve the authentication effect. Therefore, in the existing scenario, the device and the vehicle need to store keys for each other. If the number of devices and vehicles increases, the number of stored keys will increase indefinitely. If the number of devices authenticating with the vehicle increases, the vehicle needs to store the keys of N devices, resulting in bloat and even insufficient memory at the vehicle end. When a device needs to authenticate with multiple vehicles, the device needs to store the keys of multiple vehicles, which will also cause bloat and insufficient memory of the device.

[0003] Patent document CN110406498A (application number: 201910628589.2) discloses a vehicle control method and device. The above method includes: negotiating a key with a mobile terminal to obtain a first key; decrypting the ciphertext of the device fingerprint sent by the mobile terminal using the first key to obtain the device fingerprint; comparing the device fingerprint with the stored device fingerprint; if the comparison is consistent, triggering the vehicle control system. Summary of the Invention

[0004] Aiming at the defects in the prior art, the purpose of the present invention is to provide a method and system for authenticating a mobile terminal and a vehicle.

[0005] According to a method for authenticating a mobile terminal and a vehicle provided by the present invention, it includes:

[0006] Step S1: The mobile terminal decrypts the encrypted information of the cloud server using the mobile terminal key to obtain a first authentication key and an authentication factor;

[0007] Step S2: Send the authentication factor to the vehicle end, and the vehicle end derives a second authentication key by combining the vehicle root key and the authentication factor;

[0008] Step S3: Use the first authentication key and the second authentication key for authentication.

[0009] Preferably, the encrypted information of the cloud server adopts:

[0010] Step S1.1: The mobile terminal uploads the mobile terminal information to the cloud;

[0011] Step S1.2: The cloud obtains the vehicle information associated with the mobile terminal based on the mobile terminal information and obtains the vehicle root key;

[0012] Step S1.3: The cloud server randomly generates an authentication factor and combines the vehicle root key with the authentication factor to derive an authentication key;

[0013] Step S1.4: Use the mobile terminal key to encrypt the authentication factor and the authentication key to obtain encrypted information and send it to the mobile terminal.

[0014] Preferably, the mobile terminal information includes the mobile terminal ID and the mobile terminal key.

[0015] Preferably, the vehicle uploads the vehicle root key to the cloud server, and the cloud server encrypts and stores the vehicle root key with the server key.

[0016] Preferably, the cloud server includes the relationships of all mobile terminals and vehicles.

[0017] According to a system for authenticating a mobile terminal and a vehicle provided by the present invention, it includes:

[0018] Module M1: The mobile terminal decrypts the encrypted information of the cloud server using the mobile terminal key to obtain the first authentication key and the authentication factor;

[0019] Module M2: Send the authentication factor to the vehicle side, and the vehicle side combines the vehicle root key and the authentication factor to derive the second authentication key;

[0020] Module M3: Use the first authentication key and the second authentication key for authentication.

[0021] Preferably, the encrypted information of the cloud server adopts:

[0022] Module M1.1: The mobile terminal uploads the mobile terminal information to the cloud;

[0023] Module M1.2: The cloud obtains the vehicle information associated with the mobile terminal based on the mobile terminal information and obtains the vehicle root key;

[0024] Module M1.3: The cloud server randomly generates an authentication factor and combines the vehicle root key with the authentication factor to derive an authentication key;

[0025] Module M1.4: Use the mobile terminal key to encrypt the authentication factor and the authentication key to obtain encrypted information and send it to the mobile terminal.

[0026] Preferably, the mobile terminal information includes the mobile terminal ID and the mobile terminal key.

[0027] Preferably, the vehicle uploads the vehicle root key to the cloud server, and the cloud server encrypts and stores the vehicle root key with the server key.

[0028] Preferably, the cloud server includes the relationships of all mobile terminals and vehicles.

[0029] Compared with the prior art, the present invention has the following beneficial effects:

[0030] 1. The authentication key of the present invention is derived from the vehicle root key, and the vehicle only needs to store the vehicle root key;

[0031] 2. When the present invention performs authentication, the device receives the authentication factor and authentication key encrypted by the cloud server, and sends the authentication factor to the vehicle. The vehicle end receives the authentication factor sent by the device, derives the authentication key in combination with the vehicle root key, and performs authentication with the authentication key received by the device; there is no need to store it and it can be discarded after authentication, solving the problem that the vehicle end needs to store the authentication key. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] By reading the detailed description of the non-limiting embodiments with reference to the following drawings, other features, objects, and advantages of the present invention will become more apparent:

[0033] Figure 1 It is a flow chart of the symmetric key distribution method for mobile phones and vehicles. DETAILED DESCRIPTION OF THE INVENTION

[0034] The present invention will be described in detail below with reference to specific embodiments. The following embodiments will help those skilled in the art to further understand the present invention, but do not limit the present invention in any form. It should be noted that those of ordinary skill in the art can make several changes and improvements without departing from the concept of the present invention. These all belong to the protection scope of the present invention.

[0035] Example 1

[0036] In the existing scenario, the device end (mobile terminal) and the vehicle need to store keys for each other during authentication. If the number of devices and vehicles increases, the number of stored keys will increase infinitely.

[0037] According to a method for authenticating a mobile terminal and a vehicle provided by the present invention, as Figure 1 shown, it includes:

[0038] The authentication key of the device end of the present invention is derived by the cloud server using the vehicle root key plus the authentication factor. The authentication key of the vehicle end is derived by adding the authentication factor sent by the device during authentication plus the vehicle root key. There is no need to store it and it can be discarded after authentication, solving the problem that the vehicle end needs to store the authentication key.

[0039] Specifically,

[0040] Step S1: The mobile terminal decrypts the encrypted information of the cloud server using the mobile terminal key to obtain the first authentication key and the authentication factor; the encrypted information of the cloud server is obtained by uploading the mobile terminal information to the cloud by the mobile terminal; the cloud obtains the vehicle information associated with the mobile terminal according to the mobile terminal information (mobile terminal ID and mobile terminal key), and obtains the vehicle root key; the authentication factor is randomly generated by the cloud server, and the authentication key is derived by combining the vehicle root key and the authentication factor; the authentication factor and the authentication key are encrypted using the mobile terminal key to obtain the encrypted information and sent to the mobile terminal.

[0041] Step S2: Send the authentication factor to the vehicle side, and the vehicle side derives the second authentication key by combining the vehicle root key and the authentication factor;

[0042] Step S3: At this time, the first authentication key and the second authentication key of the device and the vehicle are both derived from the vehicle root key plus the authentication factor, and the keys are the same, so authentication can be performed.

[0043] Specifically, the vehicle uploads the vehicle root key to the cloud server, and the cloud server encrypts and stores the vehicle root key using the server key.

[0044] Specifically, the cloud server needs to store the relationship between all mobile terminals and vehicles.

[0045] The mobile terminal includes a smart watch, a smart phone or an iPad, etc.

[0046] According to a system for authenticating a mobile terminal and a vehicle provided by the present invention, it includes:

[0047] The authentication key of the device end of the present invention is derived by the cloud server using the vehicle root key plus the authentication factor. The authentication key of the vehicle end is derived by adding the authentication factor sent by the device during authentication plus the vehicle root key. There is no need to store it, and it can be discarded after authentication, which solves the problem that the vehicle end needs to store the authentication key.

[0048] Specifically,

[0049] Module M1: The mobile terminal decrypts the encrypted information of the cloud server using the mobile terminal key to obtain the first authentication key and the authentication factor; the encrypted information of the cloud server is obtained by uploading the mobile terminal information to the cloud by the mobile terminal; the cloud obtains the vehicle information associated with the mobile terminal according to the mobile terminal information (mobile terminal ID and mobile terminal key), and obtains the vehicle root key; the authentication factor is randomly generated by the cloud server, and the authentication key is derived by combining the vehicle root key and the authentication factor; the authentication factor and the authentication key are encrypted using the mobile terminal key to obtain the encrypted information and sent to the mobile terminal.

[0050] Module M2: Send the authentication factor to the vehicle side, and the vehicle side derives the second authentication key by combining the vehicle root key and the authentication factor;

[0051] Module M3: At this time, both the first authentication key and the second authentication key of the device and the vehicle are derived from the vehicle root key plus an authentication factor, and the keys are the same, so authentication can be performed.

[0052] Specifically, the vehicle uploads the vehicle root key to the cloud server, and the cloud server encrypts and stores the vehicle root key with the server key.

[0053] Specifically, the cloud server needs to store the relationships between all mobile terminals and the vehicle.

[0054] Mobile terminals include smart watches, smart phones, or iPads, etc.

[0055] Those skilled in the art know that in addition to implementing the system, device, and their respective modules provided by the present invention in the form of pure computer-readable program code, the method steps can be logically programmed to enable the system, device, and their respective modules provided by the present invention to be implemented in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers, etc. to implement the same program. Therefore, the system, device, and their respective modules provided by the present invention can be regarded as a kind of hardware component, and the modules included therein for implementing various programs can also be regarded as the structure within the hardware component; the modules for implementing various functions can also be regarded as either software programs for implementing the method or the structure within the hardware component.

[0056] The specific embodiments of the present invention have been described above. It should be understood that the present invention is not limited to the above specific embodiments, and those skilled in the art can make various changes or modifications within the scope of the claims, which does not affect the essence of the present invention. Without conflict, the embodiments of the present application and the features in the embodiments can be combined arbitrarily with each other.

Claims

1. A method for mobile terminal and vehicle authentication, characterized in that, Including: Step S1: The mobile terminal decrypts the encrypted information of the cloud server using the mobile terminal key to obtain the first authentication key and the authentication factor; Step S2: Send the authentication factor to the vehicle side, and the vehicle side derives the second authentication key by combining the vehicle root key and the authentication factor; Step S3: Use the first authentication key and the second authentication key for authentication; The encrypted information of the cloud server adopts: Step S1.1: The mobile terminal uploads the mobile terminal information to the cloud; Step S1.2: The cloud obtains the vehicle information associated with the mobile terminal according to the mobile terminal information and obtains the vehicle root key; Step S1.3: The cloud server randomly generates the authentication factor, and derives the authentication key by combining the vehicle root key and the authentication factor; Step S1.4: Encrypt the authentication factor and the authentication key using the mobile terminal key to obtain the encrypted information and send it to the mobile terminal; The mobile terminal information includes the mobile terminal ID and the mobile terminal key; The vehicle uploads the vehicle root key to the cloud server, and the cloud server encrypts and stores the vehicle root key using the server key; The cloud server includes the relationships of all mobile terminals and vehicles.

2. A system for mobile terminal and vehicle authentication, characterized in that Including: Module M1: The mobile terminal decrypts the encrypted information of the cloud server using the mobile terminal key to obtain the first authentication key and the authentication factor; Module M2: Send the authentication factor to the vehicle side, and the vehicle side derives the second authentication key by combining the vehicle root key and the authentication factor; Module M3: Use the first authentication key and the second authentication key for authentication; The encrypted information of the cloud server adopts: Module M1.1: The mobile terminal uploads the mobile terminal information to the cloud; Module M1.2: The cloud obtains the vehicle information associated with the mobile terminal according to the mobile terminal information and obtains the vehicle root key; Module M1.3: The cloud server randomly generates the authentication factor, and derives the authentication key by combining the vehicle root key and the authentication factor; Module M1.4: Encrypt the authentication factor and the authentication key using the mobile terminal key to obtain the encrypted information and send it to the mobile terminal; The mobile terminal information includes the mobile terminal ID and the mobile terminal key; The vehicle uploads the vehicle root key to the cloud server, and the cloud server encrypts and stores the vehicle root key using the server key; The cloud server includes the relationships of all mobile terminals and vehicles.

Citation Information

Patent Citations

  • Vehicle control method and device

    CN110406498A

  • Method for starting vehicle and related equipment

    CN111757320A