Digital car key processing method, sharing method, device, SIM card and vehicle
By presetting a digital car key program on the SIM card and using NFC to establish a secure channel, the problems of insufficient security and inconvenient cross-brand migration of mobile terminals in the prior art are solved, and convenient use and offline car key sharing are achieved between terminals of different brands.
Patent Information
- Application Number
- CN202011471071.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-14
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2040-12-14
AI Technical Summary
The existing mobile terminal car key solutions have problems such as insufficient security and inconvenience of cross-brand migration, especially the risk of public and private keys stored in the network environment, and the eSE solution does not support cross-brand sharing and online sharing.
Through the SIM card as the security carrier of the digital car key, the shared key is determined with the target vehicle through Near Field Communication (NFC), and a secure channel is established, and the information related to the digital car key is encrypted and decrypted through the shared key to realize the vehicle control function.
It improves the security of digital car keys, realizes convenient switching between terminals of different brands and the normal use of car key services, lowers the threshold for user to migrate car keys after changing the phone, and supports offline car key sharing.
Smart Images

Figure CN114697898B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to a digital car key processing method, a sharing method, a device, a SIM card and a vehicle. Background Art
[0002] With the deepening of vehicle intelligence and networking, digital car keys have emerged with the core goal of convenient life. Digital car keys are physical car keys that are virtualized into digital identities and stored in mobile terminals. Through communication authentication between mobile terminals and vehicles, control operations such as opening / locking car doors and starting cars are realized. Digital car keys have become one of the key infrastructures of the Internet of Vehicles. Digital car keys are portable, easy to share, low-cost, and have a cool user experience.
[0003] There are currently two mainstream mobile terminal car key implementation solutions:
[0004] The first category is the software implementation solution: the digital car key (public and private key pair) is stored in the application (APP) of the mobile terminal, the Bluetooth function of the mobile terminal is used to communicate with the vehicle, and identity authentication information (signature information) is sent to the vehicle. If the vehicle verification passes, the unlocking, starting and other functions are realized.
[0005] The second type is the eSE (embedded Secure Element) solution led by mobile terminal manufacturers: the digital car key (public and private key pair) is stored in the mobile terminal of the mobile terminal, and the vehicle is communicated with through the built-in Near Field Communication (NFC) chip of the mobile terminal, and the identity verification information (signature information) is sent to the vehicle. If the vehicle verification passes, the unlocking and starting functions are realized. At the same time, the car owner can share the digital car key with relatives and friends through the car key APP.
[0006] The simple process of sharing car keys on mobile terminals is as follows:
[0007] The car owner initiates a sharing application to the background server through the car key APP in the mobile terminal. The background server generates temporary car key data for the car owner's relatives and friends according to the permission information set by the car owner, and then pushes it to the car owner's relatives and friends. After the relatives and friends obtain the temporary car key through the car key APP, they will store it in the eSE of the mobile phone.
[0008] In summary, the first type of solution has the following problems:
[0009] The public and private keys of the car key are stored in a network environment, which has a low security level and is at risk of being stolen; once the mobile terminal is powered off, the Bluetooth connection cannot be enabled to use the car key function.
[0010] The second type of solution has the following problems:
[0011] Since the current car key eSE solutions of mobile terminal manufacturers are all privately implemented, from the user's perspective, mobile terminals are updated quickly, and the eSE car key solution does not support cross-mobile phone brand migration and cross-mobile phone brand sharing. If a user chooses a car key from a certain mobile terminal, it means that he or she must always use the mobile terminal of that manufacturer. During the car key sharing process, the terminals of the car owner and the key sharing object (such as relatives and friends) must be connected to the Internet, that is, only online key sharing is supported. Car key sharing is not supported in an environment without a network. Summary of the invention
[0012] The purpose of the embodiments of the present invention is to provide a digital car key processing method, sharing method, device, SIM card and vehicle to solve the problem of insecurity of existing mobile terminal car keys.
[0013] In order to solve the above problem, an embodiment of the present invention provides a method for processing a digital car key, which is executed by a user identification module SIM card, and a digital car key program is pre-installed in the SIM card; the method includes:
[0014] Based on near field communication NFC, negotiate with the target vehicle to determine a first shared key and establish a secure channel;
[0015] The digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted using the first shared key.
[0016] Wherein, based on near field communication NFC, negotiating with the target vehicle to determine a first shared key includes:
[0017] Generate a first temporary public key and a first temporary private key according to a first elliptic encryption curve;
[0018] Based on NFC, the first temporary public key is sent to the target vehicle; so that the target vehicle determines a first shared key according to the first temporary public key and the second temporary private key; wherein the second temporary private key is generated by the target vehicle according to the first elliptic encryption curve;
[0019] Receiving a second temporary public key generated by the target vehicle according to the first elliptic encryption curve and sent by the target vehicle based on NFC;
[0020] The first shared key is determined according to the first temporary private key and the second temporary public key.
[0021] Wherein, the method further comprises:
[0022] After determining the first shared key, the SIM card sends a first shared key negotiation success message to the target vehicle; or receives a first shared key negotiation success message sent by the target vehicle to the SIM card after determining the first shared key;
[0023] According to the first shared key negotiation success message, it is determined that the secure channel is successfully established.
[0024] The encryption and decryption of the digital car key related information transmitted between the SIM card and the target vehicle by using the first shared key includes:
[0025] Generate a digital car key public key and a digital car key private key;
[0026] Encrypting the digital vehicle key public key by using a first shared key, and sending the encrypted digital vehicle key public key to the target vehicle via NFC;
[0027] Receive the pairing result fed back by the target vehicle through NFC; wherein, if the target vehicle uses the first shared key to decrypt the encrypted digital car key public key to obtain and store the digital car key public key, the pairing result is a successful pairing; otherwise, the pairing result is a failed pairing.
[0028] Wherein, in the case where the vehicle stores the public key of the digital car key corresponding to the SIM card, the digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted by using the first shared key, further comprising:
[0029] Encrypting the identity of the SIM card by using the first shared key, and sending the encrypted identity to the target vehicle by using NFC;
[0030] Receiving an encrypted random challenge message sent by the target vehicle through NFC after the target vehicle verifies the identity of the SIM card using the first shared key; the random challenge message is encrypted by the first shared key;
[0031] Decrypting the encrypted random challenge information using the first shared key to obtain random challenge information;
[0032] Sign the random challenge information using the digital car key private key to generate first ciphertext information, and send the first ciphertext information to the target vehicle via NFC;
[0033] Receive the execution result fed back by the target vehicle through NFC; wherein, when the target vehicle verifies the first ciphertext information according to the digital car key public key corresponding to the digital car key private key, the execution result is that the door is opened or locked; otherwise, the execution result is that the door fails to open or lock.
[0034] Wherein, in the case where the vehicle does not store the digital vehicle key public key corresponding to the SIM card, before receiving the encrypted random challenge information sent via NFC, the method further includes:
[0035] Receive the authorization verification request sent by the target vehicle via NFC;
[0036] According to the authorization verification request, the signature information of the SIM card paired with the vehicle is sent to the target vehicle via NFC, so that the target vehicle decrypts the signature information using the digital car key public key of the SIM card paired with the vehicle, obtains the digital car key public key corresponding to the SIM card and stores it.
[0037] The embodiment of the present invention further provides a method for processing a digital car key, which is executed by a target vehicle, wherein an NFC card reader module is pre-installed in the target vehicle, and the method includes:
[0038] Based on the NFC card reader module, negotiate with the SIM card to determine the first shared key and establish a secure channel;
[0039] The digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted using the first shared key.
[0040] Wherein, based on the NFC card reader module, negotiating with the SIM card to determine the first shared key includes:
[0041] Receiving a first temporary public key sent by the SIM card based on NFC; wherein the SIM card generates a first temporary public key and a first temporary private key according to a first elliptic encryption curve;
[0042] Generate a second temporary public key and a second temporary private key according to the first elliptic encryption curve;
[0043] Determine the first shared key according to the first temporary public key and the second temporary private key;
[0044] The second temporary public key is sent to the SIM card based on NFC; so that the SIM card determines the first shared key according to the first temporary private key and the second temporary public key.
[0045] Wherein, the method further comprises:
[0046] The target vehicle sends a first shared key negotiation success message to the SIM card after determining the first shared key; or, receives the first shared key negotiation success message sent by the SIM card to the target vehicle after determining the first shared key;
[0047] According to the first shared key negotiation success message, it is determined that the secure channel is successfully established.
[0048] The encryption and decryption of the digital car key related information transmitted between the SIM card and the target vehicle by using the first shared key includes:
[0049] Receive the encrypted digital car key public key sent by the SIM card via NFC;
[0050] Decrypting the encrypted digital vehicle key public key using the first shared key;
[0051] If the digital car key public key of the SIM card is successfully decrypted, the digital car key public key is stored and a pairing result is sent to the SIM card, and the pairing result is a successful pairing; otherwise, a pairing result indicating a failed pairing is sent to the SIM card.
[0052] Wherein, in the case where the vehicle stores the public key of the digital car key corresponding to the SIM card, the digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted by using the first shared key, further comprising:
[0053] Receive the encrypted identity sent by the SIM card via NFC;
[0054] Decrypting and verifying the encrypted identity using the first shared key, and sending encrypted random challenge information to the SIM card via NFC; the random challenge information is encrypted using the first shared key;
[0055] After receiving the first ciphertext information sent by the SIM card through NFC after decrypting the random challenge information using the first shared key; the first ciphertext information is obtained by signing the random challenge information using the digital car key private key by the SIM card;
[0056] The first ciphertext information is verified using the digital car key public key, and the execution result is sent to the SIM card; if the verification is passed, the car door is opened or locked, and the execution result is that the car door is opened or locked; otherwise, the execution result is that the car door fails to open or lock.
[0057] Wherein, in the case that the vehicle does not store the digital vehicle key public key corresponding to the SIM card, before sending the encrypted random challenge information to the SIM card via NFC, the method further includes:
[0058] Send an authorization verification request to the SIM card via NFC;
[0059] Receiving the signature information of the SIM card paired with the vehicle sent by the SIM card according to the authorization verification request; the signature information of the SIM card paired with the vehicle is generated by the SIM card paired with the vehicle signing the digital car key public key of the SIM card according to its corresponding digital car key private key;
[0060] The signature information is verified according to the digital car key public key corresponding to the SIM card that has been paired with the vehicle. If the verification is successful, the digital car key public key corresponding to the SIM card is stored.
[0061] The embodiment of the present invention further provides a digital car key sharing method, which is executed by a first SIM card, in which a digital car key level is preset; and a first digital car key private key and a first digital car key public key of the first SIM card are successfully paired with a target vehicle; the method comprises:
[0062] Establishing an NFC connection with a second SIM card based on NFC; wherein the second SIM card is pre-installed with a digital car key program;
[0063] Receiving a first request sent through an NFC connection after a second digital car key public key and a second digital car key private key are generated by a second SIM card; the first request carries the second digital car key public key;
[0064] Using the first digital car key private key of the first SIM card to sign the second digital car key public key to generate signature information, and sending the signature information to the second SIM card through the NFC connection;
[0065] A receiving result fed back by the second SIM card after receiving the signature information is received, wherein the receiving result is used to indicate that the second SIM card successfully receives the signature information.
[0066] Wherein, the method further comprises:
[0067] The first SIM card and the second SIM card determine a second shared key based on NFC negotiation and establish an NFC connection;
[0068] The information transmitted between the first SIM card and the second SIM card is encrypted and decrypted using the second shared key.
[0069] An embodiment of the present invention further provides a digital car key sharing method, which is executed by a second SIM card, and the method further includes:
[0070] An NFC connection is established with the first SIM card based on NFC, wherein the first SIM card and the second SIM card are respectively pre-installed with digital car key programs; and a first digital car key private key and a first digital car key public key of the first SIM card are successfully paired with the target vehicle;
[0071] Generate a second digital car key public key and a second digital car key private key, and send a first request to the first SIM card through NFC; the first request carries the second digital car key public key;
[0072] The first SIM card is received to sign the second digital car key public key using the first digital car key private key of the first SIM card to generate signature information;
[0073] A receiving result is sent to the first SIM card, where the receiving result is used to indicate that the second SIM card successfully receives the signature information.
[0074] Wherein, the method further comprises:
[0075] The second SIM card and the first SIM card determine a second shared key based on NFC negotiation and establish an NFC connection;
[0076] The information transmitted between the second SIM card and the first SIM card is encrypted and decrypted using the second shared key.
[0077] Wherein, if the target vehicle stores the second digital vehicle key public key; the method further includes:
[0078] Send the identification to the target vehicle via NFC;
[0079] Receiving a random challenge message sent by the target vehicle via NFC after verifying the identity of the second SIM card;
[0080] Sign the random challenge information using the second digital car key private key to generate second ciphertext information, and send the second ciphertext information to the target vehicle via NFC;
[0081] Receive the execution result fed back by the target vehicle through NFC; wherein, when the target vehicle verifies the second ciphertext information according to the second digital vehicle key public key, the execution result is that the door is opened or locked; otherwise, the execution result is that the door fails to open or lock.
[0082] Wherein, in the case where the vehicle does not store the second digital vehicle key public key, before receiving the random challenge information sent via NFC, the method further includes:
[0083] Receive the authorization verification request sent by the target vehicle via NFC;
[0084] According to the authorization verification request, the signature information of the first SIM card is sent to the target vehicle via NFC, so that the target vehicle decrypts the signature information using the first digital car key public key of the first SIM card, obtains the second digital car key public key of the second SIM card and stores it.
[0085] The embodiment of the present invention further provides a digital car key processing device, which is applied to a user identification module SIM card, in which a digital car key program is pre-installed; the device comprises:
[0086] A first establishing module, used to negotiate with a target vehicle to determine a first shared key and establish a secure channel based on near field communication NFC;
[0087] The first processing module is used to encrypt and decrypt the digital car key related information transmitted between the SIM card and the target vehicle through the first shared key.
[0088] An embodiment of the present invention further provides a SIM card, comprising a processor and a transceiver, wherein the transceiver receives and sends data under the control of the processor, and is characterized in that the processor is used to perform the following operations:
[0089] Based on near field communication NFC, negotiate with the target vehicle to determine a first shared key and establish a secure channel;
[0090] The digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted using the first shared key.
[0091] The embodiment of the present invention further provides a digital car key processing device, which is applied to a target vehicle, and is characterized in that an NFC card reader module is pre-installed in the target vehicle, and the device includes:
[0092] A second establishing module is used to negotiate with the SIM card to determine a first shared key and establish a secure channel based on the NFC card reader module;
[0093] The second processing module is used to encrypt and decrypt the digital car key related information transmitted between the SIM card and the target vehicle through the first shared key.
[0094] An embodiment of the present invention further provides a target vehicle, comprising a processor and a transceiver, wherein the transceiver receives and sends data under the control of the processor, and is characterized in that the processor is used to perform the following operations:
[0095] Based on the NFC card reader module, negotiate with the SIM card to determine the first shared key and establish a secure channel;
[0096] The digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted using the first shared key.
[0097] The embodiment of the present invention further provides a digital car key sharing device, which is applied to a first SIM card, in which a digital car key is preset; and a first digital car key private key and a first digital car key public key of the first SIM card are successfully paired with a target vehicle; the device comprises:
[0098] A first connection module, used to establish an NFC connection with a second SIM card based on NFC; wherein the second SIM card is pre-installed with a digital car key program;
[0099] A first request receiving module, used to receive a first request sent through an NFC connection after a second SIM card generates a second digital car key public key and a second digital car key private key; the first request carries the second digital car key public key;
[0100] A signature sending module, used to use the first digital car key private key of the first SIM card to sign the second digital car key public key to generate signature information, and send the signature information to the second SIM card through the NFC connection;
[0101] The result receiving module is used to receive a receiving result fed back by the second SIM card after receiving the signature information, wherein the receiving result is used to indicate that the second SIM card successfully receives the signature information.
[0102] The embodiment of the present invention further provides a SIM card, wherein the SIM card is a first SIM card, in which a digital car key is preset; and a first digital car key private key and a first digital car key public key of the first SIM card are successfully paired with a target vehicle; the SIM card further includes a processor and a transceiver, and the transceiver receives and sends data under the control of the processor, wherein the processor is used to perform the following operations:
[0103] Establishing an NFC connection with a second SIM card based on NFC; wherein the second SIM card is pre-installed with a digital car key program;
[0104] Receiving a first request sent through an NFC connection after a second digital car key public key and a second digital car key private key are generated by a second SIM card; the first request carries the second digital car key public key;
[0105] Using the first digital car key private key of the first SIM card to sign the second digital car key public key to generate signature information, and sending the signature information to the second SIM card through the NFC connection;
[0106] A receiving result fed back by the second SIM card after receiving the signature information is received, wherein the receiving result is used to indicate that the second SIM card successfully receives the signature information.
[0107] An embodiment of the present invention further provides a digital car key sharing device, which is applied to a second SIM card, and the device includes:
[0108] A second connection module is used to establish an NFC connection with the first SIM card based on NFC, wherein the first SIM card and the second SIM card are respectively pre-installed with digital car key programs; and the first digital car key private key and the first digital car key public key of the first SIM card are successfully paired with the target vehicle;
[0109] A first request sending module, used to generate a second digital car key public key and a second digital car key private key, and send a first request to the first SIM card through NFC; the first request carries the second digital car key public key;
[0110] A signature receiving module, used to receive signature information generated by the first SIM card using the first digital car key private key of the first SIM card to sign the second digital car key public key;
[0111] The result sending module is used to send a receiving result to the first SIM card, where the receiving result is used to indicate that the second SIM card successfully receives the signature information.
[0112] An embodiment of the present invention further provides a SIM card, wherein the SIM card is a second SIM card, and the SIM card further includes a processor and a transceiver, wherein the transceiver receives and sends data under the control of the processor, and wherein the processor is configured to perform the following operations:
[0113] An NFC connection is established with the first SIM card based on NFC, wherein the first SIM card and the second SIM card are respectively pre-installed with digital car key programs; and a first digital car key private key and a first digital car key public key of the first SIM card are successfully paired with the target vehicle;
[0114] Generate a second digital car key public key and a second digital car key private key, and send a first request to the first SIM card through NFC; the first request carries the second digital car key public key;
[0115] The first SIM card is received to sign the second digital car key public key using the first digital car key private key of the first SIM card to generate signature information;
[0116] A receiving result is sent to the first SIM card, where the receiving result is used to indicate that the second SIM card successfully receives the signature information.
[0117] An embodiment of the present invention also provides a communication device, comprising a memory, a processor, and a program stored in the memory and executable on the processor; characterized in that when the processor executes the program, the method for processing a digital car key as described above is implemented; or, when the processor executes the program, the method for sharing a digital car key as described above is implemented.
[0118] An embodiment of the present invention also provides a computer-readable storage medium having a computer program stored thereon, characterized in that when the program is executed by a processor, the steps in the method for processing a digital car key as described above are implemented; or, when the program is executed by a processor, the steps in the method for sharing a digital car key as described above are implemented.
[0119] The above technical solution of the present invention has at least the following beneficial effects:
[0120] In the digital car key processing method, device, SIM card and vehicle of the embodiment of the present invention, the SIM card of the mobile terminal is used as the security carrier of the digital car key. The SIM card can be easily switched between terminals of different brands. When the user changes the mobile terminal, the car key service can be used normally by inserting the SIM card, which reduces the migration threshold of the car key after the user changes the phone; further, the establishment of a secure channel between the SIM card and the vehicle is realized through NFC, which can ensure the security of data transmission and realize one-time one-key. BRIEF DESCRIPTION OF THE DRAWINGS
[0121] Figure 1 A schematic diagram showing an application system of a method for processing a digital vehicle key provided by an embodiment of the present invention;
[0122] Figure 2 A flowchart showing a method for processing a digital vehicle key according to an embodiment of the present invention;
[0123] Figure 3 A flowchart showing the establishment of a security channel in the method for processing a digital car key provided by an embodiment of the present invention;
[0124] Figure 4 A flowchart showing a digital car key pairing method in a digital car key processing method provided by an embodiment of the present invention;
[0125] Figure 5 A flowchart showing the use of the digital car key of the car owner's SIM card in the digital car key processing method provided in an embodiment of the present invention;
[0126] Figure 6 A second flowchart showing the method for processing a digital car key provided by an embodiment of the present invention;
[0127] Figure 7 A flowchart showing the steps of the digital car key sharing method provided by an embodiment of the present invention;
[0128] Figure 8 A flowchart showing offline sharing of a digital car key of a first SIM card in a digital car key sharing method provided by an embodiment of the present invention;
[0129] Fig. 9 A second flowchart showing the steps of the digital car key sharing method provided by an embodiment of the present invention;
[0130] Fig.10 A flowchart showing the first use of a digital car key by a second SIM card in a digital car key sharing method provided by an embodiment of the present invention;
[0131] Fig.11One of the structural schematic diagrams showing a digital car key processing device provided by an embodiment of the present invention;
[0132] Fig.12 One of the structural schematic diagrams of a SIM card provided in an embodiment of the present invention is shown;
[0133] Fig.13 A second structural schematic diagram showing a digital vehicle key processing device provided by an embodiment of the present invention;
[0134] Fig.14 A schematic diagram showing the structure of a target vehicle provided by an embodiment of the present invention;
[0135] Fig.15 One of the structural schematic diagrams of the digital car key sharing device provided by an embodiment of the present invention is shown;
[0136] Fig.16 A second structural diagram of a SIM card provided in an embodiment of the present invention is shown;
[0137] Fig.17 A second structural diagram showing a digital car key sharing device provided by an embodiment of the present invention;
[0138] Fig.18 The third structural diagram of the SIM card provided by the embodiment of the present invention is shown. DETAILED DESCRIPTION
[0139] In order to make the technical problems, technical solutions and advantages to be solved by the present invention more clear, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.
[0140] like Figure 1 As shown, the digital car key processing method provided by the embodiment of the present invention uses the SIM card in the mobile terminal as the security carrier of the digital car key, and realizes the car control operation through NFC. This solution can be used as a universal SIM car key service to provide digital car key services to all car manufacturers. Figure 1 As shown, the system used includes: a mobile terminal, a SIM card, a vehicle, and a car key business backend server.
[0141] Mobile terminal: With NFC function, it is the carrier of the digital car key APP and provides car owners with a visual operation interface for car key services. The digital car key operation framework in the mobile terminal provides the digital car key APP with universal digital key service functions, including operations such as car owner pairing and car key sharing.
[0142] SIM card: It is an NFC card that supports multiple cryptographic algorithms and is connected to the NFC module in the mobile terminal through the SWP (Single Wire Protocol) interface, enabling contactless communication with the car. The digital car key APPLET (app or program) is pre-installed in the SIM card.
[0143] Vehicle: The target vehicle must be equipped with an NFC card reader module to communicate with the SIM card in the mobile terminal and read the car key related information in the card to lock / unlock the door.
[0144] Car key business backend server: It is the business processing backend of the digital car key APP, and is connected to the vehicle through a private link to realize the pre-setting and update of keys, certificates and other data in the vehicle.
[0145] It should be noted that the above-mentioned APPLET, digital car key APP and business platform can be operated and maintained by operators to provide digital car key services to car companies, simplifying the workload of cooperation and adaptation between car manufacturers and numerous mobile phone manufacturers.
[0146] like Figure 2 As shown, an embodiment of the present invention provides a method for processing a digital car key, which is executed by a user identification module SIM card, and a digital car key program is pre-installed in the SIM card; the method includes:
[0147] Step 201, based on near field communication NFC, negotiate with the target vehicle to determine a first shared key and establish a secure channel;
[0148] Step 202: encrypt and decrypt the digital car key related information transmitted between the SIM card and the target vehicle using the first shared key.
[0149] In order to improve the communication security between the SIM card and the target vehicle in the embodiment of the present invention, the vehicle and the SIM card establish a secure channel based on the NFC near-field communication protocol, negotiate a shared key (i.e., the first shared key), and the subsequent data exchange processes are protected by this key. The SIM card can be the owner's SIM card or any other SIM card except the owner's SIM card. It should be noted that the owner's SIM card mentioned in the embodiment of the present application is the SIM card that is successfully paired with the vehicle for the first time.
[0150] As an optional embodiment, the secure channel is established based on the ECDH (Elliptic Curve Diffie-Hellman key Exchange) key negotiation algorithm, and the two parties negotiate the key based on the selected elliptic curve. Specifically, step 201 includes:
[0151] Generate a first temporary public key PKt and a first temporary private key SKt according to the first elliptic encryption curve;
[0152] Based on NFC, the first temporary public key PKt is sent to the target vehicle; so that the target vehicle determines the first shared key K according to the first temporary public key PKt and the second temporary private key SKs; wherein the second temporary private key SKs is generated by the target vehicle according to the first elliptic encryption curve;
[0153] Receiving a second temporary public key PKs generated by the target vehicle according to the first elliptic encryption curve and sent by the target vehicle based on NFC;
[0154] The first shared key K is determined according to the first temporary private key SKt and the second temporary public key PKs.
[0155] Furthermore, the method further comprises:
[0156] After determining the first shared key K, the SIM card sends a first shared key negotiation success message to the target vehicle; or receives a first shared key negotiation success message sent by the target vehicle to the SIM card after determining the first shared key K;
[0157] According to the first shared key negotiation success message, it is determined that the secure channel is successfully established.
[0158] like Figure 3 As shown, the process of establishing a secure channel between the SIM card and the target vehicle includes:
[0159] Step 1, the SIM card uses the established elliptic encryption algorithm (ECC algorithm) curve to generate the first temporary public-private key pair (PKt, SKt);
[0160] Step 2, send PKt to the target vehicle;
[0161] Step 3, the target vehicle generates a second temporary public-private key pair (PKs, SKs) using a predetermined ECC algorithm curve;
[0162] Step 4: The target vehicle uses PKt and SKs to calculate the first shared key K;
[0163] Step 5, the target vehicle sends PKs to the SIM card;
[0164] Step 6: The SIM card calculates the first shared key K using PKs and SKt.
[0165] Among them, K is the key to establish a secure channel. The SIM card and the target vehicle will subsequently use the first shared key to encrypt and decrypt the transmitted information.
[0166] In the embodiment of the present invention, the SIM card communicates with the vehicle by means of the NFC capability opened by the mobile terminal. The communication process adopts the ECDH key negotiation algorithm, which can ensure the security of information transmission, realize one-time one-key, and improve the security of the digital car key.
[0167] As an optional embodiment, in the case where the SIM card is the owner's SIM card, the owner's SIM card has been pre-configured with a digital car key program and key data personalization has been completed. The owner needs to download the digital car key APP through the mobile terminal of the secure owner's SIM card; accordingly, step 202 includes:
[0168] The car owner's SIM card generates a digital car key public key PKc and a digital car key private key SKc;
[0169] Encrypting the digital car key public key PKc by using a first shared key, and sending the encrypted digital car key public key to the target vehicle via NFC;
[0170] Receive the pairing result fed back by the target vehicle through NFC; wherein, if the target vehicle uses the first shared key to decrypt the encrypted digital car key public key PKc to obtain and store the digital car key public key PKc, the pairing result is a successful pairing; otherwise, the pairing result is a failed pairing.
[0171] like Figure 4 As shown, the pairing process of the digital car key and the target vehicle is as follows:
[0172] Step 1: The car owner starts the pairing process in the car key APP;
[0173] Step 2: The car key APP notifies the SIM card through the machine-card interface to prepare for car key pairing.
[0174] Step 3: The car owner places the mobile terminal close to the NFC card reader on the side of the car.
[0175] Step 4: The target vehicle and the SIM card establish a secure channel based on the NFC near-field communication protocol, negotiate and determine a first shared key, and subsequent data exchange processes are protected by the first shared key.
[0176] Step 5, the SIM card generates a digital car key (PKc, SKc);
[0177] Step 6: The SIM card sends PKc to the target vehicle.
[0178] Step 7: The target vehicle stores PKc, completes the vehicle key pairing, and returns the pairing result.
[0179] It should be noted that, in steps 5-6, all information previously transmitted between the SIM card and the target vehicle is protected by the first shared key.
[0180] As an optional embodiment, in the case where the vehicle stores the digital vehicle key public key corresponding to the SIM card, step 202 further includes:
[0181] Encrypting the identity of the SIM card by using the first shared key, and sending the encrypted identity to the target vehicle by using NFC;
[0182] Receiving an encrypted random challenge message sent by the target vehicle through NFC after the target vehicle verifies the identity of the SIM card using the first shared key; the random challenge message is encrypted by the first shared key;
[0183] Decrypting the encrypted random challenge information using the first shared key to obtain random challenge information;
[0184] Sign the random challenge information using the digital car key private key to generate first ciphertext information, and send the first ciphertext information to the target vehicle via NFC;
[0185] Receive the execution result fed back by the target vehicle through NFC; wherein, when the target vehicle verifies the first ciphertext information according to the digital car key public key corresponding to the digital car key private key, the execution result is that the door is opened or locked; otherwise, the execution result is that the door fails to open or lock.
[0186] The SIM card can be the owner's SIM card that has been paired with the vehicle (i.e., the target vehicle stores the digital car key public key corresponding to the owner's SIM card), or it can be the SIM card of other users who are not using the digital car key for the first time (i.e., the target vehicle stores the digital car key public key corresponding to the SIM card). That is, the SIM card uses the digital car key private key generated by itself (for example, the owner's SIM card corresponds to the first digital car key private key, and other SIM cards correspond to the second digital car key private key) to sign the random challenge information, and the target vehicle uses the corresponding digital car key public key (for example, the owner's SIM card corresponds to the first digital car key public key, and other SIM cards correspond to the second digital car key public key) to verify the signature, thereby opening or locking the door.
[0187] like Figure 5 As shown, the process of using the SIM card digital car key is as follows:
[0188] Step 1: The car owner places the mobile terminal close to the NFC card reader on the car to establish an NFC connection.
[0189] Step 2: The target vehicle and the SIM card establish a secure channel based on the NFC near-field communication protocol, negotiate and determine a first shared key, and subsequent data exchange processes are protected by the first shared key.
[0190] Step 3: The SIM card sends an identity authentication request to the vehicle, carrying the identity identifier.
[0191] Step 4: The target vehicle determines whether it is the owner's SIM card or a SIM card that has stored the corresponding digital car key public key based on the identity identifier, and the vehicle sends a random challenge message;
[0192] Step 5: The SIM card signs the random challenge information using its own digital car key private key to generate the first ciphertext information;
[0193] Step 6, the SIM card sends the first ciphertext information to the target vehicle;
[0194] Step 7: The target vehicle uses the digital car key public key corresponding to the SIM card to verify the signature of the first ciphertext information; if the verification is successful, the door is opened or locked; otherwise, no response is given;
[0195] Step 8: The target vehicle returns the execution result to the SIM card.
[0196] It should be noted that, in steps 3-7, all information previously transmitted between the SIM card and the target vehicle is protected by the first shared key.
[0197] The embodiment of the present invention pre-installs the digital car key program in the SIM card, communicates with the car key APP through the mobile phone terminal card channel, and connects with the NFC module in the mobile phone through the SWP interface and performs contactless communication with the car equipped with the NFC card reader, thereby realizing functions such as locking / unlocking the vehicle.
[0198] As another optional embodiment, when a non-owner SIM card (also referred to as a SIM card that is not paired with a target vehicle) uses a digital vehicle key for the first time, that is, when the vehicle does not store a public key of the digital vehicle key corresponding to the SIM card, before receiving the encrypted random challenge information sent via NFC, the method further includes:
[0199] Receive the authorization verification request sent by the target vehicle via NFC;
[0200] According to the authorization verification request, the signature information of the SIM card paired with the vehicle is sent to the target vehicle via NFC, so that the target vehicle decrypts the signature information using the digital car key public key of the SIM card paired with the vehicle, obtains the digital car key public key corresponding to the SIM card and stores it.
[0201] In summary, the embodiment of the present invention adopts the SIM card of the mobile terminal as the security carrier of the digital car key. The SIM card can be easily switched between terminals of different brands. When the user changes the mobile terminal, the car key service can be used normally by inserting the SIM card, which reduces the migration threshold of the car key after the user changes the phone. Further, the establishment of a secure channel between the SIM card and the vehicle is realized through NFC, which can ensure the security of data transmission and realize one-time one-key.
[0202] like Figure 6 As shown, an embodiment of the present invention further provides a method for processing a digital car key, which is executed by a target vehicle, wherein an NFC card reader module is pre-installed in the target vehicle, and the method includes:
[0203] Step 801: Based on the NFC card reader module, negotiate with the SIM card to determine a first shared key and establish a secure channel;
[0204] Step 802: encrypt and decrypt the digital car key related information transmitted between the SIM card and the target vehicle using the first shared key.
[0205] In order to improve the communication security between the SIM card and the target vehicle in the embodiment of the present invention, the vehicle and the SIM card establish a secure channel based on the NFC near-field communication protocol, negotiate a shared key (i.e., the first shared key), and the subsequent data exchange processes are protected by this key. The SIM card can be the owner's SIM card or any other SIM card except the owner's SIM card. It should be noted that the owner's SIM card mentioned in the embodiment of the present application is the SIM card that is successfully paired with the vehicle for the first time.
[0206] As an optional embodiment, the secure channel is established based on the ECDH (Elliptic Curve Diffie-Hellman key Exchange) key negotiation algorithm, and both parties negotiate the key based on the selected elliptic curve. Specifically, step 801 includes:
[0207] Receiving a first temporary public key sent by the SIM card based on NFC; wherein the SIM card generates a first temporary public key and a first temporary private key according to a first elliptic encryption curve;
[0208] Generate a second temporary public key and a second temporary private key according to the first elliptic encryption curve;
[0209] Determine the first shared key according to the first temporary public key and the second temporary private key;
[0210] The second temporary public key is sent to the SIM card based on NFC; so that the SIM card determines the first shared key according to the first temporary private key and the second temporary public key.
[0211] Furthermore, the method further comprises:
[0212] The target vehicle sends a first shared key negotiation success message to the SIM card after determining the first shared key; or, receives the first shared key negotiation success message sent by the SIM card to the target vehicle after determining the first shared key;
[0213] According to the first shared key negotiation success message, it is determined that the secure channel is successfully established.
[0214] In the embodiment of the present invention, the SIM card communicates with the vehicle by means of the NFC capability opened by the mobile terminal. The communication process adopts the ECDH key negotiation algorithm, which can ensure the security of information transmission, realize one-time one-key, and improve the security of the digital car key.
[0215] As an optional embodiment, the digital car key program has been pre-configured in the car owner's SIM card and the key data has been personalized. The car owner needs to download the digital car key APP through the mobile terminal of the secure car owner's SIM card; accordingly, step 802 includes:
[0216] Receive the encrypted digital car key public key sent by the SIM card via NFC;
[0217] Decrypting the encrypted digital vehicle key public key using the first shared key;
[0218] If the digital car key public key of the SIM card is successfully decrypted, the digital car key public key is stored and a pairing result is sent to the SIM card, and the pairing result is a successful pairing; otherwise, a pairing result indicating a failed pairing is sent to the SIM card.
[0219] As another optional embodiment, in the case where the vehicle stores the digital vehicle key public key corresponding to the SIM card, step 802 further includes:
[0220] Receive the encrypted identity sent by the SIM card via NFC;
[0221] Decrypting and verifying the encrypted identity using the first shared key, and sending encrypted random challenge information to the SIM card via NFC; the random challenge information is encrypted using the first shared key;
[0222] After receiving the first ciphertext information sent by the SIM card through NFC after decrypting the random challenge information using the first shared key; the first ciphertext information is obtained by signing the random challenge information using the digital car key private key by the SIM card;
[0223] The first ciphertext information is verified using the digital car key public key, and the execution result is sent to the SIM card; if the verification is passed, the car door is opened or locked, and the execution result is that the car door is opened or locked; otherwise, the execution result is that the car door fails to open or lock.
[0224] The embodiment of the present invention pre-installs the digital car key program in the SIM card, communicates with the car key APP through the mobile phone terminal card channel, and connects with the NFC module in the mobile phone through the SWP interface and performs contactless communication with the car equipped with the NFC card reader, thereby realizing functions such as locking / unlocking the vehicle.
[0225] As an optional embodiment, when the vehicle does not store the digital vehicle key public key corresponding to the SIM card, before sending the encrypted random challenge information to the SIM card via NFC, the method further includes:
[0226] Send an authorization verification request to the SIM card via NFC;
[0227] Receiving the signature information of the SIM card paired with the vehicle sent by the SIM card according to the authorization verification request; the signature information of the SIM card paired with the vehicle is generated by the SIM card paired with the vehicle signing the digital car key public key of the SIM card according to its corresponding digital car key private key;
[0228] The signature information is verified according to the digital car key public key corresponding to the SIM card that has been paired with the vehicle. If the verification is successful, the digital car key public key corresponding to the SIM card is stored.
[0229] In summary, the embodiment of the present invention adopts the SIM card of the mobile terminal as the security carrier of the digital car key. The SIM card can be easily switched between terminals of different brands. When the user changes the mobile terminal, the car key service can be used normally by inserting the SIM card, which reduces the migration threshold of the car key after the user changes the phone. Further, the establishment of a secure channel between the SIM card and the vehicle is realized through NFC, which can ensure the security of data transmission and realize one-time one-key.
[0230] like Figure 7 As shown, an embodiment of the present invention further provides a digital car key sharing method, which is executed by a first SIM card, in which a digital car key level is preset; and a first digital car key private key and a first digital car key public key of the first SIM card are successfully paired with a target vehicle, and the method includes:
[0231] Step 701, establishing an NFC connection with a second SIM card based on NFC; wherein the second SIM card is pre-installed with a digital car key program;
[0232] Step 702, receiving a first request sent through an NFC connection after a second SIM card generates a second digital car key public key and a second digital car key private key; the first request carries the second digital car key public key;
[0233] Step 703, using the first digital car key private key of the first SIM card to sign the second digital car key public key to generate signature information, and sending the signature information to the second SIM card through the NFC connection;
[0234] Step 704: Receive a reception result fed back by the second SIM card after receiving the signature information, where the reception result is used to indicate that the second SIM card successfully receives the signature information.
[0235] For example, the first SIM card is the car owner's SIM card, and the second SIM card is the relative's and friends' SIM card; in the embodiment of the present invention, the car owner's SIM card and the relative's and friends' SIM card rely on the NFC function opened by the mobile terminal to the SIM card to realize the offline digital car key authorization of the car owner to the relatives and friends.
[0236] In at least one optional embodiment of the present invention, the SIM card of the car owner and the SIM card of the relative or friend can be connected by the NFC function opened by the mobile terminal to the SIM card, so that the car owner can authorize the offline car key to the relative or friend; that is, when the car owner needs to share the digital car key with the relative or friend, even if the mobile terminals of both parties are not connected to the Internet, the car owner can share the car key through the NFC connection. At the same time, when sharing the car key, the relative or friend does not need to download and install the car key APP on the mobile phone, nor does he need to worry about the brand of the mobile terminal of the relative or friend.
[0237] It should be noted that the NFC interaction between the two SIM cards can be transmitted only through NFC or through an NFC secure channel (i.e., a second shared key is pre-established), which is not specifically limited here. Accordingly, the method further includes:
[0238] The first SIM card and the second SIM card determine a second shared key based on NFC negotiation and establish an NFC connection;
[0239] The information transmitted between the first SIM card and the second SIM card is encrypted and decrypted using the second shared key.
[0240] like Figure 8 As shown, the offline car key sharing process is as follows:
[0241] Step 1: The car owner starts the car key sharing process in the car key APP.
[0242] Step 2: The car owner's APP calls the machine-card interface to send a car key sharing notification to the car owner's SIM card (i.e., the first SIM card).
[0243] Step 3: The car owner uses the mobile terminal to approach the mobile terminal of a relative or friend, and an NFC connection is established between the car owner's SIM card and the second SIM card, and a secure channel is established.
[0244] Step 4: The second SIM card generates a public and private key pair (PKr, SKr) of the vehicle key.
[0245] Step 5: The second SIM card requests the car owner's signature information from the car owner's SIM card.
[0246] Step 6: The second SIM card signs PKr using SKc.
[0247] Step 7: The first SIM card sends the owner's signature information to the second SIM card.
[0248] Step 8: The second SIM card returns the receiving result, and the car key APP informs the owner of the sharing result. After the sharing is successful, relatives and friends can use the second SIM card to control the vehicle.
[0249] In summary, the embodiment of the present invention adopts the SIM card of the mobile terminal as the security carrier of the digital car key. The SIM card can be easily switched between terminals of different brands. When the user changes the mobile terminal, the car key service can be used normally by inserting the SIM card, which reduces the migration threshold of the car key after the user changes the phone. And the NFC function opened by the mobile terminal to the SIM card between the car owner's SIM card and the SIM card of relatives and friends can realize the offline digital car key authorization of the car owner to relatives and friends.
[0250] like Fig. 9 As shown, an embodiment of the present invention further provides a digital car key sharing method, which is executed by a second SIM card, and the method further includes:
[0251] Step 901, establishing an NFC connection with a first SIM card based on NFC, wherein the first SIM card and the second SIM card are respectively pre-installed with digital car key programs; and a first digital car key private key and a first digital car key public key of the first SIM card are successfully paired with a target vehicle;
[0252] Step 902: Generate a second digital car key public key and a second digital car key private key, and send a first request to the first SIM card via NFC; the first request carries the second digital car key public key;
[0253] Step 903, receiving the first SIM card to sign the second digital car key public key using the first digital car key private key of the first SIM card to generate signature information;
[0254] Step 904: Send a receiving result to the first SIM card, where the receiving result is used to indicate that the second SIM card successfully receives the signature information.
[0255] For example, the first SIM card is the car owner's SIM card, and the second SIM card is the relative's and friends' SIM card; in the embodiment of the present invention, the car owner's SIM card and the relative's and friends' SIM card rely on the NFC function opened by the mobile terminal to the SIM card to realize the offline digital car key authorization of the car owner to the relatives and friends.
[0256] In at least one optional embodiment of the present invention, the SIM card of the car owner and the SIM card of the relative or friend can be connected by the NFC function opened by the mobile terminal to the SIM card, so that the car owner can authorize the offline car key to the relative or friend; that is, when the car owner needs to share the digital car key with the relative or friend, even if the mobile terminals of both parties are not connected to the Internet, the car owner can share the car key through the NFC connection. At the same time, when sharing the car key, the relative or friend does not need to download and install the car key APP on the mobile phone, nor does he need to worry about the brand of the mobile terminal of the relative or friend.
[0257] It should be noted that the NFC interaction between the two SIM cards can be transmitted only through NFC or through an NFC secure channel (i.e., a second shared key is pre-established), which is not specifically limited here. Accordingly, the method further includes:
[0258] The second SIM card and the first SIM card determine a second shared key based on NFC negotiation and establish an NFC connection;
[0259] The information transmitted between the second SIM card and the first SIM card is encrypted and decrypted using the second shared key.
[0260] As an optional embodiment, if the target vehicle stores a second digital vehicle key public key; the method further includes:
[0261] Send the identification to the target vehicle via NFC;
[0262] Receiving a random challenge message sent by the target vehicle via NFC after verifying the identity of the second SIM card;
[0263] Sign the random challenge information using the second digital car key private key to generate second ciphertext information, and send the second ciphertext information to the target vehicle via NFC;
[0264] Receive the execution result fed back by the target vehicle through NFC; wherein, when the target vehicle verifies the second ciphertext information according to the second digital vehicle key public key, the execution result is that the door is opened or locked; otherwise, the execution result is that the door fails to open or lock.
[0265] The method of using the second SIM card to open or lock the door is the same as the method of using the owner's SIM card to open or lock the door, so it will not be repeated here.
[0266] When a non-owner SIM card (also referred to as a SIM card not paired with the target vehicle, i.e., a second SIM card) uses the digital vehicle key for the first time, and the vehicle does not store the second digital vehicle key public key, before receiving the random challenge information sent via NFC, the method further includes:
[0267] Receive the authorization verification request sent by the target vehicle via NFC;
[0268] According to the authorization verification request, the signature information of the first SIM card is sent to the target vehicle via NFC, so that the target vehicle decrypts the signature information using the first digital car key public key of the first SIM card, obtains the second digital car key public key of the second SIM card and stores it.
[0269] like Fig.10 As shown, the first-time use process of the digital car key of the second SIM card is as follows:
[0270] Step 1: The car owner's friend places the mobile terminal close to the NFC card reader on the car to establish an NFC connection.
[0271] Step 2: The target vehicle and the SIM card establish a secure channel based on the NFC near-field communication protocol, negotiate and determine a first shared key, and subsequent data exchange processes are protected by the first shared key.
[0272] Step 3: The second SIM card sends an identity authentication request to the vehicle, carrying the identity identifier.
[0273] Step 4: the target vehicle determines that it is the second SIM card according to the identity identifier, and sends an authorization verification request to the second SIM card;
[0274] Step 5, the second SIM card sends the signature information of the first SIM card to the target vehicle;
[0275] Step 6: The target vehicle uses the PKc of the owner's SIM card to verify the signature. If the verification is successful, the PKr of the second SIM card is stored;
[0276] Step 7, the target vehicle sends a random challenge message;
[0277] Step 8: The second SIM card signs the random challenge information using the second digital car key private key SKr to generate the second ciphertext information;
[0278] Step 9, the second SIM card sends the second ciphertext information to the target vehicle;
[0279] Step 10: The target vehicle uses the second digital car key public key PKr to verify the signature of the second ciphertext information; if the verification is successful, the door is opened or locked; otherwise, no response is given;
[0280] Step 11: The target vehicle returns the execution result to the second SIM card.
[0281] It should be noted that, in step 3-10, all information previously transmitted between the second SIM card and the target vehicle is protected by the first shared key.
[0282] In summary, the embodiment of the present invention adopts the SIM card of the mobile terminal as the security carrier of the digital car key. The SIM card can be easily switched between terminals of different brands. When the user changes the mobile terminal, the car key service can be used normally by inserting the SIM card, which reduces the migration threshold of the car key after the user changes the phone. And the NFC function opened by the mobile terminal to the SIM card between the car owner's SIM card and the SIM card of relatives and friends can realize the offline digital car key authorization of the car owner to relatives and friends.
[0283] like Fig.11 As shown, an embodiment of the present invention further provides a digital car key processing device, which is applied to a user identification module SIM card, and a digital car key program is pre-installed in the SIM card; the device includes:
[0284] The first establishing module 101 is used to negotiate with the target vehicle to determine a first shared key and establish a secure channel based on near field communication NFC;
[0285] The first processing module 102 is used to encrypt and decrypt the digital vehicle key related information transmitted between the SIM card and the target vehicle by using the first shared key.
[0286] As an optional embodiment, the first establishing module includes:
[0287] A first submodule, configured to generate a first temporary public key and a first temporary private key according to a first elliptic encryption curve;
[0288] A second submodule is configured to send the first temporary public key to a target vehicle based on NFC, so that the target vehicle determines a first shared key according to the first temporary public key and the second temporary private key; wherein the second temporary private key is generated by the target vehicle according to the first elliptic encryption curve;
[0289] A third submodule is used to receive a second temporary public key generated by the target vehicle according to the first elliptic encryption curve and sent by the target vehicle based on NFC;
[0290] The fourth submodule is used to determine the first shared key according to the first temporary private key and the second temporary public key.
[0291] As an optional embodiment, the device further includes:
[0292] A message processing module, used for the SIM card to send a first shared key negotiation success message to the target vehicle after determining the first shared key; or to receive the first shared key negotiation success message sent by the target vehicle to the SIM card after determining the first shared key;
[0293] A determination module is used to determine whether a secure channel is successfully established based on the first shared key negotiation success message.
[0294] As an optional embodiment, the first processing module includes:
[0295] A fifth submodule, for generating a digital car key public key and a digital car key private key;
[0296] A sixth submodule, configured to encrypt the digital vehicle key public key by using a first shared key, and send the encrypted first digital vehicle key public key to the target vehicle via NFC;
[0297] The seventh submodule is used to receive the pairing result fed back by the target vehicle through NFC; wherein, when the target vehicle uses the first shared key to decrypt the encrypted digital car key public key to obtain and store the digital car key public key, the pairing result is a successful pairing; otherwise, the pairing result is a failed pairing.
[0298] As an optional embodiment, when the vehicle stores the digital vehicle key public key corresponding to the SIM card, the first processing module further includes:
[0299] An eighth submodule, configured to encrypt the identity of the SIM card by using the first shared key, and send the encrypted identity to the target vehicle by using NFC;
[0300] A ninth submodule, configured to receive an encrypted random challenge message sent by the target vehicle through NFC after the target vehicle verifies the identity of the SIM card using the first shared key; the random challenge message is encrypted by the first shared key;
[0301] A tenth submodule, configured to decrypt the encrypted random challenge information using the first shared key to obtain random challenge information;
[0302] An eleventh submodule is used to sign the random challenge information using the digital vehicle key private key to generate first ciphertext information, and send the first ciphertext information to the target vehicle via NFC;
[0303] The twelfth sub-module is used to receive the execution result fed back by the target vehicle through NFC; wherein, when the target vehicle verifies the first ciphertext information according to the digital car key public key corresponding to the digital car key private key, the execution result is that the door is opened or locked; otherwise, the execution result is that the door fails to open or the door fails to lock.
[0304] As an optional embodiment, when the vehicle does not store the digital vehicle key public key corresponding to the SIM card, the device further includes:
[0305] A verification receiving module, used to receive an authorization verification request sent by a target vehicle via NFC;
[0306] The sending module is used to send the signature information of the SIM card paired with the vehicle to the target vehicle through NFC according to the authorization verification request, so that the target vehicle can decrypt the signature information using the digital car key public key of the SIM card paired with the vehicle, obtain the digital car key public key corresponding to the SIM card and store it.
[0307] The embodiment of the present invention adopts the SIM card of the mobile terminal as the security carrier of the digital car key. The SIM card can be easily switched between terminals of different brands. When the user changes the mobile terminal, the car key service can be used normally by inserting the SIM card, which reduces the migration threshold of the car key after the user changes the phone. Further, the establishment of a secure channel between the SIM card and the vehicle is realized through NFC, which can ensure the security of data transmission and realize one-time one-key.
[0308] It should be noted that the digital car key processing device provided in the embodiment of the present invention is a device capable of executing the above-mentioned digital car key processing method. All embodiments of the above-mentioned digital car key processing method are applicable to the device and can achieve the same or similar beneficial effects.
[0309] like Fig.12 As shown, an embodiment of the present invention further provides a SIM card, including a processor 100 and a transceiver 110, wherein the transceiver 110 receives and sends data under the control of the processor 100, and the processor 100 is used to perform the following operations:
[0310] Based on near field communication NFC, negotiate with the target vehicle to determine a first shared key and establish a secure channel;
[0311] The digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted using the first shared key.
[0312] As an optional embodiment, the processor 100 is further configured to perform the following operations:
[0313] Generate a first temporary public key and a first temporary private key according to a first elliptic encryption curve;
[0314] Based on NFC, the first temporary public key is sent to the target vehicle; so that the target vehicle determines a first shared key according to the first temporary public key and the second temporary private key; wherein the second temporary private key is generated by the target vehicle according to the first elliptic encryption curve;
[0315] Receiving a second temporary public key generated by the target vehicle according to the first elliptic encryption curve and sent by the target vehicle based on NFC;
[0316] The first shared key is determined according to the first temporary private key and the second temporary public key.
[0317] As an optional embodiment, the processor 100 is further configured to perform the following operations:
[0318] After determining the first shared key, the SIM card sends a first shared key negotiation success message to the target vehicle; or receives a first shared key negotiation success message sent by the target vehicle to the SIM card after determining the first shared key;
[0319] According to the first shared key negotiation success message, it is determined that the secure channel is successfully established.
[0320] As an optional embodiment, the processor 100 is further configured to perform the following operations:
[0321] Generate a digital car key public key and a digital car key private key;
[0322] Encrypting the digital vehicle key public key by using a first shared key, and sending the encrypted digital vehicle key public key to the target vehicle via NFC;
[0323] Receive the pairing result fed back by the target vehicle through NFC; wherein, if the target vehicle uses the first shared key to decrypt the encrypted digital car key public key to obtain and store the digital car key public key, the pairing result is a successful pairing; otherwise, the pairing result is a failed pairing.
[0324] As an optional embodiment, when the vehicle stores the digital vehicle key public key corresponding to the SIM card, the processor 100 is further configured to perform the following operations:
[0325] Encrypting the identity of the SIM card by using the first shared key, and sending the encrypted identity to the target vehicle by using NFC;
[0326] Receiving an encrypted random challenge message sent by the target vehicle through NFC after the target vehicle verifies the identity of the SIM card using the first shared key; the random challenge message is encrypted by the first shared key;
[0327] Decrypting the encrypted random challenge information using the first shared key to obtain random challenge information;
[0328] Sign the random challenge information using the digital car key private key to generate first ciphertext information, and send the first ciphertext information to the target vehicle via NFC;
[0329] Receive the execution result fed back by the target vehicle through NFC; wherein, when the target vehicle verifies the first ciphertext information according to the digital car key public key corresponding to the digital car key private key, the execution result is that the door is opened or locked; otherwise, the execution result is that the door fails to open or lock.
[0330] As an optional embodiment, when the vehicle does not store the digital vehicle key public key corresponding to the SIM card, the processor 100 is further configured to perform the following operations:
[0331] Receive the authorization verification request sent by the target vehicle via NFC;
[0332] According to the authorization verification request, the signature information of the SIM card paired with the vehicle is sent to the target vehicle via NFC, so that the target vehicle decrypts the signature information using the digital car key public key of the SIM card paired with the vehicle, obtains the digital car key public key corresponding to the SIM card and stores it.
[0333] The embodiment of the present invention adopts the SIM card of the mobile terminal as the security carrier of the digital car key. The SIM card can be easily switched between terminals of different brands. When the user changes the mobile terminal, the car key service can be used normally by inserting the SIM card, which reduces the migration threshold of the car key after the user changes the phone. Further, the establishment of a secure channel between the SIM card and the vehicle is realized through NFC, which can ensure the security of data transmission and realize one-time one-key.
[0334] It should be noted that the SIM card provided in the embodiment of the present invention is a SIM card capable of executing the above-mentioned digital car key processing method. All embodiments of the above-mentioned digital car key processing method are applicable to the SIM card and can achieve the same or similar beneficial effects.
[0335] like Fig.13 As shown, an embodiment of the present invention further provides a digital car key processing device, which is applied to a target vehicle, wherein an NFC card reader module is pre-installed in the target vehicle, and the device includes:
[0336] The second establishing module 131 is used to negotiate with the SIM card to determine the first shared key and establish a secure channel based on the NFC card reader module;
[0337] The second processing module 132 is used to encrypt and decrypt the digital vehicle key related information transmitted between the SIM card and the target vehicle by using the first shared key.
[0338] As an optional embodiment, the second establishing module includes:
[0339] The twentieth submodule is configured to receive a first temporary public key sent by the SIM card based on NFC; wherein the SIM card generates a first temporary public key and a first temporary private key according to a first elliptic encryption curve;
[0340] A twenty-first submodule, configured to generate a second temporary public key and a second temporary private key according to the first elliptic encryption curve;
[0341] A twenty-second submodule, configured to determine the first shared key according to the first temporary public key and the second temporary private key;
[0342] The twenty-third submodule is configured to send the second temporary public key to the SIM card based on NFC, so that the SIM card determines the first shared key according to the first temporary private key and the second temporary public key.
[0343] As an optional embodiment, the device further includes:
[0344] A successful negotiation module, used for the target vehicle to send a first shared key negotiation success message to the SIM card after determining the first shared key; or to receive the first shared key negotiation success message sent by the SIM card to the target vehicle after determining the first shared key;
[0345] The establishment success module is used to determine that the security channel is successfully established according to the first shared key negotiation success message.
[0346] As an optional embodiment, the second processing module includes:
[0347] The twenty-fourth submodule is used to receive the encrypted digital car key public key sent by the SIM card via NFC;
[0348] A twenty-fifth submodule, configured to decrypt the encrypted digital vehicle key public key using the first shared key;
[0349] The twenty-sixth submodule is used to store the digital car key public key and send a pairing result to the SIM card if the digital car key public key of the SIM card is successfully decrypted, and the pairing result is a successful pairing; otherwise, a pairing result of failed pairing is sent to the SIM card.
[0350] As an optional embodiment, when the vehicle stores the digital vehicle key public key corresponding to the SIM card, the second processing module includes:
[0351] The twenty-seventh submodule is used to receive the encrypted identity sent by the SIM card through NFC;
[0352] The twenty-eighth submodule is configured to decrypt and verify the encrypted identity using the first shared key, and send the encrypted random challenge information to the SIM card via NFC; the random challenge information is encrypted using the first shared key;
[0353] The twenty-ninth submodule is used to receive the first ciphertext information sent by the SIM card through NFC after the random challenge information is obtained by decrypting the random challenge information using the first shared key; the first ciphertext information is obtained by the SIM card signing the random challenge information using the digital car key private key;
[0354] The 30th sub-module is used to verify the first ciphertext information using the digital car key public key and send the execution result to the SIM card; if the verification is passed, the car door is opened or locked, and the execution result is that the car door is opened or locked; otherwise, the execution result is that the car door fails to open or locks.
[0355] As an optional embodiment, when the vehicle does not store the digital vehicle key public key corresponding to the SIM card, the device further includes:
[0356] The thirty-fifth submodule is used to send an authorization verification request to the SIM card via NFC;
[0357] A thirty-sixth submodule is configured to receive the signature information of the SIM card that has been paired with the vehicle and sent by the SIM card according to the authorization verification request; the signature information of the SIM card that has been paired with the vehicle is generated by the SIM card that has been paired with the vehicle signing the digital car key public key of the SIM card according to its corresponding digital car key private key;
[0358] The thirty-seventh sub-module is used to verify the signature information according to the digital car key public key corresponding to the SIM card that has been paired with the vehicle. If the verification is successful, the digital car key public key corresponding to the SIM card is stored.
[0359] The embodiment of the present invention adopts the SIM card of the mobile terminal as the security carrier of the digital car key. The SIM card can be easily switched between terminals of different brands. When the user changes the mobile terminal, the car key service can be used normally by inserting the SIM card, which reduces the migration threshold of the car key after the user changes the phone. Further, the establishment of a secure channel between the SIM card and the vehicle is realized through NFC, which can ensure the security of data transmission and realize one-time one-key.
[0360] It should be noted that the digital car key processing device provided in the embodiment of the present invention is a device capable of executing the above-mentioned digital car key processing method. All embodiments of the above-mentioned digital car key processing method are applicable to the device and can achieve the same or similar beneficial effects.
[0361] like Fig.14 As shown, an embodiment of the present invention further provides a target vehicle, including a processor 120 and a transceiver 121, wherein the transceiver 121 receives and sends data under the control of the processor 120, and the processor 120 is used to perform the following operations:
[0362] Based on the NFC card reader module, negotiate with the SIM card to determine the first shared key and establish a secure channel;
[0363] The digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted using the first shared key.
[0364] As an optional embodiment, the processor 120 is further configured to perform the following operations:
[0365] Receiving a first temporary public key sent by the SIM card based on NFC; wherein the SIM card generates a first temporary public key and a first temporary private key according to a first elliptic encryption curve;
[0366] Generate a second temporary public key and a second temporary private key according to the first elliptic encryption curve;
[0367] Determine the first shared key according to the first temporary public key and the second temporary private key;
[0368] The second temporary public key is sent to the SIM card based on NFC; so that the SIM card determines the first shared key according to the first temporary private key and the second temporary public key.
[0369] As an optional embodiment, the processor 120 is further configured to perform the following operations:
[0370] The target vehicle sends a first shared key negotiation success message to the SIM card after determining the first shared key; or, receives the first shared key negotiation success message sent by the SIM card to the target vehicle after determining the first shared key;
[0371] According to the first shared key negotiation success message, it is determined that the secure channel is successfully established.
[0372] As an optional embodiment, when the SIM card is a SIM card of a vehicle owner, the processor 120 is further configured to perform the following operations:
[0373] Receive the encrypted digital car key public key sent by the SIM card via NFC;
[0374] Decrypting the encrypted digital vehicle key public key using the first shared key;
[0375] If the digital car key public key of the SIM card is successfully decrypted, the digital car key public key is stored and a pairing result is sent to the SIM card, and the pairing result is a successful pairing; otherwise, a pairing result indicating a failed pairing is sent to the SIM card.
[0376] As an optional embodiment, when the vehicle stores the digital vehicle key public key corresponding to the SIM card, the processor 120 is further configured to perform the following operations:
[0377] Receive the encrypted identity sent by the SIM card via NFC;
[0378] Decrypting and verifying the encrypted identity using the first shared key, and sending encrypted random challenge information to the SIM card via NFC; the random challenge information is encrypted using the first shared key;
[0379] After receiving the first ciphertext information sent by the SIM card through NFC after decrypting the random challenge information using the first shared key; the first ciphertext information is obtained by signing the random challenge information using the digital car key private key by the SIM card;
[0380] The first ciphertext information is verified using the digital car key public key, and the execution result is sent to the SIM card; if the verification is passed, the car door is opened or locked, and the execution result is that the car door is opened or locked; otherwise, the execution result is that the car door fails to open or lock.
[0381] As an optional embodiment, when the vehicle does not store the digital vehicle key public key corresponding to the SIM card, the processor 120 is further configured to perform the following operations:
[0382] Send an authorization verification request to the SIM card via NFC;
[0383] Receiving the signature information of the SIM card paired with the vehicle sent by the SIM card according to the authorization verification request; the signature information of the SIM card paired with the vehicle is generated by the SIM card paired with the vehicle signing the digital car key public key of the SIM card according to its corresponding digital car key private key;
[0384] The signature information is verified according to the digital car key public key corresponding to the SIM card that has been paired with the vehicle. If the verification is successful, the digital car key public key corresponding to the SIM card is stored.
[0385] The embodiment of the present invention adopts the SIM card of the mobile terminal as the security carrier of the digital car key. The SIM card can be easily switched between terminals of different brands. When the user changes the mobile terminal, the car key service can be used normally by inserting the SIM card, which reduces the migration threshold of the car key after the user changes the phone. Further, the establishment of a secure channel between the SIM card and the vehicle is realized through NFC, which can ensure the security of data transmission and realize one-time one-key.
[0386] It should be noted that the target vehicle provided in the embodiment of the present invention is a target vehicle capable of executing the above-mentioned digital car key processing method. All embodiments of the above-mentioned digital car key processing method are applicable to the target vehicle and can achieve the same or similar beneficial effects.
[0387] like Fig.15 As shown, an embodiment of the present invention further provides a digital car key sharing device, which is applied to a first SIM card, in which a digital car key is preset; and a first digital car key private key and a first digital car key public key of the first SIM card are successfully paired with a target vehicle; the device includes:
[0388] The first connection module 151 is used to establish an NFC connection with a second SIM card based on NFC; wherein the second SIM card is pre-installed with a digital car key program;
[0389] The first request receiving module 152 is used to receive a first request sent through the NFC connection after the second SIM card generates a second digital car key public key and a second digital car key private key; the first request carries the second digital car key public key;
[0390] A signature sending module 153, configured to sign the second digital car key public key using the first digital car key private key of the first SIM card to generate signature information, and send the signature information to the second SIM card through an NFC connection;
[0391] The result receiving module 154 is used to receive a receiving result fed back by the second SIM card after receiving the signature information, wherein the receiving result is used to indicate that the second SIM card successfully receives the signature information.
[0392] The embodiment of the present invention adopts the SIM card of the mobile terminal as the security carrier of the digital car key. The SIM card can be easily switched between terminals of different brands. When the user changes the mobile terminal, the car key service can be used normally by inserting the SIM card, which reduces the migration threshold of the car key after the user changes the phone. Moreover, the NFC function opened by the mobile terminal to the SIM card between the car owner's SIM card and the SIM card of relatives and friends can realize the offline digital car key authorization of the car owner to relatives and friends.
[0393] It should be noted that the digital car key sharing device provided in the embodiment of the present invention is a device capable of executing the above-mentioned digital car key method, and all embodiments of the above-mentioned digital car key sharing method are applicable to the device and can achieve the same or similar beneficial effects.
[0394] like Fig.16 As shown, an embodiment of the present invention further provides a SIM card, wherein the SIM card is a first SIM card, in which a digital car key is preset; and a first digital car key private key and a first digital car key public key of the first SIM card are successfully paired with a target vehicle; the SIM card further includes a processor 160 and a transceiver 161, wherein the transceiver 161 receives and sends data under the control of the processor 160, and the processor 160 is used to perform the following operations:
[0395] Establishing an NFC connection with a second SIM card based on NFC; wherein the second SIM card is pre-installed with a digital car key program;
[0396] Receiving a first request sent through an NFC connection after a second digital car key public key and a second digital car key private key are generated by a second SIM card; the first request carries the second digital car key public key;
[0397] Using the first digital car key private key of the first SIM card to sign the second digital car key public key to generate signature information, and sending the signature information to the second SIM card through the NFC connection;
[0398] A receiving result fed back by the second SIM card after receiving the signature information is received, wherein the receiving result is used to indicate that the second SIM card successfully receives the signature information.
[0399] The embodiment of the present invention adopts the SIM card of the mobile terminal as the security carrier of the digital car key. The SIM card can be easily switched between terminals of different brands. When the user changes the mobile terminal, the car key service can be used normally by inserting the SIM card, which reduces the migration threshold of the car key after the user changes the phone. Moreover, the NFC function opened by the mobile terminal to the SIM card between the car owner's SIM card and the SIM card of relatives and friends can realize the offline digital car key authorization of the car owner to relatives and friends.
[0400] It should be noted that the digital car key sharing device provided in the embodiment of the present invention is a device capable of executing the above-mentioned digital car key method, and all embodiments of the above-mentioned digital car key sharing method are applicable to the device and can achieve the same or similar beneficial effects.
[0401] like Fig.17 As shown, an embodiment of the present invention further provides a digital car key sharing device, which is applied to a second SIM card, and the device includes:
[0402] The second connection module 171 is used to establish an NFC connection with the first SIM card based on NFC, wherein the first SIM card and the second SIM card are respectively pre-installed with digital car key programs; and the first digital car key private key and the first digital car key public key of the first SIM card are successfully paired with the target vehicle;
[0403] A first request sending module 172 is used to generate a second digital car key public key and a second digital car key private key, and send a first request to the first SIM card via NFC; the first request carries the second digital car key public key;
[0404] The signature receiving module 173 is used to receive signature information generated by the first SIM card using the first digital car key private key of the first SIM card to sign the second digital car key public key;
[0405] The result sending module 174 is used to send a receiving result to the first SIM card, where the receiving result is used to indicate that the second SIM card successfully receives the signature information.
[0406] The embodiment of the present invention adopts the SIM card of the mobile terminal as the security carrier of the digital car key. The SIM card can be easily switched between terminals of different brands. When the user changes the mobile terminal, the car key service can be used normally by inserting the SIM card, which reduces the migration threshold of the car key after the user changes the phone. Moreover, the NFC function opened by the mobile terminal to the SIM card between the car owner's SIM card and the SIM card of relatives and friends can realize the offline digital car key authorization of the car owner to relatives and friends.
[0407] It should be noted that the digital car key sharing device provided in the embodiment of the present invention is a device capable of executing the above-mentioned digital car key method, and all embodiments of the above-mentioned digital car key sharing method are applicable to the device and can achieve the same or similar beneficial effects.
[0408] like Fig.18 As shown, an embodiment of the present invention further provides a SIM card, the SIM card is a second SIM card, the SIM card further includes a processor 180 and a transceiver 181, the transceiver 181 receives and sends data under the control of the processor 180, and the processor 180 is used to perform the following operations:
[0409] An NFC connection is established with the first SIM card based on NFC, wherein the first SIM card and the second SIM card are respectively pre-installed with digital car key programs; and a first digital car key private key and a first digital car key public key of the first SIM card are successfully paired with the target vehicle;
[0410] Generate a second digital car key public key and a second digital car key private key, and send a first request to the first SIM card through NFC; the first request carries the second digital car key public key;
[0411] The first SIM card is received to sign the second digital car key public key using the first digital car key private key of the first SIM card to generate signature information;
[0412] A receiving result is sent to the first SIM card, where the receiving result is used to indicate that the second SIM card successfully receives the signature information.
[0413] The embodiment of the present invention adopts the SIM card of the mobile terminal as the security carrier of the digital car key. The SIM card can be easily switched between terminals of different brands. When the user changes the mobile terminal, the car key service can be used normally by inserting the SIM card, which reduces the migration threshold of the car key after the user changes the phone. Moreover, the NFC function opened by the mobile terminal to the SIM card between the car owner's SIM card and the SIM card of relatives and friends can realize the offline digital car key authorization of the car owner to relatives and friends.
[0414] It should be noted that the digital car key sharing device provided in the embodiment of the present invention is a device capable of executing the above-mentioned digital car key method, and all embodiments of the above-mentioned digital car key sharing method are applicable to the device and can achieve the same or similar beneficial effects.
[0415] An embodiment of the present invention also provides a communication device, which is a SIM card or a target vehicle, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, each process in the above-mentioned digital car key processing method embodiment or the digital car key sharing method embodiment is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
[0416] The embodiment of the present invention also provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, each process in the above-mentioned digital car key processing method embodiment or digital car key sharing method embodiment can be implemented, and the same technical effect can be achieved. To avoid repetition, it is not repeated here. The computer-readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0417] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to disk storage and optical storage, etc.) containing computer-usable program code.
[0418] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A device that specifies functions in one or more processes and / or one or more blocks.
[0419] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable storage medium produce a paper product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0420] These computer program instructions may also be loaded onto a computer or other programmable data processing device to cause the computer or other programmable device to execute a series of operating steps to produce a computer-implemented process, thereby providing instructions executed on the computer or other programmable device for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0421] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A method for processing a digital car key, executed by a user identification module SIM card, characterized in that: A digital car key program is pre-installed in a SIM card; the method comprises: Based on near field communication NFC, negotiate with the target vehicle to determine a first shared key and establish a secure channel; Encrypt and decrypt the digital car key related information transmitted between the SIM card and the target vehicle using the first shared key; Wherein, when the vehicle stores the public key of the digital car key corresponding to the SIM card, the digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted by using the first shared key, including: Encrypting the identity of the SIM card by using the first shared key, and sending the encrypted identity to the target vehicle by using NFC; Receiving the encrypted random challenge information sent by the target vehicle through NFC after the target vehicle verifies the identity of the SIM card by using the first shared key; the encrypted random challenge information is obtained by encrypting the random challenge information by using the first shared key; Decrypting the encrypted random challenge information using the first shared key to obtain random challenge information; The random challenge information is signed using the digital car key private key to generate first ciphertext information, and the first ciphertext information is sent to the target vehicle via NFC.
2. The method according to claim 1, characterized in that Based on near field communication NFC, a first shared key is determined through negotiation with the target vehicle, including: Generate a first temporary public key and a first temporary private key according to a first elliptic encryption curve; Based on NFC, the first temporary public key is sent to the target vehicle; so that the target vehicle determines a first shared key according to the first temporary public key and the second temporary private key; wherein the second temporary private key is generated by the target vehicle according to the first elliptic encryption curve; Receiving a second temporary public key generated by the target vehicle according to the first elliptic encryption curve and sent by the target vehicle based on NFC; The first shared key is determined according to the first temporary private key and the second temporary public key.
3. The method according to claim 2, characterized in that The method further comprises: After determining the first shared key, the SIM card sends a first shared key negotiation success message to the target vehicle; or receives a first shared key negotiation success message sent by the target vehicle to the SIM card after determining the first shared key; According to the first shared key negotiation success message, it is determined that the secure channel is successfully established.
4. The method according to claim 1, characterized in that The digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted using the first shared key, including: Generate a digital car key public key and a digital car key private key; Encrypting the digital vehicle key public key by using a first shared key, and sending the encrypted digital vehicle key public key to the target vehicle via NFC; Receive the pairing result fed back by the target vehicle through NFC; wherein, if the target vehicle uses the first shared key to decrypt the encrypted digital car key public key to obtain and store the digital car key public key, the pairing result is a successful pairing; otherwise, the pairing result is a failed pairing.
5. The method according to claim 1, characterized in that In the case where the vehicle stores the public key of the digital car key corresponding to the SIM card, the digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted by using the first shared key, further comprising: Receive the execution result fed back by the target vehicle through NFC; wherein, when the target vehicle verifies the first ciphertext information according to the digital car key public key corresponding to the digital car key private key, the execution result is that the door is opened or locked; otherwise, the execution result is that the door fails to open or lock.
6. The method according to claim 5, characterized in that In the case where the vehicle does not store the digital vehicle key public key corresponding to the SIM card, before receiving the encrypted random challenge information sent via NFC, the method further includes: Receive the authorization verification request sent by the target vehicle via NFC; According to the authorization verification request, the signature information of the SIM card paired with the vehicle is sent to the target vehicle via NFC, so that the target vehicle decrypts the signature information using the digital car key public key of the SIM card paired with the vehicle, obtains the digital car key public key corresponding to the SIM card and stores it.
7. A method for processing a digital car key, executed by a target vehicle, characterized in that: The target vehicle is pre-installed with an NFC card reader module, and the method comprises: Based on the NFC card reader module, negotiate with the SIM card to determine the first shared key and establish a secure channel; Encrypt and decrypt the digital car key related information transmitted between the SIM card and the target vehicle using the first shared key; Wherein, when the vehicle stores the public key of the digital car key corresponding to the SIM card, the digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted by using the first shared key, including: Receiving the encrypted SIM card identity sent by the SIM card through NFC; Decrypting and verifying the encrypted identity using the first shared key, and sending the encrypted random challenge information to the SIM card via NFC; the encrypted random challenge information is obtained by encrypting the random challenge information using the first shared key; After receiving the first ciphertext information sent by the SIM card through NFC after decrypting the encrypted random challenge information using the first shared key to obtain the random challenge information; the first ciphertext information is obtained by the SIM card signing the random challenge information using the digital car key private key; The first ciphertext information is verified using the digital car key public key.
8. The method according to claim 7, characterized in that Based on the NFC card reader module, the first shared key is determined through negotiation with the SIM card, including: Receiving a first temporary public key sent by the SIM card based on NFC; wherein the SIM card generates a first temporary public key and a first temporary private key according to a first elliptic encryption curve; Generate a second temporary public key and a second temporary private key according to the first elliptic encryption curve; Determine the first shared key according to the first temporary public key and the second temporary private key; The second temporary public key is sent to the SIM card based on NFC; so that the SIM card determines the first shared key according to the first temporary private key and the second temporary public key.
9. The method according to claim 8, characterized in that The method further comprises: The target vehicle sends a first shared key negotiation success message to the SIM card after determining the first shared key; or, receives the first shared key negotiation success message sent by the SIM card to the target vehicle after determining the first shared key; According to the first shared key negotiation success message, it is determined that the secure channel is successfully established.
10. The method according to claim 7, characterized in that The digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted using the first shared key, including: Receive the encrypted digital car key public key sent by the SIM card via NFC; Decrypting the encrypted digital vehicle key public key using the first shared key; If the digital car key public key of the SIM card is successfully decrypted, the digital car key public key is stored and a pairing result is sent to the SIM card, and the pairing result is a successful pairing; otherwise, a pairing result indicating a failed pairing is sent to the SIM card.
11. The method according to claim 7, characterized in that In the case where the vehicle stores the public key of the digital car key corresponding to the SIM card, the digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted by using the first shared key, further comprising: Send the execution result to the SIM card; if the first ciphertext information is verified, open the door or lock the door, and the execution result is that the door is opened or locked; otherwise, the execution result is that the door fails to open or lock.
12. The method according to claim 11, characterized in that In the case that the vehicle does not store the digital vehicle key public key corresponding to the SIM card, before sending the encrypted random challenge information to the SIM card via NFC, the method further includes: Send an authorization verification request to the SIM card via NFC; Receiving the signature information of the SIM card paired with the vehicle sent by the SIM card according to the authorization verification request; the signature information of the SIM card paired with the vehicle is generated by the SIM card paired with the vehicle signing the digital car key public key of the SIM card according to its corresponding digital car key private key; The signature information is verified according to the digital car key public key corresponding to the SIM card that has been paired with the vehicle. If the verification is successful, the digital car key public key corresponding to the SIM card is stored.
13. A digital car key processing device, applied to a user identification module SIM card, characterized in that: A digital car key program is pre-installed in the SIM card; the device comprises: A first establishing module, used to negotiate with a target vehicle to determine a first shared key and establish a secure channel based on near field communication NFC; A first processing module, used for encrypting and decrypting the digital car key related information transmitted between the SIM card and the target vehicle by using the first shared key; Wherein, when the vehicle stores the public key of the digital car key corresponding to the SIM card, the digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted by using the first shared key, including: Encrypting the identity of the SIM card by using the first shared key, and sending the encrypted identity to the target vehicle by using NFC; Receiving the encrypted random challenge information sent by the target vehicle through NFC after the target vehicle verifies the identity of the SIM card by using the first shared key; the encrypted random challenge information is obtained by encrypting the random challenge information by using the first shared key; Decrypting the encrypted random challenge information using the first shared key to obtain random challenge information; The random challenge information is signed using the digital car key private key to generate first ciphertext information, and the first ciphertext information is sent to the target vehicle via NFC.
14. A SIM card, comprising a processor and a transceiver, wherein the transceiver receives and sends data under the control of the processor, characterized in that: The processor is configured to perform the following operations: Based on near field communication NFC, negotiate with the target vehicle to determine a first shared key and establish a secure channel; Encrypt and decrypt the digital car key related information transmitted between the SIM card and the target vehicle using the first shared key; Wherein, when the vehicle stores the public key of the digital car key corresponding to the SIM card, the digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted by using the first shared key, including: Encrypting the identity of the SIM card by using the first shared key, and sending the encrypted identity to the target vehicle by using NFC; Receiving the encrypted random challenge information sent by the target vehicle through NFC after the target vehicle verifies the identity of the SIM card by using the first shared key; the encrypted random challenge information is obtained by encrypting the random challenge information by using the first shared key; Decrypting the encrypted random challenge information using the first shared key to obtain random challenge information; The random challenge information is signed using the digital car key private key to generate first ciphertext information, and the first ciphertext information is sent to the target vehicle via NFC.
15. A digital car key processing device, applied to a target vehicle, characterized in that: The target vehicle is pre-installed with an NFC card reader module, and the device comprises: A second establishing module is used to negotiate with the SIM card to determine a first shared key and establish a secure channel based on the NFC card reader module; A second processing module, used for encrypting and decrypting the digital car key related information transmitted between the SIM card and the target vehicle by using the first shared key; Wherein, when the vehicle stores the public key of the digital car key corresponding to the SIM card, the digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted by using the first shared key, including: Receiving the encrypted SIM card identity sent by the SIM card through NFC; Decrypting and verifying the encrypted identity using the first shared key, and sending the encrypted random challenge information to the SIM card via NFC; the encrypted random challenge information is obtained by encrypting the random challenge information using the first shared key; After receiving the first ciphertext information sent by the SIM card through NFC after decrypting the encrypted random challenge information using the first shared key to obtain the random challenge information; the first ciphertext information is obtained by the SIM card signing the random challenge information using the digital car key private key; The first ciphertext information is verified using the digital car key public key.
16. A target vehicle, comprising a processor and a transceiver, wherein the transceiver receives and sends data under the control of the processor, characterized in that: The processor is configured to perform the following operations: Based on the NFC card reader module, negotiate with the SIM card to determine the first shared key and establish a secure channel; Encrypt and decrypt the digital car key related information transmitted between the SIM card and the target vehicle using the first shared key; Wherein, when the vehicle stores the public key of the digital car key corresponding to the SIM card, the digital car key related information transmitted between the SIM card and the target vehicle is encrypted and decrypted by using the first shared key, including: Receiving the encrypted SIM card identity sent by the SIM card through NFC; Decrypting and verifying the encrypted identity using the first shared key, and sending the encrypted random challenge information to the SIM card via NFC; the encrypted random challenge information is obtained by encrypting the random challenge information using the first shared key; After receiving the first ciphertext information sent by the SIM card through NFC after decrypting the encrypted random challenge information using the first shared key to obtain the random challenge information; the first ciphertext information is obtained by the SIM card signing the random challenge information using the digital car key private key; The first ciphertext information is verified using the digital car key public key.
17. A communication device comprising a memory, a processor, and a program stored in the memory and executable on the processor; characterized in that: When the processor executes the program, it implements the digital car key processing method as described in any one of claims 1-6; or, when the processor executes the program, it implements the digital car key processing method as described in any one of claims 7-12.
18. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps in the method for processing a digital car key as described in any one of claims 1 to 6 are implemented; or, when the program is executed by a processor, the steps in the method for processing a digital car key as described in any one of claims 7 to 12 are implemented.
Citation Information
Patent Citations
Vehicle control method based on digital vehicle key
CN111923863A