Login method and device, electronic equipment and storage medium
By obtaining the update token corresponding to the digital key from the vehicle terminal and directly binding it to the account server, automatic login is achieved, solving the problem of complex vehicle terminal login and improving user experience.
Patent Information
- Application Number
- CN202211321378.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-04-29
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2040-04-29
AI Technical Summary
In existing technologies, logging into a user account via a vehicle-mounted terminal requires scanning a QR code through a smart terminal, which makes the login process complex and time-consuming, causing inconvenience to users.
The vehicle terminal obtains the update token corresponding to the digital key and directly establishes a binding relationship with the account server, using the access token to achieve automatic login, avoiding the step of scanning a QR code each time.
It reduces the time required to log in to user accounts on the vehicle terminal, improves user experience, and simplifies the login process.
Smart Images

Figure CN115733663B_ABST
Abstract
Description
[0001] This application is a divisional application of the original application with the application number 202010354712.9 and the original filing date of April 29, 2020, and the entire contents of the original application are incorporated herein by reference. TECHNICAL FIELD
[0002] Embodiments of the present application relate to terminal technology, and in particular to a login method and device, electronic equipment and storage medium. BACKGROUND
[0003] With the continuous integration of information technology, the Internet and the automobile industry, the networking and intelligentization of automobiles has become an inevitable trend of the development of the automobile industry. A typical scenario of interconnection between intelligent terminals and vehicle terminals is to display the content on the intelligent terminal on the vehicle terminal, and to realize the function of playing music on the intelligent terminal on the vehicle terminal. In another scenario of interconnection between intelligent terminals and vehicle terminals, the vehicle terminal can also log in to the same user account on the intelligent terminal to obtain cloud services corresponding to the user account, such as music, travel information, intelligent service recommendations, remote management and other services corresponding to the user account.
[0004] In the prior art, the user can log in to the user account on the vehicle terminal by scanning the two-dimensional code displayed on the vehicle terminal through the intelligent terminal in the case that the intelligent terminal has logged in to the user account. This login method requires the user to scan the two-dimensional code through the intelligent terminal every time the user logs in to the user account on the vehicle terminal, which is complex and time-consuming, and causes inconvenience to the user. SUMMARY
[0005] Embodiments of the present application provide a login method and device, electronic equipment and storage medium, which reduce the time of logging in to the application program by the vehicle terminal using the user account and improve the user experience.
[0006] In a first aspect, an embodiment of the present application provides a login method, an execution subject of the login method is a vehicle terminal or a chip in the vehicle terminal. The following is described by taking the execution subject as the vehicle terminal. In an embodiment of the present application, when the vehicle terminal starts an application program, if the vehicle terminal obtains an update token corresponding to a first digital key, the vehicle terminal sends the update token to an account server, the first digital key is used to indicate that a first mobile terminal has a permission to control a vehicle to which the vehicle terminal belongs, the update token is used to indicate a first user account, and the first user account is a user account of a user who logs in the application program on the first mobile terminal; the vehicle terminal receives an access token generated by the account server based on the update token, the access token is related to the first user account, and the access token is used to indicate that the vehicle terminal has a permission to access data of the application program under the first user account; the vehicle terminal uses the access token to access the account server; receives the data of the application program under the first user account from the account server, and displays a first interface according to the data, the first interface being an interface after the vehicle terminal logs in the first user account.
[0007] It should be understood that in an embodiment of the present application, after the first digital key of the vehicle is verified, the door of the vehicle can be opened, and after the vehicle terminal is started and the application program is started, the vehicle terminal can directly execute the process of logging in the first user account of the vehicle terminal. Alternatively, after the first digital key of the vehicle is verified, the door of the vehicle can be opened, and after the user starts the vehicle terminal and starts the application program, the vehicle terminal executes the process of logging in the first user account.
[0008] In the process, if the vehicle terminal obtains the update token corresponding to the first digital key, it is determined that the first digital key has established a binding relationship with the first user account. It should be understood that the binding relationship between the first digital key and the first user account here means that the update token corresponding to the first digital key is stored in the first mobile terminal, or the vehicle terminal, or a vehicle-side authentication device, and the server side stores a corresponding relationship between the update token and the first user account. Therefore, when the vehicle terminal sends the update token corresponding to the first digital key to the server, the server can determine the access token related to the first user account, and then make the vehicle terminal log in the first user account by using the access token. It should be understood that the vehicle-side authentication device is not verified by the first digital key.
[0009] In the embodiments of the present application, when the vehicle door is opened by using the digital key and the vehicle terminal starts the application program, the vehicle terminal can obtain the access token corresponding to the user account according to the update token bound with the digital key, and then log in to the account server by using the access token, thereby avoiding the problem that the user needs to scan the two-dimensional code by using the mobile terminal every time the vehicle terminal logs in to the account server by using the user account. The login method in the embodiments of the present application reduces the login time and improves the user experience.
[0010] The following describes the steps of obtaining the update token corresponding to the first digital key by the vehicle terminal, in the case that the storage location of the update token bound with the first digital key is in the first mobile terminal, the vehicle authentication device or the vehicle terminal:
[0011] The first mode: the update token corresponding to the first digital key is stored in the first mobile terminal. When the first digital key is verified, the vehicle authentication device can read the update token in the first mobile terminal, and then store the update token in the vehicle authentication device, or establish and store the correspondence between the identifier of the first digital key and the update token.
[0012] When the vehicle terminal starts the application program, the vehicle authentication device can send the identifier of the first digital key to the vehicle terminal, so that the vehicle terminal can obtain the update token corresponding to the first digital key according to the correspondence stored in the vehicle authentication device. Alternatively, when the vehicle terminal starts the application program, the vehicle authentication device can read the update token stored therein.
[0013] The second mode: the correspondence between the identifier of the first digital key and the update token is stored in the vehicle authentication device. When the first digital key is verified, the vehicle authentication device can determine the update token corresponding to the first digital key according to the identifier of the first digital key and the stored correspondence.
[0014] When the vehicle terminal starts the application program, the vehicle authentication device can send the identifier of the first digital key to the vehicle terminal, so that the vehicle terminal can obtain the update token corresponding to the first digital key according to the correspondence stored in the vehicle authentication device.
[0015] The third mode: the correspondence between the identifier of the first digital key and the update token is stored in the vehicle authentication device, and the correspondence is also stored in the vehicle terminal. When the first digital key is verified, the vehicle authentication device can determine the update token corresponding to the first digital key according to the identifier of the first digital key and the stored correspondence.
[0016] When the vehicle terminal starts the application, the vehicle terminal can send the identification of the first digital key to the vehicle terminal, so that the vehicle terminal can obtain the update token corresponding to the first digital key according to the correspondence stored in the vehicle terminal.
[0017] It should be understood that the first mode and the second / third mode can be used in combination.
[0018] In a possible implementation, when the first digital key of the vehicle is verified and the vehicle terminal starts the application, if the vehicle terminal does not obtain the update token corresponding to the first digital key, a second interface is displayed, and the second interface displays an authorization binding control, which indicates that the digital key of the mobile terminal and the user account are bound.
[0019] In the embodiments of the present application, in the case that the first digital key and the first user account are not bound, a second interface for binding the digital key and the user account can also be provided to instruct the user to perform the binding operation of the first digital key and the first user account, so that the vehicle terminal can be directly logged in when the first digital key is verified the next time the vehicle terminal logs in the first user account, thereby reducing the login time.
[0020] It should be understood that the Device Flow / Grant process provided based on the OAuth2.0 protocol in the embodiments of the present application realizes the binding of the first user account and the first digital key. If the vehicle terminal receives the selection indication of the authorization binding control by the user, the identification of the vehicle terminal is pushed to the first mobile terminal, so that the first mobile terminal sends the identification of the vehicle terminal to the authorization server, so that the authorization server verifies the authorization of the user of the first mobile terminal. During the verification of the authorization of the user of the first mobile terminal by the authorization server, the vehicle terminal sends an authorization result query request to the authorization server at regular intervals, and after the authorization of the user of the first mobile terminal is verified by the authorization server, the vehicle terminal can be sent response information, which indicates that the authorization of the user of the first mobile terminal is verified. It should be understood that the identification of the vehicle terminal is the user code of the vehicle terminal, or the identification of the vehicle terminal includes the user code and a verification uniform resource identifier.
[0021] After the authorization of the user of the first mobile terminal is verified by the authorization server, the authorization server can also send the response information to the account server associated with the authorization server, so that the account server sends the access token and the update token to the vehicle terminal. The vehicle terminal uses the access token to access the account server, and displays the first interface. The vehicle terminal can store the correspondence between the identification of the first digital key and the update token.
[0022] Optionally, when the account server sends the update token, the first mobile terminal can be sent the new update token; or the vehicle-end authentication device can be sent the new update token to obtain the three storage modes of the update token.
[0023] Optionally, in addition to the above-mentioned mode of binding the first digital key and the first user account to obtain the update token, the vehicle terminal can receive the update token from the account server when the first digital key is opened on the vehicle terminal or the vehicle-end authentication device; or the vehicle terminal can receive the update token from the account server when the first digital key is obtained by negotiation with the first mobile terminal and the first digital key is recorded on the vehicle terminal or the vehicle-end authentication device.
[0024] In a possible implementation, when the vehicle terminal receives the access token from the account server, it also receives a new update token from the account server, and the new update token is the update token corresponding to the first digital key. When the vehicle terminal is powered off, the vehicle terminal exits the application program and deletes the access token; when the vehicle terminal starts the application program next time, the new update token is sent to the account server.
[0025] In this mode, the update token is valid only once, that is, after the update token is used, a new update token needs to be used to log in to the first user account, so as to avoid the problem that the vehicle terminal continues to log in to the first user account when the user leaves the vehicle with the first mobile terminal.
[0026] It should be understood that the account server can send the new update token to the vehicle terminal, the vehicle-end authentication device, or the first mobile terminal, or send the new update token to the vehicle-end authentication device or the first mobile terminal through the vehicle terminal, so as to obtain the three storage modes of the update token. Correspondingly, the vehicle terminal can send the new update token to the first mobile terminal; or the vehicle terminal can send the new update token to the vehicle-end authentication device; or the vehicle terminal can generate the correspondence between the identifier of the first digital key and the new update token according to the new update token; and the vehicle terminal can store the correspondence between the identifier of the first digital key and the new update token.
[0027] In a possible implementation, if the vehicle-mounted terminal receives an indication of selection of the switching control by the user, a third interface is displayed, and the third interface displays an identifier of a second mobile terminal; if the vehicle-mounted terminal receives an indication of selection of the identifier of the second mobile terminal by the user and the vehicle-mounted terminal acquires an update token corresponding to a second digital key, the vehicle-mounted terminal sends the update token corresponding to the second digital key to the account server, and the second digital key is a digital key corresponding to the second mobile terminal and the vehicle.
[0028] In this way, the user can switch the user account logged in on the vehicle-mounted terminal, so that the user can obtain information of the user account that needs to be viewed on the vehicle-mounted terminal, and user experience is improved.
[0029] In a second aspect, an embodiment of the present application provides a login method, including: a vehicle-side authentication device verifying a first digital key of a vehicle, the first digital key being used to represent that a first mobile terminal has a permission to control the vehicle; if the first digital key is verified and the vehicle-side authentication device acquires an identifier of the first digital key or an update token corresponding to the first digital key, when an application program is started on a vehicle-mounted terminal, the vehicle-side authentication device sends the identifier of the first digital key or the update token to the vehicle-mounted terminal, and the update token is used to indicate a first user account, and the first user account is a user account logged in on the first mobile terminal and the application program.
[0030] In a possible implementation, the vehicle-side authentication device reads the update token in the first mobile terminal; or, the vehicle-side authentication device acquires the update token corresponding to the first digital key according to the identifier of the first digital key and a correspondence relationship between the identifier of the first digital key and the update token.
[0031] In a possible implementation, the correspondence relationship is stored in a secure storage area in the vehicle-mounted terminal or a secure storage area in the vehicle-side authentication device, and the vehicle-side authentication device acquires the update token corresponding to the first digital key according to the identifier of the first digital key and the correspondence relationship between the identifier of the first digital key and the update token, including: the vehicle-side authentication device acquires the update token corresponding to the first digital key according to the identifier of the first digital key and the correspondence relationship between the identifier of the first digital key and the update token stored in the secure storage area in the vehicle-side authentication device.
[0032] In a possible implementation, after the vehicle-end authentication device sends the identification of the first digital key or the update token to the vehicle-mounted terminal, the vehicle-end authentication device further receives a new update token from the vehicle-mounted terminal, the new update token being an update token corresponding to the first digital key; or the vehicle-end authentication device receives the new update token from the account server.
[0033] In a possible implementation, the vehicle-end authentication device sends the new update token to the first mobile terminal; the vehicle-end authentication device generates a correspondence between the identification of the first digital key and the new update token according to the new update token; and the vehicle-end authentication device stores the correspondence between the identification of the first digital key and the new update token.
[0034] In a possible implementation, the vehicle-end authentication device receives the update token from the account server when the vehicle-end authentication device or the vehicle-end authentication device opens the first digital key; or the vehicle-end authentication device receives the update token from the account server when the vehicle-mounted terminal or the vehicle-end authentication device negotiates the first digital key with the first mobile terminal.
[0035] It should be understood that the login method of the first aspect and the second aspect in the embodiments of the present application can also be executed by an electronic device in which a vehicle-mounted terminal and a vehicle-end authentication device are integrated, for executing the login method of the first aspect and the second aspect in the above embodiments. It should be noted that in this scenario, the interaction process between the vehicle-mounted terminal and the vehicle-end authentication device can be omitted.
[0036] The implementation principle and technical effects of the login method provided by the second aspect can be specifically referred to the related descriptions of the first aspect and the possible implementations, which will not be repeated here.
[0037] In a third aspect, the embodiments of the present application provide a login method, which includes: an account server receiving an update token from a vehicle-mounted terminal, the update token being sent by the vehicle-mounted terminal when starting an application program, the update token being used to indicate a first user account, the first user account being a user account of the application program logged in on a first mobile terminal; the account server sending an access token to the vehicle-mounted terminal according to a correspondence between the update token and the first user account, the access token being related to the first user account, the access token being used to represent that the vehicle-mounted terminal has a permission to access data of the application program under the first user account; the account server receiving the access token from the vehicle-mounted terminal; and the account server sending the data of the application program under the first user account to the vehicle-mounted terminal.
[0038] In one possible implementation, the method further includes: when the account service sends an access token to the vehicle terminal, it also sends a new update token to the vehicle terminal, the new update token being an update token corresponding to the first digital key; or, the account server sends the new update token to a vehicle authentication device, the vehicle authentication device being used to verify the first digital key; or, the account server sends the new update token to a first mobile terminal.
[0039] In one possible implementation, the method further includes: if the account server determines that the user authorization of the first mobile terminal has been verified, then sending the access token and the update token to the vehicle terminal.
[0040] In one possible implementation, the account server determines that the user authorization of the first mobile terminal has been verified by: if the account server receives a response information from the authorization server, then it determines that the user authorization of the first mobile terminal has been verified, wherein the response information indicates that the user authorization of the first mobile terminal has been verified, and the authorization server is used to verify the user authorization of the first mobile terminal.
[0041] In one possible implementation, the method further includes: if the account server determines that the user authorization of the first mobile terminal has been verified, then generating the update token corresponding to the first user account and obtaining the correspondence between the update token and the first user account; or, when the in-vehicle terminal or vehicle authentication device activates the first digital key, the account server generates the update token corresponding to the first user account and obtains the correspondence between the update token and the first user account; or, when the in-vehicle terminal or vehicle authentication device negotiates with the first mobile terminal to obtain the first digital key, the account server generates the update token corresponding to the first user account and obtains the correspondence between the update token and the first user account.
[0042] The implementation principle and technical effects of the login method provided in this third aspect can be found in the description of the first aspect and the various possible implementation methods mentioned above, and will not be elaborated here.
[0043] Fourthly, this application provides a login device, including: a transceiver module, used to send the update token to an account server when the vehicle terminal starts an application, if the vehicle terminal obtains an update token corresponding to a first digital key, wherein the first digital key is used to indicate that the first mobile terminal has the authority to control the vehicle to which the vehicle terminal belongs, and the update token is used to indicate a first user account, wherein the first user account is the user account that logs into the application on the first mobile terminal.
[0044] The transceiving module is further configured to receive an access token generated by the account server based on the update token, the access token being associated with the first user account, and the access token being used to indicate that the vehicle-mounted terminal has the permission to access data of the application program under the first user account.
[0045] The processing module is configured to access the account server using the access token.
[0046] The display module is configured to receive the data of the application program under the first user account from the account server, and display a first interface according to the data, the first interface being an interface after the vehicle-mounted terminal logs in the first user account.
[0047] In a possible implementation, the transceiving module is further configured to receive an identification of a first digital key sent by a vehicle-side authentication device, the vehicle-side authentication device being configured to verify the first digital key.
[0048] Correspondingly, the processing module is further configured to obtain the update token corresponding to the first digital key according to the identification of the first digital key and a correspondence between the identification of the first digital key and the update token.
[0049] In a possible implementation, the correspondence is stored in a secure storage area in the vehicle-mounted terminal, or the processing module is further configured to obtain the correspondence from a secure storage area of the vehicle-side authentication device.
[0050] In a possible implementation, the processing module is further configured to read the update token corresponding to the first digital key from a vehicle-side authentication device, the vehicle-side authentication device being configured to verify the first digital key. In a possible implementation, the display module is further configured to, when the first digital key of the vehicle is verified and the vehicle-mounted terminal starts the application program, display a second interface if the vehicle-mounted terminal does not obtain the update token corresponding to the first digital key, the second interface displaying an authorization binding control, the authorization binding control indicating that the digital key of the mobile terminal is bound to the user account.
[0051] Correspondingly, the processing module is further configured to, if the vehicle-mounted terminal receives an indication of selection of the authorization binding control by a user, push the identification of the vehicle-mounted terminal to the first mobile terminal.
[0052] The transceiving module is further configured to receive the access token and the update token from the account server, the access token and the update token being sent after the first mobile terminal is verified by the user authorization using the identifier of the vehicle terminal.
[0053] The processing module is further configured to enable the vehicle terminal to access the account server using the access token.
[0054] The display module is further configured to receive data of the first user account from the account server, and display the first interface according to the data.
[0055] Optionally, the identifier of the vehicle terminal is a user code of the vehicle terminal, or the identifier of the vehicle terminal comprises the user code and a verification uniform resource identifier.
[0056] In a possible implementation, the transceiving module is further configured to send an authorization result query request to the authorization server at a regular time, the authorization result query request being used to query a verification result of the authorization server on the user authorization of the first mobile terminal.
[0057] Correspondingly, the processing module is further configured to determine that the user authorization of the first mobile terminal is verified if response information from the authorization server is received, the response information indicating that the user authorization of the first mobile terminal is verified.
[0058] In a possible implementation, the processing module is further configured to delete the update token. Correspondingly, the transceiving module is configured to receive a new update token from the account server when receiving the access token from the account server, the new update token being an update token corresponding to the first digital key.
[0059] In a possible implementation, the transceiving module is further configured to send the new update token to the first mobile terminal, or send the new update token to a vehicle-terminal authentication device. Alternatively, the processing module is further configured to generate a correspondence between an identifier of the first digital key and the new update token according to the new update token, and the storage module is configured to store the correspondence between the identifier of the first digital key and the new update token.
[0060] In a possible implementation, the processing module is further configured to exit the application program when the vehicle terminal is powered off.
[0061] Correspondingly, the transceiving module is further configured to send the new update token to the account server when the application program is started next time.
[0062] In a possible implementation, the processing module is further configured to delete the access token.
[0063] In a possible implementation, the display module is further configured to display a third interface if the selection indication of the switching control by the user is received, and the identification of the second mobile terminal is displayed on the third interface.
[0064] Correspondingly, the transceiving module is further configured to send the update token corresponding to the second digital key to the account server if the selection indication of the identification of the second mobile terminal by the user is received, and the vehicle terminal obtains the update token corresponding to the second digital key, the second digital key being a digital key corresponding to the second mobile terminal and the vehicle, and the selection indication indicating that the first user account is switched to the user account of the application program logged on the second mobile terminal.
[0065] In a possible implementation, when the first digital key is opened by the vehicle terminal or the vehicle-side authentication device, the transceiving module is further configured to receive the update token from the account server; or, when the first digital key is negotiated by the vehicle terminal or the vehicle-side authentication device and the first mobile terminal, the transceiving module is further configured to receive the update token from the account server.
[0066] The implementation principle and technical effects of the login device provided by the fourth aspect are specifically referable to the related descriptions of the first aspect and the possible implementations, which are not described herein.
[0067] In the fifth aspect, the embodiments of the present application provide a login device, comprising: a processing module configured to verify a first digital key of a vehicle, the first digital key being used to indicate that a first mobile terminal has the permission to control the vehicle.
[0068] A transceiving module is configured to send the identification of the first digital key or the update token to the vehicle terminal when the application program is started by the vehicle terminal if the first digital key is verified and the identification of the first digital key or the update token corresponding to the first digital key is obtained, the update token being used to indicate a first user account, the first user account being a user account of the application program logged on the first mobile terminal.
[0069] In a possible implementation, the processing module is further configured to read the update token in the first mobile terminal; or, according to the identification of the first digital key and the correspondence between the identification of the first digital key and the update token, obtain the update token corresponding to the first digital key.
[0070] In a possible implementation, the correspondence is stored in a secure storage area in the vehicle terminal or a secure storage area in the vehicle-side authentication device.
[0071] The processing module is specifically configured to obtain an update token corresponding to the first digital key according to the identity of the first digital key and a correspondence between the identity of the first digital key and an update token stored in a secure storage area in the vehicle-side authentication device.
[0072] In a possible implementation, the transceiving module is further configured to receive a new update token from the vehicle terminal, the new update token being an update token corresponding to the first digital key, or receive the new update token from an account server.
[0073] In a possible implementation, the transceiving module is further configured to send, by the vehicle-side authentication device, the new update token to the first mobile terminal, or the processing module is further configured to generate a correspondence between the identity of the first digital key and the new update token according to the new update token. The storage module is configured to store the correspondence between the identity of the first digital key and the new update token.
[0074] In a possible implementation, when the vehicle-side authentication device or the vehicle-side authentication device opens the first digital key, the transceiving module is further configured to receive the update token from an account server, or when the vehicle terminal or the vehicle-side authentication device negotiates the first digital key with the first mobile terminal, the transceiving module is further configured to receive the update token from the account server.
[0075] The implementation principle and technical effects of the login apparatus provided in the fifth aspect are the same as those of the second aspect and the possible implementation manners, which will not be described here.
[0076] In a sixth aspect, an embodiment of the present application provides a login apparatus, which comprises a transceiving module configured to receive an update token from a vehicle terminal, the update token being sent by the vehicle terminal when starting an application program, and the update token being used to indicate a first user account, the first user account being a user account of a user who logs in the application program on a first mobile terminal.
[0077] The transceiving module is further configured to send, to the vehicle terminal, an access token according to a correspondence between the update token and the first user account, the access token being related to the first user account, and the access token being used to represent that the vehicle terminal has a permission to access data of the application program under the first user account.
[0078] The transceiving module is further configured to receive the access token from the vehicle terminal and send data of the application under the first user account to the vehicle terminal.
[0079] In a possible implementation, the transceiving module is further configured to, when sending the access token to the vehicle terminal, send a new update token to the vehicle terminal, the new update token being an update token corresponding to the first digital key; or send the new update token to a vehicle-side authentication device configured to verify the first digital key; or send the new update token to the first mobile terminal.
[0080] In a possible implementation, the transceiving module is further configured to, if the account server determines that the user of the first mobile terminal is authorized to pass the verification, send the access token and the update token to the vehicle terminal.
[0081] In a possible implementation, the processing module is further configured to, if receiving response information from an authorization server, determine that the user of the first mobile terminal is authorized to pass the verification, the response information indicating that the user of the first mobile terminal is authorized to pass the verification, the authorization server being configured to verify the authorization of the user of the first mobile terminal.
[0082] In a possible implementation, the processing module is further configured to, if determining that the user of the first mobile terminal is authorized to pass the verification, generate the update token corresponding to the first user account and obtain a correspondence between the update token and the first user account; or, when the first digital key is opened on the vehicle terminal or the vehicle-side authentication device, generate the update token corresponding to the first user account and obtain the correspondence between the update token and the first user account; or, when the first digital key is obtained by negotiation between the vehicle terminal or the vehicle-side authentication device and the first mobile terminal, generate the update token corresponding to the first user account and obtain the correspondence between the update token and the first user account.
[0083] The login apparatus provided in the sixth aspect has the implementation principle and technical effects as described above with reference to the third aspect and the possible implementation manners, which will not be described herein.
[0084] In the seventh aspect, an embodiment of the present application provides a chip, including a memory and a processor, the memory is configured to store a computer program, and the processor is configured to call and run the computer program from the memory, so that the device installed with the chip executes the method performed by the first aspect, the second aspect and the third aspect in the above method embodiment.
[0085] In an eighth aspect, an embodiment of the present application provides an electronic device, which comprises a computer program stored in the electronic device, and the computer program, when executed by the electronic device, implements the method performed by the first aspect, the second aspect, and the third aspect.
[0086] In a ninth aspect, an embodiment of the present application provides a computer readable storage medium, which stores a computer program or instructions, and when the computer program or instructions are executed, the method performed by the first aspect, the second aspect, and the third aspect is implemented.
[0087] In a tenth aspect, an embodiment of the present application provides a vehicle, which comprises the login device in the fourth aspect and the fifth aspect, to implement the login method in the first aspect and the second aspect.
[0088] The login method, the login device, the electronic device, and the storage medium provided by the embodiments of the present application can pre-establish the correspondence between the digital key and the update token, and the correspondence is specifically the correspondence between the identifier of the digital key and the update token. The server pre-establishes the correspondence between the update token and the user account. Then, when the digital key is used to open the door of the vehicle and the application program of the vehicle terminal is started, the vehicle terminal can obtain the access token corresponding to the user account according to the update token bound with the digital key, and then log in to the account server by using the access token. Therefore, the problem that the user needs to scan the two-dimensional code by using the mobile terminal every time the vehicle terminal logs in to the account server by using the user account can be avoided. The login method in the embodiments of the present application reduces the login time and improves the user experience. BRIEF DESCRIPTION OF DRAWINGS
[0089] Figure 1 Flowchart of a process in which a third-party application accesses a protected resource in the prior art;
[0090] Figure 2 Interface change diagram of a terminal device in which a third-party application accesses a protected resource in the prior art;
[0091] Figure 3 Flowchart of a process in which a first device is authorized to log in to a user account of a second device on the second device in the prior art;
[0092] Figure 4 Interface change diagram of a first device in the prior art;
[0093] Figure 5 Scenario diagram to which the login method provided by the embodiments of the present application is applicable;
[0094] Figure 6 Flowchart of an embodiment of the login method provided by the embodiments of the present application;
[0095] Figure 7A FIG. 2 is a flowchart illustrating another embodiment of a login method provided by the present application;
[0096] Figure 7B FIG. 2 is a flowchart illustrating another embodiment of a login method provided by the present application;
[0097] Figure 7C FIG. 2 is a flowchart illustrating another embodiment of a login method provided by the present application;
[0098] Figure 8 FIG. 2 is a flowchart illustrating another embodiment of a login method provided by the present application; Figure 1 ;
[0099] Figure 9 FIG. 2 is a flowchart illustrating another embodiment of a login method provided by the present application; Figure 2 ;
[0100] Figure 10 FIG. 2 is a flowchart illustrating another embodiment of a login method provided by the present application;
[0101] Figure 11 FIG. 2 is a flowchart illustrating another embodiment of a login method provided by the present application; Figure 3 ;
[0102] Figure 12 FIG. 2 is a flowchart illustrating another embodiment of a login method provided by the present application; Figure 4 ;
[0103] Figure 13 FIG. 2 is a flowchart illustrating another embodiment of a login method provided by the present application; Figure 1 ;
[0104] Figure 14 FIG. 2 is a flowchart illustrating another embodiment of a login method provided by the present application; Figure 2 ;
[0105] Figure 15 FIG. 2 is a flowchart illustrating another embodiment of a login method provided by the present application; Figure 3 ;
[0106] Figure 16 FIG. 2 is a flowchart illustrating another embodiment of a login method provided by the present application; DETAILED DESCRIPTION
[0107] In existing terminal device-server authentication processes, if a terminal device needs to access protected resources stored on a server (such as resources in application server 1, which stores resources for application 1), the server authenticates the terminal device using credentials provided by the terminal device, such as the user account and password of application 1. After successful authentication, the terminal device gains permission to access the protected resources corresponding to that account. If a third-party application (such as application 2) also needs to access the protected resources of application 1 on application server 1, in existing technologies, the terminal device can share the user account and password of application 1 with the third-party application to enable the third-party application to access the protected resources. However, sharing user accounts and passwords poses significant security risks. To address this issue, the OAuth 2.0 protocol was developed. The OAuth 2.0 protocol allows a third-party application to access protected resources on a server with the user's permission, without sharing the user account and password with the third-party application.
[0108] Figure 1 This is a schematic diagram illustrating the process of a third-party application accessing protected resources in existing technology. For example... Figure 1 As shown, the process by which a third-party application accesses protected resources may include:
[0109] S101, the terminal device displays the authorization login interface.
[0110] To more clearly illustrate the process of a third-party application (client) accessing protected resources, combined with Figure 2 Please provide an explanation. Figure 2 This diagram illustrates the interface changes on a terminal device for third-party applications accessing protected resources in existing technologies. For example, Figure 2 The third-party application in this context is a shopping application, and the protected resources are resources from other applications (such as social applications), such as the user's social application avatar and user ID. When the shopping application requests access to the social application's resources (i.e., when logging into the shopping application using the social application's user account), as shown in interface 201, which is the shopping application's login interface, this interface displays "Account, Password" input boxes and controls for logging in using the social application (such as the social application icon shown in interface 201).
[0111] The user can select the icon of the social application by clicking or other operation modes, and the interface 201 can jump to the interface 202. The interface 202 is an interface for authorizing the social application to log in the shopping application. The interface 202 can display the icon of the shopping application and the text prompt information “You can log in using the following personal information”, and can also display the user account of the social application that can be selected to log in the shopping application. In addition, the interface 202 can also display the “social application authorization login” control.
[0112] In S102, the terminal device receives the authorization permission input by the user.
[0113] For example, when the user (resource owner) selects the “social application authorization login” control displayed on the interface 202 by clicking or other operation modes, the authorization grant can be triggered. The authorization grant is used to represent that the user agrees to authorize the user account of the social application to log in the shopping application, that is, agrees to authorize the shopping application to access the protected resources in the social application. The protected resources in the social application can be the user's avatar, user identification, etc.
[0114] Corresponding to the above-mentioned interface 202, the interface of the terminal device can jump to the interface 203, and the interface 203 can display the interface of the user who is logging in the shopping application.
[0115] In S103, the terminal device sends the authorization permission to the authorization server.
[0116] It should be understood that during the process of displaying the above-mentioned interface 203 by the terminal device, that is, the process of executing S103-S106. Optionally, the authorization permission can include the identity information of the terminal device.
[0117] The authorization code is the most commonly used authorization permission. When the authorization code is used as the authorization permission, the authorization request can be initiated by the terminal device directly to the authorization server, and the authorization server can issue the authorization code to the terminal device after authenticating the identity information of the terminal device.
[0118] In S104, the authorization server sends the access token to the terminal device.
[0119] After the authorization server verifies the authorization permission submitted by the third-party application on the terminal device, the authorization server can send the access token to the terminal device. For example, the access token is used to represent the access permission of the shopping application to access the authorized resources of the social application.
[0120] S105, the terminal device sends an access token to the resource server.
[0121] S106, the resource server feeds back the protected resource to the terminal device.
[0122] The process that the terminal device sends the access token to the resource server is the process that the user account of the social application program is logged in the shopping application program. When the login is successful, the terminal device can access the protected resource 0, and the interface 203 can jump to the login interface after the user account of the social application program is logged in the shopping application program.
[0123] The above Figure 2 The above describes the scenario that the shopping application program obtains the authorization to log in the shopping application program by using the user account of the social application program. Similarly, after the terminal device logs in the shopping application program, the user can also request to authorize to access the resource of the user in the server of the social application program (such as the game record) in the open authorization mechanism, and then the shopping application program can recommend the information related to the game (such as the game card, the game peripheral product, etc.) according to the game record.
[0124] The above authorization server and the resource server can be the same or separate devices. In the following embodiments, the authorization server can be the same device as the resource server (account server or authorization server) is taken as an example for description.
[0125] It should be understood that the above terminal device can be a terminal, a user equipment (UE), a mobile station (MS), a mobile terminal (MT), etc. The terminal device can be a mobile phone, a pad, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc.
[0126] The OAuth2.0 protocol provides a process for a third-party application to securely access a protected resource. In addition, the OAuth2.0 protocol provides a Device Flow / Grant process that allows a user to authorize a first device to access resources on a second device. A typical use case is to authorize the first device to log in to a user account on the second device. For example, the first device can be a vehicle terminal with limited input capabilities, and the second device can be a mobile phone. In this case, the Device Flow / Grant process allows the mobile phone to authorize the vehicle terminal to log in to the user account (such as a system account or an application user account) on the mobile phone.
[0127] Figure 3 Figure 1 shows a process for authorizing a first device to log in to a user account on a second device in the prior art, i.e., a process for authorizing the first device to access resources corresponding to the user account on the second device. As shown in Figure 1, the process can include the following steps: Figure 3
[0128] S301, the first device sends an authorization request to the authorization server.
[0129] When a user needs to log in to the same user account on the first device as on the second device, the first device can send an authorization request to the authorization server. For example, in this embodiment, the authorization request is sent in conjunction with the OAuth2.0 protocol. Figure 4 The process for authorizing a first device to log in to a user account on a second device using an open authorization mechanism is described. Figure 4 Figure 2 shows a change in the interface of the first device in the prior art. As shown in Figure 2, the interface of the first device can display an "authorized login" control. When the first device receives a user selection instruction for the "authorized login" control, it sends an authorization request to the authorization server. Figure 4
[0130] The authorization request can include identification information of the first device. The identification information of the first device can be a device identifier, a media access control (MAC) address, an application unique identifier, or other identity information representing the first device.
[0131] S302, the authorization server sends an authorization response to the first device, and the authorization response includes a device code, a user code, and a verification uniform resource identifier.
[0132] After the authorization server receives the authorization request from the first device, the identity information of the first device is verified. After verification, the authorization response can be sent to the first device. The authorization response can include the device code, the user code and the verification uniform resource identifier (verification URI) of the first device.
[0133] The device code is used to identify the first device in this authorization process. The user code is passed from the first device to the second device and submitted to the server for verification, indicating that the user has confirmed the authorization of the first device that passed the user code. The verification uniform resource identifier is used to indicate the location of the authorization server to be accessed.
[0134] S303, the first device displays a two-dimensional code, and the two-dimensional code includes the user code and the verification uniform resource identifier.
[0135] In the prior art, the first device displays the two-dimensional code in the form of generating the two-dimensional code on the interface. The two-dimensional code contains the user code and the verification uniform resource identifier, so that the second device obtains the user code and the verification uniform resource identifier. Correspondingly, the above interface 401 can jump to interface 402, and the interface 402 displays the two-dimensional code.
[0136] S304, the first device submits the device code to the authorization server, and sends a query request to the authorization server at a regular time, and the query request is used to confirm the authorization result of the second device.
[0137] The first device can send a query request to the authorization server at a regular time to request the authorization result of the second device. When the authorization behavior of the user on the second device passes the verification, the authorization server can send an access token to the first device in response to the latest query request of the first device, and the access token is used to indicate that the first device has the permission to access the resources corresponding to the account of the first device in the resource server.
[0138] S305, the second device sends the verification uniform resource identifier and the user code to the authorization server.
[0139] The user can scan the two-dimensional code displayed on the first device through the second device, so that the second device obtains the user code and the verification uniform resource identifier.
[0140] After obtaining the user code and verifying the uniform resource identifier, the second device can send the verified uniform resource identifier and the user code to the authorization server. In this process, the authorization server verifies the authorization behavior of the user on the second device, specifically, after the second device account login and the user confirmation operation, it can be determined that the user authorizes the access permission of the first device corresponding to the user code to the resource.
[0141] Optionally, before the second device accesses the authorization server, the steps in S101-S102 described above can be performed. After the second device receives the authorization permission input by the user, the authorization server can be accessed to obtain the access token.
[0142] S306, the authorization server sends the access token to the first device.
[0143] After the verification of the authorization behavior of the user on the second device is passed, the authorization server can send the access token to the first device corresponding to the user code.
[0144] S307, the first device uses the access token to access the resource in the resource server.
[0145] The first device uses the access token to access the resource in the resource server, that is, the first device logs in the same user account as the second device and accesses the resource in the resource server. Correspondingly, the interface 402 described above can jump to the interface 403, which is the interface after logging in the same user account as the second device.
[0146] The above-mentioned Figure 3 corresponding process can be used to log in the same user account as the second device on the first device through the authorization login on the second device, so as to log in the same user account on different devices, realize information sharing, and improve user experience.
[0147] With the continuous integration of information technology, the Internet and the automobile industry, automobile networking and intelligentization have become an inevitable trend of the development of the automobile industry. In real life, users can connect smart home, smart wear, mobile office and related services through the user account on the smart phone.
[0148] At this time, after the vehicle terminal is connected with the Internet of things (IoT) cloud server by logging in the user account, the driver and the user's home audio can make a phone call, the real-time scenery outside the car can be shared to the TV at home, and the content shot by the camera at home can be displayed on the vehicle terminal, which greatly facilitates the user's life.
[0149] In the prior art, the above-mentioned Figure 3In the prior art, the same user account on the second device (smartphone) is logged in on the first device (vehicle terminal) in the same way, and the rapid login of the vehicle terminal is realized. For example, since the same user account as the smartphone is logged in on the vehicle terminal, the schedule information of the user account can be synchronized to the vehicle terminal, and the vehicle terminal can recommend navigation information, surrounding services, etc. to the user according to the schedule information, thereby improving the intelligence and user experience of the vehicle terminal.
[0150] It should be noted that in the prior art, when the same user account on the vehicle terminal as the smartphone is logged in, the user needs to obtain the user code and the uniform resource identifier by scanning the two-dimensional code on the vehicle terminal through the smartphone, so as to perform the verification of the authorization server, and then the purpose of logging in the same user account on the first device on the second device can be realized (for details, see the description of S301-S307 above). In this case, every time the user logs in the user account of the smartphone on the vehicle terminal (i.e., logs in the same user account as the smartphone on the vehicle terminal), the user needs to open the App through the smartphone to scan the two-dimensional code on the vehicle terminal, which causes inconvenience to the user. Therefore, this problem needs to be solved.
[0151] In order to solve the problem in the prior art that the user needs to scan the two-dimensional code through the smartphone every time the user logs in the user account on the vehicle terminal, a digital vehicle key (also referred to as a digital key, hereinafter referred to as a digital key) is introduced in the present application. Since the digital key has uniqueness, and the digital key will be authenticated during the vehicle opening stage. Therefore, in the embodiments of the present application, the association between the user account and the digital key is established, and when the vehicle is opened, it is known which user account to log in, i.e., to log in the user account, so as to avoid the problem of needing to actively scan the two-dimensional code to log in the user account.
[0152] The digital key, as well as the verification and generation process of the digital key, will be described below.
[0153] The digital key can realize the functions of opening the door, closing the door and starting the engine of the traditional car key through the mobile terminal (such as a mobile phone, a wearable device, etc.) of the user. Taking the mobile terminal as a mobile phone as an example, in the scenario of opening the door, the vehicle-side authentication device in the vehicle sends a verification request of the digital key to the mobile phone, the mobile phone generates authentication ciphertext by using the key stored in the secure environment and returns the authentication ciphertext to the vehicle-side authentication device, and after the vehicle-side authentication device and the mobile phone pass the one-way or two-way authentication, the opening operation is performed. Alternatively, when the vehicle-side authentication device further detects that the distance between the mobile phone is within a preset distance range, and after the digital key authentication passes, it is determined to perform the opening operation. In the above two ways, the mobile phone and the vehicle-side authentication device have established a Bluetooth connection or a UWB connection in advance. Alternatively, when the user opens the door, the mobile phone can be placed in the NFC card swiping area, and the vehicle-side authentication device performs authentication on the digital key in the form of NFC communication, and after the authentication passes, it is determined to perform the opening operation. The vehicle-side authentication device can interact with the vehicle control system (such as a system that realizes the operations of opening the door, closing the door, starting the engine, etc.) to realize the control of the vehicle.
[0154] The opening of the digital key can be a process in which the user requests the service server to generate the digital key through the application program installed on the mobile phone, and then the digital key is sent to the secure environment of the mobile phone. Alternatively, the digital key can also be generated by the mobile phone and the vehicle-side authentication device according to the pre-defined negotiation rules, and the generated digital key is sent to the service server for filing, so that the service server can determine and store the digital key corresponding to the mobile phone and the vehicle-side authentication device before use.
[0155] Among them, Figure 5 The login method provided by the embodiments of the present application is applicable to the scenario as shown in Figure 5 The scenario can include a mobile terminal and a vehicle. It should be understood that the mobile terminal in the embodiments of the present application can be a smart phone, a notebook computer, a wearable device (such as a smart bracelet, a smart watch, etc.). The vehicle can include a vehicle-side authentication device and a vehicle terminal. It should be understood that the vehicle-side authentication device is the device for verifying the digital key as described above, and the vehicle terminal can be an in-vehicle infotainment (IVI). It should be understood that the vehicle-side authentication device and the vehicle terminal in the following embodiments are taken as separate devices as an example for description, and the vehicle-side authentication device and the vehicle terminal can also be integrated into one device to perform the actions performed by the vehicle-side authentication device and the vehicle terminal in the embodiments of the present application.
[0156] The login method provided by the embodiments of the present application will be described below in combination with specific embodiments. The following embodiments can be combined with each other, and the same or similar concepts or processes can not be described in detail in some embodiments.
[0157] Embodiment one
[0158] Figure 6 The flowchart of an embodiment of the login method provided by the embodiments of the present application is shown. As shown in the flowchart, the login method provided by the embodiments of the present application can include the following steps. Figure 6
[0159] S601, the vehicle-side authentication device verifies the first digital key of the vehicle, the first digital key being associated with a first user account, the first user account being a user account of a first mobile terminal logging into an application program.
[0160] S602, the vehicle-side authentication device obtains an identifier of the first digital key or an update token corresponding to the first digital key, the update token being used to indicate the first user account.
[0161] S603, if the first digital key is verified, when the application program is started on the vehicle terminal, the vehicle terminal reads the identifier of the first digital key or the update token from the vehicle-side authentication device.
[0162] S604, the vehicle terminal obtains the update token corresponding to the first digital key according to the identifier of the first digital key, and sends the update token or the update token read from the vehicle-side authentication device to the account server.
[0163] S605, the account server sends an access token and a new update token to the vehicle terminal, the access token being related to the first user account, and the access token being used to indicate that the vehicle terminal has the right to access the data of the application program under the first user account.
[0164] S606, the vehicle terminal writes the new update token into a storage area of the digital key of the first mobile terminal, a storage area of the vehicle terminal, or a storage area of the vehicle-side authentication device.
[0165] S607, the vehicle terminal accesses the account server using the access token.
[0166] S608, the vehicle terminal receives the data of the application program under the first user account from the account server, and displays a first interface according to the data, the first interface being an interface after the vehicle terminal logs into the first user account.
[0167] In the above S601, the digital key for opening the door of the vehicle can be at least one, and the vehicle-side authentication device can verify at least one digital key, and the first digital key in the embodiments of the present application is a digital key in the at least one digital key. The first digital key is associated with the first user account, and the first user account is a user account of a first mobile terminal logging into an application program. It should be understood that the first mobile terminal can be one or more, and the user account of the first mobile terminal logging into the application program is the first user account.
[0168] Optionally, the first digital key can be a digital key corresponding to the vehicle to which the first mobile terminal and the vehicle-side authentication device belong, that is, the first digital key of the first mobile terminal can realize the control (such as the opening of the vehicle door described above) of the vehicle corresponding to the vehicle-side authentication device, that is, the first digital key is used to represent that the first mobile terminal has the permission to control the vehicle.
[0169] In the embodiment of the application, in the scenario of opening the vehicle door through the first digital key, the vehicle-side authentication device can verify the first digital key of the first mobile terminal when it detects that the first mobile terminal is within a preset distance range. Alternatively, when the user initiates an instruction to open the vehicle door on the control interface of the first mobile terminal, the vehicle-side authentication device verifies the first digital key. Alternatively, when the user needs to open the door, the first mobile terminal can be placed in the NFC card swiping area so that the vehicle-side authentication device verifies the first digital key. The verification method of the first digital key by the vehicle-side authentication device can refer to the related description of the digital key described above.
[0170] Notably, if the verification of the first digital key is performed when the vehicle-side authentication device detects that the first mobile terminal is within a preset distance range, and there are multiple mobile terminals corresponding to digital keys within the preset distance range, the mobile terminal with the highest priority can be used as the first mobile terminal, and the digital key of the first mobile terminal with the highest priority can be used as the first digital key. Optionally, the priority of the mobile terminal can be pre-stored in the vehicle-side authentication device and correspond to the corresponding digital key. It should be understood that the first mobile terminal with the highest priority can be the mobile terminal corresponding to the primary driver, and the primary driver can be the owner of the vehicle. Alternatively, the first mobile terminal with the highest priority can also be the mobile terminal closest to the primary driving position.
[0171] In S602 described above, the vehicle-side authentication device can obtain the identifier of the first digital key or the refresh token corresponding to the first digital key in the process of verifying the first digital key. The following three possible implementation manners are described below to explain the case where the vehicle-side authentication device obtains the identifier of the first digital key or the refresh token corresponding to the first digital key:
[0172] The first way: the first mobile terminal stores the refresh token corresponding to the first digital key. Specifically, the refresh token is stored in the storage area of the digital key of the first mobile terminal. The storage area of the digital key in the first mobile terminal can be the storage area of the first digital key in the key applet installed in the first mobile terminal.
[0173] In this way, the vehicle-end authentication device can read the update token in the storage area of the digital key of the first mobile terminal in the process of verifying the first digital key, and then store the update token in the storage area in the vehicle-end authentication device. The storage area in the vehicle-end authentication device can be a storage area in a vehicle lock applet of the vehicle-end authentication device. The first way can be as shown in Figure 7A Figure 7A A flowchart of another embodiment of the login method provided by the embodiments of the present application is shown.
[0174] Correspondingly, S602 can be replaced by S701: the vehicle-end authentication device obtains the update token corresponding to the first digital key from the first mobile terminal.
[0175] The second way: the vehicle-end authentication device stores the update token corresponding to the first digital key. It should be understood that the vehicle-end authentication device can store update tokens corresponding to multiple digital keys respectively.
[0176] In this way, the vehicle-end authentication device can obtain the update token corresponding to the first digital key in the storage area of the vehicle-end authentication device. The second way can be as shown in Figure 7B Figure 7B A flowchart of another embodiment of the login method provided by the embodiments of the present application is shown.
[0177] Correspondingly, S602 can be replaced by S701': the vehicle-end authentication device obtains the identifier of the first digital key, and obtains the update token corresponding to the first digital key according to the identifier of the first digital key. It should be understood that the vehicle-end authentication device can store a correspondence between the identifier of the first digital key and the update token, and the vehicle-end authentication device can obtain the update token corresponding to the first digital key according to the identifier of the first digital key and the correspondence, i.e., the update token corresponding to the identifier of the first digital key in the correspondence.
[0178] The third way: the vehicle-end authentication device stores the update token corresponding to the first digital key. It should be understood that, similar to the vehicle-end authentication device, the vehicle-end authentication device can store update tokens corresponding to multiple digital keys respectively. It should be understood that the specific way in which the vehicle-end authentication device stores the update token corresponding to the first digital key can be that the vehicle-end authentication device stores a correspondence between the identifier of the first digital key and the update token, to represent the update token corresponding to the first digital key.
[0179] In this way, because the vehicle terminal has not started up, the vehicle-end authentication device cannot determine whether the updated token corresponding to the first digital key is stored in the vehicle, and thus the identifier of the first digital key can be acquired. When the vehicle terminal starts the application, the vehicle terminal acquires the identifier of the first digital key from the vehicle-end authentication device, and then acquires the updated token corresponding to the first digital key according to the identifier of the first digital key and the updated token corresponding to each digital key stored in the vehicle terminal. The third way can be as shown in Figure 7C Figure 7C A flowchart of another embodiment of the login method provided by the embodiments of the present application is shown.
[0180] Correspondingly, S602 can be replaced by S701: the vehicle-end authentication device acquires the identifier of the first digital key.
[0181] It should be understood that whether the updated token is stored in the storage area of the digital key of the first mobile terminal or in the storage area of the vehicle terminal or the vehicle-end authentication device can be predetermined. The updated token can be issued to the first mobile terminal, the vehicle-end authentication device or the vehicle terminal by the account server after the account server establishes the correspondence between the first user account and the updated token, and the updated token is used to indicate the first user account.
[0182] In the embodiments of the present application, the first possible implementation manner of the account server issuing the updated token can be that the account server issues the updated token in the process of binding the first digital key and the first user account by the user. In this process, the account server can establish the correspondence between the first user account and the updated token. The process of binding the first digital key and the first user account can be specifically described with reference to the related description in Embodiment 2 below.
[0183] Alternatively, the second possible implementation manner of the account server issuing the updated token can be that when the first digital key is opened, the business server generates the first digital key, the account server associated with the business server can generate the updated token corresponding to the first digital key, and issue the updated token.
[0184] Alternatively, the third possible implementation manner of the account server issuing the update token can be that: the first mobile terminal and the vehicle-side authentication device / vehicle terminal generate the first digital key according to the pre-defined negotiation rule, and record (i.e., send the first digital key related information such as the public key, the key identifier, etc. to the service server) with the service server, and the service server instructs the account server to generate the update token corresponding to the first user account, and issues the update token. In the second and third possible implementation manners, since the first mobile terminal needs to log in the first user account in the process of opening the digital key and recording, the account server can establish the corresponding relationship between the update token and the first user account of the first mobile terminal.
[0185] Wherein, the account server can issue the update token to the vehicle terminal or the first mobile terminal after establishing the corresponding relationship between the first user account and the update token. The vehicle terminal can write the update token into the storage area of the digital key of the first mobile terminal, or write into the storage area of the vehicle-side authentication device or the vehicle terminal after receiving the update token.
[0186] Alternatively, the account server can directly write the update token into the storage area of the digital key of the first mobile terminal after storing the corresponding relationship between the first user account and the update token. It should be noted that when the vehicle terminal or the account server writes the update token into the secure storage area of the first mobile terminal, it can be written through a secure channel to ensure the security of the update token.
[0187] Optionally, in the embodiment of the application, the first mobile terminal can perform digital signature or HMAC operation on the update token when sending the update token to the vehicle terminal, to prove the reliability of the source of the token. And the update token can also be encrypted and transmitted by negotiating a secure channel.
[0188] In the above S603, if the first digital key verification is passed, and the vehicle terminal starts the application program, the vehicle terminal extracts the identifier of the first digital key or the update token from the vehicle-side authentication device.
[0189] Corresponding to the above three ways, in the first and second ways, the vehicle terminal can read the update token corresponding to the first digital key from the vehicle-side authentication device when starting the application program. Wherein, corresponding to the above, in the first and second ways, the above S603 can be replaced by S702 or S702': if the first digital key verification is passed, and the vehicle terminal starts the application program, the vehicle terminal extracts the update token from the vehicle-side authentication device.
[0190] In the third mode, the vehicle terminal can read the identification of the first digital key from the vehicle-end authentication device when the application is started, to obtain the update token corresponding to the first digital key. The S603 can be replaced by S702: if the first digital key is verified and the vehicle terminal starts the application, the vehicle terminal extracts the identification of the first digital key from the vehicle-end authentication device. It should be understood that the vehicle terminal can store the correspondence between the identification of the first digital key and the update token, and the vehicle terminal can obtain the update token corresponding to the first digital key according to the identification of the first digital key and the correspondence, i.e. the update token corresponding to the identification of the first digital key in the correspondence.
[0191] Optionally, if the first digital key is verified, the vehicle-end authentication device can set the identification of the first digital key or the update token corresponding to the first digital key to a readable state, and the vehicle terminal can read the identification of the first digital key or the update token corresponding to the first digital key from the vehicle-end authentication device when the application is started. Alternatively, when the vehicle terminal starts the application, the vehicle-end authentication device can send a read credential to the vehicle terminal, so that the vehicle terminal reads the identification of the first digital key or the update token corresponding to the first digital key using the read credential.
[0192] In the S604, the vehicle terminal can directly read the update token from the vehicle-end authentication device, or read the identification of the first digital key from the vehicle-end authentication device, and then obtain the update token corresponding to the first digital key according to the identification of the first digital key.
[0193] Corresponding to the above, in the first mode and the second mode, the S604 can be replaced by S703 or S703': the vehicle terminal sends the update token to the account server. In the third mode, the S604 can be replaced by S703": the vehicle terminal obtains the update token corresponding to the first digital key according to the identification of the first digital key, and sends the update token to the account server.
[0194] Correspondingly, whether the vehicle terminal reads the update token from the vehicle-end authentication device or obtains the update token corresponding to the first digital key according to the identification of the first digital key, after the vehicle terminal obtains the update token, the vehicle terminal sends the obtained update token to the account server.
[0195] The action of starting the application by the vehicle terminal can be performed when the first digital key is verified and the vehicle terminal is powered on. Alternatively, the action of starting the application by the vehicle terminal can also be performed when the vehicle terminal displays an interface of "whether to log in the application using the user account" and the user determines to log in the application using the user account.
[0196] Correspondingly, the vehicle-mounted terminal receives the access token and the new update token from the account server in S605.
[0197] After receiving the update token from the vehicle-mounted terminal, the account server can determine the first user account corresponding to the update token according to the update token, and generate an access token and a new update token corresponding to the first user account. It should be understood that the access token and the update token in the embodiments of the present application are one-time tokens, and the access token and the update token are invalid after the vehicle-mounted terminal submits and verifies them to the account server. The access token is used to represent that the vehicle-mounted terminal has the right to access the data of the application under the first user account.
[0198] The purpose of regarding the access token and the update token as one-time in the embodiments of the present application is that the embodiments of the present application establish the binding relationship between the first digital key for opening the door and the first user account on the mobile terminal where the first digital key exists, so the first user account corresponding to the first digital key verified this time should be logged in each time. If the user account of the vehicle owner is always logged in, it will bring great risk to the security of the user account and the privacy of the vehicle owner.
[0199] It should be understood that the account server is a server corresponding to the first user account.
[0200] In S606, after obtaining the new update token, the vehicle-mounted terminal can interact with the first mobile terminal, delete or overwrite the update token in the storage area of the digital key of the first mobile terminal, and write the new update token into the storage area. Alternatively, the vehicle-mounted terminal can delete the update token stored in the storage area of the vehicle-mounted terminal or the storage area of the vehicle-end authentication device and write the new update token into the corresponding storage area.
[0201] Corresponding to the above, as shown in Figure 7A In the first mode, S606 can be replaced by S704: the vehicle-mounted terminal writes the new update token into the storage area of the digital key of the first mobile terminal.
[0202] As shown in Figure 7B In the second mode, S606 can be replaced by S704': the vehicle-mounted terminal writes the new update token into the storage area of the vehicle-end authentication device.
[0203] As shown in Figure 7C In the third mode, S606 can be replaced by S704": the vehicle-mounted terminal writes the new update token into the storage area of the vehicle-mounted terminal.
[0204] The vehicle terminal can use the access token to access the account server. The vehicle terminal can send the access token to the account server, and the account server feeds back a login response to the vehicle terminal based on the access token. The login response is used to indicate that the vehicle terminal logs in the account server using the first user account associated with the access token and accesses resources corresponding to the first account. It should be understood that the account server can store the access token, the new update token and the first user account after generating the access token and the new update token, so as to feed back the login response when receiving the access token sent by the vehicle terminal.
[0205] Optionally, after the account server feeds back the login response to the vehicle terminal, the account server can mark the access token as invalid. The vehicle terminal can delete the access token when the vehicle terminal is turned off, or the vehicle terminal deletes the access token after sending the access token to the account server.
[0206] It should be understood that there is no order between writing the new update token by the vehicle terminal and using the access token to access the account server, and they can be executed simultaneously or separately.
[0207] In the above S607, the vehicle terminal can use the access token to access the account server, that is, the vehicle terminal sends the access token to the account server.
[0208] In the above S608, after the account server ends the access token from the vehicle terminal, the account server can send data of an application under the first user account associated with the access token to the vehicle terminal.
[0209] Correspondingly, the vehicle terminal can receive the data of the application under the first user account from the account server, and display a first interface according to the data of the application under the first user account. The first interface is an interface after the vehicle terminal logs in the first user account. Compared with the above Figure 4 Compared with the above, in the login method provided in the embodiments of the present application, the user does not need to log in the account server by scanning the two-dimensional code through the mobile terminal, but directly logs in the account server through the standard OAuth authorization login process according to the update token of the first user account bound with the first digital key for opening the door, which reduces the operation complexity of the user logging in the account and improves the user experience.
[0210] Exemplarily, Figure 8 Interface change of the vehicle terminal provided in the embodiments of the present application Figure 1 As Figure 8The interface 801 shown in FIG. 8 is a first interface. Taking the first user account as an example, the system account is described. The first interface can display the system application program after the first user account is logged in. In order to remind the user of the currently logged-in first user account, the first interface can also display the identification information of the first user account, such as "User 1".
[0211] For example, if the first user account has schedule information and express information, the interface 801 can jump to the interface 802, and the interface 802 can display the specific information of the incoming call schedule information and express information. It should be understood that the interface 802 is only an example, and the vehicle terminal can also display the navigation, movie, scenic spot, restaurant, maintenance, take-out, refueling, hotel, parking, etc. information of the first user account.
[0212] Optionally, in the embodiment of the application, the vehicle terminal can push information after obtaining the first user account. For example, after the vehicle terminal obtains the schedule information, it can push the weather, route, etc. information of the day of the trip to improve the user experience. For example, the interface 802 can jump to the interface 803.
[0213] Optionally, in the embodiment of the application, if the first digital key verification is passed, the interface 804 (the interface of the vehicle terminal that has not logged in the first user account) can be displayed before the vehicle terminal logs in the application, that is, before the interface 801. Figure 8 As shown in the interface 804, the interface 804 can be the same as the interface 801, except that no "User 1" is displayed in the interface 804 because the user account is not used for login.
[0214] In one possible implementation, the first interface can display a switching control or set a switching control in the "Settings" menu. The switching control is used to instruct the vehicle terminal to switch from the first user account to the second user account. The second user account can be the user account logged in the application on the second mobile terminal. The digital key corresponding to the vehicle in the second mobile terminal is a second digital key. The second digital key is a digital key in the at least one digital key stored in the vehicle-side authentication device except the first digital key. Correspondingly, the second digital key is used to represent that the second mobile terminal has the right to control the vehicle. Optionally, the second mobile terminal can be the same as the first mobile terminal.
[0215] Figure 9 Interface change of the vehicle terminal provided by the embodiment of the application Figure 2 . Figure 9 The first interface displays a switching control as an example. For example, Figure 9The interface 901 is shown in FIG. 9. Compared with the interface 801, the interface 901 further displays a switching control. If the vehicle-mounted terminal receives a selection instruction of the switching control input by the user, a third interface is displayed. Correspondingly, the interface 901 jumps to the interface 902, and the interface 902 displays controls of the second mobile terminal, such as "mobile terminal 2" and "mobile terminal 3". It should be understood that different mobile terminals can correspond to different user accounts.
[0216] If the vehicle-mounted terminal receives a selection instruction of the control of the second mobile terminal input by the user, the actions in S601 are performed, and if the vehicle-mounted terminal successfully extracts the update token corresponding to the second digital key, the actions in S606-S608 are performed. Correspondingly, the interface 902 jumps to the interface 903. The interface 903 is different from the interface 801 in that the interface 903 displays identification information of the second user account, such as "user 2" or related services.
[0217] It should be noted that if the vehicle-end authentication device does not detect that the update token is stored in the storage area of the digital key of the second mobile terminal, or does not detect that the update token is stored in the storage area of the vehicle-end authentication device, the actions in S1001-S1006 in Embodiment II are performed.
[0218] In the embodiments of the present application, the correspondence between the digital key and the update token can be established in advance, the server establishes the correspondence between the update token and the user account in advance, and then when the digital key is used to open the door and the application program of the vehicle-mounted terminal is started, the vehicle-mounted terminal can obtain the access token corresponding to the user account according to the update token bound to the digital key, and then log in to the account server using the access token, thereby avoiding the problem that the user needs to scan the two-dimensional code through the mobile terminal every time the vehicle-mounted terminal logs in to the account server using the user account. The login method in the embodiments of the present application reduces the login time and improves the user experience.
[0219] Embodiment II
[0220] On the basis of the above-mentioned embodiments, when the vehicle-end authentication device does not read the update token in the storage area of the digital key of the mobile terminal (the first mobile terminal or the second mobile terminal), or does not detect that the update token is stored in the storage area of the vehicle-end authentication device, the steps in Figure 10 may be triggered, or when the user needs to bind the digital key of the mobile terminal to the user account, the steps in Figure 10 may be triggered. After the digital key of the mobile terminal is bound to the user account according to the steps in Figure 10 , the steps of automatically logging in to the account corresponding to the digital key in the above-mentioned embodiments can be performed.
[0221] The following will be described in combination withFigure 10 The login method provided in the embodiment of the present application is described. Figure 10 The flowchart of another embodiment of the login method provided in the embodiment of the present application is shown in FIG. 6. As shown in FIG. 6, the login method provided in the embodiment of the present application can include the following steps. Figure 10
[0222] S1001, the in-vehicle terminal displays an authorization binding control, and the authorization binding control is used to indicate that the digital key of the mobile terminal and the user account are bound.
[0223] S1002, if the in-vehicle terminal receives a selection instruction of the authorization binding control input by the user, the in-vehicle terminal pushes the identifier of the in-vehicle terminal to the first mobile terminal.
[0224] S1003, the in-vehicle terminal sends an authorization result query request to the account server at a regular time, and the authorization result query request is used to query the verification result of the user authorization on the first mobile terminal by the account server.
[0225] S1004, the in-vehicle terminal receives the access token and the update token sent by the account server.
[0226] S1005, the in-vehicle terminal writes the update token into the storage area of the digital key of the terminal device, the storage area of the in-vehicle terminal, or the storage area of the in-vehicle authentication device.
[0227] S1006, the in-vehicle terminal logs in the account server using the access token, and displays a first interface, which is the interface of the in-vehicle terminal logging in the first user account of the first mobile terminal.
[0228] In the above S1001, it should be understood that one scenario in which the interface of the in-vehicle terminal displays the authorization binding control can be that the interface displays the authorization binding control when the in-vehicle terminal fails to successfully extract the update token corresponding to the first digital key after the execution of the above S603. Alternatively, one scenario in which the interface of the in-vehicle terminal displays the authorization binding control can be that the interface displays the authorization binding control when the in-vehicle terminal fails to successfully extract the update token corresponding to the second digital key in the above embodiment. Alternatively, one scenario in which the interface of the in-vehicle terminal displays the authorization binding control can be that the interface displays the authorization binding control when the first digital key authentication is passed, the vehicle door is opened, and the in-vehicle terminal is powered on; or the interface displays the authorization binding control when the user triggers the control for binding the user account and the digital key in the powered-on state of the in-vehicle terminal; or the interface displays the authorization binding control when the in-vehicle terminal automatically logs in the application program when powered on.
[0229] In the embodiment of the present application, the interface displaying the authorization binding control is referred to as a second interface. The authorization binding control indicates the binding of the digital key and the user account, and the first digital key and the first user account are taken as examples for description. Exemplarily, Figure 11 The interface change of the in-vehicle terminal provided in the embodiment of the present application is shown in FIG. 7. Figure 3 .like Figure 11 As shown in interface 1101, this interface 1101 is the second interface, and the authorization binding control is displayed on this interface 1101.
[0230] Optionally, the second interface may also display a first reminder message, which explains the function of the authorization binding control. For example, interface 1101 may also display a first reminder message such as "Click the authorization binding control to bind the user account to your digital key".
[0231] In step S1002 above, after receiving the user's input instruction to select the authorization binding control, the vehicle terminal can push its identifier. The identifier is either the vehicle terminal's user code or includes both a user code and a Uniform Resource Identifier (URLI). Optionally, in this embodiment, the vehicle terminal can execute steps S301-S303 above, corresponding to displaying a first QR code. This first QR code includes the vehicle terminal's user code, or the vehicle terminal's user code and a URLI. Optionally, the vehicle terminal can also push its user code, or its user code and URLI, to a first mobile terminal that has established a Bluetooth connection with the vehicle terminal, or send it to a mobile phone via Bluetooth after the user confirms receipt on the mobile terminal. Optionally, the vehicle terminal can also push its user code, or its user code and URLI, to the first mobile terminal via NFC. Optionally, the vehicle terminal can also push the user code of the vehicle terminal, or the user code of the vehicle terminal and the verification Uniform Resource Identifier, to the first mobile terminal via SMS or other means.
[0232] In this embodiment, the method of pushing a user code to the vehicle terminal via a QR code is used as an example for illustration. Correspondingly, the above-mentioned interface 1101 jumps to interface 1102, which displays the first QR code.
[0233] If a user scans the first QR code displayed on the vehicle terminal using the first mobile terminal, it should be understood that after scanning the first QR code, the user can perform the action described in S304 above. Correspondingly, the vehicle terminal can periodically send authorization result query requests to the account server. These authorization result query requests are used to query the account server's verification result of the user's authorization operation on the first mobile terminal.
[0234] Optionally, after the vehicle terminal receives the scanning instruction for the first QR code from the first mobile terminal, interface 1102 can jump to interface 1103, which can display a third reminder message. This third reminder message indicates that the first digital key and the first user account are being bound.
[0235] For example, the third reminder information displayed on the interface 1103 is "Please do not disconnect the mobile terminal and the vehicle terminal during the binding of the digital key and the user account", or "Please place the mobile terminal in the NFC card swiping area and do not move the mobile terminal away from the area". Figure 11 For example, the third reminder information displayed on the interface 1103 is "Please do not disconnect the mobile terminal and the vehicle terminal during the binding of the digital key and the user account", or "Please place the mobile terminal in the NFC card swiping area and do not move the mobile terminal away from the area".
[0236] The S1003 can refer to the related description of S304.
[0237] In the S1004, it should be understood that after the authorization operation of the user on the first mobile terminal is verified by the account server, the access token and the update token can be generated, and the access token and the update token can be issued to the first mobile terminal, the vehicle authentication device or the vehicle terminal. The step of issuing or storing can refer to the related description of S602. Different from S305, in the embodiment of the application, since the user selects the authorization binding control, the account server needs to generate a credential for binding the first user account and the first digital key, that is, the update token.
[0238] Corresponding to S1005, the vehicle terminal can access the account server using the access token. Correspondingly, the implementation mode of the vehicle terminal accessing the account server using the access token in the embodiment of the application, and the mode of the vehicle terminal writing the update token into the storage area of the digital key of the terminal device or storing the update token into the local storage area of the digital key can refer to the related description of the embodiment S602.
[0239] Optionally, in a possible implementation manner of the embodiment of the application, the second interface can also display a second two-dimensional code. The second two-dimensional code is only used for authorized login and does not bind the digital key and the user account. After the user scans the code using the first terminal, the user logs in the same user account on the second terminal. It should be understood that the second two-dimensional code is the same as the two-dimensional code displayed in S303. Figure 12 Interface change of the vehicle terminal provided by the application Figure 4 . Figure 12 The interface 1201 in the embodiment of the application is a second interface, and the authorization binding control and the second two-dimensional code are displayed on the interface 1201. The second interface of the embodiment of the application can also display the first reminder information and the second reminder information. The first reminder information is as described above, and the second reminder information is used to explain the function of the second two-dimensional code. For example, the second reminder information "scan the second two-dimensional code to log in the user account" is also displayed on the interface 1201.
[0240] Correspondingly, if the user scans the second two-dimensional code through the mobile terminal, the vehicle-mounted terminal also performs the steps in S304-S307 to realize login of the first user account. Correspondingly, the interface 1201 can jump to the interface 1202, which can be the same as the interface 801 described above.
[0241] In S1006 described above, the vehicle-mounted terminal logs in the account server using the access token, that is, logs in the account server using the first user account. For details, refer to the related description in S607-S608 in the above embodiment. Correspondingly, the first interface can be displayed on the vehicle-mounted terminal. It should be understood that the interface 1103 jumps to the interface 1104, which is the same as the interface 801 described above. For details, refer to the related description of the interface 801 in the above embodiment.
[0242] It can be understood that after the vehicle-mounted terminal is disconnected from the mobile terminal, and the next time the vehicle-mounted terminal needs to log in the same user account of the mobile terminal, the steps in Embodiment I described above can be performed.
[0243] In the embodiment of the application, when the user account of the mobile terminal and the digital key have not been bound, the vehicle-mounted terminal can display an interface to guide the user to bind the user account of the mobile terminal and the digital key, so as to realize that when the digital key is used to open the door, the user account bound with the digital key is used to log in the server, thereby reducing the login time and improving the user experience.
[0244] Figure 13 Structure diagram of the login device provided in the embodiment of the application Figure 1 The login device can perform the actions of the vehicle-mounted terminal described above. As shown in Figure 13 The login device 1300 can include a transceiver module 1301, a processing module 1302, a display module 1303, and a storage module 1304.
[0245] The transceiver module 1301 is configured to, when starting an application, if an update token corresponding to a first digital key is acquired, send the update token to an account server, the first digital key being associated with a first user account, the first user account being a user account logged in the application on a first mobile terminal, and the update token being used to indicate the first user account.
[0246] The transceiver module 1301 is further configured to receive an access token generated by the account server based on the update token, the access token being related to the first user account, and the access token being used to represent the right to access data of the application under the first user account.
[0247] The processing module 1302 is configured to access the account server using the access token.
[0248] The display module 1303 is configured to receive data of an application under the first user account from the account server, and display a first interface according to the data, the first interface being an interface after the vehicle-mounted terminal logs in the first user account.
[0249] In a possible implementation, the transceiver module 1301 is further configured to receive an identification of the first digital key sent by the vehicle-side authentication device, the vehicle-side authentication device being configured to verify the first digital key.
[0250] Correspondingly, the processing module 1302 is further configured to obtain an update token corresponding to the first digital key according to the identification of the first digital key and a correspondence between the identification of the first digital key and the update token.
[0251] In a possible implementation, the correspondence is stored in a secure storage area in the vehicle-mounted terminal or a secure storage area in the vehicle-side authentication device; or the processing module 1302 is further configured to obtain the correspondence from the secure storage area in the vehicle-side authentication device.
[0252] In a possible implementation, the processing module 1302 is further configured to read the update token corresponding to the first digital key from the vehicle-side authentication device, the vehicle-side authentication device being configured to verify the first digital key.
[0253] In a possible implementation, the display module 1303 is further configured to, when the first digital key of the vehicle is verified and the vehicle-mounted terminal starts the application, if the vehicle-mounted terminal does not obtain the update token corresponding to the first digital key, display a second interface, the second interface displaying an authorization binding control, the authorization binding control indicating that the digital key of the mobile terminal is bound to the user account.
[0254] Correspondingly, the processing module 1302 is further configured to, if the vehicle-mounted terminal receives an indication of selection of the authorization binding control by the user, push an identification of the vehicle-mounted terminal to the first mobile terminal.
[0255] The transceiver module 1301 is further configured to receive an access token and an update token from the account server, the access token and the update token being sent after the first mobile terminal uses the identification of the vehicle-mounted terminal to pass the user authorization verification.
[0256] The processing module 1302 is further configured to use the access token to access the account server by the vehicle-mounted terminal.
[0257] The display module 1304 is further configured to receive data of an application under the first user account from the account server, and display a first interface according to the data.
[0258] In a possible implementation, the identifier of the vehicle-mounted terminal is a user code of the vehicle-mounted terminal, or the identifier of the vehicle-mounted terminal comprises the user code and a verification uniform resource identifier.
[0259] In a possible implementation, the transceiver 1301 is further configured to send, in a timely manner, an authorization result query request to the authorization server, where the authorization result query request is used to query a verification result of the authorization server on the user authorization of the first mobile terminal.
[0260] Correspondingly, the processing module 1302 is further configured to determine that the user authorization of the first mobile terminal passes the verification if the response information from the authorization server is received, where the response information indicates that the user authorization of the first mobile terminal passes the verification.
[0261] In a possible implementation, the processing module 1302 is further configured to delete the update token.
[0262] The transceiver 1301 is further configured to receive, when the access token from the account server is received, a new update token from the account server, where the new update token is an update token corresponding to the first digital key.
[0263] In a possible implementation, the transceiver 1301 is further configured to send the new update token to the first mobile terminal, or
[0264] send the new update token to the vehicle-end authentication device, or
[0265] Correspondingly, the processing module 1302 is further configured to generate, according to the new update token, a correspondence between the identifier of the first digital key and the new update token.
[0266] The storage module 1304 is configured to store the correspondence between the identifier of the first digital key and the new update token.
[0267] In a possible implementation, the processing module 1302 is further configured to exit the application program when the vehicle-mounted terminal is powered off.
[0268] Correspondingly, the transceiver 1301 is further configured to send, when the application program is logged in next time, the new update token to the account server.
[0269] In a possible implementation, the processing module 1302 is further configured to delete the access token.
[0270] In a possible implementation, the display module 1303 is further configured to display a third interface if the selection indication of the switching control by the user is received, where the third interface displays the identifier of the second mobile terminal.
[0271] Correspondingly, the transceiver module 1301 is further configured to, if the selection indication of the identification of the second mobile terminal is received and the vehicle-mounted terminal obtains the update token corresponding to the second digital key, send the update token corresponding to the second digital key to the account server, the second digital key being the digital key corresponding to the second mobile terminal and the vehicle.
[0272] In a possible implementation, when the first digital key is opened by the vehicle-mounted terminal or the vehicle-side authentication device, the transceiver module 1301 is further configured to receive the update token from the account server; or,
[0273] When the first digital key is negotiated with the first mobile terminal by the vehicle-mounted terminal or the vehicle-side authentication device, the transceiver module 1301 is further configured to receive the update token from the account server.
[0274] The implementation principle and technical effects of the vehicle-mounted terminal provided in this embodiment are similar to those in the above embodiments, and will not be repeated here.
[0275] Figure 14 Structure of a login device provided in an embodiment of the present application Figure 2 The login device can perform the actions of the vehicle-side authentication device described above. As shown in Figure 14 The login device 1400 can include a processing module 1401, a transceiver module 1402, and a storage module 1403.
[0276] The processing module 1401 is configured to verify a first digital key of a vehicle, the first digital key being associated with a first user account, the first user account being a user account of an application program logged in on a first mobile terminal.
[0277] The transceiver module 1402 is configured to, if the first digital key is verified and the identification of the first digital key or the update token corresponding to the first digital key is obtained, send the identification of the first digital key or the update token to the vehicle-mounted terminal when the application program is started on the vehicle-mounted terminal, the update token being used to indicate the first user account, the first user account being a user account of an application program logged in on a first mobile terminal.
[0278] In a possible implementation, the processing module 1401 is further configured to read the update token in the first mobile terminal; or, according to the identification of the first digital key and the correspondence between the identification of the first digital key and the update token, obtain the update token corresponding to the first digital key.
[0279] In a possible implementation, the correspondence is stored in a secure storage area in the vehicle terminal or a secure storage area in the vehicle-side authentication device. The processing module 1401 is specifically configured to: according to the identification of the first digital key and the correspondence between the identification of the first digital key and the update token stored in the secure storage area in the vehicle-side authentication device, obtain the update token corresponding to the first digital key.
[0280] In a possible implementation, the transceiving module 1402 is further configured to: receive the new update token from the vehicle terminal, the new update token being the update token corresponding to the first digital key; or receive the new update token from the account server.
[0281] In a possible implementation, the transceiving module 1402 is further configured to: send, by the vehicle-side authentication device, the new update token to the first mobile terminal; or
[0282] The processing module 1401 is further configured to: according to the new update token, generate the correspondence between the identification of the first digital key and the new update token.
[0283] The storage module 1403 is configured to store the correspondence between the identification of the first digital key and the new update token.
[0284] In a possible implementation, the transceiving module 1402 is further configured to: receive the update token from the account server when the vehicle-side authentication device or the vehicle-side authentication device opens the first digital key; or receive the update token from the account server when the vehicle terminal or the vehicle-side authentication device negotiates the first digital key with the first mobile terminal.
[0285] The implementation principle and technical effects of the vehicle-side authentication device provided in this embodiment are similar to those in the above embodiments, and will not be described here.
[0286] Figure 15 Structure of a login device provided in an embodiment of this application Figure 3 The login device can perform the actions of the account server described above. As shown in Figure 15 , the login device 1500 can include a transceiving module 1501 and a processing module 1502.
[0287] The transceiving module 1501 is configured to receive the update token from the vehicle terminal, the update token being sent when the vehicle terminal starts an application program, and the update token being used to indicate a first user account, the first user account being a user account logged in to the application program on the first mobile terminal.
[0288] The transceiver module 1501 is further configured to send, according to the correspondence between the update token and the first user account, an access token to the vehicle-mounted terminal, the access token being related to the first user account, and the access token being used to indicate that the vehicle-mounted terminal has the permission to access data of an application under the first user account.
[0289] The transceiver module 1501 is further configured to receive the access token from the vehicle-mounted terminal, and send, to the vehicle-mounted terminal, data of the application under the first user account.
[0290] In a possible implementation, the transceiver module 1501 is further configured to, when sending the access token to the vehicle-mounted terminal, also send, to the vehicle-mounted terminal, a new update token, the new update token being an update token corresponding to the first digital key; or send, to a vehicle-end authentication device, the new update token, the vehicle-end authentication device being used to verify the first digital key; or send, to the first mobile terminal, the new update token.
[0291] In a possible implementation, the transceiver module 1501 is further configured to, if the account server determines that the user authorization of the first mobile terminal passes the verification, send, to the vehicle-mounted terminal, the access token and the update token.
[0292] In a possible implementation, the processing module 1502 is further configured to, if receiving the response information from the authorization server, determine that the user authorization of the first mobile terminal passes the verification, the response information indicating that the user authorization of the first mobile terminal passes the verification, and the authorization server being used to verify the user authorization of the first mobile terminal.
[0293] In a possible implementation, the processing module 1502 is further configured to, if determining that the user authorization of the first mobile terminal passes the verification, generate an update token corresponding to the first user account, and obtain the correspondence between the update token and the first user account; or, when the first digital key is opened by the vehicle-mounted terminal or the vehicle-end authentication device, generate the update token corresponding to the first user account, and obtain the correspondence between the update token and the first user account; or, when the first digital key is negotiated by the vehicle-mounted terminal or the vehicle-end authentication device and the first mobile terminal, generate the update token corresponding to the first user account, and obtain the correspondence between the update token and the first user account.
[0294] The implementation principle and technical effects of the account server provided in this embodiment are similar to those in the above-described embodiments, and will not be described here.
[0295] Figure 16 The electronic device provided in this embodiment is shown in a structural schematic diagram. It should be understood that the electronic device can be the vehicle-mounted terminal, the vehicle-end authentication device, or the account server in the above-described embodiments. Figure 16As shown, the electronic device 1600 can include a processor 1601, a memory 1602, and a communication interface 1603.
[0296] The memory 1602 is configured to store a computer program, and the processor 1601 is configured to execute the computer program stored in the memory 1602 to implement the method performed by the vehicle terminal, the vehicle-side authentication device, or the account server in the above embodiments. The communication interface 1603 is configured to implement communication between the vehicle terminal, the vehicle-side authentication device, or the account server.
[0297] Optionally, the memory 1602 can be independent or integrated with the processor 1601. When the memory 1602 is independent of the processor 1601, the electronic device 1600 can further include a bus 1604 configured to connect the memory 1602 and the processor 1601.
[0298] In a possible implementation, the processing module can be integrated in the processor 1601, and the transceiver module can be integrated in the communication interface 1603.
[0299] In a possible implementation, the electronic device 1600 can include a display 1605 configured to perform the action of displaying the interface of the vehicle terminal in the above embodiments. Similarly, the display 1605 can be connected to the bus 1604.
[0300] An embodiment of the present application provides a storage medium including a computer program, the computer program being configured to implement the login method performed by the vehicle terminal, the vehicle-side authentication device, or the account server in the above method embodiments.
[0301] An embodiment of the present application further provides a chip including a memory and a processor, the memory being configured to store a computer program, and the processor being configured to call and run the computer program from the memory, so that a device installed with the chip performs the login method performed by the vehicle terminal, the vehicle-side authentication device, or the account server in the above method embodiments.
[0302] An embodiment of the present application further provides a computer program product including computer program code, when the computer program code is run on a computer, the computer program code causes the computer to perform the login method performed by the vehicle terminal, the vehicle-side authentication device, or the account server in the above method embodiments.
[0303] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other manners. For example, the embodiments of the device described above are merely schematic. For example, the division of the modules is merely logical function division. There can be another division manner for the actual implementation. For example, a plurality of modules or features can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections can be indirect couplings or communication connections through some interfaces, devices or modules, and can be electrical, mechanical or in other forms.
[0304] The modules illustrated as separated components can or can not be physically separated, and the components illustrated as modules can or can not be physical units, i.e., can be located in one place, or can be distributed on a plurality of network units. Some or all of the modules can be selected according to actual needs to achieve the purposes of the embodiments.
[0305] In addition, each functional module in each embodiment of the present application can be integrated in one processing unit, or each module can be physically present alone, or two or more modules can be integrated in one unit. The unit of the above modules can be realized in the form of hardware, or in the form of hardware plus software functional unit.
[0306] The integrated modules realized in the form of software functional modules can be stored in a computer readable storage medium. The software functional modules stored in the storage medium include a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor (English: processor) to execute some steps of the method described in each embodiment of the present application.
[0307] It should be understood that the processor can be a central processing unit (English: central processing unit, CPU for short), and can also be other general-purpose processors, digital signal processors (English: digital signal processor, DSP for short), application specific integrated circuits (English: application specific integrated circuit, ASIC for short), etc. The general-purpose processor can be a microprocessor, or the processor can be any conventional processor, etc. The steps of the method disclosed in combination with the application can be directly embodied as hardware processor execution, or executed by a combination of hardware and software modules in the processor.
[0308] The memory can include a high-speed RAM memory, and can also include a non-volatile storage NVM, such as at least one disk memory, and can also be a U disk, a mobile hard disk, a read-only memory, a magnetic disk or an optical disk, etc.
[0309] The bus can be an industry standard architecture (ISA) bus, a peripheral component (PCI) bus, or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, the bus in the drawings of the present application does not limit to only one bus or one type of bus.
[0310] The storage medium described above can be realized by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0311] An exemplary storage medium is coupled to the processor, so that the processor can read information from the storage medium, and can write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the storage medium can also exist as discrete components in an electronic device or a host device.
[0312] The term "a plurality of" herein refers to two or more. The term "and / or" herein is only a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can represent the three cases of A alone, A and B together, and B alone. In addition, the character " / " herein generally represents that the associated objects before and after are an "or" relationship; in the formula, the character " / " represents that the associated objects before and after are a "division" relationship.
[0313] It can be understood that various numerical numbers involved in the embodiments of the embodiments of the present application are only for the convenience of differentiation, and do not limit the scope of the embodiments of the present application.
[0314] It can be understood that, in the embodiments of the embodiments of the present application, the size of the serial number of each process does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the embodiments of the present application.
Claims
1. A login method characterized by, The method comprises: When the vehicle terminal starts an application, if the vehicle terminal acquires a first token, the vehicle terminal sends the first token to an account server, the first token is associated with a first user account, and the first user account is a user account of a first mobile terminal that logs in the application; The vehicle terminal receives a second token generated by the account server based on the first token; The vehicle terminal accesses the account server using the second token; The vehicle terminal receives data related to the first user account from the account server, and displays a first interface according to the data, the first interface being an interface after the vehicle terminal logs in the first user account.
2. The method of claim 1, wherein, The vehicle terminal acquires the first token, comprising: The vehicle terminal receives an identification of a first digital key sent by a vehicle-side authentication device, the vehicle-side authentication device being configured to verify the first digital key; The vehicle terminal acquires the first token corresponding to the first digital key according to the identification of the first digital key and a correspondence between the identification of the first digital key and the first token.
3. The method of claim 2, wherein, The correspondence is stored in a secure storage area of the vehicle terminal.
4. The method of claim 1, wherein, The vehicle terminal acquires the first token, comprising: The vehicle terminal reads the first token corresponding to the first digital key from the vehicle-side authentication device, the vehicle-side authentication device being configured to verify the first digital key.
5. The method according to any one of claims 1 to 4, characterized in that, The method further comprises: When the vehicle terminal starts the application, if the vehicle terminal does not acquire the first token, the vehicle terminal displays a second interface, the second interface displaying an authorization binding control, the authorization binding control indicating that the digital key and the user account of the first mobile terminal are bound; If the vehicle terminal receives an indication of selection of the authorization binding control by a user, the vehicle terminal pushes an identification of the vehicle terminal to the first mobile terminal; The vehicle terminal receives the second token and the first token from the account server, the second token and the first token being sent by the account server after the first mobile terminal passes the verification of user authorization using the identification of the vehicle terminal; The vehicle terminal accesses the account server using the second token; The vehicle terminal receives data of the application under the first user account from the account server, and displays the first interface according to the data.
6. The method of claim 5, wherein, The identification of the vehicle terminal is a user code of the vehicle terminal, or the identification of the vehicle terminal comprises the user code and a verification uniform resource identifier.
7. The method of claim 5, wherein, After the vehicle terminal pushes the identification of the vehicle terminal to the first mobile terminal, the method further comprises: The vehicle terminal sends an authorization result query request to an authorization server at a regular time, the authorization result query request being configured to query a verification result of user authorization of the first mobile terminal by the authorization server; If the vehicle terminal receives response information from the authorization server, it is determined that the user authorization of the first mobile terminal passes the verification, the response information indicating that the user authorization of the first mobile terminal passes the verification.
8. The method according to any one of claims 1-4, characterized in that, The method further comprises: The vehicle terminal deletes the first token. The vehicle terminal receives a new first token from the account server when receiving the second token from the account server, the new first token being a first token corresponding to the first mobile terminal.
9. The method of claim 8, wherein, The method further comprises: The vehicle terminal sends the new first token to the first mobile terminal; or, The vehicle terminal sends the new first token to a vehicle-end authentication device; or, The vehicle terminal generates a correspondence between the first mobile terminal and the new first token according to the new first token. The vehicle terminal stores the correspondence between the first mobile terminal and the new first token.
10. The method of claim 8, wherein, The method further comprises: The vehicle terminal exits the application program. The vehicle terminal sends the new first token to the account server when logging into the application program next time.
11. The method of any one of claims 1-4, 6-7, 9-10, wherein, The method further comprises: The vehicle terminal deletes the second token.
12. The method of any one of claims 1-4, 6-7, 9-10, wherein, The first interface further displays a switching control, the switching control indicating switching the first user account, and the method further comprises: If the vehicle terminal receives a selection indication of the switching control by a user, a third interface is displayed, the third interface displaying an identifier of a second mobile terminal. If the vehicle terminal receives a selection indication of the identifier of the second mobile terminal by the user and the vehicle terminal acquires a third token, the vehicle terminal sends the third token corresponding to the second mobile terminal to the account server, the third token being associated with a second user account, the second user account being a user account of the application program logged in on the second mobile terminal, and the selection indication representing switching the first user account to the second user account.
13. The method of any one of claims 1-4, wherein, The method further comprises: The vehicle terminal receives the first token from the account server when the vehicle terminal or a vehicle-end authentication device opens a first digital key; or, The vehicle terminal receives the first token from the account server when the vehicle terminal or the vehicle-end authentication device negotiates the first digital key with the first mobile terminal.
14. The method of claim 1, wherein, The method further comprises: The vehicle terminal displays a first control when the vehicle terminal starts an application program and no first token is acquired by the vehicle terminal, If the vehicle terminal receives a first operation of the first control by a user, the vehicle terminal sends an identifier of the vehicle terminal to a first mobile terminal; The vehicle terminal sends a first query request to an account server, the first query request being used to query a verification result of user authorization of the first mobile terminal by the account server; The vehicle terminal receives the second token from the account server in response to the query request; The vehicle terminal logs in the account server using the second token; The vehicle terminal displays the first interface.
15. A login method characterized by comprising: The method further comprises: The vehicle-end authentication device verifies a first digital key of the vehicle, the first digital key being associated with a first user account, the first user account being a user account of a user who logs in an application on a first mobile terminal; If the first digital key is verified, the vehicle-end authentication device obtains a first token, and when the application on the vehicle terminal is started, the vehicle-end authentication device sends an identification of the first digital key or the first token to the vehicle terminal, the first token being used to indicate the first user account, and the identification of the first digital key being used for the vehicle terminal to obtain the first token; The vehicle terminal is configured to send the first token to an account server and receive a second token generated by the account server based on the first token, and use the second token to access the account server.
16. The method of claim 15, wherein, The vehicle-end authentication device obtains the first token, including: The vehicle-end authentication device reads the first token in the first mobile terminal; or The vehicle-end authentication device obtains the first token corresponding to the first digital key according to the identification of the first digital key and the correspondence between the identification of the first digital key and the first token.
17. The method of claim 16, wherein, The correspondence is stored in a secure storage area in the vehicle terminal or a secure storage area in the vehicle-end authentication device, and the vehicle-end authentication device obtains the first token corresponding to the first digital key according to the identification of the first digital key and the correspondence between the identification of the first digital key and the first token, including: The vehicle-end authentication device obtains the first token corresponding to the first digital key according to the identification of the first digital key and the correspondence between the identification of the first digital key and the first token stored in the secure storage area of the vehicle-end authentication device.
18. The method according to any one of claims 15-17, characterized by, After the vehicle-end authentication device sends the identification of the first digital key or the first token to the vehicle terminal, the method further includes: The vehicle-end authentication device receives a new first token from the vehicle terminal, the new first token being the first token corresponding to the first digital key; or The vehicle-end authentication device receives the new first token from the account server.
19. The method of claim 18, wherein, The method further includes: The vehicle-end authentication device sends the new first token to the first mobile terminal; The vehicle-end authentication device generates a correspondence between the identification of the first digital key and the new first token according to the new first token; The vehicle-end authentication device stores the correspondence between the identification of the first digital key and the new first token.
20. The method of any one of claims 15-17, wherein, The method further includes: When the vehicle-end authentication device or the vehicle-end authentication device opens the first digital key, the vehicle-end authentication device receives the first token from the account server; or When the vehicle terminal or the vehicle-end authentication device negotiates the first digital key with the first mobile terminal, the vehicle-end authentication device receives the first token from the account server.
21. An electronic device, comprising: The method further includes: a memory for storing a computer program, and a processor for calling and running the computer program from the memory, so that the processor runs the computer program to perform the method of any one of claims 1-20.
22. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program or instructions, which, when executed, implement the method of any one of claims 1-20.
23. A computer program product, characterised in that, The computer program product comprises a computer program, which, when executed, implements the method of any one of claims 1-20.
Citation Information
Patent Citations
Same-account incredible terminal login method and system based on credible terminal
CN104135494A