Digital key sharing method and apparatus, terminal device, vehicle, and storage medium
By generating self-signed certificates and issuing new key certificates through direct interaction between terminal devices, the problem of slow and inefficient digital key sharing in poor network environments is solved, and efficient key sharing without server intervention is achieved.
Patent Information
- Application Number
- CN202211448389.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-18
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2042-11-18
AI Technical Summary
In poor network conditions, sharing digital keys between terminal devices can easily result in response delays, leading to slow and inefficient sharing speeds.
By directly interacting between terminal devices, a self-signed certificate is generated and a new key certificate is issued, enabling the sharing of digital keys and avoiding server intervention.
It improves the speed and efficiency of sharing digital keys between terminal devices, and the sharing process of digital keys does not require the intervention of a server.
Smart Images

Figure CN115734223B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of vehicle control, and in particular to a digital key sharing method and device, a terminal device, a vehicle and a storage medium. BACKGROUND
[0002] With the development of science and technology, vehicles are indispensable means of transportation in people's daily life, and the development of vehicle intelligence can make people's life more convenient.
[0003] At present, most vehicles have a digital key function, that is, the vehicle and the terminal device share the digital key, so that the user can control the vehicle (such as starting the vehicle) without using a physical key. In addition, the terminal device that has opened the digital key can share the digital key with other terminal devices, so that other terminal devices also have the right to control the vehicle. Usually, the terminal device that has opened the digital key needs to introduce the assistance of the server side to share its digital key with other terminal devices, and other terminal devices also obtain new key certificates through the server link to control the vehicle.
[0004] In the above scheme, since the server side needs to be introduced, in the case of poor network environment, the sharing of digital keys between terminal devices is prone to response delay and other phenomena, resulting in slow and inefficient sharing of digital keys. SUMMARY
[0005] In order to solve the problems of the prior art and improve the sharing speed and efficiency of digital keys between terminal devices, the embodiments of the present application provide a digital key sharing method, device, terminal device, vehicle and storage medium. The technical solution is as follows:
[0006] In one aspect, the present application provides a digital key sharing method applied to a first terminal device, the method comprising:
[0007] receiving a first message for sharing the control right of a second terminal device to a first vehicle with the first terminal device, the second terminal device storing a first target certificate for controlling the first vehicle;
[0008] generating a self-signed certificate in response to the first message;
[0009] sending the self-signed certificate to the second terminal device;
[0010] receiving the first target certificate and a second target certificate returned by the second terminal device, the second target certificate being determined by the second terminal device according to the self-signed certificate.
[0011] In an aspect, the present application provides a digital key sharing method applied to a second terminal device, wherein the second terminal device stores a first target certificate for controlling a first vehicle, and the method comprises:
[0012] sending a first message to a first terminal device, wherein the first message is used to share a control right of the second terminal device for controlling the first vehicle to the first terminal device;
[0013] receiving a self-signed certificate returned by the first terminal device based on the first message;
[0014] issuing a second target certificate according to the self-signed certificate and a second key pair, wherein the second key pair is a key pair corresponding to the first target certificate in the second terminal device;
[0015] sending the second target certificate and the first target certificate to the first terminal device.
[0016] In an aspect, the present application provides a digital key sharing method applied to a first terminal device, and the method comprises:
[0017] sending a first target certificate and a second target certificate to a first vehicle, wherein the first target certificate and the second target certificate are sent by a second terminal device, the second terminal device stores the first target certificate for controlling the first vehicle, and the second target certificate is determined by the second terminal device according to a self-signed certificate of the first terminal device;
[0018] receiving a verification result of the first vehicle for verifying the first target certificate and the second target certificate;
[0019] when the verification result indicates that the first terminal device passes the verification, establishing a communication connection with the first vehicle and controlling the first vehicle based on the communication connection.
[0020] In an aspect, the present application provides a digital key sharing method applied to a first vehicle, and the method comprises:
[0021] receiving a first target certificate and a second target certificate sent by a first terminal device, wherein the first target certificate and the second target certificate are sent by a second terminal device to the first terminal device, the second terminal device stores the first target certificate for controlling the first vehicle, and the second target certificate is determined by the second terminal device according to a self-signed certificate of the first terminal device;
[0022] sending a verification result of the first vehicle for verifying the first target certificate and the second target certificate to the first terminal device.
[0023] when the verification result indicates that the first terminal device passes the verification, establishing a communication connection with the first vehicle, so that the first terminal device controls the first vehicle based on the communication connection.
[0024] In one aspect, the present application provides a digital key sharing device, applied to a first terminal device, the device comprising:
[0025] a first receiving module configured to receive a first message, the first message being used to share a control right of a second terminal device to a first vehicle to the first terminal device, the second terminal device storing a first target certificate used to control the first vehicle;
[0026] a first generating module configured to generate a self-signed certificate in response to the first message;
[0027] a first sending module configured to send the self-signed certificate to the second terminal device;
[0028] a second receiving module configured to receive the first target certificate and a second target certificate returned by the second terminal device, the second target certificate being determined by the second terminal device according to the self-signed certificate.
[0029] In one aspect, the present application provides a digital key sharing device, applied to a second terminal device, the second terminal device storing a first target certificate used to control a first vehicle, the device comprising:
[0030] a second sending module configured to send a first message to a first terminal device, the first message being used to share a control right of the second terminal device to the first vehicle to the first terminal device;
[0031] a third receiving module configured to receive a self-signed certificate returned by the first terminal device based on the first message;
[0032] a first issuing module configured to issue a second target certificate according to the self-signed certificate and a second key pair, the second key pair being a key pair corresponding to the first target certificate in the second terminal device;
[0033] a third sending module configured to send the second target certificate and the first target certificate to the first terminal device.
[0034] In one aspect, the present application provides a digital key sharing device, applied to a first terminal device, the device comprising:
[0035] a fourth sending module, configured to send a first target certificate and a second target certificate to the first vehicle, the first target certificate and the second target certificate being sent by a second terminal device, the second terminal device storing the first target certificate for controlling the first vehicle, the second target certificate being determined by the second terminal device according to a self-signed certificate of the first terminal device;
[0036] a fourth receiving module, configured to receive a verification result of the first vehicle verifying the first target certificate and the second target certificate;
[0037] a first control module, configured to, when the verification result indicates that the first terminal device passes the verification, establish a communication connection with the first vehicle, and control the first vehicle based on the communication connection.
[0038] In one aspect, the present application provides a digital key sharing device applied to a first vehicle, the device comprising:
[0039] a fifth receiving module, configured to receive a first target certificate and a second target certificate sent by a first terminal device, the first target certificate and the second target certificate being sent by a second terminal device to the first terminal device, the second terminal device storing the first target certificate for controlling the first vehicle, the second target certificate being determined by the second terminal device according to a self-signed certificate of the first terminal device;
[0040] a fifth sending module, configured to send a verification result of the first vehicle verifying the first target certificate and the second target certificate to the first terminal device;
[0041] a first control module, configured to, when the verification result indicates that the first terminal device passes the verification, establish a communication connection with the first vehicle, and control the first vehicle based on the communication connection.
[0042] In another aspect, the present application provides a terminal device, comprising a processor and a memory, the memory storing at least one instruction, at least one program, a code set or an instruction set, the at least one instruction, the at least one program, the code set or the instruction set being loaded and executed by the processor to implement the digital key sharing method according to one aspect.
[0043] In another aspect, the present application provides a vehicle, comprising a processor and a memory, the memory storing at least one instruction, at least one program, a code set or an instruction set, the at least one instruction, the at least one program, the code set or the instruction set being loaded and executed by the processor to implement the digital key sharing method according to one aspect.
[0044] In another aspect, the present application provides a computer readable storage medium having stored therein at least one instruction, at least one program, a code set or an instruction set, which is loaded and executed by a processor to implement the method for sharing a digital key according to one aspect.
[0045] In another aspect, the present application provides a computer program product, which, when running on a computer, causes the computer to perform the method for sharing a digital key according to one aspect.
[0046] In another aspect, the present application provides an application publishing platform for publishing a computer program product, which, when running on a computer, causes the computer to perform the method for sharing a digital key according to one aspect.
[0047] The technical scheme provided by the embodiments of the present application has at least the following beneficial effects:
[0048] The first terminal device receives a first message, the first message being used to share the control authority of the second terminal device for controlling the first vehicle to the first terminal device, and the second terminal device stores a first target certificate for controlling the first vehicle; in response to the first message, a self-signed certificate is generated; the self-signed certificate is sent to the second terminal device; the first terminal device receives the first target certificate and a second target certificate returned by the second terminal device, the second target certificate being determined by the second terminal device according to the self-signed certificate. The first terminal device receives the first message used to share the control authority of the second terminal device for controlling the first vehicle to the first terminal device, generates a self-signed certificate of the first terminal device, and receives the second target certificate determined by the second terminal device according to the self-signed certificate, so that the first terminal device obtains the control authority for controlling the first vehicle, completes the sharing process of the digital key, does not need the intervention of a server, and completes the issuance of the second target certificate based on the interaction between the two terminal devices, thereby improving the sharing speed and efficiency of the digital key between the terminal devices. BRIEF DESCRIPTION OF DRAWINGS
[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort.
[0050] Figure 1is a flowchart of a digital key opening flow of a vehicle, which is related to an exemplary embodiment of the present application;
[0051] Figure 2 is a method flowchart of a digital key sharing method, which is provided by an exemplary embodiment of the present application;
[0052] Figure 3 is a method flowchart of a digital key sharing method, which is provided by an exemplary embodiment of the present application;
[0053] Figure 4 is a method flowchart of a digital key sharing method, which is provided by an exemplary embodiment of the present application;
[0054] Figure 5 is a method flowchart of a digital key sharing method, which is provided by an exemplary embodiment of the present application;
[0055] Figure 6 is a method flowchart of a digital key sharing method, which is provided by an exemplary embodiment of the present application;
[0056] Figure 7 is a method flowchart of a digital key sharing method, which is provided by an exemplary embodiment of the present application;
[0057] Figure 8 is a method flowchart of a digital key sharing method, which is provided by an exemplary embodiment of the present application;
[0058] Figure 9 is a structural block diagram of a digital key sharing apparatus, which is provided by an exemplary embodiment of the present application;
[0059] Figure 10 is a structural block diagram of a digital key sharing apparatus, which is provided by an exemplary embodiment of the present application;
[0060] Figure 11 is a structural block diagram of a digital key sharing apparatus, which is provided by an exemplary embodiment of the present application;
[0061] Figure 12 is a structural block diagram of a digital key sharing apparatus, which is provided by an exemplary embodiment of the present application;
[0062] Figure 13 is a structural diagram of a terminal device, which is provided by an exemplary embodiment of the present application. DETAILED DESCRIPTION
[0063] The exemplary embodiments will be described in detail below with reference to the accompanying drawings. In the following description, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementations described in the following exemplary embodiments are not meant to represent all implementations consistent with the present disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the present disclosure as detailed in the appended claims.
[0064] Digital key: or also known as digital car key, refers to an innovative technology under the intelligent transformation of automobile, because the user terminal device, wearable device, etc. can obtain the digital key of the car, and through the terminal device, wearable device, etc. to unlock the car and implement relevant operations on the car, improve the convenience of using the car.
[0065] With the development of science and technology, vehicles as an indispensable means of transportation in people's daily life, the intelligent of vehicles is more and more common, various terminal devices and vehicle-mounted terminals in vehicles can establish communication connection and data transmission, realize the interaction between vehicles and terminal devices. Among them, the digital key of the vehicle is one of the technologies that embody the intelligence of the vehicle. In practical application, users can control the start of the vehicle through the physical key of the vehicle.
[0066] With the application of digital key in vehicles, most vehicle manufacturers provide digital key opening function for the vehicles produced by them. Users can interact with the vehicle-mounted terminal through the terminal device, obtain the digital key on the terminal device side, and thus control the start, operation, etc. of the vehicle through the terminal device. Even if the user does not carry the physical key, he can also control the vehicle through the digital key opened in the terminal device to start the vehicle and drive the vehicle.
[0067] Please refer to Figure 1 , which shows a flowchart of a digital key opening process of a vehicle related to an example embodiment of the present application. As Figure 1 shown, the digital key opening process of the vehicle can include the following steps.
[0068] Step 101, the terminal device and the vehicle-mounted terminal establish a communication connection.
[0069] Among them, the user can establish a communication connection between the terminal device and the vehicle-mounted terminal through Bluetooth technology, wireless fidelity (WiFi), data line, wireless access point (AP), etc. during the use of the terminal device and the vehicle-mounted terminal, so as to carry out data transmission.
[0070] Optionally, in the present application, the terminal device can be an electronic device with communication function, for example, the terminal device can include but is not limited to wearable devices (such as bracelet, smart watch, smart glasses, etc.), mobile phones, tablet computers, notebook computers, smart glasses, smart watches, MP3 players (Moving Picture Experts Group Audio Layer III), MP4 (Moving Picture Experts Group Audio Layer IV) players, desktop computers, laptop computers, etc.
[0071] Step 102, the vehicle-mounted terminal initiates the digital key opening process.
[0072] Optionally, the user can actively initiate the digital key opening process through the vehicle-mounted terminal of the vehicle. For example, after establishing the communication connection in step 101, the user can operate the vehicle-mounted terminal to display a digital key opening interface, and trigger the digital key opening control in the interface to initiate the digital key opening process by the vehicle-mounted terminal.
[0073] Step 103, the vehicle-mounted terminal transmits the vehicle public key certificate to the terminal device.
[0074] Optionally, the vehicle public key certificate is a vehicle manufacturer certificate issued by a server through a certificate authority before the vehicle is manufactured and pre-stored in the vehicle. After the vehicle-mounted terminal initiates the digital key opening process, it actively sends the vehicle public key certificate stored in itself to the terminal device through the communication connection.
[0075] Step 104, the terminal device verifies the vehicle public key certificate using a preset certificate, or the terminal device requests the server to verify the vehicle public key certificate.
[0076] The preset certificate can also be negotiated by the manufacturer of the terminal device and the manufacturer of the vehicle in advance and set in the terminal device. When the terminal device receives the vehicle public key certificate, it can verify the vehicle public key certificate using the preset certificate, and when the verification is passed, step 105 is executed. Alternatively, the terminal device can send the obtained vehicle public key certificate to the server for establishing the digital key to request the server to verify the vehicle public key certificate.
[0077] Step 105, the terminal device generates a digital key pair and a key public key certificate.
[0078] Optionally, after the terminal device verifies the vehicle public key certificate, the terminal device can generate a random key pair using a key pair generation algorithm pre-set by the terminal device, and bind the key pair with the vehicle public key certificate, and the key pair can be used for subsequent control of the vehicle.
[0079] Optionally, after the terminal device generates the digital key pair, the terminal device issues a key public key certificate through the digital key pair, obtains a key public key certificate for subsequent control of the vehicle, and the key public key certificate can be authenticated to open the digital key, so as to realize data interaction and vehicle control.
[0080] In step 106, the terminal device transmits the key public key certificate to the vehicle terminal.
[0081] Optionally, the terminal device transmits the generated key public key certificate to the vehicle terminal.
[0082] In step 107, the vehicle terminal verifies the key public key certificate and saves it.
[0083] Correspondingly, the vehicle terminal receives the key public key certificate sent by the terminal device and verifies it, so as to determine whether the key public key certificate is obtained based on the vehicle public key certificate of the vehicle terminal, and when the verification is passed (i.e., the key public key certificate is obtained based on the vehicle public key certificate of the vehicle terminal), the obtained key public key certificate is saved, so as to complete opening of the digital key on the terminal device side, and the terminal device uses the key public key certificate for verification when controlling the vehicle subsequently.
[0084] In one possible implementation, after the terminal device opens the digital key, the terminal device can share the digital key opened by the terminal device with other terminal devices through a key sharing function. For example, in a technical solution of digital key sharing, after a terminal device opens a digital key with a vehicle, if the terminal device needs to share the digital key with another terminal device, the two terminal devices need to install the same application program (Application APP), and the terminal device that has opened the digital key sends the key certificate stored by the terminal device to a background server through the APP, and the terminal device that has not opened the digital key also applies to the background server for issuance of a new key certificate through the APP, and the server sends the new key certificate to the terminal device that has not opened the digital key after verifying the new key certificate.
[0085] That is, for the mechanism of sharing the digital key of the vehicle between multiple terminal devices (such as mobile phones, smart watches, etc.) of the same vehicle owner, the intervention of the server is usually required. When the new terminal device requesting sharing initiates a key sharing request to the terminal device that has opened the digital key, the response request link of the terminal device that has opened the digital key also needs to pass through the server. Due to the above process, the intervention of the server is required. In the case of poor network environment, the sharing of the digital key between terminal devices is prone to response delay and other phenomena, resulting in slow and low efficiency of the sharing of the digital key.
[0086] In order to solve the problems existing in the above related technologies and improve the sharing speed and efficiency of the digital key between terminal devices, the present application provides a digital key sharing method, which can directly interact with the terminal device to obtain a self-signed certificate of a terminal device that has not obtained the digital key, and the terminal device that has obtained the digital key can independently issue a new key certificate according to the self-signed certificate, thereby realizing the sharing of the digital key.
[0087] Please refer to Figure 2 which shows a method flowchart of a digital key sharing method provided by an exemplary embodiment of the present application, which can be executed by a first terminal device. The first terminal device can be the above-mentioned terminal device that has not opened the digital key. As Figure 2 shown, the digital key sharing method can include the following steps:
[0088] Step 201, receiving a first message, the first message is used to share the control right of the first vehicle controlled by a second terminal device to the first terminal device, and the second terminal device stores a first target certificate for controlling the first vehicle.
[0089] Among them, the first vehicle can be any brand of vehicle with a data key function in actual life, and the second terminal device is a terminal device that has completed the opening of the digital key with the first vehicle in advance. The second terminal device and the first vehicle can successfully open the digital key in the manner shown in the above Figure 1 , and store a first target certificate for controlling the first vehicle in itself. The first target certificate can include the key public key certificate and the vehicle public key certificate in the above Figure 1 , that is, the first target certificate includes the key certificate saved in the second terminal device during the opening of the digital key by the second terminal device for subsequent control of the first vehicle, and the vehicle public key certificate transmitted by the first vehicle.
[0090] The first terminal device is a terminal device without a digital key. In the present scheme, the first terminal device receives the first message to indicate that the second terminal device will share the control right of the first vehicle with the first terminal device, and the first terminal device performs the subsequent steps. Optionally, the first terminal device can receive the first message after establishing a close-range wireless communication with the second terminal device, and the second terminal device feeds back the first message to the first terminal device.
[0091] In step 202, a self-signed certificate is generated in response to the first message.
[0092] Optionally, after receiving the first message, the first terminal device can generate a self-signed certificate based on a certificate issuance scheme pre-set by itself.
[0093] In step 203, the self-signed certificate is sent to the second terminal device.
[0094] The first terminal device sends the self-signed certificate generated by itself to the second terminal device through a communication connection between the first terminal device and the second terminal device.
[0095] In step 204, the first target certificate and the second target certificate returned by the second terminal device are received, and the second target certificate is determined by the second terminal device according to the self-signed certificate.
[0096] The first terminal device receives the first target certificate returned by the second terminal device, that is, accepts each key certificate of the second terminal device for controlling the first vehicle and the second target certificate newly issued by the second terminal device. The second target certificate can indicate that the second terminal device shares the right of the digital key with the first terminal device. After receiving the first target certificate and the second target certificate, the first terminal device can control the first vehicle in the future, thereby realizing the sharing of the digital key between terminal devices.
[0097] To sum up, the first terminal device receives a first message for sharing the control right of the second terminal device to the first vehicle with the first terminal device, the second terminal device stores a first target certificate for controlling the first vehicle; in response to the first message, a self-signed certificate is generated; the self-signed certificate is sent to the second terminal device; the first target certificate and a second target certificate returned by the second terminal device are received, and the second target certificate is determined by the second terminal device according to the self-signed certificate. The first terminal device of the present application receives the first message for sharing the control right of the second terminal device to the first vehicle with the first terminal device, generates the self-signed certificate of the first terminal device, and receives the second target certificate determined by the second terminal device according to the self-signed certificate, so that the first terminal device obtains the control right of the first vehicle, completes the sharing process of the digital key, does not need the intervention of the server, and completes the issuance of the second target certificate based on the interaction between the two terminal devices, thereby improving the sharing speed and efficiency of the digital key between the terminal devices.
[0098] Next, the method shown in the above Figure 2 is described with the second terminal device as the execution subject. Please refer to Figure 3 , which shows a method flowchart of a digital key sharing method provided by an example embodiment of the present application, which can be executed by the second terminal device, which can be the terminal device with the digital key opened above. As shown in Figure 3 , the digital key sharing method can include the following steps:
[0099] Step 301, a first message is sent to the first terminal device, and the first message is used to share the control right of the second terminal device to the first vehicle with the first terminal device.
[0100] Among them, the second terminal device is a terminal device that has completed the digital key opening with the first vehicle in advance, and itself stores a first target certificate for controlling the first vehicle. In a possible implementation manner, the second terminal device can display a sharing control in the screen, and the control right of the second terminal device is shared with the first terminal device in the manner that the user triggers the sharing control, that is, when the user triggers the sharing control, the second terminal device sends the first message to the first terminal device.
[0101] Step 302, a self-signed certificate returned by the first terminal device based on the first message is received.
[0102] Among them, corresponding to the above step 203, the second terminal device will receive the self-signed certificate returned by the first terminal device.
[0103] Step 303, a second target certificate is issued according to the self-signed certificate and a second key pair, and the second key pair is a key pair corresponding to the first target certificate in the second terminal device.
[0104] Optionally, the first terminal device issues a second target certificate according to the obtained self-signed certificate and a second key pair. The second key pair is a key pair corresponding to the first target certificate in the second terminal device. Optionally, the second key pair is a key pair generated in a process of completing the digital key opening procedure by the second terminal device and the first vehicle. For example, in the digital key opening procedure completed by the second terminal device and the first vehicle as described above, the second terminal device generates a digital key key pair in step 105, and the second key pair can be the key pair generated by the second terminal device in this step. Figure 1
[0105] Optionally, the first terminal device reissues a certificate containing the subject information of the self-signed certificate of the first terminal device according to the second key pair and the self-signed certificate. The reissued certificate is the second target certificate.
[0106] In step 304, the second target certificate and the first target certificate are sent to the first terminal device.
[0107] Optionally, the second terminal device packages and sends the first target certificate stored by itself and the second target certificate reissued to the first terminal device, so as to realize sharing of the digital key between the terminal devices.
[0108] In summary, the first message is sent to the first terminal device, the first message is used to share the control right of the second terminal device to control the first vehicle to the first terminal device; the self-signed certificate returned by the first terminal device based on the first message is received; the second target certificate is issued according to the self-signed certificate and the second key pair, the second key pair is a key pair corresponding to the first target certificate in the second terminal device; and the second target certificate and the first target certificate are sent to the first terminal device. The second terminal device of the present application shares the first message for sharing the control right of the second terminal device to control the first vehicle to the first terminal device, issues the second target certificate according to the self-signed certificate and the second key pair, and sends it to the first terminal device, so that the first terminal device obtains the control right to control the first vehicle, completes the sharing process of the digital key, does not need the intervention of the server, completes the issuance of the second target certificate based on the interaction between the two terminal devices, and improves the sharing speed and efficiency of the digital key between the terminal devices.
[0109] Next, taking the sharing application between the first terminal device and the second terminal device as an example, the second terminal device issues a certificate to the first terminal device to complete sharing of the digital key through interaction between the first terminal device and the second terminal device. The interaction between the first terminal device and the second terminal device is described above Figure 2 and Figure 3 The embodiments shown are illustrative.
[0110] Please refer to Figure 4 , which shows a method flowchart of a digital key sharing method provided by an exemplary embodiment of the present application. The digital key sharing method can be executed by a first terminal device and a second terminal device. The first terminal device can be a terminal device without a digital key, and the second terminal device can be a terminal device with a digital key. As shown in Figure 4 , the digital key sharing method can include the following steps:
[0111] Step 401: The second terminal device sends a first message to the first terminal device.
[0112] The first message is used to share the control authority of the second terminal device to control the first vehicle to the first terminal device. The second terminal device stores a first target certificate for controlling the first vehicle.
[0113] The first terminal device and the second terminal device are as described above Figure 2 and Figure 3 in the embodiments, which will not be described here.
[0114] Optionally, the first terminal device and the second terminal device need to establish a near field wireless communication connection, such as a Bluetooth connection, an Ultra Wide Band (UWB), a Near Field Communication (NFC), etc., before executing the present scheme. In a possible implementation manner, the first message is a sharing request sent by the second terminal device. For example, after the second terminal device opens the digital key of the first vehicle, the second terminal device can actively send a sharing request to the first terminal device through the near field wireless communication connection, and then share the digital key authority owned by the second terminal device to the first terminal device. For example, the display screen of the second terminal device can display a sharing control. When a user clicks the sharing control, the second terminal device sends a sharing request to the first terminal device.
[0115] In a possible implementation manner, the first terminal device can also actively request the second terminal device to share the digital key to itself. For example, the first terminal device can send a sharing application to the second terminal device before receiving the first message. The sharing application includes an identifier of the first terminal device. The first message received by the first terminal device is a response message fed back by the second terminal device according to the sharing application. That is, the first terminal device receives a response message corresponding to the sharing application. The response message is sent by the second terminal device after verifying the identifier and passing the verification.
[0116] That is, the first terminal device carries its own identifier in the sharing application sent to the second terminal device in an active request manner, so that the second terminal device knows that the first terminal device needs to open the digital key for the first vehicle, and the second terminal device can feed back corresponding response information based on the sharing application, so as to indicate sharing the control right of the second terminal device to the first vehicle with the first terminal device.
[0117] At step 402, the first terminal device receives the first message.
[0118] Correspondingly, the first terminal device receives the first message sent by the second terminal device.
[0119] At step 403, the first terminal device generates a self-signed certificate in response to the first message.
[0120] In a possible implementation manner, after receiving the first message, the first terminal device generates a first key pair in response to the first message, and issues a self-signed certificate according to the first key pair. The first terminal device can be pre-configured with a manner of generating the first key pair, and when receiving the first message, the first terminal device can be triggered to generate the first key pair according to the manner, and use a private key in the first key pair to issue the self-signed certificate.
[0121] At step 404, the first terminal device sends the self-signed certificate to the second terminal device.
[0122] The first terminal device sends the generated self-signed certificate to the second terminal device through a communication connection between the first terminal device and the second terminal device after generating the self-signed certificate.
[0123] At step 405, the second terminal device receives the self-signed certificate returned by the first terminal device based on the first message.
[0124] Correspondingly, the second terminal device receives the self-signed certificate returned by the first terminal device.
[0125] At step 406, the second terminal device issues a second target certificate according to the self-signed certificate and a second key pair, and the second key pair is a key pair corresponding to the first target certificate in the second terminal device.
[0126] Optionally, the second terminal device reissues a second target certificate according to the received self-signed certificate and the key pair corresponding to the first target certificate, that is, the second target certificate is issued by the second terminal device according to the self-signed certificate and the second key pair. The second key pair is a key pair corresponding to the first public key certificate in the second terminal device. Optionally, the second target certificate can indicate that the second terminal device shares the control right of the digital key to the first vehicle with the first terminal device.
[0127] Optionally, the first target certificate includes the first public key certificate and the vehicle public key certificate. That is, the second terminal device performs the above-mentioned Figure 1 After the opening flow shown, the first vehicle stores the key public key certificate (i.e., the first public key certificate) last transmitted by the second terminal device and the vehicle public key certificate owned by itself, and the second terminal device also stores the vehicle public key certificate transmitted by the first vehicle and the key public key certificate (i.e., the first public key certificate) generated by itself.
[0128] In a possible implementation manner, the second terminal device can obtain the second key pair in advance before this step. For example, during the above-mentioned opening flow, after generating the digital key key pair (the second key pair) and the key public key certificate, the generated second key pair can be stored, and after receiving the self-signed certificate, the second key pair already stored is obtained. For example, the second terminal device can obtain the public key in the first public key certificate according to the first public key certificate, and obtain the second key pair corresponding to the public key according to the public key. For example, the second terminal device queries the key pair corresponding to the public key in the already stored key pair according to the public key in the first public key certificate, and the key pair is the second key pair, so as to obtain the second key pair.
[0129] In a possible implementation manner, after receiving the self-signed certificate of the first terminal device, the second terminal device obtains the subject information of the self-signed certificate according to the received self-signed certificate, and issues the second target certificate according to the private key in the second key pair and the subject information. That is, the second terminal device receives the self-signed certificate of the first terminal device, parses the subject information (tbsCertificate information) of the self-signed certificate, signs and generates the second target certificate using the private key of the second key pair.
[0130] Step 407, the second terminal device sends the second target certificate and the first target certificate to the first terminal device.
[0131] Optionally, the first public key certificate, the vehicle public key certificate and the above-mentioned newly issued second target certificate stored by the second terminal device are packaged and sent to the first terminal device.
[0132] Step 408, the first terminal device receives the first target certificate and the second target certificate returned by the second terminal device.
[0133] Correspondingly, the first terminal device receives the first public key certificate, the vehicle public key certificate and the above-mentioned newly issued second target certificate returned by the second terminal device, and saves the received first public key certificate, vehicle public key certificate and above-mentioned newly issued second target certificate locally. The second target certificate is determined by the second terminal device.
[0134] In a possible implementation, the second terminal device can further receive a revocation instruction, the revocation instruction being used to indicate that the first target certificate between the second terminal device and the first vehicle is invalid; in response to the revocation instruction, the first target certificate stored in the second terminal device is deleted; and the revocation instruction is sent to the first terminal device, so that the first terminal device deletes the stored second target certificate and the first target certificate. Correspondingly, the first terminal device can also receive the revocation instruction sent by the second terminal device, and in response to the revocation instruction, the first target certificate and the second target certificate are deleted.
[0135] For example, the second terminal device receives a revocation instruction initiated by the vehicle-mounted terminal of the first vehicle, and the first target certificate between the second terminal device and the first vehicle is invalid, so that the second terminal device closes the digital key for controlling the first vehicle. Then, the second terminal device can delete the first target certificate stored in the second terminal device in response to the revocation instruction, and send the revocation instruction to the first terminal device, so that the first terminal device deletes the stored second target certificate and the first target certificate. Optionally, the revocation instruction can also be generated by the second terminal device, and the present application does not limit this.
[0136] It should be noted that the first terminal device and the second terminal device in the present application can be terminal devices supporting a trusted execution environment (Trusted Execution Environment, TEE). The identity authentication, asymmetric encryption and decryption, signature, signature verification, and data storage between the first terminal device and the second terminal device can be performed by a Trusted Application (TA) program in the trusted environment of the TEE.
[0137] In summary, the first terminal device receives a first message, the first message being used to share the control right of the first vehicle controlled by the second terminal device to the first terminal device, and the second terminal device stores a first target certificate for controlling the first vehicle; in response to the first message, a self-signed certificate is generated; the self-signed certificate is sent to the second terminal device; the first target certificate and a second target certificate returned by the second terminal device are received, and the second target certificate is determined by the second terminal device according to the self-signed certificate. The first terminal device of the present application receives the first message used to share the control right of the first vehicle controlled by the second terminal device to the first terminal device, generates a self-signed certificate of the first terminal device, and receives the second target certificate determined by the second terminal device according to the self-signed certificate, so that the first terminal device obtains the control right of the first vehicle, completes the sharing process of the digital key, does not need the intervention of a server, and completes the issuance of the second target certificate based on the interaction between the two terminal devices, thereby improving the sharing speed and efficiency of the digital key between the terminal devices.
[0138] In addition, based on the effect of the certificate chain, the key certificate obtained by the first terminal device is one level lower than the key certificate of the second terminal device. When the key certificate of the second terminal device is revoked, the key certificate obtained by the first terminal device will also be automatically invalidated, and the unnecessary certificate chain is cleaned up in time.
[0139] In a possible implementation, after the sharing of the digital key is completed, the first terminal device can further establish a communication connection with the first vehicle, and control the first vehicle by the granted first target certificate and the second target certificate. Before the control, the first vehicle also needs to be authenticated with the second terminal device to achieve secure control.
[0140] Please refer to Figure 5 , which shows a method flowchart of a digital key sharing method provided by an example embodiment of the present application. The digital key sharing method can be executed by a first terminal device, which can be the first terminal device described above by Figure 2 Or Figure 4 The first terminal device shared the digital key by the second terminal device. As Figure 5 shown, the digital key sharing method can include the following steps:
[0141] Step 501, sending a first target certificate and a second target certificate to the first vehicle, the first target certificate and the second target certificate being sent by the second terminal device, the second terminal device storing a first target certificate for controlling the first vehicle, and the second target certificate being determined by the second terminal device according to the self-signed certificate of the first terminal device.
[0142] Among them, after the sharing of the digital key is completed, the first terminal device can establish a communication connection with the first vehicle, and control the first vehicle by the digital key opened by itself. Before the control, the first vehicle needs to verify the first terminal device, therefore, the first terminal device sends the first target certificate and the second target certificate received by the second terminal device to the first vehicle through the communication connection.
[0143] Among them, the second terminal device sends the first target certificate and the second target certificate to the first terminal device in the manner described above Figure 2 、 Figure 3 Or Figure 4 , which will not be described here.
[0144] Step 502, receiving a verification result of the first vehicle verifying the first target certificate and the second target certificate.
[0145] Optionally, after the first vehicle receives the first target certificate and the second target certificate sent by the first vehicle, the first vehicle verifies the first target certificate and the second target certificate respectively, and returns the verification result to the first terminal device. Correspondingly, the first terminal device receives the verification result returned by the first vehicle.
[0146] Step 503: When the verification result indicates that the first terminal device passes the verification, a secure channel is established with the first vehicle, and the first vehicle is controlled based on the secure channel.
[0147] Wherein, after the first terminal device receives the verification result, the first terminal device obtains the indication content of the verification result, and when the verification result indicates that the first terminal device passes the verification, a secure channel is established with the first vehicle, and the first vehicle is controlled based on the secure channel.
[0148] It should be noted that, Figure 5 The embodiments shown in the above Figure 2 , Figure 3 or Figure 4 The embodiments shown in the above
[0149] In summary, the first target certificate and the second target certificate are sent to the first vehicle, the first target certificate and the second target certificate are sent by the second terminal device, the second terminal device stores the first target certificate for controlling the first vehicle, and the second target certificate is determined by the second terminal device according to the self-signed certificate of the first terminal device; the verification result of the first target certificate and the second target certificate verified by the first vehicle is received; when the verification result indicates that the first terminal device passes the verification, a secure channel is established with the first vehicle, and the first vehicle is controlled based on the secure channel. The first terminal device of the present application sends the first target certificate and the second target certificate sent by the second terminal device to the first vehicle, and the first vehicle directly verifies the first target certificate and the second target certificate. When the verification is passed, the control right of the first vehicle can be autonomously controlled, the process of quickly controlling the first vehicle after the second terminal device shares the digital key to itself is realized, the server does not need to be involved, the issuance of the second target certificate is completed based on the interaction between the two terminal devices, and the sharing speed and efficiency of the digital key between the terminal devices are improved.
[0150] Next, the method shown in the above Figure 5 will be described with the first vehicle as the execution subject. Please refer to Figure 6 , which shows a method flowchart of a digital key sharing method provided by an example embodiment of the present application, which can be executed by the first vehicle. As shown in Figure 6 , the digital key sharing method can include the following steps:
[0151] In step 601, a first target certificate and a second target certificate sent by a first terminal device are received, the first target certificate and the second target certificate being sent by a second terminal device to the first terminal device, the second terminal device storing a first target certificate for controlling a first vehicle, and the second target certificate being determined by the second terminal device according to a self-signed certificate of the first terminal device.
[0152] Optionally, after the sharing of the digital key is completed, the first terminal device establishes a communication connection with the first vehicle, and the communication connection can be a Bluetooth connection. The first terminal device sends the first target certificate and the second target certificate received by the second terminal device to the first vehicle through the communication connection, and correspondingly, the first vehicle receives the first target certificate and the second target certificate sent by the first terminal device.
[0153] The interaction between the first terminal device and the second terminal device can refer to the description in the above Figure 2 Figure 3 or Figure 4 , and details are not described herein again.
[0154] In step 602, a verification result of the first vehicle verifying the first target certificate and the second target certificate is sent to the first terminal device.
[0155] Optionally, the first vehicle verifies the first target certificate and the second target certificate, obtains a verification result, and sends the verification result to the first terminal device.
[0156] In step 603, when the verification result indicates that the first terminal device passes the verification, a secure channel is established with the first vehicle, so that the first terminal device controls the first vehicle based on the secure channel.
[0157] When the verification result indicates that the first terminal device passes the verification, the first vehicle establishes a secure channel with the first terminal device subsequently.
[0158] In summary, the first target certificate and the second target certificate sent by the first terminal device are received, the first target certificate and the second target certificate are sent by the second terminal device to the first terminal device, the second terminal device stores the first target certificate for controlling the first vehicle, and the second target certificate is determined by the second terminal device according to the self-signed certificate of the first terminal device; the first vehicle is sent to the first terminal device to verify the verification result of the first target certificate and the second target certificate, and when the verification result indicates that the first terminal device passes the verification, a secure channel is established with the first vehicle, so that the first terminal device controls the first vehicle based on the secure channel. After the first terminal device of the present application obtains the first target certificate and the second target certificate sent by the second terminal device, the first target certificate and the second target certificate are sent to the first vehicle, and the first vehicle directly verifies, and when the verification is passed, the control right of the first vehicle can be autonomously controlled, realizing the process of quickly controlling the first vehicle after the second terminal device shares the digital key to itself, without the intervention of the server, and the issuance of the second target certificate is completed based on the interaction between the two terminal devices, improving the sharing speed and efficiency of the digital key between the terminal devices.
[0159] Next, the way of generating the same control symmetric key for data encryption interaction when establishing a secure channel between the first terminal device and the first vehicle is described, and the first terminal device controls the first vehicle. The interaction between the first terminal device and the first vehicle is used to illustrate the embodiments shown in Figure 5 and Figure 6 .
[0160] Please refer to Figure 7 , which shows a method flowchart of a digital key sharing method provided by an exemplary embodiment of the present application, which can be executed by the first terminal device and the first vehicle. As shown in Figure 7 , the digital key sharing method can include the following steps:
[0161] Step 701, the first terminal device sends the first target certificate and the second target certificate to the first vehicle.
[0162] Among them, the first target certificate and the second target certificate are sent by the second terminal device, the second terminal device stores the first target certificate for controlling the first vehicle, and the second target certificate is determined by the second terminal device according to the self-signed certificate of the first terminal device.
[0163] Step 702, the first vehicle receives the first target certificate and the second target certificate sent by the first terminal device.
[0164] Among them, the interaction mode between the first terminal device and the second terminal device can refer to the above Figure 2 , Figure 3 orFigure 4 The details are described in the foregoing description of the method, and are not repeated here.
[0165] In step 703, the first vehicle verifies the first target certificate and the second target certificate.
[0166] Optionally, the first vehicle verifies the first target certificate and the second target certificate in the following manner: the first vehicle verifies the first target certificate received this time based on the first target certificate stored in advance by the first vehicle. In the above case, the first target certificate includes the first public key certificate and the vehicle public key certificate, and the second terminal device and the first vehicle perform the opening flow shown in FIG. 6. After the opening flow, the first vehicle stores the key public key certificate (i.e., the first public key certificate) last transmitted by the second terminal device and the vehicle public key certificate owned by the first vehicle. In this step, the first vehicle verifies the first public key certificate and the vehicle public key certificate stored in advance, respectively. Figure 1
[0167] Optionally, since the first public key certificate stored in the first vehicle is sent by the second terminal device, when verifying the first public key certificate in the first target certificate of the first terminal device, the first vehicle also uses the public key in the first public key certificate stored in advance to verify the second target certificate, so as to ensure that the first public key certificate stored in the first vehicle and the first public key certificate received by the second terminal device are issued by the same first terminal device, thereby ensuring the consistency of the certificates.
[0168] In step 704, the first vehicle sends the verification result to the first terminal device.
[0169] Optionally, the first vehicle verifies the first target certificate and the second target certificate, obtains the verification result, and sends the verification result to the first terminal device.
[0170] In step 705, the first terminal device receives the verification result.
[0171] In step 706, when the verification result indicates that the first terminal device passes the verification, the first terminal device generates a control symmetric key.
[0172] The verification result indicates that the first terminal device passes the verification, which means that the first target certificate sent by the first terminal device to the first vehicle is the same as the first target certificate stored in the first vehicle, and the second target certificate sent by the first terminal device to the first vehicle is issued by the same second terminal device as the first public key certificate stored in the first vehicle.
[0173] Optionally, when the first target certificate sent by the first terminal device to the first vehicle is different from the first target certificate stored by the first vehicle itself, the verification result indicates that the first terminal device fails to pass the verification, and when the second target certificate sent by the first terminal device to the first vehicle is not the first public key certificate issued by the same second terminal device, the verification result indicates that the first terminal device fails to pass the verification.
[0174] Optionally, after the first terminal device learns that it passes the verification according to the verification result, the first terminal device can generate a control symmetric key according to a key agreement algorithm, which can be pre-set in the first terminal device. For example, the first terminal device inputs the device number of the first terminal device and the device number of the first vehicle into the key agreement algorithm to obtain a corresponding control symmetric key. The type of the generated control symmetric key is also the same.
[0175] In step 707, the first terminal device sends target data to the first vehicle.
[0176] The target data is data information used by the first terminal device to generate the control symmetric key, so that the first vehicle generates the same symmetric key as the control symmetric key according to the data information.
[0177] In step 708, the first vehicle receives the target data sent by the first terminal device.
[0178] In step 709, the first vehicle generates the same symmetric key as the control symmetric key according to the data information in the target data.
[0179] Optionally, during the process of steps 707 to 709, after the first terminal device generates the control symmetric key, the first terminal device also needs to send the target data to the first vehicle, so that the first vehicle also generates the same symmetric key using the same data information. For example, the data information used by the first terminal device is the device number of the first terminal device and the device number of the first vehicle. In this step, the device number of the first terminal device and the device number of the first vehicle are packaged and sent to the first vehicle, so that the first vehicle generates the same symmetric key as the control symmetric key according to the data information.
[0180] In step 710, the first terminal device and the first vehicle establish a secure channel.
[0181] Optionally, the first terminal device and the first vehicle complete the establishment of the secure channel for transmitting data, and subsequent transmitted instructions are encrypted by the same control symmetric key and transmitted based on the secure channel. That is, the first terminal device controls the first vehicle based on the control symmetric key and the secure channel.
[0182] It should be noted that, Figure 7 The scheme shown can also be combined with the aboveFigure 5 The scheme shown combines application, completes the sharing of the digital key and the process of authenticating the shared terminal device by the first vehicle, so that the shared terminal device controls the first vehicle through the digital key obtained by sharing, without introducing a server, and improves the sharing efficiency of the digital key. In addition, when the first terminal device and the first vehicle perform encrypted communication, an Intrusion Detection & Prevention System (IDPS) can also be introduced to further enhance system security.
[0183] In summary, the first target certificate and the second target certificate are sent to the first vehicle, the first target certificate and the second target certificate are sent by the second terminal device, the second terminal device stores the first target certificate for controlling the first vehicle, and the second target certificate is determined by the second terminal device according to the self-signed certificate of the first terminal device; a verification result of verifying the first target certificate and the second target certificate by the first vehicle is received; when the verification result indicates that the first terminal device passes the verification, a secure channel is established with the first vehicle, and the first vehicle is controlled based on the secure channel. After the first terminal device obtains the first target certificate and the second target certificate sent by the second terminal device, the first target certificate and the second target certificate are sent to the first vehicle, and the first vehicle directly performs verification, and when the verification passes, the control right of the first vehicle can be autonomously controlled, the process of quickly controlling the first vehicle after the second terminal device shares the digital key to itself is realized, the server does not need to be involved, the second target certificate is issued based on the interaction between the two terminal devices, and the sharing speed and efficiency of the digital key between the terminal devices are improved.
[0184] Next, taking the first terminal device as the owner master device and the second terminal device as the owner auxiliary device as an example, after the user opens the digital key of the first vehicle based on the owner master device, the digital key is shared to the owner auxiliary device by using the scheme, and the first vehicle is controlled by the owner auxiliary device.
[0185] Please refer to Figure 8 which shows a method flowchart of a digital key sharing method provided by an example embodiment of the application, which can be executed by an owner master device, an owner auxiliary device and a first vehicle. As shown in Figure 8 The digital key sharing method can include the following steps:
[0186] Step 801, the owner master device initiates a sharing command to the owner auxiliary device.
[0187] The sharing command is equivalent to the first message in the above embodiment.
[0188] Step 802, the owner secondary device generates a first key pair and issues a self-signed certificate.
[0189] Optionally, the first key pair can be an Elliptic Curves Cryptography (ECC) key pair.
[0190] Step 803, the owner secondary device transmits the self-signed certificate to the owner primary device.
[0191] Step 804, the owner primary device issues a secondary key certificate according to the self-signed certificate and a second key pair.
[0192] Optionally, the second key pair is generated when the owner primary device opens the digital key of the first vehicle, that is, the digital key pair generated in step 105.
[0193] Step 805, the owner primary device sends the primary key certificate, the secondary key certificate and the vehicle public key certificate to the owner secondary device.
[0194] The primary key certificate is a key public key certificate saved by the owner primary device when opening the digital key, and the vehicle public key certificate is a key public key certificate saved by the first vehicle when opening the digital key.
[0195] Step 806, the owner secondary device saves the primary key certificate, the secondary key certificate and the vehicle public key certificate in the local TEE.
[0196] Step 807, the owner secondary device establishes a Bluetooth connection with the first vehicle for the first time.
[0197] Step 808, the owner secondary device sends the primary key certificate, the secondary key certificate and the vehicle public key certificate to the first vehicle.
[0198] Step 809, the first vehicle verifies the primary key certificate, the secondary key certificate and the vehicle public key certificate.
[0199] The first vehicle verifies the consistency of the primary key certificate and the vehicle public key certificate with the certificates saved on the first vehicle side, and verifies the secondary key certificate using the saved public key of the owner primary device, and finally obtains a verification result.
[0200] Step 810, the first vehicle returns the verification result to the owner secondary device.
[0201] Step 811, when the verification result indicates that the verification is passed, the owner secondary device generates a symmetric key using a key agreement algorithm.
[0202] Step 812, the owner secondary device sends target data of generating the symmetric key to the first vehicle.
[0203] Step 813, the first vehicle generates the same symmetric key according to the target data.
[0204] Step 814, the first vehicle and the owner secondary device establish a secure channel.
[0205] After the verification passes, the first vehicle and the owner secondary device will establish a secure channel according to the key negotiation algorithm. The key negotiation algorithm and the type of symmetric key are not limited here.
[0206] In summary, the owner secondary device of the present application receives the sharing command sent by the owner primary device, generates a self-signed certificate of the owner secondary device, and receives the secondary key certificate determined by the owner primary device according to the self-signed certificate, so that the owner secondary device obtains the control right of the first vehicle, completes the sharing process of the digital key, does not need the intervention of the server, and completes the issuance of the secondary key certificate based on the interaction between the two terminal devices, thereby improving the sharing speed and efficiency of the digital key between the terminal devices.
[0207] In addition, the owner primary device replaces the introduction of the cloud server in the key sharing of the general solution of the digital key by realizing part of the functions of the cloud server, shortens the link of authentication and opening of the key during sharing, and can effectively achieve the optimization purpose of fast sharing of the digital key. In some scenarios, such as basements and other places with relatively poor network environment, the digital key needs to be shared, and it is not necessary to connect to the server, which can enhance the scene coverage of the digital key function and expand the application scenarios.
[0208] The following is an embodiment of the device of the present application, which can be used to execute the method embodiment of the present application. For details not disclosed in the device embodiment of the present application, please refer to the method embodiment of the present application.
[0209] Please refer to Figure 9 which shows the structure block diagram of the digital key sharing device provided by an exemplary embodiment of the present application. The digital key sharing device 900 can be used in the first terminal device to execute Figure 2 or Figure 4 all or part of the steps executed by the first terminal device in the method provided by the embodiment. The digital key sharing device 900 includes:
[0210] The first receiving module 901 is configured to receive a first message, wherein the first message is used to share the control right of the first vehicle controlled by the second terminal device to the first terminal device, and the second terminal device stores a first target certificate for controlling the first vehicle.
[0211] The first generating module 902 is configured to generate a self-signed certificate in response to the first message.
[0212] The first sending module 903 is configured to send the self-signed certificate to the second terminal device.
[0213] The second receiving module 904 is configured to receive the first target certificate and a second target certificate returned by the second terminal device, wherein the second target certificate is determined by the second terminal device according to the self-signed certificate.
[0214] In summary, the first terminal device receives a first message, the first message is used to share the control right of the first vehicle controlled by the second terminal device to the first terminal device, and the second terminal device stores a first target certificate for controlling the first vehicle; in response to the first message, a self-signed certificate is generated; the self-signed certificate is sent to the second terminal device; and the first target certificate and a second target certificate returned by the second terminal device are received, wherein the second target certificate is determined by the second terminal device according to the self-signed certificate. The first terminal device of the present application receives the first message used to share the control right of the first vehicle controlled by the second terminal device to the first terminal device, generates a self-signed certificate of the first terminal device, and receives a second target certificate determined by the second terminal device according to the self-signed certificate, so that the first terminal device obtains the control right of the first vehicle, completes the sharing process of the digital key, does not need the intervention of a server, and completes the issuance of the second target certificate based on the interaction between the two terminal devices, thereby improving the sharing speed and efficiency of the digital key between the terminal devices.
[0215] Optionally, the first generating module 902 includes a first generating unit and a first issuing unit.
[0216] The first generating unit is configured to generate a first key pair in response to the first message.
[0217] The first issuing unit is configured to issue the self-signed certificate according to the first key pair.
[0218] Optionally, the first message is a sharing request sent by the second terminal device.
[0219] Optionally, the apparatus further includes:
[0220] The sixth sending module is configured to send a sharing application to the second terminal device before receiving the first message, wherein the sharing application includes an identifier of the first terminal device.
[0221] The first receiving module 901 is further configured to receive a response message corresponding to the sharing application, wherein the response message is sent by the second terminal device after verification according to the identifier.
[0222] Optionally, the first target certificate includes a first public key certificate and a vehicle public key certificate.
[0223] The second target certificate is issued by the second terminal device according to the self-signed certificate and a second key pair, the second key pair being a key pair corresponding to the first target certificate in the second terminal device.
[0224] Optionally, the apparatus further comprises:
[0225] The sixth receiving module is configured to receive a revocation instruction sent by the second terminal device after receiving the first target certificate and the second target certificate returned by the second terminal device, the revocation instruction being used to indicate that the first target certificate between the second terminal device and the first vehicle is invalid.
[0226] The first deleting module is configured to delete the first target certificate and the second target certificate in response to the revocation instruction.
[0227] Please refer to Figure 10 , which shows a structural block diagram of a digital key sharing apparatus provided by an example embodiment of the present application. The digital key sharing apparatus 1000 can be used in a second terminal device to perform Figure 3 or Figure 4 all or part of the steps performed by the second terminal device in the method provided by the example embodiment. The digital key sharing apparatus 1000 comprises:
[0228] The second sending module 1001 is configured to send a first message to a first terminal device, the first message being used to share a control right of the second terminal device to control the first vehicle to the first terminal device.
[0229] The third receiving module 1002 is configured to receive a self-signed certificate returned by the first terminal device based on the first message.
[0230] The first issuing module 1003 is configured to issue a second target certificate according to the self-signed certificate and a second key pair, the second key pair being a key pair corresponding to the first target certificate in the second terminal device.
[0231] The third sending module 1004 is configured to send the second target certificate and the first target certificate to the first terminal device.
[0232] In summary, the first terminal device is sent a first message, the first message is used to share the control right of the second terminal device controlling the first vehicle to the first terminal device; a self-signed certificate returned by the first terminal device based on the first message is received; a second target certificate is issued according to the self-signed certificate and a second key pair, the second key pair is a key pair corresponding to the first target certificate in the second terminal device; and the second target certificate and the first target certificate are sent to the first terminal device. The second terminal device of the application shares the first message used to share the control right of the second terminal device controlling the first vehicle to the first terminal device, issues the second target certificate according to the self-signed certificate and the second key pair, and sends the second target certificate to the first terminal device, so that the first terminal device obtains the control right of controlling the first vehicle, completes the sharing process of the digital key, does not need the intervention of a server, completes the issuance of the second target certificate based on the interaction between the two terminal devices, and improves the sharing speed and efficiency of the digital key between the terminal devices.
[0233] Optionally, the first target certificate includes a first public key certificate and a vehicle public key certificate, and the apparatus further includes:
[0234] a first obtaining module, configured to, before issuing the second target certificate according to the self-signed certificate and the second key pair, obtain a public key in the first public key certificate according to the first public key certificate;
[0235] a second obtaining module, configured to obtain the second key pair corresponding to the public key according to the public key.
[0236] Optionally, the first issuing module 1003 includes a first obtaining unit and a second issuing unit.
[0237] The first obtaining unit is configured to obtain subject information of the self-signed certificate according to the self-signed certificate.
[0238] The second issuing unit is configured to issue the second target certificate according to a private key in the second key pair and the subject information.
[0239] Optionally, the apparatus further includes:
[0240] a seventh receiving module, configured to, after sending the second target certificate and the first target certificate to the first terminal device, receive a revocation instruction, the revocation instruction being used to indicate that the first target certificate between the second terminal device and the first vehicle is invalid;
[0241] a second deleting module, configured to, in response to the revocation instruction, delete the first target certificate stored in the second terminal device;
[0242] A seventh sending module is configured to send the revocation instruction to the first terminal device, so that the first terminal device deletes the stored second target certificate and the first target certificate.
[0243] Please refer to Figure 11 which shows a structural block diagram of a digital key sharing apparatus provided by an exemplary embodiment of the present application. The digital key sharing apparatus 1100 can be used in a first terminal device to perform Figure 5 or Figure 7 all or part of the steps performed by the first terminal device in the method provided by the embodiments shown. The digital key sharing apparatus 1100 includes:
[0244] A fourth sending module 1101 is configured to send a first target certificate and a second target certificate to a first vehicle, wherein the first target certificate and the second target certificate are sent by a second terminal device, the second terminal device stores the first target certificate for controlling the first vehicle, and the second target certificate is determined by the second terminal device according to a self-signed certificate of the first terminal device.
[0245] A fourth receiving module 1102 is configured to receive a verification result of verification of the first target certificate and the second target certificate by the first vehicle.
[0246] A first control module 1103 is configured to, when the verification result indicates that the first terminal device passes the verification, establish a communication connection with the first vehicle and control the first vehicle based on the communication connection.
[0247] In summary, the first target certificate and the second target certificate are sent to the first vehicle, the first target certificate and the second target certificate are sent by the second terminal device, the second terminal device stores the first target certificate for controlling the first vehicle, and the second target certificate is determined by the second terminal device according to the self-signed certificate of the first terminal device; the verification result of verification of the first target certificate and the second target certificate by the first vehicle is received; when the verification result indicates that the first terminal device passes the verification, a secure channel is established with the first vehicle, and the first vehicle is controlled based on the secure channel. After the first terminal device of the present application obtains the first target certificate and the second target certificate sent by the second terminal device, the first target certificate and the second target certificate are sent to the first vehicle, and the first vehicle directly performs verification, and when the verification passes, the control right of the first vehicle can be autonomously controlled, the process of quickly controlling the first vehicle after the second terminal device shares the digital key to itself is realized, the server does not need to be involved, the issuance of the second target certificate is completed based on the interaction between the two terminal devices, and the sharing speed and efficiency of the digital key between the terminal devices are improved.
[0248] Optionally, the first control module 1103 comprises a second generation unit and a first control unit.
[0249] The second generation unit is configured to generate a control symmetric key.
[0250] The first control unit is configured to control the first vehicle based on the control symmetric key and the secure channel.
[0251] Optionally, the apparatus further comprises:
[0252] An eighth sending module is configured to send target data to the first vehicle after the control symmetric key is generated, the target data being data information used by the first terminal device to generate the control symmetric key, so that the first vehicle generates a symmetric key same as the control symmetric key according to the data information.
[0253] Please refer to Figure 12 which shows a structural block diagram of a digital key sharing apparatus provided by an example embodiment of the present application. The digital key sharing apparatus 1200 can be used in a first vehicle to perform Figure 6 or Figure 7 all or part of the steps performed by the first vehicle in the method provided by the example embodiment. The digital key sharing apparatus 1200 comprises:
[0254] A fifth receiving module 1201 is configured to receive a first target certificate and a second target certificate sent by a first terminal device, the first target certificate and the second target certificate being sent to the first terminal device by a second terminal device, the second terminal device storing the first target certificate used to control the first vehicle, and the second target certificate being determined by the second terminal device according to a self-signed certificate of the first terminal device.
[0255] A fifth sending module 1202 is configured to send a verification result of verification of the first target certificate and the second target certificate by the first vehicle to the first terminal device.
[0256] A first control module 1203 is configured to, when the verification result indicates that the first terminal device passes the verification, establish a communication connection with the first vehicle, so that the first terminal device controls the first vehicle based on the communication connection.
[0257] In summary, the first target certificate and the second target certificate sent by the first terminal device are received, the first target certificate and the second target certificate are sent by the second terminal device to the first terminal device, the second terminal device stores the first target certificate for controlling the first vehicle, and the second target certificate is determined by the second terminal device according to the self-signed certificate of the first terminal device; the first terminal device sends the first vehicle the verification result of the first target certificate and the second target certificate; when the verification result indicates that the first terminal device passes the verification, a secure channel is established with the first vehicle, so that the first terminal device controls the first vehicle based on the secure channel. The first terminal device of the present application sends the first target certificate and the second target certificate to the first vehicle after obtaining the first target certificate and the second target certificate sent by the second terminal device, and the first vehicle directly verifies the first target certificate and the second target certificate. When the verification is passed, the control right of the first vehicle can be autonomously controlled, the process of quickly controlling the first vehicle after the second terminal device shares the digital key with itself is realized, the server does not need to be intervened, the issuance of the second target certificate is completed based on the interaction between the two terminal devices, and the sharing speed and efficiency of the digital key between the terminal devices are improved.
[0258] Optionally, the first control module 1203 comprises a first receiving unit and a third generating unit.
[0259] The first receiving unit is configured to receive target data sent by the first terminal device, wherein the target data is data information generated by the first terminal device for controlling a symmetric key.
[0260] The third generating unit is configured to generate a symmetric key same as the control symmetric key according to the data information in the target data, so that the first terminal device controls the first vehicle based on the control symmetric key and the secure channel.
[0261] Please refer to Figure 13 which shows a structural schematic diagram of a terminal device provided by an example embodiment of the present application. As shown in Figure 13 , the terminal device comprises a processor 1310, a transceiver 1320 and a display unit 1370. The display unit 1370 can comprise a display screen.
[0262] Optionally, the terminal device can further comprise a memory 1330. The processor 1310, the transceiver 1320 and the memory 1330 can communicate with each other through an internal connection path to transfer ranging data. The memory 1330 is configured to store a computer program, and the processor 1310 is configured to call and run the computer program from the memory 1330.
[0263] The processor 1310 described above can be integrated with the memory 1330 into one processing device, and more commonly, be independent components from each other, and the processor 1310 is configured to execute program codes stored in the memory 1330 to implement the functions described above. In a specific implementation, the memory 1330 can also be integrated in the processor 1310, or be independent of the processor 1310.
[0264] It can be understood that, Figure 13 The terminal device shown can include one or more processing units, for example: the processor 1310 can include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units can be independent devices, or can be integrated in one or more processors.
[0265] The processor 1310 can also be provided with a memory for storing instructions and data. In some embodiments, the memory in the processor 1310 is a cache memory. The memory can save instructions or data that the processor 1310 has just used or repeatedly uses. If the processor 1310 needs to use the instructions or data again, it can directly call from the memory. Avoiding repeated access, reducing the waiting time of the processor 1310, thus improving the efficiency of the system.
[0266] In some embodiments, the processor 1310 can include one or more interfaces. The interfaces can include an inter-integrated circuit (I-C) interface, an inter-integrated circuit sound (I-S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.
[0267] The UART interface is a universal serial data bus for asynchronous communication. The bus can be a bidirectional communication bus. It converts the data to be transmitted between serial communication and parallel communication. In some embodiments, the UART interface is usually used to connect the processor 1310 and the transceiver 1320. For example, the processor 1310 communicates with the Bluetooth module in the transceiver 1320 through the UART interface to realize the Bluetooth function.
[0268] The MIPI interface can be used to connect the processor 1310 and peripheral devices such as the display unit 1370. The MIPI interface includes a camera serial interface (CSI), a display screen serial interface (DSI), etc. In some embodiments, the processor 1310 and the display unit 1370 communicate through the DSI interface to realize the display function of the terminal device.
[0269] The GPIO interface can be configured by software. The GPIO interface can be configured as a control signal or as a data signal. In some embodiments, the GPIO interface can be used to connect the processor 1310 and the display unit 1370, the transceiver 1320, etc. The GPIO interface can also be configured as an I13C interface, an I13S interface, a UART interface, a MIPI interface, etc.
[0270] The transceiver 1320 can provide a wireless communication solution applied to the terminal device, including wireless local area networks (WLAN) (such as a wireless fidelity (Wi-Fi) network), Bluetooth (BT), a global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR) technology, and the like. The transceiver 1320 can be one or more devices integrated with at least one communication processing module, for example, can include a Bluetooth module.
[0271] The memory 1330 can be configured to store computer-executable program codes including instructions. The memory 1330 can include a program storage area and a data storage area. The program storage area can store an operating system, at least one application program (such as a sound playing program, an image playing program, etc.) required by at least one function, and the like. The data storage area can store data (such as positioning data) created during use of the terminal device, and the like. In addition, the memory 1330 can include a high-speed random access memory, and can further include a nonvolatile memory such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), and the like. The processor 1310 executes various function applications and data processing of the terminal device by running the instructions stored in the memory 1330 and / or the instructions stored in the memory arranged in the processor.
[0272] In addition, in order to make the function of the terminal device more perfect, the terminal device can further include one or more of a power supply 1350, an input unit 1360, an audio circuit 1380, and a sensor 1302, and the like.
[0273] The power supply 1350 is configured to supply power to various devices or circuits in the terminal device. Preferably, the power supply 1350 can be logically connected to the processor 1310 through a power management device, so as to realize functions such as management of charging, discharging, and power consumption management through the power management device.
[0274] The input unit 1360 can be used to receive inputted digital or character information, and to generate key signal input related to user settings of the terminal device and function control. Specifically, the input unit 1360 can include a touch panel and other input devices. The touch panel, also called a touch screen, can collect a user's touch operation on or near it, such as the user's operation on or near the touch panel using a finger, a stylus, or any suitable object or accessory, and drive the corresponding connection device according to the pre-set program. Optionally, the touch panel can include two parts, a touch detection device and a touch controller. The touch detection device detects the user's touch position and detects the signal generated by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device, converts it into touch coordinates, and sends it to the processor 1310, and can also receive commands from the processor 1310 and execute them. In addition, the touch panel can be implemented in various types such as resistive, capacitive, infrared, and surface acoustic wave. In addition to the touch panel, the input unit 1360 can also include other input devices. Specifically, the other input devices can include one or more of a function key, a trackball, an operation lever, etc.
[0275] The display unit 1370 can be used to display information input by the user or information provided to the user, as well as various menus of the terminal device. The display unit 1370 can include a display panel, which can be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), etc. Further, a touch panel can cover the display panel, and when the touch panel detects a touch operation on or near it, it transmits to the processor 1310 to determine the type of touch event, and then the processor 1310 provides corresponding visual output on the display panel according to the type of touch event.
[0276] The terminal device can also include at least one sensor 1302, such as a gyroscope sensor, a motion sensor, and other sensors. Specifically, the gyroscope sensor can be used to determine the motion posture of the terminal device. In some embodiments, the angular velocity of the terminal device around three axes (i.e., x, y, and z axes) can be determined by the gyroscope sensor. The gyroscope sensor can also be used for navigation, motion sensing game scenarios. As one of the motion sensors, the acceleration sensor can detect the magnitude of acceleration in each direction (i.e., x, y, and z axes), and when at rest, it can detect the magnitude and direction of gravity, which can be used for applications that identify the posture of the terminal device (such as landscape / portrait switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc. As for other sensors that the terminal device can also be configured, such as a manometer, a barometer, a hygrometer, a thermometer, an infrared sensor, etc., will not be described here.
[0277] The audio circuit 1380 can include a speaker and a microphone to provide audio interface between the user and the terminal device. The audio circuit 1380 can convert the received audio data into an electrical signal, and transmit the electrical signal to the speaker to be converted into a sound signal and output by the speaker. On the other hand, the microphone collects a sound signal, and converts the sound signal into an electrical signal, which is received by the audio circuit 1380 and converted into audio data. The audio data is output to the processor 1310 for processing, and then transmitted to another terminal device via the RF circuit, or output to the memory 1330 for further processing.
[0278] It can be understood that the structure of the embodiments of the present application does not constitute a specific limitation on the terminal device. In other embodiments of the present application, the terminal device can include more or fewer components than the illustrated components, or combine certain components, or split certain components, or different component arrangements. The illustrated components can be implemented in hardware, software, or a combination of software and hardware.
[0279] The embodiments of the present application also provide a computer readable medium, which stores at least one instruction, at least one program, a code set or an instruction set, and the at least one instruction, the at least one program, the code set or the instruction set are loaded and executed by the processor to implement the digital key sharing method as described in the various embodiments above.
[0280] The embodiments of the present application also provide a computer program product, which stores at least one instruction, and the at least one instruction is loaded and executed by the processor to implement the digital key sharing method as described in the various embodiments above.
[0281] It should be noted that: the apparatus provided by the above embodiments is executed, and only the division of the above functional modules is exemplified, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus and method embodiments provided by the above embodiments belong to the same concept, and the specific implementation process is detailed in the method embodiments, which will not be described here.
[0282] The serial numbers of the above embodiments of the present application are only for description, not representing the advantages and disadvantages of the embodiments.
[0283] Those of ordinary skill in the art can understand that all or part of the steps of the above embodiments can be completed by hardware, or by programs instructing relevant hardware to complete, and the programs can be stored in a computer readable storage medium, and the storage medium mentioned above can be a read-only memory, a disk or an optical disk.
[0284] The above merely provides the optional embodiments of the present application, and is not intended to limit the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A digital key sharing method characterized by, The method applied to a first terminal device comprises: receiving a first message, the first message being used for sharing, by a second terminal device, a control right of controlling a first vehicle to the first terminal device, the second terminal device storing a first target certificate used for controlling the first vehicle, the first target certificate comprising a first public key certificate; in response to the first message, generating a self-signed certificate; sending the self-signed certificate to the second terminal device; receiving the first target certificate and a second target certificate returned by the second terminal device, the second target certificate being issued by the second terminal device according to the self-signed certificate and a second key pair, the second key pair being a key pair corresponding to the first public key certificate in the second terminal device.
2. The method of claim 1, wherein, The response to the first message, generating a self-signed certificate, comprises: in response to the first message, generating a first key pair; issuing the self-signed certificate according to the first key pair.
3. The method according to claim 1 or 2, characterized in that, The first message is a sharing request sent by the second terminal device.
4. The method according to claim 1 or 2, characterized in that, Before the receiving a first message, the method further comprises: sending a sharing application to the second terminal device, the sharing application comprising an identifier of the first terminal device; the receiving a first message comprises: receiving a response message corresponding to the sharing application, the response message being sent by the second terminal device after verification according to the identifier.
5. The method according to claim 1 or 2, characterized in that, The first target certificate further comprises a vehicle public key certificate.
6. The method of claim 1 or 2, wherein, After the receiving the first target certificate and the second target certificate returned by the second terminal device, the method further comprises: receiving a revocation instruction sent by the second terminal device, the revocation instruction being used for indicating that the first target certificate between the second terminal device and the first vehicle is invalid; in response to the revocation instruction, deleting the first target certificate and the second target certificate.
7. A digital key sharing method characterized by, The method applied to a second terminal device, the second terminal device storing a first target certificate used for controlling a first vehicle, the first target certificate comprising a first public key certificate, the method comprising: sending a first message to a first terminal device, the first message being used for sharing, by the second terminal device, a control right of controlling the first vehicle to the first terminal device; receiving a self-signed certificate returned by the first terminal device based on the first message; issuing a second target certificate according to the self-signed certificate and a second key pair, the second key pair being a key pair corresponding to the first public key certificate in the first target certificate in the second terminal device; sending the second target certificate and the first target certificate to the first terminal device.
8. The method of claim 7, wherein, The first target certificate further comprises a vehicle public key certificate, before the issuing a second target certificate according to the self-signed certificate and a second key pair, the method further comprises: obtaining a public key in the first public key certificate according to the first public key certificate; obtaining the second key pair corresponding to the public key according to the public key.
9. The method of claim 7, wherein, The issuing a second target certificate according to the self-signed certificate and a second key pair comprises: obtaining subject information of the self-signed certificate according to the self-signed certificate; According to the private key in the second key pair and the subject information, the second target certificate is issued.
10. The method according to any one of claims 7 to 9, characterized in that, After the second target certificate and the first target certificate are sent to the first terminal device, the method further includes: receiving a revocation instruction, the revocation instruction being used to indicate that the first target certificate between the second terminal device and the first vehicle is invalid; in response to the revocation instruction, deleting the first target certificate stored in the second terminal device; and sending the revocation instruction to the first terminal device, so that the first terminal device deletes the second target certificate and the first target certificate stored.
11. A digital key sharing method, characterized by, Applied to a first terminal device, the method includes: sending a first target certificate and a second target certificate to a first vehicle, the first target certificate and the second target certificate being sent by a second terminal device, the second terminal device storing the first target certificate for controlling the first vehicle, the first target certificate including a first public key certificate, the second target certificate being issued by the second terminal device according to a self-signed certificate of the first terminal device and a second key pair, the second key pair being a key pair corresponding to the first public key certificate in the second terminal device; receiving a verification result of the first vehicle verifying the first target certificate and the second target certificate; when the verification result indicates that the first terminal device passes the verification, establishing a secure channel with the first vehicle and controlling the first vehicle based on the secure channel.
12. The method of claim 11, wherein, The establishment of the secure channel with the first vehicle and the control of the first vehicle based on the secure channel include: generating a control symmetric key; controlling the first vehicle based on the control symmetric key and the secure channel.
13. The method of claim 12, wherein, After the generation of the control symmetric key, the method further includes: sending target data to the first vehicle, the target data being data information used by the first terminal device to generate the control symmetric key, so that the first vehicle generates a symmetric key same as the control symmetric key according to the data information.
14. A digital key sharing method characterized by, Applied to a first vehicle, the method includes: receiving a first target certificate and a second target certificate sent by a first terminal device, the first target certificate and the second target certificate being sent by a second terminal device to the first terminal device, the second terminal device storing the first target certificate for controlling the first vehicle, the first target certificate including a first public key certificate, the second target certificate being issued by the second terminal device according to a self-signed certificate of the first terminal device and a second key pair, the second key pair being a key pair corresponding to the first public key certificate in the second terminal device; sending a verification result of the first vehicle verifying the first target certificate and the second target certificate to the first terminal device; when the verification result indicates that the first terminal device passes the verification, establishing a secure channel with the first vehicle, so that the first terminal device controls the first vehicle based on the secure channel.
15. The method of claim 14, wherein, The establishing the secure channel with the first vehicle enables the first terminal device to control the first vehicle based on the secure channel, including: receiving target data sent by the first terminal device, the target data being data information generated by the first terminal device for controlling symmetric key use; generating a symmetric key same as the control symmetric key according to the data information in the target data, so that the first terminal device controls the first vehicle based on the control symmetric key and the secure channel.
16. A digital key sharing device, characterized by The application is applied to a first terminal device, and the device includes: A first receiving module is configured to receive a first message, the first message being used to share control authority of a second terminal device for controlling a first vehicle to the first terminal device, the second terminal device storing a first target certificate for controlling the first vehicle, the first target certificate including a first public key certificate; A first generating module is configured to generate a self-signed certificate in response to the first message; A first sending module is configured to send the self-signed certificate to the second terminal device; A second receiving module is configured to receive the first target certificate and a second target certificate returned by the second terminal device, the second target certificate being issued by the second terminal device according to the self-signed certificate and a second key pair, the second key pair being a key pair corresponding to the first public key certificate in the second terminal device.
17. A digital key sharing device, characterized by The application is applied to a second terminal device, the second terminal device storing a first target certificate for controlling a first vehicle, the first target certificate including a first public key certificate, and the device includes: A second sending module is configured to send a first message to a first terminal device, the first message being used to share control authority of the second terminal device for controlling the first vehicle to the first terminal device; A third receiving module is configured to receive a self-signed certificate returned by the first terminal device based on the first message; A first issuing module is configured to issue a second target certificate according to the self-signed certificate and a second key pair, the second key pair being a key pair corresponding to the first public key certificate in the first target certificate in the second terminal device; A third sending module is configured to send the second target certificate and the first target certificate to the first terminal device.
18. A digital key sharing device, characterized by The application is applied to a first terminal device, and the device includes: A fourth sending module is configured to send a first target certificate and a second target certificate to a first vehicle, the first target certificate and the second target certificate being sent by a second terminal device, the second terminal device storing the first target certificate for controlling the first vehicle, the first target certificate including a first public key certificate, the second target certificate being issued by the second terminal device according to a self-signed certificate of the first terminal device and a second key pair, the second key pair being a key pair corresponding to the first public key certificate in the second terminal device; A fourth receiving module is configured to receive a verification result of the first vehicle for verifying the first target certificate and the second target certificate. The first control module is configured to establish a communication connection with the first vehicle when the verification result indicates that the first terminal device passes the verification, and control the first vehicle based on the communication connection.
19. A digital key sharing device, characterized by The device is applied to a first vehicle, and the device comprises: The fifth receiving module is configured to receive a first target certificate and a second target certificate sent by a first terminal device, the first target certificate and the second target certificate being sent to the first terminal device by a second terminal device, the second terminal device storing the first target certificate for controlling the first vehicle, the first target certificate comprising a first public key certificate, the second target certificate being issued by the second terminal device according to a self-signed certificate of the first terminal device and a second key pair, the second key pair being a key pair corresponding to the first public key certificate in the second terminal device; The fifth sending module is configured to send, to the first terminal device, a verification result of the first vehicle verifying the first target certificate and the second target certificate. The first control module is configured to establish a communication connection with the first vehicle when the verification result indicates that the first terminal device passes the verification, and control the first vehicle based on the communication connection.
20. A terminal device, comprising: The terminal device comprises a processor and a memory, the memory storing at least one instruction, at least one program, a code set or an instruction set, the at least one instruction, the at least one program, the code set or the instruction set being loaded and executed by the processor to implement the digital key sharing method according to any one of claims 1 to 13.
21. A vehicle characterized by The vehicle comprises a processor and a memory, the memory storing at least one instruction, at least one program, a code set or an instruction set, the at least one instruction, the at least one program, the code set or the instruction set being loaded and executed by the processor to implement the digital key sharing method according to any one of claims 14 to 15.
22. A computer-readable storage medium, characterized in that, The storage medium stores at least one instruction, at least one program, a code set or an instruction set, the at least one instruction, the at least one program, the code set or the instruction set being loaded and executed by a processor to implement the digital key sharing method according to any one of claims 1 to 15.
Citation Information
Patent Citations
Automobile digital cloud key sharing system
CN106301781A
Safe distribution method, device and system of vehicle Bluetooth key and storage medium
CN112039951A