Vehicle unlocking method and device, computer device and storage medium

By using offline transmission channels and asymmetric encryption algorithms for verification, the unlocking and pairing issues of digital key systems in poor network or offline states have been resolved, enabling a secure vehicle unlocking process.

CN115767552BActive Publication Date: 2026-01-30国汽智端(成都)科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211515789.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-30
Publication Date
2026-01-30
Estimated Expiration
2042-11-30

AI Technical Summary

Technical Problem

Existing digital key systems are difficult to pair and unlock when the network is poor or offline, and their security is also poor.

Method used

Communication is achieved through an offline transmission channel, and asymmetric encryption algorithms are used to sign and verify digital keys and vehicle certificates, including reading digital key serial numbers, sending authentication commands, generating and verifying signature values, and establishing offline association relationships.

Benefits of technology

It enables secure unlocking and pairing of vehicles even in poor network or offline conditions, improving the security of the digital key system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115767552B_ABST
    Figure CN115767552B_ABST
Patent Text Reader

Abstract

This application relates to a vehicle unlocking method, apparatus, computer device, storage medium, and computer program product. The method includes: sending a read command to a digital key terminal in real time via an offline transmission channel; detecting whether the digital key exists in the registered digital key list based on the digital key serial number, and determining the registration result of the digital key; if the registration result is registered, sending an authentication request command to the digital key; receiving second concatenated data and a second signature value sent by the digital key terminal in response to the authentication request command; verifying the second concatenated data and the second signature value according to a pre-stored second public key to obtain a verification result; and unlocking the vehicle terminal if the verification result is successful. This method enables high-security vehicle unlocking even in offline or poor network conditions.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet of Things, and in particular to a vehicle unlocking method and device, a computer device, a storage medium, and a computer program product. BACKGROUND

[0002] With the development of Internet of Things technology, the use of digital keys for cars is gradually increasing. Using a digital key to unlock a vehicle end has the characteristics of convenient use, easy to carry, and not easy to lose. A vehicle owner can use their own mobile device, such as a smartphone or smartwatch, to activate the digital key function.

[0003] In the traditional technology, the digital key mainly uses technologies such as frequent communication technology, NFC, or UWB to complete the communication between the digital key and the vehicle, and then realizes the unlocking, locking, and starting of the vehicle.

[0004] However, the current vehicle unlocking of the digital key needs to be connected to the network, which makes it difficult for the digital key and the vehicle to be paired or for the unlocking authentication and security to be poor in the case of poor network or offline state of the digital key. SUMMARY

[0005] Therefore, it is necessary to provide a vehicle unlocking method, device, computer device, computer readable storage medium, and computer program product to solve the above technical problems.

[0006] In a first aspect, the present application provides a vehicle unlocking method. The method comprises:

[0007] sending a read instruction to the digital key end in real time through an offline transmission channel; the read instruction is used to read the digital key serial number;

[0008] detecting whether the digital key exists in the registered digital key list according to the digital key serial number, and determining the registration result of the digital key;

[0009] in the case of the registration result being registered, sending a request authentication instruction to the digital key;

[0010] receiving second spliced data and a second signature value sent by the digital key end in response to the request authentication instruction, verifying the second spliced data and the second signature value according to a pre-stored second public key, obtaining a verification result, and unlocking the vehicle end in the case of the verification result being verification success.

[0011] In one of the embodiments, after detecting whether the digital key exists in the registered digital key list according to the digital key serial number and determining the registration result of the digital key, the method further comprises:

[0012] In the case that the registration result is unregistered, the digital key end error information is returned.

[0013] In one of the embodiments, before the read instruction is sent to the digital key end in real time through the offline transmission channel, the method further comprises:

[0014] The registration instruction is sent to the digital key end through the offline transmission channel.

[0015] The digital key device certificate, the third splicing data, the second public key and the third signature value sent by the digital key end are received, the digital key device certificate is verified according to the first root certificate, and in the case that the first root certificate verification is successful, the third splicing data and the third signature value are verified according to the key public key in the key device certificate.

[0016] In the case that the key public key verification of the third splicing data and the third signature value is successful, the digital key serial number and the second public key are saved in the registered digital key list.

[0017] In one of the embodiments, the method comprises:

[0018] In response to the read instruction sent by the vehicle end, the digital key serial number is sent to the vehicle end.

[0019] The request authentication instruction sent by the vehicle end is received, and the request authentication instruction comprises vehicle feature information, vehicle certificate, first splicing data and first signature value.

[0020] The vehicle certificate is verified according to the second root certificate, in the case that the second root certificate verification is successful, the first splicing data and the first signature value are verified according to the first public key in the vehicle certificate, and in the case that the verification is successful, it is checked whether the vehicle end is in the registered vehicle list.

[0021] In the case that the vehicle feature information exists in the registered vehicle list, the second splicing data is generated, the second splicing data is signed using the preset second private key to obtain the second signature value, and the second signature value and the second splicing data are sent to the vehicle end.

[0022] In one of the embodiments, before the digital key serial number is sent to the vehicle end in response to the read instruction sent by the vehicle end, the method further comprises:

[0023] In response to the registration instruction, the vehicle end is registered and verified according to the vehicle feature information in the registration instruction to obtain a vehicle registration result.

[0024] In a case where the vehicle registration result is unregistered, a second public key and the second private key are generated for the vehicle end;

[0025] Third splicing data is generated, the third splicing data is signed according to a preset key private key, a third signature value is obtained, and the third splicing data, a digital key device certificate, the second public key, and the third signature value are sent to the vehicle end.

[0026] In one of the embodiments, the registration instruction further includes the vehicle certificate and a fourth signature value, the vehicle end is registered and verified according to the vehicle feature data in the registration instruction to obtain a vehicle registration result, including:

[0027] The vehicle certificate is verified according to the second root certificate in response to the registration instruction;

[0028] In a case where the second root certificate verification is successful, the fourth signature value and the vehicle feature data contained in the registration instruction are verified according to the first public key, and in a case where the first public key verification is successful, the vehicle end is registered and verified according to the vehicle feature data in the registration instruction to obtain a vehicle registration result.

[0029] In a second aspect, the application further provides a vehicle unlocking device. The device includes:

[0030] A first sending module is configured to send a reading instruction to a digital key end in real time through an offline transmission channel; the reading instruction is used to read a digital key serial number;

[0031] A verification module is configured to detect whether the digital key exists in a registered digital key list according to the digital key serial number to determine a registration result of the digital key;

[0032] A request authentication module is configured to send a request authentication instruction to the digital key in a case where the registration result is registered;

[0033] An unlocking module is configured to receive second splicing data and a second signature value sent by the digital key end in response to the request authentication instruction, verify the second splicing data and the second signature value according to a second public key stored in advance to obtain a verification result, and unlock the vehicle end in a case where the verification result is verified successfully.

[0034] In one of the embodiments, the verification module further includes:

[0035] In a case where the registration result is unregistered, the digital key end is returned with an error message.

[0036] In one of the embodiments, before the sending module, the apparatus further comprises a first registration module:

[0037] An offline transmission channel, sending a registration instruction to the digital key end;

[0038] Receiving the digital key device certificate, the third splicing data, the second public key and the third signature value sent by the digital key end, verifying the digital key device certificate according to the first root certificate, and verifying the third splicing data and the third signature value according to the key public key in the key device certificate in the case of successful verification of the first root certificate;

[0039] In the case of successful verification of the key public key to the third splicing data and the third signature value, saving the digital key serial number and the second public key in the registered digital key list.

[0040] In a third aspect, the application also provides a vehicle unlocking apparatus. The apparatus comprises:

[0041] A second sending module, configured to send a digital key serial number to the vehicle end in response to a read instruction sent by the vehicle end;

[0042] A receiving module, configured to receive a request authentication instruction sent by the vehicle end;

[0043] A checking module, configured to verify the vehicle certificate according to a second root certificate, verify the first splicing data and the first signature value according to a first public key in the vehicle certificate in the case of successful verification of the second root certificate, and check whether the vehicle end is in a registered vehicle list in the case of successful verification.

[0044] A signature module, configured to generate second splicing data and sign the second splicing data using a preset second private key to obtain a second signature value in the case that the vehicle feature information exists in the registered vehicle list, and send the second signature value and the second splicing data to the vehicle end.

[0045] In one of the embodiments, before the third sending module, the apparatus further comprises a second registration module:

[0046] In response to a registration instruction, verifying the vehicle end according to the vehicle feature information in the registration instruction to obtain a vehicle registration result;

[0047] In the case that the vehicle registration result is unregistered, generating a second public key and the second private key for the vehicle end;

[0048] generate third splicing data, sign the third splicing data according to a preset key private key to obtain a third signature value, and send the third splicing data, the digital key device certificate, the second public key, and the third signature value to the vehicle end.

[0049] In one of the embodiments, before the receiving module, the apparatus further comprises a second registration module:

[0050] In response to the registration instruction, performing registration verification on the vehicle end according to vehicle feature information in the registration instruction to obtain a vehicle registration result;

[0051] In a case where the vehicle registration result is unregistered, generating a second public key and the second private key for the vehicle end;

[0052] generate third splicing data, sign the third splicing data according to a preset key private key to obtain a third signature value, and send the third splicing data, the digital key device certificate, the second public key, and the third signature value to the vehicle end.

[0053] In one of the embodiments, the second registration module further comprises:

[0054] In response to the registration instruction, performing registration verification on the vehicle end according to vehicle feature information in the registration instruction to obtain a vehicle registration result;

[0055] In a case where the vehicle registration result is unregistered, generating a second public key and the second private key for the vehicle end;

[0056] In a fourth aspect, the present application further provides a computer device. The computer device comprises a memory and a processor, the memory stores a computer program, and the processor implements the steps of the method of the first aspect when executing the computer program.

[0057] In a fifth aspect, the present application further provides a computer readable storage medium. The computer readable storage medium stores a computer program, and the computer program implements the steps of the method of the first aspect when executed by a processor.

[0058] In a sixth aspect, the present application further provides a computer program product. The computer program product comprises a computer program, and the computer program implements the steps of the method of the first aspect when executed by a processor.

[0059] The vehicle unlocking method, device, computer equipment, storage medium and computer program product provided in the above embodiment can realize relatively safe unlocking and pairing of the digital key to the vehicle in an offline state by signing the device certificate and the vehicle certificate of the digital key respectively through the offline channel based on the asymmetric encryption algorithm and verifying the signature through the public key and the private key of the vehicle. BRIEF DESCRIPTION OF DRAWINGS

[0060] Figure 1 An application environment diagram of the vehicle unlocking method in an embodiment;

[0061] Figure 2 A flowchart of the vehicle unlocking method of the vehicle end in an embodiment;

[0062] Figure 3 A flowchart of the vehicle end step in the registration process in an embodiment;

[0063] Figure 4 A flowchart of the digital key end of the vehicle unlocking method in an embodiment;

[0064] Figure 5 A flowchart of the digital key end step in the registration process in an embodiment;

[0065] Figure 6 A flowchart of the vehicle unlocking method of the digital key end in another embodiment;

[0066] Figure 7 A flowchart of an instance of the vehicle unlocking method in an embodiment;

[0067] Figure 8 A structural block diagram of the vehicle unlocking device of the vehicle end in an embodiment;

[0068] Figure 9 A structural block diagram of the vehicle unlocking device of the digital key end in an embodiment;

[0069] Figure 10 An internal structure diagram of the computer equipment in an embodiment. DETAILED DESCRIPTION

[0070] In order to make the objects, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and should not be used to limit the present application.

[0071] The vehicle unlocking method provided in the embodiments of the present application can be applied to, for example, Figure 1The application environment is shown. Among them, the vehicle end 102 communicates with the digital key end 104 through short-range wireless communication technology. The data storage system can store the data that the vehicle end 102 and the digital key end 104 need to process. The data storage system can be integrated on the vehicle end 102 and the digital key end 104. Among them, the vehicle end 102 can be but not limited to various vehicle integrated terminals, and the digital key end 104 can be but not limited to various smart phones, smart cards, Internet of Things devices and portable wearable devices. The smart card can be a non-contact IC card (Integrated Circuit Card) / Bluetooth card, and the portable wearable device can be a smart watch, a smart bracelet, etc.

[0072] In one embodiment, as shown in Figure 2 , a vehicle unlocking method is provided, which is applied to the vehicle end 102 in Figure 1 for example, including the following steps:

[0073] Step 202, sending a read instruction to the digital key end in real time through an offline transmission channel.

[0074] Among them, the read instruction is used to read the digital key serial number. The digital key serial number is a unique serial number set by the digital key when it is manufactured or issued. The offline transmission channel can be an NFC (Near Field Communication) communication (such as ISO / IEC 14443 protocol), Bluetooth, UWB (Ultra Wide Band), etc. offline communication channel, and the type of offline transmission channel is not limited in the embodiment. This read instruction also includes a first random number, which is used as the content of the first splicing data. This sending of the read instruction can be activated by the digital key end.

[0075] In the embodiment, the vehicle end sends the read instruction to the digital key end in real time through the transmission channel. Specifically, for example, when the digital key enters the signal range of the vehicle end, the vehicle end starts to send the read instruction in real time.

[0076] Step 204, detecting whether the digital key exists in the registered digital key list according to the digital key serial number, and determining the registration result of the digital key.

[0077] In the embodiment, the vehicle end obtains the digital key serial number through the read instruction, and then checks whether the digital key serial number exists in the registered digital key list to determine the registration result of the digital key. If the digital key serial number exists in the registered digital key list, it indicates that the registration result of the digital key is registered, and if the digital key serial number does not exist in the registered digital key list, the registration result of the digital key is unregistered.

[0078] Step 206, in the case of the registration result being registered, sending a request authentication instruction to the digital key.

[0079] The request authentication instruction includes a second random number, vehicle feature information, a digital key serial number, a vehicle certificate, first spliced data, and a first signature value.

[0080] In this embodiment, if the registration result of the digital key is registered, the vehicle end sends a request authentication instruction to the digital key end. The first spliced data is obtained by splicing the first random number, the second random number, the vehicle feature information, and the digital key serial number, and the first signature value is obtained by signing the first spliced data with the first private key. The first random number and the second random number are used to prevent replay attacks, for example, the vehicle end and the digital key end record the independent random number generated each time authentication is performed. If an attacker replays the previously recorded authentication data, the vehicle end and the digital key end will find that the random number in the authentication message is not generated this time, and will consider it a replay attack.

[0081] The vehicle feature information can be the VIN (Vehicle Identification Number) of the vehicle, or other information that can uniquely indicate the vehicle features, for example, it can be the license plate number, the MAC (Media Access Control Address) address of the network device installed on the vehicle, etc., or one or more of the above data are spliced, and a fixed-length hash value is generated as the vehicle feature data using a one-way hash algorithm such as the SHA256 (a cryptographic hash function with a hash length of 256 bits) algorithm or the SM3 (a domestic hash algorithm) algorithm.

[0082] Step 208, receiving the second spliced data and the second signature value sent by the digital key end in response to the request authentication instruction, verifying the second spliced data and the second signature value according to the pre-stored second public key, obtaining a verification result, and in the case of the verification result being verification success, unlocking the vehicle end.

[0083] In this embodiment, the vehicle end receives the second spliced data and the second signature value sent by the digital key end, determines the second public key according to the pre-stored digital key serial number, verifies the second spliced data and the second signature value according to the second public key, and if the verification is successful, the vehicle end performs an unlocking or starting operation; if the verification fails, the vehicle end returns a verification error.

[0084] In the above vehicle unlocking method, the vehicle and digital key communicate through an offline transmission channel. Furthermore, the vehicle uses asymmetric encryption to verify the digital key, which enables relatively secure unlocking of the vehicle even in poor network conditions or when offline, thus improving the security of vehicle unlocking.

[0085] In one embodiment, after detecting whether a digital key exists in the list of registered digital keys based on its serial number and determining the registration result of the digital key, the method further includes:

[0086] If the registration result is "not registered", a digital key error message will be returned.

[0087] In this embodiment, if the detection result of the digital key serial number on the vehicle side is that it is not registered, the system returns a message indicating that the digital key is incorrect and ends the authentication process.

[0088] In this embodiment, by interrupting the unlocking process of an unregistered digital key, the system can prevent incorrect unlocking by similar digital keys, thereby improving vehicle security.

[0089] In one embodiment, such as Figure 3 As shown, in step 202, before sending the reading command to the digital key terminal in real time via the offline transmission channel, the method further includes:

[0090] Step 302: Send a reading command to the digital key terminal in real time through the offline transmission channel.

[0091] The registration instructions include a third random number and vehicle characteristic information.

[0092] In this embodiment, the vehicle sends a registration command to the digital key. The function of this third random number is similar to that of the first and second random numbers in step 206. Therefore, the function of this third random number will not be described again in this embodiment.

[0093] Step 304: Receive the digital key device certificate, third concatenated data, second public key, and third signature value sent by the digital key terminal; verify the digital key device certificate based on the first certificate; if the first certificate is successfully verified, verify the third concatenated data and third signature value based on the key public key in the key device certificate.

[0094] The third concatenation data consists of the digital key serial number, the second public key, and the third random number.

[0095] In the embodiment, the vehicle end receives the third spliced data, the second public key and the third signature value sent by the digital key end, first, verifies the digital key device certificate according to the root certificate, and then, in the case that the root certificate verification is successful, the vehicle end verifies the third spliced data and the third signature value according to the key public key in the key device certificate.

[0096] Step 306, in the case that the key public key verifies the third spliced data and the third signature value successfully, save the digital key serial number and the second public key in the registered digital key list.

[0097] In the embodiment, the vehicle end saves the key serial number and the second public key corresponding in the registered digital key list in the case that the key public key verifies the third spliced data and the third signature value successfully, and uses the digital key to unlock or start the vehicle.

[0098] Optionally, if the verification fails, the vehicle end returns that the digital key signature is wrong, and terminates the pairing. The root certificate is used to verify whether the digital key device certificate is legal.

[0099] In the embodiment, the vehicle end and the digital key end communicate through the offline transmission channel, and use the asymmetric encryption to build the association relationship with the digital key end, save the digital key serial number and the corresponding second public key, so that the pairing of the vehicle end and the digital key end in the poor network or offline state is realized.

[0100] In one embodiment, as shown in Figure 4 , a vehicle unlocking method is provided, which is taken as an example of the digital key end 104 in Figure 1 for illustration, and includes the following steps:

[0101] Step 402, in response to the read instruction sent by the vehicle end, send the digital key serial number to the vehicle end.

[0102] In the embodiment, the digital key end sends the digital key serial number of the digital key end to the vehicle end in response to the read instruction of the vehicle end.

[0103] Optionally, the digital key end can also send the first random number to the vehicle end in addition to the digital key serial number.

[0104] Step 404, receive the request authentication instruction sent by the vehicle end, and the request authentication instruction includes the vehicle feature information, the vehicle certificate, the first spliced data and the first signature value.

[0105] In the embodiment, when the vehicle end sends the request authentication instruction to the digital key end, the digital key end receives the request authentication instruction sent by the vehicle end, and the request authentication instruction is used to judge whether the vehicle end can be unlocked or started by the digital key.

[0106] At step 406, the vehicle certificate is verified according to the second root certificate, and in the case that the second root certificate is verified successfully, the first spliced data and the first signature value are verified according to the first public key in the vehicle certificate, and in the case that the verification is successful, it is checked whether the vehicle end is in the registered vehicle list.

[0107] The root certificate is used to determine whether the vehicle certificate is legal.

[0108] In the embodiment, the digital key end verifies the vehicle certificate according to the root certificate, and in the case that the root certificate fails to be verified, an authentication failure is returned; in the case that the root certificate is verified successfully, the first spliced data and the first signature value are verified according to the first public key in the vehicle certificate, and in the case that the first public key fails to be verified, a vehicle verification failure is returned; in the case that the first public key is verified successfully, it is checked whether the vehicle is in the registered vehicle list according to the vehicle feature information, and if the vehicle feature information of the vehicle exists in the registered vehicle list, step 408 is executed, and if the vehicle feature information of the vehicle does not exist in the registered vehicle list, the digital key end returns a vehicle unregistered message.

[0109] At step 408, in the case that the vehicle feature information exists in the registered vehicle list, the second spliced data is generated, the second spliced data is signed by using a preset second private key to obtain a second signature value, and the second signature value and the second spliced data are sent to the vehicle end.

[0110] In the embodiment, the authentication counter is a counter saved by the digital key end, and the authentication counter is increased by one unit after each authentication, and the count value is output. In the case that the vehicle feature information exists in the registered vehicle list, the digital key end generates the second spliced data, and the second spliced data is obtained by splicing the vehicle feature information, the count value, the first random number and the second random number.

[0111] The digital key end signs the second spliced data by using the preset second private key to obtain the second signature value, and sends the second signature value and the second spliced data to the vehicle end, and the value of the authentication counter is increased by one unit.

[0112] In the above vehicle unlocking method, the vehicle end and the digital key end communicate through the offline transmission channel, and the digital key end verifies the vehicle end by using the asymmetric encryption method, so that the vehicle end can be unlocked more safely in the case of poor network or offline.

[0113] In one embodiment, as shown in FIG. 4B, before step 402, the method further includes: Figure 5 ​

[0114] Step 502, in response to the registration instruction, the vehicle end is registered according to the vehicle feature information in the registration instruction, and the vehicle registration result is obtained.

[0115] The registration instruction includes the vehicle feature information of the vehicle end and the third random number.

[0116] In this embodiment, the digital key end responds to the registration instruction of the vehicle end, and the vehicle is registered according to the vehicle feature information in the registration instruction. If the vehicle feature information exists in the registered vehicle list, the vehicle registration result is registered, and the vehicle is returned. If the vehicle feature information does not exist in the registered vehicle list, the vehicle registration result is not registered, and step 504 is continued.

[0117] Step 504, in the case of vehicle registration result is not registered, the second public key and the second private key are generated for the vehicle end.

[0118] In this embodiment, the digital key end generates the second public key and the second private key for the vehicle end in the case that the vehicle registration result is not in the registered vehicle list. The second public key and the second private key are generated for the digital key end, and correspond to the digital key.

[0119] Step 506, the third splicing data is generated, the third splicing data is signed according to the preset key private key, the third signature value is obtained, and the third splicing data, the digital key device certificate, the second public key and the third signature value are sent to the vehicle end.

[0120] The third splicing data is spliced by the digital key serial number, the second public key and the third random number obtained in step 502.

[0121] In this embodiment, the digital key end signs the third splicing data according to the preset key private key, obtains the third signature value, and sends the third splicing data, the digital key device certificate, the second public key and the third signature value to the vehicle end.

[0122] Optionally, the third splicing data can also increase a digital key validity period, and the digital key validity period is used as an item of the third splicing data, signed by the preset key private key, and returned to the vehicle end in this step. In the authentication process, the vehicle end checks the validity period of the key private key of the digital key in advance, and returns the authentication failure information if the validity period is exceeded.

[0123] In the embodiment, the digital key end and the vehicle end communicate through the offline transmission channel, the digital key is authenticated by asymmetric encryption, and the third splicing data, the digital key device certificate, the second public key and the third signature value are sent to the vehicle end, so that the pairing of the vehicle end and the digital key end in a poor network or offline state can be realized.

[0124] In one embodiment, as shown in Figure 6 The registration instruction includes the vehicle certificate and the fourth signature value, in step 502, in response to the registration instruction, the vehicle is registered and verified according to the vehicle feature data in the registration instruction, and a vehicle registration result is obtained, including:

[0125] In step 602, in response to the registration instruction, the vehicle certificate is verified according to the second root certificate.

[0126] In the embodiment, in response to the registration instruction of the vehicle end, the digital key end can also check whether the vehicle certificate can be verified by the second root certificate according to the second root certificate.

[0127] In step 604, in the case of successful verification of the second root certificate, the fourth signature value and the vehicle feature data contained in the registration instruction are verified according to the first public key, and in the case of successful verification of the first public key, the vehicle end is registered and verified according to the vehicle feature data in the registration instruction, and a vehicle registration result is obtained.

[0128] The fourth signature value is obtained by signing the fourth splicing data obtained by splicing the third random number and the vehicle feature information in the registration instruction by the first private key of the vehicle end.

[0129] In the embodiment, in the case of failed root certificate verification, the digital key end returns that the vehicle certificate is illegal; in the case of successful root certificate verification, the fourth signature value, the third random number and the vehicle feature data are verified according to the first public key, in the case of successful verification of the first public key, the vehicle is registered and verified according to the vehicle feature data in the registration instruction, and a vehicle registration result is obtained; in the case of failed verification of the first public key, the digital key end returns verification failure.

[0130] Optionally, the vehicle certificate can also include the validity period of the vehicle certificate, if the vehicle certificate is within the validity period, if the vehicle certificate exceeds the validity period, the digital key end returns verification failure.

[0131] In the embodiment, the fourth signature value and the vehicle certificate are added in the registration instruction, and by verifying the vehicle certificate and verifying the signature containing the vehicle feature information, the security of the pairing of the digital key end and the vehicle end can be further improved.

[0132] The embodiment of the application also provides an example of a vehicle unlocking method, as shown in Figure 7As shown, specifically comprising the following steps:

[0133] Step 701, the vehicle end sends a registration instruction to the digital key end through an offline transmission channel.

[0134] Step 702, the digital key end responds to the registration instruction and performs registration verification on the vehicle end according to the vehicle feature information in the registration instruction, to obtain a vehicle registration result.

[0135] Step 703, in the case where the vehicle registration result is not registered, the digital key end generates a second public key and a second private key for the vehicle end.

[0136] Step 704, the digital key end generates third splicing data, signs the third splicing data according to a preset key private key, obtains a third signature value, and sends the third splicing data, the digital key device certificate, the second public key and the third signature value to the vehicle end.

[0137] Step 705, the vehicle end receives the digital key device certificate, the third splicing data, the second public key and the third signature value sent by the digital key end, verifies the digital key device certificate according to the first root certificate, and in the case where the first root certificate verification is unsuccessful, step 706 is executed. In the case where the first root certificate verification is successful, step 707 is executed.

[0138] Step 706, return the information that the digital key verification fails.

[0139] Step 707, verify the third splicing data and the third signature value according to the key public key in the key device certificate.

[0140] Step 708, in the case where the key public key verifies the third splicing data and the third signature value successfully, the vehicle end saves the digital key serial number and the second public key in the registered digital key list.

[0141] Step 709, the vehicle end sends a read instruction to the digital key end in real time through the offline transmission channel.

[0142] Step 710, the digital key end responds to the read instruction sent by the vehicle end and sends the digital key serial number to the vehicle end.

[0143] Step 711, the vehicle end detects whether the digital key end exists in the registered digital key list according to the digital key serial number, and determines the registration result of the digital key end. In the case where the registration result is registered, step 712 is executed, and in the case where the registration result is not registered, step 713 is executed.

[0144] Step 712, return the information that the digital key is not registered.

[0145] Step 713, the vehicle end sends a request authentication instruction to the digital key.

[0146] Step 714, the digital key end receives the request authentication instruction sent by the vehicle end.

[0147] Step 715, the digital key end verifies the vehicle certificate according to the second root certificate, and if the verification fails, step 716 is performed. If the verification succeeds, step 717 is performed.

[0148] Step 716, return the vehicle end error information.

[0149] Step 717, verify the first splicing data and the first signature value according to the first public key in the vehicle certificate, and if the verification fails, step 718 is performed; if the verification succeeds, step 719 is performed.

[0150] Step 718, return the vehicle end error information.

[0151] Step 719, the digital key end checks whether the vehicle end is in the registered vehicle list. If the vehicle end is not registered, step 720 is performed; if the vehicle end is registered, step 721 is performed.

[0152] Step 720, return the vehicle end unregistered information.

[0153] Step 721, the digital key end generates second splicing data, and signs the second splicing data using a preset second private key to obtain a second signature value, and sends the second signature value and the second splicing data to the vehicle end.

[0154] Step 722, the vehicle end receives the second splicing data and the second signature value sent by the digital key end in response to the request authentication instruction, verifies the second splicing data and the second signature value according to the pre-stored second public key, obtains a verification result, and in the case that the verification result is verification success, the vehicle end is unlocked.

[0155] It should be understood that although each step in the flowchart involved in the above embodiments is displayed in sequence according to the arrow, these steps are not necessarily executed in sequence according to the arrow. Unless otherwise specified herein, the execution of these steps is not strictly limited in sequence, and these steps can be executed in other sequences. Moreover, at least part of the steps in the flowchart involved in the above embodiments can include multiple steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution sequence of these steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least part of other steps or steps or stages in other steps.

[0156] Based on the same inventive concept, the embodiments of the present application also provide a vehicle unlocking device for implementing the vehicle unlocking method described above. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme described in the above method, so the specific limitations in one or more vehicle unlocking device embodiments provided below can refer to the limitations of the vehicle unlocking method described above, which will not be repeated here.

[0157] In one embodiment, as Figure 8 It is shown that a vehicle unlocking device is provided, comprising: a first sending module 801, a verification module 802, a request authentication module 803 and an unlocking module 804, wherein:

[0158] The first sending module 801 is configured to send a reading instruction to the digital key end in real time through an offline transmission channel; the reading instruction is used to read the digital key serial number;

[0159] The verification module 802 is configured to detect whether the digital key exists in the registered digital key list according to the digital key serial number, and determine the registration result of the digital key;

[0160] The request authentication module 803 is configured to send a request authentication instruction to the digital key in the case of a registered registration result;

[0161] The unlocking module 804 is configured to receive second spliced data and a second signature value sent by the digital key end in response to the request authentication instruction, verify the second spliced data and the second signature value according to a pre-stored second public key, obtain a verification result, and in the case of a successful verification result, unlock the vehicle end.

[0162] In one embodiment, the verification module 802 further comprises:

[0163] In the case of an unregistered registration result, the information of the digital key end error is returned.

[0164] In one embodiment, before the first sending module 801, the device further comprises a first registration module 805:

[0165] The registration instruction is sent to the digital key end through the offline transmission channel;

[0166] The digital key device certificate, the third spliced data, the second public key and the third signature value sent by the digital key end are received, the digital key device certificate is verified according to the first root certificate, and in the case of a successful first root certificate verification, the third spliced data and the third signature value are verified according to the key device certificate in the key public key;

[0167] In case that the key public key pair successfully verifies the third spliced data and the third signature value, the digital key serial number and the second public key are stored in the registered digital key list.

[0168] In one embodiment, as shown in the figure, a vehicle unlocking device is provided, comprising a second sending module 901, a receiving module 902, a checking module 903 and a signature module 904, wherein: Figure 9

[0169] The second sending module 901 is configured to send the digital key serial number to the vehicle end in response to a read instruction sent by the vehicle end.

[0170] The receiving module 902 is configured to receive a request authentication instruction sent by the vehicle end.

[0171] The checking module 903 is configured to verify the vehicle certificate according to the second root certificate, verify the first spliced data and the first signature value according to the first public key in the vehicle certificate in case that the second root certificate is successfully verified, and check whether the vehicle end is in the registered vehicle list in case that the verification is successful.

[0172] The signature module 904 is configured to generate the second spliced data in case that the vehicle feature information exists in the registered vehicle list, sign the second spliced data using the preset second private key to obtain the second signature value, and send the second signature value and the second spliced data to the vehicle end.

[0173] In one embodiment, before the second sending module 901, the device further comprises a second registration module 905:

[0174] In response to a registration instruction, the vehicle end is registered and verified according to the vehicle feature information in the registration instruction to obtain a vehicle registration result.

[0175] In case that the vehicle registration result is unregistered, the second public key and the second private key are generated for the vehicle end.

[0176] The third spliced data is generated, the third spliced data is signed according to the preset key private key to obtain the third signature value, and the third spliced data, the digital key device certificate, the second public key and the third signature value are sent to the vehicle end.

[0177] In one embodiment, before the receiving module, the device further comprises a second registration module:

[0178] In response to a registration instruction, the vehicle end is registered and verified according to the vehicle feature information in the registration instruction to obtain a vehicle registration result.

[0179] In case that the vehicle registration result is unregistered, the second public key and the second private key are generated for the vehicle end. ​

[0180] The third splicing data is generated, the third splicing data is signed according to a preset private key of the key, a third signature value is obtained, and the third splicing data, the digital key device certificate, the second public key, and the third signature value are sent to the vehicle end.

[0181] In one of the embodiments, the second registration module 905 further includes:

[0182] In response to the registration instruction, the vehicle certificate is verified according to the second root certificate;

[0183] In a case where the second root certificate is verified successfully, the fourth signature value and the vehicle feature data contained in the registration instruction are verified according to the first public key, in a case where the first public key is verified successfully, the vehicle end is registered and verified according to the vehicle feature data in the registration instruction, and a vehicle registration result is obtained.

[0184] The above-mentioned modules in the vehicle unlocking device can be all or partially implemented by software, hardware, and combinations thereof. The above-mentioned modules can be embedded in or independent of the processor in the computer device in hardware form, or can be stored in the memory in the computer device in software form, so as to be called and executed by the processor to perform the operations corresponding to the above-mentioned modules.

[0185] In one embodiment, a computer device, which can be a server, is provided, and an internal structure diagram of the computer device can be as shown in Figure 10 The computer device includes a processor, a memory, and a network interface connected through a system bus. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium. The database of the computer device is configured to store first public keys, first private keys, first signature values, and the like. The computer program is executed by the processor to implement a vehicle unlocking method.

[0186] In one embodiment, a computer device, which can be a terminal, is provided, and an internal structure diagram of the computer device can be as shown in Figure 10As shown in the figure. The computer device includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium to run. The computer program is executed by the processor to implement a vehicle unlocking method. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer overlaid on the display screen, or a key, trackball or touchpad arranged on the shell of the computer device, or an external keyboard, touchpad or mouse, etc.

[0187] Those skilled in the art can understand that, Figure 10 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement.

[0188] In one embodiment, a computer device is provided, including a memory and a processor, the memory stores a computer program, and the processor executes the computer program to implement the steps in each embodiment of the vehicle unlocking method.

[0189] In one embodiment, a computer readable storage medium is provided, which stores a computer program, and the computer program is executed by a processor to implement the steps in each embodiment of the vehicle unlocking method.

[0190] In one embodiment, a computer program product is provided, including a computer program, and the computer program is executed by a processor to implement the steps in each embodiment of the vehicle unlocking method.

[0191] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties.

[0192] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when the computer program is executed, the processes of the above-mentioned embodiments of the methods can be included. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (Read-Only Memory, ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive memory (ReRAM), magnetoresistive random access memory (Magnetoresistive Random Access Memory, MRAM), ferroelectric memory (Ferroelectric Random Access Memory, FRAM), phase change memory (Phase Change Memory, PCM), graphene memory, etc. Volatile memory can include random access memory (Random Access Memory, RAM) or external cache memory, etc. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (Static Random Access Memory, SRAM) or dynamic random access memory (Dynamic Random Access Memory, DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., without being limited thereto.

[0193] Any combination of the technical features of the above embodiments can be made. In order to make the description simple, all possible combinations of the technical features in the above embodiments are not described, however, as long as the combination of the technical features does not exist contradictory, it should be considered as the scope of the present application.

[0194] The above embodiments only express several implementation manners of the present application, and the description is more specific and detailed, but it should not be understood as a limitation on the scope of the patent of the present application. It should be pointed out that for ordinary skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of protection of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A vehicle unlocking method characterized by, The method comprises: sending a read instruction to the digital key end in real time through an offline transmission channel; the read instruction is used to read a digital key serial number and a first random number generated by the digital key end; detecting whether the digital key exists in a registered digital key list according to the digital key serial number, to determine a registration result of the digital key; in a case where the registration result is registered, concatenating the first random number, a second random number, vehicle feature information and the digital key serial number to obtain first concatenated data, signing the first concatenated data according to a first private key to obtain a first signature value, and sending a request authentication instruction to the digital key; the request authentication instruction comprises the second random number, the vehicle feature information, a vehicle certificate, the first concatenated data and the first signature value; in response to successful authentication of the request authentication instruction by the digital key end, receiving second concatenated data and a second signature value sent by the digital key end in response to the request authentication instruction; the second concatenated data is obtained by concatenating the vehicle feature information, a count value, the first random number and the second random number; verifying the second concatenated data and the second signature value according to a pre-stored second public key to obtain a verification result, and in a case where the verification result is successful verification, unlocking the vehicle end.

2. The method of claim 1, wherein, After the step of detecting whether the digital key exists in a registered digital key list according to the digital key serial number, to determine a registration result of the digital key, the method further comprises: in a case where the registration result is unregistered, returning information indicating an error of the digital key end.

3. The method of claim 1, wherein, Before the step of sending a read instruction to the digital key end in real time through an offline transmission channel, the method further comprises: sending a registration instruction to the digital key end through an offline transmission channel; receiving a digital key device certificate, third concatenated data, a second public key and a third signature value sent by the digital key end, verifying the digital key device certificate according to a first root certificate, and in a case where the first root certificate is verified successfully, verifying the third concatenated data and the third signature value according to a key public key in the key device certificate; in a case where the key public key verifies the third concatenated data and the third signature value successfully, saving the digital key serial number and the second public key in the registered digital key list.

4. A vehicle unlocking method characterized by, The method comprises: in response to a read instruction sent by the vehicle end through an offline transmission channel, sending a digital key serial number and a first random number generated by the digital key end to the vehicle end; receiving a request authentication instruction sent by the vehicle end, the request authentication instruction comprising a second random number, vehicle feature information, a vehicle certificate, first concatenated data and a first signature value; the first signature value is obtained by concatenating the first random number, the second random number, the vehicle feature information and the digital key serial number, and signing the first concatenated data according to a first private key, in a case where a registration result of the digital key is registered; verify the vehicle certificate according to the second root certificate, and in the case of successful verification of the second root certificate, verify the first splicing data and the first signature value according to the first public key in the vehicle certificate, and in the case of successful verification, check whether the vehicle end is in the registered vehicle list; in the case that the vehicle feature information exists in the registered vehicle list, generate second splicing data, sign the second splicing data using a preset second private key to obtain a second signature value, and send the second signature value and the second splicing data to the vehicle end; the second splicing data is obtained by splicing the vehicle feature information, a count value, the first random number and the second random number; the second signature value and the second splicing data are used for verification at the vehicle end, and in the case of successful verification, the vehicle end is controlled to be unlocked.

5. The method of claim 4, wherein, Before the method further comprises: in response to the registration instruction, performing registration verification on the vehicle end according to the vehicle feature information in the registration instruction to obtain a vehicle registration result; in the case that the vehicle registration result is unregistered, generating a second public key and the second private key for the vehicle end; generating third splicing data, signing the third splicing data according to a preset key private key to obtain a third signature value, and sending the third splicing data, a digital key device certificate, the second public key and the third signature value to the vehicle end.

6. The method of claim 5, wherein, The registration instruction further includes the vehicle certificate and a fourth signature value, and the response to the registration instruction, the vehicle end is registered according to the vehicle feature data in the registration instruction to obtain a vehicle registration result, including: in response to the registration instruction, verifying the vehicle certificate according to the second root certificate; in the case of successful verification of the second root certificate, verifying the fourth signature value and the vehicle feature data contained in the registration instruction according to the first public key, and in the case of successful verification of the first public key, performing registration verification on the vehicle end according to the vehicle feature data in the registration instruction to obtain a vehicle registration result.

7. An implementation device of a digital key, characterized by The device comprises: a first sending module for sending a read instruction to a digital key end in real time through an offline transmission channel; the read instruction is used to read a digital key serial number and a first random number generated by the digital key end; a verification module for detecting whether the digital key exists in a registered digital key list according to the digital key serial number, and determining a registration result of the digital key; a request authentication module for, in the case that the registration result is registered, splicing the first random number, a second random number, vehicle feature information and the digital key serial number to obtain first splicing data, signing the first splicing data according to a first private key to obtain a first signature value, and sending a request authentication instruction to the digital key; the request authentication instruction includes the second random number, the vehicle feature information, a vehicle certificate, the first splicing data and the first signature value; An unlocking module is configured to, in response to the authentication of the digital key end to the request authentication instruction being successful, receive second spliced data and a second signature value sent by the digital key end in response to the request authentication instruction; the second spliced data is obtained by splicing the vehicle feature information, a count value, the first random number and the second random number; and the second spliced data and the second signature value are verified according to a second public key stored in advance to obtain a verification result, and the vehicle end is unlocked in a case where the verification result is a verification success.

8. A computer device comprising a memory and a processor, the memory storing a computer program, characterized in that, The computer program, when executed by the processor, implements the steps of the method of any one of claims 1-3 and 4-6.

9. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program, when executed by the processor, implements the steps of the method of any one of claims 1-3 and 4-6.

10. A computer program product comprising a computer program, characterized in that, The computer program, when executed by the processor, implements the steps of the method of any one of claims 1-3 and 4-6. The computer program, when executed by the processor, implements the steps of the method of any one of claims 1-3 and 4-6.

Citation Information

Patent Citations

  • Application program logging method and system based on vehicle bluetooth communication in mobile terminal

    CN105471480A

  • Networked automobile digital key security authentication method and device

    CN112396735A