Vehicle control methods, devices and storage media

By classifying vehicle control commands into security levels and establishing a security mechanism for key-vehicle negotiation, the security issues of remote vehicle control are resolved, achieving improved control security while maintaining a good user experience at a distance.

CN116311858BActive Publication Date: 2025-10-28ZHEJIANG ZEEKR INTELLIGENT TECH CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310346943.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-03
Publication Date
2025-10-28
Estimated Expiration
2043-04-03

AI Technical Summary

Technical Problem

In existing technologies, contactless key control of vehicles has low security at long distances, which affects the user experience.

Method used

By classifying vehicle control commands into security levels, high-security commands are sent through a stable connection, while low-security commands are sent through a broadcast mechanism. A security mechanism negotiated between the key and the vehicle is used for data encryption and decryption.

Benefits of technology

It improves vehicle handling safety at long distances while maintaining a good user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116311858B_ABST
    Figure CN116311858B_ABST
Patent Text Reader

Abstract

This application provides a vehicle control method, device, and storage medium. The method includes: a key generating a vehicle control command in response to a user's key press; determining whether the vehicle control command has a high-security level or a low-security level; if the vehicle control command is a low-security command, generating a vehicle control message according to the security mechanism corresponding to the low-security command negotiated between the key and the vehicle, and broadcasting the message; the vehicle receiving the broadcast message, parsing the vehicle control message according to the security mechanism corresponding to the low-security command negotiated between the vehicle and the contactless key, obtaining the vehicle control command, and executing the vehicle control command. This method of negotiating the security mechanism corresponding to the low-security command between the key and the vehicle increases the security of remote vehicle control and improves the user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to vehicle safety technology, and more particularly to a vehicle control method, device, and storage medium. Background Technology

[0002] With the development of intelligent automotive technology, controlling vehicles using contactless keys has become a trend. The key connects to the vehicle via Bluetooth or other wireless methods, and after completing security authentication, the user can use the key to control the vehicle.

[0003] In existing technologies, establishing a stable wireless connection and performing security authentication between a key and a vehicle requires the key and vehicle to be sufficiently close, resulting in a poor user experience. To improve the user experience and enable vehicle control from as far away as possible, long-distance broadcasting via wireless interface is required, which reduces security.

[0004] Therefore, improving vehicle handling safety while ensuring user experience is an urgent issue to be addressed. Summary of the Invention

[0005] This application provides a vehicle control method, device, and storage medium to address the problem of improving vehicle handling safety under long-distance conditions.

[0006] In a first aspect, this application provides a vehicle control method applied to a contactless key for a vehicle, the method comprising:

[0007] Responding to user key presses, generate vehicle control commands;

[0008] The safety level of the vehicle control command is determined to be either a high-safety command or a low-safety command.

[0009] If the vehicle control command is a low-security command, a vehicle control message is generated according to the security mechanism corresponding to the low-security command negotiated between the contactless key and the vehicle.

[0010] The vehicle control message is broadcast.

[0011] In one specific implementation, before generating vehicle control commands in response to user key presses, the method further includes:

[0012] Establish a connection with the vehicle via a wireless interface and construct a secure session;

[0013] Through the secure session, the security mechanism is negotiated with the vehicle to determine the security mechanism for subsequent low-security command transmission. The security mechanism includes at least one of encryption / decryption algorithms, command counting, and message format.

[0014] Store the security mechanism.

[0015] In one specific implementation, the security mechanism includes: an encryption / decryption algorithm and algorithm parameters for the encryption / decryption algorithm;

[0016] Accordingly, a vehicle control message is generated based on the security mechanism corresponding to the low-security command negotiated between the contactless key and the vehicle, including:

[0017] The vehicle control command is encrypted according to the encryption / decryption algorithm and its parameters to obtain the vehicle control message.

[0018] In one specific implementation, the method further includes;

[0019] If the vehicle control command is a high-security command, a secure session is established with the vehicle via a wireless interface;

[0020] If establishing a secure session fails, the vehicle control commands are discarded.

[0021] Secondly, this application also provides a vehicle control method, applied to a vehicle, the method comprising:

[0022] Receive vehicle control messages broadcast;

[0023] Based on the security mechanism corresponding to the low-security command negotiated with the contactless key of the vehicle, the vehicle control message is parsed to obtain the vehicle control command.

[0024] Execute the vehicle control command.

[0025] In one specific implementation, before receiving the broadcast vehicle control message, the method further includes:

[0026] A secure session is established by connecting the contactless key via a wireless interface.

[0027] The secure session is used to negotiate and determine the security mechanism for receiving low-security instructions in the future. The security mechanism includes at least one of encryption / decryption algorithms, instruction counting, and message format.

[0028] Store the security mechanism.

[0029] In one specific implementation, the security mechanism includes: an encryption / decryption algorithm and algorithm parameters for the encryption / decryption algorithm;

[0030] Accordingly, based on the security mechanism corresponding to the low-security command negotiated with the vehicle's contactless key, the vehicle control message is parsed to obtain the vehicle control command, including:

[0031] The vehicle control message is decrypted according to the encryption / decryption algorithm and its parameters to obtain the vehicle control command.

[0032] Thirdly, this application also provides a vehicle control device, the device comprising:

[0033] The instruction generation module is used to generate vehicle control instructions in response to user key presses.

[0034] The instruction distribution module is used to determine whether the security level of the vehicle control instruction is a high-security instruction or a low-security instruction;

[0035] The safety control module is used to generate a vehicle control message according to the safety mechanism corresponding to the low-security instruction negotiated between the vehicle's control device and the vehicle if the vehicle control instruction is a low-security instruction.

[0036] The Bluetooth communication module is used to broadcast the vehicle control messages.

[0037] Fourthly, this application also provides a vehicle control device, the device comprising:

[0038] The receiving module is used to receive broadcast vehicle control messages;

[0039] The security parsing module parses the vehicle control message according to the security mechanism corresponding to the low-security command negotiated with the contactless key of the vehicle's control device to obtain the vehicle control command.

[0040] An execution module is used to execute the vehicle control commands.

[0041] Fifthly, this application may also provide a contactless key, comprising:

[0042] The processor, the memory communicatively connected to the processor, and the communication interface for interacting with other devices;

[0043] The memory stores computer-executed instructions;

[0044] The processor executes computer execution instructions stored in the memory to implement the vehicle control method as described in any of the first aspects.

[0045] Sixthly, this application may also provide a vehicle, including:

[0046] The vehicle body, controller, memory, and communication interfaces for interacting with other devices;

[0047] The memory stores computer-executed instructions;

[0048] The controller executes computer-executable instructions stored in the memory to implement the vehicle control method as described in any of the second aspects.

[0049] In a seventh aspect, this application may also provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the vehicle control method as described in either the first or second aspect.

[0050] The vehicle control method, device, and storage medium provided in this application involve a contactless key responding to a user's key press to generate a vehicle control command. The security level of the vehicle control command is then determined to be either a high-security command or a low-security command. If the vehicle control command is a low-security command, a vehicle control message is generated according to the security mechanism corresponding to the low-security command negotiated between the contactless key and the vehicle, and this vehicle control message is broadcast. The vehicle receives the broadcast vehicle control message and, according to the security mechanism corresponding to the low-security command negotiated with the vehicle's contactless key, parses the vehicle control message to obtain the vehicle control command, and then executes the vehicle control command. In this solution, the key generates a vehicle control message for a low-security command at a remote distance through a security mechanism negotiated with the vehicle, and the vehicle executes the low-security command that conforms to the security mechanism. Therefore, the security of vehicle control is improved without changing the user's ability to remotely control the vehicle. Attached Figure Description

[0051] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0052] Figure 1 This is a schematic diagram illustrating an application scenario of the vehicle control method provided in the embodiments of this application;

[0053] Figure 2 A schematic flowchart of a vehicle control method according to an embodiment of this application;

[0054] Figure 3 A schematic flowchart of a second embodiment of the vehicle control method provided in this application;

[0055] Figure 4 A flowchart illustrating a third embodiment of the vehicle control method provided in this application;

[0056] Figure 5 This is a schematic diagram of the structure of a vehicle control device according to an embodiment of this application.

[0057] Figure 6This is a schematic diagram of the structure of a second embodiment of the vehicle control device provided in this application.

[0058] Figure 7 This is a schematic diagram of the structure of a contactless key provided in an embodiment of this application;

[0059] Figure 8 This is a schematic diagram of the vehicle structure provided in an embodiment of this application.

[0060] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0061] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0062] First, let me introduce the background involved in this application:

[0063] Modern smart car keys are no longer limited to simply locking and unlocking the doors; they offer a wider range of functions, such as car location, air conditioning control, window operation, seat heating, and trunk opening. The greater the distance between the vehicle and the key, the lower the probability of establishing a connection. Even if a connection is established, the bandwidth for transmitting data is smaller, resulting in higher latency. This means a longer delay between the user pressing the key button and the vehicle responding, leading to a poorer user experience. Conversely, the closer the vehicle and the key are, the more stable the connection, the higher the bandwidth, the lower the latency, and the better the user experience.

[0064] The transmission of business data between the vehicle and the key must be trusted and secure. Therefore, before the user operates the vehicle using the key, necessary security authentication needs to be completed between the vehicle and the key, and the instructions for operating the key should also be encrypted when transmitted over the wireless link. Robust and secure authentication requires a large amount of data interaction.

[0065] There are currently two types of technical solutions for the communication mechanism between the key and the vehicle:

[0066] The first technical solution emphasizes a user-friendly approach:

[0067] 1. The user holds the key and approaches the vehicle. The user can operate the key from any distance that the user considers within control of the vehicle.

[0068] 2. The key responds to user actions by generating a message and broadcasting it on the Bluetooth interface;

[0069] Generally, broadcast messages are encrypted. The encryption mechanism for broadcast messages, including algorithms and keys, is pre-written into the key and vehicle.

[0070] Broadcast messages are connectionless. Due to Bluetooth signal limitations, the vehicle may not receive the broadcast message, or may not receive the message completely and correctly. Therefore, the key needs to broadcast multiple times.

[0071] 3. When a vehicle receives any broadcast message, it will use a preset decryption mechanism to decrypt the message. If the decryption is successful and the content of the message conforms to the preset rules, it is considered a legitimate vehicle control command.

[0072] 4. The vehicle responds to vehicle control commands.

[0073] The second technical solution emphasizes security:

[0074] Before a user can send control commands to the vehicle, the key and the vehicle need to establish a secure channel and undergo sufficient security authentication. The user needs to be close enough to the vehicle to establish a stable wireless connection; otherwise, the user's actions will be invalid.

[0075] Both of the aforementioned technical solutions have drawbacks. The first solution offers a good user experience, but due to the rule-based nature of its algorithm and data, and its connectionless data transmission and reception via a wireless interface broadcast method, it is susceptible to attacks such as Denial of Service (DOS) and replay attacks, posing a significant security risk. The second solution requires the key and vehicle to be very close to establish a stable connection, which negatively impacts the user experience.

[0076] Based on the aforementioned problems, the inventors, during their research in this technical field, discovered that by tiering vehicle control commands, high-security commands are sent through a stable and secure connection, while low-security commands are transmitted and received via a broadcast mechanism. Furthermore, the transmitted and received data utilizes a security mechanism of dynamic negotiation between the key and the vehicle, thereby ensuring vehicle control security while improving the user experience. Therefore, this application proposes a vehicle control method, device, and storage medium.

[0077] Figure 1 This is a schematic diagram illustrating an application scenario of the vehicle control method provided in an embodiment of this application. For example... Figure 1As shown, this application scenario includes a vehicle and at least one contactless key for the vehicle. The contactless key has wireless communication capabilities. This wireless communication can be based on Bluetooth communication using the Ultra Low Power Application Bluetooth protocol, or other Bluetooth protocols, or on Wireless Fidelity (Wi-Fi), Ultra Wide Band (UWB), or other similar point-to-point wireless communication. The user controls the vehicle using the contactless key. The key can be a physical key, digital key, mobile phone, wearable device, etc., and is not limited here.

[0078] In the embodiments of this application, the contactless key and the key of the vehicle refer to the same entity.

[0079] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.

[0080] Figure 2 A flowchart illustrating an embodiment of the vehicle control method provided in this application is shown below. Figure 2 As shown, the vehicle control method may include the following steps:

[0081] S101. Responding to the user's key press operation, generate vehicle control commands.

[0082] In this step, within a certain range of the vehicle, the user needs to control the vehicle—for example, locate it within a certain range or unlock it. This requires wireless communication. Therefore, the user sends a wireless control command by pressing a button on the vehicle's contactless key to control the vehicle. The user can operate the vehicle by pressing a single button or by pressing a combination of buttons. The key responds to the user's button presses, generating corresponding control commands.

[0083] S102. Determine whether the safety level of the vehicle control command is a high-safety command or a low-safety command.

[0084] In this step, the key classifies the generated vehicle control commands into security levels, categorizing them into high-security and low-security commands. High-security commands are those potentially related to vehicle theft and can be operations controlling vehicle movement or door control, such as unlocking, starting, and stopping the engine. Low-security commands are generally not related to vehicle theft and are typically unrelated to vehicle movement or door control, such as vehicle location, ambient lighting control, and seat heating. It should be noted that this is merely an example of one classification method, and the invention does not limit the classification of commands.

[0085] The key contains a pre-stored lookup table of commands that the key can issue. This table includes the correspondence between control commands, their meanings, and security levels. After the key generates a vehicle control command, it is compared with the lookup table to determine whether the command is a high-security or low-security command.

[0086] Optionally, after the key generates vehicle control commands, the specific meaning of the control commands is analyzed according to the command lookup table. Based on the specific meaning of the control commands, the control commands are classified into security levels to determine whether the control commands belong to high-security commands or low-security commands.

[0087] Optionally, after determining the security level of the control command, an identifier can be added to the control command to indicate whether it is a high-security command or a low-security command.

[0088] S103. If the vehicle control command is a low-security command, then a vehicle control message is generated according to the security mechanism corresponding to the low-security command negotiated between the contactless key and the vehicle.

[0089] In this step, after classifying the vehicle control commands into security levels, commands classified as low-security commands are processed according to the security mechanism negotiated between the key and the vehicle. This negotiated security mechanism is determined under a stable connection between the key and the vehicle, and the security mechanism negotiated each time can be different from the previous one, or it can remain the same. The specific negotiation variation method can be set according to user needs. It should be noted that security mechanism negotiation is not required after every stable connection is established. The triggering method for the security mechanism negotiation can be periodic or event-based selective negotiation, such as once a day or once a month; this application does not impose any restrictions on this.

[0090] Specifically, the vehicle control command is encrypted according to the agreed-upon algorithm, and then a vehicle control message is generated according to the agreed-upon message format. The vehicle control message includes the encrypted vehicle control command and a key identifier. The key identifier is used to verify the legitimacy of the key; the key identifier can be a number, a string of text, or other content. The key identifier can be sent in plaintext or encrypted; this solution does not impose any restrictions.

[0091] Optionally, broadcast messages may also include other fields, such as command count and random value.

[0092] It should be noted that the negotiated security mechanism includes, but is not limited to: the encryption and decryption algorithms used subsequently, the subsequent message format, subsequent algorithm parameters such as keys, and subsequent command counter values. Negotiation can be periodic, such as once a day or once a month, or it can be performed for every connection; this patent does not limit this. This negotiation security mechanism increases the difficulty of being attacked and cracked, thereby improving vehicle security.

[0093] Taking command counting as an example, the security mechanism for key-vehicle negotiation is further explained. When the vehicle and key are stably connected, they negotiate a number to be used in subsequent broadcasts. Each time the key sends a vehicle control message via broadcast, this count is incremented by one. When the vehicle receives the broadcast message, it decrypts the message, extracts the command count, and compares it with the negotiated number. If the increment is greater than 0 and less than a preset threshold, the vehicle control command is considered valid; otherwise, the vehicle control command is considered invalid. The security mechanism of command counting can prevent the vehicle from being subjected to replay attacks.

[0094] S104. Broadcast the vehicle control message.

[0095] In this step, the key broadcasts vehicle control messages via a broadcast communication channel established through Bluetooth. During the broadcast, the vehicle may not receive the messages due to distance, so the key needs to broadcast periodically.

[0096] In one specific implementation, before broadcasting a low-security command vehicle control message, it first checks whether a stable security session has been established between the key and the vehicle. If not, it broadcasts the message; if so, it sends the message through the security session channel or broadcasts the message.

[0097] S105, Receive broadcast vehicle control messages.

[0098] In this step, the vehicle receives a broadcast vehicle control message.

[0099] S106. Based on the security mechanism corresponding to the low-security instruction negotiated with the vehicle's contactless key, the vehicle control message is parsed to obtain the vehicle control instruction.

[0100] In this step, after receiving the broadcast message, the vehicle parses the message using the security mechanism corresponding to the low-security command negotiated with the key. The parsing process includes decrypting the vehicle control command using the encryption / decryption algorithm stored in the vehicle to obtain the decrypted vehicle control command, and also includes other security measures in the negotiated security mechanism, which are consistent with those in step S103 on the key end, and will not be explained further here.

[0101] The vehicle identifies the key identifier in the message, authenticates the key identifier's legitimacy, and ensures that the key has the ability to control the vehicle. If the key identifier authentication fails, the vehicle control command cannot be executed.

[0102] Optionally, the vehicle may have multiple keys, each with different control permissions. After authenticating the key identifier, the control permissions of the key are identified to confirm whether the vehicle control commands are within the control permissions.

[0103] S107. Execute vehicle control commands.

[0104] In this step, the vehicle executes vehicle control commands and responds to user actions.

[0105] Optionally, the vehicle can respond to the key with a message indicating whether the control command was successful. This message is also sent through the security mechanism corresponding to the negotiated low-security command. After receiving the message, the key decrypts it according to the security mechanism corresponding to the negotiated low-security command and responds to the user based on whether the message was successful. Alternatively, the vehicle may not respond through the wireless interface, but instead respond through other means such as flashing headlights or honking the horn.

[0106] The vehicle control method provided in this embodiment classifies the generated vehicle control commands by the key according to their security levels. If the vehicle control command is a low-security command, a vehicle control message is generated according to the security mechanism corresponding to the low-security command negotiated between the key and the vehicle, and this message is broadcast. Then, the vehicle receives the broadcast message, parses the vehicle control message according to the security mechanism corresponding to the low-security command negotiated with the key, obtains the vehicle control command, and then controls the vehicle. Through this method, users can still control the vehicle remotely using low-security commands, ensuring a good user experience. Furthermore, the security mechanism corresponding to the low-security command negotiated between the key and the vehicle increases the security of remote vehicle control.

[0107] Based on the above embodiments, the process of negotiating the security mechanism corresponding to low-security commands between the key and the vehicle will be explained. Figure 3 A flowchart illustrating a second embodiment of the vehicle control method provided in this application is shown below. Figure 3 As shown, the vehicle control method includes the following steps:

[0108] S201. The key and vehicle establish a connection via a wireless interface to build a secure session.

[0109] In this step, the user opens and closes the car door using the contactless key, establishing a stable wireless connection between the key and the vehicle, thus constructing a secure session. This stable wireless connection refers to a secure session channel established through the wireless interface. This secure session channel can be based on Bluetooth JustWorks pairing or Out of Band (OOB) pairing, or it can be a manufacturer-defined secure session channel built on top of the Bluetooth protocol stack, or it can be based on other point-to-point wireless interfaces such as Ultra Wideband (UWB).

[0110] S202. Through a secure session, the key and the vehicle negotiate to determine the security mechanism for subsequent low-security command transmission. The security mechanism includes at least one of the following: encryption / decryption algorithm, algorithm parameters of the encryption / decryption algorithm, command count, and message format.

[0111] In this step, after establishing a secure session, the key and the vehicle negotiate to determine the security mechanism for subsequent broadcasts of low-security commands. This negotiated security mechanism differs from the initial one, and this change in negotiation better protects the security of subsequent broadcasts of low-security commands controlling the vehicle. The security mechanism includes at least one of the following: encryption / decryption algorithm, command counting, message format, and parameters required for encryption / decryption, such as a key.

[0112] It should be noted that security mechanism negotiation is not required every time a key and vehicle establish a security session, and the parameters for security mechanism negotiation do not need to be changed every time; they can be set according to user needs.

[0113] In one possible implementation, the security mechanism includes encryption / decryption algorithms and their parameters. Specifically, the vehicle and key store multiple encryption / decryption algorithms, such as Advanced Encryption Standard (AES), Data Encryption Standard (DES), Elliptic Curve Cryptography (SM2), and RSA. After establishing a secure session, the key and vehicle negotiate the encryption / decryption algorithm to be used in subsequent broadcasts and then determine the key for that algorithm. This process can involve randomly selecting an encryption / decryption algorithm or choosing one according to a set pattern. Therefore, the vehicle control method also includes: after the key generates a low-security vehicle control command, it processes it using the negotiated encryption / decryption algorithm to make it unreadable ciphertext. The vehicle can then decrypt the ciphertext based on the negotiated encryption / decryption algorithm and its parameters.

[0114] In one possible implementation, the security mechanism includes message formatting. Specifically, after establishing a secure session, the key and vehicle negotiate the format of subsequent broadcast messages, such as determining the Packet Data Unit (PDU) type, broadcast address, and Cyclic Redundancy Check (CRC) code for subsequent messages. Therefore, the vehicle control method also includes: the key generating messages according to the negotiated message format, and the vehicle parsing the control messages.

[0115] In one possible implementation, the security mechanism includes command counting. Specifically, after establishing a secure session, the key and the vehicle negotiate the command count value in subsequent broadcast messages. Each time the key broadcasts, this command count value is incremented by one. After receiving the broadcast message, the vehicle decrypts it, extracts the command count, and compares it with the command count value negotiated by the key. Because broadcast messages may be lost and not received by the vehicle, if the comparison result is greater than 0 and less than a preset value, the command is considered valid; otherwise, the command is considered invalid.

[0116] S203, Separate storage security mechanisms for keys and vehicles.

[0117] In this step, after the key and vehicle negotiate and determine the security mechanism for subsequent low-security command transmission, both the key and the vehicle store the security mechanism.

[0118] The vehicle control method provided in this embodiment first establishes a connection between the key and the vehicle via a wireless interface, constructing a secure session. Then, through the secure session, the key and the vehicle negotiate to determine a security mechanism for subsequent low-security command transmissions. The security mechanism includes at least one of encryption / decryption algorithms, algorithm parameters, command counting, and message format. Finally, this security mechanism is stored separately in the key and the vehicle. By negotiating the security mechanism for subsequent broadcasts after establishing a secure session between the key and the vehicle, the security of the negotiation process can be increased, thereby improving the security of vehicle control.

[0119] Figure 4 A flowchart illustrating Embodiment 3 of the vehicle control method provided in this application is shown below. Figure 4 As shown, based on Embodiment 1, if the user issues a high-security command using the key, the vehicle control method further includes the following steps:

[0120] S301. If the vehicle control command is a high-security command, a secure session is established with the vehicle via a wireless interface.

[0121] In this step, the key classifies the generated vehicle control commands into security levels. If the vehicle control command is a high-security command, it needs to be sent through a secure session channel. Therefore, the key actively initiates a link establishment broadcast and waits for the vehicle to establish a link, or the key listens to the vehicle broadcast and actively initiates a link establishment. The key and the vehicle shake hands with each other, negotiate wireless parameters, and establish a stable wireless connection.

[0122] S302. If establishing a security session fails, discard the vehicle control commands.

[0123] In this step, if the establishment of a secure session channel fails, high-security commands cannot be sent to the vehicle, and the high-security vehicle control commands are discarded.

[0124] Optionally, after discarding the high-security command, prompt the user.

[0125] The vehicle control method provided in this application sends high-security commands through a secure session channel. If establishing a secure session fails, the high-security commands are discarded. This method controls that high-security commands can only be sent through a secure session channel, reducing the risk of vehicle attacks.

[0126] Figure 5 This is a schematic diagram of the structure of a vehicle control device according to an embodiment of this application, as shown in the figure. Figure 5 As shown, the vehicle's control device 200 includes:

[0127] The instruction generation module 211 is used to generate vehicle control instructions in response to user key operations;

[0128] The instruction distribution module 212 is used to determine whether the security level of the vehicle control instruction is a high-security instruction or a low-security instruction;

[0129] The safety control module 213 is used to generate a vehicle control message according to the safety mechanism corresponding to the low-security instruction negotiated between the vehicle control device and the vehicle if the vehicle control instruction is a low-security instruction.

[0130] Bluetooth communication module 214 is used to broadcast the vehicle control message.

[0131] Optionally, the device further includes: a security mechanism refresh module 215 and a storage module 216;

[0132] The safety control module 213 is also used to establish a connection with the vehicle via a wireless interface and construct a security session;

[0133] The security mechanism refresh module 215 is used to negotiate with the vehicle through the security session to determine the security mechanism when sending subsequent low-security instructions. The security mechanism includes at least one of the following: an encryption / decryption algorithm, algorithm parameters of the encryption / decryption algorithm, instruction count, and message format.

[0134] Storage module 216 is used to store the security mechanism.

[0135] Optionally, the security mechanism may include: an encryption / decryption algorithm and algorithm parameters for the encryption / decryption algorithm;

[0136] Accordingly, the safety control module 213 is also used for:

[0137] The vehicle control command is encrypted according to the encryption algorithm and the algorithm parameters of the encryption and decryption algorithm to obtain the vehicle control message.

[0138] Optionally, the security control module is also used for;

[0139] If the vehicle control command is a high-security command, a secure session is established with the vehicle via a wireless interface;

[0140] If establishing a secure session fails, the vehicle control commands are discarded.

[0141] The vehicle control device provided in this embodiment is used to execute the key-side technical solution in any of the above method embodiments. Its implementation principle and technical effect are similar, and will not be described in detail here.

[0142] Figure 6 This is a schematic diagram of the structure of a second embodiment of the vehicle control device provided in this application, as shown below. Figure 6As shown, the vehicle's control device 300 includes:

[0143] The receiving module 311 is used to receive broadcast vehicle control messages;

[0144] The security parsing module 312 parses the vehicle control message according to the security mechanism corresponding to the low-security command negotiated with the contactless key of the vehicle's control device to obtain the vehicle control command.

[0145] The execution module 313 is used to execute the vehicle control commands.

[0146] Optionally, the device further includes:

[0147] The secure session control module 314 is used to establish a connection with the contactless key via a wireless interface to build a secure session;

[0148] The key management module 315 is used to negotiate through the secure session to determine the security mechanism when receiving low-security instructions. The security mechanism includes at least one of the following: an encryption / decryption algorithm, algorithm parameters of the encryption / decryption algorithm, instruction count, and message format.

[0149] Storage module 316 is used to store the security mechanism.

[0150] Optionally, the security mechanism may include: an encryption / decryption algorithm and algorithm parameters for the encryption / decryption algorithm;

[0151] Correspondingly, the security parsing module is also used for:

[0152] The vehicle control message is decrypted according to the decryption algorithm and its parameters in the encryption / decryption algorithm to obtain the vehicle control command.

[0153] The vehicle control device provided in this embodiment is used to execute the technical solution on the vehicle side in any of the above method embodiments. Its implementation principle and technical effect are similar, and will not be described in detail here.

[0154] Figure 7 This is a schematic diagram of the structure of the contactless key provided in the embodiments of this application, as shown below. Figure 7 As shown, the contactless key 400 includes:

[0155] The processor 411, the memory 412 communicatively connected to the processor, and the communication interface 413 for interacting with other devices;

[0156] The memory 412 stores computer-executed instructions;

[0157] The processor executes the computer program instructions stored in the memory to implement the key-side technical solution in any of the above method embodiments.

[0158] Optionally, the various components of the key 400 can be connected via a system bus.

[0159] The memory 412 can be a separate memory unit or a memory unit integrated into the processor 411. The number of processors 411 can be one or more.

[0160] Optionally, the contactless key may also include a display for showing the processor's processing results and for human-computer interaction. In some embodiments, the display may be the front panel of an electronic device; in other embodiments, the display may be a flexible display screen, or even a non-rectangular, irregularly shaped display screen, i.e., a non-rectangular screen. The display may be made of materials such as liquid crystal display (LCD) or organic light-emitting diode (OLED).

[0161] It should be understood that the processor 411 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this application can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0162] The system bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The system bus can be divided into address bus, data bus, control bus, etc. For ease of representation, only one thick line is used in the diagram, but this does not indicate that there is only one bus or one type of bus. Memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0163] All or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a readable memory. When the program is executed, it performs the steps of the above method embodiments; and the aforementioned memory (storage medium) includes: read-only memory (ROM), RAM, flash memory, hard disk, solid-state drive, magnetic tape, floppy disk, optical disk, and any combination thereof.

[0164] The key provided in this application embodiment can be used to execute the key-side technical solution in any of the above method embodiments. Its implementation principle and technical effect are similar, and will not be repeated here.

[0165] Figure 8 This is a structural schematic diagram of the vehicle provided in the embodiments of this application, such as... Figure 8 As shown, the vehicle 500 includes:

[0166] The system includes a controller 511, a memory 512 communicatively connected to the processor, a communication interface 513 for interacting with other devices, and a vehicle body 514.

[0167] The memory 512 stores computer-executed instructions;

[0168] The controller 511 executes the computer program instructions stored in the memory 512 to implement the technical solution on the vehicle side in any of the above method embodiments.

[0169] Optionally, the various devices mentioned above in the vehicle 500 can be connected via a system bus.

[0170] The memory 512 can be a separate memory unit or a memory unit integrated into the controller 511. The number of controllers 511 can be one or more.

[0171] It should be understood that the controller 511 can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this application can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0172] The system bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The system bus can be divided into address bus, data bus, control bus, etc. For ease of representation, only one thick line is used in the diagram, but this does not indicate that there is only one bus or one type of bus. Memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0173] All or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a readable memory. When the program is executed, it performs the steps of the above method embodiments; and the aforementioned memory (storage medium) includes: read-only memory (ROM), RAM, flash memory, hard disk, solid-state drive, magnetic tape, floppy disk, optical disk, and any combination thereof.

[0174] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the vehicle control method as described in any of the foregoing method embodiments.

[0175] The aforementioned computer-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory, electrically erasable programmable read-only memory, erasable programmable read-only memory, programmable read-only memory, read-only memory, magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0176] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.

[0177] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A method for controlling a vehicle, characterized in that, A contactless key for a vehicle, the method comprising: Responding to user key presses, generate vehicle control commands; The safety level of the vehicle control command is determined to be either a high-safety command or a low-safety command. If the vehicle control command is a low-security command, a vehicle control message is generated according to the security mechanism corresponding to the low-security command negotiated between the contactless key and the vehicle. Broadcast the vehicle control message; The method further includes; If the vehicle control command is a high-security command, a secure session is established with the vehicle via a wireless interface; If establishing a secure session fails, the vehicle control commands are discarded.

2. The method according to claim 1, characterized in that, Before generating vehicle control commands in response to user key presses, the method further includes: Establish a connection with the vehicle via a wireless interface and construct a secure session; Through the secure session, the security mechanism for subsequent low-security command transmission is determined by negotiating with the vehicle. The security mechanism includes at least one of the following: an encryption / decryption algorithm, algorithm parameters of the encryption / decryption algorithm, command count, and message format. Store the security mechanism.

3. The method according to claim 2, characterized in that, If the security mechanism includes: encryption / decryption algorithm and algorithm parameters of the encryption / decryption algorithm; Accordingly, a vehicle control message is generated based on the security mechanism corresponding to the low-security command negotiated between the contactless key and the vehicle, including: The vehicle control command is encrypted according to the encryption / decryption algorithm and its parameters to obtain the vehicle control message.

4. A method for controlling a vehicle, characterized in that, Applied to vehicles, the method includes: The vehicle control message is received when the vehicle control command is a low-security command. If the vehicle control command is a high-security command and the establishment of a secure session fails, the contactless key of the vehicle discards the vehicle control command. Based on the security mechanism corresponding to the low-security command negotiated with the contactless key of the vehicle, the vehicle control message is parsed to obtain the vehicle control command. Execute the vehicle control command.

5. The method according to claim 4, characterized in that, Before receiving the broadcast vehicle control message, the method further includes: A secure session is established by connecting the contactless key via a wireless interface. The security mechanism for receiving low-security instructions is determined through negotiation in the secure session. The security mechanism includes at least one of the following: an encryption / decryption algorithm, algorithm parameters of the encryption / decryption algorithm, instruction count, and message format. Store the security mechanism.

6. The method according to claim 5, characterized in that, If the security mechanism includes: encryption / decryption algorithm and algorithm parameters of the encryption / decryption algorithm; Accordingly, based on the security mechanism corresponding to the low-security command negotiated with the vehicle's contactless key, the vehicle control message is parsed to obtain the vehicle control command, including: The vehicle control message is decrypted according to the decryption algorithm and its parameters in the encryption / decryption algorithm to obtain the vehicle control command.

7. A vehicle control device, characterized in that, The device includes: The instruction generation module is used to generate vehicle control instructions in response to user key presses. The instruction distribution module is used to determine whether the security level of the vehicle control instruction is a high-security instruction or a low-security instruction; The safety control module is used to generate a vehicle control message according to the safety mechanism corresponding to the low-security instruction negotiated between the vehicle's control device and the vehicle if the vehicle control instruction is a low-security instruction. The Bluetooth communication module is used to broadcast the vehicle control messages; The instruction generation module is specifically used for: If the vehicle control command is a high-security command, a secure session is established with the vehicle via a wireless interface; If establishing a secure session fails, the vehicle control commands are discarded.

8. A vehicle control device, characterized in that, The device includes: A receiving module is used to receive broadcast vehicle control messages, which are generated when the vehicle control command is a low-security command. When the vehicle control command is a high-security command and the establishment of a secure session fails, the contactless key of the vehicle discards the vehicle control command. The security parsing module parses the vehicle control message according to the security mechanism corresponding to the low-security command negotiated with the contactless key of the vehicle's control device to obtain the vehicle control command. An execution module is used to execute the vehicle control commands.

9. A contactless key, characterized in that, include: The processor, the memory communicatively connected to the processor, and the communication interface for interacting with other devices; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the vehicle control method as described in any one of claims 1 to 3.

10. A vehicle, characterized in that, include: The vehicle body, controller, memory, and communication interfaces for interacting with other devices; The memory stores computer-executed instructions; The controller executes computer execution instructions stored in the memory to implement the vehicle control method as described in any one of claims 4 to 6.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the vehicle control method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • A system for controlling functions of a vehicle by speech

    GB2512313A