Vehicle digital key pairing method, device, equipment and storage medium
The mobile and vehicle key information is sent and encrypted and decrypted through the cloud server, which solves the security risks of vehicle digital keys when pairing in the network-free area, and realizes the secure pairing and control of the mobile terminal and the on-board terminal.
Patent Information
- Application Number
- CN202211701841.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-29
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2042-12-29
AI Technical Summary
When the vehicle digital key pairs without network areas, there are security risks of information transmission, and it is impossible to achieve secure pairing between mobile terminals and on-board terminals.
Digital key information is sent through a cloud server, including mobile key information and vehicle key information, and the preset key is used for encryption and decryption, ensuring the security of the communication connection channel between the first mobile terminal and the vehicle terminal, and realizing secure pairing.
The security of the communication connection channel between the mobile terminal and the vehicle terminal is improved, ensuring that the vehicle terminal is controlled under the secure channel, and reducing the safety risks of information transmission.
Smart Images

Figure CN116419180B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of vehicle technology, and in particular to a method, device, equipment, and storage medium for pairing a vehicle digital key. Background Art
[0002] With the development of intelligent vehicles, digital keys allow car owners to unlock their cars using smartphones and wearable devices, enabling them to control vehicle operations and thus improving the convenience of car use. However, while vehicle digital keys are easy to use, they face information security issues. For example, when an authorized mobile terminal and a vehicle terminal are paired for the first time, if the vehicle is parked in an area without a network, the mobile terminal needs to synchronize the digital key information from the mobile terminal to the vehicle terminal. However, this information transmission poses security risks, making it impossible to achieve secure pairing between the mobile terminal and the vehicle terminal. Summary of the Invention
[0003] The embodiments of the present application provide a method, apparatus, device and storage medium for pairing a vehicle digital key, which can achieve secure pairing of a first mobile terminal and an in-vehicle terminal, so that the first mobile terminal can control the in-vehicle terminal under the secure channel.
[0004] In a first aspect, an embodiment of the present application provides a method for pairing a vehicle digital key, which is applied to a first mobile terminal, and the method includes:
[0005] receiving digital key information sent by a cloud server in response to a sharing request, the sharing request being a request sent by a second mobile terminal to the cloud server, the digital key information including mobile terminal key information and vehicle terminal key information, the mobile terminal key information including first channel key information, and the vehicle terminal key information including second channel key information;
[0006] Decrypting the mobile terminal key information based on a preset first key to obtain a first channel key, where the first channel key is associated with the first channel key information;
[0007] Sending the second channel key information to the vehicle-mounted terminal through the communication connection channel, so that the vehicle-mounted terminal decrypts the second channel key information based on a preset second key to obtain a second channel key;
[0008] receiving association information of the second channel key sent by the vehicle-mounted terminal through the communication connection channel;
[0009] When the first channel key matches the second channel key, the communication connection channel is determined to be a secure channel, and the vehicle-mounted terminal is controlled under the secure channel.
[0010] In a second aspect, an embodiment of the present application provides a method for pairing a vehicle digital key, which is applied to an in-vehicle terminal. The method includes:
[0011] Receiving second channel key information sent by a first mobile terminal through a communication connection channel, wherein the first mobile terminal receives digital key information sent by a cloud server in response to a sharing request, the sharing request being a request sent by the second mobile terminal to the cloud server, the digital key information including mobile terminal key information and vehicle terminal key information, the mobile terminal key information including first channel key information, and the vehicle terminal key information including second channel key information; decrypting the mobile terminal key information based on a preset first key to obtain a first channel key, the first channel key being associated with the first channel key information; and sending the second channel key information to the vehicle-mounted terminal through the communication connection channel;
[0012] Decrypting the second channel key information based on a preset second key to obtain a second channel key;
[0013] The associated information of the second channel key is sent to the first mobile terminal through the communication connection channel, so that the first mobile terminal receives the second channel key sent by the vehicle-mounted terminal through the communication connection channel; when the first channel key matches the second channel key, the communication connection channel is determined to be a secure channel, and the vehicle-mounted terminal is controlled under the secure channel.
[0014] In a third aspect, an embodiment of the present application provides a method for pairing a vehicle digital key, which is applied to a cloud server. The method includes:
[0015] receiving a sharing request sent by the second mobile terminal;
[0016] In response to the sharing request, digital key information is sent to the first mobile terminal, the digital key information includes mobile key information and vehicle key information, the mobile key information includes first channel key information, and the vehicle key information includes second channel key information, so that the first mobile terminal receives the digital key information sent by the cloud server in response to the sharing request; based on the preset first key, the mobile key information is decrypted to obtain the first channel key, and the first channel key is associated with the first channel key information; the second channel key information is sent to the vehicle terminal through the communication connection channel.
[0017] In a fourth aspect, an embodiment of the present application provides a vehicle digital key pairing device, which is applied to a first mobile terminal, and the device includes:
[0018] a first receiving module, configured to receive digital key information sent by a cloud server in response to a sharing request, the sharing request being a request sent by a second mobile terminal to the cloud server, the digital key information including mobile terminal key information and vehicle terminal key information, the mobile terminal key information including first channel key information, and the vehicle terminal key information including second channel key information;
[0019] A first decryption module is configured to decrypt the mobile terminal key information based on a preset first key to obtain a first channel key, where the first channel key is associated with the first channel key information;
[0020] a first sending module, configured to send the second channel key information to the vehicle-mounted terminal through a communication connection channel, so that the vehicle-mounted terminal decrypts the second channel key information based on a preset second key to obtain a second channel key;
[0021] A second receiving module is used to receive the second channel key sent by the vehicle terminal through the communication connection channel;
[0022] The first determination module is used to determine that the communication connection channel is a secure channel when the first channel key matches the second channel key, and control the vehicle-mounted terminal under the secure channel.
[0023] In a fifth aspect, an embodiment of the present application provides a vehicle digital key pairing device, which is applied to a vehicle terminal, and the device includes:
[0024] a third receiving module, configured to receive, via the communication connection channel, second channel key information sent by a first mobile terminal, wherein the first mobile terminal receives digital key information sent by a cloud server in response to a sharing request, the sharing request being a request sent by the second mobile terminal to the cloud server, the digital key information including mobile terminal key information and vehicle terminal key information, the mobile terminal key information including first channel key information, and the vehicle terminal key information including second channel key information; decrypt the mobile terminal key information based on a preset first key to obtain a first channel key, the first channel key being associated with the first channel key information; and send the second channel key information to the vehicle-mounted terminal via the communication connection channel;
[0025] A second decryption module is configured to decrypt the second channel key information based on a preset second key to obtain a second channel key;
[0026] The second sending module is used to send the second channel key to the first mobile terminal through the communication connection channel, so that the first mobile terminal receives the second channel key sent by the vehicle-mounted terminal through the communication connection channel; when the first channel key and the second channel key match, the communication connection channel is determined to be a secure channel, and the vehicle-mounted terminal is controlled under the secure channel.
[0027] In a sixth aspect, an embodiment of the present application provides a vehicle digital key pairing device applied to a cloud server, the device comprising:
[0028] a fourth receiving module, configured to receive a sharing request sent by a second mobile terminal;
[0029] The third sending module is used to send digital key information to the first mobile terminal in response to the sharing request, where the digital key information includes mobile key information and vehicle key information, the mobile key information includes first channel key information, and the vehicle key information includes second channel key information, so that the first mobile terminal receives the digital key information sent by the cloud server in response to the sharing request; based on the preset first key, decrypt the mobile key information to obtain the first channel key, and the first channel key is associated with the first channel key information; and send the second channel key information to the vehicle terminal through the communication connection channel.
[0030] In the seventh aspect, an embodiment of the present application provides an electronic device, comprising: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, it implements the vehicle digital key pairing method described in any one of the above items.
[0031] In an eighth aspect, an embodiment of the present application provides a computer-readable storage medium, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the vehicle digital key pairing method as described in any one of the above items is implemented.
[0032] The vehicle digital key pairing method, device, equipment and storage medium of the embodiment of the present application can receive digital key information sent by the cloud server in response to a sharing request through the first mobile terminal, the digital key information includes mobile key information and vehicle key information, the mobile key information includes first channel key information, and the vehicle key information includes second channel key information. The first mobile terminal decrypts the mobile key information based on the preset first key, obtains the first channel key, and sends the second channel key information to the vehicle terminal through the communication connection channel; the vehicle terminal decrypts the second channel key information based on the second key, obtains the second channel key, and sends the second channel key to the first mobile terminal through the communication connection channel; when the first channel key and the second channel key match, the communication connection channel is determined to be a secure channel, thereby controlling the vehicle terminal under the secure channel. In this way, in an embodiment of the present application, the first channel key information and the second channel key information can be encrypted and decrypted to improve the security of each channel key, and by comparing whether the first channel key and the second channel key match, it can be determined whether the communication connection channel between the first mobile terminal and the vehicle-mounted terminal is a secure channel, so as to achieve secure pairing of the first mobile terminal and the vehicle-mounted terminal, so that the first mobile terminal can control the vehicle-mounted terminal under the secure channel. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0034] Figure 1 This is a framework diagram of a vehicle digital key pairing system provided in an embodiment of the present application;
[0035] Figure 2 1 is a flow chart of a method for pairing a vehicle digital key provided in an embodiment of the present application;
[0036] Figure 3 This is a flow chart of a scenario embodiment of a method for pairing a vehicle digital key provided in an embodiment of the present application;
[0037] Figure 4 This is a schematic diagram of the structure of a vehicle digital key pairing device provided in an embodiment of the present application;
[0038] Figure 5 1 is a schematic structural diagram of another vehicle digital key pairing device provided in an embodiment of the present application;
[0039] Figure 6 This is a structural diagram of another vehicle digital key pairing device provided in an embodiment of the present application;
[0040] Figure 7 It is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0041] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present application by illustrating the examples of the present application.
[0042] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, the elements defined by the phrase "comprising..." do not exclude the presence of other identical elements in the process, method, article, or device comprising the elements.
[0043] With the development of intelligent vehicles, digital keys allow car owners to unlock their cars using smartphones and wearable devices, enabling them to control vehicle operations and thus improving the convenience of car use. However, while vehicle digital keys are easy to use, they face information security issues. For example, when an authorized mobile terminal and a vehicle terminal are paired for the first time, if the vehicle is parked in an area without a network, the mobile terminal needs to synchronize the digital key information from the mobile terminal to the vehicle terminal. However, this information transmission poses security risks, making it impossible to achieve secure pairing between the mobile terminal and the vehicle terminal.
[0044] In order to solve the problems of the prior art, the embodiments of the present application provide a method, apparatus, device and storage medium for pairing a vehicle digital key.
[0045] first, Figure 1 A framework diagram of a vehicle digital key pairing system applicable to an embodiment of the present application is shown.
[0046] like Figure 1As shown, the vehicle digital key pairing system 100 may include: a first mobile terminal 101, a second mobile terminal 102, an in-vehicle terminal 103, and a cloud server 104. In this embodiment, the second mobile terminal 102 can be the device of the vehicle owner corresponding to the in-vehicle terminal 103, the first mobile terminal 101 is the device authorized by the second mobile terminal 102 to share the vehicle digital key, and the cloud server 104 stores digital key information and can remotely send digital key information to the first mobile terminal 101.
[0047] The first mobile terminal 101 and the second mobile terminal 102 may be computer devices used on the move, and their mobility is mainly reflected in their mobile communication capabilities and portable size. For example, they include but are not limited to smartphones, laptops, tablet computers, smart bracelets, etc.
[0048] The vehicle-mounted terminal 103 may be a carrier used in a vehicle and having information processing and computing functions. The vehicle-mounted terminal may receive and transmit information to the first mobile terminal 101 via wireless communication methods such as Bluetooth. The wireless communication method is not limited to Bluetooth and is not specifically limited in this embodiment.
[0049] The cloud server 104 can be a computing service with elastically scalable processing capabilities, and its management is simpler and more efficient than that of a physical server. The cloud server 104 can receive and send information to the first mobile terminal 101 and the second mobile terminal 102 via wireless communication. The wireless communication method is not limited to mobile communication technology or wireless broadband (Wireless-Fidelity, WIFI) and is not specifically limited in this embodiment.
[0050] The following is an introduction to the vehicle digital key pairing method provided in the embodiment of the present application.
[0051] Figure 2 1 shows a flow chart of a method for pairing a vehicle digital key provided by an embodiment of the present application. Optionally, the method 200 of the embodiment of the present application may be applied to the above Figure 1 The pairing system for the vehicle's digital key is shown.
[0052] like Figure 2 As shown, a method for pairing a vehicle digital key may include the following steps S201 to S208.
[0053] S201: The cloud server receives a sharing request sent by a second mobile terminal.
[0054] S202. The cloud server sends digital key information to the first mobile terminal in response to the sharing request. The digital key information includes mobile terminal key information and vehicle terminal key information. The mobile terminal key information includes first channel key information, and the vehicle terminal key information includes second channel key information.
[0055] S203. The first mobile terminal receives the digital key information sent by the cloud server in response to the sharing request.
[0056] S204: The first mobile terminal decrypts the mobile terminal key information based on the preset first key to obtain a first channel key, where the first channel key is associated with the first channel key information.
[0057] S205. The first mobile terminal sends the second channel key information to the vehicle-mounted terminal through the communication connection channel.
[0058] S206. The vehicle-mounted terminal receives the second channel key information sent by the first mobile terminal through the communication connection channel.
[0059] S207. The vehicle-mounted terminal decrypts the second channel key information based on the preset second key to obtain the second channel key.
[0060] S208. The vehicle-mounted terminal sends the associated information of the second channel key to the first mobile terminal through the communication connection channel.
[0061] S209. The first mobile terminal receives the association information of the second channel key sent by the vehicle-mounted terminal through the communication connection channel.
[0062] S210: When the first channel key matches the second channel key, the first mobile terminal determines that the communication connection channel is a secure channel, and controls the vehicle-mounted terminal in the secure channel.
[0063] The vehicle digital key pairing method of the embodiment of the present application can receive digital key information sent by a cloud server in response to a sharing request through a first mobile terminal, the digital key information including mobile terminal key information and vehicle terminal key information, the mobile terminal key information including first channel key information, and the vehicle terminal key information including second channel key information. The first mobile terminal decrypts the mobile terminal key information based on a preset first key to obtain the first channel key, and sends the second channel key information to the vehicle terminal through a communication connection channel; the vehicle terminal decrypts the second channel key information based on the second key to obtain the second channel key, and sends the associated information of the second channel key to the first mobile terminal through the communication connection channel; when the first channel key and the second channel key match, the communication connection channel is determined to be a secure channel, thereby controlling the vehicle terminal under the secure channel. In this way, in the embodiment of the present application, the first channel key information and the second channel key information can be encrypted and decrypted to ensure the security of each channel key, and by comparing whether the first channel key and the second channel key match, it is determined whether the communication connection channel between the first mobile terminal and the vehicle terminal is a secure channel, thereby achieving secure pairing of the first mobile terminal and the vehicle terminal, so that the first mobile terminal can control the vehicle terminal under the secure channel.
[0064] In S201 , the sharing request may be used to instruct the cloud server to send digital key information to the first mobile terminal authorized by the second mobile terminal.
[0065] The cloud server receives the sharing request sent by the second mobile terminal, which may be that the cloud server receives the sharing request sent by the second mobile terminal through mobile communication technology or WIFI technology.
[0066] In S202, the digital key information includes mobile terminal key information and vehicle terminal key information. As the name implies, the mobile terminal key information is the key information used for pairing by the first mobile terminal, and the vehicle terminal key information is the key information used for pairing by the vehicle terminal.
[0067] The mobile terminal key information includes the first channel key information, which is generated by the cloud server by encrypting the first channel key based on the preset first key. The cloud server has a preset first key for secure communication with the first mobile terminal.
[0068] Similarly, the aforementioned vehicle-side key information includes second-channel key information, which can be generated by the cloud server encrypting the second-channel key based on a preset second key. Alternatively, the cloud server can calculate the preset second key based on a preset derivation operation rule to determine a third key, and then encrypt the second channel key based on the third key to obtain the second-channel key information. The cloud server also presets a second key for secure communication with the vehicle terminal.
[0069] The first key and the second key may be 6 decimal digits.
[0070] In S203, the first mobile terminal receives the digital key information sent by the cloud server in response to the sharing request. The first mobile terminal may receive the digital key information sent by the cloud server in response to the sharing request via mobile communication technology or WIFI technology.
[0071] In S204, the first mobile terminal decrypts the mobile key information based on a preset first key to obtain a first channel key. This may be the case where the first mobile terminal decrypts the first channel key information in the mobile key information based on the preset first key to obtain the first channel key. The first mobile terminal also has a preset first key for secure communication with the cloud server.
[0072] In S205 , the communication connection channel may, for example, be a Bluetooth connection channel established between the first mobile terminal and the vehicle-mounted terminal.
[0073] In S206, the vehicle-mounted terminal receives the second channel key information sent by the first mobile terminal through the communication connection channel, which may be the case where the vehicle-mounted terminal receives the second channel key information sent by the first mobile terminal through a Bluetooth connection channel.
[0074] In S207, the above-mentioned vehicle-mounted terminal decrypts the second channel key information based on the preset second key to obtain the second channel key. The vehicle-mounted terminal may directly decrypt the second channel key information based on the preset second key to obtain the second channel key; or, the vehicle-mounted terminal may perform an operation on the preset second key based on a preset derivation operation rule to determine the third key, and decrypt the second channel key information based on the third key to obtain the second channel key.
[0075] In S208 , the association information of the second channel key may illustratively include the second channel key and / or a result of inputting the second channel key into the Bluetooth standard protocol stack for operation.
[0076] The vehicle-mounted terminal sends the associated information of the second channel key to the first mobile terminal through the communication connection channel, and the vehicle-mounted terminal may send the associated information of the second channel key to the first mobile terminal through the Bluetooth connection channel.
[0077] In S209, the first mobile terminal receives the associated information of the second channel key sent by the vehicle-mounted terminal through the communication connection channel, which may be that the first mobile terminal receives the second channel key sent by the vehicle-mounted terminal through the Bluetooth connection channel.
[0078] In S210, the situation where the first channel key and the second channel key match each other can be a situation where the calculation results of the first channel key and the second channel key are the same based on the operation of the Bluetooth standard protocol stack, or a situation where the calculation results of the first channel key and the second channel key are proportional.
[0079] In some embodiments, in order to enhance the security of the second channel key, before the above S202, the following steps may be further included:
[0080] The cloud server calculates the preset second key based on the preset derivation operation rules to determine the third key;
[0081] The cloud server encrypts the second channel key based on the third key to obtain the second channel key information.
[0082] In some embodiments, the above S207 may specifically include:
[0083] The vehicle terminal performs calculation on the preset second key based on the preset derivation calculation rule to determine the third key;
[0084] The vehicle-mounted terminal decrypts the second channel key information based on the third key to obtain the second channel key.
[0085] The above-mentioned derivation operation rules may be key derivation algorithms, illustratively including HKDF, PBKDF2 and other algorithms.
[0086] In this embodiment, the third key is generated by performing a derivative calculation on the second key, and the second channel key information is encrypted and decrypted based on the third key, thereby enhancing the security of the second channel key.
[0087] As another implementation of the present application, in order to authenticate that the second mobile terminal is a mobile terminal authorized by the first mobile terminal, the mobile terminal key information further includes first authorization key information, and the vehicle terminal key information further includes second authorization key information;
[0088] The above S204 may further include:
[0089] Decrypting the first authorization key information based on the preset first key to obtain the first authorization key;
[0090] After the above S210, the following steps may also be included:
[0091] The first mobile terminal sends the second authorization key information to the vehicle terminal;
[0092] The vehicle-mounted terminal receives the second authorization key information sent by the first mobile terminal;
[0093] The vehicle terminal decrypts the second authorization key information based on the second key to obtain the second authorization key;
[0094] The vehicle terminal calculates the second authorization key according to a preset operation rule to obtain a second authentication result;
[0095] The vehicle-mounted terminal sends an authentication request to the first mobile terminal, where the authentication request is used to request verification of whether the second mobile terminal is a mobile terminal authorized by the first mobile terminal;
[0096] The first mobile terminal receives an authentication request sent by the vehicle-mounted terminal, where the authentication request is used to request verification of whether the first mobile terminal is a mobile terminal authorized by the second mobile terminal;
[0097] The first mobile terminal calculates the first authentication result based on the operation rule on the first authorization key in response to the authentication request;
[0098] The first mobile terminal sends the first authentication result to the vehicle terminal;
[0099] The in-vehicle terminal receives the first authentication result sent by the second mobile terminal;
[0100] When the first authentication result matches the second authentication result, the in-vehicle terminal determines that the first mobile terminal is a mobile terminal authorized by the second mobile terminal.
[0101] The first authorization key information may be information generated by the cloud server by encrypting the first authorization key based on the first key.
[0102] The second authorization key information may be information generated by the cloud server by encrypting the second authorization key based on the second key.
[0103] The information interaction between the first mobile terminal and the vehicle-mounted terminal is achieved through the Bluetooth connection channel determined as a safe channel.
[0104] The above-mentioned preset operation rules may be the Milenage algorithm encryption algorithm, or other authentication encryption algorithms. This embodiment is not limited thereto and is not specifically limited here.
[0105] The first authentication result matches the second authentication result. Exemplarily, the first authentication result may be the same as the second authentication result, or the first authentication result may be proportional to the second authentication result, which is not specifically limited in this embodiment.
[0106] In this embodiment, when the communication connection channel is a secure channel, the first authorization key and the second authorization key are encrypted and decrypted to ensure the security of the authorization key, and when the first authentication result is compared with the second authentication result and matches, the first mobile terminal is identified as the mobile terminal authorized by the second mobile terminal, thereby establishing a trust relationship between the authorized first mobile terminal and the vehicle-mounted terminal.
[0107] To facilitate understanding of the vehicle digital key pairing method in the embodiment of the present application, the actual application process of the vehicle digital key pairing method is described as follows:
[0108] like Figure 3 As shown, a vehicle digital key pairing method is applied to a vehicle telematics service provider (TSP) (i.e., a cloud server), a car owner's mobile phone (i.e., a second mobile terminal), an authorized person's mobile phone (i.e., a first mobile terminal), and a Bluetooth key module of an in-vehicle terminal.
[0109] Among them, Key1 (i.e. the second key): the secure communication key between the vehicle side and Tsp, which has been preset on the vehicle side before the start of this process.
[0110] Key2 (i.e. the first key): the secure communication key between the mobile phone and Tsp, which has been preset on the mobile phone before this process starts.
[0111] Key3 (the third key): A key derived from key1, specifically used to encrypt the vehicle-side passkey (which can be randomly generated by TSP).
[0112] Passkey: A 6-digit number (decimal) used in the Bluetooth LE passkey entry pairing method.
[0113] Authorization key Authkey: A key customized based on the application layer by the authorized person's mobile phone and the vehicle-side Bluetooth key module and used for authorization and authentication.
[0114] The specific steps include:
[0115] Step 1: The car owner's mobile phone sends a sharing request to Tsp.
[0116] Step 2: Tsp receives the sharing request and sends the vehicle key information and mobile key information to the authorized person's mobile phone. The vehicle key information includes the encrypted passkey encrypted using key3.
[0117] Step 3: The mobile phone uses key2 to decrypt the mobile key information and obtain the first channel key passkey, the first authorization key Authkey, etc.
[0118] Step 4: The vehicle-side Bluetooth key module sends a broadcast signal to the authorized person's mobile phone.
[0119] Step 5: The authorized person's mobile phone receives the broadcast signal and sends a connection request to the vehicle's Bluetooth key module.
[0120] Step 6: The vehicle-side Bluetooth key module sends a successful connection signal to the authorized person’s mobile phone.
[0121] Step 7: Pass the encrypted passkey to the vehicle-side Bluetooth key module.
[0122] Step 8: The vehicle-side Bluetooth key module uses key1 to derive key3, and then uses key3 to decrypt and encrypt passkey to obtain the second passkey.
[0123] Step 9: The authorized person's mobile phone sends a pairing request to the vehicle's Bluetooth key module.
[0124] Step 10: The authorized person's mobile phone inputs the Bluetooth standard protocol stack based on the first passkey for calculation, and interacts with the vehicle-side Bluetooth key module for the calculation results.
[0125] Step 11: The vehicle-side Bluetooth key module inputs the Bluetooth standard protocol stack based on the second passkey to perform calculations, and interacts with the authorized person's mobile phone to obtain the calculation results.
[0126] Step 12: Pairing response, the vehicle-side Bluetooth key module sends the pairing result to the authorized person's mobile phone (pairing is successful when the first passkey and the second passkey are the same).
[0127] Step 13: Send the first Authkey in the vehicle key information to the vehicle Bluetooth key module. The first Authkey is obtained by encrypting Tsp using key1.
[0128] Steps 14 to 18 are a security authentication process based on random numbers, such as HMAC-SHA256. The key used for authentication is AuthKey. The message to be authenticated can use fields such as the random number generated in step 11. Specific authentication mainly occurs after the Bluetooth connection is established.
[0129] During the entire passkey pairing process, there is no need to manually enter the passkey on the car or mobile phone side, as it is all entered automatically by the program.
[0130] In this embodiment, after passkey pairing, the secure Bluetooth-based encrypted channel ensures that parameters such as random numbers are private information, further enhancing security. Furthermore, the identities of the vehicle and the authorized person's mobile phone can be authenticated, further reducing security risks when directly synchronizing vehicle key information from the authorized mobile device to the vehicle for the first time, thereby establishing a trust relationship between the authorized mobile device and the vehicle.
[0131] Based on the vehicle digital key pairing method provided in the above embodiment, this application also provides a specific implementation of a vehicle digital key pairing device. It is understood that the relevant descriptions in the following device embodiments can refer to the above method embodiments, and for the sake of brevity, they are not repeated here. Please refer to the following embodiments.
[0132] See Figure 4 , is a structural diagram of a vehicle digital key pairing device 400 provided in an embodiment of the present application, which is applied to a first mobile terminal. The above-mentioned device 400 may include: a first receiving module 401, a first decryption module 402, a first sending module 403, a second receiving module 404 and a first determination module 405.
[0133] A first receiving module 401 is configured to receive digital key information sent by the cloud server in response to a sharing request, where the sharing request is a request sent by the second mobile terminal to the cloud server, the digital key information including mobile terminal key information and vehicle terminal key information, the mobile terminal key information including first channel key information, and the vehicle terminal key information including second channel key information;
[0134] A first decryption module 402 is configured to decrypt the mobile terminal key information based on a preset first key to obtain a first channel key, where the first channel key is associated with the first channel key information;
[0135] The first sending module 403 is configured to send the second channel key information to the vehicle terminal through the communication connection channel, so that the vehicle terminal decrypts the second channel key information based on a preset second key to obtain the second channel key;
[0136] The second receiving module 404 is configured to receive the associated information of the second channel key sent by the vehicle terminal through the communication connection channel;
[0137] The first determining module 405 is configured to determine that the communication connection channel is a secure channel when the first channel key matches the second channel key, and control the vehicle-mounted terminal in the secure channel.
[0138] See Figure 5 , is a structural diagram of a vehicle digital key pairing device 500 provided in an embodiment of the present application, which is applied to a vehicle-mounted terminal. The above-mentioned device 500 may include: a third receiving module 501, a second decryption module 502 and a second sending module 503.
[0139] The third receiving module 501 is configured to receive second channel key information sent by the first mobile terminal through the communication connection channel, wherein the first mobile terminal receives digital key information sent by the cloud server in response to a sharing request, the sharing request being a request sent by the second mobile terminal to the cloud server, the digital key information including mobile terminal key information and vehicle terminal key information, the mobile terminal key information including first channel key information, and the vehicle terminal key information including second channel key information; decrypt the mobile terminal key information based on a preset first key to obtain the first channel key, the first channel key being associated with the first channel key information; and send the second channel key information to the vehicle terminal through the communication connection channel;
[0140] A second decryption module 502 is configured to decrypt the second channel key information based on a preset second key to obtain a second channel key;
[0141] The second sending module 503 is used to send the associated information of the second channel key to the first mobile terminal through the communication connection channel, so that the first mobile terminal receives the second channel key sent by the vehicle-mounted terminal through the communication connection channel; when the first channel key and the second channel key match, the communication connection channel is determined to be a secure channel, and the vehicle-mounted terminal is controlled under the secure channel.
[0142] See Figure 6 , is a structural diagram of a vehicle digital key pairing device 600 provided in an embodiment of the present application, which is applied to a cloud server. The above-mentioned device 600 may include: a fourth receiving module 601 and a third sending module 602.
[0143] The fourth receiving module 601 is configured to receive a sharing request sent by a second mobile terminal;
[0144] The third sending module 602 is used to send digital key information to the first mobile terminal in response to a sharing request. The digital key information includes mobile key information and vehicle key information. The mobile key information includes first channel key information, and the vehicle key information includes second channel key information, so that the first mobile terminal receives the digital key information sent by the cloud server in response to the sharing request; based on the preset first key, decrypt the mobile key information to obtain the first channel key, and the first channel key is associated with the first channel key information; and send the second channel key information to the vehicle terminal through the communication connection channel.
[0145] The vehicle digital key pairing device of the embodiment of the present application can receive digital key information sent by a cloud server in response to a sharing request through a first mobile terminal. The digital key information includes mobile key information and vehicle key information. The mobile key information includes first channel key information and vehicle key information. The first mobile terminal decrypts the mobile key information based on a preset first key to obtain the first channel key and sends the second channel key information to the vehicle terminal through a communication connection channel. The vehicle terminal decrypts the second channel key information based on the second key to obtain the second channel key and sends the associated information of the second channel key to the first mobile terminal through the communication connection channel. When the first channel key and the second channel key match, the communication connection channel is determined to be a secure channel, thereby controlling the vehicle terminal under the secure channel. In this way, in the embodiment of the present application, the first channel key information and the second channel key information can be encrypted and decrypted to improve the security of each channel key. By comparing whether the first channel key and the second channel key match, it is determined whether the communication connection channel between the first mobile terminal and the vehicle terminal is a secure channel, thereby achieving secure pairing between the first mobile terminal and the vehicle terminal, so that the first mobile terminal can control the vehicle terminal under the secure channel.
[0146] As another implementation of the present application, in order to authenticate that the second mobile terminal is a mobile terminal authorized by the first mobile terminal, the mobile terminal key information further includes first authorization key information, and the vehicle terminal key information further includes second authorization key information;
[0147] The first decryption module 402 may also be configured to decrypt the first authorization key information based on a preset first key to obtain the first authorization key;
[0148] The above-mentioned apparatus 400 may further include:
[0149] a fourth sending module, configured to send the second authorization key information to the vehicle-mounted terminal, so that the vehicle-mounted terminal decrypts the second authorization key information based on the second key to obtain the second authorization key; calculates the second authorization key according to a preset operation rule to obtain a second authentication result; and sends an authentication request to the first mobile terminal;
[0150] a fifth receiving module, configured to receive an authentication request sent by the vehicle-mounted terminal, the authentication request being used to request verification of whether the first mobile terminal is a mobile terminal authorized by the second mobile terminal;
[0151] A first calculation module is configured to calculate, in response to the authentication request, the first authorization key according to a calculation rule to obtain a first authentication result;
[0152] The fifth sending module is configured to send the first authentication result to the vehicle terminal, so that the vehicle terminal determines that the first mobile terminal is a mobile terminal authorized by the second mobile terminal when the first authentication result matches the second authentication result.
[0153] As another implementation of the present application, in order to authenticate that the second mobile terminal is a mobile terminal authorized by the first mobile terminal, the mobile terminal key information further includes first authorization key information, and the vehicle terminal key information further includes second authorization key information;
[0154] The above-mentioned apparatus 500 may further include:
[0155] A sixth receiving module, configured to receive second authorization key information sent by the first mobile terminal;
[0156] A third decryption module is used to decrypt the second authorization key information based on the second key to obtain the second authorization key;
[0157] A second calculation module is used to calculate the second authentication result based on the second authorization key according to a preset operation rule;
[0158] a sixth sending module, configured to send an authentication request to the first mobile terminal, the authentication request being used to request verification of whether the second mobile terminal is a mobile terminal authorized by the first mobile terminal, so that the first mobile terminal responds to the authentication request, calculates the first authorization key according to the operation rule to obtain a first authentication result, and sends the first authentication result to the in-vehicle terminal;
[0159] a seventh receiving module, configured to receive a first authentication result sent by the second mobile terminal;
[0160] The second determining module is configured to determine that the first mobile terminal is a mobile terminal authorized by the second mobile terminal if the first authentication result matches the second authentication result.
[0161] As another implementation of the present application, in order to enhance the security of the second channel key, the apparatus 600 may further include:
[0162] A second derivation operation unit, configured to calculate the preset second key based on a preset derivation operation rule to determine a third key;
[0163] The encryption module is used to encrypt the second channel key based on the third key to obtain the second channel key information.
[0164] In some embodiments, the second decryption module 502 may specifically include:
[0165] A first derivation operation unit, configured to operate the preset second key based on a preset derivation operation rule to determine a third key;
[0166] The decryption unit is configured to decrypt the second channel key information based on the third key to obtain the second channel key.
[0167] Figure 7 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application is shown.
[0168] The electronic device may include a processor 701 and a memory 702 storing computer program instructions.
[0169] Specifically, the processor 701 may include a central processing unit (CPU), or an application-specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.
[0170] The memory 702 may include a large capacity memory for data or instructions. By way of example and not limitation, the memory 702 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory 702 may include removable or non-removable (or fixed) media. Where appropriate, the memory 702 may be inside or outside the integrated gateway disaster recovery device. In a specific embodiment, the memory 702 is a non-volatile solid-state memory.
[0171] In certain embodiments, the memory 702 may include read-only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical, or other physical / tangible memory storage devices. Thus, in general, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to an aspect of the present disclosure.
[0172] The processor 701 reads and executes computer program instructions stored in the memory 702 to implement any one of the vehicle digital key pairing methods in the above embodiments.
[0173] In one example, the electronic device may further include a communication interface 703 and a bus 710. Figure 7 As shown, the processor 701, the memory 702, and the communication interface 703 are connected via a bus 710 and communicate with each other.
[0174] The communication interface 703 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present application.
[0175] Bus 710 comprises hardware, software or both, couples the parts of electronic equipment to each other.For example, and not limitation, bus can comprise accelerated graphics port (AGP) or other graphics bus, enhanced industry standard architecture (EISA) bus, front side bus (FSB), hypertransport (HT) interconnection, industry standard architecture (ISA) bus, infinite bandwidth interconnection, low pin count (LPC) bus, memory bus, micro channel architecture (MCA) bus, peripheral component interconnection (PCI) bus, PCI-Express (PCI-X) bus, serial advanced technology attachment (SATA) bus, video electronics standard association local (VLB) bus or other suitable bus or two or more of these combinations.In suitable cases, bus 710 can comprise one or more buses.Although the present application embodiment describes and shows specific bus, the application considers any suitable bus or interconnection.
[0176] The electronic device can execute the vehicle digital key pairing method in the embodiment of the present application, thereby realizing the combination Figure 1 、 Figures 4 to 6 A method and device for pairing a vehicle digital key are described.
[0177] In addition, in conjunction with the vehicle digital key pairing method in the above embodiments, embodiments of the present application may provide a computer-readable storage medium for implementation. The computer-readable storage medium stores computer program instructions; when the computer program instructions are executed by a processor, any of the vehicle digital key pairing methods in the above embodiments is implemented.
[0178] It should be understood that the present application is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, a detailed description of known methods is omitted here. In the above embodiments, several specific steps are described and illustrated as examples. However, the method process of the present application is not limited to the specific steps described and illustrated. Those skilled in the art can make various changes, modifications, and additions, or change the order of the steps after understanding the spirit of the present application.
[0179] The functional blocks shown in the above-described block diagram can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of the present application are programs or code segments that are used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link by a data signal carried in a carrier wave. "Machine-readable medium" can include any medium that can store or transmit information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROMs, flash memories, erasable ROMs (EROMs), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segment can be downloaded via a computer network such as the Internet, an intranet, etc.
[0180] It should also be noted that the exemplary embodiments mentioned in this application describe some methods or systems based on a series of steps or devices. However, this application is not limited to the order of the above steps. In other words, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0181] Aspects of the present disclosure have been described above with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present disclosure. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer or other programmable data processing device to produce a machine so that these instructions executed by the processor of the computer or other programmable data processing device enable the implementation of the function / action specified in one or more boxes of the flowchart and / or block diagram. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor or a field programmable logic circuit. It is also understood that each box in the block diagram and / or flowchart and the combination of the boxes in the block diagram and / or flowchart can also be implemented by dedicated hardware that performs the specified function or action, or can be implemented by a combination of dedicated hardware and computer instructions.
[0182] The above description is only a specific embodiment of the present application. Those skilled in the art will clearly understand that for the convenience and brevity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present application, and these modifications or replacements should be included in the scope of protection of the present application.
Claims
1. A method for pairing a vehicle digital key, characterized in that: Applied to a first mobile terminal, the method includes: receiving digital key information sent by a cloud server in response to a sharing request, the sharing request being a request sent by a second mobile terminal to the cloud server, the digital key information including mobile terminal key information and vehicle terminal key information, the mobile terminal key information including first channel key information, and the vehicle terminal key information including second channel key information; Decrypting the mobile terminal key information based on a preset first key to obtain a first channel key, where the first channel key is associated with the first channel key information; Sending the second channel key information to the vehicle terminal through the communication connection channel, so that the vehicle terminal decrypts the second channel key information based on a preset second key to obtain a second channel key; receiving association information of the second channel key sent by the vehicle-mounted terminal through the communication connection channel; When the first channel key matches the second channel key, the communication connection channel is determined to be a secure channel, and the vehicle-mounted terminal is controlled under the secure channel.
2. The method according to claim 1, characterized in that The mobile terminal key information also includes first authorization key information, and the vehicle terminal key information also includes second authorization key information; The decrypting the mobile terminal key information based on the preset first key to obtain the first channel key also includes: Decrypting the first authorization key information based on a preset first key to obtain a first authorization key; After determining that the communication connection channel is a secure channel, the method further includes: Sending the second authorization key information to the vehicle-mounted terminal, so that the vehicle-mounted terminal decrypts the second authorization key information based on the preset second key to obtain a second authorization key; calculating the second authorization key according to a preset operation rule to obtain a second authentication result; and sending an authentication request to the first mobile terminal; receiving the authentication request sent by the vehicle-mounted terminal, wherein the authentication request is used to request verification of whether the first mobile terminal is a mobile terminal authorized by the second mobile terminal; In response to the authentication request, calculating the first authorization key according to the operation rule to obtain a first authentication result; The first authentication result is sent to the vehicle-mounted terminal, so that the vehicle-mounted terminal determines that the first mobile terminal is a mobile terminal authorized by the second mobile terminal when the first authentication result matches the second authentication result.
3. A method for pairing a vehicle digital key, characterized in that: Applied to a vehicle-mounted terminal, the method includes: Receiving second channel key information sent by a first mobile terminal through a communication connection channel, wherein the first mobile terminal receives digital key information sent by a cloud server in response to a sharing request, the sharing request being a request sent by the second mobile terminal to the cloud server, the digital key information including mobile terminal key information and vehicle terminal key information, the mobile terminal key information including first channel key information, and the vehicle terminal key information including second channel key information; decrypting the mobile terminal key information based on a preset first key to obtain a first channel key, the first channel key being associated with the first channel key information; and sending the second channel key information to the vehicle-mounted terminal through the communication connection channel; Decrypting the second channel key information based on a preset second key to obtain a second channel key; The associated information of the second channel key is sent to the first mobile terminal through the communication connection channel, so that the first mobile terminal receives the second channel key sent by the vehicle-mounted terminal through the communication connection channel; when the first channel key matches the second channel key, the communication connection channel is determined to be a secure channel, and the vehicle-mounted terminal is controlled under the secure channel.
4. The method according to claim 3, characterized in that The mobile terminal key information also includes first authorization key information, and the vehicle terminal key information also includes second authorization key information; After sending the second channel key to the first mobile terminal through the communication connection channel, the method further includes: receiving the second authorization key information sent by the first mobile terminal; decrypting the second authorization key information based on the second key to obtain a second authorization key; Calculating the second authorization key according to a preset operation rule to obtain a second authentication result; sending an authentication request to the first mobile terminal, the authentication request being used to request verification of whether the first mobile terminal is a mobile terminal authorized by the second mobile terminal, so that the first mobile terminal responds to the authentication request, calculates the first authorization key according to the operation rule to obtain a first authentication result; and sending the first authentication result to the in-vehicle terminal; receiving a first authentication result sent by the first mobile terminal; In a case where the first authentication result matches the second authentication result, it is determined that the first mobile terminal is a mobile terminal authorized by the second mobile terminal.
5. The method according to claim 3, characterized in that The decrypting the second channel key information based on the preset second key to obtain the second channel key includes: Based on a preset derivation operation rule, the preset second key is operated to determine the third key; The second channel key information is decrypted based on the third key to obtain a second channel key.
6. A method for pairing a vehicle digital key, characterized in that: Applied to a cloud server, the method includes: receiving a sharing request sent by the second mobile terminal; In response to the sharing request, digital key information is sent to the first mobile terminal, the digital key information includes mobile key information and vehicle key information, the mobile key information includes first channel key information, and the vehicle key information includes second channel key information, so that the first mobile terminal receives the digital key information sent by the cloud server in response to the sharing request; based on the preset first key, the mobile key information is decrypted to obtain the first channel key, and the first channel key is associated with the first channel key information; the second channel key information is sent to the vehicle terminal through the communication connection channel, so that the vehicle terminal decrypts the second channel key information based on the preset second key to obtain the second channel key; the first mobile terminal receives the association information of the second channel key sent by the vehicle terminal through the communication connection channel; when the first channel key matches the second channel key, the communication connection channel is determined to be a secure channel, and the vehicle terminal is controlled under the secure channel.
7. The method according to claim 6, characterized in that Before sending the digital key information to the first mobile terminal in response to the sharing request, the method further includes: Calculating the preset second key based on a preset derivation operation rule to determine the third key; The second channel key is encrypted based on the third key to obtain second channel key information.
8. A vehicle digital key pairing device, characterized in that: Applied to a first mobile terminal, the apparatus includes: a first receiving module, configured to receive digital key information sent by a cloud server in response to a sharing request, the sharing request being a request sent by a second mobile terminal to the cloud server, the digital key information including mobile terminal key information and vehicle terminal key information, the mobile terminal key information including first channel key information, and the vehicle terminal key information including second channel key information; A first decryption module is configured to decrypt the mobile terminal key information based on a preset first key to obtain a first channel key, where the first channel key is associated with the first channel key information; a first sending module, configured to send the second channel key information to the vehicle-mounted terminal through the communication connection channel, so that the vehicle-mounted terminal decrypts the second channel key information based on a preset second key to obtain a second channel key; A second receiving module is configured to receive associated information of the second channel key sent by the vehicle-mounted terminal through the communication connection channel; The first determining module is configured to determine that the communication connection channel is a secure channel when the first channel key matches the second channel key, and control the vehicle-mounted terminal under the secure channel.
9. A vehicle digital key pairing device, characterized in that: Applied to a vehicle-mounted terminal, the device includes: a third receiving module, configured to receive, via the communication connection channel, second channel key information sent by a first mobile terminal, wherein the first mobile terminal receives digital key information sent by a cloud server in response to a sharing request, the sharing request being a request sent by the second mobile terminal to the cloud server, the digital key information including mobile terminal key information and vehicle terminal key information, the mobile terminal key information including first channel key information, and the vehicle terminal key information including second channel key information; decrypt the mobile terminal key information based on a preset first key to obtain a first channel key, the first channel key being associated with the first channel key information; and send the second channel key information to the vehicle-mounted terminal via the communication connection channel; A second decryption module is configured to decrypt the second channel key information based on a preset second key to obtain a second channel key; The second sending module is used to send the associated information of the second channel key to the first mobile terminal through the communication connection channel, so that the first mobile terminal receives the second channel key sent by the vehicle-mounted terminal through the communication connection channel; when the first channel key and the second channel key match, the communication connection channel is determined to be a secure channel, and the vehicle-mounted terminal is controlled under the secure channel.
10. A vehicle digital key pairing device, characterized in that: Applied to a cloud server, the device includes: a fourth receiving module, configured to receive a sharing request sent by a second mobile terminal; The third sending module is used to send digital key information to the first mobile terminal in response to the sharing request, where the digital key information includes mobile key information and vehicle key information, the mobile key information includes first channel key information, and the vehicle key information includes second channel key information, so that the first mobile terminal receives the digital key information sent by the cloud server in response to the sharing request; decrypts the mobile key information based on a preset first key to obtain a first channel key, and the first channel key is associated with the first channel key information; sends the second channel key information to the vehicle terminal through the communication connection channel, so that the vehicle terminal decrypts the second channel key information based on a preset second key to obtain a second channel key; the first mobile terminal receives the association information of the second channel key sent by the vehicle terminal through the communication connection channel; when the first channel key matches the second channel key, determines that the communication connection channel is a secure channel, and controls the vehicle terminal under the secure channel.
11. An electronic device, characterized in that: The device includes: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, it implements the vehicle digital key pairing method as described in any one of claims 1 to 7.
12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer program instructions, which, when executed by a processor, implement the vehicle digital key pairing method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Vehicle digital key sharing method and system and mobile terminal
CN110290525A
Communication verification method and system, mobile terminal and vehicle terminal
CN111083696A