A method and system for sharing vehicle bluetooth digital key implementation control
Patent Information
- Application Number
- CN202310613244.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-29
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2043-05-29
AI Technical Summary
实际生活中,车辆经常停在地下车库等网络不好的地方,而蓝牙数字钥匙由云端生成无法正常下发到车端,从而导致分享流程无法完成,那么被分享人就无法和车端建立可信的连接
[0014]本发明具有如下优点:本发明在此提供一种分享车辆蓝牙数字钥匙实现控车的方法和系统,分享蓝牙数字钥匙后,车端在无网状态下通过对蓝牙数字钥匙验签和比对临时密码,确定被分享人身份来达到安全控车的目的;本发明能够在车端处于无网络条件下分享钥匙实现控车,因而给车主带来方便;同时提出了钥匙对账方式,车端在无网络情况下能收回钥匙,给车主带来安全。具体体现为;
Smart Images

Figure CN116614729B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vehicle technology, specifically to a method and system for controlling a vehicle by sharing a Bluetooth digital key. Background Technology
[0002] With the development of the automotive industry, in-vehicle Bluetooth digital keys are becoming increasingly common. Car owners can control their vehicles via Bluetooth using their mobile phones, including opening and closing doors and windows, bringing convenience to car owners. Just as car owners can share their physical keys to lend their cars to family and friends, the same applies to Bluetooth digital keys. Car owners can share their Bluetooth digital keys with family and friends to achieve the same car control effect as with physical keys, and they can set the validity period for a few hours or days.
[0003] However, the difference between Bluetooth digital keys and other types of Bluetooth digital keys lies in the fact that Bluetooth digital keys need to be generated in the cloud and distributed to the vehicle's key whitelist to complete the key sharing process. In real life, vehicles are often parked in underground garages or other places with poor network connectivity. Since the Bluetooth digital key generated in the cloud cannot be properly distributed to the vehicle, the sharing process cannot be completed, and the recipient cannot establish a reliable connection with the vehicle. Furthermore, if the Bluetooth digital key used to lend out a car has an excessively long validity period (e.g., one month), and the user wants to revoke the Bluetooth digital key access midway through the period, this cannot be done when the car is parked in an underground garage with poor network connectivity. Summary of the Invention
[0004] Therefore, in order to overcome the above-mentioned shortcomings, the present invention provides a method and system for controlling a vehicle by sharing a Bluetooth digital key. After sharing the Bluetooth digital key, the vehicle can determine the identity of the person whose key is being shared and verify the temporary password when there is no network connection, thereby achieving the purpose of secure vehicle control.
[0005] This invention is implemented by constructing a method for controlling a vehicle by sharing a vehicle's Bluetooth digital key, characterized by comprising: The sharing terminal sends a request to the cloud to share the Bluetooth digital key with the sharing terminal. After receiving the request, the cloud sends a notification to the sharing terminal. The user's terminal requests a Bluetooth digital key from the cloud, and the cloud sends the Bluetooth digital key data to the user's terminal after digital signature. The sharing terminal sends a request to the cloud, which is used by the cloud to generate a temporary password according to a preset algorithm. After receiving the request, the cloud responds and generates a temporary password and sends it to the sharing terminal. The user's terminal obtains a temporary password from the sharer; When the user's terminal establishes a Bluetooth connection with the vehicle's terminal (which is offline) to control the vehicle, the vehicle's terminal performs Bluetooth digital key verification and temporary password comparison. This process is as follows: First, the user's terminal sends a verification request to the vehicle's terminal using the acquired Bluetooth digital key and temporary password. During verification, the vehicle's terminal holds a cloud public key, which is used to verify the Bluetooth digital key. Simultaneously, the vehicle's terminal generates a temporary password using its own pre-set algorithm, which is then compared with the temporary password on the user's terminal. If both the Bluetooth digital key verification and the temporary password comparison pass, the vehicle's terminal and the user's terminal establish a connection, allowing the user to control the vehicle.
[0006] Preferably, before sharing the Bluetooth digital key, the method further includes: pre-setting a temporary password generation algorithm in the cloud; the user's terminal sends a request to the cloud and sets the temporary password generation method; the cloud responds and communicates with the vehicle terminal with network access to synchronize the algorithm corresponding to the temporary password generation method to the vehicle terminal.
[0007] Preferably, when the vehicle terminal initially establishes a connection with the shared user's operating terminal in a network-free state, the sharing user provides a temporary password to the shared user. The sharing user's operating terminal will set the validity period of the temporary password. The temporary password can only be used within the validity period. If the shared user reconnects to control the vehicle after the validity period expires, a new temporary password needs to be obtained from the sharing user's operating terminal again.
[0008] Preferably, it also includes the following Bluetooth digital key recycling operation: the sharing terminal sends a request to the cloud to recycle the Bluetooth digital key shared with the sharing terminal; after receiving the request, the cloud cancels the Bluetooth digital key on the sharing terminal and notifies the sharing terminal. When the vehicle is connected to the internet, the cloud communicates with the vehicle and sends the cancelled Bluetooth digital key to the vehicle's key blacklist from the cloud.
[0009] Preferably, during the period when the person being shared controls the vehicle, the person being shared's operating terminal also needs to perform the following reconciliation operation: The person being shared's operating terminal needs to perform key reconciliation with the cloud at least once within a certain period of time to obtain the latest Bluetooth digital key status information from the cloud. The Bluetooth digital key of the person being shared's operating terminal stores the latest reconciliation time. When the person being shared's operating terminal connects to the vehicle terminal again, the vehicle terminal will automatically identify the most recent reconciliation time of the Bluetooth digital key of the person being shared's operating terminal. If it is identified that the person being shared's operating terminal has not performed key reconciliation with the cloud within the corresponding time, the connection will not pass the vehicle terminal's verification.
[0010] Preferably, the temporary password generation includes the unique identifier of the sharer, the unique identifier of the recipient, and the current time.
[0011] A vehicle Bluetooth digital key sharing system, characterized in that: the system includes a sharing terminal, a sharing recipient terminal, a cloud terminal, and a vehicle terminal; The sharing terminal is used to interact with the cloud, send requests to the cloud for sharing and recycling of Bluetooth digital keys, and set the temporary password generation method in the cloud. The user's terminal is used to interact with the cloud, complete the application for the Bluetooth digital key and store it locally, and establish a secure Bluetooth channel between the mobile phone's Bluetooth module and the vehicle to control the vehicle; Cloud-based: Used to generate and cancel Bluetooth digital keys and distribute them to the operator and vehicle terminals; and to distribute temporary key generation algorithms to the vehicle terminal; Vehicle-side: The vehicle-side includes a TBOX and a Bluetooth communication device; the TBOX is responsible for communicating with the cloud, completing the issuance of the Bluetooth digital key and the transmission of cloud information; Bluetooth communication devices are used to establish Bluetooth connections with the user's operating device in the absence of a network, and to complete signature verification and temporary password comparison.
[0012] Preferably, in this system, the communication between the vehicle and the cloud is encrypted with SSL. The vehicle stores the public key of the cloud, and the cloud holds the public and private keys for communication. The Bluetooth digital key data itself carries cloud signature information, and when the connection is established, the mobile terminal transmits the signature data to the vehicle terminal for verification, which is used to prove that the Bluetooth digital key was generated by the cloud.
[0013] Preferably, in this system, the sharing terminal is also used to send a temporary password to the sharing terminal; after being authorized, the sharing user can also synchronously obtain their own Bluetooth digital key. Preferably, in this system, the user's terminal is also used to communicate with the cloud periodically to complete information reconciliation.
[0014] This invention has the following advantages: It provides a method and system for controlling a vehicle by sharing a Bluetooth digital key. After sharing the Bluetooth digital key, the vehicle can securely control the vehicle by verifying the signature of the shared key and comparing it with a temporary password in a network-free state. This invention enables vehicle control by sharing the key even when the vehicle is without a network connection, thus providing convenience for car owners. It also proposes a key reconciliation method, allowing the vehicle to retrieve the key in a network-free environment, enhancing security for the car owner. Specifically, this is manifested in: First, this method employs asymmetric encryption for communication between the vehicle and the cloud during implementation, ensuring data security and tamper resistance. Furthermore, asymmetric encryption provides non-repudiation, guaranteeing the sender's identity during data transmission. Since the Bluetooth digital key provided by the cloud to the shared user is digitally signed, the public key can verify that the data was sent from the cloud even when the vehicle has no network connection. When the shared user's device establishes a Bluetooth connection with the vehicle, the Bluetooth digital key is provided to the vehicle. Even if the vehicle does not have this key's whitelist at this time, the Bluetooth digital key signature can still be verified.
[0015] Secondly, a temporary password generation algorithm is pre-installed in the cloud, capable of generating relevant temporary passwords based on the current scenario. This algorithm is pre-installed on the vehicle, ensuring that the temporary passwords generated in the cloud and on the vehicle are consistent. The vehicle compares the temporary password provided by the recipient (generated and provided by the vehicle owner) with its own generated temporary password to determine if the Bluetooth digital key has been shared with the owner's authorization. By confirming both the key's issuance from the cloud and the owner's authorization, the Bluetooth digital key can be trusted as authentic and reliable, thus establishing secure Bluetooth communication.
[0016] Third, based on the key-based reconciliation method, namely the "Bluetooth digital key reconciliation" between the shared user (APP) and the cloud, the mobile app's Bluetooth digital key uses a digital signature and stores the latest reconciliation time. For example, the car owner can set up reconciliation once within 6 hours before controlling the car. If the shared user does not reconcile with the cloud more than 6 hours before controlling the car, it is considered an abnormal situation, and the shared user will not be able to control the car until the reconciliation is completed through the mobile app. Attached Figure Description
[0017] Figure 1 This is a schematic diagram illustrating the interaction process of a car owner sharing a Bluetooth digital key; Figure 2 This is a schematic diagram illustrating the process of the cloud-based vehicle sending a temporary password generation algorithm to the vehicle. Figure 3 This is a schematic diagram illustrating the process of connecting and controlling the vehicle when it is offline. Figure 4 This is a diagram illustrating how the owner can recycle the Bluetooth digital key when the vehicle has internet access. Figure 5 This is a schematic diagram of the Bluetooth digital key reconciliation process of the present invention; Figure 6 This is a system block diagram of the present invention. Detailed Implementation
[0018] The following will be combined with the appendix Figures 1-6This invention will be described in detail, and the technical solutions in the embodiments of this invention will be clearly and completely described. Obviously, the described embodiments are only some embodiments of this invention, and not all embodiments. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.
[0019] This invention provides a method for controlling a vehicle by sharing a Bluetooth digital key. The method enables vehicle control even when the vehicle is offline. This will be described in detail below. like Figure 1 The diagram illustrates the process of a car owner sharing a Bluetooth digital key; the steps involved in this process are: Step 1: The sharing terminal (i.e., the car owner's mobile APP) sends a request to the cloud to share the Bluetooth digital key with the sharing terminal (not the car owner's mobile APP, i.e., the third party's mobile APP). Step 2: After receiving the request, the cloud sends a notification to the client's terminal. Step 3: The user's device requests a Bluetooth digital key from the cloud. Step 4: The cloud sends the Bluetooth digital key data to the sharing user's terminal after digital signature. This process represents the process of a non-car owner obtaining the Bluetooth digital key. At this time, the sharing user's terminal (i.e., the car owner's mobile APP), the sharing user's terminal (the non-car owner's mobile APP, i.e., the third party's mobile APP), and the cloud are all connected to the internet.
[0020] During the above process, the cloud will also send the Bluetooth digital key to the corresponding key whitelist on the vehicle.
[0021] like Figure 2 The diagram illustrates the process of the cloud sending a temporary password generation algorithm to the vehicle. This algorithm is used to generate a temporary password on the vehicle. Before the user controls the vehicle, the cloud synchronizes this algorithm with the vehicle. The implementation steps are as follows: Step 1: The user's terminal sends a request to the cloud and sets the temporary password generation method; Step 2: The cloud synchronizes the algorithm corresponding to the temporary password generation method to the vehicle terminal. That is, both the vehicle terminal and the cloud can generate temporary passwords using the preset algorithm. When the user's terminal establishes a connection with the vehicle terminal and the vehicle terminal is offline, the vehicle terminal generates a temporary password for comparison with the temporary password of the user's terminal.
[0022] like Figure 3 As shown, Figure 3 This diagram illustrates the process of connecting and controlling the vehicle when it is offline. Figure 3The upper half of the process involves sharing the Bluetooth digital key, while the lower half involves connecting to the vehicle. During Bluetooth digital key sharing, the vehicle, the sharer's (owner's) mobile app, the recipient's (non-owner's mobile app, a third party's app), and the cloud must all be connected to the network. The steps for sharing the Bluetooth digital key are as follows: Step 1: The sharing terminal (i.e., the car owner's mobile APP) sends a request to the cloud to share the Bluetooth digital key with the sharing terminal (not the car owner's mobile APP, i.e., the third party's mobile APP). Step 2: After receiving the request, the cloud responds and sends a notification to the client's terminal. Step 3: The user's terminal sends a request to the cloud to apply for a Bluetooth digital key. After receiving the request, the cloud responds by digitally signing the Bluetooth digital key data and then sending it to the user's terminal. At this point, the user's terminal obtains the corresponding Bluetooth digital key. This part of the operation is performed by the user before connecting to the vehicle.
[0023] When the vehicle is connected to the internet, the cloud will also send the Bluetooth digital key to the corresponding key whitelist on the vehicle.
[0024] The problem that this invention aims to solve is that when a vehicle is parked in an underground garage or a place with poor network connectivity, the vehicle is in a state of no network connection, which makes it impossible to complete vehicle verification and control. Therefore, this method also has the following operations. Step 1 involves the user's terminal (i.e., the car owner's mobile app) sending a request to the cloud. This request is used by the cloud to generate a temporary password based on a pre-set algorithm. Step 2: After receiving the request, the cloud responds and generates a temporary password, which is then sent to the sharing user's terminal. The recipient's terminal obtains the temporary password from the sharing user (it should be noted that there are multiple ways to obtain the temporary password, such as online networks, social software, SMS, etc.).
[0025] When the user's terminal establishes a Bluetooth connection with the vehicle to control the vehicle, the vehicle verifies the Bluetooth digital key on the user's terminal. The verification process is as follows: The user's terminal sends a verification request to the vehicle using the acquired Bluetooth digital key and temporary password. The vehicle verifies the Bluetooth digital key on the user's terminal. During verification, the vehicle holds the cloud public key, which is issued by the cloud. Therefore, verification is achieved using the cloud public key held by the vehicle, allowing it to verify the cloud-based Bluetooth digital key. Additionally, the vehicle generates a password using its own pre-set algorithm, which is compared with the temporary password on the user's terminal. If both the Bluetooth digital key verification and the temporary password comparison pass, a connection is established between the vehicle and the user's terminal, allowing the user to control the vehicle.
[0026] During implementation, the algorithm for generating temporary passwords is pre-configured in the cloud, and the operation of synchronizing the algorithm with the vehicle is completed before the user controls the vehicle (i.e., it is pre-configured when the vehicle has internet access, meaning the vehicle owner sets it in advance); that is, as shown below. Figure 2 When the sharing user's terminal selects and sets the temporary password generation method from the cloud, the cloud responds and synchronizes the algorithm corresponding to the temporary password generation method to the vehicle terminal. When the sharing user's terminal establishes a connection with the vehicle terminal and the vehicle terminal is in a network-free state, it is used to compare the temporary password of the sharing user's terminal.
[0027] During implementation, the connection between the shared user's operating terminal and the vehicle terminal is divided into the first connection (initial connection) and subsequent connections within the validity period (such as the second and third connections). When the vehicle terminal initially establishes a connection with the shared user's operating terminal in a non-network state, as mentioned above, the shared user's operating terminal will receive a temporary password sent by the sharing user's operating terminal. The sharing user's operating terminal will set the validity period of the temporary password. The temporary password can only be used within the validity period. If the shared user reconnects to control the vehicle after the validity period has expired, it needs to obtain a new temporary password from the sharing user's operating terminal again.
[0028] Generally speaking, asymmetric encryption can be used to ensure data security and tamper resistance. The non-repudiation inherent in asymmetric encryption also ensures the sender's identity during data transmission. Therefore, if the Bluetooth digital key provided to the recipient by the cloud is digitally signed, the vehicle can verify that the data was sent from the cloud using the corresponding public key, even without a network connection. Thus, when the mobile phone establishes a Bluetooth connection directly with the vehicle and provides the Bluetooth digital key, the vehicle can verify the key signature even if it doesn't have the key's whitelist at that time.
[0029] Meanwhile, if the cloud provides an algorithm that can generate a temporary password based on the current scenario, such as "660912" valid for 5 minutes, and this algorithm is pre-installed on the vehicle's infotainment system, then at the same time and under the same conditions (owner and recipient), the password generated by the cloud and the password generated by the vehicle will be consistent, similar to the temporary passwords commonly used on home locks. By comparing the password provided by the recipient (generated and provided by the owner) with the password generated by the vehicle itself, it can be determined that the Bluetooth digital key was shared with the owner's authorization. At this point, it can be confirmed that the Bluetooth digital key is issued from the cloud and authorized by the vehicle owner. Therefore, the Bluetooth digital key can be trusted to be genuine and reliable, and secure Bluetooth communication can be established.
[0030] like Figure 4 As shown, Figure 4 This diagram illustrates how a car owner can reclaim their Bluetooth digital key (assuming the vehicle has a network connection or a good network connection). Specifically, the sharing user's terminal (the car owner's mobile app) sends a request to the cloud to reclaim the Bluetooth digital key shared with the recipient's terminal. Upon receiving the request, the cloud cancels the Bluetooth digital key on the recipient's terminal and notifies it. Simultaneously, the cloud sends the Bluetooth digital key to the vehicle's key blacklist. Based on this, the recipient can no longer control the vehicle.
[0031] This scenario requires the vehicle to have a network connection or a good network connection. To prevent malicious network disconnection, this patent introduces a reconciliation process, requiring the recipient to retrieve the latest key status from the cloud. If reconciliation is not performed within a certain period, the key will no longer be able to control the vehicle.
[0032] During implementation, the following situation may occur: For Bluetooth digital keys shared for a longer period, such as one month, if the car owner wants to reclaim the key, and both the car and the shared user (on the app) are in a no-network scenario (malicious non-return), then both keys can still be used normally for one month because the car owner needs to blacklist both the app and the car to cancel the key. The solution is to set up Bluetooth digital key reconciliation. Figure 5 This is a diagram illustrating the reconciliation process for this key. During the period when the shared user controls the vehicle (within the password's validity period), the shared user's operating terminal also includes the following reconciliation operations; the specific steps are as follows; Step 1: The user's terminal needs to perform key reconciliation with the cloud at least once within a certain period of time to obtain the latest key status information. The Bluetooth digital key on the user's terminal stores the latest reconciliation time. Step 2: When the shared user's terminal reconnects to the vehicle, the vehicle will automatically recognize the latest reconciliation time of the Bluetooth digital key (i.e., the most recent reconciliation time). If the shared user's terminal fails to reconcile the key with the cloud within the corresponding time, it will not be able to obtain the latest key status information. When the shared user's terminal reconnects to the vehicle via Bluetooth, it will fail the vehicle's signature verification. This is essentially a "Bluetooth digital key reconciliation" between the shared user (APP) and the cloud. The mobile app's Bluetooth digital key uses a digital signature and stores the latest reconciliation time. For example, the car owner can set up reconciliation once within 6 hours before controlling the car. If the shared user fails to reconcile with the cloud more than 6 hours before controlling the car, it is considered an abnormal situation, and the shared user will not be able to control the car until reconciliation is completed through the mobile app.
[0033] In implementation, the temporary password generation includes the unique identifier of the sharer, the unique identifier of the recipient, and the current time. The following is an example of temporary password generation: Taking the remainder of 1000000 (6-digit default value, which can be specified by the vehicle owner) yields a 6-digit password. To obtain a 6-digit password, set a 6-digit seed number for the remainder. For cases where the remainder result is not 6 digits, such as "1%1000000=1", the result is 999999 by taking the inverse code. The maximum length can be 32 digits (the length of the user's unique identifier). For example, 11…11 (vehicle owner's unique identifier, 32 digits) + 22…22 (recipient's unique identifier, 32 digits) + 1676805147 (timestamp) yields the temporary key "138480" (in the scenario where the default is a 6-digit password).
[0034] like Figure 6 As shown, a vehicle Bluetooth digital key sharing system includes a vehicle terminal 100, a sharing terminal 200, a sharing terminal 300, and a cloud terminal 400. The sharing terminal 200 is used to interact with the cloud terminal 400, to send requests to the cloud terminal 400 for key sharing and retrieval, and to select and set the temporary password generation method to the cloud terminal 400; the sharing terminal 200 is also used to send a temporary password to the sharing terminal 300; the sharing recipient can also synchronously obtain their own key after being authorized.
[0035] The user-operated terminal 300 is used to interact with the cloud 400, complete the application for the Bluetooth digital key and store it locally, and establish a secure Bluetooth channel with the vehicle terminal 100 through the mobile phone Bluetooth module to control the vehicle; the user-operated terminal 300 is also used to communicate with the cloud 400 at regular intervals to complete information reconciliation.
[0036] The cloud 400 is used to generate and deregister Bluetooth digital keys and distribute them to the user's operating terminal 300 and the vehicle terminal 100, generate and distribute whitelists, and deregister blacklists; as well as distribute temporary key generation algorithms to the vehicle terminal 100.
[0037] The vehicle terminal 100 includes a TBOX 101 and a Bluetooth communication device 102; the TBOX 101 is responsible for communicating with the cloud 400 to complete the issuance of the Bluetooth digital key and the transmission of cloud information. Bluetooth communication device 102 is used to establish Bluetooth connection and communication with the sharing user's operating terminal 300 in the absence of network, and is used to complete the verification of signature and comparison of temporary password.
[0038] This system enables Bluetooth digital key sharing: The sharing terminal 200 communicates with the cloud terminal 400 to send a request to the shared terminal 300 to share the Bluetooth digital key. Upon receiving the request, the cloud terminal 400 responds and sends a notification to the shared terminal 300. The shared terminal then communicates with the cloud terminal 400 to request the Bluetooth digital key. Upon receiving this request, the cloud terminal 400 responds, digitally signs the Bluetooth digital key data, and sends the signed data to the shared terminal 300. At this point, the shared terminal obtains the key. The cloud terminal 400 then adds the Bluetooth digital key to the vehicle's key whitelist.
[0039] When the vehicle is parked in an underground garage or in a place with poor network, the vehicle terminal is offline. At this time, when the user wants to control the vehicle, the system establishes a connection with the vehicle terminal 100 as follows: the user's operating terminal 200 sends a request to the cloud terminal 400. This request is used by the cloud terminal 400 to generate a temporary password according to a preset algorithm. After receiving the request, the cloud terminal 400 responds and generates a temporary password and sends it to the user's operating terminal 200. The user's operating terminal 300 obtains the temporary password from the user's operating terminal 200.
[0040] When the user's operating terminal 300 establishes a Bluetooth connection with the vehicle terminal 100 (which has no network) to control the vehicle, the vehicle terminal 100 needs to perform the following verification operation: The user's operating terminal 300 sends a verification request to the vehicle terminal 100 using the acquired Bluetooth digital key and temporary password; the vehicle terminal 100 verifies the Bluetooth digital key of the user's operating terminal 300, and at the same time, the vehicle terminal 100 generates a password using its own preset algorithm, which is compared with the temporary password of the user's operating terminal 300; if both the verification of the Bluetooth digital key and the comparison of the temporary password pass, the vehicle terminal 100 establishes a connection with the user's operating terminal 300, allowing the user to control the vehicle.
[0041] During implementation, the algorithm for generating temporary passwords is pre-stored in the cloud (400), and the operation of synchronizing the algorithm to the vehicle terminal (100) is completed before the user's operating terminal (300) controls the vehicle. When the user's operating terminal (200) selects and sets the temporary password generation method in the cloud, the cloud (400) responds and synchronizes the algorithm corresponding to the temporary password generation method to the vehicle terminal (100). When the user's operating terminal (300) establishes a connection with the vehicle terminal (100) and the vehicle terminal is in a network-free state, the algorithm is used to compare the temporary password with the temporary password of the user's operating terminal.
[0042] This system also has the function of reclaiming Bluetooth digital keys. During implementation, the sharing terminal 200 first sends a request to the cloud terminal 400 to reclaim the Bluetooth digital key shared with the sharing terminal 300. After receiving the request, the cloud terminal 400 cancels the Bluetooth digital key of the sharing terminal 300 and notifies the sharing terminal 300. At the same time, the cloud terminal 400 sends the Bluetooth digital key to the vehicle terminal 100 key blacklist. Based on this, the sharing terminal can no longer control the vehicle.
[0043] During implementation, the following situation may occur: For Bluetooth digital keys with a long sharing period, such as one month, if the car owner wants to retrieve the key, and both the car and the person being shared with (on the APP) are in a no-network scenario (maliciously not returning the key), then the keys on both ends can be used normally within one month, because the car owner needs to send a blacklist to both the APP and the car to cancel the key. To address this issue, this system also introduces the following Bluetooth digital key reconciliation mechanism between the user's operating terminal 300 and the cloud terminal 400. Specifically, during the user's vehicle control period, the user's operating terminal includes the following reconciliation operation: The user's operating terminal 300 needs to perform at least one key reconciliation with the cloud terminal 400 within a certain timeframe to obtain the latest key status information. The user's operating terminal 300's Bluetooth digital key stores the latest reconciliation time. When the user's operating terminal 300 connects to the vehicle terminal 100 again (not the first time), the vehicle terminal 100 automatically recognizes the latest reconciliation time of the Bluetooth digital key. If the user's operating terminal 300 fails to perform key reconciliation with the cloud terminal 400 within the corresponding timeframe, it will not be able to obtain the latest key status information. Therefore, when the user's operating terminal 300 reconnects to the vehicle terminal 100 via Bluetooth, it will fail the vehicle terminal 100's signature verification operation.
[0044] Therefore, firstly, communication between the vehicle-side device 100 and the cloud-side device 400 is encrypted using SSL. This means the vehicle-side device 100 stores the public key of the cloud-side device 400, while the cloud-side device 400 holds both the public and private keys for communication. The Bluetooth digital key data itself carries cloud-based signature information, and during connection establishment, the mobile device transmits the signature data to the vehicle-side device for verification, proving that the Bluetooth digital key was generated by the cloud. Secondly, the temporary password generation rules are defined by the cloud-side device 400. The cloud-side device 400 provides several algorithms for the car owner to choose from and configure, and then synchronizes the algorithms to the vehicle-side device. In the event of no network connection, the recipient needs to provide a temporary password for pairing.
[0045] When the Bluetooth digital key establishes a connection, the vehicle's terminal receives the unique identifier of the user being shared with, the Bluetooth digital key application time, and the vehicle owner's existing unique identifier. A temporary password is generated using a pre-set algorithm and compared with the parameters transmitted by the user. If the comparison is successful, a trusted connection is established. In the absence of a network connection, the Bluetooth digital key can only be used within its validity period, set by the vehicle owner (e.g., 5 minutes). If the user wants to control the vehicle again after the validity period expires, they can obtain a new temporary password from the vehicle owner.
[0046] When the car is driven to a location with network coverage, the cloud will push the Bluetooth digital key to the car. At this time, the person whose car is being shared can use the Bluetooth digital key to control the car without transmitting a temporary password.
[0047] This invention provides a method and system for controlling a vehicle by sharing a Bluetooth digital key. After sharing the key, the vehicle can verify the identity of the shared user by checking the Bluetooth digital key and comparing a temporary password in a network-free state, thus achieving secure vehicle control. This invention enables vehicle control by sharing the key even when the vehicle is offline, providing convenience for car owners. It also proposes a key reconciliation method, allowing the vehicle to retrieve the key in a network-free environment, enhancing security for the car owner. Specifically, this is manifested in... First, this method employs asymmetric encryption for communication between the vehicle and the cloud during implementation, ensuring data security and tamper resistance. Furthermore, asymmetric encryption provides non-repudiation, guaranteeing the sender's identity during data transmission. Since the Bluetooth digital key provided by the cloud to the recipient is digitally signed, the data can be verified as originating from the cloud even without a network connection in the vehicle. When the recipient's device establishes a Bluetooth connection with the vehicle, the Bluetooth digital key is provided to the vehicle. Even if the vehicle does not have this key's whitelist at this time, the key signature can still be verified.
[0048] Secondly, a temporary password generation algorithm is pre-installed in the cloud, capable of generating relevant temporary passwords based on the current scenario. This algorithm is pre-installed on the vehicle, ensuring that the temporary passwords generated in the cloud and on the vehicle are consistent. The vehicle compares the temporary password provided by the recipient (generated and provided by the vehicle owner) with its own generated password to determine if the key has been shared with the owner's authorization. By confirming both the key's issuance from the cloud and the owner's authorization, the Bluetooth digital key can be trusted as authentic and reliable, thus establishing secure Bluetooth communication.
[0049] Third, based on the key-based reconciliation method, namely the "Bluetooth digital key reconciliation" between the shared user (APP) and the cloud, the mobile app's Bluetooth digital key uses a digital signature and stores the latest reconciliation time. For example, the car owner can set up reconciliation once within 6 hours before controlling the car. If the shared user does not reconcile with the cloud more than 6 hours before controlling the car, it is considered an abnormal situation, and the shared user will not be able to control the car until the reconciliation is completed through the mobile app.
[0050] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for controlling a vehicle by sharing a Bluetooth digital key, characterized in that, include: The sharing terminal sends a request to the cloud to share the Bluetooth digital key with the sharing terminal. After receiving the request, the cloud sends a notification to the sharing terminal. The user's terminal requests a Bluetooth digital key from the cloud, and the cloud sends the Bluetooth digital key to the user's terminal after digitally signing it. The sharing terminal sends a request to the cloud to generate a temporary password according to a preset algorithm. After receiving the request, the cloud responds and generates a temporary password and sends it to the sharing terminal. The cloud also communicates with the vehicle terminal with network access to synchronize the algorithm corresponding to the temporary password generation method to the vehicle terminal. The generated temporary password includes the sharing terminal's unique identifier, the recipient's unique identifier, and the current time. The user's terminal obtains a temporary password from the sharer, and the sharer's terminal sets the validity period of the temporary password. When the user's terminal establishes a Bluetooth connection with the vehicle's terminal (which is offline) to control the vehicle, the vehicle's terminal performs Bluetooth digital key verification and temporary password comparison. This process is as follows: First, the user's terminal sends a verification request to the vehicle's terminal using the acquired Bluetooth digital key and temporary password. During verification, the vehicle's terminal holds a cloud public key, which is used to verify the Bluetooth digital key. Simultaneously, the vehicle's terminal generates a temporary password using its own pre-set algorithm, which is then compared with the temporary password of the user's terminal. If both the Bluetooth digital key verification and the temporary password comparison pass, the vehicle's terminal establishes a connection with the user's terminal, allowing the user to control the vehicle. During the validity period of the temporary password, the user's terminal also performs the following reconciliation operation: the user's terminal periodically reconciles with the cloud to obtain the latest Bluetooth digital key status information and stores the latest reconciliation time. When the user's terminal reconnects to the vehicle, the vehicle identifies the latest reconciliation time of the user's terminal. If the time difference between the identified current time and the latest reconciliation time recorded on the vehicle exceeds a preset corresponding time, it is considered that the user's terminal has not reconciled with the cloud within the preset corresponding time, and the connection of the user's current operation cannot pass the vehicle's signature verification. The preset corresponding time is a time period on the order of hours.
2. The method according to claim 1, characterized in that, When the vehicle-side device initially establishes a connection with the user's control terminal in a non-networked state, the sharing device provides a temporary password to the user. The sharing device sets the validity period of the temporary password. The temporary password can only be used within the validity period. If the user reconnects to control the vehicle after the validity period expires, a new temporary password needs to be obtained from the sharing device's control terminal.
3. The method according to claim 1, characterized in that, It also includes the following Bluetooth digital key recycling operation: the sharing terminal sends a request to the cloud to recycle the Bluetooth digital key shared with the sharing terminal; after receiving the request, the cloud cancels the Bluetooth digital key on the sharing terminal and notifies the sharing terminal. When the vehicle is connected to the internet, the cloud communicates with the vehicle and sends the cancelled Bluetooth digital key to the vehicle's key blacklist from the cloud.
4. A vehicle Bluetooth digital key sharing system, characterized in that; The system includes a sharing terminal, a sharing recipient terminal, a cloud platform, and a vehicle terminal. The sharing terminal is used to interact with the cloud, send requests to the cloud for sharing and recycling of Bluetooth digital keys, and set the temporary password generation method in the cloud. The sharing terminal is also used to send a temporary password to the sharing terminal and set the validity period of the temporary password. The generation of the temporary password includes the sharing terminal's unique identifier, the sharing terminal's unique identifier, and the current time. The user's operating terminal is used to interact with the cloud, complete the application for the Bluetooth digital key and store it locally, and establish a secure Bluetooth channel with the vehicle via the mobile phone's Bluetooth module to control the vehicle. After being authorized, the user can also synchronously obtain their own Bluetooth digital key. The user's operating terminal is also used to perform the following reconciliation operations within the validity period of the temporary password: the user's operating terminal periodically reconciles with the cloud to obtain the latest Bluetooth digital key status information from the cloud and stores the latest reconciliation time. When the user's operating terminal connects to the vehicle again, the vehicle identifies the latest reconciliation time of the user's operating terminal. If the time difference between the identified current time and the latest reconciliation time recorded on the vehicle exceeds a preset corresponding time, it is considered that the user's operating terminal has not reconciled with the cloud within the preset corresponding time, and the connection of the user's current operation cannot pass the vehicle's signature verification. The preset corresponding time is a time period on the order of hours. Cloud-based: Used to generate and cancel Bluetooth digital keys and distribute them to the operator and vehicle terminals; and to distribute the algorithm corresponding to the temporary key generation method to the vehicle terminal; Vehicle-side: The vehicle-side includes a TBOX and a Bluetooth communication device; the TBOX is responsible for communicating with the cloud, completing the issuance of the Bluetooth digital key and the transmission of cloud information; Bluetooth communication devices are used to establish Bluetooth connections with the user's operating device in the absence of a network, and to complete signature verification and temporary password comparison.
5. The system according to claim 4, characterized in that, The communication between the vehicle and the cloud is encrypted with SSL. The vehicle stores the public key of the cloud, and the cloud holds the public and private keys for communication. The Bluetooth digital key data itself carries cloud signature information, and when the connection is established, the mobile terminal transmits the signature data to the vehicle terminal for verification, which is used to prove that the Bluetooth digital key was generated by the cloud.
Citation Information
Patent Citations
Unlocking method and device, password authorization method and device, and door lock system
CN110930551A
Reliable failure method and system of offline digital key
CN113781682A
Backend system
CN115766021A