Vehicle digital key management method and system, storage medium, and main controller

CN117437713BActive Publication Date: 2026-09-29BEIJING AUTOMOBILE RES GENERAL INST
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311530218.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-16
Publication Date
2026-09-29
Estimated Expiration
2043-11-16

AI Technical Summary

Technical Problem

但是当车主在使用NFC数字钥匙时,如果NFC数字钥匙丢失,车主的财产就存在安全风险,因此NFC数字钥匙的无卡注销必不可少

Benefits of technology

[0013]根据本发明实施例的车辆数字钥匙的管理系统,通过上述的数字钥匙主控制器,能够防止被第三方应用篡改或者网络攻击,提高信息安全性,保证车主的财产安全。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117437713B_ABST
    Figure CN117437713B_ABST
Patent Text Reader

Abstract

The application discloses a kind of vehicle digital key management method and system, storage medium, main controller, method includes: in response to the management instruction of digital key, generate first encryption instruction, and first encryption instruction is sent to digital key management platform, to make digital key management platform confirm the credibility of the main controller of digital key of vehicle;In response to second encryption instruction, confirm the credibility of digital key management platform, wherein, second encryption instruction is generated by digital key management platform after confirming digital key main controller credible;After confirming digital key management platform credible, send check pass information to digital key management platform, to make digital key management platform transmit management data;Receive management data, and execute management instruction based on management data. Thus, the method can prevent third-party applications from tampering or network attacks, improve information security, and ensure the property safety of the vehicle owner.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle technology, and in particular to a method and system for managing vehicle digital keys, a storage medium, and a main controller. Background Technology

[0002] In recent years, with the application of Near Field Communication (NFC) technology in the automotive industry, more and more cars are equipped with NFC cards, and NFC digital keys are gradually becoming the next trend in car keys. Currently, NFC digital keys come in the form of NFC cards and NFC mobile phone keys. NFC cards are pre-installed by the manufacturer when the vehicle leaves the factory, pairing the NFC card with the vehicle to enable functions such as locking / unlocking and starting the car. However, if the NFC digital key is lost, the owner's property is at risk; therefore, cardless cancellation of the NFC digital key is essential.

[0003] While the technology can functionally achieve NFC digital cancellation, the brief information interaction between the TBOX (Telematics Box) and the digital key master controller makes it vulnerable to simulation or tampering, creating significant weaknesses in information and property security. In the event of a network attack or hijacking by a third-party application, the car's NFC card information could be easily altered, deleted, frozen, or unfrozen, posing a substantial information security risk. Summary of the Invention

[0004] This invention aims to at least partially solve one of the technical problems in related technologies. Therefore, the first objective of this invention is to provide a method for managing vehicle digital keys that can prevent tampering by third-party applications or network attacks, thereby improving information security and ensuring the safety of vehicle owners' assets.

[0005] A second objective of this invention is to provide a computer-readable storage medium.

[0006] The third objective of this invention is to provide a digital key master controller.

[0007] The fourth objective of this invention is to provide a management system for vehicle digital keys.

[0008] To achieve the above objectives, a first aspect of the present invention provides a method for managing a vehicle digital key, the method comprising: generating a first encryption instruction in response to a digital key management instruction, and sending the first encryption instruction to a digital key management platform, so that the digital key management platform confirms the trustworthiness of the vehicle's digital key master controller; confirming the trustworthiness of the digital key management platform in response to a second encryption instruction, wherein the second encryption instruction is generated by the digital key management platform after confirming the trustworthiness of the digital key master controller; sending verification pass information to the digital key management platform after confirming the trustworthiness of the digital key management platform, so that the digital key management platform transmits management data; receiving the management data, and executing the management instruction based on the management data.

[0009] According to the vehicle digital key management method of the present invention, after confirming the trustworthiness of the vehicle's digital key master controller and digital key management platform, a verification pass information is sent to the digital key management platform so that the digital key management platform can transmit management data, thus establishing a secure and reliable information security channel. This can prevent tampering by third-party applications or network attacks, improve information security, and ensure the safety of the vehicle owner's property.

[0010] To achieve the above objectives, a second aspect of the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the vehicle digital key management method.

[0011] To achieve the above objectives, a third aspect of the present invention provides a digital key master controller, including a memory, a processor, and a computer program stored in the memory. When the computer program is executed by the processor, it implements the vehicle digital key management method.

[0012] To achieve the above objectives, a fourth aspect of the present invention provides a vehicle digital key management system, the system comprising: a mobile terminal; a digital key management platform, configured to receive vehicle identity information and a digital key management request sent by the mobile terminal, encrypt the identity information and the management request, and generate a management instruction for the digital key; and a vehicle, including a TBOX and the digital key main controller, wherein the TBOX is configured to receive the management instruction sent by the digital key management platform and send the management instruction to the digital key main controller.

[0013] According to the vehicle digital key management system of the present invention, the digital key master controller described above can prevent tampering by third-party applications or network attacks, improve information security, and ensure the safety of the vehicle owner's property.

[0014] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0015] Figure 1 This is a flowchart illustrating a method for managing vehicle digital keys according to an embodiment of the present invention;

[0016] Figure 2 This is a schematic diagram of the structure of a digital key master controller according to an embodiment of the present invention;

[0017] Figure 3 This is a schematic diagram of the structure of a vehicle digital key management system according to an embodiment of the present invention. Detailed Implementation

[0018] Embodiments of the present invention are described in detail below, examples of which are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain the present invention, and should not be construed as limiting the present invention.

[0019] The following is a reference appendix. Figure 1-3 This invention describes a vehicle digital key management method and system, storage medium, and main controller according to embodiments of the present invention.

[0020] Figure 1 This is a flowchart illustrating a vehicle digital key management method according to an embodiment of the present invention. Figure 1 As shown, the management method for vehicle digital keys includes the following steps:

[0021] S101. In response to the management command of the digital key, generate a first encryption command and send the first encryption command to the digital key management platform so that the digital key management platform can confirm the trustworthiness of the vehicle's digital key master controller.

[0022] Specifically, taking the management command of the digital key as an encrypted random number as an example, the digital key management platform sends the encrypted random number (i.e., the management command) to the digital key main controller. After decrypting the management command, the digital key main controller encrypts the random number using an algorithm to generate a first encrypted command, and sends the first encrypted command to the digital key management platform. After receiving the first encrypted command, the digital key management platform decrypts and verifies the first encrypted command to confirm the trustworthiness of the digital key main controller.

[0023] As an example, when interacting with the digital key management platform via the vehicle's TBOX, the vehicle digital key management method may further include, before receiving management instructions: receiving a security authentication instruction sent by the TBOX, wherein the security authentication instruction is generated and sent by the TBOX after receiving the management instructions; performing information security authentication with the TBOX in response to the security authentication instruction; and, after successful authentication, sending authentication success information back to the TBOX so that the TBOX can transmit management instructions to the digital key master controller.

[0024] Specifically, after receiving a management command, the TBOX generates a security authentication command and sends it to the digital key master controller. Upon receiving the security authentication command, the digital key master controller performs information security authentication with the TBOX. After successful authentication, it sends authentication success information back to the TBOX, enabling the TBOX to transmit management commands to the digital key master controller. The TBOX has a pre-configured information security algorithm. Each management command is approximately 1 kbyte in size. The TBOX primarily transmits the commands transparently, converting them into CAN bus diagnostic messages for the digital key master controller. On the CAN (Controller Area Network) bus, flow control frames ensure the success rate and reliability of data transmission. Therefore, by responding to the security authentication command sent by the TBOX, performing information security authentication with the TBOX, and sending authentication success information back to the TBOX, the TBOX transmits management commands to the digital key master controller, improving the stability and reliability of data transmission.

[0025] The management instructions are sent from the mobile terminal to the TBOX via the digital key management platform and are encrypted by the digital key management platform.

[0026] For example, when a user discovers their digital key is lost and needs to cancel it, they can click the cancellation command on their mobile device. The mobile device sends the vehicle's VIN (Vehicle Identification Number) and the cancellation command to the digital key management platform. The digital key management platform generates an encrypted management command based on the vehicle's VIN and the cancellation command, and sends the management command to the vehicle's TBOX. The digital key master controller receives the management command sent by the TBOX, thus enabling the digital key master controller to interact with the digital key management platform through the TBOX.

[0027] As an example, before receiving the security authentication command sent by the TBOX, the vehicle digital key management method may further include: receiving a diagnostic extension command sent by the TBOX, wherein the diagnostic extension command is generated and sent by the TBOX according to the management command; and responding to the diagnostic extension command by replying to the TBOX with positive response information, so that the TBOX generates and sends a security authentication command according to the positive response information.

[0028] Specifically, the TBOX generates diagnostic extension instructions based on management commands and sends them to the digital key master controller. The digital key master controller receives the diagnostic extension instructions from the TBOX, enters an extension session, and then responds to the diagnostic extension instructions by sending a positive response message back to the TBOX, enabling the TBOX to generate and send security authentication instructions based on the positive response message.

[0029] S102. In response to the second encryption instruction, the trustworthiness of the digital key management platform is confirmed, wherein the second encryption instruction is generated by the digital key management platform after confirming the trustworthiness of the digital key master controller.

[0030] Specifically, after confirming the trustworthiness of the digital key master controller, the digital key management platform encrypts the data returned by the digital key master controller (i.e., the first encryption command) a second time to generate a second encryption command. Upon receiving the second encryption command, the digital key master controller decrypts and verifies it to confirm the trustworthiness of the digital key management platform.

[0031] S103. After confirming the trustworthiness of the digital key management platform, send a verification pass message to the digital key management platform so that the digital key management platform can transmit management data.

[0032] Specifically, after confirming the trustworthiness of the digital key management platform, the digital key master controller sends a verification pass message to the digital key management platform, so that the digital key management platform can transmit management data to the digital key master controller.

[0033] S104. Receive management data and execute management instructions based on the management data.

[0034] As a first example, management instructions may include a digital key cancellation instruction, and management data may include an encrypted blacklist or whitelist. Executing management instructions based on the management data may include: decrypting the encrypted blacklist or whitelist; and adding the digital key to the blacklist in the decrypted blacklist or whitelist via the vehicle's digital key controller to cancel the digital key.

[0035] Specifically, when management commands include a digital key cancellation command, after verifying the trustworthiness of the vehicle's digital key master controller and the digital key management platform, the digital key management platform transmits management data (i.e., the encrypted blacklist and whitelist) to the digital key master controller. The digital key master controller decrypts the encrypted blacklist and whitelist and, through the vehicle's digital key controller, adds the digital key to the blacklist in the decrypted blacklist and whitelist, thus canceling the digital key. The encryption and decryption calculations within the digital key controller are performed by the security chip within the controller. It should be noted that the digital key master controller can also communicate with the NFC controller, which is used for digital key execution. This enables the updating of the blacklist and whitelist within the security chip of the digital key controller, thereby realizing the function of remotely canceling the vehicle's digital key, improving the convenience of cancelling the vehicle's digital key for users and enhancing the security of their property.

[0036] As a second example, management instructions may include upgrade instructions for the digital key master controller, and management data may include an encrypted upgrade package. Executing management instructions based on management data may include: decrypting the encrypted upgrade package; and upgrading the digital key master controller according to the decrypted upgrade package.

[0037] Specifically, when the management command includes an upgrade command for the digital key master controller, after verifying the trustworthiness of the vehicle's digital key master controller and the digital key management platform, the digital key management platform transmits management data (i.e., the encrypted upgrade package) to the digital key master controller. The digital key master controller decrypts the encrypted upgrade package and upgrades itself (e.g., the Bluetooth function and Bluetooth protocol within the digital key master controller) according to the decrypted upgrade package. It should be noted that the digital key master controller is used for the management and maintenance of digital key information. This provides a pathway and guarantee for subsequent remote function and protocol upgrades of the digital key, resulting in significant economic benefits.

[0038] As an example, the management method for vehicle digital keys may also include: after the management command is executed, the execution result of the management command is fed back to the mobile terminal through the digital key management platform.

[0039] Specifically, after executing management commands (digital key cancellation commands or digital key master controller upgrade commands), the digital key master controller sends the execution result back to the mobile terminal through the digital key management platform. The mobile terminal then notifies the user that the cancellation or upgrade was successful.

[0040] In summary, the vehicle digital key management method establishes a secure and reliable information security channel by sending verification information to the digital key management platform after confirming the trustworthiness of the vehicle's digital key master controller and digital key management platform. This allows the digital key management platform to transmit management data, preventing tampering by third-party applications or network attacks, improving information security, and ensuring the safety of the vehicle owner's property. Furthermore, this secure channel provides a pathway and guarantee for subsequent remote function upgrades and protocol upgrades of the digital key, resulting in significant economic benefits. By responding to the security authentication command sent by the TBOX and performing information security authentication with the TBOX, and then sending authentication success information back to the TBOX, the method enables the TBOX to transmit management commands to the digital key master controller, thereby improving the stability and reliability of data transmission.

[0041] The present invention also provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the above-described vehicle digital key management method is implemented.

[0042] According to embodiments of the present invention, when a computer program corresponding to a vehicle digital key management method stored thereon is executed by a processor, it can prevent tampering by third-party applications or network attacks, thereby improving information security and ensuring the safety of the vehicle owner's property.

[0043] Figure 2 This is a schematic diagram of the structure of a digital key master controller according to an embodiment of the present invention. Figure 2 As shown, the digital key master controller 200 includes: a memory 210, a processor 220, and a computer program 230 stored on the memory 210. When the computer program 230 is executed by the processor 220, it implements the above-described vehicle digital key management method.

[0044] The digital key master controller of this invention, when the computer program corresponding to the vehicle's reminder method stored in its memory is executed by the processor, can prevent it from being tampered with by third-party applications or attacked by networks, thereby improving information security and ensuring the safety of the vehicle owner's property.

[0045] Figure 3 This is a schematic diagram of the structure of a vehicle digital key management system according to an embodiment of the present invention. Figure 3As shown, the vehicle digital key management system 300 includes: a mobile terminal 310; a digital key management platform 320, used to receive vehicle identity information and digital key management requests sent by the mobile terminal 310, encrypt the identity information and management requests, and generate digital key management instructions; and a vehicle 330, including a TBOX 331 and the aforementioned digital key main controller 200, wherein the TBOX 331 receives management instructions sent by the digital key management platform 320 and sends the management instructions to the digital key main controller 200. The mobile terminal 310 provides a human-machine interface.

[0046] It should be noted that for other specific implementations of the vehicle digital key management system of the present invention, please refer to the specific implementations of the vehicle digital key management method of the above embodiments.

[0047] Therefore, the vehicle digital key management system, through the aforementioned digital key master controller, can prevent tampering by third-party applications or network attacks, thereby improving information security and ensuring the safety of the vehicle owner's property.

[0048] It should be noted that the logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include: an electrical connection having one or more wires (electronic device), a portable computer disk drive (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Alternatively, the computer-readable medium may be paper or other suitable media on which the program can be printed, since the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in a computer memory.

[0049] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0050] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0051] In the description of this invention, it should be understood that the terms "center," "longitudinal," "lateral," "length," "width," "thickness," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," "outer," "clockwise," "counterclockwise," "axial," "radial," and "circumferential" indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are used only for the convenience of describing this invention and simplifying the description, and are not intended to indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this invention.

[0052] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0053] In this invention, unless otherwise explicitly specified and limited, the terms "installation," "connection," "linking," and "fixing," etc., should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components, unless otherwise explicitly limited. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0054] In this invention, unless otherwise explicitly specified and limited, "above" or "below" the second feature can mean that the first feature is in direct contact with the second feature, or that the first feature is in indirect contact with the second feature through an intermediate medium. Furthermore, "above," "over," and "on top" of the second feature can mean that the first feature is directly above or diagonally above the second feature, or simply that the first feature is at a higher horizontal level than the second feature. "Below," "below," and "under" the second feature can mean that the first feature is directly below or diagonally below the second feature, or simply that the first feature is at a lower horizontal level than the second feature.

[0055] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention.

Claims

1. A method for managing vehicle digital keys, characterized in that, Applied to a digital key master controller, the method includes: The vehicle's TBOX interacts with the digital key management platform to receive security authentication commands sent by the TBOX. These security authentication commands are generated and sent by the TBOX after receiving management commands from the digital key management platform. In response to the security authentication command, perform information security authentication with the TBOX; After successful authentication, the authentication information is sent back to the TBOX, so that the TBOX can transmit the management command to the digital key master controller; In response to the management command of the digital key, a first encrypted command is generated and sent to the digital key management platform so that the digital key management platform can confirm the trustworthiness of the digital key master controller of the vehicle; Receive a second encryption instruction, and in response to the second encryption instruction, confirm the trustworthiness of the digital key management platform, wherein the second encryption instruction is generated by the digital key management platform after confirming the trustworthiness of the digital key master controller; After confirming the trustworthiness of the digital key management platform, a verification pass message is sent to the digital key management platform to enable the digital key management platform to transmit management data; Receive the management data and execute the management instructions based on the management data.

2. The vehicle digital key management method according to claim 1, characterized in that, Before receiving the security authentication command sent by the TBOX, the method further includes: Receive diagnostic extension instructions sent by the TBOX, wherein the diagnostic extension instructions are generated and sent by the TBOX according to the management instructions; In response to the diagnostic extended instruction, a positive response message is sent back to the TBOX, so that the TBOX generates and sends the security authentication instruction based on the positive response message.

3. The vehicle digital key management method according to claim 1, characterized in that, The management command is sent from the mobile terminal to the TBOX through the digital key management platform, and is encrypted by the digital key management platform.

4. The vehicle digital key management method according to claim 1, characterized in that, The management instructions include the cancellation instructions for the digital key, the management data includes encrypted blacklists and whitelists, and the execution of the management instructions based on the management data includes: Decrypt the encrypted blacklist and whitelist; The digital key is added to the blacklist of the decrypted blacklist / whitelist via the vehicle's digital key controller to cancel the digital key.

5. The vehicle digital key management method according to claim 1, characterized in that, The management instructions include upgrade instructions for the digital key master controller, and the management data includes an encrypted upgrade package. Executing the management instructions based on the management data includes: Decrypt the encrypted upgrade package; The digital key master controller is upgraded according to the decrypted upgrade package.

6. The vehicle digital key management method according to claim 1, characterized in that, The method further includes: After the management command is executed, the execution result of the management command is fed back to the mobile terminal through the digital key management platform.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the vehicle digital key management method according to any one of claims 1-6.

8. A digital key master controller, characterized in that, The device includes a memory, a processor, and a computer program stored in the memory, wherein when the computer program is executed by the processor, it implements the vehicle digital key management method according to any one of claims 1-6.

9. A vehicle digital key management system, characterized in that, The system includes: Mobile terminal; The digital key management platform is used to receive vehicle identity information and digital key management requests sent by the mobile terminal, encrypt the identity information and management requests, generate management instructions for the digital key, and transmit management data to the digital key main controller after the digital key main controller confirms that the digital key management platform is trustworthy. The vehicle includes a TBOX and a digital key master controller according to claim 8, wherein the TBOX is used to receive the management instructions sent by the digital key management platform and send the management instructions to the digital key master controller, and the digital key master controller executes the management instructions based on the management data.

Citation Information

Patent Citations

  • Vehicle NFC digital key management system and method

    CN115631556A

  • Key security authentication method and device, vehicle and storage medium

    CN116456337A