Vehicle unlocking and locking systems, methods, and NFC digital key management methods
The NFC digital key system solves the problem of vehicles being unusable when Bluetooth keys are powered off or disconnected, enabling vehicle unlocking and starting in different scenarios, thus improving convenience and security.
Patent Information
- Application Number
- CN202410340512.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-25
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2044-03-25
AI Technical Summary
Traditional Bluetooth keys cannot be used in vehicles when the phone battery is depleted or the connection is lost, reducing convenience.
The NFC digital key system utilizes the collaborative work of mobile devices, vehicle manufacturers' servers, mobile servers, and vehicles to unlock and lock vehicles using NFC functionality when the Bluetooth connection is lost or the mobile device is powered off. This includes the generation, distribution, verification, and secure connection of the NFC digital key.
Even when the Bluetooth connection is lost or the mobile device is powered off, it can still maintain communication with the vehicle, ensuring that users can operate the vehicle smoothly in different scenarios, improving the convenience and security of unlocking and starting the vehicle, and enhancing the flexibility and reliability of the system.
Smart Images

Figure CN118280022B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of automotive key technology, and more specifically, to a vehicle unlocking and locking system, method, and NFC digital key management method. Background Technology
[0002] With the development of technology, the portability shortcomings of traditional mechanical keys, chip keys, and remote keys have become increasingly apparent, while mobile phones are almost always with us. Therefore, with the advancement of vehicle networking technology, mobile phone Bluetooth keys have emerged, providing users with great convenience. However, Bluetooth keys have a significant problem: when the mobile phone is powered off due to depleted battery, the vehicle will be unusable; therefore, there is room for improvement. Summary of the Invention
[0003] The present invention aims to at least solve one of the technical problems existing in the prior art. To this end, the first objective of the present invention is to provide a vehicle locking / unlocking system that enables vehicle locking / unlocking via NFC function when the Bluetooth connection is lost or the mobile device is powered off.
[0004] The second objective of this invention is to provide a method for unlocking and locking a vehicle.
[0005] The third objective of this invention is to propose an NFC digital key management method.
[0006] The first aspect of this invention proposes a vehicle unlocking and locking system, the system comprising: an NFC digital key, the NFC digital key comprising: a mobile device terminal, a vehicle manufacturer server, a mobile terminal server, and a vehicle terminal, wherein the mobile device terminal includes: a mobile device NFC terminal, used to establish a connection with the vehicle terminal NFC terminal when the mobile device terminal is powered off or the Bluetooth connection is lost; the vehicle manufacturer server, used to manage the generation, distribution, and verification of the digital key; the mobile terminal server, used to realize data transmission and remote access between the mobile device terminal and the vehicle manufacturer server; and the vehicle terminal NFC terminal, used to receive authentication requests and information sent by the mobile device terminal and perform verification. If the verification is successful, unlocking or starting the vehicle is allowed. In the unlocked or started state of the vehicle, the mobile device terminal NFC terminal and the vehicle terminal NFC terminal establish a point-to-point wireless connection, the mobile device terminal establishes a communication connection with the vehicle manufacturer server through the mobile terminal server, the vehicle manufacturer server communicates with the vehicle terminal through a secure connection, the vehicle manufacturer server sends authentication instructions and verification results, and the vehicle terminal, after receiving the authentication instructions and verification results, decides whether to allow unlocking or starting the vehicle based on the authentication instructions and verification results.
[0007] According to one embodiment of the present invention, the mobile device further includes: a Native APP, a Business APP, and a Security Element (SE); the Native APP is used to send an authentication request to the vehicle manufacturer's server and receive the authentication result; the Business APP is used to send an API key request to the vehicle manufacturer's server and receive the verification result; the Security Element (SE) is used to store and verify the key; the vehicle includes: a TSP1 platform; the vehicle manufacturer's server includes: a TSP platform; the TSP1 platform and the TSP platform establish a connection for vehicle information integration, remote communication, security verification, and data analysis; the mobile server includes: an STM service module, used to realize data transmission and remote access between the mobile device and the vehicle manufacturer's server; when the mobile device establishes a connection with the vehicle via Bluetooth, the Native APP sends an authentication request to the vehicle manufacturer's server through the STM service module, and the vehicle manufacturer's server establishes a secure connection after verification by the TSP platform; if the mobile device disconnects via Bluetooth, it can establish a connection with the vehicle via NFC.
[0008] According to one embodiment of the present invention, the vehicle manufacturer server further includes: a DK management module for managing the generation, distribution and verification of digital keys.
[0009] In some embodiments, the system further includes a security verification module, used to perform security verification on the connection after the mobile device and the vehicle establish an NFC connection, to ensure that only authorized mobile devices can establish a connection with the vehicle.
[0010] In some embodiments, after the mobile device establishes a connection with the vehicle's NFC via the mobile device's NFC, the vehicle verifies the identity and permissions of the mobile device. If the verification is successful, the mobile device is allowed to lock or unlock the vehicle.
[0011] A second aspect of the present invention provides a method for unlocking and locking a vehicle, the method comprising the following steps:
[0012] a. The mobile device establishes a connection with the vehicle via Bluetooth and sends an authentication request to the vehicle manufacturer's server;
[0013] b. After the car manufacturer's server verifies the authentication request, it verifies it through the TSP platform. If the verification is successful, a secure connection is established.
[0014] c. If the mobile device establishes a connection with the vehicle's NFC via the mobile device's NFC after the Bluetooth connection is lost;
[0015] d. The mobile device sends authentication requests and information to the vehicle via its NFC terminal;
[0016] e. After receiving the authentication request and information, the vehicle verifies it. If the verification is successful, the vehicle can be unlocked or started.
[0017] f. The vehicle sends the verification result to the vehicle manufacturer's server for recording.
[0018] According to an embodiment of the present invention, in step c, after the mobile device establishes a connection with the vehicle's NFC module via the NFC module, the Native APP sends an authentication request to the STM service module. The STM service module verifies the validity of the user credential. If the verification is successful, it sends an authentication success response to the Native APP, thereby allowing the mobile device to perform unlocking and locking operations on the vehicle.
[0019] According to an embodiment of the present invention, in step e, the vehicle verifies the identity and permissions of the mobile device. If the verification is successful, the mobile device is allowed to perform unlocking and locking operations on the vehicle, and the unlocking and locking operation records are uploaded to the vehicle manufacturer's server for storage.
[0020] A third aspect of this invention provides an NFC digital key management method, which includes the following steps:
[0021] A1. The car manufacturer's server generates a digital key and authorizes the mobile server with the distribution rights of the digital key;
[0022] B2. After receiving the distribution permission for the digital key, the mobile server distributes the digital key to the Native APP on the mobile device.
[0023] C3. The native app on the mobile device stores the digital key in the security element SE;
[0024] D4. When the NFC on the mobile device establishes a connection with the NFC on the vehicle, the Native APP reads the digital key from the security element SE and sends the digital key to the vehicle via the NFC on the mobile device;
[0025] E5. After receiving the digital key, the vehicle terminal verifies it. If the verification is successful, the mobile device is allowed to lock and unlock the vehicle.
[0026] According to an embodiment of the present invention, in step A1, the vehicle manufacturer's server also generates a key and a signature corresponding to the digital key, and uploads the key and signature to the mobile terminal server;
[0027] In step D4, the Native APP on the mobile device reads the digital key from the security element SE, and also reads the key and signature, and sends the key and signature to the vehicle via the NFC on the mobile device.
[0028] In step E5, the vehicle verifies the validity of the key and signature while verifying the digital key.
[0029] The vehicle unlocking and locking system according to embodiments of the present invention integrates multiple components, including a mobile device, a vehicle manufacturer server, a mobile server, and a vehicle, to achieve efficient, secure, and flexible vehicle unlocking and starting functions. Utilizing NFC technology, the system maintains communication with the vehicle even when Bluetooth connectivity is lost or the mobile device is powered off, ensuring smooth vehicle operation for users in various scenarios. Furthermore, the system's functionality is enhanced by introducing components such as a Native App, a Business App, a TSP platform, a TSP1 platform, and an STM service module. The DK management module and digital key management method on the vehicle manufacturer server ensure the secure generation, distribution, and verification of digital keys, effectively reducing security risks. The security verification module further enhances system security, ensuring that only authorized users can perform vehicle unlocking and locking operations. Finally, by recording and uploading the unlocking and locking operation results, the system provides valuable vehicle usage data to the vehicle manufacturer, aiding in security verification and data analysis. In summary, this vehicle unlocking and locking system, along with its related methods and digital key management method, not only improves the convenience of vehicle unlocking and starting but also significantly enhances the system's security and reliability.
[0030] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description
[0031] The above and / or additional aspects and advantages of the present invention will become apparent and readily understood from the following description of the embodiments with reference to the accompanying drawings, in which:
[0032] Figure 1 This is a flowchart of a vehicle unlocking and locking system according to an embodiment of the present invention;
[0033] Figure 2 This is a flowchart of a vehicle unlocking / locking method according to an embodiment of the present invention;
[0034] Figure 3 This is a flowchart of an NFC digital key management method according to an embodiment of the present invention;
[0035] Figure 4 This is a schematic diagram illustrating the binding principle between the NFC card and the vehicle's NFC terminal.
[0036] Figure 5 This is a flowchart of the NFC card authentication process. Detailed Implementation
[0037] Embodiments of the present invention are described in detail below. Examples of these embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention.
[0038] The following is combined with Figures 1-5 This describes a vehicle unlocking and locking system according to an embodiment of the present invention.
[0039] like Figure 1 As shown, the first aspect of this disclosure proposes a vehicle unlocking and locking system, which includes: an NFC digital key, the NFC digital key including: a mobile device terminal, a vehicle manufacturer server, a mobile terminal server, and a vehicle terminal, wherein the mobile device terminal includes: a mobile device terminal NFC, used to establish a connection with the vehicle terminal NFC when the mobile device terminal is powered off or the Bluetooth connection is lost; the vehicle manufacturer server, used to manage the generation, distribution, and verification of the digital key; the mobile terminal server, used to realize data transmission and remote access between the mobile device terminal and the vehicle manufacturer server; and the vehicle terminal NFC, used to receive authentication requests and information sent by the mobile device terminal and perform verification. If the verification is successful, the vehicle can be unlocked or started.
[0040] When the vehicle is unlocked or started, the NFC on the mobile device establishes a point-to-point wireless connection with the NFC on the vehicle. The mobile device establishes a communication connection with the vehicle manufacturer's server through the mobile terminal server. The vehicle manufacturer's server communicates with the vehicle through a secure connection. The vehicle manufacturer's server sends authentication instructions and verification results. After receiving the authentication instructions and verification results, the vehicle decides whether to allow unlocking or starting the vehicle based on the authentication instructions and verification results.
[0041] The vehicle unlocking and locking system involves the collaborative work of mobile devices, the vehicle manufacturer's server, the mobile server, and the vehicle itself, using an NFC digital key to unlock and start the vehicle.
[0042] Specifically, both the mobile device and the vehicle are equipped with NFC functionality, allowing connections to be established even when Bluetooth is disconnected or the mobile device is powered off. The vehicle manufacturer's server manages the digital key, while the mobile server handles data transmission and remote access. When the authentication request is successful, the vehicle can be unlocked or started. This design provides vehicle unlocking and starting capabilities in various situations, enhancing the system's flexibility and reliability.
[0043] According to one embodiment of the present invention, the mobile device further includes: a Native App and a Business App. The Native App is used to send authentication requests to the vehicle manufacturer's server and receive authentication results. The Business App is used to send API key requests to the vehicle manufacturer's server and receive verification results. The vehicle side includes: a TSP1 platform. The vehicle manufacturer's server includes: a TSP platform. The TSP1 platform establishes a connection with the TSP platform for vehicle information integration, remote communication, security verification, and data analysis. The mobile server includes: an STM service module, used to realize data transmission and remote access between the mobile device and the vehicle manufacturer's server.
[0044] Once the mobile device establishes a connection with the vehicle via Bluetooth, the Native App sends an authentication request to the vehicle manufacturer's server through the STM service module. The vehicle manufacturer's server then establishes a secure connection after verification through the TSP platform.
[0045] If the mobile device loses its Bluetooth connection, it can establish a connection with the vehicle's NFC via the mobile device's NFC.
[0046] The native app communicates with the vehicle manufacturer's server, sending authentication requests and receiving results. The business app sends API key requests. The TSP1 and TSP platforms together implement vehicle information integration, remote communication, security verification, and data analysis. The STM service module handles data transmission and remote access between the mobile device and the vehicle manufacturer's server. This design enhances the system's functionality and security.
[0047] According to one embodiment of the present invention, the vehicle manufacturer server further includes: a DK management module for managing the generation, distribution and verification of digital keys.
[0048] A DK management module has been introduced on the automaker's server, specifically for managing the generation, distribution, and verification of digital keys.
[0049] With a dedicated DK management module, automakers' servers can manage digital keys more efficiently and securely. This helps reduce potential security risks and improves overall system performance.
[0050] In some embodiments, the system further includes a security verification module, used to perform security verification on the connection after the mobile device and the vehicle establish an NFC connection, to ensure that only authorized mobile devices can establish a connection with the vehicle.
[0051] The security verification module ensures that only authorized mobile devices can connect to the vehicle, thereby enhancing system security and preventing unauthorized access and potential malicious behavior.
[0052] In some embodiments, after the mobile device establishes a connection with the vehicle's NFC via the mobile device's NFC, the vehicle will verify the identity and permissions of the mobile device. If the verification is successful, the mobile device is allowed to lock or unlock the vehicle.
[0053] Once the mobile device establishes a connection with the vehicle via NFC, the vehicle will verify the identity and permissions of the mobile device.
[0054] Specifically, by verifying the identity and permissions of the mobile device, the vehicle can ensure that only authorized users can lock and unlock the vehicle. This enhances the system's security and reliability.
[0055] like Figure 2 As shown, a second aspect of the present invention provides a vehicle unlocking / locking method, which includes the following steps:
[0056] a. The mobile device establishes a connection with the vehicle via Bluetooth and sends an authentication request to the vehicle manufacturer's server;
[0057] b. After the car manufacturer's server verifies the authentication request, it verifies it through the TSP platform. If the verification is successful, a secure connection is established.
[0058] c. If the mobile device establishes a connection with the vehicle's NFC via the mobile device's NFC after the Bluetooth connection is lost;
[0059] d. The mobile device sends authentication requests and information to the vehicle via its NFC terminal;
[0060] e. After receiving the authentication request and information, the vehicle verifies it. If the verification is successful, the vehicle can be unlocked or started.
[0061] f. The vehicle sends the verification result to the vehicle manufacturer's server for recording.
[0062] A vehicle unlocking and starting method is provided, which enables the vehicle to be unlocked and started through the collaborative work of mobile devices, vehicle manufacturers' servers, and the vehicle itself.
[0063] Specifically, the mobile device first establishes a connection with the vehicle via Bluetooth and sends an authentication request to the vehicle manufacturer's server. If authentication is successful, a secure connection is established. If the Bluetooth connection is lost, the mobile device can establish a connection with the vehicle via NFC and send an authentication request. After the vehicle verifies the request, if successful, it allows the vehicle to be unlocked or started. This method provides multiple unlocking and starting methods, enhancing the system's flexibility and convenience.
[0064] In some embodiments, in step c, after the mobile device establishes a connection with the vehicle's NFC module via the NFC module, the Native APP sends an authentication request to the STM service module. The STM service module verifies the validity of the user credentials. If the verification is successful, it sends an authentication success response to the Native APP, thereby allowing the mobile device to perform unlocking and locking operations on the vehicle.
[0065] After the mobile device establishes a connection with the vehicle via NFC, how does the Native App send an authentication request to the STM service module and receive a successful authentication response?
[0066] Specifically, through the interaction between the native app and the STM service module, the mobile device can verify the validity of user credentials. If the verification is successful, it allows the vehicle to be locked or unlocked, enhancing the system's security and convenience.
[0067] In some embodiments, in step e, the vehicle verifies the identity and permissions of the mobile device. If the verification is successful, the mobile device is allowed to perform unlocking and locking operations on the vehicle, and the unlocking and locking operation records are uploaded to the vehicle manufacturer's server for storage.
[0068] After verifying the identity and permissions of the mobile device, the vehicle-mounted system allows the vehicle to be unlocked or started if successful, and records the operation results and uploads them to the automaker's server.
[0069] Specifically, by recording and uploading the results of locking and unlocking operations, the automaker's server can monitor vehicle usage in real time, providing data for security verification and analysis. This enhances the system's security and reliability.
[0070] like Figure 3 As shown, a third aspect of the present invention proposes an NFC digital key management method, which includes the following steps:
[0071] A1. The car manufacturer's server generates a digital key and authorizes the mobile server with the distribution rights of the digital key;
[0072] B2. After receiving the distribution permission for the digital key, the mobile server distributes the digital key to the Native APP on the mobile device.
[0073] C3. The native app on the mobile device stores the digital key in the security element SE;
[0074] D4. When the NFC on the mobile device establishes a connection with the NFC on the vehicle, the Native APP reads the digital key from the security element SE and sends the digital key to the vehicle via the NFC on the mobile device;
[0075] E5. After receiving the digital key, the vehicle terminal verifies it. If the verification is successful, the mobile device is allowed to lock and unlock the vehicle.
[0076] An NFC digital key management method includes steps such as digital key generation, distribution, storage, reading, and verification.
[0077] Specifically, the automaker's server generates a digital key and distributes it to the native app on the mobile device. The native app stores the digital key in a security element (SE) and reads and sends the digital key when establishing an NFC connection with the vehicle. After the vehicle receives and verifies the digital key, it allows the vehicle to be locked or unlocked if successful. This method provides a secure process for the generation, distribution, and use of digital keys, enhancing the system's security and reliability.
[0078] In some embodiments, in step A1, the vehicle manufacturer's server also generates a key and signature corresponding to the digital key, and uploads the key and signature to the mobile terminal server.
[0079] In step D4, the Native APP on the mobile device reads the digital key from the security element SE, and also reads the key and signature, and sends the key and signature to the vehicle via the NFC on the mobile device.
[0080] In step E5, the vehicle verifies the validity of the key and signature while verifying the digital key.
[0081] The verification process for a digital key includes verifying the validity of the key and signature corresponding to the digital key.
[0082] In addition to verifying the validity of the digital key itself, it also verifies the validity of the corresponding key and signature. This enhances the security of the digital key and prevents potential forgery or tampering.
[0083] This vehicle unlocking and locking system, along with its related methods and digital key management approach, integrates multiple components including mobile devices, vehicle manufacturer servers, mobile servers, and vehicle terminals to achieve efficient, secure, and flexible vehicle unlocking and starting functions. Utilizing NFC technology, the system maintains communication with the vehicle even when Bluetooth connectivity is lost or the mobile device is powered off, ensuring smooth vehicle operation in various scenarios. Furthermore, the introduction of components such as a Native App, a Business App, a TSP platform, a TSP1 platform, and an STM service module enhances the system's functionality. The DK management module and digital key management method on the vehicle manufacturer server ensure the secure generation, distribution, and verification of digital keys, effectively reducing security risks. The security verification module further enhances system security, ensuring that only authorized users can unlock and lock the vehicle. Finally, by recording and uploading the unlocking and locking operation results, the system provides vehicle manufacturers with valuable vehicle usage data, aiding in security verification and data analysis. In conclusion, this vehicle unlocking and locking system, along with its related methods and digital key management approach, not only improves the convenience of vehicle unlocking and starting but also significantly enhances the system's security and reliability.
[0084] like Figure 1-5 The diagram illustrates a general embodiment of the vehicle locking / unlocking system according to an embodiment of the present invention.
[0085] A vehicle unlocking and locking system, specifically, requires four parts to coordinate and cooperate to realize the NFC digital key function of a smart car: the vehicle end, the mobile phone (including the mobile app and the security element SE), the car manufacturer's server (TSP platform and DKS), and the mobile server, so as to realize the car's keyless entry function (locking and locking), keyless start and digital key sharing function.
[0086] The vehicle locking / unlocking system comprises: a vehicle-side terminal, a mobile device terminal, a vehicle manufacturer's server, and a mobile terminal server. The mobile device terminal includes: a Native App, a Business App, UWB2, BLE2, and mobile device NFC. The mobile terminal server includes: an STM service module. The vehicle manufacturer's server includes: a DK management module and a TSP platform. The vehicle-side terminal includes: a TSP1 platform, UWB1, BLE1, vehicle-side NFC, a DK1 management module, and a BCM module. The mobile terminal server is installed on the mobile device and is used for data transmission and remote access.
[0087] like Figure 1 As shown:
[0088] Certification of mobile servers and automotive enterprise servers:
[0089] The mobile server sends an authentication request to the vehicle manufacturer's server, along with the device identifier;
[0090] After receiving the device identifier, the car manufacturer's server verifies its validity. If the verification is successful, the result is sent to the mobile server, completing two-way authentication. This ensures the authenticity and reliability of the identities of both communicating parties.
[0091] First, the automaker's server is responsible for the entire lifecycle of generating, storing, distributing, and managing digital keys. When a user requests to generate a digital key via a mobile phone or other mobile device, the automaker's server verifies the user's identity and permissions, and then generates an encrypted key paired with the vehicle. This key is securely stored on the automaker's server and can only be accessed and used by authorized users. The automaker's server is also responsible for tracking and recording the usage of digital keys, including usage time, device ID, and vehicle ID, for subsequent auditing and troubleshooting. Furthermore, if a user's device is lost or stolen, the automaker's server can remotely revoke the digital key authorization for that device, ensuring vehicle security.
[0092] Secondly, the mobile server is responsible for receiving, storing, and transmitting requests and responses for the digital key. When a user interacts with the automaker's server using a mobile phone or other mobile device to generate or use a digital key, the mobile server acts as an intermediary, processing and forwarding these requests and responses. The user's request is first sent to the mobile server, and then forwarded to the automaker's server for processing. Similarly, the automaker's server's response is first sent to the mobile server, and then forwarded to the user. In this way, the mobile server acts as a bridge, connecting the communication between the user and the automaker's server.
[0093] Regarding digital key authentication, the vehicle manufacturer's server and the mobile server collaborate to ensure the authenticity and legitimacy of the digital key. When a user attempts to unlock the vehicle using the digital key, the vehicle sends a verification request to the vehicle manufacturer's server. The vehicle manufacturer's server verifies the validity and legitimacy of the digital key in the request, including verifying information such as the digital key's signature and timestamp. Simultaneously, the vehicle manufacturer's server also interacts with the mobile server to verify the user's identity and the device's legitimacy. Only when all verifications pass will the vehicle allow the user to unlock and start the vehicle.
[0094] In summary, the vehicle manufacturer's server and the mobile server collaborate in digital key management and authentication to ensure the security, reliability, and validity of the digital key. Through their respective functions and responsibilities, they achieve full lifecycle management of the digital key, secure communication and verification mechanisms, and a convenient user experience. These functions and mechanisms together constitute the core of the digital key in the connected vehicle system, providing users with a more convenient, intelligent, and secure travel experience.
[0095] Authentication between mobile devices and mobile servers:
[0096] The native app sends an authentication request to the STM service module, along with user credentials (such as a token);
[0097] After receiving the user credentials, the TSM service module verifies their validity. If the verification is successful, it sends an authentication success response to the Native App. This ensures the legitimacy of the user's avatar in the Native App and protects user data security.
[0098] Authentication between mobile devices and car manufacturer servers:
[0099] The business app sends a request, including an API key, to the car manufacturer's server;
[0100] After receiving the API key request, the car manufacturer's server verifies the API key. If the verification is successful, it sends a verification success response to the business app. This ensures the legitimate access of the business app and prevents unauthorized data access.
[0101] TSP1 and TSP platform certification:
[0102] TSP1 sends a request containing authentication information to the TSP platform;
[0103] After receiving a request containing authentication information, the TSP platform verifies the correctness of the authentication information. If the verification is successful, a secure connection is established. This ensures secure communication between TSP1 and the TSP platform and prevents data leakage.
[0104] UWB2, BLE2, NFC on mobile devices and vehicle authentication:
[0105] The mobile device sends authentication requests and information to the vehicle via UWB2, BLE2, and mobile device NFC.
[0106] After receiving and verifying the authentication request and information, the vehicle's terminal allows unlocking or starting the vehicle if the verification is successful. This enables keyless entry and start, improving user convenience. It should be noted that... Figure 1 As shown, the vehicle-side includes UWB1, BLE1, and vehicle-side NFC, and the mobile device-side includes WB2, BLE2, and NFC, connected point-to-point.
[0107] NFC and Security Element (SE) authentication on mobile devices:
[0108] Authentication method: Based on NFC communication and the security features of the security element SE.
[0109] The mobile device sends an authentication request and key to the security element (SE) via NFC.
[0110] The security element (SE) verifies the validity of the key. If the verification is successful, access to the stored digital key information is allowed; thus, the security of the NFC digital key is ensured and unauthorized access is prevented.
[0111] UWB2, BLE2 and Car Key System Service Layer Certification:
[0112] Authentication method: Based on the UWB and BLE communication protocols and the authentication mechanism of the car key system service layer.
[0113] UWB2 and BLE2 send authentication requests and related information to the car key system service layer.
[0114] The car key system service layer verifies the legality of the request information and its compatibility with the mobile device. If the verification is successful, the vehicle can be unlocked or started, thereby enhancing the security of keyless entry and start functions.
[0115] Certification of the service layer and security element (SE) of the car key system:
[0116] Authentication method: Based on the communication protocol and security mechanism between the car key system service layer and the security element SE.
[0117] The car key system service layer sends an authentication request and key to the security element (SE);
[0118] The security element (SE) verifies the validity of the key. If the verification is successful, access to or operation of the digital key is permitted. This ensures the security of NFC digital key operations and prevents unauthorized access.
[0119] UWB2 and UWB1 certifications:
[0120] UWB2 sends a request signal containing digital key information to UWB1.
[0121] Upon receiving the request, UWB1 verifies the validity of the digital key information.
[0122] If the verification is successful, UWB1 sends a confirmation signal to UWB2, allowing the digital key to be used. This ensures the security and accuracy of the digital key in short-range wireless communication, enabling a fast and reliable connection between the vehicle and the mobile device.
[0123] BLE1 and BLE2 certifications:
[0124] BLE2 sends digital key information to BLE1.
[0125] After receiving the digital key information, BLE1 verifies the legality and completeness of the digital key information.
[0126] Once verification is successful, BLE1 and BLE2 establish a communication connection, allowing the digital key to be used.
[0127] NFC authentication on both the vehicle and mobile devices:
[0128] The mobile device's NFC writes the digital key information into the NFC tag.
[0129] The vehicle's NFC reader reads the digital key information from the NFC tag.
[0130] The vehicle's NFC verifies the authenticity of the digital key information.
[0131] If verification is successful, NFC1 and NFC2 establish a communication connection to complete the digital key authentication. Therefore, even when Bluetooth is disconnected, the vehicle can be locked and unlocked via NFC1 and NFC2. This utilizes NFC technology to achieve fast and convenient digital key transmission.
[0132] NFC Digital Key Management:
[0133] Management between mobile server and car manufacturer server:
[0134] Management method: Centralized management, with digital key information stored in a database.
[0135] Specific steps:
[0136] Users register on the car manufacturer's server and generate a digital key.
[0137] Digital key information is stored in the automaker's server database and synchronized to the user's mobile device via a mobile server. This enables centralized management and synchronized updates of the digital key.
[0138] DK1 management module on the vehicle side:
[0139] Management method: Modular management, including: authentication control module, key management module and key storage module.
[0140] Specific steps:
[0141] The authentication control module is responsible for verifying the legitimacy of the digital key.
[0142] The key management module is responsible for generating, storing, updating, and deleting digital key keys.
[0143] The key storage module securely stores the digital key, ensuring that the key is not accessed by unauthorized personnel. This modular management approach improves the security and efficiency of digital key management.
[0144] The vehicle-side BCM module (i.e., body control module) interacts with the vehicle key system service layer to perform tasks such as unlocking, locking, and starting.
[0145] The vehicle unlocking and locking system according to embodiments of the present invention improves security in several ways. Firstly, it ensures the authenticity and reliability of the identity of the communicating party through mechanisms such as two-way authentication, API key verification, and pre-shared keys, preventing man-in-the-middle attacks and data leaks. Secondly, it enhances convenience by enabling keyless entry and start, allowing users to easily operate the vehicle without carrying a physical key. Thirdly, it improves efficiency by enabling rapid generation, updating, and deletion of digital keys through centralized management and modular design, thus improving management efficiency. Fourthly, it offers compatibility and scalability by supporting various wireless communication technologies, such as UWB, BLE, and NFC, demonstrating good compatibility and scalability.
[0146] The digital key master module is located in the vehicle body (with a built-in safety element SE chip), and communicates with the BCM via private / public CAN protocols.
[0147] Communication between in-vehicle and external NFC reader nodes. The diagnostic tool can connect to the CAN bus and communicate with the digital key master module to initiate learning pairing commands, stop commands, and resume commands. The NRC reader has a low-power card detection function, which can detect card arrival in sleep mode, wake up its own MCU and digital key master module, interact with the card via NFC, confirm the card's legitimacy, complete authentication, and wake up other nodes on the bus. After authentication, the digital key module needs to work with the BCM to complete vehicle unlocking, locking, and starting functions.
[0148] The main functions of DK management on the server side are:
[0149] (1) Information synchronization, specifically including card information, watch information, vehicle NFC, module information, whitelist, binding of NFC module with vehicle information and vehicle owner information, etc.
[0150] (2) Transmission key management.
[0151] (3) Personalized data management.
[0152] (4) User permission management.
[0153] TSP Function:
[0154] (1) Information synchronization: synchronize the binding relationship between VIN and security element SE ID to DKM.
[0155] (2) NFC module management, including binding, unbinding, pairing, NFC replacement records and operation records.
[0156] (3) NFC firmware upgrade.
[0157] (4) Mobile log management, permission settings and log download.
[0158] Before using the NFC card's unlocking function, card authentication with the vehicle is required. The pairing and binding process between the NFC card and the vehicle is completed by the card distribution computer on the production line. The production inspector logs into the TSP system and places a blank NFC card in the vehicle's card reader. The vehicle then uploads the NFC card information to the digital key management platform via the TSP platform, completing the binding relationship between the NFC card and the vehicle's NFC module. The specific process is as follows: Figure 4 As shown,
[0159] Open the mobile device and log in to the TSP system. Enter the required authentication information for verification. If the verification is successful, the verification result will be sent to the mobile device.
[0160] Place the NFC card from the mobile device at the card reader in the vehicle to read the card;
[0161] Upload the card reading information to the mobile device;
[0162] After receiving the card reading information, the mobile device uploads it to the TSP platform.
[0163] After receiving the card reading information, the TSP platform uploads it to the TSPI platform for verification.
[0164] If the verification is successful, the TSP1 platform sends a verification success response to the TSP platform to complete the binding of the NFC card with the vehicle.
[0165] The TSP platform will synchronize this binding information to the digital key management platform;
[0166] After receiving the successful binding information, the digital key management platform generates a key and a signature, and uploads the generated key and signature data to the mobile device.
[0167] After receiving the key and signature data, the mobile device decrypts them and obtains the key, then uploads the obtained key to the card reader. The card reader receives the obtained key and writes the key data to the NFC card. After receiving the key data, the NFC card sends the key data to the security element SE for authentication. If the authentication is successful, the card is successfully configured and the car lights flash.
[0168] In addition to production line card pairing, card pairing can also be completed online through TSP and diagnostic instruments. Similarly, during the after-sales phase at 4S stores, card pairing can be triggered via the 4S store's cloud platform, through diagnostic instruments, and through self-service card pairing on a large screen for user assistance.
[0169] Once the NFC card is paired with the vehicle, the NFC function can be used. The authentication process is briefly described as follows:
[0170] 1) The NFC card sends an access request to the NFC card's main reader;
[0171] 2) After receiving the entry request, the NFC card reader sends the entry request to the digital key main module;
[0172] In other words, the NFC card reader features low-power card finding, card entry from sleep mode, and wake-up of the NFC main card reader + digital key main module.
[0173] 3) After receiving the entry request, the digital key master module sends an APDU command to the NFC card. After receiving the APDU command, the NFC card sends the APDU command to the NFC card's main card reader.
[0174] 4) After receiving the APDU command, the NFC card's main reader responds to the APDU command and sends the APDU command response to the NFC card;
[0175] 5) After receiving the APDU command response, the NFC card sends the APDU command response to the digital key main module;
[0176] 6) After receiving the APDU command response, the digital key master module determines whether the APDU command response is valid;
[0177] 7) If the APDU command response is valid, then send the time acquisition information to the CAN bus;
[0178] In other words, the NFC master card reader interacts with the NFC card through APDU commands, transmits commands, and the digital key master module confirms the validity of the key.
[0179] 8) After receiving the time information, the CAN bus sends the time information to the digital key master module;
[0180] 9) After receiving the time information, the digital key main module determines whether the time information is valid;
[0181] In other words, the digital key master module confirms the validity of the card key, wakes up the vehicle system via the CAN bus, obtains the time, and confirms the validity of the time.
[0182] 10) If the time information is valid, send the authentication information to the BCM module;
[0183] Therefore, after the digital key master module confirms that the time is valid, it reports the relevant information of the current authentication through a specified message.
[0184] 11) After receiving the authentication information, the BCM module determines whether to lock or unlock and blocks the alarm signal for three minutes;
[0185] In other words, after receiving the message, the BCM determines whether locking or unlocking is necessary and then blocks the alarm signal for 3 minutes.
[0186] 12) Three minutes later, the vehicle owner sends a no-card warning response to the digital key main module;
[0187] In other words, three minutes after the car owner gets in the car, when the owner triggers the key-finding scenario, the BCM sends an alarm signal via CAN.
[0188] 13) After receiving the no-card warning response, the digital key master module sends the user card swipe message to the CAN bus;
[0189] Specifically, the digital key master module receives a subsequent message, prompting the driver / vehicle owner to swipe their card on the large screen / instrument panel.
[0190] 14) After the CAN bus receives the user's card swipe message, the digital key master module sends a card search response to the NFC card slave reader;
[0191] In other words, the CAN bus notifies the NFCR master card reader to start the card search from the module.
[0192] 15) After the NFC card's slave reader receives the card search response, the NFC card sends an entry request to the NFC card's slave reader.
[0193] 16) After receiving the entry request from the card reader, the NFC card sends the entry request to the digital key main module;
[0194] In other words, after the card is inserted into the module, the module resets the card and notifies the NFC reader that the card has been received.
[0195] 17) After receiving the entry request, the digital key master module sends an APDU instruction to the NFC card slave reader.
[0196] In other words, the NFCReader transmits APDU commands through the CAN transparent transmission channel.
[0197] 18) After receiving the APDU instruction from the card reader, the NFC card sends the APDU instruction to the NFC card.
[0198] 19) After receiving the APDU instruction, the NFC card sends an APDU instruction response to the NFC card's reader;
[0199] In other words, the module transmits APUD commands to the digital key master module, interacts with the card through contactless communication, and obtains a response.
[0200] 20) After receiving the APDU command response from the card reader, the NFC card transmits the APDU command response to the digital key main module.
[0201] In other words, the module transmits the response data back to the digital key master module, which then parses the data to determine whether the authentication was successful.
[0202] 21) After receiving the APDU instruction response pass-through, the digital key master module sends a pass-through end instruction to the NFC card slave reader.
[0203] 22) After receiving the pass-through end command from the card reader, the NFC card sends the upload authentication result to the CAN bus.
[0204] In other words, once the pass-through process is complete, the slave module is notified via CAN to release the slave module.
[0205] After the digital key master module confirms the time is valid, it reports the relevant information for the current authentication via a message. The specific process is as follows (e.g., Figure 5 (As shown).
[0206] The vehicle locking / unlocking system according to embodiments of the present invention, as well as other configurations and operations described herein, are known to those skilled in the art and will not be described in detail here.
[0207] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "illustrative embodiment," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0208] Although embodiments of the invention have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the claims and their equivalents.
Claims
1. A vehicle unlocking / locking system, characterized in that, The system includes an NFC digital key, which comprises a mobile device, a vehicle manufacturer's server, a mobile server, and a vehicle terminal. On the mobile device side, including: mobile device NFC, used to establish a connection with vehicle NFC when the mobile device is powered off or the Bluetooth connection is lost; The vehicle manufacturer's server is used to manage the generation, distribution, and verification of digital keys; the mobile server is used to enable data transmission and remote access between mobile devices and the vehicle manufacturer's server. The vehicle-mounted NFC is used to receive authentication requests and information sent from mobile devices and to verify them. If the verification is successful, the vehicle can be unlocked or started. When the vehicle is unlocked or started, the NFC on the mobile device establishes a point-to-point wireless connection with the NFC on the vehicle. The mobile device establishes a communication connection with the vehicle manufacturer's server through the mobile terminal server. The vehicle manufacturer's server communicates with the vehicle through a secure connection. The vehicle manufacturer's server sends authentication instructions and verification results. After receiving the authentication instructions and verification results, the vehicle decides whether to allow unlocking or starting the vehicle based on the authentication instructions and verification results.
2. The vehicle unlocking and locking system according to claim 1, characterized in that, in, Mobile devices also include: Native Apps, Business Apps, and Security Elements (SEs). The native app is used to send authentication requests to the car manufacturer's server and receive authentication results; The business app is used to send API key requests to the car manufacturer's server and receive verification results; The security element (SE) is used to store and verify keys; The vehicle-side includes: the TSP1 platform; Automotive manufacturers' servers include: TSP platform; The TSP1 platform establishes a connection with the TSP platform for vehicle information integration, remote communication, security verification, and data analysis. The mobile server includes an STM service module, used to enable data transmission and remote access between mobile devices and the vehicle manufacturer's server. Once the mobile device establishes a connection with the vehicle via Bluetooth, the Native App sends an authentication request to the vehicle manufacturer's server through the STM service module. The vehicle manufacturer's server then establishes a secure connection after verification through the TSP platform. If the mobile device loses its Bluetooth connection, it can establish a connection with the vehicle's NFC via the mobile device's NFC.
3. The vehicle unlocking and locking system according to claim 1 or 2, characterized in that, The automaker's server also includes a DK management module, which manages the generation, distribution, and verification of digital keys.
4. The vehicle unlocking and locking system according to claim 3, characterized in that, The system also includes a security verification module, which performs security verification on the connection after the mobile device and the vehicle establish an NFC connection, ensuring that only authorized mobile devices can establish a connection with the vehicle.
5. The vehicle unlocking and locking system according to claim 4, characterized in that, After the mobile device establishes a connection with the vehicle's NFC via the mobile device's NFC, the vehicle will verify the identity and permissions of the mobile device. If the verification is successful, the mobile device is allowed to lock and unlock the vehicle.
6. A method for unlocking and locking a vehicle, characterized in that, The method includes the following steps: a. The mobile device establishes a connection with the vehicle via Bluetooth and sends an authentication request to the vehicle manufacturer's server; b. After the car manufacturer's server verifies the authentication request, it verifies it through the TSP platform. If the verification is successful, a secure connection is established. c. If the mobile device establishes a connection with the vehicle's NFC via the mobile device's NFC after the Bluetooth connection is lost; d. The mobile device sends authentication requests and information to the vehicle via its NFC terminal; e. After receiving the authentication request and information, the vehicle verifies it. If the verification is successful, the vehicle can be unlocked or started. f. The vehicle sends the verification result to the vehicle manufacturer's server for recording.
7. The vehicle unlocking and locking method according to claim 6, characterized in that, In step c, after the mobile device establishes a connection with the vehicle's NFC module via the NFC module, the Native APP sends an authentication request to the STM service module. The STM service module verifies the validity of the user's credentials. If the verification is successful, it sends an authentication success response to the Native APP, thereby allowing the mobile device to lock and unlock the vehicle.
8. The vehicle unlocking and locking method according to claim 6, characterized in that, In step e, the vehicle verifies the identity and permissions of the mobile device. If the verification is successful, the mobile device is allowed to lock and unlock the vehicle, and the lock and unlock operation record is uploaded to the vehicle manufacturer's server for storage.
9. An NFC digital key management method, characterized in that, The method includes the following steps: A1. The car manufacturer's server generates a digital key and authorizes the mobile server with the distribution rights of the digital key; B2. After receiving the distribution permission for the digital key, the mobile server distributes the digital key to the Native APP on the mobile device. C3. The native app on the mobile device stores the digital key in the security element SE; D4. When the NFC on the mobile device establishes a connection with the NFC on the vehicle, the Native APP reads the digital key from the security element SE and sends the digital key to the vehicle via the NFC on the mobile device; E5. After receiving the digital key, the vehicle terminal verifies it. If the verification is successful, the mobile device is allowed to lock and unlock the vehicle.
10. The NFC digital key management method according to claim 9, characterized in that, In step A1, the car manufacturer's server also generates a key and signature corresponding to the digital key, and uploads the key and signature to the mobile server; In step D4, the Native APP on the mobile device reads the digital key from the security element SE, and also reads the key and signature, and sends the key and signature to the vehicle via the NFC on the mobile device. In step E5, the vehicle verifies the validity of the key and signature while verifying the digital key.
Citation Information
Patent Citations
Automobile central door lock control device and method based on near field communication (NFC) technology
CN109696869A
Bluetooth key vehicle control method and system
CN112233281A