Methods and related equipment for verifying the identity of electronic devices

By leveraging the RSS property and the reciprocity of wireless channels, and employing challenge-response packets and a nonce encryption mechanism, the vulnerability of KES to attacks was solved, achieving efficient authentication and secure ranging estimation.

CN118339851BActive Publication Date: 2026-03-10YINWANG INTELLIGENT TECHNOLOGIES CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-30
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Existing keyless entry systems (KES) are vulnerable to relay attacks and other active attacks, and existing distance estimation methods are not secure enough.

Method used

Authentication is performed using the characteristics of Received Signal Strength (RSS). By sending and receiving challenge and response packets, the reciprocity and multipath effect of the wireless channel are utilized to verify the identity of electronic devices. Information is encrypted using a nonce and a preset key to ensure data integrity and device authentication.

Benefits of technology

It provides an efficient authentication process, prevents relay attacks, replay attacks and active attacks, ensures the accuracy of ranging and proximity estimation, and improves system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118339851B_ABST
    Figure CN118339851B_ABST
Patent Text Reader

Abstract

This application provides a method and related equipment for verifying the identity of an electronic device, comprising: a first electronic device sending N challenge data packets to a second electronic device; the first electronic device receiving N response data packets from the second electronic device, wherein each of the N response data packets corresponds one-to-one with the N challenge data packets; the first electronic device determining first verification information based on the N response data packets, wherein the first verification information indicates the received signal strength (RSS) information of the N response data packets; the first electronic device acquiring second verification information from the second electronic device, wherein the second verification information indicates the RSS information of the N challenge data packets; and verifying the identity of the second electronic device based on the first verification information and the second verification information. The above technical solution utilizes the properties of RSS to provide an efficient identity authentication process. Therefore, this technical solution can ensure the execution of authenticated ranging and proximity estimation, and avoid relay attacks, replay attacks, and active attacks against digital key schemes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of information technology, and more specifically, to a method and related equipment for verifying the identity of an electronic device. Background Technology

[0002] Keyless entry systems (KES) for vehicles are becoming increasingly popular due to their ease of use. With KES, each user is no longer required to carry a physical car key, as the owner can authorize multiple users to use his / her car. KES uses a digital key stored in the user's personal device (such as a mobile phone), which is provided to the user by a trusted entity during registration. Bluetooth Low Energy (BLE) technology is used for communication between the car and the user's device. Figure 1 An example illustrating this architecture is provided. For example... Figure 1 As shown, the car owner's personal device stores the car's digital key. The car sends commands / messages within its range to locate the key. When the owner's personal device detects these commands / messages, it responds. The car then receives the command from the owner's personal device, interprets it as a command sent by the owner's personal device, and unlocks the car. The owner can then authorize user device 1 to use his / her car. Specifically, the authorized user's device 1 responds to the commands sent by the car. The car receives the command from the authorized user's device 1, interprets it as a command sent by the authorized device, and unlocks the car.

[0003] Current KES (Knowledge, Equipment, and Service) solutions are vulnerable to relay attacks and other proactive attacks, which is a serious problem. Some existing solutions use distance estimation methods to calculate the distance between the mobile device and the vehicle based on signal characteristics. If the device is found to be within range, the vehicle accepts the command. Summary of the Invention

[0004] This application provides a method and related equipment for verifying the identity of an electronic device. This technical solution can utilize the characteristics of RSS to provide an efficient identity authentication process.

[0005] According to a first aspect, embodiments of this application provide a method for verifying the identity of an electronic device, comprising: a first electronic device sending N challenge data packets to a second electronic device, where N is a positive integer greater than or equal to 1; the first electronic device receiving N response data packets from the second electronic device, wherein the N response data packets correspond one-to-one with the N challenge data packets; the first electronic device determining first verification information based on the N response data packets, wherein the first verification information is used to indicate the received signal strength (RSS) information of the N response data packets; the first electronic device acquiring second verification information from the second electronic device, wherein the second verification information is used to indicate the RSS information of the N challenge data packets; and verifying the identity of the second electronic device based on the first verification information and the second verification information.

[0006] The above technical solution utilizes the characteristics of RSS to provide an efficient authentication process. Due to the reciprocity of wireless channels, only interconnected pairs of wireless devices can have similar RSS values. If another device (e.g., an attacker) exists in the same neighborhood and can eavesdrop on all communications using the same channel by a legitimate device, the RSS observed by the attacker (through received data packets / signals) will be irrelevant to that of the legitimate device due to the multipath effect of the wireless channel. Therefore, this technical solution can ensure the execution of authenticated ranging and proximity estimation, and avoid relay attacks, replay attacks, and active attacks against digital key schemes.

[0007] In one possible design, before the first electronic device sends N challenge data packets to the second electronic device, the method further includes: the first electronic device determining a number use once (Nonce); the first electronic device sending the Nonce to the second electronic device; the first electronic device determining the N challenge data packets, each of the N challenge data packets including: first encrypted information encrypted by a preset key, the first encrypted information including the Nonce.

[0008] In one possible design, the first electronic device sends the Nonce to the second electronic device by: the first electronic device encrypting the Nonce using the preset key, and the first electronic device sending the encrypted Nonce to the second electronic device.

[0009] In one possible design, the first encrypted information may also include a data packet index and a first command identifier (ID).

[0010] Nonce is used in the authentication process. Therefore, security is further enhanced.

[0011] In one possible design, each of the N challenge data packets includes first verification information for verifying the data integrity of the first encrypted information of each of the N challenge data packets.

[0012] Based on the first verification information, the data integrity of the first encrypted information in each of the N challenge data packets can be verified.

[0013] In one possible design, the first electronic device determines the first verification information based on the N response data packets, including: the first electronic device determines K RSS information based on the N response data packets, each of the K RSS information corresponding to one of the N response data packets, where K is a positive integer greater than or equal to N; the first electronic device determines the first verification information based on the K RSS information.

[0014] In one possible design, before the first electronic device determines the K RSS messages based on the N response data packets, the method further includes: determining that the N response data packets are trustworthy based on the nonce of each of the N response data packets.

[0015] For example, each of the N response data packets may include second encrypted information and second verification information. The second encrypted information may include the Nonce. The key used to encrypt / decrypt the second encrypted information may be the same as the key used to encrypt / decrypt the first encrypted information. The first electronic device can use the key to decrypt the second information to obtain the decrypted information (i.e., the Nonce). The first electronic device can compare the Nonce in the decrypted information with a previously received Nonce. If the Nonce in the decrypted information is the same as the previously sent Nonce, the first electronic device can use the second verification information to verify the data integrity of the encrypted information. If the encrypted information passes the verification, the first electronic device can determine that the response data packet is a trusted data packet; if the encrypted information fails the verification, the first electronic device can instruct the second electronic device to resend the response data packet. If the Nonce in the decrypted information is different from the previously sent Nonce, the first electronic device can determine that the response data packet is not a trusted data packet.

[0016] In one possible design, the first electronic device determines the first verification information based on the K RSS information, including: the first electronic device applies a filter to the K RSS information to obtain M RSS information, where M is a positive integer less than or equal to K; the first electronic device determines the first verification information based on the M RSS information.

[0017] According to the above technical solution, the filter can be used to remove noise components and smooth the signal.

[0018] In one possible design, the first electronic device determines the first verification information based on the M RSS information, including: the first electronic device determines M RSS level information based on the M RSS information, wherein the M RSS level information corresponds one-to-one with the M RSS information; the first electronic device determines the first verification information based on the M RSS level information.

[0019] In one possible design, verifying the identity of the second electronic device based on the first verification information and the second verification information includes: the first electronic device determining the similarity between the first verification information and the second verification information; if the similarity between the first verification information and the second verification information is greater than a threshold, then sending an authentication success indication to the second electronic device, the authentication success indication being used to indicate that the second electronic device has passed identity authentication.

[0020] According to a second aspect, embodiments of this application provide a method for verifying the identity of an electronic device, comprising: a second electronic device receiving N challenge data packets from a first electronic device, where N is a positive integer greater than or equal to 1; the second electronic device sending N response data packets to the first electronic device, wherein the N response data packets correspond one-to-one with the N challenge data packets; the second electronic device determining second verification information based on the N challenge data packets, wherein the second verification information is used to indicate the received signal strength (RSS) information of the N challenge data packets; and the second electronic device sending the second verification information to the first electronic device.

[0021] The above technical solution utilizes the characteristics of RSS to provide an efficient authentication process. Due to the reciprocity of wireless channels, only interconnected pairs of wireless devices can have similar RSS values. If another device (e.g., an attacker) exists in the same neighborhood and can eavesdrop on all communications using the same channel by a legitimate device, the RSS observed by the attacker (through received data packets / signals) will be irrelevant to that of the legitimate device due to the multipath effect of the wireless channel. Therefore, this technical solution can ensure the execution of authenticated ranging and proximity estimation, and avoid relay attacks, replay attacks, and active attacks against digital key schemes.

[0022] In one possible design, before the second electronic device receives N challenge data packets from the first electronic device, the method further includes: the second electronic device receiving a number use once (Nonce) from the first electronic device; before the second electronic device sends N response data packets to the first electronic device, the method further includes: the second electronic device determining the N response data packets, each of the N response data packets including: second encrypted information encrypted by a preset key, the second encrypted information including the Nonce.

[0023] In one possible design, the second electronic device receiving a number use once (Nonce) from the first electronic device includes: the second electronic device receiving an encrypted Nonce from the first electronic device; and the second electronic device using the preset key to decrypt the encrypted Nonce to obtain the Nonce.

[0024] In one possible design, the second encrypted information may also include a packet index and a second command identifier (ID).

[0025] Nonce is used in the authentication process. Therefore, security is further enhanced.

[0026] In one possible design, each of the N response data packets includes second verification information for verifying the data integrity of the second encrypted information in each of the N response data packets.

[0027] Based on the first verification information, the data integrity of the first encrypted information in each of the N challenge data packets can be verified.

[0028] In one possible design, the second electronic device determines the second verification information based on the N challenge data packets, including: the second electronic device determines K RSS messages based on the N challenge data packets, each of the K RSS messages corresponding to one of the N response data packets, where K is a positive integer greater than or equal to N; the second electronic device determines the second verification information based on the K RSS messages.

[0029] In one possible design, before the second electronic device determines the K RSS messages based on the N challenge data packets, the method further includes: determining that the N challenge data packets are trustworthy based on the nonce of each of the N challenge data packets.

[0030] The second electronic device can receive the Nonce from the first electronic device before receiving the N challenge data packets. In this case, the challenge data packets sent by the first electronic device can carry the Nonce. The second electronic device can determine whether the Nonce carried in the challenge data packet is the same as the previously received Nonce. If they are the same, the second electronic device can determine that the received challenge data packet is trustworthy; if they are different, the first electronic device can determine that the received challenge data packet is untrustworthy.

[0031] In one possible design, the second electronic device determines the second verification information based on the K RSS information, including: the second electronic device applies a filter to the K RSS information to obtain M RSS information, where M is a positive integer less than or equal to K; the second electronic device determines the second verification information based on the M RSS information.

[0032] According to the above technical solution, the filter can be used to remove noise components and smooth the signal.

[0033] In one possible design, the second electronic device determines the second verification information based on the M RSS information, including: the second electronic device determines M RSS level information based on the M RSS information, wherein the M RSS level information corresponds one-to-one with the M RSS information; the second electronic device determines the second verification information based on the M RSS level information.

[0034] According to a third aspect, embodiments of this application provide an electronic device having the function of implementing the method described in the first aspect. The function can be implemented by hardware or by hardware executing corresponding software. The hardware corresponding to the software includes one or more modules corresponding to the function.

[0035] According to a fourth aspect, embodiments of this application provide an electronic device having the function of implementing the method described in the second aspect. The function can be implemented by hardware or by hardware executing corresponding software. The hardware corresponding to the software includes one or more modules corresponding to the function.

[0036] According to a fifth aspect, embodiments of this application provide a computer-readable storage medium including instructions. When the instructions are executed on a computer, the computer causes the computer to perform the method described in the first aspect or any possible implementation thereof.

[0037] According to a sixth aspect, embodiments of this application provide a computer-readable storage medium including instructions. When the instructions are executed on a computer, the computer causes the computer to perform the method described in the second aspect or any possible implementation thereof.

[0038] According to a seventh aspect, an electronic device is provided, including a processor and a memory. The processor is connected to the memory. The memory is used to store instructions, and the processor is used to execute the instructions. When the processor executes the instructions stored in the memory, the processor performs the method of the first aspect or any possible implementation thereof.

[0039] According to an eighth aspect, an electronic device is provided, including a processor and a memory. The processor is connected to the memory. The memory is used to store instructions, and the processor is used to execute the instructions. When the processor executes the instructions stored in the memory, the processor performs the method of the second aspect or any possible implementation thereof.

[0040] According to a ninth aspect, a chip system is provided, the chip system including a memory and a processor, the memory for storing a computer program, and the processor for calling the computer program from the memory and running the computer program, such that a server on which the chip resides performs the method of the first aspect or any possible implementation thereof.

[0041] According to a tenth aspect, a chip system is provided, the chip system including a memory and a processor, the memory for storing a computer program, and the processor for calling the computer program from the memory and running the computer program, such that a server on which the chip resides performs the method of the second aspect or any possible implementation thereof.

[0042] According to an eleventh aspect, a computer program product is provided. When the computer program product is run on an electronic device, it causes the electronic device to perform the method of the first aspect or any possible implementation thereof.

[0043] According to a twelfth aspect, a computer program product is provided. When the computer program product is run on an electronic device, it causes the electronic device to perform the method described in the second aspect or any possible implementation thereof.

[0044] According to the thirteenth aspect, a vehicle is provided, the vehicle including the electronic equipment described in the third aspect. Attached Figure Description

[0045] Figure 1 The keyless entry system is shown.

[0046] Figure 2 This illustrates a relay attack scenario.

[0047] Figure 3 A flowchart illustrating an embodiment of a method for verifying the identity of an electronic device is shown.

[0048] Figure 4 A flowchart illustrating an embodiment of a method for verifying the identity of an electronic device is shown.

[0049] Figure 5 This is a schematic block diagram of an electronic device according to an embodiment of this application.

[0050] Figure 6 This is a schematic block diagram of an electronic device according to an embodiment of this application.

[0051] Figure 7 This is a schematic block diagram of an electronic device according to an embodiment of this application.

[0052] Figure 8 This is a schematic block diagram of an electronic device according to an embodiment of this application. Detailed Implementation

[0053] The technical solutions in this application are described below with reference to the accompanying drawings.

[0054] Figure 2 This illustrates a relay attack scenario.

[0055] An attacker's device impersonates the car and communicates with the genuine key / user device. In other words, the attacker's device sends commands / messages that should be sent by the car to locate the key within its range. When the genuine key / user device detects the commands / messages sent by the attacker's device, it responds to the commands / messages, assuming it is the user's legitimate / own car. The attacker's device then captures / records signals from the genuine key / user device, amplifies them, and sends them to the car. The car receives messages sent by the attacker's device and interprets them as commands sent by the genuine key / user device. In this way, the attacker can easily unlock and steal the car. Similarly, the attacker can also record and reply to messages between the car and the genuine key / user device to unlock and steal the car. These are some of the most serious threats KES faces; therefore, the security of the KES scheme is crucial to preventing such attacks.

[0056] Figure 3 A flowchart illustrating an embodiment of a method for verifying the identity of an electronic device is shown.

[0057] 301, The vehicle sends periodic BLE beacons.

[0058] In some embodiments of this application, the vehicle may include one or more antenna arrays. The antenna arrays may be thin, flexible antennas that can be attached to any plane of the vehicle. Each array may be connected to the same BLE module or different BLE modules of the vehicle. The vehicle can determine which BLE module to use based on the current user's approach direction.

[0059] 302. The user equipment detects the BLE beacon and uses the Bluetooth connection key (hereinafter referred to as "K") B () can be connected to the vehicle via BLE.

[0060] User equipment can be the vehicle's physical key, a mobile phone storing the vehicle's digital key, etc. B Shared between user devices and vehicles by trusted entities (such as cloud services) for establishing Bluetooth connections and encrypted BLE communication.

[0061] 303, The user equipment sends its identification (ID) to the vehicle. U The command ID is used to indicate when authentication will begin.

[0062] ID U Assigned by a trusted party, such as a cloud service. ID U It is unique to each user device, non-transferable, and bound to the user's device.

[0063] Optionally, the user equipment can also send verification information to the vehicle. The verification information is used to verify the data integrity of the information sent by the user equipment (i.e., the user equipment ID and command ID). Based on the verification information, the vehicle can determine whether the information sent by the user equipment has been tampered with. The verification information can be a message authentication code (MAC) or a hash-based message authentication code (HMAC) for the information sent by the user equipment, etc.

[0064] For example, a user equipment can send the following message to a vehicle: (ID) U ||CMD_START_AUTH,MAC(K U ID U ||CMD_START_AUTH)), where ID U This is the user equipment ID, and CMD_START_AUTH is the command ID used to indicate the start of authentication. MAC(k,m) represents the message authentication code using key k and password m. U Shared between a user's devices and vehicles by a trusted entity (such as a cloud server), it is unique, device-bound, and non-transferable. K U It can be used to encrypt commands / data in BLE packets to enhance security.

[0065] To give another example, a user device can send two messages to a vehicle. The first message carries the ID. U And CMD_START_AUTH, the second message is used to carry MAC(K) U ID U ||CMD_START_AUTH).

[0066] Accordingly, the vehicle receives the information sent by the user equipment in step 303. If the vehicle receives verification information from the user equipment, it can use the verification information to verify the ID. U And the data integrity of CMD_START_AUTH. If ID U After data integrity verification via CMD_START_AUTH, the vehicle can perform the following steps.

[0067] 304, The vehicle determines the key based on the user equipment ID.

[0068] In some embodiments of this application, the key determined based on the user equipment ID can be the same as the key used in step 303 to determine the MAC address of the information sent by the user equipment, i.e., Ku. In this case, the vehicle can determine Ku based on the user equipment ID.U Then, it determines whether the received information has passed the data integrity verification.

[0069] In some other embodiments of this application, the key determined based on the user equipment ID may be different from the key used in step 303 to determine the MAC of the information sent by the user equipment.

[0070] 305. The vehicle determines a number for once-used (Nonce) and sends that Nonce to the user equipment.

[0071] Optionally, Nonce is any number generated by the vehicle.

[0072] Optionally, the vehicle may also send a command ID with a nonce to the user equipment, which indicates that the vehicle has successfully received the ID sent by the user equipment. U And CMD_START_AUTH.

[0073] The Nonce and Command ID can be encrypted using the key determined in step 304.

[0074] Similarly, vehicles can also send verification information to user equipment. This verification information is used to verify the data integrity of the information sent by the vehicle (i.e., the Nonce and command ID).

[0075] For example, a vehicle can send the following message to a user device: (E(K) U ,n||CMD_ACK_AUTH),MAC(K U ,n||CMD_ACK_AUTH)), where E(k,m) indicates that message m is encrypted using key k; n is the Nonce; CMD_ACK_AUTH is the command ID used to indicate that the vehicle has successfully received the Nonce and CMD_START_AUTH sent by the user equipment.

[0076] Similarly, a vehicle can also send two messages to a user device, one of which carries encrypted information (i.e., Nonce and CMD_ACK_AUTH) and the other carries verification information.

[0077] Accordingly, the user equipment can receive the information sent by the vehicle in step 306. The user equipment can use the key to decrypt the received message to obtain the Nonce and CMD_START_AUTH. Furthermore, the user equipment can use the received verification information to determine whether the Nonce and CMD_START_AUTH pass the data integrity verification. If the Nonce and CMD_START_AUTH pass the data integrity verification, the user equipment can perform the following steps.

[0078] 306. The user equipment determines a random channel sequence and a waiting period, and sends the channel sequence and waiting period to the vehicle.

[0079] The user's device can send the Nonce received in step 305, along with the channel sequence and the waiting period, to the vehicle.

[0080] Similarly, a user's device can send a command ID to the vehicle.

[0081] Similarly, a user's device can first encrypt the information to be sent (such as channel sequence, wait period, nonce, command ID) and then send the encrypted information to the vehicle.

[0082] For example, a user equipment can send the following message to a vehicle: (E(K) U ,n||Ch||Tw||CMD_CHN),MAC(K U ,n||Ch||Tw||CMD_CHN)), where Ch is the channel sequence, Tw is the wait period, and CMD_CHN is the command ID. The wait period is the time the switch spends on the antenna after completing the transmission / reception of data packets and collecting RSSI.

[0083] Accordingly, in step 306, the vehicle receives information sent by the user equipment. The vehicle can use a key to decrypt the received information to obtain Nonce, Ch, Tw, and CMD_CHN. Furthermore, the user equipment can use the received verification information to determine whether Nonce, Ch, Tw, and CMD_CHN pass data integrity verification. If Nonce, Ch, Tw, and CMD_CHN pass data integrity verification, the user equipment can perform the following steps.

[0084] 307. Vehicles and user equipment initiate channel hopping based on Tw and Ch.

[0085] For the vehicle, it can generate a random antenna switching sequence (hereinafter referred to as "As"), extract the received channel sequence (i.e., Ch), and begin channel hopping with the antenna switching. On each channel, the vehicle can send a challenge data packet, receive a response data packet, and record the received signal strength indicator (RSSI) of the received response data packet. After the TTi time interval, the vehicle, according to A... S Switch the antenna to another antenna. Gi This is a preset value, typically several hundred milliseconds. In some embodiments, T... Gi =T wRepeat this process until N RSSIs are collected, where N is a positive integer greater than or equal to 1. Accordingly, the user equipment can receive challenge packets, send response packets, and record the RSSIs of the received challenge packets.

[0086] Challenge data packets may include the following: (E(K) U ,n||i||CMD_CH),MAC(n||i||CMD_CH)), where i is the packet index and CMD_CH is the command ID used to indicate the channel from which the challenge packet was sent. CMD_CH is an example of the first command ID.

[0087] The response data packet may include the following: (E(K) U ,n||i||CMD_RSP),MAC(n||i||CMD_RSP)), where i is the packet index and CMD_RSP is the command ID indicating the response packet. CMD_RSP is an example of a second command ID.

[0088] In some embodiments, an RSSI can correspond one-to-one with a response packet. In other words, a vehicle can determine an RSSI based on a response packet. Similarly, an RSSI can correspond one-to-one with a challenge packet, meaning that a user equipment can determine an RSSI based on a challenge packet.

[0089] In other embodiments, two or more RSSIs may correspond to a single response packet. In other words, a vehicle can determine multiple RSSIs based on a single response packet. Similarly, a user equipment can determine multiple RSSIs based on a single challenge packet.

[0090] In the above embodiments, after step 304, all information transmitted and received between the user equipment and the vehicle (e.g., nonce, packet index, channel sequence, waiting period, etc.) is encrypted. In other embodiments, only a portion of the information transmitted and received between the user equipment and the vehicle is encrypted. For example, the nonce may be encrypted, while other information (e.g., packet index, command ID, etc.) does not need to be encrypted. As another example, the nonce, channel sequence, and waiting period may be encrypted, while other information (e.g., packet index, command ID, etc.) does not need to be encrypted.

[0091] 308. The vehicle determines the first verification information based on the recorded RSSI. The user equipment determines the second verification information based on the recorded RSSI and sends the second authentication to the vehicle.

[0092] In some embodiments of this application, the first verification information may include the RSSI recorded by the vehicle. Similarly, the second authentication may include the RSSI recorded by the user equipment.

[0093] In some embodiments of this application, each RSSI may correspond to an RSSI level. For example, Table 1 shows the correspondence between RSSI and RSSI levels.

[0094] Table 1

[0095] RSSI RSSI rating -10~0dBm 0 -20~-11dbm 1 -40~-21dBm 2 -80~-41dBm 3 <-81dbm 4

[0096] According to Table 1, if the RSSI detected by the vehicle based on the response data packet is -70 dBm, the vehicle can determine the RSSI level to be 3. The vehicle can determine the RSSI level of the recorded RSSI based on the correspondence between RSSI and RSSI levels. The first verification information may include the RSSI level of the recorded RSSI. Similarly, the user equipment can determine the RSSI level of the recorded RSSI. The second verification information may also include the RSSI level of the recorded RSSI.

[0097] In some embodiments, the vehicle can remove some noise components from the recorded RSSIs to smooth the signal. For example, the vehicle can use a low-pass filter or a Svizsky-Golay filter to filter the recorded RSSIs. Assuming the vehicle records N RSSIs, filtering them leaves M RSSIs. The vehicle can then sort the M RSSIs from lowest to highest and determine their RSSI ranks. In some embodiments, the RSSI ranks can use Gray code. The vehicle can then rearrange the Gray-coded RSSI ranks back to their original positions based on index numbers and encode the Gray-coded RSSI ranks to obtain first check information. The user equipment can perform a similar process to obtain second check information.

[0098] 309. The vehicle verifies the identity of the user equipment based on the first verification information and the second verification information.

[0099] The vehicle can determine the similarity between the first verification information and the second verification information. If the similarity between the first verification information and the second verification information is greater than a preset threshold (e.g., 75%), the vehicle can determine that the user equipment has passed authentication and send an authentication success indication to the user equipment. The authentication success indication is used to indicate that the user equipment has passed authentication. In some embodiments, after successful authentication, the user equipment and the vehicle can determine the distance and range based on the time of flight (TOF) and / or angle of arrival (AOA), and determine whether to unlock the vehicle based on the determined results. In other embodiments, RSSI can be used together with the distance estimated by TOF and AOA to verify whether the distance is close. Therefore, the user equipment and the vehicle can determine whether to unlock the vehicle based on RSSI, TOF, and AOA.

[0100] If the similarity between the first verification information and the second verification information is equal to or less than a preset threshold (e.g., 75%), the vehicle can determine that the user's device has failed authentication. The vehicle can send a failure indication to the user device indicating that the user device has failed authentication, or the vehicle can ignore subsequent messages sent by the user device.

[0101] Due to the reciprocity of wireless channels, BLE feature sets (e.g., RSS on vehicles and RSS on user devices) show a high correlation in their variation trends, but individual values ​​may not be exactly the same due to channel noise, hardware factors, etc. Because of the reciprocity of wireless channels, only interconnected wireless device pairs can have similar RSS values. An attacker or other BLE device near the legitimate device cannot predict the RSS value obtained by the legitimate party. RSS information can be used to confirm different user activities. Both parties, i.e., the vehicle and the user's devices, can confirm this behavior. If another device (e.g., an attacker or eavesdropper) is present in the same neighborhood and is able to eavesdrop on all communications in the (same) channel used by the legitimate device, the RSS observed by this device (through received data packets / signals) will be unrelated to that of the legitimate device due to the multipath effect of the wireless channel. Therefore, this application provides an authentication scheme for ranging and proximity estimation to protect KES.

[0102] Figure 4 A flowchart illustrating an embodiment of a method for verifying the identity of an electronic device is shown.

[0103] 401. The first electronic device sends N challenge data packets to the second electronic device. N is a positive integer greater than or equal to 1.

[0104] The first electronic device may be an electronic device employing one or more antenna arrays with multiple antennas. The second electronic device may have only a single antenna.

[0105] For example, such as Figure 3 The first electronic device mentioned can be a vehicle, and the second electronic device can be a user device. The user device can be a smartphone, smartwatch, vehicle key, etc.

[0106] To give another example, the first electronic device could be a laptop, computer, smart lock, etc. The second electronic device could be a smartphone, smartwatch, smart bracelet, etc.

[0107] To give another example, the first electronic device can be a device included in the aforementioned devices, and the second electronic device can be a device included in the aforementioned devices. For example, the first electronic device can be a telematics box (TBox). The second electronic device can be a radio frequency module in a smartphone.

[0108] Before sending the first challenge data packet to the second electronic device, the first and second electronic devices can establish a wireless connection. For example, such as... Figure 3 As mentioned, the first and second electronic devices establish a wireless connection using BLE. Alternatively, the first and second electronic devices can also use other wireless technologies to establish a wireless connection, such as ZigBEE, IEEE 802.15.4, and ultra-wideband (UWB).

[0109] 402, The first electronic device receives N response data packets from the second electronic device. Each of the N response data packets corresponds one-to-one with one of the N challenge data packets.

[0110] N challenge packets can be sent via channel hopping. In each channel, a first electronic device can send one or more of the N challenge packets to a second electronic device. Correspondingly, the second electronic device can respond with a corresponding response packet in the same channel. The parameters for channel hopping can be pre-set in both the first and second electronic devices based on a trusted party, such as a cloud service, or negotiated during the establishment of wireless communication. The process of negotiating parameters, sending challenge packets, and receiving response packets is described in... Figure 3 The details have already been explained in detail, so they will not be repeated here.

[0111] 403. The first electronic device determines first verification information based on N response data packets. The first verification information is used to indicate the RSS information of the N response data packets.

[0112] 404, The first electronic device obtains the second verification information from the second electronic device. The second verification information is used to indicate the RSS information of N challenge data packets.

[0113] 405. The first electronic device verifies the identity of the second electronic device based on the first verification information and the second verification information.

[0114] according to Figure 4 In the proposed technical solution, the first electronic device can use RSS information to verify the identity of the second electronic device. The RSS information on the first and second electronic devices shows a high correlation in their changing trends, making it difficult for third-party devices to predict or obtain this RSS information. Figure 4 The technical solution in this paper provides an effective identity authentication process by utilizing the characteristics of RSS.

[0115] In some embodiments of this application, the first electronic device may determine a Nonce and send the Nonce to a second electronic device; alternatively, it may determine N challenge data packets. Each of the N challenge data packets includes: first encrypted information encrypted with a preset key, the first encrypted information including the Nonce. Accordingly, the second electronic device may receive the Nonce from the first electronic device.

[0116] The nonce can be used to assist in verifying the identities of both communicating parties. For example, if the nonce obtained by the second electronic device after decrypting the first encrypted information is not one previously sent by the first electronic device, the second electronic device can determine that the first electronic device may be an illegitimate device and will not respond to the response data packet from that device. If the nonce obtained by the second electronic device after decrypting the first encrypted information is one previously sent by the first electronic device, the second electronic device can determine the corresponding response data packet and send the response data packet to the first electronic device. The key used to encrypt / decrypt the first encrypted information can be a pre-shared key or can be determined based on the ID of the second electronic device.

[0117] In some embodiments of this application, each of the N challenge data packets includes first verification information. After decrypting the first encrypted information, the second electronic device can use the first verification information to verify the data integrity of the decrypted information (i.e., the nonce). If the data integrity of the decrypted information passes verification, the second electronic device can determine the corresponding response data packet and send the response data packet to the first electronic device. If the data integrity of the decrypted information fails verification, the second electronic device can instruct the first electronic device to resend the challenge data packets. The first verification information can be the MAC or HMAC of the decrypted information. The key used to determine the first verification information can be the same as the key used to encrypt / decrypt the first encrypted information.

[0118] Similarly, each of the N response packets includes second verification information, which is used to verify the data integrity of the second encrypted information in each of the N response packets. After decrypting the second encrypted information, the first electronic device can use the second verification information to verify the data integrity of the decrypted information (i.e., the Nonce). If the data integrity of the decrypted information passes verification, the first electronic device can determine the corresponding response packet and send the next challenge packet to the second electronic device. If the data integrity of the decrypted information fails verification, the first electronic device can instruct the second electronic device to resend the response packet. The second verification information can be the MAC or HMAC of the decrypted information. The key used to determine the second verification information can be the same as the key used to encrypt / decrypt the second encrypted information.

[0119] In some embodiments of this application, the first electronic device determines first verification information based on N response data packets, including: determining K RSS information based on the N response data packets, each of the K RSS information corresponding to one of the N response data packets, where K is a positive integer greater than or equal to N, and determining the first verification information based on the K RSS information.

[0120] In some embodiments of this application, before determining K RSS information based on N response data packets, the first electronic device can determine whether the N response data packets are trustworthy based on the nonce of each of the N response data packets.

[0121] For example, each of the N response data packets may include second encrypted information and second verification information. Similarly, the second encrypted information may include a Nonce. The key used to encrypt / decrypt the second encrypted information may be the same as the key used to encrypt / decrypt the first encrypted information. The first electronic device can use the key to decrypt the second information to obtain the decrypted information (i.e., the Nonce). The first electronic device can compare the Nonce in the decrypted information with a previously sent Nonce. If the Nonce in the decrypted information is the same as the previously sent Nonce, the first electronic device can use the second verification information to verify the data integrity of the encrypted information. If the encrypted information passes verification, the first electronic device can determine that the response data packet is a trusted data packet; if the encrypted information fails verification, the first electronic device can instruct the second electronic device to resend the response data packet. If the Nonce in the decrypted information is different from the previously received Nonce, the first electronic device can determine that the response data packet is not a trusted data packet.

[0122] RSS information can be the RSS of the corresponding response data packet or the received signal strength indicator (RSSI) of the corresponding response data packet.

[0123] In some embodiments, the first electronic device may apply a filter to K RSS information to obtain M RSS information, where M is a positive integer less than or equal to N; and determine first verification information based on the M RSS information.

[0124] In some embodiments, a first electronic device can determine M RSS level information based on M RSS information, wherein the M RSS level information corresponds one-to-one with the M RSS information; and determine the first verification information based on the M RSS level information. According to the above scheme, the first electronic device uses RSS levels to replace RSS information. Therefore, the amount of data that the first electronic device needs to send to the second electronic device will be reduced.

[0125] In some embodiments, RSS ratings may use Gray code. Gray code is the order of a binary number system such that two consecutive values ​​differ only in one bit (binary digit). Gray code avoids errors or ambiguity during the transition from one number to the next.

[0126] The process of determining the first authentication information is in Figure 3 The details have already been explained in detail, so they will not be repeated here.

[0127] In some embodiments of this application, the second electronic device determines the second verification information based on N challenge data packets, including: determining K RSS information based on the N challenge data packets, each of the K RSS information corresponding to one of the N challenge data packets, where K is a positive integer greater than or equal to N, and determining the second verification information based on the K RSS information.

[0128] In some embodiments of this application, the second electronic device may determine that the N challenge packets are trustworthy based on the Nonce of each of the N challenge packets before determining the K RSS information based on the N challenge packets.

[0129] For example, each of the N challenge packets may include first encrypted information and first verification information. Similarly, the first encrypted information may include a Nonce. The key used to encrypt / decrypt the first encrypted information may be the same as the key used to encrypt / decrypt the first encrypted information. A second electronic device can use the key to decrypt the second information to obtain the decrypted information (i.e., the Nonce). The second electronic device can compare the Nonce in the decrypted information with a previously received Nonce. If the Nonce in the decrypted information is the same as the previously received Nonce, the second electronic device can use the first verification information to verify the data integrity of the encrypted information. If the encrypted information passes verification, the second electronic device can determine that the challenge packet is a trusted packet; if the encrypted information fails verification, the second electronic device can instruct the first electronic device to resend the challenge packet. If the Nonce in the decrypted information is different from the previously received Nonce, the second electronic device can determine that the challenge packet is not a trusted packet.

[0130] RSS information can be the RSS of the corresponding challenge packet or the received signal strength indicator (RSSI) of the corresponding challenge packet.

[0131] In some embodiments, the second electronic device may apply a filter to K RSS messages to obtain M RSS messages, where M is a positive integer less than or equal to N; and determine the second verification information based on the M RSS messages.

[0132] In some embodiments, the second electronic device can determine M RSS level information based on M RSS information, wherein the M RSS level information corresponds one-to-one with the M RSS information; and determine the second verification information based on the M RSS level information. According to the above scheme, the second electronic device uses RSS levels to replace RSS information. Therefore, the amount of data that the second electronic device needs to send to the first electronic device will be reduced.

[0133] The process of determining the second authentication information is in Figure 3 The details have already been explained in detail, so they will not be repeated here.

[0134] In some embodiments, the first electronic device can determine the similarity between first verification information and second verification information. If the similarity between the first verification information and the second verification information is greater than a threshold, the first electronic device can send an authentication success indication to the second electronic device. The authentication success indication is used to indicate that the second electronic device has passed identity authentication. Then, the second electronic device can determine the distance and range based on Time-of-Flight (TOF) and Area of ​​Effect (AOA). Alternatively, in some embodiments, the second electronic device can determine the distance and range based on TOF, AOA, and RSSI.

[0135] Furthermore, in some embodiments, multiple antennas can be used to help obtain sufficient randomness in the RSS values ​​captured on both devices (e.g., for spatial diversity of decorrelated consecutive RSS samples). Therefore, this approach is also suitable for completely static devices (i.e., independent of device mobility). Consequently, this approach is more robust and faster than other mobility-dependent RSS approaches.

[0136] Furthermore, the latest BLE standard version 5.1 and later support the use of BLE channel characteristics to estimate angle of arrival and time of flight. Therefore, this technical solution can be easily implemented on all platforms that support this feature and antenna arrays.

[0137] The technical solutions in the above embodiments can also be implemented in other wireless communication methods for direction finding and ranging, such as UWB, short-range wireless technology (ZigBee / IEEE 802.15.4), etc.

[0138] Figure 5 This is a schematic block diagram of an electronic device 500 according to an embodiment of this application. Figure 5 As shown, the electronic device 500 includes: a transmitting module 501, a receiving module 502, and a determining module 503.

[0139] The sending module 501 is used to send N challenge data packets to another electronic device, where N is a positive integer greater than 1.

[0140] The receiving module 502 is used to receive N response data packets from another electronic device, wherein the N response data packets correspond one-to-one with the N challenge data packets.

[0141] The determining module 503 is used to determine first verification information based on the N response data packets, wherein the first verification information is used to indicate the RSS information of the N response data packets.

[0142] The determining module 503 is further configured to obtain second verification information from the second electronic device, the second verification information being used to indicate the RSS information of the N challenge data packets.

[0143] The determining module 503 is further configured to verify the identity of the other electronic device based on the first verification information and the second verification information.

[0144] Optionally, the electronic device 500 may be the first electronic device or a component of the first electronic device mentioned in the above embodiments. The other electronic device may be the second electronic device or a component of the second electronic device mentioned in the above embodiments.

[0145] Optionally, in some embodiments, the determining module 503 is further configured to determine the Nonce; the sending module is further configured to send the Nonce to another electronic device. The determining module 503 is also configured to determine the N challenge data packets, each of the N challenge data packets including: first encrypted information encrypted by a preset key, the first encrypted information including the Nonce.

[0146] Optionally, in some embodiments, each of the N challenge packets includes first verification information for verifying the data integrity of the first encrypted information in each of the N challenge packets.

[0147] Optionally, in some embodiments, the determining module 503 is specifically configured to: determine K RSS information based on the N response data packets, each of the K RSS information corresponding to one of the N response data packets, where K is a positive integer greater than or equal to N; and determine the first verification information based on the K RSS information.

[0148] Optionally, in some embodiments, the determining module 503 is specifically used to: apply a filter to K RSS information to obtain M RSS information, where M is a positive integer less than or equal to N; and determine first verification information based on the M RSS information.

[0149] In some embodiments, the determining module 503 is specifically used to: determine M RSS level information based on M RSS information, wherein the M RSS level information corresponds one-to-one with the M RSS information; and determine the first verification information based on the M RSS level information.

[0150] Optionally, in some embodiments, the determining module 503 is specifically used to determine the similarity between the first verification information and the second verification information; if the similarity between the first verification information and the second verification information is greater than a threshold, the sending module is further used to send an authentication success indication to the second electronic device, the authentication success indication being used to indicate that the second electronic device has passed identity authentication.

[0151] Figure 6 This is a schematic block diagram of an electronic device 600 according to an embodiment of this application. Figure 6 As shown, the electronic device 600 includes: a receiving module 601, a transmitting module 602, and a determining module 603.

[0152] The receiving module 601 is used to receive N challenge data packets from another electronic device, where N is a positive integer greater than 1.

[0153] The sending module 602 is used to send N response data packets to another electronic device, wherein the N response data packets correspond one-to-one with the N challenge data packets.

[0154] The determination module 603 is used by the second electronic device to determine the second verification information based on the N challenge data packets.

[0155] The sending module 602 is also used to send second verification information to another electronic device.

[0156] Optionally, the electronic device 600 may be the second electronic device or a component of the second electronic device mentioned in the above embodiments. The other electronic device may be the first electronic device or a component of the first electronic device mentioned in the above embodiments.

[0157] Optionally, in some embodiments, the receiving module 601 is further configured to receive a Nonce from another electronic device. The determining module 603 is further configured to determine the N response data packets, each of the N response data packets including: second encrypted information encrypted by a preset key, the second encrypted information including the Nonce.

[0158] Optionally, in some embodiments, each of the N response data packets includes second verification information for verifying the data integrity of the second encrypted information in each of the N response data packets.

[0159] Optionally, in some embodiments, the determining module 603 is specifically used to: determine K RSS information based on the N challenge data packets, each of the K RSS information corresponding to one of the N response data packets, where K is a positive integer greater than or equal to N; and determine the second verification information based on the K RSS information.

[0160] Optionally, in some embodiments, the determining module 603 is specifically used to: apply a filter to K RSS information to obtain M RSS information, where M is a positive integer less than or equal to N; and determine second verification information based on the M RSS information.

[0161] Optionally, in some embodiments, the determining module 603 is specifically used to: determine M RSS level information based on M RSS information, wherein the M RSS level information corresponds one-to-one with the M RSS information; and determine the second verification information based on the M RSS level information.

[0162] like Figure 7 As shown, the electronic device 700 may include a transceiver 701, a processor 702, and a memory 703. The memory 703 may be used to store code, instructions, etc., executed by the processor 702. The electronic device 700 may be the first electronic device or a component of the first electronic device mentioned in the above embodiments.

[0163] It should be understood that the processor 702 can be an integrated circuit chip with signal processing capabilities. In implementation, the various steps of the above method embodiments can be completed by hardware integrated logic circuits in the processor or by software instructions. The processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The processor can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this invention. The general-purpose processor can be a microprocessor, or it can be any conventional processor. The steps of the methods disclosed in the embodiments of this invention can be directly embodied in the execution of a hardware decoding processor, or executed using a combination of hardware and software modules in the decoding processor. The software modules can be located in mature storage media in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. The storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above methods.

[0164] It should be understood that the memory 703 in the embodiments of the present invention can be volatile memory or non-volatile memory, or may include both volatile memory and non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced SDRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), and Direct Rambus RAM (DR RAM).

[0165] like Figure 8 As shown, the electronic device 800 may include a transceiver 801, a processor 802, and a memory 803. The memory 803 may be used to store code, instructions, etc., executed by the processor 802. The electronic device 800 may be a second electronic device or a component of a second electronic device mentioned in the above embodiments.

[0166] It should be understood that the processor 802 can be an integrated circuit chip with signal processing capabilities. In implementation, the various steps of the above method embodiments can be completed by hardware integrated logic circuits in the processor or by software instructions. The processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The processor can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this invention. The general-purpose processor can be a microprocessor, or it can be any conventional processor. The steps of the methods disclosed in the embodiments of this invention can be directly embodied in the execution of a hardware decoding processor, or executed using a combination of hardware and software modules in the decoding processor. The software modules can be located in mature storage media in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. The storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above methods.

[0167] It should be understood that the memory 803 in the embodiments of the present invention can be volatile memory or non-volatile memory, or may include both volatile memory and non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced SDRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), and Direct Rambus RAM (DR RAM).

[0168] It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0169] This application also provides a system-on-a-chip (SoC) including an input / output interface, at least one processor, at least one memory, and a bus. The at least one memory is used to store instructions, and the at least one processor is used to invoke the instructions from the at least one memory to execute the operations performed by the first electronic device in the methods described above.

[0170] This application also provides a system-on-a-chip (SoC) including an input / output interface, at least one processor, at least one memory, and a bus. The at least one memory stores instructions, and the at least one processor invokes the instructions stored in the at least one memory to execute the operations performed by the second electronic device in the methods described above.

[0171] This application also provides a computer storage medium that can store program instructions for performing the steps executed by the first electronic device in the above method.

[0172] Optionally, the storage medium may be a memory 703.

[0173] This application also provides a computer storage medium that can store program instructions for performing the steps executed by the second electronic device in the above method.

[0174] Optionally, the storage medium may be a memory 803.

[0175] This application also provides a computer program product that, when run on an electronic device, causes the electronic device to perform the steps executed by the first electronic device in the above method.

[0176] According to the twelfth aspect, a computer program product is provided that, when the computer program product is run on an electronic device, causes the electronic device to perform the steps performed by the second electronic device in the above method.

[0177] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether the function is performed by hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but should not consider such implementation to be beyond the scope of this application.

[0178] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the above method embodiments, and will not be repeated here.

[0179] In the embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely examples. For example, unit division is only a logical functional division, and other division methods may be used in actual implementation. For example, multiple units or components may be merged or integrated into another system, or some features may be ignored or not performed. In addition, the mutual coupling or direct coupling or communication connection shown or described can be implemented through some interfaces. Direct coupling or communication connection between apparatuses or units can be implemented electronically, mechanically, or in other forms.

[0180] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; they may be located in one place or distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.

[0181] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0182] When these functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to instruct a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0183] The above description is merely a specific embodiment of this application and is not intended to limit the scope of protection of this application. Any variations or substitutions that are readily conceived by those skilled in the art within the scope of the technology disclosed in this application should fall within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for verifying the identity of an electronic device, the method comprising: The method comprises: The first electronic device sends N challenge data packets to a second electronic device, N being a positive integer greater than or equal to 1; The first electronic device receives N response data packets from the second electronic device, the N response data packets corresponding one-to-one to the N challenge data packets; The first electronic device determines first check information according to the N response data packets, the first check information being used to indicate received signal strength, RSS, information of the N response data packets; The first electronic device obtains second check information from the second electronic device, the second check information being used to indicate RSS information of the N challenge data packets; According to the first check information and the second check information, the identity of the second electronic device is verified.

2. The method of claim 1, wherein, Before the first electronic device sends N challenge data packets to a second electronic device, the method further comprises: The first electronic device determines a one-time use digital nonce; The first electronic device sends the nonce to the second electronic device; The first electronic device determines the N challenge data packets, each of the N challenge data packets comprising first encrypted information encrypted by a preset key, the first encrypted information comprising the nonce, a packet index, and a first command identification, ID.

3. The method of claim 2, wherein, Each of the N challenge data packets comprises first check information used to verify the data integrity of the first encrypted information of each of the N challenge data packets.

4. The method according to any one of claims 1 to 3, characterized in that, The first electronic device determines first check information according to the N response data packets, comprising: The first electronic device determines K RSS information according to the N response data packets, each of the K RSS information corresponding to one of the N response data packets, K being a positive integer greater than or equal to N; The first electronic device determines the first check information according to the K RSS information.

5. The method of claim 4, wherein, The first electronic device determines the first check information according to the K RSS information, comprising: The first electronic device applies a filter to the K RSS information to obtain M RSS information, M being a positive integer less than or equal to K; The first electronic device determines the first check information according to the M RSS information.

6. The method according to any one of claims 1 to 3, characterized in that, The first electronic device determines the first check information according to the K RSS information, comprising: The first electronic device determines the similarity of the first check information and the second check information; If the similarity of the first check information and the second check information is greater than a threshold value, a successful authentication indication is sent to the second electronic device, the successful authentication indication being used to indicate that the second electronic device has passed the identity authentication.

7. A method for verifying the identity of an electronic device, the method comprising: The method comprises: The second electronic device receives N challenge data packets from a first electronic device, N being a positive integer greater than or equal to 1; The second electronic device sends N response data packets to the first electronic device, the N response data packets corresponding one-to-one to the N challenge data packets; The second electronic device determines second check information according to the N challenge data packets, the second check information being used to indicate received signal strength, RSS, information of the N challenge data packets; The second electronic device sends the second check information to the first electronic device.

8. The method of claim 7, wherein, Before the second electronic device receives the N challenge data packets from the first electronic device, the method further includes: The second electronic device receives a one-time used digital nonce from the first electronic device; Before the second electronic device sends the N response data packets to the first electronic device, the method further includes: The second electronic device determines the N response data packets, each of the N response data packets including second encrypted information encrypted by a preset key, the second encrypted information including the nonce.

9. The method of claim 8, wherein, Each of the N response data packets includes second check information, the second check information being used to verify data integrity of the second encrypted information of each of the N response data packets.

10. The method according to any one of claims 7 to 9, characterized in that, The second electronic device determines second check information according to the N challenge data packets, including: The second electronic device determines K RSS information according to the N challenge data packets, each of the K RSS information corresponding to one of the N response data packets, K being a positive integer greater than or equal to N; The second electronic device determines the second check information according to the K RSS information.

11. The method of claim 10, wherein, The second electronic device determines the second check information according to the K RSS information, including: The second electronic device applies a filter to the K RSS information to obtain M RSS information, M being a positive integer less than or equal to K; The second electronic device determines the second check information according to the M RSS information.

12. An electronic device, comprising: including: The sending module is configured to send N challenge data packets to another electronic device, N being a positive integer greater than or equal to 1; The receiving module is configured to receive N response data packets from the another electronic device, the N response data packets corresponding to the N challenge data packets one by one; The determining module is configured to determine first check information according to the N response data packets, the first check information being used to indicate received signal strength, RSS, information of the N response data packets; The determining module is further configured to obtain second check information from the another electronic device, the second check information being used to indicate RSS information of the N challenge data packets; The determining module is further configured to verify an identity of the another electronic device according to the first check information and the second check information.

13. The electronic device of claim 12, wherein, The determining module is further configured to determine a one-time used digital nonce; The sending module is further configured to send the nonce to the another electronic device; The determining module is further configured to determine the N challenge data packets, each of the N challenge data packets including first encrypted information encrypted by a preset key, the first encrypted information including the nonce.

14. The electronic device of claim 13, wherein, Each of the N challenge data packets comprises first check information for verifying data integrity of first encrypted information of each of the N challenge data packets.

15. The electronic device of any of claims 12 to 14, wherein, The determination module is specifically configured to: determine K RSS information according to the N challenge data packets, each of the K RSS information corresponding to one of the N response data packets, K being a positive integer greater than or equal to N; determine the first check information according to the K RSS information.

16. The electronic device of claim 15, wherein, The determination module is specifically configured to: apply a filter to the K RSS information to obtain M RSS information, M being a positive integer less than or equal to K; determine the first check information according to the M RSS information.

17. The electronic device of any of claims 12-14, wherein, The determination module is specifically configured to determine similarity of the first check information and the second check information. The sending module is further configured to send an authentication success indication to the other electronic device if the similarity of the first check information and the second check information is greater than a threshold, the authentication success indication being used to indicate that the other electronic device has passed the identity authentication.

18. An electronic device, comprising: Comprise: a receiving module configured to receive N challenge data packets from another electronic device, N being a positive integer greater than or equal to 1; a sending module configured to send N response data packets to the other electronic device, the N response data packets corresponding to the N challenge data packets one by one; a determination module configured to determine second check information according to the N challenge data packets, the second check information being used to indicate received signal strength RSS information of the N challenge data packets; The sending module is further configured to send the second check information to the other electronic device.

19. The electronic device of claim 18, wherein, The receiving module is further configured to receive a one-time use digital nonce from the other electronic device; The determination module is further configured to determine the N response data packets, each of the N response data packets comprising second encrypted information encrypted by a preset key, the second encrypted information comprising the nonce.

20. The electronic device of claim 18, wherein, Each of the N response data packets comprises second check information, the second check information being used to verify data integrity of the second encrypted information of each of the N response data packets.

21. The electronic device of any one of claims 18-20, wherein, The determination module is specifically configured to: determine K RSS information according to the N challenge data packets, each of the K RSS information corresponding to one of the N response data packets, K being a positive integer greater than or equal to N; determine the second check information according to the K RSS information.

22. The electronic device of claim 21, wherein, The determination module is specifically configured to: apply a filter to the K RSS information to obtain M RSS information, M being a positive integer less than or equal to K; determine the second check information according to the M RSS information.

23. A computer-readable storage medium, characterized in that, The computer readable storage medium stores instructions, when the instructions run on the server, cause the server to execute the method according to any one of claims 1 to 6.

24. A computer-readable storage medium, characterized in that, The computer readable storage medium stores instructions, when the instructions run on the server, cause the server to execute the method according to any one of claims 7 to 11. The computer readable storage medium stores instructions, when the instructions run on the server, cause the server to execute the method according to any one of claims 1 to 6. The computer readable storage medium stores instructions, when the instructions run on the server, cause the server to execute the method according to any one of claims 7 to 11.

25. An electronic device, comprising: The electronic device comprises a memory for storing a computer program and a processor for calling the computer program from the memory and running the computer program, so that the computer on which the chip is located executes the method according to any one of claims 1 to 6.

26. An electronic device, comprising: The electronic device comprises a memory for storing a computer program and a processor for calling the computer program from the memory and running the computer program, so that the computer on which the chip is located executes the method according to any one of claims 7 to 11.

27. A computer program product, characterised in that, When the computer program product is running on a server, the server is caused to execute the method according to any one of claims 1 to 6.

28. A computer program product, characterised in that, When the computer program product is running on a server, the server is caused to execute the method according to any one of claims 7 to 11.

29. A vehicle characterized by An electronic device according to any one of claims 12 to 17.

Citation Information

Patent Citations

  • Method of authentication of users in data processing systems

    CN101897165A

  • System for preventing establishment of unauthorized communication

    CN102555991A