A method and system for locating a vehicle
By using cloud server-side permission verification and end-to-end encryption, the problem of mechanical keys or NFC card keys needing to be close to the vehicle to perform control functions is solved, improving the efficiency of finding and moving the vehicle while ensuring operational security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHONGQING JINKANG NEW ENERGY VEHICLE CO LTD
- Filing Date
- 2024-09-24
- Publication Date
- 2026-04-21
AI Technical Summary
After the remote key is removed, mechanical keys or NFC card keys need to be close to the vehicle to perform unlocking and locking control, making it difficult to find the car and affecting the efficiency of finding and moving the car.
The system obtains the account application information through the cloud server, sets vehicle search permissions, and performs permission and certificate verification to achieve end-to-end encryption, ensuring the security and legitimacy of vehicle control commands.
It improves the efficiency of finding and moving vehicles, ensures operational security, and avoids abuse of permissions and the system.
Smart Images

Figure CN119110287B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vehicle technology, and in particular to a vehicle location method and a vehicle location system. Background Technology
[0002] With the development of smart technology, automotive electronics are constantly innovating, and the form of car keys is also constantly changing. From the first stage of mechanical keys, the second stage of keys, to the current stage of digital keys, car keys are becoming increasingly convenient. Currently, smart cars can be equipped with digital car keys, NFC card keys, etc., and the usage frequency of traditional remote keys is gradually decreasing. However, before the car is assembled and leaves the factory, because the remote key has been eliminated, it is necessary to use the equipped mechanical key or NFC card key to control the car. But both mechanical keys and NFC cards need to be close to the vehicle to perform unlocking and other controls.
[0003] Therefore, after the remote key is removed, when it is necessary to find the vehicle, the mechanical key or NFC card needs to be close to the vehicle to perform control functions such as locking and unlocking, which will make it extremely difficult to find the vehicle and seriously affect the efficiency of finding and moving the vehicle.
[0004] How to accurately know the specific location of vehicles when they are parked in batches after they roll off the production line, simplify the vehicle location process, and improve the efficiency of finding and moving vehicles is an urgent problem to be solved. Summary of the Invention
[0005] In view of the above problems, embodiments of the present invention are proposed to provide a vehicle location method and a vehicle location system that overcome or at least partially solve the above problems.
[0006] According to a first aspect of the present invention, a vehicle location method is provided, applied to a cloud server, the method comprising:
[0007] Obtain account application information from the account application portal;
[0008] Set the vehicle search permissions corresponding to the account based on the application information;
[0009] Obtain the vehicle identification number (VIN) of the target vehicle to be queried by the current client account, and verify the vehicle search permission of the current client account based on the VIN. If the permission verification passes, send the location information request of the target vehicle corresponding to the VIN to the vehicle terminal, so that the vehicle terminal sends the location information of the target vehicle to the cloud server according to the location information request.
[0010] The location information of the target vehicle is sent to the client. Upon receiving the encrypted vehicle search command from the client, the client performs a secondary permission verification on the vehicle search permission of the current account based on the vehicle identification number. If the secondary permission verification passes, the vehicle search command is transmitted to the vehicle terminal, so that the vehicle terminal performs certificate verification on the vehicle search command. If the certificate verification passes, the vehicle search command is executed.
[0011] Optionally, the vehicle search permissions include at least: a first vehicle search permission, a second vehicle search permission, and no vehicle search permission;
[0012] The step of setting the vehicle search permissions corresponding to the account based on the application information includes:
[0013] If the personnel information in the application meets the application conditions and the usage type of the application information is within a preset range, the account has the first vehicle search permission;
[0014] If the personnel information in the application meets the application conditions and the usage type of the application information is outside the preset range, the account has the second vehicle search permission;
[0015] If the applicant's personal information does not meet the application requirements, the account does not have vehicle search privileges.
[0016] Optionally, before obtaining the vehicle identification number (VIN) of the target vehicle to be queried by the client's current account, the method further includes:
[0017] Upon receiving a remote control certificate application instruction sent by the client, the remote control certificate is generated and sent to the client.
[0018] Optionally, the cloud server includes at least: a vehicle networking service platform and a certificate management platform;
[0019] The step of generating the remote control certificate and sending it to the client upon receiving the remote control certificate application instruction sent by the client includes:
[0020] When the vehicle network service platform receives a remote control certificate application instruction sent by the client, it transmits the remote control certificate application instruction to the certificate management platform.
[0021] The certificate management platform generates a remote control certificate and sends it to the vehicle network service platform;
[0022] The vehicle networking service platform issues the remote control certificate to the client.
[0023] Optionally, the cloud server includes at least: a vehicle networking service platform and a production and sales platform;
[0024] The process includes obtaining the vehicle identification number (VIN) of the target vehicle to be queried by the current client account, verifying the vehicle search permission of the current client account based on the VIN, and if the permission verification passes, sending a location information request for the target vehicle corresponding to the VIN to the vehicle terminal.
[0025] Obtain the vehicle identification number (VIN) of the target vehicle that the current client account needs to query;
[0026] The production and sales platform determines the production and sales status of the target vehicle based on the vehicle identification number of the target vehicle;
[0027] The vehicle networking service platform verifies the vehicle search permission of the client's current account based on the production and sales status of the target vehicle. If the permission verification passes, the platform sends a request for the location information of the target vehicle corresponding to the vehicle identification number to the in-vehicle terminal.
[0028] Optionally, the production and sales status includes: sold, received but not shipped, and received but shipped.
[0029] The vehicle networking service platform verifies the vehicle search permission of the client's current account based on the production and sales status of the target vehicle, including:
[0030] If the target vehicle is in the state of having been sold, the authorization verification fails.
[0031] If the target vehicle's production and sales status is "in stock - not shipped" and the account has the first vehicle search permission, the permission verification passes.
[0032] If the target vehicle's production and sales status is "in stock - shipped" and the account has the second vehicle search permission, the permission verification will pass.
[0033] Optionally, upon receiving an encrypted vehicle-finding instruction from the client, performing a secondary permission verification on the client's current account's vehicle-finding permissions based on the vehicle identification number; if the secondary permission verification passes, transmitting the vehicle-finding instruction to the vehicle terminal, includes:
[0034] If the target vehicle's production and sales status is "in stock - not shipped" and the account has the first vehicle search permission, the permission verification passes and the encrypted vehicle search command is transmitted to the vehicle terminal.
[0035] According to a second aspect of the present invention, a vehicle location method is provided, applied to a client, the method comprising:
[0036] The application information is sent to the account application terminal; the account application terminal generates an account and password based on the application information.
[0037] Log in to apply for an account and check if a remote control certificate exists. If the remote control certificate exists, enter the vehicle identification number of the target vehicle to obtain the location information of the target vehicle. If the remote control certificate does not exist, send a remote control certificate application command to the cloud server and obtain the remote control certificate.
[0038] Based on the location information of the target vehicle, a vehicle search command is sent to the cloud server. The cloud server performs permission verification, and if the permission verification is successful, the vehicle search command is sent to the vehicle terminal.
[0039] According to a third aspect of the present invention, a vehicle location method is provided, applied to an in-vehicle terminal, the method comprising:
[0040] A request to obtain the location information of the target vehicle is made, and the location information of the target vehicle is sent to the cloud server.
[0041] Obtain the vehicle search command, verify the signature chain of the root certificate and remote control certificate of the vehicle search command, and execute the vehicle search command if the verification passes.
[0042] According to a fourth aspect of the present invention, a vehicle location system is provided, the system comprising:
[0043] The cloud server is used to execute the steps of the vehicle location method applied to the cloud server.
[0044] The client is used to execute the steps of the vehicle location method applied to the client.
[0045] The vehicle terminal is used to execute the steps of the vehicle location method applied to the vehicle terminal.
[0046] The embodiments of the present invention have the following advantages:
[0047] In this embodiment of the invention, the application information of the account is obtained from the account application terminal; the corresponding vehicle search permission is set according to the application information; the vehicle identification number of the target vehicle queried by the current account is obtained; the vehicle search permission of the current account is verified based on the vehicle identification number; if the permission verification passes, the location information of the target vehicle is obtained through the vehicle terminal; if an encrypted vehicle search command is received, the vehicle search permission of the current account of the client is verified a second time based on the vehicle identification number; if the verification passes, the vehicle search command is transmitted to the vehicle terminal so that the vehicle terminal can perform certificate verification on the vehicle search command; if the certificate verification passes, the vehicle search command is executed. Setting the corresponding vehicle search permission through the application information can avoid the abuse of permissions and the system, and all vehicle control commands are encrypted end-to-end to ensure the security of the operation.
[0048] The above description is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of the present invention more apparent and understandable, specific embodiments of the present invention are described below. Attached Figure Description
[0049] The accompanying drawings, which form part of this application, are used to provide a further understanding of this application. The illustrative embodiments of this application and their descriptions are used to explain this application and do not constitute an undue limitation of this application.
[0050] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments of this application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0051] Figure 1 This is a flowchart of the cloud server steps of an embodiment of the vehicle location method of the present invention;
[0052] Figure 2 This is a flowchart of the client-side steps of an embodiment of the vehicle location method of the present invention;
[0053] Figure 3 This is a flowchart of the vehicle terminal steps in an embodiment of the vehicle location method of the present invention;
[0054] Figure 4 This is a system control diagram of the vehicle location system provided in an embodiment of the present invention;
[0055] Figure 5 This is a flowchart illustrating the overall steps of a vehicle location system according to the present invention. Detailed Implementation
[0056] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this invention will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.
[0057] The terms "first," "second," etc., used in the specification and claims of this invention are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.
[0058] The following detailed description, in conjunction with the accompanying drawings, of a vehicle location method and system provided by the present invention through specific embodiments and application scenarios, will illustrate this invention in detail.
[0059] With the development of smart technology, automotive electronics are constantly innovating, and the form of car keys is also constantly changing. From the first stage of mechanical keys, the second stage of keys, to the current stage of digital keys, car keys are becoming increasingly convenient. Currently, smart cars can be equipped with digital car keys, NFC card keys, etc., and the usage frequency of traditional remote keys is gradually decreasing. However, before the car is assembled and leaves the factory, because the remote key has been eliminated, it is necessary to use the equipped mechanical key or NFC card key to control the car. However, both mechanical keys and NFC cards need to be close to the vehicle to perform unlocking and other controls. Therefore, after the remote key has been eliminated, finding the car will be extremely difficult because the mechanical key or NFC card needs to be close to the vehicle to perform unlocking and other controls, seriously affecting the efficiency of finding and moving the car.
[0060] The embodiments of the present invention can avoid the abuse of permissions and systems by setting corresponding vehicle search permissions through application information, and all vehicle control commands are encrypted end-to-end to ensure the security of operation.
[0061] Reference Figure 1 The diagram illustrates a cloud server-side flowchart of an embodiment of the vehicle location method of the present invention, which may specifically include the following steps:
[0062] Step 101: Obtain the account application information from the account application platform;
[0063] In this embodiment of the invention, account application information sent by the user on the account application terminal can be obtained from the account application terminal. The application information includes at least the employment status of the account applicant and the type of account usage. After the account application terminal approves the application, the cloud service obtains the corresponding account application information from the account application terminal. The account application terminal can be an OA system (Office Automation System) or other office systems; this embodiment of the invention does not limit the system used for the account application terminal.
[0064] Step 102: Set the vehicle search permissions corresponding to the account based on the application information;
[0065] In this embodiment of the invention, the cloud server can set the vehicle search permission for the corresponding account based on the obtained account application information, and the vehicle search permission will be updated as the account application information changes.
[0066] Specifically, the cloud server can obtain the applicant's employment status and / or account usage type in real time based on the account application. When the applicant's employment status and / or account usage type change, the car-finding permissions corresponding to the account will also change. By dynamically updating the car-finding permissions based on the application information, strict access control can be implemented for users. Once an employee leaves the company or their employment status changes, the account will be automatically disabled.
[0067] Step 103: Obtain the vehicle identification number (VIN) of the target vehicle to be queried by the current client account. Based on the VIN, verify the vehicle search permission of the current client account. If the permission verification passes, send the location information request of the target vehicle corresponding to the VIN to the vehicle terminal, so that the vehicle terminal sends the location information of the target vehicle to the cloud server according to the location information request.
[0068] In this embodiment of the invention, the cloud server can obtain the vehicle identification number (VIN) of the target vehicle that the client's current account wants to query, determine the vehicle status based on the VIN, and determine whether the client's current account's vehicle search permission can pass the permission verification based on the vehicle status. That is, it can determine whether the account can query the location information of the vehicle and / or control the target vehicle. Only if the permission verification is passed will the cloud server send the target vehicle's location information request to the vehicle terminal, so that the vehicle terminal can send the target vehicle's location information to the cloud server according to the location information request.
[0069] Step 104: Send the location information of the target vehicle to the client. Upon receiving the encrypted vehicle search command from the client, perform a secondary permission verification on the vehicle search permission of the client's current account based on the vehicle identification number. If the secondary permission verification passes, transmit the vehicle search command to the vehicle terminal so that the vehicle terminal can perform certificate verification on the vehicle search command. If the certificate verification passes, execute the vehicle search command.
[0070] In this embodiment of the invention, after the cloud server sends the location information of the target vehicle to the client, it also obtains the encrypted vehicle search command issued by the client based on the target vehicle. After receiving the encrypted vehicle search command sent by the client, it performs a secondary permission verification on the current account's vehicle search permission based on the VIN code. Only after passing the secondary permission verification will the cloud server transmit the vehicle search command to the vehicle terminal, so that the vehicle terminal can perform certificate verification on the vehicle search command. If the certificate verification is successful, the vehicle search command is executed. The vehicle search command is signed using the certificate private key, and the terminal verifies the received signed command.
[0071] This invention provides a vehicle location method that obtains account application information from the account application client; sets corresponding vehicle location permissions based on the application information; obtains the vehicle identification number (VIN) of the target vehicle currently being queried by the current account; verifies the vehicle location permissions of the current account based on the VIN; if the permission verification passes, the location information of the target vehicle is obtained through the vehicle terminal; if an encrypted vehicle location command is received, a second permission verification is performed on the current account's vehicle location permissions based on the VIN; if the verification passes, the vehicle location command is transmitted to the vehicle terminal so that the vehicle terminal can perform certificate verification on the vehicle location command; if the certificate verification passes, the vehicle location command is executed. Setting corresponding vehicle location permissions through the application information can prevent the abuse of permissions and the system, and all vehicle control commands are end-to-end encrypted to ensure operational security.
[0072] In one embodiment of the present invention, the vehicle search permission includes at least: a first vehicle search permission, a second vehicle search permission, and no vehicle search permission;
[0073] The step of setting the vehicle search permissions corresponding to the account based on the application information includes:
[0074] If the personnel information in the application meets the application conditions and the usage type of the application information is within a preset range, the account has the first vehicle search permission;
[0075] If the personnel information in the application meets the application conditions and the usage type of the application information is outside the preset range, the account has the second vehicle search permission;
[0076] If the applicant's personal information does not meet the application requirements, the account does not have vehicle search privileges.
[0077] In this embodiment of the invention, vehicle search permissions can be divided into at least a first vehicle search permission, a second vehicle search permission, and no vehicle search permission, with different application information corresponding to different vehicle search permissions. In one embodiment, when the account applicant's employment status is active and the usage type is within a preset range, the account has the first vehicle search permission, which allows it to obtain the location information of target vehicles within the preset range and / or control the target vehicles; when the account applicant's job status is active and the usage type is outside the preset range, the account has the second vehicle search permission, which allows it to obtain the location information of target vehicles outside the preset range; when the account applicant's job status is unemployed, the account has no vehicle search permission and cannot obtain the location information of target vehicles and / or control the target vehicles. The preset range can be an area of the factory parking lot or a specific area responsible for parking vehicles after they have finished production. It can be set according to the specific usage situation. This embodiment of the invention does not limit the preset range.
[0078] By restricting account access based on the applicant's job status and usage type, strict access control is implemented to prevent individuals from viewing vehicle location information and controlling the vehicle even when the applicant's application information does not meet the requirements, thus avoiding privacy leaks.
[0079] In one embodiment of the present invention, before obtaining the vehicle identification number of the target vehicle to be queried by the client's current account, the method further includes:
[0080] Upon receiving a remote control certificate application instruction sent by the client, the remote control certificate is generated and sent to the client.
[0081] In this embodiment of the invention, before the cloud server obtains the vehicle identification number of the target vehicle to be queried by the client's current account, it will also generate a remote control certificate and send it to the client upon receiving the remote control certificate application instruction sent by the client. Specifically, the client can generate a public-private key pair. The public key will be used to generate a CSR (Certificate Signing Request) file, and the private key will be used for subsequent signing operations. After generating the public-private key pair, the public key needs to be assembled into a CSR file. The CSR file contains the public key, user information, and signature. After generating the CSR file, it is sent to the cloud server.
[0082] When the client logs in to an account, it checks whether the account has vehicle search permission. If vehicle search permission exists, it checks whether a remote control certificate exists. If a remote control certificate does not exist, it generates a remote control certificate application command and sends it to the cloud server. The cloud server generates a remote control certificate based on the remote control certificate application command and distributes it to the client. By distributing the remote control certificate, all vehicle control commands are encrypted end-to-end, ensuring the security of the commands.
[0083] In one embodiment of the present invention, the cloud server includes at least: a vehicle networking service platform and a certificate management platform;
[0084] The step of generating the remote control certificate and sending it to the client upon receiving the remote control certificate application instruction sent by the client includes:
[0085] When the vehicle network service platform receives a remote control certificate application instruction sent by the client, it transmits the remote control certificate application instruction to the certificate management platform.
[0086] The certificate management platform generates a remote control certificate and sends it to the vehicle network service platform;
[0087] The vehicle networking service platform issues the remote control certificate to the client.
[0088] In this embodiment of the invention, the cloud server includes at least a vehicle network service platform and a certificate management platform. The certificate management platform is responsible for issuing certificates to clients and vehicle terminals for end-to-end encryption support of commands. The TSP platform (Telematics Service Provider) is the core system for business processing, responsible for account permission management, vehicle status management, vehicle location information processing, vehicle search command processing, etc. When the vehicle network service platform receives a remote control certificate application command sent by the client, it transmits the remote control certificate application command to the certificate management platform. The certificate management platform generates a remote control certificate and sends it to the vehicle network service platform. Then, the vehicle network service platform distributes the remote control certificate to the client. By transmitting commands through the TSP platform and distributing remote control certificates through the certificate management platform, all vehicle control commands are ensured to undergo end-to-end encryption processing, guaranteeing the security of the commands.
[0089] In one embodiment of the present invention, the cloud server includes at least: a vehicle networking service platform and a production and sales platform;
[0090] The process includes obtaining the vehicle identification number (VIN) of the target vehicle to be queried by the current client account, verifying the vehicle search permission of the current client account based on the VIN, and if the permission verification passes, sending a location information request for the target vehicle corresponding to the VIN to the vehicle terminal.
[0091] Obtain the vehicle identification number (VIN) of the target vehicle that the current client account needs to query;
[0092] The production and sales platform determines the production and sales status of the target vehicle based on the vehicle identification number of the target vehicle;
[0093] The vehicle networking service platform verifies the vehicle search permission of the client's current account based on the production and sales status of the target vehicle. If the permission verification passes, the platform sends a request for the location information of the target vehicle corresponding to the vehicle identification number to the in-vehicle terminal.
[0094] In this embodiment of the invention, the cloud server includes at least a vehicle network service platform and a production and sales platform. The TSP platform (Telematics Service Provider) is the core system for business processing, responsible for account permission management, vehicle status management, vehicle location information processing, vehicle search command processing, etc. The production and sales platform is responsible for synchronizing the current production status or sales status of the vehicle to the TSP platform to support the TSP platform in determining whether the vehicle can be located or searched.
[0095] When the TSP platform obtains the VIN code of the target vehicle that the client's current account needs to query, the production and sales platform will determine the production and sales status of the target vehicle based on the VIN code. Then, the TSP platform will verify the client's current account's vehicle search permission based on the production and sales status of the target vehicle. Only when the permission verification is successful will the target vehicle's location information request be sent to the vehicle terminal.
[0096] By restricting vehicle search permissions based on the vehicle's production and sales status and the account's vehicle search permissions, companies can better manage the vehicle lifecycle. From production and sales to after-sales service, each stage has clear permission controls. This can restrict access to information on vehicles that have not yet been sold, without affecting the use of vehicles by owners after they have been sold.
[0097] In one embodiment of the present invention, the production and sales status includes: sold, warehoused but not shipped, and warehoused and shipped.
[0098] The vehicle networking service platform verifies the vehicle search permission of the client's current account based on the production and sales status of the target vehicle, including:
[0099] If the target vehicle is in the state of having been sold, the authorization verification fails.
[0100] If the target vehicle's production and sales status is "in stock - not shipped" and the account has the first vehicle search permission, the permission verification passes.
[0101] If the target vehicle's production and sales status is "in stock - shipped" and the account has the second vehicle search permission, the permission verification will pass.
[0102] In this embodiment of the invention, the production and sales status can be divided into three categories: sold, warehoused but not yet shipped, and warehoused and shipped. The vehicle networking service platform verifies the vehicle-finding permissions of the client's current account based on the production and sales status of the target vehicle. Specifically, this may include: when the production and sales status of the target vehicle is sold, the target vehicle has already left the factory's off-line vehicle parking area and has been delivered or is being delivered to the user. At this time, regardless of whether the account's vehicle-finding permission is the first vehicle-finding permission, the second vehicle-finding permission, or other vehicle-finding permissions, the permission verification will fail. The location information of the sold vehicle cannot be viewed, and the sold vehicle cannot be controlled. This restricts permissions to the sold vehicle but does not affect the use of the vehicle by the owner after the sale. When the target vehicle's production and sales status is "in stock - not shipped," and the account has the first vehicle search permission, the permission verification passes. Since the target vehicle in the "in stock - not shipped" status will be parked in the factory's off-line vehicle parking area, i.e., within the preset range, the account can obtain the location information of the target vehicle in the "in stock - not shipped" status and control the target vehicle. When the target vehicle's production and sales status is "in stock - shipped," and the account has the second vehicle search permission, the permission verification passes. Since the vehicle in the "in stock - shipped" status has left the factory's off-line vehicle parking area, i.e., within the preset range, and is en route to other locations, the account can obtain the location information of the target vehicle in the "in stock - shipped" status but cannot control the vehicle.
[0103] Based on the production and sales status, the production and sales status of vehicles are divided into sold, warehoused but not shipped, and warehoused and shipped. Different vehicle search permissions can control vehicles in different production and sales statuses, which can help enterprises better manage the vehicle life cycle. From production and sales to after-sales service, each stage has clear permission control, and the information can only be viewed on vehicles that have not been sold, so as not to affect the use of vehicles by owners after the vehicles have been sold.
[0104] In an optional embodiment of the present invention, upon receiving the encrypted vehicle-finding instruction sent by the client, performing a secondary permission verification on the vehicle-finding permission of the client's current account based on the vehicle identification number, and transmitting the vehicle-finding instruction to the vehicle terminal if the secondary permission verification passes, includes:
[0105] If the target vehicle's production and sales status is "in stock - not shipped" and the account has the first vehicle search permission, the permission verification passes and the encrypted vehicle search command is transmitted to the vehicle terminal.
[0106] In this embodiment of the invention, after the cloud server sends the location information of the target vehicle to the client, the client will issue a vehicle-finding command based on the location information of the target vehicle to control the vehicle to flash its lights, honk its horn, etc. At this time, if the cloud server receives the encrypted vehicle-finding command sent by the client, specifically, the client signs the command using the private key generated when applying for the certificate, and sends the signed command to the TSP platform. The TSP platform performs a secondary permission verification on the vehicle-finding permission of the client's current account based on the VIN code. Only when the production and sales status of the target vehicle is "in stock - not shipped", and the account has the first vehicle-finding permission, will the secondary permission verification pass, and the vehicle-finding command will be transmitted to the vehicle terminal. Furthermore, the cloud server does not parse the vehicle-finding command when transmitting it. All vehicle-finding commands are end-to-end encrypted, preventing them from being exploited by network or cloud vulnerabilities or tampered with or leaked by attackers, thus ensuring the security of the vehicle-finding command.
[0107] In this embodiment of the invention, the application information of the account is obtained from the account application terminal; the corresponding vehicle search permission is set according to the application information; the vehicle identification number of the target vehicle queried by the current account is obtained; the vehicle search permission of the current account is verified based on the vehicle identification number; if the permission verification passes, the location information of the target vehicle is obtained through the vehicle terminal; if an encrypted vehicle search command is received, the vehicle search permission of the current account of the client is verified a second time based on the vehicle identification number; if the verification passes, the vehicle search command is transmitted to the vehicle terminal so that the vehicle terminal can perform certificate verification on the vehicle search command; if the certificate verification passes, the vehicle search command is executed. Setting the corresponding vehicle search permission through the application information can avoid the abuse of permissions and the system, and all vehicle control commands are encrypted end-to-end to ensure the security of the operation.
[0108] Reference Figure 2 The diagram illustrates a client-side flowchart of an embodiment of the vehicle location method of the present invention, which may specifically include the following steps:
[0109] Step 201: Send application information to the account application terminal; the account application terminal generates an account and password based on the application information;
[0110] In this embodiment of the invention, the applicant can send the application information to the account application terminal through the client, and the account application terminal will generate an account and password based on the application information.
[0111] Step 202: Log in to the application account and check if a remote control certificate exists. If the remote control certificate exists, enter the vehicle identification number of the target vehicle to obtain the location information of the target vehicle. If the remote control certificate does not exist, send a remote control certificate application command to the cloud server and obtain the remote control certificate.
[0112] In this embodiment of the invention, when a user logs in to the account applied for through the client, the existence of a remote control certificate is checked. If the remote control certificate exists, the target vehicle's vehicle identification number is entered and the cloud server transmits data to obtain the target vehicle's location information. If the remote control certificate does not exist, a remote control certificate application instruction is sent to the cloud server to obtain the remote control certificate.
[0113] Step 203: Based on the location information of the target vehicle, a vehicle search command is sent to the cloud server. The cloud server performs permission verification. If the permission verification is successful, the vehicle search command is sent to the vehicle terminal.
[0114] In this embodiment of the invention, after obtaining the location information of the target vehicle, navigation can be performed based on the location information of the target vehicle, and a vehicle search command can be issued. The vehicle search command is signed with a private key and sent to the cloud server. The cloud server transmits the vehicle search command to the vehicle terminal without being responsible for parsing the vehicle search command. This ensures that the vehicle control command is encrypted end-to-end and will not be exploited by network or cloud vulnerabilities or tampered with or leaked by attackers, thereby improving the security of using digital keys for vehicle location and control.
[0115] Reference Figure 3 The diagram illustrates a vehicle terminal step flowchart of an embodiment of the vehicle location method of the present invention, which may specifically include the following steps:
[0116] Step 301: Obtain the location information request of the target vehicle and send the location information of the target vehicle to the cloud server;
[0117] Step 302: Obtain the vehicle search command, verify the signature chain of the root certificate and remote control certificate of the vehicle search command, and execute the vehicle search command if the verification passes.
[0118] In this embodiment of the invention, the location information request for the target vehicle received by the client is verified by the cloud server based on the production and sales status of the target vehicle and the current account's full vehicle permissions. Only location information requests that meet the permission requirements are received, thus implementing strict access control for users, greatly improving the efficiency of vehicle locating and the security of digital key vehicle locating. Furthermore, the vehicle locating command obtained by the vehicle terminal undergoes a second permission verification by the cloud server. That is, the vehicle locating command is only transmitted to the vehicle terminal if the target vehicle is in the warehouse but not yet shipped, and the account has primary vehicle locating permissions. The cloud server does not parse the vehicle locating command. The vehicle locating command can only be executed if the vehicle terminal verifies the signature chain of the root certificate and remote control certificate of the vehicle locating command.
[0119] In an optional embodiment of the present invention, the vehicle terminal includes at least a TBOX telematics processor and an ECU electronic control unit. The TBOX telematics processor is responsible for sending the location information of the target vehicle to the cloud server and receiving the vehicle search command and verifying the root certificate of the vehicle search command and the signature chain of the remote control certificate. When the verification is successful, the vehicle search request is sent to the ECU electronic control unit. The ECU electronic control unit is responsible for controlling the vehicle to perform operations such as flashing lights and honking the horn.
[0120] In this embodiment of the invention, the application information of the account is obtained from the account application terminal; the corresponding vehicle search permission is set according to the application information; the vehicle identification number of the target vehicle queried by the current account is obtained; the vehicle search permission of the current account is verified based on the vehicle identification number; if the permission verification passes, the location information of the target vehicle is obtained through the vehicle terminal; if an encrypted vehicle search command is received, the vehicle search permission of the current account of the client is verified a second time based on the vehicle identification number; if the verification passes, the vehicle search command is transmitted to the vehicle terminal so that the vehicle terminal can perform certificate verification on the vehicle search command; if the certificate verification passes, the vehicle search command is executed. Setting the corresponding vehicle search permission through the application information can avoid the abuse of permissions and the system, and all vehicle control commands are encrypted end-to-end to ensure the security of the operation.
[0121] Reference Figure 4 The diagram illustrates a system control schematic of a vehicle location system according to the present invention, which may specifically include the following:
[0122] The cloud server is responsible for executing the steps and processes of the vehicle location method on the cloud server, and is responsible for account management, permission management, vehicle status, certificate management, vehicle location data and vehicle control command transmission;
[0123] The client is responsible for executing the steps of the vehicle location method, including querying vehicle information and issuing vehicle location commands.
[0124] The vehicle terminal is responsible for executing the steps and procedures of the vehicle location method of the on-board terminal, determining the vehicle location data, and decrypting and executing the vehicle location control commands.
[0125] In one optional embodiment of the present invention, the cloud server includes at least a certificate management platform, a TSP platform (Telematics Service Provider), and a production and sales platform; wherein the certificate management platform is responsible for generating remote control certificates; the TSP platform is at least responsible for receiving and transmitting data such as vehicle information query requests, vehicle search instructions, account application information, and vehicle production and sales status; and the production and sales platform is responsible for synchronizing the vehicle production and sales status to the TSP platform.
[0126] In an optional embodiment of the present invention, the vehicle location system further includes an account application terminal, which is responsible for generating an account and password based on the applicant's application information. The account application terminal can be an OA system (Office Automation System) or other office systems. The embodiments of the present invention do not limit the system of the account application terminal.
[0127] Reference Figure 5 The diagram shows an overall flowchart of a vehicle location system according to the present invention, which may specifically include the following steps:
[0128] 1. Use the account application portal to apply for a client account;
[0129] 2. Once the account application is approved, the information is synchronized to the vehicle network service platform. The vehicle network service platform then generates the account and initial password and returns them to the account application end.
[0130] 3. Client account login: The vehicle networking service platform verifies account permissions and validity; if successful, proceed to the next step; otherwise, end.
[0131] 4. The client checks if a remote control certificate exists. If a remote control certificate exists, proceed to the next step. If no remote control certificate exists, a public / private key pair and a certificate signing request file are generated, and a certificate application is requested from the vehicle network service platform. The vehicle network service platform then transmits instructions to the certificate management terminal to apply for the certificate. The certificate management system generates the certificate and returns it to the vehicle network service platform, which then distributes it to the client, allowing for the next step.
[0132] 5. Enter the VIN (Vehicle Identification Number) to request a vehicle location query;
[0133] 6. The vehicle network service platform determines vehicle status and verifies permissions. When a vehicle's production and sales status is "sold," the client will prompt that it does not have viewing or control permissions, and cannot view the location information of sold vehicles or control sold vehicles. When a vehicle's production and sales status is "in storage - not shipped," the client will display the vehicle location interface and the vehicle search function interface, and can obtain the location information of the target vehicle in storage - not shipped and control the target vehicle. When a vehicle's production and sales status is "in storage - shipped," the client will only display the vehicle location interface and will not display the vehicle search function interface, meaning it can obtain the location information of the target vehicle in storage - shipped but cannot control the vehicle.
[0134] 7. When the client queries the vehicle's current location, the vehicle networking service platform wakes up the in-vehicle terminal and uploads the location information, which is then displayed on the client, and navigation can be performed through the client;
[0135] 8. The client sends a vehicle search command, signs the command with its private key, and sends the signed command to the vehicle network service platform;
[0136] 9. The vehicle network service platform performs a second verification of the client account permissions. If the second verification passes, proceed to the next step; otherwise, the process ends.
[0137] 10. The vehicle-to-everything (V2X) service platform transmits commands transparently without modifying their content;
[0138] 11. The TBOX remote information processor receives vehicle control commands and verifies the signature chain of the terminal remote control certificate to ensure the integrity of the commands;
[0139] 12. After the TBOX remote information processor verifies the instruction, it sends the vehicle search request to the vehicle's ECU electronic control unit, which then controls the vehicle to flash its lights and sound its horn.
[0140] In an optional embodiment of the present invention, the vehicle terminal includes at least a TBOX telematics processor and an ECU electronic control unit. The TBOX telematics processor is responsible for sending the location information of the target vehicle to the cloud server and receiving vehicle search commands and verifying the root certificate of the vehicle search command and the signature chain of the remote control certificate. When the verification is successful, the vehicle search request is sent to the ECU electronic control unit. The ECU electronic control unit is responsible for controlling the vehicle to perform operations such as flashing lights and honking the horn. The TBOX telematics processor and the ECU electronic control unit interact with each other to perform vehicle search commands.
[0141] As the system implementation is basically similar to the method implementation, it is described in a relatively simple way. For relevant details, please refer to the description of the method implementation.
[0142] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.
[0143] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the present invention.
[0144] Finally, it should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation portals are provided for users to choose to authorize or refuse.
[0145] It should also be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.
[0146] The present invention has provided a detailed description of a vehicle location method and a vehicle location system. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A vehicle location method, characterized in that, Applied to cloud servers, the method includes: Obtain account application information from the account application platform; the application information includes at least the account applicant's employment status and the type of account usage; The vehicle search permissions for the account are set according to the application information, including: obtaining the applicant's employment status in real time based on the account application terminal, and / or determining the corresponding vehicle search permissions based on the account usage type. Obtain the vehicle identification number (VIN) of the target vehicle to be queried by the current client account, and verify the vehicle search permission of the current client account based on the VIN. If the permission verification passes, send the location information request of the target vehicle corresponding to the VIN to the vehicle terminal, so that the vehicle terminal sends the location information of the target vehicle to the cloud server according to the location information request. The location information of the target vehicle is sent to the client. Upon receiving the encrypted vehicle search command from the client, the client performs a secondary permission verification on the vehicle search permission of the current account based on the vehicle identification number. If the secondary permission verification passes, the vehicle search command is transmitted to the vehicle terminal, so that the vehicle terminal performs certificate verification on the vehicle search command. If the certificate verification passes, the vehicle search command is executed.
2. The method according to claim 1, characterized in that, The vehicle search permissions include at least: first vehicle search permission, second vehicle search permission, and no vehicle search permission; The step of setting the vehicle search permissions corresponding to the account based on the application information includes: If the personnel information in the application meets the application conditions and the usage type of the application information is within a preset range, the account has the first vehicle search permission; If the personnel information in the application meets the application conditions and the usage type of the application information is outside the preset range, the account has the second vehicle search permission; If the applicant's personal information does not meet the application requirements, the account does not have vehicle search privileges.
3. The method according to claim 1, characterized in that, Before obtaining the vehicle identification number (VIN) of the target vehicle to be queried by the client's current account, the method further includes: Upon receiving a remote control certificate application instruction sent by the client, the remote control certificate is generated and sent to the client.
4. The method according to claim 3, characterized in that, The cloud server includes at least: a vehicle networking service platform and a certificate management platform; The step of generating the remote control certificate and sending it to the client upon receiving the remote control certificate application instruction sent by the client includes: When the vehicle network service platform receives a remote control certificate application instruction sent by the client, it transmits the remote control certificate application instruction to the certificate management platform. The certificate management platform generates a remote control certificate and sends it to the vehicle network service platform; The vehicle networking service platform issues the remote control certificate to the client.
5. The method according to claim 1, characterized in that, The cloud service includes at least: a vehicle networking service platform and a production and sales platform; The process includes obtaining the vehicle identification number (VIN) of the target vehicle to be queried by the current client account, verifying the vehicle search permission of the current client account based on the VIN, and if the permission verification passes, sending a location information request for the target vehicle corresponding to the VIN to the vehicle terminal. Obtain the vehicle identification number (VIN) of the target vehicle that the current client account needs to query; The production and sales platform determines the production and sales status of the target vehicle based on the vehicle identification number of the target vehicle; The vehicle networking service platform verifies the vehicle search permission of the client's current account based on the production and sales status of the target vehicle. If the permission verification passes, the platform sends a request for the location information of the target vehicle corresponding to the vehicle identification number to the in-vehicle terminal.
6. The method according to claim 5, characterized in that, The production and sales status includes: sold, received but not shipped, and received but shipped. The vehicle networking service platform verifies the vehicle search permission of the client's current account based on the production and sales status of the target vehicle, including: If the target vehicle is in the state of having been sold, the authorization verification fails. If the target vehicle's production and sales status is "in stock - not shipped" and the account has the first vehicle search permission, the permission verification passes. If the target vehicle's production and sales status is "in stock - shipped" and the account has the second vehicle search permission, the permission verification will pass.
7. The method according to claim 1, characterized in that, Upon receiving the encrypted vehicle-finding command from the client, the method involves performing a secondary permission verification on the client's current account's vehicle-finding permissions based on the vehicle identification number. If the secondary permission verification passes, the vehicle-finding command is transmitted to the vehicle terminal. This includes: If the target vehicle's production and sales status is "in stock - not shipped" and the account has the first vehicle search permission, the permission verification passes and the encrypted vehicle search command is transmitted to the vehicle terminal.
8. A vehicle location method, characterized in that, Applied to a client, the method includes: The application information is sent to the account application terminal; the account application terminal generates an account and password based on the application information; the application information includes at least the account applicant's employment status and the type of account usage; Log in to apply for an account and check if a remote control certificate exists. If the remote control certificate exists, enter the vehicle identification number of the target vehicle to obtain the location information of the target vehicle. If the remote control certificate does not exist, send a remote control certificate application command to the cloud server and obtain the remote control certificate. Based on the location information of the target vehicle, a vehicle search command is sent to the cloud server. The cloud server performs permission verification. If the permission verification is successful, the vehicle search command is sent to the vehicle terminal. This includes: obtaining the applicant's employment status in real time based on the account application terminal, and / or determining the corresponding vehicle search permission based on the account usage type.
9. A vehicle location method, characterized in that, Applied to vehicle-mounted terminals, the method includes: A request to obtain the location information of the target vehicle is made, and the location information of the target vehicle is sent to the cloud server. The location information request is based on the production and sales status of the target vehicle and the current account's vehicle search permission. After the permission is verified, a location information request that meets the permission requirements is received. The vehicle search permission is determined based on the applicant's employment status and / or the account usage type obtained in real time from the account application terminal. Obtain the vehicle search command, verify the signature chain of the root certificate and remote control certificate of the vehicle search command, and execute the vehicle search command if the verification passes.
10. A vehicle location system, characterized in that, The system includes: The cloud server is used to execute the steps of the vehicle location method according to any one of claims 1-7; The client is used to execute the steps of the vehicle location method as described in claim 8; The vehicle terminal is used to perform the steps of the vehicle location method as described in claim 9.
Citation Information
Patent Citations
Method for positioning rental vehicle
CN109598921A
Vehicle certificate management method, device and system based on vehicle recognition code
CN113315738A
Remote vehicle searching method based on cloud computing and related device
CN113763745A