A method, system, and vehicle for key pairing binding

By embedding a pre-made key into the key and obtaining a target key from the cloud for key-key pairing and binding, combined with communication authentication and key verification, the problem of insufficient key binding security in existing technologies is solved, and the pairing security of key and key controller is improved.

CN119131937BActive Publication Date: 2026-03-17CHONGQING JINKANG NEW ENERGY VEHICLE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-29
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

The existing pairing and binding methods for keys and key controllers have security issues. Illegal diagnostic tools can forge keys, resulting in unreliable counterfeit keys and increasing the risk of car theft.

Method used

The first pre-made key is loaded into the security chip of the key, and the target key is obtained from the cloud key system through the key's identification information. The key and the key controller are paired and bound together. Combined with communication authentication and key verification, the legitimacy of the key controller is ensured.

Benefits of technology

This enhances the security of key-key pairing and binding. Even if the supplier leaks the pre-made key, legitimate pairing and binding cannot be performed, preventing the creation of counterfeit keys and improving vehicle security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119131937B_ABST
    Figure CN119131937B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a key pairing binding method, system and vehicle, the method comprising: filling a first pre-made key into a security chip of a key; based on the first pre-made key in the key and a target key in a key controller, pairing and binding with the key controller; the target key is a key corresponding to the identification information of the key, which is obtained from a cloud key system and written into the key controller. The purpose is to improve the security of pairing and binding between the key and the key controller.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of key pairing technology, specifically to a method, system, and vehicle for key pairing and binding. Background Technology

[0002] Currently, the pairing and binding method between the vehicle key and the key controller inside the vehicle mainly involves the key controller having a pre-key pre-installed into a security chip at the supplier's location. At the vehicle factory, a diagnostic tool triggers the key controller to enter pairing and binding mode via the OBD interface. The key controller derives a random key from the pre-key and VIN, and transmits this random key to the key via short-range communication, thus successfully binding the key. This pairing and binding method has two main problems: After the vehicle leaves the factory, criminals can use an unauthorized diagnostic tool to trigger the key pairing and binding command via the OBD interface, or directly simulate a key pairing and binding command from the key controller's input port. In this case, the key controller will send out the key via short-range communication, which can be received by any counterfeit key terminal. Once the key is received, a counterfeit key can be forged. Because the pre-key needs to be pre-installed in the key controller by the supplier, this pre-key is not managed by the vehicle factory. If the supplier inadvertently leaks the key, a large number of counterfeit keys can easily appear on the market. The quality of counterfeit keys cannot be guaranteed, and this also increases the risk of car theft. Summary of the Invention

[0003] In view of this, embodiments of this application provide a method, system, and vehicle for key pairing and binding. The aim is to improve the security of pairing and binding between the key and the key controller.

[0004] The first aspect of this application provides a key pairing and binding method, applied to keys, the method comprising:

[0005] Fill the security chip of the key with the first pre-made key;

[0006] Based on the first pre-made key in the key and the target key in the key controller, it is paired and bound with the key controller; the target key is a key corresponding to the identification information obtained from the cloud key system and written into the key controller based on the identification information of the key.

[0007] Optionally, pairing and binding with the key controller based on a first pre-made key in the key and a target key in the key controller includes:

[0008] Based on the first pre-made key in the key and the second pre-made key in the key controller, communication authentication is performed with the key controller; the second pre-made key in the key controller is a key corresponding to the identification information obtained and written by the key controller from the cloud key system based on the key's identification information.

[0009] If the communication authentication is successful, the target key sent by the key controller will be received;

[0010] The target key sent by the key controller is verified based on its own first pre-made key;

[0011] If the verification is successful, it will be paired and bound with the key controller.

[0012] Optionally, communication authentication with the key controller is performed based on a first pre-made key in the key and a second pre-made key in the key controller, including:

[0013] Based on the first pre-made key in the key, a second Bluetooth pairing code and a second root key of the target security protocol are derived through a derivation algorithm.

[0014] If the first Bluetooth pairing code and the second Bluetooth pairing code are successfully paired and the first root key and the second root key are successfully authenticated, the communication authentication is confirmed to be successful; wherein, the first Bluetooth pairing code and the first root key of the target security protocol are derived by the key controller based on its own second pre-made key through a derivation algorithm.

[0015] Optionally, the legitimacy of the target key sent by the key controller is verified based on its own first pre-made key, including:

[0016] The verification bit key of the first pre-made key in the key is compared with the verification bit key of the received target key to obtain the comparison result;

[0017] If the comparison result shows that the verification bit key of the first pre-made key is the same as the verification bit key of the received target key, the verification passes.

[0018] If the comparison result shows that the verification bit key of the first pre-made key is different from the verification bit key of the received target key, the verification fails.

[0019] Optionally, upon successful verification, pairing and binding with the key controller includes:

[0020] If the verification passes, disconnect the connection with the key controller and derive the fourth Bluetooth pairing code and the fourth root key of the target security protocol based on the target key in the key through a derivation algorithm;

[0021] If the third Bluetooth pairing code and the fourth Bluetooth pairing code are successfully paired and the third root key and the fourth root key are successfully authenticated, the device will be paired and bound to the key controller. The third Bluetooth pairing code and the third root key of the target security protocol are derived by the key controller based on its own target key through a derivation algorithm.

[0022] Optionally, the method further includes:

[0023] Once pairing and binding are complete, the control command is encrypted based on the target key in the key and sent to the key controller, so that the key controller can decrypt the control command based on its own target key and execute the corresponding control operation.

[0024] Optionally, the method further includes:

[0025] Once the key and the key controller have been paired and bound, the first pre-made key in the key is deleted.

[0026] Optionally, if the keys written into the key controller are a second pre-made key and a target key, the method further includes:

[0027] When the key and the key controller are paired and bound, the first pre-made key is deleted, and the key controller is controlled to delete the second pre-made key in the key controller.

[0028] A second aspect of this application provides a key pairing and binding method applied to a key controller, the method comprising:

[0029] Obtain the target key corresponding to the key's identification information in the cloud key system;

[0030] Write the target key;

[0031] Based on the first pre-made key in the key and the target key in the key controller, the key is paired and bound together. The first pre-made key is a key that is pre-filled into the security chip of the key.

[0032] Optionally, obtain the target key corresponding to the key's identification information in the cloud key system, including:

[0033] Receive the broadcast signal from the key and obtain the key's identification information;

[0034] Based on the identification information, obtain the target key corresponding to the identification information in the cloud key system.

[0035] Optionally, obtain the target key corresponding to the key's identification information in the cloud key system, including:

[0036] Receive a target key obtained from the cloud key system by a terminal device; the terminal device is a device that can obtain the identification information of the key and can establish communication with the cloud key system.

[0037] Optionally, the method further includes:

[0038] Obtain the second pre-made key corresponding to the identification information in the cloud key system;

[0039] Write the second pre-made key;

[0040] The pairing and binding of the key with the first pre-made key in the key and the target key in the key controller includes:

[0041] Based on the first pre-made key in the key and the second pre-made key in the key controller, communication authentication is performed with the key;

[0042] If the communication authentication is successful, the target key is sent to the key;

[0043] In response to the result that the key passes the validity verification of the target key based on its own first pre-made key, it is paired and bound with the key.

[0044] Optionally, communication authentication with the key is performed based on a first pre-made key in the key and a second pre-made key in the key controller, including:

[0045] Based on the second pre-made key in the key controller, the first Bluetooth pairing code and the first root key of the target security protocol are derived through a derivation algorithm;

[0046] If the first Bluetooth pairing code and the second Bluetooth pairing code are successfully paired and the first root key and the second root key are successfully authenticated, the communication authentication is confirmed to be successful; wherein, the second Bluetooth pairing code and the second root key of the target security protocol are derived by the key based on its own first pre-made key through a derivation algorithm.

[0047] Optionally, in response to the result that the key passes the validity verification of the target key based on its own first pre-made key, pairing and binding with the key includes:

[0048] In response to the result of the key passing the validity verification of the target key based on its own first pre-made key and the key disconnecting the connection, a third Bluetooth pairing code and a third root key of the target security protocol are derived based on the target key through a derivation algorithm;

[0049] If the third Bluetooth pairing code and the fourth Bluetooth pairing code are successfully paired and the third root key and the fourth root key are successfully authenticated, they are paired and bound to the key; wherein, the fourth Bluetooth pairing code and the fourth root key of the target security protocol are derived by the key based on the received target key through a derivation algorithm.

[0050] Optionally, the method further includes:

[0051] Once pairing and binding are complete, receive control commands encrypted by the key based on the target key;

[0052] After decrypting the control command based on its own target key, the corresponding control operation is executed.

[0053] Optionally, the method further includes:

[0054] Once the key and the key controller have completed pairing and binding, the control key deletes the first pre-made key from the key.

[0055] Optionally, if the keys written into the key controller are a second pre-made key and a target key, the method further includes:

[0056] Once the key and the key controller have completed pairing and binding, the second pre-made key is deleted, and the control key deletes the first pre-made key from the key.

[0057] A third aspect of this application provides a key pairing and binding system for keys, the system comprising:

[0058] A security chip is used to pack the first pre-made key;

[0059] The pairing and binding module is used to pair and bind with the key controller based on the first pre-made key in the key and the target key in the key controller; the target key is a key corresponding to the identification information obtained from the cloud key system and written into the key controller based on the identification information of the key.

[0060] A fourth aspect of this application provides a key pairing and binding system applied to a key controller, the system comprising:

[0061] The data acquisition module is used to acquire the target key corresponding to the key's identification information in the cloud key system;

[0062] A security chip is used to write the target key;

[0063] The pairing and binding module is used to pair and bind the key with the key based on a first pre-installed key in the key and a target key in the key controller. The first pre-installed key is a key that has been pre-filled into the security chip of the key.

[0064] The fifth aspect of this application provides a vehicle in which the key of the vehicle is paired and bound based on a key pairing and binding method described in the first aspect of this application, or the key controller of the vehicle is paired and bound based on a key pairing and binding method described in the second aspect of this application.

[0065] A sixth aspect of this application provides an electronic device, including: a processor, a memory, and a computer program stored in the memory and running on the processor. When the computer program is executed by the processor, it implements the steps of a key pairing and binding method as described in the first aspect of this application, or when the computer program is executed by the processor, it implements the steps of a key pairing and binding method as described in the second aspect of this application.

[0066] A seventh aspect of this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of a key pairing and binding method as described in the first aspect of this application, or when executed by the processor, implements the steps of a key pairing and binding method as described in the second aspect of this application.

[0067] The key pairing and binding method provided in this application has the following advantages:

[0068] This application provides a key pairing and binding method applied to keys. First, a first pre-made key is injected into the key's security chip. Based on the first pre-made key in the key and a target key in the key controller, the key is paired and bound to the key controller. The target key is a key corresponding to the identification information obtained from a cloud key system and written into the key controller based on the key's identification information. Therefore, a first pre-made key is first injected into the key. This first pre-made key is given to the supplier for key generation. Then, the vehicle manufacturer establishes a mapping relationship between the key's identification information and the first pre-made key. When pairing the key and the key controller, a legitimate diagnostic tool that can access the cloud key system obtains the target key corresponding to the identification information from the cloud key system based on the key's identification information. This target key is then written into the vehicle's key controller. When pairing and binding the key and the key controller, the target key of the key controller is verified based on the first pre-made key of the key. If the verification is successful, the key and the key controller are bound. In this way, even if the supplier leaks the first pre-made key in the key, they cannot obtain a legitimate target key for pairing and binding, thus effectively improving the security of pairing and binding the key and the key controller. Attached Figure Description

[0069] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments of this application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0070] Figure 1 A flowchart illustrating a key pairing and binding method according to one embodiment of this application;

[0071] Figure 2 This is another flowchart illustrating a key pairing and binding method according to one embodiment of this application;

[0072] Figure 3 This is a flowchart illustrating a key pairing and binding method based on a diagnostic instrument, as shown in one embodiment of this application.

[0073] Figure 4 This is a schematic diagram illustrating a key pairing and binding system according to one embodiment of this application. Detailed Implementation

[0074] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0075] refer to Figure 1 , Figure 1 This is a schematic diagram illustrating a key pairing and binding method according to one embodiment of this application. Figure 1 As shown, this application provides a key pairing and binding method, applied to keys, including:

[0076] Step S1: Fill the first pre-made key into the key's security chip.

[0077] In this embodiment, the vehicle manufacturer first pre-creates a large number of first pre-built keys, each unique and non-repeating. Simultaneously, the vehicle manufacturer creates a corresponding target key for each first pre-built key, each also unique and non-repeating. These first pre-built keys and target keys are stored in a cloud-based key system controlled by the vehicle manufacturer, in a one-to-one correspondence. For the supplier that produces keys for the vehicle manufacturer, the vehicle manufacturer provides the supplier with the created first pre-built keys for key production. Specifically, for each key produced, a unique first pre-built key is programmed into the key's security chip; different keys are programmed with different first pre-built keys. Each key has unique identification information, and the identification information of a corresponding key corresponds to a unique first pre-built key. The supplier then provides this correspondence between the key's identification information and the first pre-built key to the vehicle manufacturer, who records it in the cloud-based key system.

[0078] For example, a large number of first pre-made keys PK1 to PKn are pre-created, and a corresponding target key is created for each first pre-made key, resulting in n target keys K, where each target key Ki corresponds to a first pre-made key PKI, and i takes the value of a positive integer from 1 to n. All the created first pre-made keys are given to the supplier, and the j-th key among the m keys produced has a unique identifier IDj, where j takes the value of a positive integer from 1 to m. For the j-th key produced, the first pre-made key PKj is loaded into the security chip of the j-th key, and then the correspondence between the key's identifier IDj and the first pre-made key PKj is given to the vehicle manufacturer.

[0079] Step S2: Based on the first pre-made key in the key and the target key in the key controller, pair and bind with the key controller; the target key is a key corresponding to the identification information obtained from the cloud key system and written into the key controller based on the key's identification information.

[0080] In this embodiment, upon obtaining any key and pairing it with the key controller at the key control terminal, an engineer scans the key using a legitimate diagnostic tool with access to the cloud key system to determine its identification information. Based on this identification information, the engineer then accesses the cloud key system to determine the target key corresponding to that identification information. The cloud key system records the correspondence between the key's identification information, a first pre-built key, and the target key. The legitimate diagnostic tool then writes the target key into the key controller at the key control terminal via the OBD interface. The key control terminal includes, but is not limited to, the vehicle itself; unauthorized diagnostic tools not provided by the vehicle manufacturer will not have access to the cloud key system. In another embodiment, the key controller receives the key's broadcast signal to obtain its identification information. The key controller then directly retrieves the target key corresponding to that identification information from the cloud key system and writes the target key into the key controller.

[0081] For example, continuing with the example in step S1 above, for a key with identification information ID2, based on the correspondence between the key's identification information and the first pre-made key in the cloud key system, the first pre-made key corresponding to the key's identification information ID2 in the cloud key system is determined to be PK2. Then, based on the determined first pre-made key PK2, the target key K2 corresponding to the first pre-made key PK2 in the cloud key system is determined. Then, the legitimate diagnostic instrument writes the target key K2 into the security chip of the key controller at the key control end through the OBD interface.

[0082] In this embodiment, after the target key is written into the key controller, the target key in its own security chip is sent to the key through the key controller. The key determines whether the received target key is the target key corresponding to its own first pre-set key in the cloud key system based on its own first pre-set key. If it is determined that the received target key is the target key corresponding to its own first pre-set key in the cloud key system, the key controller is determined to be legitimate. Based on the first pre-set key in the key and the target key in the key controller, the key and the key controller are paired and bound.

[0083] This application provides a key pairing and binding method applied to keys. First, a first pre-made key is injected into the key's security chip. Based on the first pre-made key in the key and a target key in the key controller, the key is paired and bound to the key controller. The target key is a key corresponding to the identification information obtained from a cloud key system and written into the key controller based on the key's identification information. Therefore, a first pre-made key is first injected into the key. This first pre-made key is given to the supplier for key generation. Then, the vehicle manufacturer establishes a mapping relationship between the key's identification information and the first pre-made key. When pairing the key and the key controller, a legitimate diagnostic tool that can access the cloud key system obtains the target key corresponding to the identification information from the cloud key system based on the key's identification information. This target key is then written into the vehicle's key controller. When pairing and binding the key and the key controller, the target key of the key controller is verified based on the first pre-made key of the key. If the verification is successful, the key and the key controller are bound. In this way, even if the supplier leaks the first pre-made key in the key, they cannot obtain a legitimate target key for pairing and binding, thus effectively improving the security of pairing and binding the key and the key controller.

[0084] In conjunction with the above embodiments, in one implementation, this application also provides a key pairing and binding method. In this key pairing and binding method, step S2 may include steps S21 to S24:

[0085] Step S21: Based on the first pre-made key in the key and the second pre-made key in the key controller, perform communication authentication with the key controller; the second pre-made key in the key controller is a key corresponding to the identification information obtained and written by the key controller from the cloud key system based on the key's identification information.

[0086] In this embodiment, to ensure the security of transmitting the target key used for pairing and binding the key and the key controller, this application first verifies the legitimacy of the key controller before transmitting the target key to the key. Specifically: as follows... Figure 2As shown, based on the key's identification information, while obtaining the target key corresponding to the identification information in the cloud key system, a second pre-made key corresponding to the identification information is also obtained. If the key controller obtains the second pre-made key from the cloud key system in a correct and legal manner, the obtained second pre-made key is actually the first pre-made key corresponding to that key in the cloud key system. Then, the second pre-made key is written to the key controller. For example, if the identification information of the second key is ID2 and the first pre-made key of the second key is PK2, the correspondence between the identification information ID2 and the first pre-made key PK2 is given to the vehicle manufacturer. The vehicle manufacturer then adds a target key K2 to this correspondence and stores the uniquely determined correspondence between the identification information ID2, the first pre-made key PK2, and the target key K2 in the cloud key system. When the key controller obtains the corresponding second pre-made key from the cloud key system based on the identification information ID2 of the second key in a correct and legal manner, this second pre-made key is actually the first pre-made key PK2.

[0087] In this embodiment, if the first pre-made key in the key and the second pre-made key in the key controller are the same, the communication authentication between the key and the key controller is confirmed to be successful. If the communication authentication fails under different circumstances, the key will not receive the target key from the key controller, and the subsequent binding and pairing will not be performed. This process also ensures the security of the pairing and binding between the key and the key controller to a certain extent.

[0088] Step S22: If the communication authentication is successful, receive the target key sent by the key controller.

[0089] In this embodiment, after the key-to-key controller communication authentication is successful, the target key sent by the key controller is received.

[0090] Step S23: Verify the legitimacy of the target key sent by the key controller based on its own first pre-made key.

[0091] In this embodiment, after the key receives the target key sent by the key controller, the key determines whether the received target key is the same as its own pre-made key in the cloud key system. If the key determines that the received target key is the same as its own pre-made key in the cloud key system, the key controller is deemed to be legitimate.

[0092] Step S24: If the verification is successful, pair and bind with the key controller.

[0093] In this embodiment, if the key controller corresponding to the target key is found to be legitimate, the verification is confirmed to be successful. At this time, the key and the key controller are paired and bound based on the first pre-made key in the key and the target key in the key controller.

[0094] In conjunction with the above embodiments, in one implementation, this application also provides a key pairing and binding method. In this key pairing and binding method, step S21 may include steps S211 to S212:

[0095] Step S211: Based on the first pre-made key in the key, derive the second Bluetooth pairing code and the second root key of the target security protocol through a derivation algorithm.

[0096] In this embodiment, the key derives a second Bluetooth pairing code and a second root key for the target security protocol at the application layer from a first pre-built key in its own security chip using a derivation algorithm. The target security protocol is preferably the ICCE protocol (Intelligent Connected Car Ecosystem Alliance).

[0097] Step S212: If the first Bluetooth pairing code and the second Bluetooth pairing code are successfully paired and the first root key and the second root key are successfully authenticated, the communication authentication is confirmed to be successful; wherein, the first Bluetooth pairing code and the first root key of the target security protocol are derived by the key controller based on its own second pre-made key through a derivation algorithm.

[0098] In this embodiment, the key controller derives a first Bluetooth pairing code and a first root key for the target security protocol at the application layer using the same derivation algorithm based on the second pre-built key in its own security chip. After deriving the first Bluetooth pairing code, the first root key, the second Bluetooth pairing code, and the second root key, if the first Bluetooth pairing code derived from the second pre-built key in the key controller matches the second Bluetooth pairing code derived from the first pre-built key in the key, and the first root key derived from the second pre-built key in the key controller matches the second root key derived from the first pre-built key in the key, then the key and the key controller will be successfully authenticated.

[0099] In conjunction with the above embodiments, in one implementation, this application also provides a key pairing and binding method. In this key pairing and binding method, step S23 may include steps S231 to S233:

[0100] Step S231: Compare the verification bit key of the first pre-made key in the key with the verification bit key of the received target key to obtain the comparison result.

[0101] In this embodiment, the vehicle manufacturer designates a preset length of data at a specified position in the first pre-built key as a verification sub-key. This verification sub-key is used to verify whether the target key received from the key controller is the same as the target key corresponding to the first pre-built key in the cloud key system. Simultaneously, the vehicle manufacturer designates a preset length of data at a specified position in the target key as a verification sub-key. The specified positions of the verification sub-key for the pre-built key and the verification sub-key for the target key can be the same or different. For example, if the specified position for the verification sub-key of the first pre-built key starts from the 50th position, and the specified position for the verification sub-key of the target key starts from the 70th position, then the two specified positions are different. Specifically, after the key receives the target key sent by the key controller, the key compares the verification sub-key of the first pre-built key in its own security chip with the verification sub-key of the received target key to obtain the corresponding comparison result.

[0102] Step S232: If the comparison result shows that the verification bit key of the first pre-made key is the same as the verification bit key of the received target key, the verification passes.

[0103] In this embodiment, after obtaining the corresponding comparison result through step S231, if the comparison result shows that the verification bit key of the first pre-made key of the key is the same as the verification bit key of the received target key, it is determined that the key controller corresponding to the target key has passed the verification, and the target key belongs to the target key corresponding to the first pre-made key in the cloud key system. At this time, the pairing and binding process is legal.

[0104] Step S233: If the comparison result shows that the verification bit key of the first pre-made key is different from the verification bit key of the received target key, the verification fails.

[0105] In this embodiment, after obtaining the corresponding comparison result through step S231, if the comparison result shows that the verification bit key of the first pre-made key of the key is different from the verification bit key of the received target key, it is determined that the key controller corresponding to the target key fails the verification, and the target key does not belong to the target key corresponding to the first pre-made key in the cloud key system. At this time, the pairing and binding process is illegal, and the pairing and binding of the key and the key controller is refused.

[0106] In conjunction with the above embodiments, in one implementation, this application also provides a key pairing and binding method. In this key pairing and binding method, step S24 may include steps S241 to S242:

[0107] Step S341: If the verification passes, disconnect the connection with the key controller and derive the fourth Bluetooth pairing code and the fourth root key of the target security protocol based on the target key in the key through a derivation algorithm.

[0108] In this embodiment, if the target key received by the key pair passes the verification, the received target key is stored in the security chip and the Bluetooth and application layer connections established with the key controller are disconnected.

[0109] In this embodiment, after the key disconnects from the Bluetooth and application layer of the key controller, the key derives a fourth Bluetooth pairing code and a fourth root key of the target security protocol at the application layer based on the target key in its own security chip through a derivation algorithm.

[0110] Step S242: If the third Bluetooth pairing code and the fourth Bluetooth pairing code are successfully paired and the third root key and the fourth root key are successfully authenticated, pair and bind with the key controller; wherein, the third Bluetooth pairing code and the third root key of the target security protocol are derived by the key controller based on its own target key through a derivation algorithm.

[0111] In this embodiment, the key controller derives a third Bluetooth pairing code and a third root key for the application-layer target security protocol based on the target key in its own security chip using the same derivation algorithm. If the third Bluetooth pairing code derived from the target key in the key controller matches the fourth Bluetooth pairing code derived from the target key in the key, and the fourth root key derived from the target key in the key matches the fourth root key derived from the target key in the key, the key and key controller will be authenticated, and then paired and bound. The paired key can then be used to control the corresponding key control terminal of the key controller.

[0112] In conjunction with the above embodiments, in one implementation, this application also provides a key pairing and binding method. This key pairing and binding method further includes: upon completion of pairing and binding, encrypting a control command based on a target key in the key and sending it to a key controller, so that the key controller can decrypt the control command based on its own target key and execute the corresponding control operation.

[0113] In this embodiment, when the key and the key controller are paired and bound, based on the user's selection operation on the key, the key encrypts the control command corresponding to the selection operation based on the target key and sends it to the paired and bound key controller.

[0114] In this embodiment, the key controller decrypts the control command based on the target key and then executes the control operation corresponding to the control command.

[0115] In conjunction with the above embodiments, in one implementation, this application also provides a key pairing and binding method. In this key pairing and binding method, when the key written into the key controller is a target key, the method further includes: deleting a first pre-made key from the key after the key and the key controller have completed pairing and binding.

[0116] In this embodiment, in the implementation of directly sending the target key, the key controller will not obtain the second pre-made key corresponding to the key's identification information from the cloud key system. For this implementation, in order to ensure the security of key and key controller pairing and binding, when the key and key controller have completed pairing and binding, the first pre-made key in the key is directly deleted, so that the paired and bound key will no longer have the first pre-made key, and thus cannot be paired and bound again. It is necessary to return to the factory to refill the first pre-made key before a new pairing and binding can be performed on the key again, thereby ensuring the security of pairing and binding.

[0117] In conjunction with the above embodiments, in one implementation, this application also provides a key pairing and binding method. In this key pairing and binding method, when the keys written into the key controller are a second pre-made key and a target key, the method further includes: deleting the first pre-made key and controlling the key controller to delete the second pre-made key from the key controller after the key and the key controller have completed pairing and binding.

[0118] In this embodiment, where communication authentication is required before sending the target key, a second pre-made key corresponding to the key is obtained from the cloud key system and given to the key controller. To ensure the security of key-key and key controller pairing, once pairing is complete, the first pre-made key in the key and the second pre-made key in the key controller are directly deleted. This prevents the paired key from having any pre-made keys and thus makes pairing impossible. The key must be returned to the factory to have the first pre-made key refilled before a new pairing can be performed, thereby ensuring the security of the pairing.

[0119] Based on the same inventive concept, one embodiment of this application provides a key pairing and binding method, which is applied to a key controller and includes:

[0120] Step S101: Obtain the target key corresponding to the key's identification information in the cloud key system, and write the target key.

[0121] In this embodiment, upon obtaining any key and pairing it with the key controller at the key control terminal, the system retrieves the target key corresponding to the key's identification information from the cloud key system and writes the target key into the key controller. The key control terminal includes, but is not limited to, vehicles; unauthorized diagnostic tools not provided by vehicle manufacturers will not have access to the cloud key system.

[0122] Step S102: Based on the first pre-made key in the key and the target key in the key controller, pair and bind the key. The first pre-made key is a key that has been pre-filled into the security chip of the key.

[0123] In this embodiment, the vehicle manufacturer first pre-creates a large number of first pre-built keys, each unique and non-repeating. Simultaneously, the vehicle manufacturer creates a corresponding target key for each first pre-built key, each also unique and non-repeating. These first pre-built keys and target keys are stored in a cloud-based key system controlled by the vehicle manufacturer, in a one-to-one correspondence. For the supplier that produces keys for the vehicle manufacturer, the vehicle manufacturer provides the supplier with the created first pre-built keys for key production. Specifically, for each key produced, a unique first pre-built key is programmed into the key's security chip; different keys are programmed with different first pre-built keys. Each key has unique identification information, and the identification information of a corresponding key corresponds to a unique first pre-built key. The supplier then provides this correspondence between the key's identification information and the first pre-built key to the vehicle manufacturer, who records it in the cloud-based key system.

[0124] In this embodiment, after the target key is written into the key controller, the target key in its own security chip is sent to the key through the key controller. The key determines whether the received target key is the target key corresponding to its own first pre-set key in the cloud key system based on its own first pre-set key. If it is determined that the received target key is the target key corresponding to its own first pre-set key in the cloud key system, the key controller is determined to be legitimate. Based on the first pre-set key in the key and the target key in the key controller, the key and the key controller are paired and bound.

[0125] In conjunction with the above embodiments, in one implementation, this application also provides a key pairing and binding method. In this key pairing and binding method, step S101 may include: receiving a broadcast signal from a key to obtain key identification information; and based on the identification information, obtaining a target key corresponding to the identification information in a cloud key system.

[0126] In this embodiment, as Figure 3 As shown, the key broadcasts its own identification information, which is directly received by the key controller. Based on this broadcast signal, the key's identification information is determined. The key controller then retrieves the corresponding target key from the key cloud system based on this identification information. This target key is written into the key controller's security chip. The key cloud system records the correspondence between the key's identification information, the first pre-built key, and the target key.

[0127] In conjunction with the above embodiments, in one implementation, this application also provides a key pairing and binding method. In this key pairing and binding method, step S101 may include: receiving a target key obtained from the cloud key system by a terminal device; the terminal device is a device capable of obtaining the key's identification information and establishing communication with the cloud key system.

[0128] In this embodiment, in another implementation, an engineer scans the key using a terminal device that can access the cloud key system to determine the key's identification information. Based on this identification information, the engineer then determines the target key corresponding to the identification information by accessing the cloud key system. The cloud key system records the correspondence between the key's identification information, a first pre-built key, and the target key. The terminal device then writes the target key into the key controller of the key control terminal. This terminal device includes, but is not limited to, a diagnostic tool that can legally access the cloud key system. The diagnostic tool writes the target key into the key controller of the key control terminal via the OBD interface. The key control terminal includes, but is not limited to, the vehicle itself; unauthorized diagnostic tools not provided by the vehicle manufacturer will not have permission to access the cloud key system.

[0129] In conjunction with the above embodiments, in one implementation, this application also provides a key pairing and binding method. This key pairing and binding method further includes step S0101: obtaining a second pre-made key corresponding to the identification information in a cloud key system, and writing the second pre-made key.

[0130] In this embodiment, to ensure the security of transmitting the target key used for pairing and binding the key and the key controller, this application first verifies the legitimacy of the key controller before transmitting the target key to the key. Specifically: as follows... Figure 2As shown, based on the key's identification information, while obtaining the target key corresponding to the identification information in the cloud key system, a second pre-made key corresponding to the identification information is also obtained. If the key controller obtains the second pre-made key from the cloud key system in a correct and legal manner, the obtained second pre-made key is actually the first pre-made key corresponding to that key in the cloud key system. Then, the second pre-made key is written to the key controller. For example, if the identification information of the second key is ID2 and the first pre-made key of the second key is PK2, the correspondence between the identification information ID2 and the first pre-made key PK2 is given to the vehicle manufacturer. The vehicle manufacturer then adds a target key K2 to this correspondence and stores the uniquely determined correspondence between the identification information ID2, the first pre-made key PK2, and the target key K2 in the cloud key system. When the key controller obtains the corresponding second pre-made key from the cloud key system based on the identification information ID2 of the second key in a correct and legal manner, this second pre-made key is actually the first pre-made key PK2.

[0131] The key pairing and binding method provided in this application further includes step S102, which may include: performing communication authentication with the key based on a first pre-made key in the key and a second pre-made key in the key controller; sending the target key to the key if the communication authentication is successful; and pairing and binding with the key in response to the result that the key passes the validity verification of the target key based on its own first pre-made key.

[0132] In this embodiment, if the first pre-made key in the key and the second pre-made key in the key controller are the same, the communication authentication between the key and the key controller is confirmed to be successful. In other cases, the communication authentication fails, and the key will not receive the target key from the key controller, thus preventing subsequent binding and pairing. This process, to some extent, ensures the security of the key and key controller pairing and binding. After the key successfully authenticates its communication with the key controller, the key controller sends the target key to the key. Upon receiving the target key from the key controller, the key determines whether the received target key is the same as its own pre-made key in the cloud key system. If the received target key is indeed the same as its own pre-made key in the cloud key system, the key controller is deemed legitimate. If the key controller corresponding to the target key is deemed legitimate, the verification is confirmed to be successful. At this point, the key and the key controller are paired and bound based on the first pre-made key in the key and the target key in the key controller.

[0133] In conjunction with the above embodiments, in one implementation, this application also provides a key pairing and binding method. In this key pairing and binding method, communication authentication is performed with the key based on a first pre-defined key in the key and a second pre-defined key in the key controller, including: deriving a first Bluetooth pairing code and a first root key of a target security protocol using a derivation algorithm based on the second pre-defined key in the key controller; determining that communication authentication is successful when the first Bluetooth pairing code and the second Bluetooth pairing code are successfully paired and the first root key and the second root key are authenticated successfully; wherein the second Bluetooth pairing code and the second root key of the target security protocol are derived by the key based on its own first pre-defined key using a derivation algorithm.

[0134] In this embodiment, the key derives a second Bluetooth pairing code and a second root key for the target security protocol at the application layer based on a first pre-built key in its own security chip using a derivation algorithm. The target security protocol is preferably the ICCE protocol (Intelligent Connected Car Ecosystem Alliance). The key controller derives a first Bluetooth pairing code and a first root key for the target security protocol at the application layer based on the second pre-built key in its own security chip using the same derivation algorithm. After deriving the first Bluetooth pairing code, the first root key, the second Bluetooth pairing code, and the second root key, if the first Bluetooth pairing code derived from the second pre-built key in the key controller matches the second Bluetooth pairing code derived from the first pre-built key in the key, and the first root key derived from the second pre-built key in the key controller matches the second root key derived from the first pre-built key in the key, then the key and key controller will successfully authenticate.

[0135] In conjunction with the above embodiments, in one implementation, this application also provides a key pairing and binding method. In this key pairing and binding method, in response to the result of the key passing the validity verification of the target key based on its own first pre-made key, pairing and binding with the key includes: in response to the result of the key passing the validity verification of the target key based on its own first pre-made key and the key disconnecting from the connection, deriving a third Bluetooth pairing code and a third root key of the target security protocol based on the target key using a derivation algorithm; and pairing and binding with the key if the third Bluetooth pairing code and the fourth Bluetooth pairing code are successfully paired and the third root key and the fourth root key are authenticated; wherein the fourth Bluetooth pairing code and the fourth root key of the target security protocol are obtained by the key based on the received target key using a derivation algorithm.

[0136] In this embodiment, if the key verifies the received target key, the received target key is stored in the security chip, and the Bluetooth and application layer connections established with the key controller are disconnected. After the key disconnects from the key controller's Bluetooth and application layer connections, the key, based on the target key in its own security chip, derives a fourth Bluetooth pairing code and a fourth root key for the target security protocol at the application layer using a derivation algorithm. The key controller, based on the target key in its own security chip, derives a third Bluetooth pairing code and a third root key for the target security protocol at the application layer using the same derivation algorithm. If the third Bluetooth pairing code derived from the target key in the key controller matches the fourth Bluetooth pairing code derived from the target key in the key, and the fourth root key derived from the target key in the key controller matches the fourth root key derived from the target key in the key, the key and key controller will be authenticated, and then paired and bound. The key that has completed pairing and binding can be used to control the key control terminal corresponding to the key controller.

[0137] In conjunction with the above embodiments, in one implementation, this application also provides a key pairing and binding method. This key pairing and binding method further includes: upon completion of pairing and binding, receiving a control command encrypted and sent by the key based on a target key; and decrypting the control command based on its own target key to execute a corresponding control operation.

[0138] In this embodiment, after the key and key controller are paired and bound, based on the user's selection operation on the key, the key encrypts the control command corresponding to the selection operation using the target key and sends it to the paired key controller. The key controller decrypts the control command using the target key and executes the control operation corresponding to the control command.

[0139] In conjunction with the above embodiments, in one implementation, this application also provides a key pairing and binding method. This key pairing and binding method further includes: when the key and the key controller have completed pairing and binding, controlling the key to delete a first pre-made key from the key.

[0140] In this embodiment, in the implementation of directly sending the target key, the key controller will not obtain the second pre-made key corresponding to the key's identification information from the cloud key system. For this implementation, in order to ensure the security of key and key controller pairing and binding, when the key and key controller have completed pairing and binding, the key is directly controlled to delete the first pre-made key from the key, so that the paired and bound key will no longer have the first pre-made key, and thus cannot be paired and bound again. It is necessary to return to the factory to refill the first pre-made key before a new pairing and binding can be performed on the key again, thereby ensuring the security of pairing and binding.

[0141] In conjunction with the above embodiments, in one implementation, this application also provides a key pairing and binding method. In this key pairing and binding method, when the keys written into the key controller are a second pre-made key and a target key, the method further includes: deleting the second pre-made key after the key and the key controller have completed pairing and binding, and controlling the key to delete the first pre-made key from the key.

[0142] In this embodiment, where communication authentication is required before sending the target key, a second pre-made key corresponding to the key is obtained from the cloud key system and given to the key controller. To ensure the security of key-key and key controller pairing, once pairing is complete, the first pre-made key in the key and the second pre-made key in the key controller are directly deleted. This prevents the paired key from having any pre-made keys and thus makes pairing impossible. The key must be returned to the factory to have the first pre-made key refilled before a new pairing can be performed, thereby ensuring the security of the pairing.

[0143] Based on the same inventive concept, one embodiment of this application provides a key pairing and binding system, applied to keys, such as... Figure 3 As shown, the system 400 includes:

[0144] Security chip 401 is used to fill the first pre-made key;

[0145] The pairing and binding module 402 is used to pair and bind with the key controller based on the first pre-made key in the key and the target key in the key controller; the target key is a key corresponding to the identification information obtained from the cloud key system and written into the key controller based on the identification information of the key.

[0146] Optionally, the pairing and binding module 402 includes:

[0147] The communication authentication module is used to perform communication authentication with the key controller based on a first pre-made key in the key and a second pre-made key in the key controller; the second pre-made key in the key controller is a key corresponding to the identification information obtained and written by the key controller from the cloud key system based on the identification information of the key.

[0148] A key receiving module is used to receive the target key sent by the key controller when communication authentication is successful;

[0149] The legitimacy verification module is used to verify the legitimacy of the target key sent by the key controller based on its own first pre-made key;

[0150] The pairing and binding submodule is used to pair and bind with the key controller if the verification is successful.

[0151] Optional, the communication authentication module includes:

[0152] The first derivation module is used to derive the second Bluetooth pairing code and the second root key of the target security protocol based on the first pre-made key in the key through a derivation algorithm;

[0153] The communication authentication submodule is used to determine that the communication authentication is successful when the first Bluetooth pairing code and the second Bluetooth pairing code are successfully paired and the first root key and the second root key are successfully authenticated; wherein, the first Bluetooth pairing code and the first root key of the target security protocol are derived by the key controller based on its own second pre-made key through a derivation algorithm.

[0154] Optional, a validity verification module, including:

[0155] The comparison module is used to compare the verification bit key of the first pre-made key in the key with the verification bit key of the received target key to obtain the comparison result;

[0156] The first legitimacy verification module is used to verify the validity if the comparison result shows that the verification bit key of the first pre-made key is the same as the verification bit key of the received target key.

[0157] The second legitimacy verification module is used to fail the verification if the comparison result shows that the verification bit key of the first pre-made key is different from the verification bit key of the received target key.

[0158] Optional, pairing and binding submodules, including:

[0159] The second derivation module is used to disconnect the connection with the key controller when the verification is successful, and derive the fourth Bluetooth pairing code and the fourth root key of the target security protocol based on the target key in the key through the derivation algorithm.

[0160] The first pairing and binding submodule is used to pair and bind with the key controller when the third Bluetooth pairing code and the fourth Bluetooth pairing code are successfully paired and the third root key and the fourth root key are successfully authenticated; wherein, the third Bluetooth pairing code and the third root key of the target security protocol are derived by the key controller based on its own target key through a derivation algorithm.

[0161] Optionally, the system 400 further includes:

[0162] The control command sending module is used to encrypt the control command based on the target key in the key and send it to the key controller after pairing and binding are completed, so that the key controller can decrypt the control command based on its own target key and execute the corresponding control operation.

[0163] Optionally, the system 400 further includes:

[0164] The first key deletion module is used to delete the first pre-made key from the key when the key and the key controller have been paired and bound.

[0165] Optionally, if the keys written into the key controller are a second pre-made key and a target key, the system 300 further includes:

[0166] The second key deletion module is used to delete the first pre-made key when the key and the key controller are paired and bound, and to control the key controller to delete the second pre-made key in the key controller.

[0167] Based on the same inventive concept, one embodiment of this application provides a key pairing and binding system applied to a key controller, the system comprising:

[0168] The data acquisition module is used to acquire the target key corresponding to the key's identification information in the cloud key system;

[0169] A security chip is used to write the target key;

[0170] The pairing and binding module is used to pair and bind the key with the key based on a first pre-installed key in the key and a target key in the key controller. The first pre-installed key is a key that has been pre-filled into the security chip of the key.

[0171] Optionally, the system further includes:

[0172] The key acquisition module is used to acquire the second pre-made key corresponding to the identification information in the cloud key system;

[0173] A security chip is used to write the second pre-made key;

[0174] The pairing and binding module includes:

[0175] A communication authentication module is used to perform communication authentication with the key based on a first pre-made key in the key and a second pre-made key in the key controller;

[0176] A key sending module is used to send the target key to the key when communication authentication is successful;

[0177] The pairing and binding submodule is used to pair and bind with the key in response to the result that the key passes the validity verification of the target key based on its own first pre-made key.

[0178] Optional, the communication authentication module includes:

[0179] The first derivation module is used to derive the first Bluetooth pairing code and the first root key of the target security protocol based on the second pre-made key in the key controller through a derivation algorithm;

[0180] The communication authentication submodule is used to determine that the communication authentication is successful when the first Bluetooth pairing code and the second Bluetooth pairing code are successfully paired and the first root key and the second root key are successfully authenticated; wherein, the second Bluetooth pairing code and the second root key of the target security protocol are derived by the key based on its own first pre-made key through a derivation algorithm.

[0181] Optional, pairing and binding submodules, including:

[0182] The second derivation module is used to derive a third Bluetooth pairing code and a third root key of the target security protocol based on the target key, in response to the result of the key passing the legality verification of the target key based on its own first pre-made key and the key disconnecting the connection.

[0183] The first pairing and binding submodule is used to pair and bind with the key when the third Bluetooth pairing code and the fourth Bluetooth pairing code are successfully paired and the third root key and the fourth root key are successfully authenticated; wherein, the fourth Bluetooth pairing code and the fourth root key of the target security protocol are derived by the key based on the received target key through a derivation algorithm.

[0184] Optionally, the system further includes:

[0185] The control command receiving module is used to receive control commands encrypted by the key based on the target key after pairing and binding are completed.

[0186] The control module is used to decrypt the control command based on its own target key and then execute the corresponding control operation.

[0187] Optionally, the system further includes:

[0188] The first deletion module is used to control the key to delete the first pre-made key from the key when the key and the key controller have completed pairing and binding.

[0189] Optionally, if the keys written into the key controller are a second pre-made key and a target key, the system further includes:

[0190] The second deletion module is used to delete the second pre-made key when the key and the key controller have completed pairing and binding, and to control the key to delete the first pre-made key in the key.

[0191] Based on the same inventive concept, one embodiment of this application provides a vehicle in which the key of the vehicle is paired and bound according to a key pairing and binding method described in the first aspect of this application, or the key controller of the vehicle is paired and bound according to a key pairing and binding method described in the second aspect of this application.

[0192] Based on the same inventive concept, one embodiment of this application provides an electronic device, including: a processor, a memory, and a computer program stored in the memory and running on the processor. When the computer program is executed by the processor, it implements the steps of a key pairing and binding method as described in the first aspect of this application, or when the computer program is executed by the processor, it implements the steps of a key pairing and binding method as described in the second aspect of this application.

[0193] Based on the same inventive concept, one embodiment of this application provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the steps of a key pairing and binding method as described in the first aspect of this application, or when the computer program is executed by the processor, it implements the steps of a key pairing and binding method as described in the second aspect of this application.

[0194] As the system implementation is basically similar to the method implementation, it is described in a relatively simple way. For relevant details, please refer to the description of the system implementation.

[0195] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of this application are not limited to the described order of actions, because according to the embodiments of this application, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also understand that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily necessary for the embodiments of this application.

[0196] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0197] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, embodiments of this application can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of this application can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0198] This application describes embodiments with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0199] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0200] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0201] Although preferred embodiments of the present application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present application.

[0202] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.

[0203] The above provides a detailed description of a key pairing and binding method, system, and vehicle provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A method of key pairing binding, characterized by, The method is applied to a key, and comprises the following steps: Filling a first pre-made key into a security chip of the key; Based on the first pre-made key in the key and a target key in a key controller, pairing binding is performed with the key controller; the target key is a key corresponding to identification information of the key, which is obtained from a cloud key system and written into the key controller based on the identification information; Based on the first pre-made key in the key and a target key in a key controller, pairing binding is performed with the key controller, comprising the following steps: Based on the first pre-made key in the key and a second pre-made key in the key controller, communication authentication is performed with the key controller; the second pre-made key in the key controller is a key corresponding to identification information of the key, which is obtained from a cloud key system and written into the key controller based on the identification information; In the case that the communication authentication is passed, a target key sent by the key controller is received; Based on the first pre-made key of the key, the target key sent by the key controller is verified for legitimacy; In the case that the verification is passed, pairing binding is performed with the key controller; In the case that the verification is passed, pairing binding is performed with the key controller, comprising the following steps: In the case that the verification is passed, the connection with the key controller is disconnected, and based on the target key in the key, a fourth Bluetooth pairing code and a fourth root key of a target security protocol are derived through a derivation algorithm; In the case that the third Bluetooth pairing code and the fourth Bluetooth pairing code are successfully paired and the third root key and the fourth root key are authenticated, pairing binding is performed with the key controller; wherein the third Bluetooth pairing code and the third root key of the target security protocol are obtained by the key controller based on the target key of the key through the derivation algorithm.

2. The method of claim 1, wherein, Based on the first pre-made key in the key and a second pre-made key in the key controller, communication authentication is performed with the key controller, comprising the following steps: According to the first pre-made key in the key, a second Bluetooth pairing code and a second root key of a target security protocol are derived through a derivation algorithm; In the case that the first Bluetooth pairing code and the second Bluetooth pairing code are successfully paired and the first root key and the second root key are authenticated, it is determined that the communication authentication is passed; wherein the first Bluetooth pairing code and the first root key of the target security protocol are obtained by the key controller based on the second pre-made key of the key through the derivation algorithm.

3. The method of claim 1, wherein, Based on the first pre-made key of the key, the target key sent by the key controller is verified for legitimacy, comprising the following steps: The verification bit sub-key of the first pre-made key in the key is compared with the verification bit sub-key of the received target key to obtain a comparison result; In the case that the comparison result is that the verification bit sub-key of the first pre-made key is the same as the verification bit sub-key of the received target key, the verification is passed; In the case that the comparison result is that the verification bit sub-key of the first pre-made key is different from the verification bit sub-key of the received target key, the verification is not passed.

4. The method of claim 1, wherein, The method further comprises the following steps: In the case that the pairing binding is completed, the control instruction is encrypted based on the target key in the key and sent to the key controller to control the key controller to decrypt the control instruction based on the target key of the key controller and execute the corresponding control operation.

5. The method of key pairing binding of claim 1, wherein, The method further comprises: In the case that the pairing binding between the key and the key controller is completed, the first pre-installed key in the key is deleted.

6. A method of key pairing binding according to any one of claims 1 to 3, characterized in that, In the case that the key written in the key controller is the second pre-installed key and the target key, the method further comprises: In the case that the pairing binding between the key and the key controller is completed, the first pre-installed key is deleted, and the key controller is controlled to delete the second pre-installed key in the key controller.

7. A method of key pairing binding, characterized by, Applied to the key controller, the method comprises: Obtaining a target key corresponding to the identification information of the key in a cloud key system; Writing the target key; Pairing and binding with the key based on the first pre-installed key in the key and the target key in the key controller, the first pre-installed key being a key pre-installed in a security chip of the key; The method further comprises: Obtaining a second pre-installed key corresponding to the identification information in the cloud key system; Writing the second pre-installed key; The pairing and binding with the key based on the first pre-installed key in the key and the target key in the key controller comprises: Performing communication authentication with the key based on the first pre-installed key in the key and the second pre-installed key in the key controller; In the case that the communication authentication is passed, sending the target key to the key; In response to the result that the key passes the legality verification of the target key based on the first pre-installed key of the key, pairing and binding with the key; In response to the result that the key passes the legality verification of the target key based on the first pre-installed key of the key, pairing and binding with the key comprises: In response to the result that the key passes the legality verification of the target key based on the first pre-installed key of the key and the disconnection of the key, deriving a third Bluetooth pairing code and a third root key of the target security protocol based on the target key through a derivation algorithm; In the case that the third Bluetooth pairing code and the fourth Bluetooth pairing code are successfully paired and the third root key and the fourth root key are successfully authenticated, pairing and binding with the key; wherein the fourth Bluetooth pairing code and the fourth root key of the target security protocol are obtained by the key based on the received target key through a derivation algorithm.

8. The method of key pairing binding of claim 7, wherein, Obtaining a target key corresponding to the identification information of the key in a cloud key system comprises: Receiving a broadcast signal of the key to obtain the identification information of the key; Based on the identification information, obtaining the target key corresponding to the identification information in the cloud key system.

9. The method of key pairing binding of claim 7, wherein, Obtaining a target key corresponding to the identification information of the key in a cloud key system comprises: Receiving the target key obtained from the cloud key system by a terminal device; the terminal device is a device capable of obtaining the identification information of the key and capable of establishing communication with the cloud key system.

10. The method of key pairing binding of claim 7, wherein, Performing communication authentication with the key based on the first pre-installed key in the key and the second pre-installed key in the key controller comprises: Deriving a first Bluetooth pairing code and a first root key of a target security protocol based on a second pre-made key in the key controller through a derivation algorithm; In a case where the first Bluetooth pairing code and the second Bluetooth pairing code are successfully paired and the first root key and the second root key are successfully authenticated, determining that communication authentication is passed; wherein the second Bluetooth pairing code and the second root key of the target security protocol are derived based on a first pre-made key of the key itself through a derivation algorithm.

11. The method of key pairing binding of claim 7, wherein, The method further comprises: In a case where the pairing binding is completed, receiving a control instruction sent by the key based on the target key encryption; Decrypting the control instruction based on the target key of the key itself and then performing a corresponding control operation.

12. The method of key pairing binding of claim 7, wherein, The method further comprises: In a case where the key and the key controller complete the pairing binding, controlling the key to delete the first pre-made key in the key.

13. The method of key pairing binding according to any one of claims 9 to 10, wherein, In a case where the keys written in the key controller are the second pre-made key and the target key, the method further comprises: In a case where the key and the key controller complete the pairing binding, deleting the second pre-made key, and controlling the key to delete the first pre-made key in the key.

14. A system for key pairing binding, characterized by Applied to the key, the system comprises: A secure chip for filling the first pre-made key; A pairing binding module for pairing and binding with the key controller based on the first pre-made key in the key and the target key in the key controller; the target key is a key corresponding to the identification information of the key obtained from the cloud key system and written into the key controller; The pairing binding module comprises: A communication authentication module for performing communication authentication with the key controller based on the first pre-made key in the key and the second pre-made key in the key controller; the second pre-made key in the key controller is a key corresponding to the identification information of the key obtained from the cloud key system and written into the key controller by the key controller based on the identification information of the key; A key receiving module for receiving the target key sent by the key controller in a case where the communication authentication is passed; A legality verification module for verifying the legality of the target key sent by the key controller based on the first pre-made key of the key itself; A pairing binding submodule for pairing and binding with the key controller in a case where the verification is passed; The pairing binding submodule comprises: A second derivation module for disconnecting the connection between the key and the key controller in a case where the verification is passed, and deriving a fourth Bluetooth pairing code and a fourth root key of a target security protocol based on the target key in the key through a derivation algorithm; A first pairing binding submodule for pairing and binding with the key controller in a case where a third Bluetooth pairing code and the fourth Bluetooth pairing code are successfully paired and a third root key and the fourth root key are successfully authenticated; wherein the third Bluetooth pairing code and the third root key of the target security protocol are derived based on the target key of the key controller itself through a derivation algorithm.

15. A system for key pairing binding, characterized by Applied to the key controller, the system comprises: A data acquisition module for acquiring a target key corresponding to the identification information of the key in the cloud key system; A secure chip for writing the target key; A pairing binding module for pairing and binding with the key based on the first pre-made key in the key and the target key in the key controller; the target key is a key corresponding to the identification information of the key obtained from the cloud key system and written into the key controller; A pairing binding module comprises: A communication authentication module for performing communication authentication with the key controller based on the first pre-made key in the key and the second pre-made key in the key controller; the second pre-made key in the key controller is a key corresponding to the identification information of the key obtained from the cloud key system and written into the key controller by the key controller based on the identification information of the key; A key receiving module for receiving the target key sent by the key controller in a case where the communication authentication is passed; A legality verification module for verifying the legality of the target key sent by the key controller based on the first pre-made key of the key itself; A pairing binding submodule for pairing and binding with the key controller in a case where the verification is passed; The pairing binding submodule comprises: A second derivation module for disconnecting the connection between the key and the key controller in a case where the verification is passed, and deriving a fourth Bluetooth pairing code and a fourth root key of a target security protocol based on the target key in the key through a derivation algorithm; A first pairing binding submodule for pairing and binding with the key controller in a case where a third Bluetooth pairing code and the fourth Bluetooth pairing code are successfully paired and a third root key and the fourth root key are successfully authenticated; wherein the third Bluetooth pairing code and the third root key of the target security protocol are derived based on the target key of the key controller itself through a derivation algorithm. The pairing binding module is configured to perform pairing binding with the key based on a first pre-provisioned key in the key and a target key in the key controller, the first pre-provisioned key being a key pre-provisioned in a secure chip of the key. The system further comprises: The key acquisition module is configured to acquire a second pre-provisioned key corresponding to the identification information in the cloud key system. The secure chip is configured to write the second pre-provisioned key. The pairing binding module comprises: The communication authentication module is configured to perform communication authentication with the key based on a first pre-provisioned key in the key and a second pre-provisioned key in the key controller. The key sending module is configured to send the target key to the key in the case of passing the communication authentication. The pairing binding submodule is configured to perform pairing binding with the key in response to the result that the key passes the verification of the legality of the target key based on the first pre-provisioned key of the key. The pairing binding submodule comprises: The second derivation module is configured to, in response to the result that the key passes the verification of the legality of the target key based on the first pre-provisioned key of the key and the key is disconnected, derive a third Bluetooth pairing code and a third root key of a target security protocol based on the target key through a derivation algorithm. The first pairing binding submodule is configured to perform pairing binding with the key in the case that the third Bluetooth pairing code and a fourth Bluetooth pairing code are successfully paired and the third root key and a fourth root key are successfully authenticated, wherein the fourth Bluetooth pairing code and the fourth root key of the target security protocol are obtained by the key based on the received target key through the derivation algorithm.

16. A vehicle characterized by comprising: The key of the vehicle is paired and bound based on the key pairing binding method according to any one of claims 1 to 6, or the key controller of the vehicle is paired and bound based on the key pairing binding method according to any one of claims 7 to 13.

17. An electronic device, comprising: The processor, the memory, and the computer program stored on the memory and running on the processor, when executed by the processor, implement the steps in the key pairing binding method according to any one of claims 1 to 6, or when executed by the processor, implement the steps in the key pairing binding method according to any one of claims 7 to 13. The computer program is stored on the computer readable storage medium, and when executed by the processor, implements the steps in the key pairing binding method according to any one of claims 1 to 6, or when executed by the processor, implements the steps in the key pairing binding method according to any one of claims 7 to 13.

18. A computer-readable storage medium, characterized in that, ​

Citation Information

Patent Citations

  • Vehicle key processing method and device, vehicle, vehicle key and storage medium

    CN117915324A