Digital key creation method, device, equipment and medium

By matching public and private key pairs for fleet vehicles and issuing and verifying the terminal public key certificate of vehicle users, the problem of vehicle fleet users entering the pairing code is solved, and the efficiency of vehicle pickup and vehicle use experience is improved.

CN119296207BActive Publication Date: 2025-08-12XIAOMI EV TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411356845.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-26
Publication Date
2025-08-12
Estimated Expiration
2044-09-26

AI Technical Summary

Technical Problem

Under the fleet management system, the existing technology requires car users to enter the vehicle through other keys to enter the vehicle pairing code, resulting in a complicated process of picking up the vehicle, inefficient and poor car use experience.

Method used

An additional pair of fleet pairs of public and private key pairs are maintained for each fleet vehicle. By issuing the target terminal public key certificate of the vehicle user, a digital key creation without the need for the vehicle user to enter the vehicle and enter the pairing code is realized. The fleet pairing public key visa verification certificate is used to ensure communication security.

Benefits of technology

It improves the car pick-up efficiency and car use experience of car users, simplifies the convenience of management of fleet vehicles, and realizes that you can apply for vehicle use without other keys.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119296207B_ABST
    Figure CN119296207B_ABST
Patent Text Reader

Abstract

This application proposes a method, device, equipment and medium for creating a digital key, which relates to the field of communication technology, wherein the method includes: receiving a terminal public key certificate sent by a target terminal; wherein the terminal public key certificate is obtained by signing the terminal public key of the target terminal using the fleet pairing private key; verifying the terminal public key certificate using the fleet pairing public key; when the signature verification is successful and the terminal public key is obtained, sending the vehicle public key certificate of the target vehicle to the target terminal; in response to receiving the signature verification success notification sent by the target terminal, determining that the digital key corresponding to the target terminal for controlling the target vehicle is successfully created. As a result, there is no need to be constrained by the requirement that "the user needs to have other keys for the target vehicle", so that the user can apply for the use of the fleet vehicle conveniently and flexibly, thereby improving the user's vehicle pick-up efficiency and the user's vehicle experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication processing technology, and in particular to a method, apparatus, device and medium for creating a digital key. Background Art

[0002] In a digital key system based on a public-private key pair mechanism and a certificate system, assuming that the vehicle owner's terminal device (hereinafter referred to as the owner device) and the vehicle each have a public-private key pair, and that the vehicle holds the owner device's public key (hereinafter referred to as the owner device public key) through some pre-existing method, and the owner device also holds the vehicle's public key through some pre-existing method, it can be considered that mutual trust has been established between the vehicle and the owner device, that is, the owner device can become the vehicle's digital key. Therefore, the process of creating a digital key for the owner device is also called the process of exchanging public keys between the owner device and the vehicle.

[0003] In the relevant technology, under the fleet management system, in order for any car user to use the vehicle in the fleet, he needs to execute the complete digital key creation process. During the execution of the digital key creation process, the car user needs to enter the vehicle pairing code on the vehicle's central control screen (the vehicle pairing code is sent from the cloud to the terminal device used by the car user (hereinafter referred to as the car user device)), and then the vehicle verifies the vehicle pairing code and enters the communication connection establishment mode after the verification is passed. Through the communication connection establishment mode, the mutual trust between the vehicle and the car user's device is completed to create the car user's digital key.

[0004] However, this method requires the user to have already entered the vehicle using another key, which places a restriction on the user having another key to the vehicle. This restriction complicates the user's first-time vehicle use, resulting in inefficient vehicle pickup and a poor user experience. Summary of the Invention

[0005] The present application aims to solve one of the technical problems in the related art at least to a certain extent.

[0006] To this end, this application proposes a method, device, equipment and medium for creating a digital key, so as to achieve the goal of not being subject to the constraint that "the car user needs to have other keys of the target vehicle", so that the car user can apply for the use of fleet vehicles conveniently and flexibly, improve the car user's efficiency in picking up the vehicle, and improve the car user's car experience.

[0007] The first embodiment of the present application proposes a method for creating a digital key, which is applied to a target vehicle in a fleet, comprising:

[0008] Receive the terminal public key certificate sent by the target terminal; the terminal public key certificate is obtained by signing the terminal public key of the target terminal using the fleet pairing private key from the fleet pairing public-private key pair associated with the target vehicle;

[0009] Use the fleet pairing public key in the fleet pairing public-private key pair to verify the signature of the terminal public key certificate;

[0010] If the signature verification is successful and the terminal public key is obtained, the vehicle public key certificate of the target vehicle is sent to the target terminal;

[0011] In response to receiving a signature verification success notification sent by the target terminal, it is determined that the digital key corresponding to the target terminal for controlling the target vehicle is successfully created.

[0012] A second embodiment of the present application provides a method for creating a digital key, which is applied to a target terminal and includes:

[0013] Send a terminal public key certificate to the target vehicle in the fleet; the terminal public key certificate is signed with the target terminal's terminal public key using the fleet's paired private key from the fleet's paired public-private key pair associated with the target vehicle.

[0014] Receive the vehicle public key certificate sent by the target vehicle; the vehicle public key certificate is signed by the target vehicle using the fleet paired public key in the fleet paired public-private key pair to verify the terminal public key certificate, and is sent after the signature verification is successful and the terminal public key is obtained;

[0015] The vehicle public key certificate is verified, and if the verification is successful and the vehicle public key of the target vehicle is obtained, a verification success notification is sent to the target vehicle.

[0016] The third embodiment of the present application provides a device for creating a digital key, which is applied to a target vehicle in a fleet, including:

[0017] a receiving module, configured to receive a terminal public key certificate sent by a target terminal; wherein the terminal public key certificate is obtained by signing the terminal public key of the target terminal using the fleet pairing private key of the fleet pairing public-private key pair associated with the target vehicle;

[0018] The signature verification module is used to verify the signature of the terminal public key certificate using the fleet pairing public key in the fleet pairing public-private key pair;

[0019] The sending module is used to send the vehicle public key certificate of the target vehicle to the target terminal when the signature verification is successful and the terminal public key is obtained;

[0020] The determination module is used to determine whether the digital key corresponding to the target terminal for controlling the target vehicle is successfully created in response to receiving a signature verification success notification sent by the target terminal.

[0021] A fourth embodiment of the present application provides a device for creating a digital key, which is applied to a target terminal and includes:

[0022] a sending module, configured to send a terminal public key certificate to a target vehicle in a fleet; wherein the terminal public key certificate is obtained by signing the terminal public key of the target terminal using the fleet paired private key from the fleet paired public-private key pair associated with the target vehicle;

[0023] A receiving module is configured to receive a vehicle public key certificate sent by a target vehicle; wherein the vehicle public key certificate is signed by the target vehicle using the fleet paired public key in the fleet paired public-private key pair against the terminal public key certificate, and is sent when the signature verification is successful and the terminal public key is obtained;

[0024] Signature verification module, used to verify the signature of the vehicle public key certificate;

[0025] The sending module is also used to send a signature verification success notification to the target vehicle when the signature verification is successful and the vehicle public key of the target vehicle is obtained.

[0026] The fifth aspect embodiment of the present application proposes an electronic device, including a memory, a processor, and a computer program stored in the memory and runnable on the processor. When the processor executes the program, it implements the method for creating a digital key as described in the first aspect above, or implements the method for creating a digital key as described in the second aspect above.

[0027] The sixth aspect embodiment of the present application proposes a non-temporary computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, it implements the method for creating a digital key as described in the first aspect above, or implements the method for creating a digital key as described in the second aspect above.

[0028] The seventh aspect embodiment of the present application proposes a computer program product, which stores a computer program. When the computer program is executed by a processor, it implements the method for creating a digital key as described in the first aspect above, or implements the method for creating a digital key as described in the second aspect above.

[0029] The digital key creation method, device, equipment and medium proposed in this application maintain an additional fleet pair of public and private key pairs for each fleet vehicle, which is used to subsequently issue a terminal public key certificate for the target terminal of the vehicle user. As a result, there is no need for the vehicle user to enter the target vehicle and enter the vehicle pairing code of the pairing process on the central control screen of the target vehicle. The target vehicle uses the device pairing code of the pairing process to verify the vehicle pairing code to confirm the correctness of the pairing process. This allows the vehicle user to apply for the use of fleet vehicles conveniently and flexibly, improves the efficiency of the vehicle pick-up by the vehicle user, and improves the vehicle user experience. That is, in this application, an additional digital key certificate chain is added to the vehicle digital key certificate system (for example, in addition to the existing cloud public key certificate, vehicle public key certificate and owner device public key certificate, the terminal public key certificate of the target terminal used by the vehicle user (or called the vehicle user device public key certificate), and the fleet pairing public key certificate generated based on the fleet pairing public-private key pair) are added. This can be compatible with the ability to identify the new digital key certificate system, thereby improving the constraint of "the vehicle user needs to have other keys for the vehicle" when the vehicle user uses the vehicle for the first time and creates the digital key of the target terminal used by the vehicle user in the traditional fleet vehicle usage process, thereby improving the vehicle user experience and the convenience of fleet vehicle management.

[0030] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:

[0032] Figure 1 This is a schematic diagram of the existing certificate structure;

[0033] Figure 2 This is a schematic diagram of the existing digital key public and private key pair system;

[0034] Figure 3 This is a schematic diagram of the existing digital key certificate chain;

[0035] Figure 4 Create a process diagram for existing car owners' digital keys;

[0036] Figure 5 A flowchart of the first method for creating a digital key provided in an embodiment of the present application;

[0037] Figure 6 A flowchart of a second method for creating a digital key provided in an embodiment of the present application;

[0038] Figure 7A flowchart of a third method for creating a digital key provided in an embodiment of the present application;

[0039] Figure 8 A schematic diagram of the fleet vehicle registration process provided in an embodiment of the present application;

[0040] Figure 9 A schematic diagram of a fleet vehicle deregistration process provided in an embodiment of the present application;

[0041] Figure 10 A schematic diagram of the fleet vehicle deregistration process provided in an embodiment of the present application;

[0042] Figure 11 A flowchart of the fourth method for creating a digital key provided in an embodiment of the present application;

[0043] Figure 12 A flowchart of the fifth method for creating a digital key provided in an embodiment of the present application;

[0044] Figure 13 Schematic diagram of the improved digital key public and private key pair system provided in the embodiment of the present application;

[0045] Figure 14 A schematic diagram of the improved digital key certificate chain provided in an embodiment of the present application;

[0046] Figure 15 A schematic diagram of the process for creating a digital key for a car user provided in an embodiment of the present application;

[0047] Figure 16 A schematic diagram of the structure of a digital key creation device provided in an embodiment of the present application;

[0048] Figure 17 A schematic diagram of the structure of another device for creating a digital key provided in an embodiment of the present application;

[0049] Figure 18 is a block diagram of a target vehicle according to an exemplary embodiment. DETAILED DESCRIPTION

[0050] The following describes in detail embodiments of the present application, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present application, and should not be construed as limiting the present application.

[0051] Digital keys based on Bluetooth, NFC (Near Field Communication, also known as short-range wireless communication), and UWB (Ultra-Wide Band) communications terminals (such as mobile phones) are already very popular in various models of major car companies. Users can create digital keys for car owners independently, allowing users to unlock the vehicle directly through the terminal later, greatly improving the user experience of the vehicle.

[0052] Fleets are a common mode of vehicle operation, and are more common in the commercial operation models of companies such as taxi companies and freight companies. They usually have the characteristic that the human-vehicle matching relationship is easily subject to change. The use of the digital key function that allows users to independently create digital keys for car owners can help improve the car-using experience of relevant car users.

[0053] Therefore, how to design a more user-friendly fleet digital key management system based on the digital key function has also become a consideration for automakers when designing vehicle digital key functions.

[0054] From a security perspective, a public-private key pair is a commonly used digital key security solution. This solution ensures the information security of both communicating parties by fulfilling three basic conditions:

[0055] 1. In a pair of public and private keys, the private key is stored at one end and is not easily leaked, while the public key can be released to the outside world;

[0056] 2. For the same public-private key pair, the content signed by the private key can be verified by the public key;

[0057] 3. For communicating parties A and B, party A holds its own public-private key pair and party B's public key, and party B holds its own public-private key pair and party A's public key;

[0058] After the above three prerequisites are met, the communicating parties can use their own private keys to sign the communication content and then transmit it. Only when the other party successfully completes the signature using the public key can it accept the received message content.

[0059] In order to enable the public key to be transmitted between the ends, a method such as Figure 1 The certificate structure shown. Figure 1 In the certificate, the certificate name is the name of the certificate; the certificate body is the main content that the certificate wants to encapsulate or transmit. For example, when transmitting public key A, public key A can be the certificate body; the certificate signature is the complete signature of the certificate, usually signed by a private key, and its corresponding public key can verify the signature, thereby ensuring that the communication peer completes the security authentication of the received certificate content.

[0060] Furthermore, in a digital key system based on a public-private key pair mechanism and a certificate system, assuming that the terminal device used by the vehicle owner (i.e., the user who expects to use the vehicle this time) (hereinafter referred to as the owner device) and the vehicle each have a pair of public-private key pairs, and the vehicle holds the owner device public key through some pre-existing method, and the owner device also holds the vehicle public key through some pre-existing method, it can be considered that mutual trust has been achieved between the vehicle and the owner device, that is, the owner device can become the digital key of the vehicle. Therefore, the process of creating a digital key for the owner device is also called the process of exchanging public keys between the owner device and the vehicle.

[0061] Based on the above description, the digital key public and private key pair system and certificate chain are introduced as follows: Figure 2 and Figure 3 As shown. Among them, Figure 2 In the figure, the public and private key pairs of digital keys are marked. When all ends in the system are in the initial state, the public and private key pairs held by each party are marked.

[0062] Figure 3 In the Figure 2 The certificate style used when each public key generates a certificate also includes the verification relationship between each certificate, that is, the public key in the upper-level certificate can verify the signature of the lower-level certificate, so that the system can recognize the public key in the lower-level certificate, and this public key can verify the signature of the lower-level certificate, and so on. A single system can use a root certificate and a series of sub-certificates to recognize the public keys in certificates at all levels received in the system after completing a series of verifications.

[0063] Based on the above premise, the current common process for creating a digital key for a car owner is as follows: Figure 4 As shown, it mainly includes the following steps:

[0064] 1. Before the owner's digital key is created, the cloud obtains a cloud public key certificate by self-signing the cloud public key. For example, if the cloud is a car manufacturer cloud service with vehicle management functions, the cloud public key can be the car manufacturer's public key, and the cloud public key certificate can be the car manufacturer's public key certificate (A);

[0065] The vehicle obtains the manufacturer's public key certificate (A) and vehicle public key certificate (B) through the manufacturer's customized vehicle-to-cloud communication link or the manufacturer's self-built production line data filling capability. The owner's device obtains the manufacturer's public key certificate (A) and the owner's device public key certificate (C) through the communication link between the manufacturer and the manufacturer's APP (Application) installed on the owner's device.

[0066] 2. When the car owner wishes to use the car owner's device to complete the creation of the digital key, a request for the car owner's digital key creation is sent to the cloud (i.e., the car manufacturer's cloud service);

[0067] 3. The cloud (i.e., the manufacturer's cloud service) responds to the owner's digital key creation request, returns the vehicle pairing code to the owner's device, and sends the device pairing code to the corresponding vehicle;

[0068] 4. The owner enters the vehicle pairing code received by the owner's device on the vehicle's central control screen;

[0069] 5. The vehicle verifies the received device pairing code to confirm the correctness of the pairing process, and then enters the communication connection establishment mode to establish a secure communication connection with the owner's device via NFC, Bluetooth, or UWB.

[0070] 6. The vehicle sends the vehicle public key certificate (B) to the owner's device through the above communication connection;

[0071] 7. The owner's device verifies the signature of the vehicle public key certificate (B) using the cloud public key (such as the manufacturer's public key). Once the signature is verified, the owner obtains the vehicle public key.

[0072] 8. The owner's device sends the owner's device public key certificate (C) to the vehicle;

[0073] 9. The vehicle verifies the signature of the owner's device public key certificate (C) using the cloud public key (such as the manufacturer's public key). Once the signature is verified, the vehicle obtains the owner's device public key.

[0074] 10. The vehicle returns a successful signature verification notification to the owner's device.

[0075] After the above process, the vehicle and the owner's device can exchange each other's public keys, complete mutual trust, and communicate securely thereafter, which means that the owner's digital key is successfully created.

[0076] Under the fleet management system, the current vehicle user can then use the owner's digital key on his or her own terminal device to complete the use of the vehicle, that is, the vehicle user enters the vehicle use status.

[0077] In the above solution, in order to use a vehicle in the fleet, the user must complete the entire process of creating a digital key. However, in step 4 of this process, the user must enter the vehicle pairing code received by their device on the vehicle's central control screen. This process requires the user to already have access to the vehicle using another key, which restricts the user's need to have another key. This restriction complicates the user's first-time vehicle use, resulting in inefficient vehicle pickup and a poor user experience.

[0078] In response to the above-mentioned technical problems, this application mainly proposes a method, device, equipment and medium for creating a digital key.

[0079] The following describes the method, apparatus, device, and medium for creating a digital key according to an embodiment of the present application with reference to the accompanying drawings.

[0080] Figure 5 A flowchart of the first method for creating a digital key provided in an embodiment of the present application.

[0081] The method for creating a digital key according to an embodiment of the present application can be applied to a target vehicle, where the target vehicle can be any vehicle in a fleet.

[0082] like Figure 5 As shown, the method for creating a digital key may include the following steps S501 to S504:

[0083] Step S501: Receive a terminal public key certificate sent by a target terminal; wherein the terminal public key certificate is obtained by signing the terminal public key of the target terminal using the fleet paired private key in the fleet paired public-private key pair associated with the target vehicle.

[0084] Among them, the target terminal can be any terminal device used by a user who wishes to use the target vehicle, including but not limited to smartphones, tablets, personal digital assistants, wearable devices and other hardware devices with various operating systems, touch screens and / or display screens.

[0085] Among them, the fleet pairing public-private key pair includes a fleet pairing public key and a fleet pairing private key, which is a public-private key pair generated or created by the cloud for the target vehicle when the target vehicle performs the fleet vehicle registration action.

[0086] The terminal public key is the public key in the public-private key pair generated by the target terminal.

[0087] Among them, the terminal public key certificate (or the vehicle user device public key certificate) can be obtained by responding to the digital key creation request sent by the target terminal through the cloud, using the fleet pairing private key in the fleet pairing public-private key pair associated with the target vehicle to sign the terminal public key of the target terminal carried in the digital key creation request.

[0088] Among them, the terminal public key certificate contains the certificate name, certificate body and certificate signature. The certificate name is the name of the terminal public key certificate, the certificate body contains the terminal public key of the target terminal, and the certificate signature is the complete signature of the terminal public key certificate. For example, the fleet paired private key is used to sign the terminal public key to obtain a complete certificate signature.

[0089] In an embodiment of the present application, when the target terminal approaches the target vehicle, the target terminal can establish a communication link with the target vehicle through communication methods such as NFC, Bluetooth, UWB, etc., and based on the communication link, send the terminal public key certificate to the target vehicle. Correspondingly, the target vehicle can receive the terminal public key certificate sent by the target terminal.

[0090] Step S502: Use the fleet pairing public key in the fleet pairing public-private key pair to verify the signature of the terminal public key certificate.

[0091] Among them, signature verification is the process of verifying the validity of digital signatures to ensure the integrity of data and the authenticity of the source.

[0092] In an embodiment of the present application, the target vehicle can use the fleet pairing public key in the fleet pairing public-private key pair to verify the signature of the terminal public key certificate.

[0093] Step S503: When the signature verification is successful and the terminal public key is obtained, the vehicle public key certificate of the target vehicle is sent to the target terminal.

[0094] Among them, the vehicle public key certificate includes a certificate name, a certificate body and a certificate signature. The certificate name is the name of the vehicle public key certificate, the certificate body contains the vehicle public key of the target vehicle, and the certificate signature is the complete signature of the vehicle public key certificate.

[0095] In an embodiment of the present application, when the signature verification is successful or correct, the target vehicle can obtain a trusted terminal public key from the certificate body of the terminal public key certificate. At this time, the target vehicle can further send the target vehicle's vehicle public key certificate to the target terminal.

[0096] Step S504: In response to receiving the signature verification success notification sent by the target terminal, it is determined that the digital key corresponding to the target terminal for controlling the target vehicle is successfully created.

[0097] In any embodiment of the present application, the signature verification success notification may be sent by the target terminal in response to successful signature verification of the vehicle public key certificate and acquisition of the vehicle public key of the target vehicle.

[0098] The vehicle public key is the public key in the public-private key pair generated by the target vehicle.

[0099] In an embodiment of the present application, when the target terminal receives the vehicle public key certificate sent by the target vehicle, it can verify the signature of the vehicle public key certificate. If the verification is successful or correct, it obtains the trusted vehicle public key from the certificate body of the vehicle public key certificate and sends a verification success notification to the target vehicle.

[0100] Correspondingly, when the target vehicle receives the notification of successful signature verification, it can be determined that the target vehicle and the target terminal both hold each other's public keys, that is, the digital key of the target terminal is successfully created.

[0101] The method for creating a digital key in the embodiment of the present application maintains an additional fleet pair of public and private key pairs for each fleet vehicle, which is used to subsequently issue a terminal public key certificate for the target terminal of the vehicle user. As a result, there is no need for the vehicle user to enter the target vehicle and enter the vehicle pairing code of the pairing process on the central control screen of the target vehicle. The target vehicle uses the device pairing code of the pairing process to verify the vehicle pairing code to confirm the correctness of the pairing process. This allows the vehicle user to apply for the use of fleet vehicles conveniently and flexibly, improves the efficiency of the vehicle pick-up by the vehicle user, and improves the vehicle user experience. That is, in this application, an additional digital key certificate chain is added to the vehicle digital key certificate system (for example, in addition to the existing cloud public key certificate, vehicle public key certificate and owner device public key certificate, the terminal public key certificate of the target terminal used by the vehicle user (or called the vehicle user device public key certificate), the fleet pairing public key certificate generated based on the fleet pairing public-private key pair, and the relevant certificates are issued to the target terminal and the target vehicle), which can be compatible with the ability to identify the new digital key certificate system, thereby improving the constraint of "the vehicle user needs to have other keys for the vehicle" when the vehicle user uses the vehicle for the first time and creates the digital key of the target terminal used by the vehicle user in the traditional fleet vehicle usage process, thereby improving the vehicle user experience and the convenience of fleet vehicle management.

[0102] This embodiment of the application provides another method for creating a digital key. Figure 6 A schematic diagram of a second method for creating a digital key provided in an embodiment of the present application, wherein the method for creating a digital key can be applied to a target vehicle.

[0103] It should be noted that the method for creating a digital key can be executed alone, or it can be executed in combination with any embodiment in the present application or a possible implementation method in the embodiment, or it can be executed in combination with any technical solution in the relevant technology, and the embodiments of the present application do not limit this.

[0104] like Figure 6 As shown, the method for creating a digital key may include the following steps S601 to S604:

[0105] Step S601: Receive a terminal public key certificate sent by a target terminal.

[0106] The terminal public key certificate is obtained by signing the terminal public key of the target terminal using the fleet paired private key in the fleet paired public-private key pair associated with the target vehicle.

[0107] Step S602: Use the fleet pairing public key in the fleet pairing public-private key pair to verify the signature of the terminal public key certificate.

[0108] The explanation of steps S601 to S602 can be found in the relevant description in any embodiment of the present application and will not be repeated here.

[0109] In step S603, when the signature verification is successful and the terminal public key is obtained, the vehicle public key certificate of the target vehicle is sent to the target terminal; wherein, the vehicle public key certificate is obtained by signing the vehicle public key of the target vehicle using the cloud private key in the cloud.

[0110] The cloud private key is the private key in the public-private key pair generated on the cloud.

[0111] The cloud has the function of managing vehicles. For example, the cloud can be a vehicle manufacturer cloud service. In this case, the cloud private key can also be referred to as the vehicle manufacturer private key generated by the vehicle manufacturer cloud service. Correspondingly, the public key in the public-private key pair generated by the cloud is referred to as the cloud public key in this application, and can also be referred to as the vehicle manufacturer public key generated by the vehicle manufacturer cloud service.

[0112] In an embodiment of the present application, when the signature verification is successful or correct, the target vehicle can obtain a trusted terminal public key from the certificate body of the terminal public key certificate. At this time, the target vehicle can further send the target vehicle's vehicle public key certificate to the target terminal.

[0113] The vehicle public key certificate is obtained by signing the target vehicle's vehicle public key with the cloud's private key. For example, the target vehicle can send its vehicle public key to the cloud via the manufacturer's customized vehicle-to-cloud communication link. The cloud then signs the vehicle public key with its private key to obtain the vehicle public key certificate. The cloud can then use the manufacturer's customized vehicle-to-cloud communication link or the data injection capabilities of the manufacturer's in-house production line to enable the target vehicle to obtain the vehicle public key certificate.

[0114] Step S604, in response to receiving the successful signature verification notification sent by the target terminal, it is determined that the digital key corresponding to the target terminal for controlling the target vehicle is successfully created; wherein, the successful signature verification notification is sent when the target terminal uses the cloud public key to verify the vehicle public key certificate, and the vehicle public key of the target vehicle is obtained when the verification is successful.

[0115] In an embodiment of the present application, upon receiving the vehicle public key certificate sent by the target vehicle, the target terminal can use the cloud public key to verify the signature of the vehicle public key certificate. If the verification is successful or correct, the target terminal obtains the trusted vehicle public key from the certificate body of the vehicle public key certificate and sends a verification success notification to the target vehicle. Accordingly, upon receiving the verification success notification, it can be determined that the target vehicle and the target terminal both hold each other's public keys, i.e., the target terminal's digital key has been successfully created.

[0116] In any embodiment of the present application, the target vehicle may obtain the cloud public key by following steps A to C:

[0117] Step A: The target vehicle receives the cloud public key certificate sent by the cloud; wherein, the cloud public key certificate is obtained by the cloud using the cloud private key to self-sign the cloud public key.

[0118] Step B: The target vehicle verifies the signature of the cloud public key certificate.

[0119] As an example, the target vehicle may obtain and trust the cloud certificate fingerprint or cloud public key in advance, and verify the cloud public key certificate based on the cloud certificate fingerprint or cloud public key.

[0120] Step C: If the signature verification is successful, the target vehicle can extract the cloud public key from the certificate body of the cloud public key certificate.

[0121] The method for creating a digital key in the embodiment of the present application can enable the target vehicle to effectively obtain a vehicle public key certificate by using a cloud public key with a vehicle management function to sign the vehicle public key of the target vehicle.

[0122] This embodiment of the application provides another method for creating a digital key. Figure 7 This is a flow chart of a third method for creating a digital key provided in an embodiment of the present application. This method for creating a digital key can be applied to a target vehicle.

[0123] It should be noted that the method for creating a digital key can be executed alone, or it can be executed in combination with any embodiment in the present application or a possible implementation method in the embodiment, or it can be executed in combination with any technical solution in the relevant technology, and the embodiments of the present application do not limit this.

[0124] like Figure 7 As shown, based on any of the above embodiments, the target vehicle can obtain the fleet pairing public key by following the steps S701 to S703:

[0125] Step S701: Send a fleet vehicle registration application to the cloud; wherein the fleet vehicle registration application is used to register the vehicle in the cloud and generate a fleet pairing public key certificate for the target vehicle.

[0126] It should be noted that the above embodiments all require that the target vehicle has completed the fleet vehicle registration action, so the fleet vehicle registration process needs to be introduced, that is, the target vehicle needs to execute the fleet vehicle registration process.

[0127] In this application, the target vehicle can send a fleet vehicle registration application to the cloud. Accordingly, when the cloud receives the fleet vehicle registration application, it can respond to the fleet vehicle registration application, register the vehicle for the registration application information carried in the fleet vehicle registration application, and generate a fleet pairing public key certificate for the target vehicle.

[0128] As a possible implementation, upon receiving a fleet vehicle registration application, the cloud may perform the following steps A' to D':

[0129] Step A': the cloud may respond to the fleet vehicle registration application and verify the registration application information carried in the fleet vehicle registration application.

[0130] Among them, the registration application information includes the vehicle number, model, vehicle color and other information of the target vehicle.

[0131] For example, the fleet manager can manually verify the registration application information through the cloud backend, that is, the fleet manager can authorize the target vehicle to join the fleet.

[0132] Step B': If the verification is successful, the cloud registers the registration application information and creates a fleet-paired public-private key pair for the target vehicle.

[0133] Step C': The cloud can use the cloud private key to sign the fleet pairing public key in the fleet pairing public-private key pair associated with the target vehicle to obtain a fleet pairing public key certificate.

[0134] Step D': The cloud can send the fleet pairing public key certificate to the target vehicle.

[0135] In this way, it is possible to effectively generate a vehicle pairing public key certificate for the target vehicle through the fleet vehicle registration process.

[0136] Step S702: Receive and store the fleet pairing public key certificate sent by the cloud.

[0137] In an embodiment of the present application, the target vehicle may receive the fleet pairing public key certificate sent by the cloud in response to the fleet vehicle registration application, and store the fleet pairing public key certificate locally.

[0138] In step S703, the cloud public key is used to verify the signature of the fleet pairing public key certificate to obtain the fleet pairing public key.

[0139] It should be noted that the explanation of the cloud public key in the above embodiment is also applicable to this embodiment and will not be repeated here.

[0140] In an embodiment of the present application, the target vehicle can use the cloud public key to verify the signature of the fleet pairing public key certificate. If the signature verification is successful or correct, the fleet pairing public key can be extracted from the certificate body of the fleet pairing public key certificate.

[0141] The digital key creation method of the embodiment of the present application can enable the target vehicle to effectively obtain the fleet pairing public key in the fleet pairing public-private key pair through the fleet vehicle registration process.

[0142] In the above embodiments, the target vehicle is required to be a vehicle that has completed the fleet vehicle registration action, so a fleet vehicle registration process needs to be introduced. For example, the fleet vehicle registration process can be as follows: Figure 8 As shown, it mainly includes the following steps:

[0143] a. Before registering a target vehicle in a fleet, the cloud (or manufacturer cloud service) self-signs its public key (or manufacturer public key) to obtain a cloud public key certificate. For example, if the cloud is a manufacturer cloud service with vehicle management capabilities, the cloud public key can be the manufacturer public key, and the cloud public key certificate can be the manufacturer public key certificate (A).

[0144] Through the manufacturer's customized vehicle-to-cloud communication link or the manufacturer's self-built production line data filling capabilities, the target vehicle obtains the certificate (A) and the vehicle public key certificate (B).

[0145] b. The fleet manager initiates a fleet vehicle registration application to the cloud by operating the target vehicle's central control screen.

[0146] c. The fleet manager verifies the registration application information in the fleet vehicle registration application through the cloud backend.

[0147] d. After the cloud backend verifies that the registration application information is correct, it creates a public-private key pair for the target vehicle fleet and uses the cloud private key (or the vehicle manufacturer's private key) to sign the fleet pairing public key in the fleet pairing public-private key pair to obtain the fleet pairing public key certificate (D).

[0148] e. The cloud sends the fleet paired public key certificate (D) to the target vehicle.

[0149] f. The target vehicle receives the fleet pairing public key certificate (D) and verifies the signature of the fleet pairing public key certificate (D) using the cloud public key (or the vehicle manufacturer's public key) to obtain the fleet pairing public key.

[0150] At this point, the target vehicle has obtained the fleet pairing public key that can be used to verify the terminal public key certificate (or called the vehicle user's device public key certificate, marked as Certificate E) in the future, and the target vehicle can be considered to have completed the fleet vehicle registration process.

[0151] In any embodiment of the present application, when the target vehicle is no longer used as a fleet vehicle, the target vehicle can execute the corresponding fleet vehicle deregistration process. Figure 9 , which provides detailed instructions on the fleet vehicle deregistration process.

[0152] Figure 9 A schematic diagram of a fleet vehicle deregistration process provided in an embodiment of the present application.

[0153] like Figure 9 As shown, the fleet vehicle deregistration process may include the following steps S901 to S902:

[0154] Step S901 : In response to removing the target vehicle from the fleet, deleting the locally stored fleet pairing public key certificate and fleet pairing public key.

[0155] In an embodiment of the present application, when a target vehicle is removed from a fleet, the target vehicle may delete the locally stored fleet pairing public key certificate and fleet pairing public key.

[0156] Step S902: In response to the completion of deletion of the fleet pairing public key certificate and the fleet pairing public key, a fleet vehicle cancellation application is sent to the cloud; wherein the fleet vehicle cancellation application is used by the cloud to delete the fleet pairing public-private key pair, the fleet pairing public key certificate, and the registration application information associated with the target vehicle.

[0157] In an embodiment of the present application, when the fleet pairing public key certificate and the fleet pairing public key are deleted, the target vehicle can send a fleet vehicle cancellation application to the cloud. Correspondingly, when the cloud receives the fleet vehicle cancellation application, it can delete the fleet pairing public-private key pair, fleet pairing public key certificate and registration application information associated with the target vehicle.

[0158] The digital key creation method of the embodiment of the present application can achieve the removal of the fleet pairing public key certificate and fleet pairing public key stored locally in the target vehicle when the target vehicle is no longer used as a fleet vehicle, so that the target vehicle no longer has the ability to verify the terminal public key certificate and falls back to the existing digital key certificate chain originally possessed by the target vehicle.

[0159] In summary, when the target vehicle is no longer used as a fleet vehicle, the corresponding fleet vehicle deregistration process can be executed. For example, the fleet vehicle deregistration process can be as follows: Figure 10 As shown, it mainly includes the following steps:

[0160] a'. The fleet manager initiates the fleet vehicle deregistration process by operating the target vehicle's central control screen. The target vehicle first deletes the fleet pairing public key certificate (D) and the corresponding fleet pairing public key locally.

[0161] b', after the target vehicle is deleted, a fleet vehicle deregistration application is sent to the cloud;

[0162] c'. After receiving the fleet vehicle deregistration application, the cloud cancels the relevant vehicle information (including the fleet pairing public and private key pair associated with the target vehicle, the fleet pairing public key certificate and registration application information) on the cloud.

[0163] At this point, the target vehicle removes the fleet paired public key certificate (D) and no longer has the ability to verify the terminal public key certificate (or the vehicle user's device public key certificate, that is, certificate E), and falls back to the digital key certificate chain originally possessed by the target vehicle.

[0164] The above are various method embodiments executed by the target vehicle. This application also proposes a method for creating a digital key executed by the target terminal.

[0165] Figure 11 This is a flow chart of a fourth method for creating a digital key provided in an embodiment of the present application. This method for creating a digital key can be applied to a target terminal.

[0166] like Figure 11 As shown, the method for creating a digital key may include the following steps S1101 to S1103:

[0167] Step S1101: Send a terminal public key certificate to a target vehicle in a fleet; wherein the terminal public key certificate is obtained by signing the terminal public key of the target terminal using the fleet paired private key in the fleet paired public-private key pair associated with the target vehicle.

[0168] Step S1102, receiving the vehicle public key certificate sent by the target vehicle; wherein, the vehicle public key certificate is signed by the target vehicle using the fleet paired public key in the fleet paired public-private key pair to verify the terminal public key certificate, and is sent when the signature verification is successful and the terminal public key is obtained.

[0169] Step S1103: Verify the signature of the vehicle public key certificate, and if the verification is successful and the vehicle public key of the target vehicle is obtained, send a verification success notification to the target vehicle.

[0170] In any embodiment of the present application, the signature verification success notification is used to notify the target terminal that the corresponding digital key for controlling the target vehicle has been successfully created.

[0171] As a possible implementation method, the vehicle public key certificate is obtained by signing the vehicle public key using the cloud private key in the cloud. The vehicle public key certificate verification method can be specifically as follows: the target terminal uses the cloud public key to verify the vehicle public key certificate.

[0172] As one possible implementation, the target terminal obtains the cloud public key through the following steps: the target terminal receives a cloud public key certificate sent by the cloud; the cloud public key certificate is self-signed using the cloud private key; the target terminal verifies the signature of the cloud public key certificate and, if the signature verification is successful, extracts the cloud public key from the certificate body of the cloud public key certificate. The implementation principle can be found in the relevant description of step S604 in the above embodiment and is not further elaborated here.

[0173] It should be noted that the explanation of the method executed on the target vehicle in the above embodiment is also applicable to the method executed by the target terminal in this embodiment. The implementation principles are similar and will not be repeated here.

[0174] The digital key creation method of the embodiment of the present application, by adding an additional digital key certificate chain to the vehicle digital key certificate system (for example, in addition to the existing cloud public key certificate, vehicle public key certificate and owner device public key certificate, the terminal public key certificate of the target terminal used by the vehicle user (or called the vehicle user device public key certificate), the fleet pairing public key certificate generated based on the fleet pairing public-private key pair, and issuing relevant certificates to the target terminal and target vehicle), can be compatible with the ability to identify new digital key certificate systems, thereby improving the constraint of "the vehicle user needs to have other keys for the vehicle" when the vehicle user uses the vehicle for the first time and creates the digital key of the target terminal used by the vehicle user during the use of digital keys for traditional fleet vehicles, thereby improving the vehicle user experience and the convenience of fleet vehicle management.

[0175] This embodiment of the application provides another method for creating a digital key. Figure 12 This is a flow chart of the fifth method for creating a digital key provided in an embodiment of the present application. This method for creating a digital key can be applied to a target terminal.

[0176] It should be noted that the method for creating a digital key can be executed alone, or it can be executed in combination with any embodiment in the present application or a possible implementation method in the embodiment, or it can be executed in combination with any technical solution in the relevant technology, and the embodiments of the present application do not limit this.

[0177] like Figure 12 As shown, the method for creating a digital key may include the following steps S1201 to S1205:

[0178] Step S1201: Send a digital key creation request for the target vehicle to the cloud; wherein, the digital key creation request carries the terminal public key of the target terminal, which is used by the cloud to verify the digital key creation request. If the verification is successful, the terminal public key is signed with the fleet pairing private key in the fleet pairing public-private key pair associated with the target vehicle to obtain a terminal public key certificate.

[0179] In an embodiment of the present application, the target terminal can send a digital key creation request for the target vehicle to the cloud. Accordingly, when the cloud receives the digital key creation request, it can verify the request parameters in the digital key creation request.

[0180] Among them, the request parameters include but are not limited to: account information of the target terminal; vehicle information of the target vehicle (such as vehicle code, model, vehicle color, etc.); application information of the target terminal for applying for a digital key (such as the reason for application); in the business scenario to which the fleet belongs, business information associated with the target terminal (such as the business department and position of the vehicle user), etc.

[0181] As an example, the cloud backend administrator can verify the request parameters in the digital key creation request, that is, manually authorize the digital key to the car user.

[0182] In this application, if the request parameters are verified, the cloud can use the fleet pairing private key in the fleet pairing public-private key pair associated with the target vehicle to sign the terminal public key of the target terminal to obtain the terminal public key certificate of the target terminal.

[0183] Step S1202: Receive the terminal public key certificate sent by the cloud in response to the digital key creation request.

[0184] In an embodiment of the present application, the target terminal can receive the terminal public key certificate sent by the cloud in response to the digital key creation request.

[0185] Step S1203: Send the terminal public key certificate to the target vehicle in the fleet.

[0186] Step S1204: Receive the vehicle public key certificate sent by the target vehicle.

[0187] Among them, the vehicle public key certificate is the target vehicle using the fleet pairing public key in the fleet pairing public-private key pair to verify the terminal public key certificate, and is sent when the verification is successful and the terminal public key of the target terminal is obtained.

[0188] Step S1205: Verify the signature of the vehicle public key certificate, and if the verification is successful and the vehicle public key of the target vehicle is obtained, send a verification success notification to the target vehicle.

[0189] In any embodiment of the present application, the signature verification success notification is used to notify the target terminal that the corresponding digital key for controlling the target vehicle has been successfully created.

[0190] The explanation of steps S1203 to S1205 can be found in the relevant description in any embodiment of the present application and will not be repeated here.

[0191] The method for creating a digital key in the embodiment of the present application can be implemented through a cloud with vehicle management functions, using the fleet pairing private key in the fleet pairing public-private key pair generated for the target vehicle to sign the terminal public key of the target terminal, so that the target terminal can effectively obtain the terminal public key certificate.

[0192] In any embodiment of the present application, by adding an additional certificate chain to the traditional digital key certificate system and designing a fleet vehicle registration process on the cloud (such as a car manufacturer's cloud service) to issue the necessary vehicle-side certificates, the current common process of fleet vehicle users creating digital keys is improved. Due to the constraint that "the user needs to have other keys for the vehicle", the user's vehicle collection efficiency is low and the vehicle-using experience is poor, thereby improving the user's vehicle-using experience.

[0193] As an example, the improved digital key public-private key pair system can be as follows Figure 13 As shown, the improved digital key certificate chain can be Figure 14 shown.

[0194] like Figure 13 As shown, the improved digital car key public-private key pair system is compared with Figure 2 In terms of the cloud side (i.e., the car manufacturer's cloud service), it is possible to maintain an additional pair of fleet-matched public-private key pairs for each registered fleet vehicle, which is used to issue the terminal public key certificate (hereinafter collectively referred to as the vehicle user's equipment public key certificate (E)).

[0195] like Figure 14 As shown, the improved digital car key certificate chain is compared with Figure 3 On the one hand, Figure 14 Zhongxin introduced the fleet pairing public key certificate (D). The certificate body of the fleet pairing public key certificate (D) contains the fleet pairing public key, which is used by the cloud (car manufacturer cloud service) to obtain the fleet pairing public key. Figure 14 The signature is generated by the manufacturer's private key, one for each car; on the other hand, Figure 14 Sino-Singapore introduces the vehicle user device public key certificate (E). The certificate body of the vehicle user device public key certificate (E) contains the vehicle user device public key (i.e. the terminal public key of the target terminal), which is generated by the cloud (car manufacturer cloud service) using the fleet paired private key signature.

[0196] Furthermore, the improved process of creating a digital key for a user can be as follows: Figure 15 As shown, it mainly includes the following steps:

[0197] 1', Before the car user's digital key is created, the cloud (car manufacturer cloud service) uses the cloud private key (or car manufacturer private key) to self-sign the cloud public key (or car manufacturer public key) and obtains the cloud public key certificate ( Figure 14 The fleet pairing public key certificate (denoted as the manufacturer's public key certificate (A)) is obtained by signing the target vehicle's fleet pairing public key using the cloud-based private key through the fleet vehicle registration process. By performing the fleet vehicle registration action on the target vehicle, the target vehicle obtains the manufacturer's public key certificate (A), the vehicle's public key certificate (B), and the fleet pairing public key certificate (D). Through the communication link between the manufacturer and the manufacturer's app installed on the user's target terminal, the user's target terminal obtains the manufacturer's public key certificate (A).

[0198] 2', When the car user expects to use the target terminal to complete the digital key creation, the car user's digital key creation request is sent to the cloud, and the terminal public key of the car user's target terminal ( Figure 14 The public key of the user's device is included in the request.

[0199] 3'. The cloud backend administrator verifies the digital key creation request through the cloud backend;

[0200] 4'. After verifying the digital key creation request, use the fleet's paired private key to sign the user's device public key to obtain the user's device public key certificate (E);

[0201] 5', the cloud returns the user's device public key certificate (E) to the user's target terminal;

[0202] 6'. When the user holds the target terminal close to the target vehicle, a communication link is established with the target vehicle through NFC, Bluetooth, UWB and other communication methods;

[0203] 7', the target terminal of the vehicle user sends the vehicle user's device public key certificate (E) to the target vehicle;

[0204] 8'. The target vehicle uses the fleet's paired public key to verify the signature of the user's device public key certificate (E) to obtain a trusted user's device public key;

[0205] 9', the target vehicle sends the vehicle public key certificate (B) to the target terminal of the vehicle user;

[0206] 10'. The user's target terminal uses the cloud public key to verify the signature of the vehicle public key certificate (B) to obtain a trusted vehicle public key;

[0207] 11'. The user's target terminal sends a signature verification success notification to the target vehicle. At this point, the user's target terminal and the target vehicle both hold each other's public keys, that is, the digital key of the user's target terminal is successfully created.

[0208] Through the above method, the fleet can easily add a new certificate chain system to the target vehicle when it is used as a fleet vehicle. Through the newly added certificate chain system, the target vehicle can change the trust logic of digital key creation from "people who enter the vehicle with a physical key can create a digital key" to "people who are approved or authorized by the backend can create a digital key". Therefore, when subsequent vehicle users create digital keys for their devices, they no longer need to be constrained by "the user needs to have other keys for the target vehicle" and can easily and flexibly apply for fleet vehicle use. When the target vehicle is no longer used as a fleet vehicle, the fleet paired public key certificate (D) and its subsequent certificate chain can also be easily removed without affecting the original vehicle digital key certificate chain and certificate system.

[0209] In summary, the solution provided by this application has at least the following advantages compared to the existing solutions: by introducing a fleet vehicle registration process for fleet vehicles and issuing fleet paired public key certificates for fleet vehicles, it can add additional certificate chains while still maintaining its original digital key certificate system, and be compatible with the ability to identify new digital key certificate systems, thereby improving the constraint of "the user needs to have other keys for the fleet vehicle" when the user uses the vehicle for the first time and creates a digital key for the user's device during the use of traditional fleet vehicle digital keys. This can better improve the user's car-using experience and the convenience of fleet vehicle management.

[0210] With the above Figures 5 to 10 Corresponding to the method provided in the embodiment, the present application also provides a digital key creation device. Since the digital key creation device provided in the embodiment of the present application is similar to the above-mentioned Figures 5 to 10 The method provided in the embodiment corresponds to the method provided in the embodiment, so the implementation method of the above method is also applicable to the digital key creation device provided in the embodiment of the present application, and will not be described in detail in the embodiment of the present application.

[0211] Figure 16 A schematic diagram of the structure of a digital key creation device provided in an embodiment of the present application.

[0212] like Figure 16 As shown, the digital key creation device 1600 can be applied to a target vehicle in a fleet, and includes: a receiving module 1610, a signature verification module 1620, a sending module 1630 and a determination module 1640.

[0213] The receiving module 1610 is configured to receive a terminal public key certificate sent by the target terminal; wherein the terminal public key certificate is obtained by signing the terminal public key of the target terminal using the fleet paired private key of the fleet paired public-private key pair associated with the target vehicle;

[0214] The signature verification module 1620 is used to verify the signature of the terminal public key certificate using the fleet pairing public key in the fleet pairing public-private key pair;

[0215] The sending module 1630 is used to send the vehicle public key certificate of the target vehicle to the target terminal when the signature verification is successful and the terminal public key is obtained;

[0216] The determination module 1640 is configured to determine, in response to receiving a signature verification success notification sent by the target terminal, whether the digital key corresponding to the target terminal and used to control the target vehicle has been successfully created.

[0217] In any embodiment of the present application, the signature verification success notification is sent in response to the successful signature verification of the vehicle public key certificate and the acquisition of the vehicle public key of the target vehicle.

[0218] Furthermore, in one implementation of the embodiment of the present application, the fleet pairing public key is obtained by the target vehicle using the following modules:

[0219] The first processing module is used to send a fleet vehicle registration application to the cloud; wherein the fleet vehicle registration application is used to register the vehicle on the cloud and generate a fleet pairing public key certificate for the target vehicle; receive and store the fleet pairing public key certificate sent by the cloud; use the cloud public key to verify the signature of the fleet pairing public key certificate to obtain the fleet pairing public key.

[0220] In one implementation of an embodiment of the present application, a fleet vehicle registration application is used to: verify the registration application information carried in the fleet vehicle registration application; if the verification is passed, register the registration application information and create a fleet pairing public-private key pair for the target vehicle; use a cloud private key to sign the fleet pairing public key in the fleet pairing public-private key pair to obtain a fleet pairing public key certificate; and send the fleet pairing public key certificate to the target vehicle.

[0221] In one implementation method of an embodiment of the present application, the vehicle public key certificate is obtained by signing the vehicle public key using the cloud private key in the cloud; the successful signature verification notification is that the target terminal verifies the vehicle public key certificate using the cloud public key, and when the verification is successful and the vehicle public key is obtained, it is sent to the target vehicle.

[0222] In one implementation of the embodiment of the present application, the cloud public key is obtained by the target vehicle using the following modules:

[0223] The second processing module is used to receive the cloud public key certificate sent by the cloud; wherein the cloud public key certificate is obtained by self-signing the cloud public key using the cloud private key; verify the signature of the cloud public key certificate; if the signature verification is successful, extract the cloud public key from the certificate body of the cloud public key certificate.

[0224] In one implementation of the embodiment of the present application, the digital key creation device 1600 further includes:

[0225] a deletion module, configured to delete the locally stored fleet pairing public key certificate and fleet pairing public key in response to removing the target vehicle from the fleet;

[0226] The sending module 1630 is further used to send a fleet vehicle cancellation application to the cloud in response to the fleet pairing public key certificate and the fleet pairing public key being deleted; wherein the fleet vehicle cancellation application is used by the cloud to delete the fleet pairing public-private key pair, the fleet pairing public key certificate and the registration application information associated with the target vehicle.

[0227] In the digital key creation device of the embodiment of the present application, by adding an additional digital key certificate chain to the vehicle digital key certificate system (for example, in addition to the existing cloud public key certificate, vehicle public key certificate and owner device public key certificate, the terminal public key certificate of the target terminal used by the vehicle user (or called the vehicle user device public key certificate), the fleet pairing public key certificate generated based on the fleet pairing public-private key pair, and issuing relevant certificates to the target terminal and target vehicle), it can be compatible with the ability to identify new digital key certificate systems, thereby improving the constraint of "the vehicle user needs to have other keys for the vehicle" when the vehicle user uses the vehicle for the first time and creates the digital key of the target terminal used by the vehicle user in the traditional fleet vehicle usage process, thereby improving the vehicle user experience and the convenience of fleet vehicle management.

[0228] With the above Figures 11 to 15 Corresponding to the method provided in the embodiment, the present application also provides a digital key creation device. Since the digital key creation device provided in the embodiment of the present application is similar to the above-mentioned Figures 11 to 15 The method provided in the embodiment corresponds to the method provided in the embodiment, so the implementation method of the above method is also applicable to the digital key creation device provided in the embodiment of the present application, and will not be described in detail in the embodiment of the present application.

[0229] Figure 17 A schematic diagram of the structure of another digital key creation device provided in an embodiment of the present application.

[0230] like Figure 17 As shown, the digital key creation device 1700 can be applied to the target terminal, including: a sending module 1710, a receiving module 1720 and a signature verification module 1730.

[0231] The sending module 1710 is configured to send a terminal public key certificate to a target vehicle in the fleet; the terminal public key certificate is obtained by signing the terminal public key of the target terminal using the fleet paired private key of the fleet paired public-private key pair associated with the target vehicle;

[0232] Receiving module 1720 is configured to receive a vehicle public key certificate sent by a target vehicle; wherein the vehicle public key certificate is generated by the target vehicle using the fleet paired public key in the fleet paired public-private key pair to verify the signature of the terminal public key certificate, and is sent when the signature verification is successful and the terminal public key is obtained;

[0233] The signature verification module 1730 is used to verify the signature of the vehicle public key certificate;

[0234] The sending module 1710 is further configured to send a signature verification success notification to the target vehicle if the signature verification is successful and the vehicle public key of the target vehicle is obtained.

[0235] In any embodiment of the present application, the signature verification success notification is used to notify the target terminal that the corresponding digital key for controlling the target vehicle has been successfully created.

[0236] In one implementation of the embodiment of the present application, the sending module 1710 is further configured to: send a digital key creation request for the target vehicle to the cloud; wherein the digital key creation request carries the terminal public key, which is used by the cloud to verify the digital key creation request and, if the verification is successful, sign the terminal public key with the fleet paired private key to obtain a terminal public key certificate;

[0237] The receiving module 1720 is further used to: receive the terminal public key certificate sent by the cloud in response to the digital key creation request.

[0238] In one implementation of an embodiment of the present application, the digital key creation request carries at least one of the following information: account information of the target terminal; vehicle information of the target vehicle; application information of the target terminal for the digital key; and business information associated with the target terminal in the business scenario to which the fleet belongs.

[0239] In one implementation of the embodiment of the present application, the vehicle public key certificate is obtained by signing the vehicle public key using the cloud private key in the cloud; the signature verification module 1730 is used to: verify the vehicle public key certificate using the cloud public key.

[0240] In one implementation of the embodiment of the present application, the cloud public key is obtained by the target terminal using the following modules:

[0241] The processing module is used to receive the cloud public key certificate sent by the cloud; wherein the cloud public key certificate is obtained by self-signing the cloud public key using the cloud private key; verify the signature of the cloud public key certificate; if the signature verification is successful, extract the cloud public key from the certificate body of the cloud public key certificate.

[0242] The digital key creation device of the embodiment of the present application can be compatible with the ability to identify new digital key certificate systems by adding an additional digital key certificate chain to the vehicle digital key certificate system (for example, in addition to the existing cloud public key certificate, vehicle public key certificate and owner device public key certificate, a terminal public key certificate of the target terminal used by the vehicle user (or called the vehicle user device public key certificate), a fleet pairing public key certificate generated based on the fleet pairing public-private key pair, and issuing relevant certificates to the target terminal and target vehicle). This improves the constraint of "the vehicle user needs to have other keys for the vehicle" when the vehicle user uses the vehicle for the first time and creates the digital key of the target terminal used by the vehicle user during the use of digital keys for traditional fleet vehicles, thereby improving the vehicle user experience and the convenience of fleet vehicle management.

[0243] In order to implement the above embodiments, the present application also proposes an electronic device, including a memory, a processor, and a computer program stored in the memory and runnable on the processor. When the processor executes the program, it implements the method for creating a digital key as described in any of the above embodiments.

[0244] In order to implement the above embodiments, the present application also proposes a non-temporary computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the method for creating a digital key as described in any of the above embodiments is implemented.

[0245] In order to implement the above embodiments, the present application also proposes a computer program product on which a computer program is stored. When the computer program is executed by a processor, it implements the method for creating a digital key as described in any of the above embodiments.

[0246] Figure 18 FIG1 is a block diagram illustrating a target vehicle 1800 according to an exemplary embodiment. For example, target vehicle 1800 may be a hybrid vehicle, a non-hybrid vehicle, an electric vehicle, a fuel cell vehicle, or another type of vehicle. Target vehicle 1800 may be an autonomous vehicle, a semi-autonomous vehicle, or a non-autonomous vehicle.

[0247] Reference Figure 18Target vehicle 1800 may include various subsystems, such as an infotainment system 1810, a perception system 1820, a decision control system 1830, a drive system 1840, and a computing platform 1850. Target vehicle 1800 may also include more or fewer subsystems, and each subsystem may include multiple components. Furthermore, each subsystem and each component of target vehicle 1800 may be interconnected via wired or wireless means.

[0248] In some embodiments, the infotainment system 1810 may include a communication system, an entertainment system, a navigation system, and the like.

[0249] The perception system 1820 may include several sensors for sensing information about the environment surrounding the target vehicle 1800. For example, the perception system 1820 may include a global positioning system (which may be a GPS system, a BeiDou system, or other positioning systems), an inertial measurement unit (IMU), a laser radar, a millimeter-wave radar, an ultrasonic radar, and a camera.

[0250] The decision control system 1830 may include a computing system, a vehicle controller, a steering system, a throttle, and a braking system.

[0251] Drive system 1840 may include components that provide powered motion for target vehicle 1800. In one embodiment, drive system 1840 may include an engine, an energy source, a transmission system, and wheels. The engine may be one or a combination of an internal combustion engine, an electric motor, and an air compression engine. The engine is capable of converting energy provided by the energy source into mechanical energy.

[0252] Some or all functions of the target vehicle 1800 are controlled by a computing platform 1850. The computing platform 1850 may include at least one processor 1851 and a memory 1852. The processor 1851 may execute instructions 1853 stored in the memory 1852.

[0253] The processor 1851 can be any conventional processor, such as a commercially available CPU. The processor can also include a graphics processor (GPU), a field programmable gate array (FPGA), a system on chip (SOC), an application specific integrated circuit (ASIC), or a combination thereof.

[0254] Memory 1852 can be implemented by any type of volatile or non-volatile memory device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.

[0255] In addition to instructions 1853 , memory 1852 may also store data, such as road maps, route information, and vehicle location, direction, speed, etc. The data stored in memory 1852 may be used by computing platform 1850 .

[0256] In an embodiment of the present application, the processor 1851 may execute instruction 1853 to complete all or part of the steps of the above-mentioned method embodiment.

[0257] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification and features of different embodiments or examples without contradiction.

[0258] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of such features. Throughout the description of this application, "plurality" means at least two, for example, two, three, etc., unless otherwise specifically defined.

[0259] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code comprising one or more executable instructions for implementing the steps of a custom logical function or process, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may be performed out of the order shown or discussed, including performing functions in a substantially simultaneous manner or in the reverse order depending on the functions involved, which should be understood by those skilled in the art to which the embodiments of the present application belong.

[0260] The logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection with one or more wires (electronic devices), a portable computer disk cartridge (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and programmable read-only memory (EPROM or flash memory), fiber optic devices, and a portable compact disc read-only memory (CDROM). Furthermore, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium and then editing, interpreting or processing it in another suitable manner if necessary, and then storing it in a computer memory.

[0261] It should be understood that various parts of the present application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used to implement: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0262] Those skilled in the art will understand that all or part of the steps in the method of the above embodiment can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiment.

[0263] In addition, the functional units in the various embodiments of the present application may be integrated into a processing module, or each unit may exist physically separately, or two or more units may be integrated into a module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.

[0264] The storage medium mentioned above may be a read-only memory, a magnetic disk, or an optical disk, etc. Although the embodiments of the present application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present application. Persons skilled in the art may make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present application.

Claims

1. A method for creating a digital key, characterized in that: Target vehicles used in fleets include: When the target terminal approaches the target vehicle, a terminal public key certificate sent by the target terminal is received; wherein the terminal public key certificate is obtained by signing the terminal public key of the target terminal using the fleet pairing private key of the fleet pairing public-private key pair associated with the target vehicle. The fleet pairing public-private key pair is a public-private key pair generated or created by the cloud for the target vehicle when the target vehicle performs a fleet vehicle registration action; Using the fleet pairing public key in the fleet pairing public-private key pair to verify the signature of the terminal public key certificate; If the signature verification is successful and the terminal public key is obtained, the vehicle public key certificate of the target vehicle is sent to the target terminal; In response to receiving the signature verification success notification sent by the target terminal, it is determined that the digital key corresponding to the target terminal for controlling the target vehicle is successfully created.

2. The method according to claim 1, characterized in that The fleet pairing public key is obtained by the target vehicle through the following steps: Sending a fleet vehicle registration application to the cloud; wherein the fleet vehicle registration application is used to register the vehicle on the cloud and generate a fleet pairing public key certificate for the target vehicle; Receiving and storing the fleet pairing public key certificate sent by the cloud; The cloud public key is used to verify the signature of the fleet pairing public key certificate to obtain the fleet pairing public key.

3. The method according to claim 2, characterized in that The fleet vehicle registration application is used to: Verify the registration application information contained in the fleet vehicle registration application; If the verification is passed, register the registration application information and create the fleet paired public and private key pair for the target vehicle; Using the cloud private key, sign the fleet pairing public key in the fleet pairing public-private key pair to obtain the fleet pairing public key certificate; Send the fleet pairing public key certificate to the target vehicle.

4. The method according to claim 1, wherein The vehicle public key certificate is obtained by signing the vehicle public key using the cloud private key in the cloud; The signature verification success notification is sent to the target vehicle when the target terminal verifies the vehicle public key certificate using the cloud public key and obtains the vehicle public key after the signature verification is successful.

5. The method according to claim 4, characterized in that The cloud public key is obtained by the target vehicle using the following steps: Receiving a cloud public key certificate sent by the cloud; wherein the cloud public key certificate is obtained by self-signing the cloud public key using the cloud private key; Verify the signature of the cloud public key certificate; If the signature verification is successful, the cloud public key is extracted from the certificate body of the cloud public key certificate.

6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: In response to removing the target vehicle from the fleet, deleting the locally stored fleet pairing public key certificate and the fleet pairing public key; In response to the fleet pairing public key certificate and the fleet pairing public key being deleted, sending a fleet vehicle cancellation application to the cloud; The fleet vehicle cancellation application is used by the cloud to delete the fleet pairing public-private key pair, the fleet pairing public key certificate, and registration application information associated with the target vehicle.

7. A method for creating a digital key, characterized in that: Applied to target terminals, including: When the target terminal approaches the target vehicle, a terminal public key certificate is sent to the target vehicle in the fleet; wherein the terminal public key certificate is obtained by signing the terminal public key of the target terminal using the fleet pairing private key of the fleet pairing public-private key pair associated with the target vehicle, and the fleet pairing public-private key pair is a public-private key pair generated or created by the cloud for the target vehicle when the target vehicle performs a fleet vehicle registration action; Receive a vehicle public key certificate sent by the target vehicle; wherein the vehicle public key certificate is sent by the target vehicle when the target vehicle verifies the signature of the terminal public key certificate using the fleet pairing public key in the fleet pairing public-private key pair and obtains the terminal public key; The vehicle public key certificate is signature-verified, and if the signature verification is successful and the vehicle public key of the target vehicle is obtained, a signature verification success notification is sent to the target vehicle.

8. The method according to claim 7, characterized in that Before sending the terminal public key certificate to the target vehicle in the fleet, the method further includes: Sending a digital key creation request for the target vehicle to the cloud; wherein the digital key creation request carries the terminal public key, which is used by the cloud to verify the digital key creation request and, if the verification is successful, sign the terminal public key with the fleet paired private key to obtain the terminal public key certificate; Receive the terminal public key certificate sent by the cloud in response to the digital key creation request.

9. The method according to claim 8, characterized in that The digital key creation request carries at least one of the following information: Account information of the target terminal; Vehicle information of the target vehicle; Application information of the target terminal for the digital key; Business information associated with the target terminal in the business scenario to which the fleet belongs.

10. The method according to any one of claims 7 to 9, characterized in that The vehicle public key certificate is obtained by signing the vehicle public key using the cloud private key in the cloud; The verifying the signature of the vehicle public key certificate includes: The cloud public key is used to verify the signature of the vehicle public key certificate.

11. The method according to claim 10, characterized in that The cloud public key is obtained by the target terminal through the following steps: Receiving a cloud public key certificate sent by the cloud; wherein the cloud public key certificate is obtained by self-signing the cloud public key using the cloud private key; Verify the signature of the cloud public key certificate; If the signature verification is successful, the cloud public key is extracted from the certificate body of the cloud public key certificate.

12. A device for creating a digital key, characterized in that: Target vehicles used in fleets include: a receiving module, configured to receive a terminal public key certificate sent by the target terminal when the target terminal approaches the target vehicle; wherein the terminal public key certificate is obtained by signing the terminal public key of the target terminal using a fleet pairing private key of a fleet pairing public-private key pair associated with the target vehicle, the fleet pairing public-private key pair being a public-private key pair generated or created by the cloud for the target vehicle when the target vehicle performs a fleet vehicle registration action; a signature verification module, configured to verify the signature of the terminal public key certificate using the fleet pairing public key in the fleet pairing public-private key pair; A sending module, configured to send the vehicle public key certificate of the target vehicle to the target terminal when the signature verification is successful and the terminal public key is obtained; A determination module is used to determine that the digital key corresponding to the target terminal for controlling the target vehicle is successfully created in response to receiving a signature verification success notification sent by the target terminal.

13. A digital key creation device, characterized in that: Applied to target terminals, including: a sending module, configured to send a terminal public key certificate to a target vehicle in a fleet when the target terminal approaches the target vehicle; wherein the terminal public key certificate is obtained by signing the terminal public key of the target terminal using a fleet pairing private key from a fleet pairing public-private key pair associated with the target vehicle, the fleet pairing public-private key pair being a public-private key pair generated or created by the cloud for the target vehicle when the target vehicle performs a fleet vehicle registration action; a receiving module, configured to receive a vehicle public key certificate sent by the target vehicle; wherein the vehicle public key certificate is sent by the target vehicle when the target vehicle verifies the signature of the terminal public key certificate using the fleet pairing public key in the fleet pairing public-private key pair and obtains the terminal public key upon successful verification; A signature verification module, used to verify the signature of the vehicle public key certificate; The sending module is further configured to send a signature verification success notification to the target vehicle when the signature verification is successful and the vehicle public key of the target vehicle is obtained.

14. An electronic device, characterized in that: include: processor; a memory for storing processor-executable instructions; Wherein, the processor is configured to: Implement the steps of the method according to any one of claims 1 to 6, or implement the steps of the method according to any one of claims 7 to 11.

15. A non-transitory computer-readable storage medium, which, when the instructions in the storage medium are executed by a processor of an electronic device, enables the processor to perform the steps of the method described in any one of claims 1 to 6, or the steps of the method described in any one of claims 7 to 11.

16. A computer program product, characterized in that The invention comprises a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 6, or implements the method according to any one of claims 7 to 11.

Citation Information

Patent Citations

  • Digital key sharing method and device, terminal equipment, vehicle and storage medium

    CN115734223A