Security login system and method of vehicle-mounted network equipment
By introducing a secure login system with multi-modal authentication, situational awareness and layered permission management in vehicle network devices, the security vulnerabilities and insufficient user experience of traditional vehicle network devices are solved, more accurate identity verification and intelligent permission management are achieved, and the security and user experience of the system are improved.
Patent Information
- Application Number
- CN202510518251.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-05-27
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The secure login method of traditional vehicle network devices is prone to security vulnerabilities and insufficient user experience, especially when authorization is authorized between different users, equal weights lead to easy stolen vehicle information.
It provides a secure login system for on-board network equipment, including a multi-modal identity verification unit, a situational awareness unit and a hierarchical permission management unit. Through various authentication methods such as biometric recognition, voiceprint recognition, key/mobile phone near-field perception and dynamic token encryption, combined with dynamic risk level adjustment and abnormal behavior monitoring, the functional permissions of on-board network equipment are dynamically allocated.
Through multi-modal authentication, drivers are accurately identified, and different usage permissions are intelligently provided according to situational awareness and layered permission management. After the authorized user's driving permission is deactivated, they will automatically switch to the autonomous driving mode and park safely, improving the security and user experience of on-board network equipment.
Smart Images

Figure CN120050658A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network communication security technology, and in particular to a security login system and method for vehicle-mounted network equipment. Background Art
[0002] The secure login of in-vehicle network devices involves multiple systems inside the vehicle, such as the infotainment system, the Internet of Vehicles module, and even parts related to autonomous driving; the traditional password login method is easy to be stolen, or the applicability of biometrics in the in-vehicle environment. There may be different users in the car, such as the owner, family, and friends. When using in-vehicle network devices, it is necessary to distinguish the usage permissions of different users according to their needs.
[0003] In the relevant existing technologies, the commonly used secure login method for in-vehicle network devices is to log in directly through an account and password. After login, the user's identity is confirmed separately through face recognition or fingerprint recognition. After confirmation, the vehicle's use rights are managed and authorized by the preset user with unified specifications.
[0004] With the existing driving authority management method, different users can enjoy the same weight when authorizing each other, so when the vehicle is temporarily used by others, the vehicle's input information and driving information can be easily stolen by others; resulting in security vulnerabilities and insufficient user experience in traditional vehicle network equipment and systems.
[0005] Therefore, it is necessary to provide a secure login system for an in-vehicle network device to solve the above technical problems. Summary of the invention
[0006] The present invention provides a secure login system for an in-vehicle network device, which solves the problem in the related art that traditional in-vehicle network devices and systems are prone to security vulnerabilities and insufficient user experience.
[0007] In order to solve the above technical problems, the present invention provides a secure login system for an in-vehicle network device, comprising: User login module, driving mode module, human-machine association module, control recording module, road condition analysis module and fatigue detection module; The user login module includes a multimodal identity authentication unit, a context perception unit, and a hierarchical authority management unit. The multimodal identity authentication unit is used to identify and verify the identity of the driver and assign a driving weight according to the identity authentication result; the context perception unit is used to analyze the network connection status of the current driving environment and analyze the abnormal status of the driving environment; the hierarchical authority management unit is used to allocate different login usage modes of the vehicle-mounted network device; The driving mode module is used to preset the online management of the driving mode authority of the vehicle network device after the vehicle owner remotely logs into the terminal platform; The human-machine association module is used to manage the human-machine association rights of the vehicle network device online after the vehicle owner remotely logs into the terminal platform; The control record module is used to manage the control records of the vehicle network equipment online after the vehicle owner remotely logs into the terminal platform; The traffic condition analysis module is used to manage the traffic condition information of the vehicle network device online after the vehicle owner remotely logs into the terminal platform; The fatigue detection module is used to preset the vehicle owner to remotely log into the terminal platform to perform online management of fatigue detection of the vehicle network equipment.
[0008] Preferably, the multimodal identity authentication unit includes biometric recognition, voiceprint recognition, key / mobile phone near-field sensing and dynamic token encryption, and the biometric recognition, voiceprint recognition, key / mobile phone near-field sensing and dynamic token encryption are respectively used to identify the driving weight of the current driver.
[0009] Preferably, the priority of the biometric recognition is greater than the priority of the voiceprint recognition, greater than the priority of the key / mobile phone near-field sensing, and greater than the priority of the dynamic token encryption.
[0010] Preferably, the situational awareness unit includes dynamic adjustment of risk levels and abnormal behavior monitoring; The risk level is dynamically adjusted according to the network environment in which the vehicle network device is currently located, and the verification process is dynamically adjusted; The abnormal behavior monitoring analyzes abnormal login attempts through the on-board AI chip and automatically triggers the abnormal defense mechanism of the on-board network equipment.
[0011] Preferably, the hierarchical authority management unit includes role-based authority allocation, temporary authority allocation and driving authority management, wherein the role-based authority allocation dynamically allocates functional authority of the vehicle network device according to the preset roles of the vehicle owner, family member, visitor and maintenance mode; The temporary authority allocation is preset by the car owner on the terminal platform, through online generation of a temporary digital key and sending it to the visitor terminal, the digital key includes the validity period and the map fence; The driving authority management is used to disable high-risk operations during vehicle driving online by presetting the authorized items that the vehicle owner can remotely manage on-board network devices during driving.
[0012] Preferably, when the logged-in user of the in-vehicle network device is the preset car owner, he or she enjoys the in-vehicle network, map driving range modification, function permission setting and modification, manual driving, automatic driving and one-button start.
[0013] Preferably, when the logged-in user of the in-vehicle network device is a family member, he or she enjoys the permissions of the in-vehicle network, driving within a preset map range, manual driving, and automatic driving, and can open the car door normally, but the vehicle start-up requires remote online authorization by the preset owner, and the preset owner can manage the permissions of the running vehicle online through the terminal platform.
[0014] Preferably, when the logged-in user of the vehicle network device is a visitor, he or she only has the authority to drive manually; the identity authentication of the vehicle network device and the start-up of the vehicle both require the preset remote online authorization of the owner, and safe driving must be performed within the permitted map driving range; visitors are only allowed to browse maps and play media through the mobile network.
[0015] Preferably, the user login module further includes a privacy data protection unit and a security protection unit. The privacy data protection unit includes localized encrypted storage, anonymized communication and user data sovereignty. The localized encrypted storage is used for local storage of biometric data; the anonymized communication is used for Internet of Vehicles communication using a pseudonym certificate; the user data sovereignty provides a blockchain audit interface, and the user can view / revoke data authorization at any time; The security protection unit uses secure startup and a trusted execution environment to isolate key processes, and the system uses differential encryption upgrade packages and dual partition backup.
[0016] The present invention also provides a secure login method, which uses the secure login system of the vehicle-mounted network device to perform identity authentication, authorization and secure login on the user.
[0017] Compared with the related art, the secure login system for the vehicle network device provided by the present invention has the following beneficial effects: Multimodal authentication is used to conveniently and accurately identify drivers. After identification, different usage permissions are intelligently provided to users based on the situational awareness unit and the hierarchical permission management unit. When an authorized user is driving, the preset user is allowed to remotely switch driving permissions and enjoy direct control permissions. After the authorized user's driving permissions are revoked, the manual driving mode automatically switches to the automatic driving mode and the parking brake is applied safely. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the structures shown in these drawings without paying creative work.
[0019] Figure 1 A system diagram of a first embodiment of a secure login system for an in-vehicle network device provided by the present invention; Figure 2 for Figure 1 The system block diagram of the user login module shown; Figure 3 for Figure 2 A system block diagram of a multimodal authentication unit is shown; Figure 4 for Figure 2 The system block diagram of the situational awareness unit shown; Figure 5 for Figure 2 The system block diagram of the hierarchical rights management unit shown; Figure 6 A system diagram of a second embodiment of a secure login system for an in-vehicle network device provided by the present invention; Figure 7 for Figure 6 The system block diagram of the privacy data protection unit shown; Figure 8 for Figure 6 The system block diagram of the safety protection unit shown; Fig. 9 for Figure 6 A system block diagram of a multimodal authentication unit is shown.
[0020] The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0021] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0022] The invention provides a safe login system for vehicle-mounted network equipment.
[0023] First embodiment:
[0024] Please refer to Figures 1 to 4 In a first embodiment of the present invention, a secure login system for an in-vehicle network device includes: User login module, driving mode module, human-machine association module, control recording module, road condition analysis module and fatigue detection module; The user login module includes a multimodal identity authentication unit, a context perception unit and a hierarchical authority management unit. The multimodal identity authentication unit is used to identify and verify the identity of the driver and assign a driving weight according to the identity authentication result; the context perception unit is used to analyze the network connection status of the current driving environment and analyze the abnormal status of the driving environment; the hierarchical authority management unit is used to allocate different login usage modes of the vehicle network device; The driving mode module is used to preset the online management of the driving mode authority of the vehicle network device after the vehicle owner remotely logs into the terminal platform; The human-machine association module is used to manage the human-machine association rights of the vehicle network device online after the vehicle owner remotely logs into the terminal platform; The control record module is used to manage the control records of the vehicle network equipment online after the vehicle owner remotely logs into the terminal platform; The traffic condition analysis module is used to manage the traffic condition information of the vehicle network device online after the vehicle owner remotely logs into the terminal platform; The fatigue detection module is used to preset the vehicle owner to remotely log into the terminal platform to perform online management of fatigue detection of the vehicle network equipment.
[0025] In this embodiment, the driving mode module, the human-machine association module, the control recording module, the road condition analysis module and the fatigue detection module are integrated on a terminal management platform (cloud platform) to provide support for remote weight management and authorization of the vehicle network terminal; the terminal user logs in to the terminal management platform through a preset user ID and password verification, and the terminal management platform and the vehicle network device are connected through a network signal to provide the terminal user with remote authorization management and related information query and management.
[0026] In this embodiment, the driving modes include manual driving, automatic driving and map area management, and manual driving is used to authorize the current driver to use manual driving; Autonomous driving is used to authorize the current driver to use autonomous driving; Map area management is used to change the map area that the current driver can drive, so that the vehicle can only drive safely within the preset map area. When the preset map area is exceeded, the autonomous driving vehicle sends an early warning to the terminal management platform and notifies the terminal user. The terminal user remotely revokes the current driver's permission, and the on-board network equipment can be adjusted to the autonomous driving mode and the destination can be reset.
[0027] For a vehicle in motion, while the on-board network device controls the vehicle to switch from manual driving mode to autonomous driving mode, the vehicle automatically turns on the hazard lights and slowly decelerates and brakes to the edge of the lane.
[0028] In this embodiment, the control record is the driver behavior information recorded by the vehicle network device during operation; Traffic condition information refers to surrounding traffic conditions and road information recorded by the vehicle network device during operation; Fatigue monitoring is an on-board network device that uses the on-board camera and driving time to analyze whether the current driver is driving fatigued.
[0029] Multimodal authentication is used to conveniently and accurately identify drivers. After identification, different usage permissions are intelligently provided to users based on the situational awareness unit and the hierarchical permission management unit. When an authorized user is driving, the preset user is allowed to remotely switch driving permissions and enjoy direct control permissions. After the authorized user's driving permissions are revoked, the manual driving mode automatically switches to the automatic driving mode and the parking brake is applied safely.
[0030] Please refer again Figure 3 Furthermore, the multimodal identity authentication unit includes biometric recognition, voiceprint recognition, key / mobile phone near-field sensing and dynamic token encryption, and the biometric recognition, voiceprint recognition, key / mobile phone near-field sensing and dynamic token encryption are used to identify the driving weight of the current driver.
[0031] Biometrics: Combination of in-car cameras and infrared sensors: supports 3D facial recognition (anti-photo / video spoofing) and liveness detection (such as blinking, micro-expression analysis); Door and steering wheel fingerprint sensor combination: adopts high-precision capacitive fingerprint module and supports multi-user pre-storage; While the driver is holding the steering wheel, the fingerprint sensor continues to identify and compare the driver's fingerprint, achieving dual identification and authentication of the door opening user and the driver.
[0032] Voiceprint recognition: The vehicle microphone collects user voice commands (such as custom wake-up words) and analyzes the driver's voiceprint characteristics for rapid voiceprint recognition of the driver, providing support for subsequent use of voice functions.
[0033] Mobile phone / key near-field sensing: Based on UWB technology, user devices are accurately located to prevent relay attacks.
[0034] Dynamic token encryption: The user generates a one-time dynamic key (synchronized with the vehicle system time) through the terminal platform and must complete the verification within the preset time.
[0035] It enables the in-vehicle network equipment to meet the needs of keyless remote start, keyless authorized driving, and remote management of permissions; reduces the necessity of near-field sensing unlocking with keys / mobile phones (even if the keys are not brought, remote management and authorization of in-vehicle network equipment usage permissions can be provided to users in need), and improves the convenience of users' remote management of in-vehicle network equipment weights.
[0036] It provides users with a multi-modal identity authentication method and can continue to verify the driver's identity after the car door is opened to ensure accurate identification and recording of the driver's identity; avoiding unauthorized driving due to the door opener being different from the driver.
[0037] Furthermore, the priority of the biometric recognition is greater than the priority of the key / mobile phone near-field sensing, greater than the priority of the dynamic token encryption, and greater than the priority of the voiceprint recognition.
[0038] In this embodiment, when the biometric identification is authenticated as an authorized user, the login and activation of the vehicle network device can be realized without the need for key / mobile phone near-field sensing and dynamic token encryption, and the door can be opened automatically, and the vehicle network device registers the user's identity, fingerprint information, and door opening time; When the in-vehicle network device receives the vehicle start signal, if the authorized user is not the vehicle owner, the vehicle owner is required to perform secondary authorization to start the vehicle (if the vehicle is continuously running and has not been shut down for more than the preset time (within half an hour), the vehicle does not require secondary authorization when it is restarted. If the preset time is exceeded, secondary authorization is required again), providing support for vehicle safety authorization and driving; If the authorized user is the car owner himself, the in-vehicle network device will directly start the vehicle.
[0039] It facilitates quick identification of authorized users, enables true keyless entry and vehicle start-up, and provides support for rapid vehicle identification.
[0040] Please refer again Figure 4 ,Further, the situation awareness unit includes dynamic adjustment of risk level and abnormal ,behavior monitoring; The risk level is dynamically adjusted according to the network environment in which the vehicle network device is currently located, and the verification process is dynamically adjusted; The abnormal behavior monitoring analyzes abnormal login attempts through the on-board AI chip and automatically triggers the abnormal defense mechanism of the on-board network equipment.
[0041] Dynamic adjustment of risk level: If the vehicle network device is in the home garage and connected to private WiFi, the system automatically determines that the vehicle is in a low-risk scenario: the verification process is simplified, and only one verification requirement is required (authorized users included in the records; if unauthorized users, multi-factor verification is required) to log in to the vehicle network device.
[0042] If the vehicle's network device is in an unfamiliar geographical location / a network attack environment is detected, the system automatically determines that the vehicle is in a high-risk scenario: triggering multi-factor verification (if the vehicle is not the owner), the fingerprint + voiceprint + dynamic key verification requirements must be met at the same time.
[0043] Real-time monitoring of abnormal behavior: The on-board AI chip analyzes frequent password errors and unfamiliar device access, determines that the device is in an abnormal login attempt, and automatically triggers the defense mechanism. The defense mechanism can lock the on-board network device and send an alarm message to the terminal platform.
[0044] See also Figure 5 ,Furthermore, the hierarchical authority management unit includes role-based authority allocation, temporary authority allocation and driving authority management, and the role-based authority allocation dynamically allocates functional authority of the vehicle network device according to the preset roles of the vehicle owner, family member, visitor, and maintenance mode; The temporary authority allocation is preset by the car owner on the terminal platform, through online generation of a temporary digital key and sending it to the visitor terminal, the digital key includes the validity period and the map fence; The driving authority management is used to disable high-risk operations during vehicle driving online by presetting the authorized items that the vehicle owner can remotely manage on-board network devices during driving.
[0045] Furthermore, when the logged-in user of the in-vehicle network device is the preset car owner, he or she enjoys the in-vehicle network, map driving range modification, function permission setting and modification, manual driving, automatic driving and one-button start.
[0046] When the logged-in user of the in-vehicle network device is a family member, he or she enjoys the permissions of the in-vehicle network, driving within the preset map range, manual driving, and automatic driving, and can open the car door normally, but the vehicle start requires remote online authorization by the preset owner, and the preset owner can manage the permissions of the running vehicle online through the terminal platform.
[0047] When the logged-in user of the in-vehicle network device is a visitor, he or she only has the authority to drive manually; the identity authentication of the in-vehicle network device (digital key-QR code) and the start-up of the vehicle both require the preset remote online authorization of the owner, and safe driving must be performed within the permitted map driving range; visitors are only allowed to browse maps and play media through the mobile network.
[0048] In this embodiment, the preset car owner has the right to log in to the terminal platform and the ownership of the in-vehicle network device. Only the preset car owner has the right to enter the quick start and log in to the in-vehicle network device, and has the management and authorization of family members, visitors and maintenance mode.
[0049] Family members are entered and authorized by the preset car owner, and the permissions they can use are managed and modified on the terminal platform according to the preset car owner. When family members log in to the in-vehicle network device and use it, the preset car needs to be remotely started on the terminal platform before they can authorize and start the vehicle through the in-vehicle network device.
[0050] The preset car owner generates a temporary digital key for the visitor, granting the visitor temporary access to the vehicle's in-vehicle network equipment and the vehicle. The scope of this access is managed and authorized by the preset car owner (such as restricting the visitor's access to the vehicle's OBD interface). After authorization, the visitor needs to complete the use of the vehicle within the authorization period, otherwise it will automatically enter the automatic driving mode and stop at the edge of the road with double flashes, and the preset car owner needs to authorize the visitor again to continue driving.
[0051] The maintenance mode is authorized online by the preset vehicle owner through the terminal platform to facilitate the maintenance user to manage the vehicle.
[0052] It is convenient to assign corresponding usage weights according to different roles, and can remotely monitor the vehicle driving conditions and risks recorded when the vehicle network equipment is running; automatically disable high-risk operations (such as firmware upgrades, changes in driving users) during vehicle driving.
[0053] By integrating hardware security, behavioral analysis and dynamic strategies, the authentication method of in-vehicle network devices is redefined, taking into account both security and user-friendly experience.
[0054] Application scenarios: Personal passenger cars, shared car fleets, unmanned delivery vehicles, special operation vehicles, etc.
[0055] Second embodiment:
[0056] Please refer to Figures 6 to 8 Based on the secure login system for an in-vehicle network device provided by the first embodiment of the present invention, the second embodiment of the present invention provides another secure login system for an in-vehicle network device. The second embodiment is only a preferred embodiment of the first embodiment, and the implementation of the second embodiment will not affect the independent implementation of the first embodiment.
[0057] Specifically, the security login system of the vehicle network device provided by the second embodiment of the present invention is different in that the user login module also includes a privacy data protection unit and a security protection unit, the privacy data protection unit includes localized encrypted storage, anonymized communication and user data sovereignty, the localized encrypted storage is used for local storage of biometric data; the anonymized communication is used for vehicle network communication using a pseudonym certificate; the user data sovereignty provides a blockchain audit interface, and the user can view / revoke data authorization at any time; The security protection unit uses secure startup and a trusted execution environment to isolate key processes, and the system uses differential encryption upgrade packages and dual partition backup.
[0058] Local encrypted storage: Biometric data is only stored in the vehicle's security chip (eSE / TEE) and is not uploaded to the cloud; Anonymized communications: Vehicle-to-everything (V2X) communications use pseudonymous certificates that are changed regularly to protect user trajectory privacy; User data sovereignty: Provides a blockchain audit interface, allowing users to review / revoke data authorization at any time.
[0059] Hardware protection (security protection unit): Secure Boot (SecureBoot) + Trusted Execution Environment (TEE) isolates key processes; OTA security update (security protection unit): Differential encryption upgrade package + dual partition backup (the system automatically rolls back if the upgrade fails).
[0060] While achieving privacy enhancement, it also meets the needs of data protection, provides security for users' privacy data, and avoids data leakage.
[0061] See also Fig. 9 Furthermore, the multimodal authentication unit also includes hierarchical downgrade, which can enable "emergency driving mode" through the key when biometric identification fails.
[0062] When the mobile phone is out of power / biometric recognition cannot be used normally, after the user enters the vehicle with the key, the user needs to wait for a preset time (5 minutes / 10 minutes) after being recognized by the on-board network device and there is no feedback from the terminal platform. The on-board network device automatically enters the emergency driving mode. In the emergency driving mode, the user is only provided with navigation to the destination within the preset map range (charging place, home place and surrounding shopping mall place), and the driving mode is manual driving.
[0063] When the on-board network device analyzes and determines that the current vehicle is driving in the direction of the original destination for 5 minutes, the on-board network device turns off the emergency driving mode and enters the automatic driving mode until it safely stops at the edge of the road.
[0064] You need to repeat the above operation to enter the emergency driving mode. After the emergency driving mode is automatically closed after two repetitions, the vehicle will lock itself and you need to contact the terminal platform administrator by phone (supermarket / passerby's mobile phone) to confirm that the driving user is the preset user (ID card and related verification information) and that the biometric recognition fails and the mobile phone cannot be authorized. The terminal platform administrator can remotely lift the restrictions on the current vehicle and provide remote management and authorization support for some extreme usage conditions. The operators authorized for remote management need to be registered on the terminal platform. After registration, the administrator cannot delete the authorization record to facilitate the maintenance and management of the preset user's permissions.
[0065] The invention also provides a safe login method.
[0066] A secure login method uses the secure login system of the vehicle-mounted network device to authenticate, authorize and securely log in a user.
[0067] A1, when the car owner logs in: When the owner approaches the vehicle with an authorized terminal device, the vehicle network device locates the phone and automatically unlocks the door; After the owner gets in the car, facial recognition and steering wheel fingerprint verification are used to complete the seamless login within 5 seconds; A2, when a visitor uses the site temporarily: The car owner sends a temporary pass (authorization code, which can be identified and authenticated by the facial recognition camera) through the terminal device; After scanning the QR code, visitors must complete facial recognition and voiceprint verification before starting the vehicle; After pressing the start button, the car owner needs to remotely authorize the vehicle online again through the terminal. After authorization, the vehicle starts. After the visitor starts the vehicle, he cannot access the navigation history or address book and can only drive within the authorized map range. A3, attack response scenario: When the in-vehicle network device detects a relay attack from a fake Bluetooth key, the system automatically switches to defense mode: Disable wireless interfaces in defense mode and enforce physical fingerprint authentication; When the defense mode is activated, an encrypted alarm notification is sent to the car owner and the attack fingerprint is recorded in the blacklist.
[0068] The above description is only a preferred embodiment of the present invention, and does not limit the patent scope of the present invention. All equivalent structural changes made by using the contents of the present invention specification and drawings under the concept of the present invention, or directly / indirectly applied in other related technical fields are included in the patent protection scope of the present invention.
Claims
1. A secure login system for an in-vehicle network device, characterized in that: include: User login module, driving mode module, human-machine association module, control recording module, road condition analysis module and fatigue detection module; The user login module includes a multimodal identity authentication unit, a context perception unit, and a hierarchical authority management unit. The multimodal identity authentication unit is used to identify and verify the identity of the driver and assign a driving weight according to the identity authentication result; the context perception unit is used to analyze the network connection status of the current driving environment and analyze the abnormal status of the driving environment; The hierarchical authority management unit is used to allocate different login usage modes for the vehicle network device; The driving mode module is used to preset the online management of the driving mode authority of the vehicle network device after the vehicle owner remotely logs into the terminal platform; The human-machine association module is used to manage the human-machine association rights of the vehicle network device online after the vehicle owner remotely logs into the terminal platform; The control record module is used to manage the control records of the vehicle network equipment online after the vehicle owner remotely logs into the terminal platform; The traffic condition analysis module is used to manage the traffic condition information of the vehicle network device online after the vehicle owner remotely logs into the terminal platform; The fatigue detection module is used to preset the vehicle owner to remotely log into the terminal platform to perform online management of fatigue detection of the vehicle network equipment.
2. The secure login system for an in-vehicle network device according to claim 1, characterized in that: The multimodal identity authentication unit includes biometric recognition, voiceprint recognition, key / mobile phone near-field sensing and dynamic token encryption, and the biometric recognition, voiceprint recognition, key / mobile phone near-field sensing and dynamic token encryption are respectively used to identify the driving weight of the current driver.
3. The secure login system for vehicle-mounted network equipment according to claim 2, characterized in that: The priority of the biometric recognition>the priority of the voiceprint recognition>the priority of the key / mobile phone near-field sensing>the priority of the dynamic token encryption.
4. The secure login system for an in-vehicle network device according to claim 3, characterized in that: The situational awareness unit includes dynamic adjustment of risk levels and abnormal behavior monitoring; The risk level is dynamically adjusted according to the network environment in which the vehicle network device is currently located, and the verification process is dynamically adjusted; The abnormal behavior monitoring analyzes abnormal login attempts through the on-board AI chip and automatically triggers the abnormal defense mechanism of the on-board network equipment.
5. The secure login system for vehicle-mounted network equipment according to claim 4, characterized in that: The hierarchical authority management unit includes role-based authority allocation, temporary authority allocation and driving authority management. The role-based authority allocation dynamically allocates functional authority of the vehicle network device according to the preset roles of the vehicle owner, family member, visitor and maintenance mode; The temporary authority allocation is preset by the car owner on the terminal platform, through online generation of a temporary digital key and sending it to the visitor terminal, the digital key includes the validity period and the map fence; The driving authority management is used to disable high-risk operations during vehicle driving online by presetting the authorized items that the vehicle owner can remotely manage on-board network devices during driving.
6. The secure login system for an in-vehicle network device according to claim 5, characterized in that: When the logged-in user of the in-vehicle network device is the preset car owner, he or she has the right to use the in-vehicle network, map driving range modification, function permission setting and modification, manual driving, automatic driving and one-button start.
7. The secure login system for an in-vehicle network device according to claim 6, characterized in that: When the logged-in user of the in-vehicle network device is a family member, he or she enjoys the permissions of the in-vehicle network, driving within the preset map range, manual driving, and automatic driving, and can open the car door normally, but the vehicle start requires remote online authorization by the preset owner, and the preset owner can manage the permissions of the running vehicle online through the terminal platform.
8. The secure login system for an in-vehicle network device according to claim 7, characterized in that: When the logged-in user of the in-vehicle network device is a visitor, he or she only has the authority to drive manually; the identity authentication of the in-vehicle network device and the start-up of the vehicle require the preset remote online authorization of the owner, and safe driving must be performed within the permitted map driving range; visitors are only allowed to browse maps and play media through the mobile network.
9. The secure login system for an in-vehicle network device according to claim 8, characterized in that: The user login module also includes a privacy data protection unit and a security protection unit. The privacy data protection unit includes localized encrypted storage, anonymized communication and user data sovereignty. The localized encrypted storage is used to locally store biometric data; the anonymized communication is used for Internet of Vehicles communication using pseudonym certificates; the user data sovereignty provides a blockchain audit interface, and users can view / revoke data authorization at any time; The security protection unit uses secure startup and a trusted execution environment to isolate key processes, and the system uses differential encryption upgrade packages and dual partition backup.
10. A secure login method, characterized in that: The secure login system of the vehicle-mounted network device as described in any one of claims 1 to 9 is used to authenticate, authorize and securely log in the user.
Citation Information
Patent Citations
Automatic driving control method and system based on multimode recognition, medium and vehicle-mounted terminal
CN111409646A
Automobile transportation safety monitoring system based on driver holographic management
CN114912878A
Vehicle control method, device and equipment and storage medium
CN114967662A
Vehicle control method, device, equipment, storage medium and computer program product
CN118107586A
Application account information management and control method and system for vehicle-mounted system
WO2018040729A1