Method for authorizing use of telematics service, mobile communication device and communication system performing method
By storing digital vehicle keys in mobile communication devices and authenticating with the vehicle backend, the problem of registration and activation of existing telematics services before use is solved, and the service is quickly enabled and the user experience is improved.
Patent Information
- Application Number
- CN202380071834.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-10-25
- Filing Date
- 2023-09-14
- Publication Date
- 2025-06-06
AI Technical Summary
The existing telematics service requires user registration and activation before use, resulting in a reduced user experience.
By storing the digital vehicle key in the mobile communication device and authenticating it with the vehicle backend, the vehicle's telematics service can be quickly enabled.
No user registration and activation is required, which significantly improves user comfort experience and simplifies the use of telematics services.
Smart Images

Figure CN120113265A_ABST
Abstract
Description
Technical Field
[0001] The invention relates to a method for authorizing the use of a telematics service of a vehicle according to the preamble of method claim 1. The invention relates in particular to a mobile communication device for carrying out the method and expediently to a communication system for carrying out the method. Background Art
[0002] Many vehicle manufacturers offer so-called telematic services for vehicles, which provide useful vehicle functions to the user of the respective vehicle. For example, navigation services, traffic information services, opening and closing functions for vehicle doors and windows, remote control assistants and programming for auxiliary vehicle heating. After registration and activation in the server infrastructure of the vehicle manufacturer assigned to the vehicle (hereinafter referred to as the vehicle backend), the user of the vehicle can use the telematic services, usually via a mobile communication device based on an application provided by the vehicle manufacturer, which communicates directly with the vehicle to implement the desired vehicle functions. The disadvantage is that a certain amount of effort is required to register and activate the telematic services before using them, which reduces the user's comfort experience with the vehicle.
[0003] DE 10 2012 012 389 A1 discloses a device and a method for controlling access authorization and / or driving authorization of a vehicle, in particular using a mobile communication device. Summary of the invention
[0004] It is therefore an object of the present invention to provide an improved or at least a different embodiment of the method for authorizing the use of telematic services of a vehicle.
[0005] The basic idea of the present invention is to implement the use authorization of the vehicle's telematics service based on the digital vehicle key.
[0006] To this end, a method for authorizing the use of a telematics service of a vehicle is proposed, within the framework of which a mobile communication device, such as a smartphone, is provided with a storage medium, in which at least one digital vehicle key and at least one executable application for executing a telematics service of the vehicle are stored. Advantageously, in a preparatory step before the method, at least one digital vehicle key has been created in the storage medium of the mobile communication device, and the relevant digital certificate, such as a digital certificate in accordance with the X.509v3 standard, has been registered in a vehicle backend assigned to the vehicle. It is also provided that the application has commands, which, when executed by the mobile communication device, enable, for example, the selection of an available vehicle by a user request, and based on at least one digital vehicle key, the mobile communication device and / or the application perform authentication / identification with the vehicle backend. The user request can be implemented by a screen query on the mobile communication device, which provides the user with a list of vehicles to choose from. Alternatively, the available vehicle can be selected without user interaction according to a computer-based algorithm. Suitably, the mobile communication device and / or the application perform authentication / authentication with the vehicle backend using a private key of the digital vehicle key. During the authentication, the vehicle backend also suitably uses a certificate for at least one digital vehicle key stored in the vehicle backend. Furthermore, the vehicle backend provides telematic services for the vehicle. To this end, the vehicle backend can be equipped with suitable hardware and software components. Furthermore, within the scope of the method, the vehicle backend establishes a user session for the mobile communication device and / or the application with the user assigned to the selected vehicle. In this case, when the authentication with the vehicle backend is successful, the user of the vehicle can use the telematic services provided for the vehicle via the application.
[0007] By means of the invention, telematic services can be conveniently and, most importantly, relatively quickly enabled for the vehicle using a digital vehicle key. In this case, there is no longer any need to register the user in the vehicle backend, which was necessary for the previous use of telematic services, no need for subsequent activation of the telematic services by the vehicle backend, and no need for password-based authentication of the user before the use of the telematic services. This significantly increases the user's comfort.
[0008] In the present invention, the telematics services of a vehicle are advantageously understood to refer to vehicle functions that are provided by the vehicle backend for the vehicle, can be executed by the vehicle and are useful to the user of the respective vehicle. Telematics services are, for example, navigation services, traffic information services, opening and closing functions for vehicle doors and windows, remote control assistants, and programming for auxiliary heating of the vehicle. The user of the vehicle can usually use an application provided by the vehicle manufacturer to use the telematics services, which application is installed on a mobile communication device, in particular a smartphone, for example, and communicates with the vehicle in order to implement the vehicle functions selected by the user on the vehicle. It should be clear that the corresponding vehicle functions must be implemented in the vehicle. Through this communication path (application), the user of the vehicle can also activate / release new functions directly via the backend - for example, additional navigation maps, seat heating in rental mode, etc. This is of particular interest in the rental process.
[0009] The mobile communication device may in particular be implemented as a smartphone or smartwatch and may be expediently arranged to communicate via telecommunication means with a vehicle backend, at least one vehicle and at least one further mobile communication device. However, the invention is not limited to such mobile communication devices.
[0010] The invention appropriately understands a digital vehicle key as a digital key stored in a storage medium, which in particular enables basic vehicle functions, such as contactless unlocking and locking of the vehicle and starting of the vehicle. In addition to these basic functions, at least one digital vehicle key may also provide in particular comfort functions. This includes, for example, digitally sharing a digital vehicle key with a common user of the vehicle.
[0011] The invention advantageously understands application programs as executable computer programs. These computer programs can be optimized for use in mobile communication devices, in particular smart phones.
[0012] The invention advantageously understands a vehicle backend as any server infrastructure suitable for providing telematics services to a vehicle. The vehicle backend may comprise in particular backend devices and backend software, ie hardware and software components.
[0013] In order to be able to set the scope of telematic services provided that the user is allowed to use within the scope of an established user session, the at least one digital vehicle key advantageously contains a usage rights feature related to the telematic services. Based on the usage rights feature, the scope of telematic services of the vehicle that can be used during the established user session can be restricted, in order in particular to make fewer vehicle functions available for the vehicle. The usage rights feature can be depicted or implemented, for example, on the access profile of the at least one digital vehicle key. Thus, the permitted scope of use of the telematic services can be set relatively simply.
[0014] In this case, the usage rights features assigned to at least one digital vehicle key are advantageously pre-set by the user of the vehicle, the owner of the vehicle or a person authorized by the owner of the vehicle or the vehicle backend before establishing the user session. Thus, the user of the vehicle, the owner of the vehicle or a person authorized by the owner of the vehicle can relatively easily pre-set the scope of use of the telematics service in the user session. The use of the vehicle's telematics services is therefore only possible within the scope specified by the usage rights features of the digital vehicle key. Conveniently, the owner of the vehicle or a person authorized by the owner of the vehicle has the full usage rights features, allowing unrestricted use of the vehicle's telematics services. In rental scenarios or in the case of digital sharing of digital vehicle keys with a common user of the vehicle, it may be advantageous if the use of the telematics services is configured (e.g. restricted) before the user session.
[0015] Furthermore, the method is advantageously performed using a digital buddy vehicle key, which is issued, for example, by the user of the vehicle, the owner of the vehicle or a person authorized by the owner of the vehicle for a co-user of the vehicle based on the digital vehicle key. The digital buddy vehicle key is advantageously generated when at least one digital vehicle key is digitally shared with a co-user of the vehicle, which together with an associated certificate (e.g. an X.509v3 certificate) is subsequently stored in the mobile communication device of the co-user and / or its storage medium, and the associated certificate is registered in the vehicle backend assigned to the vehicle. In the context of the proposed method, a digital buddy vehicle key can be used instead of a digital vehicle key for authentication with the vehicle backend. This ensures that a co-user of the vehicle (user of the vehicle, owner of the vehicle or a person authorized by the owner of the vehicle) to whom the digital buddy vehicle key has been provided by digital sharing can also use the telematic services of the vehicle. In this case, the co-user does not need to transmit personal data to the vehicle backend, since the authentication of the mobile communication device and / or the application of the co-user is realized based on the digital buddy vehicle key, which is more convenient for the co-user.
[0016] Advantageously, the digital buddy vehicle key is also equipped with a usage rights feature. This can be configured when the digital buddy vehicle key is issued or in a user account created in the vehicle backend, so that when a user session is established for a common user of the vehicle, the scope of the telematics services of the vehicle that the common user can use during the established user session is set. The usage rights feature of the digital buddy vehicle key can be pre-set, for example, by the user of the vehicle or the owner of the vehicle or a person authorized by the owner of the vehicle.
[0017] It can advantageously be provided that the user of the vehicle or the owner of the vehicle or a person authorized by the owner of the vehicle can declare a digital buddy vehicle key issued for a joint user invalid or that the key has become invalid due to expiration of a time period, and that the established user session is terminated and can no longer be accepted. This ensures that after the issuance of a digital buddy vehicle key or the expiration of the key, the right to use the vehicle telematics service granted to the joint user is terminated and is therefore no longer available. The method is therefore more secure when digitally sharing digital vehicle keys.
[0018] Furthermore, it is advantageous if, when executing the method, a user of the vehicle or a co-user of the vehicle carries out the following steps, in particular using an application:
[0019] 1) Launch the application on the mobile communication device;
[0020] 2) In case at least one digital vehicle key is stored in the storage medium of the mobile communication device, executing a user request, wherein the user decides by selecting:
[0021] a) performing authentication based on at least one stored digital vehicle key,
[0022] b) authentication is still performed via password-based authentication;
[0023] 3) As an alternative to step 2), the application can authenticate without user interaction and based on a specified computer algorithm (e.g., digital vehicle keys cannot be used for authentication)
[0024] To decide:
[0025] a) performing authentication based on at least one stored digital vehicle key,
[0026] b) authentication is still performed via password-based authentication;
[0027] 4) Wherein, in the case of selecting a), proceed to the subsequent step 6);
[0028] 5) wherein, in the case of option b), performing password-based authentication with the vehicle backend to authorize use of the vehicle's telematics services;
[0029] 6) In case more than one digital vehicle key is stored in the storage medium of the mobile communication device, a further user request is performed, wherein the user actively decides by selection which vehicle the telematics service will be used for.
[0030] Thus, the user or co-user of the vehicle can appropriately decide to use the digital vehicle key to perform authentication with the vehicle backend and then, in the case where more than one digital vehicle key is stored in the storage medium of the mobile communication device, select for which vehicle the telematics service will be used. The proposed method is therefore relatively easy to master and, in particular, improves customer acceptance.
[0031] In particular, at least one digital vehicle key can be provided according to the digital vehicle key standard from the Car Connectivity Consortium. The digital friend vehicle key according to the ccc standard is also suitably provided. In this case, the "ccc standard" is suitably predefined by the document "Car Connectivity Consortium Digital Key Release 3 Technical Specification Version 1.0.0 (Car Connectivity Consortium Digital Key Release 3 Technical Specification Version 1.0.0) (CCC-TS-101)" and subsequent documents (abbreviated as CCC), the disclosure of which is fully included in this document by reference. Therefore, in particular during the user pairing or friend pairing process, at least one digital vehicle key is generated in a secure storage element (referred to as a secure element) of a CCC-compliant mobile communication device, and a digital certificate (in particular an X.509v3 certificate) associated with the digital vehicle key is registered in the vehicle backend of the selected vehicle. In addition, it is advantageous that at least one digital vehicle key has an asymmetric encryption key pair, a so-called public key and a private key, and an associated certificate, such as an X.509v3 certificate.
[0032] Advantageously, the established user session is performed in an anonymous or pseudonymous manner, ie as an anonymous or pseudonymous user session.
[0033] Definition of pseudonymization by data protection authorities:
[0034] “EU personal data protection legislation defines pseudonymisation as the processing of personal data in such a way that the data can no longer be attributed to a specific individual, without the use of additional information.”
[0035] Sources:
[0036] https: / / edps.europa.eu / press-publications / press-news / blog / pseudonymous-data-processing-personal-data-while-mitigating_en .
[0037] The difference between anonymity and pseudonymity is that pseudonymity requires additional information to infer a person. In the case of anonymity, this is not possible. This firstly satisfies the data protection interests of the user, since the user does not have to disclose personal data in order to use telematic services. In addition, in particular, the co-user does not need to provide personal data in the vehicle backend, which is particularly advantageous in rental scenarios or when digitally sharing digital vehicle keys for co-users.
[0038] Furthermore, it is conceivable that the method according to the invention is used as an entry point for new customers of the vehicle backend. This can be achieved by enabling co-users who are not registered in the vehicle backend (representing potential new customers of the vehicle backend) to conveniently and relatively quickly use the vehicle's telematics services based on the proposed method, wherein the telematics services are supplemented by a procedure that allows simplified registration of co-users in the vehicle backend.
[0039] According to another basic idea of the invention, a mobile communication device, in particular a smart phone or a smart watch, is provided, which has a computer-readable storage medium, in which at least one digital vehicle key and an executable application for performing telematic services for the vehicle are stored. The mobile communication device is expediently arranged to perform the method according to the above description. This provides an advantageous mobile communication device, by means of which the method in question can be performed. In particular, the mobile communication device is arranged so that more than one digital vehicle key can be stored in the computer-readable storage medium.
[0040] According to another basic idea of the invention, a communication system for executing the subject method according to the above description is provided. The communication system comprises a vehicle for executing telematics services, a mobile communication device constructed according to the above description and suitable for executing the method according to the above description, an executable application for executing telematics services for the vehicle stored in a storage medium of the mobile communication device, and a vehicle backend. The application has a command, which, when executed by the mobile communication device, causes an authentication of the mobile communication device and / or the application to be performed in the vehicle backend assigned to the vehicle based on at least one digital vehicle key. The vehicle backend provides telematics services for the vehicle and is also configured to establish and terminate at least one user session of the mobile communication device and / or the application, wherein within the framework of the user session, the respective user of the vehicle can use the telematics services provided for the vehicle based on the respective application. This provides an advantageous communication system, with the aid of which the method in question can be executed.
[0041] In addition, it is advantageous when the application uses the digital key framework defined by the CCC during authentication. In this case, the device-side framework for the digital vehicle key is advantageously referred to as the digital key framework, which implements key functions such as vehicle pairing, digital sharing of digital vehicle keys, and management of digital vehicle keys.
[0042] Furthermore, in the case where no digital vehicle key or a digital vehicle key provided in accordance with the ccc standard is available, it is advantageous to establish a parallel process for the digital vehicle key based on the vehicle backend or the vehicle manufacturer. This can use an asymmetric encryption key pair consisting of a public key and a private key with a certificate, in particular an X.509v3 certificate, just like the digital vehicle key provided in accordance with the ccc standard.
[0043] Advantageously, the user of the vehicle is the owner of the vehicle, a person authorized by the owner of the vehicle, or a vehicle backend. In a rental scenario, the co-user may be the lessee of the vehicle, or a person the user trusts.
[0044] In summary, the present invention suitably relates to a method for authorizing the use of a telematics service of a vehicle based on a digital vehicle key, and more particularly to a mobile communication device and a communication system for executing the method.
[0045] Further important features and advantages of the invention emerge from the dependent claims, the drawings and the description of the associated figures based on the drawings.
[0046] It is to be understood that the features mentioned above and those yet to be explained below can be used not only in the respectively specified combination but also in other combinations or alone, without departing from the scope of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Preferred embodiments of the invention are shown in the drawings and are explained in more detail in the following description, wherein the same reference numerals refer to the same or similar or functionally identical components.
[0048] in:
[0049] Figure 1 shows a very simplified flow chart of the method according to the invention, and
[0050] Figure 2 A more detailed flow chart of the method according to the present invention is shown. DETAILED DESCRIPTION
[0051] Figure 1A very simplified flow chart of the proposed method 1 for authorizing the use of telematic services of a vehicle is shown, wherein in a first step A, a mobile communication device 2 having a storage medium is first provided, in which at least one digital vehicle key 4 and an executable application 6 for executing telematic services of a vehicle are stored. In addition, the application 6 has commands which, when the mobile communication device 2 executes these commands in a second step B of the method 1, enable the selection of an available vehicle and the authentication of the mobile communication device 2 and / or the application 6 to a vehicle backend 9 assigned to the vehicle based on the at least one digital vehicle key 4. The vehicle backend 9 provides telematic services for the vehicle and, in a third step C of the method, establishes a user session 10 assigned to the selected vehicle for the mobile communication device 2 and / or the application 6. In the event of a successful authentication, the user of the vehicle can use the telematic services provided for the vehicle via the application 6 during the user session 10.
[0052] Figure 2 A more detailed flow chart of the proposed method 1 for authorizing the use of a telematics service of a vehicle is shown, wherein within the scope of the method 1, substantially the same steps as those described above are performed. Figure 1 The same method steps A, B and C are shown in the flow chart. Therefore, Figure 2A mobile communication device 2 compliant with the CCC standard is shown, which is configured to perform the proposed method 1, for which purpose the mobile communication device 2 comprises a storage medium in which at least one digital vehicle key 4 provided according to the ccc standard and an executable application 6 for performing telematic services for a vehicle are stored. The application 6, which serves as a user interface for a user to use the telematic services, comprises or communicates with a secure element 11 (referred to as a secure element) stored in the storage medium, in which the at least one digital vehicle key 4 is located, and uses a digital key framework 12 also stored in the storage medium and defined according to the ccc standard, which in this case provides a device-side framework for functioning with the at least one digital vehicle key 4. Purely by way of example, the application 6 has a user authentication logic 13, which can be seen as an application-side implementation of an authentication based on the digital vehicle key 4. The application 6 also comprises a command which, when executed by the mobile communication device 2, enables the selection of a provided vehicle and, based on the private key of the at least one digital vehicle key 4, performs an authentication 7 of the mobile communication device 2 and / or the application 6 to a vehicle backend 9 assigned to the vehicle. To this end, in a preparatory step prior to the method 1, in the vehicle backend 9, a certificate 8, for example an X.509v3 certificate, associated with at least one digital vehicle key 4 is registered in a digital key backend 16 of the vehicle backend 9. As an example, the vehicle backend 9 providing telematic services for the vehicle has a backend authentication logic 14, which is implemented in a backend application 17 and represents a backend-side implementation based on the authentication of at least one digital vehicle key 4, the backend application 17 being a server-side implementation of the telematic services. Within the scope of the proposed method 1, in the event of a successful authentication, the backend authentication logic 14 of the vehicle backend 9 establishes, for example, an anonymous user session 10 assigned to the selected vehicle for the mobile communication device 2 and / or the application 6. During the established user session 10, the user of the vehicle can use the telematic services provided for the vehicle using the application 6. It should also be mentioned that the at least one digital vehicle key 4 used for the authentication can be provided with a usage right feature 15 related to the telematic services, by means of which the extent / scope to which the user of the vehicle can use the telematic services of the vehicle during the user session 10 can be set when establishing the user session 10. For example, in a rental scenario in which a digital buddy vehicle key 5 with a corresponding certificate 8 is issued to a common user of a vehicle by digitally sharing at least one digital vehicle key 4, the usage right features 15 are preferably specified / pre-set by the user of the vehicle, such as the owner of the vehicle or a person authorized by the owner of the vehicle, before establishing a user session 10.
Claims
1. A method for authorizing use of a vehicle's telematics service (1) It is characterized in that - providing a mobile communication device (2) having a storage medium in which at least one digital vehicle key (4) and an executable application (6) for performing a telematics service for a vehicle are stored, wherein the application (6) further comprises commands which, when executed by the mobile communication device (2), cause the selection of a provided vehicle and the execution of an authentication of the mobile communication device (2) and / or the application (6) to a vehicle backend (9) assigned to the vehicle based on the at least one digital vehicle key (4), - wherein the vehicle backend (9) provides telematics services for vehicles assigned to the vehicle backend, - wherein the vehicle backend (9) establishes a user session (10) assigned to the selected vehicle for the mobile communication device (2) and / or the application (6), during which user session, in the event of successful authentication, the user of the vehicle can use the telematics services provided for the vehicle through the application (6).
2. The method (1) according to claim 1, It is characterized in that - The at least one digital vehicle key (4) has a usage right feature (15) related to a telematics service, and when the user session (10) is established, the scope of the telematics service available to the user of the vehicle during the user session (10) is set based on the usage right feature.
3. The method (1) according to claim 2, It is characterized in that The access right feature (15) is pre-set before the user session (10) is established by the user of the vehicle, the owner of the vehicle or a person authorized by the owner of the vehicle or by the vehicle backend (9).
4. The method (1) according to any one of the preceding claims, It is characterized in that The method (1) is performed using a digital buddy vehicle key (5) which is issued to a common user of the vehicle based on the digital vehicle key (4).
5. The method (1) according to claim 4, It is characterized in that The digital buddy vehicle key (5) is equipped with a right of use feature (15) according to claim 2 or 3.
6. The method (1) according to claim 4 or 5, It is characterized in that - the user of the vehicle or the owner of the vehicle or a person authorized by the owner of the vehicle invalidates the digital buddy vehicle key (5) issued to the co-user of the vehicle, -in, At the same time, the established user session (10) is terminated, and future user sessions cannot be established using the digital friend vehicle key.
7. The method (1) according to any one of the preceding claims, It is characterized in that To carry out the method (1), the user of the vehicle or a co-user of the vehicle uses the application (6) to carry out in particular the following steps: 1) starting the application (6) on the mobile communication device (2); 2) in the case where at least one digital vehicle key (4) is stored in the storage medium of the mobile communication device (2), executing a user request, wherein the user actively decides by selecting: a) authentication is performed based on at least one stored digital vehicle key (4), or b) performing authentication via password-based authentication; 3) As an alternative to step 2), the application (6) can decide without user interaction and based on a predetermined computer algorithm: a) authentication is performed based on at least one stored digital vehicle key (4), or b) performing authentication via password-based authentication; 4) Wherein, in the case of selecting a), proceed to the subsequent step 6); 5) wherein, in the case of option b), performing a password-based authentication to the vehicle backend (9) to authorize the use of the vehicle's telematics services; 6) In case more than one digital vehicle key (4) is stored in the storage medium of the mobile communication device (2), a further user request is performed, wherein the user actively decides by selection for which vehicle the telematics service is to be used.
8. The method (1) according to any one of the preceding claims, It is characterized in that - providing the at least one digital vehicle key (4) according to the ccc standard.
9. The method (1) according to any one of the preceding claims, It is characterized in that - The user session (10) is performed as an anonymous or pseudonymous user session (10).
10. A mobile communication device (2), in particular a smartphone, - having a computer-readable storage medium having stored therein at least one digital vehicle key (4) and an executable application (6) for performing telematics services for the vehicle, in, The mobile communication device (2) is arranged to perform the method (1) according to claims 1 to 9.
11. A communication system for performing the method (1) according to claims 1 to 9, comprising - a vehicle configured to perform telematics services, a mobile communication device (2), which is designed in particular according to claim 10 and is suitable for carrying out the method (1) according to claims 1 to 9 and has a storage medium, - an executable application (6) for performing telematics services for a vehicle, stored in a storage medium of the mobile communication device (2), the application having commands which, when executed by the mobile communication device (2), cause an authentication of the mobile communication device (2) and / or the application (6) to be performed with a vehicle backend (9) assigned to the vehicle based on the at least one digital vehicle key (4), - A vehicle backend (9) providing telematics services for the vehicle and being arranged to establish and terminate a user session (10) assigned to the selected vehicle for the mobile communication device (2) and / or the application (6), during which user session (10) the user of the vehicle can use the telematics services provided for the vehicle via the application (6).
Citation Information
Patent Citations
Device for controlling access authorization and / or driving authorization for e.g. hire car, has database server transferring authorization data to data carrier and including data memory authorization for protected memory areas
DE102012012389A1