Authentication method, device and system

CN120359723APending Publication Date: 2025-07-22YINWANG INTELLIGENT TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380086188.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-02-28
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

Existing digital key authentication methods cannot effectively prevent the digital key signal processing unit from being attacked, resulting in vehicle theft and threats to user property and personal safety.

Method used

When the in-vehicle control unit receives the control information from the digital key signal processing unit, it performs secondary authentication to ensure the legitimacy of the source device of the control information. The unlocking and starting operations of the vehicle are only performed when the verification is successful to prevent the spread of attacks. .

Benefits of technology

It improves the security of the digital key signal processing unit, prevents the spread of attacks, enhances the overall security of the vehicle, and protects the user's property security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120359723A_ABST
    Figure CN120359723A_ABST
Patent Text Reader

Abstract

An authentication method, apparatus and system, the method comprising: a first node receives control request information from a second node, the control request information being used for requesting to execute a preset operation on a first device, the first device comprising the first node and the second node; the first node verifies first verification information, wherein the first verification information is used by the first node to verify the legality of source equipment of the control request information; and when the verification succeeds, the first node controls the first device to execute the preset operation according to the control request information. The authentication method can be applied to intelligent driving equipment such as a new energy vehicle and an electric vehicle, can also be applied to three-node systems such as a three-node system in the IT field and a three-node system in the industrial control field, and is beneficial to improving the safety of the authentication system.
Need to check novelty before this filing date? Find Prior Art

Description

Authentication method, device and system Technical Field

[0001] The present application relates to the field of security authentication technology, and more specifically, to an authentication method, device, and system. Background Art

[0002] Digital car keys are widely popular due to their convenience, and their adoption rate continues to rise year by year. However, in recent years, digital keys have become one of the most popular cyberattack surfaces for hackers. For example, according to data from Tracker, the UK's largest stolen vehicle recovery company, 92% and 93% of stolen vehicles in 2019 and 2020, respectively, were stolen through vulnerabilities in passive keyless entry (PKE) technology.

[0003] In order to prevent relay attacks, replay attacks and other attacks against digital keys, when controlling the opening of the car door through the digital key, it is usually necessary to complete the authentication between the "key device" and the "digital key signal processing unit", as well as the authentication between the "digital key signal processing unit" and the "in-vehicle control unit".

[0004] However, the aforementioned authentication method only reduces the risk of key device attacks, but cannot prevent attacks on the digital key signal processing unit. If the digital key signal processing unit is attacked, the in-vehicle control unit may unconditionally execute commands from the digital key signal processing unit, resulting in vehicle theft, property loss, and even threats to the user's personal safety.

[0005] In view of this, a digital key authentication solution that can improve security is in urgent need of development.

[0006] Summary of the Invention

[0007] The present application provides an authentication method, device and system, which help to improve the reliability and security of security authentication of a three-node system.

[0008] In a first aspect, an authentication method is provided, which can be executed by an intelligent driving device; alternatively, it can be executed by a chip or circuit used for the intelligent driving device, for example, by a chip or circuit in a computing platform of the intelligent driving device, which is not limited in this application.

[0009] The intelligent driving devices involved in this application may include road vehicles, water vehicles, air vehicles, industrial equipment, agricultural equipment, or entertainment equipment, etc. For example, the intelligent driving device can be a vehicle, which is a vehicle in a broad sense, and can be a vehicle (such as a commercial vehicle, a passenger car, a motorcycle, a flying car, a train, etc.), an industrial vehicle (such as a forklift, a trailer, a tractor, etc.), an engineering vehicle (such as an excavator, a bulldozer, a crane, etc.), agricultural equipment (such as a mower, a harvester, etc.), amusement equipment, a toy vehicle, etc. The embodiments of this application do not specifically limit the type of vehicle. For another example, the intelligent driving device can be a vehicle such as an airplane or a ship.

[0010] The method includes: a first node receives control request information from a second node, the control request information is used to request a preset operation to be performed on a first device, the first device includes the first node and the second node; the first node verifies first verification information, the first verification information is used by the first node to verify the legitimacy of the source device of the control request information; when the verification is successful, the first node controls the first device to perform the preset operation according to the control request information; or, when the verification fails, the first node ignores the control request information.

[0011] In this technical solution, when a first node receives a control request from a second node, it doesn't unconditionally execute the control request. Instead, it executes the control request only after determining that the source device is legitimate. If the second node is compromised by an attacker, the attacker's control request can be blocked, improving the security of the authentication process and, by extension, the security of the first device.

[0012] In some possible implementations, the first node verifying the first verification information includes: the first node verifying the first verification information using information associated with a second device, where the second device is a legitimate device used to control the first device to perform a preset operation. The information associated with the second device may include a shared key negotiated between the first and second devices, a public key of the second device, and the like.

[0013] Exemplarily, when the above technical solution is applied to a keyless entry system, the first device may be an intelligent driving device such as a vehicle, and the first node may include an in-vehicle control unit, such as a vehicle intranet unit (VIU), a vehicle domain controller (VDC), etc.; the second node may include a digital key signal processing unit, such as a Bluetooth low energy (BLE) master node; the preset operation may include controlling the operation of one or more components in the vehicle, such as unlocking the door, starting the vehicle, turning on the cabin air conditioning, etc.

[0014] When the above technical solution is applied to an information technology (IT) three-node system or an industrial control three-node system, the preset operation may be other operations that require security authentication before they can be performed.

[0015] It can be understood that the three-node system involved in this application includes three nodes, such as node 1 to node 3, and node 1 needs to control node 3 through node 2.

[0016] In some possible implementations, the source device of the control request information is a legitimate device that controls the first device to perform a preset operation. For example, the source device has completed authentication with the first device through the second node, or the user of the source device is an authorized user of the first device. The source of the first verification information is also the source device. For example, the first verification information can be forwarded from the source device to the first node via a cloud server, or the first verification information can be transparently transmitted from the source device to the first node via the second node. Furthermore, when the first node verifies the first verification information, the verification will be successful.

[0017] In some possible implementations, if the source device of the control request information is an illegal device of an attacker, the source of the first verification information may be the source device, or the source of the first verification information may be a legitimate device that controls the first device to perform a preset operation. Furthermore, when the first node verifies the first verification information, the verification will fail.

[0018] In combination with the first aspect, in certain implementations of the first aspect, before the first node verifies the first verification information, the method also includes: the first node sends verification request information based on the control request information, and the verification request information is used to request the first verification information from the second device, and the second device is a legitimate device used to control the first device to perform the preset operation; the first node receives the first verification information.

[0019] Exemplarily, the verification request information may be a challenge message, or may be information containing a random number generated based on the zero-knowledge proof principle; or may be other information that can trigger the second device to send the first verification information.

[0020] Exemplarily, the first verification information may be transparently transmitted from the second device to the first node via the second node.

[0021] In the above technical solution, when the first node receives the control request information, it directly sends relevant information to the legal device to obtain the first verification information, and then determines whether the source of the control request information is a legal device based on the first verification information. When the source of the control request information is not a legal device, the control request information is not executed, which helps to improve the security of the first device.

[0022] In combination with the first aspect, in certain implementations of the first aspect, the verification request information includes a first random number, the first verification information is associated with the first random number and the shared key between the first device and the second device, and the first node verifies the first verification information, including: the first node verifies the first verification information based on the shared key.

[0023] Exemplarily, the first verification information is associated with the first random number and a shared key between the first device and the second device, including: the first verification information is generated according to the first random number and the shared key.

[0024] In some possible implementations, the first verification information is generated based on control information sent by the second device, a first random number, and a shared key.

[0025] In some possible implementations, before the first node verifies the first verification information according to the shared key, the method further includes: the first node generating and / or obtaining the shared key.

[0026] Exemplarily, the shared key can be dynamically generated by the first node. After the first node generates the shared key, the shared key is sent to the second device through a cloud server or a wireless communication network (such as BLE), or the second device obtains the shared key by actively scanning a specific QR code.

[0027] In the above technical solution, by verifying the first verification information generated according to the first random number, it helps to prevent replay attacks and further improve the security of the first device.

[0028] In combination with the first aspect, in some implementations of the first aspect, before the first node verifies the first verification information, the method further includes: the first node receiving the first verification information from the second node.

[0029] Exemplarily, the first node receives the first verification information at the same time as receiving the control request information.

[0030] Exemplarily, the control request information and the first verification information may be transmitted through the same message, or may be transmitted through two messages.

[0031] Exemplarily, the first verification information may be forwarded from a legitimate device to the first node via the second node; or, may be forwarded from an illegal device to the first node via the second node.

[0032] In combination with the first aspect, in certain implementations of the first aspect, the method also includes: the first node receives a first public key of a second device, and the second device is a legitimate device used to control the first device to perform the preset operation; the first node verifies the first verification information, including: the first node verifies the first verification information based on the first public key.

[0033] In the above technical solution, there is no need for an additional shared key to be deployed between the second device and the first node. Only the public key of the second device stored in the first node is required to verify the first verification information, which helps to reduce the complexity of key management.

[0034] In combination with the first aspect, in certain implementations of the first aspect, the first verification information is associated with a signature generated by a first private key of the second device, the first private key and the first public key form a key pair, and the verification is successful, including: the first node uses the first public key to verify the first verification information.

[0035] In combination with the first aspect, in some implementations of the first aspect, the first verification information includes a time identifier, which indicates the moment when the first verification information is generated.

[0036] Exemplarily, the time identifier may include a timestamp, or may also include other forms of information for identifying the moment when the first verification information is generated.

[0037] In the above technical solution, by adding a time identifier such as a timestamp to the first verification information, it helps to prevent replay attacks and further improve the security of the first device.

[0038] In combination with the first aspect, in certain implementations of the first aspect, the method further includes: when the first node receives the control request information, determining whether the first verification information is received; when the first node does not receive the first verification information within a preset time length, determining that the verification has failed.

[0039] In some possible implementations, the legitimate device and the first device agree that the legitimate device sends first verification information simultaneously with the control request information sent to the second node. Furthermore, the second node sends both the control request information and the first verification information to the first node. If the first node receives the control request information but does not receive the first verification information, it deems the control request information to be sent by an illegitimate device and determines that verification has failed.

[0040] In some possible implementations, the legitimate device and the first device agree that, after receiving the control request information sent by the second node, the first node will request first verification information from the legitimate device via a verification request information. In specific implementations, if the first node fails to receive the first verification information within a preset time period due to reasons such as a malfunction of the legitimate device itself or unauthorized interception of the verification request information or the first verification information, the verification may be determined to have failed.

[0041] Exemplarily, the preset duration may be 0.2 seconds, or 0.5 seconds, or other durations.

[0042] In the above technical solution, by setting the above verification failure identification conditions, the reliability and robustness of the authentication system can be improved, which helps to further improve the security of the first device.

[0043] In a second aspect, an authentication method is provided, which can be executed by a mobile terminal; alternatively, it can also be executed by a chip or circuit used for a mobile terminal, which is not limited in this application.

[0044] The mobile terminals involved in this application may include key devices such as smart keys, or various handheld devices with wireless communication functions, wearable devices, computing devices, or other processing devices connected to a wireless modem, as well as various forms of terminals, mobile stations, user equipment, etc. For example, watches, bracelets, wireless headphones, electronic wallets, etc., which are not limited in the embodiments of this application.

[0045] The method includes: a second device generates first verification information, the second device is a legal device used to control the first device to perform a preset operation, the first verification information is used by the first node of the first device to verify the legitimacy of the source device of the control request information, and the control request information is used to request the first device to perform the preset operation; the second device sends the first verification information.

[0046] In some possible implementations, the second device generates first verification information when generating or sending control request information.

[0047] Exemplarily, the second device sending the first verification information includes: the second device sending the first verification information to the first node of the first device.

[0048] In the above technical solution, the legal device sends first verification information to the first node of the first device, so that the first device determines whether the source of the control request information is a legal device based on the first verification information. When the source of the control request information is not a legal device, the control request information is not executed, which helps to improve the security of the first device.

[0049] In combination with the second aspect, in certain implementations of the second aspect, the method also includes: the second device receives verification request information, the verification request information is used to request the first verification information; the second device sends the first verification information, including: the second device sends the first verification information according to the verification request information.

[0050] Exemplarily, the second device transparently transmits the first verification information to the first node of the first device through the second node of the first device.

[0051] In combination with the second aspect, in certain implementations of the second aspect, the verification request information includes a first random number, and the method further includes: the second device generates the first verification information based on the first random number and a shared key between the first device and the second device.

[0052] In some possible implementations, before the second device generates the first verification information, the method further includes: the second device obtaining the shared key.

[0053] Exemplarily, the shared key can be dynamically generated for the first device. After the first device generates the shared key, the shared key is sent to the second device through a cloud server or a wireless communication network (such as BLE), or the second device obtains the shared key by actively scanning a specific QR code.

[0054] In the above technical solution, first verification information is generated according to the first random number for verification by the first node of the first device, which helps to prevent replay attacks and further improve the security of the first device.

[0055] In combination with the second aspect, in certain implementations of the second aspect, the first verification information includes a signature generated by the second device based on the first private key of the second device, the first private key and the first public key form a key pair, and the first public key is used to verify the first verification information.

[0056] In the above technical solution, there is no need to deploy an additional shared key between the second device and the first node. Only the public key of the second device is needed to verify the first verification information, which helps to reduce the complexity of key management.

[0057] In combination with the second aspect, in some implementations of the second aspect, the method further includes: the second device sending the first public key.

[0058] Exemplarily, the second device sends the first public key to the first device. For example, during the initial pairing (or initial authentication) phase between the first device and the second device, the second device sends the first public key to the first device.

[0059] In combination with the second aspect, in some implementations of the second aspect, the first verification information further includes a time identifier, which indicates the moment when the first verification information is generated.

[0060] In the above technical solution, by adding a time identifier such as a timestamp to the first verification information, it helps to prevent replay attacks and further improve the security of the first device.

[0061] On the third aspect, an authentication method is provided, which can be executed by an intelligent driving device; alternatively, it can also be executed by a chip or circuit used for an intelligent driving device, for example, by a chip or circuit in a computing platform of the intelligent driving device, which is not limited in this application.

[0062] The method includes: the second node of the first device obtains first verification information, which is used by the first node of the first device to verify the legitimacy of the source device of the control request information, and the control request information is used to request to perform a preset operation on the first device; the second node sends the first verification information.

[0063] Exemplarily, the second node of the first device obtains the first verification information includes: the second node obtains the first verification information from a legitimate device; the second node obtains the first verification information from an illegal device.

[0064] In the above technical solution, after the second node of the first device obtains the first verification information, it sends the first verification information to the first node of the first device, so that the first device determines whether the source of the control request information is a legitimate device based on the first verification information. When the source of the control request information is not a legitimate device, the control request information is not executed, which helps to improve the security of the first device.

[0065] In combination with the third aspect, in certain implementations of the third aspect, the first verification information is associated with a first random number and a shared key between the first device and a second device, and the second device is a legitimate device used to control the first device to perform the preset operation.

[0066] In the above technical solution, the first verification information is associated with the first random number, which helps to prevent replay attacks and further improve the security of the first device.

[0067] In combination with the third aspect, in certain implementations of the third aspect, the first verification information is associated with a signature generated by a first private key of the second device, the first private key and the first public key form a key pair, and the second device is a legitimate device used to control the first device to perform the preset operation. The method also includes: the second node sends the first public key.

[0068] The second node sending the first public key includes: the second node sending the first public key to the first node of the first device, so that the first node verifies the first verification information according to the first public key.

[0069] In the above technical solution, there is no need to deploy an additional shared key between the second device and the first node. Only the public key of the second device is needed to verify the first verification information, which helps to reduce the complexity of key management.

[0070] In combination with the third aspect, in certain implementations of the third aspect, the first verification information includes a time identifier, which indicates the moment when the first verification information is generated.

[0071] In the above technical solution, by adding a time identifier such as a timestamp to the first verification information, it helps to prevent replay attacks and further improve the security of the first device.

[0072] In a fourth aspect, an authentication device is provided, which includes a transceiver unit, a verification unit and a processing unit, wherein the transceiver unit is used to: receive control request information from a second node, the control request information is used to request to perform a preset operation on a first device, and the first device includes the second node; the verification unit is used to: verify the first verification information, and the first verification information is used by the first node to verify the legitimacy of the source device of the control request information; the processing unit is used to: when the verification is successful, control the first device to perform the preset operation according to the control request information; or, when the verification fails, ignore the control request information.

[0073] In combination with the fourth aspect, in certain implementations of the fourth aspect, the transceiver unit is also used to: send verification request information based on the control request information, the verification request information is used to request the first verification information from the second device, and the second device is a legitimate device used to control the first device to perform the preset operation; receive the first verification information.

[0074] In combination with the fourth aspect, in certain implementations of the fourth aspect, the verification request information includes a first random number, the first verification information is associated with the first random number and the shared key between the first device and the second device, and the verification unit is used: the first node verifies the first verification information based on the shared key.

[0075] In combination with the fourth aspect, in certain implementations of the fourth aspect, the transceiver unit is further used to: receive the first verification information from the second node.

[0076] In combination with the fourth aspect, in certain implementations of the fourth aspect, the transceiver unit is also used to: receive a first public key of a second device, where the second device is a legitimate device used to control the first device to perform the preset operation; and the verification unit is used to: verify the first verification information based on the first public key.

[0077] In combination with the fourth aspect, in certain implementations of the fourth aspect, the first verification information is associated with a signature generated by a first private key of the second device, the first private key and the first public key form a key pair, and the verification unit successfully verifies, including: the verification unit uses the first public key to verify the first verification information.

[0078] In combination with the fourth aspect, in certain implementations of the fourth aspect, the first verification information includes a time identifier, which indicates the moment when the first verification information is generated.

[0079] In combination with the fourth aspect, in certain implementations of the fourth aspect, the processing unit is also used to: determine whether the first verification information is received when the transceiver unit receives the control request information; and determine that the verification has failed when the transceiver unit does not receive the first verification information within a preset time period.

[0080] In a fifth aspect, an authentication device is provided, which is arranged in a legitimate device for controlling a first device to perform a preset operation. The device includes a generation unit and a transceiver unit, wherein the generation unit is used to: generate first verification information, and the first verification information is used by the first node of the first device to verify the legitimacy of the source device of the control request information, and the control request information is used to request the first device to perform a preset operation; the transceiver unit is used to: send the first verification information.

[0081] In combination with the fifth aspect, in certain implementations of the fifth aspect, the transceiver unit is further used to: receive verification request information, where the verification request information is used to request the first verification information; and send the first verification information according to the verification request information.

[0082] In combination with the fifth aspect, in certain implementations of the fifth aspect, the verification request information includes a first random number, and the generation unit is used to: generate the first verification information based on the first random number and a shared key between the first device and the legitimate device.

[0083] In combination with the fifth aspect, in certain implementations of the fifth aspect, the first verification information includes a signature generated by the generation unit based on the first private key of the legitimate device, the first private key and the first public key form a key pair, and the first public key is used to verify the first verification information.

[0084] In combination with the fifth aspect, in certain implementations of the fifth aspect, the transceiver unit is further used to: send the first public key of the legitimate device.

[0085] In combination with the fifth aspect, in certain implementations of the fifth aspect, the first verification information also includes a time identifier, which indicates the moment when the first verification information is generated.

[0086] In the sixth aspect, an authentication device is provided, which includes an acquisition unit and a sending unit, wherein the acquisition unit is used to obtain first verification information, and the first verification information is used by the first node of the first device to verify the legitimacy of the source device of the control request information, and the control request information is used to request to perform a preset operation on the first device; the sending unit sends the first verification information.

[0087] In combination with the sixth aspect, in certain implementations of the sixth aspect, the first verification information is associated with a first random number and a shared key between the first device and a second device, and the second device is a legitimate device used to control the first device to perform the preset operation.

[0088] In combination with the sixth aspect, in certain implementations of the sixth aspect, the first verification information is associated with a signature generated by a first private key of the second device, the first private key and the first public key form a key pair, the second device is a legitimate device used to control the first device to perform the preset operation, and the sending unit is also used to: send the first public key.

[0089] In combination with the sixth aspect, in certain implementations of the sixth aspect, the first verification information includes a time identifier, which indicates the moment when the first verification information is generated.

[0090] In the seventh aspect, an authentication device is provided, which includes: a memory for storing a computer program; and a processor for executing the computer program stored in the memory, so that the device performs a method in any possible implementation of the first to third aspects.

[0091] In an eighth aspect, a communication system is provided, which includes an apparatus as in any possible implementation of the third aspect and an apparatus as in any possible implementation of the sixth aspect.

[0092] In a ninth aspect, an intelligent driving device is provided, which includes a system as in any possible implementation of the seventh aspect.

[0093] In combination with the ninth aspect, in certain implementations of the ninth aspect, the intelligent driving device is a vehicle.

[0094] In a tenth aspect, a mobile terminal is provided, wherein the intelligent driving device includes a device as in any possible implementation of the fifth aspect.

[0095] In the eleventh aspect, a computer program product is provided, comprising: a computer program code, which, when executed on a computer, enables the computer to execute the method in any one of the possible implementations of the first to third aspects.

[0096] It should be noted that the above-mentioned computer program code may be stored in whole or in part on a first storage medium, wherein the first storage medium may be packaged together with the processor or separately from the processor.

[0097] In the twelfth aspect, a computer-readable medium is provided, wherein the computer-readable medium stores instructions. When the instructions are executed by a processor, the processor implements the method in any possible implementation of the first to third aspects.

[0098] In a thirteenth aspect, a chip is provided, which includes a circuit for executing the method in any possible implementation of the first to third aspects above. BRIEF DESCRIPTION OF THE DRAWINGS

[0099] FIG1 is a schematic block diagram of a keyless entry system;

[0100] FIG2 is a schematic block diagram of an authentication system provided in an embodiment of the present application;

[0101] FIG3 is a schematic flow chart of an authentication method provided in an embodiment of the present application;

[0102] FIG4 is another schematic flow chart of the authentication method provided in an embodiment of the present application;

[0103] FIG5 is another schematic flow chart of the authentication method provided in an embodiment of the present application;

[0104] FIG6 is a schematic block diagram of an authentication device provided in an embodiment of the present application;

[0105] FIG7 is another schematic block diagram of an authentication device provided in an embodiment of the present application;

[0106] FIG8 is another schematic block diagram of the authentication device provided in an embodiment of the present application;

[0107] FIG9 is another schematic block diagram of an authentication device provided in an embodiment of the present application;

[0108] FIG10 is a schematic block diagram of an authentication system provided in an embodiment of the present application. DETAILED DESCRIPTION

[0109] In the description of the embodiments of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in this article is a kind of association relationship that describes associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In this application, "at least one" refers to one or more, and "more than one" refers to two or more. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.

[0110] In the embodiments of this application, prefixes such as "first" and "second" are used only to distinguish different description objects and have no limiting effect on the position, order, priority, quantity, or content of the described objects. The use of prefixes such as ordinal numbers in the embodiments of this application to distinguish description objects does not constitute a limitation on the described objects. For a statement of the described objects, please refer to the description in the context of the claims or embodiments, and the use of such prefixes should not constitute an unnecessary limitation.

[0111] As shown in Figure 1, when controlling the door opening through a digital key, it is usually necessary to complete the authentication between the key device and the digital key signal processing unit, as well as the authentication between the digital key signal processing unit and the in-vehicle control unit. Among them, the digital key signal processing unit may include a BLE master node, and the in-vehicle control unit may include a VIU and a VDC. After completing the above authentication, the in-vehicle control unit sends a control request message to the body control module (BCM), power domain controller, etc., to realize the control of the vehicle such as door unlocking and vehicle starting.

[0112] However, the above authentication method can only reduce the risk of key devices being attacked, but cannot prevent the digital key signal processing unit from being attacked. When the digital key signal processing unit is attacked, the control unit in the vehicle may unconditionally execute the instructions from the digital key signal processing unit, resulting in the theft of the vehicle and property loss to the user. As shown in Figure 1, the attacker can attack the BLE master node through the BLE air port attack, or the attacker can access the vehicle network through the communication box (telematics box, T-Box) and attack the BLE master node through the electronic control unit (electronic control unit, ECU).

[0113] In view of this, the present application provides an authentication method, device and system. When the in-vehicle control unit receives control information sent by the digital key signal processing unit, the in-vehicle control unit verifies the legitimacy of the source device of the control information. When the verification is successful, the in-vehicle control unit controls the vehicle to unlock and / or start according to the control information; when the verification fails, the in-vehicle control unit ignores the control information sent by the digital key signal processing unit, which can improve the security of the digital key signal processing unit. Even if it is attacked, the authentication method, device and system provided by this application can prevent the attack from spreading, improve the safety of the vehicle, and ensure the property safety of the user.

[0114] The technical solutions in the embodiments of the present application will be described below with reference to the accompanying drawings.

[0115] Figure 2 is a schematic block diagram of an authentication system provided in an embodiment of the present application. As shown in Figure 2, the system includes a vehicle and a key device, wherein the key device is a legal device for controlling the unlocking and / or starting of the vehicle. For example, the key device has been paired or authenticated with the vehicle through a digital key signal processing unit. For example, the vehicle includes a communication box, an ECU node, a digital key signal processing unit, and an in-vehicle control unit. An attacker can attack the digital key signal processing unit through the communication box and the ECU node, or can attack the digital key signal processing unit through an air port attack. In an embodiment of the present application, when the vehicle is controlled by the key device, after a primary authentication is completed between the key device and the digital key signal processing unit, and between the digital key signal processing unit and the in-vehicle control unit, when the in-vehicle control unit receives the control information of the digital key signal processing unit, the in-vehicle control unit will also complete a secondary authentication with the key device. When the secondary authentication is passed, the in-vehicle control unit controls the vehicle according to the control information.

[0116] Exemplarily, the digital key signal processing unit may include a wireless communication module, such as a BLE module, a radio frequency identification (RFID) module, an ultra-wideband (UWB) module, a near-field communication (NFC) module, and other wireless short-range communication systems (e.g., an in-vehicle wireless short-range communication system). Correspondingly, the key device may include a BLE device, an NFC device, or other wireless short-range communication device.

[0117] Exemplarily, the in-vehicle control unit may include at least one of a VIU, a VDC, an advanced driving domain controller (ADC), and a chassis domain controller (CDC); or, the in-vehicle control unit may further include an in-car application-server (ICAS) controller, a body domain controller (BDC), a special equipment system (SAS), a media graphics unit (MGU), a body super core (BSC), an advanced driving assistant system super core (ADAS super core), etc., which is not limited in this application. Among them, the ICAS may include at least one of the following: a vehicle control server ICAS1, an intelligent driving server ICAS2, an intelligent cockpit server ICAS3, and an infotainment server ICAS4.

[0118] Exemplarily, the in-vehicle control unit, the digital key signal processing unit, and the key device may each include one or more processors. A processor is a circuit with the ability to process signals. In one implementation, the processor may be a circuit with the ability to read and execute instructions, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP); in another implementation, the processor may implement certain functions through the logical relationship of a hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable, such as a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as a field programmable gate array (FPGA). In a reconfigurable hardware circuit, the process of the processor loading a configuration document to implement the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc. In addition, the in-vehicle control unit, the digital key signal processing unit, and the key device can also respectively include a memory for storing instructions. Some or all of the processors in the processor can call the instructions in the memory and execute the instructions to achieve the corresponding functions.

[0119] FIG3 shows a schematic flow chart of an authentication method provided in an embodiment of the present application. The method 300 may include S301 to S304 , wherein S302 and S302 ′ may be performed alternatively.

[0120] S301: The second node sends control request information to the first node.

[0121] The first node and the second node are both included in the first device.

[0122] Exemplarily, the second node may include the digital key signal processing unit in the above embodiment, and the first node may include the in-vehicle control unit in the above embodiment.

[0123] Exemplarily, the control request information may be used to request execution of a preset operation on the first device.

[0124] When the embodiments of the present application are applied to an intelligent driving device, such as a vehicle, the preset operations may include controlling the operation of one or more components in the vehicle, such as unlocking the doors, starting the vehicle, turning on the cabin air conditioning, etc.

[0125] Exemplarily, the control request information may be sent by a legitimate device for controlling the first device to perform a preset operation to the second node; or, the control request information may be sent by an illegitimate device to the second node.

[0126] S302: The second node sends first verification information to the first node.

[0127] Exemplarily, the first verification information may come from a legitimate device used to control the first device to perform a preset operation, or may also come from an illegal device.

[0128] In some possible implementations, S301 and S302 may be performed simultaneously, i.e., the second node sends the control request information and the first verification information to the first node simultaneously. Specifically, the second node may include the control request information and the first verification information in the same message or in different messages.

[0129] S302': The second device sends the first verification information to the first node.

[0130] The second device is a legitimate device used to control the first device to perform a preset operation. For example, the second device may include the key device in the above embodiment.

[0131] In some possible implementations, before executing S301, authentication has already been completed between the second device and the second node based on a specific protocol, a secure communication channel has been established between the second device and the second node, and the second device can transmit control instructions to the first device through the second node. For example, the specific protocol may include the Car Connectivity Consortium (CCC) protocol.

[0132] Exemplarily, the second device may transmit the first verification information to the first node through the second node, for example, the second device may transmit the first verification information to the first node through the BLE air interface; or, the second device may also send the first verification information to the first node through the cloud server.

[0133] In some possible implementations, the second device sends the first verification information to the first node according to the verification request information.

[0134] S303: The first node verifies first verification information, where the first verification information is used to verify the legitimacy of the source device of the control request information.

[0135] Exemplarily, the first node verifies the first verification information using information associated with the legitimate device.

[0136] For example, taking the second device as the legitimate device, the first node can verify the first verification information through the first public key of the second device; or, the first node can verify the first verification information through a shared key, which is a key negotiated by the first device and the second device.

[0137] S304: When the verification succeeds, the first node controls the first device to perform a preset operation according to the control request information; or, when the verification fails, the first node ignores the control request information.

[0138] When the verification is successful, it is determined that the source device of the control request information is a legitimate device, and the first device can be controlled to perform a preset operation according to the control request.

[0139] In the authentication method provided in the embodiments of the present application, when a first node receives a control request from a second node, it does not unconditionally execute the control request. Instead, it executes the control request only after determining that the source device of the control request is legitimate. If the second node is compromised by an attacker, the control request sent by the attacker can be blocked, thereby improving the security of the authentication process and, in turn, the security of the first device.

[0140] Figure 4 shows another schematic flow chart of the authentication method provided in an embodiment of the present application. Method 400 can be understood as an extension of method 300, wherein the vehicle can be understood as an example of the first device, the digital key signal processing unit can be understood as an example of the second node, the in-vehicle control unit can be understood as an example of the first node, and the key device can be understood as an example of the second device. Method 400 may include S401 to S407, wherein S404 to S406 can be understood as an implementation of S302'.

[0141] S401: The key device and the in-vehicle control unit negotiate a pre-shared key.

[0142] The pre-shared key can be understood as an example of the shared key in the above embodiment.

[0143] In some possible implementations, when the key device and the in-vehicle control unit are paired (or authenticated) for the first time, the two negotiate a pre-shared key.

[0144] Exemplarily, the pre-shared key can be dynamically generated for the vehicle. Specifically, the pre-shared key can be generated by a hardware security module inside the in-vehicle control unit. For example, if the in-vehicle control unit is a VIU, the pre-shared key is generated by a hardware security module (HSM) inside the VIU. Furthermore, the in-vehicle control unit sends the pre-shared key to the key device. In one example, the in-vehicle control unit sends the pre-shared key to the key device through the cloud server, and the pre-shared key transmission path is: in-vehicle control unit—T-Box—cloud server—key device; in another example, the in-vehicle control unit sends the pre-shared key to the key device through BLE, and the pre-shared key transmission path is: in-vehicle control unit—digital key signal processing unit—key device.

[0145] S402 : The key device sends control information to the digital key signal processing unit. The control information is used to request control of vehicle unlocking and / or starting.

[0146] Among them, the control information can be understood as an example of the control request information in the above embodiment; the vehicle unlocking and / or starting can be understood as an example of the preset operation in the above embodiment.

[0147] S403: The digital key signal processing unit sends the control information to the in-vehicle control unit.

[0148] S404: The in-vehicle control unit sends a challenge message to the key device, where the challenge message includes a random number 1.

[0149] The challenge message may be an example of the verification request information in the above embodiment; and the random number 1 may be an example of the first random number in the above embodiment.

[0150] Exemplarily, the random number 1 may be generated by a true random number generator (TRNG) of an in-vehicle control unit, or may be generated by a cryptography secure pseudorandom number generator (CPRNG), or may be generated by other methods.

[0151] S405: The key device generates an authentication code according to the pre-shared key and the random number 1.

[0152] The authentication code can be understood as an example of the first verification information in the above embodiment.

[0153] Exemplarily, the authentication code may be in the form of MAC(A, η), where A represents the control information sent by the key device and η represents the random number 1.

[0154] S406: The key device sends the authentication code to the in-vehicle control unit.

[0155] S407 , when the in-vehicle control unit successfully verifies the authentication code according to the pre-shared key, it controls the vehicle according to the control information.

[0156] For example, if in S403, the control information sent by the digital key signal processing unit to the in-vehicle control unit is A, the verification of the authentication code by the in-vehicle control unit will be successful; if the control information sent by the digital key signal processing unit to the in-vehicle control unit is not A, the verification of the authentication code by the in-vehicle control unit will fail.

[0157] It should be noted that the steps or operations of the authentication method shown in Figure 4 are only exemplary, and the embodiment of the present application may also perform other operations or variations of the operations in Figure 4. In some possible implementations, not all operations in Figure 4 need to be performed.

[0158] In one example, S402 may not be performed. That is, the control information received by the digital key signal processing unit may be sent by another device, potentially an unauthorized device. If the digital key signal processing unit receives the control information from the unauthorized device and forwards it to the in-vehicle control unit, the in-vehicle control unit will fail to verify the authentication code using the pre-shared key in S407. Furthermore, the in-vehicle control unit will ignore the control information sent by the unauthorized device.

[0159] In another example, after executing S404, if the in-vehicle control unit does not receive the authentication code within a preset time period, the in-vehicle control unit determines that the verification has failed. The preset time period may be 0.2 seconds, 0.5 seconds, or other time periods.

[0160] In another example, in S405, the key device may generate an authentication code based on another symmetric key; alternatively, the key device may generate a signature based on an asymmetric key and send it to the in-vehicle control unit, so that the in-vehicle control unit verifies the legitimacy of the source of the control information based on the signature. It is understood that the signature generated based on the asymmetric key may be an example of the first verification information.

[0161] In another example, before executing S401 , the key device and the digital key signal processing unit have completed an authentication based on a specific protocol. For example, the specific protocol may include a CCC protocol.

[0162] The authentication method provided in the embodiments of this application utilizes secondary authentication of the key device by the in-vehicle control unit. Even if the digital key signal processing unit is compromised by an unauthorized device, the control information sent by the unauthorized device can be blocked by the in-vehicle control unit due to the unauthorized device's lack of a response to the secondary authentication. This improves authentication security and, in turn, ensures vehicle safety. Furthermore, the process of negotiating the key used for secondary authentication is integrated into the key device application or pairing process, making it user-unaware, ensuring ease of use, and reducing deployment complexity.

[0163] FIG5 shows another schematic flow chart of an authentication method provided in an embodiment of the present application. Method 500 can be understood as another extension of method 300, wherein the vehicle can be understood as an example of the first device, the digital key signal processing unit can be understood as an example of the second node, the in-vehicle control unit can be understood as an example of the first node, and the key device can be understood as an example of the second device. Method 500 may include S501 to S506, wherein S505 can be understood as an implementation of S302.

[0164] S501 , the key device sends the public key PK1 to the digital key signal processing unit.

[0165] For example, when the key device and the digital key signal processing unit are initially authenticated based on the CCC protocol, the key device sends its public key PK1 to the digital key signal processing unit.

[0166] The public key PK1 can be understood as an example of the first public key in the above embodiment.

[0167] S502 , the digital key signal processing unit sends the public key PK1 to the in-vehicle control unit.

[0168] In some possible implementations, S501 and S502 occur during the initial authentication process between the key device and the digital key signal processing unit.

[0169] In some possible implementations, after the in-vehicle control unit receives the public key PK1, it can also verify the authenticity of the public key PK1 through a cloud server to further enhance security.

[0170] S503, the key device sends the control information and the signature of the private key SK1 to the digital key signal processing unit. The control information is used to request control of vehicle unlocking and / or starting. PK1 and SK1 are a key pair.

[0171] The control information may be understood as an example of the control request information in the above embodiment; and the signature of the private key SK1 may be understood as an example of the first verification information in the above embodiment.

[0172] In some possible implementations, the signature of the private key SK1 further includes a time identifier, which indicates the moment when the signature of the private key SK1 is generated. Exemplarily, the time identifier may include a timestamp.

[0173] S504: The digital key signal processing unit authenticates the control information.

[0174] Exemplarily, the digital key signal processing unit authenticates the control information and confirms that the control information comes from the key device.

[0175] S505: After successful authentication, the digital key signal processing unit sends control information and signature to the in-vehicle control unit.

[0176] Exemplarily, the digital key signal processing unit may send the control information and the signature to the in-vehicle control unit via one message; alternatively, the digital key signal processing unit may send the control information and the signature to the in-vehicle control unit separately via different messages.

[0177] S506, the in-vehicle control unit verifies the signature according to PK1, and if the verification is successful, controls the vehicle according to the control information.

[0178] For example, if in S505, the control information sent by the digital key signal processing unit to the in-vehicle control unit is sent by the key device, the signature will also be the signature of the private key SK1 of the key device, and the in-vehicle control unit will successfully verify the signature based on PK1; otherwise, the verification will fail.

[0179] It should be noted that the steps or operations of the authentication method shown in Figure 5 are only exemplary, and the embodiment of the present application may also perform other operations or variations of the operations in Figure 5. In some possible implementations, not all operations in Figure 5 need to be performed.

[0180] In one example, S503 may not be executed, that is, the control information and signature received by the digital key signal processing unit may be sent by another device, which may be an illegal device. When the digital key signal processing unit receives the control information and signature from the illegal device and forwards the control information and signature to the in-vehicle control unit, since the signature sent by the illegal device is not the signature of SK1, the verification of the signature by the in-vehicle control unit according to PK1 in S506 will fail. Furthermore, the in-vehicle control unit will ignore the control information sent by the illegal device. It is understandable that when the digital key signal processing unit is compromised by an attacker, even if the control information comes from an illegal device, the authentication of the control information in S504 will succeed, thereby allowing the control information from the illegal device to flow into the in-vehicle control unit.

[0181] In another example, the key device and the vehicle agree that the key device sends a signature along with control information to the digital key signal processing unit. Furthermore, the digital key signal processing unit sends both the control information and the signature to the in-vehicle control unit. If, in S505, the digital key signal processing unit sends only the control information to the in-vehicle control unit without receiving the signature, the in-vehicle control unit may determine, based on the lack of a signature in the received information, that the control information was sent by an unauthorized device and thus determine that verification has failed.

[0182] The authentication method provided in this embodiment verifies the authenticity of the control information's source device by verifying the signature from the digital key signal processing unit through the in-vehicle control unit. Because illegal devices lack the key device's private key and cannot forge the signature, even if the digital key signal processing unit is compromised by an illegal device, the control information sent by the illegal device can be blocked by the in-vehicle control unit. Furthermore, the public key of the key device is deployed to the in-vehicle control unit during the key device pairing process, making it user-unaware, ensuring ease of use, and reducing deployment difficulty.

[0183] It should be noted that, based on the concept of this application, those skilled in the art can apply the solution provided in this embodiment in the authentication of three-node systems such as IT systems and industrial control, and the above solution should also be included in the scope of protection of this application.

[0184] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between the various embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

[0185] The method provided in the embodiments of the present application is described in detail above with reference to Figures 1 to 5 . The apparatus provided in the embodiments of the present application will be described in detail below with reference to Figures 6 to 9 . It should be understood that the description of the apparatus embodiment corresponds to the description of the method embodiment. Therefore, for matters not described in detail, reference can be made to the method embodiment above, and for the sake of brevity, no further description will be given here.

[0186] FIG6 shows a schematic block diagram of an authentication device 2000 provided in an embodiment of the present application. The device 2000 includes a transceiver unit 2010 , a verification unit 2020 , and a processing unit 2030 .

[0187] The apparatus 2000 may include a unit for executing the method executed by the first node in FIG3 , or may include a unit for executing the method executed by the in-vehicle control unit in FIG4 or FIG5 . Furthermore, each unit in the apparatus 2000 is for implementing the corresponding process of the method embodiments in FIG3 , FIG4 , and FIG5 .

[0188] In which, when the device 2000 is used to execute the method 300 in Figure 3, the transceiver unit 2010 is used to: receive control request information from the second node, the control request information is used to request to perform a preset operation on the first device, and the first device includes the second node; the verification unit 2020 is used to: verify the first verification information, and the first verification information is used by the first node to verify the legitimacy of the source device of the control request information; the processing unit 2030 is used to: when the verification is successful, control the first device to perform the preset operation according to the control request information; or, when the verification fails, ignore the control request information.

[0189] In some possible implementations, the transceiver unit 2010 is also used to: send verification request information based on the control request information, the verification request information is used to request the first verification information from the second device, and the second device is a legitimate device used to control the first device to perform the preset operation; receive the first verification information.

[0190] In some possible implementations, the verification request information includes a first random number, the first verification information is associated with the first random number and a shared key between the first device and the second device, and the verification unit 2020 is used for: the first node verifies the first verification information according to the shared key.

[0191] In some possible implementations, the transceiver unit 2010 is further configured to: receive the first verification information from the second node.

[0192] In some possible implementations, the transceiver unit 2010 is also used to: receive a first public key of a second device, where the second device is a legitimate device used to control the first device to perform the preset operation; the verification unit 2020 is used to: verify the first verification information based on the first public key.

[0193] In some possible implementations, the first verification information is associated with a signature generated by a first private key of the second device, the first private key and the first public key form a key pair, and the verification unit 2020 successfully verifies, including: the verification unit 2020 uses the first public key to verify the first verification information.

[0194] In some possible implementations, the first verification information includes a time identifier, which indicates the moment when the first verification information is generated.

[0195] In some possible implementations, the processing unit 2030 is further used to: determine whether the first verification information is received when the transceiver unit receives the control request information; and determine that the verification has failed when the transceiver unit does not receive the first verification information within a preset time period.

[0196] Exemplarily, the transceiver unit 2010 , the verification unit 2020 and the processing unit 2030 may be provided in the in-vehicle control unit shown in FIG. 2 .

[0197] FIG7 shows a schematic block diagram of an authentication device 2100 provided in an embodiment of the present application. The device 2100 includes a generating unit 2110 and a transceiver unit 2120 .

[0198] The apparatus 2100 may include a unit for executing the method executed by the second device in Figure 3, or may include a unit for executing the method executed by the key device in Figures 4 and 5. Furthermore, each unit in the apparatus 2100 is for implementing the corresponding process of the method embodiments in Figures 3, 4, and 5, respectively.

[0199] In which, when the device 2100 is used to execute method 300 in Figure 3, the generation unit 2110 is used to: generate first verification information, which is used by the first node of the first device to verify the legitimacy of the source device of the control request information, and the control request information is used to request to perform a preset operation on the first device; the transceiver unit 2120 is used to: send the first verification information.

[0200] In some possible implementations, the transceiver unit 2120 is further configured to: receive verification request information, where the verification request information is used to request the first verification information; and send the first verification information according to the verification request information.

[0201] In some possible implementations, the verification request information includes a first random number, and the generation unit 2110 is configured to generate the first verification information according to the first random number and a shared key between the first device and the legitimate device.

[0202] In some possible implementations, the first verification information includes a signature generated by the generation unit based on a first private key of the legitimate device, the first private key and the first public key form a key pair, and the first public key is used to verify the first verification information.

[0203] In some possible implementations, the transceiver unit 2120 is further configured to: send the first public key of the legitimate device.

[0204] In some possible implementations, the first verification information further includes a time identifier, which indicates the moment when the first verification information is generated.

[0205] Exemplarily, the generating unit 2110 and the transceiver unit 2120 may be provided in the key device shown in FIG. 2 .

[0206] FIG8 shows a schematic block diagram of an authentication device 2200 provided in an embodiment of the present application. The device 2200 includes an acquiring unit 2210 and a sending unit 2220 .

[0207] The apparatus 2100 may include a unit for executing the method executed by the second node in FIG3 , or may include a unit for executing the method executed by the digital key signal processing unit in FIG4 or FIG5 . Furthermore, each unit in the apparatus 2100 is configured to implement the corresponding process of the method embodiments in FIG3 , FIG4 , and FIG5 .

[0208] In which, when the device 2200 is used to execute method 300 in Figure 3, the acquisition unit 2210 is used to obtain first verification information, and the first verification information is used by the first node of the first device to verify the legitimacy of the source device of the control request information, and the control request information is used to request to perform a preset operation on the first device; the sending unit 2220 sends the first verification information.

[0209] In some possible implementations, the first verification information is associated with a first random number and a shared key between the first device and a second device, and the second device is a legitimate device used to control the first device to perform the preset operation.

[0210] In some possible implementations, the first verification information is associated with a signature generated by a first private key of the second device, the first private key and the first public key form a key pair, the second device is a legitimate device used to control the first device to perform the preset operation, and the sending unit 2220 is also used to: send the first public key.

[0211] In some possible implementations, the first verification information includes a time identifier, which indicates the moment when the first verification information is generated.

[0212] Exemplarily, the acquiring unit 2210 and the sending unit 2220 may be provided in the digital key signal processing unit shown in FIG. 2 .

[0213] It should be understood that the division of the various units in the above device is merely a division of logical functions. In actual implementation, they may be fully or partially integrated into a single physical entity, or they may be physically separated. Furthermore, the units in the device may be implemented in the form of a processor calling software; for example, the device includes a processor connected to a memory storing instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or the functions of the various units in the device. The processor may be a general-purpose processor, such as a CPU or a microprocessor, and the memory may be a memory within the device or external to the device. Alternatively, the units in the device may be implemented in the form of hardware circuits, and the functions of some or all of the units may be implemented through the design of the hardware circuits. The hardware circuits may be understood as one or more processors. For example, in one implementation, the hardware circuit is an ASIC, and the functions of some or all of the above units may be implemented through the design of the logical relationships between the components within the circuits. In another implementation, the hardware circuit may be implemented using a PLD, such as an FPGA, which may include a large number of logic gate circuits. The connections between the logic gate circuits are configured using a configuration file to implement the functions of some or all of the above units. All units of the above apparatus may be implemented entirely in the form of software called by a processor, or entirely in the form of hardware circuits, or partially in the form of software called by a processor and the rest in the form of hardware circuits.

[0214] Each unit in the above device can be one or more processors (or processing circuits) configured to implement the above method, such as: CPU, GPU, NPU, TPU, DPU, microprocessor, DSP, ASIC, FPGA, or a combination of at least two of these processor forms.

[0215] In addition, the various units in the above devices can be fully or partially integrated together, or can be implemented independently. In one implementation, these units are integrated together and implemented in the form of a system-on-a-chip (SoC). The SoC may include at least one processor for implementing any of the above methods or implementing the functions of the various units of the device. The type of the at least one processor can be different, for example, including a CPU and FPGA, a CPU and an artificial intelligence processor, a CPU and a GPU, etc.

[0216] In a specific implementation, the operations performed by the transceiver unit 2010, the verification unit 2020, and the processing unit 2030 are performed by the same processor, or they can be performed by different processors, for example, by multiple processors. In a specific implementation, the one or more processors can be processors or chips provided in the vehicle shown in FIG2 .

[0217] In a specific implementation, the operations performed by the generating unit 2110 and the transceiver unit 2120 are performed by the same processor, or by different processors, for example, by multiple processors. In a specific implementation, the one or more processors may be a processor or chip provided in the key device shown in FIG2 .

[0218] In a specific implementation, the operations performed by the acquisition unit 2210 and the sending unit 2220 are performed by the same processor, or they can also be performed by different processors, for example, by multiple processors. In a specific implementation, the one or more processors can be processors or chips provided in the vehicle shown in FIG2 .

[0219] Figure 9 is a schematic block diagram of an authentication device provided in an embodiment of the present application. The authentication device 2300 shown in Figure 9 may include a processor 2310, a transceiver 2320, and a memory 2330. The processor 2310, transceiver 2320, and memory 2330 are interconnected via an internal connection path. The memory 2330 is configured to store instructions, and the processor 2310 is configured to execute the instructions stored in the memory 2330 to implement the authentication methods described in the aforementioned embodiments. Optionally, the memory 2330 may be coupled to the processor 2310 via an interface or integrated with the processor 2310.

[0220] It should be noted that the transceiver 2320 may include but is not limited to a transceiver device such as an input / output interface to implement communication between the device 2300 and other devices or a communication network.

[0221] The memory 2330 may be a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM).

[0222] The transceiver 2320 uses a transceiver device such as but not limited to a transceiver to implement communication between the device 2300 and other devices or communication networks to receive / send data / information used to implement the authentication method in the above embodiments.

[0223] In a specific implementation process, the device 2300 may be provided in the vehicle shown in FIG. 2 ; or may also be provided in the key device shown in FIG. 2 .

[0224] The embodiment of the present application further provides an authentication system 2400 , as shown in FIG10 , the system 2400 includes a device 2000 and a device 2200 .

[0225] An embodiment of the present application further provides an intelligent driving device, which includes the above-mentioned system 2400 or the above-mentioned device 2300.

[0226] In some possible implementations, the intelligent driving device may be a vehicle.

[0227] An embodiment of the present application further provides a mobile terminal, which includes the above-mentioned device 2100 or the above-mentioned device 2300.

[0228] In some possible implementations, the mobile terminal may be a key device.

[0229] An embodiment of the present application further provides a computer program product, which includes computer program code. When the computer program code runs on a computer, the computer implements the authentication method in the above embodiments of the present application.

[0230] An embodiment of the present application further provides a computer-readable storage medium, which stores computer instructions. When the computer instructions are executed on a computer, the computer implements the authentication method in the above-mentioned embodiments of the present application.

[0231] An embodiment of the present application also provides a chip, including a circuit, for executing the authentication method in the above embodiments of the present application.

[0232] During implementation, each step of the above method can be completed by an integrated logic circuit of the hardware in the processor or by instructions in the form of software. The method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor. The software module can be located in a storage medium mature in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or a power-on erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware. To avoid repetition, it will not be described in detail here.

[0233] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0234] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0235] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0236] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0237] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. An authentication method, characterized in that: include: A first node receives control request information from a second node, where the control request information is used to request to perform a preset operation on a first device, where the first device includes the first node and the second node; The first node verifies the first verification information, where the first verification information is used by the first node to verify the legitimacy of the source device of the control request information; When the verification succeeds, the first node controls the first device to perform the preset operation according to the control request information; or, when the verification fails, the first node ignores the control request information.

2. The method according to claim 1, characterized in that Before the first node verifies the first verification information, the method further includes: The first node sends verification request information according to the control request information, where the verification request information is used to request the first verification information from a second device, where the second device is a legitimate device used to control the first device to perform the preset operation; The first node receives the first verification information.

3. The method according to claim 2, characterized in that The verification request information includes a first random number, the first verification information is associated with the first random number and a shared key between the first device and the second device, and the first node verifies the first verification information, including: The first node verifies the first verification information according to the shared key.

4. The method according to claim 1, characterized in that Before the first node verifies the first verification information, the method further includes: The first node receives the first verification information from the second node.

5. The method according to claim 4, characterized in that The method further comprises: The first node receives a first public key of a second device, where the second device is a legitimate device used to control the first device to perform the preset operation; The first node verifies the first verification information, including: The first node verifies the first verification information according to the first public key.

6. The method according to claim 5, characterized in that The first verification information is associated with a signature generated by a first private key of the second device, the first private key and the first public key form a key pair, and the verification is successful, including: The first node verifies the first verification information using the first public key.

7. The method according to any one of claims 4 to 6, characterized in that The first verification information includes a time identifier, and the time identifier indicates a time when the first verification information is generated.

8. The method according to any one of claims 1 to 7, characterized in that The method further comprises: When the first node receives the control request information, determining whether the first verification information is received; The verification failure includes: when the first node does not receive the first verification information within a preset time period, determining that the verification has failed.

9. An authentication method, characterized in that: include: The second device generates first verification information, and the second device is used to control the first device to perform a preset operation. A legitimate device, wherein the first verification information is used by a first node of the first device to verify the legitimacy of a source device of a control request information, and the control request information is used to request to perform the preset operation on the first device; The second device sends the first verification information.

10. The method according to claim 9, characterized in that The method further comprises: The second device receives verification request information, where the verification request information is used to request the first verification information; The second device sending the first verification information includes: The second device sends the first verification information according to the verification request information.

11. The method according to claim 10, characterized in that The verification request information includes a first random number, and the method further includes: The second device generates the first verification information according to the first random number and a shared key between the first device and the second device.

12. The method according to claim 9, characterized in that The first verification information includes a signature generated by the second device according to a first private key of the second device, the first private key and the first public key form a key pair, and the first public key is used to verify the first verification information.

13. The method according to claim 12, characterized in that The method further comprises: The second device sends the first public key.

14. The method according to claim 12 or 13, characterized in that The first verification information also includes a time identifier, and the time identifier indicates the time when the first verification information is generated.

15. An authentication method, characterized in that: include: The second node of the first device acquires first verification information, where the first verification information is used by the first node of the first device to verify the legitimacy of the source device of the control request information, where the control request information is used to request to perform a preset operation on the first device; The second node sends the first verification information.

16. The method according to claim 15, characterized in that The first verification information is associated with a first random number and a shared key between the first device and a second device, and the second device is a legitimate device used to control the first device to perform the preset operation.

17. The method according to claim 15, characterized in that The first verification information is associated with a signature generated by a first private key of the second device, the first private key and the first public key form a key pair, the second device is a legitimate device for controlling the first device to perform the preset operation, and the method further includes: The second node sends the first public key.

18. The method according to claim 17, characterized in that The first verification information includes a time identifier, and the time identifier indicates a time when the first verification information is generated.

19. An authentication device, characterized in that: It includes a transceiver unit, a verification unit and a processing unit, wherein: The transceiver unit is used to: receive control request information from a second node, where the control request information is used to request to perform a preset operation on a first device, where the first device includes the second node; The verification unit is used to: verify the first verification information, where the first verification information is used by the first node to verify the legitimacy of the source device of the control request information; The processing unit is used to: when the verification is successful, control the first device to perform the preset operation according to the control request information; or when the verification fails, ignore the control request information.

20. The device according to claim 19, characterized in that The transceiver unit is also used for: Sending verification request information according to the control request information, where the verification request information is used to request the first verification information from a second device, where the second device is a legitimate device used to control the first device to perform the preset operation; The first verification information is received.

21. The device according to claim 20, characterized in that The verification request information includes a first random number, the first verification information is associated with the first random number and a shared key between the first device and the second device, and the verification unit is used to: The first node verifies the first verification information according to the shared key.

22. The device according to claim 19, characterized in that The transceiver unit is also used for: The first verification information is received from the second node.

23. The device according to claim 22, characterized in that The transceiver unit is also used for: Receiving a first public key of a second device, where the second device is a legitimate device used to control the first device to perform the preset operation; The verification unit is used for: The first verification information is verified according to the first public key.

24. The device according to claim 23, characterized in that The first verification information is associated with a signature generated by a first private key of the second device, the first private key and the first public key form a key pair, and the verification by the verification unit succeeds, including: The verification unit verifies the first verification information using the first public key.

25. The device according to any one of claims 22 to 24, characterized in that The first verification information includes a time identifier, and the time identifier indicates a time when the first verification information is generated.

26. The device according to any one of claims 19 to 25, characterized in that The processing unit is also used for: When the transceiver unit receives the control request information, determining whether the first verification information is received; When the transceiver unit does not receive the first verification information within a preset time period, it is determined that the verification has failed.

27. An authentication device, characterized in that: The device is arranged in a legitimate device for controlling a first device to perform a preset operation, and the device comprises a generating unit and a transceiver unit, wherein: The generating unit is used to: generate first verification information, the first verification information is used by a first node of the first device to verify the legitimacy of a source device of a control request information, the control request information is used to request to perform the preset operation on the first device; The transceiver unit is used to send the first verification information.

28. The device according to claim 27, characterized in that The transceiver unit is also used for: receiving a verification request message, wherein the verification request message is used to request the first verification information; The first verification information is sent according to the verification request information.

29. The device according to claim 28, characterized in that The verification request information includes a first random number, and the generating unit is used to: The first verification information is generated according to the first random number and a shared key between the first device and the legitimate device.

30. The device according to claim 27, characterized in that The first verification information includes a signature generated by the generation unit according to a first private key of the legitimate device, the first private key and the first public key form a key pair, and the first public key is used to verify the first verification information.

31. The device according to claim 30, characterized in that The transceiver unit is also used for: The first public key of the legitimate device is sent.

32. The device according to claim 30 or 31, characterized in that The first verification information also includes a time identifier, and the time identifier indicates the time when the first verification information is generated.

33. An authentication device, characterized in that: It includes an acquisition unit and a sending unit, wherein: The acquisition unit is used to acquire first verification information, where the first verification information is used by a first node of a first device to verify the legitimacy of a source device of a control request information, where the control request information is used to request to perform a preset operation on the first device; The sending unit sends the first verification information.

34. The device according to claim 33, characterized in that The first verification information is associated with a first random number and a shared key between the first device and a second device, and the second device is a legitimate device used to control the first device to perform the preset operation.

35. The device according to claim 33, characterized in that The first verification information is associated with a signature generated by a first private key of the second device, the first private key and the first public key form a key pair, the second device is a legitimate device for controlling the first device to perform the preset operation, and the sending unit is further used to: Send the first public key.

36. The device according to claim 35, characterized in that The first verification information includes a time identifier, and the time identifier indicates a time when the first verification information is generated.

37. An authentication device, characterized in that: include: Memory for storing computer programs; A processor, configured to execute a computer program stored in the memory so that the apparatus performs the method according to any one of claims 1 to 8; or, the method according to any one of claims 9 to 14; or, the method according to any one of claims 15 to 18.

38. An authentication system, characterized in that: The system comprises an apparatus as claimed in any one of claims 19 to 26 and an apparatus as claimed in any one of claims 33 to 36.

39. An intelligent driving device, characterized in that: Comprising a system as claimed in claim 38.

40. A mobile terminal, characterized in that: Comprising a device as claimed in any one of claims 27 to 32.

41. A computer-readable storage medium, characterized in that Instructions are stored thereon, and when the instructions are executed by a processor, the processor implements the method according to any one of claims 1 to 8; or the method according to any one of claims 9 to 14; or the method according to any one of claims 15 to 18.

42. A chip, characterized in that: The chip comprises a circuit for performing the method according to any one of claims 1 to 8; or, the method according to any one of claims 9 to 14; or, the method according to any one of claims 15 to 18.