Digital vehicle key use safety control method and system

Through the dynamic correlation of the trust level with the usage limit benchmark and the multiple retry mechanism, the security control problem of digital car keys in the event of network abnormalities is solved, and permission management and security verification in a network-free environment is realized to ensure the safety and reliability of vehicle use.

CN120580756APending Publication Date: 2025-09-02DONGFENG MOTOR GRP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510714186.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-09-02

AI Technical Summary

Technical Problem

The existing digital car key sharing mechanism cannot be effectively retracted when network abnormalities are not available, resulting in the person being shared that may continue to use the vehicle, which poses safety risks and lacks effective safety control strategies.

Method used

By setting the trust level of the shared person and the usage limit benchmark relationship under the unconnected network, including time and number of times, the car owner selects the trust level when sharing the digital car key, and limits the functional use of the shared person based on this level when the network is not connected; when the network is restored, the local stored key is verified through the cloud whitelist, and retry the command multiple times when the network is abnormal.

Benefits of technology

It realizes effective control of digital car key permissions when network abnormalities are not available, improves security, prevents the shared person from abusing the vehicle in a network-free environment, ensures the rights and interests of the car owner, and avoids failure to recover permissions caused by network failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120580756A_ABST
    Figure CN120580756A_ABST
Patent Text Reader

Abstract

The invention discloses a digital vehicle key use safety control method and system. The method comprises the following steps: setting a relationship between a trust level of a shared person and a use limit reference of a digital vehicle key which is not connected to a network; when the car owner shares the digital car key, the trust level of the shared person is selected; and after the vehicle owner shares the digital vehicle key, limiting the function of using the digital vehicle key by the shared person when the shared person is not connected to the network on the basis of the use limitation reference corresponding to the selected trust level. According to the invention, by setting the trust level and the use limit reference when the network is disconnected, differentiated management can be carried out according to different trust levels of the shared persons, so that the shared persons with high trust can use the vehicle conveniently, and the shared persons with low trust are limited reasonably; the technical effect that the authority of the digital car key can still be effectively controlled when the network is abnormal is achieved, and the use safety of the digital car key is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of intelligent automobile safety control, and in particular relates to a method and system for controlling the use of digital vehicle keys. Background Art

[0002] With the development of intelligent vehicles, the use of digital car keys is becoming increasingly widespread. Digital car keys can be easily shared, for example, with car owners able to share their car keys with family, friends, or designated drivers. However, in practice, retrieving existing digital car keys after sharing requires using the vehicle-to-cloud channel to send a command to the vehicle-side module to remove the shared key information from the whitelist. However, the network connection of the vehicle-to-cloud channel is susceptible to external interference, such as abnormal interference, human interruption, device failure, and poor network signal, which can cause network disconnection. When a shared digital car key needs to be retrieved, the retraction command may not be transmitted to the vehicle-side digital car key module due to reasons such as vehicle-to-cloud network disconnection, resulting in a retrieval failure. This poses certain security risks. For example, if the shared person continues to use the vehicle without the owner's knowledge, it may harm the owner's rights and interests. Currently, there is a lack of effective security control strategies to address this issue. Summary of the Invention

[0003] The purpose of the present invention is to address the deficiencies in the above-mentioned background technology and to provide a method and system for controlling the use of digital car keys in a secure manner, so as to effectively control the permissions of digital car keys when the digital car keys fail to be retrieved due to network anomalies, thereby improving the security of the use of digital car keys.

[0004] The technical solution adopted by the present invention is: a digital car key use security control method,

[0005] Setting the relationship between the trust level of the person being shared and the usage restriction criteria for the digital car key when not connected to the network;

[0006] When sharing a digital car key, the car owner selects the trust level of the person being shared with;

[0007] After the car owner shares the digital car key, the function of using the digital car key when the shared person is not connected to the network will be restricted based on the usage restriction criteria corresponding to the selected trust level.

[0008] Furthermore, the relationship between the trust level of the person being shared and the usage restriction benchmark of the digital car key when not connected to the network may include:

[0009] When the trust level of the person being shared is set to high, the usage restriction basis for the digital car key when not connected to the network is that the usage time is less than or equal to the first set time;

[0010] When the trust level of the person being shared is set to medium, the usage restriction standard for the digital car key when not connected to the network is that the usage time is less than or equal to the second set time;

[0011] When the trust level of the person being shared is set to low, the usage restriction standard for the digital car key when not connected to the network is that the usage time is less than or equal to the third set time;

[0012] The first set time is greater than the second set time and greater than the third set time.

[0013] Furthermore, the relationship between the trust level of the person being shared and the usage restriction benchmark of the digital car key when not connected to the network may include:

[0014] When the trust level of the person being shared is set to high, the usage limit for the digital car key when not connected to the network is set to a number of uses less than or equal to the first set number;

[0015] When the trust level of the person being shared is set to medium, the usage limit for the digital car key when not connected to the network is set to the number of times it has been used being less than or equal to the second set number of times.

[0016] When the trust level of the person being shared is set to low, the usage limit for the digital car key when not connected to the network is set to a number of uses less than or equal to the third set number;

[0017] The first set number of times is greater than the second set number of times and greater than the third set number of times.

[0018] Furthermore, the usage restriction benchmark corresponding to the selected trust level is used to restrict the functions of the digital car key used by the shared person when the digital car key is not connected to the network, including:

[0019] When the shared person is not connected to the Internet, he or she is allowed to use the digital car key within the set usage restrictions. If the usage restrictions are exceeded, the digital car key function will become invalid.

[0020] Furthermore, after the car owner shares the digital car key, if the person being shared with is connected to the Internet, the locally stored digital car key will be verified based on the key whitelist in the cloud. If the verification is successful, the digital car key can be used; if the verification fails, the locally stored digital car key will be deleted.

[0021] Furthermore, the use of a digital car key includes using a non-sensing digital car key and using a sensing digital car key.

[0022] Furthermore, when the car owner shares the digital car key and then takes it back, the cloud will send a take-back command to the car. If the cloud receives a reply from the car indicating that the digital car key has been deleted within a certain period of time, the digital car key is successfully taken back.

[0023] If the cloud does not receive the vehicle's feedback within a certain period of time that the digital car key has been deleted, it will send a retrieval command to the vehicle again based on the set standards until the digital car key is successfully retrieved or the number of retrieval commands sent reaches the set number.

[0024] Furthermore, the setting standard is an interval setting time or a time period of daily use of the vehicle.

[0025] Furthermore, the set number of times is 3-10 times.

[0026] A digital car key use safety control system, comprising

[0027] The FirstKey app is used to set the relationship between the trust level of the person being shared with and the usage restriction criteria for the digital car key when not connected to the network; it is used to select the trust level of the person being shared with when sharing the digital car key;

[0028] The cloud server is used to send the usage restriction benchmark corresponding to the trust level of the shared person to the second key app;

[0029] The second key APP is used to limit the functions of the digital car key used by the shared person based on usage restriction criteria when not connected to the network.

[0030] The beneficial effects of the present invention are:

[0031] 1. By setting the trust level and the usage restriction benchmark when the network is disconnected, the present invention can implement differentiated management based on the different trust levels of the shared persons. This not only facilitates the use of the vehicle by highly trusted shared persons, but also imposes reasonable restrictions on low-trust shared persons. This achieves the technical effect of effectively controlling the digital car key permissions even if the digital car key fails to be retrieved due to network anomalies, thereby improving the security of digital car key use.

[0032] 2. The key verification and deletion mechanism of the present invention is based on the cloud-based trusted whitelist, which can promptly clear out invalid local keys when the network is restored, effectively avoiding the security risks caused by the failure of digital car key retrieval due to network problems.

[0033] 3. The present invention has a strategy for restricting the use of digital car keys when not connected to the network, which further strengthens the security control of digital car keys in various usage scenarios, preventing the shared person from using the vehicle without restrictions when the network is disconnected, and comprehensively protecting the rights and interests of car owners.

[0034] 4. In the present invention, when the vehicle network signal is poor (for example, the vehicle signal is poor in an underground garage, the network signal coverage is insufficient at the vehicle's location, etc.), the cloud sends multiple sharing retrieval instruction strategies, which can avoid the sharing retrieval failure caused by objective reasons such as poor network signal to a certain extent. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 Flow chart of the method of the present invention. DETAILED DESCRIPTION

[0036] The following is a further description of specific embodiments of the present invention in conjunction with the accompanying drawings. It should be noted that the description of these embodiments is intended to facilitate understanding of the present invention and does not constitute a limitation of the present invention. In addition, the technical features involved in the various embodiments of the present invention described below may be combined with each other as long as they do not conflict with each other.

[0037] In existing technology, revoking digital car keys relies on a stable network connection. When a car owner wishes to reclaim a shared car key, the system sends a deletion command to the car via the cloud. However, in real-world scenarios, such as underground parking lots or remote areas, communication between the car and the cloud may fail due to network signal interruption. In this case, the person with whom the key was shared could continue to use the digital car key, creating a security vulnerability that could allow for the retention of vehicle control.

[0038] To address these issues, the inventors discovered that traditional permission management mechanisms lack proactive control capabilities in offline scenarios and are unable to implement differentiated management and control based on user attributes. Further analysis revealed significant differences in the trust relationships between different sharees and car owners. For example, family members and temporary drivers require different levels of permissions. Based on this understanding, the design approach shifted to building a trust grading model that dynamically associates offline usage permissions with trust levels. By presetting multi-level restriction benchmarks, a permission termination mechanism is automatically triggered in the absence of a network, forming a complementary solution between network dependence and local control.

[0039] Therefore, the present invention proposes a digital car key use security control method, such as Figure 1 As shown, the relationship between the trust level of the person being shared with and the usage restriction benchmark of the digital car key when not connected to the network is set; the car owner selects the trust level of the person being shared with when sharing the digital car key; after the car owner shares the digital car key, the function of the digital car key used by the person being shared with when not connected to the network is restricted based on the usage restriction benchmark corresponding to the selected trust level.

[0040] Among them, the trust level refers to the classification identification of the credibility of the identity of the person being shared. This can be achieved by the car owner selecting preset tags in the key app, such as classifying family members as high-level, colleagues as medium-level, and temporary service personnel as low-level. This feature makes the allocation of permissions operational and avoids subjective judgment errors. The usage restriction benchmark refers to the pre-set offline usage constraints, which can be achieved by setting a time threshold or a number of operations threshold. For example, high-level users are allowed to use offline for 48 hours, and medium-level users are allowed for 24 hours. This feature provides differentiated security strategies for different trust levels, forming a hierarchical protection mechanism.

[0041] Specifically, a mapping relationship between trust levels and offline restriction parameters is established during the initialization phase. When a car owner shares a digital car key through a mobile terminal, it is mandatory to select a trust classification label for the person being shared. This selection operation triggers the system to call pre-stored restriction benchmark data. For example, when "low trust" is selected, single-use permissions are automatically loaded. In offline usage scenarios, the vehicle control module monitors the key usage status in real time. When it detects that the usage time or number of times reaches the corresponding level limit threshold, the digital key function authorization is immediately terminated. For example, after a designated driver completes a single drive, his offline permissions automatically expire to prevent subsequent unauthorized vehicle starts.

[0042] Compared to existing technologies, traditional solutions can only update permission status when the network is connected and cannot cope with control failures caused by interruptions in vehicle-cloud communication. This solution embeds trust parameters during the key sharing phase and pre-sets dynamic expiration conditions locally, making permission control no longer completely dependent on real-time network communication. For example, in a temporary car loan scenario, even if the vehicle is offline, the borrower's key will automatically expire after exceeding the preset number of uses, effectively preventing the borrower from leaving the vehicle unused for an extended period of time.

[0043] Through the above technical solution, the present invention achieves active security control of digital car keys in offline environments, implementing differentiated permission constraints for users with different trust levels. This ensures the basic usage needs of legitimate users while preventing abuse of offline permissions by less-trusted users. In particular, in the event of a vehicle-to-cloud communication interruption, permission termination is automatically triggered based on locally stored restriction benchmarks, eliminating the risk of delayed key retrieval due to network failures.

[0044] The present invention further proposes that when the trust level of the person being shared is set to high, the usage restriction criterion for the digital car key when not connected to the network is: the usage time is less than or equal to the first set time; when the trust level of the person being shared is set to medium, the usage restriction criterion for the digital car key when not connected to the network is: the usage time is less than or equal to the second set time; when the trust level of the person being shared is set to low, the usage restriction criterion for the contactless car key when not connected to the network is: the usage time is less than or equal to the third set time; wherein the first set time is greater than the second set time, and the second set time is greater than the third set time.

[0045] It should be noted that the first, second, and third set times are not limited to fixed values ​​and can be set according to actual needs. A special level can also be set for the trust level of the person being shared with. This means that when the trust level of the person being shared with is the highest, the usage restriction for the digital car key when not connected to the network is set to unlimited usage time. In this case, the person being shared with can use the digital car key for an unlimited time when not connected to the network.

[0046] Among them, the trust level refers to the trust level divided according to the degree of association between the person being shared and the car owner. It can be achieved through manual selection by the car owner or automatic evaluation based on historical usage behavior, and is used to distinguish the usage permissions of different objects. The usage restriction benchmark refers to a preset time threshold, which can be implemented by a locally stored timing module to constrain the effective usage time of the car key in an offline state. The first set time, the second set time, and the third set time refer to the decreasing offline usage time limits set for different trust levels. For example, the first set time can be 24 hours, the second set time can be 12 hours, and the third set time can be 6 hours. The hierarchical control of permissions is achieved through a step-by-step decreasing relationship.

[0047] Specifically, when the car owner selects a high trust level, the time the shared user can use the digital car key when offline is limited to a first set time, for example, 24 hours, allowing normal vehicle operation. When the medium trust level is selected, this time is shortened to a second set time, for example, 12 hours. A low trust level is further limited to a third set time, for example, 6 hours. In an offline environment, the key app uses a local timer to accumulate offline usage time. If the set time for the corresponding level is exceeded, the digital car key function is automatically disabled. This dynamic matching of trust levels and time thresholds creates a gradient control mechanism for usage time in offline scenarios.

[0048] Compared to existing technologies, existing solutions typically only set a single offline usage time limit and fail to adjust permissions based on the identity of the person being shared. This solution, by establishing rules linking trust levels with time thresholds, enables differentiated control in offline conditions. This prevents strict restrictions on high-trust users from impacting their experience while mitigating potential abuse by low-trust users.

[0049] Through the above technical solution, the present invention automatically enforces offline usage time limits based on the trust level of the shared person when the car-cloud network experiences an anomaly, preventing car keys from being misused in offline environments. Furthermore, a design with decreasing time thresholds ensures that shared persons of different trust levels receive appropriate usage permissions, balancing security and convenience.

[0050] The present invention further proposes setting a relationship between the trust level of the shared person and the usage restriction benchmark of the digital car key when not connected to the network, including setting the usage restriction benchmark of the digital car key when not connected to the network when the trust level of the shared person is high to a number of uses less than or equal to a first set number of times, setting the usage restriction benchmark of the digital car key when not connected to the network when the trust level of the shared person is medium to a number of uses less than or equal to a second set number of times, setting the usage restriction benchmark of the digital car key when not connected to the network when the trust level of the shared person is low to a number of uses less than or equal to a third set number of times, and the first set number of times is greater than the second set number of times, which is greater than the third set number of times.

[0051] It should be noted that the first, second, and third set times are not limited to fixed values ​​and can be set according to actual needs. A special level can also be set for the trust level of the person being shared with. This means that when the trust level of the person being shared with is the highest, the usage limit for the digital car key when not connected to the network is set to "unlimited usage." In this case, the person being shared with can use the digital car key an unlimited number of times when not connected to the network.

[0052] Among them, the trust level refers to the security level divided according to the relationship with the person being shared or the usage scenario. It can be implemented through a pre-set kinship database or a historical usage behavior evaluation model to reflect the user's trustworthiness. The usage limit benchmark refers to the maximum numerical threshold allowed for operating the vehicle in an offline state. It can be implemented by comparing the counter module with the preset value stored locally. When the cumulative number of uses exceeds the threshold, the locking mechanism is triggered. The step-by-step number reduction rule refers to the gradually decreasing upper limit of the available number of times corresponding to different trust levels. It can be implemented by setting high, medium and low trust levels to correspond to different numerical ranges. For example, the first set number of times can be 10 times, the second set number of times can be 5 times, and the third set number of times can be 2 times.

[0053] Specifically, when the vehicle is disconnected from the internet, the key app continuously monitors offline usage data. Each time a door is opened or the engine is started, a counter automatically increments, and the current cumulative value is compared in real time with the threshold corresponding to the preset trust level. If it is detected that the actual usage count by a high-trust user reaches the first set number, the second set number by a medium-trust user, or the third set number by a low-trust user, the digital car key function is immediately disabled. By dynamically adjusting the upper limit of the number of operations for different trust levels, a hard blocking mechanism is established while ensuring necessary usage needs, preventing continued abuse when permission recovery fails due to network interruptions.

[0054] Compared with existing technologies, traditional solutions rely solely on network connection status for permission control and lack effective usage constraint mechanisms in offline environments. This solution establishes a mapping relationship between trust and usage count, establishes autonomous judgment logic on the local device, and implements permission management without relying on cloud communication. Existing technologies do not consider the differentiated control needs of different user groups, while this solution achieves refined permission control through three-level trust division and a decreasing number of times rule.

[0055] Through the above technical solution, the present invention effectively solves the security risks of excessive use of digital car keys in an offline state. In special scenarios where the vehicle is without a network connection, access control is automatically performed based on the locally stored trust level and a preset number of times threshold, avoiding the problem of delayed or invalid permission recovery due to network interruptions. For temporary low-trust scenarios such as designated driver services, by setting a minimum number of uses, potential unauthorized use can be forcibly terminated.

[0056] The present invention further proposes a control method that allows the shared person to use the digital car key within a set usage restriction benchmark when not connected to the network, and disables the function of the digital car key if the usage restriction benchmark is exceeded.

[0057] The usage restriction benchmark refers to the offline usage thresholds pre-defined by trust level. This can be implemented using quantitative metrics such as time or frequency, for example, assigning a higher level of trust a longer permitted usage time. This feature converts abstract trust levels into executable restriction parameters through quantitative criteria, providing a basis for judgment in offline scenarios.

[0058] Functional failure means the digital key can no longer trigger vehicle control commands. This can be achieved by using a self-destruct mechanism for the locally stored encrypted token. This feature automatically executes the failure action to block excessive use in an offline environment, forming a closed-loop security control.

[0059] Specifically, when the shared user is offline, the key app continuously monitors actual usage data and compares it against a preset benchmark. As long as the cumulative usage time does not exceed the set value or the number of uses does not reach the upper limit, vehicle control commands can be executed normally. If a situation exceeding the benchmark is detected, the locally stored encryption key immediately triggers a self-destruct sequence, causing all subsequent operation requests to be rejected due to failure to pass legitimacy verification. This dual control mechanism retains limited usage permissions while completely terminating illegal operations through an automatic expiration mechanism.

[0060] Compared to existing technologies, traditional solutions rely on network connections to reclaim permissions and are unable to promptly terminate abnormal use in offline environments. This solution, through locally stored baseline parameters and an autonomous expiration mechanism, enables real-time monitoring and permission termination in offline environments, resolving the security risks associated with existing technologies caused by network interruptions.

[0061] Through the above technical solution, the present invention effectively prevents the shared user from exceeding the limit on digital car key usage when the key app is offline, avoiding the risk of illegal vehicle use caused by permission revocation failure due to network communication failure. Specifically, it achieves real-time permission control through a localized benchmark comparison mechanism, completing security verification without relying on cloud-based instructions; and uses automatic deactivation technology to ensure that over-limit operations are physically blocked, forming an irreversible security protection.

[0062] The present invention further proposes that after the car owner shares the digital car key, if the person being shared is connected to the Internet, the locally stored digital car key is verified based on the cloud-based key whitelist. If the verification is successful, the digital car key can be used; if the verification fails, the locally stored digital car key is deleted.

[0063] Among them, the cloud-based key whitelist refers to a key identification database that stores the current authorization validity status of the car owner. It can be implemented by a real-time updated distributed database, which is synchronized with the car owner's operations. The locally stored digital car key refers to the key copy cached in the device of the sharer. It can be implemented by an encrypted storage module, which controls access rights through a key management mechanism. Verification passed means that the local key identification matches the cloud-based whitelist. It can be implemented by a hash value comparison algorithm, which ensures data integrity through one-way encryption. Deleting the locally stored digital car key means removing the invalid key copy. It can be implemented by a secure erase protocol, which overwrites the storage area and clears the key-associated data.

[0064] Specifically, when the device of the person being shared is connected to the Internet, the system triggers the cloud whitelist comparison process. The key APP sends a verification request to the cloud server, and the cloud returns a list of currently valid key identifiers. The locally stored copy of the key is decrypted and the identification information is extracted to match it with the whitelist. If the match is successful, the key usage permission is maintained; if the match fails or there is no corresponding record in the whitelist, the automatic deletion mechanism is triggered. This process is executed first when the network is connected to ensure that the authorization status verification is forced to be completed every time the person being shared uses the key online. For example, when the owner has revoked the key permission of a person being shared, the cloud whitelist will remove the key identifier. When the person being shared uses the key online again, the locally stored key will be immediately deleted because it cannot pass the verification.

[0065] Compared to existing technologies, existing solutions rely on a one-way vehicle-to-cloud channel to send deletion commands, making it impossible to guarantee timely updates to authorization status on the vehicle side during network interruptions. This solution utilizes a two-way online verification mechanism to shift key validity verification from the vehicle side to the shared device side, utilizing the inherent communication link when connected to the network for real-time verification. Furthermore, by dynamically deleting locally expired keys, it avoids residual permissions caused by network delays or command loss.

[0066] Through the above technical solution, the present invention solves the problem of digital car key retrieval failure caused by a disconnected car-cloud network. When the car owner revokes access, the shared device automatically clears the expired key upon subsequent connection, eliminating the security risks caused by network outages. For example, if the car fails to receive the retrieval instruction in a timely manner, once the shared device restores its network connection, the locally stored key copy will be forcibly deleted due to failure to pass cloud verification, effectively preventing unauthorized use.

[0067] The present invention further proposes that the use of a digital car key includes using a non-sensing digital car key and / or using a sensing digital car key.

[0068] Among them, a non-sensing digital car key refers to a key form that uses near-field communication technology to achieve automatic sensing functions, specifically using Bluetooth or NFC technology. Its operation can complete the vehicle unlocking or starting without the user's active triggering. A sensory digital car key refers to an interactive key form that requires active user triggering, specifically manually controlling the vehicle through the mobile terminal application interface. These two key forms are incorporated into a unified trust level restriction baseline framework, so that keys with different interactive forms can adapt to the same security strategy.

[0069] Specifically, in scenarios where the network is not connected, the automatic sensing feature of the contactless digital car key may lead to unconscious repeated use, while the active operation feature of the sensory digital car key may create the risk of malicious use. By unifying the two types of keys into the usage restriction benchmark system, the usage time or number threshold corresponding to the trust level can simultaneously constrain automatic sensing operations and manual triggering operations. For example, when the trust level of the shared person is set to low, the contactless key only allows a single automatic unlocking when disconnected from the network, while the sensory key only allows a single manual unlocking in the same scenario. Both key forms are subject to the same restriction policy.

[0070] Compared to existing technologies, traditional solutions typically design security policies for a single key form factor, such as limiting the use of Bluetooth keys alone. This results in a lack of control over app keys that require active user interaction. This solution, through clear classification of key forms and integrated policies, ensures that car keys implemented with different hardware can adhere to unified security control standards even in offline environments, avoiding management vulnerabilities caused by differences in key types.

[0071] Through the above technical solution, the present invention realizes unified security management of car keys with different interactive forms in the network disconnection scenario, eliminates the risk of security policy failure caused by differences in key technical forms, and ensures that the trust level limit benchmark set by the car owner can fully cover all types of digital car key usage behaviors.

[0072] The present invention further proposes that when the car owner takes back the digital car key after sharing it, the cloud will send a retrieval instruction to the car side. If the cloud receives an instruction from the car side to complete the deletion of the digital car key within a certain period of time, the digital car key is successfully retrieved; if the cloud does not receive an instruction from the car side to complete the deletion of the digital car key within a certain period of time, the retrieval instruction will be sent to the car side again based on the set standards until the digital car key is successfully retrieved or the number of times the retrieval instruction is sent reaches a set number.

[0073] Among them, the retrieval command refers to a control signal actively triggered by the cloud and transmitted to the vehicle side, which is used to instruct the vehicle side to delete the locally stored digital car key. It can be implemented in the form of an encrypted data packet. Its function is to ensure that the vehicle side can perform the key deletion operation.

[0074] The certain time refers to the time window in which the cloud waits for feedback from the vehicle, which can be implemented using a fixed time threshold, such as 5-30 minutes, preferably 10 minutes or 20 minutes. This feature is used to determine whether the vehicle has processed the retraction instruction in a timely manner.

[0075] The setting standard refers to the conditions for the cloud to resend the retrieval command, which can be specifically a time interval or a vehicle usage period, such as resending every 10 minutes or only resending when the vehicle is running. This feature is used to increase the probability of command delivery after the network is restored.

[0076] The set number of times refers to the maximum number of attempts for the cloud to send a retraction command, which can be in the range of 3-10 times. This feature is used to prevent invalid cycles caused by long-term network failures.

[0077] Specifically, after initiating the retrieval operation, the cloud first sends an encrypted retrieval instruction to the vehicle and starts a timer to monitor the feedback. If the vehicle returns a deletion completion signal within the set time, the cloud marks the key as reclaimed. If the vehicle does not respond in time, the cloud will resend the instruction according to the preset retransmission strategy, such as after an interval of 5 minutes, or trigger a second transmission when the vehicle is started next time. This process is repeated until the vehicle successfully receives and deletes the key, or the process is terminated after the maximum number of transmissions is reached and no more instructions are sent. During the retry process, the vehicle performs a local key deletion operation each time it receives an instruction, and feedbacks the execution result through the first connection after the network is restored. Therefore, by combining the redundant sending mechanism with the conditional termination strategy, it is ensured that key retrieval can be completed reliably in network fluctuation scenarios.

[0078] Compared to existing solutions, which terminate the retrieval process after a single command failure, this approach prevents the vehicle from executing the deletion operation due to network outages. This solution, however, utilizes an active retry mechanism to retry the command multiple times after network recovery, effectively overcoming the instability of the vehicle-to-cloud channel. Furthermore, by setting a maximum number of retries, it avoids wasting system resources due to persistent network failures, achieving a balance between improved reliability and resource consumption.

[0079] Through the above technical solution, the present invention solves the problem of failure to revoke digital car keys caused by abnormal vehicle-cloud network connection, ensuring that after the car owner issues a revoke command, even if a temporary network interruption occurs, the car-side key can still be deleted through a multiple retry mechanism, eliminating the safety hazards of the shared person continuing to use the vehicle and improving the reliability of digital key management.

[0080] The present invention further proposes that when a retraction instruction is sent from the cloud to the vehicle, if no feedback is received from the vehicle within a certain period of time, the retraction instruction is sent again based on the interval setting time or the time period of daily use of the vehicle.

[0081] The interval setting refers to the length of time the cloud resends commands at a fixed interval, such as 30 minutes or one hour. This feature periodically triggers a retry mechanism to ensure that commands are delivered quickly after a short network outage.

[0082] The vehicle's daily usage period refers to the period of high vehicle usage based on the owner's historical vehicle usage data. Specifically, this can be implemented as morning and evening commuting time or weekend travel time. This feature takes advantage of the fact that vehicles are more likely to connect to the network when they are active, and prioritizes sending commands during these times to increase the probability of reach.

[0083] Specifically, when the cloud sends a recall command for the first time and does not receive a response from the vehicle, if the interval setting time standard is selected, the command will be automatically resent at fixed intervals, for example, once every 1 hour. If the vehicle's daily use time period standard is selected, the resend operation will only be triggered during the preset high-frequency vehicle use periods, for example, once every 8-9 am and 6-7 pm each day. The two standards can be applied separately or in combination: in the combined mode, the cloud first retries with the interval setting time standard, and when the maximum number of intervals is reached, it switches to the vehicle's daily use time period standard to continue sending, thus forming a multi-stage coverage mechanism.

[0084] Compared with existing technologies, existing solutions only rely on single-time command transmission and have no retransmission strategy optimization. However, this solution, through the coordinated application of two standards, can not only respond quickly at fixed intervals in the early stage of network recovery, but also actively adapt the transmission timing during the period when the vehicle has a high probability of being connected to the Internet, effectively avoiding command loss due to network fluctuations or vehicle offline.

[0085] Through the above technical solution, the present invention solves the problem that the key retrieval command cannot be delivered when the vehicle-cloud network is unstable, ensuring that the key retrieval operation can be reliably completed when the network is restored or the vehicle is in normal use, thereby eliminating the safety hazards caused by the failure of command transmission.

[0086] The present invention further proposes that the set number of times the cloud sends a retraction instruction to the vehicle is configured to be 3-10 times.

[0087] Among them, the set number of times refers to the maximum number of times the cloud is allowed to repeatedly send and retrieve instructions when no feedback is received from the vehicle side. It can be implemented specifically by using a counter module, which is configured to record the current number of transmissions and compare it with a preset threshold. For example, when the counter value reaches 10 times and no feedback is received, the instruction is stopped. This feature limits the range of the number of retries, while ensuring the effective transmission of instructions and avoiding resource occupation caused by unlimited retries. Among them, the time period of daily use of the vehicle refers to the time period when the vehicle is in a non-silent state, which can be specifically judged by the vehicle ignition signal or GPS movement status. This feature is used to optimize the timing of instruction retransmission to avoid invalid sending of instructions when the vehicle is not running.

[0088] Specifically, in the scenario where the vehicle side is unable to respond to the retraction command due to network anomalies, the cloud starts the retry mechanism after sending the command for the first time. When the number of transmissions does not reach the lower limit of 3 times, the system continues to try to establish communication with the vehicle side to avoid misjudgment caused by short-term network fluctuations; when the number of transmissions reaches the upper limit of 10 times and is still unsuccessful, the system terminates the retry process and triggers the exception handling process. This mechanism strikes a balance between communication resource consumption and operational reliability through empirical threshold setting. For example, in a scenario where the vehicle side is in an underground parking lot and the network is intermittent, the system can cover the typical signal recovery time window within 3 retry cycles, and the upper limit of 10 times can prevent long-term occupation of the communication channel.

[0089] In some embodiments, the set number of retry attempts can be dynamically adjusted based on the vehicle type. For example, commercial vehicles, due to their high frequency of use, can be configured with a set number of 5-8 attempts, while residential vehicles can be configured with a set number of 3-5 attempts. Furthermore, the retry interval can be dynamically optimized based on the vehicle's historical communication success rate, for example, automatically extending the interval in areas with poor network quality.

[0090] Compared with existing technologies, existing solutions typically adopt a fixed number of command retransmission strategies, such as allowing only a single retry or unlimited retries. The former is prone to operation failures due to occasional network failures, while the latter results in continuous waste of communication resources. By limiting the number of retries to 3-10 times, this solution not only covers the typical network anomaly recovery cycle but also avoids the excessive consumption of system resources by unlimited retries. This control method based on an empirical threshold range achieves the coordinated optimization of communication reliability and resource efficiency without increasing hardware costs.

[0091] Through the above technical solution, the present invention effectively solves the problem of the vehicle side being unable to respond to the retrieval instruction in a timely manner due to network anomalies, ensuring that the key deletion operation is completed within a reasonable number of retries. At the same time, by setting an upper limit on the number of times, the communication channel is prevented from being occupied for a long time, ensuring the normal operation of other network functions of the vehicle. For example, if the vehicle-side communication module is temporarily offline, the system can complete more than 90% of the abnormal recovery scenario coverage within 3 retry cycles, and unsuccessful cases will be marked as requiring manual intervention, thus forming a complete abnormal handling closed loop.

[0092] The present invention further proposes a process for the car owner to share the digital car key on the key APP, including setting the information and trust level of the person being shared, setting the digital car key, and synchronizing all information to the cloud, and then the cloud synchronizes the digital car key to the car.

[0093] Among them, the key APP refers to the application installed on the mobile terminal, which is used to complete the creation, sharing and permission setting of digital car keys. Specifically, it can be implemented by using mobile application software with integrated encryption algorithms, such as saving key data by calling the secure storage interface provided by the operating system. The cloud refers to a remote server cluster, which is used to store and forward digital car key configuration information. Specifically, it can be implemented by using a distributed database combined with message queue technology, such as interacting with the APP and the vehicle side through the HTTP protocol. The vehicle side refers to the vehicle's built-in electronic control unit, which is used to store and execute digital car key operation instructions. Specifically, it can be implemented by using an on-board T-Box module combined with a security chip, such as receiving key data sent from the cloud through the CAN bus.

[0094] Specifically, when a car owner needs to share a digital car key, he or she first enters the identity of the person being shared with, such as a mobile phone number or email address, in the key APP interface and selects a preset trust level. The key APP encapsulates the associated digital car key parameters and the above information into a structured data packet and uploads it to the cloud server through an encrypted channel. After completing the data integrity check, the cloud server will persist the configuration information in the main database and trigger an asynchronous task to push the digital car key to the vehicle-side system of the target vehicle. After receiving the data, the vehicle-side system writes the digital car key and its corresponding permission attributes in the local secure storage area to complete the offline digital key deployment. Through this phased data transmission mechanism, the cloud is introduced as a reliable transit node between the APP and the vehicle-side to avoid the vehicle-side from failing to obtain the latest permission configuration in a timely manner due to fluctuations in the mobile network signal.

[0095] Compared to existing technologies, existing digital car key sharing solutions typically rely on direct communication between the app and the vehicle. This can easily lead to loss of permission settings or synchronization delays when the network environment is unstable. This solution, by establishing a data transfer layer in the cloud and leveraging the high availability and data retransmission mechanisms of cloud servers, ensures that even in the event of a brief network outage, final data synchronization can still be completed through redundant communication links between the cloud and the vehicle. Furthermore, the cloud stores complete permission configuration records, providing a data foundation for subsequent key status verification and audit tracing.

[0096] The above technical solution effectively solves the problem of permission information synchronization failure caused by network fluctuations during digital car key sharing. By intervening in a cloud server, multi-node redundant storage and reliable transmission of the owner's settings are achieved, ensuring that the vehicle-side system always has accurate permissions for the shared key holder, thus avoiding the security risk of inconsistent vehicle control permissions with the owner's intended intent due to network instability.

[0097] The present invention further proposes a process for the car owner to reclaim the digital car key: the car owner deletes the set shared person and digital car key on the key APP, and sends a reclaim instruction to the cloud. After receiving the reclaim instruction, the cloud synchronously deletes the shared person information and the corresponding digital car key stored in the cloud, and the cloud sends a reclaim instruction to the car.

[0098] When a car owner reclaims a digital car key, they are reclaiming the previously shared permissions to operate the vehicle. To do so, they first delete the previously entered information about the person being shared with and the corresponding digital car key on the key app interface. At the same time, the key app sends a revocation instruction to the cloud through an encrypted channel. After completing the data integrity check, the cloud server deletes the internally stored information about the person being shared with and the corresponding digital car key, and pushes the revocation instruction to the target vehicle's on-board system. After receiving the data, the on-board system deletes the digital car key and its corresponding permission attributes from the local secure storage area, and sends a feedback instruction to the cloud confirming the deletion is complete. Upon receiving the feedback instruction, the cloud indicates that the key has been successfully reclaimed.

[0099] The present invention further proposes that the shared person uses the digital car key, including using the digital car key when the shared person's key APP is not connected to the network and using the digital car key when the shared person's key APP is connected to the network.

[0100] Among them, when the key APP of the shared person is not connected to the network, the specific method of using the digital car key is: the key APP detects whether the usage time of the digital car key exceeds the set usage time or whether the number of uses exceeds the set number of uses. If it does not exceed, the car key can be used several times to operate the vehicle. If it exceeds, the car key is prohibited from being used several times to operate the vehicle. That is, the above-mentioned restriction on the function of using the digital car key when the shared person is not connected to the network.

[0101] The shared person's key APP uses the digital car key when it connects to the network. The process is: when used for the first time, the key APP downloads the digital car key from the cloud based on the shared person's information; when used subsequently, the key APP automatically requests the cloud's trusted key whitelist, and the cloud sends the key whitelist to the key APP. The key APP compares the locally stored digital car key with the digital car key in the key whitelist. If there is a digital car key in the key whitelist that is consistent with the locally stored digital car key, the verification is successful and the shared person can use the digital car key; otherwise, the verification fails, and the key APP automatically deletes the locally stored digital car key.

[0102] In order to implement the above-mentioned digital car key use safety control method, the present invention also provides a digital car key use safety control system, including

[0103] The first key APP (i.e. the key APP on the car owner's mobile terminal) is used to set the relationship between the trust level of the person being shared and the usage restriction benchmark of the digital car key when not connected to the network; it is used to realize the above-mentioned functional operations of the car owner sharing the digital car key and retrieving the digital car key.

[0104] The cloud server (i.e. the cloud above) is used to cooperate with the first key APP and the second key APP to realize the functional operations of the car owner sharing the digital car key and retrieving the digital car key, as well as the functional operations of the shared person using the digital car key. The specific implementation process has been described in the above method and will not be elaborated here.

[0105] The second key APP (i.e. the key APP on the mobile terminal of the person being shared) is used by the person being shared to realize the above-mentioned functional operations of using the digital car key, including restricting the functions of using the digital car key by the person being shared based on the usage restriction benchmark when not connected to the network, and key verification and deletion operations based on the cloud-based trusted whitelist when connected to the network.

[0106] The vehicle-side controller (or control system) is used to implement vehicle driving operations based on digital car keys based on instructions from the car owner, the person being shared with, the cloud, etc.

[0107] The above are only specific embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be covered by the scope of protection of the present invention. Matters not described in detail in this specification belong to the prior art known to those skilled in the art.

Claims

1. A digital car key usage security control method, characterized by: Setting the relationship between the trust level of the person being shared and the usage restriction criteria for the digital car key when not connected to the network; When sharing a digital car key, the car owner selects the trust level of the person being shared with; After the car owner shares the digital car key, the function of using the digital car key when the shared person is not connected to the network will be restricted based on the usage restriction criteria corresponding to the selected trust level.

2. The digital car key usage security control method according to claim 1, characterized in that: The relationship between the trust level of the person being shared and the usage restriction criteria for the digital car key when not connected to the network includes: When the trust level of the person being shared is set to high, the usage restriction basis for the digital car key when not connected to the network is that the usage time is less than or equal to the first set time; When the trust level of the person being shared is set to medium, the usage restriction standard for the digital car key when not connected to the network is that the usage time is less than or equal to the second set time; When the trust level of the person being shared is set to low, the usage restriction standard for the digital car key when not connected to the network is that the usage time is less than or equal to the third set time; The first set time is greater than the second set time and greater than the third set time.

3. The digital car key usage security control method according to claim 1, characterized in that: The relationship between the trust level of the person being shared and the usage restriction criteria for the digital car key when not connected to the network includes: When the trust level of the person being shared is set to high, the usage limit for the digital car key when not connected to the network is set to a number of uses less than or equal to the first set number; When the trust level of the person being shared is set to medium, the usage limit for the digital car key when not connected to the network is set to the number of times it has been used being less than or equal to the second set number of times. When the trust level of the person being shared is set to low, the usage limit for the digital car key when not connected to the network is set to a number of uses less than or equal to the third set number; The first set number of times is greater than the second set number of times and greater than the third set number of times.

4. The digital car key usage security control method according to claim 1, characterized in that: The usage restriction benchmark corresponding to the selected trust level restricts the functions of the shared person using the digital car key when not connected to the network, including: When the shared person is not connected to the Internet, he or she is allowed to use the digital car key within the set usage restrictions. If the usage restrictions are exceeded, the digital car key function will become invalid.

5. The digital car key usage security control method according to claim 1, characterized in that: After the car owner shares the digital car key, if the person being shared is connected to the Internet, the locally stored digital car key will be verified based on the cloud key whitelist. If the verification is successful, the digital car key can be used; If the verification fails, the locally stored digital car key will be deleted.

6. The digital car key usage security control method according to claim 1, characterized in that: The use of a digital car key includes using a non-sensing digital car key and using a sensing digital car key.

7. The digital car key usage security control method according to claim 1, characterized in that: When the car owner shares the digital car key and takes it back, the cloud will send a take-back command to the car. If the cloud receives the car's feedback within a certain period of time that the digital car key has been deleted, the digital car key is successfully taken back. If the cloud does not receive the vehicle's feedback within a certain period of time that the digital car key has been deleted, it will send a retrieval command to the vehicle again based on the set standards until the digital car key is successfully retrieved or the number of retrieval commands sent reaches the set number.

8. The digital car key usage security control method according to claim 7, characterized in that: The setting standard is an interval setting time or a time period of daily use of the vehicle.

9. The digital car key usage security control method according to claim 7, characterized in that: The set number of times is 3-10 times.

10. A digital car key use safety control system, characterized by: include The FirstKey app is used to set the relationship between the trust level of the person being shared with and the usage restriction criteria for the digital car key when not connected to the network; it is used to select the trust level of the person being shared with when sharing the digital car key; The cloud server is used to send the usage restriction benchmark corresponding to the trust level of the shared person to the second key app; The second key APP is used to limit the functions of the digital car key used by the shared person based on usage restriction criteria when not connected to the network.