Digital key access authentication method and device, terminal equipment and storage medium

By collaboratively generating and verifying key verification information at the vehicle terminal, device terminal, and cloud, the problem of key validity verification in offline states in digital car key systems is solved, achieving higher security and saving storage resources.

CN120582912BActive Publication Date: 2025-10-28SHANGHAI INGEEK CYBER SECURITY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511089031.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-05
Publication Date
2025-10-28
Estimated Expiration
2045-08-05

AI Technical Summary

Technical Problem

Existing digital car key systems cannot verify the validity of keys in a timely manner when the device and vehicle are offline, resulting in the continued use of invalid keys, which occupies vehicle storage resources and cannot effectively prevent unauthorized access.

Method used

By working collaboratively across the vehicle's infotainment system, the device itself, and the cloud, key verification information is generated and verified to ensure the legality and timeliness of the key upon first access. Local key verification information is then deleted to prevent deleted keys from being accessed again.

Benefits of technology

It improves vehicle security, reduces the storage resource consumption of the blacklist mechanism, and effectively prevents the continued use of deleted keys.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120582912B_ABST
    Figure CN120582912B_ABST
Patent Text Reader

Abstract

This invention provides a digital key access authentication method, apparatus, terminal device, and storage medium. The method generates key verification information simultaneously with the digital key generated in the cloud. When the vehicle's infotainment system receives a digital key access request from the device, if it determines that the digital key is not a valid key already accessed, it requests the device to provide key verification information and verifies the digital key based on this information. Upon successful verification, the system notifies the device to delete the locally stored key verification information. Compared to existing technologies where the vehicle's infotainment system cannot intercept vehicle access permissions from keys that have not expired in time, this method, by adding a key initial access verification mechanism, effectively prevents deleted keys from regaining vehicle access, improving vehicle security. Furthermore, it does not require additional storage resources compared to a blacklist mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of vehicle security technology, and in particular to a digital key access authentication method and device, terminal equipment and storage medium. Background Technology

[0002] In a digital car key system, keys typically need to be stored on both the device and the vehicle. The key in the device is used when the device is offline, while the key in the vehicle is used for key management on the vehicle's infotainment screen and for verifying the validity of the device's key when the vehicle is offline.

[0003] In the scenario where car owners use their vehicles, if the key in the vehicle is deleted (e.g., through the car's infotainment screen), and the digital key device happens to be offline at the time, it cannot invalidate the local key in time. When the device and the vehicle re-authenticate the key, the vehicle will still recognize that the device contains a valid key and continue to use the key function. This will cause the car's infotainment system to be unable to recognize the validity of the invalidated key and will not be able to prevent the continued use of the invalidated key.

[0004] For example, if the car owner cancels the sharing of the key and the friend's device is offline, the vehicle will still recognize the key on the friend's device as a valid key when the friend's device accesses the vehicle again.

[0005] Most existing digital car key specifications in the industry do not consider scenarios where the device is offline when the key is managed inside the vehicle or remotely deleted. When both the device and the vehicle are offline and online verification of the key's validity is impossible, if a user deletes the key from the vehicle, the vehicle will still recognize the device as a new, legitimate device and allow it to continue functioning. This fails to effectively restrict the continued use of deleted keys. In remote deletion scenarios that rely on the vehicle's online network, the vehicle uses a blacklist mechanism to block the continued use of deleted keys. If many keys are deleted, the blacklist data will continuously increase, consuming the vehicle's storage resources. Summary of the Invention

[0006] This invention provides a digital key access authentication method and device, a terminal device and a storage medium. By verifying the validity of the initial access permission of the digital key, it prevents invalid keys that have not been deleted in time from illegally accessing the vehicle, thereby improving vehicle security. Compared with a blacklist mechanism, it can save vehicle-side storage resources.

[0007] In a first aspect, embodiments of the present invention provide a digital key access authentication method, applied to a vehicle-mounted system, the method comprising:

[0008] The device receives a digital key access authentication request and determines whether the corresponding digital key is a valid key that has been accessed based on the access authentication request.

[0009] When the digital key is not a valid key that has been connected, the device requests the key authentication information of the digital key to be connected; the key authentication information includes the access permission authentication information of the digital key.

[0010] After receiving the key verification information sent by the device, the device authenticates the digital key to be accessed based on the key verification information. When the digital key to be accessed passes authentication, the device returns an authentication success result to the device so that the device can delete the key verification information after the digital key passes authentication.

[0011] As one embodiment, the method further includes:

[0012] When the key verification information is not obtained or the authentication of the digital key to be connected fails based on the key verification information, a request is made to the cloud to authenticate the digital key to be connected, and the cloud returns the authentication result to determine whether to allow the digital key to connect to the vehicle terminal.

[0013] Secondly, embodiments of the present invention also provide a digital key access authentication method, applied to a device, the method comprising:

[0014] A digital key access authentication request is sent to the vehicle-mounted terminal. When the vehicle-mounted terminal receives a request from the vehicle-mounted terminal to obtain the key verification information of the digital key to be accessed, and the key verification information is stored locally, the key verification information is sent to the vehicle-mounted terminal so that the vehicle-mounted terminal can authenticate the digital key to be accessed based on the key verification information. If the vehicle-mounted terminal determines that the digital key to be accessed is not a valid key that has already been accessed, it requests the key verification information from the device terminal. The key verification information includes the access permission authentication information of the digital key. The key verification information is generated and sent to the device terminal by the cloud when the digital key is generated.

[0015] When the vehicle terminal receives a confirmation that the digital key to be connected has passed authentication, the key verification information is deleted.

[0016] Thirdly, embodiments of the present invention also provide a digital key access authentication method, applied in the cloud, the method comprising:

[0017] In response to a digital key generation request from the device, a digital key and key verification information for the digital key are generated; the key verification information includes access permission authentication information for the digital key.

[0018] The generated digital key and key verification information are returned to the device so that when the vehicle terminal requests access to the digital key from the device and the digital key is not a valid key that has already been accessed, the device terminal can perform access authentication on the digital key based on the key verification information, and delete the key verification information after the access authentication is successful.

[0019] Fourthly, embodiments of the present invention provide a digital key access authentication device configured on a vehicle-mounted system, the device comprising:

[0020] The initial access judgment module is used to receive the digital key access authentication request sent by the device and determine whether the corresponding digital key is a valid key that has been accessed based on the access authentication request.

[0021] The key verification request module is used to request key verification information of the digital key to be accessed from the device when the digital key is not the valid key that has been accessed; the key verification information includes the access permission authentication information of the digital key;

[0022] The key verification module is used to authenticate the digital key to be accessed based on the key verification information sent by the device after receiving the key verification information. When the digital key to be accessed passes the authentication, the module returns the authentication pass result to the device so that the device can delete the key verification information after the digital key passes the authentication.

[0023] Fifthly, embodiments of the present invention provide a digital key access authentication device, configured on a device, the device comprising:

[0024] The access request module is used to send a digital key access authentication request to the vehicle-mounted terminal. When it receives a request from the vehicle-mounted terminal to obtain the key verification information of the digital key to be accessed and has the key verification information stored locally, it sends the key verification information to the vehicle-mounted terminal so that the vehicle-mounted terminal can authenticate the digital key to be accessed based on the key verification information. If the vehicle-mounted terminal determines that the digital key to be accessed is not a valid key that has already been accessed, it requests the key verification information from the device terminal. The key verification information includes the access permission authentication information of the digital key. The key verification information is generated and sent to the device terminal by the cloud when the digital key is generated.

[0025] The deletion module is used to delete the key verification information when the vehicle terminal returns a message indicating that the digital key to be accessed has passed authentication.

[0026] Sixthly, embodiments of the present invention provide a digital key access authentication device configured in the cloud, the device comprising:

[0027] The key and proof generation module is used to generate a digital key and key proof information of the digital key in response to a digital key generation request from the device; the key proof information includes the access permission authentication information of the digital key.

[0028] The sending module is used to return the generated digital key and key verification information to the device, so that when the vehicle terminal requests access to the digital key from the device and the digital key is not a valid key that has already been accessed, the device terminal can perform access authentication on the digital key based on the key verification information, and the device terminal can delete the key verification information after the access authentication is successful.

[0029] In a seventh aspect, embodiments of the present invention provide a terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the authentication method as described in the first aspect.

[0030] Eighthly, embodiments of the present invention provide a vehicle-mounted terminal, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the authentication method as described in the second aspect.

[0031] In a ninth aspect, embodiments of the present invention provide a cloud, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the authentication method as described in the third aspect.

[0032] In a tenth aspect, embodiments of the present invention provide a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the authentication method as described in the first, second, or third aspect.

[0033] The technical solutions provided by the embodiments of the present invention have at least the following positive effects compared with the prior art:

[0034] In this embodiment of the invention, the vehicle-mounted terminal receives a digital key access authentication request sent by the device terminal. Based on the access authentication request, it determines whether the corresponding digital key is a valid key that has already been accessed. If the digital key is not a valid key that has already been accessed, it requests the key verification information of the digital key to be accessed from the device terminal. The key verification information includes the access permission authentication information of the digital key. The key verification information is generated by the cloud when the digital key is generated and then sent to the device terminal and stored locally on the device terminal. After receiving the key verification information sent by the device terminal, it authenticates the digital key to be accessed based on the key verification information. When the digital key to be accessed passes the authentication, it returns the authentication success result to the device terminal so that the device terminal can delete the key verification information after the digital key passes the authentication. Therefore, once the digital key on the device successfully connects to the vehicle's infotainment system for the first time, the key authentication information on the device is deleted. Subsequently, if the valid key that has been connected is deleted by the vehicle but not promptly invalidated by the device, since the deleted key is no longer a valid key that has been connected, when the device requests access to the vehicle's infotainment system for the deleted key, the system will request the key authentication information of the deleted digital key to be re-authenticated. Because the key authentication information has been deleted, the key deleted by the vehicle cannot be authenticated again, thus preventing the use of digital keys that have been deleted by the vehicle but not promptly invalidated by the device, improving vehicle security, and saving storage resources compared to a blacklist mechanism. Attached Figure Description

[0035] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0036] Figure 1 This is a flowchart illustrating the digital key access authentication method provided in Embodiment 1 of the present invention;

[0037] Figure 2 This is a flowchart illustrating the digital key access authentication method provided in Embodiment 2 of the present invention;

[0038] Figure 3 This is a flowchart illustrating the digital key access authentication method provided in Embodiment 3 of the present invention;

[0039] Figure 4 This is a flowchart illustrating the digital key access authentication method provided in an embodiment of the present invention.

[0040] Figure 5 This is a schematic diagram of the structure of the digital key access authentication device provided in Embodiment 4 of the present invention;

[0041] Figure 6 This is a schematic diagram of the structure of the digital key access authentication device provided in Embodiment 5 of the present invention;

[0042] Figure 7 This is a schematic diagram of the structure of the digital key access authentication device provided in Embodiment Six of the present invention;

[0043] Figure 8 This is a schematic diagram of the vehicle-mounted terminal provided in Embodiment 7 of the present invention;

[0044] Figure 9 This is a schematic diagram of the structure of the terminal device provided in Embodiment 8 of the present invention;

[0045] Figure 10 This is a schematic diagram of the cloud structure provided in Embodiment 9 of the present invention. Detailed Implementation

[0046] The present invention will be further described in detail below with reference to the accompanying drawings and examples. It will be understood that the specific embodiments described herein are intended only to illustrate the present invention and are not intended to limit the present invention. It should also be noted that, for ease of description, the accompanying drawings only illustrate portions relevant to the present invention, not all structures.

[0047] The following describes a digital key access authentication method, apparatus, terminal device, and storage medium according to embodiments of this application with reference to the accompanying drawings. Addressing the problem mentioned in the background art that the vehicle-mounted system cannot prevent deleted but not promptly deactivated digital keys from continuing to be used in the vehicle, this application provides a digital key access authentication method. In this method, the vehicle-mounted system receives a digital key access authentication request sent by the device terminal. Based on the access authentication request, it determines whether the corresponding digital key is a valid key that has been accessed. When the digital key is not a valid key that has been accessed, it requests key verification information of the digital key to be accessed from the device terminal. The key verification information includes access permission authentication information of the digital key. This key verification information is generated by the cloud when the digital key is generated and then sent to the device terminal and stored locally on the device terminal. Upon receiving the key verification information sent by the device terminal, it authenticates the digital key to be accessed based on the key verification information. When the digital key to be accessed passes authentication, it returns an authentication success result to the device terminal, allowing the device terminal to delete the key verification information after the digital key passes authentication. Therefore, after the digital key on the device successfully connects to the vehicle's infotainment system for the first time, the key verification information on the device is deleted locally. When the vehicle's infotainment system deletes the connected key, if the device does not invalidate the key in time, when the device requests the vehicle's infotainment system to connect the key again, the vehicle's infotainment system will request the key verification information from the device. Since the key verification information has been deleted after the first successful connection, the vehicle's infotainment system cannot obtain the key verification information, so the key cannot pass the access authentication. This allows the vehicle to prevent the continued use of the deleted key, thus improving vehicle security.

[0048] Figure 1 This is a flowchart illustrating the digital key access authentication method provided in Embodiment 1 of the present invention. This method is used by the vehicle's infotainment system to verify the initial access permission of the digital key, ensuring that deleted keys that have not been used for the first time can be prevented from continuing to be used. The method of this application can be executed by a digital key access authentication device provided in this embodiment of the invention. This device can be implemented in software and configured in the digital key system of the vehicle's infotainment system. Specifically, this embodiment of the invention includes steps 101 to 103.

[0049] Step 101: Receive the digital key access authentication request sent by the device, and determine whether the corresponding digital key is a valid key that has been accessed based on the access authentication request.

[0050] The term "device-side" is short for "digital key device-side." The device requests a digital key from the cloud. The cloud generates the digital key and its associated key verification information simultaneously, and returns both to the device. The device stores the digital key and key verification information in its local Secure Element (SE) chip. The digital key and key verification information can be generated using common technologies. For example, the cloud can generate the digital key based on the device's identity information, the vehicle's infotainment system's identity information, and the digital key's user information; details will not be elaborated here. The key verification information includes access permission authentication information for the digital key, used to verify the legality and validity of the digital key offline. The key verification information may include a digital certificate, which may contain a CA (Certificate Authority) public key, validity period, etc., used for device authentication. The digital verification information can be generated based on asymmetric encryption and signature technologies. The cloud generates a key pair: a private key for signing and a public key for verification. The cloud's public key is distributed to both the device and the vehicle's infotainment system. The cloud uses the private key to sign the key data and key validity period information to generate the key verification information. The vehicle's infotainment system uses a cloud-based private key to verify the key's authentication information, thereby validating the digital key's legitimacy and validity. It's understood that the key's authentication information can also be generated in other ways, as long as it meets the offline verification requirements for the digital key's legitimacy and validity; no specific restrictions are imposed here.

[0051] After obtaining the digital key and key verification information, when the device first requests access to the vehicle's infotainment system, it sends a digital key access authentication request. The vehicle's system performs initial access authentication on the digital key. If the initial authentication is successful, the digital key is added to a whitelist. The vehicle's system maintains a whitelist of all connected and valid digital keys. When the vehicle's system deletes a digital key from the device, the deleted digital key is removed from the whitelist, confirming that the digital key is no longer a valid connected key. If the requested digital key is in the whitelist, it is a valid connected digital key, and initial access authentication is not required; the device can continue to legally access and use the vehicle. The key verification information is used offline to verify the legality and timeliness of the digital key's initial access. The key verification information has a certain time limit and can only be used within a certain period after the digital key is downloaded to prevent hackers from using legitimate key verification information for attacks. Offline access authentication for digital keys means that the device can be online, but the initial access authentication process does not require the device to be online.

[0052] Step 102: When the digital key is not a valid key that has been connected, request the key verification information of the digital key to be connected from the device.

[0053] If the device has key verification information stored locally, it will send the key verification information to the vehicle's terminal if requested by the terminal.

[0054] Step 103: After receiving the key verification information sent by the device, authenticate the digital key to be connected based on the key verification information. When the digital key to be connected passes the authentication, return the authentication success result to the device so that the device can delete the key verification information after the digital key passes the authentication.

[0055] When the vehicle's infotainment system recognizes the digital key as a new key—meaning it has not been registered on the vehicle before or has been registered but deleted—it requests key verification information from the device. Upon receiving the verification information, the system verifies its legality and validity. If verification is successful, the vehicle stores the key data, and the device simultaneously clears the key verification information. The infotainment system can verify or decrypt the key verification information based on the public keys stored in the cloud and on the device, thereby verifying the digital key data and whether the digital key has expired. Alternatively, it can employ verification methods known to those skilled in the art, which will not be elaborated upon here.

[0056] It's worth noting that when the vehicle's infotainment system fails to obtain key verification information or when authentication of the digital key to be accessed fails based on the key verification information, it requests authentication of the digital key from the cloud. Based on the authentication result returned by the cloud, it determines whether to allow the digital key to access the vehicle's infotainment system. If the cloud's authentication result deems the digital key valid, the vehicle's infotainment system adds the digital key to its whitelist; if the cloud's authentication result deems the digital key invalid, the vehicle's infotainment system prevents the digital key from further accessing the vehicle. Initial access authentication based on key verification information reduces reliance on the cloud, and authentication can be successfully performed even when the vehicle's infotainment system and the device are offline.

[0057] Compared with the prior art, the embodiments of the present invention involve the vehicle-mounted terminal receiving a digital key access authentication request sent by the device terminal, determining whether the corresponding digital key is a valid key that has already been accessed based on the access authentication request, and requesting key verification information of the digital key to be accessed from the device terminal when the digital key is not a valid key that has already been accessed. The key verification information includes access permission authentication information of the digital key, and the key verification information is generated by the cloud when the digital key is generated and then sent to the device terminal and stored locally on the device terminal. After receiving the key verification information sent by the device terminal, the vehicle-mounted terminal authenticates the digital key to be accessed based on the key verification information. When the digital key to be accessed passes the authentication, the vehicle-mounted terminal returns the authentication pass result to the device terminal so that the device terminal can delete the key verification information after the digital key passes the authentication. When generating a digital key, the cloud generates key verification information along with the key. When the digital key is connected for the first time, the vehicle's infotainment system requests the key verification information stored locally from the device and verifies it. If the verification is successful, the digital key can be added to the whitelist. If the device does not have key verification information or the verification fails, the digital key can be further authenticated through the cloud. By performing multi-level authentication on the first-time connected digital key, invalid keys can be prevented from being used, improving vehicle security. At the same time, there is no need to record invalid keys through a blacklist mechanism, saving vehicle-side storage resources.

[0058] Figure 2 This is a flowchart illustrating the digital key access authentication method provided in Embodiment 2 of the present invention. This method can be applied to the device side to verify the initial access permission of the digital key, ensuring that continued vehicle use by deleted keys that have not been used for the first time is prevented. The method of this application can be executed by a digital key access authentication device provided in this embodiment of the invention. This device can be implemented in software and configured on the digital key device side. Specifically, this embodiment of the invention includes steps 201 and 202.

[0059] Step 201: Send a digital key access authentication request to the vehicle terminal. When the vehicle terminal receives a request from the vehicle terminal to obtain the key verification information of the digital key to be accessed and has the key verification information stored locally, the vehicle terminal sends the key verification information to the vehicle terminal so that the vehicle terminal can authenticate the digital key to be accessed based on the key verification information.

[0060] Before sending a digital key access authentication request to the vehicle's infotainment system, the device requests the cloud to generate a digital key. After the cloud generates the digital key and key verification information, it sends it to the device, which then stores the digital key and key verification information in the SE chip.

[0061] When the vehicle terminal determines that the digital key to be accessed is not a valid key that has already been accessed, it requests key verification information from the device terminal. The key verification information includes the access permission authentication information of the digital key.

[0062] Step 202: When the digital key to be connected is successfully authenticated and returned by the vehicle terminal, delete the key verification information.

[0063] When the key verification information is deleted, if the device requests the digital key to access the vehicle's infotainment system again, the vehicle's infotainment system will need to perform an initial access authentication for the digital key since the digital key has been deleted. This means requesting the device to provide key verification information to verify the legality and validity of the digital key. Since the device has deleted the key verification information, the initial access authentication cannot be passed, thus preventing the invalid digital key from being used in the vehicle.

[0064] Compared with the prior art, the embodiments of the present invention generate key verification information at the same time as generating the digital key in the cloud. When the digital key is connected for the first time, the vehicle terminal requests the device to provide the key verification information stored locally and verifies the key verification information. If the verification is successful, the digital key can be added to the whitelist. If the device does not have key verification information or the verification fails, the digital key can be further authenticated through the cloud. By performing multi-level authentication on the digital key connected for the first time, invalid keys can be prevented from continuing to be used, improving vehicle security. At the same time, there is no need to record invalid keys through a blacklist mechanism, saving vehicle terminal storage resources.

[0065] Figure 3 This is a flowchart illustrating the digital key access authentication method provided in Embodiment 3 of the present invention. This method can be applied to the cloud to verify the initial access permission of a digital key, ensuring that continued vehicle use by deleted keys that have not been used for the first time is prevented. The method of this application can be executed by a digital key access authentication device provided in this embodiment of the invention. This device can be implemented in software and configured in the cloud. Specifically, this embodiment of the invention includes steps 301 and 302.

[0066] Step 301: In response to the digital key generation request from the device, generate a digital key and its key verification information. The key verification information includes the access permission authentication information of the digital key.

[0067] Step 302: Return the generated digital key and key verification information to the device. This allows the vehicle's infotainment system to authenticate the digital key based on the key verification information when the device requests access to the digital key and the digital key is not an already valid key. After successful authentication, the device deletes the key verification information. It is understood that the processes executed by the device, vehicle's infotainment system, and cloud in this embodiment correspond to those in embodiments one and two, and will not be repeated here.

[0068] Compared with the prior art, the embodiments of the present invention generate key verification information at the same time as generating the digital key in the cloud. When the digital key is connected for the first time, the vehicle terminal requests the device to provide the key verification information stored locally and verifies the key verification information. If the verification is successful, the digital key can be added to the whitelist. If the device does not have key verification information or the verification fails, the digital key can be further authenticated through the cloud. By performing multi-level authentication on the digital key connected for the first time, invalid keys can be prevented from continuing to be used, improving vehicle security. At the same time, there is no need to record invalid keys through a blacklist mechanism, saving vehicle terminal storage resources.

[0069] like Figure 4 As shown, the digital key access authentication method of this invention embodiment is described below based on the digital key system, the method including S401~S419.

[0070] S401, The device sends a digital key generation request to the cloud.

[0071] S402, Generate digital keys and key verification information in the cloud.

[0072] S403: The cloud returns digital key and key verification information to the device.

[0073] S404. The device receives and stores the digital key and key verification information.

[0074] S405, The device sends a digital key access request to the vehicle's infotainment system.

[0075] S406. The vehicle's infotainment system determines whether the digital key to be connected is a valid key that has already been connected. If yes, proceed to S408 to end the first key connection authentication. If no, proceed to S407.

[0076] S407. The vehicle-mounted terminal requests key verification information from the device terminal.

[0077] S409. The device determines whether key verification information is stored locally. If yes, proceed to S410; otherwise, proceed to S412.

[0078] S410, The device sends key verification information to the vehicle's terminal.

[0079] S411. The vehicle terminal verifies the key verification information and determines whether the key verification information passes. If it passes, proceed to S415; otherwise, proceed to S412.

[0080] S412, The vehicle's infotainment system requests a cloud-based online authentication digital key from the cloud.

[0081] S413, Cloud-based authentication of digital keys.

[0082] S414, The cloud returns the cloud authentication result to the vehicle's infotainment system.

[0083] S415. The vehicle's infotainment system determines whether the digital key has passed cloud authentication. If it has, proceed to S416 to store the digital key. If it has not passed, proceed to S419 to disable the digital key.

[0084] S416, Store the digital key on the vehicle's infotainment system and add the digital key to the whitelist.

[0085] S417. If the device has key verification information, the vehicle terminal will notify the device to delete the key verification information.

[0086] S418. Delete key verification information on the device side.

[0087] Embodiment 4 of the present invention provides a digital key access authentication device, configured on the vehicle's infotainment system. For example... Figure 5 As shown, the authentication device 500 includes: an initial access judgment module 502, a key proof request module 504, and a key proof verification module 506.

[0088] The initial access judgment module 502 is used to receive the digital key access authentication request sent by the device and determine whether the corresponding digital key is a valid key that has been accessed based on the access authentication request.

[0089] The key verification request module 504 is used to request key verification information of the digital key to be accessed from the device when the digital key is not a valid key that has been accessed; the key verification information includes the access permission authentication information of the digital key.

[0090] The key verification module 506 is used to authenticate the digital key to be accessed based on the key verification information sent by the device after receiving the key verification information. When the digital key to be accessed passes the authentication, it returns the authentication result to the device so that the device can delete the key verification information after the digital key passes the authentication.

[0091] Compared with existing technologies, the authentication device of this invention generates key verification information simultaneously with the digital key generated in the cloud. When the vehicle terminal receives a digital key access request from the device, if it determines that the digital key is not a valid key that has already been accessed, it requests the device to provide key verification information and verifies the digital key based on the key verification information. After successful verification, it notifies the device to delete the locally stored key verification information. By adding a key initial access verification mechanism, it can effectively prevent deleted keys from obtaining vehicle access again, improving vehicle security, and does not require more storage resources compared to a blacklist mechanism.

[0092] Embodiment 5 of the present invention provides a digital key access authentication device, configured on the device side. For example... Figure 6 As shown, the authentication device 600 includes: a request access module 602 and a deletion module 604.

[0093] The access request module 602 is used to send a digital key access authentication request to the vehicle terminal. When it receives a request from the vehicle terminal to obtain the key verification information of the digital key to be accessed and has the key verification information stored locally, it sends the key verification information to the vehicle terminal so that the vehicle terminal can authenticate the digital key to be accessed based on the key verification information. When the vehicle terminal determines that the digital key to be accessed is not a valid key that has already been accessed, it requests the key verification information from the device terminal. The key verification information includes the access permission authentication information of the digital key. The key verification information is generated and sent to the device terminal by the cloud when the digital key is generated.

[0094] The deletion module 604 is used to delete the key verification information when the digital key to be accessed is successfully authenticated and returned by the vehicle terminal.

[0095] Compared with existing technologies, the authentication device of this invention generates key verification information simultaneously with the digital key generated in the cloud. When the vehicle terminal receives a digital key access request from the device, if it determines that the digital key is not a valid key that has already been accessed, it requests the device to provide key verification information and verifies the digital key based on the key verification information. After successful verification, it notifies the device to delete the locally stored key verification information. By adding a key initial access verification mechanism, it can effectively prevent deleted keys from obtaining vehicle access again, improving vehicle security, and does not require more storage resources compared to a blacklist mechanism.

[0096] Embodiment 6 of the present invention provides a digital key access authentication device configured in the cloud. For example... Figure 7 As shown, the authentication device 700 includes a key and certificate generation module 702 and a sending module 704.

[0097] The key and certificate generation module 702 is used to generate a digital key and key certificate information for the digital key in response to a digital key generation request from the device. The key certificate information includes access permission authentication information for the digital key.

[0098] The sending module 704 is used to return the generated digital key and key verification information to the device, so that when the vehicle terminal requests access to the digital key from the device and the digital key is not a valid key that has already been accessed, it can perform access authentication of the digital key based on the key verification information, and delete the key verification information after the access authentication is successful.

[0099] Compared with existing technologies, the authentication device of this invention generates key verification information simultaneously with the digital key generated in the cloud. When the vehicle terminal receives a digital key access request from the device, if it determines that the digital key is not a valid key that has already been accessed, it requests the device to provide key verification information and verifies the digital key based on the key verification information. After successful verification, it notifies the device to delete the locally stored key verification information. By adding a key initial access verification mechanism, it can effectively prevent deleted keys from obtaining vehicle access again, improving vehicle security, and does not require more storage resources compared to a blacklist mechanism.

[0100] Figure 8 This is a schematic diagram of the vehicle-mounted terminal provided in Embodiment 7 of the present invention. The vehicle-mounted terminal 80 includes a memory 81, a processor 82, and a computer program stored in the memory 81 and executable on the processor 82. When the processor 82 executes the program, it implements the technical solution described in Embodiment 1 above.

[0101] Figure 9 This is a schematic diagram of the structure of a terminal device provided in Embodiment 8 of the present invention. The terminal device 90 includes a memory 91, a processor 92, and a computer program stored in the memory 91 and executable on the processor 92. When the processor 92 executes the program, it implements the technical solution described in Embodiment 2 above.

[0102] Figure 10 This is a schematic diagram of the cloud structure provided in Embodiment 9 of the present invention. The cloud 100 includes a memory 110, a processor 120, and a computer program stored in the memory 110 and executable on the processor 120. When the processor 120 executes the program, it implements the technical solution described in Embodiment 3 above.

[0103] Embodiment 10 of the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a computer processor, is used to perform the technical solution of any method embodiment.

[0104] Based on the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or grid device, etc.) to execute the methods described in the various embodiments of the present invention.

[0105] It is worth noting that in the embodiments of the above-mentioned device, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of each functional unit are only for easy distinction between each other and are not used to limit the scope of protection of the present invention.

[0106] Note that the above description is merely a preferred embodiment of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of the present invention, the scope of which is determined by the scope of the appended claims.

Claims

1. A digital key access authentication method, characterized in that, Applied to in-vehicle infotainment systems, the method includes: The device receives a digital key access authentication request and determines whether the corresponding digital key is a valid key that has been accessed based on the access authentication request. When the digital key is not a valid key that has been connected, the device requests the key authentication information of the digital key to be connected; the key authentication information includes the access permission authentication information of the digital key. After receiving the key verification information sent by the device, the device authenticates the digital key to be accessed based on the key verification information. When the digital key to be accessed passes the authentication, the device returns the authentication success result to the device so that the device can delete the key verification information after the digital key passes the authentication. The method further includes: when the key verification information is not obtained or the authentication of the digital key to be accessed based on the key verification information fails, requesting the cloud to authenticate the digital key to be accessed, and determining whether to allow the digital key to access the vehicle terminal based on the authentication result returned by the cloud.

2. A digital key access authentication method, characterized in that, Applied to the device side, the method includes: A digital key access authentication request is sent to the vehicle-mounted terminal. When the vehicle-mounted terminal receives a request from the vehicle-mounted terminal to obtain the key verification information of the digital key to be accessed, and the key verification information is stored locally, the key verification information is sent to the vehicle-mounted terminal so that the vehicle-mounted terminal can authenticate the digital key to be accessed based on the key verification information. If the vehicle-mounted terminal determines that the digital key to be accessed is not a valid key that has already been accessed, it requests the key verification information from the device terminal. The key verification information includes the access permission authentication information of the digital key. The key verification information is generated and sent to the device terminal by the cloud when the digital key is generated. When the vehicle terminal receives a confirmation that the digital key to be connected has passed authentication, the key verification information is deleted. The method further includes: when the vehicle terminal fails to obtain the key verification information or fails to authenticate the digital key to be accessed based on the key verification information, requesting the cloud to authenticate the digital key to be accessed, and determining whether to allow the digital key to access the vehicle terminal based on the authentication result returned by the cloud.

3. A digital key access authentication method, characterized in that, Applied to the cloud, the method includes: In response to a digital key generation request from the device, a digital key and key verification information for the digital key are generated; the key verification information includes access permission authentication information for the digital key. The generated digital key and key verification information are returned to the device so that when the vehicle terminal requests access to the digital key from the device and the digital key is not a valid key that has already been accessed, the device terminal can perform access authentication on the digital key based on the key verification information. After the access authentication is successful, the device terminal deletes the key verification information. The method further includes: when the vehicle terminal fails to obtain the key verification information or fails to authenticate the digital key to be accessed based on the key verification information, requesting the cloud to authenticate the digital key to be accessed, and determining whether to allow the digital key to access the vehicle terminal based on the authentication result returned by the cloud.

4. A digital key access authentication device, characterized in that, The device, configured on the vehicle's infotainment system, includes: The initial access judgment module is used to receive the digital key access authentication request sent by the device and determine whether the corresponding digital key is a valid key that has been accessed based on the access authentication request. The key verification request module is used to request key verification information of the digital key to be accessed from the device when the digital key is not the valid key that has been accessed; the key verification information includes the access permission authentication information of the digital key; The key verification module is used to authenticate the digital key to be accessed based on the key verification information sent by the device after receiving the key verification information. When the digital key to be accessed passes the authentication, the module returns the authentication pass result to the device so that the device can delete the key verification information after the digital key passes the authentication. The device is also used to request the cloud to authenticate the digital key to be accessed when the key authentication information is not obtained or the authentication of the digital key to be accessed based on the key authentication information fails, and to determine whether to allow the digital key to access the vehicle terminal based on the authentication result returned by the cloud.

5. A digital key access authentication device, characterized in that, Configured on the device side, the device includes: The access request module is used to send a digital key access authentication request to the vehicle-mounted terminal. When it receives a request from the vehicle-mounted terminal to obtain the key verification information of the digital key to be accessed and has the key verification information stored locally, it sends the key verification information to the vehicle-mounted terminal so that the vehicle-mounted terminal can authenticate the digital key to be accessed based on the key verification information. If the vehicle-mounted terminal determines that the digital key to be accessed is not a valid key that has already been accessed, it requests the key verification information from the device terminal. The key verification information includes the access permission authentication information of the digital key. The key verification information is generated and sent to the device terminal by the cloud when the digital key is generated. The deletion module is used to delete the key verification information when the vehicle terminal returns a message indicating that the digital key to be accessed has passed authentication. The device is also used to request the cloud to authenticate the digital key to be accessed when the vehicle terminal fails to obtain the key authentication information or fails to authenticate the digital key to be accessed based on the key authentication information, and to determine whether to allow the digital key to access the vehicle terminal based on the authentication result returned by the cloud.

6. A digital key access authentication device, characterized in that, Configured in the cloud, the device includes: The key and proof generation module is used to generate a digital key and key proof information of the digital key in response to a digital key generation request from the device; the key proof information includes the access permission authentication information of the digital key. The sending module is used to return the generated digital key and key verification information to the device, so that when the vehicle terminal requests access to the digital key from the device and the digital key is not a valid key that has already been accessed, the device terminal can perform access authentication on the digital key based on the key verification information, and the device terminal can delete the key verification information after the access authentication is successful. The device is also used to request the cloud to authenticate the digital key to be accessed when the vehicle terminal fails to obtain the key authentication information or fails to authenticate the digital key to be accessed based on the key authentication information, and to determine whether to allow the digital key to access the vehicle terminal based on the authentication result returned by the cloud.

7. A terminal device, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the method as described in claim 2.

8. A vehicle-mounted terminal, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the method as described in claim 1.

9. A cloud platform, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the method as described in claim 3.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1 to 3.

Citation Information

Patent Citations

  • Digital key authorization issuing and withdrawing method and system

    CN113706743A

  • Intelligent lock key management system and method

    CN119274255A