Communication method and related equipment

By using private key signature and public key encryption technology during the upload process of car smart keys, combined with certificate verification and periodic updates, the security risks in the generation, distribution, use and update of car smart keys are solved, end-to-end encrypted communication and identity authentication are achieved, and network security and user experience are improved.

CN120639306APending Publication Date: 2025-09-12YINWANG INTELLIGENT TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510622600.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-07-30
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

Automotive smart keys face huge security risks during their generation, distribution, use, and update processes, and are unable to achieve end-to-end security throughout their entire life cycle, resulting in a high risk of cyberattacks and causing economic losses to users and OEMs.

Method used

By using private key signature and public key encryption technology when uploading the car smart key to the server, combined with certificate verification and periodic update of key credential information, network security is improved, and keys are generated and stored in vehicles and electronic devices to achieve end-to-end encrypted communication and authentication.

Benefits of technology

It improves the network security of car smart keys, prevents keys from being tampered with and stolen, enhances user experience and system security, and reduces the risk of network attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639306A_ABST
    Figure CN120639306A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a communication method and related equipment, and relates to the field of intelligent automobiles, and the method comprises the steps: determining key certificate information based on an automobile intelligent key; and sending the key certificate information to a server. According to the method provided by the embodiment of the invention, the network security of the full life cycle of the automobile intelligent key can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application. The application number of the original application is 202280007451.0, and the original application date is July 30, 2022. The entire content of the original application is incorporated into this application by reference. Technical Field

[0002] The embodiments of the present application relate to the field of security, and in particular to a communication method and related equipment. Background Art

[0003] With the rapid development of mobile internet, mobile apps like Mobile Butler can integrate mobile phone control functions with car modules, achieving intelligent connection between mobile phones and cars, thereby providing users with comfortable and convenient driving. Smart car keys can not only replace traditional car keys, but also add functions such as mobile phone remote start, keyless entry, and automatic door opening and closing.

[0004] However, the network security level of car smart keys is far from meeting the corresponding requirements, resulting in very prominent network security issues. For example, car smart keys face huge security risks during the generation, distribution, use and update processes. At present, the industry's car smart keys are unable to achieve end-to-end security throughout the entire life cycle, and are therefore at risk of being attacked in certain weak links, causing huge economic losses to users and original equipment manufacturers (OEMs). Among them, the network security issue of car smart keys is currently the top three network attacks on smart cars. Therefore, in order to avoid the above network security issues, it is necessary to ensure the network security of the entire car smart key system on the cloud, mobile phone, and vehicle side end-to-end, and to raise the network security levels of the cloud, mobile phone, and vehicle side to the same high security level. How to ensure end-to-end network security has become a systemic problem that needs to be solved urgently. Summary of the Invention

[0005] The embodiments of the present application provide a communication method and related equipment to provide a way to upload, distribute and use automobile smart keys, thereby improving the network security of automobile smart keys.

[0006] In a first aspect, an embodiment of the present application provides a communication method, which is applied to a vehicle, wherein the vehicle includes a smart key, which is an electronic key information used to control the vehicle, including:

[0007] Determining key credential information based on the vehicle smart key;

[0008] Send key credential information to the server.

[0009] The embodiments of the present application can improve the network security of the car smart key during the process of uploading the car smart key to the server.

[0010] In one possible implementation, determining key credential information based on the vehicle smart key includes:

[0011] The car smart key is used as a key to encrypt the car smart key and obtain key credential information.

[0012] In the embodiment of the present application, the car smart key is encrypted by using the car smart key as a key, which can improve the security of the car smart key.

[0013] In one possible implementation, the vehicle further includes vehicle identification information corresponding to the vehicle, and determining the key credential information based on the vehicle smart key includes:

[0014] Use the first private key to sign the car smart key and vehicle identification information to obtain signature data;

[0015] Obtaining a second public key, and using the second public key to encrypt the signature data, the vehicle smart key, and the vehicle identification information to obtain a first ciphertext; wherein the second public key is sent by the server to the vehicle;

[0016] Key credential information is generated based on the first ciphertext and the first public key, where the first public key corresponds to the first private key.

[0017] In the embodiment of the present application, the car smart key and vehicle identification information are signed by the private key, and the signature data, car smart key and vehicle identification information are encrypted using the public key, which can improve the security of the car smart key.

[0018] In one possible implementation, the method further includes:

[0019] The first certificate is sent to the server. The first certificate includes vehicle identification information and a first public key. The first certificate is signed by a third-party organization and issued to the vehicle. The first certificate is used to verify the first public key.

[0020] In the embodiment of the present application, by sending the first certificate, the server can verify the identity of the vehicle based on the first certificate, thereby improving security.

[0021] In one possible implementation, the method further includes:

[0022] The second public key is verified according to the second certificate.

[0023] In the embodiment of the present application, the second public key is verified by the second certificate, thereby ensuring that the second public key is sent by the server, preventing others from tampering with the first public key, and thus ensuring the security of the encrypted data.

[0024] In one possible implementation, before verifying the second public key according to the second certificate, the method further includes:

[0025] Receive the second certificate sent by the server, where the second certificate includes the server's identity information and a second public key. The second certificate is signed by a third-party organization and issued to the server.

[0026] In the embodiment of the present application, by receiving the second certificate, the identity of the server can be verified based on the second certificate, thereby improving security.

[0027] In one possible implementation, the vehicle pre-stores a root certificate, which is used to verify the certificate. After receiving the second certificate sent by the server, the method further includes:

[0028] Verify the signature of the second certificate based on the root certificate.

[0029] In the embodiment of the present application, the second certificate is signed by the root certificate, thereby ensuring the authenticity of the second certificate and preventing the second certificate from being forged.

[0030] In one possible implementation manner, the second certificate is pre-installed in the vehicle.

[0031] In one possible implementation, the first public key and the first private key are generated in a security module of the vehicle.

[0032] In the embodiment of the present application, since the first public key and the first private key are generated in the security module of the vehicle, the security of the first public key and the first private key can be improved.

[0033] In one possible implementation, the car smart key is generated in the vehicle's factory mode.

[0034] In the embodiment of the present application, since the car smart key is generated in the vehicle's factory mode, the security of the car smart key can be improved.

[0035] In one possible implementation, the method further includes:

[0036] Periodically update key credential information based on the car smart key;

[0037] Send the updated key credential information to the server.

[0038] In the embodiment of the present application, the security of the car smart key can be improved by periodically updating the car smart key.

[0039] In one possible implementation, after sending the updated key credential information to the server, the method further includes:

[0040] A key update prompt is sent to the first electronic device to prompt the user to update the car smart key.

[0041] The embodiment of the present application can improve the user experience by actively reminding the user to update the car smart key.

[0042] In one possible implementation, the method further includes:

[0043] Receiving a key update request sent by a first electronic device, wherein the key update request is used to request generation of a new vehicle smart key;

[0044] Determining new key credential information based on the new vehicle smart key;

[0045] Send the new key credential information to the server.

[0046] In the embodiment of the present application, the car smart key is updated by the user's active request, thereby improving the flexibility of the car smart key update and also improving the security of the car smart key.

[0047] In one possible implementation, the key update request includes an old vehicle smart key. Before determining new key credential information based on the new vehicle smart key, the method further includes:

[0048] Authenticate old car smart keys.

[0049] In an embodiment of the present application, before updating the car smart key, the old car smart key is authenticated to prevent unlawful users from maliciously stealing the car smart key, thereby improving the security of the car smart key.

[0050] In one possible implementation, the method further includes:

[0051] If it is detected that the authentication of the first electronic device requesting to use the new car smart key is successful, the old car smart key in the vehicle is deleted.

[0052] In the embodiment of the present application, after the car smart key is successfully updated, the old car smart key is deleted, which can effectively save the vehicle's storage resources.

[0053] In a second aspect, an embodiment of the present application further provides a communication method, applied to a vehicle, comprising:

[0054] sending a random value to the first electronic device;

[0055] Receiving a first control message sent by a first electronic device; wherein the first control message is generated based on a vehicle smart key and a random value;

[0056] The first control message is verified based on the vehicle smart key and the random value. If the verification passes, the vehicle is controlled according to the first control message.

[0057] The embodiments of the present application can effectively improve the network security of automobile smart keys during the use of the keys.

[0058] In one possible implementation, verifying the first control message based on the vehicle smart key and the random value includes:

[0059] Generate a second control message based on the vehicle smart key and the random value;

[0060] comparing the second control message with the first control message;

[0061] If the verification passes, controlling the vehicle according to the first control message includes:

[0062] If the first control message is consistent with the second control message, the vehicle is controlled according to the first control message.

[0063] In the embodiment of the present application, the correctness of the control message can be verified by performing consistency check on the control message, thereby improving the network security of the car smart key.

[0064] In a third aspect, an embodiment of the present application further provides a communication method, applied to a vehicle, comprising:

[0065] Obtaining a control request sent by the second electronic device; wherein the control request includes a temporary key and a control instruction;

[0066] Verify the temporary key;

[0067] Performing a time validity check according to a first valid time period; the first valid time period is used to represent a valid time period of the temporary key; the first valid time period is stored in a security module of the vehicle;

[0068] If the temporary key verification passes and the time validity verification passes, the vehicle is controlled according to the control instruction of the second electronic device.

[0069] The embodiments of the present application can effectively improve the network security of the car smart key when the user borrows the car.

[0070] In one possible implementation, before obtaining the control request sent by the second electronic device, the method further includes:

[0071] Obtaining a vehicle request; wherein the vehicle request includes a first valid time period;

[0072] generating a temporary key according to the first valid time period;

[0073] Send the temporary key to the server.

[0074] The embodiments of the present application can effectively enable users to borrow vehicles when the vehicles are connected to the Internet.

[0075] In one possible implementation, the vehicle use request is sent by the first electronic device via short-range communication.

[0076] In the embodiment of the present application, direct communication between the first electronic device and the vehicle can simplify user operations and improve user experience.

[0077] In one possible implementation, the vehicle request is sent by the first electronic device via a mobile network.

[0078] The embodiments of the present application can enable users to remotely control the vehicle, thereby facilitating the user's control of the vehicle.

[0079] In one possible implementation, the car request is sent by the car rental platform.

[0080] The embodiments of the present application can realize the control of the vehicle by a third party.

[0081] In one possible implementation, the vehicle use request further includes a signed vehicle smart key, and the signed vehicle smart key is obtained by signing the vehicle smart key with a third private key. After obtaining the vehicle use request, the method further includes:

[0082] The car smart key is signed and verified according to the third public key, and the third public key is sent to the vehicle by the first electronic device.

[0083] In one possible implementation, the method further includes:

[0084] The first certificate is sent to the first electronic device. The first certificate includes vehicle identification information and a first public key. The first certificate is signed by a third-party organization and issued to the vehicle. The first certificate is used to verify the first public key.

[0085] In one possible implementation manner, the third public key is verified according to the third certificate.

[0086] In one possible implementation, before verifying the third public key according to the third certificate, the method further includes:

[0087] A third certificate sent by the first electronic device is received, where the third certificate includes identity information of the first electronic device and a third public key, and is signed by a third-party organization and issued to the first electronic device.

[0088] In one possible implementation, the vehicle pre-stores a root certificate, which is used to verify the certificate. After receiving the third certificate sent by the first electronic device, the method further includes:

[0089] Verify the signature of the third certificate based on the root certificate.

[0090] In one possible implementation, the first valid time period is encrypted by the automobile smart key, and after the authentication is performed based on the automobile smart key, the method further includes:

[0091] The encrypted first valid time period is decrypted using the automobile smart key, and the decrypted first valid time period is securely stored.

[0092] In one possible implementation, the method further includes:

[0093] Receiving encrypted data sent by the second electronic device; wherein the encrypted data is obtained by encrypting the temporary credentials and the first valid time period using the car smart key, the car smart key is stored in the first electronic device, and the temporary credentials are generated by the first electronic device;

[0094] Use the car smart key to decrypt the encrypted data and obtain the temporary credentials and the first valid time period;

[0095] Verify the temporary credentials and the first validity period;

[0096] If the verification passes, a temporary key is generated;

[0097] The temporary key is encrypted according to the encrypted data to obtain an encrypted temporary key, and the encrypted temporary key is sent to the second electronic device.

[0098] The embodiments of the present application can effectively enable users to borrow vehicles when the vehicles are not connected to the Internet.

[0099] In one possible implementation, after generating the temporary key, the method further includes:

[0100] The first valid time period is securely stored.

[0101] In one possible implementation, temporary credentials are generated based on the car smart key and a first valid time period, and encrypted data is sent to the server by the first electronic device.

[0102] In one possible implementation, the control request includes an encrypted temporary key, which is obtained by encrypting the temporary key using the first public key. Before verifying the temporary key, the method further includes:

[0103] The encrypted temporary key is decrypted using the first private key to obtain the temporary key.

[0104] In one possible implementation, the method further includes:

[0105] The first certificate is sent to the second electronic device. The first certificate includes vehicle identification information and a first public key. The first certificate is signed by a third-party organization and issued to the vehicle. The first certificate is used to verify the first public key.

[0106] In one possible implementation, the method further includes:

[0107] A fourth public key is verified according to the fourth certificate, wherein the fourth public key is sent to the vehicle by the second electronic device.

[0108] In one possible implementation, before verifying the fourth public key according to the fourth certificate, the method further includes:

[0109] A fourth certificate sent by the second electronic device is received, where the fourth certificate includes identity information of the second electronic device and a fourth public key, and is signed by a third-party organization and issued to the second electronic device.

[0110] In one possible implementation, the vehicle pre-stores a root certificate, which is used to verify the certificate. After receiving the fourth certificate sent by the second electronic device, the method further includes:

[0111] Verify the signature of the fourth certificate based on the root certificate.

[0112] In one possible implementation, verifying the temporary key includes:

[0113] sending the random value to the second electronic device;

[0114] Receiving a first control message sent by a second electronic device; wherein the first control message is generated based on a temporary key and a random value;

[0115] A temporary key verification is performed on the first control message based on the temporary key and the random value.

[0116] In one possible implementation, the method further includes:

[0117] A key failure notification is sent to the second electronic device, wherein the key failure notification is used to indicate that the temporary key is failed.

[0118] The embodiment of the present application reminds the user that the temporary key has expired through an active reminder, thereby preventing the user from using the temporary key incorrectly, thereby improving the user's usage experience.

[0119] In one possible implementation, before sending the key failure notification to the second electronic device, the method further includes:

[0120] If it is detected that the current system time exceeds the first valid time period, the temporary key is set to invalid.

[0121] In one possible implementation, the method further includes:

[0122] If the time validity check fails, the user will be prompted that the temporary key has expired.

[0123] In a fourth aspect, an embodiment of the present application further provides a communication method, applied to a server, comprising:

[0124] Receive key credential information;

[0125] The key credential information is securely stored, and secure storage is storage through secure encryption means.

[0126] The embodiments of the present application can improve the network security of the car smart key during the process of uploading the car smart key to the server.

[0127] In one possible implementation, the key credential information includes a first ciphertext and a first public key, and securely storing the key credential information includes:

[0128] Decrypt the first ciphertext using the second private key to obtain the signature data, the car smart key, and the vehicle identification information;

[0129] Use the first public key to verify the signature data;

[0130] If the signature verification is passed, the car smart key and vehicle identification information will be securely stored.

[0131] In one possible implementation, the method further includes:

[0132] Obtaining a third public key, and using the third public key to encrypt the vehicle smart key to obtain an encrypted vehicle smart key; wherein the third public key is sent by the first electronic device to the server;

[0133] The encrypted car smart key is sent to the first electronic device.

[0134] In an embodiment of the present application, the car smart key is encrypted by the third public key and then sent to the first electronic device, thereby improving the security of the car smart key.

[0135] In one possible implementation, before sending the encrypted automobile smart key to the first electronic device, the method further includes:

[0136] Receiving a registration request; wherein the registration request includes a user account and vehicle identification information corresponding to the user account;

[0137] A user account is created based on the registration request, and the user account corresponds to the car smart key and vehicle identification information.

[0138] In an embodiment of the present application, by registering the user on the server, the server can verify the user's account before sending the car smart key, thereby improving the security of the car smart key.

[0139] In one possible implementation, the method further includes:

[0140] The second certificate is sent to the vehicle. The second certificate includes the server's identity information and the second public key. The second certificate is signed by a third-party organization and issued to the server. The second certificate is used to verify the second public key.

[0141] In one possible implementation, the method includes:

[0142] The first public key is verified according to the first certificate.

[0143] In one possible implementation, before verifying the first public key according to the first certificate, the method further includes:

[0144] Receive a first certificate sent by the vehicle, where the first certificate includes vehicle identification information and a first public key. The first certificate is signed by a third-party organization and issued to the vehicle.

[0145] In one possible implementation, the server pre-stores a root certificate, and the root certificate is used to verify the certificate. After verifying the first public key according to the first certificate, the method further includes:

[0146] Verify the signature of the first certificate based on the root certificate.

[0147] In one possible implementation manner, the first certificate is pre-installed in the server.

[0148] In one possible implementation, the first public key is generated in a security module of the vehicle.

[0149] In one possible implementation, the car smart key is generated in the vehicle's factory mode.

[0150] In one possible implementation, after receiving the key credential information, the method further includes:

[0151] The key credential information is periodically received and used for periodically updating the key credential information.

[0152] In one possible implementation, after periodically receiving key credential information, the method further includes:

[0153] A key update prompt is sent to the first electronic device to prompt the user to update the car smart key.

[0154] In one possible implementation, the method further includes:

[0155] receiving a credential update instruction, wherein the credential update instruction is used to instruct to update the key credential information, and the credential update instruction includes new key credential information;

[0156] The key credential information is updated based on the credential update instruction.

[0157] In one possible implementation, the credential update indication further includes an old vehicle smart key, the old vehicle smart key is stored in the server, and the new key credential information includes the new vehicle smart key. Before updating the key credential information based on the credential update indication, the method further includes:

[0158] Authenticate old car smart keys.

[0159] In one possible implementation, the method further includes:

[0160] If it is detected that the authentication of the new key credential information is successful, the new key credential information is stored and the old key credential information is deleted.

[0161] In a fifth aspect, an embodiment of the present application further provides a communication method, applied to a server, comprising:

[0162] Receiving a key acquisition request sent by a second electronic device, wherein the key acquisition request is used to request acquisition of first information; wherein the first information is used to determine a temporary key;

[0163] The first information is sent to the second electronic device.

[0164] In one possible implementation, the first information is a temporary key, and sending the first information to the second electronic device includes:

[0165] The temporary key is encrypted using the fourth public key and then sent to the second electronic device, wherein the fourth public key is sent by the second electronic device to the server.

[0166] In one possible implementation, the temporary key is sent by the vehicle to the server.

[0167] In one possible implementation, the first information is encrypted data, and sending the first information to the second electronic device includes:

[0168] The encrypted data is sent to the second electronic device, wherein the encrypted data is obtained by encrypting the temporary credentials and the first valid time period using the car smart key, the car smart key is stored in the first electronic device, the temporary credentials are generated by the first electronic device, and the first valid time period is used to represent the valid time period of the temporary key.

[0169] In one possible implementation, the encrypted data is sent by the first electronic device to the server.

[0170] In one possible implementation, the key acquisition request includes a temporary account number, and the key acquisition request is used to request to obtain first information corresponding to the temporary account number.

[0171] In a sixth aspect, an embodiment of the present application provides a communication method, applied to a first electronic device, including:

[0172] Receive the random value sent by the vehicle;

[0173] Obtaining a car smart key, and generating a first control message according to the car smart key and the random value, wherein the first control message is used to control the vehicle;

[0174] A first control message is sent to the vehicle.

[0175] The embodiments of the present application can improve the safety of the vehicle when the user uses the key to control the vehicle.

[0176] In one possible implementation, the first control message is generated in a trusted execution environment TEE.

[0177] In an embodiment of the present application, by generating the first control message in a trusted execution environment TEE, the security of the first control message can be improved, and the first control message can be prevented from being stolen, thereby improving the safety of the vehicle.

[0178] In one possible implementation, obtaining the vehicle smart key includes:

[0179] Receiving an encrypted car smart key sent by the server; wherein the encrypted car smart key is obtained by the server encrypting the car smart key using a third public key, and the third public key is sent to the server by the first electronic device;

[0180] The encrypted car smart key is decrypted using the third private key to obtain the car smart key.

[0181] In one possible implementation, the third public key and the third private key are generated in a trusted execution environment TEE of the first electronic device.

[0182] In an embodiment of the present application, by generating the third public key and the third private key in a trusted execution environment TEE, the security of the third public key and the third private key can be improved, and the theft of the third public key and the third private key can be prevented, thereby improving the safety of the vehicle.

[0183] In one possible implementation, decrypting the encrypted car smart key using the third private key to obtain the car smart key includes:

[0184] In the trusted execution environment (TEE) of the first electronic device, decrypt the encrypted car smart key using the third private key to obtain the car smart key;

[0185] After decrypting the encrypted automobile smart key using the third private key to obtain the automobile smart key, the method further includes:

[0186] The car smart key is stored in the trusted execution environment TEE of the first electronic device.

[0187] In an embodiment of the present application, the security of the car smart key can be improved by performing decryption and storage operations in a trusted execution environment (TEE).

[0188] In one possible implementation, before receiving the encrypted automobile smart key sent by the server, the method further includes:

[0189] A key request is sent to the server, where the key request includes a user account and is used to obtain the car smart key corresponding to the user account.

[0190] In one possible implementation, the method further includes:

[0191] Sending a key update request to the vehicle; wherein the key update request is used to generate a new car smart key;

[0192] Get a new car smart key from the server.

[0193] In one possible implementation, after obtaining a new car smart key from the server, the method further includes:

[0194] Use the new car smart key to authenticate with the vehicle;

[0195] If the authentication is successful, the old car smart key in the first electronic device is deleted.

[0196] In a seventh aspect, an embodiment of the present application provides a communication method, applied to a first electronic device, comprising:

[0197] In response to the detected vehicle operation by the user, second information is sent, wherein the second information is used to determine the temporary key.

[0198] In one possible implementation, in response to the detected vehicle operation of the user, sending the second information includes:

[0199] In response to the detected user's vehicle use operation, a vehicle use request is sent to the vehicle, wherein the vehicle use request includes a first valid time period.

[0200] In one possible implementation, the first valid time period is encrypted via the vehicle smart key.

[0201] In one possible implementation, the vehicle use request also includes a vehicle smart key.

[0202] In one possible implementation, in response to the detected vehicle operation of the user, sending the second information includes:

[0203] In response to a detected vehicle operation by a user, generating a temporary credential based on the vehicle smart key and a first validity period;

[0204] The temporary credentials and the first valid time period are encrypted using the car smart key to obtain encrypted data, and the encrypted data is sent to the server.

[0205] In an eighth aspect, an embodiment of the present application provides a communication method, applied to a second electronic device, including:

[0206] Sending a key acquisition request to a server, wherein the key acquisition request is used to request acquisition of first information; wherein the first information is used to determine a temporary key;

[0207] receiving a first message sent by the server;

[0208] A control request is sent to the vehicle based on the first information, wherein the control request includes a temporary key and a control instruction, and the control instruction is used to control the vehicle.

[0209] In one possible implementation, the first information is an encrypted temporary key, and the encrypted temporary key is obtained by encrypting the temporary key with a fourth public key. After receiving the first information sent by the server, the method further includes:

[0210] The encrypted temporary key is decrypted using the fourth private key to obtain the temporary key.

[0211] In one possible implementation method, the first information is encrypted data, and the encrypted data is obtained by encrypting the temporary credentials and the first valid time period using the car smart key. The car smart key is stored in the first electronic device, the temporary credentials are generated by the first electronic device, and the first valid time period is used to represent the valid time period of the temporary key.

[0212] In one possible implementation, the method further includes:

[0213] Receive a key expiration notification; wherein the key expiration notification is used to indicate that the temporary key is invalid.

[0214] In one possible implementation, the key acquisition request further includes a temporary account number, and the key acquisition request is used to request to obtain the first information corresponding to the temporary account number.

[0215] In a ninth aspect, an embodiment of the present application provides a communication method, which is applied to a car rental platform, comprising:

[0216] Get the first valid time period;

[0217] Get the car smart key from the server;

[0218] The car smart key is used as a key, encrypted for the first valid time period and then sent to the vehicle.

[0219] The embodiment of the present application can effectively enable users to rent cars by setting a valid time period for the car smart key.

[0220] In one possible implementation, the method further includes:

[0221] Apply for a temporary account from the server. The temporary account corresponds to a temporary key.

[0222] The temporary account number is sent to the second electronic device.

[0223] In one possible implementation, the method further includes:

[0224] Send a key expiration notification; wherein the key expiration notification is used to indicate that the temporary key is invalid.

[0225] In an embodiment of the present application, by indicating that the temporary rental car key is invalid through notification, the rental can be returned in special scenarios such as early rental, thereby improving the efficiency of the rental return.

[0226] In a tenth aspect, an embodiment of the present application provides a communication device, comprising: one or more functional modules, wherein the one or more functional modules are used to execute the communication method as described in any one of the first to third aspects.

[0227] In the eleventh aspect, an embodiment of the present application further provides a communication device, comprising: one or more functional modules, wherein the one or more functional modules are used to execute the communication method as described in the fourth or fifth aspect.

[0228] In the twelfth aspect, an embodiment of the present application further provides a communication device, comprising: one or more functional modules, wherein the one or more functional modules are used to execute the communication method as described in the sixth or seventh aspect.

[0229] In the thirteenth aspect, an embodiment of the present application further provides a communication device, comprising: one or more functional modules, wherein the one or more functional modules are used to execute the communication method as described in the eighth aspect.

[0230] In the fourteenth aspect, an embodiment of the present application further provides a communication device, comprising: one or more functional modules, wherein the one or more functional modules are used to execute the communication method as described in the ninth aspect.

[0231] In the fifteenth aspect, an embodiment of the present application provides a vehicle, comprising: a processor and a memory, the memory being used to store a computer program; the processor being used to run the computer program and execute the communication method as described in any one of the first to third aspects.

[0232] In the sixteenth aspect, an embodiment of the present application provides a server, comprising: a processor and a memory, the memory being used to store a computer program; the processor being used to run the computer program and execute the communication method as described in the fourth or fifth aspect.

[0233] In the seventeenth aspect, an embodiment of the present application provides a first electronic device, comprising: a processor and a memory, the memory being used to store a computer program; the processor being used to run the computer program and execute the communication method as described in the sixth or seventh aspect.

[0234] In the eighteenth aspect, an embodiment of the present application provides a second electronic device, comprising: a processor and a memory, the memory being used to store a computer program; the processor being used to run the computer program and execute the communication method as described in the eighth aspect.

[0235] In the nineteenth aspect, an embodiment of the present application provides a car rental platform, comprising: a processor and a memory, the memory being used to store a computer program; the processor being used to run the computer program and execute the communication method as described in the ninth aspect.

[0236] In the twentieth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer-readable storage medium is run on a computer, the computer implements the communication method as described in any one of the first to ninth aspects.

[0237] In the twenty-first aspect, a communication system is provided, comprising: the vehicle provided in the fifteenth aspect, the server provided in the sixteenth aspect, and the first electronic device provided in the seventeenth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0238] Figure 1 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application;

[0239] Figure 2 A schematic diagram of the hardware structure of the server provided in the embodiment of the present application;

[0240] Figure 3 A schematic diagram of the hardware structure of a vehicle provided in an embodiment of the present application;

[0241] Figure 4 A schematic diagram of the architecture of the application scenario provided in the embodiment of the present application;

[0242] Figure 5 A flow chart of an embodiment of the communication method provided by this application;

[0243] Figure 6 A flow chart of another embodiment of the communication method provided by the present application;

[0244] Figure 7 A flowchart of another embodiment of the communication method provided by the present application;

[0245] Figure 8 A flowchart of another embodiment of the communication method provided by the present application;

[0246] Figure 9 A flowchart of another embodiment of the communication method provided by the present application;

[0247] Figure 10 A flowchart of another embodiment of the communication method provided by the present application;

[0248] Figure 11 A flowchart of another embodiment of the communication method provided by the present application;

[0249] Figure 12 A schematic structural diagram of an embodiment of a communication device provided by this application;

[0250] Figure 13 A schematic structural diagram of another embodiment of the communication device provided by this application;

[0251] Figure 14 A schematic structural diagram of another embodiment of the communication device provided by the present application;

[0252] Figure 15 A schematic structural diagram of another embodiment of the communication device provided by the present application;

[0253] Figure 16 A schematic structural diagram of another embodiment of the communication device provided by the present application;

[0254] Figure 17 A schematic structural diagram of another embodiment of the communication device provided by the present application;

[0255] Figure 18 A schematic structural diagram of another embodiment of the communication device provided by the present application;

[0256] Figure 19 A schematic structural diagram of another embodiment of the communication device provided by the present application;

[0257] Figure 20 This is a structural diagram of another embodiment of the communication device provided by this application. DETAILED DESCRIPTION

[0258] The following describes the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings. In the description of the embodiments of the present application, unless otherwise specified, " / " represents "or." For example, A / B can represent A or B. "And / or" in this document is merely a description of the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, or B exists alone.

[0259] In the following, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of this application, unless otherwise specified, "plurality" means two or more.

[0260] With the rapid development of mobile internet, mobile apps like Mobile Butler can integrate mobile phone control functions with car modules, achieving intelligent connection between mobile phones and cars, thereby providing users with comfortable and convenient driving. Smart car keys can not only replace traditional car keys, but also add functions such as mobile phone remote start, keyless entry, and automatic door opening and closing.

[0261] However, the cybersecurity level of automotive smart keys falls far short of the required standards, leading to significant cybersecurity issues. For example, automotive smart keys face significant security risks during their generation, distribution, use, and update processes. Currently, no automotive smart key in the industry achieves end-to-end security throughout its entire lifecycle, leaving them vulnerable to attacks at certain weak links, resulting in significant economic losses for users and OEMs. Cybersecurity issues with automotive smart keys are currently among the top three cyberattacks targeting smart cars. Therefore, to prevent these cybersecurity issues, end-to-end cybersecurity assurance is required for the entire automotive smart key system—from the cloud, mobile phone, and vehicle—and the cybersecurity levels of these three systems must be raised to the same high security level. Ensuring end-to-end cybersecurity has become a systemic issue that urgently needs to be addressed.

[0262] Based on the above problems, an embodiment of the present application proposes a communication method, which is applied to an electronic device 100, a server 200 and a vehicle 300. Among them, the electronic device 100 can be a mobile terminal with a display screen. The mobile terminal can also be called a terminal device, user equipment (UE), an access terminal, a user unit, a user station, a mobile station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent or a user device. The mobile terminal can also be a wearable device, such as a smart watch, a smart bracelet, etc. The embodiment of the present application does not impose any special restrictions on the specific form of the electronic device 100 that implements the technical solution. The server 200 can be a physical server or a virtual cloud server. The embodiment of the present application does not impose any special restrictions on the specific form of the server 200 that implements the technical solution. The vehicle 300 can be a smart vehicle with a smart key system.

[0263] The following combination Figure 1 First, an exemplary electronic device provided in the following embodiments of the present application is introduced. Figure 1 A schematic structural diagram of the electronic device 100 is shown.

[0264] The electronic device 100 may include a processor 110, an antenna 1, an antenna 2, a mobile communication module 120, a wireless communication module 130,

[0265] It should be understood that the structure illustrated in the embodiments of the present invention does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0266] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). The different processing units may be independent devices or integrated into one or more processors.

[0267] The controller can generate operation control signals according to the instruction operation code and timing signal to complete the control of instruction fetching and execution.

[0268] Processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in processor 110 is a cache memory. This memory can store instructions or data that have just been used or are being recycled by processor 110. If processor 110 needs to use the same instruction or data again, it can directly access the memory. This avoids duplicate accesses, reduces processor 110 latency, and thus improves system efficiency.

[0269] The wireless communication function of the electronic device 100 can be implemented through the antenna 1, the antenna 2, the mobile communication module 120, the wireless communication module 130, the modem processor and the baseband processor.

[0270] Antenna 1 and Antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In other embodiments, the antennas can be used in conjunction with a tuning switch.

[0271] The mobile communication module 120 can provide solutions for wireless communications including 2G / 3G / 4G / 5G applied to the electronic device 100. The mobile communication module 120 may include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 120 can receive electromagnetic waves from the antenna 1, and filter, amplify, and process the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 120 can also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves for radiation through the antenna 1. In some embodiments, at least some of the functional modules of the mobile communication module 120 can be set in the processor 110. In some embodiments, at least some of the functional modules of the mobile communication module 120 can be set in the same device as at least some of the modules of the processor 110.

[0272] The modem processor may include a modulator and a demodulator. The modulator is used to modulate the low-frequency baseband signal to be transmitted into a medium- or high-frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After being processed by the baseband processor, the low-frequency baseband signal is passed to the application processor. In some embodiments, the modem processor may be an independent device. In other embodiments, the modem processor may be independent of the processor 110 and be provided in the same device as the mobile communication module 120 or other functional modules.

[0273] The wireless communication module 130 can provide wireless communication solutions including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR), etc., applied to the electronic device 100. The wireless communication module 130 can be one or more devices integrating at least one communication processing module. The wireless communication module 130 receives electromagnetic waves via the antenna 2, frequency modulates and filters the electromagnetic wave signals, and sends the processed signals to the processor 110. The wireless communication module 130 can also receive the signal to be sent from the processor 110, frequency modulate it, amplify it, and convert it into electromagnetic waves for radiation through the antenna 2.

[0274] In some embodiments, the antenna 1 of the electronic device 100 is coupled to the mobile communication module 120, and the antenna 2 is coupled to the wireless communication module 130, so that the electronic device 100 can communicate with a network and other devices through wireless communication technologies. The wireless communication technologies may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), new radio (NR), BT, GNSS, WLAN, NFC, FM, and / or IR technology. The GNSS may include a global positioning system (GPS), a global navigation satellite system (GLONASS), a Beidou navigation satellite system (BDS), a quasi-zenith satellite system (QZSS) and / or a satellite based augmentation system (SBAS).

[0275] Next, combine Figure 2 The exemplary server provided in the following embodiments of this application is introduced. Figure 2 The schematic diagram of the structure of server 200 is shown. Server 200 may include: at least one processor; and at least one memory in communication with the processor. The memory stores program instructions executable by the processor, and the processor invokes the program instructions to perform the actions of the method provided in the embodiments of the present application.

[0276] like Figure 2 As shown, the server 200 may be in the form of a general-purpose computing device. Components of the server 200 may include, but are not limited to, one or more processors 210, a memory 220, a communication bus 240 connecting different system components (including the memory 220 and the processor 210), and a communication interface 230.

[0277] Communication bus 240 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, and a processor or local bus using any of a variety of bus architectures.

[0278] The memory 220 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) and / or cache memory.

[0279] A program / utility having a set (at least one) of program modules may be stored in memory 220. Such program modules include, but are not limited to, an operating system, one or more application programs, other program modules, and program data, each of which, or some combination thereof, may include an implementation of a network environment. The program modules generally implement the functions and / or methods of the embodiments described herein.

[0280] The server 200 may also communicate with one or more external devices (e.g., keyboards, pointing devices, displays, etc.), one or more devices that enable a user to interact with the server 200, and / or any device that enables the server 200 to communicate with one or more other computing devices (e.g., network cards, modems, etc.). Such communication may be performed via the communication interface 230. Furthermore, the server 200 may also communicate with the network adapter ( Figure 2 The network adapter can communicate with other modules of the electronic device through the communication bus 240. It should be understood that although Figure 2 Not shown, other hardware and / or software modules may be used in conjunction with the server 200, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, disk arrays (Redundant Arrays of Independent Drives, RAID) systems, tape drives, and data backup storage systems.

[0281] Next, combine Figure 3 An exemplary vehicle provided in the following embodiments of the present application is introduced. Figure 3The schematic diagram of the structure of a vehicle 300 is shown. Vehicle 300 may include: at least one processor 310; a mobile communication module 320; a wireless communication module 330; and at least one memory 340 communicatively connected to the processor. The memory stores program instructions executable by the processor, and the processor invokes these program instructions to perform the actions of the method provided in the embodiments of the present application.

[0282] The memory 340 stores program instructions that can be executed by the processor 310 , and the processor 310 calls the program instructions to execute the actions in the method provided in the embodiment of the present application.

[0283] The mobile communication module 320 can provide a solution for wireless communication including 2G / 3G / 4G / 5G etc. applied to the vehicle 300. The specific implementation of the mobile communication module 320 can refer to Figure 1 The mobile communication module 120 in the embodiment will not be described in detail here. The mobile communication module 320 can be used to enable communication between the electronic device 100 and the server 200. For example, the mobile communication module 320 can be used to communicate with a base station and access the Internet through the base station to enable communication with the server 200.

[0284] The wireless communication module 330 can provide wireless communication solutions including WLAN (such as WIFI), BT, GNSS, FM, NFC, IR, etc. applied to the electronic device 100. The specific implementation of the wireless communication module 330 can be referred to Figure 1 The wireless communication module 130 in the embodiment will not be described in detail here. Through the wireless communication module 330, communication between the electronic device 100 and the vehicle 300 can be achieved. For example, the electronic device 100 can communicate with the vehicle 300 via BT.

[0285] Figure 4 This is a schematic diagram of the application scenario architecture of the embodiment of the present application. Figure 4As shown, the above application scenario may include an electronic device 100, a server 200 and a vehicle 300. The electronic device 100 may be a terminal device such as a mobile phone or a tablet, and an application may be installed in the electronic device. For example, the application may be a car smart key APP, and the car smart key APP may be used to request the smart key server in the server 200 to generate, update, revoke and authorize the car smart key. Among them, the car smart key is an electronic key information for controlling the vehicle. The car smart key can be used as an electronic key to unlock the vehicle or perform other vehicle control operations, and can establish a wireless channel such as Bluetooth with the on-board short-range controller in the vehicle 300, thereby transmitting vehicle control instructions to the on-board short-range controller. It can be understood that the embodiment of the present application only exemplarily illustrates the Bluetooth wireless communication method, but does not constitute a limitation to the embodiment of the present application. In some embodiments, other wireless communication methods may also be used.

[0286] The server 200 can be a single computer or a computer cluster. The embodiment of the present application does not specifically limit the form of the server 200, and the server 200 may include a smart key server. Among them, the smart key server can be used to receive requests for car smart keys and the like sent by an application (e.g., a car smart key APP) in the electronic device 100, and complete operations such as generation, update, revocation and authorization of car smart keys for users. It is understandable that the smart key server can also be used to receive car smart keys sent by the on-board short-range controller in the smart car 300, and securely store the car smart keys through the key management service module (Key Management Service, KMS). Optionally, the server 200 may also include a public key infrastructure (PKI) server, which can be used to issue certificates to the smart key server and the on-board short-range controller. The certificate can be used to establish a secure transmission channel of the Transport Layer Security (TLS), thereby ensuring the secure transmission of the car smart key.

[0287] Vehicle 300 may include an onboard short-range controller, which is responsible for broadcasting radio frequency signals, such as Bluetooth, and authenticating the vehicle's smart key. Furthermore, the onboard short-range controller can communicate with the Passive Entry Passive Start (PEPS) system and the Body Control Module (BCM) to control vehicle doors and windows. Smart keys can be generated and stored by a secure element (SE), ensuring the security of the smart key.

[0288] In one possible implementation, the car smart key is generated only in the vehicle 300. For example, it can be generated by the OEM when the vehicle is assembled, and the car smart key can be generated in factory mode. After the car smart key is generated in the vehicle 300, the car smart key can be stored in, for example, a hardware security module (HSM) or an SE chip. The plain text of the car smart key does not leave the security module, so that the car smart key cannot be obtained from the outside, thereby ensuring the security of the car smart key. In the electronic device 100, a trusted execution environment (TEE) can be used to store the car smart key, and the car smart key does not leave the TEE. The server 300 uses KMS to store the car smart key. Through the secure storage of the car smart key by the above three parties (for example, the electronic device 100, the smart vehicle 200 and the server 300), it can be finally achieved that the car smart key cannot be obtained by attackers at any time in terms of use, transmission and storage, thereby ensuring the end-to-end security of the car smart key.

[0289] Optionally, the car smart key can not only use an encrypted channel to ensure the confidentiality of the server, vehicle and terminal, but also use a public key to encrypt the car smart key in the security module to ensure that the car smart key does not leave the security module in plain text and avoid leakage of the car smart key in the car and terminal, thereby further improving the security of the car smart key.

[0290] Now combined Figure 5 The communication method provided in the embodiment of the present application is described.

[0291] like Figure 5 FIG. 1 is a flow chart of an embodiment of a communication method provided by the present application, which is applied to a vehicle 300 and includes:

[0292] Step 501: The vehicle-mounted short-range controller generates a public-private key pair.

[0293] Specifically, the on-board short-range controller can generate a public-private key pair in the security module. Generating a public-private key pair in the security module can greatly improve vehicle safety. Among them, the public-private key pair generated in the on-board short-range controller can be generated using an asymmetric encryption algorithm. Exemplarily, the public-private key pair can include a public key and a private key. For ease of explanation, the public key generated in the on-board short-range controller is referred to as the "first public key" and the private key generated in the on-board short-range controller is referred to as the "first private key".

[0294] Preferably, in order to further improve security and prevent others from counterfeiting the public key, the vehicle identity information can also be sent together with the first public key to a third party organization, such as an authoritative certificate issuing authority. Among them, the vehicle identity information can be used to identify the identity of the vehicle. The vehicle identity information can be a vehicle identification number (VIN), which can also be called a frame number. In specific implementation, the vehicle identity information can also be replaced by a license plate number or other information used to characterize the identity of the vehicle. The specific form used to identify the vehicle identity information is not specifically limited in the embodiment of the present application. After the third party organization verifies the vehicle identity information, it can issue a digital certificate to the vehicle corresponding to the vehicle identity information. The digital certificate is obtained by the third party organization using the third party organization's private key to sign. The first certificate contains the vehicle identity information and the first public key, which is used to prove that the generator of the first public key is the vehicle corresponding to the vehicle identity information. After the on-board short-range controller obtains the digital certificate, it can send the digital certificate to the smart key server. For convenience of explanation, the digital certificate in the on-board short-range controller can be referred to as the first certificate.

[0295] To prevent the first certificate from being forged, the onboard short-range controller may also pre-store a root certificate. This root certificate may also be pre-issued by the third-party organization that issued the first certificate. The root certificate includes the third-party organization's public key and information about the third-party organization. Since the first certificate is signed by the third-party organization using its private key, the first certificate can be verified using the third-party organization's public key in the root certificate, thereby ensuring that the first certificate was issued by the third-party organization.

[0296] In step 502 , the vehicle-mounted short-range controller obtains the vehicle smart key and signs the vehicle smart key and vehicle identification information using a first private key.

[0297] In one possible implementation, the vehicle smart key may be generated by the OEM in factory mode.

[0298] The onboard short-range controller can use the first private key generated in step 501 to sign the vehicle smart key and the vehicle identification information, thereby obtaining signature data. The signature data may include the signed vehicle smart key and the signed vehicle identification information. The signed vehicle smart key is the signature information obtained by signing the vehicle smart key, and the signed vehicle identification information is the signature information obtained by signing the vehicle identification information. In one possible implementation, the signature data may be data obtained by signing a file containing the vehicle smart key and the vehicle identification information.

[0299] In one possible implementation, the specific process of signing the vehicle smart key and vehicle identification information using the first private key may be: using a hash algorithm to calculate a hash value for the vehicle smart key and vehicle identification information, wherein the hash algorithm can be pre-set, for example, any one of SHA-1, SHA-224, SHA-256, SHA-384, and SHA-512, or other types of hash algorithms, which are not specifically limited in this embodiment of the present application. Then, the hash value can be signed to obtain signature data.

[0300] In step 503 , the vehicle-mounted short-range controller uses the public key of the smart key server to encrypt the signature data, the vehicle smart key, and the vehicle identification information to obtain a first ciphertext.

[0301] Specifically, the smart key server can also generate a public-private key pair, wherein the public-private key pair generated in the smart key server can also be generated using an asymmetric encryption algorithm. It is understandable that the asymmetric encryption algorithm used by the on-board short-range controller to generate the public-private key pair can be the same as or different from the asymmetric encryption algorithm used by the smart key server to generate the public-private key pair. The embodiments of the present application do not specifically limit the asymmetric encryption algorithm used above. For ease of explanation, the public key generated in the smart key server will be referred to as the "second public key" and the private key generated in the smart key server will be referred to as the "second private key".

[0302] To prevent the second public key from being counterfeited, the smart key server can also apply for a digital certificate. For ease of explanation, this document refers to the digital certificate in the server as the second certificate. The second certificate can include the smart key server's identity information and the second public key. The specific method for obtaining the second certificate is similar to the method for obtaining the first certificate and will not be further described here. Once the second certificate is obtained, it can be sent to the vehicle's short-range controller, thereby verifying that the second public key was generated by the smart key server, thereby improving security.

[0303] In order to prevent the second certificate from being forged, the smart key server may also pre-store a root certificate. The method for obtaining the root certificate of the smart key server may refer to the method for obtaining the root certificate of the vehicle-mounted short-range controller, which will not be repeated here.

[0304] It should be noted that after generating the second public key, the smart key server can send the second public key to the vehicle-mounted short-range controller; similarly, after generating the first public key, the vehicle-mounted short-range controller can also send the first public key to the smart key server.

[0305] Next, the onboard short-range controller uses the second public key to encrypt the signature data, the vehicle smart key, and the vehicle identification information, thereby obtaining a first ciphertext. In one possible implementation, the first ciphertext may include the encrypted signature data, the encrypted vehicle smart key, and the encrypted vehicle identification information. In one possible implementation, the first ciphertext includes the encrypted signature data, the vehicle smart key, and the vehicle identification information.

[0306] In step 504, the vehicle-mounted short-range controller sends the key credential information to the smart key server. Correspondingly, the smart key server receives the key credential information.

[0307] Specifically, the onboard short-range controller can transmit key credential information to the smart key server, thereby completing the upload of the vehicle smart key to the server. The key credential information can be obtained by encrypting the vehicle smart key using the vehicle smart key as a key; the key credential information can also include a first ciphertext and a first public key. Because the vehicle smart key is signed and / or encrypted before uploading, the security of the vehicle smart key and the transmitted encrypted signature data are guaranteed to be tamper-proof.

[0308] Step 505: The smart key server decrypts the first ciphertext using the second private key.

[0309] Specifically, after the smart key server receives the first ciphertext, it can use the second private key to decrypt the first ciphertext, thereby obtaining the signature data, the car smart key and the vehicle identification information, wherein the signature data may include the signed car smart key and the signed vehicle identification information.

[0310] Step 506: The smart key server uses the first public key to verify the signature of the car smart key and the vehicle identification information.

[0311] Specifically, after the smart key server obtains the signature data, it can use the first public key to verify the signature data. In other words, signature verification can be used to verify whether the car smart key and vehicle identification information are generated by the owner of the first public key (or first private key). If the signature verification succeeds, step 507 can be further executed. If the signature verification fails, the car smart key and vehicle identification information can be discarded, and the current process can be terminated.

[0312] The specific method of using the first public key to verify the signature may be: using the first public key to perform a verification operation on the signature data to obtain a first hash value. Then, a hash operation is performed based on the vehicle smart key and vehicle identification information decrypted in step 505 to obtain a second hash value. The first hash value is compared with the second hash value. If the first hash value and the second hash value are consistent, the signature verification is considered to have passed; if the first hash value and the second hash value are inconsistent, the signature verification is considered to have failed.

[0313] Preferably, if the smart key server has received the first certificate sent by the on-board short-range controller before receiving the encrypted signature data, it can also verify the first public key based on the first certificate to ensure that the first public key is sent by the on-board short-range controller, thereby preventing others from counterfeiting the first public key, and confirming that the car smart key and vehicle identity information are sent by the on-board short-range controller, thereby improving security.

[0314] To prevent the first certificate from being forged or tampered with, the smart key server can use a pre-stored root certificate to verify the first certificate. Since the first certificate is signed by a third-party organization using a private key, the first certificate can be verified by the root certificate, thereby ensuring that the first certificate has not been tampered with.

[0315] Step 507: The smart key server stores the car smart key and vehicle identification information.

[0316] Specifically, the smart key server can use KMS to securely store the car smart key and the vehicle identification information corresponding to the car smart key. In other words, the car smart key and the vehicle identification information can be bound and stored, thereby completing the upload of the car smart key to the server by the on-board short-range controller. Since the second private key is only owned by the smart key server, the encrypted signature data obtained after encryption with the second public key can only be decrypted by the smart key server, thereby ensuring the security of the encrypted car smart key. In addition, since the first private key is only owned by the on-board short-range controller, the car smart key is verified by the first public key, thereby ensuring the correctness of the signature of the car smart key.

[0317] It should be understood that the above embodiments illustrate only the scenario of uploading a car smart key via an onboard short-range controller and do not constitute a limitation of the present invention. These embodiments are also applicable to scenarios involving updating car smart keys. For example, vehicle 300 can proactively update key credential information via the onboard short-range controller, upload the updated key credential information to the smart key server, and notify the user after the key credential information has been updated. For example, vehicle 300 can send a key update notification to the user's electronic device, prompting the user to update the car smart key. In one possible implementation, vehicle 300 can also passively update key credential information via the onboard short-range controller and upload the updated key credential information to the smart key server. For example, a user can send a key update request to vehicle 300 via an electronic device. This key update request can be used to request the generation of a new car smart key. Vehicle 300 can generate a new car smart key based on the key update request and determine new key credential information based on the new car smart key; alternatively, the smart key server can request the vehicle 300 to update the key credential information. This ensures that if the smart key is lost or leaked, the owner or other user can promptly trigger a vehicle-side update of the car smart key. Correspondingly, the smart key server can periodically receive key credential information for periodically updating the key credential information. In addition, the smart key server can also send a key update prompt to the user's electronic device for prompting the user to update the automobile smart key.

[0318] In the embodiment of the present application, the car smart key is only generated on the vehicle side and stored in the security module. All transmissions outside the security module are encrypted, and the car smart key cannot be obtained from the outside, thereby ensuring the safety of the vehicle.

[0319] The above Figure 5 The generation and uploading of car smart keys are explained as an example. Figure 6 The key distribution scenario provided in the embodiment of the present application is described.

[0320] like Figure 6 FIG. 1 is a flow chart of another embodiment of the communication method provided by the present application, including:

[0321] Step 601: The user logs in to the smart key server.

[0322] Specifically, the user can use a pre-registered account to log in to the smart key server. The pre-registered account can be bound to the vehicle identification information. Exemplarily, the user can use an application (for example, a car smart key APP) to pre-register an account in the smart key server, and the account can be bound to the vehicle identification information entered by the user. When the user registers successfully, the smart key server assigns the registered account to the user in the system, and the registered account is bound to the vehicle identification information. It is understandable that the smart key server has pre-stored the car smart key and the vehicle identification information corresponding to the car smart key in the system. Through the account registered by the user, the smart key server can assign the user a car smart key corresponding to the account.

[0323] Step 602: The application generates a public-private key pair and sends the public key to the smart key server.

[0324] Specifically, the application can generate a public-private key pair in the TEE, which can improve vehicle security. For ease of explanation, the public key generated by the application is referred to as the "third public key" and the private key generated by the application is referred to as the "third private key."

[0325] Then, the application may send the third public key to the smart key server.

[0326] In step 603 , the smart key server obtains the car smart key and encrypts the car smart key using the third public key to obtain an encrypted car smart key.

[0327] Specifically, after the user logs in to the smart key server using an account, the smart key server can obtain the vehicle identity identification information corresponding to the account according to the account logged in by the user, and obtain the car smart key corresponding to the vehicle identity identification information from the vehicle identity identification information.

[0328] Next, the smart key server may use the third public key sent by the application to encrypt the car smart key, thereby obtaining an encrypted car smart key, wherein the encrypted car smart key is an encrypted key obtained after encrypting the car smart key.

[0329] Step 604: The smart key server sends the encrypted car smart key to the application.

[0330] In step 605 , the application program decrypts the encrypted car smart key and stores the decrypted car smart key.

[0331] Specifically, after the application receives the encrypted car smart key sent by the smart key server, it can use the third private key in the TEE to decrypt the encrypted car smart key, thereby obtaining the car smart key.

[0332] The application can then store the decrypted smart key in the TEE, which improves security. Because only the application possesses the third private key, only the application can decrypt the encrypted smart key, which is encrypted with the third public key. This ensures the security of the smart key during distribution.

[0333] In some optional embodiments, a user can also proactively request a car smart key. For example, the user can operate on the application to send a key request to the smart key server. The key request includes the user account and is used to obtain the car smart key corresponding to the user account. After receiving the key request, the smart key server can send the encrypted car smart key to the application.

[0334] In an embodiment of the present application, the car smart key is securely stored in the security module of the terminal, and all transmissions outside the security module are encrypted, so the car smart key cannot be obtained from the outside, thereby ensuring the safety of the vehicle.

[0335] The above Figure 6 The key distribution scenario is illustrated in the following example. Figure 7 and Figure 8 The key usage and key update scenarios are explained respectively.

[0336] like Figure 7 FIG. 1 is a flow chart of another embodiment of the communication method provided by the present application, which specifically includes the following steps:

[0337] Step 701: The vehicle-mounted short-range controller sends a random value to the application.

[0338] Specifically, the vehicle-mounted short-range controller may send a random value to the application in advance. The random value may be a random number or a string of random numbers. The embodiment of the present application does not specifically limit the form of the random value.

[0339] Step 702: The application generates a first control message based on the vehicle smart key and the random value, and sends the first control message to the vehicle short-range controller.

[0340] Specifically, the first control message can be generated based on the car smart key and a random value. For example, the application can use a symmetric encryption algorithm such as PBKDF2 or AES in the TEE to generate the first control message based on the random value, the car smart key and the control instruction. The control instruction can be used to control the smart vehicle. It is understandable that the above-mentioned algorithms such as PBKDF2 or AES are only preferred methods that can ensure security, but do not constitute a limitation of the embodiments of the present application. In some embodiments, other asymmetric encryption algorithms can also be used.

[0341] Exemplarily, when the application uses the PBKDF2 algorithm in the TEE, the first control message can be generated based on the random value and the car smart key.

[0342] When the application uses the AES algorithm, a first control message can be generated based on a random value, a car smart key and a control instruction, wherein the control instruction can be an operation instruction input by the user, such as opening a door or opening a window.

[0343] The difference between using the AES algorithm and using the PBKDF2 algorithm is that the first control message generated using the PBKDF2 algorithm may not carry a control instruction, while the first control message generated using the AES algorithm may carry a control instruction.

[0344] Step 703: The onboard short-range controller controls the vehicle based on the first control message.

[0345] Specifically, after the on-board short-range controller receives the first control message sent by the application, it can verify the first control message. The verification method can be: the on-board short-range controller can generate a control message (for example, it can be called a second control message) based on the random value in step 701 and the smart car key. It can be understood that the second control message uses the same symmetric encryption algorithm as the first control message. For example, if the first control message uses the PBKDF2 algorithm, the second control message also uses the PBKDF2 algorithm. At this time, neither the first control message nor the second control message contains a control instruction. If the first control message uses the AES algorithm, the second control message also uses the AES algorithm. At this time, the first control message and the second control message can both contain control instructions.

[0346] Next, the second control message can be compared with the first control message. If the second control message is completely consistent with the first control message, verification is successful, that is, the user has successfully unlocked vehicle 300. At this time, if the first control message also contains control instructions, the on-board short-range controller can use the communication key comKey to encrypt the control instructions in the first control message and send them to on-board components such as the BCM for controlling vehicle 300. The communication key comKey can be a key used for communication within vehicle 300 and can be used during the communication process after the user unlocks vehicle 300.

[0347] In some optional embodiments, the user can also update the vehicle smart key while controlling vehicle 300. For example, the user can send a key update request to vehicle 300 via an application; the key update request is used to generate a new vehicle smart key, which can then be obtained from the smart key server. Once the user authenticates the vehicle 300 with the new vehicle smart key, the old vehicle smart key can be deleted, thereby conserving storage resources in vehicle 300.

[0348] In the embodiment of the present application, during the use of the car smart key, it cannot be obtained from the outside, thereby ensuring the safety of the vehicle.

[0349] like Figure 8 FIG. 1 is a flow chart of another embodiment of the communication method provided by the present application, which specifically includes the following steps:

[0350] Step 801: The user logs in to the smart key server.

[0351] Specifically, the user can use a pre-registered account to log in to the smart key server through the application in the electronic device 100. The specific login process can be referred to step 601 and will not be described in detail here.

[0352] Step 802: The smart key server obtains the old car smart key and sends the old car smart key to the application.

[0353] Specifically, the smart key server can find the corresponding old car smart key according to the account logged in by the user. The specific search process can be referred to step 603 and will not be repeated here.

[0354] The smart key server can then securely transmit the old car smart key to the application. For example, the old car smart key can be encrypted using the third public key sent by the application to obtain an encrypted car smart key. The encrypted car smart key can then be sent to the application, ensuring secure transmission of the car smart key.

[0355] In step 803 , the application sends a key update request to the vehicle-mounted short-range controller, so as to trigger the vehicle-mounted short-range controller to update the vehicle smart key.

[0356] Specifically, the user can proactively request to update the car smart key. For example, if the user loses or leaks the car smart key, the car smart key can be updated. In this case, the user can use an application to send a key update request to the onboard short-range controller to trigger the onboard short-range controller to update the car smart key. The key update request may include the old car smart key, that is, the car smart key before the update. After receiving the key update request, the onboard short-range controller can authenticate the old car smart key. The specific authentication process can be referred to step 703 and will not be repeated here.

[0357] When the authentication is passed, the update of the car smart key can be triggered, thereby obtaining a new car smart key. In specific implementation, the security module in the vehicle 300 can be triggered to generate a new car smart key.

[0358] In step 804 , the vehicle-mounted short-range controller uploads the new key credential information to the smart key server.

[0359] Specifically, after the onboard short-range controller obtains the new car smart key, it can determine the new key credential information based on the new car smart key and upload the new key credential information to the smart key server in a secure manner. Correspondingly, the smart key server can receive the new key credential information.

[0360] The vehicle-mounted short-range controller may send a credential update instruction to the smart key server, the credential update instruction being used to instruct the key credential information to be updated, and the credential update instruction including the new key credential information. The smart key server may update the key credential information based on the credential update instruction.

[0361] In some optional embodiments, before the key credential information is updated based on the credential update indication, the old car smart key can also be authenticated. If the authentication of the old car smart key fails, the key credential information will not be updated, thereby ensuring the security of the key credential information and thus the safety of the vehicle; if the authentication of the old car smart key is successful, the key credential information can be updated, and the old key credential information can be deleted after the successful update.

[0362] In some optional embodiments, after receiving the new car smart key, the smart key server may further send a key update prompt to the user's electronic device, where the key update prompt is used to prompt the user to update the car smart key.

[0363] Step 805 : The user downloads a new car smart key from the smart key server.

[0364] Specifically, the user can use the application to log in to the car smart key server again to obtain a new car smart key. It is understandable that in the process of obtaining the new car smart key, the new car smart key can also be transmitted to the application in a safe manner.

[0365] Furthermore, when the application obtains the new car smart key, it can use the new car smart key for authentication. When the authentication is passed, the application, the smart key server and the vehicle-mounted short-range controller delete the old car smart key, thereby completing the update of the car smart key.

[0366] The embodiment of the present application can update the car smart key in the event that the car smart key is lost or leaked, thereby ensuring the safety of the vehicle.

[0367] The above Figure 5-Figure 8 The following describes the example of uploading, distributing, using and updating the key. Figure 9 and Figure 10 The following describes the car rental scenario. Figure 9 The embodiment shown is an application scenario of a vehicle 300 in a networked environment. Figure 10 The illustrated embodiment is an application scenario in which the vehicle 300 is unable to connect to the Internet.

[0368] like Figure 9 FIG. 1 is a flow chart of another embodiment of the communication method provided by the present application, which specifically includes the following steps:

[0369] Step 901: In response to a first user's vehicle use operation, a first application sends a vehicle use request to an onboard short-range controller.

[0370] Specifically, the first user may be the vehicle owner or vehicle operator, and the first application may be an application installed on the electronic device 100 used by the first user. When a second user needs to borrow the vehicle from the first user, the first user can operate on the first application on their electronic device 100 to request the generation of a temporary key. The second user may be the actual user borrowing the vehicle. The temporary key may be a temporary smart car key with a validity period. For example, the temporary smart car key is valid for a certain period of time and becomes invalid after the period of time has expired.

[0371] In response to a first user's vehicle usage operation on a first application, the first application sends a vehicle usage request to the vehicle's short-range controller. The vehicle usage request may include the vehicle's smart key and a validity period. For ease of explanation, the validity period in the vehicle usage request is referred to as the "first validity period," which represents the validity period of the temporary key.

[0372] Preferably, when the first application sends a vehicle use request to the onboard short-range controller, the first valid time period may also be encrypted, wherein the encryption key may be the vehicle smart key. In other words, the first application may encrypt the first valid time period using the vehicle smart key as the key, thereby obtaining the encrypted first valid time period. In this case, the vehicle use request may include the vehicle smart key and the encrypted first valid time period.

[0373] In some optional embodiments, the smart car key in the car use request may be a signed smart car key, thereby ensuring the security of the car use. The signed smart car key may be obtained by signing the smart car key with a third private key.

[0374] In some optional embodiments, the above-mentioned car request can be sent by the electronic device used by the first user via short-range communication. In some optional embodiments, the above-mentioned car request can also be sent by the electronic device used by the first user via a mobile network.

[0375] In some optional embodiments, the above-mentioned car use request can also be sent by the electronic device or car rental platform used by the second user.

[0376] Step 902: The vehicle-mounted short-range controller generates a temporary key.

[0377] Specifically, the first application can be authenticated by the vehicle smart key and the vehicle-mounted short-range controller. Specific authentication methods can refer to the above embodiment and will not be repeated here.

[0378] It can be understood that if the car use request contains a signed car smart key, the signed car smart key can also be verified before authentication with the on-board short-range controller through the car smart key. The verification method can be: verifying the car smart key based on the third public key, and the third public key is sent to the vehicle by the electronic device used by the first user.

[0379] After authentication is successful, the onboard short-range controller can generate a temporary key based on the vehicle use request. In a specific implementation, if the vehicle use request includes a first validity period, the onboard short-range controller can use the first validity period in the vehicle use request as a factor to generate the temporary key, and can securely store the first validity period, for example, in a security module of the vehicle 300.

[0380] Optionally, if the request to use the vehicle includes an encrypted first valid time period, the method for generating the temporary key can be: the on-board short-range controller can use the car's smart key in the security module to decrypt the encrypted first valid time period, thereby obtaining the first valid time period. Then, the on-board short-range controller can use the first valid time period as a factor to generate a temporary key, and can securely store the first valid time period. The specific method for securely storing the first valid time period can be to store it in the vehicle's security module. The security module has comprehensive information security protection measures that can effectively ensure vehicle safety.

[0381] Step 903: The vehicle-mounted short-range controller uploads the temporary key to the smart key server.

[0382] Specifically, the vehicle-mounted short-range controller can upload the temporary key to the smart key server in a secure manner. The specific secure manner can refer to the manner in which the car smart key is uploaded to the smart key server, which will not be repeated here.

[0383] Step 904: The first user logs in to the smart key server and applies for a temporary car borrowing account.

[0384] Specifically, the first user may log in to the smart key server through the first application program. The first user may log in to the smart key server using a pre-registered user account, which may be a permanent account, that is, the user account has no validity period.

[0385] After the first user successfully logs in to the smart key server using their user account, they can use the first application to send a temporary car borrowing account registration request to the smart key server to generate a temporary car borrowing account. The temporary car borrowing account registration request may include a validity period. For ease of explanation, the validity period in the temporary car borrowing account registration request will be referred to as the "second validity period," which represents the validity period of the temporary car borrowing account. It is understood that the second validity period may be the same as or different from the first validity period. Preferably, the second validity period is less than or equal to the first validity period.

[0386] Step 905: The smart key server generates a temporary car borrowing account and sends the temporary car borrowing account to the first application.

[0387] Specifically, after receiving the temporary car borrowing account registration request sent by the first application, the smart key server may generate a temporary car borrowing account. It is understood that the temporary car borrowing account has a validity period, which may be determined by the second validity period in the temporary car borrowing account registration request.

[0388] The smart key server can then bind the temporary car borrowing account to the temporary key, allowing the second user (e.g., the borrower) to log in to the smart key server within the second valid time period to obtain the temporary key, and thus use the temporary key within the second valid time period. It is understood that after the second valid time period, the temporary car borrowing account becomes invalid. At this time, the smart key server can delete the temporary car borrowing account. In other words, the second user cannot log in to the smart key server using the temporary car borrowing account to obtain the temporary key, thereby improving the convenience and safety of borrowing a car.

[0389] In step 906 , the second user logs in to the smart key server, obtains a temporary key, and opens the vehicle 300 using the temporary key.

[0390] Specifically, the first user can give the temporary car borrowing account to the second user. The second user can then use the temporary car borrowing account to log in to the smart key server through a second application and initiate a temporary key request to the smart key server to obtain a temporary key corresponding to the temporary car borrowing account. The second application can be an application installed on the electronic device 100 used by the second user.

[0391] After the second user obtains the temporary key, he can use the temporary key to authenticate with the vehicle-mounted short-range controller to initiate a control request to the vehicle 300. The specific process of this authentication can refer to the authentication process of the smart car key in the above embodiment, and will not be repeated here.

[0392] After the vehicle-mounted short-range controller authenticates the temporary key, it can further verify the time validity, that is, it can verify whether the current borrower is within the valid borrowing time period. In specific implementation, the vehicle-mounted short-range controller can obtain the current system time and determine whether the current system time is within the first valid time period.

[0393] If the current system moment is within the first valid time period, the second user can use the current vehicle normally, thereby successfully unlocking the current vehicle, and the second user can further issue instructions for controlling the current vehicle.

[0394] If the current system time is not within the first valid time period, the second user has no right to use the current vehicle, so the current vehicle can continue to be locked, thereby ensuring the safety of the vehicle.

[0395] like Figure 10 FIG. 1 is a flow chart of another embodiment of the communication method provided by the present application, including:

[0396] Step 1001: In response to a first user's vehicle operation, a first application generates a temporary credential.

[0397] Specifically, the first user can perform a car-use operation on the first application, and in response to the first user's car-use operation, the first application can generate a temporary credential, wherein the temporary credential can include the car smart key and a first validity period.

[0398] It is understood that the above method of generating temporary credentials can use any function, for example, temporary credentials = func(car smart key, first valid time period), where func() is a function. Temporary credentials can also be generated by other methods, and the embodiments of this application do not specifically limit the method of generating temporary credentials.

[0399] In step 1002 , the first application encrypts the temporary credentials and the first valid time period to obtain encrypted data.

[0400] Specifically, the first application can use a key to encrypt the temporary credentials and the first valid time period, thereby obtaining encrypted data. Preferably, since the first user has a car smart key, that is, the first user's electronic device 100 has a car smart key, the key can be a car smart key, and the first application can use the car smart key as a key to encrypt the temporary credentials and the first valid time period without the need for key negotiation with the on-board short-range controller, thereby improving communication efficiency. However, this does not constitute a limitation on the embodiments of the present application. In some embodiments, the key can be other keys, and the first application can also use other keys to encrypt the temporary credentials and the first valid time period. Among them, the other keys can be obtained through key negotiation between the first application and the on-board short-range controller.

[0401] It should be noted that when encrypting the temporary credentials and the first valid time period, the temporary credentials and the first valid time period can be encrypted separately, thereby obtaining two encrypted data, for example, the encrypted temporary credentials and the encrypted first valid time period; or the packaged data of the temporary credentials and the first valid time period can be encrypted, thereby obtaining one encrypted data. The embodiments of the present application do not specifically limit the above encryption method.

[0402] Step 1003: The first application uploads the encrypted data to the smart key server.

[0403] Step 1004: The first user logs in to the smart key server and applies for a temporary car borrowing account.

[0404] Specifically, the first user may log in to the smart key server through the first application.

[0405] After the first user successfully logs in to the smart key server using the user account, the first application can send a temporary car borrowing account registration request to the smart key server to generate a temporary car borrowing account. The temporary car borrowing account can be bound to the encrypted data.

[0406] Step 1005: The smart key server generates a temporary car borrowing account and sends the temporary car borrowing account to the first application.

[0407] Specifically, after receiving the temporary car borrowing account registration request sent by the first application, the smart key server may generate a temporary car borrowing account and bind the temporary car borrowing account to the encrypted data sent by the first application.

[0408] Then, the smart key server may send the temporary car borrowing account to the first application.

[0409] Step 1006: The second application obtains the encrypted data.

[0410] Specifically, the second application may obtain the encrypted data in the following two ways.

[0411] Method 1

[0412] The first user can give the temporary car borrowing account to the second user. At this time, the second user can use the temporary car borrowing account to log in to the smart key server through the second application to obtain the encrypted data corresponding to the temporary car borrowing account.

[0413] Method 2

[0414] The first user can directly send the encrypted data to the second application. It is understandable that in the second method, steps 1003 to 1005 are optional steps.

[0415] In step 1007 , the second application sends the encrypted data to the vehicle-mounted short-range controller to request a temporary key.

[0416] Specifically, the second user may perform a temporary key request operation on the second application. In response to the detected temporary key request operation of the second user, the second application may send encrypted data to the in-vehicle short-range controller.

[0417] Step 1008 : The vehicle-mounted short-range controller authenticates the encrypted data, generates a temporary key, and sends the temporary key to the second application.

[0418] Specifically, after receiving the encrypted data sent by the second application, the onboard short-range controller can authenticate the encrypted data. The authentication process can include: the onboard short-range controller can decrypt the encrypted data using the vehicle's smart key or a key previously agreed upon by both parties, thereby obtaining the decrypted data, namely the temporary credentials and the first validity period. The onboard short-range controller can then verify the validity of the temporary credentials and the first validity period.

[0419] The method for verifying the validity of the temporary credential may be: on the vehicle short-range controller, using the same method (e.g., the same func function) as in step 1001, to calculate the temporary credential based on the vehicle smart key and the first valid time period. Then, the temporary credential calculated on the vehicle short-range controller is compared with the temporary credential calculated in the first application. If the two are consistent, the temporary credential can be determined to be valid; if the two are inconsistent, the temporary credential can be determined to be invalid.

[0420] The validity of the first valid time period can be verified by obtaining the current system time and comparing the current system time with the first valid time period. If the current system time is within the first valid time period, the first valid time period is valid; if the current system time is not within the first valid time period, the first valid time period is invalid.

[0421] When the on-board short-range controller passes verification and determines that the temporary credentials and the first valid time period are both valid, a temporary key can be generated, and the temporary key can be encrypted using the temporary credentials as a key, thereby obtaining an encrypted temporary key.

[0422] The vehicle-mounted short-range controller can then send the encrypted temporary key to the second application and securely store the first valid time period. The secure storage method for the first valid time period is as described above, which can improve vehicle security and prevent external access or tampering with the valid time period.

[0423] In some optional embodiments, after the temporary key is generated, a time validity check may be further performed for the first validity period. If it is detected that the current system time has exceeded the first validity period, that is, if the time validity check fails, the temporary key may be set to invalid and the user may be notified that the temporary key has expired.

[0424] In step 1009 , the second application program decrypts the encrypted temporary key and uses the temporary key to control the vehicle.

[0425] Specifically, after the second application receives the encrypted temporary key sent by the vehicle-mounted short-range controller, it can decrypt the encrypted temporary key according to the temporary credentials, thereby obtaining the temporary key.

[0426] Then, the second user can use the temporary key to control the vehicle. Exemplarily, the second user can send a control request to the vehicle-mounted short-range controller through the second application, and the control request includes the temporary key.

[0427] In some optional embodiments, the second user can also encrypt the temporary key using the first key through the second application to obtain the encrypted temporary key, and can carry the encrypted temporary key in the control request. Accordingly, the vehicle 300 can decrypt the encrypted temporary key using the first private key to obtain the temporary key, thereby improving the security of the vehicle 300 and preventing the temporary key from being stolen during transmission.

[0428] In some optional embodiments, the second user's electronic device may also send a fourth public key to the vehicle 300, and the vehicle 300 may verify the fourth key based on a fourth certificate, wherein the fourth certificate may be sent in advance by the second user's electronic device to the vehicle 300, and the fourth key is used to encrypt information sent by the vehicle 300 to the second user's electronic device.

[0429] It is understood that once the second application successfully decrypts the encrypted temporary key or the second user successfully unlocks the vehicle using the temporary key, the encrypted data becomes invalid. At this point, the second application can store the temporary key in the TEE, thereby ensuring its security. If the current system time exceeds the first validity period, the temporary key in both the second application and the vehicle's short-range controller becomes invalid.

[0430] In some optional embodiments, when the temporary key fails, a key failure notification can also be sent to the second user's electronic device; wherein, the key failure notification is used to indicate that the temporary key has failed, thereby avoiding the user from performing erroneous operations when the temporary key fails, thereby improving the user's usage experience.

[0431] In the vehicle borrowing scenario, embodiments of the present application can support both connected and unconnected vehicle scenarios. In scenarios where the vehicle is unable to connect to the internet, the owner can issue a temporary credential to the borrower instead of the vehicle's smart key. The borrower can then exchange the temporary credential for a temporary key at the vehicle's door. This ensures that only the borrower can obtain the temporary key, preventing the smart key from being randomly distributed to others, thereby ensuring vehicle safety.

[0432] Next, the following further Figure 11 The car rental scenario is described below. It should be noted that in this car rental scenario, the smart key server and the rental / sharing car platform can be the same server or different servers. Figure 11 The illustrated embodiment is merely described by taking the smart key server and the rental / shared car platform as different servers as an example, but does not constitute a limitation on the embodiments of the present application.

[0433] like Figure 11 The figure shows a flow chart of an embodiment of the car rental method provided by the present application, including:

[0434] Step 1101: The second user sends a car rental request to the rental / sharing car platform.

[0435] Specifically, the second user may also be the car renter. When the second user needs to rent a car, they may enter the rental time period on the application of their electronic device 100 to send a rental request to the rental / car sharing platform. In one possible embodiment, the second user may enter the rental time period and rental car model on the second application of their electronic device 100. In one possible embodiment, the second user may enter information such as the rental time period, rental car model, and rental location on the application. In one possible embodiment, the rental request may also include vehicle identification information and the rental time period.

[0436] In step 1102 , the car rental / sharing platform requests the car smart key from the smart key server.

[0437] Specifically, after receiving a rental request from the second application, the rental / sharing car platform can obtain eligible vehicles based on the rental request and the vehicle identification information of the eligible vehicles. For example, the platform can select an available and suitable vehicle based on at least one of the user-entered rental time period, rental vehicle model, rental location, and vehicle identification information. After selecting a vehicle, the rental / sharing car platform can send a key request to the smart key server based on the vehicle identification information. This key request can be used to request the vehicle's smart key. In one possible implementation, the key request can include the vehicle identification information and is used to request the vehicle's smart key for a specific vehicle.

[0438] TLS communication can be established between the rental / shared car platform and the smart key server, providing mutual authentication using certificates. For example, the rental / shared car platform can send its own certificate to the smart key server, and the smart key server can also send its own certificate to the rental / shared car platform. Each can encrypt the transmission using the other's public key and decrypt the received encrypted information using its own private key. This is not detailed here. TLS communication between the rental / shared car platform and the smart key server improves overall system security and ensures vehicle safety.

[0439] Step 1103: The smart key server distributes the car smart key to the rental / sharing car platform.

[0440] Specifically, after receiving the key request from the rental / sharing car platform, the smart key server can query the vehicle identity information in the key request to obtain the car smart key corresponding to the vehicle identity information, and can distribute the car smart key to the rental / sharing car platform.

[0441] In step 1104 , the rental / sharing car platform uses the car smart key to authenticate with the onboard short-range controller and sends the rental time period to the onboard short-range controller.

[0442] Specifically, after the rental / sharing car platform receives the car smart key distributed by the smart key server, it can use the car smart key to authenticate with the onboard short-range controller. The authentication process is as described above.

[0443] In addition, the rental / sharing car platform can also send the rental time period to the vehicle's short-range controller. It is understood that the rental time period can be sent to the vehicle's short-range controller at the same time as the car's smart key, or it can be sent to the vehicle's short-range controller separately. This embodiment of the application does not specifically limit the time when the rental time period is sent.

[0444] Preferably, the rental / sharing car platform can also send the encrypted rental time period to the on-board short-range controller, thereby ensuring the security of the rental time period. In a specific implementation, the rental time period can be encrypted using the car smart key as the key.

[0445] After obtaining the encrypted rental time period, the vehicle can decrypt it and retrieve the rental time period. In one possible implementation, the vehicle (or its short-range controller) can use the vehicle's smart key as the key for decryption. Using the vehicle's smart key for encryption or decryption can improve efficiency and enhance security.

[0446] After obtaining the rental time period, the vehicle can store the rental time period securely, for example, the rental time period can be stored in a security module, which can improve vehicle security and prevent the rental time period from being tampered with or illegally obtained.

[0447] Step 1105 : The vehicle-mounted short-range controller generates first information and uploads the first information to the smart key server.

[0448] Specifically, after the on-board short-range controller authenticates the car smart key sent by the rental / shared car platform, it can generate the first information. The first information can be a temporary key, which is used to unlock the vehicle 300 and operate it. The first information can also be encrypted data, which can be obtained by encrypting the temporary credentials and the first valid time period using the car smart key, and the first valid time period can be the rental time period. The temporary key can be bound to the rental time period. In other words, the temporary key is valid within the rental time period, and is invalid beyond the rental time period. In specific implementation, the methods of generating a temporary key can include the following two methods:

[0449] Method 1

[0450] If the on-board short-range controller receives the rental time period sent by the rental / sharing car platform, it can directly generate a temporary key, which can be bound to the rental time period.

[0451] Method 2

[0452] If the vehicle's short-range controller receives the encrypted rental time slot from the rental / sharing platform, it can use the vehicle's smart key as a key to decrypt the encrypted rental time slot, thereby obtaining the rental time slot. The vehicle's short-range controller can then generate a temporary key. In one possible implementation, this temporary key can be bound to the rental time slot.

[0453] It should be noted that after the vehicle-mounted short-range controller generates the first information, it can also upload the first information to the smart key server and securely store the rental time period. The vehicle-mounted short-range controller can generate a temporary key in the security module, which can improve vehicle security.

[0454] In some optional embodiments, the first information (eg, encrypted data) may also be uploaded to the smart key server by the first user's electronic device.

[0455] Step 1106: The rental / sharing car platform applies for a car rental account from the smart key server.

[0456] In step 1107 , the smart key server allocates a car rental account to the rental / sharing car platform, binds the car rental account to the temporary key, and sends the car rental account to the rental / sharing car platform.

[0457] Step 1108: The rental / sharing car platform sends the rental account to the second user.

[0458] Step 1109: The second user logs in to the smart key server and obtains a temporary key.

[0459] Specifically, the second user can log in to the smart key server using the car rental account on the second application, and thereby obtain a temporary key corresponding to the car rental account in the smart key server.

[0460] In some optional embodiments, the smart key server may use the fourth public key to encrypt the temporary key and send the encrypted key to the electronic device of the second user, wherein the fourth public key may be sent to the smart key server by the electronic device of the second user.

[0461] In step 1110 , the rental / sharing car platform sends a key failure notification to the vehicle-mounted short-range controller.

[0462] Specifically, when a rental / sharing car platform wishes to terminate a vehicle lease, it can send a key expiration notification to the vehicle's short-range controller. This key expiration notification can be used to notify the user of the expiration of the temporary rental key. In other words, regardless of whether the temporary rental key is currently valid during the rental period, upon receiving the key expiration notification, the on-board short-range controller can set the temporary rental key to an invalid state, thereby terminating the current vehicle lease and preventing the renter from using the temporary rental key to unlock the vehicle. This provides rental / sharing car platforms with more flexible permission control capabilities, making it easier for them to control the vehicle's usage period.

[0463] In some optional embodiments, a key expiration notification may also be sent to the electronic device of the second user; wherein the key expiration notification is used to indicate that the temporary key is expiration.

[0464] In this embodiment of the present application, only the renter can use the temporary rental key during the rental period, and no one else can obtain the temporary rental key, thereby ensuring the safety of the car. In addition, the rental / sharing car platform can terminate the use of the temporary rental key at any time, thereby achieving the ability to terminate the rental at any time and improving the convenience of rental.

[0465] above Figure 5-Figure 11In the illustrated embodiment, the smart key server is used to store the vehicle smart key. Alternatively, instead of storing the vehicle smart key in the smart key server, only authentication credentials are stored, which can be used to exchange for the vehicle smart key. In this scenario, the vehicle smart key is stored only in the electronic device 100 and the vehicle 300, and transmission of the vehicle smart key occurs only between the electronic device 100 and the vehicle 300. This reduces the attack surface exposed by the vehicle smart key transmission and improves security.

[0466] by Figure 5 Taking the embodiment shown as an example, after the on-board short-range controller generates a car smart key, it does not upload the car smart key to the smart key server. Instead, it uses the car smart key to generate an authentication credential, and can upload the authentication credential to the smart key server. After the user obtains the authentication credential, he cannot use it directly as a car smart key, but needs to use the authentication credential to exchange for the car smart key from the on-board short-range controller. The function of the authentication credential and the method of exchanging the authentication credential for the car smart key can be specifically referred to in Figure 10 The functions of the temporary credentials and the method of exchanging the temporary credentials for the car smart key in the illustrated embodiment will not be described in detail here.

[0467] Furthermore, in the car borrowing scenario where the vehicle cannot be connected to the Internet in the embodiment of the present application, the on-board short-range controller can also send temporary credentials with a valid time period to the smart key server, and the second user can exchange the temporary credentials for a car smart key with a valid time period in the on-board short-range controller.

[0468] In addition, in the car rental scenario in the embodiment of the present application, the on-board short-range controller can also send authentication credentials to the smart key server. The rental / sharing car platform can exchange the authentication credentials for the car smart key. Then, the rental / sharing car platform can send the rental time period to the on-board short-range controller. The on-board short-range controller generates a temporary credential corresponding to the rental time period and sends the temporary credential to the smart key server. The second user can obtain the temporary credential from the smart key server and use the temporary credential to exchange for a temporary key corresponding to the rental time period at the on-board short-range controller.

[0469] Figure 12 This is a schematic structural diagram of an embodiment of the present communication device. Figure 12 As shown, the communication device 1200 is applied to a vehicle, which includes a car smart key, which is an electronic key information for controlling the vehicle, and may include: a determination module 1210 and a sending module 1220; wherein,

[0470] A determination module 1210 is configured to determine key credential information based on the vehicle smart key;

[0471] The sending module 1220 is used to send the key credential information to the server.

[0472] In one possible implementation, the determination module 1210 is specifically configured to:

[0473] The car smart key is used as a key to encrypt the car smart key and obtain key credential information.

[0474] In one possible implementation, the vehicle further includes vehicle identification information corresponding to the vehicle, and the above-mentioned determination module 1210 is specifically used to

[0475] Use the first private key to sign the car smart key and vehicle identification information to obtain signature data;

[0476] Obtaining a second public key, and using the second public key to encrypt the signature data, the vehicle smart key, and the vehicle identification information to obtain a first ciphertext; wherein the second public key is sent by the server to the vehicle;

[0477] Key credential information is generated based on the first ciphertext and the first public key, where the first public key corresponds to the first private key.

[0478] In one possible implementation, the sending module 1220 is further configured to:

[0479] The first certificate is sent to the server. The first certificate includes vehicle identification information and a first public key. The first certificate is signed by a third-party organization and issued to the vehicle. The first certificate is used to verify the first public key.

[0480] In one possible implementation, the communication device 1200 further includes:

[0481] A verification module is used to verify the second public key according to the second certificate.

[0482] In one possible implementation, the communication device 1200 further includes:

[0483] The receiving module is used to receive the second certificate sent by the server, where the second certificate includes the identity information and the second public key of the server, and is issued to the server after being signed by a third-party organization.

[0484] In one possible implementation, the vehicle pre-stores a root certificate, which is used to verify the certificate. The communication device 1200 further includes:

[0485] The signature verification module is used to verify the signature of the second certificate based on the root certificate.

[0486] In one possible implementation manner, the second certificate is pre-installed in the vehicle.

[0487] In one possible implementation, the first public key and the first private key are generated in a security module of the vehicle.

[0488] In one possible implementation, the car smart key is generated in the vehicle's factory mode.

[0489] In one possible implementation, the communication device 1200 further includes:

[0490] An update module, used to periodically update key credential information based on the vehicle smart key;

[0491] Send the updated key credential information to the server.

[0492] In one possible implementation, the sending module 1220 is further configured to send a key update reminder to the first electronic device, so as to prompt the user to update the car smart key.

[0493] In one possible implementation, the receiving module is further configured to

[0494] Receiving a key update request sent by a first electronic device, wherein the key update request is used to request generation of a new vehicle smart key;

[0495] Determining new key credential information based on the new vehicle smart key;

[0496] Send the new key credential information to the server.

[0497] In one possible implementation, the key update request includes an old vehicle smart key, and the communication device 1200 further includes:

[0498] Authentication module, used to authenticate old car smart keys.

[0499] In one possible implementation, the communication device 1200 further includes:

[0500] The deleting module is configured to delete the old car smart key in the vehicle if it is detected that the authentication of the first electronic device requesting to use the new car smart key is successful.

[0501] Figure 13 This is a structural diagram of another embodiment of the communication device of the present application, such as Figure 13 As shown, the above communication device 1300 is applied to a server and may include: a receiving module 1310 and a storage module 1320; wherein,

[0502] Receiving module 1310, for receiving key credential information;

[0503] The storage module 1320 is used to securely store the key credential information, where secure storage is performed through secure encryption.

[0504] In one possible implementation, the key credential information includes a first ciphertext and a first public key, and the storage module 1320 is specifically used to

[0505] Decrypt the first ciphertext using the second private key to obtain the signature data, the car smart key, and the vehicle identification information;

[0506] Use the first public key to verify the signature data;

[0507] If the signature verification is passed, the car smart key and vehicle identification information will be securely stored.

[0508] In one possible implementation, the communication device 1300 further includes:

[0509] an acquisition module, configured to acquire a third public key and encrypt the vehicle smart key using the third public key to obtain an encrypted vehicle smart key; wherein the third public key is sent to the server by the first electronic device;

[0510] The encrypted car smart key is sent to the first electronic device.

[0511] In one possible implementation, the receiving module 1310 is further configured to:

[0512] Receiving a registration request; wherein the registration request includes a user account and vehicle identification information corresponding to the user account;

[0513] A user account is created based on the registration request, and the user account corresponds to the car smart key and vehicle identification information.

[0514] In one possible implementation, the communication device 1300 further includes:

[0515] The sending module is used to send the second certificate to the vehicle. The second certificate includes the identity information of the server and the second public key. The second certificate is signed by a third party and issued to the server. The second certificate is used to verify the second public key.

[0516] In one possible implementation, the communication device 1300 further includes:

[0517] A verification module is used to verify the first public key according to the first certificate.

[0518] In one possible implementation, the receiving module 1310 is further configured to:

[0519] Receive a first certificate sent by the vehicle, where the first certificate includes vehicle identification information and a first public key. The first certificate is signed by a third-party organization and issued to the vehicle.

[0520] In one possible implementation, the server pre-stores a root certificate, which is used to verify the certificate. The communication device 1300 further includes:

[0521] The signature verification module is used to verify the signature of the first certificate based on the root certificate.

[0522] In one possible implementation manner, the first certificate is pre-installed in the server.

[0523] In one possible implementation, the first public key is generated in a security module of the vehicle.

[0524] In one possible implementation, the receiving module 1310 is further configured to:

[0525] The key credential information is periodically received and used for periodically updating the key credential information.

[0526] In one possible implementation, the sending module is further used to

[0527] A key update prompt is sent to the first electronic device to prompt the user to update the car smart key.

[0528] In one possible implementation, the receiving module 1310 is further configured to:

[0529] receiving a credential update instruction, wherein the credential update instruction is used to instruct to update the key credential information, and the credential update instruction includes new key credential information;

[0530] The key credential information is updated based on the credential update instruction.

[0531] In one possible implementation, the credential update indication further includes an old car smart key, the old car smart key is stored in the server, and the new key credential information includes the new car smart key. The communication device 1300 further includes:

[0532] Authentication module, used to authenticate old car smart keys.

[0533] In one possible implementation, the communication device 1300 further includes:

[0534] The deletion module is used to store the new key credential information and delete the old key credential information if it is detected that the authentication of the new key credential information is passed.

[0535] Figure 14This is a structural diagram of an embodiment of the communication device of the present application, as shown in FIG. Figure 14 As shown, the communication device 1400 is applied to a vehicle and may include: a sending module 1410, a receiving module 1420 and a verification module 1430; wherein,

[0536] The sending module 1410 is configured to send a random value to the first electronic device;

[0537] The receiving module 1420 is configured to receive a first control message sent by a first electronic device; wherein the first control message is generated based on the vehicle smart key and a random value;

[0538] The verification module 1430 is configured to verify the first control message based on the vehicle smart key and the random value, and if the verification passes, control the vehicle according to the first control message.

[0539] In one possible implementation, the verification module 1430 is specifically used to

[0540] Generate a second control message based on the vehicle smart key and the random value;

[0541] comparing the second control message with the first control message;

[0542] If the first control message is consistent with the second control message, the vehicle is controlled according to the first control message.

[0543] Figure 15 This is a structural diagram of another embodiment of the communication device of the present application, such as Figure 15 As shown, the communication device 1500 is applied to a first electronic device and may include: a receiving module 1510, a generating module 1520 and a sending module 1530; wherein,

[0544] Receiving module 1510, for receiving a random value sent by a vehicle;

[0545] A generating module 1520 is configured to obtain a vehicle smart key and generate a first control message based on the vehicle smart key and a random value, wherein the first control message is used to control the vehicle;

[0546] The sending module 1530 is configured to send the first control message to the vehicle.

[0547] In one possible implementation, the first control message is generated in a trusted execution environment TEE.

[0548] In one possible implementation, the generation module 1520 is specifically used to

[0549] Receiving an encrypted car smart key sent by the server; wherein the encrypted car smart key is obtained by the server encrypting the car smart key using a third public key, and the third public key is sent to the server by the first electronic device;

[0550] The encrypted car smart key is decrypted using the third private key to obtain the car smart key.

[0551] In one possible implementation, the third public key and the third private key are generated in a trusted execution environment TEE of the first electronic device.

[0552] In one possible implementation, the generation module 1520 is further configured to:

[0553] In the trusted execution environment (TEE) of the first electronic device, decrypt the encrypted car smart key using the third private key to obtain the car smart key;

[0554] The car smart key is stored in the trusted execution environment TEE of the first electronic device.

[0555] In one possible implementation, the sending module 1530 is further configured to:

[0556] A key request is sent to the server, where the key request includes a user account and is used to obtain the car smart key corresponding to the user account.

[0557] In one possible implementation, the sending module 1530 is further configured to:

[0558] Sending a key update request to the vehicle; wherein the key update request is used to generate a new car smart key;

[0559] Get a new car smart key from the server.

[0560] In one possible implementation, the communication device 1500 further includes:

[0561] Authentication module, used to authenticate the new car smart key with the vehicle;

[0562] If the authentication is successful, the old car smart key in the first electronic device is deleted.

[0563] Figure 16 This is a structural diagram of an embodiment of the communication device of the present application, as shown in FIG. Figure 16 As shown, the communication device 1600 is applied to a vehicle and may include: an acquisition module 1610, a verification module 1620 and a control module 1630; wherein,

[0564] The acquisition module 1610 is configured to acquire a control request sent by the second electronic device, wherein the control request includes a temporary key and a control instruction;

[0565] Verification module 1620, for verifying the temporary key; performing time validity verification according to a first valid time period; the first valid time period is used to represent the valid time period of the temporary key; the first valid time period is stored in the vehicle's security module;

[0566] The control module 1630 is configured to control the vehicle according to a control instruction of the second electronic device if the temporary key verification and the time validity verification are passed.

[0567] In one possible implementation, the acquisition module 1610 is further configured to:

[0568] Obtaining a vehicle request; wherein the vehicle request includes a first valid time period;

[0569] generating a temporary key according to the first valid time period;

[0570] Send the temporary key to the server.

[0571] In one possible implementation, the vehicle use request is sent by the first electronic device via short-range communication.

[0572] In one possible implementation, the vehicle request is sent by the first electronic device via a mobile network.

[0573] In one possible implementation, the vehicle use request further includes a signed vehicle smart key, which is obtained by signing the vehicle smart key with a third private key. The communication device 1600 further includes:

[0574] The signature verification module is used to verify the signature of the car smart key according to the third public key, and the third public key is sent to the vehicle by the first electronic device.

[0575] In one possible implementation, the communication device 1600 further includes:

[0576] The sending module is used to send a first certificate to a first electronic device. The first certificate includes vehicle identification information and a first public key. The first certificate is signed by a third-party organization and issued to the vehicle. The first certificate is used to verify the first public key.

[0577] In one possible implementation, the communication device 1600 further includes:

[0578] The verification module is configured to verify the third public key according to the third certificate.

[0579] In one possible implementation, the communication device 1600 further includes:

[0580] The receiving module is used to receive a third certificate sent by the first electronic device, where the third certificate includes the identity information of the first electronic device and a third public key. The third certificate is signed by a third-party organization and issued to the first electronic device.

[0581] In one possible implementation, the vehicle pre-stores the root certificate, which is used to verify the certificate. The above-mentioned signature verification module is also used to

[0582] Verify the signature of the third certificate based on the root certificate.

[0583] In one possible implementation, the first valid time period is encrypted by the vehicle smart key, and the communication device 1600 further includes:

[0584] The decryption module is used to decrypt the encrypted first valid time period using the automobile smart key and securely store the decrypted first valid time period.

[0585] In one possible implementation, the receiving module is further configured to

[0586] Receiving encrypted data sent by the second electronic device; wherein the encrypted data is obtained by encrypting the temporary credentials and the first valid time period using the car smart key, the car smart key is stored in the first electronic device, and the temporary credentials are generated by the first electronic device;

[0587] Use the car smart key to decrypt the encrypted data and obtain the temporary credentials and the first valid time period;

[0588] Verify the temporary credentials and the first validity period;

[0589] If the verification passes, a temporary key is generated;

[0590] The temporary key is encrypted according to the encryption data to obtain an encrypted temporary key, and the encrypted temporary key is sent to the second electronic device.

[0591] In one possible implementation, the communication device 1600 further includes:

[0592] The storage module is used to safely store the first valid time period.

[0593] In one possible implementation, temporary credentials are generated based on the car smart key and a first valid time period, and encrypted data is sent to the server by the first electronic device.

[0594] In one possible implementation, the manipulation request includes an encrypted temporary key, which is obtained by encrypting the encrypted temporary key with the first public key. The decryption module is further configured to decrypt the encrypted temporary key using the first private key to obtain the temporary key.

[0595] In one possible implementation, the sending module is also used to send a first certificate to a second electronic device. The first certificate includes vehicle identification information and a first public key. The first certificate is signed by a third-party organization and issued to the vehicle. The first certificate is used to verify the first public key.

[0596] In one possible implementation, the verification module is further configured to verify a fourth public key based on a fourth certificate, wherein the fourth public key is sent to the vehicle by the second electronic device.

[0597] In one possible implementation, the receiving module is further used to receive a fourth certificate sent by the second electronic device. The fourth certificate includes the identity information and the fourth public key of the second electronic device. The fourth certificate is signed by a third-party organization and issued to the second electronic device.

[0598] In one possible implementation, the vehicle pre-stores a root certificate, which is used to verify the certificate. The signature verification module is also used to verify the signature of the fourth certificate based on the root certificate.

[0599] In one possible implementation, the sending module is further used to

[0600] sending the random value to the second electronic device;

[0601] Receiving a first control message sent by a second electronic device; wherein the first control message is generated based on a temporary key and a random value;

[0602] A temporary key verification is performed on the first control message based on the temporary key and the random value.

[0603] In one possible implementation, the sending module is further used to

[0604] A key failure notification is sent to the second electronic device, wherein the key failure notification is used to indicate that the temporary key is failed.

[0605] In one possible implementation, the communication device 1600 further includes:

[0606] The setting module is used to set the temporary key to be invalid if it is detected that the current system time exceeds the first valid time period.

[0607] In one possible implementation, the communication device 1600 further includes:

[0608] The prompt module is used to prompt the user that the temporary key has expired if the time validity check fails.

[0609] Figure 17 This is a structural diagram of another embodiment of the communication device of the present application, such as Figure 17 As shown, the communication device 1700 is applied to a server and may include: a receiving module 1710 and a sending module 1720; wherein,

[0610] The receiving module 1710 is configured to receive a key acquisition request sent by a second electronic device, wherein the key acquisition request is used to request acquisition of first information; wherein the first information is used to determine a temporary key;

[0611] The sending module 1720 is configured to send the first information to the second electronic device.

[0612] In one possible implementation, the first information is a temporary key, and the sending module 1720 is specifically configured to encrypt the temporary key using the fourth public key and then send the encrypted key to the second electronic device, wherein the fourth public key is sent by the second electronic device to the server.

[0613] In one possible implementation, the temporary key is sent by the vehicle to the server.

[0614] In one possible implementation method, the first information is encrypted data, and the above-mentioned sending module 1720 is specifically used to send the encrypted data to the second electronic device, wherein the encrypted data is obtained by encrypting the temporary credentials and the first valid time period using the car smart key, the car smart key is stored in the first electronic device, the temporary credentials are generated by the first electronic device, and the first valid time period is used to represent the valid time period of the temporary key.

[0615] In one possible implementation, the encrypted data is sent by the first electronic device to the server.

[0616] In one possible implementation, the key acquisition request includes a temporary account number, and the key acquisition request is used to request to obtain first information corresponding to the temporary account number.

[0617] Figure 18 This is a structural diagram of an embodiment of the communication device of the present application, as shown in FIG. Figure 18 As shown, the communication device 1800 is applied to a first electronic device and may include: a sending module 1810; wherein,

[0618] The sending module 1810 is configured to send second information in response to a detected vehicle operation by a user, wherein the second information is used to determine a temporary key.

[0619] In one possible implementation, the sending module 1810 is specifically configured to send a vehicle use request to the vehicle in response to a detected vehicle use operation by the user, wherein the vehicle use request includes a first valid time period.

[0620] In one possible implementation, the first valid time period is encrypted via the vehicle smart key.

[0621] In one possible implementation, the vehicle use request also includes a vehicle smart key.

[0622] In one possible implementation, the sending module 1810 is further configured to generate a temporary credential based on the vehicle smart key and the first validity period in response to a detected vehicle operation by the user;

[0623] The temporary credentials and the first valid time period are encrypted using the car smart key to obtain encrypted data, and the encrypted data is sent to the server.

[0624] Figure 19 This is a structural diagram of another embodiment of the communication device of the present application, such as Figure 19 As shown, the communication device 1900 is applied to a second electronic device and may include: a sending module 1910, a receiving module 1920 and a control module 1930; wherein,

[0625] The sending module 1910 is configured to send a key acquisition request to the server, wherein the key acquisition request is used to request to obtain first information; wherein the first information is used to determine a temporary key;

[0626] Receiving module 1920, configured to receive first information sent by the server;

[0627] The control module 1930 is configured to send a control request to the vehicle based on the first information, wherein the control request includes a temporary key and a control instruction, and the control instruction is used to control the vehicle.

[0628] In one possible implementation, the first information is an encrypted temporary key, which is obtained by encrypting the temporary key with the fourth public key.

[0629] In one possible implementation, the communication device 1900 further includes:

[0630] The decryption module is used to decrypt the encrypted temporary key using the fourth private key to obtain the temporary key.

[0631] In one possible implementation method, the first information is encrypted data, and the encrypted data is obtained by encrypting the temporary credentials and the first valid time period using the car smart key. The car smart key is stored in the first electronic device, the temporary credentials are generated by the first electronic device, and the first valid time period is used to represent the valid time period of the temporary key.

[0632] In one possible implementation, the receiving module 1920 is further configured to receive a key expiration notification; wherein the key expiration notification is used to indicate that the temporary key is expiration.

[0633] In one possible implementation, the key acquisition request further includes a temporary account number, and the key acquisition request is used to request to obtain the first information corresponding to the temporary account number.

[0634] Figure 20 This is a structural diagram of an embodiment of the communication device of the present application, as shown in FIG. Figure 20 As shown, the communication device 2000 is applied to the car rental platform and may include: an acquisition module 2010 and a sending module 2020; wherein,

[0635] The acquisition module 2010 is configured to acquire a first valid time period and obtain a car smart key from a server;

[0636] The sending module 220 is used to use the car smart key as a key, encrypt the first valid time period, and then send it to the vehicle.

[0637] In one possible implementation, the communication device 2000 further includes:

[0638] The application module is used to apply for a temporary account from the server. The temporary account corresponds to a temporary key.

[0639] The temporary account number is sent to the second electronic device.

[0640] In one possible implementation, the sending module 2020 is further configured to send a key expiration notification; wherein the key expiration notification is configured to indicate that the temporary key is expiration.

[0641] Figure 12-Figure 20 The communication device provided in the embodiment shown can be used to implement the present application Figures 1-11 The technical solution of the method embodiment shown, its implementation principle and technical effects can be further referred to the relevant description in the method embodiment.

[0642] It should be understood that the above Figures 11-20The division of the various modules of the communication device shown is merely a division of logical functions. In actual implementation, they can be fully or partially integrated into one physical entity, or they can be physically separated. Moreover, these modules can all be implemented in the form of software called through processing elements; they can also all be implemented in the form of hardware; some modules can also be implemented in the form of software called through processing elements, and some modules can be implemented in the form of hardware. For example, the detection module can be a separately established processing element, or it can be integrated into a chip of an electronic device. The implementation of other modules is similar. In addition, these modules can all or partly be integrated together, or they can be implemented independently. During the implementation process, each step of the above method or each of the above modules can be completed by the hardware integrated logic circuit in the processor element or by instructions in the form of software.

[0643] For example, the above modules may be one or more integrated circuits configured to implement the above methods, such as one or more application-specific integrated circuits (ASICs), one or more microprocessors (DSPs), or one or more field programmable gate arrays (FPGAs). For another example, these modules may be integrated together to implement a system-on-a-chip (SOC).

[0644] Through the description of the above embodiments, those skilled in the art will clearly understand that for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0645] The functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0646] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as flash memory, mobile hard disk, read-only memory, random access memory, magnetic disk or optical disk.

[0647] The above is only a specific embodiment of the present application, but the scope of protection of this application is not limited to this. Any changes or substitutions within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A communication method, applied to a vehicle, characterized in that: The method comprises: Obtaining a control request sent by the second electronic device; wherein the control request includes the temporary key and a control instruction; Verifying the temporary key; Performing a time validity check according to a first valid time period; the first valid time period is used to represent the valid time period of the temporary key; the first valid time period is stored in the security module of the vehicle; If the temporary key verification passes and the time validity verification passes, the vehicle is controlled according to the control instruction of the second electronic device.

2. The method according to claim 1, characterized in that Before obtaining the manipulation request sent by the second electronic device, the method further includes: Obtaining a vehicle use request; wherein the vehicle use request includes the first valid time period; generating the temporary key according to the first valid time period; The temporary key is sent to the server.

3. The method according to claim 2, characterized in that The vehicle use request is sent by the first electronic device via short-range communication.

4. The method according to claim 2, characterized in that The vehicle use request is sent by the first electronic device via a mobile network.

5. The method according to claim 2, characterized in that The car rental request is sent by the car rental platform.

6. The method according to claim 2, characterized in that The vehicle use request also includes a signed vehicle smart key, which is obtained by signing the vehicle smart key with a third private key. After obtaining the vehicle use request, the method further includes: The vehicle smart key is signature-verified according to a third public key, and the third public key is sent by the first electronic device to the vehicle.

7. The method according to claim 6, characterized in that The method further comprises: A first certificate is sent to the first electronic device, the first certificate including the vehicle identification information and a first public key, the first certificate is signed by a third-party organization and issued to the vehicle, and the first certificate is used to verify the first public key.

8. The method according to claim 6, characterized in that The method further comprises: The third public key is verified according to the third certificate.

9. The method according to claim 8, characterized in that Before verifying the third public key according to the third certificate, the method further includes: A third certificate sent by the first electronic device is received, where the third certificate includes the identity information of the first electronic device and the third public key, and is signed by the third-party organization and issued to the first electronic device.

10. The method according to claim 9, characterized in that The vehicle pre-stores a root certificate, and the root certificate is used to verify the certificate. After receiving the third certificate sent by the first electronic device, the method further includes: The third certificate is signed based on the root certificate.

11. The method according to claim 6, characterized in that The first valid time period is encrypted by the automobile smart key, and after the authentication is performed based on the automobile smart key, the method further includes: The encrypted first valid time period is decrypted using the automobile smart key, and the decrypted first valid time period is securely stored.

12. The method according to claim 1, characterized in that The method further comprises: Receiving encrypted data sent by the second electronic device; wherein the encrypted data is obtained by encrypting the temporary credentials and the first validity period using a car smart key, the car smart key is stored in the first electronic device, and the temporary credentials are generated by the first electronic device; Decrypting the encrypted data using the car smart key to obtain the temporary credential and the first valid time period; Verifying the temporary credential and the first validity period; If the verification passes, the temporary key is generated; The temporary key is encrypted according to the encryption data to obtain an encrypted temporary key, and the encrypted temporary key is sent to the second electronic device.

13. The method according to claim 12, characterized in that After generating the temporary key, the method further includes: The first valid time period is securely stored.

14. The method according to claim 12, characterized in that The temporary credential is generated based on the car smart key and the first valid time period, and the encrypted data is sent to the server by the first electronic device.

15. The method according to claim 1, wherein The control request includes an encrypted temporary key, and the encrypted temporary key is obtained by encrypting the first public key. Before verifying the temporary key, the method further includes: The encrypted temporary key is decrypted using the first private key to obtain the temporary key.

16. The method according to claim 15, characterized in that The method further comprises: A first certificate is sent to the second electronic device, wherein the first certificate includes the vehicle identification information and the first public key. The first certificate is signed by a third-party organization and issued to the vehicle. The first certificate is used to verify the first public key.

17. The method according to claim 15, characterized in that The method further comprises: A fourth public key is verified according to a fourth certificate, wherein the fourth public key is sent to the vehicle by the second electronic device.

18. The method according to claim 17, characterized in that Before verifying the fourth public key according to the fourth certificate, the method further includes: A fourth certificate sent by the second electronic device is received, where the fourth certificate includes the identity information of the second electronic device and the fourth public key, and is signed by the third-party organization and issued to the second electronic device.

19. The method according to claim 18, characterized in that The vehicle pre-stores a root certificate, the root certificate being used to verify the certificate. After receiving the fourth certificate sent by the second electronic device, the method further includes: The fourth certificate is signed based on the root certificate.

20. The method according to any one of claims 1 to 19, characterized in that The verifying the temporary key includes: sending the random value to the second electronic device; receiving a first control message sent by the second electronic device; wherein the first control message is generated based on the temporary key and the random value; A temporary key verification is performed on the first control message based on the temporary key and the random value.

21. The method according to any one of claims 1 to 19, characterized in that The method further comprises: A key expiration notification is sent to the second electronic device, wherein the key expiration notification is used to indicate that the temporary key is invalid.

22. The method according to claim 21, characterized in that Before sending the key failure notification to the second electronic device, the method further includes: If it is detected that the current system time exceeds the first valid time period, the temporary key is set to invalid.

23. The method according to any one of claims 1 to 19, characterized in that The method further comprises: If the time validity check fails, the user is prompted that the temporary key has expired.

24. A communication method, applied to a server, characterized in that: The method comprises: Receiving a key acquisition request sent by a second electronic device, wherein the key acquisition request is used to request acquisition of first information; wherein the first information is used to determine the temporary key; The first information is sent to the second electronic device.

25. The method according to claim 24, characterized in that The first information is a temporary key, and sending the first information to the second electronic device includes: The temporary key is encrypted using a fourth public key and then sent to the second electronic device, wherein the fourth public key is sent by the second electronic device to the server.

26. The method according to claim 25, characterized in that The temporary key is sent by the vehicle to the server.

27. The method according to claim 24, characterized in that The first information is encrypted data, and sending the first information to the second electronic device includes: Send encrypted data to the second electronic device, wherein the encrypted data is obtained by encrypting the temporary credentials and the first valid time period using the car smart key, the car smart key is stored in the first electronic device, the temporary credentials are generated by the first electronic device, and the first valid time period is used to represent the valid time period of the temporary key.

28. The method according to claim 27, characterized in that The encrypted data is sent by the first electronic device to the server.

29. The method according to any one of claims 24 to 28, characterized in that The key acquisition request includes a temporary account number, and the key acquisition request is used to request to obtain first information corresponding to the temporary account number.

30. A communication method, applied to a first electronic device, characterized in that: The method comprises: In response to a detected vehicle operation by a user, second information is sent, wherein the second information is used to determine a temporary key.

31. The method according to claim 30, wherein The sending of the second information in response to the detected vehicle operation of the user includes: In response to the detected user's vehicle use operation, a vehicle use request is sent to the vehicle, wherein the vehicle use request includes a first valid time period.

32. The method of claim 72, wherein: The first valid time period is encrypted by the automobile smart key.

33. The method according to claim 71 or 72, characterized in that The car use request also includes a car smart key.

34. The method according to claim 71, wherein The sending of the second information in response to the detected vehicle operation of the user includes: In response to a detected vehicle operation by a user, generating a temporary credential based on the vehicle smart key and a first validity period; The temporary credentials and the first valid time period are encrypted using the automobile smart key to obtain encrypted data, and the encrypted data is sent to a server.

35. A communication method, applied to a second electronic device, characterized in that: The method comprises: Sending a key acquisition request to a server, wherein the key acquisition request is used to request acquisition of first information; wherein the first information is used to determine a temporary key; receiving first information sent by the server; A control request is sent to the vehicle based on the first information, wherein the control request includes the temporary key and a control instruction, and the control instruction is used to control the vehicle.

36. The method of claim 76, wherein: The first information is an encrypted temporary key, and the encrypted temporary key is obtained by encrypting the temporary key with a fourth public key. After receiving the first information sent by the server, the method further includes: The encrypted temporary key is decrypted using the fourth private key to obtain the temporary key.

37. The method according to claim 76, wherein The first information is encrypted data, which is obtained by encrypting the temporary credentials and the first valid time period using a car smart key. The car smart key is stored in a first electronic device, the temporary credentials are generated by the first electronic device, and the first valid time period is used to represent the valid time period of the temporary key.

38. The method of claim 76, wherein: The method further comprises: Receive a key expiration notification; wherein the key expiration notification is used to indicate that the temporary key is invalid.

39. The method according to any one of claims 76 to 79, characterized in that The key acquisition request further includes a temporary account number, and the key acquisition request is used to request to obtain first information corresponding to the temporary account number.

40. A communication method, applied to a car rental platform, characterized in that: The method comprises: Get the first valid time period; Get the car smart key from the server; The car smart key is used as a key, the first valid time period is encrypted and then sent to the vehicle.

41. The method according to claim 81, wherein The method further comprises: Apply for a temporary account from the server, where the temporary account corresponds to a temporary key; The temporary account number is sent to the second electronic device.

42. The method according to claim 82, wherein The method further comprises: Sending a key expiration notification; wherein the key expiration notification is used to indicate that the temporary key is invalid.

43. A vehicle, characterized in that: include: A processor and a memory, the memory being used to store a computer program; the processor being used to run the computer program to implement the communication method according to any one of claims 1 to 23.

44. A server, characterized in that include: A processor and a memory, the memory being used to store a computer program; the processor being used to run the computer program to implement the communication method according to any one of claims 24 to 29.

45. A first electronic device, characterized in that: include: A processor and a memory, the memory being used to store a computer program; the processor being used to run the computer program to implement the communication method as described in any one of claims 30-34.

46. ​​A second electronic device, characterized in that: include: A processor and a memory, the memory being used to store a computer program; the processor being used to run the computer program to implement the communication method as described in any one of claims 35-39.

47. A car rental platform, characterized in that: include: A processor and a memory, the memory being used to store a computer program; the processor being used to run the computer program to implement the communication method as described in any one of claims 40-42.

48. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is run on a computer, the communication method according to any one of claims 1 to 42 is implemented.