Vehicle using method and device based on multi-level verification

By employing multi-level verification methods, including biometric and one-time dynamic password verification, the problem of insufficient vehicle identity verification is solved, vehicle security is improved, the risk of theft is reduced, and the property and information security of vehicle owners are protected.

CN121505718APending Publication Date: 2026-02-10MERCEDES BENZ GRP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511481624.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-16
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

In the existing technology, the identity verification of vehicle users is insufficient, which may lead to the theft of the vehicle when the car key is stolen or the digital key is intercepted, resulting in property loss for the vehicle owner.

Method used

A multi-level authentication method is adopted, including Level 1 authentication (collecting and verifying the vehicle user's biometric data such as fingerprints and voice commands), Level 2 authentication (collecting and verifying one-time dynamic passwords), and Level 3 authentication (collecting iris scans and voice commands) to determine the legitimate identity of the vehicle user and authorize them to use vehicle functions.

Benefits of technology

Multi-level verification enhances vehicle security, reduces the likelihood of vehicle theft or misuse, and ensures the safety of vehicle owners' property and information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121505718A_ABST
    Figure CN121505718A_ABST
Patent Text Reader

Abstract

The invention discloses a vehicle using method and device based on multistage verification, and relates to the technical field of vehicles. The method comprises the steps that in response to a received vehicle door opening request sent by a vehicle user, first-level identity information of the vehicle user is collected, and the first-level identity information is sent to a server side so that the server side can conduct first-level identity verification; under the condition that a first verification result which is issued by the server and indicates that the first-level identity verification is passed is received, a vehicle door is unlocked, and under the condition that a vehicle starting request sent by a vehicle user is received, second-level identity information of the vehicle user is collected; sending the second-level identity information to the server side to enable the server side to perform second-level identity verification; the secondary identity verification comprises one-time dynamic password verification; and starting the vehicle under the condition that a second verification result which is issued by the server and indicates that the second-level identity verification is passed is received. According to the embodiment, the property and information safety of the vehicle owner is guaranteed through hierarchical verification and authorization for the vehicle user.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of vehicles, in particular to a vehicle use method and device based on multi-level verification. BACKGROUND

[0002] When a vehicle user uses a vehicle, in order to protect the property safety of the vehicle, the vehicle user generally needs to use a vehicle key to unlock the vehicle, or remotely control the vehicle unlocking through a digital key. In this case, the identity of the vehicle user cannot be verified, and once the vehicle key is stolen or the digital key is intercepted, the vehicle may be stolen without the vehicle owner's knowledge, causing property loss to the vehicle owner. SUMMARY

[0003] Therefore, the embodiments of the present application provide a vehicle use method and device based on multi-level verification, which protects the property and information safety of the vehicle owner through the hierarchical verification and authorization of the vehicle user (sharing user).

[0004] To achieve the above-mentioned purpose, according to an aspect of an embodiment of the present application, a vehicle use method based on multi-level verification is provided, applied to a vehicle end, comprising:

[0005] In response to receiving a vehicle door opening request sent by a vehicle user, collecting first-level identity information of the vehicle user, and sending the first-level identity information to a service end to enable the service end to perform first-level identity verification;

[0006] In the case of receiving a first verification result indicating that the first-level identity verification is passed issued by the service end, unlocking the vehicle door and, in the case of receiving a vehicle start request sent by the vehicle user, collecting second-level identity information of the vehicle user;

[0007] Sending the second-level identity information to the service end to enable the service end to perform second-level identity verification; the second-level identity verification includes one-time dynamic password verification;

[0008] In the case of receiving a second verification result indicating that the second-level identity verification is passed issued by the service end, starting the vehicle.

[0009] Optionally, the method further comprises:

[0010] In the process of using the vehicle by the vehicle user, in response to receiving a call request for a privacy data unit sent by the vehicle user, collecting third-level identity information of the vehicle user;

[0011] Sending the third-level identity information to the service end to enable the service end to perform third-level identity verification;

[0012] Upon receiving a third verification result indicating that the three-level authentication has been successfully completed from the server, the aforementioned privacy data unit is unlocked for use by the vehicle user.

[0013] Optionally, the above-mentioned collection of the vehicle user's primary identity information includes: collecting the vehicle user's fingerprint information and first voice command;

[0014] And / or,

[0015] The aforementioned collection of the vehicle user's secondary identity information includes: collecting a second voice command issued by the vehicle user containing a one-time dynamic password, wherein the one-time dynamic password originates from the terminal application or server bound to the vehicle.

[0016] Optionally, the aforementioned collection of the three-level identity information of the vehicle user includes:

[0017] Collect iris information and third-party voice commands from the users of the aforementioned vehicles.

[0018] To achieve the above objectives, according to another aspect of the present invention, a vehicle usage method based on multi-level verification is provided, applied to a server, comprising:

[0019] Receive the vehicle user's primary identity information sent by the vehicle terminal, and perform primary identity verification on the vehicle user based on the aforementioned primary identity information.

[0020] If the Level 1 authentication is successful, a first authentication result indicating that the Level 1 authentication has been successful is generated and sent to the vehicle terminal, so that the vehicle terminal can unlock the door based on the door unlocking command included in the first authentication result indicating that the Level 1 authentication has been successful.

[0021] The system receives the secondary identity information of the vehicle user sent by the vehicle and performs secondary identity verification on the vehicle user based on the secondary identity information; the secondary identity verification includes one-time dynamic password verification.

[0022] If the secondary authentication is successful, a second authentication result indicating that the secondary authentication has been successful is generated and sent to the vehicle terminal, so that the vehicle terminal can start the vehicle based on the vehicle start command included in the second authentication result indicating that the secondary authentication has been successful.

[0023] Optionally, the above method further includes:

[0024] A shared user information database containing fingerprint, iris, and voiceprint data of shared users is pre-built;

[0025] Based on the aforementioned shared user information database, the users of the aforementioned vehicles are subject to Level 1 and Level 2 identity verification, respectively.

[0026] Optionally, the above method further includes:

[0027] Receive the vehicle user's three-level identity information sent by the vehicle, and perform three-level identity verification on the vehicle user based on the three-level identity information.

[0028] If the Level 3 authentication is successful, a third authentication result indicating that the Level 3 authentication has been successful is generated and sent to the vehicle terminal, so that the vehicle terminal can authorize the vehicle user to call the privacy data unit based on the privacy data unit authorization instruction included in the third authentication result indicating that the Level 3 authentication has been successful.

[0029] Optionally, the aforementioned secondary identity information includes a second voice command containing a one-time dynamic password;

[0030] The above-mentioned secondary identity verification of the vehicle user based on the above-mentioned secondary identity information includes:

[0031] After the terminal application bound to the vehicle or the server provides the one-time dynamic password to the vehicle user, a countdown timer is set for the validity period of the one-time dynamic password.

[0032] If the time for receiving the second voice command exceeds the countdown time, a second verification result indicating that the second-level authentication failed is generated.

[0033] If the time of receiving the second voice command does not exceed the countdown of the effective time, the correctness of the one-time dynamic password and the voiceprint information of the second voice command are verified.

[0034] If the above correctness verification and the above voiceprint verification pass, a second verification result indicating that the second-level authentication has passed is generated.

[0035] Optionally, the above-mentioned verification of the correctness of the one-time dynamic password and the voiceprint verification of the voiceprint information of the second voice command include:

[0036] Obtain the target password set by the vehicle owner from the terminal application bound to the vehicle, or determine the target password generated by the server for the vehicle, and compare the one-time dynamic password with the target password to verify the correctness of the one-time dynamic password.

[0037] If the comparison result indicates that the one-time dynamic password and the target password are consistent, it is determined that the one-time dynamic password has been verified.

[0038] Simultaneously, the voiceprint information carried by the second voice command is collected, and the voiceprint information is matched with the voiceprint data pre-stored in the shared user information database.

[0039] If the matching result indicates that the above voiceprint information matches any voiceprint data in the above-mentioned shared user information database, the voiceprint verification is deemed successful.

[0040] To achieve the above objectives, according to another aspect of the present invention, a vehicle-using device based on multi-level verification is provided, configured on a vehicle, comprising:

[0041] The first data collection module is used to respond to a door opening request sent by the vehicle user, collect the first-level identity information of the vehicle user, and send the first-level identity information to the server so that the server can perform first-level identity verification.

[0042] The second collection module is used to unlock the car door when it receives the first verification result indicating that the first-level identity verification has been passed from the server, and to collect the second-level identity information of the vehicle user when it receives the vehicle start request sent by the vehicle user.

[0043] The sending module is used to send the aforementioned secondary identity information to the server so that the server can perform secondary identity verification; the aforementioned secondary identity verification includes one-time dynamic password verification;

[0044] The startup module is used to start the vehicle upon receiving a second verification result from the server indicating that the second-level authentication has been successful.

[0045] To achieve the above objectives, according to another aspect of the present invention, a vehicle use device based on multi-level verification is provided, configured on a server, comprising:

[0046] The first verification module is used to receive the vehicle user's first-level identity information sent by the vehicle terminal, and to perform first-level identity verification on the vehicle user based on the first-level identity information.

[0047] The first generation module is used to generate a first verification result indicating that the first-level authentication has been passed and send it to the vehicle terminal when the first-level authentication has been passed, so that the vehicle terminal can unlock the door based on the door unlocking command included in the first verification result indicating that the first-level authentication has been passed.

[0048] The second verification module is used to receive the secondary identity information of the vehicle user sent by the vehicle, and to perform secondary identity verification on the vehicle user based on the secondary identity information; the secondary identity verification includes one-time dynamic password verification.

[0049] The second generation module is used to generate a second verification result indicating that the second-level authentication has been passed when the second-level authentication is passed, and send it to the vehicle terminal so that the vehicle terminal can start the vehicle based on the vehicle start command included in the second verification result indicating that the second-level authentication has been passed.

[0050] To achieve the above objectives, according to another aspect of the present invention, an electronic device for vehicle use based on multi-level verification is provided.

[0051] An embodiment of the present invention provides an electronic device for vehicle use based on multi-level verification, comprising: one or more processors; and a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement a vehicle use method based on multi-level verification according to an embodiment of the present invention.

[0052] To achieve the above objectives, according to another aspect of the present invention, a computer-readable storage medium is provided.

[0053] An embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a vehicle use method based on multi-level verification according to an embodiment of the present invention.

[0054] One embodiment of the above invention has the following advantages or beneficial effects: by collecting the vehicle user's primary identity information when receiving a door opening request from the vehicle user and determining whether to unlock the door based on the first verification result of the primary identity information, and collecting the vehicle user's secondary identity information when receiving a vehicle start request from the vehicle user and determining whether to start the vehicle based on the second verification result of the secondary identity information, multi-level identity verification is performed on the vehicle user when the vehicle user wants to use the vehicle to determine whether the vehicle user has the right to use the vehicle. This avoids the problem that a single verification method cannot effectively prevent others without the right to use the vehicle from stealing the vehicle, improves the vehicle security factor, and reduces the possibility of the vehicle being stolen or misused.

[0055] In addition, during the secondary identity verification process for vehicle users, one-time dynamic passwords are verified. Based on the one-time nature of one-time dynamic passwords, vehicle property losses caused by the theft of one-time dynamic passwords can be further avoided, thus improving the security of vehicle use.

[0056] By implementing tiered verification and authorization for vehicle users (sharing users), the property and information security of vehicle owners is protected.

[0057] The further effects of the aforementioned unconventional alternative methods will be explained below in conjunction with specific implementation methods. Attached Figure Description

[0058] The accompanying drawings are provided to better understand the invention and are not intended to unduly limit the scope of the invention. Wherein:

[0059] Figure 1 This is a flowchart illustrating a vehicle usage method based on multi-level verification applied to the vehicle side according to an embodiment of the present invention.

[0060] Figure 2 This is a flowchart illustrating a multi-level verification-based vehicle usage method applied to a server according to an embodiment of the present invention.

[0061] Figure 3 This is a flowchart illustrating a vehicle usage method based on multi-level verification according to another embodiment of the present invention;

[0062] Figure 4 This is a schematic diagram of the main modules of a vehicle-use device based on multi-level verification configured on the vehicle end according to an embodiment of the present invention;

[0063] Figure 5 This is a schematic diagram of the main modules of a vehicle use device based on multi-level verification configured on the server according to an embodiment of the present invention;

[0064] Figure 6 This is an exemplary system architecture diagram in which embodiments of the present invention can be applied;

[0065] Figure 7 This is a schematic diagram of the structure of a computer system suitable for implementing the vehicle-side or server-side embodiments of the present invention. Detailed Implementation

[0066] The following description, in conjunction with the accompanying drawings, illustrates exemplary embodiments of the present invention, including various details to aid understanding. These details should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the invention. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0067] It should be noted that, unless otherwise specified, the embodiments of the present invention and the technical features thereof can be combined with each other.

[0068] It should be noted that the collection, gathering, updating, analysis, processing, use, transmission, and storage of user personal information involved in this disclosed technical solution all comply with relevant laws and regulations, are used for legitimate purposes, and do not violate public order and good morals. Necessary measures are taken to prevent unauthorized access to user personal information data and to safeguard user personal information security, network security, and national security.

[0069] like Figure 1 As shown, the vehicle usage method based on multi-level verification in this embodiment of the invention mainly includes the following steps S101 to S104:

[0070] Step S101: In response to receiving a door opening request sent by the vehicle user, collect the primary identity information of the vehicle user and send the primary identity information to the server so that the server can perform primary identity verification.

[0071] The vehicle can receive door opening requests from the user when they touch the door switch, via voice, or by touching a fingerprint sensor pre-installed on the door, among other things. For example, a door opening request can also be sent by the user via the remote vehicle key.

[0072] Primary identity information can be collected through sensors pre-configured in the vehicle. This primary identity information should include biometric data that uniquely identifies the vehicle user. This biometric data may include fingerprint, iris, and / or voiceprint information.

[0073] Step S102: Upon receiving the first verification result indicating that the first-level identity verification has passed from the server, unlock the car door and, upon receiving the vehicle start request sent by the vehicle user, collect the second-level identity information of the vehicle user.

[0074] The first verification result of Level 1 authentication determines whether the vehicle door can be unlocked for the vehicle user. This can be achieved by using the vehicle user's (e.g., a shared user's) voiceprint, fingerprint, and corresponding voice command. When a first verification result indicating successful Level 1 authentication is received, it means the vehicle user's legitimate identity has been confirmed through Level 1 identity information, and the door can be unlocked. Conversely, when a first verification result indicating failed Level 1 authentication is received, it means the vehicle user's legitimate identity cannot be confirmed through Level 1 identity information, and the current vehicle user's identity is questionable. To avoid property loss for the vehicle owner, the door will remain locked, and the door will not be unlocked for the vehicle user.

[0075] Secondary identity information can be collected through sensors pre-configured in the vehicle. This secondary identity information should include biometric data that uniquely identifies the vehicle user. It should be noted that secondary identity information and primary identity information should include at least one different biometric data. For example, when primary identity information includes fingerprint information, secondary identity information may include iris information.

[0076] Step S103: Send the aforementioned secondary identity information to the server so that the server can perform secondary identity verification; the aforementioned secondary identity verification includes one-time dynamic password verification;

[0077] Secondary identity information includes not only the vehicle user's biometric data, but also a one-time dynamic password, so that the vehicle user's biometric data and one-time dynamic password can be verified during the secondary identity verification process on the server side.

[0078] The one-time dynamic password is a temporary password with a single verification attempt. It expires immediately after the second-level authentication to prevent theft or repeated use. Furthermore, the one-time dynamic password is dynamically changing; it can be different for each instance of second-level identity information collection. For example, when a vehicle user (e.g., a sharing user) starts the vehicle, the in-vehicle entertainment system announces "Please say the password." The sharing user obtains the one-time dynamic password from the vehicle owner and speaks it aloud. The in-vehicle entertainment system then parses the voice information and uploads it to the server for voiceprint and one-time dynamic password matching to further control the shared vehicle startup.

[0079] Setting a one-time dynamic password can prevent it from being leaked, reused, or attacked. Based on its timeliness and uniqueness, it can further avoid illegal verification and improve the accuracy of confirming the legitimate identity of the vehicle user.

[0080] Step S104: Upon receiving the second verification result from the server indicating that the second-level authentication has passed, start the vehicle.

[0081] The second verification result of the secondary identity verification determines whether the vehicle can be started for the vehicle user. For example, the second verification result is determined based on the voiceprint, dynamic password, and corresponding voice command of the vehicle user (e.g., a shared user). When a second verification result indicating that the secondary identity verification has passed is received, it means that the legitimate identity of the vehicle user has been confirmed through the primary and secondary identity information, and the vehicle can be started for the vehicle user. When a second verification result indicating that the secondary identity verification has failed is received, it means that even if the primary identity information of the vehicle user has been verified, the legitimate identity of the vehicle user cannot be confirmed through the secondary identity information, and the identity of the current vehicle user is questionable. In order to avoid property loss to the vehicle owner, the vehicle can not be started for the vehicle user.

[0082] In an optional embodiment, the method further includes: during the vehicle user's use of the vehicle, in response to receiving a request from the vehicle user to call the privacy data unit, collecting the vehicle user's three-level identity information; sending the three-level identity information to the server to enable the server to perform three-level authentication; and, upon receiving a third verification result from the server indicating that the three-level authentication has passed, unlocking the privacy data unit for the vehicle user to call.

[0083] It is understandable that vehicles may contain data or functions that involve the owner's privacy or that the owner does not wish to directly display to others. Therefore, a privacy data unit including such data and functions can be pre-built. When a vehicle user requests access to any data or function within the privacy data unit, a three-level authentication process can be used to verify whether the current vehicle user is authorized to access the privacy data unit. As an example, the privacy data unit may include contacts, user information, playlists, air conditioning functions, health data, etc.

[0084] The data and functions in the privacy data unit can be adjusted according to the owner's needs. For example, if the owner does not want other vehicle users to be able to directly access historical navigation data, the historical navigation data can be included in the privacy data unit; if the owner believes that playlists already existing in the privacy data unit can be directly displayed to other vehicle users, the playlists can be removed from the privacy data unit.

[0085] Level 3 identity information should include biometric data that uniquely identifies the vehicle user. It should be noted that Level 3 identity information should include at least one type of biometric data that differs from Level 2 and Level 1 identity information, thereby improving the accuracy of vehicle user authentication. For example, Level 1 identity information includes fingerprint information, Level 2 identity information includes voiceprint information, and Level 3 identity information includes iris information, which is a different type of biometric data from fingerprint and voiceprint information.

[0086] The third verification result of three-level authentication determines whether the vehicle user is allowed to access the privacy data unit. For example, the third verification result is determined based on the vehicle user's (e.g., a shared user's) voiceprint, iris information, and corresponding voice commands. When a third verification result indicating that the three-level authentication has passed is received, it means that the vehicle user's legitimate identity has been confirmed through the first-level, second-level, and third-level identity information, and the vehicle user has passed the three-level authentication. In this case, the vehicle user is authorized to access the privacy data unit, and access to the privacy data unit can be permitted. When a third verification result indicating that the three-level authentication has failed is received, it means that even if the first-level and second-level identity information verifications of the vehicle user have passed, it is impossible to determine whether the vehicle user has the permission to access the privacy data unit through the third-level identity information. In order to protect the privacy and security of the vehicle owner, access to the privacy data unit may not be authorized.

[0087] In one optional embodiment, the above-mentioned collection of the vehicle user's primary identity information includes: collecting the vehicle user's fingerprint information and a first voice command.

[0088] Understandably, the purpose of Level 1 authentication is to determine whether the vehicle door can be unlocked for the user. If a door opening request is received but Level 1 authentication has not been performed, and the user is located outside the vehicle cabin, a fingerprint sensor can be pre-installed on the door and a voice acquisition sensor can be configured inside the vehicle to facilitate the collection of the user's biometric data. This allows the user to collect their fingerprint information when they touch the fingerprint sensor and their first voice command when they speak.

[0089] The purpose of collecting the first voice command is to obtain the voiceprint information of the vehicle user contained therein. The content of the first voice command may include a command to start the vehicle door, or it may not include any vehicle-specific commands.

[0090] By collecting the vehicle user's fingerprint information and the first voice command carrying their voiceprint information, the vehicle user can be identified at the first level using both biometric data, thus improving the accuracy of the verification.

[0091] In one optional embodiment, the above-mentioned collection of the secondary identity information of the vehicle user includes: collecting a second voice command containing a one-time dynamic password issued by the vehicle user, wherein the one-time dynamic password originates from the terminal application or server bound to the vehicle.

[0092] When collecting secondary identity information, the vehicle user has already entered the vehicle. A second voice command containing a one-time dynamic password can be collected via a pre-installed voice sensor within the vehicle cabin. The purpose of collecting the second voice command is to obtain the one-time dynamic password and the voiceprint information of the vehicle user contained within it.

[0093] By simultaneously verifying vehicle users' identity using both iris and voiceprint information, the accuracy of verification can be further improved.

[0094] In one optional embodiment, the above-mentioned collection of the vehicle user's three-level identity information includes: collecting the vehicle user's iris information and third voice commands.

[0095] The collection of Level 3 identity information should occur after the vehicle user enters the vehicle cabin. This involves using an iris sensor pre-configured in the vehicle to collect the user's iris information, and a voice sensor to collect a third voice command. By collecting the user's iris information and the third voice command carrying their voiceprint information, Level 3 identity verification can be performed simultaneously using two types of biometric data, improving the accuracy of the verification and further protecting the vehicle owner's privacy and security.

[0096] It should be noted that the content of the first, second, and third voice commands can be preset content provided by the server or the vehicle, or content organized by the vehicle user. The second voice command must include at least a one-time dynamic password.

[0097] In one optional embodiment, the above-described vehicle use method based on multi-level verification can be applied to scenarios such as a car owner temporarily lending their private car to a vehicle user or a vehicle user using a shared vehicle, and is not limited thereto.

[0098] According to the multi-level authentication-based vehicle usage method of the present invention, when a vehicle user sends a door opening request, the method collects the vehicle user's primary identity information and determines whether to unlock the door based on the first verification result of the primary identity information. When a vehicle user sends a vehicle start request, the method collects the vehicle user's secondary identity information and determines whether to start the vehicle based on the second verification result of the secondary identity information. Thus, when a vehicle user wants to use the vehicle, the method performs multi-level authentication to determine whether the vehicle user has the right to use the vehicle. This avoids the problem that a single authentication method cannot effectively prevent unauthorized persons from stealing the vehicle, improves vehicle security, and reduces the possibility of vehicle theft or misuse.

[0099] In addition, during the secondary identity verification process for vehicle users, one-time dynamic passwords are verified. Based on the one-time nature of one-time dynamic passwords, property losses caused by the theft of one-time dynamic passwords can be further avoided, thereby improving the security of vehicle use. Through hierarchical verification and authorization for vehicle users (shared users), the property and information security of vehicle owners can be protected.

[0100] like Figure 2 As shown, the vehicle usage method based on multi-level verification according to an embodiment of the present invention is applied to the server and includes the following steps S201 to S204:

[0101] Step S201: Receive the vehicle user's first-level identity information sent by the vehicle terminal, and perform first-level identity verification on the vehicle user based on the first-level identity information.

[0102] Step S202: If the Level 1 authentication is successful, a first authentication result indicating that the Level 1 authentication is successful is generated and sent to the vehicle terminal, so that the vehicle terminal can unlock the door based on the door unlocking command included in the first authentication result indicating that the Level 1 authentication is successful.

[0103] By performing Level 1 authentication on the vehicle user, the system can determine whether to unlock the car door based on the first authentication result. If Level 1 authentication is successful, it indicates that the legitimate identity of the vehicle user has been confirmed, and a first authentication result containing a door unlock command is generated and sent to the vehicle, enabling the vehicle to unlock the door for the user. If Level 1 authentication fails, it indicates that the legitimate identity of the vehicle user cannot be confirmed, and a first authentication result indicating that Level 1 authentication failed is generated and sent to the vehicle, ensuring the door remains locked to prevent loss of the owner's property.

[0104] Step S203: Receive the secondary identity information of the vehicle user sent by the vehicle, and perform secondary identity verification on the vehicle user based on the secondary identity information; the secondary identity verification includes one-time dynamic password verification.

[0105] Step S204: If the secondary authentication is successful, a second authentication result indicating that the secondary authentication is successful is generated and sent to the vehicle terminal, so that the vehicle terminal starts the vehicle based on the vehicle start command included in the second authentication result indicating that the secondary authentication is successful.

[0106] By performing two-level authentication on the vehicle user, the system can determine whether the vehicle user is authorized to start the vehicle based on the second authentication result. If both the first-level and second-level authentications are successful, it indicates that the vehicle user's legitimate identity has been confirmed. A second authentication result containing a vehicle start command is then generated and sent to the vehicle, enabling the vehicle to start the vehicle for the user. If the second-level authentication fails, it indicates that the vehicle user's legitimate identity cannot be confirmed. A second authentication result indicating that the second-level authentication failed is then generated and sent to the vehicle, keeping the vehicle in an inactive state to prevent loss of property to the vehicle owner.

[0107] Optionally, the server in this embodiment of the invention may be a cloud or a back-end management server that has a data connection with the vehicle, and no specific limitation is made here.

[0108] In an optional embodiment, the method further includes: pre-constructing a shared user information database containing fingerprint data, iris data, and voiceprint data of the shared user; and performing first-level authentication and second-level authentication on the vehicle user based on the shared user information database. In addition to the fingerprint data, iris data, and voiceprint data, the shared user information database may also include other biometric data of the shared user.

[0109] In this context, "shared users" refers to users whose biometric data has been pre-stored and who have vehicle usage rights. The purpose of performing Level 1 and Level 2 authentication on vehicle users is to determine whether they are indeed shared users.

[0110] Optionally, users can register on the server. The vehicle owner or staff can add the user's account information to the vehicle's shared user information database. Pre-configured sensors in the vehicle, used for collecting fingerprint, iris, and voiceprint data, or other data collection devices linked to the vehicle, can be used to collect the user's biometric data. This biometric data, associated with the user's account information, is stored in the shared user information database. This allows for subsequent identity verification of vehicle users, identifying whether they are shared users and determining their legitimacy to unlock doors, start the vehicle, or access privacy data units.

[0111] Specifically, the aforementioned first-level identity verification of the vehicle user based on the shared user information database includes: retrieving fingerprint data and voiceprint data from the shared user information database that match the fingerprint information and voiceprint information carried by the first voice command in the first-level identity information; if fingerprint data matching the fingerprint information and voiceprint data matching the voiceprint information carried by the first voice command are retrieved from the shared user information database, and the retrieved fingerprint data and voiceprint data are associated with the same shared user account information, it indicates that the vehicle user is one of the shared users with door unlocking permissions, and a door unlocking function can be generated. The lock command indicates a first verification result indicating that the first-level authentication has passed; if no fingerprint data matching the fingerprint information can be found in the shared user information database, or no voiceprint data matching the voiceprint information carried by the first voice command can be found, or if fingerprint data matching the fingerprint information and voiceprint data matching the voiceprint information carried by the first voice command can be found, but the retrieved fingerprint data and voiceprint data are associated with different shared user account information, it indicates that the vehicle user may not be a shared user with door unlocking authority, and a first verification result indicating that the first-level authentication has failed can be generated.

[0112] In an optional embodiment, the method further includes: receiving the vehicle user's three-level identity information sent by the vehicle, and performing three-level authentication on the vehicle user based on the three-level identity information; if the three-level authentication is successful, generating a third verification result indicating that the three-level authentication is successful and sending it to the vehicle terminal, so that the vehicle terminal authorizes the vehicle user to call the privacy data unit based on the privacy data unit authorization instruction included in the third verification result indicating that the three-level authentication is successful.

[0113] By performing three-level authentication on the vehicle user, the third authentication result can determine whether the vehicle user is allowed to access the privacy data unit.

[0114] Specifically, the system retrieves fingerprint and voiceprint data from the shared user information database that match the iris information in the three-level identity information and the voiceprint information carried by the third voice command. If iris data matching the aforementioned iris information and voiceprint data matching the aforementioned voiceprint information carried by the third voice command are found in the shared user information database, and the retrieved iris data and voiceprint data are associated with the same shared user account information, it indicates that the vehicle user is a shared user with permission to access the privacy data unit, and a notification indicating that the three-level identity verification has passed is generated, containing a privacy data unit authorization command. The third verification result is as follows: If no iris data matching the aforementioned iris information or voiceprint data matching the aforementioned voiceprint information carried by the aforementioned third voice command can be retrieved from the aforementioned shared user information database, or if iris data matching the aforementioned iris information and voiceprint data matching the aforementioned voiceprint information carried by the aforementioned third voice command can be retrieved, but the retrieved iris data and voiceprint data are associated with different shared user account information, then it indicates that the vehicle user may not be a shared user with the permission to access the privacy data unit, and a third verification result indicating that the three-level identity verification failed is generated.

[0115] In one optional embodiment, the aforementioned secondary identity information includes a second voice command containing a one-time dynamic password. The one-time dynamic password is unique and time-sensitive, which can improve the accuracy of verification and avoid the problem of password reuse leading to potential property security risks.

[0116] The aforementioned secondary identity verification for the vehicle user based on the aforementioned secondary identity information includes: after the terminal application bound to the vehicle or the aforementioned server provides the aforementioned one-time dynamic password to the vehicle user, performing a countdown on the validity period of the aforementioned one-time dynamic password; if the time for receiving the aforementioned second voice command exceeds the aforementioned countdown on the validity period, generating a second verification result indicating that the secondary identity verification has failed; if the time for receiving the aforementioned second voice command does not exceed the aforementioned countdown on the validity period, verifying the correctness of the aforementioned one-time dynamic password and verifying the voiceprint information of the aforementioned second voice command; if the aforementioned correctness verification and the aforementioned voiceprint verification pass, generating a second verification result indicating that the secondary identity verification has passed.

[0117] One-time dynamic passwords have a limited validity period. From the time the one-time dynamic password is provided to the vehicle user until the server receives the secondary identity information sent by the vehicle, if this process exceeds the countdown of the one-time dynamic password's validity period, the one-time dynamic password becomes invalid, and secondary identity verification fails. By setting an validity period for one-time dynamic passwords, vehicle security can be improved. Even if the one-time dynamic password is stolen, it cannot be used to repeatedly obtain vehicle start permissions due to its single-use validity and timeout expiration, making it suitable for scenarios where the vehicle is temporarily authorized for use by the vehicle user.

[0118] In an optional embodiment, the above-mentioned verification of the correctness of the one-time dynamic password and the verification of the voiceprint information of the second voice command include: obtaining the target password set by the vehicle owner from the terminal application bound to the vehicle or determining the target password generated by the server for the vehicle; comparing the one-time dynamic password and the target password to verify the correctness of the one-time dynamic password; if the comparison result indicates that the one-time dynamic password and the target password are consistent, determining that the one-time dynamic password verification is successful; simultaneously, collecting the voiceprint information carried by the second voice command, matching the voiceprint information with the voiceprint data pre-stored in the shared user information database; if the matching result indicates that the voiceprint information matches any voiceprint data in the shared user information database, determining that the voiceprint verification is successful.

[0119] In addition to ensuring that the one-time dynamic password meets the timeliness requirement, it is also necessary to verify the correctness of the one-time dynamic password and the voiceprint information carried by the second voice command.

[0120] The target password can be generated by the server according to preset password update rules, or it can be set by the vehicle owner through the terminal application bound to the vehicle. When the target password is set by the vehicle owner through the terminal application bound to the vehicle, the server can obtain the target password from the terminal application, thereby comparing the one-time dynamic password with the target password and verifying the correctness of the one-time dynamic password.

[0121] If both the one-time dynamic password verification and voiceprint verification pass, a second verification result indicating successful secondary identity verification is generated. The second verification result should include a vehicle start command so that the vehicle can start the vehicle for the user after receiving the second verification result indicating successful secondary identity verification. If either the one-time dynamic password verification or the voiceprint verification fails, or if both fail, a second verification result indicating failed secondary identity verification is generated.

[0122] According to the multi-level authentication-based vehicle usage method of the present invention, after receiving the first-level identity information sent by the vehicle terminal, the method performs first-level authentication on the vehicle user. If the first-level authentication is successful, a first authentication result containing a door unlocking command is sent to the vehicle terminal indicating that the first-level authentication has been successful. After receiving the second-level identity information sent by the vehicle terminal, the method performs second-level authentication on the vehicle user. If the second-level authentication is successful, a second authentication result containing a vehicle start command is sent to the vehicle terminal indicating that the second-level authentication has been successful. Thus, when the vehicle user wants to use the vehicle, multi-level authentication is performed on the vehicle user to determine whether the vehicle user has the right to use the vehicle. This avoids the problem that a single authentication method cannot effectively prevent others without the right to use the vehicle from stealing it, improves the vehicle security level, and reduces the possibility of the vehicle being stolen or misused.

[0123] In addition, during the secondary identity verification process for vehicle users, one-time dynamic passwords are verified. Based on the one-time nature and time-limited validity of one-time dynamic passwords, vehicle property losses caused by the theft of one-time dynamic passwords can be further avoided, thereby improving the security of vehicle use.

[0124] The following specific embodiment illustrates the vehicle usage method based on multi-level verification.

[0125] like Figure 3 As shown, the vehicle usage method based on multi-level verification in this embodiment of the invention includes the following steps S301 to S312:

[0126] Step S301: When the vehicle terminal receives a door opening request sent by the vehicle user, it collects the primary identity information of the vehicle user and sends the primary identity information to the server.

[0127] The primary identity information includes the vehicle user's fingerprint information and the first voice command;

[0128] The vehicle can collect the fingerprint information of the vehicle user through a fingerprint collection device pre-installed on the outside of the vehicle door, and collect the first voice command issued by the vehicle user through a voice collection device.

[0129] In step S302, the server receives the aforementioned primary identity information and retrieves fingerprint data matching the fingerprint information in the shared user information database. Simultaneously, it extracts voiceprint information from the first voice command and retrieves voiceprint data matching the aforementioned voiceprint information in the shared user information database. If both fingerprint data matching the fingerprint information and voiceprint data matching the voiceprint information are retrieved (Y1), the process proceeds to step S303. If neither fingerprint data matching the fingerprint information nor voiceprint data matching the voiceprint information is retrieved (N1), the process proceeds to step S305.

[0130] In step S303, the server can determine whether the shared user account information associated with the fingerprint data matching the fingerprint information and the shared user account information associated with the voiceprint data matching the voiceprint information belong to the same shared user account information; if they do not belong to the same shared user account information, proceed to step S305; if they belong to the same shared user account information, proceed to step S304.

[0131] In step S304, the server can generate a first verification result indicating that the first-level authentication has passed, which includes a door unlocking command, and send the first verification result indicating that the first-level authentication has passed to the vehicle, proceeding to step S306.

[0132] In step S305, the server can generate a first verification result indicating that the first-level authentication failed and send it to the vehicle terminal, proceeding to step S312;

[0133] Step S306: Based on the door unlocking command contained in the first verification result indicating that the first-level identity verification has passed, the vehicle terminal unlocks the door for the vehicle user, and upon receiving the vehicle start request sent by the vehicle user, collects the second-level identity information of the vehicle user and sends it to the server.

[0134] Secondary identity information includes a second voice command containing a one-time dynamic password;

[0135] In step S307, the server can determine the time when the terminal application bound to the vehicle terminal or the time when the server provides the one-time dynamic password to the vehicle user, and start a countdown for the validity period of the one-time dynamic password at that time to determine whether the time of receiving the second voice command exceeds the countdown. If the countdown exceeds the validity period, a second verification result indicating that the second-level authentication failed is generated and sent to the vehicle terminal, proceeding to step S312. If the countdown does not exceed the validity period, proceeding to step S308.

[0136] Step S308: Obtain the target password set by the vehicle owner from the terminal application bound to the vehicle or determine the target password generated by the server for the vehicle. Compare the one-time dynamic password with the target password and determine whether the correctness verification of the one-time dynamic password has passed based on the comparison result. At the same time, collect the voiceprint information carried by the second voice command, match the voiceprint information with the voiceprint data pre-stored in the shared user information database, and determine whether the voiceprint verification has passed based on the matching result.

[0137] If both the one-time dynamic password verification and voiceprint verification pass, Y4 generates a second verification result indicating that the secondary identity verification has passed, which includes the vehicle start command, and sends it to the vehicle terminal, proceeding to step S309; ​​if either or both of the one-time dynamic password verification and voiceprint verification fail, N4 generates a second verification result indicating that the secondary identity verification has failed, and sends it to the vehicle terminal, proceeding to step S312.

[0138] In step S309, the vehicle starts the vehicle for the user based on the vehicle start command included in the second verification result indicating that the second-level authentication has been passed; and during the use of the vehicle, it receives the user's request to access the privacy data unit, collects the user's third-level identity information, and sends it to the server.

[0139] The three-level identity information includes iris information and third-party voice commands;

[0140] In step S310, the server can receive the aforementioned three-level identity information and retrieve iris data matching the iris information in the shared user information database. Simultaneously, it extracts voiceprint information from the third voice command and retrieves voiceprint data matching the aforementioned voiceprint information in the shared user information database. If both the iris data matching the iris information and the voiceprint data matching the voiceprint information are retrieved, Y5, a third verification result indicating that the three-level identity verification has passed, containing a privacy data unit authorization command, is generated and sent to the vehicle terminal, proceeding to step S311. If neither the iris data matching the iris information nor the voiceprint data matching the voiceprint information is retrieved, N5, a third verification result indicating that the three-level identity verification has failed is generated and sent to the vehicle terminal, proceeding to step S312.

[0141] Step S311: The vehicle receives the third verification result indicating that the three-level authentication has been passed, and authorizes the vehicle user to call the privacy data unit based on the privacy data unit authorization instruction therein;

[0142] In step S312, according to steps S305, S307, S308 or S310, the vehicle receives a first verification result indicating that the first-level authentication failed, a second verification result indicating that the second-level authentication failed, or a third verification result indicating that the third-level authentication failed, and ends the current process.

[0143] According to the multi-level authentication-based vehicle usage method of the present invention, when a vehicle user sends a door opening request, the method collects the vehicle user's primary identity information and determines whether to unlock the door based on the first verification result of the primary identity information. When a vehicle user sends a vehicle start request, the method collects the vehicle user's secondary identity information and determines whether to start the vehicle based on the second verification result of the secondary identity information. Thus, when a vehicle user wants to use the vehicle, the method performs multi-level authentication to determine whether the vehicle user has the right to use the vehicle. This avoids the problem that a single authentication method cannot effectively prevent unauthorized persons from stealing the vehicle, improves vehicle security, and reduces the possibility of vehicle theft or misuse.

[0144] In addition, during the secondary identity verification process for vehicle users, one-time dynamic passwords are verified. Based on the one-time nature of one-time dynamic passwords, vehicle property losses caused by the theft of one-time dynamic passwords can be further avoided, thus improving the security of vehicle use.

[0145] like Figure 4 As shown in the figure, the vehicle-using device 400 based on multi-level authentication configured on the vehicle end according to an embodiment of the present invention includes: a first acquisition module 401, used to acquire the first-level identity information of the vehicle user in response to receiving a door opening request sent by the vehicle user, and send the first-level identity information to the server so that the server can perform first-level authentication; a second acquisition module 402, used to unlock the door when receiving a first verification result indicating that the first-level authentication has passed from the server, and to acquire the second-level identity information of the vehicle user when receiving a vehicle start request sent by the vehicle user; a sending module 403, used to send the second-level identity information to the server so that the server can perform second-level authentication; the second-level authentication includes one-time dynamic password authentication; and a start module 404, used to start the vehicle when receiving a second verification result indicating that the second-level authentication has passed from the server.

[0146] In an optional embodiment of the present invention, the vehicle use device 400 based on multi-level verification further includes: a third collection module, configured to, during the process of the vehicle user using the vehicle, in response to receiving a request from the vehicle user to call a privacy data unit, collect the vehicle user's three-level identity information; send the three-level identity information to the server so that the server can perform three-level authentication; and, upon receiving a third verification result from the server indicating that the three-level authentication has passed, unlock the privacy data unit for the vehicle user to call.

[0147] In an optional embodiment of the present invention, the first acquisition module 401 is further used to acquire the fingerprint information and first voice command of the vehicle user.

[0148] And / or,

[0149] The second acquisition module 402 is also used to acquire the second voice command containing a one-time dynamic password issued by the vehicle user, wherein the one-time dynamic password comes from the terminal application or server bound to the vehicle.

[0150] In an optional embodiment of the present invention, the third acquisition module is further configured to acquire the iris information and third voice command of the vehicle user.

[0151] According to an embodiment of the present invention, a vehicle-mounted device based on multi-level authentication, when receiving a door opening request from a vehicle user, collects the vehicle user's primary identity information and determines whether to unlock the door based on a first verification result of the primary identity information. When receiving a vehicle start request from a vehicle user, it collects the vehicle user's secondary identity information and determines whether to start the vehicle based on a second verification result of the secondary identity information. Thus, when a vehicle user wants to use the vehicle, multi-level authentication is performed on the vehicle user to determine whether the vehicle user has the right to use the vehicle. This avoids the problem that a single authentication method cannot effectively prevent unauthorized persons from stealing the vehicle, improves vehicle security, and reduces the possibility of vehicle theft or misuse.

[0152] In addition, during the secondary identity verification process for vehicle users, one-time dynamic passwords are verified. Based on the one-time nature of one-time dynamic passwords, vehicle property losses caused by the theft of one-time dynamic passwords can be further avoided, thus improving the security of vehicle use.

[0153] like Figure 5As shown, the vehicle usage device 500 based on multi-level authentication configured on the server in this embodiment of the invention includes: a first authentication module 501, used to receive the first-level identity information of the vehicle user sent by the vehicle terminal, and perform first-level authentication on the vehicle user based on the first-level identity information; a first generation module 502, used to generate a first authentication result indicating that the first-level authentication has passed when the first-level authentication has passed, and send it to the vehicle terminal, so that the vehicle terminal can unlock the door based on the door unlocking command included in the first authentication result indicating that the first-level authentication has passed; a second authentication module 503, used to receive the second-level identity information of the vehicle user sent by the vehicle, and perform second-level authentication on the vehicle user based on the second-level identity information; the second-level authentication includes one-time dynamic password authentication; and a second generation module 504, used to generate a second authentication result indicating that the second-level authentication has passed when the second-level authentication has passed, and send it to the vehicle terminal, so that the vehicle terminal can start the vehicle based on the vehicle start command included in the second authentication result indicating that the second-level authentication has passed.

[0154] In an optional embodiment of the present invention, the vehicle use device 500 based on multi-level verification further includes: a construction module, used to pre-build a shared user information database containing fingerprint data, iris data and voiceprint data of shared users, so as to perform first-level identity verification of the vehicle user through the first verification module 501 and second-level identity verification of the vehicle user through the second verification module 503 based on the shared user information database.

[0155] In an optional embodiment of the present invention, the vehicle use device 500 based on multi-level authentication further includes: a third authentication module, configured to receive the vehicle user's three-level identity information sent by the vehicle, and perform three-level authentication on the vehicle user based on the three-level identity information; if the three-level authentication is successful, generate a third authentication result indicating that the three-level authentication is successful and send it to the vehicle terminal, so that the vehicle terminal authorizes the vehicle user to call the privacy data unit based on the privacy data unit authorization instruction included in the third authentication result indicating that the three-level authentication is successful.

[0156] In an optional embodiment of the present invention, the secondary identity information includes a second voice command containing a one-time dynamic password. The second verification module 503 is further configured to: after the terminal application bound to the vehicle or the server provides the one-time dynamic password to the vehicle user, perform a countdown on the validity period of the one-time dynamic password; if the time for receiving the second voice command exceeds the countdown, generate a second verification result indicating that the secondary identity verification failed; if the time for receiving the second voice command does not exceed the countdown, verify the correctness of the one-time dynamic password and perform voiceprint verification on the voiceprint information of the second voice command; and if the correctness verification and the voiceprint verification pass, generate a second verification result indicating that the secondary identity verification passed.

[0157] In an optional embodiment of the present invention, the second verification module 503 is further configured to obtain the target password set by the vehicle owner from the terminal application bound to the vehicle or determine the target password generated by the server for the vehicle, compare the one-time dynamic password with the target password to verify the correctness of the one-time dynamic password; if the comparison result indicates that the one-time dynamic password and the target password are consistent, determine that the one-time dynamic password verification is successful; simultaneously, collect the voiceprint information carried by the second voice command, match the voiceprint information with the voiceprint data pre-stored in the shared user information database; if the matching result indicates that the voiceprint information matches any voiceprint data in the shared user information database, determine that the voiceprint verification is successful.

[0158] According to an embodiment of the present invention, a vehicle use device configured on a server based on multi-level authentication performs first-level authentication on the vehicle user after receiving first-level identity information sent by the vehicle terminal. If the first-level authentication is successful, a first authentication result containing a door unlocking command is sent to the vehicle terminal indicating that the first-level authentication has been successful. After receiving second-level identity information sent by the vehicle terminal, the device performs second-level authentication on the vehicle user. If the second-level authentication is successful, a second authentication result containing a vehicle start command is sent to the vehicle terminal indicating that the second-level authentication has been successful. Thus, when the vehicle user wants to use the vehicle, multi-level authentication is performed on the vehicle user to determine whether the vehicle user has the right to use the vehicle. This avoids the problem that a single authentication method cannot effectively prevent others without the right to use the vehicle from stealing it, improves the vehicle security level, and reduces the possibility of the vehicle being stolen or misused.

[0159] In addition, during the secondary identity verification process for vehicle users, one-time dynamic passwords are verified. Based on the one-time nature and time-limited validity of one-time dynamic passwords, vehicle property losses caused by the theft of one-time dynamic passwords can be further avoided, thereby improving the security of vehicle use.

[0160] Figure 6 An exemplary system architecture 600 is shown that can be applied to a vehicle use method or device based on multi-level verification according to embodiments of the present invention.

[0161] like Figure 6 As shown, system architecture 600 may include vehicle terminals 601, 602, and 603, network 604, and server 605. Network 604 serves as the medium for providing a communication link between vehicle terminals 601, 602, and 603 and server 605. Network 604 may include various connection types, such as wired or wireless communication links or fiber optic cables, etc.

[0162] Vehicle-mounted devices 601, 602, and 603 interact with server 605 via network 604 to receive or send data. Vehicle-mounted devices 601, 602, and 603 can be configured with sensors to collect the vehicle user's identity information, such as image sensors, fingerprint sensors, and / or iris sensors.

[0163] Server 605 can be a server that provides various services, such as a backend management server that supports the primary and secondary identity information sent by vehicle terminals 601, 602, and 603. The backend management server can perform verification and other processing on the acquired primary and secondary identity information and feed back the processing results (such as the first verification result and the second verification result) to the vehicle terminal.

[0164] It should be noted that the vehicle use method based on multi-level verification provided in the embodiments of the present invention can be a method executed by vehicle terminals 601, 602, and 603 and / or a method executed by server terminal 605. Correspondingly, the vehicle use device based on multi-level verification can be a device disposed in vehicle terminals 601, 602, and 603 and / or a device disposed in server terminal 605.

[0165] It should be understood that Figure 6 The number of vehicle terminals, network terminals, and server terminals shown is merely illustrative. Depending on implementation needs, any number of vehicle terminals, network terminals, and server terminals can be included.

[0166] The following is for reference. Figure 7 It shows a schematic diagram of the structure of a computer system 700 suitable for implementing embodiments of the present invention, either on the vehicle side or the server side. Figure 7The vehicle or server shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of the present invention.

[0167] like Figure 7 As shown, the computer system 700 includes a central processing unit (CPU) 701, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 702 or programs loaded from storage section 708 into random access memory (RAM) 703. The RAM 703 also stores various programs and data required for the operation of the computer system 700. The CPU 701, ROM 702, and RAM 703 are interconnected via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.

[0168] The following components are connected to the I / O interface 705: an input section 706 including a keyboard, mouse, etc.; an output section 707 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 708 including a hard disk, etc.; and a communication section 709 including a network interface card such as a LAN card, modem, etc. The communication section 709 performs communication processing via a network such as the Internet. A drive 710 is also connected to the I / O interface 705 as needed. A removable medium 711, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 710 as needed so that computer programs read from it can be installed into the storage section 708 as needed.

[0169] In particular, according to the embodiments disclosed in this invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this invention include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 709, and / or installed from removable medium 711. When the computer program is executed by central processing unit (CPU) 701, it performs the functions defined above in the system of this invention.

[0170] It should be noted that the computer-readable medium shown in this invention can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this invention, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0171] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0172] The modules described in the embodiments of the present invention can be implemented in software or hardware. The described modules can also be located in a processor. For example, when the processor is located in a vehicle, it can be described as follows: a processor includes a first acquisition module, a second acquisition module, a sending module, and a startup module. The names of these modules do not necessarily limit the module itself. For example, the first acquisition module can also be described as "a module that, in response to receiving a door opening request sent by a vehicle user, acquires the vehicle user's primary identity information and sends the primary identity information to the server for primary identity verification." As another example, when the processor is located on the server, it can be described as follows: a processor includes a first verification module, a first generation module, a second verification module, and a second generation module.

[0173] In another aspect, the present invention also provides a computer-readable medium, which may be included in the device described in the above embodiments; or it may exist independently and not assembled into the device. The computer-readable medium carries one or more programs that, when executed by the device, cause the device to: in response to receiving a door opening request from a vehicle user, collect primary identity information of the vehicle user and send the primary identity information to a server for primary identity verification; upon receiving a first verification result from the server indicating that primary identity verification has passed, unlock the door; and upon receiving a vehicle start request from the vehicle user, collect secondary identity information of the vehicle user; send the secondary identity information to the server for secondary identity verification; the secondary identity verification includes one-time dynamic password verification; and upon receiving a second verification result from the server indicating that secondary identity verification has passed, start the vehicle. Alternatively, the aforementioned computer-readable medium carries one or more programs that, when executed by a device, cause the device to include: receiving primary identity information of a vehicle user sent by a vehicle terminal, and performing primary identity verification on the vehicle user based on the primary identity information; if the primary identity verification is successful, generating a first verification result indicating successful primary identity verification and sending it to the vehicle terminal, so that the vehicle terminal unlocks the vehicle door based on a door unlocking command included in the first verification result indicating successful primary identity verification; receiving secondary identity information of the vehicle user sent by the vehicle, and performing secondary identity verification on the vehicle user based on the secondary identity information; the secondary identity verification includes one-time dynamic password verification; if the secondary identity verification is successful, generating a second verification result indicating successful secondary identity verification and sending it to the vehicle terminal, so that the vehicle terminal starts the vehicle based on a vehicle start command included in the second verification result indicating successful secondary identity verification.

[0174] According to the technical solution of the present invention, when a vehicle user sends a request to open the car door, the system collects the vehicle user's primary identity information and determines whether to unlock the car door based on the first verification result of the primary identity information. When a vehicle user sends a request to start the vehicle, the system collects the vehicle user's secondary identity information and determines whether to start the vehicle based on the second verification result of the secondary identity information. This multi-level identity verification is performed on the vehicle user when they want to use the vehicle to determine whether the vehicle user has the right to use the vehicle. This avoids the problem that a single verification method cannot effectively prevent others without the right to use the vehicle from stealing it, thus improving the vehicle security level and reducing the possibility of the vehicle being stolen or misused.

[0175] In addition, during the secondary identity verification process for vehicle users, one-time dynamic passwords are verified. Based on the one-time nature of one-time dynamic passwords, property losses caused by the theft of one-time dynamic passwords can be further avoided, thereby improving the security of vehicle use and effectively protecting the property security of vehicle owners.

[0176] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A vehicle usage method based on multi-level verification, applied to the vehicle end, characterized in that, include: In response to receiving a door opening request from the vehicle user, the system collects the vehicle user's primary identity information and sends the primary identity information to the server for primary identity verification. Upon receiving the first verification result indicating that the first-level identity verification has passed from the server, the car door is unlocked, and upon receiving a vehicle start request from the vehicle user, the second-level identity information of the vehicle user is collected. The secondary identity information is sent to the server so that the server can perform secondary identity verification. The secondary authentication includes one-time dynamic password verification; Upon receiving a second verification result from the server indicating that the second-level authentication has passed, the vehicle is started.

2. The vehicle usage method based on multi-level verification according to claim 1, characterized in that, The method further includes: during the vehicle user's use of the vehicle, in response to receiving a request from the vehicle user to call the privacy data unit, collecting the vehicle user's three-level identity information; sending the three-level identity information to the server to enable the server to perform three-level authentication; and, upon receiving a third verification result from the server indicating that the three-level authentication has passed, unlocking the privacy data unit for the vehicle user to call. And / or, The collection of the vehicle user's primary identity information includes: collecting the vehicle user's fingerprint information and a first voice command; And / or, The collection of the vehicle user's secondary identity information includes: collecting a second voice command issued by the vehicle user containing a one-time dynamic password, wherein the one-time dynamic password originates from the terminal application or server bound to the vehicle.

3. The vehicle usage method based on multi-level verification according to claim 2, characterized in that, In response to receiving a request from the vehicle user to access the privacy data unit, the collection of the vehicle user's three-level identity information includes: Collect the iris information and third voice commands of the vehicle user.

4. A vehicle usage method based on multi-level verification, applied to the server side, characterized in that, include: Receive the vehicle user's primary identity information sent by the vehicle terminal, and perform primary identity verification on the vehicle user based on the primary identity information; If the Level 1 authentication is successful, a first authentication result indicating that the Level 1 authentication has been successful is generated and sent to the vehicle terminal, so that the vehicle terminal can unlock the door based on the door unlocking command included in the first authentication result indicating that the Level 1 authentication has been successful. Receive the secondary identity information of the vehicle user sent by the vehicle, and perform secondary identity verification on the vehicle user based on the secondary identity information; The secondary authentication includes one-time dynamic password verification; If the secondary authentication is successful, a second authentication result indicating that the secondary authentication was successful is generated and sent to the vehicle terminal, so that the vehicle terminal can start the vehicle based on the vehicle start command included in the second authentication result indicating that the secondary authentication was successful.

5. The vehicle usage method based on multi-level verification according to claim 4, characterized in that, The method further includes: A shared user information database containing fingerprint, iris, and voiceprint data of shared users is pre-built; Based on the shared user information database, the vehicle users are respectively subjected to first-level authentication and second-level authentication.

6. The vehicle usage method based on multi-level verification according to claim 4, characterized in that, The method further includes: Receive the vehicle user's three-level identity information sent by the vehicle, and perform three-level identity verification on the vehicle user based on the three-level identity information; If the Level 3 authentication is successful, a third authentication result indicating that the Level 3 authentication has been successful is generated and sent to the vehicle terminal, so that the vehicle terminal can authorize the vehicle user to call the privacy data unit based on the privacy data unit authorization instruction included in the third authentication result indicating that the Level 3 authentication has been successful.

7. The vehicle usage method based on multi-level verification according to claim 5, characterized in that, The secondary identity information includes a second voice command containing a one-time dynamic password; The step of performing secondary identity verification on the vehicle user based on the secondary identity information includes: After the terminal application bound to the vehicle or the server provides the one-time dynamic password to the vehicle user, a countdown timer is set for the validity period of the one-time dynamic password. If the time it takes to receive the second voice command exceeds the countdown timer, a second verification result indicating that the second-level authentication failed is generated; If the time of receiving the second voice command does not exceed the countdown of the effective time, the correctness of the one-time dynamic password and the voiceprint information of the second voice command are verified. If the correctness verification and the voiceprint verification pass, a second verification result indicating that the secondary authentication has passed is generated.

8. The vehicle usage method based on multi-level verification according to claim 7, characterized in that, The verification of the correctness of the one-time dynamic password and the verification of the voiceprint information of the second voice command include: The system obtains the target password set by the vehicle owner from the terminal application bound to the vehicle or determines the target password generated by the server for the vehicle. It then compares the one-time dynamic password with the target password to verify the correctness of the one-time dynamic password. If the comparison result indicates that the one-time dynamic password and the target password are consistent, it is determined that the one-time dynamic password verification is successful; Simultaneously, the voiceprint information carried by the second voice command is collected, and the voiceprint information is matched with the voiceprint data pre-stored in the shared user information database; If the matching result indicates that the voiceprint information matches any voiceprint data in the shared user information database, the voiceprint verification is deemed successful.

9. A vehicle-use device based on multi-level verification, configured at the vehicle end, characterized in that, include: The first acquisition module is used to respond to a door opening request sent by the vehicle user, acquire the first-level identity information of the vehicle user, and send the first-level identity information to the server so that the server can perform first-level identity verification. The second acquisition module is used to unlock the car door when it receives a first verification result indicating that the first-level identity verification has passed from the server, and to acquire the second-level identity information of the vehicle user when it receives a vehicle start request sent by the vehicle user. The sending module is used to send the secondary identity information to the server so that the server can perform secondary identity verification; The secondary authentication includes one-time dynamic password verification; The startup module is used to start the vehicle upon receiving a second verification result from the server indicating that the second-level authentication has been successful.

10. A vehicle usage device based on multi-level verification, configured on a server, characterized in that, include: The first verification module is used to receive the vehicle user's first-level identity information sent by the vehicle terminal, and to perform first-level identity verification on the vehicle user based on the first-level identity information. The first generation module is used to generate a first verification result indicating that the first-level authentication has been passed and send it to the vehicle terminal when the first-level authentication has been passed, so that the vehicle terminal can unlock the door based on the door unlocking command included in the first verification result indicating that the first-level authentication has been passed. The second verification module is used to receive the secondary identity information of the vehicle user sent by the vehicle, and to perform secondary identity verification on the vehicle user based on the secondary identity information; The secondary authentication includes one-time dynamic password verification; The second generation module is used to generate a second verification result indicating that the second-level authentication has been passed when the second-level authentication has been passed, and send it to the vehicle terminal so that the vehicle terminal can start the vehicle based on the vehicle start command included in the second verification result indicating that the second-level authentication has been passed.