Vehicle and encryption authentication method thereof

By sending encrypted authentication commands to the vehicle and performing secondary encryption verification, the security risks of NFC keys are resolved, achieving a balance between vehicle anti-theft functionality and user convenience.

CN121509994APending Publication Date: 2026-02-10CHERY NEW ENERGY AUTOMOBILE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511600953.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-04
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

While NFC keys enhance user convenience, they also introduce information security risks such as unauthorized relay attacks, data theft, and identity spoofing, necessitating the development of a communication solution that balances high security with a superior user experience.

Method used

When the digital key is valid, an encrypted authentication command is sent, an authentication response message is generated through the near-field communication module, and a second verification is performed based on a preset encryption algorithm to ensure that the vehicle is started only after the digital key authentication is successful, thus realizing the vehicle anti-theft function.

Benefits of technology

By using secondary encryption verification, the system prohibits unauthorized digital key activation, thus enabling vehicle anti-theft functionality. Furthermore, the authentication process is invisible to the user, enhancing both security and convenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121509994A_ABST
    Figure CN121509994A_ABST
Patent Text Reader

Abstract

The invention discloses a vehicle and an encryption authentication method thereof. The method comprises the following steps: under the condition of determining that a digital key is valid, sending an encryption authentication instruction, so that a near field communication module of the digital key receives the encryption authentication instruction and generates an authentication response message according to the encryption authentication instruction; receiving an authentication response message, and under the condition that the authentication response message comprises the first random plaintext data and the first reference encrypted data, performing encryption processing on the first random plaintext data based on a preset encryption algorithm to determine first target encrypted data; and under the condition that the first target encrypted data is consistent with the first reference encrypted data, it is determined that digital key authentication succeeds, and under the condition that digital key authentication succeeds, the vehicle is controlled to be started. Thus, the starting operation of the digital key function without legal authentication is forbidden through secondary verification, the vehicle anti-theft function is achieved, user participation is not needed in the whole anti-theft authentication process, and the authentication process is invisible to a user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle technology, and more particularly to an encrypted authentication method for a vehicle and a vehicle. Background Technology

[0002] With the continuous improvement of automotive intelligence, the installation rate of digital key functions such as "keyless entry" and "remote start" in newly launched models has shown a significant upward trend. Among various digital key forms, NFC (Near Field Communication) keys, due to their card-like design, flexible and diverse shapes, and ease of use, exhibit unique advantages and are gradually becoming an important supplement to traditional remote control keys and Bluetooth keys. However, while NFC card keys enhance user convenience, they also introduce new information security challenges, such as risks of unauthorized relay attacks, data theft, and identity spoofing. Therefore, in promoting the development of convenient vehicle start technology, it is urgent to build a communication solution that balances high security and user experience to ensure the reliability and security of digital key systems in increasingly complex application environments. Summary of the Invention

[0003] This application aims to at least partially address one of the technical problems in related technologies. To this end, the first objective of this application is to propose an encrypted authentication method for a vehicle, applied to a vehicle body control module. The method includes: upon determining that the digital key is valid, sending an encrypted authentication command so that the near-field communication module of the digital key receives the encrypted authentication command and generates an authentication response message based on the encrypted authentication command; receiving the authentication response message, and if the authentication response message includes first random plaintext data and first reference encrypted data, encrypting the first random plaintext data based on a preset encryption algorithm to determine first target encrypted data; if the first target encrypted data matches the first reference encrypted data, determining that the digital key authentication is successful, and controlling the vehicle to start upon successful digital key authentication. This application first determines that the authentication response message includes first random plaintext data and first reference encrypted data, then locally encrypts the received first random plaintext data based on a preset encryption algorithm to generate first target encrypted data, and performs consistency matching between this first target encrypted data and the original first reference encrypted data in the authentication message to authenticate the digital key. In this way, by performing secondary verification, the digital key function is prohibited from being activated without proper authentication, thereby achieving vehicle anti-theft function. Furthermore, the entire anti-theft authentication process does not require user participation and is invisible to the user.

[0004] The second objective of this application is to propose an encrypted authentication method for vehicles.

[0005] The third objective of this application is to propose a vehicle.

[0006] To achieve the above objectives, a first aspect of this application proposes an encrypted authentication method for a vehicle, applied to a vehicle body control module. The method includes: when a digital key is determined to be valid, sending an encrypted authentication command so that the near-field communication module of the digital key receives the encrypted authentication command and generates an authentication response message based on the encrypted authentication command; receiving the authentication response message, and when the authentication response message includes first random plaintext data and first reference encrypted data, encrypting the first random plaintext data based on a preset encryption algorithm to determine first target encrypted data; when the first target encrypted data is consistent with the first reference encrypted data, determining that the digital key authentication is successful, and controlling the vehicle to start when the digital key authentication is successful.

[0007] According to one embodiment of this application, the method further includes: determining that digital key authentication has failed when the authentication response message is a preset authentication response message.

[0008] According to one embodiment of this application, the method further includes: determining that digital key authentication has failed if the first target encrypted data is inconsistent with the first reference encrypted data.

[0009] According to one embodiment of this application, after sending the encryption authentication command, the method further includes: if no authentication response message is received within a first preset time period, resending the encryption authentication command multiple times based on a preset time interval; if no authentication response message is received within a second preset time period, then determining that the digital key authentication has failed.

[0010] According to one embodiment of this application, the encryption authentication instruction includes second random plaintext data and second reference encrypted data. The method further includes generating the second random plaintext data based on a preset random number generation algorithm; encrypting the second random plaintext data based on a preset encryption algorithm to determine the second reference encrypted data; and generating the encryption authentication instruction based on the second random plaintext data and the second reference encrypted data.

[0011] According to one embodiment of this application, determining that a digital key is valid includes: within a preset time window after the vehicle anti-theft status is successfully deactivated by the digital key outside the vehicle, or when a digital key signal is detected inside the vehicle, determining that the digital key is valid.

[0012] According to one embodiment of this application, the method further includes: determining that the vehicle control module is in a released state when the digital key authentication is successful; and determining that the vehicle control module is in an anti-theft state when the digital key authentication fails.

[0013] To achieve the above objectives, a second aspect of this application proposes an encrypted authentication method for a vehicle, applied to a near-field communication module of a digital key. The method includes: receiving an encrypted authentication command, wherein the encrypted authentication command is sent by a vehicle control module; determining second random plaintext data and second reference encrypted data based on the encrypted authentication command; encrypting the second random plaintext data based on a preset encryption algorithm to determine second target encrypted data; and, if the second target encrypted data matches the second reference encrypted data, sending an authentication response message to the vehicle control module, wherein the authentication response message includes first random plaintext data and first reference encrypted data.

[0014] According to one embodiment of this application, the method further includes: sending an authentication response message when the second target encrypted data is inconsistent with the second reference encrypted data, wherein the authentication response message is a preset authentication response message.

[0015] To achieve the above objectives, a third aspect of this application provides a vehicle, including a memory, a processor, and a vehicle encryption and authentication program stored in the memory and executable on the processor. When the processor executes the vehicle encryption and authentication program, it implements the aforementioned vehicle encryption and authentication method.

[0016] According to the vehicle and its encryption authentication method in this application, when the digital key is determined to be valid, an encryption authentication command is sent so that the near-field communication module of the digital key can receive the encryption authentication command and generate an authentication response message according to the encryption authentication command; upon receiving the authentication response message, if the authentication response message includes first random plaintext data and first reference encrypted data, the first random plaintext data is encrypted based on a preset encryption algorithm to determine first target encrypted data; if the first target encrypted data is consistent with the first reference encrypted data, the digital key authentication is determined to be successful, and the vehicle is started upon successful digital key authentication. This application first determines that the authentication response message includes first random plaintext data and first reference encrypted data, then locally encrypts the received first random plaintext data based on a preset encryption algorithm to generate first target encrypted data, and performs consistency matching with the original first reference encrypted data in the authentication message to authenticate the digital key. Thus, by performing secondary verification, the digital key function is prohibited from starting without proper authentication, thereby achieving vehicle anti-theft functionality. Furthermore, the entire anti-theft authentication process does not require user participation and is invisible to the user. Attached Figure Description

[0017] Figure 1 Here is a flowchart of an encrypted authentication method for a vehicle according to some embodiments of this application; Figure 2Here is a flowchart of an encrypted authentication method for a vehicle according to other embodiments of this application; Figure 3 This is a schematic diagram illustrating the interaction process between the vehicle control module and the near-field communication module of the digital key according to some embodiments of this application; Figure 4 This is a block diagram of a vehicle according to some embodiments of this application. Detailed Implementation

[0018] The embodiments of this application are described in detail below. Examples of these embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain this application, and should not be construed as limiting this application.

[0019] The vehicle and its encryption authentication method according to embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0020] Figure 1 This is a flowchart of an encrypted authentication method for a vehicle according to some embodiments of this application. (Refer to...) Figure 1 The vehicle encryption authentication method in this application embodiment may include the following steps: S110, if the digital key is confirmed to be valid, sends an encryption authentication command so that the near-field communication module of the digital key can receive the encryption authentication command and generate an authentication response message based on the encryption authentication command.

[0021] Specifically, when the vehicle control module has completed initialization and there is a startup requirement, the system determines whether the digital key is valid. For example, if the digital key is recognized when it is in direct contact with the external card reader or is very close to the external card reader, the digital key is determined to be valid; if the digital key is far from the external card reader and is not recognized, the digital key is determined to be invalid.

[0022] Once the digital key is confirmed to be valid, the body control module sends an encrypted authentication command to the digital key. After receiving the encrypted authentication command, the near-field communication module of the digital key generates an authentication response message based on the encrypted authentication command and sends the authentication response message back to the body control module.

[0023] S120, receive an authentication response message, and if the authentication response message includes first random plaintext data and first reference encrypted data, encrypt the first random plaintext data based on a preset encryption algorithm to determine the first target encrypted data.

[0024] Specifically, after receiving the authentication response message, the body control module parses the message to determine the first random plaintext data and the first reference encrypted data. The first random plaintext data can be 4 bytes, and the first reference encrypted data can also be 4 bytes. Then, the body control module encrypts the first random plaintext data using a preset encryption algorithm, such as AES (Advanced Encryption Standard) 128 encryption algorithm, to determine the first target encrypted data. It should be noted that after encrypting the first random plaintext data using the preset encryption algorithm, the body control module obtains 16 bytes of encrypted data; the first 4 bytes can be used as the first target encrypted data.

[0025] S130, if the first target encrypted data is consistent with the first reference encrypted data, determine that the digital key authentication is successful, and control the vehicle to start if the digital key authentication is successful.

[0026] Specifically, after determining the first target encrypted data, the vehicle control module matches the first target encrypted data with the first reference encrypted data. If the two match successfully, the digital key authentication is confirmed to be successful. If the digital key authentication is successful, the vehicle is controlled to start, for example, with one-button start.

[0027] One-button start occurs when the Body Control Module (BCM) receives a VCU_START_AuthenticationReq (portable start authentication request) = 1 from the Vehicle Control Unit (VCU). This indicates the BCM detects a valid 0-to-1 rising transition of the signal and finds a valid digital key inside the vehicle within 2 seconds. The BCM then sends a power level signal (ID: 0x245) = Start, and a 5-second timer is set. If the BCM receives a VCU_PowertrainReadySts = 1 signal within 5 seconds (indicating the powertrain is ready) or the timer ends, the power level signal is set to 2. All signals are CAN communication signals, and the BCM and NFC authenticate via the CAN network.

[0028] This application first determines that the authentication response message includes first random plaintext data and first reference encrypted data. Then, based on a preset encryption algorithm, it locally encrypts the received first random plaintext data to generate first target encrypted data. This target encrypted data is then matched with the original first reference encrypted data in the authentication message to authenticate the digital key. In this way, through secondary verification, the digital key function is prevented from starting without proper authentication, thereby achieving vehicle anti-theft functionality. Furthermore, the entire anti-theft authentication process requires no user intervention and is invisible to the user.

[0029] In some embodiments, the method further includes: determining that digital key authentication has failed if the authentication response message is a preset authentication response message. The preset authentication response message can be 0xFF.

[0030] Specifically, the authentication response message can be either first random plaintext data and first reference encrypted data, or a preset authentication response message. If the authentication response message received by the body control module contains first random plaintext data and first reference encrypted data, the first random plaintext data is encrypted using a preset encryption algorithm to determine the first target encrypted data, and the digital key authentication is determined to be successful based on the first target encrypted data and the first reference encrypted data. If the authentication response message received by the body control module is a preset authentication response message, the digital key authentication is directly determined to have failed.

[0031] In some embodiments, the method further includes: determining that digital key authentication has failed if the first target encrypted data is inconsistent with the first reference encrypted data.

[0032] Specifically, when the authentication response message received by the vehicle control module contains first random plaintext data and first reference encrypted data, the first random plaintext data is encrypted based on a preset encryption algorithm to determine the first target encrypted data. If the first target encrypted data is inconsistent with the first reference encrypted data, the digital key authentication is determined to have failed.

[0033] In some embodiments, after sending the encryption authentication command, the method further includes: if no authentication response message is received within a first preset time period, resending the encryption authentication command multiple times based on a preset time interval; if no authentication response message is received within a second preset time period, then determining that the digital key authentication has failed. The first preset time, the preset time interval, and the second preset time can be determined according to actual conditions; for example, the first preset time and the second preset time can be 2 seconds, and the preset time interval can be 150 ms. No specific limitations are imposed here.

[0034] Specifically, after the vehicle control module sends an encrypted authentication command to the near-field communication module of the digital key, if no authentication response message is received within a first preset time period, the vehicle control module will send the same encrypted authentication command to the near-field communication module of the digital key at preset time intervals within a second preset time period. If no authentication response message is received within the second preset time period, the digital key authentication is determined to have failed. If an authentication response message is received within the second preset time period, and the authentication response message includes first random plaintext data and first reference encrypted data, the first random plaintext data is encrypted based on a preset encryption algorithm to determine the first target encrypted data. The digital key authentication is then determined based on the first target encrypted data and the first reference encrypted data.

[0035] In some embodiments, the encryption authentication instruction includes second random plaintext data and second reference encrypted data. The method further includes: generating second random plaintext data based on a preset random number generation algorithm; encrypting the second random plaintext data based on a preset encryption algorithm to determine second reference encrypted data; and generating an encryption authentication instruction based on the second random plaintext data and the second reference encrypted data.

[0036] Specifically, when the vehicle control module generates an encrypted authentication command, it first generates first random plaintext data based on a preset random number generation algorithm, such as HMAC-DRBG; then, it encrypts the second random plaintext data based on a preset encryption algorithm to determine the second reference encrypted data; finally, the vehicle control module assembles the second random plaintext data and the second reference encrypted data into a complete data packet according to a predefined communication protocol format, which is the encrypted authentication command.

[0037] In some embodiments, determining that the digital key is valid includes: within a preset time window after the vehicle's anti-theft status is successfully deactivated by the digital key outside the vehicle, or when a digital key signal is detected inside the vehicle. The preset time window can be set according to actual conditions; for example, it could be 3 minutes, but this is not specifically limited here.

[0038] Specifically, in external scenarios, when a user successfully uses the digital key to disable the vehicle's anti-theft system (such as unlocking the car door), the vehicle will initiate a preset time window. During this window, it is assumed that the user intends to enter and start the vehicle, thus maintaining the key's valid state and achieving a seamless transition from unlocking to starting. In internal scenarios, the vehicle uses low-frequency antennas or Bluetooth sensors located inside the vehicle to detect the digital key signal in real time. Once a legitimate key is detected in the cockpit, the vehicle immediately determines that the key is valid and prepares to respond to the start command.

[0039] In this way, the entire process of user access from outside the vehicle to inside the vehicle is covered, which not only avoids the cumbersome operation caused by frequent repeated authentication, but also ensures the safety boundary through accurate judgment of spatial position, and ultimately significantly improves the user's car use convenience experience while ensuring safety.

[0040] In some embodiments, the method further includes: determining that the vehicle control module is in a released state if the digital key authentication is successful; and determining that the vehicle control module is in an anti-theft state if the digital key authentication fails.

[0041] Specifically, if digital key authentication is successful, the user is deemed a legitimate authorized user, and the vehicle control module immediately switches to the released state. In this state, critical vehicle functions (such as the starter motor, fuel pump, and ignition system) are unlocked, allowing the user to start and drive the vehicle normally, thus achieving a seamless transition from identity verification to function authorization. Conversely, if digital key authentication fails, it is determined to be an unauthorized access or operation attempt, and the vehicle control module will maintain or immediately switch to anti-theft mode. In this state, the vehicle will refuse to execute start commands and may trigger active protection mechanisms such as alarm systems.

[0042] Figure 2 This is a flowchart of an encrypted authentication method for a vehicle according to some embodiments of this application. (Refer to...) Figure 2 The vehicle encryption authentication method in this application embodiment may include the following steps: S210 receives encryption authentication commands, which are sent by the vehicle body control module.

[0043] S220, determine the second random plaintext data and the second reference encrypted data according to the encryption authentication instruction.

[0044] S230, the second random plaintext data is encrypted based on a preset encryption algorithm to determine the second target encrypted data.

[0045] S240, if the second target encrypted data is consistent with the second reference encrypted data, an authentication response message is sent to the vehicle body control module, wherein the authentication response message includes the first random plaintext data and the first reference encrypted data.

[0046] Specifically, after receiving the encryption authentication command, the near-field communication module of the digital key parses the encryption authentication command to determine the second random plaintext data and the second reference encrypted data. Then, the near-field communication module of the digital key encrypts the second random plaintext data based on a preset encryption algorithm to determine the second target encrypted data, and determines the content of the authentication response message to be sent to the body control module based on the second target encrypted data and the second reference encrypted data. For example, if the second target encrypted data and the second reference encrypted data are consistent, the authentication response message sent to the body control module includes the first random plaintext data and the first reference encrypted data.

[0047] The near-field communication module of the digital key generates first random plaintext data based on a preset random number generation algorithm, and encrypts the first random plaintext data based on a preset encryption algorithm to determine the first reference encrypted data.

[0048] In some embodiments, the method further includes: sending an authentication response message when the second target encrypted data is inconsistent with the second reference encrypted data, wherein the authentication response message is a preset authentication response message.

[0049] Specifically, when the second target encrypted data is inconsistent with the second reference encrypted data, the authentication response message sent to the body control module includes a preset authentication response message.

[0050] As a concrete example, refer to Figure 3 The interaction process between the vehicle control module and the near-field communication module of the digital key is as follows: Step 1: NFC initialization complete, waiting for BCM to send encryption authentication command (Challenge message); Step 2: After BCM initialization is complete and a startup requirement is triggered, and provided the digital key is valid, NFC authentication begins. An encrypted authentication command is sent. If no authentication response message is received from the NFC, the BCM sends the same encrypted authentication command every 150ms for 2 seconds. If no authentication response message is received from the NFC after 2 seconds, the authentication fails. The encrypted authentication command contains second random plaintext data (4 bytes) and second reference encrypted data (4 bytes). The second random plaintext data is encrypted using the AES128 encryption algorithm to produce 16 bytes. The second reference encrypted data sent by the BCM to the CAN bus consists of the first 4 bytes.

[0051] Step 3: After receiving the encryption authentication command, the NFC module performs encryption operation on the received second random plaintext data to obtain the second target encrypted data. The first 4 bytes are taken and compared with the second reference encrypted data. If the data are consistent, the authentication response message sent by the NFC includes the first random plaintext data (4 bytes) and the first reference encrypted data (4 bytes). If the data are inconsistent, the authentication response message sent by the NFC includes 0xFF, and the authentication fails.

[0052] Step 4: After receiving the authentication response message, the BCM decodes the authentication response message, that is, it calculates the first target encrypted data based on the first random plaintext data, takes the first 4 bytes, and compares them with the first reference encrypted data. If the comparison is consistent, the two-way authentication is successful; otherwise, the two-way authentication fails.

[0053] Corresponding to the above embodiments, this application also proposes a vehicle.

[0054] See Figure 4 As shown, the vehicle 300 of this application includes a memory 310, a processor 320, and a vehicle encryption and authentication program stored in the memory 310 and executable on the processor 320. When the processor executes the vehicle encryption and authentication program, it implements the aforementioned vehicle encryption and authentication method.

[0055] It should be noted that the above-described embodiments and explanations of the beneficial effects of the vehicle encryption authentication method also apply to the vehicles in the embodiments of this application. To avoid redundancy, they will not be elaborated in detail here.

[0056] It should be noted that the logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection having one or more wires (electronic device), a portable computer disk drive (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Alternatively, the computer-readable medium may be paper or other suitable media on which the program can be printed, since the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in a computer memory.

[0057] It should be understood that various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0058] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0059] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0060] In this application, unless otherwise expressly specified and limited, the terms "installation," "connection," "joining," and "fixing," etc., should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components, unless otherwise expressly limited. Those skilled in the art can understand the specific meaning of the above terms in this application according to the specific circumstances.

[0061] Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of this application.

Claims

1. A method for encrypted authentication of vehicles, characterized in that, Applied to a body control module, the method includes: If the digital key is found to be valid, an encryption authentication command is sent so that the near-field communication module of the digital key can receive the encryption authentication command and generate an authentication response message based on the encryption authentication command. Upon receiving the authentication response message, if the authentication response message includes first random plaintext data and first reference encrypted data, the first random plaintext data is encrypted based on a preset encryption algorithm to determine the first target encrypted data; If the first target encrypted data is consistent with the first reference encrypted data, the digital key authentication is determined to be successful, and the vehicle is controlled to start upon successful digital key authentication.

2. The vehicle encryption authentication method according to claim 1, characterized in that, The method further includes: If the authentication response message is a preset authentication response message, it is determined that the digital key authentication has failed.

3. The vehicle encryption authentication method according to claim 1 or 2, characterized in that, The method further includes: If the first target encrypted data is inconsistent with the first reference encrypted data, the digital key authentication is determined to have failed.

4. The vehicle encryption authentication method according to claim 1, characterized in that, After sending the encryption authentication command, the method further includes: If the authentication response message is not received within a first preset time period, the encryption authentication command is resent multiple times based on a preset time interval. If the authentication response message is still not received within a second preset time period, the digital key authentication is determined to have failed.

5. The vehicle encryption authentication method according to claim 1, characterized in that, The encryption authentication command includes second random plaintext data and second reference encrypted data; the method further includes: The second random plaintext data is generated based on a preset random number generation algorithm; The second random plaintext data is encrypted based on the preset encryption algorithm to determine the second reference encrypted data; The encryption authentication command is generated based on the second random plaintext data and the second reference encrypted data.

6. The vehicle encryption authentication method according to claim 1, characterized in that, To confirm the validity of a digital key, the following steps are required: Within a preset time window after the vehicle's anti-theft status is successfully deactivated via the digital key outside the vehicle, or when a digital key signal is detected inside the vehicle, the digital key is determined to be valid.

7. The vehicle encryption authentication method according to claim 1, characterized in that, The method further includes: If the digital key authentication is successful, the vehicle control module is determined to be in a released state. If the digital key authentication fails, the vehicle control module is determined to be in anti-theft mode.

8. A method for encrypting and authenticating vehicles, characterized in that, The method for a near-field communication module applied to a digital key includes: Receive an encryption authentication command, wherein the encryption authentication command is sent by the vehicle body control module; The second random plaintext data and the second reference encrypted data are determined according to the encryption authentication instruction; The second random plaintext data is encrypted based on a preset encryption algorithm to determine the second target encrypted data; If the second target encrypted data is consistent with the second reference encrypted data, an authentication response message is sent to the vehicle control module, wherein the authentication response message includes first random plaintext data and first reference encrypted data.

9. The vehicle encryption authentication method according to claim 8, characterized in that, The method further includes: If the second target encrypted data is inconsistent with the second reference encrypted data, an authentication response message is sent, wherein the authentication response message is a preset authentication response message.

10. A vehicle, characterized in that, The system includes a memory, a processor, and a vehicle encryption authentication program stored in the memory and executable on the processor. When the processor executes the vehicle encryption authentication program, it implements the vehicle encryption authentication method according to any one of claims 1-9.