Low-power-consumption radio frequency receiving method and device based on bidirectional authentication and medium

The low-power radio frequency receiving method with two-way authentication and periodic wake-up solves the problems of insufficient security and compatibility in the existing technology, realizes low-power and high-security communication, and supports battery power.

CN121842680AActive Publication Date: 2026-04-10ECARTECK
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-03-16
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Existing low-power radio frequency receiver solutions have shortcomings in terms of security and compatibility. One-way reception is vulnerable to capture and replay attacks, and cannot be powered independently by a battery.

Method used

A low-power radio frequency receiving method based on two-way authentication is adopted. The radio frequency signal is detected by periodic wake-up, and encryption calculation is performed by combining random numbers and preset keys to achieve two-way authentication handshake. It also supports one-way compatibility mode and reduces average power consumption.

Benefits of technology

It improves communication security and system functionality, ensures compatibility with traditional one-way remote controls, and significantly reduces the average power consumption of the receiver to the microampere level, supporting battery power.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121842680A_ABST
    Figure CN121842680A_ABST
Patent Text Reader

Abstract

The invention discloses a low-power-consumption radio frequency receiving method and device based on bidirectional authentication and a medium, and relates to the field of wireless communication. In the method, a low power consumption mode is switched to a working mode; if the wake-up challenge code conforming to the preset format is received within the first preset time, judging that the current communication is in a bidirectional authentication mode, and extracting a random number; if the wake-up challenge code conforming to the preset format is not received within the first preset time, judging that the current communication is in a one-way compatible mode; after the current communication is judged to be in the bidirectional authentication mode, generating a response code through encryption operation by using a preset key and a random number, and sending the response code to the transmitting end to complete bidirectional authentication handshake; after the bidirectional authentication handshake is completed or the current communication is judged to be in a one-way compatible mode, continuously receiving radio frequency signals within a second preset time to obtain a control instruction frame; and executing corresponding control operation according to the control instruction frame. By implementing the application, the security of radio frequency communication interaction is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of wireless communication, in particular to a low-power radio frequency receiving method and device based on bidirectional authentication and medium. BACKGROUND

[0002] With the rapid development of the automotive aftermarket, intelligent products such as remote start and mobile key are increasingly popular. These products, while implementing new features, often need to be compatible with the original 433MHz or 315MHz remote control to ensure user habits. In order to respond to instructions from the remote control at any time, the radio frequency receiving circuit of the vehicle receiving end in the existing conventional receiving scheme must remain in a continuous working state. This results in a static working current of 8-12mA, which cannot be powered independently by a battery, and must be directly connected to the vehicle battery, increasing the complexity and cost of installation, and also posing a risk of long-term power loss.

[0003] Currently, to solve the problem of high power consumption, the industry generally uses intermittent wake-up listening technology. This technology allows the receiving end to wake up briefly for a few milliseconds to listen to radio frequency signals at periodic intervals of hundreds of milliseconds, thereby significantly reducing the average power consumption to the level of hundreds of microamperes, making it possible to use dry batteries or button batteries for power supply. However, this low-power solution based on one-way reception has problems. In terms of security, since only fixed codes or traditional rolling code signals can be received in one direction, they are extremely vulnerable to capture and replay attacks, and are less secure. SUMMARY

[0004] The present application provides a low-power radio frequency receiving method and device based on bidirectional authentication, which improves the security of radio frequency communication interaction.

[0005] In a first aspect of the present application, a low-power radio frequency receiving method based on bidirectional authentication is provided. The method comprises: periodically waking up in a low-power mode and detecting radio frequency signals in a preset listening period, and switching from the low-power mode to a working mode when the radio frequency signals meet preset legitimacy requirements and the radio frequency signal strength exceeds a preset strength threshold; after entering the working mode, receiving a wake-up challenge code containing a random number within a first preset time; if a wake-up challenge code in a preset format is received within the first preset time, determining that the current communication is in a bidirectional authentication mode, and extracting the random number; if a wake-up challenge code in the preset format is not received within the first preset time, determining that the current communication is in a unidirectional compatible mode; after determining that the current communication is in the bidirectional authentication mode, generating a response code through an encryption operation using a preset key and the random number, and sending the response code to the transmitting end to complete bidirectional authentication handshake; after completing the bidirectional authentication handshake, or after determining that the current communication is in the unidirectional compatible mode, continuously receiving radio frequency signals within a second preset time to obtain a control instruction frame; performing a corresponding control operation according to the control instruction frame, and returning to the low-power mode after the control operation is completed.

[0006] By adopting the above technical solution, the low-power intermittent listening mode is adopted, the vehicle receiving end is in a deep sleep state most of the time, and is only woken up and detects radio frequency signals in a preset listening period, thereby effectively reducing the average power consumption of the receiving end. When the radio frequency signals meet the legitimacy requirements and the signal strength exceeds the threshold, the receiving end will only switch to the working mode to prepare to receive data. This avoids the receiving end from being frequently woken up by illegal signals, further saving power. After confirming the bidirectional authentication mode, the receiving end performs encryption operation using the preset key and the received random number to generate a response code and send it back to the transmitting end, completing bidirectional handshake authentication and improving communication security. In the unidirectional compatible mode, the receiving end can also adapt to traditional fixed code transmitters, ensuring good compatibility. Finally, according to the received control instruction frame, a corresponding control operation is performed, and the low-power mode is returned in time, reliably completing the remote control function while minimizing energy consumption. The present technical solution introduces a bidirectional authentication mechanism based on random numbers and preset keys, solves the problem of poor security of the unidirectional receiving scheme in the prior art, and significantly enhances the anti-replay attack capability; through bidirectional communication design, the state interaction function between the remote controller and the vehicle is realized, expanding the functionality of the system; through the dual-mode compatible mechanism, backward compatibility to traditional unidirectional remote controllers is ensured, and seamless upgrade to a safer bidirectional protocol is achieved; at the same time, through the periodic wake-up listening of the low-power mode, the average power consumption of the receiving end is greatly reduced to microamperes, supporting battery power supply. The scheme ensures low-power characteristics while realizing high security, richer functionality, and compatibility with traditional devices.

[0007] Optionally, the receiving the wake-up challenge code containing the random number within the first preset time comprises: starting a challenge code receiving timer, and demodulating and decoding the received radio frequency signal to obtain a decoded data frame; detecting whether the decoded data frame contains a preset challenge code frame header identifier; if it is determined that the decoded data frame contains the preset challenge code frame header identifier, parsing a payload field of the data frame, extracting the random number and a transmitter identifier from the payload field; performing frame check operation on the data frame, and if the check passes, determining that the wake-up challenge code conforming to the preset format is received, and temporarily storing the random number and the transmitter identifier to a receiving buffer area; if the challenge code receiving timer times out or the frame check fails, determining that the wake-up challenge code conforming to the preset format is not received.

[0008] By adopting the technical scheme, in the process of receiving the wake-up challenge code, the challenge code receiving timer is started to accurately control the receiving window, so that the radio frequency channel is not occupied for a long time by the receiving end, and communication of other nodes is not affected; the received radio frequency signal is demodulated and decoded, and the format characteristics of the decoded data frame are detected, so that illegal wake-up challenge codes are identified and filtered as early as possible, and unnecessary energy consumption is reduced; by parsing the payload field of the legal wake-up challenge code, the random number and the transmitter identifier can be accurately extracted, necessary key materials are provided for subsequent bidirectional authentication; finally, the challenge code frame is checked to further confirm the integrity and validity of the challenge code frame, so that the receiving end is not misled by incorrect or fake challenge codes, and the system robustness is improved. Meanwhile, the challenge code receiving timeout mechanism is introduced, so that the receiving end does not stay in the high-power working mode for a long time due to waiting for the challenge code.

[0009] Optionally, the executing the corresponding control operation according to the control instruction frame comprises: extracting a main instruction frame and an extended instruction frame from the control instruction frame, the main instruction frame is used to carry a main control instruction, the main control instruction comprises vehicle door unlocking and vehicle starting, the extended instruction frame is used to carry an auxiliary control instruction, the auxiliary control instruction comprises adjusting air conditioner temperature and opening a vehicle window; decoding the main instruction frame to obtain an operation type and an operation parameter of the main control instruction; determining an execution result of the main control instruction based on the operation type, and executing or rejecting to execute the main control instruction based on the execution result; determining an execution result of the extended instruction frame after executing or rejecting to execute the main control instruction, and executing or rejecting to execute the auxiliary control instruction based on the execution result.

[0010] By adopting the technical scheme, the main instruction frame and the extended instruction frame are extracted from the control instruction frame, and are respectively decoded and processed, so that flexible combination of multiple control functions can be realized on a single radio frequency channel, and communication efficiency and control flexibility are improved. Key control instructions such as vehicle door unlocking and vehicle starting are divided into main control instructions, and are carried by the main instruction frame, and are preferentially received and processed, so that the real-time response capability of the system to core control functions is improved. Auxiliary instructions such as air conditioner control and window control are divided into extended instructions, and are carried by the extended instruction frame, so that the types and quantities of the extended instructions can be dynamically adjusted according to actual needs without affecting the main control functions, and the control freedom is improved. Different control strategies are determined and executed for the main control instructions and the extended instructions respectively, so that conflicts and interference between instructions can be effectively avoided, and the safety and reliability of control are improved.

[0011] Optionally, the execution result of the main control instruction is determined based on the operation type, and specifically includes: judging whether the transmitting end has the permission to execute the main control instruction according to the operation type of the main control instruction; if the transmitting end has the permission to execute the main control instruction, it is determined to execute the main control instruction, and an execution result status code is generated; if the transmitting end does not have the permission to execute the main control instruction, it is determined to refuse to execute the main control instruction, and a permission exception status code is generated.

[0012] By adopting the technical scheme, the permission judgment mechanism based on the operation type of the instruction is introduced, and different transmitting ends are given the execution permission of different types of control instructions, so that illegal control of the vehicle by unauthorized transmitting ends can be effectively avoided, and the safety of the system is improved. By generating different instruction execution result status codes based on the permission judgment, and feeding back the status codes to the transmitting end in a timely manner, the transmitting end can master the execution of the instruction in real time, judge the current state of the vehicle, and provide a basis for subsequent man-machine interaction and control decision. At the same time, the permissionless instruction that is refused to be executed is recorded as an abnormal event, which can provide reliable data support for safety audit and fault diagnosis of the system. This fine-grained permission management and state feedback mechanism not only ensures the safety and controllability of the system, but also improves the transparency and diagnosability of the system, so that users and administrators can find and handle potential safety hazards in a timely manner.

[0013] Optionally, after the periodic wake-up in the low-power mode and the radio frequency signal detection, the method further comprises: preliminary demodulating the radio frequency signal to listen for a dynamic wake-up preamble; generating an expected preamble by a preset one-way hash function based on an authentication parameter used in a historical successful authentication interaction, the authentication parameter being a random number sent by a transmitting end or a response code generated by the vehicle receiving end in the historical successful authentication interaction; matching and comparing the dynamic wake-up preamble with the expected preamble; if the matching is successful, determining that the radio frequency signal meets the preset legitimacy requirement; if the matching fails or the dynamic wake-up preamble is not listened for, determining that the radio frequency signal is an invalid wake-up signal, and keeping the low-power mode.

[0014] By adopting the above technical solution, the dynamic wake-up preamble mechanism is introduced, which can effectively prevent the illegal transmitting end from miswaking up the receiving end by means of replay attacks and the like, and avoid the malicious consumption of the power of the receiving end. By preliminary demodulating the radio frequency signal after it is woken up and extracting the dynamic wake-up preamble possibly existing in the radio frequency signal, the legitimacy of the source of the radio frequency signal is preliminarily screened before entering the formal wake-up authentication process, which can greatly reduce the unnecessary energy consumption and time cost of the receiving end. The random number or the response code generated in the historical authentication process is used as a seed parameter, and a one-time dynamic expected preamble is generated by a one-way hash function, which can avoid the risk of the preamble being cracked due to long-term use. By strict preamble matching and comparison, an illegal wake-up signal that does not meet the expectation is identified, and the subsequent wake-up process is blocked in time, so that the receiving end is kept in the low-power mode, and the limited battery resources are maximally saved.

[0015] Optionally, after determining that the current communication is in the one-way compatible mode, the method further comprises: starting a compatible mode wake-up counter, and accumulating the compatible mode wake-up counter each time it is determined to be in the one-way compatible mode; determining whether a count value of the compatible mode wake-up counter reaches a preset count threshold; if the count value does not reach the count threshold, continuously receiving the radio frequency signal; if the count value reaches the count threshold, entering a temporary high-alert state for a preset lock time, and prohibiting the control operation to be performed and recording an abnormal event log in the temporary high-alert state; and if it is determined that the preset lock time ends, clearing the compatible mode wake-up counter and restoring a normal working process.

[0016] By adopting the technical solution, the wake-up characteristics of the receiving end in the one-way compatible mode are considered, and a compatible mode wake-up counter and a temporary high alert state mechanism are designed, which can effectively deal with potential wake-up attacks and improve the security and reliability of the receiving end. By accumulating the number of times the receiving end is woken up by the one-way mode, it is determined whether it exceeds a certain threshold, and suspicious high-frequency false wake-up behavior can be detected in time. Once the number of wake-ups is confirmed to be abnormal, the temporary high alert state is entered, and any wake-up signal is rejected for a period of time, and the execution of control instructions is prohibited, thereby isolating the receiving end from potential attackers and avoiding serious consequences such as vehicle out of control. The abnormal wake-up event is recorded in the log, which can assist users and system administrators in post-analysis and auditing, and provide data support for optimizing system configuration and improving defense strategies. After reaching the preset locking time, the system is automatically restored to the normal working state, avoiding long-term service interruption and affecting user experience.

[0017] Optionally, after continuously receiving the radio frequency signal for the second preset time to obtain the control instruction frame, the method further comprises: counting the number of actually received control instruction frames, and comparing the number of control instruction frames with a preset total number of instruction frames; if the number of control instruction frames is less than the preset total number of instruction frames, a retransmission request is sent to the transmitting end, and the retransmission request contains the serial number of the instruction frame that has not been received; if the new received instruction frame retransmitted by the transmitting end is received within a preset retransmission waiting time, the new received instruction frame is spliced with the original instruction frame sequence to obtain a spliced instruction frame, and the spliced instruction frame is taken as a new control instruction frame; if the number of instruction frames is still less than the expected total number of instruction frames after the number of retransmissions reaches a preset retransmission threshold, a receiving failure notification is sent to the transmitting end.

[0018] By adopting the above technical solution, the number of received control instruction frames is counted and compared, and the problem of missing instruction frames caused by channel interference, transmitting end failure, etc. can be found in time, so as to avoid the receiving end controlling based on incomplete instruction information and improve the control reliability. By actively sending a retransmission request to the transmitting end after confirming the missing instruction frame and explicitly informing the serial number of the missing frame, the blind retransmission of the transmitting end can be reduced, and the retransmission efficiency can be improved. By using the preset retransmission waiting time, the receiving end can avoid occupying the receiving buffer for a long time, which affects the reception of subsequent new instructions. By aligning and splicing the serial numbers of the new instruction frame obtained by retransmission and the original instruction frame, the complete and continuous instruction sequence can be seamlessly restored, and the consistency of control can be ensured. However, when the number of retransmissions exceeds a certain threshold, the complete instruction frame cannot be obtained, and the receiving failure notification is sent to the transmitting end in time, which can avoid unnecessary consumption of channel resources and trigger the transmitting end to take emergency measures to minimize the loss.

[0019] In a second aspect, the embodiments of the present application provide a low-power radio frequency receiving device based on bidirectional authentication, comprising one or more processors and a memory; the memory is coupled to the one or more processors, and the memory is configured to store computer program codes, the computer program codes comprising computer instructions, and the one or more processors are configured to invoke the computer instructions to enable the low-power radio frequency receiving device based on bidirectional authentication to perform the method described in the first aspect and any possible implementation manner of the first aspect.

[0020] In a third aspect, the embodiments of the present application provide a computer readable storage medium comprising instructions, which, when executed on a low-power radio frequency receiving device based on bidirectional authentication, enable the low-power radio frequency receiving device based on bidirectional authentication to perform the method described in the first aspect and any possible implementation manner of the first aspect.

[0021] In a fourth aspect, the embodiments of the present application provide a computer program product comprising instructions, which, when executed on a low-power radio frequency receiving device based on bidirectional authentication, enable the low-power radio frequency receiving device based on bidirectional authentication to perform the method described in the first aspect and any possible implementation manner of the first aspect.

[0022] To sum up, the one or more technical solutions provided by the present application have at least the following technical effects or advantages: 1. The technical solution introduces a bidirectional authentication mechanism in a low-power mode, generates a response code using a random number, a pre-set key, and an encryption operation, completes a challenge-response bidirectional authentication handshake, thereby effectively preventing replay attacks and illegal signal interference, and greatly improves the security of communication. At the same time, by matching and comparing the dynamic wake-up preamble with the historical authentication parameters, the accuracy of signal legality detection is further improved, and it is ensured that the system only responds to trusted signals.

[0023] 2. The technical solution supports parsing of main control instructions and extended control instructions from radio frequency signals through a bidirectional communication mechanism, realizes diversified control operations on vehicles, such as unlocking vehicle doors, starting vehicles, adjusting air conditioners, and controlling vehicle windows, etc. In addition, through the statistical and retransmission mechanism of the instruction frame, the integrity and reliability of the control instructions are ensured, and the failure of operation caused by signal loss or interference is avoided, thereby improving the user experience and system stability.

[0024] 3. The technology scheme adopts periodic wake-up listening technology, reduces the average power consumption of the receiving end to microampere level, supports battery power supply, and prolongs the device endurance time. At the same time, through the dynamic switching design of the one-way compatible mode and the two-way authentication mode, the backward compatibility of the traditional one-way remote controller is ensured, and through the abnormal event log recording and high alert state, the defense ability against illegal signals is enhanced, which provides flexible support for the safety and compatibility of the system. BRIEF DESCRIPTION OF DRAWINGS

[0025] Figure 1 is a flow diagram of a low-power radio frequency receiving method based on two-way authentication disclosed by the embodiment of the present application; Figure 2 is another flow diagram of a low-power radio frequency receiving method based on two-way authentication disclosed by the embodiment of the present application; Figure 3 is a structural diagram of a low-power radio frequency receiving device based on two-way authentication provided by the embodiment of the present application.

[0026] The reference signs are explained as follows: 301, central processing unit; 302, read-only memory; 303, random access memory; 304, bus; 305, input / output interface; 306, input part; 307, output part; 308, storage part; 309, communication part; 310, driver; 311, detachable medium. DETAILED DESCRIPTION

[0027] In order for those skilled in the art to better understand the technical solutions in the specification, the technical solutions in the specification will be clearly and completely described below in combination with the drawings in the embodiment of the specification. Obviously, the described embodiments are only some of the embodiments of the present application, not all the embodiments.

[0028] In the description of the embodiments of the present application, the words such as "for example" or "for instance" are used to represent an example, illustration or description. Any embodiment or design scheme described as "for example" or "for instance" in the embodiments of the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the words such as "for example" or "for instance" are intended to present the relevant concept in a specific way.

[0029] In the description of the embodiments of the present application, the term "a plurality of" means two or more. For example, a plurality of system devices means two or more system devices, and a plurality of screen terminals means two or more screen terminals. In addition, the terms "first", "second", etc. are used only for the purpose of description and should not be understood as indicating or implying relative importance or implicitly indicating the indicated technical features. Therefore, the features defined with "first", "second", etc. can be explicitly or implicitly included one or more of the features. The terms "include", "contain", "have" and their variants mean "include but not limited to", unless otherwise specifically emphasized.

[0030] The present application provides a low-power radio frequency receiving method based on bidirectional authentication. Referring to Figure 1 , Figure 1 is a flowchart of a low-power radio frequency receiving method based on bidirectional authentication provided by an embodiment of the present application. The method is applied to a device, which is a vehicle receiving end. The vehicle receiving end can execute a low-power radio frequency receiving method based on bidirectional authentication program. The method includes steps S101 to S107, which are as follows: Step S101: In a preset listening period, periodically wake up in a low-power mode and perform radio frequency signal detection, and when the radio frequency signal meets the preset legitimacy requirement and the radio frequency signal strength exceeds the preset strength threshold, switch from the low-power mode to the working mode.

[0031] In step S101, the preset listening period refers to a time cycle period set in advance for the system, and the system performs intermittent wake-up detection in the period. The low-power mode represents a standby state of the system for saving power, in which most of the circuits are in sleep or off. The radio frequency signal refers to the radio frequency signal emitted by the transmitting end device, such as a smart key. The preset legitimacy requirement is used to represent a set of predetermined rules for preliminary screening of the radio frequency signal, such as the preamble or frame format of the signal must comply with the regulations. The preset strength threshold refers to the signal power threshold set to filter out invalid signals that are too far or too weak. The working mode represents a state in which the system is fully activated, the processor and related radio frequency circuits are running at full power, to perform data processing and communication.

[0032] Specifically, the timer inside the vehicle receiving end wakes up the radio frequency receiving front-end circuit for a short time according to a preset listening period, for example, every 100 milliseconds. Within the short wake-up window, the vehicle receiving end performs radio frequency signal detection to scan whether there is a radio frequency signal in a specific frequency band. If a radio frequency signal is detected, the vehicle receiving end first determines whether the signal strength of the radio frequency signal exceeds a preset strength threshold, for example, -85 dBm. If the signal strength meets the requirement, the vehicle receiving end further analyzes whether the radio frequency signal meets a preset legality requirement. Only when both the radio frequency signal strength and the legality requirement are met, the vehicle receiving end considers it as a valid wake-up attempt, and then activates the internal main processor and complete communication protocol stack, switching from the low-power mode to the working mode, to prepare for subsequent data reception. If no signal is detected within the wake-up window, or the signal does not meet any condition, the vehicle receiving end immediately returns to the low-power mode, waiting for the arrival of the next listening period.

[0033] In a possible implementation, after periodic wake-up in the low-power mode and radio frequency signal detection, the method further includes: performing preliminary demodulation on the radio frequency signal to listen for a dynamic wake-up preamble; generating an expected preamble based on an authentication parameter used in a historical successful authentication interaction through a preset one-way hash function, the authentication parameter being a random number sent by the transmitting end or a response code generated by the vehicle receiving end in the historical successful authentication interaction; and performing matching comparison between the dynamic wake-up preamble and the expected preamble; if the matching is successful, determining that the radio frequency signal meets the preset legality requirement; if the matching fails or the dynamic wake-up preamble is not listened to, determining that the radio frequency signal is an invalid wake-up signal, and keeping the low-power mode.

[0034] Specifically, after the vehicle receiving end completes periodic wake-up and detects that the radio frequency signal strength exceeds the preset strength threshold, in order to further distinguish between valid signals sent by a legal transmitting end and possible interference signals or malicious attack signals, the vehicle receiving end needs to perform a signal legality verification mechanism based on a dynamic wake-up preamble. The core idea of the mechanism is to generate an expected preamble through a preset one-way hash function using an authentication parameter that has been verified in a historical successful authentication interaction, and perform matching comparison between the expected preamble and a dynamic wake-up preamble demodulated from the currently received radio frequency signal, so as to quickly filter out illegal or invalid wake-up signals before formally entering the challenge code receiving and authentication handshake process, and reduce the power consumption overhead of the system due to responding to invalid signals.

[0035] When the signal strength detection circuit of the vehicle receiving end determines that the received signal strength indication value exceeds the preset strength threshold, the main controller does not immediately enter the complete working mode, but first instructs the radio frequency receiving module to perform preliminary demodulation operation on the currently received radio frequency signal. The preliminary demodulation operation is different from the subsequent demodulation processing of the complete data frame, and its purpose is only to extract the preamble sequence of the starting part of the radio frequency signal.

[0036] Specifically, the radio frequency receiving module starts to sample the bit stream of the received signal after completing carrier synchronization and clock recovery. The vehicle receiving end defines the structure format of the dynamic wake-up preamble in advance, which usually includes a fixed-length synchronization field and a variable-content dynamic identification field. The host controller first detects whether the synchronization field matches the preset pattern during demodulation. If the synchronization field matches successfully, it continues to extract the content of the dynamic identification field that follows, and temporarily stores the content as the dynamic wake-up preamble in the receiving buffer area.

[0037] For example, assuming that the total length of the dynamic wake-up preamble is 32 bits, the first 16 bits are the fixed synchronization field (such as 0xAA55), and the last 16 bits are the dynamic identification field. The radio frequency receiving module detects a continuous 0xAA55 bit sequence during demodulation, and then determines that the synchronization field matches successfully, and then extracts the content of the subsequent 16 bits as the dynamic wake-up preamble to be verified.

[0038] After detecting the dynamic wake-up preamble, the vehicle receiving end needs to generate an expected preamble for matching comparison with the dynamic wake-up preamble. The generation process of the expected preamble depends on the authentication parameters used in the historical successful authentication interaction. The state storage of the vehicle receiving end maintains a historical authentication parameter record table, which stores the authentication parameters of the last several times of successful completion of the bidirectional authentication handshake. The authentication parameters specifically include two categories: one is the random number sent by the transmitting end in the historical successful authentication interaction, that is, the random number value carried by the transmitting end in the wake-up challenge code; the other is the response code generated by the vehicle receiving end itself, that is, the response code content sent by the vehicle receiving end to the transmitting end in the bidirectional authentication handshake process.

[0039] The host controller reads the authentication parameters corresponding to the last successful authentication interaction from the historical authentication parameter record table. Assuming that the authentication parameters are the random number R prev sent by the transmitting end in the last authentication interaction, the value of which is 0x3A7F29B1. The host controller takes this random number R prev as input and calls a preset one-way hash function for operation. The preset one-way hash function can be SHA-256, MD5, or other hash algorithms that meet the requirements of one-wayness and collision resistance. In order to meet the length requirement of the dynamic wake-up preamble, the host controller performs truncation processing on the hash operation result, and only keeps the lower 16 bits as the expected preamble.

[0040] Continuing the above example, if the lower 16 bits of the 256-bit result obtained by performing SHA-256 hash operation on the random number 0x3A7F29B1 are 0xC4E7, then 0xC4E7 is the expected preamble generated by the vehicle receiving end.

[0041] It should be particularly pointed out that the legitimate transmitting end generates the dynamic wake-up preamble based on the same historical authentication parameter and the same preset one-way hash function when sending the radio frequency signal. Since the vehicle receiving end and the legitimate transmitting end both save the same authentication parameter after the last successful authentication interaction, and both parties agree to use the same hash function and truncation rule in advance, the dynamic wake-up preamble generated by the legitimate transmitting end should be completely consistent with the expected preamble generated by the vehicle receiving end.

[0042] After generating the expected preamble, the main controller performs a bit-by-bit matching comparison between the dynamic wake-up preamble temporarily stored in the receiving buffer and the expected preamble. If the matching is successful, that is, each bit of the dynamic wake-up preamble and the expected preamble is the same, the main controller determines that the current received radio frequency signal meets the preset legitimacy requirement. At this time, the vehicle receiving end determines that the radio frequency signal comes from the legitimate transmitting end, and then formally switches from the low-power mode to the working mode to continue to perform the subsequent wake-up challenge code receiving and bidirectional authentication handshake process. If the matching fails, that is, there is at least one bit difference between the dynamic wake-up preamble and the expected preamble, the main controller determines that the current received radio frequency signal is an invalid wake-up signal. The invalid wake-up signal may come from the following situations: random radio frequency interference in the environment, signals transmitted by other non-associated devices, or illegal signals of malicious attackers trying to wake up the vehicle receiving end through a replay attack. Regardless of which situation, the vehicle receiving end does not respond to the signal, but closes the radio frequency receiving module, the main controller reduces the core clock frequency back to the lowest running gear, and keeps the low-power mode to wait for the next timer wake-up interrupt. In addition, if the vehicle receiving end fails to detect the dynamic wake-up preamble conforming to the preset format in the preliminary demodulation process, such as synchronization field detection failure or seriously damaged demodulation data, it is also determined that the radio frequency signal is an invalid wake-up signal, and the low-power mode remains unchanged.

[0043] Step S102: receiving a wake-up challenge code containing a random number within a first preset time after entering the working mode.

[0044] In step S102, the first preset time refers to a specific time window set for receiving the wake-up challenge code after the vehicle receiving end enters the working mode. The wake-up challenge code refers to a data frame sent by the transmitting end, which is used to initiate a bidirectional authentication request and contains authentication key information. The random number refers to an unpredictable value generated by the transmitting end and different for each communication, which is contained in the wake-up challenge code and used to prevent replay attacks.

[0045] Specifically, after switching from the low-power mode to the working mode, the vehicle receiving end starts an internal timer immediately, and the counting period of the timer is set as a first preset time, for example, 50 milliseconds. During this time period, the radio frequency receiving circuit of the vehicle receiving end is kept in a continuously open state and focuses on receiving and decoding the radio frequency signal from the air. The vehicle receiving end expects to receive a complete wake-up challenge code data frame sent by the transmitting end supporting the bidirectional authentication within this time window, and the payload of the data frame must contain a random number for the subsequent authentication process.

[0046] In a possible implementation, the wake-up challenge code containing the random number is received within the first preset time, and specifically includes steps S1021-S1025, and the steps are as follows: Step S1021: Start the challenge code receiving timer, and demodulate and decode the received radio frequency signal to obtain the decoded data frame.

[0047] In step S1021, the challenge code receiving timer refers to an internal timer for limiting the maximum time for receiving the wake-up challenge code. Demodulation refers to the process of restoring the modulated radio frequency carrier signal to a baseband signal. Decoding refers to converting the baseband signal into a binary digital data stream, i.e., the decoded data frame, according to a predetermined encoding rule, such as Manchester encoding or NRZ encoding. The decoded data frame refers to the original binary data sequence containing the frame header, payload, and check structured information.

[0048] Specifically, after entering the working mode, the vehicle receiving end starts a challenge code receiving timer immediately, and the set time length of the timer is the first preset time. At the same time, the digital signal processing unit of the vehicle receiving end starts processing the analog signal received by the radio frequency front end. First, after mixing, filtering, and amplifying, the signal is sent to the demodulator, and the demodulator restores the high-frequency signal to the baseband level signal representing 0 and 1 according to the agreed modulation mode, for example, FSK frequency shift keying. Then, the decoder performs clock recovery and data synchronization on the baseband signal, and translates it into binary data bit by bit according to the encoding rule, and finally combines it into a complete data frame structure, i.e., the decoded data frame, for subsequent protocol layer analysis.

[0049] Step S1022: Detect whether the decoded data frame contains a preset challenge code frame header identifier.

[0050] In step S1022, the preset challenge code frame header identifier refers to a fixed and unique bit sequence located at the front end of the wake-up challenge code data frame, which is used to explicitly identify that the type of the data frame is the wake-up challenge code.

[0051] Specifically, the vehicle receiving protocol processing unit checks the start portion of the decoded data frame obtained in step S1021. The protocol stack compares the first several bits of the data frame with an internally stored preset challenge code frame header identifier. For example, the preset challenge code frame header identifier can be a specific 8-bit sequence, such as 10101010. Only when the start bit sequence of the decoded data frame completely matches the preset value, the vehicle receiving end considers that the data frame can be a valid wake-up challenge code, and continues subsequent processing. If the start portion does not match, the decoded data frame is directly discarded, and the vehicle receiving end continues to wait for a new data frame.

[0052] Step S1023: If it is determined that the decoded data frame contains the preset challenge code frame header identifier, the payload field of the data frame is parsed, and the random number and the transmitter identifier are extracted from the payload field.

[0053] In step S1023, the payload field refers to the portion of the data frame that carries core valid information, distinguished from the frame header, address, check, and other protocol overhead portions. The transmitter identifier is an encoding for uniquely identifying the identity of the transmitter device, such as the serial number of the smart key.

[0054] Specifically, after confirming the preset challenge code frame header identifier, the protocol processing unit of the vehicle receiving end skips the frame header portion and locates to the payload field according to the preset data frame format definition. The internal structure of the payload field is also predefined, for example, the first 128 bits are random numbers, and the last 32 bits are transmitter identifiers. The processor accurately copies the bit stream of the corresponding length from the specified position of the payload field, parses the random number and the transmitter identifier respectively, and temporarily saves the two data items in the working register.

[0055] Step S1024: Perform frame check operation on the data frame, and if the check passes, determine that a wake-up challenge code conforming to the preset format is received, and temporarily store the random number and the transmitter identifier to the receiving buffer area.

[0056] In step S1024, the frame check operation is a technique for verifying whether errors occur in the transmission process of data, and common algorithms include cyclic redundancy check (CRC). The receiving buffer area is a special memory area for temporarily storing valid data that passes the preliminary check and is to be processed subsequently.

[0057] Specifically, after the load information is extracted, the vehicle receiving end performs the same frame check operation as the transmitting end on the entire decoded data frame, usually excluding the frame check field itself, such as the CRC-16 algorithm. The result of the calculation is compared with the frame check field carried at the end of the data frame. If they are completely consistent, it means that the data frame has not occurred bit error during transmission, and the check passes. At this time, the vehicle receiving end finally confirms that a complete and correct wake-up challenge code in the preset format has been received. Then, the vehicle receiving end formally transfers the random number and the transmitting end identifier extracted in step S1023 from the temporary working register to the receiving buffer area for use in the two-way authentication process.

[0058] Step S1025: If the challenge code receiving timer times out or the frame check fails, it is determined that a wake-up challenge code in the preset format has not been received.

[0059] In step S1025, the challenge code receiving timer timeout means that the timer started in step S1021 has not completed the successful determination of step S1024 before the countdown ends. The frame check fails means that the check value calculated in step S1024 is inconsistent with the check value carried in the data frame.

[0060] Specifically, if the challenge code receiving timer counts down to zero within the entire first preset time, the vehicle receiving end has not received any data frame containing the correct frame header identifier, or the received data frame has a correct frame header but the final frame check operation fails, then the vehicle receiving end determines that this attempt has failed. Regardless of which case, the timer times out or the frame check fails, the final result is to determine that a wake-up challenge code in the preset format has not been received within the specified time. This determination result triggers the subsequent process to switch to the one-way compatible mode.

[0061] Step S103: If a wake-up challenge code in the preset format is received within the first preset time, it is determined that the current communication is in the two-way authentication mode, and the random number is extracted.

[0062] In step S103, the preset format refers to the specific data structure that the wake-up challenge code data frame must follow, including the provisions of the frame header, data length, command identifier, data load, and checksum. The two-way authentication mode refers to a high security level communication mode in which the vehicle receiving end and the transmitting end need to verify each other's identity.

[0063] Specifically, the vehicle receiving end successfully receives one radio frequency data frame within the first preset time. The vehicle receiving end then parses the data frame, checks whether the frame header identification is the bidirectional authentication request identification, whether the data length is correct, and whether the cyclic redundancy check code (CRC) of the frame tail is passed. If all checks are passed, it indicates that the data frame conforms to the preset format of the wake-up challenge code, and the vehicle receiving end determines that the current communication enters the bidirectional authentication mode. After the determination is completed, the vehicle receiving end accurately extracts the random number from the data payload area of the wake-up challenge code according to the protocol, and temporarily stores the random number for the encryption operation in step S105.

[0064] Step S104: If no wake-up challenge code conforming to the preset format is received within the first preset time, it is determined that the current communication is in the unidirectional compatible mode.

[0065] In step S104, the unidirectional compatible mode refers to a communication mode set for compatibility with old or simplified transmitting end devices. In this mode, the vehicle receiving end does not perform bidirectional authentication handshake, but directly waits to receive control instructions.

[0066] Specifically, if the timer started in step S102 counts down to zero within the first preset time, and the vehicle receiving end has not successfully received and verified any wake-up challenge code conforming to the preset format, the vehicle receiving end determines that the initiator of the current communication does not support or enable the bidirectional authentication function. At this time, the vehicle receiving end marks the state of the current communication process as the unidirectional compatible mode, and gives up waiting for the wake-up challenge code, and directly enters the phase of waiting for subsequent control instructions.

[0067] In one possible implementation, after determining that the current communication is in the unidirectional compatible mode, the method further includes: starting a compatible mode wake-up counter, and incrementing the compatible mode wake-up counter each time it is determined to be in the unidirectional compatible mode; determining whether the count value of the compatible mode wake-up counter reaches a preset count threshold; if the count value does not reach the count threshold, continuously receiving radio frequency signals; if the count value reaches the count threshold, entering a temporary high alert state for a preset lock time, in which control operations are prohibited and an abnormal event log is recorded; and if it is determined that the preset lock time is over, clearing the compatible mode wake-up counter and restoring the normal working process.

[0068] Specifically, to achieve backward compatibility with traditional one-way remote controllers, when the vehicle receiving end does not receive a wake-up challenge code in a preset format within a first preset time, it determines that the current communication is in one-way compatible mode and continues to receive subsequent control instruction frames. However, this compatibility mechanism can be exploited by malicious attackers to repeatedly trigger the vehicle receiving end to enter one-way compatible mode by continuously sending radio frequency signals that do not contain valid challenge codes, thereby implementing a denial-of-service attack or attempting to brute-force the rolling code of traditional remote controllers.

[0069] To address the above security threats, after determining that the current communication is in one-way compatible mode, the vehicle receiving end needs to perform an abnormality detection and temporary locking mechanism based on compatible mode wake-up counting. The core idea of this mechanism is to count the number of times the vehicle receiving end enters one-way compatible mode within a certain time window. When this number exceeds a reasonable threshold in normal use scenarios, it is determined that the system may be under attack or there is an abnormal condition, and a temporary high-alert state is entered to prevent potential illegal control operations.

[0070] When the main controller of the vehicle receiving end determines that the current communication is in one-way compatible mode, it first checks the current state of the compatible mode wake-up counter. The compatible mode wake-up counter is a software counter maintained by the main controller, and its count value is stored in a designated register area of the state memory to ensure that the count value is not lost when the vehicle receiving end enters low-power mode.

[0071] If the compatible mode wake-up counter has not been started, i.e., it is the first time to determine that it enters one-way compatible mode, the main controller performs counter initialization, sets the count value to 1, and records the current time as the start timestamp of the counting period. If the compatible mode wake-up counter is already in the started state, i.e., there has been a record of entering one-way compatible mode before, the main controller first checks whether the time difference between the current time and the start timestamp of the counting period exceeds the preset counting period length.

[0072] The preset counting period length is a configurable parameter, and its typical value range is 5 minutes to 30 minutes. If the time difference exceeds the counting period length, it indicates that the previous counting period has ended, and the main controller clears the compatible mode wake-up counter and sets the current time as the start timestamp of the new counting period, and then sets the count value to 1. If the time difference does not exceed the counting period length, it indicates that it is still within the same counting period, and the main controller performs a one-increment operation on the count value of the compatible mode wake-up counter.

[0073] For example, assume that the preset counting period is 10 minutes and the preset counting threshold is 5 times. At 9:00 am, the vehicle receiver determines for the first time that it enters the one-way compatible mode, at which time the counter is started, the counting value is 1, and the start time stamp is 9:00 am. At 9:02 am, 9:04 am, and 9:06 am, the vehicle receiver determines for three times that it enters the one-way compatible mode, respectively. Since the three determinations all occur within 10 minutes after the start time stamp, the counting value is sequentially added to 2, 3, and 4.

[0074] After completing the counting operation of the compatible mode wake-up counter, the main controller immediately compares the current counting value with the preset counting threshold. The preset counting threshold is a parameter value determined according to the reasonable frequency of user operation of a traditional one-way remote controller in a normal use scenario. In a normal case, the number of times that a user continuously uses a traditional remote controller in a short time usually does not exceed 3 to 5 times, and thus the typical value range of the preset counting threshold is 3 to 10 times. The specific value can be configured according to the vehicle safety level requirement.

[0075] If the counting value does not reach the preset counting threshold, the main controller determines that the current one-way compatible mode communication belongs to the normal use category, and immediately continues to perform subsequent operations according to the standard process, that is, continuously receives the radio frequency signal to obtain the control instruction frame within the second preset time, and performs the corresponding control operation according to the control instruction frame after the reception is completed.

[0076] Continuing the above example, at 9:06 am, the counting value is 4, which does not reach the preset counting threshold 5, and thus the vehicle receiver normally receives and processes the control instruction. If the counting value reaches the preset counting threshold, the main controller determines that there may be an abnormal condition or that the system is under attack, and immediately triggers the vehicle receiver to enter a temporary high alert state.

[0077] When entering the temporary high alert state, the following operation sequence is first performed: first, the current time is recorded as the entry time stamp of the temporary high alert state; second, a new log record is created in the abnormal event log, which includes the event type identifier (identified as "compatible mode abnormal frequent wake-up"), the entry time stamp, the cumulative wake-up number in the current counting period, and the detailed information of the recent wake-up events (including the time of each wake-up, the received signal strength, the demodulated data digest, etc.); third, the temporary high alert state flag is set to be valid.

[0078] In the temporary high alert state, the behavior of the vehicle receiving end changes significantly. Specifically, the vehicle receiving end will still respond to the wake-up of the radio frequency signal and receive the control instruction frame. After decoding the control instruction frame, it will check the temporary high alert state flag. If the flag is valid, the main controller will prohibit the execution of the control operation, i.e., will not send any control command to the vehicle body control interface, and the vehicle's door lock, starter relay, and other actuators will remain in their current state. At the same time, the main controller will append a record of each prohibited control operation details to the abnormal event log, including the type of prohibited instruction, reception time, and source signal characteristics.

[0079] Continuing with the above example, at 9:08, the vehicle receiving end determines again to enter the one-way compatible mode, and the count value accumulates to 5, reaching the preset threshold. At this time, the vehicle receiving end enters the temporary high alert state and records the abnormal event log. Assuming the preset lock time is 15 minutes, during 9:08 to 9:23, even if the vehicle receiving end receives a valid traditional remote control door opening instruction, it will not execute the door opening operation, but record the instruction in the abnormal event log.

[0080] During the temporary high alert state, the main controller, upon waking up from low power consumption mode each time, will additionally check whether the time difference between the current time and the temporary high alert state entry timestamp has exceeded the preset lock time, in addition to performing the regular radio frequency signal detection process. The preset lock time is a configurable parameter, with a typical value range of 10 minutes to 60 minutes, used to ensure that the system can automatically restore normal function within a reasonable time after the possible attack behavior stops.

[0081] If the main controller determines that the time difference between the current time and the entry timestamp has exceeded the preset lock time, i.e., determines that the preset lock time has ended, it will perform a state recovery operation sequence: first, clear the count value of the compatible mode wake-up counter and remove the count period start timestamp; second, set the temporary high alert state flag to invalid; third, append a state recovery record to the abnormal event log, indicating the end time of the temporary high alert state and the number of control operations intercepted during the lock period; fourth, restore the normal working process, and subsequent valid control instructions received will be executed normally.

[0082] Continuing with the above example, after 9:23, when the vehicle receiving end is woken up again, the main controller detects that the current time has exceeded the preset lock time end time, and immediately performs state recovery operations to clear the counter and restore the normal working process. After that, if the user uses the traditional remote control to send a door opening instruction, the vehicle receiving end will execute the door opening operation normally.

[0083] Step S105: After determining that the current communication is in the bidirectional authentication mode, a response code is generated by using the preset key and the random number through an encryption operation, and the response code is sent to the transmitting end to complete the bidirectional authentication handshake.

[0084] In step S105, the preset key refers to a piece of secret data that is securely and uniquely stored in the vehicle receiving end and the legal transmitting end during the vehicle production or key matching stage. The encryption operation refers to a mathematical process of processing the random number by using the preset key to generate an irreversible ciphertext, and a symmetric encryption algorithm such as AES is usually used. The response code refers to an encryption result generated by the encryption operation, which is used to prove the identity of the vehicle receiving end to the transmitting end. The bidirectional authentication handshake refers to a process of completing mutual identity confirmation by exchanging and verifying encrypted information based on the random number and the preset key between the vehicle receiving end and the transmitting end.

[0085] Specifically, after determining that the current communication is in the bidirectional authentication mode in step S103, the vehicle receiving end reads the preset key paired with the current transmitting end from the internal secure storage unit. Then, the vehicle receiving end calls the internal encryption algorithm hardware or software, takes the random number extracted in step S103 and the read preset key as input, performs the encryption operation, and generates a unique response code. After the operation is completed, the vehicle receiving end constructs the response code into a new radio frequency data frame, and sends the data frame to the transmitting end through the radio frequency transmitting circuit. After receiving the response code, the transmitting end performs local verification, and if the verification is passed, the bidirectional authentication handshake is completed.

[0086] Step S106: After completing the bidirectional authentication handshake, or after determining that the current communication is in the one-way compatible mode, the radio frequency signal is continuously received within a second preset time to obtain a control instruction frame.

[0087] In step S106, the second preset time refers to another time window set by the vehicle receiving end for waiting to receive specific operation instructions of the user after the authentication process is completed. The control instruction frame refers to a data frame containing specific intentions of the user, such as operation commands such as unlocking the vehicle door, opening the trunk, etc.

[0088] Specifically, after completing the bidirectional authentication handshake, or after determining that the current communication is in the one-way compatible mode in step S104, the authentication stage is completed. At this time, the vehicle receiving end starts another timer with a second preset time, for example, 200 milliseconds. During this period, the radio frequency receiving circuit of the vehicle receiving end continues to remain in an open state, and waits for and receives the control instruction frame sent by the transmitting end that has passed the authentication.

[0089] In a possible implementation, after continuously receiving the radio frequency signal for the second preset time to obtain the control instruction frame, the method further includes: counting the number of actually received control instruction frames, and comparing the number of control instruction frames with the preset total number of instruction frames; if the number of control instruction frames is lower than the preset total number of instruction frames, sending a retransmission request to the transmitting end, wherein the retransmission request contains the serial numbers of the instruction frames that have not been received; if the new received instruction frame retransmitted by the transmitting end is received within a preset retransmission waiting time, splicing the new received instruction frame with the original instruction frame sequence to obtain a spliced instruction frame, and taking the spliced instruction frame as a new control instruction frame; if the number of instruction frames is still lower than the expected total number of instruction frames after the number of retransmissions reaches a preset retransmission threshold, sending a receiving failure notification to the transmitting end.

[0090] Specifically, after the second preset time ends, the main controller of the vehicle receiving end first traverses and counts the data stored in the sliding window receiving buffer. During the data receiving process, the main controller has numbered the data frames that are successfully demodulated and pass the cyclic redundancy check, and marks the value of the frame serial number field in the received frame bitmap. The received frame bitmap is a binary vector with the same length as the preset total number of instruction frames, where each bit corresponds to a frame serial number, and a bit value of 1 indicates that the frame with the serial number has been successfully received, and a bit value of 0 indicates that the frame with the serial number has not been received.

[0091] The main controller counts the number of bits with a bit value of 1 by performing a bit counting operation on the received frame bitmap, and the sum of the bits is the number of actually received control instruction frames. Then, the main controller compares the number of control instruction frames with the preset total number of instruction frames. The preset total number of instruction frames is a parameter notified by the transmitting end to the vehicle receiving end through the wake-up challenge code or the response confirmation frame in the two-way authentication handshake phase, indicating the total number of control instruction frames planned to be sent by the transmitting end in this communication session.

[0092] For example, it is assumed that the preset total number of instruction frames is 7 frames, and the transmitting end sends control instruction frames with serial numbers 1 to 7 in turn. After the second preset time ends, the received frame bitmap of the vehicle receiving end is [1, 1, 0, 1, 1, 0, 1], indicating that the frames with serial numbers 1, 2, 4, 5, and 7 have been successfully received, while the frames with serial numbers 3 and 6 have not been received. At this time, the main controller counts that the number of control instruction frames is 5, which is lower than the preset total number of instruction frames 7.

[0093] If the main controller determines that the number of control instruction frames is lower than the preset total number of instruction frames, the retransmission request process is started. First, the main controller initializes the retransmission count counter and sets its initial value to 0. Then, the main controller traverses the received frame bitmap and extracts the frame serial numbers corresponding to all bits with a bit value of 0, and arranges these frame serial numbers in ascending order to form a list of unreceived frame serial numbers.

[0094] The main controller generates a retransmission request data packet according to the list of un-received frame sequence numbers. The data structure of the retransmission request includes the following fields: a request frame header identification field, used to indicate that the frame is of the retransmission request type; a session identifier field, used to associate the current communication session to prevent replay confusion; an un-received frame number field, indicating the number of frames requested to be retransmitted; an un-received frame sequence number field, listing all the frame sequence numbers that need to be retransmitted in a compact encoding manner; and a frame check field, used to ensure the transmission integrity of the retransmission request itself.

[0095] After generating the retransmission request data packet, the main controller activates the micro radio frequency transmission module integrated in the vehicle receiving end. The micro radio frequency transmission module uses the same modulation method and transmission parameters as when sending the response code, and transmits the retransmission request data packet to the transmitting end within the preset retransmission request transmission time window. After transmission is completed, the main controller closes the micro radio frequency transmission module and switches the radio frequency receiving module to the receiving mode, and starts waiting for the retransmission response from the transmitting end.

[0096] Continuing with the above example, in the retransmission request generated by the vehicle receiving end, the un-received frame number field value is 2, and the un-received frame sequence number field content is [3, 6], indicating that the transmitting end is requested to retransmit two frames of control instructions with frame sequence numbers 3 and 6. After sending the retransmission request, the main controller starts the retransmission waiting timer and begins timing the preset retransmission waiting time. The preset retransmission waiting time is a parameter that takes into account the processing delay of the transmitting end and the wireless transmission delay, and its typical value range is 50 milliseconds to 200 milliseconds. Within the preset retransmission waiting time, the radio frequency receiving module continuously listens for retransmission response signals from the transmitting end.

[0097] After receiving the retransmission request sent by the vehicle receiving end, the transmitting end extracts the control instruction frames corresponding to the sequence numbers from its sending buffer according to the content of the un-received frame sequence number field, and retransmits these frames. The radio frequency receiving module of the vehicle receiving end demodulates and decodes the received signals, and the main controller performs frame sequence number identification and cyclic redundancy check on the decoded data frames.

[0098] If the main controller successfully receives the newly received instruction frames retransmitted by the transmitting end within the preset retransmission waiting time, and the newly received instruction frames pass the verification, the main controller performs frame sequence splicing operations. Specifically, the main controller inserts the newly received instruction frames into the corresponding positions of the sliding window receiving buffer according to the frame sequence number field values of the newly received instruction frames, and updates the values of the corresponding bit positions in the received frame bitmap to 1. After all the newly received instruction frames are inserted, the main controller rearranges and splices all the frames in the sliding window receiving buffer according to the frame sequence number order to obtain spliced instruction frames. The main controller uses the spliced instruction frames as new control instruction frames for subsequent instruction analysis and control operation execution.

[0099] Continuing with the above example, assume that the vehicle receiving end successfully receives the two control command frames with frame sequence numbers 3 and 6 retransmitted by the transmitting end within the preset retransmission waiting time. The host controller inserts these two frames into the sliding window receiving buffer at the 3rd and 6th positions, and updates the received frame bitmap to [1, 1, 1, 1, 1, 1, 1]. Subsequently, the host controller concatenates the 7 frames in the order of sequence numbers 1 to 7 to obtain the complete concatenated command frame, which is used as the new control command frame for subsequent processing.

[0100] If the command frame retransmitted by the transmitting end is not received within the preset retransmission waiting time, or the received retransmitted frame fails the check, the host controller increments the retransmission count counter by one, and determines whether the current retransmission count has reached the preset retransmission threshold. The preset retransmission threshold is a parameter for limiting the number of retransmission attempts, and its typical value range is 2 to 5 times, so as to avoid excessive power consumption and communication delay caused by continuous retransmission.

[0101] If the retransmission count has not reached the preset retransmission threshold, the host controller regenerates the retransmission request and sends it again, and then enters the retransmission waiting state again. At this time, the list of unreceived frame sequence numbers in the retransmission request should be recalculated based on the latest received frame bitmap, so as to ensure that only those frames that have not been successfully received are requested.

[0102] If the retransmission count reaches the preset retransmission threshold, and the number of control command frames is still less than the preset total number of command frames, i.e., there are still missing frames that cannot be completed, the host controller determines that this time of control command frame reception has finally failed. At this time, the host controller generates a reception failure notification data packet, which includes a failure reason code field, a list of final missing frame sequence numbers field, and a statistical information field of this session. The host controller sends the reception failure notification to the transmitting end through the micro radio frequency transmitting module, to inform the transmitting end that this communication has failed.

[0103] After sending the reception failure notification, the host controller of the vehicle receiving end decides the subsequent behavior according to the preset failure handling strategy. If the received control command frames contain enough key frames to perform basic control operations, the host controller can choose to perform partial control operations and feed back partial execution results to the transmitting end. If the received frames are insufficient to support any valid control operation, the host controller discards all received data, records the details of this reception failure event in the exception event log, and returns to the low power consumption mode to wait for the next communication session.

[0104] Step S107: Perform the corresponding control operation according to the control command frame, and return to the low power consumption mode after the control operation is completed.

[0105] In step S107, the control operation refers to the physical action completed by the vehicle receiving end through driving the related actuators in the vehicle internal bus according to the parsed instruction content.

[0106] Specifically, after successfully receiving the control instruction frame within the second preset time, the vehicle receiving end decrypts and verifies the control instruction frame to confirm the validity and integrity of the instruction. Then, the vehicle receiving end analyzes the specific content of the instruction, for example, unlocking all doors. The vehicle receiving end sends the operation instruction to the body control unit through the vehicle-mounted communication network such as the CAN bus or the LIN bus. After receiving the instruction, the body control unit drives the door lock motor to perform the unlocking action. After confirming that the control operation is completed, for example, receiving the completion feedback of the body control unit or waiting for a fixed execution time, the vehicle receiving end actively disconnects the power supply of the main processor and the high-power part such as the radio frequency transceiver circuit, and returns to the low-power mode of step S101 to wait for the next wake-up event.

[0107] Reference Figure 2 In a possible implementation, the corresponding control operation is performed according to the control instruction frame, specifically including steps S201-S204, and the steps are as follows: Step S201: Extracting a main instruction frame and an extended instruction frame from the control instruction frame, the main instruction frame being used to carry a main control instruction, and the main control instruction including door unlocking and vehicle starting, and the extended instruction frame being used to carry an auxiliary control instruction, and the auxiliary control instruction including adjusting the air conditioning temperature and opening the window.

[0108] In step S201, the main instruction frame refers to the part of the control instruction frame that is specially used to transmit instructions that have a significant impact on the safety and core functions of the vehicle. The main control instruction refers to the key command that directly relates to the access permission and driving ability of the vehicle. The extended instruction frame refers to the part of the control instruction frame that is used to transmit non-core function instructions that improve comfort and convenience. The auxiliary control instruction refers to the additional command that does not directly affect the safety and basic functions of the vehicle.

[0109] Specifically, after receiving the complete control instruction frame sequence, the vehicle receiving end analyzes the sequence according to the predefined protocol format. The protocol divides the control instruction frame into two logical parts or independent physical frames: the main instruction frame and the extended instruction frame. The protocol processing unit of the vehicle receiving end accurately separates the two parts according to the identifier or fixed data structure in the frame. For example, the first 64 bits of a long control instruction frame can be defined as the main instruction frame, which is used to carry main control instructions such as unlocking all doors or authorizing engine start; and the next 64 bits are defined as the extended instruction frame, which is used to carry auxiliary control instructions such as setting the air conditioner to 23 degrees Celsius or lowering the driver's side window. The vehicle receiving end sends the separated main instruction frame and extended instruction frame to different processing logics.

[0110] Step S202: decode the main instruction frame to obtain the operation type and operation parameter of the main control instruction.

[0111] In step S202, the operation type refers to the specific action category of the instruction, for example, whether it is an unlocking operation or a starting operation. The operation parameter refers to the specific quantification or description of the operation type, for example, which door to unlock, or the specific condition for starting the engine.

[0112] Specifically, the vehicle receiving end first focuses on the main instruction frame extracted from step S201. The protocol processing unit decodes according to the internal data structure specification of the main instruction frame. For example, the first byte of the main instruction frame may define the operation type, where 0x01 represents unlocking the door, and 0x02 represents starting the vehicle. One or more subsequent bytes define the operation parameter. If the operation type is door unlocking, the operation parameter may be 0xFF, indicating unlocking all doors, or 0x01, indicating unlocking only the driver's side door. The vehicle receiving end accurately translates the binary main instruction frame into an operation type and operation parameter that can be understood by the upper layer application by parsing these bits.

[0113] Step S203: determine the execution result of the main control instruction based on the operation type, and execute or reject the execution of the main control instruction based on the execution result.

[0114] In step S203, the execution result refers to the decision made by the vehicle receiving end before executing the instruction, according to the current vehicle state and permission policy, i.e. whether to allow execution or reject execution.

[0115] Specifically, after decoding the operation type and operation parameter of the main control instruction, the decision logic unit of the vehicle receiving end will make a series of conditional judgments. For example, if the operation type is vehicle starting, the logic unit will check whether the vehicle is in P gear, whether the brake is depressed, and whether the transmitter identifier used in the previous authentication process has the permission to start the vehicle. Based on these checks, the decision logic unit will generate an execution result. If all conditions are met, the execution result is "allow execution". If any condition is not met, for example, the vehicle is not in P gear, the execution result is "reject execution". Subsequently, the vehicle receiving end takes action according to the execution result: if the result is "allow execution", it sends a start command to the engine control unit through the vehicle-mounted network; if the result is "reject execution", it does not send any command and may record a failed attempt.

[0116] In one possible implementation, determining the execution result of the main control instruction based on the operation type specifically includes steps S2031-S2033, as follows: Step S2031: determine whether the transmitter has the permission to execute the main control instruction according to the operation type of the main control instruction.

[0117] In step S2031, the permission refers to a function range or an operation set allowed to be invoked by a specific transmitter identifier, which is pre-set in the vehicle interior.

[0118] Specifically, after decoding the operation type of the main control instruction, the vehicle receiver will call the transmitter identifier obtained in the two-way authentication stage and temporarily stored in the receiving buffer area. The vehicle receiver compares the transmitter identifier with the permission configuration table stored in the internal non-volatile memory. The permission configuration table records in detail the specific rights of each paired transmitter. For example, the transmitter identifier corresponding to the main key has all permissions including vehicle door unlocking, vehicle starting, air conditioning adjustment, while the transmitter identifier corresponding to the service key may be granted only the permission of vehicle door unlocking. The vehicle receiver will verify whether the corresponding transmitter identifier is marked as allowed in the permission configuration table according to the currently parsed operation type. If the operation type is vehicle starting and the permission configuration table shows that the transmitter identifier has the starting permission, it is determined that the permissions match.

[0119] Step S2032: If the transmitter has the permission to execute the main control instruction, it is determined to execute the main control instruction and generate an execution result status code.

[0120] In step S2032, the execution result status code refers to a specific numerical identifier used to represent that the main control instruction has passed the permission check and is allowed to enter the execution phase.

[0121] Specifically, if the vehicle receiver confirms in step S2031 that the transmitter identifier has the permission required to execute the current operation type, the vehicle receiver will make a decision to execute the main control instruction. At this time, the vehicle receiver will generate an execution result status code representing a successful check in the memory, for example, assigning the status code to a hexadecimal number 0x55. The execution result status code serves as an intermediate variable, which is used to pass the signal of passing the permission check to the subsequent task processing flow, ensuring that only authorized operations can trigger the physical action of the vehicle, thereby maintaining the accuracy of the controlled state of the vehicle.

[0122] Step S2033: If the transmitter does not have the permission to execute the main control instruction, it is determined to refuse to execute the main control instruction and generate a permission exception status code.

[0123] In step S2033, the permission exception status code refers to a specific error identifier used to represent that the current operation violates the permission regulation and the instruction has been intercepted.

[0124] Specifically, if the vehicle receiving end finds that the current transmitter identifier is not granted the right to perform the operation type in the permission configuration table after searching, for example, the transmitter sends a vehicle start instruction, but the transmitter is only a temporary device without start permission in the system record, the vehicle receiving end determines that the permission is not passed, and then determines to reject the execution of the main control instruction. In order to record and handle this abnormal situation, the vehicle receiving end generates a specific permission exception state code, for example, assigned as a hexadecimal number 0xAA. The permission exception state code prevents the instruction from being sent to the vehicle bus, and serves as the basis for subsequent logical judgment, so that the vehicle receiving end directly skips the instruction execution link, effectively preventing illegal operations from threatening the safety of the vehicle.

[0125] Step S204: After executing or rejecting the execution of the main control instruction, the execution result of the extended instruction frame is determined, and based on the execution result, the execution or rejection of the auxiliary control instruction is executed.

[0126] In step S204, the execution result here is the execution decision of the auxiliary control instruction.

[0127] Specifically, whether the main control instruction in step S203 is executed or rejected, the flow will continue to process the extended instruction frame. The vehicle receiving end decodes the extended instruction frame to obtain the operation type and parameters of the auxiliary control instruction, for example, the operation type is to adjust the air conditioner, and the parameter is 23 degrees Celsius. Then, the decision logic unit determines the execution result of the auxiliary control instruction. This decision is usually associated with the execution result of the main control instruction. One strategy is that the auxiliary control instruction is only allowed to be executed when the main control instruction is successfully executed. For example, only after the vehicle door is successfully unlocked, the instruction to open the vehicle window is executed. Another strategy is that the execution condition of the auxiliary control instruction is relatively loose, and as long as the identity authentication is passed, the auxiliary control instruction can be executed regardless of whether the main instruction is successfully executed. The vehicle receiving end generates an execution result according to the preset strategy. If the result is "allow execution", the corresponding instruction is sent to the air conditioner controller or the vehicle window controller. If the result is "reject execution", the auxiliary control instruction is ignored.

[0128] Next, a low-power radio frequency receiving device based on bidirectional authentication in the embodiment of the application is described from the perspective of hardware processing. Please refer to Figure 3 , which is a structural schematic diagram of a low-power radio frequency receiving device based on bidirectional authentication in the embodiment of the application.

[0129] It should be noted that, Figure 3 The structure of the low-power radio frequency receiving device based on bidirectional authentication shown is only an example, and should not limit the functions and use range of the embodiment of the application.

[0130] As Figure 3As shown, a low-power radio frequency reception apparatus based on bidirectional authentication includes a Central Processing Unit (CPU) 301 that can perform various appropriate actions and processes in accordance with a program stored in a Read-Only Memory (ROM) 302 or a program loaded from a storage section 308 into a Random Access Memory (RAM) 303, such as performing the methods described in the above embodiments. In the RAM 303, various programs and data required for the operation of the apparatus are also stored. The CPU 301, the ROM 302, and the RAM 303 are connected to each other through a bus 304. An Input / Output (I / O) interface 305 is also connected to the bus 304.

[0131] Connected to the I / O interface 305 are an input section 306 including an audio input apparatus, a push button switch, and the like; an output section 307 including a Liquid Crystal Display (LCD), an audio output apparatus, an indicator, and the like; the storage section 308 including a hard disk and the like; and a communication section 309 including a network interface card such as a LAN (Local Area Network) card, a modem, and the like. The communication section 309 performs communication processing via a network such as the Internet. A drive 310 is also connected to the I / O interface 305 as necessary. A removable media 311 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, and the like is attached to the drive 310 as necessary, so that a computer program read therefrom is installed into the storage section 308 as necessary.

[0132] In particular, the processes described above with reference to the flowcharts can be implemented as a computer software program in accordance with embodiments of the present application. For example, embodiments of the present application include a computer program product comprising a computer program carried on a computer readable medium, the computer program containing a computer program for executing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network by the communication section 309 and / or installed from the removable media 311. When the computer program is executed by the Central Processing Unit (CPU) 301, various functions defined in the present application are performed.

[0133] Note that specific examples of computer-readable storage media can include but are not limited to an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the present disclosure, a computer-readable storage medium can be any tangible medium that can contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device.

[0134] The flow diagrams and the block diagrams in the drawings are illustrations of architectures, functional processes, and operational processes, according to various embodiments of the present application. Each block in the flow diagrams and the block diagrams can represent a module, a procedure, or a part of code that comprises one or more executable instructions for implementing the specific logical functions specified for the block. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures.

[0135] Specifically, the low-power radio frequency receiving device based on bidirectional authentication in the embodiment includes a processor and a memory, and the memory stores a computer program. When the computer program is executed by the processor, the low-power radio frequency receiving method based on bidirectional authentication provided in the above embodiment is implemented.

[0136] As another aspect, the present application further provides a computer-readable storage medium. The storage medium can be included in the low-power radio frequency receiving device based on bidirectional authentication described in the above embodiments, or can exist independently without being assembled into the low-power radio frequency receiving device based on bidirectional authentication. The storage medium carries one or more computer programs. When the one or more computer programs are executed by a processor of the low-power radio frequency receiving device based on bidirectional authentication, the low-power radio frequency receiving device based on bidirectional authentication implements the low-power radio frequency receiving method based on bidirectional authentication provided in the above embodiments.

Claims

1. A low-power radio frequency receiving method based on two-way authentication, characterized in that, The method is applied to a vehicle receiver, and the method includes: Within a preset listening period, the system periodically wakes up in low-power mode and performs radio frequency signal detection. When the radio frequency signal meets the preset legality requirements and the radio frequency signal strength exceeds the preset strength threshold, the system switches from the low-power mode to the working mode. After entering the working mode, a wake-up challenge code containing a random number is received within a first preset time. If a wake-up challenge code conforming to a preset format is received within the first preset time, the current communication is determined to be in two-way authentication mode, and the random number is extracted. If a wake-up challenge code conforming to the preset format is not received within the first preset time, the current communication is determined to be in one-way compatibility mode. After determining that the current communication is the two-way authentication mode, a response code is generated through encryption operation using a preset key and the random number, and the response code is sent to the transmitting end to complete the two-way authentication handshake; After completing the two-way authentication handshake, or after determining that the current communication is the one-way compatible mode, the radio frequency signal is continuously received for a second preset time to obtain control command frames. The system performs corresponding control operations according to the control instruction frame, and returns to the low-power mode after the control operations are completed.

2. The method according to claim 1, characterized in that, Receiving a wake-up challenge code containing a random number within a first preset time period specifically includes: Start the challenge code receiving timer, and demodulate and decode the received radio frequency signal to obtain the decoded data frame; Detect whether the decoded data frame contains a preset challenge code frame header identifier; If it is determined that the decoded data frame contains the preset challenge code frame header identifier, then the payload field of the data frame is parsed, and the random number and transmitter identifier are extracted from the payload field; A frame verification operation is performed on the data frame. If the verification passes, it is determined that a wake-up challenge code conforming to the preset format has been received, and the random number and the transmitter identifier are temporarily stored in the receiving buffer. If the challenge code receiving timer times out or the frame verification fails, it is determined that no wake-up challenge code conforming to the preset format has been received.

3. The method according to claim 1, characterized in that, The execution of the corresponding control operation according to the control instruction frame specifically includes: Extract the main command frame and the extended command frame from the control command frame. The main command frame is used to carry the main control command, which includes unlocking the door and starting the vehicle. The extended command frame is used to carry the auxiliary control command, which includes adjusting the air conditioning temperature and opening the windows. The main instruction frame is decoded to obtain the operation type and operation parameters of the main control instruction; Based on the operation type, determine the execution result of the main control instruction, and based on the execution result, execute or refuse to execute the main control instruction; After executing or rejecting the main control instruction, the execution result for the extended instruction frame is determined, and based on the execution result, the auxiliary control instruction is executed or rejected.

4. The method according to claim 3, characterized in that, Determining the execution result of the main control instruction based on the operation type specifically includes: Based on the operation type of the main control command, determine whether the transmitting end has the authority to execute the main control command; If the transmitting end has the authority to execute the main control command, then it determines to execute the main control command and generates an execution result status code; If the transmitter does not have the authority to execute the main control command, it will refuse to execute the main control command and generate an authority exception status code.

5. The method according to claim 1, characterized in that, After periodically waking up in low-power mode and detecting radio frequency signals, the method further includes: The radio frequency signal is initially demodulated to listen for the dynamic wake-up preamble; Based on the authentication parameters used in historical successful authentication interactions, a desired preamble is generated through a preset one-way hash function. The authentication parameters are random numbers sent by the transmitter or response codes generated by the vehicle receiver in the historical successful authentication interactions. The dynamic wake-up preamble is matched and compared with the expected preamble; If the match is successful, the radio frequency signal is determined to meet the preset legality requirements; If the matching fails or the dynamic wake-up preamble is not detected, the radio frequency signal is determined to be an invalid wake-up signal, and the low-power mode is maintained.

6. The method according to claim 1, characterized in that, After determining that the current communication is in one-way compatibility mode, the method further includes: Start the compatibility mode wake-up counter, and increment the compatibility mode wake-up counter each time it is determined to be in one-way compatibility mode; Determine whether the count value of the compatibility mode wake-up counter has reached a preset count threshold; If the count value does not reach the count threshold, the radio frequency signal is continuously received; If the count value reaches the count threshold, a temporary high alert state with a preset lock time is entered. In the temporary high alert state, the control operation is prohibited and an abnormal event log is recorded. If the preset lock time is determined to have ended, the compatibility mode wake-up counter will be reset to zero and the normal working process will be restored.

7. The method according to claim 1, characterized in that, After continuously receiving radio frequency signals for a second preset time to obtain control command frames, the method further includes: The number of control command frames actually received is counted, and the number of control command frames is compared with the preset total number of command frames; If the number of control command frames is less than the preset total number of command frames, a retransmission request is sent to the transmitting end. The retransmission request includes the sequence number of the unreceived command frames. If a new receive command frame is received from the transmitter within the preset retransmission waiting time, the new receive command frame is concatenated with the original command frame sequence to obtain a concatenated command frame, and the concatenated command frame is used as a new control command frame. If the number of retransmissions reaches the preset retransmission threshold and the number of instruction frames is still lower than the expected total number of instruction frames, a reception failure notification is sent to the transmitting end.

8. A low-power radio frequency receiver based on two-way authentication, characterized in that, The low-power radio frequency receiver based on two-way authentication includes: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code including computer instructions, and the one or more processors call the computer instructions to cause the low-power radio frequency receiver based on two-way authentication to perform the method as described in any one of claims 1-7.

9. A computer-readable storage medium comprising instructions, characterized in that, When the instruction is executed on a low-power radio frequency receiver based on two-way authentication, the low-power radio frequency receiver based on two-way authentication performs the method as described in any one of claims 1-7.

10. A computer program product, characterized in that, When the computer program product is run on a low-power radio frequency receiver based on two-way authentication, the low-power radio frequency receiver based on two-way authentication performs the method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Automobile keyless entry and start integrated system based on Bluetooth recognition

    CN120711391A

  • Voice trigger type remote control method for low-power-consumption equipment

    CN120932646A

  • Wake-up frame protection

    WO2019005942A1