Security enhancement method and system for identity authentication of vehicle assisted by mobile phone
By using a mobile phone-assisted vehicle identity authentication method, which generates and verifies message authentication codes through near-field and remote secure channels, the problem of low identity authentication security in the absence of in-vehicle cameras is solved, thereby improving user experience and privacy protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 深圳开鸿数字产业发展有限公司
- Filing Date
- 2025-12-11
- Publication Date
- 2026-04-28
AI Technical Summary
In the absence of an in-vehicle camera when logging into in-vehicle applications, existing technologies skip the stringent requirements of facial recognition in order to ensure user experience, resulting in reduced identity authentication security and compromised user privacy.
The method of using mobile phones to assist in vehicle identity authentication utilizes the near-field secure connection and remote secure channel between the mobile app and the vehicle app to generate and verify message authentication codes. Combined with the verification of the application's remote server, temporary and target login credentials are obtained to ensure security.
It improves the user experience while enhancing security isolation and ensuring the safety of user privacy information.
Smart Images

Figure CN121940752A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to a security enhancement method and system for mobile phone-assisted vehicle identity authentication. Background Technology
[0002] In the context of the Internet of Things, users may log in to the same application on different terminal devices (such as mobile phones, vehicles, or laptops). Due to the sensitivity of the application itself, such as its involvement with user privacy or payment data, application developers typically implement strict user authentication. However, different terminal devices have different hardware capabilities, and using the same authentication scheme can easily lead to compatibility and user experience issues. For example, some car models lack in-car cameras; when an in-car application requires facial recognition, the user needs to get out of the car and use an external camera to complete the authentication.
[0003] To address the aforementioned issues, in existing technologies, when logging into in-vehicle applications without an in-vehicle camera, application service providers choose to skip the stringent requirements of facial recognition to ensure user experience. This results in reduced security of identity authentication and compromises the protection of users' privacy information.
[0004] Therefore, existing technologies still need to be improved and developed. Summary of the Invention
[0005] The main objective of this invention is to provide a security enhancement method and system for mobile phone-assisted vehicle identity authentication. This aims to solve the problem in the prior art where, in order to ensure user experience, application service providers choose to skip the strict requirements of facial recognition when logging into in-vehicle applications without an in-vehicle camera, resulting in reduced identity authentication security and compromised user privacy.
[0006] To achieve the above objectives, the present invention provides a security enhancement method for mobile phone-assisted vehicle identity authentication. This method is applied to a security enhancement system for mobile phone-assisted vehicle identity authentication, which includes a mobile app, a remote server for the app, and a vehicle-side app. The security enhancement method for mobile phone-assisted vehicle identity authentication includes the following steps: When the vehicle-side APP requests to log in to the application's remote server, the vehicle-side APP obtains a random number generated by the application's remote server and generates a first message authentication code based on the random number and preset vehicle-side information. The vehicle-side APP sends the preset vehicle-side information and the first message authentication code to the mobile APP, and the mobile APP sends the preset vehicle-side information and the first message authentication code to the application's remote server. The application's remote server performs a first verification based on the preset vehicle information and the first message authentication code. When the verification passes, the application's remote server generates a temporary login credential and sends the temporary login credential to the mobile APP. The mobile app sends the temporary login credential to the vehicle app, and the vehicle app sends the symmetric key to the application's remote server based on the temporary login credential. The application's remote server generates a second message authentication code based on the preset vehicle information and the symmetric key. The application's remote server performs a second verification based on the first message authentication code and the second message authentication code. When the verification passes, the application's remote server generates a target login credential and sends the target login credential to the vehicle-side APP. The vehicle-mounted app logs into the application's remote server using the target login credentials.
[0007] Optionally, the security enhancement method for mobile phone-assisted vehicle identity authentication, wherein when the vehicle-side APP requests to log in to the application's remote server, the vehicle-side APP obtains a random number generated by the application's remote server and generates a first message authentication code based on the random number and preset vehicle-side information, further includes: Establish a near-field secure connection between the mobile app and the vehicle app; A remote secure channel is established between the mobile app and the application's remote server, and the mobile app logs into the application's remote server based on the remote secure channel.
[0008] Optionally, in the aforementioned security enhancement method for mobile phone-assisted vehicle identity authentication, the preset vehicle-side information includes the application's vehicle-side login information, symmetric key, and vehicle device information; When the vehicle-mounted APP requests to log in to the application's remote server, the vehicle-mounted APP obtains a random number generated by the application's remote server and generates a first message authentication code based on the random number and preset vehicle-mounted information, specifically including: When the vehicle-side APP requests to log in to the application's remote server, the application's remote server generates a random number and returns the random number to the vehicle-side APP; The vehicle-side APP constructs the vehicle-side login information of the application and the symmetric key, obtains the vehicle device information through the vehicle terminal system, and generates a first message authentication code based on the vehicle-side login information of the application, the symmetric key, the vehicle device information, and the random number.
[0009] Optionally, the security enhancement method for mobile phone-assisted vehicle identity authentication, wherein the vehicle-side APP sends the preset vehicle-side information and the first message authentication code to the mobile-side APP, and the mobile-side APP sends the preset vehicle-side information and the first message authentication code to the application's remote server, further includes: The vehicle-mounted APP randomly generates a PIN code and sets the PIN code as a QR code or barcode; The mobile app obtains the PIN code by scanning the QR code or the barcode, and establishes a data layer secure channel with the vehicle app based on the near-field secure connection and the PIN code.
[0010] Optionally, the security enhancement method for mobile phone-assisted vehicle identity authentication includes the following: the vehicle-side APP sends the preset vehicle-side information and the first message authentication code to the mobile-side APP, and the mobile-side APP sends the preset vehicle-side information and the first message authentication code to the application's remote server. Specifically, this includes: The vehicle-side APP sends the application's vehicle login information, the vehicle equipment information, the random number, and the first message authentication code to the mobile APP through the data layer security channel; The mobile app sends the application's vehicle login information, the vehicle equipment information, the random number, and the first message authentication code to the application's remote server through the remote security channel.
[0011] Optionally, the security enhancement method for mobile phone-assisted vehicle identity authentication includes the following: the remote server of the application performs a first verification based on the preset vehicle information and the first message authentication code. When the verification passes, the remote server of the application generates a temporary login credential and sends the temporary login credential to the mobile APP. Specifically, this includes: The application's remote server performs facial recognition with the target user on the mobile APP based on the first message authentication code. If the facial recognition is successful, the application's vehicle login information is used for information verification. If the information verification is successful, the application's remote server generates a temporary login credential. The application's remote server associates the temporary login credential with the application's vehicle login information, the vehicle equipment information, the random number, and the first message authentication code, and sends the temporary login credential to the mobile app.
[0012] Optionally, the security enhancement method for mobile phone-assisted vehicle identity authentication further includes, whereby the remote server of the application performs facial recognition with the target user on the mobile phone APP based on the first message authentication code, and then includes: If facial recognition fails, the authentication will be rejected.
[0013] Optionally, the security enhancement method for mobile phone-assisted vehicle identity authentication further includes, after verifying information based on the vehicle login information of the application, the method further includes: If the information verification fails, the authentication will be rejected.
[0014] Optionally, the security enhancement method for mobile phone-assisted vehicle identity authentication includes the following steps: the mobile app sends the temporary login credential to the vehicle app; the vehicle app sends the symmetric key to the application's remote server based on the temporary login credential; and the application's remote server generates a second message authentication code based on the preset vehicle information and the symmetric key. Specifically, this includes: The mobile app sends the temporary login credential to the vehicle app; The vehicle-side APP sends the temporary login credential and the symmetric key to the application's remote server; The application's remote server generates a second message authentication code based on the temporary login credentials, the application's vehicle login information, the vehicle equipment information, the random number, the first message authentication code, and the symmetric key.
[0015] Optionally, the security enhancement method for mobile phone-assisted vehicle identity authentication includes the following: the remote server of the application performs a second verification based on the first message authentication code and the second message authentication code. When the verification passes, the remote server of the application generates a target login credential and sends the target login credential to the vehicle-side APP. Specifically, this includes: The application's remote server compares the first message authentication code and the second message authentication code. If the first message authentication code and the second message authentication code are the same, a target login credential is generated. The application's remote server sends the target login credentials to the vehicle-side APP.
[0016] Optionally, the security enhancement method for mobile phone-assisted vehicle identity authentication further includes, whereby the application's remote server compares the first message authentication code and the second message authentication code, and then includes: If the first message authentication code and the second message authentication code are different, the authentication will be rejected.
[0017] Optionally, the security enhancement method for mobile phone-assisted vehicle identity authentication further includes, whereby the vehicle-side APP logs into the application's remote server based on the target login credentials, and then includes: The remote server of the application and the vehicle-side APP delete the random number, the first message authentication code, and the temporary login credential.
[0018] Furthermore, to achieve the above objectives, the present invention also provides a security enhancement system for mobile phone-assisted vehicle identity authentication, wherein the security enhancement system for mobile phone-assisted vehicle identity authentication includes: The vehicle-side APP is used to obtain a random number generated by the remote server of the application, generate a first message authentication code based on the random number and preset vehicle-side information, and send the preset vehicle-side information and the first message authentication code to the mobile APP. A mobile app is used to send the preset vehicle information and the first message authentication code to the application's remote server. The application's remote server is used to perform a first verification based on the preset vehicle terminal information and the first message authentication code. When the verification is successful, a temporary login credential is generated and the temporary login credential is sent to the mobile APP. A mobile app is used to send the temporary login credentials to the vehicle-side app; The vehicle-side APP is used to send the symmetric key to the application's remote server based on the temporary login credentials; The application's remote server is used to generate a second message authentication code based on the preset vehicle-side information and the symmetric key, perform a second verification based on the first message authentication code and the second message authentication code, generate a target login credential when the verification passes, and send the target login credential to the vehicle-side APP. The vehicle-side APP is used to log in to the remote server of the application based on the target login credentials.
[0019] Optionally, in the aforementioned security enhancement system for mobile phone-assisted vehicle identity authentication, the remote server of the application includes: A random number generation module is used to generate random numbers and return the random numbers to the vehicle-side APP.
[0020] Optionally, in the aforementioned security enhancement system for mobile phone-assisted vehicle identity authentication, the vehicle-side APP includes: The first message authentication code generation module is used to construct the vehicle login information and symmetric key of the application, obtain vehicle equipment information through the vehicle terminal system, and generate the first message authentication code based on the vehicle login information of the application, the symmetric key, the vehicle equipment information and the random number. A PIN code generation module is used to randomly generate a PIN code and set the PIN code as a QR code or barcode; The first message authentication code sending module is used to send the vehicle login information of the application, the vehicle equipment information, the random number and the first message authentication code to the mobile APP through the data layer security channel.
[0021] Optionally, in the aforementioned security enhancement system for mobile phone-assisted vehicle identity authentication, the mobile app includes: The data layer secure channel construction module is used to obtain the PIN code by scanning the QR code or the barcode, and establish a data layer secure channel with the vehicle-side APP based on the PIN code using a near-field secure connection. The first message authentication code forwarding module is used to send the vehicle login information of the application, the vehicle equipment information, the random number and the first message authentication code to the remote server of the application through a remote secure channel.
[0022] Optionally, in the aforementioned security enhancement system for mobile phone-assisted vehicle identity authentication, the remote server of the application further includes: The first verification module is used to perform facial recognition on the mobile APP based on the first message authentication code and the target user. If the facial recognition is successful, the information is verified based on the vehicle login information of the application. If the information verification is successful, a temporary login credential is generated. The temporary login credential sending module is used to associate the temporary login credential with the vehicle login information of the application, the vehicle equipment information, the random number and the first message authentication code, and send the temporary login credential to the mobile APP.
[0023] Optionally, in the aforementioned security enhancement system for mobile phone-assisted vehicle identity authentication, the mobile app further includes: The temporary login credential forwarding module is used to send the temporary login credential to the vehicle-side APP.
[0024] Optionally, in the aforementioned security enhancement system for mobile phone-assisted vehicle identity authentication, the vehicle-side APP further includes: A symmetric key sending module is used to send the temporary login credential and the symmetric key to the remote server of the application.
[0025] Optionally, in the aforementioned security enhancement system for mobile phone-assisted vehicle identity authentication, the remote server of the application further includes: The second message authentication code generation module is used to generate a second message authentication code based on the temporary login credential, the vehicle login information of the application, the vehicle equipment information, the random number, the first message authentication code, and the symmetric key. The target login credential generation module is used to compare the first message authentication code and the second message authentication code. If the first message authentication code and the second message authentication code are the same, a target login credential is generated. The target login credential sending module is used to send the target login credential to the vehicle-side APP.
[0026] In this invention, when the vehicle-side APP requests to log in to the application's remote server, the vehicle-side APP obtains a random number generated by the application's remote server and generates a first message authentication code based on the random number and preset vehicle-side information; the vehicle-side APP sends the preset vehicle-side information and the first message authentication code to the mobile APP, and the mobile APP sends the preset vehicle-side information and the first message authentication code to the application's remote server; the application's remote server performs a first verification based on the preset vehicle-side information and the first message authentication code; when the verification passes, the application's remote server generates a temporary login credential and sends the temporary login credential to the application's remote server. The credential is sent to the mobile app; the mobile app sends the temporary login credential to the vehicle app; the vehicle app sends a symmetric key to the application's remote server based on the temporary login credential; the application's remote server generates a second authentication code based on the preset vehicle information and the symmetric key; the application's remote server performs a second verification based on the first and second authentication codes; when the verification passes, the application's remote server generates a target login credential and sends it to the vehicle app; the vehicle app logs in to the application's remote server based on the target login credential. This invention, in the absence of an in-vehicle camera, uses facial recognition on a mobile phone to assist in obtaining a temporary login credential, combined with verification by the application's remote server to obtain the target login credential. This avoids the mobile phone directly obtaining the vehicle's login credential, effectively improving the user experience and enhancing security isolation, thus ensuring the security of user privacy information. Attached Figure Description
[0027] Figure 1This is a flowchart of identity authentication in existing technologies; Figure 2 This is a flowchart of a preferred embodiment of the security enhancement method for mobile phone-assisted vehicle identity authentication of the present invention; Figure 3 This is a schematic diagram of the overall implementation process of a preferred embodiment of the security enhancement method for mobile phone-assisted vehicle identity authentication of the present invention; Figure 4 This is a flowchart illustrating the generation of the first message authentication code in a preferred embodiment of the security enhancement method for mobile phone-assisted vehicle identity authentication of the present invention; Figure 5 This is a flowchart of the first message authentication code forwarding in a preferred embodiment of the security enhancement method for mobile phone-assisted vehicle identity authentication of the present invention; Figure 6 This is a flowchart illustrating the generation of temporary login credentials in a preferred embodiment of the security enhancement method for mobile phone-assisted vehicle identity authentication of the present invention; Figure 7 This is a flowchart of the second message authentication code generation process in a preferred embodiment of the security enhancement method for mobile phone-assisted vehicle identity authentication of the present invention; Figure 8 This is a flowchart illustrating the generation of target login credentials in a preferred embodiment of the security enhancement method for mobile phone-assisted vehicle identity authentication of the present invention; Figure 9 This is a flowchart illustrating the construction of a remote secure channel in a preferred embodiment of the mobile phone-assisted vehicle identity authentication security enhancement method of the present invention; Figure 10 This is a flowchart illustrating the construction of a data layer security channel in a preferred embodiment of the mobile phone-assisted vehicle identity authentication security enhancement method of the present invention; Figure 11 This is a flowchart illustrating the first verification process where facial recognition fails in a preferred embodiment of the security enhancement method for mobile phone-assisted vehicle identity authentication of the present invention. Figure 12 This is a flowchart illustrating the first verification process where information verification fails in a preferred embodiment of the security enhancement method for mobile phone-assisted vehicle identity authentication of the present invention. Figure 13 This is a flowchart illustrating the second verification authentication failure in a preferred embodiment of the security enhancement system for mobile phone-assisted vehicle identity authentication of the present invention; Figure 14 This is a flowchart illustrating the temporary login data deletion process in a preferred embodiment of the security enhancement system for mobile phone-assisted vehicle identity authentication of the present invention. Figure 15 This is a schematic diagram of the security enhancement system for mobile phone-assisted vehicle identity authentication according to the present invention. Detailed Implementation
[0028] To make the objectives, technical solutions, and advantages of this invention clearer and more explicit, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
[0029] In the context of the Internet of Things, users may log in to the same application on different terminal devices (such as mobile phones, vehicles, or laptops). Due to the sensitivity of the application itself, such as involving user privacy and payment data, application developers generally conduct strict identity verification for users.
[0030] However, different terminal devices have different hardware conditions. If the same identity authentication scheme is used, compatibility and user experience issues can easily occur. For example, some car models do not have in-car cameras. When in-car applications require facial recognition for login, users need to get out of the car and use an external camera to complete the identity authentication.
[0031] Therefore, it is necessary to design effective identity authentication security enhancement schemes for terminal devices with limited conditions, so as to achieve a balance between security and user experience.
[0032] For ease of understanding below, the Chinese meanings of each English term are provided here: APP_Server is the application's remote server; V_APP_Login_Info is the application's vehicle login information; V_APP is the APP's vehicle application; M_APP is the APP's mobile application; V_OS is the vehicle terminal system; V_Info is the vehicle device information; M_OS is the mobile terminal system; V_ATT_API is the interface for the vehicle device authentication service; V_ATT_Priv is the private key for the vehicle device authentication service; V_ATT_Cert is the certificate for the vehicle device authentication service; V_ATT_Pub is the public key for the vehicle device authentication service; V_ATT_InterCAChain is the intermediate certificate chain for the vehicle device authentication service; V_ATT_RootCA is the root certificate for the vehicle device authentication service.
[0033] like Figure 1 As shown, the summary of the existing technical solution is as follows: 1. The APP_Server (the application's remote server) pre-stores the root certificate of the vehicle-side device authentication service (denoted as V_ATT_RootCA, which is generated by the vehicle manufacturer and comes with the vehicle from the factory).
[0034] 2. A certain application on the vehicle (i.e., the vehicle APP, denoted as V_APP) requests to log in to the remote server (denoted as APP_Server) of its corresponding application.
[0035] 3. APP_Server returns a random number N to V_APP (setting a random number N is to prevent duplicate submissions, generally known as anti-replay).
[0036] 4. V_APP constructs login information V_APP_Login_Info (i.e., the vehicle-side login information of the application) and calls the device verification service interface (denoted as V_ATT_API) provided by the vehicle terminal system V_OS (i.e., the interface for vehicle-side device verification service, which is generally called directly by the APP developer when writing code).
[0037] The process of constructing the vehicle-side login information for the application is as follows: Vehicle manufacturers define the specific parameters of V_APP_Login_Info (the vehicle-side login information for the application), which generally include {the vehicle owner's mobile phone number (or vehicle owner's user account), timestamp, and the vehicle owner's vehicle configuration options}.
[0038] 5. The vehicle terminal system (denoted as V_OS) executes V_ATT_API (i.e., device authentication service interface) to extract vehicle device information (denoted as V_Info), and uses the private key of the vehicle device authentication service (denoted as V_ATT_Priv) to digitally sign {V_APP_Login_Info, V_Info, N} (denoted as V_APP_Login_Sig). The expression for the digital signature is: V_APP_Login_Sig=Sign(private_key=V_ATT_Priv, data={V_APP_Login_Info, V_Info, N}).
[0039] Where N represents vehicle equipment information obtained through vehicle system interface calls.
[0040] The process by which the vehicle terminal system (referred to as V_OS) executes V_ATT_API (the interface for the vehicle-side device authentication service) is as follows: extract the vehicle device information V_Info, and use the private key of the vehicle-side device authentication service (referred to as V_ATT_Priv) to digitally sign {V_APP_Login_Info, V_Info, N} as V_APP_Login_Sig, and finally return {vehicle device information, V_APP_Login_Sig}.
[0041] Vehicle equipment information V_Info typically includes {vehicle equipment ID (e.g., VIN number), vehicle model, and vehicle production batch}.
[0042] In this invention, the digital signature follows international standards and serves as a means for the vehicle-side app (V_APP) to use the digital signature to prove to the outside world that the data comes from this particular vehicle of this car manufacturer, and not from other vehicles.
[0043] 6. The V_ATT_API interface (the interface for vehicle terminal device authentication service) of V_OS (Vehicle Terminal System) returns {V_Info, V_APP_Login_Sig}.
[0044] 7. V_APP submits {V_APP_Login_Info, V_Info, N, V_APP_Login_Sig, V_ATT_Cert (certificate of vehicle-side device verification service), V_ATT_InterCAChain (intermediate certificate chain of vehicle-side device verification service)} to APP_Server.
[0045] 8. The APP_Server (the application's remote server) performs a certificate chain security verification on {V_ATT_Cert, V_ATT_InterCAChain} based on V_ATT_RootCA. If the verification fails, the authentication is rejected.
[0046] 9. The APP_Server (the application's remote server) uses the public key of the vehicle-side device authentication service (denoted as V_ATT_Pub) in the V_ATT_Cert (the certificate for the vehicle-side device authentication service) to verify the digital signature V_APP_Login_Sig of {V_APP_Login_Info, V_Info, N}. If the verification fails, the authentication is rejected. The expression for the verification process is as follows: Verify_Result=Verify_Sig(pub_key=V_ATT_Pub, sig= V_APP_Login_Sig, data={V_APP_Login_Info, N}).
[0047] 10. The APP_Server checks the vehicle model hardware information based on V_Info (vehicle equipment information) to confirm whether the vehicle contains a camera. If V_Info shows that there is no camera in the vehicle, the facial recognition authentication process is skipped, and the APP_Server performs verification based on V_APP_Login_Info. If the verification fails, the authentication is rejected.
[0048] If V_Info shows that there is a camera inside the vehicle, APP_Server and the user will use the camera to perform facial recognition. If facial recognition fails, the authentication will be rejected.
[0049] If the verification is successful, APP_Server returns the login credential V_APP_Cred to V_APP, and the user successfully logs in to the APP on the vehicle. V_APP can then use V_APP_Cred to request relevant resources from APP_Server.
[0050] In summary, the disadvantages of the existing technical solutions are as follows: 1. In the absence of in-vehicle cameras, in order to ensure user experience, application service providers have skipped the strict requirements of facial recognition, thus reducing the security of identity authentication.
[0051] 2. The APP_Server needs to pre-store the root certificate of the vehicle-side device authentication service (denoted as V_ATT_RootCA). However, the root certificates of different vehicle manufacturers and different models may be different, requiring timely updates and maintenance, which results in high operation and maintenance costs.
[0052] 3. Application service providers mainly rely on vehicle-side device authentication services to determine the hardware information of in-vehicle cameras. Once a hacker steals the private key of the vehicle-side device authentication service, the hacker can forge requests for "vehicle terminals without in-vehicle cameras" in batches, bypassing facial recognition, which poses a security risk.
[0053] The preferred embodiment of the security enhancement method for mobile phone-assisted vehicle identity authentication described in this invention, such as... Figure 2 and Figure 3 As shown, the security enhancement method for mobile phone-assisted vehicle identity authentication includes the following steps: Step S10: When the vehicle-side APP requests to log in to the application's remote server, the vehicle-side APP obtains a random number generated by the application's remote server and generates a first message authentication code based on the random number and preset vehicle-side information.
[0054] Specifically, when an app in the vehicle needs to log in to the application's remote server, the app in the vehicle sends a login request to the application's remote server. After receiving this login request, the application's remote server generates a random number N and returns this random number N to the app in the vehicle. After receiving this random number N, the app in the vehicle combines it with preset vehicle information to generate a first message authentication code.
[0055] like Figure 4 As shown, step S10 specifically includes: Step S11: When the vehicle-side APP requests to log in to the application's remote server, the application's remote server generates a random number and returns the random number to the vehicle-side APP.
[0056] Specifically, step S11 is implemented as follows: After receiving the login request from the vehicle-side APP, the application's remote server (i.e., APP_Server) generates a random number N and returns this random number N to the vehicle-side APP. The random number N is set to prevent duplicate submissions, commonly known as replay protection.
[0057] Step S12: The vehicle-side APP constructs the vehicle-side login information of the application and the symmetric key, obtains the vehicle device information through the vehicle terminal system, and generates a first message authentication code based on the vehicle-side login information of the application, the symmetric key, the vehicle device information, and the random number.
[0058] Specifically, step S12 is implemented as follows: 1. A certain application on the vehicle (i.e., the vehicle-side APP in this invention, denoted as V_APP) requests to log in to its corresponding remote server (i.e., the remote server of the application in this invention, denoted as APP_Server).
[0059] 2. APP_Server (i.e., the remote server used in this invention) returns a random number N to V_APP (vehicle-side APP).
[0060] 3. V_APP (vehicle-side APP) constructs login information V_APP_Login_Info (i.e., vehicle-side login information used in this invention) and randomly generates the symmetric key K for this authentication (i.e., the symmetric key in this invention).
[0061] The process of constructing the vehicle-side login information for the application is as follows: Vehicle manufacturers define the specific parameters of V_APP_Login_Info (the application's vehicle login information), which generally include {the vehicle owner's mobile phone number (or vehicle owner's user account), timestamp, and the vehicle owner's vehicle configuration options}, etc.
[0062] 4. V_APP (vehicle-side APP) obtains V_Info (i.e., vehicle equipment information in this invention) from V_OS (vehicle terminal system).
[0063] The process by which the vehicle terminal system (referred to as V_OS) executes V_ATT_API (the interface for the vehicle-side device authentication service) is as follows: extract the vehicle device information V_Info, and use the private key of the vehicle-side device authentication service (referred to as V_ATT_Priv) to digitally sign {V_APP_Login_Info, V_Info, N} as V_APP_Login_Sig, and finally return {vehicle device information, V_APP_Login_Sig}.
[0064] 5. V_APP (vehicle-side APP) calculates the message authentication code V_MAC (i.e., the first message authentication code in this invention). The expression for calculating the message authentication code V_MAC is: V_MAC = MAC(key=K, data={ V_APP_Login_Info, V_Info, N}).
[0065] Step S20: The vehicle-side APP sends the preset vehicle-side information and the first message authentication code to the mobile-side APP, and the mobile-side APP sends the preset vehicle-side information and the first message authentication code to the application's remote server.
[0066] Specifically, after the vehicle-side APP obtains the preset vehicle-side information and the first message authentication code, it needs to send the preset vehicle-side information and the first message authentication code to the application's remote server for verification. However, it cannot send them directly and needs to rely on the mobile APP to forward them, because the mobile APP has already established communication connections with the vehicle-side APP and the application's remote server respectively.
[0067] like Figure 5 As shown, step S20 specifically includes: Step S21: The vehicle-side APP sends the vehicle-side login information, the vehicle equipment information, the random number, and the first message authentication code to the mobile APP through the data layer security channel.
[0068] Specifically, step S21 is implemented as follows: V_APP (i.e., the vehicle-side APP in this invention) securely returns {V_APP_Login_Info (the application's vehicle-side login information), V_Info (vehicle equipment information), N (random number), and V_MA (first message authentication code)} to M_APP (i.e., the mobile-side APP in this invention) based on the data layer security channel (the data layer security channel is the communication channel between the vehicle-side APP and the mobile-side APP).
[0069] Step S22: The mobile APP sends the vehicle login information, vehicle equipment information, random number and the first message authentication code to the application's remote server through the remote security channel.
[0070] Specifically, step S22 is implemented as follows: M_APP (i.e., the mobile APP in this invention) securely submits {V_APP_Login_Info (vehicle login information of the application), V_Info (vehicle equipment information), N (random number), V_MA (first message authentication code)} to APP_Server (i.e., the remote server used in this invention) based on the existing remote security channel to request auxiliary authentication.
[0071] Step S30: The remote server of the application performs a first verification based on the preset vehicle terminal information and the first message authentication code. When the verification is successful, the remote server of the application generates a temporary login credential and sends the temporary login credential to the mobile APP.
[0072] Specifically, the application's remote server receives the preset vehicle information and the first message authentication code from the vehicle-side app via the mobile app. It then performs verification based on these two pieces of information. The verification includes: 1. The user performs facial recognition via their mobile phone. If facial recognition is successful, the user logs in to the vehicle-side app; otherwise, authentication fails. 2. After successful facial recognition, the user verifies the vehicle-side login information from the preset information. Only after both verifications are successful will the application's remote server generate a temporary login credential and send it to the vehicle-side app via the mobile app.
[0073] like Figure 6 As shown, step S30 specifically includes: Step S31: The remote server of the application performs face recognition with the target user on the mobile APP based on the first message authentication code. If the face recognition is successful, the application verifies the information based on the vehicle login information. If the information verification is successful, the remote server of the application generates a temporary login credential.
[0074] Specifically, step S31 is implemented as follows: 1. The APP_Server (i.e., the remote server used in this invention) performs facial recognition with the user on the mobile phone. If facial recognition fails, the authentication is rejected.
[0075] 2. The APP_Server (i.e., the remote server used in this invention) verifies the information based on V_APP_Login_Info (i.e., the vehicle login information used in this invention). If the verification fails, the authentication is rejected.
[0076] 3. Only after face recognition and V_APP_Login_Info have both passed verification will APP_Server generate a temporary login credential V_APP_Cred and associate the temporary login credential V_APP_Cred with information such as {V_APP_Login_Info, V_Info, N, V_MAC, V_APP_Cred}.
[0077] Step S32: The remote server of the application associates the temporary login credential with the vehicle login information of the application, the vehicle equipment information, the random number and the first message authentication code, and sends the temporary login credential to the mobile APP.
[0078] Specifically, step S32 is implemented as follows: APP_Server (the application's remote server) securely returns V_APP_Cred (a temporary login credential) to M_APP (the mobile app).
[0079] After the application's remote server generates temporary login credentials, it needs to send the temporary login credentials to the vehicle-side APP. However, it needs to send them to the mobile APP first, and then the mobile APP forwards the temporary login credentials to the vehicle-side APP.
[0080] Step S40: The mobile APP sends the temporary login credential to the vehicle APP. The vehicle APP sends the symmetric key to the application's remote server based on the temporary login credential. The application's remote server generates a second message authentication code based on the preset vehicle information and the symmetric key.
[0081] Specifically, after receiving the temporary login credential from the application's remote server via the mobile app, the vehicle-side app recognizes that the remote server has completed the first verification and then sends the symmetric key to the remote server via the mobile app. Upon receiving the symmetric key, the remote server generates a second authentication code, which can then be used for a second verification.
[0082] like Figure 7 As shown, step S40 specifically includes: Step S41: The mobile APP sends the temporary login credential to the vehicle APP.
[0083] Specifically, step S41 is implemented as follows: M_APP (the mobile app) securely returns V_APP_Cred (temporary login credentials) to V_APP (the vehicle app).
[0084] After receiving the temporary login credentials sent by the application's remote server, the mobile app forwards the temporary login credentials to the vehicle app.
[0085] Step S42: The vehicle-side APP sends the temporary login credential and the symmetric key to the application's remote server.
[0086] Specifically, step S42 is implemented as follows: V_APP (vehicle-side APP) uses V_APP_Cred (temporary login credentials) to securely submit K (symmetric key) to APP_Server (the application's remote server).
[0087] After receiving the temporary login credential forwarded by the mobile app, the vehicle app determines that the application's remote server has passed the first verification. Based on the temporary login credential, it forwards the symmetric key K to the application's remote server through the mobile app.
[0088] Step S43: The remote server of the application generates a second message authentication code based on the temporary login credentials, the vehicle login information of the application, the vehicle equipment information, the random number, the first message authentication code, and the symmetric key.
[0089] Specifically, step S43 is implemented as follows: APP_Server (the remote server of the application) locates the recorded {V_APP_Login_Info (i.e., the vehicle login information of the application in this invention), V_Info (i.e., the vehicle equipment information in this invention), N (random number), V_MAC (first message authentication code)} based on V_APP_Cred (temporary login credential) (because it has already been associated with these data when the temporary login credential was generated), and calculates V_MAC2 (second message authentication code) in conjunction with the received K (symmetric key). The expression for calculating the second message authentication code is: V_MAC2 = MAC(key=K, data={ V_APP_Login_Info, V_Info, N}).
[0090] Step S50: The remote server of the application performs a second verification based on the first message authentication code and the second message authentication code. When the verification is successful, the remote server of the application generates a target login credential and sends the target login credential to the vehicle-side APP.
[0091] Specifically, after the remote server of the application generates the second message authentication code, it will perform a second verification based on the second message authentication code. The second verification process is to compare the first message authentication code and the second message authentication code. If they match, the verification can be determined to be successful, the target login credential will be generated, and the target login credential will be sent to the vehicle-side APP.
[0092] like Figure 8 As shown, step S50 specifically includes: Step S51: The remote server of the application compares the first message authentication code and the second message authentication code. If the first message authentication code and the second message authentication code are the same, a target login credential is generated.
[0093] Specifically, step S51 is implemented as follows: 1. The APP_Server (i.e., the remote server used in this invention) checks whether V_MAC2 (second message authentication code) is equal to V_MAC (first message authentication code). If they are not equal, the authentication is rejected.
[0094] 2. If the first message authentication code and the second message authentication code are equal, APP_Server (the application's remote server) generates login credential V_APP_Cred2 (the target login credential).
[0095] Step S52: The remote server of the application sends the target login credentials to the vehicle-side APP.
[0096] Specifically, step S52 is implemented as follows: APP_Server (the application's remote server) returns login credentials V_APP_Cred2 (the target login credentials) to V_APP (the vehicle-side APP).
[0097] After the application's remote server generates the target login credentials, it forwards the target login credentials to the vehicle's app via the mobile app.
[0098] Step S60: The vehicle-side APP logs into the application's remote server based on the target login credentials.
[0099] Specifically, after the vehicle-side APP obtains the target login credential sent by the application's remote server through the mobile APP, the user can successfully log in to the application's remote server on the vehicle-side using the target login credential. Simultaneously, V_APP (the vehicle-side APP) can subsequently use V_APP_Cred2 (the target login credential) to obtain relevant resources from APP_Server (the application's remote server).
[0100] Furthermore, such as Figure 9As shown, when the vehicle-side APP requests to log in to the application's remote server, the vehicle-side APP obtains a random number generated by the application's remote server, and generates a first message authentication code based on the random number and preset vehicle-side information. Prior to this, the following steps are also included: Step S61: Establish a near-field secure connection between the mobile app and the vehicle app; Step S62: Establish a remote secure channel between the mobile APP and the application's remote server, and the mobile APP logs into the application's remote server based on the remote secure channel.
[0101] 1. The mobile app M_APP has been pre-logged into the APP_Server, and both parties have a remote secure channel.
[0102] Before the vehicle-side app requests login to the application's remote server, communication connections need to be established between the mobile app and the vehicle-side app, as well as between the mobile app and the application's remote server. Specifically, before the vehicle-side app requests login to the application's remote server, the mobile app needs to pre-login to the application's remote server. The communication connection between the mobile app and the application's remote server is established via a remote secure channel. Subsequently, based on the remote secure channel, the mobile app can receive data sent by the application's remote server and forward it to the vehicle-side app, or receive data sent by the vehicle-side app and forward it to the application's remote server.
[0103] 2. The mobile M_APP and the vehicle V_APP have been pre-connected with a near-field security connection (e.g., Bluetooth, NFC, WIFI).
[0104] Before the vehicle-side app requests to log in to the application's remote server, the mobile app needs to establish a near-field secure connection with the vehicle-side app. Subsequently, based on the near-field secure connection, the mobile app can forward data sent by the application's remote server to the vehicle-side app.
[0105] Furthermore, such as Figure 10 As shown, the vehicle-side APP sends the preset vehicle-side information and the first message authentication code to the mobile-side APP, and the mobile-side APP sends the preset vehicle-side information and the first message authentication code to the application's remote server. Prior to this, the process also includes: Step S71: The vehicle-side APP randomly generates a PIN code and sets the PIN code as a QR code or barcode; Step S72: The mobile APP obtains the PIN code by scanning the QR code or the barcode, and establishes a data layer secure channel with the vehicle APP based on the near-field secure connection and the PIN code.
[0106] The specific implementation process is as follows: 1. V_APP (vehicle-side APP) randomly generates a PIN on the vehicle side, which is displayed in the form of a QR code or barcode.
[0107] 2. The M_APP (mobile app) scans the QR code or barcode displayed on the V_APP (vehicle app) on the mobile device to obtain the PIN.
[0108] 3. Based on the existing near-field secure connection, M_APP (mobile APP) and V_APP (vehicle APP) further establish a data layer secure channel according to the PIN. Based on the data layer secure channel, M_APP and V_APP can perform data layer secure communication in the near field.
[0109] Furthermore, such as Figure 11 As shown, the application's remote server performs facial recognition with the target user on the mobile app based on the first message authentication code, and then further includes: Step S81: The remote server of the application performs facial recognition with the target user on the mobile APP based on the first message authentication code; Step S82: If the facial recognition fails, the authentication will be rejected.
[0110] The application's remote server verifies the user's identity via facial recognition on the mobile app. If facial recognition fails, the user is deemed not to be the target user, and the authentication fails. To protect the user's information security, the login authentication will be rejected.
[0111] Furthermore, such as Figure 12 As shown, the information verification based on the vehicle login information of the application further includes: Step S91: Verify information based on the vehicle login information of the application; Step S92: If the information verification fails, the authentication will be rejected.
[0112] After facial recognition verification is successful, the application's vehicle login information will be further verified. If the application's vehicle login information verification fails, it proves that the vehicle device's verification service information does not match, that is, the current vehicle information is inconsistent with the information registered in the application's vehicle login information. In order to protect the user's information security, the login authentication will be rejected.
[0113] Furthermore, such as Figure 13 As shown, the application's remote server compares the first message authentication code and the second message authentication code, and then further includes: Step S101: The remote server of the application compares the first message authentication code and the second message authentication code; Step S102: If the first message authentication code and the second message authentication code are different, then the authentication is rejected.
[0114] The verification and comparison of the first and second message authentication codes is the second verification process of the application's remote server. It is performed after the user's facial recognition and the application's vehicle login information, which can prevent the leakage of temporary login credentials, improve the effect of security isolation, and narrow the risk surface.
[0115] Furthermore, such as Figure 14 As shown, the vehicle-side APP logs into the application's remote server based on the target login credentials, and then further includes: Step S111: The vehicle-mounted APP logs into the application's remote server based on the target login credentials; Step S112: The remote server of the application and the vehicle-side APP delete the random number, the first message authentication code, and the temporary login credential.
[0116] APP_Server (the application's remote server) and V_APP (the vehicle-side application) delete records of N (random number), V_MAC (first message authentication code), and V_APP_Cred (temporary login credential).
[0117] To protect user privacy, after each login to the application's remote server via the vehicle-side app, the "temporary login data," including the random number, the first message authentication code, and the temporary login credentials, is deleted. These data are then regenerated for subsequent logins, ensuring the accuracy of identity verification.
[0118] The technical effects that this invention can bring are as follows: 1. This invention utilizes a mobile phone to assist in vehicle identity security authentication. Even when the vehicle does not have an in-vehicle camera, it can still support facial recognition between the APP_Server (the application's remote server) and the user, while ensuring a good user experience.
[0119] 2. This invention uses facial recognition on a mobile phone to assist in obtaining V_Cred (temporary login credential), and then combines this with MAC verification on the vehicle to obtain the final V_Cred2 (target login credential), thus avoiding the mobile phone directly obtaining the vehicle's login credential. Even if the secure channel between the mobile phone and the vehicle is maliciously hijacked by a hacker, and the hacker obtains V_Cred (temporary login credential) but cannot obtain K (symmetric key), the leakage of login credential VCred2 (target login credential) can still be avoided, improving the effectiveness of security isolation and narrowing the risk surface.
[0120] 3. This invention uses a PIN code to construct a secure data channel between the M_APP (mobile app) and V_APP (vehicle app) to transmit authentication information, rather than directly obtaining authentication information by scanning a code, thus offering better privacy. Furthermore, even if security vulnerabilities exist in the underlying near-field security protocols (such as Bluetooth, NFC, or Wi-Fi), defenses can still be implemented based on data layer security.
[0121] 4. This invention uses a one-time symmetric key K to calculate the message authentication code, which has a smaller data volume and faster processing speed compared to digital signatures proven by devices.
[0122] 5. This invention does not require strong reliance on equipment verification to determine vehicle hardware information, nor does it require maintaining root certificates for different vehicle manufacturers and models, resulting in lower maintenance costs.
[0123] 6. This invention supports various types of terminal devices. Terminal devices with facial recognition capabilities (such as mobile phones and tablets) can assist other terminal devices without cameras (such as vehicles and watches) in identity authentication.
[0124] In addition, the present invention can be further extended, and the extension methods include: 1. In addition to assisting cars, it can also assist other terminal devices without screen displays (such as speakers) in identity authentication. The mobile phone scans a fixed barcode or QR code on the speaker device as a PIN, replacing a randomly generated PIN code.
[0125] 2. This invention can be combined with existing device verification schemes to determine the hardware information of the original device through device verification information, and has good compatibility.
[0126] 3. The digital signature algorithm of the present invention can be flexibly selected, such as the internationally used ECDSA, RSASA-PSS, etc.
[0127] 4. The message authentication code algorithm of the present invention can be flexibly selected, such as the internationally used HMAC, CMAC, etc.
[0128] 5. The certificate format of this invention can be flexibly selected, for example, using the internationally recognized X.509v3. The certificate chain security verification follows the internationally recognized chain verification method, and the trust relationship among the three is: V_ATT_RootCA -> V_ATT_InterCAChain -> V_ATT_Cert.
[0129] 6. The data layer security channel protocol of the present invention can be flexibly selected, such as internationally common SPAKE2, CPACE, SRP, SPAKE2PLUS, etc.
[0130] The main protection points of this invention are: 1. This invention utilizes a mobile phone to assist in vehicle identity security authentication. Even when the vehicle does not have an in-vehicle camera, it can still support facial recognition between the APP_Server and the user, while ensuring a good user experience.
[0131] 2. This invention uses facial recognition on a mobile phone to assist in obtaining V_Cred, and then combines this with MAC verification on the vehicle to obtain the final V_Cred2, thus avoiding the mobile phone directly obtaining the login credentials from the vehicle. Even if the secure channel between the mobile phone and the vehicle is maliciously hijacked by a hacker, and the hacker obtains V_Cred but cannot obtain K, the leakage of the login credential VCred2 can still be avoided, improving the effectiveness of security isolation and narrowing the risk surface.
[0132] 3. This invention uses a PIN code to construct a secure data channel between the M_APP and V_APP to transmit authentication information, rather than directly scanning a code to obtain authentication information, thus offering better privacy. Furthermore, even if security vulnerabilities exist in the underlying near-field security protocols (such as Bluetooth, NFC, and Wi-Fi), defenses can still be implemented based on data layer security.
[0133] Furthermore, such as Figure 15 As shown, based on the above-described security enhancement method for mobile phone-assisted vehicle identity authentication, the present invention also provides a corresponding security enhancement system for mobile phone-assisted vehicle identity authentication, wherein the security enhancement system for mobile phone-assisted vehicle identity authentication includes a vehicle-side APP 50, a remote server for the application 60, and a mobile phone APP 70: The vehicle-side APP 50 is used to obtain a random number generated by the remote server of the application, generate a first message authentication code based on the random number and preset vehicle-side information, and send the preset vehicle-side information and the first message authentication code to the mobile APP. The mobile APP 70 is used to send the preset vehicle information and the first message authentication code to the application's remote server; The application's remote server 60 is used to perform a first verification based on the preset vehicle terminal information and the first message authentication code. When the verification is successful, a temporary login credential is generated and the temporary login credential is sent to the mobile APP. Mobile APP 70 is used to send the temporary login credential to the vehicle-side APP; The vehicle-side APP 50 is used to send the symmetric key to the application's remote server based on the temporary login credential. The application's remote server 60 is used to generate a second message authentication code based on the preset vehicle-side information and the symmetric key, perform a second verification based on the first message authentication code and the second message authentication code, generate a target login credential when the verification is successful, and send the target login credential to the vehicle-side APP. The vehicle-side APP 50 is used to log in to the remote server of the application based on the target login credentials.
[0134] like Figure 15 As shown in this embodiment of the security enhancement system for mobile phone-assisted vehicle identity authentication, in this embodiment, the vehicle-side APP 50 includes: The first message authentication code generation module 501 is used to construct the vehicle login information and symmetric key of the application, obtain vehicle equipment information through the vehicle terminal system, and generate the first message authentication code according to the vehicle login information of the application, the symmetric key, the vehicle equipment information and the random number. The PIN code generation module 502 is used to randomly generate a PIN code and set the PIN code as a QR code or barcode; The first message authentication code sending module 503 is used to send the vehicle login information of the application, the vehicle equipment information, the random number and the first message authentication code to the mobile APP through the data layer security channel; The symmetric key sending module 504 is used to send the temporary login credential and the symmetric key to the remote server of the application.
[0135] In this embodiment, the remote server 60 of the application includes: The random number generation module 601 is used to generate random numbers and return the random numbers to the vehicle-side APP; The first verification module 602 is used to perform face recognition on the mobile APP based on the first message authentication code and the target user. If the face recognition is successful, the information is verified based on the vehicle login information of the application. If the information verification is successful, a temporary login credential is generated. The temporary login credential sending module 603 is used to associate the temporary login credential with the vehicle login information of the application, the vehicle equipment information, the random number and the first message authentication code, and send the temporary login credential to the mobile APP. The second message authentication code generation module 604 is used to generate a second message authentication code based on the temporary login credential, the vehicle login information of the application, the vehicle equipment information, the random number, the first message authentication code, and the symmetric key. The target login credential generation module 605 is used to compare the first message authentication code and the second message authentication code. If the first message authentication code and the second message authentication code are the same, a target login credential is generated. The target login credential sending module 606 is used to send the target login credential to the vehicle-side APP.
[0136] In this embodiment, the mobile APP 70 includes: The data layer secure channel construction module 701 is used to obtain the PIN code by scanning the QR code or the barcode, and establish a data layer secure channel with the vehicle-side APP based on the PIN code using a near-field secure connection. The first message authentication code forwarding module 702 is used to send the vehicle login information of the application, the vehicle equipment information, the random number and the first message authentication code to the remote server of the application through a remote secure channel. The temporary login credential forwarding module 703 is used to send the temporary login credential to the vehicle-side APP.
[0137] In summary, this invention provides a security enhancement method and system for mobile phone-assisted vehicle identity authentication. The method includes: when the vehicle-side APP requests to log in to the application's remote server, the vehicle-side APP obtains a random number generated by the application's remote server and generates a first message authentication code based on the random number and preset vehicle-side information; the vehicle-side APP sends the preset vehicle-side information and the first message authentication code to the mobile-side APP, and the mobile-side APP sends the preset vehicle-side information and the first message authentication code to the application's remote server; the application's remote server performs a first verification based on the preset vehicle-side information and the first message authentication code, and when the verification passes, the application's remote server... The device generates a temporary login credential and sends it to the mobile app. The mobile app then sends the temporary login credential to the vehicle app. The vehicle app sends a symmetric key to the application's remote server based on the temporary login credential. The application's remote server generates a second authentication code based on the preset vehicle information and the symmetric key. The application's remote server performs a second verification based on the first and second authentication codes. When the verification passes, the application's remote server generates a target login credential and sends it to the vehicle app. The vehicle app then logs in to the application's remote server based on the target login credential. This invention, even in vehicles without in-vehicle cameras, uses facial recognition on a mobile phone to assist in obtaining a temporary login credential, combined with verification from the application's remote server to obtain the target login credential. This avoids the mobile phone directly obtaining the vehicle's login credential, effectively improving the user experience and enhancing security isolation, thus ensuring the safety of user privacy information.
[0138] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal that includes that element.
[0139] Of course, those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware (such as a processor, controller, etc.). The program can be stored in a computer-readable storage medium, and when executed, it can include the processes described in the above method embodiments. The computer-readable storage medium can be a memory, magnetic disk, optical disk, etc.
[0140] It should be understood that the application of the present invention is not limited to the examples above. Those skilled in the art can make improvements or modifications based on the above description, and all such improvements and modifications should fall within the protection scope of the appended claims.
Claims
1. A security enhancement method for mobile phone-assisted vehicle identity authentication, characterized in that, The security enhancement method for mobile phone-assisted vehicle identity authentication is applied to the security enhancement system for mobile phone-assisted vehicle identity authentication, which includes a mobile phone APP, a remote server of the application, and a vehicle-side APP. The security enhancement method for mobile phone-assisted vehicle identity authentication includes: When the vehicle-side APP requests to log in to the application's remote server, the vehicle-side APP obtains a random number generated by the application's remote server and generates a first message authentication code based on the random number and preset vehicle-side information. The vehicle-side APP sends the preset vehicle-side information and the first message authentication code to the mobile APP, and the mobile APP sends the preset vehicle-side information and the first message authentication code to the application's remote server. The application's remote server performs a first verification based on the preset vehicle information and the first message authentication code. When the verification passes, the application's remote server generates a temporary login credential and sends the temporary login credential to the mobile APP. The mobile app sends the temporary login credential to the vehicle app, and the vehicle app sends the symmetric key to the application's remote server based on the temporary login credential. The application's remote server generates a second message authentication code based on the preset vehicle information and the symmetric key. The application's remote server performs a second verification based on the first message authentication code and the second message authentication code. When the verification passes, the application's remote server generates a target login credential and sends the target login credential to the vehicle-side APP. The vehicle-mounted app logs into the application's remote server using the target login credentials.
2. The security enhancement method for mobile phone-assisted vehicle identity authentication according to claim 1, characterized in that, When the vehicle-side APP requests to log in to the application's remote server, the vehicle-side APP obtains a random number generated by the application's remote server and generates a first message authentication code based on the random number and preset vehicle-side information. Prior to this, the process also includes: Establish a near-field secure connection between the mobile app and the vehicle app; A remote secure channel is established between the mobile app and the application's remote server, and the mobile app logs into the application's remote server based on the remote secure channel.
3. The security enhancement method for mobile phone-assisted vehicle identity authentication according to claim 2, characterized in that, The preset vehicle-side information includes the application's vehicle-side login information, symmetric key, and vehicle equipment information; When the vehicle-mounted APP requests to log in to the application's remote server, the vehicle-mounted APP obtains a random number generated by the application's remote server and generates a first message authentication code based on the random number and preset vehicle-mounted information, specifically including: When the vehicle-side APP requests to log in to the application's remote server, the application's remote server generates a random number and returns the random number to the vehicle-side APP; The vehicle-side APP constructs the vehicle-side login information of the application and the symmetric key, obtains the vehicle device information through the vehicle terminal system, and generates a first message authentication code based on the vehicle-side login information of the application, the symmetric key, the vehicle device information, and the random number.
4. The security enhancement method for mobile phone-assisted vehicle identity authentication according to claim 3, characterized in that, The vehicle-side APP sends the preset vehicle-side information and the first message authentication code to the mobile APP, and the mobile APP sends the preset vehicle-side information and the first message authentication code to the application's remote server. Prior to this, the process also includes: The vehicle-mounted APP randomly generates a PIN code and sets the PIN code as a QR code or barcode; The mobile app obtains the PIN code by scanning the QR code or the barcode, and establishes a data layer secure channel with the vehicle app based on the near-field secure connection and the PIN code.
5. The security enhancement method for mobile phone-assisted vehicle identity authentication according to claim 4, characterized in that, The vehicle-side APP sends the preset vehicle-side information and the first message authentication code to the mobile APP, and the mobile APP sends the preset vehicle-side information and the first message authentication code to the application's remote server, specifically including: The vehicle-side APP sends the application's vehicle login information, the vehicle equipment information, the random number, and the first message authentication code to the mobile APP through the data layer security channel; The mobile app sends the application's vehicle login information, the vehicle equipment information, the random number, and the first message authentication code to the application's remote server through the remote security channel.
6. The security enhancement method for mobile phone-assisted vehicle identity authentication according to claim 3, characterized in that, The application's remote server performs a first verification based on the preset vehicle information and the first message authentication code. When the verification passes, the application's remote server generates a temporary login credential and sends the temporary login credential to the mobile app, specifically including: The application's remote server performs facial recognition with the target user on the mobile APP based on the first message authentication code. If the facial recognition is successful, the application's vehicle login information is used for information verification. If the information verification is successful, the application's remote server generates a temporary login credential. The application's remote server associates the temporary login credential with the application's vehicle login information, the vehicle equipment information, the random number, and the first message authentication code, and sends the temporary login credential to the mobile app.
7. The security enhancement method for mobile phone-assisted vehicle identity authentication according to claim 6, characterized in that, The application's remote server performs facial recognition with the target user on the mobile app based on the first message authentication code, and then includes: If facial recognition fails, the authentication will be rejected.
8. The security enhancement method for mobile phone-assisted vehicle identity authentication according to claim 6, characterized in that, The information verification based on the vehicle login information of the application further includes: If the information verification fails, the authentication will be rejected.
9. The security enhancement method for mobile phone-assisted vehicle identity authentication according to claim 3, characterized in that, The mobile app sends the temporary login credential to the vehicle app. The vehicle app then sends the symmetric key to the application's remote server based on the temporary login credential. The application's remote server generates a second message authentication code based on the preset vehicle information and the symmetric key, specifically including: The mobile app sends the temporary login credential to the vehicle app; The vehicle-side APP sends the temporary login credential and the symmetric key to the application's remote server; The application's remote server generates a second message authentication code based on the temporary login credentials, the application's vehicle login information, the vehicle equipment information, the random number, the first message authentication code, and the symmetric key.
10. The security enhancement method for mobile phone-assisted vehicle identity authentication according to claim 1, characterized in that, The application's remote server performs a second verification based on the first message authentication code and the second message authentication code. When the verification passes, the application's remote server generates a target login credential and sends the target login credential to the vehicle-side APP, specifically including: The application's remote server compares the first message authentication code and the second message authentication code. If the first message authentication code and the second message authentication code are the same, a target login credential is generated. The application's remote server sends the target login credentials to the vehicle-side APP.
11. The security enhancement method for mobile phone-assisted vehicle identity authentication according to claim 10, characterized in that, The application's remote server compares the first message authentication code and the second message authentication code, and then further includes: If the first message authentication code and the second message authentication code are different, the authentication will be rejected.
12. The security enhancement method for mobile phone-assisted vehicle identity authentication according to claim 3, characterized in that, The vehicle-side APP logs into the application's remote server based on the target login credentials, and then further includes: The remote server of the application and the vehicle-side APP delete the random number, the first message authentication code, and the temporary login credential.
13. A security enhancement system for mobile phone-assisted vehicle identity authentication, characterized in that, The security enhancement system for mobile phone-assisted vehicle identity authentication includes a mobile app, a remote server for the app, and a vehicle-side app: The vehicle-side APP is used to obtain a random number generated by the remote server of the application, generate a first message authentication code based on the random number and preset vehicle-side information, and send the preset vehicle-side information and the first message authentication code to the mobile APP. A mobile app is used to send the preset vehicle information and the first message authentication code to the application's remote server. The application's remote server is used to perform a first verification based on the preset vehicle terminal information and the first message authentication code. When the verification is successful, a temporary login credential is generated and the temporary login credential is sent to the mobile APP. A mobile app is used to send the temporary login credentials to the vehicle-side app; The vehicle-side APP is used to send the symmetric key to the application's remote server based on the temporary login credentials; The application's remote server is used to generate a second message authentication code based on the preset vehicle-side information and the symmetric key, perform a second verification based on the first message authentication code and the second message authentication code, generate a target login credential when the verification passes, and send the target login credential to the vehicle-side APP. The vehicle-side APP is used to log in to the remote server of the application based on the target login credentials.
14. The security enhancement system for mobile phone-assisted vehicle identity authentication according to claim 13, characterized in that, The remote servers for the application include: A random number generation module is used to generate random numbers and return the random numbers to the vehicle-side APP.
15. The security enhancement system for mobile phone-assisted vehicle identity authentication according to claim 14, characterized in that, The vehicle-side app includes: The first message authentication code generation module is used to construct the vehicle login information and symmetric key of the application, obtain vehicle equipment information through the vehicle terminal system, and generate the first message authentication code based on the vehicle login information of the application, the symmetric key, the vehicle equipment information and the random number. A PIN code generation module is used to randomly generate a PIN code and set the PIN code as a QR code or barcode; The first message authentication code sending module is used to send the vehicle login information of the application, the vehicle equipment information, the random number and the first message authentication code to the mobile APP through the data layer security channel.
16. The security enhancement system for mobile phone-assisted vehicle identity authentication according to claim 15, characterized in that, Mobile apps include: The data layer secure channel construction module is used to obtain the PIN code by scanning the QR code or the barcode, and establish a data layer secure channel with the vehicle-side APP based on the PIN code using a near-field secure connection. The first message authentication code forwarding module is used to send the vehicle login information of the application, the vehicle equipment information, the random number and the first message authentication code to the remote server of the application through a remote secure channel.
17. The security enhancement system for mobile phone-assisted vehicle identity authentication according to claim 15, characterized in that, The remote server for the application also includes: The first verification module is used to perform facial recognition on the mobile APP based on the first message authentication code and the target user. If the facial recognition is successful, the information is verified based on the vehicle login information of the application. If the information verification is successful, a temporary login credential is generated. The temporary login credential sending module is used to associate the temporary login credential with the vehicle login information of the application, the vehicle equipment information, the random number and the first message authentication code, and send the temporary login credential to the mobile APP.
18. The security enhancement system for mobile phone-assisted vehicle identity authentication according to claim 13, characterized in that, The mobile app also includes: The temporary login credential forwarding module is used to send the temporary login credential to the vehicle-side APP.
19. The security enhancement system for mobile phone-assisted vehicle identity authentication according to claim 15, characterized in that, The vehicle-side app also includes: A symmetric key sending module is used to send the temporary login credential and the symmetric key to the remote server of the application.
20. The security enhancement system for mobile phone-assisted vehicle identity authentication according to claim 15, characterized in that, The remote server for the application also includes: The second message authentication code generation module is used to generate a second message authentication code based on the temporary login credential, the vehicle login information of the application, the vehicle equipment information, the random number, the first message authentication code, and the symmetric key. The target login credential generation module is used to compare the first message authentication code and the second message authentication code. If the first message authentication code and the second message authentication code are the same, a target login credential is generated. The target login credential sending module is used to send the target login credential to the vehicle-side APP.