Vehicle access control system and method

By combining the user's access device and biometrics for two-factor authentication, and utilizing Bluetooth Low Energy and UWB technologies, the security threats and user inconvenience issues of existing vehicle access systems are resolved, thereby improving both security and convenience.

CN122002239APending Publication Date: 2026-05-08NXP USA INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NXP USA INC
Filing Date
2025-09-29
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Existing vehicle access systems rely on single-factor authentication, which is vulnerable to security threats from unauthorized use, and conventional two-factor authentication methods may cause inconvenience to users.

Method used

Two-factor authentication is performed by combining the user's access device and the user's own biometrics (such as gait). Bluetooth Low Energy devices are used for initial scanning and UWB technology is used for distance measurement and authentication. Machine learning technology is used to identify the user's identity.

Benefits of technology

It improves the security of vehicle access, reduces the risk of unauthorized use, avoids inconvenience to users, and provides a convenient authentication process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122002239A_ABST
    Figure CN122002239A_ABST
Patent Text Reader

Abstract

Aspects of the present disclosure relate to systems and methods for controlling access to a vehicle. The system comprises: a transceiver device configured to send and receive signals to and from a user's access device, thereby providing an indication that the user is within a first range of the system; a sensing system comprising a camera, and configured to record a movement of the user in response to the indication; and a processor coupled to the sensing system and configured to analyze the movement, determine, based on the movement, whether the user is a known user of a set of known users, and in response to determining that the user is a known user of the set of known users, authenticate the user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to systems and methods for controlling access to vehicles. Background Technology

[0002] Conventional vehicle access systems and methods typically use communication technologies such as Bluetooth Low Energy (BLE) and Ultra Wideband (UWB) communication protocols, and use one or more digital keys stored in an access device (such as a key card, or other mobile device like a mobile phone) to provide access to the vehicle. Such systems and methods generally rely on a single-factor authentication process based on cryptographic verification of the digital keys (or multiple digital keys) stored in the access device.

[0003] Some access devices may offer a second level of protection, such as requiring the user to activate or "unlock" the device. However, an increasing number of access devices are configured to remain always on to minimize inconvenience for the user when approaching the vehicle. Therefore, unauthorized use of the access device (e.g., due to device theft) could pose a security threat.

[0004] Conversely, to avoid inconveniencing users, conventional two-factor authentication methods, such as requiring users to enter a personal identification number (PIN), may be undesirable. Summary of the Invention

[0005] According to a first aspect of this disclosure, a system is provided for controlling access to a vehicle and includes: a transceiver device configured to send signals to and receive signals from a user's access device, thereby providing an indication of the user within a first range of the system; a sensing system including a camera and configured to record movement of the user in response to the indication; and a processor coupled to the sensing system and configured to: analyze the movement, determine whether the user is a known user in a set of known users based on the movement, and authenticate the user in response to determining that the user is a known user in a set of known users.

[0006] Therefore, this system provides access rights based on a combination of a digital key in the access device and the user's own attributes or characteristics (especially attributes or characteristics related to the user's mode of movement).

[0007] In one or more embodiments, the system further includes an access controller configured to grant access to the vehicle in response to processor authentication of a user. In one or more embodiments, the system further includes an access controller configured to grant access to the vehicle in response to both receiving authentication of an access device and processor authentication of a user. Therefore, the access device can implement motion identification, or it can identify and directly provide a second factor for authentication.

[0008] Movement can include gait. Gait is a type of movement that is typically unique to one or a very small group of individuals. Therefore, using gait as a "biometric identifier" can uniquely identify an individual, or identify an individual with high confidence, and is particularly convenient because gait may be less dependent on environmental factors such as lighting compared to other biometric identifiers such as facial recognition.

[0009] In one or more embodiments, the transceiver device includes a Bluetooth Low Energy (BLE) device configured to authenticate access. The access controller may include a lock, and granting access includes unlocking the lock. Furthermore, the access controller may include a vehicle management system, and granting access includes enabling the vehicle management system.

[0010] In one or more embodiments, the processor is further configured to authenticate the user in response to receiving an indication that the user is a guest user, without determining whether the user is a known user in a set of known users. Therefore, the system may include a "bypass" function, for example, in cases where the system does not have sufficient data about possible users to authenticate the user with a sufficiently high degree of confidence.

[0011] According to another aspect of this disclosure, a method for controlling access to a vehicle is provided, comprising: receiving an indication from a user’s access device that the user is within a first range of the vehicle; in response to the indication, recording the user’s movement by a sensing system including a camera; analyzing the movement; determining, based on the movement, whether the user is a known user among a set of known users; and authenticating the user in response to determining that the user is a known user among a set of known users.

[0012] In one or more embodiments, receiving an indication from a user that an access device is within a first range of the system includes: scanning for the presence of the access device using a transceiver device; and exchanging a key with the access device. In one or more embodiments, the method further includes, in response to a processor authenticating the user, granting access to the vehicle by an access controller.

[0013] In one or more embodiments, determining whether a user is a known user in a set of known users includes using a trained neural network. The method may include recording further movements of the user by a sensing system. The method may additionally include modifying the weights associated with the trained neural network in response to further movement.

[0014] The method may further include an authentication access device; and in response to the processor authenticating the user and the authentication access device: access to the vehicle is granted by the access controller. In one or more embodiments, the authentication access device includes exchanging security information using a UWB device. In one or more embodiments, the method further includes receiving an indication that the user is a guest user, and in response, authenticating the user. Attached Figure Description

[0015] Please refer to the accompanying drawings, which are not necessarily drawn to scale, and in the accompanying drawings:

[0016] Figure 1 A vehicle access system consistent with one or more embodiments of this disclosure is shown;

[0017] Figure 2 A flowchart of a method according to one or more embodiments is shown;

[0018] Figure 3 A flowchart of a method according to one or more other embodiments is shown; and

[0019] Figure 4 A flowchart of a method according to one or more other embodiments is shown.

[0020] It should be noted that the figures are illustrative and not drawn to scale. For clarity and convenience in the figures, the relative dimensions and proportions of the parts have been shown by enlarging or reducing them in size. The same reference numerals are generally used to indicate corresponding or similar features in modified and different embodiments. Detailed Implementation

[0021] This disclosure specifically describes methods and systems for controlling access to vehicles. While conventional systems provide access control by means of a user device, typically through single-factor authentication using cryptographic verification of a digital key stored in or associated with the user device, embodiments of this disclosure also enhance the security of access control by using a second factor associated with the user themselves, rather than the user device. Therefore, this disclosure relates to and can be considered similar to two-factor authentication, which typically requires “what you own and what you know.” In the context of this disclosure, this can be rephrased as “what you own and your own characteristics.”

[0022] Figure 1 A vehicle access system consistent with one or more embodiments of this disclosure is illustrated. The figure shows a vehicle 100, which includes a system 110 for controlling access to the vehicle.

[0023] The access control system 110 includes several parts, components, or devices. Specifically, the system is equipped with a transceiver device 120, which is configured to send signals to and receive signals from the access device 105 of user 102. Typically, the transceiver device operates in a scanning mode, in which it periodically sends signals that can be received by any nearby access device. If the access device is within a first range (e.g., ... Figure 1 Within (as shown in 150), the access device receives the signal and responds by sending a response. Transceiver device 120 receives the response, and the two devices perform a handshake process. This handshake process may be followed by cryptographic verification through the exchange of a digital key typically stored in the access device. In other embodiments, cryptographic verification may not be performed at this stage. While this disclosure is not limited thereto, the Bluetooth Low Energy (BLE) signaling protocol is typically used to perform a scanning mode to identify the presence of nearby access devices and to perform signal exchange.

[0024] When the access control system 110 senses a potentially valid access device nearby, it activates the sensing system 130. That is, once a connection is established and encrypted, an identification process is triggered, and the vehicle begins monitoring the user as they approach. The sensing system includes one or more cameras that image the vicinity of the vehicle. The sensing system may include other sensors, such as motion sensors, radar, or other sensing devices. The range 160 of the sensing system may be similar to the range 150 of the transceiver device 120; conversely, since imaging is typically only required when a user approaches the vehicle, the range 160 may be slightly smaller, such as... Figure 1 As shown schematically in the diagram.

[0025] The sensing system is configured to record user movement, which typically includes one or more of walking speed, gait, movement patterns, posture, etc. The user movement is used to identify the user by executing an identification algorithm and comparing the results with a defined user matching threshold, in order to determine whether the user is a known user within a set of known users. Therefore, the access control system 110 includes a processor 140, one function of which is to run the identification algorithm to make this determination.

[0026] Those skilled in the art will understand that when the transceiver device implements the BLE communication protocol, the range of this communication is high enough (typically up to 30m) that the sensing system usually has sufficient time to detect movement and the processor has sufficient time to run the recognition algorithm before the user arrives at the vehicle. Generally, even if it takes a few seconds to run the recognition algorithm, the user will not experience any delay.

[0027] To identify whether a user is one of a set of known users, machine learning techniques are used in the inference phase. Therefore, a training phase is required before deploying the access control system in operation, during which the sensing system provides training data to the neural network. The sensing system used for the training phase can be a vehicle-associated sensing system, or a standalone sensing system if the training phase is performed remotely from the vehicle. In some embodiments, the access control system is not deployed for inference immediately upon the individual user's commencement of vehicle use. Instead, there may be a period during which the sensing system is used in conjunction with the neural network, or with machine learning algorithms in the processor, to train the system about the individual user and, in particular, to identify the user's sequence based on the user's gait or other movements. Non-limiting examples of other movements the system uses to identify a particular user are gestures such as a double wave, which the user can choose to perform to quickly train the system. Those skilled in the art will understand that this disclosure is not limited to this, and that the user can adopt other gestures, such as specific head or foot movements, to further accelerate the system's training phase. Once the system is trained, it can enter inference mode. From this point onward, the same capture devices (cameras, motion sensors, etc.) will not only collect data for analysis and recognition, but, under appropriate conditions, can also feed more training samples into the database for better accuracy results in the future. For example, samples obtained using the same devices during the inference phase can include additional information, and once a sample is confirmed as a "match," this additional information can be used sequentially to further improve the model's accuracy, subject to authorized access. Furthermore, once a match is confirmed, the sensing system can continue to collect data that can be used to improve the model. It should be understood that such model improvement may be subject to user settings, such as continuing training until the user deems it unnecessary, or that such improvement may be limited by certain memory constraints on the system.

[0028] In other embodiments, the movement associated with an individual user may have already been used by a similar system, such as a previously owned or used vehicle, allowing the model associated with that user to be directly transmitted to the processor. In this case, the access control system can be deployed to perform inference immediately upon the user's commencement of vehicle use.

[0029] The access controller may include, be part of, or interact with a vehicle management system 180. The vehicle management system can control the operation of the vehicle. Specifically, in the case of a gasoline or diesel-powered vehicle, the vehicle management system may include an ignition system that can be enabled or disabled. In embodiments where device authentication is required in addition to user authentication, the access controller can enable the vehicle management system to grant the user control over the vehicle, for example, by activating the emission system, once the user has been authenticated and the access device has also been authenticated. In the case of an electric vehicle (EV), the vehicle management system can control various functions within the vehicle and, in response to user authentication, and, where appropriate, to authentication of the access device, enable the user to interact with the vehicle, such as by starting the vehicle's motor. Therefore, as used herein, the term "access" should be interpreted broadly to include not only physical access (e.g., permission to enter the vehicle) but also other enabling mechanisms, such as allowing the user to operate or "access" electronic vehicle systems or engine systems.

[0030] The access controller may include lock 190 or other vehicle access security mechanisms. In response to authenticating a user, and, where appropriate, an access device, the access controller may grant access to the vehicle by, for example, unlocking said lock 190.

[0031] Vehicle control access systems are increasingly relying not only on long-range BLE communication and cryptographic authentication using digital keys, but also on short-range (e.g., Figure 1 The UWB communication shown is within the range 170). Therefore, in one or more embodiments, UWB technology is used to perform another authentication process. UWB technology, also known as pulse radio ultra-wideband (IR-UWB), is an RF communication technology that uses short-duration pulses for data communication. A key feature of IR-UWB technology is its ability to securely and accurately measure distances between two or more devices. Typical distance measurement methods are the so-called single-sided two-way ranging (SS-TWR) and two-sided two-way ranging (DS-TWR) methods. In addition to this ranging operation, UWB devices can also perform radar operations. Therefore, UWB devices can operate in ranging mode as well as in radar mode.

[0032] In ranging operation mode, frames are typically exchanged between the two devices via at least one antenna on each device, and at least SS-TWR operation (also known as ping-pong operation) is performed. Specifically, the channel impulse response (CIR) is estimated for both devices, timestamps are generated based on the CIRs of the two devices, and those timestamps are exchanged. Then, the time of flight (ToF) is calculated based on the timestamps, and the range (i.e., distance) is calculated based on the ToF. Alternatively, DS-TWR operation (also known as ping-pong operation) can be performed. It should be noted that angle of arrival (AoA) operation mode is similar to ranging mode, but AoA operation mode involves at least two antennas on one device. Specifically, in AoA operation mode, two phase values ​​associated with at least two CIRs are calculated for one device. Then, the phase difference of arrival (PDoA) is calculated based on the two phase values, and the AoA is calculated based on the PDoA. AoA operation mode can facilitate more accurate determination of the object's orientation and can therefore complement the ranging operation performed in ranging mode. As used herein, the ranging operation mode can therefore be extended to include an AoA operation mode, whereby when the device operates in ranging mode, it can optionally perform additional operations typically performed in AoA operation mode. Furthermore, as used herein, ranging mode may include operations based on so-called Time Difference of Arrival (TDoA) technology rather than Time of Flight (ToF) technology. TDoA technology is particularly suitable for real-time positioning operations. Generally, the term "ranging mode" encompasses all types of positioning operations based on UWB message exchange with external UWB communication devices. It should be noted that AoA calculation can be used in combination with both ToF calculation and TDoA calculation.

[0033] In UWB-based authentication, UWB ranging operation mode can be combined with cryptographic verification of a digital key stored in the access device to ensure that the device interacting with the vehicle-based system is indeed the user's access device and not a "man-in-the-middle" forwarding device. Those skilled in the art will recognize that many modern security threats stem from the use of "man-in-the-middle" forwarding devices to deceive the vehicle into believing that a remote (attacker) device is a local user's device. By combining ranging measurement with cryptographic authentication, UWB security authentication can significantly reduce or even eliminate this threat.

[0034] Now refer to Figure 2 , Figure 2A flowchart of method 200 according to one or more embodiments of the present disclosure is shown. Method 200 begins with the access control system scanning for the presence of any access device at 210. Transceiver device 120 is typically connected to access device 105 via BLE at 220, provided the access control system receives a signal from a user's access device 105 (e.g., a key card, or a mobile device such as a mobile phone). The two devices also perform cryptographic verification of the access device key by means of key exchange, typically as defined under a Bluetooth Low Energy (BLE) protocol established, for example, according to the IEEE 802.15.1 standard. Furthermore, once the access device has been verified as a potentially valid device, a motion identification step 230 is initiated. During this step, sensing system 130 typically records movement of the access device or movement in the vicinity of the access device in a 360° omnidirectional manner. During the sensing of such movement, the system records movement of the user's access device. For example, the access device may be held by the user or placed in the user's pocket. At 240, the processor runs a motion identification algorithm and determines whether the user has been identified. If the process identifies a user, and particularly if the process can determine that the user is still a known user among a set of known users whose mobility characteristics are known to the processor and who are considered authorized to use the vehicle, the processor authenticates the user as shown in step 250. In one or more embodiments, if the processor fails to identify the user, or in some embodiments, if the processor identifies the user as a known but unauthorized person, the system can provide an alert as shown in 260. The alert can take one of a variety of forms, such as, but not limited to, providing a message to the vehicle owner, temporarily or permanently deactivating the vehicle, providing audible or visual alarm signals, etc.

[0035] It should be understood that the authentication process is user-based, not device-based. This user authentication can be provided as the sole security measure, but in a preferred embodiment, it is combined with secondary authentication. Secondary authentication can be provided by the BLE communication exchange described above in step 220.

[0036] Figure 3 A method 300 according to one or more other embodiments of the present disclosure is illustrated. The method is similar to... Figure 2The method shown here will not describe the corresponding steps. However, if the processor cannot identify the user, at step 345, the system may attempt to identify whether the user is a guest user. The system may use one of various mechanisms to identify a guest user. For example, the system may message the vehicle owner to determine whether access should be granted at this time. Alternatively, and not limitingly, the system may provide the vehicle owner with an image of a user approaching and request the owner to confirm whether the approaching user is indeed a guest user. In other embodiments, the system may send a message to the access device requesting verification (e.g., a PIN code), which the guest user can provide, but an unauthorized user will not be able to provide. If the system can confirm that the user is a guest user, the method continues to grant access at step 250. In this embodiment, an alert 260 may be provided only if the user is not identified at step 240 and the determination at step 345 is that the user is not a guest user.

[0037] As Figure 3 A variation of the method shown, according to other embodiments, may include performing motion identification while surveying visitor users.

[0038] Figure 4 A method 400 according to one or more other embodiments of the present disclosure is illustrated. The method is similar to... Figure 3 The method shown will not be described in detail here. However, in this embodiment, if UWB authentication is available (as shown in step 432), a UWB-based authentication process is performed, such as the process described above, as shown in step 434.

[0039] The systems and methods described herein may be embodied, at least in part, by one or more computer programs, which may exist in various forms, both active and inactive, either within a single computer system or across multiple computer systems. For example, the computer program may exist as a software program consisting of program instructions in the form of source code, object code, executable code, or other formats for performing certain steps. Any of these formats may be embodied in compressed or uncompressed form on a computer-readable medium, which may include storage devices and signals.

[0040] As used herein, the term "computer" refers to any electronic device that includes a processor, such as a general-purpose central processing unit (CPU), a dedicated processor, or a microcontroller. A computer is capable of receiving data (input), performing a series of predetermined operations on the data, and thereby producing results (output) in the form of information or signals. Depending on the context, the term "computer" will mean (specifically) a processor or (more generally) a processor associated with a combination of related elements housed within a single chassis or housing.

[0041] The term "processor" or "processing unit" refers to a data processing circuit, which can be a microprocessor, coprocessor, microcontroller, microcomputer, central processing unit, field-programmable gate array (FPGA), programmable logic circuit, and / or any circuit based on operable instruction control signals (analog or digital signals) stored in memory. The term "memory" refers to one or more storage circuits, such as read-only memory, random access memory, volatile memory, non-volatile memory, static memory, dynamic memory, flash memory, cache memory, and / or any circuit storing digital information.

[0042] As used herein, "computer-readable medium" or "storage medium" can be any component that can contain, store, transmit, propagate, or transfer a computer program for use by or in conjunction with an instruction execution system, device, or apparatus. A computer-readable medium can be (e.g., but not limited to) an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, apparatus, or propagation medium.

[0043] It should be noted that the above embodiments have been described with reference to different subjects. In particular, some embodiments may have been described with reference to claims of the method class, while other embodiments may have been described with reference to claims of the device class. However, those skilled in the art will conclude from the foregoing that, unless otherwise indicated, any combination of features related to different subjects, particularly features of claims of the method class and features of claims of the device class, is also considered to be disclosed in this document, except for any combination of features belonging to one type of subject matter.

[0044] Furthermore, it should be noted that the drawings are schematic. Similar or identical elements are represented by the same reference numerals in different drawings. Additionally, it should be noted that, in order to provide a concise description of the illustrative embodiments, implementation details that are customary to those skilled in the art may not be described. It should be understood that in the development of any such implementation, as in any engineering or design project, numerous implementation-specific decisions must be made to achieve the developer's specific objectives, such as complying with system-related and business-related constraints, which may vary from implementation to implementation. Furthermore, it should be understood that such development work may be complex and time-consuming, but is merely a routine task of design, manufacture, and production for those of ordinary skill in the art who benefit from this disclosure.

[0045] Finally, it should be noted that those skilled in the art should be able to devise numerous alternative embodiments without departing from the scope of the appended claims. Any reference numerals placed between parentheses in the claims should not be construed as limiting the claims. The words “comprise(s)” or “comprising” do not exclude the presence of elements or steps other than those listed in the claims. The words “a(a)” or “an(an)” preceding an element do not exclude the presence of a plurality of such elements. The measures recited in the claims can be implemented by means of hardware comprising several distinct elements and / or by means of a suitably programmed processor. In device claims enumerating several components, several of these components can be embodied by one and the same hardware. The mere fact that certain measures recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used to exert an advantage.

[0046] List of reference numerals in the attached diagram:

[0047] 100 vehicles

[0048] 102 users

[0049] 105 Access Device

[0050] 110 Access Control System

[0051] 120 transceiver unit

[0052] 130 Sensing System

[0053] 140 processor

[0054] 150 Transceiver Unit Range

[0055] 160 Range of the sensing system

[0056] 170 locks

[0057] 180 Vehicle Management System

[0058] 190 Access Controller

[0059] 200, 300, 400 Methods according to various embodiments

[0060] Methods and steps for 210, 220, 230, 240, 250, and 260

[0061] 345 Methods and Steps

[0062] Methods and steps 432 and 434.

Claims

1. A system, characterized in that, Used to control access to the vehicle and includes: A transceiver device configured to send signals to and receive signals from a user's access device, thereby providing the user with an instruction within a first range of the system; A sensing system, the sensing system including a camera and configured to record the user's movement in response to the instruction; and A processor, coupled to the sensing system, and configured to: Analyze the movement, Based on the movement, determine whether the user is a known user in a group of known users, and In response to determining that the user is a known user in the set of known users, the user is authenticated.

2. The system according to claim 1, characterized in that, In addition, including: An access controller is configured to grant access to the vehicle in response to the processor authenticating the user.

3. The system according to claim 1, characterized in that, In addition, including: Access controller, The access controller is configured to grant access to the vehicle in response to both receiving authentication of the access device and the processor authenticating the user.

4. The system according to any one of the preceding claims, characterized in that, The movement includes gait.

5. The system according to claim 3 or any other claim dependent on claim 3, characterized in that, The transceiver device includes a Bluetooth Low Energy (BLE) device configured to authenticate the access device.

6. The system according to any one of claim 2 or 3, or any claim dependent on claim 2 or 3, characterized in that, The access controller includes a lock, and granting access includes unlocking the lock.

7. The system according to any one of claim 2 or 3, or any claim dependent on claim 2 or 3, characterized in that, The access controller includes a vehicle management system, and granting access includes enabling the vehicle management system.

8. The system according to any one of the preceding claims, characterized in that, The processor is further configured to authenticate the user in response to receiving an indication that the user is a guest user, without determining whether the user is a known user in a set of known users.

9. The system according to any one of the preceding claims, characterized in that, The processor includes a trained neural network.

10. A method for controlling access to a vehicle, characterized in that, include: Receive instructions from the user's access device within a first range of the vehicle; In response to the instruction, the user's movement is recorded by a sensing system including a camera; Analyze the movement; Based on the movement, determine whether the user is a known user in a group of known users; as well as In response to determining that the user is a known user in the set of known users, the user is authenticated.