Commercial vehicle electronic vehicle theft control method and system
Patent Information
- Application Number
- CN202611125898.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-28
- Publication Date
- 2026-08-28
AI Technical Summary
[0003]针对上述现有技术中机械锁止结构易被暴力拆解、防盗可靠性差、破解门槛低等问题,本领域技术人员试图通过增加机械锁止结构的强度和复杂度来提升物理防护能力,例如采用更高强度的合金材料或更复杂的锁止机构,但导致零部件成本和整车重量显著增加
[0016] The beneficial effects of this invention are: the complete elimination of mechanical locking structures, and the combination of triple electronic authentication and risk authentication verification process, which achieves a balance between security and verification efficiency.
Smart Images

Figure CN122646032A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vehicle anti-theft control technology, and in particular to an electronic vehicle anti-theft control method and system for commercial vehicles. Background Technology
[0002] Currently, the vehicle anti-theft solutions commonly used in commercial vehicles typically consist of a vehicle anti-theft device composed of a steering mechanism ESCL locking system, key authentication, and engine anti-theft authentication. It adopts a hybrid mode of electronic authentication and mechanical locking, in which the steering mechanism ESCL is responsible for the physical locking of the steering wheel, and the electronic system is responsible for identity verification and authentication management.
[0003] To address the issues of vulnerability to forced disassembly, poor anti-theft reliability, and low barrier to entry in existing technologies, those skilled in the art have attempted to enhance physical protection by increasing the strength and complexity of the mechanical locking structure, such as by using higher-strength alloy materials or more complex locking mechanisms. However, this significantly increases component costs and vehicle weight. Other solutions attempt to introduce more complex encryption algorithms at the electronic authentication level, such as increasing key length or employing multiple encryption protocols, but these fail to fundamentally eliminate the risk of physical damage to the mechanical structure. Since current improvements still retain the mechanical locking structure, they fail to completely eliminate the possibility of bypassing the anti-theft system through physical disassembly or forced destruction. Furthermore, while some solutions improve the security of electronic authentication, the authentication logic is relatively static and cannot dynamically adjust security strategies based on the vehicle's actual environment and potential risks. For example, using the same authentication strength in high-risk and low-risk areas makes it difficult to balance user experience and security, and the verification process is time-consuming and still carries the risk of being cracked. Summary of the Invention
[0004] To address the aforementioned technical problems, this invention provides a method and system for electronic vehicle anti-theft control of commercial vehicles.
[0005] To provide a basic understanding of some aspects of the disclosed embodiments, a brief summary is given below. This summary is not intended as a general commentary, nor is it intended to identify key / important components or to describe the scope of protection of these embodiments. Its sole purpose is to present some concepts in a simple form as a prelude to the detailed description that follows.
[0006] The present invention adopts the following technical solution: This invention provides an electronic vehicle anti-theft control method for commercial vehicles, comprising the following steps: In response to the start command, the first level of authentication is performed. The one-button start control unit verifies the authenticity of the key through wireless interaction with the smart key. After the first level of authentication is passed, the second level of authentication is performed. The one-button start control unit communicates encrypted with the electronic shift lever to verify the legality of the electronic shift lever. After the second level of authentication is passed, the third level of authentication is performed. The one-button start control unit communicates encrypted with the engine controller to verify the legitimacy of the engine controller. During the first-level certification process, dynamic certification parameters are collected and evaluated. Based on the results of the first to third-level certifications and the evaluation results of the dynamic certification parameters, a risk score is calculated, and the vehicle's safety level is determined according to the risk score.
[0007] The dynamic authentication parameters include: the matching degree between the vehicle's current location and the preset safe area, the matching degree between the current time and the preset safe time period, and the matching degree between the driver's behavioral characteristics and the historical behavior model. The process of collecting and evaluating dynamic authentication parameters includes the following steps: The vehicle's current location information is collected in real time by the vehicle positioning module and spatially matched with one or more preset safe areas stored locally or in the cloud to obtain a location matching score. The current time is obtained by the vehicle clock module and matched with the pre-stored preset safe time period to obtain the time matching score. The driver's operational behavior data is continuously collected by sensors within a preset time before the vehicle starts. The operational behavior data is input into a pre-trained behavior feature model, and the similarity with the historical behavior model is calculated to obtain a behavior matching score. The location matching score, time matching score, and behavior matching score are assigned preset weights and then summed to obtain a comprehensive dynamic authentication score. If the overall dynamic authentication score is lower than a preset first threshold, the dynamic authentication is deemed to have failed and an additional verification process is triggered. If the overall dynamic authentication score is higher than a preset second threshold, the dynamic authentication is deemed to have passed and subsequent one or more authentication steps can be simplified.
[0008] The process of calculating the risk score and determining the vehicle's safety level based on the risk score includes: After the first, second, and third level authentications are completed, the authentication results of each step are obtained, and a basic security score is assigned to each level of authentication result. Obtain the evaluation results of the dynamic authentication parameters, and map each matching score to a dynamic security score; The basic safety score and the dynamic safety score are weighted and summed according to preset weights to obtain the risk score. The risk score is then compared with multiple level thresholds to determine the vehicle's safety level.
[0009] The aforementioned electronic vehicle anti-theft control method for commercial vehicles further includes: granting different operating permissions to the vehicle according to the security level, wherein the operating permissions include: fully unlocked, speed-limited driving, power-limited driving, and completely prohibited from starting; The security levels include: The first safety level corresponds to a risk score greater than or equal to the low-risk threshold. At this level, the vehicle is fully unlocked and can be started, shifted, and driven normally. The second safety level corresponds to a risk score that is greater than or equal to the high-risk threshold and less than the low-risk threshold. In this case, the vehicle is allowed to start and shift gears, but the engine output power is limited to a preset percentage of the rated power, and the maximum speed is limited to a preset speed limit. The third safety level corresponds to a risk score that is less than the high-risk threshold. At this level, the vehicle is completely prohibited from starting, or although starting is allowed, shifting gears is prohibited, and the vehicle cannot leave.
[0010] The additional verification process includes: The one-click start control unit sends a verification request to the pre-bound mobile terminal; The verification application on the mobile terminal displays a preset gesture operation guide interface, requiring the user to draw a preset trajectory graphic or perform a preset touch gesture sequence on the touch screen of the mobile terminal. The mobile terminal collects the user's gesture trajectory, extracts its feature parameters and matches them with the locally stored gesture templates. If the matching degree exceeds a preset threshold, the successfully matched signature result is encrypted and sent back to the one-click start control unit. After the one-click start control unit decrypts and verifies that the signature is correct, it determines that the verification is successful. Then, the one-click start control unit corrects the comprehensive dynamic authentication score to a value higher than the first threshold. If the verification fails, the one-button start control unit maintains the overall dynamic authentication score unchanged and prohibits the vehicle from starting or maintains the restricted driving mode.
[0011] During the second and third level authentication processes, the encrypted communication includes the following steps: The one-button start control unit sends a request verification message to the electronic gear shift lever or the engine controller. In response to the request verification message, the electronic gear shift lever or the engine controller generates a random number and sends it to the one-button start control unit. The one-button start control unit performs encryption calculations on random numbers according to the AES128 CMAC algorithm, generates ciphertext, and sends the encrypted data back to the electronic gear shift lever or the engine controller. The electronic gear shift lever or the engine controller performs encryption calculation on the same random number according to the AES128 CMAC algorithm to generate reference ciphertext. After confirming that the encrypted data returned by the one-key start control unit has been successfully received, the received ciphertext is compared with the reference ciphertext. If the two are consistent, the authentication is deemed to have passed; if they are inconsistent, the authentication is deemed to have failed. The second level of authentication also includes: once the electronic shift lever passes the authentication, the electronic shift lever is authorized to send shift requests via the CAN bus; The third level of authentication also includes: once the engine controller passes the legality authentication, the one-button start control unit is allowed to send a start request to the engine.
[0012] The aforementioned electronic vehicle anti-theft control method for commercial vehicles further includes: when the security level is a second security level or a third security level, responding to a re-verification command to perform dynamic password verification, wherein the dynamic password verification includes the following steps: The one-button start control unit sends a re-verification request to the pre-bound mobile terminal. The re-verification request includes the vehicle's current location information, timestamp, and a randomly generated challenge code. The mobile terminal generates a one-time dynamic password with a preset validity period based on the time synchronization algorithm shared with the one-click start control unit and the challenge code, and displays it on the screen. When the one-button start control unit receives the dynamic password entered by the user on the vehicle's central control screen or instrument panel, it compares the dynamic password entered by the user with the password synchronously calculated on the local end. If they match, the verification is deemed successful, and the security level is reset to the first security level.
[0013] The operational behavior data includes the initial force curve of pressing the accelerator, the angular velocity distribution of turning the steering wheel, and the sequence of actions to adjust the seat after sitting down.
[0014] A commercial vehicle electronic anti-theft control system is provided, comprising: The Level 1 authentication module is used to perform Level 1 authentication in response to the start command. The one-button start control unit verifies the authenticity of the key through wireless interaction with the smart key. The secondary authentication module is used to perform the second-level authentication after the first-level authentication is passed. The one-button start control unit communicates encrypted with the electronic shift lever to verify the legality of the electronic shift lever. The three-level authentication module is used to perform the third-level authentication after the second-level authentication is passed. The one-button start control unit communicates encrypted with the engine controller to verify the legitimacy of the engine controller. The safety authentication module is used to collect and evaluate dynamic authentication parameters during the first-level authentication process, calculate a risk score based on the results of the first to third-level authentication and the evaluation results of the dynamic authentication parameters, and determine the safety level of the vehicle based on the risk score.
[0015] The dynamic authentication parameters include: the matching degree between the vehicle's current location and the preset safe area, the matching degree between the current time and the preset safe time period, and the matching degree between the driver's behavioral characteristics and the historical behavior model. The security authentication module includes: The location matching unit is used to collect the vehicle's current location information in real time through the vehicle positioning module, and perform spatial matching with one or more preset safe areas stored locally or in the cloud to obtain a location matching score. The time matching unit is used to obtain the current time through the vehicle clock module and match it with the pre-stored preset safe time period to obtain the time matching score. The behavior matching unit is used to continuously collect the driver's operation behavior data within a preset time before the vehicle starts through sensors, input the operation behavior data into a pre-trained behavior feature model, calculate the similarity with the historical behavior model, and obtain the behavior matching score. The authentication scoring unit is used to assign preset weights to the location matching score, time matching score and behavior matching score respectively, and then perform weighted summation to obtain a comprehensive dynamic authentication score; The dynamic determination unit is used to determine that dynamic authentication has failed and trigger an additional verification process if the overall dynamic authentication score is lower than a preset first threshold, and to determine that dynamic authentication has passed if the overall dynamic authentication score is higher than a preset second threshold, and to allow simplification of one or more subsequent authentication steps.
[0016] The beneficial effects of this invention are: the complete elimination of mechanical locking structures, and the combination of triple electronic authentication and risk authentication verification process, which achieves a balance between security and verification efficiency.
[0017] In terms of security, it completely avoids the risk of physical cracking of the mechanical locking structure, and eliminates anti-theft failure or false triggering caused by mechanical wear and other reasons. At the same time, by incorporating dynamic parameters such as location, time, and driver behavior characteristics into the risk assessment, and combining them with the results of three-level electronic authentication for comprehensive scoring, it can dynamically grant differentiated permissions according to the actual risk level, significantly improving security.
[0018] In terms of verification efficiency, the collection and evaluation of dynamic authentication parameters run in parallel with the three-level authentication process as an independent branch. When the overall dynamic authentication score exceeds a preset threshold, subsequent authentication steps can be simplified, further shortening the overall verification time. In addition, the pure software implementation requires no hardware modification, reducing the cost per vehicle. Attached Figure Description
[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0020] Figure 1 This is a flowchart illustrating an electronic vehicle anti-theft control method for commercial vehicles according to the present invention. Figure 2 This is a schematic diagram of the encrypted communication process of the present invention; Figure 3 This is a schematic diagram of the process for collecting and evaluating dynamic authentication parameters according to the present invention. Detailed Implementation
[0021] The embodiments of the present invention will now be described in detail with reference to the accompanying drawings. It should be understood that the described embodiments are merely some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0022] like Figure 1 As shown in some illustrative embodiments, a method for electronic vehicle anti-theft control of a commercial vehicle is provided, including the following steps: Triple electronic authentication process: 101: In response to the startup command, perform the first level of authentication, namely the key authentication process.
[0023] When the vehicle is off, the push-button start control unit continuously monitors the status of the push-button start switch. If the push-button start switch is detected to be pressed, the first-level authentication process, namely the key authentication process, is immediately initiated in response to the start command. The push-button start control unit verifies the authenticity of the key through wireless interaction with the smart key. Specifically, the push-button start control unit transmits an encrypted interaction signal to the smart key via the vehicle's low-frequency antenna. After receiving the signal, the smart key chip decrypts and performs calculations using its internally stored key, and sends the calculation result back to the push-button start control unit. The push-button start control unit compares the returned result with the locally pre-stored key data to verify the authenticity of the smart key.
[0024] 102: Determine the validity of the key. If the key is valid, proceed to step 103; otherwise, proceed to step 104.
[0025] 103: Key authentication successful, vehicle powered on. If the result of step 102 indicates that the key is valid, then the first level of authentication is successful. At this time, the one-button start control unit switches the vehicle power supply to the IG ON state, i.e., the vehicle is powered on, preparing for the subsequent second level of authentication process.
[0026] 104: Key authentication failed, vehicle power remains off. If the result of step 102 is that the key is invalid, the first level of authentication fails. At this time, the one-button start control unit prevents the vehicle power from being connected, the vehicle remains in a power-off state, and cannot enter the subsequent authentication process, thus preventing unauthorized vehicle starting behavior in the first step.
[0027] 105: After the first level of certification is passed, the second level of certification, namely the gear shift lever certification process, will be executed.
[0028] After the first level of authentication is passed and the vehicle is successfully powered on, the one-button start control unit immediately initiates the second level of authentication process, namely the gear shift lever authentication process. In this process, the one-button start control unit communicates encrypted with the electronic gear shift lever to verify its legitimacy.
[0029] 106: The one-button start control unit determines the validity of the electronic gear shift lever based on the verification result of the encrypted communication. If the electronic gear shift lever is valid, proceed to step 107; otherwise, proceed to step 108.
[0030] 107: The electronic gear shift lever has passed legal certification, and the lever has been unlocked and authorized.
[0031] If the result of step 106 indicates that the electronic gear shift lever is valid, then the second-level authentication is successful. At this point, the electronic gear shift lever performs an electronic unlocking operation, releasing its internal lock. The unlocked gear shift lever is granted permission to send shift requests via the CAN bus, enabling it to convert the driver's shifting intentions into valid CAN bus signals and send them to the vehicle network.
[0032] 108: Electronic shift lever authentication failed; the lever is prohibited from sending requests.
[0033] If the result of step 106 is that the electronic shift lever is invalid, the second-level authentication fails. At this time, the electronic shift lever remains locked and is prohibited from sending any shift request via the CAN bus. Even if the driver operates the shift lever, the signal it sends will not be responded to by the vehicle network.
[0034] 109: After passing the second-level certification, the third-level certification, namely the engine certification process, is carried out.
[0035] After the second level of authentication is passed and the electronic gear shift lever is successfully unlocked, the one-button start control unit immediately initiates the third level of authentication process, namely the engine authentication process. In this process, the one-button start control unit communicates encrypted with the engine controller to verify the legitimacy of the engine controller.
[0036] 110: The one-button start control unit determines the legitimacy of the engine controller based on the verification result of the encrypted communication. If the engine controller is legitimate, proceed to step 111; otherwise, proceed to step 112.
[0037] 111: Engine controller validity authentication passed, start request allowed.
[0038] If the judgment result of step 110 is that the engine controller is valid, then the third-level authentication is passed. At this time, the one-button start control unit is authorized to send a start request signal to the engine, allowing the engine to start and run normally.
[0039] 112: Engine controller validity authentication failed; startup request prohibited.
[0040] At this point, the triple electronic authentication process is complete. Only when all three authentications—key authentication, gear shift lever authentication, and engine authentication—pass can the vehicle be started, shifted, and driven normally. Failure in any one of these authentication steps will prevent the vehicle from entering a drivable state, thus achieving purely electronic vehicle anti-theft protection.
[0041] During the process of Level 2 and Level 3 certification, such as Figure 2 As shown, encrypted communication includes the following steps: 201: The one-button start control unit sends a verification request message to the electronic shift lever or engine controller, indicating that the authentication process is about to begin.
[0042] 202: The electronic shift lever or engine controller responds to the verification request message, generates a random number, and sends it to the one-button start control unit; 203: After receiving the random number, the one-button start control unit encrypts the random number according to the AES128 CMAC algorithm, generates the corresponding ciphertext, and sends the encrypted data to the electronic shift lever or engine controller. 204: The electronic gear shift lever or engine controller uses the AES128 CMAC algorithm to encrypt the same random number it previously generated, generating a local reference ciphertext. 205: The electronic shift lever or engine controller determines whether it has successfully received the encrypted data returned by the one-button start control unit. If the reception is successful, proceed to step 206; if the reception fails, the authentication is directly determined to have failed.
[0043] 206: The electronic shift lever or engine controller compares the received ciphertext with the locally generated reference ciphertext. If they match, the authentication is deemed successful; otherwise, the authentication is deemed unsuccessful.
[0044] The present invention also includes: 113: During the first-level authentication process, collect and evaluate dynamic authentication parameters.
[0045] During the first-level authentication process, the one-click start control unit simultaneously initiates the dynamic authentication parameter collection and evaluation process, running as an independent branch task in parallel with the main authentication process. This process uses environmental and behavioral information to assess the security risk level of the current scenario in real time, providing a basis for subsequent permission decisions. The dynamic authentication parameters include: the matching degree between the vehicle's current location and the preset safe area, the matching degree between the current time and the preset safe time period, and the matching degree between the driver's behavioral characteristics and historical behavioral models.
[0046] like Figure 3 As shown, step 113 specifically includes: 1131: Location matching degree assessment.
[0047] The vehicle's current location information, such as latitude and longitude coordinates, is collected in real time by the onboard positioning module and spatially matched with one or more preset safe zones stored locally or in the cloud to obtain a location matching score. Preset safe zones can be trusted locations set by the vehicle owner, such as home address, work address, or frequently visited parking lots. A higher matching score indicates a safer geographical environment for the vehicle, resulting in a higher location matching score.
[0048] For example, car owners can set a center point, such as the latitude and longitude of their home address, and a radius, such as 500 meters, through the in-vehicle central control screen or mobile app, forming a circular safety zone. If the distance between the vehicle's current position and this center point is less than the radius, it is considered to have fallen within this safety zone. The scoring method is as follows: If the vehicle's current location is within any preset safe area, the location matching score is full, for example, 100 points; If the vehicle's current position is not within any safe zone but is within the buffer zone, and the distance to the nearest safe zone boundary is less than the preset buffer zone radius, the score is calculated using a linearly decreasing formula: Score = Full score × (1 - Distance / Buffer radius); For example, if the distance from the boundary is 50 meters and the buffer zone radius is 200 meters, then the score is 100 × (1 - 50 / 200) = 75 points.
[0049] If the distance between the vehicle's current location and all safe zones exceeds the buffer radius, the location matching score is 0.
[0050] 1132: Time matching assessment.
[0051] The vehicle clock module obtains the current time and matches it with a pre-stored safe time period to obtain a time matching score. The preset safe time period can be the high-frequency time period of the car owner's daily use, such as mornings and evenings on weekdays, and daytime on weekends. If the current time falls within the safe time period, the time matching score is higher; if it is late at night or during irregular times, the score is lower.
[0052] For example, car owners can manually set daily safe usage periods via the in-vehicle central control screen or a mobile app, such as 06:00-09:00 and 17:00-22:00 on weekdays and 08:00-23:00 on weekends. Alternatively, the system can record vehicle start-up and shutdown times over a long period and automatically identify high-frequency usage periods through statistical analysis and clustering algorithms. For instance, if the system finds that the vehicle was started more than 90% of the time on weekdays between 7:30-8:30 am and 18:00-20:00 pm in the past three months, it will automatically mark these periods as safe usage periods.
[0053] If the current time falls within any matching safe time interval, the time matching score is full, for example, 100 points.
[0054] If the current time is not within the safe period, but the time difference with the nearest safe period boundary is less than the preset buffer time, the score will be calculated using a linearly decreasing formula: Score = Full score × (1 - Time difference / Buffer duration); For example, if the safe period ends at 22:00, the current time is 22:15, the time difference is 15 minutes, and the buffer time is 30 minutes, then the score is 100×(1 - 15 / 30) = 50 points.
[0055] If the time difference between the current moment and all safe time periods exceeds the buffer duration, the time matching score is 0.
[0056] 1133: Behavioral matching assessment.
[0057] The system continuously collects driver behavior data within a preset timeframe before vehicle startup using sensors. This data is then input into a pre-trained behavioral feature model, and the similarity score between the model and historical behavior models is calculated to obtain a behavior matching score. The behavioral data includes the initial force curve of pressing the accelerator, the angular velocity distribution of turning the steering wheel, and the sequence of actions for adjusting the seat after sitting down.
[0058] The one-button start control unit continuously collects driver behavior data within a preset timeframe before vehicle start-up using sensors deployed on the steering wheel, accelerator pedal, brake pedal, and seat. The initial accelerator pedal pressure curve reflects the driver's acceleration habits upon starting; the angular velocity distribution of the steering wheel reflects the driver's steering style; and the sequence of seat adjustments after settling in reflects the driver's personalized settings. This behavioral data is input into a pre-trained behavioral feature model, and similarity is calculated between it and historical behavioral models to obtain a behavioral matching score. Commonly used calculation methods include Mahalanobis distance, probability density method, and reconstruction error method.
[0059] Historical behavior models are trained on long-term driver operation data using machine learning algorithms, enabling them to accurately identify individual driver characteristics.
[0060] 1134: The location matching score, time matching score, and behavior matching score are assigned preset weights and then summed to obtain a comprehensive dynamic authentication score, which serves as the evaluation result of the dynamic authentication parameters.
[0061] Preset weights: Location matching score weight W1 = 0.4; Time matching score weight W2 = 0.3; Behavioral matching score weight W3 = 0.3. Overall dynamic authentication score = Location matching score × W1 + Time matching score × W2 + Behavioral matching score × W3.
[0062] 1135: If the overall dynamic authentication score is lower than the preset first threshold, the dynamic authentication is deemed to have failed and an additional verification process is triggered.
[0063] 1136: If the overall dynamic authentication score exceeds a preset second threshold, the dynamic authentication is deemed successful, and simplification of one or more subsequent authentication steps is permitted. This means simplification of subsequent Level 2 and / or Level 3 authentication is allowed to shorten the overall verification time. Simplification methods include one or more combinations of the following: Skip some encrypted communication rounds: During the challenge response process of gear shift lever authentication or engine authentication, reduce the number of handshakes, that is, the authenticator directly sends an authorization token, and the authenticated party is considered to have passed the authentication after verifying the validity of the token, without the need to generate and exchange random numbers; Shorten key length or encryption strength: Temporarily downgrade the key length of the AES128 CMAC algorithm to AES64 or use the lightweight HMAC algorithm to reduce encryption and decryption time; Merged Authentication Process: The second and third level authentications are combined into a single joint authentication step. This involves the electronic gear shifter and engine controller jointly generating a composite response message, which is sent to the keyless start control unit in one go. This composite response message contains the identities and encrypted signatures of both parties. Upon receiving it, the keyless start control unit verifies the identities of both parties in a single process, compressing the original two authentication steps into a single parallel authentication.
[0064] Cache authentication results: If the vehicle starts continuously within a short period of time, such as 15 minutes, and the comprehensive dynamic authentication score is higher than the second threshold each time, the electronic shift lever or engine controller can cache the previous authentication result.
[0065] 1137: If the overall dynamic authentication score is between the first threshold and the second threshold, the complete triple authentication process remains unchanged.
[0066] By collecting and evaluating dynamic authentication parameters in parallel during the key authentication phase, both security and verification efficiency are balanced. Location, time, and behavioral characteristics corroborate each other, effectively identifying abnormal startup scenarios. Even if all three electronic authentications pass, a low overall dynamic authentication score can still be intercepted through additional verification or subsequent risk scoring mechanisms, fundamentally preventing illegal driving after key theft or duplication. The collection and evaluation of dynamic parameters run concurrently with the main authentication process as a branch process, without consuming additional time. When the overall dynamic authentication score exceeds a second threshold, subsequent authentication steps can be proactively simplified, reducing user waiting time and improving the user experience.
[0067] In step 1135, when the overall dynamic authentication score is lower than a preset first threshold, it is determined that the current startup scenario has a high risk, triggering an additional verification process: First, the one-button start control unit sends a verification request to the pre-bound mobile terminal. This verification request includes the vehicle's current location information, timestamp, and a randomly generated session identifier to ensure the traceability of the verification process.
[0068] After receiving a verification request, the mobile terminal automatically wakes up or launches the pre-installed verification application and displays a preset gesture operation guide interface, requiring the user to draw a preset trajectory graphic or perform a preset touch gesture sequence on the mobile terminal's touch screen. The preset trajectory graphic can be a user-defined personalized signature pattern, a specific shape, or a custom combination of swiping gestures. The mobile terminal collects the user's gesture trajectory, including the coordinate sequence of touch points, movement speed, stroke order and other feature parameters. It extracts the feature parameters and matches them with the locally stored gesture template. The matching algorithm can use feature-based similarity calculation. If the matching degree exceeds the preset threshold, the successfully matched signature result is encrypted and sent back to the one-click start control unit. After the one-button start control unit decrypts and verifies the signature, it determines that the verification is successful. Then, the one-button start control unit will correct the comprehensive dynamic authentication score to a value higher than the first threshold, so that the overall risk rating returns to the safe range, allowing the vehicle to start and drive normally. If the verification fails, the one-button start control unit will maintain the overall dynamic authentication score unchanged and prohibit the vehicle from starting or maintain the restricted driving mode to prevent the vehicle from leaving illegally.
[0069] The additional verification process provides a correction channel. When the overall dynamic authentication score is low due to non-malicious reasons, such as location signal drift or abnormal behavior caused by driver illness, legitimate users can still prove their identity through additional verification, avoiding vehicle malfunction due to system misjudgment. Moreover, the additional verification process can be dynamically activated according to the actual risk level, intervening only when the overall dynamic authentication score is below the threshold, without affecting authentication efficiency in normal scenarios.
[0070] The present invention also includes: 114: Based on the results of Level 1 to Level 3 certifications and the evaluation results of dynamic certification parameters, a risk score is calculated, and the vehicle's safety level is determined according to the risk score. Specifically, this includes: First, after completing the first, second, and third level authentications, obtain the authentication results for each step and assign a basic security score to each authentication result.
[0071] The basic security score reflects the pass / fail status of each of the three electronic certification levels. Each level is either passed or failed. For example, for Level 1 certification, a pass assigns a basic security score of A1 (e.g., 40 points), while a failure assigns 0 points. For Level 2 certification, a pass assigns a basic security score of A2 (e.g., 30 points), while a failure assigns 0 points. For Level 3 certification, a pass assigns a basic security score of A3 (e.g., 30 points), while a failure assigns 0 points. The total basic security score is 100 points. If any level fails, that level receives a score of 0, and the total score decreases accordingly.
[0072] Then, the evaluation results of the dynamic authentication parameters are obtained, and each matching score is mapped to a dynamic security score. The evaluation results of the dynamic authentication parameters include three matching scores: location matching score, time matching score, and behavior matching score, each ranging from 0 to 100. When mapping the matching scores to dynamic security scores, a linear mapping can be used to adjust their sensitivity to the final risk score.
[0073] Finally, the basic safety score and the dynamic safety score are weighted and summed according to preset weights to obtain the risk score. The risk score is then compared with multiple level thresholds to determine the vehicle's safety level.
[0074] The weights can be adjusted according to the security strategy. For example, the weight of the sum of basic security scores is 0.6, and the weight of the sum of dynamic security scores is 0.4. The sum of dynamic security scores is the average of the three dynamic security scores. Then, the risk score = (A1 + A2 + A3) × 0.6 + [(D1 + D2 + D3) / 3] × 0.4. D1 is the dynamic security score corresponding to the location matching score, D2 is the dynamic security score corresponding to the time matching score, and D3 is the dynamic security score corresponding to the behavior matching score.
[0075] The risk score ranges from 0 to 100 points, with preset thresholds: a high-risk threshold TH1 and a low-risk threshold TH2. For example, the high-risk threshold TH1 is 30 points, and the low-risk threshold TH2 is 80 points. The risk score is compared with the threshold to determine the vehicle's safety level.
[0076] The security levels are as follows: Level 1, corresponding to a risk score greater than or equal to the low-risk threshold; Level 2, corresponding to a risk score greater than or equal to the high-risk threshold and less than the low-risk threshold; and Level 3, corresponding to a risk score less than the high-risk threshold.
[0077] The present invention also includes: 115: Based on the security level, grant different operating permissions to the vehicle, including: fully unlocked, speed-limited driving, power-limited driving, and completely prohibited from starting.
[0078] When the safety level is at the highest level, the vehicle is fully unlocked and can be started, shifted, and driven normally. When the risk score reaches or exceeds the low-risk threshold, indicating that the current starting scenario is extremely safe, the one-button start control unit sends a full unlock command to the engine controller, allowing the engine to start normally and output full power; it also sends a full unlock command to the electronic gear shift lever, allowing it to send any shift request via the CAN bus; simultaneously, all speed limits are lifted. With full unlocked access, the driver can start, shift, and drive normally, providing a completely consistent user experience.
[0079] When the safety level is Level 2, the vehicle is allowed to start and shift gears, but the engine output power is limited to a preset percentage of the rated power, and the maximum speed is limited to a preset speed limit. When the risk score is between the high-risk threshold and the low-risk threshold, it indicates that there are some suspicious factors in the current starting scenario, but it has not yet reached the high-risk level. At this time, the vehicle is allowed to start and shift gears, but the vehicle's performance is restricted: a power limiting command is sent to the engine controller, limiting the engine's maximum output torque to a preset percentage of the rated torque, for example, 60% to 80% of the rated torque; a speed limiting command is sent to the engine controller, limiting the vehicle's maximum speed to a preset speed limit, such as 60 km / h to 80 km / h. Under this safety level, although the vehicle can be driven, its power performance and speed are significantly constrained, insufficient to support long-distance high-speed driving or aggressive driving, thus allowing legitimate users to move the vehicle in emergencies while effectively limiting the vehicle's escape ability after being illegally stolen.
[0080] When the safety level is level three, the vehicle is completely prohibited from starting, or starting is permitted but shifting gears is prohibited, and the vehicle cannot leave. When the risk score is below the high-risk threshold, it indicates that the current starting scenario poses an extremely high safety risk. A start request signal is sent to the engine controller, but the engine cannot ignite and the vehicle remains off. Alternatively, the engine is allowed to start, but a command to prohibit shifting is sent to the electronic gear shift lever. In this case, although the engine can idle, the transmission remains in neutral or park, and the vehicle cannot be engaged in forward or reverse gear, thus preventing it from leaving its current location.
[0081] This invention establishes three security levels, allowing limited vehicle use in medium-risk scenarios. Even if a legitimate user's risk score is accidentally lowered, they can still drive at low speeds for short distances, avoiding the embarrassing situation where the vehicle becomes completely unusable due to system misjudgment. The second security level's restriction strategy prevents thieves from escaping at high speeds or engaging in dangerous driving, even if they bypass electronic authentication, significantly reducing the vehicle's value for theft. The third security level's gear-shifting prohibition strategy fundamentally blocks the possibility of vehicle movement. Furthermore, the power limit percentage and speed limit can be dynamically adjusted based on the specific risk score, rather than remaining fixed, making permission granting more reasonable. As the risk score changes, the security level can switch between different levels, achieving continuous response to the security status.
[0082] The present invention also includes: 116: When the security level is Level 2 or Level 3, dynamic password verification is performed in response to the re-verification command. This includes the following steps: First, in response to the re-verification command, the one-click start control unit sends a re-verification request to the pre-bound mobile terminal. The re-verification request includes the vehicle's current location information, a timestamp, and a randomly generated challenge code. The vehicle's current location information is used to assist the user in confirming the vehicle's identity; the current timestamp is used for time synchronization calibration; and the challenge code is used to prevent replay attacks.
[0083] Upon receiving a re-authentication request, the mobile terminal generates a one-time dynamic password with a preset validity period based on the time synchronization algorithm and challenge code shared with the one-click start control unit, and displays it on the screen. Due to the use of the time synchronization algorithm, this dynamic password changes continuously over time, and each password is only valid within its validity period.
[0084] When a dynamic password is received from the user on the vehicle's central control screen or instrument panel, the one-button start control unit compares the user-entered dynamic password with a password synchronously calculated locally. If they match, the verification is deemed successful, and the security level is reset to the first security level. If the user-entered password does not match the reference password, or if the password has expired, the verification is deemed unsuccessful, and the one-button start control unit maintains the current security level.
[0085] When a vehicle enters a restricted or prohibited state due to a low dynamic score, authorized users can quickly regain full permissions through dynamic password verification. This avoids misjudgments caused by occasional sensor errors, positioning drift, or abnormal behavior that could affect normal vehicle use, thus improving the system's fault tolerance and user experience. Drivers can proactively initiate re-verification based on their own needs, rather than passively waiting for the system to handle it automatically. This gives users more autonomy while ensuring safety, and is especially suitable for scenarios where it is necessary to immediately restore the vehicle's full performance in emergency situations.
[0086] The present invention also provides an electronic vehicle anti-theft control system for commercial vehicles, comprising: The Level 1 authentication module is used to perform Level 1 authentication in response to the start command. The one-button start control unit verifies the authenticity of the key through wireless interaction with the smart key. The secondary authentication module is used to perform secondary authentication after the first-level authentication is passed. It enables encrypted communication between the control unit and the electronic gear shift lever with one click to verify the legitimacy of the electronic gear shift lever. The Level 3 authentication module is used to perform Level 3 authentication after Level 2 authentication is passed, enabling encrypted communication between the control unit and the engine controller with a single click, and verifying the legitimacy of the engine controller. The safety certification module is used to collect and evaluate dynamic certification parameters during the first-level certification process. Based on the results of the first to third-level certifications and the evaluation results of the dynamic certification parameters, it calculates the risk score and determines the vehicle's safety level according to the risk score. The permission distribution module is used to grant different operating permissions to the vehicle according to the security level. The operating permissions include: fully unlocked, speed-limited driving, power-limited driving, and completely prohibited from starting. The dynamic password verification module is used to perform dynamic password verification in response to a re-verification command when the security level is the second or third security level.
[0087] Dynamic authentication parameters include: the degree of matching between the vehicle's current location and the preset safe area, the degree of matching between the current time and the preset safe time period, and the degree of matching between the driver's behavioral characteristics and the historical behavior model.
[0088] The safety levels include: Level 1, corresponding to a risk score greater than or equal to the low-risk threshold, where the vehicle is fully unlocked and can be started, shifted, and driven normally; Level 2, corresponding to a risk score greater than or equal to the high-risk threshold and less than the low-risk threshold, where the vehicle is allowed to start and shift gears, but the engine output power is limited to a preset percentage of the rated power, and the maximum speed is limited to a preset speed limit; Level 3, corresponding to a risk score less than the high-risk threshold, where the vehicle is completely prohibited from starting, or although starting is allowed, shifting gears is prohibited, and the vehicle cannot leave.
[0089] The security authentication module includes: The location matching unit is used to collect the vehicle's current location information in real time through the vehicle positioning module, and perform spatial matching with one or more preset safe areas stored locally or in the cloud to obtain a location matching score. The time matching unit is used to obtain the current time through the vehicle clock module and match it with the pre-stored preset safe time period to obtain the time matching score. The behavior matching unit is used to continuously collect the driver's operation behavior data within a preset time before the vehicle starts through sensors, input the operation behavior data into a pre-trained behavior feature model, calculate the similarity with the historical behavior model, and obtain the behavior matching score. The authentication scoring unit is used to assign preset weights to the location matching score, time matching score, and behavior matching score, and then perform a weighted sum to obtain a comprehensive dynamic authentication score. The dynamic determination unit is used to determine that dynamic authentication has failed and trigger an additional verification process if the overall dynamic authentication score is lower than a preset first threshold, and to determine that dynamic authentication has passed if the overall dynamic authentication score is higher than a preset second threshold, and to allow simplification of one or more subsequent authentication steps. The basic security score allocation unit is used to obtain the authentication results of each step after the first-level authentication, second-level authentication, and third-level authentication are completed, and to assign a basic security score to each level of authentication result. The dynamic security score allocation unit is used to obtain the evaluation results of dynamic authentication parameters and map each matching score to a dynamic security score. The safety level confirmation unit is used to weight and sum the basic safety score and the dynamic safety score according to preset weights to obtain a risk score. The risk score is then compared with multiple level thresholds to determine the vehicle's safety level.
[0090] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A method for electronic anti-theft control of commercial vehicles, characterized in that, Includes the following steps: In response to the start command, the first level of authentication is performed. The one-button start control unit verifies the authenticity of the key through wireless interaction with the smart key. After the first level of authentication is passed, the second level of authentication is performed. The one-button start control unit communicates encrypted with the electronic shift lever to verify the legality of the electronic shift lever. After the second level of authentication is passed, the third level of authentication is performed. The one-button start control unit communicates encrypted with the engine controller to verify the legitimacy of the engine controller. During the first-level certification process, dynamic certification parameters are collected and evaluated. Based on the results of the first to third-level certifications and the evaluation results of the dynamic certification parameters, a risk score is calculated, and the safety level of the vehicle is determined according to the risk score. The dynamic authentication parameters include: the matching degree between the vehicle's current location and the preset safe area, the matching degree between the current time and the preset safe time period, and the matching degree between the driver's behavioral characteristics and the historical behavior model. The process of collecting and evaluating dynamic authentication parameters includes the following steps: The vehicle's current location information is collected in real time by the vehicle positioning module and spatially matched with one or more preset safe areas stored locally or in the cloud to obtain a location matching score. The current time is obtained by the vehicle clock module and matched with the pre-stored preset safe time period to obtain the time matching score. The driver's operational behavior data is continuously collected by sensors within a preset time before the vehicle starts. The operational behavior data is input into a pre-trained behavior feature model, and the similarity with the historical behavior model is calculated to obtain a behavior matching score. The location matching score, time matching score, and behavior matching score are assigned preset weights and then summed to obtain a comprehensive dynamic authentication score. If the overall dynamic authentication score is lower than a preset first threshold, the dynamic authentication is deemed to have failed and an additional verification process is triggered. If the overall dynamic authentication score is higher than a preset second threshold, the dynamic authentication is deemed to have passed and one or more subsequent authentication processes can be simplified. The process of calculating the risk score and determining the vehicle's safety level based on the risk score includes: After the first, second, and third level authentications are completed, the authentication results of each step are obtained, and a basic security score is assigned to each level of authentication result. Obtain the evaluation results of the dynamic authentication parameters, and map each matching score to a dynamic security score; The basic safety score and the dynamic safety score are weighted and summed according to preset weights to obtain the risk score. The risk score is then compared with multiple level thresholds to determine the vehicle's safety level.
2. The electronic vehicle anti-theft control method for commercial vehicles according to claim 1, characterized in that, Also includes: Based on the security level, different operating permissions are granted to the vehicle, including: fully unlocked, speed-limited driving, power-limited driving, and completely prohibited from starting. The security levels include: The first safety level corresponds to a risk score greater than or equal to the low-risk threshold. At this level, the vehicle is fully unlocked and can be started, shifted, and driven normally. The second safety level corresponds to a risk score that is greater than or equal to the high-risk threshold and less than the low-risk threshold. In this case, the vehicle is allowed to start and shift gears, but the engine output power is limited to a preset percentage of the rated power, and the maximum speed is limited to a preset speed limit. The third safety level corresponds to a risk score that is less than the high-risk threshold. At this level, the vehicle is completely prohibited from starting, or although starting is allowed, shifting gears is prohibited, and the vehicle cannot leave.
3. The electronic vehicle anti-theft control method for commercial vehicles according to claim 2, characterized in that, The additional verification process includes: The one-click start control unit sends a verification request to the pre-bound mobile terminal; The verification application on the mobile terminal displays a preset gesture operation guide interface, requiring the user to draw a preset trajectory graphic or perform a preset touch gesture sequence on the touch screen of the mobile terminal. The mobile terminal collects the user's gesture trajectory, extracts its feature parameters and matches them with the locally stored gesture templates. If the matching degree exceeds a preset threshold, the successfully matched signature result is encrypted and sent back to the one-click start control unit. After the one-click start control unit decrypts and verifies that the signature is correct, it determines that the verification is successful. Then, the one-click start control unit corrects the comprehensive dynamic authentication score to a value higher than the first threshold. If the verification fails, the one-button start control unit maintains the overall dynamic authentication score unchanged and prohibits the vehicle from starting or maintains the restricted driving mode.
4. The electronic vehicle anti-theft control method for commercial vehicles according to claim 3, characterized in that, During the second and third level authentication processes, the encrypted communication includes the following steps: The one-button start control unit sends a request verification message to the electronic gear shift lever or the engine controller. In response to the request verification message, the electronic gear shift lever or the engine controller generates a random number and sends it to the one-button start control unit. The one-button start control unit performs encryption calculations on random numbers according to the AES128 CMAC algorithm, generates ciphertext, and sends the encrypted data back to the electronic gear shift lever or the engine controller. The electronic gear shift lever or the engine controller performs encryption calculation on the same random number according to the AES128 CMAC algorithm to generate reference ciphertext. After confirming that the encrypted data returned by the one-key start control unit has been successfully received, the received ciphertext is compared with the reference ciphertext. If the two are consistent, the authentication is deemed to have passed; if they are inconsistent, the authentication is deemed to have failed. The second level of authentication also includes: once the electronic shift lever passes the authentication, the electronic shift lever is authorized to send shift requests via the CAN bus; The third level of authentication also includes: once the engine controller passes the legality authentication, the one-button start control unit is allowed to send a start request to the engine.
5. The electronic vehicle anti-theft control method for commercial vehicles according to claim 4, characterized in that, Also includes: When the security level is the second or third security level, in response to the re-verification command, dynamic password verification is performed, which includes the following steps: The one-button start control unit sends a re-verification request to the pre-bound mobile terminal. The re-verification request includes the vehicle's current location information, timestamp, and a randomly generated challenge code. The mobile terminal generates a one-time dynamic password with a preset validity period based on the time synchronization algorithm shared with the one-click start control unit and the challenge code, and displays it on the screen. When the one-button start control unit receives the dynamic password entered by the user on the vehicle's central control screen or instrument panel, it compares the dynamic password entered by the user with the password synchronously calculated on the local end. If they match, the verification is deemed successful, and the security level is reset to the first security level.
6. The electronic vehicle anti-theft control method for commercial vehicles according to claim 5, characterized in that, The operational behavior data includes the initial force curve of pressing the accelerator, the angular velocity distribution of turning the steering wheel, and the sequence of actions to adjust the seat after sitting down.
7. A commercial vehicle electronic anti-theft control system, characterized in that, include: The Level 1 authentication module is used to respond to the start command and perform Level 1 authentication. The one-button start control unit verifies the authenticity of the key through wireless interaction with the smart key. The secondary authentication module is used to perform the second-level authentication after the first-level authentication is passed. The one-button start control unit communicates encrypted with the electronic shift lever to verify the legality of the electronic shift lever. The three-level authentication module is used to perform the third-level authentication after the second-level authentication is passed. The one-button start control unit communicates encrypted with the engine controller to verify the legitimacy of the engine controller. The safety authentication module is used to collect and evaluate dynamic authentication parameters during the first-level authentication process, calculate a risk score based on the results of the first to third-level authentication and the evaluation results of the dynamic authentication parameters, and determine the safety level of the vehicle based on the risk score. The dynamic authentication parameters include: the matching degree between the vehicle's current location and the preset safe area, the matching degree between the current time and the preset safe time period, and the matching degree between the driver's behavioral characteristics and the historical behavior model. The security authentication module includes: The location matching unit is used to collect the vehicle's current location information in real time through the vehicle positioning module, and perform spatial matching with one or more preset safe areas stored locally or in the cloud to obtain a location matching score. The time matching unit is used to obtain the current time through the vehicle clock module and match it with the pre-stored preset safe time period to obtain the time matching score. The behavior matching unit is used to continuously collect the driver's operation behavior data within a preset time before the vehicle starts through sensors, input the operation behavior data into a pre-trained behavior feature model, calculate the similarity with the historical behavior model, and obtain the behavior matching score. The authentication scoring unit is used to assign preset weights to the location matching score, time matching score and behavior matching score respectively, and then perform weighted summation to obtain a comprehensive dynamic authentication score; The dynamic determination unit is used to determine that dynamic authentication has failed and trigger an additional verification process if the overall dynamic authentication score is lower than a preset first threshold, and to determine that dynamic authentication has passed if the overall dynamic authentication score is higher than a preset second threshold, allowing simplification of one or more subsequent authentication steps.