Establishing a ble coupling between a mobile device and a motor vehicle
Patent Information
- Application Number
- CN202610335375.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2025-03-20
- Filing Date
- 2026-03-19
- Publication Date
- 2026-09-22
AI Technical Summary
然后可能失败的是,随后使用存储在移动设备上的数字钥匙来控制机动车
Smart Images

Figure CN122802910A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the control of motor vehicles using a digital key stored in a mobile device. More particularly, this invention relates to establishing BLE coupling between a mobile device and a motor vehicle. Background Technology
[0002] Motor vehicles can be protected using digital key designs, particularly in accordance with the recommendations of the CarConnectivity Consortium (CCC). The cryptographic structure used as the digital key can be stored on a mobile device. After the digital key is presented at the vehicle, predetermined security functions of the vehicle can be controlled, such as unlocking doors or the hood, or starting the drive motor. Presentation (Vorweisen) falls within the scope of Standard Transactions or Fast Transactions, as specified in the CCC recommendations.
[0003] The described transactions can be conducted via various interfaces, including Bluetooth Low Energy (BLE). For BLE connectivity to work, the mobile device and the vehicle must first establish BLE coupling. Typically, the vehicle sends a connection broadcast with a predefined identifier of 0xFFF5. The mobile device receives the broadcast and compares this identifier to the predefined value 0xFFF5. If the received broadcast has the correct identifier, the mobile device responds, and coupling can be established between the mobile device and the vehicle. Typically, the user must enter the vehicle's identification code at the mobile device's user interface for this purpose.
[0004] If multiple vehicles ready to communicate are in a confined space, coupling between the mobile device and one of the vehicles may fail, and other couplings may be attempted or implemented. Then, it may fail to subsequently use a digital key stored on the mobile device to control the vehicles. Summary of the Invention
[0005] The objective of this invention is to provide an improved technique for establishing BLE coupling between mobile devices and motor vehicles. This invention achieves this objective through the technical solutions provided in the independent claims. The dependent claims provide preferred embodiments.
[0006] According to a first aspect of the present invention, a method for establishing BLE coupling between a mobile device and a motor vehicle includes the following steps: determining an identifier belonging to the motor vehicle; transmitting the identifier to the mobile device; transmitting a connection broadcast with the identifier via BLE on the motor vehicle side; detecting the connection broadcast with the identifier via BLE through the mobile device; transmitting the mobile device's response to the connection broadcast via BLE; and establishing BLE coupling between the mobile device and the motor vehicle.
[0007] This method is particularly useful when a digital key is stored on a mobile device, which can then be used to control a motor vehicle. The key can be presented at the vehicle by exchanging predetermined cryptographic messages via a Bluetooth Low Energy (BLE) connection. This allows for two-way authentication between the vehicle and the mobile device. This authentication is preferably based on an asymmetric encryption method using a private key and a public key.
[0008] Mobile devices can be assigned to the owner of a motor vehicle, and the stored keys can be used to control the vehicle in a predetermined manner. In particular, another key for the motor vehicle can be created or signed based on that key. The person to whom the key is assigned can act as the owner of the motor vehicle.
[0009] Unlike known implementations, vehicle identification can be personalized, thus avoiding erroneous BLE coupling between mobile devices and non-target vehicles. For example, if BLE coupling is to be established while the mobile device is within range of multiple vehicles that are separately sending connection broadcasts, the mobile device can only respond to connection broadcasts containing an identifier associated with a digital key stored on the mobile device.
[0010] Preferably, the identifier is associated with the BLE interface of the vehicle. In particular, the identifier can be derived from an identification code or key used for BLE communication on the vehicle side.
[0011] The identity is preferably determined using the Identity Resolving Key (IRK) of the BLE interface on the vehicle. The IRK is typically used to determine the Resolvable Private Address (RPA). In this way, only trusted devices can establish communication or coupling. Details of this can be found in the relevant Bluetooth Low Energy specifications.
[0012] In one implementation, the identifier includes the IRK of the BLE interface. The IRK is 128 bits long, while the identifier for motor vehicles is only 16 bits according to applicable CCC recommendations. Therefore, in one implementation, predefined bits of the IRK can be mapped to bits of the identifier. In a simple implementation, predefined segments of the IRK, such as the first 16 bits, can be used as the identifier. In another implementation, different segments of the IRK can be combined to form the identifier. The order of the segments in the IRK does not necessarily correspond to the order in the identifier.
[0013] A vehicle's BLE interface can include multiple transceivers. These transceivers are configured to transmit or receive electromagnetic signals. They can also send connection broadcasts with the same IRK for BLE connectivity. Therefore, mobile devices can communicate with any transceiver to establish BLE coupling to the vehicle.
[0014] The vehicle's identifier can be stored at the key server within the scope of owner pairing. Within owner pairing, the digital key for the vehicle is stored on the mobile device. This key is specifically associated with the owner role, enabling it to be used to sign other digital keys for the vehicle. The key server plays a role in verifying new digital keys for the vehicle. In particular, the key server can create a verification package based on the digital key, which is transmitted to the vehicle. The verification package corresponds to the digital key, ensuring that the digital key can only be used if the vehicle has already obtained the verification package. Particularly preferred is that the IRK (Information Technology Kit) is stored at the key server. The identifier can then be derived from the IRK on the key server side or the mobile device side.
[0015] The vehicle's identifier can be negotiated and determined within the scope of owner pairing between the vehicle and the key server. If a valid owner pairing does not occur, there is no valid identifier or valid IRK at the key server. In this case, the method described herein can revert to a known method in which a fixed, predetermined identifier is used instead of the identifier assigned to the vehicle. This identifier can, in particular, be 0xFFF5.
[0016] Within the scope of digital keys for motor vehicles installed on mobile devices, prompts regarding identification can be transmitted to the mobile device. This is particularly applicable when the digital key is not the owner's key. In this case, communication between the mobile device and the key server can be conducted via an interface other than BLE, such as WLAN or NFC. Prompts regarding identification can be part of the digital key or transmitted along with it. In one implementation, the identification or prompts regarding identification are transmitted from the key server to the mobile device in encrypted form.
[0017] Similarly, it is preferable that, within the scope of owner pairing, communication between the vehicle and the mobile device is conducted using an interface other than the BLE interface. In particular, Near Field Communication (NFC) can be used. This interface has an effective operating range of only a few centimeters, requiring the sensitive owner pairing process to necessitate that the mobile device be physically within the vehicle's range. This better prevents misuse.
[0018] According to another variation of the invention, the identifier or indication of the identifier can be determined based on a Bluetooth address. In particular, the address BD_ADDR can be used. The variation described herein with respect to IRK can be applied to BD_ADDR.
[0019] According to another aspect of the invention, a control device for a motor vehicle includes a BLE interface and a processing device. The processing device is configured to: transmit a connection broadcast carrying a predetermined identifier of the motor vehicle via the BLE interface; and implement BLE coupling with a mobile device responding to the connection broadcast.
[0020] According to another aspect of the invention, a motor vehicle includes the control devices described herein. Motor vehicles may, in particular, include motorcycles or passenger cars.
[0021] According to another aspect of the invention, a mobile device includes a BLE interface and a processing device. The processing device is configured to: receive an identifier of a motor vehicle from an external entity; receive a connection broadcast carrying the identifier via the BLE interface; respond to the connection broadcast; and establish a BLE coupling to the motor vehicle.
[0022] In particular, the processing device may establish a BLE coupling only to the motor vehicle that sends the connection broadcast with an identifier corresponding to an identifier previously received from an external entity. The external entity may, in particular, include a key server. A digital key for controlling the motor vehicle may be stored on the mobile device. The storage or verification of the digital key may include communication with the external entity or the key server.
[0023] Digital keys are typically stored in the secure memory of a mobile device. To access this secure memory, the person associated with the mobile device can be required to authenticate with the device. This can be achieved, for example, by presenting biometric data or entering a pre-defined password. Control of a motor vehicle can be linked to this person in this way.
[0024] According to another aspect of the invention, the proposed system includes the control device and the mobile device described herein. In an alternative embodiment, the system includes the motor vehicle and the mobile device described herein. The system can be configured to make the control of the motor vehicle, and in particular the predetermined safety functions of the motor vehicle, available only to personnel associated with the mobile device.
[0025] The system or its components can be advantageously integrated with the recommendations provided by the Car Connectivity Consortium for protecting motor vehicles with the aid of digital keys. A technical specification entitled "Car Connectivity Consortium Digital Key Technical Specification" has been published for this purpose.
[0026] The processing apparatus described herein is preferably configured to partially or fully execute the methods described herein. For this purpose, the processing apparatus can be constructed electronically and includes, for example, integrated circuits, programmable logic devices, or programmable microcomputers. The method can be implemented in configuration form or as a computer program product having program code means for the processing apparatus. The configuration or computer program product can be stored on a computer-readable data carrier. Features or advantages of the method can be transferred to the apparatus, or vice versa. Attached Figure Description
[0027] The invention will now be described in more detail with reference to the accompanying drawings, in which:
[0028] Figure 1 This illustrates a system;
[0029] Figure 2 A flowchart of one method is shown; and
[0030] Figure 3 A flowchart illustrating another method is shown. Detailed Implementation
[0031] Figure 1 A system 100 with a motor vehicle 105 is shown. The motor vehicle 105 is equipped with a device 110 configured to control predetermined security functions of the motor vehicle 105, particularly concerning entry into or movement of the motor vehicle 105. Personnel 115 are equipped with a mobile device 120, which enables them to control the security functions of the motor vehicle 105. The necessary cryptographic keys can be generated or verified with the participation of a key server 125.
[0032] Device 110 includes a processing unit 130 that is connected to one or more interfaces. By way of example only, a BLE interface 135, an NFC interface 140, and a mobile communication interface 145 are provided.
[0033] Similarly, the illustrated mobile device 120 includes a processing unit 150 connected to a BLE interface 155, an NFC interface 160, and a mobile communication interface 165. Interfaces 135 to 145 and 155 to 165 are respectively configured to establish data connections with corresponding entities. Specifically, data can be transferred between BLE interfaces 135 and 155 or between NFC interfaces 140 and 160. Mobile communication interfaces 145 and 165 can communicate with each other indirectly or directly. Furthermore, communication with a key server 125 can be achieved via these interfaces.
[0034] Figure 1 An additional interface, not shown, may be located on the device 110 or mobile device 120 side and is primarily used for distance determination. This interface may, in particular, include an Ultra-Wideband (UWB) interface. Determining the distance between the vehicle 105 and the mobile device 120 may be part of an authentication method to control the safety functions of the vehicle 105 via the mobile device 120.
[0035] The key server 125 preferably includes a processing unit 170 connected to an interface 175 and an optional data storage device 180. The interface 175 may, in particular, include a mobile communication interface to enable communication with onboard devices 110 or mobile devices 120 of the vehicle 105.
[0036] To control the security functions of vehicle 105, a predetermined exchange method for a cryptographic key is typically performed between device 110 and mobile device 120. This exchange method preferably operates over a BLE connection between interfaces 135 and 155. To establish a BLE connection, BLE coupling must be implemented between devices 110 and 120. For coupling, device 110 sends a connection broadcast including a predetermined identifier for vehicle 105. According to CCC recommendations, this identifier is fixed at a value of 0xFFF5. Mobile device 120 first passively receives connection broadcasts from surrounding devices. If a connection broadcast is received, its associated identifier is checked. If the connection broadcast contains a predetermined identifier with a value of 0xFFF5 according to CCC recommendations, mobile device 120 responds, and BLE coupling can be implemented between device 110 and mobile device 120.
[0037] The proposal suggests using an improved, personalized identifier for vehicle 105 or device 110 instead of a fixed identifier. This identifier can be determined, in particular, based on an IRK (In-Vehicle Key), which is determined within the scope of owner pairing between device 110 on vehicle 105 and key server 125 and stored on the key server 125 side. The IRK has a length of 128 bits, thus eliminating conflicts with the IRKs of other devices within the scope of vehicle 105 in practice.
[0038] It has been recognized that BLE coupling between device 110 and mobile device 120 is only meaningful when a digital key matching the vehicle 105 is stored on mobile device 120. To store a valid or usable digital key in mobile device 120, a creation or distribution method is required, which necessitates communication between mobile device 120 and key server 125. It is proposed that, within the scope of this method, the IRK stored on the key server 125 side is transmitted to mobile device 120 and preferably assigned to the digital key for vehicle 105. To implement BLE coupling between interfaces 135 and 155 of devices 110 and 120, it is also proposed that device 110 send its connection broadcast based on an identifier derived from the IRK in a predetermined manner. If mobile device 120 receives the connection broadcast, it can compare the accompanying identifier with an identifier derived in the same manner from the IRK provided by key server 125. If the identifiers match, mobile device 120 can respond to the connection broadcast, and BLE coupling can be established between interfaces 135 and 155. BLE coupling can require the participation of personnel 115, for example, by requiring the input of predetermined information already determined on the device 110 on the vehicle 105 on the mobile device 120.
[0039] The establishment of BLE coupling between devices 110 and 120 typically requires only one instance. Through BLE coupling, devices 110 and 120 can notify each other, enabling them to subsequently establish a communication connection between interfaces 135 and 155 automatically, and especially without the intervention of personnel 115. The described exchange method can be performed via the established BLE connection to implement mutual authentication between the mobile device 120 and the onboard device 110 of the vehicle 105. If the authentication is successful, predetermined safety functions of the vehicle 105 can be controlled.
[0040] Figure 2 A flowchart illustrating an exemplary method 200 is shown. Method 200 is a summary of owner pairing, which is preferably implemented according to CCC recommendations. Details can be obtained from publicly available technical specifications.
[0041] In step 205, it can be determined that owner pairing needs to be performed. Owner pairing establishes a connection between mobile device 120 and vehicle 105. Here, a digital key is stored on mobile device 120, which enables control of vehicle 105, and this digital key is associated with specific extended permissions. In particular, another digital key for vehicle 105 can be created or signed based on the owner key and thereby verified. Owner pairing is typically performed when the owner of vehicle 105 changes. Accordingly, the security requirements for method 200 are high.
[0042] In step 210, a communication connection can be established between the NFC interfaces 140 and 160 of device 110 and mobile device 120. The transceiver of device 110, which converts electromagnetic waves into electrical signals and vice versa, is preferably located inside the interior space of vehicle 105. Since the effective range of an NFC connection is limited to a few centimeters, to implement method 200, mobile device 120 must be brought into the interior space and brought sufficiently close to the transceiver. Typically, mobile device 120 is placed on or held against the transceiver of device 110.
[0043] In step 215, proof of ownership can be presented. Various variations are conceivable for this purpose, particularly those that can be chosen by the manufacturer of vehicle 105. In one embodiment, at least two digital keys, which have been previously disclosed to the owner of vehicle 105, must be presented at the vehicle's onboard location. These digital keys can be stored, for example, on a key card or key device (Fob). Presentation of the digital keys is preferably also via an NFC interface 140 located within the interior of vehicle 105.
[0044] In step 220, a cryptographic key can be generated on the mobile device 120 side, and then the cryptographic key should be used to control the motor vehicle 105.
[0045] According to a predetermined method, in step 225, the generated digital key can be signed and verified on the key server 125 side. Within the scope of verification, in step 230, the signed verification packet can be transmitted to the vehicle 105. This transmission is typically performed via the mobile communication interface 145. Furthermore, a message containing the signed key from the mobile device 120 can be transmitted to the mobile device 120.
[0046] In step 235, the IRK is transmitted to the mobile device 120. The IRK is created between the device 110 and the key server 125 and stored on the key server 125 side within the scope of step 225.
[0047] Figure 3A flowchart of another method 300 for controlling motor vehicle 105 is shown. Method 300 is predicated on the successful execution of method 200. In this sense, methods 200 and 300 can also be understood as a single, coherent method.
[0048] In step 305, an identifier can be determined on the vehicle 105 side based on the IRK, which has been provided to the key server 125 in advance and stored there.
[0049] In the corresponding step 310, the identifier of the vehicle 105 can be determined on the mobile device 120 side, which is received from the key server 125. In particular, the IRK can be received from the key server 125 on the mobile device 120 side within the scope of the key granting or verification method of the digital key used to control the vehicle 105.
[0050] In step 315, a connection broadcast is sent on the device 110 side of the vehicle 105 using the identifier determined on the device 110 side. The transmission of the connection broadcast is also referred to as an announcement, advertisement, or advertising. In step 320, the connection broadcast from the device 110 of the vehicle 105 is received on the mobile device 120 side.
[0051] In step 325, it can be determined whether the received identifier corresponds to the identifier determined in step 310. If so, the mobile device 120 can respond to the connection broadcast in step 330 and send a corresponding message to the device 110 on the vehicle 105. The response can be received on the device 110 side in step 335. If devices 110 and 120 agree on the mentioned and other exchanged parameters, BLE coupling can be established in step 340.
[0052] It should be noted that method 300 constitutes a modification of the method disclosed by the CCC in the technical specifications for digital keys, particularly in Chapter 19. In this regard, specific reference is made to Figure 19-1, which illustrates a flowchart of a method for BLE coupling between mobile device 120 and onboard device 110 of vehicle 105. Furthermore, reference is made to Table 19-2, where the vehicle identifier, named UUID, has a fixed, predetermined value. Within the scope of this art, it is proposed that a dynamically determined value be used for the UUID instead of a static value.
[0053] Following method 300, a transaction can be implemented to verify the validity of the cryptographic key stored on the mobile device 120 side via communication between BLE interfaces 135 and 155. If the verification is successful, predetermined security functions of the vehicle 105 can be controlled via the mobile device 120.
[0054] List of reference numerals
[0055] 100 System
[0056] 105 Motor vehicles
[0057] 110 equipment
[0058] 115 personnel
[0059] 120 mobile devices
[0060] 125 Key Server
[0061] 130 processing unit
[0062] 135 BLE interface
[0063] 140 NFC interface
[0064] 145 Mobile communication interface
[0065] 150 processing unit
[0066] 155 BLE interface
[0067] 160 NFC interface
[0068] 165 Mobile Communication Interface
[0069] 170 processing unit
[0070] 175 interface
[0071] 180 Data Storage
[0072] 200 methods
[0073] 205 Start Owner Pairing
[0074] 210 Coupling mobile devices with motor vehicles via NFC
[0075] 215. Present proof of ownership.
[0076] 220 Generate keys on mobile devices
[0077] 225 Verification Key
[0078] 230 Transmit the signed certificate packet to the motor vehicle
[0079] 235 Transmit the signed key to the mobile device
[0080] 300 methods
[0081] 305 Identification Based on IRK
[0082] 310 Identify the identifier
[0083] 315 Send a connection broadcast with an identifier
[0084] 320 Receive connection broadcast
[0085] 325 The received identifier corresponds to the determined identifier.
[0086] 330 responded to the connection broadcast.
[0087] 335 Receive Response
[0088] 340 Establishing Coupling
Claims
1. A method (300) for establishing BLE coupling between a mobile device (120) and a motor vehicle (105), wherein, The method (300) includes the following steps: Identify (305) the identification mark belonging to the motor vehicle (105); The identifier is transmitted (310) to the mobile device (120). A connection broadcast bearing the aforementioned identifier is transmitted (315) via BLE from the vehicle (105) side; Broadcast of the connection with the identifier via BLE detection (320) through the mobile device (120); The mobile device (120) responds to the connection broadcast via BLE transmission (330); and Establish (340) the BLE coupling between the mobile device (120) and the motor vehicle (105).
2. The method (300) according to claim 1, wherein, The identifier is associated with the BLE interface of the motor vehicle (105).
3. The method (300) according to claim 2, wherein, The identifier is determined based on the IRK of the BLE interface.
4. The method (300) according to claim 2 or 3, wherein, The identifier includes a predetermined segment of the IRK.
5. The method (300) according to claim 3 or 4, wherein, The BLE interface on the vehicle (105) side includes multiple transceivers that transmit connection broadcasts with the same IRK for BLE connection.
6. The method (300) according to any one of the preceding claims, wherein, The identifier is stored at the key server (125) within the scope of the owner pair (200).
7. The method (300) according to claim 6, wherein, The identifier is determined through negotiation within the scope of owner pairing (200) between the motor vehicle (105) and the key server (125).
8. The method (300) according to any one of the preceding claims, wherein, Within the scope of the digital key for the motor vehicle (105) installed on the mobile device (120), a prompt for the identifier is transmitted to the mobile device (120).
9. The method (300) according to any one of the preceding claims, wherein, Within the scope of owner pairing (200), communication between the motor vehicle (105) and the mobile device (120) is carried out via an interface other than the Bluetooth interface.
10. The method (300) according to any one of the preceding claims, wherein, The identifier is determined based on BD_ADDR.
11. A control device (110) for a motor vehicle (105), wherein, The control device (110) includes the following components: BLE interface (135); The processing device (130) is configured to: transmit a connection broadcast with a predetermined identifier of a motor vehicle (105) via the BLE interface (135); and implement BLE coupling with a mobile device (120) that responds to the connection broadcast.
12. A motor vehicle (105), said motor vehicle including the control device (110) according to claim 11.
13. A mobile device (120), the mobile device comprising: BLE interface (155); A processing device (150) configured to: receive the identification mark of a motor vehicle (105) from an external entity (125); The system receives a connection broadcast with the identifier via the BLE interface (155); responds to the connection broadcast; and establishes a BLE coupling to the vehicle (105).
14. A system (100), the system comprising: The control device (110) according to claim 11 or the motor vehicle (105) according to claim 12; and the mobile device (120) according to claim 13.