Access system for a vehicle

The method and control device allow multiple users to securely access multiple vehicles using mobile terminals, managing authentication locally and verifying with a server, addressing the limitations of existing systems in network coverage and key management.

DE102012022786B4Active Publication Date: 2025-10-09VOLKSWAGEN AG
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
DE102012022786
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2012-11-22
Publication Date
2025-10-09
Estimated Expiration
2032-11-22

AI Technical Summary

Technical Problem

Existing vehicle access systems require multiple keys for multiple vehicles and rely on online connections for authorization, which can be unreliable in areas with poor network coverage.

Method used

A method and control device that uses a mobile terminal to authenticate and authorize access to multiple vehicles via short-range communication, with authentication information managed locally and verified by a server, ensuring secure and reliable access without constant online connectivity.

Benefits of technology

Enables multiple users to access multiple vehicles securely using their mobile terminals, allowing flexible authorization management and preventing unauthorized access, even in areas with poor network coverage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for an access system for a vehicle, wherein the access system comprises a control device (11) which can be installed in the vehicle, an identification device (16) assigned to the control device (11) and a mobile terminal (12), wherein a function of the control device (11) can be controlled via the mobile terminal (12) depending on authentication information stored in the mobile terminal (12) and the control device (11), characterized in that the method comprises: - Verifying identification information of the identification device (16) by the control device (11), wherein the control device (11) checks on the basis of the identification information whether the identification device (16) is the identification device (16) assigned to the control device (11), and if the verification is successful: - generating the authentication information in the control device (11), and - transmitting the authentication information from the control device (11) to the mobile terminal (12); - the method further comprising: - transmitting the authentication information to a server (18) outside the vehicle (10), - receiving an acknowledgment information from the server (18), wherein the acknowledgment information indicates that the authentication information has been transmitted to the server (18), and - Releasing the authentication information in the control device (11) for controlling the function of the control device (11) via the mobile terminal (12) using the authentication information.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to a method for an access system for a vehicle, in particular for an access system that enables access to and starting of the vehicle using a mobile terminal, such as a mobile phone. The present invention further relates to a control device for a vehicle that uses the method.

[0002] Conventional vehicle access and vehicle start systems require the possession of an original key belonging to the vehicle. This key can be a mechanical key or an electronic key that communicates with a receiver in the vehicle via electromagnetic waves or infrared. This communication includes, for example, an interrogation protocol in which the electronic key transmits a code to the vehicle, which is then compared with a stored code in the vehicle to verify the access authorization of an electronic door opener or vehicle start system.

[0003] In the case of multiple vehicles for multiple people, for example in companies with a fleet or in a family with multiple vehicles and multiple authorized drivers, appropriate regulations are required for managing the keys assigned to the vehicles. Alternatively, so-called online services can be used to open and start a vehicle. These online services are connected to the vehicle via a radio link and enable a user to open and start the vehicle, for example using a suitable application on the user's mobile phone. The online service checks whether the mobile device used, for example the mobile phone, has the appropriate authorization to open and / or start the vehicle.An online connection to the online service is required each time the vehicle is opened and started, which can be problematic, for example, in underground car parks or areas with poor wireless network coverage.

[0004] In this context, DE 10 2005 034 477 A1 discloses a locking system with a digital key for access and / or driving authorization in the form of a keyless entry / go functionality. The locking system comprises a control device with at least two states, a signal generator for unlocking and / or locking the car doors, the ignition lock, the steering wheel lock, or the like in the form of a mobile phone, and a management unit for sending and managing digital keys. The management unit sends a coded digital, time-limited or time-unlimited key to the mobile device. Using this digital key, which is stored on the mobile device, the user can change the state of the control device in the vehicle.

[0005] DE 101 42 967 A1 relates to a vehicle with on-board electronics, which, on the one hand, has an interface designed as a plug-in or wireless connection for data exchange with a PDA (Personal Digital Assistant) and, on the other hand, is connected to at least one control unit. The control unit can be controlled by the PDA depending on an identification code assigned to the PDA. The control unit is, for example, a vehicle immobilizer or a central locking system. The PDA thus serves as a "key" for controlling the control unit.

[0006] US 2010 / 0233957 A1 relates to a personalization system for a vehicle, which includes a mobile phone and the vehicle. When a vehicle user prepares to use the vehicle, personalization data, such as a preferred seating position, is transmitted from the mobile phone to the vehicle and used by the vehicle to make a corresponding adjustment according to the vehicle user's preferences.

[0007] DE 10 2009 037 234 A1 relates to a method for transmitting data between a data processing device located outside a motor vehicle and a motor vehicle from a fleet of motor vehicles. To enable the exchange of data between the data processing device and any motor vehicle in the fleet, a central server is used on which user accounts are maintained, and the data processing device can access these user accounts. A vehicle identification number is stored in the user account. A portable device is then coupled to a first motor vehicle and functions, in a sense, as a user's ID. A password can be requested from the user once. The first coupling results in the portable device being defined as an ID, even if it is later coupled to other motor vehicles.Pairing the portable device with any motor vehicle then enables data exchange between the server and the respective motor vehicle.

[0008] DE 102 37 831 A1 relates to an access control and data acquisition system for shared vehicles. A communication unit in the vehicle can wirelessly exchange data with a remote control center using a transmitting and receiving device. It receives booking information relating to the vehicle from the control center and reports billing-relevant information, such as the user, usage time, fuel consumption, and distance traveled, to the control center. The user is provided with either a handheld control unit with a built-in display and control buttons, which is permanently programmed with a personal user number. Alternatively, a device already owned by the user can be used, such as a mobile phone with suitable features. Both variants, in conjunction with a PIN entered by the user, allow for unique user identification.

[0009] US 2011 / 0312273 A1 relates to an access system for a vehicle, which comprises a control device in the form of a microprocessor. The control device provides a key holder with access to the vehicle, whereby the key can be a conventional key or a USB key. Furthermore, a function of the vehicle, such as starting or opening the doors, can be controlled with the help of the microprocessor. The control device also has the option of coupling to a mobile device using Bluetooth technology. Thus, once a mobile device has been identified by the control device, it is possible to use this mobile device to control the functions of the vehicle. Furthermore, coupling with the mobile device can only take place if the key is inserted in the designated area.To increase the security of the access system, the control device can also request authentication information from a user, e.g. in the form of a PIN entry or biometric file such as a photo, which can then be compared with pre-stored information in the control device.

[0010] The BLUETOOTH SIG: Specification of the Bluetooth System; Core System Package. Bluetooth Specification Version 2.1 + EDR [vol. 3]. July 26, 2007, pages 258-259, concerns an authentication method between two devices using Bluetooth technology called "numeric comparison." This method allows randomly generated numbers to be exchanged and compared between two devices if both devices have an input and output function and no man-in-the-middle protection is provided.

[0011] US 2011 / 0153121 A1 relates to an access system for a protected area such as a vehicle or a building. The access system allows a user to access the protected area after successful verification. Verification is performed by inputting a signal into a suitable terminal device with an optical or acoustic input function. The terminal device can be, for example, a mobile device with an app, computer software, or a watch. The optical or acoustic signal can then be encrypted and transmitted to a control device of the access system, which can be used to compare the signal with pre-stored information. Furthermore, the software or app for encrypting the optical or acoustic signal can be located on a dedicated server.

[0012] DE 102009 037 234 A1 relates to a method for the unidirectional transmission of data between a data processing device located outside a motor vehicle and a respective motor vehicle from a fleet of motor vehicles. A central server manages information such as user accounts and vehicle identification numbers, with a portable device such as the SIM card of a mobile terminal serving for user identification. To enable data exchange, the vehicle identification number and an electronic identifier of the portable device are transmitted to the server, and the server assigns the electronic identifier to the user account. If a different motor vehicle from the fleet is used, the portable device can be re-linked to the new motor vehicle.

[0013] The object of the present invention is to provide a reliable and secure method to enable several people, each with a mobile terminal, to have access to several different vehicles, i.e., that the people can, for example, open and start different vehicles with their respective mobile terminal.

[0014] This object is achieved according to the present invention by a method for an access system for a vehicle according to claim 1, a method for an access system for a vehicle according to claim 2, a control device for a vehicle according to claim 5 and a control device for a vehicle according to claim 6. The dependent claims define preferred and advantageous embodiments of the invention.

[0015] According to the present invention, a method for an access system for a vehicle is provided. The access system comprises a control device that can be installed in the vehicle, an identification device that is assigned to the control device, and a mobile terminal, such as a personal digital assistant (PDA) or a mobile phone, in particular a so-called smartphone. A function of the control device can be controlled via the mobile terminal depending on authentication information stored in the mobile terminal and the control device. In other words, a function of the control device can be controlled with the help of the mobile terminal via, for example, a radio connection, in particular a short-range radio connection such as, for example,NFC or Bluetooth, wherein authentication information is used during communication between the mobile terminal and the control device to authenticate the mobile terminal to the control device. The control device can, for example, comprise or be coupled to a central locking system of the vehicle, so that openings of the vehicle, such as doors or a trunk of the vehicle, can be locked or unlocked using the mobile terminal using suitable instructions transmitted from the mobile terminal to the control device. Furthermore, the control device can be coupled to an immobilizer of the vehicle, and operation of the vehicle can be enabled or disabled using the mobile terminal. If a new mobile terminal is to be used in conjunction with the control device, the new mobile terminal requires corresponding authentication information.Equipping the mobile terminal with the authentication information is also referred to as "registering" the mobile terminal with the control device. The registration process may further comprise registering a unique identification code of the mobile terminal in the control device. To register the mobile terminal with the control device, in the method according to the invention, identification information of the identification device is verified by the control device. The control device uses the identification information to check whether the identification device is the identification device assigned to the control device. The identification device may, for example, comprise a vehicle key, in particular an electronic vehicle key with a radio transmitter.If the identification information is successfully verified, authentication information for the mobile terminal is generated in the control device and transmitted from the control device to the mobile terminal.

[0016] By first ensuring that the identification device assigned to the vehicle is in communication with the control device, for example via short-range communication, before teaching a new mobile device, it can be prevented that unauthorized mobile devices are registered with the control device.

[0017] On the other hand, it makes it possible to program a new mobile device locally and without the need for a communication connection to a server or central facility. This can be done, for example, by the owner or occupant of the vehicle who is in possession of the identification device. This allows a large number of mobile devices to be easily programed, i.e., a large number of mobile devices receive the appropriate authentication information to allow the owner of the mobile device access to the vehicle.

[0018] According to the invention, the authentication information is transmitted to a server outside the vehicle. The authentication information can be transmitted, for example, from the control device to the server. In response to the transmission of the authentication information to the server, the server sends acknowledgment information, which can be received, for example, by the control device. The acknowledgment information indicates that the authentication information has been transmitted to the server. In the control device, the authentication information is enabled for controlling the function of the control device via the mobile terminal using the authentication information.In other words, the authentication information generated by the control device and transmitted to the mobile device is only released by the control device once it has also been transmitted to the server and this transmission has been acknowledged by the server. By additionally transmitting the authentication information to the server, insurance requirements can be met, for example, which stipulate that information indicating which mobile devices or devices have access to the vehicle is available. This information is available on the server even if the vehicle has been stolen, for example.

[0019] In order to register a further mobile terminal, via which one or more functions of the control device are to be controllable, with the control device, a further piece of authentication information is generated in the control device, which is preferably different from the previously described authentication information that was assigned to the aforementioned mobile terminal. The further authentication information is transmitted to the further mobile terminal. The further authentication information is only generated and transmitted if the identification information of the identification device could be verified by the control device. In other words, a further mobile terminal can only be registered with the control device if the control device has previously verified the identification information of the identification device.when the control device is connected to the identification device. This ensures that additional mobile devices can only be paired by people who own the identification device. People who only own a paired mobile device are unable to register additional mobile devices with the control device.

[0020] Access authorization information can be associated with the authentication information. The access authorization information is stored in the control device and defines an access authorization setting. To change the access authorization information or delete the authentication information in the control device, the control device must first verify the identification information of the identification device. If verification is successful, the access authorization information can then be changed or the authentication information deleted depending on a user input in the control device.This ensures that changing the access authorization information or deleting authentication information, whereby the mobile terminal no longer has access to the control device, can only be carried out if the identification device is simultaneously coupled to the control device for verifying the identification information.

[0021] According to the present invention, a further method for an access system for a vehicle is provided. The access system comprises a control device that can be installed in the vehicle, a code word assigned to the control device, a server outside the vehicle, and a mobile terminal. A function of the control device can be controlled via the mobile terminal depending on authentication information stored in the mobile terminal and the control device. In the method, the code word is entered into the mobile terminal by a user of the vehicle. The code word is transmitted from the mobile terminal to the server, and authentication information is generated in the server depending on the code word. The authentication information is transmitted to the mobile terminal and the control device in the vehicle.The code word can, for example, be given to the owner or occupier of the vehicle in written form together with the vehicle in which the control device is installed. This ensures that only an authorized person who is in possession of the code word can register a mobile device with the control device in order to control functions of the control device via the mobile device. The term "registration" in this context means that the mobile device receives authentication information, which is checked by the control device each time the mobile device controls a function of the control device. The authentication information can, for example, be stored on the server together with identification information of the mobile device in order to provide a list of all mobile devices registered with the control device.

[0022] In order to register a further mobile terminal with the control device, the code word must be entered into the further mobile terminal by a user and is transmitted from the further mobile terminal to the server. The server generates further authentication information. This further authentication information is preferably different from the previously described authentication information, i.e. a separate individual authentication information is generated in the server for each mobile terminal. The authentication information can, for example, also be generated as a function of identification information of the mobile terminal. The further authentication information is transmitted to the further mobile terminal and to the control device. Thus, any number of mobile terminals can be registered with the control device in order to control functions of the control device.

[0023] According to the invention, the access system further comprises an identification device assigned to the control device. The identification device, for example, an electronic key of the vehicle, comprises identification information that can be verified by the control device. After the code word has been transmitted from the mobile terminal to the server, the server can request the control device to verify the identification information of the identification device and transmit the result of this verification to the server. If the verification shows that the identification device corresponds to the identification device assigned to the control device, the server generates the authentication information and transmits it to the mobile terminal and to the control device.Thus, the authentication information is only generated and the mobile device is only registered with the control device if both the code word assigned to the control device is present and the identification device assigned to the control device is coupled to the control device via, for example, a near-field radio connection.

[0024] According to one embodiment, the previously described methods may further comprise assigning an operating parameter to the authentication information. The operating parameter is stored in the control device. The operating parameter may, for example, comprise an access time that defines the time at which the vehicle can be used using the corresponding mobile terminal. For example, the access time may be limited to a specific period of time, such as certain days of the week. The operating parameter may, for example, define a maximum speed at which the vehicle can be operated using the corresponding mobile terminal. Furthermore, the operating parameter may define a maximum distance the vehicle may travel using the mobile terminal.Furthermore, the operating parameter can include, for example, a vehicle usage period for which the vehicle can be used using the mobile device, a number of vehicle uses for which the vehicle can be used using the mobile device, an authorization to lock and / or unlock vehicle openings using the mobile device, or an authorization to start the vehicle using the mobile device. This makes it possible, for example, when using the method for a vehicle in a fleet, to individually specify for each person who is allowed to drive how fast, who is allowed to use the vehicle when, for how long, or for which distances, who can lock or unlock which openings of the vehicle, for example the glove compartment, trunk, or hood, or whether a person is only granted access to the vehicle or is also authorized to start the vehicle.

[0025] The function controlled by the mobile device can, in particular, be locking and / or unlocking vehicle doors or enabling the vehicle to start and / or drive. Thus, the mobile device can replace the traditional functions of a vehicle key.

[0026] According to the present invention, a control device for a vehicle is further provided, which comprises a first interface for coupling the control device to an identification device assigned to the control device, a second interface for coupling the control device to a mobile terminal, and a processing unit. A function of the control device can be controlled via the mobile terminal depending on authentication information stored in the mobile terminal and the control device. The processing unit is able to verify identification information of the identification device via the first interface and, if verification is successful, to generate the authentication information. The generated authentication information is transmitted to the mobile terminal via the second interface.Based on the identification information, the processing unit checks whether the identification device is the identification device that is assigned to the control device.

[0027] According to the present invention, a further control device for a vehicle is provided, which comprises a first interface for coupling the control device to a server outside the vehicle, a second interface for coupling the control device to a mobile terminal, and a processing unit. A function of the control device can be controlled via the mobile terminal depending on authentication information stored in the mobile terminal and the control device. The server generates authentication information depending on a code word assigned to the control device, which code word was entered into the mobile terminal by a user of the vehicle and transmitted from the mobile terminal to the server. The processing unit is able to receive the authentication information from the server via the first interface.

[0028] The control devices described above are thus suitable for carrying out the methods described above and therefore also include the advantages described in connection with the methods.

[0029] The present invention will be described in detail below with reference to the accompanying drawings. Fig. 1 schematically shows components of an access system according to an embodiment of the present invention. Fig. 2 shows components of a control device for a vehicle according to an embodiment of the present invention. Fig. 3 shows a flowchart of a method for registering a mobile terminal with a control device of a vehicle according to an embodiment of the present invention. Fig. 4 shows a schematic representation of components of an access system according to another embodiment of the present invention. Fig. Figure 5 schematically shows an example distribution of driving authorizations of different mobile devices for different vehicles. Fig. 6 shows a flowchart of a method for an access system for a vehicle according to another embodiment of the present invention.

[0030] The following describes methods that allow multiple people to open and start several different vehicles using a single mobile device. Communication between the mobile device and the vehicle can be achieved, for example, via a short-range radio connection, so-called near-field communication, such as NFC (Near Field Communication) or Bluetooth.

[0031] Fig. Figure 1 shows a schematic arrangement of components which are described in more detail below in connection with a method. Fig. 1 shows a vehicle 10 comprising a control device 11. The control device 11 can receive and process commands or instructions from a mobile terminal 12 assigned to a user 13. Communication 14 between the mobile terminal 12 and the control device 11 is, for example, a short-range communication. The control device 11 can also communicate with an identification device 16 via a connection 15, for example, a short-range communication. The identification device 16 can, for example, comprise an electronic key assigned to the vehicle 10 or the control device 11.The control device 11 can, for example, be coupled to a central locking system of the vehicle 10 or an electronic immobilizer of the vehicle 10 in order to forward instructions from the identification device 16 or the mobile terminal 12 to the central locking system or the immobilizer. The control device 11 can be coupled to other components of the vehicle 10, as will be described in detail below. Via a so-called online connection 17, the control device 11 can communicate with a server 18 outside the vehicle, e.g., an internet server. The online connection 17 can be implemented, for example, via a mobile radio method, such as UMTS or GSM. The mobile terminal 12, which can comprise, for example, a mobile phone, a personal digital assistant (PDA), or a so-called smartphone, can also communicate with the server 18 via an online connection 19.

[0032] During communication between the mobile terminal 12 and the control device 11, for example, to unlock a vehicle door of the vehicle 10 or to enable the start of a drive engine of the vehicle 10, authentication information is used, which is known to both the mobile terminal 12 and the control device 11. Using the authentication information, for example, information can be transmitted in encrypted form, or the authentication information can be transmitted and verified together with an instruction. For example, a so-called rolling code based on the authentication information can be used to prevent the communication between the mobile terminal 12 and the control device 11 from being intercepted and replayed by an attacker at a later time.The authentication information is stored in the control device 11 in a system for a so-called "virtual key management" (VKM), i.e., a key management system. Fig. 2 shows a control device 11 with a key management system (VKM) 20. The control device 11 further comprises an interface or a system for mobile online services 21 for coupling the key management system 20 to a database 22 of the server 18. The control device 11 further comprises a so-called keyless-go system 23, which can detect the presence of an identification system 25, such as an electronic vehicle key, via an identification and communication unit 24 in order to enable the start of a drive engine of the vehicle or an electronic immobilizer 26. For communication with the identification system 25, the control device 11 comprises, for example, a short-range radio interface 27 for an exterior area of ​​the vehicle 10, for example in the area of ​​the doors, and a short-range radio interface 28 for the interior of the vehicle 10.Such short-range radio interfaces are also referred to as "NFC readers." The short-range interface 27 can be used, for example, to receive commands to unlock and lock (Open / Close) vehicle doors. The short-range radio interface 28 in the interior can, for example, receive commands to release (Go) the keyless-go system 23.

[0033] Fig. 3 shows method steps for registering the mobile terminal 12 with the control device 11 of the vehicle 10. The vehicle 10 is equipped for such a function and includes, for example, a menu-oriented operating system with which the method steps described below can be controlled by a user 13. Furthermore, the user of the vehicle 10 has received a so-called identification system (IDS) together with the vehicle 10. This identification system 16 can be a separate identification transmitter (ID transmitter) or secret carrier, or, for example, an original vehicle key with an additional function for transmitting secret information to the control device 11. The identification system 16 is known to the vehicle 10 or the control device 11 upon delivery of the vehicle 10, analogous to a vehicle key.The identification system 16 serves to activate and enable a management function of the VKM system 20 in the vehicle 10 in order to be able to teach and manage a mobile terminal 12.

[0034] In step 30, a user of the vehicle 10 selects and confirms a menu for registering a mobile terminal via a user interface of the vehicle 10. The control device 11 then searches for an identification system 16 in step 31 by attempting, for example, via the short-range radio interfaces 27 and 28 to establish a radio connection to the identification system 16. If no identification system 16 was found in step 32 after, for example, a predetermined time, the user is asked via the user interface in step 33 whether the search should be aborted and the registration process of the mobile terminal ended. If the user confirms, the process is ended. Otherwise, the search for the identification system 16 continues in step 31.If an identification system was found in step 32, the identification information of the identification system 16 is verified in step 34, thus checking whether the user is authorized to log in and manage a mobile terminal 12. If it is determined in step 35 that the identification system 16 is invalid, the login process is aborted. Otherwise, in step 36, a search is carried out for a mobile terminal 12 within the range of the short-range radio interfaces 27 or 28. If no mobile terminal 12 is present within the range of the short-range radio interfaces 27, 28, the login process is aborted. Otherwise, in step 37, authentication information for the mobile terminal 12 is generated. The authentication information for the mobile terminal 12 is individual for the mobile terminal 12 and is also referred to as a device individual secret key code (DI-SKC).The authentication information is transmitted to the mobile terminal 12, stored there, and receipt is acknowledged (step 37). Furthermore, the authentication information is stored in the VKM of the control device 11. In step 38, the authentication information is transmitted to the server 18, a so-called backend, and this server 18 acknowledges receipt of the authentication information. After the authentication information has been received and acknowledged by the server 18, the authentication information is released in the control device 11 in order to receive and process instructions transmitted from the mobile terminal 12 to the control device 11 using the authentication information. This completes the registration process for the mobile terminal 12.Any number of additional mobile terminals can be registered with the control device 11 in the same way, but each mobile terminal 12 receives individual authentication information.

[0035] After the mobile terminal 12 has registered, communication between the mobile terminal 12 and the control device 11 takes place using the authentication information, directly, for example, via the short-range radio interfaces 27, 28. An online connection 19 or 17 between the mobile terminal 12 or the control device 11 and the server 18 is therefore not required for communication between the mobile terminal 12 and the control device 11. Furthermore, different usage conditions can be assigned to the authentication information assigned to a specific mobile terminal 12, for example, a speed limit, a number of kilometers traveled, a number of times the vehicle can be used, or a number of days the vehicle can be used. The assigned conditions can be structured differently for each vehicle and user.The assigned conditions or authorizations can be individually changed, deleted, reassigned, expanded, or reduced. Since user management is carried out in the vehicle, flexible start and drive authorization management is possible. The user authorizations are primarily stored and managed in the vehicle. In addition, the user authorizations can also be transferred to the mobile device 12 and displayed there, for example, to a user. A change to the user authorizations can be made in the control device 11 even if the mobile device 12 is not coupled to the control device 11. The only condition for changing the user authorizations in the control device 11 is that the identification system 16 is present and has been verified. The customer can thus independently and menu-drivenly teach in mobile devices, provided they are in possession of the identification system 16.The authentication information for the mobile terminal 12, also referred to as a "secret," is generated in the vehicle 10 and transmitted to the mobile terminal 12. Since the transmission between the vehicle 10 and the mobile terminal preferably takes place via the short-range radio interfaces 27, 28, eavesdropping and misuse of the authentication information can be prevented.

[0036] In addition to the authentication information, the control device 11 can generate an initial rolling code, which is also transmitted to the mobile device 12 in parallel with the authentication information. This rolling code is part of the shared secret for opening and starting the vehicle and is designed to be changed according to a specified procedure after each correct operation (opening and / or starting), analogous to a rolling code transponder procedure in a conventional vehicle key.

[0037] The mobile terminal 12 can be registered with multiple vehicles. In order to distinguish between multiple vehicles 10 in the mobile terminal 12, a vehicle identification code, such as a chassis number or a secure derivation thereof, can be transmitted to the mobile terminal 12 during the registration process and stored in the mobile terminal. This vehicle identification code can be used in the communication between the mobile terminal 12 and the control device 11.

[0038] As previously described, the authentication information is additionally transmitted to a server or backend 18. This can be done, for example, based on symmetric encryption and using a so-called challenge-response procedure. This can prevent eavesdropping or misuse of the authentication information.

[0039] Combined with Fig. 4, a further method for registering a mobile terminal 12 with a vehicle 10 or a control device 11 will be described. In this method, a password letter 40 with a code is additionally used, which is required for registering the mobile terminal 12. This method requires an online connection 19 between the mobile terminal 12 and the server 18, as well as an online connection 17 between the control device 11 and the server 18. After the training of a new mobile terminal 12 has been activated in the vehicle 10 via a user interface, a corresponding request is transmitted via the online connection 17 to the server 18 set up for this purpose. The required data, in particular the authentication information and, if applicable, an initial switching code, are generated and provided in the server 18. The connection 19 between the server 18 and the mobile terminal 12 is then established.The server 18 requests the user 13, via the mobile terminal 12, to enter the code of the password letter 40. The code is transmitted from the mobile terminal 12 to the server 18. The control device 11 verifies whether the identification system 16 associated with the vehicle 10 is present, as previously described in connection with . Fig. 3. The result of the verification of the verification system 16 is transmitted via the connection 17 to the server 18. If a connection exists between the server 18 and the vehicle 10 and a connection 19 between the server 18 and the mobile terminal 12, and if both the code of the password letter 40 and the identification system 16 could be verified, the server 18 transmits the generated authentication information to both the control device 11 and the mobile terminal 12. As a result, the mobile terminal 12 is trained, i.e., registered, with the control device 11.

[0040] After or during the login process, device properties or user attributes can be configured for access or startup. These parameters are assigned to the authentication information and stored in the VKM 20. These parameters can optionally also be transmitted to the server 18.

[0041] In Fig. 5 schematically shows that, using the previously described methods, multiple mobile devices can be registered to a vehicle, and, in addition, a mobile device can also be registered to different vehicles. For example, mobile device 51 is registered to vehicles 56 and 57, mobile device 52 is registered to vehicles 56 and 57, mobile device 53 is registered to vehicles 57 and 58, mobile device 54 is registered to vehicles 56, 57 and 58, and mobile device 55 is registered to vehicle 58. For each access authorization, which is Fig. 5 is represented by an arrow, individual authentication information is stored in the corresponding mobile devices 51-55 or vehicles 56-58.

[0042] User authorizations assigned to the authentication information can be subsequently changed in the vehicle, and trained mobile devices can be deleted. This requires that the identification system 16 is connected to the control device 11. However, it is not necessary for a connection to exist between the mobile device 12 and the control device 11. For example, to remove an access authorization for a mobile device 12 from the control device 11, a required menu item is selected in the vehicle and executed by the control device 11, provided that the identification system 16 could be verified. To correct the parameters of the user authorizations or to completely withdraw the authorizations, a transmission to the server 18 and acknowledgment of the changes by the server 18 is also required, analogous to the login process.If the server 18 cannot be reached during the change, the process can be aborted and no change is made. Alternatively or optionally, the change can be stored in the control device and automatically transmitted the next time contact is made with the server 18. It becomes valid in the control device 11 upon receipt of the acknowledgment from the server 18. In the event of a complete revocation of user authorizations, i.e., if the mobile terminal is deregistered from the control device 11, the authentication information in the VKM 20 can be deleted. If the same mobile terminal is to be granted access authorization again, a new registration is required, as previously described.

[0043] With reference to Fig.6, a process for opening and issuing a start authorization with a mobile terminal device is described below by way of example. In order to open a vehicle 10 with a mobile terminal device 12 or to obtain a start authorization for the vehicle 10, the mobile terminal device 12 must be in connection with the control device 11 via the short-range radio interfaces 27 or 28. First, in step 60, the control device 11 detects whether valid hardware, i.e. a suitable mobile terminal device 12, is in connection with the control device 11 via the short-range radio connection. In step 61, the mobile terminal device 12 is identified and, in accordance with the identification, the data stored for the mobile terminal device 12 in the VKM 20 is accessed. In step 62, the vehicle generates a random number which is sent to the mobile terminal device 12 together with a vehicle identification code.In step 64, a calculation result E(M) is generated in the mobile device based on the random number R. In step 63, a corresponding result E(F) is generated in the vehicle based on the random number R. In step 66, the result E(M) is transmitted from the mobile device 12 to the vehicle 10. In step 65, the results E(F) and E(M) are compared in the vehicle 10. If it is determined in step 67 that the results are the same, a subsequent check of the user authorizations assigned to the mobile device via the authentication information takes place in step 68. If the user authorizations are valid, for example, if the current time is a time authorized for the user, the vehicle is unlocked in step 69 and starting of the vehicle is authorized. If one of the checks in steps 67 or 68 is negative, access to the vehicle 10 is denied.

[0044] In order to start the vehicle 10, it may be necessary for the mobile terminal 12 to be arranged in the vehicle in the area of ​​the interior short-range radio interface 28. For this purpose, the mobile terminal 12 may, for example, be placed on a predetermined storage area within the vehicle 10.

[0045] If the user presses the vehicle's start button, similar to a keyless go system, a new test can be carried out as described above.

[0046] In the key management system 20 (VKM), all data of the registered and, optionally, also the deregistered mobile devices 12 are stored and managed. The data can, for example, be stored in the form of a separate data record for each mobile device 12. The data record can, for example, include an internal serial number (VKM-ID), an identification of the mobile device 12 (device ID), the authentication information (DI-SKC), a current rolling code, access authorization restrictions, driving authorization restrictions, a log file for an access and a start, and a server acknowledgment and validity status for the access authorization restrictions and driving authorization restrictions. For example, the following data can be stored in parallel in the mobile device 12: device ID, DI-SKC, rolling code, and the vehicle identification code (vehicle ID), which is identical for all mobile devices registered in the VKM.

[0047] The VKM ID is used for the internal management and differentiation of the respective data and information for a mobile device 12. In addition to the currently valid data for access and driving authorizations, previous states and data are also stored to enable subsequent verification of changes. Furthermore, future valid data for which the server has not yet acknowledged can also be stored. All access and start attempts, especially invalid ones, are logged and stored in the log file. Furthermore, all changes to access authorization restrictions or driving authorization restrictions are logged. The log file can be automatically backed up to the server on a regular basis. Access to the data in the VKM, such as reading and / or writing, is only possible to a limited extent. Verification of the identification information of the identification system (IDS) 16 is always required.This means that only the owner of the identification system can read data or change authorizations. The owner of the identification system is thus considered the master of the system and has the ability to grant or revoke access and / or driving authorizations to users of mobile devices. Furthermore, the owner of the IDS has the ability to restrict or prevent transmission of the log file to the server.

Claims

[1] Method for an access system for a vehicle, wherein the access system comprises a control device (11) which can be installed in the vehicle, an identification device (16) assigned to the control device (11) and a mobile terminal (12), wherein a function of the control device (11) can be controlled via the mobile terminal (12) in dependence on authentication information stored in the mobile terminal (12) and the control device (11), characterized by that the procedure includes: - Verifying identification information of the identification device (16) by the control device (11), wherein the control device (11) checks on the basis of the identification information whether the identification device (16) is the identification device (16) assigned to the control device (11), and if the verification is successful: - generating the authentication information in the control device (11), and - transmitting the authentication information from the control device (11) to the mobile terminal (12); - the method further comprising: - transmitting the authentication information to a server (18) outside the vehicle (10), - receiving an acknowledgment information from the server (18), wherein the acknowledgment information indicates that the authentication information has been transmitted to the server (18), and - Releasing the authentication information in the control device (11) for controlling the function of the control device (11) via the mobile terminal (12) using the authentication information. [2] Method for an access system for a vehicle, wherein the access system comprises a control device (11) which can be installed in the vehicle, a code word (40) assigned to the control device, a server (18) outside the vehicle (10) and a mobile terminal (12), wherein a function of the control device (11) can be controlled via the mobile terminal (12) in dependence on authentication information stored in the mobile terminal (12) and the control device (11), wherein the method comprises: - entering the code word (40) into the mobile terminal (12) by a user (13) of the vehicle (10), - transmitting the code word (40) from the mobile terminal (12) to the server (18), - generating the authentication information in the server (18) in dependence on the code word (40), and - transmitting the authentication information to the mobile terminal (12) and the control device (11); - wherein the access system further comprises an identification device (16) assigned to the control device (11), wherein the authentication information is transmitted from the server (18) to the control device (11) only after a successful verification of identification information of the identification device (16), wherein the control device (11) checks on the basis of the identification information whether the identification device (16) is the identification device (16) assigned to the control device (11). [3] Method according to one of the preceding claims, characterized by that the procedure further comprises: - Assigning an operating parameter of the vehicle (10) to the authentication information, and - Storing the operating parameter in the control device (11). [4] Method according to claim 3, characterized by that the operating parameter includes: - an access time at which the vehicle (10) can be used using the mobile terminal (12), - a maximum speed at which the vehicle (10) can be operated using the mobile terminal (12), - a maximum distance that the vehicle (10) can be moved using the mobile terminal (12), - a vehicle usage period for which the vehicle (10) can be used using the mobile terminal (12), - a number of vehicle uses for which the vehicle (10) can be used using the mobile terminal (12), - a release for locking and / or unlocking vehicle openings using the mobile terminal (12), and / or - an authorization to start the vehicle (10) using the mobile terminal (12). [5] Control device for a vehicle, comprising: - a first interface (24) for coupling the control device (11) to an identification device (16) associated with the control device (11), - a second interface (27, 28) for coupling the control device (11) to a mobile terminal (12), wherein a function of the control device (11) can be controlled via the mobile terminal (12) depending on authentication information stored in the mobile terminal (12) and the control device (11), and - a processing unit (20, 24) which is designed to verify identification information of the identification device (16) via the first interface (20) and, if the verification is successful, to generate the authentication information and to transmit it to the mobile terminal (12) via the second interface (27, 28), wherein the processing unit (20, 24) checks on the basis of the identification information whether the identification device (16) is the identification device (16) assigned to the control device (11); - wherein the control device (11) is designed to carry out a method according to claim 1 or according to one of claims 3 or 4, in which reference is made back to claim 1. [6] Control device for a vehicle, comprising: - a first interface (21) for coupling the control device (11) to a server (18) outside the vehicle, - a second interface (27, 28) for coupling the control device (11) to a mobile terminal (12), wherein a function of the control device (11) can be controlled via the mobile terminal (12) depending on authentication information stored in the mobile terminal (12) and the control device (11), and - a processing unit (20) which is designed to receive the authentication information from the server (18) via the first interface (21), wherein the authentication information is generated by the server (18) as a function of a code word (40) assigned to the control device (11), which code word was entered into the mobile terminal (12) by a user (13) of the vehicle (10) and was transmitted from the mobile terminal (12) to the server (18); - wherein the control device (11) is designed to carry out a method according to claim 2 or according to one of claims 3 or 4 as referred to in claim 2.

Citation Information

Patent Citations

  • Method for unidirectional transmission of data between data processing device and vehicle from fleet of motor vehicle, involves connecting user name for user account in data processing device with vehicle identification of motor vehicle

    DE102009037234A1

  • Secured area access system, apparatus, and method

    US20110153121A1

  • Cellular Phone Entry Techniques

    US20110312273A1