Method for operating an authorization device for a vehicle, authorization device for a vehicle, method for operating a system for authorizing the operation of a vehicle, and system for authorizing the operation of a vehicle
The authorization device with a tracking unit ensures secure and convenient vehicle operation by enabling communication only when near the vehicle, effectively mitigating relay attacks.
Patent Information
- Application Number
- DE102015223342
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2015-11-25
- Publication Date
- 2026-02-19
- Estimated Expiration
- 2035-11-25
AI Technical Summary
Keyless access systems for vehicles are vulnerable to relay station attacks, allowing unauthorized access and operation of vehicles without proper authorization.
An authorization device with a tracking unit, such as GPS, determines the current location and compares it with a stored locking location to control communication states, enabling secure and convenient vehicle operation by allowing communication only when the device is near the vehicle.
Significantly reduces the probability of relay attacks by ensuring communication is enabled only when the authorization device is close to the vehicle, enhancing security and convenience.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] Method for operating an authorization device for a vehicle, authorization device for a vehicle, method for operating a system for authorizing the operation of a vehicle, and system for authorizing the operation of a vehicle
[0002] A method for operating an authorization device for a vehicle and a corresponding authorization device for a vehicle are described. Furthermore, a method for operating a system for authorizing the operation of a vehicle and a corresponding system for authorizing the operation of a vehicle are described.
[0003] Keyless access systems for vehicles, especially motor vehicles, are also known as keyless entry or keyless go. These systems allow for the automatic unlocking and starting of a vehicle without the active use of a car key. For this purpose, the vehicle user carries a short-range communication unit which, for example, when the user mechanically operates a door handle, provides the vehicle with a cryptographic key for authentication. After successful authentication, the vehicle is unlocked and can be started.
[0004] In a so-called relay station attack (RSA), the radio link between the communication unit and the vehicle can be extended using relay stations. As a result, an attacker can unlock and start the vehicle without authorization.
[0005] Vehicle access systems are known from the publications DE 11 2013 006 560 T5, DE 100 46 571 A1, DE 102 35 132 A1, DE 10 2005 003 452 A1 and DE 10 2013 015 478 A1.
[0006] The object of the invention is to provide a method for operating an authorization device for a vehicle, as well as a corresponding authorization device, which contributes to a high level of protection against manipulation. A further object of the invention is to provide a method for operating a system for authorizing the operation of a vehicle, as well as a corresponding system, which contribute to secure and convenient authorization for operating the vehicle.
[0007] The problems are solved by the independent patent claims. Advantageous embodiments are characterized in the dependent claims.
[0008] According to a first aspect, the invention is characterized by a method for operating an authorization device for a vehicle. The authorization device is configured for first-order communication with the vehicle. The authorization device includes a tracking unit configured to determine the current location of the authorization device.
[0009] In this process, a locking location is provided to the authorization device. The locking location is representative of a location of the vehicle where the vehicle was last locked.
[0010] The tracking unit is placed in a state of operation that determines the current location of the authorization device, at least for a predetermined period of time.
[0011] Depending on the current location and the locking position, a communication operating state of the authorization device is controlled. This communication operating state represents the authorization device's communicative operation. If the authorization device is in this communication operating state, an initial authorization signal is provided to operate the vehicle via this first communication.
[0012] The authorization device is, for example, a key for the vehicle, such as a remote key. Alternatively, the authorization device can also be a suitably equipped data processing device such as a smartphone or similar.
[0013] The initial communication can be a predefined communication protocol, such as Near Field Communication (NFC). For example, during this initial communication, the vehicle sends a request signal, which is received by the authorization device. Depending on the request signal, the authorization device then sends a response signal to the vehicle, which, for example, represents locking or unlocking the vehicle. In particular, this initial communication can authorize keyless operation of the vehicle, i.e., unlocking and starting without active input. Additionally, the authorization device can use a mechanical key and / or a conventional radio module to lock and / or unlock the vehicle.
[0014] The tracking unit is primarily a satellite-based system such as GPS (Global Positioning System). Alternatively, tracking can also be achieved using or in combination with GSM tracking (Global System for Mobile Communications, GSM) and / or using or in combination with WLAN tracking (Wireless Local Area Network).
[0015] The tracking unit can, for example, be continuously in operation, determining the current location of the authorization device. Preferably, the tracking unit is only placed in operation, determining the current location of the authorization device, for a predetermined period of time, for example, cyclically.
[0016] The current location and the locking location are each a key parameter, including, for example, GPS data. The locking location is stored, for instance, in a memory unit assigned to the authorization device. Alternatively, the locking location can also be provided by a backend system. The locking location is not provided by the vehicle itself. Therefore, controlling the operating state based on the current location and the locking location is not simply a matter of comparing the actual vehicle position with the current location of the authorization device.
[0017] For example, depending on the current location and the locking location, a distance between the current location and the locking location is determined. If this distance falls below a certain threshold, the authorization device is switched to a communication operating state, enabling it to communicate. In other words, the authorization device's first communication is only enabled when it is close to the locking location, for example, by activating an antenna designed for this initial communication. The threshold could, for example, depend on the antenna's range. Similarly, if the threshold is exceeded, the authorization device could be switched to an operating state in which initial communication is deactivated or severely restricted.
[0018] Advantageously, this allows the authorization signal for operating the vehicle, such as the aforementioned response signal for unlocking the vehicle, to be sent only when the authorization device is actually near the vehicle or the locking point. A relay attack would therefore only be effective in this proximity, significantly reducing the probability of an attack occurring while the owner of the authorization device is present.
[0019] The current location of the authorization device is re-determined after a predetermined time interval. This predetermined time interval is determined based on the distance between the current location and the locking location.
[0020] This advantageously contributes to energy-efficient operation of the authorization device. In particular, it allows the system to determine when the distance between the authorization device and the vehicle, or between the current location and the locking point, falls below the predefined threshold at which the authorization device enters the communication operating state, which is representative of communicating operation. For example, the predefined time interval is shortened as the distance decreases and lengthened as the distance increases. The predefined time interval is, for example, between one minute and one hour.
[0021] In a further advantageous embodiment according to the first aspect, the authorization device includes a storage unit. If the vehicle is locked by the authorization device, a first determined current location of the authorization device is stored in the storage unit as the locking location after the locking process has been carried out.
[0022] Advantageously, this method eliminates the need to query the locking location, thus preventing manipulation attempts where an attacker provides a falsified vehicle location near the authorization device. To transition to the communication operating state, which is representative of the authorization device's active operation, the device simply compares the current location with the stored locking location. This ensures a particularly high level of tamper resistance against relay attacks.
[0023] If a location cannot be determined at the time the locking process is performed, for example, because the authorization device is located in an underground parking garage, the earliest location receivable by the tracking unit is stored as the locking location. In this case, a period of time without signal reception from the tracking unit can be stored as a feature, so that when subsequently approaching the stored locking location, this period of time without signal reception is also waited for before the authorization device switches to the communication operating state, which is representative of a communicating operation of the authorization device.
[0024] In a further advantageous embodiment according to the first aspect, the authorization device has a communication interface. This communication interface is configured for communication with a backend. When the authorization device performs a locking operation on the vehicle, the device's initial, determined current location is provided as the locking location via the communication interface after the locking operation has been completed. The communication interface can, in particular, be a mobile communication unit. Advantageously, this enables synchronization of the locking location, so that when several such authorization devices are used, authorization to operate the vehicle by the respective authorization device is possible even if the vehicle's locking location changes.This contributes to reliable and comfortable operation of the vehicle.
[0025] To transition to the communication operating state, which is representative of the authorization device's communicative operation, the authorization device queries, for example, the locking location stored in the backend and compares it with the current location. This prevents manipulation attempts where an attacker provides a falsified location of the vehicle near the authorization device. This ensures a high level of security against relay attacks.
[0026] In the event that no location can be determined at the time the locking process is carried out, the earliest possible location receivable by the tracking unit can be provided to the backend as the locking location, as well as optionally the period without reception of the tracking unit or a route characteristic value as described below, as already described.
[0027] In a further advantageous embodiment according to the first aspect, the authorization device comprises a vibration and / or motion sensor unit. The vibration and / or motion sensor unit detects any movement of the authorization device. Depending on the detected movement of the authorization device, the operation of the tracking unit, which determines the current location of the authorization device, is controlled.
[0028] This advantageously contributes to particularly energy-efficient operation of the authorization device. In particular, it allows for the detection of potential changes in the distance between the authorization device and the vehicle, or between the current location and the locking point. For example, the tracking unit's operation, which determines the current location of the authorization device, is deactivated if no movement of the authorization device has been detected for a predetermined period. In this context, the aforementioned predetermined time interval is interrupted.
[0029] In a further advantageous embodiment according to the first aspect, the authorization device comprises a vibration and / or motion sensor unit. The vibration and / or motion sensor unit detects any movement of the authorization device. Depending on the detected movement of the authorization device, the communication operating state of the authorization device is controlled.
[0030] This advantageously contributes to energy-saving operation of the authorization device. For example, the authorization device can switch to an inactive operating state independently of the tracking unit if no movement of the authorization device is detected.
[0031] In a further advantageous embodiment according to the first aspect, a distance parameter is determined depending on the detected movement of the authorization device. The distance parameter is representative of the distance traveled by the authorization device.
[0032] Depending on the last location determined by the tracking unit and the route identifier, a corrected current location is determined. The communication operating state of the authorization device is then controlled based on this corrected current location.
[0033] This advantageously enables particularly reliable and tamper-proof operation of the authorization device. For example, if the tracking unit is in a non-receiving state or is performing a relatively inaccurate location measurement, the distance parameter can be used. The distance parameter can, for example, comprise a movement pattern, analogous to a pedometer. Depending on the corrected current location, it can be inferred, for example, that the device is approaching the locking position.
[0034] In a further advantageous embodiment according to the first aspect, the authorization device includes a first near-field antenna. The first near-field antenna is configured for initial communication with the vehicle.
[0035] Controlling the communication operating state of the authorization device includes controlling the communicating operation of the first near-field antenna. For example, this involves disconnecting the first near-field antenna and / or significantly reducing its transmit and / or receive range. The first near-field antenna is configured, for example, to receive frequencies in the longwave (low frequency, LF) range, such as 125 kHz or 130 kHz, and / or in the very low frequency (VLF) range, such as 20 kHz. The first near-field antenna is also configured, for example, to transmit frequencies in the decimeter wave (ultra high frequency, UHF) range, such as 315 MHz, 433 MHz, or 868 MHz. The first near-field antenna may, in particular, be a so-called radio-frequency identification (RFID) transponder.For example, such an active transponder has a power supply that can be switched on or off as part of controlling the communicating operation of the transponder, so that its transmit and / or receive range is greatly reduced.
[0036] Advantageously, the first near-field antenna enables keyless operation of the vehicle without active activation of the authorization device.
[0037] In a further advantageous embodiment according to the first aspect, the authorization device has a second near-field antenna. The second near-field antenna is configured for a second communication with the vehicle.
[0038] A second authorization signal for operating the vehicle is provided via the second communication channel.
[0039] The second authorization signal serves, for example, to enable the vehicle to be started. In this context, the second communication can, for instance, take place solely between the second near-field antenna and the vehicle's interior antennas, so that authorization is only granted when the user is inside the vehicle. The second near-field antenna can then, for example, remain continuously in communication mode. Advantageously, this allows the vehicle to be started even if the authorization device remains inactive for an extended period, such as when the user is waiting inside the vehicle with the engine off.
[0040] According to a second aspect, the invention is characterized by a method for operating a system for authorizing the operation of a vehicle. The system comprises a backend with a communication interface and at least one authorization device.
[0041] At least one authorization device performs a procedure according to the first aspect.
[0042] In an advantageous embodiment according to the second aspect, a locking location is provided to the at least one authorization device via the communication interface of the backend. The locking location is representative of a location of the vehicle at which the last locking process of the vehicle was carried out. If a locking process of the vehicle is carried out by the at least one authorization device, a first determined current location of the respective authorization device after execution of the locking process is provided to the backend as the locking location.
[0043] Advantageously, this allows for synchronization of the locking location, so that even if the vehicle's locking location changes when multiple such authorization devices are used, authorization to operate the vehicle is still possible via the respective authorization device. This contributes to reliable and convenient vehicle operation.
[0044] To transition to the communication operating state, which is representative of the authorization device's communicative operation, the authorization device sends a request signal to the backend. The backend provides the requesting authorization device with the most recent locking location determined by one of the multiple authorization devices, which the backend then compares with its own current location. This prevents manipulation attempts where an attacker provides a falsified vehicle location near the authorization device. This ensures a high level of security against relay attacks.
[0045] In the event that no location can be determined at the time the locking process is carried out, the earliest possible location receivable by the tracking unit can be provided to the backend as the locking location, as well as optionally the period without reception of the tracking unit and / or the route identifier, as already described.
[0046] According to a third aspect, the invention is characterized by a system for authorizing the operation of a vehicle. The system comprises a backend with a communication interface and at least one authorization device. The system is configured to carry out a method according to the second aspect.
[0047] Examples of implementation are explained in more detail below with reference to the schematic drawings.
[0048] They show: Fig. 1 a system for authorizing the operation of a vehicle in a first state, Fig. 2 the system according to Fig. 1 in a second state, Fig. 3 the system according to Fig. 1 in a third state, Fig. 4 a first embodiment of a system for authorizing the operation of a vehicle, Fig. 5 an authorization device according to the first embodiment, Fig. 6. A flowchart for operating the system according to the first embodiment, Fig. 7 a second embodiment of a system for authorizing the operation of a vehicle, Fig. 8 the authorization device according to the second embodiment, Fig. 9 a flowchart for operating the system according to the second embodiment, and Fig. 10 a third embodiment of an authorization device.
[0049] Elements of the same construction or function are provided with the same reference symbols across all figures.
[0050] The following describes an automatic system for unlocking a vehicle without actively using a car key and starting it simply by pressing the start button. This is made possible by an authorization device such as a chip-enabled vehicle key carried by the vehicle user.
[0051] As soon as a hand approaches a vehicle door handle to within a few centimeters, the system is awakened from its "sleep mode" by a capacitive or optical proximity sensor and transmits a coded request signal via several antennas distributed throughout the vehicle. The system then enters a receive mode and waits for an acknowledgment signal. If the authorization device is within range, it receives the acknowledgment signal, decodes it, and retransmits it as a response signal with a new code. Inside the vehicle, a control unit decodes the response signal and compares it to the request signal. If no correct response signal is received within a predetermined time, the control unit returns to sleep mode. Pulling the door handle has no effect, as the system does not change the state of the door lock.If the response signal is correct, the control unit releases the door lock, and the door can be opened by pulling the door handle. Alternatively, the vehicle can also be opened by using the remote control and / or a mechanical emergency key. The authorization device therefore includes, for example, the mechanical emergency key, the remote control, and an RFID transponder.
[0052] Starting the engine is essentially the same as unlocking the doors, except that the engine start / stop button is pressed. Crucially, the control unit must have recognized the transponder as being in the vehicle.
[0053] The maximum range of an RFID transponder, for example, is between 2 meters and several tens of meters, but as described earlier, this can be increased through a so-called relay attack. For this reason, such access systems are highly controversial. However, a distinction must be made between standard key fob systems and true keyless access systems. These systems will be explained in more detail below.
[0054] Fig. 1, Fig. 2 to Fig. Figure 3 shows a system for authorizing the operation of a vehicle 200 in three states. The authorization device 100 is, for example, designed as a radio key that is located outside a near-field area (first and third states). Fig. 1, Fig. 3) or within the near field (second state) Fig. 2) regarding vehicle 200.
[0055] The authorization device 100 is designed, for example, to communicate using at least one of the following radio technologies: Remote Keyless Entry (RKE), Passive Keyless Entry (PKE), Near Field Communication (NFC).
[0056] In this context, the authorization device 100 includes, for example, a radio unit 101 for activating remote keyless entry (RCE) via a push button. RCE allows, for example, vehicle doors and trunk lids to be unlocked or locked by sending a radio signal when the vehicle user presses the button. The radio unit 101 is configured, for example, to transmit an RCE signal at 315 MHz or 433.92 MHz. The authorization device 100 also houses, for example, a microcontroller which, like the radio unit 101, only sends a precisely defined protocol when the button is pressed. Advantageously, this means that power is only consumed when the button is pressed, and the system is only vulnerable during this time.
[0057] Vehicle 200 features a control unit 201 with an RF receiver for evaluating received radio signals and activating further control units 221, 231, and 241. Control unit 221 could, for example, be a steering wheel lock, which can be released by control unit 201. Control unit 231 could, for example, be a start button for starting the engine. Control unit 241 could, for example, be an engine control unit. The RF receiver receives the data from radio unit 101 and forwards it to control units 221, 231, and 241. During this process, the identity of the transmitter is verified, and instructions for controlling the door opening are issued. Authorization devices with multiple buttons can also perform additional functions such as opening the trunk, activating the turn signals, triggering an alarm, etc.Great emphasis is placed on encrypting the transmitted protocol to ensure that only a specific vehicle is opened.
[0058] The authorization device 100 further comprises a unit for transmitting PKE and / or NFC, which is hereinafter also referred to as the first near-field antenna 111. The first near-field antenna 111 is specifically designed for initial communication with antennas 211 installed in the vehicle. This initial communication is based, for example, on PKE and / or NFC. PKE enables the vehicle user to unlock a vehicle door or the trunk simply by pulling the door handles, without having to press a button. It is sufficient for the vehicle user to carry the authorization device with them or bring it close to the vehicle.
[0059] For this purpose, a low-frequency radio link is used between the vehicle 200 and the authorization device 100. The antennas 211 of the vehicle 200 can be used in this context as described in... Fig. Figure 1 shows that the antennas can be located in different areas of the vehicle. For example, near the door opener (i.e., directly in the door or, for example, in the side mirror) or in the area of the tailgate or fuel filler cap. These built-in low-frequency antennas initiate the initial communication and can, for example, detect multiple authorization devices within a radius of 1.5 to 2 meters. Ideally, the reception radius is kept as small as possible.
[0060] As soon as the vehicle user pulls on or even touches a door handle, the control unit 201 sends a low-frequency signal to confirm the authenticity of the authorization device. Provided the authorization unit 100 and the respective antenna 211 are within range of each other, the authorization unit 100 can then transmit an RF response to the control unit 201. If the signal is successfully matched with the authorization unit 100, the vehicle is then automatically unlocked within a few milliseconds.
[0061] Furthermore, the vehicle 200 can also disable the immobilizer and unlock the ignition if the authorization unit 100 is located inside the vehicle. The engine can then be started by pressing the starter button or turning an ignition switch.
[0062] When leaving the vehicle 200, locking is achieved either by pressing a button on one of the door handles, by touching a capacitive area, or by the vehicle user moving away from the vehicle 200.
[0063] For example, short-range communication (NFC) can be used for the low-frequency radio link between the vehicle 200 and the authorization device 100. This is a radio technology for extremely short ranges that facilitates the secure exchange of data and is increasingly used for other secure transactions as well – for example, for an “electronic wallet” integrated into a mobile phone.
[0064] Such an NFC operates, for example, at 13.56 MHz with baud rates ranging from 106 kbit / s to 424 kbit / s. Unlike the systems described above, one of the NFC interfaces activates its transmitter and thus acts as the NFC initiator. The high-frequency current flowing in the antenna induces a magnetic field that extends around the antenna loop and passes through the antenna loop of the other nearby NFC interface. This creates an induced voltage in the antenna loop of the other NFC interface, which the receiver of that other NFC device can detect. If the NFC interface receives signals and the corresponding commands from an NFC initiator, this NFC interface automatically assumes the role of an NFC target. For data transmission between the NFC interfaces, the amplitude of the emitted alternating field is modulated (ASK modulation).
[0065] In Fig. Figure 1 further shows a symbolic range 113 of PKE and NFC in the area of the authorization device 100, a symbolic range 103 of RKE, and a symbolic range 213a-d of PKE and NFZ in the area of the vehicle 200 (range 213a in the area of the driver's door, range 213b in the area of the passenger door, range 213c in the area of the trunk lid, range 213d in the area of the fuel filler cap). For clarity, the range of PKE and NFC for immobilizer activation in the interior of the vehicle 200 is not shown in detail.
[0066] The authorization device 100 and / or the vehicle 200 may have an extremely short range, for example, to prevent misuse and / or due to a limited permissible transmission power. Multiple antennas 211 on the vehicle 200, positioned at different locations, can detect whether the vehicle user is at the driver's door, the trunk, or, for example, at the fuel filler cap during refueling. Accordingly, only the necessary access points can be unlocked in the vicinity of the user. If the vehicle user is, for example, more than 0.5 meters away from the vehicle 200 (see...), the system will not unlock the access points. Fig. 1) If the vehicle cannot be opened at any of the access points, then vehicle 200 cannot be started. Starting the vehicle is also not possible if the authorization device 200 is not recognized in vehicle 200. The respective range of 113, 213a-213d, for example, is a maximum of 2 meters at 125 kHz and several tens of meters at 433 MHz.
[0067] Fig. 3 shows the system according to Fig. 1 in a third state, in which the ranges 113, 213a are bridged by means of range bridging technology 300, for example in the context of a relay attack. Here, two transmit and receive units 310, 320 with symbolic ranges 313, 323 are used, which replicate an identical interface as is also present in the authorization device 100 and in the vehicle 200 itself. These two receive and transmit units 310, 320 are in turn connected to each other by means of high-speed radio technology 311, 321. If the first receive and transmit unit 310 is now positioned near the authorization device 100 and the second transmit and receive unit 320 near the vehicle 200, then the vehicle 200 and the authorization device 100 can communicate with each other undetected, regardless of the spatial distance 301. The vehicle 200 can be started and moved in this way, for example.
[0068] To make such manipulation attempts more difficult, signal propagation times and / or modulation methods can be adjusted, for example. With increasing power of manipulation components, the system remains secure according to... Fig. However, 1 is still surmountable.
[0069] Fig. Figure 4 shows a further system for authorizing the operation of a vehicle in a first embodiment, in which the effort required for manipulation is not limited to the technique of bridging distances. This system differs from the previous system in that the authorization device 100 additionally has a tracking unit 121, which is configured to determine the current location 511 of the authorization device 100. For this purpose, the tracking unit 121 receives, for example, signals from a tracking system 500, here exemplified by satellites 501, 503, 505 of a GPS system. The authorization device 100 is in Fig. 4. Examples are shown at one time at each of several locations 511a, 511b, 511c.
[0070] The authorization device 100 according to the first embodiment is described in detail in Fig. Figure 5 shows that, in addition to the tracking unit 121, the authorization device 100 may optionally include, for example, a motion and / or vibration unit 131 and / or a control device 141. The control device 141 may, for example, include a storage unit and / or a battery.
[0071] Both the size and cost, as well as the power consumption, of such components are low. In particular, these components can improve the security standard of the first system with regard to short-range radio communication. Additionally, they can increase the flexibility of keyless access and enable maintenance and / or provide vehicle owners with status information about their vehicle.
[0072] Currently, car keys are being equipped with increasingly sophisticated convenience features, which may already provide a basis for such an expansion. For example, newer remote keys often contain a control unit such as a microcontroller, in addition to the vehicle unlocking technology.
[0073] With the additional components, in particular the tracking unit 121, it is now possible to detect whether the authorization device 100 is in the vicinity of vehicle 215 and whether it functions independently of the existing radio and antenna technology and also independently of the vehicle. This would allow all externally vulnerable radio technology to be switched off as soon as the authorization device 100 is no longer in the vicinity of vehicle 215.
[0074] A GPS receiver, for example, is suitable as a tracking unit 121. These GPS receivers are now found in most smartphones and anti-theft tracking systems. They are extremely small, measuring only a few millimeters. The power consumption of such systems is also now relatively low.
[0075] To reduce the power consumption of the tracking unit 121, it is also conceivable to additionally install the motion and / or vibration unit 131 in the authorization device 100. Such components are also available in very small and inexpensive designs. They are also used in most smartphones for sports applications.
[0076] Fig. Figure 4 shows the authorization device 100 at location 511a, for example, outside the vehicle's range or not near the vehicle 215. The authorization device 100 is in a standby state in which no movements have been registered for an extended period. In this state, for example, the tracking unit 121 and the motion and / or vibration unit 131 are completely deactivated, the first near-field antenna 111 is switched off or extremely throttled, and the radio unit 101 and the control device 141 are only active briefly.
[0077] At location 511b, the authorization device 100 is outside the vehicle's range and in motion, i.e., not in a resting state. In this state, for example, the radio unit 101 and the tracking unit 121 are only active briefly. For instance, the tracking unit 121 is only active when the control device 141 activates it after a process as described in the... Fig. The algorithm described in section 6 is used to query the data. For example, the motion and / or vibration unit 131 and the control device 141 are fully active, while the first near-field antenna 111 is switched off or extremely throttled.
[0078] At location 511c, the authorization device 100 is located near vehicle 215, for example, also in a moving state. In this state, for example, the radio unit 101 is only active briefly, while the first near-field antenna 111, the tracking unit 121, the motion and / or vibration unit 131, and the control device 141 are fully active. Location 511c is, in particular, the location where vehicle 200 was last locked. Location 511c is also referred to below as the locking location.
[0079] The system, in particular the control device 141, is assigned, for example, a data and program memory in which a program is stored, which is described below using the flowchart of the Fig. Section 6 will be explained in more detail.
[0080] The program is started in step S61, in which, for example, variables are initialized. For instance, in step S61, if the vehicle 200 is locked by the authorization device 100, the current location 511 of the authorization device 100 is determined and stored in the memory unit.
[0081] For example, shortly after leaving vehicle 200, the relevant GPS data is determined and stored in the memory unit of the authorization device 100. The vehicle user ( Fig. 4, location 511c) exits vehicle 200, causing the motion and / or vibration sensor 131 to detect movement. If movement is detected, the control device 141 activates the first near-field antenna 111 for short-range communication. The authorization device 100 is thus placed in a communication operating state. As long as the vehicle user remains in the vicinity of vehicle 215, the authorization device receives short-range radio signals from vehicle 200, which may contain information such as whether vehicle 200 is currently open and not locked. For example, the first near-field antenna 111 is not deactivated at least as long as the authorization device 100 receives short-range data from an interior antenna 211 of vehicle 200 (see Figure 4). Fig. 1) receives, or if no vibrations are registered.
[0082] However, if the vehicle user leaves the vehicle's proximity 215, the authorization device 100 immediately saves the GPS data of location 511c. This is also the moment when the vehicle 200 locks itself, either directly or with a slight delay. If the vehicle user moves further away from the vehicle 200 and leaves the vehicle's proximity 215 area, which corresponds to a precisely defined area between, for example, 10 and 1000 meters around location 511c, the authorization device 100 detects this based on new GPS data, which is compared with the stored GPS data of the locking location 511c. Therefore, only GPS data that was determined simultaneously with the vehicle's "open" state and at which the short-range radio contact is lost is saved. If, on the other hand, the vehicle 200 locks itself while driving, this could also be the point at which the vehicle user manually opens the vehicle 200 from the inside.Unlocked. The program then continues in step S63.
[0083] In step S63, the authorization device 100 is located at position 511b, outside the near-field radio range of the vehicle 200. The current GPS data of the authorization device 100, encompassing the current position 511 determined by the tracking unit 121, therefore differs from the stored GPS data of the locking position 511c. The control device 141 now uses this information to control the communication operation of the first near-field antenna 121. For example, an antenna section for the short range is disconnected, or the range 113 is drastically reduced. From this point on, the authorization device 100 is no longer susceptible to external attack by artificially simulating the presence of a nearby vehicle. The program then continues in step S65.
[0084] In step S65, the tracking unit 121 is switched to a mode that determines the current location 511 of the authorization device 100 for at least a predetermined period. The authorization device 100 compares the current GPS data with the stored GPS data so that the first near-field antenna 111 can be activated in a timely manner. If the authorization device 100 is located outside the vehicle's vicinity 215, the program continues directly in step S65. Alternatively, for example, to extend the battery life of the authorization device 100, the program can also be continued in step S65 only after a predetermined time interval, so that the GPS tracking or position determination is carried out again with a delay.
[0085] In particular, the time interval can be determined depending on the distance to vehicle 200, or the position determination can be performed depending on the distance. Depending on a last determined distance and a theoretically possible approach to vehicle 200, a timer can, for example, trigger the next position determination. Advantageously, the motion sensor 131 can also be used for this purpose. The more vibrations the motion sensor 131 detects and the smaller the calculated distances between the GPS positions, the shorter the GPS position determinations need to be. If the motion sensor 131 does not register any movement, no position determination is carried out. This ensures that the authorization device 100 detects the area around the vehicle 215 early and activates the first near-field antenna 111 in a timely manner.Thus, safe and convenient keyless access to the vehicle 200 is achievable.
[0086] If the authorization device 100 is not moved, for example, placed down, etc., it switches to standby or sleep mode. In sleep mode, the first near-field antenna 111 remains deactivated, and the authorization device 100 requires virtually no power. In this case, as if no movement of the authorization device 100 is detected for a certain period of time, the program continues at step S67. Otherwise, if the authorization device 100 is within the vehicle's proximity 215, the program continues at step S69.
[0087] In step S67, the system checks whether the authorization device 100 is moved. Only upon another vibration, e.g., when the vehicle user picks up the authorization device 100 in the morning, does the authorization device 100 reactivate and the program continues in step S65, allowing GPS data to be synchronized.
[0088] Sleep mode and GPS data acquisition can be configured flexibly and depending on the environmental data. If the authorization device 100 receives radio data from inside the vehicle, for example, from antenna 211, which is used to authorize the ignition and immobilizer, the authorization device 100 does not enter sleep mode. This also ensures that the vehicle 200 does not lock itself automatically if the vehicle user leaves the vehicle 200 without the authorization device 100.
[0089] Even an authorization device 100, simply enhanced with the motion / vibration sensor 131, could improve tamper resistance. Linking it to the tracking unit 121 can further enhance tamper resistance. In particular, the effort required for manipulation is significantly increased. However, if fake GPS data is superimposed on the genuine signals, it will only be evaluated if the authorization device 100 is in motion and not in sleep mode. Optionally, as mentioned above, additional improvements can be made to the existing communication system.
[0090] In step 69, the first near-field antenna 111 is switched to communicating mode, so that operation of the vehicle 200, such as unlocking or starting the engine as described above, can be authorized. The program then continues in step S61.
[0091] Fig. Figure 7 shows a system 1 for authorizing the operation of a vehicle 200 in a second embodiment. This system 1 differs from the previous embodiment in that the authorization device 100 additionally has a communication interface 151 (see detailed illustration in Figure 7). Fig. 8) The communication interface 151 is, for example, a mobile communication unit such as GSM, UMTS, or LTE. In this context, the communication interface 151 includes, for example, a subscriber identification module such as a SIM card. In contrast to the first embodiment, the system 1 also has a backend 400 with a communication interface 401, 403, 405. In particular, the system 1 can include several such authorization devices.
[0092] In the future, the automatic emergency call system eCall will be mandatory for all vehicles in the EU. Furthermore, many vehicles will offer internet connectivity or be technically equipped for it. This means that every vehicle is already equipped with a mobile SIM card or has the necessary infrastructure for one. Therefore, in principle, every future vehicle would be able to transmit specific vehicle data to an external system.
[0093] SIM cards are available in very small, compact sizes such as Mini-SIM, Micro-SIM, and Nano-SIM as pluggable systems, or as an even smaller embedded SIM system that is installed directly. One SIM card size is, for example, 6 mm x 5 mm. If a data transmission device (including an embedded SIM card) is added to each authorization device 100, certain data can be encrypted and synchronized as needed. These do not have to be different SIM cards; rather, the SIM cards can have the same subscriber ID, for example, like one installed in the vehicle 200. Alternatively, it is also conceivable that the authorization devices 100 could have a subscriber ID independent of the one installed in the vehicle 200. In particular, the vehicle 200 does not need digital data access in this case.For such a system, for example, provider fees can be low, since no telephony function is used, but only a very small data volume is incurred, which can be organized by the vehicle manufacturer.
[0094] The purpose of mobile data access is an encrypted comparison of GPS data so that all authorization devices 100 assigned to the vehicle 200 can query the locking location 511c. Similar to theft tracking devices that send GPS location information, the authorization device 100 can store the GPS data recorded when the vehicle 200 is locked, encrypted, in the backend 400, for example, on external storage. This could be, for example, an encrypted cloud service offered and managed by the vehicle manufacturer.
[0095] In the second embodiment at location 511c, both the vehicle 200 and the authorization device 100 can receive and internally store the GPS data at the moment the vehicle 200 is locked, and also transmit it in encrypted form to the backend 400. In this state, for example, the communication interface 151 is also fully active.
[0096] In the second embodiment, at location 511b, it is also possible to query the backend 400 to determine whether a newer locking location 511c exists with respect to the time key. In this state, for example, the communication interface 151 is only active for a short time.
[0097] In the second embodiment, for example, at location 511a, the first near-field antenna 111 and the communication interface 151 are completely deactivated.
[0098] Authorization occurs as follows: The vehicle user is initially inside vehicle 200. The authorization device 100 is active in the near field because it is still receiving signals from the vehicle 200's internal near-field antenna 211. The vehicle user exits vehicle 200. As they do so, they move, and the motion / vibration sensor 131 registers this movement. They leave vehicle 200, and the near-field receiver detects the antenna 211 in the door area. Vehicle 200 can now locate the authorization device 100 in the door area. The authorization device 100 also receives the near-field radio data from the antenna 211 in the door area. At this precise moment, both the authorization device 100 and vehicle 200 are informed that the vehicle user is about to leave the near-field radio range of vehicle 200. Consequently, the current GPS data is received.If the near-field contact is lost, the authorization device 100 saves the last received GPS data. The vehicle 200 proceeds identically. It determines the current GPS data and transmits it, encrypted, to the backend 400 via the communication interface 401. In the backend 400, this data is stored as the locking location 511c, along with the time key.
[0099] The authorization device 100 also immediately transmits its stored GPS data encrypted via the communication interface 403 to the backend 400 after loss of short-range radio communication from the vehicle 200, where it is also stored key-related with a time key.
[0100] Depending on the permitted proximity radius of the vehicle 215, the GPS data of both the vehicle 200 and the authorization device 100 should be within a defined range of each other. The same applies to the time code of both transmitted signals. If the vehicle user moves further away from the vehicle 200 and leaves the proximity radius 215, the authorization device 100 detects this based on new GPS data, which it compares with the stored GPS data. Therefore, only GPS data acquired in close proximity at the same time as the vehicle's "open" status is stored. Thus, if the vehicle 200 locks itself while driving, this is the point in time when the vehicle user manually opens or unlocks the vehicle 200 from the inside. While the authorization device 100 moves away from the vehicle 200, the doors lock, for example, either manually or automatically after a short time.
[0101] The authorization device 100 is now located at site 511b, outside the near-field radio range of vehicle 200, and the current GPS data also differs from the stored GPS data. The control device 141 now uses this information to disconnect the first near-field antenna 111 or the antenna section for the short range, or to drastically reduce its range.
[0102] As previously described, the motion sensor 131 can also be used for position determination. The more vibrations the motion sensor 131 detects and the smaller the calculated distances between the GPS positions, the more frequently the GPS position determinations need to be. The same applies to the cloud query to check whether the stored GPS data is still up-to-date, i.e., the communication via the communication interfaces 151, 401, 403, and 405.
[0103] If the authorization device 100 is not moved, it also enters sleep mode. Only upon renewed vibration does the authorization device 100 reactivate and synchronize with the GPS data from the backend 400. If, in the meantime, differing GPS data with a newer timestamp are available in the backend 400, this data is stored internally and the query algorithms are adjusted accordingly.
[0104] Other authorization devices 100, such as those that have not been used for an extended period, function in the same way. Upon movement, the GPS data is first queried from the backend 400 and stored internally. The backend 400 always sends the GPS data with the most recent timestamp.
[0105] The data query from the backend 400 behaves similarly to direct GPS data acquisition. To save power, this can be done analogously to the first embodiment shown. The further the authorization device 100 is from the vehicle 200, the less frequently the data should be queried or acquired.
[0106] Changes in vehicle position, for example during towing, could also be synchronized with the backend 400. This could be achieved using vibration sensors in vehicle 200, such as those associated with alarm systems or crash sensors. As long as these sensors are active during a towing operation, vehicle 200 could continuously synchronize the current GPS data with the backend 400, even when locked.
[0107] GPS data acquisition and cloud usage minimize direct communication between vehicle 200 and authorization device 100. Since very little data is transmitted, extremely strong encryption can be applied, particularly to backend 400 communication. Because authorization device 100 is not constantly receiving data, there are hardly any vulnerabilities to external manipulation attacks. The identity key, or internal verification key, used to calibrate vehicle 200 and its immobilizer at the factory, remains on the corresponding authorization device 100, as with established systems.
[0108] Advantageously, the described synchronization of the locking location 511c enables separate, keyless operation of the vehicle 200 by several authorization devices 100, even if it has been moved in the meantime and has a new locking location.
[0109] A program for operating System 1 is in Fig. Figure 9 is shown. In step S91, the GPS data of the respective authorization device 100 are determined analogously to the program according to the first embodiment. However, instead of merely storing the locking location 511c in the local memory unit of the authorization device 100, it is additionally provided to the backend 400 in step S92, for example, via the communication interfaces 151, 401, 403, 405. The program then continues in step S93.
[0110] In step S93, unlike in step S63 according to the first embodiment, the locking location 511c is provided by the backend 400. For example, the location information of the vehicle 200 can be queried by the respective authorization device 100. If this information is identical to that stored in the memory unit, then the vehicle user has the currently used vehicle key. If the stored GPS data differs, then, for example, a stored time key determines which GPS data is more current.
[0111] The position data stored in backend 400 can be directly recorded by the vehicle or by the last used authorization device 100, with which the vehicle 200 was exited. The determining factor for which GPS data is the most recent is the timestamp stored at that time. This timestamp does not necessarily have to be generated by the authorization device 100, but can be stored by backend 400, for example, at the moment of connection. The probability that an authorization device 100, which locked the vehicle 200 at an earlier time, would later establish a connection to backend 400 is very low. The program then continues in step S95.
[0112] Steps S95-S99 can be performed analogously to steps S65-S69 of the program according to the first embodiment. If the authorization device 100 is in sleep mode because, for example, it is not being moved, the communication interface 151 can also be set to a communicating mode, so that no one can access the authorization device 100 via the mobile data system. Each authorization device 100 is unique, for example, because it is also prepared for the electronic immobilizer with an internal matching key. This key can then also be used for data encryption via the backend 400 and can thus be continuously adapted.
[0113] The procedures described in the first and second examples contribute to improved tamper protection. The direct costs per vehicle increase only slightly.
[0114] In a third embodiment ( Fig. Figure 10) shows an authorization device 100 which differs from the preceding embodiments in that it has a second near-field antenna 161 with a symbolic range 163. The second near-field antenna is designed, for example, analogously to the first near-field antenna 111 and serves for a second communication with the vehicle 200, separate from the first communication by the first near-field antenna 111.
[0115] The second near-field antenna 161 can therefore only be addressed by the antenna 211 located in the vehicle 200. In particular, a separate identity key can be provided via this second communication. The second near-field antenna 161 is not addressed by the antennas 211 in the vehicle door or by the antennas 211 used for vehicle access, and the vehicle 200 accepts the separate identity key only if the vehicle 200 has been properly unlocked, i.e., as described, by means of the radio unit 101 or via the first communication. The second near-field antenna 161 can then, for example, be permanently activated. Advantageously, this enables keyless starting of the vehicle 200 even if the authorization device 100 has been in place for an extended period and there is no movement. This would be the case, for example, if the vehicle 200 is switched off and the vehicle user is waiting with the engine off.
[0116] In a fourth embodiment (not shown in detail), as an alternative to the third embodiment, the first near-field antenna 111 remains active until it is actively disconnected. For example, the first near-field antenna 111 is activated as soon as the authorization device 100 approaches the vehicle 200 (see first and second embodiments), or when the vehicle 200 is opened via the radio unit 121. In both cases, the authorization device detects when it enters the interior of the vehicle 200. The first near-field antenna 111 therefore remains active. Only the GPS and backend synchronization, which requires the most energy, is suppressed. Only when the vehicle user leaves the vehicle 200 and thus moves the authorization device 100, is the first near-field antenna 111 actively disconnected, as soon as the authorization device 100 no longer detects the vehicle 200's antenna 211.
[0117] If the vehicle 200 goes into sleep mode after a certain period of time, for example, when it is stationary and its control units shut down, the internal antenna 211 no longer transmits signals, and keyless start is no longer possible. However, if the vehicle user leaves the vehicle, the internal antenna 211 is reactivated as soon as the door is opened. Thus, the first near-field antenna 111, which is permanently activated inside the vehicle 200, can be deactivated when the authorization device 100 passes the respective antenna 211 in the door area. Advantageously, this enables keyless locking of the vehicle 200 even if the authorization device 100 remains stationary for an extended period and there is no movement.
[0118] The following describes a first use case in which a driver leaves the vehicle. 1. The driver switches off the engine. 2. He leaves the vehicle using the radio key designed as an authorization device, which causes it to be moved or to register vibrations. 3. The driver passes through the vehicle door and locks the vehicle either using a remote control button or the vehicle locks automatically when the driver moves away from it. The remote key detects the near-field antennas in the vehicle door when the driver leaves the vehicle. 4. In both cases (activation of the wireless button or removal from the near-field antennas in the door area), GPS tracking is initiated. Simultaneously, the near-field wireless connection is disconnected. 5. Once GPS data has been acquired, it is stored internally in the radio key and / or compared with a backend system. A time key is then additionally stored in the backend. 6. In the special case where no GPS signal can be received immediately and / or no synchronization with the backend is possible, the key fob measures the time from when the vehicle was manually or automatically locked. This time can then be used again when the vehicle approaches to reactivate the short-range antennas earlier. 7. In the special case where no GPS signal can be received at all, e.g., in an underground parking garage, and there is no reception from the time the vehicle is locked until the key fob is stationary, the key fob stores the time from when the vehicle is locked until the point at which no further vibrations occur. In addition to being stored internally, this time data from when the vehicle is locked until the key fob goes into sleep mode can also be transmitted to the backend, for example, shortly before the key fob goes into sleep mode due to a lack of vibrations. It is also conceivable that the key fob only disconnects its antennas once GPS or network reception is established.
[0119] The following describes a second use case in which a driver takes the radio key and moves towards the vehicle. 1. The driver takes the key fob and starts moving towards the vehicle. The key fob therefore detects movement or vibration. 2. The key fob uses GPS to determine the vehicle's location and compares it to the stored values from the last vehicle locking. If a connection to a backend exists, more recent GPS data with a more recent time code can be retrieved and applied. 3. The key fob calculates the vehicle distance from the data it has determined and stored, or from data newly obtained from the backend. 4. Based on the calculated distance, the key fob can determine an internal time or time interval for when the next GPS synchronization is necessary. At greater distances, this occurs at longer intervals; at shorter distances, at shorter intervals. Therefore, the closer the key fob gets to the vehicle, the more frequently the GPS synchronizations are performed. Additional GPS queries can be useful during synchronization with the backend. For example, the vehicle might have been moved with a different key fob and parked elsewhere. If the data from the backend has changed, i.e., different GPS data with more recent timestamps are available, these are reused, and the process starts again from step 3. 5. In the special case where no GPS data is available, a period can be programmed into the key fob during which the key fob received no GPS data when locking the vehicle. This period lasts from when the vehicle was locked until the key fob was placed on a surface or no further movement was detected. For this period plus a predefined time interval, the short-range antenna is then activated. Simultaneously, GPS reception is continuously monitored while the key fob detects movement. If GPS reception becomes possible during the period in which the short-range antennas are activated, the process restarts from step 3. 6. Points 4 and 5 ensure that the short-range antennas are activated well in advance of reaching the vehicle. This can also be achieved using hysteresis, where the short-range antennas are deactivated early when moving away from the vehicle and activated earlier when approaching it. When approaching the vehicle, a relay attack or manipulation by a third party is significantly less likely. Therefore, the antenna can be activated earlier. Activating the short-range antennas early when approaching the vehicle also allows the time interval to remain relatively long, thus reducing computational effort and power consumption. 7. Whenever no movement is detected, an additional timer can record this. Depending on the time period, it can then be determined whether a new GPS query is necessary when movement resumes. The key fob should ultimately calculate the new GPS coordinates based on the period of movement. Periods in which the key fob is not moved or subjected to any vibrations are not included in the approximation calculation.
[0120] In a third use case, the driver is in the immediate vicinity of the vehicle and wants to start or restart the vehicle. 1. The driver approaches the vehicle. Using the GPS proximity algorithm, the near-field communication of the key fob was activated early enough, or the driver opens the vehicle door via the remote button. 2. In both cases, the near-field communication system in the door detects the key fob while the driver is getting into the vehicle. In the simplest case, the key fob keeps the near-field antenna activated, but foregoes further GPS alignment as long as it remains within range of the vehicle's interior near-field antenna. It also keeps the near-field antennas activated even when no further vibrations are detected. The key only deactivates the antenna when it detects the near-field antenna in the door again, or when it receives a locking command via the remote button. The moment a door is opened from the inside, these door antennas are activated, or the vehicle keeps them permanently active. 3. Alternatively, a second near-field radio antenna could be used, which is always active and only accepted by the vehicle's internal antenna. This second antenna would only be accepted, for example, if the vehicle has been approached or unlocked, and the key fob has not moved away from the vehicle or locked using the key fob. Registering the key fob at the door and then registering it inside the vehicle indicates approach. Conversely, registering it first inside the vehicle and then at the door indicates movement away from the vehicle. A constantly active second near-field radio antenna, solely for the vehicle's internal antenna, would only be recognized by the vehicle if the vehicle has previously detected vehicle access via its external antennas using GPS.In other words, the key includes separate short-range antennas for vehicle access (GPS and a switchable antenna) and a permanently active antenna for starting the vehicle. The vehicle only recognizes the permanently active antenna with a different subscriber ID for the vehicle interior if normal vehicle access has been detected. Reference symbol list: 1 system 100 authorization device 101 radio unit 103 Range 111 first near-field antenna 113 Range 121 Location unit 131 Motion sensor unit 141 Control device 151 Communication interface 161 second near-field antenna 163 Range 200 vehicles 201 Control Center 211 Antenna 213a, 213b, 213c, 213d Range 215 Vehicle proximity 221 Steering lock 231 Start button 241 Engine control unit 300 range bridging technology 310 first transmitting and receiving unit 311 High-speed radio technology 313 Range 320 second transmitting and receiving unit 321 High-speed radio technology 323 Range 400 Backend 401, 403, 405 communication interface 500 tracking system 501, 503, 505 Satellite 511 current location 511a, 511b Location 511c Locking location
Claims
[1] Method for operating an authorization device (100) for a vehicle (200) which is configured for initial communication with the vehicle (200) and includes a location unit (121) configured for determining a current location (511) of the authorization device (100), wherein - the authorization device (100) is provided with a locking location (511c) that is representative of a location of the vehicle (200) at which a last locking operation of the vehicle (200) was carried out, - the locating unit (121) is placed in an operation that determines the current location (511) of the authorization device (100) for at least a specified period of time, in which the current location (511) of the authorization device (100) is determined, - depending on the current location (511) and the locking location (511c), a communication operating state of the authorization device (100) is controlled, which is representative of a communicating operation of the authorization device (100), and - in the event that the authorization device (100) is in the communication operating state, a first authorization signal for operating the vehicle (200) is provided by means of the first communication, and in the procedure - the current location (511) of the authorization device (100) is determined again after a predetermined time interval, wherein - the specified time interval is determined depending on a distance between the current location (511) and the locking location (511c). [2] Method according to claim 1, wherein the authorization device (100) has a storage unit in which - in the event that a locking process of the vehicle (200) is carried out by the authorization device (100), a first determined current location (511) of the authorization device (100) is stored in the storage unit as a locking location (511c) after the locking process has been carried out. [3] Method according to one of the preceding claims, wherein the authorization device (100) has a communication interface (151) configured for communication with a backend (400), in which - in the event that a locking operation of the vehicle (200) is carried out by the authorization device (100), a first determined current location (511) of the authorization device (100) after the locking operation has been carried out is provided as the locking location (511c) via the communication interface (151). [4] Method according to one of the preceding claims, wherein the authorization device (100) comprises a vibration and / or motion sensor unit (131), wherein - a movement of the authorization device (100) is detected by means of the vibration and / or motion sensor unit (131), and - depending on the detected movement of the authorization device (100), the operation of the tracking unit (121) which determines the current location (511) of the authorization device (100) is controlled. [5] Method according to one of the preceding claims, wherein the authorization device (100) comprises a vibration and / or motion sensor unit (131), wherein - a movement of the authorization device (100) is detected by means of the vibration and / or motion sensor unit (131), and - depending on the detected movement of the authorization device (100), the communication operating state of the authorization device (100) is controlled. [6] Method according to one of the preceding claims 4 or 5, wherein - depending on the detected movement of the authorization device (100), a distance characteristic value is determined which is representative of a distance traveled by the authorization device (100), - depending on a location last determined by means of the location unit (121) and the route identifier, a corrected current location is determined, and - depending on the corrected current location, the communication operating state of the authorization device (100) is controlled. [7] Method according to one of the preceding claims, wherein the authorization device (100) has a first near-field antenna (111) configured for first communication with the vehicle (200), in which - includes controlling the communication operating state of the authorization device (100) and controlling the communicating operation of the first near-field antenna (111). [8] Method according to one of the preceding claims, wherein the authorization device (100) has a second near-field antenna (161) configured for a second communication with the vehicle (200), in which - a second authorization signal for operating the vehicle (200) is provided via the second communication. [9] Method for operating a system (1) for authorising the operation of a vehicle (200), wherein the system (1) comprises a backend (400) with a communication interface (401, 403, 405) and at least one authorization device (100), wherein - the at least one authorization device (100) performs a method according to any one of the preceding claims 1 to 8. [10] The method of claim 9, wherein - at least one authorization device (100) is provided via the communication interface (401, 403, 405) of the backend (400) with a locking location (511c) that is representative of a location of the vehicle (200) at which a last locking operation of the vehicle (200) was carried out, and - in the event that a locking operation of the vehicle (200) is carried out by the at least one authorization device (100), a first determined current location (511) of the respective authorization device (100) is provided to the backend (400) as a locking location (511c) after the locking operation has been carried out. [11] System (1) for authorising the operation of a vehicle (200), comprising - a backend (400) with a communication interface (401, 403, 405), and - at least one authorization device (100) wherein the system (1) is configured to perform a method according to one of the preceding claims 9 or 10.
Citation Information
Patent Citations
Vehicle key containing satellite-supported position determination device has transmitter / receiver device and with vehicle stationary, vehicle position is stored in storage unit and / or storage device of access control system
DE10046571A1
Motor vehicle localization system for use in parking garages, has evaluation device evaluating information about orientation of key and vehicle, and providing direction information of current position of key for current position of vehicle
DE102005003452A1
External secure unit
DE102013015478A1
Hand unit to help in finding an object, especially a parked car, comprises a storage unit for storing of direction and distance data as a person moves away from the object, so that the data can be replayed later as necessary
DE10235132A1
Power consumption suppression system for electronic key terminal and power consumption suppression method for electronic key terminal
DE112013006560T5