Method for operating an authorization device for a vehicle, authorization device for a vehicle, method for operating a system for authorizing the operation of a vehicle, and system for authorizing the operation of a vehicle
The authorization device with near-field communication and location tracking securely manages vehicle access by relaying authorization signals only when in proximity, addressing relay attacks and ensuring secure, convenient operation.
Patent Information
- Application Number
- DE102015223345
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2015-11-25
- Publication Date
- 2026-02-19
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing keyless access systems for vehicles are vulnerable to relay station attacks, allowing unauthorized access and operation of vehicles without proper authentication.
An authorization device with a first communication interface for near-field communication and a tracking unit to determine its location, which relays authorization signals only when in proximity to the vehicle, using a backend to authenticate and manage authorization securely.
This approach significantly reduces the likelihood of unauthorized access by ensuring that authorization signals are only sent when the device is near the vehicle, enhancing security and convenience by preventing relay attacks.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] A method for operating an authorization device for a vehicle and a corresponding authorization device for a vehicle are described. Furthermore, a method for operating a system for authorizing the operation of a vehicle and a corresponding system for authorizing the operation of a vehicle are described.
[0002] Keyless access systems for vehicles, especially motor vehicles, are also known as keyless entry or keyless go. These systems allow for the automatic unlocking and starting of a vehicle without the active use of a car key. For this purpose, the vehicle user carries a short-range communication unit which, for example, when the user mechanically operates a door handle, provides the vehicle with a cryptographic key for authentication. After successful authentication, the vehicle is unlocked and can be started.
[0003] In a so-called relay station attack (RSA), the radio link between the communication unit and the vehicle can be extended using relay stations. As a result, an attacker can unlock and start the vehicle without authorization.
[0004] Vehicle access systems are known from the publications DE 11 2013 006 560 T5, DE 10 2012 111 361 A1 and DE 102 35 132 A1.
[0005] The object of the invention is to provide a method for operating an authorization device for a vehicle, as well as a corresponding authorization device, which contributes to a high level of protection against manipulation. A further object of the invention is to provide a method for operating a system for authorizing the operation of a vehicle, as well as a corresponding system, which contribute to secure and convenient authorization for operating the vehicle.
[0006] The problems are solved by the independent patent claims. Advantageous embodiments are characterized in the dependent claims.
[0007] According to a first aspect, the invention is characterized by a method for operating an authorization device for a vehicle.
[0008] The authorization device comprises a first communication interface configured for communication with the vehicle. Furthermore, the authorization device comprises a second communication interface configured for communication with a backend. Finally, the authorization device includes a tracking unit configured for determining the current location of the authorization device.
[0009] In this process, the current location of the authorization device is determined and provided to the backend via the second communication interface.
[0010] In an authorization step, depending on an authorization value provided to the authorization device via the second communication interface, an authorization signal for operating the vehicle is provided to the vehicle via the first communication interface.
[0011] This advantageously enables convenient and tamper-proof operation of the vehicle, since the authorization signal for operating the vehicle is only sent, for example, when the authorization device is actually in the vicinity of the vehicle. A relay attack would therefore only be effective in this proximity, significantly reducing the probability of an attack occurring when the owner of the authorization device is present.
[0012] The authorization device is, for example, a suitably equipped data processing device such as a smartphone or similar device. Alternatively, the authorization device can also be a key for the vehicle, such as a remote key.
[0013] The first communication interface is, for example, a near-field antenna. Communication via this first interface can then use a predefined communication protocol, such as Near Field Communication (NFC). For instance, the vehicle provides a request signal, which is received by the authorization device. Depending on the request signal, the authorization device then provides the vehicle with a response signal, which, for example, represents locking or unlocking the vehicle. In particular, this allows for keyless operation of the vehicle, i.e., unlocking and starting without active input. The response signal is specifically the authorization signal.
[0014] The authorization signal is not triggered by the authorization device and provided to the vehicle. Rather, the authorization device itself acts as a kind of relay station, forwarding a received authorization value to the vehicle. In other words, this eliminates the need to store security-relevant data in the authorization device, thus helping to prevent unauthorized operation of the vehicle through manipulation or theft of the authorization device.
[0015] The tracking unit is primarily a satellite-based system such as GPS (Global Positioning System). Alternatively, tracking can also be achieved using or in combination with GSM tracking (Global System for Mobile Communications, GSM) and / or using or in combination with WLAN tracking (Wireless Local Area Network).
[0016] The tracking unit can, for example, be continuously operating in a mode that determines the current location of the authorization device. Preferably, the tracking unit is only placed in this mode for a predetermined period of time, for example, cyclically.
[0017] The current location is, in particular, a key metric that includes, for example, GPS data.
[0018] In an advantageous embodiment according to the first aspect, the authorization parameter is passed directly from the second communication interface to the first communication interface as an authorization signal in the authorization step.
[0019] Advantageously, no security-relevant data is temporarily stored, thus helping to prevent unauthorized operation of the vehicle through manipulation or theft of the authorization device. Passing through the authorization value can also be described as "streaming."
[0020] In a further advantageous embodiment according to the first aspect, the authorization device includes a storage unit. In this method, the authorization identifier is stored in the storage unit for the duration of the authorization step.
[0021] Advantageously, security-relevant data is stored only temporarily, thus enabling convenient vehicle operation even in areas where communication via the second communication interface is blocked, such as underground parking garages. In this context, the authorization device can be designed to detect such an area early on in order to request the authorization code. Furthermore, storing the security-relevant data only temporarily helps to prevent unauthorized vehicle operation through manipulation or theft of the authorization device.
[0022] In a further advantageous embodiment according to the first aspect, an identification value is determined that is representative of a user of the vehicle. The identification value is provided via the second communication interface.
[0023] This advantageously ensures that a user of the authorization device is indeed a legitimate user of the vehicle. This helps to prevent unauthorized operation of the vehicle through the theft of the authorization device.
[0024] Determining the identification value can, for example, include authenticating the respective user. This might involve entering an identification number (PIN) and / or capturing a fingerprint. In this context, the authorization device includes a suitable identification unit, such as a keypad or a fingerprint sensor.
[0025] In a further advantageous embodiment according to the first aspect, a start signal is provided to the tracking unit and / or the first communication interface. Depending on the start signal, the tracking unit is activated to determine the current location of the authorization device, or the first communication interface is activated to communicate with the vehicle. This advantageously minimizes the energy consumption of the authorization device. Furthermore, a relay attack can be effectively prevented by temporarily deactivating the communicating operation of the first communication interface.
[0026] The start signal can be determined or provided by the authorization device itself. For example, the start signal is provided after a predetermined time interval.
[0027] In a further advantageous embodiment according to the first aspect, the authorization device comprises a vibration and / or motion sensor unit. In this method, the vibration and / or motion sensor unit detects any movement of the authorization device. Depending on the detected movement of the authorization device, the start signal is provided to the tracking unit and / or the first communication interface.
[0028] This advantageously allows the energy consumption of the authorization device to be kept low. In particular, this makes it possible to provide the start signal only when the authorization device is in use.
[0029] In a further advantageous embodiment according to the first aspect, a locking location of the vehicle is provided to the authorization device. The locking location is representative of a location of the vehicle at which the last locking process of the vehicle was carried out.
[0030] Depending on the distance between the current location and the locking location, a time interval is determined, and depending on the time interval of the tracking unit and / or the first communication interface, the start signal is provided.
[0031] This advantageously allows the energy consumption of the authorization device to be kept low. In particular, this makes it possible to provide the start signal only when the authorization device approaches the vehicle or its locking location.
[0032] For example, in this context, the authorization device has an additional storage unit, whereby, if the vehicle is locked by the authorization device, an initial determined current location of the authorization device after the locking process has been carried out is stored as the locking location in the additional storage unit. Alternatively or additionally, the locking location is provided to the authorization device, for example, via the second communication interface.
[0033] In a further advantageous embodiment according to the first aspect, in the event that a locking process of the vehicle is carried out by the authorization device, a first determined current location of the authorization device after the locking process has been carried out is provided as the locking location via the second communication interface.
[0034] This advantageously eliminates the need for communication between the vehicle and the backend, thus contributing to a high level of tamper protection.
[0035] In a further advantageous embodiment according to the first aspect, an authorization request for authorizing the vehicle is determined by the authorization device. Depending on the authorization request, an authorization request signal is provided to the backend via the second communication interface.
[0036] This can advantageously enable third parties to authorize the operation of the vehicle. The authorization request includes, for example, the identification code and / or a specific area or component of the vehicle that the third party is seeking to authorize.
[0037] For example, the authorization request signal can be provided to a legitimate vehicle owner so that they can confirm the authorization to operate the vehicle.
[0038] According to a second aspect, the invention is characterized by a method for operating a system for authorizing the operation of a vehicle. The system comprises a backend and at least one authorization device, which is operated according to the first aspect.
[0039] In this process, the backend is provided with a locking location that is representative of the vehicle's location where the last locking process was performed. Furthermore, the backend is provided with the current location of the respective authorization device. Based on the current location of the authorization device and the vehicle's locking location, an authorization code for operating the vehicle is determined. This authorization code is then provided to the respective authorization device.
[0040] This advantageously enables convenient and tamper-proof operation of the vehicle, since the authorization code for operating the vehicle is only sent, for example, when the authorization device is actually near the vehicle or the locking point. A relay attack would therefore only be effective in this proximity, significantly reducing the probability of an attack occurring when the owner of the authorization device is present.
[0041] The locking location is, in particular, a key parameter that includes, for example, GPS data.
[0042] The authorization code is determined primarily by the backend and includes, for example, a cryptographic response code to a request signal from the vehicle, which is representative of whether the vehicle is locked or unlocked. The authorization device acts as a relay station, forwarding the received authorization code to the vehicle. Authorization itself, however, takes place in the backend, thus helping to prevent unauthorized operation of the vehicle through manipulation or theft of the authorization device.
[0043] In an advantageous embodiment according to the second aspect, the backend is provided with an identification value that is representative of a user of the vehicle. The authorization value is determined based on the identification value.
[0044] This advantageously ensures that a user of the authorization device is indeed a legitimate user of the vehicle. This helps to prevent unauthorized operation of the vehicle through the theft of the authorization device.
[0045] The identification value is determined primarily by the authorization device and includes, for example, authentication of the respective user. Alternatively, depending on the identification value, authentication is performed by the backend.
[0046] For example, the identification value includes an identification number (PIN) and / or a captured fingerprint.
[0047] The user of the vehicle in this context does not necessarily have to be a legitimate vehicle owner or driver. Rather, this can also include persons who are authorized to access at least part of the vehicle or to operate at least one component of the vehicle. For example, a parcel service may only have access to the trunk of the vehicle.
[0048] In a further advantageous embodiment according to the second aspect, the authorization indicator is representative of an authorization to operate at least one of the following components of the vehicle: - one or more doors, - trunk, - Fuel cap, - Ignition, - Engine.
[0049] In this way, access to individual areas or the use of individual components of the vehicle can be advantageously restricted or authorized for a legitimate user of the vehicle.
[0050] In a further advantageous embodiment according to the second aspect, a time interval is determined depending on the distance between the current location of the respective authorization device and the locking location of the vehicle. Depending on this time interval, a start signal is provided to the respective authorization device, which is representative of an operation of the respective authorization device that determines its current location and / or communicates with the vehicle.
[0051] This advantageously minimizes the energy consumption of the authorization device. In particular, it allows the start signal to be provided only when the authorization device approaches the vehicle or its locking location. Furthermore, a relay attack can be effectively prevented by temporarily deactivating the communicating operation of the first communication interface. Additionally, communication between the vehicle and the backend can be dispensed with, thus contributing to a high level of tamper resistance.
[0052] In a further advantageous embodiment according to the second aspect, an authorization request signal is provided for operating the vehicle by the authorization device. Depending on the authorization request signal, an authorization request message is provided to a predefined communication interface assigned to a vehicle owner, and the authorization key value is provided to the authorization device depending on a response to the authorization request message.
[0053] This can advantageously enable third parties to authorize the operation of the vehicle. The authorization request signal includes, for example, the identification value and / or a sub-area or component of the vehicle whose authorization by the third party is sought.
[0054] The specified communication interface is, for example, an email address, telephone number or customer number assigned to the vehicle owner.
[0055] In particular, the authorization request signal can also be provided to a customer account of the vehicle owner by means of a program on the authorization device, for example an “app” offered by the vehicle manufacturer.
[0056] The response to the authorization request message is, in particular, an encrypted message, thus ensuring that the sender is indeed the legitimate owner of the vehicle. For example, the response is also sent via the manufacturer's app or a web portal, where, for instance, an identification value is used to verify the user's identity, thereby guaranteeing that they are the legitimate owner of the vehicle.
[0057] According to a third aspect, the invention is characterized by a system for authorizing the operation of a vehicle. The system comprises a backend and at least one authorization device. The system is configured to perform a method according to the second aspect.
[0058] Examples of implementation are explained in more detail below with reference to the schematic drawings.
[0059] They show: Fig. 1 a first embodiment of a system for authorizing the operation of a vehicle, Fig. 2. A flowchart for operating an authorization device of the system according to Fig. 1, Fig. 3. A flowchart for operating the system according to Fig. 1, and Fig. 4 a second embodiment of a system for authorizing the operation of a vehicle.
[0060] Elements of the same construction or function are provided with the same reference symbols across all figures.
[0061] The following describes an automatic system for unlocking a vehicle without actively using a car key and starting it simply by pressing the start button. This is made possible by an authorization device such as a modern mobile phone (so-called "smartphone"), a smartwatch, or a chip-enabled vehicle key carried by the vehicle user.
[0062] As soon as a hand approaches a vehicle door handle to within a few centimeters, the system is awakened from its "sleep mode" by a capacitive or optical proximity sensor and transmits a coded request signal via several antennas distributed throughout the vehicle. The system then enters a receive mode and waits for an acknowledgment signal. If the authorization device is within range, it receives the acknowledgment signal, decodes it, and retransmits it as a response signal with a new code. Inside the vehicle, a control unit decodes the response signal and compares it to the request signal. If no correct response signal is received within a predetermined time, the control unit returns to sleep mode. Pulling the door handle has no effect, as the system does not change the state of the door lock.If the response signal is correct, the control unit releases the door lock, and the door can be opened by pulling the door handle. Alternatively, the vehicle can also be opened by using the remote control and / or a mechanical emergency key. The authorization device can therefore include, for example, the mechanical emergency key, the remote control, and an RFID transponder.
[0063] Starting the engine is essentially the same as unlocking the doors, except that the engine start / stop button is pressed. Crucially, the control unit must have recognized the transponder as being in the vehicle.
[0064] The maximum range of an RFID transponder, for example, is between 2 meters and several tens of meters, but as described earlier, this can be increased in a so-called relay attack. For this reason, such access systems are highly controversial.
[0065] Fig. Figure 1 shows a first embodiment of a system 1 for authorizing the operation of a vehicle 300, comprising an authorization device 100. The authorization device 100 is, for example, designed as a mobile phone, which may be located outside a near-field area or within the near-field area with respect to the vehicle 300.
[0066] The authorization device 100 is designed, for example, to communicate using at least one of the following radio technologies: Remote Keyless Entry (RKE), Passive Keyless Entry (PKE), or Near Field Communication (NFC). Modern mobile phones, in particular, are already equipped with the latter radio technology. Specifically, the authorization device 100 has a unit for transmitting PKE and / or NFC signals, which is also referred to below as the first communication interface 103. This unit consists, for example, of one or more near-field antennas.
[0067] The first communication interface 103 is specifically designed for communication with antennas installed in the vehicle 300, which are based, for example, on PKE and / or NFC. This allows the vehicle user to unlock a vehicle door or the trunk simply by pulling the door handles, without having to press a button. It is sufficient for the vehicle user to carry the authorization device 100 with them or bring it close to the vehicle 300.
[0068] This is achieved using a low-frequency radio link between the vehicle 300 and the authorization device 100. The vehicle 300's antennas can be located in various areas of the vehicle, such as near the door opener (i.e., directly in the door or, for example, in the side mirror), or in the area of the tailgate or fuel filler cap. These integrated low-frequency antennas initiate communication between the vehicle 300 and the authorization device 100 and can, for example, detect multiple authorization devices within a radius of 1.5 to 2 meters. Ideally, the reception radius is kept as small as possible.
[0069] As soon as the vehicle user pulls on or even touches a door handle, the vehicle 300's control unit sends a low-frequency signal to confirm the authenticity of the authorization device 100. Provided the authorization device 100 and the respective antenna of the vehicle 300 are within range of each other, the authorization device 100 can then transmit a response to the vehicle 300's control unit. If the signal is successfully matched with the authorization device 100, the vehicle 300 is then automatically unlocked within a few milliseconds.
[0070] Furthermore, the vehicle 300 can also disable the immobilizer and the ignition if the authorization device 100 is located inside the vehicle. The engine can then be started by pressing the starter button or turning an ignition switch.
[0071] When leaving the vehicle 300, locking is achieved either by pressing a button on one of the door handles, by touching a capacitive area, or by the vehicle user moving away from the vehicle 300 together with the authorization device 100.
[0072] For example, short-range communication (NFC) can be used for the low-frequency radio link between the vehicle 300 and the authorization device 100. This is a radio technology for extremely short ranges that facilitates the secure exchange of data and is increasingly used for other secure transactions as well – for example, for an “electronic wallet” integrated into a mobile phone.
[0073] Such an NFC operates, for example, at 13.56 MHz with baud rates ranging from 106 kbit / s to 424 kbit / s. In this process, one of the NFC interfaces activates its transmitter and thus acts as an NFC initiator. The high-frequency current flowing in the antenna induces a magnetic field that extends around the antenna loop and passes through the antenna loop of the other nearby NFC interface. This creates an induced voltage in the antenna loop of the other NFC interface, which the receiver of that other NFC device can detect. If the NFC interface receives signals and the corresponding commands from an NFC initiator, this NFC interface automatically assumes the role of an NFC target. For data transmission between the NFC interfaces, the amplitude of the emitted alternating field is modulated (ASK modulation).
[0074] The authorization device 100 and / or the vehicle 300 may have an extremely short transmission and reception range, for example, to prevent misuse and / or due to limited permissible transmission power. Multiple antennas on the vehicle 300, positioned at different locations, can detect whether the vehicle user is at the driver's door, the trunk, or, for example, at the fuel filler flap during refueling. Accordingly, only the necessary access points can be unlocked, and only those in close proximity to the user. If the vehicle user is, for example, more than 0.5 meters away from the vehicle 300, then the vehicle 300 cannot be opened at any of the access points. Starting the vehicle is also impossible if the authorization device 100 is not detected in the vehicle 300. The respective ranges are, for example, a maximum of 2 meters at 125 kHz and several tens of meters at 433 MHz.
[0075] For example, in the context of a relay attack, an attempt can be made to exploit the respective transmit and receive ranges of system 1 according to Fig. 1. The range can be bridged using range bridging technology. Two transmitter and receiver units could be used for this purpose, replicating an identical interface to that found in the authorization device 100 and the vehicle 300 itself. These two transmitter and receiver units could then be connected to each other using high-speed radio technology. If the first transmitter and receiver unit is positioned near the authorization device 100 and the second transmitter and receiver unit near the vehicle 300, then, with continuous transmission and reception capability, the vehicle 300 and the authorization device 100 could communicate with each other unnoticed, regardless of their physical distance. In particular, the vehicle 300 could, for example, be unlocked, started, and moved in this way.To make such manipulation attempts more difficult, signal propagation times and / or modulation methods can be adjusted, for example. However, with increasing power of manipulation components, System 1 would still remain surmountable.
[0076] In this context, the authorization device 100 of system 1 according to Fig. 1 therefore also includes a second communication interface 105 and a (not shown in detail) tracking unit. The tracking unit is configured to determine the current location SA of the authorization device 100. For this purpose, the tracking unit receives, for example, signals from a tracking system, such as satellites of a GPS system.
[0077] A GPS receiver, for example, is suitable as a tracking device. These GPS receivers are now found in most mobile phones and anti-theft tracking systems. They are extremely small, measuring only a few millimeters. The power consumption of such systems is also now relatively low.
[0078] Furthermore, in this context, System 1 includes a backend 500. Communication between the authorization device 100 and the backend 500 takes place via the second communication interface 105 of the authorization device 100. The authorization device 100 is specifically configured to provide its current location SA to the backend 500. The second communication interface 105, for example, represents an internet connection.
[0079] In an authorization step, depending on whether the authorization device 100 is actually near the vehicle, an authorization value AK for operating the vehicle 300 can be provided to the authorization device 100 via the second communication interface 105. This AK is then, for example, relay-like, provided to the vehicle 300 as an authorization signal AS for operating the vehicle 300 via the first communication interface 103. This advantageously enables convenient and tamper-proof operation of the vehicle 300.
[0080] An important feature of the described system 1 is that the backend 500 does not unlock the vehicle 300 via the internet, but rather the authorization device 100 serves as a transmission interface from backend 500 to vehicle 300 via authorization device 100. System 1 therefore also works with vehicles that do not have their own direct internet access.
[0081] The tracking unit can now detect whether the authorization device 100 is near the vehicle. Advantageously, this works independently of the existing radio and antenna technology and, in particular, independently of the vehicle 300. This would allow all externally vulnerable radio technology aimed at communicating with the vehicle 300 to be switched off as soon as the authorization device 100 is no longer near the vehicle.
[0082] In addition to the tracking unit, the authorization device 100 may optionally include, for example, a motion and / or vibration unit and / or a control unit (also not shown in detail). The control unit may, for example, include a storage unit and / or a battery. A motion and / or vibration unit installed in the authorization device 100 may, in particular, serve to reduce the power consumption of the tracking unit or as an alternative or additional indicator of when a radio technology of the authorization device 100 is switched on or off.
[0083] These components are also available in very small and inexpensive form factors with low power consumption. They are also installed in most mobile phones for sports applications. In particular, these components can improve the security standard of System 1 with regard to short-range radio communication. Additionally, they can increase the flexibility of keyless entry and enable maintenance and / or provide vehicle owners with status information about their vehicle. Such components are now widespread, especially in modern mobile phones.
[0084] In the first embodiment, the vehicle owner's authorization device 100, designed as a mobile phone, is used for the direct authorization of operation of the vehicle 300. For this purpose, the authorization device 100, in particular the control device, is assigned, for example, a data and program memory in which a first program for operating the authorization device 100 is stored, which is described below using the flowchart of the Fig. 2 is explained in more detail. In the first embodiment, the authorization device 100 thus includes, for example, a key function by means of the first program (so-called “app”).
[0085] The first program could be, in particular, a personalized and therefore encrypted vehicle manufacturer program with corresponding access to backend 500. Personalization is achieved, for example, by creating a customer account to which a password or similar security feature is assigned. By capturing the respective security feature, the user of the authorization device 100 or the vehicle owner can be authenticated. A step in capturing such a security feature can also be referred to as capturing an identification key (IK).
[0086] For the vehicle owner, using the personalized authorization device 100 in this way is relatively simple. Using the first program from the vehicle manufacturer and a corresponding activation, i.e., the backend 500 and the vehicle owner program are synchronized via fingerprint sensor, manufacturer password, etc., access to the vehicle 300 can then be granted by comparing the GPS data from the backend 500 with a PIN request or verification via fingerprint sensor. A related security algorithm could be implemented similarly to that used in currently implemented electronic wallets, so-called "mobile payment" systems, where the payment system's security algorithm or matching and security technology is used for mobile phone verification. The first program is started in step S201, in which, for example, variables are initialized.In a first implementation variant, the vehicle and / or mobile phone owner is, for example, in close proximity to vehicle 300 and starts the personalized first program offered and activated by the manufacturer. The authorization device 100 receives the near-field radio signal from vehicle 300. In a second implementation variant, the vehicle and / or mobile phone owner can also start the first program earlier, for example, regardless of their position relative to vehicle 300. The first program is then continued in step S203.
[0087] In step S203, the identification key IK is determined by the authorization device 100. For example, the authorization device 100, prompted by the received near-field communication signal from the vehicle 300, requests identification from the user of the authorization device 100, such as identification via fingerprint sensor or PIN. For this purpose, a fingerprint of the user of the authorization device 100 is captured, or a PIN query is initiated. Access to the backend 500 to activate or deactivate vehicle authorizations is thus similar to so-called "banking apps" with a stored password or fingerprint identification. The first program then continues in step S205.
[0088] In step S205, it is checked whether the determined identification key IK is assigned to a legitimate user of the authorization device 100. For this purpose, the authorization device 100 compares the identification with the matching data activated in the backend 500. If such authentication of the respective legitimate user is successful, the first program continues in step S213 in the first execution variant. In the second execution variant, if authentication is successful, the first program continues in step S207. Otherwise, in both execution variants, the first program continues, for example, in step S203.
[0089] In step S207, it is checked whether a start signal SS is present, which is representative of an operation of the authorization device 100 determining the current location SA and / or an operation of the authorization device 100 communicating with the vehicle 300. The start signal SS is determined, for example, by the authorization device 100 itself, or received via the second communication interface 105. If the start signal SS is present, the first program is then continued in step S213. Otherwise, the first program is then continued in step S209.
[0090] In step S209, it is checked whether the motion and / or vibration sensor has detected movement, and / or whether it is likely that the authorization device 100 is located near a stored locking location SV of the vehicle 300, which is representative of a location of the vehicle 300 where a locking operation was last performed. In this context, for example, a last determined location of the authorization device 100 is consulted. Movement of the authorization device 100 can indicate, in particular, that the user of the authorization device 100 is in motion and may intend to operate the vehicle 300. The probability of this increases further if the user is moving towards the vehicle 300.If movement is detected and / or the authorization device 100 is likely to be near the locking location SV, the first program will then continue in step S211. Otherwise, the first program will then continue in step S207.
[0091] In step S211, a start signal SS is provided by the authorization device 100, which is representative of an operation of the authorization device 100 determining the current location SA and / or an operation of the authorization device 100 communicating with the vehicle 300. For example, the start signal SS is provided to the tracking unit and / or the first communication interface 103, so that these are put into operation or activated. Subsequently, the first program continues in step S213.
[0092] In step S213, the current location SA of the authorization device 100 is determined by the tracking unit. The first program then continues in step S215.
[0093] In step S215, the current location SA is provided to the backend 500 via the second communication interface 105 of the authorization device 100. In the first embodiment, the GPS data is only checked now, for example, when the vehicle owner is standing at the vehicle 300. The current location SA determined by the authorization device 100, or the corresponding GPS data, is compared with the locking location SV or the position data stored in the backend 500. In further embodiments, this could, for example, be handled by the authorization device 100 itself; ideally, however, as in the first embodiment, this is done by the backend 500. This prevents GPS data containing the vehicle 300's position from being transmitted to the authorization device 100, which could then be intercepted.In this case, however, it is necessary to transmit the respective location as locking location SV to backend 500 for each locking operation of vehicle 300. The first program then continues in step S217.
[0094] What is missing for authorizing the operation of the vehicle 300 is an identification number such as that stored in the key of the vehicle 300, which is used, for example, to compare the electronic immobilizer.
[0095] Such an additional identification, i.e., one or more vehicle identifications that have not yet been assigned to a vehicle key, can be stored in the backend 500 for the vehicle 300, in particular externally to the authorization device 100.
[0096] If the authorization device 100 is located near the locking location SV and is operated by an authenticated user, then the backend 500 transmits a signal to the authorization device 100 containing the aforementioned identification which the vehicle 300 requires, or by which it then opens the doors.
[0097] In step S217, it is checked whether – possibly after a specified waiting period – an authorization code AK has been received via the second communication interface 105, which the vehicle 300 requires for operation. If the authorization code AK is present, the first program then continues in step S219. Otherwise, the first program then continues in step S213.
[0098] In step S219, an authorization signal AS is finally provided to the vehicle 300 via the first communication interface 103. The authorization signal AS can, for example, simply be a forwarded authorization code AK. If necessary, the authorization code AK is adapted to the corresponding protocol according to the first communication interface 103. In the first and second implementation variants, intermediate storage of the authorization code AK or the authorization signal AS is avoided. In other implementation variants, however, intermediate storage can occur; however, any temporarily stored data is preferably deleted immediately after the authorization signal AS is sent. The first program then terminates.
[0099] In other words, the aforementioned signal composition is not generated by the authorization device 100, but by the backend 500. The authorization device 100 forwards the information directly to its internal short-range antenna. The identification for the immobilizer is not stored in the authorization device 100, but is only transmitted along in the protocol. Since, in this case, both the authorization device 100 and the vehicle 300 are constantly connected to the backend 500 via the authorization device 100 using encryption, constantly changing protocols can be sent. Even the server time of the backend 500 can be included in the protocol for encryption. This therefore only works with the authorization device 100 that has been unlocked by the manufacturer with respect to an identifier, and the corresponding propagation delays must be adjusted for such a protocol.Furthermore, this only works if the user of the authorization device 100 is near the vehicle and all identifications are correct. Although the authorization device 100 is near the vehicle, it doesn't store the access data itself; everything is handled via the backend 500. This can lead to varying response times. The authorization device 100 only receives the protocols for which it is authorized. If someone tries to open the trunk with the authorization device 100, but it is not authorized for this purpose, the backend 500 can detect this. The backend 500 then simply doesn't send the necessary protocol. In other words, the authorization value AK is then only representative of vehicle access without trunk access.Alternatively, this could, for example, represent exclusive access to the trunk, or vehicle access and authorization to start the engine of vehicle 300.
[0100] Therefore, interception and / or manipulation from outside System 1 is also impossible, since nothing except the identification code IK is stored on the authorization device 100. Everything runs via the personalized, secure first program and the backend 500.
[0101] The described system 1 according to the first embodiment is easy to use with the appropriate security technology without significant additional effort. A mobile phone as an authorization device 100 is seen here as supplementing the authorization of operating the vehicle 300 by means of a conventional key and represents, for example, an additional emergency solution for authorizing the operation of the vehicle 300.
[0102] Advantageously, in the first implementation variant, the current location SA or GPS data is not constantly queried, thus keeping the power consumption of the authorization device 100 low. Therefore, when the first program is not active, it requires no processing power and thus no battery power, and no GPS synchronization takes place. Instead, the first program, the GPS synchronization, and the data transmission only occur at the vehicle 300 upon request. Furthermore, the access data can be forwarded directly to the vehicle 300 and does not need to be stored on the authorization device 100.
[0103] To ensure genuine keyless vehicle access, where the authorization device 100 does not need to be specifically handled or activated, the second design variant will be discussed below.
[0104] As described in the first version, the authorization device 100 contains a personalized initial program that is activated for the vehicle owner. Once this program has been started on the authorization device 100 and activated via password or fingerprint sensor, it runs continuously in the background. This can continue until it is removed from the operating memory or the authorization device 100 is restarted.
[0105] Such an initial program can, of course, also define how it should function. In particular, this type of operation is possible with fewer limitations compared to the first version, albeit with a slightly increased battery drain.
[0106] If the first program is now running in the background, a continuous comparison can be made between the locking location SV stored in the backend 500 and the actual current location SA determined by the authorization device 100. This only occurs, for example, after the function has been reactivated using a password or fingerprint identification, thus preventing illegitimate operation of the vehicle 300 with an authorization device 100 such as an unlocked, stolen mobile phone.
[0107] As demonstrated in steps S207, S209, and S211, an algorithm can be triggered based on a difference, i.e., the distance between the locking location SV and the current location SA, which then controls the next GPS query. The greater the distance, the less frequently a GPS comparison is performed. Most modern mobile phones also have an accelerometer or motion sensor. This could additionally be factored into the calculation. If no movement is registered, the mobile phone has probably not approached the vehicle, and the next GPS query or comparison with the cloud can be postponed accordingly. The closer the authorization device 100 gets to the locking location SV stored in the backend 500, the more frequently comparisons and recalculations occur. Within a predefined distance to the vehicle 300, the first communication interface 103 is then activated.The short-range radio is activated and waits until it receives signals from vehicle 300. Once this occurs, communication between backend 500 and vehicle 300 begins via the authorization device 100, as described above.
[0108] This enables convenient and tamper-proof keyless access to the vehicle 300.
[0109] System 1, in particular backend 500, also has, for example, a data and program memory in which, corresponding to the first program executed by the authorization device 100 according to the first embodiment, a second program for operating system 1 to authorize operation of the vehicle 300 is stored, which is described below using the flowchart of the Fig. 3 will be explained in more detail.
[0110] The second program is started in step S301, in which, for example, variables are initialized. Specifically, the locking location SV, representing the last location where vehicle 300 was locked, is provided to backend 500. The second program then continues in step S303.
[0111] In step S303, the authorization device 100 transmits the identification code IK and the current location SA of the authorization device 100 to backend 500. The second program then continues in step S305.
[0112] In step S305, it is checked whether the determined identification value IK is assigned to a legitimate user of vehicle 300. Optionally, a query can first be made to a legitimate vehicle owner to ascertain whether the corresponding user of the authorization device 100 is permitted to operate vehicle 300, as described in a second embodiment. If such authentication of the respective legitimate user is successful, the second program then continues in step S307. Otherwise, the second program continues, for example, in step S303.
[0113] In step S307, the user of the authorization device 100 is checked to determine if they are near the vehicle 300 by comparing their current location SA with the locking location SV stored in the backend 500. If the current location SA is less than a predefined distance from the locking location SV, the second program continues in step S315 in the first and second implementation variants of the first embodiment. In a third implementation variant, the second program continues first in step S313 instead. Otherwise, if the current location SA is too far from the locking location SV, the second program continues in step S307 after a predefined waiting period in the first and second implementation variants, or, according to the third implementation variant, continues in step S309.
[0114] Similar to steps S207, S209, and S211, step S309 determines a time interval based on the distance between the current location SA and the locking location SV. After this interval, the current location SA of the authorization device 100 is to be queried again, for example, because the authorization device 100 is then highly likely to be near the vehicle. It is particularly important to assume that with a large distance between the authorization device 100 and the vehicle 300, a subsequent location check may occur later than with a correspondingly shorter distance. The second program then continues, specifically after the determined time interval has elapsed, in step S311.
[0115] In step S311, the backend 500 provides the authorization device 100 with a start signal SS, which is representative of an operation of the authorization device 100 that determines the current location SA. The second program then continues in step S307.
[0116] In step S313, the authorization device 100 receives another start signal SS from the backend 500, which is representative of the authorization device 100 operating in communication with the vehicle 300. The second program then continues in step S315.
[0117] In step S315, the authorization value AK is determined based on the identification value IK. The authorization value AK is particularly representative of a specific sub-area or component of the vehicle 300, whose authorization is assigned to the respective identification value IK. The second program then continues in step S317.
[0118] In step S317, the authorization code AK is finally provided to the authorization device 100 via the second communication interface 105. The authorization code AK is therefore only provided to the authorization device 100 when it is near the locking location SV and user authentication of the authorization device 100 has been performed. The second program then terminates.
[0119] With System 1, according to the first version, problems can occur during vehicle operation authorization if the vehicle 300 is parked in a location without telephone, internet, and / or GPS reception. Even if the short-range radio of the authorization device 100 is activated early, a connection can be established between the vehicle 300 and the device itself, but communication with the backend 500 cannot be established. Since, as already described, vehicle access data should not be stored in the authorization device 100 under normal circumstances, vehicle access is then impossible.
[0120] For example, if a locking operation of the vehicle 300 is carried out by the authorization device 100, the corresponding locking location SV is stored in the authorization device 100 or in the backend 500.
[0121] For example, the authorization device 100 records when vehicle 300 was vacated, i.e., a location and / or time at which reception from the short-range antennas of the authorization device 100 is no longer possible. When this occurs, vehicle 300 locks itself automatically. At this point, the authorization device 100 attempts to determine its current location SA and thus the locking position SV of vehicle SV. Alternatively or additionally, this data can then be transferred to the backend 500.
[0122] If neither GPS data can be determined nor the backend 500 is reachable at this time, a time measurement is started, taking into account data from the motion sensor if necessary (second version). The authorization device 100 then stores or transmits to the backend 500, as soon as a GPS signal or access to the backend 500 is available again, not only the GPS data but also an estimated distance traveled during the time measurement period when the authorization device 100 was without reception.
[0123] This additional data is intended to enable the authorization device 100 to activate the short-range radio earlier. In other words, this ensures that the first communication interface 103 is already activated before the user of the authorization device 100 is near the vehicle without GPS reception and access to the backend 500.
[0124] However, in order for the authorization device 100 to be able to open the vehicle 300 even without GPS reception and access to the backend 500, it is necessary that access data such as the authorization key AK is stored in the authorization device 100 at that time.
[0125] In a fourth implementation variant, backend 500 is provided with data regarding the last vehicle locking event, along with the locking location SV. This ensures that backend 500 contains the information that no GPS signal or connection to backend 500 existed during the last vehicle locking event. This information can be determined, for example, by recording the time elapsed since the vehicle locking event and comparing it to the GPS coordinates of backend 500. Only in this specific case are the vehicle access data, such as the authorization code AK, temporarily stored on the authorization device 100 or simply transferred to volatile memory. However, this data is deleted as quickly as possible once it is no longer needed. This could be after a predetermined time or shortly after the authorization device 100 moves away from the vehicle 300.Since the data is not permanently stored on the authorization device 100, protection against manipulation can still be guaranteed, especially because the data is only transmitted shortly before vehicle access and is not permanently stored on the authorization device 100.
[0126] In summary, the first example refers to vehicle access via short-range radio, a feature of many modern mobile phones. The respective mobile phone has an "app" provided by the vehicle manufacturer. This app can be activated by the manufacturer for the specific vehicle; the vehicle owner receives an activation code from the manufacturer for communication with the backend (which can also be referred to as "cloud" access) and possibly an additional encryption code. Therefore, this approach does not require the vehicle to be equipped with internet access. Instead of the vehicle obtaining information via the internet, the mobile phone unlocks the door.
[0127] In this system, the mobile phone acts as a transmitter and receiver for the activated backend. The backend uses the mobile phone's location data, which contains the manufacturer-personalized, activated, and encrypted app, to compare this data with the stored data—GPS data and timestamps from the last vehicle locking—stored in the backend. Only then does it initiate communication with the vehicle via the mobile phone's near-field transmitter. No data even needs to be stored on the mobile phone itself that could potentially be read later. Once all conditions (GPS data matching) for vehicle access are met, the mobile phone simply forwards the communication between the backend and the vehicle.
[0128] The backend can also store permissions for individual key fobs, which would naturally also apply to a mobile phone version. If the vehicle owner has the corresponding access codes or the personalized app, they can temporarily expand or restrict individual permissions. This can be done via the personalized app, as described, or from a regular computer with internet access. The access restrictions apply not only to the individual key fobs but also to the vehicle owner's personalized app and the later-described authorization function for additional mobile phone users.
[0129] This could be used, for example, in the event of a lost key. Almost all functions and permissions can be completely blocked via the backend. Therefore, even after a lost or stolen key, driving with the corresponding key would be impossible. Blocking all keys for starting the vehicle's engine would thus be possible for both the vehicle owner and the vehicle manufacturer upon request.
[0130] In the simplest case, this can be done by using outdated GPS data during a request, or, to completely disable the key fob, by sending a complete shutdown message. The next time the key fob attempts to synchronize with the backend, it will no longer function. However, if the key fob also contains a mechanical key, the stolen key can still be used to open the door, but starting or stealing the vehicle will no longer be possible.
[0131] Not only could a customer block a key, but different permissions could also be assigned to the key, especially a mobile phone key. For example, a specific key could be granted access only to the vehicle interior, which cannot be prevented even with a built-in mechanical emergency key. However, access to the trunk or the start function could be revoked. Alternatively, the key owner could be granted only trunk access.
[0132] Such a scenario is described in a second embodiment in Fig.Figure 4 illustrates how an authorization device 100, also designed as a mobile phone, is used by a third-party user for the indirect authorization of the operation of the vehicle 300. For this purpose, the authorization device 100 is assigned a data and program memory, analogous to the first embodiment, in which a further program for operating the authorization device 100 is stored, which will be explained in more detail below. In the second embodiment, the authorization device 100 thus includes, for example, a key function for third-party users by means of the further program. Furthermore, the second embodiment relates to the individual activation of the authorization to operate the vehicle 300 by the vehicle owner.
[0133] Essentially, the further program according to the second embodiment can be the first program according to the first embodiment.
[0134] However, in this case, individual activation occurs via access to backend 500 by the vehicle owner through a request, for example, also via the vehicle manufacturer's program. In particular, this allows for expansion to additional authorization devices 700, 900, such as those belonging to family members, a parcel service, and similar entities. Approval for these additional authorization devices 700, 900 is granted, for example, with specific permissions or restrictions and / or only for a predetermined period. A prerequisite for system 1 according to the second embodiment may be, for example, that the vehicle owner's authorization device 100 and its encrypted "app" are personalized or activated via the vehicle manufacturer.
[0135] The respective additional authorization device 700, 900, for example, has the same "app" provided by the vehicle manufacturer or a similar "app" specifically designed for this purpose, which can be activated in advance by the vehicle manufacturer. This activation can be done, for example, by the user of the respective additional authorization device 700, 900 authorizing themselves with the appropriate data. This can be done via a phone call, a request for access data, or by sending access data by mail. Currently, many methods are conceivable to ensure that only a specific person works with the provided "app." In particular, it should be ensured that the "app" belongs to a specific authorization device and a specific owner.Access to the "app" can then be granted in the same way as described above, either via an access code or via the fingerprint sensor, i.e., by capturing an identification value (IK). The "app" does not need to be as complex, as it does not have to include the full range of functions of the vehicle owner's "app".
[0136] If the vehicle owner wishes to grant a third party limited access to the vehicle (300), they can assign the corresponding rights to that person. These rights can be granted without restrictions or with limitations, for example, by denying or granting access to the trunk.
[0137] For example, assuming that the corresponding "app" for the third-party user is personalized and activated as described above, this user can send a request to the vehicle owner and their authorization device 100 via an authorization request signal (AAS) to operate the vehicle 300 using the respective additional authorization device 700, 900, for example via the backend 500. In the simplest case, this could be implemented if the owner of the respective additional authorization device 700, 900 sends a request to the vehicle owner and owner of the authorization device 100 via the activated vehicle owner program, for example by entering the telephone number or another identifier of the authorization device 100 in the "app" and activating a request, possibly with accompanying text.This request can now be transmitted in encrypted form via backend 500 to the vehicle owner's authorization device 100. For example, backend 500 provides the vehicle owner with an authorization request message AAN for this purpose.
[0138] It would also be conceivable that an SMS message would be sent simultaneously via the usual text messaging channels, indicating that such a request exists. This request is then displayed in the vehicle owner's "app" and their authorization device 100.
[0139] The request is not transmitted directly from the respective authorization device 700 or 900 to the vehicle owner's authorization device 100, but rather via the backend 500. This means the transmission is fully encrypted, proceeding from authorization device 100 through the vehicle manufacturer's backend 500 to the respective authorization device 700 or 900. Additional information or notification via SMS or a similar messaging service like WhatsApp can occur in parallel, as this serves only to inform the vehicle owner that a request has been made, in case the corresponding app is not open.
[0140] The vehicle owner can now open the "app" on their authorization device 100 after successful authentication via fingerprint identification or password and read the request. For example, the authorization request message includes the identification code IK of the user of the respective additional authorization device 700, 900. If this user of the respective additional authorization device 700, 900 is known to the vehicle owner or the request has been agreed upon, they can release the request with their response AAA, for example, again via fingerprint identification or PIN.
[0141] Before the request is approved, access can also be restricted. Possible restrictions could be, for example, access only to the trunk and only for one day or one hour.
[0142] This AAA response for authorization is then encrypted and sent back to the vehicle manufacturer's backend 500, which forwards the corresponding authorizations. There is no direct connection between the authorization device 100 and the respective further authorization devices 700 and 900. Instead, all data is transmitted via backend 500 and the previously personalized vehicle manufacturer programs. Once the process is complete, the user of the respective further authorization device 700 or 900 can request the desired access directly at the vehicle 300, as described in the first example. This is done by using the "app" and identification in the immediate vicinity to obtain the access defined or activated by the authorization device 100. The backend 500 checks all indicators and then transmits the authorization code AK, which is required to operate the vehicle 300.In other words, restricted vehicle access can be granted while incorporating the same security mechanisms as described above. For example, the vehicle owner's mobile phone app for the authorization device 100 records all requests and approvals, allowing the vehicle owner to quickly revoke or extend previously granted permissions.
[0143] Advantageously, the described system 1, the authorization device 100, and the operating methods enable a high degree of flexibility, security, and availability with regard to keyless operation of the vehicle 300. In particular, it enables keyless convenience access, which also functions, for example, in areas where there may be no telephone reception. Such a system can be manufactured particularly cost-effectively, as the direct costs per vehicle do not increase. Reference symbol list: 1 system 100 authorization device 300 vehicles 500 Backend 700, 900 additional authorization devices AS authorization signal AK authorization indicator SS Start signal SA current location IK identification value SV locking location AAS authorization request signal AAN authorization request message AAA answer S201...S219 Program steps S301...S317 Program steps
Claims
[1] Method for operating an authorization device (100) for a vehicle (300), wherein the authorization device (100) comprises: - a first communication interface (103) which is designed for communication with the vehicle (300), - a second communication interface (105) configured for communication with a backend (500), and - a location unit designed to determine the current location (SA) of the authorization device (100), in which - the current location (SA) of the authorization device (100) is determined and provided to the backend (500) via the second communication interface (105), and - in an authorization step, depending on one of the authorization indicator values (AK) provided by the authorization device (100) via the second communication interface (105) for operating the vehicle (300), an authorization signal (AS) for operating the vehicle (300) is provided via the first communication interface (103). [2] The method of claim 1, wherein - the authorization indicator (AC) is passed through the authorization step from the second communication interface (105) directly as an authorization signal (AS) to the first communication interface (103). [3] Method according to claim 1, wherein the authorization device (100) has a storage unit in which - the authorization key value (AC) is stored in the storage unit for the duration of the authorization step. [4] Method according to any of the foregoing claims, wherein - an identification value (IK) that is representative of a user of the vehicle (300) is determined and provided via the second communication interface (105). [5] Method according to any of the foregoing claims, wherein - a start signal (SS) is provided to the tracking unit and / or the first communication interface (103), and - depending on the start signal (SS), an operation of the tracking unit determining the current location (SA) of the authorization device (100) or an operation of the first communication interface (103) communicating with the vehicle (300) is controlled. [6] Method according to claim 5, wherein the authorization device (100) comprises a vibration and / or motion sensor unit, wherein - a movement of the authorization device (100) is detected by means of the vibration and / or motion sensor unit, and - depending on the detected movement of the authorization device (100), the start signal (SS) of the tracking unit and / or the first communication interface (103) is provided. [7] Method according to one of the preceding claims 5 or 6, wherein - the authorization device (100) is provided with a locking location (SV) of the vehicle which is representative of a location of the vehicle (300) at which a last locking operation of the vehicle (300) was carried out, - depending on the distance between the current location (SA) and the locking location (SV), a time interval is determined, and - depending on the time interval, the start signal (SS) of the tracking unit and / or the first communication interface (103) is provided. [8] Method according to any of the foregoing claims, wherein - in the event that a locking operation of the vehicle (300) is carried out by the authorization device (100), a first determined current location (SA) of the authorization device (100) after the locking operation has been carried out is provided as the locking location (SV) via the second communication interface (105). [9] Method according to any of the foregoing claims, wherein - an authorization request for the authorization of the vehicle (300) by the authorization device (100) is determined, and - depending on the authorization request, an authorization request signal is provided to the backend (500) via the second communication interface (105). [10] Method for operating a system (1) for authorizing the operation of a vehicle (300), wherein the system (1) comprises a backend (500) and at least one authorization device (100) which is operated according to the method according to one of the preceding claims, and in the method - the backend (500) is provided with a locking location (SV) that is representative of a location of the vehicle (300) at which a last locking operation of the vehicle (300) was carried out, - the backend (500) is provided with a current location (SA) of the respective authorization device (100), - depending on the current location (SA) of the respective authorization device (100) and the locking location (SV) of the vehicle (300), an authorization key value (AK) for operating the vehicle (300) is determined, and - the authorization code (AC) for operating the vehicle (300) is provided by the respective authorization device (100). [11] The method of claim 10, wherein - the backend (500) is provided with an identification value (IK) that is representative of a user of the vehicle (300), and - the authorization key value (AK) is determined depending on the identification key value (IK). [12] Method according to one of the preceding claims 10 or 11, wherein the authorization identifier (AC) is representative of an authorization to operate at least one of the following components of the vehicle (300): - one or more doors, - trunk, - Fuel cap, - Ignition, - Engine. [13] Method according to any one of claims 10 to 12 above, wherein - depending on the distance between the current location (SA) of the respective authorization device (100) and the locking location (SV) of the vehicle (300), a time interval is determined, and - depending on the time interval of the respective authorization device (100), a start signal (SS) is provided which is representative of an operation of the respective authorization device (100) that determines the current location (SA) of the respective authorization device (100) and / or communicates with the vehicle (300). [14] Method according to any one of claims 10 to 13 above, wherein - an authorization request signal (AAS) for operation of the vehicle (300) is provided by the authorization device (100), - depending on the authorization request signal (AAS) of a predefined communication interface assigned to a vehicle owner (300), an authorization request message (AAN) is provided, and - depending on a response (AAA) to the authorization request message (AAN), the authorization identifier (AK) of the authorization device (100) is provided. [15] System (1) for authorising the operation of a vehicle (300), comprising - a backend (500), and - at least one authorization device (100) wherein the system (1) is configured to perform a method according to any one of the preceding claims 10 to 14.
Citation Information
Patent Citations
Method for operating motor car, involves transferring key code of transponder key to electronic immobilizer if release mechanism of transponder key is activated by key activation device, and deactivating immobilizer by key code
DE102012111361A1
Hand unit to help in finding an object, especially a parked car, comprises a storage unit for storing of direction and distance data as a person moves away from the object, so that the data can be replayed later as necessary
DE10235132A1
Power consumption suppression system for electronic key terminal and power consumption suppression method for electronic key terminal
DE112013006560T5