A method for access control on motor vehicles

A two-stage authentication process for motor vehicles ensures secure vehicle access and use by separating initial access from engine start authorization, preventing unauthorized operation.

DE102016103128B4Active Publication Date: 2026-05-21HUF HÜLSBECK & FÜRST GMBH & CO KG
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
HUF HÜLSBECK & FÜRST GMBH & CO KG
Filing Date
2016-02-23
Publication Date
2026-05-21

AI Technical Summary

Technical Problem

Existing access control methods for motor vehicles do not adequately monitor the use of vehicles after initial access, allowing unauthorized individuals to potentially operate the vehicle.

Method used

A two-stage authentication process is implemented, where initial access to the vehicle is granted via a mobile communication device, but engine start requires a second set of authorization information verified through a central database server, ensuring that vehicle use is controlled and secured.

Benefits of technology

The method enhances security by requiring separate authorization for vehicle access and engine start, preventing unauthorized operation and ensuring only authorized users can initiate vehicle use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for monitoring the use of a motor vehicle (3), comprising the steps, - Establishing an initial communication link (5) between a mobile communication device (1) and a remote database server (2), - Transmission of initial authentication information (5) of a user and initial vehicle identification data for a motor vehicle from the mobile communication device (1) to the database server (2), - Checking the initial authentication information and initial vehicle identification data in the database server (2), whereby, depending on the check, the database server sends initial authorization information (6) to the mobile communication device (1) to open the motor vehicle belonging to the initial vehicle identification data, - Pairing the mobile communication device (1) with a control unit in the motor vehicle (3) assigned to the first vehicle identification data and transferring the first authorization information (7) from the mobile communication device (1) to the control unit, - Checking the initial authorization information in the control unit and releasing the vehicle from opening (3) depending on the check, characterized by the steps, - Establishing a second communication link between the mobile communication device and the remote database server, - Transmission of second authentication information (10) of the user and second vehicle identification data for the motor vehicle from the mobile communication device (1) to the database server (2), wherein the second vehicle identification data contains start information which is readable and displayed inside the vehicle, - Checking the second authentication information and second vehicle identification data in the database server (3), wherein, depending on the check, the database server sends second authorization information (11) to the mobile communication device to start the motor vehicle belonging to the second vehicle identification data, - Pairing the mobile communication device (1) with the control unit in the motor vehicle (3) assigned to the first vehicle identification data and transferring the second authorization information from the mobile communication device to the control unit, - Checking the second authorization information in the control unit and releasing a start of the motor vehicle depending on the check.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for access control and usage control of motor vehicles. In particular, the invention relates to a method for controlling shared user access and the use of motor vehicles by different users.

[0002] In engineering, various methods are known for implementing so-called car-sharing concepts, which allow for the shared use of vehicles. The vehicle is used as a resource by different users at different times, thus improving its utilization.

[0003] This requires that the user of a car-sharing service register with a provider who stores the user's data and authorization in a central database server. The provider manages the vehicles and the central database server. After registration, the user can access the provider's vehicle inventory. To do this, the user can connect to the database server using a mobile communication device, such as a smartphone, via a public communication network (e.g., the internet).

[0004] When a user wishes to temporarily rent a specific vehicle, the database server, upon request, grants the previously registered user the necessary rights via their mobile device and downloads these authorizations to the user's mobile device. A provider-specific application (app) may be installed on the mobile device to facilitate communication between the mobile device and the database server, as well as to manage user rights.

[0005] An example of such a procedure is disclosed in DE 10 2012 013 450 A1.

[0006] German patent DE 10 2014 224 769 A1 describes a system for delivering virtual keys for vehicles. A cloud server generates temporary access codes and start codes, which are transmitted to both the user's mobile phone and the vehicle. The user enters the access code on a vehicle keypad to unlock the vehicle and then enters a start code to start the vehicle. In scenarios without a network connection, pre-calculated rolling codes or pre-transmitted PINs can be used.

[0007] German patent DE 10 2012 022 786 A1 discloses a method for access authorization on a vehicle, in which the vehicle sends a random number to a mobile device. This random number is used in a challenge-response procedure for local authentication between the vehicle and the mobile device.

[0008] US Patent 2006 / 0041513 A1 describes a vehicle authentication device in which a vehicle-mounted communication unit communicates with an electronic driver's license card. The driver's license card stores driver's license information, including driver identification, as well as activation information for vehicle functions.

[0009] Document US 2005 / 0193212 A1 discloses an authentication system that captures driver's license information from a storage medium carried by the driver, as well as the driver's biometric information. The system stores pre-registered driver's license and biometric data and authenticates the driver by comparing it with this stored data.

[0010] The known methods differ in their technical implementation, but they all have in common that users are registered centrally and communication with this central location takes place when renting and returning a vehicle. Whether this communication occurs via the vehicle, which effectively extends the connection from the mobile communication device to the database server, or whether a connection to the database server is established via the user's mobile communication device itself, or whether both sides establish independent connections to the database server, varies.

[0011] Once the communication connection is established, the mobile communication device sends user authentication information and vehicle identification for a selected vehicle to the database server. For this purpose, the user can, for example, select a specific vehicle in an application, which is then displayed as available for rent. Furthermore, the authentication information is either stored on the mobile communication device or entered by the user, for example, by entering a username or other identifying information.

[0012] The authentication information and vehicle identification data transmitted from the mobile communication device to the database server via the communication link are checked on the database server. If this data is found to be valid, authorization information to open the vehicle associated with the vehicle identification data is sent to the mobile communication device.

[0013] The user can now pair the mobile communication device with a vehicle control unit, for example, via a short-range wireless connection such as NFC or Bluetooth. The authorization information received from the database server is transmitted from the mobile communication device to a control unit in the vehicle. The control unit verifies this authorization information and, depending on the verification, unlocks the vehicle.

[0014] According to current technology, the vehicle typically contains a key that can be used to start the engine. Alternatively, the vehicle is prepared for immediate driving via an engine start button.

[0015] The conventional technology has the problem that only access to the vehicle is controlled; the provider does not control its subsequent use until the engine is started. For example, someone other than the person who unlocked the vehicle could get in the driver's seat and drive off.

[0016] The object of the invention is to provide a particularly safe method for monitoring the use of motor vehicles.

[0017] This problem is solved by a method having the features of claim 1.

[0018] The invention provides that the first communication connection and negotiation of the authorization information with the database server in the manner described above initially only allows access to the vehicle, but does not include the authorization to start the engine and begin driving.

[0019] According to the invention, a communication connection is first established between a mobile communication device and a remote database server. This process can occur, for example, during an initial, one-time registration. However, it can also be performed repeatedly, for example, when accessing a specific vehicle.

[0020] The established connection transmits initial user authentication information from the mobile communication device to the database server. This initial authentication information is checked on the database server, and depending on the check, the database server sends initial authorization information for opening a vehicle back to the mobile communication device.

[0021] The check may, for example, include a comparison with a user database or the verification of entered personal data.

[0022] The user then pairs the mobile communication device with a control unit in the vehicle. This pairing is done wirelessly, for example via a Bluetooth or NFC connection.

[0023] The initial authorization information is sent from the mobile communication device to the control unit and checked there. This check can, for example, verify a certificate that was encoded in the data from the central database server.

[0024] The vehicle will be unlocked depending on the inspection, i.e., upon successful confirmation of access rights.

[0025] A key aspect of the invention is that this dialogue between the mobile communication device and the control unit in the vehicle only allows the vehicle to be opened and accessed, but not to be started.

[0026] To start the vehicle, the mobile communication device is re-paired or re-paired with the vehicle's control unit, and a second set of authorization information is transmitted from the mobile communication device to the control unit. This second set of authorization information may have been transmitted separately from the central database server to the mobile communication device, or it may have been generated within the mobile communication device itself. In any case, user input is required to initiate the second transmission and thus request access to start the vehicle. The second set of authorization information is checked in the control unit, and the vehicle start is authorized based on the validity of this check.

[0027] According to the invention, separate requirements are provided for accessing and starting the vehicle. This allows, for example, tiered access authorization to be implemented in the mobile communication device. While any user has access to the authorization information that permits access to the vehicle, access to the secondary authorization information can be blocked. Access to this secondary authorization information can then only be granted, for example, via a separate password or biometric data. This increases security when using the vehicles.

[0028] According to the invention, the second vehicle identification data contains start information which can be read and displayed inside the vehicle.

[0029] According to the invention, information is stored in the vehicle that can only be read from inside the vehicle. This can be visual information recognizable by the user, which the user then enters into a mobile communication device. However, it can also be information that the mobile communication device can read from a designated reading point inside the vehicle via a very short-range radio connection, in particular an NFC connection. This ensures that the second vehicle identification data and the start authorization request actually originate from inside the vehicle. It can also be provided that an identifier is displayed on an existing display or a separately installed display in the vehicle, which must be entered when requesting start authorization.

[0030] In a preferred embodiment of the invention, a second communication link between the mobile communication device and the remote database server is established once access to the vehicle has been achieved, i.e., once the user is inside the vehicle. The mobile communication device then sends the user's second authentication information and second vehicle identification data to the database server. This second authentication information and the second vehicle identification data are checked by the database server. If the check is successful, authorization information is transmitted from the database server to the mobile communication device, which, as second authorization information, permits the vehicle to be started. This authorization information is again tailored to the specific motor vehicle to which the vehicle identification data belongs.

[0031] The mobile communication device is then paired again with the control unit in the vehicle (or such a pairing already exists via vehicle access), and the second set of authorization information is transmitted to the control unit. This second set of authorization information is checked in the control unit, and the vehicle is allowed to start depending on the results of this check.

[0032] According to the invention, a two-stage process is used which, after access to the vehicle, requires a second verification via the mobile communication device before the central database server. This additional authentication allows the vehicle to be opened, for example, for loading, and even left unattended temporarily while open. Only when the same user requests the second authentication, for example, while seated in the driver's seat, is the vehicle allowed to start. An unauthorized user who happens to be present in the meantime cannot move the opened vehicle.

[0033] In a preferred embodiment of the invention, biometric data of the user is captured using the mobile communication device and transmitted to the central database server during the transmission of the second authentication information. For example, a voice sample or facial image can be recorded with the mobile communication device and transmitted to the database server for biometric comparison. Alternatively, an evaluation for biometric characteristics can take place within the mobile communication device itself, and only the extracted characteristics are transmitted to the database server.

[0034] This embodiment allows, for example, a use where an authorized user hands over the mobile communication device to another person, such as a minor family member, to open a vehicle and enter or load it. However, starting the vehicle is only possible with biometric information, i.e., by the actually authorized person. The person who can open the vehicle cannot then initiate a starting process, as the biometric data verification fails.

[0035] In a further development of the invention, the start information, which becomes part of the second vehicle identification data, is captured with the communication device.

[0036] As mentioned above, this detection can be achieved via a wireless connection or optical recognition using a camera on the communication device. A tone sequence detected inside the vehicle via the mobile communication device can also be used as start information.

[0037] In a preferred embodiment of the aforementioned configurations, a character string or optical code is displayed on the vehicle's interior display. The code displayed on the screen can be captured by a mobile communication device; this code can be, for example, a barcode or a two-dimensional barcode in the style of a QR code. This information also ensures that the start authorization request originates from inside the vehicle, as the information can only be read from this position.

[0038] In a modification of the invention, a permanent display can be arranged in the vehicle, in particular a printed display or an e-ink display. This display presents information that can be entered by the user into the mobile communication device or read directly by the mobile communication device. For example, a QR code can be arranged in the vehicle on a sticker.

[0039] This design is particularly cost-effective and yet ensures that a request for takeoff clearance can only be made from inside the vehicle.

[0040] In a further development of the invention, the start information will have a temporarily valid transaction code, which is generated by an asymmetric calculation method and allows the transaction code to be checked as being appropriate to the vehicle and time.

[0041] The use of asymmetric encoding and signing methods is known in the art. It is also known to generate devices or algorithms for creating so-called transaction authentication numbers (TANs) that can be verified as valid by a central authority. For example, TAN generators are used in online banking, which calculate a valid transaction authentication number for a specific registered device according to predefined rules, optionally taking the current time into account. Such TAN keys also exist for online payment services, and the calculation methods are known in the art. According to the embodiment of the invention, an identifier can be stored for each vehicle, and a corresponding calculation rule for transaction authentication numbers will be stored in the vehicle system.Such identifiers are only valid temporarily, for example, for five minutes at a time, and can be validated centrally in the database server according to the principles of asynchronous signing methods. The database server knows the vehicle and its identifier and can verify whether it is an authentic transaction identifier for the vehicle. In this way, the respective code of the start information changes at short intervals, and it can always be ensured that, for example, a user requests a start authorization with changed access information each time they use a vehicle repeatedly or continuously. This further increases the security of the process.

[0042] As described above, the connection between the mobile communication device and the vehicle system can be established in various ways. Wireless communication connections are typically used, especially Bluetooth connections (particularly Low Energy Bluetooth). For connections with a particularly short range, such as those inside the vehicle, connections with extremely short ranges, such as NFC connections, can also be used.

[0043] The invention will now be explained in more detail with reference to the accompanying drawing.

[0044] Fig. Figure 1 shows the diagram of a communication process according to the invention.

[0045] In Fig. Figure 1 shows, in the form of a diagram, the basic communication sequence for vehicle access and vehicle start according to one embodiment of the invention.

[0046] In the diagram, the processes proceed chronologically from top to bottom, using a smartphone 1 as the mobile communication device. A central database server 2 is located at a remote location, with both the smartphone and the server having access to a common public communication network, in particular the internet. A vehicle 3 is located near the user with the smartphone 1.

[0047] When the user approaches vehicle 3 with their smartphone 1, they will send a request to server 2 if they wish to use the vehicle. This request from smartphone 1 to server 2 is represented by arrow 5. Message 5 transmits the user's identification data and the vehicle's identification data to server 2 from the smartphone. An application is installed on smartphone 1 containing user data and a unique identifier. Using the same application, smartphone 1 can read a barcode behind the windshield of vehicle 3, which uniquely identifies vehicle 3 to server 2. Based on this information in message 5, server 2 can recognize the user as a legitimate user and identify vehicle 3 as belonging to the managed vehicle pool.

[0048] After successfully verifying the user and vehicle data, Server 2 will send a message 6 back to the smartphone. This message 6 contains authorization information for opening the vehicle 3. Upon receiving the authorization information, the smartphone 1 signals to the user that the server has successfully authorized access, and the smartphone 1 will pair with the vehicle 3 via a Bluetooth or NFC connection, transmitting the authorization information to the vehicle 3 via a message 7.

[0049] The vehicle verifies this authorization information and unlocks the exterior doors. The user now has access to the vehicle's interior, but cannot yet start the engine.

[0050] If the user wishes to start the vehicle, in this embodiment they take a seat in the vehicle 3 with their smartphone 1 and read an identifier that can be read from inside the vehicle 3 and is uniquely assigned to the vehicle 3. In this embodiment, the vehicle 3 therefore has an identifier that can be read from the outside (for example, a barcode behind the windshield), as well as an identifier inside the vehicle that can only be read from inside after accessing the vehicle. In this embodiment, when the engine start button is pressed, a two-dimensional graphic code (QR code) is displayed on a screen in the vehicle, which can be read via the smartphone app. Thus, in step 8, the smartphone 1 is paired with readable information from the vehicle 3.In a variation of the example, the data can also be read via an NFC connection between the smartphone and the vehicle's center console, obtaining a second vehicle identification identifier. In either case, at arrow 9, an identifier is read from vehicle 3 into smartphone 1.

[0051] Smartphone 1 now uses this second vehicle identification, transmitted from vehicle 3 and received from inside the vehicle, and sends it to server 2. There, the identifier is verified, as the server, knowing the formula for calculating the identifier, can trace and verify its authenticity to this vehicle. The verification principle of an asymmetric signature can be used for this purpose.

[0052] Server 2 transmits second authorization information for starting the vehicle via message 11. This information is temporarily stored on the smartphone and then transmitted to the vehicle via message 12. This occurs via the existing pairing between the smartphone and the vehicle, such as the Bluetooth connection. Alternatively, this can also be achieved through a forced pairing within the vehicle via a field communication method (especially NFC) to verify the smartphone's presence inside the vehicle.

[0053] If the authorization data for starting the vehicle is successfully verified in the vehicle, the user has permission to start.

[0054] This ensures that, within the scope of the exemplary embodiment, a vehicle start is only possible if a user has both legitimately gained access to the vehicle and requested the start of the vehicle from inside the vehicle.

Claims

[1] Method for monitoring the use of a motor vehicle (3), comprising the steps, - Establishing an initial communication link (5) between a mobile communication device (1) and a remote database server (2), - Transmission of initial authentication information (5) of a user and initial vehicle identification data for a motor vehicle from the mobile communication device (1) to the database server (2), - Checking the initial authentication information and initial vehicle identification data in the database server (2), whereby, depending on the check, the database server sends initial authorization information (6) to the mobile communication device (1) to open the motor vehicle belonging to the initial vehicle identification data, - Pairing the mobile communication device (1) with a control unit in the motor vehicle (3) assigned to the first vehicle identification data and transferring the first authorization information (7) from the mobile communication device (1) to the control unit, - Checking the initial authorization information in the control unit and releasing the vehicle from being opened (3) depending on the check, characterized by the steps, - Establishing a second communication link between the mobile communication device and the remote database server, - Transmission of second authentication information (10) of the user and second vehicle identification data for the motor vehicle from the mobile communication device (1) to the database server (2), wherein the second vehicle identification data contains start information which is readable and displayed inside the vehicle, - Checking the second authentication information and second vehicle identification data in the database server (3), wherein, depending on the check, the database server sends second authorization information (11) to the mobile communication device to start the motor vehicle belonging to the second vehicle identification data, - Pairing the mobile communication device (1) with the control unit in the motor vehicle (3) assigned to the first vehicle identification data and transferring the second authorization information from the mobile communication device to the control unit, - Checking the second authorization information in the control unit and releasing a start of the motor vehicle depending on the check. [2] Method according to claim 1, wherein the mobile communication device captures biometric data of a user and the second authentication information includes biometric data of the user. [3] Method according to claim 1, wherein the start information is captured in the vehicle by the communication device. [4] Method according to claim 3, wherein the start information is displayed on a display in the vehicle as a string of characters or as a one- or two-dimensional optical code. [5] Method according to claim 3, wherein the start information is displayed on a permanent display in the vehicle, in particular on a printed display or an e-ink display. [6] Method according to one of claims 3 to 4, wherein the start information includes a temporarily valid transaction code which is checked as being suitable for the vehicle and time by an asymmetric calculation method in the database server. [7] Method according to one of the preceding claims, wherein the coupling of the mobile communication device with the control unit is carried out via a wireless coupling, in particular via Bluetooth coupling or NFC coupling.