Procedure and system for authorizing the execution of an action in a service system

Biometric authentication across the communication chain in vehicles and mobile devices addresses the limitations of traditional methods, providing secure and continuous user control resistant to quantum threats.

DE102019117108B4Active Publication Date: 2025-12-04BAYERISCHE MOTOREN WERKE AG
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
DE102019117108
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2019-06-25
Publication Date
2025-12-04
Estimated Expiration
2039-06-25

AI Technical Summary

Technical Problem

Traditional authentication methods, such as passwords and PINs, are inadequate for modern vehicles due to the need to remember multiple credentials and pose security risks, especially with the increasing availability of cloud-based services, and conventional cryptographic systems are vulnerable to quantum computing.

Method used

Implement biometric authentication along the entire communication chain, using sensors like fingerprint, finger veins, face, heartbeat, and anatomy sensors, integrated into vehicles and mobile devices, for continuous and passive user verification, with two-factor authentication by external entities.

Benefits of technology

Enhances security by preventing unauthorized access to service systems like smart homes and vehicles, ensuring secure and continuous user control through biometric verification resistant to quantum decryption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method (200) for authorizing the execution of an action in a service system (1), comprising: Capture (210) at least one biometric characteristic of a user; Sending (220), by a vehicle (100), an authorization request with the captured at least one biometric characteristic to a first external unit (10), in particular a backend; Generating (230) a biometric token by the first external entity (10); Sending (240) a request with the generated biometric token to a service system (1), wherein the request concerns the execution of an action in the service system (1), and wherein the service system (1) is an external service system (1) outside the vehicle (100), and wherein the service system (1) is a smart home or an IoT system; and Performing (250) the action by the service system (1) based on the received request, where at least one biometric characteristic of the user is continuously recorded for multiple authentications.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present disclosure relates to a method and system for authorizing the execution of an action in a service system. In particular, the present disclosure relates to the biometric authentication of a user for controlling a service system, such as an IoT system, especially while the user is in a vehicle. State of the art

[0002] The connectivity of modern vehicles, for example to the internet, is becoming increasingly important. Cloud-based services can be made available to users in their vehicles. To use these and other services, user authentication is often required. With the increasing number of available services, traditional authentication methods such as passwords and PINs are reaching their limits. In particular, users have to remember a large number of individual login credentials to access a corresponding number of services. Furthermore, at least some of the traditional authentication methods pose a risk of misuse. For example, passwords can be stolen and used by unauthorized individuals.

[0003] DE 10 2016 123 857 A1 relates to a system for authenticating a vehicle user, comprising: a vehicle; an in-vehicle biometric system; and a vehicle-integrated communication platform programmed to: detect a sequence of events, including the shifting of the vehicle's transmission from the driving position to the park position, the starting of the vehicle's engine, and the downshifting of the vehicle's transmission from the park position to the driving position; in response to the sequence of events, monitor a distance traveled by the vehicle or monitor the time elapsed since the occurrence of the sequence of events;and instructing the vehicle's in-vehicle biometric system to switch to an authentication mode after a specified time has elapsed since the occurrence of the sequence of events, or after the vehicle has traveled a specified distance since the occurrence of the sequence of events; wherein the vehicle's in-vehicle biometric system responds to instructions from the vehicle's communication platform by initiating an authentication routine.

[0004] The DE 10 2018 120 679 A1 concerns a vehicle comprising a biometric scanner to generate a biometric token; a body control module for the following: activating an ignition switch when the biometric token has been authorized; and, if the biometric token has not been authorized and an additional authorization source has been received: tracking vehicle usage after receiving the biometric token; and marking the biometric token as authorized when usage meets a threshold. Disclosure of the invention

[0005] The purpose of this disclosure is to specify a method and system for authorizing the execution of an action in a service system, enabling secure control of the service system by a user. In particular, the purpose of this disclosure is to prevent unauthorized access to a service system, such as a smart home.

[0006] This problem is solved by the subject matter of the independent claims. Advantageous embodiments are specified in the dependent claims.

[0007] According to an independent aspect of the present disclosure, a method for authorizing the execution of an action in a service system is specified. The method preferably comprises capturing at least one biometric characteristic of a user; sending an authorization request with the captured at least one biometric characteristic to a first external entity; generating a biometric token, for example, by the first external entity; sending a request with the generated biometric token by the first external entity to a service system, wherein the request relates to the execution of an action in the service system; and executing the action by the service system based on the request received, for example, from the first external entity.

[0008] According to the invention, biometric authentication takes place along the entire communication chain, which includes at least the service system and the first external unit (e.g., a central unit such as a backend). Using biometric authentication along the entire communication chain improves security. In particular, unauthorized access to a service system, such as a smart home or a vehicle, can be prevented. This is especially advantageous because conventional cryptographic systems, which use, for example, a public key and tokens, can be decrypted using quantum computing.

[0009] Preferably, the first external unit is a central unit, such as a backend. However, the present disclosure is not limited to this, and the first external unit can be implemented decentrally.

[0010] Preferably, at least one biometric characteristic is selected from, or consists of, a fingerprint, finger veins, face, eye, heartbeat, foot, and anatomy (or combinations thereof). The at least one biometric characteristic is suitable for uniquely identifying the user. This improves the security of user authentication for controlling the service system and prevents misuse.

[0011] Preferably, the at least one biometric characteristic can be acquired by means of at least one biometric sensor. The at least one biometric sensor can be selected from, or consist of, a fingerprint sensor, a finger vein sensor, a face sensor, an eye sensor, a heart rate sensor, a foot sensor, and an anatomy sensor (or combinations thereof).

[0012] The anatomy sensor can be configured to detect at least one anatomical characteristic of the user. This at least one anatomical characteristic can be, for example, a body shape or part of a body shape, such as the shape of the user's back and / or buttocks. Additionally or alternatively, the at least one anatomical characteristic can include dimensions of the body shape or part of the body shape, such as back length and / or back width. The anatomy sensor, or an arrangement of several anatomy sensors, can be provided in at least one vehicle seat, and in particular the driver's seat.

[0013] Preferably, the at least one biometric sensor comprises a sensor for passive recognition of the biometric characteristic. Passive recognition (also referred to as "seamless authentication", "direct authentication", or "immediate authentication") requires no (additional) active action by the user.

[0014] Passive recognition typically occurs via sensors such as heart rate, foot, and / or anatomy. For example, the user is seated in the driver's seat, and no active action, such as placing a finger on a fingerprint sensor, is required to capture their biometric characteristics. Instead, recognition occurs passively, without any input or additional action from the user. This enables continuous user authentication.

[0015] Preferably, at least one biometric sensor is integrated into a user's mobile device, enabling the capture of at least one biometric characteristic. The term "mobile device" includes, in particular, smartphones, but also other mobile phones, personal digital assistants (PDAs), tablet PCs, notebooks, smartwatches, and all current and future electronic devices that are equipped, for example, with technology for capturing biometric characteristics. The mobile device may, for example, include a fingerprint sensor and / or a camera that can be used to capture at least one biometric characteristic of the user.

[0016] Preferably, at least one biometric sensor is integrated into a vehicle so that at least one biometric characteristic can be detected by the vehicle. The heartbeat sensor, for example, can be integrated into a seat belt. The foot sensor can be located in the footwell of the vehicle, and in particular in the floor of the vehicle. The term "vehicle" includes cars, trucks, buses, motorhomes, motorcycles, etc., used for the transport of persons, goods, etc. In particular, the term includes motor vehicles for the transport of persons.

[0017] In some embodiments, all sensors used to capture the at least one biometric characteristic can be integrated into the mobile device or the vehicle. In other embodiments, the sensors used to capture the at least one biometric characteristic can be distributed between the mobile device and the vehicle.

[0018] In other words, to capture at least one biometric characteristic, at least one biometric sensor can be integrated into the mobile device and at least one biometric sensor can be integrated into the vehicle.

[0019] Preferably, the method further comprises a verification of user authorization by the first external entity based on the received at least one biometric characteristic, wherein the biometric token is generated only if the verification results in positive authorization for the user. For example, the first external entity may contain a user profile of the user, which includes the at least one biometric characteristic. By comparing the received at least one biometric characteristic with the stored at least one biometric characteristic, it can be determined whether the user has the necessary access rights for the service system. The access rights can be stored in the user profile and define the scope of possible access to the service system by this specific user.

[0020] Preferably, the service system includes a second external entity, wherein the second external entity receives the request with the generated biometric token, for example, from the first external entity, and wherein the procedure further includes verification of user authorization by the second external entity. The second external entity can be a central entity, such as a backend. This two-factor authentication enhances security.

[0021] Preferably, the method further comprises sending a request to the user by the second external entity regarding further authorization of the user by means of at least one additional biometric characteristic. The at least one additional biometric characteristic may be selected from, or consist of, the group comprising a fingerprint, a finger vein, a face, an eye, a heartbeat, a foot, and an anatomy (or combinations thereof).

[0022] In some embodiments, at least one biometric characteristic, such as a fingerprint, can be used for authentication in both the first and second external units. For example, the at least one biometric characteristic can be captured and then used for authentication in both the first and second external units. In another example, the at least one biometric characteristic can be captured once and used for authentication in the first external unit, and then captured a second time and used for authentication in the second external unit.

[0023] In further embodiments, different biometric characteristics can be used for authentication in the first external unit and for authentication in the second external unit. For example, a first biometric characteristic (e.g., a fingerprint) can be captured and used for authentication in the first external unit. A second biometric characteristic (e.g., a heartbeat) can then be captured and used for authentication in the second external unit.

[0024] Preferably, two or more biometric sensors are provided to capture the first biometric characteristic and the second biometric characteristic. A first biometric sensor among the two or more sensors can be configured to capture the first biometric characteristic, such as a fingerprint. A second biometric sensor among the two or more sensors can be configured to capture the second biometric characteristic, such as a heartbeat. The first and second biometric characteristics are distinct biometric characteristics.

[0025] The two or more biometric sensors can be integrated into a single unit (e.g., the mobile device or the vehicle) or contained in separate subunits. For example, at least one of the two or more biometric sensors can be integrated into the vehicle. At least one of the two or more biometric sensors can be provided independently of the vehicle, such as in the mobile device.

[0026] Preferably, the authorization request, including the captured at least one biometric characteristic, is sent to the first external unit by the vehicle, in particular a motor vehicle. For example, the vehicle may include a communication module configured to communicate with the first external unit and / or the second external unit and / or the mobile device. The communication module may, in particular, be configured to transmit data comprising the captured at least one biometric characteristic and the authorization request to the first external unit.

[0027] In some configurations, the vehicle's communication module can be set up to communicate wirelessly with the backend via a mobile network, for example, via local area networks (LANs) such as wireless LAN (WiFi / WLAN), or via wide area networks (WANs) such as the Global System for Mobile Communications (GSM), General Package Radio Service (GPRS), Enhanced Data Rates for Global Evolution (EDGE), Universal Mobile Telecommunications System (UMTS), High Speed ​​Downlink / Uplink Packet Access (HSDPA, HSUPA), Long-Term Evolution (LTE), or World Wide Interoperability for Microwave Access (WiMAX). Communication via other current or future communication technologies, such as 5G mobile communication systems, is also possible.

[0028] In some embodiments, the mobile device is connected to the vehicle via a first communication link, such as Bluetooth, and communicates with the vehicle via this first link, for example, to transmit data containing the captured at least one biometric characteristic. The vehicle can be connected to the first and / or second external unit via a second communication link, such as one of the aforementioned networks like LTE or 5G, and communicate with the first and / or second external unit via this second link. In some embodiments, the mobile device cannot communicate directly with the first and / or second external unit.Instead, data provided by the mobile device, such as data regarding the biometric characteristics captured by the mobile device, can be transmitted to the vehicle and subsequently sent by the vehicle to the first external unit and / or second external unit for authentication.

[0029] Preferably, at least one biometric characteristic of the user, such as the first and / or second biometric characteristic, is continuously recorded. In other words, instead of a one-time recording and authentication, multiple recordings and authentications are performed. This prevents, for example, unauthorized access to the service system by another user. Furthermore, continuous authentication is advantageous because it prevents misuse. Continuous or multiple recordings and authentication can be performed, for example, using one or more biometric sensors configured for passive biometric characteristic detection. These could include, in particular, a heart rate sensor, a foot sensor, and / or an anatomy sensor.

[0030] Preferably, the method further comprises defining a location for sending the authorization request with the captured at least one biometric characteristic to the first external unit, wherein the request is sent when the vehicle reaches the location. This allows the user to define a location at which the service system, such as a smart home system, should be activated. For example, the user can define a location along their route home from work where an oven, heater, air conditioner, etc., should be switched on. Thus, user-specific control of the service system is possible and, in particular, can occur automatically upon reaching the defined location.

[0031] Preferably, the service system is a smart home, a vehicle, and / or an IoT system. The service system can include one or more service devices that can be controlled by the user via biometric authentication. Smart home service devices can include, for example, a kitchen appliance (e.g., an oven, dishwasher, etc.), a washing machine, a dryer, an infotainment device (e.g., a television), an air conditioner, a heater, and the like. Vehicle service devices can include, for example, vehicle door locking, engine start authorization, navigation functions, climate control, seat settings, driving mode settings (e.g., Sport or Eco), and similar functions.

[0032] The term “IoT” (Internet of Things) refers to technologies of an IT infrastructure for implementing functions that allow interaction between people and any electronic systems networked through it, as well as between the systems themselves.

[0033] According to another independent aspect, a software (SW) program is described. The SW program can be configured to run on one or more processors and thereby execute the procedure described in this document.

[0034] According to a further independent aspect of the present disclosure, a system for authorizing the execution of an action in a service system is specified. The system preferably comprises a biometric acquisition module configured to acquire at least one biometric characteristic of a user; a communication module configured to send an authorization request with the acquired at least one biometric characteristic to a first external entity, in particular a backend; and the first external entity configured to generate a biometric token, wherein the system is further configured to send a request with the generated biometric token to a service system, the request relating to the execution of an action in the service system.

[0035] In some embodiments, the system (or the system's functionalities) is implemented partly in a vehicle and / or partly in an external unit and / or partly in a mobile device. For example, the biometric capture module can be integrated into the user's mobile device and / or the vehicle. The communication module can be integrated into the user's mobile device and / or the vehicle. The external unit can be, for example, a central unit such as a backend.

[0036] The system can implement aspects of the procedure described in this document for authorizing the execution of an action in a service system. Brief description of the drawings

[0037] Examples of the manifestation of the revelation are shown in the figures and are described in more detail below. They show: Fig. 1 schematically a system for authorizing the execution of an action in a service system according to embodiments of the present disclosure, and Fig. 2 a flowchart of a method for authorizing the execution of an action in a service system according to embodiments of the present disclosure. Implementations of the revelation

[0038] Unless otherwise noted, the same reference symbols are used for identical and equivalent elements in the following.

[0039] Fig. Figure 1 schematically shows a system for authorizing the execution of an action in a service system 1 according to embodiments of the present disclosure. In particular, the user can control the service system 1 while in the vehicle 100. The vehicle 100 can be a motor vehicle for passenger transport.

[0040] The system comprises a biometric capture module 110, which is configured to capture at least one biometric characteristic of a user; a communication module 120, which is configured to send an authorization request with the captured at least one biometric characteristic to a first external unit 10, in particular a backend; and the first external unit 10, which is configured to generate a biometric token, wherein the system is further configured to send a request with the generated biometric token to a service system 1, wherein the request concerns the execution of an action in the service system 1.

[0041] The system's functionalities can be distributed between the first external unit 10 and / or the vehicle 100 and / or the mobile device 30. In the example of the Fig. 1. The biometric acquisition module 110 and the communication module 120 are integrated into the vehicle 100. However, the present disclosure is not limited to this, and the biometric acquisition module 110 and / or the communication module 120 can be partially or completely contained in a user's mobile device 30, such as a smartphone. For example, at least one biometric characteristic can be acquired by the mobile device 30.

[0042] In some embodiments, the vehicle 100 is connected to a first external unit 10, such as a backend of the vehicle manufacturer, via a communication link 20. For this purpose, the vehicle 100 can include the communication module 110, which is configured to provide the communication link 20. The communication link 20 can be a bidirectional communication link. The communication link 20 can be, for example, an LTE or 5G communication link. Optionally, the vehicle 100 can be connected to the mobile device 30 via a further communication link 40, such as a Bluetooth connection.

[0043] In some embodiments, the first external unit 10 is connected to the service system 1 via a communication link 2 in order to transmit the request, along with the generated biometric token, to the service system 1 to perform an action. Alternatively, the vehicle 100 can communicate (directly) with the service system 1 to transmit the request. In this case, the first external unit 10 can transmit the generated biometric token to the vehicle 100, which then sends the generated biometric token to the service system 1 as part of the request.

[0044] For example, vehicle 100 can send the biometric data captured by the biometric data acquisition module 110 to the first external unit 10 via the communication link 20. The first external unit 10 can then compare the captured biometric data with, for example, authorization data or access data from a user profile. Upon successful authentication, the biometric token can be generated in the first external unit 10 and sent to the service system 1 to initiate the corresponding actions, such as controlling devices in a smart home.

[0045] In some embodiments, the biometric acquisition module 110 can comprise at least one biometric sensor. Several biometric sensors can be integrated into a single unit, e.g., in the vehicle 100, or contained in separate subunits. For example, at least one first sensor can be integrated into the vehicle 100. At least one second sensor can be provided in the mobile device 30.

[0046] The biometric sensors can be selected from the group that includes a fingerprint sensor, a finger vein sensor, a face sensor, an eye sensor, a heart rate sensor, a foot sensor, and an anatomy sensor (or combinations thereof). The heart rate sensor, for example, can be integrated into a seat belt. The foot sensor can be located in the vehicle's footwell, and in particular in the vehicle floor.

[0047] The anatomy sensor can be configured to detect at least one anatomical characteristic of the user. This at least one anatomical characteristic can be, for example, a body shape or part of a body shape, such as the shape of the user's back and / or buttocks. In particular, the anatomy sensor can be a buttocks sensor. The buttocks sensor can enable automatic authentication as soon as the user has taken a seat. Additionally or alternatively, the at least one anatomical characteristic can include dimensions of the body shape or part of the body shape, such as back length and / or back width.

[0048] In some embodiments, the biometric acquisition module 110 can be configured to continuously acquire at least one biometric characteristic of the user over a specific period, such as the user's usage of the vehicle 100. In other words, there is no one-time acquisition and authentication at the start of use, but rather repeated or continuous acquisition and authentication over a certain period, such as the user's usage of the vehicle 100. This can, for example, prevent unauthorized access to the service system 1 by another user.

[0049] Continuous detection and authentication can be performed using a passive sensor, such as the anatomy sensor.

[0050] The following describes an example of how to implement the invention. Example 1: Door opener • For authentication, the user can, for example, use a fingerprint in conjunction with an app on their smartphone or smartwatch. • Together with a cloud service, the app can authenticate the user and generate a biometric token, which is used to authenticate the user in a backend. • After authentication of the biometric token, the backend can send an SMS / MQTT request to the vehicle to open the door. The backend could, for example, be the vehicle manufacturer's backend. Example 2: Smart home • For example, the user can use the continuous authentication described above to control a function in the smart home from inside the vehicle. • The backend (first external unit), e.g., of the vehicle manufacturer, generates the user's biometric token and sends the biometric token to a backend of the smart home (second external unit) for authentication. • The smart home backend authenticates the biometric token and can optionally request a second biometric authentication from the vehicle or mobile device for additional security. • Following complete authentication, the smart home backend can execute the function requested by the user, such as turning on an oven. Example 3: location-based control • The user can configure a location-based IoT service to start a smart kitchen program after the vehicle has arrived at a specific location (e.g., a shopping center) while driving home from work. • Afterwards, for example the next day, the vehicle can ask the user to authenticate the IoT service, e.g., based on a fingerprint (or finger vein), while returning home, whereupon the user authenticates. • The vehicle then sends the authentication request to the backend, which uses the fingerprint data to generate a biometric token for the user. • The backend then sends a request to the smart home to start the kitchen program for the user based on the generated token. • The smart home authenticates the user's biometrics and sends a request to the kitchen to start the program. This way, the user can, for example, find a hot meal waiting for them when they return home.

[0051] Fig.Figure 2 shows a flowchart of a method 200 for authorizing the execution of an action in a service system according to embodiments of the present disclosure.

[0052] The procedure 200 comprises, in block 210, the acquisition of at least one biometric characteristic of a user; in block 220, the sending of an authorization request with the acquired at least one biometric characteristic to a first external entity; in block 230, the generation of a biometric token by the first external entity; in block 240, the sending of a request with the generated biometric token by the first external entity to a service system, wherein the request concerns the performance of an action in the service system; and in block 250, the performance of the action by the service system based on the request received from the first external entity.

[0053] According to the invention, biometric authentication takes place along the entire communication chain, which includes at least the service system and the first external unit (e.g., a central unit such as a backend). Using biometric authentication along the entire communication chain improves security. In particular, unauthorized access to a service system, such as a smart home or a vehicle, can be prevented. This is especially advantageous because conventional cryptographic systems, which use, for example, a public key and tokens, can be decrypted using quantum computing.

Claims

[1] Method (200) for authorizing the performance of an action in a service system (1), comprising: Capture (210) at least one biometric characteristic of a user; Sending (220), by a vehicle (100), an authorization request with the captured at least one biometric characteristic to a first external unit (10), in particular a backend; Generating (230) a biometric token by the first external entity (10); Sending (240) a request with the generated biometric token to a service system (1), wherein the request concerns the execution of an action in the service system (1), and wherein the service system (1) is an external service system (1) outside the vehicle (100), and wherein the service system (1) is a smart home or an IoT system; and Performing (250) the action by the service system (1) based on the received request, where at least one biometric characteristic of the user is continuously recorded for multiple authentications. [2] The method (200) according to claim 1, further comprising: Verification of user authorization by the first external entity (10) based on the received at least one biometric characteristic, wherein the biometric token is only generated if the verification results in a positive authorization for the user. [3] The method (200) according to claim 1 or 2, wherein the service system (1) comprises a second external unit, wherein the second external unit receives the request with the generated biometric token, and wherein the method (200) further comprises: Verification of user authorization by the second external entity. [4] The method (200) according to claim 3, further comprising: Sending a request to the user regarding further authorization of the user by means of at least one additional biometric characteristic by the second external entity. [5] The method (200) according to claim 1, further comprising: Specifying a location for sending the authorization request with the captured at least one biometric characteristic to the first external unit (10), wherein the authorization request is sent when the vehicle (100) reaches the location. [6] The method (200) according to one of the preceding claims, wherein the at least one biometric characteristic is captured by a mobile terminal device (30) of the user. [7] System for authorizing the execution of an action in a service system (1), comprising: a biometric data acquisition module (110) designed to capture at least one biometric characteristic of a user; a communication module (120) of a vehicle (100) which is equipped to send an authorization request with the recorded at least one biometric characteristic to a first external unit (10), in particular a backend; and the first external unit (10) that is set up to generate a biometric token, wherein the system is set up to send a request with the generated biometric token to a service system (1), wherein the request relates to the execution of an action in the service system (1), wherein the service system (1) is an external service system (1) outside the vehicle (100), wherein the service system (1) is a smart home or an IoT system, and wherein the at least one biometric characteristic of the user is continuously recorded for multiple authentication.

Citation Information

Patent Citations

  • authentication of a vehicle user

    DE102016123857A1

  • Biometric authentication for a vehicle without prior registration

    DE102018120679A1