Portable user device and method for preparing an authorization of access to a means of transportation
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- VOLKSWAGEN AG
- Filing Date
- 2019-08-21
- Publication Date
- 2026-07-30
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
The invention relates to a portable user terminal and a method for preparing authorization for access to a means of transportation. In particular, the present invention relates to a means of defending against so-called relay attacks aimed at gaining unauthorized access to a means of transportation. Access control systems are known in the prior art in which the user does not need to actively use the vehicle key to gain access to a means of transport. Instead, the user's identifier can be carried on a radio key or a smart mobile device (e.g., smartphone). Only mechanical access to the means of transport (placing a hand on a door handle or activating a microswitch in the door handle) triggers an exchange of the ID with the means of transport, thus recognizing the user as authorized for access. When these actuators are activated, the aforementioned radio-based key / smart mobile device is authorized. The start of the authorization process can therefore always be extended by a relay attack in the radio spectrum. For this purpose, all radio activity is extended in range, depending on a radio frequency or radio band.A first station is temporarily set up near the vehicle, which relays the trigger signal from the vehicle to a second station located near the key fob. The second station transmits the extended signal, reaching the key fob, which—assuming the vehicle is initiating an authorization process—transmits its radio identification code. This code is received by the second station and extended so that the first station receives it and retransmits it. The vehicle then receives this retransmission, unlocking the vehicle even if the key fob and the authorized user are many meters away. One point of entry for the aforementioned technology is therefore that mechanical access (trigger) to the vehicle initiates the authorization process. To thwart the aforementioned unauthorized access methods, time-of-flight (TOF) measurements of radio signals are sometimes performed nowadays. Based on these measurements, authorization signals are invalidated if they arrive at the receiver too late. The multiple conversions involved in the relay attacks described above cause delays, rendering the signal ultimately received by the vehicle invalid. In this case, the vehicle is no longer unlocked by the received signal. Today's wireless access systems operate at frequencies such as 125 kHz, 433 MHz, or Bluetooth. Ultra-wideband (UWB) technology is also used, all of which extend the radio signal between the key and the smart mobile device. However, even if the aforementioned time-of-flight measurement is currently the most effective method, it is only a matter of time before faster repeater technologies render this measure ineffective. DE 10 2013 217 010 A1 and DE 20 2016 105 621 U1 disclose keyless vehicle systems that can be used to defend against relay attacks. This involves using location-based information regarding the key fob and vehicle to ensure sufficient proximity between the transmitter and receiver to prevent a relay attack. DE 10 2014 222 427 A1 discloses a radio key, a mobile user device, a means of transportation, and a method for adapting an assignment between a user profile and a radio key for a means of transportation. The method comprises
[0008] “querying for authentication for data exchange between the radio key and a mobile user device. The data exchange includes, in particular, the authorization for adapting the user profile. This step could also be referred to as matching (pairing) between the radio key and the mobile user device, whereby an identifier representing the user profile to be activated is transmitted, at least in one direction.”“In this process, the correlation of a movement profile is analyzed to identify a permissible adjustment of an assignment between a user profile and a radio key by identifying two movement profiles created at the same time. DE 10 2007 023 140 A1 discloses a method for identifying a driver of a motor vehicle, wherein a movement and / or sequence of movements of the person is recorded by means of a camera system and analyzed for identification purposes. DE 10 2016 204 750 A1 discloses a method for authorizing the use of a motor vehicle, wherein two spatially separated antennas are used, wherein each antenna receives the spatial components of the signals from the antenna of the identification transmitter and the authorization signal is only sent to the motor vehicle if the angle between the spatial components exceeds a predetermined threshold. WO 2014 / 064297 A1 discloses a vehicle access system for opening and closing a vehicle and a method for operating the vehicle access system, in which distance information between a user and the vehicle is determined at various times, a match between the movement pattern and a predefined movement pattern is checked, and the vehicle is opened. The use of ultrasonic distance sensors and / or capacitive distance sensors is proposed for determining the distance information. Based on the aforementioned prior art, it is an object of the present invention to achieve improved protection against relay attacks. The aforementioned problem is solved according to the invention by a method for preparing the authorization of access to a means of transportation. The means of transportation can be, for example, a car, van, truck, motorcycle, aircraft, and / or watercraft. Preparing the authorization of access to the means of transportation can be understood as a process by which an authorized user is ultimately granted access to the means of transportation. In this process, the identifier assigned to the authorized user is verified by the means of transportation or an instance assigned to it, and the means of transportation is unlocked (e.g., a door or all doors). In a first step, a movement profile of a user authorized to access the means of transportation is determined. Sensors can be used for this purpose, and their information is processed by an electronic evaluation unit.At this stage, it is not yet necessary to establish that the user is actually an authorized user. Rather, the movement profile of a user or a wireless communication device they are carrying is determined using data. The movement profile can be characterized by the relationship between location and time, speed and time, acceleration and time, or other sensor data recorded over time. Microphones, light sensors, magnetic field sensors, barometric pressure sensors, and antennas for various wireless signals can also be used to capture sensor signals received over time during a user's movement and thus record the movement profile or characterize the movement. Particularly in densely populated areas, the sequence in which the user's device receives signals from specific wireless access networks (e.g., Wi-Fi, Bluetooth, etc.) can identify a traversed path as a movement profile.The movement profile, or the data derived from it, is then compared with a predefined reference. This reference can, for example, be assigned to an authorized user, thus identifying them from other users. If the previously determined movement profile sufficiently matches the predefined reference, this indicates that the user is authorized to access the vehicle. However, if there is a slight discrepancy between the determined movement profile and the predefined reference, it may be necessary to adjust the predefined reference to the movement profile of the authorized user. This, of course, assumes that the user is indeed the authorized user. Therefore, the following steps assume that the verification of the user as an authorized user is successful.For this purpose, an additional signal is received to authenticate the authorized user. In other words, the user authenticates themselves via an additional signal that does not correspond to the signal representing the movement profile. Put another way, the additional signal has a different nature than the movement profile. Examples of additional signals include biometrically determined signals or user input (facial recognition, fingerprint, retinal scan, etc.). Once the user has been authenticated by the additional signal, the predefined reference can be adapted to the determined movement profile in a subsequent step. This involves modifying, extending, or supplementing a file, thereby using the most recently determined movement profile of the authorized user as the basis for the new or modified predefined reference.In other words, this ensures that the determined movement profile can also be recognized as characteristic of the authorized user in the future. The reasons for a change in the user's movement profile can vary widely. For example, the user may be wearing different footwear than when the predefined reference was first defined. Alternatively or additionally, different ground conditions (slippery / snow / slush, construction site leading to an obstacle course), the user's aging process, and / or carrying bulky and / or heavy objects can cause the user's movement profile to no longer match the predefined reference or to deviate from it in some way.The method according to the invention avoids a situation where a trigger sent by the means of transport in conjunction with a relay attack leads to an unauthorized user being granted access to the means of transport, while an authorized user, for example due to an aging process, different footwear or different ground conditions, has a movement profile different from that represented by the predefined reference, and therefore does not gain access to the means of transport. The dependent claims describe preferred embodiments of the invention. In a further step, an optional initial signal is also issued to prepare for access to the vehicle. This initial signal can thus indicate that the movement profile belongs to the authorized user. It therefore signals that the vehicle can grant access to the user exhibiting this movement profile. The initial signal can, for example, be generated by a smartphone or a smart wearable and transmitted wirelessly. It is generally irrelevant whether the initial signal is sent directly to the vehicle or only indirectly (e.g., via the internet and / or a separate key fob). Preparing for access does not necessarily constitute the final command to unlock an access control device, but it can be understood as a condition for the vehicle to ultimately (e.g.,(under further conditions) unlocks. The first signal can be generated, for example, from a distance of nine meters from the vehicle, so that at a later time, when the user has approached the vehicle (e.g., to within three or two meters), the actual unlocking can be carried out. For example, the first signal can be understood as a "ping" or trigger, which checks whether the vehicle is even in the vicinity of the authorized user. If this is the case, the first signal in the vehicle can cause antennas to switch to receive mode to receive an identifier, which is used to authorize access to the vehicle. The antennas can be, for example, UWB antennas. The first signal can therefore be the vehicle or...The first signal initiates the access authorization check and does not itself have to meet such high integrity requirements as the second signal, which is actually required for the authorization process later on. The first signal can, for example, be relayed by other vehicles located in the vicinity of the vehicle in question. These could be vehicles from the same manufacturer, operator, and / or owner, and thus exhibit a minimum level of integrity. The movement profile can be recorded, for example, using a smartphone or other smart wearable. Such devices typically have a variety of suitable sensors to identify and characterize a movement profile in a recognizable way. For example, accelerometers can be used to characterize the movement profile over time by measuring horizontal and / or vertical acceleration. As is known, human movement patterns, similar to a fingerprint, can be used to identify an individual and, according to the invention, can therefore be used to authorize the authorized user to access the means of locomotion. Alternatively or additionally, a gyroscope or rotation sensor can be used to measure the position of the device and / or to record / characterize the movement profile. The same applies to microphones, cameras / light sensors, and barometric pressure sensors, etc.Using the aforementioned sensors, a sufficiently detailed recording of the movement profile can be made and the movement profile can be related to the predefined reference with a maximum of possible detail before a successful comparison prepares the unlocking of the means of transport. The movement profile can be characterized, for example, by reaching a predefined speed. For instance, a minimum speed typically achieved on foot can be used as a prerequisite for the movement profile. A stationary car key, for example, would not meet this condition, thus successfully thwarting relay attacks in many situations. Alternatively or additionally, the movement profile can be characterized by a direction of movement towards the means of transport. It is important to note that simply detecting that the user falls below a predefined distance from the means of transport is not sufficient for determining the direction of movement; at least two, and preferably three, measurements must be taken, the results of which indicate a continuous or strictly monotonous approach to the means of transport.If the vehicle key remains stationary or the user moves away from the vehicle, a relay attack cannot be performed. Alternatively or additionally, vertical and / or horizontal accelerations of the user or the portable user device can be recorded and compared with a predefined reference. In particular, user-specific accelerations, which allow conclusions to be drawn about the user's mode of movement (e.g., gait), can be determined, characterized, and compared with the predefined reference. This prevents unauthorized users who possess a vehicle key or...The portable user device is used for access control to verify authorization. Access to the means of transport is granted to unauthorized users along a path typically traversed by the authorized user, because the unauthorized user exhibits a different, sensor-detected acceleration profile when approaching the means of transport. The movement profile can also be characterized by a previously stored path geometry. In other words, the orientation between the starting point and destination, or even the segments of the traversed path relative to each other or in absolute terms, is recorded and then checked to see if the path matches the existing reference. The path geometry can also be recorded three-dimensionally or represented in the predefined reference, so that movements in stairwells and / or elevators also provide suitable combinations of features for identifying the authorized user.Alternatively or additionally, a temporal sequence of received sensor signals can also characterize the movement profile, so that, for example, signals received by means of antennas, microphones or light sensors and in particular electromagnetic signatures over time and over place characterize the movement profile. In the event of a discrepancy between the determined movement profile and the predefined reference, the user may receive a corresponding signal or message. This may include a request to authenticate themselves via an additional signal. For example, this signal could be emitted by a smartphone or other smart wearable carried by the user and optionally used to determine the movement profile. The request could be visual, audible, and / or haptic (e.g., vibration). The prompt to enter the additional signal could also specify the method of authentication or additional authentication.For example, facial recognition (Face ID), the entry of a personal identification number (PIN), the entry of a predefined swipe pattern, and / or the scanning of a user's fingerprint may be required to generate the additional signal. In this way, the additional signal and its generation differ from the nature of the signal that represents the determined movement profile. One signal can thus be used to perform or correct a failed authentication attempt using the other signal. This allows for more robust recognition of the user's movement profile. Optionally, after generating the additional signal and successfully authenticating the authorized user, a prompt can appear asking whether the most recently detected movement profile, which necessitated the additional authentication, should be used to adjust the predefined reference. An unusual event or singularity might result in the user exhibiting an unusual or non-recurring movement profile. For example, the user might have transported a particularly bulky or heavy object, in which case the predefined reference should not be expanded or altered. If the user declines the prompt or refuses to consent to adjusting the predefined reference, the predefined reference remains unchanged.If the user agrees to the adjustment of the predefined reference, in a subsequent step the user's terminal device and / or means of transport can adjust the predefined reference to the last determined movement profile. In particular, a message can be sent from a user-carrying wireless portable device to the vehicle, specifying the predefined reference to be adjusted. Information from the user device, including data representing the most recently determined movement profile, can be transmitted to the vehicle. Specifically, parameters of the movement profile can be transmitted to the vehicle in a suitable level of detail. Suitable transmission technologies include those that offer both an appropriate data rate and a sufficiently high level of data security. For example, an induction coil in a portable device can transmit the data to the vehicle, while a second induction coil in the vehicle can receive the data from the portable device.This involves establishing a short-range radio connection that cannot be intercepted outside the passenger compartment of the vehicle, or only with considerable technical effort. In this way, the data representing the user's movement profiles cannot be misused. Alternatively or additionally, WLAN signals, ultrawideband (UWB) signals, and / or Bluetooth (low energy, LE) signals can be used to send the message and are preferably transmitted in encrypted form. If a machine learning algorithm (machine learning, deep learning, etc.) is used to determine the predefined reference, the data / messages transmitted from the portable user device to the vehicle can be adjusted according to the weights of this algorithm.In other words, the evaluation of the machine-based learning performed on the vehicle is adapted to the user's most recently determined movement profile by changing and / or adding new weights, in order to continue recognizing the most recently determined movement profile as belonging to the authorized user. To further hinder the interception of the message from the portable user device to the vehicle, it may be ensured that the vehicle is in motion before the message transmission is initiated. In this way, stationary interception devices may only receive parts of the message that are unusable for misuse.Once the machine-based learning algorithm has been successfully completed, the modified predefined reference can be returned to the portable user device and thus made available for future recognition of the user's movement profile without requiring additional user authentication as described above. The scenarios described above do not preclude the possibility of preparatory steps for adapting the machine learning algorithm being performed on the portable user device before it is installed in the vehicle. In this way, particularly powerful portable user devices can utilize their available computing power to generate the most rapid possible adaptation of a predefined reference. This approach may also reduce the amount of data that needs to be transferred to the vehicle. In any case, the data used to adapt the predefined reference can be protected against unauthorized access by means of encryption between the portable user device and the vehicle. Since the movement profile represents an identifier exclusively linked to the authorized user, a training mode can be used to learn and record a predefined reference. This training mode can be triggered, for example, initially, repeatedly, or continuously to capture a predefined reference. For this purpose, a situation can be created in which the user alternatively authorizes themselves to the vehicle. This can be done, for example, using the key fob or by continuously or repeatedly requesting activation of the key fob. The user then moves along their usual route to the vehicle with a suitable portable wireless communication device (vehicle key and / or smart mobile device), while the movement profile is recorded by the sensors of the smart mobile device and / or the key fob.Subsequently, an initially permissible degree of inaccuracy can be applied to the motion profile or the acquired data, for example, by repeating the aforementioned process or by mathematically imposing an inaccuracy using the acquired data. The training mode can then be terminated and the predefined reference used. In this way, the predefined reference can be optimally adapted initially to the site-specific conditions and the individual, authorized user, and, according to the invention, also to subsequently changed circumstances. Subsequently, the system can detect when an authorized user has approached the vehicle within a predefined distance. In other words, it can determine whether the user has moved to within one, two, or three meters of the vehicle. This indicates the user's close proximity to the vehicle, making unauthorized access at the same time highly unlikely. Upon this detection, a second signal is automatically sent to the vehicle to prepare for access. This signal can also be sent from a portable device or key fob carried by the authorized user. During this process, the actual authorization of the key is exchanged and verified in conjunction with the vehicle.In particular, authorization classes for accessing the vehicle can also be determined. For example, a first identifier can allow subsequent access to the vehicle, including driving it, while a second identifier only allows access to the second row of seats in the passenger compartment and specifically prohibits driving tasks. A corresponding second identifier could, for example, be assigned to the authorized user's children, who can board independently but cannot drive the vehicle. Similarly, a third identifier can be predefined, which can be assigned to postal workers or parcel delivery personnel who should only have access to the trunk but not to the passenger compartment itself.If the aforementioned identifiers and the access rights associated with them should not be part of the state of the art, they are hereby explicitly understood to be disclosed independently of the aforementioned items for the purpose of defending against relay attacks and can therefore constitute an independent subject matter of an application. To save energy, especially when access to the vehicle by an authorized user is unlikely, the inventive method can be triggered by the following steps: First, the current position of the vehicle is determined. Only when the distance between the user and the vehicle falls below a predefined threshold is the movement profile automatically determined, as described above. For this purpose, the current position of the vehicle can be stored in the memory of a smart mobile device and / or the key fob. The current distance to the vehicle can then be monitored (continuously or event-based), for example, by satellite-based tracking of the smart mobile device or key fob.Event-based monitoring can be triggered, for example, by acceleration signals and / or acoustic events and / or changes in position detected when the key is picked up. Subsequently, similar to a geofence function, the system determines when a maximum distance to the vehicle has been reached, which then triggers the determination of the movement profile as described above. In some cases, it may be advantageous to explicitly determine the access intent of the authorized user while the user is still outside such a distance that unlocking the means of transport seems sensible at the current time. However, the user may already know at this point that they will not have a free hand or prefer hands-free access authorization for other reasons. For this purpose, the user's intention to access the vehicle shortly can be detected on a smartphone and / or vehicle key, triggering the aforementioned procedure. In other words, the user presses a button on a portable device, whereupon their approach is monitored and, at an appropriate time, the movement profile of the authorized user is also determined. At this point, the authorized user's key or smartphone may already be in a pocket, and the user may be using their hands to carry bags or other luggage.Upon arrival at the vehicle, it unlocks automatically without requiring the activation of a trigger such as a capacitive or microswitch. The automatic opening of the door can also be initiated by the user explicitly and in advance expressing their access request. This also saves energy and reduces the risk of the authorized user not being recognized. According to a second aspect of the present invention, a portable user device is proposed, which can be configured as a radio key and / or smart mobile device (i.e., smartphone) or smart wearable. The user device comprises a data input, a data output, and an evaluation unit, which is linked to the aforementioned elements via information technology. The evaluation unit is configured to automatically determine a movement profile of a user authorized to access a means of transportation using the data input. For this purpose, the data input can be linked to one, several, or all of the user device's sensors. In principle, sensors located outside the user device (e.g., stationary surveillance cameras and / or sensors on the authorized user's means of transportation) can also be linked to the data input for recording information.The evaluation unit is then configured to compare the movement profile with a predefined reference and, upon receiving a negative result from the comparison in conjunction with the data input, automatically receives an additional signal to authenticate the authorized user. This additional signal can be understood as an alternative authentication measure to identify the authorized user and, on the one hand, grant access to the means of transportation and, on the other hand, enable the predefined reference to be adapted to the determined movement profile. In other words, the portable user device according to the invention is configured to implement the features, feature combinations, and advantages of the aforementioned method according to the invention in such a way that, to avoid repetition, reference is made to the above explanations. In particular, the portable user device has storage media configured to store a data set representing the current position of the vehicle. The portable user device can, for example, automatically save its current position to the storage media when it is removed from the vehicle or disconnected from it (e.g., when the Bluetooth connection is terminated). Alternatively or additionally, the portable user device can be dynamically informed about the current location of the vehicle. This can be done, for example, via the internet. Based on the current position, the portable user device can determine the current distance to the vehicle and, upon reaching or falling below a predefined distance, initiate or execute the above steps in an energy-efficient manner. Further details, advantages, and features of the present invention will become apparent from the following description of exemplary embodiments with reference to the drawings. The drawings show: Fig. 1 a schematic overview of usage scenarios for carrying out a method for authorizing access to a means of transportation; Fig. 2 a flowchart illustrating the steps of an exemplary embodiment of a method according to the invention; Fig. 3 a schematic detail view of elements of an exemplary embodiment of a portable user terminal device according to the invention; and Fig. 4 a schematic representation of a past movement profile in relation to a predefined reference, as well as a currently determined movement profile and an adapted predefined reference. Fig. 1 shows a car 10 as a means of transport usable according to the invention, which has a module 15 for access authorization verification. The module 15 is linked to an evaluation unit 11, which in turn is linked to an antenna 9 and a data storage device 14. A first movement profile 2a is characterized by the geometry of the user's 1 walking path from his house 20 towards the car 10. A second movement profile 2b is characterized by the reverse path from the car 10 to the house 20. A third movement profile 3a shows the geometry of a walking path of the user from the car 10 to the desk 302 in an office building 30, and a fourth movement profile 3b shows the reverse path of the user 1 from his desk 302 to the car 10.The user carries a smartphone 4, an example of a portable user device, which is known to have a variety of (not shown) sensors that can determine and record information about the movement profiles 2a, 2b, 3a, 3b. As soon as the smartphone 4 detects that it is within the area, it will initiate the determination of the movement profile 2a, 2b, 3a, 3b and thus prepare access to the car 10. The movement profile 2a, 2b can be determined, for example, solely based on the acceleration that occurs when the user 1 walks from their house 20 to the car or vice versa. In addition, the paths taken by the user 1 can be recorded or detected by the gyroscope, accelerometer, and magnetic field sensors contained in the smartphone 4.Furthermore, an antenna for accessing a wireless access network 291 can determine the home network identifier (SSID) and track the signal over time and distance. Upon reaching a vehicle-proximity area, the determined movement profile 2a is compared with the predefined reference. If the comparison is successful, an initial signal is sent to the vehicle 10. This initial signal contains information indicating that the comparison was successful and that the authorized user 1, or their smartphone 4, has approached the vehicle 10. Upon this response, the vehicle 10's UWB antennas (not shown) are activated. If the user 1 approaches again to within two to three meters, the user 1's actual identifier is exchanged between the smartphone 4 and the vehicle 10.If the personal identifier of user 1 is successfully matched, car 10 unlocks, granting user 1 access. To ensure the movement profile provides sufficient information indicating that the authorized user 1 is approaching car 10, the data identifying the movement profile in smartphone 4 is invalidated within a short time, particularly if user 1's approach to car 10 is aborted or takes too long. This prevents the car 10's UWB antennas from being operated unnecessarily or even erroneously. The following section discusses movement profiles 3a and 3b, which result from user 1's movement between their desk 302 and their car 10. While movement profile 3a is recorded after the authorized user 1 exits the car using the sensors of the smartphone 4, the smartphone 4 first determines the two curves using a position sensor / magnet sensor, then determines the spatial proximity and field strength of the antennas 391 to 395 of the wireless access networks within building 30, and uses a barometric pressure sensor to determine the elevator ride 301, before connecting to a smart coffee machine 303 behind user 1's desk 302. On the return journey 3b, the aforementioned information is recorded using the same sensors and compared with a predefined reference, which was previously recorded in a training mode during movement profile 3a.If movement profile 3b essentially represents the reverse of the location / time sequence of movement profile 3a, a positive match triggers the transmission of the first signal to car 10 upon reaching the proximity range. This prepares the car for verification of user 1's access authorization or that of their smartphone 4, for example, by activating car 10's UWB antennas (not shown). If the comparison of movement profile 3b yields a negative result, additional authentication is requested before car 10 is unlocked. This is done to verify user 1's authorization and to adjust or "soften" the predefined reference in the form of the reverse of the location / time sequence of movement profile 3a. If user 1 or their smartphone 4 approaches further, the system will then...Once the distance between the smartphone 4 and the car 10 is determined (especially two to three meters), the smartphone 4 initiates the exchange of the ID required for unlocking the car 10 via the UWB antennas and the comparison of the ID with a corresponding predefined reference. Fig. 2 shows a flowchart illustrating the steps of an embodiment of a method according to the invention for authorizing access to a means of transportation. In step 100, a movement profile is learned or created as a predefined reference in a training mode. Suitable sensors are operated automatically, and while the portable user device, which is subsequently to be used to authorize access to the means of transportation, is moved, the data they provide based on received signals is recorded over time. A predefined blur is then applied to the sensor data, and the result is stored as a predefined reference in a data memory of the portable user device.In step 200, the current position of the means of transport is determined. In step 300, when the distance between the user and the means of transport falls below a predefined threshold, a movement profile of the user's device is automatically generated. This movement profile is assigned to a user authorized to access the means of transport. In step 400, the movement profile is automatically compared to the predefined reference created in step 100. In other words, the movement profile determined in step 300 is examined for its similarity to the predefined reference. If the comparison fails in step 500, the user is automatically prompted to enter an additional authentication signal. In step 600, this additional authentication signal is generated.For this purpose, biometric sensors on the user's portable device are used for identification. Upon successful additional user authentication, an initial signal is sent to prepare for access to the vehicle. The first signal is sent from the portable user device to the vehicle. In response, the vehicle activates its UWB antennas to receive, thus pre-conditioning it for an authorization process in conjunction with the portable user device. In step 700, the vehicle detects when the user has approached the vehicle within a predefined distance. This can also be done using sensors or the portable user device. The approach might be to within two to three meters, for example, at which point a second signal is automatically sent to the vehicle in step 800 to prepare for and authorize access. This second signal, also sent from the portable user device, contains the actual identifier (ID) that identifies the user as authorized to access the vehicle. In step 900, it is determined that the user device is now located inside the vehicle. At this point, secure data transmission between the user device and the vehicle's electrical system is possible. The user device sends a message indicating that the predefined reference needs to be adjusted, along with additional information for this adjustment, via an inductive data interface to the vehicle. This allows the weights of a machine-based learning algorithm running inside the vehicle to be adjusted, ensuring that the most recently determined movement profile is now covered by the predefined reference.In other words, it is ensured that a sufficient safety zone exists around the last determined movement profile, which guarantees successful access to the means of transport even in the event of further deviations of a future movement pattern from the last determined movement profile. Finally, in step 1000, the predefined reference is adapted to the most recently determined movement profile using a machine learning algorithm. As a result, changes to an authorized user's movement profile (over time) prevent a "drift between the predefined reference and the user's movement profile" and thus ultimately lead to the authorized user being denied access to the vehicle. Furthermore, it prevents a relay attack or theft of the smartphone from granting unauthorized access to the means of transport.Fig. 3 shows a detailed view of components of an embodiment of a portable user terminal device according to the invention in the form of a smartphone 4. A programmable processor 11 as an evaluation unit has data inputs and outputs 12, which are connected to an antenna 9 for receiving wireless access network messages, a data storage device 14 for providing program codes for executing the method according to the invention and for storing a current position of the means of transport, a gyroscope 6 for determining rotational movements of the smartphone 4, an accelerometer 5, which is designed as a three-axis sensor, a magnetic field sensor 7 for determining the orientation of the smartphone 4 relative to the Earth's magnetic field, and an air pressure sensor 8 for determining an altitude or...The smartphone 4 is connected to a light sensor 10 and a screen 13 as a display device. The antenna 9 also enables the smartphone 4 to transmit a first and second wireless communication signal to the (not shown) means of transport and, if necessary, to receive satellite-based signals for location tracking. Fig. 4 shows a vertical acceleration signal 18 over time t. The vertical acceleration signal 18 was learned in a training mode while an authorized user performed a typical walking motion in a controlled environment. The user's gait, learned through the acceleration signal 18, was determined by several successive gaits, utilizing the inherent imprecision of the signals relative to each other to generate a lower limit 17a and an upper limit 17b as a predefined reference. Characteristic of this are the vertical acceleration peaks that occur with each step, which characterize the authorized user's movement profile and thus reveal their approach to the means of locomotion. After some time, however, the user developed wear-related knee pain and unconsciously adjusted their gait.Its motion profile now exhibits less pronounced, but slower rising and falling acceleration peaks, which have led to a broadening of the acceleration peaks. This signal is additionally plotted as the recently determined motion profile 18'. A lower limit 17a of the predefined reference is not thereby more closely approximated. However, areas adjacent to the acceleration peaks of signal 18 are "violated" of the upper limit 17b, meaning that the recently determined motion profile 18' could no longer be used to unlock the vehicle as it falls below the predefined reference 17a, 17b. In response to additional user authentication via a biometric sensor, permission was therefore granted to adjust the upper limit 17b, resulting in a modified upper limit 17b' within the predefined reference.This profile also has a sufficient distance from the recently determined movement profile 18', so that both acceleration profiles 18 and 18' can henceforth be satisfactorily tested as the predefined reference. As a result, the user can access their means of transportation hands-free in the usual way, even though the biometric characteristic of their gait has changed over time. Within the scope of the present invention, a simple method for creating a movement profile of an authorized user involves recording the user's path from the moment they leave the vehicle until they reach a secure, fixed location using sensors. Upon their return from this secure location to the vehicle, corresponding movement data is then compared with the aforementioned data. Movement data is also generated immediately in front of the vehicle and before the user takes their seat, which can be used to record and recognize a movement profile. Furthermore, movement data can be collected at location-relevant points (e.g., in the office, at the gym, in a shopping center, in schools, at home, in a parking lot, or in a garage) and recognized for user authorization. A portable user device, configured for wireless communication with the vehicle, carries an electronic identifier (ID) and transmits its location only upon entering a ten-meter radius around the vehicle. Reaching this ten-meter radius is determined solely from the portable user device's movement data. The secure zones are stored in the portable user device, and movement profiles determined within these zones are transmitted to the vehicle upon authorized access. These profiles are continuously updated to detect and correct gradual changes and aging processes, such as those occurring during user gait. The data collected regarding the movement profiles is checked for plausibility. If the position data or other factors are consistent, the system automatically checks the vehicle's location and / or the user's movement.If the movement profiles do not match, the vehicle must be opened using a biometric feature on the portable user device. This could involve, for example, a fingerprint scanner or facial recognition. Optionally, movement data from the portable user device regarding the direction of movement towards the vehicle (e.g., satellite-based) can also be determined to detect actual movement towards the vehicle. As a result, the present invention prevents relay attacks or avoids the complex programming of security functions in known systems for defending against relay attacks and the misappropriation of smartphones and other portable user devices used for access authorization verification. According to the invention, various mechanisms are presented alternatively or cumulatively to establish communication between the portable user device / vehicle key and the vehicle for the purpose of access authorization verification. Reference symbol list 1 User 2a, b Motion profile 3a, b Motion profile 4 Smartphone 5 Accelerometer 6 Gyroscope 7 Magnetic field sensor 8 Air pressure sensor 9 Antenna 10 Car 11 Evaluation unit 12 Data inputs and outputs 13 Screen 14 Data storage 15 Module 16 Light sensor 17 a Lower limit 17 b Upper limit 17 b' Adjusted upper limit 18 Vertical acceleration over time 18' Modified vertical acceleration over time 20 House 30 Office building 100, 200 Process steps 291 Antenna Home network 300 Process step 301 Elevator 302 Desk 303 Smart coffee machine 391-395 Antennas Wireless access networks 400-1000 Process steps az Vertical acceleration Di Vehicle proximity Da Ambient area t Time
Claims
Method for authorizing access to a means of transportation (10) comprising: - automatic detection (300) of a movement profile (2b; 3b; 18') of a user (1) authorized to access the means of transportation (10), wherein the movement profile (2b; 3b; 18') is detected by means of an antenna (9) for access to a local radio access network, - automatic comparison (400) of the movement profile (2b; 3b, 18') with a predefined reference (17a, 17b) and, depending on a negative result of the comparison: ◯ receiving (600) an additional signal to authenticate the authorized user (1); and ◯ automatic adjustment (800) of the predefined reference (17b) to the detected movement profile (2b; 3b; 18'). Method according to claim 1, wherein the motion profile (2b; 3b;18') is determined by means of a smartphone (4) and / or accelerometer (5) and / or gyroscope (6). Method according to one of the preceding claims, wherein the motion profile (2b; 3b; 18') is determined by means of a magnetic field sensor (7) and / or an air pressure sensor (8). Method according to one of the preceding claims, wherein the motion profile (2a, b; 3a, b; 18; 18') is characterized by • reaching a predefined speed and / or • a direction of movement towards the means of locomotion (10) and / or • user-specific vertical accelerations. Method according to one of the preceding claims further comprising the step:- Automatically issuing (500) a request to the user (1) to generate the additional signal for authentication. Method according to one of the preceding claims further comprising the step of: - Automatically determining (700) that the user (1) is in the means of transport (10) and - Sending a message that the predefined reference (17b) needs to be adjusted or - Adjusting (800) the predefined reference (17b). Method according to claim 6, wherein the sending of the message that the predefined reference (17b) needs to be adjusted is carried out via an ultra-wideband and / or Bluetooth and / or an induction coil and / or when adjusting the predefined reference (17b) weights of a deep learning algorithm are adjusted. Method according to one of the preceding claims further comprising the step: - Determining (600) an approach to a predefined distance of the user (1) to the means of transport (10) and in response thereto - automatically sending (700) a second signal to prepare for access to the means of transport (10). Method according to one of the preceding claims further comprising the step: - determining (200) a current position of the means of transport (10) and, in response to falling below a predefined distance (Da) between the user (1) and the means of transport (10) - automatically determining (300) the movement profile (2a, b; 3a, b). Method according to one of the preceding claims, wherein the first signal and / or motion profile (18) is sent from a portable user terminal device (4) to the means of locomotion (10). Portable user terminal (4) comprising: a data input (12), an evaluation unit (11), and a data output (12), wherein the evaluation unit (11) is configured to automatically determine a movement profile (2a, b; 3a, b; 18; 18') of a user (1) authorized to access a means of transportation (10) by means of the data input (12), wherein the movement profile (2b; 3b; 18') is determined by means of an antenna (9) for access to a local radio access network (Source for amendment to claim 11: claim 3 in conjunction with p. 12, first sentence of the first paragraph in the accompanying description: "In other words, the portable user terminal according to the invention is configured to implement the features, combinations of features, and advantages of the above-mentioned method according to the invention in such a way that reference is made to the above statements to avoid repetition.),- automatically compare the movement profile (2b; 3b; 18') with a predefined reference (17b) and, in response to a negative result of the comparison, receive an additional signal for authentication of the authorized user (1) via the data input (12) and, in conjunction with the data output (12), automatically adapt the predefined reference (17b) to the determined movement profile (2b; 3b; 18'). Portable user terminal (4) according to claim 11, which is configured to perform a method according to any one of the preceding claims 1 to 10. Portable user terminal device according to claim 11 or 12, which is configured to store a data set representing a current position of the means of transport (10).