Method for activating a control command set in a user's motor vehicle

An external data processing device facilitates secure and efficient transfer of vehicle usage rights by remotely deactivating and activating control command sets, addressing the complexity of existing methods and enhancing security and usability in vehicle fleets.

DE102023115178B4Active Publication Date: 2026-05-07AUDI AG
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
AUDI AG
Filing Date
2023-06-12
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

Existing methods for transferring vehicle usage rights, such as those in car sharing, require users to register each time they use a different vehicle and demand complex control unit retrofits, making them difficult to implement.

Method used

A method involving an external data processing device for authenticating users and remotely deactivating and activating control command sets across vehicles, ensuring secure and efficient transfer of usage rights without the need for electronic vehicle keys.

Benefits of technology

Enhances security and simplifies the transfer of vehicle usage rights, allowing seamless access to predetermined functions across multiple vehicles while preventing double use and reducing the need for complex vehicle retrofits.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for activating a control command set in a user vehicle to provide at least one predetermined function, wherein the at least one predetermined function relates to a vehicle interior experience and the method comprises: - Authenticating a person (100; 200, 300) who has a right to use the control command set, and upon successful authentication: first - Deactivating the control command set on another motor vehicle (1) and only if deactivation is successful, then - Activation of the control command set on the user vehicle (1'), wherein an external data processing device (40) is used, which the person (100, 200; 300) can use to authenticate themselves, and via which deactivation and activation take place, wherein the external data processing device (40) sends a command (Deakt.) to the other vehicle (1) to deactivate, which executes the command and revokes the use of the at least one predetermined function and then sends a response (R1) to the external data processing device (40), and wherein, after receiving the response (R1), the external data processing device (40) sends a command (Akt.) to activate the user vehicle (1'), which executes the command and releases the at least one predetermined function.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for activating a control command set in a user vehicle to provide at least one predetermined function. The invention preferably utilizes a system (not separately claimed herein) for transferring the right to use at least one control command set between a first user vehicle and a second user vehicle.

[0002] The aforementioned predetermined function is intended to relate to vehicle interior experiences; it can also additionally relate to vehicle functions for its operation while driving, such as a parking assistant, a lane keeping assistant, cruise control, use of navigation system maps, an infotainment function, and much more.

[0003] Insofar as control command sets are activated here, this refers to a piece of software that issues control commands during its operation (the execution of a program in a processor, etc.). These control commands do not necessarily have to be predetermined, but can depend on incoming sensor data, for example, for the purpose of implementing a control system.

[0004] An activation code is regularly used in connection with activating functions in a motor vehicle.

[0005] The issue of a predetermined function being linked to a right that is to be transferred from one motor vehicle to another is addressed, for example, in DE 10 2016 215 628 A1. Here, personal usage rights are granted for a single vehicle or, for example, within the framework of car sharing, for a group of vehicles. These rights are proven by possession of the electronic vehicle key, which includes a communication module. The electronic vehicle key is not permanently linked to a specific vehicle, and the driver can log in using two-factor authentication upon entry.

[0006] The disadvantage of this is that a user who frequently uses a vehicle has to register each time. Furthermore, the requirement to possess the key and link it to specific vehicles places demands on their control units that are not easily implemented, for example, they are difficult to retrofit.

[0007] It is known from US case 2022 / 0291648A1 that a vehicle user who initially uses a first vehicle and has rights therein can, upon later use of a second vehicle, also use at least some of those rights with the second vehicle. A central data processing facility is used as an intermediary in this process.

[0008] DE 10 2014 224 769 A1 discloses the use of a virtual key, which can be used to activate the opening mechanism for vehicles in a fleet (e.g., in car sharing).

[0009] DE 10 2016 203 715 A1 describes that for agricultural machinery, individual users can have individual functional authorizations that can be transferred from one agricultural machine to another.

[0010] The object of the invention is to improve a method for activating a control command set in a user's motor vehicle to provide at least one predetermined function when several vehicles are to be used alternately, wherein the at least one predetermined function relates to a vehicle interior experience.

[0011] The problem is solved by a method with the features according to claim 1.

[0012] The inventive method for activating a control command set in a user's motor vehicle to provide at least one predetermined function, wherein the at least one predetermined function relates to a vehicle interior experience, comprises: - Authenticating a person who has a right to use the control command set, and upon successful authentication: First - Deactivating the control command set on another motor vehicle and only after successful deactivation, - Activating the control command set on the user vehicle.

[0013] Compared to the procedure according to DE 10 2016 215 628 A1, the advantage is that the electronic vehicle key is unnecessary. In contrast to US 2022 / 0 291 648 A1, there is reliable monitoring to prevent the function from being used twice, as deactivation must first be successfully completed on one vehicle.

[0014] In particular, it is also an advantage of the invention that the transfer of rights from one motor vehicle to another can also take place in the backend, for example via a secure human-machine interface, such as by a fleet operator. The invention provides for the use of an external data processing device, separate from the motor vehicles, where the user can authenticate themselves and through which deactivation and activation are carried out.

[0015] Furthermore, the invention provides that the external data processing device sends a command to the other vehicle to deactivate the function, which executes the command and revokes the use of the at least one predetermined function (in a certain sense, thus temporarily locking the function until later reactivation) and then sends a response to the external data processing device, wherein, after receiving the response, the external data processing device sends a command to activate the user vehicle, which executes the command and releases the at least one predetermined function (and further preferably also sends a response).

[0016] This sequence of data exchange ensures increased security, especially for fleet operators of vehicle fleets.

[0017] According to a preferred embodiment, access to the external data processing device is provided via a personal computer and / or laptop and / or via an application on a smartphone, smartwatch and / or other wearable device and / or tablet computer. Accordingly, the human-machine interface of the external data processing device is provided, for example, via a web interface or via the specific application ("app", "applet").

[0018] According to a preferred embodiment of the invention, the first activation of the control command set for a predetermined user vehicle also results in its transmission to the user vehicle. This can be particularly useful for vehicle interior experiences that are not provided in every vehicle.

[0019] Alternatively, or preferably, if the control command set is reactivated after initial activation and subsequent deactivation, a control set already stored on the user's vehicle can be used. This allows the vehicle manufacturer to pre-configure a large number of functions and make them available to those who pay the associated costs ("on-demand activation").

[0020] The system for transferring the right of use to at least one set of control commands between a first user vehicle and a second user vehicle, which is not specifically claimed here but is preferably used in the invention, comprises: - An external data processing unit with a communication interface for corresponding communication with the communication interfaces of the user vehicles; and - a user data processing facility for accessing the external data processing facility, wherein the external data processing facility is designed, a) to enable the user data processing facility (via input mask or application) to specify a deactivation of the right of use on the user vehicle on which the right of use was previously activated, b) and then send a deactivation command to the respective user vehicle via the communication interface, c) to then receive feedback via the communication interface that the deactivation has taken place, d) to enable the user data processing facility to specify the activation of the right of use on a user vehicle where the right of use had previously been deactivated, e) and then send an activation command to the corresponding user vehicle via the communication interface.

[0021] The system's user data processing unit can be intended, in particular, for the owner of multiple vehicles (i.e., at least the first and second user vehicles). This could be a family member who uses several user vehicles alternately with different people as drivers. It could also be the owner of a vehicle fleet.

[0022] According to a preferred embodiment, the external data processing device is designed to request user authentication before operations a) and c). Either the user's data processing device can enable this authentication (the family member's smartphone in the example above), or the authentication can be performed by the person who is to act as the user at their own personal data processing device.

[0023] In the event that the personal data processing device and the user data processing device coincide, according to a preferred embodiment, the user data processing device can communicate with the external data processing device via a communication interface of a motor vehicle, in particular the first or the second motor vehicle.

[0024] According to a further preferred embodiment, it is provided that in a first database of the external data processing facility, data is stored for a plurality of persons, providing information on the usage rights of these persons to control command sets, wherein it is provided that during a transfer, several and preferably all usage rights of a person are always transferred at once from one user vehicle to another.

[0025] In this case, the fleet operator can naturally also vary the usage rights of individuals in the database.

[0026] The external data processing system can be designed to provide a purchase or rental option for a right to another, not yet activated, set of control commands when a right is activated for a vehicle. This provision can be automated by software or actively decided by the fleet operator, for example, if they wish to recommend or promote an additional right to a specific person, supplementing their existing rights.

[0027] The motor vehicle is preferably designed as a motor vehicle, in particular as a passenger car or truck, or as a passenger bus or motorcycle.

[0028] As a further solution, the invention also includes a computer-readable storage medium comprising instructions that, when executed by a computer or a computer network, cause it to execute an embodiment of the method according to the invention. The storage medium can, for example, be configured at least partially as a non-volatile data storage medium (e.g., as flash memory and / or as an SSD - solid state drive) and / or at least partially as a volatile data storage medium (e.g., as RAM - random access memory). The storage medium can also be operated, for example, as an app store server on the internet. The computer or computer network can provide a processor circuit with at least one microprocessor. The instructions can be provided as binary code or assembly language and / or as source code in a programming language (e.g., C).

[0029] The invention also includes combinations of the features of the described embodiments. The invention therefore also includes realizations that each exhibit a combination of the features of several of the described embodiments, provided that the embodiments have not been described as mutually exclusive.

[0030] The following are exemplary embodiments of the invention with reference to the drawing, wherein: The single figure shows an embodiment of such a system in which an embodiment of the method according to the invention can be implemented.

[0031] The exemplary embodiments described below are preferred embodiments of the invention. In these exemplary embodiments, the described components each represent individual features of the invention, which can be considered independently of one another and each further develops the invention independently. Therefore, the disclosure is intended to include combinations of features of the embodiments other than those shown. Furthermore, the described embodiments can also be supplemented by further features of the invention already described.

[0032] In the figures, identical reference symbols denote functionally equivalent elements.

[0033] In a vehicle 1, there is a central control unit 10 through which vehicle functions can be accessed. Examples include the vehicle parking assistant (actuator 12a), the lane keeping assistant (actuator 12b), and a symbolically shown actuator 12c (possibly representing a plurality of actuators) for providing a vehicle interior experience.

[0034] Motor vehicle 1 has a communication interface 14. A motor vehicle 1' is similarly equipped, and there may be further motor vehicles 2 and 3. Vehicle 1' may have different actuators that provide comparable functions (12a', 12b' and 12c') as well as at least one further actuator 12d' (for example, for providing a navigation system), which may not be present in motor vehicle 1.

[0035] In this case, user 100 initially used vehicle 1 but later wishes to use vehicle 1'. The fleet operator has assigned certain rights to functions to the user. This assignment may have been made based on purchase or rental, or by an employer based on earnings, the content of the employment contract, and the like.

[0036] In addition to the motor vehicle 1 with its vehicle system (comprising the control unit 10 as the central management unit and the communication interface 14 as a transmit / receive unit), the entire system consists of further units such as the so-called frontend system for the user (with the subcomponents "input-human-machine interface", transmit / receive unit and "processing unit") as well as a backend system (with the subcomponents "transmit / receive unit", "processing unit", "documentation unit", "authentication unit" and, if applicable, "security unit") and the shop system, if applicable (with the subcomponents "transmit / receive unit", "management unit", "documentation unit" and a "financial processing unit").

[0037] Each system is tamper-proof and all internal communication is cryptographically encrypted.

[0038] The core of the present procedure is the so-called backend or backend system 40, which can implement the central data processing unit that is located externally to the vehicles 1 and 1' in the system. (In principle, it would also be possible to integrate this unit into a dedicated vehicle. Since it is described as external, this applies at least to vehicles 1 and 1' as well as 2 and 3.)

[0039] The frontend system includes the user data processing unit 20, which, in addition to a central processor 22, has a communication interface 24. The backend system 40 also has a processor 42 and a communication interface 44, which can communicate wirelessly with the communication interfaces 14 of the vehicles 1, 1', possibly via satellite transfer (not shown here), and which can also communicate with the communication interface 24 of the user data processing unit 20, for example via the symbolically shown internet 30. The shop system 50 is also connected to the internet.

[0040] The process encompasses several aspects: - User authentication, - Vehicle function coupling change, - Function upgrade purchase - Implementation of coupling changes.

[0041] A user, such as user 100 or the associated fleet operator, can log in to the external data processing facility (backend system 40) via the user data processing facility 20 (symbolized here by the arrows "Log" for "Login," for example, for logging in via a form or using an application on a smartphone as user data processing facility 20). The external data processing facility 40 requests authentication. The user must enter their credentials via a human-machine interface of the user data processing facility. The prompt for this input is symbolized by the arrows labeled "Auth?". The results of the input are transmitted to the external data processing facility as indicated by the arrows "Auth!".In the processor 22 of the user data processing unit, the input is formally checked and, if formally valid, transmitted via communication interface 24 to communication interface 44. This communication channel is cryptographically secured. For this purpose, the external data processing unit 40 has a memory 48 for cryptographic keys K100, K200, K300 corresponding to the persons 100, 200, 300, where "K" stands for a key.

[0042] The external data processing unit accepts the user authentication and processes it in processor 42. The result is either "User is authenticated" or "User is not authenticated." This section further considers the case where the user has been successfully authenticated. Again, with cryptographic security, optional feedback (not illustrated in the figure) is sent to the user or their user data processing unit 20 confirming that the authentication was successful, after which the result can be displayed to the user.

[0043] In the sub-step "Vehicle-Function-Coupling Change," which is only initiated if the result "User is authenticated," the processor 22 of the user data processing unit 20, acting as a front-end system, decides to retrieve the information about the user's assigned vehicles, functions, and "Vehicle-Function" couplings from the back-end system 40, i.e., the external data processing unit. A database 46 of the back-end system 40, i.e., the external data processing unit, contains, in particular, a number of records relating to persons 100, 200, and 300, each linked to a list of the rights assigned to those persons. These records are labeled 100-R, 200-R, and 300-R in the figure, corresponding to persons 100, 200, and 300, respectively, where "R" stands for "rights."

[0044] The communication interface 44 in the external data processing unit receives the request and forwards it to the processor 42. There, the authentication is checked again for validity. The validity might have already expired after a period defined in the process. In that case, user authentication would have to be performed again.

[0045] Processor 42 reads the vehicles, functions, and vehicle-function pairings assigned to user 100 from database 46 as a "documentation unit" according to data record 100-R. The data package is transferred from database 46 to processor 42 upon request, which then transmits this record to user data processing unit 20 via communication interface 44. Optionally, the data package can now be made available to the authenticated user for viewing. Within the limited validity period of the authentication, the authenticated user can edit the assignment or pairing between vehicle and function as appropriate.

[0046] Depending on the type of function acquisition (inclusive or exclusive modifiability), the user can now edit the assignments according to data set 100-R. The user can dissolve "vehicle-function" pairings and create new pairings between unpaired functions and vehicles. The shop system 50, which will be used later, can also play a role here.

[0047] The human-machine interface 26 now transmits a desired pairing request to the processor 22, which checks the general usability of a function for the vehicle to be paired. This is done via a function portfolio of the vehicle supplied in the data package. If the vehicle is not capable of the function, for example, if the required sensors, actuators and / or control units are not installed, the interface 26 refuses the pairing and indicates this fact appropriately.

[0048] If functions exist in different versions, it is also checked whether this is usable for the vehicle or whether the user can only use the function with the vehicle by upgrading the function. For example, the parking assistant according to actuator 12a' in vehicle 1' can work with more cameras than the parking assistant 12a in vehicle 1. In that case, an upgrade of the function might be necessary.

[0049] Interface 26 offers the authenticated user the option to purchase an upgrade, for which the user is redirected to shop system 50. There, the user can purchase the upgrade. After the transaction is completed, the vehicle, function, and "vehicle-function" coupling assigned to the user are updated in the external data processing unit (backend system 40), and this information is then retrieved again. Suitable forms with simplified displays can be provided in user data processing unit 20 (frontend system).

[0050] The authenticated user actively saves their changes, as this is necessary for the next step to begin.

[0051] By saving, it definitively transfers a new vehicle function coupling to the backend system 40. A data packet is thus generated via interface 26, which is formally checked by processor 22 as the processing unit in the user data processing unit 20 and then transmitted via communication interface 24 of the user data processing unit 20 to communication interface 44 of the external data processing unit (backend system 40). This communication channel is also cryptographically secured.

[0052] Now, either without a purchase or after purchasing an upgrade, the next step, "Implementing the coupling change," can be completed.

[0053] Processor 42 of the external data processing unit now checks the existing data for consistency to prevent possible manipulation. In case of inconsistency, the sub-step is aborted. Processor 42 then determines which change should be made to the vehicle-function couplings. The vehicles involved are checked for reachability for function activation or deactivation (accessibility of the respective communication interfaces 14). If at least one vehicle is currently unreachable, the sub-step is aborted and an error message is sent to user 100. If all required vehicles are reachable, a deactivation is generated for the vehicles for which a vehicle-function coupling is to be removed. This is explained here using vehicle 1 as an example: A command is transmitted via communication interface 44 to communication interface 14 of vehicle 1 (arrow "Deactivate.").After the vehicle function has been deactivated, the vehicle 1 sends a feedback signal according to R1 via the communication interface 14 to the communication interface 44 of the external data processing unit 40. Here too, the deactivation can be secured individually for each vehicle using encryption (K100).

[0054] In vehicle 1, deactivation occurs through the transfer of data from communication interface 14 to the central control unit 10, which interprets the data packet and performs the necessary tasks to change the authorizations. The response is then generated.

[0055] If processor 42 receives feedback R1 from vehicle 1 (and, if applicable, other vehicles), meaning the function has been successfully deactivated, then processor 42 generates an activation for the vehicles to which a vehicle-function coupling is to be added. This activation is again encrypted. This is symbolized in the figure by the message "Akt." for "Activate" transmitted from communication interface 44 of the external data processing unit (backend system 40) to communication interface 14 of vehicle 1'. Here, too, the data is forwarded from communication interface 14 to the central control unit 10, which processes the data packet and, in particular, activates the authorization of functions. In the example case, the purchased function can be activated for actuator 12a', and, if the functions are identical, for actuators 12b' and 12c'.

[0056] It may also be optional that a function has been purchased that activates the navigation system with the actuator 12d'.

[0057] The control unit 10 of the motor vehicle 1' transmits, via the communication interface 14, the feedback R2 to the external data processing unit 40 that the function is now activated.

[0058] Once all deactivations and activations have been completed, database 46 is updated. For example, data 100-R will record that the rights to the functions are linked to vehicle 1, and no longer to vehicle 1 as before. (Naturally, a history may also be stored, until deletion after a predetermined time or after predetermined events such as billing, etc.)

[0059] A success message is then transmitted to the user data processing facility 20, where the change in the coupling is thus known; a message including a timestamp of the last activation is then sent to the interface 26 of the authenticated user and displayed there.

[0060] Interface 26 does not allow any further changes between saving a coupling change and the success message of the implemented coupling change, or at least does not allow saving.

[0061] The invention provides fleet operators in particular with a way to equip part of their fleet with customer-experienced functions or functional enhancements and to exchange these vehicles. A fleet operator can thus offer their customers an equivalent replacement vehicle, for example, during service maintenance or similar periods.

[0062] Overall, the examples show how a procedure for transferring usage rights for customer-experienced functions between two or more vehicles can be provided.

Claims

[1] Method for activating a control command set in a user vehicle to provide at least one predetermined function, wherein the at least one predetermined function relates to a vehicle interior experience and the method comprises: - Authenticating a person (100; 200, 300) who has a right to use the control command set, and upon successful authentication: first - Deactivating the control command set on another motor vehicle (1) and only if deactivation is successful, then - Activation of the control command set on the user vehicle (1'), wherein an external data processing device (40) is used, which the person (100, 200; 300) can use to authenticate themselves, and via which deactivation and activation take place, wherein the external data processing device (40) sends a command (Deakt.) to the other vehicle (1) to deactivate, which executes the command and revokes the use of the at least one predetermined function and then sends a response (R1) to the external data processing device (40), and wherein, after receiving the response (R1), the external data processing device (40) sends a command (Akt.) to activate the user vehicle (1'), which executes the command and releases the at least one predetermined function. [2] Method according to claim 1, wherein access to the external data processing device (40) is via a personal computer and / or a laptop computer and / or via an application on a smartphone, on a smartwatch and / or on another wearable and / or on a tablet computer. [3] Method according to claim 1 or 2, wherein the control command set for a specific user vehicle is first activated and is also transmitted to the user vehicle.

Citation Information

Patent Citations

  • METHOD AND DEVICE FOR DELIVERY OF A VIRTUAL KEY

    DE102014224769A1

  • Arrangement for checking the functions of a working machine

    DE102016203715A1