Control of a motor vehicle
By detecting and blocking unauthorized digital vehicle keys and using a key management system to synchronize counters, the security of motor vehicles is enhanced by preventing unauthorized keys from controlling safety functions.
Patent Information
- Application Number
- DE102024112710
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-06
- Publication Date
- 2025-11-06
AI Technical Summary
The process of creating or adding a newly created digital vehicle key represents a potential attack vector on the security concept of motor vehicles, necessitating improved techniques to secure the vehicle against unauthorized digital keys.
Implementing a method to detect and block the addition of newly created digital vehicle keys by requiring authorization from an existing and authorized digital vehicle key, establishing locks to prevent validation or storage on the vehicle, and using a key management system to manage and synchronize counters to ensure only authorized keys can be used for safety functions.
Prevents unauthorized digital vehicle keys from being added to the vehicle's key inventory, enhancing security by ensuring only authorized keys can control safety functions, thus fortifying the vehicle's security system.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The present invention relates to the control of a motor vehicle by means of a digital vehicle key. In particular, the invention relates to the addition of a newly created digital vehicle key.
[0002] A motor vehicle includes a control unit configured to operate a predetermined security function of the vehicle based on a digital vehicle key. A digital vehicle key, which is assigned authorization to control a security function, is stored in the control unit. This security function may include, in particular, central locking or an immobilizer. Another part of the digital vehicle key may be stored on a user's device. The user can wirelessly present their digital vehicle key to the vehicle to control the security function.
[0003] A new vehicle key can be added to the system by first creating it and digitally signing it using a certified vehicle key. The new vehicle key is then submitted to a key management system, which signs it and stores it with the vehicle. The new vehicle key can now be presented at the vehicle to control a security function.
[0004] The process of creating or adding a newly generated digital vehicle key represents a potential attack vector against the security concept. One of the problems underlying the present invention is therefore to provide an improved technology for securing a motor vehicle by means of a digital vehicle key. The invention solves this problem by means of the subject matter of the independent claims. Dependent claims describe preferred embodiments.
[0005] According to a first aspect of the present invention, a method for controlling a motor vehicle comprises steps of detecting a request to block the addition of a newly created digital vehicle key that can be used to control the motor vehicle; determining that the request is based on an existing and authorized digital vehicle key; and establishing a block that prevents a newly created digital vehicle key from being validated or stored on the motor vehicle.
[0006] The digital vehicle key can be designed, in particular, according to the proposals of the Car Connectivity Consortium. A technical specification of the underlying technology has been published. The invention aims to selectively ensure that no new digital vehicle key can be created or activated within a set of vehicle keys that can be used to control a security function of the motor vehicle. This prevention is achieved by implementing the block.
[0007] The control of the motor vehicle and communication with a device on which a user's digital vehicle key is stored are typically carried out by a control unit on board the vehicle. For simplicity, it is also referred to here as such functions being implemented by the vehicle itself. Controlling the motor vehicle based on a digital vehicle key typically includes controlling a predetermined security function, in particular unlocking a central locking system, disabling an immobilizer, or starting a drive engine.
[0008] By opting out of the process for adding new digital vehicle keys, the vehicle can immediately prevent a new digital vehicle key from being added to an existing set of keys. A vehicle key not registered with the vehicle cannot be used to control a security function. Registration can be done in various ways and includes transmitting an attestation package from the key management system to the vehicle.
[0009] A block can be implemented in various ways, and multiple blocks can be established. Optionally, several blocks can also be combined. In one embodiment, a device storing an existing digital vehicle key, which can be used to sign a newly created vehicle key—or a creation request—can be configured to prevent it from providing such a signature. If multiple such vehicle keys or devices are involved, implementing blocks for all of them can be challenging; however, such a block can be implemented as an additional security measure.
[0010] In another embodiment, a block is implemented on the vehicle side. This block prevents a newly created digital vehicle key from being stored on the vehicle. Storage typically involves the transmission of an attestation package regarding the newly created vehicle key from the key management system. If the vehicle does not receive the attestation package or refuses to process its contents, the cryptographic data of the newly created vehicle key is not stored on the vehicle, and the new key cannot be used to control the vehicle.
[0011] In yet another embodiment, a block is implemented by the key management system. This block prevents the key management system from signing a newly created digital vehicle key. By denying the digital cryptographic signature, a valid attestation package cannot be created.
[0012] In yet another embodiment, the blocking mechanism prevents the key management system from providing an attestation package for a newly created digital vehicle key. The attestation package cannot be created in the first place, nor can a created attestation package be transmitted to the vehicle. Without transmitting the attestation package to the vehicle, a newly created digital vehicle key cannot be used there.
[0013] A digital vehicle key authorized to immobilize a vehicle can be assigned to a predetermined person. This person is also referred to herein as the owner, in accordance with the CCC Technical Specification, although another person or, in some cases, a technical device may assume this role. Accordingly, a person for whom the new digital vehicle key is created can be referred to as a friend.
[0014] A person's digital vehicle key is typically stored on a device. This device preferably comprises a mobile device, but in other embodiments can also include, for example, a smartwatch, a smartband, a wearable device, or a head-mounted device. More preferably, the key is stored in secure memory within the device, and the device can be configured to require authentication of the person in order to access the secure memory. For this purpose, the person can present a biometric feature or enter a predetermined secret. In this way, the person, the device, and the key can be cryptographically linked.
[0015] It is further preferred that at least one digital vehicle key exists for controlling the vehicle, which can later be used to remove the lock. If such a digital vehicle key does not exist, the creation of a lock may be refused. The digital vehicle key for removing the lock should be stored with the vehicle. Generally, all digital vehicle keys in a set of valid vehicle keys are stored with the vehicle. It should be noted that not every digital vehicle key stored with the vehicle necessarily has the authorization to remove the lock.
[0016] A lock can be removed using another existing vehicle key. A vehicle key that can set a lock can be different from one that can remove a lock. The vehicle keys can be assigned to different people and / or different devices.
[0017] A request to immobilize a vehicle can originate from various parties. In one scenario, the request is generated in response to direct interaction with the vehicle. This can be achieved by a person activating a corresponding control element on board the vehicle. Alternatively, a digital vehicle key, which serves as the basis for the request, can be located near the vehicle. The vehicle key can be wirelessly verified by the vehicle. In this scenario, the immobilizer can be activated immediately.
[0018] Optionally, a request to implement a lock is transmitted from the vehicle to the key management system, instructing it to initiate the signature of a newly created key or the provision of an attestation package for the vehicle. However, a transmission path from the vehicle to the key management system might be temporarily unavailable, so the lock request to the key management system may be delayed.
[0019] In a second variant, the request is generated in response to an input on a device where the authorized digital vehicle key is stored. This device is typically a mobile device that can be assigned to a specific person, particularly the vehicle owner. In this variant, the mobile device can also be located remotely from the vehicle. The request can be sent directly to the key management system, which can then confirm that the lock has been activated. A request to activate the lock from the vehicle can be sent either from the device or from the key management system to the vehicle.
[0020] In a third variant, a central authority is provided from which the request originates. This central authority could, for example, be operated by the vehicle manufacturer. Thus, for instance, an owner who can prove their legal status regarding the vehicle can implement a locking mechanism. The central authority can then send a request to the key management system and / or the vehicle itself to implement the locking mechanism. In one embodiment, the central authority is integrated with the key management system.
[0021] Preferably, the vehicle is controlled in such a way as to not accept a digital vehicle key that was generated after a lock was applied and before the lock was removed. This prevents a digital key generated while the vehicle was locked from automatically becoming valid when the lock is removed.
[0022] In a particularly preferred embodiment, the key management system and the vehicle each maintain a counter. The counter can operate in any unit and is configured to only increment the counter value and never decrement it. The counter is incremented, in particular, when a lock is applied and optionally when the lock is released. The key management system preferably assigns the current counter value of its counter to a vehicle key being deposited. The vehicle can refuse to deposit a vehicle key whose assigned counter value is lower than the current counter value of the vehicle.
[0023] This allows for consideration of the possibility that the creation or removal of a lock on the key management system may be delayed compared to the creation or removal of a lock on the vehicle itself. Preferably, the key management system's counter is synchronized with the vehicle's counter when a lock is removed.
[0024] It remains preferred that resetting the vehicle to factory settings removes any set lock. This involves completely resetting the vehicle to a state similar to its original delivery condition. Various security measures, user settings, learned values, or collected data can each be reset to predetermined values. This process does not involve creating a new digital vehicle key, but it does allow for the creation of a new key.
[0025] According to a further aspect of the present invention, a mobile device for controlling a motor vehicle comprises a user interface for inputting a request to block the addition of a newly created digital vehicle key that can be used to control the motor vehicle; a communication device for communicating with a key management system or the motor vehicle; a secure memory in which an existing digital vehicle key for the motor vehicle is stored; and a processing device. The processing device is configured to receive an input and, in response to the input, to send a request to the key management system and / or the motor vehicle, based on the vehicle key, to establish a block, thus preventing a newly created digital vehicle key from being validated or stored on the motor vehicle.
[0026] Additionally, the processing unit can send a request to the key manager to request the establishment of an additional lock. Furthermore, a local lock can be established to prevent the mobile device from signing a newly generated key.
[0027] According to a further aspect of the present invention, a device for controlling a motor vehicle comprises a user interface for inputting a request to block the addition of a newly created digital vehicle key that can be used to control the motor vehicle; an interface for communication with a mobile device on which an existing digital vehicle key for the motor vehicle is stored; and a processing unit. The processing unit is configured to check the digital vehicle key and to prevent a newly created digital vehicle key from being stored on the motor vehicle. The device is located on board the motor vehicle and is preferably permanently attached to it.
[0028] Optionally, the device can also transmit a request to the key management system to establish a lock. If transmission is temporarily impossible, it can also occur later, for example, when a communication link with the key management system can be re-established.
[0029] According to yet another aspect of the present invention, a motor vehicle comprises a control device described herein. The motor vehicle preferably comprises a motorcycle or a passenger car; in further embodiments, the motor vehicle may also, for example, comprise a truck or a bus.
[0030] According to yet another aspect of the present invention, a key management system for a digital vehicle key for a motor vehicle is configured to receive a request to block the addition of a newly created digital vehicle key that can be used to control the motor vehicle; and to refuse to sign or deposit a newly created vehicle key with the motor vehicle.
[0031] A method described herein can be implemented, in whole or in part, by devices described herein, in particular a mobile device, a motor vehicle or a control device comprising it, and / or a key management system. For this purpose, a device can include a processing unit, preferably of electronic design, which may include, for example, an integrated circuit, a programmable logic device, or a programmable microcomputer. The method can be implemented in the form of a configuration or as a computer program product with program code means for the processing unit. The configuration or the computer program product can be stored on a computer-readable data carrier. Features or advantages of the method can be transferred to the device or vice versa.
[0032] According to yet another aspect of the present invention, a system comprises a key management system described herein and at least one motor vehicle described herein.
[0033] The invention will now be described in more detail with reference to the attached drawings, in which: Fig. 1 a system; Fig. 2. A flowchart of a process Fig. 3 a flowchart of another procedure; and Fig. 4. A flowchart of yet another procedure is illustrated.
[0034] Fig. Figure 1 shows a system 100 with a motor vehicle 105 and a key management system 110. The motor vehicle 105 includes a control device 115 configured to control a predetermined function of the motor vehicle 105, in particular a security function, based on a digital vehicle key. The security function may, for example, include unlocking a vehicle door or hatch of the motor vehicle 105, deactivating an immobilizer, or activating a drive motor.
[0035] The concept of the digital vehicle key presented here preferably follows the proposals of the Car Connectivity Consortium (CCC). In simplified terms, a specific digital vehicle key is assigned to a first person 120 and is typically stored on a first mobile device 125, which is also assigned to that first person 120. The digital vehicle key is additionally stored on the control unit 115 in the motor vehicle 105. Controlling a security function of the motor vehicle 105 requires cryptographic communication between the control unit 115 and the mobile device 125. Preferably, an asymmetric cryptographic method is used to authenticate one of the communication partners. The digital vehicle key can comprise a private part, which is stored on the mobile device 125, and a public part, which is stored on the control unit 115.
[0036] Conversely, the first mobile device 125 may possess a public key of the control device 115, whose corresponding private key is known only to the control device 115. Mutual authentication between the first mobile device 125 and the control device 115 can be performed in a so-called standard transaction. To make their digital key accessible on the first mobile device 125, the person 120 can first authenticate themselves to the first mobile device 125, for example, by presenting a biometric feature or by entering a predetermined secret.
[0037] A new digital vehicle key can be created and assigned to a second person 130, who is assigned a second mobile device 135 for this purpose. For example, it is assumed that the first person 120 is the owner of the vehicle 105 and that the digital vehicle key assigned to them authorizes them to issue or sign a newly created vehicle key. The second person 120 is usually referred to as a friend.
[0038] The generation process can include the key management system 110 digitally signing a newly created digital vehicle key and creating an attestation package that includes the signed key, and storing this attestation package with the motor vehicle 105 or the control device 115.
[0039] It is proposed to selectively prevent or re-enable the addition of a newly created digital vehicle key to a pool of valid digital vehicle keys that can be used to control the motor vehicle 105. It is particularly preferred that a lock be implemented or removed to prevent the addition of a newly created vehicle key by the motor vehicle 105 or the control device 115 and / or also by the key management system 110.
[0040] Optionally, a device 140 can be provided through which a request to the key management system 110 for the creation of a lock can be submitted directly. Device 140 can be equipped with its own digital vehicle key, which can be used to generate the request. Access to device 140 can be restricted in any way. For example, a person 120 or 130 who wishes to set or remove a lock can explain their legal position that authorizes them to do so. Their request can then be reviewed by another person or automatically by device 140.
[0041] Fig. Figure 2 shows a flowchart of a procedure 200 for exiting or participating in a key creation process for a motor vehicle 105. Exiting corresponds to erecting at least one lock; and participating to removing all locks.
[0042] In step 205, it is assumed that the motor vehicle 105 is in an initial state with regard to its control by means of a digital vehicle key. This state can be reached when the motor vehicle 105 is handed over by the manufacturer to its first owner.
[0043] In step 210, an owner key can be generated. This is a digital vehicle key, which is typically assigned the authorization to create or sign a newly created vehicle key. In other words, the first person 120, as the owner, can use their assigned vehicle key to create or cryptographically sign further digital vehicle keys.
[0044] In step 215, additional keys can be generated if necessary, for example, for the second person 130. If the number of digital vehicle keys that can be used to control the motor vehicle 105 meets the requirements of the first person 120, they can request to stop adding new vehicle keys. To do this, the first person 120 can send a corresponding message to the control device 115 using their first mobile device 125 and the digital vehicle key stored on it.
[0045] In step 225, the control device 115 can check whether a received request grants authorization to exit the vehicle. Specifically, it can verify whether this authorization is assigned to the digital vehicle key on which the request was based. Authorizations for a digital vehicle key are generally defined before the vehicle key is generated or cryptographically signed.
[0046] In step 230, it can be checked whether at least one digital vehicle key is present in the inventory of valid digital vehicle keys for vehicle 105, which can be used as a basis for controlling later participation in adding a newly created digital vehicle key. In other words, before a block is placed against adding a newly created digital vehicle key for vehicle 105, it can be checked whether predetermined conditions are met in order to later remove the block.
[0047] In step 235, a corresponding lock can be installed on the motor vehicle 105 or on the control device 115. This lock can, in particular, prevent the acceptance of an attestation package for a newly created digital vehicle key for the motor vehicle 105 or the storage of the digital vehicle key contained therein.
[0048] In step 240, a message can be transmitted from vehicle 105 to the key management system to instruct it to also implement a block against adding a digital vehicle key to vehicle 105. This block can prevent a key signing request or a key tracking request for vehicle 105 from being fulfilled.
[0049] Furthermore, it can be prevented that an information package regarding a newly created digital vehicle key is transmitted to the motor vehicle 105 or the control device 115.
[0050] Adding a newly created digital vehicle key to the inventory of valid vehicle keys for vehicle 105 is already prevented if only one of the locks is active. Existing digital vehicle keys in the inventory can still be used. Optionally, a digital vehicle key in the inventory can also be invalidated while one of the locks is active. In this case, priority is given to ensuring that at least one digital vehicle key remains in the inventory that can be used to remove the lock.
[0051] An existing lock on the vehicle (105) and / or the key management system (110) can remain in place indefinitely. An option is available to remove a lock. This can be done, in particular, using a digital vehicle key to which appropriate authorization can be assigned.
[0052] Fig. Figure 3 shows a flowchart of a procedure 300 for establishing a block against the addition of a newly created vehicle key for the motor vehicle 105. At the beginning of the procedure 300, all participants 105, 110, 120, 125, 135 can be informed that a new digital vehicle key can be created and made functional for controlling the motor vehicle 105.
[0053] In step 205, a person 120 can request the establishment of a lock via device 140. To do this, person 120 can identify and / or authenticate themselves to device 140. If the request is successfully processed, a request to establish a lock can be transmitted to the key management system 110 in step 310. These steps correspond to a third variant of establishing a lock described herein.
[0054] In step 315, person 120 can enter information on a mobile device 125 to initiate a lock. In step 320, person 120 can authenticate themselves. Optionally, they can reconfirm their entry to prevent unintentional locking. In step 325, a request to establish a lock can be generated based on a digital vehicle key stored on person 110's mobile device 125. In step 330, the request can be transmitted to the key management system 110. In step 335, the key management system 110 can establish the lock. These steps correspond to a second variant of establishing a lock described herein.
[0055] Following step 310 or step 335, the key management system 110 can verify the request based on the digital vehicle key used for its creation. If the verification is successful, a request to establish a lock can be transmitted to the vehicle 105 in step 340, which can then establish the lock in step 345.
[0056] Optionally, in step 350, a notification of a set block can be sent from the key management system 110 to the mobile device 125 of person 110. In step 355, the mobile device 110 can adjust its user interface for person 110 so that the set block is visible or the option to set a block is no longer offered. Furthermore, in step 330, sharing an existing key with another person 130 can be prevented.
[0057] Similarly, optionally in step 365, a notification of the set block can be transmitted from the key management system 110 to a mobile device 135. The mobile device 135 is assigned to a person 130 who is not the owner of the vehicle 105 or whose digital vehicle key does not have the authorization to sign a newly created vehicle key. In step 370, sharing an existing vehicle key by person 130 can be prevented.
[0058] At the end of procedure 300, all participants 105, 110, 120, 125, 135 can be informed that no new digital vehicle key can be created for the motor vehicle 105.
[0059] Fig. Figure 4 shows a flowchart of a further method 400, which can implement a first variant for setting a lock as described herein. In one embodiment, a counter is provided for both the motor vehicle 105 and the key management system 110, the reading of which can be increased when a lock is set. At the beginning of the method, it is assumed that the counter readings of the motor vehicle 105 and the key management system 110 are equal.
[0060] In step 405, person 120 makes an entry at vehicle 105 to establish a lock. In step 410, vehicle 105 checks for the presence of a mobile device 125 within its range and determines that a digital vehicle key stored on it is authorized to set a lock. In step 420, the lock is established. A meter reading on vehicle 105 can be incremented in step 420. This causes the meters of vehicle 105 and the key management system 110 to become unsynchronized. In step 425, the vehicle can transmit a lock activation request to the key management system 110.
[0061] The following steps 430 to 450 are optional and correspond to steps 350 to 370, which are described above with reference to Fig. 3 are described.
[0062] In step 455, the key management system 110 can increase the reading of its own counter. In one embodiment, the vehicle 105 transmits its counter reading in step 425, and the key management system 110 increases its own counter reading to this value. Confirmation of the applied lock, optionally including the current counter reading of the key management system 110, can be transmitted to the vehicle 105 in step 455. In step 460, the vehicle 105 can compare its counter reading with that of the key management system 110 and, if necessary, reconcile them. The counters of the vehicle 105 and the key management system 110 are synchronized. Reference sign 100 System 105 motor vehicles 110 Key Management 115 Control device 120 first person (owner) 125 first mobile device 130 second person (friend) 135 second mobile device 140 Device 200 procedures 205 new motor vehicles 210 Generate owner keys 215. Possibly generate another key. 220 Record exit request 225 Request justified? 230 vehicle keys exist for participation? 235 vehicles blocked Lock 240 key management 245 Record participation request, check eligibility Release 250 vehicles Release 255 key management 260 Synchronize 300 procedures 305 Create a request for a lock 310 Request to set up a lock (proprietary message) 315 Input: Set lock 320 Confirmation and authentication of the person 325 Generate a request to establish a barrier 330 Submit request 335 Check request 340 Submit request to set a block Set 345 block 350 Send notification of set block 355 Deactivate the control for setting a lock 360 key sharing not possible 365 Send notification of set block Sharing 370 keys is not possible. 400 procedures 405 Input: Set lock 410 Check the presence and authorization of a digital key 415 Erect barrier 420 Increase meter reading, meter unsynchronized 425 Submit request 430 Send notification of set block 435 Deactivate control for setting a lock Sharing 440 keys is not possible. 445 Send notification of set block Sharing 450 keys is not possible. 455 Increase meter reading, submit confirmation of imposed blockage 460 vehicles locked, counter synchronized
Claims
[1] Method (200) for steering a motor vehicle (105), wherein the method (200) comprises the following steps: - Capture (220) a request to lock an added new digital vehicle key that can be used to control the motor vehicle (105); - Determine (245) that the request is based on an existing and authorized digital vehicle key; and - Establishing (235, 245) a lock that prevents a newly created digital vehicle key from being validated or stored on the motor vehicle (105). [2] Method (200) according to claim 1, wherein the lock comprises preventing the deposit of a newly created digital vehicle key on the motor vehicle (105). [3] Method (200) according to claim 1 or 2, wherein the lock comprises preventing a key management system (110) from signing a newly created digital vehicle key. [4] Method (200) according to claim 2, wherein the block comprises preventing a key management system (110) from providing an attestation package for a newly created digital vehicle key. [5] Method (200) according to one of the preceding claims, wherein it is determined that at least one digital vehicle key exists for controlling the motor vehicle (105) with which the lock can be lifted (250, 255). [6] Method (200) according to one of the preceding claims, wherein the requirement is created in response to a direct interaction with the motor vehicle (105). [7] Method (200) according to any of the preceding claims, wherein the request is created in response to an input on a device on which the authorized digital vehicle key is stored. [8] Method (200) according to any of the preceding claims, wherein the request is provided by a central body. [9] Method (200) according to one of the preceding claims, wherein the motor vehicle (105) is controlled, not to accept a digital vehicle key which was generated after the locking on the motor vehicle (105) was established (235, 240) and before the locking was removed. [10] Method (200, 300) according to claim 9, wherein the key management system (110) and the motor vehicle (105) each maintain a counter which is incremented when an associated lock is established; wherein the key management system (110) assigns a current counter reading of its counter to a vehicle key to be deposited; wherein the motor vehicle (105) refuses to deposit a vehicle key whose assigned counter reading is less than the current counter reading of the motor vehicle (105). [11] Mobile device (125) for controlling a motor vehicle (105), wherein the mobile device (125) comprises the following elements: - a user interface for entering a request to lock an added newly created digital vehicle key that can be used to control the motor vehicle (105); - a communication device for communication with a key management system (110) or the motor vehicle (105); - a secure storage device in which an existing digital vehicle key for the motor vehicle (105) is stored; - a processing unit configured to receive an input; and in response to the input, to provide a request to the key management system (110) and / or the motor vehicle (105) to establish a lock based on the vehicle key, in order to prevent a newly created digital vehicle key from being validated or stored on the motor vehicle (105). [12] Device (115) for controlling a motor vehicle (105), wherein the device (115) comprises the following elements: - a user interface for entering a request to lock an added newly created digital vehicle key that can be used to control the motor vehicle (105); - an interface for communication with a mobile device on which an existing digital vehicle key for the motor vehicle (105) is stored; - a processing unit designed to check the digital vehicle key; and to prevent a newly created digital vehicle key from being stored on the motor vehicle (105). [13] Motor vehicle (105) comprising a device (125) according to claim 12. [14] Key management (110) for a digital vehicle key for a motor vehicle (105), wherein the key management (110) is configured to receive a request to block the addition of a newly created digital vehicle key that can be used to control the motor vehicle (105); and to refuse to sign or deposit a newly created vehicle key with the motor vehicle (105). [15] System (100) comprising a key management system (110) according to claim 14 and at least one motor vehicle (105) according to claim 13.
Citation Information
Patent Citations
Method for digital key misbehavior and sybil attack detection through user profiling
US20210104107A1