Method for authenticating a user, control device, motor vehicle, control unit and electronic device

The UWB-based dual-factor authentication method addresses the reliability and cost issues of existing vehicle authentication systems by using distance and field strength measurements to securely verify user proximity and identity, enhancing security and usability.

DE102024201006A1Pending Publication Date: 2025-08-07VOLKSWAGEN AG
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
DE102024201006
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-05
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

Existing vehicle authentication systems face challenges in reliably authenticating the source of wireless signals due to susceptibility to relay station attacks, leading to increased installation costs and reduced ease of operation.

Method used

A method using UWB antennas for determining distances between electronic devices and the vehicle, combined with field strength measurements, provides a two-factor authentication system that minimizes interference with other signals and reduces the risk of relay attacks.

Benefits of technology

The method ensures secure, cost-effective, and user-friendly dual-factor authentication by passively verifying the proximity and identity of the user, preventing unauthorized access without requiring additional user actions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a method of an electronic device (14, 16) for authenticating a user (12), a method of a motor vehicle (10) for authenticating a user, a control device (20) for operating a motor vehicle (10), a motor vehicle (10) comprising the control device (20), a control unit for operating an electronic device (14, 16) and an electronic device (14, 16) comprising the control unit. It is provided that passive authentication of the user (12) takes place based on two-factor authentication. The first factor relates to a determined first distance (d1) between the motor vehicle (10) and a first electronic device (14, 16) of the user (12). For the second factor, a second distance (d2) between the first electronic device (14, 16) and a second electronic device (16, 14) of the user (12) is determined by a positioning method based on time-of-flight measurements of radio signals. The authentication of the user (12) by the motor vehicle (10) then takes place on the basis of the determined first and second distances (d1, d2) and associated authentication information.
Need to check novelty before this filing date? Find Prior Art

Description

The invention relates to a method of an electronic device for authenticating a user, to a method of a motor vehicle for authenticating a user, to a control device for operating a motor vehicle, to a motor vehicle comprising the control device, to a control unit for operating an electronic device, and to an electronic device comprising the control unit.Modern vehicles include a variety of electronic systems that are directed to wireless interaction of the user with the vehicle. For example, solutions are known that allow keyless access to a vehicle. By wireless communication between a wireless interface located in the vehicle and, for example, a mobile terminal of the user, the user can lock or unlock the central lock of the vehicle by input into the mobile terminal. In order to determine whether the user is authorized to access the access system of the vehicle, authentication of the user by an electronic system of the vehicle is required.A common problem here is that the systems used cannot reliably authenticate the source of the received radio signal, namely whether the received radio signal actually originates from the user or originates from a source which has obtained the information of the radio signal by means of quantitative energy. In order to meet such security problems, modern systems query position and movement data of the portable device in order to locate the user in this way and authenticate the user on the basis of the location information.Thus, document WO 2014 / 052059 A1 describes a solution that provides multi-factor authentication. Here, a first approach status of a first mobile device with respect to a vehicle and a second approach status of a second mobile device with respect to the vehicle are determined by NFC (Near Field Communications) technology, RFID (Radio Frequency Identifier) technology or infrared (IR) technology. Accessibility of one or more functions of the vehicle is then enabled based on the first distance status and the second distance status.The problem with the known solutions is that the wireless interfaces are necessary for detecting authorized access by a user at the operating point of the vehicle, i.e. in a vehicle door or flap, whereby the installation outlay and the costs of the vehicle are increased. It is sometimes necessary for the user to guide the two mobile terminals to provided control stations of the vehicle for two-factor authentication, as a result of which the ease of operation suffers.The invention is therefore based on the object of providing methods and devices for authenticating a user of a motor vehicle, which enable cost-effective and easily operable dual-factor authentication.The object according to the invention is achieved by a method of an electronic device for authenticating a user, a method of a motor vehicle for authenticating a user, a control device for operating a motor vehicle, a motor vehicle comprising the control device, a control unit for operating an electronic device and an electronic device comprising the control unit according to the independent patent claims. Preferred refinements are the subject matter of the respective dependent claims which refer back.A first aspect relates to a method of an electronic device for authenticating a user. The method is suitable in particular for wirelessly authenticating a user of a motor vehicle using two electronic devices.The motor vehicle, in particular a passenger car with an internal combustion, electric or hybrid engine, comprises a vehicle communication unit configured to exchange radio signals with the two electronic devices. In other words, the driving communication unit of the motor vehicle comprises one or a plurality of antennas, preferably UWB antennas, configured to transmit and receive radio signals, preferably UWB radio signals. The driving communication unit of the motor vehicle preferably further comprises a long-wave (LF) antenna, an ultra-high-frequency (UHF) antenna, Bluetooth (BT) antenna, in particular a Bluetooth Low Energy (BLE) antenna, a local area network (WLAN) antenna and / or a near field communication (NFC) antenna or a plurality thereof. As a result, LF, UHF, BT, WLAN and / or NFC radio communication can be established with the electronic devices. The additionally possible radio communications make it possible to use a multiplicity of different electronic devices. In other words, the design margin of the usable electronic devices can be increased. The frequency bands and standards used for LF, UHF BT, WLAN and NFC radio communications are well known in the art and will therefore not be discussed in greater detail here.The first and / or the second electronic device is preferably a mobile terminal. Examples are electronic identification transmitters (ID transmitters), for example a battery-operated vehicle radio key, or digital vehicle device keys (mobile device keys), which are stored on mobile terminals, such as smartphones, in order to enable operation of the motor vehicle via the (respective) mobile terminal. In other words, the two electronic devices are preferably each ID transmitter, each mobile device key or an ID transmitter and a mobile device key. The two communication units of the electronic devices are designed in particular for transmitting and receiving signals in very large frequency ranges, in particular in a frequency range from 3.1 GHz to 10.6 GHz, preferably in a frequency range from 3.5 GHz to 9 GHz, particularly preferably in a frequency range from 6 GHz to 8.5 GHz, using the antennas, preferably the UWB antennas. The transmission power of the UWB pulses is low in this case. The bandwidth of the UWB signal is at least 500 MHz, and the UWB transceiver is preferably designed for transmitting signals with a transmission power of between 0.5 mW / -41.3 dBm / MHz. Furthermore, the communication units are preferably designed according to the IEEE 802.15.4 standard (in particular the sections relating to the UWB PHY layer) and preferably according to the IEEE 802.15.4z standard. Owing to the dispersion of the signals over such large frequency ranges, UWB signals interfere with other radio signals only minimally.In a method step of the electronic device, a first distance between a first electronic device and a second electronic device is determined using a positioning method based on runtime measurements using the communication unit. In other words, the communication unit of the first electronic device is controlled to perform a positioning method based on runtime measurements with the communication unit of the second electronic device to determine a first distance between the two electronic devices. In yet other words, the actuation of the communication unit of the first electronic device comprises at least the steps according to which the antenna of the communication unit of the first electronic device is actuated for transmitting a first pulse to the communication unit of the second electronic device at a time t 1 and for receiving a second pulse from the communication unit of the second electronic device at a time t 2 a total transit time is determined on the basis of the transit times of the first pulse, of the second pulse and a processing time of the communication unit of the second electronic device ΔT and a distance between the communication unit of the first electronic device and the communication unit of the second electronic device is determined on the basis of the total transit time and the speed of light. In this way, a distance measurement can preferably be carried out within a radius of up to 10 m of the communication unit of the first electronic device. Positioning methods based on runtime measurements have the advantage over conventional positioning methods based on field strength measurements that are less susceptible to relay station attacks (RSA) on wireless operations of motor vehicle functions, such as keyless vehicle access systems, in which an attacker positions one or more radio amplifiers between the motor vehicle and the electronic device and thereby increases the transmission power of the radio signals emitted by the electronic device and detected by the vehicle. On the basis of the conventional field strength measurement, the vehicle thus incorrectly locates the key at a position closer than its real position and enables opening. RSA attacks thus make it possible to operate the functions of the motor vehicle of a user even if the latter is located outside the normal range of wireless operation of the motor vehicle function, for example in a coffee shop or his home.In a further step of the method of the electronic device, a second distance between the first electronic device and the motor vehicle is determined using a first radio signal exchanged with the motor vehicle. The second distance is preferably determined on the basis of a field strength measurement, for example an RSSI indicator (Received Signal Strength Indication), of the first radio signal. The second distance is preferably determined on the vehicle side. In other words, the vehicle communication unit receives the first radio signal of the first electronic device and determines the second distance from the signal strength of the received first radio signal. However, this does not exclude the possibility that the vehicle communication unit transmits the first radio signal and the first electronic device analogously determines the second distance and transmits it to the vehicle communication unit of the motor vehicle via a further radio signal comprising the determined second distance.Furthermore, a second radio signal for authorisation of the user is transmitted from the first electronic device to the motor vehicle. The second radio signal comprises the determined first distance and the authentication information. In other words, the motor vehicle now has at least the information about the first distance between the two electronic devices, about the second distance between the first electronic device and the motor vehicle and corresponding authentication information from the first electronic device. The motor vehicle preferably acquires the mentioned information only by the radio communication with the first electronic device. In some embodiments, the first radio signal and the second radio signal can represent a radio signal, for example by basing the signal strength of the transmitted second radio signal on the motor vehicle for ascertaining the second distance.A further aspect relates to a method of a motor vehicle for authenticating a user.In a method step of the method of the motor vehicle, a second distance between a first electronic device of the user and the motor vehicle is determined using a first radio signal exchanged with the first electronic device using the vehicle communication unit.Further, a second radio signal for authorizing the user is received from the first electronic device using the vehicle communication unit. The second radio signal includes a first distance between the first electronic device and a second electronic device of the user and authentication information.In a further method step of the method of the motor vehicle, the user is authenticated by the motor vehicle on the basis of the ascertained first and second distances and the authentication information items. According to the invention, use is made of the fact that the second distance serves as a first security factor and the first distance serves as a second security factor in the sense of a two-factor authentication. For example, a (positive) authentication of the user is present if the first distance falls below a predefined first threshold value, the second distance falls below a predefined second threshold value, and the transmitted authentication information items coincide with authentication information items stored in a memory unit of the motor vehicle. If, for example, at least one of the conditions does not apply, the user is not authenticated, that is to say the authentication of the user fails. The first threshold value is preferably 2 m, preferably 1.5 m, particularly preferably 1 m. This ensures that the two electronic devices are close enough to one another or on the body of the user, so that it can be assumed that these are in possession of the user (second safety factor). Thus, the typical use cases are covered in which the user holds the first electronic device in the hand and carries the second electronic device in the jacket or pants pocket, in a hand-held bag or a back-held backpack and the like (or vice versa). The second threshold value is preferably 15 m, preferably 10 m, particularly preferably 5 m. This ensures that the user is in the immediate vicinity of the motor vehicle, for example in the field of view (first safety factor). The user's authentication according to the invention thus reliably prevents unauthorized users from being able to gain access to motor vehicle functions. Passive authentication of the user is preferably carried out, that is to say that the user does not have to actively prove his authorisation, for example by the electronic device requesting biometric data from the user, such as fingerprints or a face identification, for the purpose of authentication. In other words, preferably no additional action is required by the user for the purpose of authentication (passive access concept).In a preferred embodiment, it is provided that the positioning method based on runtime measurements is carried out on the basis of exchanged UWB radio signals. Owing to the dispersion of the signals over large frequency ranges, UWB signals interfere with other radio signals only minimally.In a further preferred embodiment, it is provided that according to a further method step, at least one vehicle function of the motor vehicle is actuated upon successful authentication of the user. The vehicle function preferably comprises a keyless entry system of a motor vehicle, which is configured to lock or unlock a central lock of the motor vehicle, a door and / or window system, which is configured to open and / or close the or a plurality of doors and / or windows, a immobilizer, an electric steering wheel lock and / or a driver authorisation system, which is configured to allow or block the switching on of the ignition and / or the operation of the engine. The second radio signal preferably comprises an instruction which of the vehicle functions are to be activated. This allows a simple assignment of the vehicle function desired by the user.In a further preferred embodiment, it is provided that the communication unit of the first electronic device and / or the vehicle communication unit is / are further configured to receive and / or transmit NFC radio signals, BT radio signals, LF radio signals and / or UHF radio signals, and the second radio signal is an NFC, BT, LF or UHF radio signal. In other words, the communication unit of the first electronic device further comprises an NFC antenna, a BT antenna, for example a BLE antenna, an LF antenna and / or a UHF antenna. This allows the first electronic device to be used in a versatile manner for transmitting the determined first distance and the authentication information to the motor vehicle.In a further preferred embodiment, it is provided that the communication unit of the first electronic device or the vehicle communication unit is actuated for carrying out a positioning method based on runtime measurements with the motor vehicle or the first electronic device for determining the second distance. In other words, the first radio signal in this case comprises mutually exchanged UWB signals. Positioning methods based on runtime measurements are less susceptible to RSA attacks, so that the authentication of the user can be carried out even more securely.In a further preferred embodiment, it is provided that the first electronic device and the motor vehicle are each configured to locate their own location, wherein the first radio signal comprises the located location of the first electronic device and the second distance is determined based on the located locations. Satellite-supported positioning systems, such as GPS (Global Positioning System), are particularly suitable in this case. This represents a further possibility for ascertaining the second distance.In a further preferred embodiment, it is provided that the first electronic device comprises an acceleration sensor and that the first distance is determined depending on the fact that a movement of the first electronic device has been detected by the acceleration sensor. Preferably, the second electronic device also comprises an acceleration sensor. In this case, the first distance may be further determined depending on that a movement of the second electronic device has been detected by the acceleration sensor of the second electronic device. The (last) determined first distance is preferably stored in the memory unit of the first and / or of the second electronic device. In the event that no movement of the first and / or second electronic device has been determined, but the user is to be authenticated according to the invention, the first distance determined in each case (last) in the respective memory unit is transmitted to the motor vehicle in the form of the second radio signal. This allows energy-saving operation of the first and / or second electronic device.In a further preferred embodiment, it is provided that the first distance is determined depending on a function that can be activated (and deactivated) by the user, and the authentication of the user by the motor vehicle is carried out only when the function is activated by the user based on the determined second distance. In other words, a setting is provided for the motor vehicle, which allows the user to choose whether a one-factor or a two-factor authentication is to be carried out by the motor vehicle. The selection can be made, for example, via a human machine interface (HMI)) of the motor vehicle. Consequently, the user can decide between different security levels of authentication. Preferably, the function can be deactivated via a cloud service in order to be able to further enable (simple) authentication of the user with the existing electronic device in the event of a lost electronic device.In a further preferred embodiment, it is provided that, according to a further method step, the vehicle communication unit is actuated for carrying out a positioning method based on runtime measurements using the second electronic device for determining a third distance between the motor vehicle and the second electronic device. The authentication of the user is preferably carried out by the motor vehicle further based on the third distance. For example, a (positive) authentication of the user is present if the third distance additionally falls below a predefined third threshold value. If these conditions do not apply, the user is not authenticated. The third threshold value is preferably set based on the first distance and the second distance. For example, the third threshold value is the sum of the first distance and the second distance plus a tolerance distance for taking account of a measurement imprecision. For example, the third threshold value is 12 m. If the second electronic device is at a distance above the third threshold value from the motor vehicle, it can be assumed that the user is not authorized to use the motor vehicle. In this respect, the determination of the third distance offers a possibility on the part of the motor vehicle for verifying the received information via a direct communication with the second electronic device.In a further preferred embodiment, it is provided that a third radio signal for verifying the authorization of the user is exchanged between the motor vehicle and the second electronic device using the vehicle communication unit. The third radio signal comprises the authentication information of the second electronic device, which is stored in the storage unit of the second electronic device. The authentication of the user, for example by the motor vehicle, then furthermore takes place based on a match of the received authentication information of the second electronic device. In this respect, a possibility on the part of the motor vehicle for verifying the user via a direct communication with the second electronic device is made possible. Preferably, the authentication information of the second electronic device is different from the authentication information of the first electronic device. This allows a further security level to be incorporated for authenticating the user.A further aspect of the invention relates to a control device for a motor vehicle. The control device is configured to carry out the method described above. The motor vehicle is preferably the motor vehicle described above. The advantages achieved with the methods can be achieved in an analogous manner with the control unit. The disclosed combinations of features of the methods can be transferred analogously to the control unit. A repetitive description of the features and advantages is therefore omitted.A further aspect of the invention relates to a motor vehicle, comprising a vehicle communication unit configured to exchange radio signals with electronic devices, and the control device described above. The advantages achieved with the methods can be achieved in an analogous manner with the motor vehicle. The disclosed combinations of features of the methods can be transferred analogously to the motor vehicle. A repetitive description of the features and advantages is therefore omitted.A further aspect of the invention relates to a control unit for operating an electronic device. The control unit is configured to determine a first distance between the electronic device and a further electronic device using a positioning method based on runtime measurements, to determine a second distance between the electronic device and a motor vehicle using a first radio signal exchanged with the motor vehicle, and to transmit a second radio signal from the electronic device to the motor vehicle for authorisation of the user, wherein the second radio signal comprises the determined first distance and the authentication information. The advantages achieved with the methods can be achieved in an analogous manner with the control unit. The disclosed combinations of features of the methods can be transferred analogously to the control unit. A repetitive description of the features and advantages is therefore omitted.A further aspect of the invention relates to an electronic device which is preferably a vehicle radio key or a smartphone. The electronic device comprises a communication unit having an antenna configured to transmit and receive radio signals, a storage unit having stored authentication information, and the above-described control unit. The advantages achieved with the methods can be achieved in an analogous manner with the electronic device. The disclosed combinations of features of the methods can be transferred analogously to the electronic device. A repetitive description of the features and advantages is therefore omitted.A further aspect of the invention relates to a system comprising the above motor vehicle having the above control device and the above first and second electronic devices.The individual method steps of the methods according to the invention are furthermore preferably embodied as one or more processes which run on one or more processors in one or more electronic computing devices and are generated during the execution of one or more computer programs. The computing devices are preferably designed to cooperate with other components, in particular a control device for operating a motor vehicle or with a control unit for operating an electronic device, in order to realize the functionalities described herein. Likewise preferably, the control unit or the control unit is designed as a central (one-part) or as a decentral (multi-part) component.The individual components of the control unit or of the control unit are furthermore preferably designed as one or more processes which run on one or more processors in one or more electronic computing devices and are generated during the execution of one or more computer programs. The computing devices are preferably designed to cooperate with other components, for example a vehicle communication unit configured to exchange radio signals with the two electronic devices or with a communication unit having an antenna configured to transmit and receive radio signals, in order to realize the functionalities described herein. The instructions of the computer programs are likewise preferably stored in a memory, such as a RAM element. However, the computer programs may also be stored in a nonvolatile storage medium such as a CD-ROM, a flash memory, or the like.It will also be apparent to those skilled in the art that the functionalities of multiple computers (data processing devices) may be combined or combined in a single device or that the functionality of a particular data processing device may be distributed among a plurality of devices to perform the steps of the methods of the invention without departing from the methods of the invention.A further aspect of the invention relates to a computer program comprising commands which, when the program is executed by a computer, such as a control device for operating a motor vehicle or a control unit for operating an electronic device, cause the latter to carry out one of the methods, in particular a method of a first electronic device for authenticating a user or a method of a motor vehicle for authenticating a user.Further preferred embodiments of the invention result from the other features mentioned in the dependent claims.The various embodiments of the invention mentioned in this application can be combined with one another with advantage unless stated otherwise in the individual case.The invention is explained below in exemplary embodiments with reference to the associated drawings. The following are shown: FIG. 1 shows a schematic illustration of a method for wirelessly authenticating a user of a motor vehicle according to one embodiment, and FIG. 2 shows a schematic illustration of a motor vehicle having a control device for operating the motor vehicle according to one specific embodiment.FIG. 1 shows a schematic illustration of a method for wirelessly authenticating a user 12 of a motor vehicle 10 according to one embodiment. The method according to the invention is explained in more detail with reference to FIG. 2. FIG. 2 shows a schematic illustration of the motor vehicle 10 having a control unit 20 for operating the motor vehicle 10 according to one specific embodiment. The control unit 20 is configured to carry out the method according to FIG. 1.As shown in FIG. 2, the user 12 has a first electronic device 14 and a second electronic device 16 that exchange radio signals with a vehicle communication unit 18 of the motor vehicle 10. The electronic devices 14, 16 each comprise a communication unit (not shown) with a UWB antenna (not shown) configured to transmit and receive UWB signals, and a storage unit (not shown) with stored authentication information. The first electronic device 14 is a smartphone with a mobile device key and the second electronic device 16 is an ID transmitter in the form of a battery-operated vehicle key. It will be understood that the type of electronic devices 14, 16 illustrated is merely exemplary in nature and is not limited thereto. Rather, the electronic devices 14, 16 can also be ID transmitters or smartphones.The vehicle communication unit 18 of the motor vehicle 10 is configured to exchange radio signals with the two electronic devices 14, 16. For this purpose, this comprises six UWB antennas 22, one being arranged on each of the four vehicle doors, one on the front and one on the rear of the motor vehicle 10, and three NFC antennas 24, one respectively being arranged on the front vehicle doors and one on the rear of the motor vehicle 10. However, the number and type of antennas chosen are merely exemplary in nature and are not limited thereto.According to a first method step 50 of the method shown in FIG. 1, the communication unit of the first electronic device 14 is controlled to perform a positioning method based on runtime measurements with the communication unit of the second electronic device 16 in order to determine a first distance d 1 between the two electronic devices 14, 16. In this case, corresponding UWB radio signals are exchanged between the first and the second electronic device 14, 16 and the respective propagation times of the radio signals are used to calculate the first distance d 1. Such a positioning method is hardly susceptible to RSA attacks. The first distance d 1 between the two electronic devices 14, 16 is 1.5 m in the example shown in FIG. 2.In a second method step 52, a second distance d 2 between the first electronic device 14 and the motor vehicle 10 is determined using a first radio signal. The vehicle communication unit 18 is preferably actuated by the control unit 20 of the motor vehicle 10 in order to ascertain the second distance d 2, and the ascertained second distance d 2 is stored on a storage unit of the control unit 20. For example, the second distance is determined on the basis of a field strength measurement of an RSSI indicator (received signal strength indication) of the first radio signal. Additionally or alternatively, a positioning method based on runtime measurements can likewise be carried out using the vehicle communication unit 18. The determination of the second distance d 2 can be based on different radio technologies depending on the range required for the safety level. For example, the radio technologies such as LF, UHF, UWB or BLE allow communication with the vehicle communication unit 18 in a long range, that is to say at second distances d 2 above 1 m, in particular above 10 m. In other radio technologies, for example NFC radio communications, which frequently determine a distance via field strength measurements, the range is limited to a few centimeters to at most 10 cm. The second distance d 2 between the first electronic device 14 and the motor vehicle 10 is 2 m in the example shown in FIG. 2.In a third method step 54, a second radio signal for the authorization of the user 12 is exchanged between the first electronic device 14 and the motor vehicle 10. For this purpose, the electronic device 14 transmits the second radio signal to the motor vehicle 10, which in turn receives the second radio signal. The second radio signal comprises the determined first distance d 1 and the authentication information of the first electronic device 14. Thus, the control device 20 of the motor vehicle 10 now has at least the information about the first distance d 1 between the two electronic devices 14, 16, about the second distance d 2 between the first electronic device 14 and the motor vehicle 10 and corresponding authentication information from the first electronic device 14.In a fourth method step 56, the user 12 is authenticated by the control device 20 of the motor vehicle 10 on the basis of the ascertained first and second distances d 1, d 2 and the authentication information items of the first electronic device 14. In the example shown in FIG. 2, the user 12 is successfully authenticated by the control unit 20 of the motor vehicle 10 because the first distance d 1 of 1.5 m falls below the predefined first threshold value of 2 m, the second distance d 2 of 2 m falls below the predefined second threshold value of 10 m, and the authentication information items of the first electronic device 14 transmitted with the second radio signal match authentication information items stored in the memory unit of the control unit 20. If, in contrast, one of the three conditions mentioned were not fulfilled, the user 12 would not be authenticated. Thus, the present method represents a two-factor authentication in which the second distance d2is a first security factor and the first distance d2is a second security factor. The process-based authentication of the user 12 thus reliably prevents unauthorized users from being able to gain access to the motor vehicle 10. Passive authentication of the user 12 preferably takes place, that is to say that the user 12 does not have to actively prove his authorisation. In other words, no additional action is required by the user 12 for the purpose of authentication, so that only the carrying along of the two electronic devices 14, 16 and the presence close (below the second threshold value) of the motor vehicle 10 are sufficient (passive access concept).The security level of authentication can be increased, for example, by using NFC radio technology in one of the electronic devices 14, 16. Due to the limited range of NFC radio technology, the user 12 or the electronic device 14, 16 must be brought particularly close to the motor vehicle 10, for example a few centimeters. This means for the example shown in FIG. 2 that a third distance d 3 between the motor vehicle 10 and the second electronic device 16 must be below 10 cm. In this respect, the authentication of the user 12 is then further dependent on a third threshold value, according to which the third distance d 3 must be less than 10 cm. The vehicle communication unit 18 is preferably configured to transmit electromagnetic energy to the second electronic device 16 by means of the NFC antennas 24. Thus, a distance measurement of the third distance d 3 can advantageously be carried out and / or authorization data can be exchanged via NFC, even if the battery of the second electronic device 16 is discharged.In an optional fifth method step 58, a third radio signal for verifying the authorization of the user 12 is exchanged between the motor vehicle 10 and the second electronic device 16, for example by means of NFC radio technology. The third radio signal comprises the authentication information of the second electronic device 16 in this case. the authentication of the user 12 by the control device 20 of the motor vehicle 10 then furthermore takes place on the basis of a match of the received authentication information of the second electronic device 16 with authentication information stored in the memory unit of the control device 20. In other words, the authentication of the user by the authentication process initiated by the first electronic device 14 is verified by the second electronic device 16. Such verification is possible either upon interrogation of the vehicle communication unit 18 or automatically by the second electronic device 16. This allows for a still secure authentication.In an optional sixth method step 60, a vehicle function of the motor vehicle 10 is activated. This is possible because the user 12 has been successfully authenticated in the example shown in FIG. 2. For example, the keyless access system of the motor vehicle 10 is controlled to unlock the central lock, so that the user 12 can gain access to the motor vehicle 10 without having to perform an additional action (passive access concept). However, it is understood that other vehicle functions can also be operated wirelessly accordingly.List of reference characters10 Motor vehicle 12 user 14 first electronic device 16 second electronic device 18 vehicle communication unit 20 control device 22 UWB antenna 24 NFC antenna d 1 first distance between the two electronic devices d 2, second distance between the first electronic device and the motor vehicle d 3, third distance between the motor vehicle and the second electronic device 50, first method step - actuation of the communication unit 52 second method step - determination of the second distance 54 third method step - exchange of the second radio signal 56 fourth method step - authentication of the user 58 fifth method step - exchange of a third radio signal 60 sixth method step - actuation of a vehicle functionReferences included in the specificationThis list of documents cited by the applicant has been produced in an automated manner and is only included for the better information of the reader. The list is not part of the German patent application or utility model application. The DPMA does not take any adhesion for any faults or omissions.Patent Literature citedWO 2014 / 052059 A1

[0004]

Claims

Method of an electronic device (14, 16) for authenticating a user (12), the method comprising the steps of: - determining (50) a first distance (d1) between a first electronic device (14, 16) and a second electronic device (16, 14) using a positioning method based on runtime measurements using a communication unit of the first electronic device (14, 16) having an antenna (22) configured to transmit and receive radio signals, - determining (52) a second distance (d2) between the first electronic device (14, 16) and a motor vehicle (10) using a first radio signal exchanged with the motor vehicle (10), and - transmitting (54) a second radio signal for authorisation of the user (12) from the first electronic device (14, 16) to the motor vehicle (10), wherein the second radio signal comprises the determined first distance (d1) and authentication information stored in a memory unit of the first electronic device (14, 16).Method of a motor vehicle (10) for authenticating a user (12), the method having the steps of: - determining (52) a second distance (d2) between a first electronic device (14, 16) of the user (12) and the motor vehicle (10) using a first radio signal exchanged with the first electronic device (14, 16) using a vehicle communication unit (18) of the motor vehicle (10) configured to exchange radio signals, - receiving (54) a second radio signal for authorisation of the user (12) from the first electronic device (14, 16) using the vehicle communication unit (18) of the motor vehicle (10), the second radio signal comprising a first distance (d1) between the first electronic device (14, 16) and a second electronic device (16, 14) of the user (12) and authentication information, and authenticating (56) the user (12) based on the first and second distances (d1, d2) and the authentication information.Method according to claim 1, wherein the positioning method based on runtime measurements is carried out on the basis of exchanged UWB radio signals.Method according to Claim 2, further comprising the step of: - activating (60) at least one vehicle function of the motor vehicle (10) in the event of successful authentication of the user (12).Method according to one of the preceding claims, wherein the communication unit of the first electronic device (14, 16) and / or the vehicle communication unit (18) is / are further configured to receive and / or transmit NFC radio signals, BT radio signals, LF radio signals and / or UHF radio signals and the second radio signal is an NFC, BT, LF or UHF radio signal.Method according to one of the preceding claims, wherein the communication unit of the first electronic device (14, 16) or the vehicle communication unit (18) is controlled to carry out a positioning method based on runtime measurements with the motor vehicle (10) or the first electronic device (14, 16) in order to determine the second distance (d2).Method according to one of the preceding claims, wherein the first electronic device (14, 16) and the motor vehicle (10) are each configured to locate their own location, wherein the first radio signal comprises the located location of the first electronic device (14, 16) and the second distance (d2) is determined based on the located locations.Method according to one of the preceding claims, if dependent on claim 1, wherein the first electronic device (14, 16) comprises an acceleration sensor and the first distance (d1) is determined as a function of the fact that a movement of the first electronic device (14, 16) has been detected by the acceleration sensor.Method according to one of the preceding claims, if dependent on claim 2, further comprising the step of: - controlling the vehicle communication unit (18) to perform a positioning method based on runtime measurements with the second electronic device (16, 14) for determining a third distance (d3) between the motor vehicle (10) and the second electronic device (16, 14), wherein the authentication of the user (12) is further performed based on the third distance (d3).Method according to one of the preceding claims, if dependent on claim 2, further comprising the step of: - exchanging (58) a third radio signal for verifying the authorisation of the user (12) between the motor vehicle (10) and the second electronic device (16, 14) using the vehicle communication unit (18), wherein the third radio signal comprises the authentication information of the second electronic device (16, 14), and - the authentication of the user (12) is further carried out based on a match of the received authentication information of the second electronic device (16, 14).Control device (20) for operating a motor vehicle (10), which is configured to carry out the method according to Claim 2.Motor vehicle (10), comprising a vehicle communication unit (18) set up to exchange radio signals with electronic devices (14, 16) and the control device (20) according to Claim 11.Control unit for operating an electronic device (14, 16), wherein the control unit is configured to: - determine a first distance (d1) between the electronic device (14, 16) and a further electronic device (16, 14) using a positioning method based on runtime measurements, - determine a second distance (d2) between the electronic device (14, 16) and a motor vehicle (10) using a first radio signal exchanged with the motor vehicle (10), and - transmit a second radio signal from the electronic device (14, 16) to the motor vehicle (10) for authorisation of the user (12), wherein the second radio signal comprises the determined first distance (d1) and the authentication information.Electronic device (14, 16), which is in particular a vehicle radio key or a smartphone, comprising: - a communication unit having an antenna (22) configured to transmit and receive radio signals, - a storage unit having stored authentication information, and the control unit according to Claim 13.

Citation Information

Patent Citations

  • Method for controlling a functionality of a vehicle by means of a user terminal and associated control system

    EP3350030B1

  • Key security device

    US20190080539A1

  • Mobile device and key FOB pairing for multi-factor security

    WO2014052059A1