Method and device for transferring a digital vehicle key
The method and device for transferring digital vehicle keys using NFC and policy-based authorization address inefficiencies and security gaps by enabling secure, proximity-free transfers, ensuring only authorized users can access the keys, thus enhancing convenience and security.
Patent Information
- Application Number
- DE102025104440
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-02-06
- Publication Date
- 2025-12-11
- Estimated Expiration
- 2045-02-06
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a method for handing over a digital vehicle key.
[0002] The invention further relates to a device for carrying out such a method.
[0003] From DE 10 2023 001 311 B3 a method for establishing a communication link between a new vehicle key and a vehicle is known, in which - a mobile communication device with a storage medium, a programmable vehicle key that is communicatively connected to the vehicle, and a programmable new vehicle key that can be communicatively connected to the vehicle, will be provided, - wherein a learning application is provided which includes an executable user application provided in the storage medium of the mobile communication device and an executable backend application provided in a vehicle backend and wirelessly connected to the mobile communication device, - where a digital permission to connect the new vehicle key to the vehicle is provided or can be provided in the backend application for a user, - where a user of the communication device logs into the learning application and initiates a key connection process, - as part of the key connection process, the learning application checks whether - a) the user is in the vehicle and a digital permission to connect the new vehicle key to the vehicle has been provided to the user in the backend application, while further checking whether the user is logged into the learning application, - b) the new vehicle key is inside the vehicle, - c) the vehicle key is inside the vehicle, - whereby, after successful verification of criteria a) to c), the new vehicle key is connected to the vehicle in a coupling step.
[0004] The invention is based on the objective of specifying a novel method and a novel device for the transfer of a digital vehicle key.
[0005] The problem is solved according to the invention by - a method which has the features specified in claim 1, - a method which has the features specified in claim 2, - a method which has the features specified in claim 3, - a device which has the features specified in claim 16, and - a device which has the features specified in claim 17.
[0006] Advantageous embodiments of the invention are the subject of the dependent claims.
[0007] The method for handing over a digital vehicle key of a vehicle according to a first aspect of the invention provides that - a digital unique vehicle identifier is transmitted by means of a door handle transmitter-receiver unit arranged in or on an exterior door handle of the vehicle and designed for near-field communication, - the vehicle identifier is received by means of a device transmit-receive unit of a mobile device, - the vehicle identifier, together with a user identifier of a user of the terminal device, is transmitted via the terminal device to a central computing unit external to the vehicle, for example a backend server of a vehicle manufacturer, - the vehicle identifier is assigned to the vehicle by means of the processing unit, and it is checked using the user identifier whether the user has authorization to use the digital vehicle key, and - if the authorization to use the vehicle is granted, the digital vehicle key is transmitted to the terminal device via the computing unit.
[0008] The digital vehicle key, based on the Car Connectivity Consortium standard (CCC standard) as described at https: / / carconnectivity.org / digital-key-release-3-0-specification-download / (accessed January 21, 2025), is gaining in popularity and importance due to increasing support from vehicle manufacturers. This digital vehicle key, stored on a user's mobile device such as a smartphone or wearable, can replace traditional physical vehicle keys, also known as key fobs. This shifts the role of the key fob from an essential component of user-vehicle interaction to an optional element. Vehicle manufacturers aim to offer their customers the option of purchasing such key fobs as an optional extra rather than as standard equipment.In return, the digital key, especially according to the CCC standard, should become standard equipment.
[0009] However, there are regulatory requirements stipulating that a vehicle may only leave a manufacturer's factory premises if at least one vehicle key is programmed to it. After leaving the factory, the vehicle goes through a logistics chain with numerous transfer stations until it arrives at a dealership and is finally handed over to a customer. At each transfer station in the logistics chain, the vehicle key must be transferred. Using a key fob simplifies this process, as the key fob can be easily transferred and stored.
[0010] Using the present method as described in the first aspect, it is possible to implement such a transfer of a vehicle key, even with a digital vehicle key, in a simple and secure manner. This involves verifying and ensuring the proximity of the mobile device, such as a mobile phone, smartphone, or wearable, by transmitting the vehicle identifier via near-field communication (NFC). This enables the secure provisioning of the digital vehicle key on the device. Such a secure transfer of the digital vehicle key allows vehicles to be delivered from a factory site to dealers and customers via a logistics chain, even without a traditional physical vehicle key, particularly a key fob.
[0011] The method for handing over a digital vehicle key of a vehicle according to a second aspect of the invention provides that - using policy-based authorization and attribute-based authorization by means of context-specific authorization rules for each handover station in a logistics chain for the vehicle, it is determined under which conditions the digital vehicle key is transmitted to a mobile device, - at a transfer station, a request to transfer the digital vehicle key to the end device is transmitted to an external central computing unit, for example a backend server of a vehicle manufacturer, using the mobile device together with a user identifier of the user, - the computing unit checks, based on the authorization rules defined for the relevant transfer station, whether the conditions for transferring the digital vehicle key to the mobile device are met, and, based on the user identifier, checks whether the user has authorization to use the digital vehicle key, and - if the user authorization is present, the digital vehicle key is transmitted to the terminal device via the computing unit, provided it is not located on another mobile device belonging to a different user.
[0012] Using the present method as described in the second aspect, a configurable set of rules for authorizing the transfer of the digital key is generated and used on the processing unit. For the transfer of a digital vehicle key between two end devices, such as two devices belonging to logistics employees, temporal and spatial proximity of the devices is not required. This results in increased convenience and efficiency during the transfer of the digital vehicle key. Furthermore, the authorization rules ensure that only authorized users, such as logistics employees, are able to obtain a digital vehicle key for a vehicle. This achieves enhanced theft protection.
[0013] Policy-based authorization, as used here, refers to an authorization concept in which user access rights, or rights to obtain a digital vehicle key, are determined by policies. User roles and their associated permissions are checked to determine access. Additional attributes are also evaluated. This authorization concept is characterized by its flexibility and speed, as administrators have better control over an access level and can grant, revoke, or modify permissions for many users simultaneously. Policies cover a wide range of dynamic attributes and context-related controls, such as time- or location-based access restrictions, making this authorization concept highly adaptable.
[0014] Attribute-based authorization, as used here, refers to an authorization concept that determines user access rights, or rights to obtain a digital vehicle key, based on attributes or characteristics. Administrators create access policies based on user roles and attributes and define rules that dynamically determine access and rights. When an access request or a request to obtain the digital vehicle key is made, a decision is made depending on the context and risk. While policy-based authorization relies on policies to grant or deny resource access, attribute-based authorization focuses on the specific attributes that influence the policies.Because the relationships between users and resources are defined by attributes rather than roles, administrators can create precisely targeted rules without having to set up additional roles. Instead of modifying rules or creating new roles, administrators simply assign the appropriate attributes to new users or resources, making attribute-based authorization highly flexible. Furthermore, this type of authorization is also highly adaptable, as administrators can modify attributes and create context-dependent rules as needed.
[0015] The method for handing over a digital vehicle key of a vehicle according to a third aspect of the invention provides that in an initial handover of the digital vehicle key - a digital unique vehicle identifier is transmitted by means of a door handle transmitter-receiver unit arranged in or on an exterior door handle of the vehicle and designed for near-field communication, - the vehicle identifier is received by means of a device transmit-receive unit of a mobile device, - the vehicle identifier, together with a user identifier of a user of the terminal device, is transmitted via the terminal device to a central computing unit external to the vehicle, - the vehicle identifier is assigned to the vehicle by means of the processing unit, and it is checked using the user identifier whether the user has authorization to use the digital vehicle key, and - if the authorization to use the vehicle is granted, the digital vehicle key is transmitted to the terminal device via the computing unit, and wherein in a handover of the digital vehicle key immediately or indirectly following the initial handover - using policy-based authorization and attribute-based authorization by means of context-specific authorization rules for each handover station in a logistics chain for the vehicle, it is determined under which conditions the digital vehicle key is transmitted to a mobile device, - at a transfer station, a request to transfer the digital vehicle key to the vehicle's external central computing unit is transmitted via the mobile device together with a user identifier of the user, - the computing unit checks, based on the authorization rules defined for the relevant transfer station, whether the conditions for transferring the digital vehicle key to the mobile device are met, and, based on the user identifier, checks whether the user has authorization to use the digital vehicle key, and - if the authorization to use the digital vehicle key is granted, it is transmitted to the terminal device via the computing unit, unless it is located on another mobile device of another user to which the vehicle key was transmitted in the initial transfer or in a transfer immediately or indirectly following.
[0016] Using the present method, as described in the third aspect, it is possible to implement the transfer of a vehicle key, even a digital one, in a simple and secure manner. This involves an initial transfer where the proximity of the mobile device, such as a mobile phone, smartphone, or wearable, is verified and ensured by transmitting the vehicle identifier via near-field communication (NFC). This enables the secure provisioning of the digital vehicle key on the device. Such a secure transfer of the digital vehicle key allows vehicles to be delivered from a factory to dealers and customers via a logistics chain, even without a traditional physical key, particularly a key fob.
[0017] Furthermore, for the transfer of digital vehicle keys between different mobile devices, a configurable rule set is generated and used on the processing unit after the initial transfer to authorize the transfer of the digital key. For the transfer of a digital vehicle key between two devices, for example, two devices belonging to logistics employees, temporal and spatial proximity of the devices is not required. This results in increased convenience and efficiency during the transfer of the digital vehicle key. Moreover, the authorization rules ensure that only authorized users, such as logistics employees, are able to obtain a digital vehicle key for a vehicle. This achieves enhanced theft protection.
[0018] The following are possible embodiments which may relate to all three of the aforementioned aspects of the invention.
[0019] One possible design stipulates that - before the vehicle key is transmitted to the terminal device via the processing unit, a request for approval of the transmission to a person's terminal device, for example a dispatcher of a logistics company, is sent and - the vehicle key is only transmitted to the user's mobile device if, in addition to the existence of the authorization to use it and the condition that the vehicle key is not located on another user's mobile device, the request for authorization from the computing unit is met with authorization for the transmission from the person on their device.
[0020] This can further increase security during the transmission of the digital vehicle key.
[0021] In another possible configuration, authorization information for obtaining the vehicle key and authentication information for different users and / or different mobile devices are stored in the processing unit. This enables authentication and authorization of all participants in the process at the processing unit, particularly at the vehicle manufacturer's backend server.
[0022] Another possible configuration allows for the use of both natural and legal persons as users. This would enable companies, such as logistics companies, to be issued digital vehicle keys in addition to individuals. The end device used would then no longer be linked to a specific person and could, for example, be made available by the company to different employees to receive digital vehicle keys.
[0023] In another possible configuration, communication between the terminal device and the vehicle, the processing unit, and a user, as well as the processing of data transmitted and received for the transfer of the vehicle key, is controlled and / or executed on the terminal device by means of an application program running on the terminal device. Such an application program, also referred to as an application or app, can provide the user with a user interface through which they can easily and intuitively send requests to the processing unit and receive and use the vehicle key from it.
[0024] In another possible embodiment, it is envisaged that the input variables for selecting and executing authorization rules are used. - a current transfer point in a logistics chain and / or - a current time and / or - a current geographical position of the vehicle and / or - the user's affiliation with a company and / or - User permissions and / or - a role of the user and / or - a vehicle identity and / or - the existence of an authorization for the handover of the vehicle key by a person, for example by a dispatcher of the logistics company, These input variables can be used to easily adapt the authorization rules to different transfer stations and their requirements. This makes it possible to customize the authorization rules for each transfer station in the logistics chain.
[0025] In another possible configuration, the computing unit stores a vehicle identification number (VIN) for each of several vehicles. These VINs allow for the unique identification of each individual vehicle.
[0026] In another possible configuration, the vehicle identification number is used to generate the vehicle identifier. This allows for the creation of a unique vehicle identifier that is assigned to only one vehicle.
[0027] In another possible configuration, each transmission of the digital vehicle key to an end device is logged in the processing unit. This ensures that it is always known on which end device a digital vehicle key is stored and has been stored in the past. In other words, the status and current owner of the digital vehicle key are always known.
[0028] In another possible configuration, the vehicle key is automatically deleted from a terminal device after a predefined deletion condition is met. This ensures that the vehicle key is only available on a predetermined number of terminal devices, and in particular, only on one terminal device at a time. In another configuration, the digital vehicle key is terminated on the terminal device after use, i.e., at the end of its usage. This occurs automatically. The deletion or termination of the vehicle key is logged centrally, particularly in the processing unit. This prevents the duplication of digital vehicle keys.
[0029] In another possible configuration, it is envisaged that the vehicle key can be transferred from one mobile device to another mobile device. - a request to surrender the vehicle key is transmitted to the computing unit via the terminal device on which the vehicle key is active, - is deleted on the terminal device by means of the computing unit after receipt of the request to surrender the vehicle keys, - by means of the additional mobile device at the handover station, together with the user's user identifier, the request to transfer the digital vehicle key to the device is transmitted to a central computing unit external to the vehicle, - the computing unit checks, based on the authorization rules defined for the relevant transfer station, whether the conditions for transferring the digital vehicle key to the other mobile device are met, and, based on the user identifier, checks whether the user has authorization to use the digital vehicle key, and - if the authorization to use the vehicle is granted, the digital vehicle key is transmitted to the other terminal device via the computing unit.
[0030] This ensures that the vehicle key is first deleted on one device and only then transferred to another. Furthermore, this allows for the transfer of a digital vehicle key between the devices of two users without requiring either physical or temporal proximity.
[0031] In another possible configuration, it is envisaged that - before the vehicle key is deleted from the user's terminal device, a request for approval of the deletion is transmitted by the processing unit to a person's terminal device, for example a dispatcher of the logistics company, and - the vehicle key will only be deleted from the user's mobile device if the computing unit receives permission to delete it from the person on their device.
[0032] This allows the deletion of the vehicle key from a previous user's device, which is necessary for transferring the vehicle key to another user's device, to be authorized by another person, resulting in a further increase in security when transferring the digital vehicle key.
[0033] In another possible configuration, it is envisaged that - before the vehicle key is transferred to the user's terminal device by means of the processing unit, a request for approval of the transfer to a person's terminal device is transmitted and - the vehicle key is only transferred to the user's mobile device if the computing unit receives authorization for the transfer from the person on their device.
[0034] This means that the transfer of the vehicle key to a user's terminal device must be authorized by another person, resulting in a further increase in security when transferring the digital vehicle key.
[0035] The device according to the invention for transferring a digital vehicle key of a vehicle according to a first embodiment comprises - a door handle transmitter-receiver unit arranged in or on an exterior door handle of the vehicle, which is designed to transmit a digital unique vehicle identifier via near-field communication, - a mobile terminal device which has a device transceiver unit which is configured to receive the vehicle identifier from the door handle transceiver unit, and which is configured to transmit the vehicle identifier together with a user identifier of a user of the terminal device to a central computing unit external to the vehicle, - the vehicle-external central computing unit, which is designed to assign the vehicle identifier to the vehicle and to check, using the user identifier, whether the user has authorization to use the digital vehicle key, and, if authorization to use exists, to transmit the digital vehicle key to the terminal device.
[0036] Using the device according to the first embodiment, it is possible to transfer a vehicle key, even a digital one, in a simple and secure manner. This is achieved by verifying and ensuring the proximity of the mobile device, such as a mobile phone, smartphone, or wearable, through the transmission of the vehicle identifier via near-field communication (NFC). This enables the secure provisioning of the digital vehicle key on the device. Such a secure transfer of the digital vehicle key allows vehicles to be delivered from a factory to dealers and customers via a logistics chain, even without a traditional physical vehicle key, particularly a key fob.
[0037] The device according to the invention for transferring a digital vehicle key of a vehicle according to a second embodiment comprises - a mobile device which is trained to transmit a request to transfer the digital vehicle key to the device to an external central computing unit at a transfer station together with a user identifier of a user of the mobile device, - the vehicle-external central computing unit, which is designed, - using policy-based authorization and attribute-based authorization, by means of context-specific authorization rules for each handover station in a logistics chain for the vehicle, to determine under which conditions the digital vehicle key is transmitted to a mobile device, - to check, based on the authorization rules defined for the relevant transfer station, whether the conditions for transferring the digital vehicle key to the mobile device are met, - to verify, using the user identifier, whether the user has authorization to use the digital vehicle key, and - to transmit the digital vehicle key to the terminal device if the user authorization is granted, unless it is located on another mobile device belonging to a different user.
[0038] Using the device according to the second embodiment, a configurable set of rules for authorizing the transfer of the digital key is generated and used on the processing unit. For the transfer of a digital vehicle key between two end devices, for example, two end devices belonging to logistics employees, temporal and spatial proximity of the end devices is not required. This results in increased convenience and efficiency during the transfer of the digital vehicle key. Furthermore, the authorization rules ensure that only authorized users, such as logistics employees, are able to obtain a digital vehicle key for a vehicle. This achieves enhanced theft protection.
[0039] The device according to the invention for transferring a digital vehicle key of a vehicle according to a third embodiment has - a door handle transmitter-receiver unit arranged in or on an exterior door handle of the vehicle, which is designed to transmit a digital unique vehicle identifier via near-field communication, - a mobile terminal device which has a device transceiver unit which is configured to receive the vehicle identifier from the door handle transceiver unit, and which is configured to transmit the vehicle identifier together with a user identifier of a user of the terminal device to a central computing unit external to the vehicle, and - the vehicle-external central computing unit, which is designed to assign the vehicle identifier to the vehicle and to check, using the user identifier, whether the user has authorization to use the digital vehicle key, and, if authorization to use exists, to transmit the digital vehicle key to the terminal device.
[0040] The mobile device is additionally equipped to transmit a request to transfer the digital vehicle key to the device to an external central processing unit at a transfer station, together with a user identifier of a user of the mobile device. The external central processing unit is additionally equipped to... - using policy-based authorization and attribute-based authorization, by means of context-specific authorization rules for each handover station in a logistics chain for the vehicle, to determine under which conditions the digital vehicle key is transmitted to a mobile device, - to check, based on the authorization rules defined for the relevant transfer station, whether the conditions for transferring the digital vehicle key to the mobile device are met, - to verify, using the user identifier, whether the user has authorization to use the digital vehicle key, and - to transmit the digital vehicle key to the terminal device if the user authorization is granted, unless it is located on another mobile device belonging to a different user.
[0041] Using the device according to the third embodiment, it is possible to implement the transfer of a vehicle key, even a digital one, in a simple and secure manner. In an initial transfer, the proximity of the mobile device, such as a mobile phone, smartphone, or wearable, is first established and ensured by transmitting the vehicle identifier via near-field communication (NFC). This enables the secure provisioning of the digital vehicle key on the device. Such a secure transfer of the digital vehicle key allows vehicles to be delivered from a factory to dealers and customers via a logistics chain, even without a traditional physical vehicle key, particularly a key fob.
[0042] Furthermore, for the transfer of digital vehicle keys between different mobile devices, a configurable rule set is generated and used on the processing unit after the initial transfer to authorize the transfer of the digital key. For the transfer of a digital vehicle key between two devices, for example, two devices belonging to logistics employees, temporal and spatial proximity of the devices is not required. This results in increased convenience and efficiency during the transfer of the digital vehicle key. Moreover, the authorization rules ensure that only authorized users, such as logistics employees, are able to obtain a digital vehicle key for a vehicle. This achieves enhanced theft protection.
[0043] Exemplary embodiments of the invention are explained in more detail below with reference to drawings.
[0044] This shows: Fig. 1. Schematic representation of a logistics chain for a vehicle with multiple transfer stations, Fig. 2 schematically a block diagram of an embodiment of a device for transferring a digital vehicle key of a vehicle, Fig. 3 schematically a block diagram of a further embodiment of a device for transferring a digital vehicle key of a vehicle and Fig. 4 schematically a block diagram of a further embodiment of a device for handing over a digital vehicle key of a vehicle.
[0045] Corresponding parts are marked with the same reference symbols in all figures.
[0046] In Fig. 1 is a possible embodiment of a logistics chain LK for a in Fig. 2. Vehicle 1 shown in more detail with several transfer stations US1 to USn.
[0047] The logistics chain LK describes the route of vehicle 1 from a vehicle manufacturer's factory premises to a customer. The factory premises constitute the first station S1 of the logistics chain LK, and the customer is the last station Sm.
[0048] Between these two stations S1, Sm, a plurality of further stations S2 to Sm-1 are formed, whereby in the illustrated embodiment of the logistics chain LK - a station S2 a transport of vehicle 1 by means of a rail vehicle, - one S3 station has a loading station, - a station S4 transports vehicle 1 by means of a truck, - a station S5 a loading port, - a station S6 transports vehicle 1 by means of a ship, - a station S7 a loading port, - a station S8 a renewed transport of vehicle 1 by means of a truck and - station Sm-1 represents a vehicle dealer.
[0049] Between each station S1 to Sm, a transfer station US1 to USn is provided, at which a transfer of vehicle 1 and a transfer of a [vehicle / item] can take place. Fig. 2. The digital vehicle key 2, as shown in more detail, will be used.
[0050] The digital vehicle key 2 is specifically designed in accordance with the standard of the Car Connectivity Consortium (CCC standard for short).
[0051] The following requirements apply to the handover of the digital vehicle key 2: Requirement 1: The handover process for the digital vehicle key 2 in the logistics chain LK must not require a classic physical vehicle key, in particular a key fob, at any handover station US1 to USn. Requirement 2: The handover process for the digital vehicle key 2 in the logistics chain LK must ensure that one in the Fig. 2 to 4 more detailed users 3 the digital vehicle key 2 to one in the Fig. 3 and Fig. The digital vehicle keys 2 can be transferred to another user 4, as further described in more detail. This other user 4 must not be able to obtain the digital vehicle keys 2 without being transferred by user 3. This requirement ensures that in insecure environments within the logistics chain, such as rest areas, the vehicle 1 is secured against unauthorized access and removal. Requirement 3: The handover process for the digital vehicle key 2 in the logistics chain LK must enable a user 3, 4 to receive the digital vehicle key 2 on a device located in the Fig. The mobile device 5, 6, as shown in more detail in sections 2 to 4, is transferred or provisioned after user 3, 4 has proven their direct proximity to vehicle 1. User 4 must not be able to obtain the digital vehicle keys 2 without being handed over by user 3. This requirement ensures that, in secure environments of the logistics chain LK, vehicle 1 can be moved at any time by authorized users 3, 4, such as logistics employees. Requirement 4: The transfer of digital vehicle keys 2 from one user 3 to another user 4, for example from one logistics employee to another, should be possible without physical proximity. This requirement increases convenience compared to existing state-of-the-art solutions. Requirement 5: The transfer of digital vehicle keys 2 from one user 3 to another user 4, for example from one logistics employee to another, should be possible without any temporal proximity. This requirement also increases convenience compared to solutions known from the current state of the art. Requirement 6: The transfer process for the digital vehicle key 2 in the logistics chain LK must enable the transfer of digital vehicle keys 2 from one user 3, a legal entity (e.g., a logistics company), to another user 4, also a legal entity (e.g., a logistics company), without being tied to specific natural persons. This requirement allows the transfer of the digital vehicle key 2 between two legal entities, for example, in Fig. 2 and Fig. 4 companies shown, 9, 10. Requirement 7: The handover process for the digital vehicle key 2 in the logistics chain LK must enable the handover of the digital vehicle key 2 to the customer at the end of the logistics chain LK. Requirement 8: The handover process for the digital vehicle key 2 in the logistics chain LK must not be less secure with regard to theft protection than the handover of a physical vehicle key, for example key fobs. Requirement 9: The handover process for the digital vehicle key 2 in the logistics chain LK must ensure that the digital vehicle key 2 is no longer on the mobile device 5, 6 of the original user 3, 4 after its handover. This prevents the duplication of digital vehicle keys 2. Requirement 10: If requirement 9 cannot be implemented or if a specific implementation fails, this must be documented in a report within the Fig. 2 to 4, as detailed in more detail, are logged by the vehicle-external central computing unit 7, in particular a backend server of the vehicle manufacturer, and reported as a security event in order to take measures to eliminate this risk.
[0052] To meet the aforementioned requirements, the handover process for the digital vehicle key 2 in the logistics chain LK is based on the following principles: Principle 1: Proof of the immediate proximity of the user 3, 4 to a specific vehicle 1 as a condition for obtaining a digital vehicle key 2, without requiring access to a vehicle interior.
[0053] Principle 1 is implemented through the use of "Near Field Communication" technology, or NFC for short. Every vehicle 1 equipped with a digital vehicle key 2 has, according to the CCC standard, a Fig. 2. Exterior door handle 1.1, shown in more detail, with a door handle transmitter-receiver unit 1.2 designed for near-field communication. The door handle transmitter-receiver unit 1.2 uses near-field communication to transmit a signal to the user. Fig. 2. A more detailed digital unique vehicle identifier FI, also known as Unique ID, is transmitted.
[0054] This vehicle identifier (FI) is generated by a device in the Fig. 2 to 4, as detailed in more detail below, the device transmitting and receiving unit 5.1, 6.1 of a mobile terminal device 5, 6 located within the range of near-field communication is received. The range is a few centimeters, in particular a maximum of ten centimeters.
[0055] The mobile device 5, 6 transmits the vehicle identifier FI together with a user identifier NI of user 3, 4 of the device 5, 6 to the processing unit 7. A unique mapping of the vehicle identifier FI of the door handle transceiver unit 1.2 to a vehicle identification number (VIN) is stored on the processing unit 7. The processing unit 7 therefore concludes that the user 3, 4, whose device 5, 6 transmitted the vehicle identifier FI, is in close proximity to the vehicle 1 with the associated VIN, since the range of near-field communication is in the centimeter range.
[0056] To prevent an attacker from obtaining a large number of digital vehicle keys 2 by iterating over all possible near-field communication vehicle identifiers (NFCs), mass queries are prevented by the processing unit 7. Furthermore, the digital vehicle key 2 is only transmitted if a request originates from an authorized user 3, 4, for example, an employee of a logistics company in whose possession the vehicle 1 is located. Principle 2:
[0057] Use of a configurable rule set for authorizing the transfer of the digital vehicle key 2 in the logistics chain LK on computing unit 7, in particular a backend server of the vehicle manufacturer. The rule set defines and enforces the conditions under which a transfer of the digital vehicle key 2 can take place and how a specific process for the transfer of the digital vehicle key 2 at the respective transfer station US1 to USn of the logistics chain LK is designed.
[0058] Here, using policy-based and attribute-based authorization, context-specific authorization rules are defined for each transfer station US1 to USn in a logistics chain LK for vehicle 1, specifying the conditions under which the digital vehicle key 2 is transmitted to a mobile device 5, 6. Policy-based authorization is implemented, for example, according to https: / / www.nextlabs.com / products / cloudaz-policy-platform / what-is-policy-based-accesscontrol-pbac / (accessed January 21, 2025). Attribute-based authorization is implemented, for example, according to http: / / docs.oasis-open.org / xacml / 3.0 / xacml-3.0-core-spec-osen.html (accessed January 21, 2025).
[0059] Since these conditions vary depending on the process step or transfer station US1 to USn in the logistics chain LK, several authorization rules are provided. Which authorization rule is used for an authorization decision depends on the current context. Input variables for rule selection and execution can include, for example... - a current transfer station US1 to USn of the logistics chain LK and / or - a current time and / or - a current geographical position of vehicle 1 and / or - an affiliation of the user 3, 4 with a company 9, 10 and / or - User permissions 3, 4 and / or - a role of user 3, 4 and / or - a vehicle identity, in particular described by the vehicle identifier FI, and / or - the existence of a G2 approval authorizing the handover of the vehicle key 2 by a person be used. Principle 3:
[0060] Authentication and authorization of all participants or users 3, 4 of the handover process at the computing unit 7. Users 3, 4 are natural persons and legal persons, for example companies 9, 10. Companies 9, 10 must be taken into account because different companies 9, 10, for example logistics companies, are involved in the logistics chain LK and rules for authorizing the handover of the digital vehicle key 2 can take the respective companies 9, 10 into account. Principle 4:
[0061] Use of an end-device-based application program, also referred to as an application or app, on the mobile end devices 5, 6 of users 3, 4, to establish a data connection to the computing unit 7; in particular, use of a mobile phone or smartphone-based app on end devices 5, 6, each designed as a mobile phone or smartphone.
[0062] Based on the following Fig. Sections 2 to 4 describe possible embodiments of a handover of the digital vehicle key 2.
[0063] This shows Fig. 2 a block diagram of a possible embodiment of a device 8 for the transfer of a digital vehicle key 2 of a vehicle 1 when a user 3 located in the immediate vicinity of the vehicle 1 requests a transfer of the digital vehicle key 2 to his mobile terminal 5.
[0064] In this process, the user 3 belonging to a company 9, for example a logistics employee of a logistics company, uses the device transmit-receive unit 5.1 of his mobile device 5, for example smartphones, to record the vehicle identifier FI transmitted by the door handle transmit-receive unit 1.2 of the vehicle 1 via near field communication.
[0065] The vehicle identifier FI is transmitted to the computing unit 7, specifically a backend server of a vehicle manufacturer, by means of the application program installed on the terminal device 5. Additional information is also transmitted from the terminal device 5 to the computing unit 7, in particular the user identifier NI, also referred to as the user ID.
[0066] The processing unit 7 assigns the vehicle identifier FI to a corresponding vehicle identification number and checks the request for the transmission of the digital vehicle key 2 via a rule system. For this purpose, the processing unit 7 comprises a process control unit 7.1, a rule set 7.2, and a database 7.3. Using the processing unit 7, the vehicle identifier FI is assigned to vehicle 1, and the user identifier NI is used to verify whether user 3 has authorization to use the digital vehicle key 2.
[0067] If the rule system has reached a positive decision, meaning that user 3 is entitled to receive the digital vehicle key 2 for this vehicle 1, the digital vehicle key 2 is transferred or provisioned by the computing unit 7 to the terminal device 5 of user 3.
[0068] Such a previously described transfer of the digital vehicle key 2 to the terminal device 5 of a user 3 takes place in particular at a first transfer station US1 of the logistics chain LK, for example when the vehicle 1 is handed over from the factory premises of the vehicle manufacturer to a second station S2 of the logistics chain LK.
[0069] The processing unit 7 ensures that the transmitted digital vehicle key 2 is terminated and deleted as soon as a user 3, 4 no longer needs or is no longer authorized to use this digital vehicle key 2. The termination and deletion are carried out primarily based on the CCC standard.
[0070] In Fig. Figure 3 shows a block diagram of a possible further embodiment of a device 8 for transferring a digital vehicle key 2 of a vehicle 1. Using this embodiment of the device 8, an indirect transfer of a digital vehicle key 2 is carried out between mobile devices 5, 6 of two users 3, 4. Direct spatial proximity of the users 3, 4 and their devices 5, 6 to the vehicle 1 is not required.
[0071] First, a request A1 to surrender or delete the vehicle key 2 is transmitted to the computing unit 7 via the terminal device 5, on which the digital vehicle key 2 is active or provisioned.
[0072] Using the computing unit 7, after receiving the request A1 for submission, the digital vehicle key 2 is deleted on the terminal device 5 in a deletion process L.
[0073] Using the other user's mobile device 6, a request A2 is transmitted at a transfer station US2 to USn, together with the user identifier NI of user 4, to transfer the digital vehicle key 2 to the vehicle-external central computing unit 7. No temporal proximity between requests A1 and A2 is required.
[0074] Using the processing unit 7, the authorization rules defined for the respective transfer station US2 to USn are checked to determine whether the conditions for transferring the digital vehicle key 2 to the further mobile device 6 are met. Furthermore, the processing unit 7 uses the user identifier NI to verify whether the user 4 has authorization to use the digital vehicle key 2.
[0075] If the authorization to use the vehicle is granted, the digital vehicle key 2 is transmitted or provisioned to the further terminal device 6 by means of the computing unit 7.
[0076] The processing unit 7 ensures that, even after such a transfer, the transferred digital vehicle key 2 is terminated and deleted as soon as a user 3 or 4 no longer needs or is authorized to use this digital vehicle key 2. The termination and deletion are carried out primarily based on the CCC standard.
[0077] Such a previously described transfer of the digital vehicle key 2 between end devices 5, 6 of different users 3, 4 takes place in particular at transfer stations US2 to USn following transfer station US1 in the logistics chain LK. Such a transfer can also take place when the digital vehicle key 2 is handed over from the vehicle dealer to the customer at the last transfer station USn in the logistics chain LK.
[0078] Fig. Figure 4 shows a block diagram of a possible further embodiment of a device 8 for transferring a digital vehicle key 2 of a vehicle 1. Using this embodiment of the device 8, an indirect transfer of a digital vehicle key 2 is carried out between mobile devices 5, 6 of two users 3, 4. Direct spatial proximity of the users 3, 4 and their devices 5, 6 to the vehicle 1 is not required.
[0079] In addition to the one in Fig. In the embodiment shown in Figure 3, after the deletion process L has been carried out on the terminal device 5 of the user 3, an authorization G1 to hand over the digital vehicle key 2 is transmitted from the company 9 to the company 10 to the computing unit 7 by a terminal device 11 of a person 13 belonging to the same company 9 as the user 3, for example a dispatcher belonging to the same logistics company.
[0080] Once this authorization G1 is granted, an authorization G2 for the acceptance of the digital vehicle key 2 by company 10 is transmitted from an end device 12 belonging to a person 14 belonging to the same company 10 as user 4, for example, a dispatcher belonging to the same logistics company, to the processing unit 7. Only when this authorization G2 is granted can user 4 submit the request A2 to transfer the digital vehicle key 2 to the processing unit 7, and, if the user authorization is granted, the digital vehicle key 2 is then transmitted or provisioned by the processing unit 7 to the further end device 6.
[0081] Before the respective approval G1, G2 is granted, the computing unit 7 can transmit a request to grant the approval G1, G2 to the terminal device 11, 12 of the respective person 13, 14.
Claims
[1] Method for handing over a digital vehicle key (2) of a vehicle (1), wherein - a digital unique vehicle identifier (FI) is transmitted by means of a door handle transmit-receive unit (1.2) arranged in or on an external door handle (1.1) of the vehicle (1) and designed for near-field communication, - the vehicle identifier (FI) is received by means of a device transmit-receive unit (5.1, 6.1) of a mobile terminal (5, 6), - the vehicle identifier (FI) together with a user identifier (NI) of a user (3, 4) of the terminal device (5, 6) is transmitted by means of the terminal device (5, 6) to a central computing unit external to the vehicle (7), - by means of the computing unit (7) the vehicle identifier (FI) is assigned to the vehicle (1) and it is checked using the user identifier (NI) whether the user (3, 4) has an authorization to use the digital vehicle key (2), and - if the authorization to use is present, the digital vehicle key (2) is transmitted to the terminal device (5, 6) by means of the computing unit (7). [2] Method for handing over a digital vehicle key (2) of a vehicle (1), wherein - using policy-based authorization and attribute-based authorization by means of context-specific authorization rules for each transfer station (US1 to USn) of a logistics chain (LK) for the vehicle (1), it is determined under which conditions the digital vehicle key (2) is transmitted to a mobile device (5, 6), - at a transfer station (US1 to USn) a request (A2) to transfer the digital vehicle key (2) to the terminal (5, 6) to an external central computing unit (7) is transmitted by means of the mobile device (5, 6) together with a user identifier (NI) of a user (3, 4), - using the computing unit (7) to check, based on the authorization rules defined for the relevant transfer station (US1 to USn), whether the conditions for the transfer of the digital vehicle key (2) to the mobile device (5, 6) are met, and using the user identifier (NI) to check whether the user (3, 4) has an authorization to use the digital vehicle key (2), and - if the authorization to use the digital vehicle key (2) is transmitted to the terminal device (5, 6) by means of the computing unit (7), unless it is located on another mobile terminal device (5, 6) of another user (3, 4). [3] Method for handing over a digital vehicle key (2) of a vehicle (1), wherein in an initial handover of the digital vehicle key (2) - a digital unique vehicle identifier (FI) is transmitted by means of a door handle transmit-receive unit (1.2) arranged in or on an external door handle (1.1) of the vehicle (1) and designed for near-field communication, - the vehicle identifier (FI) is received by means of a device transmit-receive unit (5.1, 6.1) of a mobile terminal (5, 6), - the vehicle identifier (FI) together with a user identifier (NI) of a user (3, 4) of the terminal device (5, 6) is transmitted by means of the terminal device (5, 6) to a central computing unit external to the vehicle (7), - by means of the computing unit (7) the vehicle identifier (FI) is assigned to the vehicle (1) and it is checked using the user identifier (NI) whether the user (3, 4) has an authorization to use the digital vehicle key (2), and - if the authorization to use the vehicle is granted, the digital vehicle key (2) is transmitted to the terminal device (5, 6) by means of the computing unit (7), and wherein in a transfer of the digital vehicle key following the initial transfer, whether directly or indirectly (2) - using policy-based authorization and attribute-based authorization by means of context-specific authorization rules for each transfer station (US1 to USn) of a logistics chain (LK) for the vehicle (1), it is determined under which conditions the digital vehicle key (2) is transmitted to a mobile device (5, 6), - at a transfer station (US1 to USn) a request (A2) for the transfer of the digital vehicle key (2) to the vehicle-external central computing unit (7) is transmitted by means of the mobile device (5, 6) together with a user identifier (NI) of the user (3, 4), - using the computing unit (7) to check, based on the authorization rules defined for the relevant transfer station (US1 to USn), whether the conditions for the transfer of the digital vehicle key (2) to the mobile device (5, 6) are met, and using the user identifier (NI) to check whether the user (3, 4) has an authorization to use the digital vehicle key (2), and - if the authorization to use the digital vehicle key (2) is transmitted to the terminal device (5, 6) by means of the computing unit (7), unless it is located on another mobile terminal device (5, 6) of another user (3, 4) to which the vehicle key (2) was transmitted in the initial transfer or in a transfer immediately or indirectly thereafter. [4] Method according to any one of the preceding claims, wherein - before the vehicle key (2) is transmitted to the terminal device (5, 6) by means of the computing unit (7) a request for approval (G2) of the transmission to a terminal device (5, 6) of a person (14) is transmitted and - the vehicle key (2) is only transmitted to the mobile device (5, 6) of the user (3, 4) if, in addition to the existence of the authorization to use and the condition that the vehicle key (2) is not located on another mobile device (5, 6) of another user (3, 4), the request for authorization (G2) from the computing unit (7) is met with authorization (G2) for the transmission made by the person (14) on their device (5, 6). [5] Method according to one of the preceding claims, wherein authorization information for obtaining the vehicle key (2) and authentication information are stored in the computing unit (7) for different users (3, 4) and / or for different mobile devices (5, 6). [6] Method according to any of the preceding claims, wherein natural persons and / or legal persons are permitted as users (3, 4). [7] Method according to one of the preceding claims, wherein communication between the terminal device (5, 6) and the vehicle (1), the computing unit (7) and a user (3, 4) as well as processing of data transmitted and received for the transfer of the vehicle key (2) on the terminal device (5, 6) is controlled and / or executed by means of an application program executed on the terminal device (5, 6). [8] Method according to one of the preceding claims, wherein the input variables for selecting and executing authorization rules during the handover of the vehicle key are (2) - a current transfer station (US1 to USn) of a logistics chain (LK) and / or - a current time and / or - a current geographical position of the vehicle (1) and / or - the user's (3, 4) affiliation with a company (9, 10) and / or - User permissions (3, 4) and / or - a role of the user (3, 4) and / or - a vehicle identity and / or - the existence of an approval (G2) of an authorization of the handover of the vehicle key (2) by a person (14) will be used. [9] Method according to one of the preceding claims, wherein a vehicle identification number is stored in the computing unit (7) for several vehicles (1). [10] Method according to claim 9, wherein the vehicle identification number is used to form the vehicle identifier (FI). [11] Method according to one of the preceding claims, wherein each transmission of the digital vehicle key (2) to an end device (5, 6) is logged in the computing unit (7). [12] Method according to one of the preceding claims, wherein the vehicle key (2) is automatically deleted on an end device (5, 6) after the occurrence of a predetermined deletion condition. [13] Method according to one of the preceding claims, wherein for the transfer of the vehicle key (2) from a mobile terminal (5, 6) to another mobile terminal (5, 6) - by means of the terminal device (5, 6) on which the vehicle key (2) is active, a request (A1) to surrender the vehicle key (2) is transmitted to the computing unit (7), - is deleted on the terminal device (5, 6) by means of the computing unit (7) after receipt of the request (A1) to hand over the vehicle keys (2), - by means of the further mobile device (5, 6) at a transfer station (US1 to USn) together with the user identifier (NI) of the user (3, 4) the request (A2) to transfer the digital vehicle key (2) to the device (5, 6) is transmitted to the vehicle-external central computing unit (7), - using the computing unit (7) to check, based on the authorization rules defined for the relevant transfer station (US1 to USn), whether the conditions for the transfer of the digital vehicle key (2) to the further mobile device (5, 6) are met, and using the user identifier (NI) to check whether the user (3, 4) has an authorization to use the digital vehicle key (2), and - if the authorization to use the vehicle is granted, the digital vehicle key (2) is transmitted to the further terminal device (5, 6) via the computing unit (7). [14] Method according to claim 13, wherein - before the vehicle key (2) is deleted from the terminal device (5, 6) of the user (3, 4) a request for approval (G1) of the deletion is transmitted to a terminal device (11) of a person (13) by means of the computing unit (7) and - the vehicle key (2) is only deleted on the mobile device (5, 6) of the user (3, 4) if the computing unit (7) receives authorization (G1) for deletion from the person (13) on their device (11). [15] Method according to any one of the preceding claims, wherein - before the vehicle key (2) is transferred to the terminal device (5, 6) of the user (3, 4) by means of the computing unit (7) a request for approval (G2) of the transfer to a terminal device (12) of a person (14) is transmitted and - the vehicle key (2) is only transferred to the mobile device (5, 6) of the user (3, 4) if the computing unit (7) receives authorization (G2) for the transfer from the person (14) on their device (12). [16] Device (8) for transferring a digital vehicle key (2) of a vehicle (1) with - a door handle transmitter-receiver unit (1.2) arranged in or on an exterior door handle (1.1) of the vehicle (1), which is designed to transmit a digital unique vehicle identifier (FI) by means of near field communication, - a mobile terminal (5, 6) which has a device transceiver unit (5.1, 6.1) configured to receive the vehicle identifier (FI) from the door handle transceiver unit (1.2) and configured to transmit the vehicle identifier (FI) together with a user identifier (NI) of a user (3, 4) of the terminal (5, 6) to a vehicle-external central computing unit (7), and - the vehicle-external central computing unit (7), which is designed to assign the vehicle identifier (FI) to the vehicle (1) and to check, using the user identifier (NI), whether the user (3, 4) has an authorization to use the digital vehicle key (2), and, if the authorization to use exists, to transmit the digital vehicle key (2) to the terminal device (5, 6). [17] Device (8) for transferring a digital vehicle key (2) of a vehicle (1) with - a mobile device (5, 6) which is configured to transmit a request (A2) to transfer the digital vehicle key (2) to the device (5, 6) to an external central computing unit (7) at a transfer station (US1 to USn) together with a user identifier (NI) of a user (3, 4) of the mobile device (5, 6), and - the vehicle-external central computing unit (7), which is designed, - using policy-based authorization and attribute-based authorization by means of context-specific authorization rules for each transfer station (US1 to USn) of a logistics chain (LK) for the vehicle (1) to determine under which conditions the digital vehicle key (2) is transmitted to a mobile device (5, 6), - to check, based on the authorization rules defined for the relevant transfer station (US1 to USn), whether the conditions for the transfer of the digital vehicle key (2) to the mobile device (5, 6) are met, - to verify, using the user identifier (NI), whether the user (3, 4) has authorization to use the digital vehicle key (2), and - if the authorization to use the vehicle is granted, to transmit the digital vehicle key (2) to the terminal device (5, 6) if it is not located on another mobile terminal device (5, 6) of another user (3, 4).
Citation Information
Patent Citations
Method for establishing a communication link between a new vehicle key and a vehicle, and system for executing the method
DE102023001311B3