Method for authenticating a mobile device of a vehicle occupant to a backend service of a vehicle manufacturer, computer-readable medium, system, and vehicle
The method facilitates secure, anonymous access to vehicle manufacturer backend services by establishing an encrypted connection and using temporary access tokens, addressing privacy and convenience issues in existing authentication methods.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- BAYERISCHE MOTOREN WERKE AG
- Filing Date
- 2025-02-11
- Publication Date
- 2026-05-07
AI Technical Summary
Existing vehicle authentication methods require personal user accounts and data collection, compromising privacy and being inconvenient for vehicle occupants accessing vehicle manufacturer backend services.
A method involving an encrypted communication connection between a vehicle occupant's mobile device and the vehicle, generating a temporary access token with driver consent, and authenticating requests using this token without personal data collection, ensuring secure and anonymous access.
Enables efficient, secure, and user-friendly access to vehicle manufacturer backend services without personal accounts, protecting privacy by not requiring personal data and enhancing security through token validation.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a method for authenticating a mobile device belonging to a vehicle occupant with a backend service of a vehicle manufacturer. The invention further relates to a computer-readable medium for authenticating a mobile device belonging to a vehicle occupant with a backend service of a vehicle manufacturer, a system for authenticating a mobile device belonging to a vehicle occupant with a backend service of a vehicle manufacturer, and a vehicle comprising the system for authenticating a mobile device belonging to a vehicle occupant with a backend service of a vehicle manufacturer.
[0002] Modern vehicles are increasingly connected, offering passengers the ability to access vehicle-related data and functions via mobile devices. To use these services, users typically need to authenticate themselves via a user account, which is inconvenient and can compromise privacy. Therefore, there is a need for an authentication method that allows vehicle occupants to anonymously access a vehicle manufacturer's backend service.
[0003] DE 10 2019 116 490 A1 describes a method for assigning a user to a vehicle. The method comprises providing a code at the vehicle, wherein the code is readable by a user's mobile device and includes unique identification information of a SIM card in the vehicle; reading the code provided at the vehicle by the mobile device; sending a request for assigning the user to the vehicle by the mobile device to a central unit, wherein the request includes the read unique identification information of the SIM unit in the vehicle; and assigning the user to the vehicle by the central unit.
[0004] DE 10 2018 209 190 A1 describes a method for assigning a specific motor vehicle to a user account of a specific user. A user's terminal device automatically detects that it is in the motor vehicle and automatically initiates the corresponding assignment process. After receiving a requested user confirmation to continue the assignment process, the terminal device or a communication device in the motor vehicle automatically establishes a data connection to an external assignment server. A user identification and a vehicle identification are automatically transmitted to the assignment server via this data connection. The assignment server then automatically assigns the motor vehicle to the user account based on the transmitted identifications.
[0005] US 2018 / 0375855 A1 relates to a method and a system for authenticating a user to access a service. The method comprises the following: Receiving an authentication token by a vehicle control unit located in a vehicle based on a request for authentication to access the service, the vehicle being in a communication link with a remote server. A token sequence is transmitted by flashing a light device integrated into the vehicle; the token sequence is based on the authentication token. The token sequence is received by a light detector. The server compares the token with the authentication token. If it is determined that the token sequence matches the authentication token, access to the service is granted. The invention also relates to a vehicle that uses the method.
[0006] It is therefore an object of the invention to efficiently improve the authentication of a vehicle occupant's mobile device to a vehicle manufacturer's backend service. In particular, an object of the invention is to make access to a vehicle manufacturer's backend service more efficient for a vehicle occupant.
[0007] This problem is solved by the features of the independent claims. Advantageous embodiments and further developments of the invention result from the dependent claims.
[0008] According to a first aspect, the invention is characterized by a method for authenticating a vehicle occupant's mobile device to a vehicle manufacturer's backend service. The method can be computer-implemented and / or control unit-implemented. The method comprises establishing an encrypted communication connection between the vehicle occupant's mobile device and the vehicle, generating a temporary access token for the occupant's mobile device by the vehicle after establishing the encrypted communication connection, and authenticating a request from the vehicle occupant's mobile device to the vehicle manufacturer's backend service using the generated temporary access token.
[0009] Advantageously, this method efficiently enables anonymous access from a vehicle occupant's mobile device to a vehicle manufacturer's backend service. A temporary access token for accessing the backend service can be automatically generated by the vehicle and provided to the occupant's mobile device after an encrypted connection is established. The occupant does not need a personal user account to access the vehicle manufacturer's backend service. This makes the backend service easier and faster to use. Furthermore, no personal data of the vehicle occupant needs to be collected and / or stored to use the backend service. The occupant's privacy is thus effectively protected.
[0010] According to an advantageous embodiment, establishing the encrypted communication connection between the vehicle occupant's mobile device and the vehicle can include the vehicle receiving consent from the vehicle driver to establish the encrypted communication connection between the occupant's mobile device and the vehicle, and establishing the encrypted connection between the occupant's mobile device and the vehicle if the vehicle driver's consent has been received. This allows a temporary access token for accessing the vehicle manufacturer's backend service to be efficiently generated automatically with the driver's consent.
[0011] According to a further advantageous embodiment, the generation of the temporary access token for the occupant's mobile device by the vehicle after the establishment of the encrypted communication connection between the occupant's mobile device and the vehicle can include the generation of a temporary access token for the occupant's mobile device by the vehicle, wherein the access token comprises a unique identity of the vehicle and one or more access authorizations for a backend service of the vehicle manufacturer, and wherein the one or more access authorizations for the vehicle manufacturer's backend service are linked to the received consent of the vehicle's driver to establish the encrypted communication connection.Furthermore, the generation of the temporary access token for the occupant's mobile device by the vehicle, after establishing an encrypted communication connection between the occupant's mobile device and the vehicle, can include the vehicle determining an asymmetric key pair, signing the generated temporary access token with a private key from the determined asymmetric key pair, determining a certificate chain for the asymmetric key pair, and transmitting the signed access token and the determined certificate chain from the vehicle to the mobile device via the established, encrypted communication connection. This effectively protects the access token against manipulation by the occupant's mobile device. The security of the process can be significantly increased.
[0012] According to a further advantageous embodiment, the generation of the temporary access token for the occupant's mobile device by the vehicle, after establishing the encrypted communication connection between the occupant's mobile device and the vehicle, can further include the vehicle storing the signed access token for the mobile device and transmitting the stored, signed access token and the determined certificate chain from the vehicle to the mobile device via the newly established and encrypted communication connection, provided the signed access token of the mobile device has been stored by the vehicle and the mobile device has established a new encrypted connection with the vehicle. This allows a returning occupant of the vehicle to efficiently obtain a temporary access token for accessing a backend service of the vehicle.
[0013] According to a further advantageous embodiment, authenticating the request from the vehicle occupant's mobile device to the vehicle manufacturer's backend service with the generated temporary access token of the vehicle can involve transmitting the request from the vehicle occupant's mobile device, the signed temporary access token, and the certificate chain from the vehicle occupant's mobile device to a gateway service of a backend server of the vehicle manufacturer, verifying the signed temporary access token with a public key of the asymmetric key pair by the gateway service of the vehicle manufacturer's backend server, and determining a root certificate by the gateway service of the vehicle manufacturer's backend server.and include validating the certificate chain using the determined root certificate by the gateway service of the vehicle manufacturer's backend server. Furthermore, authenticating the request from the vehicle occupant's mobile device to the vehicle manufacturer's backend service with the generated temporary access token of the vehicle can include extracting the vehicle's identity from the signed temporary access token by the gateway service of the vehicle manufacturer's backend server after successful validation of the certificate chain, adding the vehicle's identity to the request from the vehicle occupant's mobile device by the gateway service of the vehicle manufacturer's backend server, and forwarding the request with the added vehicle identity from the gateway service of the vehicle manufacturer's backend server to the vehicle manufacturer's backend server.and include providing a response to the request from the vehicle occupant's mobile device from the vehicle manufacturer's backend server's backend service to the vehicle occupant's mobile device, depending on one or more access permissions of the access token. This allows the mobile device to efficiently use the vehicle manufacturer's backend service. The mobile device occupant does not need a user account or have to provide personal data to access the backend service. The backend service can be used more easily and quickly by the occupant.
[0014] According to another aspect, the invention is characterized by a computer-readable medium for authenticating a mobile device of an occupant of a vehicle to a backend service of a vehicle manufacturer, wherein the computer-readable medium comprises instructions which, when executed on a control unit and / or a computer, perform the method described above.
[0015] According to another aspect, the invention is characterized by a system for authenticating a mobile device of an occupant of a vehicle to a backend service of a vehicle manufacturer, wherein the system is configured to perform the method described above.
[0016] According to another aspect, the invention is characterized by a vehicle comprising the system described above for authenticating a mobile device of an occupant of a vehicle to a backend service of a vehicle manufacturer.
[0017] Further features of the invention will become apparent from the claims, the figures, and the description of the figures. All features and combinations of features mentioned above in the description, as well as those subsequently mentioned in the description of the figures and / or shown in the figures alone, are usable not only in the combinations specified, but also in other combinations or individually.
[0018] A preferred embodiment of the invention is described below with reference to the accompanying drawings. Further details, preferred configurations, and further developments of the invention will be derived from these drawings. Specifically, the drawings schematically illustrate... Fig. 1 an exemplary procedure for authenticating a mobile device of an occupant of a vehicle to a backend service of a vehicle manufacturer, Fig. 2. An exemplary sequence diagram for establishing an encrypted communication connection between a mobile device of a vehicle occupant and the vehicle, and Fig. 3. An example sequence diagram for generating and using a temporary access token.
[0019] In detail, it shows Fig. 1 An exemplary method 100 for authenticating a vehicle occupant's mobile device to a vehicle manufacturer's backend service. Method 100 can establish an encrypted communication link between the vehicle occupant's mobile device and the vehicle 102. The encrypted communication link can be an encrypted wireless communication link. For example, the encrypted communication link can be a wireless communication link using Bluetooth Low Energy and / or WiFi. The encrypted communication link can be authorized by a driver of the vehicle.
[0020] Method 100 can generate a temporary access token for the occupant's mobile device by the vehicle after establishing the encrypted communication connection between the occupant's mobile device and the vehicle.104 The temporary access token can be a JSON Web Token, or JWT for short. By generating the temporary access token, the vehicle can grant one or more temporary access permissions to one or more mobile devices of one or more occupants of the vehicle. Finally, Method 100 can authenticate a request from the occupant's mobile device to the vehicle manufacturer's backend service using the generated temporary access token of the vehicle.106
[0021] Method 100 can provide a secure and user-friendly authentication procedure for one or more occupants of a vehicle. The vehicle itself preferably acts as an authentication instance and can grant temporary access permissions to one or more of its occupants.
[0022] In detail, it shows Fig. 2 An exemplary sequence diagram 200 for establishing 102 an encrypted communication connection between a mobile device 202 of a vehicle occupant and a vehicle 204. The mobile device 202 can establish an encrypted wireless communication connection with the vehicle 204 206. The vehicle 204 can detect whether the established encrypted wireless communication connection is a new encrypted wireless communication connection of a mobile device of a vehicle occupant 204 and provide a message to approve the new encrypted wireless communication connection on a display 208 of the vehicle 204 210. A driver 212 of the vehicle 204 can approve the encrypted wireless communication connection of the mobile device 202 of the vehicle occupant 204 by a user input from the driver 212 on the display 208 214.The display 208 can transmit the user input to the vehicle 216 to authorize the encrypted wireless communication connection of the vehicle occupant's mobile device. The vehicle 204 can then transmit confirmation of the authorized encrypted wireless communication connection to the mobile device 202 218. In other words, the driver must explicitly authorize each new encrypted wireless communication connection from an occupant's mobile device to the vehicle in order to grant that occupant temporary access to the vehicle. After explicitly authorizing each new encrypted wireless communication connection, the vehicle can, as described in... Fig. As described in section 3, a temporary access token can be generated. The generated temporary access token can then be used, as also described in section 3. Fig. 3 described, can be used to utilize a baking service provided by a vehicle manufacturer.
[0023] In detail, it shows Fig.3 An exemplary sequence diagram for generating and using a temporary access token. The mobile device 202 can transmit a message to retrieve a temporary access token from the mobile device 202 to the vehicle 204 via the encrypted wireless communication link 310, which has been authorized by the vehicle's driver. As long as the encrypted wireless communication link authorized by the vehicle's driver exists between the mobile device and the vehicle, the message to retrieve the temporary access token can be transmitted from the mobile device 202 to the vehicle 204. The temporary access token can thereby be retrieved for the first time or retrieved again after a predetermined validity period of the temporary access token has expired. The vehicle 204 can generate the temporary access token 312.The temporary access token can be a JSON Web Token, which includes the identity of the vehicle 204 and one or more permissions for the vehicle occupant to access a backend service of the vehicle manufacturer. The vehicle 204 sends a message to a key store 306 to generate an asymmetric key pair 314 and receives the asymmetric key pair from the key store 306 316. The vehicle 204 can sign the generated temporary access token with a private key from the asymmetric key pair 318. Furthermore, the vehicle can request a certificate chain from the key store 320 and receive the certificate chain from the key store 322. The vehicle 204 can transmit the signed temporary access token and the certificate chain to the mobile device 324. The vehicle manufacturer's backend can use the certificate chain to verify the authenticity of the temporary access token.
[0024] The following steps of sequence diagram 300 describe using the signed temporary access token and certificate chain to authenticate the mobile device 202 to a vehicle manufacturer's backend service 304. The mobile device 202, for example, an app on the mobile device, can transmit the signed temporary access token and certificate chain to a gateway service 302 of the vehicle manufacturer's backend 326. As an alternative to the gateway service 302, another service of the vehicle manufacturer's backend can be used. The vehicle manufacturer's backend can include the gateway service 302 and the backend service 304. The gateway service can receive one or more requests from the mobile device 202. Each request to the backend gateway service can include a request to a backend service 304, the signed temporary access token, and / or the certificate chain.The gateway service 302 can verify the signed temporary access token 328. For example, verifying the signed temporary access token can involve verifying the signature of the signed temporary access token against a public key of the asymmetric key pair. Additionally or alternatively, verifying the signed temporary access token can also involve verifying the validity of the signed temporary access token.
[0025] The gateway service 302 can request a root certificate from a root certificate service 308 330 and receive the root certificate from root certificate service 308 332. Next, the gateway service 302 can validate the certificate chain with the root certificate 334. Then, the gateway service 302 can extract the vehicle's identity from the signed temporary access token 336. The extracted vehicle identity can be added by the gateway service 302 to the request to the backend service 304, and the request can be submitted to the backend service 338. In response to the request to the backend service, the gateway service can receive a response message 340 and forward the response message from the backend service 304 to the mobile device 342.
[0026] Advantageously, the gateway service can forward the mobile device's request to the appropriate backend service and add the vehicle's identity from the signed, temporary access token. This allows the backend service to identify the vehicle the mobile device's request is intended for without the occupant's mobile device being able to manipulate the vehicle's identity. Furthermore, the security of the process can be enhanced by giving the temporary access token a limited validity period. After this period expires, the mobile device must request a new temporary access token from the vehicle. Requesting a new temporary access token from the vehicle can be automated as long as the encrypted communication link between the mobile device and the vehicle is active.As soon as the encrypted communication connection is disconnected by the occupant or the driver revokes authorization for the encrypted communication connection, the mobile device loses access to the vehicle manufacturer's backend service upon expiration of the temporary access token. The driver can continuously monitor this process and grant or revoke access rights as needed. This ensures efficient security.
[0027] Furthermore, the method enables anonymous access by vehicle occupants to one or more backend services without requiring a user account for accessing a backend service. Thus, the method effectively protects user privacy, as no personal data needs to be collected to access a backend service of the vehicle manufacturer. Reference symbol list 100 procedures 102 Establishing an encrypted communication connection 104 Generating a temporary access token 106 Authenticating a request from the mobile device 200 sequence diagram 202 mobile device 204 vehicles 206 Establishing an encrypted, wireless communication link with the vehicle 208 Display 210 Providing a message to authorize a new, encrypted, wireless communication link 212 drivers 214 Approval of the new, encrypted, wireless communication link 216 Transmitting user input to approve the new encrypted wireless communication link to the vehicle 218 Transmitting confirmation of the approved, encrypted, wireless communication connection to the mobile device 300 sequence diagram 302 Gateway Service 304 Backend Service 306 key storage 308 Root Certificate Service 310 Sending a message to retrieve a temporary access token 312 Generating a temporary access token 314 Transmitting a message to generate an asymmetric key pair 316 Receiving an asymmetric key pair 318 Signing the temporary access token 320 requests from a certificate chain 322 Receiving a certificate chain 324 Transmitting the signed, temporary access token and certificate chain 326 Submitting a request for a back service comprising the signed, temporary access token and certificate chain to a gateway service 328 Verifying a signed, temporary access token 330 requests for a root certificate 332 Receiving a root certificate 334 Validating the certificate chain 336 Extracting the vehicle's identity 338 Submitting a request to the backend service 340 Receiving a reply message 342 Sending a reply message
Claims
[1] Method for authenticating a mobile device of an occupant of a vehicle to a backend service of a vehicle manufacturer, the method comprising: Establishing an encrypted communication connection between the vehicle occupant's mobile device and the vehicle; Generating a temporary access token for the occupant's mobile device by the vehicle after establishing the encrypted communication connection between the occupant's mobile device and the vehicle, wherein generating the temporary access token for the occupant's mobile device by the vehicle after establishing the encrypted communication connection between the occupant's mobile device and the vehicle includes: Generating a temporary access token for the vehicle occupant's mobile device by the vehicle, wherein the access token comprises a unique identity of the vehicle and one or more access authorizations for a backend service of the vehicle manufacturer, and wherein one or more access authorizations for the vehicle manufacturer's backend service are linked to the received consent of the vehicle's driver to establish the encrypted communication connection; and Determining an asymmetric key pair by the vehicle; Signing the generated temporary access token with a private key from the determined asymmetric key pair; Determining a certificate chain to the asymmetric key pair by the vehicle; and Transmission of the signed access token and the determined certificate chain from the vehicle to the mobile device via the established, encrypted communication connection; and Authenticating a request from the vehicle occupant's mobile device to the vehicle manufacturer's backend service using the vehicle's generated temporary access token. [2] Method according to claim 1, wherein the establishment of the encrypted communication connection between the mobile device of the occupant of the vehicle and the vehicle comprises: Receiving consent from the vehicle's driver to establish the encrypted communication connection between the vehicle occupant's mobile device and the vehicle; and Establishing the encrypted connection between the vehicle occupant's mobile device and the vehicle, provided the vehicle has received the driver's consent. [3] Method according to any of the preceding claims, wherein the generation of the temporary access token for the occupant's mobile device by the vehicle after the establishment of the encrypted communication connection between the occupant's mobile device and the vehicle further comprises: Storing the signed access token for the mobile device by the vehicle; and If the signed access token of the mobile device was stored by the vehicle and the mobile device established a new encrypted connection with the vehicle: Transmitting the stored, signed access token and the determined certificate chain from the vehicle to the mobile device via the newly established and encrypted communication connection. [4] Method according to any of the preceding claims, wherein the authentication of the request of the vehicle occupant's mobile device to the vehicle manufacturer's backend service with the generated temporary access token of the vehicle comprises: Transmitting the request from the vehicle occupant's mobile device, the signed temporary access token, and the certificate chain from the vehicle occupant's mobile device to a gateway service of a backend server of the vehicle manufacturer; Verification of the signed, temporary access token with a public key of the asymmetric key pair by the gateway service of the vehicle manufacturer's backend server; Determining a root certificate through the gateway service of the vehicle manufacturer's backend server; Validation of the certificate chain using the identified root certificate by the gateway service of the vehicle manufacturer's backend server; Extracting the vehicle's identity from the signed, temporary access token by the gateway service of the vehicle manufacturer's backend server after successful validation of the certificate chain; Adding the vehicle's identity to the request from the vehicle occupant's mobile device via the vehicle manufacturer's backend server gateway service; Transmitting the request with the added vehicle identity from the gateway service of the vehicle manufacturer's backend server to the backend service of the vehicle manufacturer's backend server; and Providing a response to the request from the vehicle occupant's mobile device from the vehicle manufacturer's backend server's backend service to the vehicle occupant's mobile device, depending on one or more access permissions of the access token. [5] Computer-readable medium for authenticating a mobile terminal of an occupant of a vehicle to a backend service of a vehicle manufacturer, wherein the computer-readable medium comprises instructions which, when executed on a control unit and / or a computer, execute the method according to any one of claims 1 to 4. [6] System for authenticating a mobile terminal of an occupant of a vehicle to a backend service of a vehicle manufacturer, wherein the system is configured to perform the method according to any one of claims 1 to 4. [7] Vehicle comprising the system according to claim 6 for authenticating a mobile terminal of an occupant of a vehicle to a backend service of a vehicle manufacturer.
Citation Information
Patent Citations
Procedure for assigning a specific motor vehicle to a user account of a specific user and motor vehicle
DE102018209190A1
Method and system for assigning a user to a vehicle
DE102019116490A1
Method for authenticating a user
US20180375855A1