Method for improving the release of a digital key, device, vehicle and computer program
Displaying invite data as a QR code on the owner device enhances the security of digital key exchange by enabling secure, proximity-based access, addressing the vulnerabilities of messaging applications in existing systems.
Patent Information
- Application Number
- DE112022008089
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-12-06
- Publication Date
- 2025-10-02
AI Technical Summary
The use of messaging applications for digital key release is uncertain and prone to man-in-the-middle attacks, compromising the security of the digital key exchange process.
Displaying invite data in the form of a QR code on the owner device, allowing the friend device to scan and access the invite data directly, thereby eliminating the need for proprietary messaging apps and enhancing security.
This method improves the security of digital key release by preventing man-in-the-middle attacks and ensuring secure, proximity-based key exchange without relying on uncertain messaging channels.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The present disclosure relates to the field of digital identity authorization. Embodiments relate to methods for improving the release of a digital key, a device, a vehicle, and a computer program.
[0002] The Digital Car Key solution defined in the Car Connectivity Consortium (CCC) Standard Release 3, Version 1.0.11 [1] standardizes an access system consisting of: a) a smartphone and software that i) carry a digital key embedded in secure memory on the smartphone; ii) provide interfaces from the secure storage to the smartphone operating system; and iii) provide interfaces from the smartphone operating system to other applications running on the smartphone (e.g. an app from the vehicle's original equipment manufacturer); (b) a vehicle that enables holders of a digital key to operate certain vehicle functionalities; and c) Backend systems that connect smart devices and vehicles, enabling the release and management of digital keys and the provision of additional services.
[0003] Digital keys for a specific vehicle can only be released by the owner key of that specific vehicle. The owner's public key is known to the vehicle through the owner pairing process. Key release is a multi-step process in which the owner (e.g., using an owner's user device, also called an owner device) first configures the parameters of the digital key to be created ("key creation request") and then transmits it to the "friend" (e.g., a friend's user device who is to be allowed to use the vehicle, also called a friend device). Releasing the digital key can be done as follows: 1. The user in possession of the Owner Device initiates the release process on the Owner Device; 2. A “mailbox” containing the key creation data is created and encrypted by the owner device on a relay server; 3. An “invitation” consisting of a link to the mailbox (2.) and an encryption token is created on the owner device; 4. The invitation is sent to the friend device using a messaging application, the messaging application being chosen by the user initiating the sharing process; 5. The invitation is received on the sharee's friend device; 6. The release recipient “accepts” the invitation to initiate the process of installing the digital key on their friend device. and 7. Further steps in the release process are required, such as exporting the endpoint certificate and confirming the key release.
[0004] However, using a messaging application can be insecure (man-in-the-middle attacks, identity spoofing). Therefore, there may be a need to improve the invitation exchange.
[0005] It is therefore a result that releasing a digital key by displaying shared data indicative of invitation data. The invitation data is indicative of key creation data. By displaying the shared data, multiple user devices in close physical proximity can exchange or access the invitation data. Messaging applications can be cumbersome and potentially insecure, and therefore, releasing the digital key can be improved by displaying the shared data. The owner device can display the shared data so that the friend device can scan the shared data. In this way, for example, the security for releasing the digital key can be increased.
[0006] Examples provide a method for unlocking a digital key, comprising generating invitation data indicative of key creation data. The method further comprises obtaining unlock data indicative of a desired unlock of the key creation data. The method further comprises generating unlocked data indicative of the invitation data from the unlock data and displaying the unlocked data. By obtaining the unlock data, a desired step for unlocking the invitation data can be determined. Therefore, unlocked data can be generated from the unlock data. By displaying the unlocked data to the user, for example, a user of the friend device can receive information indicative of the invitation data. In this way, the owner device can provide the invitation data to the friend device in an enhanced manner.
[0007] In one example, the method may further comprise generating the key creation data and transmitting the key creation data to a server. Furthermore, the shared data may be indicative of an address of the server, e.g., a URL address and a URL link. By transmitting the invitation data to the server, it may be ensured that the invitation data is stored in a secure location, e.g., a backend of a vehicle original equipment manufacturer. In this way, the friend device can receive the information needed to access the invitation data from a reliable source.
[0008] In one example, the generated shared data is a QR code. This can facilitate reading of the shared data by the friend device.
[0009] In one example, the method may further include preventing screenshots while viewing the shared data. This may increase the security of the shared data.
[0010] In one example, the method may further include transmitting information about a use of the shared data to a vehicle. This allows the vehicle to receive information to decide whether or not to trust the digital key released using the shared data.
[0011] In one example, the sharing data may be obtained by receiving the desired sharing from a user device (friend device), receiving the desired sharing from an input from the user of an owner user device (owner device), and / or determining the location of the user device. In this way, displaying the shared data may be initiated when needed.
[0012] Examples provide a method that includes reading shared data displayed on the owner user device to generate a digital key for the friend. Thus, the friend device can receive the shared data indicative of the invitation data in an enhanced manner.
[0013] In one example, the method may further comprise transmitting release data indicative of a desired release of key creation data to the owner user device. In this way, the friend device may transmit information about a desired release to the owner user device.
[0014] Examples relate to a device comprising an interface circuit configured to communicate with the owner user device or friend user device, and a processing circuit configured to perform a method as described above. Examples relate to a vehicle comprising a device as described above.
[0015] Examples further relate to a computer program having a program code for carrying out the method described above when the computer program is executed on a computer, a processor or a programmable hardware component.
[0016] Some examples of devices, methods and / or computer programs are described below by way of example only and with reference to the accompanying figures, in which Fig. 1 shows an example of a method for releasing a digital key; Fig. 2 shows another example of a method for releasing a digital key; and Fig. 3 shows a block diagram of an example of a device for a vehicle.
[0017] The term "or," as used herein, refers to a non-exclusive or, unless otherwise specified (e.g., "or else" or "or alternatively"). Furthermore, terms used herein to describe a relationship between elements should be broadly construed to include a direct relationship or the presence of intervening elements, unless otherwise specified. For example, when an element is described as being "connected" or "coupled" to another element, the element may be directly connected or coupled to the other element, or there may be intervening elements. Conversely, when an element is described as being "directly connected" or "directly coupled" to another element, no intervening elements are present. Words such as "between," "adjacent," and the like should be construed in a similar manner.
[0018] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of embodiments. The singular forms "a," "an," and "the," as used herein, are intended to include the plural forms unless the context clearly indicates otherwise. Further, it is to be understood that the terms "comprises," "comprising," "includes," or "including," when used herein, indicate the presence of specified features, integers, steps, acts, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, acts, elements, components, or groups thereof.
[0019] Unless otherwise specified, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art, including embodiments. It is further understood that terms, e.g., those defined in commonly used dictionaries, should be interpreted to have a meaning consistent with their meaning in the context of the relevant technology and should not be interpreted in an idealized or overly formal sense unless expressly defined herein.
[0020] Fig. Figure 1 shows an example of a method 100 for releasing a digital key. The method 100 can be performed by an owner user device (also called an owner device). The method 100 includes generating 110 invitation data indicative of key creation data. The invitation data includes relevant data for cross-platform sharing as described in [1].
[0021] Furthermore, the method 100 includes obtaining 120 release data indicative of a desired release of the key creation data. The desired release may indicate whether the release of a digital key can be performed by transmitting a message and / or displaying information.
[0022] The method 100 further includes generating 130 shared data indicative of the invitation data based on the shared data. The shared data is for sharing with the friend device. The method 100 further includes displaying 140 the shared data. By displaying 140 the shared data, the friend device can receive information, e.g., scan, to evaluate the invitation data.
[0023] By obtaining the release data, a desired step for releasing the invitation data can be determined. Therefore, released data can be generated based on the release data. By displaying the released data to the user, for example, a user of the friend device can receive information indicative of the invitation data. In this way, the owner device can provide the invitation data to the friend device in an improved manner.
[0024] By displaying 140 the shared data, the security of cross-platform sharing can be increased. Cross-platform sharing can be a sharing process without using proprietary messaging mechanisms of a user device's original equipment manufacturer. In contrast, [1] discloses in Chapter 11.3, Communication Channel, that invitation data can only be sent via any messaging or chat channel. However, sending the invitation data through a messaging app or chat channel depends on the specific messaging app used in the sharing process and, in particular, may not prevent attacks such as a man-in-the-middle attack. Allowing the owner device to display the shared data allows only a friend device located in proximity to the owner device to receive the shared data. This can prevent the man-in-the-middle attack.
[0025] In one example, the method 100 may further comprise generating the key creation data and transmitting the key creation data to a server. Furthermore, the shared data may be indicative of an address of the server, e.g., a URL address and a URL link. As described in [1], during cross-platform sharing, the invitation data is transmitted to a (relay) server, e.g., a backend of a vehicle original equipment manufacturer. The shared data may include information about a storage location of the invitation data. Therefore, by transmitting the invitation data to the (relay) server and displaying the shared data, the invitation data may be evaluated by the friend device by reading the storage location and connecting to the (relay) server.
[0026] In one example, the generated shared data is a QR code. Therefore, the shared data can be displayed in a format that could be easily read by the friend device. This could improve the sharing of the shared data.
[0027] In one example, method 100 may further include transmitting information about usage of the shared data to a vehicle (e.g., a communication device of the vehicle such as a central control unit). The vehicle may be one to which the owner of the owner user device wishes to grant access to a friend. For example, the owner of the user device may transmit information about usage of a QR code to the vehicle. The information may be cryptographically secured. In this way, the vehicle can decide whether to entrust the digital key shared with the QR code without further verification.
[0028] In one example, method 100 may further include preventing screenshots while viewing the shared data. This may ensure that the shared data is not shared in an undesirable manner. Thus, the shared data can only be read by a friend device in proximity to the owner device.
[0029] In one example, the sharing data may be obtained by receiving the desired sharing from a user device (friend device), receiving the desired sharing from an input from the user of an owner user device (owner device), and / or determining the location of the user device. In this way, displaying the shared data may be initiated when needed. For example, the owner device may determine a location of the friend device. When the friend device is within a certain distance of the owner device, the owner device may initiate displaying 140 of the shared data. Alternatively or optionally, the friend device may transmit a request to display the shared data to the owner device. Alternatively or optionally, a user of the owner device may select displaying 140 of the shared data.In this way, the owner can initiate the display 140 if necessary.
[0030] For example, a user of the owner device may choose to perform a QR code-based cross-platform close-to-home digital key sharing. Shared data, including a QR code encoding the server's invitation URL, may be generated by the owner device and displayed on a user interface. The user of the friend device may read / scan the QR code with the friend device. The friend device may identify the invitation URL as a digital key invitation and connect to the server to receive the invitation data. In this way, steps 4 and 5 described above and defined in [1] may be replaced and / or extended to increase the security of sharing a digital key.
[0031] In general, the owner device may be any device capable of communicating wirelessly. In particular, however, the owner device may be a mobile user device, e.g., a user device capable of being carried around by a user. For example, the owner device may be a user terminal or a user device within the meaning of the relevant communication standards used for mobile communication. For example, the owner device may be a mobile phone such as a smartphone or another type of mobile communication device such as a smartwatch, a laptop computer, a tablet computer, or standalone augmented reality glasses.
[0032] More details and aspects are mentioned in connection with the embodiments described below. Fig. 1 may comprise one or more optional additional features corresponding to one or more aspects related to the proposed concept or one or more examples described below (e.g. Fig. 2 to 3) are mentioned.
[0033] Fig. 2 shows another example of a method 200 for releasing a digital key. The method 200 may be performed by a friend device. The method 200 includes reading released data displayed on the owner user device to generate a digital key for the friend. In this way, the friend device may receive the released data indicative of the invitation data in an enhanced manner. The method 200 may be performed by a friend device, which may be a counterpart to the owner device that has the Fig. 1 described procedure.
[0034] In one example, the method may further comprise transmitting release data indicative of a desired release of key creation data to the owner user device. In this way, the friend device may transmit information about a desired release to the owner user device. For example, as described above, the friend device may transmit a request to the owner device to trigger a display of the released data. The request may comprise release data.
[0035] In general, the friend device may be any device capable of communicating wirelessly. In particular, however, the friend device may be a mobile user device, e.g., a user device capable of being carried around by a user. For example, the friend device may be a user terminal or a user device in the sense of the relevant communication standards used for mobile communication. For example, the friend device may be a mobile phone such as a smartphone or another type of mobile communication device such as a smartwatch, a laptop computer, a tablet computer, or standalone augmented reality glasses.
[0036] More details and aspects are mentioned in connection with the embodiments described above and / or below. Fig. The example shown in Figure 2 may comprise one or more optional additional features corresponding to one or more aspects related to the proposed concept or one or more of the above (e.g. Fig. 1) and / or below (e.g. Fig. 3) examples are mentioned.
[0037] Fig. 3 shows a block diagram of an example of a device 30 for a vehicle 40. The device 30 comprises an interface circuit 32 configured to communicate with the owner user device or friend user device, and a processing circuit 34 configured to perform a method as described above, e.g. the method for the owner user device as described with reference to Fig. 1, or the method for the friend user device as described with reference to Fig. 2 described.
[0038] The vehicle 40 may, for example, be a land vehicle such as a road vehicle, a passenger car, an automobile, an off-road vehicle, a motor vehicle, a bus, a robo-taxis, a delivery van, a truck, or a lorry. Alternatively, the vehicle 40 may be another type of vehicle, such as a train, a subway, a boat, or a ship. For example, the proposed concept can be applied to public transport (trains, buses) and future mobility means (e.g., robo-taxis).
[0039] As in Fig. 3, the respective interface circuit 32 is coupled to the respective processing circuit 34 on the device 30. In examples, the processing circuit 34 may be implemented using one or more processing units, one or more processing devices, any processing means such as a processor, a computer, or a programmable hardware component operable with appropriate software. Similarly, the described functions of the processing circuit 34 may equally well be implemented in software that is then executed on one or more programmable hardware components. Such hardware components may include a general-purpose processor, a digital signal processor (DSP), a microcontroller, etc.The processing circuit 34 is adapted to control the interface circuit 32 such that data transmissions via the interface circuit 32 and / or any interactions in which the interface circuit 32 may be involved can be controlled by the processing circuit 34.
[0040] In one embodiment, the device 30 may comprise a memory and at least one processing circuit 34 operatively coupled to the memory and configured to perform the method described above.
[0041] In examples, interface circuitry 32 may correspond to any means for acquiring, receiving, transmitting, or providing analog or digital signals or information, e.g., any connectors, contacts, pins, registers, input ports, output ports, conductors, traces, etc., that enable the provision or acquiring of a signal or information. Interface circuitry 32 may be wireless or wired, and may be configured to communicate, e.g., transmit or receive, signals or information with other internal or external components.
[0042] The device 30 may be a computer, a processor, a controller, a (field) programmable logic array ((F)PLA), a (field) programmable gate array ((F)PGA), a graphics processing unit (GPU), an application-specific integrated circuit (ASIC), integrated circuit (IC), or a system-on-chip (SoC).
[0043] More details and aspects are mentioned in connection with the described embodiments. Fig. The example shown in Figure 3 may comprise one or more optional additional features corresponding to one or more aspects related to the proposed concept or one or more examples described above (e.g. Fig. 1 to 2) are mentioned.
[0044] The aspects and features described with respect to a particular one of the previous examples may also be combined with one or more of the further examples to replace an identical or similar feature of that further example or to additionally introduce the features into the further example.
[0045] Examples may further be or refer to a (computer) program that includes program code for performing one or more of the above methods when the program is executed on a computer, processor, or other programmable hardware component. Therefore, the steps, acts, or processes of various of the methods described above may also be performed by programmed computers, processors, or other programmable hardware components. Examples may also include program storage devices, such as digital data storage media, that are machine-, processor-, or computer-readable and encode and / or contain machine-executable, processor-executable, or computer-executable programs and instructions.Program storage devices may be or include, for example, digital storage devices, magnetic storage media such as magnetic disks and magnetic tapes, hard disk drives, or optically readable digital data storage media. Other examples may also include computers, processors, controllers, (field-)programmable logic arrays ((F)PLAs), (field-)programmable gate arrays ((F)PGAs), graphics processing units (GPUs), application-specific integrated circuits (ASICs), integrated circuits (ICs), or system-on-a-chip systems (SoCs) programmed to perform the steps of the methods described above.
[0046] It is further understood that the disclosure of multiple steps, processes, operations, or functions disclosed in the description or claims should not be construed as necessarily requiring those operations to be performed in the described order, unless expressly stated in the particular case or required for technical reasons. Therefore, the foregoing description does not limit the performance of multiple steps or functions to any particular order. Furthermore, in further examples, a single step, function, process, or operation may include and / or be divided into multiple sub-steps, functions, processes, or operations.
[0047] Where some aspects are described in relation to a device or system, these aspects should also be understood as a description of the corresponding method. For example, a block, device, or functional aspect of the device or system may correspond to a feature, such as a method step, of the corresponding method. Accordingly, aspects described in relation to a method should also be understood as a description of a corresponding block, element, property, or functional feature of a corresponding device or system.
[0048] Where some aspects have been described with reference to a device or system, these aspects should also be understood as a description of the corresponding method, and vice versa. For example, a block, device, or functional aspect of the device or system may correspond to a feature, such as a method step, of the corresponding method. Accordingly, aspects described in connection with a method should also be understood as a description of a corresponding block, element, property, or functional feature of a corresponding device or system.
[0049] The following claims are hereby incorporated into the detailed description, and each claim may stand on its own as a separate example. It should also be noted that although a dependent claim in the claims refers to a particular combination with one or more other claims, other examples may include a combination of the dependent claim with the subject matter of any other dependent or independent claim. Such combinations are hereby expressly contemplated unless it is stated in a particular case that a particular combination is not intended. Furthermore, features of one claim should also be included for any other independent claim, even if that claim is not directly defined as dependent on that other independent claim.
[0050] The aspects and features described with respect to a particular one of the previous examples may also be combined with one or more of the further examples to replace an identical or similar feature of that further example or to additionally introduce the features into the further example. Reference symbol 30 furnishings 32 interface circuit 34 Processing circuit 40 vehicles 100 Methods to Improve Digital Key Release 110 Generating invitation data 120 Obtaining release data 130 Creating shared data 140 Viewing shared data 200 Methods for Improving the Release of a Digital Key 210 Reading shared data
Claims
[1] A method (100) for improving the release of a digital key, comprising: generating (110) invitation data indicative of key creation data; Obtaining (120) release data indicative of a desired release of the key creation data; Generating (130) released data indicative of the invitation data from the release data; and View (140) of shared data. [2] The method (100) of claim 1, further comprising: Generating the key creation data; and Transferring the key creation data to a server; where the released data is representative of an address of the server. [3] Method (100) according to one of the preceding claims, wherein the generated released data is a QR code. [4] Method (100) according to one of the preceding claims, further comprising transmitting information about a use of the released data to a vehicle. [5] The method (100) of any preceding claim, wherein the release data is obtained by at least one of receiving the desired release from a user device, receiving the desired release from an input from a user of the user device, or determining the location of the user device. [6] A method (200) for enhancing the sharing of a digital key, comprising reading (210) shared data displayed on the owner user device to generate a digital key for the friend. [7] The method (200) of claim 6, further comprising transmitting release data indicative of a desired release of key creation data to the owner user device. [8] Facility (30) comprising: an interface circuit (32) configured to communicate with at least one of a communication device, a user device, or backend; and a processing circuit (34) designed to carry out a method according to one of the preceding claims. [9] Vehicle comprising the device according to claim 8. [10] Computer program with a program code for carrying out the method (100) according to claims 1 to 8 when the computer program is executed on a computer, a processor or a programmable hardware component.