METHOD FOR CONTROLLING ACCESS TO ELECTRONICALLY CONTROLLED EQUIPMENT
Patent Information
- Application Number
- DE502017016887
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2016-03-11
- Filing Date
- 2017-01-16
- Publication Date
- 2025-06-26
- Estimated Expiration
- 2037-01-16
AI Technical Summary
Existing systems for managing access to electronically controllable devices, such as vehicles, often rely on central databases and wireless connections, which can be unreliable, especially in areas with limited network access.
A method where a central control platform generates a signed and encrypted data container that is transmitted to a mobile communication device, which then transfers it to the access control unit of the electronically controllable device, ensuring secure and reliable data transfer even without direct network access.
This solution ensures secure and flexible management of access privileges, allowing for updates and configurations of access control devices even in areas with limited network connectivity, thereby enhancing the reliability and security of access control systems.
Description
[0001] The invention relates to a system and a method for controlling user access to electronically controllable devices, in particular vehicles. In particular, the invention relates to a system and a method in which access privileges to electronically controllable devices can be distributed and managed among individuals.
[0002] The management of access rights or user rights can be found in many areas of technology. For example, complex rights hierarchies and schemes exist in the management of access privileges in computer systems. In this case, an individual who identifies themselves to the computer system using, for example, a secret identifier or biometric data is granted access to the computer system's services or files. However, if the assigned rights or privileges are insufficient to perform a requested action, this is prevented by technical measures.
[0003] In locking systems for vehicles and buildings, a locking device is often identified for access control purposes in order to check access to a function, such as access to the vehicle or building. It is assumed that the holder of the locking device is also the authorized person to request the respective function. Similar concepts can be found particularly in the area of vehicle locking systems, particularly keyless entry and keyless go systems. There, a user carries a vehicle key known as an ID transmitter. This ID transmitter contains coded information that legitimizes the ID transmitter's (not necessarily the holder of the ID transmitter) authorization to perform functions with a vehicle. Therefore, if the ID transmitter is given to another user, that user is also able to access and operate the vehicle's functions using the ID transmitter.
[0004] In the field of vehicle access systems, numerous different management systems are known for allowing access to vehicles. For example, US 2013 / 0259232 A1 describes a system for pairing a mobile phone with a vehicle in order to control vehicle functions with the mobile phone.
[0005] DE 10 2011 078 018 A1 describes another system for executing vehicle functions, whereby a telematics center carries out part of the communication with the vehicle.
[0006] US 2012 / 0164989 relates to another method and system for a wireless locking function of a vehicle.
[0007] EP 1 910 134 B1 describes a system with a central administration that distributes data packets as keys to mobile communication devices.
[0008] The document WO 2007 / 009453 A2 apparently describes a rights management method that uses a central server for rights management.
[0009] WO 2011 / 109460 A2 describes access control procedures for charging stations and hotel room locks.
[0010] In known systems and methods for vehicle management and leasing, a central control platform assumes central rights management and control functions. The central control platform is operated by a lessor or other manager of a vehicle pool and is equipped with information on the privileges (rights) of identified users. This central control platform can, for example, be implemented as a database connected to a data network. A communication link can be established from remote locations to the central control platform via the data network (internet, mobile network, etc.).
[0011] On the vehicle side, to which access or the granting of privileges is to be regulated, a second component in the form of a technical access control unit is provided, which can restrict or enable access to functions of the physical unit. In the case of a vehicle, for example, an access control unit is coupled to the vehicle system in such a way that the access control unit can specifically enable or prevent locking functions, engine start, or other functions. This device can be coupled to communication means for wireless communication in order to connect to the central control platform and exchange data. These communication means include devices that allow a wireless connection via existing communication networks, in particular via mobile radio networks.However, this connection is not always possible, particularly due to poor conditions for establishing communication. Since the invention does not rely on this connection option, it will not be discussed further.
[0012] As a further component of the system and method, a mobile communication device is provided as part of the system, which in turn can establish a communication link with both the central control platform and the access control unit on the electronically controllable device (e.g., a vehicle) in order to exchange information. This mobile communication device can be implemented in a smartphone. The mobile communication device is provided with associated application software, which handles communication with the central control platform and allows user interaction. A communication link can also be established between the mobile access device and the access control unit of the electronically controllable device. This occurs, for example, through a wireless connection according to a wireless network standard, by means of a Bluetooth interface, or via near-field communication, e.g.,an NFC interface.
[0013] In such an access method, a relationship is established regarding communication and data transport, in which, on the one hand, the central control platform can establish a communication link with the mobile access device, and, on the other hand, the mobile communication device can connect with the access control unit for data exchange. The user interacts with the mobile access device.
[0014] Granting access, for example, when renting a vehicle from a rental pool, occurs as follows: Under the control of the user, the mobile communication device can enter into data communication with the central control platform. This occurs, for example, when an application from a rental car company is called up on the user's mobile access device. The central control platform provides the mobile access device with information in a dialog that enables authentication with the access control unit of a physical unit. This can, for example, be a certificate issued and signed by the central control platform.
[0015] When a booking is made on the central platform, a confirmation is sent to the mobile access device via a response. The central control platform also contacts the access control unit of the booked vehicle via a separate connection and saves the booking in the configuration.
[0016] This way, the mobile communication device and the access control unit are prepared for each other. A user can then use their mobile access device to authenticate themselves to the corresponding access control unit, which uses the data received from the central platform in its own database to verify the booking.
[0017] The central platform ensures that both components, namely the mobile communication device and the vehicle's access control unit, receive the booking data directly from the central platform. Since the central control platform is trustworthy, a high level of security is guaranteed.
[0018] However, some of the known systems and methods of this type, which enable access to technical, electronically controllable devices, have disadvantages. For example, systems with a central database for rights management, in particular, require that the managed devices to which access is to be granted or denied be accessible via wireless connections. However, this is not always guaranteed, for example, if a vehicle is parked in a garage with limited reception or if a managed device does not have a constantly available connection to a data transport network.
[0019] The object of the invention is to provide a secure and flexible system and method to enable privilege management for access to electronically controllable units, in particular vehicles, at any time.
[0020] This object is achieved by a method having the features of patent claim 1.
[0021] According to the invention, the central platform not only sends the data intended for the mobile access device regarding a completed booking. This data is readable in the mobile access device and transferable to the access control device when the user couples the mobile access device to the access control device of the electronically controllable device, in accordance with the invention, a vehicle. According to the invention, the central control platform also transmits at least one data container to the mobile communication device, which is signed and possibly encrypted and cannot be changed in the mobile access device.
[0022] The invention provides for a signature of the data container or the data in the data container by the central control platform so that the access control unit can verify the integrity and origin of the data in the data container. Manipulation of the data en route between the central control platform and the access control device is thus prevented. The signature by the central control platform is verified using certificates stored in the access control unit. The access control unit has stored certificates for this purpose. These were stored in a secure environment, e.g., by the manufacturer or administrator. This concept is familiar, for example, from Internet browsers, which provide information for verifying certificates from numerous certification authorities upon installation.It is therefore technically almost impossible to change the data, and the security of both the integrity of the data and its origin from the authorized central control platform is ensured.
[0023] Encryption of the data in the container can be achieved, in particular, using symmetric or asymmetric encryption, whereby only the central control platform and the access control unit on the electronically controllable device have the necessary keys. Encryption is achieved, in particular, using an individual key for the respective access control device. Decryption is then only possible in the addressed access control device for which the central control platform performed the encryption.
[0024] In particular, the data container can be encrypted with one of the access control unit's public keys so that the access control unit can decode the data container after receiving it using a stored private key.
[0025] According to the invention, the mobile communications device is used as a transport medium for this data container, without the mobile communications device having access to the container's contents. The purpose of this measure is to allow access rights, booking information, and other information for configuring the access control device to be transported in the inaccessible data container, which the access control device would otherwise receive directly from the central platform. However, if this direct reception is not possible, e.g., because the electronically controllable device is not coupled to a data transmission network or, if the electronically controllable device is a vehicle, the vehicle is parked in an inaccessible location for communication, the mobile communications device brings the required data in the protected container.The protected container can contain configuration data as well as program updates.
[0026] Once the mobile communications device connects to the access control unit of the electronically controllable device, the container can be transferred to the access control unit. There, it is decrypted, verified, and processed. During this process, for example, the stored user rights in the access control unit are updated. The authorization of the user who is connected to the mobile access device and the access control unit can then be verified.
[0027] This process can be completely transparent for the user. For example, the user books a vehicle using a rental car provider's application. This occurs through communication between the application on the mobile access device and the central platform. After the booking has been verified and a specific vehicle has been assigned, the central control platform checks the vehicle's accessibility via a mobile network. If it is reachable, the booking information is transmitted. If it is not reachable, the central control platform packs the booking information into a data container that is encrypted with a unique key from the vehicle's access control unit and then signs it. This data container is transmitted back to the user's mobile communication device, along with the booking confirmation and readable booking information.
[0028] The user now approaches the vehicle with their mobile access device and initiates an opening dialog. However, if no booking information is available in the access control unit because the booking information could not be updated via connection to the central platform, the encrypted container is transferred in the opening dialog. This container is decrypted in the vehicle's access control unit, where the private key for decryption is stored.
[0029] As explained above, the signature of the container or the data stored therein is verified by the central control platform using stored certificates. The access control unit has stored certificates for this purpose. After successful verification of the certificate, the booking information is read and stored in the system. The user's access authorization can then be verified.
[0030] It is essential that the contents of the data container in the mobile access device are never accessible, or at least cannot be modified without destroying the signature. The container is used exclusively for data transport. This allows the configuration and programming of the access control device to be updated even without a direct connection between the central platform and the access control device. This allows bookings for vehicles that are inaccessible to the central control platform.
[0031] The described method is applicable not only to vehicles according to the invention, but also, although not claimed, to electronically controllable physical devices in general. This may include, for example, access systems for buildings or locking systems for other vehicles. It is then possible to update access systems with reduced connection to data transport networks via users' mobile access devices.
[0032] In a preferred embodiment of the invention, the central platform packs all information for updating the access control device into the protected data container. This means that when a user makes a booking on the central platform, a complete set of data for updating the access control device is transmitted to their mobile communication device. To this end, the central control platform checks, upon receipt of an incoming booking, when there was last direct contact with the vehicle in question. All booking information and configuration data that have not yet been transmitted to the vehicle (e.g., cancellations, etc.) are then packed into the protected data container, allowing the user to perform a complete update of the vehicle with their mobile access device as soon as they connect to the vehicle's access control device.In this way, the access control facility receives a complete, up-to-date set of rights for the existing bookings.
[0033] It is particularly advantageous if the container also contains a timestamp, so that upon transmission to the access control device and after decryption, it can be determined whether a decrypted data update is more recent than an already installed update. This is useful, for example, if updates have been transmitted to multiple booking users.
[0034] Alternatively or additionally, the data container can also contain a numbering system that provides information about the chronological creation of the data. This also allows the access control unit to check whether stored data is current or whether the data from the container should be used for updating. Furthermore, such a numbering system can prevent accidental or malicious re-entry of data from a previously used or expired container. The numbering system is stored in the access control unit so that a previously accepted container is not accepted again.
[0035] In one embodiment of the invention, after booking a vehicle, the central platform attempts to contact the mobile access device if the booking information for the booked vehicle changes. Thus, if a user books a vehicle for the following day, the data container can be updated after a few hours, for example, through communication between the central platform and an application on the mobile access device, e.g., to transmit additional bookings for the following days to the vehicle.
[0036] The described concept can, in principle, replace the direct data transmission from the central platform to the access control device. However, it can also complement methods that, according to the invention, initially provide for direct transmission during operation and, if the transmission fails, provide for an alternative transmission via encrypted transport on a user's device.
[0037] Within the scope of the invention, it is also possible to provide for data transport in the opposite direction, i.e., from the access control device to the central control platform. In this case, the mobile access device is also used as the transport system for the data, with the signature and, if applicable, encryption being performed in the access control device, and the verification of the signature and, if applicable, decryption being performed in the central control platform.
[0038] The invention will now be explained with reference to the accompanying figures.
[0039] Figure 1 shows schematically the information flow between a user, a central management platform and a vehicle for applying an embodiment of the method according to the invention.
[0040] In Figure 1 the three stations are shown as vertical bars, which are used in the method according to the invention.
[0041] The left vertical bar symbolizes a user using a smartphone as a mobile communication device. The middle vertical bar represents the central control platform, which is a central database of a rental car provider connected to the internet. The central database manages vehicle usage rights and authorization information, as well as vehicle data. An application issued and authorized by the operator of the central platform is installed on the user's smartphone. This application is designed to communicate with the central platform.
[0042] The application on the user's smartphone offers a graphical user interface, allowing the user to conveniently enter data and make bookings in the vehicle fleet of the central platform operator. The application can also provide additional functions, such as the recording and comparison of biometric data for verifying user authorization.
[0043] The right vertical bar represents the vehicle with its access control device. The access control device may be integrated into the vehicle during construction as an integral part of the control system. However, it may also be a retrofitted access control device that is coupled to the vehicle control system.
[0044] The user connects to the central platform via the application on their smartphone, which is represented by arrow 1. Various vehicles are offered to the user for rental. The user selects a vehicle to start using at a specified time and for a specified period of use. The user may also have to enter further personal identification data into the application for transmission to the central control platform, possibly also biometric data such as a fingerprint or a facial image. The user is stored in the central platform along with their access rights through a prior registration process. The creation of a user in the central platform is not the subject matter of the invention and is also not relevant for this invention.For this purpose, trusted locations and persons are regularly designated for a one-time, immediate check of the user and the facility in the central system.
[0045] The central control platform verifies the data received in communication 1. This checks the user's basic authorization to rent the given vehicle at the given time. If this check is successful, the central control platform attempts to establish a connection to the vehicle at arrow 2 in order to store the rental data and the user's authorization in its access control device. This arrow is shown broken because the vehicle is located in a location that does not allow mobile communication. The central control platform cannot therefore store the updated booking data in the vehicle's access control device.
[0046] The configuration data for the access control device for the user's booking is then packed into a data container on the central platform, which is encrypted with a key of the vehicle's access control device known to the central platform. It should be clarified in this context that this key of the access control device is only public to the central platform. The concept of asymmetric encryption can be used here. In this exemplary embodiment, it is essential that the encryption is selected at all times so that the data container remains inaccessible on the user's smartphone.Accordingly, the keys are used only for the purpose of encrypting data traffic between the vehicle-mounted access control device and the central platform, and not for data traffic between the mobile phone and the access control device or the mobile phone and the central platform. The required keys were stored in the central platform when the vehicle was equipped with the access control device.
[0047] In addition, the data container 3b is signed by the central platform, with corresponding certificates for verifying the signature being stored in the access control units, which are managed by the central platform.
[0048] The encrypted and signed data container 3b is transmitted to the user, together with readable data 3a, in a joint message 3. The user thus receives a data packet containing a readable data portion, in particular a booking confirmation and identification data for identifying the booking to the access control device. Furthermore, the data container 3b has been transmitted, which is stored in a memory area of the application on the user's smartphone and remains encrypted and unreadable. Viewing the content of message 3b or tampering with it is impossible, since the user and the smartphone do not have the key to the vehicle's access control device.
[0049] This transmission of encrypted data container 3b can be completely transparent for the user, as this container typically only contains a small data volume. In addition to the user's booking, other future bookings for the same vehicle can also be stored in encrypted container 3b.
[0050] The user now moves toward the vehicle, i.e., into the area where communication with the central platform is no longer possible. However, since the user can approach the vehicle, unlike the central platform, they can establish a communication connection, in particular a Bluetooth connection, with the vehicle's access control device and initiate communication. Message 4 transmits the data from data packets 3a and 3b to the vehicle, more specifically to its access control device. Readable data 3a serves to identify the booking, about which the vehicle has not yet been informed, since message 2 could not reach it.
[0051] The access control unit verifies the signature of the received container. This is done using stored certificate information. This information is stored in the access control unit during vehicle manufacture or at a later time in a secure environment. The concept of certificate verification is well known in technology, for example, in the area of internet browsers. If the integrity or origin of the container cannot be successfully verified, the container is discarded. Access to the vehicle is then only possible with the data previously stored in the access control unit.
[0052] If the signature is successfully verified, the system then uses the stored key to decrypt the data container 3b, which contains the updated booking data. This data is stored in the access control device's associated memory, where the vehicle's booking data is stored for retrieval. The current booking is then verified again using the readable data 3a, for example, a booking identification number. The booking can now be verified, and the user is granted access to the vehicle.
[0053] Data container 3b can also contain additional booking data or other cancellation data, as well as programming data, which are recognized as authentic by the access control device in the vehicle. Reprogramming of the access control device in the vehicle is only permitted if the data has been encrypted with a key matching the vehicle control device and only if it has been signed by the central platform.
[0054] The method according to the invention allows booking data in vehicle access control devices to be updated, even if they are not accessible for communication via a communication network with the central platform. Configuration data or data for programming the access control device are transported via a mobile radio device, which is used exclusively as a transport medium without access to the stored data.
Claims
1. A method of controlling access to an electronically controllable device, wherein the electronically controllable device is a vehicle, comprising the steps of: Establishing a communication link between a mobile communication device and a central control platform via a communication network, Creating a booking for an electronically controllable device in the central control platform and transmitting first data for the booking from the central control platform to the mobile communication device, the data being in the form of access information for access to the electronically controllable device and for processing in the mobile communication device, whereby additionally, second data is transmitted from the central control platform to the mobile communication device in a data container, wherein the second data contains booking information, wherein the second data is signed in the central platform prior to transmission and encrypted with an individual key, wherein the individual key is assigned to an access control unit in the electronically controllable device, and wherein the encrypted second data is stored in the mobile communication device, whereby access to the content of the data container in the mobile communication device is not possible at any time, or at least this content cannot be changed without destroying the signature, the mobile communication device for accessing the electronically controllable device is wirelessly coupled to the access control unit of the electronically controllable device, wherein at least the second data and at least a subset of the first data are transmitted to the access control unit, the access control unit decrypts the second data and checks a signature of the second data and, if the check is successful, a configuration of the access control unit is adapted as a function of the decrypted data, the booking information being read out and stored in the system after the signature of the second data has been successfully checked, whereupon an opening authorization of the user can then be verified and with the updated booking information the booking is verified on the basis of the first data and the user is granted access to the electronically controllable device, whereby in operation initially a direct data transmission from the central control platform to the access control unit takes place and in the event of failure alternatively the transmission takes place via the encrypted transport on the mobile communication device.
2. Method according to claim 1, wherein in the second data, in addition to the data of a booking of the mobile communication device, information on further booking processes for the same electronically controllable device is also encrypted.
3. Method according to any one of the preceding claims, wherein the second data includes a timestamp at the time of encryption and wherein the access control unit adjusts the configuration of the access control unit only if the timestamp indicates that the encrypted data is more recent than the existing configuration of the access control unit.
4. Method according to one of the preceding claims, wherein the central control platform establishes a connection with the mobile communication device after the booking has been created and before the electronically controllable device is accessed with the aid of the mobile communication device and replaces the encrypted second data with updated encrypted data.