Concept for providing a key signal or an immobilizer signal for a vehicle
Patent Information
- Application Number
- DE502019013835
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2018-12-27
- Filing Date
- 2019-12-16
- Publication Date
- 2025-09-11
- Estimated Expiration
- 2039-12-16
AI Technical Summary
Existing vehicles, especially those not designed for car-sharing or car-on-demand scenarios, lack secure mechanisms to prevent unauthorized access and use, as they often rely on a vehicle key that can be stolen during a break-in.
A device, referred to as a CDIS box, integrates a key chip with non-manipulable firmware that transmits key or immobilizer signals only after authorization by a central computer via wireless communication, using a mobile device for authentication and cryptographic security to prevent misuse.
The solution provides secure, retrofitable access control for vehicles, preventing unauthorized use and ensuring legitimate users can unlock, lock, and operate the vehicle through a smartphone, meeting legal and insurance requirements.
Description
[0001] The present invention relates to a method for a device for a vehicle, to the device for the vehicle, to a method and a device for a central computer, to a method and a device for a mobile device, and to corresponding computer programs.
[0002] The use of vehicles in a car-sharing (literally: sharing vehicles) or in a car-on-demand (literally: vehicle on demand) scenario is becoming increasingly popular. In this case, the user of the vehicle is often given the opportunity to unlock and start the vehicle using a radio card or a mobile device. In order to use vehicles in such scenarios, it is usually necessary for the vehicles to include security functions to prevent unauthorized opening or starting. These functions are already integrated in some vehicles; however, in vehicles where these scenarios were not considered in the design, it may be necessary to retrofit the corresponding functions. Some providers use an approach in which the vehicle is only opened using a mobile device or radio card, but a vehicle key is stored in the car itself.Since such a vehicle key can also fall into the hands of a vehicle thief in the event of a break-in, one object of this invention is to provide an improved concept that enables the use of vehicles in car-sharing scenarios (also) in vehicles in which such functionalities were not planned from the outset.
[0003] WO 2016 / 054276 A1 discloses integrating a key simulator into a vehicle that can be controlled by a smartphone via the Bluetooth communication protocol. In this case, the user retrieves a secret for using the key simulator from a server and provides this secret to the key simulator via Bluetooth. If this secret matches a secret stored in the key simulator, the user can unlock the vehicle using the key simulator.
[0004] Embodiments create a device for a vehicle. This device, hereinafter also referred to as a CDIS box (Car on Demand Interim Solution), can be used to control a central locking system and / or an immobilizer of the vehicle. This device comprises a key chip, which can be designed similarly to a key chip of a vehicle key, but has (non-manipulable) firmware that only provides the corresponding key signals or immobilizer signals if the corresponding signals have previously been authorized by a central computer via a wireless mobile communication system, for example, by a server of a vehicle manufacturer.Once this authorization has been granted, the key chip is instructed to transmit the appropriate signals to the immobilizer system or central locking system via a wireless communication link, similar to a vehicle key. A mobile device can serve as the trigger, communicating directly with the device via another wireless communication link.
[0005] Embodiments thus provide a method for a device for a vehicle. The device comprises a key chip. The method comprises obtaining information about a release of a key signal and / or an immobilizer signal from a central computer via a wireless communication link and / or mobile communication system. The release of the key signal indicates an enablement of a functionality for unlocking or locking a central locking system of the vehicle by the central computer. The release of the immobilizer signal indicates an enablement of a functionality for deactivating or activating an immobilizer by the central computer. The method further comprises providing a control signal for the key chip based on the information about the release of the key signal or the immobilizer signal.The control signal is configured to enable the key chip to generate (or provide) the key signal or the immobilizer signal. The method further comprises providing, by the key chip, the key signal and / or the immobilizer signal via a wireless communication connection to a central locking system and / or an immobilizer system of the vehicle after receiving the control signal.
[0006] By enabling the key signal and / or the immobilizer signal through the central computer, misuse of the key chip can be prevented. Furthermore, by transmitting the key signal or the immobilizer signal via a wireless communication link, the device can also be used as a retrofit solution in vehicles.
[0007] For example, the key signal can be transmitted via a wireless high-frequency communication link. The immobilizer signal can be transmitted via a wireless low-frequency communication link. This can enable the signals to be transmitted via the communication links also used by a vehicle key.
[0008] The key signal can be similar to a wireless key signal of a vehicle key. The immobilizer signal can be similar to a wireless immobilizer signal of the vehicle key. The key chip can be similar to a key chip of a vehicle key. This allows the device to be provided as a retrofit solution.
[0009] The method further comprises obtaining identity information of a user of the vehicle from a mobile device of the user via another wireless communication connection. Information about enabling the key signal comprises information about a user for whom the key signal and / or the immobilizer signal is to be enabled. The control signal is provided if the information about the user matches the identity information. This can enable the user to authenticate themselves to the device (e.g., the CDIS box) to gain access to the immobilizer and / or central locking functionality.
[0010] For example, the information about the release of the key signal can include information about a time period for which the release of the key signal and / or the immobilizer signal is granted. The control signal can be provided within the time period. This makes it possible to temporarily store the information about the release of the key signal over several booking periods, for example, to enable operation if the device does not have immediate access to the wireless mobile communication system. In some embodiments, the information about the release of the key signal includes cryptographic key information. The identity information can correspond to an encrypted token. The encrypted token can originate from the central computer. The method can further include verifying the encrypted token based on the cryptographic key information.By providing the encrypted token through the central computer, the user's mobile device can be granted access without fear of tampering with the mobile device. Furthermore, if the encrypted token is signed by the mobile device, even theft of the token may be irrelevant.
[0011] The method may further comprise communicating with a user's mobile device via another wireless communication connection. The method may comprise providing the mobile device with access to functions of the central locking system based on the information about the release of the key signal. Alternatively or additionally, the method may comprise providing the mobile device with access to functions of an electric immobilizer based on the information about the release of the immobilizer signal. Alternatively or additionally, the method may comprise providing the mobile device with data from a vehicle communication system of the vehicle. This enables the user to use the vehicle via the mobile device in a car-on-demand scenario.
[0012] For example, the immobilizer signal can be provided to the vehicle's immobilizer system to deactivate the vehicle's immobilizer. The key signal can be provided to the vehicle's central locking system to unlock or lock at least one of the vehicle's doors. The immobilizer signal can be provided to the vehicle's immobilizer system to enable the vehicle to be started. This enables the device to be used as a retrofit solution in a car-on-demand scenario.
[0013] In at least some embodiments, the control signal is provided to the key chip by a control module of the device. Transmission of the control signal by the control module can be cryptographically secured. This makes it possible to cryptographically couple the control module and the key chip in such a way that generation of the control signal by another entity, such as an attacker, is made difficult or impossible.
[0014] Embodiments further provide a method for a central computer. The method comprises providing information about the release of a key signal or an immobilizer signal for a device of a vehicle via a wireless mobile communication system. The release of the key signal indicates the release of a functionality for unlocking or locking a central locking system of the vehicle by the central computer. Alternatively or additionally, the release of the immobilizer signal indicates the release of a functionality for deactivating or activating an immobilizer by the central computer.The release refers to a key signal or an immobilizer signal that is provided to an immobilizer module or a central locking system of the vehicle via a wireless communication link within the vehicle, provided the key signal or immobilizer signal is enabled by the central computer. By enabling the key signal or immobilizer signal by the central computer, misuse of the key chip can be prevented. Furthermore, by transmitting the key signal or immobilizer signal via a wireless communication link, the device can also be used as an aftermarket solution in vehicles.
[0015] For example, the information about the release of the key signal or the immobilizer signal can include cryptographic key information. The method can further comprise providing an encrypted token to a mobile device of a user of the vehicle. The encrypted token and the cryptographic key information can be based on the same cryptographic key. The encrypted token can be provided to the mobile device for forwarding to the vehicle's device. By providing the encrypted token by the central computer, the user's mobile device can be granted access without having to fear tampering with the mobile device. If the encrypted token is also signed by the mobile device, theft of the token can also be irrelevant.
[0016] Embodiments further provide a method for a mobile device. The method comprises providing identity information of a user of a vehicle from the user's mobile device to a device of the vehicle via a wireless communication connection. The identity information is provided to the device of the vehicle for comparison with information about a user for whom a key signal or an immobilizer signal is to be released, so that the key signal or the immobilizer signal is provided to an immobilizer module or a central locking system of the vehicle via a wireless communication connection within the vehicle if the information about the user matches the identity information. By releasing the key signal or the immobilizer signal by the central computer, misuse of the key chip can be prevented.In addition, by transmitting the key signal or the immobilizer signal via a wireless communication connection, the device can also be used as a retrofit solution in vehicles. By providing the identification information, the user of the mobile device can authenticate themselves to the device (e.g., the CDIS box) to gain access to the vehicle.
[0017] For example, the identity information can correspond to an encrypted token. The method can further comprise receiving the encrypted token from a central computer for transmission to the vehicle. By providing the encrypted token to the central computer, the user's mobile device can be granted access without fear of tampering with the mobile device. If the encrypted token is also signed by the mobile device, theft of the token can also be irrelevant.
[0018] Embodiments further provide a computer program for performing one of the methods when the computer program runs on a computer, a processor, or a programmable hardware component.
[0019] Embodiments further provide a device for a vehicle. The device comprises a key chip. The device comprises at least one interface configured for communication via a wireless mobile communication system. The device comprises a control module configured for receiving information about the release of a key signal or an immobilizer signal from a central computer via the wireless mobile communication system. The release of the key signal indicates the release of a functionality for unlocking or locking a central locking system of the vehicle by the central computer. Alternatively or additionally, the release of the immobilizer signal indicates the release of a functionality for deactivating or activating an immobilizer by the central computer.The control module is configured to provide a control signal for the key chip based on the information about the release of the key signal or the immobilizer signal. The control signal is configured to enable the key chip to generate (or provide) the key signal or the immobilizer signal. The key chip is configured to provide the key signal and / or the immobilizer signal via a wireless communication connection to a central locking system and / or an immobilizer system of the vehicle upon receipt of the control signal.
[0020] Embodiments further provide a device for a central computer. The device comprises at least one interface configured for communication via a wireless mobile communication system. The device further comprises a control module configured to provide information about the release of a key signal or an immobilizer signal for a device of a vehicle via the wireless mobile communication system. The release of the key signal indicates the release of a functionality for unlocking or locking a central locking system of the vehicle by the central computer. Alternatively or additionally, the release of the immobilizer signal indicates the release of a functionality for deactivating or activating an immobilizer by the central computer.The release refers to a key signal or an immobilizer signal provided via a wireless communication link within the vehicle to an immobilizer module or a central locking system of the vehicle if the key signal or the immobilizer signal is released by the central computer.
[0021] Embodiments further provide a device for a mobile device. The device comprises at least one interface configured for communication via a wireless communication connection. The device comprises a control module configured to provide identity information of a user of a vehicle from the user's mobile device to a device of the vehicle via the wireless communication connection. The identity information is provided to the device of the vehicle for comparison with information about a user for whom a key signal or an immobilizer signal is to be released, so that the key signal or the immobilizer signal is provided via a wireless communication connection within the vehicle to an immobilizer module or a central locking system of the vehicle if the information about the user matches the identity information.
[0022] Further advantageous embodiments are described in more detail below with reference to the exemplary embodiments shown in the drawings, to which exemplary embodiments are generally not limited. They show: Figs. 1a and 1b show flow diagrams of embodiments of a method for a device for a vehicle; Fig. 1c shows a block diagram of an embodiment of a device for a vehicle; Fig. 2a shows a flow diagram of an embodiment of a method for a central computer; Fig. 2b shows a block diagram of an embodiment of a device for a central computer; Fig. 3a shows a flow diagram of an embodiment of a method for a mobile device; Fig. 3b shows a block diagram of an embodiment of a device for a mobile device; Fig. 4 illustrates a flow of information in a key system; Figs. 5a and 5b show a schematic flow of information in key chips; Fig. 6 shows an integration of a key chip in a CDIS box; and Fig. 7 shows an embodiment of a connection of a key chip.
[0023] Various embodiments will now be described in more detail with reference to the accompanying drawings, in which some embodiments are shown.
[0024] In the following description of the attached figures, which show only a few exemplary embodiments, identical reference numerals may designate identical or comparable components. Furthermore, collective reference numerals may be used for components and objects that appear multiple times in an exemplary embodiment or in a drawing, but are described together with respect to one or more features. Components or objects described with identical or collective reference numerals may be identical with respect to individual, several, or all features, for example, their dimensions, but may also be different, unless the description explicitly or implicitly indicates otherwise.
[0025] Although embodiments are susceptible to various modifications and variations, embodiments are illustrated in the figures as examples and will be described in detail herein. It should be understood, however, that embodiments are not intended to limit the specific forms disclosed, but rather, embodiments are intended to cover all functional and / or structural modifications, equivalents, and alternatives within the scope of the invention. Like reference numerals designate like or similar elements throughout the description of the figures.
[0026] Unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as one of ordinary skill in the art to which the embodiments belong. Furthermore, it should be understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning consistent with their meaning in the context of the relevant art, and should not be interpreted in an idealized or overly formal sense, unless expressly defined herein.
[0027] The Fign. 1a und 1b show flowcharts of embodiments of a method for a device 10 for a vehicle. The device 10 comprises a key chip 12. The device 10 with the key chip 12 is Fig. 1c introduced. The method comprises receiving 110 information about a release of a key signal or an immobilizer signal from a central computer via a wireless mobile communication system. The release of the key signal indicates an enablement of a functionality for unlocking or locking a central locking system of the vehicle by the central computer. Additionally or alternatively, the release of the immobilizer signal indicates an enablement of a functionality for deactivating or activating an immobilizer by the central computer. The method further comprises providing 130 a control signal for the key chip 12 based on the information about the release of the key signal or the immobilizer signal. The control signal is designed to enable the key chip to generate (or provide) the key signal or the immobilizer signal.The immobilizer secret is located, for example, in the key chip and is only released if authorized / released by the central computer. The method further includes providing 140, by the key chip, the key signal and / or the immobilizer signal via a wireless communication connection to a central locking system 50 and / or an immobilizer system 40 of the vehicle after receiving the control signal. The central locking system 50 and the immobilizer system 40 are also described in . Fig. 1c shown.
[0028] Fig. 1c shows a block diagram of an embodiment of a (corresponding) device 10 for a vehicle 100. The device 10 comprises a key chip 12. The device 10 comprises at least one interface 14, designed for communication via a wireless mobile communication system. The device 10 comprises a control module 16, designed to receive information about a release of a key signal or an immobilizer signal from a central computer 200 via the wireless mobile communication system. The control module 16 is coupled to the key chip 12 and to the at least one interface 14. The control module 16 can be designed to carry out the method, for example using the at least one interface and the key chip.The control module is further configured to provide a control signal for the key chip 12 based on the information about the release of the key signal or the immobilizer signal. The control signal is configured to enable the key chip to generate (or provide) the key signal or the immobilizer signal. The key chip 12 is configured to provide the key signal and / or the immobilizer signal via a wireless communication connection to a central locking system 50 and / or an immobilizer system 40 of the vehicle 100 after receiving the control signal. Fig. 1c further shows the vehicle 100 comprising the device 10, the central locking system 50 and the immobilizer system 40.
[0029] The following description refers to both the procedure of Fign. 1a und 1b as well as the device 10 of the Fig. 1c .
[0030] At least parts of the invention relate to device 10. In at least some embodiments, device 10 is a car-on-demand retrofit device (such as a CDIS box) for a vehicle. Device 10 may be an access device 10. Device 10 may enable a user of a car-on-demand service to unlock and operate the vehicle.
[0031] To this end, the method comprises obtaining 110 (e.g., receiving) the information about the release of the key signal or the immobilizer signal from the central computer via the wireless mobile communication system. In at least some embodiments, the wireless mobile communication system is a cellular mobile communication system. The wireless mobile communication system can, for example, be a mobile radio system from the group of Global System for Mobile telecommunications (GSM), General Packet Radio Service (GPRS), Enhanced Data rates for GSM Evolution (EDGE), Universal Mobile Telecommunication System (UMTS), Long Term Evolution (LTE), Long Term Evolution Advanced (LTE-A), and a 5th Generation (5G) mobile radio system. In some embodiments, the information about the release of the key signal can be obtained via a mobile device 300.Mobile device 300 can, for example, temporarily store the information about the release of the key signal or provide a connection to the central computer for device 10. The central computer can, for example, correspond to a server (service computer) or a group of servers. In at least some embodiments, the term "central computer" is used for a group of computers (servers) that cooperate to provide the information about the release of the key signal.
[0032] This group of computers can, for example, include a server of a vehicle manufacturer, a server of a provider of the car-on-demand service, and / or a central trusted authority. In at least some embodiments, the information about the release can be provided through the interaction of the manufacturer's server, the provider's server, and the central trusted authority, for example, the vehicle manufacturer's server.
[0033] The release of the key signal indicates the release of a functionality for unlocking or locking the vehicle's central locking system by the central computer. The release of the immobilizer signal also indicates the release of a functionality for deactivating or activating an immobilizer by the central computer. The release can, for example, refer to device 10. Thus, by releasing the key signal, device 10 can be authorized to provide the key signal (e.g., under certain conditions) (analogous to the immobilizer signal). If the key signal is not released, device 10 (e.g., key chip 12) can be prohibited from providing the key signal (analogous to the immobilizer signal).
[0034] The method further comprises providing 130 the control signal for the key chip 12 based on the information about the release of the key signal or the immobilizer signal. In at least some embodiments, the control signal is provided 130 to the key chip by the control module of the device. Transmission of the control signal can be cryptographically secured by the control module. In other words, the control signal can be cryptographically secured. The control module can be configured to transmit the control signal to the key chip in a cryptographically secured manner. For example, the control module and the key chip can be arranged on the same circuit board. When the control signal is transmitted via printed circuit boards, the control signal can be cryptographically secured. For example, control commands transmitted via the control signal can be cryptographically encrypted or cryptographically signed.The control signal can be cryptographically secured, for example, based on a cryptographic secret. For example, the control module can comprise a Trusted Platform Module (TPM) or a Hardware Security Module (HSM), or have access to such a module. The TPM / HSM can comprise the cryptographic secret.
[0035] The control signal is designed to enable the key chip to generate the key signal or the immobilizer signal. For example, the key chip can be designed to generate the key signal and / or the immobilizer signal only if an (authentic / valid) control signal is provided to the key chip. Authentic in this context means that the control signal truly originates from the device or control module. Valid in this context means that a security feature of the control signal, such as the cryptographic security, is intact. For example, the key chip can include a memory for an immobilizer secret and / or a central locking secret.The key chip may include a security functionality that grants the key chip access to the immobilizer secret and / or the central locking secret (only) if an (authentic / valid) control signal is provided to the key chip. The key chip may be configured to grant the key chip access to the immobilizer secret and / or the central locking secret (only) if an (authentic / valid) control signal is provided to the key chip.
[0036] The method further comprises providing 140, by the key chip, the key signal or the immobilizer signal via a wireless communication link for a central locking system 50 or an immobilizer system 40 of the vehicle after receiving the control signal. Generally, immobilizer signals and key signals are transmitted by a vehicle key in different frequency bands. Key signals are often transmitted in the radio frequency (RF) range around 400 MHz, while immobilizer signals are often transmitted in the low frequency (LF) range around 100 kHz. Thus, the key signal can be transmitted by the key chip via a wireless high-frequency communication link. The immobilizer signal can be transmitted by the key chip via a wireless low-frequency communication link.Both signals can correspond to the signals transmitted by a corresponding vehicle key. For example, the key signal can be similar to (i.e., approximately equivalent to) a wireless key signal of a vehicle key of the vehicle. The immobilizer signal can be similar to (i.e., approximately equivalent to) a wireless immobilizer signal of the vehicle key of the vehicle. "Similar" in this context can refer to a frequency, coding, and / or security functionality of the key signal and / or the immobilizer signal. Furthermore, the key chip can be similar to (i.e., approximately equivalent to) a key chip of a vehicle key of the vehicle. The firmware or programming of the key chip can be an exception.The firmware or programming of the key chip may configure the key chip to provide the key signal and / or the immobilizer signal only if an (authentic / valid) control signal is provided to the key chip.
[0037] The key chip is configured to provide the key signal and / or the immobilizer signal upon receipt of the control signal. The key chip can further be configured to check the control signal to determine the authenticity or validity of the control signal. The key chip can, for example, determine the authenticity or validity of the control signal based on the cryptographic security of the control signal. The key chip can be configured to provide the key signal and / or the immobilizer signal upon receipt of the control signal if the control signal is authentic / valid.
[0038] The key signal and / or the immobilizer signal are provided to the respective systems to gain access to various functionalities of the vehicle. Thus, the immobilizer signal can be provided 140 to the immobilizer system 40 of the vehicle to deactivate (or activate) a vehicle immobilizer. The key signal can be provided 140 to the central locking system 50 of the vehicle to unlock or lock at least one flap (such as a door or a trunk lid) of the vehicle. The immobilizer signal can be provided 140 to the immobilizer system 40 of the vehicle to enable (keyless) starting of the vehicle. If the immobilizer signal is provided to a vehicle immobilizer system that requires a mechanical key for starting, a mechanical key bit (without electronics) can be used for starting.
[0039] In principle, the immobilizer system and / or the central locking system can be remotely controlled by the central computer alone, i.e., the central computer can instruct the device to unlock the vehicle or deactivate the immobilizer. In at least some embodiments, the method further comprises direct communication between the device and a mobile device of a (potential) user of the vehicle. The central computer can authorize the key signal for this user, and the user can authenticate themselves to the vehicle via their mobile device (such as a smartphone (programmable phone), tablet, or a wearable such as a smartwatch (a programmable watch)) and utilize the enabled functionality.
[0040] The procedure can also be used, as in Fig. 1b shown, may include communicating 120 with a mobile device 300 of the user via a further wireless communication connection. The further wireless communication connection may, for example, correspond to a wireless near-field communication connection. For example, the wireless communication connection may be based on Bluetooth, such as Bluetooth Low Energy (BTLE) or near-field communication (NFC). The method may further include providing 150 access to functions of the central locking system for the mobile device based on the information about the release of the key signal. The functions of the central locking system may, for example, include locking and / or unlocking the vehicle.The method may further comprise providing 160 access to functions of an electric immobilizer for the mobile device based on the information about the release of the immobilizer signal. The functions of the immobilizer may, for example, include deactivating or activating an immobilizer and / or activating keyless entry. The method may further comprise providing 170 data from a vehicle communication system of the vehicle for the mobile device. In this case, the data of the vehicle communication system may merely be read out and not modified. The data of the vehicle communication system may, for example, correspond to data from a CAN (Controller Area Network, a vehicle bus used for vehicle data) of the vehicle.
[0041] In order for the user to gain access to the vehicle via their mobile device, they can authenticate themselves to the vehicle. The authentication of the user's mobile device can be based, for example, on the user's identity information. The method can also be implemented as described in Fig. 1b shown, obtaining 122 the identity information of the user of the vehicle from a mobile device of the user via the further wireless communication connection. The information about the release of the key signal can include information about a user for whom the key signal and / or the immobilizer signal is to be released. The control signal (and thus also the key signal / immobilizer signal) can be provided 130 if the information about the user matches the identity information.
[0042] To secure this authentication of the user's mobile device, an encrypted token can be used as identity information, for example. The encrypted token can, for example, originate from the central computer, for example from a central trusted authority of the central computer, i.e., be generated by the central computer based on a cryptographic key. Alternatively, the token can be generated by the central trusted authority of the central computer and provided directly to the device for the vehicle by the server of the vehicle manufacturer or a service provider of the central computer, for example in cases where the user's mobile device does not communicate directly with the device, but via the server of the vehicle manufacturer or service provider. The information about the release of the key signal can include cryptographic key information.The device (e.g., the control module) can then use the cryptographic key information to verify the encrypted token. Verifying the encrypted token can, for example, include checking whether the cryptographic key information and the encrypted token originate from the same cryptographic key (e.g., the private key of the central computer). In other words, the method can further include verifying the encrypted token based on the cryptographic key information.
[0043] Furthermore, the authorization can only be granted for a specific period of time. For example, in a car-sharing scenario in which the vehicle is assigned to users via a sequence of multiple, short-term bookings, the authorization can be granted in advance for a plurality of bookings, for example to account for the case in which the vehicle cannot establish a connection to the central computer when the user wishes to gain access. In other words, the authorization for the key signal or the immobilizer signal can be obtained in advance from the central computer, for example before receiving the identity information from the mobile device. Thus, the information about the authorization of the key signal can include information about a period of time for which the authorization for the key signal and / or the immobilizer signal is granted (in advance).The control signal (and thus also the immobilizer signal and / or the key signal) can be provided (only) within the time period. After the time period has elapsed, the method can further comprise activating the immobilizer, for example, to decommission the vehicle after the end of the rental transaction. A grace period can also be granted for this purpose. Alternatively, the method can further comprise requesting the release of the key signal or the immobilizer signal based on the received identity information, for example, after receiving the identity information.
[0044] In embodiments, the control module 16 (and / or control modules 24; 34, which are used in connection with the Fign. 2b or 3b introduced) correspond to any controller or processor or programmable hardware component.
[0045] For example, the control module 16; 24; 34 can also be implemented as software programmed for a corresponding hardware component. In this respect, the control module 16; 24; 34 can be implemented as programmable hardware with appropriately adapted software. Any processors, such as digital signal processors (DSPs), can be used. Embodiments are not limited to a specific type of processor. Any processor or even multiple processors are conceivable for implementing the control module 16; 24; 34.
[0046] The at least one interface 14 (and / or interfaces 22; 32, which are used in connection with the Fign. 2b or 3bintroduced) may, for example, correspond to one or more inputs and / or one or more outputs for receiving and / or transmitting information, for example in digital bit values, based on a code, within a module, between modules, or between modules of different entities. In at least some embodiments, the interfaces 14; 22 and 32 may be configured to communicate via the wireless mobile communication system. In addition, the interfaces 14 and 32 may be configured to communicate via the further wireless communication link (for example, the wireless short-range radio communication link).
[0047] More details and aspects of the method and apparatus 10 are mentioned in connection with the concept or examples given before or after (e.g. Fig. 2a bis 7 ). The apparatus 10 or method may include one or more additional optional features corresponding to one or more aspects of the proposed concept or described examples, as described before or after.
[0048] Another component of the invention is the central server. This provides the device 10 with the authorization for the key signal and / or the immobilizer signal, but can also communicate with the mobile device. The authorization of the key signal is then implemented by the device, for example, by a main processor (the control module) of the device, in conjunction with a Trusted Platform Module (TPM) of the device, and in conjunction with the key chip, which processes the implementation of the authorization and processes the key signal and / or the immobilizer signal.
[0049] Fig. 2a shows a flowchart of an embodiment of a method for a central computer 200. The method comprises providing 210 information about a release for the key signal or the immobilizer signal for a device 10 of a vehicle 100 via a wireless mobile communication system (for example, the system described in connection with the Fign. 1a bis 1c introduced information about the release of the key signal or the immobilizer signal). In at least some embodiments, the central computer merely provides an enable signal for the device; the actual enable occurs through the device, for example through an interaction of the control module of the device with a TPM of the device and with the key chip of the device. The release of the key signal indicates an enablement of a functionality for unlocking or locking a central locking system of the vehicle by the central computer 200. Additionally or alternatively, the release of the immobilizer signal indicates an enablement of a functionality for deactivating or activating an immobilizer by the central computer.The enablement refers to a key signal or an immobilizer signal provided via a wireless communication link within the vehicle to an immobilizer module or a central locking system of the vehicle if the key signal or the immobilizer signal is enabled by the central computer (such as the key signal and / or the immobilizer signal provided in connection with the . Fign. 1a bis 1c be introduced).
[0050] Fig. 2b shows a block diagram of an embodiment of a (corresponding) device 20 for a central computer 200. Fig. 2b further shows the central computer 200 with the device 20. Fig. 2b further shows a system comprising the central computer 200 with the device 20, the vehicle 100 with the device 10 and optionally a mobile device 300 with a device 30, which in connection with the Fign. 3a und 3b The device 20 comprises at least one interface 22 configured for communication via a wireless mobile communication system (such as the wireless mobile communication system used in conjunction with the Fign. 1a bis 1c is introduced). The device 20 comprises a control module 24 coupled to the at least one interface. The control module 24 can be configured to carry out the method, for example, using the at least one interface. The control module 24 is configured to provide the information about the release of a key signal or the immobilizer signal for the device 10 of the vehicle via the wireless mobile communication system.
[0051] The following description refers to both the procedure of Fig. 2a as well as the device 20 of the Fig. 2b .
[0052] The method comprises providing 210 (e.g., transmitting) the information about the release of a key signal or the immobilizer signal. The release refers to a key signal or an immobilizer signal that is provided via the wireless communication connection within the vehicle to an immobilizer module or a central locking system of the vehicle if the key signal or the immobilizer signal is released by the central computer. The key signal and / or the immobilizer signal can be the key signal and / or the immobilizer signal that are associated with the Fign. 1a bis 1c were introduced. For example, the central computer can provide information about the release of a key signal or the immobilizer signal based on a request from a server of a car-sharing provider or based on a request from a user's mobile device 300.
[0053] In at least some embodiments, the information about the release of the key signal or the immobilizer signal may include cryptographic key information. The method may further include providing 220 an encrypted token to a mobile device 300 of a user of the vehicle, for example, via the wireless mobile communication system. The encrypted token and the cryptographic key information are based on the same cryptographic key. In other words, the method may include generating the cryptographic key information and the encrypted token based on the cryptographic key. The cryptographic key may, for example, be a private key of the central computer. The encrypted token may be provided to the mobile device for forwarding to the vehicle device. The encrypted token may, for example, not be decrypted by the mobile device.However, the mobile device can sign the encrypted token and then pass it on to the device 10 for the vehicle in signed form.
[0054] More details and aspects of the method and apparatus 20 are mentioned in connection with the concept or examples given before or after (e.g. Fig. 1a bis 1c , 3a bis 7 ). The apparatus 20 or method may include one or more additional optional features corresponding to one or more aspects of the proposed concept or described examples, as described before or after.
[0055] The invention further relates in some embodiments to a mobile device.
[0056] Fig. 3a shows a flowchart of an embodiment of a method for a mobile device 300. The method includes providing 310 identity information of a user of a vehicle from the user's mobile device to a device of the vehicle via a wireless communication connection. The identity information is provided to the device 10 of the vehicle for comparison with information about a user. Based on the identity information, a key signal or an immobilizer signal is to be released for the user by the device 10 if the information about the user matches the identity information. If the key signal or the immobilizer signal is released, the key signal or the immobilizer signal is provided to an immobilizer module or a central locking system of the vehicle via a wireless communication connection within the vehicle.
[0057] Fig. 3b shows a block diagram of an embodiment of a (corresponding) device 30 for the mobile device. The device 30 comprises at least one interface 32, designed for communication via a wireless communication connection (such as the further wireless communication connection used in connection with the Fign. 1a bis 1c The device 30 comprises a control module 34 which is coupled to the at least one interface. The control module 34 can be designed to carry out the method of Fig. 3a The control module 34 is configured to provide identity information of a user of a vehicle 100 from the user's mobile device to a device 10 of the vehicle via the wireless communication link. The identity information is provided to the device of the vehicle for comparison with information about a user for whom a key signal or an immobilizer signal is to be released, so that the key signal or the immobilizer signal is provided to an immobilizer module or a central locking system of the vehicle via a wireless communication link within the vehicle if the information about the user matches the identity information.
[0058] The following description refers to both the procedure of Fig. 3a and the device 30 of the Fig. 3b .
[0059] In some embodiments, the identity information, as in connection with the Fign. 1a bis 2b executed, correspond to an encrypted token. The method may further comprise receiving 320 (or obtaining) the encrypted token from a central computer 200 for forwarding to the vehicle (for example, by providing / transmitting the encrypted token as identity information to the device 10 of the vehicle). In some embodiments, the method may further comprise signing the encrypted token based on a private key of the mobile device. The method may further comprise providing the signed version of the encrypted token to the device 10 of the vehicle 100.
[0060] More details and aspects of the method and apparatus 30 are mentioned in connection with the concept or examples given before or after (e.g. Fig. 1a bis 2b , until 7). The apparatus 10 or method may include one or more additional optional features corresponding to one or more aspects of the proposed concept or described examples, as described before or after.
[0061] At least some embodiments relate to a CDIS box (Car On Demand Interim Solution, a telematics solution). This may correspond approximately to the device 10 used in connection with the Figuren 1a bis 1c was introduced.
[0062] Some vehicles, such as older vehicles, lack the hardware necessary to ensure secure car-sharing use. Since it is legally controversial whether a fully functional key may be located in the vehicle, the CDIS box provides a telematics solution that only releases a key after interaction and authentication via the backend (e.g., the central computer 200), smartphone (the mobile device 300), and vehicle communication (CDIS box).
[0063] The CDIS box enables various user experiences (also known as customer journeys), including for public car-sharing services. In a first step, users are made aware of the car-sharing service via a website or social media, for example, by scanning a QR (Quick Response) code with a mobile device. The user can then register for the service via a smartphone or website and upload the necessary documents for verification and activation of membership. In a third step, users can locate and reserve (book) a vehicle and pay a deposit via a payment service provider such as PayPal or AliPay. Personalization is also possible. Once the rental begins, personalized settings can be configured, for example for infotainment (amalgam of information and entertainment), pre-conditioning of the vehicle, etc., can be transferred to the vehicle. In a fifth step, users can use the vehicle, for example, using a smartphone application to open the vehicle, monitor their route, view the associated rental costs, and terminate the rental. Users can then pay via the selected payment service provider and, for example, invite friends via mobile social media applications.
[0064] The so-called CDIS box can be used for this purpose. This can be used, for example, to open and close the vehicle, to mobilize and demobilize the vehicle, and / or to provide access to the comfort vehicle bus (K-CAN, Comfort Controller Area Network). The procedure can be divided into two parts. In a first step, the smartphone can be used to open the vehicle from the outside via a direct wireless connection between the smartphone and the CDIS box. In a second step, the vehicle can be started via the smartphone. The CDIS box communicates directly (via wireless communication) with the smartphone, with the vehicle's immobilizer module, with a vehicle key module to release the immobilizer, and via the K-CAN to read vehicle data.
[0065] The invention (key chip with Car on Demand software) or the CDIS box is a Car on Demand telematics retrofit solution that can authorize the user to lock / unlock and mobilize the vehicle using a smartphone. This also involves authenticating and ensuring authorized use of the vehicle. Once this is ensured, the vehicle immobilizer (WFS) can be deactivated, and the customer can use the vehicle. Furthermore, it is possible to read vehicle information stored on the comfort CAN and view it via a backend on the mobile device (smartphone).
[0066] For this purpose, the software of a conventional key chip (such as key chip 12) can be adapted accordingly so that the signals (e.g., opening / closing or immobilizer, via the key signal and / or the immobilizer signal) are verified before being processed by the CDIS box and are not executed directly. This provides an alternative to opening and using the vehicle with a digital key without a mechanical key device, or to installing a non-encrypted, fully functional vehicle key inside the vehicle.
[0067] This can be achieved by a modified key chip integrated into the circuit board. This chip can be a modified version of the key chip used in a conventional vehicle key. The software modification can prevent unauthorized access to the immobilizer's secret code and the vehicle from being mobilized. The advantages of this concept arise from the modification of the key chip, which is integrated into the circuit board.
[0068] Thus, in at least some embodiments, write access to the vehicle CAN is not necessary. Protection against unauthorized use can be provided because the key is encrypted, thus this solution can also be legally compliant and meet insurance requirements. Furthermore, development effort can be saved because an existing chip is used.
[0069] The following illustrates an example vehicle booking. In a first step, the customer registers in the backend (a central computer or data center). In step 2, the customer books the vehicle on a third-party backend, such as a car-sharing provider. In step 3, the booking period is transmitted from the third-party backend (e.g. via wireless communication) to a backend of the vehicle manufacturer. In step 4, the booking period is transmitted via the smartphone (via wireless communication) to the vehicle's CDIS box. In step 5, the customer opens the vehicle using the smartphone via Bluetooth Low Energy. The vehicle data is transmitted via cellular data. The main functions provided by the CDIS box are unlocking / locking the vehicle, releasing the immobilizer, and accessing vehicle data via the convenience CAN.
[0070] It may be desirable for the vehicle key to be removed from the vehicle. Thus, in at least some embodiments, the entire system consisting of the CDIS box, the user's smartphone, and the backends of the manufacturer and a car-sharing provider can represent the key. Fig. 4 illustrates the flow of information in such an overall system. In a first step, a possibility for verifying user identities is provided from a user's mobile device (smartphone) 410 via the third party's backend 420 to the manufacturer's backend 430 (for example, the central computer 200). In step 2, the booking information with the possibility for verifying user identities is transmitted from the manufacturer's backend 430 to the CDIS box 440 (for example, the device 10). The identity (for example, the identity information) of the user is transmitted from the user's mobile device 410 (for example, the mobile device 300) to the CDIS box in step 3. If the user's identity matches the possibility for verifying user identities, the shared secret (for example, the symmetric key, K.Sym) of the key signal and / or the immobilizer signal of the key chip 450 is released by a control signal from the CDIS box 440 in order to unlock the vehicle and deactivate the immobilizer. Each device can comprise a public and a private key, wherein the public key can be known to the device's communication partners and the private key only to the device itself. Communication with the device can be based on the device's public key.
[0071] The Figuren 5a und 5b show how the current solution (conventional vehicle key) and the implementation with the CDIS box are realized in the event of an immobilizer signal. In both cases, the immobilizer secret is stored in the ROM via the firmware of the microcontroller (micro control unit, with manufacturer-specific special functions). With the conventional key, an LF signal, which contains the immobilizer system's request to provide the immobilizer signal, is received via the LF Passive 510 module (passive low-frequency module) and forwarded directly to the ROM. There, the immobilizer secret is read out and provided to the immobilizer system, and the WFS is released. When implemented with the CDIS box, this LF signal is first forwarded via the LF Passive to the EROM (520). There, a check is carried out to determine whether the immobilizer signal is enabled.A signal path is established between the EROM and the CDIS box 540 (e.g., the control module 16 of the device 10), which checks the authorization of the unlocking request. Once the vehicle's use is authorized, a signal is forwarded through the EROM to the ROM to read the immobilizer secret, thus disabling the WFS in a similar way to the conventional solution.
[0072] Fig. 6 shows the integration of the key chip in the CDIS box 600. The CDIS box can comprise the host microcontroller 610, which communicates with a Bluetooth module 620 (which can be configured to communicate via Bluetooth or Bluetooth Low Energy), a hardware encryption device 630 (HED, such as a Trusted Platform Module or a Hardware Security Module, HSM), and the key chip 640. The host microcontroller, together with the TPM, can correspond to the control module 16, the at least one interface can comprise the Bluetooth module 620, and the key chip 640 can correspond to the key chip 12. The microcontroller communicates with the mobile device 650 (which can correspond to the mobile device 300) via the Bluetooth module 620.The key chip 640 is coupled to the microcontroller, for example, via a Serial Peripheral Interface (SPI). Communication between the microcontroller and the key chip is encrypted and / or signed. One goal is to achieve secure communication between the Car on Demand logic unit and the key chip (mobilization chip) for the purpose of unlocking and mobilizing the vehicle. In some embodiments, this can prevent manipulation such as unwanted sending of commands, unwanted modification of commands, or repetition of commands to the key chip. The key chip is coupled to three inductors L1-L3. The inductors L2 and L3 are arranged at a specific angle to each other and can be used for the keyless access system. L1 is connected to the key chip via a twisted pair cable with a maximum length of 1 m.3 meters coupled with the key chip and located outside the CDIS box.
[0073] Fig. 7 shows an embodiment of a connection of a key chip 710 (such as key chip 12). The key chip 710 is coupled to a control module 720 (such as control module 16), an LF antenna module 730, and an RF antenna module 740. The control module triggers functions of the key chip via simulated button presses and provides a control signal to enable the key chip to provide the key signal and / or the immobilizer signal. The key signal is transmitted via the RF antenna module 740, which is configured to communicate with the central locking system, and the immobilizer signal is transmitted via the LF antenna module 730, which is configured to communicate with the immobilizer.
[0074] Another embodiment is a computer program for performing at least one of the methods described above when the computer program runs on a computer, a processor, or a programmable hardware component. Another embodiment is also a digital storage medium that is machine- or computer-readable and that has electronically readable control signals that can interact with a programmable hardware component to execute one of the methods described above.
[0075] The features disclosed in the above description, the following claims and the attached figures can be important and implemented both individually and in any combination for the realization of an embodiment in its various forms.
[0076] Although some aspects have been described in connection with a device, it is understood that these aspects also represent a description of the corresponding method, so that a block or component of a device can also be understood as a corresponding method step or as a feature of a method step. Similarly, aspects described in connection with or as a method step also represent a description of a corresponding block, detail, or feature of a corresponding device.
[0077] Depending on specific implementation requirements, embodiments of the invention may be implemented in hardware or software. The implementation may be performed using a digital storage medium, such as a floppy disk, a DVD, a Blu-ray disc, a CD, a ROM, a PROM, an EPROM, an EEPROM, or a FLASH memory, a hard disk, or other magnetic or optical storage device storing electronically readable control signals that can interact or interact with a programmable hardware component to perform the respective method.
[0078] A programmable hardware component can be formed by a processor, a computer processor (CPU = Central Processing Unit), a graphics processor (GPU = Graphics Processing Unit), a computer, a computer system, an application-specific integrated circuit (ASIC = Application-Specific Integrated Circuit), an integrated circuit (IC = Integrated Circuit), a single-chip system (SOC = System on Chip), a programmable logic element or a field-programmable gate array with a microprocessor (FPGA = Field Programmable Gate Array).
[0079] The digital storage medium can therefore be machine- or computer-readable. Some embodiments thus comprise a data carrier having electronically readable control signals capable of interacting with a programmable computer system or a programmable hardware component such that one of the methods described herein is performed. One embodiment is thus a data carrier (or a digital storage medium or a computer-readable medium) on which the program for performing one of the methods described herein is recorded.
[0080] In general, embodiments of the present invention can be implemented as a program, firmware, computer program, or computer program product with program code or data, wherein the program code or data is effective to perform one of the methods when the program runs on a processor or a programmable hardware component. The program code or data can also be stored, for example, on a machine-readable medium or data carrier. The program code or data can be present, among other things, as source code, machine code, or bytecode, as well as other intermediate code.
[0081] A further embodiment is a data stream, a signal sequence, or a sequence of signals that represents the program for performing one of the methods described herein. The data stream, the signal sequence, or the sequence of signals can be configured, for example, to be transferred via a data communication connection, for example, via the Internet or another network. Thus, embodiments also include signal sequences representing data that are suitable for transmission via a network or data communication connection, wherein the data represents the program.
[0082] A program according to one embodiment can implement one of the methods during its execution, for example, by reading memory locations or writing one or more pieces of data into them, which may trigger switching operations or other processes in transistor structures, amplifier structures, or other electrical, optical, magnetic, or other functionally principle-based components. Accordingly, by reading a memory location, data, values, sensor values, or other information can be acquired, determined, or measured by a program. A program can therefore acquire, determine, or measure quantities, values, measured quantities, and other information by reading one or more memory locations, and can trigger, initiate, or perform an action and control other devices, machines, and components by writing to one or more memory locations.
[0083] The above-described embodiments are merely illustrative of the principles of the present invention. It is understood that modifications and variations of the arrangements and details described herein will be apparent to others skilled in the art. Therefore, it is intended that the invention be limited only by the scope of the following claims and not by the specific details presented in the description and explanation of the embodiments herein. List of reference symbols
[0084] 10 Device 12 Key chip 14 At least one interface 16 Control module 20 Device 22 At least one interface 24 Control module 30 Device 32 At least one interface 34 Control module 100 Vehicle 110 Receiving information about the release of a key signal or an immobilizer signal 120 Communicating with a mobile device 122 Receiving identity information 130 Providing a control signal 140 Providing a key signal or an immobilizer signal 150 Providing access to functions of a central locking system 160 Providing access to functions of an electric immobilizer 170 Providing data of a vehicle communication system 200 Central computer 210 Providing information about the release of a key signal or an immobilizer signal 220 Providing an encrypted token 300Mobile device 310Providing identity information 320Receiving an encrypted token410 Mobile device 420 Third-party backend 430 Manufacturer backend 440 CDIS box 450 Key chip 510 LF passive 520 EROM 530 ROM 540 CDIS box 600 CDIS box 610 Host microcontroller 620 Bluetooth module 630 Key chip 640 TPM module 710 Key chip 720 Control module 730 LF antenna module 740 RF antenna module
Claims
1. A method for a device (10) for a vehicle (100), wherein the device (10) comprises a key chip (12), the method comprising: obtaining (110) information about a release of a key signal or an immobilizer signal from a central computer via a wireless mobile communication system, wherein the release of the key signal indicates a release, by the central computer, of a functionality for unlocking or locking central locking of the vehicle, and / or wherein the release of the immobilizer signal indicates a release, by the central computer, of a functionality for deactivating or activating an immobilizer, wherein the information about the release of the key signal comprises information about a user for whom the key signal and / or the immobilizer signal is to be released; obtaining (122) identity information of a user of the vehicle from a mobile device of the user via another wireless communication link; providing (130) a control signal for the key chip (12) based on the information about the release of the key signal or the immobilizer signal, wherein the control signal is designed to enable the key chip to generate the key signal or the immobilizer signal, wherein the control signal is provided (130) if the information about the user matches the identity information; and by means of the key chip, providing (140) the key signal and / or the immobilizer signal via a wireless communication link for a central locking system (50) and / or an immobilizer system (40) of the vehicle after the control signal has been obtained.
2. The method according to claim 1, wherein the key signal is transmitted via a wireless high-frequency communication link and / or wherein the immobilizer signal is transmitted via a wireless low-frequency communication link.
3. The method according to one of the preceding claims, wherein the key signal is similar to a wireless key signal of a vehicle key of the vehicle, and / or wherein the immobilizer signal is similar to a wireless immobilizer signal of the vehicle key of the vehicle, and / or wherein the key chip is similar to a key chip of a vehicle key of the vehicle.
4. The method according to one of the preceding claims, wherein the information about the release of the key signal comprises information about a time period for which the release of the key signal and / or the immobilizer signal is granted, wherein the control signal is provided within the time period, and / or wherein the information about the release of the key signal comprises cryptographic key information, wherein the identity information corresponds to an encrypted token, wherein the encrypted token originates from the central computer, wherein the method further comprises verifying the encrypted token based on the cryptographic key information.
5. The method according to one of the preceding claims, wherein the method further comprises communicating (120) with a mobile device of the user via a further wireless communication link, wherein the method comprises providing (150) access to functions of the central locking for the mobile device based on the information about the release of the key signal, and / or wherein the method comprises providing (160) access to functions of an electric immobilizer for the mobile device based on the information about the release of the immobilizer signal, and / or wherein the method comprises providing (170) data of a vehicle communication system of the vehicle for the mobile device.
6. The method according to one of the preceding claims, wherein the immobilizer signal is provided (140) to the immobilizer system (40) of the vehicle in order to deactivate an immobilizer of the vehicle, and / or wherein the key signal is provided (140) to the central locking system (50) of the vehicle in order to unlock or lock at least one panel of the vehicle, and / or wherein the immobilizer signal is provided (140) to the immobilizer system (40) of the vehicle to enable the vehicle to start.
7. The method according to one of the preceding claims, wherein the control signal is provided in a cryptographically secured manner.
8. A method for a central computer (200), the method comprising: providing (210) information about a release of a key signal or an immobilizer signal for a device of a vehicle via a wireless mobile communication system, wherein the release of the key signal indicates a release, by the central computer, of a functionality for unlocking or locking central locking of the vehicle, and / or wherein the release of the immobilizer signal indicates a release, by the central computer, of a functionality for deactivating or activating an immobilizer, wherein the release refers to a key signal or an immobilizer signal provided via a wireless communication link within the vehicle to an immobilizer module or a central locking system of the vehicle if the key signal or the immobilizer signal is released by the central computer, wherein the information about the release of the key signal comprises information about a user for whom the key signal and / or the immobilizer signal is to be released.
9. The method according to claim 8, wherein the information about the release of the key signal or the immobilizer signal comprises cryptographic key information, wherein the method further comprises providing (220) an encrypted token for a mobile device of a user of the vehicle, wherein the encrypted token and the cryptographic key information are based on the same cryptographic key, and the encrypted token is provided to the mobile device in order to forward said token to the device of the vehicle.
10. A computer program for carrying out one of the methods according to one of claims 1 to 9 when the computer program runs on a computer, a processor, or a programmable hardware component.
11. A device (10) for a vehicle (100), the device (10) comprising: a key chip (12); at least one interface (14) designed for communication via a wireless mobile communication system; and a control module (16) designed to: obtain information about a release of a key signal or an immobilizer signal from a central computer (200) via the wireless mobile communication system, wherein the release of the key signal indicates a release, by the central computer, of a functionality for unlocking or locking central locking of the vehicle, and / or wherein the release of the immobilizer signal indicates a release, by the central computer, of a functionality for deactivating or activating an immobilizer, wherein the information about the release of the key signal comprises information about a user for whom the key signal and / or the immobilizer signal is to be released, obtain identity information of a user of the vehicle from a mobile device of the user via a further wireless communication link, and providing a control signal for the key chip (12) based on the information about the release of the key signal or the immobilizer signal, wherein the control signal is designed to enable the key chip to generate the key signal or the immobilizer signal, wherein the control signal is provided (130) if the information about the user matches the identity information, wherein the key chip (12) is designed to provide the key signal and / or the immobilizer signal via a wireless communication link for a central locking system (50) and / or an immobilizer system (40) of the vehicle (120) after the control signal has been received.
12. A device (20) for a central computer (200), the device (20) comprising: at least one interface (22) designed for communication via a wireless mobile communication system; and a control module (24) designed to: provide information about a release of a key signal or an immobilizer signal for a device (10) of a vehicle via the wireless mobile communication system, wherein the release of the key signal indicates a release, by the central computer, of a functionality for unlocking or locking central locking of the vehicle, and / or wherein the release of the immobilizer signal indicates a release, by the central computer, of a functionality for deactivating or activating an immobilizer, wherein the release refers to a key signal or an immobilizer signal provided via a wireless communication link within the vehicle to an immobilizer module or a central locking system of the vehicle if the key signal or the immobilizer signal is released by the central computer, wherein the information about the release of the key signal comprises information about a user for whom the key signal and / or the immobilizer signal is to be released.