Method for authenticating a vehicle, authentication unit, service unit and vehicle-external central processing unit
Patent Information
- Application Number
- DE502020011189
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-04-12
- Filing Date
- 2020-04-02
- Publication Date
- 2025-07-03
- Estimated Expiration
- 2040-04-02
AI Technical Summary
Current authentication methods for vehicles and drivers at infrastructure units involve the transmission of sensitive data, which poses data protection risks and requires secure, reliable authentication without transmitting sensitive information.
A method using a vehicle-external central processing unit for authenticating a vehicle to a service unit, where an initial value is generated and transmitted to an authentication unit, allowing it to read a request command from a request table and output it to the vehicle's interface, without transmitting sensitive output values directly to the service unit.
Enables secure authentication of vehicles without transmitting sensitive data, ensuring that even if the service unit or unauthorized recipients intercept values, they cannot access or reconstruct the output values, thus maintaining data protection and security.
Description
[0001] The invention relates to a method for authenticating a vehicle and a vehicle-external central processing unit. During use of a vehicle, a multitude of functions and motor vehicle-related services are used which require authentication of the vehicle or its driver to infrastructure facilities. This may be necessary, for example, at barriers to restricted access or paid parking spaces that are only accessible to certain vehicles and / or drivers. Another example is company petrol stations or charging stations whose use is restricted to company vehicles. According to the current state of the art, authentication is carried out using local systems that are generally limited to the respective application. In this case, authorized drivers are provided with magnetic cards or radio devices, for example, with which they can authenticate themselves or activate a function.
[0002] The increasing proliferation of communication systems that enable communication between vehicles (so-called Car-2-Car systems) or between vehicles and infrastructure units (so-called Car-2-X systems) is opening up new opportunities for vehicle-related services. The usual local solutions, limited to individual use cases, are no longer appropriate given the capabilities of these systems. The multitude of local solutions could be replaced by a central solution. However, a central authentication system has not yet been established. One problem with authenticating a vehicle or driver is the use of personal or sensitive data. For data protection reasons, it is necessary to withhold personal data from the service provider when authenticating a vehicle or driver.Nevertheless, certain services require reliable and secure authentication of the driver and / or vehicle to the service provider.
[0003] A method that enables authentication using specific secret values without transmitting the secret values themselves is described in a conference paper by Dass, Prajnamaya and OM, Hari: "A secure authentication scheme for RFID systems" (Procedia Computer Science, 2016, vol. 78, pp. 100-106).
[0004] A method for access management of a vehicle is disclosed in DE 10 2016 218 986 A1, and a communication system comprising a vehicle and an authentication device comprising a mobile terminal and a central computer is known therefrom.
[0005] DE 10 2012 010 723 A1 relates to a diagnostic system with a diagnostic device in a vehicle and a diagnostic script provision device.
[0006] A system and a method for access control, a portable terminal and an interface unit for the system are known from FR 2 881 304 A1.
[0007] US 2008 / 211624 A1 discloses a system and method for controlling physical access using a digital certificate validation process.
[0008] It is an object of the invention to enable secure authentication of a vehicle or a driver to an infrastructure unit without transmitting sensitive data to the infrastructure unit.
[0009] The invention provides a method for authenticating a vehicle to a service unit by means of a vehicle-external central processing unit according to claim 1. During the method, an authentication unit is provided in the vehicle. In other words, the authentication unit is arranged as a standalone device on the vehicle or is a component of the vehicle. The authentication unit can, for example, comprise a microprocessor and / or microcontroller. In a first step of the method, an initial value is generated by the service unit and transmitted from the service unit to the authentication unit. In other words, the service unit to which authentication of the vehicle and / or the driver is to take place creates a random or pseudo-random value as an initial value to initiate the method and transmits it to the authentication unit.The service unit can, for example, comprise a microprocessor and / or microcontroller and a radio unit and can, for example, be arranged in a barrier at which a driver of the vehicle requests entry. The transmission can, for example, take place via a radio connection between the service unit and the authentication unit. Depending on the initial value, the authentication unit reads a request command from a request table stored in the authentication unit. In other words, the request table is stored in the authentication unit. The request table can have the at least one request command as a table element. To determine the request command to be read from the request table, a selection is made according to a predetermined method, wherein the initial value alone or in combination with other values is used as the input variable, or a value calculated from the initial value.The method can, for example, determine an index value assigned to the request commands for the initial value. The request command can, for example, be a program code and / or signal for querying a predetermined parameter of the vehicle from a network of the vehicle. The request command read from the request table is output by the authentication unit to an interface of the vehicle. In other words, the request command is transmitted from the authentication unit to the interface. The interface of the vehicle can, for example, be an OBD port (on-board diagnostic port) of the vehicle. The request command can be a command for outputting a predetermined value of a vehicle component of the vehicle, which enables identification of the vehicle and, for example, complies with the CAN standard.In the vehicle, the request command is executed by the vehicle component, which outputs an output value in response to the request command. In other words, after the vehicle component receives the request command, the output value associated with the request command is generated. The vehicle component can, for example, be an engine control unit of the vehicle. In this case, the request command can provide for the output of an identification value of the engine control unit as an output value. The generated output value is received from the interface by the authentication unit. In other words, the output value is transmitted from the vehicle component to the authentication unit via the interface.
[0010] The authentication unit calculates a vehicle verification value from the output value using a predetermined verification value function. The verification value function can be, for example, a hash value function or a pseudorandom value function (pseudo random number generator, PRNG). In other words, the authentication unit calculates the assigned vehicle verification value, with the calculation being carried out using the predetermined verification value function. The vehicle verification value can be, for example, a verification signature, a hash value, or a pseudorandom value that can be used to verify the output value, but from which the output value itself cannot be calculated. In a further step, the vehicle verification value generated from the output value and the initial value are transmitted from the authentication unit to a central processing unit. This can be done, for example, via a mobile radio network and / or the Internet.The central processing unit can, for example, be a central computer or a computer network and be located outside the vehicle. The transmission can be made directly from the authentication unit to the central processing unit or routed via the service unit.
[0011] Depending on the received initial value, the central processing unit reads a characteristic value from a characteristic value table stored in the central processing unit. The characteristic value is an expected value which, if the process runs correctly, matches the output value received from the vehicle component. This can, for example, be the aforementioned unique identification value of the engine control unit. The characteristic value to be read out can be determined using the same process as in the authentication unit. Using the predetermined test value function, the central processing unit calculates a further vehicle test value from the characteristic value. The vehicle test value calculated by the authentication unit from the output value and the further vehicle test value generated by the central processing unit from the characteristic value are checked by the central processing unit for a match.If the vehicle test value matches the additional vehicle test value, the central processing unit sends a predetermined release signal to the service unit. In other words, the central processing unit sends a release signal to the service unit. The transmission can be done via a wired or wireless connection, for example.
[0012] The invention provides the advantage that a vehicle can be authenticated at a service unit without transmitting sensitive output values to the service unit itself. The service unit and / or an unauthorized recipient intercepting transmitted values cannot thus access the output value or reconstruct it from the intercepted values. This enables the vehicle to be linked to the central processing unit via the query table with the associated characteristic value table.
[0013] The invention includes optional developments which result in further advantages.
[0014] A further development of the invention provides that an identification value uniquely assigned to the authentication unit is stored in the authentication unit. In other words, the identification value is a value that uniquely identifies the authentication unit. The authentication unit generates an identification check value from the identification value using the check value function. In other words, the authentication unit calculates the identification check value using the check value function. The method provides for the identification check value to be transmitted to the central processing unit together with the vehicle check value. In other words, this further development provides for the identification check value to be sent from the authentication unit to the central processing unit in addition to the vehicle check value.The central processing unit checks whether the identification check value matches entries in an identification table stored in the processing unit. In other words, the central processing unit checks whether the received identification check value is stored in the central processing unit's identification table. The central processing unit is designed to send the predetermined release signal to the service unit only if one of the entries in the identification table matches the identification check value. Sending the release signal therefore requires that, in addition to the vehicle check value matching the other vehicle check value, the identification check value must also be stored in the identification table.
[0015] The further development has the advantage that the procedure requires a verification of the authentication unit and thus security can be increased.
[0016] A further development of the invention provides that a second initial value is generated by the authentication unit, and a secret value is stored in the authentication unit. A further secret value is stored in the central processing unit. In other words, a respective secret value is stored in both units as a so-called shared secret. For the method to be successfully carried out, the secret value and the further secret value must be identical. The authentication unit calculates a session check value using the predetermined check value function. This session check value is generated from the secret value stored in the authentication unit, the initial value generated by the service unit, and the further initial value generated by the authentication unit.In other words, the session check value is generated using the check value function from the secret value stored in the authentication unit, the initial value generated by the service unit, and the further initial value generated by the authentication unit. The session check value is transmitted from the authentication unit to the central processing unit together with the vehicle check value. The central processing unit uses the check value function to generate a further session check value, which is created from the further secret value, the initial value, and the further initial value. In other words, the central processing unit uses the check value function to generate the further session check value from the further secret value stored in the central processing unit, the initial value, and the further initial value. The central processing unit checks the further session check value and the session check value for a match.The central processing unit thus checks whether the session verification value generated by the authentication unit and the additional session verification value generated by the central processing unit are identical. The central processing unit is only intended to send the predetermined release signal to the service unit if the session verification value matches the additional session verification value. In other words, for the method to continue, the two session verification values must be identical. This ensures that the same initial value, the same additional initial value, and the same secret value are provided in the central processing unit and the authentication unit.
[0017] This offers the advantage that each authentication process between the authentication unit and the central processing unit can be secured using session verification values. For example, it is possible that the respective initial values and / or the respective additional initial values and / or the respective secret values differ between different authentication procedures. This can result in each authentication procedure having a unique session verification value. If the previously used session verification value is used again, a discrepancy occurs because, for example, the secret value can be updated during a respective authentication process.
[0018] A further development of the invention provides that the central processing unit sends the additional secret value to the service unit as the predetermined release signal. In other words, the predetermined release signal is the additional secret value stored in the central processing unit, which corresponds to the secret value stored in the authentication unit. The service unit calculates a first release check value from the secret value and the initial value using the check value function. The service unit calculates a second release check value N from the first release check value M using the check value function. The first release check value M is transmitted from the service unit to the central processing unit. The second release check value N is transmitted from the service unit to the authentication unit.The central processing unit uses the check value function to calculate an update value U from the additional secret value and the first release check value M. The additional secret value stored in the central processing unit is updated by the update value U using a predetermined update function. In other words, the central control unit updates the additional secret value, calculating an updated secret value from the existing additional secret value and the update value U using the predetermined update function. This updated secret value replaces the additional secret value originally stored in the external processing unit.
[0019] The authentication unit uses the check value function to calculate a further first release check value M' from the secret value and the initial value. The check value function then calculates a further second release check value N' from the further first release check value M'. In other words, the authentication unit performs the same steps as those performed in the service unit. After calculating the further second release check value N', the authentication unit checks it for a match with the second release check value N. In other words, the authentication unit checks whether the further second release check value N' calculated by the authentication unit is identical to the second release check value N calculated by the service unit and transmitted to the authentication unit.In this way, it is checked whether the additional secret value transmitted from the central processing unit to the service unit and the initial value stored in the service unit match the corresponding values in the authentication unit. If there is a match, the authentication unit calculates the update value from the secret value and the additional second release check value N' using the check value function. The secret value stored in the authentication unit is updated by the update value using the predetermined update function, as in the central processing unit. In other words, the authentication unit updates the secret value, whereby the updated secret value is calculated from the existing secret value and the update value using the predetermined update function.This secret value replaces the secret value originally stored in the authentication unit. This results in the same updated secret value being calculated in the authentication unit as in the central processing unit. Thus, at the end of the process step, the authentication unit and the central processing unit have the same updated secret values for a future authentication process. The update function can, for example, be an SOR (exclusive-OR) function.
[0020] This enhancement provides the advantage that the secret value shared by the central processing unit and the authentication unit is checked for consistency and updated during the process. This ensures that the secret values remain synchronized.
[0021] A further development of the invention provides that the query command to be read from the query table and the characteristic value to be read from the characteristic value table are selected by means of a selection function depending on the session verification value. In other words, a predetermined selection function is stored in the central processing unit and in the authentication unit. The selection function is used by the central processing unit and the authentication unit to determine the query command to be read from the query table and the characteristic value to be read from the characteristic value table based on the initial value, the further initial value, and the secret value. This results in the advantage that the selection depends on three variables. Influencing the selection of the characteristic value and the query command can thus be avoided.
[0022] A further development of the invention provides that the selection function is the Luhn algorithm. In other words, the selection function is a modulo-10 function. The selection is thus performed by determining an index value that is assigned to the characteristic value to be read and the query command to be read. The index value is determined by dividing the session check value by 10 with a remainder, where the index value is the remainder remaining when the session check value is divided by 10.
[0023] A further development of the invention provides that, after the service unit receives the release signal, a communication process is initiated between the service unit and the authentication unit and / or a control unit of the vehicle. In other words, communication between the service unit and the authentication unit and / or the control unit of the vehicle takes place as soon as the authentication unit has been authenticated by the central processing unit.
[0024] A further development of the invention provides that the service unit transmits a service identifier to the central processing unit. The central processing unit checks whether the service identifier for the identification value is enabled in the central processing unit. The central processing unit only sends the predetermined enable signal to the service unit if the service identifier for the identification value is activated. In other words, the method comprises transmitting the service identifier from the service unit to the central processing unit. The service identifier can, for example, uniquely identify the service unit or a function provided by the service unit. A status of the service identifier for the identification value can be defined in the central processing unit.The "activated" status means that the activation of the service unit or the function provided by the service unit for the authentication unit with the identification value is permitted. The "deactivated" status means that the activation of the service unit or the function provided by the service unit for the authentication unit with the identification value is not permitted. For example, it can be specified that the release signal is only sent by the central processing unit if the service identifier for the identification value is activated in the central processing unit.
[0025] A further development of the invention provides that a predetermined query signal is transmitted by the central processing unit to an input unit if the service identifier for the identification value is deactivated. In other words, the query signal is transmitted to the input unit if the authentication unit with the associated identification value is not activated for the service unit or the function of the service unit with the associated service identifier. The input unit can be, for example, a mobile phone, a tablet, an input system of a vehicle or a mobile user device. Upon receipt of the query signal, the input unit outputs a predetermined warning signal. The warning signal can be, for example, a haptic, acoustic or visual signal.When a predetermined user input is made, the input unit sends an activation signal to the central processing unit. In other words, the activation signal is transmitted from the input unit to the central processing unit when the predetermined user input has been made at the input unit. For example, the warning signal can include a text message prompting the user to activate the function. If the user then taps a predetermined area on a touch-sensitive screen as user input, the input unit can generate the activation signal and send it to the central processing unit. The central processing unit activates the service identifier for the identification value upon receipt of the activation signal. Alternatively or additionally, the release signal is sent to the service unit.
[0026] A further development of the invention provides that the transmissions between the authentication unit and the central processing unit are routed via the service unit. In other words, transmissions from the authentication unit to the central processing unit and from the central processing unit to the authentication unit are routed via the service unit. For example, it can be provided that messages are sent from the authentication unit to the service unit, received by the service unit, and forwarded to the central processing unit. This results in the advantage that no direct transmission between the authentication unit and the central processing unit is required. The transmissions can, for example, be carried out by the authentication unit using Wi-Fi direct, Bluetooth, Car-2-X, or comparable wireless transmission paths with ranges in the meter range.Contacting the central processing unit via mobile internet is therefore not necessary.
[0027] A method for generating a characteristic value table does not fall within the scope of protection of the claim. A coupling signal is transmitted to a central processing unit via an input unit, which then transmits at least one request command for requesting a characteristic value from a vehicle component of the vehicle to the authentication unit. The request command is stored by the authentication unit in a request table in the authentication unit. In addition, the request command is output by the authentication unit to an interface of the vehicle. In the vehicle, the request command is executed by the vehicle component, and the characteristic value is generated as a response. The characteristic value is received from the interface by the authentication unit. The characteristic value is transmitted from the authentication unit to the central processing unit.The central processing unit stores the characteristic value in the characteristic value table of the central processing unit.
[0028] The scope of protection of the claim does not include an input unit which is designed to send a coupling signal to a central processing unit in order to initiate a method for generating a characteristic value table.
[0029] An authentication unit configured to receive an initial value, to read a query command from a query table stored in the authentication unit based on the initial value, and to output the query command to an interface of the vehicle, is not covered by the scope of protection of the claim. The authentication unit is configured to receive an output value generated by a vehicle component in the vehicle in response to the query command from the interface and, using a predetermined check value function, to calculate a vehicle check value associated with the output value and to transmit the vehicle check value associated with the output value to a central processing unit.
[0030] The invention also includes a central processing unit according to claim 11, which is configured to receive a vehicle test value and an initial value and, depending on the initial value, to read a characteristic value from a characteristic value table stored in the central processing unit. The central processing unit is configured to calculate a vehicle test value associated with the characteristic value using a predetermined test value function, to check this value for a match with the received vehicle test value, and, if the test values match, to send a predetermined release signal to a service unit.
[0031] A service unit which is configured to generate an initial value and send it to an authentication unit and to enable a predetermined function upon receipt of a predetermined enable signal does not fall within the scope of protection of the claim.
[0032] The invention also includes further developments of the central processing unit according to the invention that have features already described in connection with the further developments of the method according to the invention. For this reason, the corresponding further developments of the central processing unit according to the invention are not described again here.
[0033] The invention also includes combinations of the features of the described embodiments.
[0034] An embodiment of the invention is described below. It shows: Fig. 1 shows a method for generating a characteristic value table; Fig. 2 shows a method for authenticating a vehicle to a service unit using a vehicle-external central processing unit; Fig. 3 shows a characteristic value table and the associated query table; and Fig. 4 shows a method for authenticating a vehicle to a service unit using a vehicle-external central processing unit.
[0035] The exemplary embodiment explained below is a preferred embodiment of the invention. In the exemplary embodiment, the described components of the embodiment each represent individual, independently considered features of the invention, which also further develop the invention independently of one another and are thus also to be considered as components of the invention, either individually or in a combination other than that shown. Furthermore, the described embodiment can also be supplemented by further features of the invention already described.
[0036] In the figures, functionally identical elements are provided with the same reference numerals.
[0037] Fig. 1 shows a method for generating a characteristic value table. The aim of a coupling is to integrate a vehicle 1 into a system so that it can be authenticated to third parties. In order to enable authentication of the vehicle 1, it is provided to use an authentication unit 2. The authentication unit 2 can, for example, comprise a microprocessor and / or a microcontroller. The authentication unit 2 can be installed in the vehicle 1 or connected to the vehicle 1 as an accessory. In this case, it can be provided, for example, that the authentication unit 2 is connected, for example as a plug (stick or dongle), to an OBD interface of the vehicle 1. To couple the vehicle 1, it can be provided that a driver or owner of the vehicle 1 makes a predetermined user input in an input unit 3.The input unit 3 can be, for example, a mobile device, in particular a smartphone, a tablet, or a laptop. It can also be a console of the vehicle 1.
[0038] It can be provided that the user enters personal identification data and / or login data as part of the user input. After the user input, a coupling signal 5 can be generated by the input unit 3 and transmitted to a central processing unit 4. The coupling signal 5 can, for example, comprise the user's login data and / or information about the vehicle 1 and / or the authentication unit 2. The transmission of the coupling signal 5 can, for example, take place via mobile internet. In response to receiving the coupling signal 5, the central processing unit 4 can send at least one request command 6 to the authentication unit 2 to request an assigned characteristic value 7. The transmission can, for example, take place directly to the authentication unit 2 via mobile internet or via the input unit 3.The request command 6 can be received by the authentication unit 2 and stored in a request table 8. The request command 6 can also be output by the authentication unit 2 to an interface 9 of the vehicle 1. The interface 9 can be, for example, an OBD port of the vehicle 1 or a connection to an Ethernet network of the vehicle 1.
[0039] In the vehicle 1, a vehicle component 10 can receive the request command 6, execute it, and output the characteristic value 7 as an output value in response. The vehicle component 10 can be, for example, an engine control unit of the vehicle 1. The characteristic value 7 can be, for example, an identification number of the engine control unit. The characteristic value 7 can be output from the interface 9 of the vehicle 1 and received by the authentication unit 2. The characteristic value 7 can be transmitted to the central processing unit 4 by the authentication unit 2. The central processing unit 4 can receive the characteristic value 7 and store it in a characteristic value table 11. The characteristic value table 11 and the request table 8 can have an index, wherein a request command 6 in the request table 8 is assigned the respective characteristic value 7 in the characteristic value table 11 via an index value 13.By creating the query table 8 and the characteristic value table 11, a shared secret is provided to the central processing unit 4 and the authentication unit 2. The query commands 6 are designed to result in the output of the same characteristic value 7 from the vehicle 1. The advantage is that the authentication unit 2 is functionally connected to the vehicle 1. If, for example, the authentication unit 2 is integrated into a different vehicle, this results in a different characteristic value 7 being output when the query command 6 is input to the vehicle 1. During the coupling, a secret value S can be generated by the central processing unit. The secret value S can be transmitted to the authentication unit 2 and stored as another secret value S' in the central processing unit 4.
[0040] Fig. 2 shows an authentication of the vehicle 1 at a service unit 12 via the central processing unit 4. It can be provided that a function that is connected to the vehicle 1 and is carried out by a service unit 12 requires authentication of the vehicle 1 to the service unit. The service unit 12 can be, for example, a fuel pump at a petrol station, a charger or a barrier. It can be provided that only certain vehicles are intended for the service unit 12 or a function of the service unit 12. A communication connection C1 between the vehicle 1 or the authentication unit 2 and the service unit 12 can, for example, exist via an insecure connection. This can mean, for example, that the communication is unencrypted.For this reason, it can be ruled out that sensitive information for the authentication of vehicle 1 to service unit 12 is sent via communication link C1. To nevertheless enable secure, reliable authentication of vehicle 1 to service unit 12, the authenticity of vehicle 2 to service unit 12 is confirmed by central processing unit 4.
[0041] For example, it can be provided that a driver of the vehicle 1 makes an input in the service unit 12 at the beginning of an authentication process. It can also be provided that the authentication process is initiated automatically by the service unit 12 when, for example, the vehicle 1 is at a predetermined distance from the service unit 12. This can be the case, for example, when the vehicle 1 is located in front of a service unit 12 designed as a barrier. The method can provide for communication to be initiated between the service unit 12 and the authentication unit 2. During the method, communication can be established simultaneously between the service unit 12 and the central processing unit 4.To enable secure authentication, it may be provided that the communication between the central processing unit 4 and the service unit 12 is encrypted via a secure communication connection C2. It may be provided that an additional communication connection C3 is established between the authentication unit 2 and the central processing unit 4, which can be established via the input unit 3.
[0042] Fig. 3 shows a possible characteristic value table 11 with the respective characteristic values 7, which is stored in the central processing unit 4. Each of the characteristic values 7 can be assigned an index value 13. Characteristic values 7 can be values that identify the vehicle 1 or components of the vehicle 10. In particular, these can be a make of the vehicle 1, a model, a year of manufacture, a VIN number, a chassis number, or an identification number of an engine control unit. The individual characteristic values 7 together form a so-called fingerprint of the vehicle 1 in the characteristic value table 11, which enables a unique identification of the vehicle 1.
[0043] As a corresponding counterpart to the authentication of the vehicle 1, a request table 8 is stored in the authentication unit 2, in which the request commands 6 with the assigned index values 13 can be stored. A respective request command 6 with a respective index value 13 is assigned a corresponding characteristic value 7 in the characteristic value table 11 with the same index value 13. The request command 6 can, for example, be a code for the CAN bus of the vehicle 1, which causes the assigned characteristic value 7 to be output from the interface 9. In other words, the characteristic values 7 in the characteristic value table 11 are the expected values that are to be output by the vehicle 1 when a request is sent to the vehicle 1 using the assigned request command 6.The request commands 6 can, for example, be request commands 6 that have been transmitted by the central processing unit 4 to the authentication unit 2 during the coupling process in order to query the associated characteristic values 7 of the vehicle 1.
[0044] Fig. 4 shows a sequence of a method for authenticating a vehicle 1. It can be provided that the central processing unit 4, the service unit 12 and the authentication unit 2 are set up to carry out check values using a check value function h. It can be provided that the central processing unit 4 and the authentication unit 2 are coupled to one another, which means that the coupling method has been carried out with the central processing unit 4 and the authentication unit 2. Coupled can mean, for example, that the further secret value S', the identification value ID of the authentication unit 2 and the characteristic value table 11 are stored in the central processing unit 4. The secret value S, the identification value ID and the request table 8 can be stored in the authentication unit 2.
[0045] At the beginning of the method, it may be provided that the service unit 12 generates an initial value Nr using a random function or a pseudorandom function. The initial value Nr can be transmitted from the service unit 12 to the authentication unit 2 (S1).
[0046] After the initial value Nr has been received by the authentication unit 2, the authentication unit 2 can generate another initial value Np using a random function (S2).
[0047] The authentication unit 2 can calculate a session check value V from the secret value S, the first initial value Nr and the second initial value Np by means of the check value function h, which session check value V can be assigned to the secret value S, the first initial value Nr and the second initial value Np (S3).
[0048] The next sub-step S4 comprises a determination of the index value 13 by the authentication unit 2 in order to be able to read one of the request commands 6 from the request table 8. It can be provided that the selection of the index value 13 is dependent on the secret value S, the initial value Nr, and the second initial value Np. For this purpose, it can be provided that the index value 13 is calculated from the session check value V using a selection function m. For example, it can be provided that the index value 13 is a remainder of a division of the session check value V by the number 10.
[0049] From the request table 8, the authentication unit 2 reads the request command 6, which is assigned to the calculated index value 13 (S5). The read request command 6 is output by the authentication unit 2 to the interface 9 of the vehicle 1 and received by the vehicle component 10 (S6). As in the coupling process, the vehicle component 10 outputs a response signal R, which is identical to the characteristic value 7 (S7). The authentication unit 2 can receive the response signal R from the interface 9 (S10). Using the check value function h, the authentication unit 2 can calculate a vehicle check value Hr assigned to the response signal R (S11). In addition, it can be provided that the authentication unit 2 calculates an identification check value H from the identification value ID using the check value function h (S12).
[0050] The session check value V, the vehicle check value Hr, the identification check value H and the further initial value Np can be transmitted from the authentication unit 2 to the service unit 12 (S13).
[0051] The service unit 12 can receive the values and forward them together with the initial value Nr to the central processing unit 4 (S14).
[0052] Upon receiving the values, the central processing unit 4 can check in a step S15 whether the identification check value H of the authentication unit 2 is registered in an identification table 14 in the external processing unit 4. For this purpose, the central processing unit 4 can compare the identification check value H with identification check values stored in an identification table 14. If the transmitted identification check value H matches one of the stored identification check values H in the identification table 14, this means that the authentication unit 2 is registered in the central processing unit 4.
[0053] In a step S16, the central processing unit 4 uses the check value function h to calculate a further session check value V' from the further secret value S', the initial value Nr and the further initial value Np. If the further session check value V' calculated by the central processing unit 4 matches the session check value V sent by the authentication unit 2, the index value 13 can be calculated from the further session check value V' in a next step S17 using the selection algorithm m. The central processing unit 4 reads the characteristic value 7 from the characteristic value table 11, which is assigned to the calculated index value 13. For the read characteristic value 7, a further vehicle check value Hr' can be calculated using the check value function h.Subsequently, the central processing unit 4 checks whether the further vehicle test value Hr' calculated by the central processing unit 4 matches the vehicle test value Hr sent by the authentication unit 2.
[0054] If this is the case, the central processing unit 4 sends an enable signal 16 to the service unit 12 to signal that the authentication unit 2 has been successfully authenticated by the central processing unit 4 (S18). The enable signal can, for example, be the additional secret value S'.
[0055] The service unit 12 can calculate a first release check value M from the further secret value S' and the initial value Nr using the check value function h (S19). From the first release check value M, the service unit 12 can calculate a second release check value N (S20).
[0056] In a subsequent step, the service unit 12 can send the first release check value M to the central processing unit 4 (S21).
[0057] The central processing unit 4 can calculate an update value U from the secret value S and the first release check value M using the check value function h (S22).
[0058] By means of an update function, the central processing unit 4 can update the further secret value S' (S23) so that it has a different value after the update than before the update.
[0059] The second release check value N can be transmitted to the authentication unit 2 by the service unit 12 (S24).
[0060] The authentication unit 2 can calculate the first release check value M' from the initial value Nr and the secret value S using the check value function (S25) and the second release check value N' from the first release check value M' using the check value function (S26). In a further step S27, the authentication unit 2 checks whether the second release check value N' calculated by it matches the received second release check value N. If this condition is met, the update value U is calculated from the secret value S and the second release check value M' using the check value function (S28). The secret value S is replaced by an updated secret value S using the update value U (S29).
[0061] In a further step S30, it may be provided that a predetermined communication input is initiated between the service unit 12 and the authentication unit 2 or a control unit of the vehicle 1. It may also be provided that a predetermined function is activated in the service unit 12. The predetermined function may, for example, include opening a barrier, dispensing fuel, or initiating a charging process.
[0062] Vehicles have become an integral part of our lives. They transport the majority of people and goods. During a vehicle's life cycle, which extends from its manufacture to its scrapping, the driver uses a variety of vehicle-related services.
[0063] Until now, the use of vehicle-related services required actions on the part of the vehicle driver. For example, the driver had to enter into a written or verbal contract or operate a vending machine. Vehicle-related services include, for example, providing a parking space, refueling the vehicle, or requesting maintenance or breakdown assistance.
[0064] With the introduction of the smartphone, life and the use of services have changed dramatically. Nowadays, almost all services are offered in digital form and can be managed via smartphone. This development has not yet had an impact on motor vehicle-related services, or has only had a limited impact. A motor vehicle-related service is defined as a set of transactions between a service provider and a customer. The customer could be, for example, the driver or the owner of the vehicle. Motor vehicle-related services require, at a minimum, a contract outlining the contract components, authentication of the driver or vehicle to ensure identity, and authorization of the service by the vehicle driver, for example in the form of a handwritten or digital confirmation.
[0065] Typical examples of motor vehicle-related services include refueling the vehicle, charging the vehicle or using a paid parking space for the vehicle.
[0066] Depending on the region or target audience, different types of transactions may be common. In the German-speaking market, it is common for a gas station to offer its services only during certain business hours of the day. These business hours are determined by the presence of a gas station employee. During business hours, the customer agrees to the terms and conditions (fuel price, payment terms, minimum purchase quantity) by refueling their vehicle at the gas station. The transaction is considered complete once the customer has paid for the purchased fuel at the gas station cash register.
[0067] In other countries, such as Italy, Canada, and the United States, it is common for gas station services to be available 24 hours a day, every day of the week. To accommodate these business hours, gas stations have equipped their pumps with payment systems. These payment systems require the customer to authorize payment before refueling. Typically, a customer specifies a specific amount (for example, 100 dollars or euros) for which the vehicle can be refueled. If less fuel is used, the actual amount is charged. If the vehicle is operated as part of a company fleet or a rental car fleet, it is common for the driver to be provided with fuel cards. These fuel cards can be used as a means of payment at certain gas stations. In this case, the customer is required to enter relevant information during the payment process.This is usually the current mileage of the vehicle to be refueled.
[0068] The above-mentioned state of the art presents several disadvantages: Motor vehicle-related services and the associated transactions are predominantly manual and therefore time-consuming and costly. Manual processing steps make the execution and transactions error-prone. Motor vehicle records are primarily documented on paper and therefore require meticulous maintenance to ensure a complete record. Authorization of motor vehicle-related services using manual or paper-based solutions is slow, error-prone, expensive, and requires extensive archiving effort.
[0069] These problems can be solved by pre-defining the vehicle-related services used by the driver and storing their login credentials on a central processing unit. Automated authentication and authorization of the services at the service units can be performed by the central processing unit.
[0070] The invention comprises four main components: The first component is the input unit 3. The input unit 3 (for example, a smartphone / tablet / PC / vehicle console) can have a user interface in which the driver can enter their access data and activate the desired services. The other main components are the authentication unit 2, the service unit 12, which is located at the service provider, and the central processing unit 4, which is configured to authenticate and authorize the authentication unit 2 at the service unit 12.
[0071] The method provides that all authentication units 2 provided for the method must undergo a predetermined pairing process, whereby the driver loads their login data into the central processing unit 4 and links the authentication unit 2 to their vehicle 1. The driver performs this pairing process using the input unit 3. Once the pairing process is completed, the authentication unit 2, which is arranged in the vehicle 1, can wirelessly authenticate itself to the service units 12 using the central processing unit 4 and use the offered services.
[0072] The solution provides the following advantages: Authentication of vehicle 1 by authentication unit 2 is performed using the characteristic values 7 provided from interface 9 (e.g., the OBD port) of vehicle 1. If authentication unit 2 is used with a different vehicle 1, authentication unit 2 will receive different characteristic values 7 from interface 9. Consequently, authentication will fail.
[0073] Fast, secure and automatic authentication of drivers and subsequent authorization of services at the service units 12 is enabled.
[0074] Vehicle-based authentication and authorization of services is driver-independent. This is an advantage for vehicles 1 used by multiple drivers, for example, multiple family members or different renters.
[0075] Fast and automatic authentication of driving licenses and vehicle documents can be carried out.
[0076] The procedure provides the driver with a central system through which he can register for various vehicle-related services.
[0077] In general, the solution is applicable to all motor vehicle-related services. In particular, the process can be used in connection with automated and cashless payments at gas stations, automatic vehicle identification, and the associated granting of entry to parking lots. It can also be used to enable the automatic handover of a rental car.
[0078] Fig. 1 shows the coupling of an authentication unit 2. The driver uploads his login data to the central processing unit 4 and selects the services he wants. The input unit 3 guides the driver through the coupling process, in which the authentication unit 2 is linked to the vehicle 1 with the involvement of the central processing unit 4. The central processing unit 4, with the help of the authentication unit 2, searches the vehicle 1 for data and identifies a subset of data, the so-called key values 7, which remain constant during the usage time of the authentication unit 2 in the vehicle 1. These key values 7 are used as a so-called fingerprint of the vehicle 1 and are also referred to as a key set. The key set can also be time-dependent, since there are key values 7 that are transient but remain constant for a specific driver during the usage time of the authentication unit 2.This could, for example, be an inspection appointment. For example, it is not expected that a rental car will be serviced by the renter during the rental period, which would result in the inspection appointment changing. The central processing unit 4 records data including the driver details and the vehicle identification code.
[0079] Authentication unit 2 that are relevant for the authentication of vehicle 1.
[0080] Fig. 2 shows the application of the authentication unit 2. This can only occur if the authentication unit 2 has been coupled to the vehicle 1. In this method, the authentication unit 2 authenticates itself to the service unit 12. The service unit 12 verifies the authenticity of the authentication unit 2 using the central processing unit 4 and provides the requested service to the vehicle 1.
[0081] The driver of vehicle 1 has the option of subsequently activating additional services they wish to use while using the authentication unit 2. For example, it may happen that the driver is on vacation in a city for which they have not activated the use of parking spaces or refueling. They may stop at a gas station or parking lot with a service unit 12, and the central processing unit 4 authenticates their identity. During the process, the central processing unit 4 can check whether the service identifier F and / or the service unit 12 are permitted in the register table 15 for the identification check value H.In other words, at least one value can be assigned to a respective identification check value H in the register table 15, which value indicates which services or service units 12 are enabled by the central processing unit 4 for the identification check value H and thus for the authentication unit 2 with the associated identification value ID. In this case, it can be determined that for the authentication unit 2, the services of the service identifier F are not enabled at the service unit 12 at this location. The enable signal 16 is therefore not sent by the central processing unit 4. In this case, a query signal B can be sent to the user's input unit 3. Upon receipt of the query signal B, the input unit 3 can output a warning signal, whereby the user can be asked whether they wish to use the services at the service unit 12 despite the lack of activation.The relevant contractual components for the services can be displayed on the input unit 3. If the driver agrees to these conditions by means of a predetermined user input, the input unit 3 can transmit an activation signal A to the central processing unit 4. The central processing unit 4 can then send the release signal 16 to the service unit 12, thus authorizing the service unit 12 to provide the services of the service identifier F.
[0082] Overall, the example shows how the invention can provide automatic authentication of vehicles for the authorization of vehicle-related services.
Claims
1. Method for authenticating a vehicle (1) with a service unit (12) by way of a central computer unit (4) external to the vehicle, wherein - an authentication unit (2) is provided in the vehicle (1), - an initial value (Nr) is transmitted from the service unit (12) to the authentication unit (2), - depending on the initial value (Nr), the authentication unit (2) reads a request command (6) from a request table (8) stored in the authentication unit (2), - the request command (6) is output by the authentication unit (8) to an interface (9) of the vehicle (1), - in the vehicle (1), a vehicle component (10) executes the request command (6) and generates an output value (R) in response, - the output value (R) from the interface (9) is received by the authentication unit (2), - the authentication unit (2) uses a predetermined check value function (h) to generate a vehicle check value (Hr) from the output value (R), - the vehicle check value (Hr) generated from the output value (R) and the initial value (Nr) are transmitted to the central computer unit (4), - depending on the initial value (Nr), the central computer unit (4) reads a characteristic value (7) from a characteristic value table (11) stored in the central computer unit (4), - the central computer unit (4) uses the predetermined check value function (h) to generate a further vehicle check value (Hr') from the characteristic value (7), - the vehicle check value (Hr) generated from the output value (R) and the further vehicle check value (Hr') generated from the characteristic value (7) are checked with one another for a match by the central computer unit (4), and - in the event that the vehicle check values (Hr) match, the central computer unit (4) sends a predetermined enable signal (16) to the service unit (12).
2. Method according to Claim 1, characterized in that - an identification value (ID) uniquely associated with the respective authentication unit (2) is stored in the authentication unit (2), - the authentication unit (2) uses the check value function (h) to generate an identification check value (H) from the identification value (ID), - the identification check value (H) is transmitted together with the vehicle check value (Hr) to the central computer unit (4), - the central computer unit (4) checks the identification check value (H) against entries in an identification table (14) stored in the computer unit (4) for a match, and - the central computer unit (4) sends the predetermined enable signal (16) to the service unit (12) only if one of the entries in the identification table (14) matches the identification check value (H).
3. Method according to either of the preceding claims, characterized in that - the authentication unit (2) generates a second initial value (Np), - a secret value (S) is stored in the authentication unit (2), - a further secret value (S0) is stored in the central computer unit (4), - the authentication unit (2) uses a further predetermined check value function (h) to generate a session check value (V) from the secret value (S), the initial value (Nr) and the further initial value (Np), - the session check value (V) is transmitted together with the vehicle check value (Hr) associated with the characteristic value (7) to the central computer unit (4), - the central computer unit (4) uses the check value function (h) to generate a further session check value (V') from the further secret value (S1), the initial value (Nr) and the further initial value (Np), - the central computer unit (4) checks the further session check value (V') and the session check value (V) for a match, and - the central computer unit (4) sends the predetermined enable signal (16) to the service unit (12) only if the session check value (V) matches the second session check value (V').
4. Method according to Claim 3, characterized in that - the central computer unit (4) sends the further secret value (S0) as the predetermined enable signal (16) to the service unit (12), the service unit (12) - uses the check value function (h) to calculate a first enable check value (M) from the further secret value (S0) and the initial value (Nr), - uses the check value function (h) to calculate a second enable check value (N) from the first enable check value (M), - transmits the first enable check value (M) to the external central computer (4), - transmits the second enable check value (N) to the authentication unit (2), the central computer unit (4) - uses the check value function (h) to calculate an update value (U) from the further secret value (S0) and the first enable check value (M), - uses a predetermined update function to update the further secret value (S0) with the update value (U), the authentication unit (2) - uses the check value function (h) to calculate a further first enable check value (M') from the secret value (S) and the first initial value (Nr), - uses the check value function (h) to calculate a further second enable check value (N') from the further first enable check value (M'), - in the event that the further second enable check value (N') and the second enable check value (N) match, - uses the check value function (h) to calculate the update value (U) from the secret value (S) and the further first enable check value (M'), and - uses the predetermined update function to update the secret value (S) with the further update value (U1).
5. Method according to one of the preceding claims, characterized in that - the request command (6) to be read from the request table (8) and the characteristic value (7) to be read from the characteristic value table (11) are selected by way of a predetermined selection function depending on the session check value (V).
6. Method according to Claim 5, characterized in that the selection function is the Luhn algorithm.
7. Method according to one of the preceding claims, characterized in that a communication procedure is initiated between the service unit (12) and the authentication unit (2) and / or a controller of the vehicle (1) following reception of the enable signal (16) by the service unit (12).
8. Method according to one of the preceding claims, characterized in that - the service unit (12) transmits a service identifier (F) to the central computer unit (4), - the central computer unit (4) checks whether the service identifier (F) for the identification value (ID) is activated in the central computer unit (4), - the central computer unit (4) sends the predetermined enable signal (16) to the service unit (12) only if the service identifier (F) for the identification value (ID) is activated.
9. Method according to one of the preceding claims, characterized in that the transmissions between the authentication unit (2) and the central computer unit (4) are routed via the service unit (3).
10. Method according to Claim 8 or 9, characterized in that - the central computer unit (4) transmits a predetermined query signal (B) to an input unit (3) if the service identifier (F) for the identification value (ID) is deactivated, - the input unit (3) outputs a predetermined warning signal upon receiving the query signal (B), - in the case of a predetermined user input, the input unit (3) sends an activation signal (A) to the central computer unit (4), and / or - the central computer unit (4) activates the service identifier (F) for the identification value (ID).
11. System comprising an authentication unit (2), a service unit (12) and a computing unit (4), configured to carry out a method according to one of the preceding claims.