Method, apparatus, and system for authenticating access to shared vehicle
Patent Information
- Application Number
- JP2022130060
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2021-08-18
- Filing Date
- 2022-08-17
- Publication Date
- 2025-05-30
AI Technical Summary
Existing vehicle access control systems for shared fleets face challenges when vehicles are parked in areas without network coverage, leading to failed access authorizations due to memory limitations and inability to update reservations.
A method and device for managing vehicle access reservations that involve a server manipulating a local representation of the vehicle's memory, allowing asynchronous updates via short-range wireless connections, prioritizing newer reservations, and using temporary storage for deprioritized reservations.
Enables access authorization even in areas without network coverage by asynchronously updating vehicle memories, improving responsiveness and avoiding memory constraints.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of controlling access to vehicles, and more particularly, to a method for distributing virtual keys for accessing shared vehicles.
[0002] Prior Art For decades, the problem of controlling access to vehicles has been solved through one or more physical keys held by the vehicle owner. With the development of in-vehicle electronic devices, conventional keys have been gradually replaced by electronic devices with the ability to communicate wirelessly, enabling non-contact access to the vehicle and starting the vehicle.
[0003] However, when it is a problem to share a vehicle among multiple users, especially when a fleet of vehicles is placed at the pick-up and drop-off locations of a large number of users, such a key system is not suitable. In particular, the use of such physical keys involves steps of receiving and returning the keys, resulting in additional costs and lack of flexibility (such as limited opening hours, the need for personnel to hand over and collect the keys, etc.).
[0004] The development of cellular communication networks and the incorporation of in-vehicle communication devices into vehicles have made it possible to improve the situation by enabling new methods of controlling access.
[0005] Thus, a technology is known that consists of transmitting one or more access authentications to a vehicle via a wireless connection. Such authentication for accessing the vehicle is associated with a specific user who is provided with an identification device such as an NFC tag. Alternatively, a specific identifier may be provided on the user's mobile device. When a user attempts to access the vehicle, the identifier contained in the user's tag or mobile device is transmitted to the vehicle's communication unit, for example, via a Bluetooth or NFC connection, within a certain time frame, so that the vehicle can verify that the user is indeed authorized to access the vehicle. At the end of the period of use permitted to the user, the authentication is revoked.
[0006] Such technologies will clearly improve the situation, especially by allowing users to rent and return vehicles at any time.
[0007] However, the limitations of this system become apparent when vehicles are parked in locations not covered by the network, such as underground parking garages. Under these circumstances, vehicles can no longer receive new access authentication. For example, a self-service scooter left in an uncovered area after being used by the last user can no longer be reserved.
[0008] To overcome these shortcomings, it has been proposed to indirectly transmit vehicle access authentication via the user's mobile device. For this purpose, each vehicle in the fleet is equipped with a reservation calendar and an online server assigned to monitoring it. When a user wishes to reserve a vehicle, they send a request to the server. The server then generates an authentication if the vehicle is available within the desired time range. If the vehicle is unavailable, all pending authentications for that vehicle are sent to the user's mobile device. In this way, when a user wishes to access a vehicle, the authentication stored on the user's mobile device is sent to the vehicle, which then can either authenticate access or not.
[0009] In this way, even if a vehicle is unavailable, it can still be reserved and accessed. Nevertheless, for cost reasons, the memory locations available to store future reservations and authentications in a vehicle are limited. Therefore, a problem arises when a user attempts to access a vehicle that does not have network coverage, and the vehicle's memory already contains the maximum number of reservations. That is, even though the user has reserved the vehicle, they will be unable to access it because the vehicle cannot load the corresponding authentication.
[0010] Therefore, technology is needed to improve this situation.
[0011] Summary of the Invention For this purpose, a method is provided to manage authentication for accessing shared vehicles. The vehicle is equipped with memory designed to store the maximum number of reservations simultaneously. This method is executed when a request to reserve a vehicle is received by a server that has a local memory representation of the vehicle, namely, -The method includes a step of obtaining a first reservation for the vehicle, the reservation being associated with at least the reservation start date, the reservation end date, and the identifier of the mobile device used to access the vehicle, and this method further includes -When the number of reservations stored in the vehicle's memory local representation reaches the maximum number of reservations that can be simultaneously stored in the vehicle's memory, -Select a second reservation from the reservations stored in the vehicle's memory's local representation, and ensure that the start date of the second reservation is later than the start date of the first reservation. -In the local representation of the vehicle's memory, the second reservation is replaced by the first reservation. -at least, - A command to delete the second reservation, and - Command to add the first reservation The process includes the step of sending a memory synchronization command to the vehicle.
[0012] The reservation server manipulates an image of the vehicle's memory. This image of the vehicle's memory is synchronized with the vehicle's physical memory through the transmission of commands to add and remove reservations to the vehicle. In this way, the responsiveness of the reservation system is improved, and the vehicle's memory is updated asynchronously. Furthermore, by lowering the priority of subsequent reservations to favor newer reservations with earlier start dates, it is possible to avoid being constrained by the number of physically available memory locations in the vehicle. This further improves the responsiveness of the reservation system.
[0013] According to one particular embodiment, the method has a substep of sending a command to add a first reservation and a command to delete a second reservation, which sends the above command to at least one mobile terminal associated with an identifier to the reservation stored in memory associated with the vehicle, such that the mobile terminal resends the above command via a short-range wireless connection during a vehicle handover.
[0014] In this way, access authentication can be transmitted to the vehicle even if it is parked in an uncovered area. For example, if a vehicle is returned to an underground parking garage outside the cellular network area, the vehicle's memory can be updated with the new reservation when the user acquires ownership of the vehicle. In other words, the mobile device used to unlock the vehicle is used to asynchronously update the reservation in the vehicle's memory.
[0015] In one particular embodiment, this method temporarily stores the characteristics of a second reservation in the exchange step, and this method further proceeds to the next step, namely, when the reservation slot is released in the local representation of the vehicle's memory, - A step of generating a third reservation having the characteristics of a temporarily stored second reservation, - A step of storing a third reservation in the local representation of the vehicle's memory, - A method having the step of sending a command to the vehicle to add a third reservation.
[0016] In the memory associated with a vehicle, if a later reservation is replaced by a more recent reservation, the characteristics of the deleted reservation are stored in temporary memory. In this way, for example, if the location in memory is freed following the expiration or cancellation of a reservation, the data about the replaced reservation can be used to generate a new reservation.
[0017] According to one particular embodiment, the reservation is at least, - First reservation data for mobile devices, which includes the mobile device's public key, reservation start date, and reservation end date, - It includes a second reservation data set which is for a vehicle and has the vehicle's public key, reservation start date, and reservation end date.
[0018] The first and second reservation data correspond to the virtual key of the mobile device authorized to unlock the vehicle and the second virtual key of the reserved vehicle, respectively. Therefore, the data that enables access to the vehicle is distributed between the access device, such as the user's smartphone, and the reserved vehicle. This allows the device to grant access only to the vehicle it has reserved, and the vehicle to grant access only to the device it has reserved.
[0019] In another aspect, the present invention relates to a device for managing authentication for accessing a shared vehicle, wherein the vehicle is provided with memory designed to simultaneously store a maximum number of reservations, and the device comprises a local representation of the vehicle's memory, a processor, and memory, wherein when an instruction is executed by the processor, the following steps occur, namely, - A step of obtaining a first reservation for a vehicle, wherein the reservation is associated with at least a reservation start date, a reservation end date, and an identifier of a mobile device used to access the vehicle. -When the number of reservations stored in the vehicle's memory local representation reaches the maximum number of reservations that can be simultaneously stored in the vehicle's memory, -Select a second reservation from the reservations stored in the vehicle's memory's local representation, and ensure that the start date of the second reservation is later than the start date of the first reservation. -In the local representation of the vehicle's memory, the second reservation is replaced by the first reservation. -at least, - A command to delete the second reservation, and - Command to add the first reservation The above memory is stored in the memory and includes the step of sending a memory synchronization command to the vehicle and an instruction configured to perform the following:
[0020] The present invention also relates to a server having the management device described above.
[0021] According to yet another aspect, the present invention relates to a data medium including computer program instructions configured to perform the steps of the method of managing access authentication as described above when the computer program instructions are executed by a processor.
[0022] The data medium may be a non - volatile data medium such as, for example, a hard disk, a flash memory, or an optical disk.
[0023] The data medium may be any entity or device capable of storing instructions. For example, the medium may have storage means such as ROM, RAM, PROM, EPROM, CD ROM, or may have magnetic recording means such as a hard disk.
[0024] Furthermore, the data medium may be a transmissible medium such as an electrical signal or an optical signal that can be transferred via an electrical cable or an optical cable, wirelessly, or by other means.
[0025] Alternatively, the data medium may be an integrated circuit in which the program is incorporated, and this circuit can execute the method in question or can be used for the execution of the method in question.
[0026] The various embodiments and features described above can be added to the steps of the management method independently or in combination with each other. The server and the device have at least advantages similar to those provided by the methods to which they are related.
[0027] Another feature and advantage of the present invention will become clearer by reading the following description. This description is purely explanatory and should be read with reference to the accompanying drawings.
Brief Description of the Drawings
[0028] [Figure 1]This figure shows a suitable environment for implementing a method of managing reservations according to one specific embodiment. [Figure 2] This figure shows the main steps of a control method according to one specific embodiment. [Figure 3] This figure shows a server environment suitable for implementing the management method according to another specific embodiment. [Figure 4] This diagram shows the availability of reservations.
[0029] Detailed explanation Figure 1 shows a shared vehicle 100. Vehicle 100 forms part of a fleet of vehicles that can be reserved remotely by a user, for example.
[0030] The user can access the vehicle 100 via a communication terminal 103, such as a smartphone, smartwatch, tag, or tablet. To do this, the mobile terminal 103 has memory in which first reservation data is stored. The first reservation data is a virtual key 105 of the mobile terminal 103, which allows the mobile terminal 103 to access the reserved vehicle. The virtual key of the mobile terminal has at least the vehicle's public key, the reservation start date, and the reservation end date. Optionally, the first reservation data may further include the right to access specific functions or equipment of the vehicle, such as the right to access the trunk, or the right to use the air conditioning, entertainment system, or network connectivity.
[0031] During a request to access the vehicle, terminal 103 transmits its virtual key 105 to vehicle 100 via a wireless network connection, such as Bluetooth®, Wi-Fi®, NFC, and / or a 2G, 3G, 4G, or 5G cellular network connection.
[0032] Vehicle 100 is equipped with wireless communication means, such as Bluetooth®, Wi-Fi®, or NFC network interfaces, and / or 2G, 3G, 4G, or 5G cellular network interfaces, which enable the vehicle to establish connections 102 with other devices such as terminals 103, and in particular to receive virtual keys 105 from mobile terminals.
[0033] The vehicle 100 further includes memory 104, such as flash memory, RAM, or EEPROM, which is configured to store a predetermined maximum number of second reservation data for future reservations, for example, 10 reservations. The second reservation data is a virtual key for the vehicle. The maximum number of reservations that the vehicle can store is limited, for example, by the amount of physical memory installed.
[0034] More precisely, the vehicle's memory 104 may store a virtual vehicle key for the purpose of authenticating or denying access to the vehicle. The virtual vehicle key stored in the vehicle's memory 104 has at least the public key of a mobile device authorized to unlock the vehicle, a reservation start date, and a reservation end date. Optionally, the vehicle's virtual key may further have authorization to access one or more parts of the vehicle's equipment, such as the trunk or the air conditioning, or a duration and / or maximum number of uses of a particular function, such as a usage time limit or download limit associated with a network connection.
[0035] Finally, the vehicle 100 has a computer with a processor and memory, for example, an ECU 106, in which the memory stores computer program instructions configured to process access requests to the vehicle and, in particular, to grant or deny access to the vehicle by evaluating the match between the virtual key of the mobile terminal, transmitted by the terminal 103, and the virtual key of the vehicle, stored in memory 104, and also based on the current date obtained from the clock of the ECU 106. More precisely, the server signs the vehicle and terminal virtual keys using the server's private key, so the vehicle can check the authenticity of the mobile terminal virtual key using the server's public key, which is delivered to the vehicle in advance.
[0036] Figure 1 also shows a server 107 of the communication network 108. The server 107 has a communication means, for example, a network interface that allows the server 107 to set up connections with other devices, and in particular to exchange messages with a mobile terminal 103 and / or a vehicle 100 via a cellular access network (not shown). More precisely, the network interface allows the server to send first reservation data, i.e., a virtual key 105, to the mobile terminal 103 and second reservation data, for example, a virtual key 110, to the vehicle 100. The server further has a processor and memory, the memory storing a number of computer program instructions, which, when executed by the processor, configure the server to perform steps of a method for managing access authentication according to one particular embodiment of the present invention.
[0037] Server 107 is provided with a database 109 that stores a representation of the vehicle 100's memory 104. Therefore, the database 109 can store reservation data to be stored or recorded in the vehicle 100's memory 104. The database 109 has the same storage capacity as the vehicle 100's memory 104. When a reservation for vehicle 100 is added or canceled, server 107 updates the corresponding record in database 109, synchronizing database 109 with the vehicle 100's memory 104. The update in database 109 is reflected in the vehicle 100's memory 104 via commands to add and / or delete reservations sent to the vehicle 100. In one particular embodiment, commands to add and / or delete reservations are sent to the vehicle via a cellular network. In one particular embodiment, commands for adding and / or deleting are sent to the vehicle via terminal 103, which can synchronize the vehicle 100's memory 104 with the database 109. Therefore, the server 107 first sends an update command to the terminal 103, and then the terminal 103 sends these commands to the vehicle 100.
[0038] Next, we will describe how authentication is managed, referring to Figure 2. Figure 2 shows the main steps of how authentication is managed, according to one specific embodiment, in the form of a flowchart.
[0039] In the first step 200, the server 107 receives a request to reserve a vehicle 100. The vehicle is reserved by the user, for example, via a website or mobile application. Therefore, the reservation received by the server 107 includes at least one identifier of the vehicle 100 to be reserved, the reservation start date and reservation end date, and the identifier of the mobile terminal 103 of the user who reserved the vehicle.
[0040] More precisely, the reservation consists of two parts. The first part is for storage in the mobile terminal 103. This is for the virtual key of the mobile terminal, and at least - Public key for vehicle 100, -Reservation start date, -Reservations closed. It holds.
[0041] Optionally, the first reservation data may also have the right to access specific functions of the vehicle.
[0042] The first reserved data is signed with the server's private key to authenticate its source and integrity.
[0043] The reservation also has a second part for storage in the vehicle's memory 104. This is for the vehicle's virtual key and at least -Public key of mobile device 103, -Reservation start date, -Reservations closed. It holds.
[0044] Optionally, the second reservation data may also have the right to access specific functions of the vehicle.
[0045] The vehicle's virtual key is signed with the server 107's private key to authenticate its source and encrypted with the vehicle 100's public key. In this way, the vehicle's virtual key can be transmitted to the vehicle in a completely confidential manner via the user's mobile device.
[0046] In step 201, the server 107 searches for available locations in a local representation of the vehicle's memory, such as the database 108, where the received reservation can be stored. To do this, the server can, for example, use an appropriate SQL query to retrieve the number of records contained in the database 108, and then compare the number of records thus retrieved with the maximum number of reservations that can be stored in the vehicle's memory 104.
[0047] If, at the end of the comparison, it is determined that there are no available locations where the reservation can be stored, the server 107 performs step 202, in which the server 107 selects a reservation from among the reservations stored in the database 108 whose start date is after the start date of the newly acquired reservation. For example, the server selects the reservation with the furthest start date.
[0048] In step 203, server 107 stores the characteristics of the selected reservation. For example, the identifier of the vehicle, the reservation start date and reservation end date, and the identifier of the mobile device associated with the reservation are stored, for example, in a waiting list in database 109, which can then replace the reservation in database 108 and be sent to the vehicle when the location becomes available before the reservation starts.
[0049] In step 204, the server 107 deletes the selected reservation from the database 108, thereby freeing up space to store a new reservation. Then, in step 205, the vehicle's memory 104 is updated, thereby synchronizing its contents with those of the database 108.
[0050] To do this, in step 205, the server sends commands to the vehicle to delete the de-priority reservation and to add a new reservation. In one particular embodiment, these commands are sent directly to the vehicle via a cellular network. According to one particular embodiment, these commands are sent to the mobile terminals of one or more users for whom the reservation has been made. For example, these commands are sent to terminal 103 along with the first reservation data 105. In this way, when the user of terminal 103 acquires ownership of the vehicle, these commands can be sent to the vehicle and the memory 104 can be updated even if transmission via the cellular network would fail.
[0051] In one particular embodiment, when a location is released in the database 108, the server 107 regenerates a new reservation based on the characteristics of the reservation stored in step 203. This regeneration specifically involves generating a virtual key 105 for a mobile terminal and a corresponding virtual key 110 for a vehicle. The vehicle's virtual key can then be stored in the database 108 and sent to the vehicle.
[0052] In one particular embodiment, the server 107 is provided with three databases 200-202.
[0053] The first reserved portion, namely the virtual key for the user's mobile device 103, is stored in the database 200.
[0054] The second reservation portion, namely the virtual key intended to be stored in the vehicle's memory 104, is stored in the database 201.
[0055] Finally, the third database 202 has records that enable the formation of a link between the virtual key in database 200, which is the virtual key for the vehicle, and the virtual key in database 201, which is the virtual key for the mobile terminal.
[0056] Figure 4 shows the various states of the virtual key used for reservations.
[0057] In step 200, when the server receives a new reservation, the reservation enters the state "Upsert". When a virtual key is created for the mobile device and a virtual key is created for the vehicle, the reservation moves to the state "Upsert WIP". When the vehicle acknowledges that it has correctly received the virtual key sent to it, the reservation moves to the state "Upsert", meaning the vehicle indicates that it has received the key. As we have seen, the key can be sent to the vehicle directly via the cellular network, or in fact, via the mobile device of the user who reserved the vehicle. In this case, the vehicle's acknowledgment may also be sent to the server 107 via the user's mobile device. Receiving such an acknowledgment ensures that the representation of the vehicle's memory in database 201 actually represents the contents of the vehicle's memory 104.
[0058] If the priority of a virtual key loaded into the vehicle's memory 104 is lowered, that is, if it is replaced by a higher-priority key in steps 202 to 204, the corresponding virtual key returns to the state "upsert". In other words, a virtual key whose priority has been lowered must be sent back to the vehicle in order to return to the state "upsert" and become available again.
[0059] After the booking end date, the booking will take the status "Expd".
[0060] When a user cancels a reservation, the reservation moves to the "Rvke" state, and then to "RvkeWIP" when a cancellation message is sent to the vehicle. When the vehicle acknowledges the cancellation message, it returns to the "Rvked" state.
[0061] Such a state machine ensures synchronization between the contents of database 201 and the contents of the vehicle's memory.
Claims
1. A method for managing authentication for accessing a shared vehicle, wherein the vehicle is provided with a memory designed to store a maximum number of reservations simultaneously, and the method comprises the following steps that are executed when a request to reserve the vehicle is received by a server having a local representation of the memory of the vehicle, namely: - Obtaining a first reservation of the vehicle, wherein the reservation is associated with at least a reservation start date, a reservation end date, and an identifier of a mobile terminal used to access the vehicle; - When the number of reservations stored in the local representation of the memory of the vehicle reaches the maximum number of reservations that can be stored simultaneously in the memory of the vehicle, - Selecting a second reservation from the reservations stored in the local representation of the memory of the vehicle such that the start date of the second reservation is after the start date of the first reservation; - Replacing the second reservation with the first reservation in the local representation of the memory of the vehicle; - At least, - A command to delete the second reservation, and - A command to add the first reservation And transmitting a memory synchronization command having the commands to the vehicle; Step; A method comprising the steps.
2. Transmitting the command to add the first reservation and delete the second reservation has a sub-step of transmitting the command to at least one mobile terminal associated with the identifier in the reservation stored in the memory associated with the vehicle, and the mobile terminal is configured to retransmit the command via a short-range wireless connection during handover of the vehicle. The method according to claim 1.
3. Temporarily storing the characteristics of the second reservation in the exchange step, and the method further comprises the following steps when a reservation slot is released in the local representation of the memory of the vehicle, namely: - Generating a third reservation having the characteristics of the temporarily stored second reservation; - Storing the third reservation in the local representation of the memory of the vehicle; - Transmitting a command to add the third reservation to the vehicle; The method according to claim 1 or 2, comprising the steps.
4. The reservation is at least - First reservation data for the mobile terminal and having at least a public key of the mobile terminal, a reservation start date, and a reservation end date; - The method according to claim 1 or 2, which is for the vehicle and has second reservation data for the vehicle and at least the public key, reservation start date, and reservation end date of the vehicle.
5. An apparatus for managing authentication for accessing a shared vehicle, wherein the vehicle is provided with a memory designed to store a maximum number of reservations simultaneously, and the apparatus has a local representation of the memory of the vehicle, a processor, and a memory in which instructions are stored, and when the instructions are executed by the processor, the following steps, namely, - Obtaining a first reservation of the vehicle, wherein the reservation is associated with at least a reservation start date, a reservation end date, and an identifier of a mobile terminal used to access the vehicle. - When the number of reservations stored in the local representation of the memory of the vehicle reaches the maximum number of reservations that can be stored simultaneously in the memory of the vehicle, - Selecting a second reservation from the reservations stored in the local representation of the memory of the vehicle such that the start date of the second reservation is later than the start date of the first reservation. - Replacing the second reservation with the first reservation in the local representation of the memory of the vehicle. - At least, - A command to delete the second reservation, and - A command to add the first reservation - Transmitting a memory synchronization command having the above to the vehicle. - Step, - An apparatus configured to execute the above.
6. A data medium including the computer program instructions configured to execute the steps of the method for managing access authentication according to claim 1 or 2 when the computer program instructions are executed by a processor.