Digital key management apparatus, digital key management system, digital key management method, and program
The digital key management device securely manages multiple keys by transmitting and storing distinct identification information, preventing unauthorized rewriting and enhancing security.
Patent Information
- Application Number
- JP2024095137
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-12
- Publication Date
- 2025-12-24
AI Technical Summary
Existing digital key management systems allow only one owner key per vehicle, preventing the registration of an emergency key and allowing external rewriting of digital keys lent to friends' devices.
A digital key management device that transmits and stores multiple identification information and keys, enabling separate control of owner and emergency keys, preventing unauthorized rewriting.
Prevents unauthorized rewriting of non-owner keys, ensuring secure management of digital keys.
Smart Images

Figure 2025186785000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a digital key management device, a digital key management system, a digital key management method, and a program. [Background technology]
[0002] A technology has been developed that uses a device with a digital key installed to unlock and lock vehicle doors, start the engine, and perform other operations (see, for example, Patent Document 1). Digital keys comply with the Car Connectivity Consortium (CCC) standard. To ensure that the device is linked to the vehicle, pairing must be performed in advance between the vehicle and the device.
[0003] With existing technology, only one device can have owner authority for one vehicle and can use the owner key. A device with owner authority can lend its digital key to a third-party device called a friend. The device with owner authority centrally manages the information on the digital keys registered to the vehicle.
[0004] 11 shows how digital key information is managed. Information stored in the respective storage units of the digital key management device 5, device 6, and device 7 is shown.
[0005] The digital key management device 5 is installed in a vehicle and controls the vehicle's door unlocking and locking, engine start, etc., using a digital key. Device 6 and device 7 are, for example, smartphones. Device 6 is a device with owner authority, and device 7 is a friend's device.
[0006] Digital key management device 5 has a storage unit 50. Device 6 has a storage unit 60. Device 7 has a storage unit 70. Each storage unit stores a combination of an ID and a public key that are associated with each other. The ID is identification information unique to the public key. The public key constitutes digital key information.
[0007] The storage unit 50 stores a combination of the ID (ID1) and the public key of device 6 (device A public key) and a combination of the ID (ID2) and the public key of device 7 (device B public key). The storage unit 60 stores a combination of the ID (ID1) and the public key of the digital key management device 5 (digital key management device public key) and a combination of the ID (ID2) and the public key of device 7 (device B public key). The storage unit 70 stores a combination of the ID (ID2) and the public key of the digital key management device 5 (digital key management device public key).
[0008] The public key of device 6 (device A public key) stored in storage unit 50 and the public key of digital key management device 5 (digital key management device public key) stored in storage unit 60 are associated with each other by an ID (ID1). The public key of device 6 (device A public key) is information of the owner key. The public key of device 7 (device B public key) stored in storage unit 50, the public key of device 7 (device B public key) stored in storage unit 60, and the public key of digital key management device 5 (digital key management device public key) stored in storage unit 70 are associated with each other by an ID (ID2). The public key of device 7 (device B public key) is information of a digital key lent to a friend's device. Device 6, which has owner authority, can know that a key has been lent to device 7. [Prior art documents] [Patent documents]
[0009] [Patent Document 1] Japanese Patent Application Laid-Open No. 2008-303630 Summary of the Invention [Problem to be solved by the invention]
[0010] An emergency key is used as a digital key to replace the owner key when the owner key is lost, or as a digital key to replace the owner key in an emergency such as a disaster. Since only one owner key can be registered per vehicle, an emergency key cannot be registered as an owner key. If an emergency key is registered as a digital key lent to a friend's device, it is possible to delete the emergency key by externally rewriting the information on the emergency key registered to the vehicle.
[0011] An object of the present invention is to provide a digital key management device, a digital key management system, a digital key management method, and a program that can prevent information on a digital key that is not an owner key from being rewritten. [Means for solving the problem]
[0012] The present invention is a digital key management device having a transmitting unit that transmits first identification information to a first device and transmits second identification information, which is different from the first identification information, to a second device; a memory unit that stores a first digital key that is an owner key and the first identification information, and also stores a second digital key that is different from the first digital key and the second identification information; a receiving unit that receives the first identification information from the first device after the first identification information is transmitted, and receives the second identification information from the second device after the second identification information is transmitted; and a control unit that, when the first identification information is received, controls a controlled device by using the first digital key associated with the first identification information in the memory unit, and, when the second identification information is received, controls the controlled device by using the second digital key associated with the second identification information in the memory unit.
[0013] The present invention provides a digital key management apparatus having a digital key management device, a first device, and a second device, wherein the digital key management device has a device transmitting unit that transmits first identification information to the first device and transmits second identification information different from the first identification information to the second device, a device storage unit that stores a first digital key that is an owner key and the first identification information, and also stores a second digital key different from the first digital key and the second identification information, a device receiving unit that receives the first identification information from the first device after the first identification information is transmitted, and receives the second identification information from the second device after the second identification information is transmitted, and when the first identification information is received, controls a controlled device by using the first digital key associated with the first identification information in the device storage unit, a control unit that, when the second identification information is received, controls the controlled device by using the second digital key associated with the second identification information in the device memory unit, wherein the first device has a first device receiving unit that receives the first identification information, a first device memory unit that stores the received first identification information, and a first device transmitting unit that transmits the first identification information stored in the first device memory unit to the digital key management device, and the second device has a second device receiving unit that receives the second identification information, a second device memory unit that stores the received second identification information, and a second device transmitting unit that transmits the second identification information stored in the second device memory unit to the digital key management device.
[0014] The present invention includes a first transmitting step in which a transmitting unit transmits first identification information to a first device, a second transmitting step in which the transmitting unit transmits second identification information different from the first identification information to a second device, a first storing step in which a storing unit stores a first digital key which is an owner key in association with the first identification information, a second storing step in which the storing unit stores a second digital key different from the first digital key in association with the second identification information, a first receiving step in which a receiving unit receives the first identification information from the first device after the first identification information is transmitted, and a second receiving step in which the receiving unit receives the second identification information from the second device after the second identification information is transmitted. a first control step in which, when the first identification information is received, a control unit controls a control target device by using the first digital key associated with the first identification information in the storage unit; a second control step in which, when the second identification information is received, the control unit controls the controlled device by using the second digital key associated with the second identification information in the memory unit.
[0015] The present invention includes a first transmission step of transmitting first identification information to a first device, a second transmission step of transmitting second identification information different from the first identification information to a second device, a first storage step of storing a first digital key, which is an owner key, in a storage unit in association with the first identification information, a second storage step of storing a second digital key different from the first digital key in association with the second identification information in the storage unit, a first reception step of receiving the first identification information from the first device after the first identification information has been transmitted, and a second reception step of receiving the second identification information from the first device. This is a program for causing a computer of the controlled device to execute the following steps: a second receiving step of receiving the second identification information from the second device after it has been transmitted; a first control step of controlling the controlled device by using the first digital key associated with the first identification information in the memory unit when the first identification information is received; and a second control step of controlling the controlled device by using the second digital key associated with the second identification information in the memory unit when the second identification information is received. [Effects of the Invention]
[0016] According to the present invention, the digital key management device, digital key management system, digital key management method, and program can prevent information on a digital key that is not an owner key from being rewritten. [Brief explanation of the drawings]
[0017] [Figure 1] 1 is a block diagram illustrating an example of the configuration of a digital key management system according to an embodiment of the present invention. [Figure 2] 1 is a block diagram illustrating an example of the configuration of a digital key management device according to an embodiment of the present invention. [Figure 3] FIG. 1 is a block diagram illustrating an example of a configuration of a smartphone according to an embodiment of the present invention. [Figure 4] 1 is a block diagram showing an example of the configuration of an IC card according to an embodiment of the present invention. [Figure 5] FIG. 3 is a diagram illustrating an example of information stored in a storage unit according to an embodiment of the present invention. [Figure 6] FIG. 3 is a diagram illustrating an example of information stored in a storage unit according to an embodiment of the present invention. [Figure 7] FIG. 10 is a sequence diagram illustrating an example of a process for registering digital key information according to an embodiment of the present invention. [Figure 8] FIG. 10 is a sequence diagram illustrating an example of a process for registering digital key information according to an embodiment of the present invention. [Figure 9] FIG. 4 is a sequence diagram illustrating an example of a process for unlocking a door of a vehicle according to an embodiment of the present invention. [Figure 10] FIG. 4 is a sequence diagram illustrating an example of a process for unlocking a door of a vehicle according to an embodiment of the present invention. [Figure 11] FIG. 1 is a diagram showing how digital key information is managed in the prior art. DETAILED DESCRIPTION OF THE INVENTION
[0018] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. Fig. 1 shows an example of the configuration of a digital key management system 1 according to an embodiment of the present invention. The digital key management system 1 includes a digital key management device 2, a smartphone 3, and an IC card 4.
[0019] The digital key management device 2 is included in a vehicle control device installed in the vehicle. The smartphone 3 and IC card 4 are devices that perform wireless communication with the digital key management device 2. The smartphone 3 has owner authority and holds an owner key. The IC card 4 holds an emergency key. The IC card 4 may be a key fob, etc.
[0020] 2 shows an example of the configuration of the digital key management device 2. The digital key management device 2 includes a communication unit 20, a control unit 21, and a storage unit 22.
[0021] The communication unit 20 has a transmitting unit 200 and a receiving unit 201. The transmitting unit 200 transmits information or data to the smartphone 3 or the IC card 4. The receiving unit 201 receives information or data from the smartphone 3 or the IC card 4.
[0022] The control unit 21 executes processing for managing information stored in the storage unit 22. The control unit 21 also controls unlocking and locking of vehicle doors, starting of the engine, and the like, by using a digital key.
[0023] The control unit 21 may be realized by a processor such as a CPU (Central Processing Unit) executing a program recorded on a computer-readable recording medium. The control unit 21 may be realized by hardware (circuitry) such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array). The control unit 21 may also be realized by a combination of software and hardware.
[0024] The computer-readable recording medium may be a portable medium such as a flexible disk, a magneto-optical disk, a ROM, or a CD-ROM, or a storage unit such as a hard disk built into a computer system. The above-mentioned program may be a differential file (differential program). The function of the control unit 21 may be realized by combining a program already recorded in the computer with the differential program.
[0025] The storage unit 22 is a non-volatile memory such as an EPROM (Erasable Programmable Read-Only Memory), an EEPROM (Electrically Programmable Read-Only Memory), or a flash memory. The storage unit 22 stores a combination of an ID and a public key that are associated with each other. The ID is identification information unique to the public key. The public key constitutes digital key information.
[0026] The storage unit 22 has a first key management area 22a and a second key management area 22b. Information on the owner key and information on the digital key lent to the friend's device is stored in the first key management area 22a. Information on the emergency key is stored in the second key management area 22b.
[0027] 3 shows an example of the configuration of the smartphone 3. The smartphone 3 has a communication unit 30, a control unit 31, and a storage unit 32.
[0028] The communication unit 30 has a transmission unit 300 and a reception unit 301. The transmission unit 300 transmits information or data to the digital key management device 2. The reception unit 301 receives information or data from the digital key management device 2.
[0029] The control unit 31 executes a process for managing information stored in the storage unit 32. The storage unit 32 stores a combination of an ID and a public key that are associated with each other.
[0030] 4 shows an example of the configuration of the IC card 4. The IC card 4 has a communication unit 40, a control unit 41, and a storage unit .
[0031] The communication unit 40 has a transmitting unit 400 and a receiving unit 401. The transmitting unit 400 transmits information or data to the digital key management device 2. The receiving unit 401 receives information or data from the digital key management device 2.
[0032] The control unit 41 executes a process for managing information stored in the storage unit 42. The storage unit 42 stores a combination of an ID and a public key that are associated with each other.
[0033] FIG. 5 shows an example of information stored in the storage unit 22, the storage unit 32, and the storage unit .
[0034] After pairing between the digital key management device 2 and the smartphone 3 is performed, the memory unit 22 stores a combination of the ID (ID1) and the public key of the smartphone 3 (device A public key), and the memory unit 32 stores a combination of the ID (ID1) and the public key of the digital key management device 2 (digital key management device public key). The public key of the smartphone 3 (device A public key) stored in the memory unit 22 and the public key of the digital key management device 2 (digital key management device public key) stored in the memory unit 32 are associated with each other by the ID (ID1). The public key of the smartphone 3 (device A public key) is owner key information.
[0035] After the digital key is lent to the friend's device, the storage unit 22 stores a combination of the ID (ID2, ID3) and the public key of the friend's device (device B public key, device C public key), and the storage unit 32 stores a combination of the ID (ID2, ID3) and the public key of the friend's device (device B public key, device C public key). The public keys of the friend's device stored in the storage unit 22 (device B public key, device C public key) and the public keys of the friend's device stored in the storage unit 32 (device B public key, device C public key) are associated with each other by the ID (ID2, ID3). The public keys of the friend's device (device B public key, device C public key) are information on the digital key lent to the friend's device.
[0036] After pairing between the digital key management device 2 and the IC card 4 is performed, the storage unit 22 stores a combination of the ID (ID4) and the public key (emergency key public key) of the IC card 4, and the storage unit 42 stores a combination of the ID (ID4) and the public key (digital key management device public key) of the digital key management device 2. The public key (emergency key public key) of the IC card 4 stored in the storage unit 22 and the public key (digital key management device public key) of the digital key management device 2 stored in the storage unit 42 are associated with each other by the ID (ID4). The ID (ID4) stored in the storage unit 42 is an ID assigned only to the emergency key and is not assigned to the owner key or a digital key lent to a friend's device. The public key (emergency key public key) of the IC card 4 has the same authority as the owner key.
[0037] 6 shows an example of information stored in memory unit 22, memory unit 32, and memory unit 42 after a digital key is lent to a new friend's device. A combination of an ID (ID5) and the friend's device's public key (device D public key) is added to memory unit 22 and memory unit 32. The ID (ID5) and the friend's device's public key (device D public key) are stored in the first key management area 22a described above. An ID (ID5) different from the ID (ID4) assigned to the emergency key is assigned to the digital key lent to the friend's device.
[0038] 7 shows an example of processing executed by the digital key management device 2 and the smartphone 3 to register digital key information. The processing executed by the digital key management device 2 and the smartphone 3 will be described with reference to FIG. 7. The processing shown in FIG. 7 corresponds to pairing between the digital key management device 2 and the smartphone 3.
[0039] (Step S100) The control unit 21 of the digital key management device 2 outputs a SELECT command to the transmitting unit 200 to select a digital key application. The transmitting unit 200 transmits the SELECT command to the smartphone 3. The receiving unit 301 of the smartphone 3 receives the SELECT command and outputs the SELECT command to the control unit 31. The control unit 31 executes the following processing defined as processing of the digital key application.
[0040] (Step S105) The control unit 31 outputs the response to the transmission unit 300. The transmission unit 300 transmits the response to the digital key management device 2. The reception unit 201 of the digital key management device 2 receives the response and outputs the response to the control unit 21.
[0041] (Step S110) The control unit 21 generates a mutual authentication command including authentication data and outputs the mutual authentication command to the transmission unit 200. The transmission unit 200 transmits the mutual authentication command to the smartphone 3. The reception unit 301 of the smartphone 3 receives the mutual authentication command and outputs the mutual authentication command to the control unit 31.
[0042] (Step S115) The control unit 31 generates a random number and generates a device shared secret by using the generated random number and the authentication data included in the mutual authentication command. The device shared secret is the coordinates of an elliptic curve.
[0043] (Step S120) The control unit 31 generates a response including the device shared secret and outputs the response to the transmission unit 300. The transmission unit 300 transmits the response to the digital key management device 2. The reception unit 201 of the digital key management device 2 receives the response and outputs the response to the control unit 21.
[0044] (Step S125) The control unit 21 generates a mutual authentication command including a vehicle shared secret and internal authentication data, and outputs the mutual authentication command to the transmission unit 200. The vehicle shared secret is the coordinates of an elliptic curve cryptography. The internal authentication data is generated from the vehicle shared secret and the authentication data used in the mutual authentication command. The transmission unit 200 transmits the mutual authentication command to the smartphone 3. The reception unit 301 of the smartphone 3 receives the mutual authentication command and outputs the mutual authentication command to the control unit 31.
[0045] (Step S130) The control unit 31 generates internal authentication data by using the vehicle shared secret included in the mutual authentication command received in step S125 and the authentication data included in the mutual authentication command received in step S110. The control unit 31 verifies the internal authentication data by comparing the generated internal authentication data with the internal authentication data included in the mutual authentication command received in step S125.
[0046] If the two internal authentication data are the same, the authentication of the digital key management device 2 is successful. If the two internal authentication data are different, the authentication of the digital key management device 2 is unsuccessful.
[0047] (Step S135) If authentication of the digital key management device 2 is successful, the control unit 31 generates external authentication data by using the authentication data included in the mutual authentication command received in step S110 and the device shared secret generated in step S115. The control unit 31 generates a response including the external authentication data and outputs the response to the transmission unit 300. The transmission unit 300 transmits the response to the digital key management device 2. The reception unit 201 of the digital key management device 2 receives the response and outputs the response to the control unit 21.
[0048] (Step S140) The control unit 21 generates external authentication data by using the authentication data generated in step S110 and the device shared secret included in the response received in step S120. The control unit 21 verifies the external authentication data by comparing the generated external authentication data with the external authentication data included in the response received in step S135.
[0049] If the two pieces of external authentication data are the same, authentication is successful for the smartphone 3. If the two pieces of external authentication data are different, authentication is unsuccessful for the smartphone 3. In steps S110 to S140, the control unit 21 and the control unit 31 perform mutual authentication.
[0050] (Step S145) If authentication of the smartphone 3 is successful, the control unit 21 generates a command including digital key generation data and outputs the command to the transmission unit 200. The digital key generation data includes a vehicle public key certificate, a certificate of the vehicle OEM (Original Equipment Manufacturer), data for generating a digital key, and an ID assigned to the digital key (owner key) of the smartphone 3. The transmission unit 200 transmits the command to the smartphone 3. The reception unit 301 of the smartphone 3 receives the command and outputs the command to the control unit 31.
[0051] The storage unit 22 pre-stores a fixed value that the IC card 4 uses as a device shared secret and an ID that can be assigned only to the emergency key. If the device shared secret included in the response received in step S120 is different from the fixed value, the control unit 21 generates digital key generation data that includes an ID different from the fixed value.
[0052] (Step S150) The control unit 31 verifies the signature of the vehicle public key certificate by using the public key included in the vehicle OEM's certificate. If the signature verification is successful, the control unit 31 stores the ID and vehicle public key certificate included in the digital key generation data received in step S145 in the memory unit 32. The ID included in the digital key generation data and the public key of the digital key management device 2 included in the vehicle public key certificate are associated with each other. The ID included in the digital key generation data corresponds to the ID (ID1) in Figures 5 and 6. The public key of the digital key management device 2 included in the vehicle public key certificate corresponds to the digital key management device public key in Figures 5 and 6.
[0053] (Step S155) The control unit 31 generates a response including the result of the signature verification and outputs the response to the transmission unit 300. The transmission unit 300 transmits the response to the digital key management device 2. The reception unit 201 of the digital key management device 2 receives the response and outputs the response to the control unit 21.
[0054] (Step S160) The control unit 21 generates a command to instruct the smartphone 3 to generate a digital key, and outputs the command to the transmission unit 200. The transmission unit 200 transmits the command to the smartphone 3. The reception unit 301 of the smartphone 3 receives the command and outputs the command to the control unit 31.
[0055] (Step S165) The control unit 31 generates a digital key certificate by using the data included in the digital key generation data received in step S145.
[0056] (Step S170) The control unit 31 generates a response including the execution result of the process of generating a digital key certificate, and outputs the response to the transmission unit 300. The transmission unit 300 transmits the response to the digital key management device 2. The reception unit 201 of the digital key management device 2 receives the response, and outputs the response to the control unit 21.
[0057] (Step S175) The control unit 21 generates a command to instruct the smartphone 3 to transmit the digital key certificate, and outputs the command to the transmission unit 200. The transmission unit 200 transmits the command to the smartphone 3. The reception unit 301 of the smartphone 3 receives the command and outputs the command to the control unit 31.
[0058] (Step S180) The control unit 31 generates a response including the digital key certificate and an intermediate CA (Certificate Authority) certificate, and outputs the response to the transmission unit 300. The transmission unit 300 transmits the response to the digital key management device 2. The reception unit 201 of the digital key management device 2 receives the response and outputs the response to the control unit 21.
[0059] (Step S185) The control unit 21 verifies the signature of the digital key certificate by using the public key of the intermediate CA included in the intermediate CA certificate. If the signature verification is successful, the control unit 21 stores the ID and digital key certificate included in the digital key generation data transmitted in step S145 in the storage unit 22. The ID included in the digital key generation data and the public key of the smartphone 3 included in the digital key certificate are associated with each other. The ID included in the digital key generation data corresponds to the ID (ID1) in Figures 5 and 6. The public key of the smartphone 3 included in the digital key certificate corresponds to the device A public key in Figures 5 and 6.
[0060] Fig. 8 shows an example of processing executed by the digital key management device 2 and the IC card 4 to register digital key information. The processing executed by the digital key management device 2 and the IC card 4 will be described with reference to Fig. 8. The processing shown in Fig. 8 corresponds to pairing between the digital key management device 2 and the IC card 4.
[0061] (Step S200) The control unit 21 of the digital key management device 2 outputs a SELECT command to the transmitting unit 200 to select a digital key application. The transmitting unit 200 transmits the SELECT command to the smartphone 3. The receiving unit 401 of the IC card 4 receives the SELECT command and outputs the SELECT command to the control unit 41. The control unit 41 executes the following processing defined as processing of the digital key application.
[0062] (Step S205) The control unit 41 outputs the response to the transmission unit 400. The transmission unit 400 transmits the response to the digital key management device 2. The reception unit 201 of the digital key management device 2 receives the response and outputs the response to the control unit 21.
[0063] (Step S210) The control unit 21 generates a mutual authentication command including authentication data, and outputs the mutual authentication command to the transmission unit 200. The transmission unit 200 transmits the mutual authentication command to the IC card 4. The reception unit 401 of the IC card 4 receives the mutual authentication command, and outputs the mutual authentication command to the control unit 41.
[0064] (Step S215) The control unit 41 generates a device shared secret that is a fixed value that is not used as a coordinate of the elliptic curve cryptography. The fixed value may be stored in the storage unit 42 in advance.
[0065] (Step S220) The control unit 41 generates a response including the device shared secret and outputs the response to the transmission unit 400. The transmission unit 400 transmits the response to the digital key management device 2. The reception unit 201 of the digital key management device 2 receives the response and outputs the response to the control unit 21.
[0066] (Step S225) The control unit 21 generates a mutual authentication command including a vehicle shared secret and internal authentication data, and outputs the mutual authentication command to the transmission unit 200. The vehicle shared secret is the coordinates of an elliptic curve cryptography. The internal authentication data is generated from the vehicle shared secret and the authentication data used in the mutual authentication command. The transmission unit 200 transmits the mutual authentication command to the IC card 4. The reception unit 401 of the IC card 4 receives the mutual authentication command and outputs the mutual authentication command to the control unit 41.
[0067] (Step S230) The control unit 41 generates internal authentication data by using the vehicle shared secret included in the mutual authentication command received in step S225 and the authentication data included in the mutual authentication command received in step S210. The control unit 31 verifies the internal authentication data by comparing the generated internal authentication data with the internal authentication data included in the mutual authentication command received in step S225.
[0068] If the two internal authentication data are the same, the authentication of the digital key management device 2 is successful. If the two internal authentication data are different, the authentication of the digital key management device 2 is unsuccessful.
[0069] (Step S235) If authentication of the digital key management device 2 is successful, the control unit 41 generates external authentication data by using the authentication data included in the mutual authentication command received in step S210 and the device shared secret generated in step S215. The control unit 41 generates a response including the external authentication data and outputs the response to the transmission unit 400. The transmission unit 400 transmits the response to the digital key management device 2. The reception unit 201 of the digital key management device 2 receives the response and outputs the response to the control unit 21.
[0070] (Step S240) The control unit 21 generates external authentication data by using the authentication data generated in step S210 and the device shared secret included in the response received in step S220. The control unit 21 verifies the external authentication data by comparing the generated external authentication data with the external authentication data included in the response received in step S235.
[0071] If the two pieces of external authentication data are the same, authentication is successful for the IC card 4. If the two pieces of external authentication data are different, authentication is unsuccessful for the IC card 4. In steps S210 to S240, the control units 21 and 41 perform mutual authentication.
[0072] (Step S245) If authentication of the IC card 4 is successful, the control unit 21 generates a command including digital key generation data and outputs the command to the transmission unit 200. The digital key generation data includes a vehicle public key certificate, a certificate of the vehicle OEM, data for generating a digital key, and an ID assigned to the emergency key. The transmission unit 200 transmits the command to the IC card 4. The reception unit 401 of the IC card 4 receives the command and outputs the command to the control unit 41.
[0073] The storage unit 22 pre-stores a fixed value that the IC card 4 uses as a device shared secret and an ID that can be assigned only to the emergency key. If the device shared secret included in the response received in step S220 is the same as the fixed value, the control unit 21 generates digital key generation data that includes the ID.
[0074] (Step S250) The control unit 41 verifies the signature of the vehicle public key certificate by using the public key included in the vehicle OEM's certificate. If the signature verification is successful, the control unit 41 stores the ID and vehicle public key certificate included in the digital key generation data received in step S245 in the storage unit 42. The ID included in the digital key generation data and the public key of the digital key management device 2 included in the vehicle public key certificate are associated with each other. The ID included in the digital key generation data corresponds to the ID (ID4) in Figures 5 and 6. The public key of the digital key management device 2 included in the vehicle public key certificate corresponds to the digital key management device public key in Figures 5 and 6.
[0075] (Step S255) The control unit 41 generates a response including the result of the signature verification and outputs the response to the transmission unit 400. The transmission unit 400 transmits the response to the digital key management device 2. The reception unit 201 of the digital key management device 2 receives the response and outputs the response to the control unit 21.
[0076] (Step S260) The control unit 21 generates a command for instructing the IC card 4 to generate a digital key, and outputs the command to the transmission unit 200. The transmission unit 200 transmits the command to the IC card 4. The reception unit 401 of the IC card 4 receives the command and outputs the command to the control unit 41.
[0077] (Step S265) The control unit 41 generates a digital key certificate by using the data included in the digital key generation data received in step S245.
[0078] (Step S270) The control unit 41 generates a response including the execution result of the process of generating a digital key certificate, and outputs the response to the transmission unit 400. The transmission unit 400 transmits the response to the digital key management device 2. The reception unit 201 of the digital key management device 2 receives the response, and outputs the response to the control unit 21.
[0079] (Step S275) The control unit 21 generates a command for instructing the IC card 4 to transmit the digital key certificate, and outputs the command to the transmission unit 200. The transmission unit 200 transmits the command to the IC card 4. The reception unit 401 of the IC card 4 receives the command and outputs the command to the control unit 41.
[0080] (Step S280) The control unit 41 generates a response including the digital key certificate and the intermediate CA certificate, and outputs the response to the transmission unit 400. The transmission unit 400 transmits the response to the digital key management device 2. The reception unit 201 of the digital key management device 2 receives the response and outputs the response to the control unit 21.
[0081] (Step S285) The control unit 21 verifies the signature of the digital key certificate by using the public key of the intermediate CA included in the intermediate CA certificate. If the signature verification is successful, the control unit 21 stores the ID and digital key certificate included in the digital key generation data transmitted in step S245 in the storage unit 22. The ID included in the digital key generation data and the public key of the IC card 4 included in the digital key certificate are associated with each other. The ID included in the digital key generation data corresponds to the ID (ID4) in Figures 5 and 6. The public key of the IC card 4 included in the digital key certificate corresponds to the emergency key public key in Figures 5 and 6.
[0082] Fig. 9 shows an example of the process executed by the digital key management device 2 and the smartphone 3 to unlock the vehicle door. The process executed by the digital key management device 2 and the smartphone 3 will be described with reference to Fig. 9. After the process shown in Fig. 7 is executed, the process shown in Fig. 9 is executed.
[0083] (Step S300) The control unit 21 of the digital key management device 2 generates AUTHENTICATE including the vehicle temporary public key and the vehicle ID, and outputs AUTHENTICATE to the transmission unit 200. The transmission unit 200 transmits AUTHENTICATE to the smartphone 3. The reception unit 301 of the smartphone 3 receives AUTHENTICATE and outputs AUTHENTICATE to the control unit 31.
[0084] (Step S305) The control unit 31 generates a response including the device temporary public key of the smartphone 3 and outputs the response to the transmission unit 300. The transmission unit 300 transmits the response to the digital key management device 2. The reception unit 201 of the digital key management device 2 receives the response and outputs the response to the control unit 21.
[0085] (Step S310) The control unit 21 generates signature data by encrypting the vehicle ID with the vehicle temporary private key. The control unit 21 generates AUTHENTICATE including the signature data and outputs AUTHENTICATE to the transmission unit 200. The transmission unit 200 transmits AUTHENTICATE to the smartphone 3. The reception unit 301 of the smartphone 3 receives AUTHENTICATE and outputs AUTHENTICATE to the control unit 31.
[0086] (Step S315) The control unit 31 decrypts the signature data included in the AUTHENTICATE received in step S310 using the vehicle temporary public key included in the AUTHENTICATE received in step S300. The control unit 31 verifies the signature data by comparing the vehicle ID obtained by decrypting the signature data with the vehicle ID included in the AUTHENTICATE received in step S300.
[0087] (Step S320) If the two vehicle IDs are the same, the control unit 31 generates a response including the ID (ID1) stored in the storage unit 32, and outputs the response to the transmission unit 300. The transmission unit 300 transmits the response to the digital key management device 2. The reception unit 201 of the digital key management device 2 receives the response and outputs the response to the control unit 21.
[0088] (Step S325) The control unit 21 identifies the same ID (ID1) included in the response received in step S320 in the storage unit 22. The control unit 21 identifies the public key of the smartphone 3 (device A public key) associated with the identified ID.
[0089] (Step S330) The control unit 21 unlocks the vehicle door by using the public key of the smartphone 3 (device A public key).
[0090] Fig. 10 shows an example of the process executed by the digital key management device 2 and the IC card 4 to unlock the vehicle doors. The process executed by the digital key management device 2 and the IC card 4 will be described with reference to Fig. 10. After the process shown in Fig. 8 is executed, the process shown in Fig. 10 is executed.
[0091] (Step S400) The control unit 21 of the digital key management device 2 generates AUTHENTICATE including the vehicle temporary public key and the vehicle ID, and outputs AUTHENTICATE to the transmitting unit 200. The transmitting unit 200 transmits AUTHENTICATE to the IC card 4. The receiving unit 401 of the IC card 4 receives AUTHENTICATE and outputs AUTHENTICATE to the control unit 41.
[0092] (Step S405) The control unit 41 generates a response including the device temporary public key of the IC card 4, and outputs the response to the transmission unit 400. The transmission unit 400 transmits the response to the digital key management device 2. The reception unit 201 of the digital key management device 2 receives the response, and outputs the response to the control unit 21.
[0093] (Step S410) The control unit 21 generates signature data by encrypting the vehicle ID with the vehicle temporary private key. The control unit 21 generates AUTHENTICATE including the signature data and outputs AUTHENTICATE to the transmission unit 200. The transmission unit 200 transmits AUTHENTICATE to the IC card 4. The reception unit 401 of the IC card 4 receives AUTHENTICATE and outputs AUTHENTICATE to the control unit 41.
[0094] (Step S415) The control unit 41 decrypts the signature data included in the AUTHENTICATE received in step S410 using the vehicle temporary public key included in the AUTHENTICATE received in step S400. The control unit 41 verifies the signature data by comparing the vehicle ID obtained by decrypting the signature data with the vehicle ID included in the AUTHENTICATE received in step S400.
[0095] (Step S420) If the two vehicle IDs are the same, the control unit 41 generates a response including the ID (ID4) stored in the storage unit 42, and outputs the response to the transmission unit 400. The transmission unit 400 transmits the response to the digital key management device 2. The reception unit 201 of the digital key management device 2 receives the response and outputs the response to the control unit 21.
[0096] (Step S425) The control unit 21 identifies the same ID (ID4) included in the response received in step S420 in the storage unit 22. The control unit 21 identifies the public key (emergency key public key) of the IC card 4 associated with the identified ID.
[0097] (Step S430) The control unit 21 unlocks the vehicle doors by using the public key (emergency key public key) of the IC card 4.
[0098] When the vehicle doors are locked or the engine is started, processing similar to that shown in FIG. 9 or FIG. 10 may be executed.
[0099] The ID assigned to the emergency key is not notified to the smartphone 3. Therefore, the smartphone 3 cannot access the emergency key public key stored in the second key management area 22b of the storage unit 22 of the digital key management device 2, and cannot rewrite the information stored in the second key management area 22b.
[0100] In the digital key management system 1 shown in Figure 1, a digital key management device 2 is included in a vehicle control device. The embodiment of the present invention may be applied to a control system that locks or unlocks coin lockers or doors of buildings (such as offices or homes).
[0101] As described above, the transmitter 200 (device transmitter) of the digital key management device 2 transmits ID1 (first identification information) to the smartphone 3 (first device) and transmits ID4 (second identification information), which is different from ID1, to the IC card 4 (second device). The memory 22 (device memory) of the digital key management device 2 stores the device A public key (first digital key), which is an owner key, and ID1, and also stores the emergency key public key (second digital key), which is different from the device A public key, and ID4. After ID1 is transmitted, the receiver 201 (device receiver) of the digital key management device 2 receives ID1 from the smartphone 3, and after ID4 is transmitted, receives ID4 from the IC card 4. When ID1 is received, the controller 21 (device controller) of the digital key management device 2 controls the vehicle (controlled device) by using the device A public key associated with ID1 in the memory 22. When ID4 is received, the control unit 21 controls the vehicle by using the emergency public key associated with ID4 in the storage unit 22.
[0102] The receiving unit 301 (first device receiving unit) of the smartphone 3 receives ID1. The memory unit 32 (first device memory unit) of the smartphone 3 stores the received ID1. The transmitting unit 300 (first device transmitting unit) of the smartphone 3 transmits ID1 stored in the memory unit 32 to the digital key management device 2. The receiving unit 401 (second device receiving unit) of the IC card 4 receives ID4. The memory unit 42 (second device memory unit) of the IC card 4 stores the received ID4. The transmitting unit 400 (second device transmitting unit) of the IC card 4 transmits ID4 stored in the memory unit 42 to the digital key management device 2.
[0103] The digital key management device 2 can prevent the information of the emergency key, which is not the owner key, from being rewritten.
[0104] The memory unit 22 of the digital key management device 2 stores a fixed value. The receiver 201 of the digital key management device 2 receives, from the smartphone 3 or the IC card 4, a device shared secret (authentication information) used for mutual authentication performed by the smartphone 3 or the IC card 4 and the digital key management device 2. If a device shared secret different from the fixed value is received from the smartphone 3, the transmitter 200 of the digital key management device 2 transmits ID1 to the smartphone 3. If a device shared secret identical to the fixed value is received from the IC card 4, the transmitter 200 transmits ID4 to the IC card 4.
[0105] The digital key management device 2 can determine whether the digital key of a device is an emergency key by checking whether the device shared secret received from the device is a fixed value. If a device shared secret that is the same as the fixed value is received, the digital key management device 2 can register the digital key of the device that sent the device shared secret in the storage unit 22 as an emergency key.
[0106] The transmission unit 200 of the digital key management device 2 transmits ID1 to the smartphone 3 when pairing between the smartphone 3 and the digital key management device 2 is performed, and transmits ID4 to the IC card 4 when pairing between the IC card 4 and the digital key management device 2 is performed. The smartphone 3 and the IC card 4 can obtain the ID from the digital key management device 2 when pairing with the digital key management device 2 is performed.
[0107] The above has described in detail an embodiment of the present invention with reference to the drawings, but the specific configuration is not limited to the above embodiment, and design changes and the like are also included within the scope that does not deviate from the gist of the present invention. [Explanation of symbols]
[0108] 1 Digital key management system, 2 Digital key management device, 3 Smartphone, 4 IC card, 20, 30, 40 Communication unit, 21, 31, 41 Control unit, 22, 32, 42 Memory unit, 200, 300, 400 Transmission unit, 201, 301, 401 Reception unit
Claims
1. a transmitter that transmits first identification information to a first device and transmits second identification information different from the first identification information to a second device; a storage unit that stores a first digital key that is an owner key and the first identification information, and also stores a second digital key different from the first digital key and the second identification information; a receiving unit that receives the first identification information from the first device after the first identification information is transmitted, and receives the second identification information from the second device after the second identification information is transmitted; a control unit that, when the first identification information is received, controls the controlled device by using the first digital key associated with the first identification information in the storage unit, and, when the second identification information is received, controls the controlled device by using the second digital key associated with the second identification information in the storage unit; A digital key management device having:
2. the storage unit stores a fixed value; the receiving unit receives, from the first device or the second device, authentication information used for mutual authentication performed between the first device or the second device and the digital key management device; When the authentication information different from the fixed value is received from the first device, the transmitter transmits the first identification information to the first device; When the authentication information identical to the fixed value is received from the second device, the transmitter transmits the second identification information to the second device. The digital key management device according to claim 1 .
3. The transmission unit transmits the first identification information to the first device when pairing between the first device and the digital key management device is performed, and transmits the second identification information to the second device when pairing between the second device and the digital key management device is performed.
3. The digital key management device according to claim 1.
4. A digital key management system includes a first device and a second device, The digital key management device a device transmitter that transmits first identification information to the first device and transmits second identification information different from the first identification information to the second device; a device storage unit that stores a first digital key that is an owner key and the first identification information, and also stores a second digital key different from the first digital key and the second identification information; a device receiving unit that receives the first identification information from the first device after the first identification information is transmitted, and receives the second identification information from the second device after the second identification information is transmitted; a control unit that, when the first identification information is received, controls the controlled device by using the first digital key associated with the first identification information in the device storage unit, and, when the second identification information is received, controls the controlled device by using the second digital key associated with the second identification information in the device storage unit; and The first device a first device receiving unit that receives the first identification information; a first device storage unit that stores the received first identification information; a first device transmitting unit that transmits the first identification information stored in the first device storage unit to the digital key management device; and The second device a second device receiving unit that receives the second identification information; a second device storage unit that stores the received second identification information; a second device transmitting unit that transmits the second identification information stored in the second device storage unit to the digital key management device; have Digital key management system.
5. a first transmitting step in which a transmitting unit transmits first identification information to a first device; a second transmission step in which the transmission unit transmits second identification information different from the first identification information to a second device; a first storage step in which a storage unit stores a first digital key, which is an owner key, in association with the first identification information; a second storage step in which the storage unit stores a second digital key different from the first digital key in association with the second identification information; a first receiving step in which a receiving unit receives the first identification information from the first device after the first identification information is transmitted; a second receiving step in which the receiving unit receives the second identification information from the second device after the second identification information is transmitted; a first control step in which, when the first identification information is received, a control unit controls a controlled device by using the first digital key associated with the first identification information in the storage unit; a second control step in which, when the second identification information is received, the control unit controls the controlled device by using the second digital key associated with the second identification information in the storage unit; A digital key management method comprising:
6. a first transmitting step of transmitting first identification information to a first device; a second transmitting step of transmitting second identification information different from the first identification information to a second device; a first storage step of storing a first digital key, which is an owner key, in a storage unit in association with the first identification information; a second storing step of storing a second digital key different from the first digital key in the storage unit in association with the second identification information; a first receiving step of receiving the first identification information from the first device after the first identification information is transmitted; a second receiving step of receiving the second identification information from the second device after the second identification information is transmitted; a first control step of controlling a controlled device by using the first digital key associated with the first identification information in the storage unit when the first identification information is received; a second control step of controlling the controlled device by using the second digital key associated with the second identification information in the storage unit when the second identification information is received; A program for causing a computer of the device to be controlled to execute the above.
Citation Information
Patent Citations
Smart entry system for vehicle
JP2008303630A