Component control method for a device and related apparatus
By authenticating controllers instead of individual components, the method reduces costs and improves security by ensuring only authenticated and reliable controllers can operate components, effectively preventing theft.
Patent Information
- Application Number
- JP2024573864
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-06-17
- Filing Date
- 2023-06-16
- Publication Date
- 2025-07-30
- Estimated Expiration
- 2043-06-16
AI Technical Summary
Existing anti-theft solutions for devices require pre-setting keys and algorithms in all components, leading to high development and maintenance costs and inadequate security due to diverse security protection requirements across different components.
A method where authentication is performed on controllers rather than individual components, allowing only two or three controllers to be pre-set with keys and algorithms, ensuring components respond only when authentication with the controller is successful and reliable, thereby controlling multiple components securely.
Reduces development and maintenance costs while enhancing security by ensuring unauthorized operations are prevented, thus effectively preventing theft of devices.
Smart Images

Figure 2025524416000001_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of security, and more specifically, to a method for controlling components for a device and related apparatuses.
Background Art
[0002] With the development of life, more devices such as automobiles, motorcycles, or other smart devices are being used in life. To enhance security and avoid problems such as theft of devices, more anti-theft solutions are being provided for devices.
[0003] Currently, a common anti-theft solution is a point-to-point authentication solution. An automobile is used as an example. A controlled automobile component can send an authentication request to a controller, and the controller can authenticate the automobile component based on a key pre-negotiated by both parties. If the authentication is successful, the automobile component can execute the corresponding function in response to a control operation. However, different devices include various components with different functions, and the requirements for device security protection are diverse.
Summary of the Invention
[0004] This application provides a method for controlling components for a device and related apparatuses to meet more security protection requirements.
[0005] According to a first aspect, this application provides a method for controlling components for a device. The method may be executed by a component, or may be implemented by a chip or chip system configured in the component, or by another functional module or software configured to implement some or all of the functions of the component. This is not limited in this application.
[0006] For example, the method is to obtain a control instruction from a first controller, where the control instruction is an instruction sent by the first controller when the authentication performed by a second controller on the first controller is successful and the authentication result is reliable, and to obtain the result of the authentication performed by the second controller on the first controller, where the authentication result includes authentication success or authentication failure, and to respond to the control instruction when the authentication result is authentication success.
[0007] In a device, different components may be used to implement different functions. In the present application, a component may be controlled by a first controller and respond after receiving a control instruction of the first controller. In other words, the first controller may control one or more components to perform corresponding operations by using the control instruction. The components that may be controlled by the first controller may be pre-defined by the device manufacturer before delivery, or the components that may be controlled by the first controller may be adjusted according to requirements during subsequent use processes. This is not limited in the present application.
[0008] Since the first controller can control one or more components, the second controller does not authenticate the components, but authenticates the first controller, so that the second controller does not authenticate all the components. In this way, it is not necessary to pre-set keys and embed algorithms in all components with authentication requirements. It is only necessary to pre-set keys and embed algorithms in only two or three controllers, so that more components can be controlled and the anti-theft effect can be achieved. Therefore, security protection can be provided for more components, more requirements can be satisfied, and the development and maintenance costs can be reduced.
[0009] In addition, in order to send a control command to a component, two conditions, namely, successful authentication and a reliable authentication result, need to be satisfied simultaneously. In other words, since the conditions for restricting the transmission of a control command by the first controller are strict, unauthorized operations of the device can be further avoided, and theft of the device can be prevented. Therefore, the security is improved.
[0010] Referring to the first aspect, in some possible implementations of the first aspect, when the authentication result is a successful authentication, obtaining the result of the authentication performed by the second controller for the first controller includes receiving a successful authentication notification from the second controller, and the successful authentication notification is used to notify the first controller that the authentication performed by the second controller has been successful.
[0011] When the authentication of the second controller for the first controller is successful, the second controller may send a successful authentication notification to notify the component of the authentication result that the authentication of the second controller for the first controller is successful.
[0012] Optionally, the successful authentication notification is sent by broadcast.
[0013] Since the successful authentication notification is sent by broadcast, all components within the device can receive the successful authentication notification, and complete coverage is implemented. The solution of sending the successful authentication notification by broadcast is particularly applicable to the offline diagnosis phase before the device is incorporated.
[0014] Optionally, the successful authentication notification is sent to one or more predefined components.
[0015] Since the successful authentication result is sent to one or more predefined components, one or more components can receive the notification without causing unnecessary influence on other components.
[0016] The manner of sending the successful authentication notification is not limited in this application.
[0017] When the second controller cannot authenticate the first controller, the second controller may send an authentication failure notification to notify that the authentication of the first controller has failed, or may not send any notification. This is not limited in the present application.
[0018] Both the authentication success notification and the authentication failure notification indicate the authentication result and can be regarded as specific examples of indicating the authentication result.
[0019] Referring to the first aspect, in some possible implementations of the first aspect, the method further includes sending a response message to the second controller, and the response message indicates that the reception of the authentication success notification has been successful.
[0020] The component feeds back the response message to the second controller, whereby the second controller can determine whether the component is normal and further determine whether the authentication result is reliable. For example, if the component has been replaced, the second controller may not receive the response message. In this case, even if the authentication of the first controller is successful, the component may have problems, so the component may still not be able to execute operations. Therefore, the second controller can set that the authentication result is not reliable so that the first controller does not send control commands, the component does not respond, and the anti-theft effect is achieved.
[0021] According to a second aspect, the present application provides a component control method for a device. The method may be executed by a first controller, or may be implemented by a chip or chip system configured in the first controller, or by another functional module or software configured to implement some or all functions of the first controller. This is not limited in the present application.
[0022] The first controller on the second side may correspond to controller #2 in subsequent embodiments.
[0023] For example, the method may include obtaining, by the first controller, the result of authentication performed by the second controller, where the result of authentication includes authentication success or authentication failure, and sending a control instruction to a component controlled by the first controller to trigger the controller to respond when the result of authentication is authentication success and the result of authentication is reliable.
[0024] In a device, different components may be used to implement different functions. In the present application, a component may be controlled by the first controller and respond after receiving a control instruction from the first controller. In other words, the first controller may control one or more components to perform corresponding operations by using control instructions. The components that may be controlled by the first controller may be pre-defined by the device manufacturer before incorporation, or the components that may be controlled by the first controller may be adjusted according to requirements during subsequent use processes. This is not limited in the present application.
[0025] Since the first controller can control one or more components, the second controller does not authenticate the components but authenticates the first controller, so that the second controller does not authenticate all components. In this way, it is not necessary to pre-set keys and embed algorithms in all components with authentication requirements. It is only necessary to pre-set keys and embed algorithms in only two or three controllers, so that more components can be controlled and the anti-theft effect can be achieved. Therefore, more components can be provided with security protection, more requirements can be satisfied, and the development and maintenance costs can be reduced.
[0026] In addition, in order to send a control command to a component, the first controller must simultaneously meet two conditions, namely, successful authentication and a reliable authentication result. In other words, since the conditions for restricting the transmission of control commands by the first controller are strict, unauthorized operations of the device can be further avoided, and theft of the device can be prevented. Therefore, the security is improved.
[0027] Referring to a second aspect, in some possible implementations of the second aspect, the method further includes receiving an authentication reliability notification from a second controller, and the authentication reliability notification indicates that the result of the authentication is reliable.
[0028] That is, based on the notification from the second controller, the first controller can determine whether the authentication result is reliable, and further can determine whether a control command can be sent to the component.
[0029] Referring to the first aspect or the second aspect, in some possible implementations, if the key used to unlock the device is not within a pre-set range, the authentication result is an authentication failure.
[0030] Here, the pre-set range may be the sensing range of the device, that is, the maximum range within which the mobile device can detect the key.
[0031] If the key is not within the pre-set range, the device may have been illegally activated by a third party. In this case, in order to prevent the third party from illegally activating the device, prevent theft of the device, and have high security, the authentication result can be set to an authentication failure.
[0032] The key being used to unlock the device may include being used to unlock a door or window, apply a high voltage, start the device, etc. This is not limited in this application.
[0033] Referring to the first side or the second side, in some possible implementations, if a predefined abnormal situation is detected, the authentication result is authentication failure.
[0034] Here, the abnormal situation may be a predefined event regarded as unauthorized entry into the device and unauthorized startup of the device, and may include, for example, but not limited to, window breakage, door breakage, and picking behavior.
[0035] If an abnormal situation is detected, the device may have been invaded or unauthorizedly started. In this case, in order to prevent a third party from unauthorizedly starting the device, prevent theft of the device, and have high security, the authentication result may be set to authentication failure.
[0036] According to a third aspect, the present application provides a component control method for a device. The method may be executed by a first controller, or may be implemented by a chip or a chip system configured in a second controller, or other functional modules or software configured to implement some or all functions of the second controller. This is not limited in the present application.
[0037] The second controller in the third aspect may correspond to the controller #1 in subsequent embodiments.
[0038] For example, the method includes, when the authentication for the first controller is successful, sending an authentication success notification, where the authentication success notification is used to indicate that the authentication for the first controller is successful, and when a response message is received, sending an authentication reliability notification to the first controller, where the response message is from a component controlled by the first controller, the response message indicates that the reception of the authentication success notification is successful, and the authentication reliability notification indicates that the authentication success notification is reliable.
[0039] In a device, different components may be used to implement different functions. In the present application, a component may be controlled by a first controller and respond after receiving a control instruction from the first controller. In other words, the first controller may control one or more components to perform corresponding operations by using control instructions. The components that can be controlled by the first controller may be pre-defined by the device manufacturer before incorporation, or the components that can be controlled by the first controller may be adjusted according to requirements during subsequent usage processes. This is not limited in the present application.
[0040] Since the first controller can control one or more components, the second controller authenticates the first controller rather than the components, so that the second controller does not authenticate all components. Therefore, it is not necessary to pre-set keys and embed algorithms in all components with authentication requirements. It is only necessary to pre-set keys and embed algorithms in only two or three controllers, so that more components can be controlled and the anti-theft effect can be achieved. Therefore, security protection can be provided for more components, more requirements can be satisfied, and the development and maintenance costs can be reduced.
[0041] In addition, since the second controller sends an authentication success notification, the component can obtain the authentication result. Also, since the second controller sends an authentication reliability notification to the first controller based on the response message fed back by the component, the first controller sends a control instruction after determining that the authentication result is reliable. The parties cooperate with each other to satisfy the conditions for sending a control instruction by the first controller, and then satisfy the conditions for a response to the control instruction by the component. Therefore, unauthorized operations of the device can be more avoided, theft of the device can be prevented, and the security is improved.
[0042] Optionally, the authentication success notification is sent via broadcast.
[0043] Since the authentication success notification is sent via broadcast, all components within the device can receive the authentication success notification, and full coverage is implemented. The solution of sending the authentication success notification via broadcast is particularly applicable to the offline diagnosis phase before the device is incorporated.
[0044] Optionally, the authentication success notification is sent to one or more predefined components.
[0045] Since the authentication success result is sent to one or more predefined components, one or more components can receive the notification without causing unnecessary impact on other components.
[0046] The method of sending the authentication success notification is not limited in this application.
[0047] If the second controller cannot authenticate the first controller, the second controller may send an authentication failure notification to notify that the authentication of the first controller has failed, or may not send any notification. This is not limited in this application.
[0048] Both the authentication success notification and the authentication failure notification indicate the authentication result and can be regarded as specific examples of indicating the authentication result.
[0049] Referring to a third aspect, in some possible implementations of the third aspect, the method further includes receiving a response message from a component.
[0050] The component feeds back a response message to the second controller, whereby the second controller can determine whether the component is normal and furthermore can determine whether the authentication result is reliable. For example, if the component has been replaced, the second controller may not receive the response message. In this case, even if the authentication for the first controller is successful, the component may have problems and thus may still not be able to execute operations. Therefore, the second controller may set the authentication result as untrustworthy so that the first controller does not send a control command, the component does not respond, and the anti-theft effect is achieved.
[0051] Referring to the above aspects, in some possible implementations, the device is a vehicle.
[0052] In a possible design, the first controller includes a vehicle domain controller (VDC) and / or a vehicle control unit (VCU), the second controller includes at least one of the following: a vehicle integrated unit (VIU), a wireless communication control module (e.g., a Bluetooth electronic control unit (ECU)), and a BCM, and the component includes a motor and / or a battery management system (BMS).
[0053] In another possible design, the first controller includes a wireless communication control module, the second controller includes a VIU and / or a BCM, and the component includes a door controller and / or a window controller.
[0054] In yet another possible design, the first controller includes a remote communication module, the second controller includes a VIU or a BCM, and the component includes one or more of the following: a motor, a BMS, a door controller, and a window controller.
[0055] The multiple designs described above may be used separately or in combination without conflict. For example, the first controller is a VIU, the second controller includes a VDC or a wireless communication control module, and the component includes at least one of a motor and a BMS and a door controller. The motor and the BMS may be controlled by the VDC, and the door controller may be controlled by the wireless communication control module.
[0056] The above several designs of the first controller, the second controller, and the component are merely examples and should not constitute any limitation to the present application.
[0057] For ease of understanding, the following provides several specific examples.
[0058] In one example, the component includes a motor, the control command instructs the motor to perform a power output operation, and responding to the control command includes performing a power output operation in response to the control command.
[0059] In a possible implementation, the control command carries a torque request, and responding to the control command includes performing a torque response and a power output in response to the torque request in the control command. The motor can be used to convert electrical energy into mechanical energy to supply power to a device (e.g., a vehicle) and drive the device to move. When receiving the torque request, the motor can perform a torque response and a power output including but not limited to driving wheel rotation and rotational speed response. The above operations performed by the motor in response to the control command are merely examples, and the operations performed by the motor in response to the control command are not limited in the present application.
[0060] The motor is controlled so that power output operations are not performed when the device (e.g., a vehicle) is started up illegally. In this way, the device cannot be driven to move, and theft of the device is prevented.
[0061] In another example, the component includes a BMS, and the control instruction instructs the BMS to output power. Responding to the control instruction includes outputting power in response to the control instruction.
[0062] Here, outputting power includes, but is not limited to, powering on, supplying power, etc. When power is output, thereby, the motor can obtain electrical energy to drive the vehicle to move.
[0063] Based on the above solution, the BMS can be controlled so that power is not output when the device (e.g., a vehicle) is started up illegally. Accordingly, the device cannot be started up, and theft of the device is prevented.
[0064] In yet another example, the component includes a door controller, and the control instruction instructs the door controller to unlock the door. Responding to the control instruction includes unlocking the door in response to the control instruction.
[0065] In yet another example, the component includes a window controller, and the control instruction instructs the window controller to unlock the window. Responding to the control instruction includes unlocking the window in response to the control instruction.
[0066] The door controller and the window controller may be controlled simultaneously or separately. This is not limited in this application.
[0067] Based on the above solution, the door controller can be controlled so that the device (e.g., a vehicle) does not unlock the door or window when the door or window is illegally opened. Therefore, it is possible to prevent the device's door or window from being opened and prevent the loss of items inside the device.
[0068] According to a fourth aspect, the present application provides a component control device for a device, including a module or unit configured to implement a method according to any one of the first aspect and possible implementations of the first aspect. Each module or unit can implement the corresponding function by executing a computer program.
[0069] For example, the device includes a transceiver unit and a processing unit. The transceiver unit is configured to obtain a control command from a first controller, and the control command is a command sent by the first controller when the authentication performed by the second controller on the first controller is successful and the authentication result is reliable. The processing unit is configured to obtain the authentication result, and the authentication result indicates whether the authentication performed by the second controller on the first controller is successful. Further, when the authentication result is a successful authentication, the processing unit is further configured to respond to the control command.
[0070] Referring to the fourth aspect, in some possible implementations of the fourth aspect, the authentication result is a successful authentication, and the transceiver unit is particularly configured to receive a successful authentication notification from the second controller. The successful authentication notification is used to notify that the authentication performed by the second controller on the first controller is successful.
[0071] Referring to the fourth aspect, in some possible implementations of the fourth aspect, the successful authentication notification is sent by broadcast, or the successful authentication notification is sent to one or more pre-defined components.
[0072] Referring to the fourth aspect, in some possible implementations of the fourth aspect, the transceiver unit is further configured to send a response message to the second controller, where the response message indicates that the reception of the authentication success notification has been successful.
[0073] Referring to the fourth aspect, in some possible implementations of the fourth aspect, the device is a vehicle.
[0074] In a possible design, the first controller includes a VDC and / or a VCU, the second controller includes at least one of the following: a VIU, a wireless communication control unit, or a BCM, and the device includes a motor and / or a BMS.
[0075] In another possible design, the first controller includes a wireless communication control unit, the second controller includes a VIU and / or a BCM, and the device includes a door controller and / or a window controller.
[0076] In yet another possible design, the first controller includes a remote communication unit, the second controller includes a VIU and / or a BCM, and the device includes one or more of the following: a motor, a BMS, a door controller, and a window controller.
[0077] For example, the device includes a motor, and the control command carries a torque request. The processing unit is specifically configured to execute a torque response and power output in response to the torque request in the control command.
[0078] In another example, the device includes a BMS, and the control command instructs the BMS to output power. The processing unit is specifically configured to output power in response to the control command.
[0079] In yet another example, the device includes a door controller, and the control command instructs the door controller to unlock the door. The processing unit is specifically configured to unlock the door in response to the control command.
[0080] In yet another example, the device includes a window controller, and the control instruction instructs the window controller to unlock the window. Responding to the control instruction includes unlocking the window in response to the control instruction.
[0081] According to a fifth aspect, the present application provides a component control device for a device, including a module or unit configured to implement a method according to any one of the second aspect and possible implementations of the second aspect. Each module or unit may implement corresponding functions by executing a computer program.
[0082] For example, the device includes a transceiver unit and a processing unit. The processing unit is configured to obtain the result of authentication performed by a second controller for the device, and the result of authentication includes authentication success or authentication failure. The transceiver unit is configured to send a control instruction to a component controlled by the device and trigger the component to respond when the result of authentication is authentication success and the result of authentication is reliable.
[0083] Referring to the fifth aspect, in some possible implementations of the fifth aspect, the transceiver unit is further configured to receive an authentication reliability notification from the second controller, and the authentication reliability notification indicates that the authentication result is reliable.
[0084] Referring to the fifth aspect, in some possible implementations of the fifth aspect, the device is a vehicle.
[0085] In a possible design, the device includes a VDC and / or a VCU, the second controller includes at least one of the following: a VIU, a wireless communication control unit, and a BCM, and the component includes a motor and / or a BMS.
[0086] In another possible design, the device includes a wireless communication control unit, the second controller includes a VIU and / or a BCM, and the component includes a door controller and / or a window controller.
[0087] In yet another possible design, the device includes a remote communication unit, the second controller includes a VIU and / or a BCM, and the component includes one or more of the following: a motor, a BMS, a door controller, and a window controller.
[0088] Referring to the fourth or fifth aspect, in some possible implementations, if the key used to activate the device is not within a pre-set range or a predefined abnormal situation is detected, the authentication result is an authentication failure.
[0089] According to the sixth aspect, the present application provides a component control device for a device, including a module or unit configured to implement a method according to any one of the third aspect and possible implementations of the third aspect. Each module or unit may implement corresponding functions by executing a computer program.
[0090] For example, the device includes a transceiver unit. The transceiver unit is configured to send an authentication success notification when the authentication for the first controller is successful, and the authentication success notification is used to notify that the authentication for the first controller is successful. Also, when a response message is received, it is further configured to send an authentication reliability notification to the first controller. The response message is issued by a component controlled by the first controller, the response message indicates that the reception of the authentication success notification was successful, and the authentication reliability notification indicates that the authentication success notification is reliable.
[0091] Referring to the sixth aspect, in some possible implementations of the sixth aspect, the authentication success notification is sent by broadcast or the authentication success notification is sent to one or more predefined components.
[0092] Referring to the sixth aspect, in some possible implementations of the sixth face, the transceiver unit is further configured to receive a response message from the component, and the response message indicates that the reception of the authentication success notification has been successful.
[0093] Referring to the sixth aspect, in some possible implementations of the sixth aspect, the device is a vehicle.
[0094] In a possible design, the device includes at least one of the following: VIU, wireless communication control unit, and BCM. The first controller includes VDC and / or VCU, and the component includes a motor and / or BMS.
[0095] In another possible design, the device includes VIU and / or BCM. The first controller includes a wireless communication control unit, and the component includes a door controller and / or a window controller.
[0096] In yet another possible design, the device includes VIU and / or BCM. The first controller includes a remote communication unit, and the component includes one or more of the following: motor, BMS, door controller, and window controller.
[0097] Referring to the sixth aspect, in some possible implementations of the sixth aspect, the transceiver unit is further configured to receive an authentication request from the first controller. The authentication request is used to request the first controller to perform authentication. The device further includes a processing unit configured to perform authentication on the first controller in response to the authentication request and obtain an authentication result.
[0098] Optionally, the processing unit is further configured to determine that the authentication result is an authentication failure if the key is not detected within a pre-set range. The key is the key used to start the device.
[0099] Optionally, the processing unit is further configured to determine that the authentication result is an authentication failure if a predefined abnormal situation is detected.
[0100] According to a seventh aspect, the present application provides a component control device for a device including a processor, and the processor is configured to execute a component control method for the device according to any one of the first aspect or possible implementations of the first aspect.
[0101] According to an eighth aspect, the present application provides a component control device for a device including a processor, and the processor is configured to execute a component control method for the device according to any one of the second aspect or possible implementations of the second aspect.
[0102] According to a ninth aspect, the present application provides a component control device for a device including a processor, and the processor is configured to execute a component control method for the device according to any one of the third aspect or possible implementations of the third aspect.
[0103] Optionally, the device according to the seventh aspect to the ninth aspect may further include a memory configured to store instructions and data. The memory is coupled to the processor, and when the instructions stored in the memory are executed, the processor can implement the methods described in the above aspects. The device may further include a communication interface. The communication interface is used by the device to communicate with other devices. For example, the communication interface may be a transceiver, a circuit, a bus, a module, or another type of communication interface.
[0104] According to a tenth aspect, the present application provides a chip system. The chip system includes at least one processor configured to implement a function in any one of possible implementations from a first aspect to a third aspect and from the first aspect to the third aspect, for example, to support reception or processing of data and / or information included in the above information.
[0105] In a possible design, the chip system further includes a memory configured to store program instructions and data, and the memory is located inside or outside the processor.
[0106] The chip system may include a chip, or may include a chip and other discrete components.
[0107] According to an eleventh aspect, the present application provides a vehicle. The vehicle includes a first controller, a second controller, and a vehicle. The first controller is configured to send a control instruction to a component when the authentication performed by the second controller on the first controller is successful and the authentication result is reliable. Whether the authentication result is reliable is determined based on a notification from the first controller. The component is configured to obtain the result of the authentication performed by the second controller on the first controller. The authentication result includes authentication success or authentication failure. The component is further configured to respond to the control instruction when the authentication result is authentication success.
[0108] For example, the above component may be configured to execute a method according to a first aspect or any one of possible implementations of the first aspect, and the component may correspond to a device according to a fourth aspect or a seventh aspect. The first controller may be configured to execute a method according to a second aspect or any one of possible modes of the second aspect, and the first controller may correspond to a device according to a fifth aspect or an eighth aspect. The second controller may be configured to execute a method according to a third aspect or any one of possible implementations of the third aspect, and the second controller may correspond to a device according to a sixth aspect or a ninth aspect.
[0109] According to a twelfth aspect, the present application provides a computer-operated storage medium including a computer program. When the computer program is executed by a computer, the computer can implement a method according to any one of the possible implementations from the first aspect to the third aspect and from the first aspect to the third aspect.
[0110] According to a thirteenth aspect, the present application provides a computer program product, the computer program product includes a computer program (which may also be referred to as code or instructions), and when the computer program is executed, the computer can execute a method according to any one of the possible implementations from the first aspect to the third aspect and from the first aspect to the third aspect.
[0111] It should be understood that the technical solutions in the fourth aspect to the thirteenth aspect of the present application correspond to the technical solutions in the first aspect to the third aspect of the present application, and the advantageous effects achieved by these aspects and corresponding feasible implementations are similar. Details are not described here.
Brief Description of the Drawings
[0112]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Modes for Carrying Out the Invention
[0113] The following describes the technical solution of the present application with reference to the accompanying drawings.
[0114] To facilitate the understanding of the embodiments of the present application, the following description is first provided.
[0115] First, in this embodiment of the present application, prefixes such as "first" and "second" are used only to distinguish different described objects, and do not limit the position, order, priority, quantity, or content of the described objects. For example, if the described object is a "controller", the ordinal numbers in front of "controller" in "the first controller" and "the second controller" do not limit the priority between the "controllers". As another example, the quantity of the described objects is not limited by the prefix, and there may be one or more objects. "The first controller" is used as an example, and at this time, there may be one or more controllers. In short, the use of the prefix used to distinguish the described objects in this embodiment of the present application does not constitute a limitation on the described objects. Regarding the description of the described objects, reference should be made to the context description in the claims or embodiments, and the use of such prefixes should not constitute redundant limitations.
[0116] Second, in the embodiments of the present application, "at least one" means one or more, and "a plurality of" means two or more. "And / or" indicates the association relationship between related objects and represents that there may be three relationships. For example, A and / or B can represent the following cases: only A exists, both A and B exist, and only B exists, where A and BCM can be singular or plural. The character " / " generally indicates an "or" relationship between related objects. At least one of the following items (pieces) or similar expressions indicates any combination of these items, including any combination of a single item (piece) or a plurality of items (pieces). For example, at least one of a, b, or c can represent a, b, c, a and b, a and c, b and c, or a and b and c. Here, a, b, and c can be singular or plural.
[0117] Third, in the embodiments of the present application, both "when" and "case" mean that the device executes the corresponding process in an objective situation, without the intention of limiting time, and does not necessarily require the device to perform a decisive operation during implementation, nor does it mean other limitations.
[0118] Fourth, "simultaneously" in the embodiments of the present application may be understood as "at the same time point", "during a certain period", or "during the same period", and specifically can be understood by referring to the context.
[0119] The devices in the embodiments of the present application may include devices that use electrical energy as a power source, for example, including, but not limited to, automobiles, motorcycles, ships, airplanes, helicopters, flying cars, lawn mowers, construction machinery, trams, golf carts, or trains. The embodiments of the present application include this but are not limited to this.
[0120] To facilitate the understanding of the embodiments of the present application, first, a communication system applicable to the method provided in the embodiments of the present application will be described with reference to FIG. 1. As an example, the communication system 100 shown in FIG. 1 is an in-vehicle communication system arranged in an automobile. As shown in FIG. 1, the system 100 includes a plurality of modules including, but not limited to, for example, VIU, VDC, motor, telecommunication module, BMS, BCM, wireless communication control module, door controller (or door switch), and VCU.
[0121] The wireless communication control module may be configured to participate in short-range communication. For example, the wireless communication control module may participate in communication within a range of 10 meters to 20 meters. The wireless communication control module may implement wireless communication control based on technologies such as Bluetooth low energy (BLE), ultra wideband (UWB), and near field communication (NFC). For example, the wireless communication control module shown in FIG. 1 is a Bluetooth electronic control unit (ECU).
[0122] The wireless communication control module may be used for unlocking. For example, when the vehicle owner is carrying the key near the vehicle body, the key may detect the vehicle body, and an unlocking command may be automatically generated and transmitted to the wireless communication control module. The wireless communication control module can start anti-theft authentication, and after the authentication is successful, it can control the door controller to unlock the door.
[0123] The remote communication module can be configured to be involved in remote communication, for example, communication by using a mobile cellular network. The remote communication module shown in FIG. 1 is a telematics box (T-Box), and can be configured to communicate with a mobile application. For example, a user can send commands to the T-Box by using a remote application, such as a remote vehicle control application (application, APP). The remote information module may include, but is not limited to, the T-Box. This is not limited in the present application.
[0124] For example, the VIU can be configured to be involved in functions such as communication and power supply. In a possible implementation, the VIU is a controller within a low voltage domain. In some cases, the VIU may alternatively be replaced by a BCM.
[0125] The motor shown in FIG. 1 is a motor control unit (MCU), and can be configured to supply power to the vehicle and drive the vehicle to move. The VDC controls the MCS, and can trigger the MCU to perform a power output operation, for example, by sending a control command to the MCU. The VDC can further obtain battery-related information from the BMS, and further determine whether the communication of the BMS is normal, whether the parameters are normal, etc., to determine whether the BMS can operate normally. The VDC can control the MCU when it is determined that the BMS can operate normally.
[0126] The T-Box can control different operations of the vehicle, such as turning on the air conditioner, opening the window, or opening the door, in response to a user's remote operation, for example, an operation on a remote vehicle control application (application, APP) on a mobile terminal.
[0127] Modules within a vehicle can communicate with each other by using an in-vehicle communication link. For example, the VIC can communicate with the VDC, BMS, BCM, MCU, CDC, wireless communication control module, door controller, etc. by using an in-vehicle communication link. By way of non-limiting example, the in-vehicle communication link can include a controller area network (CAN) bus, a CAN bus with flexible data rate (FD) (abbreviated as CAN FD), a local interconnect network (LIN) bus, a flex ray bus, a media oriented system transport (MOST) bus, automotive Ethernet, etc. Each module in the figure is named only for convenience to distinguish different functions, and does not constitute any limitation on the quantity of each module, nor does it constitute any limitation on the name of each module included in the vehicle.
[0128] System 100 shows only a part of the modules of a motor vehicle. The motor vehicle may include more or fewer modules than these modules shown, combine some of the modules, or split some of the modules, or have different component arrangements. The components shown may be implemented by hardware, software, or a combination of software and hardware.
[0129] Also, other devices may alternatively include some or all of the modules shown in FIG. 1, or include other modules with the same or similar functions. This is not limited in the present application.
[0130] The device control module provided in the present application aims to provide an anti-theft solution for the device. The anti-theft measure is to prevent the theft of the device, that is, to provide an anti-theft solution for the power theft of the power system, and to prevent the theft of items within the device, that is, to provide an anti-theft solution for the key theft of the doors and windows of the device.
[0131] As described above, in a wide-ranging point-to-point authentication solution, keys need to be pre-set and algorithms need to be embedded in all components that require authentication and in the controller. For example, the keys and algorithms are pre-set in all modules of the vehicle before the device is delivered. The development and maintenance costs are high.
[0132] In consideration of this, the present application provides a method in which the authentication for components is transferred to the authentication for a controller that can control each component. The authentication performed by controller #1 for a component is transferred to the authentication performed by component #1 for component #2. Controller #2 can send a control command to the component when the authentication is successful and the authentication result is reliable. The component can respond to the control command after the authentication is successful. Therefore, although authentication is not directly performed on the component in this solution, the component can receive a control command only when the authentication for controller #2 is successful and the authentication result is reliable. This is the same as performing authentication on the component. It is not necessary to pre-set keys and embed algorithms in all components with authentication requirements. It is only necessary to pre-set keys and embed algorithms in only two or three controllers, and the control of each component can be implemented. Therefore, the development and maintenance costs can be reduced. In addition, since the condition for the component to respond to the control command can be satisfied only when multiple parties are controlled to cooperate with each other, unauthorized operation of the device can be more avoided, and theft of the device can be prevented. Therefore, the safety can be improved.
[0133] The following will describe in detail the method provided in the embodiments of the present application with reference to the accompanying drawings.
[0134] FIG. 2 is a schematic flowchart of a component control method 200 for a device according to an embodiment of the present application. As shown in FIG. 2, the method 200 may include steps 210 to 260. The steps of the method 200 will be described in detail below.
[0135] In step 210, the controller #1 performs authentication on the controller #2 and obtains the authentication result.
[0136] Here, the authentication may include, for example, anti-theft authentication. The controller #1 can be regarded as a primary authentication device and can be used to perform authentication on the platform. In this embodiment of the present application, the controller #2 can control a plurality of components within the device. For example, it can collect component-related information (such as whether the communication is normal and parameters) from each component and send control commands to each component. When the authentication performed by the controller #1 for each component is transferred to the authentication for the controller #2, the point-to-point authentication operations performed by the controller #1 for each component with authentication requirements can be omitted. In other words, the controller #2 can perform authentication with the primary authentication device (i.e., the controller #1) on behalf of each component. Therefore, the controller #2 in this embodiment of the present application can be regarded as a secondary authentication device.
[0137] When a user performs an operation, controller #2 may be triggered to start authentication and send an authentication request to controller #1 to enable the device to perform the operation, for example, to enable the device to output power or to output power. Specifically, in different scenarios, the user operation for triggering the device to power on may be different. The following describes the user operation for triggering the device to power on and trigger controller #2 to start authentication with reference to different scenarios. Details will not be described here.
[0138] In response to the received authentication request, controller #1 may perform authentication with controller #2 and obtain an authentication result.
[0139] An example of the authentication process is shown in Figure 3. Step 210 above is described in more detail and specifically includes the following steps:
[0140] Step 301: Controller #2 sends an authentication request to Controller #1, where the authentication request carries a random number.
[0141] For example, the authentication request may be an authentication challenge message.
[0142] Step 302: The controller #1 encrypts the received random number based on the preset key and encryption algorithm to obtain a ciphertext.
[0143] For example, the key may be a session key (SK) previously negotiated with controller #2.
[0144] The ciphertext may be, for example, a personal identification number (PIN) code. The PIN code is an identification code of the device. For example, if the device is an automobile, the PIN code is the identification code of the automobile, which is generally called an engine anti-theft system and can be used to prevent the theft of the automobile.
[0145] Step 303: Controller #1 sends the ciphertext to Controller #2.
[0146] For example, the ciphertext may be carried in an authentication response message.
[0147] Step 304: Controller #2 decrypts the ciphertext based on a pre-set key and a decryption algorithm to obtain a random number.
[0148] The pre-set key in Controller #2 is a key negotiated in advance with Controller #1, and the two keys can be the same. For example, both are SK. The decryption algorithm pre-set in Controller #2 corresponds to the encryption algorithm pre-set in Controller #1.
[0149] The ciphertext is decrypted based on a pre-set key and a decryption algorithm to obtain the plaintext.
[0150] Step 305: Controller #2 determines the authentication result based on the transmitted random number and the random number obtained by decryption.
[0151] When Controller #1 encrypts the random number from Controller #2 to obtain the ciphertext, it can be understood that the random number obtained by decrypting the ciphertext by Controller #2 should be the same random number as the one transmitted in Step 301. In other words, if the random number transmitted by Controller #2 is the same as the random number obtained by decrypting the ciphertext, the authentication is successful. If the random number transmitted by Controller #2 is different from the random number obtained by decrypting the ciphertext, the authentication fails. Controller #2 can determine the authentication result based on the transmitted random number and the random number obtained by decrypting the ciphertext.
[0152] Step 306: Controller #2 sends an authentication result notification to Controller #1.
[0153] Controller #2 can send an authentication result notification to Controller #1 to indicate whether the authentication performed by Controller #1 was successful. For example, the authentication result notification is carried in an authentication status message.
[0154] The authentication process described above with reference to Figure 3 is only an example, and the specific authentication process is not limited in this application. For example, Step 306 in Figure 3 does not need to be performed, and Controller #2 may alternatively indicate whether the authentication was successful by sending or not sending the authentication result. For example, if the authentication is successful, the authentication result is sent. If the authentication fails, the authentication result is not sent. In this way, Controller #1 can also determine whether the authentication was successful according to whether the authentication result was received.
[0155] Note that the authentication process shown above is performed when the authentication for the key is successful. The key is a key used to open the device, supply high voltage to power on the device, or start the device. The key may implement the unlocking function based on, for example, Bluetooth technology, UWB technology, or NFC technology.
[0156] The key authentication process is similar to the authentication process described above with reference to FIG. 3. For the specific process, please refer to the prior art. Details will not be described here again. If the key is not within the detection range of the device, authentication for the key cannot be performed, that is, the authentication fails. Authentication for the controller #2 in this specification may be performed when the authentication for the key is successful. If the authentication for the key fails, the authentication result may be directly determined as authentication failure, and there is no need to perform authentication for the controller #2.
[0157] The subsequent steps are performed based on the execution of authentication for the controller #2. In other words, it is assumed that the authentication for the key is successful.
[0158] In step 220, the controller #1 sends an authentication result notification, and the authentication result notification indicates the authentication result. Correspondingly, the component obtains the authentication result.
[0159] The authentication result includes authentication success or authentication failure.
[0160] It can be seen that in the above authentication process, the controller #1 can determine the authentication result. The controller #1 may further notify the component of the authentication result notification to indicate whether the authentication for the controller #2 is successful.
[0161] It can be understood that the authentication result notification may be the authentication result notification received by the controller #1 from the controller #2 in the above authentication process, or the authentication result notification generated by the controller #1 based on the authentication result notification received from the controller #2.
[0162] In a possible implementation, Controller #1 may send an authentication success notification when the authentication is successful. The authentication success notification can be used to notify that the authentication for Controller #2 has been successful. In other words, the authentication success notification is a specific example of the authentication result notification. When the authentication fails, Controller #1 may not send any notification. If the component does not receive any notification, the component may determine that the authentication performed by Controller #1 on Controller #2 has failed.
[0163] In another possible implementation, Controller #1 sends an authentication result notification regardless of whether the authentication is successful, indicating whether the authentication is successful or failed. The authentication result may include a field indicating success or failure. For example, "1" indicates that the authentication is successful, and "0" indicates that the authentication has failed. Alternatively, the authentication result may be indicated in other ways. This is not limited in this application. When the authentication result is an authentication success, the authentication result notification becomes an authentication success notification. When the authentication result is an authentication failure, the authentication result notification becomes an authentication failure notification.
[0164] From the above two implementations, it can be seen that when the authentication is successful, Controller #1 may send an authentication success notification. When the authentication fails, Controller #1 may send an authentication failure notification or may not send any notification. However, regardless of whether Controller #1 sends an authentication result notification, it can be understood that the component can determine the authentication result based on the reception status of the authentication result notification. The figure is only an example and shows the step of Controller #1 sending the authentication result notification to the component. In fact, the receiving end of the authentication result notification is not limited in this application.
[0165] The latter implementation described above is used as an example. Controller #1 may send an authentication result notification by broadcast, whereby all components connected by using the communication link can receive the notification. This achieves complete coverage. This solution is particularly applicable to the offline diagnosis phase before the device is incorporated. Controller #1 may alternatively send an authentication result notification to one or more pre-defined components, whereby the one or more components can receive the notification without causing an unnecessary impact on other components. The one or more pre-defined components may be pre-written by the developer in Controller #1 by using code. For example, in an automobile, the one or more pre-defined components may include one or more of the following: motor, BMS, and door controller.
[0166] In step 230, the component sends a response message to Controller #1, and the response message indicates that the reception of the authentication result notification was successful.
[0167] Each component that has received the above authentication result notification may send a response message to Controller #1 to indicate that the reception of the authentication result notification was successful. Alternatively, the components that need to send a response message may be pre-defined. For example, the developer may pre-write in Controller #1 by using code the components that need to feedback a response message.
[0168] As described above, if Controller #1 is unable to authenticate Controller #2, the authentication result notification may not be sent. In this case, the component does not need to send a response message to Controller #1. In other words, if the authentication fails, step 230 is not necessarily performed. The figure is only an example and shows the step where the component sends a response message to Controller #1.
[0169] In step 240, the controller #1 sends an authentication reliability notification to the controller #2 based on the received response message, and the authentication reliability notification indicates that the authentication result is reliable.
[0170] The reason why the component needs to feedback the response message is that in the scenario where the component is replaced, it is considered that the replaced component may not send the response message to the controller #1, and thereby, the controller #1 detects the component exception within the time limit and further sets the authentication result as untrustworthy.
[0171] In contrast, when the controller #1 receives a response message from the component, the controller #1 can consider that the component is normal and has not been replaced, and further, it can notify the controller #2 that the authentication result is reliable.
[0172] The controller #1 can determine whether the above authentication result is reliable based on the reception status of the response message and notify the controller #2.
[0173] In a possible implementation, when the controller #1 determines that the authentication result is reliable, it may send an authentication reliability notification to the controller #2 to indicate that the authentication result is reliable, or it may not send any notification when the authentication result is unreliable. If the controller #2 does not receive any notification, the controller #2 can determine that the authentication result is unreliable. In other words, when the controller #1 does not receive the response message, step 240 is not necessarily performed.
[0174] In another possible implementation, the controller #1 sends a notification regardless of whether the authentication result is reliable to indicate whether the authentication result is reliable or unreliable. For example, when the authentication result is reliable, the notification is an authentication reliability notification. When the authentication result is unreliable, this notification is an authentication non - reliability notification.
[0175] In the above two implementations, when the authentication is reliable, step 240 can be performed, that is, it can be seen that controller #1 sends an authentication reliability notification to controller #2. When the authentication is not reliable, step 240 may or may not be performed. The figure is only an example and shows the step where controller #1 sends an authentication reliability notification to controller #2.
[0176] In step 250, controller #2 sends a control command to the component when the authentication is successful and the authentication result is reliable.
[0177] As described above, controller #2 can determine whether the authentication is successful or failed by performing the authentication process shown in FIG. 3. Controller #2 can further determine whether the authentication result is reliable based on whether an authentication reliability notification is received. In this embodiment of the present application, controller #2 can send a control command to the component only when both of the two conditions are satisfied, that is, when the authentication is successful and the authentication result is reliable.
[0178] The control command sent by controller #2 can be used to trigger the component to respond. In other words, the component that receives the control command is the component controlled by controller #2. Furthermore, the relationship between controller #2 and the component can be predefined. For example, for each different component #2, one or more components that can be controlled by that controller #2 can be specified in advance. Since the relationship between controller #2 and the component will be described below with reference to specific examples, the details are not described here.
[0179] In step 260, the component responds to the control command when the authentication performed by controller #1 on controller #2 is successful.
[0180] Since Controller #2 sends a control command only when it receives an authentication reliability notification, for a component to receive a control command means that the authentication result is reliable. That is, the condition that the authentication result is reliable under the above two conditions is satisfied. After receiving the control command, the component may first determine whether the authentication performed by Controller #1 on Controller #2 was successful, and if the authentication was successful and the remaining conditions are also satisfied, it may respond to the control command.
[0181] Corresponding to that in the above implementation where Controller #1 sends an authentication result, the component may determine whether the authentication was successful based on different implementations. For example, corresponding to that in the former implementation, the component may determine that the authentication was successful if an authentication success notification is received, and may determine that the authentication failed if no authentication notification is received. Corresponding to that in the latter implementation, the component may determine whether the authentication was successful or failed based on the information indicated in the received authentication result.
[0182] Based on the above solution, in order to control the component to execute the corresponding operation, the authentication between Controller #1 and Controller #2 must succeed. The component needs to participate in the authentication and respond to the authentication result. Thereby, when the authentication for Controller #2 is successful and the component is normal, Controller #2 sends a control command. In this way, the component responds to the received control command only when the authentication is successful and the authentication result is reliable. Since the authentication for the component is transferred to the authentication for Controller #2, Controller #2 can control one or more components. Therefore, it is not necessary to pre-set keys and embed algorithms in all components with authentication requirements. It is only necessary to pre-set keys and embed algorithms in only two or three controllers. The control of each component can be realized, and the anti-theft effect can be achieved. Therefore, security protection can be provided to more components, more requirements can be satisfied, and the development and maintenance costs can be reduced. Also, since the condition for the component to respond to the control command can be satisfied only when multiple parties are controlled to cooperate with each other, unauthorized operation of the device can be further avoided, and theft of the device can be prevented. Therefore, the security is improved.
[0183] The following details Controller #1, Controller #2, the component, the control command, and the response of the component by using an automobile as an example of a platform. In each of the following examples, it is assumed that the authentication for Controller #2 is successful and the authentication result is reliable, and the component determines that it can respond to the control command received by the component. To better understand the method provided in this application, the following describes the method by using multiple examples with reference to specific scenarios.
[0184] 1. Anti-theft scenario for power theft
[0185] The prevention of power system theft aims to prevent vehicle theft and can be achieved by controlling power-executing components (e.g., motors) or power supply components (e.g., BMS).
[0186] Optionally, Controller #1 is at least one of the following: VIU, BCM, and wireless communication control module. Controller #2 is VDC, and the components controlled by VDC include motors and / or BMS. The components that receive control commands may include motors and / or BMS.
[0187] The control commands sent by VDC to the motor carry torque requests, and the torque requests can be used to control the motor to execute torque responses in order to output the power for driving the vehicle to move. In response to the torque requests in the control commands, the motor can execute operations such as torque responses and power output.
[0188] The control commands sent by VDC to the BMS can be used to control the BMS to output power so that the vehicle is supplied with power and starting power. In response to the control commands, the BMS can output power.
[0189] Note that Controller #2 may send control commands to the motor, or to the BMS, or to both the motor and the BMS. It can be understood that the vehicle cannot start unless either the motor or the BMS responds to the control commands. In other words, VDC can provide an anti-theft effect by controlling the motor and / or BMS to prevent vehicle theft.
[0190] For example, when detecting a gear shifting operation, VDC can start authentication. VDC can actively send an authentication request to the VIU. For the authentication between the VIU and VDC where the VIU authenticates VDC based on the authentication request, refer to the relevant description above with reference to Figure 3. Details are not described again here.
[0191] The VIU can send a VDC authentication result notification to the motor to indicate the authentication result of the VDC. The motor can feedback a response message to the authentication result. After receiving the response message from the motor, the VIU sends an authentication reliability notification to the VDC. When it is determined that the authentication is successful and the authentication result is reliable, the VDC can send a control command to the motor. The control command can be used to control the motor to perform a power output operation. In other words, if the authentication for the VDC fails, or if the VDC determines that the authentication result is not reliable, no control command will be sent to the motor. In this way, even if the authentication for the VDC is successful, if the authentication result is not reliable, the motor will not perform any operation, that is, the vehicle cannot start. In this way, vehicle theft is prevented.
[0192] After receiving the authentication result notification, the motor can determine whether the VDC authentication was successful. If the authentication is successful, the motor can respond to the received control command. If the authentication fails, no response to the received control command is required. As a result, if the authentication for the VDC fails, the motor will not perform any operation, that is, the vehicle cannot start. In this way, vehicle theft is prevented.
[0193] In some cases, a third party may steal a vehicle by replacing a module.
[0194] For example, a third party may steal a vehicle by replacing the VDC. The newly replaced VDC may not send an authentication request to the VIU to avoid authentication. However, in this solution, since the VIU does not authenticate the VDC, the motor cannot receive an authentication result notification from the VIU. However, if the authentication result notification is not received, the motor cannot determine that the authentication was successful. Therefore, even if the VDC sends a control command to the motor, the motor will not respond to the control command. That is, even if the VDC is replaced, the vehicle will not start.
[0195] As another example, a third party may steal a vehicle by replacing the VIU. However, since the keys and algorithms used for authentication in the VIU are pre-set before incorporation, it is difficult to steal. Even if the VIU is replaced, it is difficult to succeed in authenticating the VDC. If the authentication fails, the motor does not respond to the control command. That is, even if the VIU is replaced, the vehicle cannot be started.
[0196] As another example, a third party may steal a vehicle by replacing the motor. However, if the motor is replaced, the motor does not feedback a response message for the authentication result. If the VIU does not receive the response message, the VIU sets the authentication result as untrustworthy. In this way, the VDC does not send a control command to the motor, the motor does not perform any operation when it does not receive the control command, and the vehicle still cannot be started.
[0197] In another example, when detecting a gear shifting operation, the VDC may start authentication. The VDC may dynamically send an authentication request to the VIU. The VIU authenticates the VDC based on the authentication request. For the authentication between the VIU and the VDC, refer to the above related description with reference to FIG. 3. Details are not described here again.
[0198] The VIU may send a VDC authentication result notification to the BMS to indicate the authentication result of the VDC. The BMS may feedback a response message for the authentication result. After receiving the response message from the BMS, the VIU sends an authentication reliability notification to the VDC. When it is determined that the authentication is successful and the authentication result is reliable, the VDC may send a control command to the BMS. Here, the control command is used to control the BMS to execute a power output operation. In other words, if the authentication for the VDC fails, or the VDC determines that the authentication result is unreliable, no control command is sent to the BMS. In this way, the BMS does not output power when the authentication for the VDC is successful but the authentication result is unreliable. An automobile cannot start without power output. In this way, vehicle theft is prevented.
[0199] Similar to the above example, if any one of the VIU, VDC, and BMS is replaced, the BMS does not output power, and the automobile cannot start without power output. In this way, vehicle theft is prevented.
[0200] It can be seen that in this solution, the conditions for the power execution component to execute a power output operation and / or for the power supply to execute a power output operation need to be satisfied by the cooperation of multiple parties. If any party is replaced, the component cannot execute the corresponding operation, so illegal operations of the automobile can be better avoided, vehicle theft is prevented, and safety is improved.
[0201] 2. Key Theft Prevention Scenario
[0202] The key theft prevention measure aims to prevent the doors and windows of the automobile from being opened and prevent the theft of items inside the vehicle.
[0203] Optionally, Controller #1 is the VIU and / or BCM, Controller #2 is a wireless communication control module, and the components controlled by the wireless communication control module include a door controller and / or a window controller.
[0204] The control commands sent by the VDC to the door controller can be used to control the door controller so that the door can be unlocked and opened. In response to the control command, the door controller unlocks the door. Similarly, the control commands sent by the VDC to the window controller can be used to control the window controller so that the window can be unlocked and opened. In response to the control command, the window controller unlocks the window. Therefore, the VDC can provide an anti-theft effect through the control of the door controller. In this way, theft of items inside the vehicle is prevented.
[0205] As an example, when the Bluetooth ECU (i.e., an example of a wireless communication control module) receives an unlock command from the key, it may start anti-theft authentication. The Bluetooth ECU may actively send an authentication request to the VIU. For the authentication between the VIU and the Bluetooth ECU, refer to the above related description with reference to FIG. 3. Details will not be described again here.
[0206] The VIU may send a Bluetooth ECU authentication result notification to the door controller and the window controller to indicate the authentication result of the Bluetooth ECU. The door controller and the window controller may feedback a response message for the authentication result. After receiving the response message from the door controller and the window controller, the VIU sends an authentication reliability notification to the Bluetooth ECU. If it is determined that the authentication is successful and the authentication result is reliable, the Bluetooth ECU may send a control command to the door controller and the window controller. The control command can be used to instruct the door controller to perform an operation to unlock the door and the window.
[0207] After receiving the authentication result notification, the door controller can determine whether the authentication of the Bluetooth ECU is successful. If the authentication is successful, the door and window can be unlocked according to the received control command, and the door and window can be opened. If the authentication fails, no response is made to the received control command, and the door and window still cannot be opened. In this way, when the authentication fails, the Bluetooth ECU does not perform the operation of unlocking the door and window. In this way, theft of items inside the vehicle is prevented. Since the door and window cannot be opened, a third party cannot enter the vehicle and cannot start the vehicle. In this way, vehicle theft can also be prevented.
[0208] Similar to the principle described in the above example, when any one of the VIU, Bluetooth ECU, and door controller is replaced, the door controller does not unlock the door and window, and a third party cannot enter the vehicle. In this way, theft of items inside the vehicle is prevented, and vehicle theft is prevented.
[0209] 3. Remote anti-theft scenario
[0210] With the development of intelligent terminals, remote vehicle control applications are being used more widely. Remote vehicle control applications can be used to remotely control functions such as starting, stopping, unlocking, locking, and searching for a vehicle. When the application is used, the vehicle owner can open the door and start the vehicle without the need for a key.
[0211] The purpose of remote anti-theft measures is to prevent the vehicle from being remotely opened, for example, to prevent the door and window from being opened, so as to prevent theft of items inside the vehicle, or to prevent the vehicle from being started, so as to prevent the vehicle from being stolen.
[0212] Optionally, Controller #1 is a VIU, BCM, or wireless communication control module, Controller #2 is a remote communication module, and the components controlled by the remote communication module include one or more of a motor, a BMS, and a door controller. The component receiving this control instruction may be one or more of a motor, a BMS, and a door controller.
[0213] The control of the remote communication module over the motor, BMS, and door controller is similar to the control of the VDC over the motor and BMS and the control of the Bluetooth ECU over the door controller in the above example. In the above example, two cases are described in detail with reference to the examples: when implementing anti-theft measures for a vehicle by controlling a power execution component and / or a power supply component, and when implementing anti-theft measures for items inside the vehicle by controlling a door controller. The details are not described again here.
[0214] Note that the remote communication module can simultaneously control at least one of the door controller and the motor and BMS so as to provide an anti-theft effect by controlling the door controller and provide an anti-theft effect by controlling the motor and / or BMS. In this way, theft of items inside the vehicle is prevented and theft of the vehicle is prevented.
[0215] Based on the same concept, remote anti-theft measures can also be used to prevent other modules inside the vehicle from being illegally activated. For example, the vehicle's air conditioner is illegally turned on, causing waste of unnecessary resources. By implementing this solution, the air conditioner can also be prevented from being illegally turned on. For example, the VIU or wireless communication module is used as Controller #1, the remote communication module is used as Controller #2, and the BCM is used as a component to control the air conditioner. By implementing the above solution, the BCM can be prevented from controlling the air conditioner to turn on.
[0216] In the multiple scenarios and examples provided above, the examples of Controller #1, Controller #2, and components are merely examples for ease of understanding and should not constitute any limitation to this application. Based on the same concept, those skilled in the art may further use other modules to implement the functions of Controller #1, Controller #2, and components respectively.
[0217] To further improve security and better prevent theft of the device, this solution further considers other scenarios and determines the authentication result based on more factors.
[0218] As described above, if the authentication of the key fails before the authentication of Controller #2, the authentication result can be directly determined as authentication failure. In this way, theft of the device can be further prevented.
[0219] Optionally, before step 210, the method further includes determining whether the key is within a pre-set range. Correspondingly, step 210 can be executed after it is determined that the key is within the pre-set range, and the authentication result can be determined based on the authentication process of Controller #2. In contrast, if it is determined that the key is not within the pre-set range, the authentication result can be determined as authentication failure.
[0220] Here, the pre-set range may be the detection range of the device. In other words, if the key can be detected within the detection range of the device, the key is considered to be within the detection range. If the key cannot be detected within the detection range of the device, the key is considered not to be within the detection range. The specific size of the pre-set range can be determined by the device manufacturer. This is not limited in this application.
[0221] For example, when the vehicle owner temporarily leaves the automobile with the key, the vehicle is unlocked, and the vehicle is still in the powered-on state, a third party can directly enter the automobile to start it. As described above, since the key is not within the detection range of the automobile, the authentication for the key fails, and thus, the authentication result is a failed authentication. In this case, the third party cannot start the automobile to avoid theft of the automobile.
[0222] Also, to prevent a third party from entering the vehicle and causing loss of items inside the vehicle, the automobile can be automatically locked. The automatic vehicle locking function includes, but is not limited to, automatic power-off, door locking, and window locking. For example, when it is detected that the time when there is no one inside the vehicle exceeds a preset time, the vehicle is automatically locked. The preset time can be determined by the device manufacturer. This is not limited in the present application.
[0223] Optionally, the method further includes determining that the authentication result is a failed authentication when an abnormal situation is detected.
[0224] Here, the abnormal situation may be a pre-defined event, including, but not limited to, breaking a window, breaking a door, and picking behavior. The abnormal situation can be reported to Controller #1 after being detected by a sensor. When Controller #1 receives the report of the abnormal situation, Controller #1 can determine that the authentication result is a failed authentication.
[0225] For example, when the vehicle owner leaves the automobile and leaves the key inside the vehicle, but the door is locked, a third party may break into the automobile by breaking a window, breaking a door, and picking behavior to obtain the key and start the automobile. In this case as well, the authentication result can be directly determined as a failed authentication. Even if the third party obtains the key and is in a state to start the automobile, the automobile cannot be started due to the failed authentication. In this way, theft of the automobile is prevented.
[0226] In addition, in order to notify the vehicle owner within a certain time to avoid greater losses, after detecting an abnormal situation, the sensor can activate the camera to monitor the environment around the vehicle, save the captured images, and upload the images to the mobile terminal of the vehicle owner.
[0227] From multiple examples, it can be seen that by using the solution provided in this application, the development and maintenance costs caused by pre-setting keys and embedding algorithms in all components can be reduced. Furthermore, a reliable anti-theft mechanism can be provided to prevent the theft of devices such as vehicles and achieve high safety.
[0228] For ease of understanding, the above describes the component control method provided in this application by using some components in the vehicle as examples. These components and their functions are only examples and should not constitute any limitation to this application. The components used to implement functions such as power output, power supply output, and control of the doors, windows, air conditioning, etc. mentioned above, and their names are not limited in this application.
[0229] In addition, the above describes some possible scenarios by using the vehicle as an example, but this should not constitute any limitation to the devices to which this application is applied. As described above, the solution may be further applied to other devices. In different devices, the specific forms and names of Controller #1, Controller #2, and components may be different from each other. However, this should not affect the scope of application of this application. As long as the functions of Component #1, Component #2, and components can be implemented, the control of device components needs to be implemented.
[0230] The examples given above are merely some of the possible scenarios and do not constitute a limitation on the scenarios to which this solution is applicable. Based on the same concept, a person skilled in the art can further determine the authentication result based on more factors in order to further improve the security.
[0231] The above has described in detail the method provided in the embodiments of the present application with reference to FIGS. 2 and 3. The following will describe in detail the device provided in the embodiments of the present application with reference to FIGS. 4 and 5.
[0232] FIG. 4 is a block diagram of a component control device 400 for a device according to an embodiment of the present application. As shown in FIG. 4, the device 400 may include a transceiver unit 410 and a processing unit 420.
[0233] In a possible design, the device 400 shown in FIG. 4 may correspond to the components in the embodiments of the above method and may execute the steps performed by the components in the embodiments of the above method. For example, the device 400 may be a component, a chip or a chip system configured in the component, or other logic unit or software that can implement some or all of the functions of the component. This is not limited in the present application.
[0234] The transceiver unit 410 may be configured to obtain a control instruction from the controller #2, and the control instruction is an instruction transmitted by the controller #2 when the authentication performed by the controller #1 on the controller #2 is successful and the authentication result is reliable. The processing unit 420 may be configured to obtain the result of the authentication performed by the controller #1 on the controller #2, and the authentication result includes authentication success or authentication failure. The processing unit 420 may be further configured to respond to the control instruction when the authentication result is authentication success.
[0235] The device 400 may include units configured to perform processes and / or steps corresponding to the components in the above method 200. For the sake of brevity, details are not described here.
[0236] In another possible design, the device 400 shown in FIG. 4 may correspond to the controller #1 in the above method embodiment, and may perform the steps executed by the components in the above method embodiment. For example, the device 400 may be the controller #1, a chip or chip system configured in the controller #1, or other logic units or software capable of implementing some or all of the functions of the controller #1. This is not limited in this application.
[0237] The transceiver unit 410 may be configured to send an authentication success notification when the authentication for the controller #2 is successful. The authentication success notification is used to notify that the authentication for the controller #2 is successful. Further, it may be configured to send an authentication reliability notification when a response message is received. The response message is from a component controlled by the controller #2, indicates that the reception of the authentication success notification is successful, and the authentication reliability notification indicates that the authentication success notification is reliable.
[0238] The device 400 may include units configured to perform processes and / or steps corresponding to the controller #1 in the above method 200. For the sake of brevity, details are not described here.
[0239] In yet another possible design, the device 400 shown in FIG. 4 may correspond to the controller #2 in the above method embodiment, and may perform the steps executed by the components in the above method embodiment. For example, the device 400 may be the controller #2, a chip or chip system configured in the controller #2, or other logic units or software capable of implementing some or all of the functions of the controller #2. This is not limited in this application.
[0240] The processing unit 420 may be configured to obtain the result of the authentication performed by the controller #1 for the device 400, and the authentication result includes authentication success or authentication failure. The transceiver unit 410 may be configured to send a control command to a component controlled by the device 400 and trigger the component to respond when the authentication result is authentication success and the authentication result is reliable.
[0241] The device 400 may include a unit configured to execute the process and / or steps corresponding to the controller #2 in the above method 200. For the sake of brevity, details are not described here.
[0242] The functions of the device 400 may be implemented by using hardware, software, or a combination of software and hardware.
[0243] In this embodiment of the present application, the division into units is an example and is only a logical function division. In actual implementation, other division modes may be used. Also, the functional units in the embodiments of the present application may be integrated into one processor, or each of the units may physically exist alone, or two or more units may be integrated into one unit. The integrated unit may be implemented in the form of hardware or in the form of a software functional unit.
[0244] FIG. 5 is another block diagram of a component control device 500 for a device according to an embodiment of the present application. As shown in FIG. 5, the device 500 includes a processor 510 and a memory 520. The memory 520 may be configured to store a computer program, and the processor 510 may be configured to call and execute the computer program, whereby the device implements the functions of the component, the controller #1, or the controller #2 in the method provided in the embodiment of the present application.
[0245] Optionally, the device 500 may further include a communication interface 530. The communication interface 530 may be a transceiver, interface, bus, circuit, or device capable of implementing a transceiver function. The communication interface 530 is configured to communicate with other devices by using a transmission medium so that the device 500 communicates with other devices.
[0246] For example, if the device 500 corresponds to a component in the above-described method embodiment, the processor 510 may be configured to control the communication interface 530 to obtain a control command from the controller #2, where the control command is a command sent by the controller #1 when the authentication performed by the controller #2 on the controller #1 is successful and the authentication result is reliable. The processor 510 may be further configured to obtain a result of the authentication performed by the controller #1 on the controller #2, and respond to the control command when the authentication result is successful, where the authentication result includes successful authentication or failed authentication. For details, please refer to the detailed description in the method 200. The details will not be described again here.
[0247] In another example, if the device 500 corresponds to the controller #1 in the embodiment of the above method, the processor 510 may be configured to control the communication interface 530 to send an authentication success notification when authentication to the controller #2 is successful, and the authentication success notification is used to notify that authentication to the controller #2 has been successful. The processor 510 may be further configured to control the communication interface 530 to send an authentication trust notification when a response message is received, the response message being from a component controlled by the controller #2 and indicating successful receipt of the authentication success notification, and the authentication trust notification indicating that the authentication success notification is trustworthy. For details, please refer to the detailed description in the method 200. The details will not be described again here.
[0248] In another example, when the device 500 corresponds to the controller #2 in the embodiment of the above method, the processor 510 may be configured to obtain the result of the authentication performed by the controller #1 for the device 500, and the authentication result includes authentication success or authentication failure. When the authentication result is authentication success and the authentication result is reliable, the processor 510 may be further configured to control the communication interface 530 to send a control instruction to the component controlled by the device 500 to trigger the component to respond. For details, refer to the detailed description in the method 200. The details will not be described again here.
[0249] The coupling in this embodiment of the present application may be an indirect coupling or a communication connection between devices, units, or modules in an electrical form, a mechanical form, or other forms, and is used for information exchange between the devices, units, or modules. The processor 510 may operate in cooperation with the memory 520. The processor 510 may execute the program instructions stored in the memory 520. At least one of the at least one memory may be included in the processor.
[0250] The specific connection medium between the processor 510, the memory 520, and the communication interface 530 is not limited in the embodiment of the present application. In this embodiment of the present application, the memory 520, the processor 510, and the communication interface 530 are connected by a bus 540 in FIG. 5. The bus is represented by a thick line in FIG. 5. The connection manner between other components is only an example for description and is not limited thereto. The bus may be classified into an address bus, a data bus, a control bus, etc. For ease of expression, only one thick line is used for representation in FIG. 5, but this does not mean that there is only one bus or only one type of bus.
[0251] The processor in the embodiments of the present application may be an integrated circuit chip and has a signal processing function. In the implementation process, the steps in the embodiments of the above method may be implemented by using the hardware integrated logic circuit in the processor or by using instructions in the form of software. The above processor may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor or the like. The steps of the method disclosed with reference to the embodiments of the present application may be directly executed and completed by a hardware decoding processor, or may be executed and completed by using a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or a register. The storage medium is located in the memory, and the processor reads the information in the memory and combines it with the hardware of the processor to complete the steps of the above method.
[0252] The memory in the embodiments of the present application may be a non-volatile memory or a volatile memory, or may include both a non-volatile memory and a volatile memory. The non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM) used as an external cache. By way of example and not limitation, many forms of RAM may be used, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM). Note that the memory of the systems and methods described herein includes, but is not limited to, these memories and any other suitable types of memory.
[0253] The present application further provides an automobile. The automobile may include the components, Controller #1, and Controller #2 in the embodiments of the above method.
[0254] The present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the method executed by the component in the embodiment shown in FIG. 2 is implemented, or the method executed by Controller #1 in the embodiment shown in FIG. 2 or FIG. 3 is implemented, or the method executed by Controller #2 in the embodiment shown in FIG. 2 or FIG. 3 is implemented.
[0255] The present application further provides a computer program product including a computer program. When the computer program is executed, the method executed by the component in the embodiment shown in FIG. 2 is implemented, or the method executed by Controller #1 in the embodiment shown in FIG. 2 or FIG. 3 is implemented, or the method executed by Controller #2 in the embodiments shown in FIG. 2 and FIG. 3 is implemented.
[0256] Terms such as "unit" and "module" used herein may refer to a computer-related entity, hardware, firmware, a combination of hardware and software, software, or software in execution.
[0257] Those skilled in the art will recognize that the illustrative logical blocks and steps described in the embodiments disclosed herein can be implemented in combination by electronic hardware or a combination of computer software and electronic hardware. Whether a function is executed by hardware or software depends on the particular application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for each particular application, but the implementation should not be considered to exceed the scope of this application. In some embodiments provided in this application, it should be understood that the disclosed devices, apparatuses, and methods may be implemented in other manners. For example, the described embodiments of the device are merely examples. For example, the division into units is only a logical function division, and in actual implementation, other divisions may be possible. For example, a plurality of units or components may be combined or integrated with other systems, or some features may be ignored or not executed. Also, the described mutual connection, direct connection, or communication connection shown or discussed may be implemented by using some interfaces. The indirect connection or communication connection between devices or units may be implemented in an electronic, mechanical, or other form.
[0258] The units described as separate parts may be physically separated, and the parts shown as units may or may not be physical units, and may be located in one place or distributed over a plurality of network units. Some or all of the units may be selected based on actual requirements to achieve the purpose of the solution of the embodiment.
[0259] Also, the functional units in the embodiments of this application may be integrated into one processing unit, each unit may physically exist alone, or two or more units may be integrated into one unit.
[0260] In the above-described embodiments, all or part of the functions of the functional units may be implemented by software, hardware, firmware, or any combination thereof. When software is used to implement the embodiments, all or some of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions (programs). When the computer instructions (programs) are loaded and executed on a computer, all or part of the processes or functions according to the embodiments of the present application are generated. The computer may be a general-purpose computer, a dedicated computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium, or may be transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted in a wired (e.g., coaxial cable, optical fiber, or digital subscriber line (DSL)) or wireless (e.g., infrared, radio wave, or microwave) form from a website, computer, server, or data center to another website, computer, server, or data center. The computer-readable storage medium may be any usable medium accessible by a computer, or a data storage device such as a server or data center incorporating one or more usable media. The usable media may be a magnetic medium (e.g., floppy disk, hard disk, or magnetic tape), an optical medium (e.g., digital video disc (DVD)), a semiconductor medium (e.g., solid state disk (SSD)), etc.
[0261] If the function is implemented in the form of a software functional unit and sold or used as an independent product, the function may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application is essentially, or the part that contributes to the prior art, or a part of the technical solution may be implemented in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for instructing a computer device (personal computer, server, or network device) to execute all or part of the steps of the method described in the embodiments of the present application. The above storage medium includes any medium that can store program codes, such as a USB flash drive, removable hard disk, ROM, RAM, magnetic disk, or optical disk.
[0262] The above description is only a specific implementation of the present application and is not intended to limit the protection scope of the present application. Any modification or substitution that can be easily conceived by those skilled in the art within the technical scope disclosed in the present application should fall within the protection scope of the present application. Therefore, the protection scope of the present application should follow the protection scope of the claims.
[0263] This application claims priority to Chinese Patent Application No. 202210690337.4, filed with the China National Intellectual Property Administration on June 17, 2022, with the invention title "COMPONENT CONTROL METHOD FOR DEVICE AND RELATED APPARATUS", and the entire text of this Chinese patent application is incorporated herein by reference.
Claims
1. A component control method for a device applied to a component, comprising: obtaining a control command from a first controller, wherein the control command is a command sent by the first controller when authentication performed by a second controller on the first controller is successful and the authentication result is reliable; obtaining the result of authentication performed by the second controller on the first controller, wherein the authentication result includes authentication success or authentication failure; responding to the control command when the authentication result is the authentication success. A method having the above.
2. When the authentication result is the authentication success, obtaining the result of authentication performed by the second controller on the first controller includes: receiving an authentication success notification from the second controller, wherein the authentication success notification is used to notify the first controller that the authentication performed by the second controller on the first controller is successful. The method according to claim 1.
3. The authentication success notification is sent by broadcast, or the authentication success notification is sent to one or more predefined components. The method according to claim 2.
4. The method further includes sending a response message to the second controller, wherein the response message indicates that the reception of the authentication success notification is successful. The method according to claim 2 or 3.
5. The device is a vehicle, the first controller has a vehicle domain controller VDC or a vehicle control unit VCU, the second controller has at least one of the following: a vehicle integrated unit VIU, a wireless communication control module, and a body control module BCM, the component has a motor and / or a battery management system BMS. The method according to any one of claims 1 to 4.
6. The component has the motor, the control command carries a torque request, responding to the control command includes: executing a torque response and a power output in response to the control command. The method according to claim 5.
7. The component has the BMS, the control command instructs the BMS to output power, responding to the control command includes: Outputting the power in response to the control command The method according to claim 5
8. The device is a vehicle The first controller has a wireless communication control module The second controller has a VIU and / or a BCM The component has a door controller and / or a window controller The method according to any one of claims 1 to 4
9. The component has the door controller, and the control command instructs the door controller to unlock the door Responding to the control command Includes unlocking the door in response to the control command and / or The component has the window controller, and the control command instructs the window controller to unlock the window Responding to the control command Includes unlocking the window in response to the control command The method according to claim 8
10. If the key used to unlock the device is not within a pre-set range or a predefined abnormal situation is detected, the authentication result is the authentication failure The method according to any one of claims 1 to 9
11. A component control method for a device applied to a first controller, comprising: Obtaining the result of authentication performed by a second controller for the first controller, the authentication result including authentication success or authentication failure, and When the authentication result is the authentication success and the authentication result is reliable, sending a control command to a component controlled by the first controller to trigger the component to respond The method having
12. The method further includes receiving an authentication reliability notification from the second controller The authentication reliability notification indicates that the authentication result is reliable The method according to claim 11
13. The device is a vehicle The first controller has a vehicle domain controller VDC or a power control module VCU The second controller has at least one of the following: a vehicle integrated unit VIU, a wireless communication control module, and a body control module BCM The component has a motor and / or a battery management system BMS The method according to claim 11 or 12
14. The device is a vehicle, the first controller has a wireless communication control module, the second controller has a VIU and / or a BCM, the component has a door controller and / or a window controller, The method according to claim 11 or 12.
15. If the key used to start the device is not within a pre-set range, or if a predefined abnormal situation is detected, the result of the authentication is the authentication failure, The method according to any one of claims 11 to 14.
16. A component control method for a device, applied to a second controller, comprising: when the authentication for the first controller is successful, sending an authentication success notification, which is used to indicate that the authentication for the first controller is successful; and when a response message is received, sending an authentication reliability notification to the first controller, where the response message is from a component controlled by the first controller, the response message indicates that the reception of the authentication success notification is successful, and the authentication reliability notification indicates that the authentication success notification is reliable. The method having the above.
17. The authentication success notification is sent by broadcast, or the authentication success notification is sent to one or more pre-defined components, The method according to claim 16.
18. The method further comprises receiving the response message from the component, The method according to claim 16 or 17.
19. The device is a vehicle, the first controller has a vehicle domain controller VDC or a power control module VCU, the second controller has at least one of the following: a vehicle integrated unit VIU, a wireless communication control module, and a body control module BCM, the component has a motor and / or a battery management system BMS, The method according to any one of claims 16 to 18.
20. The device is a vehicle, the first controller has a wireless communication control module, the second controller has a VIU and / or a BCM, the component has a door controller and / or a window controller, The method according to any one of claims 16 to 18.
21. The method is receiving an authentication request from the first controller, the authentication request being used to request authentication of the first controller, and performing authentication on the first controller in response to the authentication request to obtain an authentication result and having The method according to any one of claims 16 to 20.
22. Before performing authentication on the first controller in response to the authentication request, the method is determining that a key used to unlock the device is within a pre-set range, and performing authentication on the key and having Performing authentication on the first controller in response to the authentication request to obtain an authentication result is when authentication of the key is successful, performing authentication on the first controller in response to the authentication request to obtain the authentication result, or when authentication of the key fails, determining that the authentication result is an authentication failure and having The method according to claim 21.
23. The method is further having, when a pre-defined abnormal situation is detected, determining that the authentication result is an authentication failure The method according to claim 21.
24. A component control device for a device, having a component configured to execute the method according to any one of claims 1 to 23.
25. A component control device for a device, having a processor and a memory, the processor being coupled to the memory, the processor being configured to control the device to implement the method according to any one of claims 1 to 23. Device.
26. Having a first controller, a second controller, and a component, the first controller being configured to send a control command to the component when the authentication performed by the second controller on the first controller is successful and the authentication result is reliable, whether the authentication result is reliable being determined based on a notification from the first controller, the component being configured to obtain the result of the authentication performed by the second controller on the first controller, the authentication result including authentication success or authentication failure. The component is further configured to respond to the control instruction when the authentication result is the authentication success. Vehicle.
27. A computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor, the method according to any one of claims 1 to 23 is implemented. Computer-readable storage medium.
28. A computer program product including a computer program, wherein when the computer program is executed, the method according to any one of claims 1 to 23 is implemented. Computer program product.
Citation Information
Patent Citations
Vehicle start limiting method, device and system
CN109572620A
Wireless communication system
JP2019080139A
Communication device
JP2020021161A
Trusted connected vehicle systems and methods
US20130212659A1
Verification method and apparatus
WO2021238968A1