Communication methods and related devices

The communication method for smart vehicle keys addresses security risks through encryption and credential management, ensuring end-to-end security and reducing economic threats by enhancing network security.

JP2025530634APending Publication Date: 2025-09-17YINWANG INTELLIGENT TECHNOLOGIES CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2025505450
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2022-07-30
Publication Date
2025-09-17

AI Technical Summary

Technical Problem

The network security level of smart vehicle keys is inadequate, leading to potential security risks during generation, distribution, use, and renewal, and existing systems lack end-to-end full-lifecycle security, posing significant economic threats.

Method used

A communication method involving encryption, key credential management, and secure storage processes to enhance network security, including encryption using the smart vehicle key as a key, signature verification, and periodic updates to ensure the integrity and authenticity of smart vehicle keys.

Benefits of technology

Enhances the security of smart vehicle keys by preventing unauthorized access and ensuring end-to-end network security, thereby reducing economic losses and improving user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025530634000001_ABST
    Figure 2025530634000001_ABST
Patent Text Reader

Abstract

The present application provides a communication method and related devices, which are related to the field of smart vehicles. The method includes: determining key credential information based on a smart vehicle key; and transmitting the key credential information to a server. The method provided in the present application can improve network security throughout the entire life cycle of the smart vehicle key.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] TECHNICAL FIELD

[0001] Embodiments of the present application relate to the field of security, and in particular to communication methods and related devices. [Background technology]

[0002]

[0002] With the rapid development of mobile internet, mobile phone applications such as Mobile Manager can integrate mobile phone control functions into vehicle modules to realize intelligent interconnection between mobile phones and vehicles, allowing users to operate their vehicles in a comfortable and convenient way. Smart vehicle keys can not only replace traditional vehicle keys, but also provide functions such as remote mobile phone start, passive entry, and automatic vehicle door opening and closing.

[0003]

[0003] However, the network security level of smart vehicle keys is far from meeting the relevant requirements. Therefore, the network security issue of smart vehicle keys is very important. For example, smart vehicle keys face immeasurable security risks during the generation, distribution, use, and renewal processes. Currently, smart vehicle keys in the industry cannot achieve end-to-end full lifecycle security. Therefore, smart vehicle keys are at risk of being attacked at any weak link, which will cause immeasurable economic losses for users and original equipment manufacturers (OEMs). The network security issue of smart vehicle keys is one of the top three network attacks currently facing smart vehicles. Therefore, to avoid network security issues, it is necessary to ensure the network security of the entire smart vehicle key system in the cloud, mobile phones, and vehicles in an end-to-end manner. The network security levels of the cloud, mobile phones, and vehicles must also be improved to the same high security level. How to ensure end-to-end network security becomes an organizational problem that urgently needs to be solved. Summary of the Invention

[0004]

[0004] Embodiments of the present application provide a communication method and associated devices for providing a method for uploading, distributing, and using smart vehicle keys, thereby enabling improved network security for smart vehicle keys.

[0005] According to a first aspect, an embodiment of the present application provides a communication method applied to a vehicle, the vehicle including a smart vehicle key, the smart vehicle key being electronic key information used to control the vehicle, and the communication method includes: determining key credentials based on the smart vehicle key; and Sending the key credential information to a server.

[0006]

[0006] In the embodiments of the present application, the network security of the smart vehicle key can be improved in the process of uploading the smart vehicle key to the server.

[0007]

[0007] In a possible implementation, the step of determining key credentials based on the smart vehicle key includes: Encrypting the smart vehicle key using the smart vehicle key as a key to obtain key credential information.

[0008]

[0008] In an embodiment of the present application, the smart vehicle key is encrypted by using the smart vehicle key as a key, thereby improving the security of the smart vehicle key.

[0009]

[0009] In a possible implementation, the vehicle further includes vehicle identification information corresponding to the vehicle, and the step of determining key credential information based on the smart vehicle key includes: signing the smart vehicle key and the vehicle identification information by using the first private key to obtain signature data; obtaining a second public key and encrypting the signature data, the smart vehicle key, and the vehicle identification information by using the second public key to obtain a first ciphertext, wherein the second public key is sent by the server to the vehicle; and generating key credential information based on the first ciphertext and a first public key, the first public key corresponding to the first private key;

[0010]

[0010] In an embodiment of the present application, the smart vehicle key and vehicle identification information are signed by using a private key, and the signature data, the smart vehicle key, and the vehicle identification information are encrypted by using a public key, thereby improving the security of the smart vehicle key.

[0011]

[0011] In a possible implementation, the method comprises: The method further includes a step of sending a first certificate to a server, the first certificate including vehicle identification information and a first public key, the first certificate being issued to the vehicle after being signed by a third party, and the first certificate being used to verify the first public key.

[0012]

[0012] In an embodiment of the present application, a first certificate is sent so that the server can verify the identity of the vehicle based on the first certificate, thereby improving security.

[0013] In a possible implementation, the method comprises: The method further includes verifying the second public key based on the second certificate.

[0014]

[0014] In an embodiment of the present application, the second public key is verified by using a second certificate, thereby ensuring that the second public key is sent by the server, preventing another person from tampering with the first public key, and ensuring the security of the encrypted data.

[0015] In a possible implementation, before the step of verifying the second public key based on the second certificate, the method comprises: The method further includes receiving a second certificate sent by the server, the second certificate including the server's identification information and a second public key, and the second certificate being issued to the server after being signed by a third party.

[0016]

[0016] In an embodiment of the present application, a second certificate is received, so that the identity of the server can be verified based on the second certificate, thereby improving security.

[0017]

[0017] In a possible implementation, the vehicle has previously stored a root certificate, which is used to verify the certificate, and after receiving the second certificate sent by the server, the method comprises: The method further includes performing a signature verification on the second certificate based on the root certificate.

[0018]

[0018] In an embodiment of the present application, signature verification is performed on the second certificate by using a root certificate, thereby ensuring the authenticity of the second certificate and preventing the second certificate from being forged.

[0019] In a possible implementation, the second certificate is pre-configured in the vehicle.

[0020]

[0020] In a possible implementation, the first public key and the first private key are generated in a security module of the vehicle.

[0021]

[0021] In an embodiment of the present application, the first public key and the first private key are generated in the vehicle's security module, thereby improving the security of the first public key and the first private key.

[0022]

[0022] In a possible implementation, the smart vehicle key is generated in factory mode for the vehicle.

[0023]

[0023] In the embodiments of the present application, the smart vehicle key is generated in the vehicle's factory mode, which can improve the security of the smart vehicle key.

[0024] In a possible implementation, the method comprises: periodically updating key credential information based on the smart vehicle key; and sending the updated key credential information to the server; Further includes:

[0025]

[0025] In an embodiment of the present application, the smart vehicle key is periodically updated, thereby improving the security of the smart vehicle key.

[0026]

[0026] In a possible implementation, after the step of sending the updated key credential information to the server, the method comprises: Further includes sending a key update prompt to the first electronic device to prompt the user to update the smart vehicle key.

[0027]

[0027] In an embodiment of the present application, the user is reminded to update the smart vehicle key in an active reminder manner, thereby improving the user experience.

[0028] In a possible implementation, the method comprises: receiving a key update request sent by the first electronic device, the key update request being used to request generating a new smart vehicle key; determining new key credentials based on the new smart vehicle key; and sending the new key credential information to the server; Further includes:

[0029]

[0029] In an embodiment of the present application, the smart vehicle key is updated in the manner of a user-initiated request, thereby improving the flexibility of updating the smart vehicle key and also improving the security of the smart vehicle key.

[0030]

[0030] In a possible implementation, the key update request includes the old smart vehicle key, and prior to the step of determining new key credentials based on the new smart vehicle key, the method further comprises: Further comprising the step of performing authentication on the old smart vehicle key.

[0031]

[0031] In an embodiment of the present application, before the smart vehicle key is updated, authentication is performed on the old smart vehicle key to prevent unauthorized users from maliciously stealing the smart vehicle key, thereby improving the security of the smart vehicle key.

[0032] In a possible implementation, the method comprises: The method further includes deleting the old smart vehicle key in the vehicle when successful authentication of the first electronic device's request to use the new smart vehicle key is detected.

[0033]

[0033] In the embodiment of the present application, after the smart vehicle key is successfully updated, the old smart vehicle key is deleted, so as to effectively save the storage resources of the vehicle.

[0034]

[0034] According to a second aspect, an embodiment of the present application further provides a communication method applied to a vehicle, the method comprising: transmitting a random value to the first electronic device; receiving a first control message transmitted by the first electronic device, the first control message being generated based on the smart vehicle key and a random value; and The method includes the step of verifying the first control message based on the smart vehicle key and the random value, and controlling the vehicle based on the first control message if the verification is successful.

[0035]

[0035] In the embodiments of the present application, the network security of the smart vehicle key may be effectively improved in the process of using the key.

[0036] In a possible implementation, the step of verifying the first control message based on the smart vehicle key and the random value includes: generating a second control message based on the smart vehicle key and the random value; and comparing the first control message and the second control message; and if the test is successful, controlling the vehicle based on the first control message includes: If the first control message matches the second control message, controlling the vehicle based on the first control message is included.

[0037]

[0037] In an embodiment of the present application, the integrity of the control message can be verified by performing an integrity check on the control message, thereby improving the network security of the smart vehicle key.

[0038]

[0038] According to a third aspect, an embodiment of the present application further provides a communication method applied to a vehicle, the method comprising: obtaining an operation request sent by the second electronic device, the operation request including a temporary key and a control command; verifying the temporary key; performing a time validity check based on a first validity time zone, the first validity time zone being used to represent a validity time zone of the temporary key, the first validity time zone being stored in a security module of the vehicle; and If the temporary key check is successful and the time validity check is successful, operating the vehicle based on a control command from the second electronic device.

[0039]

[0039] In the embodiments of the present application, the network security of the smart vehicle key may be effectively improved in the process of a user renting a vehicle.

[0040] In a possible implementation, before the step of obtaining the action request sent by the second electronic device, the method comprises: obtaining a vehicle use request, the vehicle use request including a first validity time slot; generating a temporary key based on the first validity period; and The method further includes the step of transmitting the temporary key to the server.

[0041]

[0041] In an embodiment of the present application, a user can efficiently rent a vehicle when the vehicle is connected to a network.

[0042]

[0042] In a possible implementation, the vehicle use request is sent by the first electronic device using a short-range communication method.

[0043]

[0043] In the embodiment of the present application, the first electronic device communicates directly with the vehicle, which can simplify the user's operation and improve the user experience.

[0044]

[0044] In a possible implementation, the vehicle use request is sent by the first electronic device over a mobile network.

[0045]

[0045] In the embodiments of the present application, the user can remotely control the vehicle, so that the user can conveniently control the vehicle.

[0046]

[0046] In a possible implementation, the vehicle use request is sent by a vehicle rental platform.

[0047]

[0047] In an embodiment of the present application, a third party may control the vehicle.

[0048]

[0048] In a possible implementation, the vehicle use request further includes a signed smart vehicle key, and the signed smart vehicle key is obtained by signing the smart vehicle key using the third private key; after obtaining the vehicle use request, the method includes: Further comprising performing signature verification on the smart vehicle key based on a third public key, the third public key being transmitted by the first electronic device to the vehicle.

[0049] In a possible implementation, the method comprises: The method further includes sending a first certificate to the first electronic device, the first certificate including vehicle identification information and a first public key, the first certificate being issued to the vehicle after being signed by a third party, and the first certificate being used to verify the first public key.

[0050] In a possible implementation, the third public key is verified based on a third certificate.

[0051] In a possible implementation, before the step of verifying the third public key based on the third certificate, the method comprises: The method further includes receiving a third certificate sent by the first electronic device, the third certificate including identification information of the first electronic device and a third public key, and the third certificate being issued to the first electronic device after being signed by a third party.

[0052]

[0052] In a possible implementation, the vehicle has previously stored a root certificate, which is used to verify the certificate, and after receiving the third certificate sent by the first electronic device, the method comprises: The method further includes performing a signature verification on the third certificate based on the root certificate.

[0053] In a possible implementation, the first validity time period is encrypted by using the smart vehicle key, and after performing authentication by using the smart vehicle key, the method includes: The method further includes decrypting the encrypted first validity time slot by using the smart vehicle key and performing secure storage for the decrypted first validity time slot.

[0054] In a possible implementation, the method comprises: receiving encrypted data sent by the second electronic device, the encrypted data being obtained by encrypting the temporary credential and the first validity time period with a smart vehicle key, the smart vehicle key being stored in the first electronic device, and the temporary credential being generated by the first electronic device; decrypting the encrypted data using the smart vehicle key to obtain a temporary credential and a first validity time period; validating the temporary credential and the first validity time range; If the verification is successful, generating a temporary key; and The method further includes encrypting a temporary key based on the encrypted data to obtain an encrypted temporary key, and transmitting the encrypted temporary key to the second electronic device.

[0055]

[0055] In an embodiment of the present application, a user can efficiently rent a vehicle when the vehicle is not connected to a network.

[0056] In a possible implementation, after the step of generating the temporary key, the method comprises: Further comprising the step of performing secure storage for the first validity period.

[0057]

[0057] In a possible implementation, a temporary credential is generated based on the smart vehicle key and the first validity time period, and encrypted data is sent by the first electronic device to the server.

[0058]

[0058] In a possible implementation, the operation request includes an encrypted temporary key, and the encrypted temporary key is obtained after being encrypted using the first public key, and before the step of checking the temporary key, the method includes: The method further includes decrypting the encrypted temporary key using the first private key to obtain the temporary key.

[0059] In a possible implementation, the method comprises: The method further includes sending a first certificate to the second electronic device, the first certificate including vehicle identification information and a first public key, the first certificate being issued to the vehicle after being signed by a third party, and the first certificate being used to verify the first public key.

[0060] In a possible implementation, the method comprises: The method further includes verifying a fourth public key based on a fourth certificate, wherein the fourth public key is transmitted by the second electronic device to the vehicle.

[0061] In a possible implementation, before the step of verifying the fourth public key based on the fourth certificate, the method comprises: The method further includes receiving a fourth certificate sent by the second electronic device, the fourth certificate including identification information of the second electronic device and a fourth public key, and the fourth certificate being issued to the second electronic device after being signed by a third party.

[0062]

[0062] In a possible implementation, the vehicle has previously stored a root certificate, which is used to verify the certificate, and after receiving the fourth certificate sent by the second electronic device, the method comprises: The method further includes performing a signature verification on the fourth certificate based on the root certificate.

[0063] In a possible implementation, the step of verifying the temporary key includes: transmitting the random value to a second electronic device; receiving a first control message transmitted by the second electronic device, the first control message being generated based on a temporary key and a random value; and Performing a temporary key check on the first control message based on the temporary key and the random value.

[0064] In a possible implementation, the method comprises: The method further includes sending a key revocation notification to the second electronic device, the key revocation notification indicating that the temporary key is revoked.

[0065]

[0065] In an embodiment of the present application, the user is reminded in an active reminder manner that the temporary key is invalid, thereby preventing the user from misusing the temporary key and improving the user experience.

[0066] In a possible implementation, before the step of sending the key revocation notification to the second electronic device, the method comprises: The method further includes setting the temporary key to be invalid if it is detected that the current system time is beyond the first validity time range.

[0067]

[0067] In a possible implementation, the method comprises: If the time validity check fails, the method further includes the step of notifying the user that the temporary key has expired.

[0068] According to a fourth aspect, an embodiment of the present application further provides a communication method applied to a server, the method comprising: receiving key credentials; and performing secure storage for the key credential information; wherein the secure storage is storage performed by using secure cryptographic means.

[0069]

[0069] In the embodiments of the present application, the network security of the smart vehicle key can be improved in the process of uploading the smart vehicle key to the server.

[0070]

[0070] In a possible implementation, the key credential information includes a first ciphertext and a first public key, and the step of performing secure storage for the key credential information includes: decrypting the first ciphertext by using the second private key to obtain the signature data, the smart vehicle key, and the vehicle identification information; performing signature verification on the signature data by using the first public key; and If the signature verification is successful, performing secure storage for the smart vehicle key and vehicle identification information.

[0071]

[0071] In a possible implementation, the method comprises: obtaining a third public key and encrypting the smart vehicle key by using the third public key to obtain an encrypted smart vehicle key, wherein the third public key is sent by the first electronic device to the server; and The method further includes transmitting the encrypted smart vehicle key to the first electronic device.

[0072]

[0072] In an embodiment of the present application, the smart vehicle key is encrypted using a third public key and then sent to the first electronic device, thereby improving the security of the smart vehicle key.

[0073] In a possible implementation, before the step of transmitting the encrypted smart vehicle key to the first electronic device, the method comprises: receiving a registration request, the registration request including a user account and vehicle identification information corresponding to the user account; and The method further includes creating a user account based on the registration request, the user account corresponding to the smart vehicle key and the vehicle identification information.

[0074]

[0074] In an embodiment of the present application, the user registers with the server, so that the server can perform account verification on the user before sending the smart vehicle key, thereby improving the security of the smart vehicle key.

[0075]

[0075] In a possible implementation, the method further includes: sending a second certificate to the vehicle, the second certificate including the server's identification information and a second public key, the second certificate being issued to the server after being signed by a third party, and the second certificate being used to verify the second public key.

[0076] In a possible implementation, the method comprises: The method includes verifying the first public key based on the first certificate.

[0077]

[0077] In a possible implementation, before the step of verifying the first public key based on the first certificate, the method comprises: The method further includes receiving a first certificate sent by the vehicle, the first certificate including vehicle identification information and a first public key, and the first certificate being issued to the vehicle after being signed by a third party.

[0078]

[0078] In a possible implementation, the server has pre-stored a root certificate, which is used to verify the certificate, and after verifying the first public key based on the first certificate, the method includes: The method further includes performing a signature verification on the first certificate based on the root certificate.

[0079]

[0079] In a possible implementation, the first certificate is pre-configured in the server.

[0080]

[0080] In a possible implementation, the first public key is generated in a security module of the vehicle.

[0081]

[0081] In a possible implementation, the smart vehicle key is generated in factory mode for the vehicle.

[0082]

[0082] In a possible implementation, after the step of receiving key credential information, the method comprises: The method further includes periodically receiving key credential information and periodically updating the key credential information.

[0083]

[0083] In a possible implementation, after the step of periodically receiving key credential information, the method comprises: Further includes sending a key update prompt to the first electronic device to prompt the user to update the smart vehicle key.

[0084]

[0084] In a possible implementation, the method comprises: receiving a credential update instruction, the credential update instruction instructing the key credential to be updated, the credential update instruction including the new key credential; and The step of updating the key credential information based on the credential update instruction is included.

[0085]

[0085] In a possible implementation, the key credential update instruction further includes an old smart vehicle key, where the old smart vehicle key is stored in the server, and the new key credential information includes the new smart vehicle key, and before updating the key credential information based on the credential update instruction, the method includes: Further comprising the step of performing authentication on the old smart vehicle key.

[0086]

[0086] In a possible implementation, the method comprises: The method further includes the step of, if it is detected that authentication regarding the new key credential is successful, storing the new key credential and deleting the old key credential.

[0087] According to a fifth aspect, an embodiment of the present application provides a communication method applied to a server, the method comprising: receiving a key retrieval request sent by the second electronic device, the key retrieval request being used to request obtaining first information, the first information being used to determine a temporary key; and Sending the first information to a second electronic device is included.

[0088]

[0088] In a possible implementation, the first information is a temporary key, and the step of transmitting the first information to the second electronic device includes: The method includes encrypting the temporary key using a fourth public key and sending the encrypted temporary key to the second electronic device, the fourth public key being sent by the second electronic device to the server.

[0089]

[0089] In a possible implementation, the temporary key is transmitted by the vehicle to the server.

[0090]

[0090] In a possible implementation, the first information is encrypted data, and the step of transmitting the first information to the second electronic device includes: The method includes sending an encrypted temporary key to a second electronic device, wherein the encrypted data is obtained by encrypting the temporary credential and the first validity time zone using a smart vehicle key, the smart vehicle key being stored on the first electronic device, the temporary credential being generated by the first electronic device, and the first validity time zone being used to represent the validity time zone of the temporary key.

[0091]

[0091] In a possible implementation, the encrypted data is transmitted by the first electronic device to the server.

[0092]

[0092] In a possible implementation, the key acquisition request includes a temporary account, and the key acquisition request is used to request acquisition of first information corresponding to the temporary account.

[0093] According to a sixth aspect, an embodiment of the present application provides a communication method applied to a first electronic device, the method comprising: receiving a random value transmitted by the vehicle; obtaining a smart vehicle key and generating a first control message based on the smart vehicle key and the random value, the first control message being used to control the vehicle; and The method includes transmitting a first control message to the vehicle.

[0094]

[0094] In the embodiments of the present application, vehicle security can be improved in the process where a user controls a vehicle by using a key.

[0095] In a possible implementation, the first control message is generated in a trusted execution environment (TEE).

[0096]

[0096] In an embodiment of the present application, the first control message is generated in a trusted execution environment TEE, thereby improving the security of the first control message and preventing the first control message from being stolen, thereby improving vehicle security.

[0097] In a possible implementation, the steps for obtaining a smart vehicle key include: receiving an encrypted smart vehicle key sent by the server, the encrypted smart vehicle key being obtained by the server by encrypting the smart vehicle key using a third public key, the third public key being sent to the server by the first electronic device; and Decrypting the encrypted smart vehicle key using the third private key to obtain the smart vehicle key.

[0097]

[0098] In a possible implementation, the third public key and the third private key are generated in a trusted execution environment TEE of the first electronic device.

[0098]

[0099] In an embodiment of the present application, the third public key and the third private key are generated in a trusted execution environment TEE, so that the security of the third public key and the third private key can be improved, the third public key and the third private key can be prevented from being stolen, and vehicle security can be improved.

[0099]

[0100] In a possible implementation, the step of decrypting the encrypted smart vehicle key by using the third private key to obtain the smart vehicle key includes: decrypting the encrypted smart vehicle key by using the third private key in a trusted execution environment TEE of the first electronic device to obtain the smart vehicle key; and After the step of decrypting the encrypted smart vehicle key by using the third private key to obtain the smart vehicle key, the method includes: The method further includes storing the smart vehicle key in a trusted execution environment TEE of the first electronic device.

[0100]

[0101] In an embodiment of the present application, the decryption and storage operations are performed in a trusted execution environment TEE, which can result in improved security of the smart vehicle key.

[0101]

[0102] In a possible implementation, before the step of receiving the encrypted smart vehicle key sent by the server, the method comprises: The method further includes sending a key request to a server, the key request including the user account, the key request being used to obtain a smart vehicle key corresponding to the user account.

[0102]

[0103] In a possible implementation, the method comprises: sending a key update request to the vehicle, the key update request being used to generate a new smart vehicle key; and The method further includes obtaining a new smart vehicle key from the server.

[0103]

[0104] In a possible implementation, after the step of obtaining a new smart vehicle key from the server, the method comprises: performing authentication with respect to the vehicle by using the new smart vehicle key; and If the authentication is successful, deleting the old smart vehicle key in the first electronic device.

[0104]

[0105] According to a seventh aspect, an embodiment of the present application provides a communication method applied to a first electronic device, the method comprising: Transmitting second information in response to the detected vehicle utilization activity of the user, the second information being used to determine a temporary key.

[0105]

[0106] In a possible implementation, the step of transmitting the second information in response to the detected vehicle use behavior of the user includes: The method includes transmitting a vehicle utilization request to the vehicle in response to the detected vehicle utilization action of the user, the vehicle utilization request including the first validity time period.

[0106]

[0107] In a possible implementation, the first validity time period is encrypted using the smart vehicle key.

[0107]

[0108] In a possible implementation, the vehicle access request further includes a smart vehicle key.

[0108]

[0109] In a possible implementation, the step of transmitting the second information in response to the detected vehicle use behavior of the user includes: generating a temporary credential based on the smart vehicle key and the first validity time period in response to the detected vehicle usage activity of the user; and Encrypting the temporary credential and the first validity time period using the smart vehicle key and sending the encrypted data to a server.

[0109]

[0110] According to an eighth aspect, an embodiment of the present application provides a communication method applied to a second electronic device, the method comprising: sending a key retrieval request to a server, the key retrieval request being used to request retrieval of first information, the first information being used to determine a temporary key; receiving the first information sent by the server; and The method includes sending an operation request to the vehicle based on the first information, the operation request including the temporary key and a control command, the control command being used to operate the vehicle.

[0110]

[0111] In a possible implementation, the first information is an encrypted temporary key, and the encrypted temporary key is obtained by encrypting the temporary key using the fourth public key, and after receiving the first information sent by the server, the method includes: The method further includes decrypting the encrypted temporary key using the fourth private key to obtain the temporary key.

[0111]

[0112] In a possible implementation, the first information is encrypted data, the encrypted data is obtained by encrypting a temporary credential and a first validity time zone using a smart vehicle key, the smart vehicle key is stored on the first electronic device, the temporary credential is generated by the first electronic device, and the first validity time zone is used to represent a validity time zone of the temporary key.

[0112]

[0113] In a possible implementation, the method comprises: The method further includes receiving a key revocation notification, the key revocation notification indicating that the temporary key is revoked.

[0113]

[0114] In a possible implementation, the key retrieval request further includes a temporary account, and the key retrieval request is used to request retrieval of first information corresponding to the temporary account.

[0114]

[0115] According to a ninth aspect, an embodiment of the present application provides a communication method applied to a vehicle rental platform, the method comprising: obtaining a first valid time slot; Retrieving a smart vehicle key from a server; and Encrypting the first validity time period using the smart vehicle key as a key and transmitting the encrypted first validity time period to the vehicle.

[0115]

[0116] In embodiments of the present application, an expiration time can be set for the smart vehicle key, allowing users to efficiently rent a vehicle.

[0116]

[0117] In a possible implementation, the method comprises: requesting a temporary account from the server, the temporary account corresponding to the temporary key; and The method further includes transmitting the temporary account to the second electronic device.

[0117]

[0118] In a possible implementation, the method comprises: The method further includes sending a key revocation notification, the key revocation notification indicating that the temporary key is revoked.

[0118]

[0119] In an embodiment of the present application, the notification may indicate that the temporary vehicle rental key is invalid, so that rental termination can be completed in special scenarios, such as early rental termination scenarios, improving rental termination efficiency.

[0119]

[0120] According to a tenth aspect, an embodiment of the present application provides a communication device including one or more functional modules, wherein the one or more functional modules are configured to perform a communication method according to any one of the first to third aspects.

[0120]

[0121] According to an eleventh aspect, an embodiment of the present application further provides a communication device including one or more functional modules, wherein the one or more functional modules are configured to perform a communication method according to the fourth or fifth aspect.

[0121]

[0122] According to a twelfth aspect, an embodiment of the present application further provides a communication device including one or more functional modules, wherein the one or more functional modules are configured to perform a communication method according to the sixth aspect or the seventh aspect.

[0122]

[0123] According to a thirteenth aspect, an embodiment of the present application further provides a communication device including one or more functional modules, wherein the one or more functional modules are configured to perform the communication method according to the eighth aspect.

[0123]

[0124] According to a fourteenth aspect, an embodiment of the present application further provides a communication device including one or more functional modules, wherein the one or more functional modules are configured to perform the communication method according to the ninth aspect.

[0124]

[0125] According to a fifteenth aspect, an embodiment of the present application provides a vehicle including a processor and a memory, wherein the memory is configured to store a computer program, and wherein the processor is configured to execute the computer program to perform a communication method according to any one of the first to third aspects.

[0125]

[0126] According to a sixteenth aspect, an embodiment of the present application provides a server including a processor and a memory, wherein the memory is configured to store a computer program, and wherein the processor is configured to execute the computer program to perform a communication method according to the fourth or fifth aspect.

[0126]

[0127] According to a seventeenth aspect, an embodiment of the present application provides a first electronic device including a processor and a memory, wherein the memory is configured to store a computer program, and wherein the processor is configured to execute the computer program to perform a communication method according to the sixth or seventh aspect.

[0127]

[0128] According to an eighteenth aspect, an embodiment of the present application provides a second electronic device comprising a processor and a memory, wherein the memory is configured to store a computer program, and wherein the processor is configured to execute the computer program to perform the communication method according to the eighth aspect.

[0128]

[0129] According to a nineteenth aspect, an embodiment of the present application provides a vehicle rental platform comprising a processor and a memory, wherein the memory is configured to store a computer program, and wherein the processor is configured to execute the computer program to perform the communication method according to the ninth aspect.

[0129]

[0130] According to a twentieth aspect, an embodiment of the present application provides a computer-readable storage medium storing a computer program that, when executed on a computer, enables the computer to perform a communication method according to any one of the first to ninth aspects.

[0130]

[0131] According to a 21st aspect, there is provided a communication system including the vehicle provided in the 15th aspect, the server provided in the 16th aspect, and the first electronic device provided in the 17th aspect. [Brief explanation of the drawings]

[0131] [Figure 1]

[0132] FIG. 1 is a schematic diagram of the hardware structure of an electronic device according to an embodiment of the present application. [Figure 2]

[0133] FIG. 2 is a schematic diagram of the hardware structure of a server according to an embodiment of the present application. [Figure 3]

[0134] FIG. 3 is a schematic diagram of a hardware structure of a vehicle according to an embodiment of the present application. [Figure 4]

[0135] Figure 4 is a schematic diagram of the architecture of an application scenario according to an embodiment of the present application. [Figure 5]

[0136] FIG. 5 is a schematic flow chart of an embodiment of a communication method according to the present application. [Figure 6]

[0137] FIG. 6 is a schematic flow chart of another embodiment of a communication method according to the present application. [Figure 7]

[0138] FIG. 7 is a schematic flow chart of yet another embodiment of a communication method according to the present application. [Figure 8]

[0139] FIG. 8 is a schematic flow chart of yet another embodiment of a communication method according to the present application. [Figure 9]

[0140] FIG. 9 is a schematic flow chart of yet another embodiment of a communication method according to the present application. [Figure 10]

[0141] FIG. 10 is a schematic flow chart of yet another embodiment of a communication method according to the present application. [Figure 11]

[0142] FIG. 11 is a schematic flow chart of yet another embodiment of a communication method according to the present application. [Figure 12]

[0143] FIG. 12 is a schematic diagram of the structure of an embodiment of a communication device according to the present application. [Figure 13]

[0144] FIG. 13 is a schematic diagram of the structure of another embodiment of a communication device according to the present application. [Figure 14]

[0145] FIG. 14 is a schematic diagram of the structure of yet another embodiment of a communication device according to the present application. [Figure 15]

[0146] FIG. 15 is a schematic diagram of the structure of yet another embodiment of a communication device according to the present application. [Figure 16]

[0147] FIG. 16 is a schematic diagram of the structure of yet another embodiment of a communication device according to the present application. [Figure 17]

[0148] FIG. 17 is a schematic diagram of the structure of yet another embodiment of a communication device according to the present application. [Figure 18]

[0149] FIG. 18 is a schematic diagram of the structure of yet another embodiment of a communication device according to the present application. [Figure 19]

[0150] FIG. 19 is a schematic diagram of the structure of yet another embodiment of a communication device according to the present application. [Figure 20]

[0151] FIG. 20 is a schematic diagram of the structure of yet another embodiment of a communication device according to the present application. DETAILED DESCRIPTION OF THE INVENTION

[0132]

[0152] Hereinafter, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application. In the description of the embodiments of the present application, " / " means "or" unless otherwise specified. For example, A / B may represent A or B. In the present specification, "and / or" only describes a relationship of association to describe related objects, and represents that three relationships may exist. For example, A and / or B may represent the following three cases: only A exists, both A and B exist, and only B exists.

[0133]

[0153] The terms "first" and "second" referred to below are intended solely for descriptive purposes and shall not be understood as an indication or implication of relative importance or an implicit indication of the number of specified technical features. Thus, a feature qualified by "first" or "second" may explicitly or implicitly include one or more features. In the description of embodiments of this application, unless otherwise specified, "plurality" means two or more.

[0134]

[0154] With the rapid development of mobile internet, mobile phone applications such as Mobile Manager can integrate mobile phone control functions into vehicle modules to realize intelligent interconnection between mobile phones and vehicles, allowing users to operate their vehicles in a comfortable and convenient way.Smart vehicle keys can not only replace traditional vehicle keys, but also provide functions such as remote mobile phone start, passive entry, and automatic vehicle door opening and closing.

[0135]

[0155] However, the network security level of smart vehicle keys is far from meeting the relevant requirements. Therefore, the network security issue of smart vehicle keys is very important. For example, smart vehicle keys face immeasurable security risks during the generation, distribution, use, and renewal processes. Currently, smart vehicle keys in the industry cannot achieve end-to-end full-lifecycle security. Therefore, smart vehicle keys are at risk of being attacked at any weak link, which will cause immeasurable economic losses for users and OEMs. The network security issue of smart vehicle keys is one of the top three network attacks in current smart vehicles. Therefore, to avoid network security issues, it is necessary to ensure the network security of the entire smart vehicle key system in the cloud, mobile phone, and vehicle in an end-to-end manner. The network security level of the cloud, mobile phone, and vehicle must also be improved to a similarly high security level. How to ensure end-to-end network security is an organizational issue that needs to be resolved urgently.

[0136]

[0156] Based on the above problems, the embodiments of the present application provide a communication method applied to an electronic device 100, a server 200, and a vehicle 300. The electronic device 100 may be a mobile terminal having a display. The mobile terminal may alternatively be referred to as a terminal device, user equipment (UE), access terminal, subscriber unit, subscriber station, mobile station, mobile console, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user equipment. Alternatively, the mobile terminal may be a wearable device such as a smart watch or smart band. The specific form of the electronic device 100 that executes the technical solution is not particularly limited in the embodiments of the present application. The server 200 may be a physical server or a virtual cloud server. The specific form of the server 200 that executes the technical solution is not particularly limited in the embodiments of the present application. The vehicle 300 may be a smart vehicle that uses a smart key system.

[0137]

[0157] Hereinafter, an example of an electronic device provided in the following embodiments of the present application will be described first with reference to Figure 1. Figure 1 is a schematic diagram of the structure of an electronic device 100.

[0138]

[0158] The electronic device 100 may include a processor 110, an antenna 1, an antenna 2, a mobile communication module 120, and a wireless communication module 130.

[0139]

[0159] It can be understood that the structure shown in this embodiment of the present invention does not constitute a specific limitation on the electronic device 100. In some other embodiments of the present application, the electronic device 100 may include more or fewer components than those shown in the drawings, or some components may be combined, or some components may be separated, or a different arrangement of components may be used. The components shown in the drawings may be implemented using hardware, software, or a combination of software and hardware.

[0140]

[0160] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, a neural-network processing unit (NPU), and / or the like. The different processing units may be separate components or may be integrated into one or more processors.

[0141]

[0161] The controller may generate an operation control signal according to the instruction operation code and the time series signal to complete the control of instruction fetching and instruction execution.

[0142]

[0162] Memory may also be located in processor 110 and configured to store instructions and data. In some embodiments, the memory in processor 110 is cache memory. The memory may store instructions or data that are only used or are used cyclically by processor 110. When processor 110 needs to use the instructions or data again, processor 110 can retrieve the instructions or data directly from memory. This avoids repeated accesses, reduces latency for processor 110, and improves system efficiency.

[0143]

[0163] The wireless communication functionality of the electronic device 100 may be implemented by using an antenna 1, an antenna 2, a mobile communication module 120, a wireless communication module 130, a modem processor, a baseband processor, and the like.

[0144]

[0164] Antenna 1 and Antenna 2 are configured to transmit and receive electromagnetic signals. Each antenna in electronic device 100 may be configured to cover one or more communication frequency bands. Different antennas may be further multiplexed to improve antenna utilization. For example, Antenna 1 may be multiplexed as a diversity antenna for a wireless local area network. In some other embodiments, antennas may be used in combination with tuning switches.

[0145]

[0165] Mobile communication module 120 can provide wireless communication solutions, including 2G / 3G / 4G / 5G, for application to electronic device 100. Mobile communication module 120 may include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. Mobile communication module 120 can receive electromagnetic waves via antenna 1, perform processing, such as filtering or amplification, on the received electromagnetic waves, and send the electromagnetic waves to a modem processor for demodulation. Mobile communication module 120 can further amplify signals modulated by the modem processor and convert the signals to electromagnetic waves for emission via antenna 1. In some embodiments, at least some functional modules of mobile communication module 120 may be located within processor 110. In some embodiments, at least some functional modules of mobile communication module 120 may be located in the same device as at least some modules of processor 110.

[0146]

[0166] The modem processor may include a modulator and a demodulator. The modulator is configured to modulate a low-frequency baseband signal to be transmitted into a medium- to high-frequency signal. The demodulator is configured to demodulate a received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then sends the low-frequency baseband signal obtained through demodulation to the baseband processor for processing. The low-frequency baseband signal is processed by the baseband processor and then sent to the application processor. In some embodiments, the modem processor may be a separate component. In other embodiments, the modem processor may be separate from the processor 110 and located within the same device as the mobile communication module 120 or another functional module.

[0147]

[0167] The wireless communication module 130 can provide wireless communication solutions applied to the electronic device 100, including wireless local area networks (WLANs) (e.g., wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite systems (GNSS), frequency modulation (FM), near field communication (NFC) technology, infrared (IR) technology, etc. The wireless communication module 130 can be one or more components integrating at least one communication processing module. The wireless communication module 130 receives electromagnetic waves via the antenna 2, performs frequency modulation and filtering on the electromagnetic wave signals, and sends the processed signals to the processor 110. The wireless communication module 130 can also receive signals to be transmitted from the processor 110, perform frequency modulation and amplification on the signals, and convert the signals into electromagnetic waves for emission via the antenna 2.

[0148]

[0168] In some embodiments, antenna 1 and mobile communication module 120 in electronic device 100 are coupled, and antenna 2 and wireless communication module 130 in electronic device 100 are coupled, such that electronic device 100 can communicate with a network or another device using a wireless communication technology. The wireless communication technology may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), new radio (NR), BT, GNSS, WLAN, NFC, FM, IR technology, and / or the like. GNSS may include the global positioning system (GPS), the global navigation satellite system (GLONASS), the BeiDou navigation satellite system (BDS), the quasi-zenith satellite system (QZSS), and / or satellite-based augmentation systems (SBAS).

[0149]

[0169] Next, an example of a server provided in the following embodiments of the present application will be described with reference to Fig. 2. Fig. 2 is a schematic diagram of the structure of a server 200. The server 200 may include at least one processor and at least one memory communicatively connected to the processor. The memory stores program instructions executable by the processor, and the processor can call the program instructions to perform operations in the methods provided in the embodiments of the present application.

[0150]

[0170] 2, server 200 may be embodied in the form of a general-purpose computing device. Components of server 200 may include, but are not limited to: one or more processors 210, memory 220, a communication bus 240, and a communication interface 230, which couple to various system components (including memory 220 and processor 210).

[0151]

[0171] Communication bus 240 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of multiple bus structures.

[0152]

[0172] Memory 220 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) and / or cache memory.

[0153]

[0173] A program / utility tool including a set of program modules (at least one) may be stored in memory 220. Such program modules include, but are not limited to, an operating system, one or more applications, other program modules, and program data. Each or a combination of these examples may include implementation in a network environment. The program modules typically perform the functions and / or methods in the embodiments described in this application.

[0154]

[0174] Server 200 may also communicate with one or more external devices (e.g., a keyboard, a pointing device, and a display), may further communicate with one or more devices that allow a user to interact with server 200, and / or may communicate with any device (e.g., a network interface card or a modem) that allows server 200 to communicate with one or more other computing devices. Such communication may be performed via communication interface 230. Furthermore, server 200 may further communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network such as the Internet) by using a network adapter (not shown in FIG. 2 ). The network adapter may communicate with other modules of the electronic device via communication bus 240. Although not shown in FIG. 2, it can be understood that other hardware and / or software modules may be used in combination with server 200, including, but not limited to, microcode, device drives, redundant processing units, external disk drive arrays, redundant arrays of independent drives (RAID) systems, tape drives, and data backup storage systems.

[0155]

[0175] Next, an example of a vehicle provided in the following embodiments of the present application will be described with reference to Fig. 3. Fig. 3 is a schematic diagram of the configuration of a vehicle 300. The vehicle 300 may include at least one processor 310, a mobile communication module 320, a wireless communication module 330, and at least one memory 340 communicatively connected to the processor. The memory stores program instructions executable by the processor, and the processor can call the program instructions to perform operations in the methods provided in the embodiments of the present application.

[0156]

[0176] The memory 340 stores program instructions that can be executed by the processor 310, and the processor 310 can invoke the program instructions to perform operations in the methods provided in the embodiments of the present application.

[0157]

[0177] The mobile communication module 320 can provide wireless communication solutions applied to the vehicle 300, including 2G / 3G / 4G / 5G. For a specific implementation of the mobile communication module 320, please refer to the mobile communication module 120 in FIG. 1 . Details will not be described again here. Communication between the electronic device 100 and the server 200 may be implemented via the mobile communication module 320. For example, the electronic device 100 can communicate with a base station via the mobile communication module 320, access the Internet via the base station, and communicate with the server 200.

[0158]

[0178] The wireless communication module 330 can provide wireless communication solutions applied to the electronic device 100, including WLAN (e.g., Wi-Fi), BT, GNSS, FM, NFC, and IR. For a specific implementation of the wireless communication module 330, please refer to the wireless communication module 130 in FIG. 1 . Details will not be described again here. Communication between the electronic device 100 and the vehicle 300 may be implemented via the wireless communication module 330. For example, the electronic device 100 can communicate with the vehicle 300 via BT.

[0159]

[0179] FIG. 4 is a schematic diagram of an architecture of an application scenario according to an embodiment of the present application. As shown in FIG. 4, the application scenario may include an electronic device 100, a server 200, and a vehicle 300. The electronic device 100 may be a terminal device such as a mobile phone or a tablet. An application may be installed on the electronic device. For example, the application may be a smart vehicle key application. The smart vehicle key application may be used to request a smart key server in the server 200 to generate, update, revoke, and authorize a smart vehicle key. The smart vehicle key is electronic key information used to control a vehicle. The smart vehicle key may be an electronic key used to unlock the vehicle or perform other vehicle control operations, and may establish a wireless channel, such as a Bluetooth channel, with a vehicle-mounted short-range controller in the vehicle 300, so that vehicle control commands can be transmitted to the vehicle-mounted short-range controller. It can be understood that this embodiment of the present application merely illustrates an example of a Bluetooth wireless communication method and does not constitute a limitation on the embodiment of the present application. In some embodiments, other wireless communication methods may be used instead.

[0160]

[0180] The server 200 may be a single computer or a computer cluster. The form of the server 200 is not particularly limited in the embodiments of the present application. The server 200 may include a smart key server. The smart key server may be configured to receive requests, such as a smart vehicle key request, sent by an application (e.g., a smart vehicle key application) in the electronic device 100 and complete operations, such as generating, updating, revoking, and authorizing the smart vehicle key for a user. It may be understood that the smart key server may be further configured to receive the smart vehicle key sent by the onboard short-range controller in the smart vehicle 300 and perform secure storage of the smart vehicle key by using a Key Management Service (KMS) module. Optionally, the server 200 may further include a Public Key Infrastructure (PKI) server, which may be configured to issue certificates to the smart key server and the onboard short-range controller. The certificates may be used to establish a secure transmission channel at the Transport Layer Security (TLS) layer, thereby ensuring secure transmission of the smart vehicle key.

[0161]

[0181] The vehicle 300 may include an on-board short-range controller. The on-board short-range controller may be responsible for broadcasting a radio frequency signal, such as Bluetooth, of the vehicle 300 and for authenticating the smart vehicle key. The on-board short-range controller may further cooperate with a Passive Entry Passive Start (PEPS) system and a Body Control Module (BCM) to control the vehicle's doors and windows. The smart vehicle key may be generated and stored by a security module (Secure Element (SE)), thereby ensuring the security of the smart vehicle key.

[0162]

[0182] In a possible implementation, the smart vehicle key is generated only in the vehicle 300. For example, the smart vehicle key may be generated by the OEM during vehicle assembly, or the smart vehicle key may be generated in a factory mode. After the smart vehicle key is generated in the vehicle 300, it may be stored, for example, in a Hardware Security Module (HSM) or an SE chip. The plaintext of the smart vehicle key is kept in the security module, so that the smart vehicle key cannot be obtained externally, ensuring the security of the smart vehicle key. The electronic device 100 may store the smart vehicle key by using a Trusted Execution Environment (TEE), and the smart vehicle key is kept in the TEE. The server 300 stores the smart vehicle key using a KMS. With the above three parties (such as the electronic device 100, the smart vehicle 200, and the server 300) using secure storage of the smart vehicle key, it is possible to ultimately ensure that the smart vehicle key cannot be obtained by an attacker at any point during use, transmission, storage, etc., and it is possible to ensure the end-to-end security of the smart vehicle key.

[0163]

[0183] Optionally, the smart vehicle key can be encrypted via an encrypted channel to ensure confidentiality on the server side, vehicle side, and terminal side. This also prevents leakage of the smart vehicle key in the vehicle and terminal, and ensures that the plaintext of the smart vehicle key is kept within the security module. The smart vehicle key may be encrypted using a public key in the security module, which further improves the security of the smart vehicle key.

[0164]

[0184] Referring to FIG. 5, a communication method provided in an embodiment of the present application will be described.

[0165]

[0185] 5 is a schematic flowchart of an embodiment of a communication method according to the present application. The communication method is applied to a vehicle 300 and includes the following steps:

[0166]

[0186] Step 501: The vehicle-mounted short-range controller generates a public-private key pair.

[0167]

[0187] Specifically, the onboard short-range controller may generate a public-private key pair in a security module, and if the public-private key pair is generated in the security module, vehicle security may be significantly improved. The public-private key pair generated in the onboard short-range controller may be generated by an asymmetric encryption algorithm. For example, the public-private key pair may include a public key and a private key. For ease of explanation, the public key generated in the onboard short-range controller will be referred to as a "first public key," and the private key generated in the onboard short-range controller will be referred to as a "first private key."

[0168]

[0188] Preferably, to further improve security and prevent another person from forging the public key, the vehicle identity identification information and the first public key may be sent together to a third party, such as an authoritative certificate authority. The vehicle identity identification information may be information used to identify the identity of the vehicle. The vehicle identity identification information may be a Vehicle Identification Number (VIN), which may also be referred to as a vehicle frame number. In a specific implementation, the vehicle identity identification information may alternatively be replaced by a license plate number or other information used to represent the identity of the vehicle. The specific form of the information used to identify the vehicle is not particularly limited in the embodiments of the present application. After verifying the vehicle identity identification information, the third party may issue a digital certificate to the vehicle corresponding to the vehicle identity identification information. The digital certificate is obtained by the third party through a signature using the third party's private key. The first certificate includes the vehicle identification information and the first public key, and is used to verify that the generator of the first public key is the vehicle corresponding to the vehicle identification information. After obtaining the digital certificate, the vehicle-mounted short-range controller may send the digital certificate to the smart key server. For ease of explanation, the digital certificate in the vehicle-mounted short-range controller may be referred to as the first certificate.

[0169]

[0189] To prevent the first certificate from being forged, the in-vehicle short-range controller may further store a root certificate in advance. The root certificate may be issued in advance by a third party that issues the first certificate, and the root certificate includes a public key of the third party and information about the third party. Since the first certificate is signed by the third party using its private key, the first certificate can be verified by using the public key of the third party in the root certificate, thereby ensuring that the first certificate is sent by the third party.

[0170]

[0190] Step 502: The vehicle-mounted short-range controller obtains a smart vehicle key and signs the smart vehicle key and vehicle identification information by using the first private key.

[0171]

[0191] In a possible implementation, the smart vehicle key may be generated by the OEM in factory mode.

[0172]

[0192] The vehicle-mounted short-range controller may sign the smart vehicle key and the vehicle identification information by using the first private key generated in step 501 to obtain signature data, and the signature data may include the signed smart vehicle key and the signed vehicle identification information. The signed smart vehicle key is the signature information obtained by signing the smart vehicle key, and the signed vehicle identification information is the signature information obtained by signing the vehicle identification information. In a possible implementation, the signature data may be data obtained by signing a file including the smart vehicle key and the vehicle identification information.

[0173]

[0193] In a possible implementation, the specific process of signing the smart vehicle key and the vehicle identification information using the first private key may be: calculating a hash value for the smart vehicle key and the vehicle identification information according to a hash algorithm, where the hash algorithm may be preset. For example, the hash algorithm may be any one of SHA-1, SHA-224, SHA-256, SHA-384, and SHA-512, or another type of hash algorithm, which is not particularly limited in the embodiments of the present application. Then, the hash value may be signed to obtain signature data.

[0174]

[0194] Step 503: The vehicle-mounted short-range controller encrypts the signature data, the smart vehicle key, and the vehicle identification information by using the public key of the smart key server to obtain a first ciphertext.

[0175]

[0195] Specifically, the smart key server may generate a public-private key pair, and the public-private key pair generated in the smart key server may be generated according to an asymmetric encryption algorithm. It can be understood that the asymmetric encryption algorithm used by the vehicle-mounted short-range controller to generate the public-private key pair may be the same as or different from the asymmetric encryption algorithm used by the smart key server to generate the public-private key pair. The asymmetric encryption algorithm used is not particularly limited in the embodiments of the present application. For ease of explanation, the public key generated in the smart key server is referred to as a "second public key," and the private key generated in the smart key server is referred to as a "second private key."

[0176]

[0196] Preferably, to prevent the second public key from being forged, the smart key server can alternatively apply for a digital certificate. For ease of explanation, the digital certificate in the server is referred to as the second certificate in this specification. The second certificate may include the smart key server's identification information and the second public key. For specific methods for obtaining the second certificate, please refer to the method for obtaining the first certificate. Details will not be described again here. After the second certificate is obtained, it may be sent to the vehicle-mounted short-range controller, so that the generator of the second public key can be verified as the smart key server, improving security.

[0177]

[0197] Alternatively, to prevent the second certificate from being forged, the smart key server may pre-store the root certificate. For the method of obtaining the root certificate of the smart key server, please refer to the method of obtaining the root certificate of the vehicle-mounted short-range controller. The details will not be described again here.

[0178]

[0198] It should be noted that after generating the second public key, the smart key server may transmit the second public key to the vehicle-mounted short-range controller. Similarly, after generating the first public key, the vehicle-mounted short-range controller may alternatively transmit the first public key to the smart key server.

[0179]

[0199] The vehicle-mounted short-range controller then encrypts the signature data, the smart vehicle key, and the vehicle identification information by using the second public key to obtain a first ciphertext. In a possible implementation, the first ciphertext may include the encrypted signature data, the encrypted smart vehicle key, and the encrypted vehicle identification information. In a possible implementation, the first ciphertext includes the encrypted signature data, the smart vehicle key, and the vehicle identification information.

[0180]

[0200] Step 504: The vehicle-mounted short-range controller sends the key credential information to the smart key server, which in turn receives the key credential information.

[0181]

[0201] Specifically, the vehicle-mounted short-range controller can transmit key credential information to the smart key server, thereby completing the upload of the smart vehicle key to the server. The key credential information may be obtained by encrypting the smart vehicle key using the smart vehicle key as a key. Alternatively, the key credential information may include a first ciphertext and a first public key. The smart vehicle key is signed and / or encrypted before the upload process, thereby ensuring the security of the smart vehicle key and the tamper-proofness of the transmitted encrypted signature data.

[0182]

[0202] Step 505: The smart key server decrypts the first ciphertext using the second private key.

[0183]

[0203] Specifically, after receiving the first ciphertext, the smart key server may decrypt the first ciphertext by using the second private key to obtain signature data, a smart vehicle key, and vehicle identification information, where the signature data may include the signed smart vehicle key and the signed vehicle identification information.

[0184]

[0204] Step 506: The smart key server verifies the signature of the smart vehicle key and the vehicle identity by using the first public key.

[0185]

[0205] Specifically, after obtaining the signature data, the smart key server may perform signature verification on the signature data by using the first public key. In other words, the signature verification may be used to verify whether the smart vehicle key and vehicle identification information were generated by the owner of the first public key (or first private key). If the signature verification is successful, step 507 may be further executed. If the signature verification is unsuccessful, the smart vehicle key and vehicle identification information may be discarded, and the process may be terminated.

[0186]

[0206] A specific manner of performing signature verification by using the first public key may be: performing a verification operation on the signature data by using the first public key to obtain a first hash value; then performing a hash operation based on the smart vehicle key and vehicle identification information obtained through decryption in step 505 to obtain a second hash value; the first hash value is compared with the second hash value; if the first hash value matches the second hash value, it may be determined that the signature verification is successful; if the first hash value does not match the second hash value, it may be determined that the signature verification is unsuccessful.

[0187]

[0207] Preferably, if the smart key server receives the first certificate sent by the vehicle-mounted short-range controller before receiving the encrypted signature data, the smart key server may further verify the first public key based on the first certificate to ensure that the first public key is sent by the vehicle-mounted short-range controller, which can prevent others from forging the first public key and can ensure that the smart vehicle key and vehicle identification information are sent by the vehicle-mounted short-range controller, thereby improving security.

[0188]

[0208] To prevent the first certificate from being forged or tampered with, the smart key server may verify the first certificate by using a pre-stored root certificate. Because the first certificate is signed by a third party using a private key, the first certificate may be verified by using the root certificate to ensure that the first certificate has not been tampered with.

[0189]

[0209] Step 507: The smart key server stores the smart vehicle key and vehicle identification information.

[0190]

[0210] Specifically, the smart key server may use the KMS to securely store the smart vehicle key and the vehicle identification information corresponding to the smart vehicle key. In other words, the smart vehicle key and the vehicle identification information may be bound and stored. In this way, the onboard short-range controller can upload the smart vehicle key to the server. Because the second private key is owned only by the smart key server, the encrypted signature data obtained through encryption using the second public key can only be decrypted by the smart key server, thereby ensuring the security of the encrypted smart vehicle key. Furthermore, because the first private key is owned only by the onboard short-range controller, signature verification is performed on the smart vehicle key using the first public key, thereby ensuring the authenticity of the signature of the smart vehicle key.

[0191]

[0211] It can be understood that the above-described embodiment merely illustrates an example scenario in which an onboard short-range controller uploads a smart vehicle key and does not constitute a limitation on the embodiments of the present application. The above-described embodiment can also be applied to a scenario in which a smart vehicle key is updated. For example, the vehicle 300 may actively update key credential information via the onboard short-range controller, upload the updated key credential information to a smart key server, and remind the user after the key credential information is updated. For example, the vehicle 300 may send a key update prompt to the user's electronic device to prompt the user to update the smart vehicle key. In a possible implementation, the vehicle 300 may alternatively passively update key credential information via the onboard short-range controller and upload the updated key credential information to the smart key server. For example, the user may send a key update request to the vehicle 300 by using an electronic device, and the key update request may be used to request the generation of a new smart vehicle key. The vehicle 300 may generate a new smart vehicle key based on the key update request and may determine new key credential information based on the new smart vehicle key. Alternatively, the smart key server may request the vehicle 300 to update its key credential information. This ensures that the vehicle owner or another user can trigger the vehicle to update its smart vehicle key in a timely manner if the smart key is lost or compromised. Correspondingly, the smart key server may periodically receive and periodically update the key credential information. Additionally, the smart key server may alternatively send a key update prompt to the user's electronic device to prompt the user to update the smart vehicle key.

[0192]

[0212] In an embodiment of the present application, the smart vehicle key is generated only in the vehicle and stored in the security module, and transmission outside the security module is encrypted, making it impossible to obtain the smart vehicle key externally, thereby ensuring the security of the vehicle.

[0193]

[0213] The generation and uploading of smart vehicle keys has been described above as an example with reference to Figure 5. Next, with reference to Figure 6, a key distribution scenario provided in an embodiment of the present application will be described.

[0194]

[0214] 6 is a schematic flowchart of another embodiment of a communication method according to the present application. The communication method includes the following steps:

[0195]

[0215] Step 601: A user logs into a smart key server.

[0196]

[0216] Specifically, a user can log in to the smart key server by using a pre-registered account. The pre-registered account may be bound to a vehicle identification. For example, a user can pre-register an account on the smart key server by using an application (such as a smart vehicle key application), and the account may be bound to the vehicle identification entered by the user. After the user is successfully registered, the smart key server assigns the user a registration account in the system, and the registration account is bound to the vehicle identification. It can be understood that the smart key server pre-stores the smart vehicle key and the vehicle identification corresponding to the smart vehicle key in the system. Based on the account registered by the user, the smart key server can assign the smart vehicle key corresponding to the account to the user.

[0197]

[0217] Step 602: The application generates a public-private key pair and sends the public key to the smart key server.

[0198]

[0218] Specifically, the application may generate a public-private key pair in the TEE, and vehicle security can be improved if the public-private key pair is generated in the TEE. For ease of explanation, the public key generated by the application is referred to as the "third public key" and the private key generated by the application is referred to as the "third private key."

[0199]

[0219] The application may then send the third public key to the smart key server.

[0200]

[0220] Step 603: The smart vehicle key server obtains the smart vehicle key, and encrypts the smart vehicle key by using the third public key to obtain an encrypted smart vehicle key.

[0201]

[0221] Specifically, after a user logs in to the smart key server using an account, the smart key server can obtain the vehicle identification information corresponding to the account based on the account logged in by the user, and then obtain the smart vehicle key corresponding to the vehicle identification information based on the vehicle identification information.

[0202]

[0222] The smart key server can then encrypt the smart vehicle key by using the third public key sent by the application to obtain an encrypted smart vehicle key, where the encrypted smart vehicle key is an encrypted key obtained by encrypting the smart vehicle key.

[0203]

[0223] Step 604: The smart key server sends the encrypted smart vehicle key to the application.

[0204]

[0224] Step 605: The application decrypts the encrypted smart vehicle key and stores the smart vehicle key obtained by decryption.

[0205]

[0225] Specifically, after receiving the encrypted smart vehicle key sent by the smart key server, the application can decrypt the encrypted smart vehicle key in the TEE by using the third private key to obtain the smart vehicle key.

[0206]

[0226] The application may then store the smart vehicle key obtained by decryption in the TEE, and security can be improved when the smart vehicle key is stored in the TEE. Because the third private key is owned only by the application, only the application can decrypt the encrypted smart vehicle key obtained after being encrypted by using the third public key, so that the security of the smart vehicle key in the distribution process can be guaranteed.

[0207]

[0227] In some optional embodiments, a user may alternatively actively request a smart vehicle key. For example, a user may perform an operation on an application to send a key request to a smart key server, the key request including a user account, and the key request is used to obtain a smart vehicle key corresponding to the user account. After receiving the key request, the smart key server may send an encrypted smart vehicle key to the application.

[0208]

[0228] In an embodiment of the present application, secure storage of the smart vehicle key is performed in the security module of the terminal, and transmission outside the security module is encrypted, so that the smart vehicle key cannot be obtained externally, thereby ensuring the security of the vehicle.

[0209]

[0229] The key distribution scenario has been explained above using Figure 6. Next, the key usage scenario and key update scenario will be explained below using Figures 7 and 8.

[0210]

[0230] 7 is a schematic flowchart of yet another embodiment of a communication method according to the present application. The communication method specifically includes the following steps:

[0211]

[0231] Step 701: The vehicle-mounted short-range controller sends a random value to the application.

[0212]

[0232] Specifically, the in-vehicle short-distance controller may transmit a random value to the application in advance. The random value may be a random number or a random number sequence. The form of the random value is not particularly limited in the embodiments of the present application.

[0213]

[0233] Step 702: The application generates a first control message based on the smart vehicle key and a random value, and sends the first control message to the vehicle-mounted short-range controller.

[0214]

[0234] Specifically, the first control message may be generated based on the smart vehicle key and a random value. For example, the application may generate the first control message in the TEE based on the random value, the smart vehicle key, and the control instruction according to a symmetric encryption algorithm such as PBKDF2 or AES. The control instruction may be used to control the smart vehicle. It may be understood that the aforementioned algorithms such as PBKDF2 or AES are merely preferred methods that can ensure security, but do not constitute limitations on the embodiments of the present application. In some embodiments, another asymmetric encryption algorithm may alternatively be used.

[0215]

[0235] For example, if the application uses the PBKDF2 algorithm in the TEE, the first control message may be generated based on a random value and a smart vehicle key.

[0216]

[0236] If the application uses the AES algorithm, the first control message may be generated based on the random value, the smart vehicle key, and a control command, which may be an operation command input by a user, such as opening a door or opening a window.

[0217]

[0237] The difference between using the AES algorithm and using the PBKDF2 algorithm is that the first control message generated by using the PBKDF2 algorithm may not carry a control instruction, and the first control message generated by using the AES algorithm may carry a control instruction.

[0218]

[0238] Step 703: The on-board short-range controller controls the vehicle based on the first control message.

[0219]

[0239] Specifically, after receiving a first control message sent by an application, the on-board short-range controller may verify the first control message. The verification method may be as follows: in step 701, the on-board short-range controller may generate a control message (e.g., may be referred to as a second control message) based on a random value and a smart vehicle key. It can be understood that the second control message is generated by using the same symmetric encryption algorithm as that of the first control message. For example, if the first control message is generated by using the PBKDF2 algorithm, the second control message is also generated by using the PBKDF2 algorithm. In this case, neither the first control message nor the second control message includes a control command. If the first control message is generated by using the AES algorithm, the second control message is also generated by using the AES algorithm. In this case, both the first control message and the second control message may include a control command.

[0220]

[0240] Then, the second control message can be compared with the first control message. If the second control message is completely consistent with the first control message, the verification is successful, that is, the user successfully unlocks the vehicle 300. In this case, if the first control message further includes a control command, the vehicle-mounted short-range controller can encrypt the control command in the first control message by using the communication key comKey and send the encrypted control command to a vehicle-mounted component such as a BCM to control the vehicle 300. The communication key comKey may be a key used for communication within the vehicle 300, and the communication key comKey can be used in the communication process after the user unlocks the vehicle 300.

[0221]

[0241] In some optional embodiments, in the process of controlling the vehicle 300, the user may further update the smart vehicle key. For example, the user may send a key update request to the vehicle 300 via an application. The key update request is used to generate a new smart vehicle key, which can then be obtained from the smart key server. After the user successfully authenticates to the vehicle 300 by using the new smart vehicle key, the old smart vehicle key may be deleted, thereby saving storage resources of the vehicle 300.

[0222]

[0242] In the embodiment of the present application, in the process of using the smart vehicle key, the smart vehicle key cannot be obtained externally, so that vehicle security can be guaranteed.

[0223]

[0243] 8 is a schematic flowchart of yet another embodiment of a communication method according to the present application. The communication method specifically includes the following steps:

[0224]

[0244] Step 801: A user logs into a smart key server.

[0225]

[0245] Specifically, a user can log in to the smart key server through an application in the electronic device 100 by using a pre-registered account. For the specific login process, please refer to step 601. The details will not be described again here.

[0226]

[0246] Step 802: The smart key server obtains the old smart vehicle key and sends the old smart vehicle key to the application.

[0227]

[0247] Specifically, the smart key server can find the corresponding old smart vehicle key based on the user's login account. For the specific search process, please refer to step 603. The details will not be described again here.

[0228]

[0248] The smart key server can then send the old smart vehicle key to the application in a secure manner. For example, the third public key sent by the application can be used to encrypt the old smart vehicle key, thereby obtaining an encrypted smart vehicle key. The encrypted smart vehicle key can be sent to the application, thereby ensuring secure transmission of the smart vehicle key.

[0229]

[0249] Step 803: The application sends a key update request to the vehicle-mounted short-range controller to trigger the vehicle-mounted short-range controller to update the smart vehicle key.

[0230]

[0250] Specifically, a user may actively request to update the smart vehicle key. For example, the smart vehicle key may be updated after the user loses or leaks the smart vehicle key. In this case, the user may send a key update request to the on-board short-range controller via an application to trigger the on-board short-range controller to update the smart vehicle key. The key update request may include the old smart vehicle key, i.e., the smart vehicle key before the update. After receiving the key update request, the on-board short-range controller may perform authentication on the old smart vehicle key. For the specific authentication process, please refer to step 703. The details will not be described again here.

[0231]

[0251] After successful authentication, a smart vehicle key update may be triggered, and a new smart vehicle key may be obtained. In a specific implementation, a security module in the vehicle 300 may be triggered to generate a new smart vehicle key.

[0232]

[0252] Step 804: The vehicle-mounted short-range controller uploads the new key credential information to the smart key server.

[0233]

[0253] Specifically, after obtaining a new smart vehicle key, the vehicle-mounted short-range controller can determine new key credential information based on the new smart vehicle key and upload the new key credential information to the smart key server in a secure manner, and the smart key server can receive the new key credential information in response.

[0234]

[0254] The vehicle-mounted short-range controller can send a credential update instruction to the smart key server, the credential update instruction instructing the smart key server to update the key credential information, the credential update instruction including the new key credential information, and the smart key server can update the key credential information based on the credential update instruction.

[0235]

[0255] In some optional embodiments, authentication may be further performed on the old smart vehicle key before the key credential information is updated based on the credential update instruction. If the authentication on the old smart vehicle key fails, the key credential information is not updated, so that the security of the key credential information can be ensured and vehicle security can be guaranteed. If the authentication on the old smart vehicle key is successful, the key credential information can be updated, and the old key credential information may be deleted after the update is successful.

[0236]

[0256] In some optional embodiments, after receiving the new smart vehicle key, the smart key server may further send a key update prompt to the user's electronic device, which is used to prompt the user to update the smart vehicle key.

[0237]

[0257] Step 805: The user downloads a new smart vehicle key from the smart key server.

[0238]

[0258] Specifically, the user may log back in to the smart key server via the application to obtain a new smart vehicle key. It may be appreciated that in the process of obtaining a new smart vehicle key, the new smart vehicle key may alternatively be transmitted to the application in a secure manner.

[0239]

[0259] Furthermore, after obtaining the new smart vehicle key, the application may perform authentication by using the new smart vehicle key. After the authentication is successful, the application, the smart key server, and the on-board short-range controller can delete the old smart vehicle key, thereby completing the smart vehicle key update.

[0240]

[0260] In the embodiments of the present application, if the smart vehicle key is lost or leaked, the smart vehicle key can be updated, thereby ensuring the safety of the vehicle.

[0241]

[0261] The above describes the key upload, distribution, usage, and update scenarios using Figures 5 to 8. Below, a vehicle borrowing scenario will be described using Figures 9 and 10. The embodiment shown in Figure 9 is an application scenario in which the vehicle 300 is connected to the Internet, while the embodiment shown in Figure 10 is an application scenario in which the vehicle 300 is not connected to the Internet.

[0242]

[0262] 9 is a schematic flowchart of yet another embodiment of a communication method according to the present application. The communication method specifically includes the following steps:

[0243]

[0263] Step 901: In response to a vehicle utilization action of a first user, a first application sends a vehicle utilization request to an in-vehicle short-range controller.

[0244]

[0264] Specifically, the first user may be a vehicle owner or a vehicle operator, and the first application may be an application installed on the electronic device 100 used by the first user. When a second user needs to borrow a vehicle from the first user, the first user performs an operation on the first application on the first user's electronic device to request generation of a temporary key. The second user may be the user who actually borrows the vehicle. The temporary key may be a temporary smart vehicle key having a validity time period. For example, the temporary smart vehicle key is valid for a specific time period, and when the time period expires, the temporary smart vehicle key becomes invalid.

[0245]

[0265] In response to a vehicle usage action of the first user on the first application, the first application sends a vehicle usage request to the in-vehicle short-range controller. The vehicle usage request may include a smart vehicle key and a validity time zone. For ease of explanation, the validity time zone in the vehicle usage request is referred to as a "first validity time zone," and the first validity time zone is used to represent the validity time zone of the temporary key.

[0246]

[0266] Preferably, when sending the vehicle use request to the in-vehicle short-range controller, the first application may further encrypt the first validity time slot, and the encrypted key may be the smart vehicle key. In other words, the first application may encrypt the first validity time slot by using the smart vehicle key as a key, so that the encrypted first validity time slot can be obtained. In this case, the vehicle use request may include the smart vehicle key and the encrypted first validity time slot.

[0247]

[0267] In some optional embodiments, the smart vehicle key in the vehicle usage request may be a signed smart vehicle key, thereby ensuring vehicle usage security. The signed smart vehicle key can be obtained by signing the smart vehicle key with a third private key.

[0248]

[0268] In some optional embodiments, the vehicle access request may be transmitted by the electronic device used by the first user over a short-range communication scheme. Alternatively, in some optional embodiments, the vehicle access request may be transmitted by the electronic device used by the first user over a mobile network.

[0249]

[0269] In some optional embodiments, the vehicle rental request may alternatively be sent by an electronic device used by the second user or the vehicle rental platform.

[0250]

[0270] Step 902: The in-vehicle short-range controller generates a temporary key.

[0251]

[0271] Specifically, the first application may use the smart vehicle key to authenticate to the vehicle-mounted short-range controller. For specific authentication methods, please refer to the above-mentioned embodiments. The details will not be described again here.

[0252]

[0272] It can be understood that if the vehicle usage request includes a signed smart vehicle key, signature verification may be further performed on the signed smart vehicle key before authentication is performed to the on-board short-range controller by using the smart vehicle key. The manner of performing signature verification may be as follows: performing signature verification on the smart vehicle key based on a third public key, where the third public key is sent to the vehicle by the electronic device used by the first user.

[0253]

[0273] After the authentication is successful, the vehicle-mounted short-range controller may generate a temporary key based on the vehicle use request. In a specific implementation, if the vehicle use request includes a first valid time slot, the temporary key may be generated as follows: the vehicle-mounted short-range controller may use the first valid time slot in the vehicle use request as an element for generating the temporary key, and may perform secure storage for the first valid time slot. For example, the first valid time slot may be stored in a security module of the vehicle 300.

[0254]

[0274] Optionally, if the vehicle usage request includes an encrypted first validity time slot, the manner of generating the temporary key may be as follows: the vehicle-mounted short-range controller may use the smart vehicle key to decrypt the encrypted first validity time slot in the security module to obtain the first validity time slot. The vehicle-mounted short-range controller may then use the first validity time slot as an element for generating the temporary key and may perform secure storage for the first validity time slot. A specific manner of performing secure storage for the first validity time slot may be to store the first validity time slot in the security module of the vehicle. The security module has complete information security protection measures, which can effectively guarantee vehicle security.

[0255]

[0275] Step 903: The vehicle-mounted short-range controller uploads the temporary key to the smart key server.

[0256]

[0276] Specifically, the vehicle-mounted short-range controller can upload the temporary key to the smart key server in a secure manner. For a specific secure manner, please refer to the method for uploading the smart vehicle key to the smart key server. The details will not be described again here.

[0257]

[0277] Step 904: A first user logs into the smart key server and applies for a temporary vehicle borrowing account.

[0258]

[0278] Specifically, a first user may log in to a smart key server through a first application. The first user may log in to the smart key server by using a pre-registered user account, and the user account may be a permanent account, i.e., the user account does not have a validity period.

[0259]

[0279] After successfully logging in to the smart key server using a user account, the first user can send a temporary vehicle borrowing account registration request to the smart key server via a first application to generate a temporary vehicle borrowing account. The temporary vehicle borrowing account registration request may include a validity time zone. For ease of explanation, the validity time zone in the temporary vehicle borrowing account registration request is referred to as a "second validity time zone," and the second validity time zone is used to represent the validity time zone of the temporary vehicle borrowing account. It can be understood that the second validity time zone may be the same as or different from the first validity time zone. Preferably, the second validity time zone is equal to or shorter than the first validity time zone.

[0260]

[0280] Step 905: The smart key server generates a temporary vehicle borrowing account and sends the temporary vehicle borrowing account to the first application.

[0261]

[0281] Specifically, after receiving the temporary vehicle borrowing account registration request sent by the first application, the smart key server may generate a temporary vehicle borrowing account. It can be understood that the temporary vehicle borrowing account has a validity time zone, and the validity time zone of the temporary vehicle borrowing account may be determined based on the second validity time zone in the temporary vehicle borrowing account registration request.

[0262]

[0282] The smart key server may then further link the temporary vehicle rental account to the temporary key, such that a second user (e.g., a borrower) can log in to the smart key server within the second validity time period to obtain the temporary key and use the temporary key within the second validity time period. It may be understood that the temporary vehicle rental account becomes invalid when the second validity time period expires. In this case, the smart key server may delete the temporary vehicle rental account. In other words, the second user cannot use the temporary vehicle rental account to log in to the smart key server again to obtain the temporary key, thereby improving the convenience and security of vehicle rental.

[0263]

[0283] Step 906: The second user logs into the smart key server, obtains a temporary key, and starts the vehicle 300 by using the temporary key.

[0264]

[0284] Specifically, a first user can transfer a temporary vehicle borrowing account to a second user. In this case, the second user can use the temporary vehicle borrowing account via a second application to log in to the smart key server and submit a temporary key request to the smart key server to obtain a temporary key corresponding to the temporary vehicle borrowing account. The second application may be an application installed on the electronic device 100 used by the second user.

[0265]

[0285] After obtaining the temporary key, the second user can use the temporary key to perform authentication on the vehicle-mounted short-range controller and initiate an operation request to the vehicle 300. For the specific authentication process, please refer to the authentication process of the smart vehicle key in the above embodiment, and the details will not be described again here.

[0266]

[0286] After the on-board short-range controller performs authentication on the temporary key, the time validity may be further verified, that is, whether the current vehicle borrower is within the valid period of the vehicle borrowing may be verified. In a specific implementation, the on-board short-range controller may obtain the current system time and determine whether the current system time is within the first valid time period.

[0267]

[0287] If the current system time is within the first valid time period, the second user can use the current vehicle normally, and therefore the current vehicle can be successfully unlocked, and the second user can further deliver instructions to operate the current vehicle.

[0268]

[0288] If the current system time is not within the first valid time period, the second user does not have the right to use the current vehicle, and the current vehicle can remain locked, thereby ensuring vehicle security.

[0269]

[0289] 10 is a schematic flowchart of another embodiment of a communication method according to the present application. The communication method includes the following steps:

[0270]

[0290] Step 1001: A first application generates temporary authentication information in response to a vehicle utilization action of a first user.

[0271]

[0291] Specifically, a first user may perform a vehicle-use action with a first application, and in response to the first user's vehicle-use action, the first application may generate a temporary credential, which may include a smart vehicle key and a first validity time period.

[0272]

[0292] The above method of generating temporary credentials requires some function, e.g. Temporary Credential = func(Smart Vehicle Key, First Validity Period) (temporary credential = func(smart vehicle key, first valid time period)) It can be understood that the temporary credential may be generated in another way, where func() is a function. Alternatively, the temporary credential may be generated in another way. The manner of generating the temporary credential is not particularly limited in the embodiments of the present application.

[0273]

[0293] Step 1002: The first application encrypts the temporary credential and the first validity time period to obtain encrypted data.

[0274]

[0294] Specifically, the first application can encrypt the temporary credential and the first validity time slot by using the key to obtain the encrypted data. Preferably, the first user has a smart vehicle key. In other words, the first user's electronic device 100 has the smart vehicle key. The key may be the smart vehicle key, and the first application can encrypt the temporary credential and the first validity time slot by using the smart vehicle key as the key. Key agreement with the in-vehicle short-range controller is not required, thereby improving communication efficiency. However, this does not constitute a limitation on the embodiments of the present application. In some embodiments, the key may be a different key, and the first application can alternatively encrypt the temporary credential and the first validity time slot by using the different key. The different key may be obtained through key agreement between the first application and the in-vehicle short-range controller.

[0275]

[0295] It should be noted that when the temporary credential and the first validity time period are encrypted, the temporary credential and the first validity time period may be encrypted separately, resulting in two encrypted data, for example, the encrypted temporary credential and the encrypted first validity time period. Alternatively, packaged data of the temporary credential and the first validity time period may be encrypted to obtain one encrypted data. The encryption method is not particularly limited in the embodiments of the present application.

[0276]

[0296] Step 1003: The first application uploads the encrypted data to the smart key server.

[0277]

[0297] Step 1004: A first user logs into the smart key server and applies for a temporary vehicle borrowing account.

[0278]

[0298] Specifically, a first user may log into a smart key server via a first application.

[0279]

[0299] After successfully logging in to the smart key server using the user account, the first user can send a temporary vehicle borrowing account registration request to the smart key server via the first application to generate a temporary vehicle borrowing account. The temporary vehicle borrowing account may be tied to encrypted data.

[0280]

[0300] Step 1005: The smart key server generates a temporary vehicle borrowing account and sends the temporary vehicle borrowing account to the first application.

[0281]

[0301] Specifically, after receiving the temporary vehicle borrowing account registration request sent by the first application, the smart key server can generate a temporary vehicle borrowing account and bind the temporary vehicle borrowing account to the encrypted data sent by the first application.

[0282]

[0302] The smart key server can then send a temporary vehicle borrowing account to the first application.

[0283]

[0303] Step 1006: The second application obtains the encrypted data.

[0284]

[0304] Specifically, the second application can obtain data encrypted in the following two ways:

[0285]

[0305] Method 1:

[0306] A first user can transfer a temporary vehicle borrowing account to a second user, who can then use the temporary vehicle borrowing account via a second application to log in to the smart key server and retrieve encrypted data corresponding to the temporary vehicle borrowing account.

[0286]

[0307] Method 2:

[0308] The first user can send the encrypted data directly to the second application. In Method 2, it can be understood that steps 1003 to 1005 are optional steps.

[0287]

[0309] Step 1007: The second application sends the encrypted data to the vehicle-mounted short-range controller to request a temporary key.

[0288]

[0310] Specifically, the second user may perform a temporary key request operation on the second application, and in response to the detected temporary key request operation of the second user, the second application may transmit encrypted data to the vehicle-mounted short-range controller.

[0289]

[0311] Step 1008: The vehicle-mounted short-range controller performs authentication on the encrypted data, generates a temporary key, and sends the temporary key to the second application.

[0290]

[0312] Specifically, after receiving the encrypted data sent by the second application, the in-vehicle short-range controller can perform authentication on the encrypted data. The specific process of authentication may be as follows: the in-vehicle short-range controller can use the smart vehicle key or a key pre-negotiated by the in-vehicle short-range controller and the second application to decrypt the encrypted data and obtain the decrypted data, i.e., the temporary credential and the first validity time slot. Then, the in-vehicle short-range controller can verify the validity of the temporary credential and the first validity time slot.

[0291]

[0313] The manner of verifying the validity of the temporary credential may be: on the vehicle-mounted short-range controller side, the temporary credential is obtained by calculation on the smart vehicle key and the first valid time period in the same manner (e.g., the same function func) as in step 1001. Then, the temporary credential obtained by calculation on the vehicle-mounted short-range controller side is compared with the temporary credential obtained by calculation on the first application. If the two temporary credentials match, the temporary credential may be determined to be valid. Alternatively, if the two temporary credentials do not match, the temporary credential may be determined to be invalid.

[0292]

[0314] A method for verifying the validity of the first valid time slot may be to obtain a current system time point and compare the current system time point with the first valid time slot. If the current system time point is within the first valid time slot, the first valid time slot is valid. Alternatively, if the current system time point is not within the first valid time slot, the first valid time slot is invalid.

[0293]

[0315] After the vehicle-mounted short-range controller determines that the temporary credential and the first validity time period are valid through verification, the vehicle-mounted short-range controller may generate a temporary key and encrypt the temporary key by using the temporary credential as a key to obtain an encrypted temporary key.

[0294]

[0316] The vehicle-mounted short-range controller can then send the encrypted temporary key to the second application and perform secure storage for the first validity time slot. Methods for performing secure storage for the first validity time slot are described above, which can improve vehicle security and prevent external acquisition or tampering of the validity time slot.

[0295]

[0317] In some optional embodiments, after the temporary key is generated, a time validity check may further be performed against the first validity time zone. If it is detected that the current system time exceeds the first validity time zone, i.e., the time validity check fails, the temporary key may be set to invalid, and the user may be notified that the temporary key has expired.

[0296]

[0318] Step 1009: The second application decrypts the encrypted temporary key and controls the vehicle by using the temporary key.

[0297]

[0319] Specifically, after receiving the encrypted temporary key sent by the vehicle-mounted short-range controller, the second application can decrypt the encrypted temporary key based on the temporary credentials to obtain the temporary key.

[0298]

[0320] The second user can then use the temporary key to control the vehicle. For example, the second user can send a control request via a second application to the on-board short-range controller, the control request including the temporary key.

[0299]

[0321] In some optional embodiments, the second user can alternatively encrypt the temporary key through the second application by using the first key to obtain the encrypted temporary key, and carry the encrypted temporary key in the operation request. Correspondingly, the vehicle 300 can decrypt the encrypted temporary key by using the first private key to obtain the temporary key, thereby improving the security of the vehicle 300 and avoiding theft of the temporary key in the transmission process.

[0300]

[0322] In some optional embodiments, the second user's electronic device may further transmit a fourth public key to the vehicle 300, and the vehicle 300 may verify the fourth key based on the fourth certificate. The fourth certificate may have been previously transmitted by the second user's electronic device to the vehicle 300. The fourth key is used to encrypt information transmitted by the vehicle 300 to the second user's electronic device.

[0301]

[0323] It can be understood that after the second application successfully decrypts the encrypted temporary key or after the second user successfully unlocks the vehicle by using the temporary key, the encrypted data becomes invalid. In this case, the second application may store the temporary key in the TEE, thereby ensuring the security of the temporary key. If the current system time exceeds the first valid time period, both the second application and the temporary key in the vehicle-mounted short-range controller become invalid.

[0302]

[0324] In some optional embodiments, after the temporary key is disabled, a key disabled notification may be further sent to the electronic device of the second user, indicating that the temporary key is disabled, thereby avoiding incorrect operations performed by the user when the temporary key is disabled and improving the user experience.

[0303]

[0325] In the embodiment of the present application, in a vehicle borrowing scenario, both an application scenario in which the vehicle has networking capability and an application scenario in which the vehicle does not have networking capability may be supported. In a scenario in which the vehicle cannot connect to a network, the vehicle owner may distribute a temporary credential to the borrower instead of distributing a smart vehicle key to the borrower, and the borrower may exchange the temporary key with the vehicle through the temporary credential. As a result, it is possible to ensure that only the borrower can obtain the temporary key, which can prevent the smart vehicle key from being distributed to others in an uncontrolled manner and ensure vehicle security.

[0304]

[0326] Next, a vehicle rental scenario will be further described below with reference to Figure 11. It should be noted that in the vehicle rental scenario, the smart key server and the vehicle rental / sharing platform may be the same server or different servers. In the embodiment shown in Figure 11, the example in which the smart key server and the vehicle rental / sharing platform are different servers is used for illustrative purposes only, but this does not constitute a limitation on the embodiments of the present application.

[0305]

[0327] 11 is a schematic flowchart of an embodiment of a vehicle rental method according to the present application. The vehicle rental method includes the following steps:

[0306]

[0328] Step 1101: A second user submits a vehicle rental request to a vehicle rental / sharing platform.

[0307]

[0329] Specifically, the second user may be a renter. When the second user needs to rent a vehicle, the second user may enter a vehicle rental time slot into an application on the second user's electronic device 100 and submit a vehicle rental request to the vehicle rental / sharing platform. In a possible implementation, the second user may enter a vehicle rental time slot and a vehicle model to be rented in the second application on the second user's electronic device 100. In a possible implementation, the second user may enter information in the application, such as the vehicle rental period, the vehicle model to be rented, and the vehicle rental location. In a possible implementation, the vehicle rental request may further include vehicle identification information and the vehicle rental time slot.

[0308]

[0330] Step 1102: The vehicle rental / sharing platform requests a smart vehicle key from the smart key server.

[0309]

[0331] Specifically, after receiving the vehicle rental request sent by the second application, the vehicle rental / sharing platform may obtain a qualified vehicle based on the vehicle rental request and obtain vehicle identification information for the qualified vehicle. For example, an appropriate idle vehicle may be selected based on at least one of the vehicle rental time slot, the vehicle type information to be rented, the vehicle rental location information, and the vehicle identification information entered by the user. After the vehicle is selected, the vehicle rental / sharing platform may send a key request to the smart key server based on the vehicle identification information for the vehicle, and the key request may be used to request obtaining a smart vehicle key. In a possible implementation, the key request may include the vehicle identification information and be used to request obtaining a smart vehicle key for the specific vehicle.

[0310]

[0332] TLS communication may be established between the vehicle rental / sharing platform and the smart key server, and bidirectional authentication may be performed via certificates. For example, the vehicle rental / sharing platform may issue its certificate to the smart key server, and the smart key server may also issue its certificate to the vehicle rental / sharing platform. The vehicle rental / sharing platform and the smart key server may separately perform encrypted transmissions using the public keys of the smart key server and the vehicle rental / sharing platform, and may separately decrypt received encrypted information using the private keys of the vehicle rental / sharing platform and the smart key server. Details will not be described again here. TLS communication between the vehicle rental / sharing platform and the smart key server can improve the security of the entire system and ensure vehicle security.

[0311]

[0333] Step 1103: The smart key server distributes the smart vehicle key to the vehicle rental / sharing platform.

[0312]

[0334] Specifically, after receiving a key request from a vehicle rental / sharing platform, the smart key server can obtain a smart vehicle key corresponding to the vehicle identification information by querying based on the vehicle identification information in the key request, and can distribute the smart vehicle key to the vehicle rental / sharing platform.

[0313]

[0335] Step 1104: The vehicle rental / sharing platform performs authentication with the vehicle-mounted short-range controller by using the smart vehicle key, and sends the vehicle rental time slot to the vehicle-mounted short-range controller.

[0314]

[0336] Specifically, after receiving the smart vehicle key distributed by the smart key server, the vehicle rental / sharing platform can use the smart vehicle key to authenticate with the on-board short-range controller, as described above.

[0315]

[0337] In addition, the vehicle rental / sharing platform may transmit the vehicle rental time slot to the on-board short-range controller. It can be understood that the vehicle rental time slot and the smart vehicle key may alternatively be transmitted to the on-board short-range controller simultaneously, or may be transmitted to the on-board short-range controller separately. The transmission time of the vehicle rental time slot is not particularly limited in the embodiments of the present application.

[0316]

[0338] Preferably, the vehicle rental / sharing platform may further transmit the encrypted vehicle rental time slot to the vehicle-mounted short-range controller, so that the security of the vehicle rental time slot can be guaranteed. In a specific implementation, the vehicle rental time slot may be encrypted using the smart vehicle key as a key.

[0317]

[0339] After obtaining the encrypted vehicle rental time slot, the vehicle can decrypt and obtain the vehicle rental time slot. In a possible implementation, the vehicle (or the vehicle's short-range controller) can perform the decryption using a smart vehicle key as a key. Efficiency and security can be improved if encryption or decryption is performed using the smart vehicle key.

[0318]

[0340] After obtaining the vehicle rental time slot, the vehicle may perform secure storage for the vehicle rental time slot. For example, the vehicle may store the vehicle rental time slot in a security module, thereby improving vehicle security and preventing the vehicle rental time slot from being tampered with or fraudulently obtained.

[0319]

[0341] Step 1105: The in-vehicle short-range controller generates first information and uploads the first information to the smart key server.

[0320]

[0342] Specifically, the first information may be generated after the vehicle-mounted short-range controller successfully authenticates the smart vehicle key sent by the vehicle rental / sharing platform. The first information may be a temporary key, which is used to unlock and operate the vehicle 300. Alternatively, the first information may be encrypted data. The encrypted data may be obtained by encrypting the temporary credentials and the first validity time slot using the smart vehicle key. The first validity time slot may be the vehicle rental time slot. The temporary key may be tied to the vehicle rental time slot. In other words, the temporary key is valid during the vehicle rental time slot, and is invalid beyond the vehicle rental time slot. In a specific implementation, the temporary key may be generated in the following two ways:

[0321]

[0343] Method 1:

[0344] When the on-board short-range controller receives the vehicle rental period transmitted by the vehicle rental / sharing platform, a temporary key may be generated directly, and the temporary key may be bound to the vehicle rental period.

[0322]

[0345] Method 2:

[0346] When the on-board short-range controller receives the encrypted vehicle rental time slot sent by the vehicle rental / sharing platform, it can use the smart vehicle key as a key to decrypt the encrypted vehicle rental time slot, thereby obtaining the vehicle rental time slot. The on-board short-range controller can then generate a temporary key. In a possible implementation, the temporary key may be tied to the vehicle rental time slot.

[0323]

[0347] It should be noted that after generating the first information, the on-board short-range controller may further upload the first information to a smart key server and perform secure storage for the vehicle rental time slot. The on-board short-range controller may generate a temporary key in the security module, and vehicle security may be improved by generating the temporary key in the security module.

[0324]

[0348] In some optional embodiments, the first user's electronic device may alternatively upload the first information (eg, encrypted data) to a smart key server.

[0325]

[0349] Step 1106: The vehicle rental / sharing platform registers the vehicle rental account with the smart key server.

[0326]

[0350] Step 1107: The smart key server assigns the vehicle rental account to the vehicle rental / sharing platform, binds the vehicle rental account to the temporary key, and sends the vehicle rental account to the vehicle rental / sharing platform.

[0327]

[0351] Step 1108: The vehicle rental / sharing platform sends the vehicle rental account to the second user.

[0328]

[0352] Step 1109: The second user logs into the smart key server and obtains a temporary key.

[0329]

[0353] Specifically, the second user may log in to the smart key server by using the vehicle rental account in the second application and obtain a temporary key corresponding to the vehicle rental account from the smart key server.

[0330]

[0354] In some optional embodiments, the smart key server may encrypt the temporary key using the fourth public key and send the encrypted temporary key to the second user's electronic device, and the fourth public key may be sent by the second user's electronic device to the smart key server.

[0331]

[0355] Step 1110: The vehicle rental / sharing platform sends a key invalidation notification to the vehicle-mounted short-range controller.

[0332]

[0356] Specifically, when the vehicle rental / sharing platform wishes to terminate the vehicle rental, a key invalidation notification may be sent to the vehicle's onboard short-range controller, which may be used to notify the vehicle owner that the temporary vehicle rental key is invalid. In other words, regardless of whether the temporary vehicle rental key is currently within the validity period of the vehicle rental time slot, after receiving the key invalidation notification, the vehicle's onboard short-range controller may set the temporary vehicle rental key to an invalid state and terminate the vehicle rental. The renter cannot start the vehicle using the temporary vehicle rental key. This provides more flexible access control for the vehicle rental / sharing platform and encourages the vehicle rental / sharing platform to control the validity period of the vehicle.

[0333]

[0357] In some optional embodiments, a key revocation notification may also be sent to the second user's electronic device, the key revocation notification indicating that the temporary key is revoked.

[0334]

[0358] In the embodiment of the present application, only the renter can use the temporary vehicle rental key during the vehicle rental time period, and no one else can obtain the temporary vehicle rental key, thereby ensuring vehicle usage security. In addition, the vehicle rental / sharing platform can terminate the use of the temporary vehicle rental key at any time and enable the rental to end at any time, thereby facilitating rental convenience.

[0335]

[0359] In the embodiments shown in Figures 5-11, the smart vehicle key server is configured to store the smart vehicle key. In a possible implementation, the smart vehicle key may not be stored in the smart key server; only authentication credentials are stored. The smart vehicle key can be exchanged using the authentication credentials. In this scenario, the smart vehicle key is stored only on the electronic device 100 and the vehicle 300, and transmission of the smart vehicle key occurs only between the electronic device 100 and the vehicle 300. This reduces the attack surface of smart vehicle key transmission and exposure, improving security.

[0336]

[0360] The embodiment shown in Figure 5 is used as an example. After generating the smart vehicle key, the vehicle-mounted short-range controller does not upload the smart vehicle key to the smart key server, but may generate an authentication credential by using the smart vehicle key and upload the authentication credential to the smart key server. After obtaining the authentication credential, the user cannot directly use the authentication credential as the smart vehicle key, but needs to use the authentication credential to exchange the smart vehicle key with the vehicle-mounted short-range controller. For the function of the authentication credential and the manner of exchanging the smart vehicle key by using the authentication credential, please refer to the function of the temporary credential and the manner of exchanging the smart vehicle key by using the temporary credential in the embodiment shown in Figure 10. The details will not be described again here.

[0337]

[0361] Furthermore, in an embodiment of the present application, in a vehicle borrowing scenario where the vehicle cannot connect to a network, the on-board short-range controller may alternatively send a temporary credential having a validity time slot to the smart key server, and the second user may exchange a smart vehicle key having a validity time slot at the on-board short-range controller based on the temporary authentication credential.

[0338]

[0362] Furthermore, in a vehicle rental scenario according to an embodiment of the present application, the onboard short-range controller may alternatively send an authentication credential to the smart key server, and the vehicle rental / sharing platform may obtain a smart vehicle key based on the authentication credential. The vehicle rental / sharing platform may send a vehicle rental time slot to the onboard short-range controller. The onboard short-range controller may generate a temporary credential corresponding to the vehicle rental time slot and send the temporary credential to the smart key server. The second user may obtain the temporary credential from the smart key server and use the temporary credential to exchange the temporary key corresponding to the vehicle rental time slot in the onboard short-range controller.

[0339]

[0363] 12 is a schematic diagram of the structure of an embodiment of a communication device according to the present application. As shown in FIG. 12, the communication device 1200 is applied to a vehicle, and the vehicle includes a smart vehicle key, which is electronic key information used to control the vehicle. The communication device 1200 may include a determination module 1210 and a sending module 1220.

[0340]

[0364] The determination module 1210 is configured to determine key credential information based on the smart vehicle key.

[0341]

[0365] The sending module 1220 is configured to send the key credential information to a server.

[0342]

[0366] In a possible implementation, the determination module 1210 specifically: The smart vehicle key is configured to encrypt the smart vehicle key using the smart vehicle key as a key to obtain key credential information.

[0343]

[0367] In a possible implementation, the vehicle further includes vehicle identification information corresponding to the vehicle, and the determination module 1210 specifically: signing the smart vehicle key and the vehicle identification information by using the first private key to obtain signature data; obtaining a second public key and encrypting the signature data, the smart vehicle key, and the vehicle identification information by using the second public key to obtain a first ciphertext, wherein the second public key is sent by the server to the vehicle; and generating key credential information based on the first ciphertext and a first public key, the first public key corresponding to the first private key; The device is configured to:

[0344]

[0368] In a possible implementation, the sending module 1220 further: The device is further configured to perform a step of sending a first certificate to the server, the first certificate including vehicle identification information and a first public key, the first certificate being issued to the vehicle after being signed by a third party, and the first certificate being used to verify the first public key.

[0345]

[0369] In a possible implementation, the communication device 1200 further comprises: A verification module configured to verify the second public key based on the second certificate is included.

[0346]

[0370] In a possible implementation, the communication device 1200 further comprises: and a receiving module configured to receive a second certificate sent by the server, the second certificate including identification information of the server and a second public key, the second certificate being issued to the server after being signed by a third party.

[0347]

[0371] In a possible implementation, the vehicle has pre-stored the root certificate, which is used to verify the certificate. A signature verification module configured to perform signature verification on the second certificate based on the root certificate.

[0348]

[0372] In a possible implementation, the second certificate is pre-configured in the vehicle.

[0349]

[0373] In a possible implementation, the first public key and the first private key are generated in a security module of the vehicle.

[0350]

[0374] In a possible implementation, the smart vehicle key is generated in factory mode for the vehicle.

[0351]

[0375] In a possible implementation, the communication device 1200 further comprises: periodically updating key credential information based on the smart vehicle key; and sending updated key credential information to the server; The update module is configured to:

[0352]

[0376] In a possible implementation, the sending module 1220 is further configured to send a key update prompt to the first electronic device to prompt the user to update the smart vehicle key.

[0353]

[0377] In a possible implementation, the receiving module further comprises: receiving a key update request sent by the first electronic device, the key update request being used to request generating a new smart vehicle key; determining new key credentials based on the new smart vehicle key; and sending the new key credential information to the server; The device is configured to:

[0354]

[0378] In a possible implementation, the key update request includes the old smart vehicle key, and the communication device 1200 further: An authentication module configured to perform authentication on the old smart vehicle key.

[0355]

[0379] In a possible implementation, the communication device 1200 further comprises: and a deletion module configured to delete the old smart vehicle key in the vehicle if successful authentication of the first electronic device's request to use the new smart vehicle key is detected.

[0356]

[0380] 13 is a schematic diagram of the structure of another embodiment of a communication device according to the present application. As shown in FIG. 13, the communication device 1300 is applied to a server, and may include a receiving module 1310 and a storage module 1320.

[0357]

[0381] The receiving module 1310 is configured to receive key credential information.

[0358]

[0382] The storage module 1320 is configured to perform secure storage for the key credential information, where secure storage is storage performed by using secure cryptographic means.

[0359]

[0383] In a possible implementation, the key credential information includes a first ciphertext and a first public key, and the storage module 1320 specifically: decrypting the first ciphertext by using the second private key to obtain the signature data, the smart vehicle key, and the vehicle identification information; performing signature verification on the signature data by using the first public key; and If the signature verification is successful, performing secure storage of the smart vehicle key and the vehicle identification information; The device is configured to:

[0360]

[0384] In a possible implementation, the communication device 1300 further comprises: obtaining a third public key and encrypting the smart vehicle key by using the third public key to obtain an encrypted smart vehicle key, wherein the third public key is sent by the first electronic device to the server; and transmitting the encrypted smart vehicle key to the first electronic device; The system includes an acquisition module configured to:

[0361]

[0385] In a possible implementation, the receiving module 1310 further: receiving a registration request, the registration request including a user account and vehicle identification information corresponding to the user account; and creating a user account based on the registration request, the user account corresponding to the smart vehicle key and the vehicle identification information; The device is configured to:

[0362]

[0386] In a possible implementation, the communication device 1300 further comprises: and a transmitting module configured to transmit a second certificate to the vehicle, the second certificate including identification information of the server and a second public key, the second certificate being issued to the server after being signed by a third party authority, and the second certificate being used to verify the second public key.

[0363]

[0387] In a possible implementation, the communication device 1300 further comprises: A verification module configured to verify the first public key based on the first certificate is included.

[0364]

[0388] In a possible implementation, the receiving module 1310 further: The device is configured to receive a first certificate sent by the vehicle, the first certificate including vehicle identification information and a first public key, and the first certificate is issued to the vehicle after being signed by a third party.

[0365]

[0389] In a possible implementation, the server has pre-stored the root certificate, which is used to verify the certificate. A signature verification module configured to perform signature verification on the first certificate based on the root certificate.

[0366]

[0390] In a possible implementation, the first certificate is pre-configured in the server.

[0367]

[0391] In a possible implementation, the first public key is generated in a vehicle security module.

[0368]

[0392] In a possible implementation, the receiving module 1310 further: The key credential information is configured to be periodically received and the key credential information is configured to be periodically updated.

[0369]

[0393] In a possible implementation, the sending module further comprises: A key update prompt is configured to be sent to the first electronic device to prompt the user to update the smart vehicle key.

[0370]

[0394] In a possible implementation, the receiving module 1310 further: receiving a credential update instruction, the credential update instruction instructing the key credential to be updated, the credential update instruction including the new key credential; and updating the key credential information based on the credential update instruction; The device is configured to:

[0371]

[0395] In a possible implementation, the key credential update instruction further includes an old smart vehicle key, where the old smart vehicle key is stored on the server, and the new key credential information includes a new smart vehicle key, and the communication device 1300 further: An authentication module configured to perform authentication on the old smart vehicle key.

[0372]

[0396] In a possible implementation, the communication device 1300 further comprises: and a deletion module configured to store the new key credential and delete the old key credential when successful authentication of the new key credential is detected.

[0373]

[0397] 14 is a schematic diagram of the structure of an embodiment of a communication device according to the present application. As shown in FIG. 14, the communication device 1400 is applied to a vehicle and may include a transmitting module 1410, a receiving module 1420, and an inspection module 1430.

[0374]

[0398] The transmitting module 1410 is configured to transmit the random value to the first electronic device.

[0375]

[0399] The receiving module 1420 is configured to receive a first control message sent by the first electronic device, the first control message being generated based on the smart vehicle key and a random value.

[0376]

[0400] The verification module 1430 is configured to: verify the first control message based on the smart vehicle key and the random value, and control the vehicle based on the first control message if the verification is successful.

[0377]

[0401] In a possible implementation, the validation module 1430 specifically: generating a second control message based on the smart vehicle key and the random value; and comparing the first control message and the second control message; controlling the vehicle based on the first control message if the first control message matches the second control message; The device is configured to:

[0378]

[0402] 15 is a schematic diagram of the structure of another embodiment of a communication device according to the present application. As shown in FIG. 15, the communication device 1500 is applied to a first electronic device and may include a receiving module 1510, a generating module 1520, and a transmitting module 1530.

[0379]

[0403] The receiving module 1510 is configured to receive a random value transmitted by a vehicle.

[0380]

[0404] The generation module 1520 is configured to obtain a smart vehicle key and generate a first control message based on the smart vehicle key and the random value, where the first control message is used to control the vehicle.

[0381]

[0405] The transmitting module 1530 is configured to transmit the first control message to the vehicle.

[0382]

[0406] In a possible implementation, the first control message is generated in a trusted execution environment TEE.

[0383]

[0407] In a possible implementation, the generating module 1520 specifically: receiving an encrypted smart vehicle key sent by the server, the encrypted smart vehicle key being obtained by the server by encrypting the smart vehicle key using a third public key, the third public key being sent to the server by the first electronic device; and decrypting the encrypted smart vehicle key by using the third private key to obtain the smart vehicle key; The device is configured to:

[0384]

[0408] In a possible implementation, the third public key and the third private key are generated in a trusted execution environment TEE of the first electronic device.

[0385]

[0409] In a possible implementation, the generating module 1520 further: decrypting the encrypted smart vehicle key in the trusted execution environment TEE of the first electronic device by using the third private key to obtain the smart vehicle key; and storing a smart vehicle key in a trusted execution environment TEE of the first electronic device; The device is configured to:

[0386]

[0410] In a possible implementation, the sending module 1530 further: The system is configured to send a key request to a server, the key request including a user account, the key request being used to obtain a smart vehicle key corresponding to the user account.

[0387]

[0411] In a possible implementation, the sending module 1530 further: sending a key update request to the vehicle, the key update request being used to generate a new smart vehicle key; and retrieving a new smart vehicle key from the server; The device is configured to:

[0388]

[0412] In a possible implementation, the communication device 1500 further comprises: performing authentication with respect to the vehicle by using the new smart vehicle key; and If the authentication is successful, deleting the old smart vehicle key in the first electronic device; The authentication module is configured to:

[0389]

[0413] 16 is a schematic diagram of the structure of an embodiment of a communication device according to the present application. As shown in FIG. 16, the communication device 1600 is applied to a vehicle and may include an acquisition module 1610, an inspection module 1620, and an operation module 1630.

[0390]

[0414] The acquiring module 1610 is configured to acquire an action request sent by the second electronic device, where the action request includes a temporary key and a control instruction.

[0391]

[0415] The verification module 1620 is configured to verify the temporary key; and perform a time validity check based on a first validity time zone, the first validity time zone being used to represent the validity time zone of the temporary key, the first validity time zone being stored in the vehicle security module.

[0392]

[0416] The operation module 1630 is configured to operate the vehicle based on a control command of the second electronic device if the temporary key check is successful and the time validity check is successful.

[0393]

[0417] In a possible implementation, the acquisition module 1610 further: obtaining a vehicle use request, the vehicle use request including a first validity time slot; generating a temporary key based on the first validity period; and Sending the temporary key to the server; The device is configured to:

[0394]

[0418] In a possible implementation, the vehicle use request is transmitted by the first electronic device using a short-range communication method.

[0395]

[0419] In a possible implementation, the vehicle use request is transmitted by the first electronic device over a mobile network.

[0396]

[0420] In a possible implementation, the vehicle use request further includes a signed smart vehicle key, where the signed smart vehicle key is obtained by signing the smart vehicle key with the third private key. and a signature verification module configured to perform signature verification on the smart vehicle key based on a third public key, the third public key being transmitted by the first electronic device to the vehicle.

[0397]

[0421] In a possible implementation, the communication device 1600 further comprises: The system includes a transmitting module configured to transmit a first certificate to the first electronic device, the first certificate including vehicle identification information and a first public key, the first certificate being issued to the vehicle after being signed by a third party, and the first certificate being used to verify the first public key.

[0398]

[0422] In a possible implementation, the communication device 1600 further comprises: and a verification module configured to verify the third public key based on the third certificate.

[0399]

[0423] In a possible implementation, the communication device 1600 further comprises: and a receiving module configured to receive a third certificate sent by the first electronic device, the third certificate including identification information of the first electronic device and a third public key, the third certificate being issued to the first electronic device after being signed by a third party.

[0400]

[0424] In a possible implementation, the vehicle has pre-stored the root certificate, which is used to verify the certificate. The signature verification module further: The certificate is configured to perform signature verification on the third certificate based on the root certificate.

[0401]

[0425] In a possible implementation, the first validity time period is encrypted using the smart vehicle key. and a decryption module configured to decrypt the encrypted first validity time slot by using the smart vehicle key and perform secure storage for the decrypted first validity time slot.

[0402]

[0426] In a possible implementation, the receiving module further comprises: receiving encrypted data sent by the second electronic device, the encrypted data being obtained by encrypting the temporary credential and the first validity time period with a smart vehicle key, the smart vehicle key being stored in the first electronic device, and the temporary credential being generated by the first electronic device; decrypting the encrypted data using the smart vehicle key to obtain a temporary credential and a first validity time period; validating the temporary credential and the first validity time range; If the verification is successful, generating a temporary key; and encrypting a temporary key based on the encrypted data to obtain an encrypted temporary key, and sending the encrypted temporary key to the second electronic device; The device is configured to:

[0403]

[0427] In a possible implementation, the communication device 1600 further comprises: A storage module configured to perform secure storage for the first validity period is included.

[0404]

[0428] In a possible implementation, a temporary credential is generated based on the smart vehicle key and the first validity time period, and encrypted data is sent by the first electronic device to the server.

[0405]

[0429] In a possible implementation, the operation request includes an encrypted temporary key, and the encrypted temporary key is obtained after being encrypted using the first public key, and the decryption module is further configured to decrypt the encrypted temporary key using the first private key to obtain the temporary key.

[0406]

[0430] In a possible implementation, the sending module is configured to send a first certificate to the second electronic device, the first certificate including vehicle identification information and a first public key, the first certificate being issued to the vehicle after being signed by a third party, and the first certificate being used to verify the first public key.

[0407]

[0431] In a possible implementation, the verification module is further configured to verify a fourth public key based on the fourth certificate, the fourth public key being transmitted by the second electronic device to the vehicle.

[0408]

[0432] In a possible implementation, the receiving module is further configured to receive a fourth certificate sent by the second electronic device, the fourth certificate including identification information of the second electronic device and a fourth public key, and the fourth certificate being issued to the second electronic device after being signed by a third party.

[0409]

[0433] In a possible implementation, the vehicle has pre-stored a root certificate, which is used to verify the certificate, and the signature verification module is further configured to perform signature verification on the fourth certificate based on the root certificate.

[0410]

[0434] In a possible implementation, the sending module further comprises: transmitting the random value to a second electronic device; receiving a first control message transmitted by the second electronic device, the first control message being generated based on a temporary key and a random value; and performing a temporary key check on the first control message based on the temporary key and the random value; The device is configured to:

[0411]

[0435] In a possible implementation, the sending module further comprises: A key revocation notification is configured to be sent to the second electronic device, the key revocation notification indicating that the temporary key is revoked.

[0412]

[0436] In a possible implementation, the communication device 1600 further comprises: A setting module configured to set the temporary key to be invalid when the current system time is detected to be beyond the first validity time range.

[0413]

[0437] In a possible implementation, the communication device 1600 further comprises: A prompt module configured to notify the user that the temporary key has expired if the time validity check fails.

[0414]

[0438] 17 is a schematic diagram of the structure of another embodiment of a communication device according to the present application. As shown in FIG. 17, the communication device 1700 is applied to a server and may include a receiving module 1710 and a sending module 1720.

[0415]

[0439] The receiving module 1710 is configured to receive a key retrieval request sent by the second electronic device, where the key retrieval request is used to request to retrieve first information, and the first information is used to determine a temporary key.

[0416]

[0440] The transmitting module 1720 is configured to transmit the first information to a second electronic device.

[0417]

[0441] In a possible implementation, the first information is the temporary key. The device is configured to encrypt the temporary key using a fourth public key and transmit the encrypted temporary key to the second electronic device, the fourth public key being transmitted by the second electronic device to the server.

[0418]

[0442] In a possible implementation, the temporary key is transmitted by the vehicle to the server.

[0419]

[0443] In a possible implementation, the first information is encrypted data. The smart vehicle key is configured to transmit encrypted data to the second electronic device, the encrypted data being obtained by encrypting the temporary credential and the first validity time zone using a smart vehicle key, the smart vehicle key being stored on the first electronic device, the temporary credential being generated by the first electronic device, and the first validity time zone being used to represent the validity time zone of the temporary key.

[0420]

[0444] In a possible implementation, the encrypted data is transmitted by the first electronic device to a server.

[0421]

[0445] In a possible implementation, the key retrieval request includes a temporary account, and the key retrieval request is used to request retrieval of first information corresponding to the temporary account.

[0422]

[0446] 18 is a schematic diagram of the structure of an embodiment of a communication device according to the present application. As shown in FIG. 18, the communication device 1800 may be applied to a first electronic device and may include a transmitting module 1810.

[0423]

[0447] The transmission module 1810 is configured to transmit second information in response to the detected vehicle utilization activity of the user, the second information being used to determine the temporary key.

[0424]

[0448] In a possible implementation, the transmission module 1810 is specifically configured to transmit a vehicle usage request to the vehicle in response to a detected user vehicle usage action, the vehicle usage request including a first valid time period.

[0425]

[0449] In a possible implementation, the first validity time period is encrypted using the smart vehicle key.

[0426]

[0450] In a possible implementation, the vehicle access request further includes a smart vehicle key.

[0427]

[0451] In a possible implementation, the transmitting module 1810 further: generating a temporary credential based on the smart vehicle key and the first validity time period in response to the detected vehicle usage activity of the user; and encrypting the temporary credential and the first validity time period using the smart vehicle key and sending the encrypted data to a server; The device is configured to:

[0428]

[0452] 19 is a schematic diagram of the structure of another embodiment of a communication device according to the present application. As shown in FIG. 19, the communication device 1900 is applied to a second electronic device and may include a transmitting module 1910, a receiving module 1920, and an operating module 1930.

[0429]

[0453] The sending module 1910 is configured to send a key retrieval request to the server, where the key retrieval request is used to request to retrieve first information, and the first information is used to determine a temporary key.

[0430]

[0454] The receiving module 1920 is configured to receive the first information sent by the server.

[0431]

[0455] The operation module 1930 is configured to send an operation request to the vehicle based on the first information, the operation request including the temporary key and a control instruction, the control instruction being used to operate the vehicle.

[0432]

[0456] In a possible implementation, the first information is an encrypted temporary key, the encrypted temporary key being obtained by encrypting the temporary key using a fourth public key.

[0433]

[0457] In a possible implementation, the communication device 1900 further comprises: and a decryption module configured to decrypt the encrypted temporary key by using the fourth private key to obtain the temporary key.

[0434]

[0458] In a possible implementation, the first information is encrypted data, the encrypted data is obtained by encrypting a temporary credential and a first validity time zone using a smart vehicle key, the smart vehicle key is stored on the first electronic device, the temporary credential is generated by the first electronic device, and the first validity time zone is used to represent a validity time zone of the temporary key.

[0435]

[0459] In a possible implementation, the receiving module 1920 is further configured to receive a key revocation notification, where the key revocation notification indicates that the temporary key is revoked.

[0436]

[0460] In a possible implementation, the key retrieval request further includes a temporary account, and the key retrieval request is used to request retrieval of first information corresponding to the temporary account.

[0437]

[0461] 20 is a schematic diagram of the structure of an embodiment of a communication device according to the present application. As shown in FIG. 20, the communication device 2000 is applied to a second vehicle rental platform and may include an acquisition module 2010 and a transmission module 1920.

[0438]

[0462] The obtaining module 2010 is configured to obtain a first validity time period and obtain a smart vehicle key from a server.

[0439]

[0463] The sending module 2020 is configured to encrypt the first validity time slot by using the smart vehicle key as a key, and send the encrypted first validity time slot to the vehicle.

[0440]

[0464] In a possible implementation, the communication device 2000 further comprises: Applying for a temporary account with the server, the temporary account corresponding to the temporary key; and transmitting the temporary account to the second electronic device; The device is configured to:

[0441]

[0465] In a possible implementation, the sending module 2220 is further configured to send a key revocation notification, where the key revocation notification indicates that the temporary key is revoked.

[0442]

[0466] The communication devices provided in the embodiments shown in Figures 12 to 20 can be configured to implement the technical solutions in the method embodiments shown in Figures 1 to 11 of the present application, and for the implementation principles and technical effects thereof, please refer to the relevant descriptions in the method embodiments.

[0443]

[0467] It should be understood that the division of the communication device into modules shown in Figures 11 to 20 is merely a logical functional division. In actual implementation, all or some of the modules may be integrated into one physical entity or physically separated. Furthermore, all of the modules may be implemented in the form of software called by a processing element; or in the form of hardware; or some modules may be implemented in the form of software called by a processing element and some modules in the form of hardware. For example, the detection module may be a separately located processing element or may be integrated into a chip of an electronic device for implementation. The implementation of other modules is similar to that of the detection module. Furthermore, all or some of the modules may be integrated or implemented independently. In the implementation process, the steps of the above-mentioned methods or modules may be realized by using integrated logic circuits in hardware within a processing element or by using instructions in the form of software.

[0444]

[0468] For example, the aforementioned modules may be one or more integrated circuits configured to perform the aforementioned methods, such as one or more Application Specific Integrated Circuits (ASICs for short), one or more Digital Signal Processors (DSPs) or one or more Field Programmable Gate Arrays (FPGAs), etc. As another example, the modules may be integrated together and implemented in the form of a System-On-a-Chip (SOC).

[0445]

[0469] Based on the above description of the implementation, those skilled in the art can clearly understand that for the purpose of convenient and concise description, the above division into functional modules is only used as an example for explanation. In actual application, the above functions may be allocated to different functional modules for implementation based on requirements, that is, the internal structure of the device is divided into different functional modules to implement all or part of the above functions. For the specific operation processes of the above systems, devices, and units, please refer to the corresponding processes in the above method embodiments. Details will not be described again here.

[0446]

[0470] The functional units in the embodiments of the present application may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The integrated unit may be implemented in the form of hardware or in the form of a software functional unit.

[0447]

[0471] When an integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, the integrated unit may be stored in a computer-readable storage medium. Based on this understanding, the technical solutions in the embodiments of the present application may essentially, or the part that contributes to the prior art, or all or part of the technical solutions may be implemented in the form of a software product. A computer software product is stored in a storage medium and includes several instructions for instructing a computer device (which may be a personal computer, a server, or a network device) or a processor to perform all or part of the steps of the method described in the embodiments of the present application. The aforementioned storage medium includes any medium capable of storing program code, such as a flash memory, a removable hard disk, a read-only memory, a random access memory, a magnetic disk, or an optical disk.

[0448]

[0472] The above description is merely a specific implementation of the present application and is not intended to limit the scope of protection of the present application. Any modifications or substitutions within the technical scope disclosed in the present application shall fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be subject to the scope of protection of the claims.

Claims

1. A communication method applied to a vehicle, the vehicle including a smart vehicle key, the smart vehicle key being electronic key information used to control the vehicle, the method comprising: determining key credentials based on the smart vehicle key; and sending the key credential information to a server; A method comprising:

2. 10. The method of claim 1, wherein determining key credentials based on the smart vehicle key comprises: encrypting the smart vehicle key by using the smart vehicle key as a key to obtain the key credential; A method comprising:

3. 10. The method of claim 1, wherein the vehicle further includes vehicle identification information corresponding to the vehicle, and wherein determining key credential information based on the smart vehicle key comprises: signing the smart vehicle key and the vehicle identification information by using a first private key to obtain signature data; obtaining a second public key and encrypting the signature data, the smart vehicle key, and the vehicle identification information using the second public key to obtain a first ciphertext, wherein the second public key is sent by the server to the vehicle; and generating the key credential based on the first ciphertext and a first public key, the first public key corresponding to the first private key; A method comprising:

4. 4. The method of claim 3, wherein: The method further includes a step of sending a first certificate to the server, the first certificate including the vehicle identification information and the first public key, the first certificate being signed by a third party and then issued to the vehicle, and the first certificate being used to verify the first public key.

5. 4. The method of claim 3, wherein: verifying the second public key based on a second certificate; The method further comprises:

6. 6. The method of claim 5, prior to the step of verifying the second public key based on a second certificate, the method further comprising: The method further includes receiving the second certificate sent by the server, the second certificate including the server's identification information and the second public key, and the second certificate is signed by a third party and then issued to the server.

7. 10. The method of claim 6, wherein the vehicle has pre-stored a root certificate, the root certificate being used to verify certificates, and after receiving the second certificate sent by the server: performing signature verification on the second certificate based on the root certificate; The method further comprises:

8. 6. The method of claim 5, wherein the second certificate is pre-configured in the vehicle.

9. 4. The method of claim 3, wherein the first public key and the first private key are generated in a security module of the vehicle.

10. 10. The method of any one of claims 1 to 9, wherein the smart vehicle key is generated in a factory mode of the vehicle.

11. 10. The method according to any one of claims 1 to 9, wherein: periodically updating the key credential information based on the smart vehicle key; and sending updated key credential information to the server; The method further comprises:

12. 12. The method of claim 11, after the step of sending updated key credential information to the server: sending a key update prompt to a first electronic device to prompt a user to update the smart vehicle key; The method further comprises:

13. 10. The method according to any one of claims 1 to 9, wherein: receiving a key update request sent by a first electronic device, the key update request being used to request generation of a new smart vehicle key; determining new key credentials based on the new smart vehicle key; and sending the new key credential information to the server; The method further comprises:

14. 14. The method of claim 13, wherein the key update request includes an old smart vehicle key, and prior to determining new key credentials based on the new smart vehicle key: performing authentication on the old smart vehicle key; The method further comprises:

15. 15. The method according to claim 13 or 14, wherein: deleting the old smart vehicle key in the vehicle when successful authentication of the first electronic device's request to use the new smart vehicle key is detected; The method further comprises:

16. A communication method applied to a server, comprising: receiving key credential information; and performing secure storage of said key credential information, said secure storage being performed by using secure cryptographic means; A method comprising:

17. 17. The method of claim 16, wherein the key credential includes a first ciphertext and a first public key, and wherein performing secure storage on the key credential includes: decrypting the first ciphertext by using a second private key to obtain signature data, a smart vehicle key, and vehicle identification information; performing signature verification on the signature data by using the first public key; and if the signature verification is successful, performing secure storage for the smart vehicle key and the vehicle identification information; A method comprising:

18. 18. The method of claim 17, wherein: obtaining a third public key and encrypting the smart vehicle key by using the third public key to obtain an encrypted smart vehicle key, wherein the third public key is sent by the first electronic device to the server; and transmitting the encrypted smart vehicle key to the first electronic device; The method further comprises:

19. 20. The method of claim 18, prior to the step of transmitting the encrypted smart vehicle key to the first electronic device, the method further comprising: receiving a registration request, the registration request including a user account and vehicle identification information corresponding to the user account; and creating the user account based on the registration request, the user account corresponding to the smart vehicle key and the vehicle identification information; The method further comprises:

20. 18. The method of claim 17, wherein: The method further includes the step of sending a second certificate to the vehicle, the second certificate including the server's identification information and a second public key, the second certificate being signed by a third party and then issued to the server, and the second certificate being used to verify the second public key.

21. 18. The method of claim 17, wherein: verifying the first public key based on a first certificate; A method comprising:

22. 22. The method of claim 21, prior to verifying the first public key based on a first certificate, the method further comprising: The method further includes receiving the first certificate sent by the vehicle, the first certificate including the vehicle identification information and the first public key, and the first certificate being signed by a third party and then issued to the vehicle.

23. 23. The method of claim 22, wherein the server pre-stores a root certificate, the root certificate being used to verify certificates, and after verifying the first public key based on the first certificate, the method includes: performing signature verification on the first certificate based on the root certificate; The method further comprises:

24. 22. The method of claim 21, wherein the first certificate is pre-configured on the server.

25. 20. The method of claim 17, wherein the first public key is generated in a security module of a vehicle.

26. 26. The method of any one of claims 17 to 25, wherein the smart vehicle key is generated in a factory mode of the vehicle.

27. 26. The method of any one of claims 16 to 25, after the step of receiving key credentials: periodically receiving the key credential information and periodically updating the key credential information; The method further comprises:

28. 28. The method of claim 27, after the step of periodically receiving key credential information: sending a key update prompt to a first electronic device to prompt a user to update the smart vehicle key; The method further comprises:

29. 26. The method of any one of claims 16 to 25, comprising: receiving a credential update instruction, the credential update instruction instructing the key credential information to be updated, the credential update instruction including new key credential information; and updating the key credential information based on the credential update instruction; A method comprising:

30. 30. The method of claim 29, wherein the key credential update instruction further includes an old smart vehicle key, the old smart vehicle key being stored on the server, and the new key credential information includes a new smart vehicle key, and prior to updating the key credential information based on the credential update instruction: performing authentication on the old smart vehicle key; The method further comprises:

31. 31. The method of claim 30, if it is detected that authentication regarding the new key credential is successful, storing the new key credential and deleting the old key credential; The method further comprises:

32. 1. A communication method applied to a vehicle, comprising: transmitting a random value to the first electronic device; receiving a first control message transmitted by the first electronic device, the first control message being generated based on a smart vehicle key and the random value; and verifying the first control message based on the smart vehicle key and the random value, and controlling the vehicle based on the first control message if the verification is successful; A method comprising:

33. 33. The method of claim 32, wherein the step of validating the first control message based on the smart vehicle key and the random value comprises: generating a second control message based on the smart vehicle key and the random value; and comparing the first control message with the second control message; and if the check is successful, controlling the vehicle based on the first control message comprises: controlling the vehicle based on the first control message if the first control message matches the second control message; A method comprising:

34. 1. A communication method applied to a first electronic device, comprising: receiving a random value transmitted by the vehicle; obtaining a smart vehicle key and generating a first control message based on the smart vehicle key and the random value, the first control message being used to control the vehicle; and transmitting the first control message to the vehicle; A method comprising:

35. 35. The method of claim 34, wherein the first control message is generated in a trusted execution environment (TEE).

36. 35. The method of claim 34, wherein the step of obtaining the smart vehicle key comprises: receiving an encrypted smart vehicle key sent by a server, the encrypted smart vehicle key being obtained by the server by encrypting the smart vehicle key using a third public key, the third public key being sent by the first electronic device to the server; and decrypting the encrypted smart vehicle key by using a third private key to obtain the smart vehicle key; A method comprising:

37. 37. The method of claim 36, wherein the third public key and the third private key are generated in a trusted execution environment (TEE) of the first electronic device.

38. 37. The method of claim 36, wherein decrypting the encrypted smart vehicle key using a third private key to obtain the smart vehicle key comprises: decrypting the encrypted smart vehicle key using the third private key in a trusted execution environment (TEE) of the first electronic device to obtain the smart vehicle key; and After the step of decrypting the encrypted smart vehicle key by using a third private key to obtain the smart vehicle key, the method includes: storing the smart vehicle key in a trusted execution environment (TEE) of the first electronic device; The method further comprises:

39. 39. The method of any one of claims 36 to 38, prior to the step of receiving the encrypted smart vehicle key transmitted by the server: The method further comprising sending a key request to the server, the key request including a user account, the key request being used to obtain a smart vehicle key corresponding to the user account.

40. 35. The method of claim 34, wherein the method comprises: sending a key update request to the vehicle, the key update request being used to generate a new smart vehicle key; and obtaining the new smart vehicle key from a server; The method further comprises:

41. 41. The method of claim 40, after the step of obtaining the new smart vehicle key from a server, the method further comprising: performing authentication with respect to the vehicle by using the new smart vehicle key; and If the authentication is successful, deleting the old smart vehicle key in the first electronic device; The method further comprises:

42. 1. A communication method applied to a vehicle, comprising: obtaining an operation request sent by a second electronic device, the operation request including a temporary key and a control command; verifying the temporary key; performing a time validity check based on a first validity time zone, the first validity time zone being used to represent a validity time zone of the temporary key, the first validity time zone being stored in a security module of the vehicle; and operating the vehicle based on the control command of the second electronic device if the temporary key check is successful and the time validity check is successful; A method comprising:

43. 43. The method of claim 42, prior to the step of obtaining the action request sent by the second electronic device, the method further comprising: obtaining a vehicle use request, the vehicle use request including the first validity time period; generating the temporary key based on the first validity period; and sending the temporary key to a server; The method further comprises:

44. 44. The method of claim 43, wherein the vehicle use request is transmitted by the first electronic device using a short-range communication method.

45. 44. The method of claim 43, wherein the vehicle use request is transmitted by the first electronic device over a mobile network.

46. 44. The method of claim 43, wherein the vehicle use request is transmitted by a vehicle rental platform.

47. 44. The method of claim 43, wherein the vehicle use request further includes a signed smart vehicle key, and the signed smart vehicle key is obtained by signing the smart vehicle key with a third private key, and after obtaining the vehicle use request, the method comprises: The method further comprising performing a signature verification on the smart vehicle key based on a third public key, the third public key being transmitted by the first electronic device to the vehicle.

48. 48. The method of claim 47, The method further includes sending a first certificate to the first electronic device, the first certificate including vehicle identification information and a first public key, the first certificate being signed by a third party and then issued to the vehicle, and the first certificate being used to verify the first public key.

49. 48. The method of claim 47, verifying the third public key based on a third certificate; The method further comprises:

50. 50. The method of claim 49, prior to the step of verifying the third public key based on a third certificate: The method further includes receiving the third certificate sent by the first electronic device, the third certificate including identification information of the first electronic device and the third public key, and the third certificate being signed by a third party and then issued to the first electronic device.

51. 51. The method of claim 50, wherein the vehicle has pre-stored a root certificate, the root certificate being used to verify certificates, and after receiving the third certificate sent by the first electronic device, the method comprises: performing signature verification on the third certificate based on the root certificate; The method further comprises:

52. 48. The method of claim 47, wherein the first validity time period is encrypted using the smart vehicle key, and after authentication is performed using the smart vehicle key, the method comprises: decrypting the encrypted first validity time slot by using the smart vehicle key and performing secure storage for the decrypted first validity time slot; The method further comprises:

53. 43. The method of claim 42, receiving encrypted data sent by the second electronic device, the encrypted data being obtained by encrypting a temporary credential and the first validity time period with a smart vehicle key, the smart vehicle key being stored on the first electronic device, and the temporary credential being generated by the first electronic device; decrypting the encrypted data using the smart vehicle key to obtain the temporary credential and the first validity time period; verifying the temporary credential and the first validity time period; generating the temporary key if the check is successful; and encrypting the temporary key based on the encrypted data to obtain an encrypted temporary key, and sending the encrypted temporary key to the second electronic device; The method further comprises:

54. 54. The method of claim 53, after the step of generating the temporary key: performing secure storage for said first validity time period; The method further comprises:

55. 54. The method of claim 53, wherein the temporary credential is generated based on the smart vehicle key and the first validity time period, and the encrypted data is transmitted by the first electronic device to a server.

56. 43. The method of claim 42, wherein the operation request includes an encrypted temporary key, the encrypted temporary key being obtained after being encrypted with a first public key, and prior to the step of verifying the temporary key, the method comprises: decrypting the encrypted temporary key using a first private key to obtain the temporary key; The method further comprises:

57. 57. The method of claim 56, The method further includes sending a first certificate to the second electronic device, the first certificate including vehicle identification information and a first public key, the first certificate being signed by a third party and then issued to the vehicle, and the first certificate being used to verify the first public key.

58. 57. The method of claim 56, The method further comprising verifying the fourth public key based on a fourth certificate, wherein the fourth public key is transmitted by the second electronic device to the vehicle.

59. 59. The method of claim 58, prior to the step of verifying the fourth public key based on a fourth certificate: The method further includes receiving the fourth certificate sent by the second electronic device, the fourth certificate including identification information of the second electronic device and the fourth public key, and the fourth certificate being signed by the third party and then issued to the second electronic device.

60. 60. The method of claim 59, wherein the vehicle has pre-stored a root certificate, the root certificate being used to verify certificates, and after receiving the fourth certificate sent by the second electronic device, the method comprises: performing signature verification on the fourth certificate based on the root certificate; The method further comprises:

61. 61. The method of any one of claims 42 to 60, wherein the step of verifying the temporary key comprises: transmitting the random value to a second electronic device; receiving a first control message transmitted by the second electronic device, the first control message being generated based on the temporary key and the random value; and performing a temporary key check on the first control message based on the temporary key and the random value; A method comprising:

62. 61. The method of any one of claims 42 to 60, comprising: The method, further comprising sending a key revocation notification to the second electronic device, the key revocation notification indicating that the temporary key is revoked.

63. 63. The method of claim 62, prior to the step of sending a key revocation notification to the second electronic device: setting the temporary key to be invalid when it is detected that the current system time is beyond the first validity time period; The method further comprises:

64. 61. The method of any one of claims 42 to 60, comprising: if the time validity check fails, notifying the user that the temporary key has expired; The method further comprises:

65. A communication method applied to a server, comprising: receiving a key retrieval request sent by a second electronic device, the key retrieval request being used to request obtaining first information, the first information being used to determine a temporary key; and transmitting the first information to the second electronic device; A method comprising:

66. 66. The method of claim 65, wherein the first information is the temporary key, and the step of transmitting the first information to the second electronic device includes: encrypting the temporary key using a fourth public key and sending the encrypted temporary key to the second electronic device, the fourth public key being sent by the second electronic device to the server; A method comprising:

67. 67. The method of claim 66, wherein the temporary key is transmitted to the server by a vehicle.

68. 66. The method of claim 65, wherein the first information is encrypted data, and wherein transmitting the first information to the second electronic device comprises:

11. A method for transmitting encrypted data to the second electronic device, wherein the encrypted data is obtained by encrypting a temporary credential and a first validity time zone using a smart vehicle key, the smart vehicle key being stored on a first electronic device, the temporary credential being generated by the first electronic device, and the first validity time zone being used to represent a validity time zone of the temporary key.

69. 69. The method of claim 68, wherein the encrypted data is transmitted by the first electronic device to the server.

70. 70. The method of any one of claims 65 to 69, wherein the key retrieval request includes a temporary account, and the key retrieval request is used to request retrieval of the first information corresponding to the temporary account.

71. 1. A communication method applied to a first electronic device, comprising: transmitting second information in response to the detected user vehicle utilization activity, the second information being used to determine a temporary key; A method comprising:

72. 72. The method of claim 71, wherein the step of transmitting the second information in response to the detected vehicle-utilizing activity of the user includes: transmitting a vehicle utilization request to a vehicle in response to the detected vehicle utilization action of the user, the vehicle utilization request including a first validity time period; A method comprising:

73. 73. The method of claim 72, wherein the first validity period is encrypted using a smart vehicle key.

74. 73. The method of claim 71 or 72, wherein the vehicle access request further includes a smart vehicle key.

75. 72. The method of claim 71, wherein the step of transmitting the second information in response to the detected vehicle-utilizing activity of the user includes: generating a temporary credential based on the smart vehicle key and the first validity time period in response to the detected user vehicle usage activity; and encrypting the temporary credential and the first validity time period using the smart vehicle key and sending the encrypted data to a server; A method comprising:

76. A communication method applied to a second electronic device, comprising: sending a key retrieval request to a server, the key retrieval request being used to request retrieval of first information, the first information being used to determine a temporary key; receiving the first information sent by the server; and sending an operation request to the vehicle based on the first information, the operation request including the temporary key and a control command, the control command being used to operate the vehicle; A method comprising:

77. 77. The method of claim 76, wherein the first information is an encrypted temporary key, and the encrypted temporary key is obtained by encrypting the temporary key using a fourth public key, and after receiving the first information sent by the server, the method comprises: decrypting the encrypted temporary key using the fourth private key to obtain the temporary key; The method further comprises:

78. 77. The method of claim 76, wherein the first information is encrypted data, the encrypted data being obtained by encrypting a temporary credential and a first validity time zone using a smart vehicle key, the smart vehicle key being stored on a first electronic device, the temporary credential being generated by the first electronic device, and the first validity time zone being used to represent a validity time zone of the temporary key.

79. 77. The method of claim 76, The method further comprising receiving a key revocation notification, the key revocation notification indicating that the temporary key is revoked.

80. 80. The method of any one of claims 76 to 79, wherein the key retrieval request further includes a temporary account, and the key retrieval request is used to request retrieval of the first information corresponding to the temporary account.

81. 1. A method applied to a vehicle rental platform, comprising: obtaining a first valid time slot; Obtaining a smart vehicle key from a server; and encrypting the first validity time slot using the smart vehicle key as a key and transmitting the encrypted first validity time slot to the vehicle; A method comprising:

82. 82. The method of claim 81 : Applying for a temporary account from a server, the temporary account corresponding to a temporary key; and transmitting the temporary account to a second electronic device; The method further comprises:

83. 83. The method of claim 82: The method, further comprising the step of sending a key revocation notification, the key revocation notification indicating that the temporary key is revoked.

84. A vehicle including a processor and a memory, the memory configured to store a computer program, the processor executing the computer program to: Implementing a communication method according to any one of claims 1 to 15, or Implementing a communication method according to any one of claims 32 to 33, or A vehicle configured to implement a communication method according to any one of claims 42 to 64.

85. A server including a processor and a memory, the memory configured to store a computer program, the processor executing the computer program to: Implementing a communication method according to any one of claims 16 to 31, or A server configured to implement the communication method of any one of claims 65 to 70.

86. A first electronic device including a processor and a memory, the memory configured to store a computer program, the processor executing the computer program to: Implementing a communication method according to any one of claims 34 to 41, or 76. A first electronic device configured to implement a communication method according to any one of claims 71 to 75.

87. 81. A second electronic device comprising a processor and a memory, the memory configured to store a computer program, and the processor configured to execute the computer program to implement the communication method of any one of claims 76 to 80.

88. 84. A vehicle rental platform comprising a processor and a memory, wherein the memory is configured to store a computer program, and wherein the processor is configured to execute the computer program to implement the communication method of any one of claims 81 to 83.

89. 84. A computer-readable storage medium storing a computer program which, when run on a computer, performs the communication method of any one of claims 1 to 83.

Citation Information

Patent Citations

  • Method and device for authorizing vehicle based on Bluetooth, and computer storage medium

    CN112105000A

  • Vehicle virtual key sharing method, mobile terminal, server and vehicle

    CN113766450A

  • Virtual vehicle key

    EP2743868A1

  • Key service method, system and its program

    JP2006233475A

  • Vehicle key management device, vehicle key management system, and vehicle key management method

    JP2019116791A