Key System

The key system addresses security vulnerabilities in digital key systems by generating and authenticating vehicle access based on usage count and time, ensuring secure and dynamic key management.

JP2026055994APending Publication Date: 2026-04-01AISIN CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-19
Publication Date
2026-04-01

AI Technical Summary

Technical Problem

Existing digital key systems lack robust security measures, allowing unauthorized access and potential misuse due to the lack of key updates and reliance on pre-registered unique keys, making them vulnerable to malicious actors.

Method used

A key system that generates digital keys and encryption keys based on usage count and time, utilizing a vehicle-side and server-side password acquisition and generation units, along with a determination unit to authenticate and authorize vehicle use, enhancing security through dynamic key information generation and comparison.

Benefits of technology

The system provides enhanced security by ensuring that only authorized users can access vehicles, reducing the need for physical keys and minimizing unauthorized access by using dynamic key information and periodic updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026055994000001_ABST
    Figure 2026055994000001_ABST
Patent Text Reader

Abstract

We provide a highly secure key system. [Solution] The key system 1 includes a vehicle-side password acquisition unit 21 that acquires a password, a vehicle-side key information generation unit 22 that generates key information based on the password and a key generation algorithm, a mobile terminal-side password acquisition unit 31 that acquires a password, a management unit-side password acquisition unit 42 that acquires a password from a mobile terminal 3, a management unit-side key information generation unit 43 that generates key information based on the password and a key generation algorithm, a mobile terminal-side key information acquisition unit 32 that acquires the key information generated by the management unit-side key information generation unit 43, a mobile terminal-side key information transmission unit 33 that transmits the key information acquired by the mobile terminal-side key information acquisition unit 32 to the vehicle 2, and a determination unit 23 that compares the key information generated by the vehicle-side key information generation unit 22 with the key information transmitted from the mobile terminal 3 to determine whether or not the vehicle 2 can be used.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a key system that generates a digital key that enables the use of a vehicle, and an encryption key used for encrypting the digital key and decrypting the encrypted digital key.

Background Art

[0002] In recent years, the use of vehicles with digital keys has been spreading. As a technology related to such digital keys, for example, there is one described in Patent Document 1 whose citation is shown below.

[0003] Patent Document 1 describes a sharing system. In this sharing system, a plurality of authentication device-specific keys used for authenticating key information are pre-registered in a vehicle authentication device, and a mobile terminal of a user who uses the vehicle acquires key information with one of the plurality of authentication device-specific keys. When the encrypted key information can be decrypted by the vehicle, the mobile terminal is configured to permit the operation of the vehicle.

[0004] The key information is created by the server, and after user authentication is performed, information such as a reservation date and time and a permission function is encrypted using the above-described specific key. It is also possible to limit the use period and functions according to the information included in the key information. When sharing the key with another user, the main user encrypts it using another specific key in the same manner as above, and by performing transmission via a network and authentication with the vehicle, it is configured to be able to perform the operation of the same vehicle. In a state where a plurality of users can operate the vehicle in this way, the mobile terminals are identified by the terminal IDs held by each mobile terminal. Also, in the creation of key information, when user authentication fails, the authentication process is forcibly terminated, and when decryption of the key information fails in the vehicle, the connection with the vehicle is configured to be disconnected.

Prior Art Documents

Patent Documents

[0005] [Patent Document 1] Japanese Patent Publication No. 2019-105881 [Overview of the project] [Problems that the invention aims to solve]

[0006] In the sharing system described in Patent Document 1, the unique key used for authentication of key information (whether decryption is possible with the unique key) is pre-registered, and the system is not configured to update this unique key. Therefore, for example, a malicious actor could randomly create key information and attempt to access the vehicle. Furthermore, if the system receives advertisements periodically transmitted from the vehicle and performs short-range wireless communication via a predetermined sequence, it becomes easy to access the vehicle. For these reasons, the sharing system described in Patent Document 1 has room for improvement in terms of enhancing security.

[0007] Therefore, a highly secure key system is required. [Means for solving the problem]

[0008] The key system according to the present invention is a key system that generates a digital key that enables the use of a vehicle and an encryption key used for encrypting the digital key and decrypting the encrypted digital key, comprising: a vehicle-side password acquisition unit provided in the vehicle that acquires a password set with at least one of the number of uses and usage time; a vehicle-side key information generation unit provided in the vehicle that generates key information including the digital key and the encryption key based on the password and a key generation algorithm; a mobile terminal-side password acquisition unit provided in the mobile terminal of a user of the vehicle that acquires the password; and a management unit that manages the vehicle, which acquires the mobile terminal The system comprises: a management unit-side password acquisition unit that acquires the password from the end; a management unit-side key information generation unit provided in the management unit that generates the key information based on the password and the key generation algorithm; a mobile terminal-side key information acquisition unit provided in the mobile terminal that acquires the key information generated by the management unit-side key information generation unit; a mobile terminal-side key information transmission unit provided in the mobile terminal that transmits the key information acquired by the mobile terminal-side key information acquisition unit to the vehicle; and a determination unit provided in the vehicle that compares the key information generated by the vehicle-side key information generation unit with the key information transmitted from the mobile terminal to determine whether or not the vehicle can be used.

[0009] With this configuration, key information is generated based on a password that includes at least one of the usage count and usage time, eliminating the need to possess a physical key for each vehicle. Furthermore, by generating key information including a digital key and an encryption key based on a password that includes at least one of the usage count and usage time, and determining whether the vehicle can be used based on whether the digital key matches, security can be enhanced. [Brief explanation of the drawing]

[0010] [Figure 1] This is a diagram showing the configuration of the key system. [Figure 2] This diagram shows the processing of the key system. [Figure 3]This figure illustrates the registration of a key generation algorithm according to another embodiment. [Figure 4] This figure illustrates the registration of a key generation algorithm according to another embodiment. [Modes for carrying out the invention]

[0011] The key system according to the present invention generates a digital key that enables the use of a vehicle, and an encryption key used for encrypting the digital key and decrypting the encrypted digital key. The system is configured to allow the owner of the mobile terminal to use the vehicle based on the result of comparing the digital key generated in the vehicle with the digital key obtained by the user's mobile terminal (e.g., smartphone) from the management unit that manages the vehicle. Below, an example will be given in which the key system generates a digital key and an encryption key in a car-sharing system where one vehicle can be used by multiple people. The key system 1 of this embodiment will be described below. However, the key system 1 is not limited to the following embodiment, and various modifications are possible without departing from the gist of the system.

[0012] Figure 1 is a schematic block diagram showing the configuration of Key System 1. Figure 2 is a diagram showing the processing of Key System 1. As shown in Figures 1 and 2, Key System 1 consists of a vehicle 2, a mobile terminal 3, and a server 4 (an example of a "management unit").

[0013] Vehicle 2 in this embodiment is equipped with a password generation unit 10, a vehicle-side password acquisition unit 21, a vehicle-side key information generation unit 22, a determination unit 23, a control unit 24, and a vehicle-side storage unit 25. Mobile terminal 3 in this embodiment is equipped with a mobile terminal-side password acquisition unit 31, a mobile terminal-side key information acquisition unit 32, a mobile terminal-side key information transmission unit 33, and a mobile terminal-side storage unit 34. Server 4 in this embodiment (an example of a "management unit") is equipped with a usage information acquisition unit 41, a server-side password acquisition unit 42 (an example of a "management unit-side password acquisition unit"), a server-side key information generation unit 43 (an example of a "management unit-side key information generation unit"), and a server-side storage unit 44 (an example of a "management unit-side storage unit"). Each of these functional units is constructed with a CPU as the core component, either in hardware, software, or both, to perform processing related to the generation of digital keys and encryption keys.

[0014] When using vehicle 2, the user using vehicle 2 performs a usage procedure via mobile terminal 3 (#1). The user is a pre-registered user, and the usage procedure is a procedure performed after user authentication. In other words, not just any user can perform the usage procedure. This usage procedure may be configured to be performed using a dedicated application or using a web browser. In the usage procedure, the user inputs at least one of the following, associated with an ID that can identify the user (user ID): information indicating the usage period of vehicle 2 and information indicating functional limitations. The information indicating the usage period includes the period during which the user wishes to use vehicle 2, and the information indicating functional limitations includes, for example, information that limits the driving speed of vehicle 2. The usage procedure may also be configured to accept input of information other than these.

[0015] Various information entered during the user procedure on the mobile terminal 3 is acquired via the network by the user information acquisition unit 41 of the server 4 and registered as key information associated with the ID (#2). In this embodiment, the key information is stored in the server-side storage unit 44 of the server 4.

[0016] After the registration is completed, the user is prompted to perform short-range wireless communication between a predetermined part of the vehicle 2 (for example, a door handle, a door mirror, etc.) and the mobile terminal 3 (#3). This can be configured to display a message prompting the implementation of short-range wireless communication (for example, NFC (Near Field Communication) communication) on the display of the mobile terminal 3 when the usage procedure is performed.

[0017] When the short-range wireless communication is performed, the password generation unit 10 generates a password in which at least one of the number of uses and the usage time is set (#4). The password is used for generating a digital key as will be described later. From the viewpoint of enhancing security, at least one of the number of uses and the usage time of this password is preset. The password may be a so-called one-time password. In the present embodiment, the password generation unit 10 generates a random number by a random number generator and generates a password consisting of a character string of an arbitrary length.

[0018] The vehicle-side password acquisition unit 21 acquires the password generated by the password generation unit 10. This password is stored in the vehicle-side storage unit 25.

[0019] The password acquired by the vehicle-side password acquisition unit 21 is transmitted to the mobile terminal 3 via short-range wireless communication (for example, NFC communication) (#5). This password is acquired by the mobile terminal-side password acquisition unit 31. The password acquired by the mobile terminal-side password acquisition unit 31 is stored in the mobile terminal-side storage unit 34.

[0020] The password acquired by the mobile terminal-side password acquisition unit 31 is transmitted to the server 4 via the network (#6). The password transmitted from the mobile terminal 3 is acquired by the server-side password acquisition unit 42. The password acquired by the server-side password acquisition unit 42 is stored in the server-side storage unit 44.

[0021] The server-side key information generation unit 43 generates key information based on a password and a key generation algorithm (#7). The password used is the one acquired by the server-side password acquisition unit 42. This password is the same as the one generated (acquired) by the mobile terminal side password acquisition unit 31 of the mobile terminal 3 by the vehicle side password acquisition unit 21. The key generation algorithm is a program that generates key information including a digital key and key information. When the vehicle 2 and the server 4 use a mutually common key generation algorithm and use a mutually common password, they are configured to be able to generate the same key information. In the present embodiment, the key generation algorithm is acquired by the server 4 from an algorithm management unit that manages a key generation algorithm (not shown) via a network. Of course, the key generation algorithm may be stored in the server 4 in advance. Note that different key generation algorithms are used for each vehicle.

[0022] The key information generated by the server-side key information generation unit 43 is registered as key information (#8). In the present embodiment, the key information is stored in the server-side storage unit 44 provided in the server 4. As described above, the key information includes at least one of usage information regarding the use of the vehicle 2, specifically, information indicating the usage period of the vehicle 2 and information indicating functional constraints, and is registered in advance. This key information further includes connection information that enables the mobile terminal 3 described later to connect to the vehicle 2, a digital key, and an encryption key.

[0023] The key information generated by the server-side key information generation unit 43 is sent to the mobile terminal 3 via the network (#9). The key information sent from the server 4 is acquired by the mobile terminal side key information acquisition unit 32. The key information acquired by the mobile terminal side key information acquisition unit 32 is stored in the mobile terminal side storage unit 34 of the mobile terminal 3.

[0024] When the user of mobile terminal 3 obtains key information from server 4, it establishes a short-range wireless connection with vehicle 2 based on the connection information contained in the key information (#10). The connection information includes a connection password for mobile terminal 3 to connect with vehicle 2. By using such a connection password during connection, mobile terminal 3 can connect with vehicle 2. Short-range wireless communication can be, for example, using Bluetooth (registered trademark). In such a connection, vehicle 2 can make an advertisement transmission, and when mobile terminal 3 communicates via Bluetooth, the Bluetooth communication can be established based on the connection information generated based on the password.

[0025] When vehicle 2 connects to mobile terminal 3 via short-range wireless communication, the vehicle-side key information generation unit 22 generates key information based on the password and key generation algorithm (#11). The password is the password generated (obtained) by the vehicle-side password acquisition unit 21. The key generation algorithm is the same as the key generation algorithm used by server 4 to generate key information. Although server 4 obtained this key generation algorithm via the network from the algorithm management unit that manages the key generation algorithm, vehicle 2 has this key generation algorithm stored in it beforehand. The key information generated by the vehicle-side key information generation unit 22 is stored in the vehicle-side storage unit 25.

[0026] Furthermore, when the mobile terminal 3 and the vehicle 2 are connected via short-range wireless communication, the mobile terminal-side key information transmission unit 33 transmits the key information acquired by the mobile terminal-side key information acquisition unit 32 to the vehicle 2 (#12). At this time, at least a digital key is transmitted as key information. The key information transmitted by the mobile terminal-side key information transmission unit 33 is stored in the vehicle-side storage unit 25.

[0027] Furthermore, in this embodiment, as described above, the key information generated by the server-side key information generation unit 43 includes usage information related to the use of the vehicle 2. This usage information is transmitted to the vehicle 2 via the mobile terminal-side key information transmission unit 33 and registered in the vehicle 2. That is, the usage information, along with the digital key described above, is also stored in the vehicle-side storage unit 25.

[0028] When key information is transmitted to vehicle 2, the determination unit 23 compares the key information generated by the vehicle-side key information generation unit 22 with the key information transmitted from the mobile terminal 3 to determine whether vehicle 2 can be used. The determination unit 23 decrypts the digital key contained in the key information transmitted from the mobile terminal-side key information transmission unit 33, which is stored in the vehicle-side storage unit 25, using the encryption key contained in the key information generated by the vehicle-side key information generation unit 22, which is stored in the vehicle-side storage unit 25. The decrypted digital key is then compared with the digital key contained in the key information generated by the vehicle-side key information generation unit 22, which is stored in the vehicle-side storage unit 25. If the digital keys match, the use of vehicle 2 is authenticated (permitted) (#13). In this case, vehicle 2 sends a notification to the mobile terminal 3 indicating that registration has been completed (#14). On the other hand, if the digital keys do not match, the use of vehicle 2 is not permitted. In this case, vehicle 2 sends a notification to the mobile terminal 3 indicating that registration could not be completed.

[0029] Thus, with this key system 1, authentication / registration is performed based on whether or not the key generated from a random number matches, thereby enhancing security. Furthermore, by using a technology to issue digital keys to vehicle 2 via short-range wireless communication, a device for managing digital keys is unnecessary. In addition, by using a technology to issue digital keys using a common password between vehicle 2 and server 4, a communication terminal in vehicle 2 is unnecessary, resulting in lower costs.

[0030] In this embodiment, the vehicle 2 is equipped with a control unit 24, which has functions that can further enhance the security of the key system 1. Specifically, it is configured to stop password generation for a certain period of time when the number of times a password obtained by the vehicle-side password acquisition unit 21 is generated per certain period of time reaches a specified number, to initialize the key information when authentication is not completed within the expiration date and number of valid authentications set in the key information, and to initialize all information when the usage period of the vehicle 2 included in the usage information is exceeded.

[0031] As described above, the password obtained by the vehicle-side password acquisition unit 21 has a set number of uses. When the number of times this password has been used reaches the set number of uses, the password becomes unusable. At this time, even if an attempt is made to generate a new password, the system is configured to prevent password generation for a certain period of time. Therefore, when the number of passwords generated per certain period of time reaches a specified number of generations, the control unit 24 suspends password generation for a certain period of time. This makes it possible to prevent unauthorized use of the vehicle 2 by, for example, someone trying to illegally obtain the password or someone trying to illegally obtain and use the password.

[0032] Furthermore, the key information generated by the server-side key information generation unit 43 has an expiration date and a set number of valid authentication uses. The key information is configured to be initialized when the time elapsed since the key information was issued reaches its expiration date, or when the number of times it has been used for authentication reaches the valid authentication use limit. The control unit 24 performs the initialization of the key information when the time elapsed since the key information was issued reaches its expiration date, or when the number of times it has been used for authentication reaches the valid authentication use limit. This allows the key information to be updated periodically, thereby improving security.

[0033] Furthermore, the key information includes usage information, which contains the usage period for vehicle 2 registered during the usage procedure. When the usage period for vehicle 2 exceeds the usage period registered during the usage procedure, the control unit 24 initializes the password and all information contained in the key information. As a result, vehicle 2 becomes unusable, prompting the user to renew their usage registration.

[0034] [Other Embodiments] Next, other embodiments of the key system 1 will be described.

[0035] In the above embodiment, the key generation algorithm was described as being obtained by the server 4 via the network from an algorithm management unit that manages key generation algorithms (not shown). It is also possible to configure the server 4 to create the key generation algorithm instead of obtaining it directly.

[0036] Figure 3 shows how Server 4 creates the key generation algorithm. Vehicle 2 is pre-equipped with a key generation algorithm. Short-range wireless communication is performed between a designated part of Vehicle 2 and a mobile terminal 3 (#21). Through this short-range wireless communication, vehicle-specific information is transmitted from Vehicle 2 to the mobile terminal 3 (#22), and the vehicle-specific information is stored in the mobile terminal 3 (#23). The vehicle-specific information is transmitted from the mobile terminal 3 to Server 4 via the network (#24). Server 4 obtains a base algorithm, which is the basis of the key generation algorithm, via the network (#25). This base algorithm may be of a single type, regardless of Vehicle 2. Server 4 creates a key generation algorithm from the obtained base algorithm and the vehicle-specific information (#26). Since the key generation algorithm created in this way is based on the vehicle-specific information obtained from Vehicle 2, even if there are multiple Vehicle 2s, a key generation algorithm corresponding to each Vehicle 2 can be created. In addition, although Vehicle 2 is pre-equipped with the key generation algorithm created in this way, it is the same as the key generation algorithm created by Server 4. Of course, vehicle 2 can also be configured, if necessary, to create a key generation algorithm based on a base algorithm and vehicle-specific information, similar to server 4.

[0037] It is also possible to create a key generation algorithm in the form shown in Figure 4. In the example in Figure 4, a common key generation algorithm is stored. A common key generation algorithm is not a unique key generation algorithm for each vehicle 2, but a key generation algorithm that is used in common by multiple vehicles 2. On the other hand, Server 4 obtains the vehicle management application and the common key generation algorithm via the network. The vehicle management application is an application used by Server 4 to manage the vehicles 2 under its management. The common key generation algorithm is the same as the key generation algorithm stored in Vehicle 2. Note that obtaining the vehicle management application and the common key generation algorithm does not have to be simultaneous.

[0038] In this situation, vehicle 2 obtains generation information from a generation medium 50, such as a mobile terminal or an NFC card, via short-range wireless communication (#51). The generation information is information (vehicle-specific information) used to generate the unique key generation algorithm described later. Based on the common key generation algorithm and the generation information, vehicle 2 creates a unique key generation algorithm (#52). This unique key generation algorithm is specific to vehicle 2 and is preferably created, for example, at the time of vehicle 2's factory shipment.

[0039] Furthermore, Server 4 obtains generation information from a similar generation medium 50 via short-range wireless communication (#53). Based on the common key generation algorithm and the generation information, Server 4 creates a unique key generation algorithm (#54). The creation of the unique key generation algorithm in Server 4 takes place after the delivery of Vehicle 2. It is also possible to create such a key generation algorithm.

[0040] In the above embodiment, the password generation unit 10 was described as being provided in the vehicle 2, but the password generation unit 10 may also be provided in the mobile terminal 3 or in the server 4. If the password generation unit 10 is provided in the mobile terminal 3, the mobile terminal-side password acquisition unit 31 may acquire the password from the password generation unit 10 and transmit it to the vehicle-side password acquisition unit 21 or the server-side password acquisition unit 42. If the password generation unit 10 is provided in the server 4, the server-side password acquisition unit 42 may acquire the password from the password generation unit 10 and transmit it to the vehicle-side password acquisition unit 21 or the mobile terminal-side password acquisition unit 31.

[0041] In the above embodiment, the management unit was described as being Server 4, but the management unit may be a personal computer or a mobile terminal instead of Server 4.

[0042] In the above embodiment, it was explained that the digital key is encrypted with an encryption key and can be decrypted, but the encryption and decryption of the digital key may be performed by other methods.

[0043] In the above embodiment, it was explained that the vehicle 2 and the mobile terminal 3 communicate by short-range wireless communication, and the mobile terminal 3 and the server 4 communicate via a network. However, the vehicle 2 and the mobile terminal 3 may be configured to communicate using a method other than short-range wireless communication, and the mobile terminal 3 and the server 4 may be configured to transmit information, for example, via a device.

[0044] In the above embodiment, it was explained that the usage period is registered when performing the usage procedure. For example, it is also possible to configure the system so that the registered usage period can be changed. In this case, it is possible to configure the system so that the mobile terminal 3 performs a procedure to change the reservation information to the server 4, the mobile terminal 3 obtains information indicating the changed usage period from the server 4 and transmits it to the vehicle 2.

[0045] In the above embodiment, the mobile terminal 3 was described as a smartphone, but the mobile terminal 3 may be, for example, a wearable device.

[0046] In the above embodiment, the determination unit 23 compares the decoded digital key with the digital key included in the key information generated by the vehicle-side key information generation unit 22 stored in the vehicle-side storage unit 25. If the digital keys match, the determination unit 23 permits the use of vehicle 2 and issues a registration completion notification. For example, it is possible to configure the system so that vehicle 2 can be controlled by operating the mobile terminal 3 after the registration completion notification is issued, or to configure the system so that vehicle 2 can be controlled by proximity detection of the mobile terminal 3 and operation of the vehicle 2's devices. Furthermore, when controlling vehicle 2 in this way, control may be performed using a generation medium 50 such as the mobile terminal or NFC card shown in Figure 4.

[0047] [Summary of the above embodiment] The following is an overview of Key System 1, as described above.

[0048] (1) The key system 1 is a key system 1 that generates a digital key that enables the use of the vehicle 2 and an encryption key used for encrypting the digital key and decrypting the encrypted digital key, and includes a vehicle-side password acquisition unit 21 installed in the vehicle 2 that acquires a password set with at least one of the number of uses and usage time set, a vehicle-side key information generation unit 22 installed in the vehicle 2 that generates key information including the digital key and the encryption key based on the password and key generation algorithm, a mobile terminal-side password acquisition unit 31 installed in the mobile terminal 3 of the user using the vehicle 2 that acquires the password, and a server 4 (management unit) that manages the vehicle 2 that acquires the password from the mobile terminal 3 The system includes a server-side password acquisition unit 42 (management unit-side password acquisition unit), a server-side key information generation unit 43 (management unit-side key information generation unit) provided on the server 4 that generates key information based on the password and key generation algorithm, a mobile terminal-side key information acquisition unit 32 provided on the mobile terminal 3 that acquires the key information generated by the server-side key information generation unit 43, a mobile terminal-side key information transmission unit 33 provided on the mobile terminal 3 that transmits the key information acquired by the mobile terminal-side key information acquisition unit 32 to the vehicle 2, and a determination unit 23 provided on the vehicle 2 that compares the key information generated by the vehicle-side key information generation unit 22 with the key information transmitted from the mobile terminal 3 to determine whether or not the vehicle 2 can be used.

[0049] With this configuration, key information is generated based on a password that includes at least one of the usage count and usage time, eliminating the need to possess a physical key for each vehicle 2. Furthermore, since key information including a digital key and an encryption key is generated based on a password that includes at least one of the usage count and usage time, and the ability to use vehicle 2 is determined based on whether the digital key matches, security can be enhanced.

[0050] (2) In the key system 1 described in (1), the key information preferably further includes connection information that enables the vehicle 2 and the mobile terminal 3 to be connected by short-range wireless communication.

[0051] According to this configuration, after sending a password that includes at least one of the number of uses and usage time, an advertisement transmission can be performed, for example, to establish a short-range wireless connection between the vehicle 2 and the mobile terminal 3 based on the key information generated from that password. This makes it possible to prevent the mobile terminal 3, which does not have the key information, from connecting to the vehicle 2. Therefore, security can be enhanced.

[0052] (3) In the key system 1 described in (1) or (2), the key information generated by the server-side key information generation unit 43 preferably includes usage information related to the use of the vehicle 2 that has been registered in advance, and the usage information is preferably transmitted to the vehicle 2 via the mobile terminal-side key information transmission unit 33 and registered in the vehicle 2.

[0053] With this configuration, after usage information is registered in vehicle 2, the usage information can be accessed within vehicle 2 without communicating with server 4. Therefore, since unnecessary communication is not required, security can be enhanced.

[0054] (4) In the key system 1 described in (3), it is preferable to further include a control unit 24 that performs at least one of the following: stopping the generation of passwords for a certain period of time when the number of times a password is generated per certain period of time reaches a specified number; initializing the key information when authentication is not completed within the expiration date and number of valid authentications set for the key information; and initializing all information when the usage period of the vehicle 2 included in the usage information is exceeded.

[0055] With this configuration, the control unit 24 can perform at least one of these actions, thereby enhancing security. [Industrial applicability]

[0056] The technology disclosed herein can be used in a key system that generates a digital key that enables the use of a vehicle, and an encryption key used for encrypting the digital key and decrypting the encrypted digital key. [Explanation of Symbols]

[0057] 1: Key system, 2: Vehicle, 3: Mobile terminal, 4: Server (Management Unit), 21: Password acquisition unit, 22: Vehicle-side key information generation unit, 24: Control unit, 31: Mobile terminal-side password acquisition unit, 32: Mobile terminal-side key information acquisition unit, 33: Mobile terminal-side key information transmission unit, 42: Server-side password acquisition unit (Management Unit-side password acquisition unit), 43: Server-side key information generation unit (Management Unit-side key information generation unit)

Claims

1. A key system that generates a digital key that enables the use of a vehicle, and an encryption key used for encrypting the digital key and decrypting the encrypted digital key, The vehicle includes a vehicle-side password acquisition unit that acquires a password for which at least one of the number of uses and usage time has been set, A vehicle-side key information generation unit is provided in the vehicle and generates key information including the digital key and the encryption key based on the password and the key generation algorithm, A mobile device is provided on the mobile terminal of a user using the vehicle, and includes a mobile terminal-side password acquisition unit that acquires the password, A management unit for managing the aforementioned vehicle is provided with a management unit-side password acquisition unit that acquires the password from the mobile terminal, A key information generation unit on the management unit side is provided in the management unit and generates the key information based on the password and the key generation algorithm, A mobile terminal-side key information acquisition unit is provided in the mobile terminal and acquires the key information generated by the management unit-side key information generation unit, A mobile terminal-side key information transmission unit is provided in the mobile terminal and transmits the key information acquired by the mobile terminal-side key information acquisition unit to the vehicle, A determination unit is provided in the vehicle and compares the key information generated by the vehicle-side key information generation unit with the key information transmitted from the mobile terminal to determine whether or not the vehicle can be used. A key system equipped with this feature.

2. The key system according to claim 1, further comprising connection information that enables the vehicle and the mobile terminal to be connected by short-range wireless communication.

3. The key information generated by the management unit's key information generation unit includes usage information related to the use of the vehicle that has been registered in advance. The key system according to claim 1 or 2, wherein the usage information is transmitted to the vehicle via the mobile terminal-side key information transmission unit and registered in the vehicle.

4. The key system according to claim 3, further comprising a control unit that performs at least one of the following: stopping the generation of the password for a certain period of time when the number of times the password is generated per certain period of time reaches a predetermined number; initializing the key information when authentication is not completed within the expiration date and number of authentication validity periods set for the key information; and initializing all information when the usage period of the vehicle included in the usage information is exceeded.

Citation Information

Patent Citations

  • Sharing system

    JP2019105881A