System and method for a secure keyless system
A secure keyless entry system encrypts and digitally signs each vehicle function command, addressing cyber vulnerabilities by ensuring unique authentication and execution, enhancing security and preventing unauthorized access.
Patent Information
- Application Number
- JP2023580869
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-07-01
- Publication Date
- 2025-11-19
- Estimated Expiration
- 2041-07-01
AI Technical Summary
Modern vehicle keyless entry systems are vulnerable to cyber attacks, allowing unauthorized access and control due to insecure cryptographic mechanisms and shared function codes, which can be exploited by attackers.
Implement a secure keyless entry system that encrypts and digitally signs each vehicle function command using unique function codes, verified by a vehicle's electronic control unit, ensuring each command is authenticated and executed only upon request, independent of existing vehicle infrastructure.
Prevents unauthorized access and cyber attacks by ensuring each vehicle function is uniquely coded and authenticated, enhancing security without relying on vehicle-specific infrastructure, and allowing for post-deployment configuration.
Smart Images

Figure 0007773573000001 
Figure 0007773573000002 
Figure 0007773573000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates generally to vehicle keyless systems, and more particularly to securing vehicle access via keyless systems from cyber attacks. [Background technology]
[0002] The increasing number of advanced features in modern vehicles, such as advanced driver assistance systems, has resulted in the addition of numerous advanced technology components. While these additional components enhance existing vehicle functionality, they can also introduce security vulnerabilities. Keyless entry systems, which use radio frequency (RF) signals (e.g., fixed-frequency signals) to transmit and receive vehicle control functions between the driver and the vehicle, are among the most sensitive components. Remote keyless entry (RKE) and passive keyless entry (PKE) systems not only replace the traditional physical key method of unlocking car doors, but also provide additional functionality such as starting the engine, turning the anti-theft alarm on and off, and initiating interior temperature control.
[0003] Security vulnerabilities in the autonomous driving module, wireless communication module, devices brought into the vehicle, and connected infrastructure can be exploited as bridge points to access the system's core functions. With the advent of modern technologies such as connected vehicles and vehicle-to-everything (V2X) communications, vehicles are no longer sealed box systems but multi-way connected systems. Transmission and reception of vehicle control functions via the RKE or PKE system can be compromised by cyber attackers through security attacks (e.g., jamming, spoofing, and scanning attacks) that rely on weaknesses in these technologies that remotely control vehicle functions. Therefore, a more secure cryptographic-based RF communication mechanism can advantageously help thwart cyber attacks and ensure secure vehicle access.
[0004] Current digital key standards use encryption for key tracking (e.g., authenticating and / or managing multiple keys and their corresponding users and their privileges), but not for transmitting commands used to remotely execute vehicle functions. A keyless entry device may be given common access rights to a vehicle for multiple functions, allowing a user (or intruder) to access multiple functions after the keyless entry device is authenticated (e.g., paired). Furthermore, individual commands corresponding to multiple functions may be pre-established by the manufacturer and shared among multiple vehicles, allowing an intruder to learn commands that can be used on multiple vehicles. As a result, the security of commands may be compromised and converted into different commands during a cyberattack. For example, a lock command may be converted into an unlock command to gain access to the vehicle.
[0005] Security measures outside of the Digital Key standard may be implemented. However, the additional security measures may depend on the vehicle's telematics system, which may vary from vehicle to vehicle. Furthermore, not all original equipment manufacturers (OEMs) may have a sufficiently complex infrastructure to implement the Digital Key standard. Summary of the Invention [Means for solving the problem]
[0006] In various embodiments, the aforementioned technical problems may be addressed by a method for a vehicle keyless entry system, the method including: processing, at a vehicle, a keyless entry transmission having an identification (ID) code; decrypting the ID code of the keyless entry transmission using a vehicle private key; detecting whether the decrypted ID code matches one of a plurality of predetermined function codes for the vehicle; and executing a vehicle function corresponding to the vehicle function code that matches the decrypted ID code. Multiple vehicle functions, such as opening and closing vehicle doors, opening and closing vehicle windows, controlling engine ignition, and controlling a vehicle alarm, may each correspond to a plurality of function codes, and each vehicle function may therefore correspond to a unique, different function code. The keyless entry system may be a remote keyless entry (RKE) system or a passive keyless entry (PKE) system, and the function code may be encrypted by a keyless entry device, such as a customer identification device (CID), and transmitted via an RF signal to a vehicle RF receiver with a digital signature. Authentication and verification of the digital signature may be performed by a controller in the vehicle's electronic control unit (ECU), such as a digital cockpit ECU. If the digital signature is successfully verified and the function code is successfully decoded, a function of the keyless entry system may be triggered based on the function code. An activation signal may be passed from the ECU (e.g., a digital cockpit ECU) to one or more control ECUs (e.g., a main body ECU and an engine ECU) via one or more buses, such as a Controller Area Network (CAN) bus, to perform the desired function.
[0007] In this way, access to the vehicle can be granted for each supported function, and an authentication step occurs each time the key for the keyless entry device is selected, rather than just once upon first contact (e.g., pairing). Furthermore, each function in each vehicle is assigned a unique function code, preventing function codes known from a first vehicle from being used to attack a second vehicle. For example, commands issued by the keyless entry device cannot be translated by an intruder into different commands to gain access to the vehicle. Thus, appropriate security features can be implemented in connection with opening and closing vehicle doors and / or windows, ignition or starting the engine, alarm control, and other vehicle functions, thereby preventing attackers from exploiting weaknesses in vehicle components (e.g., the multimedia radio system) and protecting the integrity of the vehicle's interior. Additional advantages of the keyless entry systems and methods disclosed herein include the fact that they do not rely on existing vehicle infrastructure or telematics systems, key provisioning during manufacturing can provide hardware-based security not present in the system, and are configurable after deployment. In various embodiments, technologies that comply with the Digital Key Standard may be advantageously extended to a more complete Digital Key solution through the mechanisms and methods disclosed herein.
[0008] It should be understood that the foregoing Summary is provided to introduce selected concepts in a concise form, and that the concepts are further described in the Detailed Description. The Summary is not intended to identify key features or essential features of the claimed subject matter, and the scope of the claimed subject matter is defined uniquely by the claims that follow the Detailed Description. Moreover, the claimed subject matter is not limited to implementations that solve any disadvantages noted above or in any part of this disclosure. The present specification also provides, for example, the following: (Item 1) 1. A method for a vehicle keyless entry system, comprising: processing, at the vehicle, a keyless entry transmission having an identification (ID) code portion; decrypting the ID code portion of the keyless entry transmission using the vehicle's private key; detecting whether the decoded ID code portion matches one of a plurality of predetermined function codes for the vehicle; executing a function of the vehicle corresponding to a function code of the vehicle that matches the decoded ID code portion; The method comprising: (Item 2) Item 10. The method of item 1, wherein the private key for the vehicle is stored in a playback prohibited memory block (RPMB) for the vehicle. (Item 3) Item 10. The method of item 1, wherein the decoding of the ID code portion is performed in an electronic control unit (ECU) of the vehicle that is powered by a secondary power source of the vehicle. (Item 4) receiving the keyless entry transmission via a radio frequency (RF) transceiver connected to the ECU; Item 3. The method according to item 3, comprising: (Item 5) the keyless entry transmission having a digital signature portion; verifying the digital signature portion of the keyless entry transmission based on the ID code portion and a predetermined public key of the vehicle keyless entry device; The method according to item 1, comprising: (Item 6) 6. The method of claim 5, wherein the public key of the keyless entry device is stored in a write-protected memory of the vehicle. (Item 7) 6. The method of claim 5, wherein the plurality of predetermined function codes corresponding to the plurality of functions of the vehicle are generated by a true random number generator (TRNG) of the vehicle and assigned to both the vehicle and the keyless entry device. (Item 8) Item 10. The method of claim 1, wherein the vehicle keyless entry system is one of a remote keyless entry (RKE) system and a passive keyless entry (PKE) system. (Item 9) Item 10. The method of item 1, wherein the function of the vehicle is one of a door lock function, a door unlock function, a vehicle start function, and a window control function. (Item 10) 1. A method for a vehicle keyless entry system, comprising: detecting, at a keyless entry device of a vehicle, a request for a selected function of the vehicle; identifying a function code corresponding to the selected function from among a plurality of predetermined function codes for the vehicle corresponding to the plurality of functions; encrypting the feature code for the vehicle into an identification (ID) code portion using a predetermined public key for the vehicle; generating, at the keyless entry device, a keyless entry transmission having the ID code portion; The method comprising: (Item 11) the keyless entry transmission having a digital signature portion; generating the digital signature portion based on the ID code portion and a private key of the keyless entry device; Item 11. The method according to item 10, comprising: (Item 12) Item 12. The method of item 11, wherein the private key of the keyless entry device is stored in a playback-protected memory block (RPMB) of the keyless entry device. (Item 13) 11. The method of claim 10, wherein the public key for the vehicle is stored in a write-protected memory of the keyless entry device. (Item 14) transmitting the keyless entry transmission via a radio frequency (RF) transceiver of the keyless entry device; Item 11. The method according to item 10, comprising: (Item 15) Item 11. The method of item 10, wherein the plurality of predetermined function codes corresponding to the plurality of functions of the vehicle are generated by a true random number generator (TRNG) of the vehicle and assigned to both the keyless entry device and the vehicle. (Item 16) Item 11. The method of item 10, wherein the vehicle keyless entry system is one of a remote keyless entry (RKE) system and a passive keyless entry (PKE) system. (Item 17) Item 11. The method of item 10, wherein the function code corresponds to one of a door lock function, a door unlock function, a vehicle start function, and a window control function. (Item 18) Vehicles and a keyless entry device for the vehicle; A vehicle keyless entry system comprising: The keyless entry device includes a first radio frequency (RF) circuit and one or more first processors having executable instructions stored in a first non-transitory memory, the executable instructions, when executed, Detecting a request for one of a plurality of functions of the vehicle; identifying a function code corresponding to the requested function of the vehicle, the function code being one of a plurality of function codes respectively corresponding to the plurality of functions; encrypting the feature code using the vehicle's public key; transmitting a keyless entry transmission via the first RF circuit; on the one or more first processors; the ID code portion of the keyless entry transmission includes the encrypted function code; The vehicle includes a second RF circuit and one or more second processors having executable instructions stored in a second non-transitory memory, the executable instructions, when executed, receiving the keyless entry transmission via the second RF circuit; decrypting the ID code portion of the keyless entry transmission using the vehicle's private key; detecting whether the decoded ID code portion matches any of the plurality of feature codes for the vehicle; executing the function of the vehicle corresponding to the function code of the vehicle that matches the decoded ID code portion; causing the one or more second processors to execute The vehicle keyless entry system. (Item 19) the keyless entry transmission having a digital signature portion; The executable instructions stored in the first non-transitory memory, when executed, further cause the one or more first processors to generate the digital signature portion based on the encrypted function code and a private key of the keyless entry device; The executable instructions stored in the second non-transitory memory, when executed, further cause the one or more second processors to verify the digital signature portion based on the decrypted ID code portion and a public key of the keyless entry device. Item 19. The vehicle keyless entry system according to item 18. (Item 20) 20. The vehicle keyless entry system of claim 18, wherein the vehicle includes a secondary power source connected to the second RF circuit, the second non-transitory memory, and the one or more second processors, the secondary power source providing power at least when power is not available from a primary power source of the vehicle.
[0009] The present disclosure may be better understood by reading the following description of non-limiting embodiments with reference to the accompanying drawings, in which: [Brief explanation of the drawings]
[0010] [Figure 1] 1 is a schematic block diagram of a secure keyless entry system for a vehicle in accordance with one or more embodiments of the present disclosure. [Figure 2A] FIG. 1 is a schematic block diagram of a system for configuring a keyless entry system including a vehicle and a customer identification device (CID) paired with the vehicle, in accordance with one or more embodiments of the present disclosure. [Figure 2B] FIG. 2B is a schematic block diagram illustrating the flow of data between the CID of FIG. 2A and the vehicle, in accordance with one or more embodiments of the present disclosure. [Figure 2C] FIG. 1 is a schematic block diagram illustrating a cryptographic message including an ID code portion and a digital signature portion, in accordance with one or more embodiments of the present disclosure. [Figure 3] 1 is a flowchart illustrating an example procedure for configuring a keyless entry system prior to operation, in accordance with one or more embodiments of the present disclosure. [Figure 4] 1 is a flowchart illustrating an example procedure for transmitting encrypted data between a CID of a keyless entry system and a vehicle, in accordance with one or more embodiments of the present disclosure. [Figure 5] 1 is a flowchart illustrating an example keyless entry procedure for verifying and decrypting a transmission from a CID, in accordance with one or more embodiments of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0011] The following detailed description relates to a secure keyless entry system for a vehicle. The vehicle may have a secure keyless entry system, such as the keyless entry system of FIG. 1. The driver of the vehicle may have a vehicle keyless entry device (e.g., a key fob), also referred to herein as a customer identification device (CID), which may be paired with and configured to operate with the vehicle, as described with reference to the configuration system of FIG. 2A. Following a procedure such as the method of FIG. 3, a set of feature codes corresponding to vehicle features and a set of public and private keys may be generated for the CID and vehicle.
[0012] During use of the secure keyless entry system, a key (e.g., a button on a key fob) of the CID may be selected to perform a desired function of the vehicle, and information may be transmitted from the CID to the vehicle as shown in the functional diagram of FIG. 2B via an encrypted message generated as described with reference to FIG. 2C. The encrypted message may include an ID code, which may be an encrypted function code corresponding to the desired function of the vehicle, and a digital signature of the CID. The CID may transmit a radio frequency (RF) signal with the encrypted message to the vehicle via a procedure such as the method of FIG. 4.
[0013] The RF signal may then be received by a vehicle electronic control unit (ECU) (e.g., by a digital cockpit ECU), which may process the RF signal and encrypted message via a procedure such as the method of Figure 5. The digital signature may be verified to authenticate the CID, and the ID code may be decrypted to recover the function code. The digital cockpit ECU may then perform a desired function of the vehicle (e.g., unlocking the vehicle doors, starting the vehicle engine, opening one or more vehicle windows, opening the vehicle trunk, etc.) based on the function code.
[0014] 1 , a keyless entry system 100 is shown that includes a vehicle 102 in wireless communication with a CID 140, which may be referred to as a keyless entry device. The keyless entry system 100 may be a different type of keyless entry system, such as a remote keyless entry (RKE) system, or a passive keyless entry (PKE) system, or any of the keyless entry systems disclosed herein. The CID 140 may be a handheld device (e.g., a key fob) carried by the driver of the vehicle 102. In some embodiments, the CID 140 may include a mobile application or any of various types or modes of user interfaces.
[0015] The vehicle 102 may include a digital driver's seat ECU 104 that may control the operation of the keyless entry system 100 via an input / output controller (IOC) 106. In some embodiments, the ECU 104 may not be a digital driver's seat ECU but may be another ECU in the vehicle. The digital driver's seat ECU 104 may include a processor 107 that may execute instructions stored in a memory 109 of the digital driver's seat ECU 104 to implement portions of the keyless entry system 100. In some embodiments, the digital driver's seat ECU 104 may be powered by a power storage device such as a battery 108. The battery 108 may be a dedicated ECU battery, i.e., the battery 108 may be a designated battery (e.g., for the IOC) such that power to execute instructions is available even when power is not available via other power sources in the vehicle. In some embodiments, the battery 108 may be belt-connected to the engine 134 and maintained in a charged state via a front-end accessory drive (FEAD) system (not shown in FIG. 1 ) of the vehicle 102 during engine operation. In various embodiments, the battery 108 may provide the keyless entry system 100 with enough power to operate when the engine 134 is not running and / or when the main battery of the vehicle 102 is not being charged.
[0016] In some embodiments, wireless communication between vehicle 102 and CID 140 may be established via an RF link supporting bidirectional communication, whereby RF signals may be transmitted from CID 140 to vehicle 102 and / or RF signals may be transmitted from vehicle 102 to CID 140. CID 140 may include RF chip 142 and battery 144, which may enable it to process executable instructions for communication and interoperation between CID 140 and vehicle 102.
[0017] The RF range at which CID 140 operates may vary between manufacturers. Additionally, the ability of a signal to reach vehicle 102 may vary due to corner pillars of vehicle 102 and / or other physical objects that may act to reduce RF range blocking CID 140. In some embodiments, CID 140 may transmit at a frequency of 315 megahertz (MHz). Components of CID 140 are omitted from FIG. 1 for simplicity, and an exemplary configuration of CID 140 is described in more detail below with reference to FIG. 2A.
[0018] Vehicle 102 may include an RF receiver and / or transmitter 110 that may receive keyless entry transmissions (e.g., via RF signals) sent from CID 140 via antenna 118. (The receiver and / or transmitter may be referred to herein as a transceiver.) The RF signal sent from RF chip 142 of CID 140 to RF transceiver 110 of vehicle 102 may include encrypted digital data.
[0019] When a key (e.g., a button) is pressed on the CID 140, an encrypted message may be sent from the CID 140 to the vehicle 102. The encrypted message may include an identification (ID) code that may be based on a function code of the vehicle 102. In various embodiments, the ID code may be an encrypted function code. The encrypted message may also include various other identification information of the vehicle 102 and / or the CID 140. The function code on which the ID code is based may be for activating or triggering a function of the vehicle 102, such as unlocking or locking the vehicle, opening a vehicle window, starting the vehicle engine 134, activating the vehicle panic signal, a remote access function for activating or deactivating the vehicle's theft detection system, or another function.
[0020] In some embodiments, the function code may be specific to the key pressed. For example, a first key may unlock the vehicle 102, a second key may lock the vehicle 102, a third key may start the engine 134, and so on. In another example, a single key may be used to transmit multiple encrypted messages based on function codes. For example, a lock / unlock key may switch between transmitting a first encrypted message based on a first function code to lock the vehicle 102 and a second encrypted message based on a second function code to unlock the vehicle 102. In yet another example, a combination of keys may be used to transmit an encrypted message having a single function code. For example, a driver may press a first key to transmit an encrypted message based on the first function code, press a second key to transmit an encrypted message based on the second function code, and press the first and second keys simultaneously or in a particular order to transmit an encrypted message based on a third function code. It should be understood that the examples described herein are for illustrative purposes only and that different or additional keys and / or key combinations may be used without departing from the scope of the present disclosure.
[0021] While the above describes an embodiment involving wireless communication via RF signaling, other types of wireless communication may be used. For example, wireless communication between vehicle 102 and CID 140 may be established via an infrared (IR) link.
[0022] In various embodiments, the keyless entry system is a type of passive keyless (PK) system in which an encrypted message can be sent from the CID 140 to the vehicle 102 without the driver pressing a key. In some embodiments, the PK system can be a PKE system in which an encrypted message (e.g., including an ID code based on a function code for unlocking and / or locking the vehicle 102) can be sent from the CID 140 to the vehicle 102 without the driver pressing a key. In some embodiments, the PK system can be a passive keyless start (PKS) system in which an encrypted message can be sent from the CID 140 to the vehicle 102 in which an ID code based on a function code for starting the engine can be sent from the CID 140 to the vehicle 102 without the driver pressing a key. In some embodiments, the PK system can be a passive keyless entry and start (PKES) system in which an encrypted message can be sent from the CID 140 to the vehicle 102 in which both an encrypted message for unlocking and / or locking the vehicle 102 and / or an encrypted message for starting the engine can be sent from the CID 140 to the vehicle 102 without the driver pressing a key.
[0023] The PKES system allows a driver to unlock and start their vehicle by bringing a CID (e.g., a key fob) within a predetermined threshold distance of the vehicle 102. In various embodiments, the PKES system may use a challenge-response-based security protocol between the vehicle 102 and the CID 140, where the vehicle 102 periodically scans the CID 140 to determine its proximity. If the CID 140 is detected within the threshold distance (e.g., 3 feet) of the vehicle 102, the vehicle 102 transmits a challenge (e.g., a digital query) to the CID 140 and the ID of the vehicle 102 and waits for a response from the CID 140. If the vehicle 102 receives the expected response from the CID 140, including an encrypted message with an ID code, the ID code may be decrypted (discussed further below), and any valid function codes recovered may be used to trigger the appropriate remote access functions of the vehicle 102 (e.g., unlocking one or more doors, starting the engine, etc.).
[0024] Both PK and RKE systems can be vulnerable to various types of cyber-attacks by intruders with the ability and skill to build electronic devices to attack security systems. For example, a cyber-attack can be a scanning attack, in which the intruder repeatedly sends various codes to the RF transceiver 110 until a matching code is found. As another example, a cyber-attack can be a replay attack, in which the attacker records a radio message sent to the vehicle and later plays the radio message when the driver is not present. As another example, a cyber-attack can be a two-person theft attack, in which a first thief with a first amplifier pulls the door handle of the vehicle 102, while a second thief with a second amplifier stands next to the driver and amplifies the interrogation message sent to the CID 140 to make it appear as if the driver is next to the vehicle 102.
[0025] In a further example, the cyber-attack may be a challenge-forward prediction attack, in which in a first step, an intruder records one or more generated interrogation messages sent from the vehicle 102 when the door handle of the vehicle 102 is pulled. In some examples, the intruder may record one or more interrogation messages when the driver or another person pulls the door handle. In a second step, the intruder approaches the vehicle 102 when the driver leaves the vehicle 102 and sends predicted subsequent interrogation messages based on the recorded interrogation messages. Responses from the CID 140 are recorded, which can then be used to unlock the vehicle 102. In yet another example, the cyber-attack may use a jammer or other device that emits a signal in the same frequency range as the RF chip 142 to create strong interference that disrupts communication between the CID 140 and the RF transceiver 110, so that when the driver leaves the vehicle 102 and presses a lock key (e.g., a button) on the CID, the vehicle 102 does not lock as the driver expected. By transmitting the ID code in an encrypted message from CID 140 to vehicle 102 rather than transmitting an unencrypted function code, vehicle 102 may be advantageously hardened or protected against cyber attacks such as those discussed above.
[0026] After receiving the RF signal with the encrypted message from CID 140, RF transceiver 110 may pass the ID code to IOC 106, which may ultimately perform the appropriate corresponding remote access functions (e.g., door lock / unlock, engine start, etc.) To this end, IOC 106 may execute instructions (e.g., via cryptographic software) responsible for decrypting the ID code received from CID 140, as described in more detail below with reference to FIG.
[0027] In various embodiments, the received cryptographic message may further include a digital signature, which may enable authentication of the CID 140. For example, the IOC 106 may decrypt the ID code and determine whether valid function codes (e.g., door lock / unlock, engine start, etc.) have been recovered. The IOC 106 may further verify the digital signature to authenticate the CID 140. The IOC 106 may similarly refrain from performing the remote access function corresponding to the recovered function code unless the digital signature has been verified (and thus the CID 140 has been authenticated). In various embodiments, the portion of the cryptographic message with the digital signature may be added or concatenated to the portion of the cryptographic message with the ID code.
[0028] After the ID code is decoded by the IOC 106, the resulting decoded data may be compared to a list of valid function codes for the vehicle 102. If the decoded data matches any of the valid function codes, the IOC 106 may execute the function for the vehicle 102 that corresponds to the recovered function code. Executing the desired function may include sending one or more control signals to other ECUs in the vehicle 102 to operate one or more actuators to perform the desired function.
[0029] One or more control signals may be sent to other ECUs via one or more communication buses 120 of the vehicle 102. In various embodiments, the one or more communication buses 120 may include a controller area network (CAN) bus, one or more ECU-to-ECU communication buses, and / or different types of buses. The other ECUs may include an engine ECU 124 that may control ignition of an engine 134 via an ignition system 132. The other ECUs may include a body control module (BCM) 122 that may control multiple ECUs and / or actuators associated with various other systems of the vehicle 102. For example, the BCM 122 may control one or more door actuator systems 126 to lock or unlock one or more doors of the vehicle 102. The BCM 122 may control an interior lighting system 128 of the vehicle 102 to turn on or off one or more interior lights of the vehicle 102. The BCM 122 may control one or more window actuator systems 130 of the vehicle 102 to open or close one or more windows of the vehicle 102. It should be understood that the examples provided herein are for illustrative purposes only, and that additional or different ECUs and / or actuators may be controlled (by BCM 122 and / or other ECUs in vehicle 102) without departing from the scope of the present disclosure.
[0030] As an example of the overall operation of the keyless entry system 100, a driver may approach the vehicle 102 and desire to unlock the vehicle 102. The driver may press a key on a keyless entry device (e.g., CID 140) paired with the vehicle 102 that is assigned a function code to unlock one or more doors of the vehicle 102. In response to the driver pressing the unlock key, the CID 140 may encrypt the function code to generate an ID code, which may be included in an ID code portion of an encrypted message. The CID 140 may further create a digital signature, which may be included in a digital signature portion of the encrypted message. The encrypted message may then be converted to RF signaling and transmitted wirelessly to the vehicle 102 by the RF chip 142 of the CID 140.
[0031] At the vehicle 102, the RF transceiver 110 may receive RF signaling from the RF chip 142 via the antenna 118 and convert the RF signaling back into an encrypted message. The RF transceiver 110 may then pass the encrypted message to the IOC 106 of the digital cab ECU 104. The IOC 106 may authenticate the CID 140 by verifying the digital signature of the encrypted message. The IOC 106 may separately decrypt the ID code and determine whether the resulting data matches a valid feature code for the vehicle 102. If the decryption process recovers a valid feature code and if the CID 140 is authenticated as the sender of the encrypted message, the recovered feature code (which may have been mapped to a door unlock function by software in the IOC 106) may generate a signal to the BCM 122 to unlock one or more doors of the vehicle 102. The signal may be sent to the BCM 122 via one or more buses 120. When the BCM 122 receives a signal to unlock one or more doors of the vehicle 102, the BCM 122 may actuate one or more corresponding door actuators 126 of the vehicle 102 to unlock the one or more doors.
[0032] As another example of the overall operation of the keyless entry system 100, the vehicle 102 may use a PKE system rather than an RKE system, such that one or more doors of the vehicle 102 may be automatically unlocked when a driver approaches the vehicle 102. The IOC 106 may instruct the RF transceiver 110 to periodically (e.g., once per second) scan for keyless entry devices (e.g., CID 140) paired with the vehicle 102 within a threshold proximity of the vehicle 102. When the driver approaches the vehicle 102 and comes within the threshold proximity, the CID 140 may automatically generate and transmit an encrypted message having a digital signature portion and an ID code portion to the RF transceiver 110 to unlock one or more doors of the vehicle 102. The RF transceiver 110 may pass the encrypted message to the IOC 106, which may decode the ID code and unlock the one or more doors as described above.
[0033] As yet another example of the overall operation of the keyless entry system 100, an intruder is located within a threshold distance (e.g., 30 feet) of the vehicle 102 when the driver exits the vehicle 102. As the driver exits the vehicle 102, the driver locks one or more doors of the vehicle 102 using the CID 140. Simultaneously, as the driver exits the vehicle 102, the intruder records the RF signals sent from the CID 140 to the vehicle 102 to perform a replay attack. After the driver leaves the area of the vehicle 102, the intruder may replay the recorded RF signals to the vehicle 102 in an attempt to gain access to the vehicle 102. When the intruder replays the recorded RF signals, the recorded RF signals are received by the RF receiver / transmitter 110 via the antenna 118 of the vehicle 102. When the RF receiver / transmitter receives the recorded RF signals, the RF receiver / transmitter may send an encrypted message to the IOC 106. The IOC 106 may attempt to authenticate the sender of a cryptographic message by verifying the cryptographic message's digital signature.
[0034] In some embodiments, the encrypted message may not have a digital signature, or if it does have a digital signature, the digital signature may not be verified by the IOC 106. As a result of the encrypted message's digital signature not being verified, the sender of the recorded RF signal may not be authenticated. In some embodiments, as a result of the sender not being authenticated, the IOC 106 may flag the sender of the encrypted message as an unauthorized user and / or may not decrypt the ID code (e.g., as part of a request denial). In some embodiments, as a result of the sender not being authenticated, the IOC 106 may not send a signal to the BCM 122 to unlock the vehicle 102 over one or more buses 120, thereby denying an intruder access to the vehicle 102. Furthermore, the IOC 106 may register a potential cyberattack on the vehicle 102 in one or more log files of the vehicle 102. Thus, the internal integrity of the vehicle 102 may be protected from intruders by encrypting the associated ID code and / or digitally signing the ID code before transmitting the encrypted message to the vehicle 102.
[0035] 2A, a block diagram of an exemplary CID configuration system 200 for configuring a keyless entry system (which may be substantially similar to keyless entry system 100 of FIG. 1) is shown. CID configuration system 200 may include a vehicle 230 and a CID 202 paired with vehicle 230 (which may be substantially similar to vehicle 102 and CID 140 of FIG. 1, respectively). In some embodiments, CID configuration system 200 may be implemented by an original equipment manufacturer (OEM) of the keyless entry system prior to deployment of vehicle 230.
[0036] CID 202 may include multiple keys. For example, CID 202 may include lock key 204, unlock key 205, engine start key 206, and window control keys 207. In some embodiments, the keys may be buttons located on the surface of CID 202, whereby a key is selected when the corresponding button is pressed. The buttons may be mechanical buttons, capillary-detection buttons, or different types of physical buttons, or the buttons may be virtual buttons located on the touchscreen of CID 202. The buttons may be identified by icons, text, color, or a combination of features. In other embodiments, the keys may not be buttons, and a different user interface (e.g., the screen of a mobile device supporting a mobile application) may be used. It should be understood that the examples provided herein are for illustrative purposes, and that other or different user interface components or combinations of components may be included without departing from the scope of this disclosure.
[0037] CID 202 may include a processor 228 that may execute instructions stored in memory 227 of CID 202. CID 202 may include an RF chip 214 that may be used to wirelessly transmit data from CID 202 to a corresponding RF transceiver 232 in vehicle 230 and / or receive data transmitted to CID 202 by RF transceiver 232. For example, execution of instructions stored in memory 227 may cause RF chip 214 to wirelessly transmit to vehicle 230 a function code associated with a key in CID 202 selected by a driver of vehicle 230 (e.g., to open a door, start the engine of vehicle 230, etc.). Alternatively, RF chip 214 may receive messages from RF transceiver 232, such as scan messages that are periodically sent to determine whether CID 202 is within a threshold proximity of vehicle 230. The RF chip 214 and the transmission and reception of RF signals via the processor 228 and memory 227 may be powered by the battery 208 of the CID 202 .
[0038] CID configuration system 200 may include a true random number generator (TRNG) 215, which may generate a corresponding number of random function codes for multiple keys. For example, if there are four keys (e.g., lock key 204, unlock key 205, engine start key 206, and window control key 207), TRNG 215 may generate first random function code 216, second random function code 217, third random function code 218, and fourth random function code 219. In some embodiments, the random function codes for each of the keys are generated once by the OEM prior to deployment of vehicle 230. In some embodiments, the random function codes may be regenerated during the validity period of CID 202, for example, if CID 202 is lost, if a user wants to change CID 202, if the OEM wants to update the random function code, or for another reason. In yet other embodiments, the random function codes for each of the keys may be regenerated periodically, for example, to improve security.
[0039] The CID configuration system 200 may include a mapping function 220. Once the random function codes are generated by the TRNG 215, the mapping function 220 may assign the random function codes to corresponding keys. For example, a first random function code 216 may be assigned to the lock key 204, where the first random function code 216 may correspond to a vehicle function for locking the vehicle 230; a second random function code 217 may be assigned to the unlock key 205, where the second random function code 217 may correspond to a vehicle function for unlocking the vehicle 230; a third random function code 218 may be assigned to the engine start key 206, where the third random function code 218 may correspond to a vehicle function for starting the vehicle 230; and a fourth random function code 219 may be assigned to the window control key 207, where the fourth random function code 219 may correspond to a vehicle function for opening one or more windows of the vehicle 230.
[0040] The mapping of keys of CID 202 to function codes may then be stored in CID 202, such as in memory 227. In some embodiments, the mapping of keys of CID 202 to function codes may be stored in write-protected memory block 210 of memory 227. After deployment, the mapping of keys to function codes may be accessed and processed by processor 228.
[0041] Similarly, the mapping of function codes to functions of vehicle 230 may be stored in memory of vehicle 230. In some embodiments, the mapping of function codes to functions may be stored in memory 236 of ECU 231 (which may be substantially similar to digital cab ECU 104 and memory 109, respectively). In some embodiments, the mapping of function codes to functions of vehicle 230 may be stored in a write-protected memory block 238 of memory 236. As described in more detail below with reference to FIG. 2B , after deployment, the mapping of function codes to functions may be accessed and processed by IOC 234 of vehicle 230 (e.g., IOC 106 of keyless entry system 100 of FIG. 1 ). Processing of the function code mapping may be powered by battery 232 of ECU 231.
[0042] Memory 227 of CID 202 may include instructions that, when executed, cause CID 202 to encrypt function codes before transmitting the function codes to vehicle 230. Similarly, memory 236 of vehicle 230 may include instructions that, when executed, cause vehicle 230 to decrypt function codes received from CID 202.
[0043] In various embodiments, the function code may be encrypted and decrypted using public key encryption techniques, with public and private key pairs assigned to the CID 202 and the vehicle 230 by the key generator 222. Thus, in various embodiments, the key generator 222 may assign to the CID 202 a CID private key 225 (which may be stored in a secure location in the memory 227 of the CID 202, such as the play-protected memory block (RPMB) 212) and a corresponding CID public key 224 (which may be stored in the write-protected memory 238 of the vehicle 230). Similarly, the key generator 222 may assign to the vehicle 230 a vehicle private key 226 (which may be stored in a secure location in the memory 236 of the vehicle 230, such as the RPMB 240) and a corresponding vehicle public key 223 (which may be stored in the write-protected memory 210 of the memory 227 of the CID 202). In some embodiments, key generator 222 may be operated by the manufacturer of CID 202 and / or vehicle 230. The encryption and digital signing of the feature code in CID 202, and the decryption and signature verification in vehicle 230, using public and private key pairs are described in more detail below with reference to Figures 4 and 5, respectively.
[0044] 3, an example method 300 illustrates a high-level procedure for configuring a CID (e.g., CID 202) of a keyless entry system (e.g., keyless entry system 100) and a vehicle (e.g., vehicle 230) prior to deployment of the vehicle. In some embodiments, method 300 may be performed by a CID configuration system (e.g., CID configuration system 200) operated by a manufacturer of the keyless entry system. Thus, one or more parts of method 300 may be performed with reference to one or more elements of FIG. 2A.
[0045] Method 300 begins at part 302, where method 300 includes generating a set of unique random function codes using a TRNG (e.g., TRNG 215), where each random function code in the set of unique random function codes corresponds to a function associated with the keyless entry system. Thus, each function associated with the keyless entry system may correspond to a key in the CID. For example, the keyless entry system shown in FIG. 2A provides four functions corresponding to four keys: a lock function associated with a lock key (e.g., lock key 204), an unlock function associated with an unlock key (e.g., unlock key 205), an engine start function associated with an engine start key (e.g., engine start key 206), and a window control function associated with a window control key (e.g., window control key 207). For each of the four functions, the TRNG may generate a unique random function code, which may be assigned to the corresponding function by a separate mapping function.
[0046] In part 304, method 300 includes mapping the generated unique random function codes to corresponding keyless entry system functions. In some embodiments, a mapping function of the CID configuration system (e.g., mapping function 220) may perform the mapping. For example, the mapping function may map a first random function code (for the lock key) to a vehicle lock function, a second random function code (for the unlock key) to a vehicle unlock function, a third random function code (for the engine start key) to a vehicle engine start function, and a fourth random function code (for the window control key) to a vehicle window control function. In this manner, a unique random identifier may be assigned to each of the four keys, and the unique random identifier may be used by the vehicle to identify a selected key of the four keys (e.g., by a vehicle driver).
[0047] In part 306, method 300 includes storing a function code in both the CID and the vehicle. In some embodiments, the function code is stored in a write-protected memory of the vehicle's ECU (e.g., write-protected memory 238 of vehicle 230), and the function code can be accessed by the vehicle's IOC (e.g., IOC 234 of FIG. 2A). Similarly, the function code can be stored in a write-protected memory of the CID (e.g., write-protected memory 210 of CID 202), and a processor in the CID can retrieve the function code when a corresponding key in the CID is selected by the driver. Thereafter, if the driver selects the CID's unlock key, the CID's processor can retrieve the function code corresponding to the CID's unlock key and the vehicle's unlock function; if the driver selects the CID's engine start key, the CID's processor can retrieve the function code corresponding to the CID's engine start key and the vehicle's engine start function; and so on. As described in more detail below with reference to FIG. 4, the function code retrieved by the processor can be transmitted to the vehicle to trigger the corresponding function.
[0048] In part 308, method 300 includes generating public and private keys for both the vehicle and the CID. In some embodiments, a key generator (e.g., key generator 222) of the CID configuration system generates the public and private keys according to a selected public key cryptosystem. The public key cryptosystem can be one of a variety of public / private key-dependent cryptosystems, such as an Elliptic Curve Cryptography system, an ElGamal cryptosystem, a Rivest-Shamir-Adelman (RSA) cryptosystem, a Paillier cryptosystem, a Cramer-Shoup cryptosystem, a YAK authenticated key agreement protocol, an NTRU cryptosystem, or a McEliece cryptosystem.
[0049] In some embodiments, the public and private keys may be numbers generated together as a pair using prime factorization, with the private and public keys being based on one or more operations performed on combinations of prime numbers. A cryptographic message encrypted with a public key (e.g., of the vehicle) may be decrypted with a corresponding private key (of the vehicle). Additionally and / or alternatively, the cryptographic message may be signed with a digital signature using a private key (e.g., of a CID paired with the vehicle), and the digital signature may be verified (e.g., authenticated) using the corresponding public key. Without knowledge of the prime numbers used to generate the public / private key pair, it may be computationally difficult (e.g., time-consuming) to decrypt the cryptographic message without knowing the corresponding private key or to verify the cryptographic message without knowing the corresponding public key. Encryption, decryption, and verification of cryptographic messages using public and private keys are described in more detail below with reference to Figures 4 and 5.
[0050] Once the public and private keys are generated, the CID public and private keys and the vehicle public and private keys are exchanged and stored. In part 310, method 300 includes storing the CID public key in a write-protected memory of the vehicle (e.g., write-protected memory 238 of vehicle 230). In part 312, method 300 includes storing the vehicle public key in a write-protected memory of the CID (e.g., write-protected memory 210 of CID 202). The CID public key and the vehicle public key may be public, and thus, no additional security mechanisms may be provided to protect the CID public key and the vehicle public key. (In various embodiments, the CID public key and the vehicle public key may not actually be published by the manufacturer.)
[0051] In part 314, method 300 includes storing the CID's private key in a secure storage area of the CID, such as an RPMB (e.g., RPMB 212 of CID 202). The RPMB may include a separate, self-contained security protocol for protecting the stored data from replay attacks of the type described above. Thus, by storing the CID's private key in the CID's RPMB, the CID's private key may advantageously be more protected from replay attacks than if it were stored in write-protected memory of the CID.
[0052] In part 316, method 300 includes storing the vehicle private key in a secure storage area of the vehicle, such as an RPMB (e.g., RPMB 240 of vehicle 230). By storing the vehicle private key in the vehicle's RPMB, the vehicle private key may advantageously be more protected from replay attacks than if it were stored in write-protected memory of the vehicle.
[0053] Referring now to FIG. 2B, functional diagram 250 illustrates an exemplary flow of data between CID 202 and vehicle 230 during operation of the keyless entry system (e.g., after configuration of CID 202 and vehicle 230 as described above with reference to CID configuration system 200).
[0054] In some embodiments, the keyless entry system may be an RKE system, and an exemplary flow of data is initiated by the driver of vehicle 230 selecting a key on CID 202. For example, the driver may select unlock key 205 on CID 202 upon approaching the vehicle to unlock the doors of vehicle 230, or the driver may select engine start key 206 to warm the engine and / or interior of vehicle 230 before driving vehicle 230. In another embodiment, the keyless entry system may be a PKE system, and an exemplary data flow is initiated by CID 202 coming within threshold proximity of vehicle 230 (e.g., to unlock the doors of vehicle 230).
[0055] When the driver selects or comes within threshold proximity of a key in CID 202, a function code 251 associated with the key and / or PKE function (e.g., unlocking the doors) may be encrypted by processor 228 of CID 202 in encryption code block 252. Encryption code block 252 may output an ID code, which is the encrypted function code. In some embodiments, function code 251 may be a random number generated by a TRNG (e.g., TRNG 215) of the vehicle 230 manufacturer. In some embodiments, encryption code block 252 may encrypt the selected and / or desired function code 251 using a public key cryptosystem, as described above with reference to method 300 of FIG. 3 .
[0056] Thus, in various embodiments, encryption of feature code 251 may be accomplished using vehicle public key 223 (e.g., the public key of vehicle 230), which may be assigned to vehicle 230 and stored in write-protected memory 210 of CID 202 (e.g., by CID configuration system 200 during a pre-deployment configuration phase of vehicle 230). Vehicle public key 223 may be a public code of vehicle 230 of the type used in public key cryptography systems. It may be computationally infeasible to decrypt a message encrypted with vehicle public key 223 without the corresponding vehicle private key 226.
[0057] In various embodiments, the ID code (e.g., the encrypted function code generated by the encryption code block 252) may be input into the signature code block 254. In the signature code block 254, the ID code may be digitally signed, and thus a digital signature may be created based on the CID private key 225 (stored in the RPMB 212 of the CID 202) and the ID code. It may be computationally infeasible to verify a digital signature created with the CID private key without using the corresponding CID public key 224. The digital signature may be created using one of a variety of digital signature algorithms, such as RSA, Digital Signature Algorithm (DSA), Elliptic Curve Digital Signature Algorithm (ECDSA), Edwards-curve Digital Signature Algorithm (EDDSA), and RSA with the Secure Hash Algorithm (SHA). Digital signatures are described in more detail below with reference to FIG. 4.
[0058] The digital signature output by signature code block 254 may be combined with the ID code to form cryptographic message 256, which includes at least an ID code portion and a digital signature portion. In some embodiments, cryptographic message 256 may be a concatenation of a first bit string representing the ID code portion and a second bit string representing the digital signature portion, as shown in FIG. 2C.
[0059] 2C, cryptographic message formation diagram 270 illustrates an exemplary bit array 276 representing cryptographic message 256, where bit array 276 is a concatenation of ID code portion 272 and digital signature portion 274. ID code portion 272 may comprise the ID code output by encryption code block 252, which receives selected and / or desired feature code 251 as input, as described above. Similarly, digital signature portion 274 may comprise the digital signature output by signature code block 254, which receives the ID code that is the output of encryption code block 252, as described above.
[0060] 2B , encrypted message 256 may be transmitted to vehicle 230 via RF chip 214. In some embodiments, encrypted message 256 may be converted into one or more RF signals by RF chip 214 and transmitted by chip antenna 258 of CID 202. The RF signals may then be received by vehicle antenna 260 of vehicle 230 and converted back into encrypted message 256 by RF transceiver 232. In other embodiments, encrypted message 256 may be transmitted using a different type of wireless digital transmission technology.
[0061] 2C , the encrypted message 256 sent by the CID 202 may have a digital signature portion and an ID code portion. The digital signature of the encrypted message 256 may be verified by the verification code block 264 of the vehicle 230. In some embodiments, the verification code block 264 may be executed by the IOC 234 of the ECU 231 of the vehicle 230. During verification, the digital signature created by the CID 202 using the CID private key 225 (in the RPMB 212 of the CID 202) is verified by the ECU 231 of the vehicle 230 using the CID public key 224 (in the write-protected memory 238 of the vehicle 230). If the verification code block 264 successfully verifies the digital signature of the encrypted message 256 using the CID public key 224, then the CID 202 is authenticated.
[0062] IOC 234 may also pass encrypted message 256 to decrypt code block 266 to decrypt the ID code of the encrypted message. In decrypt code block 266, the ID code encrypted by CID 202 using vehicle public key 223 (in write-protected memory 210 of CID 202) may be decrypted using vehicle private key 226 (in RPMB 240 of vehicle 230). After decryption code block 266 decrypts the ID code, decryption code block 266 may output the original function code 251 associated with the selected key of CID 202 (e.g., lock key 204, unlock key 205, engine start key 206, or window control key 207, depending on the driver's selection). Function code 251 may then be processed by IOC 234. Processing the function code 251 may include retrieving a function mapping 237 from the memory 236 that maps the function code 251 to a corresponding function of the vehicle 230, so that the corresponding function of the vehicle 230 may then be executed.
[0063] In some embodiments, verifying the digital signature in verification code block 264 may include comparing the decrypted data of the digital signature (e.g., data decrypted using CID public key 224) with the encrypted ID code included in the ID code portion of the encrypted message. For example, the decrypted data of the digital signature may be the ID code, and the digital signature is the ID code encrypted with CID private key 225. If the ID code obtained from the encrypted message is the same as the ID code obtained by decrypting the digital signature with the CID public key, then the CID 202 may be authenticated.
[0064] In another alternative embodiment, verifying the digital signature in verification code block 264 may include comparing the decrypted data of the digital signature with the decrypted function code 251 (e.g., the function code 251 decrypted from the ID code) output by decryption code block 266. For example, in some embodiments, the decrypted data of the digital signature may be the function code 251, and the digital signature is the function code 251 encrypted with CID private key 225. If the function code 251 obtained by decrypting the ID code of the encrypted message using vehicle private key 226 is the same as the function code 251 obtained by decrypting the digital signature with the CID public key, then CID 202 may be authenticated.
[0065] In yet another embodiment, the decrypted data of the digital signature may be a first hash of the ID code (or function code 251) (e.g., a value obtained by inputting the ID code or function code 251 into a hash function), and the digital signature is the first hash encrypted with the CID private key 225. If a second hash obtained by inputting the ID code (or function code 251) into the hash function is the same as the first hash obtained by decrypting the digital signature with the CID public key, the CID 202 may be authenticated. An advantage of using a hash in the digital signature is that the length of the cryptographic message and the corresponding transmission time may be reduced. In some embodiments, the hash function may be transmitted in the cryptographic message from the CID 202 to the vehicle 230. In another embodiment, the hash function may be stored in the memory 227 of the CID 202 and the memory 236 of the vehicle 230.
[0066] In some embodiments, executing the corresponding function of vehicle 230 may include sending an electronic signal to a BCM of vehicle 230, which may activate an actuator of vehicle 230. For example, function code 251 may correspond to unlock key 205, such that an electronic signal may be sent to a BCM (e.g., BCM 122 of vehicle 102) responsible for controlling the windows and doors of vehicle 230. The electronic signal may be relayed to one or more door actuators (e.g., door actuators 126 of vehicle 102), which may activate one or more locks on one or more doors of the vehicle to unlock one or more doors of the vehicle (e.g., a driver's door, or all doors of the vehicle, etc.). Alternatively, function code 251 may correspond to lock key 204, such that an electronic signal sent to the BCM and relayed to one or more door actuators may activate one or more locks to lock one or more doors of the vehicle.
[0067] In another example, executing the corresponding function of vehicle 230 includes sending an electronic signal to an engine ECU of vehicle 230 (e.g., engine ECU 124 of vehicle 102). For example, function code 251 may correspond to engine start key 206, indicating that the driver wishes to start vehicle 230. When the electronic signal is received by the engine ECU, the engine ECU may instruct an ignition system of vehicle 230 (e.g., ignition system 132 of vehicle 102) to start the engine. It should be understood that the examples provided herein are for illustrative purposes, and that other functions of vehicle 230 may be executed in response to function code 251 without departing from the scope of the present disclosure.
[0068] 4, a flowchart illustrating an example method 400 for transmitting a cryptographic message from a CID to a vehicle (e.g., CID 202 and vehicle 230, respectively, of FIG. 2A) during operation of the vehicle's keyless entry system (e.g., keyless entry system 100 of FIG. 1). The transmitted cryptographic message may include an ID code portion, which may be an encrypted function code, and a digital signature portion, which may enable or facilitate authentication of the CID. The function code may be associated with a key for the CID selected by an operator of the vehicle, and the function code may indicate one or more vehicle functions that may be remotely performed by the operator.
[0069] In some embodiments, the keyless entry system is a PK system, and one or more vehicle functions are performed when the CID is detected within a threshold proximity of the vehicle. In some embodiments, the keyless entry system is an RKE system, and one or more vehicle functions are performed in response to RF signals transmitted by the CID to the vehicle in response to a driver selecting one or more keys on the CID.
[0070] The method 400 begins at part 402, which includes monitoring RF signals from a vehicle to determine the proximity of a CID to the vehicle. After part 402, the method 400 may proceed to part 404.
[0071] In some embodiments, the proximity of the CID to the vehicle may be determined by measuring the strength of the RF signal transmitted by the vehicle. For example, the CID may be outside a threshold proximity (e.g., 10 feet) of the vehicle, where the strength of the RF signal is below the threshold RF signal strength, or the CID may be within a threshold proximity of the vehicle, where the strength of the RF signal is above the threshold RF signal strength.
[0072] In some embodiments, the threshold RF signal strength may be the signal strength at which an RF signal is detected by the CID's RF transceiver (e.g., RF chip 214 of FIG. 2A). Thus, when a driver carrying the CID is outside the threshold proximity, the CID's RF transceiver does not detect the RF signal, and when the driver comes within the threshold proximity, the CID's RF transceiver detects the RF signal. The signal strength may be determined by measuring the amplitude of the RF signal. In some embodiments, the RF signal is transmitted by the vehicle periodically (e.g., every second).
[0073] In some embodiments, an RF signal received from a vehicle may transmit encrypted or unencrypted data to the CID. In some embodiments, the RF signal includes a challenge message that the CID uses to authenticate the vehicle. For example, the challenge message may be based on a rolling code technique. According to the rolling code technique, the CID may maintain a first sequence counter and the vehicle may maintain a second sequence counter. The vehicle may encrypt the first sequence counter based on a shared secret key and transmit the encrypted first sequence counter in a challenge message to the CID. The CID may then decrypt the encrypted first sequence counter in the challenge message using the shared secret key and compare it with the second sequence counter. If the difference between the decrypted first and second sequence counters is below a threshold difference, the vehicle may be authenticated.
[0074] In part 404, method 400 includes determining whether the CID is within a threshold proximity of the vehicle. If it is determined in part 404 that the CID is within the threshold proximity, method 400 proceeds to part 408. Alternatively, if it is determined in part 404 that the CID is not within the threshold proximity, method 400 proceeds to part 406.
[0075] In part 408, method 400 includes encrypting a vehicle's predetermined function code (which may be stored in a write-protected memory of the CID), as described above in connection with CID configuration system 200 of FIG. 2A. The predetermined function code may be a function code assigned to a vehicle function that is predetermined to be executed in response to detecting the CID being brought within a threshold distance of the vehicle, and the predetermined function code may be encrypted using the vehicle's public key stored in the write-protected memory of the CID. In some embodiments, the predetermined function code is a function code associated with unlocking the vehicle's doors. In some embodiments, the predetermined function code is a function code associated with starting the vehicle's engine. In some embodiments, both a first predetermined function code associated with unlocking the vehicle's doors and a second predetermined function code associated with starting the vehicle's engine may be transmitted (e.g., in two respective encrypted messages). In some embodiments, encrypting the function code into an ID code includes inputting the function code into a hash function using the vehicle's public key to output the ID code. After part 408, method 400 may proceed to part 412.
[0076] In part 406, method 400 includes determining whether a CID key selection is received from the CID. For example, the driver may select an unlock key for the CID indicating a desire to unlock the vehicle, or the driver may select a lock key for the CID indicating a desire to lock the vehicle, or the driver may select another key for the CID. If it is determined in part 406 that a CID key selection is received from the CID, method 400 proceeds to part 410. If it is determined in part 406 that a CID key selection is not received from the CID, method 400 returns to part 402, and method 400 may continue to monitor RF signals from the vehicle to determine proximity to the vehicle.
[0077] In part 410, method 400 includes encrypting a feature code associated with the CID key selection into an ID code. According to the cryptographic systems disclosed herein, the feature code associated with the CID key selection may be encrypted using the vehicle's public key (which may be stored, for example, in a write-protected memory of the CID). For example, the driver may select an unlock key for the CID, and then the feature code associated with the unlock key may be encrypted using the vehicle's public key, or the driver may select a starter key for the CID, and then the feature code associated with the starter key may be encrypted using the vehicle's public key. In some embodiments, encrypting the feature code into an ID code includes inputting the feature code into a hash function that uses the vehicle's public key to output the ID code. After part 410, method 400 may proceed to part 412.
[0078] At part 412, method 400 includes generating a digital signature by digitally signing the ID code using the CID's private key (which may, for example, be stored in the CID's RPMB) in accordance with the digital signature system disclosed herein. To digitally sign the ID code, one of a variety of digital signature algorithms may be used, such as RSA, DSA, ECDSA, EDDSA, and RSA with SHA, as described above with reference to FIG. 2B. After part 412, method 400 may proceed to part 414.
[0079] At part 414, method 400 includes creating a cryptographic message, the cryptographic message including an ID code portion and a digital signature portion. In some embodiments, the cryptographic message may be generated by concatenating a first bit string that encodes the ID code and a second bit string that encodes the digital signature, as described above in connection with FIG. 2B. Thus, the encryption and signing of a feature code associated with a selected key of a CID may be described according to the following pseudocode: IDCode = Encrypt(FeatureCode, VehiclePublicKey); DigitalSignature = Signature(IDCode, CIDPrivateKey); Encrypted message = [ID code + digital signature] After part 414, the method 400 may proceed to part 416.
[0080] At part 416, method 400 includes transmitting the encrypted message wirelessly to the vehicle using any of a variety of wireless digital transmission technologies that support encoding. In some embodiments, the encrypted message may be converted to an RF signal for transmission to the vehicle, as described above in connection with FIG. 2B. After part 416, method 400 may end, and the end of one iteration of method 400 may lead to the initiation of another iteration of method 400.
[0081] In various embodiments, method 400 may be performed by one or more processors (such as processor 228) of the CID based on instructions stored in a memory (e.g., memory 227) of the CID. Thus, one or more parts of method 400 may be performed with reference to one or more elements of FIG. 2B.
[0082] 5, a flowchart illustrating an example method 500 for receiving an encrypted message sent by a CID to a vehicle (e.g., CID 202 and vehicle 230, respectively, of FIG. 2A) during operation of the vehicle's keyless entry system (e.g., keyless entry system 100 of FIG. 1). The received encrypted message may include an ID code portion, which may be an encrypted function code, and a digital signature portion, which may enable or facilitate authentication of the CID. The function code may be associated with a key for the CID selected by an operator of the vehicle, and the function code indicates one or more vehicle functions that may be remotely performed by the operator of the vehicle.
[0083] In some embodiments, the keyless entry system is a PK system and the function code corresponds to a key in the CID selected by the driver. In some embodiments, the keyless entry system is an RKE system and the function code corresponds to a predetermined function of the vehicle, such as an unlock function.
[0084] Method 500 begins at part 502, which includes transmitting a scan message to a CID to determine the proximity of the CID to the vehicle, as described above with reference to method 400 of FIG. 4. In some embodiments, the RF signal transmitted by the vehicle includes a challenge message used to authenticate the vehicle, such as a challenge message based on the rolling code technique described above. After part 502, method 500 may proceed to part 504.
[0085] At part 504, method 500 includes determining whether an RF transmission is received from the CID. If at part 504 it is determined that an RF transmission is not received from the CID, method 500 returns to part 502, where method 500 includes continuing to send scan messages to the CID. Alternatively, if at part 504 it is determined that an RF transmission is received from the CID, method 500 proceeds to part 506.
[0086] In some embodiments, the keyless entry system is a PK system, and the RF transmission is received in response to a scan message sent by the vehicle to the CID as a result of the CID being within threshold proximity of the vehicle, as described above with reference to method 400 of Figure 4. In some embodiments, the keyless entry system is an RKE system, and the RF transmission is initiated by the driver selecting a key (e.g., an unlock key and a start engine key) for the CID.
[0087] In part 506, method 500 includes recovering the encrypted message from the RF transmission. As previously mentioned, the encrypted message may include an ID code portion and a digital signature portion. After part 506, method 500 may proceed to part 508.
[0088] In part 508, method 500 includes verifying the digital signature extracted from the digital signature portion of the encrypted message using the public key of the CID paired with the vehicle (which may be stored, for example, in write-protected memory of the vehicle) according to the digital signature algorithm disclosed herein. After part 508, method 500 may proceed to part 510.
[0089] In part 510, method 500 includes decrypting the ID code portion of the recovered encrypted message based on the private key of the CID paired with the vehicle (which may be stored in the vehicle's RPMB, for example) according to one or more decryption algorithms disclosed herein. After part 510, method 500 may proceed to part 512.
[0090] At part 512, method 500 includes determining whether verification of the digital signature was successful. If it is determined at part 512 that verification of the digital signature was not successful, method 500 may proceed to part 514. Alternatively, if it is determined at part 512 that verification was successful, method 500 may proceed to part 516.
[0091] In some embodiments, determining whether the digital signature was successfully verified may include comparing the result of decrypting the digital signature portion of the encrypted message with the ID code portion of the encrypted message. For example, in some embodiments, the result of decrypting the digital signature may be a first ID code (e.g., if the digital signature was an ID code encrypted with a CID private key), and the decrypted ID code portion of the encrypted message may be a second ID code. If the first ID code equals the second ID code, the digital signature may be verified.
[0092] Determining whether the verification of the digital signature was successful may also include determining whether the decrypted ID code extracted from the recovered encrypted message matches a valid feature code for the vehicle. If the decrypted ID code matches a valid feature code for the vehicle, the digital signature may be verified. If the decrypted ID code does not match a valid feature code for the vehicle, the digital signature may not be verified. Thus, verification of the feature code associated with a selected key of the CID may be described according to the following pseudocode: Encrypted message = [ID code + digital signature (ID code)] verifiedIDCode = SignatureVerify(DigitalSignature(IDCode), CIDPublicKey); If(Verified ID Code = ID Code): functionCode = decrypt(IDCode, VehiclePrivateKey); If (function code matches enabled function code) trigger vehicle function
[0093] In another embodiment, the result of decrypting the digital signature may be a first function code (e.g., if the digital signature was a function code encrypted with the CID private key), and the decrypted function code portion of the encrypted message may be a second function code. If the first function code equals the second function code, the digital signature may be verified. Thus, verifying the function code associated with a selected key of the CID may be described according to the following pseudocode: Encrypted message = [ID code + digital signature (function code)] verifiedFunctionCode = SignatureVerify(DigitalSignature(FunctionCode), CIDPublicKey); functionCode = decrypt(IDCode, VehiclePrivateKey); If(function code = verified function code) If (function code matches enabled function code) trigger vehicle function
[0094] In some embodiments, the digital signature is not based on encrypted data; the digital signature may instead be based on a functionality code rather than a digitally signed ID code as described herein. In such embodiments, decryption of the ID code may be performed before verification of the digital signature. In other words, while Figure 5 shows that verification of the digital signature (e.g., in part 508) occurs before decryption of the ID code (e.g., in part 510), in embodiments in which the digital signature is based directly on the functionality code, decryption of the ID code may be performed in part 508 and verification of the digital signature may be performed in part 510.
[0095] Furthermore, in some embodiments, the digital signature may not be based on encrypted data; rather, the digital signature may be encrypted (separately or together with the function code), so that after a cryptographic message is received, the encrypted digital signature may be decrypted in a first step and the decrypted digital signature may be verified in a second step. For example, the function code may be signed with a CID, and the signed function code may then be encrypted and sent via a cryptographic message to the vehicle. At the vehicle, the signed function code may first be decrypted and then verified, as described by the pseudocode below: Encrypted message = Encryption (digital signature (function code), vehicle public key) Digital signature = Decrypt (digital signature (function code), vehicle private key) verifiedFunctionCode = SignatureVerify(DigitalSignature(FunctionCode), CIDPublicKey); If(function code = verified function code) If (function code matches enabled function code) trigger vehicle function An advantage of encrypting signed function code is that it may be more secure against attack than signing encrypted function code. In this scenario, the cryptographic message may contain the signed and encrypted function code without including the additional encrypted function code.
[0096] In yet another embodiment, the result of decrypting the digital signature may be a hash of either the ID code or the functionality code (e.g., if the digital signature is a hash of the ID code or functionality code using a hash function and encrypted with the CID private key), and the decrypted ID code portion of the encrypted message may be a second ID code or second functionality code. If the hash is equal to the result of applying the hash function to the second ID code or second functionality code, the digital signature may be verified.
[0097] In yet another embodiment, the digital signature may not be a hash of the ID code or feature code, but rather may be a hash of other data of the CID. For example, a separate identifier (ID) of the CID may be digitally signed and used to authenticate the CID, and during verification, the separate ID may be compared to a valid copy of the separate ID stored in the vehicle. By not including the ID code or feature code in the digital signature, the feature code may only be accessible by decrypting the ID code, which may provide greater security. Furthermore, the process of encrypting / decrypting the feature code and the process of generating / verifying the digital signature may be performed separately, and the digital signature may be generated before encrypting the feature code or after encrypting the feature code. It should be understood that the examples provided herein are for illustrative purposes, and different methods of verifying a digital signature based on different encryption and / or signature algorithms may be used without departing from the scope of the present disclosure.
[0098] In part 514, method 500 includes registering the verification failure. Registering the verification failure may include recording the time and / or duration of the intrusion, the success of the intrusion, information such as ID submitted for verification during the intrusion, signature information of the intruder, and / or other relevant data. The registration of the verification failure may be stored in a memory of the vehicle (e.g., memory 236 of FIGS. 2A and 2B ) and / or transmitted to a cloud-based server for further processing and / or analysis (e.g., by the OEM or vehicle manufacturer). In addition to registering the verification failure, method 500 may return to part 502, which includes continuing to send scan messages to the CID.
[0099] In part 516, method 500 includes interpreting a feature code (e.g., a decrypted ID code) extracted from the recovered encrypted message, and if the decrypted ID code matches a valid feature code for the vehicle, method 500 includes sending an activation signal to an associated control module to activate one or more desired features of the vehicle. The activation signal may be sent from the digital cab ECU to the vehicle's BCM (e.g., BCM 122 of FIG. 1) via a vehicle bus (e.g., a CAN bus), and activation signals may be sent to various actuators of the BCM, such as door actuators and window actuators, using signals. Activation signals may also be sent from the digital cab ECU to the engine ECU, for example, via a signal to initiate a remote start of the vehicle's engine. After part 516, method 500 may proceed to part 518.
[0100] In part 518, method 500 includes providing visual and / or audible confirmation regarding the execution of the desired vehicle function. Providing visual and / or audible confirmation may include, for example, playing a vehicle tone (e.g., a beep) and / or flashing one or more vehicle lights (e.g., parking lights). After part 518, method 500 may end, and the end of one iteration of method 500 may lead to the initiation of another iteration of method 500.
[0101] In various embodiments, method 500 may be performed by one or more processors of a vehicle's ECU (such as one or more processors of ECU 231), which may be the vehicle's digital cockpit ECU, based on instructions stored in the vehicle's memory (e.g., memory 236). Thus, one or more parts of method 500 may be performed with reference to one or more elements of FIG. 2B.
[0102] Thus, when a vehicle operator selects a key in the CID to remotely trigger a desired function of the vehicle, a secure cryptographic message may be transmitted from the CID to the vehicle. The secure cryptographic message may have an ID code portion and a digital signature portion. The ID code portion may include an encrypted function code, where the function code corresponds to a selected key in the CID that corresponds to the desired function of the vehicle. The digital signature portion may include a digital signature based on the function code.
[0103] The secure cryptographic message may be received by a vehicle's ECU, which includes a dedicated power source, dedicated memory, and RF transceiver. The ECU's IOC may extract and decrypt the ID code from the ID code portion of the cryptographic message to receive the function code. The ECU may extract the digital signature from the digital signature portion of the cryptographic message and verify the digital signature to authenticate the CID.
[0104] Verifying the digital signature may include determining whether the function code is present in a list of valid function codes stored in the ECU's memory. Verifying the digital signature may also include comparing the ID code to the decrypted data of the digital signature (e.g., a second ID code). If the ID code matches the decrypted data or the decrypted data matches the result of applying a hash function to the ID code, the digital signature is verified and the CID can be authenticated. If the ID code does not match the decrypted data or the decrypted data does not match the result of applying a hash function to the ID code, the digital signature cannot be verified and the CID cannot be authenticated. By encrypting and decrypting function codes used to trigger desired vehicle functions, security features related to opening and closing vehicle doors and / or windows, ignition or starting the engine, controlling alarms, and other vehicle functions can be implemented, thereby preventing attackers from conducting cyberattacks on the vehicle.
[0105] A technical effect of the systems and methods disclosed herein is that cyber attacks against a vehicle can be prevented by encrypting and digitally signing a feature code with a CID before sending the feature code to the vehicle via a cryptographic message, and then decrypting and verifying the cryptographic message at the vehicle.
[0106] The present disclosure also provides support for a method for a vehicle keyless entry system, the method including: processing, at a vehicle, a keyless entry transmission having an identification (ID) code portion; decrypting the ID code portion of the keyless entry transmission using a vehicle private key; detecting whether the decrypted ID code portion matches one of a plurality of predetermined function codes for the vehicle; and executing a vehicle function corresponding to the vehicle function code that matches the decrypted ID code portion. In a first embodiment of the method, the vehicle private key is stored in a playback-protected memory block (RPMB) of the vehicle. In a second embodiment of the method, which optionally includes the first embodiment, the decryption of the ID code portion occurs in a vehicle electronic control unit (ECU) powered by a secondary vehicle power source. In a third embodiment of the method, which optionally includes one or both of the first and second embodiments, the method includes receiving the keyless entry transmission via a radio frequency (RF) transceiver connected to the ECU. In a fourth embodiment of the method, optionally including one or more or each of the first through third embodiments, the keyless entry transmission has a digital signature portion, and the method includes verifying the digital signature portion of the keyless entry transmission based on the ID code portion and a predetermined public key of the vehicle's keyless entry device. In a fifth embodiment of the method, optionally including one or more or each of the first through fourth embodiments, the public key of the keyless entry device is stored in a write-protected memory of the vehicle. In a sixth embodiment of the method, optionally including one or more or each of the first through fifth embodiments, a plurality of predetermined function codes corresponding to a plurality of vehicle functions are generated by a vehicle true random number generator (TRNG) and assigned to both the vehicle and the keyless entry device. In a seventh embodiment of the method, optionally including one or more or each of the first through sixth embodiments, the vehicle keyless entry system is one of a remote keyless entry (RKE) system and a passive keyless entry (PKE) system. In an eighth embodiment of the method, optionally including one or more or each of the first to seventh embodiments, the vehicle function is one of a door lock function, a door unlock function, a vehicle start function, and a window control function.
[0107] The present disclosure also provides support for a method for a vehicle keyless entry system, the method including: detecting, at a keyless entry device of the vehicle, a request for a selected function from a plurality of vehicle functions; identifying a function code corresponding to the selected function from a plurality of predetermined vehicle function codes corresponding to the plurality of functions; encrypting the vehicle function code into an identification (ID) code portion using a predetermined vehicle public key; and generating, at the keyless entry device, a keyless entry transmission having the ID code portion. In a first embodiment of the method, the keyless entry transmission has a digital signature portion, and the method includes generating the digital signature portion based on the ID code portion and a private key of the keyless entry device. In a second embodiment of the method, which optionally includes the first embodiment, the private key of the keyless entry device is stored in a play-protected memory block (RPMB) of the keyless entry device. In a third embodiment of the method, which optionally includes one or both of the first and second embodiments, the public key of the vehicle is stored in a write-protected memory of the keyless entry device. In a fourth embodiment of the method, optionally including one or more or each of the first through third embodiments, the method includes transmitting a keyless entry transmission via a radio frequency (RF) transceiver of the keyless entry device. In a fifth embodiment of the method, optionally including one or more or each of the first through fourth embodiments, a plurality of predetermined function codes corresponding to a plurality of vehicle functions are generated by a vehicle true random number generator (TRNG) and assigned to both the keyless entry device and the vehicle. In a sixth embodiment of the method, optionally including one or more or each of the first through fifth embodiments, the vehicle keyless entry system is one of a remote keyless entry (RKE) system and a passive keyless entry (PKE) system. In a seventh embodiment of the method, optionally including one or more or each of the first through sixth embodiments, the function code corresponds to one of a door lock function, a door unlock function, a vehicle start function, and a window control function.
[0108] The present disclosure also provides support for a method for a vehicle keyless entry system, the system comprising: a vehicle; and a keyless entry device of the vehicle, the keyless entry device including a first radio frequency (RF) circuit and one or more first processors having executable instructions stored in a first non-transitory memory, the executable instructions, when executed, performing the following steps: detecting a request for a function of a plurality of functions of the vehicle; identifying a function code corresponding to the requested function of the vehicle, the function code being one of a plurality of function codes respectively corresponding to the plurality of functions; encrypting the function code using a public key of the vehicle; and transmitting a keyless entry transmission via the first RF circuit. the ID code portion carried by the keyless entry transmission includes an encrypted function code, and the vehicle includes a second RF circuit and one or more second processors having executable instructions stored in a second non-transitory memory, the executable instructions, when executed, causing the one or more second processors to receive the keyless entry transmission via the second RF circuit, decrypt the ID code portion carried by the keyless entry transmission using a vehicle private key, detect whether the decrypted ID code portion matches any of a plurality of function codes for the vehicle, and execute a vehicle function corresponding to the vehicle function code that matches the decrypted ID code portion. In a first embodiment of the system, the keyless entry transmission has a digital signature portion, and the executable instructions stored in the first non-transitory memory, when executed, further cause the one or more first processors to generate the digital signature portion based on the encrypted feature code and the keyless entry device's private key, and the executable instructions stored in the second non-transitory memory, when executed, further cause the one or more second processors to verify the digital signature portion based on the decrypted ID code portion and the keyless entry device's public key.In a second embodiment of the system, optionally including the first embodiment, the vehicle includes a secondary power source connected to the second RF circuit, the second non-transitory memory, and the one or more second processors, the secondary power source providing power at least when power is not available from the vehicle's primary power source.
[0109] In an alternative expression, this disclosure also provides support for a method in which a feature code associated with a vehicle feature is signed in a first step, and then the signed feature code is encrypted for transmission in a cryptographic message at the CID. When the cryptographic message is received at the vehicle, the encrypted and signed feature code can be decrypted in the first step, and the signed feature code can be verified in a second step.
[0110] The description of the embodiments has been presented for purposes of illustration and description. Suitable modifications and variations to the embodiments may occur in light of the foregoing description or may be attained from practicing the methods. For example, unless otherwise stated, one or more of the described methods may be performed by any suitable device and / or combination of devices, such as the embodiments described above with respect to FIGS. 1-5. The methods may be performed by executing stored instructions using one or more logic devices (e.g., processors) in combination with one or more hardware elements, such as storage devices, memories, hardware network interfaces / antennas, switches, and clock circuits. The described methods and related operations may also be performed in various orders, in parallel, and / or simultaneously in addition to the order described herein. The described systems are exemplary in nature and may include additional elements and / or omit elements. The subject matter of the present disclosure includes all novel and non-obvious combinations and subcombinations of the various disclosed systems and configurations, and other features, functions, and / or properties.
[0111] As used in this application, elements or steps referred to in the singular and preceded by the English word "a" or "an" should be understood as not excluding the plural of that element or step, unless a specific statement is made that excludes such elements or steps. Furthermore, references to "one embodiment" or "one example" of the present disclosure are not intended to be interpreted as excluding the existence of additional embodiments that also incorporate the recited features. Terms such as "first," "second," and "third" are used merely as labels and are not intended to impose numerical requirements or a particular positional order on their objects. The following claims particularly point out subject matter that is regarded as new and unobvious in light of the above disclosure.
[0112] Phrases listing elements using the phrase "and / or" refer to any combination of the listed elements. For example, "A, B, and / or C" can mean either A only, B only, C only, A and B, A and C, B and C, or A, B, and C.
Claims
1. 1. A method for a vehicle keyless entry system, the method comprising: generating a plurality of predetermined function codes corresponding to a plurality of functions of the vehicle using a true random number generator (TRNG) of the vehicle, and assigning the generated function codes to both the vehicle and a keyless entry device; processing, at the vehicle, a keyless entry transmission having an identification (ID) code portion; decrypting the ID code portion of the keyless entry transmission using the vehicle's private key; detecting whether the decoded ID code portion matches one of the plurality of predetermined function codes for the vehicle; executing a function of the vehicle corresponding to a function code of the vehicle that matches the decoded ID code portion; A method comprising:
2. The method of claim 1 , wherein the private key for the vehicle is stored in a playback prohibited memory block (RPMB) for the vehicle.
3. 10. The method of claim 1, wherein the decoding of the ID code portion occurs in an electronic control unit (ECU) of the vehicle that is powered by a secondary power source of the vehicle.
4. receiving the keyless entry transmission via a radio frequency (RF) transceiver connected to the ECU; The method of claim 3, comprising:
5. the keyless entry transmission having a digital signature portion; verifying the digital signature portion of the keyless entry transmission based on the ID code portion and a predetermined public key of the vehicle keyless entry device; The method of claim 1 , comprising:
6. The method of claim 5 , wherein the public key of the keyless entry device is stored in a write-protected memory of the vehicle.
7. Mapping each of the generated function codes to a respective one of the plurality of functions of the vehicle; The method of claim 1 further comprising:
8. The method of claim 1 , wherein the vehicle keyless entry system is one of a remote keyless entry (RKE) system and a passive keyless entry (PKE) system.
9. The method of claim 1 , wherein the function of the vehicle is one of a door lock function, a door unlock function, a vehicle start function, and a window control function.
10. 1. A method for a vehicle keyless entry system, the method comprising: generating a plurality of predetermined function codes corresponding to a plurality of functions of the vehicle using a true random number generator (TRNG) of the vehicle, and assigning the generated function codes to both the vehicle and a keyless entry device; detecting, at the keyless entry device of the vehicle, a request for a selected function of the plurality of functions of the vehicle; identifying a function code corresponding to the selected function from among the plurality of predetermined function codes of the vehicle corresponding to the plurality of functions; encrypting the feature code for the vehicle into an identification (ID) code portion using a predetermined public key for the vehicle; generating, at the keyless entry device, a keyless entry transmission having the ID code portion; A method comprising:
11. the keyless entry transmission having a digital signature portion; generating the digital signature portion based on the ID code portion and a private key of the keyless entry device; The method of claim 10, comprising:
12. 12. The method of claim 11, wherein the private key of the keyless entry device is stored in a playback-prohibited memory block (RPMB) of the keyless entry device.
13. The method of claim 10 , wherein the public key for the vehicle is stored in a write-protected memory of the keyless entry device.
14. transmitting the keyless entry transmission via a radio frequency (RF) transceiver of the keyless entry device; The method of claim 10, comprising:
15. Mapping each of the plurality of functions to a respective one of the generated function codes. The method of claim 10 further comprising:
16. The method of claim 10 , wherein the vehicle keyless entry system is one of a remote keyless entry (RKE) system and a passive keyless entry (PKE) system.
17. The method of claim 10 , wherein the function code corresponds to one of a door lock function, a door unlock function, a vehicle start function, and a window control function.
18. Vehicles and a keyless entry device for the vehicle; A vehicle keyless entry system comprising: The keyless entry device includes a first radio frequency (RF) circuit and one or more first processors having executable instructions stored in a first non-transitory memory, the executable instructions stored in the first non-transitory memory, when executed, Detecting a request for one of a plurality of functions of the vehicle; identifying a function code corresponding to the requested function of the vehicle, the function code being one of a plurality of function codes respectively corresponding to the plurality of functions; encrypting the feature code using the vehicle's public key; transmitting a keyless entry transmission via the first RF circuit; on the one or more first processors; an ID code portion of the keyless entry transmission including the encrypted function code; the vehicle includes a second RF circuit and one or more second processors having executable instructions stored in a second non-transitory memory, the executable instructions stored in the second non-transitory memory, when executed, receiving the keyless entry transmission via the second RF circuit; decrypting the ID code portion of the keyless entry transmission using the vehicle's private key; detecting whether the decoded ID code portion matches any of the plurality of feature codes for the vehicle; executing the function of the vehicle corresponding to the function code of the vehicle that matches the decoded ID code portion; on the one or more second processors; the plurality of function codes are stored in the first non-transitory memory and the second non-transitory memory and are generated by a true random number generator (TRNG).
19. the keyless entry transmission having a digital signature portion; The executable instructions stored in the first non-transitory memory, when executed, further cause the one or more first processors to generate the digital signature portion based on the encrypted function code and a private key of the keyless entry device; The executable instructions stored in the second non-transitory memory, when executed, further cause the one or more second processors to verify the digital signature portion based on the decrypted ID code portion and a public key of the keyless entry device.
20. The vehicle keyless entry system of claim 18.
20. 20. The vehicle keyless entry system of claim 18, wherein the vehicle includes a secondary power source coupled to the second RF circuit, the second non-transitory memory, and the one or more second processors, the secondary power source providing power at least when power is not available from a primary power source of the vehicle.
Citation Information
Patent Citations
Remote access system
JP1992302682A
Vehicle communication lock system, vehicle, slave machine and master machine of vehicle communication lock system
JP2007085007A
Generating IDs for Computing Devices Using Physically Unclonable Functions
JP2022527757A
Multiple vehicle authentication for entry and starting systems
US20070001805A1
Remote management and control of vehicular functions via multiple networks
US20140005859A1