Component control method and related apparatus for devices

JP7915837B2Active Publication Date: 2026-09-04YINWANG INTELLIGENT TECHNOLOGIES CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024573864
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-06-17
Filing Date
2023-06-16
Publication Date
2026-09-04
Estimated Expiration
2043-06-16

Smart Images

  • Figure 0007915837000001
    Figure 0007915837000001
  • Figure 0007915837000002
    Figure 0007915837000002
  • Figure 0007915837000003
    Figure 0007915837000003
Patent Text Reader

Abstract

The present application provides a component control method and a related device for a device that may be used in an intelligent vehicle or a new energy vehicle. The method includes that when the authentication performed by a second controller on a first controller is successful and the authentication result is reliable, the first controller sends a control instruction to a component, and when the component determines that the authentication is successful, the component responds to the control instruction. In this solution, the authentication for the component can be transferred to the first controller, and the first controller can control one or more components by using the control instruction. It is not necessary to pre-set keys and embed algorithms in all components that require authentication. It is only necessary to pre-set keys and embed algorithms in only two or three controllers, so that security protection can be provided for more components, more requirements can be met, and the development and maintenance costs can be reduced. Also, when the authentication performed on the first controller is successful, the component needs to respond to the control instruction, and the control instruction needs to be sent when the first controller determines that the authentication result is reliable. In this way, the security is higher.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present application relates to the security field, and more specifically to a component control method for a device and a related apparatus. [Background Art]

[0002] With the development of life, more and more devices such as automobiles, motorcycles, or other smart devices are used in daily life. To improve safety and avoid problems such as device theft, more anti-theft solutions are provided for devices.

[0003] Currently, a common anti-theft solution is a point-to-point authentication solution. An automobile is used as an example. A controlled automobile component can send an authentication request to a controller, and the controller may perform authentication on the automobile component based on a key negotiated in advance by both parties. If the authentication succeeds, the automobile component can execute a corresponding function in response to a control operation. However, different devices include various components with different functions, and the security protection requirements for devices vary. [Summary of the Invention]

[0004] The present application provides a component control method for a device and a related apparatus to meet more security protection requirements.

[0005] According to a first aspect, the present application provides a component control method for a device. The method may be executed by a component, or may be implemented by a chip or a chip system configured in a component, or another functional module or software that may be configured to implement some or all functions of a component. This is not limited in the present application.

[0006] For example, the method includes obtaining a control command from a first controller, the control command being a command sent by the first controller when authentication performed by the second controller to the first controller is successful and the authentication result is reliable; obtaining the result of authentication performed by the second controller to the first controller, the authentication result including authentication success or authentication failure; and responding to the control command if the authentication result is authentication success.

[0007] In a device, different components may be used to implement different functions. In this application, components may be controlled by a first controller and respond after receiving control commands from the first controller. In other words, the first controller may control one or more components to perform corresponding operations by using control commands. The components that can be controlled by the first controller may be predefined by the device manufacturer before delivery, or the components that can be controlled by the first controller may be adjusted as required during subsequent use. This is not limited to this application.

[0008] Since the first controller can control one or more components, the second controller authenticates the first controller rather than the components themselves, thus avoiding authentication for all components. In this way, it is not necessary to pre-set keys and embed algorithms for all components that have authentication requirements; keys only need to be pre-set and algorithms embedded for just two or three controllers. This allows for control of more components and achieves theft prevention. Consequently, security protection can be provided to more components, more requirements can be met, and development and maintenance costs can be reduced.

[0009] In addition, two conditions must be met simultaneously for control commands to be sent to the component: successful authentication and a reliable authentication result. In other words, the conditions restricting the transmission of control commands by the first controller are stringent, making it easier to avoid unauthorized operation of the device and preventing theft. Thus, security is improved.

[0010] Referring to the first aspect, in some possible implementations of the first aspect, the authentication result is authentication success, and obtaining the result of the authentication performed by the second controller to the first controller includes receiving an authentication success notification from the second controller, which is used to notify the first controller that the authentication performed by the second controller was successful.

[0011] The second controller may send an authentication success notification to the first controller when authentication to the first controller is successful, in order to notify the component that authentication to the first controller was successful.

[0012] Optionally, authentication success notifications can be sent via broadcast.

[0013] Since the authentication success notification is sent via broadcast, all components within the device can receive the notification, ensuring full coverage. This solution of sending authentication success notifications via broadcast is particularly applicable to the offline diagnostic phase before the device is delivered.

[0014] Optionally, authentication success notifications are sent to one or more predefined components.

[0015] The authentication success result is sent to one or more predefined components, so that one or more components can receive the notification without causing unnecessary impact on other components.

[0016] The method for sending the authentication success notification is not limited in this application.

[0017] If the second controller is unable to authenticate the first controller, the second controller may send an authentication failure notice to notify the first controller that authentication has failed, or it may not send any notice. This is not limited to the present invention.

[0018] Both authentication success notifications and authentication failure notifications indicate the authentication result and can be considered concrete examples of indicating the authentication result.

[0019] Referring to the first aspect, in some possible implementations of the first aspect, the method further includes sending a response message to a second controller, the response message indicating that it has successfully received an authentication success notification.

[0020] The component feeds a response message back to the second controller, which can then determine whether the component is functioning correctly and whether the authentication result is reliable. For example, if the component has been replaced, the second controller may not receive a response message. In this case, even if authentication to the first controller is successful, the component may still be unable to perform operations because it has a problem. Therefore, the second controller may set the authentication result to be unreliable in order to prevent the first controller from sending control commands, to prevent the component from responding, and to achieve anti-theft effects.

[0021] In accordance with a second aspect, the present application provides a method for controlling components for a device. The method may be performed by a first controller, or by a chip or chip system configured in the first controller, or by other functional modules or software that can be configured to implement some or all of the functions of the first controller. This is not limited to the present application.

[0022] The first controller in the second aspect may correspond to controller #2 in a subsequent embodiment.

[0023] For example, the method includes obtaining the result of authentication performed by the second controller on the first controller, the result of which may include authentication success or authentication failure, and, if the authentication result is successful and the result is trustworthy, sending a control command to a component controlled by the first controller to trigger the controller to respond.

[0024] In a device, different components may be used to implement different functions. In this application, components may be controlled by a first controller and respond after receiving control commands from the first controller. In other words, the first controller may control one or more components to perform corresponding operations by using control commands. The components that can be controlled by the first controller may be predefined by the device manufacturer before delivery, or the components that can be controlled by the first controller may be adjusted as required during subsequent use. This is not limited to this application.

[0025] Since the first controller can control one or more components, the second controller authenticates the first controller rather than the components themselves, thus avoiding authentication for all components. In this way, it is not necessary to pre-set keys and embed algorithms for all components that have authentication requirements; keys only need to be pre-set and algorithms embedded for just two or three controllers. This allows for control of more components and achieves theft prevention. Consequently, security protection can be provided to more components, more requirements can be met, and development and maintenance costs can be reduced.

[0026] In addition, in order to send a control instruction to the component, the first controller needs to satisfy two conditions at the same time, that is, successful authentication and a reliable authentication result. In other words, since the conditions for restricting the transmission of control instructions by the first controller are strict, unauthorized operation of the device can be further avoided, and theft of the device can be prevented. Accordingly, safety is improved.

[0027] Referring to the second aspect, in some possible implementations of the second aspect, the method further comprises receiving an authentication reliability notification from a second controller, wherein the authentication reliability notification indicates that the authentication result is reliable.

[0028] That is, the first controller can determine whether the authentication result is reliable based on the notification from the second controller, and further can determine whether a control instruction can be sent to the component.

[0029] Referring to the first aspect or the second aspect, in some possible implementations, if a key used for unlocking the device is not within a preset range, the authentication result is authentication failure.

[0030] Herein, the preset range may be the sensing range of the device, that is, the maximum range in which a mobile device can detect the key.

[0031] If the key is not within the preset range, the device may be illegally activated by a third party. In this case, in order to prevent a third party from illegally activating the device, prevent theft of the device and achieve high safety, the authentication result can be set as authentication failure.

[0032] That the key is used to unlock the device may include that the key is used to unlock a door or a window, apply a high voltage, activate the device, etc. This is not limited in the present application.

[0033] Referring to the first or second aspect, in some possible implementations, if a predefined abnormal situation is detected, the authentication result is authentication failure.

[0034] Here, an abnormal situation may be a predefined event that is considered to be unauthorized access to the device and unauthorized activation of the device, and may include, but is not limited to, breaking windows, breaking doors, and lock picking.

[0035] If an abnormal situation is detected, the device may have been compromised or illegally activated. In this case, to prevent third parties from illegally activating the device, to prevent theft, and to ensure high security, the authentication result may be set to authentication failure.

[0036] In accordance with a third aspect, the present application provides a component control method for a device. The method is: Second controller This may be performed by, or by, a chip or chip system configured in the second controller, or by other functional modules or software that can be configured to implement some or all of the functions of the second controller. This is not limited to the present invention.

[0037] The second controller in the third aspect may correspond to controller #1 in a subsequent embodiment.

[0038] For example, the method includes sending an authentication success notification if authentication to the first controller is successful, the authentication success notification being used to indicate that the authentication to the first controller was successful, and sending an authentication reliability notification to the first controller if a response message is received, the response message being from a component controlled by the first controller, the response message indicating that the authentication success notification was successfully received, and the authentication reliability notification indicating that the authentication success notification is trustworthy.

[0039] In a device, different components may be used to implement different functions. In this application, components may be controlled by a first controller and respond after receiving control commands from the first controller. In other words, the first controller may control one or more components to perform corresponding operations by using control commands. The components that can be controlled by the first controller may be predefined by the device manufacturer before delivery, or the components that can be controlled by the first controller may be adjusted as required during subsequent use. This is not limited to this application.

[0040] Since the first controller can control one or more components, the second controller authenticates the first controller rather than the components themselves, thus avoiding authentication for all components. Consequently, it is not necessary to pre-set keys and embed algorithms for all components that have authentication requirements; keys only need to be pre-set and algorithms embedded for just two or three controllers. This allows for control of more components and achieves theft prevention. Therefore, security protection can be provided to more components, more requirements can be met, and development and maintenance costs can be reduced.

[0041] In addition, the second controller sends an authentication success notification, allowing the component to obtain the authentication result. Furthermore, the second controller sends an authentication reliability notification to the first controller based on the response message fed back by the component. The first controller then sends a control command after determining that the authentication result is reliable. The parties cooperate with each other to ensure that the conditions for the first controller to send a control command are met, and then the conditions for the component to respond to the control command are met. Thus, unauthorized operation of the device can be more easily avoided, theft of the device can be prevented, and security is improved.

[0042] Optionally, authentication success notifications can be sent via broadcast.

[0043] Since the authentication success notification is sent via broadcast, all components within the device can receive the notification, ensuring full coverage. This solution of sending authentication success notifications via broadcast is particularly applicable to the offline diagnostic phase before the device is delivered.

[0044] Optionally, authentication success notifications are sent to one or more predefined components.

[0045] The authentication success result is sent to one or more predefined components, so that one or more components can receive the notification without causing unnecessary impact on other components.

[0046] The method for sending the authentication success notification is not limited in this application.

[0047] If the second controller is unable to authenticate the first controller, the second controller may send an authentication failure notice to notify the first controller that authentication has failed, or it may not send any notice. This is not limited to the present invention.

[0048] Both authentication success notifications and authentication failure notifications indicate the authentication result and can be considered concrete examples of indicating the authentication result.

[0049] Referring to the third aspect, some possible implementations of the third aspect further include receiving a response message from the component.

[0050] The component feeds a response message back to the second controller, which can then determine whether the component is functioning correctly and whether the authentication result is reliable. For example, if the component has been replaced, the second controller may not receive a response message. In this case, even if authentication to the first controller is successful, the component may still be unable to perform operations because it has a problem. Therefore, the second controller may set the authentication result to be unreliable in order to prevent the first controller from sending control commands, to prevent the component from responding, and to achieve anti-theft effects.

[0051] Referring to the aspects mentioned above, in some possible implementations, the device is a vehicle.

[0052] In a possible design, the first controller includes a vehicle domain controller (VDC) and / or a vehicle control unit (VCU), and the second controller includes a vehicle integrated unit (VIU), a wireless communication control module (e.g., a Bluetooth electronic control unit (ECU)), and Body control module, BCM ) It includes at least one of the above, and the component includes a motor and / or a battery management system (BMS).

[0053] In another possible design, the first controller includes a wireless communication control module, the second controller includes a VIU and / or BCM, and the components include a door controller and / or window controller.

[0054] In yet another possible design, the first controller includes a remote communication module, the second controller includes a VIU or BCM, and the components include one or more of the following: motor, BMS, door controller, and window controller.

[0055] The above designs may be used separately or in combination without conflict. For example, the first controller is a VIU, and the second controller includes a VDC or a wireless communication control module, and the components include at least one of a motor and BMS and a door controller. The motor and BMS may be controlled by the VDC, and the door controller may be controlled by a wireless communication control module.

[0056] The above designs of the first controller, the second controller, and components are merely examples and should not constitute any limitation to the present invention.

[0057] To facilitate understanding, the following provides some concrete examples.

[0058] In one example, the component includes a motor, a control command instructs the motor to perform a power output operation, and responding to the control command includes performing a power output operation in response to the control command.

[0059] In possible implementations, a control command carries a torque request, and responding to a control command includes performing a torque response and power output in response to the torque request in the control command. A motor may be used to convert electrical energy into mechanical energy to supply power to a device (e.g., a vehicle) and drive the device to move. Upon receiving a torque request, the motor may perform a torque response and power output including, but not limited to, drive wheel rotation and rotational speed responses. The operations performed by the motor in response to a control command described above are merely examples, and operations performed by the motor in response to a control command are not limited herein.

[0060] The motor is controlled so that power output operations are not performed if the device (e.g., a vehicle) is tampered with. In this way, the device cannot be driven to move, and theft of the device is prevented.

[0061] In another example, the component includes a BMS, and a control command instructs the BMS to output power. Responding to a control command includes outputting power in response to the control command.

[0062] Here, outputting power includes, but is not limited to, turning on the power, supplying power, etc. Power is output, thereby enabling the motor to obtain electrical energy to drive the vehicle to move.

[0063] Based on the above solution, the BMS can be controlled so that power is not output if a device (e.g., a vehicle) is tampered with. Therefore, the device cannot be started, and theft of the device is prevented.

[0064] In yet another example, the component includes a door controller, and a control command instructs the door controller to unlock the door. Responding to a control command includes unlocking the door in response to the control command.

[0065] In yet another example, a component includes a window controller, and a control command instructs the window controller to unlock the window. Responding to a control command includes unlocking the window in response to the control command.

[0066] The door controller and window controller may be controlled simultaneously or separately. This is not limited to the present invention.

[0067] Based on the above solution, the door controller can be controlled to prevent the device (e.g., a vehicle) from unlocking a door or window if the door or window is opened illegally. Thus, it is possible to prevent the device's doors or windows from being opened and to prevent items from being lost from inside the device.

[0068] In accordance with the fourth aspect, the present application provides a component control device for a device, comprising a module or unit configured to implement a method according to the first aspect and any one of the possible implementations thereof. Each module or unit may implement a corresponding function by executing a computer program.

[0069] For example, the device includes a transceiver unit and a processing unit. The transceiver unit is configured to receive control commands from a first controller, which are commands sent by the first controller if authentication performed by the second controller to the first controller is successful and the authentication result is reliable. The processing unit is configured to receive the authentication result, which indicates whether authentication performed by the second controller to the first controller was successful, and is further configured to respond to the control command if the authentication result is successful.

[0070] Referring to the fourth aspect, in some possible implementations of the fourth aspect, the authentication result is authentication success, and the transceiver unit is specifically configured to receive an authentication success notification from the second controller, which is used to notify the first controller that the authentication performed by the second controller was successful.

[0071] Referring to the fourth aspect, in some possible implementations of the fourth aspect, the authentication success notification is sent by broadcast or sent to one or more predefined components.

[0072] Referring to the fourth aspect, in some possible implementations of the fourth aspect, the transceiver unit is further configured to send a response message to a second controller, the response message indicating successful receipt of an authentication success notification.

[0073] Referring to the fourth aspect, in some possible implementations of the fourth aspect, the device is a vehicle.

[0074] In a possible design, the first controller includes a VDC and / or VCU, the second controller includes at least one of the following: a VIU, a wireless communication control unit, or a BCM, and the device includes a motor and / or BMS.

[0075] In another possible design, the first controller includes a wireless communication control unit, the second controller includes a VIU and / or BCM, and the device includes a door controller and / or window controller.

[0076] In yet another possible design, the first controller includes a remote communication unit, the second controller includes a VIU and / or BCM, and the device includes one or more of the following: motor, BMS, door controller, and window controller.

[0077] For example, the device includes a motor, and the control command carries a torque request. The processing unit is specifically configured to perform torque response and power output in response to the torque request in the control command.

[0078] In another example, the device includes a BMS, and a control command instructs the BMS to output power. The processing unit is specifically configured to output power in response to the control command.

[0079] In yet another example, the device includes a door controller, and a control command instructs the door controller to unlock the door. A processing unit is specifically configured to unlock the door in response to the control command.

[0080] In yet another example, the device includes a window controller, and a control command instructs the window controller to unlock the window. Processing unit It unlocks the window in response to a control command. It is particularly composed .

[0081] In accordance with the fifth aspect, the present application provides a component control device for a device, comprising a module or unit configured to implement a method according to the second aspect and any one of the possible implementations thereof. Each module or unit may implement a corresponding function by executing a computer program.

[0082] For example, the device includes a transceiver unit and a processing unit. The processing unit is configured to obtain the result of authentication performed on the device by a second controller, the authentication result including authentication success or authentication failure. The transceiver unit is configured to send a control command to a component controlled by the device to trigger the component to respond, if the authentication result is successful and the authentication result is reliable.

[0083] Referring to the fifth aspect, in some possible implementations of the fifth aspect, the transceiver unit is further configured to receive an authentication reliability notification from the second controller, the authentication reliability notification indicating that the authentication result is reliable.

[0084] Referring to the fifth aspect, in some possible implementations of the fifth aspect, the device is a vehicle.

[0085] In a possible design, the device includes a VDC and / or VCU, the second controller includes at least one of the following: a VIU, a wireless communication control unit, and a BCM, and the component includes a motor and / or BMS.

[0086] In another possible design, the device includes a wireless communication control unit, the second controller includes a VIU and / or BCM, and the components include a door controller and / or window controller.

[0087] In yet another possible design, the device includes a remote communication unit, the second controller includes a VIU and / or BCM, and the components include one or more of the following: motor, BMS, door controller, and window controller.

[0088] Referring to the fourth or fifth aspect, in some possible implementations, if the key used to activate the device is not within a pre-set range, or if a predefined abnormal condition is detected, the authentication result is authentication failure.

[0089] In accordance with the sixth aspect, the present application provides a component control device for a device, comprising a module or unit configured to implement a method according to the third aspect and any one of the possible implementations thereof. Each module or unit may implement a corresponding function by executing a computer program.

[0090] For example, the device includes a transceiver unit. The transceiver unit is configured to send an authentication success notification if authentication to a first controller is successful, the authentication success notification is used to notify the first controller that authentication has been successful, and is further configured to send an authentication reliability notification to the first controller if a response message is received, the response message is sent from a component controlled by the first controller, the response message indicates that the authentication success notification was successfully received, and the authentication reliability notification indicates that the authentication success notification is reliable.

[0091] Referring to the sixth aspect, in some possible implementations of the sixth aspect, the authentication success notification is sent by broadcast or sent to one or more predefined components.

[0092] Referring to the sixth aspect, in some possible implementations of the sixth aspect, the transceiver unit is further configured to receive a response message from the component, the response message indicating successful receipt of an authentication success notification.

[0093] Referring to the sixth aspect, in some possible implementations of the sixth aspect, the device is a vehicle.

[0094] In a possible design, the device includes at least one of the following: VIU, wireless communication control unit, and BCM, the first controller includes VDC and / or VCU, and the component includes motor and / or BMS.

[0095] In another possible design, the device includes a VIU and / or BCM, the first controller includes a wireless communication control unit, and the components include a door controller and / or window controller.

[0096] In yet another possible design, the device includes a VIU and / or BCM, the first controller includes a telecommunications unit, and the components include one or more of the following: motor, BMS, door controller, and window controller.

[0097] Referring to the sixth aspect, in some possible implementations of the sixth aspect, the transceiver unit is further configured to receive authentication requests from a first controller, the authentication requests being used to request the first controller to perform authentication, and the device further includes a processing unit configured to perform authentication with the first controller in response to the authentication request and obtain an authentication result.

[0098] Optionally, the processing unit may be further configured to determine that the authentication result is an authentication failure if the key is not detected within a pre-set range, and the key is the key used to activate the device.

[0099] Optionally, the processing unit may be further configured to determine that the authentication result is an authentication failure if a predefined abnormal situation is detected.

[0100] In accordance with the seventh aspect, the present application provides a component control device for a device, including a processor, the processor being configured to perform a component control method for a device according to either the first aspect or one of possible implementations thereof.

[0101] In accordance with the eighth aspect, the present application provides a component control device for a device, including a processor, the processor being configured to perform a component control method for a device according to the second aspect or one of possible implementations thereof.

[0102] In accordance with the ninth aspect, the present application provides a component control device for a device, including a processor, the processor being configured to perform a component control method for a device according to the third aspect or one of a possible implementation of the third aspect.

[0103] Optionally, a device conforming to the seventh through ninth aspects may further include memory configured to store instructions and data. The memory is coupled to a processor, and when it executes instructions stored in the memory, the processor can implement the methods described in the above aspects. The device may further include a communication interface. The communication interface is used by the device to communicate with other devices. For example, the communication interface may be a transceiver, circuit, bus, module, or other type of communication interface.

[0104] In accordance with the tenth aspect, the present application provides a chip system. The chip system includes at least one processor configured to support the implementation of a function in any one of the first to third aspects and possible implementations of the first to third aspects, for example, the receiving or processing of data and / or information contained in the above information.

[0105] In possible designs, the chip system further includes memory, which is configured to store program instructions and data, and the memory is located inside or outside the processor.

[0106] The chip system may include a chip, or it may include a chip and other discrete components.

[0107] In accordance with the eleventh aspect, the present application provides a vehicle, which includes a first controller, a second controller, and the vehicle itself. The first controller is configured to send a control command to a component if authentication performed on the first controller by the second controller is successful and the authentication result is reliable, and whether the authentication result is reliable is determined based on a notification from the first controller. The component is configured to obtain the result of authentication performed on the first controller by the second controller, the authentication result includes authentication success or authentication failure, and the component is further configured to respond to a control command if the authentication result is authentication success.

[0108] For example, the component described above may be configured to perform a method according to the first aspect or one of the possible implementations of the first aspect, and the component may correspond to a device according to the fourth aspect or the seventh aspect. The first controller may be configured to perform a method according to the second aspect or one of the possible modes of the second aspect, and the first controller may correspond to a device according to the fifth aspect or the eighth aspect. The second controller may be configured to perform a method according to the third aspect or one of the possible implementations of the third aspect, and the second controller may correspond to a device according to the sixth aspect or the ninth aspect.

[0109] In accordance with the twelfth aspect, the present application provides a computer-operated storage medium containing a computer program. When the computer program is executed on a computer, the computer may implement a method that conforms to any one of the possible implementations of the first through third aspects and the first through third aspects.

[0110] In accordance with the thirteenth aspect, the present application provides a computer program product comprising a computer program (which may also be called code or instructions), and when the computer program is executed, the computer can perform any one of the possible implementations of the first through third aspects and the first through third aspects.

[0111] It should be understood that the technical solutions in Aspects 4 through 13 of this Application correspond to the technical solutions in Aspects 1 through 3 of this Application, and that the advantageous effects achieved by those aspects and the corresponding feasible implementations are similar. Further details are not provided here. [Brief explanation of the drawing]

[0112] [Figure 1] This is a diagram of a communication system applicable to a method according to an embodiment of the present invention. [Figure 2] This is a schematic flowchart of a component control method for a device according to an embodiment of the present invention. [Figure 3] This is a diagram of the authentication process according to the embodiment of the present invention. [Figure 4] This is a block diagram of a component control device for a device according to an embodiment of the present invention. [Figure 5] This is a block diagram of a component control device for a device according to an embodiment of the present invention. [Modes for carrying out the invention]

[0113] The following describes the technical solution of this application with reference to the attached drawings.

[0114] To facilitate understanding of the embodiments of this application, the following description is given first.

[0115] Firstly, in this embodiment of the present application, prefixes such as “first” and “second” are used solely to distinguish different objects described and do not limit the location, order, priority, number, or content of the objects described. For example, if the object described is a “controller,” the ordinal numbers preceding “controller” in “first controller” and “second controller” do not limit the priority among the “controllers.” As another example, the number of objects described is not limited by prefixes and may be one or more objects. “First controller” is used as an example, and there may be one or more controllers. In short, the use of prefixes used in this embodiment of the present application to distinguish the objects described does not constitute a limitation on the objects described. For a description of the objects described, please refer to the contextual description in the claims or embodiments, and the use of such prefixes does not constitute a redundant limitation.

[0116] Secondly, in the embodiments of this application, “at least one” means one or more, and “multiple” means two or more. “And / or” indicates an association between related objects, indicating that three relationships may exist. For example, A and / or B can mean: A only exists, both A and B exist, and B only exists, where A and BCM may be singular or plural. The letter “ / ” generally indicates an “or” relationship between related objects. At least one of the following items(s) or similar expressions indicate any combination of these items, including any single item(s) or any combination of multiple items(s). For example, at least one of a, b, or c may mean a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, and c may be singular or plural.

[0117] Thirdly, in the embodiments of the present application, both "when" and "in the case" mean that the device performs the corresponding process under objective circumstances, and there is no intention to limit the time, nor is it necessary to require the device to perform a decisive action during the process, nor does it imply any other limitation.

[0118] Fourth, the term "simultaneously" in the embodiments of the present application may be understood as "at the same point in time," "during a certain period of time," or "during the same period of time," and can be understood specifically by referring to the context.

[0119] The devices in embodiments of the present application may include, but are not limited to, devices that use electrical energy as a power source, such as automobiles, motorcycles, ships, airplanes, helicopters, flying cars, lawnmowers, construction machinery, trams, golf carts, or trains. Embodiments of the present application include, but are not limited to, these.

[0120] To facilitate understanding of the embodiments of the present application, the following first describes a communication system applicable to the methods provided in the embodiments of the present application, with reference to Figure 1. As an example, the communication system 100 shown in Figure 1 is an in-vehicle communication system installed in a vehicle. As shown in Figure 1, the system 100 includes, but is not limited to, several modules, including, for example, a VIU, VDC, motor, telecommunications module, BMS, BCM, wireless communication control module, door controller (or door switch), and VCU.

[0121] A wireless communication control module can be configured to engage in short-range communication. For example, a wireless communication control module may engage in communication within a range of 10 to 20 meters. The wireless communication control module can implement wireless communication control based on technologies such as Bluetooth low energy (BLE), ultra wideband (UWB), and near-field communication (NFC). For example, the wireless communication control module shown in Figure 1 is a Bluetooth electronic control unit (ECU).

[0122] The wireless communication control module can be used for unlocking. For example, if the vehicle owner is carrying the key near the vehicle, the key may detect the vehicle, an unlock command may be automatically generated and sent to the wireless communication control module. The wireless communication control module can initiate anti-theft authentication and, after successful authentication, can control the door controller to unlock the doors.

[0123] A telecommunications module may be configured to engage in telecommunications, for example, communication using a mobile cellular network. The telecommunications module shown in Figure 1 is a telematics box (T-Box) and may be configured to communicate with a mobile application. For example, a user may send commands to the T-Box by using a remote application, for example, a remote vehicle control application (APP). A teleinformation module may include, but is not limited to, a T-Box. This is not limited in this application.

[0124] For example, the VIU may be configured to perform functions such as communication and power supply. In possible implementations, the VIU is a controller in the low-voltage domain. In some cases, the VIU may be replaced by a BCM instead.

[0125] The motor shown in Figure 1 is a motor control unit (MCU), which may be configured to supply power to the vehicle and drive it to move. The VDC controls the MCS and can trigger the MCU to perform power output operations, for example, by sending control commands to the MCU. The VDC can further obtain battery-related information from the BMS and determine whether the BMS can operate normally, such as whether the BMS communication is normal and whether the parameters are normal. If it is determined that the BMS can operate normally, the VDC can control the MCU.

[0126] The T-Box can control different functions of the vehicle, such as turning on the air conditioning, opening the windows, or opening the doors, in response to remote user input, for example, operations on a remote vehicle control application (APP) on a mobile device.

[0127] Modules within a vehicle can communicate with each other using an in-vehicle communication link. For example, VIUIt can communicate with VDC, BMS, BCM, MCU, CDC, wireless communication control module, door controller, etc., by using in-vehicle communication links. Examples, but not limited to, include controller area network (CAN) buses, CAN FD buses with flexible data rate (FD), local interconnect network (LIN) buses, flex ray buses, media-oriented system transport (MOST) buses, automotive Ethernet, etc. The modules in the diagram are named for convenience only to distinguish different functions and do not constitute any limitation on the number of modules or the names of the modules included in the vehicle.

[0128] System 100 represents only a portion of the modules of the automobile, and the automobile may contain more or fewer modules than those shown, or may be a combination of some modules, or a split of some modules, or may have a different component arrangement. The illustrated components may be implemented by hardware, software, or a combination of software and hardware.

[0129] Other devices may, alternatively, include some or all of the modules shown in Figure 1, or other modules having the same or similar functions. This is not limited to the present invention.

[0130] The device control module provided in this application is intended to provide anti-theft solutions for devices. Anti-theft measures include preventing theft of devices, i.e., providing power system power theft prevention solutions, and preventing the theft of items within devices, i.e., providing key theft prevention solutions for device doors and windows.

[0131] As mentioned above, in a wide-ranging point-to-point authentication solution, keys must be pre-set and algorithms embedded in all components requiring authentication, including the controller. For example, the keys and algorithms are pre-set in all modules of the vehicle before the device is delivered. Development and maintenance costs are high.

[0132] With this in mind, the present invention provides a method by which authentication of a component is transferred to authentication of a controller capable of controlling each component, where authentication performed on a component by controller #1 is transferred to authentication performed on component #2 by component #1. Controller #2 may send a control command to the component if authentication is successful and the authentication result is reliable. The component may respond to the control command after successful authentication. Thus, in this solution, authentication is not performed directly on the component, but the component can only receive a control command if authentication to controller #2 is successful and the authentication result is reliable. This is equivalent to performing authentication on the component. It is not necessary to pre-set keys and embed algorithms in all components that have authentication requirements; it is sufficient for the keys to be pre-set and the algorithms to be embedded in just two or three controllers, and control of each component can be implemented. Thus, development and maintenance costs can be reduced. Furthermore, since the condition for a component to respond to a control command can only be satisfied if multiple parties are controlled to cooperate with each other, unauthorized operation of the device can be better avoided, and theft of the device can be prevented. Thus, security can be improved.

[0133] The following describes in detail the method provided in the embodiments of this application with reference to the attached drawings.

[0134] Figure 2 is a schematic flowchart of a component control method 200 for a device according to an embodiment of the present invention. As shown in Figure 2, the method 200 may include steps 210 to 260. The steps of the method 200 are described in detail below.

[0135] In step 210, controller #1 authenticates controller #2 and obtains the authentication result.

[0136] Here, authentication may include, for example, anti-theft authentication. Controller #1 is considered a primary authentication device and may be used to perform authentication on the platform. In this embodiment of the present application, Controller #2 can control multiple components within the device and, for example, collect component-related information from each component (e.g., whether communication is successful and parameters) and send control commands to each component. If the authentication performed by Controller #1 for each component is transferred to authentication with Controller #2, the point-to-point authentication operation that was performed by Controller #1 for each component having authentication requirements may be omitted. In other words, Controller #2 may authenticate with the primary authentication device (i.e., Controller #1) on behalf of each component. Thus, Controller #2 in this embodiment of the present application may be considered a secondary authentication device.

[0137] When a user performs an action, controller #2 may be triggered to initiate authentication and send an authentication request to controller #1 in order to enable the device to perform the action, for example, to enable the device to output power or perform a power output. Specifically, in different scenarios, the user action to trigger the device to power on may differ. The following describes the user actions to trigger the device to power on and to trigger controller #2 to initiate authentication, referring to different scenarios. Further details are not provided here.

[0138] In response to the received authentication request, controller #1 may perform authentication on controller #2 and obtain the authentication result.

[0139] Figure 3 shows an example of the authentication process. Step 210 described above is explained in more detail and specifically includes the following steps.

[0140] Step 301: Controller #2 sends an authentication request to Controller #1, which carries a random number.

[0141] For example, an authentication request can be an authentication challenge message.

[0142] Step 302: Controller #1 encrypts the received random number based on a pre-set key and encryption algorithm to obtain the ciphertext.

[0143] For example, the key may be the session key (SK) that was negotiated in advance with controller #2.

[0144] The ciphertext may be, for example, a personal identification number (PIN) code. A PIN code is a device identification code. For example, if the device is a car, the PIN code is the car's identification code, commonly called an engine electronic anti-theft system, and can be used to prevent car theft.

[0145] Step 303: Controller #1 sends the ciphertext to Controller #2.

[0146] For example, ciphertext can be carried in an authentication response message.

[0147] Step 304: Controller #2 decrypts the ciphertext based on a pre-set key and decryption algorithm to obtain a random number.

[0148] The pre-set key in controller #2 is the key that was pre-negotiated with controller #1, and the two keys can be the same, for example, both being SK. The pre-set decryption algorithm in controller #2 corresponds to the pre-set encryption algorithm in controller #1.

[0149] The ciphertext is decrypted based on a pre-set key and decryption algorithm to obtain the plaintext.

[0150] Step 305: Controller #2 determines the authentication result based on the transmitted random number and the random number obtained through decryption.

[0151] If controller #1 encrypts a random number from controller #2 to obtain a ciphertext, it can be understood that the random number obtained by decrypting the ciphertext by controller #2 should be the same random number sent in step 301. In other words, if the random number sent by controller #2 is the same as the random number obtained by decryption, authentication is successful. If the random number sent by controller #2 is different from the random number obtained by decryption, authentication fails. Controller #2 may determine the authentication result based on the sent random number and the random number obtained by decryption.

[0152] Step 306: Controller #2 sends an authentication result notification to Controller #1.

[0153] Controller #2 may send an authentication result notification to Controller #1 to indicate whether the authentication performed by Controller #1 was successful. For example, the authentication result notification is carried in an authentication status message.

[0154] Referring to Figure 3, the authentication process described above is merely an example, and the specific authentication process is not limited in this application. For example, step 306 in Figure 3 does not need to be performed, and controller #2 may instead indicate whether authentication was successful by sending or not sending an authentication result. For example, if authentication is successful, an authentication result is sent. If authentication fails, no authentication result is sent. In this way, controller #1 may also determine whether authentication was successful depending on whether an authentication result was received.

[0155] Please note that the authentication process described above is performed only if authentication of the key is successful. The key is used to open the device, to supply high voltage to power on the device, or to start the device. The key may implement the unlocking function based on, for example, Bluetooth technology, UWB technology, or NFC technology.

[0156] The key authentication process is similar to the authentication process described above, with reference to Figure 3. For specific details, please refer to the prior art. Details are not described again here. If the key is not within the detection range of the device, authentication cannot be performed on the key, i.e., authentication fails. Authentication to controller #2 in this specification may be performed if authentication to the key is successful. If authentication to the key fails, the authentication result may be directly determined as authentication failure, and authentication to controller #2 does not need to be performed.

[0157] The next step is based on the authentication performed on controller #2. In other words, it is assumed that authentication for the key was successful.

[0158] In step 220, controller #1 sends an authentication result notification, which indicates the authentication result. Accordingly, the component retrieves the authentication result.

[0159] The authentication result includes both success and failure.

[0160] The authentication process described above shows that controller #1 can determine the authentication result. Controller #1 may also notify the component of the authentication result to indicate whether authentication to controller #2 was successful.

[0161] It can be understood that the authentication result notification may be either the authentication result notification received by controller #1 from controller #2 in the authentication process described above, or it may be the authentication result notification generated by controller #1 based on the authentication result notification received from controller #2.

[0162] In a possible implementation, controller #1 may send an authentication success notification if authentication is successful. The authentication success notification may be used to notify controller #2 that authentication was successful. In other words, the authentication success notification is a concrete example of an authentication result notification. If authentication fails, controller #1 does not have to send any notification. If a component does not receive any notification, the component may determine that the authentication performed by controller #1 to controller #2 failed.

[0163] In other possible implementations, controller #1 sends an authentication result notification indicating whether authentication was successful or unsuccessful, regardless of whether authentication was successful or unsuccessful. The authentication result may include a field indicating success or failure. For example, "1" indicates successful authentication, and "0" indicates unsuccessful authentication. Alternatively, the authentication result may be indicated in other ways, and is not limited to this application. If the authentication result is successful authentication, the authentication result notification will be a success notification. If the authentication result is unsuccessful authentication, the authentication result notification will be an unsuccessful authentication notification.

[0164] In the two implementations described above, it can be seen that if authentication is successful, controller #1 may send an authentication success notification. If authentication fails, controller #1 may send an authentication failure notification, or it may not send any notification at all. However, it can be understood that regardless of whether controller #1 sends an authentication result notification, the component may determine the authentication result based on the status of receipt of the authentication result notification. The figure is merely an example illustrating the step of controller #1 sending an authentication result notification to the component. In fact, the recipient end of the authentication result notification is not limited in this application.

[0165] The latter implementation described above is used as an example. Controller #1 may send an authentication result notification by broadcast, thereby allowing all connected components to receive the notification by using the communication link. This achieves complete coverage. This solution is particularly applicable to the offline diagnostic phase before the device is delivered. Alternatively, Controller #1 may send an authentication result notification to one or more predefined components, thereby allowing one or more components to receive the notification without causing unnecessary impact on other components. One or more predefined components can be pre-written by a developer in Controller #1 using code. For example, in an automobile, one or more predefined components may include one or more of the following: motor, BMS, and door controller.

[0166] In step 230, the component sends a response message to controller #1, which indicates that it successfully received the authentication result notification.

[0167] Each component that receives the authentication result notification may send a response message to controller #1 to indicate that it successfully received the authentication result notification. Alternatively, the components that need to send a response message may be predefined. For example, a developer may pre-write the components that need to provide feedback with a response message into controller #1 using code.

[0168] As mentioned above, if controller #1 is unable to authenticate controller #2, an authentication result notification does not need to be sent. In this case, the component does not need to send a response message to controller #1. In other words, if authentication fails, step 230 is not necessarily performed. The diagram is just an example and shows the step in which the component sends a response message to controller #1.

[0169] In step 240, controller #1 sends an authentication reliability notification to controller #2 based on the received response message, and the authentication reliability notification indicates that the authentication result is reliable.

[0170] The reason a component needs to provide feedback in response messages is that, in a scenario where a component is replaced, the replaced component might not send a response message to controller #1, which would cause controller #1 to detect a component exception in time and even set the authentication result to untrusted.

[0171] In contrast, if controller #1 receives a response message from the component, controller #1 can determine that the component is functioning correctly and has not been replaced, and may even notify controller #2 that the authentication result is reliable.

[0172] Controller #1 may determine whether the above authentication result is trustworthy based on the status of the response message received and notify Controller #2.

[0173] In possible implementations, controller #1 may send an authentication reliability notification to controller #2 to indicate that the authentication result is reliable if it determines that the authentication result is reliable, or it may choose not to send any notification if the authentication result is unreliable. If controller #2 does not receive any notification, controller #2 may determine that the authentication result is unreliable. In other words, if controller #1 does not receive a response message, step 240 is not necessarily performed.

[0174] In other possible implementations, controller #1 sends a notification indicating whether the authentication result is trustworthy or untrustworthy, regardless of whether the authentication result is trustworthy or untrustworthy. For example, if the authentication result is trustworthy, the notification is an authentication trust notification. If the authentication result is untrustworthy, the notification is an authentication untrust notification.

[0175] In the two implementations described above, it can be seen that if authentication is trusted, step 240 may be performed, meaning controller #1 sends an authentication trust notification to controller #2. If authentication is not trusted, step 240 may or may not be performed. The diagram is just one example and shows the step where controller #1 sends an authentication trust notification to controller #2.

[0176] In step 250, controller #2 sends a control command to the component if authentication is successful and the authentication result is reliable.

[0177] As described above, controller #2 can determine whether authentication was successful or unsuccessful by performing the authentication process shown in Figure 3. Controller #2 can further determine whether the authentication result is reliable based on whether an authentication reliability notification has been received. In this embodiment of the present application, controller #2 can transmit a control command to the component only if both conditions are met, i.e., authentication is successful and the authentication result is reliable.

[0178] A control command sent by controller #2 can be used to trigger a component to respond. In other words, a component that receives a control command is a component controlled by controller #2. Furthermore, the relationship between controller #2 and a component can be predefined. For example, for each different component #2, one or more components that can be controlled by that controller #2 can be specified in advance. The relationship between controller #2 and a component is explained below with specific examples, so details are not described here.

[0179] In step 260, the component responds to a control command if the authentication performed by controller #1 to controller #2 is successful.

[0180] Controller #2 sends a control command only when it receives an authentication reliability notification; therefore, a component receiving a control command means that the authentication result is reliable. In other words, the condition that the authentication result is reliable under the two conditions above is satisfied. After receiving a control command, the component may first determine whether the authentication performed by Controller #1 to Controller #2 was successful, and if the authentication was successful and the remaining conditions are also satisfied, it may respond to the control command.

[0181] In response to the above implementation in which Controller #1 sends the authentication result, the component may determine whether authentication was successful based on a different implementation. For example, in response to the former implementation, the component may determine that authentication was successful if an authentication success notification was received, and that authentication failed if no authentication notification was received. In response to the latter implementation, the component may determine whether authentication was successful or failed based on the information indicated in the received authentication result.

[0182] Based on the above solution, authentication between controller #1 and controller #2 must be successful in order to control the component to perform the corresponding operation. The component must participate in the authentication and respond to the authentication result. Thus, if authentication to controller #2 is successful and the component is normal, controller #2 sends a control command. In this way, the component responds to the received control command only if authentication is successful and the authentication result is trustworthy. Since authentication for the component is transferred to authentication to controller #2, controller #2 can control one or more components. Therefore, it is not necessary to pre-set keys and embed algorithms in all components that have authentication requirements; it is sufficient to pre-set keys and embed algorithms in only two or three controllers. Control of each component can be achieved, and theft prevention effects can be achieved. Therefore, security protection can be provided to more components, more requirements can be satisfied, and development and maintenance costs can be reduced. Also, since the conditions for a component to respond to a control command can only be satisfied when multiple parties are controlled to cooperate with each other, unauthorized operation of the device can be better avoided, and device theft can be prevented. Therefore, security is improved.

[0183] The following describes in detail controller #1, controller #2, components, control commands, and component responses, using an automobile as an example platform. In each of the following examples, authentication to controller #2 is assumed to be successful, the authentication result is assumed to be reliable, and the component is determined to be able to respond to the control command it has received. To better understand the method provided herein, the following describes the method by using several examples with reference to specific scenarios.

[0184] 1. Scenario for preventing electricity theft

[0185] Theft prevention of power systems, which aims to prevent theft of automobiles, can be achieved by controlling power execution components (e.g., motors) or power supply components (e.g., BMS).

[0186] Optionally, controller #1 is at least one of the following: VIU, BCM, and wireless communication control module. Controller #2 is a VDC, and the components controlled by the VDC include motors and / or BMS. Components that receive control commands may include motors and / or BMS.

[0187] The control commands transmitted to the motor by the VDC carry torque requests, which can be used to control the motor to perform a torque response in order to output power to drive the vehicle into motion. In response to the torque requests in the control commands, the motor may perform operations such as torque response and power output.

[0188] Control commands transmitted to the BMS by the VDC can be used to control the BMS to output power, so that power is supplied to the vehicle and power is available for starting. In response to the control commands, the BMS may output power.

[0189] Controller #2 may send control commands to the motor, to the BMS, or to both the motor and the BMS. It can be understood that the vehicle cannot start unless either the motor or the BMS responds to the control command. In other words, the VDC can provide an anti-theft effect by controlling the motor and / or the BMS to prevent theft of the vehicle.

[0190] For example, when a gear change operation is detected, the VDC may initiate authentication. The VDC may proactively send an authentication request to the VIU. The VIU then authenticates the VDC based on the authentication request. For details regarding authentication between the VIU and the VDC, please refer to Figure 3 and the relevant explanation above. Further details are not provided here.

[0191] The VIU may send a VDC authentication result notification to the motor to indicate the VDC's authentication result. The motor may feed back a response message regarding the authentication result. After receiving the response message from the motor, the VIU sends an authentication reliability notification to the VDC. If authentication is successful and the VDC determines that the authentication result is reliable, the VDC may send a control command to the motor. The control command may be used to control the motor and perform power output operations. In other words, if authentication to the VDC fails, or if the VDC determines that the authentication result is unreliable, no control command is sent to the motor. In this way, even if authentication to the VDC is successful, if the VDC determines that the authentication result is unreliable, the motor will not perform any operations, meaning the vehicle will not start. In this way, vehicle theft is prevented.

[0192] After receiving the authentication result notification, the motor can determine whether the VDC authentication was successful. If authentication is successful, the motor can respond to the received control command. If authentication fails, the motor does not need to respond to the received control command. As a result, if VDC authentication fails, the motor will not perform any operations, meaning the vehicle cannot be started. In this way, vehicle theft is prevented.

[0193] In some cases, third parties may steal a vehicle by replacing modules.

[0194] For example, a third party could steal a vehicle by replacing the VDC. The newly replaced VDC might not send an authentication request to the VIU in order to circumvent authentication. However, in this solution, the motor cannot receive an authentication result notification from the VIU because the VIU does not authenticate the VDC. However, if the motor does not receive an authentication result notification, it cannot determine that authentication was successful. Therefore, even if the VDC sends a control command to the motor, the motor will not respond to the control command. In other words, even if the VDC is replaced, the vehicle will not start.

[0195] As another example, a third party could potentially steal a vehicle by replacing the VIU. However, since the keys and algorithms used for authentication with the VIU are pre-set before delivery, it is difficult to steal. Even if the VIU is replaced, it is difficult to successfully authenticate the VDC. If authentication fails, the motor will not respond to control commands. In other words, even if the VIU is replaced, the vehicle will not start.

[0196] As another example, a third party could steal a vehicle by replacing the motor. However, if the motor is replaced, the motor will not feed back a response message to the authentication result. If the VIU does not receive a response message, the VIU sets the authentication result to untrusted. In this way, the VDC does not send control commands to the motor, the motor does not perform any operations if it does not receive control commands, and the vehicle still cannot start.

[0197] In another example, the VDC may initiate authentication upon detecting a gear change operation. The VDC may dynamically send an authentication request to the VIU. The VIU then authenticates with the VDC based on the authentication request. For details on authentication between the VIU and the VDC, please refer to Figure 3 and the relevant explanation above. Further details are not provided here.

[0198] The VIU may send a VDC authentication result notification to the BMS to indicate the VDC authentication result. The BMS may provide a response message to the authentication result as feedback. After receiving the response message from the BMS, the VIU sends an authentication reliability notification to the VDC. If authentication is successful and the VDC determines that the authentication result is reliable, the VDC may send a control command to the BMS. Here, the control command is used to control the BMS to perform power output operation. In other words, if authentication to the VDC fails, or if the VDC determines that the authentication result is unreliable, no control command is sent to the BMS. In this way, even if authentication to the VDC is successful, the BMS will not output power if the authentication result is unreliable. The vehicle cannot start without power output. In this way, vehicle theft is prevented.

[0199] Similar to the example above, if any one of the VIU, VDC, or BMS is replaced, the BMS will not output power, and the vehicle will not be able to start without power output. In this way, vehicle theft is prevented.

[0200] This solution reveals that the conditions for a power execution component to perform a power output operation and / or for a power supply to perform a power output operation must be satisfied through the coordination of multiple parties. If any of these parties are replaced, the component cannot perform the corresponding operation, thus better preventing unauthorized operation of the vehicle, preventing vehicle theft, and improving security.

[0201] 2. Key theft prevention scenario

[0202] Key theft prevention measures aim to prevent the opening of car doors and windows, and to prevent the theft of items inside the vehicle.

[0203] Optionally, controller #1 is a VIU and / or BCM, controller #2 is a wireless communication control module, and components controlled by the wireless communication control module include a door controller and / or window controller.

[0204] Control commands sent by the VDC to the door controller can be used to control the door controller so that the door can be unlocked and opened. In response to the control command, the door controller unlocks the door. Similarly, control commands sent by the VDC to the window controller can be used to control the window controller so that the window can be unlocked and opened. In response to the control command, the window controller unlocks the window. Thus, the VDC can provide an anti-theft effect through the control of the door controller. In this way, theft of items inside the vehicle is prevented.

[0205] For example, a Bluetooth ECU (i.e., an example of a wireless communication control module) may initiate anti-theft authentication upon receiving an unlock command from the key. The Bluetooth ECU may proactively send an authentication request to the VIU. The VIU then authenticates the Bluetooth ECU based on the authentication request. For details on authentication between the VIU and the Bluetooth ECU, please refer to Figure 3 and the relevant explanation above. Further details are not provided here.

[0206] The VIU may send a Bluetooth ECU authentication result notification to the door controller and window controller to indicate the authentication result of the Bluetooth ECU. The door controller and window controller may feed back a response message regarding the authentication result. After receiving the response message from the door controller and window controller, the VIU sends an authentication reliability notification to the Bluetooth ECU. If authentication is successful and the VIU determines that the authentication result is reliable, the Bluetooth ECU may send a control command to the door controller and window controller. The control command may be used to instruct the door controller to perform an action to unlock the doors and windows.

[0207] After receiving the authentication result notification, the door controller can determine whether authentication to the Bluetooth ECU was successful. If authentication is successful, the doors and windows may be unlocked and opened in accordance with the received control command. If authentication fails, no response is made to the received control command, and the doors and windows still cannot be opened. In this way, if authentication fails, the Bluetooth ECU does not perform the action to unlock the doors and windows. In this way, theft of items inside the car is prevented. Since the doors and windows cannot be opened, third parties cannot enter the car or start the car. In this way, theft of the car can also be prevented.

[0208] Similar to the principle described in the example above, if any one of the VIU, Bluetooth ECU, or door controller is replaced, the door controller will not unlock the doors and windows, and a third party will not be able to enter the vehicle. In this way, theft of items inside the vehicle and the theft of the vehicle itself are prevented.

[0209] 3. Remote Theft Prevention Scenario

[0210] With the development of intelligent devices, remote vehicle control applications are becoming more widely used. These applications can be used to remotely control functions such as starting, stopping, unlocking, locking, and locating a vehicle. When the application is used, the vehicle owner can open the doors and start the vehicle without needing a key.

[0211] Remote anti-theft measures aim to prevent vehicles from being opened remotely, for example, by preventing doors and windows from being opened, thereby preventing the theft of items inside the vehicle, or by preventing the vehicle from being started, thereby preventing the vehicle from being stolen.

[0212] Optionally, controller #1 is a VIU, BCM, or wireless communication control module, and controller #2 is a telecommunications module, with components controlled by the telecommunications module including one or more of a motor, BMS, and door controller. The component receiving this control command may be one or more of a motor, BMS, and door controller.

[0213] The control of the remote communication module for the motor, BMS, and door controller is similar to the control of the VDC for the motor and BMS, and the control of the Bluetooth ECU for the door controller in the example above. In the example above, two cases were described in detail with reference to the example: implementing vehicle anti-theft measures by controlling the power execution component and / or power supply component, and implementing anti-theft measures for items inside the vehicle by controlling the door controller. Further details are not described again here.

[0214] Furthermore, the remote communication module can simultaneously control the door controller and at least one of the motor and / or BMS to provide theft prevention effects by controlling the door controller and by controlling the motor and / or BMS. In this way, theft of items inside the vehicle is prevented, and the theft of the vehicle itself is prevented.

[0215] Based on the same concept, remote anti-theft measures can also be used to prevent other modules within a vehicle from being tampered with. For example, the vehicle's air conditioning could be tampered with, causing unnecessary resource waste. By implementing this solution, the air conditioning could also be prevented from being tampered with. For example, a VIU or wireless communication module could be used as controller #1, a remote communication module as controller #2, and a BCM could be used as a component to control the air conditioning. By implementing the above solution, the BCM could be prevented from controlling the air conditioning to turn on.

[0216] In the various scenarios and examples provided above, the examples of Controller #1, Controller #2, and Components are merely illustrative to facilitate understanding and should not constitute any limitation to the present invention. Based on the same concepts, those skilled in the art may further use other modules to implement the functions of Controller #1, Controller #2, and Components, respectively.

[0217] To further enhance security and deter device theft, this solution considers other scenarios and determines authentication results based on more factors.

[0218] As mentioned above, if authentication of the key fails before authentication of controller #2, the authentication result can be directly determined as authentication failure. In this way, device theft can be further prevented.

[0219] Optionally, prior to step 210, the method further includes determining whether the key is within a pre-set range. Correspondingly, step 210 may be performed after it has been determined that the key is within a pre-set range, and the authentication result may be determined based on the authentication process of controller #2. In contrast, if it is determined that the key is not within a pre-set range, the authentication result may be determined as authentication failure.

[0220] Here, the pre-set range may be the detection range of the device. In other words, if a key can be detected within the detection range of the device, the key is considered to be within the detection range. If a key is not detected within the detection range of the device, the key is considered not to be within the detection range. The specific size of the pre-set range may be determined by the device manufacturer, and is not limited herein.

[0221] For example, if the vehicle owner has the keys and temporarily leaves the car, and the vehicle is unlocked and still powered on, a third party could directly enter the car to start it. As mentioned above, since the key is not within the vehicle's detection range, authentication for the key will fail, and therefore the authentication result will be authentication failure. In this case, the third party cannot start the car to prevent theft.

[0222] Furthermore, to prevent third parties from entering the vehicle and causing the loss of items inside, the vehicle may be automatically locked. Automatic vehicle locking functions include, but are not limited to, automatic power off, door locking, and window locking. For example, if it is detected that the vehicle has been unoccupied for a predetermined period of time, the vehicle may be automatically locked. The predetermined period may be determined by the device manufacturer, and is not limited herein.

[0223] Optionally, the method further includes determining that the authentication result is an authentication failure if an abnormal situation is detected.

[0224] Here, an abnormal situation may be a predefined event, including, but not limited to, breaking a window, breaking a door, and picking a lock. An abnormal situation may be reported to controller #1 after being detected by a sensor. Upon receiving a report of an abnormal situation, controller #1 may determine that the authentication result is an authentication failure.

[0225] For example, if the vehicle owner leaves the car and leaves the keys inside, but the doors are locked, a third party could potentially break into the car by breaking a window, prying down a door, or picking the lock to obtain the keys and start the car. In this case, the authentication result can be directly determined as an authentication failure. Even if the third party obtains the keys and is in a position to start the car, the car will not start due to the authentication failure. In this way, car theft is prevented.

[0226] Furthermore, to notify the vehicle owner in a timely manner to avoid greater losses, the sensor can activate a camera after detecting an anomaly to monitor the environment around the vehicle, save the captured images, and upload the images to the vehicle owner's mobile device.

[0227] Multiple examples demonstrate that by using the solution provided in this application, development and maintenance costs caused by pre-setting keys and embedding algorithms in all components can be reduced, and furthermore, a reliable anti-theft mechanism can be provided to prevent the theft of devices, such as automobiles, and achieve a high level of security.

[0228] For ease of understanding, the above describes the component control methods provided in this application by using several components in an automobile as examples. These components and their functions are illustrative and should not constitute any limitation to this application. Components used to implement functions such as power output, power supply output, and control of doors, windows, air conditioning, etc., as listed above, and their names, are not limited in this application.

[0229] Furthermore, while the above uses an automobile as an example to describe several possible scenarios, this should not constitute any limitation on the devices to which this application applies. As stated above, the solution may be further applied to other devices. In different devices, the specific forms and names of controller #1, controller #2, and components may differ from one another. However, this should not affect the scope of application of this application. Control of device components must be implemented insofar as component #1, component #2, and the functions of the components can be implemented.

[0230] The examples given above are merely a few possible scenarios and do not constitute a limitation on the scenarios to which this solution applies. Based on the same concept, a person skilled in the art could further determine the certification result based on more factors to further enhance safety.

[0231] The above describes in detail the method provided in the embodiments of the present application with reference to Figures 2 and 3. The following describes in detail the apparatus provided in the embodiments of the present application with reference to Figures 4 and 5.

[0232] Figure 4 is a block diagram of a component control device 400 for a device according to an embodiment of the present invention. As shown in Figure 4, the device 400 may include a transceiver unit 410 and a processing unit 420.

[0233] In possible designs, the device 400 shown in Figure 4 may correspond to a component in an embodiment of the method described above and may perform steps performed by the component in an embodiment of the method described above. For example, the device 400 may be a component, a chip or chip system comprising the component, or other logic unit or software capable of implementing some or all of the functions of the component. This is not limited to the present application.

[0234] The transceiver unit 410 may be configured to receive control commands from controller #2, which are commands sent by controller #2 when authentication performed by controller #1 to controller #2 is successful and the authentication result is reliable. The processing unit 420 may be configured to receive the result of authentication performed by controller #1 to controller #2, which includes authentication success or authentication failure. The processing unit 420 may be further configured to respond to a control command if the authentication result is authentication success.

[0235] The apparatus 400 may include units configured to perform processes and / or steps corresponding to the components in method 200 described above. For brevity, further details are not provided here.

[0236] In another possible design, the device 400 shown in Figure 4 may correspond to controller #1 in the embodiment of the above method, Controller #1 The device may perform the steps performed by the device. For example, device 400 may be controller #1, a chip or chip system configured in controller #1, or other logic unit or software capable of implementing some or all of the functions of controller #1. This is not limited to the present invention.

[0237] The transceiver unit 410 may be configured to send an authentication success notification when authentication to controller #2 is successful, the authentication success notification is used to notify controller #2 that authentication has been successful, and may also be configured to send an authentication reliability notification when a response message is received, the response message being from a component controlled by controller #2 and indicating successful receipt of the authentication success notification, and the authentication reliability notification indicating that the authentication success notification is reliable.

[0238] The apparatus 400 may include a unit configured to perform the process and / or steps corresponding to controller #1 in method 200 described above. For brevity, further details are not provided here.

[0239] In yet another possible design, the device 400 shown in Figure 4 may correspond to controller #2 in the embodiment of the above method, Controller #2The device may perform the steps performed by the device. For example, device 400 may be controller #2, a chip or chip system configured in controller #2, or other logic unit or software capable of implementing some or all of the functions of controller #2. This is not limited to the present invention.

[0240] The processing unit 420 may be configured to obtain the result of authentication performed by controller #1 on the device 400, the authentication result including authentication success or authentication failure. The transceiver unit 410 may be configured to send a control command to a component controlled by the device 400 to trigger the component to respond, if the authentication result is authentication success and the authentication result is reliable.

[0241] The apparatus 400 may include a unit configured to perform the process and / or steps corresponding to controller #2 in the method 200 described above. For brevity, further details are not provided here.

[0242] The functions of the device 400 may be implemented using hardware, software, or a combination of software and hardware.

[0243] In this embodiment of the present application, the division into units is illustrative and merely a logical functional division. Other division patterns may be used in actual implementation. Furthermore, the functional units in the embodiment of the present application may be integrated into a single processor, or each unit may exist physically independently, or two or more units may be integrated into a single unit. The integrated unit may be implemented in hardware form or in the form of a software functional unit.

[0244] Figure 5 is another block diagram of a component control device 500 for a device according to an embodiment of the present application. As shown in Figure 5, the device 500 includes a processor 510 and a memory 520. The memory 520 may be configured to store computer programs, and the processor 510 may be configured to call and execute computer programs, thereby the device implements the functions of a component, controller #1, or controller #2 in the manner provided in the embodiments of the present application.

[0245] Optionally, the device 500 may further include a communication interface 530. The communication interface 530 may be a transceiver, interface, bus, circuit, or device capable of implementing transceiver functionality. The communication interface 530 is configured to communicate with other devices by using a transmission medium, so that the device 500 can communicate with other devices.

[0246] For example, if the device 500 corresponds to a component in the embodiment of the above method, the processor 510 may be configured to control the communication interface 530 to obtain control instructions from controller #2, and the control instructions are transmitted to controller #2 2 Controller # 1 If the authentication performed by is successful and the authentication result is trusted, then controller# 2 This is an instruction sent by [the controller]. Processor 510 may be further configured to obtain the result of authentication performed by controller #1 to controller #2 and to respond to a control instruction if the authentication result is successful, the authentication result including success or failure. For further details, see the detailed description in Method 200. Further details are not given again here.

[0247] In another example, if device 500 corresponds to controller #1 in the embodiment of the above method, the processor 510 may be configured to control the communication interface 530 to send an authentication success notification when authentication to controller #2 is successful, the authentication success notification is used to notify controller #2 that authentication has been successful. The processor 510 may further be configured to control the communication interface 530 to send an authentication reliability notification when a response message is received, the response message being from a component controlled by controller #2 and indicating successful receipt of the authentication success notification, and the authentication reliability notification indicating that the authentication success notification is reliable. For further details, see the detailed description in Method 200. Further details are not described again here.

[0248] In another example, if device 500 corresponds to controller #2 in the embodiment of the method described above, the processor 510 may be configured to obtain the result of authentication performed on device 500 by controller #1, the authentication result including authentication success or authentication failure. The processor 510 may further be configured to control the communication interface 530 to send a control command to a component controlled by device 500, thereby triggering the component to respond, if the authentication result is successful and the authentication result is reliable. For further details, see the detailed description in Method 200. Further details are not described again here.

[0249] The coupling in this embodiment of the present application may be an indirect coupling or communication connection between devices, units, or modules in an electrical, mechanical, or other form, and is used for information exchange between devices, units, or modules. The processor 510 may operate in cooperation with the memory 520. The processor 510 may execute program instructions stored in the memory 520. At least one of the at least one memory may be included in the processor.

[0250] The specific connection medium between the processor 510, the memory 520, and the communication interface 530 is not limited in this embodiment of the application. In this embodiment of the application, the memory 520, the processor 510, and the communication interface 530 are connected by a bus 540 in Figure 5. The bus is represented by a thick line in Figure 5. The connections between other components are merely examples for illustrative purposes and are not limited thereto. Buses can be classified as address buses, data buses, control buses, etc. For ease of representation, only one thick line is used for representation in Figure 5, but this does not mean that there is only one bus or only one type of bus.

[0251] The processor in the embodiments of this application may be an integrated circuit chip and may have signal processing capabilities. In the implementation process, the steps in the embodiments of the method described above may be implemented by using hardware integrated logic circuits within the processor or by using instructions in the form of software. The processor may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. It may implement or perform the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor, etc. The steps of the methods disclosed with reference to embodiments of this application may be performed and completed directly by a hardware decoding processor, or by using a combination of hardware and software modules within the decoding processor. The software module may reside in a mature storage medium in the art, such as random-access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. The storage medium resides in memory, and the processor reads the information in memory and, in combination with the processor hardware, completes the steps of the method described above.

[0252] The memory in the embodiments of this application may be non-volatile memory or volatile memory, or may include both non-volatile and volatile memory. Non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may be random access memory (RAM) used as an external cache. Rather than being an exclusive description, numerous forms of RAM may be used as examples, such as static random access memory (static RAM, SRAM), dynamic random access memory (dynamic RAM, DRAM), synchronous dynamic random access memory (synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (double data rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (enhanced SDRAM, ESDRAM), synchlink dynamic random access memory (synchlink DRAM, SLDRAM), and direct rambus dynamic random access memory (direct rambus RAM, DR RAM). The memory of the systems and methods described herein includes, but is not limited to, these memories and any other suitable types of memory.

[0253] The present invention further provides an automobile, which may include the components, controller #1, and controller #2 in the embodiment of the above method.

[0254] The present invention further provides a computer-readable storage medium that stores a computer program. When the computer program is executed by a processor, the method executed by a component in the embodiment shown in Figure 2 is implemented, or the method executed by controller #1 in the embodiment shown in Figure 2 or Figure 3 is implemented, or the method executed by controller #2 in the embodiment shown in Figure 2 or Figure 3 is implemented.

[0255] This application further provides a computer program product including a computer program. When the computer program is executed, a method performed by a component in the embodiment shown in Figure 2 is carried out, or a method performed by controller #1 in the embodiment shown in Figure 2 or Figure 3 is carried out, or a method performed by controller #2 in the embodiment shown in Figures 2 and 3 is carried out.

[0256] The terms "unit" and "module" as used herein may refer to computer-related entities, hardware, firmware, combinations of hardware and software, software, or running software.

[0257] Those skilled in the art will notice that the illustrative logical blocks and steps described in the embodiments disclosed herein can be combined and implemented by electronic hardware or by a combination of computer software and electronic hardware. Whether a function is performed by hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art will notice that different methods may be used to implement the described functions for each specific application, but implementation should not be considered to be beyond the scope of the Application. In some embodiments provided herein, it should be understood that the disclosed apparatus, devices, and methods may be implemented in other ways. For example, the embodiments of the apparatus described are merely examples. For example, the division into units is merely a logical functional division, and other divisions may be used in actual implementation. For example, multiple units or components may be combined or integrated with other systems, or some features may be ignored or not implemented. Also, the mutual coupling, direct coupling, or communication connection shown or discussed may be implemented by using some interfaces. Indirect coupling or communication connection between apparatus or units may be implemented electronically, mechanically, or in other forms.

[0258] Units described as separate parts may be physically separated, and parts shown as units may or may not be physical units, and may be located in one place or distributed across multiple network units. Some or all units may be selected based on actual requirements to achieve the objectives of the solution of the embodiment.

[0259] Furthermore, the functional units in the embodiments of the present invention may be integrated into a single processing unit, and each unit may exist physically independently, or two or more units may be integrated into a single unit.

[0260] In the embodiments described above, all or part of the functionality of the functional unit may be implemented by software, hardware, firmware, or any combination thereof. If software is used to implement the embodiments, all or part of the embodiments may be implemented in the form of a computer program product. A computer program product includes one or more computer instructions (programs). When the computer program instructions (programs) are loaded and executed on a computer, all or part of the processes or functions according to the embodiments of the present application are generated. The computer may be a general-purpose computer, a dedicated computer, a computer network, or other programmable device. The computer instructions may be stored on a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (e.g., simultaneous cable, optical fiber, or digital subscriber line (DSL)) or wirelessly (e.g., infrared, radio waves, or microwaves). The computer-readable storage medium may be any available medium accessible to a computer, or a data storage device such as a server or data center incorporating one or more available media. The usable media may include magnetic media (e.g., floppy disks, hard disks, or magnetic tapes), optical media (e.g., digital video discs (DVDs)), and semiconductor media (e.g., solid-state disks (SSDs)).

[0261] If the function is implemented in the form of a software function unit and sold or used as an independent product, the function may be stored on a computer-readable storage medium. Based on such understanding, the technical solution of the present application may be implemented essentially, or in part, in the form of a software product, or in part of the technical solution, in the form of a software product. The computer software product is stored on a storage medium and includes several instructions that instruct a computer device (personal computer, server, or network device) to perform all or part of the steps of the method described in the embodiments of the present application. The storage medium includes any medium capable of storing program code, such as a USB flash drive, removable hard disk, ROM, RAM, magnetic disk, or optical disk.

[0262] The above description merely illustrates a specific implementation of the present application and is not intended to limit the scope of protection. Any modification or substitution that a person skilled in the art could easily conceive within the scope of the art disclosed herein should fall within the scope of protection. Accordingly, the scope of protection of this application should be subject to the scope of protection of the claims.

[0263] This application claims priority to Chinese Patent Application No. 202210690337.4, filed with the China National Intellectual Property Administration on 17 June 2022, with the title of the invention being "COMPONENT CONTROL METHOD FOR DEVICE AND RELATED APPARATUS," which is incorporated herein by reference in its entirety.

Claims

1. A component control method for a device, applicable to a component controlled by a first controller, The process involves obtaining a control command from the first controller, wherein the control command is a command sent by the first controller when authentication performed by the second controller on the first controller is successful and the authentication result is reliable. The process involves obtaining the authentication result performed by the second controller on the first controller, and the authentication result includes authentication success or authentication failure. Responding to the control command when the authentication result is successful. A method of having.

2. The authentication result is that the authentication was successful, and the result of the authentication performed by the second controller on the first controller is obtained. This includes receiving an authentication success notification from the second controller, the authentication success notification being used to notify the first controller that the authentication performed by the second controller was successful. The method according to claim 1.

3. The authentication success notification is transmitted by broadcast, or the authentication success notification is transmitted to one or more predefined components. The method according to claim 2.

4. The method further includes sending a response message to the second controller. The response message indicates that the authentication success notification has been successfully received. The method according to claim 2.

5. The aforementioned device is a vehicle, The first controller includes a vehicle domain controller (VDC) or a power control module (VCU), The second controller comprises at least one of the following: a vehicle-integrated unit (VIU), a wireless communication control module, and a main unit control module (BCM), The aforementioned component includes a motor and / or a battery management system (BMS). The method according to claim 1.

6. The component has the motor, and the control command carries the torque request. Responding to the aforementioned control command means This includes performing torque response and power output in response to the aforementioned control command, The method according to claim 5.

7. The component has the BMS, and the control command instructs the BMS to output power. Responding to the aforementioned control command means This includes outputting the power supply in response to the control command. The method according to claim 5.

8. The aforementioned device is a vehicle, The first controller has a wireless communication control module, The second controller has a VIU and / or BCM, The aforementioned component includes a door controller and / or a window controller. The method according to claim 1.

9. The component has the door controller, and the control command instructs the door controller to unlock the door. Responding to the aforementioned control command means The system includes unlocking the door in response to the control command, and / or, The component has the window controller, and the control command instructs the window controller to unlock the window. Responding to the aforementioned control command means The system includes unlocking the window in response to the control command. The method according to claim 8.

10. If the key used to unlock the device is not within a pre-set range, or if a predefined abnormal situation is detected, the authentication result is the authentication failure. The method according to claim 1.

11. A component control device for a device having a component configured to perform the method described in claim 1.

12. A computer program is stored, and when the computer program is executed by a processor, the method according to claim 1 is performed. Computer-readable storage medium.

Citation Information

Patent Citations

  • Vehicle start limiting method, device and system

    CN109572620A

  • Wireless communication system

    JP2019080139A

  • Communication device

    JP2020021161A

  • Trusted connected vehicle systems and methods

    US20130212659A1

  • Verification method and apparatus

    WO2021238968A1