Method for releasing at least one vehicle-related permission
The method addresses the inefficiencies in current vehicle authorization systems by using hardware tokens to detect and authenticate users within a vehicle, allowing for rapid and flexible authorization management.
Patent Information
- Application Number
- PCT/EP2024/083473
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-06
- Filing Date
- 2024-11-25
- Publication Date
- 2025-06-12
AI Technical Summary
Current systems for granting vehicle-specific authorizations to vehicle users are cumbersome and time-consuming, especially for temporary users and the creation of new users.
A method that uses hardware tokens to detect users in a vehicle, receive authentication keys, compare them with authorization roles stored in a database, and release corresponding authorizations to recognized users.
Enables quick and simple implementation of vehicle-related authorization releases, allowing for efficient recognition and authorization of multiple users within a vehicle, regardless of their status or type.
Smart Images

Figure EP2024083473_12062025_PF_FP_ABST
Abstract
Description
[0001] PROCEDURE FOR RELEASE OF AT LEAST ONE VEHICLE-RELATED
[0002] AUTHORIZATION
[0003] The invention relates to a method for releasing at least one vehicle-related authorization to at least one user in a vehicle, according to patent claim 1. Furthermore, the invention relates to a computer-readable storage medium, according to patent claim 10.
[0004] Currently known systems for granting vehicle-specific authorizations to vehicle users, such as drivers, co-drivers, and passengers, especially for granting authorizations to temporary users, are extremely cumbersome and time-consuming. This also applies to the creation of users and the assignment of user-specific authorizations.
[0005] Therefore, the object of the present invention is to provide a method for releasing at least one vehicle-related authorization to at least one user in a vehicle, wherein the method is extremely simple and quick to implement. In particular, it should also be possible to easily create a user in a database, and the method should be usable for different types of users of a vehicle.
[0006] Furthermore, it is an object of the present invention to provide a corresponding computer-readable storage medium.
[0007] The present object is achieved with regard to the method by the subject matter of patent claim 1 and with regard to a computer-readable storage medium by the subject matter of patent claim 10.
[0008] In particular, the object is achieved by a method for releasing at least one vehicle-related authorization to at least one user in a vehicle, which method comprises the following steps: a) detecting the presence of at least one user in the vehicle using at least one hardware token; b) receiving an authentication key of the hardware token; c) comparing the authentication key with an authorization role stored in a database, in particular an authorization table; d) identifying the authorization role assigned to the authentication key; e) releasing the at least one authorization associated with the identified authorization role to the at least one recognized user.
[0009] One concept of the invention is that an authentication key of a user's hardware token is received on the vehicle side, and this authentication key is compared with an authorization role stored in a database. After identifying the authorization role assigned to the authentication key, at least one authorization associated with the identified authorization role is released to the at least one recognized user.
[0010] It is possible for the method to be used to identify several users present in a vehicle, in particular simultaneously, whereby the authentication key of each user is received by the vehicle, provided that the respective user is in possession of a hardware token or carries a hardware token.
[0011] Accordingly, the method according to the invention enables multiple users in a vehicle to be recognized and user-specific authorizations to be granted. In other words, different authorizations can be assigned to the respective users of a vehicle. The method according to the invention can thus be implemented regardless of the status or type of user.
[0012] In one embodiment of the invention, steps a) and b) can be performed simultaneously. In other words, the detection of the presence of at least one user in the vehicle and the reception of the authentication key of the hardware token of the at least one user can occur simultaneously.
[0013] It is possible that the vehicle continuously attempts to recognize authentication keys from hardware tokens, so that upon receipt of an authentication key, the presence of at least one user in the vehicle is simultaneously detected.
[0014] Preferably, at least one primary authorization role and at least one secondary authorization role are stored in the database, in particular the authorization table, wherein the primary authorization role is assigned to a main user and / or an owner of the vehicle and / or a keeper of the vehicle and the secondary authorization role is assigned to a temporary user and / or a passenger.
[0015] The primary authorization role is preferably understood to be the authorization role of a primary user and / or a vehicle owner and / or a vehicle keeper. In a preferred embodiment of the invention, this primary authorization role corresponds to the role of an administrator.
[0016] The primary authorization role preferably includes the authorization to allow or prohibit other users of the vehicle, preferably users with a secondary authorization role, from executing and / or using and / or opening certain vehicle-related applications.
[0017] The secondary authorization role is preferably assigned to a temporary user or a passenger. The secondary authorization role preferably has a smaller selection of authorizations available and / or fewer execution or usage options with regard to the types of authorizations.
[0018] According to the invention, it is possible that an authorization role, ie in particular a secondary authorization role, can also be assigned only one specific authorization.
[0019] The database can be stored in the vehicle. It is also possible that the database is stored on an external server.
[0020] In a further embodiment of the invention, it is possible for a plurality of different secondary authorization roles to be stored in the database, in particular the authorization table. Within the scope of the method according to the invention, a distinction is preferably made between primary authorization roles and secondary authorization roles. As already explained, it is possible for a secondary authorization role to be assigned a smaller selection and / or fewer options of authorizations, so that a distinction can be made between several secondary authorization roles with regard to the specific number and / or selection and / or options of authorizations.
[0021] For example, it is possible for the method to provide a first secondary authorization role that is assigned, for example, to a child or young person. A second secondary authorization role can be assigned, for example, to a temporary user. This temporary user can be a vehicle user who uses the vehicle temporarily, i.e., for a limited period of time. This use can, for example, involve driving the vehicle. The method makes it possible for the first secondary authorization role (child / young person) to be assigned, for example, only one authorization to use a streaming service provider, whereas the second secondary authorization role can be assigned multiple authorizations, in particular driving the vehicle.
[0022] Within the scope of the method according to the invention, it is possible that the assignment of an authentication key to an authorization role, in particular a secondary authorization role, and the storage of the authentication key assigned to an authorization role by
[0023] Recognition of a position between a user assigned to the primary authorization role and at least one other user, in particular a user assigned or to be assigned to the secondary authorization role, and / or a storage process preceding step a) takes place.
[0024] A first alternative to assigning an authentication key to an authorization role and storing the assigned
[0025] The authentication key thus relates to the recognition of a position between a user assigned to the primary authorization role and at least one other user, wherein this other user is a user to whom a secondary authorization role is assigned or is to be assigned. This recognition of a position preferably occurs before step a).
[0026] Alternatively, it is possible for the authentication key assigned to an authorization role to be saved in a save process prior to step a). This save process is preferably a manual save process. In other words, an authentication key can be entered into the database, in particular the authorization table, and the corresponding assignment to an authorization role, in particular to a secondary authorization role, can be made.
[0027] The first possibility, namely the detection of a position between a user assigned to the primary authorization role and at least one other user, can occur when the vehicle is used simultaneously or when a geographical proximity position is assumed, in particular outside the vehicle, and the assignment of a secondary authorization role to a user is confirmed, in particular by a user assigned to the primary authorization role.
[0028] Accordingly, it is possible that if a position is detected between a user assigned to the primary authorization role and at least one other user while simultaneously using the vehicle, this other user is assigned a secondary authorization role. The simultaneous use of the vehicle is interpreted as a type of trust basis, so that this other user is automatically assigned a secondary authorization role, in particular a secondary authorization role that is defined in advance by an administrator, in particular a user assigned to the primary authorization role.
[0029] It is possible for the user assigned to the primary authorization role to first define and save such a secondary authorization role in an initial step, which can then be assigned to another user of the vehicle. If another user uses the vehicle at the same time as the user assigned to the primary authorization role, the additional user's authentication key can be assigned to a secondary authorization role and saved in the database. The previously defined secondary authorization role is then released to the additional user.
[0030] Furthermore, assuming a geographical proximity position, which may also be outside the vehicle, is considered recognition of the position between a user assigned to the primary authorization role and at least one other user. In this case, i.e., assuming a geographical proximity position, confirmation of the assignment of a secondary authorization role is sent to the user who is in a geographical proximity position with this user. The confirmation is preferably performed by a user assigned to the primary authorization role.
[0031] Specifically, it is possible for a user assigned to the primary authorization role to receive a request asking whether a secondary authorization role should be assigned to a user located in a geographical proximity position. After confirmation of this assignment by the primary authorization role user, the authentication key of this additional user, to whom the secondary authorization role is assigned, can be stored in the database, specifically in the authorization table.
[0032] Detecting a position between a user assigned to the primary authorization role and at least one other user involves detecting the position of a user assigned to the primary authorization role and the position of at least one other user, and determining whether they are, for example, in a vehicle at the same time and / or have reached a geographical proximity to each other. A geographical proximity position can be present, for example, at a maximum distance of 1 meter, in particular a maximum of 50 cm.
[0033] The hardware token can be a smart card and / or a vehicle key and / or a mobile device and / or a transponder. In particular, it is possible for different types of hardware tokens to be used to carry out the method. For example, it is possible for a user assigned to a primary authorization role to be in possession of a vehicle key. A first user assigned to a secondary authorization role, however, can be in possession of a transponder, and a second user assigned to a secondary authorization role can be in possession of a mobile device, in particular a mobile phone. Specifically, the owner and / or keeper of a vehicle can have a vehicle key with a corresponding authentication key.A child or young person, on the other hand, may have a transponder with an authentication key and another user assigned to the secondary authorization role may in turn have a mobile device, in particular a mobile phone.
[0034] Within the scope of the method according to the invention, each hardware token is assigned an authentication key. It is possible for the method to provide that at least one user assigned to the primary authorization role is assigned a vehicle key, whereas all users with a secondary authorization role are assigned a mobile device.
[0035] When detecting the position already described between a user assigned to the primary authorization role and at least one other user, it is therefore possible that the position of a vehicle key and another hardware token, in particular a smart card and / or a mobile device and / or a transponder, is detected.
[0036] In particular, it is possible to detect within a vehicle whether hardware tokens, such as smart cards and / or vehicle keys and / or mobile devices and / or transponders, are located in the vehicle.
[0037] The authorization, especially the vehicle-related authorization, which can be assigned to an authorization role, can be, for example,
[0038] - driving the vehicle or
[0039] - opening and / or closing the vehicle or
[0040] - access to a streaming service provider or
[0041] - limited access to a streaming service provider or - a maximum travel distance or
[0042] - a maximum travel radius or
[0043] - a maximum speed of the vehicle or
[0044] - a minimum distance to be maintained from vehicles ahead or
[0045] - access to a payment service provider or
[0046] - restricted access to a payment service provider or
[0047] - performing a parking maneuver or
[0048] - carrying out a refuelling operation or
[0049] - making changes to vehicle settings or
[0050] - access to a network, in particular to a wireless local network, of the vehicle.
[0051] It is possible that several of the above-mentioned authorizations are assigned to an authorization role.
[0052] In particular, the authorization(s) can be assigned differently depending on the secondary authorization roles to be defined. Thus, it is possible for an authorization role, especially a secondary authorization role, to include several of the aforementioned authorizations.
[0053] A permission can also be understood as a restriction or reduction of certain services or actions. Such a restriction of a permission could, for example, be the maximum distance or radius of travel, a maximum speed of the vehicle, a minimum distance to be maintained from vehicles ahead, or restricted access to a payment service provider or a streaming service provider.
[0054] Access to a payment service provider can be used in particular to carry out a refuelling transaction.
[0055] In a further embodiment of the invention, it is possible that in step a), ie when the presence of at least one user in the vehicle is detected, the position of the at least one user within the vehicle is detected. The authorization roles stored in the database, in particular the authorization table, can have different authorizations depending on the position assumed in the vehicle, in particular the seating position. A position is preferably understood to be the assumption of a position on a seat in the vehicle. It is possible that users recognized within the vehicle who occupy a seat on the back seat of the vehicle are granted, for example, less authorization than users who occupy a position in the front passenger seat.
[0056] It is possible for at least one authorization of an authorization role, in particular the at least one authorization of a secondary authorization role, to be released for a limited period of time. In particular, it is possible that after a position is detected between a user assigned to the primary authorization role and at least one other user, the authorization of an authorization role and / or the assigned authorization role is released for a limited period of time.
[0057] For example, it is possible that after a position (in the vehicle) between a primary authorization role user and a secondary authorization role user is identified, the associated authorizations are only released for 24 hours, seven days, or one month. To this end, the user assigned to a primary authorization role can, after confirming the assignment of a secondary authorization role with confirmation of the assignment, specify a time frame for the assignment and / or release of the authorization(s). For example, a user with a secondary authorization role can be permitted to use the vehicle for one week after receiving appropriate approval from the secondary authorization role user.
[0058] The task is further solved by a computer-readable storage medium.
[0059] The storage medium may contain instructions that cause at least one processor to implement a method according to any one of the preceding embodiments when the instructions are executed by the at least one processor.
[0060] The processor is preferably a processor associated with a vehicle and / or is a processor of a vehicle. Similar or identical advantages arise as those described in connection with the method.
[0061] The invention is described below using exemplary embodiments, which are explained in more detail with reference to the figures. Herein:
[0062] Fig. 1 is a schematic representation of a vehicle in which a method according to the invention is carried out;
[0063] Fig. 2 is a schematic representation of a process sequence according to the invention;
[0064] Fig. 3 shows an authorization table; and
[0065] Fig. 4 shows the assignment of authorizations with regard to different authorization roles.
[0066] In the following description, the same reference numbers are used for identical and equivalent parts.
[0067] Fig. 1 shows a vehicle 100. In this vehicle 100, a method for releasing at least one vehicle-related authorization to at least one user in the vehicle 100 is carried out.
[0068] It can be seen that there are three different users in the vehicle: a primary user 10 and passengers 11a and 11b. Primary user 10 is a user assigned a primary authorization role. Passengers 11a and 11b are assigned different secondary authorization roles a and b.
[0069] In the present case, the main user 10 is the owner of a vehicle key, which vehicle key has the authentication key 12345 (see Fig. 3).
[0070] Passenger 11a (user), who is seated in the front passenger seat, is in possession of a mobile device, in particular a mobile phone. This transmits an authentication key 45678 (see Fig. 3). Another occupant (user) of the vehicle is a child 11b sitting in the back seat of the vehicle. This child, in turn, is in possession of a transponder with an authentication key 23234 (see Fig. 3).
[0071] Since the main user 10 and the passenger 11a are located in the same vehicle, this detected position between the main user 10 and the passenger 11a is detected by the vehicle 11, whereby the secondary authorization role a is automatically assigned to the mobile terminal of the passenger 11a and the authentication key 45678 sent by the mobile terminal.
[0072] It is possible that this assignment of a secondary authorization role a only takes place after corresponding confirmation by the main user 10.
[0073] As shown in Fig. 2, the method according to the invention initially provides in step S1 for detecting the presence of the users 10, 11a and 11b located in the vehicle 100 on the basis of the respectively assigned hardware tokens.
[0074] The authentication keys, namely 12345 (main user 10), 45678 (passenger 11a), and 23234 (passenger 11b), are received from all three hardware tokens. These authentication keys are compared with authorization roles stored in a database, in this case an authorization table, as shown in Fig. 3. This is step S3.
[0075] The database 20 may be located in the vehicle 10. Furthermore, it is possible that, as indicated in Fig. 1, the database is stored on an external server.
[0076] According to step S4, the authorization roles assigned to the authentication keys are identified using the authorization table stored in database 20. It becomes clear that the roles: primary authorization role, secondary authorization role a, and secondary authorization role b are identified based on the received authentication keys. According to step S5, the authorizations associated with at least one of the identified authorization roles are then released to the recognized users 10, 11a, and 11b.
[0077] As shown in Fig. 4, different permissions can be assigned to the authorization roles. For example, a user assigned to the primary authorization role, e.g., the main user and / or the owner and / or keeper of the vehicle, receives all administrator rights.
[0078] As shown in Fig. 3, it is possible for multiple users of the vehicle 100 to be assigned a primary authorization role. Specifically, multiple people, for example, a primary user and another owner of the vehicle, can possess a hardware token with one of the two authentication keys 12345 or 54321.
[0079] In the present example according to Fig. 4, it is possible that the main user 10 is assigned the primary authorization role and thus all administrator rights.
[0080] Passenger 11a in the front passenger seat has authenticated himself as a user with secondary authorization role a due to the recognition of his position in vehicle 100 in relation to primary user 10. This passenger 11a may, for example, use the infotainment system 50 and the streaming service providers assigned to primary user 10. Furthermore, he is permitted to intervene in the security system. When using vehicle 100 as a driver, he is permitted to use vehicle 100 within a radius of 100 km, calculated from the time of taking over vehicle 100.
[0081] Passenger 11b, who is seated in the rear seat of vehicle 100, is identified as a user with secondary authorization role b. Accordingly, this passenger 11b is only permitted to use the infotainment system on screen 60, with the restriction that he may only use the children's side.
[0082] The secondary authorization role x is also stored in the database 20. This role is assigned to a user of the vehicle 100 whenever the vehicle 100 does not receive an authentication key from this user or receives an unknown authentication key. A user assigned to this secondary authorization role x is not granted any rights.
[0083] At this point it should be noted that all of the parts described above are to be regarded individually - even without additionally described features in the respective context, even if these have not been explicitly identified as optional features in the respective context, e.g. by using: in particular, preferably, for example, for example, if necessary, round brackets etc. - and in combination or any sub-combination as an independent embodiment or development of the invention, as defined in particular in the introduction to the description and the claims. Deviations from this are possible. Specifically, it should be noted that the word "in particular" or round brackets do not identify any features that are mandatory in the respective context.
[0084] List of reference symbols
[0085] 10 Main user 11a, 11b Passenger
[0086] 20 Database
[0087] 50 infotainment system
[0088] 60 screen
[0089] 100 vehicles
Claims
CLAIMS 1. A method for releasing at least one vehicle-related authorization to at least one user (10, 11a, 11b) in a vehicle (100), comprising the following steps: a) detecting the presence of at least one user (10, 11a, 11b) in the vehicle (100) using at least one hardware token (S1); b) receiving an authentication key of the hardware token (S2); c) comparing the authentication key with an authorization role (S3) stored in a database (20), in particular an authorization table; d) identifying the authorization role (S4) assigned to the authentication key; e) releasing the at least one authorization associated with the identified authorization role to the at least one recognized user (S5).
2. Method according to claim 1, characterized in that in the database (20), in particular in the authorization table, at least one primary authorization role and at least one secondary authorization role are stored, wherein - the primary authorization role is assigned to a main user (10) and / or an owner of the vehicle and / or a keeper of the vehicle and - the secondary authorization role is assigned to a temporary user and / or a passenger (11a, 11b).
3. Method according to claim 2, characterized in that a plurality of different secondary authorization roles are stored in the database (20), in particular the authorization table.
4. Method according to one of the preceding claims, in particular according to one of claims 2 to 3, characterized in that the assignment of an authentication key to an authorization role, in particular a secondary authorization role, and the storage of the authentication key assigned to an authorization role by - Detecting a position between a user (10) assigned to the primary authorization role and at least one further user (11a, 11b), in particular a user assigned or to be assigned to the secondary authorization role, and / or - a storage operation takes place prior to step a).
5. Method according to claim 4, characterized in that the detection of the position at - simultaneous use of the vehicle (100) or - upon taking a geographical proximity position, in particular outside the vehicle, and confirmation of the assignment of a secondary authorization role to a user (11a, 11b), in particular by a user (10) assigned to the primary authorization role.
6. Method according to one of the preceding claims, characterized in that the hardware token is a smart card and / or a vehicle key and / or a mobile terminal and / or a transponder.
7. Method according to one of the preceding claims, characterized in that the authorization - driving the vehicle or - opening and / or closing the vehicle or - access to a streaming service provider or - limited access to a streaming service provider or - a maximum distance to be covered or - a maximum travel radius or - a maximum speed of the vehicle or - a minimum distance to be maintained from vehicles ahead or - access to a payment service provider or - limited access to a payment service provider or - performing a parking maneuver or - carrying out a refueling operation or - making changes to vehicle settings or - access to a network, in particular a wireless local network, of the vehicle.
8. Method according to one of the preceding claims, characterized in that in step a) the position, in particular sitting position, of the at least one user (10, 11a, 11b) within the vehicle (100) is recognized, wherein the authorization roles stored in the database (20), in particular the authorization table, have different authorizations depending on the position assumed in the vehicle (100), in particular sitting position.
9. Method according to one of the preceding claims, in particular according to one of claims 4 to 8, characterized in that the at least one authorization of an authorization role, in particular the at least one authorization of a secondary authorization role, is released for a limited period of time, in particular after a / the recognition of a position between a user (10) assigned to the primary authorization role and at least one further user (11a, 11b) is released for a limited period of time.
10. A computer-readable storage medium containing instructions that cause at least one processor to implement a method according to any one of claims 1 to 9 when the instructions are executed by the at least one processor.
Citation Information
Patent Citations
DEVICE FOR CONTROLLING A SEAT OF A VEHICLE, SYSTEM COMPRISING THE SAME AND METHOD THEREOF
DE102020107550A1
Access control device, vehicle, and method for operating an access control device
DE102022115575B3
Vehicle access authorization
DE112016007093T5