UWB key transmission method and related apparatus
Through the central processor, the ultra-wideband transmission key is transmitted between the UWB chip and the security chip, which solves the complex and cost-effective connection between the UWB chip and the security chip hardware, and realizes the flexible combination of the security chip and the UWB chip and cost savings.
Patent Information
- Application Number
- PCT/CN2025/073478
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-31
- Filing Date
- 2025-01-21
- Publication Date
- 2025-08-07
AI Technical Summary
In the prior art, hardware bus connection is required between the UWB chip and the security chip and pre-installed certificates or keys, resulting in high production costs and complex implementation of electronic equipment.
The ultra-wideband transmission key is obtained through the central processor and stored in the security chip. The security chip encrypts the key and transmits it to the UWB chip through the central processor. The UWB chip is decrypted and used, avoiding the need to preset the same key or certificate on the production line.
It realizes a flexible combination of security chips and UWB chips, reducing the production cost of electronic devices and the complexity of hardware and software.
Smart Images

Figure CN2025073478_07082025_PF_FP_ABST
Abstract
Description
A UWB key transmission method and related device
[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on January 31, 2024, with application number 202410141571.0 and application name “A UWB key transmission method and related device”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of ultra-wideband communication technology, and in particular to a UWB key transmission method and related devices. Background Art
[0003] With the adoption of ultrawideband (UWB) communication technology, some electronic devices are equipped with UWB chips. UWB chips can use UWB technology to perform ranging and positioning, enabling applications such as automatic door unlocking and vehicle start upon proximity. In these scenarios, the UWB chip's ranging and positioning process must be secure. Therefore, UWB requires the use of a UWB session key (URSK) to derive and encrypt parameters used in the ranging and positioning process. To ensure the security of the URSK, it is typically generated in the electronic device's secure chip (SEChip). During the UWB chip's ranging process, the secure chip establishes a secure transmission channel over the bus connection with the UWB chip and transmits the URSK to the UWB chip over the secure transmission channel. However, a hardware bus is required to connect the secure chip and the UWB chip in the electronic device. Furthermore, the certificates or keys used to establish the secure transmission channel must be pre-installed in both the UWB chip and the secure chip before the electronic device leaves the factory. This complicates the implementation of both chip software and hardware in the electronic device, increasing the production cost of the electronic device. Summary of the Invention
[0004] The present application provides a UWB key transmission method and related devices, which enable the UWB chip of an electronic device to securely transmit URSK to the UWB chip through the central processor, allowing the security chip and the UWB chip to be flexibly combined without strong binding.
[0005] In a first aspect, the present application provides a UWB key transmission method, which is applied to an electronic device, wherein the electronic device includes a central processing unit, a UWB chip and a security chip, the processor being connected to the UWB chip, and the processor being connected to the security chip; the method includes: the central processing unit obtaining an ultra-wideband transmission key and storing the ultra-wideband transmission key in the security chip, wherein the security chip stores a target ultra-wideband ranging session key URSK; the security chip uses the ultra-wideband transmission key to encrypt the target URSK into first encrypted data; the security chip sends the first encrypted data to the UWB chip through the central processing unit, wherein the UWB chip stores the ultra-wideband transmission key; the UWB chip decrypts the target URSK from the first encrypted data using the ultra-wideband transmission key, and the target URSK is used for ranging of the UWB chip.
[0006] Through the UWB key transmission method provided by the present application, the UWB chip can securely transmit URSK to the UWB chip through the central processor, without pre-setting the same symmetric key or pre-setting the digital certificates of both parties in the UWB chip and security chip of the electronic device on the production line. This allows the security chip and the UWB chip in the electronic device to be flexibly combined without strong binding, saving the production cost of the electronic device.
[0007] In one possible implementation, the central processor obtains the ultra-wideband transmission key, specifically including: the central processor obtaining the ultra-wideband transmission key sent by the server. In this way, the ultra-wideband transmission key can be requested from the server to be sent, rather than pre-installed in the security chip before the electronic device leaves the factory, thereby reducing the production cost of the electronic device.
[0008] In one possible implementation, before the central processor obtains the ultra-wideband transmission key sent by the server, the method further includes: the central processor obtains the manufacturer identifier and chip identifier of the UWB chip from the UWB chip; the central processor sends a first request to the server, the first request carrying the manufacturer identifier and chip identifier of the UWB chip, the first request being used to request the server to generate the ultra-wideband transmission key based on the root key, the manufacturer identifier and chip identifier of the UWB chip. In this way, the ultra-wideband transmission key is derived from the manufacturer identifier and chip identifier of the UWB chip and the root key, which can ensure that different electronic devices use different ultra-wideband transmission keys, ensuring the uniqueness of the ultra-wideband transmission key for the electronic device, thereby ensuring the security of URSK transmission.
[0009] In one possible implementation, before the central processor obtains the ultra-wideband transmission key, the method further includes: before the electronic device leaves the factory, the UWB chip exports the UWB chip's manufacturer identifier and the UWB chip's chip identifier to an encryption engine, the encryption engine being used to generate the ultra-wideband transmission key based on the root key, the UWB chip's manufacturer identifier, and the UWB chip's chip identifier; and the UWB chip receiving the ultra-wideband transmission key imported by the encryption engine. In this way, the ultra-wideband transmission key can be pre-set only in the UWB chip on the production line, without pre-setting the ultra-wideband transmission key in the security chip, thereby decoupling the UWB chip and the security chip, eliminating the need for a forced binding between the UWB chip and the security chip.
[0010] In one possible implementation, before the UWB chip stores the ultra-wideband transmission key, the method further includes: the UWB chip generates a first public key and a first private key, the first public key and the first private key forming a public-private key pair; the UWB chip sends the first public key to the central processor; after the central processor obtains the ultra-wideband transmission key sent by the server, it encrypts the ultra-wideband transmission key into second encrypted data using the first public key; the central processor sends the second encrypted data to the UWB chip; and the UWB chip decrypts the ultra-wideband transmission key from the second encrypted data using the first private key. In this way, it is not necessary to pre-set the ultra-wideband transmission key in the UWB chip before the electronic device leaves the factory. Instead, after obtaining the ultra-wideband transmission key from the server, the central processor establishes a secure transmission channel with the UWB chip and securely transmits the ultra-wideband transmission key to the UWB chip, thereby saving the production cost of the electronic device.
[0011] In a possible implementation, before the ultra-wideband transmission key is stored in the UWB chip, the method further includes: the UWB chip generating the ultra-wideband transmission key.
[0012] In one possible implementation, before the central processor obtains the ultra-wideband transmission key, the method further includes: the central processor generating a second public key and a second private key, the second public key and the second private key forming a public-private key pair; the central processor sending the second public key to the UWB chip; the central processor obtaining the ultra-wideband transmission key, specifically including: the UWB chip using the second public key to encrypt the ultra-wideband transmission key into third encrypted data; the UWB chip sending the third encrypted data to the central processor; and the central processor using the second private key to decrypt the ultra-wideband transmission key from the third encrypted data. In this way, the UWB chip can generate the ultra-wideband transmission key and establish a secure transmission channel with the central processor, allowing the central processor to securely write the ultra-wideband transmission key into the security chip, reducing the deployment cost of the server and the production cost of the electronic device.
[0013] In one possible implementation, the UWB chip generates the UWB transmission key by randomly generating the UWB transmission key. This ensures that the UWB chips in different electronic devices use different UWB transmission keys, ensuring the uniqueness of the UWB transmission key for each electronic device, thereby ensuring the security of URSK transmission.
[0014] In one possible implementation, the UWB chip stores the manufacturer's identifier and the chip's identifier. The UWB chip generates the UWB transmission key by, among other things, generating the UWB transmission key based on the root key, the manufacturer's identifier, and the chip's identifier. This ensures that the UWB chips in different electronic devices use different UWB transmission keys, ensuring the uniqueness of the UWB transmission key for each electronic device, thereby ensuring the security of URSK transmission.
[0015] In one possible implementation, the UWB chip generates the ultra-wideband transmission key based on the root key, the manufacturer identifier of the UWB chip, and the chip identifier of the UWB chip, specifically including: the UWB chip generates a pairing key based on the root key and the manufacturer identifier of the UWB chip; the UWB chip generates the ultra-wideband transmission key based on the pairing key and the chip identifier of the UWB chip.
[0016] In one possible implementation, the security chip stores a target ultra-wideband ranging session key URSK, specifically including: the security chip generates one or more URSKs using the stored car key session key, the one or more URSKs including the target URSK; the security chip stores the one or more URSKs, wherein different URSKs correspond to different session identifiers.
[0017] In one possible implementation, before the security chip uses the ultra-wideband transmission key to encrypt the target URSK into first encrypted data, the method further includes: the UWB chip sends a URSK acquisition command to the security chip through the central processor, and the URSK acquisition command carries a first session identifier; after receiving the URSK acquisition command, the security chip determines the target URSK corresponding to the first session identifier from the one or more URSKs.
[0018] In one possible implementation, before the UWB chip sends a URSK acquisition command to the security chip through the central processor, the method also includes: the UWB chip sends a random number acquisition command to the security chip through the central processor; after receiving the random number acquisition command, the security chip sends a first random number to the UWB chip through the central processor; the UWB chip uses the ultra-wideband transmission key to encrypt the first random number into an authentication ciphertext, and sends the authentication ciphertext to the security chip through the central processor; the security chip uses the ultra-wideband transmission key to decrypt a second random number from the authentication ciphertext; if the second random number is the same as the first random number, the security chip sends a first response to the UWB chip through the central processor, and the first response is used to indicate that the random number verification is successful; the UWB chip sends a URSK acquisition command to the security chip through the central processor, specifically including: after receiving the first response, the UWB chip sends the URSK command to the security chip through the central processor.
[0019] In one possible implementation, a rich execution environment (REE) and a trusted execution environment (TEE) are running in the central processing unit, and a car key application is running in the REE; the central processing unit obtains the ultra-wideband transmission key, specifically including: the central processing unit obtains the ultra-wideband transmission key through the car key application; the central processing unit stores the ultra-wideband transmission key in the security chip, specifically including: the central processing unit stores the ultra-wideband transmission key in the security chip through the car key application and the TEE.
[0020] In one possible implementation, the UWB chip is not connected to the security chip. This eliminates the need for a forced connection between the UWB chip and the security chip, reducing the difficulty and cost of installing the UWB chip and the security chip in an electronic device.
[0021] In a second aspect, the present application provides a UWB key transmission method, which is applied to an electronic device, wherein the electronic device includes a central processing unit, a microcontroller, a UWB chip and a security chip, wherein the processor is connected to the microcontroller, the processor is connected to the security chip, and the microcontroller is connected to the UWB chip; the method includes: the security chip stores a target URSK; the central processing unit obtains the target URSK from the security chip; the central processing unit sends the target URSK to the microcontroller; the microcontroller generates a UWB communication message based on the target URSK; the microcontroller sends the UWB communication message to the UWB chip; after receiving the UWB communication message sent by the microcontroller, the UWB chip sends the UWB communication message, and the UWB communication message is used for ranging.
[0022] In a third aspect, the present application provides an electronic device comprising one or more processors, one or more memories, a security chip, and a UWB chip. The one or more processors include a central processing unit (CPU), which is connected to the UWB chip, and the CPU is connected to the security chip; the one or more memories are used to store a computer program. When the one or more processors execute the computer program, the first electronic device executes the method of any possible implementation of any of the above aspects.
[0023] In a fourth aspect, the present application provides a computer storage medium comprising a computer program, which, when executed on a processor on an electronic device, enables the electronic device to execute a method in any possible implementation of any of the above aspects.
[0024] In a fifth aspect, the present application provides a computer program product, which, when executed on a processor of an electronic device, enables the electronic device to execute a method in any possible implementation of any of the above aspects.
[0025] The beneficial effects of the second and fifth aspects mentioned above can be referred to the beneficial effects of the first aspect and any possible implementation method of the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] FIG1 is a schematic diagram of an application scenario of UWB ranging provided by an embodiment of the present application;
[0027] FIG2 is a schematic diagram of the architecture of a digital car key system provided in an embodiment of the present application;
[0028] FIG3 is a schematic diagram of the functional modules of a security chip and a UWB chip provided in an embodiment of the present application;
[0029] FIG4 is a schematic diagram of a process of transmitting URSK from a security chip to a UWB chip according to an embodiment of the present application;
[0030] FIG5 is a schematic diagram showing the principle of a UWB key transmission method provided in an embodiment of the present application;
[0031] FIG6 is a schematic diagram of a UWB key transmission method provided in an embodiment of the present application;
[0032] FIG7A is a schematic diagram of a pairing key generation process provided in an embodiment of the present application;
[0033] FIG7B is a schematic diagram of a process for generating an ultra-wideband transmission key according to an embodiment of the present application;
[0034] FIG7C is a schematic diagram of a URSK transmission process provided in an embodiment of the present application;
[0035] FIG8 is a schematic diagram of a UWB key transmission method provided in another embodiment of the present application;
[0036] FIG9 is a schematic diagram of a UWB key transmission method provided in another embodiment of the present application;
[0037] FIG10 is a schematic diagram of a UWB key transmission method provided in another embodiment of the present application;
[0038] FIG11 is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application;
[0039] FIG12 is a schematic diagram of the hardware structure of a server provided in an embodiment of the present application. DETAILED DESCRIPTION
[0040] The following is a clear and detailed description of the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings. In the description of the embodiments of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in the text is only a description of the association relationship between related objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present application, "multiple" means two or more than two.
[0041] In the following, the terms "first" and "second" are used for descriptive purposes only and should not be understood to imply or suggest relative importance or implicitly indicate the number of the technical features indicated. Therefore, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of this application, unless otherwise specified, "plurality" means two or more.
[0042] FIG1 shows a schematic diagram of an application scenario of UWB ranging provided in an embodiment of the present application.
[0043] As shown in Figure 1, the electronic device 100 can measure the distance between the electronic device 100 and the vehicle 200 through UWB ranging technology. When the electronic device 100 approaches the vehicle 200 and enters the unlocking zone, the electronic device 100 can unlock the door of the vehicle 200 through the digital car key. Optionally, when the electronic device 100 enters the unlocking zone, the vehicle 200 can also be started (for example, the engine or power supply of the vehicle 200, etc.) through the digital car key. When the electronic device 100 gradually moves away from the unlocking zone and enters the locking zone, the electronic device 100 can automatically lock the door of the vehicle 200 with the digital car key. Optionally, when the electronic device 100 moves away from the unlocking zone and enters the locking zone, the engine or power supply of the vehicle 200 can also be turned off through the digital car key.
[0044] In this way, the user does not need to carry a physical car key. When the user brings the electronic device 100 carrying the activated digital car key close to the vehicle 200, the door of the vehicle 200 can be automatically unlocked, and when the user moves away from the vehicle 200, the door of the vehicle 200 can be automatically locked.
[0045] FIG2 is a schematic diagram of the architecture of a digital car key system provided in an embodiment of the present application.
[0046] As shown in Figure 2, the digital car key system may include an electronic device 100 and a vehicle 200. The electronic device 100 may include a central processing unit 101, a secure chip (SE Chip) 102, and a UWB chip 103. Optionally, the electronic device 100 may also include a Bluetooth chip 104 and an NFC chip 105. The vehicle 200 may include a vehicle-side digital car key (DK) authentication system 201, a vehicle control module 205, and a UWB chip 206. Optionally, the vehicle 200 may also include a Bluetooth chip 207 and an NFC chip 208.
[0047] The vehicle-side DK authentication system 201 may include an authentication control module 202, a key management module 203, and a key storage module 204. The vehicle-side DK authentication system 201 may be used to implement secure interaction between a mobile terminal and the vehicle body control module. The key management module 203 may be responsible for issuing, updating, deleting, and managing blacklists and whitelists. The authentication control module 202 may be responsible for bidirectional authentication and business information exchange with the electronic device 100, as well as controlling vehicle-side business logic. The key storage module 204 may be responsible for securely storing basic key information. The vehicle control module 205 may be responsible for controlling the vehicle's body electronics or power system and executing related digital car key business logic.
[0048] The vehicle-side DK authentication system 201 can establish a communication connection with the electronic device 100 through a short-range communication module such as the UWB chip 206, Bluetooth chip 207, or NFC chip 208, and receive authentication information and service data sent by the electronic device 100. The authentication control module 202 can perform bidirectional authentication on the electronic device 100 based on the security key stored in the key storage module, verify key service data, and perform ranging or vehicle control command verification, etc.
[0049] In some embodiments, the UWB chip 103 and the security chip 102 on the electronic device 100 are connected via a bus. For example, the bus may include a serial peripheral interface (SPI) bus or an inter-integrated circuit (I2C) bus. After the digital car key of the vehicle 200 is activated, the electronic device 100 can obtain the car key key. The electronic device 100 can store the car key key in the security chip 102. Among them, the security chip 102 can derive a car key session key (Session key) based on the car key key. The security chip 102 can generate an ultra-wideband root session key (URSK) based on the car key session key. The security chip 102 can pass the URSK to the UWB chip 103 via a bus connection. After receiving the URSK, the UWB chip 103 can derive a ranging process key based on the URSK in accordance with a UWB ranging protocol such as the Fira protocol or CCC. The UWB chip 103 can perform UWB ranging communication with the UWB chip 206 on the vehicle 200 through the ranging process key, thereby ensuring security during the UWB ranging process.
[0050] 3 and 4 , the process of transmitting the URSK from the security chip 102 on the electronic device 100 to the UWB chip 103 will be described below.
[0051] FIG3 shows a schematic diagram of the functional modules of the security chip 102 and the UWB chip 103 in an embodiment of the present application.
[0052] As shown in FIG3 , the security chip 102 and the UWB chip 103 are connected via a bus. For example, the bus may be an SPI bus or an I2C bus.
[0053] The security chip 102 may include a digital key applet (DK Applet), a secure UWB service applet (SUS Applet), security specifications, a transmission protocol (e.g., T1 protocol), and a bus driver (e.g., SPI driver or I2C driver). The security specifications may include the Global Platform Secure Protocol (GP Secure Protocol) and a smart card (Javacard) platform.
[0054] Among them, the digital key application may include one or more of the following: Car Connectivity Consortium Digital Key Applet (CCC DK Applet), Intelligent Car Connectivity Industry Ecosystem Alliance Digital Key Applet (ICCE DK Applet) or Fineranging Application (FiRa Applet). The digital key application and the SUS Applet can communicate through the secure ultra-wideband service internal application interface (secure UWB service internal application interface, SUS internal API). The digital key application can call a SUS Applet to establish a secure transmission channel between the security chip 102 and the UWB chip 103, and pass the URSK to the UWB chip 103 in the secure transmission channel.
[0055] The global platform security protocols on the security chip 102 may include the SCP03 protocol and the SCP11a protocol. These global platform security protocols can be used to establish secure transmission channels between the security chip 102 and other modules (e.g., the UWB chip 103). The Javacard platform can be used to run applications (e.g., digital key applications, secure ultra-wideband service applications, etc.) on the security chip 102 and ensure security between these applications. The transmission protocols on the security chip 102 can be used to establish data links between the UWB chip 103 and other modules (e.g., the security chip 102).
[0056] The UWB chip 103 may include a ranging module, a global platform security protocol (GP Secure protocol), an encryption service (Crypto Service), a transmission protocol (e.g., T1 protocol), a bus driver (e.g., SPI driver or I2C driver), a UWB media access control layer (UWB MAC Layer) and a UWB physical layer (UWB PHY Layer).
[0057] The ranging module may include one or more of the following: a FiRa Ranging module or a CCC Ranging module. The ranging module may send or receive UWB signals to or from other devices (e.g., vehicle 200) via the UWB MAC layer and the UWB PHY layer, thereby performing ranging or positioning between the electronic device 100 and the other device (e.g., vehicle 200).
[0058] The global platform security protocol on the UWB chip 103 can be used to establish a secure transmission channel between the UWB chip 103 and other modules (e.g., the security chip 102). The encryption and decryption services can be used to provide encryption or decryption functions within the UWB chip 103. The transmission protocol on the UWB chip 103 can be used to establish a data link between the UWB chip 103 and other modules (e.g., the security chip 102).
[0059] FIG4 is a schematic diagram showing a process of transmitting URSK from a security chip to a UWB chip provided in an embodiment of the present application.
[0060] As shown in Figure 4, the process of transmitting URSK from the security chip to the UWB chip can be as follows:
[0061] 1. The security chip 102 and the UWB chip 103 can perform bus communication via bus driver.
[0062] For example, the bus driver may include an SPI driver or an I2C driver. The bus communication may include SPI communication or I2C communication.
[0063] 2. The security chip 102 and the UWB chip 103 can establish a data link (Data Link) with the UWB chip 103 through a transmission protocol.
[0064] For example, the transmission protocol may be T1 Protocol.
[0065] 3. The security chip 102 and the UWB chip 103 can establish a secure channel through the Global Platform Security Protocol (GP Secure Protocol).
[0066] For example, the GP Secure Protocol may include the SCP03 protocol or the SCP11a protocol.
[0067] 4. The SUS Applet of the security chip 102 and the ranging module of the UWB chip 103 can interact through the application protocol data unit (APDU) and transmit the URSK to the UWB chip 103.
[0068] In the solution of establishing a secure transmission channel using the SCP03 protocol, it is necessary to pre-set the symmetric keys in the security chip 102 and the UWB chip 103 on the production line before the electronic device 100 leaves the factory. Therefore, after leaving the factory, when the electronic device 100 activates the digital car key and uses the UWB chip 103 to measure distance, the security chip 102 can encrypt the URSK using the preset symmetric key, and send the encrypted URSK to the UWB chip 103 through the secure transmission channel established by the SCP03 protocol. The UWB chip 103 uses the preset symmetric key to decrypt the URSK from the encrypted URSK. Different electronic devices need to be pre-set with different symmetric keys, so as to avoid decrypting the URSK from the encrypted URSK on the electronic device 100 using the symmetric keys preset in the security chip or UWB chip on other devices, thereby ensuring the security of the electronic device 100 during the UWB ranging or positioning process.
[0069] In a solution that uses the SCP11a protocol to establish a secure transmission channel, digital certificates for both parties must be pre-installed in the security chip 102 and the UWB chip 103 on the production line before the electronic device 100 leaves the factory. When establishing the secure transmission channel, the security chip 102 and the UWB chip 103 must mutually verify each other's digital certificates and exchange public keys. The security chip 102 can derive a symmetric key using its private key and the public key of the UWB chip 103, and the UWB chip 103 can derive the same symmetric key using its private key and the public key of the security chip 102. Therefore, after leaving the factory and activating the digital car key, when the UWB chip 103 is used for ranging or positioning, the security chip 102 can encrypt the URSK using the symmetric key and send the encrypted URSK to the UWB chip 103 via the secure transmission channel established by the SCP03 protocol. The UWB chip 103 then decrypts the encrypted URSK using the symmetric key. The UWB chip 103 needs to be paired with the security chip 102 to form a coupling relationship, so as to avoid decrypting the URSK from the URSK encrypted on the electronic device 100 through the symmetric key negotiated by the security chip and the UWB chip on other devices, thereby ensuring the security of the electronic device 100 during the UWB ranging or positioning process.
[0070] However, in the above-mentioned SCP03 solution or SCP11a solution, since the UWB chip and the security chip of the electronic device need to be connected through a bus to form a coupling relationship, and the same symmetric key or the digital certificates of both parties need to be pre-set in the UWB chip and the security chip of the electronic device on the production line, the complexity of the hardware and software on the electronic device on the production line is increased, resulting in higher production costs of the electronic device.
[0071] Therefore, as shown in Figure 5, a UWB key transmission method is provided in an embodiment of the present application, which can enable the security chip 102 to establish a secure transmission channel with the UWB chip 103 through the central processor 101, and transmit URSK to the UWB chip 103 on the secure transmission channel established through the central processor 101 and the UWB chip 103.
[0072] Specifically, the central processing unit 101 can obtain an ultra-wideband transmission key and store the ultra-wideband transmission key in the security chip 102, which stores the target URSK. The security chip 102 uses the ultra-wideband transmission key to encrypt the target URSK into first encrypted data. The security chip 102 can send the first encrypted data to the UWB chip 103 through the central processing unit 101, wherein the UWB chip 103 stores the ultra-wideband transmission key. The UWB chip 103 uses the ultra-wideband transmission key to decrypt the target URSK from the first encrypted data, and the target URSK is used for ranging by the UWB chip. In this way, the security chip 102 and the UWB chip 103 can be flexibly combined without the need for a strong binding.
[0073] The following describes a UWB key transmission method provided in an embodiment of the present application.
[0074] A UWB key transmission method is provided in an embodiment of the present application. Before the electronic device 100 leaves the factory, an ultra-wideband transmission key (UWB transferkey) can be preset in the UWB chip through an encryption machine. The electronic device 100 can request the server to generate the same ultra-wideband transmission key through the car key application running in the central processing unit. After the car key application obtains the ultra-wideband transmission key issued by the server, it can store the ultra-wideband transmission key in the security chip through the trusted execution environment (TEE) in the central processing unit. The security chip can use the UWB transferkey to encrypt the URSK required for the UWB chip to measure the distance and obtain encrypted data A. The security chip can pass the encrypted data A to the UWB chip through the TEE and the rich execution environment (REE) in the central processing unit. The UWB chip can decrypt the URSK from the encrypted data A using the pre-made UWB transferkey. In this way, while ensuring the secure transmission of URSK from the security chip to the UWB chip, the UWB chip and the security chip can be decoupled, so that there is no need for a direct connection between the UWB chip and the security chip. The security chip and the UWB chip can be flexibly combined without strong binding.
[0075] FIG6 shows a schematic diagram of a UWB key transmission method provided in an embodiment of the present application.
[0076] As shown in Figure 6, the UWB key transmission method can be applied to a UWB key transmission system. The UWB key transmission system may include an electronic device 100, a server 300, and an encryption machine 400. The electronic device 100 may include a central processing unit (CPU) 101, a security chip (SE Chip) 102, and a UWB chip 103. There is no connection between the security chip 102 and the UWB chip 103. The security chip 102 can be connected to the central processing unit 101, and the UWB chip 103 can be connected to the central processing unit 101. Among them, two application environments can run in the central processing unit 101: REE and TEE. Among them, the REE can run a car key application 1011, an ultra-wideband service (UWB Service) 1012, an ultra-wideband protocol stack and kernel (UWB stack and kernel) 1013, and a secure service (Secure Service) 1014.
[0077] In a possible implementation, when the security chip 102 is connected to the UWB chip 103 , the UWB key transmission method provided in the embodiment of the present application may also be used.
[0078] The operating system running in the REE can be called a Rich Execution Environment Operating System (REE OS), and the operating system running in the TEE can be called a Trusted Execution Environment Operating System (TEE OS). The TEE is a secure operating environment running in the CPU. The TEE's secure boot process must be verified and is separate from the REE. Applications running under the TEE are independent of each other and cannot access each other without authorization. This ensures that the resource and data processing of applications under the TEE is executed in a trusted environment, thereby providing security services for the REE OS. The TEE has its own execution space and a higher level of security than the REE OS. It is a security architecture that overlaps with the hardware architecture of the currently used CPU. The software and hardware resources accessible by the TEE are separate from the REE OS, providing hardware-supported isolation.
[0079] The security chip 102 may include a digital key application (DK Applet) 1021 and a secure UWB management application (Secure UWB Manage Applet) 1022. The digital key application 1021 may be any of the CCC DK Applet, ICCE DK Applet, or FiRa Applet. The digital key application 1021 may call the secure UWB management application 1022 through an internal API.
[0080] The UWB chip 103 may include a secure UWB service 1031 .
[0081] The UWB key transmission method may include the following steps:
[0082] S601. The encryption engine 400 derives the manufacturer identification and chip identification (EUI) of the UWB chip 103 from the UWB chip 103 before the electronic device 100 leaves the factory.
[0083] After the UWB chip 103 is produced, the manufacturer identification and chip identification of the UWB chip 103 may be stored in a storage medium inside the UWB chip 103 .
[0084] S602. The encryption machine 400 generates a pairing key (Pairkey) based on the root key (Rootkey) and the manufacturer identification of the UWB chip 103.
[0085] The encryption engine 400 generates a pairing key (Pairkey) by using the AES128-CBC encryption algorithm based on the root key and the manufacturer identification of the UWB chip 103. Optionally, the encryption engine 400 can also use other encryption algorithms to generate a pairing key (Pairkey), which is not limited in the embodiments of the present application.
[0086] For example, as shown in FIG7A , based on the Rootkey and the manufacturer identifier of the UWB chip 103 , the process of generating the Pairkey using the AES128-CBC encryption algorithm may be as follows:
[0087] 1. Generate plaintext block A0 and plaintext block A1 based on the manufacturer identification of the UWB chip 103 .
[0088] Among them, the data length of the manufacturer identification of the UWB chip 103 can be 8 bytes. The data length of plaintext block A0 and plaintext block A1 can both be 16 bytes. Plaintext block A0 can be "manufacturer identification ‖ bit-inverted manufacturer identification", where the "‖" symbol represents data splicing. Plaintext block A1 can be "manufacturer identification ‖ filling value 1 ‖ filling value 2 ‖ the first 4 bytes of manufacturer identification data ‖ filling value 3 ‖ filling value 4". Among them, the data length of each filling value is 1 byte, for example, filling value 1 can be "F2", filling value 2 can be "02", filling value 3 can be "2F", and filling value 4 can be "02".
[0089] 2. Perform an XOR operation on the initialization vector (IV) and the plaintext block A0 to obtain input data 1.
[0090] The data length of the initial vector may be 16 bytes.
[0091] 3. Input data 1 and Rootkey into the AES encryptor for encryption operation to obtain ciphertext block C0.
[0092] 4. Perform an XOR operation on the ciphertext block C0 and the plaintext block A1 to obtain input data 2.
[0093] 5. Input data 2 and Rootkey into the AES encryptor for encryption to obtain ciphertext block C1.
[0094] 6. Concatenate ciphertext block C0 and ciphertext block C1 to obtain the pairing key.
[0095] For example, the ciphertext block C1 may be concatenated onto the end of the ciphertext block C0.
[0096] S603 . The encryption machine 400 generates an ultra-wideband transfer key (UWB transferkey) based on the pairkey and the chip identification of the UWB chip 103 .
[0097] For example, as shown in FIG7B , based on the Rootkey and the manufacturer identifier of the UWB chip 103 , the process of generating the UWB transferkey through the AES128-CBC encryption algorithm may be as follows:
[0098] 1. Generate plaintext block B0 and plaintext block B1 based on the chip identifier (EUI) of the UWB chip 103.
[0099] Among them, the data length of the manufacturer identification of the UWB chip 103 can be 8 bytes. The data length of plaintext block B0 and plaintext block B1 can both be 16 bytes. Plaintext block B0 can be "EUI ‖ bit-inverted EUI". Among them, the "‖" symbol represents the splicing of data. Plaintext block A1 can be "EUI ‖ filling value 5 ‖ filling value 6 ‖ the first 4 bytes of manufacturer identification data ‖ filling value 7 ‖ filling value 8". Among them, the data length of each filling value is 1 byte, for example, filling value 5 can be "F1", filling value 2 can be "01, filling value 3 can be "1F", and filling value 4 can be "01".
[0100] 2. Perform an XOR operation on the initialization vector (IV) and the plaintext block B0 to obtain input data 3.
[0101] 3. Input data 3 and Pairkey into the AES encryptor for encryption operation to obtain ciphertext block D0.
[0102] 4. Perform an XOR operation on the ciphertext block D0 and the plaintext block B1 to obtain input data 4.
[0103] 5. Input data 4 and Pairkey into the AES encryptor for encryption to obtain ciphertext block D1.
[0104] 6. Concatenate the ciphertext block D0 and the ciphertext block D1 to obtain the ultra-wideband transfer key (UWB transferkey).
[0105] For example, the ciphertext block D1 may be concatenated onto the end of the ciphertext block D0.
[0106] S604. The encryption engine 400 imports the ultra-wideband transmission key into the UWB chip 103.
[0107] The secure UWB service 1031 can manage and store the UWB transmission key imported into the UWB chip 103 by the encryption engine 400 .
[0108] S605 . The ultra-wideband protocol stack and kernel 1013 may obtain the manufacturer identifier and chip identifier of the UWB chip 103 from the UWB chip 103 .
[0109] After the electronic device 100 leaves the factory, when the ultra-wideband protocol stack and the kernel 1013 are running in the central processing unit 101 , the manufacturer identification and the chip identification of the UWB chip 103 can be obtained from the UWB chip 103 .
[0110] S606 . The UWB protocol stack and kernel 1013 may send the manufacturer identifier and chip identifier (EUI) of the UWB chip 103 to the UWB service 1012 .
[0111] S607 . The ultra-wideband service 1012 may send the manufacturer identifier and chip identifier (EUI) of the UWB chip 103 to the car key application 1011 .
[0112] S608. The car key application 1011 sends a first request to the server 300. The first request carries the manufacturer identifier and chip identifier of the UWB chip.
[0113] The first request is used to request the server 300 to generate a UWB transfer key.
[0114] S609 . The server 300 may generate a pairkey based on the root key (Rootkey) and the manufacturer identifier of the UWB chip 103 .
[0115] Among them, a root key (Rootkey) can be stored on the server 300. The root key stored on the server 300 is the same as the root key stored in the encryption machine 400. The server 300 generates a pairkey based on the root key and the manufacturer identification of the UWB chip 103. The process is the same as the process of the encryption machine 400 generating a pairkey. For specific information about the process of the server 300 generating a pairkey, please refer to the process of the encryption machine 400 generating a pairkey in the aforementioned step S602.
[0116] S610 . The server 300 generates an ultra-wideband transfer key (UWB transferkey) based on the pairkey and the chip identification of the UWB chip 103 .
[0117] The process of generating the UWB transmission key by the server 300 is the same as the process of generating the UWB transmission key by the encryption engine 400. For details, the process of generating the UWB transmission key by the server 300 can refer to the process of generating the UWB transmission key by the encryption engine 400 in step S603, which will not be repeated here.
[0118] S611 . The server 300 sends the ultra-wideband transmission key to the car key application 1011 .
[0119] Before the server 300 sends the ultra-wideband transmission key to the car key application 1011 , it may establish a secure transmission channel with the car key application 1011 , thereby ensuring the security of data transmission between the server 300 and the car key application 1011 .
[0120] For example, the server 300 and the car key application 1011 can first verify each other's digital certificates. After the mutual verification of each other's digital certificates is successful, the server 300 can obtain the public key (PK.application) of the car key application 1011. The car key application 1011 can obtain the public key (PK.server) of the server 300. The server 300 can generate a symmetric key (SYK) based on the server 300's private key (SK.server) and the car key application 1011's public key (PK.application). The car key application 1011 can also generate the same symmetric key (SYK) based on the server 300's public key (PK.server) and the car key application 1011's private key (SK.application). The car key application 1011's public key (PK.application) and the car key application 1011's private key (SK.application) form an asymmetric key pair, and the server 300's public key (PK.server) and the server 300's private key (SK.server) form an asymmetric key pair. The server 300 can encrypt the UWB transmission key using a symmetric key (SYK) and send the encrypted UWB transmission key to the car key application 1011. The car key application 1011 can decrypt the UWB transmission key from the encrypted UWB transmission key using the symmetric key (SYK). The above examples are merely for explaining this application and should not be construed as limiting. In the embodiments of this application, the secure transmission channel between the server 300 and the car key application 1011 can adopt the SCP03 security specification or the SCP11a security specification, etc., which are not limited here.
[0121] S612 . The car key application 1011 sends the ultra-wideband transmission key to the security service 1014 .
[0122] S613 . The security service 1014 sends the UWB transmission key to the secure UWB management application 1022 of the security chip 102 through the TEE.
[0123] The secure UWB management application 1022 may manage and store UWB transmission keys.
[0124] After receiving the UWB transmission key from the server 300, the car key application 1011 can first establish a secure transmission channel with the security chip 102 through the security service 1014 and the TEE. The car key application 1011 can then send the UWB transmission key to the security chip 102 over the secure transmission channel established with the security service 1014 and the TEE. This ensures the security of the UWB transmission key from the car key application 1011 to the security chip 102.
[0125] S614. The digital key application 1021 may generate a target URSK.
[0126] The car key application 1011 can obtain the car key secret key when activating the vehicle's digital car key. The car key application 1011 can store the car key secret key in the security chip 102. The digital key application 1021 can derive a car key session key (SessionKey) based on the car key secret key. The digital key application 1021 can generate one or more URSKs based on the car key session key, where one or more URSKs include a target URSK.
[0127] S615. The secure ultra-wideband management application 1022 encrypts the target URSK using the ultra-wideband transmission key to obtain encrypted data A.
[0128] The secure UWB management application 1022 may obtain the target URSK from the digital key application 1021. The secure UWB management application 1022 may then encrypt the target URSK into encrypted data A using the UWB transmission key.
[0129] S616. The secure ultra-wideband management application 1022 sends the encrypted data A to the security service 1014 through TEE.
[0130] S617 . The security service 1014 may send the encrypted data A to the ultra-wideband service 1012 .
[0131] S618 . The UWB service 1012 sends the encrypted data A to the UWB protocol stack and kernel 1013 .
[0132] S619 . The UWB protocol stack and core 1013 sends the encrypted data A to the secure UWB service 1031 in the UWB chip 103 .
[0133] S620. The secure UWB service 1031 can decrypt the target URSK from the encrypted data A using the UWB transmission key.
[0134] For the specific content of the URSK transmission process shown in the above steps S615 to S620, please refer to the URSK transmission process schematic diagram shown in Figure 7C.
[0135] As shown in FIG7C , the URSK transmission process may include the following steps:
[0136] 1. The UWB chip 103 sends a selection command to the security chip 102 through the central processor 101, wherein the selection command carries a secure ultra-wideband management application identifier (SUM AID).
[0137] The security chip 102 may run multiple applications (applets), including the secure ultra-wideband management application 1022. The selection command is used to select the secure ultra-wideband management application 1022 in the security chip 102 to communicate with the UWB chip 103.
[0138] In an embodiment of the present application, the UWB chip 103 can perform signaling interaction with the security chip 102 through the ultra-wideband protocol stack and kernel 1013, ultra-wideband service 1012, security service 1014 and TEE in the central processor 101 in sequence.
[0139] 2. The secure UWB management application 1022 sends a select response (Select Response) to the UWB chip 103 through the central processing unit 101.
[0140] The selection response is used to instruct the security chip 102 to enable the secure ultra-wideband management application 1022 to communicate with the UWB chip 103 .
[0141] 3. The UWB chip 103 sends a random number acquisition (Get Challenge) command to the secure ultra-wideband management application 1022 through the central processor 101 .
[0142] The random number acquisition command is used to request the secure ultra-wideband management application 1022 to return a random number to the UWB chip 103 .
[0143] 4. The secure ultra-wideband management application 1022 sends a random number 1 to the UWB chip 103 via the central processor 101 .
[0144] 5. The UWB chip 103 encrypts the random number 1 using the UWB transfer key to obtain the authentication ciphertext.
[0145] 6. The UWB chip 103 sends the authentication ciphertext to the secure ultra-wideband management application 1022 through the central processor 101.
[0146] 7. The secure UWB management application 1022 uses the UWB transfer key to decrypt the random number 2 from the authentication ciphertext.
[0147] 8. The secure ultra-wideband management application 1022 may determine whether the random number 2 is the same as the random number 1.
[0148] 9. If the random number 2 is the same as the random number 1, the security chip 102 may send a response 1 to the UWB chip 103 via the central processor 101. The response 1 is used to indicate that the random number verification is successful.
[0149] If random number 2 is different from random number 1, the security chip 102 returns a response 2 to the UWB chip 103 via the central processor 101, wherein the response 2 is used to indicate that the random number verification has failed. After receiving the response 2, the security chip 102 stops performing subsequent steps.
[0150] 10. After receiving the response 1, the UWB chip 103 sends a URSK acquisition command to the secure ultra-wideband management application 1022 through the central processor 101. The URSK acquisition command carries a session identifier (Session ID) A.
[0151] 11. The secure ultra-wideband management application 1022 determines a target URSK from one or more URSKs based on the session identifier A. Different URSKs correspond to different session identifiers.
[0152] The digital key application 1021 in the security chip 102 can generate one or more URSKs based on the vehicle key session key (SessionKey). Different URSKs correspond to different session identifiers. After obtaining the session identifier A, the secure ultra-wideband management application 1022 can obtain the target URSK corresponding to the session identifier A from the one or more URSKs managed and stored by the digital key application 1021.
[0153] 12. The secure UWB management application 1022 encrypts the target URSK using the UWB transmission key to obtain encrypted data A.
[0154] 13. The secure UWB management application 1022 sends the encrypted data A to the UWB chip 103 via the central processor 101.
[0155] 14. The UWB chip 103 uses the ultra-wideband transmission key to decrypt the target URSK from the encrypted data A.
[0156] After decrypting the target URSK through the secure ultra-wideband management application 1022, the UWB chip 103 can derive a ranging process key based on the target URSK. The UWB chip 103 can use the ranging process key to perform UWB ranging communication with the UWB chip 206 on the vehicle 200, thereby ensuring security during the UWB ranging process.
[0157] In an embodiment of the present application, the encrypted data A can be called the first encrypted data, the random number 1 can be called the first random number, the random number 2 can be called the second random number, the response 1 can be called the first response, and the session identifier A can be called the first session identifier.
[0158] The following describes a UWB key transmission method provided in an embodiment of the present application.
[0159] In an embodiment of the present application, a UWB key transmission method is provided, in which the UWB chip of the electronic device 100 can generate a public key PK1 and a private key SK1, wherein the public key PK1 and the private key SK1 are a pair of public and private keys. The UWB chip sends the public key PK1 to the car key application running in the central processor of the electronic device 100. The car key application can request the server to generate an ultra-wideband transmission key (UWB transferkey). After obtaining the UWB transferkey sent by the server, the car key application can encrypt the UWB transferkey into encrypted data B using the public key PK1 and send the encrypted data B to the UWB chip. After receiving the encrypted data B, the UWB chip can decrypt the UWB transferkey from the encrypted data B using the private key SK1. After obtaining the UWB transferkey sent by the server, the car key application can also store the UWB transferkey in the security chip through the TEE. The security chip can use the UWB transferkey to encrypt the URSK required for the UWB chip to measure the distance, and obtain encrypted data A. The security chip transmits encrypted data A to the UWB chip via the TEE and REE in the central processing unit. The UWB chip can decrypt the URSK from the encrypted data A using the UWB transferkey issued by the car key application. This eliminates the need to pre-fabricate the UWB transferkey in the UWB chip before the electronic device 100 leaves the factory. While ensuring the secure transmission of the URSK from the security chip to the UWB chip, it also decouples the UWB chip from the security chip, eliminating the need for a direct connection between the UWB chip and the security chip 102. The security chip and the UWB chip can be flexibly combined without a rigid binding, reducing the cost of producing the electronic device 100 on the production line.
[0160] FIG8 shows a schematic diagram of a UWB key transmission method provided in another embodiment of the present application.
[0161] As shown in Figure 8, the UWB key transmission method can be applied to a UWB key transmission system. The UWB key transmission system may include an electronic device 100 and a server 300. The electronic device 100 may include a central processing unit (CPU) 101, a security chip (SE chip) 102, and a UWB chip 103. There is no connection between the security chip 102 and the UWB chip 103. The security chip 102 can be connected to the CPU 101, and the UWB chip 103 can be connected to the CPU 101. The CPU 101 can run two application environments: REE and TEE. The REE can run a car key application 1011, an ultra-wideband service (UWB Service) 1012, an ultra-wideband protocol stack and kernel (UWB stack and kernel) 1013, and a security service (Secure Service) 1014. The security chip 102 may include a digital key application (DK Applet) 1021 and a secure ultra-wideband management application (Secure UWB Manage Applet) 1022. The digital key application 1021 may be any of the CCC DK Applet, ICCE DK Applet, or FiRa Applet. The digital key application 1021 may call the secure UWB management application 1022 via an internal API. The UWB chip 103 may include a secure UWB service 1031.
[0162] In a possible implementation, when the security chip 102 is connected to the UWB chip 103 , the UWB key transmission method provided in the embodiment of the present application may also be used.
[0163] The UWB key transmission method may include the following steps:
[0164] S801. The secure ultra-wideband service 1031 may generate a pair of public and private keys, wherein the pair of public and private keys generated by the secure ultra-wideband service 1031 includes a public key PK1 and a private key SK1.
[0165] S802 . The secure UWB service 1031 sends the public key PK1 to the UWB protocol stack and kernel 1013 .
[0166] S803 . The ultra-wideband protocol stack and kernel 1013 sends the public key PK1 to the ultra-wideband service 1012 .
[0167] S804 . The ultra-wideband service 1012 sends the public key PK1 to the car key application 1011 .
[0168] The car key application 1011 may store the public key PK1.
[0169] S805 . The car key application 1011 sends a first request to the server 300 . The first request carries the manufacturer identifier and chip identifier (EUI) of the UWB chip 103 .
[0170] The first request is used to request the server 300 to generate a UWB transferkey. After the UWB chip 103 is produced, the manufacturer identifier and chip identifier of the UWB chip 103 may be stored in the storage medium inside the UWB chip 103. After the electronic device 100 leaves the factory, the ultra-wideband protocol stack and kernel 1013 can obtain the manufacturer identifier and chip identifier of the UWB chip 103 from the UWB chip 103 when running in the central processor 101. The ultra-wideband protocol stack and kernel 1013 can send the manufacturer identifier and chip identifier (EUI) of the UWB chip 103 to the ultra-wideband service 1012. The ultra-wideband service 1012 can send the manufacturer identifier and chip identifier (EUI) of the UWB chip 103 to the car key application 1011.
[0171] S806 . The server 300 generates a pair key based on the root key and the manufacturer identifier of the UWB chip 103 .
[0172] Among them, a root key (Rootkey) can be stored on the server 300. For the specific process of generating the Pairkey by the server 300, reference can be made to the process of generating the Pairkey in the embodiment shown in Figure 7A above, which will not be repeated here.
[0173] S807 . The server 300 may generate an ultra-wideband transfer key (UWB transferkey) based on the pairkey and the chip identification of the UWB chip 103 .
[0174] Specifically, the process of generating the pairkey by the server 300 may refer to the process of generating the ultra-wideband transmission key in the embodiment shown in FIG. 7B , which will not be described in detail here.
[0175] S808 . The server 300 may send the ultra-wideband transmission key to the car key application 1011 .
[0176] For the specific content, please refer to step S611 in the embodiment shown in FIG6 , which will not be described in detail here.
[0177] S809. The car key application 1011 can use the public key PK1 to encrypt the ultra-wideband transmission key to obtain encrypted data B.
[0178] S810 . The car key application 1011 sends encrypted data B to the ultra-wideband service (UWB Service) 1012 .
[0179] S811. The ultra-wideband service 1012 sends the encrypted data B to the ultra-wideband protocol stack and kernel 1013.
[0180] S812 . The UWB protocol stack and kernel 1013 sends the encrypted data B to the secure UWB service 1031 .
[0181] S813. The secure ultra-wideband service 1031 can use the private key SK1 to decrypt the encrypted data B to obtain the ultra-wideband transmission key.
[0182] S814 . The car key application 1011 sends the ultra-wideband transmission key to the secure service 1014 .
[0183] S815. The secure service 1014 sends the UWB transmission key to the secure UWB management application 1022 through the TEE.
[0184] After receiving the UWB transmission key from the server 300, the car key application 1011 can first establish a secure transmission channel with the security chip 102 through the security service 1014 and the TEE. The car key application 1011 can then send the UWB transmission key to the security chip 102 over the secure transmission channel established with the security service 1014 and the TEE. This ensures the security of the UWB transmission key from the car key application 1011 to the security chip 102.
[0185] S816. The digital key application 1021 may generate a target URSK.
[0186] The car key application 1011 can obtain the car key secret key when activating the vehicle's digital car key. The car key application 1011 can store the car key secret key in the security chip 102. The digital key application 1021 can derive a car key session key (SessionKey) based on the car key secret key. The digital key application 1021 can generate one or more URSKs based on the car key session key, where one or more URSKs include a target URSK.
[0187] S817. The secure ultra-wideband management application 1022 encrypts URSK using the ultra-wideband transmission key to obtain encrypted data A.
[0188] The secure UWB management application 1022 may obtain the target URSK from the digital key application 1021. The secure UWB management application 1022 may then encrypt the target URSK into encrypted data A using the UWB transmission key.
[0189] S818. The secure ultra-wideband management application 1022 sends the encrypted data A to the security service 1014 through the TEE.
[0190] S819. The security service 1014 sends the encrypted data A to the ultra-wideband service 1012.
[0191] S820 . The UWB service 1012 sends the encrypted data A to the UWB protocol stack and kernel 1013 .
[0192] S821 . The UWB protocol stack and core 1013 sends encrypted data A to the secure UWB service 1031 in the UWB chip 103 .
[0193] S822. The secure ultra-wideband service 1031 can decrypt the target URSK from the encrypted data A using the ultra-wideband transmission key.
[0194] Among them, the specific content of the URSK transmission process shown in the above steps S817 to S822 can refer to the URSK transmission process schematic diagram shown in Figure 7C above.
[0195] The target URSK can be used for ranging by the UWB chip 103. After decrypting the target URSK via the secure ultra-wideband management application 1022, the UWB chip 103 can derive a ranging process key based on the target URSK. The UWB chip 103 can use the ranging process key to perform UWB ranging communication with the UWB chip 206 on the vehicle 200, thereby ensuring security during the UWB ranging process.
[0196] In an embodiment of the present application, the encrypted data A may be referred to as the first encrypted data, the encrypted data B may be referred to as the second encrypted data, the public key PK1 may be referred to as the first public key, and the private key SK1 may be referred to as the first private key.
[0197] The following describes a UWB key transmission method provided in another embodiment of the present application.
[0198] In an embodiment of the present application, a UWB key transmission method is provided. A car key application running in the central processor of an electronic device 100 can generate a public key PK2 and a private key SK2, wherein the public key PK2 and the private key SK1 form a pair of public and private keys. The car key application can send the public key PK2 to the UWB chip of the electronic device 100. A UWB transferkey can be temporarily generated in the UWB chip. The UWB chip can encrypt the UWB transferkey into encrypted data C using the public key PK2 and send the encrypted data C to the car key application running in the central processor. After receiving the encrypted data C, the car key application can decrypt the UWB transferkey from the encrypted data C using the private key SK2. After decrypting the UWB transferkey, the car key application can store the UWB transferkey in the security chip through the TEE. The security chip can use the UWB transferkey to encrypt the URSK required for the UWB chip to measure distance, thereby obtaining encrypted data A. The security chip can transfer the encrypted data A to the UWB chip through the TEE and REE in the central processor. The UWB chip can decrypt URSK from encrypted data A using the UWB transferkey issued by the car key application. This eliminates the need to pre-fabricate the UWB transferkey in the UWB chip before the electronic device 100 leaves the factory, nor does it require the car key application to request a server to generate a UWB transferkey. While ensuring the secure transmission of URSK from the security chip to the UWB chip, the UWB chip and the security chip are decoupled, eliminating the need for a direct connection between the UWB chip and the security chip 102. The security chip and the UWB chip can be flexibly combined without a rigid binding, reducing the cost of producing the electronic device 100 on the production line and the cost of deploying servers.
[0199] FIG9 shows a schematic diagram of a UWB key transmission method provided in an embodiment of the present application.
[0200] As shown in Figure 9, the UWB key transmission method can be applied to an electronic device 100. The electronic device 100 may include a central processing unit (CPU) 101, a security chip (SE Chip) 102, and a UWB chip 103. There is no connection between the security chip 102 and the UWB chip 103. The security chip 102 can be connected to the CPU 101, and the UWB chip 103 can be connected to the CPU 101. The CPU 101 can run two application environments: REE and TEE. The REE can run a car key application 1011, an ultra-wideband service (UWB Service) 1012, an ultra-wideband protocol stack and kernel (UWB stack and kernel) 1013, and a security service (Secure Service) 1014. The security chip 102 may include a digital key application (DK Applet) 1021 and a secure ultra-wideband management application (Secure UWB Manage Applet) 1022. The digital key application 1021 may be any of the CCC DK Applet, ICCE DK Applet, or FiRa Applet. The digital key application 1021 may call the secure UWB management application 1022 via an internal API. The UWB chip 103 may include a secure UWB service 1031.
[0201] In a possible implementation, when the security chip 102 is connected to the UWB chip 103 , the UWB key transmission method provided in the embodiment of the present application may also be used.
[0202] The UWB key transmission method may include the following steps:
[0203] S901. The car key application 1011 may generate a pair of public and private keys, wherein the pair of public and private keys generated by the car key application 1011 includes a public key PK2 and a private key SK2.
[0204] S902 . The car key application 1011 sends the public key PK2 to the ultra-wideband service 1012 .
[0205] S903 . The UWB service 1012 sends the public key PK2 to the UWB protocol stack and kernel 1013 .
[0206] S904 . The UWB protocol stack and kernel 1013 sends the public key PK2 to the secure UWB service 1031 .
[0207] S905. The secure UWB service 1031 generates an UWB transfer key.
[0208] The secure UWB service 1031 may randomly generate a temporary UWB transfer key (UWB transferkey). After decrypting the target URSK using the temporary UWB transferkey, the temporary UWB transferkey may be destroyed.
[0209] In one possible implementation, the secure ultra-wideband service 1031 may generate a UWB transferkey based on the root key, the manufacturer identifier of the UWB chip 103, and the chip identifier of the UWB chip 103. Specifically, the secure ultra-wideband service 1031 may first generate a pairkey based on the root key and the manufacturer identifier of the UWB chip 103. Then, the secure ultra-wideband service 1031 may generate a UWB transferkey based on the pairkey and the chip identifier of the UWB chip 103. For details on the generation process of the pairkey and the UWB transferkey, please refer to the embodiments shown in Figures 7A and 7B above and will not be further described here.
[0210] S906. The secure ultra-wideband service 1031 uses the public key PK2 to encrypt the ultra-wideband transmission key to obtain encrypted data C.
[0211] S907 . The secure UWB service 1031 sends the encrypted data C to the UWB protocol stack and kernel 1013 .
[0212] S908 . The UWB protocol stack and kernel 1013 sends the encrypted data C to the UWB service 1012 .
[0213] S909 . The ultra-wideband service 1012 sends the encrypted data C to the car key application 1011 .
[0214] S910. The car key application 1011 uses the private key SK2 to decrypt the encrypted data C to obtain the ultra-wideband transmission key.
[0215] S911 . The car key application 1011 sends the ultra-wideband transmission key to the secure service 1014 .
[0216] S912. The security service 1014 sends the UWB transmission key to the secure UWB management application 1022 through the TEE.
[0217] After decrypting the UWB transmission key, the car key application 1011 can first establish a secure transmission channel with the security chip 102 through the security service 1014 and TEE. The car key application 1011 can then send the UWB transmission key to the security chip 102 over the secure transmission channel established with the security service 1014 and TEE. This ensures the security of the UWB transmission key transmitted from the car key application 1011 to the security chip 102.
[0218] S913. The digital key application 1021 generates a target ultra-wideband root session key (URSK).
[0219] The car key application 1011 can obtain the car key secret key when activating the vehicle's digital car key. The car key application 1011 can store the car key secret key in the security chip 102. The digital key application 1021 can derive a car key session key (SessionKey) based on the car key secret key. The digital key application 1021 can generate one or more URSKs based on the car key session key, where one or more URSKs include a target URSK.
[0220] S914. The secure ultra-wideband management application 1022 encrypts URSK using the ultra-wideband transmission key to obtain encrypted data A.
[0221] The secure UWB management application 1022 may obtain the target URSK from the digital key application 1021. The secure UWB management application 1022 may then encrypt the target URSK into encrypted data A using the UWB transmission key.
[0222] S915. The secure ultra-wideband management application 1022 sends the encrypted data A to the security service 1014 through the TEE.
[0223] S916. The security service 1014 sends the encrypted data A to the ultra-wideband service 1012.
[0224] S917 . The UWB service 1012 sends the encrypted data A to the UWB protocol stack and kernel 1013 .
[0225] S918 . The UWB protocol stack and core 1013 sends the encrypted data A to the secure UWB service 1031 in the UWB chip 103 .
[0226] S919. The secure ultra-wideband service 1031 can use the ultra-wideband transmission key to decrypt the target URSK from the encrypted data A.
[0227] For the specific content of the URSK transmission process shown in the above steps S914 to S919, reference can be made to the URSK transmission process schematic diagram shown in FIG. 7C .
[0228] The target URSK is used by the UWB chip 103 for ranging. After decrypting the target URSK via the secure ultra-wideband management application 1022, the UWB chip 103 can derive a ranging process key based on the target URSK. The UWB chip 103 can use the ranging process key to perform UWB ranging communication with the UWB chip 206 on the vehicle 200, thereby ensuring security during the UWB ranging process.
[0229] In an embodiment of the present application, encrypted data A can be called first encrypted data, encrypted data B can be called second encrypted data, encrypted data C can be called third encrypted data, public key PK2 can be called second public key, and private key SK2 can be called second private key.
[0230] The following describes a UWB key transmission method provided in another embodiment of the present application.
[0231] In some types of electronic devices 100, such as watches, bracelets and other types of devices, since the UWB chip on the electronic device 100 has no security capabilities, it can only serve as a transceiver for UWB communication and cannot generate UWB communication messages based on URSK. Therefore, a UWB key transmission method is provided in an embodiment of the present application, which can enable the TEE of the central processing unit to obtain the car key session key from the security chip of the electronic device 100. After obtaining the car key session key, the TEE can generate URSK based on the car key session key. Then, the UWB CA in the REE of the central processing unit can obtain the URSK from the TEE and send the URSK to the microcontroller. When the microcontroller performs ranging through the UWB chip, it can generate a UWB communication message based on URSK, and then use the signal transceiver capability of the UWB chip to send the UWB communication message, or it can parse the UWB communication message received by the UWB chip based on URSK, thereby completing UWB ranging. In this way, there is no need to pre-fabricate the UWB transferkey in the UWB chip before the electronic device 100 leaves the factory, nor is there a need for the car key application to request the server to generate the UWB transferkey. While transmitting the URSK to the UWB chip, the UWB chip and the security chip can be decoupled, so that there is no need for a direct connection between the UWB chip and the security chip 102. The security chip and the UWB chip can be flexibly combined without strong binding, thereby reducing the cost of producing the electronic device 100 on the production line and the server deployment cost.
[0232] FIG10 shows a schematic diagram of a UWB key transmission method provided in an embodiment of the present application.
[0233] As shown in FIG10 , the UWB key transmission method can be applied to an electronic device 100 . The electronic device 100 may include a central processing unit (CPU) 101 , a security chip (SE Chip) 102 , a microcontroller unit (MCU) 104 , and a UWB chip 103 . The security chip 102 and the UWB chip 103 are not connected in between. The security chip 102 may be connected to the CPU 101 , the UWB chip 103 may be connected to the CPU 101 , and the microcontroller 104 may be connected to the CPU 101 and the UWB chip 103 . The CPU 101 may run two application environments: REE and TEE . The REE may run a car key application 1011 , an ultra-wideband service (UWB Service) 1012 , an ultra-wideband protocol stack and kernel (UWB stack and kernel) 1013 , and a secure service (Secure Service) 1014 . The ultra-wideband service 1012 may include an ultra-wideband client application (UWB CA) 1016 . The TEE may run an ultra-wideband trusted application (UWB TEE application, UWB TA) 1015 . The microcontroller 104 may run an ultra-wideband service (UWB Service) 1041 , which may include a secure ultra-wideband service (Secure UWB Service) 1042 .
[0234] The security chip 102 may include a digital key application (DK Applet) 1021 and a secure UWB management application (Secure UWB Manage Applet) 1022. The digital key application 1021 may be any of the CCC DK Applet, ICCE DK Applet, or FiRa Applet. The digital key application 1021 can call the secure UWB management application 1022 via an internal API. The UWB chip 103 lacks security capabilities and can only function as a UWB transceiver. It cannot generate UWB communication messages based on the URSK.
[0235] In a possible implementation, when the security chip 102 is connected to the UWB chip 103 , the UWB key transmission method provided in the embodiment of the present application may also be used.
[0236] The UWB key transmission method may include the following steps:
[0237] S1001 . The car key application 1011 sends the car key secret key to the security service 1014 .
[0238] The car key application 1011 can obtain the car key secret key when activating the vehicle's digital car key and can store the car key secret key in the security chip 102 .
[0239] S1002. The security service 1014 sends the vehicle key secret to the security chip 102 via TEE.
[0240] Before sending the car key secret key to the security chip 102 via the security service 1014 and TEE, the car key application 1011 can establish a secure transmission channel with the security chip 102 via the security service 1014 and TEE. In this embodiment of the present application, the security specification used to establish the secure transmission channel can adopt the SCP03 security specification or the SCP11a security specification, etc., which is not limited here.
[0241] Among them, the digital key application 1021 in the security service 1014 can save the car key secret key.
[0242] S1003. The digital key application 1021 may derive a vehicle key session key based on the vehicle key key.
[0243] S1004 . The UWB trusted application 1015 obtains the vehicle key session key from the digital key application 1021 .
[0244] S1005. The UWB trusted application 1015 generates a target URSK based on the vehicle key session key.
[0245] S1006 . The UWB trusted application 1015 sends the target URSK to the security service 1014 .
[0246] S1007 . The security service 1014 sends the target URSK to the ultra-wideband client application 1016 .
[0247] The UWB trusted application 1015 may generate one or more URSKs using the vehicle key session key, wherein the one or more URSKs include a target URSK. Different URSKs correspond to different session identifiers (Session IDs).
[0248] Specifically, the ultra-wideband service 1041 in the microcontroller 104 can send a URSK acquisition request 1 to the ultra-wideband client application 1016 via the ultra-wideband protocol stack and kernel 1013. The URSK acquisition request 1 carries a session identifier A. The ultra-wideband client application 1016 can send a URSK acquisition request 2 to the ultra-wideband trusted application 1015 via the security service 1014. The URSK acquisition request 2 carries the session identifier A. The URSK acquisition request 2 is used to request a URSK from the ultra-wideband trusted application 1015. After receiving the URSK acquisition request 2, the ultra-wideband trusted application 1015 can determine a target URSK from one or more URSKs based on the session identifier A. The ultra-wideband trusted application 1015 can send the target URSK to the ultra-wideband client application 1016 via the security service 1014.
[0249] In one possible implementation, the ultra-wideband client application 1016 stores a requestor whitelist, where the requestor whitelist includes the identifiers of one or more modules authorized to request a URSK, and the identifiers of the one or more modules authorized to request a URSK include the identifier of the ultra-wideband service 1041. The ultra-wideband client application 1016 receives a URSK request from a target requestor, which carries the identifier of the target requestor. The ultra-wideband client application 1016 determines whether the requestor whitelist includes the identifier of the target requestor. If the requestor whitelist does include the identifier of the target requestor, the ultra-wideband client application 1016 may request a URSK from the ultra-wideband trusted application 1015 through the security service 1014. If the requestor whitelist does include the identifier of the target requestor, the ultra-wideband client application 1016 does not request a URSK from the ultra-wideband trusted application 1015. Alternatively, if the requestor whitelist does not include the identifier of the target requestor, the ultra-wideband client application 1016 may return a rejection response to the target requestor, indicating that the target requestor does not have the identifier to request a URSK.
[0250] Because the request whitelist includes the identifier of ultra-wideband service 1041, ultra-wideband service 1041 has permission to request the URSK. URSK acquisition request 1 also carries the identifier of ultra-wideband service 1041. After receiving URSK acquisition request 1, ultra-wideband client application 1016 can obtain the identifier of ultra-wideband service 1041 from it. After determining that the requester whitelist includes the identifier of ultra-wideband service 1041, ultra-wideband client application 1016 can send URSK acquisition request 2 to ultra-wideband trusted application 1015 via security service 1014. After obtaining the target URSK returned by ultra-wideband trusted application 1015, ultra-wideband client application 1016 can send the target URSK to ultra-wideband service 1041 in microcontroller 104 via the ultra-wideband protocol stack and kernel 1013. This allows ultra-wideband client application 1016 to control the permission to request the URSK, preventing other unauthorized modules from obtaining the URSK.
[0251] In one possible implementation, the digital key application 1021 can generate one or more URSKs based on the vehicle key session key, wherein the one or more URSKs include a target URSK. Different URSKs correspond to different session identifiers (Session IDs). The ultra-wideband service 1041 in the microcontroller 104 can send a URSK acquisition request 1 to the ultra-wideband client application 1016 through the ultra-wideband protocol stack and the kernel 1013, wherein the URSK acquisition request 1 carries the session identifier A. The ultra-wideband client application 1016 can send a URSK acquisition request 2 to the ultra-wideband trusted application 1015 through the security service 1014, wherein the URSK acquisition request 2 carries the session identifier A. The URSK acquisition request 2 is used to request a URSK from the ultra-wideband trusted application 1015. After receiving the URSK acquisition request 2, the ultra-wideband trusted application 1015 can send a URSK acquisition command to the secure ultra-wideband management application 1022 in the security chip 102, wherein the URSK acquisition command carries the session identifier A. After receiving the URSK acquisition command, the secure UWB management application 1022 can determine the target URSK corresponding to session identifier A from one or more URSKs stored in the digital key application 1021 through an internal API based on the session identifier A. The secure UWB management application 1022 can return the target URSK to the UWB trusted application 1015. After obtaining the target URSK, the UWB trusted application 1015 can return the target URSK to the UWB client application 1016 through the security service 1014.
[0252] S1008 . The UWB client application 1016 sends the target URSK to the UWB protocol stack and kernel 1013 .
[0253] S1009 . The UWB protocol stack and core 1013 sends the target URSK to the microcontroller 104 .
[0254] S1010. The secure ultra-wideband service 1042 in the microcontroller 104 may store the target URSK.
[0255] S1011. The ultra-wideband service 1041 in the microcontroller 104 may generate a UWB communication message based on the target URSK.
[0256] The UWB service 1041 may derive a ranging process key based on the target URSK, and then generate ranging parameters (e.g., a scrambled timestamp sequence (STS)) based on the ranging process key. The UWB service 1041 may generate a UWB communication message based on the ranging parameters.
[0257] S1012 . The ultra-wideband service 1041 sends a UWB communication message to the ultra-wideband protocol stack and kernel 1043 .
[0258] S1013 . The ultra-wideband protocol stack and core 1043 may send a UWB communication message to the UWB chip 103 .
[0259] After receiving the UWB communication message, the UWB chip 103 may send the UWB communication message to the device under test (eg, the vehicle 200 ).
[0260] The UWB chip 103 can also receive UWB communication messages sent by the device under test, and send the received UWB communication messages to the ultra-wideband service 1041 in the microcontroller 104 for analysis, thereby completing UWB secure ranging.
[0261] The following describes the hardware structure of an electronic device provided in an embodiment of the present application.
[0262] FIG11 shows a schematic diagram of the hardware structure of the electronic device 100 .
[0263] The following embodiments are described in detail using electronic device 100 as an example. It should be understood that the electronic device 100 shown in FIG11 is merely an example, and that the electronic device 100 may have more or fewer components than those shown in FIG11 , may combine two or more components, or may have a different component configuration. The various components shown in FIG11 may be implemented in hardware, including one or more signal processing and / or application-specific integrated circuits, software, or a combination of hardware and software.
[0264] The electronic device 100 may include: a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display 194, and an embedded SIM (eSIM) module 195, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, an air pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.
[0265] It should be understood that the structure illustrated in the embodiments of the present invention does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0266] The processor 110 may include one or more processing units, for example, the processor 110 may include a central processing unit (CPU), which may also be called an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), a security chip (SE), etc. Different processing units may be independent devices or integrated into one or more processors.
[0267] The controller may be the nerve center and command center of the electronic device 100. The controller may generate an operation control signal according to the instruction operation code and the timing signal to complete the control of fetching and executing instructions.
[0268] Processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in processor 110 is a cache memory. This memory can store instructions or data that have just been used or are being recycled by processor 110. If processor 110 needs to use the same instruction or data again, it can directly access the memory. This avoids duplicate accesses, reduces processor 110 latency, and thus improves system efficiency.
[0269] In some embodiments, the processor 110 may include one or more interfaces. The interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface 130, among others.
[0270] The charging management module 140 is configured to receive charging input from a charger. The charger can be either a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 140 can receive charging input from the wired charger via the USB interface 130. In some wireless charging embodiments, the charging management module 140 can receive wireless charging input via the wireless charging coil of the electronic device 100. While charging the battery 142, the charging management module 140 can also provide power to the electronic device via the power management module 141.
[0271] The power management module 141 is used to connect the battery 142, the charging management module 140 and the processor 110. The power management module 141 receives input from the battery 142 and / or the charging management module 140, and provides power to the processor 110, the internal memory 121, the external memory, the display 194, the camera 193, and the wireless communication module 160. The power management module 141 can also be used to monitor parameters such as battery capacity, battery cycle count, and battery health status (leakage, impedance). In some other embodiments, the power management module 141 can also be set in the processor 110. In other embodiments, the power management module 141 and the charging management module 140 can also be set in the same device.
[0272] The wireless communication function of the electronic device 100 can be implemented through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor and the baseband processor.
[0273] Antenna 1 and Antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In other embodiments, the antennas can be used in conjunction with a tuning switch.
[0274] The mobile communication module 150 can provide solutions for wireless communications including 2G / 3G / 4G / 5G applied to the electronic device 100. The mobile communication module 150 may include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves from the antenna 1, and filter, amplify, and process the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves for radiation through the antenna 1. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the processor 110. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the same device as at least some of the modules of the processor 110.
[0275] The modem processor may include a modulator and a demodulator. The modulator is used to modulate the low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After being processed by the baseband processor, the low-frequency baseband signal is passed to the application processor. The application processor outputs a sound signal through an audio device (not limited to the speaker 170A, the receiver 170B, etc.) or displays an image or video through the display screen 194. In some embodiments, the modem processor may be an independent device. In other embodiments, the modem processor may be independent of the processor 110 and be set in the same device as the mobile communication module 150 or other functional modules.
[0276] The wireless communication module 160 can provide wireless communication solutions including ultra-wideband (UWB), wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR), etc., which are applied to the electronic device 100. The wireless communication module 160 can be one or more devices that integrate at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via the antenna 2, frequency modulates and filters the electromagnetic wave signals, and sends the processed signals to the processor 110. The wireless communication module 160 can also receive the signal to be sent from the processor 110, frequency modulate it, amplify it, and convert it into electromagnetic waves for radiation through the antenna 2.
[0277] In some embodiments, the antenna 1 of the electronic device 100 is coupled to the mobile communication module 150, and the antenna 2 is coupled to the wireless communication module 160, so that the electronic device 100 can communicate with a network and other devices through wireless communication technologies. The wireless communication technologies may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology. The GNSS may include a global positioning system (GPS), a global navigation satellite system (GLONASS), a Beidou navigation satellite system (BDS), a quasi-zenith satellite system (QZSS) and / or a satellite based augmentation system (SBAS).
[0278] Electronic device 100 implements display functionality through a GPU, display screen 194, and an application processor. A GPU is a microprocessor for image processing that connects display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. Processor 110 may include one or more GPUs that execute program instructions to generate or modify display information.
[0279] The display screen 194 is used to display images, videos, etc. The display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD). The display screen panel can also be made of an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode or an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a mini-LED, a micro-LED, a micro-OLED, a quantum dot light-emitting diode (QLED), etc. In some embodiments, the electronic device 100 may include one or N display screens 194, where N is a positive integer greater than one.
[0280] The electronic device 100 can implement a shooting function through an ISP, a camera 193, a video codec, a GPU, a display screen 194, and an application processor.
[0281] The ISP processes data fed back by camera 193. For example, when taking a photo, the shutter is opened, and light is transmitted through the lens to the camera's photosensitive element. The light signal is converted into an electrical signal, which is then passed to the ISP for processing and converted into a visible image. The ISP can also perform algorithmic optimization on image noise, brightness, and other factors. It can also optimize parameters such as exposure and color temperature of the captured scene. In some embodiments, the ISP can be located within camera 193.
[0282] The camera 193 is used to capture still images or videos. The object generates an optical image through the lens and projects it onto the photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, and then passes the electrical signal to the ISP for conversion into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard RGB, YUV or other format. In some embodiments, the electronic device 100 may include 1 or N cameras 193, where N is a positive integer greater than 1.
[0283] The digital signal processor is used to process digital signals. In addition to processing digital image signals, it can also process other digital signals. For example, when the electronic device 100 selects a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy.
[0284] Video codecs are used to compress or decompress digital video. Electronic device 100 may support one or more video codecs. This allows electronic device 100 to play or record videos in various encoding formats, such as Moving Picture Experts Group (MPEG) 1, MPEG2, MPEG3, and MPEG4.
[0285] The NPU is a neural network (NN) computing processor. Drawing on the structure of biological neural networks, such as the transmission patterns between neurons in the human brain, it rapidly processes input information and can continuously self-learn. The NPU can enable intelligent cognitive applications in electronic device 100, such as image recognition, face recognition, speech recognition, and text comprehension.
[0286] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 via the external memory interface 120 to implement data storage functions. For example, files such as music and videos can be stored on the external memory card.
[0287] The internal memory 121 can be used to store computer executable program codes, which include instructions. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 121. The internal memory 121 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc. The data storage area can store data created during the use of the electronic device 100 (such as audio data, a phone book, etc.), etc. In addition, the internal memory 121 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.
[0288] The electronic device 100 can implement audio functions through the audio module 170, speaker 170A, receiver 170B, microphone 170C, headphone jack 170D, and application processor, etc. For example, music playback and recording. The pressure sensor 180A is used to sense pressure signals and convert them into electrical signals. In some embodiments, the pressure sensor 180A can be set on the display screen 194. The gyroscope sensor 180B can be used to determine the movement posture of the electronic device 100. The air pressure sensor 180C is used to measure air pressure. The magnetic sensor 180D includes a Hall sensor. The electronic device 100 can use the magnetic sensor 180D to detect the opening and closing of the flip leather case. The acceleration sensor 180E can detect the magnitude of the acceleration of the electronic device 100 in various directions (generally three axes). The distance sensor 180F is used to measure distance. The proximity light sensor 180G may include, for example, a light emitting diode (LED) and a light detector, such as a photodiode. The ambient light sensor 180L is used to sense the brightness of ambient light. The fingerprint sensor 180H is used to collect fingerprints. The temperature sensor 180J is used to detect temperature. The touch sensor 180K is also called a "touch panel." The touch sensor 180K can be set on the display screen 194. The touch sensor 180K and the display screen 194 form a touch screen, also called a "touch screen." The touch sensor 180K is used to detect touch operations acting on or near it. The touch sensor can transmit the detected touch operation to the application processor to determine the type of touch event. Visual output related to the touch operation can be provided through the display screen 194. In other embodiments, the touch sensor 180K can also be set on the surface of the electronic device 100, at a different location from the display screen 194. The bone conduction sensor 180M can obtain vibration signals. The buttons 190 include a power button, a volume button, etc. The motor 191 can generate vibration prompts. The indicator 192 can be an indicator light, which can be used to indicate the charging status, power changes, messages, missed calls, notifications, etc.
[0289] In the embodiment of the present application, the security chip and the NFC chip can be integrated into two parts of the same chip, or they can be two separate chips, which is not limited here.
[0290] The structure of the server provided in the embodiments of the present application is introduced below.
[0291] FIG12 shows a schematic diagram of the hardware structure of the server 300 .
[0292] As shown in Figure 12, the server 300 may include one or more processors 301, a communication interface 302, and a memory 303. The processor 301, the communication interface 302, and the memory 303 may be connected via a bus or other means. The embodiment of the present application takes connection via bus 304 as an example.
[0293] in:
[0294] The processor 301 may be composed of one or more general-purpose processors, such as a CPU, and may be used to execute program codes related to the device control method.
[0295] The communication interface 302 can be a wired interface (e.g., an Ethernet interface) or a wireless interface (e.g., a cellular network interface) for communicating with other nodes. In the embodiment of the present application, the communication interface 302 can be specifically used to communicate with the electronic device 100 and receive the manufacturer identifier and chip identifier of the UWB chip sent by the electronic device 100.
[0296] The memory 303 may include volatile memory, such as random access memory (RAM); it may also include non-volatile memory, such as ROM, flash memory, hard disk drive (HDD) or solid state drive (SSD); the memory 303 may also include a combination of the above types of memory.
[0297] It should be noted that the server 300 shown in FIG12 is only one implementation of the embodiment of the present application. In actual applications, the server 300 may also include more or fewer components, which is not limited here.
[0298] An embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.
[0299] The embodiments of the present application also provide a computer program product. When the computer program product is run on a computer, the computer can implement the steps in the above-mentioned various method embodiments.
[0300] The present application also provides a chip system, comprising a central processing unit (CPU), a UWB chip, and a security chip. The UWB chip is not connected to the security chip, while the CPU is connected to the UWB chip, and the CPU is connected to the security chip. The chip system can implement the steps of any method embodiment of the present application. The chip system can be a single chip or a chip module composed of multiple chips.
[0301] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. An ultra-wideband (UWB) key transmission method, characterized in that: Applied to electronic equipment, the electronic equipment includes a central processing unit, a UWB chip and a security chip, the processor is connected to the UWB chip, and the processor is connected to the security chip; the method includes: The central processor obtains an ultra-wideband transmission key and stores the ultra-wideband transmission key in the security chip, which stores a target ultra-wideband ranging session key URSK; The security chip encrypts the target URSK into first encrypted data using the ultra-wideband transmission key; The security chip sends the first encrypted data to the UWB chip through the central processor, wherein the UWB chip stores an ultra-wideband transmission key; The UWB chip decrypts the target URSK from the first encrypted data using the ultra-wideband transmission key, and the target URSK is used for ranging by the UWB chip.
2. The method according to claim 1, characterized in that The central processor obtains the ultra-wideband transmission key, specifically including: The central processing unit obtains the ultra-wideband transmission key sent by the server.
3. The method according to claim 2, characterized in that Before the central processor obtains the ultra-wideband transmission key sent by the server, the method further includes: The central processing unit obtains the manufacturer identifier of the UWB chip and the chip identifier of the UWB chip from the UWB chip; The central processor sends a first request to the server, where the first request carries the manufacturer identifier of the UWB chip and the chip identifier of the UWB chip. The first request is used to request the server to generate the ultra-wideband transmission key based on the root key, the manufacturer identifier of the UWB chip and the chip identifier of the UWB chip.
4. The method according to claim 2 or 3, characterized in that Before the central processor obtains the ultra-wideband transmission key, the method further includes: Before the electronic device leaves the factory, the UWB chip exports the manufacturer identifier of the UWB chip and the chip identifier of the UWB chip to the encryption machine, and the encryption machine is used to generate the ultra-wideband transmission key based on the root key, the manufacturer identifier of the UWB chip and the chip identifier of the UWB chip; The UWB chip receives the ultra-wideband transmission key imported by the encryption machine.
5. The method according to claim 2 or 3, characterized in that Before the ultra-wideband transmission key is stored in the UWB chip, the method further includes: The UWB chip generates a first public key and a first private key, where the first public key and the first private key form a pair of public and private keys; The UWB chip sends the first public key to the central processor; After acquiring the ultra-wideband transmission key sent by the server, the central processor uses the first public key to encrypt the ultra-wideband transmission key into second encrypted data; The central processing unit sends the second encrypted data to the UWB chip; The UWB chip uses the first private key to decrypt the second encrypted data to obtain the ultra-wideband transmission key.
6. The method according to claim 1, characterized in that Before the ultra-wideband transmission key is stored in the UWB chip, the method further includes: The UWB chip generates the ultra-wideband transmission key.
7. The method according to claim 6, characterized in that Before the central processor obtains the ultra-wideband transmission key, the method further includes: The central processor generates a second public key and a second private key, wherein the second public key and the second private key form a pair of public and private keys; The central processing unit sends the second public key to the UWB chip; The central processor obtains the ultra-wideband transmission key, specifically including: The UWB chip uses the second public key to encrypt the ultra-wideband transmission key into third encrypted data; The UWB chip sends the third encrypted data to the central processing unit; The central processor uses the second private key to decrypt the ultra-wideband transmission key from the third encrypted data.
8. The method according to claim 6 or 7, characterized in that The UWB chip generates the ultra-wideband transmission key, specifically including: The UWB chip randomly generates the ultra-wideband transmission key.
9. The method according to claim 6 or 7, characterized in that The UWB chip stores a manufacturer identifier of the UWB chip and a chip identifier of the UWB chip; The UWB chip generates the ultra-wideband transmission key, specifically including: The UWB chip generates the ultra-wideband transmission key based on the root key, the manufacturer identifier of the UWB chip, and the chip identifier of the UWB chip.
10. The method according to claim 9, characterized in that The UWB chip generates the ultra-wideband transmission key based on the root key, the manufacturer identifier of the UWB chip, and the chip identifier of the UWB chip, specifically including: The UWB chip generates a pairing key based on the root key and the manufacturer identifier of the UWB chip; The UWB chip generates the ultra-wideband transmission key based on the pairing key and the chip identification of the UWB chip.
11. The method according to any one of claims 1 to 10, characterized in that The target ultra-wideband ranging session key URSK is stored in the security chip, specifically including: The security chip generates one or more URSKs using a stored vehicle key session key, wherein the one or more URSKs include the target URSK; The security chip stores the one or more URSKs, wherein different URSKs correspond to different session identifiers.
12. The method according to claim 11, characterized in that Before the security chip uses the ultra-wideband transmission key to encrypt the target URSK into first encrypted data, the method further includes: The UWB chip sends a URSK acquisition command to the security chip through the central processor, where the URSK acquisition command carries a first session identifier; After receiving the URSK acquisition command, the security chip determines the target URSK corresponding to the first session identifier from the one or more URSKs.
13. The method according to claim 12, characterized in that Before the UWB chip sends a URSK acquisition command to the security chip through the central processor, the method further includes: The UWB chip sends a random number acquisition command to the security chip through the central processor; After receiving the random number acquisition command, the security chip sends a first random number to the UWB chip through the central processing unit; The UWB chip encrypts the first random number into an authentication ciphertext using the ultra-wideband transmission key, and sends the authentication ciphertext to the security chip through the central processor; The security chip uses the ultra-wideband transmission key to decrypt a second random number from the authentication ciphertext; If the second random number is the same as the first random number, the security chip sends a first response to the UWB chip through the central processor, where the first response is used to indicate that the random number verification is successful; The UWB chip sends a URSK acquisition command to the security chip through the central processor, specifically including: After receiving the first response, the UWB chip sends the URSK command to the security chip through the central processor.
14. The method according to any one of claims 1 to 13, characterized in that The central processing unit runs a rich execution environment (REE) and a trusted execution environment (TEE), and the REE runs a car key application; The central processor obtains the ultra-wideband transmission key, specifically including: The central processing unit obtains the ultra-wideband transmission key through the car key application; The central processor stores the ultra-wideband transmission key into the security chip, specifically including: The central processor stores the ultra-wideband transmission key into the security chip through the car key application and the TEE.
15. The method according to any one of claims 1 to 14, characterized in that The UWB chip is not connected to the security chip.
16. An electronic device, characterized in that: include: One or more processors, one or more memories, a security chip and a UWB chip, the one or more processors including a central processing unit; wherein the central processing unit is connected to the UWB chip, and the central processing unit is connected to the security chip; the one or more memories are used to store a computer program, and when the one or more processors execute the computer program, the first electronic device executes the method as described in any one of claims 1 to 15.
17. A computer storage medium, characterized in that The method comprises a computer program, which, when the computer program is run on a processor of an electronic device, causes the electronic device to perform the method according to any one of claims 1 to 15.
18. A chip system, characterized in that: Applied to the electronic device, the chip system includes: a central processing unit, a UWB chip and a security chip, wherein the UWB chip is not connected to the security chip, the processor is connected to the UWB chip, and the processor is connected to the security chip, and the chip system is used to execute the method according to any one of claims 1 to 15.
Citation Information
Patent Citations
UWB secret key transmission method and related device
CN120416756A
Digital key derivation allocation between secure element and ultra-wideband module
CN116034564A
Ranging method and device, storage medium and terminal equipment
CN116299382A
Cosmetic composition containing fermented extract of Perilla frutescens grown using a red LED light source for skin elasticity enhancement or inhibiting photoaging
KR102552982B1