Occupant identification for an authority outside the vehicle
The electronic certificate method within vehicles for occupant identification and authentication addresses the challenge of external verification, ensuring secure and efficient access control and feature activation.
Patent Information
- Application Number
- PCT/EP2025/059523
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-05-10
- Filing Date
- 2025-04-07
- Publication Date
- 2025-11-13
AI Technical Summary
Existing road toll systems and vehicle access control methods lack efficient means to identify and authenticate vehicle occupants externally, particularly for restricting access to certain lanes, roads, and areas, and enabling features like automated driving.
An electronic certificate representing an occupant's identification document is used within the vehicle, authenticated via biometrics or passphrases, and transmitted externally for verification, allowing permission for vehicle journeys or functions.
Ensures secure and efficient identification and authentication of vehicle occupants, enabling access control and feature activation based on occupant identity, reducing unauthorized use and enhancing system security.
Smart Images

Figure EP2025059523_13112025_PF_FP_ABST
Abstract
Description
[0001] Occupant identification for external parties
[0002] The invention relates to a method for performing an identification and authentication of a vehicle occupant at a location external to the vehicle.
[0003] A road toll system is typically operated by a service provider that facilitates payment. This payment process offers a limited number of possible payment methods. For example, payment, or an order resulting from payment, can be made via a website, a mobile application, or by inserting a personal toll payment card into a vehicle card reader.
[0004] German patent DE 102022 002 494 B3 relates to a method for paying for goods and / or services by an authorized user of a mobile communication unit with a SIM or eSIM, wherein a user-related parameter set is transmitted to a mobile communication provider assigned to the SIM or eSIM and linked to the SIM or eSIM by the latter, after which the mobile communication provider sends a request to a payment service provider, which creates a virtual payment card or virtual payment token and transmits it to the mobile communication provider, after which the mobile communication provider links the virtual payment card or virtual payment token to the SIM or eSIM, wherein the mobile communication unit is integrated into a vehicle, and wherein the user-related parameter set is determined by a vehicle-external server of the vehicle manufacturer linked to the vehicle and transmitted to the mobile communication provider.Furthermore, a user-specific, vehicle-related parameter set is determined by the vehicle manufacturer's external server and transmitted to the mobile network operator, which also links this to the SIM or eSIM. When paying for goods and / or services, the parameter sets linked to the SIM or eSIM are compared with the corresponding parameter sets stored at the mobile network operator and / or on the vehicle manufacturer's external server to authenticate the user. In many countries, there is a trend toward government agencies collecting increasing amounts of electronic data on citizens. A possible next step for governments could be to restrict the use of certain lanes (e.g., electronic toll lanes), certain types of roads (e.g., toll roads, highways), and certain areas (e.g., low-emission zones, city centers).to allow participation in motorized private transport or public mass transport only after personal identification (e.g., in certain urban areas) or in general participation in private motorized transport or public mass transport. In the case of private transport, this can apply only to the driver or also to all occupants.
[0005] The object of the invention is to provide a technical method for checking or limiting the participation of persons in road traffic.
[0006] The invention is defined by the features of the independent claims. Advantageous further developments and embodiments are the subject of the dependent claims.
[0007] A first aspect of the invention relates to a method for carrying out the identification and authentication of a vehicle occupant at a location external to the vehicle, wherein an electronic certificate virtually represents an electronically readable identification document of the occupant, and the electronic certificate is carried in the vehicle to identify the occupant before or during a journey with the vehicle, wherein the occupant associated with the identification document authenticates himself in the vehicle by means of biometric features or by entering a passphrase in the vehicle, and wherein information about the identification and authentication of the occupant is transmitted to the location external to the vehicle, wherein the location external to the vehicle grants permission for a journey or function of the vehicle upon receipt of the information.
[0008] The electronic certificate allows the physical ID card to be used digitally for identification purposes. By using the electronic certificate, identification can be established with other communication partners, who can then assume that the holder of the electronic certificate is also the holder of the corresponding ID card.
[0009] For example, an electronic certificate can be generated using a reader. If such a reader is provided in the vehicle, it can communicate wirelessly, for example via WLAN, UWB, RFID, or NFC, with a transmission unit in the vehicle, allowing the transmission unit to handle communication with the external authority. Alternatively, the electronic certificate can be stored permanently or quasi-permanently on the user's mobile device. When the electronic certificate is stored on the mobile device, it is typically referred to as a "wallet." In this case, the electronic certificate is stored there, particularly in the form of a token. The mobile device could be, for example, a smartphone or a smartwatch.
[0010] Alternatively, the electronic certificate can be stored in a vehicle telematics system, similar to storage on a mobile device. However, the advantage of storing it in the vehicle may be that it is potentially easier to transmit successful identification to the external system without requiring authorization from the occupant, as might be the case with a "wallet" like the one mentioned above. This, however, depends on the specific implementation.
[0011] The identification document is preferably a national identity card. However, a passport, driver's license, or digital identity issued by a government agency can also be used. In this case, the described procedure is also feasible, depending on the driver's identity and, in particular, on the possession of a valid driver's license for the vehicle, which may be technically prevented.
[0012] The electronic certificate is used to identify the occupant. This identification means linking the card to an individual. However, the card could have been obtained by an unauthorized person, such as a car thief. To ensure that the user is correctly identifying themselves, i.e., that the card was issued to them, authentication is necessary. This is done, for example, by entering a PIN at the reader or using biometric data such as a fingerprint or iris scan. The biometric data can be captured, for example, using an interior camera or the camera of the mobile device.
[0013] Depending on the use case and specific design, the trigger for identifying and authenticating an occupant, as well as the transmission of information about successful identification and authentication to the external system, can occur automatically, for example, in the following events: when the vehicle starts, when the vehicle begins a predefined route or route segment, when approaching certain lanes (e.g., electronic toll lanes), certain types of roads (e.g., toll roads, highways), or certain areas (e.g.,
[0014] Environmental zones, city centers, certain urban areas); as well as in route planning where the route includes certain lanes (e.g., electronic toll lanes), certain road types (e.g., toll roads, highways), or certain areas (e.g.,
[0015] This includes environmental zones, city centers, and specific urban areas. Furthermore, the procedure can be helpful for activating certain vehicle features, for example, in automated driving. Alternatively, a corresponding procedure can also be used internally, for example, to technically prevent the operation of test vehicles without appropriate training.
[0016] The identity of the occupant to be identified and authenticated depends on the specific application and its design. For example, the occupant could be the vehicle's driver, particularly if the external system is used to restrict access to a specific area, such as a city center, a restricted zone, or a toll road for authorized individuals. However, the procedure can, in principle, be applied to all occupants identified using methods such as seatbelt sensors, seat occupancy sensors, radar sensors, camera sensors, facial or voice recognition, or a combination thereof.
[0017] Until re-authentication is required, the current authentication data record is preferably stored in the vehicle. Depending on the specific requirements, re-authentication may be necessary, for example, after locking and unlocking the vehicle, during new navigation route planning, after opening and closing vehicle doors, especially the driver's door, when the number of occupants changes (determined by seatbelt switch sensors, seat occupancy sensors, radar sensors, camera sensors, facial or voice recognition, or a combination thereof), and when the number of occupants changes, particularly when new occupants enter the vehicle (determined by seatbelt switch sensors, seat occupancy sensors, radar sensors, camera sensors, facial or voice recognition, or a combination thereof).
[0018] Depending on the specific requirements, identification and authentication information can be transmitted to an external entity at specific intervals, either temporally or spatially. This occurs, for example, at certain locations (e.g., entrances and exits of low-emission zones); at the start of a journey; when approaching certain lanes (e.g., carpool lanes), certain road types (e.g., highways or roads requiring registration), or certain areas (e.g., low-emission zones, city centers, specific urban areas); at certain locations (e.g., toll payment stations) or when approaching or using toll or vignette-required roads or lanes, the information is transmitted to the toll or vignette operator for toll billing purposes. Furthermore, the transmission of identification and authentication information can occur during route planning, where the route includes certain lanes (e.g., electronic payment lanes) or certain road types (e.g.,The data is transmitted to an external location if it includes toll roads, highways, or specific areas (e.g., environmental zones, city centers, certain urban areas). Alternatively, it can be transmitted along with the destination during route planning, or when certain vehicle features are activated, such as automated driving.
[0019] Depending on the specific requirements, missing or incomplete information about identification and authentication may prevent one of the following: vehicle use, activation of certain features (e.g., automated driving), use of certain features in certain contexts (e.g., route planning with toll roads), or toll payment.
[0020] According to an advantageous embodiment, the electronic certificate is stored on a mobile device of the occupant carried in the vehicle, and the mobile device transmits the electronic certificate to a transmission unit of the vehicle, the transmission unit communicating the information about the identification and authentication of the occupant to the external body.
[0021] According to another advantageous embodiment, the electronic certificate is stored on a secure memory in the vehicle.
[0022] According to a further advantageous embodiment, the occupant identifies himself using a physical identification card at a reader in the vehicle, and the reader triggers the storage of the electronic certificate in the secure storage.
[0023] According to a further advantageous embodiment, the vehicle transmits a unique identifier assigned to the vehicle to the external entity, along with information on the identification and authentication of the occupant. According to a further advantageous embodiment, the external entity is a toll service provider and / or authorizes access to local areas that the vehicle is permitted to drive in.
[0024] According to a further advantageous embodiment, the vehicle connects to a central computer via the Internet, wherein the central computer verifies the correct association of the authentication with the electronic certificate of identification of the occupant and, if the verification is positive, transmits a security token to the external location or to the vehicle, wherein, when the security token is transmitted to the vehicle, the vehicle transmits the security token to the external location.
[0025] Further advantages, features and details will become apparent from the following description, in which - possibly with reference to the drawing - at least one embodiment is described in detail.
[0026] They show:
[0027] Fig. 1: A situation involving the identification and authentication of a vehicle occupant according to an embodiment of the invention.
[0028] Fig. 2: Another situation involving the identification and authentication of a vehicle occupant according to an embodiment of the invention.
[0029] Fig. 1 shows a method for performing the identification and authentication of a vehicle occupant 1 at an external location 3. The external location 3 requests data release from the occupant, for example, in the case of a toll system that grants access to roads or local areas on a personal basis. The occupant in the vehicle carries their identity card 5. They can use this physical identity card 5 at a reader 9 by bringing the identity card 5 close to the reader 9. This triggers the launch of an application signed by a government organization that issued the identity card 5, which establishes communication with the reader 9.This ID card application can run on a backend (cloud service) and communicate end-to-end encrypted with the reader 9. Alternatively, it can reside within the vehicle's telematics system and communicate encrypted with the reader 9 from there. The application then prompts the occupant to enter a passphrase in the form of a PIN, for example, via a specific display or voice prompt. The occupant enters and confirms this passphrase at an input unit of the vehicle's reader 9 or at an input unit of the vehicle itself. The occupant is then identified using their identity card 5 and authenticated as the true holder of the identity card 5 using the passphrase. Furthermore, consent is requested to transmit information about the identification and authentication to the external entity 3.Following this consent by the occupant, the vehicle-external entity 3 receives a security token from the application, which serves as technical confirmation of the individual occupant's presence in the vehicle. Depending on the application's configuration and the vehicle-external entity 3, a unique vehicle identifier is also transmitted to the vehicle-external entity 3, for example, in the case of a toll system or a system for monitoring access to and entry into a particularly secure area.
[0030] Figure 2 shows an alternative method for identifying and authenticating the occupant in the vehicle. Here, the occupant transfers their electronic driver's license or electronic identity card 5 to a secure element of their mobile device 7 via electronic reading and can thus use this proof of identity 5 as a digital wallet. The vehicle is connected to the mobile device via an end-to-end encrypted connection (e.g., via WLAN / UWB / RFID / NFC). When necessary, the occupant is prompted to start this wallet on the mobile device 7 and grant data access. The occupant then starts this wallet and grants data access to the identification data on their mobile device 7. This triggers the launch of an application signed by the issuing government organization 5, which establishes communication with the mobile device 7.A security chip in the mobile device 7 verifies whether the wallet has this signature and will only allow data access with the matching signature. This ID application can run on a backend (cloud service) and communicate end-to-end encrypted with the vehicle and / or the mobile device 7, or it can reside within the vehicle's telematics system itself and communicate encrypted with the mobile device 7 from there. Upon request, the occupant is authenticated using biometric data. Such biometric authentication is an alternative to a passphrase; both methods can be used. In a preferred configuration, however, the communication is not handled by the mobile device 7 with the external entity 3, but rather by a transmission unit within the vehicle.This transmission unit can also transmit the vehicle's unique identification number to the external location 3. If the vehicle has the option to store this wallet directly within it, the identification and data transmission request steps can be omitted, provided the vehicle has the necessary authorization. However, a confirmation step to verify the occupant's identity is still required to ensure authentication.
[0031] Although the invention has been further illustrated and explained in detail by means of preferred embodiments, the invention is not limited by the disclosed examples, and other variations can be derived from them by a person skilled in the art without departing from the scope of protection of the invention. It is therefore clear that a multitude of possible variations exist. It is also clear that the embodiments mentioned as examples are truly only examples and are not to be understood in any way as limiting, for example, the scope of protection, the possible applications, or the configuration of the invention.Rather, the preceding description and the description of the figures enable the person skilled in the art to implement the exemplary embodiments in concrete terms, whereby the person skilled in the art, with knowledge of the disclosed inventive concept, can make various changes, for example with regard to the function or the arrangement of individual elements mentioned in an exemplary embodiment, without leaving the scope of protection defined by the claims and their legal equivalents, such as further explanations in the description.
Claims
Patent claims 1. A method for carrying out the identification and authentication of a vehicle occupant (1) at an external location (3), wherein an electronic certificate virtually represents an electronically readable identification document (5) of the occupant, and the electronic certificate is carried in the vehicle (1) to identify the occupant before or during a journey with the vehicle (1), wherein the occupant associated with the identification document (5) authenticates himself in the vehicle (1) by means of biometric features or by entering a passphrase in the vehicle (1), and wherein information about the identification and authentication of the occupant is transmitted to the external location (3), wherein the external location (3) grants permission for a journey or function of the vehicle (1) upon receipt of the information.
2. Method according to claim 1, wherein the electronic certificate is stored on a mobile device (7) of the occupant carried in the vehicle (1), and the mobile device (7) transmits the electronic certificate to a transmission unit of the vehicle (1), wherein the transmission unit communicates the information about the identification and authentication of the occupant to the external entity (3).
3. Method according to claim 1, wherein the electronic certificate is stored on a secure storage device of the vehicle (1).
4. Method according to claim 3, wherein the occupant identifies himself by means of a physical identification document (5) at a reader (9) in the vehicle (1), and the reader (9) triggers the storage of the electronic certificate on the secure storage.
5. Method according to one of the preceding claims, wherein the vehicle (1) is connected to the vehicle-external location (3) together with the In- Information regarding the identification and authentication of the occupant is transmitted by an identifier uniquely assigned to the vehicle (1).
6. Method according to one of the preceding claims, wherein the vehicle-external entity (3) is a toll service provider and / or releases local areas that are permissible to be driven on by the vehicle (1).
7. Method according to claim 6, wherein the vehicle (1) transmits to the vehicle-external location (3) together with the information on the identification and authentication of the occupant an identifier uniquely assigned to the toll service provider.
8. Method according to one of the preceding claims, wherein the vehicle (1) connects to a central computer via the Internet, wherein the central computer verifies the correct association of the authentication with the electronic certificate of identification of the occupant and, if the verification is positive, transmits a security token to the vehicle-external location (3) or to the vehicle (1), wherein, when the security token is transmitted to the vehicle (1), the vehicle (1) transmits the security token to the vehicle-external location (3).
9. A method according to any of the preceding claims, wherein the authentication requirement is automatically triggered by at least one of the following events: - when the vehicle is started; - when approaching certain lanes, certain types of roads or certain areas; - in route planning where the route includes specific lanes, specific road types, or specific areas; - when certain vehicle functions are activated; 10. Method according to one of the preceding claims, wherein a current authentication data record is stored in the vehicle (1) until re-authentication is required.
Citation Information
Patent Citations
Information-based, biometric, asynchronous access control system
US10957136B1
Personnel and vehicle identification system using three factors of authentication
US20040002894A1
Driver and registration identification for vehicle enablement
US20080238690A1
DE102022002494B3
RS20120407A1