Method and device for transferring a digital vehicle key

WO2026166664A1PCT designated stage Publication Date: 2026-08-13MERCEDES BENZ GROUP AG
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-12-19
Publication Date
2026-08-13

Smart Images

  • Figure EP2025088520_13082026_PF_FP_ABST
    Figure EP2025088520_13082026_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to various embodiments of methods for transferring a digital vehicle key (2) of a vehicle (1), in particular in a logistics chain (LK). The invention further relates to various embodiments of devices for transferring a digital vehicle key (2) of a vehicle (1), in particular in a logistics chain (LK).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Mercedes-Benz Group AG

[0002] Method and device for transferring a digital vehicle key

[0003] The invention relates to a method for handing over a digital vehicle key.

[0004] The invention further relates to a device for carrying out such a method.

[0005] From DE 102023001 311 B3 a method for establishing a communication connection between a new vehicle key and a vehicle is known, in which

[0006] - a mobile communication device with a storage medium, a programmable vehicle key that is communicatively connected to the vehicle, and a programmable new vehicle key that can be communicatively connected to the vehicle, will be provided,

[0007] - wherein a learning application is provided which includes an executable user application provided in the storage medium of the mobile communication device and an executable backend application provided in a vehicle backend and wirelessly connected to the mobile communication device,

[0008] - where a digital permission to connect the new vehicle key to the vehicle is provided or can be provided in the backend application for a user,

[0009] - where a user of the communication device logs into the learning application and initiates a key connection process,

[0010] - as part of the key connection process, the learning application checks whether

[0011] - a) the user is in the vehicle and a digital authorization to connect the new vehicle key to the vehicle has been provided to the user in the backend application, whereby it is further checked whether the user is logged into the programming application, - b) the new vehicle key is in the vehicle,

[0012] - c) the vehicle key is inside the vehicle,

[0013] - whereby, after successful verification of criteria a) to c), the new vehicle key is connected to the vehicle in a coupling step.

[0014] The invention is based on the objective of specifying a novel method and a novel device for the transfer of a digital vehicle key.

[0015] The problem is solved according to the invention by

[0016] - a method which has the features specified in claim 1,

[0017] - a method which has the features specified in claim 2,

[0018] - a method which has the features specified in claim 3,

[0019] - a device having the features specified in claim 16, and - a device having the features specified in claim 17.

[0020] Advantageous embodiments of the invention are the subject of the dependent claims.

[0021] The method for handing over a digital vehicle key of a vehicle according to a first aspect of the invention provides that

[0022] - a digital unique vehicle identifier is transmitted by means of a door handle transmitter-receiver unit arranged in or on an exterior door handle of the vehicle and designed for near-field communication,

[0023] - the vehicle identifier is received by means of a device transmit-receive unit of a mobile device,

[0024] - the vehicle identifier, together with a user identifier of a user of the terminal device, is transmitted via the terminal device to a central computing unit external to the vehicle, for example, a backend server of a vehicle manufacturer, - the vehicle identifier is assigned to the vehicle by means of the computing unit, and it is checked using the user identifier whether the user has authorization to use the digital vehicle key, and

[0025] - if the authorization to use the vehicle is granted, the digital vehicle key is transmitted to the terminal device via the computing unit.

[0026] The digital vehicle key, based on the Car Connectivity Consortium standard (CCC standard) as described at https: / / carconnectivity.org / digital-key-release-3-0-specification-download / (accessed January 21, 2025), is gaining in popularity and importance due to increasing support from vehicle manufacturers. This digital vehicle key, stored on a user's mobile device such as a mobile phone, smartphone, or wearable, can replace traditional physical vehicle keys, also known as key fobs. This shifts the role of the key fob from an essential component of user-vehicle interaction to an optional element. Vehicle manufacturers aim to offer their customers the option of purchasing such key fobs as an optional extra rather than as standard equipment.In return, the digital key, especially according to the CCC standard, should become standard equipment.

[0027] However, there are regulatory requirements stipulating that a vehicle may only leave a manufacturer's factory premises if at least one vehicle key is programmed to it. After leaving the factory, the vehicle goes through a logistics chain with numerous transfer stations until it arrives at a dealership and is finally handed over to a customer. At each transfer station in the logistics chain, the vehicle key must be transferred. Using a key fob simplifies this process, as the key fob can be easily transferred and stored.

[0028] Using the present method as described in the first aspect, it is possible to implement such a transfer of a vehicle key, even with a digital vehicle key, in a simple and secure manner. This involves verifying and ensuring the proximity of the mobile device, such as a mobile phone, smartphone, or wearable, by transmitting the vehicle identifier via near-field communication (NFC). This enables the secure provisioning of the digital vehicle key on the device. Such a secure transfer of the digital vehicle key allows vehicles to be delivered from a factory site to dealers and customers via a logistics chain, even without a traditional physical vehicle key, particularly a key fob.

[0029] The method for transferring a digital vehicle key according to a second aspect of the invention provides that: - using policy-based authorization and attribute-based authorization, context-specific authorization rules are defined for each transfer station in a logistics chain for the vehicle, specifying the conditions under which the digital vehicle key is transmitted to a mobile device; - at a transfer station, a request to transfer the digital vehicle key to the device is transmitted to an external central computing unit, for example, a backend server of a vehicle manufacturer, using the mobile device together with a user identifier; - the request is checked by the computing unit based on the authorization rules defined for the respective transfer station.whether the conditions for transferring the digital vehicle key to the mobile device are met, and whether the user has authorization to use the digital vehicle key is verified using the user identifier, and,

[0030] - if the user authorization is present, the digital vehicle key is transmitted to the terminal device via the computing unit, provided it is not located on another mobile device belonging to a different user.

[0031] Using the present method as described in the second aspect, a configurable set of rules for authorizing the transfer of the digital key is generated and used on the processing unit. For the transfer of a digital vehicle key between two end devices, such as two devices belonging to logistics employees, temporal and spatial proximity of the devices is not required. This results in increased convenience and efficiency during the transfer of the digital vehicle key. Furthermore, the authorization rules ensure that only authorized users, such as logistics employees, are able to obtain a digital vehicle key for a vehicle. This achieves enhanced theft protection.

[0032] Policy-based authorization, as used here, refers to an authorization concept in which user access rights, or rights to obtain a digital vehicle key, are determined by policies. User roles and their associated permissions are checked to determine access. Additional attributes are also evaluated. This authorization concept is characterized by its flexibility and speed, as administrators have better control over an access level and can grant, revoke, or modify permissions for many users simultaneously. Policies cover a wide range of dynamic attributes and context-related controls, such as time- or location-based access restrictions, making this authorization concept highly adaptable.

[0033] Attribute-based authorization, as used here, refers to an authorization concept that determines user access rights, or rights to obtain a digital vehicle key, based on attributes or characteristics. Administrators create access policies based on user roles and attributes and define rules that dynamically determine access and rights. When an access request or a request to obtain the digital vehicle key is made, a decision is made depending on the context and risk. While policy-based authorization relies on policies to grant or deny resource access, attribute-based authorization focuses on the specific attributes that influence the policies.Because the relationships between users and resources are defined by attributes rather than roles, administrators can create precisely targeted rules without having to set up additional roles. Instead of modifying rules or creating new roles, administrators simply assign the appropriate attributes to new users or resources, making attribute-based authorization highly flexible. Furthermore, this type of authorization is also highly adaptable, as administrators can modify attributes and create context-dependent rules as needed.

[0034] The method for handing over a digital vehicle key of a vehicle according to a third aspect of the invention provides that in an initial handover of the digital vehicle key

[0035] - a digital unique vehicle identifier is transmitted by means of a door handle transmitter-receiver unit arranged in or on an exterior door handle of the vehicle and designed for near-field communication,

[0036] - the vehicle identifier is received by means of a device transmit-receive unit of a mobile device, - the vehicle identifier together with a user identifier of a user of the device is transmitted by means of the device to a central computing unit external to the vehicle,

[0037] - the vehicle identifier is assigned to the vehicle by means of the processing unit, and it is checked using the user identifier whether the user has authorization to use the digital vehicle key, and

[0038] - if the authorization to use the vehicle is granted, the digital vehicle key is transmitted to the terminal device via the computing unit,

[0039] and wherein in a handover of the digital vehicle key immediately or indirectly following the initial handover

[0040] - using policy-based authorization and attribute-based authorization via context-specific authorization rules for each handover station in a logistics chain for the vehicle, it is determined under which conditions the digital vehicle key is transmitted to a mobile device, - at a handover station, a request to transfer the digital vehicle key to the device is transmitted to the vehicle-external central computing unit using the mobile device together with a user identifier of the user,

[0041] - the computing unit checks, based on the authorization rules defined for the relevant transfer station, whether the conditions for transferring the digital vehicle key to the mobile device are met, and, based on the user identifier, checks whether the user has authorization to use the digital vehicle key, and

[0042] - if the authorization to use the digital vehicle key is granted, it is transmitted to the terminal device via the computing unit, unless it is located on another mobile device of another user to which the vehicle key was transmitted in the initial transfer or in a transfer immediately or indirectly following.

[0043] Using the present method, as described in the third aspect, it is possible to implement the transfer of a vehicle key, even a digital one, in a simple and secure manner. This involves an initial transfer where the proximity of the mobile device, such as a mobile phone, smartphone, or wearable, is established and ensured by transmitting the vehicle identifier via Near Field Communication (NFC). This enables the secure provisioning of the digital vehicle key on the device. Such a secure transfer of the digital vehicle key allows vehicles to be delivered from a factory to dealers and customers via a logistics chain, even without a traditional physical key, particularly a key fob.

[0044] Furthermore, for the transfer of digital vehicle keys between different mobile devices, a configurable rule set is generated and used on the processing unit after the initial transfer to authorize the transfer of the digital key. For the transfer of a digital vehicle key between two devices, for example, two devices belonging to logistics employees, temporal and spatial proximity of the devices is not required. This results in increased convenience and efficiency during the transfer of the digital vehicle key. Moreover, the authorization rules ensure that only authorized users, such as logistics employees, are able to obtain a digital vehicle key for a vehicle. This achieves enhanced theft protection.

[0045] The following are possible embodiments which may relate to all three of the aforementioned aspects of the invention.

[0046] One possible design stipulates that

[0047] - before the vehicle key is transmitted to the terminal device via the processing unit, a request for approval of the transmission to a person's terminal device, for example a dispatcher of a logistics company, is transmitted and

[0048] - the vehicle key is only transmitted to the user's mobile device if, in addition to the existence of the authorization to use it and the condition that the vehicle key is not located on another user's mobile device, the request for authorization from the computing unit is met with authorization for the transmission from the person on their device.

[0049] This further enhances security during the transmission of the digital vehicle key. Another possible configuration involves storing authorization information for receiving the vehicle key and authentication information in the processing unit for different users and / or mobile devices. This enables authentication and authorization of all participants in the process at the processing unit, particularly at the vehicle manufacturer's backend server.

[0050] Another possible configuration allows for the use of both natural and legal persons as users. This would enable companies, such as logistics companies, to be issued digital vehicle keys in addition to individuals. The end device used would then no longer be linked to a specific person and could, for example, be made available by the company to different employees to receive digital vehicle keys.

[0051] In another possible configuration, communication between the terminal device and the vehicle, the processing unit, and a user, as well as the processing of data transmitted and received for the transfer of the vehicle key, is controlled and / or executed on the terminal device by means of an application program running on the terminal device. Such an application program, also referred to as an application or app, provides the user with a user interface through which they can easily and intuitively send requests to the processing unit and receive and use the vehicle key from it.

[0052] In another possible embodiment, it is envisaged that the following are used as input variables for the selection and execution of authorization rules.

[0053] - a current transfer point in a logistics chain and / or

[0054] - a current time and / or

[0055] - a current geographical position of the vehicle and / or

[0056] - the user's affiliation with a company and / or

[0057] - User permissions and / or

[0058] - a role of the user and / or

[0059] - a vehicle identity and / or - the existence of an authorization for the handover of the vehicle key by a person, for example by a dispatcher of the logistics company,

[0060] These input variables can be used to easily adapt the authorization rules to different transfer stations and their requirements. This makes it possible to customize the authorization rules for each transfer station in the logistics chain.

[0061] In another possible configuration, the computing unit stores a vehicle identification number (VIN) for each of several vehicles. These VINs allow for the unique identification of each individual vehicle.

[0062] In another possible configuration, the vehicle identification number is used to generate the vehicle identifier. This allows for the creation of a unique vehicle identifier that is assigned to only one vehicle.

[0063] In another possible configuration, each transmission of the digital vehicle key to an end device is logged in the processing unit. This ensures that it is always known on which end device a digital vehicle key is stored and has been stored in the past. In other words, the status and current owner of the digital vehicle key are always known.

[0064] In another possible configuration, the vehicle key is automatically deleted from a terminal device after a predefined deletion condition is met. This ensures that the vehicle key is only available on a predetermined number of terminal devices, and in particular, only on one terminal device at a time. In one possible configuration, the digital vehicle key is terminated on the terminal device after use, i.e., at the end of its usage. This occurs automatically. The deletion or...

[0065] Termination of the vehicle key is logged centrally, particularly in the processing unit. This prevents the duplication of digital vehicle keys. In another possible configuration, it is envisaged that, to transfer the vehicle key from one mobile device to another, a request to transfer the vehicle key is transmitted to the processing unit via the device on which the vehicle key is active.

[0066] - is deleted on the terminal device by means of the computing unit after receipt of the request to surrender the vehicle keys,

[0067] - by means of the additional mobile device at the handover station, together with the user's user identifier, the request to transfer the digital vehicle key to the device is transmitted to a central computing unit external to the vehicle,

[0068] - the computing unit checks, based on the authorization rules defined for the relevant transfer station, whether the conditions for transferring the digital vehicle key to the other mobile device are met, and, based on the user identifier, checks whether the user has authorization to use the digital vehicle key, and

[0069] - if the authorization to use the vehicle is granted, the digital vehicle key is transmitted to the other terminal device via the computing unit.

[0070] This ensures that the vehicle key is first deleted on one device and only then transferred to another. Furthermore, this allows for the transfer of a digital vehicle key between the devices of two users without requiring either physical or temporal proximity.

[0071] In another possible configuration, it is envisaged that

[0072] - before the vehicle key is deleted from the user's terminal device, a request for approval of the deletion is transmitted by the processing unit to a person's terminal device, for example a dispatcher of the logistics company, and

[0073] - the vehicle key will only be deleted from the user's mobile device if the computing unit receives permission to delete it from the person on their device.

[0074] This allows the deletion of the vehicle key from a previous user's device, which is necessary for transferring the vehicle key to another user's device, to be authorized by another person, resulting in a further increase in security when transferring the digital vehicle key.

[0075] In another possible configuration, it is envisaged that

[0076] - before the vehicle key is transferred to the user's terminal device by means of the processing unit, a request for approval of the transfer to a person's terminal device is transmitted and

[0077] - the vehicle key is only transferred to the user's mobile device if the computing unit receives authorization for the transfer from the person on their device.

[0078] This means that the transfer of the vehicle key to a user's terminal device must be authorized by another person, resulting in a further increase in security when transferring the digital vehicle key.

[0079] The device according to the invention for transferring a digital vehicle key of a vehicle according to a first embodiment comprises

[0080] - a door handle transmitter / receiver unit arranged in or on an exterior door handle of the vehicle, which is designed to transmit a digital unique vehicle identifier via near-field communication,

[0081] - a mobile terminal device which has a device transceiver unit which is configured to receive the vehicle identifier from the door handle transceiver unit, and which is configured to transmit the vehicle identifier together with a user identifier of a user of the terminal device to a central computing unit external to the vehicle,

[0082] - the vehicle-external central computing unit, which is designed to assign the vehicle identifier to the vehicle and to check, using the user identifier, whether the user has authorization to use the digital vehicle key, and, if authorization to use is present, to transmit the digital vehicle key to the terminal device.

[0083] Using the device according to the first embodiment, it is possible to transfer a vehicle key, even a digital one, in a simple and secure manner. This is achieved by verifying and ensuring the proximity of the mobile device, such as a mobile phone, smartphone, or wearable, through the transmission of the vehicle identifier via near-field communication (NFC). This enables the secure provisioning of the digital vehicle key on the device. Such a secure transfer of the digital vehicle key allows vehicles to be delivered from a factory to dealers and customers via a logistics chain, even without a traditional physical vehicle key, particularly a key fob.

[0084] The device according to the invention for transferring a digital vehicle key of a vehicle according to a second embodiment comprises

[0085] - a mobile device which is trained to transmit a request to transfer the digital vehicle key to the device to an external central computing unit at a transfer station together with a user identifier of a user of the mobile device,

[0086] - the vehicle-external central computing unit, which is designed,

[0087] - using policy-based authorization and attribute-based authorization, by means of context-specific authorization rules for each handover station in a logistics chain for the vehicle, to determine under which conditions the digital vehicle key is transmitted to a mobile device,

[0088] - to check, based on the authorization rules defined for the relevant transfer station, whether the conditions for transferring the digital vehicle key to the mobile device are met,

[0089] - to verify, using the user identifier, whether the user has authorization to use the digital vehicle key, and

[0090] - to transmit the digital vehicle key to the terminal device if the user authorization is granted, unless it is located on another mobile device belonging to a different user.

[0091] Using the device according to the second embodiment, a configurable set of rules for authorizing the transfer of the digital key is generated and used on the processing unit. For the transfer of a digital vehicle key between two end devices, for example, two end devices belonging to logistics employees, temporal and spatial proximity of the end devices is not required. This results in increased convenience and efficiency during the transfer of the digital vehicle key. Furthermore, the authorization rules ensure that only authorized users, such as logistics employees, are able to obtain a digital vehicle key for a vehicle. This achieves enhanced theft protection.

[0092] The device according to the invention for transferring a digital vehicle key of a vehicle according to a third embodiment has

[0093] - a door handle transmitter / receiver unit arranged in or on an exterior door handle of the vehicle, which is designed to transmit a digital unique vehicle identifier via near-field communication,

[0094] - a mobile terminal device which has a device transceiver unit which is configured to receive the vehicle identifier from the door handle transceiver unit, and which is configured to transmit the vehicle identifier together with a user identifier of a user of the terminal device to a central computing unit external to the vehicle, and

[0095] - the vehicle-external central computing unit, which is designed to assign the vehicle identifier to the vehicle and to check, using the user identifier, whether the user has authorization to use the digital vehicle key, and, if authorization to use exists, to transmit the digital vehicle key to the terminal device.

[0096] The mobile device is additionally equipped to transmit a request to transfer the digital vehicle key to the device to an external central processing unit at a transfer station, together with a user identifier of a user of the mobile device. The external central processing unit is additionally equipped to...

[0097] - to define, using policy-based and attribute-based authorization, context-specific authorization rules for each handover station in a logistics chain for the vehicle, the conditions under which the digital vehicle key is transmitted to a mobile device, - to check, based on the authorization rules defined for the relevant handover station, whether the conditions for the transmission of the digital vehicle key to the mobile device are met,

[0098] - to check, using the user identifier, whether the user has authorization to use the digital vehicle key, and - if authorization to use exists, to transmit the digital vehicle key to the terminal device if it is not located on another mobile device of another user.

[0099] Using the device according to the third embodiment, it is possible to implement the transfer of a vehicle key, even a digital one, in a simple and secure manner. In an initial transfer, the proximity of the mobile device, such as a mobile phone, smartphone, or wearable, is first established and ensured by transmitting the vehicle identifier via near-field communication (NFC). This enables the secure provisioning of the digital vehicle key on the device. Such a secure transfer of the digital vehicle key allows vehicles to be delivered from a factory to dealers and customers via a logistics chain, even without a traditional physical vehicle key, particularly a key fob.

[0100] Furthermore, for the transfer of digital vehicle keys between different mobile devices, a configurable rule set is generated and used on the processing unit after the initial transfer to authorize the transfer of the digital key. For the transfer of a digital vehicle key between two devices, for example, two devices belonging to logistics employees, temporal and spatial proximity of the devices is not required. This results in increased convenience and efficiency during the transfer of the digital vehicle key. Moreover, the authorization rules ensure that only authorized users, such as logistics employees, are able to obtain a digital vehicle key for a vehicle. This achieves enhanced theft protection.

[0101] Exemplary embodiments of the invention are explained in more detail below with reference to drawings.

[0102] This shows:

[0103] Fig. 1 schematically shows a logistics chain for a vehicle with several transfer stations,

[0104] Fig. 2 schematically shows a block diagram of an embodiment of a device for transferring a digital vehicle key to a vehicle, Fig. 3 schematically shows a block diagram of another embodiment of a device for transferring a digital vehicle key to a vehicle and

[0105] Fig. 4 schematically shows a block diagram of another embodiment of a device for transferring a digital vehicle key to a vehicle.

[0106] Corresponding parts are marked with the same reference symbols in all figures.

[0107] Figure 1 shows a possible embodiment of a logistics chain LK for a vehicle 1, which is shown in more detail in Figure 2, with several transfer stations US1 to USn.

[0108] The logistics chain LK describes the route of vehicle 1 from a vehicle manufacturer's factory premises to a customer. The factory premises constitute the first station S1 of the logistics chain LK, and the customer is the last station Sm.

[0109] Between these two stations S1 and Sm there are several more

[0110] Stations S2 to Sm-1 are formed, with the logistics chain LK being configured in the illustrated embodiment.

[0111] - Station S2: Transport of vehicle 1 by means of a rail vehicle, - Station S3: Loading station,

[0112] - Station S4: transport of vehicle 1 by means of a truck, - Station S5: loading port,

[0113] - a station S6 transports vehicle 1 by means of a ship,

[0114] - a station S7 a loading port,

[0115] - a station S8 a renewed transport of vehicle 1 by means of a truck and

[0116] - station Sm-1 represents a vehicle dealer.

[0117] There is a [missing information] between each station S1 to Sm.

[0118] Transfer stations US1 to USn are designed at which the vehicle 1 and a digital vehicle key 2, shown in more detail in Figure 2, are transferred. The digital vehicle key 2 is designed in particular according to the standard of the Car Connectivity Consortium (CCC standard).

[0119] The following requirements apply to the handover of the digital vehicle key 2:

[0120] Requirement 1:

[0121] The handover process for the digital vehicle key 2 in the logistics chain LK must not require a classic physical vehicle key, in particular a key fob, at any handover station US1 to USn.

[0122] Requirement 2:

[0123] The handover process for the digital vehicle key 2 in the logistics chain LK must ensure that a user 3, depicted in more detail in Figures 2 to 4, can hand over the digital vehicle key 2 to another user 4, also depicted in more detail in Figures 3 and 4. The other user 4 must not be able to obtain the digital vehicle key 2 without this handover from the first user. This requirement ensures that in insecure environments within the logistics chain LK, such as rest areas, the vehicle 1 is secured against unauthorized access and removal.

[0124] Requirement 3:

[0125] The handover process for the digital vehicle key 2 in the logistics chain LK must enable users 3 and 4 to have the digital vehicle key 2 transferred or provisioned to a mobile device 5 or 6, as shown in more detail in Figures 2 to 4, after users 3 and 4 have proven their direct proximity to the vehicle 1. The other user 4 must not be able to receive the digital vehicle key 2 without this handover from the user 3 or 4. This requirement ensures that, in secure environments within the logistics chain LK, the vehicle 1 can be moved at any time by authorized users 3 and 4, such as logistics employees.

[0126] Requirement 4:

[0127] The transfer of digital vehicle keys 2 from one user to another user 4, for example from one logistics employee to another, should be possible without physical proximity. This requirement increases convenience compared to existing state-of-the-art solutions.

[0128] Requirement 5:

[0129] The transfer of digital vehicle keys 2 from one user to another user 4, for example from one logistics employee to another, should be possible without any temporal proximity. This requirement also increases convenience compared to solutions known from the state of the art.

[0130] Requirement 6:

[0131] The transfer process for the digital vehicle key 2 in the logistics chain LK must enable the transfer of digital vehicle keys 2 from one user structured as a legal entity, for example a logistics company, to another user structured as a legal entity 4, for example a logistics company, without being tied to specific natural persons. This requirement enables the transfer of the digital vehicle key 2 between two legal entities, for example the companies 9 and 10 shown in Figures 2 and 4.

[0132] Requirement 7:

[0133] The handover process for the digital vehicle key 2 in the logistics chain LK must enable the digital vehicle key 2 to be handed over to the customer at the end of the logistics chain LK.

[0134] Requirement 8:

[0135] The handover process for the digital vehicle key 2 in the logistics chain LK must not be less secure with regard to theft protection than the handover of a physical vehicle key, for example key fobs.

[0136] Requirement 9:

[0137] The handover process for the digital vehicle key 2 in the logistics chain LK must ensure that the digital vehicle key 2 is no longer on the mobile device 5, 6 of the original user 3, 4 after its handover. This prevents the duplication of digital vehicle keys 2. Requirement 10:

[0138] If requirement 9 cannot be implemented or if a specific implementation fails, this must be logged in a vehicle-external central computing unit 7, in particular a backend server of the vehicle manufacturer, as shown in more detail in Figures 2 to 4, and reported as a security event in order to take measures to eliminate this risk.

[0139] To meet the aforementioned requirements, the handover process for the digital vehicle key 2 in the logistics chain LK is based on the following principles:

[0140] Principle 1:

[0141] Proof of the user's immediate proximity 3, 4 to a specific vehicle 1 as a condition for obtaining a digital vehicle key 2, without requiring access to a vehicle interior.

[0142] Principle 1 is implemented using near-field communication (NFC) technology. Each vehicle 1 equipped with a digital vehicle key 2 has, according to the CCC standard, an exterior door handle 1.1 (shown in more detail in Figure 2) with a door handle transmitter / receiver unit 1.2 configured for near-field communication. The door handle transmitter / receiver unit 1.2 transmits a unique digital vehicle identifier Fl (also known as a Unique ID), shown in more detail in Figure 2, via near-field communication.

[0143] This vehicle identifier Fl is received by a device transmit-receive unit 5.1, 6.1, shown in more detail in Figures 2 to 4, of a mobile terminal device 5, 6 located within the range of near-field communication. The range is a few centimeters, in particular a maximum of ten centimeters.

[0144] The mobile device 5, 6 transmits the vehicle identifier Fl together with a user identifier NI of user 3, 4 of the device 5, 6 to the processing unit 7. A unique mapping of the vehicle identifier Fl of the door handle transceiver unit 1.2 to a vehicle identification number (VIN) is stored on the processing unit 7. The processing unit 7 therefore concludes that the user 3, 4, whose device 5, 6 transmitted the vehicle identifier Fl, is in close proximity to the vehicle 1 with the associated VIN, since the range of near-field communication is in the centimeter range.

[0145] To prevent an attacker from obtaining a large number of digital vehicle keys 2 by iterating over all possible near-field communication vehicle identifiers Fl, mass queries are prevented by the processing unit 7. Furthermore, the digital vehicle key 2 is only transmitted if a request originates from an authorized user 4, for example, an employee of a logistics company in whose possession the vehicle 1 is located.

[0146] Principle 2:

[0147] Use of a configurable rule set for authorizing the transfer of the digital vehicle key 2 in the logistics chain LK on computing unit 7, in particular a backend server of the vehicle manufacturer. The rule set defines and enforces the conditions under which a transfer of the digital vehicle key 2 can take place and how a specific process for the transfer of the digital vehicle key 2 at the respective transfer station US1 to USn of the logistics chain LK is designed.

[0148] Here, using policy-based and attribute-based authorization, context-specific authorization rules are defined for each transfer station US1 to USn in a logistics chain LK for vehicle 1, specifying the conditions under which the digital vehicle key 2 is transmitted to a mobile device 5, 6. Policy-based authorization is implemented, for example, according to https: / / www.nextlabs.com / products / cloudaz-policy-platform / what-is-policy-based-access-control-pbac / (accessed January 21, 2025). Attribute-based authorization is implemented, for example, according to http: / / docs.oasis-open.org / xacml / 3.0 / xacml-3.0-core-spec-os-en.html (accessed January 21, 2025).

[0149] Since these conditions vary depending on the process step or transfer station US1 to USn in the logistics chain LK, several authorization rules are provided. Which authorization rule is used for an authorization decision depends on the current context. Input variables for rule selection and execution can include, for example, a current transfer station US1 to USn in the logistics chain LK and / or

[0150] - a current time and / or

[0151] - a current geographical position of vehicle 1 and / or

[0152] - an affiliation of the user 3, 4 with a company 9, 10 and / or

[0153] - User permissions 3, 4 and / or

[0154] - a role of user 3, 4 and / or

[0155] - a vehicle identity, in particular described by the vehicle identifier Fl, and / or

[0156] - the existence of a G2 approval authorizing the handover of the vehicle key 2 by a person

[0157] be used.

[0158] Principle 3:

[0159] Authentication and authorization of all participants or users 3, 4 of the handover process at the computing unit 7. Users 3, 4 are natural persons and legal persons, for example companies 9, 10. Companies 9, 10 must be taken into account because different companies 9, 10, for example logistics companies, are involved in the logistics chain LK and rules for authorizing the handover of the digital vehicle key 2 can take the respective companies 9, 10 into account.

[0160] Principle 4:

[0161] Use of an end-device-based application program, also referred to as an application or app, on the mobile end devices 5, 6 of users 3, 4, to establish a data connection to the computing unit 7; in particular, use of a mobile phone or smartphone-based app on end devices 5, 6, each designed as a mobile phone or smartphone.

[0162] The following figures 2 to 4 describe possible embodiments of the transfer of the digital vehicle key 2.

[0163] Figure 2 shows a block diagram of a possible embodiment of a device 8 for transferring a digital vehicle key 2 of a vehicle 1 when a user located in the immediate vicinity of the vehicle 1 requests a transfer of the digital vehicle key 2 to his mobile terminal 5.

[0164] In this process, the user belonging to a company 9, for example a logistics employee of a logistics company, uses the device transceiver unit 5.1 of his mobile device 5, for example smartphones, to detect the vehicle identifier Fl transmitted by the door handle transceiver unit 1.2 of the vehicle 1 via near field communication.

[0165] The vehicle identifier Fl is transmitted to the computing unit 7, specifically a backend server of a vehicle manufacturer, by means of the application program installed on the terminal device 5. Additional information is also transmitted from the terminal device 5 to the computing unit 7, in particular the user identifier NI, also referred to as the user ID.

[0166] The processing unit 7 assigns the vehicle identifier Fl to a corresponding vehicle identification number and checks the request for the transmission of the digital vehicle key 2 via a rule system. For this purpose, the processing unit 7 comprises a process control unit 7.1, a rule set 7.2, and a database 7.3. Using the processing unit 7, the vehicle identifier Fl is assigned to vehicle 1, and the user identifier NI is used to verify whether user 3 has authorization to use the digital vehicle key 2.

[0167] If the control system has reached a positive decision, i.e., user 3 is entitled to receive the digital vehicle key 2 for this vehicle 1, the digital vehicle key 2 is transferred or provisioned by the computing unit 7 to the terminal device 5 of user 3.

[0168] Such a previously described transfer of the digital vehicle key 2 to the terminal device 5 of a user 3 takes place in particular at a first transfer station US1 of the logistics chain LK, for example when the vehicle 1 is handed over from the factory premises of the vehicle manufacturer to a second station S2 of the logistics chain LK.

[0169] The processing unit 7 ensures that the transmitted digital vehicle key 2 is terminated and deleted as soon as a user 3, 4 no longer needs or is no longer authorized to use this digital vehicle key 2. The termination and deletion are carried out primarily based on the CCC standard.

[0170] Figure 3 shows a block diagram of a possible further embodiment of a device 8 for transferring a digital vehicle key 2 of a vehicle 1. This embodiment of the device 8 enables the indirect transfer of a digital vehicle key 2 between mobile devices 5, 6 of two users 3, 4. The users 3, 4 and their devices 5, 6 do not need to be in close proximity to the vehicle 1.

[0171] Here, a request A1 for submission or... is first sent via the terminal device 5, on which the digital vehicle key 2 is active or provisioned.

[0172] The deletion of vehicle key 2 was transmitted to the computing unit 7.

[0173] Using the computing unit 7, after receiving the request A1 for submission, the digital vehicle key 2 is deleted on the terminal device 5 in a deletion process L.

[0174] Using the other user's mobile device 6, a request A2 is transmitted at a transfer station US2 to USn, together with the user identifier NI of user 4, to transfer the digital vehicle key 2 to the vehicle-external central computing unit 7. No temporal proximity is required between requests A1 and A2.

[0175] Using the computing unit 7, the relevant data is used to calculate the value for the specific task.

[0176] The handover station US2 to USn checks, according to the authorization rules defined above, whether the conditions for transferring the digital vehicle key 2 to the further mobile device 6 are met. Furthermore, the computing unit 7 uses the user identifier NI to check whether the user 4 has authorization to use the digital vehicle key 2.

[0177] If the user authorization is granted, the digital vehicle key 2 is transmitted or provisioned to the further terminal device 6 by means of the processing unit 7. The processing unit 7 also ensures, after such a transfer, that the transmitted digital vehicle key 2 is terminated and deleted as soon as a user 3, 4 no longer needs or is authorized to use this digital vehicle key 2. The termination and deletion are carried out primarily based on the CCC standard.

[0178] Such a previously described transfer of the digital vehicle key 2 between end devices 5, 6 of different users 3, 4 takes place in particular at transfer stations US2 to USn following transfer station US1 in the logistics chain LK. Such a transfer can also take place when the digital vehicle key 2 is handed over from the vehicle dealer to the customer at the last transfer station USn in the logistics chain LK.

[0179] Figure 4 shows a block diagram of a possible further embodiment of a device 8 for transferring a digital vehicle key 2 of a vehicle 1. Using this embodiment of the device 8, an indirect transfer of a digital vehicle key 2 is carried out between mobile devices 5, 6 of two users 3, 4. Direct spatial proximity of the users 3, 4 and their devices 5, 6 to the vehicle 1 is not required.

[0180] In addition to the embodiment shown in Figure 3, after the deletion process L has been carried out on the terminal device 5 of the user 3, an authorization G1 to hand over the digital vehicle key 2 from company 9 to company 10 to the computing unit 7 is transmitted by a terminal device 11 of a person 13 belonging to the same company 9 as the user 3, for example a dispatcher belonging to the same logistics company.

[0181] Once this authorization G1 is granted, an authorization G2 for the acceptance of the digital vehicle key 2 by company 10 is transmitted from an end device 12 belonging to a person 14 belonging to the same company 10 as user 4, for example, a dispatcher belonging to the same logistics company, to the processing unit 7. Only when this authorization G2 is granted can user 4 submit the request A2 to transfer the digital vehicle key 2 to the processing unit 7, and, if the user authorization is granted, the digital vehicle key 2 is then transmitted or provisioned to the further end device 6 by the processing unit 7.

[0182] Before the respective approval G1, G2 is granted, the computing unit 7 can transmit a request to grant the approval G1, G2 to the terminal device 11, 12 of the respective person 13, 14.

Claims

Mercedes-Benz Group AG Patent claims 1. Method for handing over a digital vehicle key (2) of a vehicle (1), wherein - a digital unique vehicle identifier (Fl) is transmitted by means of a door handle transmitting and receiving unit (1.2) arranged in or on an exterior door handle (1.1) of the vehicle (1) and designed for near-field communication, - the vehicle identifier (Fl) is received by means of a device transmit-receive unit (5.1, 6.1) of a mobile terminal (5, 6), - the vehicle identifier (Fl) together with a user identifier (NI) of a user (3, 4) of the terminal device (5, 6) is transmitted by means of the terminal device (5, 6) to a central computing unit external to the vehicle (7), - by means of the computing unit (7) the vehicle identifier (Fl) is assigned to the vehicle (1) and it is checked using the user identifier (NI) whether the user (3, 4) has an authorization to use the digital vehicle key (2), and - if the authorization to use is present, the digital vehicle key (2) is transmitted to the terminal device (5, 6) by means of the computing unit (7).

2. Method for handing over a digital vehicle key (2) of a vehicle (1), wherein - using policy-based authorization and attribute-based authorization by means of context-specific authorization rules for each transfer station (US1 to USn) of a logistics chain (LK) for the vehicle (1), it is determined under which conditions the digital vehicle key (2) is transmitted to a mobile device (5, 6), - at a transfer station (US1 to USn) a request (A2) for the transfer of the digital vehicle key (2) to the terminal device (5, 6) to a vehicle-external central computing unit (7) is transmitted by means of the mobile device (5, 6) together with a user identifier (NI) of the user (3, 4), - using the computing unit (7) to check, based on the authorization rules defined for the relevant transfer station (US1 to USn), whether the conditions for the transfer of the digital vehicle key (2) to the mobile device (5, 6) are met, and using the user identifier (NI) to check whether the user (3, 4) has an authorization to use the digital vehicle key (2), and - if the authorization to use the digital vehicle key (2) is transmitted to the terminal device (5, 6) by means of the computing unit (7), unless it is located on another mobile terminal device (5, 6) of another user (3, 4).

3. Method for handing over a digital vehicle key (2) of a vehicle (1), wherein in an initial handover of the digital vehicle key (2) - a digital unique vehicle identifier (Fl) is transmitted by means of a door handle transmitting and receiving unit (1.2) arranged in or on an exterior door handle (1.1) of the vehicle (1) and designed for near-field communication, - the vehicle identifier (Fl) is received by means of a device transmit-receive unit (5.1, 6.1) of a mobile terminal (5, 6), - the vehicle identifier (Fl) together with a user identifier (NI) of a user (3, 4) of the terminal device (5, 6) is transmitted by means of the terminal device (5, 6) to a central computing unit external to the vehicle (7), - by means of the computing unit (7) the vehicle identifier (Fl) is assigned to the vehicle (1) and it is checked using the user identifier (NI) whether the user (3, 4) has an authorization to use the digital vehicle key (2), and - if the authorization to use the vehicle is granted, the digital vehicle key (2) is transmitted to the terminal device (5, 6) by means of the computing unit (7), and wherein in a transfer of the digital vehicle key following the initial transfer, whether directly or indirectly (2) - using policy-based authorization and attribute-based authorization by means of context-specific authorization rules for each transfer station (US1 to USn) of a logistics chain (LK) for the vehicle (1), it is determined under which conditions the digital vehicle key (2) is transmitted to a mobile device (5, 6), - at a transfer station (US1 to USn) a request (A2) for the transfer of the digital vehicle key (2) to the vehicle-external central computing unit (7) is transmitted by means of the mobile device (5, 6) together with a user identifier (NI) of the user (3, 4), - using the computing unit (7) to check, based on the authorization rules defined for the relevant transfer station (US1 to USn), whether the conditions for the transfer of the digital vehicle key (2) to the mobile device (5, 6) are met, and using the user identifier (NI) to check whether the user (3, 4) has an authorization to use the digital vehicle key (2), and - if the authorization to use the digital vehicle key (2) is transmitted to the terminal device (5, 6) by means of the computing unit (7), unless it is located on another mobile terminal device (5, 6) of another user (3, 4) to which the vehicle key (2) was transmitted in the initial transfer or in a transfer immediately or indirectly thereafter.

4. Method according to any one of the preceding claims, wherein - before the vehicle key (2) is transmitted to the terminal device (5, 6) by means of the computing unit (7) a request for approval (G2) of the transmission to a terminal device (5, 6) of a person (14) is transmitted and - the vehicle key (2) is only transmitted to the mobile device (5, 6) of the user (3, 4) if, in addition to the existence of the authorization to use and the condition that the vehicle key (2) is not located on another mobile device (5, 6) of another user (3, 4), the request for authorization (G2) from the computing unit (7) is met with authorization (G2) for the transmission made by the person (14) on their device (5, 6).

5. Method according to one of the preceding claims, wherein authorization information for obtaining the vehicle key (2) and authentication information are stored in the computing unit (7) for different users (3, 4) and / or for different mobile devices (5, 6).

6. Method according to one of the preceding claims, wherein natural persons and / or legal persons are permitted as users (3, 4).

7. Method according to one of the preceding claims, wherein communication between the terminal device (5, 6) and the vehicle (1), the computing unit (7) and a user (3, 4) as well as processing of data transmitted and received for the transfer of the vehicle key (2) on the terminal device (5, 6) is controlled and / or executed by means of an application program executed on the terminal device (5, 6).

8. Method according to one of the preceding claims, wherein the input variables for selecting and executing authorization rules during the handover of the vehicle key are (2) - a current transfer station (US1 to USn) of a logistics chain (LK) and / or - a current time and / or - a current geographical position of the vehicle (1) and / or - the user's affiliation (3, 4) with a company (9, 10) and / or - the user's permissions (3, 4) and / or - a role of the user (3, 4) and / or - a vehicle identity and / or - the existence of an approval (G2) of an authorization of the handover of the vehicle key (2) by a person (14) will be used.

9. Method according to one of the preceding claims, wherein a vehicle identification number is stored in the computing unit (7) for several vehicles (1).

10. Method according to claim 9, wherein the vehicle identification number is used to form the vehicle identifier (Fl).

11. Method according to any of the preceding claims, wherein each transmission of the digital vehicle key (2) to an end device (5, 6) is logged in the computing unit (7).

12. Method according to one of the preceding claims, wherein the vehicle key (2) is automatically deleted on an end device (5, 6) after the occurrence of a predetermined deletion condition.

13. Method according to one of the preceding claims, wherein the vehicle key (2) is transferred from one mobile device (5, 6) to another mobile device (5, 6) - by means of the terminal device (5, 6) on which the vehicle key (2) is active, a request (A1) to surrender the vehicle key (2) is transmitted to the computing unit (7), - is deleted on the terminal device (5, 6) by means of the computing unit (7) after receipt of the request (A1) to hand over the vehicle keys (2), - using the additional mobile device (5, 6) at the The transfer station (US1 to USn) together with the user identifier (NI) of the user (3, 4) transmits the request (A2) for the transfer of the digital vehicle key (2) to the terminal device (5, 6) to the vehicle-external central computing unit (7), - using the computing unit (7) based on the authorization rules defined for the relevant transfer station (US1 to USn), it is checked whether the conditions for the transfer of the digital vehicle key (2) to the further mobile device (5, 6) are met, and using the user identifier (NI) it is checked whether the user (3, 4) has an authorization to use the digital vehicle key (2), and - if the authorization to use the vehicle is granted, the digital vehicle key (2) is transmitted to the further terminal device (5, 6) via the computing unit (7).

14. Method according to claim 13, wherein - before the vehicle key (2) is deleted from the terminal device (5, 6) of the user (3, 4) by means of the computing unit (7) a request for approval (G1) of the deletion is transmitted to a terminal device (11) of a person (13) and - the vehicle key (2) is only deleted from the mobile terminal device (5, 6) of the user (3, 4) if the computing unit (7) receives approval (G1) for deletion from the person (13) on their terminal device (11).

15. Method according to any one of the preceding claims, wherein - before the vehicle key (2) is transferred to the terminal device (5, 6) of the user (3, 4) by means of the computing unit (7) a request for approval (G2) of the transfer to a terminal device (12) of a person (14) is transmitted and - the vehicle key (2) is only transferred to the mobile terminal device (5, 6) of the user (3, 4) if the computing unit (7) receives approval (G2) for the transfer from the person (14) on their terminal device (12).

16. Device (8) for transferring a digital vehicle key (2) of a vehicle (1) with - a door handle transmitter-receiver unit (1.2) arranged in or on an exterior door handle (1.1) of the vehicle (1), which is designed to transmit a digital unique vehicle identifier (Fl) by means of near field communication, - a mobile terminal (5, 6) which has a device transceiver unit (5.1, 6.1) configured to receive the vehicle identifier (Fl) from the door handle transceiver unit (1.2) and configured to transmit the vehicle identifier (Fl) together with a user identifier (NI) of a user (3, 4) of the terminal (5, 6) to a vehicle-external central computing unit (7), and - the vehicle-external central computing unit (7), which is designed to assign the vehicle identifier (Fl) to the vehicle (1) and to check, using the user identifier (NI), whether the user (3, 4) has an authorization to use the digital vehicle key (2), and, if the authorization to use is present, to transmit the digital vehicle key (2) to the terminal device (5, 6).

17. Device (8) for transferring a digital vehicle key (2) of a vehicle (1) with a mobile terminal (5, 6) which is configured to transmit a request (A2) for the transfer of the digital vehicle key (2) to the terminal (5, 6) to an external central computing unit (7) together with a user identifier (NI) of a user (3, 4) of the mobile terminal (5, 6) at a transfer station (US1 to USn), and - the vehicle-external central computing unit (7), which is designed, - using policy-based authorization and attribute-based authorization by means of context-specific authorization rules for each transfer station (US1 to USn) of a logistics chain (LK) for the vehicle (1) to determine under which conditions the digital vehicle key (2) is transmitted to a mobile terminal (5, 6), - to check, based on the authorization rules defined for the relevant transfer station (US1 to USn), whether the conditions for the transfer of the digital vehicle key (2) to the mobile device (5, 6) are met, - to check, based on the user identifier (NI), whether the user (3, 4) has an authorization to use the digital vehicle key (2), and - if the authorization to use exists, to transmit the digital vehicle key (2) to the device (5, 6) if it is not located on another mobile device (5, 6) of another user (3, 4).