Vehicle Access Authorization via Encrypted Mobile Data Carrier

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing drive authorization systems for vehicles require personal access passwords for authentication, which are not suitable for allocating storage areas to companies, and lack efficient methods for secure, economic, and scalable access authorization management, especially in rental or shared vehicle scenarios.

Innovation Solution

A device and method utilizing a mobile communication device with a data carrier having protected storage areas, where authorization data is encrypted and transmitted from a database server, enabling secure, scalable, and efficient allocation of access and driving authorizations without relying on the mobile device's operating system, allowing for near-field communication and wireless energy transmission, and facilitating easy blocking of authorizations if necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If personal access passwords are used for authentication in existing drive authorization systems, then user authentication is enabled, but the system cannot allocate storage areas to companies and lacks scalability for rental or shared vehicle scenarios

Engineering Contradiction:
Improveallocation flexibility to companiesVSAvoidauthorization management system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authorization system by introducing separate authorization data structures that are independent of personal access passwords. The authorization data is divided into company-specific segments that can be allocated to different entities, enabling flexible assignment while maintaining system security through structured data organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authorization management layer that sits between the personal authentication system and the vehicle access control. This intermediary layer handles the allocation and management of authorization data, enabling company-specific storage area allocation without requiring changes to the underlying authentication infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If authorization data is stored on mobile communication devices, then access availability is improved, but security risks increase from infected devices or battery failure

Engineering Contradiction:
Improveaccess availabilityVSAvoidsecurity against infected devices
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements beforehand cushioning by designing the authorization system to be independent of the mobile device's operational state. The authorization data is structured to be verifiable without requiring the device's operating system, battery, or software to be functional, thus cushioning against security risks from infected or battery-less devices.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The patent replaces reliance on the mobile device's mechanical and software systems (battery, operating system, processors) with a cryptographic verification system. The authorization data contains embedded verification mechanisms that can be validated through mathematical proofs rather than requiring the device's hardware or software to be operational.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If traditional key systems are used for vehicle access, then security is maintained, but convenience and remote authorization management are limited

Engineering Contradiction:
Improveremote authorization managementVSAvoidauthorization system infrastructure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent makes the mobile communication device universal by enabling it to serve both as a standard communication device and as a vehicle authorization key. The same device can store and present authorization data for multiple vehicles and multiple companies, eliminating the need for separate physical keys while maintaining security through cryptographic verification.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses copying by creating digital replicas of authorization credentials that can be distributed remotely. Instead of physical keys, the system creates and distributes digital authorization data that can be copied to mobile devices, enabling remote provisioning and management of vehicle access rights without physical contact or complex infrastructure.

Inventive Principle:
Principle #26Copying

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution provides a secure, scalable, and economically viable method for managing access and driving authorizations, ensuring high availability and security, even with infected or battery-less mobile devices, and allows for easy temporary use and blocking of authorizations, particularly beneficial for rental and shared vehicles.

Implementation Method 1

a database server, by means of which the authorization data can be transferred in encrypted form to the data carrier, has data storage authorization for this protected storage area

Methodology Applied
Scientific EffectEncryption:

Implementation Method 2

allowing for near-field communication and wireless energy transmission

Methodology Applied
Scientific EffectNear Field Communication:

Implementation Method 3

a control unit in the vehicle which receives and verifies authorization data sent by the mobile communication device

Methodology Applied
Scientific EffectData verification:

Data Source

PatentEP2864967B1Device and method for controlling an access authorisation and/or driving authorisation for a vehicle
Publication Date: 2019.04.10 MERCEDES BENZ GROUP AG
  • EP2864967B1 patent drawingFigure 1~2

AI summary

The invention relates to a device (1) for controlling an access authorisation and/or a driving authorisation for a vehicle (2), the device comprising at least one mobile communications device (3) and a control unit (5) in the vehicle (2), the control unit receiving and checking authorisation data transmitted by the mobile communications device (3), wherein the mobile communications device (3) has a data carrier (6) for storing the authorisation data. According to the invention, the data carrier (6) has at least one protected memory area (C1-Cn) for storing the authorisation data, wherein a database server (4), by means of which the authorisation data can be transmitted in encrypted form to the data carrier (6), has a data storage authorisation for this protected memory area (C1-Cn). The invention further relates to a method for controlling an access authorisation and/or driving authorisation for a vehicle (2).