Motor Vehicle Access Control via Personal ID Token Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current car-sharing systems require prior scheduling and involve operators in the rental process, limiting flexibility and convenience for users.
Innovation Solution
A method for controlling access and use of motor vehicles using a data processing system that employs a network for secure authentication and authorization, allowing users to access vehicles without prior scheduling through the use of a personal ID token, soft tokens, and cryptographically secured connections, enabling ad-hoc rentals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If prior scheduling and operator involvement are required for vehicle rental, then access control and authorization can be managed centrally, but user flexibility and convenience are reduced
Solution Approach 1:
The system enables users to autonomously authenticate and access vehicles using their personal ID tokens without requiring operator intervention or prior scheduling. The control computer in the vehicle directly communicates with the user's ID token to verify authorization, allowing self-service vehicle access.
Solution Approach 2:
The invention extracts the essential authentication function from the centralized booking system, allowing users to access vehicles independently. The personal ID token contains pre-stored authorization data that enables direct verification with the vehicle's control computer, removing the need for continuous connection to the central booking system.
2Adaptability or versatility
If prior scheduling is required for vehicle access, then rental operations can be coordinated and monitored, but ad-hoc rentals and spontaneous use are limited
Solution Approach 1:
The system performs preliminary authentication by storing authorization data in the user's personal ID token during the initial registration process. This pre-stored authorization enables immediate vehicle access without requiring time-consuming booking procedures at the moment of use.
Solution Approach 2:
Users can spontaneously access vehicles at any time by presenting their pre-authenticated ID token to the vehicle's control computer, enabling ad-hoc rentals without scheduling delays or operator coordination.
3Ease of operation
If centralized booking systems are used for vehicle access, then rental management is simplified, but direct user access to vehicles is restricted
Solution Approach 1:
The system implements localized authentication by embedding authorization data directly in the user's personal ID token. Each vehicle's control computer independently verifies the token's authorization data locally, eliminating the need for continuous centralized system involvement while maintaining security through cryptographic verification.
Solution Approach 2:
The personal ID token serves as an intermediary that carries pre-stored authorization data from the centralized system to the vehicle. This intermediary enables direct user-vehicle communication while maintaining the security guarantees of the centralized authorization system.
Data Source
Figure 1
AI summary
The invention relates to a computer-implemented method for controlling the access to and usage of a motor vehicle (500), comprising the steps of: - transmitting a user log-on signal from a log-on computer (100) to a service computer (200) via a network (700); - requesting, from an ID provider computer (300), data relating to a number of attributes from a user's personal ID token (800), via the network and using said service computer; - authenticating the user in relation to the ID token, and authenticating the ID provider computer in relation to the ID token, via the network, as a condition for reading the data relating to the attributes from the ID token, using the ID provider computer, via the network and with end-to-end encryption; - transmitting the data relating to the attributes, read from the ID token, from the ID provider computer to the service computer via the network; - generating a soft token (800) using the service computer by signing a data structure consisting of the data relating to the attributes transmitted from the ID provider computer, as well as a non-plain text depiction of an authentication code (820) with the private key (210) of an asymmetrical key pair; - transmitting the generated soft token to a user's personal mobile computer (600) in order to be stored, via the network; - transmitting said stored soft token from the selected user's personal mobile computer to a control computer (520) that is connected to the motor vehicle; - testing the validity of the signature of the soft token using the control computer, with the public key (524) of the asymmetrical key pair, as a condition for emitting a signal for unlocking the vehicle locking system; - comparing an input of the user into an input device (526), associated with the control computer, to said non-plain text depiction of the authentication code contained in the soft token, as a condition for emitting a signal for deactivating a motor vehicle immobiliser; and - acquiring and storing data, for the use of said motor vehicle, in the control computer, and using the control computer to transmit the stored data to the service computer when a network connection is available.