In-Vehicle System Login Using NFC Binding Code Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current in-vehicle system login methods lack a balance between convenience and security, with Bluetooth-based methods being vulnerable to relay attacks and remote login methods requiring advance user intervention, leading to poor user experience.
Innovation Solution
A near field communication-based method for logging into an in-vehicle system involving a mobile terminal and vehicle, where a login binding code is negotiated and verified by a network side device to facilitate secure and convenient login without requiring user presence at the vehicle.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If Bluetooth near field communication is used for login, then the login process can be completed automatically without advance user intervention, but the system becomes vulnerable to relay attacks and security is compromised
Solution Approach 1:
The patent introduces a login binding code as an intermediary verification element between the mobile terminal and the in-vehicle system. This code serves as a mediator that proves the authenticity of the near field communication connection without exposing sensitive authentication data, thereby maintaining both convenience and security
Solution Approach 2:
The system performs preliminary binding between the mobile terminal and the in-vehicle system by generating and storing a login binding code before actual login occurs. This preliminary action creates a secure association that enables automatic login while preventing relay attacks, as the binding code is specific to the authenticated connection
2Reliability
If remote login via TSP is used, then login security is improved by avoiding Bluetooth vulnerabilities, but user experience deteriorates due to requirement of advance user intervention and boarding time determination
Solution Approach 1:
The system performs preliminary binding between the mobile terminal and the in-vehicle system by generating and storing a login binding code before actual login occurs. This preliminary action creates a secure association that enables automatic login while preventing relay attacks, as the binding code is specific to the authenticated connection
Solution Approach 2:
The system enables self-service automatic login by utilizing the pre-established binding relationship. When the mobile terminal approaches the vehicle, the system automatically retrieves and uses the stored login binding code to complete authentication without requiring user intervention, thereby improving ease of operation while maintaining security
3Ease of operation
If account information is stored locally in the vehicle, then login can be completed automatically, but security is compromised as the vehicle becomes a target for attacks
Solution Approach 1:
The patent extracts the critical authentication element (login binding code) from the vehicle's local storage and keeps it primarily in the mobile terminal. The vehicle only stores minimal identification information, while the mobile terminal holds the sensitive binding code that proves authentication, thereby reducing the vehicle's attack surface while maintaining automatic login capability
Data Source
AI summary
Establishing, by a mobile terminal, a near field communication link to a vehicle, where the vehicle corresponds to the in-vehicle system; negotiating a login binding code with the vehicle through the near field communication link; and providing the login binding code to a network side device, where the login binding code is used by the network side device to verify whether the in-vehicle system can be logged in to with the first user account.


