Method for automatic resynchronization of the transmitter/receiver pair in a remote keyless entry system
Abstract
THE CORRUPTED MEMORY IS DETECTED DURING THE COMMUNICATION SEQUENCE GENERATING A CHECK SUM OF THE AUTHENTICATION CODE AT THE BEGINNING OF THE COMMUNICATION SEQUENCE AND COMPARING IT WITH A PREVIOUSLY STORED CHECK SUM. IF THE CHECK SUMS DO NOT MATCH, A RESYNCHRONIZATION SEQUENCE IS INITIATED IN WHICH RANDOM NUMBERS ARE GENERATED BY THE TRANSMITTER AND ISSUED TO THE RECEIVER FOR SUBSEQUENT USE AS LINEAR FEEDBACK OR CODE DISPLACEMENT RECORD VARIABLES.

Term
Term ended
Projected expiry passed 7 November 2014, 11.9 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
5 claims: 1 independent, 4 dependent
- 1ES 2 145 253 T3 IS 2 145 253 T3 CLAIMS REIVINDICACIONES 1. A method of synchronizing transmitter and receiver in a keyless entry system, characterized by:1. Un método de sincronizar transmisor y receptor en un sistema de entrada sin llave, caracterizado por: calcular (22) y almacenar un primer céodigo de verificacioén de error indicativo del estado del transmisor en un primer tiempo;calculating (22) and storing a first error verification code indicative of the state of the transmitter in a first time;iniciar (20) una secuencia de comunicaciéon entre el transmisor y el receptor;initiate (20) a communication sequence between the transmitter and the receiver;automatically calculating, in response to the initiation of a communication sequence, a second error verification code indicative of the state of the transmitter in a second time;calcular automaéticamente, en respuesta a la iniciacioén de una secuencia de comunicaciéon, un segundo coédigo de verificaciéon de error indicativo del estado del transmisor en un segundo tiempo;comparar (24) los céodigos de verificacioén de error primero y segundo y si dichos coédigos son diferentes, iniciar automaéticamente una secuencia de resincronizaciéon entre dicho transmisor y receptor. compare (24) the first and second error verification codes and if said codes are different, automatically start a resynchronization sequence between said transmitter and receiver.
36 paragraphs in 3 sections, as filed
IS 2 145 253 T3
DESCRIPTION
Procedure for the resynchronization of the sender / receiver pair in a remote keyless entry system.
Background and summary of the invention
The present invention relates generally to keyless entry systems. More in particular, the invention relates to a method to automaotically resynchronize the transmitter / receiver pair when synchronization is lost due to momentary power failure or a low battery condition, for example.
Authentication by circulating code is a common form of vehicle entry security. In such a system, a transmitter in the form of a keyfob is provided and a receiver is placed in the vehicle where it is capable of receiving a coded transmission from the keyfob transmitter. The circulating code authentication can be performed using a simple linear counter that advances with each command of the key command. The receiver in the vehicle is configured to always wait for an increasing value and therefore prevents the repetition of counter values. Even to be in sync, the transmitter's counter should never fall behind the receiver's count, nor should the transmitter's counter allow it to go too far ahead of the receiver's count. More complex authentication using Linear Displacement Feedback Register (LFSR) technology is also used as a more secure technique for vehicle entry security.
For various reasons, a circulating code authentication system can occasionally fall out of sync when the transmitter's counter values are lower than the receiver's or when the transmitter's counter values are greater than the receiver's by a predetermined number. One reason for loss of timing is corrupted volatile memory, which may be due to momentary loss of battery power or low battery voltage.
One way to avoid loss of timing is to install a non-volatile memory such as an EEPROM in the transmitter that can be used to store circulating values so that they are not lost. Being non-volatile, the EEPROM did not go out of sync due to a power outage (eg loose battery connection or battery failure). The EEPROM protects the integrity of the counters when the internal RAM is not receiving power.
However, EEPROM devices are comparatively expensive and it would be desirable to remove them from circulating code authentication circuitry. This presents a problem, since without non-volatile memory, a system would have to rely on RAM (volatile memory) to store counter values. The need to rely on RAM increases the possibility of corrupted counter values, since even temporary loss of power due to a loose battery connection or loss of battery charge destroyed the timing.
In US Patent No. 5,191,610, a remote operating system for the remote system is detailed. Here, a device is remotely controlled to provide secure communication of coded messages between a transmitter and receiver of the system, and to perform automatic resynchronization of the transmitter and receiver without revealing the loss of synchronization to the operator. A pseudo-random binary number generator ("PRBN") in the transmitter produces a sequence of identifying numbers. Each time the transmitter is activated, the identification number contained in the transmitted encoded message is selected as the next number in the sequence of identification numbers. A PRBN generator in the receptor produces a reference number sequence that is identical to the identification number sequence. The receiver responds to an order code portion of the transmitted encoded message to operate the device when there is identity between the reference number and the identification number. The receiver responds to the transmitted message when there is no identity between the reference number and the identification number provided that a reference number identical to the identification number is generated within a search length in the sequence of the reference numbers, thereby providing automatic resynchronization of the transmitter and receiver. If a reference number that matches the identification number is not within the search length, the transmitter is controlled to produce a resynchronization signal to resynchronize the receiver to the transmitter.
The present invention addresses the problem of timing by providing a system that automaotically resynchronizes the transmitter / receiver pair when corrupted memory is detected. Ordinarily, the user is not even aware that resynchronization is being carried out. This is done by calculating and storing a first checksum indicative of the status of the transmitter at a first time. Afterwards, the communication sequence between transmitter and receiver is started and the initiation of this sequence automatically causes a second checksum to be calculated. The second checksum is indicative of the state of the transmitter at the second beat. The checksums are compared and if the checksums are different, the resynchronization sequence is started automatically.
For a more complete understanding of the invention, its objects and advantages, reference may be made to the following specification and the attached drawings.
Brief description of the drawings
FIG. 1 is a block diagram of an exemplary four-bit linear feedback shift register useful in understanding the principles of the invention;
Figure 2 is a general flow chart illustrating the principles of the invention.
Figures 3-6 are flowcharts detailing the synchronization method of
The invention is 2 145 253 T3.
Description of the preferred embodiment
To understand the timing method, some understanding of linear feedback shift register technology may be helpful, since the invention can be used with LFSR security systems. Accordingly, a four-bit linear feedback shift register (LFSR) is illustrated at 10 in Figure 1. The shift register includes four memory cells in which four bits are stored, designated bit 3, bit 2 ..., bit 0, consecutively. The shift register is configured so that each cycle or rotation causes the content of a bit to be shifted or transferred to its next right (with the exception of bits that feed an exclusive OR device).
The LFSR device also includes one or more exclusive-OR operations. In figure 1 a unique or exclusive OR 12 has been illustrated, its output supplying bit 0 and with its inputs connected to the output of bit 1 and the output of bit 0, as illustrated. Thus, with each cycle or rotation, the content of bit 1 is combined with the content of bit 0 in an exclusive OR operation and the resulting is then stored in bit 0. The linear feedback shift register 10 illustrated in FIG. 1 is merely an example. In practice, the shift register can be any number of bits, typically a number greater than four bits, and the number and position of the exclusive OR operations can be varied to provide different encryption codes.
In the keyless entry system, the linear feedback shift register operates by rotating the authentication bits, n times, through the shift register with exclusive OR feedback taps between a few bit positions. With each transmission, the transmitter performs a linear feedback shift register (LFSR) shift operation, which encrypts the authentication information and sends this encrypted authentication information to the receiver along with the selected command (open, close, trunk, etc.) . An identical LFSR operation is performed on the receiver authentication variables at the receiver after receiving a command from the transmitter. The receiver compares the results of its own LFSR operation with the authentication variables sent by the transmitter. Authentication information is validated if the receiver's match matches.
A timing problem can arise when transmitter authentication variables are lost due to power outages. The present invention provides a method to automatically detect corrupted authentication variables and perform a resynchronization of the variables.
With reference to Figure 2, an overview of the synchronization method was given. Later, a detailed explanation was given using Figures 3-6. With reference to Figure 2, the synchronization method is invoked automaotically when the transmission sequence is initiated by a key pressed by the user. This is illustrated in step 20. In response to step 20, a checksum is calculated in step 22 and this checksum is compared to a checksum calculated during the previous transmission sequence. If the checksums match, the order selected by the user is sent as indicated in step 30. On the other hand, if the checksums do not match, a resynchronization order and a series of resynchronization variables are sent in the step 26. A new checksum is then calculated in step 28 and the routine branches again to repeat steps 22 and 24.
From figure 2 it can be seen that if the checksums do not coincide, due to a temporary loss of power and the loss resulting from the stored checksum, for example, the resynchronization routine guarantees that a checksum coincides in the cycle following. Furthermore, by virtue of step 26, resynchronization variables are supplied to the receiver so that it can also match the new authentication code.
With reference to Figure 3, the synchronization method is illustrated, starting at the point where a key command key is pressed (state 100). From this state control proceeds to step 102 where the previously stored checksum is compared to the newly calculated checksum. If the checksums match, the memory is declared uncorrupted. On the other hand, if the checksums do not match, the memory is declared corrupted. Thus, at step 104, if the memory is not corrupted, control passes to step 106. Step 106 leads last to step 122 where the user-selected command is executed. On the other hand, if the memory is corrupted, control passes to step 126, so synchronization is restored. In what follows, both possibilities will be explained.
If the memory is not corrupted
When the memory is not corrupted as determined in step 104, the user keyboard input is bounced and decoded by the transmitter's microprocessor. This is illustrated in step 106. Next, the circulating code of the transmitter or cryptographic algorithm is sequenced, as indicated in step 108. Additional details regarding the sequencing operations are set forth in connection with Figures 4 and 5.
Once the circulating code has been sequenced, the transmitter assembles a message in step 110 and this message is broadcast in step 112 by RF or IR transmission to the receiver located in the vehicle. The vehicle receiver then receives the transmitted message in step 114, after which the receiver performs its circulating code sequencing or cryptographic algorithm in step 116. At this point, the authentication codes generated in steps 108 and 116, respectively, are compared in step 118. If the authentication codes match and if the transmitted command is properly decoded, then the transmitter is considered to be authentic in step 120 and the process order is performed in step 122.
IS 2 145 253 T3
In the alternative, if the authentication codes do not match, or if the transmitted command is not significantly decoded, then step 120 will cause the process to branch to step 124 in which the sequence is considered to be out of sync or out of sync. alternatively, an invalid key command transmitter can be assumed. In other terms, the wrong transmitter was used in step 124 (in which case the command was never successful) or the correct transmitter was used but was out of sequence with the receiver. If the memory is corrupted - The resynchronization procedure
If the memory is declared corrupted in step 104, control passes to step 126, where the resynchronization procedure begins. The transmitter initializes its counter in step 126 and loads its LFSR variables with random numbers. The transmitter then mounts a message in step 128 and this message is transmitted by RF or IR transmission in step 130 to the receiver. Next, a transmitter RAM checksum is calculated and stored in step 132. Then, a comparison is made at step 134 to determine if any of the last five numbers stored in the receiver match those emitted by the transmitter. (Although the preferred embodiment checks for five numbers, a larger or smaller set of numbers could be used if desired.) If no number matches, step 134 is declared failed and the LFSR variables sent by the transmitter are rejected by the receptor. In this case, the receiver and transmitter are out of sync. On the other hand, if any of the last five resynchronization numbers match, resynchronization is declared successful. After this declaration in step 136, the receiver acquires the resynchronization variables sent by the transmitter and places them in its own circulating code LFSR variable registers, after which the transmitter and receiver would then contain the same LFSR and signal variables. counter and therefore are in sync.
Other details of the implementation
The LFSR sequence used by both the transmitter and receiver is illustrated in Figure 4. Starting at step 140, the sequence proceeds to step 142, where the number of bytes in the sequence is supplied and a software loop is initiated to perform the LFSR rotation. As previously explained, one or more exclusive-OR operations can be interposed between selected bits of a given byte or word. (In figure 1 a unique exclusive OR operation was placed between bit 1 and bit 0). In step 142, the selected position of one or more exclusive-OR operations is set so that the appropriate exclusive-OR operations will occur as the cycle progresses. If desired, the selected configuration of exclusive OR operations can be supplied as a digital word or "mask" to be applied as a setting parameter. Alternatively, the mask can be permanently or semi-permanently inserted into the system or programmed into the system by the manufacturer or dealer.
Then, in step 144, a byte is inserted into the LFSR RAM variable so that the LFSR sequence can be performed on it. This is illustrated in steps 146, 148 and 150. In step 146 a clockwise operation is performed on the LFSR variable, with the most significant bit (MSB) having a forced zero in its carry register. Exclusive OR operations are performed in step 148, the resultant being sent as feedback terms according to the set mask established in step 142. Then, in step 150, the rotated byte resulting from steps 146 and 148 is stored in a temporary memory position. Next, in step 152, if there are additional bytes queued for rotation, the sequence returns to step 144 where the next byte is taken and the process is repeated.
Once all the bytes have been rotated according to steps 144-150, the temporary memory (stored as step 150) is written to the variable LFSR in RAM and control returns (step 156) to the requesting program.
Figure 5 illustrates, beginning at step 158, the way of sequencing the circulating codes. As illustrated in step 160, the circulating counter variable is retrieved from RAM, this variable is then incremented by one (step 162) and stored back in RAM (step 164). Control then returns to the requesting program (step 166).
The presently preferred embodiment mounts transmitter messages as illustrated in Figure 6. Beginning at step 168, the transmitter message is assembled by first putting the transmitter ID in the first transmit byte (step 170). Next, it is decided (step 172) whether the message is a resynchronization message or a regular command. The regular commands are assembled (step 174) by putting the circulating bits and the LFSR data in the next 39 bits to be transmitted. If the command is a resynchronization command, the message is assembled by first generating or taking random numbers (step 176) that serve as initial LFSR / circulating number variables. Next, in step 178, the exclusive OR resynchronization command is entered into the message. Then (step 180) the resynchronization bits are placed in the message along with the desired command in the next 39 transmission bits.
Once the message has been mounted (regular or resynchronized), an error correction code or checksum is calculated for that message and is also placed in the message in the last transmission byte position. In this way, the message to be sent by the transmitter to the receiver is assembled. The receiver is also capable of decoding the message by following the reverse procedure. After mounting the message, the routine returns (step 184) to its requesting program.
Although a circulating code authentication using linear feedback shift register technology has been illustrated, the method of synchronizing transmitter and receiver is not limited to LFSR techniques. In general, the invention can be used with any cryptographic authentication that is capable of supporting the checksum technique.
Contents3
3 sheets
Sheet 1 Sheet 2 Sheet 3
9 members in 7 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 14866893 | United States of America | A | |
| 14866893 | United States of America | A | |
| 19930148668 | United States of America | – | |
| 148668 | – | – | – |
| US19930148668 | – | – | – |
Members9
| Document | Office | Kind | |
|---|---|---|---|
| WO9512940A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP0727117A1 | European Patent Office (EPO) | A1 | |
| CN1134206A | China | A | |
| JPH09504925A | Japan | A | |
| US5646996A | United States of America | A | |
| EP0727117B1 | European Patent Office (EPO) | B1 | |
| DE69423509D1 | Germany | D1 | |
| ES2145253T3This record | Spain | T3 | |
| DE69423509T2 | Germany | T2 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Definitive protectionFG2A | FG2A |
Numbers
- Publication
- 2145253
- Publication, DOCDB
- 2145253
- Publication, EPODOC
- ES2145253T
- Application
- 95901799
- Application, DOCDB
- 95901799
- Application, EPODOC
- ES19950901799T
Titles2
- Spanish
- PROCEDIMIENTO PARA LA RESINCRONIZACION DEL PAR EMISOR/RECEPTOR EN UN SISTEMA DE ENTRADA SIN LLAVE A DISTANCIA.
- English
- PROCEDURE FOR THE RESYNCHRONIZATION OF THE EMITTER / RECEIVER PAIR IN AN ENTRY SYSTEM WITHOUT REMOTE KEY.
Classification
- CPC, 7
- G07C9/00182
- G07C2009/00253
- G07C2009/00769
- G07C2209/06
- H04L9/12
- H04L9/3226
- H04L9/3242
- IPC, 10
- E05B49 00
- B60R25 01
- B60R25 10
- B60R25 24
- E05B65 20
- G07C9 00
- G09C1 00
- H04L9 12
- H04L9 20
- H04L9 32