Using trust points to provide services
8 claims: 3 independent, 5 dependent
- 1複数のトラストポイントシステムと通信するよう動作する1つ以上のインタフェースと、 1つ以上のプロセッサであり、前記複数のトラストポイントシステムのうちの第1のトラストポイントシステムから受信した第1のトラストポイント情報を用いて、該第1のトラストポイントシステムを検証し、 該 検証に成功した後、 自装置及び該第1のトラストポイントシステムを検証させるために、 該第1のトラストポイント情報に含まれる情報と、自装置についての情報とを含むトラストポイント情報を生成して、前記複数のトラストポイントシステムのうちの第2のトラストポイントシステムに送信するよう動作する1つ以上のプロセッサと を有し、 前記プロセッサは更に、前記第1のトラストポイントシステムから受信した複数のタスクを有するタスクリストを前記第2のトラストポイントシステムに送信し、該第2のトラストポイントシステムから受信する前記複数のタスクのためのルートに沿って移動するよう車両に命令する処理を実行するよう動作する、 システム。
- 2前記プロセッサは更に、車両の電池の電池情報を充電トラストポイントシステムに送信し、該車両に対応する決済情報を前記充電トラストポイントシステムに送信して、前記充電トラストポイントシステムが該電池を充電することを可能にする処理を実行するよう動作する、 請求項1に記載のシステム。
- 3前記プロセッサは更に、車両に関する警備上のトリガー事象を前記第2のトラストポイントシステムへ送信し、該車両の車両環境を記録し、該記録を該第2のトラストポイントシステムに送信する処理を実行するよう動作する、請求項1に記載のシステム。
- 4前記プロセッサは更に、車両の運転データを収集し、該運転データを前記第2のトラストポイントシステムにおける該車両の1つ以上の排出物を計算することに用いられるデータとして送信する処理を実行するよう動作する、請求項1に記載のシステム。
- 5複数のトラストポイントシステムと通信するよう動作する装置のプロセッサによって実行される方法であって、 前記複数のトラストポイントシステムのうちの第1のトラストポイントシステムから受信した第1のトラストポイント情報を用いて、該第1のトラストポイントシステムを検証するステップと、 該 検証に成功した後、 自装置及び該第1のトラストポイントシステムを検証させるために、 該第1のトラストポイント情報に含まれる情報と、自装置についての情報とを含むトラストポイント情報を生成して、前記複数のトラストポイントシステムのうちの第2のトラストポイントシステムに送信するステップと、 前記第1のトラストポイントシステムから受信した複数のタスクを有するタスクリストを前記第2のトラストポイントシステムに送信するステップと、 該第2のトラストポイントシステムから受信する前記複数のタスクのためのルートに沿って移動するよう車両に命令するステップと を有する方法。
- 6当該方法は更に、車両の電池の電池情報を充電トラストポイントシステムに送信し、該車両に対応する決済情報を前記充電トラストポイントシステムに送信して、前記充電トラストポイントシステムが該電池を充電することを可能にするステップを有する、 請求項5に記載の方法。
- 7車両に関する警備上のトリガー事象を前記第2のトラストポイントシステムへ送信し、該車両の車両環境を記録し、該記録を該第2のトラストポイントシステムに送信するステップ、を更に有する請求項5に記載の方法。
- 8車両の運転データを収集し、該運転データを前記第2のトラストポイントシステムにおける該車両の1つ以上の排出物を計算することに用いられるデータとして送信するステップ、を更に有する請求項5に記載の方法。
Independent claims8
90 paragraphs, as filed
0001The present invention relates generally to information exchange, and more specifically to providing services using trust points.
0002Services provided to clients may require sending confidential information over a communication network. For example, when a client sends a service request to a service provider, the service provider may request payment information from the client. The sender of confidential information may wish to authenticate the recipient prior to sending the information.
<p num="0003"> According to the present invention, the drawbacks and problems associated with the conventional service providing technology can be alleviated or eliminated.</p>
<p num="0004"> In certain embodiments, the processor may operate to establish trust with the trustpoint system by performing user authentication, platform authentication and environmental authentication. The processor may communicate information with the trustpoint system in response to establishing trust. In certain embodiments, multiple trustpoint systems work together to provide a variety of services, such as escort services, battery charging services, vehicle security services and / or emission reporting services.</p>
<p num="0005"> Certain embodiments of the invention may provide one or more technical advantages. The technical advantage of one embodiment is that the mobile device may include a trustpoint system that may allow the mobile device to be serviced more efficiently. Another technical advantage of one embodiment is that multiple trustpoint systems may work together to provide a variety of services, such as escort services, battery charging services, vehicle security services and / or emission reporting services. That is.</p><p num="0006"> Certain embodiments of the present invention may include some or all of the above-mentioned technical advantages, or may not include the above-mentioned technical advantages. One or more other technical advantages will be apparent to those skilled in the art from the drawings, description and claims contained herein.</p>
0007For a more complete understanding of the present invention and its features and advantages, the following detailed description will be referred to with the drawings including the following figures.<figref num="1">It is a figure which shows an example of the network which one or more service systems provide a service to one or more client systems.</figref><figref num="2">It is a figure which shows an example of a client system.</figref><figref num="3A">It is a figure which shows an example of the method of providing an escort service.</figref><figref num="3B">It is a figure which shows an example of the method of providing an escort service.</figref><figref num="3C">It is a figure which shows an example of the method of providing an escort service.</figref><figref num="4">It is a figure which shows the example of the method of providing a battery charging service.</figref><figref num="5">It is a figure which shows the example of the method of providing a battery charging service.</figref><figref num="6">It is a figure which shows the example of the method of providing a battery charging service.</figref><figref num="7A">It is a figure which shows the example of the method of providing a battery charging service.</figref><figref num="7B">It is a figure which shows the example of the method of providing a battery charging service.</figref><figref num="7C">It is a figure which shows the example of the method of providing a battery charging service.</figref><figref num="8A">It is a figure which shows the example of the method of providing a battery charging service.</figref><figref num="8B">It is a figure which shows the example of the method of providing a battery charging service.</figref><figref num="9">It is a figure which shows an example of the method of providing a vehicle security service.</figref><figref num="10">It is a figure which shows an example of the method of providing the emission report service.</figref>
0008The embodiments of the present invention and their advantages are best understood by reference to FIGS. 1-10. Similar reference numerals are used for similar parts and corresponding parts in various figures.
0009FIG. 1 shows an example of network 2 in which one or more service systems 10 serve one or more client systems 20. Systems 10 and 20 may include a trustpoint system (TPS) 12 that can be used to establish trust between systems 10 and 20. In certain embodiments, the mobile device may include a trustpoint system 12 that may allow the mobile device to participate more efficiently in providing the service. In certain embodiments, these trustpoint systems 12 work together to provide a variety of services, such as escort services, battery charging services, vehicle security services and / or emission reporting services.
0010In the illustrated example, network 2 includes one or more service systems 10 coupled to one or more client systems 20 via a communication network 18. Service system 10 may provide one or more services to one or more client systems 20. Examples of services include escort, battery charging, vehicle security and / or emission reporting services. Other examples of services include managing software and / or firmware updates and / or status.
0011Examples of service system 10 include vehicle service centers, traffic information centers, charging systems, payment systems, and other systems capable of servicing client system 20. The vehicle service center can be a center that assists in providing services to the vehicle. A traffic information center may include a center that holds real-time traffic information that can be used to plan driving routes. The charging system may be a system capable of charging the power supply (eg, battery) of the client system 20 (eg, vehicle). The payment system can be a system capable of authorizing payments for services. Examples of payment systems may include banks, credit card companies, credit bureaus, companies, or other suitable organizations capable of accrediting rewards for services.
0012The service system 10 may include features that allow the service system 10 to communicate securely with other entities. For example, the service system 10 may include a trustpoint system 12 that establishes trust with other entities. The trust point system 12 will be described in more detail later. As another example, the service system 10 may include a server that manages the security policy used to authenticate other entities. A security policy may specify a set of attribute values that must be met before the client system 20 is granted permission to access the service.
0013The client system 20 can receive services from the service system 10. Examples of client systems 20 include computers, mobile devices and vehicles. Hereinafter, these are also referred to as a computer client system, a mobile client system, and a vehicle client system, respectively.
0014The computer may be any computing device, such as a server, a notebook computer, or a desktop computer. The mobile device may be a handheld device capable of wireless communication or the like. Examples of mobile devices include telephones (eg, mobile phones, mobile phones or smartphones, etc.), personal digital assistants (eg, for individuals or businesses), and gaming devices. The vehicle can be a device designed to transport humans and / or cargo. Examples of vehicles include land transport aircraft (eg, automobiles, trains, bicycles and motorcycles, etc.), and aircraft (eg, airplanes). In certain embodiments, the vehicle may include a transmitter / receiver that allows wireless communication. The communication network 18 will be described in more detail later.
0015One or more service systems 10 and / or one or more client systems 20 may include a trustpoint system 12 (or trustpoint). In certain embodiments, the trustpoint system 12 performs user authentication, platform authentication and / or environmental authentication to communicate information with the trustpoint system 12 or more. Trust point system 12 and trust can be established. This certification may involve performing approval of the service and / or accounting for the use of the service.
0016In certain embodiments, establishing trust allows the second trustpoint system to authenticate the first trustpoint system from the first trustpoint system to the second trustpoint system. May include sending trustpoint information to the system. In certain embodiments, establishing trust may include receiving trustpoint information from the trustpoint system and using the trustpoint information to authenticate the trustpoint system. Trustpoint information may include information that can be used to authenticate the trustpoint system. An example of trustpoint information will be described in more detail with reference to FIG. Examples of systems and methods that can provide certification reports across multiple trustpoint systems 12 include Trusted Computing and TrustedCube.
0017In certain embodiments, the client system 20 also has one or more virtual machine (VM) 22, virtual machine manager (VMM) 24, trusted platform module (TPM) 26, It may include a resource list 28, a client network system 30, a resource 32, and a GPS receiver 40.
0018The trusted platform module 26 may generate trustpoint information that can be used to authenticate the module 26. In certain embodiments, the trusted platform module (TPM) 26 may work with the trustpoint system 12. In certain embodiments, the trusted platform module 26 includes at least one processor with a unique RSA (Rivest, Shamir, and Adleman) key. The RSA key may be hardened into the processor. This RSA key can be used to authenticate the client system 20 of the trusted platform module 26. In certain embodiments, the trusted platform module 26 may generate an encryption key using, for example, a pseudo-random number generator.
0019In certain embodiments, the virtual machine 22 may accommodate the processing associated with the client network system 30 and / or the client network system 30. For example, virtual machine 22 can be used to incorporate sensors. One or more virtual machines 22 may boot one or more operating systems (OS). In certain embodiments, the virtual machine 22 may use a single purpose operating system and share the processing resources of the client system 20 through the virtual machine 24.
0020Virtual Machine Manager (VMM) 24 can create, start, monitor, and / or terminate virtual machines. The virtual machine manager 24 can intercept interrupts and / or errors between multiple virtual machines 22 and / or control application access to hardware and / or software. The virtual machine manager 24 may also manage multiple tasks of the processor by sharing time between the application and / or the various threads launched by the virtual machine 22. The virtual machine manager 24 may manage communication between multiple virtual machines 22.
0021The resource list 28 may include a white list of entities that have been granted access and / or a blacklist of entities that are denied access.
0022The client network 30 can be a network within the client system 20 that supports coordination between the components of the client system 20. For example, the client network 30 can be a network that manages processors in the vehicle (eg, a FlexRay network). As another example, a controller area network (CAN or CAN bus) allows microcontrollers and devices to communicate with each other without the use of a host computer. Further examples include TTP (time triggered protocol) networks and AFDX (avionics full-duplex switched Ethernet®) networks.
0023The client network 30 may manage resources 32, such as resources of the client system 20, such as the processor and / or its associated software, firmware, and / or processing instructions relating to the processor. For example, the client network 30 may have multiple central processing units (CPUs), each using software and / or firmware for operation. The client network 30 may be involved in the operation and / or maintenance of the resource 32, including managing the software and / or firmware version and / or update status associated with each resource 32 in the client system 20.
0024The Global Positioning System (GPS) receiver 40 acts as an interface to a GPS navigation satellite system that provides position and time information.
0025FIG. 2 shows an example of the client system 20. The client system 20 may be a computer client system, a mobile client system, a vehicle client system, or the like. In the illustrated example, the client system includes an interface (IF) 120, logic 122, and one or more memories 124. Logic 122 may include one or more processors 130 and applications such as trustpoint modules 132 and service modules 134. The trustpoint module 132 may include a user module 140, a platform module 144, and an environment module 148. The service module 134 may include an escort module 150, a battery charging module 152, a vehicle security module 154, and an emission reporting module 156.
0026The trustpoint module 132 can be used to establish trust with other trustpoint systems. Trustpoint module 132 may perform authentication to establish trust. As mentioned above, certification can involve approval and / or accounting. Trustpoint module 132 may perform user authentication, platform authentication, and / or environmental authentication.
0027Trustpoint module 132 may use trustpoint information to authenticate. Examples of trustpoint information include user, device and environment information, as described in more detail below. The trustpoint module 132 may check if the information meets the requirements to determine if a trustpoint is acceptable. For example, a trust point may be acceptable if it is whitelisted or not blacklisted. If the trustpoint is acceptable, the trustpoint is allowed access to the service and / or can continue to communicate with the entity.
0028The user authentication module 140 executes user authentication to authenticate the user. The user authentication module 140 may use the user information to authenticate the user. User information is about an individual user and can be entered by that user. User information may include identifiers (eg, username and PIN, etc.) and biometric information (eg, physiological information, behavioral information, etc.). Physiological information is related to the characteristics of the human body. Examples include fingerprints, palm prints, hand features, facial features, DNA, iris or retinal scans, and odors. Behavioral information is related to individual behavior. Examples include typing rhythms, walking styles and voices.
0029Platform module 144 authenticates the platform by performing platform authentication. Platform module 144 may use the device information provided by the platform to perform authentication. Device information includes identifiers (eg, registration identifiers (IDs)), network addresses (eg, Internet Protocol (IP) addresses, etc.), machine addresses (eg, media access control (MAC) addresses, etc.), certificates (, for example. It may include, for example, a public key infrastructure (PKI) certificate) and / or other identifier that identifies the device.
0030Environment module 148 authenticates the platform environment by performing environment authentication. Environmental module 148 can use environmental information to authenticate. Environmental information depends on the software information (eg, software version and / or status), hardware information (eg, hardware version and / or hardware configuration, etc.) of the software running on that platform, and that platform. Peripheral device information (eg, peripheral device identifier) of the managed peripheral device may be included.
0031The service module 134 may support the services provided to the client system 20. In this example, services include escort services, battery charging services, vehicle security services, and emission reporting services. However, any suitable number of any suitable services may be provided.
0032The escort module 150 acquires a route planned according to the task list and executes an escort process instructing the vehicle to move along the route. In certain embodiments, the escort process may include establishing trust with the mobile trustpoint system by means of the vehicle trustpoint system of the vehicle. A task list with multiple tasks is received from the mobile trustpoint system. Trust with the service trustpoint system is established, and routes for the above plurality of tasks are obtained from the service trustpoint system. Vehicles are ordered to travel along this route. An example of the escort treatment will be described in more detail with reference to FIG.
0033The battery charging module 152 performs a battery charging process that allows the battery charging system to charge the vehicle's battery. In certain embodiments, the battery charging process may include authenticating the charging trustpoint system with the vehicle trustpoint system of the vehicle. Vehicle trustpoint information is transmitted to allow the charging trustpoint system to authenticate the vehicle trustpoint system. The battery information of the vehicle battery is transmitted to the charging trustpoint system. Payment information corresponding to the vehicle is transmitted to the charging trustpoint system to allow the charging trustpoint system to charge the battery. An example of the battery charging process will be described in more detail with reference to FIGS. 4 to 8.
0034The vehicle security module 154 performs a vehicle security process that sends a record created in response to a security trigger event to one or more trustpoint systems. In certain embodiments of the vehicle security process, the vehicle trustpoint system of the vehicle in the vehicle environment may detect a security trigger event. The vehicle environment is recorded to create a record in response to a security trigger event. This record is transmitted to the trustpoint system, which allows the trustpoint system to transmit this record to the mobile trustpoint system. The trustpoint system may also store this record in a database. An example of vehicle security processing will be described in more detail with reference to FIG.
0035The emission reporting module 156 performs an emission reporting process that collects vehicle driving data used to calculate vehicle emissions. In certain embodiments, the emission reporting process may include collecting driving data by the vehicle trustpoint system of the vehicle. This driving data is transmitted to the center trustpoint system, which allows the center trustpoint system to calculate one or more emission values of the vehicle. An example of the emission reporting process will be described in more detail with reference to FIG.
0036Figures 3-10 show examples of methods related to services. In these examples, the client system 20 may include a mobile device, vehicle, or other client system. The service system 10 may include a vehicle service center, a traffic information center, a charging system, or other service system. In these examples, each system 10 and 20 may have a trustpoint system (or trustpoint). These methods may be performed by trustpoints and / or other components of systems 10 and 20.
0037Figures 3A to 3C show an example of how to provide an escort service. In this example, the client system 20 includes a mobile device and a vehicle, and the service system 10 includes a vehicle service center and a traffic information center. This method can be performed by a trustpoint, such as a vehicle trustpoint.
0038At step 210, the task list is received from the user. A task can include an action to be performed (eg, going shopping for groceries), a place (which can be represented as an address), a transaction, or a type of place (eg, a grocery store). In certain embodiments, the user may enter a task list into the mobile device. This may allow the user to enter a task list at the user's convenience, for example when not driving. At step 212, the mobile device moves into the vehicle with the user. The vehicle may detect that someone has entered the vehicle and request this user to provide a user identifier.
0039Steps 214-222 are performed to establish trust between the mobile trustpoint and the vehicle trustpoint. At step 214, information is requested. In certain embodiments, the request may require trustpoint information with user information obtained from the user and mobile trustpoint information provided by the mobile device. At step 216, the mobile trustpoint generates trustpoint information.
0040At step 218, the information is received. At step 220, the vehicle trustpoint checks to see if the mobile trustpoint is acceptable. Inspection of trustpoints can be performed by performing user authentication, platform authentication and / or environmental authentication. If the mobile trustpoint is unacceptable, this method returns to step 214 and requests information again. If the mobile trustpoint is acceptable, the method proceeds to step 222 and the vehicle checks whether the user and mobile device are acceptable according to the user information and the mobile trustpoint information. If the user and mobile device are unacceptable, the method returns to step 214 and requests information again. If the user and mobile device are acceptable, this method proceeds to step 224.
0041At step 224, the vehicle trustpoint requests a task list. At step 226, the task list is received from the mobile trustpoint. At step 228, the vehicle trust point requests a route from the center trust point.
0042Steps 230-238 are performed to establish trust between the center trust point and the vehicle trust point. At step 230, the center trustpoint requests information to authenticate the vehicle trustpoint. At step 232, the vehicle trustpoint generates trustpoint information. This trustpoint information may include device information, user information, and / or mobile trustpoint information provided by the vehicle.
0043At step 234, this trustpoint information is transmitted to the center trustpoint, allowing the center trustpoint to authenticate the vehicle trustpoint. At step 236, the center trust point checks if the vehicle trust point is acceptable. A trustpoint can be considered acceptable if the trustpoint information is acceptable. Information from acceptable trustpoints can be considered reliable, and information from unacceptable trustpoints can be considered unreliable. If the vehicle trustpoint is unacceptable, this method returns to step 230 and the center trustpoint requests the information again. If the vehicle trust points are acceptable, this method proceeds to step 238.
0044At step 238, check if the center trust point is acceptable to the user and the vehicle. According to a policy, an entity can be considered acceptable. A policy can specify what kind of information is needed from that entity to be acceptable. For example, a policy may specify what kind of user information, device information and / or environmental information is needed. If the user and vehicle are unacceptable, this method returns to step 230 and the center trust point requests the information again. If they are acceptable, this method proceeds to step 240.
0045Steps 240-244 are performed to obtain a route for the task. At step 240, the center trust point sends a route request. At step 242, the traffic information center sends the route. Routes can be planned according to real-time traffic information. For example, the route may be planned to avoid traffic congestion. At step 244, the center trust point transfers the route to the vehicle trust point.
0046At step 246, the vehicle trustpoint sends a request for payment information to the mobile trustpoint. At steps 248 and 250, the mobile trustpoint authenticates the vehicle trustpoint. At step 252, the mobile trustpoint sends the information.
0047At step 254, the escort begins. The escort may be performed in any suitable manner. For example, one or more components of the vehicle may instruct the vehicle to move along the route, or may instruct the user to move the vehicle along the route.
0048Steps 256-264 are performed to inspect the center trust point. At step 256, the vehicle sends a user account request to the Center Trust Point. At step 258, the center trustpoint generates and transmits trustpoint information. At step 260, the trust point information is received. At steps 262 and 264, the vehicle inspects the vehicle service center.
0049At step 266, payment information is transmitted. The vehicle service center updates the user account in step 268 and sends the result to the vehicle trustpoint in step 270. At step 272, the vehicle trust point transfers the result to the mobile trust point.
0050Figures 4-8 show examples of how to provide battery charging services. FIG. 4 outlines an example of how to provide a battery charging service. In this example, the client system 20 includes a mobile device and a vehicle, and the service system 10 includes a charging system and a payment system. This method can be performed by a trustpoint, such as the vehicle trustpoint of a vehicle.
0051In certain embodiments, the information for approving payment for the service is transmitted from the mobile device instead of being stored in the vehicle. This can prevent unauthorized persons from getting in the vehicle and receiving service. In certain circumstances, users who receive services through mobile trustpoints may be charged less than users who do not use mobile trustpoints. In such a situation, the user who uses the mobile trust point rarely causes a problem and can be said to have a low risk. Therefore, the service provider may not insure the trustpoint user so much and may therefore be able to provide the service at a lower cost. Users may also be encouraged to choose to use trust points if the cost is low.
0052In certain embodiments, at step 308, authentication may be performed to establish trust between the vehicle trust point and the charging trust point. In certain embodiments, authentication may include receiving charging trustpoint information at the vehicle trustpoint and using the charging trustpoint information to authenticate the charging trustpoint. Authentication may also include transmitting vehicle trustpoint information to allow the charging trustpoint to authenticate the vehicle trustpoint.
0053Any suitable trust point information may be used. The charging trustpoint information may include a charging system identifier (eg, service provider name and / or machine identifier, etc.) and a system state (eg, operating or ready to charge, etc.). The vehicle trust point information may include, for example, device information and / or user information. Vehicle device information may include a vehicle description (eg, manufacturer and / or model, etc.) and / or vehicle identification number.
0054At step 310, the vehicle trust point requests charging. At step 312, the charging trust point requests battery information. Battery information can include parameters that describe the battery, such as voltage, manufacturer, model, current charge (eg x% of capacity), capacity, free capacity, temperature, or other characteristics of the battery. At step 314, battery information is transmitted to the charging trust point.
0055At step 316, the charging trust point approves the vehicle trust point. At step 318, the charging trust point notifies the vehicle trust point that the charging system is ready to charge. At step 320, the vehicle trust point approves the vehicle.
0056In certain embodiments, at step 321 authentication can be performed to establish trust between the vehicle trustpoint and the mobile trustpoint. In certain embodiments, authentication may include receiving mobile trustpoint information at the vehicle trustpoint and using the mobile trustpoint information to authenticate the mobile trustpoint. Authentication may also include transmitting vehicle trustpoint information to allow the mobile trustpoint to authenticate the vehicle trustpoint.
0057At step 322, the vehicle trustpoint requests payment information from the mobile trustpoint for the user's accounting. In step 324, the payment information corresponding to the accounting is received from the mobile trust point. Payment information may include information that allows the account to be charged for the service. In certain embodiments, the mobile trustpoint may receive a key that allows the mobile trustpoint to encrypt payment information.
0058At step 326, payment information is transmitted to the charging trust point or payment system, allowing the charging trust point to charge the battery. The charging trust point may transfer the information to the payment system. The payment system approves the accounting in step 328 and sends the accounting approval to the vehicle in step 330. At step 332, the vehicle trust point approves the payment.
0059At step 334, the vehicle trust point performs a status check. Situation inspection may include determining that the vehicle has been approved and / or settlement has been approved. Situation inspection may include determining that the vehicle cannot move during charging, eg, the vehicle is parked and the brakes are set. If the status check is not passed, a warning will be sent to the mobile trustpoint. If the condition inspection is passed, in step 336, the vehicle trust point sends a request to start charging.
0060At step 338, the charging system begins charging the vehicle. At step 340, the charging status is sent to the mobile trustpoint. The charging status can indicate the amount of charge in the battery and the time remaining to charge the battery. The mobile device may display the charging status. In certain embodiments, the charging system may work with a smart meter (eg, an electric meter or a solar panel current collector) connected to an energy source.
0061FIG. 5 shows an example of a mutual authentication method between a vehicle trust point and a charging trust point. At step 410, the vehicle detects that the battery is at alert level. The alert level can be the level at which the battery should be charged, for example, the charge amount can be in the range of less than 10%, in the range of 10% to 25%, or in the range of 25% to 50%.
0062At step 412, the vehicle trust point requests information from the charging trust point. The charging trust point generates trust point information in step 414 and transmits the information to the vehicle trust point in step 416. At step 418, the vehicle trust point determines if the charging trust point is acceptable. If the charging trust point is unacceptable, this method returns to step 412 and the vehicle requests information again. If the charging trustpoint is acceptable, the method proceeds to step 420, where the vehicle trustpoint notifies the charging trustpoint that the charging trustpoint is acceptable.
0063At step 422, the charging trust point requests information from the vehicle trust point. The vehicle trust point generates trust point information in step 424 and transmits the information in step 426. At step 428, the charging trust point determines if the vehicle trust point is acceptable. If the vehicle trust points are unacceptable, the method returns to step 422 and requests information again. If the vehicle trust point is acceptable, the method proceeds to step 430 to notify the vehicle trust point that the vehicle trust point is acceptable. This method continues in Figure 6, 7 or 8.
0064FIG. 6 shows an example of a method of charging a vehicle battery. At step 432, the vehicle trust point requests charging by the charging trust point. At step 434, the charging trust point requests battery information. At step 436, the vehicle trust point transmits battery information. At step 438, the charging trust point sets the charging type. The charge type may include the amount of charge to be supplied to the battery described in the battery information. At step 440, the charging station is connected to the vehicle.
0065At step 442, the charging trustpoint requests payment information, and the vehicle trustpoint transfers the request to the mobile trustpoint. In step 444, the mobile trust point transmits the payment information to the vehicle trust point, and the vehicle trust point transfers the information. At step 446, the charging trust point requests payment approval. At step 448, the payment system notifies the charging trustpoint that the payment has been approved.
0066At step 450, the charging station charges the vehicle battery. At step 452, the vehicle displays the charging status. In step 454, the vehicle transmits the charging status to the mobile device, and in step 456, the mobile device displays the charging status. At step 458, charging is completed. At step 460, the charging trust point requests payment, and at step 462, the vehicle trust point notifies the payment approval. At step 464, the charging trust point sends billing information.
0067FIG. 7 shows another example of how to charge a vehicle battery. Steps 510 to 520 may be substantially similar to steps 432 to 442 of FIG.
0068At steps 522-540, mutual authentication is performed to establish trust between the mobile trustpoint and the vehicle trustpoint. At step 522, the vehicle trustpoint requests information from the mobile trustpoint. The mobile trustpoint generates trustpoint information in step 524 and transmits the information to the vehicle trustpoint in step 526. At step 528, the vehicle trust points are checked to see if the mobile trust points are acceptable. If the mobile trustpoint is unacceptable, this method returns to step 522 and the information is requested again. If the mobile trustpoint is acceptable, the method proceeds to step 530, where the vehicle trustpoint notifies the mobile trustpoint that the mobile trustpoint is acceptable.
0069At step 532, the mobile trustpoint requests information from the vehicle trustpoint. The vehicle trust point generates trust point information in step 534 and transmits the information to the mobile trust point in step 536. At step 538, the mobile trustpoint is checked to see if the vehicle trustpoint is acceptable. If the vehicle trust point is unacceptable, the method returns to step 532 and the information is requested again. If the vehicle trustpoint is acceptable, the method proceeds to step 540, where the mobile trustpoint notifies the vehicle trustpoint that the vehicle trustpoint is acceptable.
0070The vehicle trust point generates a one time key in step 542 and transmits the one time key to the mobile trust point in step 544. At step 546, the mobile trustpoint uses the one-time key to encrypt the payment information. The encrypted payment information may include, for example, an encrypted credit card number. At step 548, the mobile trustpoint sends the encrypted payment information to the vehicle trustpoint. At step 550, the vehicle trust point decrypts the payment information. Steps 552 to 576 may be substantially similar to steps 444 to 464.
0071FIG. 8 shows another example of how to charge a vehicle battery. Steps 610-620 may be substantially similar to steps 432-442.
0072Steps 622-628 describe that the vehicle service center generates a key for the mobile device. At step 622, the vehicle trust point requests a one-time key from the center trust point. The center trust point generates a one-time key in step 624, transmits the one-time key to the vehicle trust point in step 626, and transmits the one-time key to the mobile trust point in step 628. Steps 630-660 can be substantially similar to steps 546-576.
0073FIG. 9 shows an example of how to provide a vehicle security service. This method can be performed by the vehicle trust point of the vehicle in the vehicle environment. The vehicle environment may include at least a portion of the interior of the vehicle, the exterior of the vehicle, and / or the area surrounding the vehicle.
0074At step 710, a security trigger event is detected. Security trigger events can be visual events (eg, flashes, etc.), auditory events (eg, collision sounds, etc.), or movements (eg, shaking or vibration, etc.). At step 712, the vehicle environment is recorded and a record is generated. The vehicle environment may be recorded by any suitable device configured to detect visual and / or auditory signals, such as a camera or recorder. At step 714, the record is transmitted to the center trust point.
0075At step 716, the center trustpoint stores the record in the database. The preserved records may be used as evidence in a trial regarding this security-triggered event. At step 718, the center trustpoint sends the record to the mobile trustpoint. The user of the mobile trust point may replay the record.
0076Figure 10 shows an example of how to provide an emission reporting service. This method can be performed by the vehicle trust point of the vehicle.
0077At step 730, operation data is collected. The operating data may include any suitable data from which emissions can be calculated. For example, the data may include emissions detected from temperature, noise, and exhaust. Operational data can identify emissions that are emitted when only the battery is operating, when only the engine is operating, or when both are operating. In certain embodiments, personal data about the user may not be included in the driving data. In other embodiments, personal data may also be included.
0078At step 732, driving data is transmitted to the center trust point. At step 734, the center trust point calculates the vehicle emission value. For example, carbon dioxide emissions can be calculated.
0079The systems and devices disclosed herein may be modified, added or omitted without departing from the scope of the present invention. The components of these systems and devices may be integrated or separate. Also, the operation of the system and equipment may be performed by more, less, or other components. For example, the operations of trustpoint module 132 and service module 134 may be performed by one component, or the operations of module 132 or 134 may be performed by two or more components. In addition, system and device operations may be performed using any suitable logic with software, hardware and / or other logic. In the present application, "each" means each member of a set, or each member of a subset of a set.
0080The methods disclosed herein may be modified, added or omitted without departing from the scope of the present invention. These methods may include more, fewer, or other steps. Also, the steps may be performed in any suitable order.
0081In certain embodiments, an entity that performs a first step that precedes (eg, connects) the second step may be considered to facilitate the second step. For example, if an entity performs step A that precedes step B, that entity also facilitates step B. In certain embodiments, the first entity that performs the first step that precedes the second step that can be performed by the second entity allows the second entity to perform the second step. It may be considered as something to do. For example, if the first entity performs step A that precedes step B that can be performed by the second entity, the first entity also allows the second entity to perform step B.
0082The system and device components disclosed herein may include interfaces, logic, memory and / or other suitable components. The interface receives the input, sends the output, processes the input and / or the output, and / or performs other suitable processing. The interface can have hardware and / or software.
0083The logic executes the processing of the component, for example, an instruction for generating an output from an input. Logic may include hardware, software and / or other logic. Logic can be encoded in one or more tangible media and can perform processing when executed by a computer.
0084Certain logic, such as a processor, can control the behavior of its components. The processor may have logic (eg, a device or device) capable of interpreting and / or executing other logic. Examples of processors are computers, microprocessors, microcontrollers, digital signal processors (DSPs), application specific integrated circuits (ASICs), or are configured to interpret and / or execute program instructions and / or processed data. Includes one or more of other digital or analog circuits.
0085In certain embodiments, the processing of the embodiments is one or more computer readable, encoded by computer programs, software, computer executable instructions, and / or other instructions that can be executed by a computer. Can be performed by the medium. In certain embodiments, the processing of the embodiments may be performed by one or more computer-readable media containing the computer program, embodied in the computer program, and / or encoded in the computer program. It may be executed by one or more computer-readable media having a stored and / or encoded computer program.
0086Logic such as electronic content (content) such as software (including updates) can be files, code (eg, object code or executable code, etc.), data records, and / or other electronic that can be accessed by the client. May include the data structure recorded in. Examples thereof may include text files, spreadsheets, e-mails, medical records, images, web pages, programs (eg, document processing programs and file management programs), and / or other electronic data or programs. ..
0087Memory stores information. The memory can have one or more, non-temporary, tangible, computer-readable and / or computer-executable storage media. Examples of memory include computer memory (eg, random access memory (RAM), read-only memory (ROM), or electrically erasable programmable read-only memory (EEPROM)), mass storage media (eg, hard disk), Removable storage media (eg, compact discs (CDs) or digital video discs (DVDs)), databases and / or network storages (eg, servers), and / or other computer-readable media, volatile memory, or Includes non-volatile memory that holds data even when power is not supplied.
0088The components of the system and device may be coupled by any suitable communication network that communicates according to any suitable communication protocol. Communication networks (for example, communication network 18) include public exchange telephone networks (PSTN), public or private data networks, local area networks (LAN), metropolitan area networks (MAN), wide area networks (WAN), and local virtual networks. One or more of private networks (VPNs), such as regional or global communications or computer networks such as the Internet, wired or wireless networks, corporate intranets, other suitable communications links, or a combination of any of these. Can have whole or part. The communication network may include routers, hubs, switches, gateways, call controllers and / or other suitable elements of any suitable form or configuration.
0089Although the present disclosure has been described for specific embodiments, those skilled in the art will appreciate modifications and substitutions of these embodiments. Therefore, the above description of the embodiments does not limit the present disclosure. Other modifications, substitutions and modifications are possible without departing from the spirit and scope of this disclosure as set forth in the appended claims.
0090Regarding the above explanation, the following additional notes will be further disclosed. (Appendix 1) One or more interfaces that operate to communicate with multiple trustpoint systems, One or more processors By performing user authentication, platform authentication, and environmental authentication, the trust with the plurality of trustpoint systems is established, and the trust is established. Communicating information with the plurality of trustpoint systems in response to establishing trust, With one or more processors that work like System with. (Appendix 2) Establishing trust is Sending trustpoint information from the first trustpoint system to the second trustpoint system to allow the second trustpoint system to authenticate the first trustpoint system. The system according to Appendix 1. (Appendix 3) Establishing trust is Receiving trustpoint information from the trustpoint system and To authenticate the trustpoint system using the trustpoint information The system according to Appendix 1. (Appendix 4) The processor further A task list with multiple tasks is received from the first trustpoint system and The task list is sent to the second trustpoint system to obtain routes for the plurality of tasks and instruct the vehicle to move along the routes. By acting to perform an escort process, The system described in Appendix 1. (Appendix 5) The plurality of trust point systems include a charging trust point system. The processor further The battery information of the vehicle battery is transmitted to the charging trust point system, and Payment information corresponding to the vehicle is transmitted to the charging trustpoint system to allow the charging trustpoint system to charge the battery. By acting to perform a battery charging process, The system described in Appendix 1. (Appendix 6) The processor further Send a security trigger event about the vehicle, Record the vehicle environment of the vehicle, generate a record, and Send the record to the trustpoint system By acting to perform vehicle security processing, The system described in Appendix 1. (Appendix 7) The processor further Collect vehicle driving data and The driving data is transmitted to the trustpoint system to allow the trustpoint system to calculate one or more emissions of the vehicle. By acting to perform emission reporting processing, The system described in Appendix 1. (Appendix 8) By the vehicle trust point system of the vehicle Steps to establish trust with the first trustpoint system, A step of receiving a task list having a plurality of tasks from the first trustpoint system, and Steps to establish trust with the second trustpoint system, A step of obtaining a route for the plurality of tasks from the second trustpoint system, and Steps to instruct the vehicle to move along the route Method to have. (Appendix 9) The steps to establish trust with the first trustpoint system are: The step of receiving the user information acquired from the user by the first trustpoint system, and With the step of authenticating the user according to the user information The method according to Appendix 8. (Appendix 10) The steps to establish trust with the first trustpoint system are: The step of receiving device information from the first trustpoint system and With the step of authenticating the first trustpoint system according to the device information The method according to Appendix 8. (Appendix 11) The steps to establish trust with the second trustpoint system are: A step of transmitting vehicle trustpoint information to the second trustpoint system to allow the second trustpoint system to authenticate the vehicle trustpoint system. The method according to Appendix 8. (Appendix 12) The step of receiving the second trust point information from the second trust point system and The step of authenticating the second trustpoint system according to the second trustpoint information, and The step of transmitting payment information to the second trust point system and The method according to Appendix 8, further comprising. (Appendix 13) By the vehicle trust point system of the vehicle Steps to authenticate the charging trustpoint system and A step of transmitting vehicle trustpoint information to allow the charging trustpoint system to authenticate the vehicle trustpoint system. A step of transmitting the battery information of the vehicle battery to the charging trust point system, and A step of transmitting payment information corresponding to the vehicle to the charging trustpoint system and enabling the charging trustpoint system to charge the battery. Method to have. (Appendix 14) Steps to establish trust with mobile trustpoint system, With the step of receiving the payment information from the mobile trust point system The method according to Appendix 13, further comprising. (Appendix 15) A step of transmitting vehicle trustpoint information to a mobile trustpoint system to allow the mobile trustpoint system to authenticate the vehicle trustpoint system. The method according to Appendix 13, further comprising. (Appendix 16) A step of transmitting an encryption key to a mobile trustpoint system to allow the mobile trustpoint system to encrypt the payment information. The method according to Appendix 13, further comprising. (Appendix 17) Step to display the charging status indicating the charging of the battery The method according to Appendix 13, further comprising. (Appendix 18) A step of transmitting a charging status indicating the charging of the battery to the mobile trustpoint system so that the mobile trustpoint system can display the charging status. The method according to Appendix 13, further comprising. (Appendix 19) Steps to receive the encryption key from the trustpoint center, A step of transmitting the encryption key to a mobile trustpoint system to allow the mobile trustpoint system to encrypt the payment information. The method according to Appendix 13, further comprising. (Appendix 20) By the vehicle trust point system of the vehicle in the vehicle environment Steps to detect security trigger events and A step of recording the vehicle environment and generating a record, A step of transmitting the record to the center trustpoint system and allowing the center trustpoint system to transmit the record to the mobile trustpoint system. Method to have. (Appendix 21) The step of transmitting the record to the center trustpoint system further Sending the record to allow the center trustpoint system to store the record in a database. The method according to Appendix 20. (Appendix 22) By the vehicle trust point system of the vehicle Steps to collect driving data and A step of transmitting the driving data to a center trustpoint system to allow the center trustpoint system to calculate one or more emission values for the vehicle. Method to have.
00912 network 10 Service system 12 Trust Point System (TPS) 18 Communication network 20 client system 21 Logic 22 Virtual Machine (VM) 24 Virtual Machine Manager (VMM) 26 Trusted Platform Module (TPM) 28 Resource list 30 Client network 32 resources 40 GPS receiver 120 interface 122 logic 124 memory 130 processor 132 Trustpoint Module 134 Service Module 140 user module 144 platform module 148 Environment module 150 escort module 152 Battery charging module 154 Vehicle Security Module 156 Emissions reporting module
15 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP2010061237A | Cites | Japan |
| JP2010190792A | Cites | Japan |
| JP2009254052A | Cites | Japan |
| JP2009110224A | Cites | Japan |
| JP2009129262A | Cites | Japan |
44 members in 5 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 12879226 | United States of America | – | |
| 87922610 | United States of America | A | |
| 13053670 | United States of America | – | |
| 201113053670 | United States of America | A |
Members44
| Document | Office | Kind | |
|---|---|---|---|
| US2011237234A1 | United States of America | A1 | |
| US2011238260A1 | United States of America | A1 | |
| US2011238402A1 | United States of America | A1 | |
| US2011238980A1 | United States of America | A1 | |
| US2011239209A1 | United States of America | A1 | |
| US2011239210A1 | United States of America | A1 | |
| WO2011119297A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2011119298A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2011119299A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2011119300A2 | World Intellectual Property Organization (WIPO) | A2 | |
| JP2012059270A | Japan | A | |
| CN102404312A | China | A | |
| CN102823195A | China | A | |
| CN102859935A | China | A | |
| CN102870093A | China | A | |
| EP2550595A1 | European Patent Office (EPO) | A1 | |
| EP2550596A2 | European Patent Office (EPO) | A2 | |
| EP2550768A1 | European Patent Office (EPO) | A1 | |
| EP2550769A1 | European Patent Office (EPO) | A1 | |
| CN103154966A | China | A | |
| JP2013522793A | Japan | A | |
| JP2013522794A | Japan | A | |
| JP2013522795A | Japan | A | |
| JP2013532394A | Japan | A | |
| JP5516821B2 | Japan | B2 | |
| JP5522307B2 | Japan | B2 | |
| EP2550768B1 | European Patent Office (EPO) | B1 | |
| US9059978B2 | United States of America | B2 | |
| WO2011119300A3 | World Intellectual Property Organization (WIPO) | A3 | |
| JP5747981B2 | Japan | B2 | |
| US2015248286A1 | United States of America | A1 | |
| US2015248287A1 | United States of America | A1 | |
| US2015261554A1 | United States of America | A1 | |
| EP2550769B1 | European Patent Office (EPO) | B1 | |
| US9286485B2 | United States of America | B2 | |
| JP2016040727A | Japan | A | |
| CN102870093B | China | B | |
| JP5927815B2 | Japan | B2 | |
| CN102404312B | China | B | |
| CN102823195B | China | B | |
| CN102859935B | China | B | |
| EP2550595B1 | European Patent Office (EPO) | B1 | |
| JP6131994B2This record | Japan | B2 | |
| US9766914B2 | United States of America | B2 |
8 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 |
Numbers
- Publication
- 6131994
- Application
- 209382
Titles2
- Japanese
- トラストポイントを用いてサービスを提供するシステム及び方法
- English
- Systems and methods for providing services using trust points
Classification
- CPC, 14
- B60L3/12
- B60L2240/545
- B60L2240/547
- B60L2240/549
- B60L2240/72
- B60L2250/10
- Y02T90/16
- Y02T10/7072
- Y04S30/14
- B60L53/65
- Y02T10/70
- Y02T10/72
- Y02T90/12
- Y02T90/167
- IPC, 10
- G06Q50 10
- G06Q20 40
- G06F21 30
- G01C21 34
- G08G1 0968
- G08G1 00
- G06F21 31
- G06F21 32
- G06F21 33
- G06F21 44
