This article is therefore dedicated to sharing and deleting the key, as well as general data protection topics relating to the Digital Key.
The digital key: sharing, revocation and data protection
In the first part of our KaaS IT user story we were able to gain an insight into master key production and get an idea of how the digital vehicle key is handled.
Let's go back to the picture story from the first part, when my colleague Judith urgently needed my BMW 1 Series. I was then able to easily share the key with her via Apple iMessage. Is it really that easy and how does it actually work?

Key sharing: sharing vehicle keys with the digital key
As a Generation X person (almost a Y person after all) with a fascination for digital processes, you are somehow still used to carrying a real car key around with you. So for me, sharing the key with family and friends was the real reason for wanting to use a digital key.
Is it really as simple as the advertising and other reports want to tell us? Let's just take a look at it together.

Our starting point from the last blog post was that we have a working master key in the iPhone wallet with which we can open and close the vehicle, as well as start and drive it.
If we now click on the three dots button at the top right of the master key in the wallet, we will be taken to the key information page in the wallet.
Sounds super exciting, but it's not really. Behind it are three links to the BMW page, an app details page, the switch for express mode and the eagerly awaited "Invite ...„.

In the following menu we get a short explanation as well as a selection via "Invite" and "Configure access". The computer scientist in me wins out and I click on the configuration and in the subsequent selection I can choose the pre-selected "Unlock & Drive" or "Restricted Driving". That's not really self-explanatory, especially when the reference to the vehicle's user manual appears.
If I click on "Continue", I can then click on "Invite ..." and end up in Apple's iMessage. Now all I have to do is select the recipient from the address book and I'm ready to go.

Now let's take a look at the technology:

Key sharing is based on the X.509 certificate-based master key. The new, shared key is a procedural continuation of the certificate chain from the master key. Apple uses the WWDC contribution unfortunately did not go into the process in depth, but we were able to extract a little.
The process starts with an invitation in the form of an iMessage based on the master key. The iMessage itself contains the basic framework (template) for creating the key. In the process, a special main user / second user intermediary certificate is created, which is also linked to the vehicle manufacturer certificate. While the backend of the vehicle validates the key when the main key is created, this is done by the phone of the main user when the key is shared.
The main difference between the master key and the duplicate key is that the key is announced in the vehicle. While we have to carry out the entire process in the vehicle with the master key and the vehicle has to be "online", this is no longer necessary with the duplicate key. The advantage is that we can park the vehicle offline in the underground garage and still share the key.

Standard Transaction / Fast Transaction
In general, the vehicle can be opened relatively quickly in less than a second using the phone. However, only if the key is also known in the vehicle. This generally also works with the second key, but not in the aforementioned underground parking garage case on first contact. The whole process is described in very technical terms in the WWDC article and explains the communication with the vehicle and the exchange of the necessary information.
In principle, the duplicate key is not yet complete after completion of the process described above, as further information must be exchanged with the vehicle. This exchange or completion of the key information takes place during the first contact with the vehicle.
If the vehicle is missing information, as in our offline underground parking case, this is extracted from the still unknown second key and stored in the vehicle. Unfortunately, this takes some time and I found it strange the first few times. On the one hand, I had no feeling for how to hold the phone or watch on the door handle and on the other hand, there was no feedback as to whether information was currently being exchanged. As a result, I probably canceled the process a few times, as the process takes between 2-3 seconds.
The entire process is much faster if the vehicle was previously online. Only a small amount of information is then required to open the door.
Apple Watch as a digital key
In the first version of the digital key, the number of keys was limited by BMW and you could only book an additional five people with the help of an additional package. Thankfully, this option was abolished with the standard, meaning that the new digital key only has a purely technical limit on the number of keys that can be shared, according to the Car Connectivity Consortium.
In addition, Apple and BMW allow the simultaneous use of an iPhone and Apple Watch, provided they are linked to the same iCloud account. Transferring the key to the Apple Watch is just as simple as transferring credit cards with Apple Pay. No action or form of confirmation by the primary key holder is required.
In Apple's presentation, it was mentioned that each device has its own unique secure element. Therefore, for technical reasons, it must be another shared key, as otherwise the certificate chain is no longer unique.
Delete digital key
Of course, you also want to delete shared keys or your own key again and we were able to identify different processes. In general, each key could be deleted individually in the vehicle or the entire function could be reset. You can also delete your own key directly via the phone or from the iCloud. For shared keys, there is also the option for deletion by the main user key.
The process works very well. Regardless of the method used, the keys are deleted from all devices and also in the vehicle. Overall, the process is quite unspectacular, so I won't go into any more detail here. However, the special features lay in the details and when the keys are actually deleted. When deleting your own key, the deletion is triggered directly, so far so logical. However, things got interesting when deleting a shared key, as the vehicle seems to define when which key is deleted. We had to try out and experiment a little before we came up with this very clever logic.
Secure deletion
Let's say we share the key with our best friend and she is nice enough to take the car to the petrol station. Somehow, though, we've got a bit of a chip on our shoulder today and we delete her key while she's on the road.
Does the car stop? Can it still be locked at all? Or can it be locked but then no longer opened?
She would "definitely" have had fun at the gas station, or at least we would have laughed about it together in a year's time.
But to be honest, the action was totally boring because nothing happens. Honestly, nothing at all. She could probably have gone on vacation with the key and nothing would have happened.
According to our tests, the following conditions had to be met:
- Vehicle parked and locked
- The last key used must not be the key to be deleted
The conditions cannot be verified 100 percent, but they are consistent with our tests. Personally, I think it's a great idea. After all, I can't delete the key from the current user purely by mistake and possibly endanger people or the vehicle.
Problems with deleting digital keys
Deleting keys works perfectly. In our test, we only encountered one problem, which we were unable to solve without resetting the main user's phone. This involved deleting a shared key from the second user's phone. The key was deleted on the wallet of the second or secondary user's phone and the key was also deleted in the vehicle, but not on my phone (main user). I tried to delete the key several times, but couldn't get it to work. However, the error never occurred again and after contacting Apple Support, the problem was resolved.
Digital key and data protection
Apple emphasizes that data protection is particularly important to them. But how is this even possible in such a system? If you take a closer look at the wallet, you can see that the digital vehicle key is integrated into the credit card area and not in the lower area with the flight tickets or cinema tickets.
According to Apple, credit cards and the vehicle key are Secure element of the phone. In the case of credit cards, it is known that Apple does not pass on any information about the data actually stored to the card readers. Furthermore, payment via Apple Pay is considered one of the safest methods. The data exchange by Apple Pay is generally well documented and the system architecture presented allows assumptions to be made as to which data protection-relevant information could be required for the BMW Digital Key.
Let's start with the vehicle:
- Each vehicle has a so-called VIN/FIN (vehicle identification number), which is unique
- As digital identity BMW normally uses the Connected Drive user account for the user's login. In Germany, the e-mail address is used as the user's login.
Apple iPhone:
- BMW mentionedthat a linked Apple Watch to an iPhone only counts as one key and does not need to be shared again with the master key. As a result, the iCloud account very likely play a role
- Serial number from the smartphone or Apple Watch
- Serial number from Secure element from the smartphone or Apple Watch, stored in the smartphone as SEID
Digital vehicle key:
- Physical vehicle keys have a key identification number. The digital vehicle keys also have an ID, which can be viewed in the BMW vehicle in the driver profile settings for the respective key.
Apple mentions in the WWDC article that the data is stored securely on the device and cannot be traced or accessed by Apple. How can that be? After all, data is not only exchanged between the devices via NFC, but also via the servers. Apple has been advertising its end-to-end encryption for years and it can be assumed that the corresponding digital identity features additionally be masked and encrypted by each party. For example, the iPhone itself does not necessarily need to know the VIN for the key to work. The identification of the vehicle is also only relevant for BMW itself in the initial phase, as the legal requirements described cannot be implemented without the assignment. This is irrelevant for Apple, as it only needs the information about which vehicle manufacturer to communicate with.
Masked identification features
Based on the information from the Car Connectivity Consortium, the WWDC contribution and the underlying technologies, we can only make assumptions as to which IDs will be exchanged. So let's just try to build it up logically with the best guess approach:
- The vehicle must be identified in some way and also assigned to the corresponding devices/vehicle. Since only BMW knows the main user information and merges it by means of a mapping process, I assume a VehicleID which will be a link between the vehicle and the user's digital identity.
- Everyone key has its own Identification number. Although it is not displayed in the Wallet, it is displayed in the vehicle when profiles are linked to a key. BMW uses the profiles, for example, to control the outside temperatures at which the seat heating is generally switched on.
- In the first blog post, I referred to a Contribution made by Allianz Versicherungwhich deals with unique key identification in the event of theft. We remember that the police usually require proof of possession of the physical key. The physical keys are handed in at the police station and the key identification is compared with the manufacturer's information. Although we had the key identification number in the previous step, this is not displayed in the phone. As Apple states that it does not disclose any information about its users to BMW, it can be assumed that Apple also stores the serial number and the Secure Element ID individually or as a joint pair as a DeviceID is handed over masked.
- BMW and Apple promise the shared use of the user's watch and iPhone without having to share the key. Only Apple can know the identification of a person's devices, and only BMW knows the number of keys available for the vehicle. In my opinion, the most likely identification feature for this feature is Apple's iCloud account ID. It can therefore be assumed that this will also be masked as a kind of AppleAccountID.1
Conclusion
The technological basis of the digital key is very well thought out and it will be interesting to see which physical devices can be easily opened with the phone in the future. The foundation for this has been laid with this standard, even if it will probably not be possible to transfer it 1:1.
For the digital car key of the future, I would like to be able to share my Apple Car Key with users of an Android smartphone so that the key is not limited to my own "universe", but this is probably only a matter of time. I also miss a personalized display of the digital key in the wallet. We sometimes spend a lot of time in "Germany's favorite child" and BMW in particular plays on precisely this attachment. The smartphone is in no way inferior, it is carried around all day and often the most personal information and pictures can be found on the phone.
All in all, the digital vehicle key is a really successful feature of a connected car and once again we can only say: "Awesome, great job!"




