Digital key visual: smartphone, truck, excavator, motorcycle and a car

Server Based Owner Device (SBOD): How the doubleSlash Digital Key can be used for fleets

The smartphone becomes a car key - secure, contactless and digitally controlled. What once began as an innovation in the premium segment has now established itself in the private sector: Vehicles can be opened, started and managed conveniently via app.

The doubleSlash Digital Key is based on the standards of the Car Connectivity Consortium (CCC) and meets the highest requirements for safety and interoperability.

This model works well in the everyday lives of private users: one vehicle, one device, one user. However, as soon as vehicles are used in fleets, by car-sharing services or for commercial purposes, this approach reaches its technical and organizational limits.

How can digital keys be managed on a large scale when people, vehicles and locations are constantly changing?
The answer: Server Based Owner Device (SBOD).

SBOD transfers the management of digital vehicle keys from the individual end device to a central server architecture - making the doubleSlash Digital Key fit for professional use in fleets of any size.

Why classic digital keys are reaching their limits in fleets

With a conventional digital key, the authorization is stored locally on an end device (e.g. a smartphone). This device communicates directly with the vehicle via a secure connection, enabling access and - depending on the authorization - use.

However, this coupling is not practical in professional applications. The reasons for this include

  • Drivers change regularly, so devices cannot be permanently assigned.
  • Vehicles are shared or handed over at short notice, for example in logistics or rental fleets.
  • Central management and overview are missing if keys are stored locally.

As a result, a high level of organizational effort is required, security risks increase - and the digital key loses its efficiency.

What is SBOD and what makes it different from the conventional digital key?

The Server Based Owner Device is a server-side extension of digital key management based on the specifications of the Car Connectivity Consortium (CCC) Digital Key Standards.

In contrast to the classic model, in which a physical device generates and manages the key, the SBOD performs these tasks centrally on a server.
It generates and stores the digital vehicle key on the server side - comparable to a virtual owner device.

The keys generated by the SBOD are distributed to authorized end devices and used locally.
The vehicle checks the validity of these keys independently, based on cryptographic trust mechanisms - direct communication with the SBOD is not required for this.

The most important features of SBOD at a glance:

  • Central management of the owner key on a server - no longer on a mobile device.
  • Standard-compliant communication via defined interfaces in accordance with the CCC specification.
  • Secure infrastructure with modern cryptographic processes.

Use is controlled by the fleet operators - key management is handled by the SBOD.

Typical areas of application for a server-based owner device

SBOD enables fleet operators to manage vehicle access on the server side and integrate it into central processes. The range of applications extends across many industries:

Commercial vehicles and logistics

In transport and logistics companies, it can help to create, manage and revoke digital keys centrally. This enables efficient management of large vehicle fleets with frequently changing drivers.

Off-road and construction machinery

Remotely controlled activation of machines is a relevant use case for construction machinery or off-road vehicles. Server-side control allows vehicles to be used without physically assigning keys - an advantage for unstructured locations such as construction sites.

Rental fleets and mobility service providers

Companies that temporarily hand over vehicles to customers benefit from the central allocation and deactivation of digital keys. Access can thus be managed via existing systems - completely digitally.

One system, many possibilities - based on the CCC standards

The SBOD architecture is developed on the basis of the CCC digital key specification and offers a standardized, interoperable and future-proof solution for companies that want to efficiently control digital vehicle access.

With its SBOD implementation, doubleSlash provides a solution that can be seamlessly integrated into existing system landscapes without having to rely on local storage of keys.

How SBOD works: Digital key management for fleets - centralized, secure, standard-compliant

The doubleSlash SBOD assumes the role of the owner device on the server side. It manages the entire key allocation and administration on behalf of the fleet operator. This centralizes the entire lifecycle of the digital key without the need for a physical end device on the fleet side.

System components in the SBOD scenario:

  • Server Based Owner Device (SBOD)
    Generates the owner digital key, manages friend keys and their lifecycles. The SBOD completely replaces the physical owner device and acts on behalf of the fleet operator. However, it has no direct contact with the user's end device.
  • Fleet Management Server (FMS)
    Controls fleet processes such as infleeting and defleeting, user registration ("Friends") and the initiation of owner key sharing or friend key termination. The decisions are implemented technically by the SBOD.
  • Device OEM Server
    Handles the communication between the SBOD, which communicates with the device OEM via the relay server, and the end devices (friend devices). It is required to share digital keys from the SBOD with the devices.
  • Relay Server
    The SBOD can use it to communicate with the Device OEM Server. The Relay Server can be operated by different system partners, such as the Device OEM or a Secure Entity OEM.
  • Digital Key Backend
    Responsible for classic (non-SBOD) key processes and communication with the vehicle.

Procedure in the SBOD model (simplified illustration):

  1. The Fleet Management Server manages vehicles and users and initiates, for example, the registration of a new vehicle or the release for an authorized person ("friend").
  2. The SBOD generates and manages the owner key for the respective vehicle - comparable to a real owner device.
  3. To allow an authorized person access, the SBOD shares its owner key with the end device.
    Communication takes place via the relay server, which establishes the connection to the device OEM server.
  4. The friend device receives the information about the shared authorization and generates a friend key locally on this basis. This friend key must then be authenticated by the SBOD so that the key can be used. This key is used to open and start the vehicle - even without an active internet connection.
  5. The SBOD manages the life cycle of the owner key and can revoke shared access rights if requested by the FMS.
doubleSlash as a solution provider for SBOD

With the Digital Key SBOD, doubleSlash provides a product-ready, standards-compliant solution that takes the classic digital key processes for fleet use a step further.

The solution provides vehicle manufacturers with centralized, scalable key management in line with CCC specifications - including coordination with existing OEM systems for secure transmission and device management.

Conclusion: Think digital keys centrally

With SBOD, digital vehicle access can be controlled centrally and used professionally - especially where mobility needs to be shared, organized or provided temporarily.

The SBOD architecture thus creates the basis for scalable mobility solutions that are secure, standards-compliant and future-proof - in line with the requirements of modern vehicle fleets.

More about digital access solutions

Digital keys are not only changing the world of vehicles, but also the way we secure and enter buildings and rooms. Anyone interested in secure, standardized access solutions via smartphones will find exciting insights into the new Aliro standard in our next article - and how it will shape the future of access control.

Patrick Peltzer

About ME

All contributions from Patrick Peltzer

Learn more

Further information on our website and in our newsletter

Arrow up