Digital Key Technology
A digital car key is a cryptographic credential stored on a compatible phone, watch or other secure device. It can authorize entry and driving, but its security depends on ranging, enrollment, account recovery and revocation as much as on the radio technology.
Three radios, three jobs
Digital-key systems commonly combine NFC, Bluetooth Low Energy and ultra-wideband rather than choosing one.
Near-field communication (NFC) works across a very short distance. A deliberate tap at the door or interior reader gives the user a clear physical action and can provide a backup path when passive entry is unavailable. Supported devices may retain limited NFC key operation in a low-battery state.
Bluetooth Low Energy (BLE) provides discovery and a flexible communications channel. It can support remote button-like actions and help establish that an authorized device is nearby, but signal strength alone is not a trustworthy distance measurement.
Ultra-wideband (UWB) measures signal travel time to estimate distance and direction more securely. The Car Connectivity Consortium's Digital Key Release 3 uses BLE with UWB for hands-free, location-aware access while retaining NFC compatibility. UWB is intended to resist relay attacks by verifying physical proximity, but the vehicle, device and implementation all need to support the secure ranging method. Car Connectivity Consortium Digital Key Release 3 v1.1
What happens during access
The phone does not transmit the owner's ordinary account password to the car. A provisioned device holds a vehicle-specific credential, typically protected in tamper-resistant hardware. The vehicle and device authenticate each other, negotiate a protected session and authorize a precise action.
For passive entry, BLE can discover and communicate with the device while UWB determines whether it is outside a particular door, inside the cabin or near the cargo area. NFC can provide tap-based access when passive operation is unsupported or intentionally disabled.
Unlocking, opening cargo and authorizing propulsion should be separate permissions. Location also matters: a device near the outside of a door must not be mistaken for one inside the cabin.
The CCC certification program tests end-to-end interoperability for NFC, BLE and UWB functions, including cross-platform key sharing and security evaluation. Certification is useful evidence for tested interoperability; it is not a guarantee against every implementation or account-level failure. Car Connectivity Consortium Digital Key certification
Provisioning establishes the owner
The highest-risk moment may be creation of the first key. A sound enrollment process verifies the vehicle, an existing owner credential and the account or device receiving authority. Adding another key should require deliberate approval and generate a clear notification.
The owner's device can then issue shared keys with limits such as:
- a start and expiry time;
- entry-only or cargo-only access;
- permission to drive;
- restrictions on resharing; and
- immediate suspension or revocation.
The CCC describes one owner device and support for additional friend devices, along with key sharing, termination and suspension. Vehicle manufacturers may expose a narrower set of controls, so buyers should check the exact implementation rather than assuming every “digital key” follows the full standard. CCC Digital Key: The Future of Vehicle Access
The phone wallet and biometrics
Wallet-based keys can use secure hardware and the phone's screen lock or biometrics to protect provisioning and sensitive actions. Apple states that access credentials are stored in the Secure Element and that shared-key invitations are protected end to end. Express Mode can permit a supported key transaction without Face ID, Touch ID or a passcode; users who prefer explicit authentication can disable it for the key. Apple Platform Security: access using Apple Wallet
Biometrics normally authenticate the person to the phone or wallet. They do not mean that the vehicle stores a face or fingerprint, and they are different from an in-cabin driver-recognition camera. Owners should check which biometric data stays on the device, which data reaches the manufacturer and what recovery method bypasses biometrics.
Lost phones, empty batteries and offline use
A practical digital key needs defined fallback behavior:
- A supported low-battery mode may keep NFC access available for a limited period.
- A key card or physical fob can provide an independent backup.
- Remote revocation can disable the lost device when connectivity returns.
- The owner-account recovery process can restore access without weakening key enrollment.
The vehicle and device may cache authorization so that normal access works without a live cellular connection. Cloud connectivity may still be needed for first-time provisioning, remote sharing, revocation or account recovery.
If a phone is lost, mark or erase it through the device platform, revoke its vehicle key through another authorized device or the manufacturer account, and review shared drivers and account sessions. Replacing a phone is not complete until the old credential is confirmed removed.
Threats and design responses
Relay attacks exploit weak proximity checks. Secure UWB time-of-flight ranging is a direct response; BLE signal strength is not equivalent.
Account takeover can abuse legitimate provisioning or remote controls. Multi-factor authentication, fresh approval for high-impact actions and enrollment alerts reduce this risk.
Stolen unlocked devices can expose keys or owner apps. A strong device passcode, hardware-backed storage and remote erase matter.
Excessive sharing leaves forgotten credentials active. Visible key inventories, expiry and one-tap revocation make the lifecycle manageable.
Backend or update compromise can affect many vehicles at once. Vehicle cybersecurity, signed updates, monitoring and incident response remain necessary outside the key protocol.
What owners should check
Before relying on a phone as the only key, verify:
- supported phone, watch, operating-system and vehicle versions;
- NFC, BLE and UWB support on the exact device and trim;
- the backup method with a depleted phone or vehicle battery;
- whether passive entry can be disabled;
- every active owner, shared key and permitted function;
- multi-factor authentication and recovery-email security;
- alerts for a newly enrolled key or driver; and
- the resale process for deleting wallet keys and transferring ownership.
For older fobs and passive entry, see Vehicle access basics. For layered protection after a credential failure, see Theft prevention and recovery.