Vehicle control system

The vehicle control system addresses the issue of unauthorized vehicle operation by switching between operation-inhibited and enabled states based on terminal operations, effectively preventing theft and maintaining user convenience.

JP2025086079APending Publication Date: 2025-06-06TOYOTA INDUSTRIES CORP

Patent Information

Application Number
JP2023199888
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-27
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

Existing vehicle control systems do not effectively prevent unauthorized operation of vehicles even after authentication, allowing stolen vehicles to be driven.

Method used

A vehicle control system that includes a start notification sending unit and an operation control unit, which switches the vehicle between an operation-inhibited state and an operation-enabled state in response to operations performed on registered terminals, thereby preventing unauthorized operation.

Benefits of technology

The system effectively inhibits vehicle operation even after authentication, preventing theft and ensuring the vehicle cannot be driven to a remote location, while maintaining minimal user inconvenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025086079000001_ABST
    Figure 2025086079000001_ABST
Patent Text Reader

Abstract

To provide a vehicle control system that can suppress a vehicle from operating even after the vehicle is brought into an operable state by an activity of an improper user.SOLUTION: Vehicle control systems (1, 1a and 1b) comprise: start-notification transmitting parts (relay servers 71 and 71a, and an operation support ECU 21a) which transmit operation start-notifications to one or a plurality of registered terminals (portable terminals 6, 6a, 6b, and 6c) associated with vehicles (2, 2a, and 2b) in accordance with operation of starting the vehicles; and operation control parts (driving support ECU 21, 21a, and 21b) which when operation control request operation is performed to the registered terminals in response to the operation-start notifications, switch the vehicles between an operation suppression state and an operation possible state.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to a vehicle control system, and more particularly to a vehicle control system that switches a vehicle between an operation-restricted state and an operation-enabled state in response to an operation on a terminal. [Background technology]

[0002] Patent Document 1 discloses a driver authentication system that uses a mobile terminal that stores an electronic certificate to determine whether or not to permit driving of a vehicle. In this system, the electronic certificate is transmitted from the mobile terminal to an authentication authority, which then determines whether or not the electronic certificate is legitimate. If the electronic certificate is legitimate, the vehicle doors are unlocked and the engine is permitted to start. This system realizes a robust authentication function that uses a mobile terminal instead of a vehicle key (vehicle key, remote control key). [Prior art documents] [Patent documents]

[0003] [Patent Document 1] JP 2002-96715 A Summary of the Invention [Problem to be solved by the invention]

[0004] However, even in the above system, if a mobile terminal is stolen and the mobile terminal is unlocked, the vehicle associated with the mobile terminal can be driven. In other words, the above system does not take into consideration the suppression of the operation of the vehicle after the vehicle is unlocked through authentication using the mobile terminal by an unauthorized user (i.e., after the vehicle is in an operable state).

[0005] The present invention has been devised in consideration of these points, and aims to provide a vehicle control system that can suppress the operation of a vehicle even after the vehicle has become operable through actions by an unauthorized user. [Means for solving the problem]

[0006] In order to solve the above problems, the vehicle control system of the first aspect of the present invention has a start notification sending unit that sends an operation start notification to one or more registered terminals associated with the vehicle in response to a start operation on the vehicle, and an operation control unit that switches the vehicle between an operation inhibited state and an operation enabled state when an operation control request operation is performed on the registered terminal in response to the operation start notification.

[0007] A second invention of the present invention is a vehicle control system related to the first invention above, wherein the operation control unit switches the vehicle to the operable state when it is determined that deregistration information input after the vehicle is switched to the operation suppression state corresponds to registration deregistration information associated with the vehicle.

[0008] A third aspect of the present invention is the vehicle control system according to the second aspect of the present invention, wherein the release information is input via a telephone operator.

[0009] A fourth aspect of the present invention is a vehicle control system according to the first aspect of the present invention, comprising a biometric information acquisition unit that acquires biometric information of a driver of the vehicle, and when it is determined that the acquired biometric information does not correspond to registered biometric information associated with the vehicle, the operation control unit switches the vehicle to the operation suppression state.

[0010] A fifth invention of the present invention is a vehicle control system according to the first invention, comprising an in-vehicle transmitting unit that transmits an operation detection notification to the start notification transmitting unit in response to the start operation, the start notification transmitting unit being provided in a server device, and transmitting the operation start notification upon receiving the operation detection notification.

[0011] A sixth aspect of the present invention is a vehicle control system according to the fifth aspect of the present invention, wherein the registration terminal has an input control unit that, upon receiving the operation start notification, realizes a state in which each of the operation control request operations and the operation not requiring operation control can be executed by a user.

[0012] A seventh invention of the present invention is a vehicle control system related to the first invention above, wherein the start notification sending unit is provided in the vehicle, and the operation control unit determines that the operation control request operation has been performed when a reply to the operation start notification is sent from the registered terminal.

[0013] An eighth aspect of the present invention is a vehicle control system according to the seventh aspect of the present invention, wherein the operation control unit determines that the operation control request operation has been performed only if the response is to the last-sent operation start notification when the operation start notification has been sent multiple times to the registered terminal.

[0014] A ninth aspect of the present invention is a vehicle control system according to the first aspect of the present invention, wherein the operation control unit realizes the operation inhibition state by setting an upper limit acceleration if the vehicle is traveling after the start operation.

[0015] A tenth aspect of the present invention is a vehicle control system related to the first aspect of the present invention, wherein the operation control unit switches the control mode between a first control mode that switches to the operable state in response to the operation control request operation and a second control mode that switches to the operation inhibited state in response to the operation control request operation based on a determination that mode change information has been input.

[0016] An eleventh aspect of the present invention is a vehicle control system related to the first aspect of the present invention, wherein when the operation control request operation is performed, the operation control unit switches the vehicle to the operation suppression state and sends a fraudulent use report including location information of the vehicle. Effect of the Invention

[0017] In the first invention, a registration terminal (e.g., a mobile terminal) receives an operation start notification every time an operation for starting the operation of a vehicle (i.e., a start operation) is performed. If the vehicle is stolen (i.e., if the start operation is performed fraudulently), the user of the registration terminal can switch the vehicle from an operable state to an operation inhibited state by performing an operation control request operation. For example, if a vehicle key (or a mobile terminal that can be used as a vehicle key) is stolen, it is generally possible to unlock and drive the vehicle using the vehicle key. However, according to this system, even if the vehicle key is stolen, the operation of the vehicle can be inhibited by performing an operation control request operation on the registration terminal. In other words, even if a vehicle is stolen, the vehicle is inhibited from traveling to a remote location.

[0018] In addition, if multiple mobile terminals are registered as registered terminals for a vehicle, even if some of the registered terminals are stolen along with the vehicle key, the operation of the vehicle can be suppressed by issuing an operation control request to the other registered terminals.

[0019] On the other hand, if the start operation is intentional (i.e., if the start operation is performed by a legitimate driver), no operation is required on the registered terminal. In other words, in the event of theft, the vehicle can be put into an operation-suppressed state by an operation to request operation of operation control, whereas in the event of legitimate use, no specific operation is required to be performed after the start operation. Therefore, the decrease in convenience for the user of the vehicle and / or the registered terminal caused by the application of this system is very minor.

[0020] Furthermore, in the first aspect of the present invention, the vehicle may be configured to switch from the operation inhibited state to the operation enabled state in response to an operation control request operation. In this case, an operation control request operation to the registration terminal is required to set the vehicle to the operation enabled state. In other words, in this embodiment as well, the operation of the vehicle can be inhibited if the vehicle key is stolen.

[0021] In the second aspect of the present invention, the operation inhibiting state is maintained unless the release information is input, making it difficult for a person who has stolen a vehicle (a thief) to release the operation inhibiting state.

[0022] In the third invention, a telephone operator is involved when inputting the release information. If the operation inhibition state can be released by a predetermined operation on the registration terminal, if the registration terminal is stolen together with the vehicle, the thief may release the operation inhibition state by operating the registration terminal. On the other hand, according to the third invention, it is possible to prevent a thief who does not know the release information from releasing the operation inhibition state. In addition, a legitimate user of the vehicle can release the operation inhibition state of the vehicle even if the registration terminal is disabled by the thief.

[0023] In the fourth aspect of the present invention, if the biometric authentication information of the person driving the vehicle does not correspond to the registered biometric authentication information (i.e., the biometric authentication information of the legitimate driver), the vehicle is put into an operation-suppressed state. Therefore, even if an operation control request operation cannot be made to the registered terminal (for example, if the registered terminal is stolen together with the vehicle), the vehicle can be put into an operation-suppressed state.

[0024] In the fifth invention, when a start operation is performed, an in-vehicle transmitting unit transmits an operation detection notification to a server device (specifically, a start notification transmitting unit). When the server device receives the operation detection notification, it transmits an operation start notification to the registered terminal. The operation control request operation is performed, for example, via a user interface provided by an application (reporting app) that is installed in the registered terminal and communicates with the server device. In other words, when the server device transmits the operation start notification to the registered terminal (specifically, the reporting app), it can also transmit information to be provided to the user (terminal user) of the registered terminal. Therefore, the terminal user can appropriately determine whether or not to perform the operation control request operation.

[0025] In the sixth aspect of the present invention, when an activation start notification is sent to a registered terminal, if there is no need to perform an activation control request operation, the terminal user can perform an activation control unnecessary operation. Therefore, even if the terminal user has a tendency to feel uncomfortable if he or she does not perform some operation when receiving an activation start notification, he or she can feel at ease by performing an activation control unnecessary operation.

[0026] In the seventh invention, when a start operation is performed, an operation control unit provided in the vehicle transmits an operation detection notification to the registration terminal. In addition, when the terminal user who has received the operation start notification determines that the vehicle should be put into an operation suppression state, the terminal user transmits a reply to the received operation start notification to the vehicle (specifically, the operation control unit). Therefore, according to the seventh invention, it is possible to build a vehicle control system with a simple configuration that does not require a server device. In addition, the terminal user can perform an operation to request operation control with a simple operation.

[0027] In the eighth aspect of the present invention, even if the terminal user replies to a previously received activation start notification, the vehicle is not put into an activation suppression state. In other words, as described above, it is possible to perform an activation control request operation with a simple operation, while reducing the possibility that the terminal user will erroneously perform an activation control request operation.

[0028] In the ninth aspect of the invention, if the thief has already started driving the vehicle after performing the start operation, the upper limit acceleration is set. If the state in which the operation of the vehicle's driving force source is prohibited is realized as an operation suppression state while the vehicle is running, the vehicle will not be able to continue driving, which may disrupt traffic around the vehicle. On the other hand, according to the ninth aspect of the invention, it is possible to make it difficult for the vehicle to drive to a remote location, while reducing the possibility of traffic disruption.

[0029] In the tenth aspect of the invention, when switching (changing the setting) between the first control mode and the second control mode, input of mode change information is required. The mode change information is, for example, information that is kept secret by the vehicle manufacturer. In this case, only personnel of the vehicle manufacturer or dealer can change the setting. Therefore, it becomes very difficult for a thief to change the setting and switch the vehicle from an operation inhibited state to an operation enabled state.

[0030] In the eleventh aspect of the present invention, when an operation control request operation is performed, the vehicle is put into an operation inhibited state and a fraudulent use report is sent. Therefore, when personnel are dispatched based on the location information (report location) included in the fraudulent use report, there is a high possibility that the personnel can reach the vehicle at the report location (or in the vicinity of the report location). In other words, it becomes easy to recover a stolen vehicle. [Brief description of the drawings]

[0031] [Figure 1] 1 is a schematic diagram of a vehicle control system according to a first embodiment. [Diagram 2] 1 is a schematic diagram of a vehicle (controlled vehicle) and a vehicle key related to the vehicle control system. [Diagram 3] FIG. 13 is a diagram showing a message sequence when no operation request for operational control is performed on a mobile terminal (registered terminal). [Figure 4] 13 is a diagram showing an example of a notification screen displayed on a registration terminal when an unlocking operation is performed on a controlled vehicle. FIG. [Diagram 5] 4 is a flowchart showing a "driver verification process routine" executed by a driving assistance ECU of a vehicle to be controlled. [Figure 6] 13 is a diagram showing a message sequence when an operation control request operation is performed on a registered terminal. FIG. [Figure 7] 4 is a flowchart showing an "operation suppression processing routine" executed by a driving assistance ECU. [Figure 8] 13 is a diagram showing a message sequence when the operation suppression state of a controlled vehicle is released. FIG. [Figure 9] FIG. 11 is a schematic diagram of a vehicle control system according to a second embodiment. [Figure 10] FIG. 11 is a diagram showing a message sequence according to the second embodiment. [Figure 11] FIG. 11 is a diagram showing a message sequence according to the third embodiment. [Figure 12] FIG. 13 is a diagram showing an example of a notification screen according to the third embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0032] (First embodiment) A first embodiment of the present invention will be described with reference to Figures 1 to 8. The same symbols (reference numbers) in the description refer to the same elements having the same functions without duplicate explanation. As shown in Figure 1, a vehicle control system 1 according to this embodiment includes a vehicle 2, a mobile terminal 6, a relay server 71, a police system 72, and a call center system 73.

[0033] The vehicle 2 and the mobile terminal 6 are connected to a wireless communication network 81 provided by a mobile phone carrier (wireless communication carrier). The relay server 71, the police system 72, and the call center system 73 are connected to the Internet 82. The wireless communication network 81 and the Internet 82 are connected via a gateway 91 provided by the mobile phone carrier. Therefore, the vehicle 2 and the mobile terminal 6 can communicate with the relay server 71. In other words, the mobile phone carrier that provides the wireless communication network 81 is also an Internet service provider (ISP). Note that the vehicle 2 and the mobile terminal 6 may be connected to wireless communication networks 81 of different mobile phone carriers.

[0034] The call center system 73 is also connected to a fixed telephone communication network 83 provided by a fixed telephone carrier. The fixed telephone communication network 83 is connected to a wireless communication network 81 via a gateway exchange 92 (point of interconnection, POI). Therefore, it is possible to make a call from the mobile terminal 6 to the call center system 73.

[0035] A vehicle included in the vehicle control system 1, such as the vehicle 2 (specifically, a vehicle corresponding to a vehicle ID registered in a vehicle information DB described later) is also referred to as a "vehicle to be controlled." A mobile terminal included in the vehicle control system 1, such as the mobile terminal 6 (specifically, a mobile terminal corresponding to a terminal ID registered in the vehicle information DB) is also referred to as a "registered terminal." The vehicle control system 1 includes a large number of vehicles to be controlled and registered terminals, but in this embodiment, the operation of each of the vehicles to be controlled and the registered terminal will be described with reference to the vehicle 2 and the mobile terminal 6.

[0036] (Configuration of controlled vehicles) 2, the vehicle 2 includes a driving assistance ECU 21, a body ECU 22, and an engine ECU 23. The driving assistance ECU 21 is an electronic control unit (control device, control section) including a CPU, a ROM, a RAM, and an EEPROM. The body ECU 22 and the engine ECU 23 each have a configuration similar to that of the driving assistance ECU 21. These ECUs are capable of data communication (data exchange) with each other via a CAN 24 (Controller Area Network).

[0037] The CPU sequentially executes predetermined programs to read data, perform numerical calculations, and output the calculation results. The ROM stores programs executed by the CPU and maps (lookup tables), etc. The RAM temporarily stores data referenced by the CPU. The EEPROM is a non-volatile memory. The EEPROM stores data referenced by the CPU, and furthermore, continues to hold the stored data even when the driving assistance ECU 21 stops operating. The EEPROM of the driving assistance ECU 21 includes a flash memory (flash EEPROM) that stores map information.

[0038] The driving assistance ECU 21 is connected to a positioning signal receiving device 31, a touch panel display 32, a speaker 33, an in-vehicle communication device 34, and an in-vehicle camera 35.

[0039] The positioning signal receiving device 31 receives positioning signals transmitted from a plurality of positioning satellites (satellites of a navigation satellite system, for example, GPS satellites). The driving assistance ECU 21 acquires a vehicle position Pn, which is position information of the vehicle 2, every time a predetermined time elapses, based on the received positioning signals. The vehicle position Pn is represented by a combination of latitude and longitude. The driving assistance ECU 21 stores the acquired vehicle position Pn in the EEPROM.

[0040] The display 32 and the speaker 33 are disposed in the cabin of the vehicle 2. While the vehicle 2 is traveling, the driving assistance ECU 21 causes the display 32 to display map information together with the vehicle position Pn and the planned traveling route of the vehicle 2. In addition, information regarding the planned traveling route is notified to the driver via the speaker 33. That is, the driving assistance ECU 21 provides a navigation function.

[0041] The in-vehicle communication device 34 is a data communication module (DCM) that communicates with the wireless communication network 81. The in-vehicle communication device 34 transmits information related to a signal (data) received from the wireless communication network 81 to the driving assistance ECU 21, and transmits a signal to the wireless communication network 81 in response to an instruction from the driving assistance ECU 21. The telephone number assigned to the in-vehicle communication device 34 by the mobile phone carrier is treated as the vehicle ID of the vehicle 2.

[0042] The in-vehicle camera 35 is disposed in the passenger compartment of the vehicle 2. The in-vehicle camera 35 captures an image of the face of a person sitting in the driver's seat (not shown) of the vehicle 2 as a "driver image" and transmits data representing the driver image to the driving assistance ECU 21. The driver image is referred to as biometric authentication information of the driver of the vehicle 2 in a driver matching process described later. For convenience, the in-vehicle camera 35 is also referred to as a "biometric information acquisition unit."

[0043] The body ECU 22 is connected to a proximity communication device 41 and a door lock actuator 42. The proximity communication device 41 includes multiple communication antennas (not shown) and communicates with a vehicle key 5 (so-called smart entry key, intelligent key). The door lock actuator 42 includes multiple electric motors that switch the vehicle doors, rear gate, etc. equipped in the vehicle 2 between a locked state and an unlocked state.

[0044] The vehicle key 5 is provided with a lock button 51 and an unlock button 52. When the lock button 51 or the unlock button 52 is pressed while the vehicle key 5 is in the vicinity of the vehicle 2, the vehicle key 5 communicates with the near-field communication device 41. When the body ECU 22 determines that the vehicle key 5 is registered in advance, it controls the door lock actuator 42 in response to the lock button 51 or the unlock button 52 that was pressed.

[0045] Specifically, when the lock button 51 is pressed, the body ECU 22 switches the vehicle 2 to a locked state. When the unlock button 52 is pressed, the body ECU 22 switches the vehicle 2 to an unlocked state. For convenience, the operation of pressing the unlock button 52 of the vehicle key 5 to put the vehicle 2 into an unlocked state is also referred to as an "unlock operation" or "start operation." When the unlock operation is performed, the body ECU 22 transmits an "unlock signal" to the driving assistance ECU 21. Note that multiple vehicle keys (i.e., the vehicle key 5, and one or more vehicle keys different from the vehicle key 5 and of the same type as the vehicle key 5) can be registered in the body ECU 22.

[0046] The engine ECU 23 is connected to the engine 43 (more specifically, to various sensors (not shown) arranged in the engine 43) and an engine actuator 44. The engine 43 is a driving force source for the vehicle 2. The engine actuator 44 is various actuators including a throttle valve actuator and a fuel injection valve arranged to control the engine 43. The engine ECU 23 controls the engine actuator 44 based on signals received from sensors arranged in the engine 43, thereby controlling the engine 43 (in particular, the torque generated by the engine 43).

[0047] In addition, the engine ECU 23 starts or stops the operation of the engine 43 in response to an operation of an engine switch (a so-called ignition switch, not shown) of the vehicle 2. Furthermore, the engine ECU 23 transmits a vehicle speed Vs, which is the traveling speed of the vehicle 2, to the driving assistance ECU 21 every time a predetermined time elapses. The driving assistance ECU 21 corrects the vehicle position Pn based on the received vehicle speed Vs, and provides a navigation function based on the corrected vehicle position Pn.

[0048] In the following description, functions realized by an ECU (particularly, the driving assistance ECU 21) mounted on the vehicle 2 may be described as functions of the vehicle 2 (i.e., the controlled vehicle). In addition, two-way communication is possible between the relay server 71 and the vehicle 2 (more specifically, the in-vehicle communication device 34) by well-known means. For example, notification from the relay server 71 to the vehicle 2 is performed via a well-known push notification delivery service, but a detailed description will be omitted. Note that information required for two-way communication between the relay server 71 and the vehicle 2 is stored in a vehicle information DB described later, together with the vehicle ID.

[0049] (Registration terminal configuration) The mobile terminal 6 is a well-known smartphone equipped with a touch panel display 61 (see FIG. 1), as well as a speaker and a microphone (neither of which are shown). A "vehicle theft reporting application" (also simply referred to as a "reporting app") is installed in the mobile terminal 6. The reporting app communicates with the relay server 71 via the Internet 82. The operation of the reporting app in cooperation with the relay server 71 will be described later. The telephone number assigned to the mobile terminal 6 by the mobile phone carrier is treated as the terminal ID of the mobile terminal 6.

[0050] In the following description, functions realized by the reporting application may be described as functions of the mobile terminal 6. In addition, two-way communication is possible between the relay server 71 and the mobile terminal 6 (more specifically, the reporting application) by well-known means, similar to the vehicle 2.

[0051] (Configuration of relay server and police system) The relay server 71 is a known general-purpose computer (server device) and includes a CPU, a non-volatile memory, and a RAM (none of which are shown), as well as a storage device 71s (see FIG. 1). The storage device 71s is a known large-capacity storage device (storage device). The relay server 71 may be realized by multiple housings, or may be a shared server device (so-called cloud server) that is also used for purposes other than the vehicle control system 1.

[0052] The storage device 71s stores a "vehicle information DB" and a "notification history DB" to be described later. (a) vehicle IDs of various controlled vehicles, including vehicle 2; (b) the terminal ID of one or more registered terminals associated with the vehicle ID; (c) an "unlock code" associated with the vehicle ID; and (d) The vehicle registration number (or vehicle number) corresponding to the vehicle ID. In the following description, when the vehicle registration number is mentioned, it includes the case where the vehicle number is stored in the vehicle information DB instead of the vehicle registration number. For convenience, the release code is also referred to as "release information". In particular, the release code stored in the vehicle information DB is also referred to as "registration release information".

[0053] For example, the terminal ID given to the mobile terminal 6 is associated with the vehicle 2 in the vehicle information DB. That is, the vehicle information DB stores a combination including the vehicle ID of the vehicle 2 and the terminal ID of the mobile terminal 6. One terminal ID may be associated with multiple vehicle IDs. The vehicle ID and release code associated with the terminal ID can be registered via a reporting app, but a specific description of information registration in the vehicle information DB will be omitted.

[0054] The police system 72 is a general-purpose computer having the same configuration as the relay server 71. The police system 72 is operated by a police agency (i.e., an administrative agency). As described later, the police system 72 is configured to be able to receive a report of unauthorized use from the relay server 71.

[0055] (Case A) Normal use The operation of the vehicle control system 1 when a legitimate user carrying the vehicle key 5 (in this example, a terminal user carrying the mobile terminal 6 and the owner of the vehicle 2) attempts to drive the vehicle 2 will be described with reference to Figure 3.

[0056] In FIG. 3 (and FIGS. 6 and 8), the processes performed by the vehicle 2 are given step codes ending in "v". The processes performed by any of the relay server 71, the police system 72, and the call center system 73 are given step codes ending in "s". The processes performed by the mobile terminal 6 are given step codes ending in "t". Operations performed by the terminal user are given step codes ending in "u". Furthermore, the description of steps is omitted for the processes performed by the mobile terminal 6 due to operations by the terminal user (specifically, the process of transmitting data to the relay server 71).

[0057] When an unlocking operation is performed on the vehicle 2 (i.e., pressing the unlock button 52 on the vehicle key 5), the vehicle 2 enters an unlocked state as described above. In response to this, the driving assistance ECU 21 receives an unlocking signal from the body ECU 22. That is, the driving assistance ECU 21 detects the unlocking operation (step 31v). When the driving assistance ECU 21 detects the unlocking operation, it transmits an "operation detection notification" to the relay server 71. The operation detection notification includes the vehicle ID of the vehicle 2 and the last acquired vehicle position Pn. For convenience, the driving assistance ECU 21 that transmits the operation detection notification to the relay server 71 is also referred to as an "in-vehicle transmission unit."

[0058] When the relay server 71 receives the operation detection notification from the vehicle 2, it extracts the notification destination terminal (step 32s). More specifically, the relay server 71 obtains the terminal ID associated with the vehicle 2 by applying the vehicle ID included in the operation detection notification to the vehicle information DB. In addition, the relay server 71 transmits an "operation start notification" to the registered terminal corresponding to the terminal ID (in this example, the mobile terminal 6). The operation start notification includes the vehicle registration number of the vehicle 2 and the time of reception of the operation detection notification. For convenience, the relay server 71 that transmits the operation start notification is also referred to as a "start notification transmission unit."

[0059] If multiple terminal IDs are registered in the vehicle information DB for the vehicle ID, the relay server 71 transmits an operation start notification to each of the multiple terminal IDs (i.e., multiple registered terminals). Furthermore, the relay server 71 stores the vehicle ID, the vehicle position Pn, and the reception time of the operation detection notification in the notification history DB.

[0060] Upon receiving the operation start notification from the relay server 71, the mobile terminal 6 (more specifically, the report application) displays a "notification screen" on the display 61 (step 33t). As shown in Fig. 4, the notification screen includes a message indicating that the vehicle 2 is in an unlocked state (see display area R1), as well as a report button B1, a confirmation button B2, and a call button B3. The confirmation button B2 is a button that is tapped when an unlocking operation for the vehicle 2 is intended. The report button B1 and the call button B3 will be described later.

[0061] In addition, the notification screen includes the time of receipt of the operation detection notification (see display area R2) and the vehicle registration number (see display area R3). For convenience, the operation of tapping the confirmation button B2 on the notification screen is also referred to as an "operation not requiring operation control." The report app that displays the confirmation button B2 on the display 61 in addition to the report button B1 is also referred to as an "input control unit."

[0062] In this example, since the unlocking operation is performed by the owner (terminal user) of the vehicle 2, the terminal user taps the confirmation button B2 (step 34u). When the confirmation button B2 is tapped, the mobile terminal 6 transmits a “confirmation notice” to the relay server 71.

[0063] When the relay server 71 receives the confirmation notification, it stores the confirmation history (step 35s). More specifically, the relay server 71 adds the terminal ID and the reception time of the confirmation notification received from the registered terminal related to the terminal ID to the combination of the vehicle ID, the vehicle position Pn, and the reception time of the operation detection notification stored in the notification history DB. When confirmation notifications are received from multiple registered terminals, the terminal ID and the reception time of the confirmation notification related to each of the multiple confirmation notifications are added to the notification history DB. The user of the mobile terminal 6 can view the information related to the vehicle 2 (including the reception time of the confirmation notification) stored in the notification history DB using the reporting app, but a specific description of viewing the notification history DB will be omitted.

[0064] Incidentally, the tapping of the confirmation button B2 by the terminal user may be omitted. In this case, the processes of steps 34u and 35s are not executed. That is, a confirmation notification is not transmitted from the mobile terminal 6 to the relay server 71, and therefore the reception time of the confirmation notification is not stored in the notification history DB. In addition, the operation suppression process described later is not executed due to the confirmation button B2 not being tapped. In other words, the terminal user can drive the vehicle 2 without tapping the confirmation button B2.

[0065] When a predetermined "verification start condition" is satisfied after transmitting the cancellation notification, the driving assistance ECU 21 executes the "driver verification processing routine" shown in the flowchart of Fig. 5 (step 36v). In this embodiment, the verification start condition is satisfied when the vehicle 2 starts traveling after the cancellation operation is detected and the vehicle speed Vs becomes higher than a predetermined speed threshold Vth (i.e., Vs>Vth).

[0066] When the driver verification process is started, the CPU of the driving assistance ECU 21 (hereinafter also simply referred to as "CPU") starts the process from step 500 in Fig. 5 and proceeds to step 505, where it acquires (receives) an image of the driver captured by the in-vehicle camera 35. Next, the CPU proceeds to step 510, where it acquires a "registered person image" stored in the EEPROM of the driving assistance ECU 21.

[0067] The registered person image is an image of the legitimate driver of the vehicle 2 that is registered (stored) in advance. It is also possible to register images of multiple drivers as registered person images. The registered person image is registered by taking a picture of the face of a person sitting in the driver's seat of the vehicle 2 with the in-vehicle camera 35 by operating the display 32. An explanation of the specific procedure for registering the registered person image will be omitted. In this example, an image of the owner of the vehicle 2 is included in the registered person image. For convenience, the registered person image (i.e., the driver image associated with the vehicle 2) is also referred to as "registered biometric authentication information."

[0068] Furthermore, the CPU proceeds to step 515 and determines whether the driver image corresponds to the registered person image. Specifically, the CPU extracts multiple feature points from each of the driver image and the registered person image by a known method, and determines whether the driver image and the registered person image relate to the same person based on the extracted feature points. If multiple registered person images are registered, the CPU determines whether the registered person images include one that corresponds to the driver image.

[0069] In this example, since the driver is the owner of the vehicle 2, the image of the driver is included in the registered person image. That is, the driver image corresponds to the registered person image. Therefore, the CPU judges "Yes" in step 515 and proceeds to step 520 to notify the matching result. Specifically, the CPU causes the display 32 to display an image (not shown) indicating that the driver matching process has been executed and that it has been determined by the driver matching process that the driver image corresponds to the registered person image.

[0070] Next, the CPU proceeds to step 595 and ends the processing of this routine. Processing when the driver image does not correspond to the registered person image will be described later. The above-mentioned speed threshold Vth is pre-adapted so that when the vehicle speed Vs is greater than the speed threshold Vth, it becomes difficult for a thief to place a photo of another person (e.g., the owner of the vehicle 2) in front of the in-vehicle camera 35 while the thief is driving the vehicle 2. In other words, when the matching start condition is met, it becomes difficult for a thief to "impersonate" the driver of the vehicle 2.

[0071] (Case B) When the operation suppression process is executed due to a report from a registered terminal The operation of the vehicle control system 1 when a thief who has illegally obtained the vehicle key 5 attempts to drive the vehicle 2 will be described with reference to Fig. 6. In this example, it is assumed that the owner of the vehicle 2 carries a mobile terminal 6. In Fig. 6, steps in which the same processes as those in Fig. 3 are performed are denoted by the same step symbols as in Fig. 3.

[0072] In this example, after the processes of steps 31v and 32s are executed, when a notification screen (see FIG. 4) is displayed on the display 32 of the mobile terminal 6 (step 33t), the terminal user of the mobile terminal 6 (i.e., the owner of the vehicle 2) recognizes that the vehicle 2 has been unlocked illegally. Therefore, the terminal user taps the report button B1 included in the notification screen (step 64u). When the report button B1 is tapped, the mobile terminal 6 transmits a "report notification" to the relay server 71. The report notification includes the vehicle ID that was included in the operation start notification.

[0073] When the relay server 71 receives the notification, it stores the notification history (step 65s). Specifically, the relay server 71 adds the terminal ID and the reception time of the notification received from the registered terminal associated with that terminal ID to the combination of the vehicle ID, vehicle position Pn, and reception time of the operation detection notification stored in the notification history DB. In addition, the relay server 71 identifies the "operation inhibited vehicle" corresponding to the received notification (step 66s). Specifically, the relay server 71 identifies the control target vehicle corresponding to the vehicle ID included in the notification as the operation inhibited vehicle. In this example, vehicle 2 is the operation inhibited vehicle.

[0074] When the operation-inhibited vehicle is identified, the relay server 71 transmits an "operation inhibition request" to the operation-inhibited vehicle (i.e., vehicle 2). In addition, the relay server 71 transmits a "fraudulent use report" to the police system 72. The fraudulent use report includes the vehicle ID, the vehicle registration number, and the vehicle position Pn included in the operation detection notification. The relay server 71 stores the destination of the fraudulent use report (specifically, the IP address of the police system 72 on the Internet 82) in the storage device 71s.

[0075] When the vehicle 2 receives the operation suppression request, it executes an "operation suppression processing routine" shown in the flowchart of Fig. 7 (step 67v). More specifically, the CPU of the driving assistance ECU 21 (hereinafter also simply referred to as "CPU") starts the processing from step 700 in Fig. 7, proceeds to step 705, and causes the speaker 33 to play an alarm sound.

[0076] Next, the CPU proceeds to step 710, and displays a warning screen on the display 32. The warning screen includes a message informing the driver that the theft of the vehicle 2 has been reported to the police, and a message urging the driver to stop driving the vehicle 2.

[0077] Furthermore, the CPU proceeds to step 715 to determine whether or not the vehicle 2 has already been moving after it was (finally) unlocked. If the vehicle 2 has not been moving after it was unlocked (i.e., the position of the vehicle 2 has not changed after it was unlocked), the CPU determines "No" in step 715 and proceeds to step 720 to prohibit the operation of the engine 43. Specifically, the CPU requests the engine ECU 23 to stop the operation of the engine 43. When the request to stop the operation of the engine 43 is received, the engine ECU 23 stops the operation of the engine 43. Next, the CPU proceeds to step 795 to end the processing of this routine.

[0078] On the other hand, if the vehicle 2 is moving after the vehicle 2 is unlocked, the CPU determines "Yes" in step 715 and proceeds to 725. In other words, the CPU determines "Yes" in step 715 if the position of the vehicle 2 has changed after the vehicle 2 is unlocked, regardless of whether the vehicle speed Vs at the time when the processing of step 715 is executed is greater than "0".

[0079] In step 725, the CPU sets an upper limit acceleration Ah, and transmits the set upper limit acceleration Ah to the engine ECU 23. Upon receiving the upper limit acceleration Ah, the engine ECU 23 controls the engine 43 so that the acceleration As of the vehicle 2 (i.e., the amount of change per unit time of the vehicle speed Vs) does not exceed the upper limit acceleration Ah.

[0080] If the vehicle speed Vs of the vehicle 2 is relatively high, the CPU sets the upper acceleration limit Ah to "0". In this case, the driver of the vehicle 2 (i.e., the thief) cannot increase the vehicle speed Vs. On the other hand, if the vehicle speed Vs of the vehicle 2 is relatively low, the CPU sets the upper acceleration limit Ah to a relatively small positive value. In this case, the driver of the vehicle 2 cannot significantly increase the vehicle speed Vs. Next, the CPU proceeds to step 795.

[0081] In other words, the operation inhibition process is a process that makes it difficult for a thief to drive the vehicle 2 to a remote location. The state in which the operation of the engine 43 is prohibited and the upper acceleration limit Ah is set, which is realized as a result of the operation inhibition process (more specifically, the process of step 720 or step 725), is also referred to as an "operation inhibition state" for convenience. The driving assistance ECU 21 that executes the operation inhibition process is also referred to as an "operation control unit" for convenience. The operation of tapping the report button B1 on the notification screen to put the vehicle 2 into the operation inhibition state is also referred to as an "operation control request operation" for convenience. On the other hand, the state in which the operation inhibition process is not being executed (i.e., the state in which the operation of the engine 43 is not prohibited and the upper acceleration limit Ah is not set) is also referred to as an "operation possible state" for convenience.

[0082] When the police system 72 receives the fraudulent use report, it executes a "personnel dispatch process" (step 68s). Specifically, the police system 72 identifies personnel (e.g., a police officer) located near the vehicle 2 based on the vehicle position Pn included in the fraudulent use report. In addition, the police system 72 notifies the identified cause that the vehicle 2 has been reported stolen, the vehicle registration number of the vehicle 2, and the vehicle position Pn. In other words, the personnel dispatch process is a process that prompts the dispatch of personnel to the vehicle position Pn of the stolen control target vehicle.

[0083] (Case C) When the operation suppression process is executed due to biometric authentication 3 and 5, the operation of the vehicle control system 1 in the case where a thief illegally obtains the mobile terminal 6 in addition to the vehicle key 5 and drives the vehicle 2 will be described. In this case, even if a notification screen (see FIG. 4) is displayed on the display 32 of the mobile terminal 6 by the process of step 33t shown in FIG. 3, the owner of the vehicle 2 cannot tap the report button B1. In other words, a report notification is not transmitted from the mobile terminal 6 to the relay server 71.

[0084] However, when the above-mentioned matching start condition is satisfied, the driver matching process shown in FIG. 5 is executed (step 36v in FIG. 3). In this example, since the thief is driving the vehicle 2, the driver image captured of the thief does not correspond to the registered person image. Therefore, the CPU of the driving assistance ECU 21 judges "No" in step 515 and proceeds to step 525 to execute the operation inhibition process shown in FIG. 7. That is, in this case, the operation inhibition process is executed due to the driver matching process, not due to a tap of the report button B1 on the notification screen. Next, the CPU proceeds to step 595.

[0085] In this assumption, the operation inhibition process is executed due to the driver verification process, but the operation inhibition process may also be executed due to an operation control request operation. More specifically, if a mobile terminal other than the mobile terminal 6 (for example, a mobile terminal carried by a relative of the owner of the vehicle 2) is associated with the vehicle 2 as a registered terminal, an operation start notification is transmitted to these multiple registered terminals based on the processing of step 32s described above. Therefore, even if the report button B1 on the notification screen of the mobile terminal 6 is not tapped, when the report button B1 is tapped on another registered terminal (i.e., when the operation control request operation is executed), the operation inhibition process is executed.

[0086] (Case D) When canceling the operation suppression state The operation of the vehicle control system 1 when the operation inhibited state of the vehicle 2 (i.e., an operation inhibited vehicle) is released will be described with reference to Fig. 8. In this example, it is assumed that the owner of the vehicle 2 releases the operation inhibited state of the vehicle 2 using the mobile terminal 6. In Fig. 8, operations performed by a telephone operator in the call center system 73 on an operator terminal (not shown) are assigned step codes ending with "o". Also, the description of steps is omitted for the process executed by the call center system 73 due to the operation by the telephone operator (specifically, the process of transmitting data to the relay server 71).

[0087] The owner of the vehicle 2 (i.e., the terminal user) uses the mobile terminal 6 to make a call to a call center operated by the call center system 73 (step 81u). A call to the call center can be made by tapping the call button B3 included in the notification screen (see FIG. 4). Alternatively, the terminal user may make a call by inputting the phone number of the call center into the mobile terminal 6.

[0088] In response to an operation on the operator terminal by the telephone operator, the call center system 73 responds to the incoming call from the mobile terminal 6 (step 82o). At this time, the call center system 73 transmits an "incoming call notification" to the relay server 71. The incoming call notification includes the telephone number of the mobile terminal 6 (i.e., the terminal ID).

[0089] When the relay server 71 receives the incoming call notification, it identifies the release code (step 83s). Specifically, the relay server 71 applies the terminal ID included in the incoming call notification to the vehicle information DB to identify the vehicle ID corresponding to the terminal ID, and identifies the release code corresponding to the vehicle ID. The release code is, for example, a numeric string of a predetermined number of digits. When the release code is identified, the relay server 71 transmits an "release code notification" to the call center system 73. The release code notification includes the identified release code and a notification ID.

[0090] When the call center system 73 receives the release code notification, it displays the release code on the operator terminal (specifically, on the display of the operator terminal) (step 84s). When the release code is displayed on the operator terminal, the telephone operator prompts the terminal user of the mobile terminal 6 to dictate the release code. That is, the release code is entered via the telephone operator.

[0091] If the release code dictated by the terminal user corresponds to the release code displayed on the operator terminal, the telephone operator inputs an authentication completion signal into the operator terminal (step 85o). In response to the authentication completion signal, the call center system 73 transmits an "authentication completion signal" to the relay server 71. The authentication completion signal includes the signal ID included in the release code signal.

[0092] If the terminal ID included in the incoming call notification is associated with multiple vehicle IDs, the release code notification sent by the relay server 71 includes the release code and vehicle registration number associated with each of the multiple vehicle IDs. In this case, the operator terminal displays multiple combinations of the release code and vehicle registration number included in the release code notification. The telephone operator prompts the terminal user to dictate the combination of the vehicle registration number and release code for the operation-suppressed vehicle.

[0093] When the relay server 71 receives the authentication completion notification from the call center system 73, it identifies the "suppression release vehicle" corresponding to the authentication completion notification (step 86s). Specifically, the relay server 71 identifies the controlled vehicle corresponding to the notification ID included in the authentication completion notification as the suppression release vehicle. In this example, vehicle 2 is the suppression release vehicle. When the suppression release vehicle is identified, the relay server 71 transmits an "operation suppression release request" to the suppression release vehicle (i.e., vehicle 2).

[0094] When the vehicle 2 receives the operation inhibition release request, it executes an operation inhibition end process (step 87v). More specifically, if the driving assistance ECU 21 has requested the engine ECU 23 to stop the operation of the engine 43, the driving assistance ECU 21 requests the engine ECU 23 to release the operation inhibition of the engine 43. If the driving assistance ECU 21 has transmitted the upper limit acceleration Ah to the engine ECU 23, the driving assistance ECU 21 requests the engine ECU 23 to release the setting of the upper limit acceleration Ah. In addition, the driving assistance ECU 21 stops the reproduction of the alarm sound by the speaker 33 and the display of the warning screen on the display 32. As a result, the operation inhibition state of the vehicle 2 is released. That is, the operating state of the vehicle 2 becomes an operable state.

[0095] Second embodiment The second embodiment will be described with reference to Figs. 9-10. The vehicle control system 1 according to the first embodiment includes a relay server 71. Specifically, each of the controlled vehicle and the registration terminal communicates with the relay server 71. In contrast, in the vehicle control system 1a according to the second embodiment, communication is performed directly between the controlled vehicle and the registration terminal. The following description will focus on this difference.

[0096] 9, the vehicle control system 1a includes a vehicle 2a, mobile terminals 6a and 6b, and a police system 72a. The vehicle 2a is an example of a vehicle to be controlled in the vehicle control system 1a. The mobile terminals 6a and 6b are examples of registered terminals in the vehicle control system 1a.

[0097] The vehicle 2a includes a driving assistance ECU 21a (see FIG. 9). The vehicle 2a (more specifically, the in-vehicle communication device 34 of the vehicle 2a), the mobile terminals 6a and 6b, and the police system 72a are each connected to a wireless communication network 81. Therefore, the vehicle 2a, the mobile terminals 6a and 6b, and the police system 72a can use a short message service (SMS) provided by a mobile phone carrier. Note that the vehicle 2a, the mobile terminals 6a and 6b, and the police system 72a may each be connected to the wireless communication networks 81 of different mobile phone carriers.

[0098] The operation of the vehicle control system 1a will be described with reference to FIG. 10. In FIG. 10, steps in which the same processing as the steps shown in FIG. 6 are executed are given the same step symbols as in FIG. 6. In addition, the driver verification processing (see FIG. 5) executed by the driving assistance ECU 21a while the vehicle 2a is traveling is omitted. Furthermore, when each of the mobile terminals 6a and 6b receives a short message via the wireless communication network 81, it notifies the terminal user and displays the contents of the received short message on the display 61. However, the description of the steps of the processing executed by the mobile terminals 6a and 6b due to the reception of the short message is omitted in FIG. 10.

[0099] First, it is assumed that a legitimate driver of the vehicle 2a (specifically, the owner of the vehicle 2a) is about to drive the vehicle 2a. In addition, it is assumed that the mobile terminals 6a and 6b are carried by the owner of the vehicle 2a and the owner's relatives, respectively. In this case, when an unlocking operation for the vehicle 2a is performed (i.e., pressing the unlock button 52 on the vehicle key 5 of the vehicle 2a), the driving assistance ECU 21a transmits a short message as an "operation start notification" to the mobile terminals 6a and 6b (step 101v). For convenience, the driving assistance ECU 21a that transmits the operation start notification is also referred to as a "start notification transmission unit."

[0100] More specifically, the driving assistance ECU 21a transmits an operation start notification to the terminal ID (i.e., the telephone number of the registered terminal) of the registered terminal stored in the EEPROM of the driving assistance ECU 21a. In this example, since a plurality of registered terminals (i.e., the mobile terminals 6a, 6b) are registered, the driving assistance ECU 21a transmits an operation start notification to each of the registered terminals. The registration of the registered terminal (i.e., the association between the controlled vehicle and the registered terminal) is performed by operating the display 32 of the vehicle 2a. A description of the specific procedure for registering the registered terminal will be omitted.

[0101] The activation start notification includes a statement indicating that the vehicle 2a is in an unlocked state, the time when the unlocking operation was performed (unlocking time), and the vehicle registration number of the vehicle 2a. The activation start notifications transmitted to the mobile terminals 6a and 6b based on the processing of step 101v are also referred to as activation start notification-a and activation start notification-b.

[0102] An operation control request operation in the vehicle control system 1a is when a terminal user replies (i.e., sends a short message) to an operation start notification received by a registered terminal. In this example, the operation of sending a reply to the operation start notification-a or operation start notification-b to the vehicle 2a corresponds to the operation control request operation. According to the above assumption, since the owner of the vehicle 2a has performed the unlocking operation, there is no need to put the vehicle 2a into an operation inhibition state. Therefore, neither a reply to the operation start notification-a nor a reply to the operation start notification-b is sent.

[0103] It is assumed that a thief who has illegally obtained the vehicle key 5 and the mobile terminal 6a of the vehicle 2a then attempts to drive the vehicle 2a. When the thief performs an unlocking operation on the vehicle 2a, the driving assistance ECU 21a transmits an operation start notification (also referred to as an operation start notification-c and an operation start notification-d) to each of the mobile terminals 6a and 6b (step 102v).

[0104] Since the thief is carrying the mobile terminal 6a, he is unable to reply to the activation start notification-c. On the other hand, when the mobile terminal 6b receives the activation start notification-d, the terminal user of the mobile terminal 6b recognizes that the vehicle 2a is being operated illegally. Therefore, the terminal user of the mobile terminal 6b transmits a reply to the activation start notification-d to the vehicle 2a (step 103u). That is, an activation control request operation is performed.

[0105] When the driving assistance ECU 21a receives a reply to the operation start notification-d from the mobile terminal 6b, it acquires the report destination (step 104v). Specifically, the driving assistance ECU 21a acquires the report destination (specifically, the telephone number) of the police system 72a stored in the EEPROM. When the report destination is acquired, the driving assistance ECU 21a transmits a short message as a "fraudulent use report" to the report destination (i.e., the police system 72a).

[0106] Next, the driving assistance ECU 21a executes an operation inhibition process (see FIG. 7) (step 67v). By executing the operation inhibition process, the vehicle 2a enters an operation inhibition state. That is, the operation state of the vehicle 2a is switched from an operation possible state to an operation inhibition state. Meanwhile, when the police system 72 receives the fraudulent use report, it executes a personnel dispatch process (step 68s).

[0107] The operation inhibition state of the vehicle 2a is released by inputting a release code (i.e., release information) via the display 32. If the input release code corresponds to the release code (i.e., registration release information) stored in the EEPROM of the driving assistance ECU 21a, the driving assistance ECU 21a releases the operation inhibition state of the vehicle 2a. The reporting destination of the police system 72a and the release code are registered in the EEPROM by operating the display 32, similar to the terminal ID of the registration terminal, but a detailed description of the registration procedure will be omitted.

[0108] Incidentally, when the driving assistance ECU 21a receives a reply to the operation start notification transmitted to the registered terminal, if the received reply is not for the "last transmitted operation start notification (last transmitted notification)", the driving assistance ECU 21a does not determine that an operation control request operation has been performed. That is, the vehicle 2a does not enter an operation suppression state. In the example of FIG. 10, if the mobile terminal 6a transmits a reply to the operation start notification-a (received before the operation start notification-c) to the vehicle 2a after receiving the operation start notification-c, the driving assistance ECU 21a does not execute the operation suppression process. The driving assistance ECU 21a determines whether the received reply is for the last transmitted notification by comparing the unlocking time included in each of the transmitted operation start notifications with the unlocking time included in the reply to the operation start notification.

[0109] Third embodiment The third embodiment will be described mainly with reference to Figs. 11 and 12. The vehicle 2 according to the first embodiment is switched from an operable state to an operation inhibited state when an operation request operation is performed. In contrast, the vehicle 2b according to the third embodiment can also be set so that it can be switched from an operation inhibited state to an operable state when an operation request operation is performed. The following description will focus on this difference.

[0110] A vehicle control system 1b according to the third embodiment includes a vehicle 2b, a mobile terminal 6c, and a relay server 71a (see FIG. 1). The vehicle 2b is an example of a vehicle to be controlled in the vehicle control system 1b. The vehicle 2b includes a driving assistance ECU 21b (see FIG. 2). The mobile terminal 6c is an example of a registration terminal in the vehicle control system 1a. The mobile terminal 6c is associated with the vehicle 2b in the vehicle information DB related to the relay server 71a.

[0111] The control mode of the driving assistance ECU 21b can be switched between a "first control mode" and a "second control mode". In the first control mode, the driving assistance ECU 21b switches the operation state of the vehicle 2b from an operation inhibited state to an operation enabled state in response to an operation control request operation. In the second control mode, the driving assistance ECU 21b switches the operation state of the vehicle 2b from an operation enabled state to an operation inhibited state in response to an operation control request operation.

[0112] The operation of the vehicle control system 1b when the driving assistance ECU 21b is in the first control mode will be described with reference to Fig. 11. It is assumed that the owner of the vehicle 2b is a legitimate driver who intends to drive the vehicle 2b and is carrying the mobile terminal 6c.

[0113] In this case, when an unlocking operation for the vehicle 2b (i.e., pressing the unlock button 52 on the vehicle key 5 of the vehicle 2b) is performed, the driving assistance ECU 21b transmits an operation detection notification to the relay server 71a (step 111v). The operation detection notification transmitted by the driving assistance ECU 21b includes the control mode (in this example, the first control mode) of the vehicle 2b (more specifically, the driving assistance ECU 21b).

[0114] When the relay server 71a receives the operation detection notification, it extracts the notification destination terminal (in this example, the mobile terminal 6c) and transmits an operation start notification to the extracted notification destination terminal (step 112s). The operation start notification transmitted by the relay server 71a includes the control mode (i.e., the first control mode) included in the operation detection notification.

[0115] After the process of step 111v, the driving assistance ECU 21b executes an operation inhibition process (step 113v). Specifically, the driving assistance ECU 21b requests the engine ECU 23 to stop the operation of the engine 43. As a result, the vehicle 2b enters an operation inhibition state.

[0116] When the mobile terminal 6c (more specifically, the report app installed in the mobile terminal 6c) receives the operation start notification, it displays a notification screen on the display 61 (step 114t). Fig. 12 shows the notification screen that is displayed when the control mode included in the operation start notification is the first control mode. As can be seen from Fig. 12, the notification screen in this case includes a confirmation button B4 and a report button B5.

[0117] The confirmation button B4 is tapped to release the operation inhibition state of the controlled vehicle (vehicle 2b in this example). According to the above assumption, since the driver of vehicle 2b carries the mobile terminal 6c, the driver taps the confirmation button B4 (step 115u). Therefore, the mobile terminal 6c transmits a confirmation notification to the relay server 71a. For convenience, the operation of tapping the confirmation button B4 is also referred to as an "operation control request operation."

[0118] When the relay server 71a receives the confirmation notification, the relay server 71a stores the confirmation history (step 116s). That is, the notification history DB related to the relay server 71a is updated. Next, the relay server 71a identifies a "suppression release vehicle" (step 117s). Specifically, the relay server 71a identifies the control target vehicle (vehicle 2b in this example) corresponding to the vehicle ID included in the confirmation notification as the suppression release vehicle.

[0119] When the suppression release vehicle is identified, the relay server 71a transmits a "suppression release request" to the suppression release vehicle (i.e., vehicle 2b). When vehicle 2b (more specifically, driving assistance ECU 21b) receives the suppression release request, it executes operation suppression end processing (step 118v). Specifically, the driving assistance ECU 21b requests the engine ECU 23 to release the operation stop of the engine 43. As a result, the operation state of vehicle 2b is switched from the operation suppressed state to the operation enabled state.

[0120] On the other hand, the report button B5 is tapped by a terminal user who recognizes that the controlled vehicle is being operated fraudulently. If the report button B5 is tapped, the mobile terminal 6c transmits a report to the relay server 71a (not shown in the figures below). Upon receiving the report, the relay server 71a stores the report history and transmits a report of fraudulent use to the police system 72 based on the vehicle ID included in the report. As a result, the operation inhibition state of the vehicle 2b is maintained, while the police system 72 executes a personnel dispatch process. Since the operation inhibition state of the vehicle 2b is maintained when the report button B5 is tapped, the operation of tapping the report button B5 is also referred to as an "operation not requiring operation control" for convenience.

[0121] The operation of the vehicle control system 1b when the driving assistance ECU 21b is in the second control mode is the same as that of the vehicle control system 1 described above. More specifically, when the driving assistance ECU 21b detects an unlocking operation, the driving assistance ECU 21b does not switch the vehicle 2b to an operation inhibited state (i.e., the operation-enabled state is maintained). When the mobile terminal 6c receives an operation start notification from the relay server 71a, the mobile terminal 6c displays a notification screen shown in FIG. 4 on the display 61. That is, the mobile terminal 6c switches the notification screen to be displayed on the display 61 based on the control mode (specifically, either the first control mode or the second control mode) included in the operation start notification. When the report button B1 included in the notification screen is tapped, the mobile terminal 6c transmits a report notification to the relay server 71a. When the relay server 71a receives the report notification, the relay server 71a transmits an operation inhibition request to the operation inhibited vehicle (in this example, the vehicle 2b). When the driving assistance ECU 21b receives the operation inhibition request, the driving assistance ECU 21b executes the operation inhibition process shown in FIG. 7. As a result, the vehicle 2b is switched from the operable state to the inhibited state.

[0122] The control mode switching in the driving assistance ECU 21b (i.e., changing the setting between the first control mode and the second control mode) is performed by operating the display 32. However, the change in the control mode setting is performed by a worker at a maintenance shop of the manufacturer or dealer of the vehicle 2b. Specifically, when changing the control mode setting, the input of "mode change information" is required. The mode change information is, for example, a numeric string of a predetermined number of digits managed as a secret. When the driving assistance ECU 21b determines that the input mode change information corresponds to the "registered mode change information" stored in the EEPROM of the driving assistance ECU 21b, it allows the change in the control mode setting. In other words, the registered mode change information is mode change information that is previously associated with the vehicle 2b.

[0123] As described above, the user of the registered terminal (i.e., the mobile terminal 6, 6a, 6b) can place the controlled vehicle (i.e., the vehicle 2, 2a) in an operation inhibition state by operating the registered terminal to request operation control (i.e., tapping the report button B1 or replying to a received operation start notification). Therefore, even if the controlled vehicle is stolen, it is possible to make it difficult for the vehicle to travel after the fact, thereby preventing the vehicle from traveling to a remote location.

[0124] In addition, when the controlled vehicle is being used legitimately, the user of the registration terminal does not need to perform any operation, so the decrease in convenience for the vehicle user when using the vehicle as a controlled vehicle of the vehicle control system 1, 1a is very minor.

[0125] Furthermore, if multiple registered terminals (e.g., mobile terminals 6a, b) are associated with the controlled vehicle, an operation start notification is sent to each of the registered terminals. Therefore, even if some of the registered terminals become unavailable (e.g., some of the registered terminals are stolen together with the controlled vehicle), the vehicle can be put into an operation inhibited state by an operation control request operation to the other registered terminals.

[0126] When releasing the operation inhibition state of the controlled vehicle, it is necessary to input release information. If it were possible to release the operation inhibition state by operating the reporting app installed on the registered device, if the registered device were stolen along with the controlled vehicle and the lock on the registered device was illegally released, the operation inhibition state could also be released. However, by requiring the input of release information when releasing the operation inhibition state, it is possible to reduce the possibility of the operation inhibition state being illegally released.

[0127] The vehicle control system 1 includes a relay server 71 having a storage device 71s. The relay server 71 makes it relatively easy to operate the vehicle information DB and the notification history DB, and to link with the call center system 73. In addition, since the unauthorized use report is sent from the call center system 73, even if a thief unlocks the vehicle 2 and enters the vehicle compartment to destroy the in-vehicle communication device 34, the unauthorized use report is likely to be sent and personnel dispatch processing is likely to be executed. On the other hand, in the vehicle control system 1a, the vehicle 2a directly communicates with each of the mobile terminals 6a, 6b and the police system 72a, so that the system construction can be made relatively simple.

[0128] In the vehicle control system 1, the notification screen (see FIG. 4) displayed in response to receiving the operation start notification includes the time of receipt of the operation detection notification and the vehicle registration number, so that the terminal user can appropriately determine whether or not to tap the report button B1. In addition, the notification screen includes a confirmation button B2. It is possible to drive the controlled vehicle without tapping the confirmation button B2, but some terminal users may feel uneasy about not performing any operation on the displayed notification screen. Even such terminal users can feel reassured by tapping the confirmation button B2 (i.e., an operation that does not require operation control).

[0129] In the vehicle control system 1a, the controlled vehicle can be put into an operation suppression state by replying to the received operation start notification (i.e., an operation control request operation). Therefore, there is no need to install a notification app in the registered terminal in advance, and the operation control request operation can be easily performed. On the other hand, even if the driving assistance ECU 21a receives a reply to the operation start notification, it does not determine that an operation control request operation has been performed unless the reply is in response to the last transmission notification. This reduces the possibility that the controlled vehicle will be put into an operation suppression state due to the terminal user mistakenly replying to the operation start notification.

[0130] In the vehicle control system 1, 1a, when an operation control request operation is performed, the operation of the engine 43 is prohibited or the upper limit acceleration Ah is set in order to put the vehicle 2, 2a in an operation suppressed state. Therefore, even if the vehicle 2, 2a is already traveling at the time when the operation control request operation is performed, the possibility of disrupting traffic around the vehicle 2, 2a can be reduced, while the vehicle 2, 2a can be prevented from traveling to a remote location.

[0131] In addition, in the vehicle control system 1, 1a, when an operation request operation is performed, a report of unauthorized use including the vehicle position Pn is sent to the police system 72, 72a. This causes a request to dispatch personnel to the controlled vehicle that has entered an operation suppression state and is now unable to travel to a remote location, increasing the possibility that the vehicle will be smoothly restored.

[0132] Furthermore, the vehicle control system 1b can switch between a first control mode and a second control mode. In the first control mode, an operation request operation (i.e., tapping the confirmation button B4) is required on the mobile terminal 6c to switch the vehicle 2b to an operable state. Therefore, even if a thief unlocks the vehicle 2b and enters the vehicle compartment, he or she is prevented from driving the vehicle 2b.

[0133] In addition, the vehicle control system 1b requires input of mode change information when switching between the first control mode and the second control mode, which prevents a thief from switching the vehicle 2b from the inhibited state to the enabled state by switching from the first control mode to the second control mode.

[0134] Although the embodiment of the present invention has been described above with reference to the above structure, many alternatives, improvements, and modifications are possible without departing from the scope of the present invention. Therefore, the present invention includes all alternatives, improvements, and modifications that do not depart from the spirit and scope of the appended claims. The present invention is not limited to the specific structure described above, and may be modified, for example, as follows.

[0135] The start operation in the vehicle control system 1, 1a, 1b is the operation of pressing the unlock button 52 on the vehicle key 5. Alternatively, the start operation may be the operation of pressing the engine switch of the vehicle 2, 2a, 2b. If an electric motor is mounted as a driving power source of the vehicle 2, 2a, 2b instead of or in addition to the engine 43, the start operation may be the operation of pressing the power switch (start switch) of the vehicle. In addition, the driving assistance ECU 21, 21a, 21b may determine that the start operation has been performed when the engine 43 starts or when the parking brake of the vehicle 2, 2a, 2b is released. Alternatively, the driving assistance ECU 21, 21a, 21b may determine that the start operation has been performed when the vehicle 2, 2a, 2b starts traveling after the unlock operation has been performed and the vehicle speed Vs becomes greater than "0" (or a predetermined threshold value).

[0136] The release information in the vehicle control system 1, 1a is a release code. Instead of this, the release information may be biometric authentication information. For example, the driving assistance ECU 21, 21a may be configured to release the operation suppression state when it is determined that a driver image newly acquired by the in-vehicle camera 35 corresponds to a registered person image. In other words, the registered biometric authentication information may be used as the registration release information.

[0137] The biometric information acquisition unit in the vehicle control system 1, 1a is the in-vehicle camera 35. Alternatively, the biometric information acquisition unit may be a fingerprint sensor disposed on the steering wheel of the vehicle 2, 2a. In this case, the fingerprint of the driver acquired by the fingerprint sensor becomes the biometric authentication information.

[0138] In the vehicle control system 1, 1a, the upper limit acceleration Ah is set to "0" or a positive value. Alternatively, or in addition, the upper limit acceleration Ah may be set to a negative value. In this case, the braking device of the vehicle 2, 2a may be controlled based on the upper limit acceleration Ah set to a negative value.

[0139] The relay servers 71 and 71a may authenticate the controlled vehicle and the registration terminal when communicating with the controlled vehicle and the registration terminal, respectively. For example, an electronic certificate is stored in the controlled vehicle and the registration terminal, and the relay servers 71 and 71a may determine that the controlled vehicle or the registration terminal is a valid communication destination when the electronic certificate received from the controlled vehicle or the registration terminal corresponds to pre-registered authentication information.

[0140] In the vehicle control system 1, 1a, the report of fraudulent use is transmitted to the police system 72, 72a (i.e., a system operated by a government agency). Alternatively, the report of fraudulent use may be transmitted to a system operated by a security company (i.e., a private company).

[0141] The driving assistance ECU 21 executes the driver verification process when the verification start condition is satisfied. Alternatively, the driving assistance ECU 21 may execute the driver verification process every time a predetermined time elapses.

[0142] In the vehicle control system 1a, the operation start notification and the unauthorized use notification are sent as short messages. Alternatively, one or both of the operation start notification and the unauthorized use notification may be emails sent and received via a mail server.

[0143] The mode change information in the driving assistance ECU 21b is input via the display 32. Alternatively, the mode change information may be a signal that the driving assistance ECU 21b receives when a maintenance terminal device (or a predetermined tool) is connected to the vehicle 2b. In this case, the driving assistance ECU 21b determines that the mode change information has been input when the predetermined device or tool is connected to the vehicle 2b.

[0144] Each of the vehicle ID and the terminal ID was a telephone number assigned by a mobile phone carrier. Alternatively, the vehicle ID may be a vehicle registration number. In addition, the terminal ID may be a unique code assigned by the relay server 71.

[0145] The functions realized by the driving assistance ECUs 21, 21a, and 21b may be realized by a plurality of ECUs, or some or all of the functions realized by the driving assistance ECUs 21, 21a, and 21b may be realized by a general-purpose computer. [Explanation of symbols]

[0146] 1, 1a, 1b...Vehicle control system 2, 2a, 2b…Vehicle 21, 21a, 21b…Driver assistance ECU 22...Body ECU, 23...Engine ECU 31: Positioning signal receiving device, 32: Display, 33: Speaker 34...In-vehicle communication device, 35...In-vehicle camera 41: Near field communication device, 42: Door lock actuator 43...engine, 44...engine actuator 5...vehicle key, 51...lock button, 52...unlock button 6, 6a, 6b, 6c...Mobile terminal, 61...Display 71, 71a... relay server, 71s... storage device 72, 72a…Police system, 73…Call center system 81...wireless communication network, 82...internet, 83...fixed telephone communication network 91…Gateway, 92…Kanban Exchange B1: Report button, B2: Confirm button, B3: Call button B4: Confirmation button, B5: Report button R1~R3…display area

Claims

1. A vehicle control system, comprising: a start notification sending unit that sends an operation start notification to one or more registered terminals associated with the vehicle in response to a start operation on the vehicle; a vehicle control system having an operation control unit that switches the vehicle between an operation inhibited state and an operation enabled state when an operation control request operation is performed on the registered terminal in response to the operation start notification;

2. 2. The vehicle control system according to claim 1, The operation control unit includes: A vehicle control system that switches the vehicle to the operable state when it is determined that deregistration information input after the vehicle is switched to the inhibited state corresponds to registration deregistration information associated with the vehicle.

3. 3. The vehicle control system according to claim 2, The input of the release information is performed via a telephone operator in a vehicle control system.

4. 2. The vehicle control system according to claim 1, a biometric information acquisition unit that acquires biometric authentication information of a driver of the vehicle; The operation control unit includes: A vehicle control system that switches the vehicle to the operation inhibited state when it is determined that the acquired biometric authentication information does not correspond to registered biometric authentication information associated with the vehicle.

5. 2. The vehicle control system according to claim 1, an in-vehicle transmitting unit that transmits an operation detection notification to the start notification transmitting unit in response to the start operation; The start notification transmission unit is Provided in a server device, The vehicle control system transmits the operation start notification when the operation detection notification is received.

6. 6. A vehicle control system according to claim 5, The registration terminal includes: The vehicle control system further includes an input control unit that, upon receiving the operation start notification, realizes a state in which the operation control requesting operation and the operation not requiring operation can be executed by a user.

7. 2. The vehicle control system according to claim 1, The start notification transmission unit is A vehicle is provided with: The operation control unit includes: The vehicle control system determines that the operation control request operation has been performed when a reply to the operation start notification is transmitted from the registered terminal.

8. 8. A vehicle control system according to claim 7, The operation control unit includes: A vehicle control system that, if the operation start notification has been sent multiple times to the registered terminal, determines that the operation control request operation has been performed only if the reply is to the last operation start notification sent.

9. 2. The vehicle control system according to claim 1, The operation control unit includes: A vehicle control system that, if the vehicle is traveling after the start operation, realizes the operation inhibiting state by setting an upper limit acceleration.

10. 2. The vehicle control system according to claim 1, The operation control unit includes: A vehicle control system that switches a control mode between a first control mode that switches to the operable state in response to the operation control request operation and a second control mode that switches to the operation inhibited state in response to the operation control request operation based on a determination that mode change information has been input.

11. 2. The vehicle control system according to claim 1, The operation control unit includes: When the operation control request operation is performed, the vehicle control system switches the vehicle to the operation inhibited state and transmits an unauthorized use report including location information of the vehicle.

Citation Information

Patent Citations

  • Security equipment for vehicles, defending against unauthorized entry, use and gas attacks, includes detection systems for entry by unauthorized individuals and vehicle operation

    DE102005012290A1

  • Device for preventing burglary for vehicle

    JP2000020836A

  • System and method for tracking stolen vehicle

    JP2002220030A

  • Theft prevention system, theft prevention device, management server, on / off switching method of theft preventive function, and theft prevention method for industrial machine

    JP2005255093A

  • Burglar preventive device for vehicle

    JP2005297919A

Cited By

  • Gaming machine

    JP2026052637A

  • Gaming machine

    JP2026052638A

  • Gaming machine

    JP2026052639A

  • Gaming machine

    JP2026052640A

  • Gaming machine

    JP2026052641A