Service delivery program and service delivery system

The service provision system addresses the challenge of identifying the current user of a shared vehicle by using mobile wireless communication to register and query user identification, ensuring appropriate service provision.

JP2026103698APending Publication Date: 2026-06-24DENSO CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
DENSO CORP
Filing Date
2024-12-12
Publication Date
2026-06-24

AI Technical Summary

Technical Problem

Existing systems fail to accurately identify the current user of a vehicle when multiple users share the same vehicle, leading to inappropriate service provision due to the association of personal information with vehicle use numbers.

Method used

A service provision system utilizing mobile wireless communication between an in-vehicle wireless device and a roadside device to register and query user identification information, enabling the system to provide services to the correct user based on their pre-registered information.

Benefits of technology

Ensures appropriate services are provided to the current user of the vehicle by accurately identifying them using their pre-registered information, even when multiple users share the same vehicle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026103698000001_ABST
    Figure 2026103698000001_ABST
Patent Text Reader

Abstract

To realize service provision programs and other measures that enable the provision of appropriate services to users currently using the vehicles. [Solution] The service provision program is executed by the processing unit of the fare calculation device 70 and provides services to the vehicle user US using mobile wireless communication between the in-vehicle wireless device 10 and the roadside wireless device 50. In the processing based on the service provision program, pre-registration information related to the user US is registered in association with a first in-vehicle device number that identifies the in-vehicle wireless device 10 and a user ID that identifies the user US. In addition, the user ID of the user US using the vehicle is set. Then, when the second in-vehicle device number transmitted from the in-vehicle wireless device 10 to the roadside wireless device 50 is obtained, the first in-vehicle device number is queried using this second in-vehicle device number. As a result, the service is provided to the user US using the pre-registration information associated with the first in-vehicle device number.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The disclosure according to this specification relates to a technology for providing services to users of mobile bodies using mobile wireless communication.

Background Art

[0002] In the system disclosed in Patent Document 1, when a user enters a vehicle equipped with an in-vehicle wireless device into the communication area of a roadside wireless device, the roadside wireless device obtains an in-vehicle device management number by communicating with the in-vehicle wireless device. A server that controls the roadside wireless device converts the obtained in-vehicle device management number into a vehicle use number. The server searches a database for personal information associated with the vehicle use number and starts a service application such as a customer management application.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In the system disclosed in Patent Document 1, the personal information of a user is associated with the vehicle use number. Therefore, when a plurality of users use one vehicle, the server cannot grasp the user who is currently using the vehicle, and it has been difficult to correctly grasp the pre-registered information such as personal information related to the user. As a result, there has been a possibility that appropriate services may not be provided to the user who is currently using the vehicle.

[0005] An object of the present disclosure is to provide a service providing program and a service providing system capable of providing appropriate services to a user using the pre-registered information of the user who is currently using the vehicle even when a plurality of users use one vehicle.

Means for Solving the Problems

[0006] To achieve the above objective, one disclosed embodiment is a service provision program that provides services to a vehicle user (US) using mobile wireless communication between an in-vehicle wireless device (10) mounted in the vehicle and a roadside wireless device (50) located outside the vehicle, and causes at least one processing unit (11, 41, 71) to execute a process that includes the steps of: registering pre-registered information related to the user (S5) linked to specific in-vehicle device information, which is one of first in-vehicle device information and second in-vehicle device information that identifies the in-vehicle wireless device, and user identification information that identifies the user; obtaining user setting information that sets the user identification information of the user using the vehicle (S6); obtaining second in-vehicle device information transmitted from the in-vehicle wireless device to the roadside wireless device via mobile wireless communication (S8); querying the first in-vehicle device information using the second in-vehicle device information (S9); and providing services to the user using the pre-registered information linked to the specific in-vehicle device information (S10).

[0007] Another disclosed embodiment is a service provision system that provides services to a vehicle user (US) using mobile wireless communication between an in-vehicle wireless device (10) mounted in the vehicle and a roadside wireless device (50) located outside the vehicle, comprising: an information registration unit (81) that registers pre-registered information related to a user, linked to specific in-vehicle device information, which is either first in-vehicle device information or second in-vehicle device information that identifies the in-vehicle wireless device, and user identification information that identifies the user; a user selection unit (82) that acquires user setting information that sets the user identification information of a user using the vehicle; a communication acquisition unit (83) that acquires second in-vehicle device information transmitted from the in-vehicle wireless device to the roadside wireless device via mobile wireless communication; an in-vehicle device inquiry unit (84) that queries the first in-vehicle device information using the second in-vehicle device information; and a service implementation unit (85) that provides services to the user using pre-registered information linked to specific in-vehicle device information.

[0008] In these embodiments, when second on-board device information transmitted from the on-board radio device to the roadside radio device via mobile wireless communication is acquired, a query for first on-board device information is performed using the second on-board device information. Based on the information related to this query for first on-board device information and user setting information, it is possible to identify the user currently using the vehicle equipped with the on-board radio device that transmitted the second on-board device information, and consequently, the pre-registration information associated with this user. As a result, even if multiple users use one vehicle, it becomes possible to provide appropriate services to the user currently using the vehicle using their pre-registration information.

[0009] Furthermore, the reference numbers in parentheses above and in the claims are merely examples of correspondences with specific configurations in the embodiments described later, and do not in any way limit the technical scope. In addition, combinations of claims not explicitly stated in the claims are also possible, provided that they do not cause any particular problems with the combination. [Brief explanation of the drawing]

[0010] [Figure 1] This figure shows the overall picture of the toll collection system according to the first embodiment of this disclosure. [Figure 2] This is a block diagram showing the configuration of the toll collection system. [Figure 3] This is a sequence diagram showing the details of the pre-registration process. [Figure 4] This is a sequence diagram showing the details of the information setting process. [Figure 5] This is a sequence diagram showing the details of the entrance gate processing. [Figure 6] This is a sequence diagram showing the details of the exit gate processing. [Figure 7] This is a sequence diagram showing the details of the batch release process. [Figure 8] This block diagram shows the configuration of the toll collection system according to the second embodiment. [Figure 9] This is a block diagram showing the configuration of the toll collection system according to the third embodiment. [Modes for carrying out the invention]

[0011] Several embodiments will be described below with reference to the drawings. In each embodiment, the same reference numerals are used for corresponding components, and redundant explanations may be omitted. If only a part of the configuration is described in each embodiment, the configuration of other embodiments described earlier can be applied to the other parts of that configuration. Furthermore, in addition to the combinations of configurations explicitly stated in the description of each embodiment, configurations from multiple embodiments can be partially combined even if not explicitly stated, as long as there are no particular problems with the combination.

[0012] (First Embodiment) The toll collection system 100 according to the first embodiment of this disclosure, shown in Figures 1 and 2, is a system that provides services to a user US of a mobile entity (e.g., a vehicle) using mobile wireless communication. Mobile wireless communication is conducted between an on-board wireless device (hereinafter referred to as the on-board device; also referred to as the on-board device in the drawings) 10 mounted on the vehicle and a roadside wireless device 50 (also referred to as the roadside device in the drawings) located outside the vehicle. The toll collection system 100 makes it possible to use an automatic payment service for tolls, etc., without using payment cards, while utilizing existing infrastructure.

[0013] More specifically, in the toll collection system 100, payment information is pre-associated with the identification information assigned to the in-vehicle device 10 on the cloud, and payment processing is performed using the payment information on the cloud. This makes it possible for multiple users US using a specific vehicle, i.e., the in-vehicle device 10, to pay the toll using their respective payment information.

[0014] In addition, the toll collection system 100 ensures proper management of individual user US information and prevents the previous user US's payment information from being applied to a new user US when the vehicle and in-vehicle device 10 are resold. This prevents a new user US from using the previous user US's payment information.

[0015] <Configuration of the Fare Collection System> The fare collection system 100 is composed of an in-vehicle device 10, a number management device 40, a fare calculation device 70, etc. The fare collection system 100 is communicably connected to a user terminal 20, a manufacturer management system 30, a roadside wireless device 50, a security system 60, a settlement system 90, etc. At least participants such as an in-vehicle device manufacturer HM, a user US, a vehicle manager VM, an information manager IM, a service provider SP, and a settlement business operator PP are involved in the operation of the fare collection system 100.

[0016] The in-vehicle device manufacturer HM is a manufacturing company that manufactures the in-vehicle device 10. The in-vehicle device manufacturer HM operates the manufacturer management system 30. The manufacturer management system 30 issues a unique in-vehicle device number (hereinafter, the first in-vehicle device number, [A] as shown in the figure) to the in-vehicle device 10 manufactured by the in-vehicle device manufacturer HM (see S0 in FIG. 1). The manufacturer management system 30 performs storage, update, security management, etc. of the issued first in-vehicle device numbers. The first in-vehicle device number is identification information of the in-vehicle device 10. The first in-vehicle device number is printed on a seal or the like pasted on the outer surface of the in-vehicle device 10. The user US, the vehicle manager VM, etc. can confirm the first in-vehicle device number with a seal or the like. The first in-vehicle device number can also be confirmed by display on the main body of the in-vehicle device 10 and voice guidance by the in-vehicle device 10.

[0017] The user US is a user who rides in a vehicle and uses the in-vehicle device 10. The vehicle manager VM is a manager who manages such vehicles and the in-vehicle device 10 when the vehicle is for shared use such as a delivery vehicle, a rental car, a taxi, a company-owned vehicle, a public vehicle, and an official vehicle. Specifically, buses, emergency vehicles, vehicles owned by local governments and the state, etc. correspond to public vehicles and official vehicles. When the vehicle is a POV (Personally Owned Vehicle), the vehicle manager VM may not exist. The in-vehicle device 10 and the user terminal 20 are operated by at least one of the user US and the vehicle manager VM.

[0018] The in-vehicle device 10 is installed inside the vehicle cabin. The in-vehicle device 10 is a wireless communication device having a processing unit 11. The in-vehicle device 10 enables automatic toll collection at toll gates such as highways and toll roads, parking lots, and gas stations. The in-vehicle device 10 may be provided with a card slot for inserting a payment card. The payment card may include commonly used prepaid cards and credit cards, etc. When making a payment at a toll gate, the in-vehicle device 10 completes the automatic settlement of the toll by performing mobile wireless communication with the roadside wireless device 50 during the period when the vehicle passes through the toll gate.

[0019] The user terminal 20 is mainly composed of an arithmetic processing circuit including a processing unit 21, and specifically, is a personal computer, a smartphone, a tablet terminal, etc. The user terminal 20 is communicably connected to the network NW and has functions such as sending and receiving emails and browsing the Internet. The network NW is an aggregate of systems and infrastructures for sending and receiving information. The network NW is established by a mechanism that delivers data packets to appropriate destinations via routers, switches, etc. The network NW may generally be a publicly available public network or a private network with restricted access from the outside.

[0020] The user terminal 20 can communicate with the settlement system 90, the number management device 40, and the toll calculation device 70 via the network NW. The user US or the vehicle manager VM uses the user terminal 20 to conclude a settlement contract with the settlement operator PP (see S1 in FIG. 1). In addition, the user US or the vehicle manager VM uses the user terminal 20 to request the number management device 40 of the information manager IM to issue an in-vehicle device number different from the first in-vehicle device number (hereinafter, the second in-vehicle device number, [B] as shown in the figure) (see S2 in FIG. 1). The user terminal 20 applies for the issuance of the second in-vehicle device number using the first in-vehicle device number issued to the in-vehicle device 10.

[0021] The second onboard device number is a confidential number, in contrast to the first onboard device number, which is visible and accessible to anyone. It is managed only by the service provider (SP) and the information manager (IM). The second onboard device number is preferably encrypted to enhance confidentiality and is transmitted and received in an encrypted state. Such encryption is a common method for handling identifier numbers used to identify wireless devices as a countermeasure against tampering, impersonation, and forgery. In the following explanation, the second onboard device number refers to the encrypted version described above. Thus, the second onboard device number is considered more confidential identification information than the first onboard device number. As described later, the second onboard device number is managed by the information manager (IM) in conjunction with the first onboard device number.

[0022] Multiple second on-board device numbers may be issued for each service provider (SP) or for each purpose of use, in addition to the first on-board device number. In this case, it will also be possible to inquire about the first on-board device number by service provider (SP) or by purpose of use. Furthermore, as a measure to enhance confidentiality, one or both of the following methods may be employed: encrypting the numerical value of the number, or encrypting it when it is handled outside the device during communication.

[0023] User US uses user terminal 20 to request service provider SP's billing device 70 to set up a user account. Service provider SP sets up a unique user account for each user US and issues unique user identification information (hereinafter referred to as User ID). The user account and User ID may be the same information (numbers or strings, etc.). If there are multiple service provider SPs, the user account and User ID may be different for each service provider SP.

[0024] User US uses the user terminal 20 to register the first on-board device number of at least one on-board device 10 and at least one payment information to their user account (see Figure 1 S5). As a result, the user ID is linked to the on-board device 10 of the vehicle used by User US, and the payment information related to the payment contract that User US has entered into with the payment service provider PP. User US can register multiple on-board devices 10 (first on-board device numbers) and multiple payment information to a single user account (user ID). User US can register identification information, including vehicle registration certificates, theft reports, My Number cards, and biometric authentication information, as pre-registered information in the fare calculation device 70. Identification information may also be provided to the service provider SP when the user account is created.

[0025] User US uses the user terminal 20 to select the in-vehicle device 10 (first in-vehicle device number) of the vehicle they will be using in their user account (see Figure 1, S6). In other words, multiple user IDs can be registered to a single in-vehicle device 10, and User US, when using the vehicle, sets up the association of their user ID with the in-vehicle device 10 at the time of vehicle use. Furthermore, User US uses the user terminal 20 to select the payment information to be used in the in-vehicle device 10.

[0026] The vehicle manager VM uses the user terminal 20 to request the service provider SP's fare calculation device 70 to set up an administrator account. The administrator account is an account for managing multiple in-vehicle devices 10 and multiple users US. The administrator account is granted user selection authority to set user IDs and payment selection authority to set payment information. The service provider SP sets up an administrator account unique to each vehicle manager VM and issues unique administrator identification information (hereinafter referred to as administrator ID). The administrator ID is linked to multiple first in-vehicle device numbers and multiple user IDs. If there are multiple service provider SPs, the administrator account and administrator ID may also be different for each service provider SP, similar to user accounts and user IDs.

[0027] The vehicle administrator VM uses the user terminal 20 to register at least one in-vehicle device 10 (first in-vehicle device number) to its administrator account (see Figure 1, S5). As described above, the vehicle administrator VM has access rights to all pre-registered user US information (e.g., payment information) associated with one in-vehicle device 10. This allows the vehicle administrator VM to manage all user US through its administrator account. Specifically, the vehicle administrator VM can select user US (user ID) to use the in-vehicle device 10 (see Figure 1, S6), select, deselect, disable, and set usage periods for payment information. In addition, the vehicle administrator VM can switch the availability of user US registered in the in-vehicle device 10, and add and delete pre-registered information.

[0028] Here, for example, a rental car company is both a service provider (SP) and a vehicle manager (VM). In this case, employees of the rental car company may handle this pre-registered information in the fare calculation device 70 without using the user terminal 20. Similarly, corporations, government agencies, local governments, etc. that manage company-owned and official vehicles can also use the fare calculation device 70 to handle the pre-registered information of their employees and staff for the in-vehicle device 10.

[0029] The Information Manager (IM) is a business operator that issues, manages, and retrieves identification information (onboard device number) and related information for the onboard device 10 through the operation of the number management device 40. The number management device 40 is a server device mainly composed of arithmetic processing circuits, including a processing unit 41, RAM 42, and storage unit 43. The number management device 40 may be an on-premise server device physically managed by the Information Manager (IM), or it may be a virtual configuration located on the cloud.

[0030] The number management device 40 issues a confidential second in-vehicle device number to the unique first in-vehicle device number assigned by the in-vehicle device manufacturer HM, based on an issuance request from the user terminal 20 (see Figure 1 S2 and S3). The number management device 40 transmits the second in-vehicle device number to the user terminal 20, which is the source of the issuance request, via the network NW. When a smartphone is used as the user terminal 20, the smartphone is connected to the in-vehicle device 10 by communication means such as Bluetooth®, Wi-Fi, NFC, and USB. The smartphone writes the second in-vehicle device number received from the number management device 40 to the storage medium of the in-vehicle device 10 via communication (see Figure 1 S4).

[0031] In addition, a second in-vehicle device number may be issued to the SIM (Subscriber Identity Module) of a user terminal 20 such as a smartphone, and this smartphone may be constantly connected to the in-vehicle device 10. Such a SIM may contain payment information. Furthermore, the SIM information may only need to be read once by the in-vehicle device 10. Moreover, the SIM card may be permanently installed in the in-vehicle device 10.

[0032] The number management device 40 has an information management database (hereinafter referred to as the information management DB) 45 built into it (see Figure 2). The number management device 40 stores the issued second on-board device number together with the first on-board device number in the information management DB 45. The information management DB 45 may also store information about the vehicle on which the on-board device 10 is installed (for example, vehicle registration information) linked to the on-board device number. The number management device 40 performs updates and security management of the on-board device numbers etc. stored in the information management DB 45.

[0033] A service provider SP is a business that provides various services to vehicle users US through the operation of roadside wireless devices 50, security systems 60, and toll calculation devices 70. Numerous service provider SPs, each providing different services to users US, can utilize the toll collection system 100. For example, toll road operators, parking lot operators, and probe distribution operators can use the toll collection system 100 as service provider SPs.

[0034] The roadside wireless device 50 uses a 5.8GHz band DSRC (Narrowband Relay) system to communicate bidirectionally with the on-board device 10. The roadside wireless device 50 uses optical sensors or the like to detect vehicles entering the DSRC communication area. When a vehicle enters the communication area, the roadside wireless device 50 starts wireless communication with the on-board device 10. The roadside wireless device 50 reads encrypted information (e.g., second on-board device number) from the on-board device 10 (see Figure 1, S7). The roadside wireless device 50 notifies the security system 60 and the toll calculation device 70 of the information read from the on-board device 10 (see Figure 1, S8). The roadside wireless device 50 is connected to a display that notifies the user US of the billing information, a surveillance camera that reads the vehicle's license plate, and an opening / closing gate that allows the vehicle to pass when the billing process is completed successfully.

[0035] The security system 60 is a server device operated by the security center SC. The security center SC is one of the organizations included in the service provider SP and is a specific operator authorized by the information manager IM to implement security management. The security center SC performs encryption processing of various information and ensures the security of vehicle-to-infrastructure communication so that the service provider SP can handle a wide variety of payment methods and services. The security system 60 may be an on-premise server device physically managed by the security center SC, or it may be a virtual configuration located on the cloud. The security system 60 is connected to the roadside wireless device 50 and the toll calculation device 70 via a network NW. The security system 60 works in cooperation with the toll calculation device 70 and the number management device 40 to manage the decryption process of the second on-board device number, thereby enabling the inquiry of the first on-board device number.

[0036] The fare calculation device 70 is a server device mainly composed of an arithmetic processing circuit including a processing unit 71, RAM 72, and a storage unit 73. The processing unit 71 is hardware for arithmetic processing coupled with RAM 72. The storage unit 73 has a configuration that includes a non-volatile storage medium. The storage unit 73 stores various programs (such as service provision programs) executed by the processing unit 71. The service provision program is a program that causes the fare collection system 100, which includes at least the fare calculation device 70, to implement the service provision method according to this disclosure. The fare calculation device 70 may be an on-premise server device physically managed by the service provider SP, or it may be a virtual configuration provided on the cloud.

[0037] The fare calculation device 70 has a carrier database (hereinafter referred to as the carrier DB) 75 built into it (see Figure 2). The fare calculation device 70 uses the carrier DB 75 to issue and manage user IDs and administrator IDs, and to store, update, and secure the first in-vehicle device number and pre-registered information associated with each ID. In addition, the fare calculation device 70 constructs several functional units related to service provision by executing the service provision program stored in the storage unit 13 using the processing unit 71. Specifically, the fare calculation device 70 has at least the following functional units based on the service provision program: an information registration unit 81, a setting selection unit 82, a communication acquisition unit 83, an in-vehicle device inquiry unit 84, and a service implementation unit 85.

[0038] The information registration unit 81 obtains a request for information registration based on an operation of the user terminal 20 by the user US or the vehicle manager VM (see Figure 1, S5). As described above, in the case of a fare calculation device 70 of a rental car company, which is also a service provider SP, the information registration unit 81 may directly receive the request for information registration without going through the user terminal 20. Based on the request for information registration from the user terminal 20 or the request for information registration entered into the fare calculation device 70, the information registration unit 81 registers the first on-board device number in the business DB 75, linked to the user ID or administrator ID. In addition, the information registration unit 81 registers pre-registered information related to the user US, specifically payment information, etc., in the business DB 75, linked to the user ID and the first on-board device number. If the user US has multiple payment contracts with the payment provider PP, the information registration unit 81 registers multiple payment information in the business DB 75, linked to the user ID and the first on-board device number.

[0039] The setting selection unit 82 acquires user setting information and payment setting information based on the operation of the user terminal 20 by the user US or vehicle administrator VM (see Figure 1, S6). The user setting information is information that sets the user ID of the user US who is using the vehicle. The payment setting information is information that sets the payment information to be used for payment processing from among the multiple payment information registered in the business operator DB 75.

[0040] The communication acquisition unit 83 acquires the second on-board device number transmitted to the roadside radio device 50 via mobile radio communication from the on-board device 10 of a vehicle that has entered the communication area (see Figure 1, S8). The second on-board device number is encrypted on-board device information.

[0041] When the in-vehicle device inquiry unit 84 obtains the second in-vehicle device number read from the in-vehicle device 10 by the communication acquisition unit 83, it requests the number management device 40 to inquire about the first in-vehicle device number using this encrypted second in-vehicle device number (see Figure 1, S9). The in-vehicle device inquiry unit 84 decrypts the second in-vehicle device number by querying the number management device 40 in cooperation with the security system 60, and identifies the first in-vehicle device number.

[0042] The service implementation unit 85 reads pre-registered payment information from the business operator DB 75 using the first in-vehicle device number (specific in-vehicle device information) identified by the in-vehicle device inquiry unit 84. The service implementation unit 85 provides services to the user US using the payment information associated with the first in-vehicle device number. The service implementation unit 85 calculates the service usage fee to be billed to the user US of the in-vehicle device 10. The service implementation unit 85 performs the payment processing for the service usage fee using the payment information set based on the payment setting information. Specifically, the service implementation unit 85 provides the payment information to the payment system 90, which is communicated with the fee calculation device 70 via the network NW, and requests payment processing for the calculated service usage fee (see Figure 1 S10).

[0043] Furthermore, the content of the services provided by the service implementation unit 85 may be changed as appropriate depending on the business content of the service provider SP. In addition to payment services, the distribution of probe information may be provided as a service. Specifically, if the service provider SP is a probe distribution provider, the service implementation unit 85 distributes the driving history data (vehicle probe information) collected from the in-vehicle device 10 (in-vehicle device 10) to the user US or vehicle manager VM via the roadside wireless device 50. Alternatively, the driving history recorded on the user terminal 20 is transmitted to the roadside wireless device 50 via the in-vehicle device 10.

[0044] The payment service provider PP is a business that provides payment methods to the user US by issuing credit cards, etc. The payment service provider PP collects charges based on the user US's payment information through the operation of the payment system 90. The payment system 90 is a server device that manages the payment contract with the user US. Based on the payment processing request received from the charge calculation device 70, the payment system 90 performs billing processing to the user US using the payment information associated with the first in-vehicle device number. Based on the billing processing, the payment system 90 bills the user US for payment of the usage fees for the services used by the user US (see Figure 1 S11).

[0045] <Processing performed by the toll collection system> Next, the details of the processing performed by the toll collection system 100 will be further explained. The toll collection system 100 performs pre-registration processing, information setting processing, entrance gate processing, exit gate processing, and batch release processing. These processes are made possible by the cooperation of multiple participant systems and equipment, based on the service provision programs executed in each processing unit 11, 21, 41, and 71. The details of these processes will be explained below with reference to Figures 3 to 7, and with reference to Figures 1 and 2. Note that "S" is a code indicating a step. In each sequence diagram, the transmission and reception of encrypted data is indicated in parentheses.

[0046] [Pre-registration process] The pre-registration process shown in Figure 3 is a process for concluding contracts between participants who will use the toll collection system 100. In S11 of the pre-registration process, a contract regarding the inquiry of the in-vehicle device number is concluded between the security center SC and the information manager IM (Contract C). In S12, a contract regarding participation in the automatic payment service for tolls, etc. is concluded between the service provider SP and the security center SC (Contract B). Based on these contracts, the toll calculation device 70 can cooperate with the security system 60 to inquire about the first in-vehicle device number from the number management device 40.

[0047] In S13, a contract is concluded between the service provider SP and the payment provider PP regarding participation in the payment service (Contract A). Based on this contract, the fee calculation device 70 periodically obtains a negative list from the payment system 90. The negative list contains information on users US that have been deemed problematic due to fraudulent use, payment delays, etc. Based on the negative list, which is periodically updated by the processing in S14, the fee calculation device 70 restricts (prohibits) the use of the service by users US or payment information listed on the negative list.

[0048] In S15, a settlement agreement is concluded between the settlement provider PP and the user US (see also Contract D, Figure 1 S1). In S16, the user US (or vehicle manager VM) submits a setup request for the in-vehicle device 10 to the information manager IM (see also Contract E, Figure 1 S2). In S16, the first in-vehicle device number and vehicle registration information are transmitted from the user terminal 20 to the number management device 40. In S17, the setup of the in-vehicle device 10 is completed when the second in-vehicle device number is written to the in-vehicle device 10 using the user terminal 20 (see also Figure 1 S3, S4).

[0049] In S18, a contract for the use of an automatic payment service for tolls, etc., is concluded between the user US or vehicle manager VM and the service provider SP (contract F, see also Figure 1 S5). In S18, pre-registered information such as the first on-board device number, payment information, and identification information provided from the user terminal 20 to the fare calculation device 70 is registered in the service provider DB 75. The pre-registered information is registered in the service provider DB 75, linked to the first on-board device number. In S19, the fare calculation device 70 checks with the payment system 90 whether the newly registered payment information is valid. In S20, the fare calculation device 70 obtains the result of the payment information validity check from the payment system 90. In S21, the fare calculation device 70 notifies the user terminal 20 of the validity check result. If the payment information is valid, in S22, the user US can use the service.

[0050] [Information setting process] The information setting process shown in Figure 4 is a process in which payment information to be linked to the in-vehicle device 10 is set between the user US (or vehicle manager VM) and the service provider SP (see also Figure 1 S6). In S31 of the information setting process, the user US who will be using the vehicle is set. Specifically, in S31, the user US uses the user terminal 20 to log in to the fare calculation device 70 with their own user account. Alternatively, the vehicle manager VM uses the user terminal 20 to log in to the fare calculation device 70 with their own administrator account and sets the user US who will be using the vehicle. As a result, the fare calculation device 70 obtains user setting information from the user terminal 20 and sets the user ID of the user US who is using (or will be using) the vehicle.

[0051] In S32, the fare calculation device 70 requests the user terminal 20 to select an in-vehicle device 10. In S32, as an example, a list of multiple in-vehicle devices 10 associated with a user ID or administrator ID is presented to the user US or vehicle administrator VM. In S33, the user US or vehicle administrator VM selects (sets) the in-vehicle device 10 for the vehicle used by the user US from among the multiple in-vehicle devices 10 presented.

[0052] In S34, the fare calculation device 70 requests the user terminal 20 to select payment information. In S34, as an example, a list of multiple payment information associated with the in-vehicle device 10 is presented to the user US or vehicle administrator VM. In S35, the user US or vehicle administrator VM selects (sets) the payment information to be used from the presented list of payment information. The fare calculation device 70 sends a notification to the user terminal 20 indicating that the settings for the user US, the in-vehicle device 10, and the payment information are complete. If the vehicle is a connected car that can connect to a network NW, the information setting process may be performed between the vehicle HMI (Human Machine Interface) and the fare calculation device 70.

[0053] [Entrance gate processing] The entrance gate processing shown in Figure 5 is a transaction process that occurs when a vehicle enters an entrance gate on a highway or similar road. To ensure the proper execution of the entrance gate processing, the negative list is periodically updated between the settlement system 90 and the toll calculation device 70 (S40).

[0054] In S41, during the entrance gate processing, mutual vehicle-to-roadside authentication is performed between the roadside wireless device 50 and the on-board device 10. Once mutual authentication is complete, in S42, the second on-board device number is transmitted from the on-board device 10 to the roadside wireless device 50 (see also Figure 1, S7). Encrypted data is transmitted and received during the vehicle-to-roadside communication in S41 and S42. Security processing is also performed between the roadside wireless device 50 and the security system 60 in S41 and S42. Once the second on-board device number is successfully read from the on-board device 10, in S43, the second on-board device number is notified to the toll calculation device 70 in an encrypted state (see also Figure 1, S8).

[0055] In S44, the fare calculation device 70 (onboard device inquiry unit 84) requests the number management device 40 to inquire about the first onboard device number using the second onboard device number (see also Figure 1, S9). In S45 and S46, the fare calculation device 70 obtains the inquiry result for the first onboard device number via the security system 60. The fare calculation device 70 obtains either the first onboard device number associated with the second onboard device number, or a notification indicating "not applicable," as the inquiry result. The number management device 40 notifies the inquiry result of "not applicable" if the second onboard device number does not match, is not registered, or has been deactivated.

[0056] In S47, the fare calculation device 70 (service implementation unit 85) retrieves payment information linked to the first onboard device number by searching the operator DB 75. In S48, the fare calculation device 70 performs a negative list check to confirm whether the payment information extracted by the search is listed in the negative list. If the payment information is not in the negative list, in S49, the fare calculation device 70 registers the entry information linked to the second onboard device number. If the payment information is not in the negative list, an error notification may be sent to the user US.

[0057] In S50, the toll calculation device 70 transmits a notification to the roadside radio device 50 indicating that payment is possible and a notification instructing the opening of the entrance gate. As a result, the entrance gate is opened and vehicles are permitted to pass. In S51, as a vehicle passes through the entrance gate, the roadside radio device 50 writes the entrance information to the on-board device 10. Note that writing the entrance information to the on-board device 10 may be omitted.

[0058] [Exit gate processing] The exit gate processing shown in Figure 6 is a transaction process that takes place when a vehicle enters an exit gate on a highway or similar road. To ensure the proper execution of the exit gate processing, the negative list is periodically updated between the settlement system 90 and the toll calculation device 70, similar to the entrance gate processing (S60). Then, based on the pre-registration process and information setting process, the road tolling service is made available in S61.

[0059] In steps S62-S64 of the exit gate processing, the same processing as in steps S41-S43 of the entrance gate processing is performed. Specifically, in steps S62 and S63, mutual vehicle-to-roadside authentication and reading of the second on-board device number are performed between the roadside wireless device 50 and the on-board device 10 (see also Figure 1 S7). Then, in step S64, the second on-board device number read from the on-board device 10 is notified to the toll calculation device 70 (see also Figure 1 S8). In addition, in step S64, an inquiry about the service usage fee is made to the toll calculation device 70.

[0060] In S65, the toll calculation device 70 queries the entrance information registered during the entrance gate processing (see Figure 5, S49) and calculates the service usage fee (e.g., highway usage fee, parking fee, etc.). In S66, the toll calculation device 70 notifies the in-vehicle device 10 of the service usage fee via the roadside wireless device 50. In S67, the service usage fee is presented to the vehicle user US. The service usage fee is displayed on a display on the in-vehicle device 10, a display that constitutes the vehicle HMI, a display on a smartphone connected to the in-vehicle system, etc.

[0061] In S68, the fare calculation device 70 (onboard device inquiry unit 84) requests the number management device 40 to inquire about the first onboard device number using the second onboard device number (see also Figure 1, S9). In S69 and S70, the fare calculation device 70 obtains the inquiry result for the first onboard device number via the security system 60. In the exit gate processing, as in the entrance gate processing, the fare calculation device 70 obtains the first onboard device number associated with the second onboard device number, or a notification indicating "not applicable," as the inquiry result.

[0062] The toll calculation device 70 (service implementation unit 85) performs a fraudulent use check and a negative list check in S71 and determines whether the payment information linked to the first on-board device number obtained through the inquiry can be used. If the payment information can be used, the toll calculation device 70 sends a notification indicating that payment is possible and a notification instructing the exit gate to be opened to the roadside wireless device 50 in S72. As a result, the exit gate is opened and the vehicle is allowed to pass. Upon the vehicle passing through the exit gate, the entrance information written to the on-board device 10 is deleted in S73.

[0063] In S74, the fare calculation device 70 (service implementation unit 85) provides payment information to the payment system 90 and requests the execution of billing processing (see also Figure 1 S10). In S75, the fare calculation device 70 performs payment processing for service usage fees using the payment information. In S74 and S75, service provision is carried out using pre-registered information linked to both the first on-board device number, which is queried using the second on-board device number, and the user ID indicated by the user setting information. In S76, the fare calculation device 70 notifies the user US (or vehicle manager VM) of the usage fee history (see also Figure 1 S11). This allows the user US, etc., to check the usage fee via email or payment application, etc. (S77).

[0064] [Batch Cancellation Process] The batch deactivation process shown in Figure 7 is a process that deletes the registration of the second on-board device number and deactivates the usage registration of multiple service providers SP in a batch by submitting a deletion request to the information administrator IM. In S81 of the batch deactivation process, the user US or vehicle administrator VM uses the user terminal 20 to submit a deletion request (invalidation request) for the second on-board device number to the information administrator IM. Based on the deletion request to the information administrator IM, the number management device 40 deletes (invalidates) the second on-board device number specified in the deletion request from among the multiple second on-board device numbers registered in the information management DB 45.

[0065] In S82, the number management device 40, in cooperation with the user terminal 20, erases the second on-board device number written to the storage unit of the on-board device 10. By erasing the second on-board device number, the on-board device 10 is deactivated (Case 1). Once the deactivation of the on-board device 10 is complete, in S83, the user terminal 20 notifies the number management device 40 that the deactivation of the on-board device 10 is complete.

[0066] The number management device 40 may update the shared list of second onboard device numbers in S84 based on the acquisition of the invalidation completion notification. By updating the shared list, the number management device 40 notifies multiple service providers SP that a specific second onboard device number has been invalidated.

[0067] If user US uses a billing service after the second on-board device number of the on-board device 10 has been erased (S85), it becomes impossible to read the second on-board device number from the on-board device 10 (S85, Case 1). As a result, user US is unable to use services provided by multiple service providers SP that are related to the second on-board device number.

[0068] On the other hand, if the second on-board device number of the on-board device 10 has not been erased (Case 2), the fare calculation device 70, in S86 and S88, works in cooperation with the security system 60 to read the second on-board device number from the on-board device 10. In S89, the fare calculation device 70 works in cooperation with the security system 60 to query the number management device 40 for the first on-board device number using the second on-board device number. Since the second on-board device number has been erased from the information management DB 45 of the number management device 40, the fare calculation device 70 obtains a notification indicating "not applicable" as the query result in S90. As a result, service provision by multiple service providers SP that is related to the invalidated second on-board device number is restricted collectively.

[0069] If the fare calculation device 70 obtains a query result indicating that there is no first on-board device number corresponding to the second on-board device number, it sends an error notification to the on-board device 10 in S91. The error notification is a notification to the user US using the vehicle informing them that service cannot be provided. In addition to communication from the roadside radio device 50 to the on-board device 10, the error notification indicating the inability to provide service may also be made by means of a display board installed at gates and shops, for example. The error notification may also prompt the user US to contact the service provider SP and the information manager IM.

[0070] In S92, the fee calculation device 70 requests payment of service usage fees from user US, based on contract F between user US and service provider SP (see Figure 3, S18), using the identity verification information registered in the fee calculation device 70 as pre-registered information. As described above, identity verification information related to user US is registered in the service provider DB 75 as pre-registered information. Therefore, if there is no valid payment information due to non-registration of payment information, expiration of payment information, etc., and payment processing using payment information is not possible, the fee calculation device 70 performs deferred payment processing using the personal information of user US registered as pre-registered information, as in S92.

[0071] <Processes that can be implemented in the toll collection system> Next, we will explain in detail the various processes that can be implemented in the toll collection system 100, referring to Figures 1 and 2.

[0072] [Restrictions on service provision due to information sharing with public institutions] The information manager (IM) can share information with public institutions such as police agencies, transport bureaus, and light vehicle inspection associations. Specifically, the number management device 40 receives public information such as theft reports from the police agency's system. The number management device 40 also receives public information such as vehicle registration certificates for which ownership has been changed from the transport bureau's or light vehicle inspection association's system. As a result, when an application for vehicle deregistration or change of ownership is submitted to a transport bureau, etc., this public information related to the vehicle registration certificate is provided to the number management device 40.

[0073] The number management device 40 invalidates the second onboard device number specified in the theft report from among the multiple second onboard device numbers registered in the information management DB 45, based on the provision of a theft report from a police agency. Similarly, the number management device 40 invalidates (deletes) the second onboard device number associated with the vehicle whose ownership has been changed, from among the multiple second onboard device numbers registered in the information management DB 45, based on the provision of information regarding a change of ownership from a transport branch office or a light vehicle inspection association.

[0074] As a result of the above, the second on-board device number in the information management DB 45 is invalidated, and the fare calculation device 70 obtains a query result indicating "not applicable" when querying the number management device 40. Consequently, service provision by multiple service providers SPs that are related to the invalidated second on-board device number are collectively restricted.

[0075] Here, the information administrator IM may share theft report information and ownership change information with the service provider SP requesting the in-vehicle device number inquiry. By sharing public information, the contract information, user ID, and payment information registered in the service provider DB75 may be deleted (invalidated) collectively. Alternatively, the theft report and ownership change application may be submitted to the information administrator IM. In this case as well, the number management device 40 will invalidate the second in-vehicle device number registered in the information management DB45 based on the application.

[0076] [Vehicle tracking after filing a theft report] The service provider SP tracks the stolen vehicle and onboard device 10 based on a theft report from the user US or vehicle manager VM. The service provider SP can track the vehicle by collecting the second onboard device number and driving history data of the onboard device 10 as it passes the roadside radio device 50. As mentioned above, the driving history may also be transmitted to the roadside radio device 50 via the onboard device 10.

[0077] More specifically, based on the theft report, the information registration unit 81 registers the theft information (theft report) indicating the vehicle's theft as pre-registered information in the operator database 75, linked to the user ID and the first on-board device number. The on-board device inquiry unit 84 decodes the second on-board device number read from the on-board device 10, and if the theft information is linked to the inquired first on-board device number, it stores the tracking records of the vehicle and the on-board device 10. The service implementation unit 85 provides the tracking records of the vehicle and the on-board device 10 to the user US and police agencies, etc.

[0078] [Automatically disable payment information] The fare calculation device 70 cancels (invalidates) the payment information used for payment processing and prohibits payment processing based on the payment information, based on the fulfillment of pre-set cancellation conditions. The cancellation conditions include when the user US stops the vehicle's engine, when the usage period, number of uses, and amount used are exceeded after the payment information has been set, and when the user US cancels the selection of payment information. With these cancellation conditions, even when an unspecified number of users US use one in-vehicle device 10, it becomes less likely that the payment information of a previous user US will be mistakenly used.

[0079] [Applicable to car rental and taxi services] User US can use rental car and taxi services using payment information. For example, User US uses user terminal 20 to pre-register payment information on the rental car company's member website. User US selects payment information according to the store and vehicle reservation. This allows User US to use rental car services while avoiding cumbersome procedures. Furthermore, even if User US does not set up payment information, the rental car store may set and delete the payment information pre-provided by User US in the service provider SP's system or as the vehicle manager VM, according to the rental period.

[0080] Furthermore, when User US boards a taxi, they use their smartphone to read the first on-board device number of the on-board device 10 installed in the taxi using a 2D code and NFC, etc. By linking reservation information and user ID etc. with the first on-board device number, User US can use payment information to pay for the taxi fare.

[0081] [Setting conditional payment information] The fare calculation device 70 has a function to activate payment information with conditions on the number of times and duration. Specifically, the information registration unit 81 registers restricted payment information in the business operator DB 75, which is linked to the first in-vehicle device number and user ID and has limits set on the number of times or duration for which payment processing can be performed. When using the payment service, the service implementation unit 85 permits payment processing using the restricted payment information if the number of times or duration limits are not exceeded. On the other hand, the service implementation unit 85 prohibits payment processing using the restricted payment information if the number of times or duration limits are exceeded.

[0082] For example, when a user US uses a taxi as a passenger, they register restricted payment information, limited to one-time use, in the taxi's onboard device 10. This allows the user US to smoothly settle the fare related to the taxi ride. After the taxi fare payment is completed, the restricted payment information is deleted. More specifically, through the linkage between the taxi meter and the onboard device 10, or through a wide-area wireless connection with the service provider SP's fare calculation device 70, a message is transmitted when the taxi meter is set to settlement upon the user US alights, and the restricted payment information is deleted. Therefore, even if a specific user US's payment information is linked to the onboard device 10 of a taxi used by an unspecified number of people, it becomes unlikely that this payment information will be used by another user US.

[0083] [Switching between payment processing when a payment card is inserted and when it is not] The fare calculation device 70 switches the payment information used for payment processing depending on whether a payment card is inserted into the card slot of the on-board device 10 or not. More specifically, if the on-board device 10 holds the card information (card-side payment information) of the payment card inserted into the on-board device 10, the on-board device 10 associates the card-side payment information with the second on-board device number and transmits it to the roadside radio device 50. The communication acquisition unit 83 acquires the card-side payment information transmitted in association with the second on-board device number. On the other hand, if no payment card is inserted into the card slot, the transmission of card-side payment information from the on-board device 10 to the roadside radio device 50 is not performed.

[0084] If the communication acquisition unit 83 has acquired card-side payment information, the service implementation unit 85 uses this card-side payment information to provide the service (process the payment). On the other hand, if the communication acquisition unit 83 has not acquired card-side payment information, the service implementation unit 85 uses payment information (registered payment information) that has been pre-registered in the business database 75 to process the payment.

[0085] [Reducing service processing time] The process of decrypting the second onboard device number may be performed within a system operated by the security center SC or the service provider SP. The security system 60 or the fare calculation device 70 has a query database that can identify the first onboard device number from the second onboard device number, but only for the first onboard device number for which a registration application has been submitted to the service provider SP. With this configuration, the time loss associated with querying the first onboard device number from the fare calculation device 70 to the number management device 40 can be reduced. As a result, it becomes possible to provide services quickly even to vehicles traveling at high speeds.

[0086] [Automatic activation of payment information through identity verification] The fare calculation device 70 can identify the user US using the vehicle and automatically set the payment information for this user US. More specifically, the driver authentication system installed in the vehicle performs facial recognition of the user US using an in-vehicle camera when the user US is in the vehicle. The driver authentication system may also perform fingerprint authentication using the engine start button, or it may perform personal authentication of the driver using a smartphone brought into the vehicle.

[0087] The fare calculation device 70 is connected to the vehicle via a network NW for communication. The setting selection unit 82 obtains the user ID of user US, whose identity has been verified by the driver authentication system, along with the first on-board device number. The setting selection unit 82 searches the business operator DB 75 for payment information associated with the obtained user ID and first on-board device number, and automatically activates the retrieved payment information. As a result, user US does not need to input a user ID and payment information selection operation each time they use the vehicle.

[0088] [Automatic switching of payment information] When a user (US) registers multiple payment information in the business database (DB75), they can set a priority order for this payment information. The setting selection unit (82) refers to the priority order of the payment information registered in the service implementation unit (85), and if the payment information selected by the user (US) is invalid, it automatically switches to the payment information with the highest priority among the unselected payment information. As a result, even if payment information becomes invalid due to reasons such as expiration, filing of a loss report, or cancellation, the system automatically switches to the second or third registered payment information, allowing for smooth payment processing.

[0089] [Warning notification to users when payment information is not registered or set] The fare calculation device 70 notifies the user US that the service cannot be provided if payment information linked to the in-vehicle device 10 is not registered, or if payment information corresponding to the user US is not selected. If payment information is not registered or payment information is not selected, the fare calculation device 70 sends a warning notification to the user terminal 20 (smartphone, etc.) via the network NW. The fare calculation device 70 may also send a warning notification (error notification) to the vehicle via the network NW and warn the user US through the vehicle HMI that payment information is not registered or not selected. Furthermore, in the second embodiment described later (see Figure 8), in the configuration in which payment information is registered in the in-vehicle device 10, the in-vehicle device 10 alone may issue a warning notification for unregistered payment information.

[0090] Furthermore, to prevent the failure to register or select payment information, the fare calculation device 70 (information registration unit 81) sets the user US or vehicle administrator VM, who is the owner of the in-vehicle device 10, as the default payer. In addition, the fare calculation device 70 forces the user US or vehicle administrator VM to register one payment information associated with the user ID or administrator ID as the default payment information. If the fare calculation device 70 (service implementation unit 85) has not acquired payment setting information and no payment information has been selected, it provides the service using the default payment information. Note that the default payer and payment information settings can be invalidated (removed) by reporting theft or applying for a change of ownership to the fare calculation device 70 or the number management device 40.

[0091] [Suspension of service provision by each service provider] If a user US requests contract termination from a service provider SP, only the services provided by that service provider SP will be suspended. In this case, the services provided by other service providers SP will not be suspended. Thus, unlike when a user US requests deletion from the number management device 40, individual service provision can be suspended.

[0092] [Use of My Number Card and Driver's License] The fare calculation device 70 (information registration unit 81) can register information from the My Number Card and driver's license as pre-registered information in the operator database 75, associated with the first in-vehicle device number. The information from the My Number Card and driver's license includes, for example, information related to the disability of user US. The service implementation unit 85 refers to the operator database 75 and, if information related to disability is associated with the pre-registered information of user US, makes services such as disability discounts and unlocking gates for priority parking for people with disabilities available.

[0093] [How to erase the setup of an in-vehicle device] The on-board device 10 automatically erases the second on-board device number (setup information) when it is presumed that the vehicle has been sold. For example, the on-board device 10 erases the second on-board device number from its memory when the electrical connection to the vehicle's constant power supply (+B) is disconnected. Furthermore, the on-board device 10 may also have an erasure function that is activated by a specific operation (for example, pressing multiple buttons simultaneously).

[0094] However, it is desirable that the second on-board device number of the stolen on-board device 10 not be erased. Therefore, the erasure of the second on-board device number mentioned above is intended to suspend the use of the service. In this case, the second on-board device number and driving history will continue to be transmitted to the roadside radio device 50, making it possible to track the stolen item and the stolen vehicle. Furthermore, complete erasure of the second on-board device number requires procedures with the information administrator IM.

[0095] [How to check registration information on the in-vehicle device itself] In the information registered in the operator DB75, information regarding the user ID and payment information linked to the in-vehicle device 10 (first in-vehicle device number) may be made verifiable using the in-vehicle device 10 itself, for example, by the voice function of the in-vehicle device 10.

[0096] As another example, the in-vehicle device 10 is connected to a user terminal 20 such as a smartphone via Bluetooth or the like. The user US connects their smartphone to the fare calculation device 70 via the network NW and accesses their member page, etc. When the user US performs device authentication on the in-vehicle device 10, information regarding the user ID and payment information is transferred from the operator DB 75 to the in-vehicle device 10 via the smartphone.

[0097] The in-vehicle device 10 can determine how many users US (user IDs) are registered with the device 10, and which user US's information corresponds to the currently set payment information, by obtaining a copy of the information registered on the cloud. Based on a predetermined operation by the user US, the in-vehicle device 10 notifies the user US of the number of users US registered with the device 10 and the current payment user through spoken communication. Such notification functions can be useful, for example, in in-vehicle devices 10 installed in rental cars, to understand the current settings of the device 10. It is desirable that the copied information be updated periodically to prevent discrepancies between the copied information transferred to the in-vehicle device 10 and the original information on the cloud stored in the operator DB 75.

[0098] [How to check registration information using a user terminal] User US can access the fare calculation device 70 from user terminal 20 and, by using their account (member page), view the in-vehicle device 10 and payment information associated with their user ID. Based on a viewing request from user terminal 20 associated with user US, the fare calculation device 70 extracts the first in-vehicle device number and pre-registration information associated with user US's user ID from the operator database 75. Using the extracted information, the fare calculation device 70 provides the requesting user terminal 20 with information indicating the in-vehicle device 10 registered in user US's account, as well as payment information, etc. User US may also be able to view, through the member page, not only the registration status of the in-vehicle device 10 and payment information, but also the vehicle's license plate number, the expiration date of the payment information, and the usage history of the in-vehicle device 10.

[0099] User US can check whether their payment information is currently set on at least one in-vehicle device 10 associated with their user ID by viewing the member page. User US can change (deactivate) their payment information set for each in-vehicle device 10 (first in-vehicle device number) by operating the user terminal 20.

[0100] However, if payment information can be freely changed, there is a risk of fraudulent use. In particular, when multiple user IDs are associated with a single in-vehicle device 10, payment information cannot be viewed by these users US. Therefore, the payment information that users US can access is reliably distinguished for each user account (user ID). Furthermore, changing payment information requires approval from both the owner of the in-vehicle device 10 (user US or vehicle manager VM) and the user US (payer) associated with the changed payment information. In particular, in the case of in-vehicle devices 10 used in rental cars, it is desirable that changes to payment information by individual users US be restricted.

[0101] On the other hand, rental car companies may be issued administrator (supervisor) accounts with special privileges. By using the administrator account, employees of the rental car company can forcibly cancel (change) the payment information of users who have canceled their reservations. Furthermore, supervisor accounts may also be issued to corporations, government agencies, and local authorities that manage company-owned and official vehicles.

[0102] (Summary of the first embodiment) In the first embodiment described above, when the second on-board device number transmitted from the on-board device 10 to the roadside wireless device 50 via mobile wireless communication is obtained, an inquiry is made to the first on-board device number using the second on-board device number. Based on the information related to this inquiry to the first on-board device number and the user setting information, it is possible to ascertain the user US currently using the vehicle equipped with the on-board device 10 that transmitted the second on-board device number, and consequently, the pre-registration information related to this user US. As a result, even if multiple users US use one vehicle, it becomes possible to provide appropriate services to the user US currently using the vehicle using their pre-registration information.

[0103] Furthermore, if the vehicle or in-vehicle device 10 is sold and the user forgets to cancel the service, the problem of service provision and billing continuing for the previous owner (user US) can be resolved. In addition, it becomes possible to terminate service in a one-stop manner for contracts with multiple service providers SP.

[0104] In addition, in the first embodiment, multiple payment information entries are registered as pre-registered information linked to the first in-vehicle device number and user ID. Then, payment setting information is obtained to set which payment information to be used for payment processing from among the multiple payment information entries, and payment processing is carried out using the payment information based on the payment setting information. As a result, user US can appropriately select payment information according to the vehicle being used. In addition, if one payment information entry becomes invalid, user US can continue to use the service by switching to another payment information entry.

[0105] In the first embodiment, pre-registration information is registered in the service provider DB75 linked to the service provider SP, linked to the first on-board device number. Then, the service is provided using the pre-registration information linked to both the first on-board device number, which is queried using the second on-board device number, and the user ID indicated in the user setting information. As a result, even when multiple users US use one vehicle, it becomes possible to select different payment information for each user US and use it for service provision.

[0106] Furthermore, in the first embodiment, based on a deletion request (invalidation request) to the information administrator IM, the second in-vehicle device number specified in the deletion request is invalidated from among the multiple second in-vehicle device numbers registered in the information management DB45 linked to the information administrator IM. In this case, the service provision provided by multiple service providers SPs that is related to the invalidated second in-vehicle device number is restricted collectively. As a result, even if an in-vehicle device number is registered with multiple service providers SPs, it becomes possible to cancel the services provided by these service providers SPs all at once.

[0107] In addition, in the first embodiment, based on the provision of public information by a public institution to the information administrator IM, the second in-vehicle device number specified in the public information is invalidated among the multiple second in-vehicle device numbers registered in the information management DB45. As a result, the service provision by multiple service providers SP that is related to the invalidated second in-vehicle device number is collectively restricted. As a result, by filing a report with a public institution, such as a theft report or a change of ownership on the vehicle registration certificate, services from multiple service providers SP can be canceled all at once. As a result, the convenience for the user US is further improved.

[0108] In the first embodiment, theft information indicating the theft of a vehicle equipped with the on-board device 10 is registered as pre-registered information. If the theft information is linked to the second on-board device number obtained by mobile wireless communication, the vehicle tracking record is stored. Even if the on-board device number registered in the information management DB 45 is deleted and the use of payment services, etc., is stopped, the second on-board device number and the driving history etc. accumulated in the on-board device 10 are still uplinked from the on-board device 10 to the roadside wireless device 50. Therefore, by tracking the vehicle using the second on-board device number, the rapid recovery and investigation of stolen vehicles becomes possible.

[0109] Furthermore, in the first embodiment, an administrator account is set up for managing the in-vehicle device 10. This administrator account is granted user selection authority to set user IDs and payment selection authority to set payment information. The vehicle administrator VM can flexibly manage the vehicle's user US and payment information by using the administrator account. As a result, convenience for administrators who own multiple vehicles may be improved.

[0110] In addition, in the first embodiment, the payment information used for payment processing is deactivated based on the fulfillment of a pre-set deactivation condition, and payment processing based on that payment information is prohibited. Setting such deactivation conditions makes it possible to reduce the effort required of the user US to deactivate the payment information. As a result, even when an unspecified number of users US use a single in-vehicle device 10, it becomes less likely that the payment information of a previous user US will be mistakenly used.

[0111] In the first embodiment, restricted payment information, which is linked to the first in-vehicle device number and user ID and has limits set on the number of times or the period during which it can be used for payment processing, is registered as pre-registered information. If the limit is not exceeded, payment processing using the restricted payment information is permitted, while if the limit is exceeded, payment processing using the restricted payment information is prohibited. By using such restricted payment information, it becomes possible to securely use the payment information of users US even in services used by an unspecified number of users US, such as payment of taxi fares.

[0112] Furthermore, in the first embodiment, at least one payment information and identity verification information related to user US are registered as pre-registered information, linked to the first in-vehicle device number and user ID. If payment processing using the payment information linked to the first in-vehicle device number cannot be performed, a payment request using the identity verification information is made to user US. As a result, even if the payment information becomes invalid and payment processing using the payment information becomes impossible, an alternative payment method is secured, so that service provision to user US can continue. Consequently, the convenience of user US can be ensured.

[0113] In addition, in the first embodiment, if the in-vehicle device inquiry unit 84 obtains an inquiry result indicating that there is no first in-vehicle device number corresponding to the second in-vehicle device number, the user US using the vehicle is notified that the service cannot be provided. With such an error notification, the user US can quickly understand that valid payment information has not been set up. As a result, confusion during the process of using the service can be suppressed, and the convenience for the user US can be further improved.

[0114] In the first embodiment, if the in-vehicle device 10 holds the card-side payment information read from the inserted payment card, the communication acquisition unit 83 acquires the card-side payment information transmitted in association with the second in-vehicle device number via mobile wireless communication. If the communication acquisition unit 83 has not acquired the card-side payment information, the service implementation unit 85 provides the service using pre-registered information (registered payment information). On the other hand, if the communication acquisition unit 83 has acquired the card-side payment information, the service implementation unit 85 provides the service using the card-side payment information. As a result, the user US can automatically use the normal automatic payment service simply by inserting a payment card into the in-vehicle device 10. On the other hand, if a payment card is not inserted into the in-vehicle device 10, the pre-set payment method (registered payment information) is automatically applied. Therefore, payment errors and payment delays are prevented. As a result, flexible payment support in various scenarios is possible, further improving the convenience of the user US.

[0115] Furthermore, in the first embodiment, based on a viewing request from the user terminal 20 associated with user US, the fare calculation device 70 provides the user terminal 20 with at least one of the first in-vehicle device number associated with the user ID and pre-registered information. Therefore, user US can use the user terminal 20 to check the number of in-vehicle devices 10 registered in their user account, the status of payment information settings, etc.

[0116] In the first embodiment described above, the setting selection unit 82 corresponds to the "user selection unit," and the fare calculation device 70 corresponds to the "service provision system." In addition, the first in-vehicle device number corresponds to the "first in-vehicle device information" and "specific in-vehicle device information," the second in-vehicle device number corresponds to the "second in-vehicle device information," and the user ID corresponds to the "user identification information."

[0117] (Second embodiment) The second embodiment of the present disclosure shown in Figure 8 is a modification of the first embodiment. In the second embodiment, the user US sets their user ID and pre-registered information in the in-vehicle device 10 by operating the user terminal 20 or the vehicle HMI. The in-vehicle device 10 includes an information registration unit 81 and a setting selection unit 82, which are provided by the execution of a service provision program by the processing unit 11.

[0118] The information registration unit 81 registers pre-registered information such as payment information to the in-vehicle device 10, linked to the second in-vehicle device number and user ID, based on the operation by the user US (S5). The setting selection unit 82 selects and sets the user ID and payment information linked to the user US using the vehicle, based on the operation by the user US (S6, see also Figure 2 S32 and S35). The in-vehicle device 10 transmits the second in-vehicle device number, linked to the payment information, to the roadside wireless device 50 (see Figure 1) via mobile wireless communication.

[0119] The fare calculation device 70 is configured with a communication acquisition unit 83, an in-vehicle device inquiry unit 84, and a service implementation unit 85, similar to the first embodiment. On the other hand, the configurations corresponding to the information registration unit 81 and the setting selection unit 82 are omitted in the fare calculation device 70. The communication acquisition unit 83 acquires the second in-vehicle device number, as well as pre-registered information transmitted in association with the second in-vehicle device number (S7 and S8). The in-vehicle device inquiry unit 84 queries the number management device 40 for the first in-vehicle device number using the second in-vehicle device number (S9). Once the inquiry for the first in-vehicle device number by the in-vehicle device inquiry unit 84 is complete, the service implementation unit 85 uses the settlement information received from the in-vehicle device 10 to perform settlement processing for the service usage fee.

[0120] In the second embodiment described above, the same effects as in the first embodiment are achieved, and the fare calculation device 70 can obtain pre-registration information related to the user US currently using the vehicle equipped with the in-vehicle device 10. As a result, even if multiple users US use the same vehicle, it becomes possible to provide appropriate services to the user US currently using the vehicle using their pre-registration information.

[0121] In addition, in the second embodiment, pre-registration information is registered in the on-board device 10 in association with the second on-board device number. The pre-registration information transmitted from the on-board device 10 in association with the second on-board device number via mobile wireless communication is acquired by the fare calculation device 70, and the service is provided using the pre-registration information acquired by reception from the on-board device 10. As described above, even in the form in which pre-registration information is registered in the on-board device 10, by providing the pre-registration information to the fare calculation device 70 in association with the second on-board device number, it becomes possible to provide appropriate services to the user US currently using the vehicle. In the second embodiment, the fare collection system 100 corresponds to the "service provision system".

[0122] (Third embodiment) The third embodiment of this disclosure shown in Figure 9 is another modification of the first embodiment. In the third embodiment, user US requests the number management device 40 to set up a user account by operating the user terminal 20. The number management device 40 sets up a user account unique to each user US and issues a unique user ID. The number management device 40 includes an information registration unit 81 and a setting selection unit 82, which are provided by the execution of a service provision program by the processing unit 41.

[0123] The information registration unit 81 registers pre-registered information such as payment information in the information management DB 45, linked to the second on-board device number and user ID, based on a request from the user terminal 20 (S5). The setting selection unit 82 selects and sets the user ID and payment information linked to the user US using the vehicle, based on a request from the user terminal 20 (S6, see also Figure 2 S32 and S35). When the fare calculation device 70 queries the first on-board device number, the number management device 40 notifies the fare calculation device 70 of the payment information, etc., linked to the query result (first on-board device number).

[0124] The fare calculation device 70 is configured with a communication acquisition unit 83, an in-vehicle device inquiry unit 84, and a service implementation unit 85, similar to the second embodiment. On the other hand, the configurations corresponding to the information registration unit 81 and the setting selection unit 82 are omitted in the fare calculation device 70. The communication acquisition unit 83 acquires the second in-vehicle device number transmitted from the in-vehicle device 10 (S7 and S8). The in-vehicle device inquiry unit 84 queries the number management device 40 for the first in-vehicle device number using the second in-vehicle device number. The in-vehicle device inquiry unit 84 acquires pre-registered information (settlement information) associated with the received second in-vehicle device number, along with the query result for the first in-vehicle device number (S9). The service implementation unit 85 uses the settlement information acquired along with the query result for the first in-vehicle device number to perform settlement processing for service usage fees.

[0125] In the third embodiment described above, the same effects as in the first embodiment are achieved, and it becomes possible to provide appropriate services to the user US who is currently using the vehicle using the user US's pre-registration information.

[0126] In addition, in the third embodiment, pre-registration information is registered in the information management DB 45, which is linked to the second on-board device number, in association with the second on-board device number, and is associated with the second on-board device number, which is more confidential than the first on-board device number, and is linked to the second on-board device number. Then, the pre-registration information linked to the second on-board device number is obtained along with the query result for the first on-board device number, and the service is provided using the pre-registration information obtained together with the query result. As described above, even in the form in which pre-registration information is registered in the information management DB 45, by providing the pre-registration information to the fare calculation device 70 in association with the query result for the first on-board device number, it becomes possible to provide appropriate services to the user US currently using the vehicle. In the third embodiment as well, the fare collection system 100 corresponds to the "service provision system".

[0127] (Other embodiments) Although several embodiments of this disclosure have been described above, this disclosure is not to be construed as being limited to the above embodiments, and can be applied to various embodiments and combinations without departing from the gist of this disclosure.

[0128] In the above embodiment, the "first on-board device information" was a less confidential on-board device number issued by the on-board device manufacturer HM and verifiable by the service provider SP, vehicle manager VM, and user US. In addition, the "second on-board device information" was a more confidential on-board device number issued for the above on-board device number and managed in the information management DB45 together with vehicle information (vehicle inspection information). The on-board device numbers corresponding to these "first on-board device information" and "second on-board device information" may be changed as appropriate.

[0129] More specifically, another in-vehicle device number associated with the in-vehicle device 10 (hereinafter referred to as the "third in-vehicle device number") can be used as either the "first in-vehicle device information" or the "second in-vehicle device information." The issuer and administrator of the third in-vehicle device number may be changed as appropriate. The third in-vehicle device number may be an existing number that has been uniquely assigned, or it may be a number newly issued by the information administrator IM and the service provider SP. The third in-vehicle device number may be unencrypted, low-security information, or encrypted, high-security information.

[0130] In this disclosure, the vehicle on which the in-vehicle device 10 is installed is not limited to a typical privately owned POV. The in-vehicle device 10 may be installed in rental cars, manned taxis, rideshare vehicles, freight vehicles, buses, etc. Furthermore, the in-vehicle device 10 may be installed in autonomous vehicles used in mobility services, construction machinery, agricultural machinery, railway vehicles, trams, and DMVs (Dual Mode Vehicles), etc.

[0131] In the above embodiment, the functions provided by the in-vehicle device, number management device, and fare calculation device, etc., can also be provided by software and hardware that executes it, software only, hardware only, or a combination thereof. Furthermore, when such functions are provided by electronic circuits as hardware, each function can also be provided by digital circuits including a large number of logic circuits, or by analog circuits. In addition, the software for realizing such functions may include at least a portion of code automatically generated by a neural network or language model.

[0132] Each processing unit in the above embodiment is hardware for arithmetic processing coupled with RAM. The processing unit has a configuration that includes at least one arithmetic core, such as a CPU (Central Processing Unit) and a GPU (Graphics Processing Unit). The processing unit may further include an FPGA (Field-Programmable Gate Array), an NPU (Neural Network Processing Unit), and other IP cores with dedicated functions. Furthermore, the processing unit is not limited to a configuration in which it is individually mounted on a printed circuit board. The processing unit may be mounted on an ASIC (Application Specific Integrated Circuit), SoC (System on Chip), chiplet integrated circuit, FPGA, etc.

[0133] In the above embodiment, the form of the storage medium (persistent tangible computer readable medium, non-transitory tangible storage medium) that stores various programs, etc., may be changed as appropriate. Furthermore, the storage medium is not limited to a configuration provided on a circuit board, but may be provided in the form of a memory card or the like, inserted into a slot, and electrically connected to control circuits such as the driver fit ECU and cloud server. In addition, the storage medium may be an optical disk, hard disk drive, solid state drive, etc., which serves as the source for copying or distributing programs to the driver fit ECU and cloud server, etc.

[0134] The control unit and method described herein may be implemented by a dedicated computer comprising a processor programmed to perform one or more functions embodied by a computer program. Alternatively, the apparatus and method described herein may be implemented by a dedicated hardware logic circuit. Alternatively, the apparatus and method described herein may be implemented by one or more dedicated computers comprising a combination of a processor that executes a computer program and one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by the computer on a computer-readable non-transitional tangible recording medium. [Explanation of Symbols]

[0135] 10 In-vehicle device (in-vehicle wireless device), 11, 41, 71 Processing unit, 20 User terminal, 45 Information management database, 50 Roadside wireless device, 70 Toll calculation device (service provision system), 75 Operator database, 81 Information registration unit, 82 Setting selection unit (user selection unit), 83 Communication acquisition unit, 84 In-vehicle device inquiry unit, 85 Service implementation unit, 100 Toll collection system (service provision system), IM Information Manager, SP Service Provider, US User

Claims

1. A service provision program that provides services to the user (US) of a vehicle using mobile wireless communication between an in-vehicle wireless device (10) mounted on the vehicle and a roadside wireless device (50) provided outside the vehicle, The system registers pre-registered information related to the user, linked to specific in-vehicle device information, which is either first in-vehicle device information or second in-vehicle device information that identifies the in-vehicle wireless device, and user identification information that identifies the user (S5). The user setting information is obtained to set the user identification information of the user using the vehicle (S6), The second in-vehicle device information transmitted from the in-vehicle wireless device to the roadside wireless device via the mobile wireless communication is acquired (S8), The first in-vehicle device information is accessed using the second in-vehicle device information (S9), The service is provided to the user using the pre-registration information linked to the specified in-vehicle device information (S10). A service provision program that causes at least one processing unit (11, 41, 71) to perform a process that includes the following steps.

2. In the step of registering the aforementioned pre-registration information, multiple payment information is registered as the aforementioned pre-registration information, linked to the aforementioned specific in-vehicle device information and the aforementioned user identification information. The process further includes the step of obtaining payment setting information (S35) which sets the payment information to be used for payment processing from among the multiple payment information, The service provision program according to claim 1, wherein in the step of providing the service, the payment processing is performed using the payment information based on the payment setting information.

3. In the step of registering the pre-registration information, the pre-registration information is registered in the service provider database (75) linked to the service provider (SP) that provides the service, linked to the first in-vehicle device information (S18). The service provision program according to claim 1, wherein in the step of providing the service, the service provision is performed using the pre-registered information linked to both the first in-vehicle device information queried using the second in-vehicle device information and the user identification information indicated by the user setting information (S74, S75).

4. In the step of registering the pre-registration information, the pre-registration information is registered in the in-vehicle wireless device in association with the second in-vehicle device information. In the step of acquiring the second in-vehicle device information, the pre-registration information transmitted from the in-vehicle wireless device via mobile wireless communication and linked to the second in-vehicle device information is further acquired. The service provision program according to claim 1, wherein in the step of providing the service, the service provision is performed using the pre-registration information obtained by reception from the in-vehicle wireless device.

5. In the step of registering the pre-registration information, the pre-registration information is registered in an information management database (45) linked to an information manager (IM) who manages the second in-vehicle device information, which is more confidential than the first in-vehicle device information, and is linked to the second in-vehicle device information. In the step of querying the first in-vehicle device information, the pre-registered information associated with the second in-vehicle device information is obtained together with the query result for the first in-vehicle device information. The service provision program according to claim 1, wherein in the step of providing the service, the service provision is performed using the pre-registration information obtained together with the inquiry result.

6. Based on the deactivation request to the information manager (IM) who manages the second in-vehicle device information, the second in-vehicle device information specified in the deactivation request is deactivated from among the multiple second in-vehicle device information registered in the information management database (45) linked to the information manager (S81). The service provision provided by multiple service providers, which is related to the invalidated second in-vehicle device information, is restricted collectively (S82, S90). The service provision program according to claim 1, further comprising the step of:

7. Based on the provision of public information by a public institution to the Information Manager (IM) who manages the information for the second in-vehicle device, the information for the second in-vehicle device specified in the public information is invalidated among the multiple pieces of information for the second in-vehicle device registered in the information management database linked to the information manager. The service provision provided by multiple service providers, which collectively restricts the service provision related to the invalidated second in-vehicle device information, The service provision program according to claim 1, further comprising the step of:

8. In the step of registering the aforementioned pre-registration information, theft information indicating the theft of the vehicle equipped with the in-vehicle wireless device is registered as the aforementioned pre-registration information. The service provision program according to claim 1, further comprising the step of storing a tracking record of the vehicle if the theft information is linked to the second in-vehicle device information acquired by the mobile wireless communication.

9. Set up an administrator account to manage the aforementioned in-vehicle wireless device, The administrator account is granted the authority to select a user to set the user identification information and the authority to select a payment method to set the payment information. The service provision program according to claim 2, further comprising the step of...

10. The service provision program according to claim 2, further comprising the step of deactivating the payment information used for the payment processing and prohibiting the payment processing based on the payment information, based on the fulfillment of a pre-set deactivation condition.

11. In the step of registering the pre-registration information, the pre-registration information includes the registration of restricted payment information, which is linked to the specific in-vehicle device information and the user identification information, and which has a limit on the number of times or period during which it can be used for payment processing. The service provision program according to claim 1, wherein in the step of providing the service, the program permits the payment processing using the restricted payment information if the limit is not exceeded, and prohibits the payment processing using the restricted payment information if the limit is exceeded.

12. In the step of registering the pre-registration information, at least one payment information and identity verification information related to the user are registered as the pre-registration information, linked to the specific in-vehicle device information and the user identification information. The service provision program according to claim 1, wherein in the step of providing the service, a payment process is performed using the payment information linked to the specific in-vehicle device information, and if the payment process using the payment information cannot be performed, a payment request is made to the user using the identity verification information (S92).

13. The service provision program according to claim 1, further comprising the step of querying the first in-vehicle device information, and if the query result obtained indicates that there is no first in-vehicle device information corresponding to the second in-vehicle device information, notifying the user using the vehicle that the service cannot be provided (S91).

14. In the step of acquiring the second in-vehicle device information, if the in-vehicle wireless device holds card information read from a payment card inserted into the in-vehicle wireless device, the card information transmitted in association with the second in-vehicle device information is further acquired by the mobile wireless communication. In the step of providing the aforementioned service, If the aforementioned card information has not been obtained, the service will be provided using the aforementioned pre-registration information. The service provision program according to claim 1, wherein when the card information is obtained, the service provision is performed using the card information.

15. The service provision program according to claim 1, further comprising the step of providing at least one of the specific in-vehicle device information and the pre-registered information associated with the user identification information to the user terminal (20) based on a viewing request from the user terminal (20) associated with the user.

16. A service provision system that provides services to the user (US) of a vehicle using mobile wireless communication between an in-vehicle wireless device (10) mounted on the vehicle and a roadside wireless device (50) provided outside the vehicle, An information registration unit (81) registers pre-registered information related to the user, linked to specific in-vehicle device information, which is one of the first in-vehicle device information and the second in-vehicle device information that identifies the in-vehicle wireless device, and user identification information that identifies the user. A user selection unit (82) that acquires user setting information for setting the user identification information of the user using the vehicle, A communication acquisition unit (83) that acquires the second in-vehicle device information transmitted from the in-vehicle wireless device to the roadside wireless device via the mobile wireless communication, An in-vehicle device inquiry unit (84) that queries the first in-vehicle device information using the second in-vehicle device information, A service implementation unit (85) that provides services to the user using the pre-registration information linked to the specified in-vehicle device information, A service delivery system equipped with the following features.

Citation Information

Patent Citations

  • System using etc on-vehicle unit

    JP2008217099A