System and Program

The system suppresses vehicle alarms temporarily upon a first trigger, requiring a second authentication to maintain a non-monitored state, addressing false alarms and enhancing security and user convenience.

JP7876232B2Active Publication Date: 2026-06-19YUPITERU CORP
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
YUPITERU CORP
Filing Date
2025-06-17
Publication Date
2026-06-19

AI Technical Summary

Technical Problem

Existing vehicle security systems often trigger false alarms when a legitimate user attempts to use the vehicle, compromising user experience and security effectiveness.

Method used

A system and program that temporarily suppresses alarm activation upon receiving a first trigger, requiring a subsequent legitimate authentication operation to maintain a non-monitored state, ensuring high security while minimizing false alarms.

Benefits of technology

Enhances vehicle security by preventing unauthorized activities and reducing false alarms, improving user convenience and experience by allowing temporary suppression of alarms during legitimate user authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007876232000001
    Figure 0007876232000001
  • Figure 0007876232000002
    Figure 0007876232000002
  • Figure 0007876232000003
    Figure 0007876232000003
Patent Text Reader

Abstract

To provide a novel technology relating to vehicle security.SOLUTION: A system includes warning means and control means. The warning means includes a function of issuing a warning when an anomaly is detected while a vehicle 1 is under a monitoring state. The control means temporarily suppresses a warning issued by the warning means when there is a first trigger while the vehicle 1 is under the monitoring state, and when there is a second trigger indicating that a normal authentication operation is accepted, keeps the vehicle 1 under a non-monitoring state.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] For example, it relates to systems, programs, etc.

Background Art

[0002] Irregularities such as a vehicle or its accessories being stolen or used by a third party other than a regular user of the vehicle (e.g., the owner or user of the vehicle, etc.) have become a social problem. Regarding vehicle security technology, for example, in Patent Document 1, an abnormality detection device is described that, when detecting an abnormality such as a certain pattern of vibration occurring in a vehicle, operates a vehicle horn, a lighting device, etc. to issue a warning.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] By detecting an abnormality in a vehicle and activating an alarm as in the technology described in Patent Document 1, it is possible to expect an effect of suppressing irregularities such as vehicle theft. However, if the alarm is activated even when a regular user is trying to use the vehicle, this will be a false alarm, which is not desirable for the regular user.

[0005] One of the objectives of the present invention is to provide a technology related to vehicle security that is different from the prior art. One of the objectives of the present invention is to provide, for example, a system and a program, etc. that are excellent in security while suppressing the activation of false alarms.

[0006] The object of the present invention is not limited thereto, and the applicant intends to obtain rights through divisional applications, amendments, etc., for configurations that aim to obtain the effects derived from the components of the configuration disclosed in this specification and the drawings, etc. For example, problems that can be described as "can be achieved" in this specification are disclosed here by reinterpreting them as "the problem is...". Each problem is described independently, and the applicant intends to obtain rights to each configuration for solving each problem individually through divisional applications, amendments, etc. Even if a problem is implicitly understood from the description in the specification, the applicant intends to include a part of the configuration described in this specification in the claims through amendment or divisional application. Furthermore, configurations that solve problems by combining these independent problems are also disclosed, and the applicant intends to obtain rights to them. [Means for solving the problem]

[0007] The object of the present invention can be achieved, for example, by the following embodiments (1) to (16).

[0008] (1) The system should include an alarm means that has a function to activate an alarm when an abnormality is detected while the vehicle is in a monitoring state, and a control means that when the vehicle is in a monitoring state and a first trigger is received, the alarm activation by the alarm means is temporarily suppressed, and when a second trigger indicating that a legitimate authentication operation has been accepted is received, the system should maintain the vehicle in an unmonitored state.

[0009] This approach maintains a non-supervised state only after a second trigger indicating that a legitimate authentication operation has been accepted, thus providing high security. Furthermore, the presence of the first trigger suppresses the activation of the alarm, preventing false alarms from being triggered when a legitimate user is performing the authentication operation. Moreover, the period during which authentication can be performed while the alarm is suppressed is limited to a temporary period from the time of the first trigger, which can also be considered a desirable security measure. Therefore, security can be enhanced while suppressing false alarm activations. Such an invention serves not only the purpose of preventing unauthorized activities such as vehicle theft by third parties, but also the purpose of suppressing false alarm activations caused by legitimate users, thereby preventing undesirable situations for those legitimate users.

[0010] (2) The control means may be configured such that, if the regular authentication operation is not accepted, it does not keep the vehicle in an unmonitored state and releases the temporary suppression of the alarm activation by the alarm means.

[0011] In this way, if a legitimate authentication process is not accepted, an alarm will be triggered by the alarm system. For example, this can deter malicious third parties from attempting fraudulent acts such as vehicle theft, thus achieving a high level of security.

[0012] (3) The standard authentication operation described above is a system in which standard authentication information is entered into an input means.

[0013] In this way, if legitimate authentication information is not entered, the vehicle will not remain in an unmonitored state. Therefore, a high level of security can be achieved.

[0014] (4) The standard authentication operation may be a system that includes a first input operation in which standard authentication information is input to a first input means, and a second input operation performed on a second input means inherently provided in the vehicle.

[0015] In this way, if only one of the first or second input operations is received, the vehicle will enter a monitored state instead of remaining in an unmonitored state, and the vehicle will remain in an unmonitored state only when both the first and second input operations are received. Furthermore, for example, a second input means inherently provided in the vehicle can be used to indicate the completion of authentication information input in the first input operation. Therefore, a higher level of security can be achieved without providing a new means for indicating the completion of authentication information input.

[0016] (5) The second input means may be a system that receives input related to the operation of the vehicle's engine.

[0017] In this way, for example, inputs related to the operation of the vehicle's engine, or operations that are normally performed when using the vehicle, can be combined with input completion operations that indicate the completion of authentication information input. Therefore, user experience can be improved.

[0018] (6) The control means may be a system that sets the first authentication operation as the regular authentication operation before a predetermined period has elapsed from the time the first trigger occurs, and prohibits setting the first authentication operation as the regular authentication operation after the predetermined period has elapsed.

[0019] In this way, for example, if a legitimate authentication operation is not accepted within a predetermined period after the first trigger occurs, and the vehicle enters a monitored state, the system prohibits the first authentication operation from being recognized as a legitimate authentication operation. Therefore, even if a third party takes the time to perform a legitimate first authentication operation, it prevents the vehicle from remaining in an unmonitored state.

[0020] (7) When the predetermined period has elapsed, the alarm means activates an alarm, and the control means sets a second authentication operation, which is an additional user procedure than required in the first authentication operation which is the regular authentication operation, as the regular authentication operation.

[0021] In this way, as long as the normal authentication operation is performed by the user while the activation of the alarm is suppressed, an increase in the operation burden can be suppressed. For example, when there is an error in the authentication operation or the authentication operation is not performed, by increasing the necessary user procedures for the normal authentication operation together with the activation of the alarm, it is possible to reduce the possibility of erroneously authenticating a person who is not a normal user as a normal user.

[0022] (8) The first trigger may be a system that indicates that a predetermined operation has been received when the vehicle is unlocked.

[0023] In this way, when there is a predetermined operation, for example, a predetermined operation to use the vehicle, when the vehicle is unlocked, there is a possibility that this is by a normal user, so the activation of the alarm is temporarily suppressed. Therefore, it is possible to suppress the activation of an incorrect alarm caused by a normal user.

[0024] (9) When the control means receives a predetermined signal having a data part different from that transmitted by the electronic key or a predetermined signal having a frequency different from the frequency used by the electronic key for wireless communication from a remote operation terminal different from the electronic key attached to the vehicle, the system may maintain the vehicle in a non-monitored state.

[0025] In this way, even if the user does not perform a normal authentication operation, when a predetermined signal from the remote operation terminal, which can be distinguished from the signal from the electronic key, is received, the vehicle can be maintained in a non-monitored state. Therefore, it is possible to improve the convenience of the user while realizing high security.

[0026] (10) Further provided with detection means capable of detecting the first trigger, and when the control means obtains information from the detection means that the first trigger has occurred, the control means temporarily suppresses the activation of the alarm by the alarm means and has a determination function for determining whether to maintain the vehicle in an unmonitored state. It is preferable that it is a system.

[0027] In this way, even if the control means is not provided with a function capable of detecting the first trigger, it is possible to determine the presence or absence of the first trigger based on the information from the detection means capable of detecting the first trigger.

[0028] (11) The alarm means has a function of activating an alarm when an abnormality is detected in a specific monitoring area of the vehicle when the vehicle is in a monitored state, and the second trigger indicates that a normal authentication operation has been received in the specific monitoring area. It is preferable that it is a system.

[0029] In this way, it is possible to set a specific monitoring area in the vehicle as an area where the user performs an authentication operation, and to perform the authentication operation in a state where the activation of the alarm is temporarily suppressed.

[0030] (12) It is preferable that the specific monitoring area includes the internal space area of the vehicle.

[0031] In this way, it is possible to set the internal space area of the vehicle as an area where the user performs an authentication operation, and to perform the authentication of the person inside the vehicle in a state where the activation of the alarm is temporarily suppressed.

[0032] (13) When the vehicle is in a monitored state, an abnormality is monitored in each of a plurality of monitoring areas of the vehicle. When the first trigger exists when the vehicle is in a monitored state, the control means temporarily suppresses the activation of the alarm regarding the specific monitoring area, which is a part of the plurality of monitoring areas. When the second trigger exists, it is preferable that it is a system that解除 the monitoring state of abnormalities in all of the plurality of monitoring areas.

[0033] In this way, even if the anomaly monitoring state in a specific monitoring area is temporarily deactivated in response to the first trigger, if a legitimate authentication operation is not accepted in that specific monitoring area, the anomaly monitoring state will not be deactivated in all of the multiple monitoring areas. Therefore, a high level of security can be achieved.

[0034] (14) The alarm means may be a system that activates an alarm when an abnormality is detected in a predetermined area different from the specific monitoring area between the first trigger and the second trigger.

[0035] In this way, even if the monitoring state for abnormalities is temporarily deactivated in some monitoring areas in response to the first trigger, an alarm will be triggered when an abnormality is detected in other predetermined areas, thereby deterring unauthorized activities such as the theft of the vehicle itself or its accessories.

[0036] (15) The system may include an alarm means that has a function to activate an alarm when an abnormality is detected while the vehicle is in a monitoring state, and a control means that temporarily suppresses the activation of an alarm by the alarm means when a second trigger indicating that a legitimate authentication operation has been accepted while the vehicle is in a monitoring state is detected, and maintains the vehicle in an unmonitored state when a first trigger is detected.

[0037] This approach maintains a non-supervised state only after a second trigger indicating that a legitimate authentication operation has been accepted, thus providing high security. Furthermore, since the second trigger suppresses the activation of alarms, it prevents alarms from being triggered erroneously when a legitimate user is attempting to use the vehicle. Additionally, the period during which the vehicle can be maintained in a non-supervised state while preventing alarm activation is limited to a temporary period from the second trigger, which is also a desirable security measure. Therefore, it is possible to enhance security while suppressing the activation of false alarms. Such an invention has the objective of preventing unauthorized activities such as theft of vehicles by third parties, as well as the objective of suppressing the activation of false alarms caused by legitimate users, thereby preventing undesirable situations for those legitimate users.

[0038] (16) It is preferable to have a program that causes a computer to perform a system function related to any of the above forms (1) to (15).

[0039] In this way, by installing the program on a computer and enabling the functions described in (1) to (15), a high level of security can be achieved. [Effects of the Invention]

[0040] According to the present invention, it is possible to provide a vehicle security technology that differs from conventional technologies. According to the present invention, for example, it is possible to provide a system and program that is highly secure while suppressing the activation of false alarms.

[0041] Furthermore, the effects of the present invention are not limited to those described herein. Effects derived from the components of the structure disclosed in this specification and the drawings are also disclosed, and the applicant intends to obtain rights to such components through divisional applications, amendments, etc. For example, phrases such as "can do" or "is possible" in this specification are descriptions that clearly indicate the effects to be achieved, and there are components that demonstrate effects even without such descriptions. Moreover, there are effects that can be grasped by the structure even without such descriptions. [Brief explanation of the drawing]

[0042] [Figure 1] A schematic diagram illustrating an example of the system. [Figure 2] This is an example of a system block diagram. [Figure 3] This is a flowchart used to explain the control processes performed within the system. [Figure 4] This is a flowchart used to explain the control processes performed within the system. [Figure 5] This is a flowchart used to explain the control processes performed within the system. [Modes for carrying out the invention]

[0043] [System Configuration] Referring to Figure 1, an example of the configuration of the system according to the present invention will be described. The following describes the case in which the present invention is applied to an electronic key system that locks (also referred to as locking) and unlocks (also referred to as unlocking) vehicle doors using an electronic key carried by the user. In the electronic key system, for example, the vehicle doors are unlocked by exchanging wireless signals between the electronic key and the vehicle-side device. Generally, the distance over which wireless communication is possible between the electronic key and the vehicle-side device (hereinafter also referred to as the wireless communication range) is limited to a relatively small distance. Therefore, normally, when the distance between the electronic key and the vehicle-side device is greater than the wireless communication range, wireless signals are not exchanged between the electronic key and the vehicle-side device, and the vehicle doors are not unlocked.

[0044] Figure 1 is a schematic diagram showing a vehicle system 100 to which the system according to this embodiment is applied. For example, as shown in Figure 1, the vehicle system 100 is configured to include a vehicle 1, an electronic key 2, and a remote terminal 3 (described later), etc.

[0045] The vehicles exemplified in the vehicle system 100 may be, for example, automobiles, and more particularly, four-wheeled automobiles. However, they are not limited to four-wheeled automobiles, and the vehicles may be large vehicles with four or more wheels. Furthermore, the vehicles exemplified in the vehicle system 100 may not be limited to all types of vehicles, such as transport vehicles (e.g., trucks), commercial vehicles (e.g., taxis, buses), and general vehicles (so-called private cars), but may be used for a variety of purposes. For example, the vehicles may be shared by an unspecified number of people, such as for car sharing or rental.

[0046] Electronic key 2 is a key capable of wireless communication with vehicle 1, and may be, for example, the original electronic key included with vehicle 1. Electronic key 2 is usually carried by the authorized user of vehicle 1. This electronic key 2 is also referred to as a smart key, for example.

[0047] Figure 2 is an example of a block diagram of the vehicle system 100 according to this embodiment. The vehicle system 100 consists of, for example, two systems: an electronic key system 10 and an authentication system 20.

[0048] The electronic key system 10 is a system that enables locking and unlocking of the vehicle doors 9 through wireless communication between the vehicle 1 and the electronic key 2, and is a system that is inherently built into the vehicle 1.

[0049] The electronic key system 10 is configured with various ECUs, such as an electronic key ECU (Engine Control Unit) 11 and a body ECU 12.

[0050] The electronic key ECU 11 is a processing unit that controls wireless communication with the electronic key 2, etc. The electronic key ECU 11 has functions such as detecting radio waves from the electronic key 2, determining the legitimacy of the electronic key 2, and transmitting the determination result to the body ECU 12, etc.

[0051] The body ECU 12 is a processing unit that performs control over the body of the vehicle 1. For example, the body ECU 12 has the function of transmitting a lock signal (also called a locking signal) and an unlock signal (also called an unlocking signal) to the vehicle door 9 (see Figure 1) of the vehicle 1.

[0052] In the electronic key system 10, the electronic key ECU 11 and the electronic key 2 are interconnected. For example, when a user carrying the electronic key 2 presses the second receiver 7 (see Figure 1) of the vehicle 1 near the vehicle 1, wireless communication is conducted between the electronic key ECU 11 and the electronic key 2. The second receiver 7 is, for example, a door switch or other switch. The electronic key ECU 11 then performs a verification process for the electronic key 2 based on the wireless signal from the electronic key 2, and if it determines that the electronic key 2 is legitimate, it transmits a signal to the body ECU 12 indicating that the vehicle door 9 of the vehicle 1 should be unlocked. Upon receiving this signal, the body ECU 12 transmits an unlock signal to the vehicle door 9. This unlocks the vehicle door 9.

[0053] Furthermore, the unlock operation of the vehicle door 9 is not limited to pressing the second reception unit 7, but may also be performed by pressing the unlock button on the electronic key 2. In addition, various unlock operations exist depending on the vehicle manufacturer and model. For example, if a touch sensor is provided on the handle of the vehicle door, touching the handle may be the unlock operation for the vehicle door 9.

[0054] The authentication system 20 is a system for authenticating (also called user authentication) users who intend to use a vehicle (for example, a person who intends to get into vehicle 1, or a person who intends to drive vehicle 1, etc.; the same applies hereinafter), and is a system that is retrofitted to vehicle 1, for example. The authentication system 20 is a system for preventing unauthorized use of vehicle 1 itself or its accessories (for example, the engine of vehicle 1, etc.), and is also called an anti-fraud system or a security system.

[0055] As shown in Figure 2, the authentication system 20 includes, for example, a control unit 21 (an example of control means), a detection unit 22 (an example of detection means), a communication unit 23 (an example of communication means), an input device 24 (an example of input means), and an alarm device 25 (an example of alarm means).

[0056] The control unit 21 is a controller that includes a CPU, memory such as ROM and RAM, a timer (an example of a timing means), and other peripheral circuits. Various programs are stored in the ROM of the control unit 21, and the control unit 21 realizes various functions by executing these programs. These programs include programs that describe algorithms for executing the processes shown in the flowcharts in Figures 3 to 5. The control unit 21 is the processing unit that primarily operates in the authentication system 20.

[0057] The control unit 21 has various functions, such as an alarm control function that controls the activation and deactivation of alarms by the alarm device 25, an authentication function that performs user authentication, and a judgment function that determines whether or not a legitimate authentication operation (described later) has been accepted. The judgment function, for example, when information that a first trigger has occurred is obtained from the detection unit 22, has the function of temporarily suppressing the activation of alarms by the alarm device 25 and determining whether or not to switch the vehicle 1 to an unmonitored state.

[0058] The monitoring state is a state in which an anomaly (for example, a security anomaly) is being monitored, and is also referred to as an alert state. The non-monitoring state is a state in which no anomalies are being monitored, and is also referred to as a non-alert state.

[0059] The detection unit 22 is a processing unit capable of detecting, for example, the state of vehicle 1 and the behavior of vehicle 1.

[0060] The communication unit 23 (see Figure 2) is a processing unit capable of performing wireless communication with the remote terminal 3 (described below).

[0061] The remote terminal 3 (see Figure 1) is a remote control terminal capable of wireless communication with the vehicle 1 (specifically, the communication unit 23 of the authentication system 20 of the vehicle 1). The remote terminal 3 is capable of exchanging wireless signals with the vehicle 1 within the range where wireless communication with the vehicle 1 is possible. The remote terminal 3 is provided, for example, attached to the authentication system 20.

[0062] The remote terminal 3 is equipped with a non-monitoring command transmission button (not shown) for transmitting a non-monitoring command (described below). A non-monitoring command is a command to transition vehicle 1 from a monitored state to a non-monitoring state. When the communication unit 23 receives the non-monitoring command from the remote terminal 3, it transmits information to that effect to the control unit 21. Based on this information, the control unit 21 transitions vehicle 1 from a monitored state to a non-monitoring state.

[0063] Furthermore, users can perform high-security settings (described later) using, for example, remote terminal 3.

[0064] Here, the authentication system 20 is provided with two types of authentication operations, for example, a first authentication operation and a second authentication operation.

[0065] For example, if a second authentication operation is required as the authentication operation, the user is required to enter pre-registered authentication information. If a first authentication operation is required as the authentication operation, the user is required to enter authentication information that can be entered in fewer steps than when required for the second authentication operation. The authentication information may be, for example, alphabets, numbers, symbols, hiragana, katakana, or a combination of two or more of these, but using only one type makes it easier to simplify the configuration of the input means. The input means may be capable of accepting the input of authentication information and may be, for example, a keyboard, numeric keypad, or dedicated buttons. The authentication information required for the first authentication operation may be common to a part of the authentication information required for the second authentication operation (for example, one or more predetermined characters from the beginning). This reduces the possibility of the user forgetting their authentication information. The authentication information required for the first and second authentication operations may be set in advance by, for example, the user.

[0066] Thus, the user steps required in the first authentication process are fewer than those required in the second authentication process, making authentication via the first authentication process simpler for the user. The differences in when to use the first and second authentication processes will be discussed later. "Steps" can refer to the amount of user operation, such as the number of times a button on the input device 24 is pressed or the number of buttons to be operated.

[0067] The high-security setting is a setting to further enhance the security performance of the authentication system 20. The high-security setting prohibits the first authentication operation, one of two types of authentication operations (first authentication operation and second authentication operation), from being treated as a legitimate authentication operation. The authentication system 20 prohibits the first authentication operation from being treated as a legitimate authentication operation and treats the second authentication operation as the legitimate authentication operation. The user steps required for the second authentication operation, which is treated as a legitimate authentication operation, are more numerous than those required for the first authentication operation, making it suitable for ensuring higher security. On the other hand, if the high-security setting is not enabled, the authentication system 20 will treat either the first or second authentication operation as a legitimate authentication operation if either one is performed. This simplifies the authentication actions that the user must perform.

[0068] Furthermore, it would be beneficial to configure the system, for example, to immediately switch vehicle 1 from a monitored state to an unmonitored state in response to the first trigger described later, using a remote terminal 3. The authentication system 20 should allow the user to configure whether to prioritize security or user convenience.

[0069] The input device 24 functions as an input means on which authentication information can be entered. The input device 24 is preferably installed in a spatial area inside the vehicle 1, and is especially preferably installed in a place that is difficult to see from outside the vehicle. Such a place is preferably a place where it is out of the line of sight of a person outside the vehicle, for example, a place where the line of sight of a person outside the vehicle is blocked by a component of the vehicle (e.g., the vehicle body) or an object installed in the vehicle (e.g., a seat, dashboard, etc.).

[0070] The alarm device 25 is a device capable of activating an alarm. The alarm device 25 has the function of activating an alarm when an abnormality is detected in a specific monitoring area of ​​the vehicle 1 while the vehicle 1 is in a monitoring state. The alarm device 25 is provided separately from, for example, a buzzer that is originally provided in the vehicle 1.

[0071] The "activation of an alarm" by the alarm device 25 may be the sounding of an alarm sound such as a siren. However, it is not limited to this, and the "activation of an alarm" may also be the voice of an alarm message such as "An abnormality has been detected." Alternatively, the alarm device 25 may cooperate with the communication unit 23 to notify the user's smartphone or the like of an alarm message, and this alarm notification operation may also constitute the "activation of an alarm." The alarm device 25 should issue an alarm in a manner that can be perceived by a person outside the vehicle.

[0072] As shown in Figure 2, vehicle 1 is equipped with a first reception section 6 and a second reception section 7, etc.

[0073] The first receiving unit 6 functions as a means for receiving input related to the operation of the vehicle's prime mover (e.g., engine or motor). The first receiving unit 6 may be, for example, a predetermined pedal of the vehicle (e.g., accelerator pedal or brake pedal), an accessory power switch, or an ignition switch (e.g., a button-type ignition switch provided on the dashboard, or an ignition switch consisting of a switching mechanism provided inside the key cylinder). In the case of an electric vehicle, the first receiving unit 6 may also be a switch for turning on the vehicle's system power. The first receiving unit 6 is particularly preferably an operating member that is inherently provided in the internal space of the vehicle 1.

[0074] [General operation] Next, the general operation of the vehicle system 100 according to this embodiment will be described.

[0075] In this embodiment, for example, when a first trigger occurs while vehicle 1 is in a monitoring state, the control unit 21 temporarily suppresses the activation of an alarm by the alarm device 25. When a second trigger occurs indicating that a legitimate authentication operation has been accepted, the control unit 21 maintains vehicle 1 in an unmonitored state.

[0076] For example, if a legitimate authentication operation is not accepted after the first trigger and there is no second trigger, the control unit 21 does not transition the vehicle 1 to an unmonitored state and releases the temporary suppression of the alarm activation by the alarm device 25. In this way, since the alarm device 25 is activated when a legitimate authentication operation is not accepted, it is possible to deter unauthorized actions such as the theft of the vehicle by a third party other than the user (e.g., a thief), thereby achieving a high level of security.

[0077] The "first trigger" may indicate, for example, that a predetermined action has been received from the user when the lock on vehicle 1 (for example, vehicle door 9 of vehicle 1) is unlocked. For example, if a predetermined action is taken to use vehicle 1, it may be performed by a legitimate user, so the alarm is temporarily suppressed. In this way, false alarms caused by legitimate users can be suppressed.

[0078] The presence or absence of the "first trigger" can be detected, for example, by a detection unit 22 (an example of a detection means) capable of detecting the first trigger. When the control unit 21 (an example of a control means) receives information from the detection unit 22 that the first trigger was present, it is preferable to temporarily suppress the activation of the alarm by the alarm device 25 (an example of an alarm means). In this way, even if the control unit 21 is not equipped with a function capable of detecting the first trigger, it is possible to determine the presence or absence of the first trigger based on the information from the detection unit 22.

[0079] However, the system is not limited to this, and the authentication system 20 may not be provided with a detection unit 22, and the control unit 21 itself may have a function capable of detecting the first trigger.

[0080] The "first trigger" may indicate, for example, that predetermined conditions have been met so that it can be objectively determined that the user is about to use vehicle 1. The "first trigger" may indicate, for example, that the user has touched the electronic key 2, that a predetermined operation has been performed on the electronic key 2, that the electronic key 2 is in the user's possession, that the electronic key 2 has moved within a predetermined distance range from vehicle 1, that the vehicle door 9 has been opened, or that the lock on the vehicle door 9 has been released.

[0081] For example, the fact that a user has touched the electronic key 2 can be detected by, for example, a sensor that detects contact between an object and the electronic key 2. The fact that the electronic key 2 is being held by the user can be detected by, for example, a vibration sensor installed on the electronic key 2 detecting vibration. The fact that the vehicle door 9 has been opened can be detected by, for example, a door sensor that detects the opening and closing of a door. The fact that the vehicle 1 has been unlocked can be detected, for example, as follows.

[0082] For example, vehicle 1 is equipped with an answer-back function. The answer-back function is a function that allows vehicle 1 to respond to user operations (for example, an unlock operation). The answer-back function may perform actions such as flashing the hazard lights or sounding a buzzer. When the user performs an unlock operation, for example, the body ECU 12 transmits an unlock command signal to the vehicle door 9 (or the ECU that controls the operation of the vehicle door 9), thereby releasing the lock on the vehicle door 9. At this time, the body ECU 12 transmits a predetermined command signal to the answer-back execution device, and the execution device performs an operation according to the predetermined command signal. The detection unit 22 may then detect that the lock on the vehicle door 9 has been released by monitoring the behavior of the execution device.

[0083] For example, when the answer-back execution device is the hazard lights, the body ECU 12 transmits a predetermined number of flashing command signals (e.g., 2 times) to the hazard lights, and the hazard lights flash a predetermined number of times in response to the flashing command signals. The detection unit 22 then detects that the vehicle door 9 has been unlocked by detecting the flashing interval or the number of flashes of the hazard lights.

[0084] Furthermore, if the answer-back execution device is a buzzer, for example, the body ECU 12 transmits a command signal to the buzzer to sound a predetermined number of times (for example, 2 times), and the buzzer sounds a predetermined number of times in response to the command signal. The detection unit 22 detects that the lock on the vehicle door 9 has been released by detecting the interval or number of times the buzzer sounds.

[0085] Furthermore, instead of the detection unit 22 directly monitoring the behavior of the answer-back execution device, it may, for example, indirectly monitor the behavior of the answer-back execution device by monitoring the CAN (Controller Area Network) connected to each ECU in the vehicle 1.

[0086] A "legitimate authentication operation" may include, for example, a first input operation in which legitimate authentication information is entered into a first input means capable of receiving authentication information, and a second input operation performed on a second input means inherently provided in vehicle 1. Furthermore, a "legitimate authentication operation" may be defined as the second input operation occurring immediately after the first input operation. The second input operation may be performed as an input completion operation to indicate the completion of the input of authentication information in the first input operation. A legitimate authentication operation signifies successful authentication; for example, a legitimate authentication operation is considered to have occurred when correct authentication information is entered.

[0087] In this way, if only one of the first or second input operations is received, vehicle 1 will not be kept in an unmonitored state but will remain in a monitored state. Only when both the first and second input operations are received will vehicle 1 be kept in an unmonitored state. Furthermore, for example, a second input means inherently provided in vehicle 1 can be used to instruct the completion of authentication information input in the first input operation. Therefore, a higher level of security can be achieved without providing a new means for instructing the completion of authentication information input.

[0088] The authentication information may be pre-registered (e.g., initially configured) in the control unit 21, etc., by a legitimate user (such as a purchaser of the authentication system 20). However, it is not limited to this; for example, legitimate authentication information may be pre-registered in the control unit 21, etc., by the seller during the design phase, and the purchaser may be notified via a website or printed material exclusively for purchasers of the authentication system 20. Furthermore, if the authentication system 20 is installed in a vehicle 1 that is shared by an unspecified number of people, such as for car sharing or rental, the legitimate authentication information may be shared with authentication information used in car sharing or rental services (e.g., telephone number, etc.). In this case, the user does not need to consider separate authentication information for the authentication system 20, and high usability can be achieved.

[0089] The "first input means" may be an operating member provided in the internal space of the vehicle 1, for example, an input device 24.

[0090] The "second input means" may be, for example, the first reception unit 6. In this way, inputs related to the operation of the engine of the vehicle 1, or operations normally performed when using the vehicle 1, can be combined with input completion operations that instruct the completion of input of authentication information. Therefore, user operability can be improved. Furthermore, since the first reception unit 6, which is inherently provided in the vehicle 1, is used for the input completion operation, there is no need to provide a separate operating member for performing the input completion operation.

[0091] The "second trigger" should indicate that a legitimate authentication operation has been accepted in a specific monitoring area of ​​vehicle 1. In this way, user authentication operations in a specific monitoring area can be performed under the monitoring state of vehicle 1 while suppressing the activation of alarms.

[0092] A "specific monitoring area" is, for example, an area where authentication operations are performed, and one example of such an area is the spatial area inside vehicle 1. In this way, the spatial area inside vehicle 1 can be designated as the area where the user performs authentication operations, and the authentication of a person inside the spatial area inside vehicle 1 can be performed while suppressing the activation of alarms.

[0093] However, the authentication process is not limited to this, and can be performed at any location as long as it is possible to authenticate the person intending to use vehicle 1. For example, the authentication process may be performed outside vehicle 1. In this case, for example, an input means for authentication information may be provided outside vehicle 1. For example, a sensor capable of detecting knocks may be provided on the vehicle body of vehicle 1 itself (e.g., a window), and a knocking action on the vehicle body of vehicle 1 may be accepted as an authentication action. It is then possible to determine whether the accepted knock pattern is a specific pattern or not. Considering the ability to authenticate a person actually present in the spatial area inside vehicle 1, it is particularly preferable that the input means for authentication information be provided in the spatial area inside vehicle 1.

[0094] [Detailed Operation] Next, the detailed operation of the vehicle system 100 according to this embodiment will be described with reference to Figures 3 to 5. Figures 3 to 5 are flowcharts showing an example of a control process (for example, fraud prevention process) executed by the control unit 21 of the authentication system 20.

[0095] First, in step S11 of Figure 3, the control unit 21 determines whether or not vehicle 1 has transitioned from an unmonitored state to a monitored state.

[0096] For example, when a user performs a lock operation to lock the vehicle door 9 of vehicle 1, the vehicle door 9 of vehicle 1 is locked, and vehicle 1 transitions from an unmonitored state to a monitored state. Examples of lock operations include pressing the second receiver 7 on the vehicle door 9 while the electronic key 2 is near vehicle 1, or pressing the lock button on the electronic key 2 while the electronic key 2 is near vehicle 1. Once vehicle 1 transitions to the monitored state, the process proceeds from step S11 to step S12.

[0097] When vehicle 1 transitions from an unmonitored state to a monitored state, for example, the control unit 21 begins monitoring for the corresponding type of abnormality in each of the multiple monitoring areas of vehicle 1. This initiates monitoring for multiple types of abnormalities in vehicle 1. The multiple monitoring areas may also be referred to as multiple monitoring target areas.

[0098] The "multiple monitoring areas" may be determined, for example, as areas in the vehicle that require high monitoring. Such areas may include, for example, the internal spatial area of ​​the vehicle 1, the trunk and hood and other predetermined openable parts of the vehicle 1, the first reception unit 6, and one or more other areas. For example, various sensors may be provided in each of these monitoring areas, and the control unit 21 monitors abnormalities in each monitoring area by coordinating with the sensors provided in each monitoring area. An abnormality in the internal spatial area of ​​the vehicle 1 may be detected, for example, when an object (e.g., a person) moves within that spatial area or when the vehicle 1 vibrates. The movement of an object within that spatial area may be detected, for example, by a motion sensor, and the vibration of the vehicle 1 may be detected, for example, by a vibration sensor. An abnormality in the trunk and hood and other predetermined openable parts of the vehicle 1 may be detected when those parts are opened. An abnormality in the first reception unit 6 may be detected when the first reception unit 6 is operated. What kinds of events are detected as anomalies depend on the structure or other characteristics of each monitoring area.

[0099] In step S12, the control unit 21 determines whether or not high security settings have been made. If it is determined that high security settings have been made, the process proceeds from step S12 to step S51 (Figure 5). If it is determined that high security settings have not been made, the process proceeds from step S12 to step S13.

[0100] The following describes the case where the process proceeds to step S13 (Figure 3). The case where the process proceeds to step S51 (Figure 5) will be described later.

[0101] As shown in Figure 3, when vehicle 1 is in a monitoring state, the control unit 21 waits until one of the following occurs: receiving a non-monitoring command from remote terminal 3 (step S13), accepting an authentication operation (step S14), or trigger B (an example of a first trigger) (step S17). Specifically, the decision processes in steps S12, S13, S14, and S17 are repeated until one of the following occurs: receiving a non-monitoring command from remote terminal 3, accepting an authentication operation, or trigger B.

[0102] First, in step S13, the control unit 21 determines whether or not a non-monitoring command has been received from the remote terminal 3 while vehicle 1 is in a monitoring state. As described above, the non-monitoring command is a command to transition vehicle 1 to a non-monitoring state.

[0103] For example, if a user carrying the remote terminal 3 is in close proximity to the vehicle 1 and presses the non-supervised command transmission button on the remote terminal 3, a non-supervised command is transmitted from the remote terminal 3, and the communication unit 23 receives the non-supervised command. As a result, the control unit 21 determines that a non-supervised command has been received from the remote terminal 3, and the process proceeds from step S13 to step S23.

[0104] In step S23, the control unit 21 transitions vehicle 1 to a non-monitoring state. For example, the control unit 21 transitions vehicle 1 from a monitored state to a non-monitoring state. More specifically, the control unit 21 transitions all of the multiple monitored areas of vehicle 1 from a monitored state to a non-monitoring state. As a result, abnormality monitoring stops in all of the multiple monitored areas inside vehicle 1.

[0105] In this way, when the control unit 21 receives a predetermined signal (for example, a non-supervised command signal) from the remote terminal 3 (an example of a remote operation terminal), it transitions the vehicle 1 to a non-supervised state and maintains it there, regardless of the presence or absence of a first trigger and a second trigger indicating that a legitimate authentication operation has been accepted (step S22 described later). In this way, even if the user does not perform a legitimate authentication operation, when the vehicle 1 receives a predetermined signal from the remote terminal 3 that is distinguishable from the signal from the electronic key 2, it can transition the vehicle 1 to a non-supervised state and maintain it there. Therefore, it is possible to improve user convenience while achieving high security.

[0106] On the other hand, if it is determined in step S13 that no non-monitoring command has been received from remote terminal 3, the process proceeds from step S13 to step S14.

[0107] In step S14, the control unit 21 determines whether or not the authentication operation has been accepted. The processing content of step S14 is the same as that of step S19, which will be described later, so the details will be described later.

[0108] For example, if the authentication operation is not accepted, the process proceeds from step S14 to step S17, and if the authentication operation is accepted, the process proceeds from step S14 to step S15.

[0109] In step S15, the control unit 21 determines whether or not there was a trigger A (an example of a second trigger) indicating that a legitimate first authentication operation or a legitimate second authentication operation was accepted. If there is a trigger A, the process proceeds from step S15 to step S23; if there is no trigger A, the process proceeds from step S15 to step S16.

[0110] In step S16, the control unit 21 activates an alarm using the alarm device 25.

[0111] If the authentication operation is not accepted in step S14 and the process proceeds from step S14 to step S17, the control unit 21 determines whether or not trigger B occurred (step S17).

[0112] If it is determined that trigger B does not exist, the process returns to step S12. On the other hand, if it is determined that trigger B was present, the process proceeds from step S17 to step S18.

[0113] If it is determined that trigger B has occurred, the control unit 21 temporarily suppresses the activation of the alarm by the alarm device 25 while keeping the vehicle 1 in a monitoring state. For example, the control unit 21 temporarily suppresses the activation of an alarm related to a specific monitoring area, which is a part of the multiple monitoring areas. More specifically, the control unit 21 temporarily suppresses the activation of an alarm related to a specific monitoring area, which is a part of the multiple monitoring areas, by temporarily deactivating the abnormality monitoring state in that specific monitoring area, while maintaining the monitoring state for the vehicle 1 as a whole.

[0114] Furthermore, among the multiple monitoring areas (also referred to as multiple monitored areas, for example), a predetermined area different from the specific monitoring area in question (for example, the remaining monitoring areas excluding the specific monitoring area in question) remains in a monitoring state.

[0115] Since the "specific monitoring area" includes, for example, the interior space of vehicle 1, even if a user opens the vehicle door 9 and enters the interior space of vehicle 1, the alarm from the alarm device 25 will not be activated immediately. Conversely, even if the monitoring state in the "specific monitoring area" is temporarily deactivated, the monitoring state will continue for areas that still require monitoring, and if an abnormality is detected in those areas, the alarm from the alarm device 25 will be activated.

[0116] Thus, if the control unit 21 detects, for example, a trigger B indicating that a predetermined operation has been received from outside the vehicle 1 while the vehicle 1 is in a monitoring state, it temporarily suppresses the activation of the alarm by the alarm device 25. Once it is determined that trigger B has occurred, the control unit 21 starts the timing process.

[0117] In step S18, the control unit 21 determines whether a predetermined time has elapsed since trigger B. The predetermined time may be set to a fixed value in advance, or it may be set by the user.

[0118] For example, if a predetermined time elapses because the person performing the authentication operation is having difficulty with the authentication operation, it is determined in step S18 that the predetermined time has elapsed since trigger B, and the process proceeds from step S18 to step S24. Also, for example, even if the authentication operation is accepted after trigger B, if the predetermined time elapses after the first input operation without the second input operation being accepted, it is determined in step S18 that the predetermined time has elapsed since trigger B, and the process proceeds from step S18 to step S24. In step S24, the control unit 21 activates an alarm on the alarm device 25. Details of step S24 will be described later.

[0119] Thus, the moment trigger B occurs becomes, for example, the start of the time limit for performing a legitimate authentication operation, and if a legitimate authentication operation is not performed within that time limit, an alarm is triggered by the alarm device 25.

[0120] On the other hand, if a predetermined amount of time has not yet elapsed since trigger B, the process proceeds from step S18 to step S19.

[0121] In step S19, the control unit 21 determines whether or not the authentication operation has been accepted.

[0122] If the authentication operation is not accepted, the process proceeds from step S19 to step S20. If the authentication operation is accepted, the process proceeds from step S19 to step S22. The following describes the case where the process proceeds to step S22. The case where the process proceeds to step S20 will be described later.

[0123] In step S22, the control unit 21 determines whether there was a trigger C (an example of a second trigger) indicating that a legitimate first authentication operation or a legitimate second authentication operation was accepted. More specifically, the control unit 21 determines whether the first authentication operation or the second authentication operation accepted in step S19 is a legitimate authentication operation. The reason for allowing both the first and second authentication operations is to reduce the operational burden associated with authenticating legitimate users.

[0124] For example, when a user performs a first authentication operation, the user inputs authentication information using the input device 24 and then operates the first reception unit 6 (for example, by pressing it once; the same applies hereinafter). As a result, the control unit 21 accepts the authentication operation of inputting authentication information (an example of a first input operation) and the operation of the first reception unit 6 (an example of a second input operation) (step S19).

[0125] The process then proceeds from step S19 to step S22, where the control unit 21 performs user authentication by comparing the authentication information entered using the input device 24 with pre-registered legitimate authentication information.

[0126] For example, when user authentication is successful because the entered authentication information matches the legitimate authentication information, the control unit 21 determines in step S22 that there was a trigger C indicating that a legitimate authentication operation (for example, a legitimate first authentication operation) was accepted.

[0127] The process then proceeds from step S22 to step S23, and the control unit 21 transitions vehicle 1 from a monitored state to a non-monitored state.

[0128] For example, the control unit 21 maintains a specific monitoring area (e.g., a spatial area inside the vehicle 1) that had temporarily transitioned to an unmonitored state in response to trigger B, while simultaneously transitioning the remaining monitoring areas that were still in a monitored state at the time of trigger B from a monitored state to an unmonitored state and maintaining them in that state. As a result, abnormality monitoring is stopped in all of the multiple monitoring areas of the vehicle 1.

[0129] Thus, when trigger B is detected while vehicle 1 is in a monitoring state, the control unit 21 temporarily suppresses the activation of an alarm for a specific monitoring area, which is a part of the multiple monitoring areas. When trigger C is detected, the abnormal monitoring state is deactivated for all of the multiple monitoring areas. Conversely, when trigger C is not detected, the abnormal monitoring state is not deactivated for all of the multiple monitoring areas. For example, even if the abnormal monitoring state for a specific monitoring area is temporarily deactivated in response to trigger B, if a legitimate authentication operation is not accepted in that specific monitoring area, the abnormal monitoring state for all of the multiple monitoring areas will not be deactivated. Therefore, a high level of security can be achieved.

[0130] On the other hand, if there is no trigger C indicating that a legitimate authentication operation has been accepted, the process proceeds from step S22 to step S24 (described later). For example, if user authentication fails because the entered authentication information does not match the legitimate authentication information, the control unit 21 determines in step S22 that a legitimate authentication operation was not accepted (for example, that an incorrect authentication operation was accepted). Then, the process proceeds from step S22 to step S24.

[0131] In this embodiment, the number of times an authentication operation can be accepted is one, and an alarm is triggered if, for example, an incorrect authentication operation is performed even once. However, this is not limited to this, and the number of times an authentication operation can be accepted may be multiple (for example, three times).

[0132] Next, we will explain what happens when you proceed from step S19 to step S20.

[0133] In step S20, the control unit 21 determines whether a non-monitoring command has been received from the remote terminal 3 when, for example, a specific monitoring area of ​​vehicle 1 is temporarily in a non-monitoring state. Note that the difference between step S13 and step S20 in Figure 3 is, for example, whether all of the multiple monitoring areas of vehicle 1 are in a monitoring state or whether only a part of those multiple monitoring areas (such as a specific monitoring area) is in a temporarily non-monitoring state.

[0134] For example, after trigger B occurs, the user presses the non-supervised command transmission button on the remote terminal 3 within the spatial area inside vehicle 1. In response, the remote terminal 3 transmits a non-supervised command, and the control unit 21 determines in step S20 that a non-supervised command has been received from the remote terminal 3.

[0135] When a non-monitoring command is received from the remote terminal 3, the process proceeds from step S20 to step S23, and the process of transitioning vehicle 1 to a non-monitoring state is executed in the same manner as described above.

[0136] On the other hand, when no non-monitoring command is received from the remote terminal 3, the process proceeds from step S20 to step S21, and the control unit 21 determines whether an abnormality has been detected in any of the multiple monitoring areas, excluding a specific monitoring area of ​​the vehicle 1 (for example, a spatial area inside the vehicle 1) (for example, a predetermined monitoring area that is still being monitored). The remaining monitoring area may be, for example, an area different from the area where authentication operations are performed (in this embodiment, a spatial area inside the vehicle 1). Examples of such areas include one or more of the trunk, hood, first reception unit 6, and other areas in the vehicle 1.

[0137] If an anomaly is detected in the remaining monitoring area between the time trigger B occurs (step S17) and the time trigger C occurs (step S22), the process proceeds from step S21 to step S24. On the other hand, if no anomaly is detected in the remaining monitoring area, the process returns to step S18.

[0138] On the other hand, if it is determined in step S21 that an anomaly has been detected in the remaining monitoring area that is still under monitoring, the alarm device 25 will activate an alarm (step S24).

[0139] In this way, if an anomaly is detected in a predetermined area different from a specific monitoring area between the time trigger B occurs and the time trigger C occurs, an alarm is triggered. This way, even if the monitoring state for an anomaly is temporarily deactivated in some monitoring areas (for example, the spatial area inside vehicle 1) in response to trigger B, if an anomaly is detected in another predetermined area, an alarm will be immediately triggered, thus preventing unauthorized activities such as theft of vehicle 1 itself or its accessories.

[0140] Next, we will describe step S24 in Figure 3 in detail.

[0141] As mentioned above, If a valid authentication operation is not accepted within a predetermined time after trigger B occurs (step S17) (YES in step S18), • If the authentication operation accepted in step S19 is different from a legitimate authentication operation (NO in step S22), or, - When an anomaly is detected in a monitoring area other than the specific monitoring area between the occurrence of trigger B (step S17) and the occurrence of trigger C (step S22) (YES in step S21) In response, the control unit 21 activates an alarm using the alarm device 25 (step S24).

[0142] In detail, the control unit 21 prevents the vehicle 1 from remaining in an unmonitored state (for example, it does not allow it to remain in an unmonitored state) and releases the temporary suppression of the alarm activation by the alarm device 25. Then, the alarm device 25 activates the alarm (step S24).

[0143] In this way, even if a malicious third party were to intrude into the internal space of vehicle 1, an alarm would be triggered if any of the above actions were performed afterward (step S24). This would deter malicious third parties from attempting to steal the vehicle or engage in other fraudulent activities, thereby achieving a high level of security.

[0144] Furthermore, the cause that led to the alarm activation process was, • When a legitimate authentication operation is not accepted within a specified time after trigger B occurs, • When the accepted authentication action differs from the legitimate authentication action, • When an anomaly is detected in a monitoring area other than a specific monitoring area among multiple monitoring areas. It would be good to implement a system where different alarms (for example, alarms of different volume levels or different types of alarms) are triggered depending on which of the following conditions is met.

[0145] In this way, even if an alarm is triggered after trigger B occurs because the user unintentionally fails to perform a legitimate authentication action, the user can still learn the cause. As a result, for example, the user can take appropriate action during subsequent authentication actions based on the cause learned during the previous alarm.

[0146] If an alarm is triggered in step S24, the process proceeds from step S24 (Figure 3) to step S31 (Figure 4).

[0147] The actions after the alarm is triggered in step S24 (Figure 3) will be explained with reference to the flowchart in Figure 4. Note that the alarm from the alarm device 25 will automatically stop, for example, after a certain period of time has elapsed.

[0148] First, in step S31, the control unit 21 determines whether or not high security settings have been enabled. If it is determined that high security settings have been enabled, the process proceeds from step S31 to step S51 (Figure 5), which will be described later. If it is determined that high security settings have not been enabled, the process proceeds from step S31 to step S32.

[0149] Then, in step S32, the control unit 21 determines whether or not a non-monitoring command has been received from the remote terminal 3 while the vehicle 1 is in a monitoring state.

[0150] When a non-monitoring command is received from the remote terminal 3, the process proceeds from step S32 to step S40, and the control unit 21 transitions the vehicle 1 from the monitored state to the non-monitoring state. At this time, if an alarm is being sounded, the control unit 21 stops the alarm from being sounded by the alarm device 25.

[0151] On the other hand, if no non-monitoring command is received from the remote terminal 3, the process proceeds from step S32 to step S33.

[0152] Then, the control unit 21 determines whether or not the authentication operation has been accepted (step S33).

[0153] If the authentication operation is accepted in step S33, the process proceeds from step S33 to step S34, and the control unit 21 determines whether or not there is a trigger D (an example of a second trigger). Trigger D indicates that the authentication operation accepted in step S33 was a legitimate second authentication operation. The control unit 21 does not determine that there was a trigger D even if a first authentication operation was performed.

[0154] For example, if a legitimate second authentication operation different from a legitimate first authentication operation is not performed, the process proceeds from step S34 to step S41, and the alarm is triggered again. On the other hand, if trigger D is present, the process proceeds from step S34 to step S40, and the control unit 21 transitions vehicle 1 from a monitored state to an unmonitored state.

[0155] On the other hand, if the authentication operation is not accepted in step S33, the process proceeds from step S33 to step S35, and the control unit 21 determines whether or not there was a trigger E (an example of a first trigger) (step S35). Trigger E indicates the same conditions as trigger B.

[0156] Then, when trigger E is detected, the process proceeds from step S35 to step S36, and the control unit 21 starts the timing process and determines whether a predetermined time has elapsed since trigger E was detected (step S36). Note that the processing contents of steps S35, S36, etc. in Figure 4 are the same as the processing contents of steps S17, S18, etc. in Figure 3, so a detailed explanation is omitted.

[0157] For example, if a predetermined time elapses without the authentication operation being accepted, the process proceeds from step S36 to step S41. Then, the control unit 21 reactivates the alarm by the alarm device 25 (step S41).

[0158] On the other hand, if the predetermined time has not yet elapsed, the process proceeds from step S36 to step S37, and the control unit 21 determines whether or not the authentication operation has been accepted.

[0159] If the authentication operation is not accepted, the process proceeds from step S37 to step S39, where the control unit 21 determines whether or not a non-monitoring command has been received from the remote terminal 3. If a non-monitoring command is received from the remote terminal 3, the process proceeds from step S39 to step S40. If no non-monitoring command has been received from the remote terminal 3, the process returns from step S39 back to step S36.

[0160] On the other hand, if the authentication operation is accepted in step S37, the process proceeds from step S37 to step S38.

[0161] For example, the user operates the first reception unit 6, then inputs authentication information using the input device 24, and then performs an authentication operation to operate the first reception unit 6 (an example of an authentication operation different from the first authentication operation). As a result, the control unit 21 accepts the authentication operations of the authentication information input operation (an example of the first input operation) and the operation on the first reception unit 6 (an example of the second input operation) (step S37). Then the process proceeds from step S37 to step S38.

[0162] In step S38, the control unit 21 determines whether or not trigger F (an example of a second trigger) occurred in step S37. Trigger F indicates that a legitimate second authentication operation was performed. Similar to trigger D, the control unit 21 does not determine that trigger F occurred even if the first authentication operation was performed.

[0163] For example, if it is determined that there is no trigger F, the process proceeds from step S38 to step S41, and the alarm is triggered again. If it is determined that there was a trigger F, the process proceeds from step S38 to step S40.

[0164] Then, the control unit 21 transitions vehicle 1 from a monitored state to a non-monitored state (step S40). Specifically, all of the multiple monitored areas of vehicle 1 are transitioned from a monitored state to a non-monitored state and maintained in this state. At this time, if an alarm is being sounded, the control unit 21 stops the alarm from being sounded by the alarm device 25.

[0165] As described above, after the alarm is activated (step S24), if trigger F is present, the control unit 21 transitions vehicle 1 from a monitored state to a non-monitored state (step S40).

[0166] In this way, even if a legitimate first authentication operation or a legitimate second authentication operation is not accepted after trigger E occurs, and vehicle 1 enters a monitored state (step S24), when the user performs a legitimate second authentication operation, the authentication system 20 determines that trigger F occurred and vehicle 1 transitions to an unmonitored state (step S40). Therefore, for example, even if a third party takes time to perform the first authentication operation, it is possible to prevent this from being treated as a legitimate authentication operation and keeping the vehicle in an unmonitored state.

[0167] Thus, after a predetermined period has elapsed since trigger B and the alarm 25 has been activated, the control unit 21 increases the number of user steps required for the legitimate authentication process. In this way, as long as the legitimate authentication process is performed by the user, the increase in the user's burden is minimized, and if there is an error in the authentication process, the possibility of mistakenly authenticating a person who is not a legitimate user as a legitimate user is reduced by increasing the number of user steps required along with the activation of the alarm. For example, after the alarm 25 has been activated, the control unit 21 requests the user to perform the second authentication process instead of the first authentication process during the authentication process.

[0168] [If high security settings are enabled] Next, we will explain the case where high security settings are enabled.

[0169] If high security settings are enabled, the process proceeds from step S12 in Figure 3 to step S51 in Figure 5.

[0170] The processing content of steps S51, S52, S54-S59, S61, and S62 in Figure 5 is largely the same as the processing content of steps S13, S14, S16-S21, S23, and S24 in Figure 3. Therefore, the explanation of steps S51, S52, S54-S59, S61, and S62 in Figure 5 will be omitted below. However, triggers G (an example of a second trigger), H (an example of a first trigger), and I (an example of a second trigger) shown in Figure 5 represent the same conditions as triggers D, E, and F, respectively. In addition, the remote terminal 3 transmits a signal having a data section different from that transmitted by the electronic key 2. The data section being different may be, for example, at least one of the following as information specific to the remote terminal 3, such as an identifier (unique ID), authentication information, or a command. Also, for example, the remote terminal 3 and the electronic key 2 may use different frequencies for wireless communication. When the authentication system 20 receives a signal from the remote terminal 30, it transitions vehicle 1 to an unmonitored state and maintains it there, regardless of whether triggers G, H, or I are present. In this way, it is possible to avoid the fraudulent authentication being mistaken for legitimate authentication by falsifying the data transmitted by the electronic key 2.

[0171] After going through steps S51, S52, S55-S57, etc., the process proceeds to step S60, where the control unit 21 determines whether a legitimate second authentication operation has been accepted. In step S60, the control unit 21 determines whether or not trigger I occurred. The processing content of step S53 is the same as that of step S60.

[0172] In detail, the user operates the first reception unit 6, then inputs authentication information using the input device 24, and then performs an authentication operation by operating the first reception unit 6, and the control unit 21 accepts the user's authentication operation (step S57). Then, the control unit 21 performs user authentication by comparing the authentication information entered using the input device 24 in step S57 with legitimate authentication information that has been registered in the control unit 21 in advance.

[0173] When the entered authentication information matches the legitimate authentication information and user authentication is successful, the control unit 21 determines in step S60 that there was a trigger I indicating that a legitimate authentication operation (for example, a legitimate second authentication operation) has been accepted. Then, the process proceeds from step S60 to step S61, and the control unit 21 transitions vehicle 1 from the monitored state to the unmonitored state.

[0174] For example, the control unit 21 maintains a specific monitoring area (e.g., a spatial area inside the vehicle 1) that had temporarily transitioned to an unmonitored state in response to trigger H, while simultaneously transitioning the remaining monitoring areas that were still in a monitored state at the time of trigger H from a monitored state to an unmonitored state and maintaining them in that state. As a result, abnormality monitoring is stopped in all of the multiple monitoring areas of the vehicle 1.

[0175] On the other hand, if user authentication fails because the entered authentication information does not match the legitimate authentication information, the control unit 21 determines in step S60 that the legitimate authentication operation (for example, the legitimate second authentication operation) was not accepted (or, for example, that there was no trigger I indicating that the legitimate authentication operation was accepted).

[0176] The process then proceeds from step S60 to step S62, and the control unit 21 activates an alarm using the alarm device 25.

[0177] As described above, in the authentication system 20 according to this embodiment, when a first trigger is received while the vehicle 1 is in a monitoring state, the control unit 21 temporarily suppresses the activation of an alarm by the alarm device 25, and when a second trigger is received indicating that a legitimate authentication operation has been accepted, it maintains the vehicle 1 in an unmonitored state.

[0178] The authentication system 20 maintains the vehicle in an unsupervised state only if a trigger (second trigger) indicating that a legitimate authentication operation has been accepted has been received, thus providing higher security than a system without this condition. For example, a technology could be conceivable in which vehicle 1 is transitioned from a supervised state to an unsupervised state by having the user perform a predetermined action without authenticating the user. However, with such a technology, if a third party knows the mechanism, that third party can perform the predetermined action and transition vehicle 1 to an unsupervised state. In this embodiment, since an authentication operation is involved, the possibility of theft or other fraudulent activity by a third party other than a legitimate user is reduced.

[0179] Furthermore, the presence of a first trigger suppresses the activation of alarms, thus preventing false alarms from being triggered when a legitimate user is performing the authentication process. For example, if a legitimate user enters vehicle 1 to perform the authentication process, and the activation of an alarm due to the detection of an abnormality inside vehicle 1 is suppressed, the possibility of a false alarm being issued despite the user being legitimate is reduced. Also, if vibrations occur inside vehicle 1 when a legitimate user enters vehicle 1, and the activation of an alarm due to the detection of an abnormality caused by vibration is suppressed, the possibility of a false alarm being issued despite the user being legitimate is reduced. Conversely, if an alarm is issued when an abnormality is detected in an area different from the area where the authentication process takes place (for example, the "remaining monitoring area" mentioned above), it is possible to suppress false alarms caused by legitimate users and deter fraud caused by third parties at the same time.

[0180] Furthermore, the period during which authentication can be performed while the alarm is suppressed is limited to a temporary period from the time of the first trigger, which can also be considered a desirable security measure.

[0181] For the reasons stated above, this embodiment makes it possible to enhance security while suppressing the activation of false alarms. Furthermore, the authentication system 20 proposes a different security technology from conventional systems, not only from the perspective of preventing theft of vehicle 1 by a third party, but also from the perspective of suppressing the activation of false alarms caused by a legitimate user, thereby preventing the occurrence of undesirable situations for that legitimate user.

[0182] [Differentiation] Although an example of an embodiment of the present invention has been described above, the present invention is not limited to the above embodiment, and various modifications are possible. For example, the following modifications may be implemented.

[0183] (1) For example, in the above embodiment, the “regular authentication operation” includes, but is not limited to, a first input operation in which regular authentication information is input to a first input means (e.g., input device 24) capable of inputting authentication information, and a second input operation performed to a second input means inherently provided in the vehicle 1.

[0184] For example, a "legitimate authentication operation" may consist only of the first input operation. Even in such a case, if legitimate authentication information is not entered, vehicle 1 will not remain in an unmonitored state but will enter a monitored state, thus achieving a high level of security.

[0185] (2) The following may also be used as "authentication information":

[0186] For example, facial recognition may be used during the authentication process, and facial image information may be used as the "authentication information" entered using the first input means. In this case, when determining whether a legitimate authentication operation has been accepted, it is preferable that facial recognition be performed by comparing the facial image information captured and entered by a camera (an example of the first input means) installed in the spatial area inside the vehicle 1 with the legitimate facial image information that has been registered in advance.

[0187] Alternatively, fingerprint authentication may be employed during the authentication process, and fingerprint information may be used as the "authentication information" entered using the first input means. In this case, when determining whether a legitimate authentication operation has been accepted, it is preferable that fingerprint authentication be performed by comparing the fingerprint information detected and entered by a fingerprint reader (an example of the first input means) installed in a spatial area inside the vehicle 1 with pre-registered legitimate fingerprint information.

[0188] Furthermore, the authentication method is not limited to these methods; various other authentication methods (e.g., voice authentication) may be employed, and multiple authentication methods may be combined. In addition, users may be able to pre-configure which of the multiple authentication methods to use for authentication.

[0189] (3) In the above embodiments, user authentication is not performed for the first trigger, but for the second trigger; however, the embodiments are not limited to this. For example, user authentication may be performed for both the first and second triggers.

[0190] In this case, it is particularly preferable that the authentication method for user authentication in the first trigger and the authentication method for user authentication in the second trigger be of different types. For example, the first trigger may be the release of the vehicle door 9 due to successful user authentication using the digital key system, and the second trigger may be the successful user authentication using the input device 24.

[0191] (4) In addition, in the above embodiments, a remote terminal 3 is provided in the vehicle system 100, but a remote terminal 3 is not necessarily provided in the vehicle system 100. However, as described above, if a remote terminal 3 is provided, the user can transition the vehicle 1 to an unsupervised state without performing an authentication operation by having the remote terminal 3 send an unsupervised command.

[0192] (5) In the above-described embodiment, the authentication system 20 temporarily suppressed the activation of the alarm while keeping the entire vehicle 1 in a monitored state when the first trigger occurred, but it is not limited to this. For example, instead, the authentication system 20 may temporarily suppress the activation of the alarm by transitioning the entire vehicle 1 from a monitored state to an unmonitored state when the first trigger occurs. In this case, the authentication system 20 maintains the vehicle 1 in an unmonitored state if a legitimate authentication operation is performed within a predetermined period from the time of the first trigger, and returns the vehicle 1 from an unmonitored state to a monitored state if it is not. In this case as well, the condition for maintaining the unmonitored state is that a legitimate authentication operation has been accepted, so it is highly secure, and the period during which an authentication operation can be received without an alarm is limited to a temporary period from the time of the first trigger, which can also be a desirable security basis. In this modified example, the entire vehicle 1 remains in an unmonitored state until a legitimate authentication operation is performed, but since it is only for a temporary period, there are few security problems.

[0193] (6) In the above embodiments, the input device 24 is given as an example of the "first input means," but the invention is not limited to this. For example, the "first input means" may be a mobile terminal such as a smartphone or a tablet computer. If the mobile terminal is a smartphone, authentication information (for example, terminal ID, user ID, password, one-time key, or telephone number, etc.) is exchanged between the communication unit 23 of the authentication system 20 and a predetermined application installed on the smartphone, and the control unit 21 may perform user authentication using the authentication information received from the application in the communication unit 23. In this way, a so-called "digital key system" using a smartphone may be used. In this way, the user can perform user authentication using their own smartphone, etc., rather than an operating member installed in the spatial area inside the vehicle 1, that is, an operating member that can be used by anyone who enters the vehicle 1, thus achieving a higher level of security.

[0194] Furthermore, it is desirable to employ a mechanism that allows authentication to be performed only when the distance between the smartphone and vehicle 1 (specifically, the communication unit 23) is relatively small. For example, as the wireless communication method between the smartphone and the communication unit 23 of the authentication system 20, a wireless communication method with a limited communication area, such as Bluetooth®, BLE (Bluetooth Low Energy), Wi-Fi communication, or near-field communication (NFC (Near Field Communication), etc.), should be adopted. In this way, user authentication is performed only when the smartphone owner is relatively close to vehicle 1, thus achieving a high level of security.

[0195] However, the system is not limited to this, and communication between the smartphone and the communication unit 23 may take place via a public network such as LTE (Long Term Evolution) or Mobile Communication. In this case, even if the smartphone owner is relatively far from the vehicle 1, the smartphone and the vehicle 1's communication unit 23 can communicate with each other to, for example, notify the smartphone owner that a first trigger has occurred. In this way, for example, even if the user is relatively far from the vehicle 1, they can use their own smartphone to confirm that there is a possibility of theft or other misconduct of the vehicle 1. As a result, for example, the user who receives the notification can immediately return to the vehicle 1, thereby preventing such misconduct from occurring.

[0196] (7) In the above embodiments, the control unit 21 performs authentication processing based on authentication information entered using input means such as the input device 24, but is not limited to this. For example, the control unit 21 itself may not perform the authentication processing, but may cause a server on the network to perform the authentication processing. In this case, for example, the communication unit 23 of the authentication system 20 may send the authentication information entered by the user to an external server and receive the authentication result from the external server, and the control unit 21 may determine whether a legitimate authentication operation has been accepted based on the authentication result.

[0197] (8) In the above-described embodiment, the authentication system 20 temporarily suppressed the activation of an alarm when a first trigger occurred, and maintained the vehicle in an unmonitored state when a second trigger occurred. Alternatively, the authentication system 20 may temporarily suppress the activation of an alarm when a second trigger occurs, and maintain the vehicle in an unmonitored state when a first trigger occurs. In this modified example, the events caused by the first trigger and the events caused by the second trigger are swapped from those in the above-described embodiment. Thus, in one aspect of the present invention, a system can be provided that includes an alarm means having a function to activate an alarm when an abnormality is detected while the vehicle is in a monitored state, and a control means that temporarily suppresses the activation of an alarm by the alarm means when a second trigger indicating that a legitimate authentication operation has been accepted while the vehicle is in a monitored state, and maintains the vehicle in an unmonitored state when a first trigger occurs. In such a system as well, since the vehicle is maintained in an unmonitored state on the condition that a second trigger indicating that a legitimate authentication operation has been accepted has occurred, the security is high. Furthermore, since the second trigger suppresses the activation of the alarm, it prevents the alarm from being triggered erroneously when a legitimate user is trying to use the vehicle. Also, since the period during which the vehicle can be kept in an unmonitored state without triggering the alarm is limited to a temporary period from the second trigger, this can also be a desirable security measure. According to this modified authentication system 20, security can be enhanced while suppressing the activation of false alarms. Such an invention has the viewpoint of preventing unauthorized acts such as theft of a vehicle by a third party, as well as the viewpoint of suppressing the activation of false alarms caused by legitimate users, thereby preventing the occurrence of undesirable situations for those legitimate users.

[0198] (9) Furthermore, the functions of the system according to the above embodiment and modified examples may be made into a program that can be executed by a computer.

[0199] In this way, by installing the program on a computer and enabling it to perform the functions of each of the above embodiments and modifications, a high level of security can be achieved.

[0200] The term "computer" is not limited to PCs (personal computers), but may also refer to electronic devices that can be operated by microcomputer control, for example.

[0201] (10) In addition, the storage medium may store a program that can be executed by a computer for the functions of the system according to the above embodiment and modified example.

[0202] In this way, by installing the program from the storage medium onto a computer and enabling the effects of each of the above embodiments and modifications to be realized, a high level of security can be achieved.

[0203] [Other extensions, etc.] The embodiments and modifications described above are illustrative, and it goes without saying that partial substitution or combination of the configurations shown in each embodiment and modification is possible. Furthermore, the components described in each embodiment and modification may be combined in any way. For example, the control unit 21 may execute one of the processes in each embodiment and modification in parallel with another process (e.g., multitasking).

[0204] Furthermore, the inventions and their components described in the means for solving the problem may be further applied to combinations of the components of each embodiment and each modification. Similar effects due to similar configurations in multiple embodiments and multiple modifications will not be mentioned sequentially for each embodiment and modification. Moreover, the present invention is not limited to the embodiments described above. For example, it will be obvious to those skilled in the art that various changes, improvements, combinations, etc., are possible. [Explanation of symbols]

[0205] 1 vehicle 2. Electronic key 3 Remote terminal 6. First Reception Area 7. Second Reception Desk 9 vehicle doors 10 Electronic Key System 11 Electronic Key ECU 12 Body ECU 20 Authentication System 21 Control Unit 22 detection units 23 Communications Department 24 Input devices 25 Alarm

Claims

1. A system that has a function to activate an alarm when an abnormality is detected while the vehicle is under monitoring, A system comprising the function of temporarily suppressing the activation of the alarm when a first trigger is received while the vehicle is in a monitoring state, and returning the vehicle to a non-monitoring state when a second trigger indicating that a legitimate authentication operation has been accepted, The system includes a function that performs different processing depending on whether a non-high-security setting is configured, where either the first or second authentication operation (out of two types of authentication operations, the first and second authentication operations) is performed and the system considers it a legitimate authentication operation, or a high-security setting that prohibits the first authentication operation from being considered a legitimate authentication operation and instead designates the second authentication operation as the legitimate authentication operation. A system characterized by the following:

2. The authentication information required in the first authentication operation is common to a part of the authentication information required in the second authentication operation. The system according to claim 1, characterized by the following:

3. The vehicle is further configured to immediately transition from a monitored state to an unmonitored state in response to the first trigger. The system according to claim 1 or 2, characterized by the above.

4. The legitimate authentication information is pre-registered and the system is configured to notify the purchaser of the information via a website or printed material exclusively for purchasers of the system. A system according to any one of claims 1 to 3, characterized by the above.

5. To temporarily suppress the activation of the alarm, The system includes a function to determine whether a predetermined time has elapsed since the first trigger, and to activate the alarm if the predetermined time has elapsed. The system includes a function that allows the user to set the predetermined time. A system according to any one of claims 1 to 4, characterized by the above.

6. The system has a function to determine whether or not the legitimate authentication operation has been accepted by combining multiple authentication methods, and a function to allow the user to set which of the multiple authentication methods to use for the authentication operation. A system according to any one of claims 1 to 5, characterized by the above.

7. If the aforementioned regular authentication operation is not accepted, the system is equipped with a function to prevent the vehicle from remaining in an unmonitored state and to release the temporary suppression of the alarm activation. A system according to any one of claims 1 to 6, characterized by the above.

8. The device is equipped with a function to perform the high-security settings using a remote terminal. A system according to any one of claims 1 to 7, characterized by the above.

9. A program characterized by causing a computer to implement the system functions described in any one of claims 1 to 8.