Management device, management method, and recording medium containing management procedures
The management device displays the communication status between the device and the server, allowing key operation changes only when communication is good. This solves the problem of change failures caused by poor communication between the new owner's device and the server, improving user convenience and operation success rate.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-25
- Publication Date
- 2026-04-03
AI Technical Summary
In a digital key system, if the new owner's device fails to communicate with the server, the key change operation will fail, reducing user convenience.
The management device communicates with the vehicle to display the communication status with the server of the candidate device, allowing change operations only when communication is good, avoiding change operations when communication is poor, and ensuring the success of change operations.
This reduces the likelihood of key-operated device changes failing, improving user convenience and operation success rate.
Smart Images

Figure CN117315817B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to a management device, a management method, and a recording medium containing management procedures. Background Technology
[0002] As cars become increasingly prevalent as a component of mobility services, the prospect of a growing number of services, primarily car sharing, is emerging. Along with this trend, there is a growing demand for wireless digital key systems that utilize smartphones as car keys, eliminating the need for physical keys.
[0003] As a technology related to wireless digital key systems, for example, there is Japanese Patent Application Publication No. 2020-33707. Japanese Patent Application Publication No. 2020-33707 discloses an electronic key system for vehicles, which includes a portable device and an in-vehicle device, and unlocks the vehicle's doors by verifying the authentication of the portable device implemented by the in-vehicle device. Summary of the Invention
[0004] The problem that the invention aims to solve
[0005] The Car Connectivity Consortium (CCC) has developed standards related to electronic key systems for vehicles. Among the standards developed by the CCC are the owner's devices, which are used by the vehicle owner.
[0006] Here, we envision a scenario where the ownership of a digital key changes due to replacement, purchase, or other reasons. In this case, for example, we would first perform the deletion of the registered owner device, and then perform the registration of a candidate for a new owner device. However, since the change operation cannot be completed if the candidate for the new owner device cannot communicate with the server, convenience would be reduced.
[0007] This disclosure reduces the likelihood of change operations failing after a change operation is performed on a device capable of key operation, thereby improving user convenience.
[0008] Methods for solving problems
[0009] The first aspect of this disclosure relates to a management device including a memory and a processor connected to the memory, wherein the processor is configured to communicate with the vehicle when receiving a change operation for a device capable of performing key operations on the vehicle, and to display candidates for such devices on a display. In the management device, the candidates are displayed on the display in such a manner that the change operation is set to be operable when communication with a server corresponding to the candidate is possible, and the change operation is set to be inoperable when communication is poor.
[0010] According to the first method, the display is set as follows: if communication is possible with the candidate server corresponding to the device, the change operation is set to be feasible; otherwise, the change operation is set to be infeasible. This reduces the likelihood of a change operation failing after the key operation is performed on a device, thereby improving user convenience.
[0011] The second approach is that, in the first approach, the processor is configured to display a candidate for a new owner device as a candidate when it receives a change operation for an owner device based on the standards of the Internet of Vehicles Consortium.
[0012] The third approach is that, in the first approach, the processor is configured such that, in the display approach, if there are multiple candidates for the device, the communication status with the server is displayed according to each candidate.
[0013] The fourth approach is that, in the third approach, the processor is configured such that, when the ignition switch of the vehicle is turned on, in the display mode, all of the candidate change operations are displayed as unenforceable.
[0014] The fifth approach is that, in the first approach, the processor is configured to, for the candidate, if it receives the change operation when it is possible to perform the change operation, but the candidate becomes unable to communicate with the server midway through the change, set the change operation to be shelved, and when communication becomes possible again, stop the shelving and restart the implementation of the change operation.
[0015] The sixth approach is that, in the first approach, the processor is configured to notify the request for the change operation and accept the option to implement the change operation, provided that the device before the change was able to communicate with the server.
[0016] The seventh aspect of this disclosure relates to a management method in which a processor performs the following operations: upon receiving a change operation for a device capable of operating a vehicle's key, it is able to communicate with the vehicle and display candidates for devices capable of operating the vehicle's key on a display screen. The candidates are displayed on the display screen in such a manner that, if communication with the server corresponding to the candidate is possible, the change operation is set to be operable; otherwise, if communication is poor, the change operation is set to be inoperable.
[0017] The eighth aspect of this disclosure relates to a non-transitory computer-readable recording medium containing a management program that causes a processor to perform the following processing: upon receiving a change operation for a device capable of operating a vehicle's key, the processor is able to communicate with the vehicle and display candidates for devices capable of operating the vehicle's key on a display screen. These candidates are displayed in such a manner that, if communication with a server corresponding to the candidate is possible, the change operation is set to be operable; otherwise, if communication is poor, the change operation is set to be inoperable.
[0018] Invention Effects
[0019] According to this disclosure, the likelihood of a change operation failing after a change operation on a device capable of key operation is reduced, thereby improving user convenience. Attached Figure Description
[0020] Figure 1 This diagram illustrates an example of the general structure of a digital key system for a vehicle according to this embodiment.
[0021] Figure 2 This diagram illustrates an example of a change of ownership device operation in a digital key system.
[0022] Figure 3 A block diagram illustrating an example of the hardware structure of a management device.
[0023] Figure 4 A block diagram illustrating an example of the functional structure of a management device.
[0024] Figure 5 This is a diagram illustrating an example of how the display corresponds to the communication status.
[0025] Figure 6 A flowchart illustrating an example of the management process of a management device. Detailed Implementation
[0026] Hereinafter, an example of an embodiment of the present invention will be described with reference to the accompanying drawings. Furthermore, in the drawings, the same or equivalent structural elements and parts are labeled with the same reference numerals. Also, the dimensions in the drawings may be exaggerated for ease of explanation and thus differ from the actual dimensions.
[0027] Figure 1 This diagram illustrates the general structure of the digital key system for a vehicle according to this embodiment. Figure 1 The digital key system shown includes an information processing terminal 10A, one or more information processing terminals 10B, a vehicle 20, and servers 30A and 30B. A management device 40 is mounted on the vehicle 20. Additionally, although omitted for ease of explanation, the digital key system may also include, as part of the structure, an information processing terminal intended for use by family members or friends of the owner of the vehicle 20, i.e., a family / friends device.
[0028] The information processing terminal 10A is a terminal that stores a key (digital key) for unlocking the vehicle 20 or enabling driving, and is the owner device (hereinafter referred to as the owner device) according to the "Digital Key" standard established by the CCC. The information processing terminal 10A can be a portable terminal such as a smartphone or wearable device. The information processing terminal 10A communicates with the vehicle 20 using short-range wireless communication technologies such as BLE (Bluetooth Low Energy), NFC (Near Field Communication), and UWB (Ultra Wide Band). The information processing terminal 10A can perform key operations on the vehicle 20 through these communications.
[0029] Information processing terminal 10B is a terminal capable of being changed to an owner device, and is a candidate terminal to become an owner device (hereinafter, information processing terminal 10B may sometimes be referred to simply as "candidate"). Information processing terminal 10B can be a portable terminal such as a smartphone or wearable device.
[0030] Information processing terminals 10A and 10B can be used as digital keys for vehicle 20, for example, by downloading and installing an application for functioning as a digital key for vehicle 20 and sharing information related to the digital key with vehicle 20.
[0031] Vehicle 20 performs short-range wireless communication with information processing terminal 10A, which functions as a digital key for vehicle 20, using the various short-range wireless communication technologies described above, and executes processing related to the digital key. Vehicle 20 performs locking and unlocking processes for its doors as part of the digital key-related processing. Furthermore, vehicle 20 performs processing to start the engine or electric motor based on a start request from information processing terminal 10A, which functions as the digital key for vehicle 20.
[0032] Furthermore, when vehicle 20 receives an engine start request from information processing terminal 10A, it determines whether information processing terminal 10A is inside the passenger compartment of vehicle 20. The reason for determining whether information processing terminal 10A is inside the passenger compartment is to prevent engine start-up when information processing terminal 10A is outside the passenger compartment. Vehicle 20 determines whether information processing terminal 10A is inside the passenger compartment by referring to the strength of the radio waves emitted from information processing terminal 10A and received by an antenna installed inside the passenger compartment.
[0033] Server 30A is a server that provides information to information processing terminal 10A for enabling information processing terminal 10A to function as a digital key for vehicle 20. Server 30A provides information processing terminal 10A with digital key application programs and information related to digital keys, etc., based on requests from information processing terminal 10A, as information for enabling it to function as a digital key for vehicle 20.
[0034] Server 30A can be configured according to the manufacturer of each information processing terminal 10A. If the information processing terminals 10A are from the same manufacturer, the same server can also provide the information that functions as a digital key.
[0035] Server 30B is a server that works in conjunction with server 30A to provide information to information processing terminal 10A and vehicle 20, enabling information processing terminal 10A to function as a digital key for vehicle 20. Server 30B can be configured according to the manufacturer of each vehicle 20. Server 30B provides information related to the digital key to vehicle 20, either in a manner based on requests from information processing terminal 10A and vehicle 20, or in a manner that provides such information even without requests from information processing terminal 10A and vehicle 20, as information for enabling it to function as a digital key for vehicle 20.
[0036] Furthermore, the management device 40 receives a request for a change of ownership from the owner. This change of ownership refers to a change of ownership device based on the CCC's "Digital Key" standard. The management device 40 sends this request to servers 30A and 30B. Upon receiving the change request, servers 30A and 30B communicate with the information processing terminal 10B, which is a candidate for ownership device. The management device 40 displays the information processing terminal 10B as a candidate based on the communication status between the information processing terminal 10B and server 30A. The display method will be described later. The management device 40 displays the information processing terminal 10B as a candidate for ownership device and accepts the selection of the information processing terminal 10B to become the ownership device. Server 30B changes the selected information processing terminal 10B to the information processing terminal 10A as the ownership device.
[0037] Figure 2 This diagram illustrates an example of a change of ownership device operation in a digital key system. The previously owner information processing terminal is designated as information processing terminal 10A1, and the new owner information processing terminal is designated as information processing terminal 10A2. Information processing terminal 10A2 is selected from information processing terminals 10B. Through the change operation, a new digital key for becoming the owner device is issued in server 30B and sent from server 30B to information processing terminal 10A2. Information processing terminal 10A2 becomes the owner device by receiving the digital key and performing the necessary authentication processing in the CCC's "Digital Key" standard. A process to de-ownerize information processing terminal 10A1 is then performed. In this process, a digital key cancellation signal is sent from server 30B (or server 30A) to information processing terminal 10A1. Upon receiving the cancellation signal, information processing terminal 10A1 cancels the digital key, thus becoming a non-owner device. The change operation is thus completed.
[0038] The management device 40 is a device for managing the change operations from the information processing terminal 10B to the owner device. The functional structure of the management device 40 will be described later.
[0039] Next, the hardware structure of the management device 40 will be described. Figure 3 This is a block diagram illustrating the hardware structure of the management device 40.
[0040] like Figure 3As shown, the management device 40 includes a CPU (Central Processing Unit) 11, which is an example of a hardware processor; a ROM (Read Only Memory) 12, a RAM (Random Access Memory) 13, which is an example of a memory; a storage unit 14; an input unit 15; a display unit 16; and a communication interface (I / F) 17. All these components are connected together via a bus 19 in a manner that enables them to communicate with each other.
[0041] CPU 11 is a central processing unit that executes various programs or controls various components. Specifically, CPU 11 loads programs from ROM 12 or memory 14 and executes the programs using RAM 13 as its working area. CPU 11 performs control of the aforementioned structures and various arithmetic operations based on the programs recorded in ROM 12 or memory 14. In this embodiment, the ROM 12 or memory 14 stores a computer program for performing management operations.
[0042] ROM 12 stores various programs and data. RAM 13 serves as a working area to store temporary programs or data. Storage 14, which is a non-temporary recording medium, is composed of storage devices such as HDD (Hard Disk Drive), SSD (Solid State Drive), or flash memory, and stores various programs, including the operating system, and various data.
[0043] The input unit 15 includes a keyboard or buttons such as a touch panel, and is used to perform various inputs.
[0044] The display unit 16 is, for example, a liquid crystal display (LCD) that displays various information. The display unit 16 may also be a touch panel, thus functioning as an input unit 15.
[0045] Communication interface 17 is an interface for communicating with other devices such as information processing terminal 10A, server 30A, and server 30B. For example, it can use standards such as Ethernet (registered trademark), FDDI, Wi-Fi (registered trademark), BLE, NFC, and UWB.
[0046] Furthermore, the information processing terminals 10A and 10B can be configured with the same hardware structure as the management device 40. The information processing terminal 10A, which serves as the owner's device, stores the program related to the digital key of the vehicle 20.
[0047] When executing the aforementioned computer program, the management device 40 uses the aforementioned hardware resources to implement various functions. The functional structure implemented by the management device 40 will be described below.
[0048] Figure 4 A block diagram illustrating an example of the functional structure of the management device 40. (e.g.) Figure 4 As shown, the management device 40 has a change control unit 200 and a display control unit 202 as functional structures. Each functional structure is implemented by the CPU 11 reading and executing a computer program stored in the ROM 12 or memory 14. Alternatively, the server 30A or server 30B can also be configured to function as the change control unit 200.
[0049] The change control unit 200 receives a request for a change operation of the owner device from the input unit 15 and sends the change request to servers 30A and 30B. When servers 30A and 30B receive the change request, they communicate with the information processing terminal 10B, which is a candidate for owner device.
[0050] Furthermore, if the change control unit 200 receives a change operation for a candidate owner's device when the change operation is possible, and the candidate becomes unable to communicate with the server midway through the change process, the change control unit 200 will put the change operation on hold. If the candidate becomes capable of communication again, the change control unit 200 will stop the hold and restart the change operation.
[0051] The display control unit 202 can communicate with the management device 40 of the vehicle 20 and cause the display unit 16 to display the information processing terminal 10B as a candidate owner device. The display control unit 202 displays the candidate in a display mode corresponding to the communication status between the information processing terminal 10B and the server 30A. Specifically, the display control unit 202 sets the change operation to be feasible when communication is possible, and sets the change operation to be infeasible when communication is poor. An example of a server corresponding to the candidate is server 30A. Furthermore, the display control implemented by the display control unit 202 is not limited to displaying to the display unit 16 of the management device 40; it can also be used to display the candidate on the display unit of a device other than the management device 40.
[0052] Figure 5 This diagram illustrates an example of how displays correspond to communication status. Figure 5In the example, the information processing terminal 10B capable of communicating with the management device 40 of vehicle 20 includes information processing terminal 10B1 (B1), information processing terminal 10B2 (B2), and information processing terminal 10B3 (B3). B1 to B3 are terminal names. The display control unit 202 displays antennas indicating the communication strength of each terminal as identification information (RW) of the communication status with server 30A. The communication strength can be determined by, for example, the degree of communication delay detected by server 30A. In the example, having two or more antennas indicates communication capability, and having one or fewer antennas indicates poor communication. Alternatively, the structure of setting the identification information as antennas is one example; it could also be a description of the communication status or other icons indicating communication strength. B1's communication status is indicated by three antennas, signifying communication capability; B2's communication status is indicated by two antennas, signifying communication capability; and B3's communication status is indicated by one antenna, signifying poor communication. In this case, since B1 and B2 are able to communicate, the display control unit 202 displays the "Change to Owner Device" button (Ta) which allows selection, and since B3 is not communicating, the display control unit 202 displays the "Cannot Change" icon (Tw).
[0053] In addition, the above Figure 5 The display mode is set to the state where the ignition switch of vehicle 20 is off. When the ignition switch of vehicle 20 is on, the display control unit 202 sets all candidate change operations to an unfeasible state in the display mode of the information processing terminal 10B, that is, displays the "Cannot be changed" icon (Tw). In addition, the status of the ignition switch of vehicle 20 can be obtained from the ECU (Electronic Control Unit) of vehicle 20 (not shown). As a result, it is possible to prevent changes to the owner's equipment when the vehicle 20 is in a state where driving is possible.
[0054] Alternatively, the change control unit 200, when the information processing terminal 10A (which was the owner device before the change) can communicate with the server 30A, can notify the information processing terminal 10A of a change operation request and accept the option to allow or deny the change operation. The notification of the change operation request is sent to the information processing terminal 10A when the "Change to Owner Device" button (Ta) is selected or when the change operation request is sent. In the information processing terminal 10A, for example, while displaying information indicating "Allow change of owner device?", it allows the user to select "Allow" or "Deny". If the change operation request is allowed, the change control unit 200 sets the change operation to be allowed; if the change operation request is denied, it does not allow the change operation. If the change operation request is denied, the display control unit 202 displays, for example, "Change on the current owner device is denied," and sets the display to indicate that the change operation is not accepted.
[0055] (Control process)
[0056] use Figure 6 The flowchart below will be used to explain the management process of this embodiment. When the CPU 11 of the management device 40 receives a request for a change operation of the owner device from the input unit 15, it executes the following processes. This is the timing for receiving the change operation of the owner device. In addition, although the execution of each process by the CPU 11 is described, it is not limited to this. The following process can also be implemented by reading and executing programs stored in more than one memory using more than one processor.
[0057] In step S10, CPU11 sends a change request for the owner device to servers 30A and 30B.
[0058] In step S12, the CPU 11 acquires an information processing terminal 10B (hereinafter referred to as a candidate) that is a candidate to become the owner device. The candidate is a terminal that can communicate with the management device 40 mounted on the vehicle 20.
[0059] In step S14, CPU11 obtains the communication status between the acquired candidate and server 30A.
[0060] In step S16, CPU 11 determines whether the ignition switch of vehicle 20 is on. If the ignition switch is on, proceed to step S18; if the ignition switch is off, proceed to step S20. Alternatively, this step can be performed before step S12. In this case, if the ignition switch is on, steps S12 and S14 can be skipped.
[0061] In step S18, CPU11 determines that all candidate change operations cannot be implemented based on the candidate display methods.
[0062] In step S20, the CPU 11 determines a display mode corresponding to the communication status between the information processing terminal 10B and the server 30A for each candidate. The display mode for the candidate is such that if the candidate's communication status is that communication is possible, the change operation is set to be able to be implemented; and if the candidate's communication status is that communication is poor, the change operation is set to be unable to be implemented.
[0063] In step S22, the CPU11 causes the display unit 16 to display each candidate according to the determined display method.
[0064] In step S24, CPU11 accepts the selection of the terminal from the candidates to be changed to the owner device, completes the change operation, and ends the processing.
[0065] According to the management device 40 of this embodiment, the possibility of the change operation of the owner's equipment failing is reduced, thereby improving the convenience for users.
[0066] Alternatively, when the display control unit 202 receives a change operation for an owner device based on the CCC (CarConnectivity Consortium) "Digital Key" standard, it can display a candidate for the new owner device. This allows for the display of candidates based on communication conditions during change operations according to this standard.
[0067] Alternatively, when there are multiple candidate devices, the display control unit 202 can display the communication status with the server for each candidate in the display mode. This allows the user to monitor the communication status, thereby improving user convenience.
[0068] Alternatively, the change control unit 200 can accept a change request when it is possible to perform the change operation on a candidate. If, during the change process, the candidate becomes unable to communicate with the server 30A, the change operation is suspended. When communication becomes possible again, the suspension is stopped and the change operation is restarted. Therefore, since the change operation can be restarted even if communication becomes unavailable midway through, the user does not need to start the change operation request from the beginning, thus improving user convenience.
[0069] Alternatively, the change control unit 200 can notify the request for the change operation and accept the option to proceed if the information processing terminal 10, which is the owner device before the change, can communicate with the server 30A. This ensures that the change operation is performed only after obtaining permission from the current owner device, thus preventing the owner device from being mistakenly changed.
[0070] Furthermore, the management processing executed by the CPU reading the software (program) in the above embodiments can also be executed by various processors other than the CPU. Examples of processors in this case include FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices) whose circuit structure can be changed after manufacturing, and ASICs (Application Specific Integrated Circuits), which are dedicated circuits with circuit structures specifically designed for executing specific processes. Moreover, management processing can be executed using only one of these various processors, or it can be executed using a combination of two or more processors of the same or different types (e.g., multiple FPGAs, and a combination of a CPU and an FPGA). Furthermore, the hardware structure of these various processors is more specifically a circuit composed of circuit elements such as semiconductor components.
[0071] Furthermore, although the above embodiments describe the management processing program being pre-stored (installed) in ROM or memory, this is not a limitation. The program may also be provided in the form of a non-transitory recording medium such as a CD-ROM (Compact Disc Read Only Memory), DVD-ROM (Digital Versatile Disc Read Only Memory), or USB (Universal Serial Bus) memory. Additionally, the program may be configured to be downloaded from an external device via a network.
Claims
1. A management device comprising a memory and a processor connected to the memory, wherein, The processor is configured such that, When a change request is received regarding a device capable of operating the vehicle's key, the system can communicate with the vehicle and display candidate devices capable of operating the vehicle's key on the display screen. The candidate is displayed on the monitor in such a manner that, if communication with the server corresponding to the candidate is possible, the change operation is set to be executable; otherwise, if communication is poor, the change operation is set to be infeasible. When there are multiple candidates for the device, in the display mode, the communication status with the server is displayed according to each candidate. When the ignition switch of the vehicle is turned on, in the display mode, all of the candidate change operations are displayed as unfeasible.
2. The management device as described in claim 1, wherein, The processor is configured to display a candidate for a new owner device as a candidate when it receives a change operation for an owner device based on the standards of the Internet of Vehicles Consortium.
3. The management device as described in claim 1, wherein, The processor is configured to, for the candidate, if it receives the change operation when it is possible to perform the change operation, but the candidate becomes unable to communicate with the server midway through the change, set the change operation to be shelved, and stop the shelving and restart the change operation when communication becomes possible again.
4. The management device as claimed in claim 1, wherein, The processor is configured to, when the device prior to the change is able to communicate with the server, notify the request for the change operation and accept the option to implement the change operation.
5. A management method, wherein, The processor performs the following processing: When a change request is received regarding a device capable of operating the vehicle's key, the system can communicate with the vehicle and display candidate devices capable of operating the vehicle's key on the display screen. The candidate is displayed on the monitor in such a manner that, if communication with the server corresponding to the candidate is possible, the change operation is set to be executable; otherwise, if communication is poor, the change operation is set to be infeasible. When there are multiple candidates for the device, in the display mode, the communication status with the server is displayed according to each candidate. When the ignition switch of the vehicle is turned on, in the display mode, all of the candidate change operations are displayed as unfeasible.
6. A non-transitory computer-readable recording medium containing a management program, wherein, The management program causes the processor to perform the following processes: When a change request is received regarding a device capable of operating the vehicle's key, the system can communicate with the vehicle and display candidate devices capable of operating the vehicle's key on the display screen. The candidate is displayed on the monitor in such a manner that, if communication with the server corresponding to the candidate is possible, the change operation is set to be executable; otherwise, if communication is poor, the change operation is set to be infeasible. When there are multiple candidates for the device, in the display mode, the communication status with the server is displayed according to each candidate. When the ignition switch of the vehicle is turned on, in the display mode, all of the candidate change operations are displayed as unfeasible.
Citation Information
Patent Citations
Electronic key system, authentication device and portable device
JP2020033707A
Data updating system, master terminal, slave terminal, server, data updating method, program, and recording medium
JP2006274574A
Electronic key system, and lock-side terminal and portable terminal employed in same
US20140232524A1