Vehicle control system and control method thereof

By controlling vehicle locking and unlocking through portable devices and camera authentication and adjusting response strategies based on communication status, it resolves convenience and safety issues caused by vehicle program update failures and ensures that passengers can unlock the vehicle and drive when necessary.

CN120716635APending Publication Date: 2025-09-30HONDA MOTOR CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510148535.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-03-27
Filing Date
2025-02-11
Publication Date
2025-09-30

AI Technical Summary

Technical Problem

During the vehicle program update process, if the passenger does not have an electronic key or other device to unlock the vehicle, the program update will fail and the vehicle cannot be unlocked, and the passenger will be unable to board the vehicle, affecting convenience and safety.

Method used

Through wireless communication between the portable device and the vehicle and camera image authentication, the locking and unlocking of the vehicle is controlled. In the event of a program update failure, different response measures are taken according to the communication status, such as notifying the target, unlocking the doors, or disabling the driving source, ensuring the convenience and safety of the passengers.

Benefits of technology

Improves the convenience and safety of passengers when a program update fails, ensuring that the vehicle can be unlocked and driven when necessary, avoiding the inconvenience and safety risks caused by program update failures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120716635A_ABST
    Figure CN120716635A_ABST
Patent Text Reader

Abstract

The invention provides a vehicle control system and a control method thereof, which can improve the convenience of passengers by changing the response when the program update of a vehicle fails according to the communication state between a portable device and the vehicle. A vehicle control system (1) is provided with: a key authentication ECU (50); an image authentication ECU (60); and a central ECU (10) that executes a first operation when an update process for updating a program executed by the image authentication ECU (60) fails and when communication between the key authentication ECU (50) and the portable device (5) is communicable, and executes a second operation different from the first operation when the update process fails and when communication between the key authentication ECU (50) and the portable device (5) is non-communicable.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a vehicle control system and a control method thereof. Background Art

[0002] Conventionally, a program rewriting system for updating a program of a computer mounted on a vehicle has been proposed (for example, see Patent Document 1).

[0003] [Prior art literature]

[0004] [Patent Document]

[0005] Patent Document 1: Japanese Patent Application Laid-Open No. 2006-082648 Summary of the Invention

[0006] [Problems to be Solved by the Invention]

[0007] In recent years, vehicles have been equipped with multiple devices that lock and unlock the vehicle's locking mechanism. However, if a passenger does not have a device such as an electronic key to unlock the vehicle, and the electronic control device that authenticates the passenger undergoes a program update, the vehicle may not be unlocked, preventing the passenger from boarding or moving the vehicle until the program update is complete.

[0008] To address the aforementioned issues, the present application aims to modify the vehicle's response to a program update failure based on the communication status between the portable device and the vehicle, thereby improving passenger convenience and safety. Furthermore, this application contributes to the development of a sustainable transportation system that further improves traffic safety.

[0009] [Means for solving the problem]

[0010] As a first method for achieving the above-mentioned purpose, a vehicle control system can be cited, which comprises: a first control device, which obtains first authentication information through wireless communication with a portable device, and controls locking and unlocking of the vehicle according to the first authentication information obtained; a second control device, which obtains second authentication information based on an image captured by a camera, and controls locking and unlocking of the vehicle according to the second authentication information obtained; and an update management device, which, when an update process for updating a program executed by the second control device fails, and when communication between the first control device and the portable device is communicable, performs a first action; and when the update process fails, and when communication between the first control device and the portable device is not communicable, performs a second action different from the first action.

[0011] In the above-mentioned vehicle control system, it can also be constructed so that, when the update processing fails and the communication between the first control device and the portable device is communicable, the update management device notifies a pre-set first notification target as the first action; and when the update processing fails and the communication between the first control device and the portable device is not communicable, the update management device notifies a pre-set second notification target different from the first notification target as the second action.

[0012] In the above-mentioned vehicle control system, it can also be configured that when the update processing fails and the communication between the first control device and the portable device is communicable, the update management device uses the registered address of the owner of the portable device or the vehicle as the first notification target and sends the failure notification of the update processing to the first notification target.

[0013] In the vehicle control system, the update management device may transmit the failure notification including guidance indicating that at least one of unlocking the vehicle and starting a driving source mounted on the vehicle by the portable device is required.

[0014] In the above-mentioned vehicle control system, it can also be configured that, when the update processing fails and the communication between the first control device and the portable device is not communicable, the update management device uses the address of the user registered corresponding to at least one of the loading service provider company and the owner of the vehicle as the second notification target, and sends the failure notification of the update processing to the second notification target.

[0015] In the above-mentioned vehicle control system, the update management device may be configured to transmit the failure notification including position information indicating the position of the vehicle.

[0016] In the above-mentioned vehicle control system, it can also be configured that the vehicle control system has a locking mechanism for locking the vehicle doors, and the update management device instructs the locking mechanism to release the lock when the update process fails and the communication between the first control device and the portable device is not communicable.

[0017] In the above-mentioned vehicle control system, it can also be configured that the vehicle control system has a wireless communication unit and an acceptance device for accepting operations, and when the update processing fails, the update management device wirelessly connects to the object selected through the operation accepted by the acceptance device via the wireless communication unit.

[0018] In the above-mentioned vehicle control system, it can also be constructed that the vehicle control system has a drive source control device that controls the drive source mounted on the vehicle, and when the update management device instructs the locking mechanism to release the lock, it sends an instruction to the drive source control device to prohibit the driving of the drive source.

[0019] In the vehicle control system described above, the vehicle control system may include an accepting device for accepting an operation, and the update management device may accept settings of the first action and the second action through the accepting device.

[0020] As a second method for achieving the above-mentioned purpose, a control method for a vehicle control system can be cited, wherein the vehicle control system comprises: a first control device, which obtains first authentication information through wireless communication with a portable device, and controls locking and unlocking of the vehicle according to the first authentication information obtained; a second control device, which obtains second authentication information based on an image captured by a camera, and controls locking and unlocking of the vehicle according to the second authentication information obtained; and an update management device, which manages the update of programs executed by the first control device and the second control device, wherein the control method includes the following processing: when the update processing of the program executed by the second control device fails, when the communication between the first control device and the portable device is not communicable, the processor mounted on the update management device executes a first action; when the update processing fails, when the communication between the first control device and the portable device is communicable, the processor mounted on the update management device executes a second action different from the first action.

[0021] [Effects of the Invention]

[0022] According to the vehicle control system and control method thereof, the response to a vehicle program update failure is changed according to the communication status between the portable device and the vehicle, thereby improving the convenience of the occupants. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 : is a system configuration diagram showing the configuration of a vehicle control system.

[0024] Figure 2 It is a block diagram showing the structure of the central ECU.

[0025] Figure 3 This is a diagram showing an example of a permission request screen.

[0026] Figure 4 This is a flowchart showing the operation of the central ECU according to the first embodiment.

[0027] Figure 5It is a diagram showing an example of the first setting screen.

[0028] Figure 6 It is a diagram showing an example of the second setting screen.

[0029] Figure 7 This is a flowchart showing the operation of the central ECU according to the second embodiment.

[0030] Figure 8 : is a diagram showing an example of a contact destination table.

[0031] Figure 9 This is a flowchart showing the operation of the central ECU according to the third embodiment.

[0032] Figure 10 This is a flowchart showing the operation of the central ECU according to the third embodiment. DETAILED DESCRIPTION

[0033] [1. Configuration of Vehicle Control System of First Embodiment]

[0034] Figure 1 This is a system configuration diagram showing the structure of a vehicle control system 1 installed in a vehicle 3. Vehicle control system 1 is configured such that a central ECU (Electronic Control Unit) 10, an electronic control device functioning as a central gateway, is connected to the electronic control device targeted for program updates so that data can be communicated with each other. Central ECU 10 functions as an update management device.

[0035] Connected to the central ECU 10 is a TCU (Telematics Control Unit) 14, a wireless device compliant with the communication standards of a mobile communication system. The central ECU 10 utilizes the TCU 14 to perform OTA (Over The Air) management. OTA management includes downloading update programs for the electronic control devices in the vehicle 3 from a server device 300 via a network 350 and applying the downloaded update programs to the electronic control devices.

[0036] The central ECU 10 is connected to a plurality of communication lines including the first communication lines 3a, 3b and the second communication lines 4a, 4b, and implements a gateway function for managing the exchange of communication data between these communication lines.

[0037] The first communication lines 3a, 3b and the second communication lines 4a, 4b are composed of buses that perform communication based on standards such as CAN and Ethernet (registered trademark), or communication lines that perform P2P (peer to peer) communication. The first communication lines 3a, 3b can be composed of multiple communication lines that perform communication based on the same standard, or they can be composed of multiple communication lines that perform communication based on different standards. The same applies to the second communication lines 4a, 4b.

[0038] An ICB (Infotainment Control Box) 11, a speaker 12, and a microphone 13 are connected to the first communication line 3a via an in-vehicle connection link 19. Furthermore, a TCU (Telematics Control Unit) 14, a GNSS (Global Navigation Satellite System) sensor 15, and a touch panel 16 are connected to the in-vehicle connection link 19. Touch panel 16 includes a display 17 and a touch sensor 18. Touch panel 16 corresponds to an in-vehicle display device.

[0039] The in-vehicle connection link 19 is composed of multiple communication transmission paths based on various communication standards. The in-vehicle connection link 19 may also include, for example, multiple communication networks. In this case, multiple communication networks may also be interconnected via a device with a gateway function. In addition, the in-vehicle connection link 19 may also include a communication network for P2P communication. In the communication network, various communication buses for network communication based on various standards can be used. Examples of such standards include CAN, Ethernet, USB (Universal Serial Bus), LIN (Local Interconnect Network), and LVDS (Low Voltage Differential Signaling), but other standards may also be used.

[0040] The ICB 11 is an IVI (In-Vehicle Infotainment) ECU and provides various information and entertainment to vehicle passengers using a speaker 12 , a microphone 13 , a GNSS sensor 15 , a touch panel 16 , and the like.

[0041] A DMC (Driver Monitoring Camera) 20 that monitors the driver is connected to the first communication line 3 b.

[0042] The second communication line 4a is connected to the area A-ECU 30. The area A-ECU 30 is connected to a drive device 31 and a battery 33. The drive device 31 is, for example, a motor or an internal combustion engine that drives the vehicle 3. The area A-ECU 30 corresponds to a drive source control device.

[0043] The second communication line 4b is connected to the area B-ECU 40. The area B-ECU 40 is connected to a lamp 41, a window motor 43, a door sensor 45, a door lock mechanism 47, and a weight sensor 49.

[0044] The lamp body 41 includes, for example, headlights, taillights, and turn signals. The window motor 43 opens and closes the window. The door sensor 45 detects the operation of the door. The door lock mechanism 47 performs locking and unlocking of the doors of the vehicle 3. The weight sensor 49 is arranged on the seat where the occupant sits, and detects the weight applied to the seat. The weight sensor 49 outputs sensor data indicating the weight applied to the seat to the area B-ECU 40. In this embodiment, an example of providing the weight sensor 49 is described, but it is also possible to detect the seating or non-seating (leaving) of a person based on the detection results of a pressure sensor, a human sensor, etc. instead of the weight sensor 49. The area B-ECU 40 outputs the sensor data input from the weight sensor 49 to the central ECU 10.

[0045] The key authentication ECU 50 and the image authentication ECU 60 are connected to the area B-ECU 40. The key authentication ECU 50 serves as the first control unit. The image authentication ECU 60 serves as the second control unit. The key authentication ECU 50 is connected to an LF / RF antenna 55 for wireless communication with the portable device 5. The portable device 5 is an electronic device with wireless communication capabilities and is known as a smart key or FOB key. Alternatively, the portable device 5 may be a smartphone used as a digital key.

[0046] The key authentication ECU 50 is an electronic control unit comprising a first memory 51 and a first processor 53. The first memory 51 is comprised of, for example, a nonvolatile semiconductor memory, or a combination of volatile and nonvolatile semiconductor memory. The first processor 53 is an arithmetic processing unit comprised of a CPU (Central Processing Unit) and an MPU (Micro Processor Unit). The first processor 53 may be a single processor or a plurality of processors.

[0047] The first memory 51 stores a first program as a control program executed by the first processor 53 and a key ID. The key ID is an ID for the vehicle control system 1 to identify the portable device 5, and a different value is assigned to each portable device 5.

[0048] The first processor 53 executes a first program to perform authentication processing. Upon receiving the key ID of the portable device 5 via the LF / RF antenna 55, the first processor 53 determines whether the received key ID matches the key ID stored in the first memory 51. The key ID corresponds to the first authentication information. If the received key ID matches the key ID stored in the first memory 51, the first processor 53 instructs the area B-ECU 40 to unlock or lock the door locks. Based on the instruction from the key authentication ECU 50, the area B-ECU 40 instructs the door lock mechanism 47 to unlock or lock the door locks. Furthermore, the key authentication ECU 50 outputs information indicating the communication status between the portable device 5 and the LF / RF antenna 55 to the area B-ECU 40. The area B-ECU 40 then outputs the communication status information received from the key authentication ECU 50 to the central ECU 10.

[0049] The image authentication ECU 60 is connected to a camera 65. The camera 65 is a digital camera, and is installed in the vehicle 3 so as to be able to capture the face of a passenger outside the vehicle on the driver's side. The camera 65 is, for example, located on the driver's side B-pillar, the roof edge, or a side mirror.

[0050] The image authentication ECU 60 is an electronic control unit including a second memory 61 and a second processor 63. The second memory 61 is composed of, for example, a nonvolatile semiconductor memory or a volatile and nonvolatile semiconductor memory. The second processor 63 is an arithmetic processing unit composed of a CPU or an MPU.

[0051] The second memory 61 stores a second program and feature data, which are control programs executed by the second processor 63. The feature data is data representing features of the passenger's face and is extracted from a captured image of the passenger's face.

[0052] The image authentication ECU 60 activates the camera 65 and acquires an image captured by the camera 65. The image authentication ECU 60 extracts facial features from the image captured by the camera 65 and authenticates the user based on the comparison of these features with the features stored in the second memory 61. The facial features correspond to the second authentication information. If the features match, the image authentication ECU 60 instructs the region B-ECU 40 to unlock the doors. The region B-ECU 40, in accordance with the instruction from the image authentication ECU 60, instructs the door lock mechanism 47 to unlock the doors.

[0053] Figure 2 2 is a block diagram showing the configuration of the central ECU 10 .

[0054] Will refer to Figure 2The configuration of the central ECU 10 is described.

[0055] The central ECU 10 is an electronic control unit that includes a third memory 110 and a third processor 130. The third memory 110 is composed of, for example, a nonvolatile semiconductor memory, or a combination of volatile and nonvolatile semiconductor memories. The third memory 110 stores a third program 111 and map data 113, which are executed by the third processor 130. Furthermore, the third memory 110 serves as a calculation area for the third processor 130.

[0056] The third processor 130 is an arithmetic processing device composed of a CPU or an MPU. The third processor 130 may be composed of a single processor or a plurality of processors.

[0057] The central ECU 10 includes an information acquisition unit 131, a vehicle exit detection unit 133, a program update unit 135, and a determination unit 137 as functional components. These functional components are functions obtained by the third processor 130 executing the third program 111 and performing calculations.

[0058] The information acquisition unit 131 acquires information from the key authentication ECU 50 and the area B-ECU 40. For example, the information acquisition unit 131 acquires information indicating the communication status with the portable device 5 from the key authentication ECU 50. The information acquisition unit 131 also acquires information indicating the status of the door locks and sensor data from the weight sensor 49 from the area B-ECU 40.

[0059] The vehicle exit detection unit 133 detects the passenger's exit from the vehicle. The vehicle exit detection unit 133 detects the passenger's exit based on sensor data from the weight sensor 49. The vehicle exit detection unit 133 may also determine that the passenger has exited the vehicle based on the communication status between the key authentication ECU 50 and the portable device 5. For example, the vehicle exit detection unit 133 may determine that the passenger has exited the vehicle 3 if the communication status between the key authentication ECU 50 and the portable device 5 changes from a communicable state to a non-communicable state.

[0060] When an update is required for a program executed by an electronic control unit mounted on vehicle 3, program update unit 135 downloads the updated program from server device 300. Program update unit 135 temporarily stores the obtained updated program in third memory 110. At a predetermined timing, program update unit 135 causes the target electronic control unit to update the downloaded program.

[0061] If the downloaded update program updates the second program executed by the image authentication ECU 60 and the determination unit 137 determines that program update is permitted, the program update unit 135 causes the image authentication ECU 60 to update the second program executed by the image authentication ECU 60 to the updated program.

[0062] When the update program downloaded by the program update unit 135 is a program for updating the second program, the determination unit 137 determines whether to permit the image authentication ECU 60 to update to the updated program based on the communication status between the key authentication ECU 50 and the portable device 5 .

[0063] When the key authentication ECU 50 and the portable device 5 are in a state in which communication is possible, the determination unit 137 permits the image authentication ECU 60 to update the program.

[0064] For example, if the key authentication ECU 50 and the portable device 5 are in a communicable state, the image authentication ECU 60 program update permission operation is accepted, and it is detected that the portable device 5 is taken outside the vehicle, the determination unit 137 permits the program update unit 135 to update the second program of the image authentication ECU 60.

[0065] In addition, even if the key authentication ECU 50 and the portable device 5 are in a state where communication is possible, but the permission operation for permitting the image authentication ECU 60 to update the program has not been received, when it is detected that the portable device 5 has been taken out of the vehicle, the determination unit 137 may allow the program update unit 135 to update the second program of the image authentication ECU 60.

[0066] Regarding the portable device 5 being taken out of the vehicle, for example, when the communication state between the key authentication ECU 50 and the portable device 5 changes from a communicable state to a non-communicable state, and the vehicle exit detection unit 133 determines that the passenger has been detected exiting the vehicle, the determination unit 137 determines that the portable device 5 has been taken out of the vehicle.

[0067] Figure 3 1 shows an example of a permission request screen 150 that the central ECU 10 displays on the touch panel 16 when the second program is updated. The permission request screen 150 corresponds to an example of a guidance screen.

[0068] The permission request screen 150 displays a message indicating that the second program executed by the image authentication ECU 60 is to be updated, and a message inquiring whether to permit the program update of the image authentication ECU 60. Furthermore, the permission request screen 150 displays a message requesting that the portable device 5 be taken out of the vehicle if the program update of the image authentication ECU 60 is permitted and the vehicle is moved outside the vehicle.

[0069] In addition, a radio button 151 for permitting program update, a radio button 153 for rejecting program update, and a decision button 155 are displayed on the permission request screen 150 .

[0070] When the passenger approves the program update, the passenger selects the radio button 151 and presses the decision button 155. When the passenger rejects the program update, the passenger selects the radio button 153 and presses the decision button 155.

[0071] Next, a case will be described where the determination unit 137 accepts a permission operation for permitting program update on the permission request screen 150 , but the passenger gets out of the vehicle while leaving the mobile device 5 in the vehicle.

[0072] When the determination unit 137 determines that the portable device 5 remains inside the vehicle despite the vehicle exit detection unit 133 detecting that the occupant has exited the vehicle, it obtains latitude and longitude information indicating the location of the vehicle 3 from the GNSS sensor 15. Based on the obtained latitude and longitude information, the determination unit 137 references the map data 113 and obtains facility information for the facility where the vehicle 3 is parked. The GNSS sensor 15 and the central ECU 10 function as a position detection device.

[0073] Determination unit 137 first determines whether the acquired latitude and longitude information indicates a location registered as home. If the acquired latitude and longitude information indicates a location registered as home, determination unit 137 does not determine whether to permit the image authentication ECU 60 to perform a program update based on the communication status between portable device 5 and key authentication ECU 50. If the vehicle's location is a location registered as home, the vehicle can be unlocked by taking out a spare portable device from home, thus minimizing the likelihood of passengers being unable to board or drive the vehicle.

[0074] Based on the acquired facility information, the determination unit 137 obtains a predicted length of time the passenger will stay at the facility indicated in the facility information. For example, the determination unit 137 stores the types of facilities the passenger has previously stayed at and the average length of stay at facilities in that category in the third memory 110 as a history of their behavior. Examples of facility categories include information indicating the type of facility, such as supermarkets, convenience stores, amusement parks, and karaoke parlors. The determination unit 137 may also calculate the average length of stay for each facility and store it in the third memory 110. Alternatively, the average length of stay for multiple users may be calculated for each facility or facility category and registered in a server device (not shown). The determination unit 137 obtains the facility category indicated in the acquired facility information and transmits an acquisition request to the server device containing the acquired category information and the average length of stay. Upon receiving the acquisition request from the vehicle 3, the server device obtains the facility category indicated by the information included in the acquisition request and obtains the average length of stay at facilities corresponding to the acquired category. The server device transmits the obtained average length of stay to the vehicle 3 that received the acquisition request.

[0075] When the determination unit 137 obtains the predicted duration of the occupant's stay at the facility, it compares the obtained predicted duration with the update time required for updating the second program. If the predicted duration is longer than the update time, the determination unit 137 permits the image authentication ECU 60 to update the second program. If the predicted duration is shorter than the update time, the determination unit 137 does not permit the image authentication ECU 60 to update the second program.

[0076] In addition, the determination unit 137 prohibits the image authentication ECU 60 from updating the program when the key authentication ECU 50 and the portable device 5 are unable to communicate. In addition, the determination unit 137 prohibits the image authentication ECU 60 from updating the program when the key authentication ECU 50 and the portable device 5 are unable to communicate. Figure 3 The permission request screen 150 shown is displayed on the touch panel 16 .

[0077] While the key authentication ECU 50 is updating the first program, the determination unit 137 does not permit the image authentication ECU 60 to update the second program. Specifically, the determination unit 137 manages the execution timing of the update processes of the key authentication ECU 50 and the image authentication ECU 60 so that the key authentication ECU 50's update of the first program and the image authentication ECU 60's update of the second program do not overlap.

[0078] [2. Operation of the Central ECU in the First Embodiment]

[0079] Figure 41 is a flowchart showing the operation of the central ECU 10. Figure 4 The flowchart shown explains the operation of the central ECU 10 .

[0080] The central ECU 10 determines whether there is an update program downloaded from the server device 300 (step SA1 ). If there is no update program downloaded (step SA1 / No), the central ECU 10 waits until the update program is downloaded from the server device 300 .

[0081] When there is a downloaded update program (step S1A / YES), the central ECU 10 determines whether this downloaded update program is an update program of the second program executed by the image authentication ECU 60 (step SA2).

[0082] When the downloaded update program is not the update program of the second program (step SA2 / No), the central ECU 10 ends this processing flow and executes another processing flow.

[0083] When the downloaded update program is the update program of the second program (step SA2 / Yes), the central ECU 10 determines whether the key authentication ECU 50 is in a state capable of communicating with the portable device 5 (step SA3 ).

[0084] When the key authentication ECU 50 and the portable device 5 are unable to communicate (step SA3 / No), the central ECU 10 does not permit the image authentication ECU 60 to update the second program (step SA11 ), and ends this processing flow.

[0085] When the key authentication ECU 50 and the portable device 5 are able to communicate (step SA3 / Yes), the central ECU 10 causes the touch panel 16 to display a permission request screen 150 requesting the occupant to permit the second program update (step SA4). This permission request screen 150 displays a radio button 151 for permitting the program update, a radio button 153 for rejecting the program update, and an OK button 155. Furthermore, permission request screen 150 displays guidance requesting the removal of the portable device 5 when permitting the program update by the image authentication ECU 60 and moving the device outside the vehicle. To permit the program update, the occupant selects radio button 151 and presses OK button 155.

[0086] The central ECU 10 determines whether a permission operation is received (step SA5 ). If a rejection operation is received but a permission operation is not received (step SA5 / No), the central ECU 10 does not permit the image authentication ECU 60 to update the second program (step SA11 ).

[0087] When the permission operation is received (step SA5 / YES), the central ECU 10 determines whether the occupant has exited the vehicle 3 while carrying the portable device 5 (step SA6). The central ECU 10 detects the occupant's exit based on sensor data from the weight sensor 49. Furthermore, if the communication status between the key authentication ECU 50 and the portable device 5 changes from a communicable state to a non-communicable state, the central ECU 10 determines that the portable device 5 has been taken outside the vehicle upon detecting the occupant's exit.

[0088] When the central ECU 10 determines that the portable device 5 has been taken outside the vehicle (step SA6 / Yes), it permits the program update of the image authentication ECU 60 (step SA10 ), and ends this processing flow.

[0089] If the portable device 5 has not been taken outside the vehicle (step SA6 / No), the central ECU 10 obtains the latitude and longitude information indicating the location of the vehicle 3, as calculated by the GNSS sensor 15. Based on the obtained latitude and longitude information, the central ECU 10 references the map data 113 and obtains facility information for facilities within the site that include the obtained latitude and longitude (step SA7). Furthermore, if no facilities within the site include the obtained latitude and longitude, the central ECU 10 may obtain facility information for facilities within a predetermined range of the latitude and longitude.

[0090] Next, the central ECU 10 obtains a predicted duration of stay at the facility in the obtained facility information based on the occupant's behavioral history (step SA8). For example, the third memory 110 may store the categories of facilities the occupant has previously visited and the average duration of stay at facilities of that category as the occupant's behavioral history. The central ECU 10 obtains the average duration of stay at the facility corresponding to the facility information as the predicted duration.

[0091] Next, the central ECU 10 determines whether the average dwell time obtained in step SA8 is longer than the update time required for the image authentication ECU 60 program update (step SA9). If the predicted dwell time is longer than the update time (step SA9 / Yes), the central ECU 10 permits the image authentication ECU 60 to perform the program update (step SA10). If the predicted dwell time is less than the update time (step SA9 / No), the central ECU 10 disallows the image authentication ECU 60 from performing the program update (step SA11), terminating the process.

[0092] [3. Operation of the Central ECU in the Second Embodiment]

[0093] Next, a second embodiment will be described with reference to the drawings.

[0094] The configuration of the vehicle control system 1 of the second embodiment is the same as that of the first embodiment, and therefore the description of the configuration of the vehicle control system 1 will be omitted.

[0095] In the second embodiment, when the central ECU 10 downloads the update program of the image authentication ECU 60 from the server device 300 , it inquires the key authentication ECU 50 about the communication status with the portable device 5 .

[0096] When the central ECU 10 receives a response from the key authentication ECU 50 indicating that the communication status with the portable device 5 is enabled, the touch panel 16 displays Figure 5 The first setting screen 200 is shown. If the central ECU 10 receives a reply from the key authentication ECU 50 that the communication state with the portable device 5 is not communicateable, the touch panel 16 displays Figure 6 The second setting screen 250 is shown.

[0097] Figure 5 1 is a diagram showing an example of a first setting screen 200 that the central ECU 10 displays on the touch panel 16 .

[0098] The first setting screen 200 displays a guidance display notifying the image authentication ECU 60 of a program update. The first setting screen 200 also displays a radio button 211 for selecting "Permit" program update, a radio button 213 for selecting "Reject", and a decision button 215.

[0099] When the passenger approves the program update, the passenger selects the radio button 211 and presses the decision button 215 . When the passenger rejects the program update, the passenger selects the radio button 213 and presses the decision button 215 .

[0100] Figure 6 1 is a diagram showing an example of a second setting screen 250 that the central ECU 10 displays on the touch panel 16. The second setting screen 250 corresponds to a setting screen.

[0101] A first display field 260 , a second display field 270 , and a determination button 280 are displayed on the second setting screen 250 .

[0102] A guidance display notifying the image authentication ECU 60 of a program update is displayed in first display field 260. Also displayed in first display field 260 are a radio button 261 for selecting "Apply" for program updates and a radio button 263 for selecting "Reject." To approve the program update, the occupant selects radio button 261. To disapprove the program update, the occupant selects radio button 263.

[0103] Second display field 270 displays a warning message in the event that the image authentication ECU 60 program update fails. For example, second display field 270 displays a message stating that if the image authentication ECU 60 program update fails, the image authentication ECU 60 may not operate, making it impossible to unlock the doors using facial recognition. Second display field 270 also displays a message asking the occupant whether to lock the doors when exiting the vehicle. Second display field 270 displays a radio button 271 for selecting "Lock" and a radio button 273 for selecting "Unlock." Radio buttons 271 and 273 displayed in second display field 270 are selectable when radio button 261 is selected in first display field 260.

[0104] The passenger selects radio button 261 to approve the image authentication ECU 60 program update. Alternatively, the passenger selects radio button 263 to deny the image authentication ECU 60 program update. Furthermore, the passenger selects radio button 271 to lock the vehicle doors upon exiting the vehicle. Alternatively, the passenger selects radio button 273 to leave the vehicle doors unlocked. The passenger selects radio button 261 or 263, or radio button 271 or 273, and presses enter button 280.

[0105] When the first setting screen 200 is displayed, the communication status between the key authentication ECU 50 and the portable device 5 is enabled. Therefore, even if the image authentication ECU 60 program update is permitted, the occupant can still board the vehicle 3 by operating the portable device 5. Therefore, the central ECU 10 does not display a warning message on the first setting screen 200 in the event that the image authentication ECU 60 program update fails.

[0106] When the key authentication ECU 50 and the portable device 5 are in a communication state and the radio button 211 is selected on the first setting screen 200, the central ECU 10 determines that an operation has been received to permit a program update for the image authentication ECU 60. In this case, upon detecting that the occupant has exited the vehicle, the central ECU 10 instructs the region B-ECU 40 to lock the vehicle doors and permits a program update for the image authentication ECU 60. In response to the instruction from the central ECU 10, the region B-ECU 40 controls the door lock mechanism 47 to lock the doors.

[0107] Furthermore, if the communication status between the key authentication ECU 50 and the portable device 5 is enabled and the radio button 213 is selected in the first setting screen 200, the central ECU 10 determines that a rejection operation has been received to reject the program update of the image authentication ECU 60. In this case, the central ECU 10 prohibits the program update of the image authentication ECU 60 and does not cause the image authentication ECU 60 to execute the program update.

[0108] Furthermore, if the key authentication ECU 50 and the portable device 5 are unable to communicate, and radio buttons 261 and 271 are selected on the second setting screen 250, the central ECU 10 determines that both the permission operation for program updating and the door lock operation have been accepted. In this case, upon detecting the occupant's exit from the vehicle, the central ECU 10 instructs the region B-ECU 40 to lock the vehicle doors and permits the image authentication ECU 60 to update the program. In response to the instruction from the central ECU 10, the region B-ECU 40 controls the door lock mechanism 47 to lock the doors.

[0109] Furthermore, if the key authentication ECU 50 and the portable device 5 are unable to communicate, and if radio buttons 261 and 273 are selected on the second setting screen 250, the central ECU 10 determines that both a permission operation to permit a program update and an unlock operation to prevent the doors from being locked have been accepted. If the central ECU 10 detects the occupant exiting the vehicle, it permits the program update to the image authentication ECU 60 but does not instruct the zone B-ECU 40 to lock the doors.

[0110] Furthermore, upon receiving a permission operation to permit program updates and an unlock operation to prevent the doors from being locked, the central ECU 10 transmits an instruction to the area A-ECU 30 to prohibit the driving of the drive device 31. Furthermore, the central ECU 10 may be configured not to transmit an instruction signal to the area A-ECU 30 to lock the doors of the vehicle 3. Upon receiving the instruction from the central ECU 10, the area A-ECU 30 prohibits the driving of the drive device 31, rendering the vehicle 3 unable to travel. This prevents the theft of the vehicle 3. The prohibition of the driving of the drive device 31 continues, for example, until the occupant operates the portable device 5 and the key authentication ECU 50 receives the key ID from the portable device 5. Furthermore, the prohibition of the driving of the drive device 31 continues, for example, until the program update of the image authentication ECU 60 is completed and the image authentication ECU 60 authenticates the occupant based on images captured by the camera 65.

[0111] If the communication status between the key authentication ECU 50 and the portable device 5 is not established and the radio button 263 is selected on the second setting screen 250, the central ECU 10 determines that a rejection operation for rejecting the program update has been received. In this case, the central ECU 10 prohibits the image authentication ECU 60 from performing the program update and does not cause the image authentication ECU 60 to execute the program update.

[0112] Figure 7 This is a flowchart showing the operation of the central ECU 10 according to the second embodiment.

[0113] Reference Figure 7The flowchart shown explains the operation of the central ECU 10 .

[0114] The central ECU 10 determines whether there is an update program downloaded from a server (not shown) (step SB1 ). If there is no update program downloaded (step SB1 / No), the central ECU 10 waits until the update program is downloaded from the server.

[0115] When there is a downloaded update program (step SB1 / Yes), the central ECU 10 determines whether the downloaded update program is an update program of the program executed by the image authentication ECU 60 (step SB2 ).

[0116] When the downloaded update program is not the update program for the image authentication ECU 60 (step SB2 / No), the central ECU 10 ends this processing flow and executes another processing flow.

[0117] If the downloaded update program is for the image authentication ECU 60 (step SB2 / Yes), the central ECU 10 inquires of the key authentication ECU 50 whether communication with the portable device 5 is possible. Upon receiving a response from the key authentication ECU 50 confirming that communication with the portable device 5 is possible (step SB3 / Yes), the central ECU 10 causes the touch panel 16 to display the first setting screen 200 (step SB4). The central ECU 10 changes the display of the first setting screen 200 in response to a touch operation on the touch panel 16. For example, the central ECU 10 changes a selected radio button to radio button 211 or 213 in response to the touch operation.

[0118] Next, the central ECU 10 determines whether the decision button 215 is pressed (step SB5 ). If the decision button 215 is not pressed (step SB5 / No), the central ECU 10 waits until the decision button 215 is pressed.

[0119] If the decision button 215 is pressed (step SB5 / Yes), the central ECU 10 determines whether a permission operation for permitting the image authentication ECU 60 to update its program has been accepted on the first setting screen 200 (step SB6). If the permission operation has been accepted (step SB6 / Yes), upon detecting that an occupant has exited the vehicle 3, the central ECU 10 instructs the area B-ECU 40 to lock the doors (step SB7). In response to the instruction from the central ECU 10, the area B-ECU 40 controls the door lock mechanism 47 to lock the doors of the vehicle 3. The central ECU 10 then permits the image authentication ECU 60 to update its program (step SB8).

[0120] If the central ECU 10 does not receive the permission operation for permitting the image authentication ECU 60 program update on the first setting screen 200 (step SB6 / No), it does not permit the image authentication ECU 60 program update (step SB9 ) and ends this processing flow.

[0121] Next, the operation of the central ECU 10 when receiving a response from the key authentication ECU 50 indicating that communication with the portable device 5 is not possible in the determination of step SB3 will be described.

[0122] When receiving a response from the key authentication ECU 50 that communication with the portable device 5 is not possible (step SB3 / No), the central ECU 10 causes the touch panel 16 to display the second setting screen 250 (step SB10 ).

[0123] Next, the central ECU 10 determines whether the decision button 215 is pressed (step SB11 ). When the decision button 215 is not pressed (step SB11 / No), the central ECU 10 waits until the decision button 215 is pressed.

[0124] When the decision button 280 is pressed (step SB11 / Yes), the central ECU 10 determines whether a permission operation for permitting the image authentication ECU 60 to update the program has been accepted on the second setting screen 250 (step SB12). The central ECU 10 determines whether the radio button 261 in the first display field 260 has been selected, and whether the permission operation has been accepted.

[0125] If the central ECU 10 determines that the radio button 263 of the first display field 260 is selected and a rejection operation is accepted (step SB12 / No), it does not permit the image authentication ECU 60 to perform a program update (step SB9 ) and ends this processing flow.

[0126] When the central ECU 10 receives selection of the radio button 261 in the first display field 260 and determines that a permission operation has been received (step SB12 / Yes), it determines whether a setting for locking the doors when exiting the vehicle has been received (step SB13 ).

[0127] Upon receiving a selection of radio button 271 in second display field 270, central ECU 10 determines that the vehicle 3 doors are locked upon exiting the vehicle (step SB13 / Yes). In this case, central ECU 10 instructs region B-ECU 40 to lock the doors (step SB14). Region B-ECU 40 controls door lock mechanism 47 in accordance with the instruction from central ECU 10, locking the vehicle 3 doors. Central ECU 10 then authorizes image authentication ECU 60 to perform a program update (step SB17).

[0128] Furthermore, upon receiving a selection of radio button 273 in second display field 270, central ECU 10 determines that the vehicle 3 door locks have been unlocked upon exit (step SB13 / No). In this case, central ECU 10 transmits an instruction to disable driving device 31 to zone A-ECU 30 (step SB15) and does not instruct zone B-ECU 40 to lock the door locks. Consequently, the vehicle 3 door locks remain unlocked even after the occupant exits the vehicle (step SB16). Subsequently, central ECU 10 authorizes image authentication ECU 60 to perform a program update (step SB17).

[0129] [4. Operation of the Central ECU in the Third Embodiment]

[0130] Next, a third embodiment will be described. The configuration of the vehicle control system 1 is the same as that of the first embodiment described above, and therefore, the description of the configuration of the vehicle control system 1 will be omitted.

[0131] The central ECU 10 of the third embodiment also inquires the key authentication ECU 50 about the communication status with the portable device 5 when downloading the update program for the image authentication ECU 60 from the server device 300. The central ECU 10 of the third embodiment changes the operation when the program update of the image authentication ECU 60 fails, based on the communication status between the key authentication ECU 50 and the portable device 5.

[0132] The central ECU 10 executes the first action when the communication status between the key authentication ECU 50 and the portable device 5 is enabled and the program update of the image authentication ECU 60 fails.

[0133] As a first action, the central ECU 10 sends a failure notification to the portable device 5 held by the driver, the owner of the vehicle 3, as a first notification destination, indicating that the image authentication ECU 60 program update has failed. Furthermore, if the portable device 5 is a smartphone serving as a digital key, the failure notification is sent to the smartphone's registered email address or IP address. This failure notification includes guidance that the portable device 5 needs to unlock the vehicle 3 and start the driving source, such as the engine, installed in the vehicle 3.

[0134] Furthermore, when the central ECU 10 is unable to communicate with the portable device 5 and the program update of the image authentication ECU 60 fails, the central ECU 10 executes the second action.

[0135] As a second operation, the central ECU 10 transmits a failure notification indicating that the program update of the image authentication ECU 60 has failed to a second notification target, wherein the second notification target is the contact information of a portable device owned by a loading service provider or the owner of the vehicle 3, that is, the driver's family.

[0136] Figure 8 1 is a diagram showing an example of the contact destination table 115 in which emergency contact destinations are registered.

[0137] The second notification destination is registered in the contact destination table 115 .

[0138] As the second notification destination, the phone number of the loading service provider company providing the loading service, the email address and phone number of the family of the owner of the vehicle 3, etc. are registered. In addition, when the portable device 5 is a smartphone used as a digital key, the phone number and email address of the owner of the vehicle 3 can also be registered in advance as the first notification destination.

[0139] If communication with the portable device 5 is lost and the image authentication ECU 60 program update fails, the central ECU 10 sends an email containing a failure notification to the email address of the loading service provider or the registered family member's mobile phone. Alternatively, the central ECU 10 may call the loading service provider's phone number or the registered family member's mobile phone to notify the failure, for example, using a voice synthesized by voice synthesis software.

[0140] Furthermore, when the central ECU 10 sends a program update failure notification to the second notification destination, it sends the failure notification including the vehicle 3 location information obtained from the GNSS sensor 15. Including the vehicle 3 location information makes it easier for the loading service provider or the user to locate the vehicle 3.

[0141] Furthermore, if the image authentication ECU 60 program update fails, the central ECU 10 instructs the region B-ECU 40 to unlock the vehicle 3 doors, forcibly unlocking the vehicle 3 doors. There are also cases where a passenger exits the vehicle 3 without the portable device 5. In this case, it is also possible that the image authentication ECU 60 program update failure could prevent the door locks from being unlocked using image authentication. Therefore, the central ECU 10 instructs the region B-ECU 40 to forcibly unlock the vehicle 3 doors.

[0142] Furthermore, the central ECU 10 transmits a prohibition instruction to the area A-ECU 30 to prohibit the driving of the driving device 31. Since the doors of the vehicle 3 remain unlocked, the prohibition instruction is transmitted to the area A-ECU 30 to prevent the vehicle 3 from traveling in order to prevent theft.

[0143] Furthermore, the central ECU 10 continues to supply power from the battery 33 to the TCU 14, maintaining a state in which external communication is possible via the TCU 14. Then, for example, the central ECU 10 causes the touch panel 16 to display the phone number of the loading service provider or the phone number registered as the second notification destination. When the occupant selects a phone number through a touch operation, the central ECU 10 calls the selected phone number, enabling a call.

[0144] Furthermore, the registration of the first and second notification targets can be changed by a touch operation on the touch panel 16 by a passenger or the like. In other words, the notification targets registered as the first and second notification targets can be changed by a touch operation. For example, the phone number of another load service company can be registered as the second notification target, and the email address or phone number of a smartphone held by a passenger, the owner of the vehicle 3, can be registered as the first notification target instead of the mobile device 5.

[0145] Figure 9 and Figure 10 1 is a flowchart showing the operation of the central ECU 10 according to the third embodiment. Figure 9 and Figure 10 The flowchart shown explains the operation of the central ECU 10 .

[0146] The central ECU 10 determines whether an update program has been downloaded from a server (not shown) (step SC1 ). If no update program has been downloaded (step SC1 / No), the central ECU 10 waits until the update program is downloaded from the server.

[0147] When there is a downloaded update program (step SC1 / Yes), the central ECU 10 determines whether the downloaded update program is an update program of the program executed by the image authentication ECU 60 (step SC2 ).

[0148] When the downloaded update program is not the update program for the image authentication ECU 60 (step SC2 / No), the central ECU 10 ends this processing flow and executes another processing flow.

[0149] If the downloaded update program is an update program for the image authentication ECU 60 (step SC2 / Yes), the central ECU 10 inquires the key authentication ECU 50 whether the communication status with the portable device 5 is in a communication-enabled state. If the central ECU 10 receives a reply from the key authentication ECU 50 that the communication with the portable device 5 is in a communication-enabled state (step SC3 / Yes), the touch panel 16 displays Figure 3 The first setting screen 200 is shown (step SC4). When the passenger permits the program update, the passenger selects the radio button 151 and presses the decision button 155. When the passenger does not permit the program update, the passenger selects the radio button 153 and presses the decision button 155.

[0150] The central ECU 10 determines whether a permission operation is received (step SC5 ). If a rejection operation is received but a permission operation is not received (step SC5 / No), the central ECU 10 does not allow the image authentication ECU 60 to update the second program (step SC6 ).

[0151] When receiving the permission operation (step SC5 / Yes), the central ECU 10 permits the image authentication ECU 60 to update the program (step SC7 ).

[0152] The central ECU 10 then determines whether the image authentication ECU 60 program update was successful (step SC8). If the image authentication ECU 60 program update was unsuccessful (step SC8 / No), the central ECU 10 notifies the portable device 5 that key authentication by the portable device 5 is required (step SC9). At this point, the central ECU 10 notifies the portable device 5 that the image authentication ECU 60 program update failed.

[0153] If the program update of the image authentication ECU 60 is successful (step SC8 / Yes), the central ECU 10 instructs the image authentication ECU 60 to perform image authentication (step SC10 ). At this time, the central ECU 10 may also send a guidance instructing the portable device 5 to perform face authentication.

[0154] The image authentication ECU 60, in response to instructions from the central ECU 10, causes the camera 65 to capture images and extracts the passenger's facial image from the captured image. The image authentication ECU 60 extracts facial features from the image captured by the camera 65 and authenticates the user based on a comparison of the extracted features with those stored in the second memory 61.

[0155] Next, refer to Figure 10 The flowchart shown here will explain the operation when a response indicating that communication with the portable device 5 is not possible is received from the key authentication ECU 50 in the determination of step SC3 .

[0156] The central ECU 10 causes the touch panel 16 to display Figure 3 The first setting screen 200 is shown (step SC11). When the passenger permits program updating, the passenger selects radio button 151 and presses decision button 155. When the passenger does not permit program updating, the passenger selects radio button 153 and presses decision button 155.

[0157] The central ECU 10 determines whether a permission operation is received (step SC12). If a rejection operation is received but no permission operation is received (step SC12 / No), the central ECU 10 does not allow the image authentication ECU 60 to update the second program (step SC21) and ends this processing flow.

[0158] When receiving the permission operation (step SC12 / Yes), the central ECU 10 permits the image authentication ECU 60 to update the program (step SC13 ) Thereafter, the central ECU 10 determines whether the program update of the image authentication ECU 60 is successful (step SC14 ).

[0159] If the program update of the image authentication ECU 60 is successful (step SC14 / Yes), the central ECU 10 instructs the image authentication ECU 60 to perform image authentication (step SC15) in the same manner as step SC10. At this time, the central ECU 10 may also send a guidance instructing the mobile device 5 to perform face authentication.

[0160] If the image authentication ECU 60 program update fails (step SC14 / No), the central ECU 10 obtains the vehicle 3's location information from the GNSS sensor 15 (step SC16). The central ECU 10 then refers to the contact destination table 115 and notifies the notification destination registered as the second notification destination of the failure to update the image authentication ECU 60 program (step SC17). This notification destination can be a loading service provider or the contact information of the vehicle 3 owner's family members registered in the contact destination table 115.

[0161] Next, the central ECU 10 instructs the zone B-ECU 40 to release the door locks (step SC18 ), thereby forcibly unlocking the doors.

[0162] Next, the central ECU 10 controls the area A-ECU 30 to maintain power supply to the TCU 14, thereby activating the TCU 14. For example, if the central ECU 10 selects the phone number of a company providing an onboarding service by touching the touch panel 16, the central ECU 10 calls the selected number via the TCU 14.

[0163] Furthermore, the central ECU 10 transmits an instruction to prohibit the driving of the driving device 31 to the zone A-ECU 30 (step SC20 ).

[0164] The above-described embodiment is a preferred embodiment of the present invention, but the present invention is not limited thereto and various modifications can be made without departing from the spirit of the present invention.

[0165] For example, Figure 1 The structure of the vehicle control system 1 shown in Figure 2 The structure of the central ECU 10 shown in FIGURE 1 illustrates a functional configuration, and its specific implementation is not particularly limited. Specifically, it is not necessary to install hardware corresponding to each functional unit. Alternatively, a single processor executing a program can implement the functions of multiple functional units. Furthermore, in the above-described embodiments, a portion of the functions implemented by software can be implemented by hardware, and vice versa.

[0166] in addition, Figure 4 、 Figure 7 、 Figure 9 as well as Figure 10 The processing units in the flowchart shown are units divided according to the main processing contents in order to facilitate understanding of the processing of the central ECU 10. The present invention is not limited to Figure 4 、 Figure 7 、 Figure 9 as well as Figure 10 The method of dividing the processing units shown in the flowcharts and the name restrictions are not applicable. Furthermore, depending on the processing content, the processing of the central ECU 10 may be divided into more processing units, or a single processing unit may be divided to include more processing. Furthermore, the processing order of the flowcharts is not limited to the example shown.

[0167] [5. Structure supported by the above-mentioned embodiment]

[0168] The above-mentioned embodiment is a specific example of the following structure.

[0169] (Structure 1)

[0170] A vehicle control system comprising: a first control device, which obtains first authentication information through wireless communication with a portable device, and controls locking and unlocking of the vehicle based on the first authentication information obtained; a second control device, which obtains second authentication information based on an image captured by a camera, and controls locking and unlocking of the vehicle based on the second authentication information obtained; and an update management device, which, when an update process for updating a program executed by the second control device fails and the communication between the first control device and the portable device is communicable, performs a first action; and when the update process fails and the communication between the first control device and the portable device is not communicable, performs a second action different from the first action.

[0171] The vehicle control system of Structure 1 performs a first action when the program update of the second control device fails, if the communication between the first control device and the portable device is communicable. When the update process fails, if the communication between the first control device and the portable device is not communicable, a second action different from the first action is performed. Therefore, the action performed by the update management device is changed according to the communication status between the control device and the portable device. For example, if the communication between the first control device and the portable device is communicable, the failure of the program update can be notified to the portable device. If the communication between the first control device and the portable device is not communicable, the failure of the program update can be notified to a pre-set notification target. Therefore, it is possible to prevent the situation where the program update failure is not notified to the second control device, and it is possible to improve the convenience of the user.

[0172] (Structure 2)

[0173] According to the vehicle control system of structure 1, when the update processing fails and the communication between the first control device and the portable device is communicable, the update management device notifies a pre-set first notification target as the first action, and when the update processing fails and the communication between the first control device and the portable device is not communicable, the update management device notifies a pre-set second notification target different from the first notification target as the second action.

[0174] The vehicle control system of Configuration 2 notifies a pre-set first notification destination as a first action when communication between the first control device and the portable device is successful. If communication between the first control device and the portable device is unsuccessful, the vehicle control system notifies a second notification destination as a second action. Therefore, the failure of a program update to the second control device can be notified regardless of the communication status between the first control device and the portable device. This prevents situations in which the second control device is not notified of a program update failure, thereby improving user convenience.

[0175] (Structure 3)

[0176] According to the vehicle control system of structure 2, when the update processing fails and the communication between the first control device and the portable device is communicable, the update management device uses the registered address of the owner of the portable device or the vehicle as the first notification target and sends the failure notification of the update processing to the first notification target.

[0177] The vehicle control system of Configuration 3 transmits an update failure notification to the registered address of the owner of the portable device or vehicle when the first control device and the portable device are able to communicate.

[0178] (Structure 4)

[0179] According to the vehicle control system of Configuration 3, the update management device transmits the failure notification including guidance indicating that at least one of unlocking the vehicle and starting a driving source mounted on the vehicle is required by the portable device.

[0180] The vehicle control system of Configuration 4 sends a notification indicating that at least one of unlocking the vehicle and starting the driving source mounted on the vehicle needs to be performed by the portable device.

[0181] (Structure 5)

[0182] According to the vehicle control system of structure 2, when the update processing fails and the communication between the first control device and the portable device is not communicable, the update management device uses the address of the user registered corresponding to at least one of the loading service provider company and the owner of the vehicle as the second notification target, and sends the failure notification of the update processing to the second notification target.

[0183] The vehicle control system of Configuration 5, when communication between the first control unit and the portable device is unavailable, transmits a notification of update failure to the user's address registered with at least one of the loading service provider and the vehicle owner. Therefore, if the vehicle cannot be unlocked using the portable device, notification of update failure can be sent to at least one of the loading service provider and the registered user's address, thereby improving user convenience.

[0184] (Structure 6)

[0185] According to the vehicle control system of Configuration 5, the update management device transmits the failure notification including position information indicating the position of the vehicle.

[0186] The vehicle control system of configuration 6 includes position information indicating the position of the vehicle in the failure notification. Therefore, even when the vehicle cannot be unlocked and becomes unable to travel, the position of the vehicle can be identified.

[0187] (Structure 7)

[0188] According to the vehicle control system of structure 1, the vehicle control system has a locking mechanism for locking the vehicle doors, and the update management device instructs the locking mechanism to release the lock when the update process fails and the communication between the first control device and the portable device is not communicable.

[0189] The vehicle control system of Configuration 7 instructs the locking mechanism to release the lock if the update process fails and communication between the first control unit and the portable device is unavailable. Therefore, if the program update of the second control unit fails, the vehicle is released, thereby reducing the occurrence of situations where passengers cannot board the vehicle.

[0190] (Structure 8)

[0191] According to the vehicle control system of structure 7, the vehicle control system has a wireless communication unit and an acceptance device for accepting operations, and when the update processing fails, the update management device wirelessly connects to the object selected by the operation accepted by the acceptance device via the wireless communication unit.

[0192] The vehicle control system of configuration 8 can wirelessly connect to a destination selected by the occupant via the wireless communication unit provided in the vehicle control system if the update process fails. If the program update of the second control device fails, the selected destination can be communicated with.

[0193] (Structure 9)

[0194] According to the vehicle control system of structure 7 or 8, the vehicle control system has a drive source control device for controlling the drive source mounted on the vehicle, and when the update management device instructs the locking mechanism to release the lock, it sends an instruction to the drive source control device to prohibit the driving of the drive source.

[0195] The vehicle control system of structure 9 sends an instruction to prohibit the driving of the driving source to the driving source control device when instructing the locking mechanism to release the lock. Therefore, even if the vehicle is not locked, the driving source will not be driven and the vehicle will not travel, thereby preventing the vehicle from being stolen.

[0196] (Structure 10)

[0197] According to the vehicle control system of configuration 1, the vehicle control system includes an accepting device for accepting an operation, and the update management device accepts settings of the first action and the second action through the accepting device.

[0198] The vehicle control system of the configuration 10 receives settings of the first and second actions via the receiving device. Therefore, the first and second actions can be set by the operation of the passenger.

[0199] (Structure 11)

[0200] A control method for a vehicle control system, the vehicle control system comprising: a first control device, which obtains first authentication information through wireless communication with a portable device, and controls locking and unlocking of the vehicle based on the first authentication information obtained; a second control device, which obtains second authentication information based on an image captured by a camera, and controls locking and unlocking of the vehicle based on the second authentication information obtained; and an update management device, which manages updates of programs executed by the first control device and the second control device, wherein the control method includes the following processing: when the update processing of updating the program executed by the second control device fails, if the communication between the first control device and the portable device is not communicable, the processor mounted on the update management device executes a first action; when the update processing fails, if the communication between the first control device and the portable device is communicable, the processor mounted on the update management device executes a second action different from the first action.

[0201] The control method of the vehicle control system of structure 11 performs a first action when the program update of the second control device fails, if the communication between the first control device and the portable device is communicable, and performs a second action different from the first action when the update process fails, if the communication between the first control device and the portable device is not communicable. Therefore, the action performed by the update management device is changed according to the communication status between the control device and the portable device. For example, if the communication between the first control device and the portable device is communicable, the failure of the program update can be notified to the portable device, and if the communication between the first control device and the portable device is not communicable, the failure of the program update can be notified to a pre-set notification target. Therefore, it is possible to prevent the situation where the program update failure is not notified to the second control device, and it is possible to improve the convenience of the user.

[0202] Description of Reference Numerals

[0203] 1…Vehicle Control System, 3…Vehicle, 3a…First Communication Line, 3b…First Communication Line, 4a…Second Communication Line, 4b…Second Communication Line, 5…Portable Device, 10…Central ECU, 11…ICB, 12…Speaker, 13…Microphone, 14…TCU, 15…GNSS Sensor, 16…Touch Panel, 17…Display, 18…Touch Sensor, 19…In-Vehicle Connectivity Link, 20…DMC, 30…Area A-ECU, 31…Drive Unit, 33…Battery, 40…Area B-ECU, 41…Lamp Body, 43…Window Motor, 45…Door Sensor, 47…Door Lock Mechanism, 49…Weight Sensor, 50…Key Authentication ECU, 51…First Memory, 53…First Processor, 55…LF / RF Antenna, 60…Image Authentication ECU, 61… 1…Second memory, 63…Second processor, 65…Camera, 110…Third memory, 111…Third program, 113…Map data, 115…Contact target table, 130…Third processor, 131…Information acquisition unit, 133…Get-off detection unit, 135…Program update unit, 137…Determination unit, 150…Permission request screen, 151…Radio button, 153…Radio button, 155…Decision button, 200…First setting screen, 211…Radio button, 213…Radio button, 215…Decision button, 250…Second setting screen, 260…First display field, 261…Radio button, 263…Radio button, 270…Second display field, 271…Radio button, 273…Radio button, 280…Decision button, 300…Server device, 350…Network.

Claims

1. A vehicle control system, comprising: a first control device that obtains first authentication information through wireless communication with the portable device and controls locking and unlocking of the vehicle based on the obtained first authentication information; a second control device that obtains second authentication information based on the image captured by the camera and controls locking and unlocking of the vehicle based on the obtained second authentication information; and An update management device that, when an update process for updating a program executed by the second control device fails and the communication between the first control device and the portable device is communicable, performs a first action; and when the update process fails and the communication between the first control device and the portable device is not communicable, performs a second action different from the first action.

2. The vehicle control system according to claim 1, wherein: When the update process fails and the communication between the first control device and the portable device is possible, the update management device notifies a preset first notification target as the first action. When the update process fails and the first control device and the portable device are unable to communicate, the update management device notifies a second notification destination that is preset and different from the first notification destination as the second action.

3. The vehicle control system according to claim 2, wherein: When the update process fails and the first control device is able to communicate with the portable device, the update management device sends a notification of the failure of the update process to the first notification destination using the registered address of the owner of the portable device or the vehicle as the first notification destination.

4. The vehicle control system according to claim 3, wherein: The update management device transmits the failure notification including guidance indicating that at least one of unlocking the vehicle and starting a driving source mounted on the vehicle is required to be performed by the portable device.

5. The vehicle control system according to claim 2, wherein: When the update process fails and the communication between the first control device and the portable device is not communicable, the update management device uses the address of the user registered corresponding to at least one of the loading service provider and the owner of the vehicle as the second notification target, and sends the failure notification of the update process to the second notification target.

6. The vehicle control system according to claim 5, wherein: The update management device transmits the failure notification including position information indicating the position of the vehicle.

7. The vehicle control system according to claim 1, wherein: The vehicle control system includes a locking mechanism for locking doors of the vehicle, and the update management device instructs the locking mechanism to release the lock when the update process fails and communication between the first control device and the portable device is unavailable.

8. The vehicle control system according to claim 7, wherein: The vehicle control system includes a wireless communication unit and an accepting device for accepting operations. When the update process fails, the update management device establishes a wireless connection with a target selected by the operation accepted by the acceptance device via the wireless communication unit.

9. The vehicle control system according to claim 7 or 8, wherein: The vehicle control system includes a drive source control device for controlling a drive source mounted on the vehicle. The update management device transmits an instruction to prohibit driving of the drive source to the drive source control device when instructing the lock mechanism to release the lock.

10. The vehicle control system according to claim 1, wherein: The vehicle control system includes an accepting device for accepting operations. The update management device accepts settings of the first action and the second action through the acceptance device.

11. A control method for a vehicle control system, the vehicle control system comprising: a first control device that obtains first authentication information through wireless communication with a portable device and controls locking and unlocking of the vehicle based on the obtained first authentication information; a second control device that obtains second authentication information based on an image captured by a camera and controls locking and unlocking of the vehicle based on the obtained second authentication information; and an update management device that manages updates of programs executed by the first control device and the second control device, wherein: The control method includes the following processing: When the update process of the program executed by the second control device fails and the communication between the first control device and the portable device is not possible, the processor mounted on the update management device executes a first action. When the update process fails and communication between the first control device and the portable device is possible, the processor mounted on the update management device executes a second action different from the first action.

Citation Information

Patent Citations

  • Program rewriting system

    JP2006082648A