Vehicle control system and control method thereof

Through the authentication information communication and position detection of the vehicle control system, the program update time is reasonably arranged, which solves the problem of passengers being unable to use the vehicle during the update process and improves convenience and safety.

CN120716636APending Publication Date: 2025-09-30HONDA MOTOR CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510171069.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-03-27
Filing Date
2025-02-17
Publication Date
2025-09-30

AI Technical Summary

Technical Problem

When the vehicle program is updated, if the occupants do not have an electronic key or other device to unlock the vehicle, the vehicle may not be unlocked, affecting the convenience and safety of the occupants.

Method used

Wireless communication of authentication information is performed through the first and second control devices in the vehicle control system. Combined with camera image authentication and position detection, it is determined whether the program update is permitted, ensuring the status of the passenger's portable device inside or outside the vehicle, and reasonably arranging the update time to avoid the vehicle being unusable during the update process.

Benefits of technology

It improves the convenience and safety of passengers, ensures a smooth program update process, and avoids the problem of vehicles being unusable due to updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120716636A_ABST
    Figure CN120716636A_ABST
Patent Text Reader

Abstract

The invention provides a vehicle control system and a control method thereof. Problems which may occur when a program is updated are suppressed. A vehicle control system (1) is provided with: a key authentication ECU (50) that acquires a key ID by wireless communication with a portable device (5) and controls locking and unlocking of a vehicle (3) on the basis of the acquired key ID; an image authentication ECU (60) that acquires a feature amount of a face portion on the basis of an image captured by the camera (65), and controls locking and unlocking of the vehicle (3) on the basis of the acquired feature amount of the face portion; and a central ECU (10) provided with a determination unit (137) that determines, on the basis of the communication state between the key authentication ECU (50) and the portable device (5), whether or not to permit the update of the second program executed by the image authentication ECU (60).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a vehicle control system and a control method thereof. Background Art

[0002] Conventionally, a program rewriting system for updating a program of a computer mounted on a vehicle has been proposed (for example, see Patent Document 1).

[0003] [Prior art literature]

[0004] [Patent Document]

[0005] Patent Document 1: Japanese Patent Application Laid-Open No. 2006-082648 Summary of the Invention

[0006] [Problems to be Solved by the Invention]

[0007] In recent years, vehicles have been equipped with multiple devices that lock and unlock the vehicle's locking mechanism. However, if a passenger does not have a device such as an electronic key to unlock the vehicle, and the electronic control device that authenticates the passenger undergoes a program update, the vehicle may not be unlocked, preventing the passenger from boarding or moving the vehicle until the program update is complete.

[0008] In order to solve the above-mentioned problems, the present application aims to improve the convenience and safety of passengers by suppressing the occurrence of problems that may occur when updating vehicle programs. Moreover, it contributes to the development of a sustainable transportation system that further improves traffic safety.

[0009] [Means for solving the problem]

[0010] As a first method for achieving the above-mentioned purpose, a vehicle control system can be cited, which includes: a first control device, which obtains first authentication information through wireless communication with a portable device, and controls the locking and unlocking of the vehicle according to the first authentication information obtained; a second control device, which obtains second authentication information based on an image captured by a camera, and controls the locking and unlocking of the vehicle according to the second authentication information obtained; and an update management device, which has a determination unit, which determines whether to permit the update of the second program executed by the second control device based on the communication status between the first control device and the portable device.

[0011] In the vehicle control system described above, the determination unit may be configured to permit updating of the second program when the first control device and the portable device are in a state capable of communicating.

[0012] In the above-mentioned vehicle control system, it can also be configured that the vehicle control system has an on-board display device installed on the vehicle, and the judgment unit prohibits the display of a guidance screen for guiding the update of the second program on the on-board display device, or prohibits the update of the second program when the first control device cannot communicate with the portable device.

[0013] In the vehicle control system described above, the determination unit may be configured to permit updating of the second program when the first control device detects that the portable device has been moved from inside the vehicle to outside the vehicle.

[0014] In the above-mentioned vehicle control system, it can also be constructed as follows: the vehicle control system includes a position detection device that detects the position of the vehicle, and the update management device includes: a getting-off detection unit that detects that an occupant gets off the vehicle; and a storage unit that stores map data. When the getting-off detection unit detects that the occupant gets off the vehicle and the first control device determines that the portable device is inside the vehicle, the determination unit obtains facility information from the map data based on the position of the vehicle, and based on the obtained facility information, determines whether the vehicle has been parked at the position of the vehicle for more than a pre-set set time. When it is determined that the vehicle has been parked for more than the set time, the update of the second program is permitted.

[0015] In the above-mentioned vehicle control system, it can also be configured that the judgment unit obtains a predicted parking time of the vehicle at the location of the vehicle based on the category of the facility represented by the facility information, and permits the update of the second program when the obtained predicted time is longer than the update time required for the update of the second program as the set time.

[0016] In the above-mentioned vehicle control system, it can also be configured that the vehicle control system includes an on-board display device installed in the vehicle, and the determination unit causes the on-board display device to display a guidance screen for guiding the update of the second program and a take-out request for taking the portable device out of the vehicle.

[0017] In the above-mentioned vehicle control system, it can also be configured that the vehicle control system includes a position detection device for detecting the position of the vehicle, and the determination unit determines whether to permit the update of the second program executed by the second control device based on the communication status between the first control device and the portable device when the location detected by the position detection device is a location other than a pre-registered location.

[0018] In the above-mentioned vehicle control system, it can also be configured that the determination unit manages the update of the first control device and the second control device so that the update of the first program performed by the first control device and the update of the second program performed by the second control device do not overlap, and the first program is executed by the first control device.

[0019] As a second method for achieving the above-mentioned purpose, a control method for a vehicle control system can be cited, wherein the vehicle control system comprises: a first control device, which obtains first authentication information through wireless communication with a portable device, and controls locking and unlocking of the vehicle according to the first authentication information obtained; a second control device, which obtains second authentication information based on an image captured by a camera, and controls locking and unlocking of the vehicle according to the second authentication information obtained; and an update management device, which manages the update of programs executed by the first control device and the second control device, wherein the control method includes the following processing: a processor mounted on the update management device determines whether to permit the update of the second program executed by the second control device based on the communication status between the first control device and the portable device.

[0020] [Effects of the Invention]

[0021] According to the vehicle control system and control method thereof, the convenience of passengers can be improved by suppressing the occurrence of problems that may occur when updating a program. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 : is a system configuration diagram showing the configuration of a vehicle control system.

[0023] Figure 2 It is a block diagram showing the structure of the central ECU.

[0024] Figure 3 This is a diagram showing an example of a permission request screen.

[0025] Figure 4 This is a flowchart showing the operation of the central ECU according to the first embodiment.

[0026] Figure 5 This is a diagram showing an example of the first setting screen.

[0027] Figure 6 It is a diagram showing an example of the second setting screen.

[0028] Figure 7 This is a flowchart showing the operation of the central ECU according to the second embodiment.

[0029] Figure 8 : is a diagram showing an example of a contact destination table.

[0030] Figure 9 This is a flowchart showing the operation of the central ECU according to the third embodiment.

[0031] Figure 10 This is a flowchart showing the operation of the central ECU according to the third embodiment. DETAILED DESCRIPTION

[0032] [1. Configuration of Vehicle Control System of First Embodiment]

[0033] Figure 1 This is a system configuration diagram showing the structure of a vehicle control system 1 installed in a vehicle 3. Vehicle control system 1 is configured such that a central ECU (Electronic Control Unit) 10, an electronic control device functioning as a central gateway, is connected to the electronic control device targeted for program updates so that data can be communicated with each other. Central ECU 10 functions as an update management device.

[0034] Connected to the central ECU 10 is a TCU (Telematics Control Unit) 14, a wireless device compliant with the communication standards of a mobile communication system. The central ECU 10 utilizes the TCU 14 to perform OTA (Over The Air) management. OTA management includes downloading update programs for the electronic control devices in the vehicle 3 from a server device 300 via a network 350 and applying the downloaded update programs to the electronic control devices.

[0035] The central ECU 10 is connected to a plurality of communication lines including the first communication lines 3a, 3b and the second communication lines 4a, 4b, and implements a gateway function for managing the exchange of communication data between these communication lines.

[0036] The first communication lines 3a, 3b and the second communication lines 4a, 4b are composed of buses that perform communication based on standards such as CAN and Ethernet (registered trademark), or communication lines that perform P2P (peer to peer) communication. The first communication lines 3a, 3b can be composed of multiple communication lines that perform communication based on the same standard, or they can be composed of multiple communication lines that perform communication based on different standards. The same applies to the second communication lines 4a, 4b.

[0037] An ICB (Infotainment Control Box) 11, a speaker 12, and a microphone 13 are connected to the first communication line 3a via an in-vehicle connection link 19. Furthermore, a TCU (Telematics Control Unit) 14, a GNSS (Global Navigation Satellite System) sensor 15, and a touch panel 16 are connected to the in-vehicle connection link 19. Touch panel 16 includes a display 17 and a touch sensor 18. Touch panel 16 corresponds to an in-vehicle display device.

[0038] The in-vehicle connection link 19 is composed of multiple communication transmission paths based on various communication standards. The in-vehicle connection link 19 may also include, for example, multiple communication networks. In this case, multiple communication networks may also be interconnected via a device with a gateway function. In addition, the in-vehicle connection link 19 may also include a communication network for P2P communication. In the communication network, various communication buses for network communication based on various standards can be used. Examples of such standards include CAN, Ethernet, USB (Universal Serial Bus), LIN (Local Interconnect Network), and LVDS (Low Voltage Differential Signaling), but other standards may also be used.

[0039] The ICB 11 is an IVI (In-Vehicle Infotainment) ECU and provides various information and entertainment to vehicle passengers using a speaker 12 , a microphone 13 , a GNSS sensor 15 , a touch panel 16 , and the like.

[0040] A DMC (Driver Monitoring Camera) 20 that monitors the driver is connected to the first communication line 3 b.

[0041] The second communication line 4a is connected to the area A-ECU 30. The area A-ECU 30 is connected to a drive device 31 and a battery 33. The drive device 31 is, for example, a motor or an internal combustion engine that drives the vehicle 3. The area A-ECU 30 corresponds to a drive source control device.

[0042] The second communication line 4b is connected to the area B-ECU 40. The area B-ECU 40 is connected to a lamp 41, a window motor 43, a door sensor 45, a door lock mechanism 47, and a weight sensor 49.

[0043] The lamp body 41 includes, for example, headlights, taillights, and turn signals. The window motor 43 opens and closes the window. The door sensor 45 detects the operation of the door. The door lock mechanism 47 performs locking and unlocking of the doors of the vehicle 3. The weight sensor 49 is arranged on the seat where the occupant sits, and detects the weight applied to the seat. The weight sensor 49 outputs sensor data indicating the weight applied to the seat to the area B-ECU 40. In this embodiment, an example of providing the weight sensor 49 is described, but it is also possible to detect the seating or non-seating (leaving) of a person based on the detection results of a pressure sensor, a human sensor, etc. instead of the weight sensor 49. The area B-ECU 40 outputs the sensor data input from the weight sensor 49 to the central ECU 10.

[0044] The key authentication ECU 50 and the image authentication ECU 60 are connected to the area B-ECU 40. The key authentication ECU 50 serves as the first control unit. The image authentication ECU 60 serves as the second control unit. The key authentication ECU 50 is connected to an LF / RF antenna 55 for wireless communication with the portable device 5. The portable device 5 is an electronic device with wireless communication capabilities and is known as a smart key or FOB key. Alternatively, the portable device 5 may be a smartphone used as a digital key.

[0045] The key authentication ECU 50 is an electronic control unit comprising a first memory 51 and a first processor 53. The first memory 51 is comprised of, for example, a nonvolatile semiconductor memory, or a combination of volatile and nonvolatile semiconductor memory. The first processor 53 is an arithmetic processing unit comprised of a CPU (Central Processing Unit) and an MPU (Micro Processor Unit). The first processor 53 may be a single processor or a plurality of processors.

[0046] The first memory 51 stores a first program as a control program executed by the first processor 53 and a key ID. The key ID is an ID for the vehicle control system 1 to identify the portable device 5, and a different value is assigned to each portable device 5.

[0047] The first processor 53 executes a first program to perform authentication processing. Upon receiving the key ID of the portable device 5 via the LF / RF antenna 55, the first processor 53 determines whether the received key ID matches the key ID stored in the first memory 51. The key ID corresponds to the first authentication information. If the received key ID matches the key ID stored in the first memory 51, the first processor 53 instructs the area B-ECU 40 to unlock or lock the door locks. Based on the instruction from the key authentication ECU 50, the area B-ECU 40 instructs the door lock mechanism 47 to unlock or lock the door locks. Furthermore, the key authentication ECU 50 outputs information indicating the communication status between the portable device 5 and the LF / RF antenna 55 to the area B-ECU 40. The area B-ECU 40 then outputs the communication status information received from the key authentication ECU 50 to the central ECU 10.

[0048] The image authentication ECU 60 is connected to a camera 65. The camera 65 is a digital camera, and is installed in the vehicle 3 so as to be able to capture the face of a passenger outside the vehicle on the driver's side. The camera 65 is, for example, located on the driver's side B-pillar, the roof edge, or a side mirror.

[0049] The image authentication ECU 60 is an electronic control unit including a second memory 61 and a second processor 63. The second memory 61 is composed of, for example, a nonvolatile semiconductor memory or a volatile and nonvolatile semiconductor memory. The second processor 63 is an arithmetic processing unit composed of a CPU or an MPU.

[0050] The second memory 61 stores a second program and feature data, which are control programs executed by the second processor 63. The feature data is data representing features of the passenger's face and is extracted from a captured image of the passenger's face.

[0051] The image authentication ECU 60 activates the camera 65 and acquires an image captured by the camera 65. The image authentication ECU 60 extracts facial features from the image captured by the camera 65 and authenticates the user based on the comparison of these features with the features stored in the second memory 61. The facial features correspond to the second authentication information. If the features match, the image authentication ECU 60 instructs the region B-ECU 40 to unlock the doors. The region B-ECU 40, in accordance with the instruction from the image authentication ECU 60, instructs the door lock mechanism 47 to unlock the doors.

[0052] Figure 2 2 is a block diagram showing the configuration of the central ECU 10 .

[0053] Will refer to Figure 2 The configuration of the central ECU 10 is described.

[0054] The central ECU 10 is an electronic control unit that includes a third memory 110 and a third processor 130. The third memory 110 is composed of, for example, a nonvolatile semiconductor memory, or a combination of volatile and nonvolatile semiconductor memories. The third memory 110 stores a third program 111 and map data 113, which are executed by the third processor 130. Furthermore, the third memory 110 serves as a calculation area for the third processor 130.

[0055] The third processor 130 is an arithmetic processing device composed of a CPU or an MPU. The third processor 130 may be composed of a single processor or a plurality of processors.

[0056] The central ECU 10 includes an information acquisition unit 131, a vehicle exit detection unit 133, a program update unit 135, and a determination unit 137 as functional components. These functional components are functions obtained by the third processor 130 executing the third program 111 and performing calculations.

[0057] The information acquisition unit 131 acquires information from the key authentication ECU 50 and the area B-ECU 40. For example, the information acquisition unit 131 acquires information indicating the communication status with the portable device 5 from the key authentication ECU 50. The information acquisition unit 131 also acquires information indicating the status of the door locks and sensor data from the weight sensor 49 from the area B-ECU 40.

[0058] The vehicle exit detection unit 133 detects the passenger's exit from the vehicle. The vehicle exit detection unit 133 detects the passenger's exit based on sensor data from the weight sensor 49. The vehicle exit detection unit 133 may also determine that the passenger has exited the vehicle based on the communication status between the key authentication ECU 50 and the portable device 5. For example, the vehicle exit detection unit 133 may determine that the passenger has exited the vehicle 3 if the communication status between the key authentication ECU 50 and the portable device 5 changes from a communicable state to a non-communicable state.

[0059] When an update is required for a program executed by an electronic control unit mounted on vehicle 3, program update unit 135 downloads the updated program from server device 300. Program update unit 135 temporarily stores the obtained updated program in third memory 110. At a predetermined timing, program update unit 135 causes the target electronic control unit to update the downloaded program.

[0060] If the downloaded update program updates the second program executed by the image authentication ECU 60 and the determination unit 137 determines that program update is permitted, the program update unit 135 causes the image authentication ECU 60 to update the second program executed by the image authentication ECU 60 to the updated program.

[0061] When the update program downloaded by the program update unit 135 is a program for updating the second program, the determination unit 137 determines whether to permit the image authentication ECU 60 to update to the updated program based on the communication status between the key authentication ECU 50 and the portable device 5 .

[0062] When the key authentication ECU 50 and the portable device 5 are in a state in which communication is possible, the determination unit 137 permits the image authentication ECU 60 to update the program.

[0063] For example, if the key authentication ECU 50 and the portable device 5 are in a communicable state, the image authentication ECU 60 program update permission operation is accepted, and it is detected that the portable device 5 is taken outside the vehicle, the determination unit 137 permits the program update unit 135 to update the second program of the image authentication ECU 60.

[0064] In addition, even if the key authentication ECU 50 and the portable device 5 are in a state where communication is possible, but the permission operation for permitting the image authentication ECU 60 to update the program has not been received, when it is detected that the portable device 5 has been taken out of the vehicle, the determination unit 137 may allow the program update unit 135 to update the second program of the image authentication ECU 60.

[0065] Regarding the portable device 5 being taken out of the vehicle, for example, when the communication state between the key authentication ECU 50 and the portable device 5 changes from a communicable state to a non-communicable state, and the vehicle exit detection unit 133 determines that the passenger has been detected exiting the vehicle, the determination unit 137 determines that the portable device 5 has been taken out of the vehicle.

[0066] Figure 3 1 shows an example of a permission request screen 150 that the central ECU 10 displays on the touch panel 16 when the second program is updated. The permission request screen 150 corresponds to an example of a guidance screen.

[0067] The permission request screen 150 displays a message indicating that the second program executed by the image authentication ECU 60 is to be updated, and a message inquiring whether to permit the program update of the image authentication ECU 60. Furthermore, the permission request screen 150 displays a message requesting that the portable device 5 be taken out of the vehicle if the program update of the image authentication ECU 60 is permitted and the vehicle is moved outside the vehicle.

[0068] In addition, a radio button 151 for permitting program update, a radio button 153 for rejecting program update, and a decision button 155 are displayed on the permission request screen 150 .

[0069] When the passenger approves the program update, the passenger selects the radio button 151 and presses the decision button 155. When the passenger rejects the program update, the passenger selects the radio button 153 and presses the decision button 155.

[0070] Next, a case will be described where the determination unit 137 accepts a permission operation for permitting program update on the permission request screen 150 , but the passenger gets out of the vehicle while leaving the mobile device 5 in the vehicle.

[0071] When the determination unit 137 determines that the portable device 5 remains inside the vehicle despite the vehicle exit detection unit 133 detecting that the occupant has exited the vehicle, it obtains latitude and longitude information indicating the location of the vehicle 3 from the GNSS sensor 15. Based on the obtained latitude and longitude information, the determination unit 137 references the map data 113 and obtains facility information for the facility where the vehicle 3 is parked. The GNSS sensor 15 and the central ECU 10 function as a position detection device.

[0072] Determination unit 137 first determines whether the acquired latitude and longitude information indicates a location registered as home. If the acquired latitude and longitude information indicates a location registered as home, determination unit 137 does not determine whether to permit the image authentication ECU 60 to perform a program update based on the communication status between portable device 5 and key authentication ECU 50. If the vehicle's location is a location registered as home, the vehicle can be unlocked by taking out a spare portable device from home, thus minimizing the likelihood of passengers being unable to board or drive the vehicle.

[0073] Based on the acquired facility information, the determination unit 137 obtains a predicted length of time the passenger will stay at the facility indicated in the facility information. For example, the determination unit 137 stores the types of facilities the passenger has previously stayed at and the average length of stay at facilities in that category in the third memory 110 as a history of their behavior. Examples of facility categories include information indicating the type of facility, such as supermarkets, convenience stores, amusement parks, and karaoke parlors. The determination unit 137 may also calculate the average length of stay for each facility and store it in the third memory 110. Alternatively, the average length of stay for multiple users may be calculated for each facility or facility category and registered in a server device (not shown). The determination unit 137 obtains the facility category indicated in the acquired facility information and transmits an acquisition request to the server device containing the acquired category information and the average length of stay. Upon receiving the acquisition request from the vehicle 3, the server device obtains the facility category indicated by the information included in the acquisition request and obtains the average length of stay at facilities corresponding to the acquired category. The server device transmits the obtained average length of stay to the vehicle 3 that received the acquisition request.

[0074] When the determination unit 137 obtains the predicted duration of the occupant's stay at the facility, it compares the obtained predicted duration with the update time required for updating the second program. If the predicted duration is longer than the update time, the determination unit 137 permits the image authentication ECU 60 to update the second program. If the predicted duration is shorter than the update time, the determination unit 137 does not permit the image authentication ECU 60 to update the second program.

[0075] In addition, the determination unit 137 prohibits the image authentication ECU 60 from updating the program when the key authentication ECU 50 and the portable device 5 are unable to communicate. In addition, the determination unit 137 prohibits the image authentication ECU 60 from updating the program when the key authentication ECU 50 and the portable device 5 are unable to communicate. Figure 3 The permission request screen 150 shown is displayed on the touch panel 16 .

[0076] While the key authentication ECU 50 is updating the first program, the determination unit 137 does not permit the image authentication ECU 60 to update the second program. Specifically, the determination unit 137 manages the execution timing of the update processes of the key authentication ECU 50 and the image authentication ECU 60 so that the key authentication ECU 50's update of the first program and the image authentication ECU 60's update of the second program do not overlap.

[0077] [2. Operation of the Central ECU in the First Embodiment]

[0078] Figure 4 1 is a flowchart showing the operation of the central ECU 10. Figure 4 The flowchart shown explains the operation of the central ECU 10 .

[0079] The central ECU 10 determines whether there is an update program downloaded from the server device 300 (step SA1 ). If there is no update program downloaded (step SA1 / No), the central ECU 10 waits until the update program is downloaded from the server device 300 .

[0080] When there is a downloaded update program (step S1A / YES), the central ECU 10 determines whether this downloaded update program is an update program of the second program executed by the image authentication ECU 60 (step SA2).

[0081] When the downloaded update program is not the update program of the second program (step SA2 / No), the central ECU 10 ends this processing flow and executes another processing flow.

[0082] When the downloaded update program is the update program of the second program (step SA2 / Yes), the central ECU 10 determines whether the key authentication ECU 50 is in a state capable of communicating with the portable device 5 (step SA3 ).

[0083] When the key authentication ECU 50 and the portable device 5 are unable to communicate (step SA3 / No), the central ECU 10 does not permit the image authentication ECU 60 to update the second program (step SA11 ), and ends this processing flow.

[0084] When the key authentication ECU 50 and the portable device 5 are able to communicate (step SA3 / Yes), the central ECU 10 causes the touch panel 16 to display a permission request screen 150 requesting the occupant to permit the second program update (step SA4). This permission request screen 150 displays a radio button 151 for permitting the program update, a radio button 153 for rejecting the program update, and an OK button 155. Furthermore, permission request screen 150 displays guidance requesting the removal of the portable device 5 when permitting the program update by the image authentication ECU 60 and moving the device outside the vehicle. To permit the program update, the occupant selects radio button 151 and presses OK button 155.

[0085] The central ECU 10 determines whether a permission operation is received (step SA5 ). If a rejection operation is received but a permission operation is not received (step SA5 / No), the central ECU 10 does not permit the image authentication ECU 60 to update the second program (step SA11 ).

[0086] When the permission operation is received (step SA5 / YES), the central ECU 10 determines whether the occupant has exited the vehicle 3 while carrying the portable device 5 (step SA6). The central ECU 10 detects the occupant's exit based on sensor data from the weight sensor 49. Furthermore, if the communication status between the key authentication ECU 50 and the portable device 5 changes from a communicable state to a non-communicable state, the central ECU 10 determines that the portable device 5 has been taken outside the vehicle upon detecting the occupant's exit.

[0087] When the central ECU 10 determines that the portable device 5 has been taken outside the vehicle (step SA6 / Yes), it permits the program update of the image authentication ECU 60 (step SA10 ), and ends this processing flow.

[0088] If the portable device 5 has not been taken outside the vehicle (step SA6 / No), the central ECU 10 obtains the latitude and longitude information indicating the location of the vehicle 3, as calculated by the GNSS sensor 15. Based on the obtained latitude and longitude information, the central ECU 10 references the map data 113 and obtains facility information for facilities within the site that include the obtained latitude and longitude (step SA7). Furthermore, if no facilities within the site include the obtained latitude and longitude, the central ECU 10 may obtain facility information for facilities within a predetermined range of the latitude and longitude.

[0089] Next, the central ECU 10 obtains a predicted duration of stay at the facility in the obtained facility information based on the occupant's behavioral history (step SA8). For example, the third memory 110 may store the categories of facilities the occupant has previously visited and the average duration of stay at facilities of that category as the occupant's behavioral history. The central ECU 10 obtains the average duration of stay at the facility corresponding to the facility information as the predicted duration.

[0090] Next, the central ECU 10 determines whether the average dwell time obtained in step SA8 is longer than the update time required for the image authentication ECU 60 program update (step SA9). If the predicted dwell time is longer than the update time (step SA9 / Yes), the central ECU 10 permits the image authentication ECU 60 to perform the program update (step SA10). If the predicted dwell time is less than the update time (step SA9 / No), the central ECU 10 disallows the image authentication ECU 60 from performing the program update (step SA11), terminating the process.

[0091] [3. Operation of the Central ECU in the Second Embodiment]

[0092] Next, a second embodiment will be described with reference to the drawings.

[0093] The configuration of the vehicle control system 1 of the second embodiment is the same as that of the first embodiment, and therefore the description of the configuration of the vehicle control system 1 will be omitted.

[0094] In the second embodiment, when the central ECU 10 downloads the update program of the image authentication ECU 60 from the server device 300 , it inquires the key authentication ECU 50 about the communication status with the portable device 5 .

[0095] When the central ECU 10 receives a response from the key authentication ECU 50 indicating that the communication status with the portable device 5 is enabled, the touch panel 16 displays Figure 5The first setting screen 200 is shown. If the central ECU 10 receives a reply from the key authentication ECU 50 that the communication state with the portable device 5 is not communicateable, the touch panel 16 displays Figure 6 The second setting screen 250 is shown.

[0096] Figure 5 1 is a diagram showing an example of a first setting screen 200 that the central ECU 10 displays on the touch panel 16 .

[0097] The first setting screen 200 displays a guidance display notifying the image authentication ECU 60 of a program update. The first setting screen 200 also displays a radio button 211 for selecting "Permit" program update, a radio button 213 for selecting "Reject", and a decision button 215.

[0098] When the passenger approves the program update, the passenger selects the radio button 211 and presses the decision button 215 . When the passenger rejects the program update, the passenger selects the radio button 213 and presses the decision button 215 .

[0099] Figure 6 1 is a diagram showing an example of a second setting screen 250 that the central ECU 10 displays on the touch panel 16. The second setting screen 250 corresponds to a setting screen.

[0100] A first display field 260 , a second display field 270 , and a determination button 280 are displayed on the second setting screen 250 .

[0101] A guidance display notifying the image authentication ECU 60 of a program update is displayed in first display field 260. Also displayed in first display field 260 are a radio button 261 for selecting "Apply" for program updates and a radio button 263 for selecting "Reject." To approve the program update, the occupant selects radio button 261. To disapprove the program update, the occupant selects radio button 263.

[0102] Second display field 270 displays a warning message in the event that the image authentication ECU 60 program update fails. For example, second display field 270 displays a message stating that if the image authentication ECU 60 program update fails, the image authentication ECU 60 may not operate, making it impossible to unlock the doors using facial recognition. Second display field 270 also displays a message asking the occupant whether to lock the doors when exiting the vehicle. Second display field 270 displays a radio button 271 for selecting "Lock" and a radio button 273 for selecting "Unlock." Radio buttons 271 and 273 displayed in second display field 270 are selectable when radio button 261 is selected in first display field 260.

[0103] The passenger selects radio button 261 to approve the image authentication ECU 60 program update. Alternatively, the passenger selects radio button 263 to deny the image authentication ECU 60 program update. Furthermore, the passenger selects radio button 271 to lock the vehicle doors upon exiting the vehicle. Alternatively, the passenger selects radio button 273 to leave the vehicle doors unlocked. The passenger selects radio button 261 or 263, or radio button 271 or 273, and presses enter button 280.

[0104] When the first setting screen 200 is displayed, the communication status between the key authentication ECU 50 and the portable device 5 is enabled. Therefore, even if the image authentication ECU 60 program update is permitted, the occupant can still board the vehicle 3 by operating the portable device 5. Therefore, the central ECU 10 does not display a warning message on the first setting screen 200 in the event that the image authentication ECU 60 program update fails.

[0105] When the key authentication ECU 50 and the portable device 5 are communicating, and the radio button 211 is selected on the first setting screen 200, the central ECU 10 determines that an operation has been received to permit a program update for the image authentication ECU 60. In this case, upon detecting that the occupant has exited the vehicle, the central ECU 10 instructs the region B-ECU 40 to lock the vehicle doors, permitting a program update for the image authentication ECU 60. In response to the instruction from the central ECU 10, the region B-ECU 40 controls the door lock mechanism 47 to lock the doors.

[0106] Furthermore, if the communication status between the key authentication ECU 50 and the portable device 5 is enabled and the radio button 213 is selected in the first setting screen 200, the central ECU 10 determines that a rejection operation has been received to reject the program update of the image authentication ECU 60. In this case, the central ECU 10 prohibits the program update of the image authentication ECU 60 and does not cause the image authentication ECU 60 to execute the program update.

[0107] Furthermore, if the key authentication ECU 50 and the portable device 5 are unable to communicate, and radio buttons 261 and 271 are selected on the second setting screen 250, the central ECU 10 determines that both the permission operation for program updating and the door lock operation have been accepted. In this case, upon detecting the occupant's exit from the vehicle, the central ECU 10 instructs the region B-ECU 40 to lock the vehicle doors and permits the image authentication ECU 60 to update the program. In response to the instruction from the central ECU 10, the region B-ECU 40 controls the door lock mechanism 47 to lock the doors.

[0108] Furthermore, if the key authentication ECU 50 and the portable device 5 are unable to communicate, and if radio buttons 261 and 273 are selected on the second setting screen 250, the central ECU 10 determines that both a permission operation to permit a program update and an unlock operation to prevent the doors from being locked have been accepted. If the central ECU 10 detects the occupant exiting the vehicle, it permits the program update to the image authentication ECU 60 but does not instruct the zone B-ECU 40 to lock the doors.

[0109] Furthermore, upon receiving a permission operation to permit program updates and an unlock operation to prevent the doors from being locked, the central ECU 10 transmits an instruction to the area A-ECU 30 to prohibit the driving of the drive device 31. Furthermore, the central ECU 10 may be configured not to transmit an instruction signal to the area A-ECU 30 to lock the doors of the vehicle 3. Upon receiving the instruction from the central ECU 10, the area A-ECU 30 prohibits the driving of the drive device 31, rendering the vehicle 3 unable to travel. This prevents the theft of the vehicle 3. The prohibition of the driving of the drive device 31 continues, for example, until the occupant operates the portable device 5 and the key authentication ECU 50 receives the key ID from the portable device 5. Furthermore, the prohibition of the driving of the drive device 31 continues, for example, until the program update of the image authentication ECU 60 is completed and the image authentication ECU 60 authenticates the occupant based on images captured by the camera 65.

[0110] If the communication status between the key authentication ECU 50 and the portable device 5 is not established and the radio button 263 is selected on the second setting screen 250, the central ECU 10 determines that a rejection operation for rejecting the program update has been received. In this case, the central ECU 10 prohibits the image authentication ECU 60 from performing the program update and does not cause the image authentication ECU 60 to execute the program update.

[0111] Figure 7 This is a flowchart showing the operation of the central ECU 10 according to the second embodiment.

[0112] Reference Figure 7 The flowchart shown explains the operation of the central ECU 10 .

[0113] The central ECU 10 determines whether there is an update program downloaded from a server (not shown) (step SB1 ). If there is no update program downloaded (step SB1 / No), the central ECU 10 waits until the update program is downloaded from the server.

[0114] When there is a downloaded update program (step SB1 / Yes), the central ECU 10 determines whether the downloaded update program is an update program of the program executed by the image authentication ECU 60 (step SB2 ).

[0115] When the downloaded update program is not the update program for the image authentication ECU 60 (step SB2 / No), the central ECU 10 ends this processing flow and executes another processing flow.

[0116] If the downloaded update program is for the image authentication ECU 60 (step SB2 / Yes), the central ECU 10 inquires of the key authentication ECU 50 whether communication with the portable device 5 is possible. Upon receiving a response from the key authentication ECU 50 confirming that communication with the portable device 5 is possible (step SB3 / Yes), the central ECU 10 causes the touch panel 16 to display the first setting screen 200 (step SB4). The central ECU 10 changes the display of the first setting screen 200 in response to a touch operation on the touch panel 16. For example, the central ECU 10 changes a selected radio button to radio button 211 or 213 in response to the touch operation.

[0117] Next, the central ECU 10 determines whether the decision button 215 is pressed (step SB5 ). If the decision button 215 is not pressed (step SB5 / No), the central ECU 10 waits until the decision button 215 is pressed.

[0118] If the decision button 215 is pressed (step SB5 / Yes), the central ECU 10 determines whether a permission operation for permitting the image authentication ECU 60 to update its program has been accepted on the first setting screen 200 (step SB6). If the permission operation has been accepted (step SB6 / Yes), upon detecting that an occupant has exited the vehicle 3, the central ECU 10 instructs the area B-ECU 40 to lock the doors (step SB7). In response to the instruction from the central ECU 10, the area B-ECU 40 controls the door lock mechanism 47 to lock the doors of the vehicle 3. The central ECU 10 then permits the image authentication ECU 60 to update its program (step SB8).

[0119] If the central ECU 10 does not receive the permission operation for permitting the image authentication ECU 60 program update on the first setting screen 200 (step SB6 / No), it does not permit the image authentication ECU 60 program update (step SB9 ) and ends this processing flow.

[0120] Next, the operation of the central ECU 10 when receiving a response from the key authentication ECU 50 indicating that communication with the portable device 5 is not possible in the determination of step SB3 will be described.

[0121] When receiving a response from the key authentication ECU 50 that communication with the portable device 5 is not possible (step SB3 / No), the central ECU 10 causes the touch panel 16 to display the second setting screen 250 (step SB10 ).

[0122] Next, the central ECU 10 determines whether the decision button 215 is pressed (step SB11 ). When the decision button 215 is not pressed (step SB11 / No), the central ECU 10 waits until the decision button 215 is pressed.

[0123] When the decision button 280 is pressed (step SB11 / Yes), the central ECU 10 determines whether a permission operation for permitting the image authentication ECU 60 to update the program has been accepted on the second setting screen 250 (step SB12). The central ECU 10 determines whether the radio button 261 in the first display field 260 has been selected, and whether the permission operation has been accepted.

[0124] If the central ECU 10 determines that the radio button 263 of the first display field 260 is selected and a rejection operation is accepted (step SB12 / No), it does not permit the image authentication ECU 60 to perform a program update (step SB9 ) and ends this processing flow.

[0125] When the central ECU 10 receives selection of the radio button 261 in the first display field 260 and determines that a permission operation has been received (step SB12 / Yes), it determines whether a setting for locking the doors when exiting the vehicle has been received (step SB13 ).

[0126] Upon receiving a selection of radio button 271 in second display field 270, central ECU 10 determines that the vehicle 3 doors are locked upon exiting the vehicle (step SB13 / Yes). In this case, central ECU 10 instructs region B-ECU 40 to lock the doors (step SB14). Region B-ECU 40 controls door lock mechanism 47 in accordance with the instruction from central ECU 10, locking the vehicle 3 doors. Central ECU 10 then authorizes image authentication ECU 60 to perform a program update (step SB17).

[0127] Furthermore, upon receiving a selection of radio button 273 in second display field 270, central ECU 10 determines that the vehicle 3 door locks have been unlocked upon exit (step SB13 / No). In this case, central ECU 10 transmits an instruction to disable driving device 31 to zone A-ECU 30 (step SB15) and does not instruct zone B-ECU 40 to lock the door locks. Consequently, the vehicle 3 door locks remain unlocked even after the occupant exits the vehicle (step SB16). Subsequently, central ECU 10 authorizes image authentication ECU 60 to perform a program update (step SB17).

[0128] [4. Operation of the Central ECU in the Third Embodiment]

[0129] Next, a third embodiment will be described. The configuration of the vehicle control system 1 is the same as that of the first embodiment described above, and therefore, the description of the configuration of the vehicle control system 1 will be omitted.

[0130] The central ECU 10 of the third embodiment also inquires the key authentication ECU 50 about the communication status with the portable device 5 when downloading the update program for the image authentication ECU 60 from the server device 300. The central ECU 10 of the third embodiment changes the operation when the program update of the image authentication ECU 60 fails, based on the communication status between the key authentication ECU 50 and the portable device 5.

[0131] The central ECU 10 executes the first action when the communication status between the key authentication ECU 50 and the portable device 5 is enabled and the program update of the image authentication ECU 60 fails.

[0132] As a first action, the central ECU 10 sends a failure notification to the portable device 5 held by the driver, the owner of the vehicle 3, as a first notification destination, indicating that the image authentication ECU 60 program update has failed. Furthermore, if the portable device 5 is a smartphone serving as a digital key, the failure notification is sent to the smartphone's registered email address or IP address. This failure notification includes guidance that the portable device 5 needs to unlock the vehicle 3 and start the driving source, such as the engine, installed in the vehicle 3.

[0133] Furthermore, when the central ECU 10 is unable to communicate with the portable device 5 and the program update of the image authentication ECU 60 fails, the central ECU 10 executes the second action.

[0134] As a second operation, the central ECU 10 transmits a failure notification indicating that the program update of the image authentication ECU 60 has failed to a second notification target, wherein the second notification target is the contact information of a portable device owned by a loading service provider or the owner of the vehicle 3, that is, the driver's family.

[0135] Figure 8 1 is a diagram showing an example of the contact destination table 115 in which emergency contact destinations are registered.

[0136] The second notification destination is registered in the contact destination table 115 .

[0137] As the second notification destination, the phone number of the loading service provider company providing the loading service, the email address and phone number of the family of the owner of the vehicle 3, etc. are registered. In addition, when the portable device 5 is a smartphone used as a digital key, the phone number and email address of the owner of the vehicle 3 can also be registered in advance as the first notification destination.

[0138] If communication with the portable device 5 is lost and the image authentication ECU 60 program update fails, the central ECU 10 sends an email containing a failure notification to the email address of the loading service provider or the registered family member's mobile phone. Alternatively, the central ECU 10 may call the loading service provider's phone number or the registered family member's mobile phone to notify the failure, for example, using a voice synthesized by voice synthesis software.

[0139] Furthermore, when the central ECU 10 sends a program update failure notification to the second notification destination, it sends the failure notification including the vehicle 3 location information obtained from the GNSS sensor 15. Including the vehicle 3 location information makes it easier for the loading service provider or the user to locate the vehicle 3.

[0140] Furthermore, if the image authentication ECU 60 program update fails, the central ECU 10 instructs the region B-ECU 40 to unlock the vehicle 3 doors, forcibly unlocking the vehicle 3 doors. There are also cases where a passenger exits the vehicle 3 without the portable device 5. In this case, it is also possible that the image authentication ECU 60 program update failure could prevent the door locks from being unlocked using image authentication. Therefore, the central ECU 10 instructs the region B-ECU 40 to forcibly unlock the vehicle 3 doors.

[0141] Furthermore, the central ECU 10 transmits a prohibition instruction to the area A-ECU 30 to prohibit the driving of the driving device 31. Since the doors of the vehicle 3 remain unlocked, the prohibition instruction is transmitted to the area A-ECU 30 to prevent the vehicle 3 from traveling in order to prevent theft.

[0142] Furthermore, the central ECU 10 continues to supply power from the battery 33 to the TCU 14, maintaining a state in which external communication is possible via the TCU 14. Then, for example, the central ECU 10 causes the touch panel 16 to display the phone number of the loading service provider or the phone number registered as the second notification destination. When the occupant selects a phone number through a touch operation, the central ECU 10 calls the selected phone number, enabling a call.

[0143] Furthermore, the registration of the first and second notification targets can be changed by a touch operation on the touch panel 16 by a passenger or the like. In other words, the notification targets registered as the first and second notification targets can be changed by a touch operation. For example, the phone number of another load service company can be registered as the second notification target, and the email address or phone number of a smartphone held by a passenger, the owner of the vehicle 3, can be registered as the first notification target instead of the mobile device 5.

[0144] Figure 9 and Figure 10 1 is a flowchart showing the operation of the central ECU 10 according to the third embodiment. Figure 9 and Figure 10 The flowchart shown explains the operation of the central ECU 10 .

[0145] The central ECU 10 determines whether an update program has been downloaded from a server (not shown) (step SC1 ). If no update program has been downloaded (step SC1 / No), the central ECU 10 waits until the update program is downloaded from the server.

[0146] When there is a downloaded update program (step SC1 / Yes), the central ECU 10 determines whether the downloaded update program is an update program of the program executed by the image authentication ECU 60 (step SC2 ).

[0147] When the downloaded update program is not the update program for the image authentication ECU 60 (step SC2 / No), the central ECU 10 ends this processing flow and executes another processing flow.

[0148] If the downloaded update program is an update program for the image authentication ECU 60 (step SC2 / Yes), the central ECU 10 inquires the key authentication ECU 50 whether the communication status with the portable device 5 is in a communication-enabled state. If the central ECU 10 receives a reply from the key authentication ECU 50 that the communication with the portable device 5 is in a communication-enabled state (step SC3 / Yes), the touch panel 16 displays Figure 3The first setting screen 200 is shown (step SC4). When the passenger permits the program update, the passenger selects the radio button 151 and presses the decision button 155. When the passenger does not permit the program update, the passenger selects the radio button 153 and presses the decision button 155.

[0149] The central ECU 10 determines whether a permission operation is received (step SC5 ). If a rejection operation is received but a permission operation is not received (step SC5 / No), the central ECU 10 does not allow the image authentication ECU 60 to update the second program (step SC6 ).

[0150] When receiving the permission operation (step SC5 / Yes), the central ECU 10 permits the image authentication ECU 60 to update the program (step SC7 ).

[0151] The central ECU 10 then determines whether the image authentication ECU 60 program update was successful (step SC8). If the image authentication ECU 60 program update was unsuccessful (step SC8 / No), the central ECU 10 notifies the portable device 5 that key authentication by the portable device 5 is required (step SC9). At this point, the central ECU 10 notifies the portable device 5 that the image authentication ECU 60 program update failed.

[0152] If the program update of the image authentication ECU 60 is successful (step SC8 / Yes), the central ECU 10 instructs the image authentication ECU 60 to perform image authentication (step SC10 ). At this time, the central ECU 10 may also send a guidance instructing the portable device 5 to perform face authentication.

[0153] The image authentication ECU 60, in response to instructions from the central ECU 10, causes the camera 65 to capture images and extracts the passenger's facial image from the captured image. The image authentication ECU 60 extracts facial features from the image captured by the camera 65 and authenticates the user based on a comparison of the extracted features with those stored in the second memory 61.

[0154] Next, refer to Figure 10 The flowchart shown here will explain the operation when a response indicating that communication with the portable device 5 is not possible is received from the key authentication ECU 50 in the determination of step SC3 .

[0155] The central ECU 10 causes the touch panel 16 to display Figure 3 The first setting screen 200 is shown (step SC11). When the passenger permits program updating, the passenger selects radio button 151 and presses decision button 155. When the passenger does not permit program updating, the passenger selects radio button 153 and presses decision button 155.

[0156] The central ECU 10 determines whether a permission operation is received (step SC12). If a rejection operation is received but no permission operation is received (step SC12 / No), the central ECU 10 does not allow the image authentication ECU 60 to update the second program (step SC21) and ends this processing flow.

[0157] When receiving the permission operation (step SC12 / Yes), the central ECU 10 permits the image authentication ECU 60 to update the program (step SC13 ) Thereafter, the central ECU 10 determines whether the program update of the image authentication ECU 60 is successful (step SC14 ).

[0158] If the program update of the image authentication ECU 60 is successful (step SC14 / Yes), the central ECU 10 instructs the image authentication ECU 60 to perform image authentication (step SC15) in the same manner as step SC10. At this time, the central ECU 10 may also send a guidance instructing the mobile device 5 to perform face authentication.

[0159] If the image authentication ECU 60 program update fails (step SC14 / No), the central ECU 10 obtains the vehicle 3's location information from the GNSS sensor 15 (step SC16). The central ECU 10 then refers to the contact destination table 115 and notifies the notification destination registered as the second notification destination of the failure to update the image authentication ECU 60 program (step SC17). This notification destination can be a loading service provider or the contact information of the vehicle 3 owner's family members registered in the contact destination table 115.

[0160] Next, the central ECU 10 instructs the zone B-ECU 40 to release the door locks (step SC18 ), thereby forcibly unlocking the doors.

[0161] Next, the central ECU 10 controls the area A-ECU 30 to maintain power supply to the TCU 14, thereby activating the TCU 14. For example, if the central ECU 10 selects the phone number of a company providing an onboarding service by touching the touch panel 16, the central ECU 10 calls the selected number via the TCU 14.

[0162] Furthermore, the central ECU 10 transmits an instruction to prohibit the driving of the driving device 31 to the zone A-ECU 30 (step SC20 ).

[0163] The above-described embodiment is a preferred embodiment of the present invention, but the present invention is not limited thereto and various modifications can be made without departing from the spirit of the present invention.

[0164] For example, Figure 1 The structure of the vehicle control system 1 shown in Figure 2 The structure of the central ECU 10 shown in FIGURE 1 illustrates a functional structure, and its specific implementation is not particularly limited. Specifically, it is not necessary to install hardware corresponding to each functional unit. Alternatively, a single processor executing a program can implement the functions of multiple functional units. Furthermore, in the above-described embodiments, a portion of the functions implemented by software can be implemented by hardware, and vice versa.

[0165] in addition, Figure 4 、 Figure 7 、 Figure 9 as well as Figure 10 The processing units in the flowchart shown are units divided according to the main processing contents in order to facilitate understanding of the processing of the central ECU 10. The present invention is not limited to Figure 4 、 Figure 7 、 Figure 9 as well as Figure 10 The method of dividing the processing units shown in the flowcharts and the name restrictions are not applicable. Furthermore, depending on the processing content, the processing of the central ECU 10 may be divided into more processing units, or a single processing unit may be divided to include more processing. Furthermore, the processing order of the flowcharts is not limited to the example shown.

[0166] [5. Structure supported by the above-mentioned embodiment]

[0167] The above-mentioned embodiment is a specific example of the following structure.

[0168] (Structure 1)

[0169] A vehicle control system includes: a first control device, which obtains first authentication information through wireless communication with a portable device and controls locking and unlocking of the vehicle based on the first authentication information obtained; a second control device, which obtains second authentication information based on an image captured by a camera and controls locking and unlocking of the vehicle based on the second authentication information obtained; and an update management device, which has a determination unit, which determines whether to permit the update of a second program executed by the second control device based on the communication status between the first control device and the portable device.

[0170] The vehicle control system of Configuration 1 determines whether to permit an update of the second program executed by the second control device based on the communication status between the first control device and the portable device. For example, if the first control device and the portable device are unable to communicate, the second program executed by the second control device is not permitted to be updated. This reduces the likelihood of passengers being unable to board or operate the vehicle until the second program update is complete. Consequently, passenger convenience can be improved.

[0171] (Structure 2)

[0172] According to the vehicle control system of Configuration 1, the determination unit permits updating of the second program when the first control device and the portable device are in a state capable of communicating.

[0173] The vehicle control system of Configuration 2 permits updating of the second program when the first control device and the portable device are in a state capable of communicating. Since the first control device and the portable device are in a state capable of communicating, even if updating of the second program is permitted, the first control device obtains the first authentication information from the portable device and controls locking and unlocking of the vehicle, thereby reducing the occurrence of situations in which passengers are unable to board the vehicle or operate the vehicle.

[0174] (Structure 3)

[0175] According to the vehicle control system of structure 1 or 2, wherein the vehicle control system has an on-board display device mounted on the vehicle, the determination unit prohibits displaying a guidance screen for guiding the update of the second program on the on-board display device, or prohibits the update of the second program when the first control device cannot communicate with the portable device.

[0176] The vehicle control system of Configuration 3 prohibits displaying the guidance screen for updating the second program on the vehicle display device when the first control unit and the portable device are unable to communicate. Furthermore, updating the second program is prohibited. Therefore, if the first control unit and the portable device are unable to communicate, the second program can be prevented from being updated, reducing the likelihood of passengers being unable to board or operate the vehicle until the second program update is complete. This improves passenger convenience.

[0177] (Structure 4)

[0178] The vehicle control system according to any one of Structures 1 to 3, wherein the determination section permits updating of the second program when the first control device detects that the portable device has moved from inside to outside of the vehicle.

[0179] In the vehicle control system of Configuration 4, when the first control unit detects that the portable device has been moved from inside the vehicle to outside, the second program update is permitted. Since the portable device is outside the vehicle, the vehicle can be unlocked using the portable device, thereby reducing the likelihood of passengers being unable to board or drive the vehicle until the second program update is complete. Consequently, passenger convenience can be improved.

[0180] (Structure 5)

[0181] A vehicle control system according to any one of structures 1 to 4, wherein the vehicle control system includes a position detection device for detecting the position of the vehicle, and the update management device includes: an getting-off detection unit for detecting that an occupant has gotten off the vehicle; and a storage unit for storing map data, and when the getting-off detection unit detects that the occupant has gotten off the vehicle and the first control device determines that the portable device is inside the vehicle, the determination unit obtains facility information from the map data based on the position of the vehicle, and based on the obtained facility information, determines whether the vehicle has been parked at the position of the vehicle for more than a pre-set set time, and when it is determined that the vehicle has been parked for more than the set time, the update of the second program is permitted.

[0182] The vehicle control system of Configuration 5, when a passenger exits the vehicle while a portable device is inside the vehicle, obtains facility information from map data based on the vehicle's location and, based on the obtained facility information, determines whether the vehicle has been parked at the vehicle's location for a predetermined time period or longer. Furthermore, if it is determined that the vehicle has been parked at the vehicle's location for a predetermined time period or longer, the second program update is permitted. This reduces the likelihood of passengers being unable to board or operate the vehicle due to the second program update. Consequently, passenger convenience can be improved.

[0183] (Structure 6)

[0184] According to the vehicle control system of structure 5, the determination unit obtains a predicted parking time of the vehicle at the location of the vehicle based on the category of the facility represented by the facility information, and permits the update of the second program when the obtained predicted time is longer than the update time required for the update of the second program as the set time.

[0185] The vehicle control system of configuration 6 obtains a predicted parking time for the vehicle at the vehicle's location based on the acquired facility type, and permits the update of the second program if the acquired predicted time is longer than the update time required for the second program. Therefore, it is possible to reduce the possibility of an occupant unlocking the vehicle using the second authentication information during the second program update.

[0186] (Structure 7)

[0187] The vehicle control system according to any one of claims 1 to 6, wherein the vehicle control system includes an on-vehicle display device mounted on the vehicle, and the determination unit causes the on-vehicle display device to display a guidance screen for guiding the update of the second program and a take-out request for taking the portable device out of the vehicle.

[0188] The vehicle control system of configuration 7 causes the onboard display device to display a guidance screen for updating the second program and a request to remove the portable device from the vehicle. This allows passengers to be notified that the second program has been updated, prompting them to remove the portable device from the vehicle. This reduces the likelihood of passengers being unable to board or operate the vehicle due to the second program update, thereby improving passenger convenience.

[0189] (Structure 8)

[0190] According to a vehicle control system of structure 1, the vehicle control system includes a position detection device for detecting the position of the vehicle, and the determination unit determines whether to permit the update of the second program executed by the second control device based on the communication status between the first control device and the portable device when the location detected by the position detection device is a location other than a pre-registered location.

[0191] The vehicle control system of Configuration 8 determines whether to permit the second program update executed by the second control device based on the communication status between the first control device and the portable device when the location detected by the position detection device is not registered as the home location. Even if the second control device is updating the second program when the vehicle's location is registered as the home location, the user can remove a portable device, such as a spare device, from the home location to unlock the vehicle. Therefore, when the vehicle's location is not registered as the home location, whether to permit the second program update executed by the second control device is determined based on the communication status between the first control device and the portable device. This effectively reduces the occurrence of situations where passengers are unable to board the vehicle or operate the vehicle.

[0192] (Structure 9)

[0193] A vehicle control system according to any one of structures 1 to 8, wherein the determination unit manages updates of the first control device and the second control device so that updates of a first program performed by the first control device do not overlap with updates of the second program performed by the second control device, and the first program is executed by the first control device.

[0194] The vehicle control system of Configuration 9 manages updates of the first and second control devices so that updates of the first program by the first control device and updates of the second program by the second control device do not overlap. This reduces the likelihood of the vehicle being locked or unlocked due to program updates being executed by the first and second control devices.

[0195] (Structure 10)

[0196] A control method for a vehicle control system, the vehicle control system comprising: a first control device, which obtains first authentication information through wireless communication with a portable device, and controls locking and unlocking of the vehicle based on the first authentication information obtained; a second control device, which obtains second authentication information based on an image captured by a camera, and controls locking and unlocking of the vehicle based on the second authentication information obtained; and an update management device, which manages updates of programs executed by the first control device and the second control device, wherein the control method includes the following processing: a processor mounted on the update management device determines whether to permit the update of the second program executed by the second control device based on the communication status between the first control device and the portable device.

[0197] The vehicle control system control method of configuration 10 determines whether to permit an update of a second program executed by a second control device based on the communication status between the first control device and the portable device. For example, if the first control device and the portable device are unable to communicate, the second program executed by the second control device is not permitted to be updated. This reduces the likelihood of passengers being unable to board or operate the vehicle until the second program update is complete. Consequently, passenger convenience can be improved.

[0198] Description of Reference Numerals

[0199] 1…Vehicle Control System, 3…Vehicle, 3a…First Communication Line, 3b…First Communication Line, 4a…Second Communication Line, 4b…Second Communication Line, 5…Portable Device, 10…Central ECU, 11…ICB, 12…Speaker, 13…Microphone, 14…TCU, 15…GNSS Sensor, 16…Touch Panel, 17…Display, 18…Touch Sensor, 19…In-Vehicle Connectivity Link, 20…DMC, 30…Area A-ECU, 31…Drive Unit, 33…Battery, 40…Area B-ECU, 41…Lamp Body, 43…Window Motor, 45…Door Sensor, 47…Door Lock Mechanism, 49…Weight Sensor, 50…Key Authentication ECU, 51…First Memory, 53…First Processor, 55…LF / RF Antenna, 60…Image Authentication ECU, 61… 1…Second memory, 63…Second processor, 65…Camera, 110…Third memory, 111…Third program, 113…Map data, 115…Contact target table, 130…Third processor, 131…Information acquisition unit, 133…Get-off detection unit, 135…Program update unit, 137…Determination unit, 150…Permission request screen, 151…Radio button, 153…Radio button, 155…Decision button, 200…First setting screen, 211…Radio button, 213…Radio button, 215…Decision button, 250…Second setting screen, 260…First display field, 261…Radio button, 263…Radio button, 270…Second display field, 271…Radio button, 273…Radio button, 280…Decision button, 300…Server device, 350…Network.

Claims

1. A vehicle control system, comprising: a first control device that obtains first authentication information through wireless communication with the portable device and controls locking and unlocking of the vehicle based on the obtained first authentication information; a second control device, which obtains second authentication information based on the image captured by the camera and controls locking and unlocking of the vehicle based on the obtained second authentication information; as well as The update management device includes a determination unit that determines whether to permit the update of the second program executed by the second control device based on a communication state between the first control device and the portable device.

2. The vehicle control system according to claim 1, wherein: The determination unit permits updating of the second program when the first control device and the portable device are in a state capable of communicating.

3. The vehicle control system according to claim 1 or 2, wherein: The vehicle control system includes an on-vehicle display device mounted on the vehicle. The determination unit prohibits displaying a guidance screen for guiding the update of the second program on the in-vehicle display device, or prohibits the update of the second program, when the first control device and the portable device cannot communicate.

4. The vehicle control system according to claim 2, wherein: The determination unit permits updating of the second program when the first control device detects that the portable device has moved from inside the vehicle to outside the vehicle.

5. The vehicle control system according to claim 1, wherein: The vehicle control system includes a position detection device that detects the position of the vehicle. The update management device comprises: an alighting detection unit configured to detect an occupant alighting from the vehicle; and a storage unit storing map data, When the getting-off detection unit detects the passenger getting off the vehicle and the first control device determines that the portable device is inside the vehicle, the determination unit obtains facility information from the map data based on the position of the vehicle, and based on the obtained facility information, determines whether the vehicle has been parked at the position of the vehicle for more than a pre-set time. When it is determined that the vehicle has been parked for more than the set time, updating of the second program is permitted.

6. The vehicle control system according to claim 5, wherein: The determination unit obtains a predicted parking time of the vehicle at the location of the vehicle based on the type of the facility indicated by the facility information, and permits the update of the second program if the obtained predicted time is longer than the update time required for the update of the second program, which is the set time.

7. The vehicle control system according to claim 1, wherein: The vehicle control system includes an on-vehicle display device mounted on the vehicle. The determination unit causes the in-vehicle display device to display a guidance screen for guiding the update of the second program and a take-out request for taking the portable device outside the vehicle.

8. The vehicle control system according to claim 1, wherein: The vehicle control system includes a position detection device that detects the position of the vehicle. The determination unit determines whether to permit updating of the second program executed by the second control device based on a communication state between the first control device and the portable device when the location detected by the position detection device is other than a pre-registered location.

9. The vehicle control system according to claim 1, wherein: The determination unit manages updates of the first control device and the second control device so that updates of a first program executed by the first control device and updates of the second program executed by the second control device do not overlap.

10. A control method for a vehicle control system, the vehicle control system comprising: a first control device that obtains first authentication information through wireless communication with a portable device and controls locking and unlocking of the vehicle based on the obtained first authentication information; a second control device that obtains second authentication information based on an image captured by a camera and controls locking and unlocking of the vehicle based on the obtained second authentication information; and an update management device that manages updates of programs executed by the first control device and the second control device, wherein: The control method includes the following processing: The processor mounted on the update management device determines whether to permit the update of the second program executed by the second control device based on the communication status between the first control device and the portable device.

Citation Information

Patent Citations

  • Program rewriting system

    JP2006082648A