Vehicle management system, vehicle management method, and vehicle management program
By obtaining and storing the key information authentication code in the vehicle management system, the problem of the anti-theft device not being able to be deactivated in time after the user authorizes operation permissions is solved, and the convenience of remote start is realized.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- TOYOTA JIDOSHA KK
- Filing Date
- 2025-09-24
- Publication Date
- 2026-05-15
AI Technical Summary
In the designated area, when a user delegates vehicle operation authority to the vehicle management system, existing technology cannot quickly disarm the anti-theft device after the user leaves the vehicle, resulting in the driving system failing to start in a timely manner.
The vehicle management system obtains key information from the user terminal and saves the authentication code, which is used to unlock the anti-theft device and enable remote starting.
Without requiring the user to wait near the vehicle, the vehicle management system can quickly disarm the anti-theft device, allowing the driving system to start promptly.
Smart Images

Figure CN122034901A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to technology for controlling a vehicle that performs actions according to remote instructions within a predetermined area. Background Technology
[0002] Patent document 1 discloses a vehicle monitoring device for monitoring vehicles in their parking positions. The vehicle monitoring device switches between a vehicle location notification mode and an anti-theft mode according to a mode switching instruction.
[0003] Existing technical documents
[0004] Patent documents
[0005] Patent Document 1: Japanese Patent Application Publication No. 2015-083415 Summary of the Invention
[0006] The problem that the invention aims to solve
[0007] When a user delegates vehicle operation rights to the vehicle management system within a designated area (e.g., a parking lot), the user's terminal sends a handover start request to the vehicle management system. The user can then leave the vehicle. However, the vehicle management system needs to complete pre-defined processes, such as identifying the vehicle as the object of remote operation, from the start of the handover process according to the handover start request until the vehicle's driving system startup request is sent to the vehicle. This pre-defined process takes time; if the user holding the vehicle key leaves the vehicle before the driving system startup request is sent, the vehicle management system cannot deactivate the anti-theft device required to start the driving system.
[0008] This disclosure was made in view of the aforementioned issues, and its purpose is to provide a technology that allows the anti-theft device to be deactivated without the user having to wait near the vehicle when the user delegates the operation of the vehicle to the vehicle management system within a predetermined area.
[0009] Technical solutions for solving the problem
[0010] The vehicle management system disclosed herein manages vehicles within a predetermined area. The vehicle management system includes one or more processors and one or more storage devices. In response to a handover start request from a user terminal storing key information for functioning as a digital key to the vehicle, one or more processors initiate a handover process that transfers vehicle operation privileges from the user to the vehicle management system. Upon the handover start request being issued, the processor retrieves the key information from the user terminal and stores it in one or more storage devices. The key information includes an authentication code used to unlock the vehicle's driving system, which is controlled by a vehicle anti-theft device. When the driving system is started, the one or more processors send the authentication code along with a driving system start request to the vehicle's control device, causing the control device to unlock the start restriction.
[0011] The vehicle management method disclosed herein is a method for managing vehicles within a predetermined area, executed by a computer. The vehicle management method includes: initiating a handover process to transfer vehicle operation rights from the user to a vehicle management system in response to a handover start request from a user terminal storing key information that functions as a digital key for the vehicle; and retrieving the key information from the user terminal and storing it in one or more storage devices of the vehicle management system when the handover start request is issued. The key information includes an authentication code used to unlock the vehicle's driving system, which is enabled by a vehicle anti-theft device. The vehicle management method further includes: when the driving system is started, sending the authentication code along with a driving system start request to the vehicle's control device, causing the control device to unlock the start restriction.
[0012] The vehicle management program disclosed herein is a program for managing vehicles within a predetermined area, executed by a computer. The vehicle management program causes the computer to perform: in response to a handover start request from a user terminal storing key information that functions as a digital key for the vehicle, initiating a handover process that transfers vehicle operation rights from the user to the vehicle management system; and, upon the handover start request being issued, retrieving the key information from the user terminal and storing it in one or more storage devices of the vehicle management system. The key information includes an authentication code used to unlock the vehicle's driving system, which is enabled by a vehicle anti-theft device. The vehicle management program also causes the computer to perform: upon starting the driving system, sending the authentication code along with a driving system start request to the vehicle's control device, causing the control device to unlock the start restriction.
[0013] The effects of the invention
[0014] According to this disclosure, when the vehicle's driving system is started, the vehicle management system, upon issuing a handover start request, sends the authentication code contained in the key information obtained from the user terminal along with the driving system start request to the vehicle's control device, causing the control device to release the driving system start prohibition based on the anti-theft device. Therefore, the vehicle management system can start the driving system without requiring the user to wait near the vehicle until the vehicle management system starts the driving system after the handover process is completed. Attached Figure Description
[0015] Figure 1 This is a conceptual diagram used to illustrate the outline of the vehicle control system involved in the implementation method.
[0016] Figure 2 It is shown Figure 1 The diagram shows a block diagram of an example of a vehicle management system.
[0017] Figure 3 It is shown Figure 1 The diagram shows an example of the configuration of a vehicle system.
[0018] Figure 4 This is a flowchart illustrating an example of the process performed by a vehicle management system according to an embodiment in connection with the "deactivation of an anti-theft device using key information borrowed from a user terminal".
[0019] Figure 5 This is a flowchart illustrating an example of the process performed by the vehicle's control unit upon receiving key information from the vehicle management system.
[0020] Figure 6 This is a flowchart illustrating another example of the process performed by the vehicle management system involved in the implementation method in association with the "deactivation of the anti-theft device using key information borrowed from the user terminal".
[0021] Figure 7 This is a diagram illustrating the first example of how key information is obtained and saved.
[0022] Figure 8 This is the second example of a diagram showing the path to obtaining key information and the destination for saving it.
[0023] Figure 9 This is the third example of a diagram showing the path to obtaining key information and the destination for saving it.
[0024] Explanation of reference numerals in the attached figures
[0025] 1: Vehicle; 2: Parking lot; 3: Drop-off area; 4: Boarding area; 10: Vehicle management system; 11: Local management device; 12: Management server; 13: Infrastructure sensors; 20: Vehicle system; 21: Control device; 22: Sensors; 23: Driving system; 30: User terminal; 31: Digital key; 100: Vehicle control system; 111, 121, 211: Communication I / F; 112, 122, 212: Processor; 113, 123, 213: Storage device. Detailed Implementation
[0026] The embodiments of this disclosure will be described with reference to the accompanying drawings.
[0027] 1. Overview of Vehicle Control Systems
[0028] Figure 1 This is a conceptual diagram illustrating the outline of the vehicle control system 100 according to this embodiment. The vehicle control system 100 controls a vehicle 1. The vehicle 1 is configured to operate within a predetermined area according to a remote instruction INS. The predetermined area is, for example, an area where the vehicle 1 can drive autonomously, and the vehicle 1 drives autonomously within the predetermined area according to the remote instruction INS. The vehicle control system 100 includes a vehicle management system 10 (hereinafter also simply referred to as management system 10) and a vehicle system 20 mounted on the vehicle 1. The management system 10 manages the vehicle 1 within the predetermined area. The management of the vehicle 1 based on the management system 10 includes generating remote instruction INS. More specifically, the management system 10 manages the autonomous driving (unmanned driving) of the vehicle 1 within the predetermined area.
[0029] 1-1. Automated Valet Parking (AVP)
[0030] exist Figure 1 In the example shown, the designated area is parking lot 2. In this example, the vehicle control system 100 is equivalent to an automated valet parking system that performs AVP (Automated Valet Parking) on vehicle 1 in parking lot 2. However, the designated area is not limited to parking lot 2; for example, it could be a block or part of a smart city. The following description uses parking lot 2 as an example of a designated area.
[0031] Vehicle 1 is configured to perform AVP (Automated Vehicle Operation) within parking lot 2. Vehicle 1 can drive automatically, at least within parking lot 2, without relying on user driving operations. More specifically, the automatic driving of vehicle 1 within parking lot 2 is controlled, for example, by a management system 10 utilizing infrastructure sensors 13. Alternatively, automatic driving can also be controlled, for example, through cooperation between the management system 10 and vehicle system 20. Furthermore, vehicle 1 can also be an autonomous vehicle capable of driving automatically outside parking lot 2.
[0032] Parking lot 2 includes an alighting area 3, a boarding area 4, and a parking area 5. Vehicles 1 entering parking lot 2 stop at the stopping position (alighting frame) 6 located in the alighting area 3, where users alight from vehicle 1. Conversely, vehicles 1 exiting parking lot 2 stop in the boarding area 4, where users board vehicle 1. The alighting area 3 can also be referred to as the entry area, and the boarding area 4 as the exit area. The alighting area 3 and the boarding area 4 can be configured as follows: Figure 1 The areas can be set up separately as shown, or they can be set up without distinguishing between boarding and alighting areas. Parking area 5 includes passageway 7 and multiple parking spaces 8. Passageway 7 is the area for vehicles 1 to drive through. Parking spaces 8 are the spaces for vehicles 1 to park.
[0033] The management system 10 manages the AVPs of vehicles 1 in the parking lot 2. As an example, the management system 10 includes a local management device 11 and a management server 12 in the cloud.
[0034] Local management device 11 is set up for each parking lot 2. Local management device 11 performs the following processing, for example: Local management device 11 uses infrastructure sensors 13 to monitor the status of parking lot 2 (e.g., the location and status of each vehicle 1 within parking lot 2). Local management device 11 assigns parking spaces 8 to vehicles 1. Local management device 11 generates remote indication INS, communicates with vehicles 1, and sends the generated remote indication INS to vehicles 1.
[0035] Management server 12 oversees the local management devices 11 of multiple parking lots 2. For example, management server 12 may include three servers: OB, VB, and UB. Server OB is provided for each parking lot 2. Server OB manages the parking lot 2 (e.g., reservation of parking space 8, entry and exit of vehicle 1) and the driving control permissions of vehicle 1. Additionally, server OB communicates with the corresponding local management device 11 to collect and provide various information. Server VB manages the remote operation permissions (e.g., power operation permissions) of vehicle 1. Furthermore, server VB communicates with vehicle 1 to collect various vehicle management information (e.g., information indicating the status of vehicle 1, vehicle identification information (vehicle ID)) and provide various information (e.g., AVP's movement status). Server UB manages users of the Automated Valet Parking Service (AVP service) (including user authentication) and manages user AVP service reservations. Server UB communicates with the user terminal 30 operated by the AVP service user. User terminal 30 is, for example, a terminal held by the user (e.g., a smartphone). User membership information is pre-registered in server UB. In addition, server UB communicates with each server of server OB and server VB, and sends and receives various kinds of information between them.
[0036] The following is an example of the process when a user X uses the AVP service.
[0037] First, user X makes an AVP reservation. For example, user X uses user terminal 30 to input user ID information, desired parking lot 2, desired date of use, and desired time of use. User terminal 30 sends the reservation information, including the input information, to management system 10 (server UB). Management system 10 processes the reservation based on the reservation information and sends a reservation completion notification to user terminal 30. Additionally, management system 10 sends authentication information corresponding to the reservation information to user terminal 30. User terminal 30 accepts and retains the accepted authentication information.
[0038] Vehicle 1's entry (entry registration) into parking lot 2 is as follows. For example... Figure 1 As illustrated, vehicle 1 carrying user X arrives at drop-off area 3 of parking lot 2 and stops at stop position 6. In drop-off area 3, user X (and other passengers, if any) disembarks from vehicle 1.
[0039] To initiate automated driving of vehicle 1 in AVP (hereinafter referred to as "AVP driving") based on remote instruction INS from management system 10, the operating authority of vehicle 1 needs to be transferred from user X to management system 10. For this transfer of operating authority, user X operates user terminal 30 to send a handover start request to management system 10 (server UB). More specifically, it is envisioned that user X initiates the handover start request essentially after disembarking from vehicle 1, after vehicle 1 arrives at disembarkation area 3. However, the handover start request can also be initiated by user X before disembarking from vehicle 1. The handover start request is sent, for example, along with user X's authentication information.
[0040] In response to the handover start request sent from user terminal 30, management system 10 (server UB) authenticates user X. When the authentication is completed, management system 10 (local management device 11) begins the handover process (permission transfer process) to transfer the operating permissions of vehicle 1 from user X to management system 10.
[0041] The handover process includes, for example, the process of establishing wireless communication between the management system 10 and vehicle 1 (vehicle system 20), and the process of identifying vehicle 1 as the target vehicle for this AVP (vehicle identification process). Target vehicle identification (authentication) is necessary to confirm that vehicle 1, which is to receive the AVP service, is the legitimate vehicle 1 of user X (target vehicle). As an example, vehicle identification can also be performed using a predetermined behavior of vehicle 1 (e.g., blinking of vehicle 1's lights). If vehicle 1 is a legitimate target vehicle, it is expected that vehicle 1 will perform the predetermined behavior as instructed by the management system 10. After this instruction is given, the management system 10 uses infrastructure sensors 13 to identify the behavior performed by vehicle 1. And, if the identified behavior matches the expected behavior, the management system 10 identifies vehicle 1, which performed the identified behavior, as the target vehicle.
[0042] When the handover process is complete, the operating authority of vehicle 1 is transferred from user X to management system 10. Management system 10 (local management device 11) performs the parking process related to vehicle 1. During the parking process, management system 10 communicates with vehicle 1 and sends a remote instruction INS (start request) requesting the activation (power on of driving system 23) of vehicle 1's driving system 23. Vehicle 1 automatically activates driving system 23 according to the received remote instruction INS, provided that the anti-theft device (described later) can be deactivated. Furthermore, after allocating vacant parking spaces 8 to vehicle 1 based on the utilization status of parking lot 2, management system 10 generates a target path for vehicle 1 from drop-off area 3 to the allocated parking space 8. Management system 10 then communicates with vehicle 1, sending a remote instruction INS requesting AVP driving along the generated target path towards parking space 8, along with the target path information, to vehicle 1.
[0043] Vehicle 1 follows the target path received from the management system 10 and performs AVP (Automatic Vehicle Assist) towards its assigned parking space 8, automatically parking in the space (parking complete). When vehicle 1 completes parking, it notifies the management system 10 that parking is complete. Alternatively, the management system 10 can use infrastructure sensors 13 installed in the parking lot 2 to detect when vehicle 1 has completed parking. After vehicle 1 completes parking, the management system 10 (local management device 11) communicates with vehicle 1, sending a remote instruction INS requesting the power to the driving system 23 to be disconnected. Vehicle 1 automatically disconnects the power according to the received remote instruction INS. Additionally, the management system 10 (server OB) maintains information about the parking space 8 where vehicle 1 is parked in association with user X. Furthermore, the management system 10 (local management device 11) sometimes performs AVP on vehicle 1 during parking to allow it to move to other parking spaces 8.
[0044] The departure (departure registration) of vehicle 1 from parking lot 2 is as follows: User X operates user terminal 30 and sends a departure request for vehicle 1 to management system 10 (server UB). The departure request includes user X's authentication information. In response to the departure request, management system 10 (server UB) authenticates user X. When the authentication is completed, management system 10 (local management device 11) performs the departure processing related to vehicle 1.
[0045] During the outbound processing, the management system 10 communicates with vehicle 1 and executes a remote instruction INS (start request) requesting the activation (power on) of vehicle 1's driving system 23. Vehicle 1 automatically activates its driving system 23 according to the received remote instruction INS, provided the anti-theft device can be deactivated. Furthermore, after allocating an empty parking space 9 in the passenger area 4 to vehicle 1 based on the utilization status of parking lot 2, the management system 10 generates a target path for vehicle 1 from its parking space 8 to the allocated parking space 9. The management system 10 then communicates with vehicle 1, sending a remote instruction INS requesting AVP (Automated Guided Vehicle) travel along the generated target path towards the parking space 9, along with the target path information, to vehicle 1.
[0046] Vehicle 1 travels via AVP towards its assigned ride frame 9 according to the received target path. When vehicle 1 arrives at ride area 4 and automatically stops within its assigned ride frame 9, vehicle 1 notifies management system 10 of its arrival at ride area 4. Alternatively, management system 10 may use infrastructure sensors 13 located in ride area 4 to detect the arrival of vehicle 1.
[0047] After vehicle 1 arrives at boarding area 4, user X sends a handover start request to management system 10 (server UB) to transfer (return) control of vehicle 1 from management system 10 to user X. In response to the handover start request sent from user terminal 30, management system 10 (server UB) authenticates user X. When authentication is complete, management system 10 (local management device 11) begins the handover process. When the handover process is complete, user X (and other passengers, if any) board vehicle 1. Vehicle 1 departs for its next destination and exits parking lot 2 (exit complete).
[0048] 2. System Configuration Example
[0049] As described above, the vehicle control system 100 includes a vehicle management system 10 and a vehicle system 20.
[0050] 2-1. Vehicle Management System
[0051] Figure 2 It is shown Figure 1The diagram shows a configuration example of a vehicle management system 10. The management system 10 includes a local management device 11, a cloud-based management server 12, and one or more infrastructure sensors 13 (hereinafter simply referred to as infrastructure sensors 13). The infrastructure sensors 13 are as follows... Figure 1 As shown, various locations are set up in parking lot 2. Infrastructure sensors 13, such as infrastructure cameras, identify the status of parking lot 2, which includes drop-off area 3 and passenger area 4. The information obtained by infrastructure sensors 13 is sent to local management device 11.
[0052] The local management device 11 includes a communication interface (communication I / F) 111, one or more processors 112 (hereinafter simply referred to as processors 112), and one or more storage devices 113 (hereinafter simply referred to as storage devices 113). Furthermore, the one or more processors 112 are equivalent to an example of "one or more first processors" involved in this disclosure.
[0053] The communication I / F111 communicates with the vehicle 1 (vehicle system 20), the management server 12 (server OB), and the infrastructure sensors 13 via a communication network. Additionally, the communication I / F111 can also communicate directly with the user terminal 30 (e.g., WiFi). Furthermore, the user terminal 30 functions as the key (i.e., digital key) 31 of the vehicle 1, as described later. The communication I / F111 can also be configured to communicate with the user terminal 30 (digital key 31) using the same communication method as the digital key 31 and the communication Ckey of the vehicle 1 described later.
[0054] Processor 112 performs various processes. Examples of processor 112 include general-purpose processors, application-specific processors, CPUs (Central Processing Units), GPUs (Graphics Processing Units), ASICs (Application Specific Integrated Circuits), FPGAs (Field-Programmable Gate Arrays), integrated circuits, existing circuits, and / or combinations thereof. Processor 112 may also be referred to as a circuit or processing circuit. A circuit is hardware programmed to perform the described functions or hardware that performs functions. Storage device 113 stores various information. Examples of storage device 113 include volatile memory, non-volatile memory, HDDs (Hard Disk Drives), SSDs (Solid State Drives), etc.
[0055] The functions of the local management device 11 can be achieved through the cooperation of a processor 112 executing a computer program (equivalent to the "vehicle management program" involved in this disclosure) and a storage device 113. The computer program is stored in the storage device 113. Alternatively, the computer program may be recorded on a computer-readable recording medium or provided via a network.
[0056] The management server 12 (more specifically, for example, each of the three servers OB, VB and UB) includes a communication I / F 121, one or more processors 122 (hereinafter simply referred to as processor 122) and one or more storage devices 123 (hereinafter simply referred to as storage device 123).
[0057] The communication I / F121 communicates with the local management device 11, the vehicle 1 (vehicle system 20) and the user terminal 30 via a communication network.
[0058] The configuration of processor 122 is the same as that of processor 112 described above. Similarly, the configuration of storage device 123 is the same as that of storage device 113 described above. For example, storage device 123 of server OB stores information about a predetermined area (e.g., parking lot 2) (e.g., map information of parking lot 2, entry and exit time information of parking lot 2). Storage device 123 of server VB stores the aforementioned vehicle management information. Storage device 123 of server UB stores user information (e.g., identification information (user ID) of each user, service reservation information). The functions of managing server 12 (e.g., servers OB, VB, and UB) can also be achieved through the cooperation of processor 122 executing a computer program (equivalent to the "vehicle management program" involved in this disclosure) and storage device 123. This computer program is stored in storage device 123. Alternatively, the computer program may be recorded on a computer-readable recording medium or provided via a network.
[0059] 2-2. Vehicle System
[0060] Figure 3 It is shown Figure 1 The diagram shows a configuration example of the vehicle system 20. The vehicle system 20 is mounted on the vehicle 1 and includes a control device 21, sensors 22, and a driving system 23.
[0061] The control device 21 controls the vehicle 1 according to various remote instructions INS. The control device 21 includes a communication I / F 211, one or more processors 212 (hereinafter referred to as processor 212) and one or more storage devices 213 (hereinafter referred to as storage device 213).
[0062] The communication I / F211 communicates with the management system 10 (more specifically, the local management device 11 and the management server 12 (server VB)) via a communication network. Additionally, the communication I / F211 communicates with the digital key 31 of the vehicle 1 (more specifically, the user terminal 30 that functions as the digital key 31), as described later via a communication Ckey. Furthermore, the communication I / F211 can also communicate directly with the user terminal 30 (e.g., via WiFi).
[0063] The configuration of processor 212 is the same as that of processor 112 described above. Similarly, the configuration of storage device 213 is the same as that of storage device 113 described above. The functions of control device 21 can also be achieved through the cooperation of processor 212 executing a computer program and storage device 213. This computer program is stored in storage device 213. Alternatively, the computer program can be recorded on a computer-readable recording medium or provided via a network.
[0064] The vehicle system 20 functions as an anti-theft device to prevent unauthorized activation of the driving system 23. For example, the control device 21 has this function. Specifically, a user terminal 30 (e.g., a smartphone) held by user X stores key information Ikey for functioning as the digital key 31 of the vehicle 1. Furthermore, the user terminal 30 is configured to function as the digital key 31, eliminating the need for a physical key. More specifically, the user terminal 30 functions as a transponder for the digital key 31. That is, the user terminal 30 communicates with the vehicle 1 (control device 21) via Ckey as a transponder. The key information Ikey stored in the user terminal 30 contains the authentication code AC inherent to the digital key 31. This authentication code AC is also stored in the storage device 213 of the control device 21. The communication Ckey between the vehicle system 20 (control device 21) and the digital key 31 is a near-field wireless communication (e.g., UWB (Ultra Wideband), Bluetooth (registered trademark), NFC (Near Field Communication)).
[0065] When the driving system 23 is started, if an authentication code AC is received from the digital key 31, the control device 21 (processor 212) compares the received authentication code AC from the digital key 31 with the authentication code AC stored in the storage device 213. If these authentication codes AC match, the control device 21 allows the driving system 23 to start. In other words, the control device 21 removes the start restriction on the anti-theft driving system 23.
[0066] Sensor category 22 includes identification sensors, vehicle status sensors, and position sensors. Identification sensors identify (detect) the conditions surrounding vehicle 1. Examples of identification sensors include cameras, LIDAR (Laser Imaging Detection and Ranging), and radar. Vehicle status sensors detect the state of vehicle 1. Examples of vehicle status sensors include speed sensors, acceleration sensors, yaw rate sensors, and rudder angle sensors. Position sensors detect the position and orientation of vehicle 1. Examples of position sensors include GNSS (Global Navigation Satellite System) sensors.
[0067] The driving system 23 is the system that enables the vehicle 1 to move. The driving system 23 is, for example, an electric drive system, including an electric motor for driving the vehicle 1, a battery for supplying power to the electric motor, and a controller. In order to drive the vehicle 1, the driving system 23 may also include an internal combustion engine in addition to the electric motor, or may include an internal combustion engine instead of an electric motor.
[0068] 3. The anti-theft device was deactivated by borrowing key information from the user terminal.
[0069] When user X delegates control of vehicle 1 to management system 10 within a designated area (e.g., parking lot 2), user X operates user terminal 30 as described above, sending a handover start request to management system 10. Afterward, user X can leave vehicle 1. On the other hand, management system 10 needs to complete predetermined processes such as vehicle authentication during the period from the start of handover processing according to the handover start request until the start request for vehicle 1's driving system 23 is sent to vehicle 1. This predetermined processing takes time. If user X, holding vehicle 1's digital key 31 (user terminal 30), leaves vehicle 1 before the start request for driving system 23 is sent, management system 10 cannot enable vehicle 1 to perform a verification with the authentication code AC of digital key 31. That is, management system 10 cannot enable vehicle 1 to deactivate the anti-theft device required to start driving system 23.
[0070] Therefore, in this embodiment, when user X delegates the operation rights of vehicle 1 to management system 10 within a predetermined area (e.g., when vehicle 1 enters a predetermined area such as parking lot 2), management system 10, upon issuing a handover start request from user terminal 30, obtains key information Ikey from user terminal 30 (which serves as digital key 31) and stores it in storage device 123 or 113. In other words, user terminal 30 lends key information Ikey to management system 10. As described above, key information Ikey includes authentication code AC, which is used to unlock the start prohibition of driving system 23 implemented based on vehicle 1's anti-theft device.
[0071] Furthermore, when the driving system 23 is started, the management system 10 sends the authentication code AC along with the start request of the driving system 23 to the control device 21 of the vehicle 1, causing the control device 21 to deactivate the start restriction of the driving system 23 (i.e., deactivate the anti-theft device). More specifically, in this embodiment, the local management device 11, located in a predetermined area (e.g., parking lot 2) (i.e., near the vehicle 1), performs the process of deactivating the anti-theft device by the control device 21.
[0072] 3-1. Processing flow
[0073] Figure 4This is a flowchart illustrating an example of the process executed by the vehicle management system 10 (main local management device 11) in connection with the "deactivation of the anti-theft device using key information Ikey borrowed from user terminal 30" according to this embodiment. The process in this flowchart begins, for example, when vehicle 1 arrives at drop-off area 3. Furthermore, Figure 5 This is a flowchart illustrating an example of the process performed by the control device 21 upon receiving key information Ikey from the vehicle management system 10.
[0074] exist Figure 4 In step S100, the local management device 11 communicates with the server UB via the server OB to determine whether a handover start request has been received from the user terminal 30. If a handover start request has been received (step S100; Yes), the process proceeds to step S102.
[0075] In step S102, the local management device 11 begins the aforementioned handover process. Next, in step S104, the management system 10, in conjunction with the handover start request, executes a "key information borrowing process." The key information borrowing process is used to obtain key information Ikey containing the authentication code AC from the user terminal 30 (digital key 31) and store it in storage device 123 or 113. More specifically, the key information Ikey is stored in storage device 123 or 113, for example, in association with the reservation ID of the AVP contained in the aforementioned service reservation information held by the management server 12 (server UB). Specific examples of the acquisition path for obtaining the key information Ikey from the user terminal 30 (digital key 31) based on the key information borrowing process, the storage destination of the obtained key information Ikey, and specific examples of the acquisition path for the key information Ikey when using it (steps S108 or S114 described later) will be described in section 3-1-2.
[0076] In step S106, following step S104, the local management device 11 determines whether the handover process is complete. If the handover process is complete (step S106; yes), the process proceeds to step S108. Step S108 is performed when the driving system 23 is started in the predetermined area (more specifically, when the vehicle 1 begins to move from the drop-off area 3 of the parking lot 2 to the parking space 8 assigned to the vehicle 1).
[0077] In step S108, the local management device 11 reads (obtains) the authentication code AC from the storage device 123 or 113. Then, the local management device 11 sends the start request for the driving system 23 along with the read authentication code AC to the vehicle 1 (control device 21), causing the control device 21 to release the start restriction on the driving system 23 based on the anti-theft device. That is, the local management device 11 begins the aforementioned storage process. Furthermore, the processing entity for step S108 is not limited to the local management device 11; it can also be executed by the cloud management server 12. The same applies to step S114, which will be described later.
[0078] Furthermore, the transmission (notification) of the authentication code AC from the local management device 11 to the vehicle 1 can also be performed by transmitting the authentication code AC itself using the communication Ckey between the digital key 31 and the control device 21. Alternatively, the transmission (notification) of the authentication code AC can also be performed using AVP communication (i.e., communication used between the local management device 11 and the vehicle 1 to provide AVP services). In this AVP communication, the authentication code AC is transmitted after being converted into encrypted information (data) specific to AVP. In one example of AVP communication, the local management device 11 communicates directly with the vehicle 1 using wireless communication methods such as WiFi. In another example of AVP communication, the local management device 11 communicates with the vehicle 1 via a management server 12 (more specifically, servers OB and VB) using wireless communication methods such as LTE.
[0079] Upon receiving the authentication code AC and the start request from vehicle 1, control device 21 executes... Figure 5 The process is as follows. First, the control device 21 compares the authentication code AC sent (notified) from the local management device 11 (management system 10) with the authentication code AC stored in its own storage device 213. More specifically, when the authentication code AC itself is sent from the local management device 11 using the communication Ckey, the control device 21 compares the authentication code AC in the same way as when sending the authentication code AC from the usual digital key 31. Furthermore, when the authentication code AC is sent using the aforementioned AVP communication, the control device 21 compares the authentication code AC based on the AVP-specific encrypted information.
[0080] If the two authentication codes AC match, that is, if the authentication code AC verification is successful (step S200; Yes), the process proceeds to step S202. In step S202, the control device 21 permits the start of the driving system 23. In other words, the control device 21 removes the start restriction of the anti-theft driving system 23, allowing the driving system 23 to start. After the driving system 23 starts, the vehicle 1 proceeds towards the assigned parking space 8 via AVP.
[0081] On the other hand, if the authentication code AC fails to match (step S200; No), the process proceeds to step S204. In step S204, the control device 21 communicates with the user terminal 30 via the server VB and UB (or directly) to notify the user X of an anomaly (e.g., inability to perform AVP driving). For example, if the local management device 11 receives a message from the vehicle 1 indicating that the matching failed, the local management device 11 that receives the message may also make the above notification. In addition, the notification may also include a message requesting the user X to temporarily return to the vehicle 1 with the digital key 31 in order to start AVP driving. For example, if the control device 21 starts the driving system 23 when the user X returns to the vehicle 1, the vehicle 1 proceeds to the assigned parking space 8 for AVP driving.
[0082] exist Figure 4 In step S110, following step S108, the local management device 11 determines whether the inbound processing is complete. If the inbound processing is complete (step S110; yes), the process proceeds to step S112.
[0083] In step S112, the local management device 11 communicates with the server UB via the server OB to determine whether a request to leave the parking space for the vehicle 1 has been received from the user terminal 30. If a request to leave the parking space has been received (step S112; yes), the process proceeds to step S114. Step S114 is executed when the driving system 23 is started in the predetermined area (more specifically, when the vehicle 1 begins to move from its parking space 8 to the passenger area 4 of the parking lot 2).
[0084] In step S114, similar to step S108, the local management device 11 sends the start request for the driving system 23 along with the authentication code AC to vehicle 1 (control device 21), causing the control device 21 to release the start restriction on the driving system 23 based on the anti-theft device. That is, the local management device 11 begins the aforementioned outbound processing. If vehicle 1 receives the start request along with the authentication code AC through the processing in step S114, the control device 21 also performs the above-described actions. Figure 5 The process is shown. Afterwards, vehicle 1 proceeds towards passenger area 4 via AVP.
[0085] In step S116, following step S114, the local management device 11 determines whether vehicle 1 has arrived at the boarding area 4 (more specifically, the assigned boarding frame 9). If vehicle 1 has arrived at the boarding area 4 (step S116; yes), the process proceeds to step S118.
[0086] In step S118, the local management device 11 communicates with the server UB via the server OB to determine whether a handover start request has been received from the user terminal 30. If a handover start request has been received (step S118; yes), the process proceeds to step S120.
[0087] In step S120, the local management device 11 initiates the aforementioned return process in response to the received return start request. The return process includes outbound processing. Next, in step S122, the local management device 11 determines whether the return process is complete. As a result, if the return process is complete (step S122; yes), the process proceeds to step S124.
[0088] In step S124, the management system 10 deletes the key information Ikey. Specifically, if the key information Ikey is stored in the storage device 123 of the management server 12 (e.g., server OB or VB), for example, the local management device 11 sends an instruction to delete the key information Ikey to the server OB or VB, and the server OB or VB deletes the key information Ikey from its own storage device 123. Alternatively, if the key information Ikey is stored in the storage device 113 of the local management device 11, for example, the local management device 11 deletes the key information Ikey from the storage device 113.
[0089] Furthermore, the outbound process is completed by completing the handover process. And, when user X boards vehicle 1 and vehicle 1 exits parking lot 2, the outbound process of vehicle 1 is completed.
[0090] 3-1-1. Timed deletion of key information
[0091] As already described, the management system 10 will delete the key information Ikey used to provide AVP services from storage devices 123 or 113.
[0092] 3-1-1-1.Example 1
[0093] exist Figure 4 In the example of the process shown, the management system 10 deletes the key information Ikey from the storage device 123 or 113 (step S124) as the handover period of the vehicle 1's operating rights from user X to the management system 10 ends, that is, as the handover process is completed (step S122; yes).
[0094] 3-1-1-2. Case 2
[0095] Figure 6This is a flowchart illustrating another example of the process executed by the vehicle management system 10 (main local management device 11) according to this embodiment in connection with the "deactivation of the anti-theft device using key information Ikey borrowed from user terminal 30". The flowchart shows the timing of deleting the key information Ikey when the vehicle 1 leaves the parking space, and... Figure 4 The flowcharts shown are processed differently.
[0096] Specifically, in Figure 6 In the process, when vehicle 1 arrives at the boarding area 4 in order to leave the designated area (e.g., parking lot 2) (step S116; yes), management system 10 deletes the key information Ikey from storage device 123 or 113 (step S300).
[0097] In addition, alternative Figure 6 In the second example shown, the timing for deleting the key information Ikey when vehicle 1 leaves the parking space can also be the start-up completion time of the driving system 23 used to move vehicle 1 from parking space 8 to passenger frame 9 when leaving the parking space.
[0098] 3-1-2. Path to obtain key information and destination for saving it
[0099] Here, we will explain a specific example of the acquisition path of the key information Ikey obtained from the user terminal 30 (digital key 31) in the key information borrowing process (refer to step S104), a specific example of the storage destination of the acquired key information Ikey, and a specific example of the acquisition path of the key information Ikey when using the key information Ikey (step S108 or S114).
[0100] 3-1-2-1. Case 1
[0101] Figure 7 This diagram illustrates the first example of the path to obtain and the destination of key information Ikey. In this first example, user terminal 30, in conjunction with a handover start request, sends key information Ikey to management server 12 (more specifically, server UB) via wireless communication (e.g., LTE). Server UB receives key information Ikey from user terminal 30 and sends the received key information Ikey to server OB or VB.
[0102] Server OB or VB receives key information Ikey from server UB. Server OB or VB may also save the received key information Ikey to its own storage device 123 (step S104). Alternatively, server OB or VB may send the received key information Ikey to local management device 11. In the case where key information Ikey is sent from server OB or VB to local management device 11, local management device 11 saves the acquired (received) key information Ikey to its own storage device 113 (step S104).
[0103] When the local management device 11 sends the authentication code AC along with the start request of the driving system 23 to the vehicle 1 (step S108 or S114), it reads and obtains the key information Ikey from the storage device 123 or 113. Then, the local management device 11 sends the authentication code AC contained in the obtained key information Ikey to the control device 21 (vehicle 1).
[0104] As described above, in the first example, the local management device 11 obtains the key information Ikey from the user terminal 30 via the management server 12.
[0105] 3-1-2-2.Example 2
[0106] Figure 8 This diagram illustrates a second example of the path to obtain and the destination for storing key information (Ikey). In this second example, the user terminal 30, in conjunction with a handover start request, uses wireless communication (e.g., WiFi) to send the key information (Ikey) to the control device 21 (vehicle 1). The control device 21 receives the key information (Ikey) from the user terminal 30 and uses wireless communication (e.g., WiFi) to send the received key information (Ikey) to the local management device 11.
[0107] The local management device 11 receives key information Ikey from the control device 21. The local management device 11 may also save the received key information Ikey in its own storage device 113 (step S104). Alternatively, the local management device 11 may send the received key information Ikey to server OB, or (via server OB and UB) to server VB. When the key information Ikey is sent from the local management device 11 to server OB or VB in this way, server OB or server VB saves the acquired (received) key information Ikey in its own storage device 123 (step S104).
[0108] In the second example, when the local management device 11 sends the authentication code AC along with the start request of the driving system 23 to the vehicle 1 (step S108 or S114), it also reads and obtains the key information Ikey from the storage device 123 or 113. Furthermore, the local management device 11 sends the authentication code AC contained in the obtained key information Ikey to the control device 21 (vehicle 1).
[0109] As described above, in the second example, the local management device 11 obtains the key information Ikey from the user terminal 30 via the control device 21 (vehicle 1).
[0110] 3-1-2-3.Example 3
[0111] Figure 9 This is a diagram illustrating the third example of how the key information Ikey is obtained and stored. In this third example, the user terminal 30, in conjunction with the handover start request, uses wireless communication (e.g., WiFi) or a wireless communication method similar to that used for communicating the Ckey to directly send the key information Ikey to the local management device 11. Figure 9 As shown, the processing after the local management device 11 receives the key information Ikey from the user terminal 30 is as follows: Figure 8 The second example shown involves the same processing.
[0112] In the third example, when the local management device 11 sends the authentication code AC along with the start request of the driving system 23 to the vehicle 1 (step S108 or S114), it also reads and obtains the key information Ikey from the storage device 123 or 113. Furthermore, the local management device 11 sends the authentication code AC contained in the obtained key information Ikey to the control device 21 (vehicle 1).
[0113] As described above, in the third example, the local management device 11 directly obtains the key information Ikey from the user terminal 30.
[0114] Furthermore, as in examples 1 to 3 above, the key information Ikey can be stored by any one of the storage devices 113 of the local management device 11, the storage device 123 of the server OB, and the storage device 123 of the server VB. Based on this, in the example where the vehicle 1 manufacturer manages the server VB, the key information Ikey sent from the user terminal 30 is stored in the storage device 123 of the server VB, and the local management device 11 (not managed by the manufacturer) only reads and uses the key information Ikey from the storage device 123 when it is needed. This configuration is preferred in terms of ensuring a higher level of security for the vehicle 1.
[0115] 3-2. Effects
[0116] As explained above, according to this embodiment, when the driving system 23 of vehicle 1 is started, the vehicle management system 10, upon issuing a handover start request, sends the authentication code AC contained in the key information Ikey obtained from the user terminal 30 along with the start request for the driving system 23 to the control device 21 of vehicle 1, causing the control device 21 to release the start prohibition of the driving system 23 based on the anti-theft device. Therefore, the vehicle management system 10 can start the driving system 23 without requiring user X to wait near vehicle 1 until the driving system 23 is started after the handover process is completed. This improves the convenience for user X in the autonomous driving service (e.g., AVP service) within the designated area.
[0117] Furthermore, as described above, the timing for the management system 10 to obtain the key information Ikey is when the handover start request is issued. That is, according to this embodiment, the management system 10 does not obtain the key information Ikey before starting the AVP service, and the period during which the management system 10 retains the key information Ikey is considered to be the necessary minimum. This significantly ensures the security of the vehicle 1 related to the start-up of the driving system 23, while also contributing to improved convenience for the user X.
[0118] Additionally, as described in section 3-1-1-1, the management system 10 can also delete the key information Ikey from storage devices 123 or 113 upon the end of the handover period when the operating permissions of vehicle 1 are transferred to the management system 10. This allows the driving system 23 to be started in response to startup requests from the management system 10 when vehicle 1 enters or leaves the vehicle, while also appropriately limiting the period during which the management system 10 retains the key information Ikey, taking into account the safety of vehicle 1.
[0119] Furthermore, as described in section 3-1-1-2, the management system 10 can also delete the key information Ikey from storage devices 123 or 113 as vehicle 1 arrives at the boarding area 4 to exit from a predetermined area (e.g., parking lot 2). This allows the driving system 23 to be started in response to startup requests from the management system 10 when vehicle 1 enters or exits the parking lot, and also allows for a more appropriate limitation on the retention period of the key information Ikey by the management system 10, further enhancing the security of vehicle 1. Moreover, in scenarios where the handover process is delayed due to time spent by user X moving to vehicle 1 after vehicle 1 arrives at the boarding area 4, deleting the key information Ikey upon vehicle 1's arrival at the boarding area 4, as described above, helps to increase user X's sense of security.
Claims
1. A vehicle management system for managing vehicles within a predetermined area, comprising: One or more processors; and One or more storage devices, The one or more processors In response to a handover start request from a user terminal, a handover process begins to transfer operating permissions of the vehicle from the user to the vehicle management system. The user terminal stores key information for functioning as a digital key for the vehicle. When the handover commencement request is issued, the key information is obtained from the user terminal and stored in one or more storage devices. The key information includes an authentication code, which is used to unlock the vehicle's driving system from the anti-theft device. When the driving system is started, the one or more processors send the authentication code along with the driving system start request to the vehicle control device, causing the control device to release the start prohibition.
2. The vehicle management system according to claim 1, The one or more processors delete the key information from the one or more storage devices at the end of the handover period during which the operating permissions are transferred to the vehicle management system.
3. The vehicle management system according to claim 1, The one or more processors delete the key information from the one or more storage devices when the vehicle arrives at the boarding area in order to leave the predetermined area.
4. The vehicle management system according to any one of claims 1 to 3, The vehicle management system includes a local management device located in the predetermined area. The one or more processors include one or more first processors included in the local management device. When the driving system is started, the one or more first processors send the authentication code along with the driving system start request to the control device, causing the control device to release the start prohibition.
5. The vehicle management system according to claim 4, The vehicle management system includes one or more management servers in the cloud that can communicate with the local management device. The local management device obtains the key information from the user terminal via one or more management servers.
6. The vehicle management system according to claim 4, The local management device obtains the key information from the user terminal via the control device.
7. The vehicle management system according to claim 4, The local management device obtains the key information directly from the user terminal.
8. The vehicle management system according to claim 1, The designated area is the parking lot corresponding to the automated valet parking service. Activating the driving system in the predetermined area means starting to move the vehicle from the drop-off area of the parking lot to the parking space assigned to the vehicle.
9. The vehicle management system according to claim 1, The designated area is the parking lot corresponding to the automated valet parking service. Activating the driving system in the predetermined area means starting the movement of the vehicle from its parking space to the passenger area of the parking lot.
10. A vehicle management method for managing vehicles within a predetermined area, wherein the vehicle management method is executed by a computer. The vehicle management method includes: In response to a handover start request from a user terminal, a handover process is initiated to transfer the vehicle's operating permissions from the user to the vehicle management system. The user terminal stores key information for functioning as a digital key for the vehicle. and When the handover commencement request is issued, the key information is obtained from the user terminal and stored in one or more storage devices of the vehicle management system. The key information includes an authentication code, which is used to unlock the vehicle's driving system from the anti-theft device. The vehicle management method further includes: when starting the driving system, sending the authentication code along with the driving system startup request to the vehicle's control device, so that the control device can lift the startup restriction.
11. A vehicle management program for managing vehicles within a predetermined area, the vehicle management program being executed by a computer. The vehicle management program causes the computer to execute: In response to a handover start request from a user terminal, a handover process begins to transfer vehicle operation permissions from the user to the vehicle management system. The user terminal stores key information for functioning as a digital key to the vehicle. When the handover commencement request is issued, the key information is obtained from the user terminal and stored in one or more storage devices of the vehicle management system. The key information includes an authentication code, which is used to unlock the vehicle's driving system from the anti-theft device. The vehicle management program also causes the computer to: when starting the driving system, send the authentication code along with the driving system startup request to the vehicle's control device, causing the control device to lift the startup restriction.