Procedures for operating a carsharing vehicle and carsharing vehicle

The method uses biometric data from driver's licenses and external verification to prevent unauthorized carsharing vehicle use, ensuring secure and reliable operation.

DE102018220433B4Inactive Publication Date: 2025-12-24VOLKSWAGEN AG
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
DE102018220433
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2018-11-28
Publication Date
2025-12-24
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Current carsharing systems face issues with unauthorized use due to the potential misuse of key cards and PINs, and users with revoked driving licenses can still operate vehicles, necessitating improved security measures.

Method used

A method involving biometric data acquisition from a driver's license, comparison with stored data, and verification by external personnel to ensure authorized use, using integrated or mobile devices for data capture and verification.

Benefits of technology

Prevents unauthorized use by ensuring a direct match between the license holder and the user, enhancing security and reliability while maintaining user convenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0001_ABST
    Figure 00000000_0001_ABST
  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method (17) for operating a car sharing vehicle (1) wherein - data from a driver's license (14) carried by a user (5) are recorded by the car sharing vehicle (1) using a data acquisition device (13), - the collected data are automatically checked, and - if the verification result is positive, the car sharing vehicle (1) is activated for use by the user (5), where before each use of the car sharing vehicle (1) - biometric data of a driving licence holder (14) stored as part of the data on the driving licence (14), - by means of a recognition device (13) for recognizing the user (5) at least one biometric feature of the user (5) is detected while the user is in the area of ​​the car sharing vehicle (1), and - to verify the recorded data, these are compared with the at least one detected biometric characteristic of the user (5), whereby a match results in a positive verification result, characterized by the fact that If the car sharing vehicle (1) fails the verification test, a video connection is established to an external verification point (9) staffed by verification personnel, and the car sharing vehicle (1) is only unlocked for use by the user (5) after the car sharing vehicle (1) receives an unlock signal from the verification point (9).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for operating a car-sharing vehicle and a corresponding car-sharing vehicle.

[0002] Carsharing, the organized shared use of one or more vehicles by a large number of different users based on a framework agreement, is becoming increasingly widespread. Current systems typically require a one-time registration for each user wishing to use a carsharing service or system. This initial registration can be done online, for example via a web form or website, or in person at a branch of the respective carsharing service provider. During this process, proof of identity, such as a national identity card or credit card, is verified.If the identity verification is successful, meaning the documents presented by the user are valid, the carsharing provider will activate the user for basic access to the service, i.e., the corresponding carsharing system. The user will then receive a key card from the carsharing provider, which they can use to book and use the provider's carsharing vehicles. The key card must be held against a reader in each carsharing vehicle to activate it. As an additional security measure, the provider may request a personal identification number (PIN, PIN code) that the user has chosen or set themselves and must enter into the carsharing vehicle.

[0003] However, with this well-known system, misuse—that is, ultimately unauthorized use of the respective carsharing vehicle—cannot be ruled out. For example, the key card and, if applicable, the PIN could be intentionally or unintentionally passed on to a third party, allowing such a third party to use the carsharing vehicles of the respective provider without being registered themselves. Furthermore, a user can also use the carsharing vehicles of the respective provider even if they have had to surrender their driver's license due to a traffic violation and are therefore currently not authorized to drive.

[0004] One possible solution to these problems is for the carsharing provider to affix an RFID sticker directly to the user's driver's license, as it can generally be assumed that users will not readily hand over their license to third parties. However, this cannot be reliably prevented. Furthermore, such an alteration of the driver's license could be legally problematic, as it is an official document. Additionally, the RFID sticker could potentially be removed from the license by the user or a third party and used separately or on another license.

[0005] A device for identifying a motor vehicle is already known from WO 2018 / 043 100 A1, comprising a first detection unit for capturing a facial photograph from a medium and a second detection unit for taking a photograph of an area in which a driver's face is presumed to be located. By comparing the corresponding images, it is to be determined whether the driver is the person in the facial photograph stored on the medium.

[0006] In JP 2016 - 141 349 A, an anti-theft device for a vehicle is disclosed. This device is designed to capture a facial image from a predefined identification card and then use an imaging device to take a facial image of the driver. An authentication unit is used to verify that the driver is the person identified by the identification card. Upon successful authentication, the vehicle is put into an operational state.

[0007] German patent application DE 10 2017 202 834 A1 describes a method for operating a motor vehicle in an activated semi-autonomous driving mode. In this method, a vehicle occupant is detected in the vehicle, and then an authorization device in the vehicle verifies whether the occupant meets an authorization criterion. If the criterion is met, the semi-autonomous driving mode is activated by a control unit. If the authorization criterion is not met, a query signal is sent to an external authorization device. If an external release signal is received in response, it is forwarded to the control unit.

[0008] German Patent Application DE 10 2012 009 019 A1 describes a method for operating a vehicle and corresponding operating equipment. The method involves automatically collecting data relating to a general driving license for motor vehicles using appropriate data acquisition devices in the vehicle. This data is then automatically verified. If the data verification is successful, a corresponding vehicle function is activated. For example, the system could check whether the license holder is registered as the vehicle's renter in a database. This is intended to improve theft protection, particularly in car sharing.

[0009] As an alternative, DE 10 2016 217 890 A1 describes the use of an electronic driving licence. Specifically, before a vehicle is put into operation, the driving licence categories stored in the licence are to be compared with the vehicle category assigned to the respective vehicle. If the driving licence categories include the vehicle category, the vehicle is allowed to be put into operation. Otherwise, it is refused. The data of the electronic or programmable driving licence can be stored on a server, for example, so that the respective driver can be identified even in the event of a vehicle accident. Because the driving licence is electronic, it cannot be physically lost and then, for example, used by a third party.

[0010] The object of the present invention is to prevent the unauthorized use of a car-sharing vehicle. This object is achieved according to the invention by the subject matter of the independent claims. Advantageous embodiments and further developments of the present invention are specified in the dependent claims, in the description, and in the figures.

[0011] The method according to the invention serves to operate a carsharing vehicle, i.e., a vehicle, in particular a motor vehicle, which is designed and equipped for use by multiple users. In this method, the carsharing vehicle uses a data acquisition device to collect data from a driver's license carried by a user, i.e., to read or write data to the license. The collected data is then automatically checked, and if the check is successful, the carsharing vehicle is unlocked or released for use by the user. According to the invention, it is provided that, before each use of the carsharing vehicle, biometric data of the license holder stored on the driver's license is recorded as part of the data.This biometric data can be stored electronically, for example, on a memory chip in the driver's license, and / or printed or depicted on the driver's license. Furthermore, before each use of the carsharing vehicle, at least one biometric or anatomical characteristic of the user is detected by means of a user identification device while the user is in the vicinity of the carsharing vehicle, i.e., depending on the design, either inside the carsharing vehicle or in its immediate surroundings. This at least one biometric characteristic is therefore detected, measured, or recorded directly from the user and not read from an electronic data source, storage medium, or the like.Furthermore, according to the invention, before each use of the carsharing vehicle, the recorded data is compared with at least one biometric feature, i.e., at least one biometric characteristic, of the user to verify it. A match between the recorded biometric data and the detected biometric feature results in a positive verification result or corresponds to one. According to the invention, if the verification result is negative, the carsharing vehicle, in particular automatically, establishes a video connection to an external verification point staffed by verification personnel. The carsharing vehicle is then only unlocked for use by the user upon receipt of an activation signal from the verification point by the carsharing vehicle. A corresponding query can also be issued to the user before the video connection is established.The video connection can then be established upon confirmation of this query. The car-sharing vehicle will only be unlocked for the user after receiving an activation signal from the verification point or facility. The verification point or its personnel thus serves as an additional control instance, capable of verifying the verification result. The activation signal can therefore be sent by the verification personnel or the verification point if they determine a positive verification result, for example, if a visual inspection by the verification personnel confirms a match between the user and the driver's license holder.This method reliably addresses the problem of data acquisition and / or recognition devices failing to perform their intended function, for example, due to a technical defect, contamination, unsuitable environmental conditions, an ambiguity in the biometric characteristic (e.g., due to user injury), and / or similar issues. This improves the usability and reliability of the carsharing vehicle and / or the carsharing service. The unlock signal sent from the verification point to the carsharing vehicle can override or supersede the vehicle's own unlocking mechanism, thus ensuring that the final authority to unlock the vehicles rests with the verification personnel.The car-sharing vehicle is equipped with a suitable display device for the video connection, such as a screen mounted on the instrument panel. This can advantageously improve user-friendliness and ease of use, and enable particularly effective clarification of the situation. For example, a data signal generated by the data acquisition and / or recognition device can be transmitted via the video connection to the inspection point to allow for verification or re-evaluation by the inspection personnel.

[0012] The commissioning of the carsharing vehicle can be understood, in particular, as starting the engine or drive system of the carsharing vehicle before or at the start of a journey. The verification of the recorded data therefore takes place before the user can drive the carsharing vehicle. Driving is only possible once the carsharing vehicle has been unlocked for the user. Functions not relevant to commissioning in this sense—that is, to the actual driving or setting the carsharing vehicle in motion—may also be locked until a positive verification result is received or, alternatively, may be enabled beforehand. Such functions could include, for example, opening a door of the carsharing vehicle, switching on a light, and / or similar actions.The present invention therefore provides that the user can only start, i.e., put into operation, the vehicle once a clear assignment or correspondence exists between the user actually present and the driver's license used for identification or authentication. In other words, it is ensured directly in the respective carsharing vehicle that the user who wishes to use the carsharing vehicle is indeed the holder of the read or recorded driver's license.

[0013] By comparing the data recorded on or stored in the driver's license with the user's actual physical and biological biometric characteristics, and by ensuring that these biometric characteristics cannot be easily falsified or faked without considerable effort, which is generally unprofitable for a private user, the present invention advantageously and effectively prevents misuse by third parties, i.e., unauthorized use of the car-sharing vehicle. For example, a user registered with the provider or operator for basic use of the car-sharing vehicle cannot enable a third party to actually use or operate the vehicle by simply passing on their driver's license used for registration.

[0014] Furthermore, the data recorded on the driver's license can be compared with a registration database containing data from users registered with the operator or provider of the carsharing vehicle, service, or system. This registration database can be stored locally in the carsharing vehicle and / or externally, for example, in a data storage system on a server or cloud server. The data stored in the registration database can include, for example, a name, address, date of birth, and other information for each user. This data can also be captured or read from the driver's license carried by the user using the data capture device.If the registration database is stored externally in the vehicle, a corresponding query can be automatically sent to the server via a wireless data connection, such as a mobile network connection. This allows verification and confirmation that the driver's license holder is indeed registered for the basic use of the car-sharing vehicle.

[0015] It can also be stipulated that, as described above, all users registered or logged in to the carsharing service receive a key card or a corresponding access device, which is then recognized or detected by the data collection device or a separate access device of the carsharing vehicle. An identifying feature, such as a number or the name of the respective user stored on the key card, can then be additionally or alternatively compared with the data read from the driver's license to ensure that the holder of the driver's license matches the holder of the key card or access device and is registered or logged in to use the carsharing vehicle, and thus is generally authorized to do so.

[0016] Furthermore, a verification of the driver's license's authenticity can be implemented. This means that the driver's license can be checked for authenticity, for example, during data capture or reading by the vehicle itself and / or by the server, to prevent misuse by a forged license. This can be achieved, for instance, by verifying security features present in legitimate, officially issued driver's licenses.

[0017] The data acquisition device and the detection device can be different or similar separate devices or units. However, the data acquisition device and the detection device can also be integrated, combined, or identical within a single device. Thus, the data acquisition device can also be the detection device. It is also possible that the data acquisition device and the detection device use, for example, a single or shared sensor but have or use different devices, functional or program modules, or the like, for evaluating the corresponding sensor data—that is, for their respective different functions.A separate or independent design of the data acquisition and recognition devices can be advantageous, for example, enabling optimized or specialized functionality and / or improved user ergonomics, while an integrated design can be advantageous for simplifying use or operation for the user, as they do not have to identify different devices or components with regard to their function or task. The data acquisition device could, for example, be or include a card reader for the now common credit card-sized driver's licenses. Similarly, the data acquisition device could include a camera, an optical scanner, or the like. Likewise, the recognition device could be or include a camera. Additionally or alternatively, the recognition device could include other or additional sensors, such as a fingerprint sensor or the like.

[0018] Biometric data or biometric characteristics can, for example, specify or relate to the shape or appearance of a face, a relative arrangement (such as distance) of certain body features or distinctive points, an angle, direction, and / or length ratios of corresponding connecting lines (i.e., facial or body geometry), height or girth, hand geometry, palmar ridge structure, hand vein structure, fingerprint, nail bed pattern, ear shape, iris or retina pattern, voice pattern, and / or the like. Using a combination of several biometric data points or characteristics can advantageously enable more precise or reliable matching, identification, and authentication.

[0019] Since such data is sensitive under data protection and privacy laws, its collection and processing for verification and activation of the carsharing vehicle can be advantageous locally within the respective carsharing vehicle. This eliminates the need to establish or operate a central data processing center or database where the corresponding biometric data and characteristics of all carsharing service users are stored or processed.

[0020] A particular advantage of the present invention is that not only is improved protection against forgery or misuse achieved, but the sensitive biometric data and characteristics of the users do not need to be known to the car-sharing service provider and, for example, do not need to be permanently stored in its computer system. During the verification process, the recorded biometric data and the detected anatomical or biometric feature can, for example, be held in a temporary buffer and discarded or deleted after successful verification or after the car-sharing vehicle has been unlocked.

[0021] In an advantageous embodiment of the present invention, the data acquisition device and the recognition device are permanently installed in the carsharing vehicle. In other words, the data acquisition device and the recognition device are part of the carsharing vehicle's equipment and remain in the vehicles even when the user changes. This advantageously ensures reliable operation, availability of the devices in the carsharing vehicle, and their compatibility with a system, data processing device, or unlocking device of the carsharing vehicle. Ultimately, this leads to a significantly improved ease of use and operation of the carsharing vehicle.In particular, the data acquisition device can be, for example, an optical or electronic driver's license reader; for driver's licenses in credit card format, a card reader can be used. The recognition device can be, in particular, a camera. The data acquisition device and / or the recognition device can be integrated into or mounted on, for example, the instrument panel, center console, or headliner of the car-sharing vehicle. The data acquisition device and / or the recognition device can thus be designed and positioned for use by a user who is inside the car-sharing vehicle. This can advantageously allow for particularly convenient and, for example, weather-independent use or operation of the devices.Similarly, the data acquisition device and / or the recognition device can be arranged, for example, for use or operation by a user located outside the carsharing vehicle. For this purpose, the data acquisition device and / or the recognition device can, for instance, be integrated into the outer shell of the carsharing vehicle or, for example, be designed and positioned through a transparent window of the carsharing vehicle to capture or read the driver's license or to detect at least one biometric feature. This can prevent not only unauthorized activation but also unauthorized access to the interior of the carsharing vehicle. It can then be stipulated that the carsharing vehicle is only unlocked after a positive verification result.This may eliminate the need to issue the aforementioned key card or access device. This not only leads to improved security but also to equally good user convenience, as users do not need to carry the key card or access device with them to use the car-sharing vehicle.

[0022] In a further advantageous embodiment of the present invention, the car-sharing vehicle establishes a data connection to a mobile electronic device carried by the respective user in order to capture or read the data from the driver's license and / or to detect at least one biometric feature of the user, and this mobile electronic device is then used as the data acquisition device and / or as the recognition device. The mobile electronic device can preferably be, for example, a mobile phone (smartphone), but also, for example, a tablet computer or a portable data processing device (wearable computer, wearable).A sensor on the mobile electronic device, such as an integrated camera and / or fingerprint sensor, can then be used to read or capture the driver's license or to capture or detect at least one biometric feature. The corresponding data or signals are then transmitted via the data connection to the car-sharing vehicle, for example, to a data processing or unlocking device designed to carry out the procedure described here, and processed by this device to verify the data. This can be done alternatively or additionally to capturing the driver's license and / or detecting at least one biometric feature by devices permanently installed in the car-sharing vehicle.Whether these permanently installed devices and / or the mobile electronic device are used can depend, for example, on the equipment of the respective carsharing vehicle and the mobile electronic device, or can be offered to the user as a choice. A combination is also possible, such that, for example, the driver's license is recorded or read by means of a data acquisition device permanently installed in the carsharing vehicle, while at least one biometric feature is detected by means of the mobile electronic device as an identification device, or vice versa. Using the mobile electronic device as the data acquisition device and / or as the identification device can advantageously enable particularly flexible use or application of the present invention. In particular, it is not necessarily required, for example, to install additional hardware in the carsharing vehicle.Due to the almost ubiquitous availability of sufficiently powerful mobile electronic devices, the present invention is particularly easy to implement in practice. Furthermore, the use of a mobile electronic device can improve user comfort, as the user is typically familiar with their mobile device and can position it comfortably and flexibly without restrictions. The data connection can be, for example, a Bluetooth, WLAN, or USB connection, or the like.

[0023] In a further advantageous embodiment of the present invention, upon detection of an access authorization device by an access control unit of the carsharing vehicle, a door of the carsharing vehicle is automatically unlocked to allow entry into a passenger compartment or interior of the carsharing vehicle. Starting the carsharing vehicle remains blocked initially and is only enabled upon successful verification. The access authorization device can be, for example, the aforementioned key card, a chip card, or the like. This device can, for example, be equipped with an RFID chip. Correspondingly, the access control unit can include a corresponding card reader.The user can then, for example, bring the access token from outside to the vicinity of the access device, i.e., a corresponding reader or sensor, to unlock the carsharing vehicle or its door. The access device's reader can be directly or indirectly coupled or connected to, for example, an electronic or electromechanical locking mechanism of the door, such as via the carsharing vehicle's electrical system. In other words, a two-stage or multi-stage authorization process is intended for using the carsharing vehicle. Because the access token is required to gain access to the interior of the carsharing vehicle, the first stage already prevents just anyone from entering the vehicle.This already represents an initial access barrier. As a second process step or stage, the detection of at least one biometric feature and, based on this, the verification of the data read from the driver's license within the car-sharing vehicle can then take place. This has the advantage that conditions, such as lighting conditions, can be influenced more easily and reliably inside the car-sharing vehicle and / or vary less than outside the vehicle. This can advantageously enable more accurate or reliable capture or detection of the biometric feature and / or more accurate or reliable capture or reading of the driver's license.Furthermore, users can remove necessary items of clothing, such as a hood, hat, scarf, or gloves, from the carsharing vehicle without any obstruction. This allows at least one biometric feature to be detected more reliably and without compromising user comfort. At the same time, this system prevents unauthorized users who have gained access to the carsharing vehicle from operating it without their authorization, i.e., without being properly identified and authorized.

[0024] In a further advantageous embodiment of the present invention, the recognition device for detecting the at least one biometric feature captures the user in at least one non-optical wavelength range, in particular in an infrared range and / or in an ultraviolet range. For this purpose, the recognition device can, for example, comprise an infrared or ultraviolet camera. Likewise, the recognition device can, for example, comprise an infrared and / or ultraviolet light source. The user can then be illuminated from the outside so that the corresponding reflected infrared and / or ultraviolet radiation can be detected by the recognition device. Such non-optical wavelength ranges can be used alternatively or additionally to an optical wavelength range. The use of non-optical wavelength ranges can advantageously make manipulation of the biometric feature more difficult.Furthermore, the biometric feature can still be detected under more and / or different conditions, for example in darkness, when using non-optical wavelengths or spectral ranges. This enables a particularly flexible and reliable implementation of the method according to the invention.

[0025] In a further advantageous embodiment of the present invention, the recorded data from the driver's license is compared with a database, particularly one external to the vehicle, to verify whether the license holder is authorized to drive the car-sharing vehicle at any given time. This can include, for example, checking whether the license holder is currently subject to a driving ban. It can also include checking whether the license authorizes the holder to drive vehicles of the same class as the respective car-sharing vehicle.To easily verify a driver's license holder's authorization to drive a carsharing vehicle, the database can, for example, contain an exception list (such as a whitelist or positive list) or a blacklist (or negative or blocked list). This list would indicate which users registered for carsharing are currently authorized or ineligible to drive the vehicle. For this purpose, the name of the driver's license holder and / or their license number, or similar information, can be recorded or extracted and used, for example, by sending it to a server that manages or maintains the database.This approach advantageously enables an even more reliable prevention of unauthorized use of the car-sharing vehicle.

[0026] In a further advantageous embodiment of the present invention, the car-sharing vehicle automatically adjusts at least one ergonomic and / or comfort feature based on the recorded data and / or the at least one detected biometric characteristic. For example, a seat setting, a setting of an instrument cluster, a multimedia or infotainment system, a navigation device, and / or the like can be individually adjusted or adapted for the respective user. Similarly, a personal or personalized greeting can be issued to the user upon successful verification. By automatically adjusting or adapting the ergonomic and / or comfort features, not only ease of use but also safety when driving the car-sharing vehicle can be improved.For example, ergonomically correct adjustments to the driver's seat, steering wheel, steering column, and / or exterior and / or interior mirrors of the carsharing vehicle can improve usability, enhance visibility of surrounding traffic, and / or reduce driver fatigue. This can be achieved by taking into account the user's physical proportions, such as height, torso length, leg length, and arm length. For added convenience, the user's home address can be preset as a navigation destination. A user-specific profile, containing preferred or suitable settings, can be particularly beneficial.This user profile can be automatically loaded or retrieved, for example, from a storage device in the carsharing vehicle or from an external server, if the verification process is successful (i.e., if the user is successfully identified or authenticated). Similarly, the user's age can be used or taken into account. For example, road safety can be improved by automatically adjusting a functionality or setting of the carsharing vehicle for users whose age is below a certain threshold or above a certain threshold. For instance, the maximum speed and / or power output of the carsharing vehicle can be limited for younger drivers.For older users, for example, the display size of information or data in the instrument cluster of a car-sharing vehicle can be increased. Similarly, the intervention threshold of a driver assistance system can be adjusted to the individual user, i.e., tailored to their specific characteristics.

[0027] In a further advantageous embodiment of the present invention, at least one biometric feature of the user is detected again, particularly continuously, after the carsharing vehicle has been put into operation, and compared with the biometric feature detected before commissioning and / or with the recorded data. If a discrepancy is detected, a request to stop operating or using the carsharing vehicle is issued and / or a function of the carsharing vehicle is automatically restricted. Additionally or alternatively, the carsharing vehicle automatically or autonomously drives to the nearest parking space and automatically locks its operation or use for the user there. This can also advantageously contribute to preventing unauthorized use of the carsharing vehicle.This can, for example, prevent an authorized user from starting a carsharing vehicle, only for an unauthorized third party to then take over its operation or control. As a limitation of its functionality, the maximum speed of the carsharing vehicle can be gradually reduced or limited during stops or interruptions, or further travel can be prevented altogether. Similarly, if a deviation is detected, the carsharing vehicle can automatically switch to autonomous or automated driving mode and head for the nearest safe stopping point, where it remains stationary.For example, the respective driver or operator of the car-sharing vehicle may be asked to hand over the operation or control of the car-sharing vehicle to the user identified and authenticated before commissioning, or to leave the car-sharing vehicle.

[0028] Another aspect of the present invention is a car-sharing vehicle which has a data acquisition device for capturing or reading data from a driver's license. According to the invention, the car-sharing vehicle also has a recognition device for detecting at least one biometric feature of a user located within the area of ​​the car-sharing vehicle. Furthermore, the car-sharing vehicle according to the invention has a data processing device coupled with the data acquisition device and the recognition device for comparing the captured data with the at least one detected biometric feature.Furthermore, the carsharing vehicle according to the invention has an unlocking device coupled to, combined with, or encompassing the data processing unit, which is configured to automatically unlock or release the carsharing vehicle for use by the user when the recorded data matches the at least one detected biometric feature, i.e., one measured on the user. According to the invention, the carsharing vehicle has a display device for a video connection and is configured to establish a video connection to an external verification station staffed by verification personnel in the event of a negative verification result, and to unlock the carsharing vehicle for use by the user only upon receipt of an unlock signal from the verification station by the carsharing vehicle.The carsharing vehicle according to the invention is therefore specifically equipped for carrying out or implementing the method according to the invention. Accordingly, the carsharing vehicle according to the invention can be, in particular, the carsharing vehicle mentioned in connection with the method according to the invention. The carsharing vehicle according to the invention can therefore have some, some, or all of the features and / or devices mentioned in connection with the method according to the invention. This can, for example, relate to the access device or the like. For carrying out or implementing the method, the unlocking device or the data processing device can have a computer-readable storage medium and an associated processor device.The computer-readable storage medium can contain a computer program or program code which encodes or represents the procedural steps of the procedure, i.e., the described processes or measures, and thus, when executed by the processor, causes the execution or implementation of the procedure.

[0029] The aforementioned computer program and the storage medium containing the computer program each represent further aspects of the present invention.

[0030] The invention also includes further developments of the car-sharing vehicle according to the invention, which have features as described in connection with the further developments of the method according to the invention, and vice versa. This also applies accordingly to all other aspects of the invention. To avoid unnecessary redundancy, the corresponding further developments are not described separately here for all aspects of the present invention.

[0031] An embodiment of the invention is described below. The following is shown: Fig. 1. A schematic overview showing a car-sharing vehicle equipped with an unlocking device and an external server; and Fig. 2 an exemplary schematic flowchart for a procedure for operating the car-sharing vehicle Fig. 1.

[0032] The embodiment described below is a preferred embodiment of the invention. In this embodiment, the described components each represent individual features of the invention that can be considered independently of one another. Each of these features further develops the invention independently and can therefore be considered part of the invention individually or in a combination other than that shown. Furthermore, the described embodiment can also be supplemented by other features of the invention already described.

[0033] Fig. Figure 1 shows a schematic overview of a carsharing vehicle 1 and an external server 9. The carsharing vehicle 1 has an activation device 2, which in turn comprises a computer-readable storage medium 3 and an associated processor 4. The computer-readable storage medium 3 contains program code executable by the processor 4, which encodes or represents a method for operating the carsharing vehicle 1. An exemplary flowchart 17 for such a method is shown schematically in Figure 1. Fig. 2 shown.

[0034] This procedure will be described below with reference to Fig. 1 and Fig. 2 explained in more detail.

[0035] The aim here is to prevent misuse, i.e., unauthorized use of the car-sharing vehicle 1.

[0036] When a user 5 wishes to use the carsharing vehicle 1, they first approach it from the outside. The user 5 then holds an RFID key card, issued to them after registration with a provider or operator of the carsharing vehicle 1, against an access device 6 of the carsharing vehicle 1 in a process step S1. The access device 6 has an RFID reader for reading the key card. The access device 6, or the unlocking device 2 connected to it via the on-board network 7 of the carsharing vehicle 1, then checks whether the read key card authorizes access to the carsharing vehicle 1. If so, the access device 6 or the unlocking device 2 automatically unlocks a door 8 of the carsharing vehicle 1.Access authorization can also be verified by sending a corresponding query to the vehicle-external server 9. For this purpose, the car-sharing vehicle 1 has a corresponding communication device and the server 9 has a corresponding communication interface 10, for example, to establish a mobile communication connection between the car-sharing vehicle 1 and the server 9. The server 9 has a data storage device 11 in which a corresponding database containing valid access authorizations can be stored.

[0037] The data read from the key card of the car-sharing vehicle 1 and transmitted to the server unit 9 can be processed by a server processor unit 12 of the server unit 9, which is connected to the data storage 11. Depending on the result of the data processing or the verification of access authorization, the server unit 9 can then transmit a corresponding data signal to the car-sharing vehicle 1 via the communication interface 10 and the data connection, whereupon the vehicle can unlock the door 8 or deny access.

[0038] Once door 8 has been unlocked, user 5 can then enter the car-sharing vehicle 1. For the subsequent procedure, the car-sharing vehicle 1 has a camera 13, which is also connected to the vehicle's electrical system 7.

[0039] In process step S2, the camera 13, in conjunction with the unlocking device 2, functions as a data acquisition device for capturing or reading the biometric data of a driver's license 14 held in front of the camera 13 by the user 5. The camera 13 may also include a corresponding reader into which the driver's license 14 can be inserted. Additionally or alternatively to the camera 13, a mobile electronic device, such as a mobile phone, carried by the user 5 can be used, which can be connected to the vehicle's network 7 or to the unlocking device 2 via a wireless or wired data connection.

[0040] The data read from driving licence 14, i.e., recorded by driving licence 14, includes the name of the licence holder and the holder's biometric data stored on the licence 14. In process step S3, this data is used to verify whether the licence holder is authorized to drive car-sharing vehicle 1. This includes checking, for example, whether the licence 14 is still valid, whether it covers a vehicle class of car-sharing vehicle 1, and whether the licence holder is currently subject to a driving ban. For this purpose, some or all of the data read from driving licence 14 can also be transmitted to server 9. If it is determined that the licence holder is not authorized to drive car-sharing vehicle 1, a corresponding notification can be issued to user 5.At this point, the user is and will remain blocked from starting the carsharing vehicle 1. However, if it turns out that the holder of driving licence 14 is authorized to drive the carsharing vehicle 1, the procedure will continue.

[0041] In process step S4, the camera 13 acts as a recognition device for detecting at least one biometric feature or biometric characteristic of the user 5. For this purpose, the user 5 is imaged and corresponding image data is processed by the unlocking device 2 to determine or detect the at least one biometric feature.

[0042] In process step S5, it is then checked whether the biometric data read from driving licence 14 matches at least one detected biometric characteristic of user 5. In other words, it is determined whether user 5 is the holder of driving licence 14. If this is not the case, the process follows a program path P1 to process step S6.

[0043] In process step S6, a video connection is automatically established to an external verification point. This could, for example, be server facility 9. Via this video connection, the identity and authorization of user 5 can then be verified by appropriate verification personnel at the verification point. If it is determined that user 5 is not actually authorized to drive the carsharing vehicle 1, they can be asked in process step S7 to either leave the carsharing vehicle 1 or to register and sign up for its use.

[0044] If, however, it is determined in process step S6 that user 5 is authorized to drive the car-sharing vehicle 1, the process follows a program path P2 to a process step S8. The process also reaches process step S8 from process step S5 via a program path P3 if it has been determined in process step S5 that user 5 is identical to the holder of driving licence 14.

[0045] In process step S8, the carsharing vehicle 1 is then released or unlocked for use by user 5 via the unlocking device. User 5 can then put the carsharing vehicle 1 into operation, for example, by starting it and beginning a trip. Also in process step S8, depending on the recorded or read data and / or the at least one detected biometric feature, at least one ergonomic and / or comfort feature of the carsharing vehicle 1 can be automatically set or adjusted specifically for user 5.

[0046] During this journey, in a process step S9, user 5 is again captured by camera 13 and their biometric feature is detected, for example, at a random time and / or repeatedly, either regularly or irregularly. The biometric feature of user 5 detected during the journey is then compared with the biometric feature captured before the carsharing vehicle 1 was unlocked and put into operation, and / or with the biometric data read from the driver's license 14. If a deviation or discrepancy is detected, the process follows a program path P4 to a process step S10.

[0047] In procedure step S10, user 5 is requested to cease using carsharing vehicle 1 and to leave the carsharing vehicle 1 or to hand over its operation or control to the holder of driving licence 14. Additionally or alternatively, a functionality of carsharing vehicle 1 may be restricted.

[0048] If, however, no deviation or discrepancy is detected in process step S9, the operation of the carsharing vehicle 1 by user 5 is still permitted. A loop-shaped program path P5 indicates that the verification of the biometric feature can be repeated multiple times during the journey.

[0049] The process steps S1 to S10 and the program paths P1 to P5 can therefore represent function or program blocks or modules of the corresponding computer program. However, other arrangements or sequences than those described here as examples are also possible.

[0050] Overall, the examples described show how a procedure for unlocking the carsharing vehicle 1 by comparing biometric data can be implemented in order to prevent unauthorized use of the carsharing vehicle 1. Reference symbol list 1 car-sharing vehicle 2. Unlocking device 3 Storage medium 4 Processor setup 5 users 6 Access device 7 On-board electrical system 8 Door 9 Server setup 10 Communication interface 11 Data storage 12 Server processor setup 13 Camera 14 Driving licence 15 Control unit 16 Drive system

Claims

[1] Method (17) for operating a car sharing vehicle (1) wherein - data from a driver's license (14) carried by a user (5) are recorded by the car sharing vehicle (1) using a data acquisition device (13), - the collected data are automatically checked, and - if the verification result is positive, the car sharing vehicle (1) is activated for use by the user (5), where before each use of the car sharing vehicle (1) - biometric data of a driving licence holder (14) stored as part of the data on the driving licence (14), - by means of a recognition device (13) for recognizing the user (5) at least one biometric feature of the user (5) is detected while the user is in the area of ​​the car sharing vehicle (1), and - to verify the recorded data, these are compared with the at least one detected biometric characteristic of the user (5), whereby a match results in a positive verification result, characterized by , that If the car sharing vehicle (1) fails the verification test, a video connection is established to an external verification point (9) staffed by verification personnel, and the car sharing vehicle (1) is only unlocked for use by the user (5) after the car sharing vehicle (1) receives an unlock signal from the verification point (9). [2] Method (17) according to claim 1, characterized by , that the data acquisition device (13) and the recognition device (13) are permanently installed in the car sharing vehicle (1), in particular a driving licence reader as the data acquisition device (13) and a camera (13) as the recognition device (13). [3] Method (17) according to any one of the preceding claims, characterized by , that the car sharing vehicle (1) establishes a data connection to a mobile electronic device carried by the user (5) in order to capture the data from the driving licence (14) and / or to detect at least one biometric feature of the user (5) and the mobile electronic device is then used as the data acquisition device (13) and / or as the recognition device (13). [4] Method (17) according to any one of the preceding claims, characterized by, that upon detection of an access authorization device by an access device (6) of the carsharing vehicle (1), a door of the carsharing vehicle (1) is automatically unlocked by this device to allow access to an interior of the carsharing vehicle (1), whereby a starting process of the carsharing vehicle (1) initially remains blocked and is only unlocked upon receipt of a positive verification result. [5] Method (17) according to any one of the preceding claims, characterized by , that the detection device (13) is used to detect the at least one biometric feature of the user (5) in at least one non-optical wavelength range, in particular in an infrared range and / or in an ultraviolet range. [6] Method (17) according to any one of the preceding claims, characterized by, that, based on the recorded data of the driving licence (14) and its comparison with a database (11), in particular one external to the vehicle, it is checked whether the holder of the driving licence (14) is entitled to drive the car sharing vehicle (1) at the current time. [7] Method (17) according to any one of the preceding claims, characterized by , that if the car sharing vehicle (1) fails to perform a verification test, the video connection will be established automatically. [8] Method (17) according to any one of the preceding claims, characterized by , that the car sharing vehicle (1) automatically adjusts at least one ergonomic and / or comfort feature of the car sharing vehicle (1) depending on the data recorded and / or the at least one detected biometric feature. [9] Method (17) according to any one of the preceding claims, characterized by , that - that at least one biometric characteristic of the user (5) is detected again, in particular continuously, after the carsharing vehicle (1) has been put into operation during a trip of the carsharing vehicle (1) and compared with the biometric characteristic detected before commissioning and / or with the data read out, and - in the event of a deviation, a request to cease operation of the carsharing vehicle (1) is issued and / or the functionality of the carsharing vehicle (1) is restricted and / or the carsharing vehicle (1) automatically drives to the nearest stopping place and locks its use there. [10] Car sharing vehicle (1) comprising a data acquisition device (13) for recording data from a driver's license (14), wherein the car sharing vehicle (1) comprises a recognition device (13) for detecting at least one biometric feature of a user (5) present in the area of ​​the car sharing vehicle (1) and a data processing device for comparing the read-in data with the at least one detected biometric feature, wherein the car sharing vehicle (1) comprises an unlocking device (2) which is configured to automatically unlock the car sharing vehicle (1) for use by the user (5) when the read-in data matches the at least one detected biometric feature, characterized by, that the car sharing vehicle (1) has a display device for a video connection and is equipped to establish a video connection to an external inspection point (9) staffed by inspection personnel in the event of a negative inspection result and to only unlock the car sharing vehicle (1) for use by the user (5) upon receipt of an unlock signal from the inspection point (9) by the car sharing vehicle (1).

Citation Information

Patent Citations

  • Method for operating vehicle e.g. renting vehicle for sharing or letting of e.g. motor car, involves activating function of vehicle, if checking of data of general driving authority includes positive result

    DE102012009019A1

  • Procedure for authenticating a driver in a motor vehicle

    DE102013114394A1

  • Method and device for using an electronic driver's license

    DE102016217890A1

  • Method for operating a motor vehicle in an activated at least partially autonomous driving mode

    DE102017202834A1

  • Determination apparatus, imaging apparatus, driver confirmation system, movable body, and determination method

    EP3505404A1