Automatic valet parking system, automatic valet parking program and storage medium
Patent Information
- Application Number
- DE102020207739
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-06-28
- Filing Date
- 2020-06-23
- Publication Date
- 2025-07-24
- Estimated Expiration
- 2040-06-23
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The present invention relates to an automatic valet parking system, an automatic valet parking program, and a storage medium for providing valet parking in autonomous driving control.
[0002] In the prior art, the technique described in JP 2018-41381 A is proposed regarding a valet parking system under automatic operation control (i.e., autonomous driving control). The valet parking system under automatic operation control is hereinafter also referred to as an automatic valet parking system. According to the prior art, when automatic valet parking is performed, a terminal device generates a temporary key comparable to the authorization to perform the automatic operation control. The terminal device transmits the temporary key to an automobile and a parking space server device as a server provided for a parking space. The above-described prior art improves system security by allowing the automobile to verify a match with the temporary key.
[0003] The prior art system described above provides the parking space server device with the temporary key, which assigns authorization to operate the automobile. A digital key, such as the temporary key, for the automobile contains vehicle information and is provided with authorization to perform various manipulations, such as locking and unlocking doors. The digital key is strictly confidential and is generated based on a process that is unique to each vehicle manufacturer or OEM.
[0004] Due to this situation, it is not necessary for the digital key to be shared with any third party other than the OEM. If the third party obtains the digital key, they can decipher the digital key's functionality. The state-of-the-art system described above does not fully improve system security and leaves a security issue unsolved.
[0005] Further valet parking systems are also known from JP 2019 - 35 220 A and JP 2018 - 39 461 A.
[0006] It is an object of the invention to provide an automatic valet parking system, an automatic valet parking program and a storage medium capable of improving system security.
[0007] This object is achieved by the automatic valet parking system having the features according to claim 1, an automatic valet parking program according to claim 6, and the storage medium according to claim 7. Advantageous embodiments are the subject of the dependent claims.
[0008] According to a first aspect, an automatic valet parking system for performing valet parking under autonomous driving control includes: a terminal device; an in-vehicle device mounted on a vehicle; a parking space server mounted for a parking space; and an OEM server controlled directly or indirectly by a vehicle manufacturer. The terminal device, the in-vehicle device, the parking space server, and the OEM server are configured to mutually transmit and receive data. The terminal device includes a request information generation unit. The parking space server includes a key request generation unit. The OEM server includes a key request verification section and a temporary key generation unit. At least one of the parking space server and the in-vehicle device includes a travel scheduling section.The vehicle device includes an autonomous driving control unit. The application information generation unit generates application information as information about an application for valet parking and transmits the application information to the parking lot server and the OEM server. The key request generation unit receives the application information transmitted from the terminal device, generates a temporary key request for requesting generation of a temporary key, and transmits the temporary key request to the OEM server. The key request verification section receives the application information transmitted from the terminal device, receives the temporary key request transmitted from the parking lot server, and verifies authenticity of the temporary key request.If the key request verification section provides a true verification result, the temporary key generation unit generates the temporary key and transmits the temporary key to the in-vehicle device. The driving planning section generates a driving plan for the vehicle, including a route to a targeted parking position. When the autonomous driving control unit receives the temporary key transmitted from the OEM server, the autonomous driving control unit performs autonomous driving control according to the driving plan generated by the driving planning section.
[0009] According to a second aspect, an automatic valet parking program for performing valet parking under autonomous driving control by a terminal device, a vehicle device, a parking space server mounted for a parking space, and an OEM server controlled by a vehicle manufacturer directly or indirectly, which are configured to mutually transmit and receive data, comprises: performing a request information generation procedure using the terminal device; performing a key request generation procedure using the parking space server; performing a key request verification procedure and a temporary key generation procedure using the OEM server; performing a driving scheduling procedure and a temporary key generation procedure, respectively.A driving scheduling procedure using at least one of the parking space server and the vehicle device; and performing a procedure for controlling autonomous driving using the vehicle device. The application information generation procedure includes: generating application information as information about an application for valet parking and transmitting the application information to the parking space server and the OEM server. The key request generation procedure includes: receiving the application information transmitted from the terminal device; generating a temporary key request for requesting generation of a temporary key; and transmitting the temporary key request to the OEM server.The key request verification procedure includes receiving the application information transmitted from the terminal device; receiving the temporary key request transmitted from the parking space server; and verifying an authenticity of the temporary key request. The temporary key generation procedure includes generating the temporary key and transmitting the temporary key to the vehicle when a verification result in the key request verification procedure is true. The driving scheduling procedure includes generating a driving plan including a route to a targeted parking position for the vehicle. The autonomous driving control procedure includes performing autonomous driving control according to the driving plan generated in the driving scheduling procedure when the temporary key transmitted from the OEM server is received.
[0010] According to a third aspect, a computer-readable non-transitory tangible storage medium stores the automatic valet parking program according to the second aspect of the present invention.
[0011] The automatic valet parking system, the automatic valet parking program, and the computer-readable non-transitory tangible storage medium according to the above-described configuration enable the temporary key, which serves as a vehicle digital key, to be directly exchanged between the OEM server device and the vehicle. The temporary key is not supplied or made available to the parking server device. Even if a malicious third party hacks into or gains access to the parking server device, it is impossible to obtain the temporary key or decipher the operation of the vehicle digital key. The above-described configuration provides an excellent effect for enhancing the confidentiality of the vehicle digital key operation and thus improves system security.
[0012] The above and other objects, features, and advantages of the present invention will become more apparent from the following detailed description made with reference to the accompanying drawings. Fig. 1 is a drawing showing an entire configuration of the automatic valet parking system according to a first embodiment, Fig. 2 is a drawing schematically illustrating the detailed configuration of each section of the automatic valet parking system according to the first embodiment, Fig. 3 is a part 1 of 2 of a drawing showing a processing flow for each section when the automatic valet parking is performed according to the first embodiment, Fig. 4 is a part 2 of 2 of a drawing illustrating a processing flow for each section when the automatic valet parking is performed according to the first embodiment, Fig. 5 is a drawing schematically illustrating the detailed configuration of each section of the automatic valet parking system according to a second embodiment, Fig. 6 is a part 1 of 2 of a drawing illustrating a processing flow of each section when the automatic valet parking is performed according to the second embodiment, Fig. 7 is a part 2 of a drawing showing a processing flow of each section when the automatic valet parking is performed according to the second embodiment, Fig. 8 is a drawing schematically illustrating a detailed configuration of each section of the automatic valet parking system according to a third embodiment, Fig. 9 is a drawing illustrating a processing flow of each section when the automatic valet parking is performed according to the third embodiment, Fig. 10 is a drawing showing the detailed configuration of each section of the automatic valet parking system according to a fourth embodiment, Fig. 11 is a drawing illustrating a processing flow of each section when the automatic valet parking is performed according to the fourth embodiment, Fig. 12 is a drawing schematically illustrating the detailed configuration of each section of the automatic valet parking system according to a fifth embodiment, Fig. 13 is a drawing illustrating a processing flow of each section when the automatic valet parking is performed according to the fifth embodiment, and Fig. 14 is a drawing illustrating a processing flow of each section when automatic valet parking is performed according to a sixth embodiment. First embodiment
[0013] The following description explains a first embodiment with reference to the Fig. 1 to 4. Total configuration of the automatic valet parking system 100
[0014] As in Fig. As shown in Figure 1, an automatic valet parking system 100 according to the present embodiment includes a terminal device 200, an automobile 300 (i.e., a vehicle device) comparable to a vehicle, a parking space server device 400, an OEM server device 500, and a map server device 600. The automatic valet parking system 100 performs valet parking under automatic operation control. In the following description, automatic valet parking will be abbreviated to AVP (automatic valet parking) when necessary. In this case, an owner of the automobile 300 corresponds to a user carrying the terminal device 200. According to the present embodiment, the user is the owner of the automobile 300.
[0015] The terminal device 200 has a communication function and essentially stores authentication information about the owner. The terminal device 200 and the automobile 300 (ie, a vehicle device) can transmit and receive data to each other, so that they are capable of communication. The terminal device 200 and the automobile 300 can exchange data, for example, using short-range communication, as indicated by a dashed line in Fig. 1, or through the use of a network 700, mutually or bidirectionally transmitted and received. Network 700 may include, for example, WLAN and mobile communication networks.
[0016] The terminal device 200 is communicatively connected to the parking space server device 400 and the OEM server device 500 via the network 700. The automobile 300 is communicatively connected to the parking space server device 400 and the OEM server device 500 via the network 700. The OEM server device 500, the parking space server device 400, and the map server device 600 are communicatively connected via the network 700. The AVP system 100 enables the terminal device 200, the automobile 300, the parking space server device 400, the OEM server device 500, and the map server device 600 to mutually transmit and receive data.
[0017] According to the present embodiment, the terminal 200 is, for example, a smart device such as a smartphone or a tablet terminal. The terminal 200 may also be an electronic car key that stores owner authentication information and has a communication function. The car 300 has an automatic operation function. The parking space server device 400 is provided for a parking space of a building that provides valet parking services. The parking space server device 400 is under the jurisdiction and management of the building or a parking space management company that has a contract with the building.
[0018] The OEM server device 500 is operated by a vehicle manufacturer or an OEM that manufactures the automobile 300. In this case, the OEM directly manages the OEM server device 500. The OEM server device 500 may be indirectly operated by another company that enters into a confidentiality agreement with the OEM and is entrusted with operation by the OEM.
[0019] The card server device 600 acquires effective zone information as effective zone information for a temporary key described below. The card server device 600 transmits the effective zone information to the OEM server device 500. In the following description, the effective zone is also referred to as an effective section, and the effective zone information is also referred to as effective section information. The card server device 600 belongs to the jurisdiction and management of a reliable third-party organization, such as a public administration concerned with automatic operation control, a specialized official organization in charge of supervision, or a relevant organization of a Ministry of Land, Infrastructure, Transport, and Tourism. Detailed configuration of the terminal device 200
[0020] The terminal 200 internally stores an electronic key. Authentication using the electronic key enables the automobile 300 to perform automatic operation. However, it is disadvantageous to transmit the electronic key to external devices without limitation, resulting in, for example, a reduction in security.
[0021] As described in detail later, the OEM server device 500 generates a temporary key Da that functions only according to the electronic key when performing AVP. Similar to the electronic key, the temporary key Da can authenticate the owner and enables the automobile 300 to perform automatic operation. However, the temporary key Da is deactivated under conditions different from the electronic key, for example, when a predetermined effective period has expired or the automobile 300 leaves an effective zone.
[0022] As in Fig. As shown in Figure 2, the terminal device 200 includes a data transmission / reception section 201 and a storage section 202. The data transmission / reception section 201 transmits and receives various types of data to and from external devices. The storage section 202 stores various types of data. The storage section 202 also stores various types of information received via the data transmission / reception section 201, as well as various types of previously stored information. The terminal device 200 includes functional blocks such as an application information generation section 203 (i.e., an application information generation unit) and an information encryption section 204.
[0023] The functional blocks are implemented as software in such a way that a CPU present in the terminal device 200 executes a computer program stored in a non-transitory, tangible storage medium and performs processing according to the computer program. At least some of the functional blocks can be implemented as hardware.
[0024] The application information generation section 203 generates application information Db, namely, information about an application for valet parking. Application information Db essentially includes user information, information about a parking space where an application is made, and information about the usage time of the parking space. The application information generation section 203 transmits the generated application information Db to the parking space server device 400 and the OEM server device 500 via the data transmission / reception section 201. Each processing performed by the application information generation section 203 is comparable to an application information generation procedure.
[0025] In this case, the storage section 202 stores vehicle information as information about the automobile 300. The vehicle information includes, for example, a vehicle model (such as a regular-sized motor vehicle or a small-sized vehicle), a license plate number, the size such as a vehicle height, and information about the user as an owner of the vehicle. The information such as the vehicle model or size is useful for selecting a parking space. The information encryption section 204 reads the vehicle information from the storage section 202 and encrypts the vehicle information. The information encryption section 204 transmits the encrypted vehicle information Dc to the parking space server device 400 and the OEM server device 500 via the data transmission / reception section 201.
[0026] Request information Db and vehicle information Dc are simultaneously transmitted to the parking space server device 400. Request information Db and vehicle information Dc are simultaneously transmitted to the OEM server device 500. Request information Db to be transmitted to the OEM server device 500 only needs to include at least one piece of information about the parking space where the request is made. In the following description, request information Db and vehicle information Dc transmitted to the OEM server device 500 are collectively referred to as authentication information. Detailed configuration of the automobile 300
[0027] The automobile 300 includes a data transmission / reception section 301 and a storage section 302. The data transmission / reception section 301 transmits and receives various types of data to and from external devices. The storage section 302 stores various types of data. The storage section 302 also stores various types of information received via the data transmission / reception section 301, as well as various types of previously stored information. The automobile 300 includes functional blocks such as a request generation section 303, a decryption section 304, a mapping section 305, and an automatic operation control section 306 (i.e., an autonomous driving control unit).
[0028] The functional blocks are implemented as software in such a way that a CPU present in the automobile 300 executes a computer program stored in a non-transitory physical storage medium and performs processing according to the computer program. At least some of the functional blocks can be implemented as hardware.
[0029] The request generation section 303 receives a temporary key Da and effective zone information Dd transmitted from the OEM server device 500 via the data transmission / reception section 301, and then generates an operation plan request De (i.e., a schedule request) to request generation of an operation plan (i.e., a schedule). How the OEM server device 500 transmits the temporary key Da and the effective zone information Dd will be described later. The request generation section 303 transmits a generated operation plan request De to the parking lot server device 400 via the data transmission / reception section 301.
[0030] The decryption section 304 receives the temporary key Da transmitted from the OEM server device 500, receives a password Df received from the parking lot server device 400, and then verifies whether a combination thereof is effective. The decryption section 304 functions as a key verification section. How the parking lot server device 400 transmits the password Df will be described later. If the above-described combination is effective (i.e., suitable), the decryption section 304 uses the password Df to unlock or validate a temporary key Da. Each processing performed by the decryption section 304 is similar to a key verification procedure.
[0031] The allocation section 305 allocates an operation plan Dg transmitted from the parking lot server device 400 and effective zone information Dd transmitted from the OEM server device 500. How the parking lot server device 400 transmits an operation plan Dg will be described later. As a result of the allocation, the allocation section 305 determines whether a route included in the operation plan Dg is within the effective zone range. The automatic operation control section 306 receives a temporary key Da transmitted from the OEM server device 500 via the data transmission / reception section 301, receives an operation plan Dg and a password Df transmitted from the parking lot server device 400 via the data transmission / reception section 301, and then performs automatic operation control according to the operation plan Dg.
[0032] The verification result from the decryption section 304 may indicate that the combination of the temporary key Da and the password Df is effective, namely, that the decryption section 304 validates the temporary key Da. In this case, the automatic operation control section 306 determines that the operation plan Dg transmitted along with the password Df is usable. The automatic operation control section 306 performs automatic operation control according to the operation plan Dg.
[0033] In this case, the automatic operation control section 306 determines whether the operation plan Dg is usable, taking into account the matching result from the matching section 305. Specifically, if the matching result shows that all routes present in the operation plan Dg are within the effective zone, the automatic operation control section 306 determines that the operation plan Dg is usable. Meanwhile, if the determination shows that at least some of the routes present in the operation plan Dg exceed the effective zone, the automatic operation control section 306 determines that the operation plan Dg is not usable. Each processing performed by the automatic operation control section 306 is similar to an automatic operation control procedure. Detailed configuration of the parking server device 400
[0034] The parking space server device 400 includes a data transmission / reception section 401 and a storage section 402. The data transmission / reception section 401 transmits and receives various types of data to and from external devices. The storage section 402 stores various types of data. The storage section 402 also stores various types of information received via the data transmission / reception section 401, as well as various types of previously stored information. The parking space server device 400 includes functional blocks such as a request generation section 403 (i.e., a key request generation section) and an operation scheduling section 404.
[0035] The functional blocks are implemented as software in such a way that a CPU present in the parking space server device 400 executes a computer program stored in a non-transitory physical storage medium and performs processing according to the computer program. At least some of the functional blocks can be implemented as hardware.
[0036] The request generation section 403 receives application information Db and encrypted vehicle information Dc transmitted from the terminal device 200 via the data transmission / reception section 401, and then generates a temporary key request Dh to request generation of the temporary key Da. The request generation section 403 functions as a key request generation section. The request generation section 403 transmits the generated temporary key request Dh and encrypted vehicle information Dc to the OEM server device 500 via the data transmission / reception section 401. Each processing performed by the request generation section 403 is similar to a key request generation procedure.
[0037] The operation planning section 404 receives an operation plan request De transmitted via the data transmission / reception section 401 and then generates an operation plan Dg. The operation plan Dg essentially includes the current position of the automobile 300, a target parking position of the automobile 300, the route from the current position to the target parking position, timings for straight-ahead travel, turning, and reversing, and the traveling speed of the automobile 300. The target parking position is located at an optimal position considering the availability in the parking lot. The operation planning section 404 receives the password Df transmitted from the OEM server device 500 via the data transmission / reception section 401 and then transmits the password Df together with the generated operation plan Dg to the automobile 300 via the data transmission / reception section 401.Any processing performed by the operation planning section 404 is comparable to an operation plan procedure. Detailed configuration of the OEM server device 500
[0038] The OEM server device 500 includes a data transmission / reception section 501 and a storage section 502. The data transmission / reception section 501 transmits and receives various types of data to and from external devices. The storage device 502 stores various types of data. The storage section 502 also stores various types of information received via the data transmission / reception section 501, as well as various types of previously stored information. The OEM server device 500 includes functional blocks such as a decryption section 503, a verification section 504, a request generation section 505, and a temporary key generation section 506 (i.e., a temporary key generation unit).
[0039] The functional blocks are implemented as software in such a way that a CPU present in the OEM server device 500 executes a computer program stored in a non-transitory tangible storage medium and performs processing according to the computer program. At least some of the functional blocks can be implemented as hardware.
[0040] The decryption section 503 receives the encrypted vehicle information Dc transmitted from the terminal device 200 via the data transmission / reception section 501, and then decrypts the vehicle information Dc. The decryption section 503 receives the encrypted vehicle information Dc transmitted from the parking space server device 400 via the data transmission / reception section 501, and then decrypts the vehicle information Dc. The verification section 504 receives request information Db transmitted from the terminal device 200 via the data transmission / reception section 501, receives a temporary key request Dh transmitted from the parking space server device 400 via the data transmission / reception section 501, and then verifies the authenticity of the temporary key request Dh. The verification section 504 functions as a key request verification section.
[0041] Specifically, the verification section 504 verifies the information transmitted from the terminal device 200 and the parking space server device 400, and thereby verifies the authenticity of the temporary key request Dh as follows. The verification section 504 determines whether the vehicle information Dc transmitted from the terminal device 200 matches vehicle information Dc transmitted from the parking space server device 400. The verification section 504 determines whether the parking space to which an application is made, contained in the application information Db transmitted from the terminal device 200, matches the parking space transmitted by the parking space server device 400 as a source for transmitting the temporary key request Dh, namely, whether the parking space information matches.
[0042] If the vehicle information Dc and the parking space information match, the verification section 504 determines that the temporary key request Dh is authentic. If only one or both of the vehicle information Dc and the parking space information do not match, the verification section 504 determines that the temporary key request Dh is not authentic. Each processing performed by the verification section 504 is comparable to a key request verification procedure. The request generation section 505 generates a zone information request Di to request transmission of effective zone information Dd and functions as a zone request generation section.
[0043] The request generation section 505 transmits the generated zone information request Di to the map server device 600 via the data transmission / reception section 501. Each processing performed by the request generation section 505 is similar to a zone request generation procedure. The temporary key generation section 506 generates the temporary key Da when a verification result from the verification section 504 is true. The temporary key generation section 506 receives effective zone information Dd transmitted from the map server device 600 via the data transmission / reception section 501 and then transmits the effective zone information Dd received together with the generated temporary key Da to the automobile 300 via the data transmission / reception section 501.
[0044] When a temporary key Da is generated, the temporary key generation section 506 also generates the password Df to validate the temporary key Da. The password Df may be, for example, a one-time password. The temporary key generation section 506 transmits the generated password Df to the automobile 300 via the parking lot server device 400. Each processing performed by the temporary key generation section 506 is similar to a temporary key generation procedure. Detailed configuration of the card server device 600
[0045] The card server device 600 includes a data transmission / reception section 601 and a database 602. The data transmission / reception section 601 transmits and receives various types of data to and from external devices. The database 602 stores various types of data. The card server device 600 includes an effective area information retrieval section 603 as a functional block. The effective area information retrieval section 603 is implemented as software in such a manner that a CPU included in the card server device 600 executes a computer program stored in a non-transitory tangible storage medium and performs processing according to the computer program. The effective area information retrieval section 603 may be implemented as hardware.
[0046] The effective zone information retrieval section 603 acquires effective zone information Dd as effective zone information for the temporary key Da. The effective zone information retrieval section 603 functions as an effective zone acquisition section. The effective zone is comparable to a drivable area in which the temporary key Da allows the automobile 300 to drive. The effective zone information is comparable to drivable area information as drivable area information.Specifically, the effective area information retrieval section 603 receives a zone information request Di transmitted from the OEM server device 500 via the data transmission / reception section 601, and then searches for various types of data stored in the database 602 to obtain the effective zone information Dd.
[0047] The effective area information retrieval section 603 transmits the acquired effective zone information Dd to the OEM server device 500 via the data transmission / reception section 601. Each processing performed by the effective area information retrieval section 603 is similar to an effective zone acquisition procedure. The effective zone information Dd is, for example, previously provided by a reliable third-party organization and stored in the database 602. The effective zone information Dd provides map information, which stores the effective zone as an effectively available zone, to the temporary key Da. Only the effective zone, that is, only an area in the parking lot, can be specified as a zone for providing AVP services. Effects of the configuration described above
[0048] The Fig. 3 and Fig. 4 illustrates, for example, processing details of each section when the AVP system 100 according to the present embodiment performs AVP.
[0049] Processing process from requesting AVP to receiving a mobile area
[0050] Fig. 3 illustrates the content of processing from requesting AVP to receiving a drivable area. When user manipulation for valet parking occurs in step S201, the terminal 200 detects the request manipulation and generates request information Db according to the contents of the manipulation.
[0051] In step S202, the terminal 200 encrypts the vehicle information Dc. In step S203, the terminal 200 transmits the request information Db and the encrypted vehicle information Dc to the parking space server device 400. In step S204, the terminal 200 transmits the request information Db and the encrypted vehicle information Dc, namely the authentication information about the valet parking request, to the OEM server device 500.
[0052] In step S401, the parking space server device 400 receives the request information Db and the encrypted vehicle information Dc, and then proceeds to step S402 to generate a temporary key request Dh. In step S403, the parking space server device 400 transmits the temporary key request Dh and the encrypted vehicle information Dc to the OEM server device 500. According to the present embodiment, the OEM server device 500 can decrypt the vehicle information Dc encrypted by the terminal device 200, but the parking space server device 400 cannot. Consequently, the parking space server device 400 cannot identify the content of the vehicle information Dc transmitted from the terminal device 200, which includes, for example, personal information.
[0053] The OEM server device 500 receives the temporary key request Dh and the encrypted vehicle information Dc in step S501, receives the authentication information in step S502, and then proceeds to step S503 to decrypt the vehicle information Dc. In step S504, the OEM server device 500 verifies the authenticity of the temporary key request Dh. The OEM server device 500 performs the processing in step S505 and subsequent steps only if it is determined that the temporary key request Dh is authentic.
[0054] If it is determined that the request Dh for the temporary key is not authentic, the OEM server device 500 transmits an error message to the terminal device 200, informing the user that the temporary key Da cannot be generated and, consequently, the AVP is unavailable. All processing in the AVP system 100 is thus terminated. In step S505, the OEM server device 500 generates a zone information request Di. In step S506, the OEM server device 500 transmits the zone information request Di to the card server device 600.
[0055] In step S601, the map server device 600 receives a zone information request Di, then proceeds to step S602 and searches various types of data stored in the database 602 to obtain effective zone information Dd, namely, drivable area information. In step S603, the map server device 600 transmits effective zone information Dd to the OEM server device 500. In step S507, the OEM server device 500 receives the effective zone information Dd.
[0056] Processing sequence essentially from generating a temporary key to starting an automatic operation
[0057] Fig. 4 illustrates the contents of the processing from generating the temporary key to starting the automatic operation. As described above, the OEM server device 500 receives the effective zone information Dd, namely, the drivable area information, in step S507, then proceeds to step S508, and generates the temporary key Da and the password Df.
[0058] In step S509, the OEM server device 500 transmits the temporary key Da and the effective zone information Dd to the automobile 300. In step S510, the OEM server device 500 transmits the password Df to the parking lot server device 400. In step S301, the automobile 300 receives the temporary key Da and the effective zone information Dd, then proceeds to step S302 and generates an operation plan request De. In step S303, the automobile 300 transmits the operation plan request De to the parking lot server device 400.
[0059] The parking space server device 400 receives the password Df in step S404, receives the operation plan request De in step S405, and then proceeds to step S406 to generate the operation plan Dg. In step S407, the parking space server device 400 transmits the operation plan Dg and the password Df to the automobile 300. In step S304, the automobile 300 receives the operation plan Dg and the password Df and then proceeds to step S305 to verify whether the combination of the temporary key Da and the password Df is valid. If the verification result shows that the combination is valid, the automobile 300 uses the password Df to unlock the temporary key Da.
[0060] If the verification result shows that the combination of the temporary key Da and the password Df is invalid, the automobile 300 transmits an error message to the terminal 200, notifying the user that the temporary key Da cannot be unlocked and, consequently, the AVP is unavailable. All processing in the AVP system 100 is thus terminated.
[0061] In step S306, the automobile 300 compares the operation plan Dg and the effective zone information Dd to determine whether the route included in the operation plan Dg belongs to the drivable area. If it is determined that all the routes included in the operation plan Dg belong to the effective zone, namely, the drivable area, the automobile 300 determines that the operation plan Dg is usable and then proceeds to step S307 to start automatic operation control according to the operation plan Dg.
[0062] If it is determined that at least some of the routes present in the operation plan Dg exceed the effective zone, namely the drivable area, the automobile 300 determines that the operation plan Dg is unusable. In this case, the automobile 300 transmits an error message to the terminal 200, notifying the user that the operation plan Dg is unavailable and, consequently, the AVP is unavailable. All processing in the AVP system 100 is thus terminated.
[0063] As described above, the AVP system 100 according to the present embodiment allows the OEM server device 500 and the automobile 300 to directly exchange the temporary key as a digital key for the automobile 300. The temporary key is not disclosed to the parking space server device 400. Even if a malicious third party hacks into the parking space server device 400, it is impossible to obtain the temporary key or decipher the operation of the digital key for the automobile 300. The present embodiment provides an excellent effect of being able to enhance the confidentiality of the operation of the digital key for the automobile 300 and thus improve system security.
[0064] When the temporary key is generated, the OEM server device 500 also generates a password to validate the temporary key. The automobile 300 receives the temporary key and password and then performs automatic operation control according to the operation plan. In this case, authorization to operate the automobile 300 is not granted until both the temporary key and password are present. The OEM server device 500 transmits the temporary key directly to the automobile 300 and transmits the password indirectly via the parking lot server device 400.
[0065] The temporary key and password are thus transmitted via different paths, making it possible to reduce the possibility of a malicious third party hacking both the temporary key and password. Even if one of the temporary key and password units is hacked, it is impossible to decipher the functionality of the digital key for the automobile 300 or to provide the hacking third party with the authorization to operate the automobile 300. Consequently, it is possible to reliably avoid a worst-case scenario in which the automobile 300 is diverted from the parking space and stolen despite the user's attention.
[0066] The parking space server device 400 transmits a set of the generated operation plan and the password to the automobile 300. If the automobile 300 can normally unlock the temporary key using the password transmitted from the parking space server device 400, the automobile can determine that the operation plan received with the password is also authentic or properly transmitted from the parking space server device 400.
[0067] Even if a malicious third party, such as a hacker, transmits an incorrect operation plan, the automobile 300 can determine that the operation plan is faulty and unusable because the correct password is not attached. Even if a malicious third party generates and transmits a questionable operation plan (such as intentionally leading the automobile 300 out of the parking space), the automobile 300 according to the present embodiment does not perform automatic operation control according to the questionable operation plan (i.e., an illegal operation plan), so it is possible to reliably maintain system security.
[0068] The AVP system 100 according to the present embodiment includes the card server device 600 having the effective zone retrieval section 603 that acquires the effective zone information Dd as effective zone information for the temporary key Da. The effective zone retrieval section 603 receives the zone information request Di transmitted from the OEM server device 500 to acquire the effective zone information Dd and transmits the effective zone information Dd to the OEM server device 500.
[0069] The automobile 300 determines whether the operation plan Dg is usable by considering the result of a correlation between the operation plan Dg transmitted from the parking space server device 400 and the effective zone information Dd transmitted from the OEM server device 500. This configuration makes it possible to reduce the probability that the automatic operation control is performed according to the questionable operation plan Dg (such as a plan including a lane leading outward from the parking space). As a result, system safety is further improved. Second embodiment
[0070] With reference to the Fig. 5 to 7, a second embodiment that changes the detailed configuration of the devices in the first embodiment will be described below. Similar changes can be made by a third embodiment to be described.
[0071] As in Fig. 5, the parking space server device 400 in an AVP system 120 according to the present embodiment differs from the parking space server device 400 according to the first embodiment shown in Fig. 2, essentially by adding an emergency stop section 405.
[0072] The emergency stop section 405 generates an emergency stop request Dj and transmits the emergency stop request Dj to each automobile via the data transmission / reception section 401. The emergency stop request Dj places all moving automobiles including the automobile 300 in a parking space into an emergency stop. The emergency stop request Dj is triggered by the occurrence of a situation that hinders the normal execution of AVP, such as a case where a pedestrian is detected entering an area where pedestrians are prohibited from entering during an accident, or where the parking space server device 400 is turned off.
[0073] When the reason for the emergency stop is resolved after the emergency stop request Dj is transmitted, the emergency stop section 405 causes the request generation section 403 to regenerate a temporary key request Dh. As described in detail later, various types of processing triggered by regenerating the temporary key request Dh are performed so that the automobile 300 is released from the emergency stop state to restart the AVP. According to the present embodiment, as described above, a system at the parking lot automatically determines instructions for generating the emergency stop request Dj and regenerating the temporary key request Dh. However, for example, an administrator of the parking lot may determine the instruction.
[0074] The following description explains the operation of the configuration described above.
[0075] The Fig. 6 and Fig. 7 illustrates processing details of each section when the AVP system 120 according to the present embodiment performs AVP.
[0076] Processing sequence from the start of automatic operation to the execution of an emergency stop
[0077] Fig. 6 shows the contents of the processing from the start of automatic operation to the execution of the emergency stop. As in Fig. 6, the parking space server device 400 generates the emergency stop request Dj in step S408, which is triggered by the occurrence of the situations described above.
[0078] In step S409, the parking space server device 400 transmits the generated emergency stop request Dj to the automobile 300. In step S307, the automobile 300 starts automatic operation control according to the operation plan Dg. In step S308, the automobile 300 receives the emergency stop request Dj transmitted from the parking space server device 400 and then proceeds to step S309. In step S309, the automobile 300 determines whether the emergency stop is required.
[0079] If it is determined that an emergency stop is necessary, the automobile 300 proceeds to step S310 and performs the emergency stop. In this case, the automobile 300 has a function, such as the Pre-Crash Safety System, that automatically applies the brakes before colliding with a preceding obstacle. Even if a preceding automobile performs the AVP and comes to an emergency stop, the following automobile does not collide with the preceding vehicle.
[0080] Processing sequence from performing an emergency stop to restarting automatic operation
[0081] Fig. 7 shows the contents of the processing from the execution of the emergency stop to a restart or a re-start of the automatic operation. As in Fig. As shown in Figure 7, the parking space server device 400 transmits the emergency stop request Dj and then determines in step S410 whether the AVP can be restarted. If the parking space server device 400 determines that the cause of the emergency stop has been resolved and the AVP can be restarted, the parking space server device 400 proceeds to step S411 and regenerates the temporary key request Dh.
[0082] In step S412, the parking space server device 400 transmits the request Dh for the temporary key and the encrypted vehicle information Dc to the OEM server device 500. The vehicle information Dc transmitted from the terminal device 200 is stored in the storage section 402 of the parking space server device 400 until the parking exit is completed. In step S412, the parking space server device 400 reads the vehicle information Dc stored in the storage section 402 and then transmits the vehicle information Dc.
[0083] In step S511, the OEM server device 500 receives the temporary key request Dh and the encrypted vehicle information Dc, and then proceeds to step S512 to decrypt the vehicle information Dc. In step S513, the OEM server device 500 verifies whether the temporary key request Dh is authentic. The authentication information transmitted from the terminal device 200, namely, the application information Db and the vehicle information Dc, are stored in the storage section 502 of the OEM server device 500 until the parking is completed. In step S513, the OEM server device 500 reads the authentication information stored in the storage section 502 and then verifies whether the temporary key request Dh is authentic.
[0084] The OEM server device 500 performs the processing in step S514 and subsequent steps only if it is determined that the temporary key request Dh is authentic. The same processing as that described in the first embodiment is performed if it is determined that the temporary key request Dh is not authentic. In step S514, the OEM server device 500 generates the temporary key Da and the password Df. In this case, the OEM server device 500 is not required to transmit the effective zone information Dd to the automobile 300 and thus does not exchange data with the card server device 600.
[0085] In step S515, the OEM server device 500 transmits the temporary key Da to the automobile 300. In step S516, the OEM server device 500 transmits the password Df to the parking lot server device 400. The automobile 300 performs the emergency stop in step S310, receives the temporary key Da in step S311, and then goes to step S312 to generate the operation plan request De.
[0086] In step S313, the automobile 300 transmits the operation plan request De to the parking space server device 400. The parking space server device 400 receives the password Df in step S413, receives the operation plan request De in step S414, and then proceeds to step S415 to generate the operation plan Dg. In step S416, the parking space server device 400 transmits the operation plan Dg and the password Df to the automobile 300.
[0087] The automobile 300 receives the operation plan Dg and the password Df in step S314 and then proceeds to step S351 to determine whether the combination of the temporary key Da and the password Df is effective. If the verification result shows that the combination is effective, the automobile 300 uses the password Df to unlock the temporary key Da. Processing similar to that described in the first embodiment is performed if the verification result shows that the combination of the temporary key Da and the password Df is ineffective. In step S316, the automobile 300 associates the operation plan Dg and the effective zone information Dd, and determines whether the route included in the operation plan Dg belongs to the drivable area.
[0088] The effective zone information Dd transmitted from the OEM server device 500 is stored in the storage section 302 of the automobile 300 until the parking exit is completed. In step S316, the automobile 300 reads the effective zone information Dd stored in the storage section 302 and then associates the operation plan Dg and the effective zone information Dd. If the association result shows that it is determined that the operation plan Dg is usable, the automobile 300 proceeds to step S317 and restarts the automatic operation control according to the operation plan Dg. The processing similar to that described in the first embodiment is performed if it is determined that the operation plan Dg is not usable.
[0089] The present embodiment described above provides the following effects.
[0090] For example, all cars in the parking lot are required to stop instantly when a situation occurs that hinders the normal execution of AVP, such as a case where a pedestrian is detected entering an area where pedestrian entry is prohibited during an accident, or when the parking lot server device 400 is turned off. When such a situation occurs, the present embodiment allows the parking lot server device 400 to directly transmit the emergency stop request Dj to the car 300 without requiring authentication using the temporary key Da and the password Df. The car 300 can stop instantly.
[0091] However, if the reason for the emergency stop is resolved to restart the AVP, there may be a risk of hacking if the parking space server device 400 directly transmits an instruction to the automobile 300 to release the emergency stop state to restart the automatic operation. To restart the automatic operation, the present embodiment performs authentication using the temporary key Da and the password Df in a manner similar to each processing performed when the automatic operation first starts. This makes it possible to reduce the likelihood of hacking by a malicious third party when the automatic operation restarts.
[0092] It is highly likely that a user will leave the parking space after requesting AVP using the terminal device 200. After the automobile 300 starts automatic operation control, it is highly likely that the automobile 300, the parking space server device 400, and the OEM server device 500 will be unable to communicate with the mobile terminal device 200. As a solution, the automobile 300, the parking space server device 400, and the OEM server device 500 store various types of information (such as request information Db and vehicle information Dc) transmitted from the terminal device 200 in the storage sections 302, 402, and 502.
[0093] When the automatic operation restarts after the emergency stop, the automobile 300, the parking space server device 400, and the OEM server device 500 can perform processing similar to each processing performed when the automatic operation first starts, without requiring the terminal device 200 to retransmit various types of information. Various types of information remain stored in the storage sections 302, 402, and 502 until the AVP (parking entry or exit) service is completed. After the service is completed, the information can be automatically deleted at a specific timing. This can prevent personal information contained in, for example, the application information Db or the vehicle information Dc from being leaked. Third embodiment
[0094] With reference to the Fig. 8 and Fig. 9, the following description explains the third embodiment, which changes the detailed configuration of the devices according to the first embodiment.
[0095] As in Fig. 8, the terminal 200 in an AVP system 130 according to the present embodiment differs from the terminal 200 according to the first embodiment, which is shown in Fig. 2, essentially in that an information generating section 205 (ie, an application information generating section) replaces the application information generating section 203 and an information encryption section 206 replaces the information encryption section 204.
[0096] In this case, the automobile 300 represents a rental car or a shared car that is not owned by a user who owns the terminal 200. Consequently, the terminal 200 does not store vehicle information Dc. When the AVP is performed using the automobile 300, the user is not required to request the authentication information about the right to temporarily own the automobile 300 from the OEM server device 500.
[0097] Like the application information generation section 203, the information generation section 205 generates application information Db and generates an authentication information request DI to request the generation of temporary possession authentication information Dk. The information generation section 205 transmits the generated authentication information request DI to the OEM server device 500 via the data transmission / reception section 201. The information encryption section 206 receives the temporary possession authentication information Dk transmitted from the OEM server device 500 via the data transmission / reception section 201 and then encrypts the temporary possession authentication information Dk.
[0098] The information encryption section 206 encrypts the temporary possession authentication information Dk, which includes information about the user of the terminal 200. The information encryption section 206 transmits the encrypted temporary possession authentication information Dk to the parking space server device 400 and the OEM server device 500 via the data transmission / reception section 201. In the following description, the temporary possession authentication information Dk may be abbreviated to authentication information Dk.
[0099] In this case, the application information Db and the temporary possession authentication information Dk are simultaneously transmitted to the parking space server device 400. The application information Db and the authentication information Dk are simultaneously transmitted to the OEM server device 500. In the following description, the application information Db and the authentication information Dk transmitted to the OEM server device 500 may be collectively referred to as the authentication information.
[0100] The parking space server device 400 according to the present embodiment is different from the parking space server device 400 according to the first embodiment shown in Fig. 2, essentially in that a request generation section 406 (i.e., a key request generation unit) replaces the request generation section 403. The request generation section 406 receives the application information Db and the authentication information Dk transmitted from the terminal 200 via the data transmission / reception section 401 and then generates a temporary key request Dh. The request generation section 406 functions as a key request generation section. The request generation section 406 transmits the generated temporary key request Dh and the encrypted authentication information Dk to the OEM server device 500 via the data transmission / reception section 401.
[0101] The OEM server device 500 according to the present embodiment is different from the OEM server device 500 according to the first embodiment shown in Fig. 2, essentially by adding an authentication information generating section 507, replacing the decryption section 503 with a decryption section 508, and replacing the verification section 504 with a verification section 509. The authentication information generating section 507 receives the authentication information request DI transmitted from the terminal 200 via the data transmitting / receiving section 501 and then generates the temporary possession authentication information Dk.
[0102] The temporary possession authentication information Dk essentially includes vehicle information about the automobile 300 and information associating a user ID corresponding to the user applying the AVP with an available time slot during which the user can use the automobile 300. For example, when a specific expiration date expires, the temporary possession authentication information Dk becomes invalid and unusable. The authentication information generation section 507 transmits the generated temporary possession authentication information Dk to the terminal 200 via the data transmission / reception section 501.
[0103] The decryption section 508 receives the encrypted authentication information Dk transmitted from the terminal device 200 via the data transmission / reception section 501, and then decrypts the authentication information Dk. The decryption section 508 receives the encrypted authentication information Dk transmitted from the parking space server device 400 via the data transmission / reception section 501, and then decrypts the authentication information Dk. The verification section 509 receives the request information Db and the authentication information Dk transmitted from the terminal device 200 via the data transmission / reception section 501, receives the temporary key request Dh transmitted from the parking space server device 400 via the data transmission / reception section 501, and then verifies the authenticity of the temporary key request Dh.The verification section 509 functions as a key request verification section.
[0104] Specifically, the verification section 509 verifies the information transmitted from the terminal device 200 and the parking space server device 400, thereby verifying the authenticity of the temporary key request Dh as follows. The verification section 509 determines whether the vehicle information included in the authentication information Dk transmitted from the terminal device 200 and the vehicle information included in the authentication information Dk transmitted from the parking space server device 400 match.
[0105] The verification section 509 determines whether the parking space to which an application is made in the application information Db transmitted from the terminal 200 and the parking space provided with the parking space server device 400 as an origin for transmitting the temporary key request Dh match, namely, whether the parking space information matches. If the vehicle information and the parking space information match, the verification section 509 determines that the temporary key request Dh is authentic. If one or both of the vehicle information and the parking space information do not match, the verification section 509 determines that the temporary key request Dh is not authentic.
[0106] Initially, the authentication information generating section 507 of the OEM server device 500 generates the authentication information Dk. Consequently, the verification section 509 may preliminarily acquire the vehicle information contained in the authentication information Dk. The verification section 509 may determine that the vehicle information contained in the vehicle information previously acquired by the authentication information generating section 507 matches. In this case, the verification section 509 may determine that all three pieces of vehicle information match, or may determine that any two pieces of the three pieces of vehicle information match.
[0107] The following description explains operation of the configuration described above.
[0108] Fig. 9 illustrates the contents of the processing from requesting the AVP to receiving the drivable area according to the present embodiment. The processing from generating the temporary key to starting the automatic operation is substantially the same as the processing according to the first embodiment shown in Fig. 4, and a description is omitted for the sake of simplicity. When user tampering occurs during valet parking, the terminal 200 detects the request tampering in step S221 and generates request information Db and authentication information request DI according to the contents of the tampering.
[0109] In step S222, the terminal device 200 transmits an authentication information request DI to the OEM server device 500. In step S521, the OEM server device 500 recognizes the authentication information request DI and then proceeds to step S522 to generate the temporary possession authentication information Dk. In step S523, the OEM server device 500 transmits the temporary possession authentication information Dk to the terminal device 200.
[0110] In step S223, the terminal device 200 receives the temporary possession authentication information Dk and then proceeds to step S224 to encrypt the temporary possession authentication information Dk. In step S225, the terminal device 200 transmits the request information Db and the encrypted temporary possession authentication information Dk to the parking space server device 400. In step S226, the terminal device 200 transmits the request information Db and the encrypted temporary possession authentication information Dk, namely, the authentication information for the valet parking application, to the OEM server device 500.
[0111] In step S421, the parking space server device 400 receives the request information Db and the encrypted temporary possession authentication information Dk, and then proceeds to step S422 to generate the temporary key request Dh. In step S423, the parking space server device 400 transmits the temporary key request Dh and the encrypted temporary possession authentication information Dk to the OEM server device 500. According to the present embodiment, the OEM server device 500 can decrypt the temporary possession authentication information Dk encrypted by the terminal device 200, but the parking space server device 400 cannot. Consequently, the parking space server device 400 cannot identify the contents of the authentication information Dk, which includes, for example, personal information, transmitted from the terminal device 200.
[0112] In step S524, the OEM server device 500 receives the temporary key request Dh and the encrypted temporary possession authentication information Dk, receives the authentication information in step S525, and then proceeds to step S526 to decrypt the authentication information Dk. In step S527, the OEM server device 500 verifies whether the temporary key request Dh is authentic. The OEM server device 500 performs the processing in step S505 and subsequent steps only if it is determined that the temporary key request Dh is authentic.
[0113] The processing described in the first embodiment is applicable to the processing performed when it is determined that the request Dh for the temporary key is not authentic. The processing described in the first embodiment is also applicable to the processing in step S505 and the later steps, namely, the processing (steps S505 to S507) performed by the OEM server device 500 and the processing (steps S601 to S603) performed by the card server device 600.
[0114] As described above, the present embodiment assumes a system in which the automobile 300 represents a rental car or a shared car, rather than a car owned by the user who owns the terminal 200. As in the first embodiment, the present embodiment allows the OEM server device 500 and the automobile 300 to directly exchange the temporary key as a digital key for the automobile 300. The temporary key is not transmitted to the parking space server device 400. Therefore, the present embodiment provides an effect similar to that of the first embodiment. Fourth embodiment
[0115] With reference to the Fig. 10 and Fig. Referring to Figure 11, the following description explains a fourth embodiment that changes the detailed configuration of the devices according to the first embodiment. The same changes can be made to the third embodiment.
[0116] As in Fig. 10, the automobile 300 in an AVP system 140 according to the present embodiment differs from the automobile 300 according to the first embodiment, which is shown in Fig. 2, essentially by replacing the request generation section 303 with a request generation section 307, adding an operation planning section 308 (i.e., a driving planning section), and replacing the automatic operation control section 306 with an automatic operation control section 309 (i.e., an autonomous driving control unit).
[0117] The request generation section 307 receives the temporary key Da and the effective zone information Dd transmitted from the OEM server device 500 via the data transmission / reception section 301, and then generates a position determination request Dm requesting the determination of a target parking position. The request generation section 307 transmits the generated position determination request Dm to the parking lot server device 400 via the data transmission / reception section 301. The operation planning section 308 receives the target position information Dn transmitted from the parking lot server device 400 via the data transmission / reception section 301.Incidentally, the operation planning section 308 generates an operation plan Dg based on the target position information Dn if the verification result from the decryption section 304 shows that the combination of the temporary key Da and the password Df is effective. The following description explains how the parking space server device 400 transmits the target position information Dn.
[0118] In this case, the operation planning section 308 receives the effective zone information Dd transmitted from the OEM server device 500 and then generates the operation plan Dg taking into account the effective zone information Dd. The operation planning section 308 transmits the generated operation plan Dg to the parking lot server device 400 via the data transmission / reception section 301. The operation planning section 308 receives the correction information Do and unavailability information Dp transmitted from the parking lot server device 400 via the data transmission / reception section 301 and then regenerates the operation plan Dg based on the correction information Do. The following description explains how the parking lot server device 400 transmits the correction information Do and unavailability information Dp.The operation planning section 308 also transmits the regenerated operation plan Dg to the parking lot server device 400 via the data transmitting / receiving section 301.
[0119] The automatic operation control section 309 receives availability information Dq transmitted from the parking space server device 400 through the data transmission / reception section 301, and then performs automatic operation control according to the operation plan Dg generated by the operation planning section 308. The following description explains how the parking space server device 400 transmits the availability information Dq.
[0120] The parking space server device 400 according to the present embodiment is different from the parking space server device 400 according to the first embodiment shown in Fig. 2, essentially by omitting the operation planning section 404 (i.e., a travel planning section) and adding a parking position determination section 407 and an operation plan verification section 408. The parking position determination section 407 receives the password Df transmitted from the OEM server device 500 via the data transmission / reception section 401, receives a position determination request Dm transmitted from the automobile 300, and then determines a targeted parking position for the automobile 300.
[0121] The parking position determining section 407 transmits the password Df together with the target position information Dn as the information about the targeted parking position to the automobile 300 via the data transmitting / receiving section 401.
[0122] Each processing performed by the parking position determining section 407 is comparable to a parking position determining procedure. The target position information Dn includes map information about the parking space in addition to the targeted parking position, which represents, for example, a specific parking space.
[0123] The operation plan verification section 408 receives the operation plan Dg transmitted from the automobile 300 via the data transmission / reception section 401 and then verifies whether the operation plan Dg is questionable (i.e., unsuitable). The operation plan verification section 408 is comparable to a plan verification section. If the operation plan Dg is not questionable (i.e., suitable), the operation plan verification section 408 transmits the availability information Dq representing the operation plan Dg as available to the automobile 300 via the data transmission / reception section 401.
[0124] If the operation plan Dg is questionable, the operation plan verification section 408 generates correction information Do as the information about the correction of the operation plan Dg. The operation plan verification section 408 transmits the correction information Do and the unavailability information Dp representing the operation plan Dg as unavailable to the automobile 300 via the data transmission / reception section 401. Each processing performed by the operation plan verification section 408 is comparable to a plan verification procedure.
[0125] Specifically, the operation plan verification section 408 may use the following technique or method to verify the operation plan Dg. The operation plan verification section 408 determines that the operation plan Dg is not questionable if a first condition that the plan prevents the automobile 300 from being led out of the parking space is met. The operation plan Dg that satisfies the first condition can avoid a worst-case scenario in which a malicious third party steals the automobile 300, for example, by leading it out of the parking space contrary to the user's intention.
[0126] The operation plan verification section 408 may determine that the operation plan Dg is not questionable if a second condition is met in addition to the first condition. The second condition means that the plan is effective up to a correct target position. Specifically, the second condition may require that an error between the target position of the automobile 300 in the operation plan Dg and the targeted parking position represented by the target position information Dn be smaller than a specific threshold error. The threshold error may be set to a value corresponding to various capabilities of the parking space server device 400. The operation plan Dg that satisfies the second condition can avoid an adverse effect on the parking space management performed by the parking space server device 400.
[0127] The operation plan verification section 408 can determine that the operation plan Dg is not questionable if a third condition is met in addition to the first condition or in addition to the first and second conditions. The third condition means that the traveling direction of the automobile 300 in the operation plan Dg corresponds to the traveling direction specified in the parking space. A plurality of automobiles are most likely to travel in the parking space at the same time. In such a situation, if the automobile 300 does not travel in the specific traveling direction, traveling in the wrong direction will be caused, thereby deteriorating safety. The operation plan Dg that satisfies the third condition can prevent, for example, safety from being compromised due to traveling in the wrong direction.
[0128] The third condition may accept an approximate match between the traveling direction and the specific traveling direction. However, the condition may determine whether the automobile 300 is traveling in a non-questionable lane in a detailed direction. The operation plan verification section 408 may determine that the operation plan Dg is non-questionable if the operation plan Dg allows the automobile 300 to travel in a lane free from collision with a pillar or another parked automobile in the parking space. Such a determination may be provided as needed depending on various capabilities of the parking space server device 400.
[0129] The operation plan verification section 408 may generate the correction information Do using one of the following two specific techniques. A first generation technique generates the correction information Do represented by a specific instruction for correcting a part of the operation plan Dg. Specifically, the first generation technique generates the correction information Do represented by information relating a problem in the operation plan Dg to the method for solving the problem. The first generation technique enables the automobile 300 to recognize a problem and the method for solving the problem and then regenerate the operation plan Dg. The first generation technique may regenerate the non-questionable operation plan Dg based on a reduced number of corrections, making it possible to reduce the processing load for the automobile 300.
[0130] A second generation technique generates the correction information Do, which is represented by information indicating that the operation plan Dg is questionable, and the plan is regenerated from the beginning. This second generation technique eliminates the need to create a method for solving a problem, making it possible to reduce the processing load on the parking lot server device 400. When the operation plan Dg for guiding to the same target position is generated according to a technique or algorithm for generating the operation plan Dg, it is not necessary for the plan to be proposed with the same route, but a different route can most likely be proposed each time the plan is created.
[0131] The problem can be easily solved by regenerating the plan from the beginning. The bug or error can be resolved by regenerating the plan. It is then possible to generate a non-questionable operating plan Dg. Ultimately, a non-questionable operating plan is generated, even if the operating plan Dg is regenerated based on the correction information Do generated by the second generation technique.
[0132] The following description explains operation of the configuration described above.
[0133] Fig. Fig. 11 shows the contents of the processing from generating the temporary key to starting the automatic operation according to the present embodiment. The processing from applying for the AVP to receiving a drivable area is the same as the processing according to the first embodiment shown in Fig. 3, and a description is omitted for the purpose of simplification.
[0134] In Fig. 11, the processing in steps S508 to S510 performed by the OEM server device 500, in step S404 performed by the parking space server device 400, and in step S301 performed by the automobile 300 is the same as the processing according to the first embodiment shown in Fig. 4, and a description is omitted for the sake of simplicity. In this case, the automobile 300 receives the temporary key Da and the effective zone information Dd in step S301 and then proceeds to step S321 to generate the positioning request Dm. In step S322, the automobile 300 transmits the positioning request Dm to the parking space server device 400.
[0135] The parking space server device 400 receives the password Df in step S404, receives the position determination request Dm in step S431, and then proceeds to step S432 to determine the target parking position for the automobile 300. In step S433, the parking space server device 400 transmits the target position information Dn and the password Df as the information about the determined target parking position to the automobile 300.
[0136] In step S323, the automobile 300 receives the target position information Dn and the password Df, and then proceeds to step S324 to determine whether the combination of the temporary key Da and the password Df is valid. If the verification result shows that the combination is valid, the automobile 300 unlocks the temporary key Da using the password Df. If the verification result shows that the combination of the temporary key Da and the password Df is invalid, the processing similar to that described in the first embodiment is performed.
[0137] In step S325, the automobile 300 generates the operation plan Dg, taking into account the information Dd about the effective zone, namely the drivable area, for the automobile 300. In step S326, the automobile 300 transmits the generated operation plan Dg to the parking space server device 400. In step S434, the parking space server device 400 receives the operation plan Dg and then proceeds to step S435 to determine whether the operation plan Dg is questionable. In step S436, the parking space server device 400 transmits information about the result of a verification of the operation plan Dg to the automobile 300.
[0138] If the verification result shows that the operation plan Dg is not questionable, the parking space server device 400 transmits the availability information Dq to the automobile 300 in step S436. If the verification result shows that the operation plan Dg is questionable, the parking space server device 400 transmits the correction information Do and the unavailability information Dp to the automobile 300 in step S436. In step S327, the automobile 300 receives the availability information Dq or the correction information Do and the unavailability information Dp and then proceeds to step S328.
[0139] In step S328, the automobile 300 determines the result of the verification of the operation plan Dg performed by the parking space server device 400. If the availability information Dq is received, the automobile 300 determines that the operation plan Dg is not questionable. If the unavailability information Dp is received, the automobile 300 determines that the operation plan Dg is questionable. If it is determined that the operation plan Dg is not questionable, the automobile 300 proceeds to step S329 and starts automatic operation control according to the operation plan Dg. If it is determined that the operation plan Dg is questionable, the automobile 300 returns to step S325 and generates the operation plan Dg again.
[0140] As described above, the system according to the present embodiment is substantially incorporated in the automobile 300. The operation planning section 308 incorporated in the automobile 300 generates operation plans. Like the first embodiment, which is substantially incorporated in the parking lot, the present embodiment again allows the OEM server device 500 and the automobile 300 to directly exchange the temporary key as a digital key for the automobile 300. The temporary key is not supplied from the parking lot server device 400. Therefore, the present embodiment provides an effect similar to that of the first embodiment.
[0141] In this case, the operation plan verification section 408 provided in the parking lot server device 400 verifies whether an operation plan generated by the operation planning section 308 provided in the automobile 300 is questionable. According to the present embodiment, the parking lot server device 400 provided for a parking lot verifies the validity of an operation plan generated in the automobile 300, thereby ensuring the security of the operation plan. Fifth embodiment
[0142] With reference to the Fig. 12 and Fig. 13, the following description explains a fifth embodiment which changes the detailed configuration of the devices in the fourth embodiment.
[0143] As in Fig. 12, the parking space server device 400 in an AVP system 150 according to the present embodiment differs from the parking space server device 400 according to the fourth embodiment in Fig. 10 essentially by adding the emergency stop section 405 described in the second embodiment.
[0144] The following description explains operation of the configuration described above.
[0145] Fig. 13 shows the contents of the processing from performing the emergency stop to restarting the automatic operation. The processing from starting the automatic operation to performing the emergency stop according to the present embodiment is the same as the processing according to the second embodiment shown in Fig. 6, and a description is omitted for the purpose of simplification.
[0146] As in Fig. 13, the processing in steps S511 to S516 performed by the OEM server device 500, in steps S410 to S413 performed by the parking space server device 400, and in steps S310 and S331 performed by the automobile 300 is the same as the processing according to the second embodiment shown in Fig. 7, and a description is omitted for the sake of simplicity. In this case, the automobile 300 performs the emergency stop in step S310, receives the temporary key Da in step S331, and then proceeds to step S332 to generate the positioning request Dm. In step S333, the automobile 300 transmits the positioning request Dm to the parking space server device 400.
[0147] The parking space server device 400 receives the password Df in step S404, receives the position determination request Dm in step S441, and then proceeds to step S442 to determine the target parking position for the automobile 300. In step S433, the parking space server device 400 transmits the target position information Dn and the password Df as the information about the determined target parking position to the automobile 300.
[0148] In step S334, the automobile 300 receives the target position information Dn and the password Df, and then proceeds to step S335 to verify whether the combination of the temporary key Da and the password Df is valid. If the verification result shows that the combination is valid, the automobile 300 uses the password Df to unlock the temporary key Da. If the verification result shows that the combination of the temporary key Da and the password Df is invalid, the processing similar to that described in the first embodiment is performed.
[0149] In step S336, the automobile 300 generates the operation plan Dg taking into account the effective zone information Dd, namely the drivable area for the automobile 300. The effective zone information Dd transmitted from the OEM server device 500 is stored in the storage section 302 of the automobile 300 until the parking exit is completed. In step S336, the automobile 300 reads the effective zone information Dd stored in the storage section 302 and then generates the operation plan Dg. In step S337, the automobile 300 transmits the generated operation plan Dg to the parking space server device 400.
[0150] In step S444, the parking space server device 400 receives the operation plan Dg and then proceeds to step S445. The processing in step S445 and subsequent steps, particularly the processing in steps S444 to S446 performed by the parking space server device 400 and in steps S338 to S340 performed by the automobile 300, is similar to the processing in steps S434 to S436 and S338 to S340 according to the fourth embodiment shown in Fig. 11 is shown.
[0151] As described above, the present embodiment, which is substantially located in the automobile 300, is similar to the second embodiment, which is substantially located in the parking lot. When a situation occurs that hinders the normal execution of AVP, the present embodiment also allows the parking lot server device 400 to directly transmit the emergency stop request Dj to the automobile 300 without requiring authentication using the temporary key Da and the password Df. The automobile 300 can stop instantly.
[0152] To restart the automatic operation, the present embodiment, which is similar to the second embodiment, performs authentication using the temporary key Da and the password Df. This makes it possible to reduce the likelihood of hacking by a malicious third party when the automatic operation restarts. Consequently, the present embodiment provides an effect similar to that of the second embodiment. Sixth embodiment
[0153] With reference to Fig. Referring to Figure 14, the following description describes a sixth embodiment that modifies the processing details of the AVP when performing according to the first embodiment. The same modifications can also be made for the second to fifth embodiments.
[0154] The embodiments described above assume an on-demand application, namely a situation in which a user arrives at the parking lot and then requests AVP on the spot. For example, the AVP system 100 may respond in a situation in which a user pre-reserves AVP. The following description represents the on-demand application as a post-arrival application and represents the preceding application based on the pre-reservation as a reserved application.
[0155] In this case, for example, the valet parking implementation time is present in the request information Db transmitted from the terminal 200 to the OEM server device 500. The valet parking implementation time corresponds to the current application time after arrival and corresponds to the scheduled time specified by the user for the reserved application. The valet parking implementation time is entered in response to a user manipulation of the application. The scheduled parking time corresponds to the time to start valet parking, namely, the time when the automobile 300 departs from a specific parking space. The scheduled parking time corresponds to the time to complete valet parking, namely, the time when the automobile 300 arrives and stops at a specific exit.
[0156] The request information Db includes the information described above. Therefore, based on the contents of the request information Db, the present embodiment can identify whether the requested valet parking corresponds to the arrival application or the reserved application. The OEM server device 500 completes the information verification processing, namely, the processing in step S504, which verifies the authenticity of the temporary key request Dh. The OEM server device 500 then determines the time to start the next step, namely, step S505, which generates the zone information request Di.
[0157] The post-arrival application assumes that the automobile 300 has already arrived at the parking space and valet parking is immediately available. In the case of the post-arrival application, the OEM server device 500 proceeds to the next step once the information verification processing is completed. The reserved application assumes that the automobile 300 has not yet arrived at the parking space and valet parking is not available at that time. In the case of the reserved application, the OEM server device 500 waits until the user-specified scheduled time for valet parking without dictating the processing.
[0158] Parking based on the reserved application requires confirming whether the automobile 300 arrives at the parking space at the scheduled time. In this case, the user responsible for the reserved application performs a specific manipulation on the terminal 200 to confirm arrival at the parking space. The arrival of the automobile 300 at the parking space can be confirmed using various methods, for example, the user entering a reservation number into an access acceptance device provided for the parking space, or the automobile 300 communicating with the parking space server device 400 when driving through an entrance gate of the parking space.
[0159] Exiting based on the reserved application does not require the confirmation required for parking. Processing proceeds so that the automobile 300 arrives at the specific exit at the user-specified scheduled time. In this case, it is necessary to find the time required for the automobile 300 to travel from the parking space to the exit. The timing for performing the next step is found by subtracting the required time from the scheduled time. The required time can be found by adding the time required for the automobile 300 to start the engine, the time required for the automobile 300 to make preparations for starting, and the actual travel time.
[0160] For example, if the user specifies the reservation time as "10:30 a.m." and the required time is "3 minutes," the OEM server device 500 performs the next step at "10:27 a.m." After requesting a reserved parking exit, the user is not required to wait for the automobile 300 to arrive at a specific exit. This can eliminate the user's waiting time, thus improving convenience.
[0161] Fig. 14 illustrates the contents of the processing from requesting the AVP to receiving the drivable area according to the present embodiment. The processing according to the present embodiment supplements the comparable processing according to the first embodiment by adding steps S231 and S232 performed by the terminal device 200 and steps S531 to S533 performed by the OEM server device 500.
[0162] In this case, the OEM server device 500 determines in step S504 that the request Dh for the temporary key is authentic, and then proceeds to step S531 to determine the time to start processing in step S505 according to the next step described above. Namely, in step S531, the OEM server device 500 determines whether the reserved application is executed based on the request information Db. The OEM server device 500 may determine that the reserved application is not executed, but the application is executed after arrival. Step S531 then results in a "No" result. The OEM server device 500 proceeds to step S505 and subsequently executes the processing similar to that in the first embodiment. In this case, the user has already arrived at the parking lot. Valet parking is performed once the subsequent processing is completed.
[0163] The OEM server device 500 may determine that the reserved application is running. In this case, step S531 results in a "Yes" result. The OEM server device 500 proceeds to step S532 and waits until the user-specified scheduled time. If the user subsequently arrives at the parking space and performs a specific state manipulation, the terminal device 200 detects the start manipulation in step S231 and proceeds to step S232.
[0164] In step S232, the terminal device 200 transmits the start request Dr requesting to start valet parking to the OEM device 500. In step S533, the OEM server device 500 receives the start request Dr, then proceeds to step S505, and subsequently performs the same processing as in the first embodiment. The arrival application or the parking-based application based on the reserved application do not require steps S231 and S232 for the terminal device 200 and step S533 for the OEM server device 500.
[0165] As described above, the system according to the present embodiment assumes that a user reserves the AVP in advance. The present embodiment also allows the OEM server device 500 and the automobile 300 to directly exchange the temporary key as a digital key for the automobile 300, like the first embodiment. The temporary key is not supplied to the parking space server device 400. Therefore, the present embodiment also provides an effect similar to that of the first embodiment. Other embodiments
[0166] The present embodiment is not limited to the above-described embodiments illustrated in the attached figures, but may be modified, combined or variously expanded within the spirit and scope of the invention.
[0167] Numerical values given in the above-described embodiments are examples, and the present invention is not limited thereto.
[0168] The authentication according to the embodiments described above uses the temporary key Da and the password Df, but can only use the temporary key Da.
[0169] As described in the above-described embodiments, the operation planning sections 308 and 404 can reliably generate the operation plan Dg that prevents the automobile 300 from leaving the parking space using the effective zone information Dd supplied from the map server device 600, such as the map information around the parking space and the information about the area between the parking space and the outside. However, the AVP system may omit the map server device 600. Even with this configuration, the operation planning sections 308 and 404 can reliably generate the operation plan Dg that prevents the automobile 300 from leaving the parking space based on map information in the parking space originally stored in the parking space server device 400.
[0170] The present embodiment has been described with reference to the embodiments, but is not limited to the embodiments and structures. The present invention covers various modification examples and modifications within the range of equivalence. Furthermore, the category or scope of the idea of the present invention also covers various combinations or forms, and indeed, other combinations or forms that include only a single element or multiple or fewer elements.
[0171] The control section and its technology described in the present invention may be executed by a dedicated computer having a memory and a processor and programmed to perform one or more functions implemented by a computer program. Furthermore, the control section and its technology described in the present invention may be executed by a dedicated computer having a processor including one or more dedicated hardware logic circuits.Furthermore, the control section and its technology described in the present invention may be executed by one or more dedicated computers, each configured as a combination of a processor programmed to perform one or more functions, and a processor consisting of a memory and one or more hardware logic circuits. The computer program, as an instruction executed by the computer, may be stored in a computer-readable, non-transitory, tangible storage medium.
[0172] The control units and methods described in the present embodiment may be implemented by a computer for this specific purpose, formed by configuring a memory and a processor programmed to perform one or more specific functions embodied in computer programs. Alternatively, the control units and methods described in the present invention may be implemented by a computer for this specific purpose, formed by configuring a processor formed by one or more hardware logic circuits for this specific purpose.Alternatively, the control units and methods described in the present invention may be implemented by one or more computers for this specific purpose, created by configuring a combination of a memory and a processor programmed to perform one or more specific functions, and a processor provided by one or more hardware logic circuits. The computer programs may be stored as instructions executed by a computer in a tangible, non-transitory, computer-readable medium.
[0173] It should be noted that a flowchart or the processing of the flowchart in this description comprises sections (also referred to as steps), each of which is represented, for example, as S201. Furthermore, each section may be divided into multiple subsections, while multiple sections may be combined into a single section. Furthermore, each of these configured sections may also be referred to as a device, module, or means.
[0174] While the present invention has been described with reference to embodiments thereof, it is to be understood that the invention is not limited to the embodiments and concepts. The present invention is intended to cover various modifications and equivalent arrangements. Furthermore, various combinations and configurations, including more, fewer, or only a single element, are also included within the scope and spirit of the present invention.
Claims
[1] An automatic valet parking system (100) for performing valet parking in an autonomous driving control system, the valet parking system (100) comprising: a terminal device (200), a vehicle device (300) mounted on a vehicle, a parking server (400) mounted for a parking space, and a DEM server (500) controlled directly or indirectly by a vehicle manufacturer, wherein: the terminal (200), the vehicle device (300), the parking space server (400) and the DEM server (500) are configured to mutually transmit and receive data, the terminal (200) has an application information generating unit (203, 205), the parking server (400) has a key request generation unit (403, 406), the DEM server (500) has a key request verification section (504, 509) and a unit (506) for generating the temporary key, at least one of the units, parking space server (400) and vehicle device (300), has a route planning section (308, 404), the vehicle device (300) has a unit (306, 309) for controlling autonomous driving, the application information generating unit (203, 205) generates application information as information about an application for valet parking and transmits the application information to the parking space server (400) and the DEM server (500), the key request generation unit (403, 406) receives the request information transmitted from the terminal (200), generates a temporary key request for requesting generation of a temporary key, and transmits the temporary key request to the DEM server (500), the key request verification section (504, 509) receives the application information transmitted from the terminal (200), receives the request for the temporary key transmitted from the parking space server (400), and verifies an authenticity of the request for the temporary key, when the key request verification section (504, 509) provides a verification result that is true, the temporary key generation unit (506) generates the temporary key and transmits the temporary key to the vehicle device (300), the travel planning section (308, 404) generates a travel plan for the vehicle, which has a route to a targeted parking position, and when the autonomous driving control unit (306, 309) receives the temporary key transmitted from the OEM server (500), the autonomous driving control unit (306, 309) performs autonomous driving control according to the driving plan generated by the driving planning section (308, 404), characterized by , that when the temporary key is generated, the temporary key generation unit (506) further generates a password for validating the temporary key and transmits the password to the vehicle device (300) via the parking space server (400), and when the autonomous driving control unit (306, 309) receives the temporary key transmitted from the OEM server (500) and receives the password transmitted from the parking lot server (400), the autonomous driving control unit (306, 309) performs the autonomous driving control according to the driving plan generated by the driving planning section (308, 404). [2] Automatic valet parking system (100) according to claim 1, wherein: the travel planning section (404) is arranged in the parking space server (400), the vehicle device (300) further comprises a key verification section (304), when the route planning section (404) receives the password transmitted from the OEM server (500), the route planning section (404) transmits the password and the route plan to the vehicle device (300), when the key verification section (304) receives the temporary key transmitted from the OEM server (500) and receives the password transmitted from the parking space server (400), the key verification section (304) verifies whether a combination of the temporary key and the password is suitable, when the key verification section (304) provides the verification result that the combination is appropriate, the autonomous driving control unit (306, 309) determines that the driving plan transmitted together with the password is available and performs the autonomous driving control according to the driving plan. [3] Automatic valet parking system (100) according to claim 1, wherein: the route planning section (308) is arranged in the vehicle device (300), the parking space server (400) further comprises a parking position determining section (407) and a plan verification section (408), the vehicle device (300) further comprises a key verification section (304), when the parking position determining section (407) receives the password transmitted from the OEM server (500), the parking position determining section (407) determines the targeted parking position and transmits the password together with the target position information as information about a specific targeted parking position to the vehicle device (300), when the key verification section (304) receives the temporary key transmitted from the OEM server (500) and receives the password transmitted from the parking space server (400), the key verification section (304) verifies whether a combination of the temporary key and the password is suitable, if the key verification section (304) provides a verification result that the combination is suitable, the route planning section (308) generates the route plan based on the destination position information and transmits the route plan to the parking space server (400), when the plan verification section (408) receives the schedule transmitted from the vehicle device (300), the plan verification section (408) verifies whether the schedule is suitable, if the schedule is suitable, the schedule verification section (408) transmits availability information representing that the schedule is available to the vehicle, and when the autonomous driving control unit (306, 309) receives the availability information transmitted from the parking space server (400), the autonomous driving control unit (306, 309) performs the autonomous driving control according to the driving plan generated by the driving planning section (308). [4] Automatic valet parking system (100) according to claim 2, further comprising: a card server (600) having an effective zone acquiring section (603) that acquires effective zone information as effective zone information for the temporary key, wherein: the OEM server (500) has a zone request generation unit (505), the zone request generation unit (505) generates a zone information request for requesting transmission of the information about the effective zone and transmits the zone information request to the map server, when the effective zone acquiring section (603) receives the zone information request transmitted from the OEM server (500), the effective zone acquiring section (603) acquires the effective zone information and transmits the effective zone information to the OEM server (500), the temporary key generating unit (506) transmits the effective zone information together with the temporary key to the vehicle device (300), and the autonomous driving control unit (306, 309) determines whether the driving schedule is available according to a verification result for verifying the driving schedule transmitted from the parking lot server (400) with the effective zone information transmitted from the OEM server (500). [5] Automatic valet parking system (100) according to claim 3, further comprising: a card server having an effective zone acquiring section (603) that acquires effective zone information as effective zone information for the temporary key, wherein: the OEM server (500) further comprises a zone request generation unit (505), the zone request generation unit (505) generates a zone information request for requesting transmission of the information about the effective zone and transmits the zone information request to the map server, when the effective zone acquiring section (603) receives the zone information request transmitted from the OEM server (500), the effective zone acquiring section (603) acquires the effective zone information and transmits the effective zone information to the OEM server (500), the temporary key generating unit (506) transmits the effective zone information together with the temporary key to the vehicle device (300), and when the route planning section (308) receives the effective zone information transmitted from the OEM server (500), the route planning section (308) generates the route plan according to the effective zone information. [6] An automatic valet parking program for performing valet parking under autonomous driving control by a terminal device (200), a vehicle device (300), a parking space server (400) mounted for a parking space, and an OEM server (500) controlled directly or indirectly by a vehicle manufacturer, wherein the terminal device (200), the vehicle device (300), the parking space server (400), and the OEM server (500) are configured to mutually transmit and receive data, the automatic valet parking program comprising the following steps: performing an application information generation procedure using the terminal (200), Performing a key request generation procedure using the parking space server (400), Performing a key request verification procedure and a temporary key generation procedure using the OEM server (500), Performing a travel planning procedure using at least one of the parking space server (400) and vehicle device (300), and Performing a procedure for controlling autonomous driving using the vehicle device (300), wherein: the application information generation procedure comprises: generating application information as information about an application for valet parking and transmitting the application information to the parking space server (400) and the OEM server (500), the key request generation procedure comprises: receiving the request information transmitted from the terminal (200), generating a temporary key request for requesting generation of the temporary key, and transmitting the temporary key request to the OEM server (500), the key request generation procedure comprises: receiving the application information transmitted from the terminal (200), receiving the request for the temporary key transmitted from the parking space server (400), and verifying an authenticity of the request for the temporary key, the procedure for generating the temporary key comprises: generating the temporary key and transmitting the temporary key to the vehicle if a verification result in the key request verification procedure is true, the journey planning procedure comprises: generating a journey plan comprising a route to a targeted parking position for the vehicle, and the procedure for controlling autonomous driving comprises: performing autonomous driving control according to the driving plan generated in the driving planning procedure when receiving the temporary key transmitted from the OEM server (500), characterized by , that when the temporary key is generated, the temporary key generation procedure further generates a password for validating the temporary key and transmits the password to the vehicle device (300) via the parking space server (400), and when the autonomous driving control procedure receives the temporary key transmitted from the OEM server (500) and receives the password transmitted from the parking lot server (400), the autonomous driving control procedure performs the autonomous driving control according to the driving plan generated by the driving planning procedure. [7] A computer-readable non-transitory tangible storage medium comprising instructions executed by a computer, the instructions comprising a method for automatic valet parking for performing valet parking under autonomous driving control by a terminal device (200), a vehicle device (300), a parking space server (400) arranged for a parking space, and an OEM server (500) controlled directly or indirectly by a vehicle manufacturer, the terminal device (200), the vehicle device (300), the parking space server (400), and the OEM server (500) being configured to mutually transmit and receive data, the instructions comprising the steps of: performing an application information generation procedure using the terminal (200), Performing a key request generation procedure using the parking space server (400), Performing a key request verification procedure and a temporary key generation procedure using the OEM server (500), Performing a travel planning procedure using at least one of the parking space server (400) and vehicle device (300), and Performing a procedure for controlling autonomous driving using the vehicle device (300), wherein: the application information generation procedure comprises: generating application information as information about an application for valet parking and transmitting the application information to the parking space server (400) and the OEM server (500), the key request generation procedure comprises: receiving the request information transmitted from the terminal (200), generating a temporary key request for requesting generation of a temporary key, and transmitting the temporary key request to the OEM server (500), the key request verification procedure comprises: receiving the request information transmitted from the terminal (200), receiving the request for the temporary key transmitted from the parking space server (400), and verifying an authenticity of the request for the temporary key, the procedure for generating the temporary key comprises: generating the temporary key and transmitting the temporary key to the vehicle if a verification result in the key request verification procedure is true, the journey planning procedure comprises: generating a journey plan comprising a route to a targeted parking position for the vehicle, and the procedure for controlling autonomous driving comprises: performing the autonomous driving control according to the driving plan generated in the driving planning procedure when receiving the temporary key transmitted from the OEM server (500), characterized by , that when the temporary key is generated, the temporary key generation procedure further generates a password for validating the temporary key and transmits the password to the vehicle device (300) via the parking space server (400), and when the autonomous driving control procedure receives the temporary key transmitted from the OEM server (500) and receives the password transmitted from the parking lot server (400), the autonomous driving control procedure performs the autonomous driving control according to the driving plan generated by the driving planning procedure.
Citation Information
Patent Citations
Valet parking system, terminal device and program
JP2018039461A
Valet parking system, terminal device, automobile, server device, and program
JP2018041381A
Valet parking system and program
JP2019035220A
JP002018039461A
JP002018041381A