Motion body control system and motion body control method

The motion body control system addresses unauthorized activation issues by implementing dual verification processes to ensure legitimate operation, preventing misuse and maintaining user comfort and efficiency.

DE102025130404A1Pending Publication Date: 2026-03-12TOYOTA JIDOSHA KK
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-07-31
Publication Date
2026-03-12

AI Technical Summary

Technical Problem

Existing motion body control systems face issues where unauthorized activation can lead to misuse or operational restrictions that impair user comfort and reduce operating time, especially when malicious or non-malicious users attempt unauthorized operations.

Method used

A motion body control system with a control device and management system that performs initial and secondary verification processes to determine unauthorized activation, switching to alert standby mode if suspicious, and restoring normal operation upon validation, while preventing unauthorized use.

Benefits of technology

Prevents unauthorized operation while maintaining user comfort and operational efficiency by efficiently verifying and authenticating remote control instructions, reducing unnecessary restrictions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A moving body control system (100) comprises a management system (2) and a control device (11) mounted on a moving body (1) and configured to cause the moving body (1) to operate according to a legitimate remote control instruction (INS) from the management system (2). The remote control instruction (INS) includes an activation instruction (INS-A) that remotely activates the control device (11). The control device (11) is configured to perform an initial verification process to determine whether there is any suspicion of unauthorized activation of the control device (11), and if such suspicion exists, to change its own operating mode from a normal standby mode to an alert standby mode.If there is a suspicion of unauthorized activation, the management system (2) is further configured to perform a second verification process to finally determine whether the suspicion of unauthorized activation is valid or not.
Need to check novelty before this filing date? Find Prior Art

Description

BACKGROUND OF THE INVENTION 1. Field of the invention

[0001] The present disclosure relates to a motion body control system and a motion body control method. 2. Description of the related prior art

[0002] Unexamined Japanese patent application disclosure no. 2023-148463 (JP 2023-148463 A) discloses a motion body control system that controls a moving body capable of operating in a predetermined area in accordance with a remote control instruction. The motion body control system performs a remote control instruction verification process that determines whether the remote control instruction received by the moving body is valid, and an operation restriction process that restricts at least part of the moving body's operation without following the remote control instruction if the remote control instruction received by the moving body is invalid. SUMMARY OF THE INVENTION

[0003] According to the technique described in JP 2023-148463 A, the immediate restriction of at least part of the operation of the moving body, in accordance with the stipulation that the remote control instruction received by the moving body is invalid, can reliably prevent misuse of the moving body's functions if unauthorized access to the moving body actually exists. On the other hand, a case is also assumed in which not only a malicious person attempts to induce unauthorized operation of the moving body, but also a non-malicious person attempts to activate a control device of the moving body, for example, by a method not originally intended or a method that leads to misunderstandings.If the operation is similarly restricted in such a way that the restriction on activation by such a malicious person cannot simply be lifted, there is a possibility that the original user comfort of the moving body will be impaired or the operating time of the moving body will be reduced.

[0004] A moving body control system according to a first aspect of the present disclosure is configured to control a moving body that has the function of operating in a predetermined area in accordance with a remote control instruction. The moving body control system comprises a management system and a control device. The management system is configured to legitimately generate the remote control instruction. The control device is mounted on the moving body and configured to cause the moving body to operate in accordance with the legitimate remote control instruction from the management system. The remote control instruction includes an activation instruction that remotely activates the control device.The control device is configured to perform an initial verification process to determine whether or not there is a suspicion of unauthorized activation. If unauthorized activation is suspected, the control device is configured to change its operating mode from normal standby to alert standby. If unauthorized activation is still suspected, the management system is further configured to perform a second verification process to ultimately determine whether the suspicion of unauthorized activation is valid. Normal standby mode is a mode in which the control device waits for a legitimate activation command from the management system.The alert standby mode is a mode that reverts to normal standby mode when the second verification process finally determines that the suspicion of unauthorized activation is invalid and authentication between the control device and the management system is successful, while activation of the control device is prohibited.

[0005] In the motion body control system according to the first aspect of the present disclosure, the control device and the management system can be configured to cooperate in order to restore the operating mode from the alert standby mode to the normal standby mode when the second verification process finally determines that the suspicion of unauthorized activation is invalid.

[0006] In the motion body control system according to the first aspect of the present disclosure, the first verification process may include: determining whether the activation instruction received by the control device matches a predefined format or not, and if the activation instruction does not match the predefined format, determining that there is a suspicion of unauthorized activation.

[0007] In the motion body control system according to the first aspect of the present disclosure, the first verification process may include determining whether or not an activation of the control device that does not follow a predefined activation sequence has been detected, and if the activation of the control device that does not follow the predefined activation sequence has been detected, determining that there is a suspicion of unauthorized activation.

[0008] In the moving body control system according to the first aspect of the present disclosure, the second verification process may include determining whether the management system actually transmitted the activation instruction received from the moving body, and if the management system did not actually transmit the activation instruction to the moving body, the final determination that the suspicion of unauthorized activation is valid.

[0009] In the moving body control system according to the first aspect of the present disclosure, the management system, if the second verification process finally determines that the suspicion of unauthorized activation is correct, can be configured to request a mobile network operator to stop the transmission of information to all moving bodies managed by the management system from an electrical communications number used to transmit the activation instruction related to the suspicion of unauthorized activation, under conditions that a transmission stop condition is met, and the transmission stop condition can be a state that the electrical communications number has been used for an unauthorized activation instruction of control devices of a plurality of moving bodies, including the control device of the moving body, or a state thatthat the electronic communication number was used a large number of times within a predetermined time period for the unauthorized activation instruction of the control device of the moving body.

[0010] In the moving body control system according to the first aspect of the present disclosure, an orientation point may be arranged within the predetermined area, and the second verification process may include determining whether the orientation point is detectable by the control device from a position of the moving body or not, and if the orientation point is not detectable by the control device from the position of the moving body, the final determination that the moving body is not present in the predetermined area when the control device receives the activation instruction and the suspicion of unauthorized activation is valid.

[0011] In the moving body control system according to the first aspect of the present disclosure, the second verification process may include: obtaining position information of the moving body, determining whether the moving body is present in the predetermined area or not when the control device receives the activation instruction by comparing map information in which a position of the predetermined area is registered and the position information of the moving body, and, if the moving body is not present in the predetermined area when the control device receives the activation instruction, finally determining that the suspicion of unauthorized activation is valid.

[0012] In the moving body control system according to the first aspect of the present disclosure, the moving body and a communication device provided in the predetermined area can be configured to perform communication according to a specific communication scheme, and the second verification process can include determining whether or not communication is established between the moving body and the communication device, and, if communication is not established between the moving body and the communication device, the final determination that the moving body is not present in the predetermined area when the moving body receives the activation instruction and the suspicion of unauthorized activation is valid.

[0013] In the moving body control system according to the first aspect of the present disclosure, the first verification process may include determining whether the suspicion of unauthorized activation is a suspicion of unauthorized remote control instruction and a suspicion of unauthorized activation operation based on the direct activation operation on the moving body, or not. If the suspicion of unauthorized activation is a suspicion of unauthorized activation operation, the control device may be configured to change the operating mode to an instant shutdown mode instead of the alert standby mode, and the instant shutdown mode may be a mode for disabling the activation of the control device in an aspect where the management system is unable to remotely override an activation / disabling state of the control device.

[0014] In the motion body control system according to the first aspect of the present disclosure, the control device can be configured to be activated after the first authentication is completed, and then the second authentication is completed, and the first authentication can be the authentication regarding the mode change, and the second authentication can be the authentication regarding the activation of the control device.

[0015] A moving body control method according to a second aspect of the present disclosure is a method for controlling a moving body which has the function of operating in accordance with a remote control instruction in a predetermined area.The procedure for controlling a moving body includes causing a control device to perform a first verification process in which it is determined whether or not there is a suspicion of unauthorized activation of the control device; if there is a suspicion of unauthorized activation, changing an operating mode of the control device from a normal standby mode to an alert standby mode; and if there is a suspicion of unauthorized activation, causing an administrative system to perform a second verification process in which it is finally determined whether or not the suspicion of unauthorized activation is valid.The control device, configured to cause the moving body to operate according to a legitimate remote control instruction from the management system (which is configured to legitimately generate the remote control instruction), is mounted on the moving body. The remote control instruction includes an activation instruction that remotely activates the control device. Normal standby mode is a mode in which the device waits to receive a legitimate activation instruction from the management system. Alert standby mode is a mode that reverts to normal standby mode when the second verification process finally determines that the suspicion of unauthorized activation is unfounded and authentication between the control device and the management system is successful, at which point activation of the control device is prohibited.

[0016] According to the present disclosure, if it is determined on the side of the moving body that there is a suspicion of unauthorized activation of the control device, the final determination of whether or not there is a suspicion of unauthorized activation by the management system can be awaited by switching to the alert standby mode, while preventing the control device from being used to cause the moving body to perform unauthorized operation. Furthermore, the operating mode of the control device is restored from the alert standby mode to the normal standby mode when the second verification process finally determines that there is no suspicion of unauthorized activation and the authentication between the control device and the management system is successful.This prevents the implementation of unnecessary or excessive operational restrictions on the moving body. This, in turn, prevents misuse of the moving body's functions while simultaneously avoiding a deterioration of user comfort or a reduction in the operating time of the moving body. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Features, advantages and technical and industrial significance of embodiments of the invention are described below with reference to the accompanying drawings, in which the same reference numerals denote the same elements and in which the following applies: Fig. Figure 1 is a conceptual representation to illustrate the outline of a vehicle according to an exemplary embodiment; Fig. Figure 2 is a block diagram illustrating the structure of an in-vehicle system mounted on the vehicle; Fig. Figure 3 is a conceptual representation to explain the automatic parking service; Fig. Figure 4 is a conceptual representation to explain a mobility service in a predetermined area; Fig. Figure 5 is a block diagram showing a configuration example of a vehicle control system according to the embodiment; Fig. Figure 6 is a flowchart that illustrates an example of a vehicle-side process related to the verification and countermeasures in the event of suspected unauthorized activation according to the embodiment; Fig. Figure 7 is a flowchart showing a specific example of a procedure of step S102; Fig. Figure 8 is a flowchart showing a specific example of a process from step S106; Fig. Figure 9 is a flowchart showing an example of a process on the side of an administrative system relating to the verification and countermeasures in case of suspected unauthorized activation according to the exemplary implementation; Fig. Figure 10 is a flowchart that shows a first specific example of a second verification process; Fig. 11A is a conceptual representation to explain a second specific example of the second verification process; Fig. 11B is a flowchart to explain the second specific example of the second verification process; Fig. Figure 12 is a sequence diagram that represents a specific example of the processing flow associated with the activation of a control device based on a legitimate activation instruction; Fig. Figure 13 is a sequence diagram showing a specific example of the processing flow relating to the activation of the control device when an activation instruction is received where there is suspicion of an unauthorized remote control instruction; Fig. Figure 14 is a sequence diagram showing a specific example of the processing flow relating to the activation of the control device when an activation instruction is received that is suspected to be an unauthorized activation; and Fig. Figure 15 is a flowchart that shows a change in the vehicle-side process with regard to the verification and countermeasures in case of suspected unauthorized activation according to the embodiment. DETAILED DESCRIPTION OF THE EXECUTION EXAMPLES

[0018] An embodiment of the present disclosure is described with reference to the accompanying drawings. 1. The moving body operates according to the remote control instructions. 1-1. Overview

[0019] A moving body can be operated according to a remote control instruction. Examples of moving bodies include a vehicle, a robot, and the like. As an example, the following description considers a case in which the moving body is a vehicle. When the description is generalized, the "vehicle" in the following description is to be understood as the "moving body."

[0020] Fig. Figure 1 is a conceptual representation illustrating the outline of a vehicle 1 according to the present embodiment. The vehicle 1 has a function of operating according to a remote control instruction INS. In particular, the vehicle 1 has a function of operating in accordance with the remote control instruction INS within a predetermined area AR.

[0021] The predetermined area AR is, for example, an area in which vehicle 1 can drive autonomously. In this case, vehicle 1 drives autonomously in the predetermined area AR according to the remote control instruction INS. Another example: The predetermined area AR can be an area in which a service is to be provided by vehicle 1. In this case, vehicle 1 provides a service in the predetermined area AR according to the remote control instruction INS. Various examples of the predetermined area AR are described later.

[0022] The remote control instruction INS includes an “activation instruction INS-A”, which activates a control device 11 (see Fig. 2) of the vehicle 1 remotely activated. Furthermore, the remote control instruction INS includes an instruction that activates the control device 11 (more precisely, a vehicle control unit 13 (see Fig. 2)) causes vehicle 1 to be switched on or off (to switch on or off a main power supply of the vehicle). “Switching on vehicle 1” means putting vehicle 1 into an operational state. Switching on vehicle 1 includes, for example, starting the power supply to various devices mounted on vehicle 1. Furthermore, switching on vehicle 1 includes turning on the ignition of vehicle 1. On the other hand, “switching off vehicle 1” means that vehicle 1 is put into an inoperable state. Switching off vehicle 1 includes, for example, turning off the ignition of vehicle 1. Another example: Switching off vehicle 1 may include interrupting the power supply to various devices mounted on vehicle 1.It should be noted that even when vehicle 1 is switched off (the main power supply is switched off), the control device 11 is mounted in such a way that it can be operated with an auxiliary power supply different from the main power supply. Thus, even after vehicle 1 is switched off, at least one function of the control device 11 (more precisely, a communication management device 12 (see . )) remains operational. Fig. 2)) is activated to receive the remote control instruction INS. Thus, even after being switched off, vehicle 1 can receive the remote control instruction INS, which gives an instruction to switch on, and can be switched on automatically according to the remote control instruction INS.

[0023] Another example: The remote control instruction INS can instruct vehicle 1 to steer, accelerate, or decelerate. Another example: The remote control instruction INS can instruct vehicle 1 to drive autonomously. As another example, the remote control instruction INS can give an instruction to detect a situation in the vicinity of vehicle 1 using a detection sensor mounted on vehicle 1. As another example, the remote control instruction INS can give an instruction to lock or unlock a door of vehicle 1.

[0024] The remote control instruction INS is generated by management system 2. Management system 2 manages at least vehicle 1 within the predetermined area AR. Management system 2 can manage the predetermined area AR. Management system 2 can manage a service provided by the use of vehicle 1 within the predetermined area AR. Vehicle 1 and management system 2 can communicate with each other. Management system 2 transmits the remote control instruction INS to vehicle 1 within the predetermined area AR as needed. Vehicle 1 within the predetermined area AR receives the remote control instruction INS transmitted by management system 2 and operates according to the received remote control instruction INS. Management system 2 is implemented, for example, by a management server in the cloud. Management system 2 can consist of multiple servers performing distributed processes.

[0025] Fig. Figure 2 is a block diagram illustrating the basic features of an in-vehicle system 10 mounted on a vehicle 1. The in-vehicle system 10 comprises the control device 11. The control device 11, which is a computer that operates the vehicle 1 according to the remote control instruction INS of the management system 2, comprises a communication management device 12 and the vehicle control unit 13.

[0026] The communication management device 12 receives the remote control instruction INS transmitted by the management system 2. When the communication management device 12 receives the remote control instruction INS, the vehicle control unit 13 controls the vehicle 1 according to the received remote control instruction INS. Controlling the vehicle 1 includes, for example, turning the vehicle 1 on and off. Another example of controlling the vehicle 1 includes controlling the driving (steering, acceleration, and deceleration) of the vehicle 1. As another example, controlling the vehicle 1 can include autonomous control of the vehicle 1. As another example, controlling the vehicle 1 can include detecting a situation in the vehicle 1's environment using the detection sensor mounted on the vehicle 1. As another example, controlling the vehicle 1 can include locking or unlocking the vehicle 1's door.Another example of controlling vehicle 1 could include switching a light (e.g., a headlight, hazard warning lights) on or off. Another example: Controlling vehicle 1 could include sounding the horn.

[0027] The following describes an example of a vehicle 1 that drives in the predetermined area AR according to the remote control instruction INS. 1-2. Automatic parking with valet parking service

[0028] Fig. Figure 3 is a conceptual representation to explain the automated parking service (AVP). In this example, the predetermined area AR is a parking lot. The parking lot can be located indoors or outdoors. An AVP vehicle 1A is vehicle 1, which supports automated parking in the parking lot. The AVP vehicle 1A is capable of driving autonomously, at least within the parking lot. Specifically, the AVP vehicle 1A includes a detection sensor (e.g., a camera) for recognizing its surroundings. The AVP vehicle 1A drives autonomously within the parking lot while recognizing its surroundings using the detection sensor.

[0029] As in Fig. As shown in Figure 3, a variety of landmarks (markers) M arranged in the parking lot can be used to implement the autonomous driving described above. Information is provided to the landmarks M for identification purposes. For example, the AVP vehicle 1A acquires an image of its surroundings using its camera and recognizes the landmark M based on this image. The AVP vehicle 1A is able to identify an entry point based on the recognition of the landmark M. Furthermore, the AVP vehicle 1A performs a localization process (self-position estimation process, localization) that estimates its position within the parking lot with high accuracy based on the recognition of the landmark M.A destination path PT is a movement path from the entry area to a destination parking space assigned to the AVP vehicle 1A. The AVP vehicle 1A performs an autonomous journey to follow the destination path PT, based on the position of the AVP vehicle 1A and the destination path PT estimated by the localization process. This enables the AVP vehicle 1A to move autonomously from the entry area to the destination parking space.

[0030] Management System 2 manages the automated parking service in the parking lot. Management System 2 is capable of communicating with vehicles that include AVP vehicle 1A in the parking lot. For example, Management System 2 issues the remote control instruction INS to AVP vehicle 1A. The remote control instruction INS, for instance, instructs AVP vehicle 1A to turn on or off. Another example: The remote control instruction INS instructs AVP vehicle 1A to start autonomous driving. Management System 2 can provide AVP vehicle 1A with map information about the landmarks M in the parking lot. Management System 2 can remotely control AVP vehicle 1A in the parking lot.

[0031] As in Fig. As shown in Figure 3, the management system 2 can comprise a vehicle management center 2A and a parking control center 2B. The parking control center 2B is provided for each parking space. The parking control center 2B, for example, records the parking space status, assigns a parking space to the AVP vehicle 1A, generates the destination path PT, provides the destination path PT to the AVP vehicle 1A, and so on.

[0032] Vehicle Management Center 2A controls the parking control centers 2B of a large number of parking lots. To this end, Vehicle Management Center 2A communicates with each parking control center 2B to collect and provide various types of information. Furthermore, Vehicle Management Center 2A manages the AVP vehicle 1A and transmits the remote control instruction INS to the AVP vehicle 1A when necessary. Additionally, Vehicle Management Center 2A manages the users and reservations of an automated parking service. Vehicle Management Center 2A can communicate with a user terminal 3 operated by a user of the automated parking service. Vehicle Management Center 2A pre-registers information about the user's members.

[0033] Furthermore, the AVP vehicle 1A receives the remote control instruction INS, which instructs the management system 2 to switch it on upon entering or exiting the parking space. The AVP vehicle 1A switches on automatically according to the received remote control instruction INS and then begins autonomous driving in the parking space. The management system 2 can communicate with the AVP vehicle 1A and remotely control its autonomous driving. Once the AVP vehicle 1A has finished parking in the target parking space, the management system 2 communicates with the AVP vehicle 1A to transmit the remote control instruction INS, which contains an instruction to switch the AVP vehicle 1A off. The AVP vehicle 1A switches off automatically according to the received remote control instruction INS. 1-3. Mobility service

[0034] Fig. Figure 4 is a conceptual representation to explain a mobility service in a predetermined area AR. The predetermined area AR is the area in which the mobility service is to be provided. The predetermined area AR is, for example, a city such as a "smart city" or a part of a city.

[0035] A Mobility Service Vehicle 1B is the vehicle used to provide the mobility service in the predetermined area AR. Examples of Mobility Service Vehicle 1B include a bus, a taxi, a shared taxi, and the like. Examples of a bus include a regular bus, a sightseeing bus, a demand-responsive bus, a semi-demand bus, and the like.

[0036] For example, the mobility service vehicle 1B performs autonomous driving within the predetermined area AR. More precisely, the mobility service vehicle 1B includes a detection sensor (e.g., a camera) for recognizing its surroundings. The mobility service vehicle 1B performs autonomous driving within the predetermined area AR while recognizing the surroundings using this detection sensor.

[0037] Landmarks M for the localization process can be arranged within the predetermined area AR. The mobility service vehicle 1B uses a camera to acquire an image depicting the area around the vehicle and recognizes the landmark M based on this image. The mobility service vehicle 1B then performs the localization process based on the recognition of the landmark M to estimate its own position within the predetermined area AR. The mobility service vehicle 1B then performs autonomous driving based on this estimated position.

[0038] Management System 2 manages the mobility service and each mobility service vehicle 1B within the predetermined area AR. Management System 2 is capable of communicating with each mobility service vehicle 1B within the predetermined area AR. For example, Management System 2 communicates with each mobility service vehicle 1B to gather information about its position and status. Furthermore, Management System 2 issues the remote control instruction INS to the mobility service vehicle 1B as needed. For example, the remote control instruction INS instructs the mobility service vehicle 1B to turn on or off. Another example: The remote control instruction INS can remotely instruct the mobility service vehicle 1B to perform at least one of the functions: steering, accelerating, or braking. Additionally, Management System 2 manages the users and reservations of the mobility service.The management system 2 can communicate with a user terminal 3, which is operated by a user of the mobility service. 1-4. Further examples

[0039] The moving body can be a robot that moves autonomously within the predetermined AR area. For example, the moving body could be a logistics robot that automatically transports a package within the predetermined AR area, such as a city, a warehouse, or a factory. Another example: The moving body could be a work robot that performs a specific task within the predetermined AR area, such as a warehouse or a factory. 1-5. Example of a system configuration

[0040] Fig. Figure 5 is a block diagram showing a configuration example of the vehicle control system 100 according to the present embodiment. The vehicle control system 100 (motion control system) comprises the vehicle-internal system 10 and the management system 2. 1-5-1. In-vehicle system

[0041] The vehicle-internal system 10 is mounted on the vehicle 1 and includes, for example, sensors 14, a driving device 15 and a light / horn 16 as well as the control device 11.

[0042] The communication management device 12, which is contained in the control device 11, manages the communication between the outside of the vehicle 1 and the vehicle 1. The communication management device 12 comprises a communication interface (communication I / F) 12A, one or a plurality of processors 12B (hereinafter referred to simply as processor 12B), and one or a plurality of storage devices 12C (hereinafter referred to simply as storage device 12C).

[0043] The communication interface 12A is an interface for communicating with a device or system (e.g., the management system 2) outside the vehicle 1 to send / receive information. The communication interface 12A includes, for example, various types of equipment such as equipment for connecting to a mobile communication network, equipment for connecting to the internet, and equipment for connecting to peripheral devices (e.g., a [device / system]). Fig. 11A shown communication device 5) via a wireless LAN.

[0044] The Processor 12B performs various types of processing. Examples of Processor 12B include a central processing unit (CPU), a graphics processing unit (GPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), and similar devices. The Processor 12B can also be referred to as a "circuit" or "processing circuit." The "circuit" refers to hardware programmed to implement the described functions or to hardware that performs functions. The Storage Device 12C stores various types of information. Examples of Storage Device 12C include volatile memory, non-volatile memory, a hard disk drive (HDD), a solid-state drive (SSD), and the like.The processor 12B reads various types of information from the storage device 12C and stores various types of information in the storage device 12C. Functions of the communication management device 12 are implemented through the cooperation of the processor 12B, which executes a communication management program, and the storage device 12C. The communication management program is stored in the storage device 12C. Alternatively, the communication management program can be recorded on a computer-readable recording medium.

[0045] The vehicle control unit 13, contained in the control device 11, controls the vehicle 1 according to the remote control instruction INS. The vehicle control unit 13 comprises one or a plurality of processors 13A (hereinafter simply referred to as processor 13A) and one or a plurality of memory devices 13B (hereinafter simply referred to as memory device 13B). A configuration example of processor 13A is the same as the configuration example of processor 12B described above. Furthermore, a configuration example of memory device 13B is the same as the configuration example of memory device 12C described above. The functions of the vehicle control unit 13 are realized through the cooperation of processor 13A, which executes a vehicle control program, and memory device 13B. The vehicle control program is stored in memory device 13B.Alternatively, the vehicle control program can be recorded on a computer-readable recording medium.

[0046] The sensors include a detection sensor, a vehicle condition sensor, a position sensor, and the like. The detection sensor detects (detects) a situation around the vehicle. Examples of detection sensors include a camera, a laser imaging detection and ranging (LIDAR) system, radar, and the like. The vehicle condition sensor detects a condition of the vehicle. Examples of vehicle condition sensors include a speed sensor, an accelerometer, a yaw rate sensor, a steering angle sensor, and the like. The position sensor detects a position and orientation of the vehicle. Examples of position sensors include a global navigation satellite system (GNSS) sensor and the like.

[0047] The driving device 15 is a device that sets the vehicle 1 in motion. The driving device 15 comprises a drive device, a braking device, and a steering device. The drive device comprises, for example, at least one electric motor or an internal combustion engine for propelling the vehicle 1. The braking device comprises a brake actuator for braking the vehicle 1. The steering device comprises an electric motor for steering the wheels of the vehicle 1. The light / horn 16 comprises a light and a horn. Examples of the light include a headlight, a hazard warning light, and the like. 1-5-2. Management system

[0048] The management system 2 comprises a communications I / F 21, one or a plurality of processors 22 (hereinafter referred to simply as processor 22) and one or a plurality of storage devices 23 (hereinafter referred to simply as storage device 23).

[0049] The communication interface 21 is an interface for communicating with a device or system (e.g., the vehicle 1 (in-vehicle system 10), the user terminal 3, a mobile network operator) outside the management system 2 to send / receive information. The communication interface 21 includes, for example, various types of equipment such as equipment for connecting to the mobile communications network, equipment for connecting to the Internet, and equipment for connecting to a peripheral device (e.g., the communication device 5 shown in Figure 11A) via a wireless LAN. A configuration example of the processor 22 is the same as the configuration example of the processor 12B described above. Furthermore, a configuration example of the storage device 23 is the same as the configuration example of the storage device 12C described above.The functions of the management system 2 are realized through the cooperation of the processor 22, which executes a management program, and the storage device 23. The management program is stored in the storage device 23. Alternatively, the management program can also be recorded on a computer-readable recording medium.

[0050] Various types of information stored in the storage device 23 include, for example, map information, vehicle information, and management information. The map information comprises map information of the predetermined area AR (e.g., a parking lot). The map information may include position and identification information for each landmark (marker) M located within the predetermined area AR. The vehicle information is information transmitted by the vehicle's internal system 10 (e.g., image information obtained from a camera mounted on the vehicle 1, position information regarding the landmark M detected by the recognition sensor, vehicle 1 position information). The management information is information intended for use by the management system 2 and includes, for example,Vehicle management information, service information, and user information. Vehicle management information refers to information for managing vehicle 1 (e.g., vehicle identification information (VIN) of vehicle 1, information about the parking lot's entry / exit time). User information refers to information about the user operating vehicle 1 (e.g., a user ID, service reservation information). 2. Verification and countermeasures in case of suspected unauthorized activation

[0051] The management system 2 (processor 22) legitimately generates the remote control instruction INS. As described above, the remote control instruction includes an activation instruction INS-A, which remotely activates the control device 11 (more precisely, the vehicle control unit 13). The control device 11 of the vehicle 1 is initially intended for activation according to the legitimate activation instruction INS-A.

[0052] More precisely, the control device 11 (the communication management device 12 and the vehicle control unit 13) is in a standby state when the power supply to the vehicle 1 is off (the main power supply is switched off). In other words, when the main power supply is off, the operating mode of the control device 11 (communication management device 12) is a "normal standby mode." The normal standby mode is a mode of waiting to receive the legitimate activation instruction INS-A from the management system 2. In normal standby mode, the communication management device 12 is activated upon receipt of the legitimate activation instruction INS-A. The vehicle control unit 13 is configured to accept only the remote control instruction INS (which includes the activation instruction INS-A) from the communication management device 12.The vehicle control unit 13 in standby mode is activated according to the receipt of the legitimate activation instruction INS-A from the activated communication management device 12.

[0053] The activation instruction INS-A is not always transmitted legitimately by the management system 2 and can be transmitted by a malicious person attempting to induce an unauthorized activation of the moving body. In other words, there is a possibility that a malicious person could forge the activation instruction INS-A and attempt to activate the control device 11 by transmitting the forged activation instruction INS-A (to perform an unauthorized activation). More precisely, the forged activation instruction INS-A can be transmitted regardless of whether the vehicle 1 is outside or inside the predetermined area AR.Furthermore, unauthorized activation of the control device 11 by a malicious person can occur not only through the forged (unauthorized) activation instruction (INS-A) (remote control action), but also through a direct activation operation OPE-A (non-remote control action) on the control device 11 (e.g., the vehicle control unit 13).

[0054] On the other hand, it is also assumed that not only a malicious person attempting to induce unauthorized operation of the moving body, but also a non-malicious person attempting to activate the control device 11, e.g., using a procedure not originally provided or a procedure that leads to misunderstandings. If the operation of vehicle 1 is restricted in an aspect where the restriction on the activation instruction INS-A or the activation operation OPE-A cannot be easily lifted by a malicious person, there is a possibility that the original user comfort of vehicle 1 will be impaired or that the operating time of vehicle 1 will be reduced. The “aspect where the restriction cannot be easily lifted” described here corresponds, for example, to an aspect where the management system 2 enforces the operating restriction (e.g.,The vehicle 1 cannot be remotely switched off and an employee must actually go to vehicle 1 and replace a component of vehicle 1 to remove the operating restriction or to carry out a special removal procedure.

[0055] From the perspective described above, the vehicle control system 100, according to the present embodiment, can be described as being configured as follows. In other words, the control device 11 (communication management device 12) performs a "first verification process." The first verification process is a process in which it is determined whether or not there is a suspicion of unauthorized activation (a suspicion of unauthorized remote activation or a suspicion of unauthorized activation operation) of the control device 11 (e.g., the vehicle control unit 13). If the first verification process then determines that there is a suspicion of unauthorized activation, the communication management device 12 changes the operating mode of the control device 11 (communication management device 12) from the normal standby mode described above to an "alert standby mode."If the first verification process indicates a suspicion of unauthorized activation, the management system 2 performs a "second verification process" to definitively determine whether the suspicion of unauthorized activation is valid. The alert standby mode is a mode that must be restored if the second verification process definitively determines that the suspicion of unauthorized activation is invalid and authentication between the control device 11 (communication management device 12) and the management system 2 is successful, while activation of the control device 11 (e.g., the vehicle control unit 13) is prohibited. The authentication corresponds, for example, to that described in [reference missing]. Fig. 13 and Fig. 14 shown authentication C21.

[0056] Furthermore, the determination of whether the suspicion of unauthorized activation of the control device 11 of the vehicle 1 is correct or not is to be carried out efficiently through the interaction of the vehicle 1 (control device 11) and the management system 2. From this perspective, the vehicle control system 100 can be described as being configured as follows, according to the present embodiment. In other words, the control device 11 (communication management device 12) performs the first verification process described above.Then, if there is a suspicion of unauthorized activation, the control device 11 (communication management device 12) requests the management system 2 to perform the second verification process to finally determine whether the suspicion of unauthorized activation is valid or not, based on a criterion that differs from the criterion of the first verification process.

[0057] The following describes in detail a procedure for “verification and countermeasures in case of suspected unauthorized activation” for a procedure on the side of the control device (communication management device 12) of the vehicle 1 and a procedure on the side of the management system 2. 2-1. Process on the part of the vehicle's control device

[0058] Fig. Figure 6 is a flowchart showing an example of the process on the side of vehicle 1 relating to the verification and countermeasures of suspected unauthorized activation according to the present embodiment.

[0059] In step S100, the communication management device 12 (processor 12B) determines whether the activation instruction INS-A has been received from outside the vehicle 1 or not. If, as a result of the determination, the activation instruction INS-A has been received (step S100: Yes), the process continues to step S102.

[0060] In step S102, the communication management device 12 determines whether or not there is a suspicion of unauthorized activation (more precisely, a suspicion of an unauthorized remote control instruction) based on the activation instruction INS-A received in step S100. This operation in step S102 corresponds to the first verification process to be performed on the activation instruction INS-A.

[0061] Fig. Figure 7 is a flowchart that shows a specific example of the process from step S102 in Fig. 6 shows. In Fig. In step S120, the communication management device 12 determines whether the activation instruction INS-A received this time conforms to the predefined format. Specifically, the activation instruction INS-A can be transmitted, for example, along with a short message (text message) created according to the predefined format. This short message includes, for example, an instruction ID (symbol information that identifies the activation instruction INS-A). The predefined format in the short message example consists, for instance, of the instruction ID being described at the head of the short message, of a fixed number (e.g., 001) being described at the head of the short message with a predefined number of digits, or of a specific number (e.g., 0) being inserted among a variety of characters or symbols in the short message.In such an example, where the short message is used, the communication management device 12 determines in step S120 whether the short message conforms to the predefined format or not.

[0062] If the received activation instruction INS-A matches the predefined format (step S120: Yes), the process proceeds to step S122. Then, the communication management device 12 determines that the received activation instruction INS-A is legitimate, meaning there is no suspicion of unauthorized remote activation. However, if the received activation instruction INS-A does not match the predefined format (step S120: No), the process proceeds to step S124. Then, the communication management device 12 determines that there is a possibility the activation instruction INS-A is not legitimate, meaning there is suspicion of unauthorized remote activation.

[0063] Furthermore, the process of step S102 (the first verification process performed for the activation instruction INS-A) may include determining whether an electronic communications number NM (e.g., a telephone number, an IP address) of a transmission source of the activation instruction INS-A, received in step S100, matches an electronic communications number NM1 for the transmission of the activation instruction INS-A of the management system 2, which was detected by the communication management device 12. The communication management device 12 then determines that there is no suspicion of unauthorized remote activation if this determination is met, and determines that there is a suspicion of unauthorized remote activation if the determination is not met.

[0064] If an unauthorized remote activation is suspected in step S102, the process proceeds to step S104. In step S104, the communication management device 12 sends a "verification request message N1," which requests verification of the suspected unauthorized remote activation based on the activation instruction INS-A to management system 2. This verification request message N1 instructs management system 2 to perform the second verification process (step S202). As will be explained in the subsequent description of step S202, the second verification process is based on a different criterion than the first. For example, verification request message N1 includes detailed information D1 about the activation instruction INS-A at that time, along with information indicating that an unauthorized remote instruction is suspected.The detailed information D1 includes, for example, the reception time T1 of the activation instruction INS-A by the communication management device 12, the electrical communication number NM of the transmission source of the activation instruction INS-A, and the instruction ID (information that identifies the activation instruction INS-A). Furthermore, in step S104, the communication management device 12 changes its own operating mode from normal standby mode to alert standby mode.

[0065] On the other hand, if the activation instruction INS-A was not received (step S100: No), the communication management device 12 determines whether or not there is a suspicion of unauthorized activation (more precisely, a suspicion of an unauthorized activation operation) based on the activation operation OPE-A (step S106). This process of step S106 corresponds to the first verification process to be performed for the activation operation OPE-A.

[0066] Fig. Figure 8 is a flowchart that provides a specific example of the process from step S106 in Fig. 6 shows. In Fig. In step S126, the communication management device 12 determines whether an activation of the control device 11 (vehicle control unit 13) that does not follow a predefined activation sequence has been detected. As described above, in this embodiment, the communication management device 12 is activated by the management system 2 according to the legitimate activation instruction INS-A. Furthermore, the vehicle control unit 13 is configured to accept only the remote control instruction INS (including the activation instruction INS-A) from the activated communication management device 12. In other words, the vehicle control unit 13 is activated only by the activation instruction INS-A transmitted by the communication management device 12 (predefined activation sequence).

[0067] For example, in step S126, the communication management device 12 determines whether or not activation information I1 has been received from the vehicle control unit 13, where activation information I1 indicates that the activation operation OPE-A has been performed on the vehicle control unit 13. Activation information I1 includes, for example, a time (activation time T3) at which the activation operation OPE-A was performed. Then, if activation information I1 has been received, the communication management device 12 determines that an activation of the vehicle control unit 13, which does not follow the predefined activation sequence, has occurred (step S126: Yes). The communication management device 12 then determines that there is a possibility that the activation based on the activation operation OPE-A at this time corresponds to an unauthorized activation, i.e.,that there is a suspicion that it is an unauthorized activation operation (step S128). If an activation of the vehicle control unit 13, which is suspected to be an unauthorized activation operation, has been detected in this way, the communication management device 12 can send an instruction to the vehicle control unit 13 to stop the activated vehicle control unit 13 once (e.g., an instruction to return the state to a standby state).

[0068] On the other hand, if information indicating that the activation operation OPE-A has been performed has not been received by the vehicle control unit 13, i.e., if an activation of the vehicle control unit 13 that does not follow the predefined activation sequence has not been detected (step S126: No), the communication management device 12 determines that there is no suspicion of an unauthorized activation operation (step S130). In this case, the Fig. The process is shown in Figure 6. It should be noted that although the first verification process in step S106 is performed here for the activation process OPE-A at the vehicle control unit 13, the first verification process can also be performed in a similar manner for the activation process OPE-A at the communication management device 12.

[0069] If an unauthorized activation is suspected in step S106, the process proceeds to step S108. In step S108, the communication management device 12 sends a "verification request message N2," which instructs management system 2 to verify the suspicion of unauthorized activation based on the activation operation OPE-A at that time. This verification request message N2 also instructs management system 2 to perform the second verification process (step S210). As will be explained in the description of step S210, which is described later, the second verification process is also based on a different criterion than the first verification process. For example, the verification request message N2 includes the activation information I1 as detailed information about the activation operation OPE-A at that time, along with the information that unauthorized activation is suspected.The activation information I1 includes, for example, the activation time T3 described above. Furthermore, in step S108, the communication management device 12 changes its own operating mode from normal standby mode to alert standby mode.

[0070] In step S110 following step S104 or S108, the communication management device 12 obtains a final determination result (a result of the in Fig. 9 indicated second verification process) of the management system 2 regarding the suspicion of unauthorized activation from this point in time (a suspicion of unauthorized remote activation or a suspicion of unauthorized activation operation) of the management system 2. Then the communication management device 12 determines the related final investigation result (whether the suspicion of unauthorized activation is valid or invalid).

[0071] If the suspicion of unauthorized activation is valid (step S110: Yes), the Communication Management Device 12 maintains the alert standby mode (step S112). On the other hand, if the suspicion of unauthorized activation is invalid (step S110: No), the Communication Management Device 12 restores its own operating mode from alert standby to normal standby, according to a mode change request R-MC received from Management System 2 (step S114). Note that a specific example of the processing flow regarding the restoration from alert standby to normal standby will be given later with reference to Fig. 13 and Fig. 14 is described.

[0072] If, in step S102, it is determined that there is no suspicion of unauthorized remote activation, or after step S114, the communication management device 12 executes a process for the normal activation of the vehicle control unit 13. Specifically, the communication management device 12 controls the vehicle control unit 13 in the state in which the one-factor authentication C1 (=authentication C22) is completed, as described later with reference to Fig. 12 to Fig. 14 is described in detail. 2-2. Process on the part of the administrative system

[0073] Fig. Figure 9 is a flowchart showing an example of a process on the side of the management system 2 relating to the verification and countermeasures of suspected unauthorized activation according to the present embodiment.

[0074] In step S200, the management system 2 (processor 22) determines whether or not the verification request message N1 regarding the suspected remote unauthorized activation has been received by vehicle 1. If the verification request message N1 has been received as a result of this determination (step S200: Yes), the management system 2 executes the second verification process (step S202). In other words, the management system 2 makes a final determination as to whether the suspicion of remote unauthorized activation related to the verification request message N1 is correct. Furthermore, the management system 2 transmits the final result of this determination to vehicle 1.

[0075] Fig. Figure 10 is a flowchart showing a first specific example (issuer verification process) of the second verification process (step S202), which is to be carried out in case of suspected unauthorized remote activation. Fig. In step S220, the management system 2 determines whether it has actually transmitted the activation instruction INS-A, which was received from vehicle 1 at that time. Specifically, the management system 2 reads the transmission history of its own activation instruction INS-A from the storage device 23 and checks the detailed information D1, described above and contained in the verification request message N1, against this transmission history. For example, the management system 2 checks the reception time T1 of the activation instruction INS-A and the electrocommunication number NM of the transmission source contained in the detailed information D1 against the transmission history. Alternatively, the management system 2 can, as in the example described later in Fig. 13, compare an instruction ID together with the reception time T1 and the electrocommunication number NM of the transmission source with the transmission history.

[0076] If the reception time T1 and the electrocommunication number NM of the transmission source each match information included in the transmission history as a result of the verification, Management System 2 determines that it did indeed transmit the activation instruction INS-A at that time (Step S220: Yes). Subsequently, Management System 2 finally determines that the suspicion of an unauthorized remote activation at that time is invalid (Step S222).

[0077] Even if the communication management device 12 determines that there is a suspicion of an unauthorized remote control instruction (step S102: Yes), there is a case in which it can be said that the activation instruction INS-A was transmitted by an unauthorized person. The transmission of the activation instruction INS-A by an unauthorized person corresponds, for example, to a transmission carried out under the condition that, while a terminal transmitting the activation instruction INS-A is being modified on the side of management system 2, the information about the modification is not exchanged between management system 2 and vehicle 1.Another example is transmission by a malicious person under the condition that a version of the predefined format (see step S120) to be used in the transmission / receipt of the activation instruction INS-A between management system 2 and vehicle 1 is not identical between management system 2 and vehicle 1.

[0078] If, on the other hand, the reception time T1 and the electrocommunication number NM of the transmission source do not match the information contained in the transmission history, Management System 2 determines that it did not actually transmit the activation instruction INS-A (Step S220: No). Consequently, Management System 2 finally determines that the suspicion of an unauthorized remote control instruction is correct (Step S224). According to the issuer's verification process described above, it can be prevented that vehicle 1 is taken over by a person making an unauthorized transmission of the activation instruction INS-A, regardless of whether vehicle 1 is inside or outside the predetermined area AR.

[0079] If it is finally determined that the suspicion of unauthorized remote activation is not valid at this time (step S202: No), the procedure proceeds to step S204. In step S204, management system 2 sends a request to cancel the alert standby mode, i.e., a request to change the R-MC mode from alert standby mode to normal standby mode, to vehicle 1. Note that a specific example of a specific processing flow related to the R-MC mode change request will be described later with reference to Fig. 13 is described.

[0080] If, on the other hand, it is finally determined that the suspicion of unauthorized remote activation is correct at this time (step S202: Yes), the procedure proceeds to step S206. In step S206, the management system 2 communicates with a mobile network operator that provides a mobile communications service for a large number of vehicles 1 (including the vehicle 1 for which the in Fig. 9. The process to be carried out is provided by the management system 2. Management system 2 then requests the mobile network operator to stop the information transmission from an electrocommunications number NM-X (unauthorized transmission source) used to transmit the activation instruction INS-A in connection with a suspected unauthorized remote activation at that time. The destinations to which the information transmission (e.g., the transmission of a text message) is to be stopped are all vehicles 1 managed by management system 2 and are determined, for example, based on vehicle management information stored in storage device 23. The information transmission is then stopped under the conditions that the following transmission stop condition is met.

[0081] The transmission stop condition described above is, for example, a state in which the electrical communication number NM-X is not used for the unauthorized activation instruction INS-A of the communication devices 11 of a plurality of vehicles 1, including the control device 11 of the vehicle 1 on which the Fig. The procedure specified in section 9 is to be carried out. Alternatively, the transmission stop condition is, for example, a state in which the electrical communication number NM-X is transmitted a multitude of times within a predetermined time period for the unauthorized activation instruction INS-A of the control device 11 of the vehicle 1, on which the Fig. The operation specified in section 9 is to be carried out. Furthermore, the management system 2 stores, for example, a list of information on the electrical communication numbers NM of transmission sources, contained in the detailed information D1 received by the respective vehicles 1 to be managed, in the storage device 23. Then, based on this information from the list, the management system 2 determines whether the transmission stop condition described above is met. According to the procedure described above in step S206, it can be efficiently prevented that the unauthorized activation instruction INS-A is transmitted from the unauthorized transmission source detected at that time to all vehicles 1 to be managed by the management system 2.

[0082] On the other hand, if the verification request message N1 was not received (step S200: No), the management system 2 determines whether the verification request message N2 regarding the suspected unauthorized activation from vehicle 1 was received or not. If, as a result of this determination, the verification request message N2 was not received (step S208: No), the process ends in Fig. 9 specified processes.

[0083] Once the verification request notification N2 has been received (step S208: Yes), the management system 2 performs the second verification process (step S210). In other words, the management system 2 makes a final determination as to whether the suspicion of unauthorized activation related to the verification request message N2 is valid. Furthermore, the management system 2 transmits the final result of this determination to vehicle 1.

[0084] The second verification process in step S210, for example, involves creating a notification INQ that sends a request to a user of vehicle 1 (e.g., a current borrower or owner) to activate vehicle control 13. More precisely, the management system 2 sends the notification INQ (e.g., a text message), which contains a request element for activating vehicle control 13, to the user terminal 3. This request element could, for example, include a message confirming to the user whether or not they accidentally activated vehicle control 13 around activation time T3 (see step S126).Alternatively, the query element could, for example, include a message confirming to the user whether or not they know anything about the activation of vehicle control 13 at activation time T3, and a message confirming to the user, if they do know something about the activation, a reason why vehicle control 13 was activated.

[0085] If, for example, a response indicating that the user is aware of the activation of vehicle control 13 and that the reason for its activation is appropriate, is received by the user via user terminal 3 in response to the INQ notification described above, the management system 2 final determines that the suspicion of unauthorized activation is invalid at that time (step S210: No). Furthermore, the appropriate reason for the activation of vehicle control 13 corresponds, for example, to a case in which the user of vehicle 1 requested a repair of vehicle 1 from a repair worker, and a worker accidentally activated vehicle control 13 by pressing a power button during the repair of vehicle 1.Alternatively, another corresponding reason corresponds to a case in which the user of vehicle 1 has activated the vehicle control unit 13 by mistakenly pressing the power button. Furthermore, activation by such a reason can be described as activation of the control device 11 (vehicle control unit 13) by a malicious person.

[0086] If the suspicion of unauthorized activation is not true (step S210: No), the management system 2 sends a request to cancel the alert standby mode, i.e., the request to change mode R-MC, to vehicle 1 (step S204).

[0087] On the other hand, the management system 2 final determines that the suspicion of unauthorized activation is valid (step S210: Yes) if, for example, a response from the user via the user terminal 3 is received in response to the notification INQ described above, indicating that the user knows nothing about the activation of the vehicle control 13, or a response indicating that the user knows something about the activation, but the reason why the vehicle control 13 was activated is not appropriate.

[0088] If the suspicion of unauthorized activation is valid (step S210: Yes), the management system 2 sends a notification to the user terminal 3, requesting that the unauthorized activation be prevented. The notification corresponds, for example, to a request to the user (borrower of vehicle 1) not to attempt activation using an unauthorized method. Second specific example of a second verification process

[0089] Here, the following first to third examples of a domain verification process are described as a second specific example of the second verification process (step S202), which is to be carried out in case of suspected unauthorized remote activation.

[0090] Generally, management system 2 sends the activation instruction INS-A to vehicle 1 if vehicle 1 is located within the predetermined area AR. If vehicle 1 is outside the predetermined area AR, management system 2 does not transmit the activation instruction INS-A to vehicle 1. For example, while AVP vehicle 1A (see Fig. 3) The AVP vehicle 1A, which supports automatic parking, operates in the parking lot according to the remote control instruction INS, which includes the activation instruction INS-A. The AVP vehicle 1A is driven by the user outside the parking lot. The AVP vehicle 1A does not receive the activation instruction INS-A from the management system 2 while outside the parking lot. If the vehicle 1 receives the activation instruction INS-A while outside the predetermined area AR, there is a high probability that the activation instruction INS-A is not a legitimate instruction transmitted by the management system 2 and is an unauthorized remote control instruction.

[0091] From the perspective described above, a second specific example of the second verification process is considered to be determining whether or not vehicle 1 is located in the predetermined area AR when it receives the activation instruction INS-A. A procedure for determining whether or not vehicle 1 is located in the predetermined area AR when it receives the activation instruction INS-A is a “verification process for the area” described here. Fig. 11A is a conceptual representation to explain the first to third examples of the verification process for the area.

[0092] The first example of the area verification process is determining whether the landmark M located in the predetermined area AR is visible from the position of vehicle 1. If the landmark M is not visible from the position of vehicle 1, the management system 2 ultimately determines that vehicle 1 is not in the predetermined area AR, provided that the control device 11 (communication management device 12) receives the activation instruction INS-A and the suspicion of unauthorized remote activation is confirmed.

[0093] More precisely, vehicle 1 (in-vehicle system 10) transmits image information obtained from the camera mounted on vehicle 1 to management system 2. Management system 2 is configured to detect the landmark M around vehicle 1 based on the image information received from vehicle 1. Management system 2 determines whether the landmark M around vehicle 1 is detected. If the landmark M is not detected, management system 2 determines that the landmark M is not detectable from the position of vehicle 1. In other words, management system 2 determines that vehicle 1 is not within the predetermined area AR when the communication management device 12 receives the activation instruction INS-A.

[0094] The second example of area verification processing is the comparison between the position information of vehicle 1 and the map information. The map information contains the position of the predetermined area AR. Thus, by comparing the position information of vehicle 1 and the map information, management system 2 determines whether vehicle 1 is located in the predetermined area AR when communication management device 12 receives the activation instruction INS-A. If vehicle 1 is not located in the predetermined area AR when communication management device 12 receives the activation instruction INS-A, management system 2 ultimately determines that there is a reasonable suspicion of unauthorized remote activation.

[0095] More precisely, the vehicle's internal system 10 obtains the position information of vehicle 1 using the position sensor contained in the sensors 14. Alternatively, the vehicle's internal system 10 obtains the position information of vehicle 1 via the localization process. The vehicle's internal system 10 transmits the position information of vehicle 1 to the management system 2. The management system 2 obtains the position information of vehicle 1 from the vehicle's internal system 10. Then, when the communication management device 12 receives the activation instruction INS-A, the management system 2 determines whether vehicle 1 is located within the predetermined area AR or not by comparing the position information of vehicle 1 with the map information.

[0096] In the third example of the area verification process, vehicle 1 (in-vehicle system 10) and communication device 5, which is deployed in the predetermined area AR, are configured to communicate according to a specific communication scheme. For example, in the case of the Fig. In Figure 3 of the automated parking diagram, the parking control center 2B of the communication device 5, the AVP vehicle 1A in the parking space, and the parking control center 2B communicate according to the specific communication scheme. The specific communication scheme is, for example, a near-field communication scheme such as WiFi (registered trademark) and Bluetooth (registered trademark).

[0097] The third example is the determination of whether or not communication is established between vehicle 1 (in-vehicle system 10) and communication device 5, which is located in the predetermined area AR. If no communication is established between vehicle 1 and communication device 5, the management system 2 finally determines that vehicle 1 is not located in the predetermined area AR if the communication management device 12 receives the activation instruction INS-A and the suspicion of unauthorized remote activation is confirmed.

[0098] Fig. 11B is a flowchart showing the outline of the first three examples of the verification process for the area. Fig. In step S230, control system 2 determines whether vehicle 1 is located within the predetermined area AR. If vehicle 1 is located within the predetermined area AR (step S230: Yes), control system 2 ultimately determines that the suspicion of unauthorized remote activation is invalid at this time (step S232). However, if vehicle 1 is not located within the predetermined area AR (step S230: No), control system 2 ultimately determines that the suspicion of unauthorized remote activation is valid (step S234).

[0099] According to the area verification process described above, it can be prevented that vehicle 1, which is located outside the predetermined area AR, is taken over by a person attempting to carry out an unauthorized transmission of the activation instruction INS-A. 2-3. Specific examples of the processing sequence during activation of the control device

[0100] Here, three specific examples of the processing sequence in connection with the activation of the control device 11 (the communication management device 12 and the vehicle control 13) of the vehicle 1 are described.

[0101] First, Fig. 12 a sequence diagram showing a specific example of the processing flow in connection with the activation of the control device 11 based on the legitimate activation instruction INS-A. Fig. Figure 12 shows an example where the legitimate activation instruction INS-A is transmitted from the management system 2 to the communication management device 12 in normal standby mode.

[0102] The communication management device 12 retrieves the detailed information D1 (e.g., the reception time T1, the electrocommunication number NM of the transmission source, and the instruction ID) regarding the activation instruction INS-A1 received at that time and stores the detailed information D1 in the storage device 12C. If the activation instruction INS-A transmitted by the management system 2 is legitimate, the first verification process does not determine that the activation instruction INS-A is an unauthorized remote control instruction, as described in Fig. Example 12. Therefore, the communication management device 12 performs a normal authentication (one-factor authentication C1) procedure.

[0103] Single-factor authentication C1 is performed to confirm that the activation instruction INS-A received by the communication management device 12 was indeed transmitted by the management system 2. The single-factor authentication C1 process is similar in content to the issuer verification process described above (see Fig. 10). Specifically, during one-factor authentication C1, the communication management device 12 sends an activation confirmation request R-SC along with the detailed information D1 to the management system 2.

[0104] Management System 2, which received the activation acknowledgment request R-SC, performs a process to respond to the activation acknowledgment request R-SC as follows. For example, Management System 2 determines whether the receive time T1 received by Communication Management Device 12 matches a time at which Management System 2 transmitted the activation instruction INS-A. Furthermore, Management System 2 determines whether the transmission source's electrical communication number NM received by Communication Management Device 12 matches the electrical communication number NM1 used by Management System 2 to transmit the activation instruction INS-A. Additionally, Management System 2 determines whether the command ID received by Communication Management Device 12 matches a command ID1 of the activation instruction INS-A transmitted by Management System 2. In the Fig. In the example shown in Figure 12, the activation instruction INS-A is legitimate, and thus all three determination criteria are met. In this case, the management system 2 sends the activation instruction INS-A, along with information about the positive determination result regarding the three determination criteria, back to the communication management device 12.

[0105] When the communication management device 12 receives the activation instruction INS-A along with the information about the positive determination result, the one-factor authentication C1 is complete. In this context, the communication management device 12 exits normal standby mode and enters an active state. The communication management device 12 then transmits the activation instruction INS-A to the vehicle control unit 13 in a standby state. Upon receiving the activation instruction INS-A from the communication management device 12, the vehicle control unit 13 activates. Subsequently, the vehicle control unit 13 sends a notification of activation completion to the communication management device 12, indicating that the activation of the vehicle control unit 13 is complete.The communication management device 12, which has received the notification of completion of the activation, sends the notification of completion of the activation to the management system 2.

[0106] Fig. Figure 13 is a sequence diagram showing a specific example of the processing flow related to the activation of the control device 11 when the activation instruction INS-A, indicating suspected unauthorized remote control activation, is received. Furthermore, it corresponds to Fig. 13 an example where the second verification process finally determines that the suspicion of unauthorized remote activation is invalid.

[0107] The communication management device 12 performs the first verification process (see step S102 in Fig. 6), after obtaining the detailed information D1 regarding the activation instruction INS-A received this time. In the Fig. In the example shown in Figure 13, the first verification process determines that there is a suspicion of unauthorized remote activation. Therefore, the communication management device 12 changes its own operating mode from normal standby mode to alert standby mode and sends the verification request message N1 to the management system 2 (see step S104).

[0108] Management system 2, which received the notification of verification request N1, performs the second verification process (e.g., the one in Fig. 10 issuer verification process) through (see step S202). As above in Fig. As described in section 13, the second verification process finally determines that the suspicion of unauthorized remote activation is invalid. Therefore, the management system 2 sends the mode change request R-MC to the vehicle 1 (communication management device 12) (see step S204).

[0109] The communication management device 12, which received the mode change request R-MC, executes a two-factor authentication process C2. This two-factor authentication C2 comprises authentication C21 and the subsequent authentication C22. Authentication C21 is executed to confirm that the mode change request R-MC received by the communication management device 12 was indeed transmitted by the management system 2. The processing content of authentication C22 is the same as that of the single-factor authentication C1.

[0110] During authentication C21, the communication management device 12 obtains detailed information D2 (e.g., the reception time T2 of the mode change request R-MC, the electrical communication number NM of the transmission source, and the instruction ID) regarding the mode change request R-MC received at that time and stores the detailed information D2 in the storage device 12C. Subsequently, the communication management device 12 sends a mode change confirmation request R-MCC, along with the detailed information D2, to the management system 2.

[0111] Management System 2, which received the mode change confirmation request R-MCC, executes a process to respond to the mode change confirmation request R-MCC. This process is executed in a similar manner to the process to respond to the activation confirmation request R-SC, which is carried out with reference to Fig. 12. If, as a result, positive determination result information is obtained regarding the three types of determination included in the detailed information D2, the management system 2 retransmits the mode change request R-MC together with the positive determination result information to the communication management device 12.

[0112] When the Communication Management Device 12 receives the mode change request R-MC along with the information about the positive determination result, authentication C21 is complete. In connection with this, the Communication Management Device 12 performs a recovery from alert standby mode to normal standby mode. Then, the Communication Management Device 12 sends a notification of the completed mode change to the Management System 2.

[0113] The management system 2, having received notification of the mode change completion, sends the legitimate activation instruction INS-A to the communication management device 12. The communication management device 12, having received the legitimate activation instruction INS-A, performs authentication C22 in a manner similar to single-factor authentication C1. Once authentication C22 is complete, two-factor authentication C2 is also complete, and the communication management device 12 and the vehicle control unit 13 are activated sequentially.In other words, the control device 11 is configured to be activated after authentication C21 is completed, and then authentication C22 is completed, and authentication C21 is authentication regarding the mode change, and authentication C22 is authentication regarding the activation of the control device 11.

[0114] Furthermore, as described above, the vehicle control system 100 requires the completion of two-factor authentication C2 to activate the control device 11 after the second verification process has finally determined that the suspicion of unauthorized remote activation is unfounded (similar to the suspicion of in Fig. The unauthorized activation specified in section 14 is invalid. In other words, the control device 11 cannot be activated without the two-factor authentication C2 being completed.

[0115] Fig. Figure 14 is a sequence diagram showing a specific example of the processing flow regarding the activation of the control device 11 when the activation instruction INS-A is received, which is suspected to be an unauthorized activation. Furthermore, it corresponds to Fig. 14 an example where the second verification process finally determines that the suspicion of unauthorized activation is invalid.

[0116] When the activation operation OPE-A is performed on the vehicle controller 13, the vehicle controller 13 obtains the activation information I1, including the activation operation time T3, relating to the activation operation OPE-A and stores the activation information I1 in the storage device 13B of the vehicle controller 13. Subsequently, the vehicle controller 13 transmits the activation information I1 to the communication management device 12.

[0117] The communication management device 12, having received the activation information I1, stores the activation information I1 in the storage device 12C and performs the first verification process (see step S106). When the activation information I1 is received by the vehicle control unit 13, the first verification process determines that there is a suspicion of unauthorized remote activation. Therefore, the communication management device 12 changes its operating mode from normal standby mode to alert standby mode and sends the verification request message N2 to the management system 2 (see step S108).

[0118] Management system 2, which received the notification of verification request N2, performs the second verification process (see step S210). As above in Fig. As described in section 14, the second verification process finally determines that the suspicion of unauthorized activation is invalid. Therefore, the management system 2 sends the mode change request R-MC to the vehicle 1 (communication management device 12) (see step S204).

[0119] Even if the R-MC mode change request is received after it has been determined that there is a suspicion of unauthorized activation, as in the Fig. In the specific example shown in Figure 14, the communication management device 12 performs the two-factor authentication process C2. The subsequent processing flow is similar to that in Figure 14. Fig. 13 described, so a detailed description is omitted.

[0120] It should be noted that, during the processing sequence according to the activation operation OPE-A at the vehicle control unit 13 with reference to Fig. As described in section 14, the processing sequence is similar even if the activation operation OPE-A has been recorded on the communication management device 12. 2-4. Change of process on the side of the vehicle's control device

[0121] Fig. Figure 15 is a flowchart showing a modification of a vehicle-side process relating to the verification and countermeasures in case of suspected unauthorized activation according to the present embodiment. The process in this flowchart differs from the one in Fig. The flowchart shown in step 6 is modified by having the following process executed from step S300 instead of step S108.

[0122] Similar to in Fig. The first verification process in section 6 is included. Fig. 15 a process (step S102) to determine whether or not there is a suspicion of unauthorized remote activation, and a process (step S106) to determine whether or not there is a suspicion of unauthorized activation. One can therefore say that the first verification process in Fig. 15. The determination includes whether the suspicion of unauthorized activation is a suspicion of unauthorized remote activation or a suspicion of an unauthorized activation operation. Then, in Fig. 15, if there is suspicion of an unauthorized activation operation in step S106, the communication management device 12 changes its own operating mode to an "immediate shutdown mode" instead of the alert standby mode.

[0123] The immediate shutdown mode described here is a mode for disabling the activation of control device 11 in a situation where the management system 2 cannot remotely release the activation / deactivation state of control device 11. More specifically, one target for which activation is to be disabled is at least the vehicle control 13 between the vehicle control 13 and the communication management device 12. Furthermore, the "situation where the management system 2 cannot remotely release the activation-locked state of control device 11" is, for example, a situation where an employee must replace a component of the vehicle 1 to release the activation-locked state, or a situation where an employee must perform a specific release procedure on control device 11.

[0124] It should be noted that if the process on the side of control device 11 as in Fig. The process specified in section 15 is executed; the process on the side of the management system 2 is the process obtained by taking the processes from steps S208 to S212 from the processes of the in Fig. omits the flowchart shown in section 9. 3. Effects

[0125] As described above, according to the present embodiment, if it is determined on the vehicle 1 side that there is a suspicion of unauthorized activation of the control device 11, the transition to the alert standby mode allows the final determination by the management system 2 as to whether the suspicion of unauthorized activation exists or not to be awaited, while preventing the control device 11 from being used to cause the vehicle 1 to perform unauthorized operation. Then, the operating mode of the control device 11 (communication management device 12) is restored from the alert standby mode to the normal standby mode, provided that the second verification process finally determines that the suspicion of unauthorized activation is invalid, and authentication (e.g.,The authentication (C21) between the control device 11 and the management system 2 is successful. This prevents the execution of unnecessary or excessive operational restrictions of the vehicle 1. This prevents misuse of the functions of the vehicle 1 and avoids a deterioration of user comfort or a reduction in the service life of the vehicle 1.

[0126] Furthermore, as described above, according to the present embodiment, the control device 11 (communication management device 12) of the vehicle 1 requests the management system 2 to perform the second verification process to finally determine whether the suspicion of unauthorized activation is valid or not, based on a criterion that differs from the criterion of the first verification process. This allows the vehicle 1 (in-vehicle system 10) and the management system 2 to cooperate efficiently to determine whether the suspicion of unauthorized activation of the vehicle 1 is correct or not.

[0127] Furthermore, according to the present embodiment, if the second verification process ultimately determines that the suspicion of unauthorized activation is invalid, the operating mode of the control device 11 (communication management device 12) is restored from the alert standby mode to the normal standby mode, provided that authentication C21 is complete. In this way, even under suspicion of unauthorized remote activation, the control device 11 can be restored to a state (i.e., the normal standby mode) in which the management system 2 can remotely activate the control device 11 using the legitimate activation instruction INS-A, as a result of the cooperation between the management system 2 and the control device 11.

[0128] Furthermore, according to the above with reference to Fig.The procedures described in section 15 make it possible to take countermeasures against the misuse of the functions of vehicle 1 in order to prevent impairment of user comfort or a reduction in the operating time of vehicle 1, whereby misuse of the functions of vehicle 1 by direct unauthorized activation of vehicle 1 is reliably prevented. QUOTES INCLUDED IN THE DESCRIPTION

[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited patent literature

[0000] JP 2023-148463

[0002] JP 2023-148463 A [0002, 0003]

Claims

[1] Motion body control system (100) configured to control a moving body (1) which has a function to perform an operation in a predetermined area (AR) according to a remote control instruction (INS), wherein the motion body control system (100) comprises: an administrative system (2) configured to legitimately generate the remote control instruction (INS); and a control device (11) mounted and configured on the moving body (1) to cause the moving body (1) to perform an operation in accordance with a legitimate remote control instruction (INS) from the management system (2), wherein: The remote control instruction (INS) includes an activation instruction (INS-A) by which the control device (11) is remotely activated; the control device (11) is configured to to carry out an initial verification process to determine whether or not there is a suspicion of unauthorized activation of the control device (11), and if there is suspicion of unauthorized activation to change an operating mode of the control device (11) from a normal standby mode to an alert standby mode; if there is a suspicion of unauthorized activation, the management system (2) is configured to perform a second verification process to finally determine whether the suspicion of unauthorized activation is valid or not; wherein the normal standby mode is a mode of waiting to receive a legitimate activation instruction (INS-A) from the management system (2); and wherein the alert standby mode is a mode which is to be restored to the normal standby mode, under the conditions that the second verification process finally determines that the suspicion of unauthorized activation is invalid and the authentication between the control device (11) and the management system (2) is successful, while the activation of the control device (11) is prevented. [2] Motion control system (100) according to claim 1, wherein, when the second verification process finally determines that the suspicion of unauthorized activation is invalid, the control device (11) and the management system (2) are configured to cooperate to restore the operating mode from alert standby mode to normal standby mode. [3] Motion control system (100) according to claim 1 or 2, wherein the first verification process comprises: Determine whether the activation instruction (INS-A) received by the control device (11) conforms to a predefined format or not; and If the activation instruction (INS-A) does not conform to the predefined format, determine that there is a suspicion of unauthorized activation. [4] Motion control system (100) according to claim 1 or 2, wherein the first verification process comprises: Determine whether an activation of the control device (11) that does not follow a predefined activation sequence has been detected or not; and If activation of the control device (11) that does not follow the predefined activation sequence has been detected, determine that there is a suspicion of unauthorized activation. [5] Motion control system (100) according to claim 1 or 2, wherein the second verification process comprises: Determine whether the management system (2) has actually transmitted the activation instruction (INS-A) received from the moving body (1); and if the management system (2) has not actually transmitted the activation instruction (INS-A) to the moving body (1), finally determines that the suspicion of unauthorized activation is valid. [6] Motion control system (100) according to claim 5, wherein: if the second verification process finally determines that the suspicion of unauthorized activation is valid, the management system (2) is configured to request from a mobile network operator to stop the transmission of information to all moving bodies (1) managed by the management system (2) from an electrocommunications number (NM-X) used for transmitting the activation instruction (INS-A) relating to the suspicion of unauthorized activation, under conditions that a transmission stop condition is met; and the transmission stop condition is a condition that the electrical communication number (NM-X) was used for an unauthorized activation instruction (INS-A) of control devices (11) of a plurality of moving bodies (1) including the control device (11) of the moving body (1), or a condition that the electrical communication number (NM-X) has been used a multitude of times within a predetermined time period for the unauthorized activation instruction (INS-A) of the control device (11) of the moving body (1). [7] Motion control system (100) according to claim 1 or 2, wherein: a landmark (M) is located in the predetermined area (AR); and the second verification process includes Determine whether the reference point (M) is detectable by the management system (2) from a position of the moving body (1) or not, and If the reference point (M) cannot be detected by the management system (2) from the position of the moving body (1), final determination that the moving body (1) is not in the predetermined area (AR) when the control device (11) receives the activation instruction (INS-A) and the suspicion of unauthorized activation is valid. [8] Motion control system (100) according to claim 1 or 2, wherein the second verification process comprises: Obtaining position information of the moving body (1); Determine whether the moving body (1) is located within the predetermined area (AR) or not when the control device (11) receives the activation instruction (INS-A), by comparing map information in which a position of the predetermined area (AR) is recorded and the position information of the moving body; and If the moving body (1) is not in the predetermined area (AR), when the control device (11) receives the activation instruction (INS-A), final determination that the suspicion of an unauthorized activation is valid. [9] Motion control system (100) according to claim 1 or 2, wherein: the moving body (1) and a communication device (5) provided in the predetermined area (AR) are configured to perform communication according to a specific communication scheme; and The second verification process includes: Determine whether or not communication has been established between the moving body (1) and the communication device (5); and If communication between the moving body (1) and the communication device (5) is not established, final determination that the moving body (1) is not in the predetermined area (AR), if the moving body (1) receives the activation instruction (INS-A) and the suspicion of unauthorized activation is valid. [10] Motion body control method for controlling a moving body (1) which has the function of performing an operation in accordance with a remote control instruction (INS) in a predetermined area (AR), wherein the motion body control method comprises: Causing a control device (11) to perform an initial verification process to determine whether or not there is a suspicion of unauthorized activation of the control device (11); if there is suspicion of unauthorized activation, cause the control device (11) to change an operating mode of the control device (11) from a normal standby mode to an alert standby mode; and If there is a suspicion of unauthorized activation, (2) induce an administrative system to perform a second verification process to finally determine whether the suspicion of unauthorized activation is valid or not, wherein: the control device (11) which is configured to cause the moving body (1) to perform an operation on the moving body (1) in accordance with a legitimate remote control instruction (INS) from the management system (2) which is configured to legitimately generate the remote control instruction (INS); The remote control instruction (INS) includes an activation instruction (INS-A) that remotely activates the control device (11); the normal standby mode is a mode of waiting to receive a legitimate activation instruction (INS-A) from the management system (2); and The alert standby mode is a mode that can be restored to normal standby mode under the conditions that the second verification process finally determines that the suspicion of unauthorized activation is invalid and the authentication between the control device (11) and the management system (2) is successful, while the activation of the control device (11) is prevented.

Citation Information

Patent Citations

  • 2023-148463

  • Mobile control method, mobile control system, and mobile control program

    JP2023148463A