AUTONOMOUS DRIVING CONTROL UNIT, AUTONOMOUS DRIVING VEHICLE AND CONTROL SYSTEM FOR AUTONOMOUS DRIVING VEHICLE

DE112018002342B4Active Publication Date: 2025-10-23ASTEMO LTD
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
DE112018002342
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2017-07-31
Filing Date
2018-07-19
Publication Date
2025-10-23
Estimated Expiration
2038-07-19

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Control unit for controlling an autonomously driving vehicle (100), wherein the control unit (130) has a function to control a movement of the vehicle (100) according to instructions from an external system (300), wherein, when the function to control a movement of the vehicle (100) according to instructions from an external system (300) is activated, the control unit (130) recognizes the validity of the external system (300) by - communicates with the external system (300) and the vehicle (100) via a communication device, - recognizes that the vehicle, using content received via the communication means, has changed the communication means to a modified communication means through which the external system (300) gives instructions for the movement of the vehicle (100), - recognizes that encrypted communication has been established via the modified communication means with the external system (300) using information acquired during the change of the communication means and required for encryption, - recognizes that a user (21) of the vehicle (100) has authorized the movement of the vehicle (100) by the external system (300), and - recognizes that the user (21) who has authorized the movement of the vehicle (100) through the external system (300) is an authorized user of the vehicle (100).
Need to check novelty before this filing date? Find Prior Art

Description

Technical field

[0001] The present invention relates to a control unit for a motor vehicle that can be moved and parked autonomously, a motor vehicle that is controlled by the control unit, an infrastructure facility such as a parking management facility that issues an instruction to the vehicle, and a system comprising the motor vehicle and the infrastructure facility. State of the art

[0002] Technological advancements in autonomous vehicles, also known as self-driving vehicles, have made significant progress. As a result, it has recently become technically possible to move and park a driverless vehicle at a desired location. Consideration has been given to using this functionality to provide various services within a parking facility and to optimize its use.

[0003] PTL 1 describes a vehicle control system that outsources autonomous driving to self-driving vehicles parked in a parking lot, and also mentions the provision of a car wash service and charging service in the parking facility.

[0004] PTL 2 describes that a parking space without through traffic is provided, and that a parking management facility issues an instruction to a vehicle to move the vehicle for efficient management of the parking facility.

[0005] Document DE 10 2014 221 772 A1 discloses a system that allows the driver external access to the vehicle if they detect that their vehicle is being moved without authorization. Further systems are disclosed in DE 10 2015 202 478 A1 and DE 10 2014 224 108 A1.

[0006] Document DE 10 2011 104 061 A1 concerns a vehicle with a valet parking function which, when activated, blocks access to the trunk or glove compartment. List of reference literature Patent literature PTL 1: JP 2015- 219 811 A PTL 2: JP 2016- 6 603 A Summary of the invention: Technical problem

[0007] However, the movement of a vehicle according to information or instructions provided by an infrastructure facility, such as a parking management facility, means that someone other than the person (authorized user) with driving privileges for the vehicle is moving it. Therefore, security measures such as theft prevention and misuse prevention are necessary. This means it is necessary to take measures such as obtaining, based on the consent of the authorized user, temporary authorization from the infrastructure facility to move the vehicle. PTL 2 discloses a protocol for such a measure.The protocol includes the transmission of a temporary password from a user terminal to a vehicle and a parking management facility upon entry into the facility, communication between the vehicle and the parking management facility during the authentication process using the temporary password, and the movement of the vehicle through the parking management facility.

[0008] This protocol, however, requires the user device to communicate not only with the vehicle but also with the parking management system. This is not straightforward for a simple user device such as a small wireless authentication device supplied with a vehicle (an endpoint similar to a vehicle key, known as a "smart key"). Furthermore, transmitting a temporary password from the user device to the infrastructure system carries risks. Specifically, the communication can be intercepted and the temporary password stolen, creating a risk of the vehicle being controlled using the password. There is also a risk of the vehicle being controlled if someone impersonating the infrastructure system communicates with the user device and obtains the temporary password.

[0009] The object of the present invention is to enable an infrastructure facility to temporarily acquire a tax authorization in order to move an autonomously driving vehicle while preventing safety risks and to carry out simple operations during the storage and retrieval of vehicles. Solution to the problem

[0010] An example of the present invention for achieving the above problem is a control unit for controlling an autonomously driving vehicle, wherein the control unit has a function for controlling the movement of the vehicle according to instructions from an external system. When the function for controlling the movement of the vehicle according to the instructions from the external system is activated, the control unit recognizes the validity of the external system by communicating with the external system and the vehicle, recognizes that encrypted communication has been established with the external system, recognizes that a user of the vehicle has authorized the movement of the vehicle by the external system, and recognizes that the user is an authorized user of the vehicle.

[0011] An autonomous vehicle has a function to move according to instructions from an external system. When this function is activated, the vehicle verifies the validity of the external system by communicating with it, detecting that encrypted communication has been established, recognizing that a user of the vehicle has authorized movement by the external system, and confirming that the user is an authorized user of the vehicle.

[0012] A system causes the autonomous movement of a vehicle. When the system instructs the vehicle to move and activates a movement of the vehicle, the system communicates with the vehicle so that the vehicle can recognize the validity of the system, so that the vehicle recognizes that encrypted communication has been established, so that the vehicle recognizes that a user of the vehicle has authorized the autonomous movement of the vehicle, and so that the vehicle recognizes that the user is an authorized user of the vehicle. Advantageous effects of the invention

[0013] The present invention enables an infrastructure facility to temporarily acquire a tax authorization to move an autonomously driving vehicle while preventing safety risks and to perform simple operations when storing and retrieving vehicles in or from this environment. Brief description of the drawings Fig. Figure 1 represents an example of an overall configuration of an autonomous vehicle and an infrastructure facility that issues instructions to the vehicle. Fig. Figure 2 represents an example of the change in state of an autonomous vehicle control unit with respect to control by an infrastructure facility. Fig. Figure 3 represents an example of the movement of a vehicle and a user of the vehicle in an infrastructure facility management area during storage. Fig. Figure 4 represents an example of a communication protocol between the infrastructure facility and the vehicle at an entrance. Fig. Figure 5 presents an example of a communication protocol for establishing secure communication between the infrastructure facility and the vehicle. Fig. Figure 6 presents an example of a communication protocol between a user terminal, the vehicle and the infrastructure facility during storage. Fig. Figure 7 shows an example of a display on an interactive control panel when the user confirms whether the infrastructure facility should be allowed to control the vehicle. Fig. Figure 8 shows an example of a display on the interactive control panel when the user confirms whether to use an optional service offered by the infrastructure facility. Fig. Figure 9 represents an example of a user terminal device. Fig. Figure 10 presents an example of a communication protocol between a user authentication device, an autonomous driving control unit and a vehicle-side communication device during storage. Fig. 11 provides an example of vehicle movement when the infrastructure facility moves a parked vehicle. Fig. 12 provides an example of a communication protocol between the vehicle and the infrastructure facility when the infrastructure facility moves a parked vehicle. Fig. Figure 13 presents an example of the movement of a vehicle and a user of the vehicle in the infrastructure facility management area during outsourcing. Fig. 14 presents an example of a communication protocol between the user terminal, the vehicle and the infrastructure facility during outsourcing. Fig. Figure 15 represents an example of a payment terminal of the infrastructure facility. Fig. Figure 16 is an example of a communication protocol between an optional user terminal, the vehicle and the infrastructure facility during outsourcing. Fig. Figure 17 provides an example of the information contained in command parameters for communication between the infrastructure facility and the vehicle at the entrance. Fig. Figure 18 presents an example of a communication packet configuration used to establish secure communication between the infrastructure facility and the vehicle. Fig. 19 provides an example of the information contained in command parameters in the communication used to establish secure communication between the infrastructure facility and the vehicle. Fig. Figure 20 represents an example of a configuration of a communication packet in the secure communication between the infrastructure facility and the vehicle. Fig. Figure 21 presents an example of a protocol for generating encrypted communication data and a message authentication code. Fig. Figure 22 represents an example of the movement of a vehicle that is about to leave the infrastructure facility management area. Fig. 23 represents an example of the movement of a vehicle user to a vehicle which, due to the detection of abnormal movement, is unable to follow the instructions of the infrastructure facility. Description of embodiments

[0014] In the following, embodiments of the present invention are described with reference to the drawings. First embodiment

[0015] A system configuration according to an embodiment of the present invention is described with reference to Fig. 1 described. In this embodiment, it is assumed that an infrastructure facility 300 is a facility that is mainly used for parking a vehicle 100.

[0016] An infrastructure management device 330 manages and controls the infrastructure facility 300 as a whole to perform movement planning for a vehicle 100 within an area managed by the infrastructure facility 300 (i.e., within an infrastructure facility management area 301), resource allocation, fee management, and the like. A barrier control device 350 connected to the infrastructure management device 330 controls the opening and closing of barriers at the entrance and exit of the infrastructure facility. A payment terminal 700 is a terminal used by a user of the infrastructure facility 300 to pay a fee in cash and to call for a parked vehicle.

[0017] An infrastructure-side communication device 310 is a device that communicates with a vehicle 100 in the infrastructure facility management area 301 and with vehicles 100 entering and exiting the area. It has the capability to perform encrypted communication with authentication. Furthermore, it has the capability to use a variety of communication means as needed. For example, a configuration can be used in which dedicated short-range communications (DSRC) is employed in an area surrounding an entrance 11 to securely provide each vehicle 100 entering the infrastructure facility management area 301 with information required for network connectivity to a wireless LAN within the infrastructure facility management area 301.In such a case, the infrastructure-side communication device 310 has functions to carry out communication using dedicated near field communication and wireless LAN.

[0018] A large parking facility can be efficiently covered using the dedicated near-field communication (NFC) used at entrance 11 to provide each vehicle with wireless LAN connection information, and the wireless LAN used with the connection information in infrastructure facility management area 301. In the case of an extremely large parking facility, it is possible to use other communication methods, such as a cellular network, instead of the wireless LAN.

[0019] A large number of barrier control units 350 may be provided, depending on the number and locations of the entrances 11 and exits 12, and a large number of payment terminals 700 may be provided, depending on the frequency of use and the number and locations of the entrances and exits for vehicle occupants in the parking facility. Furthermore, a large number of infrastructure-side communication devices 310 may be provided, depending on the size of the parking facility or the means of communication. In such a case, the information required for communication with the vehicle 100 is jointly owned by the devices.

[0020] The vehicle 100, which can be controlled by the infrastructure facility 300, comprises components for implementing the basic functions of a vehicle, including a power source 220 (such as an internal combustion engine, a motor, and its drive circuitry) that provides motive power; a drivetrain 230 that transmits the motive power to the tires; a braking system 240 for controlling the brakes; a steering system 250 for controlling the direction of travel; and a vehicle control unit 210 that performs the overall control of these components. The vehicle control unit 210 may include a variety of electronic control units for engine control, steering control, vehicle behavior control, etc.

[0021] A user interface device 190 is connected to the vehicle control unit 210. The user interface device 190 serves as a device that displays the vehicle status and enables the implementation of operating settings for the vehicle. The user interface device 190 is also connected to an interactive control panel 600, which displays information to the user 21 and is used by the user 21 to perform operations.

[0022] A user authentication device 180 is also connected to the vehicle control unit 210. The user authentication device 180 is a device that performs authentication for the user 21 to confirm whether the user is an authorized user of the vehicle 100. If a small wireless user terminal 400 (e.g., a "smart key"), as in Fig. As shown in Figure 9, the terminal device used as a key for the vehicle 100 has functions to determine the presence or absence of the user terminal device 400 through encrypted communication, and to determine whether the user terminal device 400 is inside or outside the vehicle. To determine whether the terminal device is inside or outside the vehicle, long-wave radio waves are used, transmitted from the user authentication device 180 to the terminal device 400, and antennas are appropriately installed inside and outside the vehicle 100 to adjust the electric field strength accordingly.

[0023] The user authentication device 180 can include a variety of devices, such as one responsible for performing authentication, one responsible for sending radio waves to the user authentication device 180, and one responsible for receiving radio waves sent by the user authentication device 180.

[0024] The user terminal 400, which communicates with the user authentication device 180, is a device as described in Fig. Figure 9 shows a device that can be carried by the user 21 and includes a "Lock" button 410 for locking the doors of the vehicle 100, an "Unlock" button 420 for unlocking the doors, and a "Park" button 430 to issue an instruction to initiate autonomous parking after the doors of the vehicle 100 have been locked, if required. The terminal also includes a near-field communication antenna 450 for exchanging information with a touch device.

[0025] The user authentication device 180 can also have a configuration that does not involve the use of a user terminal 400. For example, a biometric authentication sensor for fingerprints and finger veins can be located and connected near a vehicle door or the ignition switch of an internal combustion engine, and the like, to be used instead of the user terminal 400. In this case, for example, a touch point or touch method (how often and how long the touch occurs) and a state of the vehicle 100 at the time of touch correspond to an operation of each button on the user terminal 400.

[0026] Even if the user terminal 400 is required, the user authentication terminal 180 can support an operation with biometric authentication instead of using the user terminal 400. Furthermore, the presence of the user authentication terminal 180 and a predetermined operation on the vehicle 100 (touching a spot near the door) can be performed as an operation equivalent to pressing a button on the user terminal 400, rather than actually using the button on the user authentication terminal 400. In this case, some or all of the buttons on the user terminal 400 can be omitted.

[0027] The vehicle 100 includes an autonomous driving control unit 130, which performs the control necessary to move the vehicle without a driver, such as in the case of autonomous parking (valet parking). The autonomous driving control unit 130 is connected to an external sensor 170 for detecting the vehicle's environment, a map information management device 150, which manages detailed map information, and a vehicle position detection device 160, which detects the current position. Additionally, a vehicle-side communication device 110 is connected, capable of communicating with the infrastructure-side communication device 310, receiving information and instructions from the infrastructure device 300, and sending a response to the infrastructure device 300.The autonomous driving control unit 130 is able to comprehensively determine information and instructions from these devices and issue an operating instruction to the vehicle control unit 210 for the vehicle 100 in order to move the vehicle 100 to a destination.

[0028] The autonomous driving control unit 130 is also connected to the user authentication device 180 and is therefore able to confirm whether an operation is being carried out by an authorized user who is entitled to drive the vehicle 100.

[0029] The autonomous driving control unit 130 is also connected to the user interface control unit 190 and is therefore able to communicate information to the user 21 regarding autonomous driving and information and messages from the infrastructure facility 300 and the like, and to receive a response from the user 21.

[0030] The map information management device 150 has functions for storing the detailed map information required for movement in the infrastructure facility management area 301 and which is acquired by the infrastructure facility 300 via the vehicle-side communication device 110 and the autonomous driving control unit 130, and for providing the autonomous driving control unit 130 with detailed map information relating to the surroundings of the vehicle 100 and the direction of travel of the vehicle 100 in response to a request from the autonomous driving control unit 130.

[0031] Referring to Fig. Section 2 describes how the state of the autonomous vehicle control unit 130 changes according to the embodiment of the present invention. The vehicle 100 performs authentication processing with the infrastructure device 300. During a period in which no encrypted communication with the infrastructure device 300 is established, the autonomous vehicle control unit 130 is in the state "Control by the infrastructure device blocked" S1. When the vehicle 100 performs authentication with the infrastructure device 300 so that encrypted communication can be carried out through communication between the vehicle-side communication device 110 and the infrastructure-side communication device 310, and when the infrastructure device 300 has a function for controlling the vehicle 100, the state changes to a state "Confirmation of user intent" S2.

[0032] In state "Confirmation of User Intent" S2, user 21 is informed that infrastructure facility 300 is capable of controlling vehicle 100, and it is checked whether user 21 is willing to allow control by infrastructure facility 300. If user 21 does not allow control, the state transitions to state "Control by Infrastructure Blocked" S1.

[0033] If user 21 selects "Allow" in state "User Intent Confirmation" S2 and the user authentication device 180 confirms that an authorized user is in vehicle 100, the state changes to state "Security Confirmation A" (S3). The state change from state "User Intent Confirmation" S2 does not occur if it is not confirmed that an authorized user is in the vehicle.

[0034] If the user authentication device 180, using the user terminal 400, determines whether an authorized user is in the vehicle, this determination is made by checking whether the user terminal 400 is in the vehicle. If biometric authentication is used instead of the user terminal 400, an authorized user is determined if the driver has remained in the driver's seat after the previous authentication. Even if a seated user is detected, the presence of even a single undetected period of occupancy results in a determination that it is unknown whether an authorized user is in the driver's seat.If an operation requiring user authentication is performed in a state where a user 21 is detected in the seat, but it is unknown whether an authorized user is in the driver's seat, a request for re-authentication is issued to user 21 via the touchscreen display 600 and acoustically, and after successful authentication, it is determined that an authorized user is in the vehicle.

[0035] If user 21 exits vehicle 100 in the "User Intention Confirmation" state (S2) without having selected the "Reject" or "Allow" option in the "User Intention Confirmation" state (S2), the state transitions to the "Safety Confirmation B" state (S4). If user 21 re-enters vehicle 100 in the "Safety Confirmation B" state (S4), the state reverts to the "User Intention Confirmation" state (S2).

[0036] When, in the “Security Confirmation A” (S3) state, all occupants have exited the vehicle and a locking operation is performed for the vehicle 100 (an operation such as touching a specific location near the door button of the vehicle 100 while carrying the user terminal 400, or a locking operation with biometric authentication such as touching the fingerprint authentication point) or the parking button 430 is pressed on the user terminal 400, the doors of the vehicle 100 are locked, the security in the vicinity of the vehicle 100 is confirmed, and then the state transitions to a “Control by Infrastructure Permitted” state S5.

[0037] When, in state “Security Confirmation B” (S4), all occupants have exited the vehicle, the information is transmitted via the user authentication device 180 that the parking button on the user terminal 400 has been pressed, and the security in the vicinity of the vehicle 100 is confirmed, the state transitions to state “Control by Infrastructure Authorized” (S5). That is, based on the activation of the parking button 430 on the user terminal 400, which corresponds to the key of the vehicle 100, it is determined that the user 21 has authorized the control of the vehicle 100 by the infrastructure device 300.

[0038] In state “Security Confirmation B” (S4), user 21 can perform a locking operation on vehicle 100 (an operation such as touching a specific spot near the vehicle 100’s door button while carrying the user terminal 400, or a locking operation with biometric authentication such as touching the fingerprint authentication point) without knowing that the infrastructure facility 300 is requesting authorization to control vehicle 100. Therefore, vehicle 100 issues a warning to user 21, audibly, via a flashing warning light, and similar means. If it is subsequently detected that the locking operation is being performed again after a longer period (approximately 2 seconds) and the security in the vicinity of vehicle 100 has been successfully confirmed, the state transitions to state “Control Authorized by Infrastructure” (S5).

[0039] In state S5, "Control by infrastructure permitted", the vehicle 100 moves according to an instruction based on encrypted communication with the infrastructure unit 300. This means that the autonomous driving control unit 130 issues an instruction to the vehicle control unit 210 to operate the vehicle 100 according to an instruction entered by the infrastructure unit 300 via the vehicle's communication device 110.

[0040] The state "Infrastructure control allowed" S5 transitions to the state "Infrastructure control blocked" S1 when vehicle 100 leaves the infrastructure facility management area 301. The transition to the state "Infrastructure control blocked" S1 also occurs if there is a possibility of a security issue resulting from the repeated reception, within one second, of anomalies in communication with infrastructure facility 300, and if it is determined that an anomaly has occurred on the part of infrastructure facility 300, indicated by an instruction to leave the parking facility. If the door is not locked, or if user 21 is in the vehicle, the instruction from infrastructure facility 300 to vehicle 100 is temporarily blocked, even in the state "Infrastructure control allowed" S5.

[0041] When biometric authentication is used without the use of the user terminal device 400, authentication at a time when authentication is required may, in addition to fingerprint authentication, include iris recognition by a camera, finger vein authentication, and the like, which involves direct contact with the sensor.

[0042] Next, a procedure for storing vehicle 100 will be described with reference to Fig. 3 to 9 described. Fig. Figure 3 represents the movement of vehicle 100 in the infrastructure facility management area 301. Fig. 4 represents a communication protocol for the infrastructure facility 300 to detect the vehicle 100 and establish initial communication when the vehicle 100 enters the infrastructure facility management area 301. Fig. 5 represents a communication protocol for establishing secure communication between the infrastructure facility 300 and the vehicle 100 through encryption. Fig. 6 represents a communication protocol between the vehicle 100, the user terminal 400 and the infrastructure facility 300 after secure communication has been established, until the vehicle 100 is parked at one of the parking spaces 51. Fig. Figure 7 shows an example of the content displayed on the interactive control panel 600 when the vehicle 100 confirms whether the user 21 is ready to allow control by the infrastructure facility 300. Fig. Figure 8 shows an example of the content displayed on the interactive control panel 600 when the user 21 of the vehicle 100 selects a service offered by the infrastructure facility 300. Fig. Figure 9 represents an example of the user terminal device 400.

[0043] When vehicle 100 passes through entrance 11, it enters infrastructure facility management area 301.

[0044] The information required by the infrastructure facility 300 for communication with each individual vehicle 100 is provided by the Fig. The communication protocol shown in Figure 4 is used between the infrastructure facility 300 and the vehicle 100. A communication medium such as dedicated near-field communication is used for this communication, enabling differentiated communication with vehicles 100 even in a state where no information has yet been exchanged between the vehicles 100 and the infrastructure facility 300. By differentiating each vehicle 100, the infrastructure facility 300 can then select each vehicle 100 in the infrastructure facility management area 301 and issue an instruction to the vehicle 100.

[0045] When the vehicle passes through entrance 11, a parking ticket is issued if required. This parking ticket contains information needed to identify the target vehicle when vehicle 100 is called upon exiting the parking facility (vehicle identification code assigned by infrastructure facility 300). Issuance of the parking ticket is unnecessary if the user 21 of vehicle 100 can record the information required to call vehicle 100 onto a device such as the user terminal 400, which they carry with them when exiting vehicle 100. Furthermore, issuance of the parking ticket is unnecessary if the call operation for vehicle 100 can be initiated by accessing vehicle 100 via a smartphone or similar device carried by user 21, and if the information required to call vehicle 100 can be recorded by vehicle 100.

[0046] In the communication protocol that is in Fig. As shown in Figure 4, after receiving the message "Change means of communication" S903, vehicle 100 establishes a communication path using the means of communication specified in the received content and also checks whether the security of the communication path can be guaranteed at that time. Infrastructure facility 300 is notified of the result of the establishment of the communication path by a response "Change means of communication" S904.

[0047] To change the communication method to a wireless LAN and establish secure encrypted communication, a communication protocol is used, for example, as described in Fig. 5 shown, to exchange the information required for encrypted communication.

[0048] After the communication protocol of Fig. Once step 4 has ended, vehicle 100 moves to a stop 15 in infrastructure facility management area 301 based on a drive activation by user 21 of vehicle 100. Furthermore, the Fig. The communication protocol shown in section 6 is initiated, and information is transmitted up to a response “List of additional services received” S922 before user 21 exits vehicle 100.

[0049] The assigned vehicle identification ID S915 is used to transmit a vehicle identification code, which is used by the infrastructure facility 300 to manage the vehicle 100, along with a fault detection code to the vehicle 100.

[0050] Upon receiving the vehicle identification code, vehicle 100 stores it if there are no errors in the vehicle identification code. If an error is detected, the transmission is repeated by sending a retransmission request from vehicle 100 to infrastructure facility 300 until a predetermined number of times has been reached.

[0051] If the vehicle identification code (VIN), which can be stored in the vehicle by the user terminal 400, is received correctly, the vehicle 100 sends a "Save VIN" request S981 to the user terminal 400, along with the VIN and its fault detection code. If the VIN is error-free, the user terminal 400 stores it as a valid VIN. If a fault is detected, the transmission is repeated by sending a retransmission request to the vehicle 100 until a predetermined number of times has been reached. After the successful completion of the storage processing, the user terminal 400 sends a "Save VIN" response S982 to the vehicle.

[0052] When the response “Save vehicle identification ID” S982 is received from the user terminal 400, or when no communication is made with the user terminal 400, the vehicle 100 sends a response “Receive vehicle identification ID” S916 to the infrastructure facility 300 after receiving the assigned vehicle identification ID S915.

[0053] Using the vehicle identification code stored in the user terminal 400, the infrastructure facility 300 can identify the vehicle 100 as the vehicle to be removed when, during removal, a user terminal contact point 770 of the payment terminal 700 of the infrastructure facility 300 is touched by the user terminal 400. This means that the issuance of the parking ticket by the infrastructure facility 300 to identify the vehicle to be removed and the receipt of the parking ticket by the user 21 are no longer necessary, thus increasing convenience during the storage process.

[0054] If the vehicle identification code stored in the user terminal 400 is used to call the vehicle during the outsourcing process, there is a risk that third parties could intercept the code and call the vehicle. However, even in this case, unlocking the vehicle 100 can be prevented by the vehicle 100's authentication function, which is used when a person attempts to enter the vehicle. To avoid unnecessary movement of the vehicle 100, secure encrypted communication is preferred for the request "Save vehicle identification ID" S981 and the response "Save vehicle identification ID" S982. Furthermore, encrypted communication should also be used for near-field communication with the user terminal 400, which occurs when the payment terminal 700 is touched.When the vehicle identification code is written from vehicle 100 to user terminal 400, the communication range is limited to an area within the vehicle. Furthermore, near-field communication (NFC) is used when the payment terminal 700 is touched. Therefore, if encrypted communication is used, simple encryption with a low security level can be employed for user terminal 400 to simplify the process. In this case, however, it must be ensured that billing for the use of infrastructure facility 300 is not automatic.

[0055] Following communication regarding the vehicle identification code, the infrastructure facility 300 transmits detailed internal infrastructure map information S917, along with the detailed map information of the infrastructure facility management area 301, to the vehicle 100. This information is stored and referenced in the map information management device 150 of the vehicle 100 when the vehicle 100 moves within the infrastructure facility management area 301 via the function of the autonomous driving control unit 130.

[0056] After the proper receipt of the detailed internal infrastructure map information S917, vehicle 100 sends a response "Detailed internal infrastructure map received" S918 to infrastructure facility 300. If an anomaly has occurred in the communication, a retransmission request is sent to infrastructure facility 300, and the information retrieval is repeated until a predetermined number of times has been reached.

[0057] Next, infrastructure facility 300 sends a list of available ancillary services S921 to vehicle 100. After successfully receiving the list, vehicle 100 sends a response "List of ancillary services received" S922 to infrastructure facility 300. If an anomaly occurred in the communication, a retransmission request is sent to infrastructure facility 300, and the information retrieval is repeated until a predetermined number of times has been reached.

[0058] When communication up to S922 is completed, the state transitions to the "User Intent Confirmation" state S2, and based on the information acquired by the infrastructure unit 300 via the vehicle-side communication device 110, the autonomous driving control unit 130 displays a message and a selection screen on the interactive control panel 600 via the user interface control unit 190, as shown in Fig. Figure 7 is shown. On this screen, the user 21 of vehicle 100 can see that the infrastructure facility 300 is requesting authorization to control vehicle 100, and also the additional services offered by the infrastructure facility 300.

[0059] If the user 21 of the vehicle 100 selects a “Reject” button 621 for the message displayed on the interactive control panel 600, the autonomous driving controller 130 returns to the “Control blocked by infrastructure” state S1, and the control of the vehicle 100 by the infrastructure facility 300 is deactivated.

[0060] When user 21 selects the "Allow" button 622, the state transitions to "Security Confirmation A" after the autonomous driving controller 130 confirms, by checking whether the user terminal 400 is in the vehicle (S3), that the selection was made by an authorized user. If it cannot be confirmed that the operation was performed by an authorized user, user 21 is prompted with a message such as "Place user terminal in vehicle" to perform an operation required for user authentication, and the state is maintained as "Confirmation of User Intent" state S2.

[0061] When the user 21 of the vehicle 100 selects a button “Allow (use optional service)” 630, the autonomous driving control unit 130 displays a message on the interactive control panel 600, as described in Fig. 8 is shown to prompt user 21 to select an optional service after it has been confirmed that the selection was made by the authorized user.

[0062] If user 21 selects a "Back" button 669 on the options selection screen, the screen returns to the state in which the previous screen is displayed (screen as shown in Fig. 7 shown).

[0063] If the user 21 selects a usage option such as a "Charge" button 650 and a "Car Wash" button 651 in the options selection screen and then selects a "Selection Completed" button 600, the autonomous driving control unit 130 enters the "Safety Confirmation A" (S3) state.

[0064] If user 21 exits vehicle 100 before the operation for the in Fig. 6 and Fig. Once the 8 messages shown are completed, the autonomous driving control unit 130 enters the "Safety Confirmation B" state (S4). When the user 21 gets back into the vehicle 100 in this state, the autonomous driving control unit 130 returns to the "Confirmation of User Intention" state (S2) and prompts the user 21 to continue operating the interactive control panel.

[0065] When the autonomous driving controller 130 is notified in the “Safety Confirmation A” (S3) state that the door is being locked by a direct operation on the vehicle 100, such as by the user 21 touching a specific part of the vehicle 100, the autonomous driving controller 130 uses a seat sensor and the like to confirm that all occupants have exited the vehicle 100, and uses an external sensor 170 to confirm that there is no obstacle in the vicinity of the vehicle 100, and then enters the “Control by Infrastructure Permitted” state S5.

[0066] Even if the "Park" button 430 of the control terminal 400 is pressed while the autonomous driving controller 130 is in the "Safety Confirmation A" (S3) state, the door of the vehicle 100 will lock, and the autonomous driving controller 130 will be notified that the door locking was successfully performed using the "Park" button 430. The autonomous driving controller 130 then uses a seat sensor and similar sensors to confirm that all occupants have exited the vehicle 100, and uses the external sensor 170 to confirm that there are no obstacles in the vicinity of the vehicle 100, and then enters the "Control by Infrastructure Permitted" (S5) state.

[0067] The autonomous driving control unit 130 also locks the doors of the vehicle 100 if the "Lock" button 410 of the user terminal 400 is pressed in the "Safety Confirmation A" (S3) state. When the autonomous driving control unit 130 is notified that the door locking has been successfully performed in response to the "Lock" button 410, the autonomous driving control unit 130 prompts the user to press the "Park" button 430 by instructing other control units in the vehicle 100 to alert the user audibly, with hazard warning lights, etc., and waits for the "Park" button 430 to be pressed.When the autonomous driving control unit 130 is notified that the "Lock" button 430 has been pressed, the autonomous driving control unit 130 confirms that all occupants have exited the vehicle 100 and uses the external sensor 170 to confirm that there is no obstacle in the vicinity of the vehicle 100, and then enters the "Control by Infrastructure Allowed" state S5.

[0068] When the autonomous driving controller 130, in the "Safety Confirmation B" state (S4), is notified that the door is being locked by a direct operation on the vehicle 100, such as by user 21 touching a specific point on the vehicle 100, the autonomous driving controller 130 instructs the other controllers in the vehicle 100 to alert the driver audibly, with hazard warning lights, and the like. If another long door locking operation is then performed by a direct operation on the vehicle 100, and the autonomous driving controller 130 is notified that the operation has been completed, the autonomous driving controller 130 confirms that all occupants have exited the vehicle 100 and uses the external sensor 170 to confirm that there are no obstacles in the vicinity of the vehicle 100, and then transitions to the "Control by Infrastructure Permitted" state (S5).

[0069] The operations performed when the “Park” button 430 and the “Lock” button 410 of the operating terminal 400 are pressed while the autonomous driving control unit 130 is in the “Safety Confirmation B” (S4) state are the same as in the “Safety Confirmation A” (S3) state.

[0070] The state “Safety Confirmation B” (S4) is a state in which it has not yet been confirmed whether user 21 has authorized the infrastructure unit 300 to control vehicle 100. Therefore, to transition to the state “Control by Infrastructure Unit Authorized” (S5), it must at least be confirmed that the operation was performed by an authorized user. If this confirmation fails, the transition to the state “Control by Infrastructure Unit Authorized” (S5) does not occur. To confirm the authorized user's intent, the message regarding locking and parking sent to the autonomous driving controller 130 includes information about whether the operation was accompanied by user authentication.If the operation is performed on the control device 400, which corresponds to a key, this operation itself serves as proof that an authorized user performed the operation. Direct operation on the vehicle 100, such as touching a specific point on the vehicle 100, must be confirmed by verifying the presence of the user device 400 near the location of the operation or by biometric authentication during the operation. However, even if authentication of an authorized user has been performed, an operation such as touching a specific point on the vehicle 100 cannot definitively determine whether the user 21 has authorized the control of the vehicle 100 by the infrastructure device 300. Therefore, a measure such as requesting an operation for re-verification is necessary.

[0071] If, during the attempt to transition to state S5, it cannot be confirmed that all occupants have exited the vehicle, the autonomous driving controller 130 will in any case instruct the other controllers in the vehicle 100 to alert the occupants audibly and with hazard warning lights to prompt them to exit, without transitioning to state S5. Furthermore, the doors will not lock, even if a door locking operation has been performed (regardless of whether it is a direct operation such as touching a specific point on the vehicle 100 or an operation using the user terminal 400), if one of the doors of the vehicle 100 is not fully closed, or if the user terminal 400 is inside the vehicle, and the user 21 is alerted audibly or by hazard warning lights.

[0072] When the autonomous driving controller 130 enters the state "Control by infrastructure permitted" S5, the vehicle 100 sends a message "Driving instruction activated" S923 to the infrastructure unit 300. In response, the infrastructure unit 300 sends a reply "Driving instruction activated" S924 back to the vehicle 100. If the communication between the vehicle 100 and the infrastructure unit 300 is complete up to this point, the vehicle 100 can be controlled, that is, moved according to the instruction from the infrastructure unit 300.

[0073] When vehicle 100 sends a storage request S925 to infrastructure facility 300, after control by infrastructure facility 300 has been enabled, infrastructure facility 300 determines the parking space 51 where vehicle 100 is to be parked and roughly determines a route (the path to be used) to reach parking space 51. To move vehicle 100 based on this determination, infrastructure facility 300 sends a storage driving instruction S926, containing information about the route and the destination, to vehicle 100. Vehicle 100, having received the storage driving instruction S926, confirms that there is no anomaly in the communication, and then the autonomous driving controller 130 instructs the vehicle control unit 210 to operate vehicle 100 according to the instruction.If an anomaly in the communication is detected, a retransmission request is sent to infrastructure facility 300, and communication is retried a predetermined number of times.

[0074] After completion of the movement, by the function of the autonomous driving control unit 130, to the position specified in the storage driving instruction S926, the vehicle 100 sends a message “Storage movement completed” S927 to the infrastructure facility 300.

[0075] If an additional movement is required for parking, the infrastructure facility 300 sends another storage movement instruction S926 to the vehicle 100. This means that the storage movement instruction S926 and the message "Storage movement completed" S927 in the communication protocol are repeated as needed. The storage instruction, which can be issued multiple times, has the advantage that, in a situation where several vehicles 100 are being moved simultaneously within the infrastructure facility management area 301, it is possible to update the route of each vehicle 100 according to the congestion tendency of the route, which is caused by the current movement status of the vehicles 100 and similar factors.For example, if vehicle 100 is moved to parking space 51, a driving instruction can first be issued up to a point before a reversing movement, and the storage driving instruction S926 for the movement to parking space 51 can then be issued again at a time that takes into account the movement of the other vehicles.

[0076] When vehicle 100 is moving, the autonomous driving controller 130 uses the external sensor 170 to check the vehicle's surroundings and continuously monitor for hazards such as obstacles. If a hazard is detected, braking, stopping, minor route changes, and similar actions are performed to avoid the hazard. Hazard avoidance operations are carried out with priority over instructions from the infrastructure facility 300.

[0077] When user 21 uses an optional service offered by infrastructure facility 300, infrastructure facility 300 allocates the space and equipment used by the optional service. If the allocated service is immediately available upon arrival, infrastructure facility 300 determines a route to a service location (e.g., a charging bay 65 in the case of a charging service and a car wash 60 in the case of a car wash service), instead of the normal parking space 51, and issues an instruction to vehicle 100.

[0078] When the movement required to park vehicle 100 is completed, the infrastructure facility 300 sends a message “Storage sequence complete” S928 to vehicle 100, and in response, vehicle 100 sends a reply “Storage sequence complete” S929 to the infrastructure facility 300.

[0079] After receiving the response "Storage sequence complete" S929, vehicle 100 puts the powertrain 230 into a parked state, shuts off the power source 220 (disconnecting the main power supply to the drive circuit in the case of a motor), and puts the brake system 240 into the parked state. Vehicle 100 then waits for further instructions from the infrastructure unit 300.

[0080] It should be noted that this in Fig. The communication protocol shown in Figure 5 can be implemented to establish secure communication between the vehicle 100 and the infrastructure facility 300 via dedicated near-field communication. In this case, the communication protocol is used from the message "Change communication means" S903 to the response "Change communication means" S904, as shown in Figure 5. Fig. 4 shown, after completion of the in Fig. The communication protocol shown in section 5 is implemented, whereby the information required for encrypted communication, such as a key used for encryption, is retained after a change in the means of communication.

[0081] In connection with the in Fig. 4 and Fig. 5 communication protocol shown between vehicle 100 and infrastructure facility 300 and the in Fig. The communication protocol shown in Figure 6 between the vehicle 100, the infrastructure facility 300 and the user terminal 400 is described below using the following: Fig. 10 a signal communication protocol within the vehicle 100 between the autonomous driving control unit 130, the user authentication device 180 and the vehicle-side communication device 110 is described.

[0082] When the vehicle 100 communicates with the infrastructure equipment 300 and the user terminal 400, the infrastructure equipment 300 communicates with the vehicle-side communication device 110, which is installed in the vehicle 100, and the user terminal 400 communicates with the user authentication device 180, which is installed in the vehicle 100.

[0083] When the infrastructure facility 300 communicates with the vehicle 100, the infrastructure facility 310 uses the infrastructure-side communication device 310.

[0084] When the infrastructure device 300 receives a "Vehicle present" signal S900 sent by the vehicle-side communication device 110 and sends an acknowledgment "Compatible for autonomous driving with external connection" S901 to the vehicle-side communication device 110, the vehicle-side communication device 110, which received the acknowledgment "Compatible for autonomous driving with external connection" S901, sends an acknowledgment "External connection function" S501 to the autonomous driving control unit 130. The autonomous driving control unit 130, which received the acknowledgment "External connection function" S501, sends a response "External connection function" S502 to the vehicle-side communication device 110, containing information about a connection function outside the vehicle 100.The vehicle-side communication device 110 sends a response “Compatible for autonomous driving with external connection” S902 to the infrastructure facility 300, which contains information that corresponds to the information received about the external connection function.

[0085] If, based on the content of the response "Compatible for autonomous driving with external connection," it is determined that the infrastructure device 300 has a function for externally controlling the movement of the vehicle 100, the infrastructure device 300 sends the message "Change means of communication" S903 to the vehicle-side communication device 110 to establish the communication path on which the infrastructure device 300 issues instructions for the movement of the vehicle 100. This message also serves as a request to obtain authorization to control the vehicle 100. It includes the type of communication path after the change and the information required for communication. For example, if a wireless LAN is used, this information includes a frequency band to be used, an SSID required for using the wireless LAN, and authentication information for the wireless LAN connection.

[0086] Upon receiving the message "Change communication means" S903, the vehicle-side communication device 110 confirms whether a communication link has been established using the specified communication means. After confirmation, the vehicle-side communication device 110 sends the response "Change communication means" S904 to the infrastructure unit 300. If the connection using the specified communication path fails, information indicating the failure is sent to the infrastructure unit 300. If an alternative communication means is available, the message "Change communication means" S903 is sent again to the vehicle 100 using this communication means, and the attempt to establish a communication path is repeated.If no means of communication is available, the infrastructure unit 300 cancels the acquisition of authorization to control the vehicle 100 and notifies the vehicle-side communication unit 110 of this decision. Upon receiving this message, the vehicle-side communication unit 110 notifies the autonomous driving control unit 130 of the decision, and the autonomous driving control unit 130 cancels the provision of authorization to the infrastructure unit 300 to control the vehicle 100.

[0087] Once the communication path for instructions to move vehicle 100 through infrastructure facility 300 has been established, the communication will be routed to the Fig. The communication protocol shown in Figure 5 is implemented to establish secure communication between the vehicle-side communication device 110 and the infrastructure device 300. In this protocol, the vehicle-side communication device 110, using an infrastructure certificate S907, receives an infrastructure-side electronic certificate, verifies the certificate's content against pre-recorded information, and, if necessary, sends a request to an external device with a reliable communication function to confirm the authorization of the infrastructure device 300 to communicate securely. By confirming the authorization of the infrastructure device 300, it is possible to prevent anyone other than the infrastructure device 300 from gaining the authority to control the vehicle 100 by impersonating the infrastructure device 300.

[0088] Once secure communication is ensured, encrypted communication with authentication, i.e., the secure communication means, will be used for subsequent communication between the vehicle 100 and the infrastructure facility 300 until the vehicle 100 is removed from the infrastructure facility 300.

[0089] Once secure communication is established, the vehicle-side communication device 110, after first receiving the assigned vehicle identification ID S915 from the infrastructure device 300, sends a vehicle identification ID (S511), which contains the vehicle identification code in its label, to the autonomous driving control unit 130. Upon receiving the vehicle identification ID (S911), the autonomous driving control unit 130 stores the vehicle identification code and uses a "store vehicle identification ID" request S571 to transmit this information to the user authentication device 180.

[0090] Upon receiving the request "Save vehicle identification ID" S571, the user authentication device 180 stores the vehicle identification code and also communicates with the user terminal 400 to store the vehicle identification code in the user terminal 400. The user authentication device 180 then confirms that the storage in the user terminal 400 is complete and sends a message "Save vehicle identification ID complete" S572 to the autonomous driving control unit 130 in response to the request "Save vehicle identification ID" S571.

[0091] In a configuration without the user terminal 400, the user authentication device 180 simply stores the vehicle identification code and then sends the message "Storing of vehicle identification ID complete" S572 to the autonomous driving control unit 130.

[0092] Upon receiving the message "Storing of vehicle identification ID completed" S572, the autonomous driving control unit 130 sends the message "Storing of vehicle identification ID completed" S512 to the vehicle-side communication device 110 in response to the vehicle identification ID (S511). Upon receiving the message "Storing of vehicle identification ID completed" S512, the vehicle-side communication device 110 sends a response "Vehicle identification ID received" S916 to the infrastructure unit 300.

[0093] Upon receiving the detailed internal infrastructure map information S917 from the infrastructure device 300, which contains the map information required for movement within the infrastructure facility management area 301, the vehicle-side communication device 110 uses the detailed internal infrastructure map S513 to transmit the information to the autonomous driving controller 130. Upon receiving the information, the autonomous driving controller 130 sends it to the map information management device 150, which manages the information as map data required for movement within the infrastructure.

[0094] After confirmation that the map information is stored in the map information management device 150, the autonomous driving control unit 130 sends a response "Detailed map stored" S514 to the vehicle-side communication device 110 in response to the detailed internal infrastructure map S513. Upon receiving the response "Detailed map stored" S514, the vehicle-side communication device 110 sends a response "Detailed internal map received" S918 to the infrastructure device 300 in response to the detailed internal infrastructure map information S917.

[0095] Since the amount of data in the internal infrastructure map information can be large, the map information can be split and transmitted by repeatedly repeating the protocol from the sending of the detailed internal infrastructure map information S917 by the infrastructure device 300 until the receipt of the response "Detailed internal map received" S918. In this case, the communication protocol from the detailed internal infrastructure map S513 to the response "Detailed map saved" S514 can also be repeated between the vehicle-side communication device 110 and the autonomous driving control unit 130.The number of repetitions between the infrastructure facility 300 and the vehicle-side communication device 110 and the number of repetitions between the vehicle-side communication device 100 and the autonomous driving control unit 130 do not necessarily have to match when the splitting and integration of packets and the like is carried out in the vehicle-side communication device 110.

[0096] After the detailed map information from the infrastructure facility management area 301 has been transmitted, the infrastructure facility 300 sends the list of available additional services S921 to the vehicle-side communication device 110. This list contains information about additional services offered by the infrastructure facility 300. Upon receiving the list of available additional services S921, the vehicle-side communication device 110 sends the information as additional service information S515 to the autonomous driving control unit 130.

[0097] At this stage, the autonomous driving controller 130 queries the user 21 via the user interface controller 190 and the interactive control panel 600 to ask whether they accept the control of the vehicle 100 by the infrastructure facility 300. Additionally, a "Confirm User" request S573 is sent to the user authentication device 180 to verify whether the user 21 is an authorized user of the vehicle 100, and a "Confirm User" response S574 is received as confirmation.

[0098] If a user terminal device 400 is used, the user authentication device 180 confirms that user 21 is an authorized user when it detects that the user terminal device 400 is in the vehicle, and if biometric authentication is used, it checks whether user 21 has exited the vehicle after the authentication has been verified, and if there is an indication that user 21 has exited, they are prompted to perform an authentication operation to re-authenticate.

[0099] By confirming whether user 21 accepts the control of vehicle 100 by infrastructure facility 300 at this stage, it can be determined whether additional services selectable by user 21 are to be provided, which require that vehicle 100 be movable by infrastructure facility 300.

[0100] If an optional service is available, the user (21) is asked via the user interface control unit (190) and the interactive control panel (600) whether they wish to use the service. A message "Service Information Received" (S516), containing information about a service selected by the user, is then sent to the vehicle communication device (110). Upon receiving the message "Service Information Received" (S516), the vehicle communication device (110) sends a reply, "List of Optional Services Received" (S922), containing information about the service selected by the user (21), to the infrastructure unit (300).

[0101] Based on the information about the service selected by user 21, which is contained in the response “List of additional services received” S922, the infrastructure facility 300 assigns the usage time of a location and equipment in the infrastructure facility, assigns a parking space and creates a plan for the movement of vehicle 100 in the infrastructure facility management area 301, so that the movement of vehicle 100 is controlled based on the plan and a current availability of the service facility.

[0102] If user 21, in a state where user 21 has confirmed that they are authorizing the infrastructure unit 300 to control vehicle 100, or in conjunction with an operation corresponding to this authorization, performs a parking operation on vehicle 100, the user authentication device 180 sends a storage request signal S575 to the autonomous driving controller 130. This signal contains information about whether user 21 has performed the operation corresponding to authorizing the infrastructure unit 300 to control vehicle 100.

[0103] In state “Safety Confirmation A” (S3), the autonomous driving control unit 130 transitions to state “Control by Infrastructure Approved” S5 upon receiving the storage request signal S575, regardless of whether authentication processing has been completed for user 21, who performed the parking operation. In state “Safety Confirmation B” (S4), the autonomous driving control unit 130 transitions to state “Control by Infrastructure Approved” S5 only if user 21, who performed the parking operation, has been successfully authenticated as an authorized user, it has been confirmed that no occupant is in the vehicle, and the safety of the vehicle's surroundings has been confirmed. A message “Driving Instruction Approved” S522 is then sent to the vehicle's communication device 110.Upon receiving the message “Driving instruction approved” S522, the vehicle-side communication device 110 sends a storage request S925 to the infrastructure facility 300.

[0104] The infrastructure unit 300, which has received the storage request S925, initiates a driving instruction required for storing vehicle 100. Specifically, a storage driving instruction S926, containing information about the destination and the route, is transmitted. The vehicle-side communication device 110, which has received the storage driving instruction S926, sends information about the destination and the route as driving instruction information S531 to the autonomous driving control unit 130. The autonomous driving control unit 130, having received the driving instruction information S531, instructs the vehicle control unit 210 to move vehicle 100 according to the instruction.The system uses map information, vehicle position information, and external sensor information to control the vehicle's speed, including adjusting the route and stopping to ensure safety with the highest priority. For example, if a hazard is detected that cannot be avoided, the vehicle will stop moving until the hazard has passed.

[0105] When the movement of vehicle 100 to the specified location is complete, the autonomous driving control unit 130 sends a "Movement completed" message S532, containing information about the current position at the end of the movement, to the vehicle-side communication device 110. The vehicle-side communication device 110, which has received the "Movement completed" message S532, sends a "Storage movement completed" message S927, containing position information at the end of the movement, to the infrastructure facility 300.

[0106] The infrastructure unit 300, having received the message "Storage movement completed" S927, issues another storage movement instruction S926 if further movement is required. The protocol from the transmission of the storage movement instruction S926 to the receipt of the message "Storage movement completed" S927 is repeated by the infrastructure unit 300 as needed. By repeating the protocol, communication with a large amount of information can be spread out, and the infrastructure unit 300 can actively change the route and destination according to the movement status of the vehicle 100.

[0107] After the completion of the movement of vehicle 100 to the final destination of the parking operation has been confirmed, the infrastructure unit 300 sends a message "Storage sequence completed" S928 to the vehicle-side communication device 110. Upon receiving the message "Storage sequence completed" S928, the vehicle-side communication device 110 sends a message "Storage sequence completed" S526 to the autonomous driving control unit 130. Upon receiving the message "Storage sequence completed" S526, the autonomous driving control unit 130 instructs the vehicle control unit 210 to put the powertrain 230 into a state corresponding to parking, switches off the power source 220 (disconnecting the main power supply to the drive circuit in the case of a motor), and puts the braking system 240 into a state corresponding to parking.

[0108] After confirmation that vehicle 100 is parked, the autonomous driving controller 130 sends a confirmation message "Storage complete" S527 to the vehicle-side communication device 110 and waits to receive a request for further driving instructions. The vehicle-side communication device, having received the confirmation message "Storage complete" S527, sends a response "Storage sequence complete" S929 to the infrastructure device 300. Upon receiving the response "Storage sequence complete" S929, the infrastructure device 300 determines that the parking processing for vehicle 100 is complete.

[0109] It should be noted that the vehicle-side communication device 110 and the infrastructure facility 300 store information such as an encryption code required for secure communication until the vehicle 100 is removed from the infrastructure facility 300.

[0110] An operation to move vehicle 100, whose control authorization was acquired by infrastructure facility 300, from its parked state in accordance with the instructions of infrastructure facility 300, is referred to as follows: Fig. 11 and Fig. 12 described. Fig. 11 represents an operation to move vehicle 100 from parking space 51 to another parking space 51 in infrastructure facility management area 301, and Fig. Section 12 describes the communication protocol between the vehicle 100 and the infrastructure facility 300 for such an operation. As during storage, the vehicle 100 uses its on-board communication device 110 to communicate with the infrastructure facility 300, and the on-board communication device 110 communicates appropriately with the autonomous driving controller 130 so that the autonomous driving controller 130 instructs the vehicle control unit 210 to operate the vehicle 100 in accordance with the instruction from the infrastructure facility 300. During this operation, the vehicle 100 is operated with the highest priority for safety, as during storage.

[0111] Vehicle 100, while parked, first receives a "Start Movement" request (S951) from infrastructure unit 300 and begins preparations to move it. Specifically, if power source 200 is off, power source 220 is activated. If power source 220 is successfully activated, vehicle 100 sends a "Start Movement" response (S952) to infrastructure unit 300. If the activation of power source 220 fails, information indicating the failure is sent to infrastructure unit 300, and both infrastructure unit 300 and vehicle 100 abort the movement.

[0112] The infrastructure unit 300, which received the response "Start movement" S952, sends a driving instruction S953 containing information about the route and destination. The vehicle 100, which received the driving instruction S953, confirms that there is no anomaly in the communication, and then the autonomous driving controller 130 instructs the vehicle control unit 210 to operate the vehicle 100 according to the instruction. During the initial movement, the braking system 240 is moved from the park state, and the movement is initiated after the powertrain 230 has been switched to a moving state. If an anomaly in the communication is detected, a retransmission request is sent to the infrastructure unit 300, and communication is retried a predetermined number of times.

[0113] After completion of the movement, by the function of the autonomous driving control unit 130, to the position specified in the driving instruction S953, the vehicle 100 sends a message “Movement completed” S954 to the infrastructure facility 300.

[0114] If an additional movement is required, the infrastructure unit 300 sends another movement instruction S953 to the vehicle 100. That is, the movement instruction S953 and the message "Movement completed" S954 in the communication protocol are repeated as often as necessary.

[0115] When the movement of vehicle 100 is complete, infrastructure unit 300 sends a message "Movement sequence complete" S955 to vehicle 100. Vehicle 100 then puts the drivetrain 230 into a state corresponding to parking, switches off the power source 220 (disconnecting the main power supply to the drive circuit in the case of a motor), and puts the braking system 240 into the parking state. Vehicle 100 then sends a response "Movement sequence complete" S956 to infrastructure unit 300. Afterward, vehicle 100 waits for further instructions from infrastructure unit 300.

[0116] An operation to outsource vehicle 100, whose tax authorization was acquired by infrastructure facility 300, in accordance with the instruction of infrastructure facility 300, using the payment terminal 700 of infrastructure facility 300, is referred to as Fig. 13, Fig. 14 and Fig. 15 described.

[0117] Fig. 13 represents an operation to move vehicle 100 from parking space 51 to stop 15 in infrastructure facility management area 301, and Fig. Section 14 describes the communication protocol between the vehicle 100, the infrastructure facility 300, and the user terminal 400 for such an operation. In the configuration without a user terminal 400, other means, such as reading the parking ticket, are used for the "Vehicle Identification ID" message S990 to transmit the information to the infrastructure facility 300 identifying the vehicle 100 as a vehicle to be offloaded.

[0118] During the outsourcing operation, as during storage, vehicle 100 uses its on-board communication device 110 to communicate with the infrastructure facility 300. The on-board communication device 110 then communicates appropriately with the autonomous driving control unit 130, enabling the autonomous driving control unit 130 to instruct the vehicle control unit 210 to operate vehicle 100 in accordance with the instruction from the infrastructure facility 300. As during storage, vehicle 100 is operated with the highest safety priority.

[0119] When user 21 has vehicle 100 removed using payment terminal 700, user 21 inserts the parking ticket into a parking ticket insertion slot 720 of payment terminal 700 or touches a user terminal contact section 770 with user terminal 400 to transmit the vehicle identification code of the vehicle 100 being removed to infrastructure facility 300. Touching the payment terminal 700 with the user terminal 400 to transmit the vehicle identification code to infrastructure facility 300 corresponds to the message "Vehicle Identification ID" S990 in Fig. 14. Based on the vehicle identification code obtained from the parking ticket or user terminal 400, the payment terminal 700 makes a request to the infrastructure management device 330 to determine a payment fee based on the parking time and any optional services used, and displays the payment amount on the display 710 of the payment terminal to request payment of the fee from the user 21.

[0120] If the user pays the fare using a banknote slot 750 and / or a coin slot 755, and if the infrastructure facility 300 is authorized to control the vehicle 100, the infrastructure facility 300 will instruct the user 21 to wait at stop 15 while the infrastructure facility 300 calls the vehicle 100. If the infrastructure facility 300 is not authorized to control the vehicle 100, the user 21 will be instructed to go directly to the vehicle. If, for any reason, the infrastructure facility 300 is unable to move the vehicle 100, control of which was acquired upon storage, the user 21 will be notified of the vehicle 100's position in the infrastructure facility management area 301, with a required message being issued and confirmation being sent to the user 21.For example, if the vehicle is being charged, a confirmation is given as to whether the charging process should be canceled. If the car wash is still in progress, a message is displayed indicating how long it will take until the vehicle is ready for pickup. However, if the vehicle's position is unknown, the last detected location may be displayed, or the location may not be displayed at all.

[0121] If there are multiple stops (15), the payment terminal 700 checks which of the stops (15) user 21 wants to use. If the payment terminal 700 is near a specific stop (15), its location is displayed, highlighted by magnification or color, so that user 21 can easily select the stop (15).

[0122] Once the payment is complete, the information indicating its completion is transmitted from the payment terminal 700 to the infrastructure management device 330 in the infrastructure facility 300. The infrastructure management device 330 then plans the route from the parking space to stop 15 based on the parking position of vehicle 100, which corresponds to the vehicle identification code, and issues an instruction to vehicle 100 via the infrastructure-side communication device 310.

[0123] To move vehicle 100 to stop 15, the infrastructure facility first sends a "Start moving" request S935 to vehicle 100. Vehicle 100, while parked, receives the "Start moving" request S936 from infrastructure facility 300 and begins preparations to move it. This involves activating power source 220. If power source 220 is successfully activated, vehicle 100 sends a "Start moving" response S936 to infrastructure facility 300. If the activation of power source 220 fails, information indicating the failure is sent to infrastructure facility 300, and both infrastructure facility 300 and vehicle 100 abort the movement of vehicle 100.

[0124] The infrastructure unit 300, which received the response "Start relocation" S936, sends a relocation driving instruction S937 containing information about the route and destination. The vehicle 100, which received the relocation driving instruction S937, confirms that there is no anomaly in the communication and then instructs the autonomous driving controller 130 to the vehicle control unit 210 to operate the vehicle 100 according to the instruction. At the start of the initial movement, the braking system 240 is moved from the parked state, and the powertrain 230 is put into a moving state. As with the storage operation, the movement is carried out using the external sensor 170 in such a way that the safety of the instruction is given the highest priority by the infrastructure unit 300, and necessary hazard prevention measures are taken.If an anomaly in the communication is detected, a retransmission request is sent to infrastructure facility 300, and communication is retried a predetermined number of times.

[0125] After the autonomous vehicle control unit 130 has completed the movement to the position specified in the outsourcing driving instruction S937, the vehicle 100 sends a message “Outsourcing movement completed” S938 to the infrastructure facility 300.

[0126] If an additional movement is required, the infrastructure facility 300 sends another relocation movement instruction S937 to the vehicle 100. This means that the relocation movement instruction S953 and the message "Movement completed" S954 in the communication protocol are repeated as often as necessary.

[0127] When the movement of vehicle 100 is complete, the infrastructure facility 300 sends a message “Outsourcing sequence complete” S939 to vehicle 100, and vehicle 100 sends a response “Outsourcing sequence complete” S940 to the infrastructure facility 300.

[0128] After the response “Outsourcing sequence completed” S940 is transmitted, vehicle 100 puts the powertrain 230 and the brake system 240 into park mode and waits for user 21 to unlock the door and enter vehicle 100.

[0129] When the user 12, in a vehicle with user terminal 400, performs the door unlocking of the vehicle 100 by a direct operation by touching a specific point on the vehicle 100, a request “User terminal response” S992 is sent to the user terminal 400, and the door unlocking is performed when the user terminal 400 returns a response “User terminal response” S993.

[0130] When user 21 presses the "Unlock" button 420 of user terminal 400, the user terminal's "User Terminal Response" request S992 is omitted, and instead of the user terminal's "User Terminal Response" S993, user terminal 400 sends a door unlocking request signal to vehicle 100. Vehicle 100 then unlocks the doors upon receiving the signal.

[0131] In a vehicle 100 with biometric authentication for door unlocking, a biometric sensor is provided at a point where the door must be touched to unlock it. The sensor then determines whether the user 21 is an authorized user, and if the user's authorization is confirmed, the door is unlocked.

[0132] Once the doors are unlocked, vehicle 100 sends a "Unlock" message S943 to infrastructure facility 300, and infrastructure facility 300 sends a "Unlock" reply S944 back to vehicle 100. If, after vehicle 100 arrives at stop 15, infrastructure facility 300 does not receive a "Unlock" message S943 for a period of time exceeding a certain threshold, it may move vehicle 100 back to parking space 51 in the same manner as described in the communication protocol for storing vehicle 100. This prevents vehicle 100 from remaining at stop 15 for an extended period.

[0133] Once user 21 has entered the vehicle, user 21 drives vehicle 100 in the normal manner. When user 21 is inside vehicle 100, the autonomous driving controller 130, even in the state "Control by infrastructure facility permitted" S5, does not receive any driving instructions from the infrastructure facility 130.

[0134] When user 21 drives vehicle 100 to exit 12, infrastructure facility 300 detects vehicle 100 using a camera or similar device installed at exit 12 and sends a message "Exit" S945 to the vehicle 100 identified by the detection. Upon receiving the "Exit" message S945, vehicle 100 sends a message "Departure" S946 to infrastructure facility 300. Upon receiving the "Departure" message S946, infrastructure facility 300 sends a reply to the "Departure" message S947, sets exit 12 to a state in which vehicle 100 can pass through, and invalidates the vehicle identification code of vehicle 100 managed by infrastructure facility 300.Upon receiving the response to the message "Departure" S947, the vehicle 100 puts the autonomous driving controller 130 into the state "Control locked by infrastructure" S1 and invalidates the vehicle identification code stored within the vehicle 100 in the autonomous driving controller 130 and in the user authentication device 180. If the user terminal 400 has a function for storing a vehicle identification code, a request to invalidate the vehicle identification ID S996 is also sent to the user terminal 400.

[0135] Upon receiving the request to invalidate the vehicle identification ID S996, the user terminal 400 invalidates the vehicle identification code stored in the user terminal 400 and outputs a response “Vehicle identification ID invalid” S997.

[0136] Upon receiving the response to the message “Departure” S947, vehicle 100 displays a message on the interactive control panel 600 indicating that vehicle 100 has left infrastructure facility 300, and a message indicating that control by infrastructure facility 300 has been deactivated, thus notifying user 21 of the departure from infrastructure facility 300.

[0137] If the response to the "Departure" message is not received, the vehicle 100, at a time after sending the "Departure" message S946, when the departure is detected by the infrastructure facility management area 301, performs processing that is equivalent to what would have happened if the response to the "Departure" message S947 had been received. The departure from the infrastructure facility management area 301 is detected based on the relationship between the detailed map information of the infrastructure facility management area 301 and the vehicle position detected by the vehicle position detection device 160, or the detection of passage through exit 12 by the external sensor 170.

[0138] At exit 12, the infrastructure facility 300 can use dedicated near-field communication (NFC) instead of detecting vehicle 100 with a camera or similar device. In this case, the infrastructure facility 300 sends the message "Exit" S945 to vehicle 100 using dedicated NFC at exit 12, and vehicle 100 sends the message "Exit" S946 to the infrastructure facility 300 using dedicated NFC. In response, the infrastructure facility 300 transmits a reply to the message "Exit" S947 using dedicated NFC, sets exit 12 to a state that allows passage, and invalidates the vehicle identification code (VIN) corresponding to vehicle 100.As in the case where no dedicated near field communication is used at exit 12, the vehicle 100 causes the message to appear on the interactive control panel 600 and invalidates all vehicle identification codes in the devices in the vehicle 100 as well as in the user terminal 400.

[0139] When the vehicle 100 is relocated, an optional user terminal 490 can be used instead of the user terminal 400. This optional terminal has the capability to communicate with the vehicle 100 even from a location outside the vehicle 100. The communication protocol in this case is described with reference to Fig. 16. The optional user terminal 490 can be a dedicated device or a smartphone, etc., in which a dedicated application is installed, provided that the information required for encrypted communication and authentication has been exchanged in advance with the vehicle-side communication device 110 of the vehicle 100. The optional user terminal 400 and the vehicle 100 communicate with each other using encryption with authentication.

[0140] If the offloading is performed using the optional user terminal 490, the optional user terminal 490 first transmits a remote offloading request S985 to the vehicle 100.

[0141] Vehicle 100, which has received the remote relocation request S985, confirms the validity of the received content and sends the relocation request S930, which contains the vehicle identification code, to infrastructure facility 300 if there is no problem.

[0142] Upon receiving the outsourcing request S930, the infrastructure facility 300 identifies the vehicle to be outsourced using the vehicle identification code, calculates the fee, and sends a payment request S931 along with fee details to the vehicle 100. After receiving the payment request S931, the vehicle 100 sends a payment confirmation S986 with the fee details to the optional user terminal 490.

[0143] If multiple stops 15 exist in infrastructure facility management area 301, a list of the available stops 15 can be included in the payment request S931 and the payment confirmation S986, along with the fare details. Additional information, such as the congestion level and the estimated time until vehicle 100 arrives, can be added for each stop 15.

[0144] Upon receiving payment confirmation S986, the vehicle displays the payment information to user 21, prompts the user for confirmation, and, if necessary, initiates the entry of credit card information, etc. The credit card information, etc., may also have been pre-stored and used in the optional user terminal 490. If a list of stops 15 is available, user 21 will also be prompted to select a stop 15.

[0145] User 21 checks the payment details, if necessary operates the optional user terminal 490 to select stop 15, and accepts the payment data, whereupon the optional user terminal 490 sends a response “Payment Authorization” S987 to vehicle 100, which contains information required for payment such as credit card information and, if applicable, information about the selected stop 15.

[0146] Upon receiving payment authorization information S987, vehicle 100 sends payment processing information S932 to infrastructure unit 300. This information contains the necessary payment details, such as credit card information and, if applicable, information about the selected stop 15. Upon receiving payment processing information S932, infrastructure unit 300 processes the payment. After confirming the completion of the payment, infrastructure unit 300 sends a "Payment Completed" response S933 to vehicle 100. Upon receiving the "Payment Completed" response S933, vehicle 100 sends a "Payment Completed" message S988 to the optional user terminal 490.

[0147] Upon receiving the message “Payment completed” S988, the optional user terminal 490 notifies user 21 that the outsourcing process is in progress.

[0148] After completion of the payment processing communication protocol, infrastructure facility 300 sends a "Start Outsourcing" request S935 to vehicle 100. Upon receiving the "Start Outsourcing" request S935, vehicle 100 begins preparing to move, just as in the case where user 21 performs the outsourcing operation with payment terminal 700. When vehicle 100 is ready to move, a "Start Outsourcing" message S989 is sent to the optional user terminal 490. Furthermore, in response to the "Start Outsourcing" request S935, a "Start Outsourcing" response S936 is sent to infrastructure facility 300. Then, as in the case where user 21 performs the outsourcing operation with payment terminal 700, the following occurs: Fig. 14. Communication shown was carried out according to the outsourcing driving instruction S937.

[0149] Upon receiving the message “Start offloading” S989, the optional user terminal 490 displays information to notify user 21 that the offloading operation of vehicle 100 has begun.

[0150] If the dedicated near-field radio with a communication function required for payment processing is used at exit 12 to perform payment processing at exit 12, the communication in the communication protocol from the payment request S931 to the "Payment Completed" message S988 can be used only to select stop 15 and can also be omitted if there is only one stop 15. In this case, however, the infrastructure facility 300 must confirm during storage whether the payment processing can be performed by vehicle 100 using the dedicated near-field radio and also check whether the payment processing can be omitted based on the result of the confirmation, through the communication from the payment request S931 to the "Payment Completed" message S988.

[0151] By using the optional user terminal 490, user 21 does not need to go to the payment terminal 700. When calling vehicle 100, user 21 can also request the vehicle's dispatch in advance, taking into account the time required to reach stop 15.

[0152] Even when using the optional user terminal 490, the optional user terminal 490 communicates with the vehicle 100 and communicates via the vehicle 100 with the infrastructure facility 300. Therefore, it is possible to design the optional user terminal 490 for the vehicle 100 independently of the function and communication means of the infrastructure facility 300.

[0153] If communication between vehicle 100 and infrastructure facility 300 is interrupted due to an anomaly in communication via a wireless LAN or similar, the following will occur: Fig. The communication protocol shown in Figure 5 is reimplemented to ensure security. In this case, the vehicle identification code is transmitted from vehicle 100 to infrastructure facility 300 as soon as a secure communication path is established, and the correlation of the information required for communication between infrastructure facility 300 and vehicle 100 is updated.

[0154] In order to prevent unauthorized control of the vehicle 100 by interrupting the communication between devices in the vehicle 100, such as the vehicle-side communication device 110, the autonomous driving control unit 130 and the user authentication device 180, in addition to secure communication between the vehicle 100 and the infrastructure facility 300, the user terminal 400 and the optional user terminal 490, encrypted communication with the authentication function must also be used for communication between the devices within the vehicle 100 in order to ensure secure communication channels for these types of communication.

[0155] Fig. Figure 17 represents an example of the information transmitted at entrance 11 by dedicated shortwave radio between vehicle 100 and infrastructure facility 300. Fig. Section 17 is a comparison of the communication label and the content contained in command parameters, which are parameters transmitted through the communication. In actual communication, the information needed to identify a communication source and destination (such as a physical connection target and software processing information transmitted through the communication) is followed by information indicating which communication corresponds to which communication label. Furthermore, a command parameter and a check value are present to detect anomalies such as corruption of the communication content.

[0156] A "Vehicle present" signal S900 is used by vehicle 100 to inform infrastructure facility 300 of the presence of a communication partner and does not contain any command parameters, as infrastructure facility 300 detects the partner via dedicated near-field radio. Nevertheless, information about the communication source contained in the "Vehicle present" signal S900 is used as communication target information by infrastructure facility 300 to communicate with vehicle 100 via dedicated near-field radio.

[0157] The confirmation “Compatible for autonomous driving with external connectivity” S901 has a command parameter containing information about a list of connectivity functions for autonomous driving provided by the infrastructure facility 300. By checking this command parameter, the vehicle 100 can determine whether the infrastructure facility 300 has a function to control the vehicle 100. The response “Compatible for autonomous driving with external connectivity” S902 is a response from the vehicle 100 to the confirmation “Compatible for autonomous driving with external connectivity” S901 and has a command parameter containing information about a list of functions connected to autonomous vehicles, corresponding to the vehicle 100, which was extracted from the list of functions provided by the infrastructure facility 300.The infrastructure facility 300 can confirm whether the vehicle 100 has a function to be controllable by the infrastructure facility 300 after receiving the response "Compatible for autonomous driving with external connection" S902.

[0158] The message "Change communication means" S903 is sent from infrastructure facility 300 to vehicle 100 to change the communication means between infrastructure facility 300 and vehicle 100. It contains information to identify the communication means to be used after the change, information needed to establish the communication means, and information to confirm whether the connection destination after the change is a communication destination belonging to the same infrastructure facility 300. For example, when changing from a dedicated near-field radio to a wireless LAN, the message contains a communication means identifier that identifies the wireless LAN user, the wireless LAN SSID, authentication information required to connect to a wireless LAN access point, and the like.The message also contains a public key for public-key encryption, which is included in the infrastructure certificate S907, received by infrastructure facility 300 when the means of communication is changed, to confirm whether the connection destination after the change of the means of communication is a communication destination belonging to the same infrastructure facility 300.

[0159] A "Change communication means" response S904 is sent from vehicle 100 to infrastructure facility 300 to inform it whether or not vehicle 100 accepts the change of communication means specified by infrastructure facility 300, and contains information indicating whether the change is accepted. Vehicle 100 accepts the change only if the communication path has been successfully established using the communication means specified by infrastructure facility 300. If vehicle 100 does not accept the change, infrastructure facility 300 sends an alternative, supported communication means by means of a "Change communication means" message S903, and vehicle 100 returns a "Change communication means" response S904 in response to the message.This process is repeated as needed until a means of communication is found that is supported by both the infrastructure facility 300 and the vehicle 100. It should be noted that the "Change means of communication" message S903 can specify a variety of means of communication supported by the infrastructure facility 300, and the vehicle 100 can select the usable means of communication from among them, thus reducing the number of repetitions of the "Change means of communication" message S903 and the "Change means of communication" response S904. If several means of communication supported by the infrastructure facility 300 are included in the "Change means of communication" message S903, then all means of communication supported by the infrastructure facility 300 can be included.Furthermore, the communication means to be included can be changed each time the message “Change communication means” S903 and the response “Change communication means” S904 are exchanged, such that the communication means preferred by infrastructure facility 300 appears in an order corresponding to the first message “Change communication means” S903.

[0160] The content of the communication, which is recorded in the communication protocol (in Fig. 5. Protocol shown) is used until secure communication is established after a change of communication means, with reference to Fig. 18, Fig. 19 and Fig. 20 described.

[0161] Fig. Section 18 represents a configuration of a communication packet. Header information 821 contains information for identifying the communication source and destination, as well as management information for communication status and the like. The information for identifying the communication destination and source includes not only information for identifying a physical device, but also information necessary for identifying the software running on the respective devices. Furthermore, the structure of the communication packet is hierarchical according to the communication medium used, and headers can be arranged in the order required for the respective hierarchy. For example, if a TCP / IP protocol is used in an IEEE 802.11-compliant wireless LAN, an IEEE 802.11 header follows the header that specifies the synchronization and modulation scheme added to the physical layer.11. Media Access Control (MAC) frame header. This header specifies an IP protocol. This is followed by an IP header specifying a TCP protocol. Finally, a TCP header is included.

[0162] Command code 825 is information used to identify which of the communication labels corresponds to the communication packet in the communication between vehicle 100 and infrastructure facility 300. Command parameter 826 is a parameter referenced during the processing of the communication packet. Packet acknowledgment information 822 is a cyclic redundancy check (CRC) code used to verify whether the packet is corrupted.

[0163] Fig. 19 is a comparison of the communication name and the information contained in a command parameter of a packet transmitted through communication.

[0164] The message "Supported Security Means" S905 is sent by vehicle 100 to inform infrastructure facility 300 about the available encryption methods. It contains a list of encryption methods that can be used as command parameters on the vehicle 100 side, as well as information about a pseudorandom number generated in vehicle 100. Each encryption method listed includes a public-key encryption algorithm and its key length, a common-key encryption algorithm and its key length, and a hash function algorithm 895 for generating a message authentication code 882.

[0165] The message “Selected Security Means” S906 is sent by the infrastructure facility 300 to inform the vehicle 100 about a currently used encryption method and includes a command parameter containing an encryption method selected by the infrastructure facility 300 from the list of encryption methods in the message “Supported Security Means” S905, as well as information about a pseudorandom number generated in the infrastructure facility 300.

[0166] The infrastructure certificate S907 is used by infrastructure facility 300 to transmit information certifying that infrastructure facility 300 is an authorized entity to vehicle 100. It includes a command parameter containing certificate information regarding infrastructure facility 300 (known as an electronic certificate). This electronic certificate contains the public key of infrastructure facility 300, which is required by vehicle 100 and infrastructure facility 300 to use public-key encryption, information about infrastructure facility 300 (name of the operating company and information identifying the facility on the internet), its validity period, and information about the certification authority that signed the certificate.The electronic signature (as a result of encrypting a hash value of the certificate content, which is generated using public-key encryption by a hash function with a secret key of the certification authority) is attached to this content.

[0167] The certification authority is a third party, distinct from the infrastructure facility (IFF) 300, that verifies the legitimacy of the IFF 300 and the content described in the electronic certificate. If no issues are found, the hash value of the IFF 300's certificate is encrypted using the certification authority's secret key, and the resulting value is provided to the IFF 300.

[0168] A public key of a trusted certification authority is pre-registered in the vehicle 100 upon delivery ex-works or similar, and a check is performed to see if the certification authority of a signatory included in the electronic certificate of the infrastructure facility 300 is registered. If it is not registered, it is determined that the infrastructure facility 300 is not an authorized facility, and the infrastructure facility 300 is notified that communication via this communication channel is not permitted but is rejected.

[0169] If the certification authority of the signatory contained in the electronic certificate is among the trusted certification authorities, the hash value of the electronic certificate of infrastructure facility 300 is decrypted using the public key corresponding to that certification authority. The decryption result is compared with the hash value of the electronic certificate of infrastructure facility 300 calculated in vehicle 100. If there is a match, infrastructure facility 300 is determined to be a valid entity, and communication continues. If there is a mismatch, infrastructure facility 300 is determined to be a non-valid entity, and infrastructure facility 300 is notified that communication on this communication channel is not permitted but is rejected.

[0170] If the electronic certificate is found to be valid, it is determined whether the public key of Infrastructure Facility 300 matches the public key of Infrastructure Facility 300 received in the "Means of Communication Change" message S903, to confirm that Infrastructure Facility 300 has not been replaced by another facility before and after the change of means of communication. If a replacement is detected, it is determined that Infrastructure Facility 300 is not the original communication partner, and Infrastructure Facility 300 is notified that communication using this means of communication is unacceptable and is therefore rejected.

[0171] By verifying the electronic certificate of the infrastructure facility 300, as described above, it is possible to prevent the vehicle 100 from connecting to a device that pretends to be the infrastructure facility 300 in order to control the vehicle 100.

[0172] A request "Provide information to generate a shared key" (S908) is sent to complete all information transfers required for encrypted communication between infrastructure facility 300 and vehicle 100, and to request from vehicle 100 the provision of information necessary to generate a shared key for encrypted shared-key communication. This request does not contain any command parameters.

[0173] The information for generating a shared key, S909, is used to transmit information about a random number for generating a shared master key, on the basis of which the shared key is generated, from vehicle 100 to infrastructure facility 300. This random number is generated separately in vehicle 100 from the random number transmitted with the message "Supported Security Means" S905 and is encrypted using public-key encryption with the public key contained in the electronic certificate of infrastructure facility 300. The resulting random number is then sent to infrastructure facility 300. Infrastructure facility 300 decrypts the encrypted random number received from vehicle 100 using a secret key corresponding to the public key.

[0174] Vehicle 100 and infrastructure facility 300 generate a common master key using the same algorithm based on the random number from vehicle 100, which is jointly owned by the message "Supported security means" S905, the random number from infrastructure facility 300, which is jointly owned by the message "Selected security means" S906, and the random number, which is jointly owned using public-key encryption by the information to generate a common key S909.

[0175] Using the shared master key, vehicle 100 and infrastructure facility 300 generate a shared key (shared key 1) used for encryption processing 890, a shared key (shared key 2) passed to the hash authentication function 895 to generate a message authentication code 882 for encrypted communication data 855, and an initial value required in encryption processing 890. This results in two shared key sets 885, one set for communication from vehicle 100 to infrastructure facility 300 and one set for communication from infrastructure facility 300 to vehicle 100. Vehicle 100 and infrastructure facility 300 jointly possess these shared keys and the initial value because they generate them using the same algorithm.The four common keys and the two initial values ​​are generated by repeating the calculation with a hash function or the like with the common master key to produce a long bit sequence and to extract different sections or perform other similar operations.

[0176] The message "Vehicle-side preparation of the shared key completed" S910 confirms that the shared key set 885 has been successfully prepared, with vehicle 100 transmitting the information for generating a shared key S909. It also notifies the user that communication transmitted by vehicle 100 will henceforth be encrypted using the shared key set 885, which is used for transmission from vehicle 100 to infrastructure facility 300. When vehicle 100 sends the message "Vehicle-side preparation of the shared key completed" S910, it resets a sequence number 886, used for encrypted transmission from vehicle 100, to 0.After receiving the message "Vehicle-side preparation of the common key completed" S910, the infrastructure facility 300 sets the sequence number 886, which is used to receive a package from vehicle 100 containing the key. Fig. The format shown in 20 is used, reverting to 0.

[0177] A confirmation code “Vehicle-side communication prepared” S911 is sent by vehicle 100 to notify infrastructure facility 300 that the protocol for conducting encrypted communication is complete. A command parameter contains a hash value of the content obtained by combining the content of the message “Supported security means” S905 up to the message “Vehicle-side preparation of shared key complete” S910 and the shared master key, each considered as a bit sequence. This message is transmitted after the message “Vehicle-side preparation of shared key complete” S910 has been sent. Therefore, encrypted communication data 855 and the message authentication code 882 are generated using the shared key set 885, which is used for communication from vehicle 100 to infrastructure facility 300, and with which in Fig. The communication packet format shown in section 20 is transmitted.

[0178] In the package format, which is in Fig. As shown in Figure 20, the header information 821 and the packet acknowledgment information 822 are the same as in the packet format of Fig. 18. The encrypted communication data 855 and the message authentication code 882 are data obtained by encrypting a bit sequence that is the result of a combination of the vehicle identification code 861, the sequence number 886, the command code 825, and the command parameter 826, each of which is considered a bit sequence. The sequence number 886 is a value that is used every time a packet containing the Fig. The format shown in 20 is transmitted, incremented by 1, and the message authentication code 882 is a bit sequence to confirm the validity of the encrypted communication data 855 and is generated during the encryption process. If the in Fig. When the packet shown in Figure 20 is received, the receiving end combines the encrypted communication data 855 and the shared key to calculate the hash value for authentication, which corresponds to the communication direction of the shared key set 885, each considered as a bit sequence. Then, it is checked whether the message authentication code 882 calculated with the hash authentication function 895 matches the received message authentication code 882. Furthermore, a value for checking the sequence number 886 in the decryption result of the encrypted communication data 855 is compared with a value for checking the sequence number 886 counted on the receiving end to verify that the values ​​match and confirm that the communication data is normal.The value used to check the sequence number 886 counted on the receiver side is incremented by 1 after receiving a normal packet to prepare for the next reception.

[0179] Upon receiving the confirmation code "Vehicle-side communication prepared" S911, the infrastructure facility 300 uses the shared key set 885, which is used for communication from the vehicle 100 to the infrastructure facility 300, to generate the message authentication code 882 for the received encrypted communication data 855 using the hash authentication function 895. It then compares the message authentication code 882 with the received message authentication code 882 to confirm the validity of the encrypted communication data 855. Furthermore, the encrypted communication data 855 is decrypted using the same shared key set 885 to confirm that the sequence number 886 is 0.The hash value contained in the decryption result's command parameter is then compared with the hash value calculated by infrastructure facility 300 of the content obtained by combining the content of the communication "Supported Security Means" S905 up to the message "Vehicle-side preparation of the shared key completed" S910 and the shared master key, each considered as a bit sequence. If a match is confirmed in all comparisons, it is determined that the communication will proceed normally. If an anomaly is detected, vehicle 100 is notified of the anomaly detection, and the [unclear] is [unclear] Fig. The communication protocol shown in section 5 is repeated a specific number of times from the beginning. If normal communication cannot be established, communication with the communication device is terminated, even if the protocol has been repeated a certain number of times.

[0180] The message "Infrastructure-side preparation of shared key complete" S912 serves to confirm that the shared key set 885 has been successfully prepared by infrastructure facility 300 and is used to indicate that communication sent by infrastructure facility 300 will henceforth be encrypted with the shared key set 885, which is used for transmission from infrastructure facility 300 to vehicle 100. When infrastructure facility 300 sends the message "Infrastructure-side preparation of shared key complete" S912, it resets the sequence number 886, which is used for encrypted transmission, to 0. Upon receiving the message "Infrastructure-side preparation of shared key complete" S912, vehicle 100 resets the sequence number 886, which is used for receiving a packet containing the key set 885. Fig. The format shown in 20 is used by the infrastructure facility 300, reverting to 0.

[0181] An acknowledgment code “Infrastructure-side communication prepared” S913 is sent by infrastructure facility 300 to notify vehicle 100 that the protocol for conducting encrypted communication is complete. A command parameter contains a hash value of the content obtained by combining the content of the message “Supported security means” S905 up to the message “Infrastructure-side preparation of the shared key completed” S912 and the shared master key, each considered as a bit sequence.Since this communication is transmitted after the message "Infrastructure-side preparation of the shared key completed" S912 has been transmitted, the encrypted communication data 855 and the message authentication code 882 are generated using the shared key set 885, which is used for communication from the infrastructure facility 300 to the vehicle 100, and with the one in . Fig. The communication packet format shown in section 20 is transmitted.

[0182] Upon receiving the confirmation code "Infrastructure-side communication prepared" S913, vehicle 100 uses the shared key set 885, which is used for communication from infrastructure facility 300 to vehicle 100, to generate the message authentication code 882 for the received encrypted communication data 855 using the hash authentication function 895. The message authentication code 882 is then compared with the received message authentication code 882 to confirm the validity of the encrypted communication data 855. Furthermore, the encrypted communication data 855 is decrypted using the same shared key set 885 to confirm that the sequence number 886 is 0.The hash value contained in the decryption result's command parameter is then compared with the hash value calculated in vehicle 100 of the content obtained by combining the content of the message "Supported Security Means" S905 up to the message "Infrastructure-side preparation of the shared key completed" S912 and the shared master key, each considered as a bit sequence. If a match is confirmed in all comparisons, it is determined that communication will proceed normally. If an anomaly is detected, infrastructure facility 300 is notified of the anomaly detection, and the process is carried out accordingly. Fig. The communication protocol shown in step 5 is repeated a certain number of times from the beginning. If communication cannot be carried out normally, even after the protocol has been repeated a certain number of times, communication with the communication device is terminated.

[0183] It should be noted that the processing to change the communication path on the vehicle 100 side can be carried out by the vehicle-side communication device 110, and the vehicle-side communication device 110 can transmit information required for the state change of the autonomous driving control unit 130 based on the processing result. Alternatively, the processing can be carried out by: transmitting, by the vehicle-side communication device 110, information required to determine whether the change of the communication path is permissible for the autonomous driving control unit 130; determining, by the autonomous driving control unit 130, whether the change of the communication path is permitted; transmitting a determination result to the vehicle-side communication device 110; and changing, by the vehicle-side communication device 110, the communication path based on the content of the result.If, after the change, no means of communication is available, it is determined in any case that it is not possible to control the vehicle 100 in accordance with an instruction from the infrastructure facility 300, and the autonomous driving control unit 130 therefore enters the state “control by the infrastructure blocked” S1.

[0184] If communication is successfully completed up to the confirmation code "Infrastructure-side communication prepared" S913, communication will then be initiated with the Fig. The communication packet format shown in section 20 is carried out. That is, all communication between vehicle 100 and infrastructure facility 300, which is shown in Fig. 6, Fig. 12, Fig. 14 and Fig. As shown in 16, it is combined with the one in Fig. The communication package format shown in the 20 images was used.

[0185] The process for generating the encrypted communication data 855 and the message authentication code 882 is described with reference to Fig. 21 described.

[0186] First, the communication data 860 is generated by combining the vehicle identification code 861, the sequence number 886, the command code 825, and the command parameter 826, each considered as a bit sequence. Then, the common keys for encryption processing 890 contained in the common key set 885 and the initial value are used to encrypt the communication data 860, generating encrypted communication data 855. Next, the encrypted communication data 855 and the common key contained in the common key set 885 for generating the message authentication code 882, each considered as a bit sequence, are combined, and the hash function used for authentication (hash authentication function 895) is used to generate the message authentication code 882.

[0187] Operation of vehicle 100 in the event that vehicle 100 is at risk of leaving infrastructure management area 301 due to an anomaly in infrastructure facility 300, in vehicle 100, or in the communication between the two, when infrastructure facility 300 instructs vehicle 100 to move, is referred to Fig. 22 and Fig. 23 described. Such a phenomenon can occur not only in the event of a malfunction of the infrastructure facility 300 or the vehicle 100, but also in the event of a security problem in the communication.

[0188] Fig. 22 represents an example in which vehicle 100 is about to leave infrastructure facility management area 301.

[0189] Vehicle 100 moves towards exit 12 without user 21, in accordance with an instruction from infrastructure facility 300. Based on detailed map information from infrastructure facility management area 301, area information on a public road segment of the map pre-stored by vehicle 100, information from external sensor 170, and similar data, vehicle 100 determines whether such movement has occurred. Using the pre-stored map and the information from external sensor 170, vehicle 100 can determine, even if an anomaly exists in the information from infrastructure facility management area 301, that vehicle 100 is about to leave infrastructure facility management area 301.

[0190] When it is detected that vehicle 100 is instructed by infrastructure facility 300 to move out of the infrastructure facility management area 301, vehicle 100 sends information indicating an abnormal condition, along with its current position, to infrastructure facility 300 and requests a new movement instruction S953 (the storage movement instruction S926 during storage and the retrieval movement instruction S937 during retrieval). If the newly received movement instruction S953 directs movement within the management area of ​​infrastructure facility 300, the vehicle follows this instruction.

[0191] If the newly received driving instruction S953 is a movement outside the infrastructure facility management area 301, the permission to follow the instruction of infrastructure facility 300 is revoked. The vehicle 100 then checks the location of an emergency parking space 55, which is indicated on the detailed map of the infrastructure facility management area 301, determines the route or detour to this point using the autonomous driving control unit 130, and drives to this location. During this process, the vehicle 100 moves with the highest priority for safety, using the external sensor 170.

[0192] If, during this movement, the map previously stored by vehicle 100 or the external sensor 170 detects movement outside the infrastructure facility management area 301 again, it is determined that there is an anomaly in the detailed map of the infrastructure facility management area 301, resulting in the position of parking space 55 being unknown. Therefore, an emergency measure is taken to park the vehicle at the roadside.

[0193] This function is applicable not only to the case where vehicle 100 is about to leave the management area of ​​infrastructure facility 300, but also to a case where, despite an unexpected obstacle on a path of infrastructure facility 301, parking lot 51 or the like, the vehicle continues to follow the instructions of infrastructure facility 300, and to a case where vehicle 100 remains stationary for a longer period of time.

[0194] If vehicle 100 revokes permission to follow the instruction of infrastructure facility 300, vehicle 100 sends information indicating this revocation to infrastructure facility 300 or sends parking position information if vehicle 100 and infrastructure facility 300 can communicate with each other. This information is transmitted when user 21 uses payment terminal 700. When using the optional user terminal 490, the situation and parking position information is sent to the optional user terminal 490.

[0195] If vehicle 100 revokes permission to follow the instruction of infrastructure facility 300, user 21 goes directly to the location of vehicle 100, as indicated in the parking position information, as shown in Fig.23 is shown, and then the driver boards vehicle 100 to leave infrastructure facility 300. At exit 12, the driver contacts a manned management room via an intercom and then leaves the facility.

[0196] It should be noted that the configuration and protocol presented in the present embodiment are merely exemplary and that the communication packet configuration, encryption method, etc., can be modified as long as this does not impair the implementation of the functions. Furthermore, communication can be carried out by splitting the communication packet into a multitude of packets if this is necessary due to limitations such as the communication medium.

[0197] According to the embodiment described above, impersonation of the infrastructure device is made more difficult because the infrastructure device's electronic certificate is verified, thus preventing damage resulting from the takeover of control authority by a device not intended by the vehicle user. Furthermore, the vehicle authenticates the infrastructure device and then establishes encrypted communication with it to receive control instructions. This prevents the risk of the vehicle's control authority being taken over by a security attack from someone other than the infrastructure device.

[0198] Since the system verifies the user's authorization to operate the vehicle during the storage process, and the user then confirms whether or not to grant the infrastructure facility control, the user can confirm that the infrastructure facility should take control of the vehicle. This prevents the risk of the key being misused elsewhere, even if the infrastructure facility's secret key is stolen, thus preventing the vehicle's control from being stolen against the user's will. Furthermore, since the user also has the option to park the vehicle themselves at the infrastructure facility without granting control, they can choose between valet parking and regular parking.

[0199] When a wireless authentication device is used to authenticate authorized users during the authentication process between the infrastructure and the vehicle, the wireless authentication device only communicates with the vehicle. Therefore, a simple wireless authentication device that only performs near-field communication can be used. The confirmation of user intent when granting permission to control the vehicle to the infrastructure is handled by the vehicle's own processing, meaning the infrastructure is not involved. Consequently, the wireless authentication device can be omitted if the vehicle uses biometric authentication to authenticate the authorized user.

[0200] The vehicle identification information (VIN) is issued upon storage, and retrieval is performed using this VIN. This allows the vehicle to be easily located. However, since the VIN is temporary, this prevents unnecessary retrieval operations caused by misuse of the VIN due to information leaks.

[0201] The above embodiment can be expressed, for example, as follows.

[0202] When the infrastructure facility temporarily acquires the authorization to move the vehicle, it requests the vehicle to acquire the necessary control authorization. When the infrastructure facility initially issues a request to the vehicle, an electronic certificate is attached and transmitted. This certificate contains the infrastructure facility's public key (required for public-key encryption), information about the certification authority, and a signature.

[0203] A vehicle to which an infrastructure provider has issued a request for tax authorization confirms the validity of the infrastructure provider's electronic certificate using a public key from a trusted certification authority, such as a public key previously registered in a device within the vehicle. Upon confirmation that the infrastructure provider is authorized, the vehicle notifies its user of the receipt of the request.

[0204] Based on the presence status of the user's device, the vehicle confirms whether the user is an authorized user of the vehicle. The user then confirms whether they accept the request from the infrastructure facility. After the user's permission has been obtained, a request for temporary control authorization from the infrastructure facility is accepted, and the infrastructure facility is notified.

[0205] The communication required when the infrastructure unit controls the vehicle is encrypted using common-key encryption with authentication. The necessary shared key is generated by encrypting a random number generated on the vehicle's side using a public key from the infrastructure unit and transmitting it to the infrastructure unit. On the infrastructure side, the vehicle-generated random number is decrypted using a secret key that corresponds to the public key. Using this random number, which is jointly owned by the vehicle and the infrastructure unit, shared keys are generated both in the vehicle and in the infrastructure unit using the same algorithm.

[0206] When the vehicle is called for retrieval or similar purposes, the temporary identification information issued by the infrastructure facility during storage is pre-recorded in the vehicle, on the user's terminal device, or on the parking ticket. During retrieval, this vehicle identification information is presented to the infrastructure facility to request the vehicle's movement. Based on this request, the infrastructure facility issues an instruction to the vehicle and moves it to a target location. List of reference symbols 11 Entrance Exit 12 15 Stop 21 users (drivers) 51 parking spaces 55 emergency parking spaces 65 parking spaces with charging function 60 Car Wash Room 61 Car wash 100 vehicles 110 vehicle-side communication device 130 autonomous driving control unit 150 map information management device 160 Vehicle Position Detection Device 170 external sensor 180 User authentication device 190 User interface control unit 210 Vehicle control unit 220 Energy source 230 Powertrain 240 brake system 250 steering system 300 infrastructure facilities 301 Infrastructure Facility Management Area 310 infrastructure-side communication device 330 Infrastructure Management Device 350 barrier control unit 400 user terminals 410 Lock button (locking button) 420 “Unlock” button 430 “Park” button (Park button) 450 near-field radio antenna 600 interactive control panel 610 Main display area for messages 621 "Reject" button 622 “Allow” button 630 “Allow” button (use optional service)” 650 "Recharge" button 651 “Car Wash” button 659 unused buttons 660 Button “Selection complete” 669 "Back" button 700 payment terminal 710 Payment terminal display 720 Parking ticket insertion slot 750 banknote insertion slots 755 Coin slot 770 Contact area for user terminal device 821 Header Information 822 Package Confirmation Information 825 Command code 826 command parameters 855 encrypted communication data 860 communication data 861 Vehicle Identification Code 882 Message authentication code 885 common key set 886 Sequence number 890 Encryption processing 895 Hash authentication function S1 status “Control blocked by infrastructure facility” S2 state “Confirmation of user intent” S3 status “Security confirmation A” S4 status “Security confirmation B” S5 status “Control by infrastructure facility permitted” S501 Confirmation “External connection function” S502 response “External connection function” S511 Vehicle Identification ID S512 Vehicle identification ID storage complete S513 Detailed internal infrastructure map S514 Answer “Save detailed map” S515 Information about additional services S516 Response “Service information received” S522 message “Driving instruction approved” S523 Approval of the driving instructions completed S525 Storage instruction request S526 Storage sequence completed S527 Confirmation message “Storage completed” S531 Driving Instructions Information S532 Information “Movement completed” S571 Request “Save vehicle identification ID” S572 Response “Save vehicle identification ID complete” S573 Request “User Confirm” S574 Response “User Confirmation” S575 Storage request signal S900 Signal “Vehicle present” S901 Confirmation “Compatible for autonomous driving with external connection” S902 answer “Compatible for autonomous driving with external connection” S903 message “Change means of communication” S904 response “Change means of communication” S905 message “Supported security measures” S906 message “Selected security measure” S907 Infrastructure Certificate S908 requirement “Provide information for generating a common key” S909 Information on generating a common key S910 message “Vehicle-side preparation of the common key completed” S911 Confirmation code “Vehicle-side communication prepared” S912 message “Infrastructure-side preparation of the common key completed” S913 Confirmation code “Infrastructure-side communication prepared” S915 Assigned Vehicle Identification ID S916 response “Vehicle identification ID received” S917 Detailed internal infrastructure map information S918 response “Received detailed internal infrastructure map information” S921 List of available additional services S922 response “Received list of available additional services” S923 message “Driving instructions activated” S924 response “Driving instructions activated” S925 Storage request S926 Storage Driving Instructions S927 message "Storage movement completed" S928 message "Storage sequence completed" S929 response "Storage sequence complete" S930 relocation request S931 Payment Request S932 Payment processing information S933 response "Payment completed" S935 Request "Start outsourcing" S936 response “Start outsourcing” S937 Outsourcing Driving Instructions S938 message "Outsourcing movement completed" S939 message "Outsourcing sequence completed" S940 response "Outsourcing sequence complete" S943 message “Unlocking” S944 response “Unlocking” S945 message “Exit” S946 message “Departure” S947 Reply to message “Departure” S951 Request “Start movement” S952 response “Start movement” S953 Driving Instructions S954 message "Movement completed" S955 message "Movement sequence completed" S956 response “Movement sequence completed” S981 Request “Save vehicle identification ID” S982 Response “Save vehicle identification ID” S983 Storage Instructions S985 Remote Outsourcing Request S986 Payment Confirmation S987 Answer “Payment authorization” S988 message "Payment completed" S989 message “Start outsourcing” S990 message “Vehicle Identification ID” S992 requirement “User terminal response” S993 Response “User terminal response” S996 Request “Void vehicle identification ID” S997 Answer “Void vehicle identification ID”

Claims

[1] Control unit for controlling an autonomously driving vehicle (100), wherein the control unit (130) has a function to control a movement of the vehicle (100) according to instructions from an external system (300), wherein, when the function to control a movement of the vehicle (100) according to instructions from an external system (300) is activated, the control unit (130) recognizes the validity of the external system (300) by - communicates with the external system (300) and the vehicle (100) via a communication device, - recognizes that the vehicle, using content received via the communication means, has changed the communication means to a modified communication means through which the external system (300) gives instructions for the movement of the vehicle (100), - recognizes that encrypted communication has been established via the modified communication means with the external system (300) using information acquired during the change of the communication means and required for encryption, - recognizes that a user (21) of the vehicle (100) has authorized the movement of the vehicle (100) by the external system (300), and - recognizes that the user (21) who has authorized the movement of the vehicle (100) through the external system (300) is an authorized user of the vehicle (100). [2] Control unit according to claim 1, wherein the vehicle (100) has a function to switch between a communication means during the storage of the vehicle (100) and a communication means during the control of the movement of the vehicle (100), which is different from the communication means during storage, and the control unit (130) detects this switching process. [3] Control unit according to claim 1, further comprising a function to transmit, when a terminal device of the user (21) is operated, a request to the external system (300) on the basis of the communication content between the terminal device and the vehicle, which is necessary for the operation of the vehicle (100) according to the operating operation. [4] Control unit according to claim 1, further comprising a function to detect that a destination is outside a management area of ​​the external system (300) during movement in accordance with instructions from the external system (300), wherein the authorization to follow the external system (300) is revoked and the control unit (130) performs control of the autonomous movement to a location available for parking in the external system (300) if, despite an anomaly indication to the external system (300), a destination is specified that is outside the management area of ​​the external system (300). [5] Control unit according to claim 1, wherein biometric authentication is performed to authenticate the authorized user (21) and the performance of the biometric authentication is requested again when it is confirmed that an operation is being performed by the authorized user (21) after it has been detected that the authorized user (21) has left a driver's seat. [6] Autonomous vehicle comprising a function to control the movement of the vehicle (100) according to instructions from an external system (300), wherein, when the function to control the movement of the vehicle (100) according to instructions from an external system (300) is activated, the vehicle (100) checks the validity of the external system by - communicates with the external system (300) via a communication device, - using content received via the first means of communication, changes the means of communication to a modified means of communication through which the external system (300) gives instructions for the movement of the vehicle (100), - recognizes that encrypted communication has been established via the modified communication means with the external system (300) using information acquired during the change of the communication means and required for encryption, - recognizes that a user (21) of the vehicle has authorized a movement according to instructions from the external system (300), and - recognizes that the user (21) who has authorized the movement of the vehicle (100) through the external system (300) is an authorized user of the vehicle (100). [7] Vehicle according to claim 6, further comprising a function to switch between a communication means during the storage of the vehicle and a communication means during the control of the movement of the vehicle, which is different from the communication means during storage. [8] Vehicle according to claim 6, further comprising a function to transmit, when a terminal device of the user (21) is operated, a request to the external system based on the communication content between the terminal device and the vehicle (100) which is necessary for the operation of the vehicle (100) according to the operating operation. [9] Vehicle according to claim 6, further comprising a function to detect that a destination is outside a management area of ​​the external system (300) during movement in accordance with the instructions from the external system (300), wherein the authorization to follow the external system (300) is revoked and the vehicle (100) moves autonomously to a location available for parking in the external system (300) if, despite an anomaly indication to the external system (300), a destination is specified that is outside the management area of ​​the external system (300). [10] Vehicle according to claim 6, wherein biometric authentication is performed to authenticate the authorized user (21) and a result of the biometric authentication is invalidated if it is detected that the authorized user (21) has left a driver's seat after the biometric authentication, and the biometric authentication is requested again before an operation is performed which is restricted to authorized users (21). [11] System that causes a vehicle to move autonomously, wherein, when the system instructs the vehicle (100) to move and activates a movement of the vehicle (100), the system communicates with the vehicle (100) via a means of communication so that the vehicle (100) recognizes a validity of the system, so that - the vehicle (100) using content received via the first means of communication changes the means of communication to a modified means of communication through which the external system (300) gives instructions for the movement of the vehicle (100), - the vehicle (100) recognizes that encrypted communication has been established via the modified communication means using information acquired during the modification of the communication means and required for encryption, so that the vehicle (100) - recognizes that a user (21) of the vehicle (100) has authorized autonomous movement of the vehicle (100), and - recognizes that the user (21) who has authorized the movement of the vehicle (100) through the external system (300) is an authorized user (21) of the vehicle (100).

Citation Information

Patent Citations

  • Method for activating and / or deactivating valet-parking function in motor car, involves activating valet parking function to inhibit access to lockable region of motor car if control element is in actuated state

    DE102011104061A1

  • Method and device for operating a vehicle

    DE102014221772A1

  • Method and device for assisted driving of a vehicle

    DE102014224075A1

  • Method and device for operating a vehicle

    DE102014224108A1

  • Method and device for automatically stopping a vehicle

    DE102015202478A1