Information processing device and on-vehicle device

The information processing device addresses the challenge of detecting vehicle theft by monitoring periodic heartbeat signals and initiating authentication processes when communication is lost, ensuring timely detection and security activation.

JP2025071478AActive Publication Date: 2025-05-08TOYOTA JIDOSHA KK
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2023181665
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-10-23
Publication Date
2025-05-08
Estimated Expiration
2043-10-23

AI Technical Summary

Technical Problem

Existing vehicle theft prevention systems may fail to detect theft when a vehicle's communication module is maliciously removed or when the vehicle enters an area with poor communication coverage.

Method used

An information processing device that receives periodic 'heartbeat' signals from vehicles and determines if an illegal act has been committed when the signal is not received at the expected time, using additional authentication processes if the signal fails.

Benefits of technology

Enables the detection of fraudulent conduct against vehicles by ensuring continuous communication and initiating security measures when communication is lost, thereby preventing delayed activation of security alarms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025071478000001_ABST
    Figure 2025071478000001_ABST
Patent Text Reader

Abstract

To detect occurrence of a fraudulent act against a vehicle.SOLUTION: An information processing device receives a heartbeat signal transmitted from a first vehicle according to a prescribed cycle, and determines that there is such a suspicion that a fraudulent act has been performed on the first vehicle when the heartbeat signal is not received from the first vehicle at the timing according to the prescribed cycle.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present disclosure relates to vehicles. [Background technology]

[0002] Many technologies have been devised to prevent vehicle theft. For example, Patent Document 1 discloses a system that warns the driver when the vehicle is parked in an area where thefts are common. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] JP 2009-107531 A Summary of the Invention [Problem to be solved by the invention]

[0004] The present disclosure is intended to detect the occurrence of fraudulent conduct against a vehicle. [Means for solving the problem]

[0005] One aspect of the present disclosure is to The information processing device has a control unit that receives a heartbeat signal transmitted from a first vehicle according to a predetermined period, and when the heartbeat signal is not received from the first vehicle at a timing according to the predetermined period, determines that there is a suspicion that fraudulent activity has been committed against the first vehicle.

[0006] One aspect of the present disclosure is to The in-vehicle device is mounted on a first vehicle and is capable of communicating with a predetermined information processing device, and has a control unit that performs the following operations: transmitting a heartbeat signal to the information processing device via a predetermined communication module in accordance with a predetermined period; and performing a predetermined authentication process if transmission of the heartbeat signal fails.

[0007] Further, other aspects include a method executed by the above-mentioned device, a program for causing a computer to execute the method, or a computer-readable storage medium non-transitoryly storing the program. Effect of the Invention

[0008] According to the present disclosure, it is possible to detect the occurrence of fraudulent conduct against a vehicle. [Brief description of the drawings]

[0009] [Figure 1] 1 is an outline diagram of a vehicle system according to the first embodiment. [Diagram 2] FIG. 1 is a configuration diagram of devices included in the system. [Diagram 3] 10 is a sequence diagram of a process for sending a vehicle message to a management server. [Figure 4] 10 is a flow chart of the processes executed by the management server in the first embodiment. [Diagram 5] 10 is a flow chart of the processes executed by the management server in the second embodiment. [Figure 6] 10 is a flow chart of a process executed by an on-vehicle device in the third embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0010] In recent years, many anti-theft technologies have been proposed in the field of vehicles. For example, a communication module and a GPS module are installed in a vehicle and the location information is periodically uploaded. Techniques are known to enable tracking a specific vehicle from the outside.

[0011] However, even if such a method is used, there are cases where it is not possible to detect the occurrence of a theft. In particular, if an intruder accesses the vehicle network from the outside and starts the vehicle system in a way that is mistaken for a legitimate procedure, the security alarm may not go off, and the occurrence of the theft may be recognized late. The information processing device in the present disclosure solves this problem.

[0012] An information processing device according to one embodiment of the present disclosure has a control unit that receives a heartbeat signal transmitted from a first vehicle according to a predetermined period, and determines that there is a suspicion of fraudulent activity having been committed against the first vehicle when the heartbeat signal is not received from the first vehicle at a timing according to the predetermined period.

[0013] The heartbeat signal is a signal periodically transmitted from the first vehicle. The heartbeat signal may include any information as long as it indicates that the first vehicle is alive and well. For example, the heartbeat signal may include a vehicle identifier, or may include information about the surrounding conditions of the first vehicle, such as location information. In addition, the transmission of the heartbeat signal may be triggered by polling, or may be spontaneously transmitted from the vehicle.

[0014] When the heartbeat signal is not received at a timing according to a predetermined cycle, the control unit determines that there is a suspicion of fraudulent activity against the first vehicle, because in such a case, it can be presumed that an action to disable the communication function, such as disconnecting the communication module, has been performed.

[0015] In addition, the heartbeat signal may include location information of the first vehicle, and the control unit may transmit the location information contained in the last received heartbeat signal to a specified device when there is a suspicion of fraudulent activity against the first vehicle. According to this form, it is possible to notify the relevant person of the location of the first vehicle along with the suspected occurrence of fraud.

[0016] Furthermore, the control unit may be able to receive a second heartbeat signal from one or more second vehicles located near the first vehicle. In addition, if a heartbeat signal transmitted from a first vehicle is not received at a timing according to a predetermined period and a second heartbeat signal is received from one or more second vehicles, it may be determined that there is a suspicion of fraudulent activity against the first vehicle.

[0017] If the determination is made based solely on whether or not a heartbeat signal has been received, it is impossible to determine whether an abnormality has occurred in the vehicle or whether the vehicle is simply in an environment where communication is not possible (such as outside the communication service area). Therefore, the determination may be made based on whether or not a heartbeat signal is normally received from a vehicle (second vehicle) located near the first vehicle. For example, if a heartbeat signal is normally received from a second vehicle located near the first vehicle but no heartbeat signal is received from the first vehicle, it can be assumed that the abnormality is not due to the communication environment.

[0018] An in-vehicle device according to an embodiment of the present disclosure is an in-vehicle device mounted on a first vehicle and capable of communicating with a predetermined information processing device. Specifically, the in-vehicle device has a control unit that transmits a heartbeat signal to the information processing device via a predetermined communication module at a predetermined cycle and, when the transmission of the heartbeat signal fails, executes a predetermined authentication process.

[0019] The on-vehicle device can be, for example, a device capable of communicating with the information processing device described above. I The in-vehicle device transmits a heartbeat signal via a predetermined communication module. On the other hand, if the transmission of the heartbeat signal fails, a predetermined authentication process is executed. If the transmission of the heartbeat signal fails, it can be assumed that some kind of fraudulent act (such as theft) has been committed against the first vehicle. Therefore, security can be ensured by the control unit executing the predetermined authentication process in such a case. The predetermined authentication process can be, for example, a process of additionally requesting authentication of the driver. It is to be noted that if the predetermined authentication process is not executed, the first vehicle may not be started.

[0020] Specific embodiments of the present disclosure will be described below with reference to the drawings. Unless otherwise specified, the hardware configuration, module configuration, functional configuration, and the like described in each embodiment are not intended to limit the technical scope of the disclosure to only those.

[0021] First Embodiment [System Overview] An overview of a vehicle system according to a first embodiment will be described. The vehicle system according to this embodiment includes a vehicle 1, a management server 2, and an MQTT server 3. The vehicle 1 is a connected vehicle that can access a wireless communication network. The vehicle 1 can communicate with the management server 2 and the MQTT server 3 via the wireless communication network (for example, a mobile communication network).

[0022] The vehicle 1 is equipped with an on-vehicle device 10 and a DCM 20. The in-vehicle device 10 is a computer that provides predetermined functions to the occupants of the vehicle 1. The in-vehicle device 10 may be, for example, a car navigation device or a head unit. In this embodiment, the in-vehicle device 10 has a function of periodically generating information about the vehicle 1 and transmitting the information as a message to an external device. In the following description, a message including information about the vehicle 1 transmitted from the in-vehicle device 10 is also referred to as a "vehicle message." The vehicle message is an example of a "heartbeat signal."

[0023] The DCM 20 is a data communication module (DCM) for connecting components of a vehicle (e.g., the in-vehicle device 10, other ECUs, etc.) to a network. ) In this embodiment, the in-vehicle device 10 can provide various services by communicating with external devices via the DCM 20. Examples of the various services include a navigation service, a remote control service (e.g., remote air conditioning, etc.), an in-vehicle Wi-Fi (registered trademark) service, an emergency call service, and a security service.

[0024] The management server 2 is a management device configured to be able to communicate with a plurality of vehicles 1 via a network. The management server 2 receives vehicle messages at a predetermined cycle from each of the plurality of vehicles 1 under its management, and when there is a vehicle 1 from which no vehicle message is received for a certain period of time or longer, it presumes that fraudulent activity has been committed against the vehicle 1. Note that in this embodiment, the fraudulent activity is theft, but the management server 2 may detect other fraudulent activities.

[0025] In this embodiment, the management server 2 and the on-vehicle device 10 transmit and receive messages using a publisher / subscriber communication model. In this embodiment, the in-vehicle device 10 is the publisher, and the management server 2 is the subscriber. In this embodiment, it is assumed that the in-vehicle device 10 asynchronously transmits the generated information to the management server 2. Note that, although only one each of the vehicle 1, the in-vehicle device 10, the DCM 20, the management server 2, and the MQTT server 3 is shown in FIG. 1, the vehicle system in this embodiment may include a plurality of these elements.

[0026] In this embodiment, the MQTT protocol is adopted as a protocol for publishing and subscribing type communication. In the MQTT protocol, a subscriber (a party receiving a message) applies to an MQTT broker for delivery of a message sent from a distributor (Subscribe). Also, a distributor can distribute any message to the MQTT broker. (Publish) MQTT brokers are requesting delivery for the message. Identify subscribers and deliver messages to those subscribers. In this embodiment, the subscriber corresponds to the management server 2 and the streamer corresponds to the in-vehicle device 10. Furthermore, the MQTT broker corresponds to the MQTT server 3.

[0027] The management server 2 registers in advance in the MQTT server 3 from which vehicle the vehicle messages sent by the management server 2 are to be subscribed. The vehicles to be registered are one or more vehicles that are managed by the management server 2. The vehicle 1 (in-vehicle device 10) transmits the generated vehicle message to the MQTT server 3. Upon receiving the vehicle message from the in-vehicle device 10, the MQTT server 3 identifies the destination device (i.e., the management server 2 that has applied to subscribe to the message) and transfers the vehicle message to the management server 2. As a result, the management server 2 can receive vehicle messages from one or more vehicles 1 to be managed.

[0028] When the management server 2 stops receiving vehicle messages from one or more vehicles that are under management, it determines that the vehicle is suspected to have been stolen, and executes a predetermined process.

[0029] [Device configuration] Next, the configuration of each device constituting the system will be described. Fig. 2 is a diagram showing an example of the configuration of each device included in the vehicle system according to this embodiment. The vehicle system according to this embodiment includes a vehicle 1, a management server 2, and an MQTT server 3.

[0030] First, the components included in the vehicle 1 will be described. The vehicle 1 includes an on-vehicle device 10 and a DCM 20 . The in-vehicle device 10 can be configured as a computer having a processor (CPU, GPU, etc.), a main storage device (RAM, ROM, etc.), and an auxiliary storage device (EPROM, hard disk drive, removable media, etc.). The auxiliary storage device stores an operating system (OS), various programs, various tables, etc., and by executing the programs stored therein, various functions (software modules) that match a predetermined purpose, as described below, can be realized. However, some or all of the functions may be realized as hardware modules by hardware circuits such as ASICs and FPGAs.

[0031] The on-vehicle device 10 includes a control unit 11, a storage unit 12, a communication unit 13, and a position information acquisition unit 14.

[0032] The control unit 11 is a calculation unit that executes a predetermined program to realize various functions of the in-vehicle device 10. The control unit 11 can be realized by a hardware processor such as a CPU. The control unit 11 may also be configured to include a RAM, a ROM (Read Only Memory), a cache memory, and the like.

[0033] The control unit 11 is configured to have two software modules: a message transmission unit 111 and a function providing unit 112. Each software module may be realized by the control unit 11 (CPU, etc.) executing a program stored in the storage unit 12, which will be described later. stomach.

[0034] The message sending unit 111 periodically generates a vehicle message and sends it to the MQTT server 3. In this embodiment, the vehicle message includes an identifier of the vehicle 1, a generation date and time of the vehicle message, location information of the vehicle 1, etc. The vehicle message is sent to the management server 2 via the MQTT server 3.

[0035] The function providing unit 112 executes various functions provided by the in-vehicle device 100. Examples of the functions provided by the in-vehicle device 100 include the following. - Device link function This function connects to a terminal (smartphone, etc.) owned by the vehicle's occupant, and performs playback of music and video, mirroring the screen, etc. Audio Features This is a function for playing music stored in a storage device. -TV / Radio function It is a function that receives radio and digital television broadcasts. Navigation features This function provides route navigation based on map data stored in the storage device. These functions can be provided, for example, via an input / output device (such as a touch panel).

[0036] The storage unit 12 is a means for storing information, and is configured with storage media such as RAM, a magnetic disk, a flash memory, etc. The storage unit 12 stores programs executed by the control unit 11, data used by the programs, etc.

[0037] The communication unit 13 is a communication interface with an in-vehicle network provided in the vehicle 1. The communication unit 13 performs communication via a CAN (Controller Area Network). The on-vehicle device 10 can communicate with the DCM 20 (and other ECUs, etc.) via the in-vehicle network.

[0038] The position information acquisition unit 14 acquires position information of the vehicle 1. The position information acquisition unit 14 includes a GPS antenna and a positioning module for positioning the position information. The GPS antenna is an antenna that receives positioning signals transmitted from positioning satellites (also called GNSS satellites). The positioning module is a module that calculates position information based on the signals received by the GPS antenna.

[0039] The DCM 20 is a device that performs wireless communication with a predetermined network in order to connect a component (e.g., the in-vehicle device 10) of the vehicle 1 to an external device (e.g., the MQTT server 3). In this embodiment, the DCM 20 is configured to be connectable to a predetermined cellular communication network. The DCM 20 is configured to include an eUICC (Embedded Universal Integrated Circuit Card) for identifying a user. The eUICC may be a physical SIM card, an eSIM, or the like.

[0040] Next, the management server 2 will be described. Like the in-vehicle device 10, the management server 2 can be configured as a computer having a processor (CPU, GPU, etc.), a main memory device (RAM, ROM, etc.), and an auxiliary memory device (EPROM, hard disk drive, removable media, etc.).

[0041] The management server 2 includes a control unit 21, a storage unit 22, and a communication unit 23.

[0042] The control unit 21 is a computing unit that executes a predetermined program to realize various functions of the management server 2. The control unit 21 can be realized by, for example, a hardware processor such as a CPU. The control unit 21 may also be configured to include a RAM, a ROM (Read Only Memory), a cache memory, and the like.

[0043] The control unit 21 is configured to have two software modules: a message receiving unit 211 and a determination unit 212. Each software module may be realized by causing the control unit 21 (such as a CPU) to execute a program stored in a storage unit 22, which will be described later.

[0044] The message receiving unit 211 receives a vehicle message transmitted from the in-vehicle device 10 via the MQTT server 3, and stores the vehicle message in a storage unit 22 described later. The message receiving unit 211 may register (subscribe) in advance to the MQTT server 3 from which vehicle the vehicle message transmitted by the message receiving unit 211 will be received (subscribed).

[0045] The determination unit 212 determines, based on the vehicle message stored in the memory unit 22, that a fraudulent act (theft) has been committed against any of the one or more vehicles 1 under its management.

[0046] The storage unit 22 is a means for storing information, and is configured with storage media such as RAM, a magnetic disk, a flash memory, etc. The storage unit 22 stores the programs executed by the control unit 21, data used by the programs, etc.

[0047] The communication unit 23 is a communication interface for connecting the management server 2 to a network. The communication unit 23 is configured to be able to communicate with the network via, for example, Ethernet (registered trademark), wireless LAN, mobile communication services, or the like.

[0048] Next, the MQTT server 3 will be described. Like the in-vehicle device 10, the MQTT server 3 can be configured as a computer having a processor (CPU, GPU, etc.), a main storage device (RAM, ROM, etc.), and an auxiliary storage device (EPROM, hard disk drive, removable media, etc.).

[0049] The MQTT server 3 includes a control unit 31, a storage unit 32, and a communication unit 33.

[0050] The control unit 31 is a calculation unit that executes a predetermined program to realize various functions of the MQTT server 3. The control unit 31 can be realized by a hardware processor such as a CPU. The control unit 31 may also be configured to include a RAM, a ROM (Read Only Memory), a cache memory, and the like.

[0051] The control unit 31 is configured to have a message relay unit 311 as a software module. The software module may be realized by causing the control unit 31 (such as a CPU) to execute a program stored in the storage unit 32, which will be described later.

[0052] The message relay unit 311 relays the vehicle message to a specified subscriber based on subscription information registered in advance. First, the message relay unit 311 receives the subscription information from the management server 2. The subscription information includes an identifier of the vehicle 1 that wishes to subscribe to the vehicle message. When there are multiple messages sent from the vehicle 1, the subscription information may include an identifier for identifying the message to be subscribed to. The subscription information is stored in the memory unit 32.

[0053] Furthermore, the message relay unit 311 receives a vehicle message from the vehicle 1 (the in-vehicle device 10) and relays the vehicle message to a specified subscriber based on the stored subscription information. If there are multiple management servers 2 and one of them receives a vehicle message that it wishes to subscribe to, the message relay unit 311 transmits the vehicle message to the corresponding management server 2.

[0054] The storage unit 32 is a means for storing information, and is configured with storage media such as RAM, a magnetic disk, a flash memory, etc. The storage unit 32 stores the programs executed by the control unit 31, data used by the programs, etc.

[0055] The communication unit 33 is a communication interface for connecting the MQTT server 3 to a network. The communication unit 33 is configured to be able to communicate with the network via, for example, Ethernet (registered trademark), a wireless LAN, a mobile communication service, or the like.

[0056] 2 is an example, and all or part of the functions shown in the figure may be executed using a dedicated circuit. Also, the programs may be stored or executed using a combination of a main memory device and an auxiliary memory device other than those shown in the figure.

[0057] [Vehicle message sending and receiving processing] Next, a method will be described in which the vehicle-mounted device 10 transmits a vehicle message and the management server 2 receives the vehicle message.

[0058] First, the management server 2 registers (Subscribes) the vehicle 1, which is a subscription target for the vehicle message, in the MQTT server 3 (message relay unit 311) (step S11). The target vehicle 1 is, for example, a vehicle Identification Number (such as Vehicle Identification Number). As a result, the subscription information is generated and stored by the MQTT server 3. The subscription information is information that links the issuer and subscriber of the vehicle message.

[0059] In parallel with this, the in-vehicle device 10 generates a vehicle message at a specified timing and transmits (Publishes) the vehicle message to the MQTT server 3 (step S12). The vehicle message may be generated and transmitted periodically (for example, every 5 minutes). Note that the vehicle message is generated and transmitted even when the driving system of the vehicle 1 is not activated.

[0060] In this step, the in-vehicle device 10 (message sending unit 111) generates a vehicle message including an identifier of the vehicle 1, the date and time when the message was generated, and the location information of the vehicle 1. The location information of the vehicle 1 can be acquired, for example, via the location information acquiring unit 14. The generated vehicle message is transmitted to the MQTT server 3 via the DCM 20.

[0061] In step S13, the MQTT server 3 that has received the vehicle message identifies the management server 2 that has registered the subscription to the vehicle message based on the stored subscription information. The vehicle message is transmitted to the management server 2 that has registered the subscription.

[0062] In step S14, the management server 2 (message receiving unit 211) that has received the vehicle message stores the vehicle message in the storage unit 22. By performing the process shown in FIG. 3, vehicle messages are periodically transmitted from vehicle 1 (vehicle device 10) to management server 2.

[0063] [Judgment process executed by Management Server 2] Next, a process executed by the management server 2 based on the received vehicle message will be described in detail. FIG. 4 is a flowchart of the process executed by the management server 2. This process is performed periodically by the control unit 21 (deciding unit 212) after the management server 2 starts receiving a vehicle message from the on-vehicle device 10 .

[0064] The illustrated processing is executed for each of the multiple vehicles 1 under the management of the management server 2. First, in step S21, the most recent reception date and time for the vehicle message received from the target vehicle is acquired. Next, in step S22, it is determined whether or not the time that has elapsed since the last vehicle message was received is equal to or longer than a predetermined time. For example, if vehicle messages are transmitted at five-minute intervals, this step may result in a positive determination if no vehicle message has been received for 30 minutes to an hour or more. The predetermined time may be determined as appropriate. If the determination in this step is positive, the process proceeds to step S23. If the determination is negative, the process moves to the next target vehicle.

[0065] In step S23, it is determined that the target vehicle is suspected of being stolen. In this step, for example, a notification may be sent to a predetermined device. For example, the management server 2 may send a message to a terminal related to the target vehicle (for example, a terminal owned by the owner of the target vehicle) notifying that reception of vehicle messages from the target vehicle has been interrupted or a message notifying that the target vehicle is suspected of being stolen.

[0066] Additionally, the message may include information related to the last vehicle message received from the target vehicle, such as when the vehicle message includes location information of the target vehicle, the date and time the vehicle message was generated, or a map on which the location information is mapped.

[0067] As described above, in the vehicle system according to this embodiment, an on-board device mounted on a vehicle transmits a vehicle message (heartbeat signal) according to a predetermined cycle. The management server receives the vehicle message for each vehicle, and if there is a vehicle that has not received the vehicle message at the timing according to the predetermined cycle, it determines that the vehicle is suspected of being stolen and issues a notification. With this configuration, even if the communication module is maliciously removed from the vehicle, it is possible to detect this and notify the user.

[0068] In this embodiment, the vehicle message is wirelessly transmitted by the MQTT protocol, but the transmission protocol and communication media are not limited to a specific one as long as the management server 2 can receive vehicle messages from multiple vehicles 1 under its management. Also, in this embodiment, the vehicle-mounted device 10 triggers the transmission of the vehicle message, but the management server 2 may trigger the transmission of the vehicle message (for example, by polling, etc.).

[0069] Second Embodiment In the first embodiment, the management server 2 infers that the target vehicle is suspected of being stolen when the vehicle message is not received at a timing according to a predetermined cycle. On the other hand, there may be cases where the vehicle message cannot be transmitted due to the wireless communication environment. For example, this may be the case when the vehicle 1 moves out of the service area of ​​the cellular communication.

[0070] In such a case, the management server 2 cannot determine whether the communication module of the target vehicle has been removed or whether the target vehicle has simply gone out of the communication service area. In order to handle such a case, the management server 2 according to the second embodiment makes the determination by also using vehicle messages received from surrounding vehicles. In this embodiment, the term "surrounding vehicle" refers to a vehicle that is located near the target vehicle and is traveling along the same or a similar route (a route that partially overlaps) as the target vehicle. Vehicles traveling along the same or similar route can be extracted based on, for example, the location information included in the vehicle message. Vehicles traveling along the same road in the same direction in the vicinity of the target vehicle can be nearby vehicles.

[0071] 5 is a flowchart of the process executed by the management server 2 in the second embodiment. The steps indicated by dotted lines are the same as those in the first embodiment, and therefore detailed explanations will be omitted.

[0072] In step S22A, it is determined whether or not a vehicle message has been received from a nearby vehicle. In this step, for example, nearby vehicles moving along the same or similar route as the target vehicle are extracted, and it is determined whether or not vehicle messages can be continuously received from the nearby vehicles near the point where reception of vehicle messages from the target vehicle stopped. If reception of vehicle messages from the nearby vehicles has not stopped (step S22B-No), the process proceeds to step S23. If reception of vehicle messages from the nearby vehicles has also stopped (step S22B-Yes), it is determined that the cause is the communication environment, and the process ends.

[0073] According to the second embodiment, it is possible to estimate that the transmission of the vehicle message has failed due to the communication environment, which means that it is possible to prevent a notification from being sent even when a theft has not occurred.

[0074] Third embodiment In the first and second embodiments, the management server 2 detects that a suspected theft of a target vehicle has occurred. In contrast, in the third embodiment, the in-vehicle device 10 mounted on the vehicle 1 detects that a suspected theft of the vehicle itself has occurred and takes a predetermined measure.

[0075] As described with reference to the drawing, the management server 2 can detect that the DCM 20 has been removed from the vehicle 1. On the other hand, when the DCM 20 is removed from the vehicle 1, communication between the in-vehicle device 10 and the DCM 20 is interrupted. If the in-vehicle device 10 can detect this, it becomes possible to take measures such as applying a security lock on the vehicle system side.

[0076] In the third embodiment, after the in-vehicle device 10 generates the vehicle message in step S12, the in-vehicle device 10 determines whether or not communication with the DCM 20 has been successful. Fig. 6 is a flowchart of a process executed by the in-vehicle device 10 after execution of step S12. As mentioned above, the vehicle message generated by the on-vehicle device 10 (message transmitting unit 111) is transmitted via the DCM 20.

[0077] In step S12A, it is determined that communication failures have occurred a predetermined number of times or more. Here, communication refers to communication between the in-vehicle device 10 and the DCM 20. In this step, it is determined that the in-vehicle device 10 is in a state in which communication with the DCM 20 via the in-vehicle network is not possible. Here, if communication failures have occurred a predetermined number of times or more, the process transitions to step S12B. If communication with the DCM 20 is successful, the process ends.

[0078] In step S12B, the in-vehicle device 10 requests a predetermined authentication process. The predetermined authentication process is a process that requests the vehicle occupant to prove that they are a legitimate user. Examples of such a process include a process that requests the input of preset authentication information (such as a password), a process that requests authentication using biometric information, and a process that requests the presentation of a key fob. The authentication information and biometric information may be acquired using a sensor or an interface connected to the in-vehicle device 10. The predetermined authentication process can be performed at any timing. For example, the in-vehicle device 10 requests the authentication process the next time the vehicle system is started, and if the authentication is successful, the in-vehicle device 10 performs the predetermined authentication process. If not completed, a signal may be sent to the ECU to lock the vehicle system.

[0079] According to the third embodiment, it becomes possible for the vehicle side to detect that the DCM 20 has been removed, and it becomes possible to prevent the vehicle from moving.

[0080] (Modification) The above-mentioned embodiment is merely an example, and the present disclosure may be modified and implemented as appropriate within the scope of the present invention. For example, the processes and means described in this disclosure can be freely combined and implemented as long as there is no technical conflict.

[0081] In addition, in the embodiment, theft has been given as an example of fraudulent acts committed against a vehicle, but fraudulent acts other than theft (for example, illegal modifications) can also be detected as long as they relate to the act of removing the communication module. In the embodiment, the vehicle message includes the vehicle position information, but the vehicle message may include other information about the surrounding conditions of the vehicle. For example, the vehicle message may include an image captured by an on-board camera.

[0082] Furthermore, a process described as being performed by one device may be shared and executed by multiple devices. Alternatively, a process described as being performed by different devices may be executed by one device. In a computer system, the hardware configuration (server configuration) by which each function is realized can be flexibly changed.

[0083] The present disclosure can also be realized by supplying a computer program implementing the functions described in the above embodiments to a computer, and having one or more processors of the computer read and execute the program. Such a computer program may be provided to the computer by a non-transitory computer-readable storage medium connectable to the system bus of the computer, or may be provided to the computer via a network. Non-transitory computer-readable storage media include, for example, any type of disk, such as a magnetic disk (floppy disk, hard disk drive (HDD), etc.), an optical disk (CD-ROM, DVD disk, Blu-ray disk, etc.), a read-only memory (ROM), a random access memory (RAM), an EPROM, an EEPROM, a magnetic card, a flash memory, an optical card, and any type of medium suitable for storing electronic instructions. [Explanation of symbols]

[0084] 10...In-vehicle equipment 11. Control section 12...Storage section 13. Communications Department 14...Location information acquisition unit 2. Management Server 21 Control section 22...Storage section 23. Communications Department 3. MQTT Server 31 Control section 32...Storage section 33. Communications Department

Claims

1. receiving a heartbeat signal transmitted from a first vehicle according to a predetermined period; determining that a fraudulent act has been committed against the first vehicle when the heartbeat signal is not received from the first vehicle at a timing according to the predetermined cycle; An information processing device having a control unit that executes the above.

2. the heartbeat signal includes location information of the first vehicle; the control unit transmits the location information included in the last received heartbeat signal to a predetermined device when there is a suspicion that an illegal act has been performed on the first vehicle. The information processing device according to claim 1 .

3. the control unit is configured to receive a second heartbeat signal from one or more second vehicles located in the vicinity of the first vehicle; determining that a fraudulent act has been suspected against the first vehicle when the heartbeat signal transmitted from the first vehicle is not received at a timing according to the predetermined cycle and the second heartbeat signal is received from the one or more second vehicles; The information processing device according to claim 1 .

4. An in-vehicle device that is mounted on a first vehicle and is capable of communicating with a predetermined information processing device, Transmitting a heartbeat signal to the information processing device via a predetermined communication module in accordance with a predetermined cycle; executing a predetermined authentication process when the transmission of the heartbeat signal fails; A control unit that executes In-vehicle device.

5. The predetermined authentication process is a process of requesting authentication information from a driver of the first vehicle. The vehicle-mounted device according to claim 4.

Citation Information

Patent Citations

  • Burglar notification device and emergency notification system

    JP2004161121A

  • Vehicle theft preventing system

    JP2005186686A

  • Vehicle theft prevention apparatus

    JP2007264877A

  • Control device and computer program

    JP2021190765A

  • Theft deterrent system for connected vehicles based on wireless messages

    US20190283709A1