Mobile body control device, mobile body control method, and program

The mobile body control device addresses the inconvenience of engine restart and security concerns in vehicle anti-theft systems by using a dual control unit system for rapid authentication and secure signal management.

JP2025089668APending Publication Date: 2025-06-16HONDA MOTOR CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023204432
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-04
Publication Date
2025-06-16

Smart Images

  • Figure 2025089668000001_ABST
    Figure 2025089668000001_ABST
Patent Text Reader

Abstract

To provide a mobile body control device which enables a quick return from the reset of an alarm function after the security authentication of a mobile body is completed and has improved security.SOLUTION: A mobile body control device 1 includes a first control unit 10 and a second control unit 20. The second control unit 20 transmits and receives an authentication signal to and from the first control unit 10 via a second communication line 32 and executes a power source activation authentication process to permit the first control unit 10 to control a power source 43. After the power source activation authentication process is completed, the second control unit 20 stops the transmission and reception of authentication signals to and from the first control unit 10 via the second communication line 32. The first control unit 10, before the completion of the power source activation authentication process, transmits an authentication incomplete signal to the second control unit 20 via a first communication line 31 at a first predetermined cycle, and after the power source activation authentication process is completed, transmits an authentication complete signal to the second control unit via the first communication line 31 at a second predetermined cycle.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a movement control device, a movement control method, and a program.

Background Art

[0002] Conventionally, in a vehicle anti-theft device, when an engine start command signal is received by a remote control operation using a portable device, a configuration has been proposed in which a flag is turned on, the state of the flag is stored, and then cranking is started (see, for example, Patent Document 1). The vehicle anti-theft device prevents a decrease in anti-theft performance by resetting the alarm system due to a decrease in power supply voltage caused by cranking, and setting the alarm system to an alarm warning state when the flag is ON when the power supply voltage returns later.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In the above vehicle anti-theft device, when security authentication is completed and the alarm is released (non-warning state) before a decrease in power supply voltage occurs due to cranking or battery charging, the engine cannot be started unless authentication is completed again when the power supply voltage returns. Therefore, there is an inconvenience that it takes time to start the engine, and when the user is in the vehicle, there is an inconvenience that a false alarm of the alarm is issued and the user is disturbed. The present invention has been made in view of such a background, and an object thereof is to provide a mobile body control device, a mobile body control method, and a program that can quickly resume from resetting an alarm function after authentication of security of a mobile body such as a vehicle is completed and can improve security.

Means for Solving the Problems

[0005] As a first aspect for achieving the above object, a first control unit that controls a power source provided in a mobile body, a second control unit that executes control related to security of the mobile body, and the first control unit and the second control unit are connected. A mobile body control device including a first communication line used for transmission and reception of a control signal for controlling the operation of the mobile body between the first control unit and the second control unit, the first control unit and the second control unit are connected, and the first control unit is connected. A second communication line used for transmission and reception of an authentication signal for authenticating whether to permit control of the power source by the control unit is provided between the control unit and the second control unit. The second control unit performs transmission and reception of the authentication signal via the second communication line with the first control unit, and executes a power source start authentication process for permitting control of the power source by the first control unit. After the power source start authentication process is completed, transmission and reception of the authentication signal with the first control unit via the second communication line is stopped. Before the power source start authentication process is completed, the first control unit transmits an authentication incomplete signal to the second control unit at a first predetermined cycle via the first communication line. After the power source start authentication process is completed, an authentication complete signal is transmitted to the second control unit at a second predetermined cycle via the first communication line.

[0006] In the above-described movement control device, when the second control unit switches from a state of receiving the authentication completion signal transmitted from the first control unit via the first communication line to a state of receiving the authentication incomplete signal transmitted from the first control unit via the first communication line, the second control unit may be configured to execute the power source startup authentication process again.

[0007] In the above-described movement control device, when the second control unit does not receive the authentication completion signal transmitted from the first control unit via the first communication line from the time when the second control unit most recently received the authentication completion signal transmitted from the first control unit via the first communication line until a determination time set to be longer than a second predetermined period has elapsed, the second control unit may be configured to execute the power source startup authentication process again.

[0008] As a second aspect for achieving the above object, a first control unit that controls a power source provided in a moving body, a second control unit that executes control related to the security of the moving body, and the first control unit and the second control unit are connected. A first communication line used for transmission and reception of a control signal for controlling the operation of the moving body between the first control unit and the second control unit, and the first control unit and the second control unit are connected. A second communication line used for transmission and reception of an authentication signal for authenticating whether or not to permit control of the power source by the first control unit between the first control unit and the second control unit. A mobile body control method executed by a mobile body control device including: the second control unit performing transmission and reception of the authentication signal via the second communication line with the first control unit, and performing a power source start authentication process for permitting control of the power source by the first control unit; after the power source start authentication process is completed, stopping transmission and reception of the authentication signal with the first control unit via the second communication line; the first control unit, before the power source start authentication process is completed, transmitting an authentication incomplete signal to the second control unit via the first communication line at a first predetermined period, and after the power source start authentication process is completed, transmitting an authentication complete signal to the second control unit via the first communication line at a second predetermined period.

[0009] As a third aspect for achieving the above object, a first control unit that controls a power source provided in a moving body, a second control unit that executes control related to the security of the moving body, and the first control unit and the second control unit are connected, and a first communication line used for transmitting and receiving a control signal for controlling the operation of the moving body between the first control unit and the second control unit, and the first control unit and the second control unit are connected, and a second communication line used for transmitting and receiving an authentication signal for authenticating whether or not to permit the control of the power source by the first control unit between the first control unit and the second control unit. In a mobile control device including the above, a program executed by the first control unit and the second control unit, in which the second control unit performs transmission and reception of the authentication signal via the second communication line with the first control unit, and executes a power source start authentication process for permitting the control of the power source by the first control unit, and after the power source start authentication process is completed, executes a process of stopping the transmission and reception of the authentication signal with the first control unit via the second communication line, and the first control unit transmits an authentication incomplete signal to the second control unit at a first predetermined period via the first communication line before the power source start authentication process is completed, and after the power source start authentication process is completed, executes a process of transmitting an authentication complete signal to the second control unit at a second predetermined period via the first communication line.

Advantages of the Invention

[0010] According to the above mobile control device, mobile control method, and program, when the authentication between the first control unit and the second control unit becomes invalid due to the reset of the second control unit, the authentication between the first control unit and the second unit can be quickly restored using the second communication line. Further, after the authentication between the first control unit and the second unit is completed, the authentication signal does not propagate through the first communication line, and furthermore, the authentication signal does not propagate through the second communication line used for transmitting and receiving the control signal, so it is possible to prevent the authentication signal from being stolen and improve the security of the moving body.

Brief Description of the Drawings

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Modes for Carrying Out the Invention

[0012] [1. Configuration of Movement Control Device] With reference to FIG. 1, the configuration of the movement control device 1 of the present embodiment will be described. The movement control device 1 is mounted on a vehicle 100 including a battery 40, a communication unit 41, a power switch 42, a power source 43, etc. The vehicle 100 corresponds to the moving body of the present disclosure. The communication unit 41 performs wireless communication with a smart key 50 held by a user of the vehicle 100. The power switch 42 is a switch for receiving operations of starting (IG ON) and stopping (IG OFF) the vehicle 100 by the user.

[0013] When the vehicle 100 is a BEV (Battery Electric Vehicle), the power source 43 is an electric motor, and when the vehicle 100 is a HEV (Hybrid Electric Vehicle), the power source 43 is an electric motor and an engine. Further, when the vehicle 100 is a gasoline or diesel vehicle, the power source 43 is an engine.

[0014] The mobile control device 1 includes a first ECU (Electronic Control Unit) and a second ECU that control the operation of the vehicle 100, and a first communication line 31 and a second communication line 32 that connect the first ECU 10 and the second ECU 20. The specification of the first communication line 31 is, for example, CAN (Controller Area Network), and the specification of the second communication line 32 is, for example, UART (Universal Asynchronous Receiver Transmitter). The first ECU 10 corresponds to the first control unit of the present disclosure, and the second ECU 20 corresponds to the second control unit of the present disclosure. The mobile body of the present disclosure may be an aircraft, a ship, etc. in addition to the vehicle.

[0015] The first ECU 10 and the second ECU 20 operate by the power supplied from the battery 40. The first ECU 10 includes a first processor 11 and a first memory 12. In the first memory 12, a first program 13 for controlling the operation of the first ECU 10 and an authentication ID 14 used for the authentication process between the first ECU 10 and the second ECU 20 are stored. The first ECU 10 executes control related to the security of the vehicle 100, including the authentication process with the smart key 50 and the authentication process with the second ECU 20, by executing the first program 13 with the first processor 11.

[0016] The second ECU 20 includes a second processor 21 and a second memory 22. In the second memory 22, a second program 23 for controlling the operation of the second ECU 20 and an authentication ID 24 used for the authentication process between the first ECU 10 and the second ECU 20 are stored. The second ECU 20 executes the authentication process with the first ECU 10 by executing the second program 23 with the second processor 21, and after the authentication is completed (successful authentication), controls the operation of the power source 43. The first program 13 and the second program 23 correspond to the program of the present disclosure. The authentication process executed by both the first ECU 10 and the second ECU 20 corresponds to the power source start authentication process that permits the control of the power source by the first control unit of the present disclosure.

[0017] [2. Authentication Process between the First ECU and the Second ECU] According to the flowcharts shown in FIGS. 2 to 5, the execution procedure of a series of authentication processes executed between the first ECU 10 and the second ECU 20 will be described. The movement control method of the present disclosure is executed by the processes according to the flowcharts shown in FIGS. 2 to 5.

[0018] FIGS. 2 to 3 are processes executed by the first ECU 10. In order to collate the key ID with the smart key 50, the first ECU 10 is supplied with power from the battery 40 even when in the IG-OFF state, and the first ECU 10 continues to operate. In step S1 of FIG. 2, when the first ECU 10 succeeds in collating the key ID by wireless communication with the smart key 50, the process proceeds to step S2, and when the power switch 42 is turned ON (start operation), the process proceeds to step S3.

[0019] In step S3, the first ECU 10 switches the vehicle 100 from the IG-OFF state to the IG-ON state. Thereby, the power supply to the second ECU 20 is started and the second ECU 20 is initialized, and the second ECU 20 starts the processes according to the flowcharts shown in FIGS. 4 to 5 described later.

[0020] In the subsequent step S4, the first ECU 10 starts communication with the second ECU 20 via the second communication line 32. By the loop process of the next steps S5 and S6, in step S5, the first ECU 10 transmits an authentication response request signal (displayed as RSP_rq in FIG. 6 described later) to the second ECU 20 via the second communication line 32, and in step S6, when the authentication ID (displayed as AU_id in FIG. 6 described later) is received from the second ECU 20 via the second communication line 32, the process proceeds to step S7.

[0021] In the subsequent step S7, the first ECU 10 collates the authentication ID received from the second ECU 20 with the authentication ID 14 stored in the first memory 12. When they match, the process proceeds to step S8, and when they do not match, the process proceeds to step S20. In step S20, the first ECU 10 executes error processing such as outputting an alarm sound from the speaker provided in the vehicle 100.

[0022] In step S8, the first ECU 10 transmits, via the second communication line 32, an authentication completion confirmation signal (displayed as AU_cp in FIG. 6 described later) indicating that the authentication has been completed to the second ECU 20. In the next step S9, when the first ECU 10 receives, via the second communication line 32, an authentication completion response signal (displayed as CP_rs in FIG. 6 described later) transmitted from the second ECU 20, the process proceeds to step S10.

[0023] In step S10, the first ECU 10 stops communicating with the second ECU 20 via the second communication line 32. In the subsequent step S11, the first ECU 10 starts communicating with the second ECU 20 via the first communication line 31. In the next step S12, the first ECU 10 starts a monitoring timer. The set time of the monitoring timer corresponds to the determination time of the present disclosure.

[0024] In the next step S13, the first ECU 10 determines whether it has received the authentication completion signal "1" transmitted from the second ECU 20 via the first communication line 31. When the first ECU 10 receives the authentication completion signal "1", the process proceeds to step S12, and when it does not receive the authentication completion signal "1", the process proceeds to step S14. In step S14, the first ECU 10 determines whether it has received the authentication incomplete signal "0" transmitted from the second ECU 20 via the first communication line 31.

[0025] When the first ECU 10 receives the authentication incomplete signal "0", it proceeds to step S15, and when it does not receive the authentication incomplete signal "0", it proceeds to step S30. In step S30, the first ECU 10 determines whether the determination timer has timed out. When the determination timer has timed out, it proceeds to step S15, and when the determination timer has not timed out, it proceeds to step S13.

[0026] Here, through the processing according to the flowcharts of FIGS. 4 to 5 described later, when the second ECU 20 is in the authentication completed state, it repeatedly transmits the authentication completed signal "1" to the first ECU 10 at a predetermined period via the first communication line 31. Also, when the second ECU 20 is in the authentication incomplete state, it repeatedly transmits the authentication incomplete signal "0" to the first ECU 10 at a predetermined period via the first communication line 31.

[0027] Therefore, when the authentication completed state continues, the first ECU 10 receives the authentication completed signal "1" from the second ECU 20 in step S13 and starts the determination timer in step S12 repeatedly until the determination timer times out in step S30. And when factors such as voltage drop of the battery 40 due to cranking at engine start when the vehicle 100 is a gasoline vehicle occur and the second ECU 20 is reset, the authentication completed state is released and the second ECU 20 enters the authentication incomplete state.

[0028] When it enters the authentication incomplete state, the second ECU 20 switches from the state of transmitting the authentication completed signal "1" to the first ECU 10 via the first communication line 31 to the state of transmitting the authentication incomplete signal "0" to the first ECU 10 via the first communication line 31. As a result, when either the first ECU 10 determines in step S14 that it has received the authentication incomplete signal "0" from the second ECU 20 via the first communication line 31 or the determination timer times out in step S30, the first ECU 10 proceeds to step S15.

[0029] In step S15, the first ECU 10 determines whether it is in the IG-ON state. When it is in the IG-ON state, that is, when it can be determined that the second ECU 20 has been reset due to factors other than the OFF operation of the power switch 42, the process proceeds to step S4 in FIG. 2. In this case, the first ECU 10 executes the processes after step S4, communicates with the second ECU 20 via the second communication line 32, and re-executes the authentication process. On the other hand, when it is in the IG-OFF state, the first ECU 10 proceeds to step S16 and ends the process according to the flowcharts in FIGS. 2 to 3.

[0030] Next, FIGS. 4 to 5 show the processes executed by the second ECU 20. The second ECU 20 executes the processes according to the flowcharts shown in FIGS. 4 to 5 when the supply of power equal to or higher than the specified voltage starts from the battery 40. The second ECU 20 is reset when the voltage of the power supplied from the battery 40 becomes less than the specified voltage, and when the voltage of the power supplied from the battery 40 returns to equal to or higher than the specified voltage, the processes according to the flowcharts in FIGS. 4 to 5 are executed again.

[0031] In step S50 of FIG. 4, the second ECU 20 sets the second ECU 20 to the unauthenticated state, and executes the processes in subsequent steps S51 to S55 and S60, and the processes in steps S60 to S64 in FIG. 5 in parallel. In step S51 of FIG. 4, the second ECU 20 starts communicating with the first ECU 10 via the first communication line 31. In the next step S52, the second ECU 20 determines whether it is in the authenticated state. Then, when the second ECU 20 is in the authenticated state, the process proceeds to step S60, and when it is in the unauthenticated state, the process proceeds to step S53.

[0032] In step S60, the second ECU 20 transmits an authentication completion signal "1" to the first ECU 10 via the first communication line 31 and proceeds with the processing to step S54. Also, in step S53, the second ECU 20 transmits an authentication incomplete signal "0" to the first ECU 10 via the first communication line 31 and proceeds with the processing to step S54. In step S54, the second ECU 20 starts the transmission cycle timer, and when the transmission cycle timer times out in the subsequent step S55, the second ECU 20 proceeds with the processing to step S52.

[0033] By the processing of steps S52 to S55 and S60, when in the authentication completed state, the authentication completion signal "1" is repeatedly transmitted from the second ECU 20 to the first ECU 10 via the first communication line 31. On the other hand, when in the authentication incomplete state, the authentication incomplete signal "0" is repeatedly transmitted from the second ECU 20 to the first ECU 10 via the first communication line 31.

[0034] Steps S60 to S64 in FIG. 5 are processes for performing authentication with the first ECU 10. In step S60 of FIG. 5, the second ECU 20 starts communication with the first ECU 10 via the second communication line 32. In the subsequent step S61, when the second ECU 20 receives an authentication response request signal (displayed as RSP_rq in FIG. 6 described later) transmitted from the first ECU 10 via the second communication line 32, the second ECU 20 proceeds with the processing to step S62.

[0035] In the next step S62, the second ECU 20 transmits the authentication ID (displayed as AU_id in FIG. 6 described later) stored in the second memory 22 to the first ECU 10 via the second communication line 32. In the subsequent step S63, when the second ECU 20 receives an authentication completion confirmation signal (displayed as AU_cp in FIG. 6 described later) transmitted from the first ECU 10 via the second communication line 32, the second ECU 20 proceeds with the processing to step S64.

[0036] In step S64, the second ECU 20 transmits an authentication completion response signal (displayed as CP_rs in FIG. 6 described later) to the first ECU 10 via the second communication line 32. In the subsequent step S65, the second ECU 20 sets the second ECU 20 to the authentication completion state. In the next step S66, the second ECU 20 stops communicating with the first ECU 10 via the second communication line 32.

[0037] [3. Execution Timing of Authentication Process] Referring to the timing chart shown in FIG. 6, the transmission and reception modes when the first ECU 10 executes the processes according to the flowcharts of FIGS. 2 to 3 described above and the second ECU 20 executes the processes according to the flowcharts of FIGS. 4 to 5 described above will be described.

[0038] FIG. 6 shows the timing of the IG state (IG-ON state, IG-OFF state) of the vehicle 100, the transmission and reception of signals via the second communication line 32, the transmission and reception of signals between the first ECU 10 and the second ECU 20, and the transmission and reception of the authentication completion signal "1" and the authentication incomplete signal "0" via the first communication line 31 on a common time axis t.

[0039] At t1 in FIG. 6, when the collation of the key ID (authentication OK) is completed between the first ECU 10 and the smart key 50 and the power switch 42 is turned on, the vehicle 100 is switched from the IG-OFF state to the IG-ON state by the first ECU 10. As a result, the second ECU 20 is activated, and the second ECU 20 starts the processes according to the flowcharts of FIGS. 4 to 5.

[0040] The first ECU 10 and the second ECU 20 start communicating via the second communication line 32 and execute the authentication process by transmitting and receiving an authentication response request signal (RSP_rq), an authentication ID (AU_id), an authentication completion confirmation signal (AU_cp), and an authentication completion response signal (CP_rs) via the second communication line 32.

[0041] t2 is the time when authentication is completed (authentication is successful), and the first ECU 10 and the second ECU 20 stop communicating via the second communication line 32. In the period from t1 to t2 when the authentication is not completed, the second ECU 20 repeatedly transmits an authentication incomplete signal "0" to the first ECU 10 via the first communication line 31. Also, in the period from t2 to t3 when the authentication is not completed, the second ECU 20 repeatedly transmits an authentication completed signal "1" to the first ECU 10 via the first communication line 31.

[0042] In this way, the authentication ID is transmitted only during the period from t1 to t2 immediately after the IG-ON state is entered. After t2 when the authentication is completed, the communication between the first ECU 10 and the second ECU 20 via the second communication line 32 stops. Therefore, as long as no abnormality such as reset of the second ECU 20 occurs as shown in t3 to t4, the authentication ID will not propagate to the second communication line 32. Also, the authentication ID will not propagate to the first communication line 31. This can prevent unauthorized connection to the first communication line 31 used for communication with various ECUs such as the first ECU 10 and the second ECU 20 and theft of the authentication ID.

[0043] t3 is the time when the second ECU 20 is reset due to a voltage drop of the battery 40 or the like, and t4 is the time when the voltage of the battery 40 returns to the specified voltage or higher and the second ECU 20 restarts. Due to the restart, the second ECU 20 enters an authentication incomplete state, and the signal transmitted by the second ECU 20 to the first ECU 10 via the first communication line 31 switches from the authentication completed signal "1" to the authentication incomplete signal "0".

[0044] Then, when the first ECU 10 recognizes from time t4 that the signal transmitted from the second ECU 20 has switched from the authentication completion signal "1" to the authentication incomplete signal "0", the first ECU 10 re-executes the authentication process. As a result, when a reset of the second ECU 20 occurs and the second ECU 20 is in an authentication incomplete state, the second ECU 20 can be quickly restored to the authentication complete state. In this case, it is possible to avoid the vehicle 100 becoming unable to travel or an alarm being output due to the authentication incomplete state of the second ECU 20 continuing.

[0045] [4. Other Embodiments] In the above embodiment, in step S14 of FIG. 3, when the signal transmitted from the second ECU 20 switches from the authentication completion signal "1" to the authentication incomplete signal "0", or in step S30, when the first ECU 10 does not receive the next authentication completion signal "1" until the set time of the determination timer has elapsed since the time when the authentication completion signal "1" transmitted from the second ECU 20 was received immediately before, the first ECU 10 re-executes the authentication process of the second ECU 20. As another embodiment, it may be configured to determine only one of step S14 and step S30 and re-execute the authentication process of the second ECU 20.

[0046] In the above embodiment, the second ECU 20 made the transmission periods of the authentication incomplete signal "0" and the authentication completion signal "1" the same by the processes of steps S52 to S55 and S60 in FIG. 4. However, the transmission period of the authentication incomplete signal "0" (corresponding to the first transmission period of the present disclosure) and the transmission period of the authentication completion signal "1" (corresponding to the second transmission period of the present disclosure) may be different periods.

[0047] Note that, for the ease of understanding of the invention of the present application, FIG. 1 is a schematic diagram showing the configuration of the movement control device 1 divided according to the main processing contents, and the movement control device 1 may be configured by other divisions. Further, the processing of each component may be executed by one hardware unit or by a plurality of hardware units. Further, the processing by each component shown in FIGS. 2 to 5 may be executed by one program or by a plurality of programs.

[0048] [5. Configuration Supported by the Above Embodiment] The above embodiment is a specific example of the following configuration.

[0049] (Configuration 1) A first control unit that controls a power source provided in a moving body, a second control unit that executes control related to the security of the moving body, a connection between the first control unit and the second control unit, and a first communication line used for transmission and reception of a control signal for controlling the operation of the moving body between the first control unit and the second control unit. A movement control device comprising: a second communication line used for transmission and reception of an authentication signal for authenticating whether or not to permit control of the power source by the first control unit between the first control unit and the second control unit; the second control unit performs transmission and reception of the authentication signal via the second communication line with the first control unit, and executes a power source start authentication process for permitting control of the power source by the first control unit. After the power source start authentication process is completed, transmission and reception of the authentication signal with the first control unit via the second communication line is stopped. Before the power source start authentication process is completed, the first control unit transmits an authentication incomplete signal to the second control unit via the first communication line at a first predetermined period, and after the power source start authentication process is completed, transmits an authentication completed signal to the second control unit via the first communication line at a second predetermined period. According to the movement control device of Configuration 1, according to the above movement control device, movement control method, and program, when the authentication between the first control unit and the second control unit becomes invalid due to the reset of the second control unit, the authentication between the first control unit and the second unit can be quickly restored using the second communication line. Further, after the authentication between the first control unit and the second unit is completed, the authentication signal does not propagate through the first communication line, and furthermore, the authentication signal does not propagate through the second communication line used for transmitting and receiving control signals, so it is possible to prevent the authentication signal from being intercepted and improve the security of the moving body.

[0050] (Configuration 2) The movement control device according to Configuration 1, wherein when the second control unit switches from a state of receiving the authentication completion signal transmitted from the first control unit via the first communication line to a state of receiving the authentication incomplete signal transmitted from the first control unit via the first communication line, the power source startup authentication process is executed again. According to the movement control device of Configuration 2, when the second control unit switches from a state of receiving the authentication completion signal to a state of receiving the authentication incomplete signal, it can be determined that the first unit has been reset, and the power source startup authentication process can be executed again.

[0051] (Configuration 3) The movement control device according to Configuration 1 or Configuration 2, wherein when the second control unit does not receive the authentication completion signal transmitted from the first control unit via the first communication line from the time when the authentication completion signal transmitted from the first control unit via the first communication line was most recently received until a determination time set longer than the second predetermined period has elapsed, the power source startup authentication process is executed again. According to the movement control device of Configuration 3, when the state in which the transmission of the authentication completion signal from the first control unit is interrupted continues for a determination time or longer, it can be determined that the first control unit has been reset, and the power source startup authentication process can be executed again.

[0052] (Configuration 4) A first control unit that controls a power source provided in a moving body, a second control unit that executes control related to the security of the moving body, and the first control unit and the second control unit are connected, and a first communication line used for transmitting and receiving a control signal for controlling the operation of the moving body between the first control unit and the second control unit, and the first control unit and the second control unit are connected, and a second communication line used for transmitting and receiving an authentication signal for authenticating whether to permit the control of the power source by the first control unit between the first control unit and the second control unit, A mobile body control method executed by a mobile body control device comprising: the second control unit performs transmission and reception of the authentication signal via the second communication line with the first control unit, and executes a power source start authentication process for permitting control of the power source by the first control unit; after the power source start authentication process is completed, stopping transmission and reception of the authentication signal with the first control unit via the second communication line; the first control unit, before the power source start authentication process is completed, transmits an authentication incomplete signal to the second control unit via the first communication line at a first predetermined period, and after the power source start authentication process is completed, transmits an authentication complete signal to the second control unit via the first communication line at a second predetermined period. By executing the mobile body control method of Configuration 4 by the mobile body control device, the same operational effects as those of the mobile body control device of Configuration 1 can be obtained.

[0053] (Configuration 5) A first control unit that controls a power source provided in a moving body, a second control unit that executes control related to the security of the moving body, a connection between the first control unit and the second control unit, and a first communication line used for transmission and reception of a control signal for controlling the operation of the moving body between the first control unit and the second control unit, and a connection between the first control unit and the second control unit, and a second communication line used for transmission and reception of an authentication signal for authenticating whether to permit control of the power source by the first control unit between the first control unit and the second control unit. In a mobile control device comprising: a program executed by the first control unit and the second control unit, wherein the second control unit performs transmission and reception of the authentication signal with the first control unit via the second communication line to execute a power source startup authentication process for permitting control of the power source by the first control unit, and after the power source startup authentication process is completed, executes a process of stopping transmission and reception of the authentication signal with the first control unit via the second communication line, and the first control unit transmits an authentication incomplete signal to the second control unit via the first communication line at a first predetermined period before the power source startup authentication process is completed, and after the power source startup authentication process is completed, executes a process of transmitting an authentication complete signal to the second control unit via the first communication line at a second predetermined period. By executing the program of Configuration 5 by the first control unit and the second control unit, the configuration of the vehicle control device of Configuration 1 can be realized.

Explanation of Signs

[0054] 1... Mobile control device, 10... First control unit, 11... First processor, 12... First memory, 13... First program, 14... Authentication ID, 20... Second control unit, 21... Second processor, 22... Second memory, 23... Second program, 24... Authentication ID, 31... First communication line, 32... Second communication line, 40... Battery, 41... Communication unit, 42... Power switch, 43... Power source, 50... Smart key.

Claims

1. A first control unit that controls a power source provided in a moving body; A second control unit that executes control related to the security of the moving body; A first communication line that connects the first control unit and the second control unit and is used for transmitting and receiving a control signal for controlling the operation of the moving body between the first control unit and the second control unit; A mobile body control device comprising: A second communication line that connects the first control unit and the second control unit and is used for transmitting and receiving an authentication signal for authenticating whether to permit control of the power source by the first control unit between the first control unit and the second control unit; The second control unit performs transmission and reception of the authentication signal via the second communication line with the first control unit, executes a power source start authentication process for permitting control of the power source by the first control unit, and after the power source start authentication process is completed, stops transmission and reception of the authentication signal with the first control unit via the second communication line; Before the power source start authentication process is completed, the first control unit transmits an authentication incomplete signal to the second control unit at a first predetermined period via the first communication line, and after the power source start authentication process is completed, transmits an authentication complete signal to the second control unit at a second predetermined period via the first communication line. A mobile body control device.

2. When the second control unit switches from a state of receiving the authentication complete signal transmitted from the first control unit via the first communication line to a state of receiving the authentication incomplete signal transmitted from the first control unit via the first communication line, the second control unit executes the power source start authentication process again. The mobile body control device according to claim 1.

3. When the second control unit has not received the authentication completion signal transmitted from the first control unit via the first communication line for a determination time set to be longer than the second predetermined period since the time when the authentication completion signal transmitted from the first control unit via the first communication line was most recently received, the second control unit re-executes the power source startup authentication process. The mobile body control device according to claim 1 or 2.

4. A first control unit that controls a power source provided in a mobile body, A second control unit that executes control related to the security of the mobile body, A first communication line that connects the first control unit and the second control unit and is used for transmitting and receiving a control signal for controlling the operation of the mobile body between the first control unit and the second control unit, A second communication line that connects the first control unit and the second control unit and is used for transmitting and receiving an authentication signal for authenticating whether to permit the control of the power source by the first control unit between the first control unit and the second control unit, A mobile body control method executed by a mobile body control device including: A step in which the second control unit performs transmission and reception of the authentication signal with the first control unit via the second communication line and executes a power source startup authentication process for permitting the control of the power source by the first control unit, and after the power source startup authentication process is completed, stops the transmission and reception of the authentication signal with the first control unit via the second communication line; A step in which the first control unit transmits an authentication incomplete signal to the second control unit via the first communication line at a first predetermined period before the power source startup authentication process is completed, and transmits an authentication completion signal to the second control unit via the first communication line at a second predetermined period after the power source startup authentication process is completed; A mobile body control method including the above steps.

5. A first control unit that controls a power source provided in a mobile body, A second control unit that executes control related to the security of the moving body, A first communication line that connects the first control unit and the second control unit and is used for transmission and reception of a control signal for controlling the operation of the moving body between the first control unit and the second control unit, A second communication line that connects the first control unit and the second control unit and is used for transmission and reception of an authentication signal for authenticating whether to permit control of the power source by the first control unit between the first control unit and the second control unit, In a mobile body control device comprising: a program executed by the first control unit and the second control unit, The second control unit performs transmission and reception of the authentication signal with the first control unit via the second communication line to execute a power source start authentication process for permitting control of the power source by the first control unit, and after the power source start authentication process is completed, executes a process of stopping transmission and reception of the authentication signal with the first control unit via the second communication line, The first control unit transmits an authentication incomplete signal to the second control unit via the first communication line at a first predetermined period before the power source start authentication process is completed, and after the power source start authentication process is completed, transmits an authentication complete signal to the second control unit via the first communication line at a second predetermined period. Program.

Citation Information

Patent Citations

  • Anti-theft device for vehicle

    JP2008279971A