System and program
The vehicle security system addresses false alarms by temporarily suppressing alarms until a valid authentication is completed, enhancing security and user experience.
Patent Information
- Application Number
- JP2025100929
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-06-17
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2039-12-19
AI Technical Summary
Existing vehicle security systems issue false alarms when legitimate users attempt to use the vehicle, detracting from their experience and potentially compromising security.
A vehicle security system that includes an alarm mechanism and a control mechanism to suppress alarms temporarily when a first trigger is detected, transitioning to a non-monitoring state only upon acceptance of a valid authentication operation, thereby preventing false alarms and enhancing security.
The system effectively prevents fraudulent acts by suppressing false alarms, ensuring high security while allowing legitimate users to operate the vehicle without unnecessary alerts.
Smart Images

Figure 2025128351000001_ABST
Abstract
Description
[Technical Field]
[0001] For example, it relates to systems and programs. [Background technology]
[0002] It has become a social problem that vehicles and their accessories are stolen or used illegally by third parties other than the legitimate user of the vehicle (for example, the owner or user of the vehicle).Regarding vehicle security technology, for example, Patent Document 1 describes an abnormality detection device that activates the vehicle's horn, lighting devices, etc. to issue a warning when it detects an abnormality, such as the occurrence of a certain pattern of vibration in the vehicle. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2010-208380 Summary of the Invention [Problem to be solved by the invention]
[0004] As with the technology described in Patent Document 1, issuing an alarm when an abnormality is detected in a vehicle is expected to have the effect of deterring fraudulent acts such as vehicle theft. However, if the alarm is issued when a legitimate user is about to use the vehicle, this will be a false alarm, which is undesirable for the legitimate user.
[0005] An object of the present invention is to provide a vehicle security technology that is different from conventional technology, for example, to provide a system, a program, etc. that has excellent security while suppressing the issuance of false alarms.
[0006] The object of the present invention is not limited to this, and the applicant intends to obtain rights for configurations that aim to achieve the effects achieved by parts of the configuration disclosed in the specification and drawings, etc., through divisional applications, amendments, etc. For example, this specification discloses problems in which the phrase "can be" is read as "the problem is...." Each problem is described as an independent problem, and the applicant intends to obtain rights for configurations that solve each problem separately through divisional applications, amendments, etc. Even if the problem is implicitly understood from the description in the specification, the applicant intends to include part of the configuration described in this specification in the scope of the patent claim through amendments or divisional applications. Furthermore, the applicant has disclosed configurations that solve problems that combine these independent problems, and the applicant intends to obtain rights for them. [Means for solving the problem]
[0007] The object of the present invention can be achieved, for example, by the following embodiments (1) to (16).
[0008] (1) The system should preferably include an alarm means having a function of issuing an alarm when an abnormality is detected while the vehicle is in a monitoring state, and a control means that temporarily suppresses the issuance of an alarm by the alarm means when a first trigger is generated while the vehicle is in a monitoring state, and that maintains the vehicle in a non-monitoring state when a second trigger is generated, indicating that a valid authentication operation has been accepted.
[0009] This provides high security by maintaining the non-monitoring state only when a second trigger indicating that a legitimate authentication operation has been accepted is detected. Furthermore, since the first trigger suppresses the issuance of an alarm, false alarms are prevented from being issued when a legitimate user is performing an authentication operation. Furthermore, the period during which authentication operations can be accepted while the issuance of an alarm is suppressed is limited to a temporary period from the time of the first trigger, which may also be desirable from a security perspective. Therefore, security can be enhanced while false alarms are suppressed. This invention not only aims to prevent fraudulent acts such as vehicle theft by third parties, but also aims to suppress false alarms issued by legitimate users and prevent undesirable situations from occurring for the legitimate user.
[0010] (2) The control means may be a system that, if the normal authentication operation is not accepted, does not maintain the vehicle in a non-monitoring state, but cancels the temporary suppression of the issuance of an alarm by the alarm means.
[0011] In this way, when a proper authentication operation is not accepted, an alarm is sounded by the alarm means, which can, for example, discourage a malicious third party from carrying out an illegal act such as stealing a vehicle, thereby realizing high security.
[0012] (3) The system may be such that the regular authentication operation is an input operation of inputting regular authentication information into an input means.
[0013] In this way, unless proper authentication information is entered, the vehicle will not be maintained in an unmonitored state, thereby achieving high security.
[0014] (4) The authorized authentication operation may be a system including a first input operation of inputting authorized authentication information into a first input means and a second input operation into a second input means inherently provided in the vehicle.
[0015] In this way, if only one of the first input operation or the second input operation is accepted, the vehicle is not maintained in the non-monitoring state but is placed in the monitoring state, and when both the first input operation and the second input operation are accepted, the vehicle is maintained in the non-monitoring state. Furthermore, for example, the second input means inherently provided in the vehicle can be used to indicate completion of input of authentication information in the first input operation. Therefore, higher security can be achieved without providing a new means for indicating completion of input of authentication information.
[0016] (5) The second input means may be a system that receives input related to the operation of the engine of the vehicle.
[0017] In this way, for example, an input related to the operation of the vehicle's engine, such as an operation normally performed when using the vehicle, can also be used as an input completion operation to instruct completion of input of authentication information, thereby improving user operability.
[0018] (6) The control means may be a system that treats the first authentication operation as the regular authentication operation before a predetermined period of time has elapsed since the first trigger occurred, and prohibits the first authentication operation from being treated as the regular authentication operation after the predetermined period has elapsed.
[0019] In this way, for example, if a regular authentication operation is not accepted within a specified period after the first trigger and the vehicle enters a monitoring state, the first authentication operation is prohibited from becoming a regular authentication operation, so even if a third party takes time to perform a first authentication operation that becomes a regular authentication operation, it is possible to prevent the vehicle from remaining in a non-monitoring state.
[0020] (7) When the predetermined period has elapsed, the alarm means issues an alarm, and the control means determines that the second authentication operation, which is an additional user procedure compared to the first authentication operation that is the normal authentication operation, is the normal authentication operation.
[0021] In this way, as long as the user performs a normal authentication operation while the issuance of the alarm is suppressed, the increase in the operational burden is suppressed. For example, if there is an error in the authentication operation or the authentication operation is not performed, the number of steps the user must take to perform a normal authentication operation along with the issuance of the alarm can be increased, thereby reducing the possibility of mistakenly authenticating an inauthentic user as a normal user.
[0022] (8) The first trigger may be a system that indicates that a predetermined action has been accepted when the vehicle is unlocked.
[0023] In this way, if a predetermined action, such as an attempt to use the vehicle, occurs while the vehicle is unlocked, the system temporarily suppresses the issuance of an alarm because there is a possibility that this action is being performed by a legitimate user, thereby preventing false alarms caused by legitimate users.
[0024] (9) The control means may be a system that maintains the vehicle in a non-monitoring state when it receives a predetermined signal from a remote control terminal other than the electronic key attached to the vehicle, the predetermined signal having a data portion different from that transmitted by the electronic key, or a predetermined signal having a frequency different from that used by the electronic key for wireless communication.
[0025] In this way, even if the user does not perform the proper authentication operation, when a predetermined signal from the remote control terminal that can be distinguished from a signal from the electronic key is received, the vehicle can be maintained in a non-monitoring state, thereby achieving high security while improving user convenience.
[0026] (10) The system may further include a detection means capable of detecting the first trigger, and the control means, when receiving information from the detection means that the first trigger has occurred, may temporarily suppress the issuance of an alarm by the alarm means and may have a judgment function for determining whether or not to maintain the vehicle in a non-monitoring state.
[0027] In this way, even if the control means is not provided with a function capable of detecting the first trigger, it is possible to determine whether or not the first trigger is present based on information from the detection means capable of detecting the first trigger.
[0028] (11) The alarm means has a function of issuing an alarm when an abnormality is detected in a specific monitoring area of the vehicle while the vehicle is in a monitoring state, and the second trigger may be a system that indicates that the legitimate authentication operation has been accepted in the specific monitoring area.
[0029] In this way, a specific monitoring area in the vehicle can be designated as an area where the user performs authentication, and the authentication can be performed in a state where the issuance of an alarm is temporarily suppressed.
[0030] (12) The specific monitoring area may be a system including the spatial area inside the vehicle.
[0031] In this way, the spatial area inside the vehicle can be used as the area where the user performs authentication operations, and authentication of people inside the vehicle can be performed while temporarily suppressing the issuance of an alarm.
[0032] (13) When the vehicle is in a monitoring state, abnormalities are monitored in each of the vehicle's multiple monitoring areas, and the control means may be configured to, when the first trigger is received while the vehicle is in a monitoring state, temporarily suppress the issuance of an alarm for the specific monitoring area, which is a part of the multiple monitoring areas, and when the second trigger is received, cancel the monitoring state for abnormalities in all of the multiple monitoring areas.
[0033] In this way, even if the abnormality monitoring state in a specific monitoring area is temporarily canceled in response to the first trigger, if a normal authentication operation is not received in the specific monitoring area, the abnormality monitoring state in all of the multiple monitoring areas will not be canceled, thereby achieving high security.
[0034] (14) The alarm means may be a system that issues an alarm when an abnormality is detected in a predetermined area different from the specific monitoring area between the first trigger and the second trigger.
[0035] In this way, even if the abnormality monitoring state is temporarily canceled in some monitored areas in response to the first trigger, an alarm will be issued if an abnormality is detected in other specified areas, thereby preventing fraudulent acts such as theft of the vehicle itself or vehicle accessories.
[0036] (15) The system may include an alarm means having a function of issuing an alarm when an abnormality is detected while the vehicle is in a monitoring state, and a control means that temporarily suppresses the issuance of an alarm by the alarm means when a second trigger indicating that a valid authentication operation has been accepted while the vehicle is in a monitoring state, and that maintains the vehicle in a non-monitoring state when a first trigger is detected.
[0037] In this way, the non-monitoring state is maintained only when a second trigger indicating that a legitimate authentication operation has been accepted is detected, thereby providing high security. Furthermore, since the second trigger prevents an alarm from being issued, false alarms are prevented from being issued when a legitimate user is attempting to use the vehicle. Furthermore, the period during which the non-monitoring state can be maintained without issuing an alarm is limited to a temporary period from the second trigger, which can also be a desirable basis for security. Therefore, security can be enhanced while preventing false alarms from being issued. This invention not only aims to prevent fraudulent acts such as vehicle theft by third parties, but also aims to prevent false alarms from being issued by legitimate users and prevent undesirable situations from occurring for the legitimate users.
[0038] (16) The present invention may be a program that causes a computer to execute the functions of the system according to any one of the above aspects (1) to (15).
[0039] In this way, high security can be achieved by installing the program on a computer and having it perform the functions according to the modes (1) to (15). [Effects of the Invention]
[0040] According to the present invention, it is possible to provide a vehicle security technology that is different from conventional technology. For example, it is possible to provide a system, a program, etc. that has excellent security while suppressing the issuance of false alarms.
[0041] The effects of the present invention are not limited to these, and effects achieved by the configuration disclosed in the present specification and drawings, etc. are also disclosed, and the applicant intends to obtain rights to the configuration achieving such effects through divisional applications, amendments, etc. For example, in this specification, phrases such as "can" and "is possible" are descriptions that clearly indicate the effects achieved, and there are also parts that demonstrate effects even without the phrases "can" and "is possible." Furthermore, there are effects that can be understood from the configuration even without such phrases. [Brief explanation of the drawings]
[0042] [Figure 1] FIG. 1 is a schematic diagram illustrating an example of a system. [Figure 2] FIG. 1 is an example of a block diagram of a system. [Figure 3] 10 is a flowchart illustrating a control process executed in the system. [Figure 4] 10 is a flowchart illustrating a control process executed in the system. [Figure 5] 10 is a flowchart illustrating a control process executed in the system. DETAILED DESCRIPTION OF THE INVENTION
[0043] [System Configuration] An example of the configuration of a system according to the present invention will be described with reference to FIG. 1. The following describes a case where the present invention is applied to an electronic key system that locks and unlocks vehicle doors using an electronic key carried by a user. In an electronic key system, unlocking of a vehicle door is performed, for example, by transmitting and receiving wireless signals between the electronic key and a vehicle-side device. Generally, the distance over which wireless communication between the electronic key and the vehicle-side device is possible (hereinafter also referred to as the wireless communication distance) is limited to a relatively short distance. Therefore, when the distance between the electronic key and the vehicle-side device is longer than the wireless communication distance, wireless signals are not transmitted and received between the electronic key and the vehicle-side device, and the vehicle door is not unlocked.
[0044] 1 is a schematic diagram showing a vehicle system 100 to which a system according to this embodiment is applied. For example, as shown in FIG. 1, the vehicle system 100 includes a vehicle 1, an electronic key 2, a remote terminal 3 (described later), and the like.
[0045] The vehicle exemplified in vehicle system 100 may be, for example, an automobile, and particularly a four-wheeled vehicle. However, the vehicle is not limited to a four-wheeled vehicle, and may be a large vehicle with four or more wheels. Furthermore, the vehicle exemplified in vehicle system 100 may be a vehicle in general, such as a transportation vehicle (e.g., a truck), a commercial vehicle (e.g., a taxi, a bus), or a general vehicle (a so-called private car), but may also be used for multiple purposes. For example, the vehicle may be one that is shared by an unspecified number of people, such as for car sharing or rental purposes.
[0046] The electronic key 2 is a key capable of wireless communication with the vehicle 1, and may be, for example, an original electronic key that comes with the vehicle 1. The electronic key 2 is usually carried by the authorized user of the vehicle 1. The electronic key 2 is also called, for example, a smart key.
[0047] 2 is an example of a block diagram of a vehicle system 100 according to this embodiment. The vehicle system 100 is configured with, for example, two systems, an electronic key system 10 and an authentication system 20.
[0048] The electronic key system 10 is a system that locks and unlocks the vehicle door 9 through wireless communication between the vehicle 1 and the electronic key 2, and is a system that is originally built into the vehicle 1.
[0049] The electronic key system 10 includes various ECUs, such as an electronic key ECU (Engine Control Unit) 11 and a body ECU 12.
[0050] The electronic key ECU 11 is a processing unit that controls wireless communication with the electronic key 2. The electronic key ECU 11 has functions such as detecting radio waves from the electronic key 2, determining the authenticity of the electronic key 2, and transmitting the determination results to the body ECU 12, etc.
[0051] The body ECU 12 is a processing unit that executes control over the body and the like of the vehicle 1. For example, the body ECU 12 has a function of transmitting a lock signal (also referred to as a lock signal) and an unlock signal (also referred to as an unlock signal) to the vehicle door 9 (see FIG. 1) of the vehicle 1.
[0052] In the electronic key system 10, the electronic key ECU 11 and the electronic key 2 are associated with each other. For example, when a user carrying the electronic key 2 presses the second reception unit 7 (see FIG. 1 ) of the vehicle 1 near the vehicle 1, wireless communication is established between the electronic key ECU 11 and the electronic key 2. The second reception unit 7 is, for example, a door switch or another switch. The electronic key ECU 11 then performs a verification process for the electronic key 2 based on the wireless signal from the electronic key 2. If the electronic key 2 is determined to be authentic, the electronic key ECU 11 transmits a signal to the body ECU 12 to unlock the vehicle doors 9 of the vehicle 1. Upon receiving this signal, the body ECU 12 transmits an unlock signal to the vehicle doors 9, thereby unlocking the vehicle doors 9.
[0053] The unlocking operation of the vehicle door 9 is not limited to pressing the second reception unit 7, but may be pressing an unlock button provided on the electronic key 2. There are various unlocking operations depending on the vehicle manufacturer, model, etc. For example, if a touch sensor or the like is provided on the handle of the vehicle door, the unlocking operation of the vehicle door 9 may be touching the handle.
[0054] The authentication system 20 is a system for performing authentication (also referred to as user authentication) of a user who intends to use a vehicle (for example, a person who intends to get in the vehicle 1 or a person who intends to drive the vehicle 1, etc.; the same applies below), and is, for example, a system that is retrofitted to the vehicle 1. The authentication system 20 is, for example, a system for preventing fraudulent acts on the vehicle 1 itself or on accessories of the vehicle 1 (for example, the engine of the vehicle 1, etc.), and is also referred to as a fraud prevention system or a security system.
[0055] As shown in FIG. 2, the authentication system 20 includes, for example, a control unit 21 (an example of a control means), a detection unit 22 (an example of a detection means), a communication unit 23 (an example of a communication means), an input device 24 (an example of an input means), and an alarm 25 (an example of an alarm means).
[0056] The control unit 21 is a controller having a CPU, memories such as ROM and RAM, a timer (an example of a timing means), other peripheral circuits, etc. Various programs are stored in the ROM of the control unit 21, and the control unit 21 realizes various functions by executing these programs. The various programs include programs describing algorithms for executing the processes shown in the flowcharts of FIGS. 3 to 5. The control unit 21 is a processing unit that mainly operates in the authentication system 20.
[0057] The control unit 21 has various functions, such as an alarm control function that controls the activation and deactivation of an alarm by the alarm device 25, an authentication function that performs user authentication, and a judgment function that determines whether or not a legitimate authentication operation (described below) has been accepted. For example, when information that a first trigger has occurred is acquired from the detection unit 22, the judgment function has the function of temporarily suppressing the activation of an alarm by the alarm device 25 and determining whether or not to transition the vehicle 1 to a non-monitoring state.
[0058] The monitoring state is a state in which abnormalities (e.g., also referred to as security abnormalities) are monitored, and is also referred to as an alert state, for example. The non-monitoring state is a state in which abnormalities are not monitored, and is also referred to as a non-alert state, for example.
[0059] The detection unit 22 is a processing unit that can detect, for example, the state of the vehicle 1, the behavior of the vehicle 1, and the like.
[0060] The communication unit 23 (see FIG. 2) is a processing unit capable of performing wireless communication with the remote terminal 3 (described next).
[0061] The remote terminal 3 (see FIG. 1) is a remotely operated terminal capable of wireless communication with the vehicle 1 (more specifically, the communication unit 23 of the authentication system 20 of the vehicle 1). The remote terminal 3 can send and receive wireless signals to and from the vehicle 1 within a range where wireless communication with the vehicle 1 is possible. The remote terminal 3 is provided, for example, as an attachment to the authentication system 20.
[0062] The remote terminal 3 is provided with a non-monitoring command transmission button (not shown) for transmitting a non-monitoring command (described below). The non-monitoring command is a command to transition the vehicle 1 from a monitoring state to a non-monitoring state. When the communication unit 23 receives the non-monitoring command from the remote terminal 3, it transmits information to that effect to the control unit 21. Based on this information, the control unit 21 transitions the vehicle 1 from the monitoring state to a non-monitoring state.
[0063] Furthermore, the user can use the remote terminal 3, for example, to set high security (described later).
[0064] Here, the authentication system 20 is provided with, for example, two types of authentication operations: a first authentication operation and a second authentication operation.
[0065] For example, when the second authentication operation is required as the authentication operation, the user is required to input pre-registered authentication information. When the first authentication operation is required as the authentication operation, the user is required to input authentication information that can be input in fewer steps than when the second authentication operation is required. The authentication information may be, for example, alphabets, numbers, symbols, hiragana, katakana, or a combination of two or more of these, but using only one type of authentication information makes it easier to simplify the configuration of the input means. The input means can accept input of authentication information and may be, for example, a keyboard, a numeric keypad, or a dedicated button. The authentication information required in the first authentication operation may be part of the authentication information required in the second authentication operation (for example, one or more predetermined characters from the beginning). This reduces the possibility that the user will forget the authentication information. The authentication information required in the first authentication operation and the second authentication operation may be, for example, set in advance by the user.
[0066] In this way, the number of steps required by the user in the first authentication operation is fewer than the number of steps required by the user in the second authentication operation, making authentication using the first authentication operation simpler for the user. How to use the first authentication operation and the second authentication operation will be described later. The "steps" may be, for example, the amount of operation by the user, such as the number of times a button on the input device 24 is pressed or the number of buttons to be operated.
[0067] The high security setting is a setting for further enhancing the security performance of the authentication system 20. The high security setting is a setting that prohibits the first authentication operation, of two types of authentication operations, the first authentication operation and the second authentication operation, from being set as the regular authentication operation. The authentication system 20 prohibits the first authentication operation from being set as the regular authentication operation and sets the second authentication operation as the regular authentication operation. The second authentication operation, which is set as the regular authentication operation, requires more user steps than the first authentication operation, so it is suitable for ensuring higher security. On the other hand, when the high security setting is not set, the authentication system 20 determines that if either the first authentication operation or the second authentication operation is performed, this is the regular authentication operation. This simplifies the authentication operation that the user must perform.
[0068] It is preferable that the vehicle 1 be set to immediately transition from a monitoring state to a non-monitoring state in response to a first trigger (described later) using, for example, the remote terminal 3. It is preferable that the authentication system 20 be set to prioritize security or user convenience.
[0069] The input device 24 functions as an input means capable of inputting authentication information. The input device 24 may be provided, for example, in a spatial region inside the vehicle 1, and in particular, in a location that is difficult to see from outside the vehicle. Such a location is preferably a location that is out of the line of sight of people outside the vehicle, and may be a location where the line of sight of people outside the vehicle is blocked by, for example, a component constituting the vehicle (for example, the vehicle body) or an object mounted on the vehicle (for example, a seat, a dashboard, etc.).
[0070] The alarm 25 is a device capable of issuing an alarm. The alarm 25 has a function of issuing an alarm when, for example, an abnormality is detected in a specific monitoring area of the vehicle 1 while the vehicle 1 is in a monitoring state. The alarm 25 is provided separately from, for example, a buzzer that is originally provided in the vehicle 1.
[0071] The "activation of an alarm" by the alarm device 25 may be the sounding of an alarm sound such as a siren. However, without being limited to this, the "activation of an alarm" may also be, for example, the utterance of an alarm message such as "an abnormality has been detected." Alternatively, the "activation of an alarm" may be an alarm notification operation in which the alarm device 25 works in conjunction with the communication unit 23 to notify the user of an alarm message or the like on a smartphone or the like. The alarm device 25 may issue an alarm in a way that can be perceived by people outside the vehicle.
[0072] As shown in FIG. 2, the vehicle 1 includes a first reception unit 6, a second reception unit 7, and the like.
[0073] The first receiving unit 6 functions as a means for receiving input related to the operation of the prime mover (for example, an engine or motor) of the vehicle 1. The first receiving unit 6 may be, for example, a predetermined pedal of the vehicle (for example, an accelerator pedal or a brake pedal), an accessory power switch, or an ignition switch (for example, a button-type ignition switch provided on the dashboard or the like, or an ignition switch configured with a switching mechanism provided inside the key cylinder). In the case of an electric vehicle, the first receiving unit 6 may be a switch for turning on the system power supply of the vehicle. It is particularly preferable that the first receiving unit 6 be an operating member that is originally provided in the spatial region inside the vehicle 1.
[0074] [General operation] Next, the general operation of the vehicle system 100 according to this embodiment will be described.
[0075] In this embodiment, for example, when a first trigger occurs while the vehicle 1 is in a monitoring state, the control unit 21 temporarily suppresses the issuance of an alarm by the alarm device 25, and when a second trigger occurs indicating that a valid authentication operation has been accepted, the control unit 21 maintains the vehicle 1 in a non-monitoring state.
[0076] For example, if a valid authentication operation is not received after the first trigger and there is no second trigger, the control unit 21 does not transition the vehicle 1 to a non-monitoring state, but cancels the temporary suppression of issuance of an alarm by the alarm device 25. In this way, an alarm is issued by the alarm device 25 when a valid authentication operation is not received, which can, for example, discourage fraudulent attempts such as vehicle theft by a third party other than the user (for example, a thief), thereby achieving high security.
[0077] The "first trigger" may, for example, indicate that a predetermined action has been received from a user when the vehicle 1 (e.g., the vehicle door 9 of the vehicle 1) is unlocked. For example, if a predetermined action is received to use the vehicle 1, this may be due to a legitimate user, and therefore the issuance of an alarm is temporarily suppressed. In this way, false alarms caused by legitimate users can be suppressed.
[0078] The presence or absence of a "first trigger" may be detected, for example, by a detection unit 22 (an example of a detection means) that can detect the first trigger, and the control unit 21 (an example of a control means) may temporarily suppress the issuance of an alarm by the alarm device 25 (an example of an alarm means) when information that the first trigger has occurred is acquired from the detection unit 22. In this way, even if the control unit 21 is not provided with a function that can detect the first trigger, it can determine the presence or absence of the first trigger based on the information from the detection unit 22.
[0079] However, the present invention is not limited to this, and the authentication system 20 may not be provided with the detection unit 22, and the control unit 21 itself may have a function capable of detecting the first trigger.
[0080] The "first trigger" may indicate, for example, the satisfaction of a predetermined condition that allows objective determination that the user is about to use the vehicle 1. The "first trigger" may indicate, for example, that the user has touched the electronic key 2, that a predetermined operation has been performed on the electronic key 2, that the electronic key 2 has been held by the user, that the electronic key 2 has been moved within a predetermined distance range from the vehicle 1, that the vehicle door 9 has been opened, or that the vehicle door 9 has been unlocked.
[0081] For example, the user's touch of the electronic key 2 may be detected by a sensor that detects contact of an object with the electronic key 2. The user's holding of the electronic key 2 may be detected by a vibration sensor that is provided in the electronic key 2 and that detects vibrations. The opening of the vehicle door 9 may be detected by a door sensor that detects the opening and closing of the door. The unlocking of the vehicle 1 may be detected, for example, as follows.
[0082] For example, the vehicle 1 is provided with an answerback function in advance. The answerback function is a function in which the vehicle 1 responds to a user operation (e.g., an unlocking operation). The answerback function, for example, flashes the hazard lights or sounds a buzzer. When the user performs an unlocking operation, for example, the body ECU 12 transmits an unlock command signal to the vehicle door 9 (or an ECU that controls the operation of the vehicle door 9), thereby unlocking the vehicle door 9. At this time, the body ECU 12 transmits a predetermined command signal to an answerback execution device, and the execution device executes an operation according to the predetermined command signal. The detection unit 22 may then detect that the vehicle door 9 has been unlocked by monitoring the behavior of the execution device.
[0083] For example, when the answerback execution device is a hazard lamp, the body ECU 12 transmits a flashing command signal to the hazard lamp a predetermined number of times (for example, twice), and the hazard lamp flashes a predetermined number of times in response to the flashing command signal. Then, the detection unit 22 detects the flashing interval or the number of flashes of the hazard lamp, thereby detecting that the vehicle door 9 has been unlocked.
[0084] Also, for example, when the device that executes the answerback is a buzzer, the body ECU 12 transmits a sound command signal to the buzzer to sound a predetermined number of times (for example, twice), and the buzzer sounds the predetermined number of times in response to the sound command signal. The detection unit 22 detects the interval between sounds of the buzzer or the number of sounds, etc., to detect that the vehicle door 9 has been unlocked.
[0085] In addition, instead of the detection unit 22 directly monitoring the behavior of the answerback execution device, the detection unit 22 may indirectly monitor the behavior of the answerback execution device, for example, by monitoring a CAN (Controller Area Network) connected to each ECU in the vehicle 1.
[0086] The "authorized authentication operation" may include, for example, a first input operation of inputting authorized authentication information into a first input means capable of inputting authentication information, and a second input operation performed into a second input means inherently provided in the vehicle 1. The "authorized authentication operation" may also be, for example, a second input operation performed immediately after the first input operation. The second input operation may be performed as an input completion operation to instruct completion of input of authentication information in the first input operation. The authorized authentication operation means that authentication has been successful, and is considered to have been performed when, for example, correct authentication information has been input.
[0087] In this way, if only one of the first input operation or the second input operation is accepted, the vehicle 1 is not maintained in the non-monitoring state but remains in the monitoring state, and when both the first input operation and the second input operation are accepted, the vehicle 1 is maintained in the non-monitoring state. Also, for example, the second input means originally provided in the vehicle 1 can be used to instruct completion of input of authentication information in the first input operation. Therefore, higher security can be achieved without providing a new means for instructing completion of input of authentication information.
[0088] The authentication information may be registered (e.g., initially set) in advance in the control unit 21 or the like by a legitimate user (e.g., a purchaser of the authentication system 20). However, the present invention is not limited to this. For example, the legitimate authentication information may be registered in the control unit 21 or the like in advance by the seller at the design stage and notified to the purchaser of the authentication system 20 via a website or printed matter dedicated to the purchaser. Furthermore, when the authentication system 20 is installed in a vehicle 1 that is shared by unspecified persons, such as for car sharing or rental, the legitimate authentication information may be shared with authentication information (e.g., a telephone number) used in the car sharing or rental service. In this case, the user does not need to separately consider authentication information for the authentication system 20, thereby achieving high usability.
[0089] The "first input means" may be an operating member provided in the spatial region inside the vehicle 1, and may be the input device 24, for example.
[0090] The "second input means" may be, for example, the first receiving unit 6. In this way, for example, an input related to the operation of the engine of the vehicle 1, such as an operation normally performed when using the vehicle 1, can also be used as an input completion operation to instruct completion of input of authentication information. This improves user operability. Furthermore, since the first receiving unit 6 originally provided in the vehicle 1 is used for the input completion operation, there is no need to provide a separate operating member for performing the input completion operation.
[0091] The "second trigger" may indicate that a legitimate authentication operation has been accepted in a specific monitoring area of the vehicle 1. In this way, authentication operations by a user in a specific monitoring area can be performed while the vehicle 1 is in a monitoring state, without issuing an alarm.
[0092] The "specific monitored area" is, for example, an area where an authentication operation is performed, and one example of this is the spatial area inside the vehicle 1. In this way, the spatial area inside the vehicle 1 is set as the area where the user performs the authentication operation, and people present in the spatial area inside the vehicle 1 can be authenticated while suppressing the issuance of an alarm.
[0093] However, the present invention is not limited to this, and the authentication operation may be accepted at any location as long as it is possible to authenticate a person attempting to use vehicle 1. For example, the authentication operation may be accepted outside vehicle 1. In this case, for example, an input means for authentication information may be provided outside vehicle 1. For example, a sensor capable of detecting knocks may be provided on the body of vehicle 1 itself (e.g., a window, etc.), and the action of knocking on the body of vehicle 1 itself may be accepted as the authentication operation. Then, it may be determined whether the accepted knock pattern is a specific pattern. Considering that it is possible to authenticate a person who is actually present in the spatial region inside vehicle 1, it is particularly preferable that the input means for authentication information be provided in the spatial region inside vehicle 1.
[0094] [Detailed operation] Next, detailed operations of vehicle system 100 according to this embodiment will be described with reference to Figures 3 to 5. Figures 3 to 5 are flowcharts showing an example of control processing (for example, fraud prevention processing) executed by control unit 21 of authentication system 20.
[0095] First, in step S11 of FIG. 3, the control unit 21 determines whether the vehicle 1 has transitioned from a non-monitoring state to a monitoring state.
[0096] For example, when a user performs a locking operation to lock the vehicle door 9 of the vehicle 1, the vehicle door 9 of the vehicle 1 is locked and the vehicle 1 transitions from a non-monitoring state to a monitoring state. Examples of locking operations include pressing the second reception unit 7 of the vehicle door 9 while the electronic key 2 is located near the vehicle 1, or pressing the lock button on the electronic key 2 while the electronic key 2 is located near the vehicle 1. When the vehicle 1 transitions to the monitoring state, the process proceeds from step S11 to step S12.
[0097] Here, when the vehicle 1 transitions from the non-monitoring state to the monitoring state, for example, the control unit 21 starts monitoring the corresponding types of abnormalities in each of the multiple monitoring areas of the vehicle 1. This starts monitoring multiple types of abnormalities in the vehicle 1. The multiple monitoring areas are also referred to as, for example, multiple monitored areas.
[0098] The "multiple monitoring areas" may be determined to be areas of the vehicle that require monitoring, for example. Examples of such areas include one or more of the interior spatial area of the vehicle 1, the trunk, the hood, and other predetermined openable / closable portions of the vehicle 1, the first reception unit 6, and other areas. For example, various sensors may be provided in each of these monitoring areas, and the control unit 21 monitors abnormalities in each monitoring area by coordinating with the sensors provided in each monitoring area. An abnormality in the interior spatial area of the vehicle 1 may be detected, for example, by the movement of an object (e.g., a person) within the spatial area or the vibration of the vehicle 1. The movement of an object within the spatial area may be detected, for example, by a motion sensor, and the vibration of the vehicle 1 may be detected, for example, by a vibration sensor. An abnormality in the trunk, the hood, and other predetermined openable / closable portions of the vehicle 1 may be detected when the corresponding portion is opened. An abnormality in the first reception unit 6 may be detected when the first reception unit 6 is operated. The type of event that is detected as an anomaly depends on the structure or other characteristics of each monitored area.
[0099] In step S12, the control unit 21 determines whether or not high security is set. If it is determined that high security is set, the process proceeds from step S12 to step S51 (FIG. 5), and if it is determined that high security is not set, the process proceeds from step S12 to step S13.
[0100] The case where the process proceeds to step S13 (FIG. 3) will be described below. The case where the process proceeds to step S51 (FIG. 5) will be described later.
[0101] 3, when the vehicle 1 is in the monitoring state, the control unit 21 waits, for example, until it receives a non-monitoring command from the remote terminal 3 (step S13), accepts an authentication operation (step S14), or triggers B (an example of a first trigger) (step S17). In detail, the determination processes of steps S12, S13, S14, and S17 are repeated until it receives a non-monitoring command from the remote terminal 3, accepts an authentication operation, or triggers B.
[0102] First, in step S13, the control unit 21 determines whether or not a non-monitoring command has been received from the remote terminal 3 when the vehicle 1 is in the monitoring state. As described above, the non-monitoring command is a command for the vehicle 1 to transition to the non-monitoring state.
[0103] For example, when a user carrying the remote terminal 3 presses a non-monitoring command transmission button on the remote terminal 3 while in proximity to the vehicle 1, a non-monitoring command is transmitted from the remote terminal 3, and the communication unit 23 receives the non-monitoring command. As a result, the control unit 21 determines that a non-monitoring command has been received from the remote terminal 3, and the process proceeds from step S13 to step S23.
[0104] In step S23, the control unit 21 transitions the vehicle 1 to a non-monitoring state. For example, the control unit 21 transitions the vehicle 1 from a monitoring state to a non-monitoring state. In detail, the control unit 21 transitions all of the multiple monitoring areas of the vehicle 1 from the monitoring state to the non-monitoring state. As a result, abnormality monitoring in all of the multiple monitoring areas inside the vehicle 1 is stopped.
[0105] In this way, when the control unit 21 receives a predetermined signal (e.g., a non-monitoring command signal) from the remote terminal 3 (an example of a remote operation terminal), the control unit 21 transitions the vehicle 1 to the non-monitoring state and maintains it there, regardless of whether the first trigger is present or not, and whether the second trigger indicating that a valid authentication operation has been accepted is present or not (step S22 described below). In this way, even if the user does not perform a valid authentication operation, when the control unit 21 receives a predetermined signal from the remote terminal 3 that is distinguishable from a signal from the electronic key 2, the vehicle 1 can be transitioned to the non-monitoring state and maintained there. Therefore, it is possible to achieve high security while improving user convenience.
[0106] On the other hand, if it is determined in step S13 that the non-monitoring command has not been received from the remote terminal 3, the process proceeds from step S13 to step S14.
[0107] In step S14, the control unit 21 determines whether or not the authentication operation has been accepted. The processing content of this step S14 is the same as the processing content of step S19, which will be described later, and therefore the details thereof will be described later.
[0108] For example, if the authentication operation has not been accepted, the process proceeds from step S14 to step S17, and if the authentication operation has been accepted, the process proceeds from step S14 to step S15.
[0109] In step S15, the control unit 21 determines whether or not there has been a trigger A (an example of a second trigger) indicating that the legitimate first authentication operation or the legitimate second authentication operation has been accepted. If there has been a trigger A, the process proceeds from step S15 to step S23, and if there has not been a trigger A, the process proceeds from step S15 to step S16.
[0110] In step S16, the control unit 21 causes the alarm device 25 to issue an alarm.
[0111] If the authentication operation is not accepted in step S14 and the process proceeds from step S14 to step S17, the control unit 21 determines whether or not trigger B has occurred (step S17).
[0112] If it is determined that trigger B does not exist, the process returns to step S12 again, whereas if it is determined that trigger B exists, the process proceeds from step S17 to step S18.
[0113] Here, if it is determined that trigger B has occurred, the control unit 21 temporarily suppresses the issuance of an alarm by the alarm device 25 while maintaining the vehicle 1 in a monitoring state. For example, the control unit 21 temporarily suppresses the issuance of an alarm for a specific monitoring area that is a part of the multiple monitoring areas. In detail, while maintaining the monitoring state for the vehicle 1 as a whole, the control unit 21 temporarily cancels the monitoring state for abnormalities in the specific monitoring area that is a part of the multiple monitoring areas, thereby temporarily suppressing the issuance of an alarm for the specific monitoring area.
[0114] In addition, among the multiple monitoring areas (also referred to as multiple monitored areas, for example), a specific area different from the specific monitoring area (for example, the remaining monitoring area excluding the specific monitoring area) remains in a monitoring state.
[0115] The "specific monitored area" includes, for example, the spatial area inside the vehicle 1, so even if a user opens the vehicle door 9 and enters the spatial area inside the vehicle 1, an alarm will not be immediately issued by the alarm device 25. Conversely, even if the monitoring state in the "specific monitored area" is temporarily canceled, the monitoring state will continue for areas that still require monitoring, and if an abnormality is detected in that area, an alarm will be issued by the alarm device 25.
[0116] In this way, for example, when trigger B indicating that a predetermined action has been received from outside the vehicle 1 while the vehicle 1 is in a monitoring state is detected, the control unit 21 temporarily suppresses the issuance of an alarm by the alarm device 25. When it is determined that trigger B has been detected, the control unit 21 starts timing processing.
[0117] In step S18, the control unit 21 determines whether or not a predetermined time has elapsed since the trigger B. The predetermined time may be set to a fixed value in advance, or may be set by the user.
[0118] For example, if the person performing the authentication operation takes time to complete the authentication operation and the predetermined time has passed, it is determined in step S18 that the predetermined time has passed since trigger B, and the process proceeds from step S18 to step S24. Also, for example, even if an authentication operation is accepted after trigger B, if a predetermined time has passed after a first input operation without a second input operation being accepted, it is also determined in step S18 that the predetermined time has passed since trigger B, and the process proceeds from step S18 to step S24. In step S24, the control unit 21 causes the alarm device 25 to issue an alarm. Details of step S24 will be described later.
[0119] In this way, the time when trigger B occurs becomes, for example, the start time of the time limit for performing a normal authentication operation, and if the normal authentication operation is not performed within that time limit, an alarm is issued by alarm device 25.
[0120] On the other hand, if the predetermined time has not yet elapsed since trigger B, the process proceeds from step S18 to step S19.
[0121] In step S19, the control unit 21 determines whether the authentication operation has been accepted.
[0122] If the authentication operation has not been accepted, the process proceeds from step S19 to step S20, and if the authentication operation has been accepted, the process proceeds from step S19 to step S22. The case where the process proceeds to step S22 will be described below. The case where the process proceeds to step S20 will be described later.
[0123] In step S22, the control unit 21 determines whether or not there has been a trigger C (an example of a second trigger) indicating that a legitimate first authentication operation or a legitimate second authentication operation has been accepted. In detail, the control unit 21 determines whether or not the first authentication operation or the second authentication operation accepted in step S19 is a legitimate authentication operation. Here, the reason why not only the second authentication operation but also the first authentication operation is permitted is to reduce the operational burden related to authentication on a legitimate user.
[0124] For example, when a user performs a first authentication operation, the user inputs authentication information using input device 24, and then operates first reception unit 6 (for example, by pressing once; the same applies below). As a result, control unit 21 accepts the authentication operation of inputting authentication information (an example of a first input operation) and operating first reception unit 6 (an example of a second input operation) (step S19).
[0125] The process then proceeds from step S19 to step S22, where the control unit 21 performs user authentication by comparing the authentication information input using the input device 24 with pre-registered legitimate authentication information.
[0126] For example, when the input authentication information matches the legitimate authentication information and user authentication is successful, the control unit 21 determines in step S22 that trigger C has occurred, indicating that a legitimate authentication operation (e.g., a legitimate first authentication operation) has been accepted.
[0127] Then, the process proceeds from step S22 to step S23, where the control unit 21 transitions the vehicle 1 from the monitoring state to the non-monitoring state.
[0128] For example, the control unit 21 maintains in the non-monitoring state a specific monitoring area (for example, a spatial area inside the vehicle 1) that was temporarily shifted to a non-monitoring state in response to the trigger B, and shifts the remaining monitoring areas that were still in the monitoring state at the time of the trigger B from the monitoring state to the non-monitoring state and maintains them in this state. This stops abnormality monitoring in all of the multiple monitoring areas of the vehicle 1.
[0129] In this way, when trigger B occurs while vehicle 1 is in the monitoring state, control unit 21 temporarily suppresses the issuance of an alarm for a specific monitoring area, which is a part of the multiple monitoring areas, and when trigger C occurs, control unit 21 cancels the abnormality monitoring state for all of the multiple monitoring areas. Conversely, when trigger C does not occur, the abnormality monitoring state for all of the multiple monitoring areas is not canceled. For example, even if the abnormality monitoring state for a specific monitoring area is temporarily canceled in response to trigger B, if a valid authentication operation is not accepted in the specific monitoring area, the abnormality monitoring state for all of the multiple monitoring areas is not canceled. Therefore, high security can be achieved.
[0130] On the other hand, if there is no trigger C indicating that a valid authentication operation has been accepted, the process proceeds from step S22 to step S24 (described below). For example, if the input authentication information does not match the valid authentication information and user authentication fails, the control unit 21 determines in step S22 that a valid authentication operation has not been accepted (for example, that an incorrect authentication operation has been accepted). Then, the process proceeds from step S22 to step S24.
[0131] In this embodiment, the authentication operation can be accepted only once, and an alarm is triggered if an incorrect authentication operation is performed even once, but this is not limited to this, and the authentication operation can be accepted multiple times (for example, three times).
[0132] Next, the case where the process proceeds from step S19 to step S20 will be described.
[0133] In step S20, the control unit 21 determines whether or not a non-monitoring command has been received from the remote terminal 3 when, for example, a specific monitoring area of the vehicle 1 is temporarily in a non-monitoring state. Note that step S13 and step S20 in Fig. 3 differ in, for example, whether all of the multiple monitoring areas of the vehicle 1 are in a monitoring state or whether some of the multiple monitoring areas (such as a specific monitoring area) are in a temporarily non-monitoring state.
[0134] For example, after trigger B, the user presses the non-monitoring command transmission button of the remote terminal 3 in the spatial region inside the vehicle 1. In response to this, the remote terminal 3 transmits a non-monitoring command, and the control unit 21 determines in step S20 that the non-monitoring command has been received from the remote terminal 3.
[0135] When a non-monitoring command is received from the remote terminal 3, the process proceeds from step S20 to step S23, and the process of transitioning the vehicle 1 to a non-monitoring state is executed in the same manner as described above.
[0136] On the other hand, if a non-monitoring command has not been received from the remote terminal 3, the process proceeds from step S20 to step S21, where the control unit 21 determines whether or not an abnormality has been detected in the remaining monitoring areas (e.g., predetermined monitoring areas that are still maintained in a monitoring state) of the multiple monitoring areas excluding a specific monitoring area of the vehicle 1 (e.g., the spatial area inside the vehicle 1). The remaining monitoring area may be, for example, an area different from the area where the authentication operation is performed (in this embodiment, the spatial area inside the vehicle 1). Examples of such areas include one or more of the trunk, hood, first reception unit 6, and other areas of the vehicle 1.
[0137] If an abnormality is detected in the remaining monitoring area between when trigger B occurs (step S17) and when trigger C occurs (step S22), the process proceeds from step S21 to step S24. On the other hand, if no abnormality is detected in the remaining monitoring area, the process returns to step S18.
[0138] On the other hand, if it is determined in step S21 that an abnormality has been detected in the remaining monitoring area that is still in the monitoring state, the alarm device 25 issues an alarm (step S24).
[0139] In this way, an alarm is issued when an abnormality is detected in a predetermined area different from the specific monitoring area between the occurrence of trigger B and the occurrence of trigger C. In this way, even if the abnormality monitoring state is temporarily canceled in some monitoring areas (for example, the spatial area inside vehicle 1) in response to the occurrence of trigger B, an alarm is immediately issued when an abnormality is detected in another predetermined area, thereby making it possible to prevent fraudulent acts such as theft of vehicle 1 itself or vehicle accessories.
[0140] Next, step S24 in FIG. 3 will be described in detail.
[0141] As mentioned above, When a normal authentication operation is not accepted within a predetermined time period after the occurrence of trigger B (step S17) (YES in step S18), When the authentication operation accepted in step S19 is different from the normal authentication operation (NO in step S22), or When an abnormality is detected in a monitoring area other than the specific monitoring area between when trigger B occurs (step S17) and when trigger C occurs (step S22) (YES in step S21). At this time, the control unit 21 activates an alarm using the alarm device 25 (step S24).
[0142] In detail, the control unit 21 does not maintain the vehicle 1 in a non-monitoring state (for example, this can also be said to not allow the vehicle 1 to be maintained in a non-monitoring state), and releases the temporary suppression of the issuance of an alarm by the alarm device 25. Then, the alarm device 25 issues an alarm (step S24).
[0143] In this way, even if a malicious third party enters the internal spatial region of the vehicle 1, an alarm will be issued if any of the above actions are subsequently performed (step S24). This makes it possible to discourage malicious third parties from committing fraud such as vehicle theft, thereby achieving high security.
[0144] The cause of the alarm being issued was: When the proper authentication operation is not accepted within a specified time from when Trigger B occurs, When the accepted authentication behavior is different from the normal authentication behavior, When an abnormality is detected in a monitoring area other than a specific monitoring area among multiple monitoring areas, It is preferable that different alarms (for example, alarms of different volumes or different types) be activated depending on whether the alarm is a fault or a malfunction.
[0145] In this way, even if the user is unintentionally unable to perform a normal authentication operation after trigger B occurs and an alarm is issued, the user can know the cause of the failure. As a result, for example, the user can take appropriate action in the next or subsequent authentication operation according to the cause that was known when the previous alarm was issued.
[0146] If an alarm is issued in step S24, the process proceeds from step S24 (FIG. 3) to step S31 (FIG. 4).
[0147] The operation after the alarm is issued in step S24 (Fig. 3) will be described with reference to the flowchart in Fig. 4. The alarm from the alarm device 25 will automatically stop after a certain period of time has elapsed, for example.
[0148] First, in step S31, the control unit 21 determines whether or not high security is set. If it is determined that high security is set, the process proceeds from step S31 to step S51 (FIG. 5) described later, and if it is determined that high security is not set, the process proceeds from step S31 to step S32.
[0149] Then, in step S32, the control unit 21 determines whether or not a non-monitoring command has been received from the remote terminal 3 when the vehicle 1 is in the monitoring state.
[0150] When the non-monitoring command is received from the remote terminal 3, the process proceeds from step S32 to step S40, and the control unit 21 transitions the vehicle 1 from the monitoring state to the non-monitoring state. At this time, if an alarm is being issued, the control unit 21 stops the alarm from being issued by the alarm device 25.
[0151] On the other hand, if the non-monitoring command has not been received from the remote terminal 3, the process proceeds from step S32 to step S33.
[0152] Then, the control unit 21 determines whether or not the authentication operation has been accepted (step S33).
[0153] When the authentication operation is accepted in step S33, the process proceeds from step S33 to step S34, where the control unit 21 determines whether or not trigger D (an example of a second trigger) is present. Trigger D indicates that the authentication operation accepted in step S33 was a regular second authentication operation. The control unit 21 does not determine that trigger D has been present even if the first authentication operation has been performed.
[0154] For example, if a legitimate second authentication operation different from the legitimate first authentication operation is not performed, the process proceeds from step S34 to step S41, and the alarm is activated again. On the other hand, if trigger D is detected, the process proceeds from step S34 to step S40, and the control unit 21 transitions the vehicle 1 from the monitoring state to the non-monitoring state.
[0155] On the other hand, if the authentication operation is not accepted in step S33, the process proceeds from step S33 to step S35, where the control unit 21 determines whether or not trigger E (an example of a first trigger) has occurred (step S35). Trigger E indicates the same condition as trigger B.
[0156] If trigger E is detected, the process proceeds from step S35 to step S36, and the control unit 21 starts timing processing and determines whether a predetermined time has elapsed since trigger E was detected (step S36). Note that the process contents of steps S35, S36, etc. in Fig. 4 are similar to the process contents of steps S17, S18, etc. in Fig. 3, and therefore detailed description thereof will be omitted.
[0157] For example, if a predetermined time has elapsed without the authentication operation being accepted, the process proceeds from step S36 to step S41, and the control unit 21 causes the alarm device 25 to issue an alarm again (step S41).
[0158] On the other hand, if the predetermined time has not yet elapsed, the process proceeds from step S36 to step S37, where the control unit 21 determines whether or not the authentication operation has been accepted.
[0159] If the authentication operation has not been accepted, the process proceeds from step S37 to step S39, where the control unit 21 determines whether or not a non-monitoring command has been received from the remote terminal 3. If a non-monitoring command has been received from the remote terminal 3, the process proceeds from step S39 to step S40, and if a non-monitoring command has not been received from the remote terminal 3, the process returns from step S39 to step S36 again.
[0160] On the other hand, if the authentication operation is accepted in step S37, the process proceeds from step S37 to step S38.
[0161] For example, after operating first reception unit 6, the user inputs authentication information using input device 24, and then performs an authentication operation by operating first reception unit 6 (an example of an "authentication operation different from the first authentication operation"). As a result, control unit 21 accepts the authentication operation of inputting authentication information (an example of a first input operation) and an operation on first reception unit 6 (an example of a second input operation) (step S37). Then, the process proceeds from step S37 to step S38.
[0162] In step S38, the control unit 21 determines whether or not trigger F (an example of a second trigger) occurred in step S37. Trigger F indicates that a regular second authentication operation has been performed. As with trigger D, the control unit 21 does not determine that trigger F has occurred even if the first authentication operation has been performed.
[0163] For example, if it is determined that there is no trigger F, the process proceeds from step S38 to step S41, and the alarm is activated again. If it is determined that there is a trigger F, the process proceeds from step S38 to step S40.
[0164] Then, the control unit 21 transitions the vehicle 1 from the monitoring state to the non-monitoring state (step S40). More specifically, all of the multiple monitoring areas of the vehicle 1 transition from the monitoring state to the non-monitoring state and maintain this state. At this time, if an alarm is being issued, the control unit 21 stops the alarm from being issued by the alarm device 25.
[0165] As described above, if a trigger F occurs after the alarm is issued (step S24), the control unit 21 transitions the vehicle 1 from the monitoring state to the non-monitoring state (step S40).
[0166] In this way, even if the regular first authentication operation or regular second authentication operation is not accepted after trigger E occurs and vehicle 1 enters a monitoring state (step S24), when the user performs a regular second authentication operation, authentication system 20 determines that trigger F has occurred and vehicle 1 transitions to a non-monitoring state (step S40). Therefore, even if a third party takes a long time to perform the first authentication operation, it is possible to prevent the vehicle from being maintained in a non-monitoring state by assuming that the first authentication operation is a regular authentication operation.
[0167] In this way, after a predetermined period of time has passed since trigger B and an alarm has been issued by the alarm device 25, the control unit 21, for example, increases the number of steps required by the user in the legitimate authentication operation. In this way, as long as the legitimate authentication operation is performed by the user, the increase in the burden on the user is suppressed, and if there is an error in the authentication operation, an alarm is issued and the number of steps required by the user is increased, thereby reducing the possibility of erroneously authenticating a person who is not a legitimate user as the legitimate user. For example, after an alarm has been issued by the alarm device 25, the control unit 21 requests that the second authentication operation be performed instead of the first authentication operation when the user performs the authentication operation.
[0168] [If high security settings are enabled] Next, a case where high security settings are made will be described.
[0169] If high security is set, the process proceeds from step S12 in FIG. 3 to step S51 in FIG.
[0170] The processing details of steps S51, S52, S54-S59, S61, and S62 in FIG. 5 are generally the same as the processing details of steps S13, S14, S16-S21, S23, and S24 in FIG. 3. Therefore, the following description of steps S51, S52, S54-S59, S61, and S62 in FIG. 5 will be omitted. However, trigger G (an example of a second trigger), trigger H (an example of a first trigger), and trigger I (an example of a second trigger) shown in FIG. 5 indicate the same conditions as triggers D, E, and F, respectively. The remote terminal 3 transmits a signal having a data portion different from that transmitted by the electronic key 2. The data portion may be different, for example, because it contains information unique to the remote terminal 3, such as an identifier (unique ID), authentication information, or a command. Furthermore, the remote terminal 3 and the electronic key 2 may use different frequencies for wireless communication. When the authentication system 20 receives a signal from the remote terminal 30, it transitions the vehicle 1 to a non-monitoring state and maintains it there, regardless of whether the triggers G, H, or I are present. This prevents fraudulent authentication from being judged as legitimate authentication by falsifying data sent by the electronic key 2.
[0171] When the process proceeds to step S60 via steps S51, S52, S55 to S57, etc., the control unit 21 determines whether or not a valid second authentication operation has been accepted. In step S60, the control unit 21 determines whether or not a trigger I has occurred. The process content of step S53 is the same as the process content of step S60.
[0172] In detail, after operating first reception unit 6, the user inputs authentication information using input device 24, and then performs an authentication operation by operating first reception unit 6, and control unit 21 accepts the authentication operation by the user (step S57). Then, control unit 21 compares the authentication information input using input device 24 in step S57 with regular authentication information registered in advance in control unit 21 to perform user authentication.
[0173] If the input authentication information matches the authorized authentication information and user authentication is successful, the control unit 21 determines in step S60 that trigger I has occurred, indicating that an authorized authentication operation (e.g., an authorized second authentication operation) has been accepted. Then, the process proceeds from step S60 to step S61, and the control unit 21 transitions the vehicle 1 from the monitoring state to the non-monitoring state.
[0174] For example, the control unit 21 maintains in the non-monitoring state a specific monitoring area (for example, a spatial area inside the vehicle 1) that was temporarily shifted to a non-monitoring state in response to the trigger H, and shifts the remaining monitoring areas that were still in the monitoring state at the time of the trigger H from the monitoring state to the non-monitoring state and maintains them in this state. This stops abnormality monitoring in all of the multiple monitoring areas of the vehicle 1.
[0175] On the other hand, if the input authentication information does not match the legitimate authentication information and user authentication fails, the control unit 21 determines in step S60 that the legitimate authentication operation (e.g., the legitimate second authentication operation) was not accepted (also, for example, that there was no trigger I indicating that the legitimate authentication operation was accepted).
[0176] Then, the process proceeds from step S60 to step S62, and the control unit 21 causes the alarm device 25 to issue an alarm.
[0177] As described above, in the authentication system 20 according to this embodiment, when the first trigger occurs while the vehicle 1 is in a monitoring state, the control unit 21 temporarily suppresses the issuance of an alarm by the alarm device 25, and when the second trigger occurs, which indicates that a valid authentication operation has been accepted, the control unit 21 maintains the vehicle 1 in a non-monitoring state.
[0178] Since the authentication system 20 maintains the non-monitoring state on the condition that a trigger (second trigger) indicating that a legitimate authentication operation has been accepted has been received, the security is higher than when this condition is not required. For example, a technology is conceivable in which the vehicle 1 is transitioned from the monitoring state to the non-monitoring state by having the user perform a predetermined operation without authenticating the user. However, with such a technology, if a third party knows how the technology works, the third party can transition the vehicle 1 to the non-monitoring state by performing the predetermined operation. In this embodiment, the authentication operation is involved, so the possibility of a third party other than the legitimate user committing fraud, such as theft of the vehicle, is reduced.
[0179] Furthermore, since the first trigger suppresses the issuance of an alarm, false alarms are prevented from being issued when a legitimate user is performing an authentication operation. For example, when a legitimate user enters vehicle 1 to perform an authentication operation, if the issuance of an alarm due to an abnormality detected inside vehicle 1 is suppressed, the possibility of a false alarm being issued despite the user being legitimate is reduced. Furthermore, when a legitimate user enters vehicle 1, vibrations may occur in vehicle 1. However, if the issuance of an alarm due to an abnormality detected due to the vibrations is suppressed, the possibility of a false alarm being issued despite the user being legitimate is reduced. Conversely, if an alarm is set to be issued if an abnormality is detected in an area other than the area where the authentication operation is performed (for example, the above-mentioned "remaining monitoring area"), it is possible to both suppress false alarms due to legitimate users and prevent fraudulent activity due to third parties.
[0180] Furthermore, the period during which authentication operations can be performed while the issuance of an alarm is suppressed is limited to a temporary period from the time the first trigger occurs, which can also be a desirable basis from a security standpoint.
[0181] For the above reasons, according to this embodiment, it is possible to enhance security while suppressing the issuance of false alarms. Furthermore, in addition to preventing fraudulent acts such as theft of the vehicle 1 by a third party, the authentication system 20 can be said to propose a security technology that is different from conventional ones in that it suppresses the issuance of false alarms caused by authorized users and suppresses the occurrence of undesirable situations for the authorized users.
[0182] [Variations] Although an example of an embodiment of the present invention has been described above, the present invention is not limited to the above embodiment and various modifications are possible. For example, the following modifications may be made.
[0183] (1) For example, in the above embodiment, the "authorized authentication operation" includes, but is not limited to, a first input operation of inputting authorized authentication information to a first input means (e.g., input device 24) capable of inputting authentication information, and a second input operation performed to a second input means inherently provided in vehicle 1.
[0184] For example, the "authorized authentication operation" may be only the first input operation. Even in this case, if the authorized authentication information is not input, the vehicle 1 is not maintained in the non-monitoring state but is switched to the monitoring state, thereby achieving high security.
[0185] (2) In addition, the following may be adopted as "authentication information."
[0186] For example, facial recognition may be employed in the authentication operation, and facial image information may be employed as "authentication information" input using the first input means. In this case, when determining whether or not a legitimate authentication operation has been accepted, facial image information captured and input by a camera (an example of the first input means) provided in a spatial region inside the vehicle 1 may be compared with legitimate facial image information registered in advance to perform facial recognition.
[0187] Alternatively, fingerprint authentication may be employed for the authentication operation, and fingerprint information may be used as "authentication information" input using the first input means. In this case, when determining whether or not a legitimate authentication operation has been accepted, fingerprint information detected and input by a fingerprint reader (an example of the first input means) provided in a spatial region inside the vehicle 1 may be compared with legitimate fingerprint information registered in advance to perform fingerprint authentication.
[0188] The authentication methods are not limited to these, and various authentication methods (for example, vocal cord authentication) may be adopted, and a plurality of authentication methods may be combined. Also, it may be possible for a user or the like to set in advance which of a plurality of authentication methods to use for the authentication operation.
[0189] (3) In the above embodiments, user authentication is not performed for the first trigger, but is performed for the second trigger, but this is not limiting. For example, user authentication may be performed for both the first trigger and the second trigger.
[0190] In this case, it is particularly preferable that the authentication method for the user authentication at the first trigger and the authentication method for the user authentication at the second trigger are different types. For example, the first trigger may be the unlocking of the vehicle door 9 due to successful user authentication using the digital key system, and the second trigger may be the success of user authentication using the input device 24.
[0191] (4) In addition, in the above-described embodiments, the remote terminal 3 is provided in the vehicle system 100, but the remote terminal 3 does not necessarily have to be provided in the vehicle system 100. However, as described above, if the remote terminal 3 is provided, the user can cause the vehicle 1 to transition to a non-monitoring state without performing an authentication operation by sending a non-monitoring command from the remote terminal 3.
[0192] (5) In the above-described embodiment, the authentication system 20 temporarily suppresses the issuance of an alarm while the entire vehicle 1 remains in a monitoring state when the first trigger is generated. However, this is not limited to this. For example, instead, the authentication system 20 may temporarily suppress the issuance of an alarm by transitioning the entire vehicle 1 from a monitoring state to a non-monitoring state when the first trigger is generated. In this case, the authentication system 20 maintains the vehicle 1 in a non-monitoring state if a legitimate authentication operation is performed within a predetermined period from the first trigger. Otherwise, the authentication system 20 returns the vehicle 1 from the non-monitoring state to a monitoring state. In this case, the condition for maintaining the non-monitoring state is the acceptance of a legitimate authentication operation, which provides high security. In addition, the period during which authentication operation can be performed without an alarm is limited to a temporary period from the first trigger, which may also be desirable from a security perspective. In this modification, the entire vehicle 1 remains in a non-monitoring state until a legitimate authentication operation is performed, but this temporary period poses few security issues.
[0193] (6) In the above embodiments, the input device 24 is exemplified as the "first input means," but this is not limiting. For example, the "first input means" may be a mobile terminal such as a smartphone or a tablet computer. In the case where the mobile terminal is a smartphone, authentication information (e.g., a terminal ID, a user ID, a password, a one-time key, or a phone number) may be exchanged between the communication unit 23 of the authentication system 20 and a predetermined application installed on the smartphone, and the control unit 21 may perform user authentication using the authentication information received from the application via the communication unit 23. In this manner, a so-called "digital key system" using a smartphone may be used. This allows the user to perform user authentication using their own smartphone or the like, rather than using an operating member installed in a spatial region inside the vehicle 1, i.e., an operating member that can be used by anyone who enters the vehicle 1, thereby achieving higher security.
[0194] It is preferable to adopt a system that allows authentication to be performed only when the distance between the smartphone and the vehicle 1 (specifically, the communication unit 23) is relatively short. For example, a wireless communication system with a limited communication area, such as Bluetooth (registered trademark), BLE (Bluetooth Low Energy), Wi-Fi communication, or near-field communication (NFC (Near Field Communication)), may be adopted as the wireless communication system between the smartphone and the communication unit 23 of the authentication system 20. In this way, user authentication is performed only when the owner of the smartphone is relatively close to the vehicle 1, thereby achieving high security.
[0195] However, without being limited thereto, communication between the smartphone and the communication unit 23 may be performed via a public network such as LTE (Long Term Evolution) or mobile communication. In this case, even if the owner of the smartphone is relatively far from the vehicle 1, the smartphone and the communication unit 23 of the vehicle 1 can communicate with each other to notify the owner of the smartphone that the first trigger has occurred, for example. In this way, for example, even if the user is relatively far from the vehicle 1, the user can use his or her own smartphone to confirm that there is a possibility of fraud, such as theft of the vehicle 1. As a result, for example, if the user who receives the notification immediately returns to the vehicle 1, such fraud can be prevented in advance.
[0196] (7) In the above-described embodiments, the control unit 21 executes the authentication process based on the authentication information input using an input means such as the input device 24. However, the present invention is not limited to this. For example, the control unit 21 may not execute the authentication process itself, but may instead have a server on a network execute the authentication process. In this case, for example, the communication unit 23 of the authentication system 20 may transmit the authentication information entered by the user to an external server and receive the authentication result from the external server, and the control unit 21 may determine whether the authentication operation has been accepted based on the authentication result.
[0197] (8) In the above-described embodiment, the authentication system 20 temporarily suppresses issuance of an alarm when a first trigger is generated, and maintains the vehicle in a non-monitoring state when a second trigger is generated. Alternatively, the authentication system 20 may temporarily suppress issuance of an alarm when a second trigger is generated, and maintain the vehicle in a non-monitoring state when a first trigger is generated. In this modification, the events generated by the first trigger and the events generated by the second trigger are interchanged with those in the above-described embodiment. As such, one aspect of the present invention may be a system comprising: an alarm means having a function of generating an alarm when an abnormality is detected while the vehicle is in a monitoring state; and a control means temporarily suppressing the generation of an alarm by the alarm means when a second trigger is generated, indicating that a legitimate authentication operation has been accepted while the vehicle is in a monitoring state, and maintaining the vehicle in a non-monitoring state when the first trigger is generated. In this manner, even in such a system, the non-monitoring state is maintained only when a second trigger is generated, indicating that a legitimate authentication operation has been accepted, thereby providing high security. Furthermore, since the second trigger suppresses the issuance of an alarm, false alarms are prevented from being issued when an authorized user is about to use the vehicle. Furthermore, the period during which the vehicle can be maintained in a non-monitoring state without issuing an alarm is limited to a temporary period from the second trigger, which may also be desirable from a security standpoint. According to the authentication system 20 of this modified example, it is possible to enhance security while suppressing false alarms. This invention not only aims to prevent fraudulent acts such as vehicle theft by third parties, but also aims to suppress false alarms issued by authorized users and prevent undesirable situations from occurring for the authorized user.
[0198] (9) Furthermore, the functions of the systems according to the above-described embodiments and modifications may be implemented as a program executable by a computer.
[0199] In this way, high security can be achieved by installing the program on a computer and causing the functions according to the above-described embodiments and modifications to be realized.
[0200] The "computer" is not limited to a PC (personal computer), but may be, for example, an electronic device that can be executed under microcomputer control.
[0201] (10) Furthermore, the functions of the systems according to the above-described embodiments and modifications may be implemented as a storage medium storing a program that can be executed by a computer.
[0202] In this way, a high level of security can be achieved by installing the program from the storage medium onto a computer and achieving the effects of each of the above-described embodiments and modifications.
[0203] [Other extension examples] The above-described embodiments and modifications are merely examples, and it goes without saying that partial substitution or combination of the configurations shown in each embodiment and each modification is possible, and the components described in each embodiment and each modification may be combined in any manner. For example, the control unit 21 may execute one process of each embodiment and each modification in parallel with another process (e.g., multitasking).
[0204] Furthermore, the invention and each component described in the Summary of the Invention may be further applied to a combination of each component of each embodiment and each modification. Similar effects resulting from similar configurations of multiple embodiments and multiple modifications will not be mentioned sequentially for each embodiment and modification. Furthermore, the present invention is not limited to the above-described embodiments. For example, it will be obvious to those skilled in the art that various modifications, improvements, combinations, etc. are possible. [Explanation of symbols]
[0205] 1 vehicle 2 Electronic Key 3 Remote Terminal 6. Reception Section 1 7. Second Reception Section 9 Vehicle Door 10 Electronic key system 11 Electronic key ECU 12 Body ECU 20 Authentication System 21 Control Unit 22 Detection unit 23 Communications Department 24 Input Devices 25 Alarm
Claims
1. an alarm means having a function of issuing an alarm when an abnormality is detected while the vehicle is in a monitoring state; a control means for temporarily suppressing the issuance of an alarm by the alarm means when a first trigger is detected while the vehicle is in a monitoring state, and for maintaining the vehicle in a non-monitoring state when a second trigger is detected, the second trigger indicating that a valid authentication operation has been received; A system comprising:
2. When the normal authentication operation is not received, the control means does not maintain the vehicle in a non-monitoring state, and cancels the temporary suppression of the issuance of an alarm by the alarm means.
2. The system of claim 1.
3. The normal authentication operation is an input operation of inputting normal authentication information to an input means.
3. The system according to claim 1 or claim 2.
4. The authorized authentication operation includes a first input operation of inputting authorized authentication information to a first input means, and a second input operation of inputting authorized authentication information to a second input means that is originally provided in the vehicle. The system according to any one of claims 1 to 3.
5. The second input means is a means for receiving an input related to the operation of the prime mover of the vehicle.
5. The system of claim 4.
6. The control means determines the first authentication operation as the regular authentication operation before a predetermined period has elapsed since the first trigger occurred, and prohibits the first authentication operation from being the regular authentication operation after the predetermined period has elapsed. The system according to any one of claims 1 to 5.
7. If the predetermined period has elapsed, The alarm means issues an alarm, The control means determines a second authentication operation, which is an additional user procedure compared to the first authentication operation, as the regular authentication operation. The system of claim 6 .
8. The first trigger indicates that a predetermined action is received when the vehicle is unlocked. The system according to any one of claims 1 to 7.
9. The control means maintains the vehicle in a non-monitoring state when a predetermined signal having a data portion different from that transmitted by the electronic key or a predetermined signal having a frequency different from that used for wireless communication by the electronic key is received from a remote control terminal different from that of the electronic key attached to the vehicle. The system according to any one of claims 1 to 8.
10. a detection means capable of detecting the first trigger; Furthermore, The control means has a determination function of temporarily suppressing the issuance of an alarm by the alarm means and determining whether or not to maintain the vehicle in a non-monitoring state when information indicating that the first trigger has occurred is acquired from the detection means. The system according to any one of claims 1 to 9.
11. the warning means has a function of issuing a warning when an abnormality is detected in a specific monitoring area of the vehicle while the vehicle is in a monitoring state, The second trigger indicates that the legitimate authentication operation has been accepted in the specific monitoring area. The system according to any one of claims 1 to 10.
12. The specific monitoring area includes a spatial area inside the vehicle. The system of claim 11 .
13. When the vehicle is in a monitoring state, abnormalities are monitored in each of a plurality of monitoring areas of the vehicle, The control means When the first trigger occurs while the vehicle is in a monitoring state, issuance of an alarm for the specific monitoring area, which is a part of the plurality of monitoring areas, is temporarily suppressed; When the second trigger occurs, the abnormality monitoring state in all of the plurality of monitoring areas is cancelled.
13. The system according to claim 11 or claim 12.
14. The alarm means issues an alarm when an abnormality is detected in a predetermined area different from the specific monitoring area during the period from the first trigger to the second trigger.
14. The system of claim 13.
15. an alarm means having a function of issuing an alarm when an abnormality is detected while the vehicle is in a monitoring state; a control means for temporarily suppressing the issuance of an alarm by the alarm means when a second trigger indicating that a valid authentication operation has been received while the vehicle is in a monitoring state, and for maintaining the vehicle in a non-monitoring state when the first trigger is received; A system comprising:
16. A program for causing a computer to realize the functions of the system according to any one of claims 1 to 15.
Citation Information
Patent Citations
Voice theft protective device for construction machine
JP2002019583A
Theft preventing system, theft prevention device, theft prevention cooperating device, and multimedia device
JP2004030480A
Theft alarm device for vehicle
JP2007015598A
Anti-theft control device
JP2010137751A
Abnormality detection and vehicle tracking device
JP2010208380A