Vehicle and authentication method

The vehicle system manages user and vehicle information to enable or disable functions based on payment, ensuring only paying users can access additional features across different vehicles, addressing security and convenience issues in car-sharing scenarios.

JP2025139279APending Publication Date: 2025-09-26PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024038117
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-12
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

Existing vehicle function update mechanisms allow additional features added by one user to be used by subsequent users without payment, increasing security risks and inconvenience in car-sharing scenarios.

Method used

A vehicle system connected to a server via a network that acquires and manages user and vehicle information to enable or disable functions based on payment, ensuring only paying users can access additional features across different vehicles.

Benefits of technology

Ensures that only authorized users can utilize additional vehicle functions, preventing unauthorized access and maintaining payment-based functionality across various vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025139279000001_ABST
    Figure 2025139279000001_ABST
Patent Text Reader

Abstract

To provide a vehicle etc. in which only a user who has paid can use an additional function regardless of the vehicle.SOLUTION: A vehicle 200 is communicably connected to a server through a network. The vehicle 200 comprises: a first acquisition unit 210 which acquires user information for identifying a user; a storage unit 230 which stores vehicle information for identifying the vehicle 200; a transmission unit 240 which transmits the acquired user information, and the vehicle information stored in the storage unit to the server 100; a second acquisition unit 220 which acquires function information indicating one or more functions which can be executed by the vehicle 200, identified on the basis of the user information and the vehicle information, and where the use by the user is permitted, from the server 100; and a control unit 250 which enables one or more functions indicated by the function information.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a vehicle and an authentication method. [Background technology]

[0002] Patent Document 1 discloses a service management system that can manage the content of services provided to vehicle users for each user. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2019-109816 Summary of the Invention [Problem to be solved by the invention]

[0004] The present disclosure provides a vehicle or the like in which only paying users can use additional functions regardless of the vehicle. [Means for solving the problem]

[0005] A vehicle according to one embodiment of the present disclosure is a vehicle communicatively connected to a server via a network, and includes a first acquisition unit that acquires user information for identifying a user, a memory unit that stores vehicle information for identifying the vehicle, a transmission unit that transmits the acquired user information and the vehicle information stored in the memory unit to the server, a second acquisition unit that acquires from the server function information indicating one or more functions that the vehicle can execute and that the user is permitted to use, which are identified based on the user information and the vehicle information, and a control unit that enables the one or more functions indicated in the function information.

[0006] Furthermore, an authentication method according to one aspect of the present disclosure is an authentication method executed in an authentication system including a server and a vehicle communicatively connected via a network, wherein the vehicle acquires user information for identifying a user, acquires vehicle information for identifying the vehicle, transmits the acquired user information and the acquired vehicle information to the server, acquires function information from the server indicating one or more functions that can be executed by the vehicle and that are identified based on the user information and the vehicle information and that the user is permitted to use, and enables the one or more functions indicated by the function information.

[0007] These general or specific aspects may be realized by a device, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, or by any combination of a device, an integrated circuit, a computer program, and a non-transitory recording medium. [Effects of the Invention]

[0008] In the vehicle etc. of the present disclosure, only users who have paid can use the additional functions regardless of the vehicle. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 1 is a diagram illustrating an overview of an authentication system according to the first embodiment. [Figure 2] FIG. 2 is a hardware configuration diagram of the server according to the first embodiment. [Figure 3] FIG. 3 is a hardware configuration diagram of the vehicle according to the first embodiment. [Figure 4] FIG. 4 is a hardware configuration diagram of the information terminal according to the first embodiment. [Figure 5] FIG. 5 is a diagram illustrating an example of a functional configuration of the authentication system according to the first embodiment. [Figure 6] FIG. 6 is a diagram for explaining the user information registration process. [Figure 7]FIG. 7 is a sequence diagram showing an example of an authentication method executed in the authentication system according to the first embodiment. [Figure 8] FIG. 8 is a diagram for explaining the flow of information in each process of the authentication method. [Figure 9] FIG. 9 is a diagram for explaining the flow of information in each process of the authentication method. [Figure 10] FIG. 10 is a diagram for explaining the flow of information in each step of the authentication method. [Figure 11] FIG. 11 is a diagram for explaining the flow of information in each step of the authentication method. [Figure 12] FIG. 12 is a diagram illustrating an overview of an authentication system according to the second embodiment. [Figure 13] FIG. 13 is a diagram illustrating an example of a functional configuration of an authentication system according to the second embodiment. [Figure 14] FIG. 14 is a diagram for explaining the user information registration process. [Figure 15] FIG. 15 is a sequence diagram showing an example of an authentication method executed in the authentication system according to the second embodiment. [Figure 16] FIG. 16 is a diagram for explaining the flow of information in each process of the authentication method. [Figure 17] FIG. 17 is a diagram for explaining the flow of information in each process of the authentication method. [Figure 18] FIG. 18 is a diagram for explaining the flow of information in each process of the authentication method. DETAILED DESCRIPTION OF THE INVENTION

[0010] (Findings that formed the basis of this disclosure) Vehicles that can update their functions through updates, such as SDVs (Software Defined Vehicles), or by installing apps developed by third parties, are known. While vehicles that can update their functions improve user convenience, they also increase the number of entry points for attacks, making attacks easier and increasing security risks.

[0011] The above-mentioned function updates may be added to the default functions by the user paying a fee to the software provider. In such cases, the vehicle functions updated by the user's payment are not linked to the user but are managed by being linked to the vehicle whose functions are the target of the function update.

[0012] Recently, the number of users of car sharing services and the like has been increasing. Such users often use different vehicles. In the above-described feature update mechanism, the updated vehicle's features are permitted to be used only in the vehicle that is the subject of the feature update. Therefore, users who frequently use different vehicles cannot use the additional features unless they pay a fee for each vehicle. Furthermore, in the above-described feature update mechanism, the updated vehicle's features are maintained as they are. Therefore, in a form in which different users use the same vehicle one after another, such as a car sharing service, a feature added by one user for a fee can be used by subsequent users of the vehicle without paying a fee.

[0013] In order to solve the above problems, the present inventors have discovered a vehicle or the like that allows only users who have paid to use additional functions regardless of the vehicle.

[0014] A vehicle according to a first aspect of the present disclosure is a vehicle communicatively connected to a server via a network, and includes a first acquisition unit that acquires user information for identifying a user, a memory unit that stores vehicle information for identifying the vehicle, a transmission unit that transmits the acquired user information and the vehicle information stored in the memory unit to the server, a second acquisition unit that acquires from the server function information indicating one or more functions that the vehicle can execute and that the user is permitted to use, which are identified based on the user information and the vehicle information, and a control unit that enables the one or more functions indicated in the function information.

[0015] This enables function information indicating one or more functions that the vehicle can execute and that the user is permitted to use, which is identified based on user information and vehicle information, so that only users who have paid can use the additional functions regardless of the vehicle.

[0016] In addition, a vehicle according to a second aspect of the present disclosure is a vehicle according to the first aspect, wherein the first acquisition unit repeatedly acquires the user information from a circuit that stores the user information by wirelessly communicating with the circuit, and the control unit disables the one or more functions when the first acquisition unit acquires information that is different from user information acquired at a previous timing.

[0017] According to this, when user information different from the user information acquired at a previous timing is acquired, one or more functions that were enabled based on the user information acquired at a previous timing can be disabled. Therefore, it is possible to prevent a user who uses the vehicle thereafter from being able to use a function that a user added by paying a fee without paying a fee.

[0018] Furthermore, a vehicle according to a third aspect of the present disclosure is a vehicle according to the second aspect, wherein the control unit keeps the one or more functions enabled when the first acquisition unit acquires user information that is the same as user information acquired at a previous timing.

[0019] According to this, when the same user information as that acquired at a previous timing is acquired, one or more functions remain valid, so that the user can continue to use one or more functions.

[0020] An authentication method according to a fourth aspect of the present disclosure is an authentication method executed in an authentication system including a server and a vehicle communicatively connected via a network, wherein the vehicle acquires user information for identifying a user, acquires vehicle information for identifying the vehicle, transmits the acquired user information and the acquired vehicle information to the server, acquires function information from the server indicating one or more functions that can be executed by the vehicle and that are identified based on the user information and the vehicle information and that the user is permitted to use, and enables the one or more functions indicated by the function information.

[0021] This enables function information indicating one or more functions that the vehicle can execute and that the user is permitted to use, which is identified based on user information and vehicle information, so that only users who have paid can use the additional functions regardless of the vehicle.

[0022] Furthermore, an authentication method according to a fifth aspect of the present disclosure is the authentication method according to the fourth aspect, in which the server acquires the user information and the vehicle information from the vehicle, identifies the one or more functions based on the user information, the vehicle information, and pre-stored permission information, and transmits the function information indicating the identified one or more functions to the vehicle.

[0023] This allows one or more functions available to the user to be appropriately identified.

[0024] Furthermore, an authentication method according to a sixth aspect of the present disclosure is an authentication method according to the fifth aspect, wherein the permission information includes one or more permitted functions that the user identified by the user information is permitted to use and one or more executable functions that the vehicle identified by the vehicle information can execute, and the server, in the identification, identifies as the one or more functions one or more common functions that are common between the one or more permitted functions and the one or more executable functions.

[0025] Therefore, it is possible to appropriately identify one or more functions that can be executed by the vehicle and that the user is permitted to use.

[0026] Furthermore, an authentication method according to a seventh aspect of the present disclosure is an authentication method according to any one of the fourth to sixth aspects, wherein the vehicle transitions to a state in which the operation can be performed by receiving operation permission information for permitting operation of the vehicle, and when the server acquires the user information and the vehicle information from the vehicle, the server transmits inquiry information to an information terminal owned by the user inquiring whether or not to permit the user identified by the user information to use the vehicle identified by the vehicle information, acquires response information from the information terminal indicating a response to the inquiry information, and if the response information indicates that use of the vehicle is not permitted, does not transmit the operation permission information.

[0027] Therefore, user authentication for the user to use the vehicle can be performed at the information terminal.

[0028] Furthermore, an authentication method according to an eighth aspect of the present disclosure is an authentication method according to any one of the fourth to sixth aspects, wherein the vehicle transitions to a state in which it can perform an operation by receiving operation permission information for permitting the vehicle to operate the vehicle, and when the server acquires the user information and the vehicle information from the vehicle, the server transmits inquiry information to another server inquiring whether the user identified by the user information has been previously permitted to use the vehicle identified by the vehicle information, receives response information from the other server indicating a response to the inquiry information, and if the response information indicates that use of the vehicle is not permitted, does not transmit the operation permission information to the vehicle.

[0029] Therefore, user authentication for a user to use a vehicle can be performed by another server.

[0030] These general or specific aspects may be realized by an apparatus, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, or may be realized by any combination of an apparatus, a method, a system, an integrated circuit, a computer program, and a non-transitory recording medium.

[0031] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. However, more detailed explanation than necessary may be omitted. For example, detailed explanation of well-known matters or redundant explanation of substantially the same configuration may be omitted. This is to avoid unnecessary redundancy in the following explanation and to facilitate understanding by those skilled in the art.

[0032] The inventors have provided the accompanying drawings and the following description to enable those skilled in the art to fully understand the present disclosure, and do not intend for them to limit the subject matter described in the claims.

[0033] (Embodiment 1) [composition] FIG. 1 is a diagram illustrating an overview of an authentication system according to the first embodiment.

[0034] Specifically, Fig. 1 shows servers 100, 400, a vehicle 200, an information terminal 300, and a network 500. For example, among these components, an authentication system 1 includes the servers 100, 400, the vehicle 200, and the information terminal 300. The server 100 is a server for managing functions of the vehicle 200 that are available to users. The server 400 is a server for providing a car-sharing service. The vehicle 200 is, for example, a vehicle rented to users in a car-sharing service. The information terminal 300 is a terminal owned by the user.

[0035] The servers 100, 400, the vehicle 200, and the information terminal 300 are communicatively connected to one another via a network 500. The information terminal 300 may be communicatively connected to the network 500 via a wireless LAN router (not shown), or may be communicatively connected to the network 500 by communicating with a base station of a mobile phone communication line.

[0036] The authentication system 1 is a system that manages additional functions that a user can use by paying a fee, and allows only the user who has paid to use the additional functions regardless of the vehicle.

[0037] In the authentication system 1, the server 100 stores one or more permitted functions, which are vehicle functions that a user is permitted to use, in association with user information for identifying the user. The one or more permitted functions include additional functions that the user becomes able to use by paying a fee. The additional functions include a function for changing the seating layout of the vehicle 200, a function for enhancing the acceleration performance of the engine, a function related to the car navigation system, and a function related to entertainment such as music and video played in the vehicle cabin. In addition to the additional functions, the vehicle 200 also includes functions that the user can use without paying a fee. The functions that the user can use without paying a fee include, for example, functions related to the basic driving of the vehicle 200 and functions related to body control of the vehicle 200, such as opening and closing doors and windows. The server 100 stores vehicle information for identifying the vehicle in association with one or more executable functions that the vehicle can execute.

[0038] Server 400 also stores information for managing the schedule of vehicles used by users. For example, server 400 stores user information for identifying a user, vehicle information for identifying a vehicle that the user plans to use, and period information indicating the period during which the user will use the vehicle, in association with each other. The user information managed by server 400 includes destination information for transmitting information to information terminal 300 owned by the user.

[0039] The user information stored by server 100 and the user information stored by server 400 may be the same or different. If these pieces of user information are different, they may be associated using common information included in each piece of user information. The common information is information unique to each user for identifying the user, such as the user's name, date of birth, address, telephone number, and user identification information assigned to the user.

[0040] The user information managed by the servers 100 and 400 may include destination information for transmitting information to the information terminal 300 owned by the user identified by the user information. The vehicle information managed by the servers 100 and 400 may include destination information for transmitting information to the vehicle 200 identified by the vehicle information.

[0041] By managing the information as described above, the servers 100 and 400 can associate a user or an information terminal 300 owned by the user with the vehicle 200 used by the user. The servers 100 and 400 can then transmit information for the user to the information terminal 300 or the vehicle 200.

[0042] FIG. 2 is a hardware configuration diagram of the server according to the first embodiment.

[0043] As shown in FIG. 2, the servers 100 and 400 each include a processor 101, a main memory 102, a storage 103, and a communication IF (Interface) 104 as a hardware configuration.

[0044] The processor 101 is a processor that executes a program stored in the storage 103 or the like.

[0045] The main memory 102 is a volatile storage area that is used to temporarily store data generated during processing by the processor 101, used as a work area used when the processor 101 executes a program, and used to temporarily store data received by the communication IF 104.

[0046] The storage 103 is a non-volatile storage area that holds various data such as programs, etc. The storage 103 stores, for example, various data generated as a result of processing by the processor 101 and various data received by the communication IF 104.

[0047] The communication IF 104 is a communication interface for transmitting and receiving information between the vehicle 200, the information terminal 300, and other servers via the network 500. The communication IF 104 may be an interface for wireless communication, such as a wireless LAN interface or a Bluetooth (registered trademark) interface. The communication IF 104 may also be an interface for wired communication, such as a USB (Universal Serial Bus) or a wired LAN interface.

[0048] FIG. 3 is a block diagram illustrating an example of a hardware configuration of a vehicle according to the first embodiment.

[0049] As shown in FIG. 3, the vehicle 200 has, as its hardware configuration, a TCU (Telematics Control Unit) 201, multiple ECUs 202, storage 203, an in-vehicle display 204, an input IF (Interface) 205, and a communication IF (Interface) 206.

[0050] The TCU 201 is a communication unit that allows the vehicle 200 to perform wireless communication with the network 500. The TCU 201 is a communication unit that includes a cellular module that complies with the standards of a mobile communication network.

[0051] The multiple ECUs 202 include control circuits that acquire information from the TCU 201, acquire detection results from various sensors, and perform processing according to the acquired information and detection results. For example, at least one of the multiple ECUs 202 is a control circuit that acquires detection results from various sensors and controls autonomous driving of the vehicle 200 using the acquired detection results. The multiple ECUs 202 also include control circuits that control an in-vehicle display 204 provided in the vehicle 200 or other devices provided in the vehicle 200. Here, the other devices include, for example, an engine, a motor, a meter, a transmission, brakes, a steering wheel, a power window, an air conditioner, and the like. The multiple ECUs 202 may be provided corresponding to each of these various devices. Although not shown here, each of the multiple ECUs 202 may include a storage unit (non-volatile storage area) that stores a program executed by each ECU 202. The storage unit is, for example, a non-volatile memory.

[0052] The storage 203 is a non-volatile storage area that stores control programs, etc. The storage 203 is realized by, for example, a hard disk drive (HDD) or a solid state drive (SSD).

[0053] The in-vehicle display 204 is disposed in the cabin of the vehicle 200 and displays information in the form of letters or symbols to a user in the cabin. The in-vehicle display 204 may also display images. The in-vehicle display 204 is a liquid crystal display, an organic EL display, or the like.

[0054] The input IF 205 is disposed in the cabin of the vehicle 200 and receives input (operations) from a user in the cabin. The input IF 205 may be, for example, a touch panel disposed on the surface of the in-vehicle display 204, or a touch pad disposed within reach of a user seated in a seat of the vehicle 200.

[0055] The communication IF 206 is a communication interface for receiving user information from a circuit that stores the user information. The communication IF 206 may be an interface for wireless communication, such as a Bluetooth (registered trademark) interface or an NFC interface.

[0056] FIG. 4 is a hardware configuration diagram of the information terminal according to the first embodiment.

[0057] As shown in FIG. 4, the information terminal 300 includes, as its hardware configuration, a processor 301, a main memory 302, a storage 303, a communication IF (Interface) 304, an input device 305, and a display 306.

[0058] The processor 301 is a processor that executes a program stored in the storage 303 or the like.

[0059] The main memory 302 is a volatile storage area that is used to temporarily store data generated during processing by the processor 301, used as a work area used when the processor 301 executes a program, and used to temporarily store data received by the communication IF 304.

[0060] The storage 303 is a non-volatile storage area that holds various data such as programs, etc. The storage 303 stores, for example, various data generated as a result of processing by the processor 301 and various data received by the communication IF 304.

[0061] The communication IF 304 is a communication interface for transmitting and receiving information between the servers 100, 400 and the vehicle 200 via the network 500. The communication IF 304 may be an interface for wireless communication, such as a wireless LAN interface or a Bluetooth (registered trademark) interface. The communication IF 304 may be an interface for wired communication, such as a USB (Universal Serial Bus) or a wired LAN interface.

[0062] The input device 305 is an interface for receiving input from a person. The input device 305 may be a pointing device such as a mouse, a touchpad, a touch panel, or a trackball, or may be a keyboard.

[0063] The display 306 is a liquid crystal display, an organic EL display, or the like.

[0064] FIG. 5 is a diagram illustrating an example of a functional configuration of the authentication system according to the first embodiment.

[0065] The authentication system 1 includes servers 100 and 400, a vehicle 200, and an information terminal 300.

[0066] The server 100 includes an acquisition unit 110, an identification unit 120, a storage unit 130, and a transmission unit 140.

[0067] The acquisition unit 110 acquires information from the vehicle 200, the information terminal 300, or the server 400. The acquisition unit 110 receives the information via the network 500, thereby acquiring the information.

[0068] Specifically, the acquisition unit 110 acquires user information for identifying the user and vehicle information for identifying the vehicle 200 from the vehicle 200. The acquisition unit 110 acquires, from the server 400, response information indicating a response to inquiry information for user authentication transmitted to the server 400. The acquisition unit 110 may acquire, from the vehicle 200, an initialization request for the server 100 to initialize one or more functions enabled in the vehicle 200.

[0069] The acquisition unit 110 is realized by the communication IF 104, for example.

[0070] The identification unit 120 identifies one or more functions that are executable by the vehicle 200 and that the user is permitted to use, based on the user information, the vehicle information, and pre-stored permission information. The permission information includes one or more permitted functions that the user identified by the user information is permitted to use, and one or more functions that the vehicle identified by the vehicle information is permitted to execute. The identification unit 120 identifies, as the one or more functions, one or more common functions that are common between the one or more permitted functions that the user is permitted to use and the one or more executable functions that the vehicle 200 is permitted to execute. The identification unit 120 is realized by, for example, the processor 101, the main memory 102, the storage 103, etc.

[0071] The storage unit 130 may store information acquired by the acquisition unit 110. Specifically, the storage unit 130 may store user information, vehicle information, response information, initialization request, etc. The storage unit 130 may also store information generated in the server 100. Specifically, the storage unit 130 may store inquiry information. The storage unit 130 may also store permission information. The storage unit 130 is realized by, for example, the storage 103.

[0072] The transmitting unit 140 transmits information to the vehicle 200, the information terminal 300, or the server 400 via the network 500. Specifically, the transmitting unit 140 transmits function information indicating one or more functions identified by the identifying unit 120 to the vehicle 200 via the network 500. The transmitting unit 140 may also transmit inquiry information to the server 400 via the network 500. The inquiry information is information for inquiring whether or not to permit a user to use the vehicle 200. The user who uses the vehicle 200 in this use is the user identified by the user information. The vehicle 200 used in this use is the vehicle identified by the vehicle information. When the response information acquired by the acquiring unit 110 indicates that use of the vehicle 200 is permitted, the transmitting unit 140 transmits operation permission information to the vehicle 200 to permit the vehicle 200 to operate. Furthermore, when the response information acquired by the acquisition unit 110 indicates that use of the vehicle 200 is not permitted, the transmission unit 140 does not transmit, to the vehicle 200, operation permission information for permitting the vehicle 200 to operate the vehicle 200. The transmission unit 140 is realized by, for example, the communication IF 104.

[0073] The server 400 includes an acquisition unit 410, a control unit 420, a storage unit 430, and a transmission unit 440.

[0074] The acquisition unit 410 acquires information from the server 100, the vehicle 200, or the information terminal 300. The acquisition unit 410 acquires the information by receiving the information via the network 500. Specifically, the acquisition unit 410 acquires reservation information indicating a reservation for use of the vehicle 200 made by a user from the information terminal 300. The acquisition unit 410 acquires setting completion information indicating completion of setting of the reservation for use of the vehicle 200. The acquisition unit 410 acquires inquiry information from the server 100. The acquisition unit 410 may also acquire return information indicating that the vehicle 200 has been returned to the operator of the car sharing service from the information terminal 300. The acquisition unit 410 is realized by, for example, the communication IF 104.

[0075] The control unit 420 accepts reservations based on the reservation information acquired by the acquisition unit 410. Specifically, based on the vehicle model and planned usage period specified in the reservation information, the control unit 420 identifies vehicles of the vehicle model that have not been reserved for use during the planned usage period, based on the reservation management information stored in the storage unit 430. The reservation management information includes information indicating the usage status or reservation status of each vehicle. In other words, the reservation management information is information in which, for each vehicle, user information indicating the user who is using or plans to use the vehicle is associated with the period for which the vehicle will be used or the period for which the vehicle will be used.

[0076] The control unit 420 generates vehicle reservation setting information for setting a reservation for use by a user identified by the user information included in the reservation information for the specified vehicle during the planned use period. The control unit 420 then causes the transmission unit 440 to transmit the generated setting information to the specified vehicle 200. The control unit 420 also performs authentication processing in response to the inquiry information acquired by the acquisition unit 410. Specifically, the control unit 420 determines whether a vehicle identified by the vehicle information included in the acquired inquiry information is scheduled to be used by a user identified by the user information included in the acquired inquiry information at the time the inquiry information is acquired. If the control unit 420 determines that the vehicle is scheduled to be used at the time the inquiry information is acquired, the control unit 420 generates response information indicating that use of the vehicle is permitted. If the control unit 420 determines that the vehicle is not scheduled to be used at the time the inquiry information is acquired, the control unit 420 generates response information indicating that use of the vehicle is not permitted. The control unit 420 then causes the transmission unit 440 to transmit the generated response information to the server 100.

[0077] The control unit 420 is realized by, for example, the processor 101, the main memory 102, the storage 103, and the like.

[0078] The storage unit 430 may store information acquired by the acquisition unit 410. Specifically, the storage unit 430 may store reservation information, setting completion information, inquiry information, return information, etc. The storage unit 430 may also store information generated in the server 400. Specifically, the storage unit 430 may store setting information for vehicle reservations. The storage unit 430 may also store user information registered in the car sharing service, reservation management information, etc. The storage unit 430 is realized by, for example, the storage 103.

[0079] The transmitter 440 transmits information to the server 100, the vehicle 200, or the information terminal 300 via the network 500. Specifically, the transmitter 440 transmits setting information for a vehicle reservation to the vehicle 200 via the network 500. The transmitter 440 transmits reservation completion information indicating that the vehicle reservation has been accepted to the vehicle 200 via the network 500. The transmitter 440 transmits response information indicating a response to the inquiry information to the server 100 via the network 500. Furthermore, when the transmitter 440 acquires return information, it transmits usage completion information indicating that the user's usage has been completed to the vehicle 200 used by the user of the information terminal 300 that transmitted the return information. The transmitter 440 is realized, for example, by the communication IF 104.

[0080] The vehicle 200 includes a first acquisition unit 210, a second acquisition unit 220, a storage unit 230, a transmission unit 240, a control unit 250, a display unit 260, and a reception unit 270.

[0081] The first acquisition unit 210 acquires user information for identifying a user. For example, the first acquisition unit 210 repeatedly acquires the user information from a circuit that stores the user information by wirelessly communicating with the circuit. The first acquisition unit 210 may acquire the user information from the information terminal 300 by wirelessly communicating with the information terminal 300 using a short-range wireless communication technology such as Bluetooth or NFC (Near Field Communication). In this case, the circuit is the processor 301, main memory 302, storage 303, communication IF 304, etc., provided in the information terminal 300. Furthermore, the circuit is not limited to a circuit provided in the information terminal 300, and may be an NFC tag embedded in a card or other item. The first acquisition unit 210 is realized by, for example, the communication IF 206.

[0082] The first acquisition unit 210 may acquire user information from the user by biometric authentication, a one-time password, or the like.

[0083] The second acquisition unit 220 acquires information from the server 100, 400, or the information terminal 300. The second acquisition unit 220 acquires the information by receiving the information via the network 500. Specifically, the second acquisition unit 220 acquires function information from the server 100. The function information indicates one or more functions that are executable by the vehicle 200 and that the user is permitted to use, which are identified based on the user information and the vehicle information. The second acquisition unit 220 also acquires setting information for vehicle reservation from the server 400. The second acquisition unit 220 also acquires operation permission information and function information from the server 100. The second acquisition unit 220 also acquires usage completion information from the server 400. The second acquisition unit 220 is realized by, for example, the TCU 201.

[0084] The storage unit 230 may store information acquired by the first acquisition unit 210 or the second acquisition unit 220. Specifically, the storage unit 230 may store user information, function information, setting information, operation permission information, use completion information, etc. The storage unit 230 may also store information generated in the vehicle 200. Specifically, the storage unit 230 may store setting completion information, an initialization request, etc. The storage unit 230 stores vehicle information for identifying the vehicle 200. The storage unit 230 is realized by, for example, the storage 203.

[0085] The transmitter 240 transmits information to the server 100, 400, or the information terminal 300 via the network 500. Specifically, the transmitter 240 transmits setting completion information indicating that the setting of the reservation based on the setting information has been completed in the vehicle 200 to the server 400. Furthermore, when the user information is acquired, the transmitter 240 transmits the user information acquired by the first acquirer 210 and the vehicle information stored in the storage unit 230 to the server 100. Furthermore, when the usage completion information is acquired, the transmitter 240 transmits an initialization request to the server 100. The transmitter 240 is realized by, for example, the TCU 201.

[0086] The control unit 250 enables one or more functions indicated in the function information acquired by the second acquisition unit 220. Furthermore, the control unit 250 determines whether or not information different from the user information acquired at a previous timing is acquired in the user information repeatedly acquired by the first acquisition unit 210. If information different from the user information acquired at a previous timing is acquired, the control unit 250 disables one or more functions indicated in the function information. Note that the control unit 250 may disable one or more functions indicated in the function information if information different from the user information acquired at a previous timing is acquired a predetermined number of times. In other words, the control unit 250 may keep one or more functions indicated in the function information enabled if information different from the user information acquired at a previous timing is acquired less than a predetermined number of times.

[0087] On the other hand, when the control unit 250 acquires the same user information as that acquired at a previous timing, the control unit 250 keeps one or more functions indicated in the function information enabled. Furthermore, when the control unit 250 detects that the user has completed using the vehicle 200, the control unit 250 executes initialization to disable one or more enabled functions indicated in the function information. The scope of initialization may be partial rather than all. In other words, the control unit 250 may disable one or more enabled functions in stages, starting with some functions and ending with all functions being disabled. The initialization may be to restore the functions of the vehicle 200 to their pre-shipment state or to the setting state set in the vehicle 200.

[0088] The control unit 250 may detect that the user's use of the vehicle 200 has been completed by acquiring use completion information. Alternatively, the control unit 250 may detect that the user's use of the vehicle 200 has been completed by detecting that the reservation period for the vehicle 200 has ended. Alternatively, the control unit 250 may detect that the user's use of the vehicle 200 has been completed by detecting that the first acquisition unit 210 has not acquired user information. Alternatively, the control unit 250 may detect that the user's use of the vehicle 200 has been completed when information different from user information acquired at a previous timing is acquired in user information repeatedly acquired by the first acquisition unit 210.

[0089] The control unit 250 is realized by, for example, a plurality of ECUs 202 and the like.

[0090] The display unit 260 displays information acquired by the first acquisition unit 210, information acquired by the second acquisition unit 220, information generated by the control unit 250, etc. The display unit 260 is realized by the in-vehicle display 204, for example.

[0091] The receiving unit 270 receives input from the user. The receiving unit 270 is realized by the input IF 205, for example.

[0092] The information terminal 300 includes an acquisition unit 310 , a transmission unit 320 , a storage unit 330 , a display unit 340 , and a reception unit 350 .

[0093] The acquisition unit 310 acquires information from the server 100, 400, or the vehicle 200. The acquisition unit 310 acquires the information by receiving the information via the network 500. Specifically, the acquisition unit 310 acquires reservation completion information from the server 400. The acquisition unit 310 is realized by, for example, the communication IF 304.

[0094] The transmitting unit 320 transmits information to the server 100, 400, or the vehicle 200 via the network 500. Specifically, the transmitting unit 320 transmits reservation information to the server 400. The transmitting unit 320 transmits user information to the vehicle 200. The transmitting unit 320 transmits return information to the server 400. The transmitting unit 320 is realized by, for example, the communication IF 304.

[0095] The storage unit 330 may store information acquired by the acquisition unit 310. Specifically, the storage unit 330 may store reservation completion information. The storage unit 330 may also store information generated in the information terminal 300. Specifically, the storage unit 330 may store reservation information and return information. The storage unit 330 may also store user information. The storage unit 330 is realized by, for example, the storage 303.

[0096] The display unit 340 displays information acquired and generated by the acquisition unit 310. The display unit 340 is realized by the display 306, for example.

[0097] The reception unit 350 receives input from a user. For example, the reception unit 350 receives input from a user regarding the reservation of the vehicle 200. The reception unit 350 is realized by the input device 305, for example.

[0098] [Operation] FIG. 6 is a diagram for explaining the user information registration process.

[0099] First, the user uses the information terminal 300 to register with the server 400 that provides the car sharing service (11). That is, the information terminal 300 transmits personal information about the user (e.g., the user's name, date of birth, address, and telephone number) to the server 400.

[0100] The server 400 generates user information (B) based on the received personal information. The user information (B) includes a user ID that identifies the user. This user ID is an ID that the server 400 uses to identify the user in the car sharing service. The user information may further include personal information. The server 400 assigns the user information (B) to the information terminal 300 (12). That is, the server 400 transmits the generated user information (B) to the information terminal 300. An article such as a card equipped with a circuit that stores the user information (B) may be issued to the user.

[0101] The user also uses the information terminal 300 to register with the server 100, which provides a service that the user can use to manage the functions of the vehicle 200 (13). That is, the information terminal 300 transmits personal information about the user (e.g., the user's name, date of birth, address, and telephone number) to the server 100.

[0102] The server 100 generates user information (A) based on the received personal information. The user information (A) includes a user ID that identifies the user. This user ID is an ID that the server 100 uses to identify the user in a service that manages the functions of the vehicle 200. The user information may further include personal information. The server 100 assigns the user information (A) indicated by (15) to the information terminal 300. In other words, the server 100 transmits the generated user information (A) to the information terminal 300.

[0103] The user also uses the information terminal 300 to purchase a license for an additional function of the vehicle 200 (14). That is, the information terminal 300 transmits information indicating that the user has paid for the additional function to the server 100. The server 100 generates permission information by charging the user based on the information indicating that the user has paid. The permission information is information indicating whether or not the use of each of a plurality of functions for each user is permitted by the user's payment.

[0104] Fig. 7 is a sequence diagram showing an example of an authentication method executed in the authentication system according to Embodiment 1. Figs. 8 to 11 are diagrams for explaining the flow of information in each step of the authentication method.

[0105] The information terminal 300 receives an input related to a reservation from a user (S1). The information terminal 300 generates reservation information in response to the received input. The reservation information includes user information, the vehicle or model of the vehicle that is the subject of the reservation, the planned period of use, etc.

[0106] The information terminal 300 transmits the reservation information to the server 400 (S2).

[0107] When the server 400 receives the reservation information, it accepts the reservation based on the reservation information (S3) and generates setting information for the vehicle reservation.

[0108] The server 400 transmits the generated setting information for the vehicle reservation to the vehicle 200 that is the subject of the reservation (S4).

[0109] Upon receiving the vehicle reservation setting information, vehicle 200 sets the reservation based on the vehicle reservation setting information (S5). The vehicle reservation setting information is information for permitting the use of vehicle 200 by the user who has made a reservation for vehicle 200 during the scheduled reservation period, based on user information indicating the user who has made a reservation for vehicle 200.

[0110] When the reservation setting is completed, vehicle 200 transmits setting completion information indicating that the reservation setting is completed to server 400 (S6).

[0111] When the server 400 receives the setting completion information, it transmits reservation completion information indicating that the reservation for the vehicle 200 has been completed to the information terminal 300 (S7). The reservation completion information includes information about the vehicle 200 that has been reserved.

[0112] When the information terminal 300 receives the reservation completion information, it presents the reservation completion information to the user. Therefore, the user then brings, for example, the information terminal 300 closer to the reserved vehicle 200 in order to use the vehicle 200. As a result, wireless communication is established between the information terminal 300 and the vehicle 200, and the information terminal 300 transmits user information to the vehicle 200 (S8).

[0113] Upon receiving the user information, the vehicle 200 transmits the user information and vehicle information to the server 100 (S9).

[0114] When the server 100 receives the user information and vehicle information, it transmits inquiry information for user authentication to the server 400 (S10).

[0115] When the server 400 receives the inquiry information, it executes an authentication process (S11) and generates response information including the authentication result of the authentication process.

[0116] The server 400 transmits the generated response information to the server 100 (S12).

[0117] If the received response information indicates that use of the vehicle 200 is permitted, the server 100 transmits to the vehicle 200 operation permission information and function information for permitting the vehicle 200 to operate the vehicle 200 (S13).

[0118] Based on the received function information, vehicle 200 enables one or more functions indicated in the function information (S14), and based on the received operation permission information, unlocks the doors of vehicle 200 (S15). Note that step S14 may be performed during step S5.

[0119] The vehicle 200 receives the user information from the information terminal 300 and repeats the process of checking the repeatedly received user information (S16).

[0120] When the information terminal 300 receives an input from the user indicating that the use of the vehicle 200 has been completed, the information terminal 300 transmits return information to the server 400 (S17).

[0121] When the server 400 receives the return information, it transmits usage completion information to the vehicle 200 (S18).

[0122] When vehicle 200 receives the usage completion information, it transmits an initialization request to server 100 to initialize information related to the enabled functions stored in server 100 (S19), and then initializes the enabled functions in vehicle 200 (S20). The processing order of steps S19 and S20 may be reversed. Vehicle 200 may initialize the enabled functions when it detects that the user's use of vehicle 200 has been completed. Vehicle 200 may detect that the user's use of vehicle 200 has been completed by, for example, receiving usage completion information from server 400, or may detect that the user's use of vehicle 200 has been completed by detecting that information terminal 300 has moved away from vehicle 200.

[0123] When the server 100 receives the initialization request, it initializes the enabled functions (S21).

[0124] [Effects, etc.] The authentication method according to this embodiment is an authentication method executed in a system including a server 100 and a vehicle 200 communicatively connected via a network 500. In the authentication method, the vehicle 200 acquires user information for identifying the user. The vehicle 200 acquires vehicle information for identifying the vehicle 200. The vehicle 200 transmits the acquired user information and acquired vehicle information to the server 100. The vehicle 200 acquires function information from the server 100 indicating one or more functions that are executable by the vehicle 200 and that the user is permitted to use, which are identified based on the user information and the vehicle information. The vehicle 200 enables the one or more functions indicated in the function information.

[0125] This enables function information indicating one or more functions that the vehicle 200 can execute and that the user is permitted to use, which is identified based on user information and vehicle information, so that only users who have paid can use the additional functions regardless of the vehicle.

[0126] In the authentication method according to the present embodiment, the server 100 acquires user information and vehicle information from the vehicle 200. The server 100 identifies one or more functions based on the user information, the vehicle information, and pre-stored permission information. The server 100 transmits function information indicating the identified one or more functions to the vehicle 200.

[0127] This allows one or more functions available to the user to be appropriately identified.

[0128] In the authentication method according to the present embodiment, the permission information includes one or more permitted functions that are permitted to be used by the user identified by the user information and one or more executable functions that can be executed by the vehicle identified by the vehicle information. In the identification process, the server 100 identifies one or more common functions that are common between the one or more permitted functions and the one or more executable functions as the one or more functions.

[0129] Therefore, it is possible to appropriately identify one or more functions that the vehicle 200 can execute and that the user is permitted to use.

[0130] Furthermore, in the authentication method according to the present embodiment, vehicle 200 transitions to a state in which it is able to execute an operation of vehicle 200 by receiving operation permission information for permitting vehicle 200 to operate vehicle 200. When server 100 acquires user information and vehicle information from vehicle 200, it transmits inquiry information to another server 400 inquiring whether or not the user identified by the user information has been previously permitted to use vehicle 200 identified by the vehicle information. Server 100 receives response information indicating a response to the inquiry information from another server 400. When the response information indicates that use of vehicle 200 is not permitted, server 100 does not transmit operation permission information to vehicle 200.

[0131] Therefore, user authentication for a user to use a vehicle can be performed by another server 400.

[0132] [Variations] In the first embodiment, an example has been described in which server 400 acquires return information from information terminal 300, but server 100 may acquire the return information from information terminal 300. In this case, server 100 may transmit the acquired return information to server 400. Server 400 may acquire the return information from information terminal 300 via server 100.

[0133] The acquisition unit 110 of the server 100 acquires return information from the information terminal 300, indicating that the vehicle 200 has been returned. The storage unit 130 further stores the return information. When the return information is acquired, the transmission unit 140 transmits usage completion information, indicating that the user's usage has been completed, to the vehicle 200 being used by the user of the information terminal 300 that transmitted the return information. The transmission unit 140 also transmits the return information to the server 400. Note that when the transmission unit 140 transmits the return information to the server 400, the transmission unit 140 does not have to transmit the usage completion information to the vehicle 200 being used by the user of the information terminal 300 that transmitted the return information, and the transmission unit 440 of the server 400 may transmit the usage completion information to the vehicle 200.

[0134] (Embodiment 2) [composition] FIG. 12 is a diagram illustrating an overview of an authentication system according to the second embodiment.

[0135] 12 shows a server 100, a vehicle 200, an information terminal 300A, and a network 500. For example, an authentication system 1A includes the server 100, the vehicle 200, and the information terminal 300A among these components. The server 100 is a server for managing functions of the vehicle 200 that are available to the user. The vehicle 200 is a vehicle that is shared with, for example, family or friends. The information terminal 300A is a terminal owned by the user.

[0136] The server 100, the vehicle 200, and the information terminal 300A are communicatively connected to one another via a network 500. The information terminal 300A may be communicatively connected to the network 500 via a wireless LAN router (not shown), or may be communicatively connected to the network 500 by communicating with a base station of a mobile phone communication line.

[0137] Authentication system 1A is a system that manages additional functions that a user becomes able to use by paying a fee, and allows only the user who has paid to use the additional functions, regardless of the vehicle. While authentication system 1 according to embodiment 1 is a system that manages the functions of vehicle 200 used in a car sharing service, authentication system 1A according to embodiment 2 is a system that manages the functions of vehicle 200 that is shared and used with family, friends, etc. Therefore, authentication system 1A differs from authentication system 1 in that it does not include server 400.

[0138] In the authentication system 1A, the server 100 stores one or more permitted functions, which are vehicle functions that a user is permitted to use, in association with user information for identifying the user. The one or more permitted functions include additional functions that the user becomes able to use by paying a fee. The server 100 stores vehicle information for identifying the vehicle in association with one or more executable functions that the vehicle can execute.

[0139] The user information managed by the server 100 may include destination information for transmitting information to the information terminal 300A owned by the user identified by the user information. The vehicle information managed by the server 100 may include destination information for transmitting information to the vehicle 200 identified by the vehicle information.

[0140] By managing the information as described above, the server 100 can associate a user or the information terminal 300A owned by the user with the vehicle 200 used by the user. The server 100 can then transmit information for the user to the information terminal 300A or the vehicle 200.

[0141] The hardware configurations of the server 100, the vehicle 200, and the information terminal 300A are similar to those of the server 100, the vehicle 200, and the information terminal 300 in the first embodiment, respectively, and therefore will not be described again.

[0142] FIG. 13 is a diagram illustrating an example of a functional configuration of an authentication system according to the second embodiment.

[0143] The authentication system 1A includes a server 100, a vehicle 200, and an information terminal 300A.

[0144] The second embodiment differs in that the authentication process is executed in information terminal 300A instead of server 400. In addition to the functional configuration of information terminal 300, information terminal 300A includes a control unit 360 for executing the authentication process.

[0145] The differences will be specifically described below.

[0146] The server 100 transmits inquiry information to the information terminal 300A. That is, the transmission unit 140 transmits the inquiry information to the information terminal 300A via the network 500. The inquiry information is information for inquiring whether or not to permit the user to use the vehicle 200.

[0147] Then, the information terminal 300A generates response information to the inquiry information and transmits the generated response information to the server 100. The control unit 360 included in the information terminal 300A causes the display unit 340 to display a UI that accepts a request from the user as to whether or not the user intends to use an additional function that has become available for use in the vehicle 200 after paying a fee. When the accepting unit 350 accepts a response from the user that affirms that the user intends to use the vehicle 200, the control unit 360 generates response information indicating that the use of the vehicle 200 is permitted. When the control unit 360 accepts a response from the user that denies that the user intends to use the vehicle 200, the control unit 360 generates response information indicating that the use of the vehicle 200 is not permitted. The control unit 360 causes the transmitting unit 320 to transmit the generated response information to the server 100.

[0148] When the server 100 has issued authentication data for use of the vehicle 200 to the information terminal 300A, the server 100 may skip the authentication process for the user indicated by the user information transmitted by the vehicle 200. In other words, in this case, the server 100 does not need to send inquiry information to the information terminal 300A and receive response information. The authentication data may be updated by the server 100 periodically executing authentication processing between the server 100 and the information terminal 300A.

[0149] FIG. 14 is a diagram for explaining the user information registration process.

[0150] First, the user uses the information terminal 300A to register with the server 100, which provides a service that the user can use to manage the functions of the vehicle 200 (21). That is, the information terminal 300A transmits personal information about the user (e.g., the user's name, date of birth, address, and telephone number) to the server 100.

[0151] The server 100 generates user information (A) based on the received personal information. The user information (A) includes a user ID that identifies the user. This user ID is an ID that the server 100 uses to identify the user in a service that manages the functions of the vehicle 200. The user information may further include personal information. The server 100 assigns the user information (A) indicated by (23) to the information terminal 300A. That is, the server 100 transmits the generated user information (A) to the information terminal 300A.

[0152] The user also uses the information terminal 300A to purchase a license for an additional function of the vehicle 200 (22). That is, the information terminal 300A transmits information indicating that the user has paid for the additional function to the server 100. The server 100 generates permission information by charging the user based on the information indicating that the user has paid. The permission information is information indicating whether or not the use of each of a plurality of functions for each user is permitted by the user's payment.

[0153] Fig. 15 is a sequence diagram showing an example of an authentication method executed in the authentication system according to Embodiment 2. Figs. 16 to 18 are diagrams for explaining the flow of information in each step of the authentication method.

[0154] In order to use the vehicle 200, the user brings, for example, the information terminal 300A close to the vehicle 200. This causes wireless communication between the information terminal 300A and the vehicle 200, and the information terminal 300A transmits user information to the vehicle 200 (S31).

[0155] Upon receiving the user information, the vehicle 200 transmits the user information and vehicle information to the server 100 (S32).

[0156] When the server 100 receives the user information and vehicle information, it transmits inquiry information for user authentication to the information terminal 300A (S33).

[0157] When the information terminal 300A receives the inquiry information, it executes authentication processing (S34). The information terminal 300A generates response information including the authentication result of the authentication processing. In the authentication processing, the information terminal 300A displays a UI that accepts a request from the user as to whether or not the user intends to use an additional function that has become available to the user in the vehicle 200 for a fee, and when the information terminal 300A receives a response from the user that affirms that the user intends to use the vehicle 200, it generates response information indicating that the use of the vehicle 200 is permitted. When the information terminal 300A receives a response from the user that denies that the user intends to use the vehicle 200, it generates response information indicating that the use of the vehicle 200 is not permitted.

[0158] The information terminal 300A transmits the generated response information to the server 100 (S35).

[0159] If the received response information indicates that use of the vehicle 200 is permitted, the server 100 transmits to the vehicle 200 operation permission information and function information for permitting the vehicle 200 to operate the vehicle 200 (S36).

[0160] Based on the received function information, the vehicle 200 enables one or more functions indicated in the function information (S37).

[0161] The vehicle 200 receives the user information from the information terminal 300A and repeats the process of checking the repeatedly received user information (S38).

[0162] When vehicle 200 detects that the user has finished using vehicle 200 (S39), it transmits an initialization request to server 100 to initialize information about enabled functions stored in server 100 (S40), and then initializes the enabled functions in vehicle 200 (S41). The processing order of steps S40 and S41 may be reversed. Vehicle 200 may detect that the user has finished using vehicle 200 by detecting that information terminal 300A has moved away from vehicle 200.

[0163] When the server 100 receives the initialization request, it initializes the enabled functions (S42).

[0164] [Effects, etc.] In the authentication method according to the present embodiment, vehicle 200 transitions to a state in which it can perform an operation by receiving operation permission information that permits vehicle 200 to operate. When server 100 acquires user information and vehicle information from vehicle 200, server 100 transmits inquiry information to information terminal 300A owned by the user, inquiring whether or not the user identified by the user information is permitted to use vehicle 200 identified by the vehicle information. Server 100 acquires response information indicating a response to the inquiry information from information terminal 300A. If the response information indicates that use of vehicle 200 is not permitted, server 100 does not transmit the operation permission information.

[0165] Therefore, user authentication for the user to use the vehicle 200 can be performed by the information terminal 300A.

[0166] [others] In the above-described embodiments, each component may be configured with dedicated hardware, or may be realized by executing a software program suitable for each component. Each component may be realized by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory. Here, the software that realizes the authentication system of the above-described embodiments is a program that causes a computer to execute each step included in the flowchart shown in the figure.

[0167] The following cases are also included in this disclosure:

[0168] (1) Each of the above devices is specifically a computer system consisting of a microprocessor, ROM, RAM, hard disk unit, display unit, keyboard, mouse, etc. A computer program is stored in the RAM or hard disk unit. Each device achieves its function when the microprocessor operates in accordance with the computer program. Here, a computer program is composed of a combination of multiple instruction codes that indicate commands to a computer to achieve a predetermined function.

[0169] (2) Some or all of the components constituting each of the above devices may be configured as a single system LSI (Large Scale Integration). A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple components on a single chip, and specifically, is a computer system configured to include a microprocessor, ROM, RAM, etc. A computer program is stored in the RAM. The system LSI achieves its functions when the microprocessor operates in accordance with the computer program.

[0170] (3) Some or all of the components constituting each of the above devices may be configured as an IC card or a standalone module that can be attached to each device. The IC card or module is a computer system composed of a microprocessor, ROM, RAM, etc. The IC card or module may include the above-mentioned ultra-multifunctional LSI. The IC card or module achieves its functions when the microprocessor operates according to a computer program. The IC card or module may be tamper-resistant.

[0171] (4) The present disclosure may be embodied as the methods described above, a computer program for implementing these methods on a computer, or a digital signal comprising the computer program.

[0172] The present disclosure may also be the computer program or the digital signal recorded on a computer-readable recording medium, such as a flexible disk, hard disk, CD-ROM, MO, DVD, DVD-ROM, DVD-RAM, BD (Blu-ray (registered trademark) Disc), semiconductor memory, etc. Alternatively, the present disclosure may be the digital signal recorded on such a recording medium.

[0173] Furthermore, the present disclosure may involve transmitting the computer program or the digital signal via a telecommunications line, a wireless or wired communication line, a network such as the Internet, data broadcasting, or the like.

[0174] The present disclosure may also be a computer system including a microprocessor and a memory, the memory storing the computer program, and the microprocessor operating in accordance with the computer program.

[0175] The program or the digital signal may also be implemented by another independent computer system by recording it on the recording medium and transferring it, or by transferring it via the network or the like.

[0176] (5) The above-described embodiments and modifications may be combined with each other. [Industrial Applicability]

[0177] The present disclosure is useful for vehicles and the like in which only users who pay a fee can use additional functions regardless of the vehicle. [Explanation of symbols]

[0178] 1. 1A Certification System 100, 400 servers 101, 301 processors 102, 302 main memory 103, 303 Storage 104, 304 communication interface 110, 310, 410 acquisition part 120 Specific section 130, 230, 330, 430 storage section 140, 240, 320, 440 transmitter 200 vehicles 201 TCU 202 ECU 203 Storage 204 In-vehicle display 205 Input IF 206 Communication Interface 210 First acquisition part 220 Second Acquisition Department 250, 360, 420 control section 260, 340 display 270, 350 Reception 300, 300A information terminal 305 Input Devices 306 Display 500 Network

Claims

1. A vehicle that is communicatively connected to a server via a network, a first acquisition unit that acquires user information for identifying a user; a storage unit that stores vehicle information for identifying the vehicle; a transmission unit that transmits the acquired user information and the vehicle information stored in the storage unit to the server; a second acquisition unit that acquires, from the server, function information indicating one or more functions that are executable by the vehicle and that are permitted to be used by the user, the function information being identified based on the user information and the vehicle information; a control unit that enables the one or more functions indicated by the function information; vehicle.

2. the first acquisition unit repeatedly acquires the user information from a circuit that stores the user information by wirelessly communicating with the circuit; The control unit disables the one or more functions when the first acquisition unit acquires information different from user information acquired at a previous timing. The vehicle of claim 1 .

3. The control unit keeps the one or more functions enabled when the first acquisition unit acquires the same user information as that acquired at a previous timing.

3. The vehicle of claim 2.

4. An authentication method executed in an authentication system including a server and a vehicle communicatively connected via a network, The vehicle is Obtaining user information for identifying the user; acquiring vehicle information for identifying the vehicle; Transmitting the acquired user information and the acquired vehicle information to the server; acquiring, from the server, function information indicating one or more functions that are executable by the vehicle and that are permitted for use by the user, the function information being identified based on the user information and the vehicle information; Enable the one or more functions indicated in the function information Authentication method.

5. The server acquiring the user information and the vehicle information from the vehicle; Identifying the one or more functions based on the user information, the vehicle information, and pre-stored permission information; transmitting the function information indicating the one or more identified functions to the vehicle; The authentication method according to claim 4.

6. the permission information includes one or more permitted functions that are permitted to be used by the user identified by the user information, and one or more executable functions that are executable by the vehicle identified by the vehicle information; In the identification, the server identifies one or more common functions common between the one or more permitted functions and the one or more executable functions as the one or more functions. The authentication method according to claim 5.

7. the vehicle transitions to a state in which the operation can be performed by receiving operation permission information for permitting the operation of the vehicle; The server When the user information and the vehicle information are acquired from the vehicle, inquiry information is sent to an information terminal owned by the user, inquiring whether or not to permit the user identified by the user information to use the vehicle identified by the vehicle information; acquiring response information indicating a response to the inquiry information from the information terminal; If the response information indicates that the use of the vehicle is not permitted, the operation permission information is not transmitted. The authentication method according to any one of claims 4 to 6.

8. the vehicle transitions to a state in which the vehicle can perform the operation by receiving operation permission information for permitting the vehicle to perform the operation; The server When the user information and the vehicle information are acquired from the vehicle, transmitting inquiry information to another server inquiring whether or not the user identified by the user information is previously permitted to use the vehicle identified by the vehicle information; receiving response information indicating a response to the inquiry information from the other server; If the response information indicates that use of the vehicle is not permitted, the operation permission information is not transmitted to the vehicle. The authentication method according to any one of claims 4 to 6.

Citation Information

Patent Citations

  • Service management system, service management program, and service management method

    JP2019109816A