Vehicle control system and vehicle control method

The vehicle control system addresses program update failures by using wireless and image-based authentication to manage locking/unlocking, improving convenience and safety during updates.

JP2025150489APending Publication Date: 2025-10-09HONDA MOTOR CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024051390
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-27
Publication Date
2025-10-09

AI Technical Summary

Technical Problem

Vehicles equipped with electronic locking mechanisms may become inaccessible during program updates if occupants lack a device for unlocking, such as an electronic key, leading to inconvenience and safety issues.

Method used

A vehicle control system that integrates a first control device for wireless communication with a portable device, a second control device for image-based authentication, and an update management device that adjusts operations based on communication status with the portable device to manage program updates, including notifications and control locking/unlocking mechanisms.

Benefits of technology

Enhances passenger convenience and safety by allowing tailored responses to program update failures, ensuring vehicle access and preventing unauthorized use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025150489000001_ABST
    Figure 2025150489000001_ABST
Patent Text Reader

Abstract

To provide a vehicle control system and a control method for the vehicle control system that improve the convenience of occupants by changing responses when a program update of a vehicle fails depending on the communication state between a portable device and the vehicle.SOLUTION: A vehicle control system 1 includes a key authentication ECU 50, an image authentication ECU 60, and a central ECU 10 that executes a first operation if communication between the key authentication ECU 50 and a portable device 5 is possible when an update process for updating a program executed by the image authentication ECU 60 fails, and executes a second operation different from the first operation if communication between the key authentication ECU 50 and the portable device 5 is not possible when the update process fails.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a vehicle control system and a vehicle control method. [Background technology]

[0002] BACKGROUND ART Conventionally, a program rewriting system for updating a program of a computer mounted on a vehicle has been proposed (see, for example, Patent Document 1). [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2006-082648 Summary of the Invention [Problem to be solved by the invention]

[0004] In recent years, vehicles have been equipped with multiple devices for locking and unlocking the vehicle's locking mechanism. However, if an occupant does not have a device for unlocking the vehicle, such as an electronic key, and an electronic control device that authenticates the occupant updates its program, the vehicle cannot be unlocked, and problems such as the occupant being unable to enter or move the vehicle until the program update is complete may arise. In order to solve the above problems, the present application aims to improve passenger convenience and safety by changing the response to a vehicle program update failure depending on the communication status between the portable device and the vehicle, thereby further improving traffic safety and contributing to the development of a sustainable transportation system. [Means for solving the problem]

[0005] A first aspect for achieving the above object is a vehicle control system comprising: a first control device that acquires first authentication information through wireless communication with a portable device and controls locking and unlocking of a vehicle based on the acquired first authentication information; a second control device that acquires second authentication information based on an image captured by a camera and controls locking and unlocking of the vehicle based on the acquired second authentication information; and an update management device that, when an update process for updating a program executed by the second control device fails, performs a first operation if communication between the first control device and the portable device is possible, and performs a second operation different from the first operation if communication between the first control device and the portable device is not possible when the update process fails.

[0006] In the above vehicle control system, the update management device may be configured to notify a predetermined first notification destination as the first action if the update process fails and communication between the first control device and the portable device is possible, and to notify a predetermined second notification destination different from the first notification destination as the second action if the update process fails and communication between the first control device and the portable device is not possible.

[0007] In the above vehicle control system, if the update process fails but communication between the first control device and the portable device is possible, the update management device may be configured to send a notification of the failure of the update process to the first notification destination, with the registered address of the portable device or the owner of the vehicle as the first notification destination.

[0008] In the above vehicle control system, the update management device may be configured to send the failure notification including guidance that at least one of unlocking the vehicle using the portable device and starting the drive source installed in the vehicle is required.

[0009] In the above vehicle control system, if the update process fails and communication between the first control device and the portable device is not possible, the update management device may be configured to send a notification of the failure of the update process to a second notification destination, the second notification destination being the address of a user registered in correspondence with at least one of a road service provider and the owner of the vehicle.

[0010] In the vehicle control system, the update management device may be configured to transmit the failure notification including location information indicating a location of the vehicle.

[0011] In the above vehicle control system, the vehicle control system may be provided with a locking mechanism that locks the doors of the vehicle, and the update management device may be configured to instruct the locking mechanism to unlock if the update process fails and communication between the first control device and the portable device is not possible.

[0012] In the above vehicle control system, the vehicle control system may be equipped with a wireless communication unit and a reception device that accepts operations, and the update management device may be configured to wirelessly connect to a party selected by the operation accepted by the reception device via the wireless communication unit if the update process fails.

[0013] In the above vehicle control system, the vehicle control system may include a drive source control device that controls the drive source installed in the vehicle, and the update management device may be configured to, when instructing the locking mechanism to unlock, send an instruction to the drive source control device to prohibit operation of the drive source.

[0014] In the above vehicle control system, the vehicle control system may include a reception device that receives an operation, and the update management device may receive settings for the first operation and the second operation from the reception device.

[0015] A second aspect for achieving the above object is a control method for a vehicle control system comprising a first control device that acquires first authentication information via wireless communication with a portable device and controls locking and unlocking of the vehicle based on the acquired first authentication information, a second control device that acquires second authentication information based on an image captured by a camera and controls locking and unlocking of the vehicle based on the acquired second authentication information, and an update management device that manages updates of programs executed by the first control device and the second control device, wherein a processor mounted on the update management device executes a first operation if communication between the first control device and the portable device is not possible when an update process for updating the program executed by the second control device fails, and executes a second operation different from the first operation if communication between the first control device and the portable device is possible when the update process fails. [Effects of the Invention]

[0016] According to the above-mentioned vehicle control system and vehicle control method, the response when a vehicle program update fails can be changed depending on the communication status between the portable device and the vehicle, thereby improving convenience for occupants. [Brief explanation of the drawings]

[0017] [Figure 1] FIG. 1 is a system configuration diagram showing the configuration of a vehicle control system. [Figure 2] FIG. 2 is a block diagram showing the configuration of the central ECU. [Figure 3] FIG. 3 is a diagram showing an example of the permission request screen. [Figure 4] FIG. 4 is a flowchart showing the operation of the central ECU according to the first embodiment. [Figure 5] FIG. 5 is a diagram showing an example of the first setting screen. [Figure 6] FIG. 6 is a diagram showing an example of the second setting screen. [Figure 7] FIG. 7 is a flowchart showing the operation of the central ECU according to the second embodiment. [Figure 8] FIG. 8 is a diagram illustrating an example of the contact table. [Figure 9] FIG. 9 is a flowchart showing the operation of the central ECU according to the third embodiment. [Figure 10] FIG. 10 is a flowchart showing the operation of the central ECU according to the third embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0018] [1. Configuration of the vehicle control system of the first embodiment] 1 is a system configuration diagram showing the configuration of a vehicle control system 1 mounted on a vehicle 3. The vehicle control system 1 is configured such that a central ECU (Electronic Control Unit) 10, which is an electronic control device that functions as a central gateway, and electronic control devices that are the target of program updates are connected to each other so that data can be communicated between them. The central ECU 10 corresponds to an update management device.

[0019] A TCU (Telematics Control Unit) 14, which is a wireless device that complies with the communication standards of a mobile communication system, is connected to the central ECU 10. The central ECU 10 executes OTA (Over The Air) management using the TCU 14. The OTA management includes control related to a process of downloading update programs for electronic control devices provided in the vehicle 3 from a server device 300 via a network 350, and a process of applying the downloaded update programs to the electronic control devices.

[0020] The central ECU 10 is connected to a plurality of communication lines including first communication lines 3a and 3b and second communication lines 4a and 4b. The central ECU 10 functions as a gateway to manage the transmission and reception of communication data between these communication lines.

[0021] The first communication lines 3a, 3b and the second communication lines 4a, 4b are configured as buses for communication conforming to standards such as CAN or Ethernet (registered trademark), or as communication lines for P2P (Peer to Peer) communication. The first communication lines 3a, 3b may be configured as multiple communication lines for communication conforming to the same standard, or multiple communication lines for communication conforming to different standards. The same applies to the second communication lines 4a, 4b.

[0022] An infotainment control box (ICB) 11, a speaker 12, and a microphone 13 are connected to the first communication line 3a via an in-vehicle connection link 19. A telematics control unit (TCU) 14, a global navigation satellite system (GNSS) sensor 15, and a touch panel 16 are also connected to the in-vehicle connection link 19. The touch panel 16 includes a display 17 and a touch sensor 18. The touch panel 16 corresponds to an in-vehicle display device.

[0023] The in-vehicle connection link 19 is configured by a plurality of communication transmission paths conforming to various communication standards. The in-vehicle connection link 19 may include, for example, a plurality of communication networks. In this case, the plurality of communication networks may be connected to each other via a device having a gateway function or the like. The in-vehicle connection link 19 may also include a communication network for performing P2P communication. The communication network may employ various communication buses that perform network communication conforming to various standards. Examples of such standards include CAN, Ethernet, USB (Universal Serial Bus), LIN (Local Interconnect Network), and LVDS (Low Voltage Differential Signaling), but other standards may also be used.

[0024] The ICB 11 is an IVI (In-Vehicle Infotainment) ECU that provides various types of information and entertainment to vehicle occupants using a speaker 12, a microphone 13, a GNSS sensor 15, a touch panel 16, and the like.

[0025] A DMC (Driver Monitoring Camera) 20 that monitors the driver is connected to the first communication line 3b.

[0026] The second communication line 4a is connected to the zone A-ECU 30. The zone A-ECU 30 is connected to a drive device 31 and a battery 33. The drive device 31 is, for example, a motor or an internal combustion engine that drives the vehicle 3. The zone A-ECU 30 corresponds to a drive source control device.

[0027] The second communication line 4b is connected to the zone B-ECU 40. The zone B-ECU 40 is connected to a lamp body 41, a window motor 43, a door sensor 45, a door lock mechanism 47, and a weight sensor 49.

[0028] The lamps 41 include, for example, headlamps, tail lamps, and turn signal lights. The window motor 43 opens and closes the vehicle windows. The door sensor 45 detects operations on the vehicle doors. The door lock mechanism 47 locks and unlocks the doors of the vehicle 3. The weight sensor 49 is disposed on the seat where the occupant sits and detects the weight applied to the seat. The weight sensor 49 outputs sensor data indicating the weight applied to the seat to the zone B-ECU 40. In this embodiment, an example in which the weight sensor 49 is provided will be described. However, the presence or absence of a person in the seat (avoidance of the seat) may be detected based on the detection results of a pressure sensor, a human presence sensor, or the like instead of the weight sensor 49. The zone B-ECU 40 outputs the sensor data input from the weight sensor 49 to the central ECU 10.

[0029] Furthermore, the Thorn B-ECU 40 is connected to a key authentication ECU 50 and an image authentication ECU 60. The key authentication ECU 50 corresponds to a first control device. The image authentication ECU 60 corresponds to a second control device. The key authentication ECU 50 is connected to an LF / RF antenna 55 that performs wireless communication with the portable device 5. The portable device 5 is an electronic device with wireless communication capabilities, and is called a smart key or FOB key. The portable device 5 may also be a smartphone used as a digital key.

[0030] The key authentication ECU 50 is an electronic control device including a first memory 51 and a first processor 53. The first memory 51 is configured, for example, by a non-volatile semiconductor memory or a combination of volatile and non-volatile semiconductor memories. The first processor 53 is an arithmetic processing device configured by a CPU (Central Processing Unit) and an MPU (Micro Processor Unit). The first processor 53 may be configured by a single processor or by multiple processors.

[0031] The first memory 51 stores a first program, which is a control program executed by the first processor 53, and a key ID. The key ID is an ID used by the vehicle control system 1 to identify the portable device 5, and a different value is assigned to each portable device 5.

[0032] The first processor 53 executes a first program to perform authentication processing. When the first processor 53 receives the key ID of the portable device 5 via the LF / RF antenna 55, the first processor 53 determines whether the received key ID matches the key ID stored in the first memory 51. The key ID corresponds to first authentication information. If the received key ID matches the key ID stored in the first memory 51, the first processor 53 instructs the zone B-ECU 40 to unlock or lock the doors. The zone B-ECU 40 instructs the door lock mechanism 47 to unlock or lock the doors in accordance with the instruction from the key authentication ECU 50. The key authentication ECU 50 also outputs information indicating the communication status between the portable device 5 and the LF / RF antenna 55 to the zone B-ECU 40. The zone B-ECU 40 outputs the information indicating the communication status input from the key authentication ECU 50 to the central ECU 10.

[0033] A camera 65 is connected to the image authentication ECU 60. The camera 65 is a digital camera, and is installed in the vehicle 3 so as to be able to capture an image of the face of an occupant present outside the vehicle on the driver's seat side, for example. The camera 65 is arranged, for example, on the B-pillar on the driver's seat side, the roof edge, or the side mirror.

[0034] The image authentication ECU 60 is an electronic control device including a second memory 61 and a second processor 63. The second memory 61 is configured, for example, by a non-volatile semiconductor memory or a combination of volatile and non-volatile semiconductor memories. The second processor 63 is an arithmetic processing unit configured by a CPU or an MPU.

[0035] The second memory 61 stores a second program, which is a control program executed by the second processor 63, and feature amount data. The feature amount data is data indicating the facial features of the occupant, and is extracted from a captured image of the occupant's face. The image authentication ECU 60 operates the camera 65 to acquire an image captured by the camera 65. The image authentication ECU 60 extracts features of the facial area included in the image captured by the camera 65 and authenticates the user based on the comparison result between the extracted features and the features stored in the second memory 61. The features of the facial area correspond to second authentication information. If the features match, the image authentication ECU 60 instructs the zone B-ECU 40 to unlock the doors. The zone B-ECU 40 instructs the door lock mechanism 47 to unlock the doors in accordance with the instruction from the image authentication ECU 60.

[0036] FIG. 2 is a block diagram showing the configuration of the central ECU 10. As shown in FIG. The configuration of the central ECU 10 will be described with reference to FIG. The central ECU 10 is an electronic control device including a third memory 110 and a third processor 130. The third memory 110 is configured, for example, by a non-volatile semiconductor memory or a combination of volatile and non-volatile semiconductor memories. The third memory 110 stores a third program 111 executed by the third processor 130 and map data 113. The third memory 110 is also used as a calculation area for the third processor 130.

[0037] The third processor 130 is an arithmetic processing unit configured with a CPU or an MPU. The third processor 130 may be configured with a single processor, or may be configured with multiple processors.

[0038] The central ECU 10 has, as functional components, an information acquisition unit 131, an alighting detection unit 133, a program update unit 135, and a determination unit 137. These functional components are functions obtained when the third processor 130 executes the third program 111 and performs calculations.

[0039] The information acquisition unit 131 acquires information from the key authentication ECU 50 and the zone B-ECU 40. For example, the information acquisition unit 131 acquires information indicating the communication state with the portable device 5 from the key authentication ECU 50. The information acquisition unit 131 also acquires information indicating the door lock state and sensor data of the weight sensor 49 from the zone B-ECU 40.

[0040] The dismounting detection unit 133 detects the occupant dismounting from the vehicle 3. The dismounting detection unit 133 detects the occupant dismounting based on sensor data from the weight sensor 49. The dismounting detection unit 133 may also determine that the occupant has dismounted based on the communication state between the key authentication ECU 50 and the portable device 5. For example, the dismounting detection unit 133 may determine that the occupant has dismounted from the vehicle 3 when the communication state between the key authentication ECU 50 and the portable device 5 changes from a communication enabled state to a communication disabled state.

[0041] When there is an update to a program executed by an electronic control unit mounted on vehicle 3, program update unit 135 downloads an update program, which is the updated program, from server device 300. Program update unit 135 temporarily stores the acquired update program in third memory 110. Program update unit 135 updates the downloaded program to the target electronic control unit at a predetermined timing.

[0042] In addition, if the downloaded update program is a program that updates a second program executed by the image authentication ECU 60, and the judgment unit 137 determines that the program update is permitted, the program update unit 135 causes the image authentication ECU 60 to update the second program executed by the image authentication ECU 60 with the update program.

[0043] When the update program downloaded by the program update unit 135 is a program that updates the second program, the judgment unit 137 judges whether or not to allow the image authentication ECU 60 to update to the update program based on the communication status between the key authentication ECU 50 and the portable device 5.

[0044] When the key authentication ECU 50 and the portable device 5 are in a state where they can communicate with each other, the determination unit 137 permits the image authentication ECU 60 to update the program. For example, when the key authentication ECU 50 and the portable device 5 are in a state where they can communicate, the judgment unit 137 receives an authorization operation to allow a program update of the image authentication ECU 60, and detects that the portable device 5 has been taken outside the vehicle, the judgment unit 137 allows the program update unit 135 to update the second program of the image authentication ECU 60.

[0045] Furthermore, even if the key authentication ECU 50 and the portable device 5 are in a state where they can communicate but an authorization operation to allow a program update of the image authentication ECU 60 has not been received, if the determination unit 137 detects that the portable device 5 has been taken out of the vehicle, it allows the program update unit 135 to update the second program of the image authentication ECU 60. When the portable device 5 is taken out of the vehicle, for example, when the communication state between the key authentication ECU 50 and the portable device 5 changes from a communication enabled state to a communication disabled state, and the disembarkation detection unit 133 determines that an occupant has disembarked, the determination unit 137 determines that the portable device 5 has been taken out of the vehicle.

[0046] 3 is a diagram showing an example of a permission request screen 150 that the central ECU 10 displays on the touch panel 16 when there is an update to the second program. The permission request screen 150 corresponds to an example of a guide screen. The permission request screen 150 displays a message that there is an update to the second program executed by the image authentication ECU 60, and a message asking whether to permit the program update of the image authentication ECU 60. In addition, the permission request screen 150 displays a message requesting the user to take the portable device 5 out of the vehicle when the program update of the image authentication ECU 60 is permitted and the user moves outside the vehicle.

[0047] The permission request screen 150 also displays a radio button 151 for permitting the program update, a radio button 153 for denying the program update, and an OK button 155. If the occupant permits the program update, the occupant selects radio button 151 and presses decision button 155. If the occupant rejects the program update, the occupant selects radio button 153 and presses decision button 155.

[0048] Next, a case will be described in which the determination unit 137 receives a permission operation to permit the program update on the permission request screen 150, but the occupant gets out of the vehicle leaving the portable device 5 inside the vehicle. When the disembarking detection unit 133 detects that the occupant has disembarked but determines that the portable device 5 remains inside the vehicle, the determination unit 137 acquires latitude and longitude information indicating the position of the vehicle 3 from the GNSS sensor 15. The determination unit 137 refers to the map data 113 based on the acquired latitude and longitude information, and acquires facility information of the facility where the vehicle 3 is parked. The GNSS sensor 15 and the central ECU 10 function as a position detection device.

[0049] The determination unit 137 first determines whether the acquired latitude and longitude information is a location registered as the home. If the acquired latitude and longitude information is a location registered as the home, the determination unit 137 does not determine whether to permit the image authentication ECU 60 to update the program based on the communication state between the portable device 5 and the key authentication ECU 50. The determination unit 137 determines whether to permit the update of the second program executed by the second control device executed by the portable device 5. If the vehicle location is a location registered as the home, it is possible to take a spare key or the like out of the home and unlock the vehicle, so there is little chance of a situation occurring in which the occupant cannot get into the vehicle or cannot drive the vehicle.

[0050] Based on the acquired facility information, the determination unit 137 acquires a predicted time for the occupant to stop at the facility indicated by the facility information. For example, the determination unit 137 stores, as a behavior history, in the third memory 110, the types of facilities the occupant has previously stopped at and the average stop times for those facilities of that type. The facility type is information indicating the type of facility, such as a supermarket, convenience store, amusement park, or karaoke bar. The determination unit 137 may calculate the average stop times for each facility and store them in the third memory 110. Alternatively, the determination unit 137 may calculate the average stop times of multiple users for each facility or each type of facility and register them in a server device (not shown). The determination unit 137 acquires the type of facility indicated by the acquired facility information and transmits information indicating the acquired type and a request to acquire the average stop times to the server device. Upon receiving the acquisition request from the vehicle 3, the server device acquires the type of facility indicated by the information included in the acquisition request and acquires the average stop times for the facility corresponding to the acquired type. The server device transmits the acquired average value of the stopover times to the vehicle 3 that has received the acquisition request.

[0051] When the determination unit 137 acquires the predicted time of the occupant's visit to the facility, it compares the acquired predicted time of the visit with the update time required to update the second program. If the predicted time of the visit is longer than the update time, the determination unit 137 permits the image authentication ECU 60 to update the second program. On the other hand, if the predicted time is shorter than the update time, the determination unit 137 does not permit the image authentication ECU 60 to update the second program.

[0052] Furthermore, when communication between the key authentication ECU 50 and the portable device 5 is disabled, the determination unit 137 prohibits program update of the image authentication ECU 60. Furthermore, when communication between the key authentication ECU 50 and the portable device 5 is disabled, the determination unit 137 prohibits display of the permission request screen 150 shown in FIG. 3 on the touch panel 16.

[0053] Furthermore, when the key authentication ECU 50 is updating the first program, the determination unit 137 does not permit the image authentication ECU 60 to update the second program. That is, the determination unit 137 manages the execution timing of the update processes of the key authentication ECU 50 and the image authentication ECU 60 so that the update process in which the key authentication ECU 50 updates the first program and the update process in which the image authentication ECU 60 updates the second program do not overlap.

[0054] [2. Operation of the Central ECU in the First Embodiment] 4 is a flowchart showing the operation of the central ECU 10. The operation of the central ECU 10 will be described with reference to the flowchart shown in FIG. The central ECU 10 determines whether or not there is an update program downloaded from the server device 300 (step SA1). If there is no update program downloaded (step SA1 / NO), the central ECU 10 waits until an update program is downloaded from the server device 300.

[0055] If there is a downloaded update program (step S1A / YES), the central ECU 10 determines whether or not the downloaded update program is an update program for the second program executed by the image authentication ECU 60 (step SA2).

[0056] If the downloaded update program is not an update program for the second program (step SA2 / NO), the central ECU 10 ends this processing flow and executes another processing flow.

[0057] If the downloaded update program is an update program for the second program (step SA2 / YES), the central ECU 10 determines whether the key authentication ECU 50 is in a state in which it can communicate with the portable device 5 (step SA3).

[0058] If the key authentication ECU 50 and the portable device 5 are unable to communicate with each other (step SA3 / NO), the central ECU 10 does not permit the image authentication ECU 60 to update the second program (step SA11), and ends this processing flow.

[0059] If the key authentication ECU 50 and the portable device 5 are able to communicate with each other (step SA3 / YES), the central ECU 10 causes the touch panel 16 to display a permission request screen 150 requesting the occupant permission to update the second program (step SA4). This permission request screen 150 displays a radio button 151 for permitting the program update, a radio button 153 for denying the program update, and an OK button 155. In addition, the permission request screen 150 displays a guide requesting the occupant to take the portable device 5 with them when the occupant moves outside the vehicle and permits the program update of the image authentication ECU 60. If the occupant permits the program update, the occupant selects the radio button 151 and presses the OK button 155.

[0060] The central ECU 10 determines whether or not the permission operation has been received (step SA5). If the permission operation has not been received but the refusal operation has been received (step SA5 / NO), the central ECU 10 does not permit the image authentication ECU 60 to update the second program (step SA11).

[0061] When the central ECU 10 receives the permission operation (step SA5 / YES), it determines whether the occupant has exited the vehicle 3 while carrying the portable device 5 (step SA6). The central ECU 10 detects the occupant's exit based on the sensor data of the weight sensor 49. Furthermore, when the communication state between the key authentication ECU 50 and the portable device 5 changes from a communication enabled state to a communication disabled state, or when the occupant's exit is detected, the central ECU 10 determines that the portable device 5 has been taken out of the vehicle.

[0062] When determining that the portable device 5 has been taken out of the vehicle (step SA6 / YES), the central ECU 10 permits the program update of the image authentication ECU 60 (step SA10), and ends this processing flow.

[0063] Furthermore, if the portable device 5 has not been taken out of the vehicle (step SA6 / NO), the central ECU 10 acquires latitude and longitude information indicating the position of the vehicle 3 calculated by the GNSS sensor 15. The central ECU 10 refers to the map data 113 based on the acquired latitude and longitude information, and acquires facility information of facilities whose premises include the acquired latitude and longitude (step SA7). Furthermore, if there is no facility whose premises include the acquired latitude and longitude, the central ECU 10 may acquire facility information of facilities within a predetermined range from the acquired latitude and longitude.

[0064] Next, the central ECU 10 acquires a predicted time for stopping at the facility in the facility information based on the acquired facility information and the occupant's behavior history (step SA8). For example, the third memory 110 stores the types of facilities that the occupant has previously stopped at and the average time for stopping at facilities of this type in the past as the behavior history. The central ECU 10 acquires the average time for stopping at the facility corresponding to the facility information as the predicted time.

[0065] Next, the central ECU 10 determines whether the average value of the stopover times acquired in step S8 is longer than the update time required for updating the program of the image authentication ECU 60 (step SA9). If the predicted time of the stopover time is longer than the update time (step SA9 / YES), the central ECU 10 permits the image authentication ECU 60 to update the program (step SA10). If the predicted time is equal to or shorter than the update time (step SA9 / NO), the central ECU 10 does not permit the image authentication ECU 60 to update the program (step SA11), and ends this processing flow.

[0066] [3. Operation of the Central ECU in the Second Embodiment] Next, a second embodiment will be described with reference to the accompanying drawings. The configuration of the vehicle control system 1 of the second embodiment is the same as that of the first embodiment, and therefore, a description of the configuration of the vehicle control system 1 will be omitted.

[0067] In the second embodiment, when the central ECU 10 downloads an update program for the image authentication ECU 60 from the server device 300, the central ECU 10 inquires of the key authentication ECU 50 about the communication state with the portable device 5.

[0068] When the central ECU 10 receives a response from the key authentication ECU 50 indicating that communication with the portable device 5 is possible, the central ECU 10 causes the touch panel 16 to display a first setting screen 200 shown in Fig. 5. When the central ECU 10 receives a response from the key authentication ECU 50 indicating that communication with the portable device 5 is impossible, the central ECU 10 causes the touch panel 16 to display a second setting screen 250 shown in Fig. 6.

[0069] FIG. 5 is a diagram showing an example of a first setting screen 200 that the central ECU 10 causes the touch panel 16 to display. The first setting screen 200 displays a guidance display notifying the user of a program update for the image authentication ECU 60. The first setting screen 200 also displays a radio button 211 for selecting "Allow" for the program update, a radio button 213 for selecting "Reject", and a decision button 215. If the occupant permits the program update, the occupant selects radio button 211 and presses decision button 215. If the occupant rejects the program update, the occupant selects radio button 213 and presses decision button 215.

[0070] 6 is a diagram showing an example of a second setting screen 250 that the central ECU 10 causes the touch panel 16 to display. The second setting screen 250 corresponds to a setting screen. On the second setting screen 250, a first display field 260, a second display field 270, and an OK button 280 are displayed. The first display field 260 displays a guidance display notifying the user of a program update for the image authentication ECU 60. The first display field 260 also displays a radio button 261 for selecting "Allow" for the program update and a radio button 263 for selecting "Reject" for the program update. If the occupant permits the program update, the occupant selects the radio button 261. If the occupant does not permit the program update, the occupant selects the radio button 263.

[0071] The second display field 270 displays a warning in the event that the program update of the image authentication ECU 60 has failed. For example, the second display field 270 displays a message that if the program update of the image authentication ECU 60 has failed, the image authentication ECU 60 may stop working, and it may become impossible to unlock the doors using facial recognition. The second display field 270 also displays a message asking whether or not to lock the doors when an occupant gets out of the vehicle. The second display field 270 displays a radio button 271 for selecting "Lock" and a radio button 273 for selecting "Do not lock." The radio buttons 271 and 273 displayed in the second display field 270 are selectable when the radio button 261 is selected in the first display field 260.

[0072] The occupant selects radio button 261 if they wish to permit the program update of the image authentication ECU 60. If they wish to refuse the program update of the image authentication ECU 60, they select radio button 263. If they wish to lock the doors when getting out of the vehicle, they select radio button 271. If they wish not to lock the doors when getting out of the vehicle, they select radio button 273. The occupant selects radio button 261 or 263, and radio button 271 or 273, and presses decision button 280.

[0073] When the first setting screen 200 is displayed, the communication state between the key authentication ECU 50 and the portable device 5 is communication enabled. Therefore, even if the program update of the image authentication ECU 60 is permitted, the occupant can get into the vehicle 3 by operating the portable device 5. For this reason, the central ECU 10 does not display a warning on the first setting screen 200 in the event that the program update of the image authentication ECU 60 has failed.

[0074] When the communication state between the key authentication ECU 50 and the portable device 5 is communication enabled and the radio button 211 is selected on the first setting screen 200, the central ECU 10 determines that it has received an authorization operation to authorize program update of the image authentication ECU 60. In this case, when the central ECU 10 detects that an occupant has exited the vehicle, it instructs the zone B-ECU 40 to lock the doors and authorizes program update of the image authentication ECU 60. In response to the instruction from the central ECU 10, the zone B-ECU 40 controls the door lock mechanism 47 to lock the doors.

[0075] Furthermore, when the communication state between the key authentication ECU 50 and the portable device 5 is communication enabled and the radio button 213 is selected on the first setting screen 200, the central ECU 10 determines that it has received a refusal operation to permit the program update of the image authentication ECU 60. In this case, the central ECU 10 prohibits the program update of the image authentication ECU 60 and does not allow the image authentication ECU 60 to perform the program update.

[0076] Furthermore, when the communication state between the key authentication ECU 50 and the portable device 5 is not available and the radio buttons 261 and 271 are selected on the second setting screen 250, the central ECU 10 determines that it has received an authorization operation to permit program update and a locking operation to lock the doors. In this case, when the central ECU 10 detects that an occupant has exited the vehicle, it instructs the zone B-ECU 40 to lock the doors and permits program update of the image authentication ECU 60. In response to the instruction from the central ECU 10, the zone B-ECU 40 controls the door lock mechanism 47 to lock the doors.

[0077] Furthermore, when the communication state between the key authentication ECU 50 and the portable device 5 is not available and the radio buttons 261 and 273 are selected on the second setting screen 250, the central ECU 10 determines that it has received an authorization operation to authorize program update and an unlock operation to not lock the doors. When the central ECU 10 detects that an occupant has exited the vehicle, it authorizes the image authentication ECU 60 to update the program but does not instruct the zone B-ECU 40 to lock the doors.

[0078] Furthermore, when the central ECU 10 receives an authorization operation to authorize a program update and an unlock operation to not lock the doors, the central ECU 10 transmits an instruction to the zone A-ECU 30 to prohibit the driving of the drive unit 31. The central ECU 10 may be configured not to transmit an instruction signal to the zone A-ECU 30 to lock the doors of the vehicle 3. Upon receiving the instruction from the central ECU 10, the zone A-ECU 30 prohibits the driving of the drive unit 31, thereby preventing the vehicle 3 from traveling. This prevents the vehicle 3 from being stolen. The prohibition of driving the drive unit 31 continues, for example, until the occupant operates the portable device 5 and the key authentication ECU 50 receives the key ID of the portable device 5. The prohibition of driving the drive unit 31 continues, for example, until the program update of the image authentication ECU 60 is completed and the image authentication ECU 60 authenticates the occupant from the image captured by the camera 65.

[0079] Furthermore, when the communication state between the key authentication ECU 50 and the portable device 5 is not available and the radio button 263 is selected on the second setting screen 250, the central ECU 10 determines that a refusal operation to refuse the program update has been received. In this case, the central ECU 10 prohibits the program update of the image authentication ECU 60 and does not allow the image authentication ECU 60 to perform the program update.

[0080] FIG. 7 is a flowchart showing the operation of the central ECU 10 of the second embodiment. The operation of the central ECU 10 will be described with reference to the flowchart shown in FIG. The central ECU 10 determines whether or not there is an update program downloaded from a server (not shown) (step SB1). If there is no update program downloaded (step SB1 / NO), the central ECU 10 waits until an update program is downloaded from the server.

[0081] If there is a downloaded update program (step SB1 / YES), the central ECU 10 determines whether or not the downloaded update program is an update program for the program executed by the image authentication ECU 60 (step SB2).

[0082] If the downloaded update program is not an update program for the image authentication ECU 60 (step SB2 / NO), the central ECU 10 ends this processing flow and executes another processing flow.

[0083] If the downloaded update program is an update program for the image authentication ECU 60 (step SB2 / YES), the central ECU 10 inquires of the key authentication ECU 50 whether communication with the portable device 5 is available. When the central ECU 10 receives a response from the key authentication ECU 50 indicating that communication with the portable device 5 is available (step SB3 / YES), the central ECU 10 displays the first setting screen 200 on the touch panel 16 (step SB4). The central ECU 10 changes the display of the first setting screen 200 in accordance with a touch operation on the touch panel 16. For example, the central ECU 10 changes the selected radio button to radio button 211 or 213 in accordance with the touch operation.

[0084] Next, the central ECU 10 determines whether or not the decision button 215 has been pressed (step SB5). If the decision button 215 has not been pressed (step SB5 / NO), the central ECU 10 waits until the decision button 215 is pressed.

[0085] When the decision button 215 is pressed (step SB5 / YES), the central ECU 10 determines whether or not an authorization operation to authorize program update of the image authentication ECU 60 has been accepted on the first setting screen 200 (step SB6). If the authorization operation has been accepted (step SB6 / YES), the central ECU 10 instructs the zone B-ECU 40 to lock the doors upon detecting that an occupant has exited the vehicle 3 (step SB7). The zone B-ECU 40 controls the door lock mechanism 47 in accordance with the instruction from the central ECU 10 to lock the doors of the vehicle 3. Next, the central ECU 10 authorizes the image authentication ECU 60 to perform the program update (step SB8).

[0086] In addition, if the central ECU 10 receives an authorization operation on the first setting screen 200 to allow the program update of the image authentication ECU 60 (step SB6 / NO), it does not allow the image authentication ECU 60 to perform the program update (step SB9) and terminates this processing flow.

[0087] Next, the operation of the central ECU 10 when a response indicating that communication with the portable device 5 is unavailable is obtained from the key authentication ECU 50 in the determination of step SB3 will be described. When the central ECU 10 receives a response from the key authentication ECU 50 indicating that communication with the portable device 5 is disabled (step SB3 / NO), the central ECU 10 displays the second setting screen 250 on the touch panel 16 (step SB10).

[0088] Next, the central ECU 10 determines whether or not the decision button 215 has been pressed (step SB11). If the decision button 215 has not been pressed (step SB11 / NO), the central ECU 10 waits until the decision button 215 is pressed.

[0089] When the decision button 280 is pressed (step SB11 / YES), the central ECU 10 determines whether or not an authorization operation to authorize program update of the image authentication ECU 60 has been accepted on the second setting screen 250 (step SB12). The central ECU 10 determines whether or not the radio button 261 in the first display field 260 has been selected, and determines whether or not the authorization operation has been accepted.

[0090] If the central ECU 10 determines that the radio button 263 in the first display field 260 has been selected and that a refusal operation has been received (step SB12 / NO), the central ECU 10 does not permit the image authentication ECU 60 to update the program (step SB9) and ends this processing flow.

[0091] In addition, when the central ECU 10 receives a selection of the radio button 261 in the first display field 260, and determines that an authorization operation has been received (step SB12 / YES), it then determines whether or not a setting to lock the doors when exiting the vehicle has been received (step SB13).

[0092] When the central ECU 10 receives the selection of the radio button 271 in the second display field 270, it determines that "lock the doors of the vehicle 3 when getting off the vehicle" has been selected (step SB13 / YES). In this case, the central ECU 10 instructs the zone B-ECU 40 to lock the doors (step SB14). The zone B-ECU 40 controls the door lock mechanism 47 in accordance with the instruction from the central ECU 10, and locks the doors of the vehicle 3. Next, the central ECU 10 permits the image authentication ECU 60 to update the program (step SB17).

[0093] Furthermore, when the central ECU 10 receives a selection of the radio button 273 in the second display field 270, it determines that the selection to not lock the doors of the vehicle 3 when the occupant exits the vehicle has been made (step SB13 / NO). In this case, the central ECU 10 transmits an instruction to the zone A-ECU 30 to prohibit the driving of the driving device 31 (step SB15), and does not instruct the zone B-ECU 40 to lock the doors. Therefore, the doors of the vehicle 3 remain unlocked even after the occupant exits the vehicle (step S16). Thereafter, the central ECU 10 permits the image authentication ECU 60 to perform a program update (step SB17).

[0094] [4. Operation of the Central ECU in the Third Embodiment] Next, a third embodiment will be described. The configuration of the vehicle control system 1 is the same as that of the first embodiment described above, so a description of the configuration of the vehicle control system 1 will be omitted.

[0095] When the central ECU 10 of the third embodiment downloads an update program for the image authentication ECU 60 from the server device 300, it also inquires of the key authentication ECU 50 about the communication status with the portable device 5. The central ECU 10 of the third embodiment changes its operation when the program update of the image authentication ECU 60 fails, depending on the communication status between the key authentication ECU 50 and the portable device 5.

[0096] When the communication state between the key authentication ECU 50 and the portable device 5 is communication enabled and the program update of the image authentication ECU 60 fails, the central ECU 10 executes a first operation. As a first operation, the central ECU 10 sends a failure notification indicating that the program update of the image authentication ECU 60 has failed to the first notification destination, which is the portable device 5 carried by the owner of the vehicle 3, i.e., the driver. If the portable device 5 is a smartphone with a digital key, the failure notification is sent to the registered email address or IP address of the smartphone. This failure notification includes guidance that the user needs to unlock the vehicle 3 using the portable device 5 and start up a drive source such as an engine mounted on the vehicle 3.

[0097] Furthermore, when the communication state with the portable device 5 is incommunicable and the program update of the image authentication ECU 60 fails, the central ECU 10 executes the second operation. As a second operation, the central ECU 10 sends a failure notification to the second notification destination, which is the road service provider or the contact information of a mobile device carried by the owner of the vehicle 3, i.e., the driver's family, indicating that the program update of the image authentication ECU 60 has failed.

[0098] FIG. 8 is a diagram showing an example of contact table 115 in which emergency contact information is registered. In the contact table 115, second notification destinations are registered. The second notification destination may include the telephone number of a road service provider that provides road service, or the email address or telephone number of a family member of the owner of the vehicle 3. In addition, if the mobile device 5 is a smartphone used as a digital key, it is also possible to register the telephone number or email address of the owner of the vehicle 3 as the first notification destination.

[0099] If the communication state with the portable device 5 is not possible and the program update of the image authentication ECU 60 fails, the central ECU 10 sends an email containing a failure notification to the email address of the road service provider or the mobile phone of the registered family member. Alternatively, the central ECU 10 may call the telephone number of the road service provider or the mobile phone of the registered family member to notify the failure notification by a voice synthesized by voice synthesis software, for example.

[0100] Furthermore, when the central ECU 10 sends a program update failure notification to the second notification destination, the central ECU 10 sends the failure notification including the location information of the vehicle 3 acquired from the GNSS sensor 15. Since the location information of the vehicle 3 is included, it becomes easier for a road service provider or a family member to identify the location of the vehicle 3.

[0101] Furthermore, if the program update of the image authentication ECU 60 fails, the central ECU 10 instructs the zone B-ECU 40 to unlock the doors of the vehicle 3, forcibly unlocking the doors of the vehicle 3. There may be cases where an occupant gets out of the vehicle 3 without the portable device 5, in which case it may be impossible to unlock the doors by image authentication due to a failure to update the program of the image authentication ECU 60. For this reason, the central ECU 10 instructs the zone B-ECU 40 to forcibly unlock the doors of the vehicle 3.

[0102] Furthermore, the central ECU 10 transmits to the zone A-ECU 30 a prohibition instruction to prohibit the zone A-ECU 30 from driving the drive unit 31. Because the doors of the vehicle 3 remain unlocked, the central ECU 10 transmits the prohibition instruction to the zone A-ECU 30 to prevent the vehicle 3 from moving, in order to prevent the vehicle 3 from being stolen.

[0103] Furthermore, the central ECU 10 continues to supply power from the battery 33 to the TCU 14, thereby maintaining a state in which communication with the outside is possible via the TCU 14. Then, the central ECU 10 causes, for example, the touch panel 16 to display the telephone number of a road service provider or a telephone number registered as a second notification destination, and when a telephone number is selected by a touch operation by the occupant, makes a call to the selected telephone number, thereby enabling communication.

[0104] Furthermore, the registration of the first notification destination and the second notification destination can be changed by the occupant or the like touching the touch panel 16. That is, the notification destination registered as the first notification destination or the second notification destination can be changed by the touch operation. For example, it is possible to register the telephone number of another road service company as the second notification destination, or it is possible to register the email address or telephone number of a smartphone carried by the occupant who is the owner of the vehicle 3 as the first notification destination, instead of the portable device 5.

[0105] 9 and 10 are flowcharts showing the operation of the central ECU 10 of the third embodiment. The operation of the central ECU 10 will be described with reference to the flowcharts shown in FIGS. The central ECU 10 determines whether or not there is an update program downloaded from a server (not shown) (step SC1). If there is no update program downloaded (step SC1 / NO), the central ECU 10 waits until an update program is downloaded from the server.

[0106] If there is a downloaded update program (step SC1 / YES), the central ECU 10 determines whether or not the downloaded update program is an update program for the program executed by the image authentication ECU 60 (step SC2).

[0107] If the downloaded update program is not an update program for the image authentication ECU 60 (step SC2 / NO), the central ECU 10 ends this processing flow and executes another processing flow.

[0108] If the downloaded update program is an update program for the image authentication ECU 60 (step SC2 / YES), the central ECU 10 inquires of the key authentication ECU 50 whether communication with the portable device 5 is possible. If the central ECU 10 receives a response from the key authentication ECU 50 indicating that communication with the portable device 5 is possible (step SC3 / YES), the central ECU 10 displays the first setting screen 200 shown in FIG. 3 on the touch panel 16 (step SC4). If the occupant permits the program update, the occupant selects the radio button 151 and presses the enter button 155. If the occupant does not permit the program update, the occupant selects the radio button 153 and presses the enter button 155.

[0109] The central ECU 10 determines whether or not the permission operation has been received (step SC5). If the permission operation has not been received but the refusal operation has been received (step SC5 / NO), the central ECU 10 does not permit the image authentication ECU 60 to update the second program (step SC6).

[0110] When the central ECU 10 receives the permission operation (step SC5 / YES), it permits the image authentication ECU 60 to update the program (step SC7). Thereafter, the central ECU 10 determines whether the program update of the image authentication ECU 60 has been successful (step SC8). If the program update of the image authentication ECU 60 has not been successful (step SC8 / NO), the central ECU 10 notifies the portable device 5 that key authentication by the portable device 5 is required (step SC9). At this time, the central ECU 10 notifies the portable device 5 that the program update of the image authentication ECU 60 has failed.

[0111] Furthermore, if the program update of the image authentication ECU 60 is successful (step SC8 / YES), the central ECU 10 instructs the image authentication ECU 60 to perform image authentication (step SC10). At this time, the central ECU 10 may transmit a guide to the portable device 5 instructing the portable device 5 to perform face authentication.

[0112] The image authentication ECU 60 causes the camera 65 to capture an image in response to an instruction from the central ECU 10, and extracts a facial image of the occupant from the captured image. The image authentication ECU 60 extracts features of the facial portion included in the image captured by the camera 65, and authenticates the user based on the comparison result between the extracted features and the features stored in the second memory 61.

[0113] Next, an operation to be performed when a response indicating that communication with the portable device 5 is not possible is obtained from the key authentication ECU 50 in the determination of step SC3 will be described with reference to the flowchart shown in FIG.

[0114] The central ECU 10 displays the first setting screen 200 shown in Fig. 3 on the touch panel 16 (step SC11). If the occupant permits the program update, the occupant selects the radio button 151 and presses the decision button 155. If the occupant does not permit the program update, the occupant selects the radio button 153 and presses the decision button 155.

[0115] The central ECU 10 determines whether or not the permission operation has been received (step SC12). If the permission operation has not been received but the refusal operation has been received (step SC12 / NO), the central ECU 10 does not permit the image authentication ECU 60 to update the second program (step SC13), and ends this processing flow.

[0116] When the central ECU 10 receives the permission operation (step SC12 / YES), it permits the image authentication ECU 60 to update the program (step SC14). After that, the central ECU 10 determines whether the program update of the image authentication ECU 60 has been successful (step SC15).

[0117] If the image authentication ECU 60 has successfully updated the program (step SC14 / YES), the central ECU 10 instructs the image authentication ECU 60 to perform image authentication (step SC15), similar to step SC10. At this time, the central ECU 10 may transmit a guide to the portable device 5 to instruct the portable device 5 to perform face authentication.

[0118] Furthermore, if the image authentication ECU 60 has not been successful in updating the program (step SC14 / NO), the central ECU 10 acquires the position information of the vehicle 3 from the GNSS sensor 15 (step SC16). Next, the central ECU 10 refers to the contact table 115 and notifies the notification destination registered as the second notification destination that the image authentication ECU 60 has failed to update the program (step SC17). This notification destination may be a road service provider that provides road service, or may be the contact information of a family member of the owner of the vehicle 3 registered in the contact table 115.

[0119] Next, the central ECU 10 instructs the zone B-ECU 40 to release the door lock (step SC18), thereby forcibly unlocking the doors.

[0120] Next, the central ECU 10 controls the zone A-ECU 30 so that power supply to the TCU 14 is maintained, and activates the TCU 14. For example, when a phone number of a road service provider is selected by touching the touch panel 16, the central ECU 10 calls the selected number via the TCU 14.

[0121] Furthermore, the central ECU 10 transmits to the zone A-ECU 30 an instruction to prohibit the driving of the driving device 31 (step SC20).

[0122] The above-described embodiment is a preferred embodiment of the present invention, but the present invention is not limited to this embodiment and various modifications are possible within the scope of the present invention.

[0123] For example, the configuration of the vehicle control system 1 shown in Fig. 1 and the configuration of the central ECU 10 shown in Fig. 2 show functional configurations, and the specific implementation form is not particularly limited. In other words, it is not necessarily necessary to implement hardware corresponding to each functional unit individually, and it is of course possible to configure the system so that one processor executes a program to realize the functions of multiple functional units. Furthermore, some of the functions realized by software in the above embodiments may be realized by hardware, or some of the functions realized by hardware may be realized by software.

[0124] 4, 7, 9, and 10 are divided into processing units according to the main processing content to facilitate understanding of the processing of the central ECU 10, and the present invention is not limited by the manner in which the processing units are divided or the names of the processing units shown in the flowcharts of FIG. 4, 7, 9, and 10. Furthermore, the processing of the central ECU 10 can be divided into more processing units according to the processing content, or one processing unit can be divided so as to include more processes. Furthermore, the processing order of the above flowcharts is not limited to the example shown in the drawings.

[0125] 5. Configurations supported by the above embodiments The above embodiment is a specific example of the following configuration.

[0126] (Configuration 1) A vehicle control system comprising: a first control device that acquires first authentication information through wireless communication with a portable device and controls locking and unlocking of a vehicle based on the acquired first authentication information; a second control device that acquires second authentication information based on an image captured by a camera and controls locking and unlocking of the vehicle based on the acquired second authentication information; and an update management device that, when an update process for updating a program executed by the second control device fails, performs a first operation if communication between the first control device and the portable device is possible, and performs a second operation different from the first operation if communication between the first control device and the portable device is not possible when the update process fails.

[0127] The vehicle control system of configuration 1 executes a first operation when a program update of the second control device fails and communication between the first control device and the portable device is possible, and executes a second operation different from the first operation when the update process fails and communication between the first control device and the portable device is impossible. Therefore, the operation executed by the update management device is changed depending on the communication status between the control device and the portable device. For example, when communication between the first control device and the portable device is possible, the update management device can notify the portable device of the program update failure, and when communication between the first control device and the portable device is impossible, the update management device can notify a preset notification destination of the program update failure. This prevents a situation in which a program update failure of the second control device goes unnotified, improving user convenience.

[0128] (Configuration 2) The vehicle control system of claim 1, wherein the update management device notifies a predetermined first notification destination as the first action if the update process fails and communication between the first control device and the portable device is possible, and notifies a predetermined second notification destination different from the first notification destination as the second action if the update process fails and communication between the first control device and the portable device is not possible.

[0129] The vehicle control system of configuration 2 notifies a preset first notification destination as a first operation when communication between the first control device and the portable device is possible, and notifies a second notification destination as a second operation when communication between the first control device and the portable device is impossible. Therefore, it is possible to notify a failure of a program update of the second control device regardless of the communication status between the first control device and the portable device. This makes it possible to prevent a situation in which a failure of a program update of the second control device is not notified, thereby improving user convenience.

[0130] (Configuration 3) The vehicle control system of configuration 2, wherein if the update process fails but communication between the first control device and the portable device is possible, the update management device sends a notification of the failure of the update process to the first notification destination, with the registered address of the portable device or the owner of the vehicle as the first notification destination.

[0131] In the vehicle control system of configuration 3, when communication between the first control device and the portable device is possible, a notification of failure of the update process is sent to the portable device or the registered address of the vehicle owner, thereby notifying the vehicle owner of the failure of the update process.

[0132] (Configuration 4) The vehicle control system of configuration 3, wherein the update management device transmits the failure notification including guidance to the effect that at least one of unlocking the vehicle using the portable device and starting the drive source installed in the vehicle is required.

[0133] The vehicle control system of configuration 4 transmits a notification that the recipient of the failure notification needs to unlock the vehicle using the portable device or start the drive source installed in the vehicle, thereby notifying the recipient of the process that they must perform.

[0134] (Configuration 5) In the vehicle control system of configuration 2, if the update process fails and communication between the first control device and the portable device is not possible, the update management device sends a notification of the failure of the update process to the second notification destination, which is the address of a user registered in correspondence with at least one of a road service provider and the owner of the vehicle.

[0135] In the vehicle control system of configuration 5, when communication between the first control device and the portable device is impossible, a notification of failure of the update process is sent to the address of the user registered in association with at least one of the road service provider and the owner of the vehicle. Therefore, when the vehicle cannot be unlocked using the portable device, the failure of the update process can be notified to at least one of the road service provider and the registered address of the user, thereby improving convenience for the user.

[0136] (Configuration 6) 6. The vehicle control system according to configuration 5, wherein the update management device transmits the failure notification including location information indicating a location of the vehicle.

[0137] In the vehicle control system of configuration 6, the failure notification includes location information indicating the location of the vehicle. Therefore, even if the vehicle cannot be unlocked and becomes unable to drive, the location of the vehicle can be identified.

[0138] (Configuration 7) The vehicle control system according to configuration 1, further comprising a locking mechanism for locking the doors of the vehicle, and the update management device instructs the locking mechanism to unlock the doors if the update process fails and communication between the first control device and the portable device is not possible.

[0139] In the vehicle control system of configuration 7, if the update process fails and communication between the first control device and the portable device is not possible, the locking mechanism is instructed to unlock. Therefore, if the program update of the second control device fails, the vehicle is unlocked, thereby reducing the occurrence of a situation where occupants cannot get into the vehicle.

[0140] (Configuration 8) The vehicle control system according to configuration 7, further comprising a wireless communication unit and a reception device that receives operations, and if the update management device fails to perform the update process, the update management device wirelessly connects to a party selected by the operation received by the reception device via the wireless communication unit.

[0141] In the vehicle control system of configuration 8, if the update process fails, the wireless communication unit of the vehicle control system can wirelessly connect to a party selected by the occupant. If the program update of the second control device fails, the selected party can be contacted.

[0142] (Configuration 9) The vehicle control system according to configuration 7 or 8 includes a drive source control device that controls a drive source mounted on the vehicle, and when the update management device instructs the locking mechanism to release the lock, it sends an instruction to the drive source control device to prohibit operation of the drive source.

[0143] In the vehicle control system of configuration 9, when an instruction to unlock the lock mechanism is sent, an instruction to prohibit driving of the driving source is sent to the driving source control device. Therefore, even if the vehicle is unlocked, the vehicle will not run without driving the driving source, thereby preventing vehicle theft.

[0144] (Configuration 10) 2. The vehicle control system according to configuration 1, wherein the vehicle control system includes a reception device that receives an operation, and the update management device receives settings for the first operation and the second operation via the reception device.

[0145] In the vehicle control system of configuration 10, the reception device receives settings for the first and second actions, so that the first and second actions can be set by an operation by the occupant.

[0146] (Configuration 11) A control method for a vehicle control system comprising: a first control device that acquires first authentication information via wireless communication with a portable device and controls locking and unlocking of a vehicle based on the acquired first authentication information; a second control device that acquires second authentication information based on an image captured by a camera and controls locking and unlocking of the vehicle based on the acquired second authentication information; and an update management device that manages updates of programs executed by the first control device and the second control device, wherein a processor mounted on the update management device performs a first operation if communication between the first control device and the portable device is not possible when an update process for updating the program executed by the second control device fails, and performs a second operation different from the first operation if communication between the first control device and the portable device is possible when the update process fails.

[0147] The control method for a vehicle control system according to configuration 11 executes a first operation when a program update for the second control device fails and communication between the first control device and the portable device is possible, and executes a second operation different from the first operation when the update process fails and communication between the first control device and the portable device is impossible. Therefore, the operation executed by the update management device is changed depending on the communication status between the control device and the portable device. For example, when communication between the first control device and the portable device is possible, the portable device can be notified of the program update failure, and when communication between the first control device and the portable device is impossible, the program update failure can be notified to a preset notification destination. This prevents a situation in which a program update failure for the second control device goes unnotified, improving user convenience. [Explanation of symbols]

[0148] 1...vehicle control system, 3...vehicle, 3a...first communication line, 3b...first communication line, 4a...second communication line, 4b...second communication line, 5...portable device, 10...central ECU, 11...ICB, 12...speaker, 13...microphone, 14...TCU, 15...GNSS sensor, 16...touch panel, 17...display, 18...touch sensor, 19...in-vehicle connection link, 20...DMC, 30...zone A-ECU, 31...drive unit, 33...battery, 40...zone B-ECU, 41...light body, 43...window motor, 45...door sensor, 47...door lock mechanism, 49...weight sensor, 50...key authentication ECU, 51...first memory, 53...first processor, 55...LF / RF antenna, 60...image authentication ECU, 61 ...Second memory, 63...Second processor, 65...Camera, 110...Third memory, 111...Third program, 113...Map data, 115...Contact table, 130...Third processor, 131...Information acquisition unit, 133...Disembarkation detection unit, 135...Program update unit, 137...Determination unit, 150...Permission request screen, 151...Radio button, 153...Radio button, 155...Decision button, 200...First setting screen, 211...Radio button, 213...Radio button, 215...Decision button, 250...Second setting screen, 260...First display field, 261...Radio button, 263...Radio button, 270...Second display field, 271...Radio button, 273...Radio button, 280...Decision button, 300...Server device, 350...Network.

Claims

1. a first control device that acquires first authentication information through wireless communication with the portable device and controls locking and unlocking of the vehicle based on the acquired first authentication information; a second control device that acquires second authentication information based on an image captured by the camera and controls locking and unlocking of the vehicle based on the acquired second authentication information; When an update process for updating the program executed by the second control device fails, if communication between the first control device and the portable device is possible, execute a first operation; an update management device that executes a second operation different from the first operation when communication between the first control device and the portable device is not possible when the update process fails; A vehicle control system comprising:

2. The update management device If the update process fails and communication between the first control device and the portable device is possible, the first operation is to notify a preset first notification destination; 2. The vehicle control system of claim 1, wherein if the update process fails and communication between the first control device and the portable device is not possible, the second operation is to notify a second notification destination that is pre-set and different from the first notification destination.

3. The vehicle control system of claim 2, wherein if the update process fails but communication between the first control device and the portable device is possible, the update management device sends a notification of the failure of the update process to the first notification destination, with the registered address of the portable device or the owner of the vehicle as the first notification destination.

4. The vehicle control system of claim 3, wherein the update management device transmits the failure notification including guidance indicating that at least one of unlocking the vehicle using the portable device and starting the drive source installed in the vehicle is required.

5. The vehicle control system of claim 2, wherein if the update process fails and communication between the first control device and the portable device is not possible, the update management device sends a notification of the failure of the update process to a second notification destination, the second notification destination being the address of a user registered in correspondence with at least one of a road service provider and the owner of the vehicle.

6. The vehicle control system according to claim 5 , wherein the update management device transmits the failure notification including location information indicating a location of the vehicle.

7. The vehicle control system includes: a locking mechanism for locking the vehicle door; The vehicle control system according to claim 1 , wherein the update management device instructs the locking mechanism to release the lock when the update process fails and communication between the first control device and the portable device is not possible.

8. The vehicle control system includes: a wireless communication unit; a reception device that receives an operation, The vehicle control system according to claim 7 , wherein, if the update process fails, the update management device wirelessly connects via the wireless communication unit to a party selected by an operation received by the reception device.

9. The vehicle control system a drive source control device that controls a drive source mounted on the vehicle; 9. The vehicle control system according to claim 7, wherein the update management device, when instructing the locking mechanism to release the lock, transmits an instruction to the drive source control device to prohibit driving of the drive source.

10. The vehicle control system includes: A reception device is provided for receiving operations, The vehicle control system according to claim 1 , wherein the update management device receives settings for the first operation and the second operation from the reception device.

11. A control method for a vehicle control system including a first control device that acquires first authentication information through wireless communication with a portable device and controls locking and unlocking of a vehicle based on the acquired first authentication information, a second control device that acquires second authentication information based on an image captured by a camera and controls locking and unlocking of the vehicle based on the acquired second authentication information, and an update management device that manages updates of programs executed by the first control device and the second control device, A processor mounted on the update management device When an update process for updating the program executed by the second control device fails and communication between the first control device and the portable device is impossible, a first operation is executed; A control method for a vehicle control system, comprising: executing a second operation different from the first operation if communication between the first control device and the portable device is possible when the update process fails.

Citation Information

Patent Citations

  • Program rewriting system

    JP2006082648A