Entry system and entry control method

The entry system addresses issues of personal authentication and data protection in vehicles by using an acquisition, authentication, and management unit to ensure secure and accurate user verification, updating authentication data for improved security and confidentiality.

JP2025153453APending Publication Date: 2025-10-10HONDA MOTOR CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024055945
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-29
Publication Date
2025-10-10

AI Technical Summary

Technical Problem

Existing vehicle entry systems face challenges in ensuring appropriate personal authentication while protecting user biometric data confidentiality, particularly due to changes in physical appearance and the risk of sensitive information exposure in transferred vehicles.

Method used

An entry system and method that includes an acquisition unit for personal data, an authentication unit for comparison with registered data, and a management unit for updating authentication data based on the latest personal data, ensuring secure and accurate user verification.

Benefits of technology

Enables appropriate personal authentication of vehicle users while effectively protecting their personal data, preventing unauthorized access and maintaining data confidentiality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025153453000001_ABST
    Figure 2025153453000001_ABST
Patent Text Reader

Abstract

To ensure appropriate personal authentication of a user of a movable body while effectively protecting data for authentication as the user's personal information.SOLUTION: An entry system includes: an acquisition unit for acquiring personal data of an object person intending to use a movable body; an authentication unit for collating the acquired personal data with a registered user's data for authentication that is stored in a storage device to authenticate that the object person is the registered user on the basis of the acquired personal data of the object person; and a management unit for managing the data for authentication. When the authentication unit succeeds in authentication of the object person, the management unit updates the data for authentication regarding the registered person who is the object person on the basis of the acquired personal data of the object person.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an entry system and an entry control method for a mobile body. [Background technology]

[0002] In recent years, efforts to provide access to sustainable transport systems that take into consideration vulnerable transport participants such as the elderly, people with disabilities, and children have been gaining momentum. To achieve this, we are focusing on research and development to further improve transport safety and convenience through development of vehicle ingress and egress.

[0003] Patent Document 1 discloses a technology that captures two types of biometric data of a user for access to and control of a vehicle, and allows the user to access and control the vehicle if the captured biometric data matches pre-registered biometric data for authentication. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] U.S. Patent No. 10,745,018 Summary of the Invention [Problem to be solved by the invention]

[0005] Incidentally, when authentication is performed using personal data of a user, such as biometric data, when getting in and out of a vehicle, it is necessary to improve the appropriateness of the authentication and the confidentiality of the personal data. For example, authentication data stored in the system for comparison with personal data must clearly express the characteristics of the personal data so that the system does not erroneously determine whether the subject is a legitimate vehicle user. On the other hand, authentication data based on a facial image, for example, may deviate from the current characteristics of the individual due to changes in the individual's physical condition, body shape, hairstyle, etc. at the time the facial image was captured, as well as changes in these over time since the image was captured. Furthermore, vehicles are frequently transferred to others, and if sensitive personal information such as biometric data remains in the storage device of a transferred vehicle, this may cause vehicle users to feel uneasy about the protection of their personal information.

[0006] The present application aims to solve the above-mentioned problems by enabling appropriate personal authentication of users of mobile vehicles while effectively protecting authentication data as personal information of users, thereby contributing to the development of sustainable transportation systems. [Means for solving the problem]

[0007] One aspect of the present invention is an entry system comprising an acquisition unit that acquires personal data of a subject who intends to use a mobile object, an authentication unit that compares the acquired personal data with authentication data of a registered user stored in a storage device and authenticates that the subject is the registered user based on the acquired personal data of the subject, and a management unit that manages the authentication data, wherein when the authentication unit successfully authenticates the subject, the management unit updates the authentication data for the registered user who is the subject based on the acquired personal data of the subject. One aspect of the present invention is an entry control method performed by a computer of an entry system, comprising: an acquisition step of acquiring personal data of a subject who intends to use a mobile object; an authentication step of comparing the acquired personal data with authentication data of a registered user stored in a storage device and authenticating that the subject is the registered user based on the acquired personal data of the subject; and a management step of managing the authentication data, wherein in the management step, when the authentication of the subject is successful in the authentication step, the authentication data for the registered user who is the subject is updated based on the acquired personal data of the subject. [Effects of the Invention]

[0008] According to the present invention, it is possible to appropriately perform personal authentication of a user of a mobile body, while effectively protecting the personal data of the user used for authentication. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 1 is a diagram showing an example of the configuration of a moving body equipped with an entry system according to one embodiment of the present invention. [Figure 2] FIG. 2 is a diagram showing the configuration of the entry system. [Figure 3] FIG. 3 is a diagram for explaining the operation of detecting a target person approaching a moving body. [Figure 4] FIG. 4 is a flowchart showing the procedure of the operation in the entry system. DETAILED DESCRIPTION OF THE INVENTION

[0010] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0011] [1. Vehicle configuration] FIG. 1 is a diagram showing the configuration of a mobile body 2 equipped with an entry system 1 according to this embodiment. The mobile body 2 includes an entry control device 3 that constitutes the entry system 1. The entry system 1 is installed in the mobile body 2 and authenticates a target person P, who is any person attempting to enter the mobile body 2. If the entry system 1 is able to authenticate that the target person P has legitimate access to the mobile body 2, the target person P is allowed to use the mobile body 2. Here, "entering" the mobile body 2 refers to at least boarding (or getting on) the mobile body 2 from outside the mobile body 2, and may also include starting use of the system by logging in to the system of the mobile body 2 after boarding. For example, logging in to the system of the mobile body 2 may include transitioning the mobile body 2 to a state in which the target person P can begin operating the system, such as enabling the start of a drive device (engine, motor, etc.) equipped in the mobile body 2.

[0012] In this embodiment, the moving body 2 is, for example, a passenger car, and may be a shared car that can accommodate multiple people. However, the moving body 2 is not limited to a passenger car, and may be any moving body. Such moving bodies may be land moving bodies such as passenger cars, buses, taxis, and trains, marine moving bodies such as ships and submarines, and air moving bodies such as aircraft including eVTOL (Electric Vertical Take-Off and Landing aircraft), and airborne moving bodies such as airships.

[0013] The right side of the moving body 2 is equipped with a right object detection sensor 4a that detects objects present on the right side of the moving body 2, a first right camera 5a and a second right camera 6a that photograph the right side of the moving body 2, and a right illuminator 7a that illuminates the right side of the moving body 2.

[0014] The left side of the moving body 2 is equipped with a left object detection sensor 4b that detects objects present on the left side of the moving body 2, a first left camera 5b and a second left camera 6b that photograph the left side of the moving body 2, and a left illuminator 7b that illuminates the left side of the moving body 2.

[0015] The rear of the moving body 2 is equipped with a rear object detection sensor 4c that detects objects present behind the moving body 2, a first rear camera 5c and a second rear camera 6c that photograph the area behind the moving body 2, and a rear illuminator 7c that illuminates the area behind the moving body 2.

[0016] In the following, when there is no need to distinguish between the right object detection sensor 4a, the left object detection sensor 4b, and the rear object detection sensor 4c, they will be referred to as object detection sensors 4. When there is no need to distinguish between the first right camera 5a, the first left camera 5b, and the first rear camera 5c, they will be referred to as first cameras 5. When there is no need to distinguish between the second right camera 6a, the second left camera 6b, and the second rear camera 6c, they will be referred to as second cameras 6. When there is no need to distinguish between the right illuminator 7a, the left illuminator 7b, and the rear illuminator 7c, they will be referred to as illuminators 7.

[0017] The second camera 6 has a higher resolution and consumes more power than the first camera 5. The first camera 5 and the second camera 6 are, for example, CCD cameras with different numbers of pixels. The object detection sensor 4 is, for example, a distance measurement sensor that can detect surrounding objects and measure the distance to the objects, and in this embodiment is a millimeter-wave radar. The object detection sensor 4 is not limited to a radar, and can be any distance measurement sensor that can detect objects and measure distances. Such a sensor can be, in addition to radar, for example, a lidar, a sonar, or the like. The illuminator 7 may be configured using, for example, any light emitter or light emitting element, and in this embodiment, the illuminator 7 is, for example, an LED floodlight.

[0018] The mobile body 2 also includes a door opener 9 provided at each of the doors 8 of the mobile body 2 for locking and unlocking the door 8 and opening and closing the door 8. The door opener 9 may include an actuator for locking and unlocking the corresponding door 8 and an actuator for opening and closing the door 8.

[0019] In this embodiment, the moving body 2 is equipped with, as the doors 8 and door opening / closing devices 9, a right front door opening / closing device 9a provided on a driver's door 8a on the right front side of the moving body 2, and a right rear door opening / closing device 9b provided on a right rear door 8b on the right rear side of the moving body 2. The moving body 2 also is equipped with a left front door opening / closing device 9c provided on a passenger's door 8c on the left front side of the moving body 2, and a left rear door opening / closing device 9d provided on a left rear door 8d on the left rear side of the moving body 2. The moving body 2 further is equipped with a back door opening / closing device 9e provided on a back door (tailgate door) 8e of the moving body 2.

[0020] The mobile object 2 also includes a communication device 10. The communication device 10 includes a transceiver for communicating with an electronic key 11 used to use the mobile object 2. The electronic key 11 may be, for example, a smart key such as a FOB key, or a mobile terminal such as a smartphone that stores key information used to use the mobile object 2.

[0021] The moving object 2 may also be provided with an interior camera 12 that captures images of the interior of the moving object 2, located at the front of the interior of the moving object 2. The interior camera 12 can capture images of the interior of the moving object 2, including the face of a driver seated in the driver's seat. For example, if the moving object 2 is a vehicle, the interior camera 12 may be a driver monitoring camera (DMC) installed in the vicinity of the center in the vehicle width direction of an instrument panel (not shown) inside the vehicle. Note that the interior camera 12 is not limited to being installed on the instrument panel, but may be installed in any position where it can capture images of the interior of the vehicle, including the face of the driver, such as below the rearview mirror.

[0022] [2. Entry system configuration] The configuration of the entry system 1 will be described. 2 is a diagram showing the configuration of the entry system 1. The entry system 1 includes at least an entry control device 3. The entry control device 3 authenticates a subject P, who is any person attempting to enter the mobile object 2, and if authentication is successful, allows the subject P to use the mobile object 2. The authentication is performed by comparing personal data acquired about the subject P with authentication data of registered users stored in advance in a storage device.

[0023] In the following, "target person" refers to a person who is the subject of authentication by the entry system 1. Furthermore, "user" refers to a registered user who has been pre-registered as a person with legitimate authority to use the mobile object 2, and who actually uses the mobile object 2. Target person P becomes a user when he or she is authenticated by the entry control device 3 and becomes able to use the mobile object 2.

[0024] The personal data used for authentication may be any data that can be used to identify or specify the individual subject P. For example, the personal data may be physical data or biometric data of the subject P. The physical data or biometric data may be one or a combination of two or more of a face image, a fingerprint image, an iris image, a vein image extracted from a skin image, and a voiceprint extracted from voice. In this embodiment, the personal data acquired for authentication is a face image.

[0025] Some of the functional elements of the entry control device 3 described below may be provided in other devices. For example, a control unit 28 (described later) provided in the entry control device 3 may be realized as a functional element of another electronic control device (ECU, Electronic Control Unit) that controls the operation of the mobile object 2. In this case, the entry system 1 includes the entry control device 3 and the above-mentioned electronic control device, and the entry control device 3 can communicate with the above-mentioned electronic control device and cause the electronic control device to execute the functions of the control unit 28. The entry system 1 may also include other devices such as an object detection sensor 4, a first camera 5, a second camera 6, etc., which are used by the entry control device 3.

[0026] The entry control device 3 includes a processor 20 and a memory 21. The memory 21 is configured, for example, with a volatile and / or non-volatile semiconductor memory and / or a hard disk drive, etc. The memory 21 stores authentication data 23 for each of one or more registered users who have been registered in advance as persons having legitimate authority to use the mobile object 2.

[0027] The processor 20 is, for example, a computer equipped with a CPU, etc. The processor 20 may have a configuration including a ROM in which a program is written, a RAM for temporarily storing data, etc. The processor 20 includes, as functional elements or functional units, a detection unit 24, an acquisition unit 25, a determination unit 26, an authentication unit 27, a control unit 28, and a management unit 29.

[0028] These functional elements of the processor 20 are realized, for example, by the processor 20, which is a computer, executing a program 22 stored in a memory 21. The program 22 can be stored in any computer-readable storage medium. Alternatively, all or part of the functional elements of the processor 20 can be configured by hardware including one or more electronic circuit components.

[0029] The detection unit 24 uses the object detection sensor 4 and the first camera 5 to detect a target person P approaching the moving object 2. The detection unit 24 operates, for example, as shown in Fig. 3. Fig. 3 is an explanatory diagram for explaining the operation of the detection unit 24. The detection unit 24 first determines whether an actual object (or an object) has entered within a predetermined distance D1 from the moving body 2 using the object detection sensor 4. The actual object may be any object, including living and non-living objects. When an actual object has entered within the predetermined distance D1, the detection unit 24 activates the first camera 5 closest to the object detection sensor 4 that detected the actual object.

[0030] The detection unit 24 continuously acquires first images of the surroundings of the moving body 2 at predetermined time intervals using the activated first camera 5. The detection unit 24 performs image recognition processing on the first images captured by the first camera 5 and determines whether the actual object is a person. If the actual object is a person, the detection unit 24 determines whether the person is approaching the moving body 2 from the first images continuously captured by the first camera 5. If the person is approaching the moving body 2, the detection unit 24 determines that the person is a target person P. In this way, the detection unit 24 detects the target person P approaching the moving body 2. When the detection unit 24 detects the target person P, it notifies the acquisition unit 25 of this fact. In the example shown in Figure 3, while the actual object detected by the object detection sensor 4 moves to a position at a distance D2 from the moving body 2, the detection unit 24 determines that the actual object is a person approaching the moving body 2, and when the person reaches a position at a distance D2, the detection unit 24 notifies the acquisition unit 25 that the target person P has been detected.

[0031] The acquisition unit 25 acquires personal data of a subject P who intends to use the moving object 2. In this embodiment, the personal data is, for example, a facial image of the subject P. When the detection unit 24 detects the subject P, the acquisition unit 25 activates a second camera 6 close to the first camera 5 used to detect the subject P, and acquires a second image of the subject P at predetermined time intervals using the activated second camera 6. When activating the second camera 6, the acquisition unit 25 may turn on an illuminator 7 close to the activated second camera 6 if the surroundings of the moving object 2 are dark.

[0032] As described above, the second camera 6 has higher resolution and consumes more power than the first camera 5. The acquisition unit 25 uses the activated second camera 6 to continuously capture high-resolution second images of the subject P at predetermined time intervals. Every time the acquisition unit 25 captures a second image of the subject P, it extracts a facial image of the subject P from the second image and acquires a plurality of facial images of the subject P captured at predetermined time intervals. Every time the acquisition unit 25 captures a second image of the subject P, it sends the captured image of the subject P and the extracted facial image to the determination unit 26 and the authentication unit 27.

[0033] The determination unit 26 determines whether or not the subject P intends to board the moving object 2, based on the movement of the subject P recognized from the plurality of second images captured at the predetermined time intervals. For example, the determination unit 26 can determine that the subject P intends to board the moving object 2 when the subject P approaches further to any of the doors 8 of the moving object 2, when the subject P stops in front of any of the doors 8 of the moving object 2, when the subject P reaches for the door handle of any of the doors 8, etc. In the example shown in FIG. 3, the determination unit 26 determines whether or not the subject person P intends to board the vehicle 2, for example, at a position at a distance D3 from the vehicle 2. The determination unit 26 notifies the authentication unit 27 of the determination result as to whether or not the subject P intends to board the moving body 2.

[0034] The authentication unit 27 compares the facial image as personal data acquired by the acquisition unit 25 with the authentication data 23 of the registered user recorded in the memory 21, which is a storage device. As a result, the authentication unit 27 authenticates that the subject P is a registered user based on the facial image as personal data of the subject P acquired above.

[0035] As described above, the acquisition unit 25 sends the captured image of the subject P and the facial image to the authentication unit 27 every time the second image of the subject P is captured, so that the authentication unit 27 can authenticate the subject P in parallel with the acquisition of the second image by the acquisition unit 25. For example, in the example of Fig. 3, the authentication unit 27 can operate to complete authentication of the subject P at a position at a distance D3 where the determination unit 26 completes the determination as to whether or not the subject P intends to board.

[0036] Specifically, the authentication unit 27 calculates the features of the facial image acquired by the acquisition unit 25, and calculates a matching score for each registered user indicating the degree of match between the calculated features (hereinafter referred to as target features) and the features of the facial image stored in the authentication data 23 of each registered user stored in the memory 21 (hereinafter referred to as authentication features).

[0037] Then, based on the calculated matching scores, the authentication unit 27 determines whether the subject P is one of the registered users. Specifically, for example, when the calculated matching scores include a matching score equal to or greater than a first predetermined value, the authentication unit 27 authenticates the subject P as the registered user corresponding to the matching score that shows the highest value among the matching scores equal to or greater than the first predetermined value. This results in successful authentication of the subject P.

[0038] On the other hand, if there is no matching score that is equal to or greater than the first predetermined value among the calculated matching scores, the authentication unit 27 determines that the subject P is not a registered user. As a result, the authentication of the subject P is unsuccessful.

[0039] Here, the authentication unit 27 may calculate the matching score for each of a plurality of facial images of the subject P extracted from a plurality of images acquired by the acquisition unit 25 at a predetermined time interval, and determine whether or not there is a registered user corresponding to the subject P based on the calculated matching score. In this case, the authentication unit 27 may determine that the subject P is the one registered user when the registered user corresponding to the subject P determined for each of the plurality of facial images is the same one registered user in the plurality of facial images with a probability equal to or greater than a predetermined value. When the authentication unit 27 cannot identify the one registered user, it can determine that the subject P is not a registered user.

[0040] When authenticating the subject P, the authentication unit 27 may perform a so-called liveness determination to determine whether or not a facial image acquired as personal data about the subject P is an image of the actual face of the subject P. If the authentication unit 27 determines in the liveness determination that the acquired facial image is not an image of the actual face of the subject P, such as an image of the head of a third party wearing a mask with a facial photograph printed on it, the authentication unit 27 may determine that the authentication using the facial image is unsuccessful.

[0041] Specifically, authentication unit 27 can authenticate whether subject P is a registered user based on the facial images, on the condition that the hue of each of the facial images extracted from each of the plurality of images captured continuously at a predetermined time interval by detection unit 24 from second camera 6 and / or the change in the time-series brightness distribution of the facial images satisfy a predetermined criterion. Here, the criterion can be, for example, that the hue of the facial image is not a hue specific to printed matter, and / or that the illumination of subject P's face as understood from the plurality of time-series facial images changes continuously and without contradiction.

[0042] This effectively prevents, for example, a target person P from fraudulently attempting to enter the moving object 2 by wearing a mask on which the face image of a registered user who is another person is printed.

[0043] The authentication unit 27 may be configured to authenticate that the target person P is a registered user when the determination unit 26 determines that the target person P has an intention to board the moving object 2. This prevents the authentication unit 27 from unnecessarily authenticating a person who is not intending to board the moving object 2 as the target person P.

[0044] The authentication unit 27 may also authenticate that the subject P is a registered user on the condition that a gesture made by the subject P matches a pre-registered authentication gesture based on a plurality of images captured continuously at a predetermined time interval by the detection unit 24 from the second camera 6. The authentication gesture may be configured, for example, from a time series of images acquired in advance from the registered user and stored in the memory 21. This allows for more appropriate authentication of the target person P based on the target person P's gestures as well.

[0045] When the authentication unit 27 has successfully authenticated the target person P, the control unit 28 controls the mobile object 2 to enable the target person P to use the mobile object 2. In the present embodiment, for example, when the authentication unit 27 has successfully authenticated the target person P, the control unit 28 instructs the door opener 9 of the mobile object 2 to automatically unlock the door 8. At that time, the control unit 28 may instruct the door opener 9 to automatically open the door 8 after unlocking the door 8. The control unit 28 may, for example, execute the automatic unlocking and automatic opening operations on the door 8 closest to the target person P. The door 8 closest to the target person P may be identified, for example, by the acquisition unit 25 from the most recently acquired second image and notified to the control unit 28.

[0046] The control unit 28 may also start the moving object 2 on the condition that the authentication unit 27 has successfully authenticated the target person P. For example, the control unit 28 may permit a control device (not shown) mounted on the moving object 2 to allow the target person P to execute a start operation for the moving object 2 on the condition that the target person P, who has been successfully authenticated, gets into the moving object 2 through the driver's door 8a.

[0047] The management unit 29 manages the authentication data 23 of registered users. In this embodiment, when the authentication unit 27 successfully authenticates the subject P, the management unit 29 updates the authentication data 23 for the registered user who is the subject P, based on the personal data of the subject P acquired by the acquisition unit 25. For example, the management unit 29 calculates the feature amount of the facial image, which is the personal data, and updates the authentication data 23 using the calculated feature amount.

[0048] As a result, the authentication data 23 of the user who is a registered user of the mobile object 2 is updated based on the latest personal data, and therefore authentication operations can be performed appropriately using the latest authentication data 23. Furthermore, since the usage history of the user's mobile object 2 can be kept as an update history of the authentication data 23, it becomes possible to appropriately determine whether or not it is necessary to delete the authentication data 23, which is personal information, based on the update history, for example, by deleting the authentication data when the mobile object 2 is not used for a long period of time.

[0049] The management unit 29 also manages the time that has elapsed since the most recent update for each piece of authentication data 23 recorded in the memory 21, and deletes from the memory 21 any piece of authentication data 23 that has elapsed a predetermined first time. This allows the unused state of the user's mobile body 2 to be grasped from the update date and time as the update history of the authentication data 23, and the authentication data 23 that is becoming unnecessary to be erased, thereby effectively protecting the authentication data 23, which is the user's personal information.

[0050] For example, the management unit 29 stores information on the date and time when the authentication data 23 was updated as the update date and time in the memory 21, in association with the updated authentication data 23. Thereafter, the management unit 29 can ascertain the time that has elapsed since the most recent update of the authentication data 23 by comparing the current date and time with the update date and time.

[0051] In addition, the management unit 29 may update the authentication data 23 recorded in the memory 21 when authentication of the corresponding registered user, subject P, is successful, for which the elapsed time since the most recent update has exceeded a predetermined second time, which is shorter than the first time. This makes it possible to avoid unnecessarily frequent updates of the authentication data 23 of registered users who frequently use the mobile unit 2, thereby realizing stable authentication operations.

[0052] Here, the second time period can be set in advance for each piece of authentication data 23 by the corresponding registered user. This allows a registered user to set the second time period according to, for example, how frequently he or she uses the mobile object 2, thereby preventing his or her authentication data 23 from being updated unnecessarily frequently.

[0053] [3. Entry System Operation] Next, the operation procedure of the entry system 1 will be described. 4 is a flowchart showing the procedure of the entry control method executed by the computer of the entry system 1. In this embodiment, the computer of the entry system 1 is the processor 20 of the entry control device 3, for example.

[0054] The process shown in FIG. 4 starts when the power of each device shown in FIG. 2, including the entry control device 3, is turned on, and is repeatedly executed. When the process starts, first, the detection unit 24 determines whether or not it has detected a target person P approaching the moving object 2 (S100). If it has not detected the target person P (NO in S100), the management unit 29 determines whether or not authentication data 23 for which a first time has elapsed since the most recent update is stored in the memory 21 (S116).

[0055] If authentication data 23 for which the first time has elapsed since the most recent update is stored in memory 21 (S116, YES), management unit 29 deletes the authentication data 23 for which the first time has elapsed since the most recent update from memory 21 (S118). Thereafter, management unit 29 returns the process to step S100.

[0056] On the other hand, if the authentication data 23 for which the first time has elapsed since the most recent update is not stored in the memory 21 (S116, NO), the management unit 29 returns the process to step 100.

[0057] On the other hand, when the subject P is detected in step S100 (S100, YES), the acquisition unit 25 acquires personal data of the subject P (S102). The authentication unit 27 compares the acquired personal data with the authentication data 23 of each registered user stored in the memory 21 (S104). The authentication unit 27 determines whether or not the authentication of the subject P has been successful through the comparison (S106).

[0058] If the authentication is successful (S106, YES), the control unit 28 executes a predetermined entry operation (S108). The predetermined entry operation may be, for example, an operation to automatically unlock the door 8 of the mobile object 2. Thereafter, the management unit 29 determines whether a second time has elapsed since the authentication data 23 of the registered user corresponding to the subject P was most recently updated (S110).

[0059] Then, when the second time has elapsed since the most recent update of the authentication data 23 of the registered user corresponding to the subject P (S110, YES), the management unit 29 updates the authentication data 23 of the registered user corresponding to the subject P stored in the memory 21 using the latest personal data about the subject P acquired by the acquisition unit 25 in step S102 (S112). Next, the management unit 29 stores information about the date and time when the authentication data 23 was updated as the update date and time in the memory 21, in association with the updated authentication data 23 (S114). Thereafter, the management unit 29 ends this process.

[0060] On the other hand, if authentication of the subject P fails in step S106, that is, if it is determined that the subject P is not a registered user (S106, NO), the management unit 29 ends this process. On the other hand, if it is determined in step S110 that the second time has not elapsed since the most recent update of the authentication data 23 of the registered user corresponding to the subject P (S110, NO), the management unit 29 ends this process. After this process is completed, the processor 20 of the entry control device 3 repeats the process from step S100.

[0061] 4, steps S102 and S104 correspond to the acquisition step and authentication step, respectively, of the present disclosure, and steps S110 to S118 correspond to the management step of the present disclosure.

[0062] 4. Other Embodiments After the target person P is authenticated by the authentication unit 27 and the control unit 28 unlocks the door 8, the acquisition unit 25 of the entry control device 3 may acquire an image of the interior of the mobile object 2 including a facial image of the person sitting in the driver's seat (for example, the target person P) using the interior camera 12 and transmit the image to the authentication unit 27. The authentication unit 27 may further authenticate whether or not the person in the driver's seat is a registered user based on the facial image of the person in the driver's seat captured in the interior image. The control unit 28 can transition the state of the moving body 2 so that, on the condition that the authentication unit 27 has authenticated the person in the driver's seat in addition to authenticating the subject person P, the person in the driver's seat can perform start-up operations on the moving body 2 (including starting the driving devices such as the engine and motor).

[0063] The present invention is not limited to the configurations of the above-described embodiments, and can be implemented in various forms without departing from the spirit of the present invention.

[0064] 5. Configurations supported by the above embodiments The above-described embodiment supports the following configurations.

[0065] (Configuration 1) An entry system comprising an acquisition unit that acquires personal data of a subject who intends to use a mobile object, an authentication unit that compares the acquired personal data with authentication data of a registered user stored in a storage device and authenticates that the subject is the registered user based on the acquired personal data of the subject, and a management unit that manages the authentication data, wherein when the authentication unit successfully authenticates the subject, the management unit updates the authentication data for the registered user who is the subject based on the acquired personal data of the subject. According to the entry system of configuration 1, the authentication data of a user who is a registered user of a mobile object is updated based on the latest personal data, so that authentication operations can be performed appropriately using the latest authentication data. Furthermore, according to the entry system of configuration 1, the usage history of the user's mobile object can be kept as an update history of the authentication data, so that it is possible to determine whether or not it is necessary to erase the authentication data, which is personal information, based on the update history, for example, by erasing the authentication data when the mobile object is not used for a long period of time.

[0066] (Configuration 2) The entry system described in Configuration 1, wherein the management unit manages the elapsed time since the most recent update for each of the authentication data, and deletes from the storage device any authentication data stored in the storage device whose elapsed time has exceeded a predetermined first time. According to the entry system of configuration 2, the unused state of the user's mobile device is identified from the update history of the authentication data and the authentication data that is becoming unnecessary is erased, thereby effectively protecting the authentication data, which is the user's personal information.

[0067] (Configuration 3) The entry system described in Configuration 2, wherein the management unit updates the authentication data stored in the storage device for which the elapsed time has passed a predetermined second time period that is shorter than the first time period when authentication of the corresponding registered user, who is the target person, is successful. According to the entry system of configuration 3, it is possible to avoid unnecessarily frequent updates of authentication data of registered users who frequently use mobile devices, thereby realizing stable authentication operations.

[0068] (Configuration 4) The entry system according to Configuration 3, wherein the second time is set by the corresponding registered user for each piece of authentication data. According to the entry system of configuration 4, a registered user can set the second time period according to, for example, the frequency with which he or she uses a mobile object, thereby preventing the authentication data from being updated unnecessarily frequently.

[0069] (Configuration 5) An entry system described in any of configurations 1 to 4, wherein the acquisition unit acquires multiple facial images of the subject taken at predetermined time intervals as the personal data of the subject, and the authentication unit authenticates whether the subject is a registered user based on the personal data, on the condition that the changes in hue and / or time-series brightness distribution of each of the multiple facial images of the subject satisfy predetermined criteria. According to the entry system of configuration 5, it is possible to effectively prevent a target person from fraudulently attempting to enter a moving object by, for example, wearing a mask on which the facial image of a registered user who is another person is printed.

[0070] (Configuration 6) An entry system described in any of configurations 1 to 5, wherein the authentication unit authenticates that the subject is a registered user based on multiple images of the subject captured consecutively at a predetermined time interval, provided that the gesture performed by the subject matches a pre-registered authentication gesture. According to the entry system of configuration 6, it is possible to more appropriately authenticate the subject based on the subject's gestures as well.

[0071] (Configuration 7) An entry system described in any of configurations 1 to 6, comprising a control unit that controls the mobile body to enable the target person to use the mobile body when the authentication unit successfully authenticates the target person, and the control unit unlocks the door of the mobile body when the authentication unit successfully authenticates the target person. According to the entry system of configuration 7, convenience for users of mobile objects can be improved.

[0072] (Configuration 8) The entry system according to Configuration 7, wherein the control unit starts the mobile body on the condition that the authentication unit has successfully authenticated the subject person. According to the entry system of configuration 8, it is possible to further improve convenience for users who use a mobile vehicle as a driver.

[0073] (Configuration 9) An entry control method performed by a computer of an entry system, comprising: an acquisition step of acquiring personal data of a subject who intends to use a mobile object; an authentication step of comparing the acquired personal data with authentication data of a registered user stored in a storage device and authenticating that the subject is the registered user based on the acquired personal data of the subject; and a management step of managing the authentication data, wherein in the management step, when authentication of the subject is successful in the authentication step, the authentication data for the registered user who is the subject is updated based on the acquired personal data of the subject. According to the entry control method of the ninth aspect, the same effects as those of the first aspect can be achieved. [Explanation of symbols]

[0074] 1...entry system, 2...mobile body, 3...entry control device, 4...object detection sensor, 4a...right object detection sensor, 4b...left object detection sensor, 4c...rear object detection sensor, 5...first camera, 5a...first right camera, 5b...first left camera, 5c...first rear camera, 6...second camera, 6a...second right camera, 6b...second left camera, 6c...second rear camera, 7...illuminator, 7a...right illuminator, 7b...left illuminator, 7c...rear illuminator, 8...door, 8a...driver's door, 8b...right Rear seat door, 8c...passenger seat door, 8d...left rear seat door, 8e...tail door, 9...door opener, 9a...right front door opener, 9b...right rear door opener, 9c...left front door opener, 9d...left rear door opener, 9e...tail door opener, 10...communication device, 11...electronic key, 12...interior camera, 20...processor, 21...memory, 22...program, 23...authentication data, 24...detection unit, 25...acquisition unit, 26...judgment unit, 27...authentication unit, 28...control unit, 29...management unit.

Claims

1. an acquisition unit that acquires personal data of a subject who intends to use a mobile object; an authentication unit that compares the acquired personal data with authentication data of the registered user stored in a storage device and authenticates that the subject is the registered user based on the acquired personal data of the subject; a management unit that manages the authentication data; Equipped with when the authentication unit has successfully authenticated the target person, the management unit updates the authentication data for the registered user who is the target person based on the acquired personal data of the target person. Entry system.

2. the management unit manages the time elapsed since the most recent update of each of the authentication data, and deletes from the storage device, among the authentication data stored in the storage device, the authentication data whose elapsed time has exceeded a predetermined first time. The entry system of claim 1 .

3. the management unit updates the authentication data stored in the storage device for which the elapsed time has passed a predetermined second time period that is shorter than the first time period when authentication of the target person who is the corresponding registered user is successful. The entry system according to claim 2 .

4. the second time period is set by the corresponding registered user for each of the authentication data; 4. The entry system according to claim 3.

5. the acquiring unit acquires, as the personal data of the subject, a plurality of facial images of the subject captured at predetermined time intervals; the authentication unit authenticates whether the subject is a registered user based on the personal data, on the condition that changes in hue and / or time-series brightness distribution of each of the plurality of facial images of the subject satisfy a predetermined criterion; The entry system of claim 1 .

6. the authentication unit authenticates that the subject is a registered user on the condition that a gesture made by the subject matches a pre-registered authentication gesture based on a plurality of images of the subject captured consecutively at a predetermined time interval. The entry system of claim 1 .

7. a control unit that controls the mobile object to enable the target person to use the mobile object when the authentication unit has successfully authenticated the target person; the control unit unlocks a door of the moving object when the authentication unit has successfully authenticated the target person.

7. An entry system according to any one of claims 1 to 6.

8. The control unit starts the mobile unit on the condition that the authentication unit has successfully authenticated the target person.

8. The entry system of claim 7.

9. An entry control method performed by a computer in an entry system, An acquisition step of acquiring personal data of a subject who intends to use a mobile object; an authentication step of comparing the acquired personal data with authentication data of the registered user stored in a storage device and authenticating that the subject is the registered user based on the acquired personal data of the subject; a management step of managing the authentication data; Equipped with In the management step, when the authentication of the subject person is successful in the authentication step, the authentication data for the registered user who is the subject person is updated based on the acquired personal data of the subject person. Entry control method.

Citation Information

Patent Citations

  • US10,745,018