Service providing apparatus
The service providing device addresses the risk of unintended vehicle control by setting expiration dates and managing access locks, ensuring reliable and secure remote operation execution.
Patent Information
- Application Number
- JP2024105506
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-28
- Publication Date
- 2026-01-16
AI Technical Summary
Existing vehicle remote control systems face the risk of unintended execution of control commands due to communication failures or malfunctions, leading to potential safety and reliability issues.
A service providing device that includes an instruction receiving unit, a determination unit to set expiration dates for remote operation instructions, an instruction management unit to manage processing status, and an authentication unit to generate access locks with expiration dates, ensuring that vehicle-side control is executed within specified timeframes and preventing unintended timing.
The system provides a remote control service that ensures reliable and secure execution of commands, allowing users to operate vehicles with confidence by managing expiration dates and access controls, thereby reducing the risk of unintended control execution.
Smart Images

Figure 2026006497000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a service providing device that provides a vehicle remote control service. [Background technology]
[0002] As this type of device, a device that locks and unlocks vehicle doors based on a locking request or an unlocking request received via wireless communication from a mobile terminal carried by a user is known (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent No. 7074108 Summary of the Invention [Problem to be solved by the invention]
[0004] However, if a vehicle is remotely controlled via communication, as in the device described in Patent Document 1, there is a risk that vehicle control based on the remote control will be executed at an unintended timing if a communication failure or the like occurs. [Means for solving the problem]
[0005] A service providing device according to one aspect of the present invention includes an instruction receiving unit that receives operation instruction information transmitted from a user terminal, the operation instruction information including instructions for remote operation of a vehicle equipped with an on-board terminal, a determination unit that determines an expiration date for the remote operation instruction based on the type of the remote operation instruction contained in the operation instruction information, an instruction management unit that transmits vehicle instruction information to the on-board terminal, the operation instruction information including expiration date information indicating the expiration date, and a memory unit that stores processing status information indicating the progress of a process executed by the on-board terminal based on the vehicle instruction information. When the instruction management unit does not receive processing result information indicating the result of the process executed based on the vehicle instruction information from the on-board terminal within the expiration date, the instruction management unit updates the processing status information stored in the memory unit to information indicating the suspension of execution of the process. [Effects of the Invention]
[0006] According to the present invention, a remote control service can be provided that users can use with peace of mind. [Brief explanation of the drawings]
[0007] [Figure 1] 1 is a diagram showing an example of the configuration of a remote control system including an information processing apparatus according to an embodiment of the present invention. [Figure 2] FIG. 2 is a diagram for explaining remote control of a vehicle via a user terminal. [Figure 3] 1 is a block diagram showing the configuration of a main part of an information processing apparatus according to an embodiment of the present invention; [Figure 4] FIG. 10 is a diagram showing an example of expiration date information. [Figure 5] FIG. 2 is a block diagram showing the configuration of a main part of the in-vehicle terminal shown in FIG. 1; [Figure 6A] FIG. 2 is a sequence diagram showing an example of the operation of the remote control system of FIG. 1. [Figure 6B] FIG. 2 is a sequence diagram showing another example of the operation of the remote control system of FIG. 1. [Figure 7A] FIG. 2 is a sequence diagram showing another example of the operation of the remote control system of FIG. 1. [Figure 7B] FIG. 2 is a sequence diagram showing another example of the operation of the remote control system of FIG. 1. [Figure 8]1 is a diagram showing an example of the configuration of a map update system including an information processing device according to an embodiment of the present invention. [Figure 9] FIG. 9 is a sequence diagram showing the operation of the map update system of FIG. 8. [Figure 10] FIG. 10 is a diagram for explaining the timing of updating an access lock and the timing of acquiring an access lock. [Figure 11] FIG. 10 is a diagram for explaining the timing for starting use of the access lock. DETAILED DESCRIPTION OF THE INVENTION
[0008] FIG. 1 is a schematic diagram showing an example of the configuration of a remote operation system 1 including an information processing device (hereinafter also referred to as a service providing device) 10 according to an embodiment of the present invention. As shown in FIG. 1, the remote operation system 1 includes the service providing device 10, a user terminal 20 such as a smartphone, and an in-vehicle terminal 30, and provides a service of remotely operating a vehicle V1 in accordance with user operations input to the user terminal 20. While FIG. 1 illustrates one user terminal 20 used by a user P1 and one vehicle V1 having an in-vehicle terminal 30, two or more user terminals may be connected to the service providing device 10. Furthermore, two or more in-vehicle terminals may be connected to the service providing device 10.
[0009] FIG. 2 is a diagram illustrating remote operation of vehicle V1 via user terminal 20. User P1 can remotely operate vehicle V1 via a dedicated application (hereinafter referred to as an app) installed on user terminal 20 used by user P1. When user P1 performs remote operation to open the door of vehicle V1 via the app, information including a door open instruction and a vehicle ID that can identify vehicle V1 (hereinafter referred to as operation instruction information) is transmitted from user terminal 20 to service providing device 10 (step S21). The operation instruction information also includes information indicating the operation target. The operation target is, for example, the driver's door or the rear door.
[0010] When the service providing device 10 receives the operation instruction information, it outputs a control command to the in-vehicle terminal 30 based on the operation instruction information (step S11). When the instruction target indicated by the operation instruction information is the "driver's door" and the instruction content is "open", the service providing device 10 transmits a door open command specifying the driver's door as a control command. The control command is transmitted to the in-vehicle terminal 30 of the vehicle V1 identified by the vehicle ID included in the operation instruction information.
[0011] When the in-vehicle terminal 30 receives the door open command, it controls the door actuator corresponding to the driver's door specified in the door open command to open the driver's door (step S31).
[0012] When a communication failure occurs between the service providing device 10 and the in-vehicle terminal 30 or a malfunction occurs in the system (ECU, etc.) of the in-vehicle terminal 30, control commands from the service providing device 10 may be delayed. In this case, as shown in FIG. 2, the process in accordance with the command (the process of step S31) may be executed with a delay after the malfunction or the like is resolved. In FIG. 2, the period during which a communication failure occurs between the service providing device 10 and the in-vehicle terminal 30 is schematically represented by a dashed line. Furthermore, if the malfunction or the like is not resolved, the process in accordance with the command may not be executed. Therefore, to solve such problems, in this embodiment, the service providing device 10 is configured as follows.
[0013] FIG. 3 is a block diagram showing the main configuration of a service providing device 10 according to an embodiment of the present invention. The service providing device 10 is configured, for example, by a server device. The service providing device 10 may be configured using a virtual server function on a cloud, or may be configured as a distributed system across multiple devices. As shown in FIG. 3, the service providing device 10 includes a controller 11 and a communication unit 12. The communication unit 12 communicates with various servers and the like via a network including a wireless communication network such as the Internet network or a mobile phone network, and transmits and receives necessary information periodically or at any timing. The network may include not only a public wireless communication network but also a closed communication network established for each predetermined management area, such as a wireless LAN or Wi-Fi (registered trademark).
[0014] The controller 11 includes a computer having an arithmetic unit 110 such as a CPU (microprocessor), a storage unit 120 such as a ROM or RAM, and other peripheral circuits (not shown) such as an I / O interface.
[0015] The storage unit 120 stores various control programs, information such as thresholds used in the programs, expiration date information and processing status information (hereinafter also referred to as status information), which will be described later, and the like.
[0016] The calculation unit 110 has, as its functional components, an instruction receiving unit 111, a deadline determining unit (hereinafter simply referred to as a determining unit) 112, an instruction managing unit 113, and an authenticating unit 114.
[0017] The instruction receiving unit 111 receives, via the communication unit 12, operation instruction information transmitted from the user terminal 20, including an instruction to remotely operate the vehicle V1 on which the in-vehicle terminal 30 is mounted.
[0018] The determination unit 112 determines the expiration date of the remote operation instruction based on the type of the remote operation instruction included in the operation instruction information received by the instruction reception unit 111. Specifically, the determination unit 112 reads out information indicating the expiration date corresponding to the remote operation instruction (hereinafter referred to as expiration date information) from the storage unit 120 based on the type of the remote operation instruction included in the operation instruction information. The expiration date information is stored in the storage unit 120 for each type of remote operation instruction. The remote operation instructions include instructions for opening and closing the doors of the vehicle V1 (driver's seat door, passenger seat door, rear door, etc.) and instructions for turning on / off the air conditioner of the vehicle V1. The remote operation instructions also include instructions for acquiring information such as the charging state (charging, non-charging, etc.), driving position, driving distance, and remaining battery level of the vehicle V1.
[0019] FIG. 4 is a diagram showing an example of the expiration date information stored in the storage unit 120. The expiration dates e1, e2, e3 (e1 < e2 < e3) of the remote operation instructions are calculated based on the length of the delay time allowed for the remote operation instructions. It is not preferable that the processes (opening and closing of the doors and windows) based on the opening and closing instructions of the doors and windows are executed at an unintended timing such as while the vehicle V1 is running. Therefore, as in the example of FIG. 4, a shorter expiration date e1 is set for those remote operation instructions than for other remote operation instructions. On the other hand, instructions for acquiring information such as the driving position, driving distance, and remaining battery level of the vehicle V1 do not require strict real-time performance. Therefore, as in the example of FIG. 4, the expiration date e3 of those remote operation instructions is set to be longer than the expiration dates of other remote operation instructions. Note that the expiration dates of each remote operation instruction shown in FIG. 4 are merely examples, and different expiration dates from the values shown in FIG. 4 may be set for each remote operation instruction.
[0020] The instruction management unit 113 generates information (hereinafter referred to as vehicle instruction information) including the operation instruction information received by the instruction reception unit 111, specifically, the control command based on the operation instruction information and the expiration date information indicating the expiration date determined by the determination unit 112. The instruction management unit 113 transmits the generated vehicle instruction information to the in-vehicle terminal 30 of the vehicle V1 via the communication unit 12.
[0021] Furthermore, the instruction management unit 113 stores status information (such as "processing in progress," "processing completed," "processing failed," or "processing stopped") indicating the progress of the processing executed by the in-vehicle terminal 30 based on the vehicle instruction information in the storage unit 120. More specifically, when the instruction receiving unit 111 receives operation instruction information from the user terminal 20, the instruction management unit 113 updates the status information to information indicating that the processing is being executed ("processing in progress"). Furthermore, after transmitting vehicle instruction information including the operation instruction information to the in-vehicle terminal 30, when the instruction management unit 113 receives processing result information ("processing completed" or "processing failed") indicating the result of the processing executed based on the vehicle instruction information from the in-vehicle terminal 30 within the expiration date determined by the determination unit 112, the instruction management unit 113 updates the status information with the processing result information. On the other hand, when the instruction management unit 113 does not receive processing result information from the in-vehicle terminal 30 within the expiration date, the instruction management unit 113 updates the status information to information indicating that the processing has been stopped ("processing stopped").
[0022] The authentication unit 114 creates (generates) an access lock (hereinafter also referred to as an access key) and an access key (hereinafter also referred to as an access token) that can unlock the access lock at predetermined intervals, and transmits the created access key to the in-vehicle terminal 30. When the authentication unit 114 receives an access request from the in-vehicle terminal 30 via the communication unit 12, it compares the access lock with the access key accompanying the access request. If the comparison shows that the access lock can be unlocked with the access key, the authentication unit 114 approves the access request from the in-vehicle terminal 30.
[0023] The determination unit 112 determines the expiration date of the remote operation instruction (hereinafter, may be referred to as the instruction expiration date) so as not to exceed the above-mentioned predetermined period, i.e., the expiration date set for the access lock (hereinafter, may be referred to as the key expiration date). More specifically, when the expiration date of the instruction expiration date determined based on the type of remote operation instruction exceeds the expiration date of the remote operation instruction, the determination unit 112 may shorten the instruction expiration date by a length corresponding to the excess. Instead of the determination unit 112 adjusting the length of the instruction expiration date, the authentication unit 114 may adjust the length of the key expiration date. Specifically, the next update of the access lock may be delayed until the expiration date of the instruction expiration date.
[0024] Fig. 5 is a block diagram showing the configuration of the main parts of the in-vehicle terminal 30 of Fig. 1. The in-vehicle terminal 30 has an electronic control unit (ECU) 31, a communication unit 32, a camera 33, a positioning sensor 34, a SOC (State Of Charge) sensor 35, and an actuator AC. Note that the communication unit 32 is similar to the communication unit 12 of Fig. 3, and therefore a description thereof will be omitted.
[0025] The camera 33 has an imaging element such as a CCD or CMOS and captures images of the surroundings (front, rear, and sides) of the vehicle. The positioning sensor 34 is a GPS sensor that receives positioning signals transmitted from GPS satellites and detects the absolute position (latitude, longitude, etc.) of the vehicle V1. Note that the positioning sensor 34 may be a sensor other than a GPS sensor. The SOC sensor 35 detects the remaining charge of a battery (not shown) mounted on the vehicle V1 as a secondary battery such as a lithium-ion battery.
[0026] The actuators AC include door actuators that automatically open and close the doors (driver's door, rear door, etc.) of the vehicle V1, and power window actuators that automatically open and close the windows (front window, rear window, etc.) of the vehicle V1. The actuators AC also include door lock actuators that unlock and lock the doors of the vehicle V1. Furthermore, the actuators AC include various actuators for controlling the driving of the host vehicle.
[0027] 5, the ECU 31 includes a computer having a calculation unit 310 such as a CPU, a storage unit 320 such as a ROM and a RAM, and other peripheral circuits (not shown) such as an I / O interface. The storage unit 320 stores various control programs, information such as thresholds used in the programs, map information (described later), and the like. The calculation unit 310 functions as a process execution unit 311 by executing programs previously stored in the storage unit 320.
[0028] The processing execution unit 311 establishes communication with the service providing device 10 using the access key distributed from the authentication unit 114 of the service providing device 10. This enables the processing execution unit 311 to securely send and receive data to and from the service providing device 10. When the processing execution unit 311 receives vehicle instruction information via the communication unit 12, it executes processing according to the remote operation instruction based on the vehicle instruction information.
[0029] If the remote operation instruction is an instruction to acquire information such as the traveling position, traveling distance, and remaining battery power of the vehicle V1, the process execution unit 311 transmits the sensor values of the positioning sensor 34 and the SOC sensor 35 together with the vehicle ID of the vehicle V1 to the service providing device 10 via the communication unit 12. The service providing device 10 transmits the received sensor values to the user terminal 20. Furthermore, if the remote operation instruction is an instruction to open or close a door or window, the process execution unit 311 controls the actuator AC to open or close the door or window of the vehicle V1.
[0030] Furthermore, if the remote operation instruction is an instruction to capture an image with a camera, the processing execution unit 311 outputs an image capture signal to the camera 33. Then, the processing execution unit 311 transmits the captured image obtained by the camera 33 to the service providing device 10. The service providing device 10 transmits the received captured image to the user terminal 20. Furthermore, if the remote operation instruction is an instruction to turn an air conditioner on / off, the processing execution unit 311 outputs an ON / OFF signal to an air conditioner device (not shown) of the vehicle V1.
[0031] When the in-vehicle terminal 30 has a detector other than a camera, for example, a radar or a lidar, the processing execution unit 311 may transmit detection data from the detector in accordance with a remote operation instruction to the service providing device 10. Furthermore, the processing execution unit 311 may transmit sensor values from other sensors, such as a vehicle speed sensor, to the service providing device 10 in accordance with a remote operation instruction.
[0032] 6A and 6B are sequence diagrams showing the operation of the remote operation system 1. Similar to Fig. 2, Fig. 6A shows an example of the operation when a user P1 remotely operates a door of a vehicle V1. When the user P1 performs a remote operation to open the door of the vehicle V1 via an app, operation instruction information including a door open instruction and the vehicle V1 is transmitted from the user terminal 20 to the service providing device 10 (step S21a).
[0033] When the service providing device 10 receives the operation instruction information, it outputs a control command to the in-vehicle terminal 30 based on the operation instruction information (step S11a). At this time, the service providing device 10 transmits vehicle instruction information including a control command (door open command) and expiration date information to the in-vehicle terminal 30. The expiration date information includes the output time of the control command (hereinafter referred to as the command output time) and the expiration date (e1, e2, or e3 in FIG. 4). Note that the expiration date information may also include other information such as the expiration date and time. The service providing device 10 updates the status information to "processing in progress" (step S12a). The service providing device 10 manages the status information together with information that can uniquely identify the control command (hereinafter referred to as the command ID). Specifically, the service providing device 10 associates the status information with the command ID and stores them in the storage unit 120.
[0034] When the on-board terminal 30 receives the vehicle instruction information (control command and expiration date information), it first determines whether the control command is valid based on the expiration date information (step S31a). Specifically, the on-board terminal 30 determines whether the time elapsed since the command output time exceeds the expiration date. If the elapsed time does not exceed the expiration date, the on-board terminal 30 executes processing in accordance with the control command (step S32a). More specifically, the on-board terminal 30 controls the door actuator based on the control command (door open command) to open the door to be operated. Then, the on-board terminal 30 transmits processing result information indicating the completion of processing to the service providing device 10 (step S33a).
[0035] Upon receiving the notification of completion of the processing, the service providing device 10 updates the status information stored in the storage unit 120 to "processing completed" (step S13a), and notifies the user terminal 20 of the completion of the remote operation (step S14a).
[0036] Fig. 6B shows an example of the operation of the remote control system 1 when a control command is received by the in-vehicle terminal 30 after a time TD has elapsed since the command output time. Note that steps S11b, S12b, and S21b in Fig. 6B are similar to steps S11a, S12ba, and S21a in Fig. 6A, and therefore will not be described here.
[0037] When receiving the control command, the in-vehicle terminal 30 determines whether the control command is valid based on the expiration date information attached to the control command (step S31b). As shown in Fig. 6B, if the elapsed time TD from the command output time exceeds the expiration date TO due to a system malfunction or the like, the in-vehicle terminal 30 cancels the process based on the control command without executing it (step S32b).
[0038] If the time elapsed since the command output time exceeds the expiration time TO but the service providing device 10 does not receive a notification of completion of the processing from the in-vehicle terminal 30, the service providing device 10 updates the status information to "processing canceled" (step S13b). Then, the service providing device 10 notifies the user terminal 20 of the cancellation of the processing (step S14b).
[0039] As shown in Figures 6A and 6B, the in-vehicle terminal 30 determines whether or not to execute processing in accordance with the control command based on the expiration date information accompanying the control command, thereby preventing vehicle-side control in accordance with remote operation from being executed at an unintended timing.
[0040] According to the embodiment of the present invention, the following advantageous effects can be achieved. (1) The service providing device 10 includes an instruction receiving unit 111 that receives operation instruction information transmitted from the user terminal 20, including an instruction for remotely operating the vehicle V1 equipped with the on-board terminal 30; a determination unit 112 that determines an expiration date (instruction expiration date) of the remote operation instruction based on the type of remote operation instruction included in the operation instruction information; an instruction management unit 113 that transmits vehicle instruction information including the operation instruction information and expiration date information indicating the instruction expiration date to the on-board terminal of the vehicle V1; and a storage unit 120 that stores processing status information indicating the progress of processing executed by the on-board terminal 30 based on the vehicle instruction information. When the instruction management unit 113 does not receive processing result information indicating the result of processing executed based on the vehicle instruction information from the on-board terminal 30 within the instruction expiration date, the instruction management unit 113 updates the processing status information stored in the storage unit 120 to information indicating the suspension of execution of the processing. This prevents vehicle-side control in accordance with the remote operation from being executed at an unintended timing. As a result, a remote operation service that users can use with confidence can be provided.
[0041] (2) The service providing device 10 further includes an authentication unit 114 that generates an access lock with an expiration date (key expiration date) set and an access key capable of unlocking the access lock, which are used in the authentication process of the in-vehicle terminal 30. The determination unit 112 determines the instruction expiration date so that it does not exceed the key expiration date. As a result, the expiration date of the remote operation instruction is set within the period during which the in-vehicle terminal 30 is authorized to access the service providing device 10, so that the service providing device 10 can reliably receive processing result information from the in-vehicle terminal 30. As a result, the execution result of the remote operation can be reliably notified to the user.
[0042] (3) When the instruction receiving unit 111 receives operation instruction information including an instruction for remote operation, the instruction management unit 113 updates the processing status information to information indicating that processing is being executed ("processing in progress"). The instruction management unit 113 transmits vehicle instruction information including the received operation instruction information to the in-vehicle terminal 30. After transmitting the vehicle instruction information to the in-vehicle terminal 30, if the instruction management unit 113 receives processing result information from the in-vehicle terminal 30 within the instruction expiration period, the instruction management unit 113 updates the processing status information to processing result information ("processing completed" or "processing failed"), while if the instruction management unit 113 does not receive processing result information from the in-vehicle terminal 30 within the instruction expiration period, the instruction management unit 113 updates the processing status information to information indicating that processing execution has been stopped ("processing stopped"). This makes it possible to appropriately manage the execution status of remote operations for which an expiration period is set.
[0043] (4) The storage unit 120 stores expiration date information (FIG. 4) corresponding to each of a plurality of remote operation instructions of different types. The determination unit 112 reads out expiration date information corresponding to the remote operation instruction from the storage unit 120 based on the type of the remote operation instruction included in the operation instruction information received by the instruction receiving unit 111. The instruction management unit 113 transmits vehicle instruction information including the operation instruction information and the expiration date information read out from the storage unit 120 by the determination unit 112 to the in-vehicle terminal 30. This allows the user to use the remote operation service with peace of mind, regardless of the type of remote operation instruction.
[0044] In the above embodiment, the operation instruction information received by the instruction receiving unit 111 includes a single remote operation instruction (door open instruction). However, the operation instruction information may include a series of remote operation instructions whose execution order is specified. FIGS. 7A and 7B are sequence diagrams showing another example of the operation of the remote operation system 1 of FIG. 1. FIG. 7A shows an example of the operation of the service providing device 10 when a user P1 remotely operates the air conditioner (A / C) of a vehicle V1 via an app.
[0045] When user P1 remotely operates vehicle V1, whose engine is stopped, via the app to start the A / C, operation instruction information including an engine (ENG) start instruction and an A / C start instruction is transmitted from user terminal 20 to service providing device 10 (step S21d), as shown in Fig. 7A. The operation instruction information includes information specifying the execution order of the ENG start instruction and the A / C start instruction. Note that steps S13d and S14d in Fig. 7A are similar to steps S13a and S14a in Fig. 6A, and therefore will not be described again.
[0046] When the service providing device 10 receives the operation instruction information including a series of remote operation instructions (an ENG start instruction and an A / C start instruction), the service providing device 10 generates vehicle instruction information including a series of control commands (an ENG start instruction and an A / C start instruction) that define an execution order based on the operation instruction information. At this time, the service providing device 10 reads out expiration date information corresponding to the series of remote operation instructions from the storage unit 120 and includes it in the vehicle instruction information. The service providing device 10 transmits the generated vehicle instruction information to the in-vehicle terminal 30 (step S11d). In this way, by transmitting the vehicle instruction information including the series of control commands that define the execution order to the in-vehicle terminal 30 and enabling the in-vehicle terminal 30 to manage the execution order of the processes, it becomes unnecessary for the service providing device 10 to manage the execution order. As a result, the processing load on the service providing device 10 can be reduced.
[0047] When the in-vehicle terminal 30 receives the vehicle instruction information, it first determines whether the series of control commands is valid based on the expiration date information (step S31d). If the series of control commands is valid, the in-vehicle terminal 30 executes the processes according to each control command in a specified execution order. Specifically, the in-vehicle terminal 30 first outputs a start signal to an engine start device (not shown) of the vehicle V1 in accordance with the ENG start command (step S32d). When the in-vehicle terminal 30 receives a notification of successful start from the engine start device, it outputs an ON signal to the air conditioning device of the vehicle V1 (step S33d). When the in-vehicle terminal 30 receives a notification of successful start from the air conditioning device, it transmits processing result information indicating the completion of the processing to the service providing device 10 (step S34d).
[0048] 7B shows another example of the operation of the service providing device 10 when the user P1 remotely operates the air conditioner (A / C) of the vehicle V1 via the app. Note that steps S11e, S12e, S21e, and S31e in FIG. 7B are similar to steps S11d, S12d, S21d, and S31d in FIG. 7A, and therefore will not be described again.
[0049] After outputting a start signal to the engine start device of the vehicle V1 in accordance with the ENG start command, if the in-vehicle terminal 30 receives a notification of start failure from the engine start device (step S32e), the in-vehicle terminal 30 cancels the processing in accordance with the subsequent A / C start command without executing it (step S33e). In addition, the in-vehicle terminal 30 transmits processing result information indicating that the processing (ENG start) has failed to the service providing device 10 (step S34e).
[0050] After receiving the notification of the start failure from the engine start device, the in-vehicle terminal 30 may transmit processing result information indicating that the processing (ENG start) has failed to the service providing device 10. That is, after step S32e, the process may proceed to step S34e. Then, the service providing device 10, which has received the notification of the processing failure from the in-vehicle terminal 30, may transmit a cancel command to the in-vehicle terminal 30, and the in-vehicle terminal 30 may cancel the processing according to the subsequent control command in response to the cancel command.
[0051] When the service providing device 10 receives the notification of the processing failure from the in-vehicle terminal 30, it updates the status information stored in the storage unit 120 to "processing failed" (step S13e) and notifies the user terminal 20 of the failure of the remote operation (step S14e).
[0052] In the above embodiment, the service providing device 10 creates an access lock and an access key capable of unlocking the access lock, and distributes the access key to the in-vehicle terminal 30. When the service providing device 10 receives an access request from the in-vehicle terminal 30, it compares the access key accompanying the access request with the access lock to determine whether to approve the access request from the in-vehicle terminal 30. However, such an authentication process may be performed between the in-vehicle terminal 30 and an external device. With such a configuration, a service such as data distribution can be provided from the external device to the vehicle V1 without going through the service providing device 10. Therefore, the authentication unit 114 of the service providing device 10 may operate as follows.
[0053] FIG. 8 is a diagram showing an example of the configuration of a map updating system 2 including a service providing device 10. As shown in FIG. 8, the map updating system 2 includes the service providing device 10, an in-vehicle terminal 30, a map server 40, and a vehicle authentication server 50. The map updating system 2 provides a service (hereinafter referred to as a map update service) in which map information is distributed from the map server 40 to the in-vehicle terminal 30 of a vehicle V1 to update the map information of the in-vehicle terminal 30. The map server 40 and the vehicle authentication server 50 are configured by, for example, server devices. Note that the map server 40 and the vehicle authentication server 50 may each be configured using a virtual server function on the cloud, or may be configured as being distributed across multiple devices.
[0054] The map update system 2 includes multiple vehicles (on-board terminals), and map information is distributed to the on-board terminals of each vehicle by the map server 40, but for the sake of simplicity, only one vehicle V1 (on-board terminal 30) is illustrated in Figure 8.
[0055] 9 is a sequence diagram showing the operation of the map update system 2. The authentication unit 114 of the service providing device 10 creates an access lock (hereinafter, may be simply referred to as a lock) K (step S111). The authentication unit 114 creates the access lock K every predetermined period PD. That is, the access lock K is updated every predetermined period PD.
[0056] The access lock K and an access key (hereinafter sometimes simply referred to as a key) T, which will be described later, are used in the authentication process between the in-vehicle terminal 30 and the map server 40. More specifically, the in-vehicle terminal 30 accesses the map server 40 using the access key T distributed from the service providing device 10. The map server 40 authenticates the in-vehicle terminal 30 using the access lock K distributed from the service providing device 10. Specifically, the map server 40 only accepts access from the in-vehicle terminal 30 using the access key T corresponding to the access lock K.
[0057] When the in-vehicle terminal 30 receives an accessory-on (ACC-ON) operation by the user (driver) of the vehicle V1 via an operation unit not shown (step S131), it sends a request command for vehicle authentication to the service providing device 10 (step S132).
[0058] When the authentication unit 114 receives the request command for vehicle authentication, it transmits the vehicle ID of the vehicle V1 accompanying the request command to the vehicle authentication server 50 (step S112). Vehicles for which the map layout service is provided are vehicles for which necessary information (such as the vehicle ID) has been registered in advance with the business entity that manages the service providing device 10 (hereinafter referred to as registered vehicles). A storage unit (not shown) of the vehicle authentication server 50 stores information (hereinafter referred to as an authentication database (DB)) that associates the vehicle IDs of registered vehicles with authentication tokens. The vehicle authentication server 50, specifically, a calculation unit (not shown) such as a CPU included in the vehicle authentication server 50, reads out the authentication token corresponding to the received vehicle ID from the authentication DB and transmits it to the service providing device 10 (step S151). Note that if the authentication token corresponding to the vehicle ID received from the service providing device 10 is not registered in the authentication DB, i.e., if the vehicle identified by the vehicle ID is not a registered vehicle, the vehicle authentication server 50 transmits information indicating an authentication error to the service providing device 10 instead of the authentication token.
[0059] When the service providing device 10 receives the authentication token from the vehicle authentication server 50, it transmits the authentication token to the in-vehicle terminal 30 (step S113). The in-vehicle terminal 30 can access the service providing device 10 by using the authentication token issued as described above. If the service providing device 10 receives information indicating an authentication error from the vehicle authentication server 50, the in-vehicle terminal 30's access to the service providing device 10 is restricted.
[0060] When the authentication token is issued, the in-vehicle terminal 30 requests vehicle setting information from the service providing device 10 (step S133). The vehicle setting information includes the URL (Uniform Resource Locator) of the map server 40, etc. In response to the request from the in-vehicle terminal 30, the service providing device 10 transmits the vehicle setting information to the in-vehicle terminal 30 (step S114).
[0061] Next, the in-vehicle terminal 30 requests the service providing device 10 for an access key T capable of unlocking the access lock K (step S134). In response to this request, the service providing device 10 creates an access key T based on the access lock K created in step S111 (step S115). The service providing device 10 transmits the created access key T to the in-vehicle terminal 30 (step S116).
[0062] The map server 40, specifically, a processing unit such as a CPU (not shown) included in the map server 40, requests an access lock K from the service providing device 10 (step S141). In response to the request from the map server 40, the service providing device 10 transmits the access lock K created in step S111 to the map server 40 (step S117). The map server 40 stores the received access lock K in a storage unit (not shown).
[0063] The in-vehicle terminal 30 uses the access key T received from the service providing device 10 to access the URL of the map server 40 indicated by the vehicle setting information. Then, the in-vehicle terminal 30 requests map information from the map server 40 (step S135). When the access key T corresponds to the access lock K held by the map server 40, that is, when the access lock K can be unlocked using the access key T, the in-vehicle terminal 30 is permitted to access the resources (map information) managed by the map server 40. As a result, the map information is distributed (downloaded) from the map server 40 to the in-vehicle terminal 30 (step S142). The in-vehicle terminal 30 updates the map information stored in the storage unit 320 with the map information distributed from the map server 40 (step S136).
[0064] In this way, by distributing the access key K to the map server 40 and distributing the access key T corresponding to the access key K to the in-vehicle terminal 30, the map information can be appropriately distributed from the map server 40 to the vehicle V1 without going through the service providing device 10. Further, by registering the vehicle ID of the registered vehicle in advance in the authentication DB of the vehicle authentication server 50, access from vehicles other than the registered vehicle to the map server 40 can be restricted, and a map update service with ensured security can be provided.
[0065] Incidentally, the access key K created by the service providing device 10 is updated at regular intervals PD as described above. On the other hand, the acquisition of the access key K by the map server 40 is executed at regular intervals PT1 (<PD). FIG. 10 is a diagram for explaining the update timing of the access key K in the service providing device 10 and the acquisition timing of the access key K in the map server 40.
[0066] In the request for the access key that is first executed in the map server 40 after the key K(0) is created by the service providing device 10 at time t0, the key K(0) is distributed from the service providing device 10 to the map server 40 (time t1). The map server 40 holds the received key K(0). Note that the map server 40 continues to hold the key K(0) without discarding the previous key (key K(-1)) until the next key (key K(1)) is acquired. When the in-vehicle terminal 30 receives an ACC-ON operation by the driver, it requests an access key from the service providing device 10 and acquires the access key (time t2). At this time, if the in-vehicle terminal 30 does not hold a valid authentication token, vehicle authentication (steps S132, S112, S151, S113 in FIG. 9) is executed.
[0067] When the service providing device 10 receives the request for the access key at time t2, it creates an access key T(0) capable of unlocking the lock K(0) and transmits it to the in-vehicle terminal 30. The in-vehicle terminal 30 uses the acquired key T(0) to request map information from the map server 40 (time t3). Because the key T(0) is an access key corresponding to the lock K(0) held by the map server 40, the in-vehicle terminal 30 is permitted to access the map server 40. As a result, the map information is distributed (downloaded) from the map server 40 to the in-vehicle terminal 30.
[0068] When a predetermined period PD has elapsed since time t0, the service providing device 10 updates the access lock (time t4). Specifically, it creates a lock K(1). Note that the map server 40 acquires an access lock every predetermined period PT1, so the time DL from when the service providing device 10 creates an access lock until the map server 40 first acquires that access lock (hereinafter referred to as the delay time) is at most PT1. If the in-vehicle terminal 30 requests an access key within this delay period DL, the access key distributed from the service providing device 10 to the in-vehicle terminal 30 in response to the request will no longer correspond to the access lock held by the map server 40.
[0069] Specifically, when a request for an access key is received from the in-vehicle terminal 30 during the delay period DL (times t3 to t7) after the creation of the lock K(1), the service providing device 10 creates a key T(1) that can unlock the lock K(1) and transmits it to the in-vehicle terminal 30 (time t5). The in-vehicle terminal 30 uses this key T(1) to request map information from the map server 40 (time t6). However, because the map server 40 has not yet acquired the lock K(1) that corresponds to the key T(1) from the service providing device 10, the in-vehicle terminal 30 is unable to obtain authentication from the map server 40 and is unable to download the map information.
[0070] Therefore, the service providing device 10 does not use the updated access lock until a predetermined time PT2 (>PT1) has elapsed since the access lock was updated. Fig. 11 is a diagram for explaining the timing for starting use of the access lock.
[0071] As shown in FIG. 11, after the service providing device 10 creates lock K(1) at time t10, if the service providing device 10 receives a request for an access key from the in-vehicle terminal 30 before a predetermined time PT2 has elapsed (time t11), the service providing device 10 creates key T(0) corresponding to the previous lock (lock K(0)). The service providing device 10 then distributes key T(0) to the in-vehicle terminal 30. The in-vehicle terminal 30 requests map information from the map server 40 using key T(0) distributed from the service providing device 10 (time t12). Because the map server 40 holds lock K(0) corresponding to key T(0), the in-vehicle terminal 30 is permitted to access the map server 40, and map information is distributed to the in-vehicle terminal 30. Furthermore, even after acquiring lock K(1) in response to the first access lock request after time t10 (time t13), the map server 40 continues to hold the pre-update lock (0). Therefore, even after time t13, the in-vehicle terminal 30 can obtain map information from the map server 40 using the key T(0) (times t14 and t15).
[0072] When a predetermined time PT2 has elapsed since the service providing device 10 created the lock K(1) at time t10 (time t15), the service providing device 10 starts using the lock K(1). Thereafter, when a request for an access key is received from the in-vehicle terminal 30 (time t16), the service providing device 10 creates a key T(1) that can unlock the lock K(1). The key T(1) is then distributed to the in-vehicle terminal 30. Because the map server 40 already holds the lock K(1) that corresponds to the key T(1), the in-vehicle terminal 30 can obtain map information from the map server 40 using the key T(1) distributed from the service providing device 10 (time t17).
[0073] According to the embodiment of the present invention, the following advantageous effects can be achieved. (1) A data update method for distributing update data from a map server 40 as a data distribution device to multiple vehicles V1, the method including: a creation step (steps S111 and S115 in FIG. 9) in which a service providing device 10 as a management server creates a single access lock that is valid for a predetermined period and an access key capable of unlocking the access lock; a lock transmission step (step S117 in FIG. 9) in which the service providing device 10 transmits the access lock to the map server 40; a key transmission step (step S116 in FIG. 9) in which the service providing device 10 transmits the access key to each of the in-vehicle terminals 30 of multiple vehicles V1 that are communicatively connected to the service providing device 10; a request step (step S135 in FIG. 9) in which the in-vehicle terminal 30 makes a distribution request for update data to the map server 40 using the access key; and a distribution step (step S142 in FIG. 9) in which the map server 40 determines whether the access key used in the distribution request can unlock the access lock, and, if it is determined that the access key can be unlocked, distributes the update data to the in-vehicle terminal 30 in response to the distribution request. This allows the data distribution device to accurately authenticate the in-vehicle terminal without going through the management server, thereby enabling authentication that is both secure and convenient.
[0074] (2) In the lock transmission step, the service providing device 10 transmits the access lock together with expiration date information indicating a predetermined period to the map server 40. In the distribution step, the map server 40 uses the access lock transmitted by the service providing device 10 in the lock transmission step within the predetermined period indicated by the expiration date information. This allows the expiration date of the access lock to be shared between the management server and the data distribution device. As a result, it is possible to prevent a mismatch between the access lock distributed to the data distribution device and the access key distributed to the in-vehicle device.
[0075] (3) In the key transmission step, the service providing device 10 does not transmit the access key created in the creation step to the in-vehicle terminal 30 until a certain time has passed since the access key was created. This prevents the in-vehicle terminal from using the access key before the access lock becomes available on the data distribution device side.
[0076] (4) In the request step, the update data that the on-board terminal 30 requests to be distributed is map information (hereinafter also referred to as map data) corresponding to the driving area of the vehicle V1 that is equipped with the on-board terminal 30. This enables authentication that achieves both security and convenience even in services that require frequent data updates, such as a map data update service for connected cars.
[0077] (5) A map update system 2 as a data update system distributes update data from a map server 40 to multiple vehicles V1. The system includes a service providing device 10, an in-vehicle terminal 30 mounted on each of the multiple vehicles V1, and the map server 40. The service providing device 10 creates a single access lock that is valid for a predetermined period of time and an access key capable of unlocking the access lock, transmits the access lock to the map server 40, and further includes an authentication unit 114 that transmits the access key to each of the in-vehicle terminals 30 of the multiple vehicles V1 communicatively connected to the service providing device 10. The in-vehicle terminal 30, specifically, a request unit functionally included in the calculation unit 310 of the in-vehicle terminal 30, requests the map server 40 to distribute update data using the access key. The map server 40, specifically, a distribution unit functionally included in the calculation unit of the map server 40, determines whether the access key used in the distribution request can unlock the access lock, and if it is determined that the access lock can be unlocked, distributes the update data to the in-vehicle terminal in response to the distribution request.
[0078] In the above embodiment, in the creation step, the service providing device 10 creates an access lock and an access key corresponding to the access lock. However, the service providing device 10 may create only a new access lock and transmit the access lock to the map server 40, thereby terminating the distribution of update data by the map server 40. That is, the data update method may further include a distribution termination step in which, when the management server terminates the distribution of update data by the data distribution device, the management server creates only a new access lock and transmits the access lock to the data distribution device. Alternatively, the service providing device 10 may create only a new access key and distribute the access key to each of the in-vehicle terminals 30 of the multiple vehicles V1, thereby terminating the distribution of update data by the map server 40. That is, the data update method may further include a distribution termination step in which, when the management server terminates the distribution of update data by the data distribution device, the management server creates only a new access key and transmits the access key to each of the in-vehicle terminals 30 of the multiple vehicles V1. This makes it possible to easily stop data distribution simply by controlling the management server, for example, when it is desired to stop data distribution because an error has been found in the distribution data.
[0079] In the above embodiment, the calculation unit 110 of the service providing device 10 has, as functional components, an instruction receiving unit 111, a determination unit 112, an instruction management unit 113, and an authentication unit 114. However, in the service providing device 10 provided in the map update system 2, the calculation unit 110 may have only the authentication unit 114 as functional components.
[0080] The above description is merely an example, and the present invention is not limited to the above-described embodiment and modifications as long as the features of the present invention are not impaired. One or more of the above-described embodiment and modifications can be arbitrarily combined, and modifications can also be combined with each other. [Explanation of symbols]
[0081] 10 Information processing device (service providing device), 20 User terminal, 30 In-vehicle terminal, 11 Controller, 110 Calculation unit, 111 Instruction receiving unit, 112 Deadline determination unit, 113 Instruction management unit, 114 Authentication unit, 120 Storage unit
Claims
1. an instruction receiving unit that receives operation instruction information including an instruction to remotely operate a vehicle equipped with the on-board terminal, the operation instruction information being transmitted from the user terminal; a determination unit that determines an expiration date of the instruction for remote operation based on a type of the instruction for remote operation included in the operation instruction information; an instruction management unit that transmits vehicle instruction information including the operation instruction information and expiration date information indicating the expiration date to the in-vehicle terminal; a storage unit that stores processing status information indicating a progress status of a processing executed by the vehicle-mounted terminal based on the vehicle instruction information, A service providing device characterized in that when the instruction management unit does not receive processing result information indicating the result of the processing performed based on the vehicle instruction information from the in-vehicle terminal within the expiration date, the instruction management unit updates the processing status information stored in the memory unit to information indicating the suspension of execution of the processing.
2. 2. The service providing device according to claim 1, the expiration date is a first expiration date, an authentication unit that generates an access lock with a second expiration date set thereto and an access key that can unlock the access lock, which are used in an authentication process of the in-vehicle terminal; The service providing device, wherein the determination unit determines the first expiration date so as not to exceed the second expiration date.
3. 3. The service providing device according to claim 1, The instruction management unit When the instruction receiving unit receives the operation instruction information including the remote operation instruction, it updates the processing status information to information indicating that the processing is being executed, and after transmitting the vehicle instruction information including the operation instruction information to the in-vehicle terminal, when it receives the processing result information from the in-vehicle terminal within the expiration date, it updates the processing status information with the processing result information, and when it does not receive the processing result information from the in-vehicle terminal within the expiration date, it updates the processing status information to information indicating that the execution of the processing has been stopped.
4. 3. The service providing device according to claim 1, the storage unit stores the expiration date information corresponding to each of the plurality of remote operation instructions of different types; the determining unit reads out, from the storage unit, the expiration date information corresponding to the remote operation instruction based on a type of the remote operation instruction included in the operation instruction information received by the instruction receiving unit; The instruction management unit transmits the vehicle instruction information, which includes the operation instruction information and the expiration date information read from the memory unit by the decision unit, to the vehicle-mounted terminal.
5. 3. The service providing device according to claim 1, the instruction management unit, when the operation instruction information received by the instruction receiving unit includes a series of instructions for the remote operation, the series of instructions being specified in an execution order, transmits the vehicle instruction information including the instructions for the series of remote operation; The instruction management unit further transmits to the in-vehicle terminal a command to cancel processing corresponding to a subsequent instruction of the series of remote control instructions when the processing result information received from the in-vehicle terminal indicates a failure of processing corresponding to one instruction of the series of remote control instructions.
Citation Information
Patent Citations
Locking / unlocking monitoring method
JP7074108B2