Mobile object control system and mobile object control method

The mobile object control system addresses high processing loads and unnecessary communication by implementing a two-stage verification process, ensuring efficient and secure validation of remote instructions through collaboration between the mobile object and management system.

JP2026049853APending Publication Date: 2026-03-19TOYOTA JIDOSHA KK
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-09
Publication Date
2026-03-19

AI Technical Summary

Technical Problem

Existing mobile object control systems face high processing loads when executing remote instruction verification, and unnecessary communication occurs when the validity of remote instructions is determined on the mobile object side, necessitating efficient collaboration between the mobile object and management system to validate unauthorized access.

Method used

A mobile object control system with a management system and control device that performs a first verification process on the mobile object, requesting a second verification process from the management system using different criteria if unauthorized activation is suspected, ensuring efficient determination of unauthorized access validity.

Benefits of technology

This approach enables efficient collaboration between the mobile device and management system to validate unauthorized activation, reducing processing loads and unnecessary communication, thereby enhancing security and convenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026049853000001_ABST
    Figure 2026049853000001_ABST
Patent Text Reader

Abstract

To enable the mobile device and the management system to work together efficiently to determine whether or not the suspicion of unauthorized activation of the mobile device is justified. [Solution] The mobile object control system controls a mobile object that has the function of operating in accordance with remote instructions in a predetermined area. The mobile object control system comprises a management system and a control device. The management system generates remote instructions in a legitimate manner. The control device is mounted on the mobile object and operates the mobile object in accordance with the legitimate remote instructions from the management system. The control device performs a first verification process to determine whether or not there is a suspicion of unauthorized activation of the control device. If there is a suspicion of unauthorized activation, the control device requests the management system to perform a second verification process to finally determine whether or not the suspicion of unauthorized activation is valid based on different judgment criteria than those used in the first verification process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a technique for controlling a moving body having a function of operating according to a remote instruction in a predetermined area.

Background Art

[0002] Patent Document 1 discloses a mobile body control system that controls a moving body having a function of operating according to a remote instruction in a predetermined area. The mobile body control system executes a remote instruction verification process for determining whether the remote instruction received by the moving body is valid, and an operation restriction process for restricting at least a part of the operation of the moving body without following the remote instruction when the remote instruction received by the moving body is not valid.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] When the in-vehicle system (moving body) executes the remote instruction verification process described in Patent Document 1, a large processing load may be imposed on the moving body. On the other hand, when the management system executes the remote instruction verification process, unnecessary communication may occur between the moving body and the management system when it is possible to determine on the moving body side that the remote instruction is valid. Therefore, it is desirable to enable the moving body and the management system to efficiently execute in cooperation the determination of whether an unauthorized access to the moving body is valid.

Means for Solving the Problems

[0005] The mobile object control system described herein controls a mobile object having the function of operating in accordance with remote instructions within a predetermined area. The mobile object control system comprises a management system and a control device. The management system legitimately generates remote instructions. The control device is mounted on the mobile object and operates the mobile object in accordance with legitimate remote instructions from the management system. The control device performs a first verification process to determine whether there is a suspicion of unauthorized activation of the control device. If there is a suspicion of unauthorized activation, the control device requests the management system to perform a second verification process to finally determine whether the suspicion of unauthorized activation is valid based on different criteria than those used in the first verification process.

[0006] The mobile body control method relating to this disclosure is a method for controlling a mobile body having the function of operating in accordance with remote instructions in a predetermined area. The mobile body is equipped with a control device that operates the mobile body in accordance with legitimate remote instructions from a management system that legitimately generates remote instructions. The mobile body control method includes causing the control device to execute a first verification process to determine whether or not there is a suspicion of unauthorized activation of the control device, and, if there is a suspicion of unauthorized activation, requesting the management system to execute a second verification process to finally determine whether or not the suspicion of unauthorized activation is valid based on judgment criteria different from those of the first verification process. [Effects of the Invention]

[0007] According to this disclosure, only when the mobile device determines that there is a suspicion of unauthorized activation, the control device of the mobile device requests the management system to execute a second verification process, which will ultimately determine whether the suspicion of unauthorized activation is valid based on different criteria than the first verification process. This enables the mobile device and the management system to work together efficiently to determine whether the suspicion of unauthorized activation on the mobile device is valid. [Brief explanation of the drawing]

[0008] [Figure 1] This is a conceptual diagram illustrating the outline of a vehicle according to an embodiment. [Figure 2] This is a block diagram illustrating the overview of the in-vehicle systems installed in a vehicle. [Figure 3] This is a conceptual diagram to explain automated valet parking. [Figure 4] This is a conceptual diagram illustrating mobility services within a designated area. [Figure 5] This is a block diagram showing an example configuration of a vehicle control system according to an embodiment. [Figure 6] This flowchart shows an example of vehicle-side processing related to the verification and countermeasures for suspected unauthorized startup according to the embodiment. [Figure 7] This flowchart shows a specific example of the process in step S102. [Figure 8] This flowchart shows a specific example of the process in step S106. [Figure 9] This flowchart shows an example of the processing on the management system side related to the verification and countermeasures for suspected unauthorized startup according to the embodiment. [Figure 10] This flowchart shows the first specific example of the second verification process. [Figure 11] These are a conceptual diagram (A) and a flowchart (B) to illustrate a second specific example of the second verification process. [Figure 12] This sequence diagram shows a specific example of the processing flow related to the startup of a control device based on a regular startup instruction. [Figure 13] This sequence diagram shows a specific example of the processing flow related to the activation of a control device when a activation command suspected of being an unauthorized remote activation is received. [Figure 14] This sequence diagram shows a specific example of the processing flow related to the startup of a control device when a startup command suspected of being an unauthorized startup operation is received. [Figure 15] This flowchart shows a modified example of the vehicle-side processing related to the verification and countermeasures for suspected unauthorized startup according to the embodiment. [Modes for carrying out the invention]

[0009] Embodiments of this disclosure will be described with reference to the attached drawings.

[0010] 1. A moving body that operates according to a remote instruction 1-1. Overview Consider a moving body having a function that operates according to a remote instruction. Examples of the moving body include a vehicle, a robot, etc. As an example, in the following description, the case where the moving body is a vehicle will be considered. When generalizing, the "vehicle" in the following description shall be read as "moving body".

[0011] FIG. 1 is a conceptual diagram for explaining the overview of the vehicle 1 according to the present embodiment. The vehicle 1 has a function of operating according to a remote instruction INS. In particular, the vehicle 1 has a function of operating according to a remote instruction INS in a predetermined area AR.

[0012] The predetermined area AR is, for example, an area where the vehicle 1 can perform autonomous driving. In that case, the vehicle 1 performs autonomous driving according to a remote instruction INS in the predetermined area AR. As another example, the predetermined area AR may be an area where a service using the vehicle 1 is provided. In that case, the vehicle 1 provides a service according to a remote instruction INS in the predetermined area AR. Various examples of the predetermined area AR will be described later.

[0013] The remote instruction INS includes a "start instruction INS-A" that remotely activates the control device 11 (see FIG. 2) of the vehicle 1. The remote instruction INS also includes an instruction to turn ON or OFF the power supply (main power supply) of the vehicle 1 for the activated control device 11 (more specifically, the vehicle controller 13 (see FIG. 2)). "Turning ON the power supply of the vehicle 1" means making the vehicle 1 operable. For example, turning ON the power supply of the vehicle 1 includes starting the power supply to various devices mounted on the vehicle 1. Also, turning ON the power supply of the vehicle 1 includes turning ON the ignition of the vehicle 1. On the other hand, "turning OFF the power supply of the vehicle 1" means making the vehicle 1 inoperable. For example, turning OFF the power supply of the vehicle 1 includes turning OFF the ignition of the vehicle 1. As another example, turning OFF the power supply of the vehicle 1 may include stopping the power supply to various devices mounted on the vehicle 1. Note that the control device 11 is operably mounted by an auxiliary power supply separate from the main power supply even when the above power supply (main power supply) of the vehicle 1 is OFF. Therefore, even after the power supply of the vehicle 1 is turned OFF, at least the function of the control device 11 (more specifically, the communication management device 12 (see FIG. 2)) to receive the remote instruction INS is activated. Thus, even after the power supply of the vehicle 1 is turned OFF, the vehicle 1 can receive a remote instruction INS to turn ON the power supply and automatically turn ON the power supply according to the remote instruction INS.

[0014] As another example, the remote instruction INS may instruct at least one of steering, acceleration, and deceleration of the vehicle 1. As yet another example, the remote instruction INS may instruct the vehicle 1 to perform autonomous driving. As yet another example, the remote instruction INS may instruct to recognize the surrounding situation of the vehicle 1 using a recognition sensor mounted on the vehicle 1. As yet another example, the remote instruction INS may instruct to lock or unlock the doors of the vehicle 1.

[0015] Remote instruction INS are generated by management system 2. Management system 2 manages vehicles 1 within at least a predetermined area AR. Management system 2 may also manage the predetermined area AR. Management system 2 may manage services provided using vehicles 1 within the predetermined area AR. Vehicles 1 and management system 2 can communicate with each other. Management system 2 sends remote instruction INS to vehicles 1 within the predetermined area AR as needed. Vehicles 1 within the predetermined area AR receive remote instruction INS sent from management system 2 and operate according to the received remote instruction INS. Management system 2 is implemented, for example, by a management server on the cloud. Management system 2 may consist of multiple servers that perform distributed processing.

[0016] Figure 2 is a block diagram illustrating the outline of the in-vehicle system 10 installed in vehicle 1. The in-vehicle system 10 includes a control device 11. The control device 11 is a computer that operates vehicle 1 according to remote instructions INS from management system 2, and includes a communication management device 12 and a vehicle controller 13.

[0017] The communication management device 12 receives remote instruction INS transmitted from the management system 2. When the communication management device 12 receives remote instruction INS, the vehicle controller 13 controls vehicle 1 according to the received remote instruction INS. For example, controlling vehicle 1 includes turning the power of vehicle 1 ON or OFF. Another example is controlling the movement of vehicle 1 (steering, acceleration, and deceleration). Yet another example is controlling the automatic driving of vehicle 1. Yet another example is controlling vehicle 1 by recognizing the surrounding conditions of vehicle 1 using recognition sensors mounted on vehicle 1. Yet another example is controlling the doors of vehicle 1 by locking or unlocking them. Yet another example is controlling the lights of vehicle 1 (e.g., headlights, hazard lights) by turning them on or off. Yet another example is controlling the horn of vehicle 1 by sounding it.

[0018] The following describes an example of vehicle 1 operating in a designated area AR according to remote instructions INS.

[0019] 1-2. Automatic valet parking Figure 3 is a conceptual diagram illustrating Automated Valet Parking (AVP). In this example, the designated area AR is a parking lot. The parking lot may be indoors or outdoors. AVP vehicle 1A is a vehicle 1 that is compatible with automated valet parking in the parking lot. AVP vehicle 1A can drive autonomously at least within the parking lot. More specifically, AVP vehicle 1A is equipped with recognition sensors (e.g., cameras) for recognizing its surroundings. AVP vehicle 1A drives autonomously in the parking lot while recognizing its surroundings using the recognition sensors.

[0020] As shown in Figure 3, multiple landmarks (markers) M placed in the parking lot may be used for the above-mentioned automated driving. Identification information is assigned to the landmarks M. For example, AVP vehicle 1A uses a camera to acquire images showing the surrounding environment of AVP vehicle 1A and recognizes landmarks M based on the images. Based on the recognition result of landmarks M, AVP vehicle 1A can recognize the parking area. AVP vehicle 1A also performs "localization processing (self-position estimation processing, Localization)" to estimate the position of AVP vehicle 1A in the parking lot with high accuracy based on the recognition result of landmarks M. The target path PT is the movement path from the parking area to the target parking space assigned to AVP vehicle 1A. Based on the position of AVP vehicle 1A estimated by localization processing and the target path PT, AVP vehicle 1A automatically drives to follow the target path PT. This makes it possible for AVP vehicle 1A to automatically move from the parking area to the target parking space.

[0021] Management system 2 manages automated valet parking in a parking lot. Management system 2 can communicate with a group of vehicles in the parking lot, including AVP vehicle 1A. For example, management system 2 issues remote instruction INS to AVP vehicle 1A. For example, the remote instruction INS instructs AVP vehicle 1A to turn on or off power. As another example, the remote instruction INS instructs the start of automated driving. Management system 2 may provide AVP vehicle 1A with map information of landmark M in the parking lot. Management system 2 may remotely control AVP vehicle 1A in the parking lot.

[0022] As shown in Figure 3, the management system 2 may include a vehicle management center 2A and a parking control center 2B. The parking control center 2B is installed for each parking lot. The parking control center 2B performs tasks such as monitoring the status of the parking lot, assigning parking spaces to AVP vehicles 1A, generating target route PT, and providing target route PT to AVP vehicles 1A.

[0023] Vehicle Management Center 2A oversees numerous parking control centers 2B for multiple parking lots. To this end, Vehicle Management Center 2A communicates with each parking control center 2B to collect and provide various types of information. Vehicle Management Center 2A also manages AVP vehicles 1A and transmits remote instruction INS to AVP vehicles 1A as needed. Furthermore, Vehicle Management Center 2A manages users and reservations for the automated valet parking service. Vehicle Management Center 2A may also communicate with user terminals 3 operated by users of the automated valet parking service. User membership information is pre-registered in Vehicle Management Center 2A.

[0024] Additionally, when entering or exiting the parking lot, AVP vehicle 1A receives a remote instruction INS from management system 2 instructing it to turn on its power. AVP vehicle 1A automatically turns on its power in accordance with the received remote instruction INS and then begins automatic driving in the parking lot. Management system 2 may communicate with AVP vehicle 1A and remotely control its automatic driving. Furthermore, when AVP vehicle 1A has completed parking in the target parking space upon entry, management system 2 communicates with AVP vehicle 1A and sends a remote instruction INS instructing it to turn off its power. AVP vehicle 1A automatically turns off its power in accordance with the received remote instruction INS.

[0025] 1-3. Mobility Services Figure 4 is a conceptual diagram illustrating mobility services in a designated area of ​​augmented reality (AR). The designated area of ​​AR is the area where mobility services are provided. For example, the designated area of ​​AR could be a city or a part of a city, such as a "smart city."

[0026] Mobility service vehicle 1B is a vehicle 1 provided for providing mobility services in a designated area AR. Examples of mobility service vehicle 1B include buses, taxis, car-sharing services, etc. Examples of buses include route buses, tour buses, on-demand buses, semi-demand buses, etc.

[0027] For example, the mobility service vehicle 1B performs autonomous driving in a designated area of ​​AR. More specifically, the mobility service vehicle 1B is equipped with recognition sensors (e.g., cameras) to recognize its surroundings. The mobility service vehicle 1B performs autonomous driving in the designated area of ​​AR while recognizing its surroundings using the recognition sensors.

[0028] Landmarks (markers) M for localization processing may be placed in the designated area AR. Mobility service vehicle 1B uses a camera to acquire images showing the surrounding environment and recognizes landmarks M based on the images. Mobility service vehicle 1B performs localization processing based on the recognition result of landmarks M and estimates its own position in the designated area AR. Mobility service vehicle 1B performs automatic driving based on its estimated own position.

[0029] The management system 2 manages mobility services and each mobility service vehicle 1B in a predetermined area AR. The management system 2 can communicate with each mobility service vehicle 1B within the predetermined area AR. For example, the management system 2 communicates with each mobility service vehicle 1B and collects information on the location and status of each mobility service vehicle 1B. The management system 2 also issues remote instructions (INS) to the mobility service vehicles 1B as needed. For example, the remote instruction INS may instruct the mobility service vehicle 1B to turn on or off power. As another example, the remote instruction INS may remotely instruct at least one of the following actions of the mobility service vehicle 1B: steering, acceleration, and deceleration. Furthermore, the management system 2 manages users and reservations for the mobility services. The management system 2 may also communicate with user terminals 3 operated by users of the mobility services.

[0030] 1-4. Other examples The mobile entity may be a robot that automatically navigates within a designated area of ​​augmented reality (AR). For example, the mobile entity may be a logistics robot that automatically transports goods within a designated area of ​​augmented reality such as a city, warehouse, or factory. Another example is a work robot that performs a predetermined task within a designated area of ​​augmented reality such as a warehouse or factory.

[0031] 1-5. Example System Configuration Figure 5 is a block diagram showing an example configuration of the vehicle control system 100 according to this embodiment. The vehicle control system 100 (mobile vehicle control system) includes an in-vehicle system 10 and a management system 2.

[0032] 1-5-1. In-vehicle systems The in-vehicle system 10 is mounted on the vehicle 1 and, together with the control device 11, includes, for example, sensors 14, a running gear 15, and lights / horns 16.

[0033] The communication management device 12 included in the control device 11 manages communication between the vehicle 1 and the outside of the vehicle 1. The communication management device 12 includes a communication interface (communication I / F) 12A, one or more processors 12B (hereinafter simply referred to as processor 12B), and one or more storage devices 12C (hereinafter simply referred to as storage devices 12C).

[0034] Communication I / F12A is an interface for communicating with external devices or systems (e.g., management system 2) of vehicle 1 to send and receive information. For example, communication I / F12A consists of various devices such as equipment for connecting to a mobile communication network, equipment for connecting to the internet, and equipment for connecting to surrounding devices (e.g., communication device 5 shown in Figure 11(A)) via wireless LAN.

[0035] Processor 12B performs various processes. Examples of processor 12B include CPU (Central Processing Unit), GPU (Graphics Processing Unit), ASIC (Application Specific Integrated Circuit), FPGA (Field-Programmable Gate Array), etc. Processor 12B can also be called "circuitry" or "processing circuitry." "Circuitry" refers to hardware programmed to realize the described functions, or hardware that performs those functions. Storage device 12C stores various information. Examples of storage device 12C include volatile memory, non-volatile memory, HDD (Hard Disk Drive), SSD (Solid State Drive), etc. Processor 12B reads various information from storage device 12C and also stores various information in storage device 12C. The functions of the communication management device 12 are realized through the cooperation of processor 12B, which executes the communication management program, and storage device 12C. The communication management program is stored in storage device 12C. Alternatively, the communication management program may be recorded on a computer-readable recording medium.

[0036] The vehicle controller 13 included in the control device 11 controls the vehicle 1 according to the remote instruction INS. The vehicle controller 13 includes one or more processors 13A (hereinafter simply referred to as processor 13A) and one or more storage devices 13B (hereinafter simply referred to as storage devices 13B). The configuration example of processor 13A is the same as that of processor 12B described above. Similarly, the configuration example of storage device 13B is the same as that of storage device 12C described above. The functions of the vehicle controller 13 are realized through the cooperation of processor 13A, which executes the vehicle control program, and storage device 13B. The vehicle control program is stored in storage device 13B. Alternatively, the vehicle control program may be recorded on a computer-readable recording medium.

[0037] Sensors 14 include recognition sensors, vehicle status sensors, position sensors, etc. Recognition sensors recognize (detect) the surrounding conditions of vehicle 1. Examples of recognition sensors include cameras, LIDAR (Laser Imaging Detection and Ranging), radar, etc. Vehicle status sensors detect the state of vehicle 1. Examples of vehicle status sensors include speed sensors, acceleration sensors, yaw rate sensors, steering angle sensors, etc. Position sensors detect the position and orientation of vehicle 1. An example of a position sensor is a GNSS (Global Navigation Satellite System) sensor.

[0038] The running gear 15 is a device for operating the vehicle 1. The running gear 15 includes a drive system, a braking system, and a steering system. The drive system includes, for example, at least one of an electric motor and an internal combustion engine for driving the vehicle 1. The braking system includes a brake actuator for braking the vehicle 1. The steering system includes an electric motor for steering the wheels of the vehicle 1. The lights / horn 16 includes lights and a horn. Examples of lights include headlights, hazard lights, etc.

[0039] 1-5-2. Management System The management system 2 includes a communication interface 21, one or more processors 22 (hereinafter simply referred to as processor 22), and one or more storage devices 23 (hereinafter simply referred to as storage devices 23).

[0040] The communication interface 21 is an interface for communicating with external devices or systems (e.g., vehicle 1 (in-vehicle system 10), user terminal 3, mobile communication carrier) of the management system 2 to send and receive information. For example, the communication interface 21 is composed of various devices such as devices for connecting to a mobile communication network, devices for connecting to the internet, and devices for connecting to surrounding devices (e.g., communication device 5 shown in Figure 11(A)) via wireless LAN. The configuration example of the processor 22 is the same as that of the processor 12B described above. Similarly, the configuration example of the storage device 23 is the same as that of the storage device 12C described above. The functions of the management system 2 are realized through the cooperation of the processor 22, which executes the management program, and the storage device 23. The management program is stored in the storage device 23. Alternatively, the management program may be recorded on a computer-readable recording medium.

[0041] The various types of information stored in the storage device 23 include, for example, map information, vehicle information, and management information. The map information includes map information of a predetermined area AR (e.g., a parking lot). The map information may also include location and identification information of each landmark (marker) M placed in the predetermined area AR. The vehicle information is information transmitted from the in-vehicle system 10 (e.g., image information acquired by a camera mounted on the vehicle 1, landmark information regarding landmark M recognized by a recognition sensor, and location information of the vehicle 1). The management information is information used for management by the management system 2, and includes, for example, vehicle management information, service information, and user information. The vehicle management information is information for managing the vehicle 1 (e.g., identification information of the vehicle 1 (vehicle ID), parking lot entry and exit time information). The user information is information about the user who uses the vehicle 1 (e.g., user ID, service reservation information).

[0042] 2. Verification and countermeasures for suspected unauthorized startup The management system 2 (processor 22) generates a remote instruction INS in the correct manner. As described above, the remote instruction includes a start instruction INS-A that remotely starts the control device 11 (more specifically, the vehicle controller 13). In principle, the control device 11 of vehicle 1 is intended to start according to the correct start instruction INS-A.

[0043] More specifically, when the power supply (main power) of vehicle 1 is OFF, the control device 11 (communication management device 12 and vehicle controller 13) is in a standby state. In other words, when the main power supply is OFF, the operating mode of the control device 11 (communication management device 12) is in "normal standby mode". Normal standby mode is a mode that waits for the reception of a legitimate (valid) start instruction INS-A from the management system 2. In normal standby mode, the communication management device 12 starts up in response to the reception of a legitimate start instruction INS-A. The vehicle controller 13 is configured to only accept remote instructions INS (including start instruction INS-A) from the communication management device 12. The vehicle controller 13, which is in a standby state, starts up in response to the reception of a legitimate start instruction INS-A from the activated communication management device 12.

[0044] The activation instruction INS-A is not always legitimately transmitted from the management system 2, and may be transmitted by a malicious actor attempting to illegally operate the mobile device. In other words, a malicious actor may forge the activation instruction INS-A and attempt to activate (illegally activate) the control device 11 by transmitting the forged activation instruction INS-A. More specifically, a forged activation instruction INS-A may be transmitted regardless of whether the vehicle 1 is outside or inside the designated area AR. Furthermore, the illegal activation of the control device 11 by a malicious actor can be carried out not only by a forged (illegible) activation instruction INS-A (remote action), but also by a direct activation operation OPE-A (non-remote action) on the control device 11 (e.g., the vehicle controller 13).

[0045] On the other hand, it is conceivable that not only malicious actors attempting to tamper with the mobile device, but also unintentional individuals may attempt to activate the control device 11 in ways that are not originally intended or that are misleading. If the operation of vehicle 1 is restricted in a manner that cannot be easily reversed in response to an activation instruction INS-A or activation operation OPE-A by an unintentional individual, it may impair the convenience of the vehicle 1's original user or lead to a reduction in the vehicle 1's operating time. An example of a "manual that cannot be easily reversed" would be a manner in which the management system 2 cannot remotely reverse the operation restriction of vehicle 1 (e.g., turning off the power to vehicle 1), and an employee must actually go to vehicle 1 and replace parts of vehicle 1 or perform a special reversal operation to reverse the operation restriction.

[0046] In response to the issues described above, the vehicle control system 100 according to this embodiment can be said to be configured as follows. Specifically, the control device 11 (communication management device 12) executes a "first verification process". The first verification process is a process to determine whether or not there is a suspicion of unauthorized activation of the control device 11 (for example, the vehicle controller 13) (suspicion of unauthorized remote activation or suspicion of unauthorized activation operation). If the first verification process determines that there is a suspicion of unauthorized activation, the communication management device 12 changes the operating mode of the control device 11 (communication management device 12) from the above-mentioned normal standby mode to the "alert standby mode". Furthermore, if the first verification process determines that there is a suspicion of unauthorized activation, the management system 2 executes a "second verification process" to make a final determination as to whether or not the suspicion of unauthorized activation is valid. The alert standby mode is a mode in which the activation of the control device 11 (for example, the vehicle controller 13) is prohibited, and the system returns to the normal standby mode on the condition that the second verification process ultimately determines that the suspicion of unauthorized activation is not valid and authentication between the control device 11 (communication management device 12) and the management system 2 is established. For example, the authentication C21 shown in Figures 13 and 14 corresponds to this authentication.

[0047] Furthermore, it is desirable that the determination of whether or not the suspected unauthorized activation of the control device 11 of vehicle 1 is valid be carried out efficiently through the cooperation of vehicle 1 (control device 11) and the management system 2. In addressing this issue, the vehicle control system 100 according to this embodiment can be said to be configured as follows: The control device 11 (communication management device 12) executes the first verification process described above. If there is a suspicion of unauthorized activation, the control device 11 (communication management device 12) requests the management system 2 to execute a second verification process that ultimately determines whether or not the suspicion of unauthorized activation is valid based on different judgment criteria than those used in the first verification process.

[0048] The following details the processes related to "verification and countermeasures for suspected unauthorized startup," divided into processes on the control device (communication management device 12) side of vehicle 1 and processes on the management system 2 side.

[0049] 2-1. Processing on the vehicle's control device side Figure 6 is a flowchart showing an example of the processing on the vehicle 1 side related to the verification and countermeasures for suspected unauthorized startup according to this embodiment.

[0050] In step S100, the communication management device 12 (processor 12B) determines whether or not it has received a start command INS-A from outside the vehicle 1. If it has received a start command INS-A (step S100; Yes), the process proceeds to step S102.

[0051] In step S102, the communication management device 12 determines whether there is a suspicion of unauthorized startup (more specifically, a suspicion of unauthorized remote startup) based on the startup instruction INS-A received in step S100. This process in step S102 corresponds to the first verification process targeting the startup instruction INS-A.

[0052] Figure 7 is a flowchart showing a specific example of the processing in step S102 in Figure 6. In Figure 7, in step S120, the communication management device 12 determines whether the startup instruction INS-A received conforms to a specified format. Specifically, for example, the startup instruction INS-A may be transmitted accompanied by a short message (text message) generated in accordance with a specified format. This short message includes, for example, an instruction ID (symbolic information that identifies the startup instruction INS-A). Examples of the specified format in a short message include, for example, the instruction ID being written at the beginning of the short message, a fixed number of a predetermined number of digits (e.g., 001) being written at the beginning of the short message, or a predetermined number (e.g., 0) being inserted between multiple characters or symbols contained in the short message. In examples where a short message is used in this way, in step S120, the communication management device 12 determines whether the short message conforms to a specified format.

[0053] If the received startup instruction INS-A conforms to the specified format (step S120; Yes), the process proceeds to step S122. The communication management device 12 then determines that the received startup instruction INS-A is legitimate, that is, there is no suspicion of unauthorized remote startup. On the other hand, if the received startup instruction INS-A does not conform to the specified format (step S120; No), the process proceeds to step S124. The communication management device 12 then determines that the startup instruction INS-A may not be legitimate, that is, there is suspicion of unauthorized remote startup.

[0054] Furthermore, the processing in step S102 (the first verification process targeting the startup instruction INS-A) may include determining whether the telecommunications number NM (e.g., telephone number, IP address) of the source of the startup instruction INS-A received in step S100 matches the telecommunications number NM1 used for transmitting the startup instruction INS-A of the management system 2, which is known to the communication management device 12. The communication management device 12 may then determine that there is no suspicion of unauthorized remote startup if this determination is satisfied, and determine that there is suspicion of unauthorized remote startup if this determination is not satisfied.

[0055] If there is suspicion of unauthorized remote activation in step S102, the process proceeds to step S104. In step S104, the communication management device 12 sends a "verification request notification N1" to the management system 2 requesting verification of the suspicion of unauthorized remote activation based on the current activation instruction INS-A. This verification request notification N1 requests the management system 2 to execute the second verification process (step S202). As can be seen from the explanation of step S202 below, the second verification process is based on different judgment criteria than the first verification process. The verification request notification N1 includes, for example, information indicating that there is suspicion of unauthorized remote activation, along with detailed information D1 regarding the current activation instruction INS-A. The detailed information D1 includes, for example, the reception time T1 of the activation instruction INS-A by the communication management device 12, the telecommunications number NM of the source of the activation instruction INS-A, and the instruction ID (information identifying the activation instruction INS-A). Also in step S104, the communication management device 12 changes its operating mode from normal standby mode to alert standby mode.

[0056] On the other hand, if the startup instruction INS-A has not been received (step S100; No), the communication management device 12 determines whether or not there is a suspicion of unauthorized startup (more specifically, a suspicion of an unauthorized startup operation) based on the startup operation OPE-A (step S106). The process in step S106 corresponds to the first verification process targeting the startup operation OPE-A.

[0057] Figure 8 is a flowchart showing a specific example of the process in step S106 in Figure 6. In Figure 8, in step S126, the communication management device 12 determines whether or not it has detected that the control device 11 (vehicle controller 13) has been started in a manner that does not follow the prescribed startup sequence. As described above, in this embodiment, the communication management device 12 is started in accordance with the regular startup instruction INS-A from the management system 2. The vehicle controller 13 is configured to accept only remote instructions INS (including startup instruction INS-A) from the started communication management device 12. In other words, the vehicle controller 13 is started only by the startup instruction INS-A transmitted from the communication management device 12 (prescribed startup sequence).

[0058] Therefore, in step S126, the communication management device 12 determines whether it has received startup information I1 from the vehicle controller 13 indicating, for example, that a startup operation OPE-A has been performed on the vehicle controller 13. The startup information I1 includes, for example, the time when the startup operation OPE-A was performed (startup operation time T3). If the startup information I1 is received, the communication management device 12 determines that a startup of the vehicle controller 13 that does not follow the prescribed startup sequence has been detected (step S126; Yes). The communication management device 12 then determines that the startup based on this startup operation OPE-A may constitute an unauthorized startup, that is, there is a suspicion of an unauthorized startup operation (step S128). If a startup of the vehicle controller 13 suspected of being an unauthorized startup operation is detected in this manner, the communication management device 12 may send an instruction to the vehicle controller 13 to temporarily stop the started vehicle controller 13 (e.g., an instruction to return to the standby state).

[0059] On the other hand, if the communication management device 12 has not received information from the vehicle controller 13 indicating that a startup operation OPE-A has occurred, that is, if no startup of the vehicle controller 13 that does not follow the prescribed startup sequence is detected (step S126; No), the communication management device 12 determines that there is no suspicion of an unauthorized startup operation (step S130). In this case, the process shown in Figure 6 ends. Note that, although the first verification process in step S106 targets the startup operation OPE-A for the vehicle controller 13, it may also be performed similarly for the startup operation OPE-A for the communication management device 12.

[0060] If there is suspicion of an unauthorized startup operation in step S106, the process proceeds to step S108. In step S108, the communication management device 12 sends a "verification request notification N2" to the management system 2 requesting verification of the suspected unauthorized startup operation based on the current startup operation OPE-A. This verification request notification N2 also requests the management system 2 to execute the second verification process (step S210). As can be seen from the explanation of step S210 below, this second verification process is also based on different judgment criteria than the first verification process. The verification request notification N2 includes, for example, information indicating that there is suspicion of an unauthorized startup operation, as well as startup information I1 as detailed information regarding the current startup operation OPE-A. The startup information I1 includes, for example, the startup operation time T3 mentioned above. Also in step S108, the communication management device 12 changes its operating mode from normal standby mode to alert standby mode.

[0061] In step S110, following step S104 or S108, the communication management device 12 obtains the final judgment result of the management system 2 regarding the suspected unauthorized startup (suspected unauthorized remote startup or suspected unauthorized startup operation) (the result of the second verification process shown in Figure 9) from the management system 2. The communication management device 12 then determines the obtained final judgment result (whether the suspected unauthorized startup is valid or not).

[0062] If the suspicion of unauthorized startup is justified (Step S110; Yes), the communication management device 12 maintains the alert standby mode (Step S112). On the other hand, if the suspicion of unauthorized startup is not justified (Step S110; No), the communication management device 12 returns its operating mode from the alert standby mode to the normal standby mode in accordance with the mode change request R-MC received from the management system 2 (Step S114). A specific example of the processing flow related to returning from the alert standby mode to the normal standby mode will be described later with reference to Figures 13 and 14.

[0063] If it is determined in step S102 that there is no suspicion of unauthorized remote activation, or after step S114, the communication management device 12 executes the process related to the normal activation of the vehicle controller 13. Specifically, the communication management device 12 activates the vehicle controller 13 on the condition that the first-stage authentication C1 (= authentication C22) is completed, as will be described later with reference to Figures 12 to 14.

[0064] 2-2. Processing on the Management System Side Figure 9 is a flowchart showing an example of the processing on the management system 2 side related to the verification and countermeasures for suspected unauthorized startup according to this embodiment.

[0065] In step S200, the management system 2 (processor 22) determines whether it has received a verification request notification N1 regarding suspected unauthorized remote activation from vehicle 1. If the verification request notification N1 is received (step S200; Yes), the management system 2 executes a second verification process (step S202). That is, the management system 2 makes a final determination as to whether the suspected unauthorized remote activation related to the verification request notification N1 is valid. In addition, the management system 2 transmits the final determination result regarding whether the suspected unauthorized remote activation is valid to vehicle 1.

[0066] Figure 10 is a flowchart showing the first specific example (issuer verification process) of the second verification process (step S202) for suspected unauthorized remote activation. In Figure 10, in step S220, the management system 2 determines whether it actually transmitted the activation instruction INS-A received by vehicle 1. Specifically, the management system 2 reads the transmission history of its own activation instruction INS-A from the storage device 23 and compares the detailed information D1 included in the verification request notification N1 with the transmission history. For example, the management system 2 compares the reception time T1 and the telecommunication number NM of the activation instruction INS-A included in the detailed information D1 with the transmission history. Alternatively, the management system 2 may compare the instruction ID along with the reception time T1 and the telecommunication number NM of the sender with the transmission history, as shown in the example in Figure 13 described later.

[0067] If, as a result of the above verification, the reception time T1 and the telecommunication number NM of the sender match the information contained in the transmission history, the management system 2 determines that the activation instruction INS-A was actually transmitted (step S220; Yes). The management system 2 then finally determines that the suspicion of unauthorized remote activation is not valid (step S222).

[0068] In addition, even if the communication management device 12 determines that there is a suspicion of unauthorized remote activation (step S102; Yes), it may still be possible to say that the activation instruction INS-A was transmitted by a person without malicious intent. An example of transmission of the activation instruction INS-A by a person without malicious intent is when the terminal used to transmit the activation instruction INS-A on the management system 2 side has been changed, but the information of this change has not been shared between the management system 2 and the vehicle 1. Another example of transmission by a person without malicious intent is when the version of the prescribed format (see step S120) used when transmitting and receiving the activation instruction INS-A between the management system 2 and the vehicle 1 does not match between the management system 2 and the vehicle 1.

[0069] On the other hand, if the reception time T1 and the telecommunication number NM of the sender do not match the information included in the transmission history, the management system 2 determines that the activation instruction INS-A was not actually transmitted (step S220; No). As a result, the management system 2 ultimately determines that the suspicion of unauthorized remote activation is valid (step S224). According to the source verification process described above, it is possible to prevent vehicle 1 from being hijacked by someone who illegally transmits the activation instruction INS-A, regardless of whether it is inside or outside the predetermined area AR.

[0070] If it is ultimately determined that the suspected unauthorized remote activation is not valid (Step S202; No), the process proceeds to Step S204. In Step S204, the management system 2 sends a request to the vehicle 1 to deactivate the alert standby mode, that is, a mode change request R-MC from alert standby mode to normal standby mode. A specific example of the processing flow related to the mode change request R-MC will be described later with reference to Figure 13.

[0071] On the other hand, if the suspicion of unauthorized remote activation in this case is ultimately determined to be valid (step S202; Yes), the process proceeds to step S206. In step S206, the management system 2 communicates with a mobile communication carrier that provides mobile communication services to multiple vehicles 1 managed by the management system 2 (including the vehicle 1 that is the target of the processing shown in Figure 9). The management system 2 then requests the mobile communication carrier to stop transmitting information from the telecommunications number NM-X (illegal destination) used to send the activation instruction INS-A related to the suspicion of unauthorized remote activation. The vehicles 1 managed by the management system 2 are the ones to which the information transmission (e.g., sending of short messages) should be stopped, and are identified, for example, based on the vehicle management information stored in the storage device 23. The stopping of the information transmission is carried out on the condition that the following transmission stop conditions are met.

[0072] The above transmission stop condition is, for example, that telecommunications number NM-X was used for an unauthorized start instruction INS-A to the control devices 11 of multiple vehicles 1, including the control device 11 of the vehicle 1 targeted for processing shown in Figure 9. Alternatively, the transmission stop condition is, for example, that telecommunications number NM-X was used multiple times within a predetermined time for an unauthorized start instruction INS-A to the control device 11 of the vehicle 1 targeted for processing shown in Figure 9. In addition, for example, the management system 2 lists the information of the source telecommunications number NM included in the detailed information D1 received from each vehicle 1 under management and stores it in the storage device 23. The management system 2 then determines whether the above transmission stop condition is met based on the information thus listed. According to the process of step S206 described above, it is possible to efficiently prevent the unauthorized start instruction INS-A from being transmitted from the detected unauthorized destination to all vehicles 1 under management of the management system 2.

[0073] On the other hand, if verification request notification N1 has not been received (step S200; No), the management system 2 determines whether or not it has received verification request notification N2 regarding suspected unauthorized startup operation from vehicle 1. If, as a result, verification request notification N2 has not been received (step S208; No), the process shown in Figure 9 ends.

[0074] If verification request notification N2 is received (step S208; Yes), the management system 2 performs a second verification process (step S210). That is, the management system 2 makes a final determination as to whether the suspected unauthorized startup operation related to verification request notification N2 is valid. In addition, the management system 2 transmits the final determination result regarding whether the suspected unauthorized startup operation is valid to the vehicle 1.

[0075] The second verification process in step S210 includes, for example, sending a notification INQ to the user of vehicle 1 (e.g., current lessee, owner) inquiring about the activation of the vehicle controller 13. More specifically, the management system 2 sends a notification INQ (e.g., short message) containing inquiries about the activation of the vehicle controller 13 to the user terminal 3 operated by the user. For example, the inquiries may include a message asking the user whether they accidentally activated the vehicle controller 13 around the activation operation time T3 (see step S126). Alternatively, for example, the inquiries may include a message asking the user whether they have any recollection of the activation of the vehicle controller 13 around the activation operation time T3, and a message asking the user, if they do have any recollection of the activation, why the vehicle controller 13 was activated.

[0076] If, in response to the above notification INQ, the management system 2 receives a response from the user via the user terminal 3 indicating that, for example, the user has some knowledge of the activation of the vehicle controller 13 and that the reason for such activation was legitimate, the management system 2 will ultimately determine that the suspicion of unauthorized activation is not valid (Step S210; No). In addition, a legitimate reason for activating the vehicle controller 13 would be, for example, that the user had requested repairs to the vehicle 1 from a repair shop, and the worker accidentally pressed the power button and activated the vehicle controller 13 during the repairs. Alternatively, another legitimate reason would be that the user of the vehicle 1 accidentally pressed the power button and activated the vehicle controller 13. In addition, activation for such reasons can be said to be an activation of the control device 11 (vehicle controller 13) by an innocent person.

[0077] If the suspicion of unauthorized activation is not valid (step S210; No), the management system 2 sends a request to the vehicle 1 to deactivate the alert standby mode, i.e., a mode change request R-MC (step S204).

[0078] On the other hand, if the management system 2 receives a response from the user via the user terminal 3 in response to the above notification INQ, for example, indicating that the user has no recollection of the activation of the vehicle controller 13, or that the user has recollection of the activation but the reason for the activation is not legitimate, the management system 2 will ultimately determine that the suspicion of an unauthorized activation operation is valid (Step S210; Yes).

[0079] If the suspicion of an unauthorized startup operation is valid (step S210; Yes), the management system 2 sends a notification to the user terminal 3 requesting action to suppress the unauthorized startup operation. For example, such a notification may be a request to the user (the lessee of vehicle 1) not to attempt to start the vehicle in an unauthorized manner.

[0080] (Second specific example of the second verification process) Here, as a second specific example of the second verification process (step S202) targeting suspected unauthorized remote activation, the first to third examples of the area verification process are described below.

[0081] Basically, the management system 2 sends an activation command INS-A to vehicle 1 only when vehicle 1 is within a designated area AR. When vehicle 1 is outside the designated area AR, the management system 2 will not send an activation command INS-A to vehicle 1. For example, an AVP vehicle 1A (see Figure 3) that supports automated valet parking operates in the parking lot according to remote instruction INS, including the activation command INS-A, but is driven by a user outside the parking lot. Outside the parking lot, the AVP vehicle 1A will not receive an activation command INS-A from the management system 2. If vehicle 1 receives an activation command INS-A when it is outside the designated area AR, that activation command INS-A is not a legitimate one sent from the management system 2 and is highly likely to be suspected of being an unauthorized remote activation.

[0082] From the above perspective, a second concrete example of the second verification process is to determine whether or not vehicle 1 is located within a predetermined area AR when vehicle 1 receives the start command INS-A. The process of determining whether or not vehicle 1 is located within a predetermined area AR when vehicle 1 receives the start command INS-A is referred to here as the "area verification process." Figure 11(A) is a conceptual diagram illustrating the first to third examples of the area verification process.

[0083] The first example of area verification processing is determining whether a landmark M located within a predetermined area AR can be recognized from the position of vehicle 1. If landmark M cannot be recognized from the position of vehicle 1, the management system 2 ultimately determines that vehicle 1 was not within the predetermined area AR when the control device 11 (communication management device 12) received the activation instruction INS-A, and that the suspicion of unauthorized remote activation is valid.

[0084] More specifically, Vehicle 1 (in-vehicle system 10) transmits image information acquired by a camera mounted on Vehicle 1 to Management System 2. Management System 2 is configured to recognize landmarks M around Vehicle 1 based on the image information received from Vehicle 1. Management System 2 determines whether or not to recognize landmarks M around Vehicle 1. If landmarks M are not recognized, Management System 2 determines that landmarks M cannot be recognized from the location of Vehicle 1. In other words, Management System 2 determines that Vehicle 1 is not located within the predetermined area AR when the communication management device 12 receives the activation instruction INS-A.

[0085] A second example of the area verification process is comparing the location information of vehicle 1 with map information. The map information contains the location of a predetermined area AR. Therefore, by comparing the location information of vehicle 1 with map information, the management system 2 determines whether vehicle 1 is within the predetermined area AR when the control device 11 (communication management device 12) receives the activation instruction INS-A. If vehicle 1 is not within the predetermined area AR when the communication management device 12 receives the activation instruction INS-A, the management system 2 ultimately determines that the suspicion of unauthorized remote activation is valid.

[0086] More specifically, the in-vehicle system 10 acquires the location information of vehicle 1 using the position sensors included in the sensors 14. Alternatively, the in-vehicle system 10 acquires the location information of vehicle 1 by performing localization processing. The in-vehicle system 10 transmits the location information of vehicle 1 to the management system 2. The management system 2 acquires the location information of vehicle 1 from the in-vehicle system 10. Then, by comparing the location information of vehicle 1 with map information, the management system 2 determines whether or not vehicle 1 is within a predetermined area AR when the communication management device 12 receives the activation instruction INS-A.

[0087] In the third example of the area verification process, the vehicle 1 (in-vehicle system 10) and the communication device 5 installed in a predetermined area AR are configured to communicate according to a specific communication method. For example, in the case of automated valet parking shown in Figure 3, the parking control center 2B corresponds to the communication device 5, and the AVP vehicle 1A in the parking lot and the parking control center 2B communicate according to a specific communication method. The specific communication method is, for example, a short-range wireless communication method such as WiFi® or Bluetooth®.

[0088] The third example is determining whether or not communication is established between vehicle 1 (in-vehicle system 10) and communication device 5 installed in a predetermined area AR. If communication is not established between vehicle 1 and communication device 5, the management system 2 ultimately determines that vehicle 1 was not in the predetermined area AR when the communication management device 12 received the activation command INS-A, and that the suspicion of unauthorized remote activation is valid.

[0089] Figure 11(B) is a flowchart that summarizes the first to third examples of the area verification process. In Figure 11(B), in step S230, the management system 2 determines whether or not vehicle 1 is located within the predetermined area AR. If vehicle 1 is located within the predetermined area AR (step S230; Yes), the management system 2 ultimately determines that the suspected unauthorized remote activation is not valid (step S232). On the other hand, if vehicle 1 is not located within the predetermined area AR (step S230; No), the management system 2 ultimately determines that the suspected unauthorized remote activation is valid (step S234).

[0090] According to the area verification process described above, it becomes possible to prevent vehicle 1, which is outside the designated area AR, from being hijacked by someone who illegally transmits the activation command INS-A.

[0091] 2-3. Specific examples of the processing flow related to the startup of the control device Here, three specific examples of the processing flow related to the startup of the control device 11 (communication management device 12 and vehicle controller 13) of vehicle 1 are explained.

[0092] First, Figure 12 is a sequence diagram showing a specific example of the processing flow related to the startup of the control device 11 based on a regular startup instruction INS-A. Figure 12 shows an example in which a regular startup instruction INS-A is sent from the management system 2 to the communication management device 12, which is in normal standby mode.

[0093] The communication management device 12 acquires detailed information D1 (e.g., reception time T1, sender's telecommunication number NM, and instruction ID) regarding the startup instruction INS-A1 received and stores it in the storage device 12C. If the startup instruction INS-A sent from the management system 2 is legitimate, as shown in the example in Figure 12, the first verification process will not determine that the startup instruction INS-A is suspected of being an unauthorized remote startup. Therefore, the communication management device 12 performs the process for normal authentication (one-factor authentication C1).

[0094] Step 1 authentication C1 is performed to verify that the startup instruction INS-A received by the communication management device 12 was indeed sent from the management system 2. In terms of processing, Step 1 authentication C1 is the same as the issuer verification process described above (see Figure 10). Specifically, in Step 1 authentication C1, the communication management device 12 sends a startup confirmation request R-SC, accompanied by detailed information D1, to the management system 2.

[0095] Upon receiving the startup confirmation request R-SC, the management system 2 performs the following response processing to the startup confirmation request R-SC. For example, the management system 2 determines whether the reception time T1 received from the communication management device 12 is consistent with the transmission time of its own startup instruction INS-A. The management system 2 also determines whether the source telecommunication number NM received from the communication management device 12 matches the telecommunication number NM1 used to transmit its own startup instruction INS-A. Furthermore, the management system 2 determines whether the instruction ID received from the communication management device 12 matches the instruction ID 1 of its own startup instruction INS-A. In the example shown in Figure 12, the startup instruction INS-A is valid, so all three of these determinations are met. In this case, the management system 2 resends the startup instruction INS-A to the communication management device 12 along with the positive determination result information regarding the three determinations.

[0096] When the communication management device 12 receives a startup instruction INS-A with positive judgment result information, the first-step authentication C1 is completed. Accordingly, the communication management device 12 exits normal standby mode and transitions to the startup state. Next, the communication management device 12 sends a startup instruction INS-A to the vehicle controller 13, which is in standby mode. The vehicle controller 13 starts up in response to receiving the startup instruction INS-A from the communication management device 12. Next, the vehicle controller 13 sends a startup completion notification to the communication management device 12 indicating that its startup is complete. Upon receiving the startup completion notification, the communication management device 12 sends the startup completion notification to the management system 2.

[0097] Next, Figure 13 is a sequence diagram showing a specific example of the processing flow related to the activation of the control device 11 when it receives an activation instruction INS-A suspected of being an unauthorized remote activation. In addition, Figure 13 corresponds to an example in which the second verification process ultimately determines that the suspected unauthorized remote activation is not valid.

[0098] After obtaining detailed information D1 regarding the startup instruction INS-A received, the communication management device 12 executes the first verification process (see step S102 in Figure 6). In the example shown in Figure 13, the first verification process determines that there is a suspicion of unauthorized remote startup. Therefore, the communication management device 12 changes its operating mode from normal standby mode to alert standby mode and sends a verification request notification N1 to the management system 2 (see step S104).

[0099] Upon receiving the verification request notification N1, the management system 2 executes a second verification process (e.g., the issuer verification process shown in Figure 10) (see step S202). As described above, in Figure 13, the second verification process ultimately determines that the suspicion of unauthorized remote activation is not valid. Therefore, the management system 2 sends a mode change request R-MC to the vehicle 1 (communication management device 12) (see step S204).

[0100] Upon receiving the mode change request R-MC, the communication management device 12 performs processing for two-factor authentication C2. This two-factor authentication C2 consists of authentication C21 and authentication C22, which follows authentication C21. Authentication C21 is performed to confirm that the mode change request R-MC received by the communication management device 12 was indeed sent from the management system 2. The processing content of authentication C22 is the same as that of one-factor authentication C1.

[0101] In authentication C21, the communication management device 12 obtains detailed information D2 regarding the mode change request R-MC received (e.g., reception time T2 of the mode change request R-MC, the telecommunication number NM of the sender, and the instruction ID) and stores it in the storage device 12C. Then, the communication management device 12 transmits a mode change confirmation request R-MCC, along with the detailed information D2, to the management system 2.

[0102] Upon receiving the mode change confirmation request R-MCC, the management system 2 performs a reply process to the mode change confirmation request R-MCC. This reply process is performed in the same manner as the reply process to the startup confirmation request R-SC, as described with reference to Figure 12. If, as a result, positive judgment result information is obtained regarding the three judgments included in the detailed information D2, the management system 2 resends the mode change request R-MC to the communication management device 12 along with the positive judgment result information.

[0103] When the communication management device 12 receives a mode change request R-MC accompanied by positive judgment result information, authentication C21 is completed. Accordingly, the communication management device 12 returns from the alert standby mode to the normal standby mode. Next, the communication management device 12 sends a mode change completion notification to the management system 2 indicating that the mode change has been completed.

[0104] Upon receiving the mode change completion notification, the management system 2 sends a regular startup instruction INS-A to the communication management device 12. Upon receiving the regular startup instruction INS-A, the communication management device 12 performs authentication C22 in the same way as the first-step authentication C1. As a result, once authentication C22 is completed, the second-step authentication C2 is completed, and the communication management device 12 and the vehicle controller 13 start up in sequence.

[0105] In addition, as explained above, in the vehicle control system 100, in the second verification process, completion of two-factor authentication C2 is required in order to activate the control device 11 after it has been determined that the suspected unauthorized remote activation (and the suspected unauthorized activation operation shown in Figure 14) is not valid. In other words, it is prevented that the control device 11 will be activated without completing two-factor authentication C2.

[0106] Next, Figure 14 is a sequence diagram showing a specific example of the processing flow related to the startup of the control device 11 when a startup instruction INS-A suspected of being an unauthorized startup operation is received. In addition, Figure 14 corresponds to an example in which the second verification process ultimately determines that the suspected unauthorized startup operation is not valid.

[0107] When a startup operation OPE-A is performed on the vehicle controller 13, the vehicle controller 13 acquires startup information I1, which includes the startup operation time T3 related to the startup operation OPE-A, and stores it in its storage device 13B. The vehicle controller 13 then transmits the startup information I1 to the communication management device 12.

[0108] Upon receiving the startup information I1, the communication management device 12 stores the startup information I1 in the storage device 12C and then executes the first verification process (see step S106). If the startup information I1 is received from the vehicle controller 13, the first verification process determines that there is a suspicion of unauthorized remote startup. Therefore, the communication management device 12 changes from normal standby mode to alert standby mode and sends a verification request notification N2 to the management system 2 (see step S108).

[0109] Upon receiving the verification request notification N2, the management system 2 executes a second verification process (see step S210). As described above, in Figure 14, the second verification process ultimately determines that the suspicion of an unauthorized startup operation is not valid. Therefore, the management system 2 sends a mode change request R-MC to the vehicle 1 (communication management device 12) (see step S204).

[0110] Even when a mode change request R-MC is received, which originates from a suspected unauthorized startup operation, as shown in the specific example in Figure 14, the communication management device 12 executes the two-factor authentication C2 process. The following process flow is the same as that explained with reference to Figure 13, so a detailed explanation is omitted.

[0111] Although the processing flow corresponding to the startup operation OPE-A for the vehicle controller 13 was explained with reference to Figure 14, the processing flow when a startup operation OPE-A for the communication management device 12 is detected is similar.

[0112] 2-4. Modified Examples of Processing on the Vehicle's Control Device Side Figure 15 is a flowchart showing a modified example of the processing on the vehicle 1 side related to the verification and countermeasures for suspected unauthorized startup according to this embodiment. The processing in this flowchart differs from the processing in the flowchart shown in Figure 6 in that the processing in the next step S300 is executed instead of step S108.

[0113] Similar to Figure 6, the first verification process in Figure 15 includes a process to determine whether or not there is a suspicion of unauthorized remote activation (step S102) and a process to determine whether or not there is a suspicion of unauthorized activation operation (step S106). Therefore, it can be said that the first verification process in Figure 15 includes determining whether the suspicion of unauthorized activation is a suspicion of unauthorized remote activation or a suspicion of unauthorized activation operation. In Figure 15, if there is a suspicion of unauthorized activation operation in step S106, the communication management device 12 changes its operating mode from the alert standby mode to the "immediately disabled mode".

[0114] The immediate inactivation mode referred to here is a mode in which the control system 2 is unable to remotely release the inactivation of the control device 11. More specifically, the inactivation is limited to at least the vehicle controller 13 among the vehicle controller 13 and the communication management device 12. Furthermore, "a mode in which the control system 2 is unable to remotely release the inactivation of the control device 11" refers to, for example, a mode in which an employee is required to replace a part of the vehicle 1 to release the inactivation, or a mode in which an employee is required to perform a special release operation on the control device 11.

[0115] Furthermore, if the processing on the control device 11 side is executed as shown in Figure 15, the processing on the management system 2 side will be the same as the flowchart in Figure 9, but with steps S208-S212 omitted.

[0116] 3. Effects As described above, according to this embodiment, if the vehicle 1 determines that there is a suspicion of unauthorized activation of the control device 11, it is possible to wait for the management system 2's final determination of whether or not there is a suspicion of unauthorized activation by transitioning to the alert standby mode, while suppressing the use of the control device 11 to operate the vehicle 1 illegally. The operating mode of the control device 11 (communication management device 12) returns from the alert standby mode to the normal standby mode, provided that the second verification process ultimately determines that the suspicion of unauthorized activation is not valid and authentication between the control device 11 and the management system 2 (e.g., authentication C21) is established. This suppresses the execution of unnecessary or excessive restrictions on the operation of the vehicle 1. This leads to suppressing the misuse of the functions of the vehicle 1 while suppressing a decrease in user convenience or a reduction in the operating time of the vehicle 1.

[0117] Furthermore, as described above, according to this embodiment, only when it is determined that there is a suspicion of unauthorized startup on the vehicle 1 side, the control device 11 (communication management device 12) of the vehicle 1 requests the management system 2 to execute a second verification process that ultimately determines whether or not the suspicion of unauthorized startup is valid based on different judgment criteria than the first verification process. This enables the vehicle 1 (in-vehicle system 10) and the management system 2 to cooperate and efficiently determine whether or not the suspicion of unauthorized startup on the vehicle 1 is valid.

[0118] Furthermore, as explained with reference to Figures 6, 9, 13, and 14, according to this embodiment, if the second verification process ultimately determines that the suspicion of unauthorized activation is not valid, the operating mode of the control device 11 (communication management device 12) returns from the alert standby mode to the normal standby mode, provided that authentication C21 is completed. In this way, even in situations where there is suspicion of unauthorized remote activation, the management system 2 and the control device 11 work together to allow the management system 2 to use a legitimate activation instruction INS-A to remotely activate the control device 11 (i.e., return it to the normal standby mode).

[0119] Furthermore, by referring to Figure 15 and following the process described above, it is possible to more reliably suppress the misuse of the functions of Vehicle 1 through direct unauthorized activation operations on Vehicle 1, while also considering the reduction of user convenience or the reduction of Vehicle 1's operating time, thereby realizing measures to suppress the misuse of Vehicle 1's functions. [Explanation of Symbols]

[0120] 1 Vehicle, 2 Management system, 3 User terminal, 5 Communication device, 10 In-vehicle system, 11 Control device, 12 Communication management device, 12A, 21 Communication I / F, 12B, 13A, 22 Processor, 12C, 13B, 23 Memory device, 13 Vehicle controller, 100 Vehicle control system

Claims

1. A mobile object control system for controlling a mobile object that has the function of operating in accordance with remote instructions within a predetermined area, A management system that generates remote instructions in a regular manner, A control device mounted on the mobile body and operating the mobile body in accordance with regular remote instructions from the management system, Equipped with, The control device is A first verification process is performed to determine whether or not there is a suspicion of unauthorized startup of the control device. If there is a suspicion of unauthorized startup, the management system is requested to execute a second verification process that will ultimately determine whether the suspicion of unauthorized startup is valid, based on different criteria than those used in the first verification process. Mobile control system.

2. A mobile body control system according to claim 1, The remote instruction includes a start instruction to remotely start the control device, The first verification process is, The control device determines whether the startup instruction received conforms to a specified format, If the aforementioned startup instruction does not conform to the aforementioned specified format, it will be determined that there is a suspicion of unauthorized startup. including Mobile control system.

3. A mobile body control system according to claim 1, The first verification process is, To determine whether or not the startup of the control device has been detected in a manner that does not follow the prescribed startup sequence, If the startup of the control device that does not follow the aforementioned startup sequence is detected, it is determined that there is a suspicion of an unauthorized startup. including Mobile control system.

4. A mobile body control system according to claim 1, The remote instruction includes a start instruction to remotely start the control device, The second verification process described above is: To determine whether the management system actually transmitted the activation instruction received by the mobile device, If the management system did not actually transmit the activation instruction to the mobile device, the suspicion of unauthorized activation will be ultimately determined to be valid. including Mobile control system.

5. A mobile control system according to claim 4, If the second verification process ultimately determines that the suspected unauthorized activation is valid, the management system, subject to the conditions for suspending transmission, requests the mobile communications carrier to suspend the transmission of information to all mobile devices managed by the management system from the telecommunications number used to transmit the activation instruction related to the suspected unauthorized activation. The aforementioned transmission termination conditions are: The telecommunications number was used to give an unauthorized start command to the control devices of multiple mobile bodies, including the control device of the mobile body, or The aforementioned telecommunications number was used multiple times within a predetermined time period for the purpose of issuing an unauthorized activation command to the control device of the mobile device. Mobile control system.

6. A mobile body control system according to claim 1, The remote instruction includes a start instruction to remotely start the control device, Landmarks are placed within the aforementioned designated area. The second verification process described above is: To determine whether the landmark can be recognized from the position of the moving object, If the landmark cannot be recognized from the position of the moving body, the control device will ultimately determine that the moving body is not within the predetermined area when it receives the activation command, and that the suspicion of unauthorized activation is valid. including Mobile control system.

7. A mobile body control system according to claim 1, The remote instruction includes a start instruction to remotely start the control device, The second verification process described above is: To acquire the location information of the aforementioned moving object, The control device determines whether the mobile body is within the predetermined area when it receives the activation command by comparing the map information in which the location of the predetermined area is registered with the location information of the mobile body, If the control device receives the activation command and the moving object is not within the predetermined area, the suspected unauthorized activation is ultimately determined to be valid. including Mobile control system.

8. A mobile body control system according to claim 1, The remote instruction includes a start instruction to remotely start the control device, The mobile body and the communication device installed in the predetermined area are configured to communicate according to a specific communication method. The second verification process described above is: To determine whether or not communication is established between the mobile body and the communication device, If communication is not established between the mobile body and the communication device, it is ultimately determined that the mobile body is not within the predetermined area when it receives the activation command, and the suspicion of unauthorized activation is valid. including Mobile control system.

9. A mobile body control method having a function to operate in accordance with remote instructions in a predetermined area, The mobile body is equipped with a control device that operates the mobile body in accordance with a legitimate remote instruction from a management system that legitimately generates the remote instruction. The aforementioned mobile body control method is: The first verification process to determine whether or not there is a suspicion of unauthorized startup of the control device is to be performed on the control device, If there is a suspicion of unauthorized startup, the system is requested to execute a second verification process that ultimately determines whether the suspicion of unauthorized startup is valid based on different criteria than those used in the first verification process. including Mobile control system.

Citation Information

Patent Citations

  • Mobile control method, mobile control system, and mobile control program

    JP2023148463A