In-vehicle device, control method, and program

The in-vehicle device addresses the issue of unawareness of stored digital key information post-contract termination by displaying a warning and prompting deletion, ensuring secure vehicle use.

JP2026065350APending Publication Date: 2026-04-15TOYOTA JIDOSHA KK
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
TOYOTA JIDOSHA KK
Filing Date
2024-10-03
Publication Date
2026-04-15

AI Technical Summary

Technical Problem

The digital key system may require a contract for use, and when this contract changes from an existing state to a non-existing state, the vehicle user may not be aware that information related to the digital key remains stored, leading to potential unauthorized access.

Method used

The in-vehicle device includes a storage unit and an execution unit that acquires contract information from an external source and controls the display unit to indicate the storage of digital key information only when the contract is terminated, prompting the user to delete it.

Benefits of technology

Prevents the user from being unaware that the system is still storing digital key information after the contract has been terminated, ensuring secure and authorized use of the vehicle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026065350000001_ABST
    Figure 2026065350000001_ABST
Patent Text Reader

Abstract

The present invention provides an in-vehicle device that prevents the vehicle from being unable to recognize that the vehicle user has stored information related to the digital key. [Solution] In step S21, the execution device acquires contract information CT indicating whether or not there is a contract to enable the vehicle's digital key. On the condition that the acquired contract information CT indicates that there is no contract (S22: YES), in step S26, the execution device causes the first display device to display information indicating that the storage device is storing information related to the digital key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an in-vehicle device, a control method, and a program.

Background Art

[0002] Patent Document 1 describes a digital key system. The digital key system includes an in-vehicle device mounted on a vehicle and a device. The in-vehicle device stores information related to a digital key for using the device as a digital key.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] A digital key system as described in Patent Document 1 may require a contract to enable the use of a digital key. In this case, when the contract changes from an existing state to a non-existing state, the vehicle user may not be able to grasp that the information related to the digital key that can be used under the contract remains stored.

Means for Solving the Problems

[0005] The in-vehicle device for solving the above problems includes a storage unit and an execution unit. The storage unit stores information related to a digital key of a vehicle. The execution unit acquires contract information indicating the presence or absence of a contract that enables the use of the digital key from the outside, and controls to display, on a display unit of the vehicle, information indicating that the storage unit stores the information related to the digital key, on the condition that the acquired contract information indicates that there is no such contract.

[0006] A control method for solving the above problem is a control method performed by an in-vehicle device that stores information about the vehicle's digital key, wherein the in-vehicle device obtains contract information from an external source indicating whether or not there is a contract that allows the digital key to be used, and, on the condition that the obtained contract information indicates that there is no such contract, performs a control method to display information on the vehicle's display unit indicating that the in-vehicle device is storing information about the digital key.

[0007] The program for solving the above problem is a program to be executed by an in-vehicle device that stores information about the vehicle's digital key, and the program causes the in-vehicle device to obtain contract information from an external source indicating whether or not there is a contract that allows the digital key to be used, and, on the condition that the obtained contract information indicates that there is no such contract, to execute a control to display information on the vehicle's display unit indicating that the in-vehicle device is storing information about the digital key. [Effects of the Invention]

[0008] Each of the above configurations prevents the vehicle user from being unaware that the system is still storing information about the digital key, by displaying information on the display unit indicating that the system is still storing information about the digital key after the contract has been terminated. [Brief explanation of the drawing]

[0009] [Figure 1] Figure 1 is a schematic diagram showing a management system of one embodiment. [Figure 2] Figure 2 is an explanatory diagram showing a series of deletion control processes performed by the management system of this embodiment. [Figure 3] Figure 3 is a flowchart showing the display control process performed by the digital key ECU in the same embodiment. [Figure 4] Figure 4 shows a warning image of the same embodiment. [Figure 5]Figure 5 shows the setting image displayed in the first aspect of the same embodiment. [Figure 6] Figure 6 shows a setting image displayed in the second aspect of the same embodiment. [Modes for carrying out the invention]

[0010] The following describes one embodiment of the in-vehicle device with reference to the drawings. First, the management system 10 will be described. <Overview of the management system> As shown in Figure 1, the management system 10 manages multiple digital keys available for the vehicle 20. Regarding digital keys, there is a standard set by the Car Connectivity Consortium (CCC). While the digital key aspects of this embodiment assume compliance with the CCC, they are also applicable to other standards and systems.

[0011] The management system 10 comprises a vehicle 20, multiple devices 40, a card key 51, a smart key (registered trademark) 52, a device server 60, and a management server 70. The devices 40 are used as digital keys.

[0012] Vehicle 20 includes a communication module 21, multiple HMIs 22, a BLE module 23, a UWB module 24, an NFC module 25, and an in-vehicle digital key ECU 26. HMI stands for Human Machine Interface. BLE stands for Bluetooth® Low Energy. UWB stands for Ultra Wide Band. NFC stands for Near Field Communication.

[0013] The communication module 21 communicates with the management server 70 via a wireless communication network. The multiple HMIs 22 include switches and touch panels as input units that accept user input for the vehicle 20. The multiple HMIs 22 include a first display device 22A and a second display device 22B as display units that display information to the user in the form of images. The multiple HMIs 22 include speakers as sound output units that present information to the user in the form of voice.

[0014] The first display device 22A is the meter display. The meter display is located in front of the steering wheel in the driver's seat. The second display device 22B is the center display. The center display is located between the driver's seat and the passenger seat.

[0015] The BLE module 23 communicates with the device 40 via BLE communication. The UWB module 24 communicates with the device 40 via UWB communication. The UWB module 24 measures the distance between the device 40 and the vehicle 20.

[0016] The NFC module 25 communicates with device 40 via NFC communication. The NFC module 25 also communicates with card key 51 via NFC communication. The digital key ECU 26 is installed in the vehicle 20. The digital key ECU 26 manages the digital key of the vehicle 20. The digital key ECU 26 has an execution unit, which is an execution device 27, and a storage unit, which is a storage device 28. The storage device 28 stores authentication information AT as information related to the digital key. Authentication information AT is information used to authenticate the digital key in order to enable control of the vehicle 20 by using the digital key when the digital key is used. Authentication information AT is provided for each digital key to be authenticated.

[0017] To authenticate the digital key means to enable the vehicle 20 to be controlled by the digital key. For example, when the digital key ECU 26 authenticates the digital key, the digital key ECU 26 enables the unlocking of the vehicle 20. Also, for example, when the digital key ECU 26 authenticates the digital key, the digital key ECU 26 enables the starting of the vehicle 20.

[0018] The storage device 28 stores various programs for performing processes related to the digital key. The execution device 27 is a CPU. The execution device 27 executes processes related to the digital key by executing various programs.

[0019] The storage device 28 stores the vehicle program PV. The vehicle program PV is a program for causing the execution device 27 to perform display control for displaying that the storage device 28 stores the authentication information AT when executed by the execution device 27. The execution device 27 performs display control for displaying that the storage device 28 stores the authentication information AT by executing the vehicle program PV.

[0020] Also, the storage device 28 stores various programs for performing processes related to the card key 51. The execution device 27 executes processes related to the card key 51 by executing various programs.

[0021] For example, when the card key 51 is held near the antenna provided outside the NFC module 25 and the NFC module 25 communicates with the card key 51, the execution device 27 determines that the authentication for the card key 51 is established. Then, the execution device 27 enables the unlocking of the door of the vehicle 20.

[0022] For example, if the card key 51 is placed near the antenna of the NFC module 25 located in the driver's seat, and the NFC module 25 communicates with the card key 51, the execution device 27 determines that authentication for the card key 51 has been successful. The execution device 27 then enables the vehicle 20 to start.

[0023] Vehicle 20 has an LF module 31, an RF module 32, and a smart key ECU 33. LF stands for Low Frequency. RF stands for Radio Frequency.

[0024] The LF module 31 communicates wirelessly with the smart key 52 using an LF signal. The RF module 32 communicates wirelessly with the smart key 52 using an RF signal. The smart key ECU 33 controls the smart key 52 of the vehicle 20. The smart key ECU 33 has an execution device 34 and a storage device 35. The storage device 35 stores various programs related to the smart key 52. ​​The execution device 34 performs the authentication process for the smart key 52 by executing the programs stored in the storage device 35.

[0025] For example, when the outer handle of the vehicle 20 is operated, the execution device 34 transmits an LF signal from the LF module 31 to the smart key 52. ​​Upon receiving the LF signal, the smart key 52 transmits an RF signal, including an individually set authentication signal, to the RF module 32. Based on the authentication signal included in the RF signal received by the RF module 32 from the smart key 52, the smart key ECU 33 authenticates the smart key 52. ​​When the authentication signal acquired by the smart key ECU 33 matches a predetermined authentication signal, the smart key ECU 33 completes the authentication for the smart key 52. ​​The smart key ECU 33 then enables, for example, the unlocking of the vehicle 20's doors. Alternatively, the smart key ECU 33 enables the vehicle 20 to start.

[0026] Device 40 is a mobile information terminal such as a smartphone. Device 40 includes a communication module 41, a device HMI 42, a BLE module 43, a UWB module 44, an NFC module 45, an execution device 46, and a storage device 47.

[0027] The communication module 41 communicates with the device server 60 via a wireless communication line. The device HMI 42 includes an input device that accepts user input for the device 40, and a presentation device that presents information to the user using images and sound, etc. The presentation device is, for example, a monitor and a speaker.

[0028] The BLE module 43 communicates with the vehicle 20 via BLE communication. The UWB module 44 communicates with the vehicle 20 via UWB communication. The NFC module 45 communicates with the vehicle 20 via NFC communication.

[0029] The storage device 47 stores key information DK as information related to the digital key. Key information DK is information that indicates the digital key. Key information DK is also information that makes device 40 available as a digital key.

[0030] The storage device 47 stores various programs for processing digital keys. The programs stored in the storage device 47 include, for example, a device application and a digital key framework. The device application is an application for storing and deleting key information DK. The digital key framework is a program that provides functions for pairing devices 40 and sharing digital keys using APIs provided by the OS. The execution device 46 executes the various programs stored in the storage device 47 to perform processing related to storing and deleting key information DK.

[0031] Multiple devices 40 include an owner device 40A and multiple share devices 40B. Note that in Figure 1, only one share device 40B is illustrated. The owner device 40A stores owner key information DKO, which indicates the owner key KO, as key information DK. Only one owner key KO can be registered for each vehicle 20. Therefore, there is only one owner key KO for each vehicle 20. The owner key information DKO is information that makes device 40 available as an owner device 40A.

[0032] The owner key information DKO includes, for example, vehicle information that identifies the target vehicle 20, identification information used for managing the digital key, certificate information that proves the digital key, public key information of the owner device 40A, and public key information of the vehicle 20. The device 40 that becomes the owner device 40A becomes the owner device 40A by pairing with the vehicle 20 and storing the owner key information DKO.

[0033] The share device 40B stores share key information DKS, which indicates the share key, as key information DK. A share key is a digital key that can be registered multiple times for a single vehicle 20 in order to register a digital key in order to enable the use of the digital key. In other words, multiple share keys can exist for a single vehicle 20.

[0034] The Share Key Information DKS is information that enables device 40 to be used as a shared device 40B. The Share Key Information DKS includes, for example, vehicle information that identifies the target vehicle 20, identification information used for managing the digital key, certificate information that certifies the digital key, and an authentication package from device 40 that authenticated the registration. The authentication package includes signature information, password information, effective start information, expiration information, and the public key information of shared device 40B.

[0035] Furthermore, device 40, which becomes shared device 40B, stores the share key information DKS when it is shared by owner device 40A. As a result, device 40 becomes shared device 40B.

[0036] In other words, a share key is a digital key that becomes usable when the owner device 40A shares a digital key. Therefore, a share key is a digital key that enables the use of a share device 40B that is different from the owner device 40A, assuming that the owner key KO is registered.

[0037] Furthermore, when a digital key is registered, it means that the digital key is usable. In other words, when a digital key is registered, the vehicle 20 stores the authentication information AT, and the device 40 stores the key information DK.

[0038] The device server 60 relays communication between the device 40 and the management server 70. A separate device server 60 is provided for each type of device 40. That is, the device server 60 that a first-type device 40 communicates with is different from the device server 60 that a second-type device 40 communicates with. For example, "type" refers to the model of the device 40, and a separate device server 60 is provided for each model of the device 40. For example, "type" also refers to the communication line used by the device 40, and a separate device server 60 is provided for each communication line used by the device 40.

[0039] Each device server 60 relays communication with the management server 70, allowing different types of devices 40 to communicate with the management server 70 via the device server 60. Note that only one device server 60 is shown in Figure 1.

[0040] <Management Server> The management server 70 manages digital keys. The management server 70 can communicate with the vehicle 20 and multiple devices 40. The management server 70 comprises an execution device 71 and a storage device 72. The storage device 72 stores a server program PS, contract information CT, and a database DB. The server program PS causes the execution device 71 to perform the deletion control of digital keys in the management system 10.

[0041] Contract Information CT indicates whether the owner of vehicle 20 has entered into a contract with a provider of digital key services. This contract allows the digital key to be used by subscribing to the digital key service.

[0042] The database DB associates each of the multiple digital keys with the corresponding vehicle 20 and the registered device 40. The database DB is divided into sections for each vehicle 20. When a digital key is registered, the management server 70 stores information in the data indicating the device 40 that stores the key information DK representing that digital key.

[0043] <Deletion control in management systems> Next, we will describe the series of processes in the deletion control for deleting digital keys in the management system 10.

[0044] When the management server 70 receives change request D10, the management system 10 performs a series of operations to delete the digital key. Change request D10 is a request to change the contract information CT from a state indicating that a contract exists to a state indicating that there is no contract. Change request D10 is obtained by the management server 70, for example, when the owner device 40A is operated.

[0045] In the following explanation, the processes executed by the execution device 27 will be described as processes executed by the vehicle 20, the processes executed by the execution device 46 will be described as processes executed by the device 40, and the processes executed by the execution device 71 will be described as processes executed by the management server 70.

[0046] As shown in Figure 2, the management system 10 performs a series of operations to delete a registered digital key. When the management server 70 receives the change request D10, the management server 70 starts executing the server program PS. Once the management server 70 starts executing the server program PS, the management server 70 first performs the process in step S11.

[0047] In step S11, the management server 70 generates a deletion request for all key information DKs that indicate digital keys that are available through the contract information CT that is the subject of the change request.

[0048] Specifically, the management server 70 identifies the owner key KO available through the contract indicated by the contract information CT, and the share key registered based on a registration request from the owner device 40A which stores the owner key information DKO indicating the said owner key KO. Next, the management server 70 generates a deletion request D11 to delete the identified owner key KO and a deletion request D12 to delete the identified share key.

[0049] Subsequently, the management server 70 sends a deletion request D11 to the owner device 40A. When the owner device 40A receives the deletion request D11, the owner device 40A performs the process in step S12.

[0050] In step S12, the owner device 40A deletes the owner key information DKO in accordance with the deletion request D11. As a result, the owner device 40A becomes unable to use the owner key KO.

[0051] After the management server 70 sends deletion request D11, the management server 70 sends deletion request D12 to the share device 40B. When the share device 40B receives deletion request D12, the share device 40B performs the process in step S13.

[0052] In step S13, the share device 40B deletes the share key information DKS in accordance with the deletion request D12. As a result, the share device 40B becomes unable to use the share key.

[0053] After the management server 70 sends the deletion request D12, the management server 70 proceeds to step S13. In step S13, the management server 70 stores the deletion history of key information DK in the database DB. After that, the management server 70 proceeds to step S14.

[0054] In step S14, the management server 70 generates a deletion request D13 for authentication information AT for authenticating the owner key KO identified in the processing of step S11, and for authentication information AT for authenticating the share key identified in the processing of step S11.

[0055] Subsequently, the management server 70 sends a deletion request D13 to the vehicle 20. When the vehicle 20 receives the deletion request D13, the vehicle 20 performs the process in step S15. In step S15, vehicle 20 deletes the authentication information AT in accordance with the deletion request D13. As a result, vehicle 20 becomes unable to authenticate the digital key.

[0056] Subsequently, vehicle 20 sends a completion notification M11 to the management server 70 indicating that the deletion of authentication information AT has been completed. When the management server 70 receives the completion notification M11, the management server 70 performs the process in step S16. In step S16, the management server 70 stores the deletion history of the authentication information AT in the database DB. After that, the management server 70 proceeds to step S17.

[0057] In step S17, the management server 70 updates the database DB. Specifically, the management server 70 deletes the information indicating the device 40 that stores the key information DK representing the digital key from the data for the target vehicle 20. After that, the management server 70 proceeds to step S18.

[0058] In step S18, the management server 70 changes the contract information CT to a state indicating that there is no contract. After that, the management server 70 terminates this series of processes. In this way, the management system 10 deletes information about digital keys that are available on the premise that the contract targeted by change request D10 exists. As a result, the management system 10 manages the system so that digital keys that are available on the premise that the contract targeted by change request D10 exists are unavailable.

[0059] <Vehicle display control> Next, we will describe a display control that displays information indicating that the storage device 28 in the vehicle 20 is storing authentication information AT.

[0060] When the communication status between the communication module 21 and the management server 70, which is an external server of the vehicle 20, changes from an area where communication is impossible to an area where communication is possible, the execution device 27 starts executing the vehicle program PV.

[0061] As shown in Figure 3, when the execution device 27 starts executing the vehicle program PV, the execution device 27 first performs the process in step S21. In step S21, the execution device 27 obtains contract information CT from the management server 70. Therefore, the execution device 27 obtains contract information CT when the communication status of the vehicle 20 with the outside world changes from outside the coverage area to within the coverage area.

[0062] In detail, when the communication status is within range, the communication module 21 acquires contract information CT from the management server 70 at predetermined intervals. As a result, the communication module 21 stores information synchronized with the contract information CT stored in the storage device 72 of the management server 70. When the communication status changes from outside range to within range, the communication module 21 acquires contract information CT from the management server 70, thereby synchronizing the information stored in the communication module 21 with the latest contract information CT. In this state, the execution device 27 acquires contract information CT from the communication module 21, thereby acquiring information synchronized with the latest contract information CT stored in the storage device 72 of the management server 70. After that, the execution device 27 proceeds to step S22.

[0063] In step S22, the execution device 27 determines whether the acquired contract information CT indicates that there is no contract. Specifically, the execution device 27 determines that the acquired contract information CT indicates that there is no contract if it indicates the same contract as the one indicated by the contract information CT acquired before going out of range.

[0064] In other words, if the acquired contract information CT indicates that there are no contracts, the same as the one acquired last time, the execution device 27 makes an affirmative judgment. On the other hand, if the acquired contract information CT indicates that there are no contracts at all, or if the acquired contract information CT indicates that there are contracts different from the ones acquired last time, the execution device 27 makes a negative judgment. If the acquired contract information CT indicates that there are contracts (S22: NO), the execution device 27 terminates this series of processes. In other words, in this case, the execution device 27 does not display information indicating that the storage device 28 has stored the authentication information AT.

[0065] On the other hand, if the acquired contract information CT indicates that there is no contract (S22: YES), the execution device 27 proceeds to step S23. In step S23, the execution device 27 determines whether or not the storage device 28 has stored the authentication information AT.

[0066] If the storage device 28 has stored the authentication information AT (S23: YES), the execution device 27 proceeds to step S24. In step S24, the execution device 27 determines whether the state in which the storage device 28 has stored the authentication information AT since the acquisition of the contract information CT satisfies a predetermined specified condition RC. The specified condition RC is that the state in which the storage device 28 has stored the authentication information AT since the acquisition of the contract information CT has elapsed for a predetermined specified time RT or longer. In other words, in this embodiment, in step S24, the execution device 27 determines whether the specified condition RC is satisfied because the state in which the storage device 28 has stored the authentication information AT since the acquisition of the contract information CT has elapsed for a predetermined time RT or longer. Specifically, the execution device 27 compares the time from the time the processing in step S21 was performed to the time the processing in step S24 was performed with the specified time RT.

[0067] If the storage device 28 has not stored the authentication information AT for more than the specified time RT since acquiring the contract information CT and the specified condition RC is not met (S24: NO), the execution device 27 returns the process to step S23.

[0068] On the other hand, if the specified condition RC is met (S24:YES) because the storage device 28 has been storing the authentication information AT for a specified time RT or longer since the acquisition of the contract information CT, the execution device 27 proceeds to step S25.

[0069] In step S25, the execution device 27 determines whether or not the vehicle 20 has been started. If the vehicle 20 has not been started (S25: NO), the execution device 27 repeats the process in step S25.

[0070] On the other hand, when the vehicle 20 is started (S25:YES), the execution device 27 proceeds to step S26. In step S26, the execution device 27 displays on the first display device 22A: storage status information MS1 ​​indicating that the authentication information AT is stored, and operation request information MS2 prompting the user to delete the authentication information AT.

[0071] As shown in Figure 4, specifically, the execution device 27 displays a warning image IM1 on the screen of the first display device 22A. The warning image IM1 includes an image showing memory status information MS1 ​​and an image showing operation request information MS2. The memory status information MS1 ​​is indicated by an image with the text "A digital key is registered." The operation request information MS2 is indicated by an image with the text "If you do not recognize this, please perform a delete operation."

[0072] As shown in Figure 3, the execution device 27 displays the warning image IM1 on the first display device 22A, provided that the acquired contract information CT indicates that there is no contract and that the state in which the authentication information AT is stored satisfies the specified condition RC. After that, the execution device 27 proceeds to step S27.

[0073] In step S27, the execution device 27 causes the second display device 22B to display a setting image IM2 related to the setting of the digital key in the first mode MD1. As shown in Figure 5, specifically, the execution device 27 displays the setting image IM2 in the first mode MD1 on the screen of the second display device 22B. The setting image IM2 includes a changeover switch SW1, a registration switch SW2, a partial deletion switch SW3, and a total deletion switch SW4.

[0074] The changeover switch SW1 is used to switch the activation of the digital key on or off. The registration switch SW2 is used to register a new owner key KO. Therefore, when the registration switch SW2 is operated, the execution device 27 performs a series of operations to delete the stored authentication information AT and store the authentication information AT for authenticating the new owner key KO.

[0075] The partial deletion switch SW3 is used to delete the owner key KO that is authenticated by the stored authentication information AT. When the partial deletion switch SW3 is operated, the execution device 27 performs the process of deleting the authentication information AT used to authenticate the owner key KO from the stored authentication information AT.

[0076] The global delete switch SW4 is a switch used to delete all digital keys authenticated by the stored authentication information AT. When the global delete switch SW4 is operated, the execution device 27 performs the process of deleting all stored authentication information AT. That is, when the global delete switch SW4 is operated, both the authentication information AT for authenticating the owner key KO and the authentication information AT for authenticating the share key are deleted.

[0077] In the setting image IM2 displayed in the first mode MD1, the toggle switch SW1, the registration switch SW2, the partial deletion switch SW3, and the total deletion switch SW4 are all displayed as operable. Therefore, the setting items related to the digital key performed while the setting image IM2 is displayed include the storage device 28 deleting the authentication information AT. Also, in the first mode MD1, it is possible to delete the authentication information AT while the setting image IM2 is displayed. The execution device 27 displays the setting image IM2 on the second display device 22B for a time predetermined in the first mode MD1, and then terminates this series of processes.

[0078] As shown in Figure 3, if the storage device 28 does not store the authentication information AT (S23: NO), the execution device 27 proceeds to step S28. In step S28, the execution device 27 causes the second display device 22B to display the setting image IM2 in the second mode MD2.

[0079] As shown in Figure 6, specifically, the execution device 27 displays the setting image IM2 on the screen of the second display device 22B in the second mode MD2. The second mode MD2 is a different mode from the first mode MD1. In the second mode MD2, the changeover switch SW1 is operable, but the registration switch SW2, the partial deletion switch SW3, and the total deletion switch SW4 are displayed as inoperable. Therefore, in the second mode MD2, it is not possible to delete the authentication information AT while the setting image IM2 is displayed.

[0080] As shown in Figure 3, if the storage device 28 does not store the authentication information AT (S23: NO), the execution device 27 will not display the warning image IM1 on the first display device 22A. After the execution device 27 displays the set image IM2 on the second display device 22B for a predetermined time in the second mode MD2, it terminates this series of processes. In this way, the execution device 27 executes the vehicle program PV, thereby realizing a control method in which the execution device 27 controls the display.

[0081] <Operation of this embodiment> According to the above embodiment, when the contract information CT switches from a contracted state to an uncontracted state, if the communication status between the communication module 21 and the management server 70 is within range, the management system 10 performs deletion control. As a result, the authentication information AT stored in the storage device 28 is deleted.

[0082] On the other hand, when the contract information CT switches from a contracted state to an uncontracted state, if the communication status between the communication module 21 and the management server 70 is out of range, the vehicle 20 cannot obtain the deletion request D13 even if the management system 10 performs deletion control. As a result, the storage device 28 remains in a state where it stores the authentication information AT.

[0083] In this case, when the communication status between the communication module 21 and the management server 70 changes from outside the service area to within the service area, the execution device 27 starts display control. The contract information CT obtained by the display control indicates that there is no contract. After that, if the execution device 27 makes a positive determination in the processing of steps S23 to S25, the first display device 22A displays the storage status information MS1 ​​and the operation request information MS2.

[0084] <Effects of this embodiment> (1) The in-vehicle digital key ECU 26 displays the memory status information MS1 ​​on the first display device 22A after the contract has been terminated, thereby preventing the user of the vehicle 20 from being unable to recognize that the authentication information AT is stored in the vehicle 20.

[0085] (2) In display control, the execution device 27 causes the first display device 22A to display operation request information MS2 in addition to the stored state information MS1. With the above configuration, the user of the vehicle 20 who sees the first display device 22A can be prompted to perform an operation to delete the authentication information AT from the storage device 28. As a result, the digital key ECU 26 can be prevented from retaining the authentication information AT that authenticates a digital key that can be used due to a voided contract.

[0086] (3) In display control, the execution device 27 causes the first display device 22A to display the warning image IM1, provided that the acquired contract information CT indicates that there is no contract and that the state in which the authentication information AT is stored satisfies the predetermined condition RC.

[0087] According to the above configuration, the warning image IM1 is displayed on the first display device 22A only when the specified condition RC is met. Therefore, the warning image IM1 is not displayed on the first display device 22A when the specified condition RC is not met.

[0088] (4) The specified condition RC is that the state in which the storage device 28 stores the authentication information AT after acquiring the contract information CT continues for a predetermined specified time RT or longer. According to the above configuration, the warning image IM1 is displayed on the first display device 22A on the condition that the state in which the authentication information AT is stored continues for a predetermined time RT or longer after acquiring the contract information CT. Therefore, if the authentication information AT is deleted from the storage device 28 before the predetermined time RT or longer has passed since acquiring the contract information CT, the warning image IM1 will not be displayed on the first display device 22A.

[0089] (5) In display control, the execution device 27 causes the second display device 22B of the vehicle 20 to display the setting image IM2. If the storage device 28 has stored the authentication information AT, the execution device 27 displays the setting image IM2 in the first mode MD1. On the other hand, if the storage device 28 does not have the authentication information AT stored, the execution device 27 displays the setting image IM2 in a second mode MD2 which is different from the first mode MD1. Therefore, when the user of the vehicle 20 sees the setting image IM2, they can determine whether or not the storage device 28 has stored the authentication information AT by the difference in mode.

[0090] (6) In the first embodiment MD1, it is possible to delete the authentication information AT using the setting image IM2. On the other hand, in the second embodiment MD2, it is not possible to delete the authentication information AT using the setting image IM2. Therefore, if the storage device 28 has stored the authentication information AT, the user of the vehicle 20 can delete the authentication information AT while the setting image IM2 is displayed. On the other hand, if the storage device 28 does not have the authentication information AT stored, even if the user of the vehicle 20 tries to delete the authentication information AT by mistake while the setting image IM2 is displayed, the operation to delete the authentication information AT will not be performed.

[0091] <Example of changes> The above embodiment can be implemented with the following modifications. The above embodiment and the following modifications can be combined with each other to the extent that they do not contradict each other technically.

[0092] Vehicle 20 does not necessarily have to have some of the BLE module 23, UWB module 24, and NFC module 25. Vehicle 20 can perform short-range wireless communication with device 40 if it has at least one of these modules. Furthermore, vehicle 20 is not limited to these modules, and may have any module that performs short-range wireless communication with device 40.

[0093] • The matters concerning digital keys in each of the above embodiments do not have to comply with CCC. The series of processes performed by the management system 10 for controlling the deletion of registered digital keys are not limited to the examples of the above embodiment. For example, the management server 70 may send deletion request D13 before sending deletion requests D11 and D12. Then, after obtaining completion notification M11, the management server 70 may perform the process in step S17 before sending deletion requests D11 and D12. In this way, the management system 10 may delete the authentication information AT and then delete the key information DK.

[0094] The in-vehicle device is not limited to the digital key ECU 26. For example, it may be a central ECU that manages multiple ECUs in the vehicle 20. Alternatively, the in-vehicle device may be an ECU that includes the digital key ECU 26 and the smart key ECU 33.

[0095] The digital key ECU 26 may be configured as a circuit including one or more processors that perform various processes according to a computer program (software). Alternatively, the digital key ECU 26 may be configured as a circuit including one or more dedicated hardware circuits, such as application-specific integrated circuits (ASICs), or a combination thereof, that perform at least some of the various processes. The processor includes a CPU and memory such as RAM and ROM. The memory stores program code or instructions configured to cause the CPU to perform the processes. Memory, i.e., computer-readable media, includes any available media that can be accessed by a general-purpose or dedicated computer. The same applies to the smart key ECU 33, device 40, and management server 70.

[0096] The share device 40B has the function of receiving a share key, as in the embodiment described above. A device 40 that has the function of receiving a digital key, like the share device 40B, is sometimes called a receiver device.

[0097] • A device server 60 does not need to be provided for each type of device 40. It is sufficient that multiple devices 40 and the management server 70 can communicate wirelessly. The device server 60 may be omitted. It is sufficient that multiple devices 40 and the management server 70 can communicate directly wirelessly.

[0098] The management server 70 may consist of multiple servers. For example, it may consist of a server that stores a database DB and a server that executes the server program PS. Alternatively, it may consist of a server that communicates with the vehicle 20 and a server that communicates with the device server 60, and these servers may be able to communicate with each other.

[0099] The management server 70 does not necessarily have to store a database DB. For example, the management server 70 may manage a combination of key information DK of device 40 and authentication information AT of digital key ECU 26 for one digital key in the management system 10. Alternatively, for example, the management server 70 may store only contract information CT.

[0100] <Information about various types of information> The authentication information AT is not limited to the examples of the above embodiments, as long as it is information used to authenticate the digital key when using the digital key. For example, the authentication information AT may be a common key shared between the digital key ECU26 and the device 40. Alternatively, the authentication information AT may be a common secret key.

[0101] The structure of the information included in the key information DK is not limited to the examples of the embodiments described above. For example, the owner key information DKO may contain information indicating the type of digital key. The type of digital key is, for example, information indicating one of the owner key KO and a share key.

[0102] The digital key information stored in the digital key ECU26 is not limited to authentication information AT; any information related to the digital key is acceptable. For example, the digital key information may also be information that identifies the digital key.

[0103] The information about the digital key stored by device 40 is not limited to key information DK, but can be any information about the digital key. For example, the information about the digital key may be information that identifies the digital key.

[0104] The information about the digital key stored in the digital key ECU26 may be different from or the same as the information about the digital key stored in the device 40, as in the embodiment described above.

[0105] <Display Control> The execution device 27 may perform display control at predetermined intervals even when the communication status is within range. This allows the execution device 27 to display the warning image IM1 even when the communication status is within range, provided that the contract information CT indicates that there is no contract. In this case, the execution device 27 does not need to delete the authentication information AT when it receives a deletion request D13 from the management server 70 while the communication status with the management server 70 is within range.

[0106] The timing at which the execution device 27 acquires contract information CT is not limited to the example of the above embodiment. For example, the execution device 27 may acquire contract information CT at a predetermined interval when the communication status is within range.

[0107] The specified condition RC does not necessarily have to be that the state in which the storage device 28 stores the authentication information AT continues for a specified time RT or longer after the acquisition of the contract information CT. For example, the specified condition RC may be that authentication is achieved using a card key 51 and a smart key 52, which are keys other than the digital key. In this case, since authentication is achieved using a key other than the digital key, even if the authentication information AT is deleted as a result of prompting the user to delete the authentication information AT, the digital key ECU 26 can prevent the continuous use of the vehicle 20 from being hindered.

[0108] The execution device 27 may display the warning image IM1 and the setting image IM2 regardless of whether the specified condition RC is met. In this case, the execution device 27 may omit the processing in step S24. For example, the execution device 27 may display the warning image IM1 if the specified condition RC is not met.

[0109] The execution device 27 may omit the processing in step S25. Alternatively, instead of step S25, the execution device 27 may determine whether the vehicle 20 has stopped and proceed to step S26 if the vehicle 20 has stopped. In this case, when the vehicle 20 moves and the communication status changes from outside the coverage area to within the coverage area, the user of the vehicle 20 can view the warning image IM1 and the setting image IM2 only after a safe situation has been established. Alternatively, for example, instead of processing in step S25, the execution device 27 may determine whether the power to the vehicle 20 has been turned off.

[0110] The execution device 27 does not need to display the operation request information MS2 on the warning image IM1 during display control. The execution device 27 only needs to display at least the stored state information MS1 ​​during display control.

[0111] • The settings related to the digital key, performed while the setting image IM2 is displayed, do not necessarily have to include the deletion of authentication information AT. For example, the setting image IM2 may be an image that only includes the toggle switch SW1.

[0112] In the first embodiment MD1, the execution device 27 does not need to display the settings related to the digital key in an operable manner when the setting image IM2 is displayed. Also, in the second embodiment MD2, the execution device 27 does not need to display the settings related to the digital key in an operable manner when the setting image IM2 is displayed.

[0113] The differences between the first mode MD1 and the second mode MD2 in which the execution device 27 displays the setting image IM2 are not limited to the example of the above embodiment. For example, the arrangement of each switch may be different in the first mode MD1 and the second mode MD2, the color of the text may be different, or the intensity of the switch color may be different. Also, for example, in the first mode MD1, four switches may be displayed, while in the second mode MD2, only the changeover switch SW1 may be displayed.

[0114] The execution device 27 may be the same as in the first embodiment MD1 and the second embodiment MD2. The execution device 27 may set the condition for displaying the setting image IM2 as the performance of a predetermined operation for displaying the setting image IM2. The predetermined operation is, for example, the operation of a predetermined switch on the second display device 22B. Specifically, the execution device 27 may determine whether or not the predetermined switch has been operated after the processing of step S26 and before the processing of step S27. If it has not been operated, the execution device 27 may repeat the determination process. In this way, the execution device 27 may set the timing for displaying the setting image IM2 to be different from the timing for displaying the warning image IM1.

[0115] The execution device 27 may display the setting image IM2 on the first display device 22A. Alternatively, the execution device 27 may display the warning image IM1 on the second display device 22B. In these cases, two images may be displayed on a single display device.

[0116] The execution device 27 may omit the processing in step S28. Furthermore, the execution device 27 may omit the processing in step S27. In other words, the execution device 27 does not need to display the setting image IM2 in the display control.

[0117] <Note> The technical concepts that can be understood from the above embodiments and modified examples are described below. [Note 1] An in-vehicle device comprising a storage unit and an execution unit, wherein the storage unit stores information relating to the vehicle's digital key, and the execution unit obtains contract information from an external source indicating whether or not there is a contract to enable the use of the digital key, and, on the condition that the obtained contract information indicates that there is no such contract, controls the vehicle's display unit to display information indicating that the storage unit is storing information relating to the digital key.

[0118] [Note 2] The in-vehicle device according to Note 1, wherein the execution unit, in the control, displays on the display unit information indicating that the storage unit is storing information related to the digital key, and information prompting the storage unit to perform an operation to delete the information related to the digital key.

[0119] [Note 3] The in-vehicle device according to Note 1 or Note 2, wherein the execution unit, in the control, causes the acquired contract information to indicate that there is no contract, and the state in which the storage unit has been storing information about the digital key since the acquisition of the contract information satisfies predetermined conditions, to display information on the display unit indicating that the storage unit is storing information about the digital key.

[0120] [Note 4] The in-vehicle device as described in Note 3, wherein the specified condition is that the storage unit has been storing information related to the digital key for a predetermined period of time or longer since the acquisition of the contract information.

[0121] [Note 5] The in-vehicle device according to any one of Notes 1 to 4, wherein the execution unit causes the vehicle's display unit to display a setting image for setting the digital key in the control, and if the storage unit has stored information regarding the digital key, it displays the setting image in a first mode, and if the storage unit does not have stored information regarding the digital key, it displays the setting image in a second mode different from the first mode.

[0122] [Note 6] The in-vehicle device according to Note 5, wherein in the first embodiment, it is possible to delete the information related to the digital key while the setting image is displayed, and in the second embodiment, it is not possible to delete the information related to the digital key while the setting image is displayed. [Explanation of Symbols]

[0123] 10…Management System 20... Vehicles 26…Digital Key ECU 27… Execution device 28…Storage device 40…Devices 70... Management Server CT... Contract Information IM1...Warning image IM2...Setting image MD1...First aspect MD2...Second aspect MS1...Memory status information MS2…Operation request information RC…Specified conditions

Claims

1. It comprises a memory unit and an execution unit, The aforementioned storage unit stores information related to the vehicle's digital key. The execution unit obtains contract information from an external source indicating whether or not there is a contract to enable the use of the digital key, and, on the condition that the obtained contract information indicates that there is no such contract, it performs control to display information on the vehicle's display unit indicating that the storage unit is storing information related to the digital key. In-vehicle device.

2. In the control, the execution unit causes the display unit to display information indicating that the storage unit is storing information related to the digital key, and information prompting the storage unit to delete the information related to the digital key. The in-vehicle device according to claim 1.

3. The execution unit, in the control, causes the display unit to display information indicating that the storage unit is storing information about the digital key, provided that the acquired contract information indicates that there is no contract, and that the state in which the storage unit has been storing information about the digital key since the acquisition of the contract information satisfies predetermined conditions. The in-vehicle device according to claim 1.

4. The aforementioned condition is that, after acquiring the contract information, the memory unit continues to store information related to the digital key for a predetermined period of time or longer. The in-vehicle device according to claim 3.

5. In the control, the execution unit, The display unit displays a setting image for configuring the digital key, If the storage unit stores information regarding the digital key, the setting image is displayed in the first mode. If the storage unit does not store information regarding the digital key, the setting image is displayed in a second mode different from the first mode. The in-vehicle device according to claim 1.

6. In the first embodiment, while the setting image is displayed, it is possible to delete the information related to the digital key. In the second embodiment, it is not possible to delete the information related to the digital key while the setting image is displayed. The in-vehicle device according to claim 5.

7. A control method performed by an in-vehicle device that stores information regarding the vehicle's digital key, The in-vehicle device obtains contract information from an external source indicating whether or not there is a contract to enable the use of the digital key, and, on the condition that the obtained contract information indicates that there is no such contract, it performs control to display information on the vehicle's display unit indicating that the in-vehicle device has stored information related to the digital key. Control method.

8. A program to be executed by an in-vehicle device that stores information about the vehicle's digital key, The in-vehicle device is instructed to obtain contract information from an external source indicating whether or not there is a contract to enable the use of the digital key, and, on the condition that the obtained contract information indicates that there is no such contract, to execute control to display information on the vehicle's display unit indicating that the in-vehicle device is storing information related to the digital key. program.

Citation Information

Patent Citations

  • Management device, management method, and management program

    JP2024001797A