Output device, output method, and program

The vehicle system employs alternative authentication to maintain essential services during network outages, addressing user inconvenience and safety by prioritizing function necessity and user consent.

JP2026066303APending Publication Date: 2026-04-16DENSO CORP
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-02-09
Publication Date
2026-04-16

AI Technical Summary

Technical Problem

Existing vehicle authentication systems fail to provide convenience to users when network connectivity is lost, leading to potential disruptions in subscription services and safety concerns during offline conditions.

Method used

Implement an alternative authentication mechanism within the vehicle system to enable the continuation of essential subscription services even in offline environments by determining the necessity and importance of functions using pre-stored information and user consent.

Benefits of technology

Ensures the continuity of critical vehicle functions and subscription services, enhancing user convenience and safety by allowing alternative authentication to override network failures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026066303000001_ABST
    Figure 2026066303000001_ABST
Patent Text Reader

Abstract

To provide an output device, output method, and program that improve convenience. [Solution] The acquisition unit acquires an instruction to perform a function, and if the instruction acquired by the acquisition unit indicates an instruction to perform a first function, the search unit searches for a second function that has the same purpose of use as the first function, and the output unit outputs information about the second function found by the search unit.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an output device, an output method, and a program.

Background Art

[0002] For example, various vehicle devices (e.g., vehicle audio devices) are installed in a vehicle, and a subscription service applied to this vehicle device may be provided. Since such a subscription service is a service based on a billing function, it is provided based on a predetermined contract. At this time, it is necessary to perform authentication to determine whether a contract has been concluded. Patent Document 1 proposes an authentication function for functions related to a moving body.

[0003] The function described in Patent Document 1 is an authentication method on the premise that it is connected to a network. When a moving body travels, it may travel in a place where radio waves are difficult to reach, such as a tunnel or a mountainous area. Therefore, even if the device mounted on the moving body executes communication, a network connection failure may occur and it may become offline. If authentication cannot be performed in an offline environment, it may cause anxiety to the passengers (equivalent to users) or interfere with driving.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] An object of the present disclosure is to provide an output device, an output method, and a program that can improve convenience for users.

Means for Solving the Problems

[0006] According to one embodiment, when the execution instruction acquired by the acquisition unit indicates an execution instruction for the first function, the output unit outputs information about the second function found by the search unit, so that the user can learn about alternative functions, thereby improving convenience for the user. [Brief explanation of the drawing]

[0007] [Figure 1A] Block diagram of the vehicle authentication system in the first embodiment [Figure 1B] Flowchart 1: A schematic explanation of the processing steps. [Figure 2] Flowchart 2: A schematic explanation of the processing steps. [Figure 3] Flowchart #3: A general overview of the processing steps. [Figure 4] Flowchart #4: A general overview of the processing steps. [Figure 5] Flowchart #5 that provides a general overview of the processing steps. [Figure 6A] Flowchart #6 that provides a general overview of the processing steps. [Figure 6B] Flowchart #7 that provides a general overview of the processing steps. [Figure 7A] Flowchart #8 that provides a general overview of the processing steps. [Figure 7B] Flowchart #9 that provides a general overview of the processing steps. [Figure 8] Block diagram of the vehicle authentication system in the second embodiment [Figure 9] Flowchart 1: A schematic explanation of the processing steps. [Figure 10A] Flowchart 2: A schematic explanation of the processing steps. [Figure 10B] Flowchart #3: A general overview of the processing steps. [Figure 10C] Flowchart #4: A general overview of the processing steps. [Figure 11A] Flowchart 1 illustrating the processing details in the third embodiment. [Figure 11B]Flowchart for Roughly Explaining Processing Content, Part 2 [Figure 11C] Explanatory Diagram of Example Display Screen, Part 1 [Figure 11D] Flowchart for Roughly Explaining Processing Content, Part 3 [Figure 11E] Explanatory Diagram of Example Display Screen, Part 2 [Figure 11F] Explanatory Diagram of Example Display Screen, Part 3 [Figure 12] Flowchart for Roughly Explaining Processing Content, Part 4 [Figure 13A] Flowchart for Roughly Explaining Processing Content, Part 5 [Figure 13B] Flowchart for Roughly Explaining Processing Content, Part 6

Modes for Carrying Out the Invention

[0008] Hereinafter, several embodiments of a vehicle authentication system and a vehicle control system will be described while referring to the drawings. In each of the embodiments described below, components that perform the same or similar operations are given the same or similar reference numerals, and the description thereof will be omitted as necessary.

[0009] (First Embodiment) The first embodiment will be described while referring to FIGS. 1A to 7B. The vehicle system 1 shown in FIG. 1A includes an HCU 3, a DCU 4, and other ECUs (not shown) installed inside the vehicle 2 connected by a network, and includes an off-vehicle management server 8 equivalent to a server outside the vehicle 2. Also, the user may possess a portable terminal 9 such as a smartphone, a tablet, or a notebook computer inside or around the vehicle 2, and this portable terminal 9 also constitutes the vehicle system 1. The vehicle system 1 is used as a vehicle authentication system and a vehicle control system.

[0010] HCU3, DCU4, external management server 8, and mobile terminal 9 are connected via network 7, thereby forming the vehicle system 1. HCU stands for Human Machine Interface Control Unit. DCU stands for Domain Control Unit. Network 7 consists of a wired communication network, a wireless communication network, etc.

[0011] <HCU3について> HCU3 constitutes the display system ECU. ECU stands for Electronics Control Unit, which is an electronic control unit. HCU3 is equipped with a processor, a memory unit 3a, I / O, and a bus connecting them, and functions as a control unit that performs various controls by executing the program stored in the memory unit 3a. The memory unit 3a is a non-transitory tangible storage medium that non-temporarily stores programs and data that can be read by a computer. The non-transitory tangible storage medium is realized by semiconductor memory or the like. A short-range wireless communication unit 5 is connected to HCU3, and the short-range wireless communication unit 5 enables communication with the short-range wireless communication unit 9b of the mobile terminal 9.

[0012] The HCU3 implements various functions, such as a billing function 3b, a local function 3c, and a notification control unit 3d, by executing application programs (hereinafter referred to as "apps") stored in the memory unit 3a. A display device 11 is connected to the HCU3. The display device 11 is composed of a liquid crystal display or an organic EL display, and is configured to display content in monochrome or full graphics. The display device 11 is a center information display, etc. An operation input unit 12 is connected to the HCU3. The operation input unit 12 accepts user input via a touch panel configured on the surface of the display device 11 or mechanical switches configured next to the display device 11 and outputs operation signals to the HCU3. The HCU3 can execute various functions based on the operation signals from the operation input unit 12. Vehicle equipment 10 is connected to the HCU3 or DCU4.

[0013] The functions of the application that HCU3 can implement can be divided into billing functions 3b and local functions 3c. Here, billing functions 3b refer to functions that are executed based on the contract information of the billing function agreed upon with the user of vehicle 2. When HCU3 obtains verification of the contract information of the billing function of the vehicle equipment 10, it becomes an execution unit that executes the contracted billing function 3b. Local functions 3c refer to functions that are not billed and are executed by applications pre-installed in the storage unit 3a, and represent functions that can be executed without the aforementioned billing function contract.

[0014] <DCU4について> The DCU4 is a centralized cockpit electronics system built on an integrated software and hardware platform, and consists of a memory unit 4d on which the database 4e is built. DCU4 stands for Domain Control Unit.

[0015] The DCU4 is configured by connecting an external environment acquisition unit 6. The external environment acquisition unit 6 acquires environmental information from outside the vehicle 2. The external environment acquisition unit 6 is connected to a detection unit 6a. The detection unit 6a is configured using sensors to acquire environmental information from outside the vehicle 2. Examples include a temperature sensor to detect the outside temperature of the vehicle 2, an illuminance sensor to detect the amount of sunlight outside the vehicle 2, a front view camera, a side view camera, a corner view camera, a rear view camera, an electronic mirror, a laser radar using LiDaR, and a peripheral monitoring sensor using millimeter-wave radar to monitor the area around the vehicle 2.

[0016] Furthermore, the detection unit 6a can also detect the user's status by using an occupant monitor. The occupant monitor detects the status of occupants in the vehicle 2 or the operating status of various control devices. The occupant monitor includes a camera that detects the status of occupants in the driver's seat, passenger seat, or rear seat by capturing images of them with an image sensor and outputs an image signal. The driver's occupant status monitor is called DSM. DSM is an abbreviation for Driver Status Monitor. The DCU4 has the function of a personal identification unit that identifies the user in the vehicle 2 based on the detection results of the occupant monitor.

[0017] The DCU4 is connected to other devices such as the HCU3 and other ECUs (not shown), and can send and receive various information from each other. The electronic control unit, including the DCU4, HCU3, and other devices, has functions such as a driving control system unit responsible for controlling the driving of the vehicle 2, a surrounding monitoring system unit that monitors the area around the vehicle 2, and a display system unit that presents information to the user via the display device 11.

[0018] The driving control unit controls the vehicle's operation using a gasoline engine, diesel engine, electric motor, etc., through manual or automatic driving. The driving control unit implements a manual driving control mode or an automatic driving mode corresponding to various levels of automatic driving. In automatic driving mode, the driving control unit for automatic driving performs a predetermined level of driving assistance and automatic driving by driving the driving actuators.

[0019] For example, Level I driver assistance can perform automatic braking to avoid collisions with obstacles, follow-the-lead driving to follow the vehicle ahead, or lane departure prevention driving to prevent the vehicle from drifting out of its lane. Level II autonomous driving can perform a combination of Level I driver assistance, or autonomous driving under specific conditions, such as automatically overtaking a slower vehicle 2 on a highway or automatically merging and diverging on a highway. Note that driver supervision is required in Level II autonomous driving. In Level III and above autonomous driving, the driving control system performs all driving tasks while monitoring by the surrounding monitoring system within the vehicle 2, but a detailed explanation is omitted. This enables driving control in each driving mode, whether manual or autonomous.

[0020] The DCU4 is configured to connect to an external network 7 via a network communication unit 4a. The network communication unit 4a represents a block for communication between the internal and external devices of the vehicle 2. The network communication unit 4a communicates via the network 7 with an external management server 8 that stores information on billing functions that can be performed by users who are occupants of the vehicle 2.

[0021] The DCU4 implements various functions, such as the authentication unit 4b and the alternate authentication unit 4c described later, by executing applications stored in the memory unit 4d. The memory unit 4d represents a non-transitory tangible storage medium that non-temporarily stores computer-readable programs and data. The non-transitory tangible storage medium is implemented using semiconductor memory or the like.

[0022] The storage unit 4d contains a database 4e. Database 4e is used as an authentication history information storage unit, which stores authentication history information indicating the result (success / failure) of authentication performed by the authentication unit 4b, along with the date and time. Database 4e also stores and maintains contract information for billing functions.

[0023] The authentication unit 4b performs authentication via the network communication unit 4a to determine whether or not the billing function can be implemented. The alternative authentication unit 4c performs authentication on behalf of the authentication unit 4b when it is not possible to connect to the external management server 8 via the network communication unit 4a.

[0024] <Regarding contracts for mobile devices and paid features> Users boarding vehicle 2 are equipped with a mobile terminal 9. The mobile terminal 9 is a device that can be brought into the vehicle and is equipped with an interface and display for operation input. The mobile terminal 9 is a device capable of various operation inputs and notification processing.

[0025] The mobile terminal 9 is comprised of a processor, memory, and I / O (none of which are shown). The mobile terminal 9 is equipped with a wireless communication unit 9a for wireless communication with an external management server 8, etc., via the network 7. The mobile terminal 9 is also equipped with a short-range wireless communication unit 9b for short-range communication with the short-range wireless communication unit 5 using wireless LAN such as WiFi (registered trademark) or short-range communication technology such as Bluetooth (registered trademark).

[0026] The mobile terminal 9 has an application for vehicle 2 installed in its memory. By running the vehicle application, the mobile terminal 9 can issue control commands to vehicle 2 from the user and obtain information about vehicle 2 from the HCU3 or DCU4 on vehicle 2. At this time, the user can set configuration information for vehicle equipment 10 by operating the mobile terminal 9. Vehicle equipment 10 here includes, but is not limited to, air conditioners and vehicle audio-visual equipment.

[0027] The user enters into a purchase or lease agreement for a subscription service related to vehicle equipment 10 by operating the operation input unit 12 or the mobile terminal 9. Hereinafter, the subscription service will be abbreviated as "sub". The user enters specified identification information as a new ID into a form provided by the management provider of the designated external management server 8 via the network 7 from the operation input unit 12 or the mobile terminal 9. Then, by the user accepting the contract terms, a purchase or lease agreement for the subscription service is concluded with the subscription service provider using the new ID. Such subscription services may have an expiration date or may be unlimited.

[0028] Then, contract information for the subscription service's billing function is registered in the database 8a of the external management server 8, linked to the user. The external management server 8 stores the contract information for the billing function in database 8a. This contract information for the billing function is also registered in the database 4e of the DCU4.

[0029] The contract information for the paid features is information indicating the purchase status of subscription services for each user of Vehicle 2, such as individuals, corporations, and organizations. The contract information for the paid features includes purchase information for various features purchased or leased by the user, user identification information, billing information for a set period or per transaction, and expiration information indicating the provision period of the subscription service. Database 8a stores contract information for paid features for a large number of users, linked to, for example, their name and its identification number.

[0030] Examples of subscription services with a fee include music streaming subscription services for in-vehicle audio equipment and video streaming subscription services that can be displayed on the display device 11. Other examples include subscription services for comfort features such as seat heaters to make the vehicle interior more comfortable, and subscription services for drive modes that allow the driver to change between manual and automated driving performance of vehicle 2. Furthermore, examples include subscription services for driver assistance or various levels of automated driving in automated driving mode, and subscription services for lighting up the interior of vehicle 2.

[0031] The following describes the internal processing of vehicle 2 after power is turned on. <If the connection with the external management server 8 is good> When the driver turns on the power switch using the ignition switch or power button, power is supplied to the HCU3, DCU4, etc. The network communication unit 4a of the DCU4 establishes a connection with the external management server 8 via the network 7 and establishes a session with the external management server 8. As long as the connection with the external management server 8 is not interrupted, the DCU4 determines that the communication status via the network 7 is good. At this time, the network communication unit 4a becomes able to communicate with the external management server 8.

[0032] The DCU4 performs authentication by comparing the contract information for the billing function stored in database 4e with the contract information for the billing function stored in database 8a on the external management server 8 using the authentication unit 4b.

[0033] If the DCU4 communicates with the external management server 8 via the network 7 from the network communication unit 4a, and the authentication unit 4b is able to authenticate whether or not the billing function can be implemented, it stores authentication history information indicating that the authentication was successful in the database 4e. Also, if the DCU4 determines that the billing function can be implemented, it updates the database 4e as necessary with the confirmation date of the contract information for the billing function indicating that it can be implemented.

[0034] As a result, the contract information for the billing function stored in database 8a by the external management server 8 and the contract information for the billing function stored in database 4e of the DCU 4 inside the vehicle 2 are updated as needed. This contract information for the billing function is updated periodically, for example, every few days or every month.

[0035] The authentication operation of the authentication unit 4b to determine whether or not the billing function can be implemented will be explained with reference to Figure 1B. When vehicle 2 is started in S121, DCU3 performs online authentication by the authentication unit 4b in S122. Similarly, when there is a command to change the occupants of vehicle 2, the authentication unit 4b performs online authentication when it receives a command to turn on the function in S123.

[0036] Login information is required when authenticating online with the external management server 8. If the occupant's (user's) login information is already registered in the DCU4 database 4e, or if the vehicle 2's identification information is already registered as login information in the DCU4 database 4e, the process proceeds to S127.

[0037] In S124, if it is determined that the occupant (user) is not registered and the identification number is not for registered vehicle 2, DCU4 notifies the occupant of vehicle 2 in S125 of a login request. As a result of notifying the login request, the occupant attempts to log in. Methods for authenticating the occupant's ID include authentication of the vehicle 2's identification information (vehicle number, etc.), personal authentication using the occupant monitor of the detection unit 6a mentioned above, and authentication by entering an individual password. If the occupant successfully logs in, the process returns to S124 and determines YES in S124.

[0038] DCU4 retrieves the contract information for the paid subscription function of the logged-in crew member from database 4e and determines in S127 whether the paid subscription function is still valid. If it is still valid, DCU4 activates the paid subscription function in S128. Conversely, if it is not still valid, DCU4 notifies the crew member in S129 to propose renewing the paid subscription function contract. For example, it may notify the crew member with information such as, "Your subscription contract expired on [date]. Would you like to renew it?" and encourage them to renew. If the crew member agrees to renew, DCU4 communicates with the external management server 8 and updates the contract information stored in databases 4e and 8a to extend the validity period.

[0039] Furthermore, at the time it is determined in S124 that the DCU4 is not registered in database 4e, communication may be performed with the external management server 8 to verify and update the contract information for the billing function registered in database 8a of the external management server 8.

[0040] <When Vehicle 2 is in motion or when it is not possible to connect to the external management server 8> The following describes the processing operations of vehicle 2 while it is in motion, with reference to Figures 2 to 6B. In S11 of Figure 2, while vehicle 2 is traveling on the road, the network communication unit 4a periodically determines in S12 whether it is able to maintain a connection with the external management server 8 via the network 7.

[0041] If, as a result of the network communication unit 4a communicating with the external management server 8 via the network 7, the network connection is interrupted due to reasons such as a weak radio wave reception environment, the authentication unit 4b in S13 is unable to authenticate whether the billing function can be implemented and determines that authentication has failed. In this case, the DCU 4 stores authentication history information indicating that authentication failed in the database 4e.

[0042] In S14, if the connection to network 7 is interrupted, the DCU4 performs alternative authentication (function of alternative authentication unit 4c) if the authentication unit 4b fails to determine whether or not to implement the billing function via the network communication unit 4a. At this time, the DCU4 performs alternative authentication based on information stored in the storage unit 4d or storage unit 3a provided on the vehicle 2 side (function of alternative authentication unit 4c). Furthermore, if the DCU4 determines whether or not to implement the billing function through alternative authentication in S14a, the notification control unit 3d should notify the occupant of the result of the alternative authentication unit 4c's determination. This allows the occupant to understand the result of the alternative authentication.

[0043] If DCU4 suddenly stops the billing function when authentication unit 4b fails, it may startle the driver and impair their driving. To solve this problem, if the billing function is related to the safety and security of the occupants, it may be possible to unconditionally allow the continuation of the billing function (function of alternative authentication unit 4c). Alternatively, if DCU4 is using the billing function at the time it determines whether to stop the billing function when authentication unit 4b fails, it may be possible to unconditionally allow the continuation of the billing function without determining whether to stop it (function of alternative authentication unit 4c).

[0044] Furthermore, DCU4 may determine that a billing function is feasible and perform alternative authentication if the billing function being judged falls under at least one of the following categories: a function necessary for the operation of vehicle 2, a function necessary for the safety of the user (occupant), or a function to make the internal environment of vehicle 2 comfortable (function of alternative authentication unit 4c). As will be explained individually below, DCU4 may also determine that a billing function is feasible if it falls under two or more of these categories.

[0045] <Functions required for vehicle 2 to operate> Specifically, as shown in Figure 3, DCU4 determines whether the billing function to be implemented in S31 is a function necessary for the operation of vehicle 2. If it determines that it is necessary, it performs the processing from S32 onward using the function of the alternative authentication unit 4c.

[0046] For example, when driving vehicle 2, the user sets a drive mode using the operation input unit 12 to change the driving performance of vehicle 2. Once a drive mode is set, the driving control system ECU sets the driving performance to match this drive mode and controls the driving of vehicle 2. In this drive mode, the system assists the user's operation when driving manually and enables driving control. The standard normal mode is pre-set to a mode that prioritizes a balance between operability and comfort.

[0047] In addition, Sport mode is set to a mode that enhances acceleration and deceleration response characteristics compared to Normal mode. Race Drive mode further enhances acceleration and deceleration response performance even more actively than Sport mode. Comfort mode is a mode that prioritizes comfort.

[0048] Snow mode is a mode that adjusts the driving performance of vehicle 2 to be suitable for driving on snowy roads. Eco mode is a mode that improves fuel efficiency compared to normal mode. When a user selects and purchases or rents these drive modes as a paid feature, the user will be able to select the drive mode by operating the operation input unit 12.

[0049] These drive modes include functions necessary for driving vehicle 2. For example, in sport mode or race drive mode, HCU3 visually displays examples of gear shifting, accelerator operation, and brake operation on the display device 11, and provides a service that allows the user to operate the gears, accelerator, and brakes according to the examples. In snow mode, it provides a service that allows the driving performance of vehicle 2 to be suitable for driving on snowy roads.

[0050] Even if DCU4 cannot authenticate these drive modes as billable functions via the network communication unit 4a, if it determines in S31 that they are functions necessary for the operation of vehicle 2, it will determine in S32 that the billable function in question can be implemented.

[0051] In S33, DCU4 determines the importance of the target payable function. This importance indicates the degree to which each function is necessary for the operation of vehicle 2, and is pre-set in stages from most necessary to least important. The importance information is pre-stored in memory unit 4d. For example, snow mode is one of the functions that is highly important for vehicle 2 to drive safely on snowy roads. Race drive mode is a mode that is relatively more for hobbyists and is therefore one of the functions that is less important for vehicle 2 to drive. This is just one example of how importance is set, and the order of importance is not limited to this setting.

[0052] If DCU4 determines in S33 that the importance level is lower than predetermined, it can activate the target billing function in S35 and make the subscription service for the billing function available, after obtaining user consent through operational instructions in S34. Conversely, if DCU4 determines that the importance level of the target billing function is higher than predetermined, it can forcibly activate the target billing function in S35 and make the subscription service available without seeking user instructions. This allows the user to use the relevant billing function.

[0053] <Functions necessary for user (occupant) safety> As shown in Figure 4, the DCU4 determines whether the billing function to be implemented in S41 is a necessary function for user safety. If it determines that it is a necessary function, the alternative authentication unit 4c executes the processing from S42 onward.

[0054] For example, vehicle 2 is equipped with manual and automatic driving modes. When driving vehicle 2, the user changes the driving mode of vehicle 2 by inputting commands from the operation input unit 12. Once this driving mode is set, the driving control system ECU controls the vehicle 2 to drive according to this driving mode.

[0055] In autonomous driving mode, the method of driver assistance or autonomous driving differs according to each level. If the user purchases or rents each level of these autonomous driving modes as a paid feature, they can select this driving mode by operating the operation input unit 12. For example, they can selectively implement functions such as radar cruise control (LCC), emergency stop function for collision avoidance, and accelerator pedal depression prevention function.

[0056] Even if DCU4 cannot authenticate these driving modes as billable functions via the network communication unit 4a, if it determines in S41 of Figure 4 that they are functions necessary for the safety of the occupants, it will determine in S42 that the billable function in question can be implemented.

[0057] Next, in S43, DCU4 determines the importance of the target billing function. This importance level indicates the degree to which it is necessary for crew safety, and is pre-set in stages from the most necessary function to the most important. The importance information is pre-stored in memory unit 4d.

[0058] For example, the emergency stop function for collision avoidance is a necessary and important function for preventing collisions with other vehicles 2 or obstacles, considering safety. Therefore, its importance is set relatively high. The accelerator pedal misapplication prevention function is also an important function for preventing collisions with obstacles, considering safety, so its importance is set relatively high. The radar cruise control function is a function that maintains a constant distance from the vehicle 2 traveling in front of the vehicle 2, and its importance is set relatively low compared to the emergency stop function and the accelerator pedal misapplication prevention function. This is just one example of how importance information can be set, but the order of importance is not limited to this.

[0059] If DCU4 determines in S43 that the importance level is lower than predetermined, it will obtain user consent through operational instructions in S44 and then activate the target billing function in S45. Conversely, if DCU4 determines that the importance level of the target billing function is higher than predetermined, it will forcibly activate the target billing function in S45 without seeking user instructions. This allows the user to use the relevant billing function.

[0060] The external management server 8 and the storage unit 4d may store whether the target billing function is a billing function related to safety and security and whether it is a function of a higher importance than predetermined. If it is a billing function related to safety and security, the DCU4 may activate the billing function unconditionally using the alternative authentication unit 4c. This allows the DCU4 to execute the billing function unconditionally if it fails to authenticate the license of the billing function it is trying to authenticate, provided that the billing function is related to the safety and security of the occupants.

[0061] <Functions to improve the internal environment of Vehicle 2> As shown in Figure 5, the DCU4 uses the alternative authentication unit 4c to determine in S52 whether the billing function to be implemented is a comfort function that improves the environment inside the vehicle. If the DCU4 determines that it is a comfort function, it determines in S53 that the billing function in question can be implemented.

[0062] When DCU4 determines in S52 whether or not to implement comfort functions to improve the internal environment of vehicle 2, it is desirable to acquire external environmental information in S51 prior to this process and to add the external environmental information of vehicle 2 to the criteria for determining whether or not to implement the billing function for alternative authentication. For example, external environmental information such as outside temperature information acquired by a temperature sensor or illuminance information acquired by an illuminance sensor may be used.

[0063] If the DCU4 determines that the outside temperature is lower than a predetermined standard temperature, it determines that the heating function inside the vehicle can be implemented using vehicle equipment 10 for heating, such as an air conditioner or seat heater (function of the alternative authentication unit 4c). If the DCU4 determines that the outside temperature is higher than a predetermined standard temperature, it determines that the cooling function can be implemented using vehicle equipment 10 for cooling, such as an air conditioner (function of the alternative authentication unit 4c).

[0064] Furthermore, a subscription service that lights up the interior of vehicle 2 also falls under the category of comfort features. In this case, DCU4 uses illuminance information acquired by an illuminance sensor as external environmental information of vehicle 2 to determine whether or not to implement the billing function (function of alternative authentication unit 4c). For example, if DCU4 determines that the illuminance outside the vehicle is lower than a predetermined value, it determines that it is possible to light up the interior with LEDs or other lighting installed inside the vehicle (function of alternative authentication unit 4c). Conversely, if DCU4 determines that the illuminance outside the vehicle is above a predetermined value, it disables the lighting (function of alternative authentication unit 4c).

[0065] Other services that qualify as convenience features include music streaming services and subscription services for streaming videos and movies. Even if authentication for the paid features of these convenience features cannot be performed through the network communication unit 4a, if DCU4 determines in S52 of Figure 5 that these features are necessary for convenience, it will determine in S53 that the paid features in question can be implemented (function of the alternative authentication unit 4c).

[0066] Next, in S54, DCU4 determines the importance of the target billing function. This importance indicates the degree to which each function is necessary to make the internal environment of vehicle 2 comfortable, and is pre-set in stages from the most necessary function to the most important. The importance information is pre-stored in memory unit 4d.

[0067] For example, among the comfort features, the air conditioning / heating function inside the vehicle is set to a relatively high level of importance. The function to light up the interior of vehicle 2 is set to a relatively low level of importance. This is just one example of how to set importance levels, but it's not limited to this order of importance.

[0068] If DCU4 determines in S54 that the importance level is lower than predetermined, it will obtain user consent through operational instructions in S55 and then activate the target billing function in S56. Conversely, if DCU4 determines that the importance level of the target billing function is higher than predetermined, it will forcibly activate the target billing function in S56 without seeking user instructions. This allows the user to use the relevant billing function.

[0069] Let's return to Figure 2 as the reference drawing and continue the explanation. In S14, the DCU4 obtains the result of the alternative authentication performed by the alternative authentication unit 4c and notifies the alternative authentication result in S14a. For example, the DCU4 may display "Alternative authentication was successful (or failed)." (First notification information) on the display device 11 via the HCU3. Alternatively, the DCU4 may communicate with the mobile terminal 9 and display the information on the display screen of the mobile terminal 9. Subsequently, the DCU4 may display "Functions will continue. The usable period is until the vehicle is stopped and the engine is turned off." (Second notification information) on the display device 11 or the mobile terminal 9.

[0070] The first and second notification information may be transmitted and announced chronologically and consecutively, or they may be announced simultaneously. Furthermore, the DCU4 may display a predetermined special icon representing this alternative function on the display device 11 or mobile terminal 9 only during the period when the function is authorized by the alternative authentication unit 4c.

[0071] In S15, DCU4 determines whether all authentication by the alternate authentication unit 4c has failed. If all authentication by the alternate authentication unit 4c has failed, DCU4 disables the subscription service for the target billing function in S20. If both authentication by the authentication unit 4b and authentication by the alternate authentication unit 4c fail, HCU3 should specifically inform the user of the reason for the authentication failure in S14b. For example, it would be good to inform the user of the reason, such as "Authentication failed due to network connection failure." This would allow the vehicle occupant to understand why they cannot use the service and provide support without causing distrust. In addition, although network connection failure was used as an example here, it would be good to inform the user of the reason for authentication failure even if the reason is something other than a connection failure to network 7.

[0072] Furthermore, if all authentications by the alternative authentication unit 4c in S15 have not failed, DCU4 allows the billing function to continue to be used through authentication by the alternative authentication unit 4c, as explained with reference to Figures 3 to 5 above. Even after authentication by the alternative authentication unit 4c is completed, DCU4 determines in S16 whether authentication is possible via the network 7 by the authentication unit 4b. In other words, DCU4 determines whether online authentication is possible or not.

[0073] If authentication by the authentication unit 4b becomes possible in S16, DCU4 will activate the billing function in S18 after authentication or ratification by the authentication unit 4b in S17. In other words, the decision made by the alternative authentication unit 4c regarding the feasibility of implementing the billing function remains valid until authentication by the authentication unit 4b becomes possible. This is because if ratification is performed by the authentication unit 4b, alternative authentication by the alternative authentication unit 4c becomes unnecessary. If authentication by the authentication unit 4b cannot be performed in S17, DCU4 will proceed to S16 and continue to wait until authentication becomes possible. That is, DCU4 will continue to wait until online authentication becomes possible.

[0074] For example, if DCU4 detects that the power switch of vehicle 2 has been turned off without authentication by authentication unit 4b, it determines NO in S16 and YES in S19. As a result, even if alternative authentication by alternative authentication unit 4c was performed for the target billing function, DCU4 will invalidate the alternative authentication by alternative authentication unit 4c if the power switch has been turned off.

[0075] In other words, DCU4 maintains the validity of the determination made by the alternative authentication unit 4c regarding the feasibility of implementing the billing function until the vehicle 2 stops and its power is cut off while authentication by the authentication unit 4b is impossible. For example, the billing function may have been enabled before operation began, but its validity period may expire during operation.

[0076] In this case, DCU4 may determine that the billing function can be implemented unconditionally while vehicle 2 is in operation. When the power switch is turned off, the unconditional permission by the alternative authentication unit 4c is released. When the power switch is turned on again, authentication by the authentication unit 4b is required. After the power switch is turned on again, authentication by the authentication unit 4b or alternative authentication by the alternative authentication unit 4c is required again, and the contract for the billing function can be complied with. If DCU4 determines that vehicle 2 is stopped, it may notify HCU3 and the display device 11 or mobile terminal 3 that authentication failed by the authentication unit 4b, and immediately stop the billing function.

[0077] The DCU4 may use the alternative authentication unit 4c to determine whether the expiration date of the billing function has passed using GPS or a timer, and then decide whether or not to implement the billing function. Alternatively, as shown in Figure 6A, the alternative authentication unit 4c may use the authentication history information of the billing function stored in the database 4e to decide whether or not to implement it.

[0078] Let's consider the case where authentication by the authentication unit 4b fails in S21 of Figure 6A due to reasons such as DCU4 being unable to connect to network 7. In this case, if the alternative authentication unit 4c refers to database 4e and determines that there is a history of successful authentication retrospectively, it should perform alternative authentication by the alternative authentication unit 4c in S23. If alternative authentication is successful, the target billing function should be activated (see S35, S45, S56).

[0079] Conversely, if authentication by the authentication unit 4b has not been successful in the past, DCU4 will determine NO in S22 and will not allow alternative authentication by the alternative authentication unit 4c. In this case, DCU4 should only accept authentication by the legitimate authentication unit 4b. If authentication has never been successful, the billing function in question is a function that has never been billed in the past. Therefore, it is best not to allow alternative authentication. As a result, it is possible to prevent the misuse of billing functions that should not be available in the first place.

[0080] Figure 6B shows a modified version of Figure 6A. If the DCU4 determines that there is no authentication success history, as shown in S22 of Figure 6B, it may display the reason why the function cannot be used on the display device 11 in S24. The DCU4 notifies the display device 11 of a message via the HCU3. The message at this time should show a reason such as, "This function has never been used before and there is no history of past authentication, so it cannot be used." This allows the vehicle occupant to understand why it cannot be used and provides support without causing distrust among the vehicle occupant. The DCU4 may also notify a message such as, "Would you like to be charged after communication is restored?" in S25 of Figure 6B and suggest that the charge be applied.

[0081] In addition, as shown in Figure 7A, the DCU4 may, even when the vehicle 2 is in motion in S61 and the billing function is being implemented in S62, make a determination in S63 using the authentication unit 4b as to whether or not the billing function can be implemented. If the DCU4 fails to determine whether or not the billing function can be implemented in S63, the alternative authentication unit 4c may forcibly determine in S64 that the billing function can be implemented even while the vehicle 2 is in motion.

[0082] If vehicle 2 is in motion, DCU4 should consider the failure to determine whether or not to implement the billing function due to poor radio communication conditions and forcibly allow alternative authentication by the alternative authentication unit 4c, thereby keeping the billing function activated. This allows the occupants to continue using the billing function in question.

[0083] As described above, according to this embodiment, if communication with the external management server 8 fails and the network connection for the billing function is interrupted, resulting in the authentication unit 4b failing to determine whether or not to implement the billing function via the network communication unit 4a, the alternative authentication unit 4c performs alternative authentication. Therefore, alternative authentication can be performed even in an offline environment.

[0084] <Modified form of the first embodiment> A modified example is shown in Figure 7B. Here, the process when vehicle 2 is started up is explained. When the ignition switch of vehicle 2 is turned on and vehicle 2 starts up, DCU4 performs authentication using the authentication unit 4b in S222 and determines in S223 whether the authentication was successful or not. If the authentication is successful, DCU4 activates the billing function in S224, but if the authentication is unsuccessful, it checks the authentication history of the alternative authentication unit 4c in S225.

[0085] Here, DCU4 checks the authentication history by the alternate authentication unit 4c at the time the ignition switch was last turned off. Specifically, it checks whether the expiration date for the billing function made available by the alternate authentication unit 4c has passed. For example, if the alternate authentication by the alternate authentication unit 4c is still valid, DCU4 performs the alternate authentication by the alternate authentication unit 4c in S227. This enables the implementation of an alternative function for the billing function, improving convenience for the occupants.

[0086] Conversely, if the alternative authentication by the alternative authentication unit 4c has expired in S226, the DCU4 retries the alternative authentication and repeats the retries from S222 until the number of retries exceeds a predetermined number in S228. If the DCU4 determines, after several retries, that the authentication has failed more than a predetermined number of times, it displays the reason for the authentication failure on the display device 11 via the HCU3 in S230. For example, the HCU3 displays a message on the display device 11 such as "Authentication also failed when the power was last turned off, so it is not in a state where it can be used unconditionally," informing the crew of the reason for the authentication failure. This allows the crew to understand why they cannot use the billing function.

[0087] Furthermore, if authentication by the authentication unit 4b fails and the power is cut off, and authentication fails again when the power is turned on next time as shown in S223~S230 of Figure 7B, the DCU4 should inform the crew via the HCU3 and display device 11 that the function for which authentication by the authentication unit 4b failed is unavailable, along with the reason for the authentication failure. In this case, the crew will be able to understand why they cannot use the billing function.

[0088] (Second Embodiment) A second embodiment will be described with reference to Figures 8 to 10C. In the second embodiment, if the billing function cannot be authenticated, an alternative function to the target billing function is searched for and the alternative function is executed.

[0089] In this embodiment, as shown in Figure 8, the DCU4 has the functionality of an application as a search unit 4f for searching for the aforementioned alternative function. The DCU4 also has the functionality of an application as an authentication determination unit 4g. Furthermore, the HCU3 has the functionality of an application as a notification control unit 3d. The other configurations are the same as in the first embodiment, so their description is omitted.

[0090] As shown in Figure 9, in S71, the DCU4 uses the authentication unit 4b to determine whether the target billing function can be implemented via the network communication unit 4a. If the DCU4 determines that the billing function can be implemented, it determines YES in S71 and implements the target billing function in S72.

[0091] Conversely, if DCU4 determines in S73 that the billing function cannot be implemented after determining in S71 whether the billing function can be implemented, it disables the billing function in S74. After this, regardless of the reason for the inability to connect to network 7, DCU4 uses the search unit 4f in S76 or S81 to search for an application that performs an alternative function that satisfies the same conditions as the billing function and has the same purpose.

[0092] If DCU4 determines in S75 that it is YES and the authentication unit 4b determines that the billing function cannot be implemented due to a loss of communication connection to network 7, it determines that it cannot connect via the network communication unit 4a. In this case, in S76, DCU4 should search for an alternative application that can be implemented in an offline state, i.e., in a local environment, using the search unit 4f. Here, if DCU4 determines in S75 that the cause is a lack of network connection, in S76 it searches offline for an application with an alternative function that has the same purpose as the billing function.

[0093] The DCU4 searches for applications pre-installed in the local environment inside the vehicle 2, for example, in the memory unit 4d of the DCU4. If an application with alternative functionality is stored in the memory unit 4d, the DCU4 determines that the alternative functionality can be performed. When performing an offline search, the DCU4 may also search for applications installed in the memory unit 3a of the HCU3.

[0094] If the DCU4 has established a connection with the external management server 8 via the network 7, but the authentication unit 4b determines that the billing function cannot be implemented due to reasons such as the expiration of the contract period or failure to authenticate personal identification information, then the DCU4 will determine NO in S75. In this case, in S81, the search unit 4f should search the external management server 8 or other sources for an alternative application that can be implemented for free or for a fee.

[0095] In other words, if DCU4 determines in S75 that the problem is not due to a lack of internet connectivity but rather to an expired contract or a failure in personal authentication, in S81 it searches for an alternative application with the same function as the billing function via network 7. When DCU4 searches via network 7 using the search unit 4f, it may search for an application from the external management server 8, or it may search for an application from another server (not shown) via network 7. This application may be a free application or an application equivalent to a function stored offline in the storage unit 4d.

[0096] Furthermore, the DCU4 may use the search unit 4f to search for alternative functions from the functions provided in the mobile terminal 4 as an external terminal. The communication method during the search may be a local communication connection via the short-range wireless communication units 5 and 9b, or a communication connection via the network communication unit 4a and network 7 through a connection server (not shown).

[0097] If network 7 is accessible, apps with the same purpose and relevant functionality may be targeted, including apps with subscription-based billing features. In this case, DCU4 should determine whether or not apps with subscription-based billing features are usable.

[0098] Therefore, the app that performs the alternative function may be a subscription-based app, a one-time payment app (so-called shareware), or a free app (so-called freeware).

[0099] As a specific example of an application, if the billed feature under contract is an application that includes driving assistance functions related to safety or security, or a driving assistance application that includes driving control functions for vehicle 2, the DCU4 uses the search unit 4f to search for a driving control application with the same purpose as driving assistance.

[0100] If the contracted paid feature is an application that displays a map on the display screen of the display device 11 and also has a navigation function that provides guidance to the destination, the DCU4 uses the search unit 4f to search for map display applications with different titles and other applications that have navigation functions.

[0101] Navigation features include, for example, a paid feature that accurately searches for locations on the network 7 that offer high-resolution 3D maps and various services. Additionally, an alternative feature is provided that provides high-resolution 2D map display and route guidance. Furthermore, a local feature is available that provides simplified map displays and geographical guidance using only basic symbols. In this way, the features can be divided into stages.

[0102] Even if authentication for a pre-contracted paid feature is difficult, the DCU4 can explore other functional applications online from the network 7 via the network communication unit 4a. Furthermore, the DCU4 can explore applications pre-stored in the memory units 3a and 4d offline. In this way, functional exploration can be performed step-by step.

[0103] For example, if the HCU3 becomes unable to display only the map portion of the navigation function, the DCU4 may search for only the map portion from the local memory units 3a and 4d. In this case, the HCU3 may read only the map portion found by the DCU4 from the memory units 3a and 4d and use it to display it on the display screen of the display device 11.

[0104] For example, DCU4 should explore the functionality of human authentication apps in a step-by-step manner. For instance, human authentication apps may have both a paid feature with relatively high recognition accuracy and a local feature with lower recognition accuracy and lower resolution. The same applies to such human recognition apps.

[0105] Furthermore, DCU4 may pre-download and store applications in the storage unit 4d that are permitted to perform alternative functions in the event of authentication failure by the authentication unit 4b. Then, DCU4 can immediately search for alternative functions that are permitted to perform alternative functions using the search unit 4f.

[0106] If the target paid-fee app is a comfort-fee app related to entertainment that enhances comfort within the vehicle 2, the search unit 4f searches for apps with the same comfort-fee function. The DCU 4 may search from the same category or genre using the search unit 4f. If the authentication unit 4b of the DCU 4 determines that the paid-fee function cannot be implemented, the HCU 3 may implement an alternative app found by the search unit 4f of the DCU 4.

[0107] Here, we will further explain specific examples of alternative functions. Alternative functions for paid features may either completely replace the original paid feature or only replace some of its functions. Typically, paid features are more powerful and feature-rich than free features. Therefore, attempting to implement an alternative to a paid feature using only free features is unlikely to achieve 100% accuracy.

[0108] If you want to completely replace the paid features in DCU4, it's best to explore and use other paid apps. For example, by exploring and using another audio app as the alternative paid app, you can receive radio broadcasts in addition to music playback. If the audio app's functions become unusable due to expired authentication, DCU4 should use a different music app. This music app should be one that can perform both music playback and radio reception.

[0109] When substituting for certain functions, it is advisable to search for apps pre-installed by default in the memory units 3a and 4d of HCU3 or DCU4, search for free apps from the system, or search for and use other paid apps that are cheaper than the usage fees for paid functions whose authentication has expired or the prescribed fees.

[0110] DCU4 may search for and use an app that only provides music playback functionality and does not receive radio signals when substituting for certain functions. If a paid feature is unavailable and an alternative is needed, it may search for and use an app that only provides music playback functionality and does not receive radio signals from the start. Alternatively, it may first search for an audio app that has both music playback and radio functions, and then, if that audio app becomes unusable due to expired authentication, it may search for and use an app that only provides music playback functionality and does not receive radio signals.

[0111] In this case, if the app being searched for has alternative functionality and is related to safety or security, it should be given a higher priority. Other lower-priority apps may be stopped, and apps deemed to be of lower priority may be deleted (removed) to free up memory.

[0112] DCU4 may implement alternative functions to reproduce the billing function that was deemed impossible to implement by using multiple alternative functions. In this case, the billing function may be reproduced by implementing alternative functions using a combination of apps that can replace some of the functions.

[0113] In this case, the system may collaborate with an external mobile device 9 and further collaborate with other applications. For example, the HCU 3 may maintain a music playback function as a local function 3c, the mobile device 9 may maintain a radio reception function, and the external management server 8 may maintain an audio setting function.

[0114] For example, when DCU4 sends, receives, or mediates music content data, it would be beneficial to add and run functions that allow it to send, receive, and adjust apps and data located in various places within the system. In this case, apps with adjustment capabilities could also be searched for from external mobile devices 9 or app servers.

[0115] For example, when linking and mediating a navigation app with navigation functionality with an audio app, one might search for a mediation app that has a mediation function to mediate between the volume adjustment function used by the navigation app when guiding to a destination and the music volume adjustment function used by the audio app. For example, HCU3 could receive the searched app from DCU4 and run this mediation app together with the navigation app and audio app. Then HCU3 could selectively notify the passengers of directions and music within the vehicle, allowing them to comfortably receive directions and enjoy music. Here, we have explained the linking and mediation of navigation apps and audio apps, but it is a good idea to search for apps that can adjust, link, and synchronize various apps and acquire them as apps with alternative functions.

[0116] If the DCU4 cannot find an alternative function through the network 7 via the search unit 4f in S81, it should determine NO in S82 and return to S76 to search for an alternative function that can be performed offline.

[0117] The DCU4 searches for an alternative function application, and if it determines in S78 that the alternative function can be implemented, the authentication unit 4b also determines in S79 via the network communication unit 4a whether the alternative function can be implemented. If the authentication unit 4b determines that it can be implemented and S79 determines YES, the DCU4 activates the alternative function application in S80. After that, the HCU3 implements the alternative function application. The user can use the alternative function, improving user convenience. If the authentication unit 4b cannot perform online authentication in S79, the DCU4 may perform offline alternative authentication using the alternative authentication unit 4c.

[0118] When a crew member (user) begins using an alternative function application, the DCU4 executes the process shown in Figure 10A. In S83, the DCU4 implements the alternative function application found by the search unit 4f. When this alternative function is used to replace a paid function, it is advisable to inform and make the crew member aware that the paid function has been disabled due to expired authentication. For example, this can be done by (1) graying out the icon of the relevant function, (2) removing the icon of the relevant function from the menu screen, or (3) displaying information on a part of the screen indicating that it has been disabled. The information displayed may be text information or a mark indicating that it has been disabled.

[0119] The amount of information that can be displayed on the display screen of the display device 11 is limited. The HCU 3 periodically checks the icons to be displayed on the display device 11, and if the number exceeds a predetermined amount, it organizes the displayed information by reducing the amount of displayed information to free up display space or by deleting less important displayed information.

[0120] HCU3 may display a link to navigate to the authentication registration site for the subscription-based app. To check if the authentication for the subscription-based feature has expired, the occupant can select the link to the contact information and access the registration site using the browser function of HCU3 or the display device 11. The phone number, URL, and QR code (registered trademark) of the contact information may also be displayed. Even if the DCU4 of vehicle 2 cannot connect to network 7, the occupant may be able to take action using the communication function of their mobile device 9, as long as the information is displayed. This means that even if DCU4 becomes unable to connect to network 7, the occupant can access the registration site via their mobile device 9, alleviating their anxiety.

[0121] In S83, the DCU4 may execute the alternative function application discovered by the search unit 4f, and in S84, the authentication unit 4b may determine whether authentication for the billing function is possible. If the DCU4 determines in S85 that authentication for the billing function is possible, in S86, the HCU3 may stop executing the alternative function application and in S87, activate the billing function. The HCU3 may then prioritize executing the billing function application. This improves user convenience by allowing the billing function application to be executed preferentially if authentication for the regular billing function application becomes possible during the execution of the alternative function application.

[0122] Conversely, once HCU3 has performed the alternative function, it may be possible to prioritize the execution of the alternative function over the subscription service's billing function. DCU4 should store this change in priority in memory unit 4d and refer to the priority in memory unit 4d to decide which function to execute. In this case, HCU3 may prioritize the execution of the alternative function over the billing function.

[0123] As explained above, according to this embodiment, even if the DCU4 searches for an alternative function using the search unit 4f and the authentication unit 4b determines that the billing function cannot be implemented, the HCU3 will implement the alternative function found by the search unit 4f. Therefore, even if license authentication for the billing function of the subscription service fails from within the vehicle 2, the alternative function can be used to implement a function at the same level as the subscription service of the billing function, or at the minimum level required by the occupants.

[0124] Hereinafter, a modified example of the second embodiment will be described with reference to Figures 10B and 10C. <Modification 1 of the second embodiment> A modification of the second embodiment, part 1, will be explained with reference to Figure 10B. The DCU4 determines whether or not to implement the billing function using the authentication unit 4b. If there are no sections where the radio waves are interrupted while the navigation application is running (NO in S281), the billing function can be activated as usual (S282). However, there are cases where it is possible to recognize in advance that there are sections where the radio waves are interrupted along the route of the navigation guidance (YES in S281). Here, the DCU4 has determined in advance that authentication of the billing function by the authentication unit 4b will be impossible by determining the possibility of network connection failure.

[0125] In such a situation, the DCU4 first notifies the crew via the HCU3 that there is a section in the route where radio waves will be interrupted (S283), and then searches for an alternative function from the mobile terminal 9 (S284). Then, in S285, the DCU4 determines whether or not an alternative function exists, and if an alternative function exists, in S286 it proposes to the crew that the alternative function be implemented in the specific section. At this time, when the DCU4 receives an operation input from the operation input unit 12, it stores the crew's response in the storage unit 4d.

[0126] On the other hand, if DCU4 determines in S285 that there is no alternative function, it notifies the crew in S288 via HCU3 and display device 11 that the billing function may become unavailable in a specific section. If DCU4 determines in S289 that authentication of the billing function is still possible even when approaching the specific section, it exits this routine and operates the billing function as usual. Conversely, if DCU4 determines in S289 that authentication of the billing function is no longer possible when approaching the specific section, it takes action in S290 according to the crew's response pre-stored in memory unit 4d.

[0127] For example, if a route is set where radio waves are interrupted, or if the validity period of the billing function expires after midnight, DCU4 can continue to operate as usual as long as authentication of the billing function is possible even when approaching the aforementioned specific section. Conversely, if DCU4 determines that authentication of the billing function is no longer possible when approaching the specific section, it will take action according to the crew's response pre-stored in memory unit 4d in S290. In this case, even if the billing function becomes unusable, the crew can perform an alternative function that they have pre-set, thus improving crew convenience.

[0128] <Modification of the second embodiment, part 2> Alternatively, as shown in Figure 10C, the system may perform the following processing steps in S381 to S386 before searching for an alternative function from the mobile terminal 9 in S284. The DCU4 refers to the memory unit 4d and determines in S381 whether a billing function with an expiration date within a predetermined period (e.g., 1 day, 2 days, 1 week, etc.) is registered. If the expiration date is set to be within a predetermined period in S381, the DCU4 notifies the occupant in S382 that there is a billing function with an expiration date approaching, using the function of the notification control unit 3d of the HCU3. Then, in S383, the DCU4 proposes updating the expiration date of the billing function. If the occupant affirms the update, i.e., does not reject the update, the DCU4 communicates with the external management server 8 in S386 to update the expiration date of the billing function and stores it in the memory unit 4d.

[0129] Furthermore, if the HCU3 has set a route using the navigation function and it is anticipated that the validity period of the billing function will expire during driving, it searches for an alternative function from the mobile terminal 9 in S284. The subsequent processing is the same as the processing in S285~S290 in Figure 10B, so the explanation is omitted.

[0130] In this modified version of the second embodiment, the network communication unit 4a communicates via the network 7 with an external management server 8 that stores information on charge-based functions that can be performed by the occupants of the vehicle 2, and the authentication unit 4b determines whether or not the charge-based functions can be performed via the network communication unit 4a. The authentication determination unit 4g determines in advance the possibility of at least one of the following situations occurring: network connection failure or expiration of the charge-based function, and thus determines in advance that authentication of the charge-based function by the authentication unit 4b will be impossible. The notification control unit 3d notifies the occupants when the authentication determination unit 4g determines that authentication by the authentication unit 4b will be impossible.

[0131] Furthermore, the DCU4 uses the search unit 4f to search for alternative functions that have the same purpose as the billing function, and if the authentication determination unit 4g determines that authentication by the authentication unit 4b is impossible due to a network connection failure, the notification control unit 3d proposes the implementation of the searched alternative function. For example, if the DCU4 determines that there is a high probability that it will be unable to connect to network 7 due to a route setting that causes radio wave interruptions, it will determine that the function will be unusable for a long period of time and propose the implementation of an alternative function. This allows the DCU4 to make a thoughtful suggestion to the crew by proposing the implementation of an alternative function even if the billing function becomes unusable for a long period of time.

[0132] When using the functions of the search unit 4f, DCU4 should incorporate occupant preferences as a condition for determining alternative functions. For example, in audio applications, it would be good to search for applications with alternative functions that are strong in bass or treble, or applications with alternative functions that enhance preferences for music genres such as J-POP or jazz. In navigation functions, it would be good to set the background color to pastel or vivid, have occupants input these preferences in advance on the options screen, or learn the audio settings input by the occupants.

[0133] The DCU4 searches for an alternative function using the search unit 4f, but if it determines that authentication by the authentication unit 4b is impossible due to the expiration of the billing function, the notification control unit 3d should propose to the occupant an extension of the billing function. For example, if the expiration date changes as the date changes across midnight, or if the expiration date expires while the vehicle 2 is in motion, it is advisable to propose to the occupant an extension of the billing function's expiration date. It is also desirable to propose an extension of the expiration date to the occupant if the expiration date is approaching in the relatively near future, such as within one week or two weeks.

[0134] (Third embodiment) The third embodiment will be described with reference to Figures 11A to 13B. In the third embodiment, the differences from the first or second embodiment will be described. As shown in Figure 11A, in S91, the DCU4 performs authentication via the network 7 using the authentication unit 4b. In S92, the DCU4 determines whether or not authentication was successful using the authentication unit 4b.

[0135] If authentication is successful in S92, DCU4 activates the paid features using the legitimate ID (personal authentication identification information) authenticated in S93. In this case, the user can use the paid features as usual.

[0136] If authentication by the authentication unit 4b fails in S92, the DCU4 determines in S94 whether the reason for the failure is a communication interruption due to a deterioration of the communication environment. If the reason for the failure is not a communication interruption, the DCU4 determines NO in S94 and concludes that personal authentication has failed. However, if the reason for the failure is a communication interruption, the DCU4 inquires in S95 whether the user intends to be charged additionally for the relevant paid function by displaying it on the display device 11 via the HCU3 or by communicating with the mobile terminal 9. For example, during a trial period of one month or so, the user may be able to use the paid function or other paid functions free of charge. In this case, the user may be notified of this and inquired about whether they intend to be charged additionally. If the DCU4 does not accept an approval operation from the operation input unit 12 for a predetermined period of time, the display indicating whether or not the user intends to be charged additionally may be cleared.

[0137] As a result, DCU4 determines in S96 whether or not there is an intention to make an additional charge. When DCU4 receives an input indicating an intention to make a charge from the operation input unit 12 or the mobile terminal 9, it determines in S96 that it is YES and that the user intends to make an additional charge for the relevant charge-based function. For example, if identification information such as a credit card number is stored in advance in the memory units 3a and 4d in the vehicle 2, DCU4 may consider this to be the user's intention to make a charge and automatically determine that there is an intention to make an additional charge.

[0138] In S97, the DCU4 performs additional charges via the mobile terminal 9 from the short-range wireless communication unit 5, for example, by credit card payment, and activates the billing function using the personal authentication information of the new ID. Subsequently, the HCU3 or the like may implement the corresponding billing function. If the certificate is stored in the mobile terminal 9, the mobile terminal 9 may send the certificate to the vehicle 2 to enable authentication even offline.

[0139] On the other hand, in S94 of Figure 11A, if the reason for failure is not a communication failure, the routine may be exited as shown in Figure 11A. However, as shown in S95a of Figure 11B, DCU4 may ask the crew whether they wish to add a charge, linking it to the existing ID. Then, in S96a, if the crew indicates their intention to charge, DCU4 may activate the charge function using the existing ID in S97a.

[0140] Even when it is determined that the occupant intends to be charged and HCU3 is implementing the corresponding billing function, DCU4 performs online authentication via the network communication unit 4a in S101 of Figure 12. When the communication environment of network 7 becomes good, DCU4 verifies the information stored in the database 8a of the external management server 8 in S101.

[0141] In S102, DCU4 determines whether the relevant paid function is available without additional charges. If DCU4 determines in S102 that it is available without additional charges, in S103, it may cancel the additional charges for the relevant paid function and cancel the crew's decision to pay additional charges. Furthermore, in S104, the new ID may be canceled. Canceling the new ID is optional and should be done after confirming the crew's intention to cancel. Subsequently, HCU3 becomes able to implement the relevant paid function using the existing valid ID. As a result, the crew can effectively utilize the paid function using the existing valid ID. Alternatively, for example, the period during which additional charges were incurred may be compared with the expiration date before the authentication expires, and if it falls outside the expiration date, additional charges may be incurred.

[0142] DCU4 should determine YES in S102 and, for example, if it determines that there has been a double charge, process a refund. If the charge is canceled in S103 and the new ID is deleted in S104, the crew should be notified of this via the display device 11. The message at this time should be, for example, "A refund will be processed because there has been a double charge," or "No additional charge was made as the charge had already been made. The function in question is functioning without additional charge." In this case, the crew can confirm whether they were charged unnecessarily, whether they received a refund after the charge, or whether they were not charged at all, thus preventing them from feeling anxious.

[0143] <Variation Example 1> <Regarding button operations by occupants and the display screen content of the display device 11 while the vehicle is stopped, in autonomous driving mode, or in motion> For example, in S94 of Figure 11A, if the reason for authentication failure by the authentication unit 4b is a communication interruption, the crew will be asked to confirm their intention to be charged. Also, even if the reason for authentication failure by the authentication unit 4b in S94 of Figure 11B is not a communication interruption, the crew will be asked to confirm their intention to be charged in S95a.

[0144] For example, as shown in Figure 11C, the HCU3 displays an inquiry message P on the display screen of the display device 11, prompting the occupant to input an action. For example, in the example shown in Figure 11C, it displays "Approval for the application being used failed. Do you want to be charged additionally? 'Yes', 'No'," prompting the occupant to input an action. At the same time, the HCU3 warns the occupant by displaying an exclamation mark in the center of the map screen M where the navigation application is running, drawing the occupant's attention to the inquiry message P. In this case, some kind of operation input from the operation input unit 12 is required.

[0145] If the designated button "Yes" is pressed by the occupant via the operation input unit 12 while vehicle 2 is stopped, in automatic driving mode, or in manual driving mode, an additional charge will be incurred, the billing function will be activated, and then the HCU 3 will erase the inquiry display P from the display screen as shown in Figure 11C.

[0146] Furthermore, during manual operation of vehicle 2, the designated "Yes" button may not be pressed by the occupant via the operation input unit 12. In this case, the processing routine shown in Figure 11A will never be able to activate the billing function. In such cases, as shown in S96a to S96c of Figure 11D, if HCU 3 determines that it has not received any operation instructions from the operation input unit 12 for a predetermined period of time, it is appropriate to delete the inquiry display P. An example of this screen transition is shown in Figure 11E.

[0147] If no input indicating intent to charge is received after a predetermined time has elapsed, a list of expired billing functions may be displayed on the display screen of the display device 11 via a pop-up at S96c in Figure 11D. An example of this screen is shown in Figure 11F. As shown in the upper section of Figure 11F, the HCU3 should prompt the occupant to input an operation by displaying an exclamation mark warning above the map screen M and displaying the inquiry display P2 for the "List of Expired Apps" button. When the HCU3 detects that the inquiry display P2 for the list of expired apps has been input, the DCU4 refers to the database 4e, and the HCU3 selects an expired billing function stored in the database 4e and displays it on the display screen. See the lower section of Figure 11F.

[0148] If no intention to charge is entered after a predetermined time has elapsed, the HCU3 may display a list of expired applications directly on the display screen of the display device 11, as shown in the lower section of Figure 11F, instead of displaying the inquiry display P2 of the list of expired applications as shown in the upper section of Figure 11F.

[0149] HCU3 may allow the crew to selectively decide whether or not they need the billing function. In this case, HCU3 should display a query prompt P3 indicating "activate," and if this query prompt P3 is pressed, the billing function can be selectively activated. Here, the billing period and history information may also be displayed for each billing function.

[0150] <Difference 2> <Regarding the expression of intent to pay while the vehicle is in motion and the content of the display screen of the display device 11> Drivers, in particular, may find it difficult to indicate their willingness to accept additional charges while the vehicle is in motion, such as when manually driving. For example, if the DCU4 requires detailed inquiries when asking the occupant about their willingness to accept additional charges, it may require repeated inputs.

[0151] For example, this would involve entering information such as a credit card number, expiration date (billing method), or billing conditions such as expiration date and number of uses required when adding a billing function, requiring at least two consecutive operations using numbers or setting buttons. Here, the billing method refers to information such as a credit card number and expiration date. The billing conditions could be conditions for billing periods in units of 1 day, 1 week, 1 month, 3 months, 6 months, or 1 year, or conditions for the number of uses, such as 1 time or 3 times while Vehicle 2 is running. In such cases, it is undesirable for the occupants of Vehicle 2, especially the driver, to have to perform operations multiple times. Therefore, it is preferable to perform all authentication by accepting a single button operation input.

[0152] The operation buttons of the operation input unit 12 in this case may be icons displayed on the display screen of the display device 11 or physical buttons installed on the steering wheel or the like. If icons are used, they are not normally displayed on the display screen of the display device 11. The HCU3 displays the icons on the display screen only in emergencies, and the occupant can input operation via the touch panel by tapping these icons. In particular, it is preferable that the icons be configured to be displayed only when an emergency request for operation from the occupant is needed while driving.

[0153] For example, physical buttons located around the steering wheel are not normally assigned any function. The HCU3 should display the function of the physical buttons on the display screen of the display device 11 only when it urgently requires the occupant to take action while driving, and the result of pressing the physical buttons should be used as the input result of the operation input unit 12 to determine whether or not to charge.

[0154] In particular, when requesting approval in an emergency, it is advisable to accept input via physical buttons or icons only if the authentication by the authentication unit 4b has already expired. There is no need to prepare a separate confirmation button for billing. This allows, for example, when a physical button or icon is pressed, if the conditions in S94 in Figure 11A are met, the processes in S95 and S96 can be skipped, and the billing function can be immediately activated in S97. Also, if it is determined that the conditions in S94 in Figure 11B are not met, the processes in S95a and S96a can be skipped, and the billing function can be immediately activated in S97a.

[0155] Furthermore, by pre-configuring various authentication methods, the intention to charge, including the aforementioned charging methods and conditions, may be pre-set in the memory unit 3a or the memory unit 4d of the DCU4 via the HCU3. Alternatively, the intention to charge, including the charging methods and conditions, may be set in the mobile terminal 9. For example, the HCU3 may display an option setting screen and allow the crew to input the charging method and conditions from the operation input unit 12. The mobile terminal 9 may display an option setting screen and allow the crew to input the charging method and conditions.

[0156] If the intention to charge is pre-stored in the memory units 3a, 4d or the mobile terminal 9, the DCU4 can refer to this information about the intention to charge locally or via the network 7 and determine that there is an intention to charge without performing various authentications. In this case as well, if the intention to charge is pre-set in the memory units 3a, 4d or the mobile terminal 9, for example, if the conditions in S94 in Figure 11A are met, the processes in S95 and S96 can be omitted and the charging function can be immediately activated in S97. Also, for example, if it is determined that the conditions in S94 in Figure 11B are not met, the processes in S95a and S96a can be omitted and the charging function can be immediately activated in S97a.

[0157] <Difference #3> The DCU4 may determine whether the crew member intends to be charged for the relevant billing function not only when online authentication by the authentication unit 4b fails, but also when offline alternative authentication by the alternative authentication unit 4c fails.

[0158] As shown in Figure 13A, in S111, the DCU4 performs authentication via the network 7 using the authentication unit 4b. In S112, the DCU4 determines whether or not the authentication was successful using the authentication unit 4b.

[0159] If authentication is successful in S112, DCU4 activates the billing function in S113 using the legitimate ID (personal authentication identification information) authenticated. In this case, the user can use the billing function as usual.

[0160] If authentication by the authentication unit 4b fails in S112, DCU4 determines in S114 whether the reason for the failure is a communication interruption due to a deterioration of the communication environment. If it is not a communication interruption, DCU4 determines NO in S114, judges that personal authentication has failed, and exits the routine. However, if the reason for the failure is a communication interruption, DCU4 replaces the authentication of the authentication unit 4b with the alternative authentication unit 4c in S115. If authentication by the alternative authentication unit 4c fails, DCU4 asks the user in S117 whether they intend to be charged additionally for the relevant billing function.

[0161] In this case, DCU4 may use the communication of the short-range wireless communication unit 5 to make an inquiry from the mobile terminal 9, thereby determining in S118 whether or not there is an intention to make an additional charge. When DCU4 receives input indicating an intention to make a charge from the mobile terminal 9, it determines in S118 that it is YES and that the user intends to make an additional charge for the relevant billing function. In S119, DCU4 makes an additional charge using, for example, credit card payment and activates the billing function using a new ID (personal authentication information). After that, the relevant billing function may be implemented by HCU3 or the like. Also, as shown in Figure 13B, if DCU4 does not indicate an intention to make a charge even after a predetermined time has elapsed in S118a, it may clear the inquiry display P in S118b and display a list of expired billing functions in S118c. Alternatively, the same process as shown in <Modification Example 1> may be executed.

[0162] As explained above, according to this embodiment, if authentication by the authentication unit 4b fails, the DCU4 determines whether the crew member intends to be charged additionally for the relevant billing function. If the DCU4 determines that the crew member intends to be charged additionally for the relevant billing function, it enables the implementation of that billing function. This allows the crew member's request to be met and improves user convenience.

[0163] (Other embodiments) The present invention is not limited to the embodiments described above, and can be implemented in various modified forms and is applicable to various embodiments without departing from its essence. In the embodiment described above, the DCU4 is shown as the primary unit performing the authentication process. However, some or all of the processing and functions may be performed by other in-vehicle devices (e.g., HCU3). Conversely, functions installed in HCU3 may be performed by other in-vehicle devices (e.g., DCU4).

[0164] The HCU3 or other DCU4 methods described in this disclosure may be implemented by a dedicated computer provided by configuring a processor and memory programmed to perform one or more functions embodied by a computer program. Alternatively, the HCU3 and DCU4 methods described in this disclosure may be implemented by a dedicated computer provided by configuring a processor with one or more dedicated hardware logic circuits. Alternatively, the control devices and methods described in this disclosure may be implemented by one or more dedicated computers configured by a combination of a processor and memory programmed to perform one or more functions and a processor configured with one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by the computer on a computer-readable non-transitional tangible recording medium.

[0165] The technologies of each function in each embodiment may be combined for processing, or the technologies between each embodiment may be combined for processing. In particular, according to the first aspect of this disclosure, in addition to the claims, the following inventions are also included.

[11] A vehicle authentication system comprising: a network communication unit (4a) that communicates via a network with a server (8) that stores information on charge-based functions that can be performed by the occupants of a vehicle; an authentication unit (4b) that authenticates whether or not the charge-based functions can be performed via the network communication unit; and an alternative authentication unit (4c) that substitutes for the authentication of the authentication unit when it is not possible to connect to the server via the network communication unit, wherein the alternative authentication unit performs alternative authentication when the connection to the server is interrupted and the authentication unit fails to determine whether or not the charge-based functions can be performed via the network communication unit.

[0166]

[12] The alternative authentication unit determines that the billing function to be determined to be implementable is implementable and performs alternative authentication if the billing function falls under at least one of the following: a function necessary for the operation of the vehicle, a function necessary for the safety of the occupants, or a function for making the internal environment of the vehicle comfortable

[11] .

[0167]

[13] A vehicle authentication system comprising an external environment acquisition unit (6) for acquiring external environmental information of the vehicle, wherein the alternative authentication unit, when determining whether or not to implement comfort functions for making the internal environment of the vehicle comfortable, adds the external environmental information of the vehicle to the conditions for determining whether or not to implement the billing function and performs alternative authentication

[11] or

[12] .

[0168]

[14] A vehicle authentication system according to any of the

[11] to

[13] , wherein if the vehicle is in motion and the authentication unit fails to determine whether or not the billing function can be performed while the billing function is being performed, the alternative authentication unit determines that the billing function can be performed.

[0169]

[15] The system further includes a notification control unit (3d) that notifies the aforementioned crew members, A vehicle authentication system according to any of the following

[11] to

[14] , wherein the alternative authentication unit determines whether or not the billing function can be implemented based on the alternative authentication, and the notification control unit notifies the occupant of the result of the alternative authentication unit's determination on whether or not the billing function can be implemented.

[0170]

[16] A vehicle authentication system according to any of the following

[11] to

[15] , wherein the result of the determination by the alternative authentication unit regarding the feasibility of implementing the billing function remains valid until authentication by the authentication unit becomes possible, or until the vehicle stops and the power to the vehicle is cut off while authentication by the authentication unit remains impossible.

[0171]

[17] A vehicle authentication system further comprising a notification control unit (3d) that notifies the occupant, wherein if the power is cut off while authentication by the authentication unit has failed, and authentication fails again when the power is turned on the next time, the notification control unit notifies the occupant that the function for which authentication by the authentication unit failed is unavailable

[16] .

[0172]

[18] The vehicle is equipped with an authentication history information storage unit that stores authentication history information for a billing function, and the alternative authentication unit is a vehicle authentication system

[11] to

[17] that uses the authentication history information for the billing function to determine whether or not it can be implemented.

[0173]

[19] A vehicle authentication method comprising: a process in which a network communication unit (4a) communicates via a network with a server (8) that stores information regarding a billing function that can be performed by the occupants of a vehicle; a process in which an authentication unit (4b) authenticates whether or not the billing function can be performed via the network communication unit; and a process in which an alternative authentication unit (4c) substitutes the authentication of the authentication unit when it is unable to connect to the server via the network communication unit, wherein the alternative authentication unit performs alternative authentication when the authentication unit fails to determine whether or not the billing function can be performed via the network communication unit as a result of the network connection being interrupted.

[0174]

[20] A vehicle authentication program comprising: a procedure for a network communication unit (4a) to communicate via a network with a server (8) that stores information regarding billing functions that can be performed by the occupants of a vehicle; a procedure for an authentication unit (4b) to authenticate whether or not the billing functions can be performed via the network communication unit; and a procedure for an alternative authentication unit (4c) to substitute the authentication of the authentication unit when it is not possible to connect to the server via the network communication unit, wherein if the network connection is interrupted and the authentication unit fails to determine whether or not the billing functions can be performed via the network communication unit, the alternative authentication unit performs an alternative authentication procedure.

[0175] According to a second aspect of this disclosure, in addition to the claims, the following inventions are also included. [twenty one] A vehicle control system comprising: a network communication unit (4a) that communicates via a network with a server that stores information on charge-based functions that can be performed by the vehicle's occupants; an authentication unit (4b) that determines whether or not a charge-based function can be performed via the network communication unit; a search unit (4f) that searches for an alternative function that has the same purpose as the charge-based function; and a control unit (3) that performs the searched alternative function if the authentication unit determines that the charge-based function cannot be performed.

[0176] [twenty two] If the authentication unit determines that the billing function cannot be performed due to a loss of network communication connection, the search unit searches for an alternative function that can be performed in an offline state.

[21] The vehicle control system as described above.

[0177] [twenty three] If the authentication unit determines that the billing function cannot be implemented despite a network connection with the server being established, the search unit searches for an alternative function that can be implemented through the server

[21] or

[22] .

[0178] [twenty four] The vehicle control system

[21] to

[23] , wherein the search unit searches for the alternative function that can be performed offline if it cannot find the alternative function by searching through the network.

[0179] [twenty five] The authentication unit also determines whether the alternative function can be performed, and the control unit performs the alternative function if the authentication unit determines that it can be performed, in any of the vehicle control systems

[21] to

[24] .

[0180]

[26] The search unit is a vehicle control system

[21] to

[25] which searches for an alternative function from a function provided on an external terminal.

[27] The control unit is a vehicle control system that uses multiple of the alternative functions to perform the alternative functions in order to reproduce the billing function that was determined to be impossible to perform

[21] to

[26] .

[0181]

[28] A vehicle control system according to any of the

[21] to

[27] , wherein if the authentication unit becomes able to perform the billing function while the alternative function is being performed, the control unit discontinues the performance of the alternative function and prioritizes the performance of the billing function.

[0182]

[29] A vehicle control system, one of the following

[21] to

[28] , wherein if the alternative function is implemented, the priority for implementing the alternative function is increased over the charge function, and the control unit prioritizes the implementation of the alternative function over the charge function.

[0183]

[30] A network communication unit (4a) communicates via a network with a server that stores information on chargeable functions that can be performed by the vehicle's occupants, An authentication unit (4b) that determines whether or not to implement a billing function via the aforementioned network communication unit, The system includes an authentication determination unit (4) that determines in advance whether authentication of the billing function by the authentication unit will be impossible by determining in advance the possibility of at least one of the following situations occurring: network connection failure or expiration of the billing function, A vehicle control system comprising a notification control unit (3) that notifies the occupant when the authentication determination unit determines that authentication by the authentication unit is impossible.

[0184]

[31] The system further includes a search unit (4f) that searches for alternative functions that have the same purpose as the aforementioned billing function, A vehicle control system in which, if the authentication determination unit determines that authentication by the authentication unit is impossible due to a network connection failure, the notification control unit proposes the implementation of the searched alternative function

[30] .

[0185]

[32] The search unit is a vehicle control system that adds the occupant's preferences as a condition for determining the alternative function.

[31]

[0186]

[33] The system further includes a search unit (4f) that searches for alternative functions that have the same purpose as the aforementioned billing function, If the authentication determination unit determines that authentication by the authentication unit becomes impossible due to the expiration of the billing function, The notification control unit is a vehicle control system of any of the following

[30] to

[32] that proposes to the occupants an extension of the billing function.

[34] A vehicle control method comprising: a process in which a network communication unit communicates via a network with a server that stores information on charge-based functions that can be performed by the vehicle's occupants; a process in which an authentication unit determines whether or not a charge-based function can be performed via the network communication unit; a process in which a search unit searches for an alternative function that has the same purpose as the charge-based function; and a process in which a control unit performs the searched alternative function if the authentication unit determines that the charge-based function cannot be performed.

[0187]

[35] A vehicle control system comprising: a procedure for a network communication unit to communicate via a network with a server that stores information on charge-based functions that can be performed by the vehicle's occupants; a procedure for an authentication unit to determine whether or not a charge-based function can be performed via the network communication unit; a procedure for a search unit to search for an alternative function that has the same purpose as the charge-based function; a procedure for a control unit to perform the searched alternative function if the authentication unit determines that the charge-based function cannot be performed; and a vehicle control program to perform the execution.

[0188] According to a third aspect of this disclosure, in addition to the claims, the following inventions are also included.

[41] A vehicle control system comprising: a network communication unit (4a) that communicates via a network with a server (8) that stores information on charge-based functions that can be performed by the occupants of a vehicle; an authentication unit (4b) that determines whether or not a charge-based function can be performed via the network communication unit; and a control unit (3) that enables the performance of the charge-based function, wherein if authentication by the authentication unit fails, the control unit determines whether or not the occupant intends to be charged additionally for the relevant charge-based function, and if the control unit determines that the occupant intends to be charged additionally for the relevant charge-based function, it enables the performance of the relevant charge-based function.

[0189]

[42] A vehicle control system

[41] in which, if the authentication unit determines that the occupant intends to be charged and the corresponding charge function is being implemented, the control unit performs online authentication via the network communication unit and verifies the information stored on the server, and if it determines that the corresponding charge function can be used without additional charges, it cancels any additional charges for the corresponding charge function and implements the corresponding charge function.

[0190]

[43] A vehicle control system according to claim

[41] or

[42] , which includes an operation input unit for receiving an approval operation from the occupant indicating their intention to charge an additional fee.

[0191]

[44] The system includes a notification control unit that indicates whether or not the user intends to incur the additional charges, The notification control unit clears the display indicating whether or not there is an intention to charge additional fees when the operation input unit does not accept the approval operation for a predetermined period of time.

[41] to

[43] A vehicle control system.

[0192]

[45] The notification control unit is a vehicle control system

[41] to

[44] which displays a list of approved operations that were not accepted by the operation input unit, or a list of expired billing functions, via a pop-up.

[0193]

[46] A vehicle control system comprising: a network communication unit (4a) that communicates via a network with a server (8) that stores information on charge-based functions that can be performed by the occupants of a vehicle; an authentication unit (4b) that determines whether or not a charge-based function can be performed via the network communication unit; and a control unit (3) that enables the performance of the charge-based function, wherein the system further comprises an alternative authentication unit (4d) that substitutes for the authentication of the authentication unit if authentication by the authentication unit fails, the alternative authentication unit determines whether or not the occupant intends to be charged additionally for the relevant charge-based function if alternative authentication by the alternative authentication unit fails, and the control unit enables the performance of the relevant charge-based function if it determines that the occupant intends to be charged additionally for the relevant charge-based function.

[0194]

[47] A vehicle control method comprising: a process in which a network communication unit communicates via a network with a server that stores information on charge-based functions that can be performed by the vehicle occupants; a process in which an authentication unit determines whether or not a charge-based function can be performed via the network communication unit; and a process in which a control unit performs a charge-based function, wherein the authentication unit determines whether or not the occupants intend to be charged additionally for the relevant charge-based function if authentication by the authentication unit fails, and the control unit enables the performance of the relevant charge-based function if it determines that the occupants intend to be charged additionally for the relevant charge-based function.

[0195]

[48] A vehicle control program for a vehicle control system, comprising: a procedure in which a network communication unit communicates via a network with a server that stores information on charge-based functions that can be performed by the vehicle's occupants; a procedure in which an authentication unit determines whether or not a charge-based function can be performed via the network communication unit; and a procedure in which a control unit performs a charge-based function, wherein the authentication unit determines whether or not the occupants intend to be charged additionally for the relevant charge-based function if authentication by the authentication unit fails, and the control unit enables the performance of the relevant charge-based function if it determines that the occupants intend to be charged additionally for the relevant charge-based function.

[0196] Although this disclosure is described in accordance with the embodiments described above, it is understood that the present invention is not limited to such embodiments or structures. The present invention also encompasses various modifications and variations within the scope of equivalents. In addition, various combinations and forms, as well as other combinations and forms that include one, more, or fewer of those elements, fall within the scope and concept of this disclosure. [Explanation of Symbols]

[0197] In the drawing, 1 represents the vehicle authentication system, 3 is the HCU, 4 is the DCU, 4a is the network communication unit, 4b is the authentication unit, 4c is the alternative authentication unit, 4d is the storage unit, 4f is the search unit, 6 is the external information acquisition unit, and 8 is the external management server.

Claims

1. An acquisition unit that acquires instructions for the execution of a function, If the execution instruction obtained by the acquisition unit indicates an execution instruction for the first function, the search unit searches for a second function that has the same purpose of use as the first function, An output unit that outputs information about the second function found by the search unit, An output device equipped with the following features.

2. The output device according to claim 1, wherein the output unit outputs information for activating the second function or information for proposing the implementation of the second function.

3. The output device according to claim 1, wherein the output unit outputs information relating to the second function when there are limitations on the performance of the first function.

4. The output device according to claim 1, wherein the output unit outputs information relating to the second function if authentication fails when performing the first function, or if there are restrictions on communication when performing the first function.

5. The output device according to claim 1, wherein the search unit searches for the second function by communication from a function provided in an external device.

6. The output device according to claim 3, wherein if the restriction on the execution of the first function is lifted while the second function is being performed after output by the output unit, the first function is performed.

7. The output device according to claim 1, which is an in-vehicle device mounted on a vehicle.

8. The acquisition unit acquires the instruction to perform the function, If the execution instruction acquired by the acquisition unit indicates an execution instruction for the first function, the search unit searches for a second function that has the same purpose of use as the first function. An output method wherein the output unit outputs information relating to the second function that has been searched by the search unit.

9. The acquisition unit is instructed to acquire instructions for the execution of a function. If the execution instruction acquired by the acquisition unit indicates an execution instruction for the first function, the search unit is instructed to search for a second function that has the same purpose of use as the first function. A program that causes the output unit to output information about the second function found by the search unit.

Citation Information

Patent Citations

  • Methods, devices and systems for authenticating to mobile networks, and servers for authenticating devices to mobile networks

    JP2018536352A

  • Method, device and system for authenticating to a mobile network, and server for authenticating a device to a mobile network

    JP6602475B2