Vehicle control system
The vehicle control device facilitates flexible and secure vehicle access by allowing initial biometric authentication followed by automatic operations, addressing limitations of existing systems that require mobile terminals and biometric registration.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- TOYOTA JIDOSHA KK
- Filing Date
- 2026-02-19
- Publication Date
- 2026-04-23
AI Technical Summary
Existing vehicle lock/unlock systems require users to possess a mobile terminal and register biometric information, limiting flexibility and raising security concerns about biometric information transmission.
A vehicle control device that allows biometric information transmission for initial lock/unlock requests, followed by automatic operations without re-authentication for subsequent requests, ensuring convenience and security by eliminating the need for continuous biometric verification.
Enables flexible vehicle access for temporary users and reduces security risks by minimizing biometric data transmission, achieving both convenience and security in vehicle access control.
Smart Images

Figure 2026069679000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a control device for a vehicle.
Background Art
[0002] Conventionally, there has been known a lock / unlock authority granting system that grants the authority to lock and unlock a vehicle to members other than the vehicle owner while maintaining the security of the vehicle (for example, Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, in the technology of Patent Document 1, since it is premised that members possess a mobile terminal, members who do not possess a mobile terminal cannot lock and unlock the vehicle. In addition, since all users who use the vehicle need to register biometric information in advance, it is impossible to flexibly respond to users who temporarily use the vehicle. Furthermore, although the biometric information of the vehicle owner is encrypted and transmitted, the owner may have concerns about the security of the communication of their own biometric information itself.
[0005] Therefore, in view of the above problems, the technology of the present disclosure aims to achieve both convenience and security of the vehicle lock / unlock system.
Means for Solving the Problems
[0006] To solve the above problems, according to one aspect of the present disclosure, A vehicle control device is provided which, upon detecting a locking / unlocking request from a vehicle user, causes the in-vehicle transceiver to transmit the user's biometric information detected by a biometric information sensor and the locking / unlocking request to an administrator terminal managed by the vehicle administrator, the locking / unlocking permission mode is a mode that always permits the locking / unlocking request, and upon detecting the receipt of the locking / unlocking permission mode input to the administrator terminal based on the biometric information, causes the door lock actuator to perform the locking / unlocking operation of the vehicle, and for subsequent locking / unlocking requests, causes the door lock actuator to perform the locking / unlocking operation of the vehicle without detecting the user's biometric information, and transmits a locking / unlocking completion notification to the in-vehicle transceiver to the administrator terminal. [Effects of the Invention]
[0007] According to one aspect of this disclosure, it is possible to achieve both convenience and security in a vehicle locking and unlocking system. [Brief explanation of the drawing]
[0008] [Figure 1] This is a diagram showing the configuration of a vehicle locking / unlocking system having a control device according to one embodiment. [Figure 2] This flowchart shows the processing procedure of a control device according to one embodiment. [Modes for carrying out the invention]
[0009] Embodiments of this disclosure will be described below with reference to the drawings. In each drawing, the same reference numerals are used for the same components, and redundant descriptions are omitted as appropriate.
[0010] (Example of a lock / unlock system configuration) Figure 1 is a diagram showing the configuration of a vehicle locking / unlocking system having a control device according to one embodiment. The vehicle locking / unlocking system comprises vehicle 1 and an administrator terminal 2 managed by the administrator of vehicle 1. Vehicle 1 and the administrator terminal 2 communicate indirectly, for example, via an information processing device at the information processing center 3, but they may also be configured to communicate directly.
[0011] In the locking and unlocking system according to this embodiment, when a user of vehicle 1 requests to lock or unlock vehicle 1, vehicle 1 transmits the user's biometric information and the vehicle 1 locking / unlocking request to administrator terminal 2. Administrator terminal 2 transmits either a locking / unlocking permission response or a locking / unlocking denial response to vehicle 1, based on the user's biometric information. Vehicle 1 performs the locking / unlocking operation based on either the locking / unlocking permission response or the locking / unlocking denial response.
[0012] Examples of managers of Vehicle 1 include, in addition to the owner of Vehicle 1, the owner's family, vehicle sales companies, transportation companies, rental car companies, car-sharing companies, and taxi companies. Examples of users of Vehicle 1 include, in addition to the owner of Vehicle 1, the owner's family, the owner's friends, delivery companies, sales representatives of vehicle sales companies, employees of transportation companies, rental car users, car-sharing users, and users of autonomous taxis.
[0013] Examples of vehicles include gasoline-powered vehicles, hybrid vehicles, and electric vehicles. Gasoline-powered vehicles are equipped with only an engine (internal combustion engine) as their prime mover, hybrid vehicles are equipped with an engine and an electric motor as their prime mover, and electric vehicles are equipped with only an electric motor as their prime mover.
[0014] Examples of engine-powered vehicles include gasoline engine vehicles and diesel engine vehicles. Examples of hybrid vehicles include HEVs (Hybrid Electric Vehicles), PHEVs (Plug-in Hybrid Electric Vehicles), and range-extender EVs. Examples of electric vehicles include BEVs (Battery Electric Vehicles) and fuel cell vehicles.
[0015] Examples of administrator terminal 2 include smartphones, tablet devices, laptops (personal computers), desktop PCs, and wearable devices.
[0016] Vehicle 1 is equipped with an operation switch 11, an in-vehicle ECU 12 (Electronic Control Unit), an output device 13, a biometric information sensor 14, and an in-vehicle transceiver 15. On the other hand, administrator terminal 2 is equipped with a terminal transceiver 21, a terminal ECU 22, and an input / output device 23.
[0017] The operation switch 11 outputs a detection signal for a user's request to lock or unlock the vehicle 1. Examples of the operation switch 11 include a door handle touch sensor, a lock / unlock button, and a remote control key button. The detection signal from the operation switch 11 is input to an in-vehicle ECU 12, which is an example of a control device. The in-vehicle ECU 12 starts the lock / unlock process based on the detection signal from the operation switch 11. The in-vehicle ECU 12 determines whether it is a lock request or an unlock request based on the current locking status.
[0018] The in-vehicle ECU 12 is primarily composed of a microcomputer. The in-vehicle ECU 12 includes, for example, a CPU (Central Processing Unit), ROM (Read Only Memory), RAM (Random Access Memory), and an input / output interface. The in-vehicle ECU 12 performs various controls of the vehicle 1, for example, by loading a program stored in ROM into RAM and executing the program with the CPU. The in-vehicle ECU 12 may be composed of multiple in-vehicle ECUs that can communicate via CAN (Controller Area Network).
[0019] The output device 13 outputs various information in response to control command signals from the in-vehicle ECU. Examples of the output device 13 include speakers, displays, lights, and projectors. The output device 13 is installed in the vehicle 1 so that a user outside the vehicle can recognize the sound, display, or illumination output from the output device 13. For example, the output device 13 outputs voice guidance, display guidance, or illumination guidance to guide the user to the location of the biometric information sensor 14 in order to authenticate the user using the vehicle 1.
[0020] The biometric information sensor 14 outputs a detection signal regarding the user's biometric information. Examples of the biometric information sensor 14 include an outside vehicle camera, a microphone, and the like. The detection signal of the biometric information sensor 14 is input to the in-vehicle ECU 12. Note that the in-vehicle ECU 12 may start the locking / unlocking process based on the detection signal of the biometric information sensor 14. For example, the in-vehicle ECU 12 detects a locking / unlocking request gesture of the user captured by the outside vehicle camera or a locking / unlocking request voice of the user captured by the microphone, and starts the locking / unlocking process.
[0021] The in-vehicle transceiver 15 transmits and receives various information between the vehicle 1 and the administrator terminal 2 through a predetermined communication line, either via the information processing center 3 or without passing through it. Examples of the in-vehicle transceiver 15 include a DCM (Data Communication Module), a Wi-Fi (registered trademark) communication module, and the like. Examples of the predetermined communication line include a mobile communication network, the Internet, a satellite communication network, a wired LAN (Local Area Network), a wireless LAN, and a one-to-one communication line.
[0022] The in-vehicle transceiver 15 encrypts and transmits various information by a predetermined encryption method and decrypts and receives various information encrypted by a predetermined encryption method. As the encryption method, a symmetric key encryption method, a public key encryption method, a hybrid encryption method combining these, and the like are used.
[0023] The in-vehicle ECU 12 causes the in-vehicle transceiver 15 to transmit to the administrator terminal 2 the user's biometric information detected by the biometric information sensor 14 and the locking / unlocking request of the vehicle 1. The in-vehicle ECU 12 detects the reception of either a locking / unlocking permission response or a locking / unlocking non-permission response input to the administrator terminal 2 based on the user's biometric information.
[0024] The terminal transceiver 21 transmits and receives various information between the administrator terminal 2 and the vehicle 1 via a predetermined communication line, with or without going through the information processing center 3. Examples of the terminal transceiver 21 include a mobile communication module, a Wi-Fi® communication module, and a wired LAN communication module.
[0025] The terminal transceiver 21 encrypts and transmits various types of information using a predetermined encryption method, and also decrypts and receives the encrypted information using a predetermined encryption method. Encryption methods include symmetric-key cryptography, public-key cryptography, and hybrid encryption methods that combine these.
[0026] The terminal ECU 22 detects the lock / unlock request of vehicle 1 received by the terminal transceiver 21. The terminal ECU 22 determines whether the lock / unlock request of vehicle 1 is a lock request or an unlock request. The terminal ECU 22 outputs the type of lock / unlock request, the user's biometric information, and the options of allowing or denying lock / unlock to the input / output device 23.
[0027] The terminal ECU 22 is mainly composed of a microcomputer, but may also be mainly composed of a PC. The terminal ECU 12 includes, for example, a CPU, ROM, RAM, non-volatile memory such as flash memory, and an input / output interface. The terminal ECU 22 performs various controls on the administrator terminal 2 by, for example, loading a program stored in the non-volatile memory into RAM and executing the program with the CPU.
[0028] The input / output device 23 outputs various information in response to control command signals from the terminal ECU 22, and also inputs various information. Examples of the input / output device 23 include a combination of a touch panel display, a display, a mouse, a keyboard, a speaker, a microphone, and a voice recognition device. The administrator of vehicle 1 determines whether to permit or deny locking / unlocking based on the user's biometric information, and inputs either a locking / unlocking permission response or a locking / unlocking denial response to the input / output device 23. The terminal ECU 22 causes the terminal transceiver 21 to transmit either the locking / unlocking permission response or the locking / unlocking denial response input to the input / output device 23 to vehicle 1.
[0029] The on-board ECU 12 detects the reception of either a lock / unlock permission response or a lock / unlock denial response. If the on-board ECU 12 detects the reception of a lock / unlock permission response, it causes the door lock actuator 16 to perform the lock / unlock operation of vehicle 1. On the other hand, if the on-board ECU 12 detects the reception of a lock / unlock denial response, it terminates the lock / unlock process.
[0030] The door lock actuator 16 may be, for example, an electric motor that operates the door lock link that locks and unlocks the doors of the vehicle 1. The doors of the vehicle 1 include at least one of the following: front doors, rear doors, and back doors (trunk).
[0031] Furthermore, if the administrator terminal 2 constantly accepts lock / unlock requests, the number of notifications will increase, which may be bothersome for the administrator of vehicle 1. Therefore, it is preferable for the terminal ECU 22 to output an option to the input / output device 23 to select a lock / unlock permission mode (especially a lock permission mode) that always allows lock / unlock requests (especially lock requests). If the administrator of vehicle 1 selects the lock / unlock permission mode, the terminal ECU 22 causes vehicle 1 to send a lock / unlock permission mode request to the terminal transceiver 21.
[0032] When the in-vehicle ECU 12 detects a lock / unlock permission mode request (especially a lock permission mode request), it automatically locks and unlocks (especially performs automatic locking) for subsequent lock / unlock requests (especially locking requests) without detecting the user's biometric information (i.e., without performing user authentication). It is preferable that the automatic locking can be set with a timer. After performing automatic locking and unlocking, it is preferable that the in-vehicle ECU 12 sends a lock / unlock completion notification (especially a lock completion notification) to the in-vehicle transceiver 15 at the administrator terminal 2.
[0033] (Example of lock / unlock system operation) Figure 2 is a flowchart showing the processing procedure of a control device according to one embodiment. The vehicle-side flowchart shown in Figure 2 is implemented, for example, by a program executed by the microcomputer of the on-board ECU 12. The administrator terminal-side flowchart shown in Figure 2 is implemented, for example, by a program executed by the microcomputer of the terminal ECU 22.
[0034] (Example of processing procedure on the vehicle side) First, we will explain an example of the locking and unlocking procedure for vehicle 1.
[0035] <Step S10> The in-vehicle ECU 12 detects a lock / unlock request for vehicle 1 based on the detection signal from the operation switch 11. Examples of lock / unlock requests for vehicle 1 include the user touching the door handle, the user pressing the lock / unlock button, and the user pressing the remote control key button. If the in-vehicle ECU 12 does not detect a lock / unlock request for vehicle 1 (no operation in step S10), it terminates the lock / unlock process, but may return to step S10 and repeat the detection of lock / unlock requests for vehicle 1.
[0036] The in-vehicle ECU 12 may also detect a lock / unlock request based on the detection signal from the biometric information sensor 14. For example, the in-vehicle ECU 12 may detect a user's lock / unlock request gesture captured by an external camera, or detect a user's lock / unlock request voice captured by a microphone, and then start the lock / unlock process.
[0037] <Step S11> When the on-board ECU 12 detects a lock / unlock request from vehicle 1 (after the operation in step S10), it determines whether it is a lock request or an unlock request based on the current locking state. The on-board ECU 12 determines it is a lock request if the current locking state is unlocked, and determines it is an unlock request if the current locking state is locked.
[0038] <Step S12> Next, the in-vehicle ECU 12 outputs voice guidance to a speaker, which is an example of an output device 13, to perform user authentication. For example, voice guidance could include guiding the user to the field of view of an external camera, which is an example of a biometric sensor 14, and guidance on the timing of the photo shoot.
[0039] <Step S13> The in-vehicle ECU 12 then, for example, instructs an external camera, which is an example of a biometric information sensor 14, to capture an image of the user's face.
[0040] <Step S14> The in-vehicle ECU 12 causes the in-vehicle transceiver 15 to send to the administrator terminal 2 an image of the user's face, which is an example of the user's biometric information, and a lock / unlock request. The lock / unlock request includes either a lock request or an unlock request.
[0041] <Step S15> Next, the on-board ECU 12 detects the reception of either a lock / unlock permission response or a lock / unlock denial response. If the on-board ECU 12 detects the reception of a lock / unlock denial response (denial response in step S15), it terminates the lock / unlock process.
[0042] <Step S16> If the onboard ECU 12 detects the receipt of a lock / unlock permission response (permission response in step S15), it causes an electric motor, which is an example of a door lock actuator 16, to perform the lock / unlock operation of the vehicle 1.
[0043] (Example of processing procedure on the administrator's terminal) Next, we will describe an example of the user authentication process procedure on administrator terminal 2.
[0044] <Step S20> Terminal ECU22 detects the receipt of a lock / unlock request for vehicle 1. If terminal ECU22 does not detect the receipt of a lock / unlock request for vehicle 1 (no request in step S20), it terminates the user authentication process, but may return to step S20 and repeat the detection of the lock / unlock request.
[0045] <Step S21> When the terminal ECU 22 detects the receipt of a lock / unlock request for vehicle 1 (if the request in step S20 is made), it determines whether the lock / unlock request for vehicle 1 is a lock request or an unlock request. The terminal ECU 22 displays the type of lock / unlock request, the user's facial image, and an example of an operation button for allowing or denying lock / unlock on the touch panel display, which is an example of an input / output device 23.
[0046] The administrator of vehicle 1 determines whether to permit or deny locking / unlocking based on the user's facial image displayed on the touch panel display, and then presses one of the operation buttons displayed on the touch panel display, either permitting or denying locking / unlocking.
[0047] <Step S22> The terminal ECU22 detects when either the lock / unlock permission or lock / unlock denial operation button is pressed. If the terminal ECU22 does not detect when either the lock / unlock permission or lock / unlock denial operation button is pressed (no operation in step S22 (timeout)), it terminates the user authentication process, but it may return to step S22 and repeat the detection of operation button presses.
[0048] <Step S23> When the terminal ECU 22 detects that the lock / unlock permission operation button has been pressed (the permission button is pressed in step S22), it causes the terminal transceiver 21 to send a lock / unlock permission response to the vehicle 1. Then, in step S15, when the in-vehicle ECU 12 detects that it has received the lock / unlock permission response, it causes the door lock actuator 16 to perform the lock / unlock operation of the vehicle 1.
[0049] <Step S24> Meanwhile, if the terminal ECU 22 detects that the lock / unlock permission operation button has been pressed (press of the permission button in step S22), it causes the terminal transceiver 21 to send a lock / unlock permission response to the vehicle 1. Then, in step S15, if the in-vehicle ECU 12 detects that it has received the lock / unlock permission response, it terminates the lock / unlock process.
[0050] Furthermore, if the administrator terminal 2 constantly accepts lock / unlock requests, the number of notifications will increase, which may be bothersome for the administrator of vehicle 1. Therefore, it is preferable that the terminal ECU 22 displays a selection button on the touch panel display in step S21 for selecting the lock / unlock permission mode (especially the lock permission mode). When the administrator of vehicle 1 selects the lock / unlock permission mode, the terminal ECU 22 causes vehicle 1 to send a lock / unlock permission mode request to the terminal transceiver 21.
[0051] When the in-vehicle ECU 12 detects the receipt of a lock / unlock permission mode request (especially a lock permission mode request), it automatically locks and unlocks (especially performs automatic locking) subsequent lock / unlock requests (especially locking requests) without detecting the user's biometric information (i.e., without performing user authentication). After performing automatic lock / unlocking, the in-vehicle ECU 12 causes the in-vehicle transceiver 15 to send a lock / unlock completion notification (especially a lock completion notification) to the administrator terminal 2.
[0052] (Effects and Benefits) As a result, users of Vehicle 1 can request to lock or unlock Vehicle 1 without carrying a mobile device. Furthermore, since there is no need to register the user's biometric information, it can flexibly accommodate users such as delivery companies that temporarily use the vehicle as a delivery box. In addition, since the biometric information of the administrator of Vehicle 1 is not transmitted or received, the administrator does not have any security concerns. Ultimately, this achieves both convenience and security in the vehicle locking and unlocking system.
[0053] The various functional units shown in the above embodiments can be realized by one or more processing circuits. Examples of processing circuits include ASICs (Application Specific Integrated Circuits) or FPGAs (Field Programmable Gate Arrays) designed to perform various functions.
[0054] The program may also be provided in a form recorded on a non-transitory recording medium such as a CD-ROM (Compact Disk Read Only Memory). Furthermore, the program may be provided in a form that can be downloaded from an external device such as a server via a network.
[0055] In the embodiments described above, when the number, quantity, units, and range of each element are mentioned, they are not limited to those mentioned unless specifically stated or determined in principle. Furthermore, the structures described in the embodiments are not necessarily essential unless specifically stated or determined in principle. [Explanation of Symbols]
[0056] 1 vehicle 11. Operation switches 12 Automotive ECU 14. Biometric Information Sensors 15. Vehicle-mounted transceiver 16 Door lock actuator 2 Administrator terminal
Claims
[Claim 1] When a locking / unlocking request from a vehicle user is detected, the system causes the in-vehicle transceiver to transmit the user's biometric information detected by the biometric information sensor and the locking / unlocking request to an administrator terminal managed by the vehicle administrator. The locking / unlocking permission mode is a mode that always permits the locking / unlocking request. When the system detects the reception of the locking / unlocking permission mode input to the administrator terminal based on the biometric information, it causes the door lock actuator to perform the locking / unlocking operation of the vehicle. For subsequent locking / unlocking requests, the system causes the door lock actuator to perform the locking / unlocking operation of the vehicle without detecting the user's biometric information, and sends a locking / unlocking completion notification to the in-vehicle transceiver. Vehicle control system.
Citation Information
Patent Citations
Locking / unlocking right granting system, authentication device, mobile terminal, and program
JP2014145200A