Vehicle management system, vehicle management method, and vehicle management program
The vehicle management system addresses the issue of delayed immobilizer deactivation by using key information from a user terminal to remotely activate the vehicle's driving system, ensuring efficient operation transfer without user presence.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- TOYOTA JIDOSHA KK
- Filing Date
- 2024-11-15
- Publication Date
- 2026-05-27
AI Technical Summary
When a user entrusts vehicle operation rights to a management system in a predetermined area, the immobilizer cannot be deactivated promptly if the user leaves the vehicle before the management system completes the necessary processes, requiring the user to wait near the vehicle.
A vehicle management system that includes processors and storage devices to acquire and store key information from a user terminal, which includes an authentication code to release the immobilizer's restriction on the vehicle's driving system, allowing the management system to activate the driving system remotely.
Enables the vehicle's driving system to be activated without the user needing to wait near the vehicle after the handover process is complete, facilitating seamless operation transfer.
Smart Images

Figure 2026087096000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a technique for controlling a vehicle that operates according to a remote instruction in a predetermined area.
Background Art
[0002] Patent Document 1 discloses a vehicle monitoring device that monitors a vehicle within a vehicle parking position. The vehicle monitoring device switches between a vehicle position notification mode and an anti-theft mode in response to a mode switching instruction.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] When a user entrusts the operation authority of a vehicle to a management system in a predetermined area (e.g., a parking lot), the user operates a user terminal to send a handover start request to the management system. After that, the user can leave the vehicle. On the other hand, the management system needs to complete predetermined processes such as processing for identifying (recognizing) the vehicle to be remotely operated between starting the handover process according to the handover start request and sending a start request for the vehicle's driving system to the vehicle. If the execution of the predetermined process takes time and the user having the vehicle key leaves the vehicle before sending the start request for the driving system, the management system cannot cause the vehicle to release the immobilizer necessary for starting the driving system.
[0005] This disclosure has been made in view of the above-mentioned issues and aims to provide a technology that enables the immobilizer to be deactivated without requiring the user to wait near the vehicle when the user entrusts vehicle operation rights to the management system in a designated area. [Means for solving the problem]
[0006] The vehicle management system described herein manages vehicles in a predetermined area. The vehicle management system comprises one or more processors and one or more storage devices. One or more processors initiate a handover process to transfer vehicle operation rights from the user to the vehicle management system in response to a handover start request from a user terminal that stores key information for functioning as a digital key for the vehicle. When a handover start request is issued, the processors acquire the key information from the user terminal and store it in one or more storage devices. The key information includes an authentication code for releasing the vehicle's immobilizer's restriction on starting the vehicle's driving system. When starting the driving system, one or more processors transmit the authentication code to the vehicle's control device along with the driving system start request, causing the control device to release the start restriction.
[0007] The vehicle management method relating to this disclosure is a method for managing a vehicle in a predetermined area, and is performed by a computer. The vehicle management method includes: initiating a handover process to transfer vehicle operation rights from a user to a vehicle management system in response to a handover start request from a user terminal storing key information for functioning as a digital key for the vehicle; and, when a handover start request is issued, obtaining the key information from the user terminal and storing it in one or more storage devices of the vehicle management system. The key information includes an authentication code for releasing the vehicle's immobilizer's restriction on starting the vehicle's driving system. The vehicle management method further includes, when starting the driving system, transmitting the authentication code to the vehicle's control device along with the driving system start request, causing the control device to release the start restriction.
[0008] The vehicle management program relating to this disclosure is a program for managing a vehicle in a predetermined area and is executed by a computer. The vehicle management program causes the computer to perform the following actions in response to a handover start request from a user terminal that stores key information for functioning as a digital key for the vehicle: to start a handover process that transfers the operation rights of the vehicle from the user to the vehicle management system; and, when a handover start request is issued, to obtain the key information from the user terminal and store it in one or more storage devices of the vehicle management system. The key information includes an authentication code for releasing the vehicle's immobilizer's restriction on starting the vehicle's driving system. When starting the driving system, the vehicle management program further causes the computer to send the authentication code to the vehicle's control device along with the driving system start request, and to have the control device release the start restriction. [Effects of the Invention]
[0009] According to this disclosure, when activating the vehicle's driving system, the vehicle management system transmits an authentication code included in the key information obtained from the user terminal when a handover start request is issued to the vehicle's control unit along with the driving system activation request, causing the control unit to release the immobilizer's restriction on driving system activation. This allows the vehicle management system to activate the driving system without requiring the user to wait near the vehicle after the handover process is complete. [Brief explanation of the drawing]
[0010] [Figure 1] This is a conceptual diagram illustrating the overview of a vehicle control system according to an embodiment. [Figure 2] Figure 1 is a block diagram showing an example configuration of a vehicle management system. [Figure 3] This block diagram shows an example of the vehicle system configuration shown in Figure 1. [Figure 4]This flowchart shows an example of the processing flow executed by the vehicle management system in relation to "deactivating the immobilizer using borrowed key information from a user terminal" according to the embodiment. [Figure 5] This flowchart shows an example of the processing flow executed by the vehicle's control unit when it receives key information from the vehicle management system. [Figure 6] This flowchart shows another example of the processing flow executed by the vehicle management system in relation to "deactivating the immobilizer using key information borrowed from a user terminal" according to the embodiment. [Figure 7] This figure shows a first example of the acquisition path and storage location of key information. [Figure 8] This figure shows a second example of the acquisition path and storage location of key information. [Figure 9] This figure shows a third example of the acquisition path and storage location of key information. [Modes for carrying out the invention]
[0011] Embodiments of this disclosure will be described with reference to the attached drawings.
[0012] 1. Overview of the Vehicle Control System Figure 1 is a conceptual diagram illustrating the overview of the vehicle control system 100 according to this embodiment. The vehicle control system 100 controls vehicle 1. Vehicle 1 is configured to operate in a predetermined area according to remote instruction INS. The predetermined area is, for example, an area in which vehicle 1 can perform automatic driving, and vehicle 1 performs automatic driving in the predetermined area according to remote instruction INS. The vehicle control system 100 includes a vehicle management system 10 (hereinafter also simply referred to as the management system 10) and a vehicle system 20 mounted on vehicle 1. The management system 10 manages vehicle 1 in the predetermined area. The management of vehicle 1 by the management system 10 includes generating remote instruction INS. More specifically, the management system 10 manages the automatic driving (unmanned driving) of vehicle 1 within the predetermined area.
[0013] 1-1. Automatic Valet Parking (AVP) In the example shown in FIG. 1, the predetermined area is the parking lot 2. In this example, the vehicle control system 100 corresponds to an automatic valet parking system that performs AVP of the vehicle 1 in the parking lot 2. However, the predetermined area is not limited to the parking lot 2, and may be, for example, one city or a part thereof such as a smart city. The following description is given taking the parking lot 2 as an example of the predetermined area.
[0014] The vehicle 1 is configured to be able to execute AVP in the parking lot 2. The vehicle 1 can automatically travel at least within the parking lot 2 without being dependent on the driving operation by the user. More specifically, the automatic driving of the vehicle 1 within the parking lot 2 is controlled by, for example, the management system 10 that utilizes the infrared sensor 13. Alternatively, the automatic driving may be controlled by, for example, the cooperation between the management system 10 and the vehicle system 20. Note that the vehicle 1 may be an autonomous vehicle that can also automatically travel outside the parking lot 2.
[0015] The parking lot 2 includes a drop-off area 3, a pick-up area 4, and a parking area 5. The vehicle 1 entering the parking lot 2 stops at the stop position (drop-off frame) 6 provided in the drop-off area 3, where the user gets off the vehicle 1. On the other hand, the vehicle 1 exiting the parking lot 2 stops at the pick-up area 4, where the user boards the vehicle 1. The drop-off area 3 can also be called the inbound area, and the pick-up area 4 can also be called the outbound area. The drop-off area 3 and the pick-up area 4 may be provided separately as shown in FIG. 1, or may be provided as a boarding and alighting area without distinction between boarding and alighting. The parking area 5 includes a passage 7 and a plurality of parking frames 8. The passage 7 is the area where the vehicle 1 travels. The parking frame 8 is the space where the vehicle 1 parks. [[ID=,12]]
[0016] The management system 10 manages the AVP of the vehicle 1 in the parking lot 2. The management system 10 includes, as an example, a local management device 11 and a management server 12 on the cloud.
[0017] The local management device 11 is installed for each parking lot 2. The local management device 11 executes the following processes, for example. That is, the local management device 11 uses the infrared sensor 13 to grasp the situation of the parking lot 2 (e.g., the position and state of each vehicle 1 in the parking lot 2). The local management device 11 assigns a parking space 8 to the vehicle 1. The local management device 11 generates a remote instruction INS, communicates with the vehicle 1, and transmits the generated remote instruction INS to the vehicle 1.
[0018] The management server 12 supervises the local management devices 11 of a plurality of parking lots 2. The management server 12 may include, as an example, three servers OB, VB, and UB. The server OB is provided for each parking lot 2. The server OB manages the parking lot 2 (e.g., reservation of the parking space 8, entry and exit of the vehicle 1), and the driving control authority of the vehicle 1. Further, the server OB communicates with the corresponding local management device 11, and collects and provides various information. The server VB manages the remote operation authority of the vehicle 1 (e.g., power operation authority). Further, the server VB communicates with the vehicle 1, and collects various vehicle management information (e.g., information indicating the state of the vehicle 1, identification information (vehicle ID) of the vehicle 1) and provides various information (e.g., progress status of AVP). The server UB manages the users of the automated valet parking service (AVP service) (including user authentication), and reservation management of the AVP service by the users. The server UB communicates with the user terminal 30 operated by the user of the AVP service. The user terminal 30 is, for example, a terminal (e.g., a smartphone) possessed by the user. The membership information of the user is registered in the server UB in advance. Further, the server UB communicates with each of the server OB and the server VB, and transmits and receives various information between each of the server OB and the server VB.
[0019] Hereinafter, an example of the process when a certain user X uses the AVP service will be described.
[0020] First, user X makes a reservation for AVP. For example, user X operates user terminal 30 and inputs information such as user X's ID information, desired parking lot 2, desired date of use, and desired time of use. User terminal 30 sends the reservation information, including the entered information, to management system 10 (server UB). Management system 10 processes the reservation based on the reservation information and sends a reservation completion notification to user terminal 30. Management system 10 also sends authentication information corresponding to the reservation information to user terminal 30. User terminal 30 receives and retains the received authentication information.
[0021] The entry (check-in) of vehicle 1 into parking lot 2 is as follows: As illustrated in Figure 1, vehicle 1, carrying user X, arrives at drop-off area 3 in parking lot 2 and stops at stopping position 6. In drop-off area 3, user X (and any other passengers, if any) disembarks from vehicle 1.
[0022] In order to initiate the automated driving of vehicle 1 based on remote instructions from management system 10 in AVP (hereinafter simply referred to as "AVP driving"), it is necessary to transfer the control authority of vehicle 1 from user X to management system 10. To transfer this control authority, user X operates user terminal 30 to send a handover start request to management system 10 (server UB). More specifically, it is assumed that after vehicle 1 arrives at disembarking area 3, user X will basically disembark from vehicle 1 and then make the handover start request. However, the handover start request may be made by user X before disembarking from vehicle 1. The handover start request is sent, for example, along with user X's authentication information.
[0023] In response to a handover start request sent from user terminal 30, the management system 10 (server UB) authenticates user X. Once authentication is complete, the management system 10 (local management device 11) starts a handover process (authorization transfer process) to transfer the operating authority of vehicle 1 from user X to the management system 10.
[0024] The handover process includes, for example, a process for establishing wireless communication between the management system 10 and vehicle 1 (vehicle system 20), and a process for identifying vehicle 1 as the target vehicle for this AVP (vehicle identification process). Target vehicle identification (authentication) is necessary to confirm that vehicle 1, which is seeking to receive the AVP service, is the legitimate user X's vehicle 1 (target vehicle). The vehicle identification process may, for example, be performed using a predetermined action of vehicle 1 (e.g., blinking of vehicle 1's lights). If vehicle 1 is a legitimate target vehicle, it is expected that the vehicle will perform the predetermined action in accordance with instructions from the management system 10. After such instructions are given, the management system 10 uses the infrastructure sensor 13 to recognize the action performed by vehicle 1. If the recognized action matches the expected action, the management system 10 identifies vehicle 1, which performed the recognized action, as the target vehicle.
[0025] Once the handover process is complete, the control authority for vehicle 1 is transferred from user X to the management system 10. The management system 10 (local management device 11) performs parking processing for vehicle 1. During parking processing, the management system 10 communicates with vehicle 1 and sends a remote instruction INS (start request) requesting the vehicle 1's driving system 23 to be activated (powered on). Provided that the immobilizer, as described later, can be deactivated, vehicle 1 automatically activates the driving system 23 according to the received remote instruction INS. The management system 10 also refers to the usage status of parking lot 2, assigns an available parking space 8 to vehicle 1, and then generates a target route for vehicle 1 from the drop-off area 3 to the assigned parking space 8. The management system 10 then communicates with vehicle 1 and sends a remote instruction INS to vehicle 1, along with the target route information, requesting that the vehicle perform AVP driving towards parking space 8 along the generated target route.
[0026] Vehicle 1 performs AVP driving towards its assigned parking space 8 according to the target route received from the management system 10, and automatically parks in the assigned parking space 8 (parking complete). Once parking is complete, vehicle 1 notifies the management system 10 of the completion of parking. Alternatively, the management system 10 may detect that vehicle 1 has completed parking using the infrastructure sensor 13 installed in the parking lot 2. After vehicle 1 has completed parking, the management system 10 (local management device 11) communicates with vehicle 1 and sends a remote instruction INS requesting the power off of the driving system 23. Vehicle 1 automatically turns off its power according to the received remote instruction INS. The management system 10 (server OB) also maintains information about the parking space 8 where vehicle 1 is parked, associating it with user X. The management system 10 (local management device 11) may cause vehicle 1 to perform AVP driving to move vehicle 1 to another parking space 8 while it is parked.
[0027] The process for vehicle 1 to leave parking lot 2 (checkout) is as follows: User X operates user terminal 30 to send a checkout request to management system 10 (server UB) to request the vehicle 1 to leave the parking lot. The checkout request includes user X's authentication information. In response to the checkout request, management system 10 (server UB) authenticates user X. Once authentication is complete, management system 10 (local management device 11) performs the checkout process for vehicle 1.
[0028] During the vehicle departure process, the management system 10 communicates with vehicle 1 and executes a remote instruction INS (start request) requesting vehicle 1 to activate (power on) its driving system 23. Provided that the immobilizer can be deactivated, vehicle 1 automatically activates its driving system 23 according to the received remote instruction INS. The management system 10 also refers to the usage status of parking lot 2 and assigns vehicle 1 an available passenger space 9 in passenger area 4, and then generates a target route for vehicle 1 from its parking space 8 to the assigned passenger space 9. The management system 10 then communicates with vehicle 1 and sends a remote instruction INS to vehicle 1, along with the target route information, requesting that it perform an AVP drive towards passenger space 9 along the generated target route.
[0029] Vehicle 1 travels according to the received target route towards its assigned passenger slot 9 using the AVP system. When Vehicle 1 arrives at the passenger area 4 and automatically stops at its assigned passenger slot 9, Vehicle 1 notifies the management system 10 of its arrival at the passenger area 4. Alternatively, the management system 10 may detect the arrival of Vehicle 1 using the infrastructure sensor 13 installed in the passenger area 4.
[0030] After vehicle 1 arrives at boarding area 4, user X sends a handback start request to management system 10 (server UB) to transfer (return) control of vehicle 1 from management system 10 to user X. In response to the handback start request sent from user terminal 30, management system 10 (server UB) authenticates user X. Once authentication is complete, management system 10 (local management device 11) starts the handback process. When the handback process is complete, user X (and any other passengers) board vehicle 1. Vehicle 1 departs for its next destination and exits parking lot 2 (exit complete).
[0031] 2. Example System Configuration As described above, the vehicle control system 100 includes the vehicle management system 10 and the vehicle system 20.
[0032] 2-1. Vehicle Management System Figure 2 is a block diagram showing an example configuration of the vehicle management system 10 shown in Figure 1. The management system 10 includes a local management device 11, a management server 12 on the cloud, and one or more infrastructure sensors 13 (hereinafter simply referred to as infrastructure sensors 13). The infrastructure sensors 13 are installed in various locations in the parking lot 2, as shown in Figure 1. The infrastructure sensors 13 include, for example, infrastructure cameras and recognize the conditions of the parking lot 2, including the drop-off area 3 and the pick-up area 4. The information acquired by the infrastructure sensors 13 is transmitted to the local management device 11.
[0033] The local management device 11 includes a communication interface (communication I / F) 111, one or more processors 112 (hereinafter simply referred to as processor 112), and one or more storage devices 113 (hereinafter simply referred to as storage devices 113). One or more processors 112 corresponds to an example of "one or more first processors" as described in this disclosure.
[0034] The communication interface 111 communicates with the vehicle 1 (vehicle system 20), the management server 12 (server OB), and the infrastructure sensor 13 via a communication network. The communication interface 111 may also communicate directly with the user terminal 30 (e.g., via Wi-Fi®). Furthermore, the user terminal 30 functions as a key (i.e., digital key) 31 for the vehicle 1, as described later. The communication interface 111 may be configured to communicate with the user terminal 30 (digital key 31) according to the same communication method as the communication Ckey between the digital key 31 and the vehicle 1, as described later.
[0035] The processor 112 performs various processes. Examples of the processor 112 include general-purpose processors, application-specific processors, CPUs (Central Processing Units), GPUs (Graphics Processing Units), ASICs (Application Specific Integrated Circuits), FPGAs (Field-Programmable Gate Arrays), integrated circuits, conventional circuits, and / or combinations thereof. The processor 112 can also be called circuitry or processing circuitry. Circuitry is hardware programmed to realize the described functions, or hardware that performs those functions. The storage device 113 stores various information. Examples of storage devices 113 include volatile memory, non-volatile memory, HDDs (Hard Disk Drives), SSDs (Solid State Drives), etc.
[0036] The functions of the local management device 11 may be realized through the cooperation of a processor 112 that executes a computer program (corresponding to the "vehicle management program" as described herein) and a storage device 113. The computer program is stored in the storage device 113. Alternatively, the computer program may be recorded on a computer-readable recording medium or provided via a network.
[0037] The management server 12 (more specifically, each of the three servers OB, VB, and UB) includes a communication interface 121, one or more processors 122 (hereinafter simply referred to as processor 122), and one or more storage devices 123 (hereinafter simply referred to as storage devices 123).
[0038] The communication interface 121 communicates with the local management device 11, the vehicle 1 (vehicle system 20), and the user terminal 30 via the communication network.
[0039] The configuration example of processor 122 is the same as that of processor 112 described above. Similarly, the configuration example of storage device 123 is the same as that of storage device 113 described above. For example, the storage device 123 of server OB stores information for a predetermined area (e.g., parking lot 2) (e.g., map information for parking lot 2, entry and exit time information for parking lot 2). The storage device 123 of server VB stores the vehicle management information described above. The storage device 123 of server UB stores user information (e.g., identification information for each user (user ID), service reservation information). The functions of the management server 12 (e.g., servers OB, VB, and UB, respectively) may be realized through the cooperation of the processor 122, which executes a computer program (corresponding to the "vehicle management program" described herein), and the storage device 123. The computer program is stored in the storage device 123. Alternatively, the computer program may be recorded on a computer-readable recording medium or provided via a network.
[0040] 2-2. Vehicle System Figure 3 is a block diagram showing an example configuration of the vehicle system 20 shown in Figure 1. The vehicle system 20 is mounted on the vehicle 1 and includes a control device 21, sensors 22, and a driving system 23.
[0041] The control device 21 controls the vehicle 1 according to various remote instruction INS. The control device 21 includes a communication I / F 211, one or more processors 212 (hereinafter simply referred to as processor 212), and one or more storage devices 213 (hereinafter simply referred to as storage devices 213).
[0042] The communication interface 211 communicates with the management system 10 (more specifically, the local management device 11 and the management server 12 (server VB)) via a communication network. The communication interface 211 also communicates with the digital key 31 of the vehicle 1 (more specifically, the user terminal 30 that functions as the digital key 31) using the Ckey communication described below. Furthermore, the communication interface 211 may communicate directly with the user terminal 30 (e.g., via WiFi).
[0043] The configuration example of processor 212 is the same as that of processor 112 described above. Similarly, the configuration example of storage device 213 is the same as that of storage device 113 described above. The functions of the control device 21 may be realized through the cooperation of processor 212, which executes the computer program, and storage device 213. The computer program is stored in storage device 213. Alternatively, the computer program may be recorded on a computer-readable recording medium or provided via a network.
[0044] The vehicle system 20 functions as an immobilizer to prevent unauthorized activation of the driving system 23. For example, the control device 21 has this function. Specifically, the user terminal 30 (e.g., a smartphone) held by user X stores key information Ikey for functioning as a digital key 31 for vehicle 1. The user terminal 30 is configured to be usable by user X as a digital key 31 in place of a physical key, without requiring a physical key. More specifically, the user terminal 30 is configured to function as a transponder for the digital key 31. That is, the user terminal 30 communicates Ckey with vehicle 1 (control device 21) as a transponder. The key information Ikey stored in the user terminal 30 includes an authentication code AC unique to the digital key 31. This authentication code AC is also stored in the storage device 213 of the control device 21. The communication Ckey between the vehicle system 20 (control device 21) and the digital key 31 is via short-range wireless communication (e.g., UWB (Ultra Wideband), Bluetooth (registered trademark), NFC (Near Field Communication)).
[0045] When the driving system 23 is started, if an authentication code AC is received from the digital key 31, the control device 21 (processor 212) compares the received authentication code AC from the digital key 31 with the authentication code AC stored in the storage device 213. If these authentication codes AC match, the control device 21 permits the starting of the driving system 23. In other words, the control device 21 releases the immobilizer's restriction on starting the driving system 23.
[0046] The sensors 22 include recognition sensors, vehicle status sensors, position sensors, etc. Recognition sensors recognize (detect) the surrounding conditions of vehicle 1. Examples of recognition sensors include cameras, LIDAR (Laser Imaging Detection and Ranging), radar, etc. Vehicle status sensors detect the state of vehicle 1. Examples of vehicle status sensors include speed sensors, acceleration sensors, yaw rate sensors, steering angle sensors, etc. Position sensors detect the position and orientation of vehicle 1. An example of a position sensor is a GNSS (Global Navigation Satellite System) sensor.
[0047] The driving system 23 is a system for operating the vehicle 1. The driving system 23 is, for example, an electric drive system and includes an electric motor for driving the vehicle 1, a battery for supplying power to the electric motor, and a controller. The driving system 23 may include an internal combustion engine together with, or instead of, the electric motor for driving the vehicle 1.
[0048] 3. Disabling the immobilizer by borrowing key information from the user's terminal. When user X entrusts the management system 10 with the operation rights of vehicle 1 in a designated area (e.g., parking lot 2), user X operates the user terminal 30 as described above to send a handover start request to the management system 10. After that, user X can leave vehicle 1. On the other hand, the management system 10 needs to complete predetermined processes such as vehicle identification processing between the time it starts the handover process in accordance with the handover start request and the time it sends a request to vehicle 1 to start the vehicle's driving system 23. If the execution of these predetermined processes takes time and user X, who has the vehicle's digital key 31 (user terminal 30), leaves vehicle 1 before the request to start the driving system 23 is sent, the management system 10 will not be able to have vehicle 1 perform the authentication code AC verification with the digital key 31. In other words, the management system 10 will not be able to have vehicle 1 perform the immobilizer deactivation necessary to start the driving system 23.
[0049] Therefore, in this embodiment, when user X entrusts the operation authority of vehicle 1 to the management system 10 in a predetermined area (e.g., when vehicle 1 is parked in a predetermined area such as parking lot 2), the management system 10 obtains key information Ikey from the user terminal 30 as a digital key 31 and stores it in the storage device 123 or 113 when a handover start request is issued from the user terminal 30. In other words, the user terminal 30 lends the key information Ikey to the management system 10. As described above, the key information Ikey includes an authentication code AC for releasing the immobilizer's restriction on starting the driving system 23 of vehicle 1.
[0050] Then, when starting the driving system 23, the management system 10 sends an authentication code AC to the control device 21 of the vehicle 1 along with a request to start the driving system 23, causing the control device 21 to release the restriction on starting the driving system 23 (i.e., deactivate the immobilizer). More specifically, in this embodiment, a local management device 11 installed in a predetermined area (e.g., parking lot 2) (i.e., located near the vehicle 1) executes the process of causing the control device 21 to deactivate the immobilizer.
[0051] 3-1. Processing Flow Figure 4 is a flowchart showing an example of the processing flow executed by the vehicle management system 10 (mainly the local management device 11) in relation to "deactivating the immobilizer using borrowed key information Ikey from the user terminal 30" according to this embodiment. The processing in this flowchart starts, for example, when vehicle 1 arrives at the drop-off area 3. Figure 5 is a flowchart showing an example of the processing flow executed by the control device 21 when it receives key information Ikey from the vehicle management system 10.
[0052] In Figure 4, in step S100, the local management device 11 communicates with server UB via server OB and determines whether or not it has received a handover start request from user terminal 30. If a handover start request is received (step S100; Yes), the process proceeds to step S102.
[0053] In step S102, the local management device 11 starts the handover process described above. Then, in step S104, in conjunction with the handover start request, the management system 10 executes the "key information borrowing process". The key information borrowing process is a process for obtaining key information Ikey, including the authentication code AC, from the user terminal 30 (digital key 31) and storing it in the storage device 123 or 113. More specifically, the key information Ikey is stored in the storage device 123 or 113, for example, linked to the AVP reservation ID included in the service reservation information held by the management server 12 (server UB). The acquisition route of key information Ikey from the user terminal 30 (digital key 31) by the key information borrowing process, specific examples of the storage location of the acquired key information Ikey, and specific examples of the acquisition route of key information Ikey when using it (in step S108 or S114 described later) will be described later in Section 3-1-2.
[0054] In step S106, following step S104, the local management device 11 determines whether the handover process has been completed. If the handover process is completed (step S106; Yes), the process proceeds to step S108. The process in step S108 is performed when the driving system 23 is activated in a predetermined area (more specifically, when the vehicle 1 begins to move from the drop-off area 3 of the parking lot 2 to the parking space 8 assigned to the vehicle 1).
[0055] In step S108, the local management device 11 reads (acquires) the authentication code AC from the storage device 123 or 113. The local management device 11 then sends a request to the vehicle 1 (control device 21) to start the driving system 23 along with the read authentication code AC, causing the control device 21 to release the immobilizer's restriction on starting the driving system 23. In other words, the local management device 11 starts the aforementioned parking process. Note that the processing entity in step S108 is not necessarily limited to the local management device 11, but may also be executed by the management server 12 on the cloud. The same applies to step S114, which will be described later.
[0056] In addition, the transmission (notification) of the authentication code AC from the local management device 11 to the vehicle 1 may be performed by using the communication Ckey between the digital key 31 and the control device 21 to transmit the authentication code AC itself. Alternatively, the transmission (notification) of the authentication code AC may be performed using AVP communication (i.e., communication used between the local management device 11 and the vehicle 1 for the provision of AVP services). In this AVP communication, the authentication code AC is transmitted after being converted into AVP-specific encrypted information (data). In one example of AVP communication, the local management device 11 communicates directly with the vehicle 1 using a wireless communication method such as WiFi. In another example of AVP communication, the local management device 11 communicates with the vehicle 1 via the management server 12 (more specifically, servers OB and VB) using a wireless communication method such as LTE.
[0057] When vehicle 1 receives a startup request along with authentication code AC, the control device 21 executes the process shown in Figure 5. First, the control device 21 compares the authentication code AC transmitted (notified) from the local management device 11 (management system 10) with the authentication code AC stored in its own storage device 213. More specifically, if the authentication code AC itself is transmitted from the local management device 11 using the communication Ckey, the control device 21 compares the authentication code AC using the same method as when the authentication code AC is transmitted from a normal digital key 31. Furthermore, if the authentication code AC is transmitted using the above-mentioned AVP communication, the control device 21 compares the authentication code AC based on the encrypted information specific to AVP.
[0058] If the two authentication codes AC mentioned above match, that is, if the authentication code AC verification is successful (step S200; Yes), the process proceeds to step S202. In step S202, the control device 21 permits the activation of the driving system 23. In other words, the control device 21 releases the immobilizer's restriction on the activation of the driving system 23 and activates the driving system 23. After the driving system 23 is activated, the vehicle 1 performs AVP driving towards the assigned parking space 8.
[0059] On the other hand, if the authentication code AC is not verified (step S200; No), the process proceeds to step S204. In step S204, the control device 21 communicates with the user terminal 30 via (or directly) the servers VB and UB and notifies user X of an abnormality (for example, that AVP driving is not possible). For example, if the local management device 11 is configured to receive information from vehicle 1 indicating that the verification was unsuccessful, the local management device 11 that receives such information may issue the above notification. The above notification may also include a message requesting user X to return to vehicle 1 with the digital key 31 so that AVP driving can be started. For example, if user X returns to vehicle 1 and the control device 21 is able to start the driving system 23, vehicle 1 will perform AVP driving towards the assigned parking space 8.
[0060] In Figure 4, in step S110, following step S108, the local management device 11 determines whether the receiving process has been completed. If the receiving process is completed (step S110; Yes), the process proceeds to step S112.
[0061] In step S112, the local management device 11 communicates with server UB via server OB to determine whether or not it has received a request from user terminal 30 to release the parked vehicle 1. If a release request is received (step S112; Yes), the process proceeds to step S114. The process in step S114 is executed when the driving system 23 is activated in a predetermined area (more specifically, when the vehicle 1 starts moving from its parking space 8 to the boarding area 4 of the parking lot 2).
[0062] In step S114, similar to step S108, the local management device 11 sends a request to start the driving system 23 along with the authentication code AC to the vehicle 1 (control device 21), causing the control device 21 to release the immobilizer's restriction on starting the driving system 23. That is, the local management device 11 starts the departure process described above. Even if the vehicle 1 receives the start request along with the authentication code AC through the process in step S114, the control device 21 executes the process shown in Figure 5 as described above. After that, the vehicle 1 performs AVP driving towards the boarding area 4.
[0063] In step S116, following step S114, the local management device 11 determines whether vehicle 1 has arrived at boarding area 4 (more specifically, the assigned boarding slot 9). If vehicle 1 has arrived at boarding area 4 (step S116; Yes), the process proceeds to step S118.
[0064] In step S118, the local management device 11 communicates with server UB via server OB and determines whether or not it has received a handback start request from user terminal 30. If a handback start request is received (step S118; Yes), the process proceeds to step S120.
[0065] In step S120, the local management device 11 starts the handback process described above in response to the received handback start request. The handback process is included in the outbound process. Next, in step S122, the local management device 11 determines whether the handback process has been completed. If the handback process is completed (step S122; Yes), the process proceeds to step S124.
[0066] In step S124, the management system 10 deletes the key information Ikey. Specifically, if the key information Ikey is stored in the storage device 123 of the management server 12 (e.g., server OB or VB), for example, the local management device 11 sends an instruction to server OB or VB to delete the key information Ikey, and server OB or VB deletes the key information Ikey from its storage device 123. Alternatively, if the key information Ikey is stored in the storage device 113 of the local management device 11, for example, the local management device 11 deletes the key information Ikey from the storage device 113.
[0067] To add to that, the departure process is completed when the handbag processing is finished. Then, when user X gets into vehicle 1 and vehicle 1 leaves parking lot 2, the departure of vehicle 1 itself is completed.
[0068] 3-1-1. Timing of key information deletion As already explained, the management system 10 deletes the key information Ikey, which has finished being used for providing the AVP service, from the storage device 123 or 113.
[0069] 3-1-1-1. Example 1 In the example process shown in Figure 4, the management system 10 deletes the key information Ikey from the storage device 123 or 113 (step S124) upon completion of the handover period during which the operation authority of vehicle 1 is transferred from user X to the management system 10, that is, upon completion of the handback process (step S122; Yes).
[0070] 3-1-1-2. Second Example Figure 6 is a flowchart showing another example of the processing flow executed by the vehicle management system 10 (mainly the local management device 11) in relation to "deactivating the immobilizer using borrowed key information Ikey from the user terminal 30" according to this embodiment. The processing in this flowchart differs from the processing in the flowchart shown in Figure 4 in the timing of deleting the key information Ikey when vehicle 1 leaves the depot.
[0071] Specifically, in Figure 6, the management system 10 deletes the key information Ikey from the storage device 123 or 113 when vehicle 1 arrives at the boarding area 4 to exit from a designated area (e.g., parking lot 2) (step S116; Yes) (step S300).
[0072] Alternatively, instead of the second example shown in Figure 6, the timing for deleting the key information Ikey when vehicle 1 leaves the parking lot may be when the driving system 23 for moving vehicle 1 from parking space 8 to passenger space 9 has finished starting up.
[0073] 3-1-2. Acquisition route and storage location of key information This section describes the acquisition path for key information Ikey from the user terminal 30 (digital key 31) via key information borrowing processing (see step S104), specific examples of the storage location for the acquired key information Ikey, and specific examples of the acquisition path for key information Ikey when it is used (step S108 or S114).
[0074] 3-1-2-1. Example 1 Figure 7 shows a first example of the acquisition path and storage location of key information Ikey. In the first example, the user terminal 30 transmits the key information Ikey to the management server 12 (more specifically, server UB) using wireless communication (e.g., LTE) in conjunction with the handover start request. Server UB receives the key information Ikey from the user terminal 30 and transmits the received key information Ikey to server OB or VB.
[0075] Server OB or VB receives key information Ikey from server UB. Server OB or VB may then store the received key information Ikey in its own storage device 123 (step S104). Alternatively, Server OB or VB may transmit the received key information Ikey to the local management device 11. When key information Ikey is transmitted from server OB or VB to the local management device 11 in this manner, the local management device 11 stores the acquired (received) key information Ikey in its own storage device 113 (step S104).
[0076] When the local management device 11 transmits the authentication code AC to the vehicle 1 along with the request to start the driving system 23 (step S108 or S114), it reads and obtains the key information Ikey from the storage device 123 or 113. The local management device 11 then transmits the authentication code AC contained in the obtained key information Ikey to the control device 21 (vehicle 1).
[0077] As described above, in the first example, the local management device 11 obtains key information Ikey from the user terminal 30 via the management server 12.
[0078] 3-1-2-2. Second Example Figure 8 shows a second example of the acquisition path and storage location of key information Ikey. In the second example, the user terminal 30 transmits the key information Ikey to the control device 21 (vehicle 1) using wireless communication (e.g., WiFi) in conjunction with the handover start request. The control device 21 receives the key information Ikey from the user terminal 30 and transmits the received key information Ikey to the local management device 11 using wireless communication (e.g., WiFi).
[0079] The local management device 11 receives key information Ikey from the control device 21. The local management device 11 may then store the received key information Ikey in its own storage device 113 (step S104). Alternatively, the local management device 11 may send the received key information Ikey to server OB, or (via server OB and UB) to server VB. When the key information Ikey is sent from the local management device 11 to server OB or VB in this manner, server OB or server VB stores the acquired (received) key information Ikey in its own storage device 123 (step S104).
[0080] In the second example as well, when the local management device 11 transmits the authentication code AC to the vehicle 1 along with the request to start the driving system 23 (step S108 or S114), it reads and obtains the key information Ikey from the storage device 123 or 113. The local management device 11 then transmits the authentication code AC contained in the obtained key information Ikey to the control device 21 (vehicle 1).
[0081] As described above, in the second example, the local management device 11 obtains key information Ikey from the user terminal 30 via the control device 21 (vehicle 1).
[0082] 3-1-2-3. Third Example Figure 9 shows a third example of the acquisition path and storage location of key information Ikey. In this third example, the user terminal 30 transmits the key information Ikey directly to the local management device 11 using wireless communication (e.g., WiFi) or wireless communication of the same type as communication Ckey, in conjunction with the handover start request. As shown in Figure 9, the processing after the local management device 11 receives the key information Ikey from the user terminal 30 is the same as the processing in the second example shown in Figure 8.
[0083] In the third example as well, when the local management device 11 transmits the authentication code AC to the vehicle 1 along with the request to start the driving system 23 (step S108 or S114), it reads and obtains the key information Ikey from the storage device 123 or 113. The local management device 11 then transmits the authentication code AC contained in the obtained key information Ikey to the control device 21 (vehicle 1).
[0084] As described above, in the third example, the local management device 11 directly obtains the key information Ikey from the user terminal 30.
[0085] In addition, as in the first to third examples described above, the storage of key information Ikey may be performed in the storage device 113 of the local management device 11, the storage device 123 of the server OB, or the storage device 123 of the server VB. Furthermore, in the example where the manufacturer of vehicle 1 manages the server VB, it is desirable in terms of ensuring a high level of security for vehicle 1 that the key information Ikey transmitted from the user terminal 30 is stored in the storage device 123 of the server VB, and the local management device 11 (which is not managed by the manufacturer) reads and uses the key information Ikey from the storage device 123 only when it is needed.
[0086] 3-2. Effects As described above, according to this embodiment, when starting the driving system 23 of vehicle 1, the vehicle management system 10 transmits the authentication code AC included in the key information Ikey obtained from the user terminal 30 when a handover start request is issued to the control device 21 of vehicle 1 along with the request to start the driving system 23, causing the control device 21 to release the immobilizer's prohibition on starting the driving system 23. As a result, the vehicle management system 10 can start the driving system 23 without requiring user X to wait near vehicle 1 until the vehicle management system 10 starts the driving system 23 after the handover process is completed. This leads to improved convenience for user X in automated driving services (e.g., AVP service) in a predetermined area.
[0087] In addition, as mentioned above, the timing at which the management system 10 acquires the key information Ikey is when a handover start request is issued. In other words, according to this embodiment, care has been taken to ensure that the period during which the management system 10 holds the key information Ikey is minimized, without the management system 10 acquiring the key information Ikey in advance prior to the start of the AVP service. This contributes to improving the convenience of user X while ensuring a high level of security for vehicle 1 regarding the startup of the driving system 23.
[0088] Furthermore, as described above in Section 3-1-1-1, the management system 10 may delete the key information Ikey from the storage device 123 or 113 upon the end of the handover period during which the operation authority of vehicle 1 is transferred to the management system 10. This allows the driving system 23 to be started in response to a start request from the management system 10 when vehicle 1 enters and leaves the depot, while appropriately limiting the period for which the management system 10 retains the key information Ikey, with consideration for the security of vehicle 1.
[0089] Furthermore, as described above in Section 3-1-1-2, the management system 10 may delete the key information Ikey from the storage device 123 or 113 when vehicle 1 arrives at the boarding area 4 for departure from a predetermined area (e.g., parking lot 2). This allows the driving system 23 to be activated in response to activation requests from the management system 10 when vehicle 1 enters and leaves the parking area, while also allowing the management system 10 to more appropriately limit the period for which it retains the key information Ikey, thereby enhancing the security of vehicle 1. Additionally, in scenarios where it takes time for user X to move to vehicle 1 after vehicle 1 arrives at the boarding area 4, delaying the execution of the handback process, the deletion of the key information Ikey upon vehicle 1's arrival at the boarding area 4, as described above, contributes to user X's sense of security. [Explanation of Symbols]
[0090] 1 Vehicle, 2 Parking area, 3 Drop-off area, 4 Pick-up area, 10 Vehicle management system, 11 Local management device, 12 Management server, 13 Infrastructure sensors, 20 Vehicle system, 21 Control device, 22 Sensors, 23 Driving system, 30 User terminal, 31 Digital key, 100 Vehicle control system, 111, 121, 211 Communication I / F, 112, 122, 212 Processor, 113, 123, 213 Storage device
Claims
1. A vehicle management system for controlling vehicles in a predetermined area, One or more processors, One or more storage devices, Equipped with, The one or more processors described above are: In response to a handover start request from a user terminal storing key information for functioning as a digital key for the vehicle, a handover process is initiated to transfer the operation rights of the vehicle from the user to the vehicle management system. When the handover start request is issued, the key information is obtained from the user terminal and stored in the one or more storage devices. The aforementioned key information includes an authentication code for releasing the vehicle's immobilizer's restriction on starting the vehicle's driving system. When starting the driving system, the one or more processors transmit the authentication code along with the request to start the driving system to the vehicle's control device, causing the control device to release the start restriction. Vehicle management system.
2. A vehicle management system according to claim 1, The one or more processors delete the key information from the one or more storage devices upon the end of the handover period during which the operation authority is transferred to the vehicle management system. Vehicle management system.
3. A vehicle management system according to claim 1, The one or more processors delete the key information from the one or more storage devices when the vehicle arrives at the boarding area to leave the predetermined area. Vehicle management system.
4. A vehicle management system according to any one of claims 1 to 3, The vehicle management system includes a local management device installed in the predetermined area. The one or more processors include one or more first processors included in the local management device. When starting the driving system, the one or more first processors transmit the authentication code along with the request to start the driving system, causing the control device to release the startup restriction. Vehicle management system.
5. A vehicle management system according to claim 4, The vehicle management system includes one or more management servers on the cloud that can communicate with the local management device. The local management device acquires the key information from the user terminal via the one or more management servers. Vehicle management system.
6. A vehicle management system according to claim 4, The local management device acquires the key information from the user terminal via the control device. Vehicle management system.
7. A vehicle management system according to claim 4, The local management device acquires the key information directly from the user terminal. Vehicle management system.
8. A vehicle management system according to claim 1, The aforementioned designated area is a parking lot equipped with an automated valet parking service. The activation of the driving system in the predetermined area refers to the moment when the vehicle begins moving from the drop-off area of the parking lot to the parking space assigned to it. Vehicle management system.
9. A vehicle management system according to claim 1, The aforementioned designated area is a parking lot equipped with an automated valet parking service. The moment when the driving system is activated in the predetermined area is when the vehicle begins to move from its parking space to the boarding area of the parking lot. Vehicle management system.
10. A vehicle management method for managing vehicles in a predetermined area, wherein the vehicle management method is executed by a computer. The aforementioned vehicle management method is: In response to a handover start request from a user terminal that stores key information for functioning as a digital key for the vehicle, the system initiates a handover process to transfer the operation rights of the vehicle from the user to the vehicle management system. When the handover start request is issued, the key information is obtained from the user terminal and stored in one or more storage devices of the vehicle management system. Includes, The aforementioned key information includes an authentication code for releasing the vehicle's immobilizer's restriction on starting the vehicle's driving system. The vehicle management method further includes, when activating the driving system, transmitting the authentication code along with the request to activate the driving system to the vehicle's control device, causing the control device to release the activation restriction. Vehicle management methods.
11. A vehicle management program for managing vehicles in a predetermined area, wherein the vehicle management program is executed by a computer. The aforementioned vehicle management program, In response to a handover start request from a user terminal that stores key information for functioning as a digital key for the vehicle, the system initiates a handover process to transfer the operation rights of the vehicle from the user to the vehicle management system. When the handover start request is issued, the key information is obtained from the user terminal and stored in one or more storage devices of the vehicle management system. The computer is made to execute the above, The aforementioned key information includes an authentication code for releasing the vehicle's immobilizer's restriction on starting the vehicle's driving system. The vehicle management program, when activating the driving system, transmits the authentication code along with the request to activate the driving system to the vehicle's control device, and further causes the computer to perform the action of releasing the activation restriction on the control device. Vehicle management program.