In-vehicle device, vehicle, display method, and display program
Patent Information
- Application Number
- JP2025031966
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2026-09-09
AI Technical Summary
【0010】 上記の車載装置、車両、表示方法、表示プログラムは、デジタルキーが登録されているデバイスの所有者に関する情報の表示を制限することができる。
Smart Images

Figure 2026144578000001_ABST
Abstract
Description
[[Technical Field]]
[0001] The present disclosure relates to an in-vehicle device, a vehicle, a display method, and a display program. [[Background Art]]
[0002] Patent Document 1 describes a digital key management system. The management system includes a vehicle, a plurality of devices, and a management server. The vehicle stores authentication information for authenticating a digital key. The device stores key information indicating the digital key. The management server is capable of communicating with the devices and the vehicle, and manages registration of digital keys. [[Prior Art Documents]] [[Patent Documents]]
[0003] [[Patent Document 1]] Japanese Unexamined Patent Application Publication No. 2024-001720 [[Summary of the Invention]] [[Problem to be Solved by the Invention]]
[0004] There are two types of keys as digital keys registered to a device. The first is an owner key registered to an owner device belonging to the owner of the vehicle. The second is a shared key registered to a device other than the owner device in response to a request from a device on the management system including the owner device.
[0005] The vehicle includes an in-vehicle device. The in-vehicle device displays, on a display unit, digital key information which is information related to the digital key and includes information indicating the owner of the device corresponding to the digital key. However, a device owner may not want digital key information related to themself to be displayed on the in-vehicle device. [[Means for Solving the Problem]]
[0006] An in-vehicle device that solves the above problems is an in-vehicle device installed in a vehicle that can be controlled by each of the multiple devices registered for each of them. This in-vehicle device comprises a processing circuit and a display unit. In this in-vehicle device, when the processing circuit displays digital key information on the display unit, which is information relating to the digital key and includes information indicating the owner of the device corresponding to the digital key, it performs the operation of displaying only the digital key information for some of the owners out of all the digital key information for the vehicle.
[0007] A vehicle that solves the above problem is equipped with an in-vehicle device. In this vehicle, the in-vehicle device is an in-vehicle device mounted on a vehicle that can be controlled by each of a plurality of devices registered for each of them. In this vehicle, the in-vehicle device comprises a processing circuit and a display unit. The processing circuit, when displaying digital key information on the display unit, which is information relating to the digital key and includes information indicating the owner of the device corresponding to the digital key, performs the operation of displaying only the digital key information for some of the owners out of all the digital key information for the vehicle.
[0008] A display method that solves the above problem is a display method for an in-vehicle device installed in a vehicle that can be controlled by each digital key registered for each of a plurality of devices, to display digital key information on a display unit, which is information about the digital key and includes information indicating the owner of the device corresponding to the digital key. This display method includes the step of displaying only the digital key information for some of the owners out of all the digital key information for the vehicle.
[0009] The display program that solves the above problem is a display program executed by a processing circuit of an in-vehicle device installed in a vehicle that can be controlled by each of the digital keys registered for each of the multiple devices. When the in-vehicle device displays digital key information on a display unit, which is information relating to the digital key and includes information indicating the owner of the device corresponding to the digital key, this display program causes the processing circuit to display only the digital key information for some of the owners out of all the digital key information for the vehicle. [Effects of the Invention]
[0010] The above-described in-vehicle devices, vehicles, display methods, and display programs can restrict the display of information regarding the owner of the device to which the digital key is registered. [Brief explanation of the drawing]
[0011] [Figure 1] Figure 1 is a schematic diagram showing a management system including an in-vehicle device according to the first embodiment. [Figure 2] Figure 2 is a schematic diagram showing the owner key information in Figure 1. [Figure 3] Figure 3 is a schematic diagram showing the share key information in Figure 1. [Figure 4] Figure 4 is a schematic diagram showing the data in the database shown in Figure 1. [Figure 5] Figure 5 is an explanatory diagram illustrating the series of processes performed by the management system shown in Figure 1 when an owner key is registered. [Figure 6] Figure 6 is an explanatory diagram illustrating the series of processes performed by the management system shown in Figure 1 when a friend key is registered. [Figure 7] Figure 7 is an explanatory diagram illustrating the series of processes performed by the management system shown in Figure 1 when a non-friend key is registered. [Figure 8] Figure 8 is an explanatory diagram illustrating the series of processes performed by the management system shown in Figure 1 when the device comes within range of the vehicle for communication. [Figure 9]FIG. 9 is a flowchart showing a series of processes executed by the in-vehicle device of FIG. 1 when display of digital key information is requested. [Figure 10] FIG. 10 is a diagram showing a first mode in which the in-vehicle device of FIG. 1 displays digital key information. [Figure 11] FIG. 11 is a diagram showing a second mode in which the in-vehicle device of FIG. 1 displays digital key information. [Figure 12] FIG. 12 is a diagram showing a third mode in which the in-vehicle device of FIG. 1 displays digital key information. [Figure 13] FIG. 13 is a diagram showing a mode in which the in-vehicle device of FIG. 1 displays a status notification. [Figure 14] FIG. 14 is a flowchart showing a series of processes executed when the in-vehicle device of FIG. 1 displays a status notification. [Figure 15] FIG. 15 is a flowchart showing a series of processes executed by the in-vehicle device according to the second embodiment when display of digital key information is requested. [Figure 16] FIG. 16 is a diagram showing a mode in which the in-vehicle device according to the second embodiment displays digital key information. [Figure 17] FIG. 17 is a flowchart showing a series of processes executed by the in-vehicle device according to the third embodiment when display of digital key information is requested. [Figure 18] FIG. 18 is a flowchart showing a series of processes executed by the in-vehicle device according to the first modification. [Figure 19] FIG. 19 is a flowchart showing a series of processes executed by the in-vehicle device according to the second modification. [Figure 20] FIG. 20 is a flowchart showing a series of processes executed by the in-vehicle device according to the third modification. DESCRIPTION OF EMBODIMENTS
[0012] (First Embodiment) Hereinafter, a management system including the in-vehicle device according to the first embodiment will be described with reference to the drawings.
[0013] <Overview of Management System 10> As shown in Figure 1, the management system 10 manages multiple digital keys available for the vehicle 20. In this embodiment, the management system 10 is the system. Regarding digital keys, there is a standard from the Car Connectivity Consortium (CCC). The digital key aspects of this embodiment comply with the CCC. The management system 10 comprises the vehicle 20, multiple devices 30, a device server 60, and a management server 70.
[0014] Vehicle 20 is equipped with an on-board device VD. The on-board device VD consists of a communication module 21, an HMI 22, a BLE module 23, a UWB module 24, an NFC module 25, and a vehicle management device 26. HMI stands for Human Machine Interface. BLE stands for Bluetooth Low Energy. UWB stands for Ultra Wide Band. NFC stands for Near Field Communication.
[0015] The communication module 21 communicates with the management server 70 via a wireless communication network. The HMI 22 includes an input device that accepts user input for the vehicle 20, and a presentation device that presents information to the user using images and sound. The presentation device in the HMI 22 includes at least a display unit 29 capable of presenting image information to the user. The presentation device is, for example, a monitor and a speaker.
[0016] The BLE module 23 communicates with the device 30 via BLE communication. The UWB module 24 communicates with the device 30 via UWB communication. The UWB module 24 measures the distance between the device 30 and the vehicle 20. The NFC module 25 communicates with the device 30 via NFC communication.
[0017] The vehicle management device 26 is installed in the vehicle 20. The vehicle management device 26 manages the digital key of the vehicle 20. The vehicle management device 26 is, for example, a digital key ECU. The vehicle management device 26 has an execution device 27 and a storage device 28.
[0018] The storage device 28 stores the vehicle program PV, the display program PR, and the authentication information AT. The vehicle program PV is executed by the execution device 27, causing the execution device 27 to store and delete the authentication information AT. The display program PR is executed by the execution device 27, causing the execution device 27 to display an image on the display unit 29 of the HMI 22. The display method described below is realized when the execution device 27 displays according to the display program PR. The authentication information AT is information for authenticating a digital key in order to enable control of the vehicle 20 by using the digital key. Authentication information AT is provided for each digital key to be authenticated.
[0019] The execution device 27 is a processing circuit. The execution device 27 executes processes related to the storage and deletion of authentication information AT by executing the vehicle program PV. Authenticating a digital key means verifying whether the digital key is capable of legitimately controlling the vehicle 20. Authentication of the digital key is completed when it is determined that the digital key is capable of legitimately controlling the vehicle 20.
[0020] Vehicle 20 is made controllable by the digital key after the digital key authentication is complete. For example, when the vehicle management device 26 authenticates the digital key, the vehicle management device 26 enables unlocking of vehicle 20. Also, for example, when the vehicle management device 26 authenticates the digital key, the vehicle management device 26 enables starting of vehicle 20.
[0021] In the management system 10, device 30 is a device that stores the key information DK, which will be described later. Device 30 is a portable information terminal such as a smartphone or smartwatch.
[0022] Device 30 includes a communication module 31, an HMI 32, a BLE module 33, a UWB module 34, an NFC module 35, an execution device 36, and a storage device 37.
[0023] The communication module 31 communicates with the device server 60 via a wireless communication line. The HMI 32 includes an input device that accepts user input for the device 30, and a presentation device that presents information to the user using images and sound, etc. The presentation device is, for example, a monitor and a speaker.
[0024] The BLE module 33 communicates with the vehicle 20 via BLE communication. The UWB module 34 communicates with the vehicle 20 via UWB communication. The NFC module 35 communicates with the vehicle 20 via NFC communication.
[0025] The storage device 37 stores the device program PD and the key information DK. The device program PD is executed by the execution device 36, which in turn causes the execution device 36 to store and delete the key information DK. The key information DK is information that indicates a digital key.
[0026] The device program PD includes, for example, a device application and a digital key framework. The device application is an application for storing and deleting key information DK. The digital key framework is a program that provides functions for pairing device 30 and sharing digital keys using APIs provided by the OS. The execution device 36 executes the device program PD to perform processes related to storing and deleting key information DK.
[0027] The multiple devices 30 include an owner device 40 and multiple share devices 50. The owner device 40 stores owner key information DKO, which indicates the owner key KO, as key information DK. Only one owner key KO can be registered for each vehicle 20. Therefore, there is only one owner key KO for each vehicle 20. The owner device 40 belongs to the owner of the vehicle 20.
[0028] The owner device 40 may not be a personal information terminal, but rather a server belonging to the owner of the vehicle 20. As will be described later, the owner device 40 can generate share keys KS for other devices. In the management system 10, if the owner device 40 is a server, the owner device 40 is used not to control the vehicle 20, but to generate share keys KS for other devices in response to requests from those devices.
[0029] If the owner device 40 is a server, the owner device 40 does not need to have the BLE module 33, the UWB module 34, and the NFC module 35.
[0030] As shown in Figure 2, the owner key information DKO has owner key structure information STO. The owner key structure information STO includes vehicle identification information ST1, device key identification information ST2, digital key identification information ST3, and slot identification information ST4. The owner key structure information STO also includes certificate information ST5, device public key information ST6, vehicle public key information ST7, and authorization public key information ST8.
[0031] Vehicle identification information ST1 is information that identifies the vehicle 20 to which the digital key is to be set. For example, it is the ID of vehicle 20. The in-device key identification information ST2 is used for managing digital keys within device 30. The in-device key identification information ST2 is information that allows for the identification of digital keys within the application of device 30.
[0032] Digital key identification information ST3 is used for managing digital keys within the management server 70. Slot identification information ST4 is information that allows the digital key to be identified locally on device 30.
[0033] Certificate information ST5 indicates the certificate that certifies the digital key. Device public key information ST6 indicates the device public key PKD, which is the public key of device 30. Note that the device public key PKD in owner key information DKO indicates the public key of owner device 40. Vehicle public key information ST7 indicates the vehicle public key PKV, which is the public key of vehicle 20. Authorized public key information ST8 indicates the vehicle public key PKV that has already been authorized.
[0034] As shown in Figure 1, the share device 50 stores share key information DKS, which indicates the share key KS, as key information DK. The share device 50 is a separate device 30 from the owner device 40. The share key KS is a digital key that can be registered multiple times for a single vehicle 20 in order to register the digital key in order to make the digital key usable. In other words, multiple share keys KS can exist for a single vehicle 20.
[0035] Multiple share devices 50 include friend devices 51 and non-friend devices 52. Friend device 51 stores friend key information DKF, which indicates friend key KF, as share key information DKS. Non-friend device 52 stores non-friend key information DKN, which indicates non-friend key KN, as share key information DKS. In other words, the types of share keys KS include friend key KF and non-friend key KN. Friend key KF is a share key KS registered based on a direct registration request D21 from owner device 40, as will be described later. Non-friend key KN is a share key KS registered based on a registration request D31 from friend device 51, as will be described later. In other words, non-friend key KN is a share key KS registered not based on a direct registration request D21 from owner device 40, but based on a registration request D31 from another device 30. To put it another way, non-friend key KN is a share key KS that is not friend key KF.
[0036] Furthermore, when a digital key is registered, it means that the digital key is usable. In other words, when a digital key is registered, the vehicle 20 stores the authentication information AT, and the device 30 stores the key information DK.
[0037] As shown in Figure 3, the share key information DKS includes the share key structure information STS and the authentication package ATP. The share key structure information STS includes vehicle identification information ST1, device key identification information ST2, digital key identification information ST3, and slot identification information ST4. The share key structure information STS also includes certificate information ST5, vehicle public key information ST7, and authorized public key information ST8. In other words, the share key structure information STS is the owner key structure information STO with the device public key information ST6 removed.
[0038] The authentication package ATP includes signature information ATP1, password information ATP2, activation start information ATP3, expiration information ATP4, name information ATP5, and device public key information ATP6.
[0039] Signature information ATP1 indicates that shared device 50 is a legitimate recipient of the digital key. For example, in the case of friend device 51, it indicates a signature by owner device 40. Owner signature information indicates that owner device 40 signed the device public key PKD of friend device 51, which is shown in device public key information ATP6. Also, for example, in the case of non-friend device 52, it indicates a signature by friend device 51. Friend signature information indicates that friend device 51 signed the device public key PKD of non-friend device 52, which is shown in device public key information ATP6.
[0040] Password information ATP2 indicates the pairing password PAS used when establishing a secure channel during pairing between the vehicle 20 and the owner device 40. Effective start information ATP3 indicates the earliest date and time when the share key KS can be used. Expiration date information ATP4 indicates the latest date and time when the share key KS can be used. Name information ATP5 indicates the name that identifies the share key KS. For example, it is set as an identifiable name for each share device 50 through an operation from the owner device 40.
[0041] As shown in Figure 1, the device server 60 relays communication between the device 30 and the management server 70. A separate device server 60 is provided for each type of device 30. That is, the device server 60 that a first-type device 30 communicates with is different from the device server 60 that a second-type device 30 communicates with. For example, "type" refers to the model of the device 30, and a separate device server 60 is provided for each model of the device 30. For example, "type" also refers to the communication line used by the device 30, and a separate device server 60 is provided for each communication line used by the device 30.
[0042] Each device server 60 relays communication with the management server 70, allowing different types of devices 30 to communicate with the management server 70 via the device server 60. Note that only one device server 60 is shown in Figure 1.
[0043] <Management Server 70> The management server 70 manages the registration of digital keys. The management server 70 can communicate with the vehicle 20 and multiple devices 30. The management server 70 comprises an execution unit 71, a storage device 72, and a communication module 73. The communication module 73 communicates with the device server 60 via a wireless communication line. The communication module 73 can also communicate wirelessly with the communication module 21 of the vehicle 20.
[0044] The storage device 72 stores the server program PS and the database DB. The server program PS is executed by the execution device 71, causing the execution device 71 to register digital keys in the database DB and delete digital keys in the database DB.
[0045] The database DB associates each of multiple digital keys with a corresponding vehicle 20 and a registered device 30. The database DB is divided into data DAs for each vehicle 20. When a digital key is registered, the management server 70 stores information in the data DAs indicating the device 30 that stores the key information DK representing that digital key. The management server 70 manages the digital keys by saving the data DAs in the database DB.
[0046] As shown in Figure 4, the data DA of a single vehicle 20 includes the type of digital key registered to that vehicle 20, the registered device 30, and the relationships between the registered devices 30. A hierarchy is established based on the type of digital key. From top to bottom in the hierarchy, the keys are Owner Key KO, Friend Key KF, and Non-Friend Key KN. Higher levels of the hierarchy grant greater authority.
[0047] Permissions include, for example, the number of shared keys KS that can be requested to be registered, and the range of vehicles 20 that can be controlled by digital key authentication. Higher levels of the hierarchy indicate greater permissions; for example, a higher number of shared keys KS that can be requested to be registered. More specifically, for example, the number of friend keys KF that an owner device 40 can request to be registered is greater than the number of non-friend keys KN that a friend device 51 can request to be registered.
[0048] Furthermore, for example, the higher the hierarchy, the greater the authority, and therefore the wider the control range of the controllable vehicle 20. The control range of the controllable vehicle 20 refers to the possible controls among, for example, engine start control of vehicle 20, power-on control of vehicle 20, and unlocking and locking control of vehicle 20. For example, if the control range of the controllable vehicle 20 includes the three controls mentioned above, the control range of the controllable vehicle 20 is wider than if the control range of the controllable vehicle 20 is limited to unlocking and locking the doors of vehicle 20. More specifically, the control range of vehicle 20 that can be controlled by friend key KF includes the three controls mentioned above, while the control range of vehicle 20 that can be controlled by non-friend key KN is limited to unlocking and locking the doors of vehicle 20.
[0049] This section describes a state in which a digital key is registered to seven devices 30 for one vehicle 20. The seven devices 30 are referred to as Device 1 30A to Device 7 30G. The digital keys registered to each of Devices 1 30A to Device 7 30G are referred to as Digital Key 1 to Digital Key 7.
[0050] In the data DA, device 30, which is registered as Owner Key KO, is the first device 30A. That is, the first device 30A is the owner device 40. In other words, the first digital key is Owner Key KO.
[0051] In the data DA, the devices 30 registered with the digital key type as Share Key KS are the second device 30B, the third device 30C, the fourth device 30D, the fifth device 30E, the sixth device 30F, and the seventh device 30G. In other words, the second device 30B, the third device 30C, the fourth device 30D, the fifth device 30E, the sixth device 30F, and the seventh device 30G are all Share Devices 50. That is, the second to seventh digital keys are all Share Key KS.
[0052] More specifically, in the data DA, the devices 30 registered with the digital key type as Friend Key KF are the second device 30B and the third device 30C. That is, the second device 30B and the third device 30C are Friend Devices 51. In the data DA, the devices 30 registered with the digital key type as Non-Friend Key KN are the fourth device 30D, the fifth device 30E, the sixth device 30F, and the seventh device 30G. That is, the fourth device 30D, the fifth device 30E, the sixth device 30F, and the seventh device 30G are Non-Friend Devices 52.
[0053] In data DA, the relationship between the second device 30B and the first device 30A is such that the friend key KF is registered in the second device 30B based on a registration request from the first device 30A. In other words, the second digital key is registered based on the first digital key.
[0054] In data DA, the relationship between the third device 30C and the first device 30A is such that the friend key KF is registered in the third device 30C based on a registration request from the first device 30A. In other words, the third digital key is registered based on the first digital key.
[0055] In the data DA, the relationship between the fourth device 30D and the second device 30B is such that the non-friendly key KN is registered in the fourth device 30D based on a registration request from the second device 30B. In other words, the fourth digital key is registered based on the second digital key.
[0056] In the data DA, the relationship between the fifth device 30E and the second device 30B is such that the non-friendly key KN is registered in the fifth device 30E based on a registration request from the second device 30B. In other words, the fifth digital key is registered based on the second digital key.
[0057] In the data DA, the relationship between the sixth device 30F and the third device 30C is such that the non-friendly key KN is registered in the sixth device 30F based on a registration request from the third device 30C. In other words, the sixth digital key is registered based on the third digital key.
[0058] In data DA, the relationship between the 7th device 30G and the 3rd device 30C is such that the non-friendly key KN is registered in the 7th device 30G based on a registration request from the 3rd device 30C. In other words, the 7th digital key is registered based on the 3rd digital key.
[0059] Thus, the data DA stores the devices 30 that have been registered as digital keys. Furthermore, it associates information indicating the device 30 that made the request that triggered the registration of the device 30. The data DA also includes information indicating which digital key each digital key is based on.
[0060] <Digital Key Registration> Next, we will describe the series of processes for registering digital keys in the management system 10. The management system 10 registers the owner key KO, the friend key KF, and the non-friend key KN as digital keys. Below, we will describe the sequence of processes from when each digital key is not registered to when it is registered. In the following explanation, the processes executed by the execution device 27 will be described as processes executed by the vehicle 20, the processes executed by the execution device 36 will be described as processes executed by the device 30, and the processes executed by the execution device 71 will be described as processes executed by the management server 70.
[0061] <Owner Key KO Registration> As shown in Figure 5, the management system 10 performs a series of processes to register the owner key KO. Among the devices 30 that do not store the key information DK indicating the owner key KO, the device 30 that will be designated as the owner device 40 is designated as the first device 30A.
[0062] In the management system 10, upon registration of the owner key KO, key information DK indicating the owner key KO is stored in the first device 30A. In the management system 10, upon registration of the owner key KO, authentication information AT for authenticating the owner key KO is stored in the vehicle 20. As a result, the first device 30A becomes the owner device 40. Note that the registration of the owner key KO is assumed to be performed on the first device 30A with the application installed.
[0063] When the management server 70 receives the owner key KO registration request D11 from the first device 30A or the like, the management server 70 first performs the process in step S11. In step S11, the management server 70 generates a pairing password PAS. Then, the management server 70 sends information indicating the pairing password PAS to the vehicle 20 and the first device 30A.
[0064] Subsequently, vehicle 20 receives the pairing password PAS. After vehicle 20 receives the pairing password PAS, it is set to pairing mode by HMI 22 and waits to receive the password from the first device 30A. Then, vehicle 20 proceeds to step S12.
[0065] In step S12, vehicle 20 pairs with the first device 30A. Once pairing is complete, vehicle 20 establishes a secure channel with the first device 30A for data communication. Pairing is performed using the pairing password PAS sent from the management server 70 to vehicle 20 and the first device 30A. Once pairing is complete, vehicle 20 proceeds to step S13.
[0066] In step S13, the vehicle 20 generates a vehicle public key PKV, which is the public key of the vehicle 20, and a vehicle private key SKV, which is the private key of the vehicle 20. Then, the vehicle 20 sends generated data DC to the first device 30A via the secure channel to generate the owner key KO. The generated data DC includes vehicle identification information ST1 and vehicle public key information indicating the vehicle public key PKV. The first device 30A then receives the generated data DC. The first device 30A then proceeds to step S14.
[0067] In step S14, the first device 30A generates owner key information DKO, which indicates the owner key KO. Then, the first device 30A proceeds to step S15. In step S15, the first device 30A stores the owner key information DKO. This makes the first device 30A the owner device 40. Subsequently, the first device 30A transmits the certificate information ST5 related to the owner key KO and the device public key information ST6 indicating the device public key PKD to the vehicle 20.
[0068] Subsequently, when vehicle 20 receives certificate information ST5 and device public key information ST6, vehicle 20 performs the process in step S16. In step S16, vehicle 20 verifies certificate information ST5. Once the verification of certificate information ST5 is complete, vehicle 20 proceeds to step S17.
[0069] In step S17, the vehicle 20 stores the device public key information ST6, which represents the device public key PKD, as authentication information AT. Subsequently, the vehicle 20 sends a completion notification M11 to the first device 30A indicating that the storage of the authentication information AT is complete.
[0070] Subsequently, when the first device 30A receives the completion notification M11, the first device 30A performs the process in step S18. In step S18, the first device 30A generates a key track request D12 for the owner key KO. The key track request D12 is a signal to the management server 70 requesting an update to the database DB. The first device 30A then sends the key track request D12 for the owner key KO to the management server 70 via the device server 60.
[0071] Subsequently, when the management server 70 receives the key track request D12, it performs the processing in step S19. In step S19, the management server 70 performs the registration management of the owner key KO. Specifically, it stores the first device 30A in the data DA of the vehicle 20 in the database DB as the device 30 registered as the owner key KO. With this, the management system 10 completes the series of processing for the owner key KO.
[0072] <Registering Friend Key KF> As shown in Figure 6, the management system 10 performs a series of processes to register the friend key KF. Of the devices 30 that do not store the friend key information DKF, the device 30 that becomes a friend device 51 through this series of processes is designated as the second device 30B.
[0073] When the owner device 40 performs an operation to request the registration of the friend key KF, the owner device 40 first performs the process in step S21. In step S21, the owner device 40 sends the friend key KF registration request D21 to a relay server (not shown in the figure). After that, the owner device 40 proceeds to step S22.
[0074] In step S22, the owner device 40 obtains invitation information IV1 for sharing the digital key from the relay server. Invitation information IV1 is, for example, a URL link. The URL link contains share information SH1 necessary for sharing the digital key. The owner device 40 then sends the invitation information IV1 to the second device 30B.
[0075] Subsequently, when the second device 30B receives the invitation information IV1, it performs the process in step S23. In step S23, the second device 30B obtains the share information SH1 based on the invitation information IV1. Specifically, the second device 30B downloads the share information SH1 from the source of the URL link.
[0076] The share information SH1 includes, for example, share key structure information STS, password information ATP2, effective start information ATP3, expiration information ATP4, and name information ATP5. Note that the effective start information ATP3, expiration information ATP4, and name information ATP5 are set by the owner device 40. After that, the second device 30B proceeds to step S24.
[0077] In step S24, the second device 30B generates unsigned friend key information DKFN using the share information SH1. Unsigned friend key information DKFN is friend key information DKFN that does not have signature information ATP1. Specifically, the second device 30B generates each piece of information contained in the acquired share information SH1 as the pieces of information in the unsigned friend key information DKFN. Subsequently, the second device 30B sends a completion notification M21 indicating that the generated unsigned friend key information DKFN has been uploaded to a URL link, and a signature request D22 requesting a signature, to the owner device 40.
[0078] Subsequently, the owner device 40 receives a completion notification M21 and a signature request D22 from the second device 30B. Upon receiving the completion notification M21, the owner device 40 obtains the unsigned friend key information DKFN. Upon receiving the signature request D22, the owner device 40 performs the process in step S25 by being operated.
[0079] In step S25, the owner device 40 generates signature information ATP1. Specifically, the owner device 40 prompts the HMI 32 to present the acquired unsigned friend key information DKFN and accepts an operation indicating consent to the registration of the friend key KF by the user of the owner device 40. Once the operation is performed, the owner device 40 obtains a signature based on the fact that the operation has been performed. After that, the owner device 40 proceeds to step S26.
[0080] In step S26, the owner device 40 adds the signature information ATP1 to the unsigned friend key information DKFN. This causes the owner device 40 to generate the friend key information DKF. The owner device 40 then uploads the generated friend key information DKF to the URL link which is the invitation information IV1. The owner device 40 then sends a completion notification M22 to the second device 30B indicating that the upload of the completed friend key information DKF to the URL link is complete.
[0081] Subsequently, the second device 30B receives a completion notification M22. Then, the second device 30B performs the process in step S27. In step S27, the second device 30B downloads and stores the friend key information DKF. As a result, the second device 30B becomes the friend device 51. Then, the second device 30B proceeds to step S28.
[0082] In step S28, the second device 30B generates a key track request D23 for the friend key KF. The second device 30B then sends the friend key information DKF and the key track request D23 for the friend key KF to the management server 70.
[0083] Subsequently, when the management server 70 receives the key track request D23 for the friend key KF, the management server 70 performs the process in step S29. In step S29, the management server 70 performs registration management for the friend key KF.
[0084] Specifically, the management server 70 verifies that the friend key KF, which is the target of keytrack request D23, is not on the rejection list. The rejection list is a list of share keys KS, including friend keys KF and non-friend keys KN for which a deletion request has already been received. If friend key KF is on the rejection list, the management server 70 sends a notification to the second device 30B that it cannot fulfill keytrack request D23.
[0085] On the other hand, if the friend key KF that received the key track request D23 is not on the rejection list, the management server 70 registers the friend key KF that received the key track request D23 in the database DB. Specifically, the management server 70 stores the second device 30B as device 30 registered as friend device 51 in the vehicle 20 data DA in the database DB. The management server 70 stores the relationship between the second device 30B and the owner device 40 by referring to the acquired friend key information DKF.
[0086] Subsequently, the management server 70 sends the authentication package ATP from the friend key information DKF and a storage request D24 requesting storage of the authentication package ATP to the vehicle 20. That is, the management server 70 sends the device public key information ST6, which indicates the device public key PKD of the friend device 51, to the vehicle 20. The management server 70 also notifies the vehicle 20 that the device public key PKD is signed by the owner device 40.
[0087] Subsequently, when vehicle 20 receives storage request D24 and authentication package ATP from management server 70, it performs the process in step S30. In step S30, vehicle 20 stores the received authentication package ATP as authentication information AT for authenticating friend key KF.
[0088] Furthermore, after completing registration management, the management server 70 sends a keytrack completion notification M23 to the second device 30B. Subsequently, when the second device 30B receives the key track completion notification M23, it performs the process in step S31. In the process of step S31, the second device 30B presents information to the HMI 32 indicating that the registration of the friend key KF is complete. For example, the second device 30B displays an image indicating the registration of the friend key KF on the HMI 32. With this, the management system 10 completes the series of processes for registering the friend key KF.
[0089] <Registering Non-Friend Keys (KN)> As shown in Figure 7, the management system 10 performs a series of processes to register the non-friendly key KN. Of the devices 30 that do not store the non-friendly key information DKN, the device 30 that becomes a non-friendly device 52 through this series of processes is designated as the fourth device 30D.
[0090] When an operation is performed in the friend device 51 to request the registration of a non-friend key KN, the friend device 51 first performs the process in step S41. In step S41, the friend device 51 sends the non-friend key KN registration request D31 to a relay server (not shown in the figure). After that, the friend device 51 proceeds to step S42.
[0091] In step S42, the friend device 51 obtains invitation information IV2 for sharing the digital key from the relay server. Invitation information IV2 is, for example, a URL link. The URL link contains the share information SH2 necessary for sharing the digital key. The friend device 51 then sends the invitation information IV2 to the fourth device 30D.
[0092] Subsequently, when the fourth device 30D receives the invitation information IV2, it performs the process in step S43. In step S43, the fourth device 30D obtains the share information SH2 based on the invitation information IV2. Specifically, the fourth device 30D downloads the share information SH2 from the URL link.
[0093] The share information SH2 includes, for example, the share key structure information STS, password information ATP2, activation start information ATP3, expiration date information ATP4, and name information ATP5. Note that the activation start information ATP3, expiration date information ATP4, and name information ATP5 are set by the friend device 51. After that, the fourth device 30D proceeds to step S44.
[0094] In step S44, the fourth device 30D generates unsigned non-friend key information DKNN using the share information SH2. Unsigned non-friend key information DKNN is non-friend key information DKNN that does not have signature information ATP1. Specifically, the fourth device 30D generates each piece of information contained in the acquired share information SH2 as the pieces of information in the unsigned non-friend key information DKNN. Subsequently, the fourth device 30D sends a completion notification M31 indicating that it has finished uploading the generated unsigned non-friend key information DKNN to a URL link, and a signature request D32 requesting a signature, to the friend device 51.
[0095] Subsequently, the friend device 51 receives a completion notification M31 and a signature request D32 from the fourth device 30D. Upon receiving the completion notification M31, the friend device 51 obtains the unsigned non-friend key information DKNN. Upon receiving the signature request D32, the friend device 51 performs the process in step S45 by being operated.
[0096] In step S45, the friend device 51 generates signature information ATP1. Specifically, the friend device 51 prompts the HMI 32 to present the acquired unsigned non-friend key information DKNN and accepts an operation indicating consent to the generation of the non-friend key KN by the user of the friend device 51. Once the operation is performed, the friend device 51 obtains a signature based on the fact that the operation has been performed. After that, the friend device 51 proceeds to step S46.
[0097] In step S46, the friend device 51 adds the signature information ATP1 to the unsigned non-friend key information DKNN. This causes the friend device 51 to generate the non-friend key information DKN. The friend device 51 then uploads the generated non-friend key information DKN to the URL link which is the invitation information IV2. Finally, the friend device 51 sends a completion notification M32 to the fourth device 30D indicating that it has finished uploading the completed non-friend key information DKN to the URL link.
[0098] Subsequently, the fourth device 30D receives a completion notification M32. Then, the fourth device 30D performs the process in step S47. In step S47, the fourth device 30D downloads and stores the non-friendly key information DKN. As a result, the fourth device 30D becomes a non-friendly device 52. Then, the fourth device 30D proceeds to step S48.
[0099] In step S48, the fourth device 30D generates a key track request D33 for the non-friend key KN. The fourth device 30D then sends the non-friend key information DKN and the key track request D33 for the non-friend key KN to the management server 70.
[0100] Subsequently, when the management server 70 receives a key track request D33 for a non-friendly key KN, the management server 70 performs the process in step S49. In step S49, the management server 70 performs registration management for the non-friendly key KN.
[0101] Specifically, the management server 70 verifies that the non-friendly key KN, which is the target of keytrack request D33, is not on the rejection list. If the non-friendly key KN is on the rejection list, the management server 70 sends a notification to the fourth device 30D that it cannot fulfill keytrack request D33.
[0102] On the other hand, if the non-friendly key KN is not on the rejection list, the management server 70 registers the non-friendly key KN that is the target of the key track request D33 in the database DB. Specifically, the management server 70 stores the fourth device 30D in the vehicle 20 data DA in the database DB as device 30 registered as non-friendly device 52. The management server 70 stores the relationship between the fourth device 30D and the friend device 51 by referring to the acquired non-friendly key information DKN. Specifically, the management server 70 stores the fourth device 30D as device 30 having a non-friendly key KN registered by the registration request D31 from the friend device 51.
[0103] Subsequently, the management server 70 sends the authentication package ATP from the non-friendly key information DKN and a storage request D34 requesting storage of the authentication package ATP to the vehicle 20. That is, the management server 70 sends the device public key information ST6, which indicates the device public key PKD of the non-friendly device 52, to the vehicle 20. The management server 70 also notifies the vehicle 20 that the device public key PKD has been signed by the friendly device 51.
[0104] Subsequently, when vehicle 20 receives the authentication package ATP and the storage request D34, it performs the process in step S50. In step S50, vehicle 20 stores the received authentication package ATP. That is, vehicle 20 stores the authentication package ATP as authentication information AT for authenticating the non-friend key KN.
[0105] Furthermore, after completing registration management, the management server 70 sends a keytrack completion notification M33 to the fourth device 30D. Subsequently, when the fourth device 30D receives the key track completion notification M33, it performs the process in step S51. In the process of step S51, the fourth device 30D presents information to the HMI 32 indicating the completion of registration of the non-friendly key KN. For example, the fourth device 30D displays an image on the HMI 32 indicating the completion of registration of the non-friendly key KN. With this, the management system 10 completes the series of processes for registering the non-friendly key KN.
[0106] <Digital Key Authentication> The digital key registered through the processing shown in Figures 5 to 7 becomes capable of controlling the vehicle 20. As mentioned above, the vehicle 20 becomes controllable by the digital key after the authentication of the digital key is completed.
[0107] In vehicle 20, the in-vehicle device VD authenticates the digital key when device 30 comes within range of vehicle 20 for BLE or NFC communication. Figure 8 shows a series of processes performed by the management system 10 when device 30 comes within range of vehicle 20 for BLE or NFC communication.
[0108] The following describes the series of processes shown in Figure 8. In the following description, the processes executed by the execution device 27 will be described as processes executed by the in-vehicle device VD, and the processes executed by the execution device 36 will be described as processes executed by the device 30.
[0109] As shown in Figure 8, after device 30 enters a range where BLE communication or NFC communication is possible with vehicle 20, device 30 transmits information indicating key information DK stored in storage device 37. If BLE communication is possible with vehicle 20, device 30 transmits information indicating key information DK to the in-vehicle device VD via BLE communication. If NFC communication is possible with vehicle 20, device 30 transmits information indicating key information DK to the in-vehicle device VD via NFC communication.
[0110] As shown in Figure 8, upon receiving information indicating key information DK, the in-vehicle device VD executes the process in step S61. In the process of step S61, the in-vehicle device VD authenticates the digital key indicated by the received key information DK.
[0111] In digital key authentication, the in-vehicle device VD compares the received key information DK with the authentication information AT stored in the storage device 28 to determine whether the digital key indicated by the key information DK is a digital key that can legitimately control the vehicle 20. For example, if the digital key indicated by the authentication information AT stored in the storage device 28 is the digital key indicated by the certificate information ST5 included in the key information DK, the in-vehicle device VD determines that the digital key is a digital key that can legitimately control the vehicle 20.
[0112] Digital key authentication is completed when the in-vehicle device VD determines that the digital key indicated by the received key information DK is a digital key that can legitimately control the vehicle 20. As shown in Figure 8, after the authentication of the digital key is completed, the in-vehicle device VD executes the process in step S62. In the process of step S62, the in-vehicle device VD stores in the storage device 28 that the authenticated digital key is valid. A digital key being valid means that, because authentication by the in-vehicle device VD has been completed, the digital key is in a state where it can control the vehicle 20. As a result, the digital key in which device 30 stores key information DK can control the vehicle 20. Hereafter, the state in which the digital key is not valid will be referred to as the digital key being invalid.
[0113] As a result, the management system 10 completes the series of processes shown in Figure 8. The in-vehicle device VD continues to remember that the authenticated digital key is valid until the device 30 moves too far away from the vehicle 20 to communicate with the vehicle 20 using any of the UWB, BLE, or NFC communication methods.
[0114] <Overview of display by in-vehicle VD system> The in-vehicle device VD displays digital key information DDK on the display unit 29 in response to user input. Digital key information DDK is information about a digital key registered through processing as shown in Figures 5 to 7. The digital key information DDK displayed by the in-vehicle device VD is based on authentication information AT stored in the storage device 28.
[0115] The digital key information DDK includes information indicating the owner of the device 30 corresponding to the digital key. The device 30 corresponding to the digital key is the device 30 that stores the key information DK of the digital key in the storage device 37.
[0116] The digital key information DDK may include various information in addition to information indicating the owner of the device 30 corresponding to the digital key. The in-vehicle device VD displays information indicating the owner of the device 30 corresponding to the digital key, as well as information on whether the digital key is valid, as part of the digital key information DDK.
[0117] <Processing performed when displaying digital key information (DDK)> Figure 9 shows the sequence of processes executed when the in-vehicle device VD displays digital key information DDK. The sequence of processes shown in Figure 9 is executed by the display program PR on the execution device 27 when an operation is made to request the in-vehicle device VD to display the digital key information DDK.
[0118] As shown in Figure 9, when an operation is made to request the display of digital key information DDK, the execution device 27 first executes the process in step S71. In the process of step S71, the execution device 27 determines the owner of the device 30 that is using the vehicle 20. At this time, the execution device 27 checks the information stored in the storage device 28 and determines that the owner of the device 30 corresponding to the valid digital key is using the vehicle 20. After that, the execution device 27 proceeds to step S72.
[0119] In step S72, the execution device 27 determines whether or not there is an owner of a device 30 that is using the vehicle 20. If, in step S71, the execution device 27 determined that there was an owner of a device 30 that was using the vehicle 20, then the execution device 27 determines that there is an owner of a device 30 that is using the vehicle 20. On the other hand, if, in step S71, the execution device 27 determined that there was no owner of a device 30 that was using the vehicle 20, then the execution device 27 determines that there is no owner of a device 30 that is using the vehicle 20.
[0120] As shown in Figure 9, if the execution device 27 determines that there is no owner of the device 30 using the vehicle 20 (step S72: NO), it terminates the series of processes shown in Figure 9. In other words, if there is no owner of the device 30 using the vehicle 20, the execution device 27 terminates the series of processes shown in Figure 9 without displaying the digital key information DDK.
[0121] As shown in Figure 9, if the execution device 27 determines that there is an owner of the device 30 that is using the vehicle 20 (step S72: YES), it proceeds to step S73. In step S73, the execution device 27 displays the digital key information DDK for the owner of the device 30 that was determined to be using the vehicle 20 in step S71, and for any related owners. Related owners will be described later. After that, the execution device 27 terminates the series of processes shown in Figure 9.
[0122] <Specific display methods by the in-vehicle VD device> Figures 10 to 12 show specific examples of how the in-vehicle device VD displays digital key information DDK in a hypothetical scenario. Below, we will explain the specific display methods used by the in-vehicle device VD while referring to Figures 10 to 12. The process performed by the in-vehicle device VD to realize the display methods shown in Figures 10 to 12 is carried out by the execution device 27 executing the display program PR.
[0123] In this hypothetical scenario, four users, User A through User D, own device 30. User A is the owner of vehicle 20. In this hypothetical scenario, owner device 40 is a smartphone owned by User A.
[0124] User B owns a smartphone. This smartphone is a friend device 51 to which the friend key KF has been registered based on a request from a smartphone owned by User A.
[0125] User B owns a smartwatch in addition to a smartphone. This smartphone is a non-friend device 52 to which a non-friend key KN has been registered based on a request from User B's smartphone.
[0126] User C owns a smartphone. This smartphone is a non-friend device 52 to which a non-friend key KN has been registered based on a request from a smartphone owned by User B.
[0127] User D owns a smartphone. This smartphone is a friend device 51 to which the friend key KF has been registered based on a request from a smartphone owned by User A.
[0128] In this hypothetical scenario, with both User A's and User B's smartphones active, the in-vehicle device VD is requested to display the digital key information DDK.
[0129] <First aspect> Figure 10 shows the display mode initially shown on the display unit 29 in a hypothetical case, triggered by a request to display digital key information DDK to the in-vehicle device VD, which then executes the series of processes shown in Figure 9. Hereafter, the display mode shown in Figure 10 will be referred to as the first mode.
[0130] In the first embodiment, the in-vehicle device VD displays the device name information DDKN of device 30 as digital key information DDK. The device name information DDKN is information indicating the device name of device 30. The device name is the name assigned to device 30 for the user to identify device 30.
[0131] As shown in Figure 10, in the first embodiment, the in-vehicle device VD displays the device name information DDKN for each device 30 in a rectangular box. In the first embodiment, the in-vehicle device VD displays a list of device names for device 30.
[0132] In Figure 10, of the two device name information DDKNs displayed, the upper device name information DDKN indicates the device name of the smartphone owned by user A. In other words, of the two device name information DDKNs displayed in Figure 10, the upper device name information DDKN is the digital key information DDK for the digital key registered for the smartphone owned by user A.
[0133] In this hypothetical scenario, the digital key registered for the smartphone owned by user A corresponds to the first digital key explained in Figure 4. In this explanation of the hypothetical scenario, the digital key registered for the smartphone owned by user A is referred to as the first digital key.
[0134] In Figure 10, of the two device name information DDKNs displayed, the lower device name information DDKN indicates the device name of the smartphone owned by user B. In other words, of the two device name information DDKNs displayed in Figure 10, the lower device name information DDKN is the digital key information DDK for the digital key registered for the smartphone owned by user B.
[0135] In the hypothetical case, the digital key registered for the smartphone owned by user B corresponds to the second digital key explained in Figure 4. In the explanation of the hypothetical case, the digital key registered for the smartphone owned by user B will be referred to as the second digital key.
[0136] The device name is composed of a combination of the owner of device 30 and the type of device 30. In Figure 10, the "User A" portion of the device name shown in the DDKN device name information indicates the owner of device 30. In Figure 10, the "Smartphone" portion of the device name shown in the DDKN device name information indicates the type of device 30.
[0137] In Figure 10, the part of the device name shown in the device name information DDKN below, specifically the "User B" portion, indicates the owner of device 30. In Figure 10, the part of the device name shown in the device name information DDKN below, specifically the "Smartphone" portion, indicates the type of device 30.
[0138] In the first embodiment, the in-vehicle device VD displays only the digital key information DDK for the valid first digital key and second digital key. In other words, in the first embodiment, the in-vehicle device VD displays only the digital key information DDK for the owner who was determined to be using the vehicle 20 in the process of step S71 shown in Figure 9.
[0139] As shown in Figure 10, in the first embodiment, the in-vehicle device VD displays the number information DDN on the display unit 29. The number information DDN is information indicating the number of digital keys that can control the vehicle 20. In the hypothetical case, as mentioned above, digital keys have been registered for five devices by users A to D. Therefore, the in-vehicle device VD displays as the number information DDN that there are five digital keys registered for the vehicle 20.
[0140] <Second aspect> In the first embodiment, the entire rectangle surrounding the device name information DDKN is a button. In Figure 10, when the user presses the upper rectangle surrounding the device name information DDKN, the in-vehicle device VD displays the details of the digital key information DDK for the first digital key. In Figure 10, when the user presses the lower rectangle surrounding the device name information DDKN, the in-vehicle device VD displays the details of the digital key information DDK for the second digital key.
[0141] Figure 11 shows the display configuration displayed on the display unit 29 when the user presses the rectangular area surrounding the device name below. In other words, Figure 11 is a screen displaying the details of the digital key information DDK for the second digital key. Hereafter, the display configuration shown in Figure 11 will be referred to as the second configuration.
[0142] As shown in Figure 11, in the second embodiment, the in-vehicle device VD displays user information DDKU for the second digital key. User information DDKU is digital key information DDK that indicates the owner of the device 30 corresponding to the digital key. In Figure 11, the name of user B is displayed as the user information DDKU for the second digital key.
[0143] As shown in Figure 11, in the second embodiment, the in-vehicle device VD displays status information DDKS for the second digital key. Status information DDKS is digital key information DDK, which indicates whether the digital key is currently valid or not. In Figure 11, the status information DDKS for the second digital key indicates that the second digital key is valid.
[0144] As shown in Figure 11, in the second embodiment, the in-vehicle device VD displays not only the digital key information DDK for the second digital key, but also the digital key information DDK for the digital key related to the second digital key.
[0145] The associated digital key is a digital key registered with device 30 that requested registration of the digital key displaying the digital key information DDK, or a digital key that the digital key displaying the digital key information DDK requested registration of. Hereinafter, device 30 corresponding to the associated digital key will be referred to as the associated device 30. And hereafter, the owner of the associated device 30 will be referred to as the associated owner.
[0146] Figure 11 shows the digital key information DDK for the first digital key, which is registered for the smartphone owned by user A, which is device 30 that requested registration of the second digital key.
[0147] Figure 11 shows the Digital Key Information DDK for the digital key registered to User B's smartwatch, where the second digital key is the digital key that requested registration.
[0148] In the hypothetical case, the digital key registered for the smartwatch owned by user B corresponds to the fourth digital key explained in Figure 4. In the explanation of the hypothetical case, the digital key registered for the smartwatch owned by user B will be referred to as the fourth digital key.
[0149] Figure 11 shows the Digital Key Information DDK for the digital key registered on User C's smartphone, where the second digital key is the digital key that requested registration.
[0150] In the hypothetical case, the digital key registered for the smartphone owned by user C corresponds to the fifth digital key explained in Figure 4. In the explanation of the hypothetical case, the digital key registered for the smartphone owned by user C will be referred to as the fifth digital key.
[0151] Thus, in this hypothetical example, the digital keys associated with the second digital key are the first digital key, the fourth digital key, and the fifth digital key. As shown in Figure 11, in the second embodiment, the in-vehicle device VD displays the device name information DDKN for the first digital key as the digital key information DDK for the digital key associated with the second digital key. Also, as shown in Figure 11, in the second embodiment, the in-vehicle device VD displays the device name information DDKN for the fourth digital key as the digital key information DDK for the digital key associated with the second digital key. In addition, as shown in Figure 11, in the second embodiment, the in-vehicle device VD displays the device name information DDKN for the fifth digital key as the digital key information DDK for the digital key associated with the second digital key.
[0152] As shown in Figure 11, in the second embodiment, the in-vehicle device VD displays the device name information DDKN for the digital key associated with the second digital key, enclosed in a rectangle for each device 30.
[0153] Thus, in the second embodiment, the in-vehicle device VD displays the digital key information DDK for the second digital key, which is currently active. In addition, in the second embodiment, the in-vehicle device VD displays the digital key information DDK for the first digital key, the fourth digital key, and the fifth digital key, which are digital keys associated with the second digital key.
[0154] In other words, in the second embodiment, the in-vehicle device VD displays digital key information DDK for user B, who is determined to be the owner of the vehicle 20 and is in use. In addition, in the second embodiment, the in-vehicle device VD displays digital key information DDK for users A and C, who are owners associated with the second digital key.
[0155] <Third aspect> In the second embodiment, the entire rectangle surrounding the device name information DDKN for the associated digital key is a button. In Figure 11, if the user presses the rectangle surrounding the device name information DDKN for the first digital key, the in-vehicle device VD displays the details of the digital key information DDK for the first digital key. In Figure 11, if the user presses the rectangle surrounding the device name information DDKN for the fourth digital key, the in-vehicle device VD displays the details of the digital key information DDK for the fourth digital key. In Figure 11, if the user presses the rectangle surrounding the device name information DDKN for the fifth digital key, the in-vehicle device VD displays the details of the digital key information DDK for the fifth digital key.
[0156] Figure 12 shows the display shown on the display unit 29 when the user presses the rectangular area surrounding the device name information DDKN for the fifth digital key. In other words, Figure 12 is a screen showing the details of the digital key information DDK for the fifth digital key. Hereafter, the display shown in Figure 12 will be referred to as the third display mode.
[0157] As shown in Figure 12, in the third embodiment, the in-vehicle device VD displays user information DDKU for the fifth digital key. In Figure 12, the name of user C is displayed as the user information DDKU for the fifth digital key.
[0158] As shown in Figure 12, in the third embodiment, the in-vehicle device VD displays the status information DDKS for the fifth digital key. In the hypothetical case, the fifth digital key is not valid. In other words, in the hypothetical case, the fifth digital key is invalid. In Figure 12, the status information DDKS for the fifth digital key indicates that the fifth digital key is invalid.
[0159] In the third embodiment, unlike the second embodiment, the digital key information DDK for the digital key related to the fifth digital key is not displayed. Thus, in the third embodiment, the in-vehicle device VD displays the digital key information DDK for a digital key related to the digital key that displayed the details of the digital key information DDK in the second embodiment.
[0160] Thus, throughout the first to third embodiments, the in-vehicle device VD displays the digital key information DDK for the owner of the device 30 using the vehicle 20, and the digital key information DDK for the associated owner. On the other hand, the in-vehicle device VD does not display the digital key information DDK for user D, who is neither the owner of the device 30 using the vehicle 20 nor the owner associated with the digital key. In this way, when the in-vehicle device VD is requested to display the digital key information DDK, it displays only the digital key information DDK for some owners out of all the digital key information DDK for the vehicle 20.
[0161] <Overview of Status Notification MS> The in-vehicle device VD may display a status notification MS on the display unit 29. Figure 13 shows an example of how the in-vehicle device VD displays the status notification MS.
[0162] A status notification MS is a notification in the management system 10 that informs the user when there is a change in the status of a digital key. The status of a digital key refers to its registration status, such as registration or deletion. In Figure 13, the in-vehicle device VD displays a status notification MS indicating that the fourth digital key has been deleted.
[0163] The status of a digital key may, for example, be whether or not the digital key is valid. <Processing performed when displaying status notification MS> Figure 14 shows the sequence of processes executed when the in-vehicle device VD displays a status notification MS. The sequence of processes shown in Figure 14 is executed by the display program PR on the execution device 27 when the management system 10 detects a change in the status of any of the digital keys.
[0164] As shown in Figure 14, when the execution device 27 detects that there has been a change in the status of any digital key in the management system 10, it first executes the process in step S81. In the process in step S81, the execution device 27 determines whether or not the status notification MS can be displayed on the display unit 29.
[0165] At this time, the execution device 27 determines that it is possible to display the status notification MS if the digital key whose status has changed is a digital key that displays digital key information DDK. A digital key that displays digital key information DDK is a digital key that the in-vehicle device VD determines to display digital key information DDK when a request for display of digital key information DDK is made to the in-vehicle device VD. In other words, a digital key that displays digital key information DDK is a digital key that displays digital key information DDK in the process of step S73 in Figure 9.
[0166] As shown in Figure 14, if the execution device 27 determines that it is not possible to display the status notification MS (step S81: NO), it proceeds to step S84. In the process of step S84, the execution device 27 determines not to display the status notification MS. After that, the execution device 27 terminates the series of processes shown in Figure 14. In this way, if the status notification MS is a status notification MS for a digital key that does not display digital key information DDK, the execution device 27 does not display the status notification MS on the display unit 29.
[0167] As shown in Figure 14, if the execution device 27 determines that it can display the status notification MS (step S81: YES), it proceeds to step S82. In the process of step S82, the execution device 27 determines to display the status notification MS.
[0168] Subsequently, the execution device 27 executes the process in step S83. In the process of step S83, the execution device 27 displays a status notification MS on the display unit 29. After that, the execution device 27 completes the series of processes shown in Figure 14. Thus, if the status notification MS is a status notification MS for a digital key that displays digital key information DDK, the execution device 27 displays the status notification MS on the display unit 29.
[0169] <Operation of the First Embodiment> When the in-vehicle device VD displays the digital key information DDK, it displays only the digital key information DDK for some owners, rather than all of the digital key information DDK for the vehicle 20.
[0170] <Effects of the First Embodiment> (1-1) The in-vehicle device VD can restrict the display of information about the owner of device 30.
[0171] (1-2) The execution device 27, which is a processing circuit, performs the function of communicating with the device 30. Through communication with the device 30, the execution device 27 performs the function of determining that the owner of the device 30 is using the vehicle 20 when the authentication of the digital key registered for the device 30 is completed. When the execution device 27 displays the digital key information DDK, it performs the function of displaying the digital key information DDK for the owner who is using the vehicle 20 out of all the digital key information DDKs for the vehicle 20.
[0172] When the in-vehicle device VD displays the digital key information DDK, it displays the digital key information DDK for the owner currently using the vehicle 20, rather than the entire digital key information DDK for the vehicle 20. This allows the in-vehicle device VD to limit the display of information regarding the owner of device 30.
[0173] (1-3) A digital key can generate other digital keys. When the execution device 27, which is a processing circuit, displays the digital key information DDK for a particular digital key, it displays, in addition to the digital key information DDK, at least one of the digital key information DDK of the digital key that generated the digital key and the digital key information DDK of the digital key that was generated by the digital key.
[0174] When a user views the Digital Key Information DDK (Data Disclosure Key) for a specific digital key, they may also want to view the Digital Key Information DDKs for related digital keys. The in-vehicle device (VD) displays the Digital Key Information DDK for a specific digital key, along with the Digital Key Information DDKs for the original digital key that generated the digital key and the digital keys that generated the digital key. This allows the VD to view the Digital Key Information DDK for a specific digital key while simultaneously viewing the Digital Key Information DDK for related digital keys.
[0175] (1-4) The execution device 27, which is a processing circuit, displays the number of digital keys that can control the vehicle 20 when displaying the digital key information DDK. If the in-vehicle device VD displays only some of the digital key information DDK, the user cannot determine the number of digital keys registered for vehicle 20. The in-vehicle device VD displays the number of digital keys registered for vehicle 20. This allows the in-vehicle device VD to inform the user of the number of digital keys registered for vehicle 20.
[0176] (1-5) The in-vehicle device VD is configured to display a status notification MS on the display unit 29 when there is a change in the state of the digital key. The execution device 27, which is a processing circuit, determines to display the status notification MS on the display unit 29 if the status notification MS is a notification about a digital key that displays digital key information DDK. The execution device 27 determines not to display the status notification MS on the display unit 29 if the status notification MS is a notification about a digital key that does not display digital key information DDK.
[0177] The in-vehicle device VD displays a status notification MS, which is a notification indicating the fact that a digital key has been deleted, on the display unit 29. The owner of device 30, who does not want their own digital key information DDK to be displayed on the in-vehicle device VD, is likely to also want the status notification MS not to be displayed on the in-vehicle device VD.
[0178] The in-vehicle device VD displays status notification MS only for digital keys that display digital key information DDK. This allows the in-vehicle device VD to limit the status notification MS displayed on the display unit 29.
[0179] (1-6) The vehicle 20 is equipped with an in-vehicle device VD. When the vehicle 20 displays the digital key information DDK, it displays only the digital key information DDK for some owners, rather than all of the digital key information DDK for the vehicle 20. This allows the vehicle 20 to limit the display of information about the owners of the device 30.
[0180] (1-7) The vehicle 20 is equipped with an in-vehicle device VD. In the in-vehicle device VD, the execution device 27, which is a processing circuit, performs communication with the device 30. Through communication with the device 30, the execution device 27 performs the function of determining that the owner of the device 30 is using the vehicle 20 when the authentication of the digital key registered for the device 30 is completed. When the execution device 27 displays the digital key information DDK, it performs the function of displaying the digital key information DDK for the owner who is using the vehicle 20 from among all the digital key information DDKs for the vehicle 20.
[0181] When vehicle 20 displays the digital key information DDK, it displays the digital key information DDK for the owner currently using vehicle 20, rather than the entire digital key information DDK for vehicle 20. This allows vehicle 20 to limit the display of information about the owner of device 30.
[0182] (1-8) The display method described in the first embodiment is a display method for an in-vehicle device VD mounted on a vehicle 20 that can be controlled by each digital key registered for each of the multiple devices 30 to display digital key information DDK on a display unit 29, which is information about the digital key and includes information indicating the owner of the device 30 corresponding to the digital key. The display method includes a step (step S73) of displaying digital key information DDK for some owners out of all digital key information DDK for the vehicle 20.
[0183] The display method, when displaying digital key information (DDK), shows only the digital key information (DDK) for certain owners, rather than all of the digital key information (DDK) for the vehicle 20. This allows the display method to limit the display of information about the owners of device 30.
[0184] (1-9) When the display program PR displays the digital key information DDK, it displays only the digital key information DDK for some owners, rather than all of the digital key information DDK for the vehicle 20. This allows the display program PR to limit the display of information about the owners of the device 30.
[0185] (Second Embodiment) The management system including the in-vehicle device of the second embodiment will be described below with reference to the drawings. In the second embodiment, unlike the first embodiment, the in-vehicle device VD does not display the digital key information DDK for the owner using the vehicle 20. Instead, the in-vehicle device VD of the second embodiment displays only the digital key information DDK for a specific digital key when the user searches for the digital key information DDK for that digital key. The following description will focus on the differences from the first embodiment, and the same points will be simplified or omitted.
[0186] <Processing performed by the in-vehicle device VD> In the second embodiment, each digital key in the management system 10 is assigned an ID as identification information.
[0187] Figure 15 shows the sequence of processes executed when the in-vehicle device VD displays digital key information DDK. The sequence of processes shown in Figure 15 is executed by the display program PR on the execution device 27 when a request is made to display the digital key information DDK.
[0188] As shown in Figure 15, when a request is made to display the digital key information DDK, the execution device 27 first executes the process in step S91. In the process of step S91, the execution device 27 displays an ID input screen on the display unit 29. The ID input screen is a screen that requests the user to input the ID of the digital key. On the ID input screen, the user enters the ID of the digital key for which they want to check the digital key information DDK into the in-vehicle device VD.
[0189] After displaying the ID input screen, the execution device 27 proceeds to step S92. In step S92, the execution device 27 determines whether or not the user has entered an ID. The execution device 27 determines that the user has entered an ID if the user has entered an ID within a certain period of time. The execution device 27 determines that the user has not entered an ID if the user has not entered an ID within a certain period of time. If the execution device 27 determines that the user has not entered an ID (step S92: NO), it terminates the series of processes shown in Figure 15. On the other hand, if the execution device 27 determines that the user has entered an ID (step S92: YES), it proceeds to step S93.
[0190] In step S93, the execution device 27 searches for the entered ID. At this time, the execution device 27 searches for the digital key indicated by the entered ID from among the digital keys indicated by the authentication information AT stored in the storage device 28. Alternatively, the execution device 27 may communicate with the management server 70, for example, and have the management server 70 search for the digital key indicated by the entered ID from among the digital keys in which the database DB stores information. After that, the execution device 27 proceeds to step S94.
[0191] In step S94, the execution device 27 determines whether or not there is a digital key corresponding to the input ID. If the execution device 27 finds the digital key indicated by the input ID after searching for the digital key, it determines that there is a digital key corresponding to the input ID. On the other hand, if the execution device 27 cannot find the digital key indicated by the input ID, it determines that there is no digital key corresponding to the input ID.
[0192] In step S94, if the execution device 27 determines that there is a corresponding digital key that has been entered (step S94: YES), it proceeds to step S95. In step S95, the execution device 27 displays the digital key information DDK for the digital key corresponding to the entered ID and the digital keys associated with that digital key. After that, the execution device 27 completes the series of processes shown in Figure 15.
[0193] In step S94, if the execution device 27 determines that there is no corresponding digital key entered (step S94: NO), it proceeds to step S96. In step S96, the execution device 27 displays on the display unit 29 that there is no digital key corresponding to the entered ID. After that, the execution device 27 terminates the series of processes shown in Figure 15.
[0194] <Specific display methods> Figure 16 shows a specific example of how the in-vehicle device VD of the second embodiment displays digital key information DDK. Below, we will explain a specific example of how the in-vehicle device VD of the second embodiment displays digital key information DDK, referring to Figure 16.
[0195] Figure 16 shows the display mode initially shown on the display unit 29 as a result of the in-vehicle device VD executing the series of processes shown in Figure 15, triggered by a request to display digital key information DDK to the in-vehicle device VD. Hereafter, the display mode shown in Figure 16 will be referred to as the fourth mode.
[0196] In Figure 16, the ID of the second digital key in the above hypothetical example is entered into the in-vehicle device VD. As shown in Figure 16, in the fourth embodiment, the in-vehicle device VD displays search content information SC. Search content information SC is information indicating the ID entered by the user into the in-vehicle device VD.
[0197] As shown in Figure 16, in the fourth embodiment, the in-vehicle device VD displays the device name information DDKN of the second digital key as the digital key information DDK. As shown in Figure 16, in the fourth embodiment, the in-vehicle device VD displays the number information DDN.
[0198] In the fourth embodiment, the entire rectangle surrounding the device name information DDKN is a button. In Figure 16, when the user presses the rectangle surrounding the device name information DDKN of the second digital key, the in-vehicle device VD displays the details of the digital key information DDK for the second digital key. When the user presses the rectangle surrounding the device name information DDKN of the second digital key, the display content of the display unit 29 transitions to the second mode shown in Figure 11. In the second embodiment, when the user presses the rectangle surrounding the device name information DDKN for the related digital key, the display content of the display unit 29 transitions to the third mode shown in Figure 12.
[0199] <Effects and Actions of the Second Embodiment> (2-1) The in-vehicle device VD of the second embodiment provides the effects of (1-1), (1-3) to (1-5) of the first embodiment.
[0200] (2-2) The vehicle 20 of the second embodiment provides the effects of (1-6) in the first embodiment. (2-3) The display method of the second embodiment produces the effects of (1-8) in the first embodiment.
[0201] (2-4) The display program PR of the second embodiment produces the effects of (1-9). (2-5) In the in-vehicle device VD of the second embodiment, the execution device 27, which is a processing circuit, displays the digital key information DDK for the digital key indicated by the identification information on the display unit 29 when it receives identification information for a digital key capable of controlling the vehicle 20.
[0202] When digital key identification information is entered into the in-vehicle device VD, it displays the digital key information DDK for the digital key indicated by that identification information. The in-vehicle device VD displays the digital key information DDK for the digital key for which the identification information was entered, out of all the digital key information DDKs for the vehicle 20. This allows the in-vehicle device VD to restrict the display of information about the owner of device 30.
[0203] (2-6) The vehicle 20 of the second embodiment is equipped with an on-board device VD. In the on-board device VD, the execution device 27, which is a processing circuit, when it receives identification information of a digital key capable of controlling the vehicle 20, displays the digital key information DDK for the digital key indicated by the identification information on the display unit 29.
[0204] When identification information for a digital key is entered, vehicle 20 displays the digital key information DDK for the digital key indicated by that identification information. Of all the digital key information DDKs for vehicle 20, vehicle 20 displays the digital key information DDK for the digital key for which the identification information was entered. This allows vehicle 20 to restrict the display of information about the owner of device 30.
[0205] (Third embodiment) The management system including the in-vehicle device of the third embodiment will be described below with reference to the drawings. In the third embodiment, the in-vehicle device VD differs from the first embodiment in that, when a request is made to display the digital key information DDK, it performs digital key authentication again and displays the digital key information DDK for the digital key for which authentication has been completed. In the following, the differences from the first embodiment will be described in detail, and the same points will be simplified or omitted.
[0206] <Processing performed by the in-vehicle device VD> Figure 17 shows the sequence of processes executed when the in-vehicle device VD displays digital key information DDK. The sequence of processes shown in Figure 17 is executed by the display program PR on the execution device 27 when an operation is made to request the in-vehicle device VD to display digital key information DDK.
[0207] As shown in Figure 17, when an operation is made to request the display of digital key information DDK from the in-vehicle device VD, the execution device 27 first executes the process in step S101. In the process of step S101, the execution device 27 authenticates the digital key.
[0208] At this time, the execution device 27 performs digital key authentication in the manner shown in Figure 8. First, the execution device 27 communicates with devices within range of the vehicle 20 that are capable of BLE or NFC communication via BLE or NFC communication, and receives key information DK from device 30. At this time, device 30 transmits the key information DK stored in the storage device 37.
[0209] Subsequently, the execution device 27 authenticates the digital key in the same manner as the process in step S61 of Figure 8. That is, the execution device 27 compares the received key information DK with the authentication information AT stored in the storage device 28 to confirm whether the digital key indicated by the key information DK is a digital key that can legitimately control the vehicle 20. When the execution device 27 determines that the digital key indicated by the received key information DK is a digital key that can legitimately control the vehicle 20, the authentication of the digital key is completed.
[0210] As shown in Figure 17, the execution device 27 performs the process in step S102 after authenticating the digital key. In the process in step S102, the execution device 27 determines whether or not there is a digital key that has been authenticated.
[0211] If the execution device 27 determines in step S102 that there are no digital keys that have been authenticated (step S102: NO), it terminates the series of processes shown in Figure 17. In other words, if there are no digital keys that have been authenticated through the process in step S101, the execution device 27 does not display the digital key information DDK.
[0212] If the execution device 27 determines in step S102 that there is a digital key that has been authenticated (step S102: YES), it proceeds to step S103. In step S103, the execution device 27 displays the digital key information DDK for the authenticated digital key and related digital keys on the display unit 29. After that, the execution device 27 completes the series of processes shown in Figure 17.
[0213] When an operation is performed to request the display of digital key information DDK, the in-vehicle device VD executes a series of processes shown in Figure 17, and then displays the digital key information DDK for the digital keys that have been authenticated and the digital keys associated with those digital keys. At this time, the in-vehicle device VD displays the digital key information DDK for the digital keys that have been authenticated and the digital keys associated with those digital keys, based on the first to third embodiments shown in Figures 10 to 12.
[0214] In the first embodiment, a list of device name information DDKNs for digital keys that have been authenticated is displayed. In the second embodiment, the details of the digital key information DDK for the authenticated digital keys and a list of device name information DDKNs for the associated digital keys are displayed. In the third embodiment, the details of the digital key information DDK for the associated digital keys are displayed.
[0215] <Effects and Actions of the Third Embodiment> (3-1) The in-vehicle device VD of the third embodiment provides the effects of (1-1), (1-3) to (1-5) of the first embodiment.
[0216] (3-2) The vehicle 20 of the third embodiment provides the effects of (1-6) in the first embodiment. (3-3) The display method of the third embodiment produces the effect of (1-8) in the first embodiment.
[0217] (3-4) The display program PR of the third embodiment produces the effects of (1-9). (3-5) In the in-vehicle device VD of the third embodiment, the execution device 27, which is a processing circuit, performs communication with the device 30 when it is requested to display digital key information DDK. When the execution device 27 displays the digital key information DDK, it performs the operation of displaying the digital key information DDK for the digital keys that have been authenticated through communication with the device 30, out of all the digital key information DDK for the vehicle 20.
[0218] When the in-vehicle device VD is requested to display the digital key information DDK, it communicates with the communicable device 30. The in-vehicle device VD then displays the digital key information DDK for the digital key whose authentication has been completed through the communication. This allows the in-vehicle device VD to restrict the display of information about the owner of device 30.
[0219] (3-6) The vehicle 20 of the third embodiment is equipped with an on-board device VD. In the on-board device VD, the execution device 27, which is a processing circuit, performs communication with the device 30 when it is requested to display digital key information DDK. When the execution device 27 displays the digital key information DDK, it performs the operation of displaying the digital key information DDK for the digital keys that have been authenticated through communication with the device 30, out of all the digital key information DDK for the vehicle 20.
[0220] When requested to display the digital key information DDK, vehicle 20 communicates with a communicable device 30. Vehicle 20 then displays the digital key information DDK for the digital key whose authentication has been completed through the communication. This allows vehicle 20 to restrict the display of information about the owner of device 30.
[0221] (Other embodiments) Each of the above embodiments can be implemented with the following modifications. Each embodiment and the following modifications can be combined with each other to the extent that they do not contradict each other technically.
[0222] <Management System 10> Vehicle 20 does not necessarily have to have some of the BLE module 23, UWB module 24, and NFC module 25. Vehicle 20 can perform short-range communication with device 30 if it has at least one of these modules. Furthermore, vehicle 20 is not limited to these modules, and may have any module that can perform short-range communication with device 30.
[0223] • The matters concerning digital keys in each of the above embodiments do not have to comply with CCC. The vehicle management device 26 is not limited to a digital key ECU. For example, it may be a central ECU that manages multiple ECUs in a vehicle 20.
[0224] The vehicle management device 26 may be configured as a circuit including one or more processors that execute various processes according to a computer program (software). Alternatively, the vehicle management device 26 may be configured as a circuit including one or more dedicated hardware circuits, such as application-specific integrated circuits (ASICs), or a combination thereof, that execute at least some of the various processes. The processor includes a CPU and memory such as RAM and ROM. The memory stores program code or instructions configured to cause the CPU to execute the processes. Memory, i.e., computer-readable media, includes any available media that can be accessed by a general-purpose or dedicated computer. The same applies to device 30 and management server 70.
[0225] The Friend Device 51 is not limited to smartphones and smartwatches. For example, the Friend Device 51 may be a predetermined server. The share device 50 has the function of receiving the share key KS, as in the embodiment described above. A device 30 that has the function of receiving a digital key, like the share device 50, is sometimes called a receiver device.
[0226] In each of the embodiments described above, the digital keys have a hierarchy in the order of owner key KO, friend key KF, and non-friend key KN, with higher levels of authority assigned to each key. However, the digital keys do not necessarily have to be configured so that higher levels of authority assign to each key. For example, the same level of authority may be assigned to all three levels: owner key KO, friend key KF, and non-friend key KN.
[0227] The device server 60 does not need to be provided for each type of device 30. It is sufficient that multiple devices 30 and the management server 70 can communicate wirelessly. The device server 60 may be omitted. It is sufficient that multiple devices 30 and the management server 70 can communicate wirelessly directly.
[0228] The management server 70 may consist of multiple servers. For example, it may consist of a server that stores a database DB and a server that executes the server program PS. Alternatively, it may consist of a server that communicates with the vehicle 20 and a server that communicates with the device server 60, and these servers may be able to communicate with each other.
[0229] The management server 70 does not need to store a database DB. The management server 70 only needs to manage the combination of the key information DK of the device 30 and the authentication information AT of the vehicle management device 26 for at least one digital key in the management system 10.
[0230] <Information about various types of information> The authentication information AT is not limited to the examples of the above embodiments, as long as it is information used to authenticate a digital key when using the digital key. For example, the authentication information AT may be a common key shared between the vehicle management device 26 and the device 30. Alternatively, the authentication information AT may be a common secret key.
[0231] The structure of the information included in the key information DK is not limited to the examples of the above embodiment. For example, the owner key information DKO does not have to have the slot identification information ST4. Also, for example, the key information DK may have information indicating the type of digital key. The type of digital key is, for example, information indicating one of the owner key KO, friend key KF, and non-friend key KN.
[0232] The database DB may include information indicating the type of device 30. The type of device 30 is information indicating one of the following, for example, a smartphone, a smartwatch, and a predetermined server as in the modified example above.
[0233] The structure of the data DA in the database DB is not limited to the examples of the embodiments described above. The database DB only needs to contain the information necessary for the management server 70 to manage in the management system 10.
[0234] In a database (DB), privileges are not uniformly defined according to the type of digital key, but may be set for each digital key. Furthermore, privileges may not be defined at all in a database (DB).
[0235] The series of processes for registering the owner key KO is not limited to the examples of the embodiments described above. For example, even if pairing is not performed by the process in step S12, the owner device 40 may store the owner key information DKO by having the vehicle 20 and the first device 30A send and receive information such as generated data DC via the management server 70. The series of processes for registering the owner key KO may be modified as appropriate to match the structure of the information contained in the owner key information DKO and the structure of the information contained in the authentication information AT.
[0236] The series of processes for registering the friend key KF is not limited to the examples of the embodiments described above. For example, the management server 70 may update the database DB by the process in step S29 after sending the authentication package ATP and storage request D24 to the vehicle 20. The series of processes for registering the friend key KF may be modified as appropriate to match the structure of the information contained in the friend key information DKF and the structure of the information contained in the authentication information AT.
[0237] The series of processes for registering a non-friend key KN is not limited to the examples of the embodiments described above. The order of the processes may differ from the series of processes for registering a friend key KF. The series of processes for registering a non-friend key KN may be modified as appropriate to match the structure of the information contained in the non-friend key information DKN and the structure of the information contained in the authentication information AT.
[0238] The types of digital keys do not necessarily include non-friend keys (KN). In other words, in the management system 10, the share key (KS) may consist only of friend keys (KF). Non-friend device 52 may send a request to register a new non-friend key KN. In other words, share device 50 may send a request to register a new non-friend key KN, regardless of whether it is friend device 51 or non-friend device 52. In this case, management system 10 can register the new non-friend key KN by the series of processes shown in Figure 7.
[0239] <Display methods by the in-vehicle VD device> In the first to third embodiments, the digital key information DDK for the relevant digital key is displayed. The in-vehicle device VD does not need to display the digital key information DDK for the relevant digital key.
[0240] In the first to third embodiments, the in-vehicle device VD displays the number information DDN when displaying the digital key information DDK. The in-vehicle device VD does not need to display the number information DDN.
[0241] In the first to third embodiments, the in-vehicle device VD displays only the status notification MS for digital keys for which it has determined that the digital key information DDK can be displayed. The in-vehicle device VD may display the status notification MS regardless of whether or not the digital key information DDK can be displayed.
[0242] In the first to third embodiments, the in-vehicle device VD displays a status notification MS. The in-vehicle device VD does not need to display a status notification MS. The manner in which the in-vehicle device VD displays the digital key information DDK in the second embodiment can be combined with that of the first embodiment. In this case, the in-vehicle device VD displays the digital key information DDK for the owner using the vehicle 20, and when an ID is entered, it displays the digital key information DDK for the digital key indicated by the ID.
[0243] The manner in which the in-vehicle device VD displays the digital key information DDK in the second embodiment can be combined with that of the third embodiment. In this case, the in-vehicle device VD displays the digital key information DDK of digital keys for which authentication has been completed, and when an ID is entered, it displays the digital key information DDK of the digital key indicated by the ID.
[0244] In the second embodiment, the user inputs the digital key ID as the digital key identification information into the in-vehicle device VD. The identification information that the user inputs into the in-vehicle device VD does not have to be an ID. For example, the user may input the device name or the name of the owner of device 30 into the in-vehicle device VD as the digital key identification information.
[0245] The in-vehicle device VD may, under certain conditions, display all digital key information DDK for the vehicle 20 without restricting the display of digital key information DDK. Figure 18 is a flowchart showing the sequence of processes performed by the in-vehicle device VD in the first modification example. The sequence of processes shown in Figure 18 is executed by the execution device 27, as instructed by the display program PR.
[0246] The first modification is applicable to the first to third embodiments. When the first modification is applied to the first embodiment, the execution device 27 executes the series of processes shown in Figure 18 before executing the series of processes shown in Figure 9 when an operation is made to request the display of digital key information DDK. When the first modification is applied to the second embodiment, the execution device 27 executes the series of processes shown in Figure 18 before executing the series of processes shown in Figure 15 when an operation is made to request the display of digital key information DDK. When the first modification is applied to the third embodiment, the execution device 27 executes the series of processes shown in Figure 18 before executing the series of processes shown in Figure 17 when an operation is made to request the display of digital key information DDK.
[0247] When the series of processes shown in Figure 18 is started, the execution device 27 first executes the process in step S111. In the process of step S111, the execution device 27 determines in the management system 10 whether or not the owner device 40 is a server.
[0248] As mentioned above, the owner device 40 may be a mobile information terminal or a server. The execution device 27 determines whether the owner device 40 is a server or not based on the authentication information AT stored in the storage device 28, for example. The execution device 27 may, for example, communicate with the owner device 40 and query the owner device 40 to determine whether it is a server or not. The execution device 27 may, for example, communicate with the management server 70 and query the owner device 40 to determine whether it is a server or not.
[0249] If the execution device 27 determines in step S111 that the owner device 40 is a server (step S111: YES), it proceeds to step S112. In step S112, the execution device 27 determines to restrict the display of the digital key information DDK. After that, the execution device 27 terminates the series of processes shown in Figure 18.
[0250] When the embodiment of the first modification is applied to the first embodiment, the execution device 27 executes the process in step S112, and then executes the series of processes shown in Figure 9. When the embodiment of the first modification is applied to the second embodiment, the execution device 27 executes the process in step S112, and then executes the series of processes shown in Figure 15. When the embodiment of the first modification is applied to the third embodiment, the execution device 27 executes the process in step S112, and then executes the series of processes shown in Figure 17.
[0251] If the execution device 27 determines in step S111 that the owner device 40 is not a server (step S111: NO), it proceeds to step S113. In step S113, the execution device 27 determines that it will not restrict the display of the digital key information DDK. After that, the execution device 27 terminates the series of processes shown in Figure 18.
[0252] When the first modified example is applied to the first embodiment, the execution device 27 displays all digital key information DDK for the vehicle 20 without performing the series of processes shown in Figure 9 after executing the process in step S113. When the first modified example is applied to the second embodiment, the execution device 27 displays all digital key information DDK for the vehicle 20 without performing the series of processes shown in Figure 15 after executing the process in step S113. When the first modified example is applied to the third embodiment, the execution device 27 displays all digital key information DDK for the vehicle 20 without performing the series of processes shown in Figure 17 after executing the process in step S113.
[0253] In this case, the execution device 27, which is a processing circuit, displays all digital key information DDKs for the vehicle 20 if the owner device 40, which is one of the devices 30 belonging to the owner of the vehicle 20, is a portable information terminal owned by the owner. If the owner device 40 is a server belonging to the owner and is a server that generates digital keys for other devices in response to requests from those devices, the execution device 27 displays only the digital key information DDKs for some owners out of all the digital key information DDKs for the vehicle 20.
[0254] The owner device 40 may be a server contracted by the owner. Such an owner device 40 is not used to perform operations such as unlocking the vehicle 20, but mainly to generate the share key KS. Therefore, if the owner device 40 is a server, it is likely that many share key KS will be generated. The owner of the device 30 that stores information about the share key KS may not want their own digital key information DDK to be displayed on the in-vehicle device VD, especially in this situation.
[0255] The in-vehicle device VD switches whether or not to restrict the display of the digital key information DDK depending on the type of owner device 40. This allows the in-vehicle device VD to restrict the display of the digital key information DDK when the owner of device 30 does not particularly want their own digital key information DDK to be displayed on the in-vehicle device VD.
[0256] Figure 19 is a flowchart showing the sequence of processes performed by the in-vehicle device VD in the second modification example. The sequence of processes shown in Figure 19 is executed by the execution device 27, as instructed by the display program PR.
[0257] The aspects of the second modification are applicable to the first to third embodiments. When the aspects of the second modification are applied to the first embodiment, the execution device 27 executes the series of processes shown in Figure 18 before executing the series of processes shown in Figure 9 when an operation is made to request the display of digital key information DDK. When the aspects of the second modification are applied to the second embodiment, the execution device 27 executes the series of processes shown in Figure 18 before executing the series of processes shown in Figure 15 when an operation is made to request the display of digital key information DDK. When the aspects of the second modification are applied to the third embodiment, the execution device 27 executes the series of processes shown in Figure 18 before executing the series of processes shown in Figure 17 when an operation is made to request the display of digital key information DDK.
[0258] When the series of processes shown in Figure 19 is initiated, the execution device 27 first executes the process in step S121. In the process of step S121, the execution device 27 displays a password input screen on the display unit 29. In the second modification example, a password has been set in advance. The password input screen is a screen that requests the user to enter a password.
[0259] After displaying the password input screen, the execution device 27 executes the process in step S122. In the process of step S122, the execution device 27 determines whether the user has successfully entered the password.
[0260] The execution device 27 determines that the user has successfully entered the password when information such as a character string input by the user matches the password. On the other hand, the execution device 27 determines that the user has successfully entered the password when information such as a character string input by the user does not match the password. For example, the execution device 27 may provide a button on the password input screen for the user to press when the user does not know the password, and may determine that the user has failed to enter the password when the button is pressed. For example, the execution device 27 may determine that the user has failed to enter the password when no password is input within a predetermined period of time.
[0261] In the process of step S122, when the execution device 27 determines that the user has failed to enter the password (step S122: NO), the execution device 27 proceeds the process to step S123. In the process of step S123, the execution device 27 determines to restrict the display of the digital key information DDK. Thereafter, the execution device 27 ends the series of processes shown in FIG. 19.
[0262] When the aspect of the second modification is applied to the first embodiment, the execution device 27 executes the series of processes shown in FIG. 9 after executing the process of step S123. When the aspect of the second modification is applied to the second embodiment, the execution device 27 executes the series of processes shown in FIG. 15 after executing the process of step S123. When the aspect of the second modification is applied to the third embodiment, the execution device 27 executes the series of processes shown in FIG. 17 after executing the process of step S123.
[0263] In the process of step S122, when the execution device 27 determines that the user has successfully entered the password (step S122: YES), the execution device 27 proceeds the process to step S124. In the process of step S124, the execution device 27 determines not to restrict the display of the digital key information DDK. Thereafter, the execution device 27 ends the series of processes shown in FIG. 19.
[0264] When the embodiment of the second modification is applied to the first embodiment, the execution device 27 displays all digital key information DDK for the vehicle 20 without performing the series of processes shown in Figure 9 after executing the process in step S124. When the embodiment of the second modification is applied to the second embodiment, the execution device 27 displays all digital key information DDK for the vehicle 20 without performing the series of processes shown in Figure 15 after executing the process in step S124. When the embodiment of the second modification is applied to the third embodiment, the execution device 27 displays all digital key information DDK for the vehicle 20 without performing the series of processes shown in Figure 17 after executing the process in step S124.
[0265] In this case, the execution device 27, which is a processing circuit, displays all digital key information (DDK) for the vehicle 20, provided that a specific password has been entered. A user may want to view all the digital key information DDK for vehicle 20. The in-vehicle device VD displays all the digital key information DDK for vehicle 20, subject to the input of a password. This allows the in-vehicle device VD to display all the digital key information DDK for vehicle 20 when necessary, while restricting the display of information about the owner of device 30.
[0266] Figure 20 is a flowchart showing the sequence of processes performed by the in-vehicle device VD in the third modification example. The sequence of processes shown in Figure 20 is executed by the execution device 27, as instructed by the display program PR.
[0267] The third modification is applicable to the first to third embodiments. When the first modification is applied to the first embodiment, the execution device 27 executes the series of processes shown in Figure 20 before executing the series of processes shown in Figure 9 when an operation is made to request the display of digital key information DDK. When the third modification is applied to the second embodiment, the execution device 27 executes the series of processes shown in Figure 20 before executing the series of processes shown in Figure 15 when an operation is made to request the display of digital key information DDK. When the third modification is applied to the third embodiment, the execution device 27 executes the series of processes shown in Figure 20 before executing the series of processes shown in Figure 17 when an operation is made to request the display of digital key information DDK.
[0268] When the series of processes shown in Figure 20 is started, the execution device 27 first executes the process in step S131. In the process of step S131, the execution device 27 determines whether or not the authentication of the owner key KO has been completed.
[0269] As shown and explained in Figure 8, after the in-vehicle device VD receives key information DK from device 30 via BLE communication or NFC communication, it stores that the digital key authenticated based on the key information DK is valid. In step S131, the execution device 27 checks the storage device 28 and determines that authentication for the owner key KO is complete if the owner device 40 is among the valid devices 30. On the other hand, in step S131, the execution device 27 checks the storage device 28 and determines that authentication for the owner key KO is not complete if the owner device 40 is not among the valid devices 30.
[0270] Furthermore, for example, when requested to display digital key information DDK, the execution device 27 may attempt BLE communication or NFC communication with the owner device 40. In this case, the execution device 27 receives owner key information DKO from the owner device 40 and determines that authentication of the owner key KO is complete if authentication of the owner key KO is completed based on the owner key information DKO. On the other hand, the execution device 27 determines that authentication of the owner key KO is not complete if BLE communication or NFC communication with the owner device 40 is not possible, or if authentication of the owner key KO is not completed based on the owner key information DKO.
[0271] In step S131, if the execution device 27 determines that the authentication of the owner key KO is not complete (step S131: NO), it proceeds to step S132. In step S132, the execution device 27 determines to restrict the display of the digital key information DDK. After that, the execution device 27 terminates the series of processes shown in Figure 20.
[0272] When the third modified example is applied to the first embodiment, the execution device 27 executes the process in step S132, and then executes the series of processes shown in Figure 9. When the third modified example is applied to the second embodiment, the execution device 27 executes the process in step S132, and then executes the series of processes shown in Figure 15. When the third modified example is applied to the third embodiment, the execution device 27 executes the process in step S132, and then executes the series of processes shown in Figure 17.
[0273] In step S131, if the execution device 27 determines that the authentication of the owner key KO is complete (step S131: YES), it proceeds to step S133. In step S133, the execution device 27 determines that it will not restrict the display of the digital key information DDK. After that, the execution device 27 terminates the series of processes shown in Figure 20.
[0274] When the third modified example is applied to the first embodiment, the execution device 27 displays all digital key information DDK for the vehicle 20 without performing the series of processes shown in Figure 9 after executing the process in step S133. When the third modified example is applied to the second embodiment, the execution device 27 displays all digital key information DDK for the vehicle 20 without performing the series of processes shown in Figure 15 after executing the process in step S133. When the third modified example is applied to the third embodiment, the execution device 27 displays all digital key information DDK for the vehicle 20 without performing the series of processes shown in Figure 17 after executing the process in step S133.
[0275] In this case, the execution device 27, which is a processing circuit, performs the action of communicating with the device 30. If the authentication of the owner device 40, which is the device 30 belonging to the owner of the vehicle 20, is completed through communication with the device 30, the execution device 27 performs the action of displaying all digital key information DDK for the vehicle 20.
[0276] The owner of vehicle 20 may want to view all the digital key information (DDK) for their vehicle 20. The in-vehicle device VD displays all the digital key information (DDK) for vehicle 20 once the owner device 40 has been authenticated. This allows the in-vehicle device VD to display all the digital key information (DDK) for vehicle 20 to the owner while restricting the display of information about the owner of device 30.
[0277] In the first modified example, the in-vehicle device VD restricts the display of the digital key information DDK when it determines that the owner device 40 is a server (step S111: YES). At this time, after executing the process in step S112, the in-vehicle device VD restricts the display of the digital key information DDK by executing a series of processes shown in Figure 9, Figure 15, or Figure 17. The manner in which the in-vehicle device VD restricts the display of the digital key information DDK is not limited to the manner in the first modified example. For example, the in-vehicle device VD may adopt a manner in which, when the owner device 40 is a server, it does not display the digital key information DDK for the owner key KO, but displays all the digital key information DDKs for other digital keys.
[0278] The criteria for determining whether the in-vehicle device VD will restrict the display of digital key information DDK are not limited to the embodiments shown in the first to third modification examples. For example, the in-vehicle device VD may perform biometric authentication when requested to display digital key information DDK, and then determine not to restrict the display of digital key information DDK once biometric authentication is complete.
[0279] [Note] The technical concepts that can be understood from the above embodiments and modified examples are described below. [Note 1] An in-vehicle device installed in a vehicle that can be controlled by each digital key registered for each of a plurality of devices, comprising a processing circuit and a display unit, wherein the processing circuit displays digital key information on the display unit, which is information relating to the digital key and includes information indicating the owner of the device corresponding to the digital key, and performs the function of displaying only the digital key information for some of the owners out of all the digital key information for the vehicle.
[0280] [Supplementary Note 2] The in-vehicle apparatus according to Supplementary Note 1, wherein the processing circuit executes: communicating with the device; determining that the owner of the device is using the vehicle when authentication of the digital key registered for the device is completed through communication with the device; and, when displaying the digital key information, displaying the digital key information for the owner who is using the vehicle among all the digital key information for the vehicle.
[0281] [Supplementary Note 3] The in-vehicle apparatus according to Supplementary Note 1 or 2, wherein the processing circuit executes, when identification information of the digital key capable of controlling the vehicle is input, displaying the digital key information for the digital key indicated by the identification information on the display unit.
[0282] [Supplementary Note 4] The in-vehicle apparatus according to any one of Supplementary Notes 1 to 3, wherein the processing circuit executes: communicating with the device when a request to display the digital key information is received; and, when displaying the digital key information, displaying the digital key information for the digital key for which authentication has been completed through communication with the device among all the digital key information for the vehicle.
[0283] [Supplementary Note 5] The in-vehicle apparatus according to any one of Supplementary Notes 2 to 4, wherein the digital key is capable of generating other digital keys, and the processing circuit executes, when displaying digital key information for a specific digital key, displaying at least one of the digital key information of the digital key that generated the specific digital key and the digital key information of the digital key generated by the specific digital key, in addition to the digital key information of the specific digital key.
[0284] [Note 6] The in-vehicle device according to any one of Notes 1 to 5, wherein the processing circuit performs the following: if the owner device, which is one of the devices belonging to the owner of the vehicle, is a portable information terminal owned by the owner, it displays all of the digital key information for the vehicle; and if the owner device is a server belonging to the owner, which generates the digital key for other devices in response to requests from other devices, it displays only some of the digital key information for the owner out of all the digital key information for the vehicle.
[0285] [Note 7] The in-vehicle device according to any one of Notes 1 to 6, wherein the processing circuit displays all of the digital key information for the vehicle, provided that a specific password has been entered.
[0286] [Note 8] The in-vehicle device according to any one of Notes 1 to 7, wherein the processing circuit performs the following: communicates with the device, and, if authentication of the owner device, which is the device belonging to the owner of the vehicle, is completed through communication with the device, displays all of the digital key information for the vehicle.
[0287] [Note 9] The in-vehicle device according to any one of Notes 1 to 8, wherein the processing circuit displays the number of digital keys capable of controlling the vehicle when displaying the digital key information.
[0288] [Note 10] An in-vehicle device according to any one of Notes 1 to 9, wherein the device is configured to display a notification on the display unit when there is a change in the state of the digital key, and the processing circuit, when displaying a notification, determines to display the notification on the display unit if the notification is for a digital key that displays the digital key information, and determines not to display the notification on the display unit if the notification is for a digital key that does not display the digital key information.
[0289] [Note 11] A vehicle equipped with any one of the on-board devices described in Note 1 to Note 10. [Explanation of Symbols]
[0290] 10…Management System 20... Vehicles 22…HMI 26... Vehicle management system 27… Execution device 28…Storage device 29…Display section 30…Device 36…Execution device 37…Storage device 40… Owner devices 50… Shared devices 51... Friend Device 52... Non-Friendly Devices 60…Device Server 70... Management Server AT... Authentication information DDK…Digital Key Information DDN... Number of units information DK...Key Information DKO... Owner Key Information DKS... Share Key Information KF...Friend Key KN... Non-Friend Key KO... Owner Key KS... Share Key MS... Status Notification PR…Display Program VD…Vehicle device
Claims
1. An in-vehicle device installed in a vehicle, which can be controlled by each digital key registered for each of multiple devices, It comprises a processing circuit and a display unit, The processing circuit, when displaying digital key information on the display unit, which is information relating to the digital key and includes information indicating the owner of the device corresponding to the digital key, performs the operation of displaying only the digital key information for some of the owners out of all the digital key information for the vehicle. In-vehicle device.
2. The aforementioned processing circuit is To communicate with the aforementioned device, Through communication with the device, when authentication of the digital key registered for the device is completed, it is determined that the owner of the device is using the vehicle. When displaying the digital key information, the digital key information of the owner currently using the vehicle is displayed from among all the digital key information for the vehicle. The in-vehicle device according to claim 1.
3. When the processing circuit receives identification information for the digital key capable of controlling the vehicle, it performs the following actions: display the digital key information for the digital key indicated by the identification information on the display unit. The in-vehicle device according to claim 1.
4. The aforementioned processing circuit is When requested to display the aforementioned digital key information, the device communicates with the device, When displaying the aforementioned digital key information, the digital key information of the digital key that has been authenticated through communication with the device, out of all the aforementioned digital key information for the vehicle, is displayed. The in-vehicle device according to claim 1.
5. The aforementioned digital key is capable of generating other such digital keys. The processing circuit, when displaying the digital key information for a specific digital key, displays, in addition to the digital key information for that digital key, at least one of the digital key information for the digital key that generated the digital key and the digital key information for the digital key generated by that digital key. The in-vehicle device according to any one of claims 2 to 4.
6. The aforementioned processing circuit is If the owner device, which is one of the devices belonging to the owner of the vehicle, is a personal information terminal owned by the owner, then all of the digital key information for the vehicle will be displayed. If the owner device is a server belonging to the owner and is a server that generates the digital key for a device in response to a request from another device, then the device will display only the digital key information for some of the owners out of all the digital key information for the vehicle. An in-vehicle device according to any one of claims 1 to 4.
7. The processing circuit, on the condition that a specific password is entered, performs the action of displaying all of the digital key information for the vehicle. An in-vehicle device according to any one of claims 1 to 4.
8. The aforementioned processing circuit is To communicate with the aforementioned device, If authentication of the owner device, which is the device belonging to the owner of the vehicle, is completed through communication with the aforementioned device, then the following actions will be performed: display all the aforementioned digital key information for the vehicle. An in-vehicle device according to any one of claims 1 to 4.
9. The processing circuit displays the number of digital keys capable of controlling the vehicle when displaying the digital key information. An in-vehicle device according to any one of claims 1 to 4.
10. The system is configured to display a notification on the display unit when there is a change in the state of the digital key. The aforementioned processing circuit is When displaying a notification, if the notification concerns the digital key that displays the digital key information, it is determined that the notification should be displayed on the display unit. When displaying a notification, if the notification concerns a digital key for which the digital key information is not displayed, the system determines that the notification will not be displayed on the display unit. An in-vehicle device according to any one of claims 1 to 4.
11. A vehicle equipped with the in-vehicle device described in any one of claims 1 to 4.
12. An in-vehicle device installed in a vehicle that can be controlled by each digital key registered for each of multiple devices, is a display method for displaying digital key information on a display unit, which includes information relating to the digital key and information indicating the owner of the device corresponding to the digital key. The step includes displaying only the digital key information for some of the owners out of all the digital key information for the vehicle. Display method.
13. A display program executed by the processing circuit of an in-vehicle device installed in a vehicle, which can be controlled by each digital key registered for each of multiple devices. When the in-vehicle device displays digital key information on a display unit, which is information relating to the digital key and includes information indicating the owner of the device corresponding to the digital key, the processing circuit is instructed to display only the digital key information for some of the owners out of all the digital key information for the vehicle. Display program.
Citation Information
Patent Citations
Information processing device, processing method, and program
JP2024001720A