Electronic key system

The electronic key system addresses the balance between user convenience and security by implementing a composite authentication process with multiple operation criteria and a simple authentication option for proximity unlocking, effectively preventing relay attacks and enhancing user experience.

JP7684175B2Active Publication Date: 2025-05-27SUBARU CORP
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
JP2021159663
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-09-29
Publication Date
2025-05-27
Estimated Expiration
2041-09-29

AI Technical Summary

Technical Problem

Existing electronic key systems face challenges in balancing user convenience and security, particularly in preventing relay attacks while simplifying the unlocking process.

Method used

An electronic key system that employs a composite authentication process requiring key information, first operation information, and second operation information for unlocking, while allowing a simple authentication process during a set time period or when the user is near the lock target.

Benefits of technology

The system enhances user convenience by simplifying the unlocking process when the user is near the vehicle, while maintaining sufficient security through multiple authentication layers, effectively preventing relay attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007684175000001
    Figure 0007684175000001
  • Figure 0007684175000002
    Figure 0007684175000002
  • Figure 0007684175000003
    Figure 0007684175000003
Patent Text Reader

Abstract

To ensure sufficient security without compromising user convenience.SOLUTION: An electronic key system of the present invention causes one or a plurality of processors to execute: a composite authentication process to permit unlocking of a door unit on the condition that key information output from a portable device conforms to registered key information, an operation of a user with respect to the portable device conforms to registered first operation information, and the operation conforms to registered second operation information; and a simple authentication process to permit unlocking of the door unit on the condition that the key information conforms to the registered key information during a period from when the door unit is locked until a set time elapses, or during a period from when the door unit is locked until the portable device is located outside an authentication notification area.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an electronic key system that controls locking and unlocking of a lock target according to an authentication result.

Background Art

[0002] An electronic key system that locks and unlocks a vehicle door by wireless communication with a portable device is known. According to this electronic key system, for example, when the portable device held by the user is within the communication range with the vehicle, the vehicle can be locked and unlocked by a simple operation such as touching the door handle without the user inputting an operation on the operation unit of the portable device.

[0003] Here, in order to prevent crimes such as a so-called relay attack in which a user tries to unlock a vehicle illegally by establishing communication between a portable device outside the communication range and the vehicle using a repeater while observing that the user has left the vehicle, technologies have been proposed.

[0004] For example, Patent Document 1 discloses a technique for preventing a relay attack by imposing user authentication by detecting a tapping operation on a portable device as a condition for permitting locking and unlocking of a vehicle door.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] In such an electronic key system, of course, security against illegal unlocking due to a relay attack or the like as disclosed in the above Patent Document 1 is ensured, but at the same time, improvement in convenience in the user's unlocking operation is also desired.

[0007] The present invention has been made in view of the above circumstances, and an object thereof is to provide an electronic key system that improves user convenience and ensures sufficient security.

Means for Solving the Problems

[0008] An electronic key system according to an embodiment of the present invention includes a door unit provided for an object to be locked, an installation device provided for the object to be locked, a portable device that can communicate with the installation device in an authentication notification area and can be held by a user, one or more processors, and a storage medium in which a program executed by the one or more processors is stored. The program includes one or more instructions, and the instructions cause the one or more processors to perform a composite authentication process for permitting unlocking of the door unit on the condition that key information output from the portable device conforms to registered key information registered in advance, the user's operation conforms to registered first operation information registered in advance, and the operation conforms to registered second operation information registered in advance. A simple authentication process for permitting unlocking of the door unit on the condition that the key information conforms to the registered key information during a set time period after the door unit is locked or until the portable device is located outside the authentication notification area after the door unit is locked.

[0009] Thus, normally, in addition to conforming to the registered key information, conditions such as conforming to the registered first operation information and conforming to the registered second operation information are imposed for permission to unlock. However, during a period from when the door unit is locked until the set time period elapses, or during a period from when the door unit is locked until the portable device is located outside the authentication notification area, in a situation where the user is assumed to be near the object to be locked, conditions such as conforming to the registered first operation information and conforming to the registered second operation information are not imposed for permission to unlock.

Effects of the Invention

[0010] According to the present invention, it is possible to provide an electronic key system that improves user convenience and ensures sufficient security.

Brief Description of the Drawings

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Modes for Carrying Out the Invention

[0012] Hereinafter, embodiments will be described with reference to FIGS. 1 to 7. Note that, among the configurations described in the drawings referred to in the description of the present embodiment, there are some that schematically show the necessary parts and the surrounding configurations for realizing the present embodiment.

[0013] <1. Configuration Example of Electronic Key System> The configuration of the electronic key system 1 according to the present embodiment will be described with reference to FIGS. 1 and 2.

[0014] As shown in FIG. 1, the electronic key system 1 includes a portable device 2 that can be held by a user, an in-vehicle device 3 as an installation device provided in a vehicle 10 to be locked, and a door unit 4 provided in a door of the vehicle 10. The portable device 2 and the in-vehicle device 3 are capable of communicating with each other.

[0015] Here, various types of vehicles such as a vehicle equipped with an internal combustion engine, an electric vehicle, and a hybrid vehicle can be applied to the vehicle 10.

[0016] In this electronic key system 1, the door unit 4 is locked by an operation on the operation unit 25 (see FIG. 2) of the portable device 2 or contact with the door handle of the vehicle 10.

[0017] The door unit 4 of the vehicle 10 is unlocked according to the operation by the user of the operation unit 25. However, when the portable device 2 is within the communication range of the in-vehicle device 3, the door unit 4 is unlocked on the condition that the vibration waveform signal of the user's motion detected by the motion sensor 22 of the portable device 2 matches the vibration waveform signal in the registered motion information registered in advance within a predetermined error range. For example, when the user performs a specific operation while approaching the vehicle 10, the door unit 4 can be unlocked without operating the operation unit 25 of the portable device 2.

[0018] The portable device 2 is composed of, for example, a smartphone or a dedicated electronic key. As shown in FIG. 2, the portable device 2 includes a radio wave receiving unit 21, a motion sensor 22, a notification unit 23, a portable device control unit 24, an operation unit 25, and a radio wave transmitting unit 26.

[0019] The radio wave receiving unit 21 is composed of a receiver for receiving a modulated signal obtained by modulating a preset polling signal from the in-vehicle device 3. The modulated signal includes a first modulated signal and a second modulated signal. The first modulated signal is, for example, an LF (Low Frequency) signal, and the second modulated signal is a signal equivalent to, for example, an LF signal whose propagation range is wider than that of the first communication signal. The radio wave receiving unit 21 receives the first modulated signal and the second modulated signal from the in-vehicle device 3.

[0020] FIG. 3 schematically shows an area near the object to be locked, denoted as area AR1, within which the radio wave receiving unit 21 can receive the first modulation signal from the in-vehicle device 3. The area near the object to be locked, area AR1, is set, for example, to a radius of about 2 m from the in-vehicle device 3. This area near the object to be locked, area AR1, is an area where unlocking by so-called smart access can be performed. By the radio wave receiving unit 21 regularly receiving the first modulation signal from the in-vehicle device 3, it can be determined that the portable device 2 is located within the area near the object to be locked, area AR1. Also in this figure, the area within which the radio wave receiving unit 21 can receive the second modulation signal from the in-vehicle device 3 is schematically shown as an authentication notification area AR2. The authentication notification area AR2 is set, for example, to a radius of about 10 m from the in-vehicle device 3. By the radio wave receiving unit 21 regularly receiving the second modulation signal from the in-vehicle device 3, it can be determined that the portable device 2 is located within the authentication notification area AR2. The radio wave receiving unit 21 demodulates the received modulation signal and supplies it to the portable device control unit 24.

[0021] The motion sensor 22 is composed of an acceleration sensor, a gyro sensor, etc. The motion sensor 22 detects a vibration waveform signal such as vibration applied to the portable device 2. This vibration waveform signal is detected, for example, by an operation performed by a user holding the portable device 2 such as tapping the portable device 2 a predetermined number of times, an operation such as walking or foot-tapping of the user holding the portable device 2, or an operation performed by the user to hold the portable device 2 such as picking up the placed portable device 2. The motion sensor 22 supplies the detected vibration waveform signal to the portable device control unit 24 and the radio wave transmission unit 26.

[0022] The notification unit 23 is configured to include a vibrator, a speaker, etc. (not shown). The notification unit 23 generates vibration and sound through a vibrator, a speaker, etc. according to a notification control signal supplied from the portable device control unit 24. Thereby, the user can recognize by vibration or sound that the held portable device 2 has entered the authentication notification area AR2.

[0023] The mobile device control unit 24 has functions as a transmission permission determination unit 27, a notification control unit 28, and an operation detection unit 29. The mobile device control unit 24 is configured to include one or more processors and a storage medium storing a program executed by the one or more processors. This program includes one or more instructions, and the instructions cause the one or more processors to execute processes for realizing the above various functions.

[0024] When the radio wave reception unit 21 receives the second modulation signal, the transmission permission determination unit 27 determines that the mobile device 2 is located within the authentication notification area AR2, and supplies a transmission permission signal of the vibration waveform signal detected by the motion sensor 22 and a key signal as ID (Identifier) information of a key preset in the mobile device 2 to the radio wave transmission unit 26.

[0025] Also, when the reception of the second modulation signal by the radio wave reception unit 21 or the supply of the vibration waveform signal from the motion sensor 22 has not been performed for a predetermined time, the transmission permission determination unit 27 stops supplying the transmission permission signal to the radio wave transmission unit 26 until the second modulation signal is supplied from the radio wave reception unit 21 again.

[0026] When the second modulation signal is supplied from the radio wave reception unit 21, the notification control unit 28 determines that the mobile device 2 is located within the authentication notification area AR2, and executes control to output a notification control signal to the notification unit 23 according to the vibration waveform signal supplied from the motion sensor 22.

[0027] The operation detection unit 29 supplies an operation signal for requesting locking and unlocking of the door unit 4 to the radio wave transmission unit 26 according to a user's operation on the operation unit 25.

[0028] The radio wave transmission unit 26 is constituted by a transmitter for modulating and transmitting, for example, the vibration waveform signal supplied from the motion sensor 22, the key signal set in the mobile device 2, etc. into an RF signal (Radio Frequency signal). The radio wave transmission unit 26 outputs according to the second modulation signal received from the in-vehicle device 3 for the RF signal. The radio wave transmitting unit 26 outputs a modulated RF signal toward the in-vehicle device 3 on the condition that a communication permission signal is supplied from the transmission permission determination unit 27. In the present embodiment, an example of a configuration in which the mobile device 2 transmits an RF signal and the in-vehicle device 3 transmits an LF signal and a signal corresponding to the LF signal has been described. However, the signals transmitted by each device are not limited to these, and other signals can also be used.

[0029] In addition, the radio wave transmitting unit 26 outputs a signal obtained by modulating the operation signal, key signal, etc. toward the in-vehicle device 3 in response to the supply of an operation signal from the operation unit 25.

[0030] The in-vehicle device 3 includes a radio wave transmitting unit 31, a radio wave receiving unit 32, and an in-vehicle device control unit 33. The radio wave transmitting unit 31 is constituted by a transmitter for transmitting a modulation signal obtained by modulating a preset polling signal. The radio wave transmitting unit 31 repeatedly transmits various modulation signals at a set period.

[0031] The radio wave receiving unit 32 is constituted by a receiver for receiving the RF signal from the mobile device 2. The radio wave receiving unit 32 receives various signals such as a key signal, a vibration waveform signal, and an operation signal modulated in the RF signal from the mobile device 2. The radio wave receiving unit 32 demodulates the received various signals and supplies them to the in-vehicle device control unit 33.

[0032] The in-vehicle device control unit 33 has the functions of a key verification unit 34, a waveform storage unit 35, a waveform verification unit 36, and an unlocking determination unit 37. The in-vehicle device control unit 33 includes one or more processors and a storage medium in which a program executed by the one or more processors is stored. This program includes one or more instructions, and the instructions cause the one or more processors to execute processes for realizing the above various functions.

[0033] The key verification unit 34 verifies the key signal supplied from the radio wave receiving unit 32 against the registered key information pre-registered in the vehicle-mounted device 3. Thereby, the key verification unit 34 determines whether the key signal matches the registered key information, that is, whether the portable device 2 is associated with the vehicle-mounted device 3. When the key signal and the registered key information match, the key verification unit 34 determines that the key signal conforms to the registered key information. At this time, the key verification unit 34 supplies a key verification completion signal to the unlocking determination unit 37.

[0034] In addition, based on the reception status of radio waves from the portable device 2 by the in-vehicle antenna (radio wave receiving unit 32) provided at various locations of the vehicle 10 (not shown), the key verification unit 34 determines whether the portable device 2 is located inside the vehicle compartment, or whether the portable device 2 is outside the vehicle and in the vicinity of the vehicle 10, that is, whether it is located within the unlocking target vicinity area AR1. The key verification unit 34 supplies the determination result to the unlocking determination unit 37.

[0035] In the waveform storage unit 35, vibration waveform signals corresponding to respective authentication operations for the user to perform unlocking are pre-registered as registration operation information. Note that the registration of the registration operation information in the waveform storage unit 35 can be performed for one or a plurality of persons at a dealer or the like. Therefore, not only the owner of the vehicle 10 but also, for example, the vibration waveform signals of the authentication operations by the owner's family members can be registered as registration operation information for each user.

[0036] Since such authentication operations draw different vibration waveform signals depending on the person even if they are the same operation, the authentication operations for each user are registered as registration operation information and can be used for user authentication by comparing with the vibration waveform signal detected by the portable device 2.

[0037] Here, an example will be described in which registration first operation information, registration second operation information, and registration third operation information are registered in the waveform storage unit 35 as the registration operation information of a certain user. For example, the registration first operation information has a vibration waveform signal of an authentication operation different from that of the registration second operation information. Also, the registration third operation information is paired with the registration second operation information, and even when it is difficult to perform the authentication operation registered as the registration second operation information, a vibration waveform signal of an operation that can be performed as an alternative authentication operation is registered.

[0038] The vibration waveform signal registered as the registration first operation information is, for example, due to an authentication operation intentionally performed by the user holding the mobile device 2 on the mobile device 2. Here, for example, a vibration waveform signal of an operation in which the user taps the mobile device 2 a predetermined number of times at a predetermined rhythm is registered as the registration first operation information.

[0039] Also, the vibration waveform signal registered as the registration second operation information is, for example, due to an authentication operation not intentionally performed by the user holding the mobile device 2 on the mobile device 2. Here, for example, a vibration waveform signal of an operation in which the user walks is registered as the registration second operation information.

[0040] Furthermore, the vibration waveform signal registered as the registration third operation information is, for example, due to an operation not intentionally performed by the user holding the mobile device 2 on the mobile device 2 in the same manner as the registration second operation information. Here, for example, assuming that it becomes difficult to detect the walking operation related to the registration second operation information because the user holding the mobile device 2 gets too close to the vehicle 10, a vibration waveform signal of a stepping operation that can be performed regardless of the distance of the user from the vehicle 10 is registered as the registration third operation information.

[0041] The waveform comparison unit 36 performs comparison of the vibration waveform signal supplied from the radio wave reception unit 32 based on the registration operation information from the waveform storage unit 35. That is, when the vibration waveform signal of the registration operation information read from the waveform storage unit 35 and the supplied vibration waveform signal match within a predetermined error range, the waveform comparison unit 36 determines that the user's operation conforms to the corresponding registration operation information.

[0042] The waveform matching unit 36 supplies a matching completion signal to the unlocking determination unit 37, for example, in response to the user's operation conforming to the registered first operation information and the user's operation conforming to the registered second operation information or the registered third operation information, that is, in response to successful composite authentication.

[0043] The unlocking determination unit 37 has functions as a composite authentication processing unit 38 and a simple authentication processing unit 39.

[0044] When the composite authentication processing unit 38 receives a locking request signal when the mobile device 2 is located outside the vehicle compartment of the vehicle 10 and outside the vicinity area AR1 of the object to be locked, it locks the door unit 4 of the vehicle 10. The locking request signal at this time is received from the mobile device 2, for example, by operating the operation unit 25. The composite authentication processing unit 38 turns on the composite authentication security in response to the locking of the door unit 4.

[0045] In a state where the composite authentication security is ON, the composite authentication processing unit 38 sets an unlocking permission state in which unlocking of the door unit 4 is permitted in response to receiving a key matching completion signal from the key matching unit 34 and a matching completion signal from the waveform matching unit 36.

[0046] In the unlocking permission state, the composite authentication processing unit 38 unlocks the door unit 4 in response to receiving an unlocking request signal. The unlocking request signal at this time is received from the door unit 4, for example, in response to contact with the touch sensor 41 of the door handle. The composite authentication processing unit 38 turns off the composite authentication security in response to the unlocking of the door unit 4.

[0047] When the simple authentication processing unit 39 receives a locking request signal when the mobile device 2 is located outside the vehicle compartment of the vehicle 10 and within the vicinity area AR1 of the object to be locked, it locks the door unit 4 of the vehicle 10. The locking request signal at this time is received from the door unit 4, for example, in response to contact with the touch sensor 41 of the door handle. At this time, the simple authentication processing unit 39 turns on the simple authentication security.

[0048] In the state where the simple authentication security is ON, until the preset set time elapses after the door unit 4 is locked, or until the mobile device 2 is located outside the authentication notification area AR2 after the door unit 4 is locked, the simple authentication processing unit 39 sets the unlocking permission state in response to receiving the key verification completion signal from the key verification unit 34.

[0049] In the unlocking permission state, the simple authentication processing unit 39 unlocks the door unit 4 in response to receiving the unlocking request signal. At this time, the locking request signal is received from the door unit 4 in response to, for example, contact with the touch sensor 41 of the door handle. The simple authentication processing unit 39 turns off the simple authentication security in response to the unlocking of the door unit 4.

[0050] On the other hand, when the preset set time elapses after the door unit 4 is locked, or when the mobile device 2 is located outside the authentication notification area AR2 after the door unit 4 is locked, the simple authentication processing unit 39 turns off the simple authentication security and turns on the composite authentication security.

[0051] Note that when the unlocking determination unit 37 detects the operation signal transmitted from the mobile device 2 to the in-vehicle device 3 by performing the unlocking operation on the operation unit 25 of the mobile device 2, regardless of whether it is in the unlocking permission state, the door unit 4 is unlocked in response to the supply of the key verification completion signal.

[0052] The door unit 4 is provided on each door of the vehicle 10 as shown in FIG. 3. This door unit 4 has a touch sensor 41 and an actuator 42.

[0053] The touch sensor 41 is provided, for example, at a position adjacent to the door handle of the vehicle 10 or on the back side of the door handle. The touch sensor 41 outputs a locking request signal or an unlocking request signal to the unlocking determination unit 37 when touched by a user or the like.

[0054] As shown in FIG. 3, the touch sensor 41 can be provided in all door units 4 of the vehicle 10. Note that the door unit 4 may be provided, for example, at least in the front door on the driver's seat side, or may be provided in some doors such as the front door and the back door on the passenger's seat side. Further, in the door unit 4, a button can be provided instead of the touch sensor 41. In this case, when the user presses the button, a locking request signal or an unlocking request signal is output.

[0055] The actuator 42 is an actuator for locking and unlocking the door unit 4 of the vehicle 10. The actuator 42 locks the door unit 4 when a locking instruction signal is input from the unlocking determination unit 37 of the in-vehicle device 3, and unlocks the door unit 4 when an unlocking instruction signal is input from the unlocking determination unit 37.

[0056] <2. Processing Example of In-Vehicle Device Control Unit> A processing example executed by the in-vehicle device control unit 33 in the present embodiment will be described with reference to FIGS. 4 to 6.

[0057] A processing example related to the control of locking and unlocking executed by the in-vehicle device control unit 33 will be described with reference to FIG. 4. The in-vehicle device control unit 33 periodically executes the processing shown in FIG. 4 at predetermined time intervals.

[0058] In step S101, the in-vehicle device control unit 33 determines whether the mobile device 2 is located outside the vehicle compartment of the vehicle 10. The in-vehicle device control unit 33 determines whether the mobile device 2 is located outside the vehicle compartment based on the reception status of the radio wave from the mobile device 2 by the in-vehicle antenna (radio wave reception unit 32) (see FIG. 3).

[0059] If it is determined in step S101 that the mobile device 2 is located inside the vehicle compartment, the in-vehicle device control unit 33 ends the processing of FIG. 4. Although details are omitted, in this case, processing related to the control of locking and unlocking inside the vehicle compartment by the in-vehicle device control unit 33 is separately executed.

[0060] When it is determined in step S101 that the mobile device 2 is located outside the vehicle compartment, the in-vehicle control unit 33 proceeds to step S102 and determines whether the mobile device 2 is located outside the vicinity area AR1 of the object to be locked. At this time, the in-vehicle control unit 33 determines whether the mobile device 2 is located outside the vicinity area AR1 of the object to be locked based on the reception status of the radio wave from the mobile device 2 that has received the first modulation signal by the in-vehicle antenna (radio wave reception unit 32).

[0061] When it is determined in step S102 that the mobile device 2 is located outside the vicinity area AR1 of the object to be locked, the in-vehicle control unit 33 proceeds to step S103. At this time, since the user holding the mobile device 2 is located outside the vicinity area AR1 of the object to be locked, it is presumed that the user is far enough away from the vehicle 10 that they cannot touch the touch sensor 41 of the door unit 4.

[0062] In step S103, the in-vehicle control unit 33 determines whether a locking request signal has been detected. The locking request signal here is, for example, a signal transmitted from the mobile device 2 to the in-vehicle device 3 when a user located outside the vicinity area AR1 of the object to be locked, away from the vicinity of the vehicle 10, performs a locking operation on the operation unit 25 of the mobile device 2 held. Note that the locking request signal may also be transmitted from the mobile device 2 to the in-vehicle device 3 when the mobile device 2 and the in-vehicle device 3 are located outside the communication range, that is, when the mobile device 2 has moved outside the authentication notification area AR2.

[0063] If the locking request signal is not detected in step S103, the in-vehicle control unit 33 ends the process of FIG. 4.

[0064] If the locking request signal is detected in step S103, the in-vehicle control unit 33 proceeds to step S104 and outputs a locking instruction signal to the actuator 42. The actuator 42 locks the door unit 4 in response to the input of the locking instruction signal from the in-vehicle control unit 33.

[0065] In the subsequent step S105, the in-vehicle control unit 33 turns on the composite authentication security. When the composite authentication security is on, the user can unlock the door unit 4 by completing the composite authentication.

[0066] In step S106, the in-vehicle control unit 33 determines whether or not it has detected an unlock request signal. The unlock request signal here is a signal output from the touch sensor 41 to the in-vehicle control unit 33 in response to a user near the vehicle 10 touching the touch sensor 41.

[0067] If the unlock request signal is not detected in step S106, the in-vehicle control unit 33 ends the process of FIG. 4.

[0068] If the unlock request signal is detected in step S106, the in-vehicle control unit 33 proceeds to step S107 and determines whether or not it is in an unlock permission state. Here, when the key signal matches the registered key information, the user's operation matches the registered first operation information, and the user's operation matches the registered second operation information or the registered third operation information, the unlock permission state is established. Details of the unlock permission state will be described again with reference to FIG. 5.

[0069] If it is not in the unlock permission state in step S107, the in-vehicle control unit 33 ends the process of FIG. 4. That is, even if the in-vehicle control unit 33 detects an unlock request signal in step S106 when the composite authentication has not been successful, the door unit 4 is not unlocked.

[0070] If it is in the unlock permission state in step S107, the in-vehicle control unit 33 proceeds to step S108 and outputs an unlock instruction signal to the actuator 42. The actuator 42 unlocks the door unit 4 in response to the input of the unlock instruction signal from the in-vehicle control unit 33.

[0071] After that, the in-vehicle control unit 33 turns off the composite authentication security in step S109 and ends the process of FIG. 4. Through the processes from step S105 to step S109 described above, the process regarding unlocking of the door unit 4 in the state where the composite authentication security is ON is completed.

[0072] On the other hand, when it is determined in step S102 described above that the mobile device 2 is located within the vicinity area AR1 of the locking target, the in-vehicle control unit 33 proceeds to step S110. At this time, it is estimated that the user is near the vehicle 10.

[0073] In step S110, the in-vehicle control unit 33 determines whether a locking request signal has been detected. The locking request signal here is, for example, a signal output from the touch sensor 41 to the in-vehicle control unit 33 in response to a user within the vicinity area AR1 of the locking target touching the touch sensor 41. Further, the locking request signal may be a signal transmitted from the mobile device 2 to the in-vehicle device 3 when the user performs a locking operation on the operation unit 25 of the mobile device 2 held by the user.

[0074] If the locking request signal is not detected in step S110, the in-vehicle control unit 33 ends the process of FIG. 4.

[0075] If the locking request signal is detected in step S110, the in-vehicle control unit 33 proceeds to step S111 and inputs a locking instruction signal to the actuator 42. The actuator 42 locks the door unit 4 in response to the input of the locking instruction signal from the in-vehicle control unit 33.

[0076] In the subsequent step S112, the in-vehicle control unit 33 turns on the simple authentication security. In the state where the simple authentication security is ON, the user is permitted to unlock the door without performing composite authentication.

[0077] After that, the in-vehicle control unit 33 performs a monitoring loop process for steps S113, S114, and S115.

[0078] In step S113 of the monitoring loop process, the in-vehicle control unit 33 determines whether or not an unlocking request signal is detected.

[0079] If an unlocking request signal is detected in step S113, the in-vehicle control unit 33 proceeds to step S116 and determines whether or not it is in an unlocking permission state. Here, the unlocking permission state is achieved when the key signal matches the registered key information. In this way, when the user is located near the vehicle 10, it is assumed that the user attempts to unlock the door unit 4 again. Therefore, in this case, by eliminating the need for composite authentication, the user can easily unlock the door unit 4.

[0080] If it is not in the unlocking permission state in step S116, the in-vehicle control unit 33 proceeds to step S113 and returns to the monitoring loop process.

[0081] If it is in the unlocking permission state in step S116, the in-vehicle control unit 33 proceeds to step S117 and outputs an unlocking instruction signal to the actuator 42. The actuator 42 unlocks the door unit 4 in response to the input of the unlocking instruction signal from the in-vehicle control unit 33.

[0082] Thereafter, the in-vehicle control unit 33 turns off the simple authentication security in step S118 and executes the processes from step S105 to step S109 regarding the unlocking of the door unit 4 in the state where the composite authentication security is ON.

[0083] In step S114 of the monitoring loop process, the in-vehicle control unit 33 determines whether or not the mobile device 2 is located outside the authentication notification area AR2. That is, it determines whether or not the user has moved sufficiently away from the vehicle 10. The in-vehicle control unit 33 determines that the mobile device 2 is located outside the authentication notification area AR2, for example, in response to the fact that the RF signal from the mobile device 2 is no longer received regularly.

[0084] When the mobile device 2 is located outside the authentication notification area AR2 in step S114, the in-vehicle control unit 33 turns off the simple authentication security in step S118 and executes the processes from step S105 to step S109 regarding unlocking the door unit 4 in the state where the composite authentication security is ON. That is, when the user is sufficiently away from the vehicle 10, the need to immediately unlock the door unit 4 decreases, so the composite authentication security, which requires a higher level of security, is turned ON.

[0085] In step S115 of the monitoring loop process, the in-vehicle control unit 33 determines whether or not a preset set time has elapsed since the door unit 4 was locked.

[0086] When the set time has elapsed since the door unit 4 was locked in step S115, the in-vehicle control unit 33 turns off the simple authentication security in step S118 and executes the processes from step S105 to step S109 regarding unlocking the door unit 4 in the state where the composite authentication security is ON. In this way, by keeping the simple authentication security ON until a predetermined time has elapsed since the door unit 4 was locked, the door can be smoothly unlocked even if the user who locked the door unit 4 tries to unlock it immediately.

[0087] A processing example regarding unlocking permission executed by the in-vehicle control unit 33 will be described with reference to FIG. 5. The in-vehicle control unit 33 periodically executes the processing shown in FIG. 5, for example, every predetermined time.

[0088] In step S201, the in-vehicle control unit 33 determines whether or not a key signal has been received from the mobile device 2.

[0089] When the in-vehicle control unit 33 has not received a key signal from the mobile device 2 in step S201, the in-vehicle control unit 33 proceeds to step S209, sets an unlocking-disabled state in which unlocking of the door unit 4 is not permitted, and ends the processing shown in FIG. 5.

[0090] When the in-vehicle control unit 33 receives a key signal from the mobile device 2 in step S201, it proceeds to step S202 and determines whether the mobile device 2 is located outside the vehicle compartment of the vehicle 10. The in-vehicle control unit 33 determines whether the mobile device 2 is located outside the vehicle compartment based on the reception status of the radio wave of the mobile device 2 by an in-vehicle antenna (radio wave reception unit 32) not shown in the figure.

[0091] If it is determined in step S202 that the device is located inside the vehicle compartment, the in-vehicle control unit 33 proceeds to step S209, sets the unlocking prohibition state, and then ends the process shown in FIG. 5.

[0092] If it is determined in step S202 that the device is located outside the vehicle compartment, the in-vehicle control unit 33 proceeds to step S203 and performs a comparison with the registered key information. The in-vehicle control unit 33 compares the key signal received from the mobile device 2 with the registered key information registered in the in-vehicle device 3. Thereby, it is possible to determine whether the mobile device 2 is associated with the in-vehicle device 3 based on the key signal received from the mobile device 2.

[0093] In the subsequent step S204, the in-vehicle control unit 33 determines whether the key signal and the registered key information match based on the comparison result.

[0094] If the key signal and the registered key information do not match in step S204, the in-vehicle control unit 33 proceeds to step S209, sets the unlocking prohibition state, and then ends the process of FIG. 5. That is, since the mobile device 2 that transmitted the key signal is not associated with the in-vehicle device 3, the unlocking of the door unit 4 is not permitted.

[0095] If the key signal and the registered key information match in step S204, the in-vehicle control unit 33 proceeds to step S205 and determines whether the composite authentication security is ON. That is, it is determined whether composite authentication is required for unlocking the door unit 4.

[0096] If the composite authentication security is ON in step S205, the in-vehicle control unit 33 proceeds to the monitoring loop processing of steps S206 and S207. The in-vehicle control unit 33 determines whether a predetermined period has elapsed since the collation with the registered key information was completed in step S206. The in-vehicle control unit 33 also determines whether a collation completion signal has been detected in step S207. Details of the collation completion signal will be described again with reference to FIG. 6.

[0097] If a predetermined time has elapsed before the in-vehicle control unit 33 detects the collation completion signal in step S207, the process proceeds from step S206 to step S209. After setting the unlocking prohibition state, the process shown in FIG. 5 is terminated. Thus, when composite authentication is required for unlocking the door unit 4, if the authentication process is not completed before a predetermined time elapses after the collation of the registered key information is completed, the unlocking of the door unit 4 is not permitted. Reasons for the authentication process not being completed include cases where the user has not performed the previously set authentication operation, or cases where a third party who is not the user has performed the authentication operation. Also, by restricting the reception time of the composite authentication in this way, it is possible to prevent malfunction of unlocking permission due to unintended operations by the user.

[0098] If the in-vehicle control unit 33 detects the collation completion signal in step S207 before the elapse of the predetermined period, it sets the unlocking permission state in which the door unit 4 can be unlocked in step S208, and terminates the process of FIG. 5. Thus, in a state where the composite authentication security is ON, unlocking of the door unit 4 becomes possible by succeeding in the composite authentication.

[0099] On the other hand, if the composite authentication security is not ON in step S205, the in-vehicle control unit 33 sets the unlocking permission state in which the door unit 4 can be unlocked in step S208 without performing the processes of steps S206 and S207, and terminates the process of FIG. 5. Thus, in a state where the composite authentication security is ON, since no composite authentication conditions are imposed, the door unit 4 can be unlocked only when the key signal matches the registered key information.

[0100] A processing example related to the composite authentication executed by the in-vehicle control unit 33 will be described with reference to FIG. 6. The in-vehicle control unit 33 periodically executes the processing shown in FIG. 6, for example, at predetermined time intervals.

[0101] First, in step S301, the in-vehicle control unit 33 determines whether the mobile device 2 is located within the authentication notification area AR2. That is, it determines whether the vibration waveform signal detected by the motion sensor 22 can be received from the mobile device 2. The in-vehicle control unit 33 determines that the mobile device 2 is located within the authentication notification area AR2, for example, in response to the periodic reception of an RF signal from the mobile device 2.

[0102] If the mobile device 2 is located outside the authentication notification area AR2 in step S301, the in-vehicle control unit 33 cannot receive the vibration waveform signal used for the composite authentication process from the mobile device 2, so the in-vehicle control unit 33 ends the process of FIG. 6.

[0103] If the mobile device 2 is located within the authentication notification area AR2 in step S301, the in-vehicle control unit 33 proceeds to step S302 and receives the vibration waveform signal detected by the motion sensor 22 from the mobile device 2.

[0104] In step S303, the in-vehicle control unit 33 performs a comparison with the registered first operation information. At this time, the in-vehicle control unit 33 determines whether the vibration waveform signal received from the mobile device 2 matches the vibration waveform signal of the registered first operation information registered in the in-vehicle device 3 within a predetermined error range.

[0105] The registered first operation information is, for example, the vibration waveform signal of an operation in which the user performs a predetermined number of taps on the mobile device 2 at a predetermined rhythm in advance.

[0106] If the vibration waveform signal received from the mobile device 2 in the subsequent step S304 does not match the registered first operation information, the in-vehicle control unit 33 determines that the user's operation does not conform to the registered first operation information and ends the process of FIG. 6. That is, the composite authentication fails.

[0107] When the vibration waveform signal received from the mobile device 2 in step S304 matches the registered first operation information, the in-vehicle control unit 33 determines that the user's operation conforms to the registered first operation information and proceeds with the process to step S305.

[0108] In step S305, the in-vehicle control unit 33 acquires the position information of the mobile device 2. The in-vehicle control unit 33 determines, for example, whether the mobile device 2 is located within the vicinity area AR1 of the locking target based on the reception status of the radio wave from the mobile device 2 that has received the first modulation signal by an in-vehicle antenna (radio wave receiving unit 32) (not shown in the figure).

[0109] In step S306, the in-vehicle control unit 33 determines whether the mobile device 2 is at a position where a vibration waveform signal used for comparison with the registered second information can be detected. The registered second operation information is, for example, the vibration waveform signal of the directional movement of the user holding the mobile device 2 walking towards the vehicle 10. However, in this case, if the distance between the user and the vehicle 10 is too close, it may not be possible to sufficiently detect the vibration waveform signal of the user's walking used for comparison with the registered second information. Therefore, the in-vehicle control unit 33 determines whether a sufficient distance is ensured between the mobile device 2 held by the user and the vehicle 10.

[0110] The in-vehicle control unit 33 determines, for example, that the mobile device 2 is at a position where a vibration waveform signal used for comparison with the registered second information can be detected when the mobile device 2 is located outside the vicinity area AR1 of the locking target.

[0111] In this case, the in-vehicle control unit 33 receives the vibration waveform signal detected from the motion sensor 22 in step S307 and performs a comparison with the registered second operation information in step S308. At this time, the in-vehicle control unit 33 determines whether the vibration waveform signal received from the mobile device 2 and the vibration waveform signal of the registered second operation information registered in the in-vehicle device 3 match within a predetermined error range.

[0112] If the vibration waveform signal received from the mobile device 2 in the subsequent step S309 does not match the registered second operation information, the in-vehicle control unit 33 determines that the user's authentication operation does not conform to the registered second operation information, and ends the process of FIG. 6. That is, the composite authentication fails.

[0113] If the vibration waveform signal received from the mobile device 2 in step S309 matches the registered second operation information, the in-vehicle control unit 33 determines that the user's authentication operation conforms to the registered second operation information. Then, the in-vehicle control unit 33 outputs a collation completion signal in step S310 and ends the process of FIG. 6. As a result, the composite authentication is successful.

[0114] On the other hand, if it is determined in step S306 that the mobile device 2 is not in a position where the vibration waveform signal used for collation with the registered second operation information can be detected, the in-vehicle control unit 33 proceeds to step S311. In this case, the collation with the vibration waveform signal received from the mobile device 2 is performed using the registered third operation information instead of the registered second operation information.

[0115] The registered third operation information includes, for example, the vibration waveform signal of a stepping motion that can detect the vibration waveform signal required for collation even if the walking distance is not sufficiently secured. Thereby, even in a situation where collation cannot be performed using the registered second operation information, composite authentication can be performed using the alternative registered third operation information.

[0116] In step S311, the in-vehicle control unit 33 receives the vibration waveform signal detected by the motion sensor 22 and performs collation with the registered third operation information in step S312. At this time, the in-vehicle control unit 33 determines whether the vibration waveform signal received from the mobile device 2 and the vibration waveform signal of the registered third operation information registered in the in-vehicle device 3 match within a predetermined error range.

[0117] If the vibration waveform signal received from the mobile device 2 in the subsequent step S313 does not match the registered third operation information, the in-vehicle control unit 33 determines that the user's authentication operation does not conform to the registered third operation information, and ends the process of FIG. 6. That is, the composite authentication fails.

[0118] When the vibration waveform signal received from the mobile device 2 in step S313 matches the registered third operation information, the in-vehicle device control unit 33 determines that the user's operation conforms to the registered third operation information. Then, the in-vehicle device control unit 33 outputs a collation completion signal in step S310 and ends the process of FIG. 6. As a result, the composite authentication is successful.

[0119] <3. Processing Example of Mobile Device Control Unit> A processing example executed by the mobile device control unit 24 in the present embodiment will be described with reference to FIG. 7. The mobile device control unit 24 periodically executes the process shown in FIG. 7 at predetermined time intervals.

[0120] In step S401, the mobile device control unit 24 determines whether the mobile device 2 has moved from outside the authentication notification area AR2 to inside the authentication notification area AR2.

[0121] For example, when the mobile device control unit 24 receives the second modulation signal again after a predetermined period has elapsed since it stopped receiving the second modulation signal from the in-vehicle device 3, it determines that the mobile device 2 has moved from outside the authentication notification area AR2 to inside the authentication notification area AR2. As a result, it can be determined that the user holding the mobile device 2 has entered the authentication notification area AR2.

[0122] Note that the mobile device control unit 24 can also determine the entry of the mobile device 2 into the authentication notification area AR2 from the change in the position of the mobile device 2 by using a GNSS (Global Navigation Satellite System) such as GPS (Global Positioning System).

[0123] When the mobile device 2 moves from outside the authentication notification area AR2 to inside the authentication notification area AR2 in step S401, the mobile device control unit 24 proceeds to step S409 and executes the notification control process. At this time, the mobile device control unit 24 causes the notification unit 23 to output the notification information. For example, by vibrating the vibrator of the notification unit 23 or by outputting a notification sound through the speaker of the notification unit 23, the user can be made aware that the mobile device 2 is located inside the authentication notification area AR2, that is, that composite authentication can be performed.

[0124] When the mobile device 2 has not moved from outside the authentication notification area AR2 to inside the authentication notification area AR2 in step S401, the mobile device control unit 24 proceeds to step S410. At this time, the mobile device 2 is located either outside the authentication notification area AR2 or inside the authentication notification area AR2.

[0125] In step S410, the mobile device control unit 24 determines whether the mobile device 2 is located inside the authentication notification area AR2. At this time, the mobile device control unit 24 determines that the mobile device 2 is located inside the authentication notification area AR2, for example, in response to the periodic reception of the second modulation signal from the in-vehicle device 3. Note that the mobile device control unit 24 can also determine whether the mobile device 2 is located inside the authentication notification area AR2 by acquiring the position information of the mobile device 2 using GPS.

[0126] If the mobile device 2 is not located inside the authentication notification area AR2 in step S410, the mobile device control unit 24 ends the process of FIG. 7.

[0127] If the mobile device 2 is located inside the authentication notification area AR2 in step S410, the mobile device control unit 24 proceeds to step S402. This is, for example, a state where the user holding the mobile device 2 has gotten out of the vehicle 10 and has not yet left the outside of the authentication notification area AR2.

[0128] In step S402, the mobile device control unit 24 starts acquiring the vibration waveform signal detected by the motion sensor 22. Also, in step S403, the mobile device control unit 24 detects the movement of the mobile device 2 based on the acquired vibration waveform signal.

[0129] If the movement of the mobile device 2 is detected in step S403, the mobile device control unit 24 proceeds to step S406 and ends the process of FIG. 7 because the non-notification mode is not set. As a result, when the mobile device 2 continues to be located within the authentication notification area AR2, no notification such as vibration or sound is output from the notification unit 23 even if the movement of the mobile device 2 is detected. Therefore, it is possible to prevent the notification unit 23 from repeatedly notifying while the user is within the authentication notification area AR2.

[0130] If the movement of the mobile device 2 is not detected in step S403, the mobile device control unit 24 proceeds to step S404 and waits until a predetermined time has elapsed since the movement of the mobile device 2 was no longer detected. If the movement of the mobile device 2 is detected in step S403 before the predetermined time has elapsed, the mobile device control unit 24 proceeds to step S406 and ends the process of FIG. 7.

[0131] In step S404, when a predetermined time has elapsed since the movement of the mobile device 2 was no longer detected, the mobile device control unit 24 proceeds to step S405 and sets the non-notification mode. As a situation where the movement of the mobile device 2 is not detected for a long time, it is assumed that, for example, the user has temporarily placed the mobile device 2 and is not holding it.

[0132] Thereafter, the mobile device control unit 24 proceeds with the process in the order of step S406 and step S407, and detects the movement of the mobile device 2 based on the acquired vibration waveform signal.

[0133] If the movement of the mobile device 2 is not detected in step S407, the mobile device control unit 24 ends the process of FIG. 7 without performing notification control on the notification unit 23. As a result, when the user temporarily leaves the mobile device 2, no notification is output from the notification unit 23. Therefore, it is possible to prevent the notification unit 23 from issuing a notification until a situation where it is presumed that the user is not holding the mobile device 2 and has no intention of returning to the vehicle 10.

[0134] If the movement of the mobile device 2 is detected in step S407, the mobile device control unit 24 cancels the non-notification mode in step S408. In this case, it can be presumed that the user is trying to pick up the mobile device 2 that was placed and return to the vehicle 10.

[0135] In the subsequent step S409, the mobile device control unit 24 executes notification control processing on the notification unit 23, and the mobile device control unit 24 ends the process of FIG. 7. The mobile device control unit 24 outputs a notification control signal to the notification unit 23, causing the notification unit 23 to generate vibration or sound through a vibrator, a speaker, or the like. Thereby, when the user tries to hold the mobile device 2 again and return to the vehicle 10, the user can be made aware that they are within the authentication notification area AR2, that is, in a position where composite authentication can be performed.

[0136] <4. Summary> The electronic key system 1 in the above embodiment includes a door unit 4 provided in the vehicle 10, an in-vehicle device 3 provided in the vehicle 10, a mobile device 2 that can communicate with the in-vehicle device 3 in the authentication notification area AR2 and can be held by the user, one or more processors, and a storage medium in which a program executed by the one or more processors is stored (see FIGS. 1 and 2).

[0137] The above command causes one or more processors to execute a composite authentication process that permits unlocking of the door unit 4 on the condition that the key information output from the mobile device 2 conforms to registered key information registered in advance, the operation of the user on the mobile device 2 conforms to registered first operation information registered in advance, and the operation conforms to registered second operation information registered in advance (see FIGS. 4 and 5).

[0138] Accordingly, normally, in addition to conformity with the registered key information for permitting unlocking, a plurality of authentication processes, namely conformity with the registered first operation information and conformity with the registered second operation information, are imposed. In this way, by imposing a plurality of authentication processes that make detection of a specific operation of the user a condition for permitting unlocking, it is possible to prevent a so-called relay attack in which, for example, the user anticipates leaving the vehicle 10 and uses a repeater to establish communication between a mobile device outside the communication range and the in-vehicle device 3 provided in the vehicle to illegally unlock the door or the like. Therefore, the security of the electronic key system 1 can be sufficiently ensured.

[0139] The above command also causes one or more processors to execute a simple authentication process that permits unlocking of the door unit 4 on the condition that the key information conforms to the registered key information during a preset time period after the door unit 4 is locked or until the mobile device 2 is located outside the authentication notification area AR2 after the door unit 4 is locked (see FIGS. 4 and 5).

[0140] In a situation where it is assumed that the user has not moved far from the vehicle 10, such as during a preset time period after the door unit 4 is locked or until the mobile device 2 is located outside the authentication notification area AR2 after the door unit 4 is locked, the risk of illegal unlocking or the like by a third party is low. Therefore, a composite authentication process, namely conformity with the registered first operation information and conformity with the registered second operation information, is not imposed for permitting unlocking.

[0141] Thus, for example, when the user forgets something in the vehicle and returns to the vehicle 10, unlocking can be performed by a simple authentication process without the need for the user to perform multiple-factor authentication such as touching the door handle (touch sensor 41). Therefore, the convenience of users who use the electronic key system 1 in a situation with a low risk of unauthorized unlocking or the like can be improved.

[0142] Instructions included in the program stored in the storage medium in the electronic key system 1 according to the embodiment cause one or more processors to execute a simple authentication process when the door unit 4 of the vehicle 10 is locked while the portable device 2 is located within the unlocking target vicinity area AR1 which is part of the authentication notification area AR2 (see FIGS. 4 and 5).

[0143] When the portable device 2 is located within the unlocking target vicinity area AR1, it is presumed that the user is near the vehicle 10. By enabling unlocking to be performed by a simple authentication process in a situation where there is a high probability of unlocking again, such as when the user is near the vehicle 10, the convenience of the user can be improved.

[0144] Instructions included in the program stored in the storage medium in the electronic key system 1 according to the embodiment cause one or more processors to execute a mode switching process that controls switching to a non-notification mode in which the portable device 2 does not output notification information when a state where movement of the portable device 2 located within the authentication notification area AR2 is not detected has elapsed for a predetermined time (see FIG. 7).

[0145] Thus, for example, when the user temporarily places the portable device 2 at the entrance of their home or the like, a notification that the portable device 2 is within the authentication notification area AR2 is not output in a situation where it is presumed that the user does not intend to unlock the vehicle 10. Therefore, it is possible to eliminate the annoyance caused by the notification being output from the portable device 2 repeatedly against the user's intention, and improve the convenience of the user staying within the authentication notification area AR2.

[0146] Instructions included in a program stored in a storage medium in the electronic key system 1 in the embodiment cause one or more processors to execute a process of canceling the non-notification mode when the movement of the portable device 2 is detected in the non-notification mode as a mode switching process (see FIG. 7).

[0147] When the movement of the portable device 2 is detected again in this way, for example, it is assumed that the user picks up the portable device 2 that was left behind and heads towards the vehicle 10. In such a case, by notifying that the portable device 2 is within the authentication notification area AR2, that is, that it is possible to perform composite authentication for unlocking, the user can smoothly shift to the operation for unlocking. Therefore, the convenience of the user staying within the authentication notification area AR2 can be improved.

[0148] When the portable device 2 is equipped with a GPS function, in response to detecting that the portable device 2 is moving in the direction of the vehicle 10, one or more processors can be made to execute a process of canceling the non-notification mode.

[0149] Instructions included in a program stored in a storage medium in the electronic key system 1 in the embodiment cause one or more processors to execute, as a composite authentication process, a process of permitting unlocking of the door unit 4 on the condition that two of the following are satisfied: the operation conforms to the registered first operation information, the operation conforms to the registered second operation information, and the operation conforms to the registered third operation information registered in advance (see FIGS. 4 and 5).

[0150] Thereby, even when there is a constraint that the user cannot perform an operation corresponding to either the registered first operation information or the registered second operation information, for example, the door unit 4 can be unlocked on the condition that the operation conforms to the registered third operation information instead.

[0151] For example, when the operation corresponding to the registered second operation information is walking and the operation corresponding to the registered third operation information is stomping, if the user is too close to the vehicle 10 and the user's walking cannot be detected, that is, in a situation where the vibration waveform signal corresponding to the registered second operation information cannot be detected, the stomping operation can meet the conditions by conforming to the registered third operation information.

[0152] Thereby, while maintaining the condition of composite authentication, the authentication means can be flexibly used according to the user's situation. Therefore, it is possible to improve the user's convenience and ensure sufficient security.

[0153] In the electronic key system 1 in the present embodiment, the functions of the waveform storage unit 35 and the waveform collation unit 36 may be provided in the portable device control unit 24 instead of the in-vehicle device control unit 33. In this case, the portable device control unit 24 executes the process of FIG. 6, and transmits the collation completion signal output in step S310 to the in-vehicle device 3 via the radio wave transmission unit 26. The in-vehicle device control unit 33 executes the process of FIG. 5 based on the collation completion signal received from the portable device 2.

[0154] The effects described in the above present disclosure are illustrative and not limiting. That is, other effects may be achieved, or some of the effects described in the present disclosure may be achieved. Further, the above-described embodiments are merely examples and do not limit the present invention. Therefore, it goes without saying that various changes can be made according to the design and the like without departing from the technical idea of the present invention. Note that not all combinations of the configurations described in the above embodiments are essential for solving the problems of the present invention.

Explanation of Reference Numerals

[0155] 1 Electronic key system 2 Portable device 3 In-vehicle device 4 Door unit 10 Vehicle 22 Motion sensor 23 Notification unit 24 Mobile device control unit 28 Notification control unit 33 Vehicle-mounted device control unit 36 Waveform comparison unit 37 Unlocking determination unit 38 Composite authentication processing unit 39 Simple authentication processing unit AR1 Area near the locking target AR2 Authentication notification area

Claims

1. A door unit provided for the locking target, An installation device provided for the locking target, A portable device that can communicate with the installation device in an authentication notification area and can be held by a user, One or more processors, A storage medium storing a program executed by the one or more processors, The program includes one or more instructions, The instructions cause the one or more processors to A composite authentication process that permits unlocking of the door unit on the condition that key information output from the portable device conforms to registered key information registered in advance, the user's operation conforms to registered first operation information registered in advance, and the operation conforms to registered second operation information registered in advance, A simple authentication process that permits unlocking of the door unit on the condition that the key information conforms to the registered key information during a set time period after the door unit is locked or until the portable device is located outside the authentication notification area after the door unit is locked, An electronic key system.

2. The instructions cause the one or more processors to Execute the simple authentication process when the locking target is locked while the portable device is located within a vicinity area near the locking target that is part of the authentication notification area The electronic key system according to claim 1.

3. The one or more processors have A function of outputting notification information to the portable device when the portable device is located within the authentication notification area, The instructions cause the one or more processors to Execute a mode switching process that controls so that when a state in which movement of the portable device located within the authentication notification area is not detected has elapsed for a predetermined time, the portable device is switched to a non-notification mode in which the notification information is not output The electronic key system according to claim 1 or claim 2.

4. The instructions cause the one or more processors to As the mode switching process, execute a process of canceling the non-notification mode when movement of the portable device is detected in the non-notification mode The electronic key system according to claim 3.

5. The instructions cause the one or more processors to As the composite authentication process, a process of permitting unlocking of the door unit is executed on the condition that two of the following are satisfied: the operation conforms to the registered first operation information, the operation conforms to the registered second operation information, and the operation conforms to the registered third operation information registered in advance. The electronic key system according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Electronic key

    JP2010275701A

  • Electronic key

    JP2011063961A

  • Electronic key system

    JP2012082653A

  • Antitheft system

    JP2013126197A

  • Remote operation system

    JP2016048018A