System and Program

The system addresses false alarms in vehicle security by temporarily suppressing alarms and requiring a successful authentication to maintain the vehicle in a non-monitoring state, enhancing security and reducing false alarms.

JP7702754B2Active Publication Date: 2025-07-04YUPITERU CORP
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2024016167
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-02-06
Publication Date
2025-07-04
Estimated Expiration
2039-12-19

AI Technical Summary

Technical Problem

Existing vehicle security systems activate alarms even when a regular user is using the vehicle, leading to false alarms and undesirable situations.

Method used

A system and program that temporarily suppress alarm activation upon detecting abnormalities while the vehicle is in a monitoring state, requiring a second trigger indicating a successful authentication operation to maintain the vehicle in a non-monitoring state, thereby enhancing security and reducing false alarms.

Benefits of technology

The system effectively prevents unauthorized acts by suppressing alarm activation during legitimate use, ensuring high security and minimizing false alarms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007702754000001
    Figure 0007702754000001
  • Figure 0007702754000002
    Figure 0007702754000002
  • Figure 0007702754000003
    Figure 0007702754000003
Patent Text Reader

Abstract

To provide a novel technology relating to vehicle security.SOLUTION: A system includes warning means and control means. The warning means includes a function of issuing a warning when an anomaly is detected while a vehicle 1 is under a monitoring state. The control means temporarily suppresses a warning issued by the warning means when there is a first trigger while the vehicle 1 is under the monitoring state, and when there is a second trigger indicating that a normal authentication operation is accepted, keeps the vehicle 1 under a non-monitoring state.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] For example, it relates to systems, programs, etc.

Background Art

[0002] It has become a social problem that unauthorized acts such as theft or use of the vehicle and its accessories are committed by a third party other than the regular user of the vehicle (e.g., the owner or user of the vehicle). Regarding vehicle security technology, for example, Patent Document 1 describes an abnormality detection device that, when detecting an abnormality such as a certain pattern of vibration occurring in the vehicle, operates a vehicle horn, a lighting device, etc. to issue a warning.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] By detecting an abnormality in the vehicle and activating an alarm as in the technology described in Patent Document 1, it is possible to expect the effect of suppressing unauthorized acts such as vehicle theft. However, if the alarm is activated even when a regular user is trying to use the vehicle, this will be a false alarm, which is not desirable for the regular user.

[0005] One object of the present invention is to provide a technology related to vehicle security different from the prior art. One object of the present invention is to provide, for example, a system and a program, etc. that are excellent in security while suppressing the activation of false alarms.

[0006] The object of the present invention is not limited to this, and the applicant also intends to obtain rights through divisional applications, amendments, etc. for configurations that aim to obtain the effects achieved by the components disclosed in this specification, drawings, etc. For example, the problems obtained by reading the parts described as "can be" in this specification as "is a problem" are disclosed in this specification. The problems are described as independent ones, and the applicant also intends to obtain rights through divisional applications, amendments, etc. alone for the configurations for solving each problem. Even if the problems are implicitly understood from the description of the specification, the applicant intends to make the scope of claims by amending or filing a divisional application for a part of the configuration described in this specification. In addition, the configurations for solving the problems obtained by combining these independent problems are also disclosed, and the applicant intends to obtain rights.

Means for Solving the Problems

[0007] The object of the present invention can be achieved, for example, in the following forms (1) to (16).

[0008] (1) An alarm means having a function of activating an alarm when an abnormality is detected while the vehicle is in a monitoring state, and a control means for temporarily suppressing the activation of the alarm by the alarm means when there is a first trigger while the vehicle is in a monitoring state, and maintaining the vehicle in a non-monitoring state when there is a second trigger indicating that a regular authentication operation has been accepted. A system may be provided with these components.

[0009] By doing so, it is maintained in an unmonitored state on condition that there is a second trigger indicating that a normal authentication operation has been received, so the security is high. Also, since the activation of the alarm is suppressed when there is a first trigger, it is suppressed that the alarm is erroneously activated when a normal user is performing an authentication operation. Furthermore, since the period during which the authentication operation can be received while the activation of this alarm is suppressed is limited to a temporary period from when there is a first trigger, this can also be a desirable basis in terms of security. Therefore, it is possible to enhance the security while suppressing the activation of false alarms. Such an invention has, in addition to the viewpoint of preventing unauthorized acts such as theft of the vehicle by a third party, the viewpoint of suppressing the activation of false alarms caused by a normal user and suppressing the occurrence of an undesirable situation for the normal user.

[0010] (2) When the normal authentication operation has not been received, the control means may be a system that does not maintain the vehicle in an unmonitored state and releases the temporary suppression of the activation of the alarm by the alarm means.

[0011] By doing so, when a normal authentication operation has not been received, an alarm is activated by the alarm means. Therefore, for example, it is possible to deter the execution of illegal acts such as theft of the vehicle by a malicious third party, and high security can be realized.

[0012] (3) The normal authentication operation may be a system that is an input operation for inputting normal authentication information to the input means.

[0013] By doing so, when normal authentication information is not input, the vehicle is not maintained in an unmonitored state. Therefore, high security can be realized.

[0014] (4) The normal authentication operation may be a system that includes a first input operation for inputting normal authentication information to a first input means and a second input operation performed on a second input means originally provided in the vehicle.

[0015] In this way, if only one of the first input operation and the second input operation is received, the vehicle is not maintained in the non-monitoring state but enters the monitoring state. When both the first input operation and the second input operation are received, the vehicle is maintained in the non-monitoring state. Also, for example, the second input means originally provided in the vehicle can be used to instruct the completion of the input of the authentication information in the first input operation. Therefore, higher security can be achieved without newly providing a means for instructing the completion of the input of the authentication information.

[0016] (5) The system may be configured such that the second input means is a means for receiving an input related to the operation of the prime mover of the vehicle.

[0017] In this way, for example, an input related to the operation of the prime mover of the vehicle, such as an operation normally performed when using the vehicle, can also serve as an input completion operation for instructing the completion of the input of the authentication information. Therefore, the operability of the user can be improved.

[0018] (6) The system may be configured such that the control means sets the first authentication operation as the normal authentication operation before a predetermined period elapses after the first trigger occurs, and prohibits setting the first authentication operation as the normal authentication operation after the predetermined period has elapsed.

[0019] In this way, for example, if the normal authentication operation is not received within the predetermined period after the first trigger occurs and the vehicle enters the monitoring state, since setting the first authentication operation as the normal authentication operation is prohibited, even if a third party takes time to perform the first authentication operation that becomes the normal authentication operation, it is possible to prevent the vehicle from being maintained in the non-monitoring state.

[0020] (7) When the predetermined period has elapsed, the warning means activates a warning, and the system may be configured such that the control means sets a second authentication operation, which has an increased number of user procedures compared to the user procedures required in the first authentication operation that is set as the normal authentication operation, as the normal authentication operation.

[0021] In this way, as long as the user performs a normal authentication operation while the activation of the alarm is suppressed, an increase in the operation burden can be suppressed. For example, when there is an error in the authentication operation or the authentication operation is not performed, by increasing the necessary user procedures for the normal authentication operation along with the activation of the alarm, the possibility of misidentifying a person who is not a legitimate user as a legitimate user can be reduced.

[0022] (8) The first trigger may be a system that indicates that a predetermined operation has been received when the lock of the vehicle is released.

[0023] In this way, when there is a predetermined operation, for example, a predetermined operation to use the vehicle, when the lock of the vehicle is released, since this may be by a legitimate user, the activation of the alarm is temporarily suppressed. Therefore, it is possible to suppress the activation of a false alarm caused by a legitimate user.

[0024] (9) When the control means receives a predetermined signal having a data part different from that transmitted by the electronic key or a predetermined signal having a frequency different from the frequency used by the electronic key for wireless communication from a remote operation terminal different from the electronic key attached to the vehicle, the system may maintain the vehicle in a non-monitored state.

[0025] In this way, even if the user does not perform a normal authentication operation, when a predetermined signal from the remote operation terminal, which can be distinguished from the signal from the electronic key, is received, the vehicle can be maintained in a non-monitored state. Therefore, it is possible to improve the convenience of the user while realizing high security.

[0026] (10) The system may further include a detection means capable of detecting the first trigger, and the control means may have a judgment function that, when information that the first trigger has occurred is obtained from the detection means, temporarily suppresses the issuance of an alarm by the alarm means and determines whether or not to maintain the vehicle in a non-monitoring state.

[0027] In this way, even if the control means is not provided with a function capable of detecting the first trigger, it is possible to determine the presence or absence of the first trigger based on information from detection means capable of detecting the first trigger.

[0028] (11) The alarm means has a function of issuing an alarm when an abnormality is detected in a specific monitoring area of ​​the vehicle while the vehicle is in a monitoring state, and the second trigger is a system that indicates that the legitimate authentication operation has been accepted in the specific monitoring area.

[0029] In this way, a specific monitored area in the vehicle can be designated as an area in which the user performs authentication operation, and the authentication operation can be performed in a state in which issuance of an alarm is temporarily suppressed.

[0030] (12) The specific monitoring area may be a system including the spatial area inside the vehicle.

[0031] In this way, the spatial area inside the vehicle can be used as the area in which the user performs authentication operations, and authentication of people inside the vehicle can be performed while temporarily suppressing the issuance of an alarm.

[0032] (13) When the vehicle is in a monitoring state, abnormalities are monitored in each of a plurality of monitoring areas of the vehicle, and when the first trigger is received while the vehicle is in the monitoring state, the control means temporarily suppresses the issuance of an alarm for the specific monitoring area which is a part of the plurality of monitoring areas, and when the second trigger is received, cancels the monitoring state for abnormalities in all of the plurality of monitoring areas.

[0033] In this way, even if the monitoring state of an abnormality in a specific monitoring area is temporarily released in response to the first trigger, if a normal authentication operation is not accepted in the specific monitoring area, the monitoring state of abnormalities in all of the plurality of monitoring areas will not be released. Therefore, high security can be achieved.

[0034] (14) It is preferable that the alarm means be a system that activates an alarm when an abnormality is detected in a predetermined area different from the specific monitoring area between the first trigger and the second trigger.

[0035] In this way, even if the monitoring state of an abnormality is temporarily released in some monitoring areas in response to the first trigger, if an abnormality is detected in a predetermined area other than this, an alarm will be activated, so that it is possible to suppress the occurrence of illegal acts such as theft of the vehicle itself or accessories of the vehicle.

[0036] (15) It is preferable that the system include alarm means having a function of activating an alarm when an abnormality is detected while the vehicle is in a monitored state, and control means for temporarily suppressing the activation of the alarm by the alarm means when there is a second trigger indicating that a normal authentication operation has been accepted while the vehicle is in a monitored state, and maintaining the vehicle in a non-monitored state when there is a first trigger.

[0037] By doing so, it is maintained in a non-monitoring state on the condition that there is a second trigger indicating that a normal authentication operation has been received, so the security is high. Also, since the activation of the alarm is suppressed by the second trigger, it is suppressed that the alarm is erroneously activated when a legitimate user tries to use the vehicle. In addition, since the period during which it can be maintained in a non-monitoring state while suppressing the activation of the alarm is limited to a temporary period from the second trigger, this can also be a desirable basis for security. Therefore, it is possible to enhance the security while suppressing the activation of false alarms. Such an invention has, in addition to the viewpoint of preventing unauthorized acts such as theft of the vehicle by a third party, the viewpoint of suppressing the activation of false alarms caused by legitimate users and suppressing the occurrence of undesirable situations for the legitimate users.

[0038] (16) It is preferable to use a program that causes a computer to execute the functions as the system according to any one of the above (1) to (15).

[0039] By doing so, by installing the program in a computer and causing it to exhibit each function according to the forms of (1) to (15), high security can be realized.

Advantages of the Invention

[0040] According to the present invention, it is possible to provide a technology related to vehicle security different from the prior art. According to the present invention, for example, it is possible to provide a system, a program, etc. that are excellent in security while suppressing the activation of false alarms.

[0041] Note that the effects of the invention of the present application are not limited to this, and the effects exerted by the components of the configuration disclosed in this specification, drawings, etc. are also disclosed, and the applicant also has the intention of obtaining rights through divisional applications, amendments, etc. for the configurations that exert such effects. For example, in this specification, the parts described as "can" or "is possible" are descriptions that explicitly indicate the effects exerted, and even if there is no description such as "can" or "is possible", there are parts that indicate the effects. Further, even if there is no such description, there are effects grasped by the said configuration.

Brief Description of the Drawings

[0042]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Modes for Carrying Out the Invention

[0043] [Configuration of the System] Referring to FIG. 1, an example of the configuration of the system according to the present invention will be described. The following describes the case where the present invention is applied to an electronic key system that locks (also referred to as locking) and unlocks (also referred to as unlocking) a vehicle door using an electronic key carried by a user. In the electronic key system, for example, unlocking of the vehicle door is executed by transmitting and receiving a wireless signal between the electronic key and the vehicle-side device. Generally, the distance at which wireless communication is possible between the electronic key and the vehicle-side device (hereinafter also referred to as the wireless communication possible distance) is limited to a relatively small distance. Therefore, usually, when the distance between the electronic key and the vehicle-side device is greater than the wireless communication possible distance, no wireless signal is transmitted and received between the electronic key and the vehicle-side device, and the unlocking of the vehicle door is not executed.

[0044] FIG. 1 is a schematic diagram showing a vehicle system 100 to which the system according to the present embodiment is applied. For example, as shown in FIG. 1, the vehicle system 100 includes a vehicle 1, an electronic key 2, and a remote terminal 3 (described later), etc.

[0045] The vehicle exemplified in the vehicle system 100 is preferably, for example, an automobile, and particularly preferably a four-wheel automobile. However, it is not limited to four-wheel automobiles, and the vehicle may be a large vehicle with four or more wheels. Further, the vehicle exemplified in the vehicle system 100 is not limited to only general vehicles such as transportation vehicles (for example, trucks, etc.), business vehicles (for example, taxis, buses, etc.) and general vehicles (so-called private cars), and may be developed for multiple uses. For example, the vehicle may be shared by unspecified persons, such as for car sharing or rental.

[0046] The electronic key 2 is a key capable of performing wireless communication with the vehicle 1, and is preferably, for example, an original electronic key attached to the vehicle 1. The electronic key 2 is usually carried by a regular user of the vehicle 1 or the like. The electronic key 2 is also referred to as a smart key, for example.

[0047] FIG. 2 is an example of a block diagram of a vehicle system 100 according to this embodiment. The vehicle system 100 is composed of, for example, two systems such as an electronic key system 10 and an authentication system 20.

[0048] The electronic key system 10 is a system for realizing locking and unlocking of the vehicle door 9 and the like by wireless communication between the vehicle 1 and the electronic key 2, and is a system originally incorporated in the vehicle 1.

[0049] The electronic key system 10 is configured to include various ECUs such as, for example, an electronic key ECU (Engine Control Unit) 11 and a body ECU 12.

[0050] The electronic key ECU 11 is a processing unit that controls wireless communication with the electronic key 2. The electronic key ECU 11 has, for example, a function of detecting radio waves from the electronic key 2, a function of determining the validity of the electronic key 2, and a function of transmitting the determination result to the body ECU 12 and the like.

[0051] The body ECU 12 is a processing unit that executes control on the body of the vehicle 1 and the like. For example, the body ECU 12 has a function of transmitting a lock signal (also referred to as a locking signal) and an unlock signal (also referred to as an unlocking signal) to the vehicle door 9 (see FIG. 1) of the vehicle 1.

[0052] In the electronic key system 10, the electronic key ECU 11 and the electronic key 2 are mutually associated. For example, when a user carrying the electronic key 2 presses the second reception unit 7 (see FIG. 1) of the vehicle 1 near the vehicle 1, wireless communication is performed between the electronic key ECU 11 and the electronic key 2. The second reception unit 7 is, for example, a door switch or other switch. Then, the electronic key ECU 11 executes the collation process of the electronic key 2 based on the wireless signal from the electronic key 2. When it is determined that the electronic key 2 is legitimate, the electronic key ECU 11 transmits a signal indicating that the vehicle door 9 of the vehicle 1 should be unlocked to the body ECU 12. The body ECU 12 that receives this signal transmits an unlock signal to the vehicle door 9. Thereby, the unlocking of the vehicle door 9 is realized.

[0053] Note that the unlocking operation of the vehicle door 9 is not limited to the pressing operation of the second reception unit 7, and may be a pressing operation of an unlock button provided on the electronic key 2. Also, there are various unlocking operations depending on the vehicle manufacturer, vehicle type, etc. For example, when a touch sensor or the like is provided on the handle portion of the vehicle door, an operation of touching the handle portion may be the unlocking operation of the vehicle door 9.

[0054] The authentication system 20 is a system for performing authentication (also referred to as user authentication) of a user who attempts to use the vehicle (for example, a person who attempts to board the vehicle 1, or a person who attempts to drive the vehicle 1, etc. The same applies hereinafter), and is, for example, a system retrofitted to the vehicle 1. The authentication system 20 is, for example, a system for preventing fraud on the vehicle 1 itself or an accessory of the vehicle 1 (for example, the engine of the vehicle 1, etc.), and is also referred to as an anti-fraud system or a security system.

[0055] As shown in FIG. 2, the authentication system 20 includes, for example, a control unit 21 (an example of control means), a detection unit 22 (an example of detection means), a communication unit 23 (an example of communication means), an input device 24 (an example of input means), and an alarm 25 (an example of alarm means).

[0056] The control unit 21 is a controller having a CPU, a memory such as a ROM and a RAM, a timer (an example of time measuring means), and other peripheral circuits. Various programs are stored in the ROM of the control unit 21, and the control unit 21 realizes various functions by executing these programs. The various programs include a program describing an algorithm for executing the processes shown in the flowcharts of FIGS. 3 to 5. The control unit 21 is a processing unit that mainly operates in the authentication system 20.

[0057] The control unit 21 has various functions such as an alarm control function for controlling the activation operation and stop operation of an alarm by the alarm device 25, an authentication function for performing user authentication, and a determination function for determining whether a normal authentication operation (described later) has been received. For example, when information indicating that there is a first trigger is acquired from the detection unit 22, the determination function has a function of temporarily suppressing the activation of the alarm by the alarm device 25 and determining whether to shift the vehicle 1 to an unmonitored state.

[0058] Note that the monitored state is a state in which an abnormality (also referred to as a security abnormality, etc.) is being monitored, and is also referred to as a warning state, for example. The unmonitored state is a state in which an abnormality is not being monitored, and is also referred to as a non-warning state, for example.

[0059] The detection unit 22 is a processing unit capable of detecting, for example, the state of the vehicle 1 and the behavior of the vehicle 1.

[0060] The communication unit 23 (see FIG. 2) is a processing unit capable of performing wireless communication with the remote terminal 3 (described below).

[0061] The remote terminal 3 (see FIG. 1) is a remote control terminal capable of performing wireless communication with the vehicle 1 (specifically, the communication unit 23 of the authentication system 20 of the vehicle 1). The remote terminal 3 can transmit and receive wireless signals with the vehicle 1 within a range where wireless communication with the vehicle 1 is possible. The remote terminal 3 is provided, for example, as an accessory to the authentication system 20.

[0062] The remote terminal 3 is provided with a non-monitoring command transmission button (not shown) for transmitting a non-monitoring command (described below). The non-monitoring command is a command for shifting the vehicle 1 from the monitoring state to the non-monitoring state. When the communication unit 23 receives the non-monitoring command from the remote terminal 3, it transmits information to that effect to the control unit 21. Based on this information, the control unit 21 shifts the vehicle 1 from the monitoring state to the non-monitoring state.

[0063] Also, the user can perform high-security settings (described later), for example, using the remote terminal 3.

[0064] Here, the authentication system 20 is provided with, for example, two types of authentication operations: a first authentication operation and a second authentication operation.

[0065] For example, when the second authentication operation is required as the authentication operation, the user needs to input pre-registered authentication information. When the first authentication operation is required as the authentication operation, the user needs to input authentication information that can be input with fewer procedures than when the second authentication operation is required. The authentication information may be, for example, alphabets, numbers, symbols, hiragana, katakana, or a combination of two or more of these, but if it is any one type, it is easy to simplify the configuration of the input means. The input means can receive the input of the authentication information and may be, for example, a keyboard, a numeric keypad, or a dedicated button. The authentication information required in the first authentication operation may be common with a part of the authentication information required in the second authentication operation (for example, the first or a plurality of predetermined characters from the beginning). In this way, the possibility that the user forgets the authentication information is reduced. The authentication information required in the first authentication operation and the second authentication operation may be preset by the user or the like, for example.

[0066] Thus, since the user procedures required in the first authentication operation are fewer than those required in the second authentication operation, the authentication by the first authentication operation becomes convenient for the user. The proper use of the first authentication operation and the second authentication operation will be described later. "Procedure" may be, for example, the amount of user operations, such as the number of times a button is pressed on the input device 24, the number of buttons to be operated, etc.

[0067] The high-security setting is a setting for enhancing the security performance of the authentication system 20. The high-security setting is a setting that prohibits setting the first authentication operation out of the two types of authentication operations, the first authentication operation and the second authentication operation, as the normal authentication operation. The authentication system 20 prohibits setting the first authentication operation as the normal authentication operation and sets the second authentication operation as the normal authentication operation. The user procedures required in the second authentication operation that is set as the normal authentication operation are more than those required in the first authentication operation, so it is suitable for ensuring higher security. On the other hand, when the high-security setting is not made, the authentication system 20 sets either the first authentication operation or the second authentication operation as the normal authentication operation if either one is performed. As a result, the authentication operation that the user should perform becomes simple.

[0068] In addition, for example, when using the remote terminal 3, it is preferable to be able to set the vehicle 1 to immediately shift from the monitoring state to the non-monitoring state in response to the first trigger described later. In the authentication system 20, it is preferable to be able to set whether to prioritize security or user convenience.

[0069] The input device 24 functions as an input means capable of inputting authentication information. The input device 24 is preferably provided, for example, in the space area inside the vehicle 1, and particularly preferably installed in a place where it is difficult to be seen from outside the vehicle. Such a place is preferably a place where the line of sight from a person outside the vehicle cannot reach, for example, a place where the line of sight from a person outside the vehicle is blocked by a member constituting the vehicle (for example, the vehicle body) or an object mounted on the vehicle (for example, a seat, a dashboard, etc.).

[0070] The alarm 25 is a device capable of activating an alarm. The alarm 25 has a function of activating an alarm when an abnormality is detected, for example, in a specific monitoring area of the vehicle 1 when the vehicle 1 is in the monitoring state. The alarm 25 is provided separately from, for example, the buzzer originally provided in the vehicle 1.

[0071] The "activation of the alarm" by the alarm device 25 may be the sounding of an alarm sound such as a siren. However, it is not limited to this, and the "activation of the alarm" may be, for example, the utterance of an alarm message such as "An abnormality has been detected". Alternatively, the "activation of the alarm" may be an alarm notification operation in which the alarm device 25 cooperates with the communication unit 23 to notify an alarm message or the like to the user's smartphone or the like. The alarm device 25 may issue an alarm by a method that can be perceived by a person outside the vehicle.

[0072] As shown in FIG. 2, the vehicle 1 includes a first reception unit 6, a second reception unit 7, and the like.

[0073] The first reception unit 6 functions as a means for receiving an input related to the operation of the prime mover (for example, an engine or a motor) of the vehicle 1. The first reception unit 6 may be, for example, a predetermined pedal of the vehicle (for example, an accelerator pedal or a brake pedal), an accessory power switch, an ignition switch (for example, a button-type ignition switch provided on a dashboard or the like, or an ignition switch composed of a switching mechanism provided inside a key cylinder). In the case of an electric vehicle, the first reception unit 6 may be a switch for turning on the system power of the vehicle. It is particularly preferable that the first reception unit 6 is an operation member originally provided in the internal space area of the vehicle 1.

[0074] [Schematic operation] Next, the schematic operation of the vehicle system 100 according to the present embodiment will be described.

[0075] In the present embodiment, for example, when there is a first trigger while the vehicle 1 is in a monitoring state, the control unit 21 temporarily suppresses the activation of the alarm by the alarm device 25, and when there is a second trigger indicating that a normal authentication operation has been received, the control unit 21 maintains the vehicle 1 in a non-monitoring state.

[0076] For example, if the normal authentication operation is not accepted after the first trigger and there is no second trigger, the control unit 21 does not shift the vehicle 1 to the non-monitored state and releases the temporary suppression of the activation of the alarm by the alarm device 25. By doing so, when the normal authentication operation is not accepted, the alarm by the alarm device 25 is activated. For example, it is possible to discourage unauthorized acts such as vehicle theft by a third party other than the user (e.g., a thief), and high security can be realized.

[0077] The "first trigger" may be configured to indicate, for example, that a predetermined operation has been received from the user when the lock of the vehicle 1 (e.g., the vehicle door 9 of the vehicle 1) is unlocked. For example, when there is a predetermined operation to use the vehicle 1, since this may be by a legitimate user, the activation of the alarm is temporarily suppressed. By doing so, it is possible to suppress the activation of a false alarm caused by a legitimate user.

[0078] The presence or absence of the "first trigger" is preferably detected, for example, by a detection unit 22 (an example of a detection means) capable of detecting the first trigger. And when the control unit 21 (an example of a control means) acquires information from the detection unit 22 that the first trigger is present, it is preferable to temporarily suppress the activation of the alarm by the alarm device 25 (an example of an alarm means). By doing so, even if the control unit 21 is not provided with a function capable of detecting the first trigger, the presence or absence of the first trigger can be determined based on the information from the detection unit 22.

[0079] Note that the present invention is not limited to this. The authentication system 20 may not be provided with the detection unit 22, and the control unit 21 itself may have a function capable of detecting the first trigger.

[0080] The "first trigger" may be configured to indicate that a predetermined condition is satisfied, for example, such that it is possible to objectively determine that the user is about to use vehicle 1. The "first trigger" may indicate, for example, that the user has touched the electronic key 2, that a predetermined operation has been performed on the electronic key 2, that the electronic key 2 is held by the user, that the electronic key 2 has moved within a predetermined distance range from vehicle 1, that the vehicle door 9 has been opened, or that the lock of the vehicle door 9 has been released.

[0081] For example, that the user has touched the electronic key 2 may be detected, for example, by a sensor that detects contact of an object with the electronic key 2. That the electronic key 2 is held by the user may be, for example, that a vibration sensor is provided on the electronic key 2 and this vibration sensor has detected vibration. That the vehicle door 9 has been opened may be detected, for example, using a door sensor that detects opening and closing of the door. That the lock of vehicle 1 has been released may be detected, for example, as follows.

[0082] For example, vehicle 1 is pre - equipped with an answer - back function. The answer - back function is a function in which vehicle 1 responds to an operation by the user (for example, an unlock operation). In the answer - back function, for example, the hazard lamp blinks or a buzzer sounds, etc. When the user performs an unlock operation, for example, the body ECU 12 transmits an unlock command signal to the vehicle door 9 (or an ECU that controls the operation of the vehicle door 9, etc.), and thereby the lock of the vehicle door 9 is released. At this time, the body ECU 12 transmits a predetermined command signal to the answer - back execution device, and the execution device performs an operation according to the predetermined command signal. Then, the detection unit 22 may detect that the lock of the vehicle door 9 has been released by monitoring the behavior of the execution device.

[0083] For example, when the execution device of the answer back is a hazard lamp, the body ECU 12 transmits a flashing command signal for a predetermined number of times (for example, 2 times) to the hazard lamp, and the hazard lamp flashes a predetermined number of times in response to the flashing command signal. Then, the detection unit 22 detects that the lock of the vehicle door 9 has been released by detecting the flashing interval or the number of flashes of the hazard lamp or the like.

[0084] Also, for example, when the execution device of the answer back is a buzzer, the body ECU 12 transmits a buzzing command signal for a predetermined number of times (for example, 2 times) to the buzzer, and the buzzer buzzes a predetermined number of times in response to the buzzing command signal. The detection unit 22 detects that the lock of the vehicle door 9 has been released by detecting the buzzing interval or the number of buzzes of the buzzer or the like.

[0085] Note that the detection unit 22 may indirectly monitor the behavior of the execution device of the answer back by, for example, monitoring a CAN (Controller Area Network) connected to each ECU in the vehicle 1 instead of directly monitoring the behavior of the execution device of the answer back.

[0086] The "normal authentication operation" may include, for example, a first input operation of inputting normal authentication information to a first input means capable of inputting authentication information, and a second input operation performed on a second input means originally provided in the vehicle 1. Also, the "normal authentication operation" may be such that, for example, the second input operation is performed immediately after the first input operation. The second input operation may be performed as an input completion operation for instructing the completion of the input of the authentication information in the first input operation. The normal authentication operation means that authentication has been successful, and for example, when correct authentication information is input, it is considered that the normal authentication operation has been performed.

[0087] In this way, if only one of the first input operation and the second input operation is received, the vehicle 1 is not maintained in the non-monitoring state but remains in the monitoring state, and when the first input operation and the second input operation are received, the vehicle 1 is maintained in the non-monitoring state. Also, for example, the second input means originally provided in the vehicle 1 can be used to instruct the completion of the input of the authentication information in the first input operation. Therefore, higher security can be achieved without newly providing a means for instructing the completion of the input of the authentication information.

[0088] The authentication information may be registered (for example, initially set) in advance in the control unit 21 or the like by a regular user (such as a purchaser of the authentication system 20). However, it is not limited to this. For example, regular authentication information may be registered in advance in the control unit 21 or the like by the seller side at the design stage and notified to the purchaser through a dedicated website or printed matter for the purchaser of the authentication system 20. Also, when the authentication system 20 is installed in the vehicle 1 shared by unspecified persons, such as for carsharing or rental, the regular authentication information may be shared with the authentication information (such as a phone number) used in services such as carsharing or rental cars. In this case, the user does not need to consider the authentication information for the authentication system 20 separately, and high usability can be achieved.

[0089] The "first input means" is preferably an operation member provided in the internal space area of the vehicle 1, for example, the input device 24.

[0090] The "second input means" is preferably, for example, the first reception unit 6. In this way, for example, an input related to the operation of the prime mover of the vehicle 1, such as an operation normally performed when using the vehicle 1, can also serve as an input completion operation for instructing the completion of the input of the authentication information. Therefore, the operability of the user can be improved. Also, since the first reception unit 6 originally provided in the vehicle 1 is used for the input completion operation, it is not necessary to separately provide an operation member for performing the input completion operation.

[0091] The "second trigger" may indicate that a normal authentication operation has been accepted in a specific monitoring area of the vehicle 1. In this way, the authentication operation by the user in the specific monitoring area can be performed in a state where the activation of the alarm is suppressed under the monitoring state of the vehicle 1.

[0092] The "specific monitoring area" is, for example, an area where the authentication operation is performed, and as an example, it may be the internal space area of the vehicle 1, for example. In this way, the internal space area of the vehicle 1 can be set as the area where the user performs the authentication operation, and the authentication of the person in the internal space area of the vehicle 1 can be performed in a state where the activation of the alarm is suppressed.

[0093] Note that it is not limited to this. If it is possible to authenticate a person who is trying to use the vehicle 1, the authentication operation may be accepted at any location. For example, the authentication operation may be accepted outside the vehicle 1. In this case, for example, an input means for authentication information may be provided outside the vehicle 1. For example, a sensor capable of detecting a knock may be provided on the vehicle body itself (for example, a window, etc.) of the vehicle 1, and an operation of knocking on the vehicle body itself of the vehicle 1 may be accepted as the authentication operation. Then, it is preferable to determine whether the received knock pattern is a specific pattern. Considering that the authentication of a person actually in the internal space area of the vehicle 1 can be performed, etc., the input means for authentication information is particularly preferably provided in the internal space area of the vehicle 1.

[0094] [Detailed operation] Next, with reference to FIGS. 3 to 5, the detailed operation of the vehicle system 100 according to the present embodiment will be described. FIGS. 3 to 5 are flowcharts showing an example of control processing (for example, anti-fraud processing) executed by the control unit 21 of the authentication system 20.

[0095] First, in step S11 of FIG. 3, the control unit 21 determines whether the vehicle 1 has shifted from a non-monitoring state to a monitoring state.

[0096] For example, when a user performs a locking operation to lock the vehicle door 9 of vehicle 1, the vehicle door 9 of vehicle 1 is locked and vehicle 1 transitions from an unmonitored state to a monitored state. Examples of the locking operation include an operation of pressing the second reception unit 7 of the vehicle door 9 while the electronic key 2 is in the vicinity of vehicle 1, or an operation of pressing the lock button of the electronic key 2 while the electronic key 2 is in the vicinity of vehicle 1. Then, when vehicle 1 transitions to the monitored state, the process proceeds from step S11 to step S12.

[0097] Here, when vehicle 1 transitions from an unmonitored state to a monitored state, for example, the control unit 21 starts monitoring for corresponding types of abnormalities in each of a plurality of monitoring areas of vehicle 1. As a result, monitoring for a plurality of types of abnormalities is started in vehicle 1. Note that the plurality of monitoring areas are also referred to as, for example, a plurality of monitored parts.

[0098] The "plurality of monitoring areas" may be determined, for example, as areas in the vehicle where there is a high need for monitoring. Such areas may be, for example, the internal space area of vehicle 1, the trunk room, the bonnet, and other predetermined parts of vehicle 1 that can be opened and closed, one or more of the first reception unit 6 and other areas. For example, various sensors are provided in each of these monitoring areas, and the control unit 21 monitors for abnormalities in each monitoring area by cooperating with the sensors provided in each monitoring area. Note that an abnormality in the internal space area of vehicle 1 may be detected, for example, by whether an object (e.g., a person) has moved within the space area or vehicle 1 has vibrated. The movement of an object within the space area may be detected, for example, by a human sensor or the like, and the vibration of vehicle 1 may be detected, for example, by a vibration sensor or the like. An abnormality in the trunk room, the bonnet, and other predetermined parts of vehicle 1 that can be opened and closed may be detected when the part is opened. An abnormality in the first reception unit 6 may be detected when the first reception unit 6 is operated. What events are detected as abnormalities depends on the structure or other characteristics of each monitoring area.

[0099] In step S12, the control unit 21 determines whether high-security settings are made. If it is determined that high-security settings are made, the process proceeds from step S12 to step S51 (Fig. 5). If it is determined that high-security settings are not made, the process proceeds from step S12 to step S13.

[0100] Hereinafter, the case where the process proceeds to step S13 (Fig. 3) will be described. The case where the process proceeds to step S51 (Fig. 5) will be described later.

[0101] As shown in Fig. 3, when the vehicle 1 is in a monitoring state, the control unit 21 waits until any one of, for example, reception of a non-monitoring command from the remote terminal 3 (step S13), reception of an authentication operation (step S14), and trigger B (an example of the first trigger) (step S17) occurs. Specifically, the determination processes of steps S12, S13, S14, and S17 are repeated until any one of reception of a non-monitoring command from the remote terminal 3, reception of an authentication operation, and trigger B occurs.

[0102] First, in step S13, the control unit 21 determines whether a non-monitoring command has been received from the remote terminal 3 when the vehicle 1 is in a monitoring state. As described above, the non-monitoring command is a command to shift the vehicle 1 to a non-monitoring state.

[0103] For example, when a user carrying the remote terminal 3 presses the non-monitoring command transmission button of the remote terminal 3 in a state of being close to the vehicle 1, a non-monitoring command is transmitted from the remote terminal 3, and the communication unit 23 receives the non-monitoring command. Thereby, the control unit 21 determines that a non-monitoring command has been received from the remote terminal 3, and the process proceeds from step S13 to step S23.

[0104] In step S23, the control unit 21 shifts the vehicle 1 to a non-monitoring state. For example, the control unit 21 shifts the vehicle 1 from the monitoring state to the non-monitoring state. Specifically, the control unit 21 shifts all of the plurality of monitoring areas of the vehicle 1 from the monitoring state to the non-monitoring state. As a result, the abnormal monitoring in all of the plurality of monitoring areas inside the vehicle 1 stops.

[0105] In this way, when the control unit 21 receives a predetermined signal (for example, a non-monitoring command signal) from the remote terminal 3 (an example of a remote operation terminal), regardless of the presence or absence of the first trigger and the presence or absence of the second trigger indicating that a normal authentication operation has been received (step S22 described later), the control unit 21 shifts the vehicle 1 to the non-monitoring state and maintains it in this state. By doing so, even if the user does not perform a normal authentication operation, when a predetermined signal from the remote terminal 3 that can be distinguished from the signal from the electronic key 2 is received, the vehicle 1 can be shifted to the non-monitoring state and maintained in this state. Therefore, it is possible to improve the convenience of the user while realizing high security.

[0106] On the other hand, if it is determined in step S13 that the non-monitoring command has not been received from the remote terminal 3, the process proceeds from step S13 to step S14.

[0107] In step S14, the control unit 21 determines whether or not an authentication operation has been received. Since the processing content of this step S14 is the same as the processing content of step S19 described later, the details will be described later.

[0108] For example, when the authentication operation has not been received, the process proceeds from step S14 to step S17, and when the authentication operation is received, the process proceeds from step S14 to step S15.

[0109] In step S15, the control unit 21 determines whether there is a trigger A (an example of the second trigger) indicating that a normal first authentication operation or a normal second authentication operation has been received. If there is trigger A, the process proceeds from step S15 to step S23. If there is no trigger A, the process proceeds from step S15 to step S16.

[0110] In step S16, the control unit 21 activates the alarm by the alarm device 25.

[0111] If the authentication operation is not received in step S14 and the process proceeds from step S14 to step S17, the control unit 21 determines whether there is a trigger B (step S17).

[0112] If it is determined that there is no trigger B, the process returns to step S12 again. On the other hand, if it is determined that there is a trigger B, the process proceeds from step S17 to step S18.

[0113] Here, if it is determined that there is a trigger B, the control unit 21 temporarily suppresses the activation of the alarm by the alarm device 25 while maintaining the vehicle 1 in the monitoring state. For example, the control unit 21 temporarily suppresses the activation of the alarm regarding a specific monitoring area which is a part of a plurality of monitoring areas. Specifically, the control unit 21 temporarily suppresses the activation of the alarm regarding the specific monitoring area by temporarily canceling the abnormal monitoring state in the specific monitoring area which is a part of a plurality of monitoring areas while maintaining the monitoring state of the entire vehicle 1.

[0114] Note that among a plurality of monitoring areas (also referred to as a plurality of monitored parts, etc.), a predetermined area different from the specific monitoring area (for example, the remaining monitoring areas excluding the specific monitoring area) remains in the monitoring state.

[0115] Since the "specific monitoring area" includes, for example, the space area inside vehicle 1, even if the user opens vehicle door 9 and enters the space area inside vehicle 1, the alarm by alarm device 25 will not be activated immediately. On the contrary, even if the monitoring state in the "specific monitoring area" is temporarily released, the areas that still require continuous monitoring will continue to be monitored. Therefore, if an abnormality is detected in such areas, the alarm by alarm device 25 will be activated.

[0116] In this way, when there is a trigger B indicating that a predetermined operation has been received from outside vehicle 1 while vehicle 1 is in a monitoring state, for example, control unit 21 temporarily suppresses the activation of the alarm by alarm device 25. When it is determined that there has been a trigger B, control unit 21 starts a timing process.

[0117] In step S18, control unit 21 determines whether a predetermined time has elapsed since trigger B. The predetermined time may be set in advance as a fixed value or may be set by the user.

[0118] For example, when the predetermined time has elapsed because the person performing the authentication operation is taking time for the authentication operation, it is determined in step S18 that the predetermined time has elapsed since trigger B, and the process proceeds from step S18 to step S24. Also, for example, even when an authentication operation is received after trigger B, or when the second input operation is not received after the first input operation and the predetermined time has elapsed, it is determined in step S18 that the predetermined time has elapsed since trigger B, and the process proceeds from step S18 to step S24. In step S24, control unit 21 activates an alarm for alarm device 25. Details of step S24 will be described later.

[0119] In this way, the point in time when there is a trigger B becomes, for example, the start point of the time limit for performing a regular authentication operation. When the regular authentication operation is not performed within that time limit, the alarm by alarm device 25 is activated.

[0120] On the other hand, when a predetermined time has not yet elapsed since trigger B, the process proceeds from step S18 to step S19.

[0121] In step S19, the control unit 21 determines whether an authentication operation has been received.

[0122] When the authentication operation has not been received, the process proceeds from step S19 to step S20, and when the authentication operation is received, the process proceeds from step S19 to step S22. Hereinafter, the case where the process proceeds to step S22 will be described. The case where the process proceeds to step S20 will be described later.

[0123] In step S22, the control unit 21 determines whether there is a trigger C (an example of a second trigger) indicating that a normal first authentication operation or a normal second authentication operation has been received. Specifically, the control unit 21 determines whether the first authentication operation or the second authentication operation received in step S19 is a normal authentication operation. Here, allowing not only the second authentication operation but also the first authentication operation is to reduce the operation burden related to the authentication of a normal user.

[0124] For example, when the user performs the first authentication operation, after the user inputs authentication information using the input device 24, the user operates the first reception unit 6 (for example, a single pressing operation. The same applies hereinafter). Thereby, the control unit 21 receives the authentication operation of the input operation of the authentication information (an example of a first input operation) and the operation of the first reception unit 6 (an example of a second input operation) (step S19).

[0125] Then, the process proceeds from step S19 to step S22, and the control unit 21 collates the authentication information input using the input device 24 with the pre-registered normal authentication information to execute user authentication.

[0126] For example, when the input authentication information matches the regular authentication information and user authentication is successful, the control unit 21 determines in step S22 that there was a trigger C indicating that a regular authentication operation (for example, a regular first authentication operation) was accepted.

[0127] Then, the process proceeds from step S22 to step S23, and the control unit 21 shifts the vehicle 1 from the monitoring state to the non-monitoring state.

[0128] For example, the control unit 21 causes a specific monitoring area (for example, the space area inside the vehicle 1) that had temporarily shifted to the non-monitoring state in response to trigger B to remain in the non-monitoring state, and causes the remaining monitoring areas that were still in the monitoring state at the time when trigger B occurred to shift from the monitoring state to the non-monitoring state and be maintained in this state. As a result, abnormal monitoring of all of the plurality of monitoring areas of the vehicle 1 stops.

[0129] In this way, when there is a trigger B while the vehicle 1 is in the monitoring state, the control unit 21 temporarily suppresses the activation of an alarm regarding a specific monitoring area that is a part of the plurality of monitoring areas, and when there is a trigger C, releases the abnormal monitoring state of all of the plurality of monitoring areas. Conversely, when there is no trigger C, the abnormal monitoring state of all of the plurality of monitoring areas is not released. For example, even if the abnormal monitoring state in a specific monitoring area is temporarily released in response to the occurrence of trigger B, if a regular authentication operation is not accepted in the specific monitoring area, the abnormal monitoring state of all of the plurality of monitoring areas is not released. Therefore, high security can be achieved.

[0130] On the other hand, when there is no trigger C indicating that a normal authentication operation has been received, the process proceeds from step S22 to step S24 (described later). For example, when the input authentication information does not match the normal authentication information and the user authentication fails, the control unit 21 determines at step S22 that a normal authentication operation has not been received (for example, that an incorrect authentication operation has been received). Then, the process proceeds from step S22 to step S24.

[0131] Note that in this embodiment, the number of times the authentication operation can be received is 1, and for example, if an incorrect authentication operation is performed even once, an alarm is activated, but it is not limited to this, and the number of times the authentication operation can be received may be a plurality of times (for example, 3 times).

[0132] Next, the case where the process proceeds from step S19 to step S20 will be described.

[0133] In step S20, the control unit 21 determines, for example, whether a non - monitoring command has been received from the remote terminal 3 when a specific monitoring area of the vehicle 1 is temporarily in a non - monitored state. Note that step S13 and step S20 in FIG. 3 are different in that, for example, whether all of the plurality of monitoring areas of the vehicle 1 are in a monitored state or a part (such as a specific monitoring area) of the plurality of monitoring areas is temporarily in a non - monitored state.

[0134] For example, after there is a trigger B, the user presses the non - monitoring command transmission button of the remote terminal 3 in the internal space area of the vehicle 1. In response to this, the remote terminal 3 transmits a non - monitoring command, and the control unit 21 determines at step S20 that a non - monitoring command has been received from the remote terminal 3.

[0135] When a non - monitoring command is received from the remote terminal 3, the process proceeds from step S20 to step S23, and in the same manner as described above, the process of shifting the vehicle 1 to a non - monitored state is executed.

[0136] On the one hand, when no non-monitoring command is received from the remote terminal 3, the process proceeds from step S20 to step S21, and the control unit 21 determines whether an abnormality has been detected in the remaining monitoring areas (for example, a predetermined monitoring area that is still maintained in the monitoring state) excluding a specific monitoring area (for example, the space area inside the vehicle 1) among the plurality of monitoring areas. The remaining monitoring areas may be, for example, areas different from the area where the authentication operation is performed (in this embodiment, the space area inside the vehicle 1). As such areas, for example, in the vehicle 1, there are one or more of the trunk room, the bonnet, the first reception unit 6, and other areas.

[0137] When an abnormality is detected in the remaining monitoring areas between when there is trigger B (step S17) and when there is trigger C (step S22), the process proceeds from step S21 to step S24. On the other hand, when no abnormality is detected in the remaining monitoring areas, the process returns to step S18 again.

[0138] On the other hand, when it is determined in step S21 that an abnormality has been detected in the remaining monitoring areas that are still in the monitoring state, the alarm 25 activates an alarm (step S24).

[0139] In this way, when an abnormality is detected in a predetermined area different from the specific monitoring area between when there is trigger B and when there is trigger C, an alarm is activated. In this way, even if the abnormal monitoring state is temporarily released in some monitoring areas (for example, the space area inside the vehicle 1, etc.) in response to the presence of trigger B, when an abnormality is detected in other predetermined areas, the alarm is immediately activated, so that it is possible to suppress illegal acts such as theft of the vehicle 1 itself or vehicle accessories.

[0140] Next, step S24 in FIG. 3 will be described in detail.

[0141] As described above, · When no normal authentication operation is received within a predetermined time after the presence of trigger B (step S17) (YES in step S18), · When the authentication operation received in step S19 is different from the normal authentication operation (NO in step S22), or · When an abnormality is detected in a monitoring area other than a specific monitoring area between the presence of trigger B (step S17) and the presence of trigger C (step S22) (YES in step S21) the control unit 21 activates an alarm by the alarm device 25 (step S24).

[0142] Specifically, the control unit 21 does not maintain the vehicle 1 in a non-monitoring state (for example, does not allow maintaining the non-monitoring state, also referred to as such), and releases the temporary suppression of the activation of the alarm by the alarm device 25. Then, the alarm device 25 activates an alarm (step S24).

[0143] In this way, for example, even if a malicious third party intrudes into the internal space area of the vehicle 1, an alarm will be activated when any of the above operations is performed thereafter (step S24). Thereby, it is possible to discourage illegal acts such as vehicle theft by a malicious third party, and high security can be realized.

[0144] Note that different alarms (for example, alarms with different volumes, or different types of alarms, etc.) may be activated depending on whether the cause leading to the alarm activation process is · When no normal authentication operation is received within a predetermined time after the presence of trigger B, and · When the received authentication operation is different from the normal authentication operation, and · When an abnormality is detected in a monitoring area other than a specific monitoring area among a plurality of monitoring areas or any of the above.

[0145] In this way, after the trigger B occurs, even if an alarm is activated when the user cannot perform a normal authentication operation unintentionally, the user can know the cause. As a result, for example, the user can take appropriate actions according to the cause known at the time of the previous alarm activation during subsequent authentication operations.

[0146] When an alarm is activated in step S24, the process proceeds from step S24 (Figure 3) to step S31 (Figure 4).

[0147] The operations after the alarm is activated in step S24 (Figure 3) will be described with reference to the flowchart of Figure 4. Note that the alarm by the alarm device 25 automatically stops, for example, after a certain period of time has elapsed.

[0148] First, in step S31, the control unit 21 determines whether a high-security setting has been made. If it is determined that the high-security setting has been made, the process proceeds from step S31 to step S51 (Figure 5) described later. If it is determined that the high-security setting has not been made, the process proceeds from step S31 to step S32.

[0149] Then, in step S32, the control unit 21 determines whether a non-monitoring command has been received from the remote terminal 3 when the vehicle 1 is in a monitored state.

[0150] When a non-monitoring command is received from the remote terminal 3, the process proceeds from step S32 to step S40, and the control unit 21 shifts the vehicle 1 from the monitored state to the non-monitored state. At this time, when the alarm is being activated, the control unit 21 stops the activation of the alarm by the alarm device 25.

[0151] On the other hand, when a non-monitoring command has not been received from the remote terminal 3, the process proceeds from step S32 to step S33.

[0152] Then, the control unit 21 determines whether the authentication operation has been accepted (step S33).

[0153] If the authentication operation is accepted in step S33, the process proceeds from step S33 to step S34, and the control unit 21 determines whether there is a trigger D (an example of the second trigger). The trigger D indicates that the authentication operation accepted in step S33 is a normal second authentication operation. The control unit 21 does not determine that there is a trigger D even if the first authentication operation is performed.

[0154] For example, if a normal second authentication operation different from the normal first authentication operation is not performed, the process proceeds from step S34 to step S41, and the alarm is activated again. On the other hand, if there is a trigger D, the process proceeds from step S34 to step S40, and the control unit 21 shifts the vehicle 1 from the monitoring state to the non - monitoring state.

[0155] On the other hand, when the authentication operation is not accepted in step S33, the process proceeds from step S33 to step S35, and the control unit 21 determines whether there is a trigger E (an example of the first trigger) (step S35). The trigger E indicates the same conditions as the trigger B.

[0156] If there is a trigger E, the process proceeds from step S35 to step S36, and the control unit 21 starts the timing process and determines whether a predetermined time has elapsed since there was a trigger E (step S36). Since the processing contents of steps S35, S36, etc. in FIG. 4 are the same as the processing contents of steps S17, S18, etc. in FIG. 3, detailed descriptions are omitted.

[0157] For example, if the predetermined time elapses without the authentication operation being accepted, the process proceeds from step S36 to step S41. Then, the control unit 21 re - activates the alarm by the alarm device 25 (step S41).

[0158] On the other hand, when the specified time has not yet elapsed, the process proceeds from step S36 to step S37, and the control unit 21 determines whether an authentication operation has been received.

[0159] When the authentication operation has not been received, the process proceeds from step S37 to step S39, and the control unit 21 determines whether a non-monitoring command has been received from the remote terminal 3. Then, when a non-monitoring command is received from the remote terminal 3, the process proceeds from step S39 to step S40, and when a non-monitoring command has not been received from the remote terminal 3, the process returns from step S39 to step S36 again.

[0160] On the other hand, when the authentication operation is received in step S37, the process proceeds from step S37 to step S38.

[0161] For example, after the user operates the first reception unit 6, the user inputs authentication information using the input device 24, and then performs an authentication operation (an example of "an authentication operation different from the first authentication operation") of operating the first reception unit 6. Thereby, the control unit 21 receives the authentication operation of the input operation of the authentication information (an example of the first input operation) and the operation on the first reception unit 6 (an example of the second input operation) (step S37). Then, the process proceeds from step S37 to step S38.

[0162] In step S38, the control unit 21 determines whether there was a trigger F (an example of the second trigger) in step S37. The trigger F indicates that a normal second authentication operation has been performed. Similar to the trigger D, the control unit 21 does not determine that there was a trigger F even if the first authentication operation has been performed.

[0163] For example, when it is determined that there is no trigger F, the process proceeds from step S38 to step S41, and the alarm is activated again. When it is determined that there was a trigger F, the process proceeds from step S38 to step S40.

[0164] Then, the control unit 21 shifts the vehicle 1 from the monitoring state to the non-monitoring state (step S40). Specifically, all of the plurality of monitoring areas of the vehicle 1 are shifted from the monitoring state to the non-monitoring state and maintained in this state. At this time, when the alarm is being activated, the control unit 21 stops the activation of the alarm by the alarm device 25.

[0165] As described above, after the alarm is activated (step S24), when there is a trigger F, the control unit 21 shifts the vehicle 1 from the monitoring state to the non-monitoring state (step S40).

[0166] In this way, even if the vehicle 1 enters the monitoring state because the normal first authentication operation or the normal second authentication operation is not accepted after the trigger E (step S24), when the user performs the normal second authentication operation, the authentication system 20 determines that there is a trigger F and the vehicle 1 shifts to the non-monitoring state (step S40). Therefore, for example, even if a third party takes time to perform the first authentication operation, it is possible to prevent the vehicle from being maintained in the non-monitoring state by regarding this as a normal authentication operation.

[0167] In this way, after a predetermined period has elapsed since the trigger B and the alarm by the alarm device 25 is activated, the control unit 21 increases, for example, the user procedures required in the normal authentication operation. In this way, as long as the normal authentication operation is performed by the user, the increase in the burden can be suppressed, and when there is an error in the authentication operation, by increasing the necessary user procedures together with the activation of the alarm, it is possible to reduce the possibility of misidentifying a person who is not a normal user as a normal user. For example, after the alarm by the alarm device 25 is activated, the control unit 21 requests the user to perform the second authentication operation instead of the first authentication operation during the authentication operation by the user.

[0168] [When high-security settings are made] Next, the case where high-security settings are made will be described.

[0169] When high security settings are made, the process proceeds from step S12 in FIG. 3 to step S51 in FIG. 5.

[0170] The processing contents of steps S51, S52, S54 to S59, S61, and S62 in FIG. 5 are substantially the same as the processing contents of steps S13, S14, S16 to S21, S23, and S24 in FIG. 3. Therefore, the descriptions of steps S51, S52, S54 to S59, S61, and S62 in FIG. 5 will be omitted below. However, the triggers G (an example of the second trigger), H (an example of the first trigger), and I (an example of the second trigger) shown in FIG. 5 indicate the same conditions as the triggers D, E, and F, respectively. Also, the remote terminal 3 transmits a signal having a data part different from that transmitted by the electronic key 2. The difference in the data part may be, for example, at least one of an identifier (unique ID), authentication information, and a command as information unique to the remote terminal 3. Also, for example, the frequencies used by the remote terminal 3 and the electronic key 2 for wireless communication may be made different. When the authentication system 20 receives a signal from the remote terminal 30, it shifts the vehicle 1 to the non-monitoring state and maintains it regardless of the presence or absence of the triggers G, H, and I. In this way, it is possible to avoid the data transmitted by the electronic key 2 being forged and an unauthorized authentication being determined as a normal authentication.

[0171] When the process proceeds to step S60 after passing through steps S51, S52, S55 to S57, etc., the control unit 21 determines whether a normal second authentication operation has been received. In step S60, the control unit 21 determines whether there was a trigger I. Note that the processing content of step S53 is also the same as the processing content of step S60.

[0172] Specifically, after the user operates the first reception unit 6, the user inputs authentication information using the input device 24, and then performs an authentication operation of operating the first reception unit 6. The control unit 21 receives the authentication operation by the user (step S57). Then, the control unit 21 collates the authentication information input using the input device 24 in step S57 with the regular authentication information pre-registered in the control unit 21 to execute user authentication.

[0173] When the input authentication information matches the regular authentication information and user authentication is successful, the control unit 21 determines in step S60 that there was a trigger I indicating that a regular authentication operation (for example, a regular second authentication operation) was received. Then, the process proceeds from step S60 to step S61, and the control unit 21 shifts the vehicle 1 from the monitoring state to the non-monitoring state.

[0174] For example, in response to the presence of trigger H, the control unit 21 temporarily shifts to the non-monitoring state and maintains as it is a specific monitoring area (for example, the space area inside the vehicle 1, etc.) that was in the non-monitoring state, and shifts and maintains from the monitoring state to the non-monitoring state the remaining monitoring areas that were still in the monitoring state at the time when trigger H occurred. Thereby, abnormal monitoring of all of the plurality of monitoring areas of the vehicle 1 stops.

[0175] On the other hand, when the input authentication information does not match the regular authentication information and user authentication fails, the control unit 21 determines in step S60 that a regular authentication operation (for example, a regular second authentication operation) was not received (for example, it can also be said that there was no trigger I indicating that a regular authentication operation was received).

[0176] Then, the process proceeds from step S60 to step S62, and the control unit 21 activates an alarm by the alarm device 25.

[0177] As described above, in the authentication system 20 according to this embodiment, when there is a first trigger while the vehicle 1 is in a monitored state, the control unit 21 temporarily suppresses the activation of the alarm by the alarm device 25, and when there is a second trigger indicating that a normal authentication operation has been accepted, the vehicle 1 is maintained in a non-monitored state.

[0178] Since the authentication system 20 is maintained in a non-monitored state on the condition that there is a trigger (second trigger) indicating that a normal authentication operation has been accepted, the security is higher than when this condition is not met. For example, there is also a technique of shifting the vehicle 1 from a monitored state to a non-monitored state by causing the user to perform a predetermined operation without authenticating the user. However, in such a technique, if a third party knows the mechanism, the vehicle 1 will be shifted to a non-monitored state by the third party performing a predetermined operation. In this embodiment, since an authentication operation is involved, the possibility of fraud such as vehicle theft by a third party other than the legitimate user is reduced.

[0179] In addition, since the activation of the alarm is suppressed when there is a first trigger, the accidental activation of the alarm is suppressed when the legitimate user is performing an authentication operation. For example, when a legitimate user gets into the vehicle 1 to perform an authentication operation, if the activation of the alarm due to detecting an abnormality inside the vehicle 1 is suppressed, the possibility of an incorrect alarm being issued despite the user being a legitimate user is suppressed. Also, when a legitimate user gets into the vehicle 1, there is a possibility that vibration occurs in the vehicle 1, but if the activation of the alarm due to detecting an abnormality caused by the vibration is suppressed, the possibility of an incorrect alarm being issued despite the user being a legitimate user is suppressed. On the contrary, if the alarm is issued when an abnormality is detected in an area different from the area where the authentication operation is performed (for example, the above-mentioned "remaining monitoring area"), it is possible to achieve both the suppression of false alarms caused by legitimate users and the prevention of fraud caused by third parties.

[0180] Furthermore, since the period during which the authentication operation can be received while the activation of the alarm is suppressed is limited to a temporary period from when the first trigger occurred, this can also be a desirable basis for security.

[0181] For the above reasons, according to this embodiment, it is possible to enhance security while suppressing the activation of false alarms. Also, in the authentication system 20, in addition to the viewpoint of preventing unauthorized acts such as theft of the vehicle 1 by a third party, it suppresses the activation of false alarms caused by legitimate users and has the viewpoint of suppressing the occurrence of undesirable situations for the legitimate users, so it can be said that it proposes a security technology different from the conventional one.

[0182] [Modification Example] As described above, an example of the embodiment of the present invention has been explained, but the present invention is not limited to the above embodiment, and various modifications are possible. For example, the following modification examples may be implemented.

[0183] (1) For example, in the above embodiment, the "normal authentication operation" includes a first input operation of inputting normal authentication information to a first input means (for example, the input device 24) capable of inputting authentication information, and a second input operation performed on a second input means originally provided in the vehicle 1, but is not limited thereto.

[0184] For example, the "normal authentication operation" may be only the first input operation. Even in such a case, when normal authentication information is not input, the vehicle 1 is not maintained in an unmonitored state but becomes a monitored state, so high security can be realized.

[0185] (2) Also, the following may be adopted as the "authentication information".

[0186] For example, face authentication may be adopted during the authentication operation, and face image information may be adopted as the "authentication information" input using the first input means. In this case, when determining whether a normal authentication operation has been received, the face image information captured and input by a camera (an example of the first input means) provided in the internal space area of the vehicle 1 is collated with the pre-registered normal face image information so that face authentication is executed.

[0187] Alternatively, fingerprint authentication may be adopted during the authentication operation, and fingerprint information may be adopted as the "authentication information" input using the first input means. In this case, when determining whether a normal authentication operation has been received, the fingerprint information detected and input by a fingerprint reader (an example of the first input means) provided in the internal space area of the vehicle 1 is collated with the pre-registered normal fingerprint information so that fingerprint authentication is executed.

[0188] Note that not limited to these authentication methods, various authentication methods (for example, vocal cord authentication, etc.) may be adopted, and further, a plurality of authentication methods may be combined. Also, it may be possible for a user or the like to preset which of the plurality of authentication methods to use for the authentication operation.

[0189] (3) Also, in the above-described embodiments and the like, user authentication has not been executed for the first trigger, but user authentication has been executed for the second trigger, but it is not limited to this. For example, user authentication may be executed for both the first trigger and the second trigger.

[0190] In this case, for example, it is particularly preferable that the authentication method for user authentication at the first trigger and the authentication method for user authentication at the second trigger are of different types. For example, the unlocking of the vehicle door 9 due to the successful user authentication using the digital key system may be used as the first trigger, and the successful user authentication using the input device 24 may be used as the second trigger.

[0191] (4) Also, in the above-described embodiments and the like, the remote terminal 3 is provided in the vehicle system 100, but the remote terminal 3 does not necessarily have to be provided in the vehicle system 100. However, as described above, when the remote terminal 3 is provided, the user can shift the vehicle 1 to the non-monitoring state without performing the authentication operation by transmitting a non-monitoring command from the remote terminal 3.

[0192] (5) Also, in the above-described embodiments, the authentication system 20 temporarily suppresses the activation of the alarm while keeping the entire vehicle 1 in the monitoring state when there is a first trigger, but it is not limited to this. For example, instead of this, the authentication system 20 may temporarily suppress the activation of the alarm by shifting the entire vehicle 1 from the monitoring state to the non-monitoring state when there is a first trigger. In this case, if a normal authentication operation is performed within a predetermined period from when the first trigger occurred, the authentication system 20 keeps the vehicle 1 in the non-monitoring state, and if not, returns the vehicle 1 from the non-monitoring state to the monitoring state. Also in this case, since the condition for maintaining the non-monitoring state is that a normal authentication operation has been received, the security is high. In addition, since the period during which the authentication operation can be received without an alarm is limited to a temporary period from when the first trigger occurred, this can also be a desirable basis for security. In this modification, the entire vehicle 1 becomes non-monitored until a normal authentication operation is performed, but since it is a temporary period, there are few security problems.

[0193] (6) Also, in the above embodiments and the like, the input device 24 is exemplified as the "first input means", but it is not limited thereto. For example, the "first input means" may be a mobile terminal such as a smartphone or a tablet computer. When the mobile terminal is described as a smartphone, authentication information (for example, terminal ID, user ID, password, one-time key, or telephone number, etc.) is exchanged between the communication unit 23 of the authentication system 20 and a predetermined application installed in the smartphone, and the control unit 21 may execute user authentication using the authentication information received from the application in the communication unit 23. In this way, a so-called "digital key system" using a smartphone may be used. In this way, the user can perform user authentication using his or her own smartphone or the like, rather than an operation member placed in the internal space area of the vehicle 1, that is, an operation member that can be used by anyone who enters the vehicle 1, so that higher security can be achieved.

[0194] In addition, it is preferable to adopt a mechanism that can perform the authentication operation only when the distance between the smartphone and the vehicle 1 (specifically, the communication unit 23) is relatively small. For example, as a wireless communication method between the smartphone and the communication unit 23 of the authentication system 20, a wireless communication method with a limited communication area such as Bluetooth (registered trademark), BLE (Bluetooth Low Energy), Wi-Fi communication, or short-range wireless communication (NFC (Near Field Communication), etc.) may be adopted. In this way, user authentication is executed only when the owner of the smartphone is in the relatively near vicinity of the vehicle 1, so that high security can be achieved.

[0195] However, it is not limited to this, and communication may be performed between the smartphone and the communication unit 23 via a public network such as LTE (Long Term Evolution) or Mobile Communication. In this case, even when the owner of the smartphone is relatively far from the vehicle 1, the smartphone and the communication unit 23 of the vehicle 1 can communicate with each other, and for example, the owner of the smartphone can be notified that there has been a first trigger. By doing so, for example, even when the user is relatively far from the vehicle 1, the user can use his or her own smartphone to confirm that there is a possibility of unauthorized acts such as theft of the vehicle 1. As a result, for example, such unauthorized acts can be avoided by the user who has received the notification immediately returning to the vehicle 1.

[0196] (7) Also, in the above-described embodiments and the like, the control unit 21 executes an authentication process based on the authentication information input using an input means such as the input device 24, but it is not limited to this. For example, the control unit 21 itself may not execute the authentication process, and the control unit 21 may cause a server or the like on the network to execute the authentication process. In this case, for example, the communication unit 23 of the authentication system 20 transmits the authentication information input by the user to an external server, receives the authentication result from the external server, and the control unit 21 may determine whether a normal authentication operation has been accepted based on the authentication result.

[0197] (8) Also, in the above-described embodiments, the authentication system 20 temporarily suppresses the activation of an alarm when there is a first trigger, and maintains the vehicle in an unmonitored state when there is a second trigger. Instead, the authentication system 20 may temporarily suppress the activation of an alarm when there is a second trigger, and maintain the vehicle in an unmonitored state when there is a first trigger. In this modification example, it can also be said that the events generated by the first trigger and the events generated by the second trigger are in a mode swapped with those in the above-described embodiments. Thus, as one aspect of the present invention, there is provided an alarm means having a function of activating an alarm when an abnormality is detected while the vehicle is in a monitored state, and a second trigger indicating that a normal authentication operation has been received while the vehicle is in a monitored state, which temporarily suppresses the activation of the alarm by the alarm means, and a control means for maintaining the vehicle in an unmonitored state when there is a first trigger. Such a system can also be provided. In such a system, in this way, since it is maintained in an unmonitored state on the condition that there is a second trigger indicating that a normal authentication operation has been received, the security is high. Also, since the activation of the alarm is suppressed by the second trigger, it is possible to suppress the accidental activation of the alarm when a legitimate user is trying to use the vehicle. Further, since the period during which the vehicle can be maintained in an unmonitored state without activating the alarm is limited to a temporary period from the second trigger, this can also be a desirable basis for security. According to the authentication system 20 of this modification example, it is possible to enhance the security while suppressing the accidental activation of the alarm. Such an invention has, in addition to the viewpoint of preventing unauthorized acts such as vehicle theft by a third party, the viewpoint of suppressing the accidental activation of an alarm caused by a legitimate user and suppressing the occurrence of an undesirable situation for the legitimate user.

[0198] (9) Further, the functions in the systems according to the above-described embodiments and modification examples may be implemented as a program executable by a computer.

[0199] By doing so, by installing the program on a computer and causing each function according to each form of the above-described embodiments and modified examples to be exhibited, high security can be realized.

[0200] The "computer" is not limited to a PC (personal computer), and may be, for example, an electronic device or the like executable under microcomputer control.

[0201] (10) Further, it is preferable to use a storage medium storing a program executable by a computer for the functions in the system according to the above-described embodiments and modified examples.

[0202] By doing so, by installing the program from the storage medium on a computer and causing the operational effects according to each form of the above-described embodiments and modified examples to be exhibited, high security can be realized.

[0203] [Other extension examples, etc.] The above-described embodiments and modified examples are illustrative, and it goes without saying that partial substitution or combination of the configurations shown in each embodiment and modified example is possible, and each component described in each embodiment and modified example may be arbitrarily combined. For example, the control unit 21 may execute any one process and another process among the embodiments and modified examples in parallel (for example, by multitasking or the like).

[0204] Also, the invention described in the means for solving the problem and each component may be further applied to the combination of the components in each embodiment and modified example. Regarding the same operational effects due to the same configurations in a plurality of embodiments and a plurality of modified examples, they will not be sequentially mentioned for each embodiment and modified example. Furthermore, the present invention is not limited to the above-described embodiments. For example, it will be obvious to those skilled in the art that various changes, improvements, combinations, etc. are possible.

Explanation of Reference Numerals

[0205] 1 Vehicle 2 Electronic Key 3 Remote terminal 6 First reception unit 7 Second reception unit 9 Vehicle door 10 Electronic key system 11 Electronic key ECU 12 Body ECU 20 Authentication system 21 Control unit 22 Detection unit 23 Communication unit 24 Input device 25 Alarm

Claims

1. Alarm means having a function of activating an alarm when an abnormality is detected while the vehicle is in a monitored state, When there is a first trigger while the vehicle is in a monitored state, temporarily suppressing the activation of the alarm by the alarm means, and when there is a second trigger indicating that a normal authentication operation has been accepted, Control means for maintaining the vehicle in a non-monitored state Comprising The control means Before a predetermined period elapses after the first trigger occurs, the first authentication operation is taken as the normal authentication operation, After the predetermined period has elapsed, prohibiting the first authentication operation from being the normal authentication operation, and using a second authentication operation with an increased number of user procedures required in the first authentication operation as the normal authentication operation, The alarm means activates an alarm when the predetermined period has elapsed A system characterized by the above.

2. When the normal authentication operation cannot be accepted, the control means does not maintain the vehicle in a non-monitored state and releases the temporary suppression of the activation of the alarm by the alarm means The system according to claim 1, characterized by the above.

3. The normal authentication operation is an input operation of inputting normal authentication information to an input means The system according to claim 1 or claim 2, characterized by the above.

4. The normal authentication operation includes a first input operation of inputting normal authentication information to a first input means and a second input operation performed on a second input means originally provided in the vehicle The system according to any one of claims 1 to 3, characterized by the above.

5. The second input means is a means for receiving an input related to the operation of the prime mover of the vehicle The system according to claim 4, characterized by the above.

6. The first trigger indicates that a predetermined operation has been accepted when the lock of the vehicle is released The system according to any one of claims 1 to 5, characterized by the above.

7. When the control means receives a predetermined signal having a data part different from that transmitted by the electronic key or a predetermined signal having a frequency different from the frequency used by the electronic key for wireless communication from a remote operation terminal different from the electronic key attached to the vehicle, the control means maintains the vehicle in a non-monitored state The system according to any one of claims 1 to 6, characterized by the above.

8. Detection means capable of detecting the first trigger, Further comprising When the control means acquires information from the detection means that the first trigger has occurred, it temporarily suppresses the activation of the alarm by the alarm means and has a determination function of determining whether to maintain the vehicle in an unmonitored state. The system according to any one of claims 1 to 7, characterized in that.

9. The alarm means has a function of activating an alarm when an abnormality is detected in a specific monitoring area of the vehicle when the vehicle is in a monitored state. The second trigger indicates that the normal authentication operation has been accepted in the specific monitoring area. The system according to any one of claims 1 to 8, characterized in that.

10. The specific monitoring area includes the internal space area of the vehicle. The system according to claim 9, characterized in that.

11. When the vehicle is in a monitored state, an abnormality is monitored in each of a plurality of monitoring areas of the vehicle. The control means. When the first trigger occurs when the vehicle is in a monitored state, the activation of the alarm regarding the specific monitoring area, which is a part of the plurality of monitoring areas, is temporarily suppressed. When the second trigger occurs, the monitoring state of the abnormality in all of the plurality of monitoring areas is released. The system according to claim 9 or claim 10, characterized in that.

12. The alarm means activates an alarm when an abnormality is detected in a predetermined area different from the specific monitoring area between the first trigger and the second trigger. The system according to claim 11, characterized in that.

13. A program characterized in that a computer is caused to realize a function as the system according to any one of claims 1 to 12.

Citation Information

Patent Citations

  • Theft preventing system, theft prevention device, theft prevention cooperating device, and multimedia device

    JP2004030480A

  • Theft alarm device for vehicle

    JP2007015598A

  • Anti-theft control device

    JP2010137751A

  • Abnormality detection and vehicle tracking device

    JP2010208380A

  • Communication device

    JP2013236151A