Rental car rental management device, rental car management system, and rental car rental management method
The rental car management system uses facial recognition to verify the identity of the key collector, addressing fraudulent activities by ensuring only the reservation holder can access the car, thus enhancing security.
Patent Information
- Application Number
- JP2021158696
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-09-29
- Publication Date
- 2025-08-06
- Estimated Expiration
- 2041-09-29
AI Technical Summary
Unmanned rental car operations lack identity verification, leading to potential fraudulent activities as the person collecting the key may not be the same as the one who made the reservation, increasing the risk of unauthorized use.
A rental car management system that includes a face image data acquisition unit, a condition determination unit, and a key access code issuance unit to ensure that the person collecting the key matches the reservation holder, using facial recognition to verify identity and issue a key access code only when the conditions are met.
Prevents fraudulent activities by ensuring that only the authorized person can access the rental car, thereby enhancing security and reducing unauthorized use.
Smart Images

Figure 0007719675000001 
Figure 0007719675000002 
Figure 0007719675000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a rental car rental management device, a rental car management system, and a rental car rental management method. [Background technology]
[0002] In rental car business, the clerk at the rental office counter generally verifies the customer's identity by showing a driver's license or other proof, and then hands over the keys directly to the customer.
[0003] A method for performing unmanned rental car rental operations without requiring identity verification by a store clerk is also being considered (see, for example, Patent Document 1 below). [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Publication No. 8-16900 Summary of the Invention [Problem to be solved by the invention]
[0005] However, if the rental business is conducted unmanned, fraudulent activities such as a third party receiving the key may occur. This is because if the business office is simply unmanned, it is not possible to confirm whether the person who comes to collect the key is the same person who made the reservation (the person corresponding to the driver's license, etc.). Or, it is not possible to confirm whether the person who performed the identity verification actually came to collect the key. Furthermore, the omission of the identity verification process due to unmanned operations is thought to lead to an increase in fraudulent activities.
[0006] An object of the present invention is to provide a rental car rental management device, a rental car management system, and a rental car rental management method that contribute to the prevention of fraudulent activities related to rental car use. [Means for solving the problem]
[0007] The rental car rental management device of the present invention is a rental car rental management device that manages the use of rental cars by users, and is equipped with a face image data acquisition unit that acquires image data of the user's face on the user's identification card, a condition determination unit that, after making a reservation for the rental car including specifying the rental car usage reservation period, determines whether a specified key access code issuance condition is met based on the image data of the user's face and image data of the target person's face from a terminal device of the target person that matches or differs from the user, and a key access code issuance unit that issues a key access code to be sent to the terminal device of the target person when the key access code issuance condition is met, and the key access code issuance condition includes a condition that the target person's face matches the user's face, and when the key access code is input into a key storage device that has a storage unit for storing the rental car key within a key access permission period based on the rental car usage reservation period, the rental car key is made available to the target person. [Effects of the Invention]
[0008] According to the present invention, it is possible to provide a rental car rental management device, a rental car management system, and a rental car rental management method that contribute to the prevention of fraudulent activities related to rental car use. [Brief explanation of the drawings]
[0009] [Figure 1] 1 is an overall configuration diagram of a rental car management system according to an embodiment of the present invention; [Figure 2] FIG. 2 is a front view of the key storage device according to the embodiment of the present invention. [Figure 3] FIG. 2 is a block diagram of a terminal device according to an embodiment of the present invention. [Figure 4] 1 is an overall flowchart relating to the use of a rental car according to an embodiment of the present invention. [Figure 5] 5 is a flowchart of the user registration process shown in FIG. 4. [Figure 6] FIG. 5 is a sequence diagram of the user registration process shown in FIG. [Figure 7] FIG. 10 is a diagram showing a structure of user registration information according to an embodiment of the present invention. [Figure 8] 5 is a flowchart of the reservation process shown in FIG. 4. [Figure 9] FIG. 5 is a sequence diagram of the reservation process shown in FIG. [Figure 10] FIG. 3 is a diagram showing a structure of business operator-side reservation information in the embodiment of the present invention. [Figure 11] FIG. 10 is a diagram showing a structure of management-side reservation information according to an embodiment of the present invention. [Figure 12] 5 is a flowchart of the authentication process shown in FIG. 4. [Figure 13] FIG. 5 is a sequence diagram of the authentication process shown in FIG. [Figure 14] 5 is a flowchart of the key access code issuing process shown in FIG. 4. [Figure 15] FIG. 5 is a sequence diagram of the key access code issuing process shown in FIG. 4. [Figure 16] FIG. 10 is a diagram illustrating the assignment of codes to several pieces of information according to an embodiment of the present invention. [Figure 17] 5 is a flowchart of the key acquisition process shown in FIG. 4. [Figure 18] FIG. 3 is a functional block diagram of a second control device according to a first example of an embodiment of the present invention. [Figure 19] FIG. 10 is a diagram showing the relationship between a rental car reservation period and a key acquisition permission period in a first example pertaining to an embodiment of the present invention. [Figure 20] FIG. 10 is a diagram showing a modified structure of a key storage device according to a second embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, examples of embodiments of the present invention will be described in detail with reference to the drawings. In each of the drawings, identical parts are designated by the same reference numerals, and duplicate descriptions of identical parts will be omitted as a general rule. For the sake of simplicity, this specification may use symbols or signs referring to information, signals, physical quantities, components, etc., and omit or abbreviate the names of the information, signals, physical quantities, components, etc. corresponding to the symbols or signs. For example, the second control device referred to by "21" below (see FIG. 1) may be written as the second control device 21 or abbreviated to the control device 21, but they all refer to the same thing.
[0011] Figure 1 shows the overall configuration of a rental car management system SYS according to an embodiment of the present invention. The rental car management system SYS comprises an operator system 10, a rental management system 20, and a key rental system 30. The rental car management system SYS manages the rental of rental cars to users. A rental car is a vehicle (automobile) for rental. A user refers to a person who uses a rental car.
[0012] In FIG. 1, the symbol "40" represents a terminal device. The terminal device 40 is an electronic device such as a smartphone, tablet, information terminal device, or personal computer. The terminal device 40 is any terminal device that can be operated by a user and may be owned by the user. The terminal device 40 may be understood to be included as a component of the rental car management system SYS. When the terminal device 40 is included as a component of the rental car management system SYS, the terminal device 40 may be a terminal device rented by a rental car company, or may be a terminal device rented by a travel agency or other entity other than the rental car company.
[0013] The business operator system 10 is a system operated and managed by a rental car company that rents out rental cars. The rental management system 20 is a system that manages rental car rentals. The management of rental car rentals is realized by managing the rental of rental car keys. The key management system 30 is a system that holds rental car keys and actually rents out rental car keys.
[0014] A user makes a reservation for a rental car with the business operator system 10 using a terminal device 40. Based on the information related to the reservation, the systems 10, 20, and 30 cooperate to lend the rental car key to the user in a manner that prevents unauthorized use of the rental car. The rental car key is provided to the user by the key lending system 30 (key storage device 33, described below).
[0015] The operator system 10 includes a first control device 11 and a first database 12. The first control device 11 includes, as hardware resources, an arithmetic processing unit 11a including a CPU (Central Processing Unit) and the like, a memory 11b including a ROM (Read Only Memory) and a RAM (Random Access Memory) and the like, and a communication processing unit 11c. The first control device 11 may perform the operations and processes described below by executing a program stored in the memory 11b in the arithmetic processing unit 11a. The first control device 11 may be configured using one or more computer devices. The first control device 11 may also be configured using cloud computing. The first database 12 is a first recording device equipped with a nonvolatile recording medium such as a magnetic disk or semiconductor memory. The first control device 11 can record any data in the first database 12 and can arbitrarily read the recorded data in the first database 12.
[0016] The lending management system 20 includes a second control device 21 and a second database 22. The second control device 21 includes, as hardware resources, an arithmetic processing unit 21a including a CPU, a memory 21b including ROM, RAM, and the like, and a communication processing unit 21c. The second control device 21 may perform the operations and processes described below by executing a program stored in the memory 21b in the arithmetic processing unit 21a. The second control device 21 is configured with one or more computer devices. The second control device 21 may also be configured using cloud computing. The second database 22 is a second recording device equipped with a non-volatile recording medium such as a magnetic disk or semiconductor memory. The second control device 21 can record any data in the second database 22 and can arbitrarily read the recorded data in the second database 22.
[0017] The key lending system 30 includes a third control device 31 and a third database 32. The third control device 31 includes, as hardware resources, an arithmetic processing unit 31a including a CPU, a memory 31b including ROM and RAM, and a communication processing unit 31c. The third control device 31 may perform the operations and processes described below by executing a program stored in the memory 31b in the arithmetic processing unit 31a. The third control device 31 may be configured using cloud computing. The third database 32 is a third recording device equipped with a non-volatile recording medium such as a magnetic disk or semiconductor memory. The third control device 31 can record any data in the third database 32 and can arbitrarily read data recorded in the third database 32. The key lending system 30 further includes a key storage device 33. The key storage device 33 may be a device that operates under the control of the third control device 31. The key storage device 33 will be described later.
[0018] Systems 10, 20, and 30 are connected to a communication network NET. Specifically, control devices 11, 21, and 31 are connected to the communication network NET. The communication network NET includes the Internet, a mobile communication network, and the like. A terminal device 40 is also connected to the communication network NET. The connection of the control devices 11, 21, 31, and 40 to the communication network NET may be a wired connection or a wireless connection, or a combination of a wired connection and a wireless connection.
[0019] The first control device 11 is capable of two-way communication with any device connected to the communication network NET using the communication processing unit 11c. The second control device 21 is capable of two-way communication with any device connected to the communication network NET using the communication processing unit 21c. The third control device 31 is capable of two-way communication with any device connected to the communication network NET using the communication processing unit 31c. The terminal device 40 also has a communication processing unit (corresponding to the communication processing unit 45 in Figure 3) and is capable of two-way communication with any device connected to the communication network NET using the communication processing unit. In the operation of the rental car management system SYS, the control device 11 mainly performs two-way communication with the control device 21 and the terminal device 40. The control device 21 mainly performs two-way communication with the control devices 11 and 31. The control device 31 mainly performs two-way communication with the control device 21.
[0020] 2(a) and (b) show schematic front views of the key storage device 33. The key storage device 33 has a form similar to a coin locker and includes multiple sets of storage compartments 331 and doors 332 corresponding to the storage compartments 331. Staff operating the key lending system 30 can store rental car keys in one or more storage compartments 331.
[0021] Each door 332 is in either a closed state or an open state. Figure 2(a) shows a schematic front view of the key storage device 33 when all doors 332 are in a closed state. Figure 2(b) shows a schematic front view of the key storage device 33 when only two doors 332 are in an open state. Only when the door 332 corresponding to a certain storage section 331 is in an open state can a user obtain an object (here, a rental car key) stored in that storage section 331. Note that the total number of pairs of storage sections 331 and doors 332 provided in the key storage device 33 may be one.
[0022] The key storage device 33 is provided with an operation unit 333 that accepts operations from an operator of the key storage device 33, and a display unit 334 that is visible to the operator of the key storage device 33. A user who wishes to rent a car can be the operator of the key storage device 33. The key storage device 33 may be formed with a touch panel that has the functions of the operation unit 333 and the display unit 334. When the operator of the key storage device 33 inputs the necessary information (a key acquisition code, described below) into the operation unit 333, the door 332 associated with the input information switches from a closed state to an open state, and the operator can obtain the object (here, the rental car key) in the storage unit 331 that corresponds to the door 332.
[0023] Hereinafter, a rental vehicle may be specifically referred to as a vehicle CR. The vehicle CR has a power source (engine, motor, etc.), which generates driving force for running the vehicle CR. The power source generates driving force based on a predetermined fuel (e.g., fossil fuel, hydrogen) or electrical energy. The key to the rental vehicle to be rented, i.e., the key to the vehicle CR, is a key for opening the door of the vehicle CR and is also a key that is essential for operating the power source of the vehicle CR. Therefore, the user can only run the vehicle CR after obtaining the key to the vehicle CR.
[0024] 3 shows an internal block diagram of the terminal device 40. The terminal device 40 includes a terminal control unit 41, a camera 42, a display unit 43, an operation unit 44, a communication processing unit 45, and a recording medium 46. However, the terminal device 40 may also include various other blocks.
[0025] The terminal control unit 41 comprises an arithmetic processing unit including a CPU and a memory including a ROM and a RAM. The terminal control unit 41 may perform each of the operations and processes described below by executing a program in the memory in the arithmetic processing unit. The camera 42 captures an image of a subject within a predetermined shooting area and generates image data of the captured image. The display unit 43 comprises an LCD display panel or the like, and displays any image under the control of the terminal control unit 41. The operation unit 44 accepts any operation from the operator of the terminal device 40. The terminal device 40 may be formed with a touch panel that has the functions of the display unit 43 and the operation unit 44. The communication processing unit 45 realizes two-way communication with other devices. The recording medium 46 is a non-volatile recording medium.
[0026] The flow of operations until a user uses a rental car in the rental car management system SYS will be described with reference to Fig. 4. Fig. 4 is a flowchart showing this flow.
[0027] First, in step S1, a user registration process is executed. Next, in step S2, a reservation process is executed. In the reservation process, a rental car is reserved. Next, in step S3, an authentication process is executed. Next, in step S4, a key acquisition code issuance process is executed. Finally, in step S5, a key acquisition process is executed.
[0028] A flowchart of the user registration process is shown in Fig. 5. The processes of steps S11 to S14 shown in Fig. 5 are executed in the user registration process of step S1 in Fig. 4. Fig. 6 is a sequence diagram of the user registration process.
[0029] In the user registration process, first, in step S11, a user registration request is made from the terminal device 40 to the first control device 11. The user registration request is realized by transmitting a user registration request signal 1110 (see FIG. 6) from the terminal device 40 to the first control device 11. In step S12 following step S11, the first control device 11 executes user registration processing based on the signal 1110. In the user registration processing, user registration information based on the signal 1110 is stored in the first database 12. When the user operates the terminal device 40, the signal 1110 is transmitted from the terminal device 40 to the first control device 11, and information that is the source of the user registration information is input to the terminal device 40 during this operation.
[0030] FIG. 7 shows the structure of user registration information stored in the first database 12. User registration information is created for each user who uses the system SYS and stored in the first database 12. Of the multiple users who use the system SYS, the i-th user is referred to as the i-th user (i is an integer). In FIG. 7, the symbol "AA[i]" represents the user registration information created for the i-th user. Each user is assigned a user ID, which is unique identification information. The user ID may be specified by each user in signal 1110, or the first control device 11 may set the user ID. A login password for logging in to various websites operated by the system 10 is set for each user. The login password may be specified by each user in signal 1110, or the first control device 11 may set the login password.
[0031] In the following description of the process, any one user who is of interest will be referred to as the "interested user." The user registration information of the interest user includes the interest user's user ID and login password, as well as a facial image and attribute information of the interest user. The facial image of the interest user is an image of the interest user's facial photograph shown on the interest user's identification card. In this embodiment, it is assumed that the system SYS is operated in Japan. Examples of identification cards include a Japanese driver's license or My Number card, or a passport issued in any country. Documents equivalent to a driver's license issued in a country other than Japan may also be considered identification cards. In addition, the interest user's identification card is any document that can prove the interest user's identity.
[0032] In signal 1110, data of the noted user's identification card, including the facial image of the noted user, is transmitted (uploaded) to the first control device 11, whereby image data of the noted user's facial image is acquired by the first control device 11. The noted user can transmit data obtained by capturing an image of their own identification card using a camera 42 or the like to the first control device 11. If the noted user already has their identification card as data without capturing an image, the data may be transmitted to the first control device 11.
[0033] The attribute information of the noted user indicates the name, address, date of birth, gender, etc. of the noted user. The attribute information of the noted user may be included as text data in the signal 1110. Alternatively, the attribute information of the noted user may be generated by identifying and extracting text information written on the noted user's identification card using optical character recognition.
[0034] When optical character recognition is used, attribute information may be acquired by the first control device 11 in the following manner. First, image data of the target user's identification card is sent from the first control device 11 to the second control device 21. The second control device 21 sends the image data of the target user's identification card to an OCR device (not shown). The OCR device performs optical character recognition on the target user's identification card based on the received image data and obtains the optical character recognition results. The optical character recognition results include text information of the target user's attribute information shown on the target user's identification card. The OCR device transmits the optical character recognition results to the second control device 21. The second control device 21 transmits the optical character recognition results received from the OCR device to the first control device 11. This allows the first control device 11 to acquire the target user's attribute information.
[0035] The OCR device is a device that can be used by the second control device 21 through cloud computing, and the OCR device is actually formed by one or more computer devices connected to the communication network NET. The OCR device may be used through a predetermined API (Application Programming Interface). If the control device 11 or 21 has an optical character recognition function, the control device 11 or 21 may perform optical character recognition to obtain text information on the attribute information of the target user. Furthermore, extraction of text information through optical character recognition may be performed during the reservation process of step S2 (see FIG. 4).
[0036] After performing the user registration process in step S12, the first control device 11 transmits a user registration link signal 1120 (see FIG. 6) to the second control device 21. In response to receiving the user registration link signal 1120, the second control device 21 performs the process in step S13. In step S13, the second control device 21 stores part of the user registration information in the second database 22. The information to be stored in the second database 22 is included in the signal 1120. The second control device 21 realizes the storage in step S13 by transmitting a registration request signal 1130 (see FIG. 6) based on the signal 1120 to the second database 22. When the storage in step S13 is completed, a predetermined response signal 1132 is returned from the second database 22 to the second control device 21.
[0037] In step S13, the information stored in the second database 22 includes the user ID. Therefore, when the processes of steps S11 to S13 are executed for the noted user, the user ID of the noted user is stored in the second database 22. Thereafter, various information corresponding to the noted user is stored in the second database 22 in association with the user ID of the noted user. Note that in step S13, in addition to the user ID, other information (for example, a facial image, attribute information, etc.) of the user registration information may also be stored in the second database 22.
[0038] In step S14 following step S13, the second control device 21 executes a facial image registration process. In the user registration process for the noted user, image data of the facial image in the user registration information of the noted user (hence, image data of the facial image of the noted user on the identification card) is included in the user registration link signal 1120. In the facial image registration process, the second control device 21 transmits a facial registration request signal 1140 to the image recognition processing device 60. The facial registration request signal 1140 is a signal requesting registration of the facial image of the noted user, and includes image data of the facial image of the noted user and the user ID of the noted user. The image data of the facial image of the noted user in the signal 1140 is the image data of the facial image of the noted user on the identification card of the noted user. The image recognition processing device 60 extracts feature data representing the features of the facial image of the noted user based on the image data of the facial image of the noted user in the signal 1140, and stores the extracted feature data in its own face registration database (not shown) in association with the user ID of the noted user. When this storage is completed, a predetermined response signal 1142 is sent back from the image recognition processing device 60 to the second control device 21.
[0039] The image recognition processing device 60 is a device that can be used by the second control device 21 through cloud computing, and the image recognition processing device 60 is actually formed by one or more computer devices connected to the communication network NET. The image recognition processing device 60 may be used through a predetermined API. Note that the second control device 21 may also be provided with a function for generating feature data, in which case the image recognition processing device 60 is not required.
[0040] The user registration process is completed through the facial image registration process of step S14. In detail, as shown in Fig. 6, when the second control device 21 receives the response signal 1142, it transmits a predetermined cooperation completion signal 1122 to the first control device 11. When the first control device 11 receives the cooperation completion signal 1122, it transmits a predetermined user registration completion signal 1112 to the terminal device 40. The transmission of signal 1112 completes the user registration process.
[0041] It is assumed here that the facial image registration process is executed in the user registration process of step S1, but the facial image registration process may also be executed in the reservation process of step S2.
[0042] Fig. 8 shows a flowchart of the reservation process. As described above, a rental car is reserved in the reservation process. The processes of steps S21 to S25 shown in Fig. 8 are executed in the reservation process of step S2 in Fig. 4. Fig. 9 is a sequence diagram of the reservation process.
[0043] In the reservation process, first, in step S21, a reservation request is made from the terminal device 40 to the first control device 11. This reservation request can also be said to be a reservation request made by a user using the terminal device 40. Note that in order for the target user to make the reservation request in step S21, the target user must access a website operated by the system 10 with the terminal device 40 and then input the target user's user ID and login password into the terminal device 40. After this input, login to the website is completed and the reservation request can be made. The reservation request is realized by transmitting a reservation request signal 1210 (see FIG. 9) from the terminal device 40 to the first control device 11.
[0044] In step S21, the user specifies the desired usage information by inputting it into the terminal device 40. The desired usage information includes the rental car reservation period, the rental car rental location, and the type of car desired to be rented. The rental car reservation period is the period during which the user wishes to rent and use the rental car, and is the period from the reservation start date and time to the reservation end date and time. The rental car rental location is the location where the rental car to be rented will be located, and the user who will rent the rental car will depart from the rental car rental location. For example, the rental car company's office (the location of the office) is specified as the rental car rental location. By including the desired usage information in the reservation request signal 1210, the specified contents of the desired usage information are transmitted to the first control device 11.
[0045] In step S22 following step S21, the first control device 11 executes a first reservation registration process based on the reservation request signal 1210. In the first reservation registration process, rental car company reservation information (hereinafter simply referred to as company reservation information) is created and stored in the first database 12. The company reservation information is created based on the reservation request signal 1210 (and therefore based on the user's desired usage information).
[0046] Figure 10 shows the structure of the business operator's reservation information stored in the first database 12. Every time the reservation process of step S2 is executed, business operator's reservation information is created and stored in the first database 12. In Figure 10, the symbol "BB[j]" represents the business operator's reservation information created in the j-th reservation process (j is an integer).
[0047] Each business reservation information includes a rental car reservation ID, a user ID, a usage reservation period, a rental location, and a rental vehicle ID. The rental car reservation ID is unique identification information (unique identification information related to the reservation) set for each business reservation information. The user ID in the business reservation information is the user ID entered into the terminal device 40 related to the reservation request. Therefore, for example, if the user ID of the i-th user is entered into the terminal device 40 in the j-th reservation step and then a reservation request is made, the user ID in the business reservation information BB[j] will be the user ID of the i-th user. The usage reservation period and rental location in the business reservation information match the usage reservation period and rental location specified in the desired usage information.
[0048] The first control device 11 determines the vehicle CR to be rented to the user based on the desired use information, and specifies identification information unique to the determined vehicle CR. The specified identification information is included in the business operator's reservation information as a rental vehicle ID. The rental vehicle ID may be license plate information of the vehicle CR to be rented to the user.
[0049] After performing the first reservation registration process in step S22, the first control device 11 transmits a reservation linking signal 1220 (see FIG. 9) to the second control device 21. The first control device 11 may include all or part of the business operator's reservation information in the reservation linking signal 1220.
[0050] In response to receiving the reservation link signal 1220, the second control device 21 acquires the key ID by performing a key ID acquisition process in step S23. In the key ID acquisition process, the second control device 21 transmits a key ID request signal 1230 to the third control device 31. The key ID request signal 1230 includes the rental vehicle ID identified by the first control device 11, and the signal 1230 requests the transmission of the key ID associated with the rental vehicle ID. The key ID is unique information about the rental car key associated with the rental vehicle ID. Upon receiving the signal 1230, the third control device 31 identifies the key ID for the rental car key corresponding to the rental vehicle ID included in the signal 1230, and replies to the second control device 21 with a response signal 1232 including the identified key ID. The key ID acquisition process in step S23 is completed by transmitting and receiving the signals 1230 and 1232.
[0051] Thereafter, in step S24, the second control device 21 acquires a key lending reservation ID by performing a key lending reservation ID acquisition process. In the key lending reservation ID acquisition process, the second control device 21 transmits a key lending reservation ID request signal 1240 to the third control device 31. The key lending reservation ID request signal 1240 requests the transmission of a key lending reservation ID. The signal 1240 includes the key ID acquired in step S23, the user ID of the user who made the reservation request in step S21, and information indicating the usage reservation period specified in step S21. Based on the signal 1240, the third control device 31 sets a key lending reservation corresponding to the key ID in the signal 1240 (i.e., the key ID in the signal 1232), and sets a key lending reservation ID, which is unique information for identifying the set lending reservation.
[0052] The third control device 31 then returns a response signal 1242 including the key lending reservation ID to the second control device 21. The third control device 31 saves the details of the key lending reservation in the third database 32 before or in parallel with returning the response signal 1242. Specifically, the third control device 31 saves the details of the key lending reservation to the user for the usage reservation period in association with the key lending reservation ID in the third database 32. In practice, a set of data associating the key lending reservation ID set in step S24 with the key ID, usage reservation period, and user ID included in signal 1240 may be saved in the third database 32 as a lending reservation. The key lending reservation ID acquisition process of step S24 is completed by sending and receiving signals 1240 and 1242.
[0053] Thereafter, in step 25, the second control device 21 performs a second reservation registration process. In the second reservation registration process, management-side reservation information for the rental car (hereinafter simply referred to as management-side reservation information) is created and stored in the second database 22. The management-side reservation information is created based on the reservation link signal 1220 and the response signals 1232 and 1242.
[0054] Fig. 11 shows the structure of the management-side reservation information stored in the second database 22. Each time the reservation process of step S2 is executed, management-side reservation information is created and stored in the second database 22. In Fig. 12, the symbol "CC[j]" represents the management-side reservation information created in the j-th reservation process (j is an integer).
[0055] Each management-side reservation information includes a rental car reservation ID, a user ID, a usage reservation period, a rental location, a rental vehicle ID, a key ID, and a key rental reservation ID. The rental car reservation ID, user ID, usage reservation period, rental location, and rental vehicle ID in the management-side reservation information are the same as the rental car reservation ID, user ID, usage reservation period, rental location, and rental vehicle ID in the business-side reservation information (see FIG. 10), and are set based on the reservation link signal 1220. The key ID and key rental reservation ID in the management-side reservation information are the same as those included in the response signals 1232 and 1242.
[0056] For example, consider the case where the i-th user makes a rental car reservation in the j-th reservation step. In this case, the rental car reservation ID corresponding to the j-th reservation step, the i-th user's user ID, the reservation period, rental location, and rental vehicle ID specified in step S21 of the j-th reservation step, and the key ID and key rental reservation ID obtained in steps S23 and S24 of the j-th reservation step are included in the management-side reservation information CC[j] in a mutually associated state. However, all or part of the information indicating the rental location, rental vehicle ID, and reservation period may not be included in the management-side reservation information.
[0057] The second control device 21 transmits a reservation registration request signal 1250 including the management-side reservation information to the second database 22, and the management-side reservation information is stored in the second database 22 based on the signal 1250. This realizes the second reservation registration process of step S25. When the management-side reservation information is stored in the second database 22, a predetermined response signal 1252 is sent back to the second control device 21.
[0058] The reservation process is completed through the second reservation registration process in step S25. In detail, as shown in Fig. 9, when the second control device 21 receives the response signal 1252, it transmits a predetermined cooperation completion signal 1222 to the first control device 11. When the first control device 11 receives the cooperation completion signal 1222, it transmits a predetermined reservation completion signal 1212 to the terminal device 40. The transmission of signal 1212 completes the reservation process.
[0059] A flowchart of the authentication process is shown in Fig. 12. The processes of steps S31 to S35 shown in Fig. 12 are executed in the authentication process of step S3 in Fig. 4. Fig. 13 is a sequence diagram of the authentication process.
[0060] The terminal device 40 used by the target person PS in the authentication process and the key acquisition code issuing process described below is specifically referred to as terminal device 40a (see FIG. 13). The target person PS is typically one of the users of the system SYS and is a specific user who made a reservation for a rental car in the reservation process. However, the target person PS may be a person who is different from the specific user and attempts to fraudulently use the rental car. Ignoring the existence of fraudulent use, the target person PS in the following explanation can be understood to be the same as the specific user.
[0061] The terminal device 40 and the terminal device 40a used in the user registration process and reservation process of steps S1 and S2 may be the same or different. It is assumed that the user registration process and reservation process of steps S1 and S2 for a specific user have already been completed. For the sake of concrete explanation, unless otherwise specified, it is assumed below that the user registration information AA[i] and the business-side reservation information BB[i] associated with the specific user have already been stored in the first database 12, and that the management-side reservation information CC[i] associated with the specific user has already been stored in the second database 22.
[0062] Before the authentication process can begin, the target person PS goes to an access location. The access location is a location where the target person PS (in other words, the terminal device 40a) can obtain a predetermined site access code. The access location may be, for example, the rental car rental location itself or the vicinity of the rental car rental location. If there are multiple rental car rental locations, it is advisable to set an access location for each rental location. At the access location, for example, an object (such as a bulletin board) with the site access code printed on it is installed.
[0063] The site access code is access information that allows the terminal device 40a to access a specific rental website operated by the system 10. Here, a QR code (registered trademark) is used as the site access code. However, the site access code may be any two-dimensional or one-dimensional code that is not classified as a QR code. Alternatively, the site access code may be any pattern code that is not classified as a one-dimensional or two-dimensional code.
[0064] In the authentication process, first, in step S31, the target person PS operates the terminal device 40a to cause the terminal device 40a to read a predetermined site access code (access information). The site access code is read into the terminal device 40a by capturing a photograph of the site access code with the camera 42 of the terminal device 40a. The URL (Uniform Resource Locator) of the rental website is embedded in the site access code. The terminal device 40a is assumed to have pre-installed an application program that operates to access the website with the URL extracted from the read site access code. Therefore, when the site access code is read into the terminal device 40a, the terminal control unit 41 accesses the rental website based on the site access code.
[0065] When the lending website is accessed, a message requesting login is displayed on the display unit 43 of the terminal device 40a based on the functions of the lending website. In response to this request, the target person PS performs the login operation in step S32. In the login operation, the user ID and login password are entered into the operation unit 44 of the terminal device 40a. Here, it is assumed that in the login operation, the user ID and login password of a specific user are entered into the operation unit 44 of the terminal device 40a. When this input content is transmitted from the terminal device 40a to the first control device 11, the first control device 11 determines that the specific user has logged in to the lending website.
[0066] Thereafter, a message requesting uploading of a facial image is displayed on the display unit 43 of the terminal device 40a on the rental website. In response to this request, the target person PS performs a selfie operation in step S33. In the selfie operation, the face of the target person PS is photographed by the camera 42 of the terminal device 40a. For convenience, the facial image of the target person PS obtained by photographing the face of the target person PS (i.e., the photographed image of the face of the target person PS) is referred to as a facial image PSf. Once the facial image PSf is obtained by the terminal device 40a, the facial image PSf is uploaded to the first control device 11 (step S33). More specifically, as shown in FIG. 13 , an authentication request signal 1310 including image data of the facial image PSf is transmitted from the terminal device 40a to the first control device 11. The authentication request signal 1310 is a signal requesting authentication that the target person PS is a specific user (the same applies to a signal 1320 described later). When the first control device 11 receives the authentication request signal 1310, it transmits to the second control device 21 an authentication request signal 1320 including image data of the face image PSf and the user ID of the specific user.
[0067] When the second control device 21 receives the authentication request signal 1320, it executes a facial authentication process in step S34. The facial authentication process is a type of personal authentication process. The facial authentication process is a process for determining whether the face of the target person PS matches the face of a specific user, and based on this determination, it is authenticated whether the target person PS is the specific user. The facial authentication process in step S34 includes sending and receiving signals 1330, 1332, 1340, and 1342 shown in FIG. 13. The facial authentication process is executed by the second control device 21 while utilizing the functions of the image recognition processing device 60.
[0068] In the face recognition process, the second control device 21 first transmits an image recognition request signal 1330 including image data of the face image PSf to the image recognition processing device 60. The signal 1330 is a signal requesting that the identity of the person corresponding to the face image PSf be notified. Upon receiving the signal 1330, the image recognition processing device 60 extracts feature data representing the features of the face image PSf and compares the feature data of the face image PSf with the feature data of each user stored in its own face registration database (not shown). It is assumed that the face registration database has already stored the feature data of the face images of the first to nth users after user registration steps have been executed for the first to nth users. n is an integer of 2 or greater.
[0069] Based on the result of the comparison, the image recognition processing device 60 derives the degree of match between the person corresponding to the facial image PSf (i.e., the target person PS) and each of the first to nth users, and transmits a result signal 1332 indicating which of the first to nth users corresponds to a degree of match equal to or greater than a predetermined value to the second control device 21. The result signal 1332 also includes the derived degree of match. The degree of match between the person corresponding to the facial image PSf (i.e., the target person PS) and the ith user is referred to as the ith degree of match. The ith degree of match represents the degree of match (in other words, the degree of similarity) between the facial image PSf and the facial image of the ith user.
[0070] The second control device 21 involved in the facial recognition processing determines whether the face of the target person PS matches the face of the specific user based on the result signal 1332, and thereby determines whether the target person PS is the specific user. The result of these determinations is called the facial recognition result. If the specific user is included among the users corresponding to a degree of match equal to or greater than a predetermined value, it is determined that the target person PS matches the specific user (i.e., the face of the target person PS matches the face of the specific user). If the specific user is not included among the users corresponding to a degree of match equal to or greater than a predetermined value, or if there is no user corresponding to a degree of match equal to or greater than the predetermined value, it is determined that the target person PS does not match the specific user (i.e., the face of the target person PS does not match the face of the specific user).
[0071] After obtaining the face authentication result, the second control device 21 transmits a result storage request signal 1340 requesting storage of the face authentication result to the second database 22. When the face authentication result is stored in the second database 22 based on the signal 1340, a predetermined response signal 1342 is returned to the second control device 21.
[0072] Thereafter, the authentication process is completed after notification of the face authentication result in step S35. In the face authentication result notification, as shown in Fig. 13, the second control device 21 transmits a result notification signal 1322 including the face authentication result to the first control device 11. Upon receiving the result notification signal 1322, the first control device 11 transmits a result notification signal 1312 including the face authentication result to the terminal device 40a. The authentication process is completed upon transmission of the signal 1312.
[0073] A flowchart of the key acquisition code issuing process is shown in Fig. 14. The key acquisition code issuing process of step S4 in Fig. 4 includes the processes of steps S41 to S47 shown in Fig. 14. Fig. 15 is a sequence diagram of the key acquisition code issuing process. Note that the key acquisition code issuing process may be executed only when the target person PS is authenticated as a specific user in the authentication process.
[0074] 16(a), for the sake of concreteness, the following reference numerals will be assigned to various pieces of information corresponding to a specific user. That is, the user ID of the specific user will be referred to as "810." The rental car reservation ID associated with a rental car reservation made by the specific user (in other words, associated with the specific user) will be referred to as "812." The rental car reservation period, rental location, rental vehicle ID, key ID, and key rental reservation ID in the rental car reservation ID 812 will be referred to as "814," "816," "818," "820," and "822," respectively. If the rental car reservation ID 812 matches the rental car reservation ID in the management reservation information CC[i], then the use reservation period 814, rental location 816, rental vehicle ID 818, key ID 820, and key rental reservation ID 822 match the use reservation period, rental location, rental vehicle ID, key ID, and key rental reservation ID in the management reservation information CC[i]. Furthermore, when a rental car reservation is made in the reservation process for a specific user, the key rental reservation ID 822, key ID 820, usage reservation period 814, and user ID 810 are stored in the third database 32 in a mutually associated state (see FIG. 9). The vehicle (rental car) CR corresponding to the rental vehicle ID 818 is referred to as "CRa." The key corresponding to the key ID 820 is referred to as "Ka." Key Ka is the key for vehicle CRa. The key acquisition code CDa shown in FIG. 16(a) will be described later. 16(b), the reservation start date and time and the reservation end date and time in the reservation period 814 are referred to by the symbols "814S" and "814E," respectively. Furthermore, hereinafter, unless otherwise specified, it is assumed that the target person PS is the same as the specific user.
[0075] 14, in the key access code issuing process, first, in step S41, a key access code request signal 1410 is sent from the terminal device 40a to the first control device 11, thereby requesting a key access code. A rental car key reserved for rental to a specific user, i.e., key Ka, is stored and kept in one of the storage sections 331 of the key storage device 33. The key access code requested in step S41 is a code (e.g., a so-called personal identification number) required to open the door 332 of the storage section 331 in which key Ka is stored, and hereinafter, this key access code will be referred to as "CDa" (see FIG. 16(a)).
[0076] The work of storing and keeping the key Ka in the storage unit 331 is completed by the staff operating the system 30 at least a predetermined time before the reservation start date and time 814S. At any time between the time the key lending reservation is set and saved (see FIG. 9) and the time the storage work is completed, the third control device 31 sets a key access code CDa and registers it in the key storage device 33. The third control device 31 also stores the key access code CDa in the third database 32 in association with the key ID 820 and the key lending reservation ID 822.
[0077] Specifically, for example, after the authentication process, with login to the rental website established using the terminal device 40a, the target person PS, who has been identified as the specific user, inputs a predetermined code issuance request operation into the terminal device 40a. As a result, a key acquisition code request signal 1410 is transmitted from the terminal device 40a to the first control device 11. The signal 1410 requests transmission of a key acquisition code (the same applies to signal 1420, described below). Upon receiving the key acquisition code request signal 1410, the first control device 11 transmits a key acquisition code request signal 1420, including the user ID 810 of the specific user, to the second control device 21.
[0078] When the key access code request signal 1420 is received by the second control device 21, the process of step S42 is executed. In step S42, the second control device 21 determines whether the key access code issuance condition is met. The key access code issuance condition includes a facial authentication condition that the face of the target person PS matches the face of the specific user in the facial authentication process of step S34 (in other words, the target person PS is authenticated as the specific user) (see FIG. 12). Therefore, the key access code issuance condition is met only when it is determined in the facial authentication process of step S34 that the face of the target person PS matches the face of the specific user (in other words, the target person PS is authenticated as the specific user).
[0079] The key acquisition code issuance condition may include a predetermined additional condition in addition to the facial authentication condition. In this case, the key acquisition code issuance condition is met only if both the facial authentication condition and the additional condition are met. For example, the additional condition may include a condition that a specific user has already viewed a predetermined manners video.
[0080] The second control device 21 determines whether the key access code issuance condition is met by referring to the stored contents of the second database 22. Since the face authentication result has already been stored in the second database 22 in the authentication process, it can determine whether the face authentication condition is met based on the stored contents. If an additional condition is set, it is assumed that information for distinguishing whether the additional condition is met (for example, information indicating whether a specific user has already viewed a specific manners video) is stored in the second database 22.
[0081] If the key access code issuance condition is met, the process proceeds from step S42 via step S43 (Y in step S43) to step S44. If the key access code issuance condition is not met, the process proceeds from step S42 via step S43 (N in step S43) to step S47. In step S47, the control devices 11 and 21 cooperate to execute a predetermined error handling process, and the operation of FIG. 14 ends.
[0082] In step S44, the second control device 21 transmits a key lending reservation ID request signal 1430 including the rental car reservation ID 812 to the second database 22. As a result, the second control device 21 reads out the key lending reservation ID 822 (FIG. 16(a)) corresponding to the rental car reservation ID 812 from the second database 22. Upon receiving the signal 1430, the second database 22 extracts the key lending reservation ID 822 corresponding to the rental car reservation ID 812 from its own stored contents and returns a response signal 1432 including the key lending reservation ID 822 to the second control device 21. If the rental car reservation ID 812 is the rental car reservation ID in the management side reservation information CC[i] (see FIG. 11), the key lending reservation ID in the management side reservation information CC[i] becomes the key lending reservation ID 822.
[0083] In step S45 following step S44, the second control device 21 transmits a key access code request signal 1440 to the third control device 31. The key access code request signal 1440 includes the key lending reservation ID 822, and the signal 1440 requests the transmission of a key access code CDa corresponding to the key lending reservation ID 822. In response to receiving the signal 1440, the third control device 31 returns a response signal 1442 including the key access code CDa corresponding to the key lending reservation ID 822 to the second control device 21. As a result, the second control device 21 acquires the key access code CDa.
[0084] Thereafter, in step S46, the key acquisition code issuance process is completed via a key acquisition code notification. In the key acquisition code notification, the key acquisition code CDa is notified to the terminal device 40a. Specifically, as shown in FIG. 15, the second control device 21 transmits a notification signal 1422 including the key acquisition code CDa to the first control device 11. Upon receiving the notification signal 1422, the first control device 11 transmits a notification signal 1412 including the key acquisition code CDa to the terminal device 40a. The transmission of the signal 1412 completes the key acquisition code issuance process. Upon receiving the signal 1412, the terminal device 40a displays the key acquisition code CDa on the display unit 43. The key acquisition code CDa may be recorded on the recording medium 46 of the terminal device 40a. In addition, the signal 1412 includes information indicating the model, license plate number, and external shape of the vehicle CRa to be rented, as well as information indicating the detailed location of the vehicle CRa. The various information included in the signal 1412 is displayed on the display unit 43 of the terminal device 40a.
[0085] 15 is a sequence diagram for proceeding to step S44, and the sequence for proceeding to step S47 is not shown in Fig. 15. When proceeding to step S47, a signal indicating that acquisition of the key acquisition code CDa has failed in the error handling process is transmitted from the second control device 21 to the terminal device 40a via the first control device 11.
[0086] A flowchart of the key acquisition process is shown in Figure 17. The key acquisition process in step S5 of Figure 4 includes the processes of steps S51 to S56 shown in Figure 17. In the key acquisition process, first in step S51, the target person PS goes to the location where the key storage device 33 having a storage section 331 that stores the key Ka is installed, and inputs a code into the key storage device 33. The code to be input here is the key acquisition code CDa, but a person who does not know the key acquisition code CDa may input a code other than the key acquisition code CDa.
[0087] If the key access code CDa is a PIN number, the target person PS inputs the PIN number as the key access code CDa into the operation unit 333 of the key storage device 33. The key access code CDa may be a two-dimensional code such as a QR code (registered trademark), a one-dimensional code, or any other pattern code. In this case, the key access code CDa displayed on the display unit 43 of the terminal device 40a is read by a code reading unit (not shown) provided in the key storage device 33, thereby inputting the key access code CDa into the key storage device 33.
[0088] In step S52 following step S51, the control unit of the key storage device 33 determines whether the code entered into the key storage device 33 is a valid key input code. Although not specifically shown, the key storage device 33 is provided with a control unit configured with a microcomputer or the like. Under the control of the control unit, each door 332 is placed in a closed or open state. If the code entered into the key storage device 33 does not match the key input code (N in step S52), the process proceeds to step S55, where the key storage device 33 executes a predetermined error handling process, and the operation of FIG. 17 ends. There may be multiple valid key input codes, but for simplicity of explanation, only the key acquisition code CDa will be focused on here as a valid key input code.
[0089] If the code input to the key storage device 33 matches the key access code CDa (Y in step S52), proceed from step S52 to step S53. In the following, it is assumed that the code input to the key storage device 33 matches the key access code CDa. In step S53, the control unit of the key storage device 33 determines whether the current date and time is within the key access permission period. If the current date and time is within the key access permission period (Y in step S53), proceed from step S53 to step S54. If the current date and time is not within the key access permission period (N in step S53), proceed from step S53 to step S56.
[0090] In step S54, the control unit of the key storage device 33 switches the door 332 of the storage unit 331 that stores the key Ka from a closed state to an open state. This switching completes the key acquisition process in Figure 17. After step S54, the target person PS can remove the key Ka from the storage unit 331. Thereafter, the target person PS can use the key Ka to open the door of the reserved vehicle CRa and drive the vehicle CRa.
[0091] Furthermore, when the door 332 of the storage section 331 that stores the key Ka is opened, or when it is detected that the key Ka has been removed from the storage section 331, a predetermined notification signal indicating this is sent from the key storage device 33 or the third control device 31 to the terminal device carried by the administrator of the system 10 or the first control device 11.
[0092] In step S56, the control unit of the key storage device 33 keeps the door 332 of the storage unit 331 that stores the key Ka in a closed state, and sends a predetermined notification to the target person PS. After the predetermined notification, the key acquisition process of Fig. 17 is completed. In the predetermined notification of step S56, the target person PS is notified using the display unit 334 that the key retrieval time is currently exceeded. Thereafter, if the target person PS enters the key acquisition code CDa into the key storage device 33 again within the key acquisition permission period, the process will proceed to step S54.
[0093] The key acquisition permission period is a period determined based on the rental car usage reservation period 814 (see Figure 16 (b)). That is, for example, it is appropriate to lend out the key Ka at the usage reservation start date and time 814S, but it is not appropriate to lend out the key Ka 30 hours before the usage reservation start date and time 814S. From this perspective, the key acquisition permission period is set based on predetermined rules. It can be understood that the key acquisition permission period is set by the third control device 31 based on the usage reservation period 814. However, the key acquisition permission period may also be set by the first control device 11 or the second control device 21 based on the usage reservation period 814.
[0094] Below, several specific configuration examples, operation examples, application techniques, modified techniques, etc. related to the system SYS will be described in multiple embodiments. The matters described above in this embodiment are applied to each of the following embodiments unless otherwise specified and unless there is a contradiction. If there are any matters in each embodiment that contradict the matters described above, the description in each embodiment may take precedence. Furthermore, unless there is a contradiction, the matters described in any of the multiple embodiments shown below can also be applied to any other embodiment (i.e., any two or more of the multiple embodiments can be combined).
[0095] <<First Example>> A first embodiment will now be described. Figures 18(a) and 18(b) show functional block diagrams of the second control device 21 according to the first embodiment. The second control device 21 includes functional blocks 211 to 217. The functional blocks 211 to 217 may be functional blocks that are realized by executing a program stored in the memory 21b in the calculation processing unit 21a.
[0096] Functional block 211 is a user registration processing unit. The user registration processing unit 211 performs processing that should be performed by the second control device 21 in the user registration process of step S1. Functional block 212 is a reservation processing unit. The reservation processing unit 212 performs processing that should be performed by the second control device 21 in the reservation process of step S2. Functional block 213 is an authentication processing unit. The authentication processing unit 213 performs processing that should be performed by the second control device 21 in the authentication process of step S3. Functional block 214 is a key acquisition code issuance processing unit. The key acquisition code issuance processing unit 214 performs processing that should be performed by the second control device 21 in the key acquisition code issuance process of step S4.
[0097] Each of the functional blocks 215 to 217 is a functional block included in one of the functional blocks 211 to 214, or is a functional block realized across two or more of the functional blocks 211 to 214.
[0098] The functional block 215 is a face image data acquisition unit that acquires image data of the user's face on the user's identification card. This acquisition is realized by receiving a user registration link signal 1120 from the first control device 11 (see FIG. 6). The user registration link signal 1120 includes image data of the user's face on the identification card. According to the sequence of FIG. 6, the face image data acquisition unit 215 can be considered to be included in the user registration processing unit 211.
[0099] The function block 216 is a condition determination unit that executes the process of step S42 in FIG. 14. That is, the condition determination unit 216 determines whether the key access code issuance condition is met. As described above, the key access code issuance condition includes a facial authentication condition that the face of the target person PS is determined to match the face of the specific user in the facial authentication process (i.e., the target person PS is authenticated as the specific user). As described above, the facial authentication process is executed based on the facial image data of the specific user acquired in the user registration process (image data of the face on the identification card) and the facial image data of the target person PS transmitted from the terminal device 40a in the authentication process (i.e., image data of the facial image PSf). Therefore, it can be said that the condition determination unit 216 determines whether the key access code issuance condition is met based on the former facial image data (image data of the specific user's face) and the latter facial image data (image data of the target person PS).
[0100] Functional block 217 is a key access code issuing unit that executes the processes of steps S44 to S46 in Fig. 14. Specifically, key access code issuing unit 217 transmits signals 1430 and 1440 and receives signals 1432 and 1442 shown in Fig. 15, and then transmits notification signal 1422 to first control device 11. The transmission of notification signal 1422 results in the issuance of a key access code to be sent to terminal device 40a. In the sequence diagram of Fig. 15, the key access code is sent from second control device 21 to terminal device 40a via first control device 11, but a modification is also possible in which the key access code is sent directly from second control device 21 to terminal device 40a.
[0101] 16(a) and 16(b). In the system SYS, when the key access code issuance conditions, including the facial authentication conditions, are met and the key access code CDa is input to the key storage device 33, which has a storage unit 331 that stores the key Ka, within the key access permission period based on the rental car reservation period 814, the door 332 of the storage unit 331 is opened (i.e., the key Ka is available to the target person PS). That is, the key Ka becomes available only when all of the following conditions are met: the key access code issuance conditions, including the facial authentication conditions, the valid key access code (here, CDa) is input to the key storage device 33, and the key access code is input within the key access permission period. That is, the key Ka becomes available after multiple checks.
[0102] By providing such a multiple check function, fraudulent activities such as the fraudulent use of rental cars are suppressed. A supplementary explanation is provided regarding this. In a reference method for rental car rental operations, a clerk at the office counter verifies the customer's identity using a driver's license or other identification before directly handing over the key. Currently, rental operations according to the reference method are common. If such rental operations were to be performed unmanned, fraudulent activities such as a third party receiving the key could occur. This is because if the office were simply unmanned based on the reference method, it would be impossible to confirm whether the person who comes to pick up the key is the same person who made the reservation (the person corresponding to the driver's license or other identification). Alternatively, it would be impossible to confirm whether the person who performed the identity verification actually came to pick up the key. Furthermore, the omission of identity verification procedures due to unmanned operation is thought to lead to an increase in fraudulent activities. The multiple check function according to this embodiment suppresses fraudulent activities. Because fraudulent activities can be suppressed, unmanned operation of offices becomes possible, which in turn enables cost reduction. However, in this embodiment, it is not essential that the sales office be unmanned, and the necessary staff may be employed at the sales office. In this case, the number of staff required at the sales office can be reduced.
[0103] In the authentication process (see FIG. 12), the target person PS's terminal device 40a accesses a predetermined rental website based on a site access code (access information) available at a predetermined access location. After this access, image data of the target person PS's face obtained by photographing the terminal device 40a is sent to the second control device 21 (condition determination unit) via the first control device 11 (in other words, via the rental website). Then, the condition determination unit 216 determines whether the key access code issuance conditions, including the facial authentication conditions, are met based on the image data of the target person PS sent via the above access and the image data of the specific user's face acquired by the facial image data acquisition unit 215 (image data of the specific user's face on the specific user's identification card).
[0104] The access location can be, for example, near the rental car rental location or near the location where the key storage device 33 is installed. This reduces the time from identity authentication by facial recognition processing to actual use of the rental car, making it highly convenient.
[0105] The access location may be a location that is within a predetermined distance from the rental car rental location or the location where the key storage device 33 is installed. Specifically, with respect to the reservation corresponding to the rental car reservation ID 812, the access location may be the following locations: The access location may be a location that is within a predetermined distance from the rental car rental location 816 or the location where the key storage device 33 equipped with a storage unit 331 that stores the key Ka is installed.
[0106] This shortens the time from identity verification through facial recognition processing to actually using the rental car, making it highly convenient.
[0107] It is preferable that the location of the address of the specific user is separated by a certain distance or more from the rental car rental location 816. For example, the address of the specific user may be far from the rental location 816 to the extent that it is difficult or impossible to walk from the address of the specific user to the rental location 816, such as when the prefecture to which the address of the specific user belongs is different from the prefecture to which the rental car rental location 816 belongs.
[0108] For example, the region to which the rental car rental location 816 belongs is a specific user's travel destination. The region to which the rental car rental location 816 belongs may be a remote island, and an example will be described in which there is an ocean between the specific user's address and the rental car rental location 816. That is, assume that the specific user's address is in a first region and the rental car rental location 816 is in a second region, and that the first and second regions are separated by ocean. Also assume that the specific user departs from the first region, crosses the ocean to arrive in the second region, and then rents a car in the second region. For example, the first region is an area within Tokyo, and the second region is an area within Okinawa Prefecture. In this case, the specific user arrives in Okinawa Prefecture by plane and then rents a car. The airport where the plane arrives (an airport within Okinawa Prefecture, hereinafter referred to as the target airport) can be set as the access location. In this case, the access location is a location connected to the rental car rental location 816 by land. For example, a rental car office adjacent to the target airport may be the rental car rental location 816.
[0109] The means of transportation for a specific user from the first region to the second region is not limited to an airplane. For example, a specific user may travel from the first region to the second region by boat. In this case, the access location can be set to a departure / arrival point in the second region where the boat departing from the first region arrives. In this case, for example, a rental car office adjacent to the departure / arrival point may be the rental car rental location 816.
[0110] When a specific user arrives from the first region to the second region, it is expected that the specific user will necessarily pass through, or will be able to easily pass through, an access location that is connected to the rental car rental location 816 by land. In particular, if the first region and the second region are separated by water, the specific user is expected to use an airplane or a boat. By posting a site access code at such an access location (for example, a designated location within the target airport or a designated location at the above-mentioned departure and arrival point), the specific user can quickly complete the procedures for using a rental car, which is very convenient.
[0111] Here, an explanation will be given of the key acquisition permission period based on the rental car usage reservation period 814. Please refer to Figures 19(a) to 19(c). Figures 19(a) to 19(c) show periods 851, 852, and 853. The key acquisition permission period based on the rental car usage reservation period 814 may be period 851, 852, or 853.
[0112] The period 851 coincides with the use reservation period 814. The period 852 is the period from a first predetermined time t1 before the use reservation start date and time 814S to the use reservation end date and time 814E. The predetermined time t1 is, for example, 30 minutes, 1 hour, or 2 hours. The period 853 is a period of a second predetermined time that includes the use reservation start date and time 814S. More specifically, the period 853 is the period from the predetermined time t1 before the use reservation start date and time 814S to the end date and time 814E. 2A The reservation start date and time 814S is set at the specified time t 2B The period from the predetermined time t 2A and t 2B The sum of the above corresponds to the second predetermined time. The second predetermined time is, for example, 1 hour, 2 hours, or 3 hours. However, the predetermined time t 2B is shorter than the length of the reservation period 814.
[0113] The third control device 31 in the system 30 may set the period 851, 852, or 853 as the key access permission period based on the usage reservation period 814. Alternatively, the second control device 21 in the system 20 may set the period 851, 852, or 853 as the key access permission period based on the usage reservation period 814, and communicate the setting result to the third control device 31.
[0114] By setting the key acquisition permission period to a period 851, 852, or 853 based on the usage reservation period 814, the key Ka can be retrieved only at the appropriate timing for the rental car rental period. Therefore, for example, even if the rental car office is unmanned, the rental car can be rented out appropriately in accordance with the rental contract.
[0115] The key acquisition permission period based on the usage reservation period 814 may be within the period 851, the period 852, or the period 853, and may be the period from the timing at which the terminal device 40a of the target person PS accesses the rental website (hereinafter referred to as access timing J1 for convenience) until a predetermined time limit has elapsed. The time limit may be, for example, one hour, two hours, or three hours.
[0116] The access timing J1, which is the starting point for calculating the time limit, may be the timing when the terminal device 40a starts accessing the rental website in step S31 of Figure 12, or the timing when the login operation is performed in step S32. The access timing J1 may be any timing within the period from the timing when the terminal device 40a starts accessing the rental website to the timing when the terminal device 40a ends accessing the rental website. The processing of steps S31 to S35 of Figure 12 and the processing of steps S41 to S46 of Figure 14 are performed while the terminal device 40a is accessing the rental website. Therefore, the access timing J1 may be the timing when any of the processing of S31 to S35 and S41 to S46 is performed.
[0117] The key acquisition permission period based on the usage reservation period 814 may be within the period 851, the period 852, or the period 853, and may be the period from the timing of issuance of the key acquisition code CDa by the key acquisition code issuing unit 217 (hereinafter referred to as the issuance timing J2 for convenience) until a predetermined time limit has elapsed. Specific examples of the time limit are as described above.
[0118] The issue timing J2, which is the starting point of the time limit, is the timing when the process of step S46 in Fig. 14 is performed. More specifically, for example, the issue timing J2 may be the timing when the key access code issuing unit 217 transmits the notification signal 1422 to the first control device 11. It may also be considered that the timing when the notification signal 1412 is transmitted to the terminal device 40a corresponds to the issue timing J2.
[0119] When setting the key access permission period according to the access timing J1 or the issuance timing J2, the third control device 31 in the system 30 may set the key access permission period based on the use reservation period 814 and the access timing J1 or the issuance timing J2. In this case, however, the access timing J1 or the issuance timing J2 is transmitted from the second control device 21 to the third control device 31 prior to setting the key access permission period. Alternatively, the second control device 21 in the system 20 may set the key access permission period based on the use reservation period 814 and the access timing J1 or the issuance timing J2, and transmit the setting result to the third control device 31.
[0120] By setting the key access permission period according to the usage reservation period 814, the key Ka can be retrieved only at the appropriate timing for the rental car rental period. Therefore, for example, even if the rental car office is unmanned, the rental car can be rented out appropriately in accordance with the rental contract. Furthermore, by setting a limit on the key access permission period according to the access timing J1 or the issuance timing J2, it is expected that fraudulent acts will be less likely to occur (it is believed that such a limit will reduce the opportunities for a person who has fraudulently obtained the key access code CDa to actually obtain the key Ka).
[0121] <<Second Example>> A second embodiment will now be described. The key storage device 33 may be configured in any way so long as it allows the target person PS to obtain the key Ka stored in the storage unit when the key access code CDa is entered within the key access permission period. Therefore, for example, the key storage device 33′ shown in FIG. 20 may be used as the key storage device 33.
[0122] The key storage device 33′ includes the above-mentioned operation units 333 and 334, as well as an outlet 336. The key storage device 33′ incorporates a storage unit (not shown) that stores one or more keys including the key Ka, and a mechanism (not shown) that can output the key Ka in the storage unit to the outlet 336.
[0123] 17, the control unit of the key storage device 33′ outputs the key Ka stored in the storage unit to the outlet 336. The target person PS operating the key storage device 33′ can retrieve an object stored in the outlet 336. Therefore, when the key Ka is output to the outlet 336, the target person PS can retrieve the key Ka from the outlet 336 and obtain it.
[0124] <<Third Example>> A third embodiment will now be described. In the third embodiment, modified techniques and supplementary points for the above-described configurations, operations, etc. will be described.
[0125] In the authentication process, when the second control device 21 determines that the face of the target person PS does not match the face of the specific user, an administrator of the system SYS (e.g., a person who can operate the second control device 21) may perform a confirmation operation. In this confirmation operation, the administrator of the system SYS visually compares the facial photograph on the specific user's identification card with the facial image PSf of the target person PS (see FIG. 13 ). Then, when the administrator of the system SYS determines that the face of the target person PS matches the face of the specific user, he or she may input a correction operation to the second control device 21 to replace the determination in the second control device 21 with a determination that the face of the target person PS matches the face of the specific user.
[0126] After the user registration process for a specific user, photographing to obtain a facial image of the specific user may be performed multiple times. For example, photographing to obtain a facial image of the specific user (photographing with the terminal device 40) may be performed during the reservation process and also on the day of rental car use. Then, face authentication processing may be performed by referring to all of the facial images obtained by photographing.
[0127] If there is information that a specific user has engaged in inappropriate driving (such as tailgating) in the past or has engaged in some kind of fraudulent activity in the past, the system SYS may not permit the specific user to rent a car. For example, the system SYS may refuse to reserve a rental car or may refuse to issue a key access code. The information regarding inappropriate driving or fraudulent activity may be provided to the system SYS from a device outside the system SYS, or may be obtained based on the specific user's past usage history of the system SYS.
[0128] In the above-described configuration, the target person PS is permitted or prohibited from using (driving) the rental car depending on whether or not the target person PS has access to a physical key. However, a modified method is also possible in which the target person PS is permitted or prohibited from using (driving) the rental car without using a physical key. In this modified method, the key access code CDa is a two-dimensional code such as a QR code (registered trademark), a one-dimensional code, or any other pattern code. Furthermore, a code reader (not shown) capable of reading two-dimensional codes, one-dimensional codes, or pattern codes is installed in the vehicle CRa. The target person PS displays the key access code CDa on the display unit 43 of the terminal device 40a and causes the display content of the display unit 43 to be read by the code reader of the vehicle CRa. An in-vehicle device (not shown) installed in the vehicle CRa opens the doors of the vehicle CRa only if the code read by the code reader matches the key access code CDa and the current time is within the key access permission period. The in-vehicle device installed in the vehicle CRa then permits the target person PS to drive the vehicle CRa during the usage reservation period 814.
[0129] To realize the above transformation method, a process is required in which the on-board device installed in the vehicle CRa recognizes the key access code CDa and the key access permission period. Information indicating the key access code CDa and the key access permission period may be transmitted from the second control device 21 to the on-board device, for example. Alternatively, a facial image PSf may be acquired by photographing the target person PS using a camera installed in the vehicle CRa, and the above facial recognition process may be performed by the on-board device installed in the vehicle CRa. In this case, for example, the on-board device installed in the vehicle CRa, the control devices 11 and 21, and the terminal device 40a may cooperate to determine whether the facial image PSf matches the face of the specific user.
[0130] The rental management system 20 or the second control device 21 is an example of a rental car rental management device. The business operator system 10 is an example of a first separate system (first external system) connected to the rental car rental management device so as to be able to communicate bidirectionally. The key rental system 30 is an example of a second separate system (second external system) connected to the rental car rental management device so as to be able to communicate bidirectionally.
[0131] The embodiments of the present invention can be modified in various ways as appropriate within the scope of the technical ideas set forth in the claims. The above-described embodiments are merely examples of the present invention, and the meanings of the terms of the present invention and each constituent element are not limited to those described in the above-described embodiments. The specific numerical values shown in the above description are merely examples, and as a matter of course, they can be changed to various numerical values. [Explanation of symbols]
[0132] SYS Rental Car Management System 10. Operator Systems 11 First control device 12 Database 1 20 Loan Management System 21 Second control device 22 Second Database 30 Key lending system 31 Third control device 32 Third Database 33 Key storage device 331 Storage Unit 332 Door 333 Operation section 334 Display section 40 Terminal Equipment 211 User registration processing unit 212 Reservation Processing Unit 213 Authentication processing section 214 Key acquisition code issuing processing unit 215 Facial image data acquisition unit 216 Condition judgment section 217 Key Acquisition Code Issuance Department
Claims
1. A rental car rental management device that has a database that stores information about a rental car reserved by a user and reservation information including a reservation period for using the rental car, and stores a facial image of the user's identification card as a registered facial image, and that performs control so that the user can obtain a key for the rental car from a key storage device before using the rental car, A key acquisition permission period is set based on the rental car reservation period, After the reservation information and the registered face image are stored in the database and the user logs in from the terminal device, the captured face image of the user is acquired from the terminal device; If it is determined that the photographed face image acquired from the terminal device matches the registered face image, A key acquisition code for the user to acquire the rental car key stored in the key storage device within the key acquisition permission period is transmitted to the terminal device. , rental car rental management device.
2. After accessing a predetermined website with the terminal device based on access information available at a predetermined location, the terminal device logs in to the website and receives a photographed face image of the user obtained by photographing the terminal device.
2. The rental car rental management device according to claim 1.
3. The rental car reservation period is the period from the reservation start date and time to the reservation end date and time, The key acquisition permission period coincides with the rental car reservation period.
3. The rental car rental management device according to claim 1 or 2.
4. The rental car reservation period is the period from the reservation start date and time to the reservation end date and time, The key acquisition permission period is a period from a first predetermined time before the reservation start date and time to the reservation end date and time.
3. The rental car rental management device according to claim 1 or 2.
5. The key acquisition permission period is limited to a period from the time when the key acquisition code is transmitted to the terminal device until a predetermined time limit has elapsed.
5. A rental car rental management device according to claim 1.
6. A rental car rental management device that has a database that stores reservation information including information on a rental car reserved by a user and the reservation period for using the rental car, and stores a facial image of the user's identification card as a registered facial image, and that controls so that the user can obtain the rental car key from a key storage device before using the rental car; a first system configured to be able to communicate with the user's terminal device and the rental car rental management device; A rental car management system comprising: a second separate system including the key storage device; the rental car rental management device sets a key acquisition permission period based on the rental car use reservation period, When the reservation information and the registered facial image are stored in the database and the user logs in from the terminal device, the first other system requests uploading of the user's facial image on the logged-in website, and upon receiving the upload of the user's photographed facial image by the terminal device, the first other system transmits the photographed facial image to the rental car rental management device, When the rental car rental management device receives the photographed facial image and determines that the photographed facial image matches the registered facial image, it transmits to the terminal device a key acquisition code that enables the user to acquire the rental car key stored in the key storage device within the key acquisition permission period. , rental car management system.
7. When the rental car rental management device receives the photographed facial image and determines that the photographed facial image matches the registered facial image, it transmits a predetermined request signal to the second separate system, and the second separate system responds to receiving the request signal by transmitting the key acquisition code associated with the rental car key to the rental car rental management device, and the rental car rental management device transmits the received key acquisition code to the user's terminal device via the first separate system, The key storage device includes a storage unit for storing the rental car key, and when the key acquisition code is input within the key acquisition permission period, the rental car key in the storage unit is made available to the user.
7. The rental car management system according to claim 6.
8. After accessing the website with the terminal device based on access information available at a predetermined location, the facial image of the user obtained by photographing the terminal device after logging in to the website with the terminal device is received by the rental car rental management device via the first separate system.
8. The rental car management system according to claim 6 or 7.
9. The rental car reservation period is the period from the reservation start date and time to the reservation end date and time, The key acquisition permission period coincides with the rental car reservation period.
9. A rental car management system according to claim 6.
10. The rental car reservation period is the period from the reservation start date and time to the reservation end date and time, The key acquisition permission period is a period from a first predetermined time before the reservation start date and time to the reservation end date and time.
9. A rental car management system according to claim 6.
11. The rental car rental management device limits the key acquisition permission period to a period from the time when the key acquisition code is transmitted to the terminal device until a predetermined time limit has elapsed.
11. A rental car management system according to claim 6.
12. A rental car rental management method executed by a rental car rental management device having a database that holds reservation information including information on a rental car reserved by a user and a reservation period for using the rental car, and that holds a facial image of the user's identification card as a registered facial image, the method performing control to enable the user to obtain the rental car key from a key storage device before using the rental car, setting a key acquisition permission period based on the rental car reservation period; a step of acquiring a facial image of the user photographed by the terminal device from the terminal device after the reservation information and the registered facial image are stored in the database and the user logs in from the terminal device; and when it is determined that the photographed face image acquired from the terminal device matches the registered face image, transmitting to the terminal device a key acquisition code that enables the user to acquire the rental car key stored in the key storage device within the key acquisition permission period. , rental car rental management method.
Citation Information
Patent Citations
Renting and returning system for rent-a-car
JP1996016900A
Device and system for issuing authentication information, and device and system for automatically renting and returning rental equipment
JP2002203244A
Issuing system, server, issuing device, issuing method, and program
JP2020021162A