Vehicle setting system according to occupants, and vehicle

A multi-factor authentication system for vehicles manages occupant-specific settings through dual authentication, enhancing security and convenience by ensuring only authorized occupants can access their personalized information.

JP7723525B2Active Publication Date: 2025-08-14SUBARU CORP
View PDF 12 Cites 0 Cited by

Patent Information

Application Number
JP2021127474
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-08-03
Publication Date
2025-08-14
Estimated Expiration
2041-08-03

AI Technical Summary

Technical Problem

Existing vehicle systems face challenges in ensuring secure and convenient access to occupant-specific setting information, particularly account information for network services, while accommodating multiple occupants with varying preferences and security needs.

Method used

A multi-factor authentication system involving a first authentication unit for individual occupants and a second authentication unit for the combination of occupants and vehicles, coupled with a server device to manage and authenticate occupant-specific setting information, enhances security and convenience by ensuring only authorized occupants can access their settings.

Benefits of technology

The system improves security by preventing unauthorized access to sensitive information and ensures each occupant can conveniently access their personalized settings, regardless of the vehicle's occupancy status.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007723525000001
    Figure 0007723525000001
  • Figure 0007723525000002
    Figure 0007723525000002
  • Figure 0007723525000003
    Figure 0007723525000003
Patent Text Reader

Abstract

To provide a setting system for a vehicle that increases safety while ensuring convenience for setting information on every occupant who uses the vehicle, and a vehicle.SOLUTION: A vehicle setting system 1 has a setting unit 75 that sets settings according to an occupant to a vehicle, and has: a service providing device having a memory 47 that records setting information for every occupant; a biological authentication unit 71 that authenticates an occupant who rides on a vehicle; and a combination authentication unit 74 that authenticates the combination of the occupant authenticated by the biological authentication unit 71 and the vehicle on which the occupant rides. The biological authentication unit 71 can authenticate a plurality of occupants who ride on the vehicle. The combination authentication unit 74 authenticates the combination of the plurality of occupants authenticated by the biological authentication unit 71 and the vehicle on which the occupants ride. The setting unit 75 acquires setting information for every occupant from the memory 47 of a device of the service providing device according to results of authentication performed by the biological authentication unit 71 and the combination authentication unit 74, and sets the setting information to the vehicle.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a vehicle setting system according to an occupant, and to a vehicle. [Background technology]

[0002] In vehicles such as automobiles, passengers can adjust the seat position and other settings. Furthermore, automobiles in recent years are equipped with sophisticated information devices, allowing passengers to use telematics services, content services, and sales services while in the automobile. In such a vehicle, after getting into the vehicle, the occupant will adjust the seat position to suit themselves and perform operations to connect to various network services such as telematics services. Even if a passenger gets into a car, they will not be able to start driving immediately. In particular, when passengers wish to use multiple network services while on board, they must perform connection operations for each of the multiple network services they wish to use, which is a hassle that passengers cannot bear. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2004-243825 [Patent Document 2] Japanese Patent Application Publication No. 2017-043268 [Patent Document 3] Japanese Patent Application Publication No. 2019-113947 Summary of the Invention [Problem to be solved by the invention]

[0004] As a countermeasure against such a situation, it is conceivable that the automobile records the setting information in a vehicle memory or in a server device with which the automobile can communicate (Patent Documents 1 and 2). When recording setting information in this manner, it is necessary to identify and authenticate the occupants of the vehicle so that the setting information is not available to anyone in the vehicle (Patent Documents 2 and 3). By combining these technologies, a vehicle can identify its occupants using biometric authentication or other methods, obtain occupant-specific setting information stored in the vehicle or a server device, and execute settings to make the information available in the vehicle.

[0005] However, if occupant-specific setting information stored in a vehicle or server device is acquired and made available solely through authentication of the occupant, it may be difficult to say that sufficient security is ensured depending on the content of the setting information. For example, it is considered strongly desirable to ensure that account information for payment services used in sales services, etc., cannot be used by anyone other than the genuine occupant. If information becomes available simply by identifying and authenticating the occupant, it is difficult to say with certainty that there is little possibility that the payment service will be fraudulently acquired or used by others through impersonation or the like. Occupant-specific setting information requires high security to prevent it from being used by others.

[0006] Furthermore, automobiles are generally shared by multiple people. Multiple passengers can ride in an automobile at the same time. Depending on the riding conditions in such automobiles, it may be desirable not to automatically set the setting information for each passenger stored in the vehicle or server device.

[0007] In this way, it is necessary to improve safety of the setting information for each occupant used in a vehicle while ensuring convenience for authentic use. [Means for solving the problem]

[0008] An occupant-specific vehicle setting system according to one aspect of the present invention has an occupant-specific setting unit that executes setting on the vehicle to make occupant-specific settings available in the vehicle, the system having a server device having a server recording unit that records occupant-specific setting information for occupants riding in the vehicle, a first authentication unit that authenticates occupants riding in the vehicle, and a second authentication unit that authenticates a combination of the occupant authenticated by the first authentication unit and the vehicle in which the occupant is riding, wherein the first authentication unit is capable of authenticating multiple occupants riding in the vehicle, and the second authentication unit authenticates a combination of the multiple occupants authenticated by the first authentication unit and the vehicle in which the occupant is riding, and the setting unit acquires occupant-specific setting information for the occupant authenticated by the second authentication unit from the server recording unit of the server device in accordance with the authentication results by the first authentication unit and the authentication results by the second authentication unit for the multiple occupants riding in the vehicle, and executes setting on the vehicle. When multiple occupants are authenticated by the first authentication unit, information on the multiple occupants authenticated by the first authentication unit is acquired together with information on the vehicle in which they are riding, and combined authentication is performed.

[0010] Preferably, the setting information recorded in the server recording unit includes at least account information for network services that the occupant can use in the vehicle and vehicle setting information for the occupant that is set in the vehicle according to the occupant, and the setting unit acquires and sets vehicle setting information for multiple occupants that is recorded in the server recording unit of the server device and has been authenticated by the second authentication unit, and acquires or sets network service account information for a occupant who is determined to be the driver based on their seating position or a occupant who is determined to be the owner of the vehicle in preference to that of other occupants.

[0011] Preferably, the setting information recorded in the server recording unit includes at least account information for network services that the occupant can use in the vehicle and vehicle setting information for the occupant that is set in the vehicle according to the occupant, and the setting unit acquires and sets vehicle setting information for multiple occupants that is recorded in the server recording unit of the server device and is authenticated by the first authentication unit, and acquires or sets network service account information for multiple occupants that is recorded in the server recording unit of the server device and is authenticated by the second authentication unit according to operations of the occupants riding in the vehicle.

[0012] Preferably, the vehicle has a wide-angle imaging device capable of capturing images of multiple occupants riding in the vehicle, and the first authentication unit and the second authentication unit authenticate the multiple occupants riding in the vehicle based on images captured by the wide-angle imaging device.

[0013] A vehicle according to one aspect of the present invention has at least the setting unit among a setting unit that executes setting of the vehicle to make settings according to occupants available in the vehicle, a first authentication unit that authenticates occupants in the vehicle, and a second authentication unit that authenticates a combination of the occupant authenticated by the first authentication unit and the vehicle in which the occupant is riding, wherein the first authentication unit is capable of authenticating multiple occupants in the vehicle, and the second authentication unit authenticates a combination of the multiple occupants authenticated by the first authentication unit and the vehicle in which the occupant is riding, and the setting unit acquires occupant-specific setting information for the occupant authenticated by the second authentication unit from a server recording unit that records occupant-specific setting information for the occupant riding in the vehicle in accordance with the authentication results by the first authentication unit and the authentication results by the second authentication unit for the multiple occupants in the vehicle, and executes setting of the vehicle. When multiple occupants are authenticated by the first authentication unit, information on the multiple occupants authenticated by the first authentication unit is acquired together with information on the vehicle in which they are riding, and combined authentication is performed. [Effects of the Invention]

[0014] In the present invention, in order for a vehicle occupant to set and use their occupant-specific setting information in the vehicle, they must be authenticated by the first authentication unit, and the combination of the occupant and the vehicle must be authenticated by the second authentication unit. By using such multi-factor and multi-stage authentication that is not based solely on authentication of the occupant, the security of the occupant-specific setting information recorded in the server recording unit of the server device is enhanced. Furthermore, the second authentication unit authenticates the combination of the occupant authenticated by the first authentication unit and the vehicle in which the occupant is riding, and therefore can also authenticate the authenticity of the routing from the vehicle to the server device. The second authentication unit of the present invention is considered to make it more difficult for the occupant-specific setting information of the server device to be fraudulently obtained or used, compared to, for example, when the server device authenticates the vehicle based on authentication of the occupant by the first authentication unit. This enhances the security of the occupant-specific setting information of the server device. Furthermore, a vehicle may have multiple occupants, and the first authentication unit of the present invention is capable of authenticating the multiple occupants. The second authentication unit authenticates the combination of the multiple occupants authenticated by the first authentication unit with the vehicle in which they are riding. The setting unit then acquires occupant-specific setting information for the occupants authenticated by the second authentication unit from the server record unit of the server device in accordance with the authentication results by the first authentication unit and the second authentication unit for the multiple occupants riding in the vehicle, and performs setting on the vehicle. In the present invention, when multiple occupants ride in a vehicle, setting on the vehicle can be performed in accordance with the authentication results by the first authentication unit and the authentication results by the second authentication unit for the multiple occupants riding in the vehicle. Each occupant can enjoy the convenience of setting according to their riding environment. In this way, the present invention can improve the convenience of authentic use of setting information for each occupant used in a vehicle while also improving safety. [Brief explanation of the drawings]

[0015] [Figure 1] FIG. 1 is an explanatory diagram of a vehicle setting system for an automobile according to an embodiment of the present invention. [Figure 2]FIG. 2 is an explanatory diagram of the control system of the automobile of FIG. [Figure 3] FIG. 3 is an explanatory diagram of a computer device that can be used as the occupant information server device of FIG. [Figure 4] FIG. 4 is an explanatory diagram of the storage destination of the setting information for each occupant in the vehicle setting system of the automobile of FIG. 1 and a plurality of functions used in the vehicle setting system. [Figure 5] FIG. 5 is a flowchart of setting control according to the passengers riding in the automobile, performed by the control system of the automobile of FIG. [Figure 6] FIG. 6 is a timing chart of setting control when an occupant undergoes two-stage authentication in the vehicle setting system of the automobile of FIG. [Figure 7] FIG. 7 is an explanatory diagram of an example of authentication information for combining a plurality of occupants in a vehicle with the vehicle, which is transmitted from the vehicle to the occupant information server device in step ST6 of FIG. [Figure 8] FIG. 8 is a flowchart showing an example of detailed setting control by the setting unit 75 when a plurality of occupants have been authenticated by the combination authentication unit 74. DETAILED DESCRIPTION OF THE INVENTION

[0016] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0017] FIG. 1 is an explanatory diagram of a vehicle setting system 1 for an automobile 2 according to an embodiment of the present invention. 1 executes settings for an automobile 2 in which an occupant, such as a driver, rides, according to the occupant. The vehicle setting system 1 has a control system 3 for the automobile 2 and an occupant information server device 4 capable of data communication with the control system 3. The automobile 2 is an example of a vehicle in which an occupant rides.

[0018] Occupants riding in the automobile 2 approach and board the automobile 2 carrying an occupant terminal 5 and a boarding key 6. FIG. 1 shows multiple occupants sharing one automobile 2. The first occupant carries a first occupant terminal 5 and a first boarding key 6. The second occupant, riding with a fellow passenger, carries a second occupant terminal 5 and a second boarding key 6. An application program for managing or using the automobile 2 may be installed on each occupant terminal 5. Similar to the boarding key 6, such an occupant terminal 5 may be capable of executing control such as unlocking the automobile 2 when an occupant approaches the automobile 2.

[0019] The control system 3 of the automobile 2, which is a moving body, may establish a communication path with a base station 7 located around the automobile 2, and perform data communication with the occupant information server device 4 through the base station 7 and a communication network 8. The base station 7 and the communication network 8 may be for 5G provided by a carrier, or may be for, for example, an ADAS (Advanced Driver Assistance System) provided by a public institution or the like. Furthermore, the control system 3 of the automobile 2 may connect to each of multiple service providing devices 9-11 used by the occupants in the automobile 2 via the base station 7 and the communication network 8, and may transmit and receive service information between the multiple service providing devices 9-11. FIG. 1 shows multiple service providing devices 9-11 that provide such network services, including a first service providing device 9, a second service providing device 10, ..., and an m-th service providing device 11 (m is a natural number greater than or equal to 1). Multiple occupants using the automobile 2 may generally use network services provided by different service providing devices in the shared automobile 2. Network services include, for example, telematics services, video and audio content providing services, sales services, payment services, navigation services for route guidance and automatic driving control, information providing services for tourist destinations, search services for the World Wide Web, communication services such as telephone and conference calls, online vehicle control services for controlling the vehicle's operation, and other application services. When users, such as occupants, use network services, they are often required to obtain account information for each network service.

[0020] FIG. 2 is an explanatory diagram of the control system 3 of the automobile 2 of FIG. The control system 3 of the automobile 2 in Figure 2 includes a vehicle ECU 21, a vehicle memory 22, a vehicle timer 23, a vehicle GNSS receiver 24, a mobile communication device 25, a short-range communication device 26, a key approach sensor 27, a door opening / closing sensor 28, an acceleration sensor 29, an in-vehicle camera 30, an occupant monitoring device 31, a vehicle display device 32, a vehicle operation device 33, a vehicle setting device 34, and a vehicle network 35 to which these are connected.

[0021] The vehicle network 35 may be a wired communication network for the automobile 2 that complies with, for example, a Controller Area Network (CAN) or a Local Interconnect Network (LIN). The vehicle network 35 may also be a communication network such as a LAN, or a combination thereof. A wireless communication network may be included as part of the vehicle network 35.

[0022] The vehicle GNSS receiver 24 receives radio waves from GNSS satellites and generates the current position of the automobile 2 and the current time.

[0023] The vehicle timer 23 measures time or time. The time of the vehicle timer 23 may be calibrated by the current time of the vehicle GNSS receiver 24.

[0024] The mobile communication device 25 establishes a communication path via wireless communication with the base station 7 whose zone includes the automobile 2. This allows the mobile communication device 25 to perform data communication with the occupant information server device 4 and multiple service providing devices 9 to 11 via the base station 7 and the communication network 8. The mobile communication device 25 may directly communicate with the mobile communication device of another vehicle and establish a communication path to the base station 7 via the other vehicle. Even in this case, the mobile communication device 25 can perform data communication with the occupant information server device 4 and the plurality of service providing devices 9 to 11 through the mobile communication device of the other vehicle, the base station 7, and the communication network 8.

[0025] The key proximity sensor 27 detects, through specific short-range wireless communication, a passenger key 6 held by a passenger inside or nearby the automobile 2. The passenger key 6 has identification information that is different from that of other passenger keys 6. The identification information of the passenger key 6 can be used as the passenger's identification information. For example, when the key proximity sensor 27 detects the passenger key 6, it generates a signal to unlock the doors of the automobile 2 and outputs the signal to the vehicle network 35. This automatically unlocks the doors of the automobile 2, allowing the passenger to enter the automobile 2 by simply approaching the automobile 2, without having to unlock the doors themselves. Furthermore, when the key proximity sensor 27 no longer detects the passenger key 6 of a passenger who has exited the automobile 2, it generates a signal to lock the doors of the automobile 2 and outputs the signal to the vehicle network 35. This automatically locks the doors of the automobile 2.

[0026] The short-range communication device 26 establishes a communication path with an occupant terminal 5 carried by an occupant inside or nearby the automobile 2 via short-range wireless communication. Examples of short-range wireless communication standards include IEEE (Institute of Electrical and Electronics Engineers) 802.15.1 and IEEE 802.11 / b / g. The occupant terminal 5 may be, for example, a mobile phone terminal or a wearable terminal that can connect to a carrier's base station 7. The short-range communication device 26 detects, authenticates, and connects to the occupant terminal 5 carried by an occupant inside or nearby the automobile 2. This enables the short-range communication device 26 to perform data communication with the occupant terminal 5. An application program installed in the passenger terminal 5 for managing or using the automobile 2 may have identification information that is different from other application programs. In this case, when the passenger terminal 5 on which the application program is installed approaches the automobile 2, the short-range communication device 26 may generate a signal to unlock the doors of the automobile 2 and output it to the vehicle network 35, similar to the key approach sensor 27. Furthermore, when the passenger terminal 5 of the passenger who has exited the automobile is no longer detected, the short-range communication device 26 may generate a signal to lock the doors of the automobile 2 and output it to the vehicle network 35. This allows the doors of the automobile 2 to be locked automatically.

[0027] The door opening / closing sensor 28 detects the opening and closing of a door (not shown) of the automobile 2. If the automobile 2 has multiple doors, such as a driver's door and a passenger's door, the door opening / closing sensor 28 may be provided for each door.

[0028] The acceleration sensor 29 detects the acceleration of the traveling automobile 2. The acceleration sensor 29 may also detect the speed of the automobile 2 by integrating the acceleration.

[0029] The in-vehicle camera 30 is provided in the vehicle 2 to capture images of the interior of the vehicle 2. The in-vehicle camera 30 may be a wide-angle imaging device capable of capturing an image of the entire cabin of the vehicle 2. The wide-angle captured image can capture images of multiple occupants, including the driver, riding in the vehicle 2. The image captured by the in-vehicle camera 30 may contain image components of the occupants' appearances and veins, for example, as biometric information.

[0030] The occupant monitoring device 31 detects and identifies occupants in the automobile 2 based on images captured by the in-vehicle camera 30 and monitors their condition. Occupants may fall asleep, look away, or experience abnormal heart rates while in the vehicle. The occupant monitoring device 31 may monitor biological information corresponding to these conditions in real time based on images captured by the in-vehicle camera 30. If the automobile 2 is equipped with a millimeter-wave sensor that outputs millimeter waves toward the interior of the vehicle, the occupant monitoring device 31 may use the images captured by the in-vehicle camera 30 together with the occupant detection results from the millimeter-wave sensor to detect and identify occupants in the automobile 2 and monitor their condition.

[0031] The vehicle display device 32 and the vehicle operation device 33 constitute an HMI (Human Machine Interface) for the passengers in the automobile 2. The vehicle display device 32 may be, for example, a liquid crystal monitor. The vehicle display device 32 may be arranged in front of the driver or on the center console in the passenger compartment of the automobile 2. The vehicle display device 32 displays a screen for the occupants. The display screen of the vehicle display device 32 may, for example, be a setting screen for setting the automobile 2, a navigation screen, a meter screen showing the status of the automobile 2, a connection screen for network services, a screen for providing network services, etc. The vehicle operation device 33 may be, for example, a touch panel overlaid on a liquid crystal monitor. The vehicle operation device 33 may also include, for example, buttons, a pointing device, or a keypad. When a non-contact HMI is configured, the vehicle operation device 33 may detect an operation based on the movement of the occupant in the image captured by the in-vehicle camera 30. The occupant may operate the vehicle operation device 33 to, for example, display a setting screen on the vehicle display device 32, and set an initial screen or screen transitions for the vehicle display device 32 on the setting screen. The occupant may also operate the vehicle operation device 33 to, for example, display a connection screen for a network service on the vehicle display device 32, and input account information on the connection screen.

[0032] The vehicle setting device 34 executes settings for each part of the automobile 2 according to the occupant. For example, when an occupant gets into the automobile 2 and performs a setting operation on a setting screen or the like, the vehicle setting device 34 acquires the setting information and executes the setting for the automobile 2. The vehicle setting device 34 may acquire information previously set by the occupant from the vehicle ECU 21 or the like and execute the setting for the automobile 2. Examples of settings that an occupant can set for the automobile 2 when getting into the automobile include the seat position, steering position, mirror position, display settings, operation settings, navigation settings, and driving settings.

[0033] The vehicle memory 22 stores programs and data. The data stored in the vehicle memory 22 may include various setting information set by the occupant using the vehicle operation device 33, navigation data, and the like. In this case, the vehicle memory 22 may be configured with a non-volatile memory that can retain data when not powered, such as an HDD or SSD. The vehicle memory 22 may also temporarily store communication data transmitted and received by the mobile communication device 25, the short-range communication device 26, and the like.

[0034] The vehicle ECU 21 may be, for example, a microcomputer, which reads and executes a program from the vehicle memory 22. This allows the vehicle ECU 21 to function as a control unit that controls the overall operation, including driving control, of the automobile 2. The microcomputer may have integrated therein functions such as the vehicle memory 22 and the vehicle timer 23. The vehicle ECU 21 as a control unit of the automobile 2 controls the traveling of the automobile 2 by automatic driving or the like. The vehicle ECU 21 may generate setting information based on setting operations performed by the occupant on the automobile 2, for example, using the vehicle display device 32 and the vehicle operation device 33, and record the information in the vehicle memory 22. In this case, the vehicle ECU 21 can read out the setting information recorded in the vehicle memory 22 and use the vehicle setting device 34 to perform setting on each part of the automobile 2. If the control system 3 of the automobile 2 does not include the vehicle setting device 34 as a setting execution module, the vehicle ECU 21 may perform setting on each part of the automobile 2 by itself. This eliminates the need for the occupant to perform setting operations by themselves every time they get in the vehicle.

[0035] FIG. 3 is an explanatory diagram of a computer device 40 that can be used as the occupant information server device 4 of FIG. The computer device 40 in FIG. 3 includes a communication device 41, a display device 42, an operation device 43, a GNSS receiver 44, a CPU 45, a timer 46, and a memory 47. The plurality of service providing devices 9 to 11 in FIG. 1 may also be realized by a computer device 40 similar to that in FIG.

[0036] The communication device 41 is connected to the communication network 8. The communication device 41 transmits and receives communication data of the computer device 40. The display device 42 is, for example, a liquid crystal monitor, and displays a screen to the operator of the computer device 40 . The operation device 43 is, for example, a keyboard or a pointing device, and is operated by an operator of the computer device 40 . The GNSS receiver 44 receives radio waves from GNSS satellites and generates the location where the computer device 40 is installed and the current time. The timer 46 measures time or the time of day. The time of the timer 46 may be calibrated by the current time of the GNSS receiver 44. The memory 47 is, for example, a non-volatile memory, and stores programs and data. For example, the memory 47 as the occupant information server device 4 may store programs and data for setting the automobile 2. The CPU 45 is, for example, a microcomputer, which reads and executes a program from the memory 47. This allows the CPU 45 to function as a control unit that controls the overall operation of the computer device 40.

[0037] In this way, in the automobile 2 shown in Fig. 2, when a passenger in the vehicle adjusts the seat position or the like, the settings are recorded in the vehicle memory 22, and when the passenger gets in the vehicle again, the settings can be retrieved from the vehicle memory 22 and set in the automobile 2. This allows the automobile 2 to execute settings according to the passenger. The settings according to the passenger can be used in the automobile 2. However, recent automobiles 2 are equipped with advanced mobile communication devices 25, etc., and passengers in the automobiles 2 can use telematics services, content services, sales services, etc. In such a vehicle 2, after getting into the vehicle 2, the occupant will adjust the seat position to suit their physique and perform operations to connect to various network services such as telematics services. Even if the passengers get into the car 2, they will not be able to start driving immediately. In particular, when a passenger attempts to use multiple network services while in a vehicle, the passenger must perform connection operations for each of the network services that the passenger wishes to use.

[0038] As a countermeasure to such a situation, it is conceivable that the vehicle 2 records the account information for the network service for each occupant in the vehicle memory 22 of the vehicle 2 in Figure 2, and reads this information when getting in the vehicle, and then connects to the network service using the vehicle setting device 34. However, from the viewpoint of capacity limitations of the vehicle memory 22 of the automobile 2, information security, etc., it is unlikely that it is desirable to record all of the account information for network services for each occupant in the vehicle memory 22 of the automobile 2. For this reason, in this embodiment, an occupant information server device 4 is provided as shown in FIG. 1, and occupant information of multiple occupants is recorded in memory 47 of the occupant information server device 4 as shown in FIG. 3. FIG. 3 shows first occupant information and second occupant information as occupant information of multiple occupants. For occupant information that requires high security management, such as account information for a payment service, the security of the information can be improved by recording it in memory 47 of the occupant information server device 4 and not recording it in the vehicle memory 22 of the automobile 2. Occupant-specific setting information for each occupant riding in the automobile 2 may basically be recorded in the occupant information server device 4.

[0039] Furthermore, the automobile 2 can basically be shared by multiple people. Multiple occupants can ride in the automobile 2 at the same time. Depending on the riding conditions in the automobile 2, it may be preferable not to automatically set the setting information for each occupant recorded in the automobile 2 or the occupant information server device 4.

[0040] Hereinafter, a description will be given of how convenience and safety can be achieved in authentic use of the setting information for each occupant used in the automobile 2 in this embodiment.

[0041] FIG. 4 is an explanatory diagram of where the setting information for each occupant is recorded in the vehicle setting system 1 of the automobile 2 of FIG. 1, and a plurality of functions used in the vehicle setting system 1. In FIG. Figure 4 shows where the setting information for each occupant is recorded for multiple occupants using one automobile 2, and various functions for setting this information in the automobile 2 according to the occupants on board.

[0042] 4, the vehicle memory 22 of the automobile 2 stores first occupant information 51, second occupant information 52, and n-th occupant information 53 as occupant information for each of a plurality of occupants. In addition to this, for example, the vehicle memory 22 stores vehicle identification information 54 that is different for each automobile 2. For example, the first occupant information 51 for the first occupant includes vehicle setting information that the first occupant has set for himself or herself in the automobile 2, as well as authentication information such as occupant identification information assigned to the first occupant by the occupant monitoring device 31 of the automobile 2, occupant biometric information indicating physical characteristics of the first occupant's head, etc., and identification information of the occupant terminal 5 used by the first occupant (hereinafter referred to as occupant terminal information). Occupant information for other occupants, such as second occupant information 52 for the second occupant and nth occupant information 53 for the nth occupant, also includes vehicle setting information, occupant identification information, occupant biometric information, and occupant terminal information. By recording the vehicle setting information for each occupant using the automobile 2 in the vehicle memory 22 of the automobile 2 in this way, the automobile 2 can execute setting control according to the occupant riding in the automobile 2 even in a situation where communication with the outside is not possible. The vehicle memory 22 serves as a vehicle recording unit and records the setting information for each occupant riding in the automobile 2 in the occupant information for each of a plurality of occupants.

[0043] In the memory 47 of the occupant information server device 4, first occupant information 56, second occupant information 57, and n-th occupant information 58 are recorded as occupant information for each of a plurality of occupants. For example, the first occupant information 56 for the first occupant includes occupant-specific setting information such as payment account information, first service account information, and second service account information used by the first occupant, as well as occupant identification information for the first occupant, occupant biometric information for the first occupant, and vehicle identification information for the automobile 2 used by the first occupant. The first service account information corresponds to the service authentication information 63 of the first occupant recorded in the memory 47 of the first service providing device 9 for authenticating the first occupant. The second service account information corresponds to the service authentication information 62 of the first occupant recorded in the memory 47 of the second service providing device 10 for authenticating the first occupant. The first occupant information 56 may also include occupant-specific vehicle setting information such as the seat position of the automobile 2. Occupant information for other occupants, such as second occupant information 57 for the second occupant and nth occupant information 58 for the nth occupant, also includes occupant-specific setting information, occupant identification information, occupant biometric information, and vehicle identification information. Occupant information for other occupants may include occupant-specific vehicle setting information regarding the seat position of the automobile 2, etc. The memory 47 of the mth service providing device 11 stores service authentication information 61 of the second occupant for authenticating the second occupant. In this case, the occupant-specific setting information of the second occupant information may include mth service account information corresponding to the service authentication information 61 of the second occupant of the mth service providing device 11. Based on the authentication, the mth service providing device 11 provides service information to the second occupant and does not provide service information to, for example, the first occupant. The first occupant does not use the service of the mth service providing device 11.

[0044] Here, the vehicle setting information recorded in the memory 47 of the occupant information server device 4 matches the vehicle identification information recorded in the vehicle memory 22 of the automobile 2. The occupant identification information and occupant biometric information recorded for each occupant in the memory 47 of the occupant information server device 4 for authentication may correspond to the occupant identification information and occupant biometric information recorded for each occupant in the vehicle memory 22 of the automobile 2. When authentication is performed based on a match between the occupant identification information and the occupant biometric information, these pieces of information match. In this case, the occupant biometric information functions as a password. In this way, the memory 47 of the occupant information server device 4 serves as a server recording unit of the server device and records the setting information for each occupant who gets into the automobile 2 in the occupant information for each of the multiple occupants. Furthermore, the vehicle setting information for each occupant that can be recorded in the first occupant information 56, the second occupant information 57, the nth occupant information 58, etc. in the memory 47 of the occupant information server device 4 basically only needs to match the vehicle setting information for each occupant for the corresponding occupant in the vehicle memory 22 of the automobile 2, but may also be different from the vehicle memory 22. Such different vehicle setting information may be, for example, vehicle setting information recommended for each occupant based on statistical data on the occupant's physique, age, etc. In this way, the memory 47 serving as the server recording unit of the occupant information server device 4 records setting information such as the occupant's vehicle setting information that is set in the automobile 2 according to the occupant, and account information for network services that the occupant can use in the automobile 2.

[0045] 4, the vehicle setting system 1 mainly implements a biometric authentication unit 71, a device authentication unit 72, a media connection unit 73, a combination authentication unit 74, and a setting unit 75 by executing a program in each device. In this embodiment, of these multiple functions, the biometric authentication unit 71, the device authentication unit 72, the media connection unit 73, and the setting unit 75 are implemented by the vehicle ECU 21 of the control system 3 of the automobile 2. The remaining function, the combination authentication unit 74, is implemented by the CPU 45 of the occupant information server device 4. The multiple functions of the vehicle setting system 1 may be appropriately allocated between the vehicle ECU 21 of the control system 3 of the automobile 2 and the CPU 45 of the occupant information server device 4 depending on the system specifications, design concept, etc.

[0046] The biometric authentication unit 71 serves as a first authentication unit and performs biometric authentication on multiple occupants riding in the automobile 2. The biometric authentication unit 71 acquires wide-angle captured images of multiple occupants riding in the automobile 2, for example, using the in-vehicle camera 30 of the automobile 2, extracts physical features of the multiple occupants' heads and the like contained in the acquired information, and compares the extracted physical features with occupant biometric information of the multiple occupants pre-registered in the vehicle memory 22. The occupant biometric information registered in the vehicle memory 22 may be, for example, a captured image of the occupant's face when registering the occupant in the automobile 2. The captured image may include information such as facial features and head vein patterns. If there is occupant biometric information that matches the captured image of the occupant riding in the automobile 2 to a certain degree or higher, the biometric authentication unit 71 authenticates the occupant corresponding to the occupant biometric information as an occupant riding in the automobile 2. When the occupant biometric information of multiple occupants recorded in the vehicle memory 22 is the vein pattern of each occupant's head or part thereof, the biometric authentication unit 71 is less susceptible to the influence of differences in head orientation, and is more likely to correctly authenticate the occupants riding in the automobile 2. Then, the biometric authentication unit 71 outputs the biometric authentication results for the multiple occupants riding in the automobile 2 to the media connection unit 73. In this way, the biometric authentication unit 71 can authenticate the passengers in the automobile 2.

[0047] The device authentication unit 72 authenticates devices carried by multiple occupants aboard the automobile 2. The device authentication unit 72 acquires, for example, using the short-range communication device 26 or the key proximity sensor 27 of the automobile 2, identification information of multiple occupant terminals 5 connected via wireless communication by the short-range communication device 26, and compares the identification information with the occupant terminal information of multiple occupants recorded in the vehicle memory 22. If the identification information of the occupant terminal 5 matches the occupant terminal information, the device authentication unit 72 may authenticate the occupant corresponding to the occupant terminal information as an occupant aboard the automobile 2. In this case, the device authentication unit 72 may determine whether the occupant terminal 5 is located inside the automobile based on information such as the communication response speed between the short-range communication device 26 and the occupant terminal 5, and may authenticate only the occupant terminal 5 located inside the automobile as an occupant aboard the automobile 2. The device authentication unit 72 then outputs device authentication results for the occupant terminals 5 of the multiple occupants aboard the automobile 2 to the media connection unit 73. In this way, the device authentication unit 72 can authenticate the occupant in the vehicle.

[0048] The media connection unit 73 uses the mobile communication device 25 to connect the automobile 2 to various server devices connected to the communication network 8, and executes communication with the server devices. The media connection unit 73 uses, for example, the mobile communication device 25 to connect the automobile 2 to the occupant information server device 4, etc., and executes data communication with the occupant information server device 4. The media connection unit 73 may connect the automobile 2 to the occupant information server device 4, for example, when a biometric authentication result indicating that authentication has been performed is obtained from the biometric authentication unit 71. The media connection unit 73 obtains, for example, from the vehicle memory 22 of the automobile 2, information necessary for connection authentication by the CPU 45 of the occupant information server device 4 for the occupants on board, and transmits the information to the combination authentication unit 74 of the media connection unit 73.

[0049] The combination authentication unit 74, as a second authentication unit, authenticates the combination of multiple occupants aboard the automobile 2 and the automobile 2. For example, the combination authentication unit 74 compares information transmitted from the media connection unit 73 of the automobile 2 for connection authentication with information recorded in the memory 47 of the occupant information server device 4 for connection authentication of the multiple occupants. The information transmitted from the automobile 2 for connection authentication may include, for example, wide-angle captured images of the multiple occupants aboard the automobile 2 or biometric information of the multiple occupants based thereon, and vehicle identification information of the automobile. The combination authentication unit 74 may approve the connection if the information for the combination of at least one occupant and the vehicle matches. If the combination authentication unit 74 approves the connection, it notifies the setting unit 75 of the connection approval via the media connection unit 73 of the automobile 2. The notification of connection approval may include the combination authentication result for each of the multiple occupants. Here, the information that the media connection unit 73 transmits to the occupant information server device 4 for connection authentication is generally considered to be the occupant identification information and password of the occupant who has been biometrically authenticated or device authenticated. However, in this embodiment, the vehicle identification information 54 of the approved vehicle 2 is also transmitted as information necessary for connection authentication. This allows the combination authentication unit 74 of the occupant information server device 4 to not only authenticate that the connection is for a registered, authorized occupant, but also authenticate that the authorized occupant is attempting to connect from the authorized vehicle 2. The occupant information server device 4 can authenticate the combination of the authorized occupant and the authorized vehicle 2 using the combination authentication unit 74. Furthermore, the occupant information server device 4 can authenticate that the connection is from the correct, authorized vehicle 2 according to the vehicle identification information 54. Even if an authorized occupant attempts connection authentication via an unregistered route from a vehicle 2 with vehicle identification information that is not registered in the occupant information 56 to 58 recorded in the memory 47 of the occupant information server device 4, the authorized occupant will not be authenticated by the occupant information server device 4, as with other occupants. The occupant information 56-58 for each occupant registered in the memory 47 of the occupant information server device 4 is not inadvertently transmitted to the vehicle 2 and leaked even during legitimate processing, and is permitted to be used only within the limited range of the vehicle 2 in which it is registered together with the occupant. Note that the occupant information 56-58 for each occupant may also register vehicle identification information for multiple vehicles 2 used by each occupant. In this way, the combination authentication unit 74, as a second authentication unit, can authenticate the combination of multiple occupants authenticated by the biometric authentication unit 71 that authenticates only occupants and the vehicle that authenticated the multiple occupants.

[0050] The setting unit 75 performs settings for the automobile 2 according to the multiple occupants aboard the automobile 2. The settings for the automobile 2 may include, for example, settings for driving for each occupant, such as seat position, and settings for network services used by each occupant in the automobile 2, as illustrated in FIG. 2 . When the setting unit 75 obtains connection approval through combination authentication from the combination authentication unit 74, it receives and obtains occupant-specific setting information for the multiple occupants related to the connection approval from the occupant information 56-58 recorded in the memory 47 of the occupant information server device 4. The multiple occupant-specific setting information obtained from the occupant information server device 4 may include, for example, account information for network services for the multiple occupants. In addition, the multiple occupant-specific setting information obtained from the occupant information server device 4 may include, for example, vehicle setting information for the multiple occupants. In addition, when the setting unit 75 obtains connection approval from the combination authentication unit 74, or when an occupant is authenticated by the device authentication unit 72 or the biometric authentication unit 71, it obtains occupant-specific setting information for the multiple occupants related to the approval from the occupant information 51 to 53 recorded in the vehicle memory 22 of the automobile 2. Then, based on the acquired setting information, the setting unit 75 uses the vehicle setting device 34 to set each part of the automobile 2. The setting unit 75 sets, for example, the seat positions of the multiple occupants, the steering position, the mirror positions, the display settings, the operation settings, the navigation settings, the driving settings, etc. This allows the multiple occupants in the automobile 2 to have an optimal riding environment, and for example, they can operate the steering wheel while seated in the seats in an optimal position. Furthermore, if account information for a network service has been acquired as setting information for each occupant, the setting unit 75 causes the media connection unit 73 to execute a connection to a service providing device that provides that network service. Based on a connection instruction from the setting unit 75, the media connection unit 73 transmits the account information from the mobile communication device 25 to the service providing device. The service providing device compares the received account information with the occupant authentication information, and approves the connection if they match. By connecting the media connection unit 73 to the service providing device, the control system 3 of the automobile 2 can send and receive data to and from multiple service providing devices that provide network services to multiple occupants via the mobile communication device 25. With such settings, the setting unit 75 can set up the automobile 2 according to the authenticated multiple occupants and set up connections to network services that the authenticated multiple occupants use in the automobile 2. The setting unit 75 automatically executes the settings based on the authentication of the multiple occupants riding in the automobile 2. The multiple occupants can obtain an optimal riding environment and start driving immediately without having to operate the vehicle operation device 33 themselves.

[0051] FIG. 5 is a flowchart of setting control according to the passengers riding in the automobile 2 by the control system 3 of the automobile 2 of FIG. The vehicle ECU 21 of the control system 3 of the automobile 2 repeatedly executes the setting control of FIG. The vehicle ECU 21 can execute, for example, a plurality of functions assigned to the automobile 2 in FIG. 4 through the setting control in FIG. Here, it is assumed that the automobile 2 has a plurality of occupants on board.

[0052] In step ST1, the vehicle ECU 21 determines whether a new occupant has entered the automobile 2 or whether the automobile 2 has been started with an occupant in it. The vehicle ECU 21 may determine whether a new occupant has entered the automobile 2 based on, for example, door opening / closing detection by the door opening / closing sensor 28, new detection of the occupant terminal 5 by the short-range communication device 26, or new detection of the occupant key 6 by the key approach sensor 27.

[0053] In step ST2, the vehicle ECU 21 uses the mobile communication device 25 to inquire about the registration status of the occupant information server device 4, and acquires from the occupant information server device 4 whether or not the vehicle itself has server registration information.

[0054] In step ST3, the vehicle ECU 21 determines whether information related to the vehicle is registered in the server registration information acquired from the occupant information server device 4. If information related to the vehicle is registered in the occupant information server device 4, the vehicle ECU 21 proceeds to step ST4. If information related to the vehicle is not registered in the occupant information server device 4, the vehicle ECU 21 proceeds to step ST17.

[0055] In step ST4, the vehicle ECU 21 acquires the occupant authentication results for the multiple occupants currently riding in the automobile 2. The biometric authentication unit 71 compares the physical features of each occupant in the automobile 2 obtained from the captured image with the occupant biometric information registered in the plurality of occupant information 51 to 53 in the vehicle memory 22, and determines whether each occupant in the automobile 2 is registered in the vehicle memory 22. If each occupant in the automobile 2 is registered in the vehicle memory 22, the biometric authentication unit 71 authenticates the occupant as registered. The biometric authentication unit 71 performs biometric authentication on all of the plurality of occupants in the automobile 2. The device authentication unit 72 compares the identification information of the occupant terminals 5 or the occupant keys 6 of the multiple occupants in the automobile 2 with the occupant terminal information registered in the multiple occupant information 51 to 53 in the vehicle memory 22. The device authentication unit 72 determines whether the occupant terminals 5 or the occupant keys 6 of each occupant in the automobile 2 are registered in the vehicle memory 22. If each occupant in the automobile 2 is registered in the vehicle memory 22, the device authentication unit 72 authenticates the occupant as registered. The device authentication unit 72 performs device authentication on all occupant terminals 5 or occupant keys 6 of the multiple occupants in the automobile 2. The vehicle ECU 21 may acquire occupant authentication results for multiple occupants riding in the automobile 2 from the biometric authentication unit 71 and the device authentication unit 72.

[0056] In step ST5, the vehicle ECU 21 determines whether the acquired occupant authentication result includes a biometric authentication result for at least one occupant. Here, the vehicle ECU 21 may determine whether the acquired occupant authentication result includes a biometric authentication result for the driver or the owner of the automobile 2 as the at least one occupant. If the biometric authentication unit 71 has authenticated at least one of the authenticated occupants as registered, the vehicle ECU 21 determines that the acquired occupant authentication result includes a biometric authentication result regardless of the authentication result of the device authentication unit 72, and proceeds to step ST6. If the biometric authentication unit 71 has not authenticated any of the authenticated occupants as registered, the vehicle ECU 21 determines that the acquired occupant authentication result does not include a biometric authentication result, and proceeds to step ST15.

[0057] In step ST6, the vehicle ECU 21 acquires new biometric information for each of the multiple occupants from the occupant monitoring device 31 or the in-vehicle camera 30, which serves as a biometric information acquisition unit that acquires the biometric information of the multiple occupants. The biometric information acquired by the vehicle ECU 21 in step ST6 is different from the biometric information at the time of the biometric authentication acquired in step ST4. The biometric information in step ST6 is a wide-angle image captured by the in-vehicle camera 30 at a timing later than the biometric information in step ST4, or biometric information generated by the occupant monitoring device 31 for a wide-angle image captured at a timing later. By using two-step authentication based on different biometric information, the overall accuracy of biometric authentication can be improved even if the accuracy of each authentication step is reduced.

[0058] In step ST7, the vehicle ECU 21 acquires, from the occupant information 51 to 53 in the vehicle memory 22, the occupant identification information of each occupant who has been biometrically authenticated.

[0059] In step ST8, the vehicle ECU 21 acquires the vehicle identification information 54 of the vehicle itself from the vehicle memory 22.

[0060] In step ST9, the vehicle ECU 21 transmits the combination information of the multiple occupants and the automobile 2 acquired in steps ST7 and ST8 to the occupant information server device 4 via the base station 7 and the communication network 8 using the mobile communication device 25. The occupant information server device 4 compares the received combination information with the combinations of multiple occupant information 56-58 registered for combination authentication in the memory 47 of the occupant information server device 4 using the combination authentication unit 74. In the memory 47 of the occupant information server device 4, the occupant identification information, occupant biometric information, and vehicle identification information may be registered for combination authentication in the occupant information 56-58 of each of the multiple occupants. In this case, the combination authentication unit 74 may authenticate the combination of each of the multiple occupants and the automobile 2 for all occupants. If the received combination information is registered in the memory 47 of the occupant information server device 4, the combination authentication unit 74 of the occupant information server device 4 authenticates it and ultimately transmits the authentication result for the combination of multiple occupants and the vehicle 2 to the vehicle 2 via the communication device 41, the base station 7 and the communication network 8.

[0061] In step ST10, the vehicle ECU 21 receives and acquires the authentication result by the combination authentication unit 74 regarding the combination information of the plurality of occupants and the automobile 2 from the occupant information server device 4 via the mobile communication device 25.

[0062] In step ST11, the vehicle ECU 21 determines whether the combination of multiple occupants and the vehicle 2 has been authenticated by the combination authentication unit 74 in the occupant information server device 4. If the combination of multiple occupants and the vehicle 2 has been authenticated in the occupant information server device 4, the vehicle ECU 21 proceeds to step ST12. If the combination of multiple occupants and the vehicle 2 has not been authenticated in the occupant information server device 4, the vehicle ECU 21 proceeds to step ST15.

[0063] In step ST12, the vehicle ECU 21 acquires occupant-specific setting information for the authenticated occupants from the occupant information 56-58 stored in the memory 47 of the occupant information server device 4 and the occupant information 51-53 stored in the vehicle memory 22 of the vehicle itself. The vehicle ECU 21 uses the mobile communication device 25 to request the occupant information server device 4 to transmit setting information, and receives and acquires the occupant-specific setting information for the authenticated occupants from the occupant information server device 4. The vehicle ECU 21 reads and acquires the occupant-specific setting information for the authenticated occupants from the vehicle memory 22. Here, the vehicle ECU 21 may, for example, acquire occupant-specific setting information for each occupant whose combination has been authenticated mainly from the memory 47 of the occupant information server device 4. Then, if the setting information acquired from the memory 47 of the occupant information server device 4 does not include vehicle setting information, the vehicle ECU 21 may acquire occupant-specific setting information for that occupant from the plurality of occupant information 51-53 in the vehicle memory 22 of the vehicle itself. In this case, the vehicle ECU 21 acquires occupant-specific setting information for each occupant whose combination has been authenticated from at least the memory 47 of the occupant information server device 4 among the memory 47 of the occupant information server device 4 and the vehicle memory 22 of the automobile 2.

[0064] In step ST13, the vehicle ECU 21 executes settings for the vehicle based on the vehicle setting information included in the acquired setting information for each occupant, using the vehicle setting device 34. As a result, the seat positions of the authenticated occupants can be set to correspond to the vehicle setting information.

[0065] In step ST14, the vehicle ECU 21 connects the vehicle to the network service via the mobile communication device 25, using the account information for the network service included in the acquired occupant-specific setting information. As a result, the vehicle ECU 21 is connected to a service providing device that provides the network service via the mobile communication device 25, and becomes able to receive service information from the service providing device. Thereafter, the vehicle ECU 21 ends this control.

[0066] In step ST15, since the combination has not been authenticated by the combination authentication unit 74 of the occupant information server device 4, the vehicle ECU 21 stops acquiring information from the occupant information server device 4 and acquires occupant-specific setting information for the authenticated occupants from the multiple occupant information 51-53 in the vehicle memory 22 of the vehicle itself. The authentication here is not limited to that performed by the biometric authentication unit 71, and may include that performed by the device authentication unit 72. When multiple occupants have been authenticated by at least one of the biometric authentication unit 71 and the device authentication unit 72, the vehicle ECU 21 may acquire occupant-specific setting information for each of the authenticated occupants.

[0067] In step ST16, the vehicle ECU 21 executes the setting of the vehicle based on the vehicle setting information included in the setting information for each occupant acquired from the vehicle memory 22. As a result, the seat positions of the authenticated occupants can be set to correspond to the vehicle setting information. After that, the vehicle ECU 21 ends this control.

[0068] In step ST17, the vehicle ECU 21 acquires the biometric authentication results for the multiple occupants in the automobile 2. In this case, since information related to the vehicle is not registered in the occupant information server device 4, the vehicle ECU 21, unlike step ST4, acquires only the biometric authentication result from the biometric authentication unit 71 from the authentication result from the biometric authentication unit 71 and the authentication result from the device authentication unit 72. Thereafter, the vehicle ECU 21 proceeds to step ST15. The vehicle ECU 21 acquires occupant-specific setting information for the plurality of biometrically authenticated occupants from the plurality of occupant information 51-53 stored in the vehicle memory 22 of the vehicle, and executes settings for the vehicle based on the acquired vehicle setting information. As a result, the seat positions of the plurality of biometrically authenticated occupants can be set to correspond to the vehicle setting information. Thereafter, the vehicle ECU 21 ends this control.

[0069] 5, when multiple occupants are biometrically authenticated by the biometric authentication unit 71, the vehicle ECU 21 transmits combination information of the multiple occupants and the vehicle 2 to the occupant information server device 4. The combination authentication unit 74 of the occupant information server device 4 authenticates the combination of the multiple occupants and the vehicle 2 by combining the occupant identification information for the multiple occupants biometrically authenticated by the biometric authentication unit 71 and the vehicle identification information for the authenticated vehicle 2. Furthermore, when multiple occupants have not been biometrically authenticated by the biometric authentication unit 71, the combination authentication unit 74 does not obtain the combination information of the multiple occupants and the vehicle 2 and therefore does not perform the authentication. It should be noted that two-stage authentication of the occupants of the automobile 2 can be performed without the processes from step ST1 to step ST3 described above. In addition, instead of processing steps ST1 to ST3, the vehicle ECU 21 may, for example, determine whether or not connection information to the occupant information server device 4 is present in the vehicle memory 22, and if the connection information is present, proceed to step ST4, or if the connection information is not present, proceed to step ST17.

[0070] FIG. 6 is a timing chart of setting control when an occupant undergoes two-stage authentication in the vehicle setting system 1 of the automobile 2 of FIG. The timing chart of the setting control in FIG. 6 is an example in which the occupant in the automobile 2 has been biometrically authenticated. 6 shows a biometric authentication unit 71, a device authentication unit 72, a media connection unit 73, and a setting unit 75, which are implemented in the vehicle ECU 21 of the automobile 2, as well as a combination authentication unit 74, which is implemented in the CPU 45 of the occupant information server device 4. In FIG. 6, time flows from top to bottom. The following describes an example of a state in which multiple occupants, including a first occupant, are riding in the automobile 2. The description also assumes that the vehicle ECU 21 of the automobile 2 mainly functions as the media connection unit 73 and executes the setting process of FIG.

[0071] 5 , the vehicle ECU 21 serving as the media connection unit 73 of the automobile 2 acquires the occupant authentication results from the biometric authentication unit 71 and the device authentication unit 72 for multiple occupants, including the first occupant, riding in the automobile 2, and determines in step ST5 that the occupant authentication results include, for example, the biometric authentication result of the driver. In this case, in steps ST6 to ST9, the vehicle ECU 21 serving as the media connection unit 73 acquires occupant identification information, new biometric information, and vehicle identification information 54 for multiple occupants, including the first occupant, riding in the automobile 2, from the first occupant information 51 in the vehicle memory 22, etc., and transmits these to the occupant information server device 4. When the communication device 41 of the occupant information server device 4 receives the combination information, the combination authentication unit 74 compares the received combination information with the multiple occupant information 56 to 58 in the memory 47 of the occupant information server device 4 in step ST21, and authenticates the combination of the multiple occupants with the automobile 2. The combination authentication unit 74 may authenticate the combination of each of the multiple occupants and the automobile 2 based on biometric information obtained at a timing different from the biometric information used for authentication by the biometric authentication unit 71. The combination authentication unit 74 then transmits an authentication result of the combination, indicating that the multiple occupants including the first occupant are registered multiple occupants, to the setting unit 75 of the automobile 2. The authentication result is transmitted from the communication device 41 of the occupant information server device 4 to the automobile 2 via the communication network 8 and the base station 7.

[0072] In the automobile 2, in step ST10, the vehicle ECU 21 serving as the media connection unit 73 receives the authentication result by the combination authentication unit 74 regarding the combination information of the plurality of occupants and the automobile 2 from the occupant information server device 4 via the mobile communication device 25. The vehicle ECU 21 serving as the media connection unit 73 of the automobile 2 instructs the setting unit 75 to perform setting. In steps ST12 to ST14, the vehicle ECU 21 serving as the setting unit 75 acquires occupant-specific setting information for a plurality of occupants including the first occupant from the plurality of occupant information 56-58 in the occupant information server device 4 and the plurality of occupant information 51-53 in the vehicle memory 22, sets the information in the host vehicle, and connects to the network service. In this case, even if the setting unit 75 has acquired various settings for vehicle setting information for each occupant from the occupant information server device 4, the setting unit 75 may prioritize the corresponding settings in the vehicle memory 22 and set them in the vehicle. Furthermore, if the setting unit 75 is unable to acquire settings from the vehicle memory 22, the setting unit 75 may acquire vehicle setting information from the occupant information server device 4 and set it in the vehicle.

[0073] In this way, when the combination authentication unit 74 has authenticated the combination of multiple occupants, including the first occupant, with the automobile 2, the setting unit 75 can obtain occupant-specific setting information for multiple occupants, including the first occupant, from the multiple occupant information 56 to 58 in the memory 47 (server recording unit) of the occupant information server device 4, and perform the setting in the vehicle. For example, if the occupant-specific setting information for the first occupant recorded in memory 47 of the occupant information server device 4 includes the occupant's vehicle setting information to be set in the automobile 2 according to the occupant, and the combination is authenticated, the setting unit 75 can perform setting in the automobile 2 using the vehicle setting information recorded in memory 47 of the occupant information server device 4. In addition, for example, if the occupant-specific setting information for the first occupant recorded in memory 47 of the occupant information server device 4 includes account information for a network service that the occupant can use in the automobile 2 and the combination is authenticated, the setting unit 75 can connect the automobile 2 to the network service using the account information for the network service from memory 47 of the occupant information server device 4.

[0074] Furthermore, when multiple occupants including the first occupant are biometrically authenticated by the biometric authentication unit 71 of the automobile 2, and the combination of multiple occupants including the first occupant and the automobile 2 is further authenticated by the combination authentication unit 74, the setting unit 75 can obtain vehicle setting information for multiple occupants including the first occupant from the multiple occupant information 56 to 58 in the memory 47 of the occupant information server device 4 and the multiple occupant information 51 to 53 in the vehicle memory 22 as a vehicle recording unit, and perform setting on the automobile 2. In addition, if the biometric authentication unit 71 has authenticated multiple occupants including the first occupant, but the combination authentication unit 74 has not authenticated the combination of the multiple occupants including the first occupant and the automobile 2, the setting unit 75 can obtain vehicle setting information for the multiple occupants including the first occupant only from the multiple occupant information 51 to 53 in the vehicle memory 22 as a vehicle recording unit, and perform setting on the automobile 2.

[0075] FIG. 7 is an explanatory diagram of an example of authentication information 100 for combination of the vehicle 2 and a plurality of occupants riding in the vehicle 2, which is transmitted from the vehicle 2 to the occupant information server device 4 in step ST6 of FIG. The combined authentication information 100 in FIG. 7 has a header and a payload. The payload may be of fixed length or variable length. The payload includes vehicle identification information for the automobile 2, as well as information slots for each occupant for the number of people who can ride in the automobile 2. The order of the multiple information slots in the payload is the order in which the seating positions in the automobile 2 are designated, which in this case is the driver, front passenger, and other multiple rear seat passengers. The information slot for each occupant includes their own occupant identification information and occupant biometric information based on their captured image. The driver's information slot may be the information slot for the owner of the automobile 2. The information slot for the owner of the automobile 2 may be provided separately from that shown in FIG. 7. When at least one of the multiple occupants on board has been biometrically authenticated by the biometric authentication unit 71, the media connection unit 72 acquires information about the biometrically authenticated occupant from the vehicle memory 22 and the in-vehicle camera 30 in steps ST6 to ST8, generates the combined authentication information 100 shown in Figure 7, and transmits it from the mobile communication device 25 to the occupant information server device 4 in step ST9. Here, the media connection unit 72 determines the riding position of each occupant in the automobile 2 based on the wide-angle captured image, and includes information about the occupant authenticated by the biometric authentication unit 71 in the information slot for that riding position. The media connection unit 72 does not need to include information about the occupant in the information slot for the riding position of an occupant who has not been authenticated by the biometric authentication unit 71. In addition, the media connection unit 72 does not need to include information about the occupant in the information slot for a riding position where no occupant is riding. The occupant information server device 4 receives the combination authentication information 100 of FIG. 7 via the communication device 41 and authenticates the combination of multiple occupants and the vehicle 2 via the combination authentication unit 74. The combination authentication unit 74 may individually authenticate the combination of each occupant and vehicle 2 whose information is included in the combination authentication information 100 of FIG. 7. In this case, the combination authentication unit 74 may determine the seating position of each occupant related to the combination authentication based on the order of each information slot in the combination authentication information 100 of FIG. 7, and authenticate the combination based on the degree of match according to the seating position. After completing the individual authentication for all multiple occupants whose information is included in the combination authentication information 100 of FIG. 7, the combination authentication unit 74 transmits a combination authentication result including all the individual authentication results from the communication device 41 to the vehicle 2. In the vehicle 2, the media connection unit 72 can obtain the combination authentication results of the multiple occupants and the vehicle 2 via the mobile communication device 25. The information of the combination authentication result may correspond to that shown in FIG. 7. In this case, the information slot for each occupant may include the authentication result of the combination with the automobile 2 for each occupant. In this way, the combination authentication unit 74 and the media connection unit 72 may collectively transmit and receive information relating to the combination authentication of a plurality of occupants with the automobile 2 in which they are riding.

[0076] FIG. 8 is a flowchart showing an example of detailed setting control by the setting unit 75 when a plurality of occupants have been authenticated by the combination authentication unit 74. The vehicle ECU 21 of the automobile 2 may, as the media connection unit 73, obtain the combination authentication results between multiple occupants and the automobile 2 from the combination authentication unit 74, and then, as the setting unit 75, execute the setting control of Figure 8, for example, in steps ST13, ST14 and ST16 of Figure 5 or Figure 6.

[0077] In step ST31, the vehicle ECU 21 of the automobile 2, as the setting unit 75, acquires occupant-specific setting information for the multiple occupants in the automobile 2 and starts setting the information for the vehicle. When the multiple occupants in the automobile 2 have been authenticated by the biometric authentication unit 71 and also by the combined authentication unit, the vehicle ECU 21 acquires occupant-specific setting information for the authenticated occupants from the memory 47 of the occupant information server device 4 based on the authentication results.

[0078] In step ST32, the vehicle ECU 21 determines whether or not the driver's setting information has been acquired based on the acquired occupant-specific setting information for the multiple occupants. When the vehicle ECU 21 has acquired a combined authentication result having multiple occupant-specific information slots corresponding to the combined authentication information 100 of FIG. 7, for example, the vehicle ECU 21 may determine whether or not the driver's setting information has been acquired based on whether or not the driver's information slot contains setting information. Alternatively, the vehicle ECU 21 may determine whether or not the owner's setting information has been acquired instead of the driver's setting information. If the driver's setting information has been acquired, the vehicle ECU 21 proceeds to step ST33. If the driver's setting information has not been acquired, the vehicle ECU 21 skips step ST34 and proceeds to step ST35.

[0079] In step ST33, the vehicle ECU 21 performs settings for the driver in the automobile 2 using the vehicle setting information of the driver acquired from the memory 47 of the occupant information server device 4. For example, the position of the seat where the driver sits corresponds to the driver.

[0080] In step ST34, the vehicle ECU 21 sets up a network connection for the driver using the network connection information of the driver acquired from the memory 47 of the occupant information server device 4. For example, if the driver is the first occupant, the automobile 2 is connected to the first service providing device 9 and the second service providing device 10. When there is a passenger, the vehicle ECU 21 may not automatically connect to some of the plurality of service providing devices depending on the combination of the passenger, for example.

[0081] In step ST35, the vehicle ECU 21 determines whether or not the setting information of the passenger in the front passenger seat has been acquired based on the acquired occupant-specific setting information for the multiple occupants. When the vehicle ECU 21 has acquired a combined authentication result having information slots for multiple occupants corresponding to the combined authentication information 100 in FIG. 7, for example, the vehicle ECU 21 may determine whether or not the setting information of the passenger in the front passenger seat has been acquired based on whether or not the setting information is included in the information slot for the passenger in the front passenger seat. If the setting information of the passenger in the front passenger seat has been acquired, the vehicle ECU 21 proceeds to step ST36. If the setting information of the passenger in the front passenger seat has not been acquired, the vehicle ECU 21 proceeds to step ST39.

[0082] In step ST36, the vehicle ECU 21 performs settings for the passenger in the passenger seat on the automobile 2 using the vehicle setting information for the passenger in the passenger seat acquired from the memory 47 of the occupant information server device 4. For example, the position of the passenger seat corresponds to the passenger in the passenger seat.

[0083] In step ST37, the vehicle ECU 21 determines whether to set up a network connection for the passenger in the front passenger seat. The vehicle ECU 21 may, for example, display a selection screen on the vehicle display device 32 for selecting whether to set up the network connection, and determine whether to set up a network connection for the passenger in the front passenger seat based on the operation of the vehicle operation device 33 by the occupant in response to the selection screen. If the network connection for the passenger in the front passenger seat is to be set up, the vehicle ECU 21 proceeds to step ST38. If the network connection for the passenger in the front passenger seat is not to be set up, the vehicle ECU 21 proceeds to step ST39.

[0084] In step ST38, the vehicle ECU 21 sets up a network connection for the passenger in the passenger seat using the network connection information for the passenger in the passenger seat acquired from the memory 47 of the occupant information server device 4. For example, if the passenger in the passenger seat is the second passenger, the automobile 2 is connected to the mth service providing device 11.

[0085] In step ST39, the vehicle ECU 21 determines whether or not setting information for a passenger other than the front passenger seat, such as a passenger in a rear seat, has been acquired based on the acquired occupant-specific setting information for the multiple occupants. When the vehicle ECU 21 has acquired a combined authentication result having information slots for multiple occupants, such as corresponding to the combined authentication information 100 in FIG. 7, the vehicle ECU 21 may determine whether or not setting information for a passenger in a rear seat has been acquired based on whether setting information is included in the information slot for the passenger in the rear seat. If setting information for a passenger in a rear seat has been acquired, the vehicle ECU 21 proceeds to step ST40. If setting information for a passenger in a rear seat has not been acquired, the vehicle ECU 21 proceeds to step ST43.

[0086] In step ST40, the vehicle ECU 21 performs settings for the rear seat passengers in the automobile 2 using the vehicle setting information for the rear seat passengers acquired from the memory 47 of the occupant information server device 4. For example, the positions of the rear seats correspond to the rear seat passengers.

[0087] In step ST41, the vehicle ECU 21 determines whether to set up a network connection for a rear seat passenger. The vehicle ECU 21 may, for example, display a selection screen on the vehicle display device 32 to select whether to set up a network connection for the rear seat passenger, and determine whether to set up a network connection for the rear seat passenger in response to an operation of the vehicle operation device 33 by the occupant. If the network connection for the rear seat passenger is to be set up, the vehicle ECU 21 proceeds to step ST42. If the network connection for the rear seat passenger is not to be set up, the vehicle ECU 21 proceeds to step ST43.

[0088] In step ST42, the vehicle ECU 21 uses the network connection information of the rear seat passenger acquired from the memory 47 of the occupant information server device 4 to set up the network connection for the rear seat passenger.

[0089] In step ST43, the vehicle ECU 21 determines whether the automatic setting for all occupants has been completed. For example, the vehicle ECU 21 may obtain a combined authentication result having information slots for multiple occupants corresponding to the combined authentication information 100 in FIG. 7, and determine whether the automatic setting for all occupants has been completed based on whether processing has been completed for all information slots containing information. If there are unprocessed information slots and the automatic setting for all occupants has not been completed, the vehicle ECU 21 determines that the automatic setting for all occupants has not been completed, and returns the process to step ST39. The vehicle ECU 21 repeats the processes from step ST39 to step ST43 until the automatic setting for all occupants has been completed. When the automatic setting for all occupants has been completed, the vehicle ECU 21 terminates this control.

[0090] As a result, the vehicle ECU 21, as the setting unit 75, can acquire and automatically set the vehicle setting information for all of the multiple occupants who have been biometrically authenticated and are recorded in the memory 47 of the occupant information server device 4 and who have been authenticated by the combination authentication unit 74. On the other hand, with regard to the network service account information for the multiple occupants who have been authenticated by the combination authentication unit 74 and recorded in the memory 47 of the occupant information server device 4, the vehicle ECU 21 can acquire and set the information for at least the occupant who is determined to be the driver based on the seating position, preferentially over that for other occupants. Note that the vehicle ECU 21 may also acquire and set the information for the occupant who is determined to be the owner of the automobile 2, rather than that for the occupant who is determined to be the driver, preferentially over that for other occupants. Furthermore, the vehicle ECU 21, as the setting unit 75, automatically acquires and sets vehicle setting information for multiple occupants that is recorded in the memory 47 of the occupant information server device 4 and is authenticated by the biometric authentication unit 71. On the other hand, the vehicle ECU 21 can acquire and set network service account information for multiple occupants that is recorded in the memory 47 of the occupant information server device 4 and is authenticated by the biometric authentication unit 71 in response to operations by the occupants aboard the automobile 2.

[0091] As described above, in this embodiment, in order for a passenger in the vehicle 2 to set and use his or her occupant-specific setting information in the vehicle 2, the passenger must be authenticated by the biometric authentication unit 71 as the first authentication unit, and the combination of the passenger and the vehicle 2 must be authenticated by the combination authentication unit 74 as the second authentication unit. By using such multi-factor and multi-stage authentication that is not based solely on the authentication of the passenger, the security of the occupant-specific setting information recorded in the memory 47 of the occupant information server device 4 is enhanced. Furthermore, the combination authentication unit 74 authenticates the combination of the passenger authenticated by the biometric authentication unit 71 and the vehicle 2 in which the passenger is riding, and therefore can also authenticate the authenticity of the routing from the vehicle 2 to the occupant information server device 4. The combination authentication unit 74 of this embodiment is considered to make it more difficult for the occupant-specific setting information of the occupant information server device 4 to be fraudulently obtained or used, compared to, for example, a case in which the occupant is authenticated by the biometric authentication unit 71 in the occupant information server device 4. The security of the occupant-specific setting information of the occupant information server device 4 is enhanced. Furthermore, a vehicle may have multiple occupants, and the biometric authentication unit 71 in this embodiment can authenticate these multiple occupants. The combination authentication unit 74 authenticates the combination of the multiple occupants authenticated by the biometric authentication unit 71 with the vehicle 2 in which they are riding. The setting unit 75 acquires occupant-specific setting information for the occupants authenticated by the combination authentication unit 74 from the memory 47 of the occupant information server device 4 in accordance with the authentication results by the biometric authentication unit 71 and the authentication results by the combination authentication unit 74 for the multiple occupants riding in the vehicle 2, and performs setting on the vehicle 2. In this embodiment, when multiple occupants ride in the vehicle 2, setting on the vehicle 2 can be performed in accordance with the authentication results by the biometric authentication unit 71 and the authentication results by the combination authentication unit 74 for the multiple occupants riding in the vehicle 2. Each occupant can enjoy the convenience of setting according to their riding environment. In this manner, in this embodiment, the setting information for each occupant used in the automobile 2 can be made more convenient for authentic use while also being more secure.

[0092] The above-described embodiment is an example of a preferred embodiment of the present invention, but the present invention is not limited to this, and various modifications and changes are possible within the scope of the gist of the invention.

[0093] For example, in the above-described embodiment, the automobile 2 is provided with a setting unit 75 that executes settings to make settings appropriate for the occupants available in the automobile 2, as well as a biometric authentication unit 71 that authenticates the occupants in the automobile 2. In addition to this, for example, the automobile 2 may be provided with a setting unit 75, a biometric authentication unit 71, and a combination authentication unit 74 that authenticates the combination of the occupant authenticated by the biometric authentication unit 71 and the automobile 2 in which they are riding. [Explanation of symbols]

[0094] 1...vehicle setting system, 2...automobile (vehicle), 3...control system, 4...occupant information server device (server device), 5...occupant terminal, 6...occupant key, 7...base station, 8...communication network, 9...first service providing device, 10...second service providing device, 11...mth service providing device, 21...vehicle ECU, 22...vehicle memory (vehicle recording unit), 23...vehicle timer, 24...vehicle GNSS receiver, 25...mobile communication device, 26...short-range communication device, 27...key approach sensor, 28...door opening / closing sensor, 29...acceleration sensor, 30...in-vehicle camera (biometric information acquisition unit), 31...occupant monitoring device (biometric information acquisition unit), 32...vehicle display device, 33...vehicle operation device, 34...vehicle setting device, 35...vehicle network, 40 ...Computer device, 41...Communication device, 42...Display device, 43...Operation device, 44...GNSS receiver, 45...CPU, 46...Timer, 47...Memory (server recording unit), 51...Setting information for first occupant, 52...Setting information for second occupant, 53...Setting information for nth occupant, 54...Vehicle identification information, 56...Setting information for first occupant, 57...Setting information for second occupant, 58...Setting information for nth occupant, 61...Service authentication information for nth occupant, 62...Service authentication information for first occupant, 63...Service authentication information for first occupant, 71...Biometric authentication unit (first authentication unit), 72...Device authentication unit (first authentication unit), 73...Media connection unit, 74...Combined authentication unit (second authentication unit), 75...Setting unit, 100...Combined authentication information

Claims

1. A vehicle setting system according to an occupant, comprising: a setting unit that executes setting of the vehicle so that a setting according to the occupant can be used in the vehicle; a server device having a server recording unit that records occupant-specific setting information for occupants riding in the vehicle; a first authentication unit that authenticates a passenger in the vehicle; a second authentication unit that authenticates a combination of the occupant authenticated by the first authentication unit and the vehicle in which the occupant is riding; and the first authentication unit is capable of authenticating a plurality of occupants riding in the vehicle; the second authentication unit authenticates a combination of the vehicle and a plurality of occupants authenticated by the first authentication unit; The setting unit acquires, from the server recording unit of the server device, setting information for each occupant authenticated by the second authentication unit, according to the authentication results by the first authentication unit and the authentication results by the second authentication unit for the multiple occupants riding in the vehicle, and executes setting for the vehicle; and when multiple occupants are authenticated by the first authentication unit, acquires information on the multiple occupants authenticated by the first authentication unit together with information on the vehicle in which they are riding, and performs combined authentication. Vehicle configuration system tailored to the occupant.

2. The setting information recorded in the server recording unit includes at least account information for network services that the occupant can use in the vehicle, and vehicle setting information for the occupant that is set in the vehicle according to the occupant; The setting unit Regarding vehicle setting information for a plurality of occupants authenticated by the second authentication unit, which is recorded in the server recording unit of the server device, acquiring and setting information for the plurality of occupants; Regarding the network service account information for the plurality of occupants authenticated by the second authentication unit, which is recorded in the server recording unit of the server device, the account information for the occupant who is determined to be the driver based on the seating position or the occupant who is determined to be the owner of the vehicle is acquired or set preferentially over that of other occupants. The vehicle occupant-dependent setting system according to claim 1.

3. the setting information recorded in the server recording unit includes at least account information for a network service that the occupant can use in the vehicle, and occupant vehicle setting information that is set in the vehicle depending on the occupant; The setting unit Vehicle setting information for the plurality of occupants authenticated by the first authentication unit, which is recorded in the server recording unit of the server device, is acquired and set for the plurality of occupants; The account information of the network service for the plurality of occupants authenticated by the first authentication unit, which is recorded in the server recording unit of the server device, is acquired or set in response to an operation by an occupant riding in the vehicle.

3. The vehicle setting system according to claim 1 or 2.

4. A wide-angle imaging device capable of imaging multiple occupants in the vehicle, the first authentication unit and the second authentication unit authenticate a plurality of occupants riding in the vehicle based on an image captured by the wide-angle imaging device; The vehicle setting system according to any one of claims 1 to 3.

5. A setting unit that performs settings on the vehicle so that settings according to the occupants can be used in the vehicle; a first authentication unit that authenticates a passenger in the vehicle; a second authentication unit that authenticates a combination of the occupant authenticated by the first authentication unit and the vehicle in which the occupant is riding; and the first authentication unit is capable of authenticating a plurality of occupants riding in the vehicle; the second authentication unit authenticates a combination of the vehicle and a plurality of occupants authenticated by the first authentication unit; The setting unit acquires occupant-specific setting information for occupants authenticated by the second authentication unit from a server recording unit of a server recording unit that records occupant-specific setting information for occupants riding in the vehicle, in accordance with the authentication results by the first authentication unit and the authentication results by the second authentication unit, and executes setting in the vehicle; and when multiple occupants are authenticated by the first authentication unit, acquires information on the multiple occupants authenticated by the first authentication unit together with information on the vehicle they are riding in, and performs combined authentication. vehicle.

Citation Information

Patent Citations

  • Control device for vehicle function

    JP2003237504A

  • Specific information management system

    JP2004243825A

  • Personal identification device and personal identification method

    JP2008059509A

  • Biometric authentication system

    JP2010146095A

  • On-vehicle device, program, and display method

    JP2014133506A