Vehicle control system, vehicle control device

The vehicle control system uses specific signals to manage responses from portable devices, preventing relay attacks and unauthorized access while ensuring user convenience, thereby enhancing security and reliability.

JP7725232B2Active Publication Date: 2025-08-19NIDEC MOBILITY CORP
View PDF 16 Cites 0 Cited by

Patent Information

Application Number
JP2021085584
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-05-20
Publication Date
2025-08-19
Estimated Expiration
2041-05-20

AI Technical Summary

Technical Problem

Existing vehicle control systems are vulnerable to relay attacks, which allow unauthorized access and theft due to complex countermeasures that can be bypassed, and methods that prevent relay attacks compromise user convenience.

Method used

A vehicle control system that uses distinct signals to indicate whether a response is required from the portable device, preventing relay attacks by ensuring the device does not transmit a response signal when unauthorized access is attempted, while allowing normal operations without additional complexity.

Benefits of technology

Effectively prevents fraudulent acts through relay attacks while maintaining user convenience by ensuring the system operates reliably without complex processing, thus enhancing security against unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007725232000001
    Figure 0007725232000001
  • Figure 0007725232000002
    Figure 0007725232000002
  • Figure 0007725232000003
    Figure 0007725232000003
Patent Text Reader

Abstract

To assure a user's convenience and reliably prevent a dishonest act using a relay attack by a simple method.SOLUTION: A vehicle control system 100 comprises a portable machine 10 possessed by a user and a vehicle control device 20 installed on a vehicle. A controller 22 of the vehicle control device 20 determines whether an operation on an operation unit 21 is an operation requiring response from the portable machine 10 or not, and transmits a first signal which announces the necessity of the response from an LF transmission unit 23 if the operation requires the response, or transmits a second signal which announces the unnecessity of the response from the LF transmission unit 23 if the operation does not require the response. The controller 12 of the portable machine 10 transmits a response signal from a UHF transmission unit 14 if an LF reception unit 13 receives the first signal, or does not transmit the response signal from the UHF transmission unit 14 if the LF reception unit 13 receives the second signal. The controller 22 of the vehicle control device 20 performs control on the vehicle depending on the operation on the operation unit 21 if a UHF reception unit 24 receives the response signal.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a control system for controlling the operation of a vehicle, and more particularly to a vehicle control system having a security function against relay attacks. [Background technology]

[0002] Vehicle control systems have been put into practical use that perform predetermined controls such as locking and unlocking vehicle doors or starting the engine based on wireless signals transmitted and received between a vehicle control device installed in a vehicle and a portable device carried by the user.

[0003] In this vehicle control system, when a user carrying a portable device performs a locking or unlocking operation using a switch provided on the door handle, a response request signal is transmitted from the vehicle control device to the portable device. When the portable device receives this response request signal, it returns a response signal including the ID of the portable device to the vehicle control device. Upon receiving the response signal, the vehicle control device verifies the ID and performs authentication, and if authentication is successful, locks or unlocks the doors. Furthermore, when the user performs a locking or unlocking operation on the portable device, an operation signal corresponding to the operation is transmitted from the portable device to the vehicle control device. This operation signal also includes the ID of the portable device. Upon receiving the operation signal, the vehicle control device verifies the ID and locks or unlocks the doors if authentication is successful.

[0004] In recent years, a fraudulent act known as a relay attack has become a problem in vehicle control systems such as those described above. A relay attack is an act of fraudulent communication in which a third party other than the owner of the vehicle uses a repeater to relay a response request signal sent from the vehicle control device or a response signal returned from the portable device, thereby making it appear as if the owner's portable device, which is located far away, is in the vicinity of the vehicle. A relay attack allows a malicious third party to unlock the vehicle doors or start the engine, which could lead to crimes such as theft of the vehicle or items inside the vehicle.

[0005] Therefore, various countermeasures to prevent such relay attacks have been proposed in the past (see, for example, Patent Documents 1 to 12). However, conventional methods require complex processing and operations to ensure thorough countermeasures against relay attacks, and if the countermeasure algorithm becomes known to a third party, the third party may be able to use the algorithm to launch a relay attack, so these methods cannot be said to be foolproof as crime prevention measures.

[0006] On the other hand, there are portable devices in practical use that have a lock button for locking and an unlock button for unlocking, and can be set to a power-saving mode by performing a specific operation using these buttons. In this portable device, all transmission and reception operations are stopped while the device is in the power-saving mode, which effectively prevents relay attacks.

[0007] However, if a driver leaves a portable device set to power-saving mode inside the vehicle and attempts to lock the doors after getting out, the vehicle control device will determine that the portable device is not inside the vehicle and will lock the doors, since the portable device will not return a response signal even if the vehicle control device sends a response request signal to the portable device. As a result, the portable device will be trapped inside the vehicle, and the driver will not be able to unlock the doors when they get in. [Prior art documents] [Patent documents]

[0008] [Patent Document 1] Japanese Patent Publication No. 2020-197083 [Patent Document 2] U.S. Patent Publication No. 2020 / 0216024 [Patent Document 3] Special Publication No. 2020-518502 [Patent Document 4] U.S. Patent Publication No. 2020 / 0193750 [Patent Document 5] Japanese Patent Application Publication No. 2018-69764 [Patent Document 6] Japanese Patent Application Publication No. 2018-71050 [Patent Document 7] Japanese Patent Application Publication No. 2018-62765 [Patent Document 8] Japanese Patent Application Publication No. 2018-62761 [Patent Document 9] Japanese Patent Application Publication No. 2018-62764 [Patent Document 10] Japanese Patent Application Publication No. 2018-62762 [Patent Document 11] Japanese Patent Application Publication No. 2018-71049 [Patent Document 12] Japanese Patent Application Laid-Open No. 2017-220759 Summary of the Invention [Problem to be solved by the invention]

[0009] An object of the present invention is to provide a vehicle control system that can reliably prevent fraudulent acts through relay attacks using a simple method while ensuring user convenience. [Means for solving the problem]

[0010] The vehicle control system according to the present invention comprises a vehicle control device mounted on a vehicle and performing predetermined control of the vehicle, and a portable device that communicates wirelessly with the vehicle control device. The portable device comprises a first operation unit that is operated to cause the vehicle to perform a predetermined operation, a first communication unit that communicates with the vehicle control device, and a first control unit that controls the first communication unit. The vehicle control device comprises a second operation unit that is operated to cause the vehicle to perform a predetermined operation, a second communication unit that communicates with the first communication unit of the portable device, and a second control unit that performs predetermined control of the vehicle based on operation of the first operation unit or the second operation unit. The second control unit controls the vehicle based on operation of the second operation unit. And , Following this operation, the second operation unit is operated as follows: Operations that require a response from the mobile device or it is an operation that does not require a response from the handheld device.and if the operation requires a response, transmits a first signal from the second communication unit notifying that a response is required, and if the operation does not require a response, transmits a second signal from the second communication unit notifying that a response is not required. The first control unit of the portable device transmits a response signal from the first communication unit when the first communication unit receives the first signal, and does not transmit a response signal from the first communication unit when the first communication unit receives the second signal. The second control unit of the vehicle control device controls the vehicle in accordance with the operation of the second operation unit when the second communication unit receives the response signal from the portable device.

[0011] According to this vehicle control system, if the operation of the second operating unit requires a response from the portable device, the portable device receives a first signal notifying the user that a response is required, and the portable device returns a response signal. However, if the operation of the second operating unit does not require a response from the portable device, the portable device receives a second signal notifying the user that a response is not required, and the portable device does not return a response signal. Therefore, if an operation that could potentially allow a third party to unlock the vehicle doors is performed, such as an unlocking operation, the vehicle control device sends a second signal to the portable device, preventing the response signal from being relayed by a relay attack, thereby reliably preventing unauthorized unlocking of the vehicle doors. On the other hand, if the operation is a locking operation that does not potentially allow a third party to unlock the vehicle doors, the vehicle control device sends a first signal to the portable device, and the portable device returns a response signal. Therefore, even if the user leaves the portable device inside the vehicle and attempts to lock the doors, the door locking is prohibited based on the response signal, thereby preventing the portable device from being trapped inside the vehicle.

[0012] In the present invention, when the first operating unit is operated, the first control unit of the portable device may transmit an operation signal indicating the content of the operation from the first communication unit, and when the second communication unit receives the operation signal from the portable device, the second control unit of the vehicle control device may perform control on the vehicle in accordance with the operation of the first operating unit.

[0013] In the present invention, the second control unit of the vehicle control device may transmit a second signal from the second communication unit when the operation of the second operating unit is an unlocking operation to unlock the vehicle door, and may transmit a first signal from the second communication unit when the operation of the second operating unit is a locking operation to lock the vehicle door.

[0014] In the present invention, the second control unit of the vehicle control device may determine whether a security mode for preventing unauthorized unlocking is set when the operation of the second operating unit is an unlocking operation, and if the security mode is set, transmit a second signal from the second communication unit.

[0015] In the present invention, the second control unit of the vehicle control device may determine whether the current time is within a preset security valid time period, and if the current time is within the security valid time period, may transmit a second signal from the second communication unit.

[0016] In the present invention, the second control unit of the vehicle control device may determine whether or not a security abnormality has occurred when the current time is outside the range of the security valid time zone, and if a security abnormality has occurred, transmit a second signal from the second communication unit.

[0017] In the present invention, the vehicle control device may include a portable device position detection unit that detects the location of the portable device based on a response signal transmitted from the portable device. When a locking operation to lock the doors is performed on the vehicle side, if the portable device position detection unit detects that the portable device is inside the vehicle, the vehicle control device may prohibit the doors from locking. [Effects of the Invention]

[0018] According to the present invention, it is possible to reliably prevent fraudulent acts through relay attacks using a simple method while ensuring user convenience. [Brief explanation of the drawings]

[0019] [Figure 1]1 is a block diagram showing an example of a vehicle control system according to the present invention; [Figure 2] FIG. 2 is a diagram illustrating an example of a portable device. [Figure 3] FIG. 2 is a schematic diagram showing the arrangement of an operation unit and an antenna in a vehicle. [Figure 4] 4 is an example of data stored in a storage unit of a vehicle control device. [Figure 5] 3 is a flowchart showing the operation of the first embodiment of the present invention. [Figure 6] FIG. 10 is a diagram showing a state in which the portable device is inside a vehicle. [Figure 7] FIG. 10 is a diagram showing a state in which the portable device is taken out of the vehicle. [Figure 8] 10 is a flowchart showing the operation of the second embodiment of the present invention. [Figure 9] 10 is a flowchart showing the operation of the third embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0020] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS An embodiment of the present invention will be described with reference to the drawings, in which the same or corresponding parts are designated by the same reference numerals.

[0021] FIG. 1 shows an example of a vehicle control system according to the present invention. Only blocks related to the present invention are shown here. The vehicle control system 100 comprises a portable device 10 and a vehicle control device 20. The portable device 10 comprises an electronic key operated to lock and unlock the vehicle doors, and is carried by the vehicle user. The vehicle control device 20 comprises an on-board device mounted in the vehicle, and performs predetermined control of each part of the vehicle. The portable device 10 and the vehicle control device 20 are configured to communicate with each other wirelessly.

[0022] The portable device 10 includes an operation unit 11 that is operated to cause the vehicle to perform a predetermined operation, a control unit 12 that is configured with a CPU, memory, etc., an LF receiving unit 13 that receives an LF (Low Frequency) signal transmitted from the vehicle control device 20, and a UHF transmitting unit 14 that transmits a UHF (Ultra High Frequency) signal to the vehicle control device 20. Fig. 2 shows an example of the portable device 10, and the operation unit 11 is provided with a lock button 11a for locking the vehicle doors and an unlock button 11b for unlocking the vehicle doors.

[0023] The control unit 12 has a response necessity determination unit 15, an authentication unit 16, and a storage unit 17. When an LF signal transmitted from the vehicle control device 20 is received by the LF receiving unit 13, the response necessity determination unit 15 determines whether a response to the LF signal is necessary. When a response to the LF signal is necessary, the authentication unit 16 verifies whether the ID included in the LF signal matches the ID of the portable device 10. The ID of the portable device 10 is stored in the storage unit 17.

[0024] The operation unit 11 corresponds to the "first operation unit" in the present invention, the control unit 12 corresponds to the "first control unit" in the present invention, and the LF receiving unit 13 and the UHF transmitting unit 14 correspond to the "first communication unit" in the present invention.

[0025] The vehicle control device 20 includes an operation unit 21 that is operated to cause the vehicle to perform a predetermined operation, a control unit 22 that is composed of a CPU, memory, etc., an LF transmission unit 23 that transmits an LF signal to the portable device 10, a UHF reception unit 24 that receives a UHF signal from the portable device 10, and a CAN reception unit 25 and a CAN transmission unit 26 that perform CAN (Controller Area Network) communication.

[0026] As shown in Fig. 3, the operation unit 21 includes switches 53 provided on the handles of the left and right front doors 52 of the vehicle 50, a touch panel 54 provided on the instrument panel inside the passenger compartment 51, and an engine start button 55 provided in the driver's seat. The switch 53 is a switch for locking and unlocking the doors. The touch panel 54 is provided on a display device for car navigation. The engine start button 55 is composed of a push button switch or the like.

[0027] The control unit 22 includes a response-needed / unnecessary determination unit 27, an authentication unit 28, a control signal output unit 29, a portable device position detection unit 30, an alarm signal output unit 31, and a storage unit 32. When an operation is performed on the operation unit 21, the response-needed / unnecessary determination unit 27 determines whether the operation requires a response from the portable device 10. When a UHF signal transmitted from the portable device 10 is received by the UHF receiving unit 24, the authentication unit 28 verifies whether an ID included in the UHF signal matches an ID stored in the storage unit 32. When the authentication unit 28 confirms that the IDs match, the control signal output unit 29 outputs a control signal for controlling the vehicle doors and engine via the CAN transmission unit 26. The portable device position detection unit 30 detects the location of the portable device 10 (inside or outside the vehicle) based on the strength of the UHF signal received from the portable device 10. The alarm signal output unit 31 outputs an alarm signal to notify the user when the portable device 10 is taken out of the vehicle with the engine running.

[0028] As shown in FIG. 4, the storage unit 32 stores security information and a portable device ID. The security information includes whether the security mode is ON (set) or OFF (not set), the security valid time period, and whether a security abnormality has occurred. The security mode is a mode for preventing a third party from performing an unauthorized unlocking by a relay attack. The security mode ON / OFF and valid time period are set by the user on the touch panel 54 of the operation unit 21 (FIG. 3) or on the user's smartphone. The presence or absence of a security abnormality is notified to the vehicle control device 20 from a gateway (not shown).

[0029] The LF transmitter 23 includes an interior antenna 23a and an exterior antenna 23b shown in Fig. 3. The interior antennas 23a are provided at the front and rear of the vehicle interior 51. The exterior antennas 23b are provided at the left and right front doors 52 of the vehicle 50, respectively.

[0030] A car navigation system 41 is connected to the CAN receiver 25. A smartphone system 42 is also connected to the CAN receiver 25 via a smartphone communication unit (not shown). GPS information required for car navigation and information input by the user from the smartphone are sent to the control unit 22 via the CAN receiver 25. A door lock system 43 and an engine system 44 are connected to the CAN transmitter 26. Control signals output by the control signal output unit 29 are sent to these systems 43 and 44 via the CAN transmitter 26.

[0031] The operation unit 21 corresponds to the "second operation unit" in the present invention, the control unit 22 corresponds to the "second control unit" in the present invention, and the LF transmission unit 23 and the UHF reception unit 24 correspond to the "second communication unit" in the present invention.

[0032] Next, the operation of the vehicle control system 100 configured as above will be described.

[0033] Fig. 5 is a flowchart showing the operation of the first embodiment. In Fig. 5, the flowchart of the vehicle control device shows the procedure executed by the control unit 22, and the flowchart of the portable device shows the procedure executed by the control unit 12 (the same applies to Figs. 8 and 9 described later).

[0034] In step S2, the vehicle control device 20 waits for detection of a user operation of the operation unit 21. Then, in step S1, an operation such as locking or unlocking a door using the switch 53 in Fig. 3 or starting the engine using the engine start button 55 in Fig. 3 is performed, and when the user operation is detected (step S3: YES), the process proceeds to step S4.

[0035] In addition, in step S22, the portable device 10 waits for detection of a user operation of the operation unit 11. Then, if the lock button 11a or the unlock button 11b in Fig. 2 is pressed in step S21 and a user operation is detected (step S23; YES), the process proceeds to step S28, and if a user operation is not detected (step S23: NO), the process proceeds to step S24.

[0036] Vehicle control device 20 Now, following the operation of the operation unit 21, Steps S4 and S6 In The user's operation performed on the operation unit 21 is an operation that requires a response from the portable device 10. or an operation that does not require a response from the portable device 10. The response necessity determination unit 27 determines 。 In step S4, it is determined whether the operation performed by the user is an unlocking operation. If the determination result is that it is not an unlocking operation (step S4: NO), for example, if it is a locking operation or an engine start operation, the process proceeds to step S5.

[0037] In step S5, information indicating a response "is required" is added to the LF signal to be transmitted to the portable device 10. Then, in step S8, the LF signal to which this information has been added is transmitted from the LF transmitter 23 to the portable device 10. This LF signal corresponds to the "first signal notifying that a response is required" in the present invention. The transmitted LF signal also includes the ID of the portable device 10.

[0038] On the other hand, if the result of the determination in step S4 is that the user operation is an unlock operation (step S4: YES), the process proceeds to step S6. In step S6, it is determined whether or not the security mode is ON based on the security information in the storage unit 32 shown in FIG.

[0039] If the result of the determination in step S6 is that the security mode is ON (step S6: YES), the process proceeds to step S7. In step S7, information indicating a "no response" is added to the LF signal to be transmitted to the portable device 10. Then, in step S8, the LF signal to which this information is added is transmitted from the LF transmitter 23 to the portable device 10. This LF signal corresponds to the "second signal notifying a no response" in the present invention. In this case, the transmitted LF signal also includes the ID of the portable device 10.

[0040] On the other hand, if the result of the determination in step S6 is that the security mode is OFF (step S6: NO), the process proceeds to step S5, where the information indicating "response required" is added to the LF signal as described above. Then, in step S8, the LF signal with the added information is transmitted from the LF transmitter 23 to the portable device 10.

[0041] In step S24, the portable device 10 waits to receive an LF signal from the vehicle control device 20, and when the LF signal is received by the LF receiver 13, the process proceeds to step S25. In step S25, the response necessity determination unit 15 checks the additional information of the received LF signal to determine whether a response is necessary. Specifically, if the LF signal has information indicating a response "necessary" added to it (step S25: YES), the process proceeds to step S26, and if the LF signal has information indicating a response "not necessary" added to it (step S25: NO), the process ends without executing steps S26 to S28.

[0042] In step S26, the LF signal received in step S24 is authenticated. Specifically, the authentication unit 16 verifies whether the ID included in the LF signal matches the ID of the portable device 10 stored in the storage unit 17. If the result of the verification shows that the two IDs match (step S27: YES), the process proceeds to step S28, and if the two IDs do not match (step S27: NO), the process ends without executing step S28.

[0043] In step S28, a UHF signal is transmitted from the UHF transmitter 14. In this case, the UHF signal is a "response signal" to the LF signal requesting a response. On the other hand, if an operation is performed on the operation unit 11 of the portable device 10 in step S21 (step S23: YES), the UHF signal transmitted in step S28 is an "operation signal" indicating the content of the operation (lock or unlock). The response signal and operation signal include the ID of the portable device 10.

[0044] In step S9, the vehicle control device 20 waits to receive a UHF signal from the portable device 10, and when the UHF signal is received by the UHF receiving unit 24, the process proceeds to step S10. In step S10, the received UHF signal is authenticated. Specifically, the authentication unit 28 verifies whether the ID included in the UHF signal matches the ID of the portable device 10 stored in the storage unit 32 (see FIG. 4). If the result of the verification shows that the two IDs match (step S11: YES), the process proceeds to step S12, and if the two IDs do not match (step S11: NO), the process ends without executing step S12.

[0045] In step S12, control signal output unit 29 outputs a control signal for performing a predetermined control on the vehicle. Specifically, if the UHF signal received in step S9 is a response signal to the LF signal, a control signal corresponding to the operation of operation unit 21 in step S1 is output via CAN transmitter 26. For example, if the operation of operation unit 21 is a locking operation or an unlocking operation, CAN transmitter 26 outputs a locking signal or an unlocking signal to door lock system 43. Furthermore, if the operation of operation unit 21 is an engine starting operation, CAN transmitter 26 outputs an engine starting signal to engine system 44.

[0046] On the other hand, if the UHF signal received in step S9 is an operation signal based on an operation on the portable device 10, a control signal corresponding to the operation of the operation unit 11 in step S21 is output via the CAN transmitter 26. That is, if the operation of the operation unit 11 is a lock operation, a lock signal is output to the door lock system 43, and if the operation of the operation unit 11 is an unlock operation, an unlock signal is output to the door lock system 43.

[0047] When the above-described control signal is output, in step S13, a control operation is executed in accordance with the operation of the operation units 11, 21. In detail, if the control signal is a lock signal, the vehicle doors are locked, if the control signal is an unlock signal, the vehicle doors are unlocked, and if the control signal is an engine start signal, the vehicle engine is started.

[0048] In addition, in step S13, measures to prevent the portable device 10 from being locked inside and measures to warn against taking out the portable device 10 are also carried out.

[0049] For example, in the case of the portable device 10 being locked out, if the portable device 10 is left behind inside the vehicle 50 as shown in Fig. 6, the portable device 10 is within the range Za of the radio waves from the interior antenna 23a and is therefore able to communicate with the vehicle control device 20. When a locking operation is performed using the switch 53 of the operation unit 21, if the portable device position detection unit 30 detects that the portable device 10 is inside the vehicle based on the response signal transmitted from the portable device 10, the control signal output unit 29 is prevented from outputting a lock signal. This prohibits the doors from being locked, thereby preventing the portable device 10 from being locked out inside the vehicle.

[0050] Regarding the portable device 10 being taken out of the vehicle, the portable device position detection unit 30 starts detecting the position of the portable device 10 when the vehicle door is opened and then closed. Then, as shown in FIG. 7 , when the portable device 10 is taken out of the vehicle by someone other than the driver and is no longer within the range Zb of the radio waves from the exterior antenna 23b, the vehicle control device 20 no longer receives a response signal from the portable device 10. This causes the portable device position detection unit 30 to detect that the portable device 10 is outside the vehicle. As a result, an alarm signal is output from the alarm signal output unit 31, and an alarm sound or display is issued based on this signal, so that it is possible to prevent the vehicle from starting when the portable device 10 is not inside the vehicle.

[0051] According to the first embodiment described above, when a third party operates the switch 53 of the vehicle 50 to perform an unlock operation while the security mode is set to ON, an LF signal with information indicating a "no" response added, i.e., a signal that does not request a response, is transmitted from the vehicle control device 20 to the portable device 10 (steps S6 to S8 in FIG. 5). Therefore, even if this LF signal is received by the portable device 10 via a repeater by a relay attack (step S24), no response signal is returned from the portable device 10 to the vehicle control device 20. Therefore, the control signal output unit 29 of the vehicle control device 20 does not output an unlock signal to the door lock system 43, and the doors of the vehicle 50 are not unlocked. In this way, even if a third party attempts to unlock the doors of the vehicle 50 by a relay attack using a repeater, the third party cannot intercept the response signal from the portable device 10, and therefore cannot unlock the doors.

[0052] On the other hand, when the security mode is ON, the authorized user of the vehicle 50 cannot unlock the doors by operating the switch 53 on the vehicle side. However, by pressing the unlock button 11b (FIG. 2) on the portable device 10, an operation signal indicating unlock is transmitted from the portable device 10 to the vehicle control device 20 (steps S21 to S23, S28 in FIG. 5), and the doors can be unlocked. Conversely, when the security mode is ON, the doors cannot be unlocked unless an unlock operation is performed on the portable device 10. Furthermore, because the portable device 10 is owned by the user, a third party cannot unlock the doors by operating the portable device 10.

[0053] Furthermore, when a user unlocks the door using the portable device 10, the user operates the portable device 10 near the vehicle, so it is virtually impossible for a third party to use a repeater near the vehicle where the user is located to relay the transmission signal (operation signal) from the portable device 10.

[0054] As described above, by prohibiting unauthorized unlocking of the doors by a third party, crimes such as theft of the vehicle 50 and theft of items inside the vehicle compartment 51 can be prevented. In particular, in the case of the present invention, even if a third party performs an unlocking operation of the doors while the security mode is ON, the third party cannot steal the response signal from the portable device 10. Therefore, even if the anti-tampering algorithm (FIG. 5) is known to a third party, unlocking by a relay attack can be reliably prevented. Furthermore, by using a simple method of transmitting a signal to the portable device 10 notifying whether a response is required, without requiring complex processing or operations, the vehicle control system 100 can be realized that exhibits excellent security functions against relay attacks.

[0055] On the other hand, if the operation on the vehicle side is a locking operation or an engine start operation other than an unlocking operation (step S4: NO), or if the operation is an unlocking operation but the security mode is OFF (step S6: NO), an LF signal with information indicating a response "required" added, i.e., a signal requesting a response, is sent from the vehicle control device 20 to the portable device 10 (steps S5, S8), and a response signal is returned from the portable device 10 to the vehicle control device 20 (step S28).

[0056] However, in the case of a locking operation, the doors will not be unlocked even if a relay attack is performed, so there is no risk of theft of the vehicle 50 or items inside the vehicle. Also, in the case of an engine start operation, an LF signal is not transmitted from the vehicle control device 20 unless the engine start button 55 is pressed inside the vehicle, so a relay attack is not a problem. Also, the security mode being set to OFF is something that the user has decided to do so so that the doors can be unlocked without operating the portable device 10, and when the security mode is OFF, there is a situation where the vehicle is in a location where there is no risk of a relay attack, so there is little possibility of a third party committing fraud.

[0057] In this way, for operations other than unlocking, mutual communication between the portable device 10 and the vehicle control device 20 is suspended, ensuring convenience for the user. For example, if the user gets out of the vehicle 50 and performs a locking operation using the door switch 53, the doors of the vehicle 50 can be locked, as in the past, without operating the lock button 11a on the portable device 10. Furthermore, even if a locking operation is performed while the portable device 10 is left inside the vehicle, as described above, the fact that the portable device 10 has been left behind can be detected based on the response signal from the portable device 10, and the door locking can be prohibited, thereby preventing the portable device 10 from being locked inside the vehicle.

[0058] Fig. 8 is a flowchart showing the operation of the second embodiment. In Fig. 8, step S6a is added after step S6 in Fig. 5. The determinations in steps S4, S6, and S6a are made by response necessity determination unit 27. In step S6a, if the security mode is OFF (step S6: NO), it is determined whether the current time is within a preset security valid time period (see Fig. 4).

[0059] If the result of the determination in step S6a is that the current time is not within the valid time period (step S6a: NO), the process proceeds to step S5, where information indicating a response "required" is added to the LF signal, and in step S8, the LF signal is transmitted from the LF transmitter 23 to the portable device 10. On the other hand, if the current time is within the valid time period in step S6a (step S6a: YES), the process proceeds to step S7, where information indicating a response "not required" is added to the LF signal, and in step S8, the LF signal is transmitted from the LF transmitter 23 to the portable device 10. The other steps are the same as in Fig. 5, so a description of steps that overlap with Fig. 5 will be omitted.

[0060] According to the second embodiment, even if the security mode is OFF, if the current time is within the valid time of the security mode, the LF signal received by the portable device 10 is a signal that does not request a response, and therefore no response signal is transmitted from the portable device 10 to the vehicle control device 20. Therefore, even if the user forgets to set the security mode ON, unauthorized unlocking of the doors by a third party can be prevented.

[0061] Fig. 9 is a flowchart showing the operation of the third embodiment. In Fig. 9, step S6b is added after step S6a in Fig. 8. The determinations of steps S4, S6, S6a, and S6b are made by response necessity determination unit 27. In step S6b, if the security mode is OFF (step S6: NO) and the current time is outside the valid time zone (step S6a: NO), it is determined whether a security abnormality (see Fig. 4) has occurred. For example, if an unauthorized intrusion is detected in the gateway, it is determined that a security abnormality has occurred.

[0062] If the result of the determination in step S6b is that no security abnormality has occurred (step S6b: NO), the process proceeds to step S5, where information indicating a response "required" is added to the LF signal, and in step S8, the LF signal is transmitted from the LF transmitter 23 to the portable device 10. On the other hand, if a security abnormality has occurred in step S6b (step S6b: YES), the process proceeds to step S7, where information indicating a response "not required" is added to the LF signal, and in step S8, the LF signal is transmitted from the LF transmitter 23 to the portable device 10. The other steps are the same as in Fig. 5, so a description of steps that overlap with Fig. 5 will be omitted.

[0063] According to the third embodiment, even if the security mode is OFF and the current time is outside the valid time of the security, if a security abnormality occurs, the LF signal received by the portable device 10 is a signal that does not request a response, and therefore no response signal is transmitted from the portable device 10 to the vehicle control device 20. This makes it possible to more effectively prevent fraudulent acts by third parties.

[0064] In addition to the above-described embodiment, the present invention can employ various other embodiments as follows.

[0065] In the above embodiment, an example was given in which the information "response required" is added to the LF signal notifying that a response is required, and the information "response not required" is added to the LF signal notifying that a response is not required, but the present invention is not limited to this. For example, the information "response required" may be added only to the LF signal notifying that a response is required, and the LF signal notifying that a response is not required may not include any additional information. In this case, the portable device 10 determines that a response is not required if the received LF signal does not include any additional information.

[0066] Alternatively, the portable device 10 may add "no" response information only to the LF signal notifying whether or not a response is possible, and not include any additional information in the LF signal notifying whether a response is required. In this case, if the received LF signal does not include any additional information, the portable device 10 determines that a response is required.

[0067] Alternatively, instead of adding information indicating whether a response is required to the LF signal, the frequency of the LF signal when a response is required may be different from the frequency of the LF signal when a response is not required. In this case, the portable device 10 determines whether a response is required by determining the frequency of the received LF signal.

[0068] In the above embodiment, whether or not the security mode is set is determined in step S6 in FIGS. 5, 8, and 9, but this step S6 may be omitted.

[0069] In the above embodiment, LF signals and UHF signals are used for communication between the portable device 10 and the vehicle control device 20, but signals other than these may also be used.

[0070] In addition, in the above embodiment, an example was given in which the car navigation system 41 and the smartphone system 42 were connected to the CAN receiver 25, but other systems may be added. Similarly, in the above embodiment, an example was given in which the door lock system 43 and the engine system 44 were connected to the CAN transmitter 26, but other systems may be added.

[0071] In addition, in the above embodiment, an example was given in which the vehicle control device 20 and each system 41 to 44 were connected via CAN, but the vehicle control device 20 and each system 41 to 44 may also be connected via a network other than CAN, such as LIN (Local Interconnect Network). [Explanation of symbols]

[0072] 10. Portable devices 11 Operation unit (1st operation unit) 12 control unit (first control unit) 13 LF receiver (communication unit, first communication unit) 14 UHF transmitter (communication unit, first communication unit) 20 Vehicle control device 21 Operation unit (second operation unit) 22 control unit (second control unit) 23 LF transmitter (communication unit, second communication unit) 24 UHF receiver (communication unit, second communication unit) 30 Portable device position detection unit 50 vehicles 100 Vehicle Control System

Claims

1. a vehicle control device that is mounted on a vehicle and performs predetermined control on the vehicle; a portable device that wirelessly communicates with the vehicle control device, The portable device includes: a first operation unit that is operated to cause the vehicle to perform a predetermined operation; a first communication unit that communicates with the vehicle control device; a first control unit that controls the first communication unit, The vehicle control device includes: a second operating unit that is operated to cause the vehicle to perform a predetermined operation; a second communication unit that communicates with the first communication unit; a second control unit that performs predetermined control on the vehicle based on operation of the first operation unit or the second operation unit, The second control unit is When the second operation unit is operated, following the operation, it is determined whether the operation of the second operation unit is an operation that requires a response from the portable device or an operation that does not require a response from the portable device; If the operation requires a response, a first signal notifying the need for a response is transmitted from the second communication unit; If the operation does not require a response, a second signal notifying whether or not a response is required is transmitted from the second communication unit; The first control unit When the first communication unit receives the first signal, a response signal is transmitted from the first communication unit; When the first communication unit receives the second signal, a response signal is not transmitted from the first communication unit; The vehicle control system is characterized in that, when the second communication unit receives the response signal, the second control unit controls the vehicle in accordance with the operation of the second operation unit.

2. 2. The vehicle control system according to claim 1, When the first operation unit is operated, the first control unit transmits an operation signal indicating the content of the operation from the first communication unit; The vehicle control system is characterized in that, when the second communication unit receives the operation signal, the second control unit controls the vehicle in accordance with the operation of the first operation unit.

3. 3. The vehicle control system according to claim 1, The second control unit is When the operation of the second operation unit is an unlocking operation for unlocking a door of the vehicle, the second signal is transmitted from the second communication unit; A vehicle control system, characterized in that, when the operation of the second operation unit is a lock operation for locking a door of a vehicle, the first signal is transmitted from the second communication unit.

4. 4. The vehicle control system according to claim 3, The second control unit is When the operation of the second operation unit is an unlocking operation, it is determined whether a security mode for preventing unauthorized unlocking is set or not; If the security mode is set, the second signal is transmitted from the second communication unit.

5. 5. The vehicle control system according to claim 3, wherein: The second control unit is Determine whether the current time is within a preset security valid time period; If the current time is within the security valid time period, the second signal is transmitted from the second communication unit.

6. 6. The vehicle control system according to claim 5, The second control unit is If the current time is outside the range of the security valid time zone, it is determined whether or not a security abnormality has occurred; If a security abnormality occurs, the second signal is transmitted from the second communication unit.

7. A vehicle control device that is mounted on a vehicle, performs predetermined control of the vehicle, and wirelessly communicates with a portable device carried by a user of the vehicle, an operation unit that is operated to cause the vehicle to perform a predetermined operation; a communication unit that communicates with the portable device; a control unit that performs predetermined control of the vehicle based on an operation of the operation unit, The control unit When the operation unit is operated, the operation unit is subsequently determined to be either an operation that requires a response from the portable device or an operation that does not require a response from the portable device; If the operation requires a response, a first signal notifying the user that a response is required is transmitted from the communication unit; If the operation does not require a response, a second signal notifying whether or not a response is required is transmitted from the communication unit; When the communication unit receives a response signal from the portable device, the vehicle control device performs control on the vehicle in accordance with the operation of the operation unit.

8. The vehicle control device according to claim 7, The vehicle control device is characterized in that, when a predetermined operation is performed on the portable device, the control unit performs control of the vehicle in accordance with the operation when the communication unit receives an operation signal indicating the content of the operation transmitted from the portable device.

9. The vehicle control device according to claim 7 or 8, a portable device location detection unit that detects the location of the portable device based on the response signal transmitted from the portable device; The vehicle control device is characterized in that, when a locking operation to lock the vehicle doors is performed using the operation unit, if the portable device position detection unit detects that the portable device is inside the vehicle, the control unit prohibits the doors from being locked.

Citation Information

Patent Citations

  • Electronic key system

    JP2011247076A

  • Smart system

    JP2013119757A

  • Vehicle verification system

    JP2016079600A

  • On-vehicle equipment control system, on-vehicle control device, and portable unit

    JP2017220759A

  • Electronic key system

    JP2018062761A