Vehicle control system, vehicle control device

The vehicle control system addresses relay attacks by selectively transmitting response signals and detecting device location to prevent unauthorized access and trapping, enhancing security and convenience.

JP7725233B2Active Publication Date: 2025-08-19NIDEC MOBILITY CORP
View PDF 19 Cites 0 Cited by

Patent Information

Application Number
JP2021085585
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-05-20
Publication Date
2025-08-19
Estimated Expiration
2041-05-20

AI Technical Summary

Technical Problem

Existing vehicle control systems are vulnerable to relay attacks, which allow unauthorized access and theft through fraudulent communication, and existing countermeasures are either complex or can be circumvented, and they also risk trapping the user's device inside the vehicle.

Method used

A vehicle control system that selectively transmits response request signals only when necessary, preventing unauthorized operations by not transmitting signals for operations that do not require a response, and includes features to detect device location and notify the user of security modes.

Benefits of technology

Effectively prevents relay attacks with a simple method while ensuring user convenience by preventing unauthorized access and ensuring the device is not trapped inside the vehicle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007725233000001
    Figure 0007725233000001
  • Figure 0007725233000002
    Figure 0007725233000002
  • Figure 0007725233000003
    Figure 0007725233000003
Patent Text Reader

Abstract

To assure a user's convenience and reliably prevent a dishonest act using a relay attack by a simple method.SOLUTION: A vehicle control system 100 comprises a portable machine 10 possessed by a user and a vehicle control device 20 installed on a vehicle. A controller 22 of the vehicle control device 20 determines whether an operation on an operation unit 21 is an operation requiring response from the portable machine 10 or not, and transmits a response request signal for requesting the response from an LF transmission unit 23 if the operation requires the response, or does not transmit the response request signal from the LF transmission unit 23 if the operation does not require the response. The controller 12 of the portable machine 10 transmits a response signal from a UHF transmission unit 14 if an LF reception unit 13 receives the response request signal. The controller 22 of the vehicle control device 20 performs control on the vehicle depending on the operation on the operation unit 21 if a UHF reception unit 24 receives the response signal.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a control system for controlling the operation of a vehicle, and more particularly to a vehicle control system having a security function against relay attacks. [Background technology]

[0002] Vehicle control systems have been put into practical use that perform predetermined controls such as locking and unlocking vehicle doors or starting the engine based on wireless signals transmitted and received between a vehicle control device installed in a vehicle and a portable device carried by the user.

[0003] In this vehicle control system, when a user carrying a portable device performs a locking or unlocking operation using a switch provided on the door handle, a response request signal is transmitted from the vehicle control device to the portable device. When the portable device receives this response request signal, it returns a response signal including the ID of the portable device to the vehicle control device. Upon receiving the response signal, the vehicle control device verifies the ID and performs authentication, and if authentication is successful, locks or unlocks the doors. Furthermore, when the user performs a locking or unlocking operation on the portable device, an operation signal corresponding to the operation is transmitted from the portable device to the vehicle control device. This operation signal also includes the ID of the portable device. Upon receiving the operation signal, the vehicle control device verifies the ID and locks or unlocks the doors if authentication is successful.

[0004] In recent years, a fraudulent act known as a relay attack has become a problem in vehicle control systems such as those described above. A relay attack is an act of fraudulent communication in which a third party other than the owner of the vehicle uses a repeater to relay a response request signal sent from the vehicle control device or a response signal returned from the portable device, thereby making it appear as if the owner's portable device, which is located far away, is in the vicinity of the vehicle. A relay attack allows a malicious third party to unlock the vehicle doors or start the engine, which could lead to crimes such as theft of the vehicle or items inside the vehicle.

[0005] Therefore, various countermeasures to prevent such relay attacks have been proposed in the past (see, for example, Patent Documents 1 to 12). However, conventional methods require complex processing and operations to ensure thorough countermeasures against relay attacks, and if the countermeasure algorithm becomes known to a third party, the third party may be able to use the algorithm to launch a relay attack, so these methods cannot be said to be foolproof as crime prevention measures.

[0006] On the other hand, there are portable devices in practical use that have a lock button for locking and an unlock button for unlocking, and can be set to a power-saving mode by performing a specific operation using these buttons. In this portable device, all transmission and reception operations are stopped while the device is in the power-saving mode, which effectively prevents relay attacks.

[0007] However, if a driver leaves a portable device set to power-saving mode inside the vehicle and attempts to lock the doors after getting out, the vehicle control device will determine that the portable device is not inside the vehicle and will lock the doors, since the portable device will not return a response signal even if the vehicle control device sends a response request signal to the portable device. As a result, the portable device will be trapped inside the vehicle, and the driver will not be able to unlock the doors when they get in. [Prior art documents] [Patent documents]

[0008] [Patent Document 1] Japanese Patent Publication No. 2020-197083 [Patent Document 2] U.S. Patent Publication No. 2020 / 0216024 [Patent Document 3] Special Publication No. 2020-518502 [Patent Document 4] U.S. Patent Publication No. 2020 / 0193750 [Patent Document 5] Japanese Patent Application Publication No. 2018-69764 [Patent Document 6] Japanese Patent Application Publication No. 2018-71050 [Patent Document 7] Japanese Patent Application Publication No. 2018-62765 [Patent Document 8] Japanese Patent Application Publication No. 2018-62761 [Patent Document 9] Japanese Patent Application Publication No. 2018-62764 [Patent Document 10] Japanese Patent Application Publication No. 2018-62762 [Patent Document 11] Japanese Patent Application Publication No. 2018-71049 [Patent Document 12] Japanese Patent Application Laid-Open No. 2017-220759 Summary of the Invention [Problem to be solved by the invention]

[0009] An object of the present invention is to provide a vehicle control system that can reliably prevent fraudulent acts through relay attacks using a simple method while ensuring user convenience. [Means for solving the problem]

[0010] The vehicle control system according to the present invention comprises a vehicle control device mounted on a vehicle and performing predetermined control of the vehicle, and a portable device that communicates wirelessly with the vehicle control device. The portable device comprises a first operation unit that is operated to cause the vehicle to perform a predetermined operation, a first communication unit that communicates with the vehicle control device, and a first control unit that controls the first communication unit. The vehicle control device comprises a second operation unit that is operated to cause the vehicle to perform a predetermined operation, a second communication unit that communicates with the first communication unit of the portable device, and a second control unit that performs predetermined control of the vehicle based on operation of the first operation unit or the second operation unit. The second control unit controls the vehicle based on operation of the second operation unit. And , Following this operation, the second operation unit is operated as follows: Operations that require a response from the mobile device or it is an operation that does not require a response from the handheld device.If the operation requires a response, the second communication unit transmits a response request signal requesting a response, and if the operation does not require a response, the second communication unit does not transmit the response request signal to the portable device. When the first communication unit of the portable device receives the response request signal, the first control unit transmits a response signal from the first communication unit, and when the second communication unit receives the response signal, the second control unit controls the vehicle in accordance with the operation of the second operation unit.

[0011] According to this vehicle control system, if the operation of the second operation unit requires a response from the portable device, a response request signal is transmitted from the vehicle control device to the portable device. However, if the operation of the second operation unit does not require a response from the portable device, the response request signal is not transmitted from the vehicle control device to the portable device, and no response signal is returned from the portable device to the vehicle control device. Therefore, if an operation that may result in unauthorized unlocking by a third party is performed, such as an unlocking operation, the response request signal is not transmitted from the vehicle control device to the portable device, so that the response request signal and the response signal are not relayed by a relay attack, thereby reliably preventing unauthorized unlocking of the vehicle doors. On the other hand, if the locking operation does not pose a risk of unauthorized unlocking by a third party, the response request signal is transmitted from the vehicle control device to the portable device, and a response signal is returned from the portable device. Therefore, even if the portable device is left inside the vehicle and a locking operation is performed, locking of the doors is prohibited based on the response signal, thereby preventing the portable device from being trapped inside the vehicle.

[0012] In the present invention, when the first operating unit is operated, the first control unit of the portable device may transmit an operation signal indicating the content of the operation from the first communication unit, and when the second communication unit receives the operation signal from the portable device, the second control unit of the vehicle control device may perform control on the vehicle in accordance with the operation of the first operating unit.

[0013] In the present invention, the second control unit of the vehicle control device may not transmit a response request signal from the second communication unit when the operation of the second operating unit is an unlocking operation to unlock the vehicle doors, and may transmit a response request signal from the second communication unit when the operation of the second operating unit is a locking operation to lock the vehicle doors.

[0014] In the present invention, the second control unit of the vehicle control device may determine whether a security mode for preventing unauthorized unlocking is set when the operation of the second operating unit is an unlocking operation, and if the security mode is set, may not send a response request signal from the second communication unit.

[0015] In the present invention, the second control unit of the vehicle control device may determine whether the current time is within a preset security valid time period, and if the current time is within the security valid time period, may not transmit a response request signal from the second communication unit.

[0016] In the present invention, the second control unit of the vehicle control device may determine whether or not a security abnormality has occurred when the current time is outside the range of the security valid time zone, and if a security abnormality has occurred, may not transmit a response request signal from the second communication unit.

[0017] In the present invention, the vehicle control device may include a portable device position detection unit that detects the location of the portable device based on a response signal transmitted from the portable device. When a locking operation to lock the doors is performed on the vehicle side, if the portable device position detection unit detects that the portable device is inside the vehicle, the vehicle control device may prohibit the doors from locking.

[0018] In the present invention, the vehicle control device may include a notification unit that notifies the user of the operation performed on the operation unit. When an unlocking operation to unlock the vehicle doors is performed on the operation unit and a security mode for preventing unauthorized unlocking is set, the notification unit makes a notification in a pattern different from that when the security mode is not set. [Effects of the Invention]

[0019] According to the present invention, it is possible to reliably prevent fraudulent acts through relay attacks using a simple method while ensuring user convenience. [Brief explanation of the drawings]

[0020] [Figure 1] 1 is a block diagram showing an example of a vehicle control system according to the present invention; [Figure 2] FIG. 2 is a diagram illustrating an example of a portable device. [Figure 3] FIG. 2 is a schematic diagram showing the arrangement of an operation unit and an antenna in a vehicle. [Figure 4] 4 is an example of data stored in a storage unit of a vehicle control device. [Figure 5] 3 is a flowchart showing the operation of the first embodiment of the present invention. [Figure 6] FIG. 10 is a diagram showing a state in which the portable device is inside a vehicle. [Figure 7] FIG. 10 is a diagram showing a state in which the portable device is taken out of the vehicle. [Figure 8] 10 is a flowchart showing the operation of the second embodiment of the present invention. [Figure 9] 10 is a flowchart showing the operation of the third embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0021] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS An embodiment of the present invention will be described with reference to the drawings, in which the same or corresponding parts are designated by the same reference numerals.

[0022] FIG. 1 shows an example of a vehicle control system according to the present invention. Only blocks related to the present invention are shown here. The vehicle control system 100 comprises a portable device 10 and a vehicle control device 20. The portable device 10 comprises an electronic key operated to lock and unlock the vehicle doors, and is carried by the vehicle user. The vehicle control device 20 comprises an on-board device mounted in the vehicle, and performs predetermined control of each part of the vehicle. The portable device 10 and the vehicle control device 20 are configured to communicate with each other wirelessly.

[0023] The portable device 10 includes an operation unit 11 that is operated to cause the vehicle to perform a predetermined operation, a control unit 12 that is configured with a CPU, memory, etc., an LF receiving unit 13 that receives an LF (Low Frequency) signal transmitted from the vehicle control device 20, and a UHF transmitting unit 14 that transmits a UHF (Ultra High Frequency) signal to the vehicle control device 20. Fig. 2 shows an example of the portable device 10, and the operation unit 11 is provided with a lock button 11a for locking the vehicle doors and an unlock button 11b for unlocking the vehicle doors.

[0024] The control unit 12 has an authentication unit 15 and a storage unit 16. When the LF receiving unit 13 receives an LF signal from the vehicle control device 20, the authentication unit 15 checks whether the ID included in the LF signal matches the ID of the portable device 10. The ID of the portable device 10 is stored in the storage unit 16.

[0025] The operation unit 11 corresponds to the "first operation unit" in the present invention, the control unit 12 corresponds to the "first control unit" in the present invention, and the LF receiving unit 13 and the UHF transmitting unit 14 correspond to the "first communication unit" in the present invention.

[0026] The vehicle control device 20 includes an operation unit 21 that is operated to cause the vehicle to perform a predetermined operation, a control unit 22 that is composed of a CPU, memory, etc., an LF transmission unit 23 that transmits an LF signal to the portable device 10, a UHF reception unit 24 that receives a UHF signal from the portable device 10, a CAN reception unit 25 and a CAN transmission unit 26 that perform CAN (Controller Area Network) communication, and an alarm unit 33 that issues an alarm to the user as described below.

[0027] As shown in Fig. 3, the operation unit 21 includes switches 53 provided on the handles of the left and right front doors 52 of the vehicle 50, a touch panel 54 provided on the instrument panel inside the passenger compartment 51, and an engine start button 55 provided in the driver's seat. The switch 53 is a switch for locking and unlocking the doors. The touch panel 54 is provided on a display device for car navigation. The engine start button 55 is composed of a push button switch or the like.

[0028] The control unit 22 includes an LF transmission necessity determination unit 27, an authentication unit 28, a control signal output unit 29, a portable device position detection unit 30, an alarm signal output unit 31, and a storage unit 32. When an operation is performed on the operation unit 21, the LF transmission necessity determination unit 27 determines whether or not it is necessary to transmit an LF signal (a response request signal) requesting a response from the portable device 10. When a UHF signal transmitted from the portable device 10 is received by the UHF receiving unit 24, the authentication unit 28 verifies whether or not an ID included in the UHF signal matches an ID stored in the storage unit 32. When the authentication unit 28 confirms that the IDs match, the control signal output unit 29 outputs a control signal for controlling the vehicle doors and engine via the CAN transmission unit 26. The portable device position detection unit 30 detects the location of the portable device 10 (inside or outside the vehicle) based on the strength of the UHF signal received from the portable device 10. The alarm signal output unit 31 outputs an alarm signal to notify the user when the portable device 10 is taken out of the vehicle with the engine running.

[0029] As shown in FIG. 4, the storage unit 32 stores security information and a portable device ID. The security information includes whether the security mode is ON (set) or OFF (not set), the security valid time period, and whether a security abnormality has occurred. The security mode is a mode for preventing a third party from performing an unauthorized unlocking by a relay attack. The security mode ON / OFF and valid time period are set by the user on the touch panel 54 of the operation unit 21 (FIG. 3) or on the user's smartphone. The presence or absence of a security abnormality is notified to the vehicle control device 20 from a gateway (not shown).

[0030] The LF transmitter 23 includes an interior antenna 23a and an exterior antenna 23b shown in Fig. 3. The interior antennas 23a are provided at the front and rear of the vehicle interior 51. The exterior antennas 23b are provided at the left and right front doors 52 of the vehicle 50, respectively.

[0031] A car navigation system 41 is connected to the CAN receiver 25. A smartphone system 42 is also connected to the CAN receiver 25 via a smartphone communication unit (not shown). GPS information required for car navigation and information input by the user from the smartphone are sent to the control unit 22 via the CAN receiver 25. A door lock system 43 and an engine system 44 are connected to the CAN transmitter 26. Control signals output by the control signal output unit 29 are sent to these systems 43 and 44 via the CAN transmitter 26.

[0032] The notification unit 33 is equipped with a buzzer, an indicator, etc. The notification unit 33 notifies the user of the operation performed on the operation units 11 and 21, and also issues a warning when the portable device 10 is taken out of the vehicle.

[0033] The operation unit 21 corresponds to the "second operation unit" in the present invention, the control unit 22 corresponds to the "second control unit" in the present invention, and the LF transmission unit 23 and the UHF reception unit 24 correspond to the "second communication unit" in the present invention.

[0034] Next, the operation of the vehicle control system 100 configured as above will be described.

[0035] Fig. 5 is a flowchart showing the operation of the first embodiment. In Fig. 5, the flowchart of the vehicle control device shows the procedure executed by the control unit 22, and the flowchart of the portable device shows the procedure executed by the control unit 12 (the same applies to Figs. 8 and 9 described later).

[0036] In step S2, the vehicle control device 20 waits for detection of a user operation of the operation unit 21. Then, in step S1, an operation such as locking or unlocking a door using the switch 53 in Fig. 3 or starting the engine using the engine start button 55 in Fig. 3 is performed, and when the user operation is detected (step S3: YES), the process proceeds to step S4.

[0037] In addition, in step S22, the portable device 10 waits for detection of a user operation of the operation unit 11. Then, if the lock button 11a or the unlock button 11b in Fig. 2 is pressed in step S21 and a user operation is detected (step S23; YES), the process proceeds to step S27, and if a user operation is not detected (step S23: NO), the process proceeds to step S24.

[0038] Vehicle control device 20 Now, following the operation of the operation unit 21, Steps S4 and S5 In The user's operation performed on the operation unit 21 is an operation that requires a response from the portable device 10. or an operation that does not require a response from the portable device 10. The LF transmission necessity determination unit 27 determines 。 In step S4, it is determined whether the operation performed by the user is an unlocking operation. If the determination result is that it is not an unlocking operation (step S4: NO), for example, if it is a locking operation or an engine start operation, the process proceeds to step S6. In step S6, Request a response from the portable device 10 An LF signal (response request signal) is transmitted from the LF transmitter 23 to the portable device 10. The transmitted LF signal includes the ID of the portable device 10.

[0039] On the other hand, if the result of the determination in step S4 is that the user operation is an unlock operation (step S4: YES), the process proceeds to step S5. In step S5, it is determined whether or not the security mode is ON based on the security information in the storage unit 32 shown in FIG.

[0040] If the result of the determination in step S5 is that the security mode is ON (step S5: YES), the process proceeds to step S11 (described later) without executing steps S6 to S10. On the other hand, if the security mode is OFF (step S5: NO), the process proceeds to step S6, where an LF signal (response request signal) is transmitted from the LF transmitter 23 to the portable device 10.

[0041] In step S24, the portable device 10 waits to receive an LF signal from the vehicle control device 20, and when the LF signal is received by the LF receiving unit 13, the process proceeds to step S25. In step S25, the received LF signal is authenticated. Specifically, the authentication unit 15 verifies whether or not the ID included in the LF signal matches the ID of the portable device 10 stored in the storage unit 16. If the result of the verification shows that the two IDs match (step S26: YES), the process proceeds to step S27, and if the two IDs do not match (step S26: NO), the process ends without executing step S27.

[0042] In step S27, a UHF signal is transmitted from the UHF transmitter 14. In this case, the UHF signal is a "response signal" in response to the LF signal (response request signal). On the other hand, if an operation is performed on the operation unit 11 of the portable device 10 in step S21 (step S23: YES), the UHF signal transmitted in step S27 is an "operation signal" indicating the content of the operation (lock or unlock). The response signal and operation signal include the ID of the portable device 10.

[0043] In step S7, the vehicle control device 20 waits to receive a UHF signal from the portable device 10, and when the UHF signal is received by the UHF receiving unit 24, the process proceeds to step S8. In step S8, the received UHF signal is authenticated. Specifically, the authentication unit 28 verifies whether the ID included in the UHF signal matches the ID of the portable device 10 stored in the storage unit 32 (see FIG. 4). If the result of the verification shows that the two IDs match (step S9: YES), the process proceeds to step S10, and if the two IDs do not match (step S9: NO), the process ends without executing steps S10 to S12.

[0044] In step S10, control signal output unit 29 outputs a control signal for performing a predetermined control on the vehicle. Specifically, if the UHF signal received in step S7 is a response signal to the LF signal, a control signal corresponding to the operation of operation unit 21 in step S1 is output via CAN transmitter 26. For example, if the operation of operation unit 21 is a locking operation or an unlocking operation, CAN transmitter 26 outputs a locking signal or an unlocking signal to door lock system 43. Furthermore, if the operation of operation unit 21 is an engine starting operation, CAN transmitter 26 outputs an engine starting signal to engine system 44.

[0045] On the other hand, if the UHF signal received in step S7 is an operation signal based on an operation on the portable device 10, a control signal corresponding to the operation of the operation unit 11 in step S21 is output via the CAN transmitter 26. That is, if the operation of the operation unit 11 is a lock operation, a lock signal is output to the door lock system 43, and if the operation of the operation unit 11 is an unlock operation, an unlock signal is output to the door lock system 43.

[0046] When the above-described control signal is output, in step S13, a control operation is executed in accordance with the operation of the operation units 11, 21. In detail, if the control signal is a lock signal, the vehicle doors are locked, if the control signal is an unlock signal, the vehicle doors are unlocked, and if the control signal is an engine start signal, the vehicle engine is started.

[0047] In addition, in step S13, measures to prevent the portable device 10 from being locked inside and measures to warn against taking out the portable device 10 are also carried out.

[0048] For example, in the case of the portable device 10 being locked out, if the portable device 10 is left behind inside the vehicle 50 as shown in Fig. 6, the portable device 10 is within the range Za of the radio waves from the interior antenna 23a and is therefore able to communicate with the vehicle control device 20. When a locking operation is performed using the switch 53 of the operation unit 21, if the portable device position detection unit 30 detects that the portable device 10 is inside the vehicle based on the response signal transmitted from the portable device 10, the control signal output unit 29 is prevented from outputting a lock signal. This prohibits the doors from being locked, thereby preventing the portable device 10 from being locked out inside the vehicle.

[0049] Regarding the portable device 10 being taken out of the vehicle, the portable device position detection unit 30 starts detecting the position of the portable device 10 when the vehicle door is opened and then closed. Then, as shown in FIG. 7 , when the portable device 10 is taken out of the vehicle by someone other than the driver and is no longer within the range Zb of the radio waves from the exterior antenna 23b, the vehicle control device 20 no longer receives a response signal from the portable device 10. This causes the portable device position detection unit 30 to detect that the portable device 10 is outside the vehicle. As a result, an alarm signal is output from the alarm signal output unit 31, and based on this signal, a warning is issued by the buzzer or indicator of the notification unit 33, so that it is possible to prevent the vehicle from starting when the portable device 10 is not inside the vehicle.

[0050] When the process of step S10 is completed, the process proceeds to step S11. In step S11, it is determined whether or not a notification to the user is required regarding the operations in steps S1 and S21. If a locking operation or an unlocking operation has been performed, it is determined that a notification is required (step S11: YES) and the process proceeds to step S12. If an operation other than these has been performed, it is determined that a notification is not required (step S11: NO) and the process ends without executing step S12.

[0051] In step S12, the buzzer of the notification unit 33 sounds in three different patterns depending on the operation performed by the user. Specifically, if the user performs a lock operation in steps S1 and S21, the buzzer sounds in pattern A to notify that the door is locked. Also, if the user performs an unlock operation in step S1 and the security mode is not ON in step S5, or if the user performs an unlock operation in step S21, the buzzer sounds in pattern B to notify that the door is unlocked. On the other hand, if the user performs an unlock operation in step S1 and the security mode is ON in step S5, the buzzer sounds in pattern C to notify that the door is not unlocked.

[0052] These patterns differ in the number of times the buzzer sounds, the duration of the sounds, or the interval between sounds, allowing the user to confirm which operation he or she performed. In particular, if the unlocking operation is performed on the vehicle side (step S1), the doors will not be unlocked if the security mode is ON, which can cause anxiety to the user if no notification is given. However, in the present invention, the buzzer sounds in pattern C, allowing the user to know why the doors will not be unlocked.

[0053] According to the first embodiment described above, when a third party operates the switch 53 of the vehicle 50 to perform an unlock operation (step S4: YES in FIG. 5), if the security mode is set to ON (step S5: YES), the vehicle control device 20 does not transmit an LF signal, i.e., a response request signal, to the portable device 10. Therefore, no response signal is returned from the portable device 10 to the vehicle control device 20. As a result, the control signal output unit 29 of the vehicle control device 20 does not output an unlock signal to the door lock system 43, and the doors of the vehicle 50 are not unlocked.

[0054] Therefore, even if a third party attempts to unlock the doors of the vehicle 50 by a relay attack using a repeater, he or she will not be able to steal either the response request signal from the vehicle control device 20 or the response signal from the portable device 10, making it impossible to unlock the doors by relaying these signals.

[0055] On the other hand, when the security mode is ON, the authorized user of the vehicle 50 cannot unlock the doors by operating the switch 53 on the vehicle side. However, by pressing the unlock button 11b (FIG. 2) on the portable device 10, an operation signal indicating unlock is transmitted from the portable device 10 to the vehicle control device 20 (steps S21 to S23, S27 in FIG. 5), and the doors can be unlocked. Conversely, when the security mode is ON, the doors cannot be unlocked unless an unlock operation is performed on the portable device 10. Furthermore, because the portable device 10 is owned by the user, a third party cannot unlock the doors by operating the portable device 10.

[0056] Furthermore, when a user unlocks the door using the portable device 10, the user operates the portable device 10 near the vehicle, so it is virtually impossible for a third party to use a repeater near the vehicle where the user is located to relay the transmission signal (operation signal) from the portable device 10.

[0057] As described above, by prohibiting unauthorized door unlocking by a third party, crimes such as theft of the vehicle 50 and items inside the vehicle compartment 51 can be prevented. In particular, in the case of the present invention, even if a third party performs an unlocking operation of the door while the security mode is ON, the third party cannot steal both the response request signal from the vehicle control device 20 and the response signal from the portable device 10. Therefore, even if the anti-tampering algorithm (FIG. 5) is known to a third party, unlocking by a relay attack can be reliably prevented. Furthermore, a vehicle control system 100 that exhibits excellent security functions against relay attacks can be realized by a simple method of selecting whether or not to send a response request signal, without requiring complex processing or operations.

[0058] On the other hand, if the operation on the vehicle side is a locking operation or an engine start operation other than an unlocking operation (step S4: NO), or if the operation is an unlocking operation but the security mode is OFF (step S5: NO), an LF signal, i.e., a response request signal, is sent from the vehicle control device 20 to the portable device 10 (step S6), and a response signal is returned from the portable device 10 to the vehicle control device 20 (step S27).

[0059] However, in the case of a locking operation, the doors will not be unlocked even if a relay attack is performed, so there is no risk of theft of the vehicle 50 or items inside the vehicle. Also, in the case of an engine start operation, an LF signal is not transmitted from the vehicle control device 20 unless the engine start button 55 is pressed inside the vehicle, so a relay attack is not a problem. Also, the security mode being set to OFF is something that the user has decided to do so so that the doors can be unlocked without operating the portable device 10, and when the security mode is OFF, there is a situation where the vehicle is in a location where there is no risk of a relay attack, so there is little possibility of a third party committing fraud.

[0060] In this way, for operations other than unlocking, mutual communication between the portable device 10 and the vehicle control device 20 is suspended, ensuring convenience for the user. For example, if the user gets out of the vehicle 50 and performs a locking operation using the door switch 53, the doors of the vehicle 50 can be locked, as in the past, without operating the lock button 11a on the portable device 10. Furthermore, even if a locking operation is performed while the portable device 10 is left inside the vehicle, as described above, the fact that the portable device 10 has been left behind can be detected based on the response signal from the portable device 10, and the door locking can be prohibited, thereby preventing the portable device 10 from being locked inside the vehicle.

[0061] Fig. 8 is a flowchart showing the operation of the second embodiment. In Fig. 8, step S5a is added after step S5 in Fig. 5. The determinations in steps S4, S5, and S5a are made by the LF transmission necessity determination unit 27. In step S5a, if the security mode is OFF (step S5: NO), it is determined whether the current time is within a preset security valid time period (see Fig. 4).

[0062] If the result of the determination in step S5a is that the current time is not within the valid time period (step S5a: NO), the process proceeds to step S6, and an LF signal (response request signal) is transmitted from the LF transmitter 23 to the portable device 10. On the other hand, if the current time is within the valid time period in step S5a (step S5a: YES), the process proceeds to step S11 without executing step S6. The other steps are the same as in Fig. 5, so a description of the steps that overlap with Fig. 5 will be omitted.

[0063] According to the second embodiment, even if the security mode is OFF, if the current time is within the valid time of security, the vehicle control device 20 does not transmit an LF signal (response request signal), and therefore no response signal is transmitted from the portable device 10 to the vehicle control device 20. Therefore, even if the user forgets to set the security mode ON, unauthorized unlocking of the doors by a third party can be prevented.

[0064] Fig. 9 is a flowchart showing the operation of the third embodiment. In Fig. 9, step S5b is added after step S5a in Fig. 8. The determinations of steps S4, S5, S5a, and S5b are made by the LF transmission necessity determination unit 27. In step S5b, if the security mode is OFF (step S5: NO) and the current time is outside the valid time zone (step S5a: NO), it is determined whether a security abnormality (see Fig. 4) has occurred. For example, if an unauthorized intrusion is detected in the gateway, it is determined that a security abnormality has occurred.

[0065] If the result of the determination in step S5b is that no security abnormality has occurred (step S5b: NO), the process proceeds to step S6, and an LF signal (response request signal) is transmitted from the LF transmitter 23 to the portable device 10. On the other hand, if a security abnormality has occurred in step S5b (step S5b: YES), the process proceeds to step S11 without executing step S6. The other steps are the same as in Fig. 5, and therefore a description of steps that overlap with Fig. 5 will be omitted.

[0066] According to the third embodiment, even if the security mode is OFF and the current time is outside the valid time of the security, if a security abnormality occurs, the vehicle control device 20 does not transmit an LF signal (a response request signal), and therefore no response signal is transmitted from the portable device 10 to the vehicle control device 20. This makes it possible to more effectively prevent fraudulent acts by third parties.

[0067] In addition to the above-described embodiment, the present invention can employ various other embodiments as follows.

[0068] In the above embodiment, when a locking operation or an unlocking operation is performed, the notification unit 33 notifies by sounding a buzzer, but instead of this, the notification may be made by displaying an indicator. Alternatively, sounding a buzzer and displaying an indicator may be used in combination.

[0069] Furthermore, in the above embodiment, an example was given in which the notification unit 33 was provided only in the vehicle control device 20, but a similar notification unit may also be provided in the portable device 10.

[0070] In the above embodiment, whether or not the security mode is set is determined in step S5 in FIGS. 5, 8, and 9, but this step S5 may be omitted.

[0071] In the above embodiment, LF signals and UHF signals are used for communication between the portable device 10 and the vehicle control device 20, but signals other than these may also be used.

[0072] In addition, in the above embodiment, an example was given in which the car navigation system 41 and the smartphone system 42 were connected to the CAN receiver 25, but other systems may be added. Similarly, in the above embodiment, an example was given in which the door lock system 43 and the engine system 44 were connected to the CAN transmitter 26, but other systems may be added.

[0073] In addition, in the above embodiment, an example was given in which the vehicle control device 20 and each system 41 to 44 were connected via CAN, but the vehicle control device 20 and each system 41 to 44 may also be connected via a network other than CAN, such as LIN (Local Interconnect Network). [Explanation of symbols]

[0074] 10. Portable devices 11 Operation unit (1st operation unit) 12 control unit (first control unit) 13 LF receiver (first communication unit) 14 UHF transmitter (first communication unit) 20 Vehicle control device 21 Operation unit (second operation unit) 22 control unit (second control unit) 23 LF transmitter (communication unit, second communication unit) 24 UHF receiver (communication unit, second communication unit) 30 Portable device position detection unit 33 Information Department 50 vehicles 100 Vehicle Control System

Claims

1. a vehicle control device that is mounted on a vehicle and performs predetermined control on the vehicle; a portable device that wirelessly communicates with the vehicle control device, The portable device includes: a first operation unit that is operated to cause the vehicle to perform a predetermined operation; a first communication unit that communicates with the vehicle control device; a first control unit that controls the first communication unit, The vehicle control device includes: a second operating unit that is operated to cause the vehicle to perform a predetermined operation; a second communication unit that communicates with the first communication unit; a second control unit that performs predetermined control on the vehicle based on operation of the first operation unit or the second operation unit, The second control unit is When the second operation unit is operated, following the operation, it is determined whether the operation of the second operation unit is an operation that requires a response from the portable device or an operation that does not require a response from the portable device; If the operation requires a response, a response request signal is transmitted from the second communication unit to the portable device. If the operation does not require a response, the response request signal is not transmitted from the second communication unit to the portable device, the first control unit, when the first communication unit receives the response request signal, transmits a response signal from the first communication unit; The vehicle control system is characterized in that, when the second communication unit receives the response signal, the second control unit controls the vehicle in accordance with the operation of the second operation unit.

2. 2. The vehicle control system according to claim 1, When the first operation unit is operated, the first control unit transmits an operation signal indicating the content of the operation from the first communication unit; The vehicle control system is characterized in that, when the second communication unit receives the operation signal, the second control unit controls the vehicle in accordance with the operation of the first operation unit.

3. 3. The vehicle control system according to claim 1, The second control unit is When the operation of the second operation unit is an unlocking operation for unlocking a door of the vehicle, the response request signal is not transmitted from the second communication unit, A vehicle control system, characterized in that, when the operation of the second operation unit is a lock operation for locking a door of the vehicle, the response request signal is transmitted from the second communication unit.

4. 4. The vehicle control system according to claim 3, The second control unit is When the operation of the second operation unit is an unlocking operation, it is determined whether a security mode for preventing unauthorized unlocking is set or not; If the security mode is set, the response request signal is not transmitted from the second communication unit.

5. 5. The vehicle control system according to claim 3, wherein: The second control unit is Determine whether the current time is within a preset security valid time period; If the current time is within the security valid time period, the response request signal is not transmitted from the second communication unit.

6. 6. The vehicle control system according to claim 5, The second control unit is If the current time is outside the range of the security valid time zone, it is determined whether or not a security abnormality has occurred; A vehicle control system, characterized in that if a security abnormality occurs, the response request signal is not transmitted from the second communication unit.

7. A vehicle control device that is mounted on a vehicle, performs predetermined control of the vehicle, and wirelessly communicates with a portable device carried by a user of the vehicle, an operation unit that is operated to cause the vehicle to perform a predetermined operation; a communication unit that communicates with the portable device; a control unit that performs predetermined control of the vehicle based on an operation of the operation unit, The control unit When the operation unit is operated, the operation unit is subsequently determined to be either an operation that requires a response from the portable device or an operation that does not require a response from the portable device; If the operation requires a response, a response request signal is transmitted from the communication unit to the portable device. If the operation does not require a response, the response request signal is not transmitted from the communication unit to the portable device, When the communication unit receives a response signal from the portable device, the vehicle control device performs control on the vehicle in accordance with the operation of the operation unit.

8. The vehicle control device according to claim 7, The vehicle control device is characterized in that, when a predetermined operation is performed on the portable device, the control unit performs control of the vehicle in accordance with the operation when the communication unit receives an operation signal indicating the content of the operation transmitted from the portable device.

9. The vehicle control device according to claim 7 or 8, a portable device location detection unit that detects the location of the portable device based on the response signal transmitted from the portable device; The vehicle control device is characterized in that, when a locking operation to lock the vehicle doors is performed using the operation unit, if the portable device position detection unit detects that the portable device is inside the vehicle, the control unit prohibits the doors from being locked.

10. 10. The vehicle control device according to claim 7, further comprising a notification unit that notifies the user of the operation performed by the operation unit; The vehicle control device is characterized in that, when an unlocking operation to unlock a vehicle door is performed using the operating unit, if a security mode for preventing unauthorized unlocking is set, the notification unit issues a notification in a pattern different from that when the security mode is not set.

Citation Information

Patent Citations

  • Antishift device for vehicle

    JP1988269759A

  • Vehicular security device

    JP2008030670A

  • Door lock device for vehicle

    JP2008179980A

  • Vehicle condition informing device

    JP2010089553A

  • Electronic key system

    JP2011247076A