Information processing device and information processing method

The information processing device prioritizes biometric authentication over device authentication to accurately identify vehicle drivers, addressing inconsistencies in shared user devices, and ensuring secure and convenient vehicle operation.

JP7736497B2Active Publication Date: 2025-09-09TOYOTA JIDOSHA KK +1
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2021152213
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-09-17
Publication Date
2025-09-09
Estimated Expiration
2041-09-17

AI Technical Summary

Technical Problem

Existing vehicle identification systems struggle to accurately identify the driver when user devices are shared or borrowed between individuals, leading to inconsistencies in authentication results.

Method used

An information processing device that prioritizes biometric authentication based on a user's body parts over device authentication, using a control unit to ensure accurate driver identification by integrating fingerprint and face recognition with communication terminal authentication, and allowing users to selectively link their body parts and devices to their identity.

Benefits of technology

Enhances driver identification accuracy by prioritizing biometric authentication, ensuring reliable user identification even when user devices are shared, and providing secure and convenient vehicle operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007736497000001
    Figure 0007736497000001
  • Figure 0007736497000002
    Figure 0007736497000002
  • Figure 0007736497000003
    Figure 0007736497000003
Patent Text Reader

Abstract

To provide a technique capable of more accurately specifying a user driving a vehicle.SOLUTION: An information processor includes a control part for specifying a driver of a vehicle on the basis of at least one authentication result of first authentication based on a first part of a living body of a user and second authentication based on a user device. The control part specifies a driver of a vehicle with a priority to the authentication result of the first authentication compared to the authentication result of the second authentication. The user device can include a first communication terminal having a function as an electronic key of the vehicle, and a second communication terminal which does not have a function as the electronic key of the vehicle. In this case, the control part specifies the driver of the vehicle with a priority to the authentication result of the first communication terminal compared to the authentication result of the second communication terminal.SELECTED DRAWING: Figure 8
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an information processing device and an information processing method. [Background technology]

[0002] There is known a technique for identifying a user who drives a vehicle by associating a different user with each user device, such as a smartphone (see, for example, Patent Document 1). [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2017-082396 Summary of the Invention [Problem to be solved by the invention]

[0004] An object of the present disclosure is to provide a technology that can more accurately identify a user who is driving a vehicle. [Means for solving the problem]

[0005] The present disclosure can be understood as an information processing device. In this case, the information processing device includes, for example, An information processing device that identifies a driver of a vehicle based on at least one of a first authentication based on a first part of a user's body and a second authentication based on a user device, The vehicle driver may be identified by a control unit that prioritizes the result of the first authentication over the result of the second authentication.

[0006] Another aspect of the present disclosure may be an information processing method. In this case, the information processing method may include, for example, An information processing method for identifying a driver of a vehicle based on at least one of a first authentication based on a first part of a user's body part and a second authentication based on a user device, the method comprising: The computer may identify the driver of the vehicle by prioritizing the result of the first authentication over the result of the second authentication.

[0007] The present disclosure can also be understood as a program for causing a computer to execute the above-described information processing method, or a non-transitory storage medium for storing the program. [Effects of the Invention]

[0008] According to the present disclosure, it is possible to provide a technology that can more accurately identify a user who is driving a vehicle. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 1 is a diagram illustrating a schematic configuration of a driver identification system. [Figure 2] FIG. 2 is a diagram illustrating an example of the hardware configuration of an in-vehicle device and a user device included in the driver identification system. [Figure 3] FIG. 2 is a block diagram showing an example of the functional configuration of a body ECU. [Figure 4] 3 is a diagram showing an example of the configuration of a driver information table registered in a driver information DB; FIG. [Figure 5] FIG. 10 is a diagram showing an example of a first screen output on a touch panel display of the input / output unit. [Figure 6] FIG. 10 is a diagram showing an example of a second screen output on the touch panel display of the input / output unit. [Figure 7] FIG. 10 is a diagram showing an example of a third screen output on the touch panel display of the input / output unit. [Figure 8] 10 is a flowchart showing a processing routine executed by a body ECU when a vehicle door is unlocked as a trigger. [Figure 9]10 is a flowchart showing a processing routine executed by a body ECU when it is determined that the driver of the vehicle is a guest user. DETAILED DESCRIPTION OF THE INVENTION

[0010] The information processing device disclosed herein is applied to a driver identification system. The driver identification system identifies a vehicle driver and reflects setting values ​​corresponding to the identified driver in on-board devices. The setting values ​​corresponding to the identified driver include, for example, at least one of setting values ​​related to a driving position, setting values ​​related to multimedia, setting values ​​related to an advanced safety system, and setting values ​​related to a body system. The body system setting values ​​include, for example, setting values ​​for automatic headlights, automatic wipers, automatic locking, automatic unlocking, air conditioning system setting values, and interior lighting setting values.

[0011] In the driver identification system, a driver is identified based on authentication results such as biometric authentication (first authentication) based on a first part of the user's body and device authentication (second authentication) based on a communication terminal (user device) carried by the user. For example, if the first authentication is successful, the user associated with the first part to be authenticated is identified as the driver of the vehicle. Furthermore, if the second authentication is successful, the user associated with the user device to be authenticated is identified as the driver of the vehicle.

[0012] The user device includes a communication terminal (first communication terminal) that can function as an electronic key for a vehicle, and a communication terminal (second communication terminal) that cannot function as an electronic key for a vehicle. The first communication terminal has, for example, a function to unlock and lock the vehicle doors and a function to start the engine of the vehicle. Such a first communication terminal is, for example, a smart key or a digital key. The second communication terminal is, for example, a smartphone.

[0013] However, in a vehicle equipped with both a function for performing first authentication and a function for performing second authentication, the user identified based on the result of the first authentication does not necessarily match the user identified based on the result of the second authentication. For example, it is conceivable that a user driving a vehicle may carry a user device linked to another user, such as when user devices are lent and borrowed between family members. In such cases, the user identified based on the result of the first authentication does not match the user identified based on the result of the second authentication. As a result, it may be impossible to accurately identify the driver of the vehicle.

[0014] In response to this, the information processing device according to the present disclosure is provided with a control unit that identifies the driver of the vehicle by prioritizing the authentication result of the first authentication over the authentication result of the second authentication. The information processing device is not limited to a device mounted on a vehicle, but may be a server device capable of communicating with the vehicle. The control unit may be, for example, a processor such as a CPU (Control Processing Unit). It is Sessa.

[0015] According to the information processing device of the present disclosure, when a user identified based on the authentication result of the first authentication does not match a user identified based on the authentication result of the second authentication, The user identified based on the authentication result of the first authentication is identified as the driver of the vehicle. Although user devices can be lent and borrowed between users, the first part cannot be lent and borrowed between users. Therefore, identification of a user based on the authentication result of the first authentication is more reliable than identification of a user based on the authentication result of the second authentication. Therefore, it is possible to more accurately identify the driver of the vehicle.

[0016] The first part in the present disclosure may include, for example, a user's finger and a user's face. In this case, the first authentication may include fingerprint authentication based on the finger and face authentication based on the face. That is, a vehicle to which an information processing device according to the present disclosure is applied may be a vehicle equipped with a fingerprint authentication function and a face authentication function. In this case, the control unit of the information processing device according to the present disclosure may prioritize the fingerprint authentication result over the face authentication result to identify the driver of the vehicle. This is based on the finding that user identification based on the fingerprint authentication result is more reliable than user identification based on the face authentication result. Therefore, even in a vehicle equipped with a fingerprint authentication function and a face authentication function, it is possible to more accurately identify the driver of the vehicle.

[0017] As described above, a user device used by a vehicle user may include a first communication terminal that functions as an electronic key for the vehicle and a second communication terminal that does not function as an electronic key for the vehicle. Therefore, the second authentication in the present disclosure may include authentication of the first communication terminal and authentication of the second communication terminal. That is, a vehicle to which an information processing device according to the present disclosure is applied may be a vehicle equipped with a function for authenticating the first communication terminal and a function for authenticating the second communication terminal. In this case, the control unit of the information processing device according to the present disclosure may prioritize the authentication result of the first communication terminal over the authentication result of the second communication terminal to identify the driver of the vehicle. This is based on the finding that user identification based on the authentication result of the first communication terminal is more reliable than user identification based on the authentication result of the second communication terminal. Therefore, even in a vehicle equipped with a function for authenticating the first communication terminal and a function for authenticating the second communication terminal, it is possible to more accurately identify the driver of the vehicle.

[0018] The information processing device according to the present disclosure may further include a storage unit that stores data linking a first body part to a user and data linking a user device to a user. In this case, the control unit may identify a first user linked to the first body part that has successfully passed the first authentication based on the data stored in the storage unit, identify a second user linked to the user device that has successfully passed the second authentication based on the data stored in the storage unit, and, if the first user and the second user are different, identify the first user as the driver of the vehicle. This allows the driver of the vehicle to be identified more accurately.

[0019] Here, the user may be allowed to arbitrarily select whether or not to link the first portion and / or user device to the user. This is because it is conceivable that a user who does not wish to link the first portion and / or user device to the user may drive a vehicle. It is also conceivable that a first communication terminal that operates as an electronic key for a vehicle, such as a smart key, may be shared by multiple users.

[0020] Therefore, the control unit of the information processing device according to the present disclosure may be configured to receive a selection of whether or not to associate the first portion and / or user device with the user, and when the selection of associating the first portion and / or user device with the user is received, store data associating the first portion and / or user device with the user in the storage unit, and when the selection of not associating the first portion and / or user device with the user is received, not store data associating the first portion and / or user device with the user in the storage unit. This allows the user to As a result, in an environment where a first communication terminal is shared by multiple users, it is possible to ensure user convenience.

[0021] In a configuration in which a user can arbitrarily select whether to link a first region and / or a user device to the user, a situation may occur in which a first region that has successfully passed the first authentication is not linked to the user, and a user device that has successfully passed the second authentication is not linked to the user. Furthermore, from the viewpoint of security, a limit may be placed on the total number of users that can be linked to a first region and a user device. That is, a limit may be placed on the number of users that can be registered as vehicle drivers. As a result, a situation may occur in which neither data linking a first region that has successfully passed the first authentication to the user nor data linking a user device that has successfully passed the second authentication to the user is stored in the storage unit. In such a situation, the driver of the vehicle cannot be identified.

[0022] Therefore, when neither data linking the first part that has been successfully authenticated with the user nor data linking the user device that has been successfully authenticated with the second part is stored in the storage unit, the control unit of the information processing device according to the present disclosure may determine that the driver of the vehicle is a guest user. This makes it possible to handle situations where a user who is not linked to either the first part or the user device is driving the vehicle.

[0023] Here, biometric information (fingerprint data) used for fingerprint authentication, which is one of the first authentications, is acquired by, for example, a fingerprint sensor provided on the door handle on the outside of the vehicle door, or a fingerprint sensor provided on a start button (a button for starting the engine) inside the vehicle. Acquisition of fingerprint data by the fingerprint sensor can be triggered by the door opening operation or the engine starting operation by the user driving the vehicle. Therefore, fingerprint authentication can be performed by triggering the door opening operation or the engine starting operation by the user driving the vehicle.

[0024] Biometric information (image data of a face) used for face authentication, which is one of the first authentication methods, is acquired, for example, by a camera installed inside the vehicle. The acquisition of face image data by the camera is triggered by the user who drives the vehicle sitting in the driver's seat. This allows face authentication to be performed when the user who drives the vehicle sits in the driver's seat.

[0025] Information used for authenticating the first communication terminal, which is one of the second authentications (for example, a key ID assigned to the first communication terminal), is acquired by short-range wireless communication between the vehicle and the first communication terminal. The short-range wireless communication between the vehicle and the first communication terminal is triggered by a predetermined vehicle operation by the user driving the vehicle. The predetermined vehicle operation includes, for example, unlocking the doors or starting the engine. This allows authentication of the first communication terminal, which is one of the second authentications, to be performed by being triggered by the unlocking of the doors or starting the engine by the user driving the vehicle.

[0026] As described above, fingerprint authentication, which is one of the first authentications, face authentication, which is one of the first authentications, and authentication of the first communication terminal, which is one of the second authentications, are triggered by an event that occurs during the period from when the door is unlocked to when the engine is started. Therefore, even if the vehicle starts to travel immediately after the engine is started, the above authentications can be completed before the vehicle starts to travel, and the driver can also be identified based on the authentication results.

[0027] On the other hand, the authentication of the second communication terminal, which is one of the second authentications, is, for example, The authentication of the second communication terminal is performed through a head unit or the like that provides the service. The head unit authenticates the second communication terminal by attempting to establish a communication connection between the head unit and the second communication terminal. That is, if a communication connection between the head unit and the second communication terminal is established, it is determined that the authentication of the second communication terminal is successful. On the other hand, if a communication connection between the head unit and the second communication terminal is not established, it is determined that the authentication of the second communication terminal is unsuccessful. When using such a method, the head unit attempts to establish a communication connection with the second communication terminal that is associated with the user in the storage unit. If a communication connection with the second communication terminal is established, it is determined that the authentication of the second communication terminal, which is one of the second authentications, is successful. However, if there are multiple second communication terminals that are associated with the user in the storage unit and attempts are made to establish communication connections with the multiple second communication terminals, it may be impossible to complete the authentication of the second communication terminal before the vehicle starts traveling. In response to this, a method can be considered in which a communication connection is attempted to be established only with a specific second communication terminal, for example, the second communication terminal associated with the user last identified as the driver among the second communication terminals associated with users in the storage unit.

[0028] However, if the second communication terminal associated with the user attempting to drive the vehicle is different from the specific second communication terminal, a communication connection is not established between the second communication terminal and the head unit, and authentication of the second communication terminal, which is one of the second authentications, fails. Therefore, if the user attempting to drive the vehicle is associated only with the second communication terminal (if the user is not associated with the first body part and the first communication terminal), there is a possibility that the user will not be identified as the driver of the vehicle.

[0029] Therefore, after determining that the driver of the vehicle is a guest user, a control unit of the information processing device according to the present disclosure may attempt to establish a communication connection with a second communication terminal other than the specific second communication terminal among the second communication terminals associated with the user. This process may be performed by attempting to establish a communication connection using a hands-free profile through a first device (e.g., the head unit described above) for providing a hands-free calling function. When a communication connection using the hands-free profile between the first device and the second communication terminal is established, the control unit may output information suggesting a change to a user (third user) associated with the second communication terminal with which the communication connection has been established. The control unit may accept an operation requesting a change to the third user and change the driver of the vehicle from the guest user to the third user. This makes it possible to accurately identify the driver of the vehicle even when the user attempting to drive the vehicle is associated only with the second communication terminal and the second communication terminal is different from the specific second communication terminal.

[0030] The user information stored in the storage unit of the present disclosure may include information regarding user-specific setting values ​​of the devices installed in the vehicle. In this case, the control unit may set the devices installed in the vehicle according to the setting values ​​included in the user information of the user identified as the driver of the vehicle. This allows the setting values ​​corresponding to the identified driver to be automatically reflected in the devices installed in the vehicle.

[0031] The present disclosure can also be understood as an information processing method in which a computer executes the above-described processes, or an information processing program for causing a computer to execute the above-described processes. In this case, the computer corresponds to the above-described information processing device.

[0032] <Embodiment> Specific embodiments of the present disclosure will be described below with reference to the drawings. The configurations described in the present embodiments are merely examples, and the present disclosure is not limited to the configurations exemplified in the examples.

[0033] (System Overview) Fig. 1 is a diagram showing a schematic configuration of a driver identification system to which the present disclosure is applied. The driver identification system in this embodiment includes an on-board device 100 mounted on a vehicle 10 and a user device 20 used by a user of the vehicle 10. The user device 20 includes a smart key 21, a digital key 22, a BL device 23, etc. In the example shown in Fig. 1, only one smart key 21, one digital key 22, and one BL device 23 are shown, but there may be multiple of each.

[0034] The in-vehicle device 100 has a function of authenticating the user device 20, a function of identifying the driver of the vehicle 10, and a function of configuring the vehicle 10 in accordance with the identified driver.

[0035] The smart key 21 is an electronic key for the vehicle 10. The digital key 22 is a personal terminal of the user that can operate in the same manner as the electronic key for the vehicle 10. The BL device 23 is a personal terminal of the user that cannot operate in the same manner as the electronic key for the vehicle 10.

[0036] (System hardware configuration) FIG. 2 is a diagram showing an example of the hardware configuration of the in-vehicle device 100 and the user device 20 included in the driver identification system.

[0037] (In-vehicle device 100)

[0038] The in-vehicle device 100 is mounted on the vehicle 10 and controls various operations of the vehicle 10, and constitutes a part of the smart key system. In this example, the in-vehicle device 100 includes an LF transmitter 101, an RF receiver 102, a short-range communication unit 103, a sensor 104, a head unit 105, a verification ECU 106, a body ECU 107, an input / output unit 108, and in-vehicle equipment 109.

[0039] The LF transmitter 101 transmits radio waves in the LF (Low Frequency) band (for example, 30 kHz to 300 The LF transmitter 101 transmits a signal using radio waves of 100 kHz. The signals transmitted by the LF transmitter 101 include, for example, a polling signal for searching for the smart key 21, and a signal (Request signal) for requesting the smart key 21 for the key ID (hereinafter sometimes referred to as the "first key ID") assigned to the smart key 21. The LF transmitter 101 is configured so that the radio waves transmitted from the LF transmitter 101 reach only the vicinity of the vehicle 10 (for example, an area within one meter of the vehicle 10).

[0040] The RF receiver 102 receives radio waves in the RF (Radio Frequency) band (for example, 100 MHz to 3 The RF receiver 102 receives a signal based on a frequency of 100 MHz (radio waves of 100 GHz). The signal received by the RF receiver 102 includes, for example, a response signal (Ack signal) from the smart key 21 in response to a polling signal, and a response signal (Response signal) from the smart key 21 in response to a Request signal. The Response signal is a signal that includes the first key ID of the smart key 21.

[0041] The short-range communication unit 103 transmits and receives data to and from the digital key 22 and the BL device 23 using wireless communication such as BLE (Bluetooth (registered trademark) Low Energy) standard wireless communication or NFC (Near Field Communication). For example, the short-range communication unit 103 broadcasts a polling signal for searching for the digital key 22 and a Request signal for requesting the digital key 22 for a key ID (hereinafter, sometimes referred to as a "second key ID") assigned to the digital key 22, and transmits a response signal to the signal (for example, an Ack signal in response to the polling signal and a Request signal in response to the Request signal). The key ID received from the digital key 22 is transmitted to the short-range communication unit 103 via an in-vehicle network such as a CAN (Controller Area Network) as a verification E. It is sent to the CU 106.

[0042] The short-range communication unit 103 also establishes a communication connection with the BL device 23 using SPP (Serial Port Profile) and a communication connection with the BL device 23 using HFP (Hands Free Profile). When a communication connection with the BL device 23 is established, the short-range communication unit 103 transmits identification information of the BL device 23 with which the communication connection has been established to the body ECU 107 via the in-vehicle network.

[0043] The communication range of the short-range communication unit 103 is limited to the vicinity of the vehicle 10 (for example, within one meter from the vehicle 10).

[0044] The sensor 104 detects biometric information of the user driving the vehicle 10. The sensor 104 of this embodiment includes a fingerprint sensor that acquires fingerprint data of the user driving the vehicle 10 and a camera that acquires image data of the face of the user driving the vehicle 10 (hereinafter, sometimes referred to as "face image data"). The fingerprint sensor may be attached, for example, to a door handle on the outside of the vehicle 10, or to a start button (a button for switching on / off the accessory power and starting / stopping the engine) inside the vehicle 10. The camera is installed, for example, in front of the driver's seat inside the vehicle 10. The fingerprint sensor acquires fingerprint data when, for example, the user's finger touches the door handle while the doors of the vehicle 10 are locked, or when the user's finger touches the start button while the engine is stopped. The camera acquires face image data when, for example, the user sits in the driver's seat. The user's seating in the driver's seat is detected by a seating sensor or the like attached to the driver's seat. The fingerprint data and facial image data acquired by the sensor 104 are transmitted from the sensor 104 to the verification ECU 106 via the in-vehicle network.

[0045] The head unit 105 is a device that provides infotainment services such as multimedia, car navigation, and the Internet to the occupants of the vehicle 10, and corresponds to a "first device" according to the present disclosure. In this embodiment, the head unit 105 has a function of attempting to establish a communication connection with a specific BL device 23 by SPP via the short-range communication unit 103. The attempt is performed during a period from when the doors of the vehicle 10 are unlocked until a first length of time has elapsed (hereinafter, also referred to as a "predetermined period"). The first length of time is shorter than the average length of time required from when the doors of the vehicle 10 are unlocked until the vehicle 10 starts moving, and is, for example, approximately 5 seconds. If a communication connection with the specific BL device 23 is established within the predetermined period of time, the head unit 105 determines that authentication of the specific BL device 23 has been successful. In this case, the head unit 105 transmits identification information of the specific BL device 23 to the body ECU 107 via the in-vehicle network. Such processing may be triggered by a request from the body ECU 107 or by unlocking the doors of the vehicle 10.

[0046] The specific BL device 23 in this embodiment may be, for example, the BL device 23 linked to the user who was last identified as the driver, among the BL devices 23 linked to the users registered as drivers of the vehicle 10. Furthermore, the specific BL device 23 may be the BL device 23 with which a communication connection was last established, among the BL devices 23 with which a communication connection was established in the past with the head unit 105.

[0047] In addition, the targets for attempting to establish communication connections by SPP are limited to specific BL devices23. This is because if multiple BL devices 23 are targeted for attempting to establish a communication connection by SPP, there is a possibility that the attempt will not be completed within the above-mentioned predetermined period.

[0048] The head unit 105 also has a function of attempting to establish a communication connection with the BL device 23 by HFP through the short-range communication unit 103. This attempt may be triggered by a request from the body ECU 107. The targets for attempting to establish a communication connection with the BL device 23 by HFP are BL devices 23 other than a specific BL device 23 among the BL devices 23 associated with a user registered as the driver of the vehicle 10, and may be specified by the body ECU 107. If the establishment of a communication connection with the BL device 23 by HFP is successful, the head unit 105 determines that authentication of the BL device 23 has been successful. In this case, the head unit 105 transmits identification information of the successfully authenticated BL device 23 to the body ECU 107 through the in-vehicle network.

[0049] The verification ECU 106 is a small computer including a processor such as a CPU (Central Processing Unit), a RAM (Random Access Memory), a ROM (Read Only Memory), an EPROM (Erasable Programmable ROM), a flash memory, and the like.

[0050] The verification ECU 106 is triggered by a predetermined vehicle operation by the user driving the vehicle to cause the LF transmitter 101 to transmit a polling signal. The predetermined vehicle operation is, for example, unlocking a door or starting the engine. When the RF receiver 102 receives an Ack signal from the smart key 21, the verification ECU 106 transmits a Request signal to the smart key 21 via the LF transmitter 101. When the RF receiver 102 receives a Response signal including the first key ID of the smart key 21, the verification ECU 106 verifies the first key ID with verification data stored in the verification ECU 106 to authenticate the smart key 21. If the authentication of the smart key 21 is successful, the verification ECU 106 permits the door unlocking operation, the engine starting operation, or the like. If the authentication of the smart key is successful, the identification information of the target smart key 21 is transmitted from the verification ECU 106 to the body ECU 107.

[0051] The verification ECU 106 also has a function of causing the short-range communication unit 103 to send a polling signal in response to the above-mentioned predetermined vehicle operation. When the short-range communication unit 103 receives an Ack signal from the digital key 22, the verification ECU 106 sends a Request signal to the digital key 22 via the short-range communication unit 103. When the short-range communication unit 103 receives a Response signal including the second key ID of the digital key 22, the verification ECU 106 verifies the second key ID against verification data stored in the verification ECU 106 to authenticate the digital key 22. If the authentication of the digital key 22 is successful, the verification ECU 106 permits operations such as unlocking the doors or starting the engine. If the authentication of the digital key 22 is successful, the verification ECU 106 transmits identification information of the digital key 22 to the body ECU 107.

[0052] The authentication of the smart key 21 and the digital key 22 may be performed by a challenge-response authentication method using encryption keys assigned to the smart key 21 and the digital key 22.

[0053] The verification ECU 106 also has a function of performing biometric authentication when the sensor 104 acquires biometric information of the user. The biometric authentication of this embodiment includes fingerprint authentication, which targets the user's finger, and face authentication, which targets the user's face. The user's finger and face are examples of the "first part" according to the present disclosure. When fingerprint data acquired by the fingerprint sensor of the sensor 104 is transmitted from the sensor 104 to the verification ECU 106, the verification ECU 106 collates the received fingerprint data with the data for verification held by the verification ECU 106. , and performs fingerprint authentication. If the fingerprint authentication is successful, the user is permitted to operate the vehicle (for example, unlock the doors, turn on the accessory power, or start the engine). If facial image data acquired by the camera of the sensor 104 is transmitted from the sensor 104 to the verification ECU 106, the verification ECU 106 performs face authentication by verifying the received facial image data with data for verification held by the verification ECU 106. If the face authentication is successful, the user is permitted to operate the vehicle (for example, turn on the accessory power, or start the engine). If the above-mentioned fingerprint authentication or face authentication is successful, identification information assigned to the user's finger (finger ID) or identification information assigned to the user's face (face ID) is transmitted from the verification ECU 106 to the body ECU 107.

[0054] The matching data used for authenticating the smart key 21, the matching data used for authenticating the digital key 22, the matching data used for fingerprint authentication, and the matching data used for face authentication are stored in a storage device (e.g., RAM, EPROM, or flash memory) of the matching ECU 106.

[0055] Like the verification ECU 106, the body ECU 107 is a small computer including a processor, RAM, ROM, EPROM, flash memory, etc. The body ECU 107 is connected to the verification ECU 106 and the head unit 105, etc., via an in-vehicle network. The body ECU 107 performs various body controls in the vehicle 10. For example, the body ECU 107 unlocks the doors of the vehicle 10 by controlling door lock actuators in response to a request from the verification ECU 106.

[0056] The body ECU 107 also has a function for realizing the "information processing device" according to the present disclosure. That is, the body ECU 107 in this embodiment also has a function for performing processing to identify the driver of the vehicle 10. The processor of the body ECU 107 in this embodiment corresponds to the "control unit" according to the present disclosure. The processing for identifying the driver of the vehicle 10 is performed based on information received from the verification ECU 106 and information received from the head unit 105. Furthermore, when a user who is the driver of the vehicle 10 is identified, the body ECU 107 also has a function for configuring the in-vehicle device 109 according to the identified user. Details of the function for identifying the driver of the vehicle 10 and the function for configuring the in-vehicle device 100 will be described later.

[0057] The input / output unit 108 outputs information in accordance with instructions from the verification ECU 106, the body ECU 107, the head unit 105, etc., and outputs information input by a user to the verification ECU 106, the body ECU 107, the head unit 105, etc. Such an input / output unit 108 includes a touch panel display installed in the interior of the vehicle 10.

[0058] The in-vehicle equipment 109 includes a driver's seat whose position and backrest angle can be electrically adjusted, a steering wheel whose tilt and telescopic movement can be electrically adjusted, automatic lights whose operating conditions can be changed, automatic wipers whose operating conditions can be changed, an advanced safety system whose operating conditions can be changed, a meter display whose design can be changed, interior lights whose lighting color can be changed, an auto-lock / unlock system whose operating conditions can be changed, a navigation system whose various settings can be switched, an automatic air conditioner, and a powertrain whose drive mode can be changed.

[0059] 2, only the components that perform the processing according to this embodiment are extracted as the hardware components of the in-vehicle device 100, and the hardware components of the in-vehicle device 100 are not limited to the components shown in Fig. 2. For example, the in-vehicle device 100 may include an ECU for controlling the prime mover, an ECU for controlling the suspension, or the like, in addition to the hardware components shown in Fig. 2.

[0060] (User Device 20) The user device 20 is equipment used by a user who may drive the vehicle 10, and includes a smart key 21, a digital key 22, and a BL device 23.

[0061] The smart key 21 is an electronic key that allows a user to unlock the doors of the vehicle 10 or start the engine of the vehicle 10. The smart key 21 includes an LF receiver 211, an RF transmitter 212, a control unit 213, a memory unit 214, and the like.

[0062] The LF receiver 211 receives signals transmitted by radio waves in the LF band. For example, the LF receiver 211 receives a polling signal and a Request signal transmitted from the in-vehicle device 100. The polling signal and the Request signal received by the LF receiver 211 are output to the control unit 213.

[0063] The RF transmitter 212 transmits a signal using radio waves in the RF band. For example, the RF transmitter 212 transmits an Ack signal in response to a polling signal, a Response signal in response to a Request signal, and the like, in accordance with a command from the control unit 213.

[0064] The control unit 213 is configured with a processor such as a CPU. The control unit 213 has a function of transmitting various signals to the in-vehicle device 100 via the RF transmitter 212. For example, when the LF receiver 211 receives a polling signal from the in-vehicle device 100, the control unit 213 transmits an Ack signal to the in-vehicle device 100 via the RF transmitter 212. Furthermore, when the LF receiver 211 receives a Request signal from the in-vehicle device 100, the control unit 213 transmits a Response signal to the in-vehicle device 100 via the RF transmitter 212.

[0065] The storage unit 214 is configured to include RAM, ROM, EPROM, flash memory, etc. The storage unit 214 stores various programs executed by the control unit 213, the first key ID assigned to the smart key 21, etc. When a Response signal is transmitted from the RF transmitter 212 to the in-vehicle device 100, the control unit 213 reads out the first key ID stored in the storage unit 214 and generates the Response signal.

[0066] In the example shown in Figure 2, only the components that perform the processing related to this embodiment are extracted as hardware components of the smart key 21, and the hardware components included in the smart key 21 are not limited to the components shown in Figure 2.

[0067] Next, the digital key 22 is a small computer that can operate as an electronic key for the vehicle 10. In other words, the digital key 22 is a small computer that has the same functions as the smart key 21. The digital key 22 is a portable personal terminal owned by an individual user, such as a smartphone, tablet terminal, or wearable terminal, and has an application program installed on it that causes the personal terminal to operate in the same manner as the smart key 21. Such a digital key 22 includes a short-range communication unit 221, a control unit 222, a memory unit 223, etc.

[0068] The short-range communication unit 221 performs short-range wireless communication with the in-vehicle device 100 using wireless communication conforming to the BLE standard or wireless communication such as NFC. For example, the short-range communication unit 221 receives a polling signal and a Request signal transmitted from the in-vehicle device 100. The polling signal and the Request signal received by the short-range communication unit 221 are output to the control unit 222. Furthermore, the short-range communication unit 221 transmits an Ack signal in response to the polling signal, a Response signal in response to the Request signal, and the like, in accordance with an instruction from the control unit 222.

[0069] The control unit 222 is configured with a processor such as a CPU. The control unit 222 has a function of transmitting various signals to the in-vehicle device 100 via the short-range communication unit 221. For example, when the short-range communication unit 221 receives a polling signal from the in-vehicle device 100, the control unit 222 transmits an Ack signal to the in-vehicle device 100 via the short-range communication unit 221. Furthermore, when the short-range communication unit 221 receives a Request signal from the in-vehicle device 100, the control unit 222 transmits a Response signal to the in-vehicle device 100 via the short-range communication unit 221.

[0070] The storage unit 223 includes RAM, ROM, EPROM, flash memory, etc. The storage unit 223 stores various programs executed by the control unit 222, a second key ID assigned to the digital key 22, etc. When a response signal is transmitted from the short-range communication unit 221 to the in-vehicle device 100, the control unit 222 reads the second key ID stored in the storage unit 223 and generates the response signal.

[0071] 2, only the components that perform the processing according to this embodiment are extracted as the hardware components of the digital key 22, and the hardware components included in the digital key 22 are not limited to the components shown in Fig. 2. For example, in addition to the hardware components shown in Fig. 2, the digital key 22 also includes components for realizing the functions of a smartphone (e.g., a communication interface for communicating via a mobile communication system, a touch panel display, a speaker, a microphone, etc.).

[0072] Next, the BL device 23 is a small computer that cannot function as an electronic key for the vehicle 10. In other words, a user carrying only the BL device 23 cannot unlock the doors of the vehicle 10 or start the engine of the vehicle 10. However, the BL device 23 has the function of establishing a communication connection with the in-vehicle device 100 via SPP and a communication connection with the in-vehicle device 100 via HFP. The BL device 23 is a portable personal terminal owned by an individual user, such as a smartphone, tablet terminal, or wearable terminal, and is a personal terminal that does not have an application program installed to operate the personal terminal in the same manner as the smart key 21, or a personal terminal in which execution of the application program is restricted. Such a digital key 22 includes a short-range communication unit 231, a control unit 232, a memory unit 233, etc.

[0073] The short-range communication unit 231 receives a connection request by SPP from the in-vehicle device 100. The connection request received by the short-range communication unit 231 is output to the control unit. The short-range communication unit 231 transmits a response signal to the connection request to the in-vehicle device 100 in accordance with a command from the control unit 232. The short-range communication unit 231 also receives an advertising signal by HFP from the in-vehicle device 100. The advertising signal received by the short-range communication unit 231 is output to the control unit 232. The short-range communication unit 231 transmits a response signal to the advertising signal to the in-vehicle device 100 in accordance with a command from the control unit 232.

[0074] The control unit 232 is configured with a processor such as a CPU. The control unit 232 has a function of setting up a connection with the in-vehicle device 100 using SPP or HFP. For example, when the short-range communication unit 231 receives an SPP connection request from the in-vehicle device 100, the control unit 232 sets up an SPP connection with the in-vehicle device 100. Furthermore, when the short-range communication unit 231 receives an advertising signal from the in-vehicle device 100, the control unit 232 sets up an HFP connection with the in-vehicle device 100 and transmits a response signal from the short-range communication unit 231 to the in-vehicle device 100.

[0075] The storage unit 233 includes RAM, ROM, EPROM, flash memory, etc. The storage unit 233 stores various programs executed by the control unit 232. The programs stored in the storage unit 233 include SPP and HFP.

[0076] 2, only the components that perform the processing according to this embodiment are extracted as the hardware components of the BL device 23, and the hardware components included in the BL device 23 are not limited to the components shown in Fig. 2. For example, the BL device 23 includes components for realizing the functions of a smartphone in addition to the hardware components shown in Fig. 2.

[0077] (Body ECU functional configuration) Next, the functional configuration of the body ECU 107 will be described with reference to Fig. 3. Fig. 3 is a block diagram showing an example of the functional configuration of the body ECU 107. The body ECU 107 in this embodiment has, as its functional components, a registration unit 1071, an identification unit 1072, a setting unit 1073, and a driver information DB 1074. The registration unit 1071, the identification unit 1072, and the setting unit 1073 are realized by the processor of the body ECU 107 executing a program stored in a storage device. Note that part or all of the registration unit 1071, the identification unit 1072, and the setting unit 1073 may be implemented by an ASIC (Application Specific Integrated Circuit) or F It may be realized by a hardware circuit such as a PGA (Field Programmable Gate Array). The driver information DB 1074 is constructed in a storage device by the processor of the body ECU 107 executing a DBMS (Database Management System) program. The driver information DB 1074 may be constructed as a relational database.

[0078] Here, the driver information DB 1074 will be first described. The driver information DB 1074 stores information about users who are registered as drivers of the vehicle 10. In this embodiment, the driver information DB 1074 stores data linking the user device 20, the user, and the setting values ​​of the in-vehicle device 109, and data linking a first part of the user's body (fingers and / or face), the user, and the setting values ​​of the in-vehicle device 109. Fig. 4 is a diagram showing an example of data stored in the driver information DB 1074.

[0079] In the example shown in FIG. 4, multiple tables (hereinafter sometimes referred to as "driver information tables") set for each user are stored in the driver information DB 1074. In this embodiment, the number of users who can be registered as drivers of the vehicle 10 is limited to three. Therefore, the number of driver information tables stored in the driver information DB 1074 is three. Note that the number of users who can be registered as drivers of the vehicle 10 may be two or less, or may be four or more.

[0080] 4, each driver information table has fields for a user ID, identification information, and a setting value. The user ID field stores identification information (user ID) of a user registered as a driver of the vehicle 10. The user ID may be determined by the body ECU 107 or may be arbitrarily set by the user.

[0081] The identification information field registers at least one of the identification information of the smart key 21 associated with each user, the identification information of the digital key 22 associated with each user, the identification information of the BL device 23 associated with each user, the identification information of the finger associated with each user (finger ID), and the identification information of the face associated with each user (face ID). In this embodiment, the number of users who can be associated with one smart key 21, the number of users who can be associated with one digital key 22, the number of users who can be associated with one BL device 23, the number of users who can be associated with one finger, and the number of users who can be associated with one face are each limited to one. However, the number of user devices 20 and first body parts that can be associated with one user are not limited to one.

[0082] The setting value field registers setting values ​​of the in-vehicle device 109 associated with each user. The setting values ​​registered in the setting value field include, for example, setting values ​​related to the driver's seat position, the angle of the driver's seat backrest, the position of the steering wheel, the conditions for turning on / off the automatic lights, the operating conditions of the automatic wipers, the operating conditions of the advanced safety system, the design of the meter display, the lighting color of the interior lights, the operating conditions of the automatic lock / unlock system, the settings of the navigation system, the settings of the automatic air conditioner, and the settings of the drive mode.

[0083] 3, the registration unit 1071 is a functional component realized by the processor of the body ECU 107 executing a program stored in a ROM or the like, and generates a driver information table and registers the generated driver information table in the driver information DB 1074. In this embodiment, the user can arbitrarily select whether to associate the user device 20 and the setting values ​​of the in-vehicle device 109 with the user, and whether to associate the first part and the setting values ​​of the in-vehicle device 109 with the user. In other words, the user can arbitrarily select whether to register the user as a driver of the vehicle 10.

[0084] The registration unit 1071 outputs a screen prompting the user to make the above selection via the touch panel display of the input / output unit 108 when, for example, the user gets into the vehicle 10 for the first time, the user device 20 is detected for the first time (when authentication of the user device 20 is successful for the first time), when matching data used to authenticate the user's finger is registered, or when matching data used to authenticate the user's face is registered. Specifically, the registration unit 1071 outputs a first screen as shown in Fig. 5 to the touch panel display of the input / output unit 108. Fig. 5 is an example of the first screen displayed on the touch panel display when prompting the user to make the above selection.

[0085] The first screen illustrated in FIG. 5 displays text information indicating a message prompting the user to select whether or not to associate the user device 20 (or the user's finger or face) with the user, and buttons for inputting the user's selection (the "Yes" button and the "No" button in FIG. 5). When the "Yes" button is operated on the first screen illustrated in FIG. 5, the registration unit 1071 outputs a second screen such as that illustrated in FIG. 6 to the touch panel display. FIG. 6 is an example of the second screen displayed on the touch panel display when prompting the user to select an association with the user device 20 (or the user's finger or face).

[0086] The second screen illustrated in FIG. 6 displays text information indicating a message prompting the user to select a user to be associated with the linkage, and buttons for selecting the user to be associated with the linkage (the "User 1" button, the "User 2" button, and the "User 3" button in FIG. 6). When any of the "User 1" button, the "User 2" button, and the "User 3" button is operated on the second screen illustrated in FIG. 6, the registration unit 1071 generates a driver information table that links the identification information (or the finger ID or the face ID) of the user device 20, the setting value of the in-vehicle device 109, and the user ID of the selected user, and registers the generated driver information table in the driver information DB 1074. At this time, the information registered in the setting value field of the driver information table may be the setting value of the in-vehicle device 109 at the time when the user selects to perform the linkage, or may be the setting value of the in-vehicle device 109 at the time when the user ends driving the vehicle 10 (for example, when the start switch is turned off).

[0087] If the driver information table corresponding to the selected user has already been registered in the driver information DB 1074, the registration unit 1071 adds the identification information (or finger ID or face ID) of the user device 20 to the identification information field of the driver information table.

[0088] Returning to the explanation of FIG. 3, the identifying unit 1072 is configured to identify the ROI of the processor of the body ECU 107. M, etc., and identifies the user who drives the vehicle 10. For example, when the body ECU 107 receives identification information of the smart key 21 that has been successfully authenticated by the verification ECU 106, the identification unit 1072 accesses the driver information DB 1074 and determines whether there is a driver information table in which information matching the identification information is registered in the identification information field. If there is a driver information table in which information matching the identification information is registered in the identification information field, the identification unit 1072 identifies the user corresponding to the driver information table as the driver of the vehicle 10.

[0089] Furthermore, when the body ECU 107 receives the identification information of the digital key 22 that has been successfully authenticated by the verification ECU 106, the identification unit 1072 accesses the driver information DB 1074 to determine whether there is a driver information table in which information matching the identification information is registered in the identification information field. If there is a driver information table in which information matching the identification information is registered in the identification information field, the identification unit 1072 identifies the user corresponding to the driver information table as the driver of the vehicle 10.

[0090] Furthermore, when the body ECU 107 receives the finger ID of a finger that has been successfully fingerprint authenticated by the verification ECU, the identification unit 1072 accesses the driver information DB 1074 and determines whether there is a driver information table in which information matching the finger ID is registered in the identification information field. If there is a driver information table in which information matching the finger ID is registered in the identification information field, the identification unit 1072 identifies the user corresponding to the driver information table as the driver of the vehicle 10.

[0091] Furthermore, when the body ECU 107 receives the face ID of a face that has been successfully authenticated by the matching ECU, the identification unit 1072 accesses the driver information DB 1074 and determines whether there is a driver information table in which information matching the face ID is registered in the identification information field. If there is a driver information table in which information matching the face ID is registered in the identification information field, the identification unit 1072 identifies the user corresponding to the driver information table as the driver of the vehicle 10.

[0092] In addition, when the body ECU 107 receives identification information of a BL device 23 (a specific BL device 23) that has established an SPP connection with the head unit 105, the identification unit 1072 accesses the driver information DB 1074 to identify a driver information table in which information matching the identification information is registered in the identification information field, and identifies the user corresponding to the identified driver information table as the driver of the vehicle 10.

[0093] Note that identification of the driver of the vehicle 10 must be completed before the vehicle 10 starts traveling or before the engine is started. Therefore, the identification unit 1072 accepts information from the verification ECU 106 and the head unit 105 only during the above-mentioned predetermined period (the period from when the doors of the vehicle 10 are unlocked until the first time length has elapsed).

[0094] Incidentally, during the above-mentioned predetermined period, it is conceivable that multiple authentications among the authentication of the smart key 21, the authentication of the digital key 22, the authentication of the specific BL device 23, the fingerprint authentication, and the facial authentication will be successful. For example, if a user who unlocks the door using the smart key 21 sits in the driver's seat and operates the start button, multiple authentications including the authentication of the smart key 21, the facial authentication, and the fingerprint authentication may be successful. It is also conceivable that at least one of the multiple authentications will be successful and a communication connection between the head unit 105 and the specific BL device 23 will be established. For example, if a user carrying the smart key 21 and the specific BL device 23 is about to drive the vehicle 10, it is conceivable that the authentication of the smart key 21 will be successful and a communication connection between the head unit 105 and the specific BL device 23 will be established (the authentication of the BL device 23 will be successful). In these cases, In this case, if the smart key 21 has been lent or borrowed between family members or the like, there is a possibility that the user linked to the smart key 21, the user linked to the finger part, the user linked to the face part, and the user linked to the specific BL device 23 may not match. As a result, there is a possibility that the driver of the vehicle 10 may not be identified accurately.

[0095] Therefore, in this embodiment, if multiple authentications are successful, or if at least one of the multiple authentications is successful and a communication connection is established between the head unit 105 and a specific BL device 23, the identification unit 1072 identifies the driver of the vehicle 10 in accordance with the following priority order according to the reliability of the authentications. (Priority: 1) Users identified based on finger authentication (fingerprint authentication) (Priority: 2nd) Users identified based on facial recognition (face recognition) (Priority: 3) User identified based on digital key authentication (Priority: 4th) Users identified based on smart key authentication (Priority: 5th) A user identified based on authentication of the BL device (a user associated with the BL device 23 that has established an SPP connection with the head unit 105)

[0096] The above-described priority order is an example and is not limiting. For example, depending on the specifications of the fingerprint sensor and camera, facial authentication may be more reliable than fingerprint authentication. In that case, a user identified based on facial authentication may be given a higher priority than a user identified based on fingerprint authentication. Furthermore, since the BL device 23 cannot function as an electronic key, it is given a lower priority than the smart key 21. However, if the BL device 23 is a smartphone or the like that is unlikely to be lent or borrowed between users, it may be given a higher priority than the smart key 21.

[0097] In this embodiment, as described above in the description of the registration unit 1071, the user can arbitrarily select whether or not to register a user as the driver of the vehicle 10. Furthermore, as described above in the description of the driver information DB 1074, the number of users who can be registered as the driver of the vehicle 10 is limited to three. For these reasons, there may be cases where none of the identification information of the smart key 21 successfully authenticated by the verification ECU 106, the identification information of the digital key 22 successfully authenticated by the verification ECU 106, the finger ID of the finger successfully fingerprint authenticated by the verification ECU 106, and the face ID of the face successfully authenticated by the verification ECU 106 are associated with the user driving the vehicle 10. In such a case, if the user driving the vehicle 10 is not associated with a specific BL device 23, the identification unit 1072 cannot identify the driver of the vehicle 10. Therefore, if the driver of the vehicle 10 cannot be identified, the identification unit 1072 determines that the driver of the vehicle 10 is a guest user.

[0098] If it is determined that the driver of the vehicle 10 is a guest user, the identification unit 1072 attempts to establish a communication connection with the BL device 23 by HFP through the head unit 105. Specifically, the identification unit 1072 transmits a signal requesting an attempt to establish a communication connection by HFP (hereinafter, may be referred to as an "HF request") to the head unit 105. The HF request includes identification information of the BL device 23 that is the target of the attempt. The BL device 23 that is the target of the attempt is a BL device 23 other than a specific BL device 23, among the BL devices 23 linked to a user registered in the driver information DB 1074 as the driver of the vehicle 10. If there are multiple such BL devices 23, the identification information of the multiple BL devices 23 is included in the HF request. If the communication connection between the head unit 105 and the BL device 23 by HFP is successfully established, a signal indicating that the communication connection has been successfully established (hereinafter, may be referred to as a "success signal") is transmitted to the head unit 105. The success signal is transmitted from the head unit 105 to the body ECU 107. The success signal includes identification information of the BL device 23 with which a communication connection has been established with the head unit 105 via HFP. If the establishment of a communication connection between the head unit 105 and the BL device 23 via HFP fails, a signal indicating that the establishment of the communication connection has failed (hereinafter, this may be referred to as a "failure signal") is transmitted from the head unit 105 to the body ECU 107.

[0099] If the signal received by the body ECU 107 from the head unit 105 is a success signal, the identification unit 1072 accesses the driver information DB 1074 and identifies a driver information table in which information matching the identification information of the BL device 23 included in the success signal is registered in the identification information field. The identification unit 1072 suggests to the user driving the vehicle that they change to a user (hereinafter, sometimes referred to as a "candidate user") corresponding to the identified driver information table. Specifically, the identification unit 1072 outputs a third screen as shown in FIG. 7 to the touch panel display of the input / output unit 108. FIG. 7 is an example of the third screen displayed on the touch panel display when making the above-mentioned suggestion.

[0100] The third screen illustrated in FIG. 7 displays text information indicating a message proposing a change to the candidate user, and buttons for inputting a response to the above-mentioned proposal (the "Yes" button and the "No" button in FIG. 7). When the "Yes" button is operated on the third screen illustrated in FIG. 7, the identification unit 1072 changes the driver of the vehicle 10 from the guest user to the candidate user. This makes it possible to accurately identify the driver of the vehicle 10 even when a user who is linked only to the BL device 23 drives the vehicle 10 and the BL device 23 of the user is different from the specific BL device 23.

[0101] If the signal received by the body ECU 107 from the head unit 105 is a failure signal, the identification unit 1072 does not perform processing to change the driver of the vehicle 10. Note that the candidate user here corresponds to the “third user” according to the present disclosure.

[0102] 3, when the user driving the vehicle 10 is identified by the identification unit 1072, the user ID of the identified user is passed from the identification unit 1072 to the setting unit 1073. When it is determined that the driver of the vehicle 10 is a guest user, the user ID indicating the guest user is passed from the identification unit 1072 to the setting unit 1073.

[0103] The setting unit 1073 sets the in-vehicle device 109 according to the user identified by the identification unit 1072. Here, if the user identified by the identification unit 1072 is a guest user, the setting unit 1073 sets the in-vehicle device 109 based on a preset reference value. The reference value is stored in a storage device of the body ECU 107. Furthermore, if the user identified by the identification unit 1072 is other than a guest user, the setting unit 1073 accesses the driver information DB 1074 to identify a driver information table corresponding to the user ID received from the identification unit 1072. The setting unit 1073 reads out a setting value registered in a setting value field of the identified driver information table, and sets the in-vehicle device 109 in accordance with the read setting value. As a result, when a user registered as the driver of the vehicle 10 drives the vehicle 10, a setting value suitable for the user is automatically reflected in the in-vehicle device 109.

[0104] (Processing flow) The flow of processing performed by the body ECU 107 in this embodiment will be described with reference to Figs. 8 and 9. Fig. 8 is a flowchart showing a processing routine that is executed when the doors of the vehicle 10 are unlocked as a trigger. Fig. 9 is a flowchart showing a processing routine that is executed when it is determined in Fig. 8 that the driver of the vehicle 10 is a guest user. The processing shown in Figs. 8 and 9 is executed by the body ECU 107. Although it is a processor, the functional components of the body ECU 107 will be described here as the execution subjects.

[0105] First, in FIG. 8, the identification unit 1072 starts accepting (receiving) information from the verification ECU 106 and the head unit 105 (step S101). The information received from the verification ECU 106 is one or more of the following: identification information of a smart key 21 that has been successfully authenticated; a digital key 22 that has been successfully authenticated; a finger ID of a finger that has been successfully fingerprint authenticated; and a face ID of a face that has been successfully authenticated. The information received from the head unit 105 is identification information of a specific BL device 23 with which a communication connection with the head unit 105 via SPP has been established (authentication has been successful). However, if a communication connection between the head unit 105 and the specific BL device 23 via SPP has not been established, the identification unit 1072 does not receive information from the head unit 105. After completing the process of step S101, the identification unit 1072 executes the process of step S102.

[0106] In step S102, the identification unit 1072 determines whether a first length of time has elapsed since the start of reception of information from the matching ECU 106 and the head unit 105. If the first length of time has not elapsed since the start of reception of information from the matching ECU 106 and the head unit 105 (negative determination in step S102), the identification unit 1072 waits until the first length of time has elapsed. Thereafter, when the first length of time has elapsed since the start of reception of information from the matching ECU 106 and the head unit 105 (positive determination in step S102), the identification unit 1072 executes the process of step S103.

[0107] In step S103, the identification unit 1072 finishes receiving information from the verification ECU 106 and the head unit 105. After completing the process of step S103, the identification unit 1072 executes the process of step S104.

[0108] In step S104, the identification unit 1072 determines whether there is a corresponding user based on information received during a period (predetermined period) from when the identification unit 1072 starts accepting information from the verification ECU 106 and the head unit 105 until a first length of time has elapsed. That is, the identification unit 1072 accesses the driver information DB 1074 and determines whether there is a driver information table in which information matching the information received during the predetermined period is registered in the identification information field. If there is a driver information table in which information matching the information received during the predetermined period is registered in the identification information field (positive determination in step S104), the process of step S105 is executed.

[0109] In step S105, the identification unit 1072 determines whether there are multiple corresponding users. Here, if multiple pieces of information are received during the predetermined period and the users linked to the pieces of information are different, it is determined that there are multiple corresponding users (positive determination in step S105). In this case, the processing of step S106 is executed. Also, if multiple pieces of information are received during the predetermined period and the users linked to the pieces of information match, it is determined that there is one corresponding user (negative determination in step S105). Furthermore, if there is only one piece of information received during the predetermined period and a driver information table in which information matching that information is registered in the identification information field is stored in the driver information DB 1074, it is also determined that there is one corresponding user (negative determination in step S105). If the determination in step S105 is negative, the processing of step S107 is executed.

[0110] In step S106, the identification unit 1072 identifies the user with the highest priority among the multiple users as the driver of the vehicle 10. In step S107, the identification unit 1072 identifies one of the users as the driver of the vehicle 10. The user identified as the driver of the vehicle 10 in step S106 or step S107 The user's user ID is passed from the identification unit 1072 to the setting unit 1073. The setting unit 1073 is triggered by receiving the user ID from the identification unit 1072 to execute the process of step S108.

[0111] In step S108, the setting unit 1073 accesses the driver information DB 1074 and extracts a setting value corresponding to the user ID received from the identification unit 1072. That is, the setting unit 1073 accesses the driver information DB 1074 and identifies a driver information table in which information matching the user ID received from the identification unit 1072 is registered in the user ID field. The setting unit 1073 extracts a setting value registered in the setting value field of the identified driver information table. After completing the processing of step S108, the setting unit 1073 executes the processing of step S111.

[0112] In step S111, the setting unit 1073 sets the in-vehicle device 109 in accordance with the setting values ​​extracted in step S108. That is, the setting unit 1073 reflects the setting values ​​extracted in step S108 in the in-vehicle device 100. After the processing of step S111 is executed, the execution of this processing routine is terminated.

[0113] In addition, if it is determined in the above-mentioned step S104 that there is no driver information table in which information matching the information received during the specified period is registered in the identification information field (negative determination in step S104), the identification unit 1072 executes the processing of step S109.

[0114] In step S109, the identification unit 1072 determines that the driver of the vehicle 10 is a guest user. If it is determined that the driver of the vehicle 10 is a guest user, the user ID of the guest user is passed from the identification unit 1072 to the setting unit 1073. The setting unit 1073 is triggered by receiving the user ID of the guest user from the identification unit 1072, and executes the processing of step S110.

[0115] In step S110, the setting unit 1073 extracts a reference value from the storage device of the body ECU 107. After completing the process of step S110, the setting unit 1073 executes the process of step S111. In this case, in step S111, the setting unit 1073 sets the in-vehicle device 109 in accordance with the reference value extracted in step S110. After the process of step S111 is executed, the execution of this processing routine is terminated.

[0116] After the process of step S109 described above is executed, the process flow of FIG. 9 is executed. In the process flow of FIG. 9, first, the identification unit 1072 transmits an HF request to the head unit 105 (step S201). As described above, the HF request is a signal requesting an attempt to establish a communication connection with the BL device 23 by HFP. The HFP request includes identification information of the BL device 23 that is to be the connection destination of the HFP communication connection. The BL device 23 that is to be the connection destination of the HFP communication connection is a BL device 23 other than the specific BL device 23 among the BL devices 23 linked to the user registered in the driver information DB 1074 as the driver of the vehicle 10. After completing the process of step S201, the identification unit 1072 executes the process of step S202.

[0117] In step S202, the identification unit 1072 determines whether the body ECU 107 has received a signal from the head unit 105. The signal here is either the success signal or the failure signal described above. If the body ECU 107 has not received a signal from the head unit 105 (negative determination in step S202), the identification unit 1072 waits until the body ECU 107 receives a signal from the head unit 105. If the body ECU 107 has received a signal from the head unit 105 (positive determination in step S202), the identification unit 1072 executes the process of step S203.

[0118] In step S203, the identification unit 1072 determines whether the signal received from the head unit 105 is a success signal. If the signal received from the head unit 105 is a failure signal (negative determination in step S203), the execution of the processing routine in Fig. 7 is terminated. On the other hand, if the signal received from the head unit 105 is a success signal (positive determination in step S203), the identification unit 1072 executes the processing of step S204.

[0119] In step S204, the identification unit 1072 accesses the driver information DB 1074 using the identification information included in the success signal (the identification information of the BL device 23 that has established a communication connection with the head unit 105 via HFP) as an argument, and identifies a driver information table in which information matching the identification information is registered in the identification information field (identification of a candidate user). After completing the process of step S204, the identification unit 1072 executes the process of step S205.

[0120] In step S205, the identification unit 1072 outputs the third screen as shown in Fig. 7 to the touch panel display of the input / output unit 108. The third screen is a screen that proposes a change to the candidate user identified in step S204. After completing the process of step S205, the identification unit 1072 executes the process of step S206.

[0121] In step S206, the identification unit 1072 determines whether an answer to the above-mentioned proposal has been input. That is, it determines whether an operation to select the "Yes" button or the "No" button has been performed on the third screen shown in FIG. 7. If an answer to the above-mentioned proposal has not been input (negative determination in step S206), the identification unit 1072 waits until an answer to the above-mentioned proposal is input. On the other hand, if an answer to the above-mentioned proposal has been input (positive determination in step S206), the identification unit 1072 executes the process of step S207.

[0122] In step S207, the identification unit 1072 determines whether the input answer is an answer that accepts the above-mentioned proposal. That is, it determines whether the "Yes" button has been operated on the third screen shown in FIG. 7. If the "No" button has been operated on the third screen shown in FIG. 7 (negative determination in step S207), the execution of the processing routine in FIG. 7 is terminated. Also, if the "Yes" button has been operated on the third screen shown in FIG. 7 (positive determination in step S207), the identification unit 1072 executes the processing of step S208.

[0123] In step S208, the identification unit 1072 changes the driver of the vehicle 10 from the guest user to the candidate user identified in step S204. That is, the identification unit 1072 requests the setting unit 1073 to change the setting of the in-vehicle device 109 from the setting corresponding to the guest user to the setting corresponding to the candidate user identified in step S204. Upon receiving the request, the setting unit 1073 executes the process of step S209.

[0124] In step S209, the setting unit 1073 changes the setting of the in-vehicle device 109 in accordance with the request. Specifically, the setting unit 1073 accesses the driver information table corresponding to the candidate user identified in step S204 and extracts the setting value registered in the setting value field. The setting unit 1073 changes the setting of the in-vehicle device 109 in accordance with the extracted setting value. After the processing of step S209 is executed, the execution of this processing routine is terminated.

[0125] According to this embodiment, in a vehicle 10 having a function of identifying a driver based on the authentication result of a user device 20 and a function of identifying a driver based on the authentication result of a first part (finger and face) of a user's biological body, the function of identifying a driver based on the authentication result of the first part (finger and face) of a user's biological body is The authentication result is given priority when identifying the driver. This allows the driver of the vehicle 10 to be identified more accurately even in an environment where the user device 20 is lent or borrowed between family members or the like.

[0126] Furthermore, according to this embodiment, in the vehicle 10 having the function of performing authentication (fingerprint authentication and face authentication) of multiple types of first parts (finger and face), the driver is identified by prioritizing the result of authentication with a relatively high reliability among those authentications. This makes it possible to more accurately identify the driver of the vehicle 10 even in a situation where authentication of multiple types of first parts is successful.

[0127] Furthermore, according to this embodiment, in a vehicle 10 having a function for authenticating multiple types of user devices 20 (the smart key 21, the digital key 22, and the BL device 23), the driver is identified by giving priority to the authentication result of a relatively highly reliable type of user device 20 among the multiple types of user devices 20. This allows the driver of the vehicle 10 to be identified more accurately even in a situation where authentication of multiple types of user devices 20 is successful.

[0128] Furthermore, according to this embodiment, whether or not to link the smart key 21 to the user, whether or not to link the digital key 22 to the user, whether or not to link the BL device 23 to the user, whether or not to link the finger unit to the user, and whether or not to link the face unit to the user are all freely selected by the user. This makes it possible to prevent the user device 20, such as the smart key 21, which operates as an electronic key for the vehicle 10, from being linked to any of the users when the user device 20 is shared by multiple users. As a result, when the user device 20 is shared by multiple users, it is possible to prevent the in-vehicle device 109 from being set according to the setting values ​​of a user other than the user driving the vehicle 10.

[0129] Furthermore, according to the present embodiment, a user device 20 that does not function as an electronic key for the vehicle 10, such as the BL device 23, can be linked to a user. As a result, for example, when a smart key 21 or the like is shared by multiple users, even if the smart key 21 or the like is not linked to any user, by linking the BL device 23 to the user, it is possible to identify the user who drives the vehicle 10.

[0130] Furthermore, according to the present embodiment, when it is determined that the driver of the vehicle 10 is a guest user, authentication of a BL device 23 (establishment of a communication connection with the head unit 105 by HFP) other than the specific BL device 23 is attempted. As a result, when the user who is about to drive the vehicle is linked only to the BL device 23 and the BL device 23 is not the specific BL device 23, the user can be identified as the driver of the vehicle 10.

[0131] <Other> The above-described embodiments and modifications are merely examples, and the present disclosure may be modified and implemented as appropriate without departing from the spirit and scope thereof. Furthermore, the processes and configurations described in the present disclosure may be freely combined and implemented as long as no technical contradictions arise. Furthermore, processes described as being performed by a single device may be shared and executed by multiple devices. For example, part of the processes performed by the body ECU 107 may be executed by the verification ECU 106 or the head unit 105, etc. Furthermore, processes described as being performed by different devices may be executed by a single device. For example, the processes performed by the body ECU 107 and the verification ECU 106 may be executed by a single ECU. In a computer system, the hardware configuration for implementing each function can be flexibly changed.

[0132] The present disclosure can also be realized by supplying a computer program implementing the functions described in the above embodiments or variations to a computer, and having one or more processors of the computer read and execute the program. Such a computer program may be provided to the computer via a non-transitory computer-readable storage medium connectable to the computer's system bus or via a network. A non-transitory computer-readable storage medium is a recording medium that stores information such as data and programs through electrical, magnetic, optical, mechanical, or chemical action and can be read by a computer or the like. Such a non-transitory computer-readable storage medium may be, for example, any type of disk, such as a magnetic disk (such as a floppy disk or HDD) or an optical disk (such as a CD-ROM, DVD disk, or Blu-ray disk). The non-transitory computer-readable storage medium may also be a medium such as a ROM, RAM, EPROM, EEPROM, magnetic card, flash memory, optical card, or solid-state drive (SSD). [Explanation of symbols]

[0133] 10 vehicles 100 In-vehicle equipment 101 LF transmitter 102 RF receiver 103 Near Field Communication Department 104 Sensors 105 head unit 106 Verification ECU 107 Body ECU 1071 Registration Department 1072 Specific part 1073 Settings 1074 Driver Information DB 108 Input / output section 109 Automotive equipment 20 User Devices 21 Smart Key 22 Digital Key 23 BL Device

Claims

1. An information processing device that identifies a driver of a vehicle based on at least one of a first authentication based on a first part of a user's body part and a second authentication based on a user device, the user device includes a first communication terminal that operates as an electronic key for the vehicle and a second communication terminal that does not operate as an electronic key for the vehicle; the second authentication includes authentication of the first communication terminal and authentication of the second communication terminal; identifying the driver of the vehicle by giving priority to the authentication result of the first communication terminal over the authentication result of the second communication terminal; A control unit is provided, the control unit identifies the driver of the vehicle by giving priority to the authentication result of the first authentication over the authentication result of the second authentication. Information processing device.

2. the first region includes a finger of the living body and a face of the living body, the first authentication includes fingerprint authentication based on the finger portion and face authentication based on the face portion, the control unit identifies the driver of the vehicle by prioritizing the authentication result of the fingerprint authentication over the authentication result of the face authentication. The information processing device according to claim 1 .

3. a storage unit configured to store data linking the first portion to a user and data linking the user device to the user as user information; The control unit Identifying a first user associated with the first region that has been successfully authenticated based on the data stored in the storage unit; and Identifying a second user associated with the user device that has successfully passed the second authentication based on the data stored in the storage unit; and If the first user and the second user are different, identifying the first user as a driver of the vehicle; To execute The information processing device according to claim 2 .

4. The control unit accepting a selection of whether to associate the first portion and / or the user device with a user; When a selection to associate the first portion and / or the user device with a user is received, storing data to associate the first portion and / or the user device with a user in the storage unit; When a selection of not associating the first portion and / or the user device with a user is accepted, data associating the first portion and / or the user device with a user is not stored in the storage unit; To execute The information processing device according to claim 3 .

5. When neither the data linking the first part that has been successfully authenticated with the user nor the data linking the user device that has been successfully authenticated with the second part is stored in the storage unit, the control unit determines that the driver of the vehicle is a guest user. The information processing device according to claim 4 .

6. After it is determined that the driver of the vehicle is a guest user, The control unit Attempting to establish a communication connection with the second communication terminal, the second communication terminal having data associated with the user stored in the storage unit; When a communication connection with the second communication terminal is established, outputting information proposing a change to a third user associated with the second communication terminal; Accepting an operation requesting a change to the third user; and changing the driver of the vehicle from the guest user to the third user. The information processing device according to claim 5 .

7. In the process of attempting to establish a communication connection with the second communication terminal, the control unit attempts to establish a communication connection with the second communication terminal using a hands-free profile through a first device for providing a hands-free calling function; The information processing device according to claim 6 .

8. The user information further includes information regarding user-specific setting values ​​of devices mounted on the vehicle, the control unit sets the device according to user information of the user identified as the driver of the vehicle. The information processing device according to claim 3 .

9. The setting values ​​include at least one of a setting value related to a driving position, a setting value related to multimedia, a setting value related to an advanced safety system, and a setting value related to a body system. The information processing device according to claim 8 .

10. 1. An information processing method for identifying a driver of a vehicle based on at least one of a first authentication based on a first part of a user's body part and a second authentication based on a user device, the method comprising: the user device includes a first communication terminal that operates as an electronic key for the vehicle and a second communication terminal that does not operate as an electronic key for the vehicle; the second authentication includes authentication of the first communication terminal and authentication of the second communication terminal; a computer identifies the driver of the vehicle by prioritizing the authentication result of the first communication terminal over the authentication result of the second communication terminal; the computer identifies the driver of the vehicle by prioritizing the result of the first authentication over the result of the second authentication; Information processing methods.

11. the first region includes a finger of the living body and a face of the living body, the first authentication includes fingerprint authentication based on the finger portion and face authentication based on the face portion, the computer identifies the driver of the vehicle by prioritizing the result of the fingerprint authentication over the result of the face authentication. The information processing method according to claim 10.

12. the computer further includes a storage unit configured to store, as user information, data linking the first portion to a user and data linking the user device to the user; The computer Identifying a first user associated with the first region that has been successfully authenticated based on the data stored in the storage unit; and Identifying a second user associated with the user device that has successfully passed the second authentication based on the data stored in the storage unit; and If the first user and the second user are different, identifying the first user as a driver of the vehicle; To execute The information processing method according to claim 11.

13. The computer accepting a selection of whether to associate the first portion and / or the user device with a user; When a selection to associate the first portion and / or the user device with a user is received, storing data to associate the first portion and / or the user device with a user in the storage unit; When a selection of not associating the first portion and / or the user device with a user is accepted, data associating the first portion and / or the user device with a user is not stored in the storage unit; To execute The information processing method according to claim 12.

14. When neither the data linking the first part that has been successfully authenticated with the user nor the data linking the user device that has been successfully authenticated with the second part is stored in the storage unit, the computer determines that the driver of the vehicle is a guest user. The information processing method according to claim 13.

15. After it is determined that the driver of the vehicle is a guest user, The computer Attempting to establish a communication connection with the second communication terminal, the second communication terminal having data associated with the user stored in the storage unit; When a communication connection with the second communication terminal is established, outputting information proposing a change to a third user associated with the second communication terminal; Accepting an operation requesting a change to the third user; changing the driver of the vehicle from the guest user to the third user; Further execute The information processing method according to claim 14.

16. In the process of attempting to establish a communication connection with the second communication terminal, the computer attempts to establish a communication connection with the second communication terminal using a hands-free profile through a first device for providing a hands-free calling function; The information processing method according to claim 15.

17. The user information further includes information regarding user-specific setting values ​​of devices mounted on the vehicle, the computer sets the device according to user information of the user identified as the driver of the vehicle; 17. The information processing method according to any one of claims 12 to 16.

18. The setting values ​​include at least one of a setting value related to a driving position, a setting value related to multimedia, a setting value related to an advanced safety system, and a setting value related to a body system.

18. The information processing method according to claim 17.

Citation Information

Patent Citations

  • Operation environment setting system, vehicle-mounted device, portable device, management device, program for vehicle-mounted device, program for portable device, and program for management device

    JP2008213634A

  • Driving position setting device

    JP2012081925A

  • Driver identification system, electronic key

    JP2017082396A

  • Authentication device and authentication method

    JP2019020917A

  • Authentication control device and authentication control system

    JP2019125297A