Authentication system and authentication method

The authentication system addresses the challenge of multiple users sharing vehicles by synchronizing user and vehicle data, enabling convenient access and settings transfer across vehicles.

JP7754188B2Active Publication Date: 2025-10-15DENSO CORP
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
JP2023556313
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-10-26
Filing Date
2022-10-13
Publication Date
2025-10-15
Estimated Expiration
2042-10-13

AI Technical Summary

Technical Problem

Conventional authentication systems face challenges when multiple users share a vehicle, as they require third parties to borrow keys or adjust settings manually, and user-specific configurations are not easily transferred between vehicles.

Method used

An authentication system with on-board and external devices that synchronize user and vehicle information, allowing bidirectional data exchange to authenticate users and apply personalized settings across vehicles.

Benefits of technology

Enables convenient and seamless vehicle use by multiple users, ensuring authorized access and maintaining personalized settings without manual adjustments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007754188000001
    Figure 0007754188000001
  • Figure 0007754188000002
    Figure 0007754188000002
  • Figure 0007754188000003
    Figure 0007754188000003
Patent Text Reader

Abstract

A vehicle-interior control unit (11) and a vehicle-exterior control unit (17) execute a synchronization process for bi-directionally synchronizing user-related information stored in a first vehicle-interior storage unit (9) and user-related information stored in a shared area (18) of a first vehicle-exterior storage unit (15). When the user requests use of a vehicle, the vehicle-interior control unit executes an authentication process that for authenticating a target user, who is the user who requested the use of the vehicle, on the basis of the user-related information stored in the first vehicle-interior storage unit and vehicle-related information stored in a second vehicle-interior storage unit (10), and reflects user-related information corresponding to the target user in the vehicle when the target user is successfully authenticated by the authentication process. When information is insufficient, which is when there is no information corresponding to the target user in the user-related information stored in the first vehicle-interior storage unit or in the vehicle-related information stored in the second vehicle-interior storage unit, the vehicle-interior control unit or the vehicle-exterior control unit executes the authentication process on the basis of user-related information stored in a non-shared area (19) of the first vehicle-exterior storage unit.
Need to check novelty before this filing date? Find Prior Art

Description

CROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This application is based on Japanese Application No. 2021-174807, filed on October 26, 2021, the contents of which are incorporated herein by reference. [Technical Field]

[0002] The present disclosure relates to an authentication system and method for managing a user's use of a vehicle. [Background technology]

[0003] Patent Document 1 discloses an authentication system that includes a mobile terminal carried by a user and a vehicle-side device used in a vehicle that outputs an answerback sound when the door is unlocked. In this authentication system, the vehicle-side device executes various processes related to authentication in the vehicle by executing a control program stored in a memory. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Publication No. 2020-165367 Summary of the Invention

[0005] It is conceivable that a single vehicle will be used not only by the vehicle owner, but also by third parties such as users of sharing services and car maintenance providers. Conventional authentication systems have posed the following challenges in such cases. Third parties have to borrow keys or other items to drive the vehicle, making it difficult to easily use the vehicle's functions. It is also difficult for third parties to use only some of the vehicle's functions, such as starting the engine or opening the hood, for maintenance purposes.

[0006] It is also assumed that a vehicle owner may use not only his or her own vehicle but also a company car. Conventional authentication systems have the following problem in such cases. Even if the vehicle owner customizes the seat position, air conditioning settings, and so on of his or her own vehicle and purchases and installs a car app, which is an application for the vehicle, from a cloud service, when using a company car, the vehicle owner must adjust the seat position and air conditioning settings again, and is unable to use the purchased car app. Thus, the conventional technology leaves room for improvement in terms of convenience when multiple users use one vehicle and when one user uses multiple vehicles.

[0007] An object of the present disclosure is to provide an authentication system and an authentication method that can improve the convenience of vehicle use.

[0008] In one aspect of the present disclosure, the authentication system is a system including an on-board device mounted on a vehicle and an external device provided outside the vehicle. The on-board device and the external device are configured to be able to communicate with each other. The on-board device includes a first internal storage unit that stores user-related information about a user who uses the vehicle, and a second internal storage unit that stores user-related information about the vehicle. The vehicle information includes a VIN, which is information about the vehicle, and user information, which is information about the user who is the target of using the vehicle. The exterior device includes a first exterior storage unit including a shared area and a non-shared area in which user-related information is stored, a second exterior storage unit in which vehicle-related information is stored, and an exterior control unit that executes various processes.

[0009] The interior control unit and the exterior control unit execute a synchronization process to bidirectionally synchronize the user-related information stored in the first interior storage unit with the user-related information stored in the shared area of ​​the first exterior storage unit. In the above configuration, when a user requests use of the vehicle, the interior control unit executes an authentication process to authenticate a target user who has requested use of the vehicle based on the user-related information stored in the first interior storage unit and the vehicle-related information stored in the second interior storage unit, and if authentication of the target user is successful in the authentication process, reflects the user-related information corresponding to the target user in the vehicle.

[0010] In the above configuration, when there is insufficient information, that is, when there is no information corresponding to the target user in the user-related information stored in the first vehicle-side storage unit and the vehicle-related information stored in the second vehicle-side storage unit, the vehicle-side control The department , and performs authentication processing based on the user-related information stored in the non-shared area of ​​the first exterior storage unit. This configuration allows various users to conveniently use one vehicle, and when one user uses multiple vehicles, various vehicle settings can be reflected in each vehicle. Therefore, this configuration has the excellent effect of improving convenience regarding vehicle use. [Brief explanation of the drawings]

[0011] The above and other objects, features and advantages of the present disclosure will become more apparent from the following detailed description taken in conjunction with the accompanying drawings, in which: [Figure 1] FIG. 1 is a diagram illustrating a configuration of an authentication system according to an embodiment; [Figure 2] FIG. 2 is a diagram illustrating an example of the configuration of user-related information according to an embodiment; [Figure 3] FIG. 3 is a diagram illustrating an example of information stored in a user setting DB of an in-vehicle device according to an embodiment; [Figure 4] FIG. 4 is a diagram illustrating an example of the configuration of vehicle-related information according to an embodiment; [Figure 5]FIG. 5 is a diagram illustrating an example of information stored in a vehicle setting DB of an in-vehicle device according to an embodiment; [Figure 6] FIG. 6 is a diagram illustrating an example of information stored in a non-shared area of ​​a user setting DB of a center according to an embodiment; [Figure 7] FIG. 7 is a diagram illustrating an example of information stored in a non-shared area of ​​a vehicle setting DB of a center according to an embodiment; [Figure 8] FIG. 8 is a diagram illustrating an example of processing details related to user authentication when outside-vehicle authentication is performed when information is insufficient according to an embodiment; [Figure 9] FIG. 9 is a diagram illustrating an example of processing details related to user authentication when in-vehicle authentication is performed when information is insufficient according to an embodiment; [Figure 10] FIG. 10 is a diagram showing an example of processing content related to synchronization processing when information on the vehicle-mounted device side is updated in an online state according to an embodiment; [Figure 11] FIG. 11 is a diagram showing an example of processing content related to synchronization processing when information on the center side is updated in an online state according to an embodiment; [Figure 12] FIG. 12 is a diagram showing an example of processing content related to synchronization processing when information on the center side is updated in an offline state according to an embodiment; [Figure 13] FIG. 13 is a diagram showing an example of processing content related to synchronization processing when information on the vehicle-mounted device side is updated in an offline state according to an embodiment; [Figure 14] FIG. 14 is a diagram showing a modified example of information stored in a non-shared area of ​​the vehicle setting DB of the center according to one embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0012] Hereinafter, an embodiment of an authentication system and an authentication method will be described with reference to the drawings. As shown in Fig. 1, the authentication system 1 includes an in-vehicle device 2 and a center 3 that are configured to be able to communicate with each other. The authentication system 1 manages the use of vehicle functions, i.e., access to vehicle functions, by a user 5 of a vehicle 4 such as an automobile, using an authentication method that includes various procedures described below. In this case, the authentication system 1 separates access to vehicle functions from the user 5, allowing them to be managed and set independently.

[0013] Using a vehicle function means performing a specific operation related to the vehicle 4, such as locking and unlocking the doors, opening and closing the doors, opening and closing the windows, operating the power seats, starting and stopping the engine, operating the air conditioner, operating the navigation system, operating the audio equipment, and various operations related to autonomous driving. In Figure 1, the implementation of such vehicle functions is represented by two functional blocks: input 6 and load 7. In addition, when using a vehicle function, multiple operations can be combined to use a single vehicle function. For example, a vehicle driving function can enable a series of operations required to drive a vehicle. In this case, the vehicle driving function includes unlocking doors, opening and closing windows, operating electric seats, starting and stopping the engine, and operating the air conditioner.

[0014] The input 6 includes, for example, input related to seat position settings, input related to air conditioning settings, and input by operating a navigation device. The input 6 includes, for example, switches, touch panels, and the like as input devices. The load 7 includes devices for locking and unlocking doors, devices for opening and closing windows, devices for operating power seats, and the like. In this case, the users 5 are assumed to be not only the owner of the vehicle 4, but also third parties such as the owner's family, users of the sharing service, and car maintenance providers, and the access rights for each vehicle function, i.e., permission or prohibition of use, are set for each user.

[0015] The vehicle-mounted device 2 is mounted on the vehicle 4 and functions as an in-vehicle device. The vehicle-mounted device 2 is used, for example, inside the vehicle 4. The vehicle-mounted device 2 includes a communication unit 8, a user setting database 9, a vehicle setting database 10, and a control device 11. Note that in this specification, the database may be abbreviated as DB. The communication unit 8 communicates with the center 3 and transmits and receives various data.

[0016] The user setting DB 9 is a DB for storing user-related information about the users 5 who use the vehicle 4, and functions as a first in-vehicle storage unit. The user-related information is information for managing and recording operations permitted for each user 5, i.e., the authorization to use vehicle functions, permitted vehicles, expiration dates, services, etc. The user-related information is composed of information such as that shown in FIG. 2. That is, the user-related information includes a user ID, authorization information, authentication information, and service settings. Note that ID is an abbreviation for identification.

[0017] The user ID is character information assigned to each user to identify the user, and corresponds to user identification information. The authorization information is information that represents the authority to use vehicle functions. The authorization information includes the authorization authority, the target vehicle, and the expiration date. The authentication information is information for authenticating the user, and is information that links the user ID with a key such as a smart key. The service settings are information that represent the settings of various services related to the vehicle 4, such as air conditioning settings, seat position settings, and autonomous driving settings. The service settings include a service ID and setting value information.

[0018] In this specification, authentication processing refers to a process of verifying who a user is. In the authentication processing, for example, a user is identified based on ID information collated by an authentication device (also referred to as an authentication device or authentication system). In the following description, the authentication device may also be referred to as an authentication device or authentication system. In addition, in this specification, authorization processing refers to a process of verifying who is requesting what to do with which resource, and determining whether to permit or deny the request. However, in this specification, authentication processing and authorization processing may also be collectively referred to as authentication processing. In this specification, authentication processing may also refer to identifying who the user 5 using the vehicle 4 is, and verifying whether or not the use of the vehicle function requested by the user 5 may be permitted.

[0019] Specifically, the user-related information stored in the user setting DB 9 of the vehicle-mounted device 2 is, for example, information as shown in FIG. 3. In this case, the user setting DB 9 stores user-related information corresponding to a user with a user ID of "001" and a user with a user ID of "002." These users are users who have actually used the vehicle 4. As will be described later, when a user who has never used the vehicle 4 before uses the vehicle 4 for the first time, the user-related information of that user is transferred from the center 3 and stored in the user setting DB 9. The authorization information includes, for example, authorization authorities such as "driving the vehicle," "opening the door," and "opening the trunk," and area designation such as "within XX city, within XX city." Furthermore, the authorization information may include, for example, a speed limit such as "60 km." The authorization information includes authorization authorities and authorization conditions.

[0020] The target vehicle of the authorization information is indicated by the VIN corresponding to the target vehicle, for example, "0001," "0002," or "0003." VIN is an abbreviation for Vehicle Identification Number. VIN is character information assigned to each vehicle to identify it, and corresponds to vehicle identification information. Vehicle identification information does not have to be limited to the VIN, and any information that can identify the vehicle will suffice. The expiration date is information that indicates the period during which use of the vehicle functions is permitted, for example, "XX year, XX month, XX day."

[0021] The service ID of the service setting is character information assigned to each service to identify the service, such as "002 (automatic driving)" or "003 (air conditioner)." The setting value information of the service setting is information that represents the setting value of the service, such as "Destination: XX Company," "Destination: △△ City Hall," "Temperature: 25°C," and "Air volume: Weak." Therefore, the setting value information differs for each service specified by the service ID.

[0022] The vehicle setting DB 10 is a DB for storing vehicle-related information about the vehicle 4, and functions as a second in-vehicle storage unit. The vehicle-related information is information for managing and recording information such as authorized users for each vehicle and expiration dates. The vehicle-related information is composed of information as shown in FIG. 4. That is, the vehicle-related information includes a VIN and user information. The user information includes a user ID, a user role, and an expiration date. Specifically, the vehicle-related information stored in the vehicle setting DB 10 of the in-vehicle device 2 is, for example, information as shown in FIG. 5.

[0023] In this case, the vehicle setting DB10 stores information about the vehicle 4 in which the on-board device 2 is installed, i.e., vehicle-related information corresponding to the vehicle 4 whose VIN is "0001." The vehicle-related information includes user information about each of the ten users whose user IDs are "001" to "010" and who are the target users of the vehicle 4. The user role in the user information is information that represents the attributes of the user, such as "sales department employee." Other examples of user roles include "owner," "family," "shared service user," and "car maintenance provider." The expiration date of the user information is information that represents the period during which use of the vehicle 4 is permitted, such as "unlimited."

[0024] The control device 11 is mainly configured with a microcomputer having a CPU, ROM, RAM, I / O, etc., and functions as an in-vehicle control unit that executes various processes. The control device 11 has functional blocks, namely, an authentication processing unit 12 that executes authentication processing and a synchronization processing unit 13 that executes synchronization processing. The details of the authentication processing and synchronization processing will be described later. Each functional block is realized by the CPU of the control device 11 executing a computer program stored in a non-transient tangible storage medium such as ROM, thereby executing processing corresponding to the computer program, that is, by software. Each functional block may be configured to be implemented in part or in whole by hardware.

[0025] The center 3 is a data management center including a server provided outside the vehicle 4, and functions as an external vehicle device. The center 3 is equipped with a communication unit 14, a user setting DB 15, a vehicle setting DB 16, and a control device 17. The communication unit 14 communicates with the vehicle-mounted device 2 of the vehicle 4 to send and receive various data. The user setting DB 15 is a DB for storing user-related information, and functions as a first external vehicle storage unit.

[0026] The user setting DB 15 includes a shared area 18 and a non-shared area 19. The user-related information stored in the shared area 18 becomes the same information as the information stored in the user setting DB 9 of the vehicle-mounted device 2 through a synchronization process described later. On the other hand, the user-related information stored in the non-shared area 19 is unique information that exists only in the user setting DB 15 of the center 3 and is not stored in the user setting DB 9 of the vehicle-mounted device 2.

[0027] In this embodiment, the description is based on the vehicle 4 whose VIN is "0001." Therefore, the information stored in the user setting DB 9 of the in-vehicle device 2 of the vehicle 4 whose VIN is "0001" is the same as the user-related information stored in the shared area 18 of the center 3. Similarly, for the vehicle 4 whose VIN is "0002," the information stored in the user setting DB 9 is the same as the user-related information stored in the shared area 18. However, the user-related information stored in the shared area 18 for the vehicle 4 whose VIN is "0001" is different from the user-related information stored in the shared area 18 for the vehicle 4 whose VIN is "0002." In other words, the shared area 18 and the non-shared area 19 change depending on the target vehicle 4. The same applies to the shared area 20 and the non-shared area 21 of the vehicle setting DB 16.

[0028] Specifically, the user-related information stored in the non-shared area 19 of the user setting DB 15 of the center 3 is, for example, information as shown in Fig. 6. In this case, the non-shared area 19 of the user setting DB 15 stores user-related information corresponding to a user with a user ID of "003." This user has no actual experience of using the vehicle 4, that is, is a potential user. In this case, "within the XX company premises" is exemplified as the area designation, and "20 km" is exemplified as the speed limit.

[0029] The vehicle setting DB 16 is a DB for storing vehicle-related information and functions as a second vehicle-exterior storage unit. The vehicle setting DB 16 includes a shared area 20 and a non-shared area 21. The vehicle-related information stored in the shared area 20 becomes the same information as the information stored in the vehicle setting DB 10 of the vehicle-mounted device 2 through a synchronization process described below. On the other hand, the vehicle-related information stored in the non-shared area 21 is unique information that exists only in the vehicle setting DB 16 of the center 3 and is not stored in the vehicle setting DB 10 of the vehicle-mounted device 2. Note that in this embodiment, the description is based on the vehicle 4. Therefore, the information in the non-shared area 19 and the non-shared area 21 is not shared with the information in the user setting DB 9 and the vehicle setting DB 10 provided in the vehicle 4, but may be shared with vehicles other than the vehicle 4.

[0030] 5, the information stored in the vehicle setting DB 10 of the in-vehicle device 2 registers user information that can use the vehicle 4, and includes user IDs of users who have never used the vehicle 4. Therefore, when a user who has never used the vehicle 4 and is set to be able to use the vehicle 4 uses the vehicle 4 for the first time, there may be cases where the user ID is registered in the vehicle setting DB 10 of the in-vehicle device 2, but the user ID is not stored in the user setting DB 9 of the in-vehicle device 2.

[0031] 7 shows an example of the vehicle setting information stored in the non-shared area 21 of the vehicle setting DB 16 of the center 3. In this case, the non-shared area 21 of the vehicle setting DB 16 stores vehicle-related information corresponding to all vehicles other than the vehicle 4 in which the on-board device 2 is installed, i.e., the vehicle 4 with the VIN "0001".

[0032] The control device 17 is mainly configured with a microcomputer having a CPU, ROM, RAM, I / O, etc., and functions as an in-vehicle control unit that executes various processes. The control device 17 has functional blocks, namely, an authentication processing unit 22 that executes authentication processing and a synchronization processing unit 23 that executes synchronization processing. Each functional block is realized by the CPU of the control device 17 executing a computer program stored in a non-transient physical storage medium such as ROM to execute processing corresponding to the computer program, i.e., by software. Each functional block may also be configured to be implemented in part or in whole by hardware.

[0033] In the above configuration, the synchronization processing unit 13 of the in-vehicle device 2 and the synchronization processing unit 23 of the center 3 execute synchronization processing to bidirectionally synchronize the user-related information stored in the user setting DB 9 of the in-vehicle device 2 with the user-related information stored in the shared area 18 of the user setting DB 15 of the center 3. In this case, the synchronization processing units 13, 23 also perform bidirectional synchronization between the vehicle-related information stored in the vehicle setting DB 10 of the in-vehicle device 2 and the vehicle-related information stored in the shared area 20 of the vehicle setting DB 16 of the center 3 during the synchronization processing.

[0034] "Bidirectional synchronization" means that the data stored in the user setting DB 9 of the in-vehicle device 2 and the data stored in the shared area 18 of the user setting DB 15 of the center 3 are kept the same. Therefore, if the user-related information stored in the user setting DB 9 of the in-vehicle device 2 is changed, the user-related information stored in the shared area 18 of the user setting DB 15 of the center 3 is also changed. Conversely, if the user-related information stored in the shared area 18 of the user setting DB 15 of the center 3 is changed, the user-related information stored in the user setting DB 9 of the in-vehicle device 2 is also changed.

[0035] The same applies to the vehicle-related information stored in the vehicle setting DB 10 of the in-vehicle device 2 and the vehicle-related information stored in the shared area 20 of the vehicle setting DB 16 of the center 3. If the vehicle-related information stored in the vehicle setting DB 10 of the in-vehicle device 2 is changed, the vehicle-related information stored in the shared area 20 of the vehicle setting DB 16 of the center 3 is also changed. If the vehicle-related information stored in the shared area 20 of the vehicle setting DB 16 of the center 3 is changed, the vehicle-related information stored in the vehicle setting DB 10 of the in-vehicle device 2 is also changed.

[0036] The center 3 is configured to be able to communicate with an external server 24. The external server 24 is accessible by the user 5. The user 5 can make changes such as adding or deleting users who use the vehicle 4, making changes such as adding or deleting access rights for each user to each vehicle function, and changing various settings of the vehicle 4 via the external server 24. When these changes are made, the external server 24 transmits information about the changes to the center 3. The center 3 updates the information stored in the user setting DB 15 and the vehicle setting DB 16 based on the change information provided by the external server 24. The center 3 and the external server 24 can also be configured as a single server.

[0037] In the above configuration, when a user 5 requests use of the vehicle 4, i.e., use of a vehicle function, the authentication processing unit 12 of the in-vehicle device 2 executes authentication processing to authenticate the target user, who is the user 5 who requested use of the vehicle 4, based on the user-related information stored in the user setting DB 9 and the vehicle-related information stored in the vehicle setting DB 10. If the authentication processing succeeds in authenticating the target user, the control device 11 of the in-vehicle device 2 reflects the service settings included in the user-related information corresponding to the target user in the vehicle 4. The authentication processing is configured to perform authentication based on at least one of a plurality of different authentication methods, such as not only a physical key or FOB key but also biometric authentication and smartphone authentication.

[0038] In this case, when there is no information corresponding to the target user in the user-related information stored in the user setting DB 9 of the in-vehicle device 2 and the vehicle-related information stored in the vehicle setting DB 10, the authentication processing unit 12 of the in-vehicle device 2 or the authentication processing unit 22 of the center 3 executes authentication processing based on the user-related information stored in the non-shared area 19 of the user setting DB 15 of the center 3. In the following description, the case where there is no information corresponding to the target user in the user-related information stored in the user setting DB 9 of the in-vehicle device 2 and the vehicle-related information stored in the vehicle setting DB 10 may be referred to as a case where there is insufficient information.

[0039] That is, in the above configuration, when information is insufficient, the authentication processing unit 12 of the in-vehicle device 2 can execute authentication processing based on the user-related information stored in the non-shared area 19 of the user setting DB 15 of the center 3. Hereinafter, the execution of authentication processing by the authentication processing unit 12 of the in-vehicle device 2 when information is insufficient will be referred to as "performing in-vehicle authentication when information is insufficient." When performing in-vehicle authentication when information is insufficient, the authentication processing unit 12 of the in-vehicle device 2 transfers the user-related information stored in the non-shared area 19 of the user setting DB 15 of the center 3 to the user setting DB 9 of the in-vehicle device 2, that is, downloads the user-related information from the non-shared area 19 of the user setting DB 15 of the center 3, and then executes authentication processing.

[0040] Furthermore, in the above configuration, when information is insufficient, the authentication processing unit 22 of the center 3 can execute authentication processing based on the user-related information stored in the non-shared area 19 of the user setting DB 15 of the center 3. Hereinafter, execution of authentication processing by the authentication processing unit 22 of the center 3 when information is insufficient in this manner will be referred to as "performing off-vehicle authentication when information is insufficient." When performing off-vehicle authentication when information is insufficient, the authentication processing unit 22 of the center 3 executes authentication processing and then transfers the user-related information stored in the non-shared area 19 of the user setting DB 15 of the center 3 to the user setting DB 9 of the in-vehicle device 2. As a result, the user-related information stored in the non-shared area 19 of the user setting DB 15 of the center 3 is additionally stored in the user setting DB 9 of the in-vehicle device 2.

[0041] In the above configuration, when at least one of the pieces of information stored in the user setting DB 15 and the vehicle setting DB 16 of the center 3 is updated in an offline state in which communication between the in-vehicle device 2 and the center 3 is not possible, synchronization processing is executed when the in-vehicle device 2 and the center 3 are subsequently placed in an online state in which communication between the in-vehicle device 2 and the center 3 is possible. Also, in the above configuration, when at least one of the pieces of information stored in the user setting DB 9 and the vehicle setting DB 10 of the in-vehicle device 2 is updated in an offline state, synchronization processing is executed when the in-vehicle device 2 is subsequently placed in an online state.

[0042] Next, the authentication method realized by the authentication system 1 having the above configuration will be described in detail with reference to a specific example. [1] User authentication when performing off-vehicle authentication when information is insufficient The user authentication process when performing off-vehicle authentication when there is insufficient information can be, for example, as shown in Fig. 8. In this case, authentication is assumed when the user 5 attempts to get into the vehicle 4 to use it. As shown in Fig. 8, this process is started when the user 5 performs a predetermined operation or action to request use of the vehicle 4. Note that in Fig. 8 and other figures, the start of the process is represented by a hollow circle, and the end of the process is represented by a filled circle.

[0043] In response to this, in step S101, the authentication processing unit 12 of the in-vehicle device 2 checks each piece of information stored in the user setting DB 9 and the vehicle setting DB 10, and performs authentication processing based on each piece of information. In step S102, the authentication processing unit 12 of the in-vehicle device 2 determines whether or not information corresponding to the user 5 is present in each piece of information checked in step S101, i.e., whether or not there is relevant information. If information corresponding to the user 5 is present, the result of step S102 becomes "YES," and the process proceeds to step S103 when authentication of the user 5 is successful through authentication processing. Note that if the result of step S102 becomes "YES," and authentication of the user 5 fails through authentication processing, an error occurs and the process ends.

[0044] In step S103, the control device 11 of the in-vehicle device 2 unlocks the doors, and in the following step S104, reflects the service settings, such as the seat position setting and the air conditioning setting, included in the user-related information corresponding to the user 5, in the vehicle 4. After step S104 is executed, the user authentication process ends. In this case, since the authentication is successful, the user 5 is able to get into the vehicle 4 and use various vehicle functions permitted based on the predetermined usage authority. In addition, in this case, the user 5 does not need to make any additional adjustments to the service settings, such as the seat position setting and the air conditioning setting, because the desired setting values ​​have already been reflected. Note that steps S103 and S104 correspond to using a vehicle function specified by a service ID and reflecting the setting value information in the vehicle. Steps S106 and S107, which will be described later, also correspond to using a vehicle function specified by a service ID and reflecting the setting value information in the vehicle.

[0045] If there is no information corresponding to the user 5 among the information checked in step S101, the result is "NO" in step S102, and the process proceeds to step S105. In step S105, the control device 11 of the vehicle-mounted device 2 determines whether or not it is online. If it is not online, that is, if it is offline, the result is "NO" in step S105, and the user authentication process ends. In this case, the authentication of the user 5 has failed, and the user 5 cannot board the vehicle 4.

[0046] On the other hand, if the vehicle is online, the result of step S105 is "YES," and the authentication processing unit 12 of the vehicle-mounted device 2 inquires of the authentication processing unit 22 of the center 3 about authentication of the user 5. In response to this, in step S201, the authentication processing unit 22 of the center 3 checks the information stored in the non-shared area 19 of the user setting DB 15 and the vehicle setting DB 16, and performs authentication processing based on the information. In step S202, the authentication processing unit 22 of the center 3 determines whether or not information corresponding to the user 5 is present in the information checked in step S201, i.e., whether or not the relevant information is present.

[0047] If there is no information corresponding to user 5, step S202 returns "NO" and the user authentication process ends. In this case, authentication of user 5 has failed, and user 5 cannot board the vehicle 4. Furthermore, in this case, the center 3 may notify the in-vehicle device 2 that authentication has failed. Then, the notification unit of the in-vehicle device 2 may notify user 5 that authentication has failed. On the other hand, if there is information corresponding to user 5 in the information confirmed in step S201, step S202 returns "YES," and the process proceeds to step S203 when authentication of user 5 is successful through the authentication process. In step S203, the authentication processing unit 22 of the center 3 transfers the user-related information stored in the non-shared area 19 of the user setting DB 15 of the center 3 to the user setting DB 9 of the in-vehicle device 2.

[0048] This updates the user setting DB 9 of the in-vehicle device 2. Thereafter, the control device 11 of the in-vehicle device 2 unlocks the doors in step S106, and then in step S107 reflects the service settings included in the user-related information corresponding to the user 5 in the vehicle 4. After step S106 is executed, the user authentication process ends. In this case, the user 5 can get into the vehicle 4 and use various vehicle functions, just as in the case where the user authentication process ends after step S104 is executed.

[0049] [2] User authentication when in-vehicle authentication is performed when information is insufficient The user authentication process when performing in-vehicle authentication when there is insufficient information can be, for example, as shown in Fig. 9. In this case, authentication is assumed when the user 5 gets into the vehicle 4 to use it. The user authentication process shown in Fig. 9 differs from the user authentication process shown in Fig. 8 in that steps S106 and S107 are omitted and steps S211 to S213 are provided instead of steps S201 to S203. In this case, the authentication processing unit 22 of the center 3 checks each piece of information stored in the non-shared area 19 of the user setting DB 15 and the vehicle setting DB 16 in step S211.

[0050] In step S212, the authentication processing unit 22 of the center 3 determines whether or not information corresponding to the user 5 is present in the information confirmed in step S211, i.e., whether or not there is relevant information. If there is no information corresponding to the user 5, the result in step S212 is "NO" and the user authentication process ends. In this case, the authentication of the user 5 has failed, and the user 5 cannot board the vehicle 4. On the other hand, if there is information corresponding to the user 5 in the information confirmed in step S211, the result in step S212 is "YES" and the process proceeds to step S213.

[0051] In step S213, the authentication processing unit 22 of the center 3 transfers the user-related information stored in the non-shared area 19 of the user setting DB 15 of the center 3 to the user setting DB 9 of the vehicle-mounted device 2. This updates the user setting DB 9 of the vehicle-mounted device 2. After step S213 is executed, the process returns to step S101. That is, in this case, in step S101 that is executed again, the authentication processing unit 12 of the vehicle-mounted device 2 checks the information stored in the user setting DB 9 and the vehicle setting DB 10 that have been updated by adding the user-related information stored in the non-shared area 19 of the user setting DB 15 of the center 3 as described above, and performs authentication processing based on the information.

[0052] [3] Synchronization process when information on the in-vehicle device is updated while online The synchronization process when the information stored in the user setting DB 9 and the vehicle setting DB 10 of the in-vehicle device 2 is updated while the device is online may be performed as shown in Fig. 10, for example. As shown in Fig. 10, this process is started when the user 5 gets into the vehicle 4 and performs an operation to change the vehicle settings, which are various settings related to the vehicle 4. In response to this, the control device 11 of the in-vehicle device 2 changes the vehicle settings in step S121.

[0053] Then, in step S122, the control device 11 of the in-vehicle device 2 updates each piece of information stored in the user setting DB 9 and the vehicle setting DB 10 in accordance with the change in the vehicle setting. In response to this, in step S221, the synchronization processing unit 23 of the center 3 updates each piece of information stored in the shared area 18 of the user setting DB 15 and the shared area 20 of the vehicle setting DB 16 so as to synchronize it with the information stored in the user setting DB 9 and the vehicle setting DB 10 of the in-vehicle device 2, that is, executes synchronization processing. After execution of step S221, the processing related to the synchronization processing ends.

[0054] [4] Synchronization process when information on the center side is updated while online The synchronization process when the information stored in the user setting DB 15 and the vehicle setting DB 16 of the center 3 is updated while the center 3 is online may be performed as shown in Fig. 11, for example. As shown in Fig. 11, this process is started when the user 5 performs an operation to change the vehicle setting via the external server 24. In response to this, the control device 17 of the center 3 changes the vehicle setting in step S231.

[0055] Then, in step S232, the control device 17 of the center 3 updates each piece of information stored in the shared area 18 of the user setting DB 15 and the shared area 20 of the vehicle setting DB 16 in accordance with the change in the vehicle setting. In response to this, in step S131, the synchronization processing unit 13 of the in-vehicle device 2 updates each piece of information stored in the user setting DB 9 and the vehicle setting DB 10 so as to synchronize with each piece of information stored in the shared area 18 of the user setting DB 15 and the shared area 20 of the vehicle setting DB 16 of the center 3, that is, executes synchronization processing. After execution of step S131, the processing related to the synchronization processing ends.

[0056] [5] Synchronization process when information on the center side is updated while offline The synchronization process when the information stored in the user setting DB 15 and the vehicle setting DB 16 of the center 3 is updated offline can be, for example, as shown in Fig. 12. The synchronization process shown in Fig. 12 differs from the synchronization process shown in Fig. 11 in that steps S233 and S234 are added. In this case, after step S232 is executed, the process proceeds to step S233.

[0057] In step S233, the control device 17 of the center 3 determines whether or not the device is online. If the device is online, the result of step S233 is "YES" and the process proceeds to step S131. On the other hand, if the device is not online, i.e., if the device is offline, the result of step S233 is "NO" and the process proceeds to step S234. The vehicle-mounted device 2 transitions to a sleep state after a certain period of time has elapsed since the ignition was turned off. If the vehicle-mounted device 2 transitions to the sleep state, communication between the vehicle-mounted device 2 and the center 3 cannot be performed. In such a case, if the vehicle-mounted device 2 transitions from the sleep state to the normal state, the vehicle-mounted device 2 will transition from the offline state to the online state.

[0058] Therefore, in step S234, the control device 17 of the center 3 executes a wake-up to transition the in-vehicle device 2 from the sleep state to the normal state. After execution of step S234, step S233 is executed again. Note that step S234 can be omitted. If step S234 is omitted, step S233 can be executed again if step S233 returns "NO." Note that there are cases where the in-vehicle device 2 does not transition to the normal state even when a wake-up command is issued from the center 3, for example, when the vehicle 4 is out of communication range or is undergoing repair. Therefore, the control device 17 of the center 3 may count the number of times that wake-up has been executed, and if the number of times that wake-up has been executed reaches a predetermined number, the control device 17 may not execute wake-up for a certain period of time.

[0059] In this manner, in this process, step S233 is repeatedly executed until the on-line state is achieved. Then, when the on-board device 2 is on-line, in step S131, the synchronization processing unit 13 of the on-board device 2 updates each piece of information stored in the user setting DB 9 and the vehicle setting DB 10 so as to synchronize it with each piece of information stored in the shared area 18 of the user setting DB 15 and the shared area 20 of the vehicle setting DB 16 of the center 3, that is, executes synchronization processing. After execution of step S131, the processing related to the synchronization processing is terminated.

[0060] [6] Synchronization process when information on the in-vehicle device is updated while offline The synchronization process when the information stored in the user setting DB 9 and the vehicle setting DB 10 of the vehicle-mounted device 2 is updated in an offline state may be, for example, as shown in Fig. 13. The synchronization process shown in Fig. 13 differs from the synchronization process shown in Fig. 10 in that step S123 is added. In this case, after step S122 is executed, the process proceeds to step S123.

[0061] In step S123, the control device 11 of the vehicle-mounted device 2 determines whether or not the device is online. If the device is online, the result of step S123 is "YES," and the process proceeds to step S221. On the other hand, if the device is not online, i.e., if the device is offline, the result of step S123 is "NO," and step S123 is executed again. In other words, step S123 is repeatedly executed until the device is online.

[0062] In this case, it is assumed that both the vehicle-mounted device 2 and the center 3 are running, but if the reception conditions of the radio waves used for communication are poor, for example, communication may not be possible between the vehicle-mounted device 2 and the center 3. In such a case, if the radio wave conditions improve, the vehicle-mounted device 2 will switch from an offline state to an online state.

[0063] Then, when the center 3 is placed in an online state, the synchronization processing unit 23 of the center 3 updates the information stored in the shared area 18 of the user setting DB 15 and the shared area 20 of the vehicle setting DB 16 in step S221 so as to synchronize it with the information stored in the user setting DB 9 and the vehicle setting DB 10 of the vehicle-mounted device 2, that is, executes synchronization processing. After execution of step S221, the processing related to the synchronization processing is completed.

[0064] According to the authentication system 1 of the present embodiment described above, when a vehicle is used not only by the vehicle owner but also by other users, the other users can easily be authenticated and can use various vehicle functions within the scope permitted based on predetermined usage rights. Furthermore, according to the authentication system 1, when a vehicle owner uses not only his / her own vehicle but also another vehicle such as a company car, the same settings as those in the vehicle owned by the user are reflected in the settings of the other vehicle, such as the seat position and air conditioning settings, without the need for additional adjustments, and if a car app is installed in the vehicle owned by the user, the car app can also be used in the other vehicle.

[0065] As described above, the authentication system 1 of this embodiment allows a single vehicle to be conveniently used by various users, and when one user uses multiple vehicles, various vehicle settings can be reflected in each vehicle. Therefore, this embodiment has the excellent effect of improving the convenience of vehicle use.

[0066] In the authentication system 1, the user-related information stored in the user setting DB 9 of the in-vehicle device 2 and the shared area 18 of the user setting DB 15 of the center 3 are synchronized by a synchronization process, and the vehicle-related information stored in the vehicle setting DB 10 of the in-vehicle device 2 and the shared area 20 of the vehicle setting DB 16 of the center 3 are synchronized by a synchronization process. In other words, the same information is stored and managed in the in-vehicle device 2 and the center 3. However, the user setting DB 15 of the center 3 includes a non-shared area 19, and this non-shared area 19 stores information that is not stored in the user setting DB 9 of the in-vehicle device 2, such as information corresponding to users who have no record of using the vehicle 4.

[0067] In the authentication system 1, when a user requests to use a vehicle, authentication processing is first performed based on the information stored in the user setting DB 9 and the vehicle setting DB 10 of the in-vehicle device 2. Then, in the case of information shortage, that is, when information corresponding to the target user does not exist in the user setting DB 9 and the vehicle setting DB 10 of the in-vehicle device 2, authentication processing is performed based on the information stored in the non-shared area 19 of the user setting DB 15 of the center 3. With this configuration, it is possible to properly authenticate users who have no history of using the vehicle 4. In this case, it is only necessary to store information corresponding to users who have a history of using the vehicle 4 in the user setting DB 9 of the in-vehicle device 2, thereby enabling efficient use of the storage area.

[0068] In the authentication system 1, when there is insufficient information, the authentication processing unit 12 of the in-vehicle device 2 can execute the authentication process based on the user-related information stored in the non-shared area 19 of the user setting DB 15 of the center 3. In this case, the authentication processing unit 12 of the in-vehicle device 2 executes the authentication process after downloading the user-related information from the non-shared area 19 of the user setting DB 15 of the center 3. In this way, the next time the same user requests to use the vehicle, the authentication process can be executed immediately using only the information in each DB of the in-vehicle device 2.

[0069] In the authentication system 1, when information is insufficient, the authentication processing unit 22 of the center 3 can execute authentication processing based on the user-related information stored in the non-shared area 19 of the user setting DB 15 of the center 3. In this case, the authentication processing unit 22 of the center 3 executes authentication processing and transfers the user-related information stored in the non-shared area 19 of the user setting DB 15 of the center 3 to the user setting DB 9 of the vehicle-mounted device 2. In this way, the next time the same user requests use of a vehicle, it becomes possible to immediately execute authentication processing using only the information in each DB of the vehicle-mounted device 2.

[0070] In the authentication system 1, when at least one of the pieces of information stored in the user setting DB 15 and the vehicle setting DB 16 of the center 3 is updated in an offline state in which communication between the in-vehicle device 2 and the center 3 is not possible, synchronization processing is executed when the in-vehicle device 2 and the center 3 subsequently enter an online state in which communication between the in-vehicle device 2 and the center 3 is possible. In this way, even if information in each DB on the center 3 side is updated while the in-vehicle device 2 is in a sleep state, synchronization processing is executed immediately when the in-vehicle device 2 returns to a normal state, thereby ensuring synchronization of the pieces of information stored in each DB of the in-vehicle device 2 and the center 3.

[0071] Furthermore, in the authentication system 1, when at least one of the pieces of information stored in the user setting DB 9 and the vehicle setting DB 10 of the vehicle-mounted device 2 is updated while the vehicle is offline, a synchronization process is executed when the vehicle is subsequently placed online. In this way, even if the information in each DB on the vehicle-mounted device 2 side is updated during a period when the reception conditions of the radio waves used for communication are poor, the synchronization process is executed immediately when the radio wave conditions improve, thereby ensuring synchronization of the pieces of information stored in the DBs of the vehicle-mounted device 2 and the center 3.

[0072] (Other embodiments) The present disclosure is not limited to the embodiments described above and shown in the drawings, and can be arbitrarily modified, combined, or expanded without departing from the spirit of the present disclosure. The numerical values ​​and the like shown in the above embodiment are examples and are not limited to these.

[0073] The specific contents of the user-related information stored in the shared area 18 of the user setting DB 9 of the vehicle-mounted device 2 and the user setting DB 15 of the center 3, the vehicle-related information stored in the shared area 20 of the vehicle setting DB 10 of the vehicle-mounted device 2 and the vehicle setting DB 16 of the center 3, the user-related information stored in the non-shared area 19 of the user setting DB 15 of the center 3, and the vehicle-related information stored in the non-shared area 21 of the vehicle setting DB 16 of the center 3, etc., are not limited to those described in the above embodiment and can be changed as appropriate.

[0074] For example, the vehicle-related information stored in the non-shared area 21 of the vehicle setting DB 16 of the center 3 can include information as shown in Fig. 14 in addition to the information shown in Fig. 7. The vehicle-related information shown in Fig. 14 is information corresponding to the vehicle 4 in which the on-board device 2 is installed, and includes the VIN corresponding to the vehicle 4 and user information for each of the ten users whose user IDs are "001" to "010" and who are targets of using the vehicle 4.

[0075] In this case, the user information includes a user ID, a vehicle service ID, a usage history, and an accumulated time. The vehicle service ID is character information assigned to each vehicle service to identify the vehicle service, such as an autonomous driving application. The usage history is information that represents the usage history, such as the number of times the vehicle service has been used. The accumulated time is information that represents the accumulated time the vehicle service has been used. Such vehicle-related information does not need to be stored on the vehicle-mounted device 2 side. Therefore, if such vehicle-related information is stored in the non-shared area 21 of the vehicle setting DB 16 of the center 3, various processes related to the vehicle service can be appropriately performed on the user who has used the vehicle service, such as charging a fee according to the number of times the vehicle service has been used and the usage time.

[0076] Although the present disclosure has been described with reference to the embodiments, it is understood that the present disclosure is not limited to the embodiments or structures. The present disclosure also encompasses various modifications and equivalent modifications. In addition, various combinations and forms, including only one element, more than one element, or less than one element, are also within the scope and spirit of the present disclosure.

[0077] The control device and the method described herein may be implemented by a special-purpose computer configured with a processor and memory programmed to perform one or more functions embodied in a computer program. Alternatively, the control device and the method described herein may be implemented by a special-purpose computer configured with a processor comprising one or more dedicated hardware logic circuits. Alternatively, the control device and the method described herein may be implemented by one or more special-purpose computers configured with a processor and memory programmed to perform one or more functions in combination with a processor configured with one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by a computer on a computer-readable non-transitory tangible storage medium.

Claims

1. An authentication system including an on-board device (2) mounted on a vehicle and an external device (3) provided outside the vehicle, the in-vehicle device and the external device are configured to be able to communicate with each other, The in-vehicle device a first vehicle interior storage unit (9) for storing user-related information relating to a user who uses the vehicle; a second vehicle interior storage unit (10) for storing vehicle-related information that is information about the vehicle and includes a VIN, which is information about the vehicle, and user information, which is information about a user who is a target user of the vehicle; an in-vehicle control unit (11) that executes various processes; Equipped with The external device is a first outside storage unit (15) including a shared area (18) and a non-shared area (19) for storing the user-related information; a second vehicle exterior storage unit (16) for storing the vehicle-related information; an exterior control unit (17) that executes various processes; Equipped with the interior-side control unit and the exterior-side control unit execute a synchronization process to bidirectionally synchronize the user-related information stored in the first interior-side storage unit and the user-related information stored in the shared area of ​​the first exterior-side storage unit, When a user requests use of the vehicle, the vehicle interior control unit executes an authentication process to authenticate a target user who has requested use of the vehicle based on the user-related information stored in the first vehicle interior storage unit and the vehicle-related information stored in the second vehicle interior storage unit, and if the authentication of the target user is successful in the authentication process, reflects the user-related information corresponding to the target user in the vehicle; In an authentication system in which, when there is insufficient information, i.e., when there is no information corresponding to the target user in the user-related information stored in the first in-vehicle storage unit and the vehicle-related information stored in the second in-vehicle storage unit, the in-vehicle control unit performs the authentication process based on the user-related information stored in the non-shared area of ​​the first outside-vehicle storage unit.

2. The authentication system according to claim 1 , wherein when the information is insufficient, the vehicle interior control unit executes the authentication process based on the user-related information stored in the non-shared area of ​​the first vehicle exterior storage unit.

3. 3. The authentication system according to claim 2, wherein when the information is insufficient, the vehicle interior control unit transfers the user-related information stored in the non-shared area of ​​the first vehicle exterior storage unit to the first vehicle interior storage unit and then executes the authentication process.

4. The authentication system according to claim 1 , wherein when the information is insufficient, the vehicle exterior control unit executes the authentication process based on the user-related information stored in the non-shared area of ​​the first vehicle exterior storage unit.

5. 5. The authentication system according to claim 4, wherein when the authentication process is performed when the information is insufficient, the vehicle exterior control unit transfers the user-related information stored in the non-shared area of ​​the first vehicle exterior storage unit to the first vehicle interior storage unit.

6. 6. The authentication system according to claim 1, wherein when the information stored in the first vehicle-external memory unit is updated in an offline state in which communication between the in-vehicle device and the external device is not possible, the synchronization process is executed when the system subsequently becomes online in which communication between the in-vehicle device and the external device is possible.

7. 7. The authentication system according to claim 1, wherein when the information stored in the first in-vehicle storage unit is updated in an offline state in which communication between the in-vehicle device and the external device is not possible, the synchronization process is executed when the system subsequently becomes online in which communication between the in-vehicle device and the external device is possible.

8. The second exterior storage unit includes a shared area (20) and a non-shared area (21), 8. The authentication system according to claim 1, wherein the vehicle-interior control unit and the vehicle-exterior control unit are configured to synchronize, in the synchronization process, the vehicle-related information stored in the second vehicle-interior storage unit and the vehicle-related information stored in the shared area of ​​the second vehicle-exterior storage unit in both directions.

9. 9. The authentication system according to claim 1, wherein the user-related information includes authorization information representing the authority to use functions of the vehicle, authentication information for authenticating the user, and service setting information representing setting values ​​of services of the vehicle.

10. The authentication system according to claim 1 , wherein the vehicle-related information includes vehicle identification information for identifying the vehicle and user identification information for identifying the user.

11. The authentication system according to claim 1 , wherein the authentication process includes identifying the target user and determining whether to permit the target user to use the vehicle as requested by the target user.

12. storing user-related information about a user who uses the vehicle in a first in-vehicle storage unit provided in an in-vehicle device mounted in the vehicle; storing vehicle-related information in a second vehicle-side storage unit included in the in-vehicle device, the vehicle-related information including a VIN, which is information about the vehicle, and user information, which is information about a user who is a target user of the vehicle; storing the user-related information in a first exterior storage unit that is provided in an exterior device provided outside the vehicle and that includes a shared area and a non-shared area; storing the vehicle-related information in a second exterior storage unit included in the exterior device; executing a synchronization process for bidirectionally synchronizing the user-related information stored in the first vehicle interior storage unit and the user-related information stored in the shared area of ​​the first vehicle exterior storage unit; When a user requests use of the vehicle, an authentication process is executed to authenticate a target user who has requested use of the vehicle based on the user-related information stored in the first vehicle interior storage unit and the vehicle-related information stored in the second vehicle interior storage unit, and if authentication of the target user is successful through the authentication process, the user-related information corresponding to the target user is reflected in the vehicle; When there is insufficient information, i.e., when there is no information corresponding to the target user in the user-related information stored in the first interior storage unit and the vehicle-related information stored in the second interior storage unit, executing the authentication process based on the user-related information stored in the non-shared area of ​​the first exterior storage unit; Authentication methods, including:

Citation Information

Patent Citations

  • Intelligent network connection automobile information safety platform based on end-pipe-cloud

    CN109714344A

  • Automatic vehicle setting device and setting method

    JP2007210457A

  • Personal identification device, personal identification system, personal identification method, and program

    JP2009043046A

  • Car sharing system

    JP2013254327A

  • Locking / unlocking system, key unit, and server

    JP2018145766A