Vehicle interlock system, mobile terminal and interlock program

The vehicle interlock system enhances security by requiring successful biometric and authentication on a mobile terminal to start a vehicle and alerts third parties to abnormal conditions, preventing unauthorized operation.

JP7770023B2Active Publication Date: 2025-11-14TRANSPORTATION SAFETY TECH CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
JP2022109951
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-07-07
Publication Date
2025-11-14
Estimated Expiration
2042-07-07

AI Technical Summary

Technical Problem

Existing vehicle key systems are vulnerable to unauthorized access and operation due to the potential for illegal copying of key identification information, allowing unauthorized individuals to drive vehicles illegally.

Method used

A vehicle interlock system that includes a mobile terminal with biometric and authentication capabilities, preventing the start of a vehicle's power source if specific authentication fails, and sending alerts to a third party if abnormal conditions are detected, such as cognitive impairment or excessive alcohol levels.

Benefits of technology

Reduces the likelihood of vehicles being operated illegally by unauthorized or impaired individuals by ensuring proper authentication and alerting third parties to potential unauthorized operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007770023000001
    Figure 0007770023000001
  • Figure 0007770023000002
    Figure 0007770023000002
  • Figure 0007770023000003
    Figure 0007770023000003
Patent Text Reader

Abstract

To provide a vehicle interlock system, a portable terminal and a program for interlock which can reduce the possibility that a vehicle may be illegally driven.SOLUTION: A vehicle interlock system includes an interlock device 20 for preventing start of an engine of a vehicle, and a portable terminal 30 including an interlock control part for controlling the interlock device. The interlock control part does not allow the interlock device to start the engine of the vehicle (S113 to S117) when face authentication of a user of the portable terminal 30 using the portable terminal 30 fails.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a vehicle interlock system, a mobile terminal, and an interlock program for preventing unauthorized driving of a vehicle. [Background technology]

[0002] Conventionally, wireless key devices installed in vehicles such as automobiles have been known (see, for example, Patent Document 1). When key identification information received from a wireless key owned by the vehicle driver matches key identification information registered in the wireless key device itself, the wireless key device unlocks or locks the vehicle doors and starts or stops the vehicle's power source. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2021-025313 Summary of the Invention [Problem to be solved by the invention]

[0004] However, the vehicle described in Patent Document 1 has a problem in that, for example, someone who illegally copies the radio waves indicating the key identification information transmitted from the wireless key can unlock the doors and start the power source, thereby potentially driving the vehicle illegally and stealing it.

[0005] Therefore, an object of the present invention is to provide a vehicle interlock system, a mobile terminal, and an interlock program that can reduce the possibility of a vehicle being driven fraudulently. [Means for solving the problem]

[0006] The vehicle interlock system of the present invention comprises an interlock device that prevents the start of a vehicle's power source, and a mobile terminal that has an interlock control unit that controls the interlock device, and the interlock control unit does not allow the interlock device to start the power source if specific authentication using the mobile terminal fails, and the specific authentication is at least one of biometric authentication of the user of the mobile terminal and authentication of the mobile terminal.

[0007] With this configuration, the vehicle interlock system of the present invention does not allow the interlock device to start the vehicle's power source if specific authentication using a mobile terminal fails, thereby reducing the possibility of the vehicle being operated illegally by an unauthorized person.

[0008] In the vehicle interlock system of the present invention, when the specific authentication using the mobile terminal is successful and the result of the assessment of the user's cognitive function is abnormal, the interlock control unit may not allow the interlock device to start the power source.

[0009] With this configuration, the vehicle interlock system of the present invention will not allow the interlock device to start the vehicle's power source if the result of the assessment of the user's cognitive function is abnormal, even if specific authentication using a mobile terminal is successful, thereby reducing the possibility of the vehicle being driven illegally by a person with abnormal cognitive function.

[0010] In the vehicle interlock system of the present invention, when the specific authentication using the mobile terminal is successful and the result of the determination of the alcohol concentration in the user's breath is abnormal, the interlock control unit may not allow the interlock device to start the power source.

[0011] With this configuration, the vehicle interlock system of the present invention will not allow the interlock device to start the vehicle's power source if the result of the determination of the alcohol concentration in the user's breath is abnormal, even if specific authentication using a mobile terminal is successful, thereby reducing the possibility of a vehicle being driven illegally by someone whose alcohol concentration in their breath is abnormal.

[0012] In the vehicle interlock system of the present invention, the mobile terminal may be provided with an information sending unit that sends information indicating that the specific authentication has failed to a specific destination if the specific authentication using the mobile terminal fails.

[0013] With this configuration, if a specific authentication using a mobile terminal fails, the vehicle interlock system of the present invention sends information indicating that the specific authentication has failed to a specific destination, thereby making it possible for a third party to recognize that the vehicle is about to be driven illegally by a person other than the legitimate driver, thereby reducing the possibility of the vehicle being driven illegally by a person other than the legitimate driver.

[0014] In the vehicle interlock system of the present invention, the mobile terminal may be provided with an information sending unit that, if the result is that the cognitive function is not normal, sends information indicating that the cognitive function is not normal to a specific destination.

[0015] With this configuration, if the result of the assessment of the user's cognitive function is that it is not normal, the vehicle interlock system of the present invention sends information indicating that the user's cognitive function is not normal to a specific destination, thereby making it possible for a third party to recognize that the vehicle is about to be driven illegally by a person with abnormal cognitive function, and as a result, reducing the possibility of the vehicle being driven illegally by a person with abnormal cognitive function.

[0016] In the vehicle interlock system of the present invention, the mobile terminal may be equipped with an information sending unit that, if the result is that the alcohol concentration is not normal, sends information indicating that the alcohol concentration is not normal to a specific destination.

[0017] With this configuration, if the result of the judgment of the alcohol concentration in the user's breath is abnormal, the vehicle interlock system of the present invention sends information indicating that the alcohol concentration in the user's breath is abnormal to a specific destination, thereby making it possible for a third party to recognize that the vehicle is about to be illegally driven by a person whose alcohol concentration in breath is abnormal, and as a result, reducing the possibility of the vehicle being illegally driven by a person whose alcohol concentration in breath is abnormal.

[0018] In the vehicle interlock system of the present invention, the mobile terminal is equipped with an information sending unit that sends the results of the assessment of the user's cognitive function to a specific destination, and when the specific authentication using the mobile terminal is successful, the interlock control unit may receive an instruction from outside the mobile terminal as to whether or not to allow the power source to start after the information sending unit sends the result to the specific destination, and control the interlock device in accordance with the received instruction.

[0019] With this configuration, in the vehicle interlock system of the present invention, after the mobile terminal sends the results of the assessment of the user's cognitive function to a specific destination, the mobile terminal receives an instruction on whether or not to allow the vehicle's power source to be started, and the mobile terminal controls the interlock device in accordance with the instruction it received.Therefore, the interlock device can allow or not allow the vehicle's power source to be started in accordance with instructions from a third party who recognizes the results of the assessment of the user's cognitive function, thereby reducing the possibility of the vehicle being driven illegally by a person with abnormal cognitive function.

[0020] In the vehicle interlock system of the present invention, the mobile terminal is equipped with an information sending unit that sends the results of the determination of the alcohol concentration in the user's breath to a specific destination, and when the specific authentication using the mobile terminal is successful, the interlock control unit may receive an instruction from outside the mobile terminal as to whether or not to allow the power source to start after the information sending unit sends the result to the specific destination, and control the interlock device in accordance with the received instruction.

[0021] With this configuration, in the vehicle interlock system of the present invention, after the mobile terminal sends the results of the determination of the alcohol concentration in the user's breath to a specific destination, the mobile terminal receives an instruction on whether or not to allow the vehicle's power source to start, and the mobile terminal controls the interlock device in accordance with the instruction received.Therefore, the interlock device can allow or not allow the vehicle's power source to start in accordance with instructions from a third party who recognizes the results of the determination of the alcohol concentration in the user's breath, thereby reducing the possibility of the vehicle being driven illegally by someone whose breath alcohol concentration is not normal.

[0022] The mobile terminal of the present invention is a mobile terminal equipped with an interlock control unit that controls an interlock device that prevents the start of a vehicle's power source, and is characterized in that the interlock control unit does not allow the interlock device to start the power source if specific authentication using the mobile terminal fails, and the specific authentication is at least one of biometric authentication of the user of the mobile terminal and authentication of the mobile terminal.

[0023] With this configuration, the mobile terminal of the present invention does not allow the interlock device to start the vehicle's power source if specific authentication using the mobile terminal fails, thereby reducing the possibility of the vehicle being operated illegally by someone other than the legitimate driver.

[0024] The interlock program of the present invention realizes an interlock control unit in a mobile terminal that controls an interlock device that prevents the start of a vehicle's power source, and the interlock control unit does not allow the interlock device to start the power source if specific authentication using the mobile terminal fails, and the specific authentication is at least one of biometric authentication of the user of the mobile terminal and authentication of the mobile terminal.

[0025] With this configuration, the mobile terminal executing the interlock program of the present invention will not allow the interlock device to start the vehicle's power source if specific authentication using the mobile terminal fails, thereby reducing the possibility of the vehicle being operated illegally by someone other than the legitimate driver. [Effects of the Invention]

[0026] The vehicle interlock system, the mobile terminal, and the interlock program of the present invention can reduce the possibility of a vehicle being driven illegally. [Brief explanation of the drawings]

[0027] [Figure 1] 1 is a block diagram of a vehicle interlock system according to a first embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram of the interlock device shown in FIG. [Figure 3] 2A and 2B are circuit diagrams of the vicinity of the starter motor of the vehicle shown in FIG. 1, which starts the engine using an ignition key and a push-button start, respectively. [Figure 4] FIG. 2 is a circuit diagram of the vicinity of the wiper motor of the vehicle shown in FIG. [Figure 5] FIG. 2 is a block diagram of the mobile terminal shown in FIG. [Figure 6] FIG. 2 is a block diagram of a third party terminal shown in FIG. [Figure 7]3 is a sequence diagram of the operation of the vehicle interlock system shown in FIG. 1 when performing personal authentication. [Figure 8] FIG. 6 is a front view of the mobile terminal shown in FIG. 5 when a PIN entry screen is displayed. [Figure 9] FIG. 6 is a front view of the mobile terminal shown in FIG. 5 when a license reader screen is displayed. [Figure 10] FIG. 6 is a front view of the mobile terminal shown in FIG. 5 when a face photographing screen is displayed. [Figure 11] 4 is a sequence diagram of the operation of the vehicle interlock system shown in FIG. 1 when an interlock application is started. FIG. [Figure 12] FIG. 12 is a sequence diagram of the main processing shown in FIG. [Figure 13] 13 is a flowchart showing the operation of the interlock device when the engine start relay is turned on in the operation shown in FIGS. 11 and 12. [Figure 14] 3 is a flowchart of the operation of the interlock device shown in FIG. 2 when the emergency button is pressed. [Figure 15] 3 is a flowchart of the operation of the interlock device shown in FIG. 2 in an emergency mode. [Figure 16] 3 is a flowchart of the operation of the interlock device shown in FIG. 2 when the panic button is activated. [Figure 17] 3 is a flowchart of the operation of the interlock device shown in FIG. 2 when a warning sound is issued in response to unauthorized driving of the vehicle. [Figure 18] FIG. 3 is a diagram showing an example of a portion of history information according to the first embodiment of the present invention. [Figure 19] FIG. 10 is a block diagram of a mobile terminal according to a second embodiment of the present invention. [Figure 20] FIG. 12 is a sequence diagram of the main process shown in FIG. 11 in the vehicle interlock system according to the second embodiment of the present invention. [Figure 21]21(a) is a front view of the mobile terminal shown in Fig. 5 when an example of a test execution screen is displayed, and (b) is a front view of the mobile terminal shown in Fig. 5 when an example of a test execution screen different from the example shown in Fig. 21(a) is displayed. [Figure 22] 22(a) is a front view of the mobile terminal shown in Fig. 5 when an example of a test result screen is displayed, and (b) is a front view of the mobile terminal shown in Fig. 5 when an example of a test result screen different from the example shown in Fig. 22(a) is displayed. [Figure 23] FIG. 10 is a diagram showing an example of a portion of history information according to a second embodiment of the present invention. [Figure 24] FIG. 10 is a block diagram of a third party terminal according to a third embodiment of the present invention. [Figure 25] FIG. 12 is a sequence diagram of the main process shown in FIG. 11 in the vehicle interlock system according to the third embodiment of the present invention. [Figure 26] FIG. 11 is a diagram showing an example of a portion of history information according to a third embodiment of the present invention. [Figure 27] FIG. 10 is a block diagram of a vehicle interlock system according to a fourth embodiment of the present invention. [Figure 28] FIG. 10 is a block diagram of a mobile terminal according to a fourth embodiment of the present invention. [Figure 29] FIG. 28 is a block diagram of the breath alcohol measurement device shown in FIG. 27. [Figure 30] 28 is a sequence diagram of the main processing shown in FIG. 11 in the vehicle interlock system shown in FIG. 27. [Figure 31] FIG. 13 is a diagram showing an example of a portion of history information according to a fourth embodiment of the present invention. [Figure 32] FIG. 12 is a sequence diagram of the main process shown in FIG. 11 in the vehicle interlock system according to the fifth embodiment of the present invention. [Figure 33] FIG. 13 is a diagram showing an example of a portion of history information according to the fifth embodiment of the present invention. [Figure 34] FIG. 13 is a block diagram of a mobile terminal according to a sixth embodiment of the present invention. [Figure 35]FIG. 12 is a sequence diagram of the main process shown in FIG. 11 in the vehicle interlock system according to the sixth embodiment of the present invention. [Figure 36] FIG. 23 is a diagram showing an example of a portion of history information according to the sixth embodiment of the present invention. [Figure 37] FIG. 12 is a sequence diagram of the main process shown in FIG. 11 in the vehicle interlock system according to the seventh embodiment of the present invention. [Figure 38] FIG. 20 is a diagram showing an example of a portion of history information according to the seventh embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0028] Hereinafter, embodiments of the present invention will be described with reference to the drawings.

[0029] (First embodiment) First, the configuration of a vehicle interlock system according to a first embodiment of the present invention will be described.

[0030] FIG. 1 is a block diagram of a vehicle interlock system 10 according to the present embodiment.

[0031] As shown in FIG. 1, the vehicle interlock system 10 includes an interlock device 20 that prevents the engine, which serves as a power source for the vehicle 90, from starting, a mobile terminal 30 that is a computer carried by the driver of the vehicle 90, a third-party terminal 50 that is a computer used by a third party other than the driver, and an authentication server 60 that performs facial authentication of the driver.

[0032] The interlock device 20 is mounted on a vehicle 90.

[0033] The mobile terminal 30 can be configured by, for example, a smartphone, etc. In the following, an example in which the mobile terminal 30 is configured by a smartphone will be described.

[0034] Third party terminal 50 can be configured, for example, by a PC (Personal Computer), a smartphone, etc. In the following, an example in which third party terminal 50 is configured by a PC will be described.

[0035] The authentication server 60 is realized by at least one computer.

[0036] The interlock device 20 and the mobile terminal 30 can communicate with each other using Bluetooth (registered trademark) Low Energy (BLE), with the mobile terminal 30 acting as the master and the interlock device 20 acting as the slave. The interlock device 20 and the mobile terminal 30 are preferably paired before the operation shown in FIG. 11 described below. BLE communication between the interlock device 20 and the mobile terminal 30 is encrypted to prevent a third party from analyzing the communication content. The encryption method for communication between the interlock device 20 and the mobile terminal 30 may be a known method such as a symmetric key encryption method, a public key encryption method, or a hybrid encryption method.

[0037] The mobile terminal 30 and the third-party terminal 50 can communicate with each other via the Internet 10a. For example, the mobile terminal 30 and the third-party terminal 50 may also communicate with each other via a cloud server. The communication between the mobile terminal 30 and the third-party terminal 50 is encrypted so that a third party cannot analyze the content of the communication. The encryption method for the communication between the mobile terminal 30 and the third-party terminal 50 may be a known method such as a symmetric key encryption method, a public key encryption method, or a hybrid encryption method.

[0038] The mobile terminal 30 and the authentication server 60 can communicate with each other via the Internet 10a. Communication between the mobile terminal 30 and the authentication server 60 is encrypted to prevent a third party from analyzing the contents of the communication. The encryption method for the communication between the mobile terminal 30 and the authentication server 60 may be a known method such as a symmetric key encryption method, a public key encryption method, or a hybrid encryption method.

[0039] FIG. 2 is a block diagram of the interlock device 20.

[0040] 2, the interlock device 20 includes an antenna 21a for wireless communication, a Bluetooth module 21b connected to the antenna 21a for performing BLE communication, an ACC input unit 22a for inputting the power status of an ACC (accessory) power supply of the vehicle 90 (see FIG. 1), a vehicle speed pulse input unit 22b for inputting a vehicle speed pulse from the vehicle 90, an emergency button 23 for starting the engine of the vehicle 90 in an emergency, an engine start relay 24 for starting the engine of the vehicle 90, a wiper relay 25 for operating the wipers of the vehicle 90, a buzzer 26 for outputting sounds, a nonvolatile memory 27 which is a storage device for storing various information, and a CPU (Central Processing Unit) 28 for overall control of the interlock device 20. The interlock device 20 receives power for operation from the +B (battery) power supply of the vehicle 90 and is always energized.

[0041] The non-volatile memory 27 can store history information 27a that indicates the history for the vehicle interlock system 10 (see FIG. 1).

[0042] The CPU 28 operates by executing a program stored in the nonvolatile memory 27, for example.

[0043] The engine start relay 24 includes a switch 24a and a switch 24b. The switches 24a and 24b are opened and closed simultaneously. That is, when the engine start relay 24 is in the ON state, it means that both the switches 24a and 24b are closed, and when the engine start relay 24 is in the OFF state, it means that both the switches 24a and 24b are open.

[0044] Fig. 3(a) is a circuit diagram of the vicinity of a starter motor 91 of a vehicle 90 (see Fig. 1) whose engine is started by an ignition key. Fig. 3(b) is a circuit diagram of the vicinity of a starter motor 91 of a vehicle 90 whose engine is started by a push start button.

[0045] The circuit shown in Figure 3(a) includes a starter motor 91 for starting the engine, an ignition relay 92 for starting the starter motor 91, and an ignition switch 93 for opening and closing the switch of the ignition relay 92. The ignition switch 93 is opened and closed by an ignition key (not shown). In a vehicle 90 including the circuit shown in Figure 3(a), after an ignition switch cable, which is a cable electrically connecting the ignition relay 92 and the ignition switch 93, is cut, one of the two terminals created by the cut of the ignition switch cable is electrically connected to one of the terminals on both sides of the switch 24a (see Figure 2) of the engine start relay 24 (see Figure 2), and the other of the two terminals created by the cut of the ignition switch cable is electrically connected to the other of the terminals on both sides of the switch 24a of the engine start relay 24. 2 of the switch 24a of the engine start relay 24 are electrically connected to the terminals a1 and a2 shown in Fig. 3(a), respectively. Therefore, in a vehicle 90 equipped with the circuit shown in Fig. 3(a), even if the ignition switch 93 is turned on (closed) by the ignition key, power is not supplied from the +B power supply to the ignition relay 92 electrically connected to the ignition switch 93 via the engine start relay 24, and the ignition relay 92 remains in the off state (open state), unless the engine start relay 24 is turned on (closed), power is not supplied from the +B power supply to the starter motor 91 electrically connected to the ignition relay 92, so the starter motor 91 does not rotate, and as a result, the engine does not start.

[0046] The circuit shown in Figure 3(b) includes a starter motor 91, an ignition relay 92, an ECU (Electronic Control Unit) 94 for opening and closing the switch of the ignition relay 92, and a push-button 95 for causing the ECU 94 to open and close the switch of the ignition relay 92. In a vehicle 90 including the circuit shown in Figure 3(b), after two cables, a first cable and a second cable, electrically connecting the ECU 94 and the push-start button 95, respectively, are cut, one of the two terminals created by the cut of the first cable is electrically connected to one of the terminals on both sides of the switch 24a (see Figure 2) of the engine start relay 24 (see Figure 2), and the other of the two terminals created by the cut of the first cable is electrically connected to the other of the terminals on both sides of the switch 24a of the engine start relay 24. Furthermore, one of the two terminals created by the cutting of the second cable is electrically connected to one of the terminals on both sides of switch 24b (see FIG. 2) of engine start relay 24, and the remaining one of the two terminals created by the cutting of the second cable is electrically connected to the remaining one of the terminals on both sides of switch 24b of engine start relay 24. That is, terminals a1, a2, b1, and b2 of engine start relay 24 shown in FIG. 2 are electrically connected to terminals a1, a2, b1, and b2 shown in FIG. 3(b), respectively. 3(b), even if the push start button 95 is pressed, unless the engine start relay 24 is turned ON (closed), the ECU 94, which is electrically connected to the push start button 95 via the engine start relay 24, does not receive a signal from the push start button 95 indicating that the push start button 95 has been pressed, and therefore, no power is supplied from the ECU 94 to the ignition relay 92, which remains in the OFF state. Therefore, no power is supplied from the +B power supply to the starter motor 91, which is electrically connected to the ignition relay 92, and so the starter motor 91 does not rotate, and as a result, the engine does not start.

[0047] The circuit shown in Fig. 3 is an example. The engine start relay 24 may be electrically connected to a location other than the connection location shown in Fig. 3, as long as it is electrically connected to a location that can prevent the engine of the vehicle 90 from starting unless the engine start relay 24 itself is in the ON state (closed state).

[0048] FIG. 4 is a circuit diagram of the vicinity of the wiper motor 96 of the vehicle 90 (see FIG. 1).

[0049] The circuit shown in Fig. 4 includes a wiper motor 96 for driving the wipers of the vehicle 90, and a wiper switch 97 for starting the wiper motor 96. In the vehicle 90, one of the terminals on both sides of the wiper switch 97 is electrically connected to one of the terminals on both sides of the switch of the wiper relay 25 (see Fig. 2), and the remaining one of the terminals on both sides of the wiper switch 97 is electrically connected to the remaining one of the terminals on both sides of the switch of the wiper relay 25. That is, the terminals c1 and c2 of the wiper relay 25 shown in Fig. 2 are electrically connected to the terminals c1 and c2 shown in Fig. 4, respectively.

[0050] FIG. 5 is a block diagram of the mobile terminal 30. As shown in FIG.

[0051] As shown in Figure 5, the mobile terminal 30 includes an operation unit 31 which is an operation device such as a button through which various operations are input, a display unit 32 which is a display device such as an LCD (Liquid Crystal Display) that displays various information, a microphone 33, a speaker 34, a camera 35, a communication unit 36 ​​which is a communication device that communicates with external devices via a network such as a LAN (Local Area Network) or the Internet, or directly via a wired or wireless connection without using a network, a memory unit 37 which is a non-volatile memory device such as a semiconductor memory that stores various information, and a control unit 38 that controls the entire mobile terminal 30.

[0052] A part of the operation unit 31 and the display unit 32 form a touch panel.

[0053] The microphone 33 and the speaker 34 are used for voice calls and video calls, for example, while the display unit 32 and the camera 35 are used for video calls, for example.

[0054] The storage unit 37 stores an identity authentication application 37a, which is an application program for authenticating that the driver is a pre-registered driver (hereinafter referred to as "identity authentication"), and an interlock application 37b, which is an application program for the vehicle interlock system 10 (see FIG. 1). The identity authentication application 37a and the interlock application 37b constitute an interlock program of the present invention. The identity authentication application 37a and the interlock application 37b may each be installed on the mobile terminal 30 during the manufacturing stage of the mobile terminal 30, or may be additionally installed on the mobile terminal 30 from an external storage medium, or may be additionally installed on the mobile terminal 30 from a network, for example.

[0055] The storage unit 37 can store history information 37c that indicates the history of the vehicle interlock system 10.

[0056] The storage unit 37 can store address information 37d that indicates the email address of the user of the third party terminal 50 (see FIG. 1).

[0057] The control unit 38 includes, for example, a CPU, a ROM (Read Only Memory) that stores programs and various data, and a RAM (Random Access Memory) that serves as a memory used as a work area for the CPU of the control unit 38. The CPU of the control unit 38 executes programs stored in the storage unit 37 or the ROM of the control unit 38.

[0058] By executing identity authentication application 37a, control unit 38 realizes identity authentication unit 38a that performs identity authentication, information transmission unit 38b that transmits information to a specific destination, history writing unit 38c that writes history to history information 37c, and notification execution unit 38d that executes notification to the user. The method of transmission to the specific destination by information transmission unit 38b may be, for example, an email addressed to the email address indicated in address information 37d.

[0059] By executing interlock application 37b, control unit 38 realizes interlock control unit 38e that controls interlock device 20 (see FIG. 1), information sending unit 38f that sends information to a specific destination, history writing unit 38g that writes a history to history information 37c, and notification execution unit 38h that executes a notification to the user. The method of sending information to the specific destination by information sending unit 38f may be, for example, sending an email to the email address indicated in address information 37d.

[0060] FIG. 6 is a block diagram of the third party terminal 50. As shown in FIG.

[0061] As shown in FIG. 6, the third-party terminal 50 includes an operation unit 51 which is an operation device such as a keyboard or mouse through which various operations are input, a display unit 52 which is a display device such as an LCD that displays various information, a microphone 53, a speaker 54, a camera 55, a communication unit 56 which is a communication device that communicates with external devices via a network such as a LAN or the Internet, or directly via a wired or wireless connection without using a network, a memory unit 57 which is a non-volatile memory device such as a semiconductor memory that stores various information, and a control unit 58 that controls the entire third-party terminal 50.

[0062] The microphone 53 and the speaker 54 are used for voice calls and video calls, for example, while the display unit 52 and the camera 55 are used for video calls, for example.

[0063] The storage unit 57 stores an interlock application 57a, which is an application program for the vehicle interlock system 10 (see FIG. 1). The interlock application 57a ​​may be installed in the third party terminal 50 during the manufacturing stage of the third party terminal 50, or may be additionally installed in the third party terminal 50 from an external storage medium, or may be additionally installed in the third party terminal 50 from a network, for example.

[0064] The storage unit 57 can store history information 57b that indicates the history of the vehicle interlock system 10.

[0065] Control unit 58 includes, for example, a CPU, a ROM that stores programs and various data, and a RAM as memory used as a work area for the CPU of control unit 58. The CPU of control unit 58 executes programs stored in storage unit 57 or the ROM of control unit 58.

[0066] By executing the interlock application 57a, the control unit 58 realizes a history writing unit 58a that writes a history into the history information 57b and a notification execution unit 58b that executes a notification to the user.

[0067] Next, the operation of the vehicle interlock system 10 will be described.

[0068] First, the operation of the vehicle interlock system 10 when the driver drives the vehicle 90 by turning on the engine start relay 24 using the mobile terminal 30 will be described.

[0069] FIG. 7 is a sequence diagram of the operation of the vehicle interlock system 10 when performing personal authentication.

[0070] As shown in FIG. 7, when an operation for unlocking the screen is input via the operation unit 31, the control unit 38 of the mobile terminal 30 unlocks the screen (S101).

[0071] FIG. 8 is a front view of the mobile terminal 30 when a PIN entry screen 71 for accepting entry of a PIN (Personal Identification Number) is displayed.

[0072] For example, when the input of a PIN is adopted as the operation for unlocking the screen, the control unit 38 displays a PIN input screen 71 (see FIG. 8) on the display unit 32.

[0073] 8, the PIN input screen 71 includes a numeric keypad 71a used to input a PIN and a display area 71b in which the PIN input using the numeric keypad 71a is displayed. If the PIN input via the PIN input screen 71 is the same as a PIN pre-registered in the mobile terminal 30, the control unit 38 unlocks the screen in S101 (see FIG. 7).

[0074] As shown in Figure 7, when the screen lock is released in S101, the personal authentication unit 38a of the mobile terminal 30 reads information from the IC card license 80 (see Figure 9), which is a driver's license embedded with an IC (Integrated Circuit) chip that records information related to the driver's license (S102).

[0075] FIG. 9 is a front view of the mobile terminal 30 when a license reader screen 72 for reading information from an IC card driver's license 80 is displayed.

[0076] 9, the personal authentication unit 38a displays a license reader screen 72 on the display unit 32. The license reader screen 72 includes a numeric keypad 72a used to input a personal identification number for reading information from an IC card license 80. The personal authentication unit 38a can read information from the IC card license 80 when the personal identification number input via the license reader screen 72 while in a state in which communication with the IC card license 80 is possible via the communication unit 36 ​​is the same as the personal identification number pre-registered in the IC card license 80.

[0077] 7, after reading information from the IC card license 80 in S102, the personal authentication unit 38a performs confirmation (hereinafter referred to as "license confirmation") based on the information read from the IC card license 80 in S102 that the IC card license 80 is a valid IC card license of a driver who is pre-registered in the mobile terminal 30 (S103). For example, the personal authentication unit 38a can determine whether the IC card license 80 is the IC card license of a driver who is pre-registered in the mobile terminal 30 based on the name and date of birth read from the IC card license 80. Furthermore, the personal authentication unit 38a can determine whether the IC card license 80 is a valid IC card license based on the validity period read from the IC card license 80.

[0078] If it is determined in S103 that the IC card license 80 whose information was read in S102 is not an IC card license within the validity period of the driver pre-registered in the portable terminal 30, i.e., if the license verification performed in S103 fails, the information transmitting unit 38b of the portable terminal 30 transmits information indicating the failure of the license verification to a specific destination (S104).

[0079] Furthermore, if the license verification executed in S103 fails, the history writing unit 38c of the mobile terminal 30 writes a history indicating the failure of the license verification into the history information 37c (S105).

[0080] In addition, if the license verification performed in S103 fails, the notification execution unit 38d of the mobile terminal 30 notifies the user of the mobile terminal 30, for example, via at least one of the display unit 32 and the speaker 34, that "You cannot start the engine" (S106).

[0081] When the third party terminal 50 receives the information sent to the specific destination in S104, the history writing unit 58a of the third party terminal 50 writes a history indicating that the license verification has failed into the history information 57b (S107).

[0082] Furthermore, when the third-party terminal 50 receives the information sent to the specific destination in S104, the notification execution unit 58b of the third-party terminal 50 notifies the user of the third-party terminal 50 of the failure of license verification, for example, via at least one of the display unit 52 and the speaker 54 (S108).

[0083] If the personal authentication unit 38a of the portable terminal 30 determines in S103 that the IC card license 80 whose information was read in S102 is an IC card license that is within the validity period of the driver pre-registered in the portable terminal 30, that is, if the license verification performed in S103 is successful, it takes a photograph of the driver's face using the camera 35 (S109).

[0084] FIG. 10 is a front view of the mobile terminal 30 when a face photographing screen 73 for taking a face photograph of the driver is displayed.

[0085] 10, the personal authentication unit 38a displays a face photographing screen 73 on the display unit 32. The face photographing screen 73 displays an image captured by the camera 35. Therefore, the driver, who is the user of the portable terminal 30, can hold the portable terminal 30 so that the driver's own face is displayed on the face photographing screen 73.

[0086] As shown in FIG. 7, after the process of S109, the personal authentication unit 38a requests the authentication server 60 to perform face authentication by transmitting the facial photograph taken in S109 to the authentication server 60 (S110).

[0087] Upon receiving the request in S110, the authentication server 60 performs face authentication using the face included in the facial photograph sent from the mobile terminal 30 in S110 and faces pre-registered in the authentication server 60 (S111). Here, the authentication server 60 determines that face authentication has been successful if the face of the person identical to the person whose face is included in the facial photograph sent from the mobile terminal 30 in S110 is registered in the authentication server 60. On the other hand, the authentication server 60 determines that face authentication has failed if the face of the person identical to the person whose face is included in the facial photograph sent from the mobile terminal 30 in S110 is not registered in the authentication server 60.

[0088] After the process of S111, the authentication server 60 transmits information indicating the result of the face authentication executed in S111 to the mobile terminal 30 (S112).

[0089] When the information indicating the failure of face authentication is transmitted in S112, the information transmitting unit 38b of the mobile terminal 30 transmits the information indicating the failure of face authentication to a specific destination (S113).

[0090] Furthermore, when information indicating a failure in face authentication is transmitted in S112, the history writing unit 38c of the mobile terminal 30 writes a history indicating the success of license verification and the failure in face authentication into the history information 37c (S114).

[0091] In addition, if information indicating a failure of face authentication is transmitted in S112, the notification execution unit 38d of the mobile terminal 30 notifies the user of the mobile terminal 30, for example, via at least one of the display unit 32 and the speaker 34, that "You cannot start the engine" (S115).

[0092] When the third party terminal 50 receives the information transmitted in S113, the history writing unit 58a of the third party terminal 50 writes a history indicating the success of the license verification and the failure of the face authentication into the history information 57b (S116).

[0093] Furthermore, when the third-party terminal 50 receives the information transmitted in S113, the notification execution unit 58b of the third-party terminal 50 notifies the user of the success of license verification and the failure of face authentication, for example, via at least one of the display unit 52 and the speaker 54 (S117).

[0094] If the information indicating the success of the face authentication is transmitted in S112, the personal authentication unit 38a of the mobile terminal 30 permits the interlock application 37b to be started (S118).

[0095] If the activation of the interlock application 37b is permitted in S118, the control unit 38 of the mobile terminal 30 activates the interlock application 37b when an instruction to activate the interlock application 37b is given via the operation unit 31 of the mobile terminal 30.

[0096] 11 is a sequence diagram of the operation of the vehicle interlock system 10 when the interlock application 37b is started up. FIG. 12 is a sequence diagram of the main process shown in FIG.

[0097] The CPU 28 of the interlock device 20 periodically transmits BLE advertisements when the CPU 28 is not connected to the mobile terminal 30, i.e., when the CPU 28 is offline. Note that the transmitted advertisements are not encrypted.

[0098] 11 and 12, when the control unit 38 of the mobile terminal 30 starts the interlock application 37b, the interlock control unit 38e of the mobile terminal 30 requests a connection via BLE to the interlock device 20 (S131). Note that the communication in S131 is not encrypted.

[0099] When the CPU 28 of the interlock device 20 receives a request in S131 from the mobile terminal 30 with which it has already been paired, it completes the BLE connection with the mobile terminal 30 (S132) and transmits information indicating the completion of the BLE connection with the mobile terminal 30 to the mobile terminal 30 (S133).

[0100] After executing the transmission in S133, the CPU 28 transmits the history written in the history information 27a when in the offline state to the mobile terminal 30 (S134).

[0101] When the portable terminal 30 receives the history transmitted in S134, the information transmitting unit 38f of the portable terminal 30 transmits the received history to a specific destination (S135).

[0102] Furthermore, when the mobile terminal 30 receives the history transmitted in S134, the history writing unit 38g of the mobile terminal 30 writes the received history into the history information 37c (S136).

[0103] When third party terminal 50 receives the history transmitted in S135, history writing unit 58a of third party terminal 50 writes the received history into history information 57b (S137).

[0104] When the mobile terminal 30 receives the information transmitted in S133, the interlock control unit 38e of the mobile terminal 30 instructs the interlock device 20 to turn on the engine start relay 24 (S141).

[0105] When the CPU 28 of the interlock device 20 receives the instruction in S141, it turns on the engine start relay 24 (S142).

[0106] After the process of S142, the CPU 28 transmits information indicating that the engine start relay 24 has been turned on to the mobile terminal 30 (S143).

[0107] After the process of S142, the CPU 28 writes a history indicating the success of the license verification, the success of the face authentication, and the completion of the ON state of the engine start relay 24 into the history information 27a (S144).

[0108] When the mobile terminal 30 receives the information transmitted in S143, the information transmitting unit 38f of the mobile terminal 30 transmits information indicating that the engine start relay 24 has been turned on to a specific destination (S145).

[0109] Furthermore, when the portable terminal 30 receives the information transmitted in S143, the history writing unit 38g of the portable terminal 30 writes a history indicating successful license verification, successful face authentication, and completion of the ON state of the engine start relay 24 into the history information 37c (S146).

[0110] Furthermore, when the mobile terminal 30 receives the information transmitted in S143, the notification execution unit 38h of the mobile terminal 30 notifies the user of the mobile terminal 30, for example, via at least one of the display unit 32 and the speaker 34, that "Please start the engine" (S147).

[0111] When the third-party terminal 50 receives the information transmitted in S145, the history writing unit 58a of the third-party terminal 50 writes a history indicating the success of license verification, the success of face authentication, and the completion of the ON state of the engine start relay 24 into the history information 57b (S148).

[0112] Furthermore, when the third-party terminal 50 receives the information transmitted in S145, the notification execution unit 58b of the third-party terminal 50 notifies the user of the third-party terminal 50 of the success of the license verification, the success of the face authentication, and the completion of the ON state of the engine start relay 24, for example, via at least one of the display unit 52 and the speaker 54 (S149).

[0113] When the mobile terminal 30 receives the information transmitted in S143, the interlock control unit 38e of the mobile terminal 30 disconnects the BLE connection with the interlock device 20 (S150). The communication in S150 is not encrypted. The reason why the BLE connection between the interlock device 20 and the mobile terminal 30 is not maintained all the time is, for example, to reduce battery consumption of the mobile terminal 30.

[0114] FIG. 13 is a flowchart of the operation of the interlock device 20 when the engine start relay 24 is turned on in the operation shown in FIGS.

[0115] When the CPU 28 of the interlock device 20 turns on the engine start relay 24 in S142 (see FIG. 12), it determines whether the ACC power supply has changed from an OFF state to an ON state based on the input to the ACC input unit 22a (S161), as shown in FIG. 13.

[0116] 3(a), when the engine start relay 24 is in the ON state, if the ignition switch 93 is turned from the OFF state (open state) to the ON state (closed state) by the ignition key, the ACC power supply changes from the OFF state to the ON state, and power is supplied from the +B power supply to the ignition relay 92, which is electrically connected to the ignition switch 93 via the engine start relay 24, so that the ignition relay 92 changes from the OFF state (open state) to the ON state (closed state). Therefore, power is supplied from the +B power supply to the starter motor 91, which is electrically connected to the ignition relay 92, so that the starter motor 91 rotates, and as a result, the engine is started by the starter motor 91.

[0117] 3(b), when the engine start relay 24 is in the ON state and the ACC power supply is in the OFF state, if the push start button 95 is pressed, a signal indicating that the push start button 95 has been pressed is input from the push start button 95 to the ECU 94, which is electrically connected to the push start button 95 via the engine start relay 24, so that the ACC power supply changes from OFF to ON, and power is supplied from the ECU 94 to the ignition relay 92, which changes the ignition relay 92 from OFF to ON. Therefore, power is supplied from the +B power supply to the starter motor 91, which is electrically connected to the ignition relay 92, so that the starter motor 91 rotates, and as a result, the engine is started by the starter motor 91.

[0118] As explained above, when the ACC power supply changes from the OFF state to the ON state, it means that the engine has started.

[0119] If the CPU 28 determines in S161 that the ACC power supply has not been changed from an OFF state to an ON state, it determines whether or not a specific time has elapsed since the start of the operation shown in Fig. 13 (S162). The specific time in S162 is, for example, about 1 to 3 minutes.

[0120] When the CPU 28 determines in S162 that a specific time has elapsed since the start of the operation shown in FIG. 13, it turns the engine start relay 24 to the OFF state (S163).

[0121] Next, the CPU 28 writes a history indicating the occurrence of the timeout and the completion of the OFF state of the engine start relay 24 to the history information 27a (S164). The history written to the history information 27a in S164 is the history written to the history information 27a in the offline state, and is to be transmitted to the mobile terminal 30 in the next processing of S134 (see FIG. 11).

[0122] If the CPU 28 determines in S162 that a specific time has not elapsed since the start of the operation shown in FIG. 13, it executes the process of S161.

[0123] When the CPU 28 determines in S161 that the ACC power supply has changed from an OFF state to an ON state, it writes a history indicating the start of the engine of the vehicle 90 to the history information 27a (S165). The history written to the history information 27a in S165 is the history that would have been written to the history information 27a in the offline state, and is to be transmitted to the mobile terminal 30 in the next processing of S134.

[0124] After the process of S165, the CPU 28 determines whether the ACC power supply has changed from the ON state to the OFF state based on the input to the ACC input unit 22a until it determines that the ACC power supply has changed from the ON state to the OFF state (S166).

[0125] If the vehicle 90 is equipped with the circuit shown in Fig. 3(a), when the engine start relay 24 is in the ON state and the ignition switch 93 is turned OFF by the ignition key, the ACC power supply changes from ON to OFF and the engine stops. Also, if the vehicle 90 is equipped with the circuit shown in Fig. 3(b), when the engine start relay 24 is in the ON state and the ACC power supply is in the ON state and the push start button 95 is pressed, the ACC power supply changes from ON to OFF and the engine stops. As explained above, the ACC power supply changing from ON to OFF means that the engine has stopped.

[0126] When the CPU 28 determines in S166 that the ACC power supply has changed from an ON state to an OFF state, it sets the engine start relay 24 to an OFF state (S167).

[0127] Next, the CPU 28 writes a history indicating the stopping of the engine of the vehicle 90 and the completion of the OFF state of the engine start relay 24 into the history information 27a (S168). The history written into the history information 27a in S168 is the history written into the history information 27a in the offline state, and is to be transmitted to the mobile terminal 30 in the next processing of S134.

[0128] When the process of S164 or S168 ends, the CPU 28 ends the operation shown in FIG.

[0129] Next, the operation of the interlock device 20 when the driver operates the emergency button 23 to drive the vehicle 90 will be described.

[0130] FIG. 14 is a flowchart of the operation of the interlock device 20 when the emergency button 23 is pressed.

[0131] When the CPU 28 of the interlock device 20 is in the offline state, it executes the operation shown in FIG.

[0132] 14, the CPU 28 sets a specific time as the value of a start enable time timer for measuring the time until the engine of the vehicle 90 can be started (S181). The specific time in S181 is, for example, 24 hours.

[0133] After the process of S181, CPU 28 determines whether or not panic button 23 has been pressed until it determines that panic button 23 has been pressed (S182). For example, the driver may press panic button 23 when the driver is unable to normally execute the operations shown in Figures 7, 11, and 12 due to some malfunction, such as a malfunction of mobile terminal 30.

[0134] When the CPU 28 determines in S182 that the emergency button 23 has been pressed, it determines whether or not the emergency button information, which is information indicating whether or not the emergency button 23 is valid, indicates that the emergency button 23 is valid (S183).

[0135] If the CPU 28 determines in S183 that the panic button information does not indicate that the panic button 23 is valid, that is, that the panic button information indicates that the panic button 23 is invalid, the CPU 28 executes the process of S182.

[0136] When the CPU 28 determines in S183 that the panic button information indicates that the panic button 23 is valid, it writes into the panic button information that the panic button 23 is not valid, that is, that the panic button 23 is invalid (S184).

[0137] After the process of S184, the CPU 28 starts counting down the start possible time timer (S185). The minimum value of the start possible time timer is 0.

[0138] After processing S185, the CPU 28 turns the engine start relay 24 to the ON state (S186). Here, if the vehicle 90 is equipped with the circuit shown in FIG. 3(a), when the engine start relay 24 is in the ON state, and the ignition switch 93 is turned from the OFF state to the ON state by the ignition key, the engine is started by the starter motor 91 as described above. Also, if the vehicle 90 is equipped with the circuit shown in FIG. 3(b), when the engine start relay 24 is in the ON state and the ACC power supply is in the OFF state, and the push start button 95 is pressed, the engine is started by the starter motor 91 as described above.

[0139] After the process of S186, the CPU 28 writes a history indicating the start of an operation mode that enables the engine of the vehicle 90 to be started in an emergency (hereinafter referred to as the "emergency mode") into the history information 27a (S187). The history written into the history information 27a in S187 is the history that would have been written into the history information 27a in the offline state, and is to be transmitted to the mobile terminal 30 in the next process of S134 (see FIG. 11).

[0140] After the process of S187, CPU 28 starts outputting a warning sound from buzzer 26 (S188). Therefore, the driver of vehicle 90 can recognize from the warning sound output by buzzer 26 that the current operation mode of interlock device 20 is the emergency mode.

[0141] After processing S188, the CPU 28 sets the wiper relay 25 to the ON state (closed state) (S189). When the wiper relay 25 is in the ON state, power is supplied from the +B power supply to the wiper motor 96 electrically connected to the wiper relay 25, regardless of whether the wiper switch 97 is in the ON state (closed state). Therefore, the wiper motor 96 rotates, and as a result, the wipers of the vehicle 90 continue to be moved by the wiper motor 96. Therefore, a person outside the vehicle 90 can recognize from the movement of the wipers that the current operating mode of the interlock device 20 is the emergency mode.

[0142] FIG. 15 is a flowchart of the operation of the interlock device 20 in the emergency mode.

[0143] When the CPU 28 of the interlock device 20 turns on the engine start relay 24 in S186 (see FIG. 14), it executes the operation shown in FIG.

[0144] 15, the CPU 28 determines whether the ACC power supply has changed from an OFF state to an ON state based on the input to the ACC input unit 22a (S211). As described above, when the engine start relay 24 is in the ON state, the change of the ACC power supply from an OFF state to an ON state means that the engine has started.

[0145] If the CPU 28 determines in S211 that the ACC power supply has not been changed from an OFF state to an ON state, it determines whether the engine start relay 24 has been changed to an OFF state (S212).

[0146] If the CPU 28 determines in S212 that the engine start relay 24 is not in the OFF state, it executes the process of S211.

[0147] When the CPU 28 determines in S211 that the ACC power supply has changed from an OFF state to an ON state, it writes a history indicating the start of the engine of the vehicle 90 to the history information 27a (S213). The history written to the history information 27a in S213 is the history that would have been written to the history information 27a in the offline state, and is to be transmitted to the mobile terminal 30 in the next processing of S134 (see FIG. 11).

[0148] After the process of S213, CPU 28 determines whether the ACC power supply has changed from the ON state to the OFF state based on the input to ACC input unit 22a until it determines that the ACC power supply has changed from the ON state to the OFF state (S214). Here, the fact that the ACC power supply has changed from the ON state to the OFF state means that the engine has stopped, as described above.

[0149] When the CPU 28 determines in S214 that the ACC power supply has changed from an ON state to an OFF state, it writes a history indicating that the engine of the vehicle 90 has stopped in the history information 27a (S215). The history written in the history information 27a in S215 is the history that would have been written in the history information 27a in the offline state, and is to be transmitted to the mobile terminal 30 in the next processing of S134.

[0150] When the process of S215 ends, the CPU 28 executes the process of S211.

[0151] When the CPU 28 determines in S212 that the engine start relay 24 has been turned off, it ends the operation shown in FIG.

[0152] As shown in FIG. 14, after the process of S189, the CPU 28 determines whether or not the panic button information indicates that the panic button 23 is valid (S190).

[0153] When the CPU 28 determines in S190 that the emergency button information does not indicate that the emergency button 23 is valid, i.e., that the emergency button information indicates that the emergency button 23 is invalid, it determines whether the value of the start-enabled time timer is 0 (S191).

[0154] When the CPU 28 determines in S191 that the value of the start-enabled time timer is not 0, it executes the process of S190.

[0155] When the CPU 28 determines in S191 that the value of the start-enabled time timer is 0, it ends the countdown of the start-enabled time timer (S192).

[0156] After the process of S192, the CPU 28 turns the engine start relay 24 to the OFF state (S193), so that the vehicle 90 cannot start the engine.

[0157] After the process of S193, the CPU 28 writes a history indicating the end of the emergency mode to the history information 27a (S194). The history written to the history information 27a in S194 is the history written to the history information 27a in the offline state, and is to be transmitted to the mobile terminal 30 in the next process of S134 (see FIG. 11).

[0158] After the process of S194, the CPU 28 stops outputting the warning sound from the buzzer 26 (S195).

[0159] After the process of S195, the CPU 28 sets the wiper relay 25 to the OFF state (open state) (S196). When the wiper relay 25 is in the OFF state, power is not supplied from the +B power supply to the wiper motor 96 electrically connected to the wiper relay 25 unless the wiper switch 97 is in the ON state. Therefore, the wipers of the vehicle 90 will not move unless the wiper switch 97 is in the ON state.

[0160] When the process of S196 ends, the CPU 28 executes the process of S181.

[0161] When the CPU 28 determines in S190 that the panic button information indicates that the panic button 23 is valid, it ends the countdown of the start-enabled time timer (S197) and executes the process of S181.

[0162] FIG. 16 is a flowchart of the operation of the interlock device 20 when the panic button 23 is activated.

[0163] When the CPU 28 of the interlock device 20 receives an emergency button activation instruction, which is an instruction to activate the emergency button 23, from a dedicated electronic device (not shown) (hereinafter referred to as a "BLE transmitter") that transmits the emergency button activation instruction via BLE, the CPU 28 executes the operation shown in FIG. 16 . The BLE transmitter is managed by a specific department or person, such as a dealer's service department. For example, when a malfunction that occurred in the mobile terminal 30 is resolved, the user of the BLE transmitter may transmit the emergency button activation instruction to the interlock device 20 from the BLE transmitter.

[0164] As shown in Fig. 16, the CPU 28 writes the fact that the panic button 23 is valid into the panic button information (S231). Therefore, it is determined in S183 and S190 (see Fig. 14) that the panic button information indicates that the panic button 23 is valid, and the panic button 23 becomes usable again.

[0165] Next, the CPU 28 determines whether the engine start relay 24 is in the ON state (S232).

[0166] If the CPU 28 determines in S232 that the engine start relay 24 is in the ON state, it executes the processes of S233 to S236 which are the same as the processes of S193 to S196 (see FIG. 14).

[0167] When the CPU 28 determines in S232 that the engine start relay 24 is in the OFF state, or when the process of S236 ends, the operation shown in FIG. 16 ends.

[0168] Next, the operation of the interlock device 20 when issuing a warning sound in response to unauthorized driving of the vehicle 90 will be described.

[0169] A person attempting to steal the vehicle 90 may be able to illegally start the engine of the vehicle 90, for example, by shorting the terminals on both sides of the switch of the engine start relay 24. If a person attempting to steal the vehicle 90 shorts the terminals on both sides of the switch of the engine start relay 24 to illegally start the engine of the vehicle 90 and then drives the vehicle 90, a vehicle speed pulse is generated even when the engine start relay 24 is in the OFF state.

[0170] FIG. 17 is a flowchart of the operation of the interlock device 20 when a warning sound is issued in response to unauthorized driving of the vehicle 90.

[0171] When the interlock device 20 is started, the CPU 28 of the interlock device 20 executes the operation shown in FIG.

[0172] As shown in FIG. 17, the CPU 28 determines whether the engine start relay 24 is in the OFF state (S251) until it determines that the engine start relay 24 is in the OFF state.

[0173] When the CPU 28 determines that the engine start relay 24 is in the OFF state, it determines whether or not a vehicle speed pulse has been generated based on the input to the vehicle speed pulse input section 22b (S252).

[0174] When the CPU 28 determines in S252 that a vehicle speed pulse has been generated, it outputs a warning sound from the buzzer 26 (S253). Therefore, the CPU 28 can notify the driver by the warning sound output from the buzzer 26 that a vehicle speed pulse has been generated when the engine start relay 24 is in the OFF state, that is, that the vehicle 90 may be being driven illegally.

[0175] When the CPU 28 determines in S252 that the vehicle speed pulse is not generated, or when the process of S253 ends, the CPU 28 executes the process of S251.

[0176] FIG. 18 is a diagram showing an example of a portion of the history information 37c according to the present embodiment.

[0177] In the history information 37c shown in FIG. 18, the history for "2022 / 04 / 20 10:12:42" is the history written in S105 and indicates that the license verification failed.

[0178] In the history information 37c shown in FIG. 18, the history for "2022 / 04 / 20 10:15:21" is the history written in S114, which indicates that the license verification was successful and the face authentication was unsuccessful.

[0179] In the history information 37c shown in Figure 18, the history for "April 21, 2022, 10:19:34" is the history written in S146, indicating successful license verification, successful face authentication, and completion of the ON state of the engine start relay 24.

[0180] In the history information 37c shown in Figure 18, the history for "April 21, 2022, 10:22:34" is a history indicating the occurrence of a timeout and the completion of the OFF state of the engine start relay 24, which was written to the history information 37c in S136 based on the history written to the history information 27a in S164.

[0181] In the history information 37c shown in Figure 18, the history for "April 21, 2022, 10:26:56" is the history written in S146, indicating successful license verification, successful face authentication, and completion of the ON state of the engine start relay 24.

[0182] In the history information 37c shown in Figure 18, the history for "April 21, 2022, 10:27:47" is a history indicating the start of the engine of vehicle 90, which was written to history information 37c in S136 based on the history written to history information 27a in S165.

[0183] In the history information 37c shown in Figure 18, the history for "April 21, 2022, 10:52:39" is a history that indicates the stopping of the engine of the vehicle 90 and the completion of the OFF state of the engine start relay 24, which was written to the history information 37c in S136 based on the history written to the history information 27a in S168.

[0184] In the history information 37c shown in Figure 18, the history for "April 22, 2022, 12:34:22" is history indicating the start of emergency mode, which was written to the history information 37c in S136 based on the history written to the history information 27a in S187.

[0185] In the history information 37c shown in Figure 18, the history for "April 22, 2022, 12:36:59" is a history indicating the start of the engine of vehicle 90, which was written to history information 37c in S136 based on the history written to history information 27a in S213.

[0186] In the history information 37c shown in Figure 18, the history for "April 22, 2022, 12:53:05" is a history indicating the engine of vehicle 90 being stopped, which was written to history information 37c in S136 based on the history written to history information 27a in S215.

[0187] In the history information 37c shown in Figure 18, the history for "April 23, 2022, 12:34:22" is history indicating the end of emergency mode, which was written to the history information 37c in S136 based on the history written to the history information 27a in S194 or S234.

[0188] As described above, the vehicle interlock system 10 does not allow the interlock device 20 to start the vehicle engine if facial authentication of the user of the mobile terminal 30 using the mobile terminal 30 fails (S113 to S117), thereby reducing the possibility of the vehicle 90 being driven illegally by an unauthorized driver, such as someone attempting to steal the vehicle 90.

[0189] When facial authentication of the user of the mobile terminal 30 using the mobile terminal 30 fails, the vehicle interlock system 10 transmits information indicating that facial authentication of the user of the mobile terminal 30 has failed to a specific destination (S113), thereby making it possible for a third party, such as the owner of the vehicle 90, to recognize that the vehicle 90 is about to be driven illegally by a person who is not a legitimate driver, and as a result, the possibility of the vehicle 90 being driven illegally by a person who is not a legitimate driver can be reduced.

[0190] (Second embodiment) First, the configuration of a vehicle interlock system according to a second embodiment of the present invention will be described.

[0191] The configuration of the vehicle interlock system according to this embodiment is the same as the configuration of vehicle interlock system 10 according to the first embodiment (see FIG. 1) except for the configuration described below. Therefore, among the components of the vehicle interlock system according to this embodiment, components similar to the components of vehicle interlock system 10 according to the first embodiment are assigned the same reference numerals as the components of vehicle interlock system 10 according to the first embodiment, and detailed description thereof will be omitted.

[0192] FIG. 19 is a block diagram of a mobile terminal 30 according to this embodiment.

[0193] As shown in Figure 19, the control unit 38 of the mobile terminal 30 in this embodiment executes the interlock application 37b to realize an interlock control unit 38e, an information sending unit 38f, a resume writing unit 38g, and a notification execution unit 38h, as well as a cognitive function assessment unit 38i that assesses the cognitive function of the user of the mobile terminal 30.

[0194] Next, the operation of the vehicle interlock system according to this embodiment will be described.

[0195] The operation of the vehicle interlock system according to this embodiment is the same as that of the vehicle interlock system according to the first embodiment, except for the operations described below.

[0196] The operation of the vehicle interlock system according to this embodiment is performed as shown in FIG. 20 instead of the operation shown in FIG.

[0197] FIG. 20 is a sequence diagram of the main processing shown in FIG. 11 in the vehicle interlock system according to this embodiment.

[0198] As shown in Figure 20, when the mobile terminal 30 receives the information transmitted in S133 (see Figure 11), the cognitive function assessment unit 38i of the mobile terminal 30 executes a test of the cognitive function of the user of the mobile terminal 30 (hereinafter referred to as the "cognitive test") (S311).

[0199] Fig. 21(a) is a front view of the mobile terminal 30 when displaying an example of a test execution screen 74, which is an execution screen for a cognitive test. Fig. 21(b) is a front view of the mobile terminal 30 when displaying an example of the test execution screen 74 that is different from the example shown in Fig. 21(a).

[0200] The test execution screen 74 shown in FIG. 21(a) includes a numeric keypad 74a used to input answers to questions in the cognitive test, an equation display area 74b that shows the equation for a calculation problem that is one of the questions in the cognitive test, and an answer display area 74c in which the answer entered using the numeric keypad 74a is displayed.

[0201] The test execution screen 74 shown in FIG. 21(b) includes a numeric keypad 74a used to input answers to questions in the cognitive test, a question display area 74d that displays a question about today's date, which is one of the questions in the cognitive test, and an answer display area 74e that displays the answer entered using the numeric keypad 74a.

[0202] The questions shown in FIGS. 21(a) and 21(b) are merely examples. To prevent the questions in the cognitive test performed in S311 from being the same every time, the cognitive function assessment unit 38i randomly selects multiple questions from a large number of general questions each time the cognitive test is performed and displays the selected multiple questions one by one on the display unit 32 in order. The cognitive function assessment unit 38i may then determine that the cognitive function is normal if the score on the cognitive test is equal to or greater than a specific threshold, and may determine that the cognitive function is abnormal if the score on the cognitive test is below the specific threshold. Even if a person has normal cognitive function, there may be cases where the score on the cognitive test falls below the specific threshold due to some cause, such as a mistake. Therefore, the cognitive function assessment unit 38i may determine that the cognitive function is normal if the score on the cognitive test is equal to or greater than a specific threshold, and may re-administer the cognitive test if the scores on the cognitive test are below the specific threshold for a specific number of consecutive cognitive tests, such as three, and determine that the cognitive function is abnormal if the scores are below the specific threshold.

[0203] Fig. 22(a) is a front view of the mobile terminal 30 when displaying an example of a test result screen 75 for displaying the results of a cognitive test. Fig. 22(b) is a front view of the mobile terminal 30 when displaying an example of the test result screen 75 that is different from the example shown in Fig. 22(a).

[0204] 22(a) is a screen showing that the cognitive function is normal as a result of the cognitive test. When the cognitive function assessment unit 38i determines that the cognitive function is normal based on the cognitive test executed in S311, the cognitive function assessment unit 38i displays the test result screen 75 shown in FIG. 22(a) on the display unit 32.

[0205] 22(b) is a screen indicating that the cognitive function is not normal as a result of the cognitive test. When the cognitive function assessment unit 38i determines that the cognitive function is not normal based on the cognitive test executed in S311, the cognitive function assessment unit 38i displays the test result screen 75 shown in FIG. 22(b) on the display unit 32.

[0206] As shown in FIG. 20, when it is determined in S311 that the cognitive function is not normal, the interlock control unit 38e of the mobile terminal 30 transmits information indicating that the cognitive function is not normal to the interlock device 20 (S321).

[0207] Furthermore, if it is determined in S311 that the cognitive function is not normal, the information transmitting unit 38f of the mobile terminal 30 transmits information indicating that the cognitive function is not normal to a specific destination (S322).

[0208] Furthermore, if it is determined in S311 that the cognitive function is not normal, the history writing unit 38g of the mobile terminal 30 writes a history indicating successful license verification, successful face authentication, that the cognitive function is not normal, and that the engine start relay 24 is in the OFF state into the history information 37c (S323).

[0209] Furthermore, if it is determined in S311 that the cognitive function is not normal, the notification execution unit 38h of the mobile terminal 30 notifies the user of the mobile terminal 30, for example, via at least one of the display unit 32 and the speaker 34, that "You cannot start the engine" (S324).

[0210] When the interlock device 20 receives the information transmitted in S321, the CPU 28 of the interlock device 20 writes a history indicating that the license verification was successful, that the face authentication was successful, that the cognitive function was not normal, and that the engine start relay 24 is in the OFF state into the history information 27a (S325).

[0211] When the third-party terminal 50 receives the information transmitted in S322, the history writing unit 58a of the third-party terminal 50 writes into the history information 57b a history indicating that the license verification was successful, that the face authentication was successful, that the cognitive function is not normal, and that the engine start relay 24 is in the OFF state (S326).

[0212] When the third-party terminal 50 receives the information transmitted in S322, the notification execution unit 58b of the third-party terminal 50 notifies the user, for example, via at least one of the display unit 52 and the speaker 54, that the license verification was successful, that the face authentication was successful, that the cognitive function is not normal, and that the engine start relay 24 is in the OFF state (S327).

[0213] When it is determined in S311 that cognitive function is normal, the vehicle interlock system according to this embodiment executes the processes of S331 to S339, which are similar to the processes of S141 to S149 (see FIG. 12). However, the information written or notified in the processes of S334, S336, S338, and S339 is the information written or notified in the processes of S144, S146, S148, and S149, respectively, with the addition that the cognitive function is normal.

[0214] FIG. 23 is a diagram showing an example of a portion of the history information 37c according to the present embodiment.

[0215] In the history information 37c shown in Figure 23, the history for "April 26, 2022, 10:12:08" is the history written in S323, indicating that license verification was successful, facial authentication was successful, cognitive function was not normal, and the engine start relay 24 was in the OFF state.

[0216] In the history information 37c shown in Figure 23, the history for "April 27, 2022, 10:11:49" is the history written in S336, indicating successful license verification, successful face authentication, normal cognitive function, and completion of the ON state of the engine start relay 24.

[0217] The history information 27a, 37c, and 57b may include actual scores as the results of cognitive tests in the history indicating whether or not cognitive function is normal.

[0218] As described above, the vehicle interlock system according to the present embodiment does not permit interlock device 20 to start the engine of vehicle 90 if the result of determining the cognitive function of the user of mobile terminal 30 is abnormal, even if facial authentication of the user of mobile terminal 30 using mobile terminal 30 is successful (S321 to S327), thereby reducing the possibility of the vehicle 90 being driven illegally by a person with abnormal cognitive function. Therefore, the vehicle interlock system according to the present embodiment can reduce the possibility of traffic violations, such as wrong-way driving or ignoring red lights, by a driver with dementia.

[0219] In the vehicle interlock system of this embodiment, when the result of the assessment of the cognitive function of the user of the mobile terminal 30 is that it is not normal, information indicating that the user's cognitive function is not normal is sent to a specific destination (S322).This makes it possible for a third party, such as the driver's family member, to recognize that the vehicle 90 is about to be driven illegally by a person with abnormal cognitive function, and as a result, the possibility of the vehicle 90 being driven illegally by a person with abnormal cognitive function can be reduced.

[0220] (Third embodiment) First, the configuration of a vehicle interlock system according to a third embodiment of the present invention will be described.

[0221] The configuration of the vehicle interlock system according to this embodiment is the same as that of the vehicle interlock system according to the second embodiment, except for the configuration described below. Therefore, among the components of the vehicle interlock system according to this embodiment, components similar to the components of the vehicle interlock system according to the second embodiment are assigned the same reference numerals as the components of the vehicle interlock system according to the second embodiment, and detailed description thereof will be omitted.

[0222] FIG. 24 is a block diagram of third party terminal 50 according to this embodiment.

[0223] As shown in FIG. 24, the control unit 58 of the third-party terminal 50 according to this embodiment executes an interlock application 57a ​​to thereby realize a history writing unit 58a, a notification execution unit 58b, and an instruction receiving unit 58c that receives an instruction from the user of the third-party terminal 50 as to whether or not to allow the engine of the vehicle 90 to start.

[0224] Next, the operation of the vehicle interlock system according to this embodiment will be described.

[0225] The operation of the vehicle interlock system according to this embodiment is similar to the operation of the vehicle interlock system according to the second embodiment, except for the operations described below.

[0226] The operation of the vehicle interlock system according to this embodiment is performed as shown in FIG. 25 instead of the operation shown in FIG.

[0227] FIG. 25 is a sequence diagram of the main process shown in FIG. 11 in the vehicle interlock system according to this embodiment.

[0228] As shown in FIG. 25, the vehicle interlock system according to this embodiment executes the process of S311 in the same manner as the operation shown in FIG.

[0229] After the process of S311, the information transmitting unit 38f of the mobile terminal 30 transmits information indicating the result of the cognitive test executed in S311 to a specific destination (S341).

[0230] When the third-party terminal 50 receives the information transmitted in S341, the notification execution unit 58b of the third-party terminal 50 notifies the user of the success of the license verification, the success of the face authentication, and the results of the cognitive test transmitted in S341, for example, via at least one of the display unit 52 and the speaker 54 (S342).

[0231] After the processing of S342, the instruction receiving unit 58c of the third party terminal 50 displays an instruction receiving screen on the display unit 52 of the third party terminal 50 to receive an instruction from the user of the third party terminal 50 as to whether or not to permit the engine of the vehicle 90 to start (S343). For example, the user of the third party terminal 50 can decide whether or not to permit the engine of the vehicle 90 to start after talking with the user of the mobile terminal 30 through at least one of a voice call and a video call realized between the third party terminal 50 and the mobile terminal 30. The user of the third party terminal 50 can input an instruction as to whether or not to permit the engine of the vehicle 90 to start into the instruction receiving screen via, for example, the operation unit 51.

[0232] After the processing of S343, when the instruction receiving unit 58c receives an instruction as to whether or not to permit the engine of the vehicle 90 to start via the instruction receiving screen, the instruction receiving unit 58c transmits information indicating the received instruction to the mobile terminal 30 (S344). Note that the information transmitted to the mobile terminal 30 in S344 may be transmitted by the instruction receiving unit 58c as reply data in response to the information transmitted from the mobile terminal 30 in S341.

[0233] If the instruction sent in S344 is an instruction not to allow the engine of the vehicle 90 to start, the interlock control unit 38e of the mobile terminal 30 sends information indicating the result of the cognitive test performed in S311 and the instruction not to allow the engine of the vehicle 90 to start to the interlock device 20 (S351).

[0234] In addition, if the instruction sent in S344 is an instruction not to allow the engine of the vehicle 90 to start, the information sending unit 38f of the mobile terminal 30 sends information indicating the result of the cognitive test performed in S311 and the instruction not to allow the engine of the vehicle 90 to start to a specific destination (S352).

[0235] In addition, if the instruction sent in S344 is an instruction not to allow the engine of the vehicle 90 to start, the history writing unit 38g of the mobile terminal 30 writes into the history information 37c a history indicating the success of the license verification, the success of the face authentication, the result of the cognitive test performed in S311, the receipt of the instruction not to allow the engine of the vehicle 90 to start, and the fact that the engine start relay 24 is in the OFF state (S353).

[0236] In addition, if the instruction sent in S344 is an instruction not to allow the engine of the vehicle 90 to be started, the notification execution unit 38h of the mobile terminal 30 notifies the user of the mobile terminal 30, for example, via at least one of the display unit 32 and the speaker 34, that "You cannot start the engine" (S354).

[0237] When the interlock device 20 receives the information transmitted in S351, the CPU 28 of the interlock device 20 writes into the history information 27a a history indicating that the license verification was successful, the face authentication was successful, the results of the recognition test transmitted in S351, that an instruction not to allow the engine of the vehicle 90 to be started has been received, and that the engine start relay 24 is in the OFF state (S355).

[0238] When the third-party terminal 50 receives the information transmitted in S352, the history writing unit 58a of the third-party terminal 50 writes into the history information 57b a history indicating the success of the license verification, the success of the face authentication, the results of the recognition test transmitted in S352, the receipt of an instruction not to permit the start of the engine of the vehicle 90, and the fact that the engine start relay 24 is in the OFF state (S356).

[0239] If the instruction sent in S344 is an instruction to permit the engine of the vehicle 90 to be started, the interlock control unit 38e of the mobile terminal 30 sends information indicating the result of the cognitive test performed in S311 and the instruction to permit the engine of the vehicle 90 to be started to the interlock device 20 (S361).

[0240] After the process of S361, the vehicle interlock system according to this embodiment executes the processes of S362 to S369 which are similar to the processes of S332 to S339 (see FIG. 20).

[0241] However, in processing S364, the CPU 28 of the interlock device 20 writes into the history information 27a a history indicating the success of the license verification, the success of the face authentication, the results of the recognition test sent in S361, the receipt of an instruction to allow the engine of the vehicle 90 to start, and the completion of the ON state of the engine start relay 24.

[0242] Also, in the processing of S365, the information transmission unit 38f of the mobile terminal 30 transmits information indicating that the engine start relay 24 has been turned on, the results of the cognitive test performed in S311, and that an instruction to allow the engine of the vehicle 90 to be started has been received.

[0243] Also, in the processing of S366, the history writing unit 38g of the mobile terminal 30 writes a history indicating the success of the license verification, the success of the face authentication, the results of the recognition test performed in S311, the receipt of an instruction to allow the engine of the vehicle 90 to start, and the completion of the ON state of the engine start relay 24.

[0244] Also, in the processing of S368, the history writing unit 58a of the third-party terminal 50 writes a history indicating the success of the license verification, the success of the face authentication, the results of the recognition test sent in S365, the receipt of an instruction to allow the engine of the vehicle 90 to start, and the completion of the ON state of the engine start relay 24.

[0245] Also, in the processing of S369, the notification execution unit 58b of the third-party terminal 50 notifies the driver's license verification success, the face authentication success, the results of the recognition test sent in S365, the receipt of an instruction to allow the engine of the vehicle 90 to start, and the completion of the ON state of the engine start relay 24.

[0246] FIG. 26 is a diagram showing an example of a portion of the history information 37c according to the present embodiment.

[0247] In the history information 37c shown in Figure 26, the history for "April 24, 2022, 10:05:42" is a history written in S353 indicating that license verification was successful, facial authentication was successful, cognitive function was not normal, an instruction not to allow the engine of vehicle 90 to start was received, and the engine start relay 24 is in the OFF state.

[0248] In the history information 37c shown in Figure 26, the history for "April 24, 2022, 10:11:12" is the history written in S366, indicating successful license verification, successful face authentication, abnormal cognitive function, receipt of an instruction to allow the engine of the vehicle 90 to start, and completion of the ON state of the engine start relay 24.

[0249] In the history information 37c shown in Figure 26, the history for "April 25, 2022, 10:21:35" is a history written in S353 that indicates that license verification was successful, facial authentication was successful, cognitive function was normal, an instruction not to allow the engine of vehicle 90 to start was received, and the engine start relay 24 is in the OFF state.

[0250] In the history information 37c shown in Figure 26, the history for "April 25, 2022, 10:37:02" is the history written in S366, indicating successful license verification, successful facial authentication, normal cognitive function, receipt of an instruction to allow the engine of vehicle 90 to start, and completion of the ON state of engine start relay 24.

[0251] The history information 27a, 37c, and 57b may include actual scores as the results of cognitive tests in the history indicating whether or not cognitive function is normal.

[0252] In the operation shown in FIG. 25 , the vehicle interlock system according to the present embodiment receives an instruction from the user of the third-party terminal 50 as to whether or not to permit the start of the engine of the vehicle 90, regardless of whether the cognitive function is normal, and executes an operation according to the instruction received from the user of the third-party terminal 50 (S341 to S369). However, the vehicle interlock system according to the present embodiment may receive an instruction from the user of the third-party terminal 50 as to whether or not to permit the start of the engine of the vehicle 90 only when the cognitive function is normal, and execute an operation according to the instruction received from the user of the third-party terminal 50. That is, the vehicle interlock system according to the present embodiment does not always permit the start of the engine of the vehicle 90 by executing processing similar to the processing of S321 to S327 (see FIG. 20 ) in the second embodiment when the cognitive function is abnormal. Furthermore, the vehicle interlock system according to the present embodiment may receive an instruction from the user of the third-party terminal 50 as to whether or not to permit the start of the engine of the vehicle 90, and execute an operation according to the instruction received from the user of the third-party terminal 50 only when the cognitive function is abnormal. In other words, the vehicle interlock system of this embodiment may always allow the engine of the vehicle 90 to start by performing processing similar to the processing of S331 to S339 (see Figure 20) in the second embodiment when cognitive function is normal.

[0253] As described above, in the vehicle interlock system of this embodiment, after the mobile terminal 30 sends the results of the assessment of the user's cognitive function to a specific destination (S341), the mobile terminal 30 receives an instruction on whether or not to allow the engine of the vehicle 90 to start (S344), and the mobile terminal 30 controls the interlock device 20 in accordance with the instruction received (S351 and S361).Therefore, the interlock device 20 can be made to allow or not allow the engine of the vehicle 90 to start in accordance with instructions from a third party who recognizes the results of the assessment of the user's cognitive function, and as a result, the possibility of the vehicle 90 being driven illegally by a person with abnormal cognitive function can be reduced.

[0254] For example, in the vehicle interlock system of this embodiment, even if the result of the assessment of the cognitive function of the user of the mobile terminal 30 is that the cognitive function is normal, if a third party, such as the user's family member, knows that the user has dementia, the third party can send an instruction from the third-party terminal 50 to the mobile terminal 30 not to allow the engine of the vehicle 90 to start, thereby reducing the possibility of the user driving the vehicle 90 illegally.

[0255] Furthermore, in the vehicle interlock system of this embodiment, even if the result of the assessment of the cognitive function of the user of the mobile terminal 30 is that the cognitive function is not normal, if a third party, such as a family member of the user of the mobile terminal 30, knows that there is actually no problem with the cognitive function of the user of the mobile terminal 30, the third party can send an instruction to allow the engine of the vehicle 90 to be started from the third-party terminal 50 to the mobile terminal 30, thereby improving convenience.

[0256] (Fourth embodiment) First, the configuration of a vehicle interlock system according to a fourth embodiment of the present invention will be described.

[0257] The configuration of the vehicle interlock system according to this embodiment is the same as the configuration of vehicle interlock system 10 according to the first embodiment (see FIG. 1) except for the configuration described below. Therefore, among the components of the vehicle interlock system according to this embodiment, components similar to the components of vehicle interlock system 10 according to the first embodiment are assigned the same reference numerals as the components of vehicle interlock system 10 according to the first embodiment, and detailed description thereof will be omitted.

[0258] FIG. 27 is a block diagram of a vehicle interlock system 400 according to this embodiment.

[0259] As shown in Figure 27, the configuration of the vehicle interlock system 400 is similar to the configuration of the vehicle interlock system 10 (see Figure 1) of the first embodiment, in which an alcohol measurement device 40 is provided for measuring the alcohol concentration in the breath of the driver of the vehicle 90 (hereinafter referred to as "alcohol measurement").

[0260] The mobile terminal 30 and the alcohol measurement device 40 can communicate using BLE, with the mobile terminal 30 acting as the master and the alcohol measurement device 40 acting as the slave. The mobile terminal 30 and the alcohol measurement device 40 are preferably paired before the operation shown in FIG. 30 described below. BLE communication between the mobile terminal 30 and the alcohol measurement device 40 is encrypted to prevent third parties from analyzing the communication content. The encryption method for communication between the mobile terminal 30 and the alcohol measurement device 40 may be a known method such as a symmetric key encryption method, a public key encryption method, or a hybrid encryption method.

[0261] FIG. 28 is a block diagram of a mobile terminal 30 according to this embodiment.

[0262] As shown in FIG. 28, the control unit 38 of the mobile terminal 30 according to this embodiment executes the interlock application 37b to realize an interlock control unit 38e, an information transmission unit 38f, a history writing unit 38g, and a notification execution unit 38h, as well as an alcohol concentration determination unit 38j that determines whether the alcohol concentration in the user's breath is normal (hereinafter referred to as "alcohol concentration determination").

[0263] FIG. 29 is a block diagram of the breath alcohol measurement device 40.

[0264] 27 and 29, the alcohol measurement device 40 includes a housing 41a, a mouthpiece 41b that is detachable from the housing 41a and is held by the subject when the subject blows breath into it, a switch 42 for starting measurement of the alcohol concentration in the breath, a display unit 43 which is a display device such as an LCD for displaying information such as the alcohol concentration, a breath pressure sensor 44 which detects the breath pressure as the strength of the breath blown into the mouthpiece 41b, a suction pump 45 which sucks the breath blown into the mouthpiece 41b, an alcohol sensor 46 which detects the alcohol concentration in the breath sucked by the suction pump 45, a communication unit 47 which is a communication device that communicates with an external device via a network such as a LAN or the Internet, or directly via a wired or wireless connection without using a network, a memory unit 48 which is a non-volatile memory device such as a semiconductor memory for storing various information, and a control unit 49 which controls the entire alcohol measurement device 40.

[0265] The control unit 49 includes, for example, a CPU, a ROM that stores programs and various data, and a RAM as memory used as a work area for the CPU of the control unit 49. The CPU of the control unit 49 executes the programs stored in the storage unit 48 or the ROM of the control unit 49.

[0266] The driver of the vehicle 90 may press the emergency button 23 if a malfunction occurs in the alcohol measurement device 40 and the operation shown in Fig. 30 described below cannot be performed normally. Furthermore, the user of the BLE transmitter may send an emergency button activation instruction from the BLE transmitter to the interlock device 20 when the malfunction that occurred in the alcohol measurement device 40 is resolved.

[0267] Next, the operation of vehicle interlock system 400 will be described.

[0268] The operation of vehicle interlock system 400 is similar to that of the vehicle interlock system according to the second embodiment, except for the operations described below.

[0269] The operation of vehicle interlock system 400 is performed as shown in FIG. 30 instead of the operation shown in FIG.

[0270] FIG. 30 is a sequence diagram of the main processing shown in FIG. 11 in vehicle interlock system 400.

[0271] 30, when the switch 42 is pressed, the control unit 49 of the breath alcohol measurement device 40 periodically transmits a BLE advertisement when the breath alcohol measurement device 40 is not connected to the mobile terminal 30, i.e., is in an offline state. Note that the transmitted advertisement is not encrypted.

[0272] When the control unit 38 of the mobile terminal 30 starts the interlock application 37b, the alcohol concentration determination unit 38j of the mobile terminal 30 requests a connection via BLE to the interlock device 20 (S411). Note that the communication in S411 is not encrypted.

[0273] When the control unit 49 of the alcohol measurement device 40 receives a request in S411 from the mobile terminal 30 with which it has already been paired, it completes the BLE connection with the mobile terminal 30 (S412) and transmits information to the mobile terminal 30 indicating the completion of the BLE connection with the mobile terminal 30 (S413).

[0274] After the process of S413, when the flow rate of the breath blown into the mouthpiece 41b reaches a specific flow rate after determining that the breath pressure detected by the breath pressure sensor 44 is equal to or higher than a specific breath pressure, the control unit 49 transmits to the portable terminal 30 a shutter command, which is a command to cause the portable terminal 30 to acquire an image during measurement as an image of the subject whose alcohol concentration is being measured by the alcohol measurement device 40 (S414). Here, the control unit 49 calculates the flow rate based on the breath pressure detected by the breath pressure sensor 44.

[0275] When the portable terminal 30 receives the shutter command transmitted in S414, the alcohol concentration determination unit 38j of the portable terminal 30 captures an image during measurement using the camera 35 (S415). The alcohol concentration determination unit 38j stores the image during measurement captured in S415 in association with the alcohol concentration received from the alcohol measurement device 40 in S417 (to be described later) as evidence that the alcohol measurement was not fraudulent.

[0276] After the process of S414, the control unit 49 of the alcohol measurement device 40 measures the alcohol concentration (S416). That is, the control unit 49 causes the suction pump 45 to suck the breath blown into the mouthpiece 41b, and calculates the alcohol concentration based on the signal output by the alcohol sensor 46 for the sucked breath.

[0277] After the process of S416, the control unit 49 transmits the alcohol concentration measured in S416 to the mobile terminal 30 (S417).

[0278] When the mobile terminal 30 receives the alcohol concentration transmitted in S417, the alcohol concentration determination unit 38j of the mobile terminal 30 disconnects the BLE connection with the alcohol measurement device 40 (S418). The communication in S418 is not encrypted. The reason why the BLE connection between the mobile terminal 30 and the alcohol measurement device 40 is not constantly maintained is, for example, to reduce battery consumption of the mobile terminal 30.

[0279] When the portable terminal 30 receives the alcohol concentration transmitted in S417, the alcohol concentration determination unit 38j of the portable terminal 30 executes an alcohol concentration determination (S419). Here, if the alcohol concentration transmitted in S417 is less than a specific threshold, the alcohol concentration determination unit 38j determines that the alcohol concentration is normal, and if the alcohol concentration transmitted in S417 is equal to or greater than the specific threshold, the alcohol concentration determination unit 38j determines that the alcohol concentration is not normal.

[0280] When it is determined in S419 that the alcohol concentration is not normal, the vehicle interlock system according to this embodiment executes the same processes of S421 to S427 as those of S321 to S327 (see FIG. 20). However, the information transmitted in S421 and S422 differs from the information transmitted in S321 and S322 in that it indicates that the alcohol concentration is not normal. Furthermore, the information written or notified in S423, S425, S426, and S427 includes information indicating that the alcohol concentration is not normal, instead of information indicating that the cognitive function is not normal, as in the information written or notified in S323, S325, S326, and S327.

[0281] When it is determined in S419 that the alcohol concentration is normal, the vehicle interlock system according to this embodiment executes the same processes of S431 to S439 as those of S331 to S339 (see FIG. 20). However, the information written or notified in the processes of S434, S436, S438, and S439 includes information that indicates that the alcohol concentration is normal, instead of information that indicates that the cognitive function is normal.

[0282] FIG. 31 is a diagram showing an example of a portion of the history information 37c according to the present embodiment.

[0283] In the history information 37c shown in Figure 31, the history for "April 26, 2022, 10:12:08" is the history written in S423, indicating that license verification was successful, facial authentication was successful, the alcohol concentration was not normal, and the engine start relay 24 was in the OFF state.

[0284] In the history information 37c shown in Figure 31, the history for "April 27, 2022, 10:11:49" is the history written in S436, indicating that license verification was successful, facial authentication was successful, the alcohol concentration was normal, and the engine start relay 24 was turned on.

[0285] The history information 27a, 37c, and 57b may include the actual alcohol concentration, which is the result of the alcohol measurement, in the history indicating whether the alcohol concentration is normal or not.

[0286] As described above, even if face authentication of the user of mobile terminal 30 using mobile terminal 30 is successful, if the determination result of the breath alcohol concentration of the user of mobile terminal 30 is abnormal, vehicle interlock system 400 does not allow interlock device 20 to start the engine of vehicle 90 (S421 to S427), thereby reducing the possibility that vehicle 90 will be illegally driven by someone whose breath alcohol concentration is abnormal. Therefore, vehicle interlock system 400 can reduce the possibility of drunk driving occurring.

[0287] When the result of the determination of the alcohol concentration in the breath of the user of the mobile terminal 30 is that it is not normal, the vehicle interlock system 400 sends information indicating that the alcohol concentration in the user's breath is not normal to a specific destination (S422).This makes it possible for a third party, such as a person in charge at the headquarters of the driver's business or the driver's family, to become aware that the vehicle 90 is about to be illegally driven by a person whose breath alcohol concentration is not normal, thereby reducing the possibility that the vehicle 90 will be illegally driven by a person whose breath alcohol concentration is not normal.

[0288] (Fifth embodiment) First, the configuration of a vehicle interlock system according to the fifth embodiment of the present invention will be described.

[0289] The configuration of the vehicle interlock system according to this embodiment is the same as the configuration of vehicle interlock system 400 according to the fourth embodiment (see FIG. 27), except for the configuration described below. Therefore, among the components of the vehicle interlock system according to this embodiment, components similar to the components of vehicle interlock system 400 according to the fourth embodiment are assigned the same reference numerals as the components of vehicle interlock system 400 according to the fourth embodiment, and detailed description thereof will be omitted.

[0290] As shown in FIG. 24, the control unit 58 of the third-party terminal 50 in this embodiment executes an interlock application 57a ​​to realize a history writing unit 58a, a notification execution unit 58b, and an instruction receiving unit 58c that receives an instruction from the user of the third-party terminal 50 as to whether or not to allow the engine of the vehicle 90 to start.

[0291] Next, the operation of the vehicle interlock system according to this embodiment will be described.

[0292] The operation of the vehicle interlock system according to this embodiment is similar to the operation of the vehicle interlock system according to the third embodiment, except for the operations described below.

[0293] The operation of the vehicle interlock system according to this embodiment is the operation shown in FIG. 32, instead of the operation shown in FIG.

[0294] FIG. 32 is a sequence diagram of the main process shown in FIG. 11 in the vehicle interlock system according to this embodiment.

[0295] As shown in FIG. 32, the vehicle interlock system according to this embodiment executes the processes of S411 to S419 in the same manner as the operation shown in FIG.

[0296] After processing S419, the vehicle interlock system according to this embodiment executes processing of S441 to S444, which are similar to the processing of S341 to S344 (see FIG. 25). However, the information transmitted in processing S441 differs from the information transmitted in processing S341 in that it is information indicating the result of the alcohol concentration determination performed in S419. Furthermore, the information notified in processing S442 is information that includes the result of the alcohol concentration determination instead of the result of the cognitive test in the information notified in processing S342.

[0297] The vehicle interlock system according to the present embodiment executes the same processes of S451 to S456 (see FIG. 25) as those of S351 to S356 when the instruction transmitted in S444 is an instruction not to permit starting of the engine of vehicle 90. However, the information transmitted, written, or notified in the processes of S451, S452, S453, S455, and S456 includes the result of the alcohol concentration determination performed in S419 instead of the result of the cognitive test.

[0298] The vehicle interlock system according to the present embodiment executes the same processes of S461 to S469 (see FIG. 25) as the processes of S361 to S369 when the instruction transmitted in S444 is an instruction to permit starting of the engine of vehicle 90. However, the information transmitted, written, or notified in the processes of S461, S464, S465, S466, S468, and S469 includes the result of the alcohol concentration determination performed in S419 instead of the result of the cognitive test.

[0299] FIG. 33 is a diagram showing an example of a portion of the history information 37c according to the present embodiment.

[0300] In the history information 37c shown in Figure 33, the history for "April 24, 2022, 10:05:42" is the history written in S453, indicating that license verification was successful, facial authentication was successful, the alcohol concentration was not normal, an instruction not to allow the engine of vehicle 90 to start was received, and the engine start relay 24 is in the OFF state.

[0301] In the history information 37c shown in Figure 33, the history for "April 24, 2022, 10:11:12" is the history written in S466, indicating successful license verification, successful face authentication, the fact that the alcohol concentration is not normal, the receipt of an instruction to allow the engine of the vehicle 90 to start, and the completion of the ON state of the engine start relay 24.

[0302] In the history information 37c shown in Figure 33, the history for "April 25, 2022, 10:21:35" is the history written in S453, indicating that license verification was successful, facial authentication was successful, the alcohol concentration was normal, an instruction not to allow the engine of vehicle 90 to start was received, and the engine start relay 24 is in the OFF state.

[0303] In the history information 37c shown in Figure 33, the history for "April 25, 2022, 10:37:02" is the history written in S466, indicating that license verification was successful, facial authentication was successful, the alcohol concentration was normal, an instruction to allow the engine of vehicle 90 to start was received, and the engine start relay 24 was turned on.

[0304] The history information 27a, 37c, and 57b may include the actual alcohol concentration, which is the result of the alcohol measurement, in the history indicating whether the alcohol concentration is normal or not.

[0305] In the operation shown in FIG. 32 , the vehicle interlock system according to the present embodiment receives an instruction from the user of the third-party terminal 50 as to whether or not to permit the engine of the vehicle 90 to start, regardless of whether the alcohol concentration is normal, and executes an operation according to the instruction received from the user of the third-party terminal 50 (S441 to S469). However, the vehicle interlock system according to the present embodiment may receive an instruction from the user of the third-party terminal 50 as to whether or not to permit the engine of the vehicle 90 to start only when the alcohol concentration is normal, and execute an operation according to the instruction received from the user of the third-party terminal 50. That is, the vehicle interlock system according to the present embodiment does not always permit the engine of the vehicle 90 to start by executing processing similar to the processing of S421 to S427 (see FIG. 30 ) in the fourth embodiment when the alcohol concentration is not normal. Furthermore, the vehicle interlock system according to the present embodiment may receive an instruction from the user of the third-party terminal 50 as to whether or not to permit the engine of the vehicle 90 to start, and execute an operation according to the instruction received from the user of the third-party terminal 50 only when the alcohol concentration is not normal. In other words, the vehicle interlock system of this embodiment may always allow the engine of the vehicle 90 to start by performing processing similar to that of S431 to S439 (see Figure 30) in the fourth embodiment when the alcohol concentration is normal.

[0306] As described above, in the vehicle interlock system of this embodiment, after the mobile terminal 30 sends the result of the determination of the alcohol concentration in the user's breath to a specific destination (S451), the mobile terminal 30 receives an instruction on whether or not to allow the engine of the vehicle 90 to start (S444), and the mobile terminal 30 controls the interlock device 20 in accordance with the instruction received (S451 and S461).Therefore, the interlock device 20 can be made to allow or not allow the engine of the vehicle 90 to start in accordance with instructions from a third party who recognizes the result of the determination of the alcohol concentration in the user's breath, and as a result, the possibility of the vehicle 90 being driven illegally by a person whose breath alcohol concentration is not normal can be reduced.

[0307] For example, in the vehicle interlock system according to the present embodiment, even if the determination result of the breath alcohol concentration of the user of the mobile terminal 30 indicates that the breath alcohol concentration is normal, if a third party, such as a family member of the user, knows that the user is an alcoholic and suspects the possibility of the user fraudulently measuring the alcohol concentration, the third party can send an instruction from the third-party terminal 50 to the mobile terminal 30 not to permit the start of the engine of the vehicle 90, thereby reducing the possibility of the user fraudulently driving the vehicle 90. For example, the user of the third-party terminal 50 can talk to the user of the mobile terminal 30 through at least one of a voice call and a video call realized between the third-party terminal 50 and the mobile terminal 30, and then determine whether the user of the mobile terminal 30 is intoxicated based on the user's speech and decide whether to permit the start of the engine of the vehicle 90. Furthermore, the user of the third party terminal 50 can talk with the user of the mobile terminal 30 through a video call realized between the third party terminal 50 and the mobile terminal 30, and then determine whether or not the user of the mobile terminal 30 is intoxicated based on the facial expression of the user of the mobile terminal 30, and decide whether or not to permit the start of the engine of the vehicle 90. Furthermore, the user of the third party terminal 50 can talk with the user of the mobile terminal 30 through at least one of a voice call and a video call realized between the third party terminal 50 and the mobile terminal 30, and then determine whether or not a person pretending to be the user of the mobile terminal 30 has measured the alcohol concentration in the breath, and decide whether or not to permit the start of the engine of the vehicle 90.

[0308] Furthermore, in the vehicle interlock system of this embodiment, even if the result of the determination of the alcohol concentration in the breath of the user of the mobile terminal 30 is that the alcohol concentration in the breath is not normal, for example, when the result that the alcohol concentration in the breath is not normal is due to a malfunction of the alcohol measurement device 40, a third party who is contacted by the user of the mobile terminal 30 can send an instruction to the mobile terminal 30 from the third-party terminal 50 to allow the engine of the vehicle 90 to start, thereby improving convenience.

[0309] (Sixth embodiment) First, the configuration of a vehicle interlock system according to the sixth embodiment of the present invention will be described.

[0310] The configuration of the vehicle interlock system according to this embodiment is the same as the configuration of vehicle interlock system 400 according to the fourth embodiment (see FIG. 27), except for the configuration described below. Therefore, among the components of the vehicle interlock system according to this embodiment, components similar to the components of vehicle interlock system 400 according to the fourth embodiment are assigned the same reference numerals as the components of vehicle interlock system 400 according to the fourth embodiment, and detailed description thereof will be omitted.

[0311] FIG. 34 is a block diagram of a mobile terminal 30 according to this embodiment.

[0312] As shown in FIG. 34, the control unit 38 of the mobile terminal 30 according to this embodiment executes the interlock application 37b to thereby realize an interlock control unit 38e, an information transmission unit 38f, a history writing unit 38g, a notification execution unit 38h, an alcohol concentration determination unit 38j, and a cognitive function determination unit 38i that determines the cognitive function of the user of the mobile terminal 30.

[0313] Next, the operation of the vehicle interlock system according to this embodiment will be described.

[0314] The operation of the vehicle interlock system according to this embodiment is the same as the operation of the vehicle interlock system according to the fourth embodiment, except for the operations described below.

[0315] The operation of the vehicle interlock system according to this embodiment is the operation shown in FIG. 35, instead of the operation shown in FIG.

[0316] FIG. 35 is a sequence diagram of the main process shown in FIG. 11 in the vehicle interlock system according to this embodiment.

[0317] As shown in FIG. 35, the vehicle interlock system according to this embodiment executes the processes of S511 to S527 which are similar to the processes of S311 to S327 (see FIG. 20).

[0318] When it is determined in S511 that cognitive function is normal, the vehicle interlock system according to this embodiment executes the processes of S531 to S559, which are similar to the processes of S411 to S439 (see FIG. 30). However, the information written or notified in the processes of S543, S545, S546, S547, S554, S556, S558, and S559 is the information written or notified in the processes of S423, S425, S426, S427, S434, S436, S438, and S439, respectively, with the addition that the cognitive function is normal.

[0319] FIG. 36 is a diagram showing an example of a portion of the history information 37c according to the present embodiment.

[0320] In the history information 37c shown in Figure 36, the history for "April 26, 2022, 10:12:08" is the history written in S543, indicating that license verification was successful, facial recognition was successful, cognitive function was normal, alcohol concentration was not normal, and the engine start relay 24 was in the OFF state.

[0321] In the history information 37c shown in Figure 36, the history for "April 27, 2022, 10:11:49" is the history written in S556, indicating that license verification was successful, facial authentication was successful, cognitive function was normal, alcohol concentration was normal, and the engine start relay 24 was turned on.

[0322] Note that the history information 27a, 37c, and 57b may include actual scores, which are the results of cognitive tests, in the history indicating whether cognitive function is normal. Similarly, the history information 27a, 37c, and 57b may include actual alcohol concentrations, which are the results of alcohol measurements, in the history indicating whether alcohol concentrations are normal.

[0323] (Seventh embodiment) First, the configuration of a vehicle interlock system according to the seventh embodiment of the present invention will be described.

[0324] The configuration of the vehicle interlock system according to this embodiment is the same as that of the vehicle interlock system according to the sixth embodiment, except for the configuration described below. Therefore, among the components of the vehicle interlock system according to this embodiment, components similar to the components of the vehicle interlock system according to the sixth embodiment are assigned the same reference numerals as the components of the vehicle interlock system according to the sixth embodiment, and detailed description thereof will be omitted.

[0325] As shown in FIG. 24, the control unit 58 of the third-party terminal 50 in this embodiment executes an interlock application 57a ​​to realize a history writing unit 58a, a notification execution unit 58b, and an instruction receiving unit 58c that receives an instruction from the user of the third-party terminal 50 as to whether or not to allow the engine of the vehicle 90 to start.

[0326] Next, the operation of the vehicle interlock system according to this embodiment will be described.

[0327] The operation of the vehicle interlock system according to this embodiment is the same as that of the vehicle interlock system according to the sixth embodiment, except for the operations described below.

[0328] The operation of the vehicle interlock system according to this embodiment is the operation shown in FIG. 37, instead of the operation shown in FIG.

[0329] FIG. 37 is a sequence diagram of the main process shown in FIG. 11 in the vehicle interlock system according to this embodiment.

[0330] As shown in FIG. 37, the vehicle interlock system according to this embodiment executes the processes of S511 to S539 in the same manner as the operation shown in FIG.

[0331] After processing S539, the vehicle interlock system according to this embodiment executes processing S561 to S589, which are similar to the processing S441 to S469 (see FIG. 32). However, the information notified or written in the processing of S562, S573, S575, S576, S584, S586, S588, and S589 is the information notified or written in the processing of S442, S453, S455, S456, S464, S466, S468, and S469, respectively, with the addition that the cognitive function is normal.

[0332] FIG. 38 is a diagram showing an example of a portion of the history information 37c according to the present embodiment.

[0333] In the history information 37c shown in Figure 38, the history for "April 24, 2022, 10:05:42" is the history written in S573, indicating that license verification was successful, facial recognition was successful, cognitive function was normal, alcohol concentration was not normal, an instruction not to allow the engine of vehicle 90 to start was received, and engine start relay 24 was in the OFF state.

[0334] In the history information 37c shown in Figure 38, the history for "April 24, 2022, 10:11:12" is the history written in S586, indicating that license verification was successful, facial authentication was successful, cognitive function was normal, alcohol concentration was not normal, an instruction to allow the engine of vehicle 90 to start was received, and the engine start relay 24 was turned on.

[0335] In the history information 37c shown in Figure 38, the history for "April 25, 2022, 10:21:35" is a history written in S573 that indicates that license verification was successful, facial authentication was successful, cognitive function was normal, alcohol concentration was normal, an instruction not to allow the engine of vehicle 90 to start was received, and the engine start relay 24 is in the OFF state.

[0336] In the history information 37c shown in Figure 38, the history for "April 25, 2022, 10:37:02" is the history written in S586, indicating successful license verification, successful facial authentication, normal cognitive function, normal alcohol concentration, receipt of an instruction to allow the engine of vehicle 90 to start, and completion of the ON state of engine start relay 24.

[0337] Note that the history information 27a, 37c, and 57b may include actual scores, which are the results of cognitive tests, in the history indicating whether cognitive function is normal. Similarly, the history information 27a, 37c, and 57b may include actual alcohol concentrations, which are the results of alcohol measurements, in the history indicating whether alcohol concentrations are normal.

[0338] In the operation shown in FIG. 37 , the vehicle interlock system according to the present embodiment receives an instruction from the user of the third-party terminal 50 as to whether or not to permit the engine of the vehicle 90 to start, regardless of whether the alcohol concentration is normal, and executes an operation according to the instruction received from the user of the third-party terminal 50 (S561 to S589). However, the vehicle interlock system according to the present embodiment may receive an instruction from the user of the third-party terminal 50 as to whether or not to permit the engine of the vehicle 90 to start only when the alcohol concentration is normal, and execute an operation according to the instruction received from the user of the third-party terminal 50. That is, the vehicle interlock system according to the present embodiment does not always permit the engine of the vehicle 90 to start by executing processing similar to the processing of S541 to S547 (see FIG. 35 ) in the sixth embodiment when the alcohol concentration is abnormal. Furthermore, the vehicle interlock system according to the present embodiment may receive an instruction from the user of the third-party terminal 50 as to whether or not to permit the engine of the vehicle 90 to start, and execute an operation according to the instruction received from the user of the third-party terminal 50 only when the alcohol concentration is abnormal. In other words, the vehicle interlock system of this embodiment may always allow the engine of the vehicle 90 to start when the alcohol concentration is normal by performing processing similar to the processing of S551 to S559 (see Figure 35) in the sixth embodiment.

[0339] In each of the above embodiments, the personal authentication unit 38a of the portable terminal 30 requests the authentication server 60 to perform facial authentication of the user of the portable terminal 30 using the portable terminal 30. However, in addition to or instead of performing facial authentication of the user of the portable terminal 30 using the portable terminal 30, the personal authentication unit 38a may request the authentication server 60 to perform biometric authentication other than facial authentication of the user of the portable terminal 30 using the portable terminal 30. Here, examples of biometric authentication other than facial authentication include fingerprint authentication and voiceprint authentication. Furthermore, in addition to or instead of performing biometric authentication of the user of the portable terminal 30 using the portable terminal 30, the personal authentication unit 38a may request the authentication server 60 to perform authentication of the portable terminal 30 using the portable terminal 30. Here, authentication of mobile terminal 30 using mobile terminal 30 may be determined to be successful, for example, if the IP (Internet Protocol) address of mobile terminal 30 matches the IP address registered in authentication server 60, or if the telephone number in the SIM (Subscriber Identity Module) card of mobile terminal 30 matches the telephone number registered in authentication server 60.

[0340] In each of the above embodiments, the interlock device 20 prevents the engine, which serves as the power source of the vehicle 90, from starting. However, the interlock device 20 can also be applied to vehicles whose power source is not an engine. For example, the interlock device 20 may prevent the motor, which serves as the power source of an electric vehicle, from starting.

[0341] In each of the above embodiments, the interlock device 20 and the mobile terminal 30 can communicate with each other using BLE. However, the interlock device 20 and the mobile terminal 30 may communicate with each other using wireless communication other than BLE, such as Wi-Fi, or may communicate with each other using wired communication. When the interlock device 20 and the mobile terminal 30 communicate with each other using wired communication, the communication between the interlock device 20 and the mobile terminal 30 does not need to be encrypted.

[0342] Similarly, in the fourth to seventh embodiments, the mobile terminal 30 and the alcohol measurement device 40 can communicate with each other via BLE. However, the mobile terminal 30 and the alcohol measurement device 40 may also communicate with each other via wireless communication other than BLE, such as Wi-Fi, or via wired communication. When the mobile terminal 30 and the alcohol measurement device 40 communicate with each other via wired communication, the communication between the mobile terminal 30 and the alcohol measurement device 40 does not need to be encrypted. [Explanation of symbols]

[0343] 10 Vehicle Interlock System 20 Interlocking Device 30 Mobile Devices 37a Personal authentication app (interlock program) 37b Interlock app (interlock program) 38b Information transmission unit 38e Interlock control section 38f Information Transmission Unit 400 Vehicle Interlock System

Claims

1. an interlock device that prevents the start of the vehicle's power source; a mobile terminal including an interlock control unit that controls the interlock device; Equipped with the interlock control unit does not permit the interlock device to start the power source when a specific authentication using the mobile terminal fails, the specific authentication is at least one of biometric authentication of the user of the mobile terminal and authentication of the mobile terminal; The vehicle interlock system is characterized in that the mobile terminal is equipped with an information sending unit that, if the specific authentication using the mobile terminal fails, sends information indicating that the specific authentication has failed to a specific destination.

2. An interlock device that prevents the start of a vehicle's power source; a mobile terminal including an interlock control unit that controls the interlock device; Equipped with the interlock control unit does not permit the interlock device to start the power source when a specific authentication using the mobile terminal fails, the specific authentication is at least one of biometric authentication of the user of the mobile terminal and authentication of the mobile terminal; the interlock control unit does not permit the interlock device to start the power source when the specific authentication using the mobile terminal is successful and the result of the determination of the cognitive function of the user is abnormal, The vehicle interlock system is characterized in that the mobile terminal is equipped with an information sending unit that, if the result is that the cognitive function is not normal, sends information indicating that the cognitive function is not normal to a specific destination.

3. An interlock device that prevents the start of a vehicle's power source; a mobile terminal including an interlock control unit that controls the interlock device; Equipped with the interlock control unit does not permit the interlock device to start the power source when a specific authentication using the mobile terminal fails, the specific authentication is at least one of biometric authentication of the user of the mobile terminal and authentication of the mobile terminal; the mobile terminal includes an information transmission unit that transmits the result of the assessment of the user's cognitive function to a specific destination; The vehicle interlock system is characterized in that, when the specific authentication using the mobile terminal is successful, the interlock control unit receives an instruction from outside the mobile terminal as to whether or not to allow the power source to start after the information sending unit sends the result to the specific destination, and controls the interlock device in accordance with the received instruction.

4. An interlock device that prevents the start of a vehicle's power source; a mobile terminal including an interlock control unit that controls the interlock device; Equipped with the interlock control unit does not permit the interlock device to start the power source when a specific authentication using the mobile terminal fails, the specific authentication is at least one of biometric authentication of the user of the mobile terminal and authentication of the mobile terminal; the mobile terminal includes an information transmitting unit that transmits the result of the determination of the alcohol concentration in the breath of the user to a specific destination; The vehicle interlock system is characterized in that, when the specific authentication using the mobile terminal is successful, the interlock control unit receives an instruction from outside the mobile terminal as to whether or not to allow the power source to start after the information sending unit sends the result to the specific destination, and controls the interlock device in accordance with the received instruction.

5. A mobile terminal equipped with an interlock control unit that controls an interlock device that prevents the start of a vehicle's power source, the interlock control unit does not permit the interlock device to start the power source when a specific authentication using the mobile terminal fails, the specific authentication is at least one of biometric authentication of the user of the mobile terminal and authentication of the mobile terminal; The mobile terminal is characterized in that it has an information sending unit that sends information indicating that the specific authentication has failed to a specific destination if the specific authentication using the mobile terminal fails.

6. A mobile terminal equipped with an interlock control unit that controls an interlock device that prevents the start of a vehicle's power source, the interlock control unit does not permit the interlock device to start the power source when a specific authentication using the mobile terminal fails, the specific authentication is at least one of biometric authentication of the user of the mobile terminal and authentication of the mobile terminal; the interlock control unit does not permit the interlock device to start the power source when the specific authentication using the mobile terminal is successful and the result of the determination of the cognitive function of the user is abnormal, The mobile terminal is characterized in that it has an information sending unit that, if the result is that the cognitive function is not normal, sends information indicating that the cognitive function is not normal to a specific destination.

7. A mobile terminal equipped with an interlock control unit that controls an interlock device that prevents the start of a vehicle's power source, the interlock control unit does not permit the interlock device to start the power source when a specific authentication using the mobile terminal fails, the specific authentication is at least one of biometric authentication of the user of the mobile terminal and authentication of the mobile terminal; the mobile terminal includes an information transmission unit that transmits the result of the assessment of the user's cognitive function to a specific destination; The interlock control unit is characterized in that, when the specific authentication using the mobile terminal is successful, after the information sending unit sends the result to the specific destination, it receives an instruction from outside the mobile terminal as to whether or not to allow the power source to start, and controls the interlock device in accordance with the received instruction.

8. A mobile terminal equipped with an interlock control unit that controls an interlock device that prevents the start of a vehicle's power source, the interlock control unit does not permit the interlock device to start the power source when a specific authentication using the mobile terminal fails, the specific authentication is at least one of biometric authentication of the user of the mobile terminal and authentication of the mobile terminal; the mobile terminal includes an information transmitting unit that transmits the result of the determination of the alcohol concentration in the breath of the user to a specific destination; The interlock control unit is characterized in that, when the specific authentication using the mobile terminal is successful, after the information sending unit sends the result to the specific destination, it receives an instruction from outside the mobile terminal as to whether or not to allow the power source to start, and controls the interlock device in accordance with the received instruction.

9. An interlock control unit that controls an interlock device that prevents the start of a vehicle's power source is implemented in a mobile terminal, the interlock control unit does not permit the interlock device to start the power source when a specific authentication using the mobile terminal fails, the specific authentication is at least one of biometric authentication of the user of the mobile terminal and authentication of the mobile terminal; The mobile terminal is characterized in that it has an information sending unit that sends information indicating that the specific authentication has failed to a specific destination if the specific authentication using the mobile terminal fails.

10. An interlock control unit that controls an interlock device that prevents the start of the vehicle's power source is implemented in a mobile terminal, the interlock control unit does not permit the interlock device to start the power source when a specific authentication using the mobile terminal fails, the specific authentication is at least one of biometric authentication of the user of the mobile terminal and authentication of the mobile terminal; the interlock control unit does not permit the interlock device to start the power source when the specific authentication using the mobile terminal is successful and the result of the determination of the cognitive function of the user is abnormal, The mobile terminal is characterized by having an information sending unit that, if the result is that the cognitive function is not normal, sends information indicating that the cognitive function is not normal to a specific destination.

11. An interlock control unit that controls an interlock device that prevents the start of a vehicle's power source is implemented in a mobile terminal, the interlock control unit does not permit the interlock device to start the power source when a specific authentication using the mobile terminal fails, the specific authentication is at least one of biometric authentication of the user of the mobile terminal and authentication of the mobile terminal; the mobile terminal includes an information transmission unit that transmits the result of the assessment of the user's cognitive function to a specific destination; The interlock control unit receives an instruction from outside the mobile terminal as to whether or not to allow the power source to start after the information sending unit sends the result to the specific destination when the specific authentication using the mobile terminal is successful, and controls the interlock device in accordance with the received instruction.

12. An interlock control unit that controls an interlock device that prevents the start of a vehicle's power source is implemented in a mobile terminal, the interlock control unit does not permit the interlock device to start the power source when a specific authentication using the mobile terminal fails, the specific authentication is at least one of biometric authentication of the user of the mobile terminal and authentication of the mobile terminal; the mobile terminal includes an information transmitting unit that transmits the result of the determination of the alcohol concentration in the breath of the user to a specific destination; The interlock control unit receives an instruction from outside the mobile terminal as to whether or not to allow the power source to start after the information sending unit sends the result to the specific destination when the specific authentication using the mobile terminal is successful, and controls the interlock device in accordance with the received instruction.

Citation Information

Patent Citations

  • Electronic key control system for vehicle

    JP2008297721A

  • Drunken driving prevention system

    JP2009029373A

  • Vehicular wireless key device

    JP2021025313A

  • Vehicle control system, vehicle control method and program

    JP2022076066A

  • JPP4512170B