Automotive and Automotive Programs
The vehicle system addresses user intention ambiguity by determining access based on door opening and drive unit usage, ensuring smooth and secure access for intended users through re-boarding plans.
Patent Information
- Application Number
- JP2024096340
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-06-14
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2036-02-04
AI Technical Summary
Existing vehicle access systems for multiple users are unclear about user intentions, leading to confusion and potential denial of service for intended users when multiple family members or employees attempt to use a shared vehicle.
A vehicle system that determines whether to allow access based on whether the door has been opened or the drive unit started using a key, and includes a re-boarding information storage and determination mechanism to ensure smooth coordination among users.
Enables smooth coordination among users by allowing intended users to access the vehicle, reducing confusion and ensuring secure access based on stored re-boarding plans.
Smart Images

Figure 0007774907000001 
Figure 0007774907000002 
Figure 0007774907000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to automobiles and automobile programs. [Background technology]
[0002] Conventionally, in order to prevent vehicle theft, devices and methods have been proposed in which authentication reference information, such as biometric information of a person who plans to use a vehicle, is registered and stored in advance, and the stored authentication reference information is compared with the authentication information of the user who is about to use the vehicle, and authentication is performed based on whether the two match, and the opening and closing of the vehicle doors and the starting of the vehicle are controlled based on the authentication results (see, for example, Patent Documents 1 and 2 below).
[0003] In this case, when it is expected that the car will be used by multiple family members or multiple employees of a company, authentication reference information such as biometric information of all persons who plan to use the car is registered in advance so that all of the multiple registered users can share the car. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2010-208554 [Patent Document 2] Japanese Patent Application Laid-Open No. 2011-025903 Summary of the Invention [Problem to be solved by the invention]
[0005] As mentioned above, when multiple potential users are allowed to use the car, it is unclear whether the other potential users also wish to use the car, and users may be confused as to whether they should start using the car.
[0006] Also, even if you are planning to use the service, there may be cases where another person who has registered to use the service gets there first and you are unable to use the service.
[0007] In view of the above problems, the present invention has an object to provide a car that allows smooth coordination with the next person who wishes to use (ride) the car. [Means for solving the problem]
[0008] In order to solve the above problem, the invention of claim 1 is as follows: By those who wish to board Whether the key was used to open the door of the vehicle or whether the door of the vehicle can be opened; or By those who wish to board a start possibility determination means for determining whether or not use of the vehicle can be started based on whether or not the drive unit of the vehicle has been started using the key or whether or not it is possible to start the drive unit of the vehicle; A person who has exited their vehicle gets back on their vehicle A re-boarding information storage means for storing information on re-boarding plans in a first storage unit; a first determination means for determining whether or not the information on the re-boarding plan is stored in the first storage unit when the start possibility determination means determines that the use of the vehicle can be started; When the first determination means determines that the information on the re-boarding plan is not stored, The aforementioned A means for permitting a person who wishes to board to use the vehicle; The present invention provides a vehicle characterized by comprising:
[0009] The automobile of the invention of claim 1 having the above-mentioned configuration includes a start possibility determination means for determining whether or not use of the vehicle can be started based on whether or not the door of the vehicle has been opened using a key, or whether or not the door of the vehicle can be opened, or whether or not the drive unit of the vehicle has been started using a key, or whether or not the drive unit of the vehicle can be started.The first determination means determines whether or not information on a re-entry plan is stored in the first memory unit when the start possibility determination means determines that use of the vehicle can be started.
[0010] The use permission means then permits the person attempting to board to use the vehicle when the first determination means determines that information on a planned re-boarding has not been stored. This makes it possible to provide a car that can be smoothly adjusted when the next person attempting to board has the key to the vehicle. [Effects of the Invention]
[0011] According to the vehicle of the present invention, adjustments can be made smoothly when the next person to board has the vehicle key. [Brief explanation of the drawings]
[0012] [Figure 1] 1 is a diagram for explaining a communication system including an embodiment of a vehicle according to the present invention; [Figure 2] 1 is a block diagram showing an example of the hardware configuration of an example of an autonomously driven vehicle that is an embodiment of the automobile according to the present invention. FIG. [Figure 3] FIG. 3 is a diagram showing a part of a flowchart for explaining an example of a processing operation when a user gets off the automatically driven vehicle in the example of FIG. 2. [Figure 4] FIG. 3 is a diagram showing a part of a flowchart for explaining an example of a processing operation when a user gets off the automatically driven vehicle in the example of FIG. 2. [Figure 5] FIG. 3 is a diagram illustrating an example of an input screen for re-boarding plans in the self-driving vehicle in the example of FIG. 2. [Figure 6] FIG. 3 is a diagram for explaining an example of a post-vehicle disembarkation behavior list for the self-driving vehicle in the example of FIG. 2. [Figure 7] 3 is a diagram showing a part of a flowchart for explaining an example of a processing operation in response to a call from a user in the self-driving vehicle in the example of FIG. 2. FIG. [Figure 8] 3 is a diagram showing a part of a flowchart for explaining an example of a processing operation in response to a call from a user in the self-driving vehicle in the example of FIG. 2. FIG. [Figure 9]3 is a diagram showing a part of a flowchart for explaining an example of a processing operation in response to a call from a user in the self-driving vehicle in the example of FIG. 2. FIG. [Figure 10] 3 is a flowchart illustrating an example of a control operation for moving the self-driving vehicle in the example of FIG. 2 in response to a call from a user. FIG. [Figure 11] FIG. 3 is a diagram showing a part of a flowchart for explaining an example of processing operations when a user gets into the self-driving vehicle in the example of FIG. 2. [Figure 12] FIG. 3 is a diagram showing a part of a flowchart for explaining an example of processing operations when a user gets into the self-driving vehicle in the example of FIG. 2. [Figure 13] FIG. 3 is a diagram showing a part of a flowchart for explaining an example of processing operations when a user gets into the self-driving vehicle in the example of FIG. 2. [Figure 14] FIG. 10 is a diagram for explaining an example of a re-boarding schedule in an embodiment of the vehicle according to the present invention. [Figure 15] FIG. 10 is a diagram for explaining an example of a re-boarding schedule in an embodiment of the vehicle according to the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0013] The embodiment described below is an example in which the automobile is a so-called private automobile and is configured as an autonomous vehicle. This embodiment enables the autonomous vehicle 1, which is an embodiment of the automobile of the present invention, to be used in the manner shown in Figure 1.
[0014] First, this usage pattern will be explained, along with an overview of the operation of the autonomous vehicle 1 of the embodiment. The autonomous vehicle 1 of the embodiment described below is assumed to be shared by multiple users, for example, among family members, relatives, or friends. The sharing users are registered in advance with the autonomous vehicle 1 as prospective users. The autonomous vehicle 1 stores information about the registered prospective users in a memory unit, correlating it with identification information such as a registrant number. In this case, the information about the prospective users may include biometric information such as facial images, voice, fingerprints, veins, and irises, as well as name, address, date of birth, ID, password, telephone number, or email address.
[0015] In this embodiment, the self-driving vehicle 1 also uses the stored information of the prospective user registrant, either alone or in combination, as authentication reference information for the prospective user registrant, as described below. That is, the authentication reference information for the prospective user registrant may include, either alone or in combination, biometric information such as a facial image, voice, fingerprint, vein pattern, or iris, as well as name, address, date of birth, ID, password, telephone number, or email address.
[0016] The facial image of the prospective user registrant can be taken by a camera equipped in the self-driving car 1, and other biometric information of the prospective user registrant can be stored in advance in the memory of the self-driving car 1. In addition, other information entered by the prospective user registrant can be used. Furthermore, biometric information including the facial image and other information stored on the cloud can be used via the communication network 3 described below. Furthermore, the facial image of the prospective user registrant can be taken by a camera equipped in the mobile phone terminal that the prospective user registrant owns, and other biometric information and other information of the prospective user registrant can be stored in advance in the memory of the mobile phone terminal.
[0017] In the example of FIG. 1, user 2A, who is, for example, a family member, who is stored in autonomous vehicle 1 as a registered planned user, uses (for example, drives) autonomous vehicle 1 to return to home 4, gets off autonomous vehicle 1, and enters home 4. In this case, while riding in autonomous vehicle 1 or when getting off autonomous vehicle 1, user 2A inputs information about plans to re-board autonomous vehicle 1 after getting off to autonomous vehicle 1 as necessary, and sets the post-dismount behavior that autonomous vehicle 1 should have after getting off.
[0018] As for information about the re-boarding plan, user 2A may input a plan to prohibit others from boarding and ensure a re-boarding for himself, or input a plan to allow the other registered planned user to use the vehicle if he / she allows it if he / she plans to re-board, as will be described later, or input a plan to not re-board (end of use), etc. Furthermore, user 2A may instruct, as his / her behavior after getting off, to move to a parking lot 5 that is a little distance from his / her home 4, for example.
[0019] The autonomous vehicle 1 accepts the input information about the re-boarding plan, and stores the information about the re-boarding plan in a storage unit in association with identification information (which will become authentication reference information as described later) of the person who input the information (hereinafter referred to as the plan inputter; user 2A in FIG. 1) and connection information for wireless communication with the plan inputter. The autonomous vehicle 1 validates this stored information about the re-boarding plan after confirming that the plan inputter has disembarked.
[0020] In this case, if the person who input the schedule is a planned user registrant like user 2A, the identification information of the person who input the schedule and the connection information for wireless communication with the person who input the schedule are extracted from the stored information of the planned user registrant and used. The connection information for wireless communication with the person who input the schedule is, for example, the telephone number of the mobile phone terminal owned by the person who input the schedule and an email address. Furthermore, if the person who input the schedule is not a planned user registrant stored in the self-driving vehicle 1, the self-driving vehicle 1 takes a facial image of the person who input the schedule and obtains, for example, a name and password from the person who input the schedule to use as identification information, and also obtains connection information such as a mobile phone number and email address, and stores it in association with the input schedule information.
[0021] In other words, the authentication reference information for the person entering the information about their planned re-boarding can be biometric information such as facial image, voice, fingerprint, vein, iris, name, address, date of birth, ID, password, telephone number, or email address, either alone or in combination.
[0022] In this embodiment, the self-driving vehicle 1 has the function of moving by autonomous driving without a driver. In accordance with the instructions for post-disembarkation behavior set by the user 2A, the self-driving vehicle 1 moves to the parking lot 5 in the example of Fig. 1 by autonomous driving without a driver.
[0023] In this embodiment, autonomous vehicle 1 has the ability to communicate via communication network 3, which includes a mobile phone network and the Internet. When autonomous vehicle 1 receives a call via the mobile phone network of communication network 3, it authenticates the user who made the call (caller in FIG. 1) 2B, and when authentication is successful, it moves to a location instructed by calling user 2B.
[0024] In this embodiment, the user of the mobile phone terminal that will make a call to the self-driving car 1 has installed an application program for calling the self-driving car 1 in advance. When the user performs a call operation on the mobile phone terminal using the call application program, a call is automatically made to the wireless communication unit of the self-driving car 1, and in this embodiment, a call request is sent to the self-driving car 1 that includes information about the current location of the mobile phone terminal as location information for the location where the self-driving car 1 will be called and wait. Once the caller has been authenticated, the self-driving car 1 moves toward the location indicated by this location information.
[0025] In this case, to authenticate the caller, the self-driving vehicle 1 of this embodiment first performs a first caller authentication to determine whether the caller is a prospective user registered in the self-driving vehicle 1, using the stored information of the prospective user as authentication reference information, and in this embodiment, if the caller is not a prospective user, the call is rejected.
[0026] Then, if the result of the first caller authentication determines that the caller is a registered prospective user, the self-driving vehicle 1 determines whether valid re-boarding plan information is stored, and if the plan information is not stored, it accepts the call from the registered prospective user and moves to the location indicated by the location information included in the call request.
[0027] Furthermore, if the result of the first caller authentication is that the caller is determined to be a registered user, and it is determined that valid re-boarding plan information is stored, a second caller authentication is performed on the caller using authentication reference information on the person who input the re-boarding plan information (plan inputter) stored in the memory unit of the autonomous vehicle 1.
[0028] Then, when the second caller authentication determines that the caller is the schedule inputter, the self-driving vehicle 1 accepts the call from the caller, the schedule inputter, and moves to the location indicated by the location information included in the call request.
[0029] Furthermore, if the second caller authentication determines that the caller is not the schedule inputter, the autonomous vehicle 1 references the stored schedule information to determine the availability of persons other than the schedule inputter. If the schedule information denies the availability of persons other than the schedule inputter, the autonomous vehicle 1 rejects the call from the caller.
[0030] Furthermore, if the second caller authentication determines that the caller is not the schedule inputter, and the schedule information indicates that there is a possibility of use by a user other than the schedule inputter with the schedule inputter's permission, the self-driving vehicle 1 inquires of the schedule inputter, as the permission authenticator, whether or not to allow calls to other scheduled users, and performs authentication of the caller (third caller authentication) based on the response to the inquiry.
[0031] That is, in the third caller authentication, the autonomously driven vehicle 1 uses the connection information of the planner who input the plan to establish a communication path with the planner who input the plan and queries the planner about whether or not to permit a call to another planned user registrant. In response to this query, the planner who input the plan to permit a call to the other planned user registrant, responds with "call permission," or "call denial," if the call to the other planned user registrant is to be denied. In this case, in this embodiment, information about the other planned user registrant is not sent to the re-boarding planner. However, information that can identify the other planned user registrant, such as biometric information such as a facial image or the name of the other planned user registrant, may be sent to the re-boarding planner as reference information for determining whether or not to permit a call.
[0032] In this third caller authentication, the self-driving vehicle 1 receives a response to an inquiry from the plan inputter via a communication channel, and determines whether to call the caller based on the received response. That is, when the self-driving vehicle 1 receives a response from the plan inputter that the call is permitted, the self-driving vehicle 1 responds to calls from other planned use registrants. On the other hand, when the self-driving vehicle 1 receives a response from the plan inputter that the call is not permitted, the self-driving vehicle 1 refuses calls from other planned use registrants. Then, if the self-driving vehicle 1 can authenticate the caller through the third caller authentication and responds to the caller's request, it moves by autonomous driving to the designated waiting location.
[0033] Note that calls made by a caller while autonomous vehicle 1 is in use, such as while driving, may be rejected without authenticating the caller. In this case, autonomous vehicle 1 may notify the caller with a voice or text message such as "Currently in use and cannot respond to calls."
[0034] The authentication information used in the first and second caller authentication methods described above may be the caller's facial image, voice, biometric information such as fingerprints, veins, or irises, or their name, address, date of birth, ID, password, telephone number, or email address, either singly or in combination. The caller sends this authentication information to autonomous vehicle 1 from their mobile phone terminal via the mobile phone network.
[0035] The caller's facial image can be captured by a camera installed in the mobile phone terminal, and the caller's voice can be captured by a microphone installed in the mobile phone terminal. Furthermore, other biometric information of the caller can be stored in advance in the memory of the mobile phone terminal. Other information can also be entered by the caller into the mobile phone terminal. Furthermore, biometric information including facial images and other information can be stored on the cloud and used via communication network 3.
[0036] In the first caller authentication and the second caller authentication, the authentication reference information to be compared with the authentication information obtained from the caller can be the information of the planned user registrant stored in the storage unit of the autonomously driven vehicle 1. In the example described below, the authentication information and authentication reference information of the caller for the first caller authentication and the second caller authentication is, for example, the telephone number of the caller's mobile phone terminal. When input of information on a re-boarding plan is accepted, the telephone number of the mobile phone terminal of the plan inputter, who is the authentication allower for the second caller authentication, is stored in association with the plan information.
[0037] Next, in this embodiment, when a user who wishes to start using the autonomous vehicle 1 for the first time gets into the designated waiting location by a call, the user is authenticated (passenger authentication), and only users who have been authenticated are allowed to use the autonomous vehicle 1, i.e., to drive the autonomous vehicle 1. Note that the waiting location does not only include cases where the autonomous vehicle has moved once and then moved back in response to a call from a caller, as in the example of Figure 1, but also cases where the vehicle was stopped or parked at that location without moving when the user last got off.
[0038] In this case, to authenticate the user when boarding, the self-driving vehicle 1 of this embodiment first performs a first user authentication to determine whether the user attempting to board is a registered prospective user registered in the self-driving vehicle 1, using the stored information of the registered prospective user as authentication reference information, and if the user is not a registered prospective user, in this embodiment, the self-driving vehicle 1 will be denied and prohibited from using its own vehicle (the self-driving vehicle 1 itself).
[0039] Then, when the result of the first passenger authentication determines that the user attempting to board is a registered scheduled user, the self-driving vehicle 1 determines whether valid scheduled re-boarding information is stored, and if no scheduled information is stored, it allows the registered scheduled user to use the vehicle.
[0040] Furthermore, if the result of the first passenger authentication determines that the user attempting to board is a registered user, and it is determined that valid re-boarding plan information is stored, a second passenger authentication is performed on the user attempting to board using authentication reference information for the person who planned to input the re-boarding plan information stored in the memory unit of the autonomous vehicle 1.
[0041] Then, when the second boarding user authentication determines that the user attempting to board is the person who input the schedule, the automatically driven vehicle 1 allows the person who input the schedule to use the vehicle.
[0042] Furthermore, if the second user authentication determines that the user attempting to board is not the person who input the schedule, the self-driving vehicle 1 refers to the stored schedule information to determine whether or not the vehicle can be used by anyone other than the person who input the schedule. If the schedule information denies the ability of anyone other than the person who input the schedule to use the vehicle, the self-driving vehicle 1 denies and prohibits the user attempting to board from using the vehicle.
[0043] Furthermore, if the second passenger authentication determines that the user attempting to board is not the person who input the schedule, and the schedule information indicates that there is a possibility that the vehicle may be used by a user other than the person who input the schedule with the permission of the person who input the schedule, the self-driving vehicle 1 inquires of the person who input the schedule as the permission authenticator as to whether or not to permit use by other registered users of scheduled use, and performs third passenger authentication for the user attempting to board based on the response to the inquiry.
[0044] That is, in the third passenger authentication, the autonomously driven vehicle 1 uses the connection information of the planner who input the plan to establish a communication path with the planner who input the plan, and queries the planner who input the plan to ask whether to permit other planned users to use the vehicle. In response to this query, the planner who input the plan to permit use by the other planned users, replies that use is permitted, and replies that use is not permitted if use by the other planned users is denied. In this case, in this embodiment, information about the other planned users is not sent to the re-boarding planner, but information that can identify the other planned users, such as biometric information such as facial images or names of the other planned users, may be sent to the re-boarding planner as reference information for determining whether to permit use.
[0045] In this third passenger authentication, the self-driving vehicle 1 receives a response to an inquiry from the plan inputter via a communication channel, and determines whether the user attempting to board the vehicle is permitted to use the vehicle based on the received response. In other words, when the self-driving vehicle 1 receives a response from the plan inputter indicating permission for use, the self-driving vehicle 1 permits other planned users to use the vehicle. On the other hand, when the self-driving vehicle 1 receives a response from the plan inputter indicating denial of use, the self-driving vehicle 1 denies (prohibits) other planned users from using the vehicle.
[0046] In this embodiment, examples of the authentication information and authentication reference information used for the first and second passenger authentication include the user's biometric information such as a facial image, voice, fingerprint, vein, and iris. In the example described below, a facial image of the prospective user is stored in the storage unit as authentication reference information for the first passenger authentication. Also, a facial image of the prospective user is stored in the storage unit as authentication reference information for the second passenger authentication.
[0047] An overview of the main operations of the autonomously driven vehicle 1 of this embodiment will be described with reference to Figure 1. It is assumed that both users 2A and 2B are registered with the autonomously driven vehicle 1 as prospective users.
[0048] 1, suppose that user 2A, who has entered information about a re-boarding plan into autonomous vehicle 1 and then gotten off, calls autonomous vehicle 1 from his or her mobile phone terminal at home 4. In response to this, autonomous vehicle 1 in this embodiment authenticates user 2A as a planned user registrant in the first caller authentication, and then authenticates user 2A as a plan inputter in the second caller authentication because the phone number of user 2A matches the phone number of the mobile phone terminal stored in association with the re-boarding plan information. In response to this call from user 2A, autonomous vehicle 1 heads from parking lot 5 to home 4 of user 2A.
[0049] Then, when the self-driving car 1 arrives at home 4, user 2A attempts to board the self-driving car 1. At this time, the self-driving car 1 photographs and acquires a facial image of user 2A who is about to board, and in a first boarding user authentication, authenticates user 2A as a registered planned user based on the acquired facial image and user 2A stored as registered planned user information. Furthermore, in a second boarding user authentication, the self-driving car 1 authenticates user 2A as a person who has planned to re-board based on the acquired facial image of user 2A and the facial image of user 2A stored in association with information on plans to re-board. Therefore, the self-driving car 1 determines that the first boarding user authentication and the second boarding user authentication have been completed, and permits user 2A to use the self-driving car.
[0050] Next, in the example of Figure 1, we will explain the case where a user 2B, other than user 2A who entered information about his or her planned re-boarding of self-driving vehicle 1 and then got off, calls self-driving vehicle 1 from his or her mobile phone terminal at home 4 and attempts to board and use self-driving vehicle 1.
[0051] In this case, the self-driving car 1 can authenticate user 2B as a prospective user in the first caller authentication, but in the second caller authentication, the phone number of user 2B does not match the phone number of the mobile phone terminal of user 2A, who is the prospective user, and therefore determines that authentication is not possible.
[0052] Therefore, the autonomous vehicle 1 refers to the stored schedule information to determine whether or not the vehicle can be used by a person other than the person who input the schedule. If the schedule information indicates that the vehicle can be used by a person other than the person who input the schedule with the permission of the person who input the schedule, the autonomous vehicle 1 queries the user 2A who input the schedule as the permission authenticator as to whether or not to permit the vehicle to call other registered users who have registered their planned use, and performs third caller authentication (re-boarding planned) based on the response to the query.
[0053] When user 2A, as the authorization authenticator, responds with call permission, self-driving vehicle 1 accepts user 2B's call and heads to the waiting location specified by user 2B, which in the example of Figure 1 is user 2B's family member, so heads to user 2A's home 4.
[0054] Then, when self-driving car 1 arrives at home 4, user 2B attempts to board self-driving car 1. In the first passenger authentication, self-driving car 1 authenticates that user 2A is a registered prospective user, but in the second passenger authentication, the facial image of user 2A stored together with the information on the planned re-boarding does not match the photographed facial image of user 2B who has boarded the vehicle, and so it determines that authentication has not been possible in the second passenger authentication.
[0055] At this time, the self-driving vehicle 1, in the same way as when authenticating the caller, refers to the stored schedule information to determine whether or not a person other than the person who inputted the schedule can use the service, and if it determines that there is availability, performs a third passenger authentication.
[0056] In other words, when the schedule information indicates that there is a possibility of use by a user other than the schedule inputter with the permission of the schedule inputter, the self-driving vehicle 1 inquires of the user 2A, who is the schedule inputter as the permission authenticator, as to whether or not to permit use by other scheduled users, and performs third passenger user authentication based on the response to the inquiry.
[0057] In this third passenger user authentication, the autonomous vehicle 1 uses the connection information of user 2A, who is the schedule inputter, to establish a communication path with user 2A, and inquires of user 2A, who is the schedule inputter, whether or not to permit use by other scheduled users. If user 2A replies to this inquiry that they are permitted to board, the autonomous vehicle 1 receives the reply, determines that third passenger user authentication has been completed for user 2B, and permits user 2B to use the vehicle. On the other hand, if user 2A replies that they are not permitted to board the vehicle, the autonomous vehicle 1 receives the reply, determines that third passenger user authentication has not been completed for user 2B, and denies (prohibits) user 2B from using the vehicle.
[0058] As described above, with the self-driving vehicle 1 of the embodiment, a user who is currently riding in the vehicle can input and store information about their planned re-boarding into the self-driving vehicle 1, and based on that plan information, the vehicle can prioritize their own re-boarding or, in some cases, allow other users to ride. This allows for smooth coordination with the next user who is planning to use (board) the vehicle, and also improves security.
[0059] [Hardware configuration example for autonomous vehicle 1] An example of the hardware configuration of the autonomously driven vehicle 1 that realizes the above processing will be described below.
[0060] 2 is a block diagram showing an example of the hardware configuration of the electronic control circuit unit 10 of the autonomously driven vehicle 1 of this embodiment. Note that the autonomously driven vehicle 1 of this embodiment is an example of an electric vehicle. However, the battery is not shown in FIG. 2.
[0061] Furthermore, the self-driving vehicle 1 of this embodiment has an autonomous driving mode and a manual driving mode. The manual driving mode is a mode in which the vehicle can travel in accordance with the driver's accelerator pedal operation, brake pedal operation, shift lever operation, and steering (handle operation), just like a normal vehicle that is not a self-driving vehicle. Furthermore, the autonomous driving mode is a driving mode in which the self-driving vehicle 1 itself automatically (autonomously) changes course while avoiding obstacles, without the driver having to operate the accelerator pedal, brake pedal, shift lever, or steering.
[0062] The driver of the autonomous vehicle 1 can switch the autonomous vehicle 1, which is traveling in manual driving mode, to autonomous driving mode by performing a specific operation, for example, via the touch panel 112 described below.The autonomous vehicle 1 is also configured to automatically return to manual driving mode if the driver operates the accelerator pedal, brake pedal, shift lever, or steering wheel while traveling in autonomous driving mode.
[0063] As shown in Figure 2, the electronic control circuit unit 10 is configured to have a control unit 101 equipped with a computer, and via a system bus 100, the electronic control circuit unit 10 is connected to a wireless communication unit 102, a motor drive control unit 103, a steering drive control unit 104, a manual / automatic driving mode switching control unit 105, a radar group 106, a camera group 107, a sensor group 108, a surrounding moving object recognition unit 109, a current position detection unit 110, a display unit 111, a touch panel 112, a car navigation (hereinafter abbreviated as car navigation) function unit 113, a planned user registration information reception unit 114, a planned user registration information memory unit 115, a caller authentication unit 116, a boarding user authentication unit 117, a re-boarding plan information reception unit 118, a planned input information memory unit 119, a post-dismounting behavior processing unit 120, a post-dismounting behavior memory unit 121, and a voice input / output unit 122.
[0064] A motor drive unit 131 is connected to the motor drive control unit 103. A steering drive unit 132 is connected to the steering drive control unit 104. A manual driving operation detection unit 133 is connected to the manual / automatic driving mode switching control unit 105. A car navigation database 134 is connected to the car navigation function unit 113. A microphone 135 and a speaker 136 are connected to the audio input / output unit 122.
[0065] In this embodiment, the wireless communication unit 102 has a function of performing communications such as telephone communications and e-mail communications via a mobile phone network. The control unit 101 has, as software processing functions, a function of performing processing when a call request is received from a caller via the wireless communication unit 102, and a processing function of generating a communication path with an authorized authenticator (scheduled inputter) to perform third caller authentication and third passenger authentication.
[0066] Under the control of the control unit 101, the motor drive control unit 103 controls the supply of drive signals to the motor drive unit 131 of the self-driving vehicle 1, which is an electric vehicle of this embodiment, to control the start of driving of the self-driving vehicle 1, driving speed control (including brake control and accelerator control), driving stop, etc.
[0067] Under the control of the control unit 101, the steering drive control unit 104 controls the supply of a drive control signal to the steering drive unit 132 of the autonomous vehicle 1 of this embodiment, thereby controlling the course change of the autonomous vehicle 1.
[0068] The manual / automatic driving mode switching control unit 105 switches the driving mode of the autonomous vehicle 1 between a manual driving mode and an automatic driving mode in response to a selection operation input via the touch panel 112. The manual driving operation detection unit 133 receives operation information of the accelerator pedal operation, brake pedal operation, shift lever operation, and steering operation by the driver, and supplies the manual driving operation information to the manual / automatic driving mode switching control unit 105.
[0069] When the autonomous vehicle 1 is in manual driving mode, the manual / autonomous driving mode switching control unit 105 supplies manual driving operation information from the manual driving operation detection unit 133 to the motor driving control unit 103 and the steering driving control unit 104, and controls the motor driving unit 131 and the steering driving unit 132 in accordance with the driver's pedal operation, shift lever operation, and steering operation (handle operation).
[0070] Furthermore, when autonomous vehicle 1 is in autonomous driving mode, manual / autonomous driving mode switching control unit 105 supplies autonomous driving operation information generated by control unit 101 based on outputs from radar group 106, camera group 107, sensor group 108, and surrounding moving object recognition unit 109 to motor drive control unit 103 and steering drive control unit 104, as will be described later, and controls driving of motor drive unit 131 and steering drive unit 132 using the autonomous driving operation information. Note that in autonomous driving mode, car navigation function unit 113 searches for a route from the current position to a destination set by the driver or the like, and controls the vehicle to travel along the searched route.
[0071] The radar group 106 is used to measure the distance to people and objects around the autonomous vehicle 1, and is made up of laser radar, millimeter-wave radar, and the like. The laser radar is embedded, for example, in the ceiling or near the bumper, and the millimeter-wave radar is installed, for example, at the front and rear of the vehicle. Both laser radar and millimeter-wave radar may be provided, or only one of them may be provided. Other radars, such as microwave radar, may also be used. Furthermore, sonar (not shown) may be used for the same purpose as radar.
[0072] Camera group 107 includes one or more cameras that capture images of the interior of autonomous vehicle 1, and one or more cameras that capture images of the surroundings outside the vehicle, such as the front, sides, and rear of autonomous vehicle 1. The cameras that capture images of the interior of the vehicle include cameras that are attached, for example, to the rearview mirror (rearview mirror, room mirror) installed between the driver's seat and the passenger seat or to the top of the front windshield, and capture images of the person sitting in the driver's seat (driver), as well as cameras that capture images of passengers sitting in the passenger seat or back seat. The cameras that capture images of the surroundings of autonomous vehicle 1 include, for example, two cameras (stereo cameras) that are attached, for example, to the left and right sides of the rearview mirror, and that mainly capture images of the left and right front of autonomous vehicle 1; cameras that are attached, for example, to door mirrors or fender mirrors of autonomous vehicle 1, and capture images of the left and right sides; and a camera that captures images behind autonomous vehicle 1.
[0073] The sensor group 108 includes an open / close detection sensor that detects whether a door or window is open or closed, a sensor that detects whether a seatbelt is fastened, a seating sensor that detects whether a passenger is seated in a seat such as the driver's seat or the passenger seat, a human presence sensor (infrared sensor) that detects a person nearby outside the vehicle, and various other sensors for acquiring information that assists autonomous driving. The various sensors for acquiring information that assists autonomous driving include, for example, a vibration sensor that detects vibrations of the vehicle or tires, a rotation speed sensor that detects the number of tire rotations, a geomagnetic sensor that detects direction, an acceleration sensor that detects acceleration, and a gyro sensor (gyroscope) that detects angles and angular velocities. In this embodiment, the sensor group 108 also includes sensors that detect the illumination of right and left turn signals (direction indicators) and hazard lights (emergency flashers).
[0074] The surrounding moving object recognition unit 109 recognizes moving objects (including people) around the vehicle using images captured by the radar group 106, the sensor group 108, and the camera group 107. The surrounding moving object recognition unit 109 recognizes surrounding obstacles and moving objects by performing processing based on Bayes' theorem, for example.
[0075] The current position detection unit 110 receives radio waves from GPS satellites to detect the current position of the vehicle. Because the accuracy of the position detected by radio waves from GPS satellites is poor, the current position detection unit 110 uses not only the information on the current position detected by receiving radio waves from GPS satellites, but also images captured by one or more sensors included in the sensor group 108, the radar group 106, and the camera group 107 (also functioning as a navigation system), and performs processing based on Bayes' theorem, for example, to detect and confirm the current position with higher accuracy.
[0076] In the autonomous driving mode, the autonomous vehicle 1 uses the current position detection unit 110 and the surrounding moving object grasping unit 109 to process various information such as location information obtained by receiving radio waves from the radar group 106, the camera group 107, the sensor group 108, and GPS satellites, in other words, information corresponding to information obtained from the human eyes and ears, using Bayes' theory, and based on this, the control unit 101 performs intelligent information processing (artificial intelligence) and control (artificial intelligence) such as changing the vehicle's course and avoiding obstacles, to generate autonomous driving operation information.
[0077] Display unit 111 is made up of, for example, an LCD (Liquid Crystal Display). Touch panel 112 is configured by superimposing a touch sensor that allows touch input with a finger on the display screen of display unit 111 made up of an LCD. Under the control of control unit 101, a display image including software buttons (including character input buttons on a keyboard) is displayed on the display screen of display unit 111. When touch panel 112 detects a touch with a finger on a software button displayed on the display screen, it transmits the touch to control unit 101. In response to this, control unit 101 is configured to execute control processing corresponding to the software button.
[0078] Domestic maps and route guidance data are stored in advance in car navigation database 134 connected to car navigation function unit 113. Car navigation function unit 113 is a functional unit that provides guidance to assist autonomous vehicle 1 in traveling to a specified destination based on the maps and route guidance data stored in car navigation database 134. In this embodiment, car navigation function unit 113 is configured to perform slightly different processes in manual driving mode and autonomous driving mode.
[0079] That is, in the manual driving mode, the car navigation function unit 113 displays an image on the display screen of the display unit 111 in which the vehicle position detected and confirmed by the current position detection unit 110 is superimposed on a map that clearly displays the route to the destination, and also moves the vehicle position (current position) on the map as the vehicle moves, and provides voice guidance at points where route guidance is necessary, such as intersections and branching points on the route. This is the same as the normal car navigation function.
[0080] On the other hand, in the autonomous driving mode, when the current position of the vehicle is away from the route to the destination, the car navigation function unit 113 notifies the control unit 101 of information on the direction and distance of the departure, and when the current position of the vehicle is on the route to the destination, the car navigation function unit 113 notifies the control unit 101 of information instructing the control unit 101 to change the course direction along the route before an intersection or branch point on the route as the vehicle moves. Based on the information notified from the car navigation function unit 113, the current position confirmation result from the current position detection unit 110, and the recognition result from the surrounding moving object recognition unit 109, the control unit 101 controls the motor drive unit 131 via the motor drive control unit 103 so that the vehicle moves along the route as instructed, and generates autonomous driving operation information for controlling the steering drive unit 132 via the steering drive control unit 104. Therefore, thanks to route guidance to the destination by the car navigation function unit 113 and the control unit 101 in the autonomous driving mode, autonomous vehicle 1 can travel to the destination even when there are no passengers.
[0081] The planned user registrant information receiving unit 114 receives registration information such as family members who plan to use the self-driving vehicle 1 of this embodiment as information about the planned user registrant, and stores the received information about the planned user registrant in the planned user registrant information storage unit 115.
[0082] That is, in the case of autonomous vehicle 1 of this embodiment, when a user selects the "prospective user registrant registration" item from the processing menu displayed on the display screen of display unit 111, for example, prospective user registrant information receiving unit 114 is activated and enters a mode for registering information about the prospective user registrant. However, the prospective user registrant registration mode is only enabled when authentication is successful using an ID and password set in advance by, for example, the owner of autonomous vehicle 1, or the like.
[0083] Then, prospective user registrant information storage unit 115 accepts information on prospective users input by the user through touch panel 112 , and stores the information in prospective user registrant information storage unit 115 .
[0084] As described above, the information of the prospective user registrant is stored as biometric information such as facial image, voice, fingerprint, vein, iris, name, address, date of birth, ID, password, telephone number (phone number of a mobile phone terminal), email address, etc. The facial image of the prospective user registrant is photographed by a predetermined camera in the camera group 107 and stored.
[0085] In this embodiment, the facial image of the prospective user registrant among the information of the registered prospective user registrant stored in the prospective user registrant information storage unit 115 is used as authentication reference information for the first and second passenger authentication. Also, the telephone number of the mobile phone terminal among the registered information of the prospective user registrant stored in the prospective user registrant information storage unit 115 is used as authentication reference information for the first and second caller authentication, and is also used as connection information for connecting a communication path with the authentication permitted person during the third passenger authentication and the third caller authentication.
[0086] The caller authentication unit 116 performs the first caller authentication, the second caller authentication, and the third caller authentication described above. In this embodiment, the authentication reference information in the first caller authentication is the telephone number of the mobile phone terminal, which is the connection information of the prospective user registrant stored in the prospective user registrant information storage unit 115. Furthermore, the authentication reference information in the second caller authentication is the telephone number of the mobile phone terminal, which is the connection information of the prospective inputter stored in the prospective input information storage unit 119, which will be described later. Furthermore, the connection information of the authentication permitted person in the third caller authentication is the telephone number of the mobile phone terminal, which is the connection information of the prospective inputter stored in the prospective input information storage unit 119, which will be described later. Of course, the connection information of the authentication permitted person in the first caller authentication, the second caller authentication, and the third caller authentication is not limited to the telephone number of the mobile phone terminal, and may be an email address, etc.
[0087] The passenger authentication unit 117 performs the first passenger authentication, second passenger authentication, and third passenger authentication described above. In this embodiment, the facial image of the scheduled user registrant stored in the scheduled user registrant information storage unit 115 is used as the authentication reference information in the first passenger authentication. Furthermore, the facial image of the scheduled user inputter stored in the schedule input information storage unit 119 described later is used as the authentication reference information in the second passenger authentication. The connection information of the authentication authorized person in the third passenger authentication is the telephone number of the mobile phone terminal, which is the connection information of the scheduled user inputter stored in the schedule input information storage unit 119 described later.
[0088] In this embodiment, the re-boarding plan information receiving unit 118 determines whether the passenger currently on board is a registered user stored in the registered user information storage unit 115, and if it determines that the passenger is a registered user, when the passenger stops driving the motor drive unit 131 of the autonomous vehicle 1 and attempts to disembark, it presents the passenger with a list of planned re-boardings and prompts them to select and input information about their planned re-boardings.
[0089] In this embodiment, the determination of whether the passenger is a planned user registrant stored in the planned user information storage unit 115 is made by the re-boarding plan information receiving unit 118 based on the results of comparing the facial image of the planned user registrant stored in the planned user information storage unit 115 with the facial image of the passenger captured by the camera in the camera group 107. If the re-boarding plan information receiving unit 118 determines that the passenger is not a planned user registrant, it does not perform processing to prompt the passenger to input information about the re-boarding plan. If the re-boarding plan information receiving unit 118 determines that the passenger is a planned user registrant, it recognizes which planned user registrant the passenger is.
[0090] Then, the re-boarding plan information receiving unit 118 receives information on re-boarding plans selected and input by a passenger who is one of the registered users, and stores the information in the plan input information storage unit 119 in association with the information of the passenger who input the plan (information of the person who input the plan).
[0091] In this embodiment, the information on the scheduled inputter includes authentication reference information for the second caller authentication, authentication reference information for the second passenger authentication, and connection information of the scheduled inputter who is the authorized authentication person for the third caller authentication and the third passenger authentication.
[0092] In this embodiment, the authentication reference information for the second caller authentication is the telephone number of the mobile phone terminal of the schedule inputter, the authentication reference information for the second passenger authentication is facial image information of the schedule inputter, and the connection information of the schedule inputter who is the authorized and authenticated person for the third caller authentication and the third passenger authentication is the telephone number of the mobile phone terminal of the schedule inputter. Therefore, in this embodiment, the information of the schedule inputter stored in association with the inputted schedule information is facial image information of the schedule inputter and the telephone number of the mobile phone terminal carried by the schedule inputter.
[0093] Then, the information of the person who has input the plan is extracted from the person who has registered as a planned user, which has been recognized by the re-boarding plan information receiving unit 118 as described above, and is stored in the plan input information storage unit 119 in association with the plan information.
[0094] In this embodiment, the re-boarding plan information receiving unit 118 prompts the user to input information about plans to re-board when getting off only when there are multiple scheduled users stored in the scheduled user information storage unit 115. This is done to avoid the passenger having to be cumbersome to inquire about plans to re-board each time the passenger gets off, since when there is only one scheduled user, there are usually no other scheduled users using the service.
[0095] Note that the system may be configured so that passengers can input their re-boarding plans, regardless of whether there is only one registered user, by selecting the "Input re-boarding plan" option from the processing menu displayed on the display screen of the display unit 111. In this case, passengers can input information about their re-boarding plans while they are on the vehicle, rather than when they disembark. Also, in this embodiment, a list of information about re-boarding plans is presented and the system accepts the selection and input of a plan from that list, but it may also be configured so that the passenger can directly input information about their re-boarding plans by entering text or voice input, for example.
[0096] In this embodiment, when the re-boarding plan information receiving unit 118 confirms that the passenger has disembarked from the vehicle, it validates the plan information stored in the plan input information storage unit 119. The confirmation of the passenger disembarking is performed, for example, by detecting that the passenger has left the vehicle from images captured by one or more cameras capturing images of the interior of the vehicle, and by detecting the opening and closing of the door sensors in the sensor group 108.
[0097] In this embodiment, the post-dismounting behavior processing unit 120 accepts settings from the passenger regarding the post-dismounting behavior that the autonomously driven vehicle 1 should perform, and stores the accepted setting information in a built-in storage unit (not shown). In this embodiment, the post-dismounting behavior storage unit 121 stores pre-planned post-dismounting behaviors planned by the user. The post-dismounting behavior processing unit 120 presents the user with a list of post-dismounting behaviors stored in the post-dismounting behavior storage unit 121, and accepts settings for post-dismounting behavior information selected and set by the passenger from the list.
[0098] Note that, as an input method for setting the behavior after getting off, each behavior after getting off can also be input by reading it out loud. The control unit 101 is provided with a voice recognition function for this purpose. When the reboarding plan information receiving unit 118 described above receives input of a reboarding plan, if the reboarding plan information receiving unit 118 is configured to receive direct input of the plan rather than a list of plan information as in this embodiment, the voice recognition function of the control unit 101 can be used to receive input of the reboarding plan information in an interactive format.
[0099] Then, the post-disembarkation behavior processing unit 120 executes the behavior of the vehicle after the passenger disembarks based on the received post-disembarkation behavior. In this case, just as when the re-boarding plan information receiving unit 118 validates the input plan information, it confirms that the passenger has disembarked and there are no passengers in the vehicle, and executes processing based on the received post-disembarkation behavior. Note that if the passenger does not set a post-disembarkation behavior, a pre-stored predetermined post-disembarkation behavior may be automatically set and executed.
[0100] The voice input / output unit 122 captures voice collected by the microphone 135 and transmits it to the system bus 100 for, for example, a voice recognition processing function of the control unit 101. The voice input / output unit 122 also incorporates, although not shown, a memory for storing voice message data to be emitted externally, as well as a voice synthesizer and a DA converter for converting the voice message data read from the memory into an analog voice signal. The voice input / output unit 122 then supplies a voice message selected under the control of the control unit 101 to a speaker 136, which emits the voice message externally as a voice. Examples of voice messages to be stored include, as will be described later, a message prompting the user to input a re-boarding plan, such as "Please enter your re-boarding plan," an inquiry message such as "Do you want to register a prospective user?", notification messages such as "Authentication completed" and "Authentication failed," and an interactive message for accepting input of post-disembarkation behavior settings.
[0101] The autonomously driven vehicle 1 of the above-described embodiment is configured so that the above-described authentication modes in the caller authentication unit 116 and the passenger authentication unit 117, and the reception process in the re-boarding plan information reception unit 118, can be turned on or off via the touch panel 112. However, the on / off setting is only possible when authentication is successful using an ID and password set in advance by, for example, the owner of the autonomously driven vehicle 1. The authentication mode can be turned on or off for each of the first caller authentication, the second caller authentication, the third caller authentication, the first passenger authentication, the second passenger authentication, and the third passenger authentication. However, in the embodiment described below, the authentication mode is turned on or off for all of the first caller authentication, the second caller authentication, the third caller authentication, the first passenger authentication, the second passenger authentication, and the third passenger authentication.
[0102] The electronic control circuit unit 10 of the autonomous vehicle 1 is configured as described above, but of the processing blocks shown in Figure 1, the processing functions of the motor drive control unit 103, steering drive control unit 104, manual / autonomous driving mode switching control unit 105, surrounding moving object recognition unit 109, current location detection unit 110, car navigation function unit 113, planned user registration information reception unit 114, caller authentication unit 116, boarding user authentication unit 117, re-boarding plan information reception unit 118, post-disembarkation behavior processing unit 120, and voice input / output unit 122 can be realized as software processing performed by the control unit 101 executing a program.
[0103] [Example of processing operations in the self-driving vehicle 1 according to the embodiment] Next, an example of the processing operation of the control unit 101 of the autonomously driven vehicle 1 when a passenger on board the autonomously driven vehicle 1 attempts to get off the vehicle will be outlined.
[0104] In this embodiment, when a passenger on board the autonomous vehicle 1 attempts to get off, the autonomous vehicle 1 prompts the passenger to input a plan to re-board if necessary, and inquires whether to set a behavior after disembarking. Then, as necessary, the autonomous vehicle 1 accepts information about the passenger's plan and accepts input by the passenger of a setting for a behavior after disembarking, and after the passenger disembarks, performs processing according to the accepted information about the plan to re-board and the behavior after disembarking.
[0105] Fig. 3 is a flowchart illustrating an example of the flow of processing operations executed by the control unit 101 of the electronic control circuit unit 10 of the autonomously driven vehicle 1 when a passenger gets off the vehicle. Note that the processing of each step in the flowchart of Fig. 3 will be explained assuming that the processing functions of the re-boarding plan information receiving unit 118 and the post-disembarkation behavior processing unit 120 are realized as software processing performed by the control unit 101 executing a program.
[0106] The control unit 101 determines whether or not the driving of the motor driving unit 131 of the vehicle has been stopped (step S1). If it is determined in step S1 that the driving of the motor driving unit 131 has not been stopped, the control unit 101 continues the control required for traveling (step S2), and then returns to step S1.
[0107] When it is determined in step S1 that the driving of the motor driving unit 131 has been stopped, it is generally expected that the passenger will disembark, and therefore the control unit 101 performs processing to determine whether or not to accept input of information on plans to re-board before the passenger disembarks. That is, the control unit 101 refers to the scheduled user information storage unit 115 to determine whether or not there is only one registered scheduled user (step S3), and if it determines that there is only one registered scheduled user, the process proceeds to a processing routine for setting and inputting behavior after disembarking, which will be described later, from step S11 onwards in Fig. 4.
[0108] Also, when it is determined in step S3 that there are multiple registered prospective users, the control unit 101 takes a facial image of the passenger about to get off the vehicle using one of the cameras 107, and compares the facial image with the facial images of prospective users stored in the prospective user information storage unit 115 to determine whether the passenger about to get off the vehicle is a prospective user (step S4).
[0109] If it is determined in step S4 that the passenger about to disembark is not a registered user, the control unit 101 proceeds to a processing routine for inputting settings for post-disembark behavior, which will be described later, from step S11 onwards in Figure 4.
[0110] Furthermore, when it is determined in step S4 that the passenger about to disembark is a registered user, the control unit 101 emits a voice message from the speaker 136 prompting the passenger to enter a re-boarding request and also displays the message on the display screen of the display unit 111.Furthermore, in this embodiment, a list of selectable re-boarding plans is displayed on the display screen of the display unit 111 (step S5).
[0111] Fig. 5 shows an example of a list of re-boarding plans displayed on the display screen 111D of the display unit 111. In the list of re-boarding plans in Fig. 5, four types of plans, plan 1 to plan 4, can be selected and input.
[0112] Plan 1 is a plan selected when a passenger who is about to get off plans to re-board and wants to prohibit other registered users from using the vehicle. Plan 1 is selected when a passenger who is about to get off wants to have exclusive use of autonomous vehicle 1 after getting off due to other needs.
[0113] Plan 2 is a plan in which a passenger who is about to disembark has a plan to reboard, but if another person who has registered a plan to use the service requests to use the service, this will be permitted after obtaining approval from the person who entered the plan.
[0114] Plan 3 is a plan in which a passenger who is about to disembark has a plan to reboard, but if another person who has registered a planned use requests to use the service, that request will be permitted without the approval of the person who entered the plan.
[0115] Plan 4 states that passengers who are about to disembark will not be allowed to reboard, and that their use will temporarily end when they disembark from Autonomous Vehicle 1.
[0116] A passenger about to get off the bus enters a check mark in the check box of any one of schedules 1 to 4 and operates the confirmation icon button 141 to confirm the selection and input of the schedule information.
[0117] In addition, regarding plans for re-boarding, it is not necessary to select and input from a list of plans for re-boarding as described above, but passengers may also be able to input plans by voice input, text input, etc.
[0118] The control unit 101 determines whether or not a selective input of schedule information by a passenger about to get off has been accepted, depending on whether or not an operation of the check mark and confirmation icon button 141 has been accepted (step S6), and if it determines that the selective input of schedule information has been accepted, stores the selectively input schedule information (e.g., schedule number) in association with the information of the person who input the schedule in the schedule input information storage unit 119 (step S7). In this case, the control unit 101 obtains the information of the person who input the schedule by extracting the information of the planned user registrant recognized in step S4 (in this embodiment, information on a face image and a mobile phone terminal telephone number) from the planned user registrant information storage unit 115. After step S7, the process proceeds to a processing routine for setting and inputting behavior after getting off, which will be described later, from step S11 onwards in Fig. 4.
[0119] In step S11 of FIG. 4, a message inquiring whether or not to set behavior after getting off the vehicle is displayed on the display screen of the display unit 111, and is also output as a sound through the speaker 136.
[0120] Control unit 101 monitors and determines the passenger's response to the inquiry in step S11 (step S12), and if it determines that the passenger has responded that they will not set a behavior after disembarking, ends the processing routines in Figures 3 and 4. In this case, autonomous vehicle 1 stops motor drive unit 131 at the location where the passenger disembarks, and turns off the power while maintaining power supply to components necessary for processing while the vehicle is stopped. Also, a predetermined behavior to be performed when the passenger does not set a behavior after disembarking may be set in advance and executed.
[0121] If it is determined in step S12 that the passenger has responded that they will set a behavior after disembarking, the control unit 101 displays the behavior after disembarking stored in the behavior after disembarking memory unit 119 on the display screen of the display unit 111 as a list, for example, as shown in Figure 6 (step S13).
[0122] An example of each post-disembarkation behavior in the example list of FIG. 6 will be described.
[0123] "Go to default parking lot" causes the autonomous vehicle 1 to move to a pre-registered default parking lot after the passenger gets off the vehicle, and moving to the parking lot marks the end of the post-disembarkation behavior. Here, multiple parking lots can be registered as default parking lots, such as "home parking lot," "company parking lot," and "contract parking lot." Registering a parking lot means storing its location information and the name (type) of the parking lot, such as "home parking lot," "company parking lot," or "contract parking lot." When the passenger selects "Go to default parking lot" as the post-disembarkation behavior, the passenger also selects and sets the name of the default parking lot. Note that the default parking lot is not limited to being selected by name, but may also be selected by a place name such as an address.
[0124] "Wait in a nearby parking lot until called" means that the self-driving car 1 searches for a parking lot near the passenger's drop-off location and waits in that parking lot. After that, when the passenger makes a call by telephone using a mobile phone terminal through the wireless communication unit 102 of the self-driving car 1, the self-driving car 1 will respond to the call and return to the location where the user dropped off.
[0125] "Wait here" means that the self-driving car 1 will wait where the passenger got off. Of course, if the location where the passenger got off is a no-parking area, the self-driving car 1 will move to a nearby location where parking is possible and wait there. In this case, the self-driving car 1 will notify the passenger that it has moved and its destination.
[0126] "Waiting at point A" means that autonomous vehicle 1 waits at a location specified by the user, waiting for the user to reboard. Point A is specified by the user when getting off the vehicle. This point A may be set from among pre-registered points, or may be specified, for example, on a map, by inputting an address, or by specifying the name of an identifiable building. It may also be specified as two-dimensional coordinates of latitude and longitude (or three-dimensional coordinates by adding altitude). Furthermore, if point B can be specified by a phone number, it may also be specified by inputting the phone number.
[0127] 4, the control unit 101 monitors the input operation of the passenger via the touch panel 112 and waits for the selection of the post-disembarkation behavior from the list displayed on the display screen (step S14). When it is determined in step S14 that the selection of the post-disembarkation behavior from the list has been accepted, the control unit 101 performs processing to accept the selected post-disembarkation behavior (step S15).
[0128] Next, the control unit 101 determines whether the processing for accepting the selected post-disembarkation behavior has been completed (step S16), and when it determines that the processing for accepting the selected post-disembarkation behavior has been completed, it stores the selection information of the post-disembarkation behavior selected by the passenger and associated information (step S17).
[0129] Next, the control unit 101 confirms whether the passenger has disembarked using a door sensor or the like, and determines whether there is a passenger present (step S18). The presence or absence of a passenger is determined using a seating sensor, such as a weight sensor, provided on the seat of the autonomously driven vehicle 1, a touch sensor that determines whether a person has touched the steering wheel, and an image captured by a camera in the camera group 107 that photographs the passenger. If there is a passenger present, the control unit 101 waits for the passenger to disembark, and upon determining in step S18 that the passenger has disembarked and is no longer present, the control unit 101 executes the selected post-disembarkation behavior that has been stored, and validates the schedule information stored in the schedule input information storage unit 119 (step S19). In step S19, if the autonomously driven vehicle 1 is traveling and moving, the autonomously driven vehicle 1 is traveling autonomously in autonomous driving mode.
[0130] Next, the authentication processing operations of the caller authentication unit 116 and the passenger authentication unit 117 in the autonomously driven vehicle 1 of this embodiment will be described below. In the following explanation, it is assumed that the control unit 101 realizes, as software processing, the processing functions of the motor drive control unit 103, steering drive control unit 104, manual / autonomous driving mode switching control unit 105, surrounding moving object recognition unit 109, current position detection unit 110, car navigation function unit 113, caller authentication unit 116, passenger authentication unit 117, and voice input / output unit 122, among the blocks shown in Fig. 2.
[0131] <Call handling process> Figure 7 and its sequels, Figures 8 and 9, are flowcharts illustrating an example of the flow of processing operations of control unit 101 (including the processing content portion of caller authentication unit 116) when autonomously driven vehicle 1 receives an incoming call. In this embodiment, as described above, a call request to call autonomously driven vehicle 1 is made by starting a dedicated application program from a mobile phone terminal on which the application program has been installed in advance. In this case, the signal transmitted from the mobile phone terminal to autonomously driven vehicle 1 indicates that it is a call request and includes, as a standby location, information on the current location determined by the mobile phone terminal.
[0132] The control unit 101 monitors an incoming call notification from the wireless communication unit 102 and determines whether an incoming call has been detected (step S21). If it determines that an incoming call has not been detected, the control unit 101 performs other necessary processing (step S22), and then returns the processing to step S21.
[0133] If it is determined in step S21 that an incoming call has been detected, an automatic response is made (step S23), and the control unit 101 determines whether the incoming call is a call request (step S24), and if it determines that it is not a call request, the process proceeds to a response processing routine for the incoming call (step S25).
[0134] When it is determined in step S24 that the incoming call is a call request, the control unit 101 performs first caller authentication. That is, in this example, the control unit 101 compares the telephone number of the mobile phone terminal of the prospective user registrant stored in the prospective user registrant information storage unit 115 with the telephone number of the person receiving the call (step S26), determines whether they match (step S27), and performs first caller authentication.
[0135] If it is determined in step S27 that the telephone numbers do not match and the first caller authentication cannot be performed, the control unit 101 rejects the call, sends a voice message to the caller such as "The call is rejected because call authentication has not been performed," disconnects the connected call path (step S28), and ends this processing routine.
[0136] On the other hand, if it is confirmed in step S27 that the telephone numbers match and the first caller authentication is successful, the control unit 101 determines whether or not valid re-boarding schedule information exists in the schedule input information storage unit 119 (step S29). If it is determined in step S29 that valid schedule information exists, the control unit 101 compares the telephone number of the mobile phone terminal serving as connection information for the person who input the schedule information (schedule inputter) stored in the schedule input information storage unit 119 with the telephone number of the person who received the call (step S30), determines whether or not they match (step S31), and performs second caller authentication.
[0137] If the telephone numbers match and second caller authentication is successful in step S31, the process proceeds to step S41 in Fig. 8, and processing in response to the call from step S41 onwards is carried out. Even if it is determined in step S29 that no valid schedule information exists, the process proceeds to step S41 in Fig. 8, and processing in response to the call from step S41 onwards is carried out.
[0138] In step S41, the caller is notified that the call will be answered. Then, the control unit 101 extracts and acquires the location information of the waiting location sent from the caller (step S42). Next, the control unit 101 uses the function of the car navigation function unit 113 to search for a route to the waiting location using data from the car navigation database 134, and predicts and calculates the required time for travel to the waiting location (step S43). Next, the control unit 101 transmits the predicted required time to the caller via the wireless communication unit 102 (step S44). Next, the control unit 101 disconnects communication with the caller, activates a travel control routine to the waiting location (step S45), and ends this processing routine.
[0139] Furthermore, if it is determined in step S31 that the telephone numbers do not match and the second caller authentication cannot be performed, the control unit 101 performs the third caller authentication as follows: That is, the control unit 101 refers to the schedule information stored in the schedule input information storage unit 119 (step S51 in FIG. 9), and determines whether the stored schedule information is information that affirms availability to persons other than the schedule inputter (step S52).
[0140] If the stored schedule information is, for example, schedule 1 in the example of Figure 5, and use by others is prohibited, in step S52, the control unit 101 determines that the stored schedule information does not affirm availability to anyone other than the schedule inputter, and rejects the call (step S53). In step S53, the control unit 101 sends a voice message to the caller, such as "Call authentication has failed, so the call is rejected," and disconnects the connected call path. After completing the process of step S53, the control unit 101 terminates this processing routine.
[0141] Furthermore, if the stored schedule information is, for example, schedule 2, schedule 3, or schedule 4 in the example of FIG. 5, and use by others is not prohibited, then in step S52, it is determined that the stored schedule information affirms availability to persons other than the schedule inputter, and the control unit 101 determines whether approval from the schedule inputter is required to answer the call from the caller (step S54).
[0142] 5, and determines that approval from the schedule inputter is not required, the control unit 101 acquires the connection information of the schedule inputter from the schedule input information storage unit 119, connects a communication path to the schedule inputter, and notifies other schedule registrants that a call will be accepted (step S55). Thereafter, the control unit 101 proceeds to step S41 in FIG. 8, and performs the process in response to the call described above from step S41 onwards.
[0143] 5 and requires the approval of the schedule inputter in step S54, the control unit 101 acquires the connection information of the schedule inputter from the schedule input information storage unit 119, connects a communication path to the schedule inputter, and inquires of the schedule inputter whether or not other schedule use registrants can use the service (step S56).The control unit 101 then waits to receive a response from the schedule inputter regarding whether or not other schedule use registrants can use the service (step S57), and when it determines that a response has been received from the schedule inputter, it determines whether or not the response permits use by other schedule use registrants (step S58).
[0144] If it is determined in step S58 that the response from the schedule inputter permits use by other scheduled users, the control unit 101 proceeds to step S41 in Fig. 8, and performs the process in response to the call described above from step S41 onwards. If it is determined in step S58 that the response from the schedule inputter does not permit use by other scheduled users, the control unit 101 proceeds to step S53, rejects the call from the caller, and ends this processing routine.
[0145] <Call mobility control> Next, an example of the call movement control routine started in step S45 of FIG. 8 will be described with reference to FIG.
[0146] First, the control unit 101 sets the location indicated by the location information of the waiting location acquired in step S42 as the destination, and sets the departure point as the current location, and executes a route search using the functions of the car navigation function unit 113, and starts navigation (guidance) along the travel route (route) obtained as a result of the search (step S61).
[0147] Then, while checking the current location during movement, the control unit 101 determines whether the destination has been reached (step S62). If it determines that the destination has not been reached, it determines whether there is a significant delay, for example, 10 minutes or more, compared to the estimated required time for travel to the waiting location (step S63). If there is no significant delay, the process returns to step S62 and the processes from step S62 onwards are repeated. If it determines in step S63 that there is a significant delay, the required time is recalculated, a communication path is re-established with the caller, and the calculation result is notified to the caller (step S64). Then, the control unit 101 returns to step S62 and repeats the processes from step S62 onwards.
[0148] When it is determined in step S62 that the vehicle has arrived at the destination (waiting location), the control unit 101 stops the vehicle at the waiting location and starts the call boarding control routine (step S65). Then, the control unit 101 ends the call movement control routine.
[0149] <Passenger control> Next, an example of a boarding user control processing routine (including the processing content portion of the boarding user authentication unit 117) for a user (boarding user) who wishes to board the autonomously driven vehicle 1 will be described with reference to Fig. 11 and its continuations Figs. 12 and 13. This boarding user control routine corresponds to the call boarding control routine that is activated in the above-mentioned step S45 in the case of an autonomously driven vehicle 1 that has moved to the specified meeting place by the above-mentioned call control routine. However, this boarding user routine is executed not only after the above-mentioned call control routine has been executed, but also when the boarding user wishes to board the vehicle without making a call.
[0150] The control unit 101 monitors for the detection of a user who is about to board (boarding user) and waits for the detection of the boarding user (step S71). When the boarding user is detected in step S71, the control unit 101 captures a facial image of the boarding user with a predetermined camera of the camera group 107 (step S72).
[0151] Next, the control unit 101 performs a first passenger authentication. That is, in this example, the control unit 101 compares the facial image of the prospective user stored in the prospective user information storage unit 115 with the facial image of the passenger (step S73), and determines whether the two facial images match (step S74).
[0152] If it is determined in step S74 that the facial images do not match and the first user authentication has not been performed, the control unit 101 locks the vehicle (self-driving vehicle 1) in a state where it cannot be driven due to the failure of authentication, and puts it in a disallowed state where the riding user cannot use (drive) the vehicle (step S81 in Figure 12).
[0153] Then, the control unit 101 generates a voice message, for example by voice synthesis, to notify the boarding user that authentication has failed and to encourage the boarding user to get off the vehicle, and outputs the message through the speaker 136 to notify the boarding user (step S82).
[0154] Next, the control unit 101 determines whether or not it has been confirmed that the boarding user has dismounted (step S83), and if it is determined in step S83 that it has not been confirmed that the boarding user has dismounted, the control unit 101 continues the processing of step S83. If it is determined in step S83 that it has been confirmed that the boarding user has dismounted, the control unit 101 maintains the state in which the vehicle is locked in a non-traveling state until the next scheduled user becomes a boarding user (step S84). With this, the control unit 101 ends the processing routine for this boarding user.
[0155] Then, when it is determined in step S74 that the facial images match and that the first boarding user authentication has been completed, the control unit 101 determines whether or not valid plan information for re-boarding exists in the plan input information storage unit 119 (step S75). When it is determined in step S75 that valid plan information exists, the control unit 101 compares the facial image of the person who input the plan information (plan inputter) stored in the plan input information storage unit 119 with the facial image of the boarding user (step S76), determines whether or not they match (step S77), and performs second boarding user authentication.
[0156] Then, in step S77, if the facial images match and second caller authentication is successful, the vehicle is put into a state in which the passenger is permitted to use the vehicle (step S78). In this case, in step S78, the passenger is notified that use is permitted, and the schedule information stored in the referenced schedule input information storage unit 119 is invalidated by being deleted in this example. Of course, the schedule information may be saved with an invalid mark or the like attached, rather than being deleted.
[0157] Furthermore, if it is determined in step S77 that the facial images do not match and the second passenger authentication cannot be performed, the control unit 101 performs the third passenger authentication as follows: That is, the control unit 101 refers to the schedule information stored in the schedule input information storage unit 119 (step S91 in FIG. 13), and determines whether the stored schedule information is information that affirms the availability of users other than the person who input the schedule (step S92).
[0158] 5, and if the stored schedule information is schedule 1 in which use by others is prohibited, in step S92, the control unit 101 determines that the stored schedule information does not affirm the availability of use by anyone other than the schedule inputter, and proceeds to step S81 in Fig. 12, where it executes processing to deny use by the boarding user from step S81 onwards. In this case, in step S82, the control unit 101 sends a voice message to the boarding user such as "Boarding use authentication has not been successful, so use is denied," and disconnects the connected call path.
[0159] Furthermore, if the stored schedule information is, for example, schedule 2, schedule 3, or schedule 4 in the example of Figure 5, and use by others is not prohibited, this step S92 determines that the stored schedule information affirms availability for use by persons other than the schedule inputter, and the control unit 101 determines whether approval from the schedule inputter is required to comply with the use request of the passenger (step S93).
[0160] 5, and determines that approval from the plan inputter is not required, the control unit 101 acquires the connection information of the plan inputter from the plan input information storage unit 119, connects a communication path with the plan inputter, and notifies the plan inputter that the vehicle will be made available for use by other plan users (step S94).The control unit 101 then proceeds to step S78 in FIG. 11, sets the vehicle to a state in which use by the boarding user is permitted, and invalidates the valid re-boarding plan information stored in the plan input information storage unit 119, for example by deleting it.
[0161] 5 and requires the approval of the schedule inputter, the control unit 101 acquires the connection information of the schedule inputter from the schedule input information storage unit 119, connects a communication path to the schedule inputter, and inquires of the schedule inputter whether or not other schedule use registrants can use the service (step S95).The control unit 101 then waits to receive a response from the schedule inputter regarding whether or not other schedule use registrants can use the service (step S96), and when it determines that a response has been received from the schedule inputter, it determines whether or not the response permits use by other schedule use registrants (step S97).
[0162] If it is determined in step S97 that the response from the plan inputter indicates that use by other planned users is permitted, the control unit 101 proceeds to step S78 in Fig. 11, where the control unit 101 permits use by the boarding user and invalidates, for example, by deleting, the information on the valid re-boarding plan stored in the plan input information storage unit 119. Also, if it is determined in step S97 that the response from the plan inputter indicates that use by other planned users is not permitted, the control unit 101 proceeds to step S81 in Fig. 12 and executes processing to deny use by the boarding user from step S81 onwards. In this case, in step S82, the control unit 101 sends a voice message to the boarding user, such as "Boarding use authentication has not been successful, so use is denied," and disconnects the connected call path.
[0163] [Advantages of the above embodiment] In the self-driving vehicle 1 of the embodiment described above, authentication is performed on the user (caller) who is trying to call the vehicle, and also on the user (boarding user) who is trying to board the vehicle, based on the information on re-boarding plans entered by the passenger.Therefore, caller authentication and boarding user authentication can be performed according to the re-boarding convenience of the plan inputter who entered the re-boarding plans.
[0164] This also has the significant effect of enabling smooth coordination with the next person who wishes to use (ride) the vehicle, and improving safety in terms of security.
[0165] [Modifications of the above embodiment] In the above embodiment, the self-driving vehicle 1 is described as a private car shared by family members or relatives, but the self-driving vehicle 1 is not limited to private cars, and may also be a company car shared by company employees, an official car shared by members of a local government, or a car shared by other organizations.
[0166] Furthermore, in the above-described embodiment, if valid schedule information is not stored in the caller authentication and the passenger authentication, and it is determined that the person is not a registered scheduled user, the call or boarding is prohibited. However, when it is determined that the caller or the user attempting to board is not a registered scheduled user, an authorization and authentication person, such as the owner of autonomous vehicle 1, may be inquired as to whether the call or boarding should be permitted, and the call or boarding may be permitted based on the response to the inquiry.
[0167] Furthermore, in the above examples, when the self-driving vehicle 1 is unable to authenticate the caller or passenger as a registered planned user in the first caller authentication or first passenger authentication, the call or ride is denied, and the second caller authentication, second passenger authentication, third caller authentication, or second passenger authentication is not performed. However, when the self-driving vehicle 1 is unable to authenticate the caller or passenger as a registered planned user in the first caller authentication or first passenger authentication, the owner or the person who input the plan of the self-driving vehicle 1 may be configured to connect a communication path using connection information and send information that can be used to determine the identity of the caller or passenger, such as a facial image of the caller or passenger, via the communication path, so that the owner or the person who input the plan may decide whether to permit or deny (not permit) the call or ride.
[0168] Furthermore, automatically driven vehicle 1 may be provided with a start permission / prohibition determination means for determining whether use of the vehicle can be started, for example, a means for determining whether use of the vehicle can be started based on whether the door of the vehicle has been opened with a key (or whether the door of the vehicle can be opened) or whether the drive unit of the vehicle has been started with a key (or whether the drive unit of the vehicle can be started), and when it is determined that the vehicle door has been opened by the passenger with a key or the drive unit of the vehicle has been started with a key, it may determine that use of the vehicle can be started, and perform the third passenger authentication even if the passenger cannot be authenticated as a registered prospective user in the first passenger authentication. The key in this case is not limited to a mechanical key, but may also be a card key or a wireless key that performs key authentication by wirelessly verifying key information.
[0169] Note that when prospective users are registered in the autonomous vehicle 1 and all of the registered prospective users carry a key for the autonomous vehicle 1, the first passenger authentication may not be performed using biometric information such as a facial image as described above, but may be performed based on whether the passenger uses the key for the autonomous vehicle 1 to open the door of the vehicle or start the drive unit of the vehicle. Of course, authenticating the key carried by the passenger can also be used for the first passenger authentication and the third passenger authentication.
[0170] Furthermore, if the key of the prospective user is, for example, a key equipped with a wireless communication function (including NFC (Near Field Communication)) that enables the door to be opened and closed or the drive unit to be activated when prior key authentication is achieved via wireless communication, the key authentication can determine whether the key can be used to open the vehicle door before the door is actually opened, or whether the key can be used to activate the vehicle's drive unit before the drive unit is actually activated. Therefore, with this type of key, it is possible to authenticate whether the passenger is a prospective user based on whether the key can be used to open the vehicle door or whether the key can be used to activate the vehicle's drive unit.
[0171] Furthermore, in the above example, the users who can use autonomous vehicle 1 are the planned users stored in planned user information storage unit 115, so first caller authentication and first passenger user authentication are performed for caller authentication and passenger use authentication, respectively. However, in a vehicle according to the present invention, it is not essential to limit the users who can use the vehicle to planned users. Therefore, in a vehicle according to the present invention, it is sufficient to simply perform second call authentication and third caller authentication for call authentication, and second passenger user authentication and third passenger user authentication for passenger authentication.
[0172] In an example where the users who can use the autonomous vehicle 1 are not limited to the planned users stored in the planned user information storage unit 115, the information of the plan inputter who inputted the re-boarding plan (authentication reference information such as a facial image, and connection information) is stored in association with the plan information in the plan input information storage unit 119 when the plan inputter inputs the re-boarding plan information, by the control unit 101 capturing and acquiring an image of the plan inputter's face using a specified camera in the camera group 107, or by prompting the plan inputter to input connection information and acquiring the connection information inputted through the touch panel 112.
[0173] In the third caller authentication and the third passenger authentication, the control unit 101 acquires information from a caller or a passenger who was not authenticated in the second caller authentication and the second passenger authentication, such as a facial image, that enables the authentication authorizer to determine who the caller or passenger is, and sends the information to the authentication authorizer via the communication path. In this way, the authentication authorizer can determine who the caller or passenger is from the received information, making it easier to determine whether to permit the call or passenger use.
[0174] In the above-described embodiment, the telephone number used as authentication reference information by the caller authentication unit 116 is the telephone number of a mobile phone terminal. However, it goes without saying that the telephone number is not limited to a mobile phone terminal telephone number, and may be a landline telephone number or an IP phone telephone number. Furthermore, an email address can be used instead of a telephone number. Email addresses can be used not only on mobile phones but also on PCs, tablets, wristwatch-type terminals, eyeglass-type terminals, and the like. The same applies to the connection information for establishing a communication path with the schedule inputter in the third caller authentication and the third passenger authentication. Furthermore, in addition to a telephone number or an email address, an ID or nickname used in communication application software such as LINE (registered trademark) or an SNS (social networking service) such as Facebook (registered trademark) can also be used.
[0175] In the above-described embodiment, the call request includes information about the current location as the waiting location. However, a location other than the current location may be specified as the waiting location. In this case, the waiting location information may be an address or a telephone number, or may be specified as "in front of the convenience store at the north exit of XX Station on the XX Line" or "the main entrance of Ginza △△ Department Store." In this case, the autonomous vehicle 1 searches for the waiting location in the map information in the car navigation database 134 and detects the waiting location. However, if the waiting location cannot be detected, the autonomous vehicle 1 can access a map server on the Internet via the wireless communication unit 102, perform a search, and obtain the results to detect the waiting location. In this case, the route search to the meeting location can be performed in cooperation with the map server, and navigation can also be performed using the services of the map server.
[0176] Furthermore, while the autonomous vehicle 1 in the above-described embodiment has both an autonomous driving mode and a manual driving mode, it may be configured with only the autonomous driving mode. In this case, there is no manual driving mode, and therefore the manual / autonomous driving mode switching control unit 105 and the manual driving operation detection unit 133 are not required. Instead, an autonomous driving control unit (not shown) that performs control processing for autonomous driving is provided. Furthermore, in the autonomous driving mode, the driver does not need to perform operations such as accelerator pedal operation, brake pedal operation, shift lever operation, or steering operation (handle operation), and therefore the mechanisms required for these operations are also not required.
[0177] The invention regarding the first and second user authentication can be applied not only to self-driving cars but also to conventional cars that require a driver and do not have an autonomous driving mode. Of course, it can be applied not only to cars but also to all types of vehicles, such as motorcycles, single-seater vehicles, aircraft such as drones, motorboats, and ships such as ferries.
[0178] Furthermore, since the above-mentioned self-driving vehicle can run without a driver, the passengers are not limited to the driver, but may also be passengers sitting in the passenger seat or the back seat.
[0179] In the above-described embodiment, the self-driving car is an electric vehicle, but it may be a gasoline-powered vehicle, a fuel cell vehicle, or another type of vehicle. Furthermore, the self-driving car may be one that can travel not only by guidance from a car navigation system, but also by guidance from external radio waves from traffic lights, signposts, etc.
[0180] In the above-described embodiment, the scheduled user registrant information storage unit 115, the scheduled input information storage unit 119, and the car navigation database 134 are installed in the vehicle, but some or all of these storage units can be installed on the cloud instead of in the vehicle and used via the communication network 3. Furthermore, some or all of the authentication units, such as the caller authentication unit 116 and the passenger authentication unit 117, can be processed on the cloud via the communication network 3 instead of in the vehicle.
[0181] Furthermore, in the above-described embodiment, the first and second passenger authentications use the passenger's facial image, but the passenger's voice can also be used. When passenger authentication is performed using the passenger's voice, the autonomously driven vehicle 1 picks up the passenger's voice with the microphone 135 and stores the voice of the prospective registered user in the prospective registered user information storage unit 115, and the passenger authentication unit 117 is configured to have a speaker voice recognition function and determines whether the stored voice matches or does not match the voice of the new user picked up by the microphone 135, thereby authenticating the passenger.
[0182] Furthermore, when passenger authentication is performed using the passenger's fingerprint, a fingerprint reader is provided in self-driving vehicle 1, the fingerprints of prospective registered users are stored in planned user information storage unit 115, and passenger authentication unit 117 is configured to have a fingerprint recognition function, and passenger authentication is performed by determining whether the stored fingerprint matches or does not match the fingerprint of the new passenger acquired by the fingerprint reader. Vein, iris, or other biometric information can also be used by changing the configuration in a similar manner.
[0183] In addition, in the above embodiment, information on the next planned re-ride is entered, but the information on the planned re-ride may also be information on a schedule spanning multiple days, such as within the same day or over two days.
[0184] For example, as shown in Figure 14, suppose that on a certain day, when the disembarking time is 9:59, the person who input the schedule has three plans to re-board the bus after disembarking: between 10:00 and 12:00, between 12:00 and 15:00, and between 15:00 and 20:00, and the schedule information for each trip is set and input as shown in Figure 14: Schedule 1 shown in Figure 5 for the time between 10:00 and 12:00, Schedule 2 shown in Figure 5 for the time between 12:00 and 15:00, and Schedule 1 shown in Figure 5 for the time between 15:00 and 20:00. Note that in the example of Figure 14, the person who input the schedule information is the passenger who will board the bus for each of the multiple trips.
[0185] When the plan information is schedule information like this, the control unit 101 of the self-driving vehicle 1 performs caller authentication and / or passenger authentication based on the information on multiple plans while managing the passage of time.
[0186] That is, the control unit 101 determines that the schedule information for schedule 1 is valid from 10:00 to 12:00, the schedule information for schedule 2 is valid from 12:00 to 15:00, and the schedule information for schedule 1 is valid from 15:00 to 20:00. Therefore, when a call or a request for boarding is made between 10:00 and 12:00, the control unit 101 performs caller authentication and boarding user authentication based on the schedule information for schedule 1, when a call or a request for boarding is made between 12:00 and 15:00, the control unit 101 performs caller authentication and boarding user authentication based on the schedule information for schedule 2, and when a call or a request for boarding is made between 15:00 and 20:00, the control unit 101 performs caller authentication and boarding user authentication based on the schedule information for schedule 1. The person authorized to be authenticated in the third caller authentication and the third passenger authentication based on the information of the schedule 2 is the person who input the schedule information.
[0187] The schedule information may be provided by presenting a schedule template from the self-driving vehicle 1 and having the user input the necessary information, or may be input directly by the person inputting the schedule. Furthermore, the schedule information may be input interactively between the self-driving vehicle 1 and the person inputting the schedule. Schedule information may also be input using a mobile phone terminal carried by the person inputting the schedule, and then transmitted to the self-driving vehicle 1.
[0188] In the example schedule of Fig. 14, the person who inputted the schedule himself / herself will be the returning passenger for each scheduled trip, but the person who inputted the schedule can also set a different person as the returning passenger for each scheduled trip, as shown in Fig. 15. In that case, the authentication reference information for the first and second call authentication and the authentication reference information for the first and second passenger authentication will use not only the person who inputted the schedule but also the telephone number of the mobile phone terminal of the returning passenger (scheduled passenger) for each scheduled trip, biometric information such as a facial image, etc.
[0189] In the first and second caller authentications, authentication is performed to determine whether the caller is either the person who input the schedule or a person who will re-board at each scheduled time (a person planning to board). In addition, the person authorized to be authenticated in the third caller authentication and the third boarding user authentication can be either the person who input the schedule or the person who will re-board at each scheduled time, or both. The person who input the schedule can set whether the person to be authenticated in the first and second caller authentications is the person who input the schedule or the person who will re-board at each scheduled time (a person planning to board), and whether the person authorized to be authenticated in the third caller authentication and the third boarding user authentication is the person who input the schedule or the person who will re-board at each scheduled time (a person planning to board).
[0190] For this purpose, in addition to schedule information and information about the person who input the schedule, information about the person who input the schedule also about the person who will be returning for each trip is input and stored in the schedule input information storage unit 119 of the autonomously driven vehicle 1. In this case, the information about the person who will be returning for each trip includes authentication reference information (e.g., telephone number) for the first and second call authentications, authentication reference information (e.g., facial image) for the first and second passenger authentications, and connection information for the third caller authentication and the third passenger authentication.
[0191] In this case, if all the re-boarding persons to be set are scheduled users, the information of the re-boarding persons stored in scheduled user registrant information storage unit 115 is extracted in response to a selection instruction from the schedule inputter for the scheduled user registrant and stored in schedule input information storage unit 119. Also, if the re-boarding persons are not scheduled users, the schedule inputter directly enters the above information for the re-boarding persons. In this case, the schedule inputter can also obtain the information of the re-boarding persons stored in the cloud and store it in schedule input information storage unit 119.
[0192] In the above-described embodiment, the plan information for the next re-boarding trip is a case in which the plan inputter himself / herself is the re-boarder. However, the plan inputter may specify a person other than himself / herself as the plan information for the next re-boarding trip. In that case, the plan information also includes information about the re-boarder (planned boarder) (biometric information such as a facial image, authentication reference information including a telephone number, and connection information such as a telephone number and an email address). As with the schedule shown in FIG. 15 , if all the re-boarders to be set are planned users, the information about the re-boarders stored in the planned user registrant information storage unit 115 is extracted and stored in the plan input information storage unit 119 in response to a selection instruction from the plan inputter for the planned user. If the re-boarder is not a planned user, the plan inputter directly inputs the above information about the re-boarder.
[0193] In this example as well, the first and second caller authentications authenticate whether the caller is either the person who input the plan or a person who will be re-boarding at each scheduled time (a person planning to board). Furthermore, the person authorized to be authenticated in the third caller authentication and the third boarding user authentication can be either the person who input the plan or the person planning to board, or both. The person who input the plan can set whether the person to be authenticated in the first and second caller authentications is the person who input the plan or the person planning to board, and whether the authorized person to be authenticated in the third caller authentication and the third boarding user authentication is the person who input the plan. [Explanation of symbols]
[0194] 1...Autonomous driving vehicle, 3...Communication network, 10...Electronic control circuit unit, 101...Control unit, 102...Wireless communication unit, 107...Camera group, 111...Display unit, 112...Touch panel, 113...Car navigation function unit, 114...Registered user information reception unit, 115...Registered user information storage unit, 116...Caller authentication unit, 117...Boarding user authentication unit, 118...Re-boarding plan information reception unit, 119...Planned input information storage unit
Claims
1. A start possibility determination means for determining whether or not use of the vehicle can be started based on whether or not the door of the vehicle has been opened by a person attempting to get in using a key, or whether or not the door of the vehicle can be opened, or whether or not the drive unit of the vehicle has been started by a person attempting to get in using a key, or whether or not the drive unit of the vehicle can be started; a re-boarding information storage means for storing in a first storage unit information on a re-boarding plan of a person who has disembarked from the vehicle and is planning to re-board the vehicle; a first determination means for determining whether or not the information on the re-boarding plan is stored in the first storage unit when the start possibility determination means determines that the use of the vehicle can be started; a usage permission means for permitting the person attempting to board to use the vehicle when the first determination means determines that the information on the re-boarding plan is not stored; and A motor vehicle comprising:
2. The key is a wireless key that authenticates the key by verifying key information wirelessly.
2. The vehicle according to claim 1 .
3. The key is a mechanical key or a card key.
2. The vehicle according to claim 1 .
4. The re-boarding information storage means stores the information on the re-boarding plan in association with information on the person who input the information on the re-boarding plan, a second determination means for determining whether the person intending to board is the same person as the person who input the information on the re-boarding plan, using information on the person who input the information on the re-boarding plan stored in the first storage unit and information acquired from the person intending to board; When the first determination means determines that the information on the re-boarding plan exists, and the second determination means determines that the person who inputted the information on the re-boarding plan is the same person as the person who intends to board, the use permission means permits the person who intends to board to use the vehicle. The automobile according to any one of claims 1 to 3.
5. The re-boarding plan information of the person who input the re-boarding plan information and who is determined by the second determination means to be the same person as the person who intends to board is deleted from the first storage unit, or a notice indicating that the information is invalid is added to the first storage unit.
5. The vehicle according to claim 4.
6. When the first determination means determines that the information on the re-boarding plan exists, and the second determination means determines that the person who inputted the information on the re-boarding plan is not the same person as the person who intends to board, the use permission means determines whether or not to permit the person who intends to board to use the vehicle based on the information on the re-boarding plan stored in the re-boarding information storage means.
6. A vehicle according to claim 4 or claim 5.
7. The re-boarding information storage means receives input of the re-boarding plan information, including information on whether or not to permit use by others other than the person who inputted the re-boarding plan information, and stores the information in a first storage unit; When the first determination means determines that the information on the re-boarding plan exists, and the second determination means determines that the person who inputted the information on the re-boarding plan is not the same person as the person who intends to board, the use permission means determines whether to permit the person who intends to board to use the vehicle based on information on permission or non-permission of use of others other than the person who inputted the information on the re-boarding plan, which is included in the information on the re-boarding plan. The automobile according to any one of claims 4 to 6.
8. The information about the re-boarding plan includes information that the use of the vehicle has ended and that the user will not re-board, When the first determination means determines that the information on the re-boarding plan exists, and the second determination means determines that the person who inputted the information on the re-boarding plan is not the same person as the person who intends to board, the use permission means permits the person who intends to board to use the vehicle based on the information that the person will not re-board, which is included in the information on the re-boarding plan. The automobile according to any one of claims 4 to 7.
9. The re-boarding information storage means stores the information on the re-boarding plan in association with information on the person who input the information on the re-boarding plan, The information on the re-boarding plan allows use by others other than the person who inputted the information on the re-boarding plan, and includes information on whether approval is required by the person who inputted the information on the re-boarding plan, means of communication; a connection information storage means for storing connection information for communication between the terminal held by the person who inputted the information on the re-boarding plan and the terminal held by the communication means; Equipped with When the first determination means determines that the information on the re-boarding plan is stored, and when the second determination means determines that the person who inputted the information on the re-boarding plan is not the same person as the person who intends to board, and when the information on the re-boarding plan includes information on whether approval is required from the person who inputted the information on the re-boarding plan, the use permission means uses the connection information stored in the connection information storage means to create and connect a communication path to the person who inputted the information on the plan, asks the person who inputted the information on the plan whether or not to allow the person to use the vehicle, and determines whether or not to allow the person who intends to board to use the vehicle based on the result of the inquiry. The automobile according to any one of claims 4 to 8.
10. If the re-boarding plan information referenced by the use permission means when determining whether or not to permit the person attempting to board to use the vehicle permits use by others other than the person who input the re-boarding plan information and does not require the approval of the person who input the re-boarding plan information, when the use permission means permits the person attempting to board to use the vehicle, the referenced re-boarding plan information is deleted from the first storage unit, or a notice that it is invalid is added to the first storage unit.
10. The vehicle according to claim 9.
11. The information is deleted from the first storage unit, or a notice indicating that the information is invalid is added to the first storage unit. The person who input the information on the re-boarding plan that was referenced is notified that the vehicle will be made available for use by another person.
11. The vehicle according to claim 10.
12. If the re-boarding plan information referenced by the use permission means when determining whether or not to permit the person attempting to board to use his / her vehicle permits use by others other than the person who input the re-boarding plan information and requires the approval of the person who input the re-boarding plan information, when the use permission means permits the person attempting to board to use his / her vehicle with the approval of the person who input the re-boarding plan information, the referenced re-boarding plan information is deleted from the first storage unit or a notice indicating that it is invalid is added to the first storage unit. The automobile according to any one of claims 9 to 11.
13. The information on the re-boarding plan is information on a schedule of subsequent boardings, and the information on the plan for the next boarding after the current time is made valid, When the first determination means determines that the information on the re-boarding plan exists, and the second determination means determines that the person attempting to board is not the same person as the person who input the schedule information, the use permission means determines whether or not to permit the person attempting to board to use the vehicle based on the valid schedule information. The automobile according to any one of claims 4 to 12.
14. The information on the re-boarding plan is information on a schedule for multiple consecutive boardings, and the person planning to board each time can be different from the person who inputted the information on the plan, and the information on the plan for boarding after the current time is valid, When the first determination means determines that the information on the re-boarding plan is stored, and when the second determination means determines that the person attempting to board is not the same person as the person who inputted the schedule information, the use permission means determines whether or not the person attempting to board is a person scheduled to board each time, and when it is determined that the person attempting to board is not a person scheduled to board each time, determines whether or not to permit the person attempting to board to use the vehicle based on the schedule information that has become valid. The automobile according to any one of claims 4 to 13.
15. The information on the re-boarding plan allows the next person planning to board the vehicle to be different from the person who input the information on the re-boarding plan, and the information on the re-boarding plan is stored in association with the authentication reference information of the person planning to board the vehicle, When the first determination means determines that the information on the re-boarding plan is stored, and when the second determination means determines that the person attempting to board is not the same person as the person who input the information on the re-boarding plan, the use permission means determines whether or not the person attempting to board is the person scheduled to board the next time, and when it determines that the person attempting to board is not the person scheduled to board, determines whether or not to permit the person attempting to board to use the vehicle based on the information on the plan that has become valid. The automobile according to any one of claims 4 to 14.
16. The re-boarding information storage means stores authentication reference information of the person who inputs the re-boarding plan information as information of the person who inputs the re-boarding plan information. The automobile according to any one of claims 4 to 15.
17. The authentication reference information is one or a combination of biometric information including a face image, voice, fingerprint, vein, and iris, name, address, date of birth, ID, password, telephone number, or email address.
17. The vehicle of claim 16.
18. The input of the re-boarding plan information is a selection setting from one or more pre-registered plans. The automobile according to any one of claims 1 to 17.
19. A car that drives automatically by autonomous driving, a registration receiving means for storing information of a person who plans to use the vehicle as a prospective user registrant in a second storage unit in association with authentication reference information for the prospective user registrant; means of communication; a third determination means for, when receiving a call request from a caller attempting to call the vehicle via the communication means, acquiring authentication information of the caller, and determining whether the caller is a prospective user registrant based on the acquired authentication information and the authentication reference information stored in the second storage unit; a fourth determination means for determining whether or not the information on the re-boarding plan is stored in the first storage unit when the third determination means determines that the caller is the scheduled user; a call permission means for permitting the caller to call the vehicle when the fourth determination means determines that the information on the re-boarding plan is not stored in the first storage unit; and The automobile according to any one of claims 1 to 18, characterized in that it comprises:
20. The re-boarding information storage means stores the information on the re-boarding plan in association with information on the person who input the information on the re-boarding plan, When the fourth determination means determines that the information on the re-boarding plan is stored in the first storage unit, if the person who inputs the information on the re-boarding plan is the same person as the caller who is determined to be the planned user by the third determination means, the call permission means permits the caller to call the vehicle.
20. The vehicle of claim 19.
21. The re-boarding information storage means stores the information on the re-boarding plan in association with information on the person who input the information on the re-boarding plan, When the fourth determination means determines that the re-boarding plan information is stored in the first storage unit, if the person who inputs the re-boarding plan information is not the same person as the caller who is determined to be the planned user by the third determination means, the call permission means determines whether to permit the caller to call the vehicle based on the re-boarding plan information stored in the re-boarding information storage means.
21. A motor vehicle according to claim 19 or claim 20.
22. A car that drives automatically by autonomous driving, A person who gets into the car sets the behavior after getting out of the car. The automobile according to any one of claims 1 to 21.
23. The behavior after getting off the vehicle is set by selecting from a list of behavior after getting off the vehicle.
23. The vehicle of claim 22.
24. If the behavior after getting off the vehicle is not set, a predetermined behavior after getting off the vehicle is executed.
24. A motor vehicle according to claim 22 or claim 23.
25. The computer installed in the car, a start permission / prohibition determination means for determining whether or not use of the vehicle can be started based on whether or not the door of the vehicle has been opened by a person attempting to get in using a key, or whether or not the door of the vehicle can be opened, or whether or not the drive unit of the vehicle has been started by a person attempting to get in using a key, or whether or not the drive unit of the vehicle can be started; a re-boarding information storage means for storing in a first storage unit information on a re-boarding plan of a person who has disembarked from the vehicle and is planning to re-board the vehicle; a first determination means for determining whether or not the information on the re-boarding plan is stored in the first storage unit when the start possibility determination means determines that the use of the vehicle can be started; a usage permission means for permitting the person attempting to board to use the vehicle when the first determination means determines that the information on the re-boarding plan is not stored; Automotive program to run as.
Citation Information
Patent Citations
Vehicle antitheft device, vehicle antitheft method, and program
JP2010208554A
Personal authentication security device
JP2011025903A
Automobile and automobile program
WO2015151862A1
Automatic driving vehicle and program for automatic driving vehicle
WO2015166811A1