Vehicle configuration system tailored to the occupants
A multi-factor authentication system for vehicles ensures secure and convenient access to occupant-specific settings by verifying both the occupant and the vehicle combination, addressing security gaps in existing systems.
Patent Information
- Application Number
- JP2021127477
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-08-03
- Publication Date
- 2025-12-10
- Estimated Expiration
- 2041-08-03
AI Technical Summary
Existing vehicle systems face challenges in ensuring secure and convenient access to occupant-specific setting information, as sole occupant authentication may not provide sufficient security against fraudulent use, and not all vehicles have necessary authentication equipment.
A multi-factor authentication system involving a first authentication unit for occupant verification and a second authentication unit for vehicle-occupant combination verification, along with a server device to record and manage occupant-specific setting information, ensuring secure access to authorized users.
Enhances security of occupant-specific setting information by requiring multi-stage authentication, preventing unauthorized access and ensuring secure use of services like payment accounts, while allowing convenient setup of vehicle settings for authorized occupants.
Smart Images

Figure 0007783704000001 
Figure 0007783704000002 
Figure 0007783704000003
Abstract
Description
[Technical Field]
[0001] The present invention provides a vehicle setting system according to the occupant. Mu Regarding. [Background technology]
[0002] In vehicles such as automobiles, passengers can adjust the seat position and other settings. Furthermore, automobiles in recent years are equipped with sophisticated information devices, allowing passengers to use telematics services, content services, and sales services while in the automobile. In such a vehicle, after getting into the vehicle, the occupant will adjust the seat position to suit themselves and perform operations to connect to various network services such as telematics services. Passengers will no longer be able to get into the car and start driving immediately. In particular, when passengers wish to use multiple network services while on board, they must perform connection operations for each of the multiple network services they wish to use, which is a hassle that passengers cannot bear. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2004-243825 [Patent Document 2] Japanese Patent Application Publication No. 2017-043268 [Patent Document 3] Japanese Patent Application Publication No. 2019-113947 Summary of the Invention [Problem to be solved by the invention]
[0004] As a countermeasure against such a situation, it is conceivable that the automobile records the setting information in a vehicle memory or in a server device with which the automobile can communicate (Patent Documents 1 and 2). When recording setting information in this manner, it is necessary to identify and authenticate the occupants of the vehicle so that the setting information is not available to anyone in the vehicle (Patent Documents 2 and 3). By combining these technologies, a vehicle can identify its occupants using biometric authentication or other methods, obtain occupant-specific setting information stored in the vehicle or a server device, and perform settings to make the information available in the vehicle.
[0005] However, if occupant-specific setting information stored in a vehicle or server device is acquired and made available solely through authentication of the occupant, it may be difficult to say that sufficient security is ensured depending on the content of the setting information. For example, it is considered strongly desirable to ensure that account information for payment services used in sales services, etc., cannot be used by anyone other than the genuine occupant. If information becomes available simply by identifying and authenticating the occupant, it is difficult to say with certainty that there is little possibility that the payment service will be fraudulently acquired or used by others through impersonation or the like. Occupant-specific setting information requires high security to prevent it from being used by others.
[0006] In addition, vehicles are generally used with the same equipment as when they were first used. Therefore, vehicles do not necessarily have all of the equipment for the authentication function described above. Even if an occupant of such a vehicle records their own occupant-specific setting information in a server device separate from the vehicle, the occupant cannot use the information in the vehicle.
[0007] In this way, it is necessary to improve safety of the setting information for each occupant used in a vehicle while ensuring convenience for authentic use. [Means for solving the problem]
[0008] A vehicle setting system according to one aspect of the present invention is an occupant-specific vehicle setting system having a setting unit that executes setting on the vehicle to make occupant-specific settings available in the vehicle, the system including a server device having a server recording unit that records occupant-specific setting information for occupants riding in the vehicle, a first authentication unit in the vehicle that authenticates the occupant riding in the vehicle, and a setting unit that executes setting on the vehicle to make occupant-specific settings available in the vehicle, the server device having a server recording unit that records occupant-specific setting information for occupants riding in the vehicle, a first authentication unit in the vehicle that authenticates the occupant riding in the vehicle, and a setting unit that executes setting on the vehicle to make occupant-specific settings available in the vehicle. The aforementioned Occupant information and the vehicle identification Get the information and Register member and before and a second authentication unit that authenticates a combination with the vehicle, the second authentication unit acquiring information from the vehicle. The aforementioned Occupant information and the vehicle identification With information The aforementioned Even if the combination of the occupant and the vehicle cannot be authenticated, the occupant may be identified as a passenger in the vehicle. The aforementioned A passenger terminal of a passenger holds the terminal to access the server device. the crew member account information and the vehicle Identification information In combination with Register member and before The combination with the vehicle is authenticated.
[0009] Preferably, the second authentication unit Register The passenger terminal of the passenger Place For access authentication Crew members If you do not have account information, Note A Count Information The above using The combination of the occupant and the vehicle may not be authenticated.
[0010] Preferably, the server recording unit of the server device R The server device also stores the set information for each occupant, together with the combination information of the occupant's identification information and the vehicle's identification information by the second authentication unit. PlaceFor access authentication Crew members The second authentication unit associates and records account information of the driver and driver's vehicle. The aforementioned The server device is installed in the passenger terminal of the passenger. Place The account information stored for access authentication of the vehicle matches the account information recorded in the server record unit of the server device, and further, the vehicle associated with the matching account information of Identification information obtained from the vehicle of the vehicle If the identification information matches, with staff The combination with the vehicle may be authenticated.
[0011] Preferably, the vehicle is The aforementioned a vehicle communication device connectable to the occupant terminal of the occupant, and the second authentication unit Vehicle Communication Device When the passenger terminal is connected to The aforementioned Occupant information and the vehicle identification Along with the information, Vehicle Communication Device The server device is held in the passenger terminal connected to the Place For access authentication The aforementioned Get your account information and Register member and before It is preferable to authenticate the combination with the vehicle.
[0012] Preferably, the vehicle communication device Register It is preferable that the vehicle information terminal can be connected to the passenger terminal of the passenger by wire.
[0013] Preferably, the vehicle has at least the setting unit among the setting unit, the first authentication unit, and the second authentication unit. [Effects of the Invention]
[0014] In the present invention, in order for a vehicle occupant to set and use their occupant-specific setting information in the vehicle, they must be authenticated by the first authentication unit, and the combination of the occupant and the vehicle must be authenticated by the second authentication unit. By using such multi-factor and multi-stage authentication that is not based solely on authentication of the occupant, the security of the occupant-specific setting information recorded in the server recording unit of the server device is enhanced. Furthermore, the second authentication unit authenticates at least the combination of the occupant authenticated by the first authentication unit and the vehicle in which the occupant is riding, and therefore can also authenticate the authenticity of the routing from the vehicle to the server device. The second authentication unit of the present invention is considered to make it more difficult for the occupant-specific setting information of the server device to be fraudulently obtained or used, compared to, for example, when the server device authenticates the vehicle based on authentication of the occupant by the first authentication unit. This enhances the security of the occupant-specific setting information of the server device. Furthermore, in the present invention, when the first authentication unit in the server device has authenticated the occupant in the vehicle, the second authentication unit acquires occupant information and vehicle information from the vehicle and authenticates the combination of the occupant in the vehicle and the vehicle. Even if the combination of the occupant and the vehicle cannot be authenticated using the occupant information and vehicle information acquired from the vehicle, the second authentication unit authenticates the combination of the occupant in the vehicle and the vehicle using the combination of the occupant's account information held by the occupant's occupant's occupant's terminal for accessing the server device. This allows the occupant in the vehicle to receive combined authentication from the second authentication unit based on the access history of the occupant's terminal to the server device, even if the occupant cannot be authenticated by the second authentication unit through combined authentication using the occupant information and vehicle information acquired from the vehicle due to, for example, vehicle functions. The setting unit can obtain setting information for each occupant in the vehicle from the server record unit of the server device and set it in the vehicle by obtaining combined authentication of the occupant's terminal and the vehicle using the second authentication unit's combined authentication of the occupant information replaced with the vehicle occupant's information. In this way, the present invention can improve safety while ensuring convenience in authentic use of setting information for each occupant used in a vehicle. [Brief explanation of the drawings]
[0015] [Figure 1] FIG. 1 is an explanatory diagram of a vehicle setting system for an automobile according to an embodiment of the present invention. [Figure 2] FIG. 2 is an explanatory diagram of the control system of the automobile of FIG. [Figure 3] FIG. 3 is an explanatory diagram of a computer device that can be used as the occupant information server device of FIG. [Figure 4] FIG. 4 is an explanatory diagram of the storage destination of the setting information for each occupant in the vehicle setting system of the automobile of FIG. 1 and a plurality of functions used in the vehicle setting system. [Figure 5] FIG. 5 is a flowchart of setting control according to the passengers riding in the automobile, performed by the control system of the automobile of FIG. [Figure 6] FIG. 6 is a timing chart of setting control when an occupant undergoes two-stage authentication in the vehicle setting system of the automobile of FIG. [Figure 7] FIG. 7 is a flowchart of authentication control for a combination of an occupant riding in a vehicle and the vehicle, performed by the occupant information server device of FIG. DETAILED DESCRIPTION OF THE INVENTION
[0016] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.
[0017] FIG. 1 is an explanatory diagram of a vehicle setting system 1 for an automobile 2 according to an embodiment of the present invention. 1 executes settings for an automobile 2 in which an occupant, such as a driver, rides, according to the occupant. The vehicle setting system 1 has a control system 3 for the automobile 2 and an occupant information server device 4 capable of data communication with the control system 3. The automobile 2 is an example of a vehicle in which an occupant rides.
[0018] A passenger in the automobile 2 approaches the automobile 2 and gets in while carrying an occupant terminal 5 and a boarding key 6. An application program for managing or using the automobile 2 may be installed on the occupant terminal 5. Like the boarding key 6, such an occupant terminal 5 may be capable of executing control to unlock the automobile 2 when the occupant approaches the automobile 2. The automobile 2 shown in FIG. 1 can be used jointly by multiple passengers.
[0019] The control system 3 of the automobile 2 may establish a communication path with a base station 7 located around the automobile 2, and perform data communication with the occupant information server device 4 and the like through the base station 7 and a communication network 8. The base station 7 and the communication network 8 may be for 5G provided by a carrier, or may be for, for example, an ADAS (Advanced Driver Assistance System) provided by a public institution or the like. Furthermore, the control system 3 of the automobile 2 may be connected to each of a plurality of service providing devices 9-11 used by the occupants in the automobile 2 via the base station 7 and the communication network 8, and may transmit and receive service information to and from the plurality of service providing devices 9-11. FIG. 1 shows a first service providing device 9, a second service providing device 10, ..., an m-th service providing device 11 (m is a natural number greater than or equal to 1) as the plurality of service providing devices 9-11 that provide such network services. The plurality of occupants using the automobile 2 may basically use network services provided by different service providing devices in the automobile 2 that they share. Network services include, for example, telematics services, video and audio content providing services, sales services, payment services, navigation services for route guidance and automatic driving control, information providing services for tourist destinations, search services for the World Wide Web, communication services such as telephone and conference, online driving control services for controlling the driving of the automobile 2, and other application services. When a user such as a passenger uses a network service, in many cases, the user is required to obtain account information for each network service and connect to a service providing device 9 to 11 for the network service using the account information. The service providing device 9 to 11 provides service information to the terminal connected using the account information.
[0020] FIG. 2 is an explanatory diagram of the control system 3 of the automobile 2 of FIG. The control system 3 of the automobile 2 in Figure 2 includes a vehicle ECU 21, a vehicle memory 22, a vehicle timer 23, a vehicle GNSS receiver 24, a mobile communication device 25, a short-range communication device 26, a key approach sensor 27, a door opening / closing sensor 28, an acceleration sensor 29, an in-vehicle camera 30, an occupant monitoring device 31, a vehicle display device 32, a vehicle operation device 33, a vehicle setting device 34, and a vehicle network 35 to which these are connected. It should be noted that some automobiles 2 have a control system 3 that does not include a mobile communication device 25.
[0021] The vehicle network 35 may be a wired communication network for the automobile 2 that complies with, for example, a Controller Area Network (CAN) or a Local Interconnect Network (LIN). The vehicle network 35 may also be a communication network such as a LAN, or a combination thereof. A wireless communication network may be included as part of the vehicle network 35.
[0022] The vehicle GNSS receiver 24 receives radio waves from GNSS satellites and generates the current position of the automobile 2 and the current time.
[0023] The vehicle timer 23 measures time or time. The time of the vehicle timer 23 may be calibrated by the current time of the vehicle GNSS receiver 24.
[0024] The mobile communication device 25 establishes a communication path via wireless communication with the base station 7 whose zone includes the automobile 2. This allows the mobile communication device 25 to perform data communication with the occupant information server device 4 and multiple service providing devices 9 to 11 via the base station 7 and the communication network 8. The mobile communication device 25 may directly communicate with the mobile communication device of another vehicle and establish a communication path to the base station 7 via the other vehicle. Even in this case, the mobile communication device 25 can perform data communication with the occupant information server device 4 and the plurality of service providing devices 9 to 11 through the mobile communication device of the other vehicle, the base station 7, and the communication network 8.
[0025] The key proximity sensor 27 detects, through specific short-range wireless communication, a passenger key 6 held by a passenger inside or nearby the automobile 2. The passenger key 6 has identification information that is different from that of other passenger keys 6. The identification information of the passenger key 6 can be used as the passenger's identification information. For example, when the key proximity sensor 27 detects the passenger key 6, it generates a signal to unlock the doors of the automobile 2 and outputs the signal to the vehicle network 35. This automatically unlocks the doors of the automobile 2, allowing the passenger to enter the automobile 2 by simply approaching the automobile 2, without having to unlock the doors themselves. Furthermore, when the key proximity sensor 27 no longer detects the passenger key 6 of a passenger who has exited the automobile 2, it generates a signal to lock the doors of the automobile 2 and outputs the signal to the vehicle network 35. This automatically locks the doors of the automobile 2.
[0026] The short-range communication device 26 establishes a communication path with an occupant terminal 5 carried by an occupant inside or nearby the automobile 2 via short-range wireless communication. Examples of short-range wireless communication standards include IEEE (Institute of Electrical and Electronics Engineers) 802.15.1 and IEEE 802.11 / b / g. The occupant terminal 5 may be, for example, a mobile phone terminal or a wearable terminal that can connect to a carrier's base station 7. The short-range communication device 26 detects, authenticates, and connects to the occupant terminal 5 carried by an occupant inside or nearby the automobile 2. This enables the short-range communication device 26 to perform data communication with the occupant terminal 5. An application program installed in the passenger terminal 5 for managing or using the automobile 2 may have identification information that is different from other application programs. In this case, when the passenger terminal 5 on which the application program is installed approaches the automobile 2, the short-range communication device 26 may generate a signal to unlock the doors of the automobile 2 and output it to the vehicle network 35, similar to the key approach sensor 27. Furthermore, when the passenger terminal 5 of the passenger who has exited the automobile is no longer detected, the short-range communication device 26 may generate a signal to lock the doors of the automobile 2 and output it to the vehicle network 35. This allows the doors of the automobile 2 to be locked automatically. The short-range communication device 26 may communicate with the passenger terminal 5 via a wired connection, for example, a USB cable, instead of short-range wireless communication. By connecting the passenger terminal 5 via a wired connection, such as a USB cable, the short-range communication device 26 can reliably recognize that the connected passenger terminal 5 has been brought into the automobile 2. The short-range communication device 26 is a vehicle communication device that can be connected to the passenger terminal 5 of the passenger in the automobile 2 by wire or wirelessly. For example, if the control system 3 of the automobile 2 does not have a mobile communication device 25, the short-range communication device 26 can be connected to the occupant terminal 5 that has established a communication path with the base station 7, and can perform data communication with the occupant information server device 4 and multiple service providing devices 9 to 11 instead of the mobile communication device 25.
[0027] The door opening / closing sensor 28 detects the opening and closing of a door (not shown) of the automobile 2. If the automobile 2 has multiple doors, such as a driver's door and a passenger's door, the door opening / closing sensor 28 may be provided for each door.
[0028] The acceleration sensor 29 detects the acceleration of the traveling automobile 2. The acceleration sensor 29 may also detect the speed of the automobile 2 by integrating the acceleration.
[0029] The in-vehicle camera 30 is provided in the automobile 2 to capture images of the interior of the automobile 2. The in-vehicle camera 30 may be a narrow-angle camera that can capture only the driver of the automobile 2, or a wide-angle camera that can capture the entire cabin. The wide-angle captured image may include passengers other than the driver who are inside the automobile 2, along with the driver. The image captured by the in-vehicle camera 30 includes biological information about the occupants, for example, their appearance.
[0030] The occupant monitoring device 31 detects and identifies occupants in the automobile 2 based on images captured by the in-vehicle camera 30 and monitors their condition. Occupants may fall asleep, look away, or experience abnormal heart rates while in the vehicle. The occupant monitoring device 31 may monitor biological information corresponding to these conditions in real time based on images captured by the in-vehicle camera 30. If the automobile 2 is equipped with a millimeter-wave sensor that outputs millimeter waves toward the interior of the vehicle, the occupant monitoring device 31 may use the images captured by the in-vehicle camera 30 together with the occupant detection results from the millimeter-wave sensor to detect and identify occupants in the automobile 2 and monitor their condition.
[0031] The vehicle display device 32 and the vehicle operation device 33 constitute an HMI (Human Machine Interface) for the passengers in the automobile 2. The vehicle display device 32 may be, for example, a liquid crystal monitor. The vehicle display device 32 may be arranged in front of the driver or on the center console in the passenger compartment of the automobile 2. The vehicle display device 32 displays a screen for the occupants. The display screen of the vehicle display device 32 may, for example, be a setting screen for setting the automobile 2, a navigation screen, a meter screen showing the status of the automobile 2, a connection screen for network services, a screen for providing network services, etc. The vehicle operation device 33 may be, for example, a touch panel overlaid on a liquid crystal monitor. The vehicle operation device 33 may also include, for example, buttons, a pointing device, or a keypad. When a non-contact HMI is configured, the vehicle operation device 33 may detect an operation based on the movement of the occupant in the image captured by the in-vehicle camera 30. The occupant may operate the vehicle operation device 33 to, for example, display a setting screen on the vehicle display device 32, and set an initial screen or screen transitions for the vehicle display device 32 on the setting screen. The occupant may also operate the vehicle operation device 33 to, for example, display a connection screen for a network service on the vehicle display device 32, and input account information on the connection screen.
[0032] The vehicle setting device 34 executes settings for each part of the automobile 2 according to the occupant. For example, when an occupant gets into the automobile 2 and performs a setting operation on a setting screen or the like, the vehicle setting device 34 acquires the setting information and executes the setting for the automobile 2. The vehicle setting device 34 may acquire information previously set by the occupant from the vehicle ECU 21 or the like and execute the setting for the automobile 2. Examples of settings that an occupant can set for the automobile 2 when getting into the automobile include the seat position, steering position, mirror position, display settings, operation settings, navigation settings, and driving settings.
[0033] The vehicle memory 22 stores programs and data. The data stored in the vehicle memory 22 may include various setting information set by the occupant using the vehicle operation device 33, navigation data, and the like. In this case, the vehicle memory 22 may be configured with a non-volatile memory that can retain data when not powered, such as an HDD or SSD. The vehicle memory 22 may also temporarily store communication data transmitted and received by the mobile communication device 25, the short-range communication device 26, and the like.
[0034] The vehicle ECU 21 may be, for example, a microcomputer, which reads and executes a program from the vehicle memory 22. This allows the vehicle ECU 21 to function as a control unit that controls the overall operation, including driving control, of the automobile 2. The microcomputer may have integrated therein functions such as the vehicle memory 22 and the vehicle timer 23. The vehicle ECU 21 as a control unit of the automobile 2 controls the traveling of the automobile 2, such as automatic driving. The vehicle ECU 21 may control the automobile 2 using data recorded in the vehicle memory 22. The vehicle ECU 21 may generate setting information based on setting operations performed by the occupant on the automobile 2, for example, using the vehicle display device 32 and the vehicle operation device 33, and record the information in the vehicle memory 22. In this case, the vehicle ECU 21 can read out the setting information recorded in the vehicle memory 22 and use the vehicle setting device 34 to perform setting on each part of the automobile 2. If the control system 3 of the automobile 2 does not include the vehicle setting device 34 as a setting execution module, the vehicle ECU 21 may perform setting on each part of the automobile 2 by itself. This eliminates the need for the occupant to perform setting operations by themselves every time they get in the vehicle.
[0035] FIG. 3 is an explanatory diagram of a computer device 40 that can be used as the occupant information server device 4 of FIG. The computer device 40 in FIG. 3 includes a communication device 41, a display device 42, an operation device 43, a GNSS receiver 44, a CPU 45, a timer 46, and a memory 47. The plurality of service providing devices 9 to 11 and the passenger terminal 5 in FIG. 1 may be realized by a computer device 40 similar to that in FIG.
[0036] The communication device 41 is connected to the communication network 8. The communication device 41 transmits and receives communication data of the computer device 40. The display device 42 is, for example, a liquid crystal monitor, and displays a screen to the operator of the computer device 40 . The operation device 43 is, for example, a keyboard or a pointing device, and is operated by an operator of the computer device 40 . The GNSS receiver 44 receives radio waves from GNSS satellites and generates the location where the computer device 40 is installed and the current time. The timer 46 measures time or the time of day. The time of the timer 46 may be calibrated by the current time of the GNSS receiver 44. The memory 47 is, for example, a non-volatile memory, and stores programs and data. For example, the memory 47 as the occupant information server device 4 may store programs and data for setting the automobile 2. The CPU 45 is, for example, a microcomputer, which reads and executes a program from the memory 47. This allows the CPU 45 to function as a control unit that controls the overall operation of the computer device 40.
[0037] In this way, in the automobile 2 shown in Fig. 2, when a passenger in the vehicle adjusts the seat position or the like, the settings are recorded in the vehicle memory 22, and when the passenger gets in the vehicle again, the settings can be retrieved from the vehicle memory 22 and set in the automobile 2. This allows the automobile 2 to execute settings according to the passenger. The settings according to the passenger can be used in the automobile 2. However, recent automobiles 2 are equipped with advanced mobile communication devices 25, etc., and passengers in the automobiles 2 can use telematics services, content services, sales services, etc. In such a vehicle 2, after getting into the vehicle 2, the occupant will adjust the seat position to suit their physique and perform operations to connect to various network services such as telematics services. Even if the passengers get into the car 2, they will not be able to start driving immediately. In particular, when a passenger attempts to use multiple network services while in a vehicle, the passenger must perform connection operations for each of the network services that the passenger wishes to use.
[0038] As a countermeasure to such a situation, it is conceivable that the vehicle 2 records the account information for the network service for each occupant in the vehicle memory 22 of the vehicle 2 in Figure 2, and reads this information when getting in the vehicle, and then connects to the network service using the vehicle setting device 34. When recording the setting information in this manner, the automobile 2 must identify and authenticate the occupants of the automobile 2 to prevent anyone in the automobile 2 from being able to use the setting information. By combining these technologies, the automobile 2 can identify the passengers on board using biometric authentication or other methods, obtain setting information for each passenger recorded in the automobile 2 or the passenger information server device 4, and perform the settings in the automobile 2.
[0039] However, if occupant-specific setting information recorded in the automobile 2 or the occupant information server device 4 were to be acquired and used solely based on authenticating the occupant in this manner, it may be difficult to say that sufficient security is ensured depending on the content of the setting information. For example, it is considered to be strongly required that account information for payment services used in sales services, etc., cannot be used by anyone other than the genuine occupant. If information becomes available simply by identifying and authenticating the occupant, it is difficult to say with certainty that there is little possibility that the payment service will be fraudulently acquired or used by someone else, for example, by someone impersonating another person. Occupant-specific setting information is required to have a high level of security so that it cannot be used by others. Furthermore, the automobile 2 is generally used with the equipment installed at the time of shipment. The automobile 2 does not necessarily have all of the equipment for the authentication function described above. Even if an occupant using such an automobile 2 registers his / her own occupant-specific setting information in the occupant information server device 4, the occupant cannot use the information in the automobile 2. Next, a description will be given of a measure to enhance safety while ensuring convenience in authentic use of the setting information for each occupant used in the automobile 2 in this embodiment.
[0040] FIG. 4 is an explanatory diagram of where the setting information for each occupant is recorded in the vehicle setting system 1 of the automobile 2 of FIG. 1, and a plurality of functions used in the vehicle setting system 1. In FIG. Figure 4 shows where the setting information for each occupant is recorded for multiple occupants using one automobile 2, and various functions for setting this information in the automobile 2 according to the occupants on board.
[0041] 4, first occupant information 51 and second occupant information 52 are recorded as occupant information for each of a plurality of occupants in the vehicle memory 22 of the automobile 2. In addition to this, for example, vehicle identification information 54 that differs for each automobile 2 is recorded in the vehicle memory 22. For example, the first occupant information 51 for the first occupant includes vehicle setting information that the first occupant has set for himself or herself in the automobile 2, as well as authentication information such as occupant identification information assigned to the first occupant by the occupant monitoring device 31 of the automobile 2, occupant biometric information indicating physical characteristics of the first occupant's head, etc., and identification information of the occupant terminal 5 used by the first occupant (hereinafter referred to as occupant terminal information). Occupant information for other occupants, such as second occupant information 52 for a second occupant, also includes vehicle setting information, occupant identification information, occupant biometric information, and occupant terminal information. By recording the vehicle setting information for each occupant using the automobile 2 in the vehicle memory 22 of the automobile 2 in this way, the automobile 2 can execute setting control according to the occupant riding in the automobile 2 even in a situation where communication with the outside is not possible. The vehicle memory 22 serves as a vehicle recording unit and records the setting information for each occupant riding in the automobile 2 in the occupant information for each of a plurality of occupants.
[0042] First occupant information 56 and second occupant information 57 are recorded as occupant information for each of a plurality of occupants in the memory 47 of the occupant information server device 4. The occupant information for each occupant may be generated and recorded in the memory 47, for example, by a user as an occupant directly logging in to the occupant information server device 4 using account information. For example, the first occupant information 56 for the first occupant initially registers account information used by the first occupant when directly accessing the occupant information server device 4. The first occupant information 56 may further register, through an occupant registration operation or the like, occupant-specific setting information such as payment account information, first service account information, and second service account information used by the first occupant, as well as occupant identification information for the first occupant, occupant biometric information for the first occupant, and vehicle identification information for the automobile 2 used by the first occupant. The first service account information corresponds to the service authentication information 63 of the first occupant recorded in the memory 47 of the first service providing device 9 for authenticating the first occupant. The second service account information corresponds to the service authentication information 62 of the first occupant recorded in the memory 47 of the second service providing device 10 for authenticating the first occupant. The first occupant information 56 may also include occupant-specific vehicle setting information such as the seat position of the automobile 2. Occupant information for other occupants, such as second occupant information 57 for the second occupant, may also include occupant-specific setting information, account information, occupant identification information, occupant biometric information, and vehicle identification information. Occupant information for other occupants may include occupant-specific vehicle setting information, such as the seat position of the automobile 2. Here, the memory 47 of the mth service providing device 11 stores service authentication information 61 of the second occupant for authenticating the second occupant. In this case, the occupant-specific setting information of the second occupant information may include mth service account information corresponding to the service authentication information 61 of the nth occupant of the mth service providing device 11. Based on the authentication, the mth service providing device 11 provides service information to the second occupant, but does not provide service information to, for example, the first occupant. The first occupant does not use the service of the mth service providing device 11. In this way, the memory 47 of the occupant information server device 4 stores, in association with the occupant-specific setting information for each occupant riding in the automobile 2, the combination information of the occupant's identification information and the automobile 2's identification information, as well as the occupant's own account information for authenticating access to the occupant information server device 4 itself.
[0043] Here, the vehicle setting information recorded in the memory 47 of the occupant information server device 4 may match the vehicle identification information recorded in the vehicle memory 22 of the automobile 2. The occupant identification information and occupant biometric information recorded for each occupant in the memory 47 of the occupant information server device 4 for authentication may correspond to the occupant identification information and occupant biometric information recorded for each occupant in the vehicle memory 22 of the automobile 2. When authentication is performed based on a match between the occupant identification information and the occupant biometric information, these pieces of information match. In this case, the occupant biometric information functions as a password. In this way, the memory 47 of the occupant information server device 4 serves as a server recording unit of the server device and records the setting information for each occupant who gets into the automobile 2 in the occupant information for each of the multiple occupants. Furthermore, the vehicle setting information for each occupant that can be recorded in the first occupant information 56, the second occupant information 57, etc. in the memory 47 of the occupant information server device 4 basically only needs to match the vehicle setting information for each occupant for the corresponding occupant in the vehicle memory 22 of the automobile 2, but may also be different from the vehicle memory 22. Such different vehicle setting information may be, for example, vehicle setting information recommended for each occupant based on statistical data on the occupant's physique, age, etc.
[0044] When an occupant accesses the occupant information server device 4 from the occupant terminal 4, the occupant's account information 59 is recorded in the memory of the occupant terminal 4. This account information 59 may be managed by an application program installed on the occupant terminal 4 for managing or using the automobile 2.
[0045] 4, the vehicle setting system 1 mainly implements a biometric authentication unit 71, a device authentication unit 72, a media connection unit 73, a combination authentication unit 74, and a setting unit 75 by executing a program in each device. In this embodiment, of these multiple functions, the biometric authentication unit 71, the device authentication unit 72, the media connection unit 73, and the setting unit 75 are implemented by the vehicle ECU 21 of the control system 3 of the automobile 2. The remaining function, the combination authentication unit 74, is implemented by the CPU 45 of the occupant information server device 4. The multiple functions of the vehicle setting system 1 may be appropriately allocated between the vehicle ECU 21 of the control system 3 of the automobile 2 and the CPU 45 of the occupant information server device 4 depending on the system specifications, design concept, etc.
[0046] The biometric authentication unit 71 performs biometric authentication on occupants riding in the automobile 2. The biometric authentication unit 71 acquires captured images of occupants riding in the automobile 2, for example, using the in-vehicle camera 30 of the automobile 2, extracts physical features of the occupants' heads and the like contained in the acquired information, and compares the extracted images with occupant biometric information of multiple occupants pre-registered in the vehicle memory 22. The occupant biometric information registered in the vehicle memory 22 may be, for example, a captured image of the occupant's face when registering the occupant in the automobile 2. The captured image may include information such as facial features and head vein patterns. If there is occupant biometric information that matches the captured image of an occupant riding in the automobile 2 to a certain degree or higher, the biometric authentication unit 71 authenticates the occupant whose occupant biometric information is contained in the occupant information as an occupant riding in the automobile 2. When the occupant biometric information of multiple occupants recorded in the vehicle memory 22 is the vein pattern of each occupant's head or part thereof, the biometric authentication unit 71 is less susceptible to the influence of differences in head orientation, and is more likely to correctly authenticate the occupants in the automobile 2. Then, the biometric authentication unit 71 outputs the biometric authentication results for the occupants in the automobile 2 to the media connection unit 73. In this way, the biometric authentication unit 71 serves as an authentication unit that authenticates only the occupant, and authenticates the occupant who is riding in the vehicle.
[0047] The device authentication unit 72 authenticates devices carried by occupants aboard the automobile 2. The device authentication unit 72 acquires, for example, identification information of the occupant terminal 5 to which the short-range communication device 26 is connected via wireless communication, for example, using the short-range communication device 26 or the key proximity sensor 27 of the automobile 2, and compares the acquired information with the occupant terminal information of multiple occupants recorded in the vehicle memory 22. If the identification information of the occupant terminal 5 matches the occupant terminal information, the device authentication unit 72 may authenticate the occupant whose occupant terminal information is included in the occupant information as a occupant aboard the automobile 2. In this case, the device authentication unit 72 may determine whether the occupant terminal 5 is located inside the automobile based on information such as the communication response speed between the short-range communication device 26 and the occupant terminal 5, and may authenticate only the occupant terminal 5 located inside the automobile as a occupant aboard the automobile 2. The device authentication unit 72 then outputs the device authentication result for the occupant terminal 5 of the occupant aboard the automobile 2 to the media connection unit 73. In this way, the device authentication unit 72 may be an authentication unit that authenticates only the occupant, and authenticates the occupant riding in the vehicle.
[0048] The media connection unit 73 uses the mobile communication device 25 to connect the automobile 2 to various server devices connected to the communication network 8, and executes communication with the server devices. The media connection unit 73 uses, for example, the mobile communication device 25 to connect the automobile 2 to the occupant information server device 4, etc., and executes data communication with the occupant information server device 4. The media connection unit 73 may connect the automobile 2 to the occupant information server device 4, for example, when a biometric authentication result indicating that authentication has been performed is obtained from the biometric authentication unit 71. The media connection unit 73 obtains, for example, from the vehicle memory 22 of the automobile 2, information necessary for connection authentication by the CPU 45 of the occupant information server device 4 for the occupants on board, and transmits the information to the combination authentication unit 74 of the media connection unit 73.
[0049] The combination authentication unit 74 authenticates the combination of the occupants aboard the automobile 2 and the automobile 2. For example, the combination authentication unit 74 compares information transmitted from the media connection unit 73 of the automobile 2 for connection authentication with information recorded in the memory 47 of the occupant information server device 4 for connection authentication of multiple occupants. The information transmitted from the automobile 2 for connection authentication may include, for example, captured images of the occupants aboard the automobile 2 or biometric information of the occupants based thereon, and the automobile's vehicle identification information. The combination authentication unit 74 approves the connection if all the transmitted information matches, and does not approve the connection otherwise. If the combination authentication unit 74 approves the connection, it notifies the setting unit 75 of the connection approval via the media connection unit 73 of the automobile 2. Here, the information that the media connection unit 73 transmits to the occupant information server device 4 for connection authentication is generally considered to be the occupant identification information and password of the occupant who has been biometrically authenticated or device authenticated. However, in this embodiment, the vehicle identification information 54 of the approved vehicle 2 is also transmitted as information required for connection authentication. This allows the combination authentication unit 74 of the occupant information server device 4 to not only authenticate that the connection is for a registered, authorized occupant, but also authenticate that the authorized occupant is attempting to connect from the authorized vehicle 2. The occupant information server device 4 can authenticate the combination of the authorized occupant and the authorized vehicle 2 using the combination authentication unit 74. Furthermore, the occupant information server device 4 can authenticate that the connection is from the correct, authorized vehicle 2 according to the vehicle identification information 54. Even if an authorized occupant attempts connection authentication via an unregistered route from a vehicle 2 with vehicle identification information that is not registered in the occupant information 56, 57 recorded in the memory 47 of the occupant information server device 4, the authorized occupant will not be authenticated by the occupant information server device 4, as in the case of other occupants. The occupant information 56, 57 for each occupant registered in the memory 47 of the occupant information server device 4 is not inadvertently transmitted to the vehicle 2 and leaked even during legitimate processing, and is permitted to be used only within the limited range of the vehicle 2 in which it is registered together with the occupant. Note that the occupant information 56, 57 for each occupant may also register vehicle identification information for multiple vehicles 2 used by each occupant. In this way, the combination authentication unit 74 can authenticate the combination of an occupant authenticated by an authentication unit that authenticates only the occupant and the vehicle that authenticated the occupant.
[0050] The setting unit 75 executes settings for the automobile 2 according to the occupants aboard the automobile. The settings for the automobile 2 may include, for example, settings for the occupants to use while driving, such as seat position, as illustrated in FIG. 2, and settings for network services used by the occupants in the automobile 2. When the setting unit 75 obtains connection approval through combination authentication from the combination authentication unit 74, it receives and obtains occupant-specific setting information for the occupant whose combination has been authenticated from the occupant information 56, 57 recorded in the memory 47 of the occupant information server device 4. The occupant-specific setting information obtained from the occupant information server device 4 may include, for example, account information for network services. In addition to this, the occupant-specific setting information obtained from the occupant information server device 4 may include, for example, vehicle setting information. In addition, when the setting unit 75 obtains connection approval from the combination authentication unit 74, or when the occupant is authenticated by the device authentication unit 72 or the biometric authentication unit 71, it obtains occupant-specific setting information for the occupant related to the approval from the occupant information 51, 52 recorded in the vehicle memory 22 of the automobile 2. Then, based on the acquired setting information, the setting unit 75 uses the vehicle setting device 34 to set each part of the automobile 2. The setting unit 75 sets, for example, the seat position, steering position, mirror position, display settings, operation settings, navigation settings, driving settings, etc. This allows the passengers in the automobile 2 to have an optimal riding environment, and for example, they can operate the steering wheel while seated in an optimal position. Furthermore, if account information for a network service has been acquired as setting information for each occupant, the setting unit 75 causes the media connection unit 73 to execute a connection to a service providing device that provides that network service. Based on a connection instruction from the setting unit 75, the media connection unit 73 transmits the account information from the mobile communication device 25 to the service providing device. The service providing device compares the received account information with the occupant authentication information, and approves the connection if they match. By connecting the media connection unit 73 to the service providing device, the control system 3 of the automobile 2 can send and receive data to and from the service providing device that provides the network service via the mobile communication device 25. By performing such settings, the setting unit 75 can set up the automobile 2 according to the authenticated occupant and set up a connection to a network service that the authenticated occupant will use in the automobile 2. The setting unit 75 automatically performs the settings based on the authentication of the occupant riding in the automobile 2. The occupant can obtain an optimal riding environment and start driving immediately without having to operate the vehicle operation device 33 themselves.
[0051] FIG. 5 is a flowchart of setting control according to the passengers riding in the automobile 2 by the control system 3 of the automobile 2 of FIG. The vehicle ECU 21 of the control system 3 of the automobile 2 repeatedly executes the setting control of FIG. The vehicle ECU 21 can execute, for example, a plurality of functions assigned to the automobile 2 in FIG. 4 through the setting control in FIG.
[0052] In step ST1, the vehicle ECU 21 determines whether a new occupant has entered the automobile 2 or whether the automobile 2 has been started with an occupant in it. The vehicle ECU 21 may determine whether a new occupant has entered the automobile 2 based on, for example, door opening / closing detection by the door opening / closing sensor 28, new detection of the occupant terminal 5 by the short-range communication device 26, or new detection of the occupant key 6 by the key approach sensor 27.
[0053] In step ST2, the vehicle ECU 21 uses the mobile communication device 25 to inquire about the registration status of the occupant information server device 4, and acquires from the occupant information server device 4 whether or not the vehicle itself has server registration information.
[0054] In step ST3, the vehicle ECU 21 determines whether information related to the vehicle is registered in the server registration information acquired from the occupant information server device 4. If information related to the vehicle is registered in the occupant information server device 4, the vehicle ECU 21 proceeds to step ST4. If information related to the vehicle is not registered in the occupant information server device 4, the vehicle ECU 21 proceeds to step ST19.
[0055] In step ST4, the vehicle ECU 21 acquires the occupant authentication result for the occupant currently riding in the automobile 2. The biometric authentication unit 71 compares the physical characteristics of the occupants in the automobile 2 obtained from the captured image with the occupant biometric information registered in the plurality of occupant information 51, 52 in the vehicle memory 22, and determines whether the occupants in the automobile 2 are registered in the vehicle memory 22. If the occupants in the automobile 2 are registered in the vehicle memory 22, the biometric authentication unit 71 authenticates the occupants as registered. The device authentication unit 72 compares the identification information of the passenger terminal 5 or the identification information of the passenger key 6 of the passenger in the automobile 2 with the passenger terminal information registered in the plurality of passenger information 51, 52 in the vehicle memory 22, and determines whether the passenger in the automobile 2 is registered in the vehicle memory 22. If the passenger in the automobile 2 is registered in the vehicle memory 22, the device authentication unit 72 authenticates the passenger as registered. The vehicle ECU 21 may acquire the occupant authentication result for the occupant riding in the automobile 2 from the biometric authentication unit 71 and the device authentication unit 72.
[0056] In step ST5, the vehicle ECU 21 determines whether the acquired occupant authentication result includes a result of biometric authentication. If the biometric authentication unit 71 has authenticated the authenticated occupant as registered, the vehicle ECU 21 determines that the acquired occupant authentication result includes a result of biometric authentication, regardless of the authentication result of the device authentication unit 72, and proceeds to step ST6. If the biometric authentication unit 71 has not authenticated the authenticated occupant as registered, the vehicle ECU 21 determines that the acquired occupant authentication result does not include a result of biometric authentication, and proceeds to step ST17.
[0057] In step ST6, the vehicle ECU 21 acquires new biometric information about the biometrically authenticated occupant from the occupant monitoring device 31 or the in-vehicle camera 30, which serves as a biometric information acquisition unit that acquires the biometric information of the occupant currently riding in the vehicle. The biometric information acquired by the vehicle ECU 21 in step ST6 is different from the biometric information obtained as the result of the biometric authentication in step ST4. The biometric information in step ST6 is an image captured by the in-vehicle camera 30 at a timing later than the biometric information in step ST4, or biometric information generated by the occupant monitoring device 31 for an image captured at a timing later. By using two-step authentication based on different biometric information, the accuracy of the biometric authentication can be improved.
[0058] In step ST7, the vehicle ECU 21 acquires the occupant identification information of the occupant who has been biometrically authenticated from the occupant information 51, 52 in the vehicle memory 22.
[0059] In step ST8, the vehicle ECU 21 acquires the vehicle identification information 54 of the vehicle itself from the vehicle memory 22.
[0060] In step ST9, the vehicle ECU 21 determines whether the short-range communication device 26 is connected to the passenger terminal 5 of the passenger in the automobile 2. If the short-range communication device 26 is connected to the occupant terminal 5, the vehicle ECU 21 proceeds to step ST10. If the short-range communication device 26 is not connected to the occupant terminal 5, the vehicle ECU 21 proceeds to step ST11.
[0061] In step ST10, the vehicle ECU 21 acquires, from the occupant terminal 5 to which the short-range communication device 26 is connected, the account information 59 of the occupant who accessed the occupant information server device 4 using the occupant terminal 5.
[0062] In step ST11, the vehicle ECU 21 transmits the combination information of the occupant and the automobile 2 acquired in steps ST7 to ST10 to the automobile 2 via the mobile communication device 25, the base station 7, and the communication network 8 to the automobile information server device 4. The combination authentication unit 74 of the automobile information server device 4 compares the received combination information with the combinations of multiple pieces of occupant information 56, 57 registered in the memory 47 of the automobile information server device 4. If the received combination information is registered in the memory 47 of the automobile information server device 4, the combination authentication unit 74 of the automobile information server device 4 authenticates it and transmits the authentication result of the combination to the automobile 2 via the communication device 41, the base station 7, and the communication network 8.
[0063] In step ST12, the vehicle ECU 21 receives and acquires the authentication result by the combination authentication unit 74 regarding the combination information of the occupant and the automobile 2 from the occupant information server device 4 via the mobile communication device 25.
[0064] In step ST13, the vehicle ECU 21 determines whether the combination included in the combination information between the occupant and the vehicle 2 has been authenticated by the combination authentication unit 74 in the occupant information server device 4. If the combination has been authenticated in the occupant information server device 4, the vehicle ECU 21 proceeds to step ST14. If the combination has not been authenticated in the occupant information server device 4, the vehicle ECU 21 proceeds to step ST17.
[0065] In step ST14, the vehicle ECU 21 acquires occupant-specific setting information for the authenticated occupant from the plurality of occupant information 56, 57 in the memory 47 of the occupant information server device 4 and the plurality of occupant information 51, 52 in the vehicle memory 22 of the vehicle itself. The vehicle ECU 21 uses the mobile communication device 25 to request the occupant information server device 4 to transmit setting information, and receives and acquires the occupant-specific setting information for the occupant whose combination has been authenticated from the occupant information server device 4. The vehicle ECU 21 reads and acquires the occupant-specific setting information for the authenticated occupant from the vehicle memory 22. Here, the vehicle ECU 21 may, for example, acquire occupant-specific setting information for the occupant whose combination has been authenticated mainly from the memory 47 of the occupant information server device 4. Then, if the setting information acquired from the memory 47 of the occupant information server device 4 does not include vehicle setting information, the vehicle ECU 21 may acquire occupant-specific setting information from the multiple pieces of occupant information 51, 52 in the vehicle memory 22 of the vehicle itself. In this case, the vehicle ECU 21 acquires occupant-specific setting information for the occupant whose combination has been authenticated from at least the memory 47 of the occupant information server device 4 out of the memory 47 of the occupant information server device 4 and the vehicle memory 22 of the automobile 2.
[0066] In step ST15, the vehicle ECU 21 executes settings for the vehicle based on the vehicle setting information included in the acquired occupant-specific setting information, using the vehicle setting device 34. As a result, the seat position of the authenticated occupant, etc., can be set to correspond to the vehicle setting information.
[0067] In step ST16, the vehicle ECU 21 connects the vehicle to the network service via the mobile communication device 25, using the account information for the network service included in the acquired occupant-specific setting information. As a result, the vehicle ECU 21 is connected to a service providing device that provides the network service via the mobile communication device 25, and becomes able to receive service information from the service providing device. Thereafter, the vehicle ECU 21 ends this control.
[0068] In step ST17, since the combination has not been authenticated by the combination authentication unit 74 of the occupant information server device 4, the vehicle ECU 21 stops acquiring information from the occupant information server device 4 and acquires occupant-specific setting information for the authenticated occupants from the multiple occupant information 51, 52 in the vehicle memory 22 of the vehicle itself. In this case, authentication is performed only by either the biometric authentication unit 71 or the device authentication unit 72. When the vehicle ECU 21 has been authenticated by at least one of the biometric authentication unit 71 and the device authentication unit 72, it may acquire occupant-specific setting information for the occupant related to that authentication.
[0069] In step ST18, the vehicle ECU 21 executes the setting of the vehicle based on the vehicle setting information included in the setting information for each occupant acquired from the vehicle memory 22. As a result, the seat position of the authenticated occupant, etc., can be set to correspond to the vehicle setting information. After that, the vehicle ECU 21 ends this control.
[0070] In step ST19, the vehicle ECU 21 acquires the occupant authentication result for the occupant currently riding in the automobile 2. In this case, since information related to the vehicle is not registered in the occupant information server device 4, the vehicle ECU 21, unlike step ST4, acquires only the biometric authentication result from the biometric authentication unit 71 from the authentication result from the biometric authentication unit 71 and the authentication result from the device authentication unit 72. Thereafter, the vehicle ECU 21 proceeds to step ST17. The vehicle ECU 21 acquires occupant-specific setting information for the biometrically authenticated occupants from the plurality of occupant information 51, 52 stored in the vehicle memory 22 of the host vehicle, and executes setting for the host vehicle based on the acquired vehicle setting information. Thereafter, the vehicle ECU 21 ends this control.
[0071] 5, when an occupant is biometrically authenticated by the biometric authentication unit 71, the vehicle ECU 21 transmits combination information between the occupant and the vehicle 2 to the occupant information server device 4. The combination authentication unit 74 of the occupant information server device 4 authenticates the combination of the occupant and the vehicle 2, for example, by combining occupant identification information about the occupant biometrically authenticated by the biometric authentication unit 71 and vehicle identification information about the authenticated vehicle 2. Furthermore, when the vehicle occupant has not been biometrically authenticated by the biometric authentication unit 71, the combination authentication unit 74 does not obtain the combination information between the occupant and the vehicle 2 and therefore does not perform the authentication. It should be noted that two-stage authentication of the occupants of the automobile 2 can be performed without the processes from step ST1 to step ST3 described above. In addition, instead of processing steps ST1 to ST3, the vehicle ECU 21 may, for example, determine whether or not connection information to the occupant information server device 4 is present in the vehicle memory 22, and if the connection information is present, proceed to step ST4, or if the connection information is not present, proceed to step ST19.
[0072] FIG. 6 is a timing chart of setting control when an occupant undergoes two-stage authentication in the vehicle setting system 1 of the automobile 2 of FIG. The timing chart of the setting control in FIG. 6 is an example in which the occupant in the automobile 2 has been biometrically authenticated. 6 shows a biometric authentication unit 71, a device authentication unit 72, a media connection unit 73, and a setting unit 75, which are implemented in the vehicle ECU 21 of the automobile 2, as well as a combination authentication unit 74, which is implemented in the CPU 45 of the occupant information server device 4. In FIG. 6, time flows from top to bottom. The following describes an example of a state in which a first occupant is in the automobile 2. The following description also assumes that the vehicle ECU 21 of the automobile 2 mainly functions as the media connection unit 73 and executes the setting process of FIG.
[0073] 5 , the vehicle ECU 21 serving as the media connection unit 73 of the automobile 2 acquires the occupant authentication result from the biometric authentication unit 71 and the occupant authentication result from the device authentication unit 72 for the first occupant in the automobile 2, and determines in step ST5 that the biometric authentication result is included. In this case, the vehicle ECU 21 serving as the media connection unit 73 acquires the occupant identification information, new biometric information, account information 59, and vehicle identification information 54 for the first occupant in the automobile 2 from the first occupant information 51 in the vehicle memory 22 in steps ST6 to ST11, and transmits them to the occupant information server device 4. When the communication device 41 of the occupant information server device 4 receives the combination information, the combination authentication unit 74 compares the received combination information with the multiple occupant information 56, 57 in the memory 47 of the occupant information server device 4 in step ST20 and authenticates the combination. The combination authentication unit 74 authenticates the combination based on biometric information obtained at a timing different from the biometric information used for authentication by the biometric authentication unit 71. Thereafter, the combination authentication unit 74 transmits an authentication result of the combination indicating that the first occupant is a registered occupant to the setting unit 75 of the automobile 2. The authentication result is transmitted from the communication device 41 of the occupant information server device 4 to the automobile 2 via the communication network 8 and the base station 7.
[0074] In the automobile 2, in step ST12, the vehicle ECU 21 serving as the media connection unit 73 receives the authentication result by the combination authentication unit 74 regarding the combination information of the occupant and the automobile 2 from the occupant information server device 4 via the mobile communication device 25. The vehicle ECU 21 serving as the media connection unit 73 of the automobile 2 instructs the setting unit 75 to perform setting. In steps ST14 to ST16, the vehicle ECU 21 serving as the setting unit 75 acquires occupant-specific setting information for the first occupant from the plurality of pieces of occupant information 56, 57 in the occupant information server device 4 and the plurality of pieces of occupant information 51, 52 in the vehicle memory 22, sets the information in the host vehicle, and connects to the network service. In this case, even if the setting unit 75 has acquired various settings for vehicle setting information for each occupant from the occupant information server device 4, the setting unit 75 may prioritize the corresponding settings in the vehicle memory 22 and set them in the vehicle. Furthermore, if the setting unit 75 is unable to acquire settings from the vehicle memory 22, the setting unit 75 may acquire vehicle setting information from the occupant information server device 4 and set them in the vehicle.
[0075] In this way, when the combination of the first occupant and the automobile 2 is authenticated by the combination authentication unit 74, the setting unit 75 can obtain occupant-specific setting information 56 for the first occupant from multiple occupant information 56, 57 in the memory 47 (server recording unit) of the occupant information server device 4, and perform the setting in the vehicle. For example, if the occupant-specific setting information 56 for the first occupant recorded in the memory 47 of the occupant information server device 4 includes the occupant's vehicle setting information to be set in the automobile 2 according to the occupant, and the combination is authenticated, the setting unit 75 can perform setting in the automobile 2 using the vehicle setting information recorded in the memory 47 of the occupant information server device 4. In addition, for example, if the occupant-specific setting information 56 for the first occupant recorded in the memory 47 of the occupant information server device 4 includes account information for a network service that the occupant can use in the automobile 2 and the combination is authenticated, the setting unit 75 can connect the automobile 2 to the network service using the account information for the network service from the memory 47 of the occupant information server device 4.
[0076] In addition, when the first occupant is biometrically authenticated by the biometric authentication unit 71 of the automobile 2 and the combination of the first occupant and the automobile 2 is further authenticated by the combination authentication unit 74, the setting unit 75 can obtain vehicle setting information of the first occupant from the multiple occupant information 56, 57 in the memory 47 of the occupant information server device 4 and the multiple occupant information 51, 52 in the vehicle memory 22 as a vehicle recording unit, and perform setting on the automobile 2. In addition, if the first occupant is authenticated by the biometric authentication unit 71 but the combination of the first occupant and the automobile 2 is not authenticated by the combination authentication unit 74, the setting unit 75 can obtain the vehicle setting information of the first occupant only from the multiple occupant information 51, 52 in the vehicle memory 22 as a vehicle recording unit and perform setting on the automobile 2.
[0077] FIG. 7 is a flowchart of authentication control for a combination of an occupant riding in the automobile 2 and the automobile 2, performed by the occupant information server device 4 of FIG. The vehicle ECU 21 of the automobile 2 transmits to the occupant information server device 4 the combined authentication information including the information acquired in steps ST6 to ST10 of FIG. When the communication device 41 receives new combination authentication information from the automobile 2, the CPU 45 of the occupant information server device 4 executes the combination authentication control of FIG. 7 as the process of the combination authentication unit 74 in step ST20 of FIG. The CPU 45 of the occupant information server device 4, as the combination authentication unit 74, acquires the occupant's biometric information authenticated by the biometric authentication unit 71, the vehicle identification information of the automobile 2 in which the occupant is riding, and the occupant's account information 59 of the occupant terminal 5 connected to the automobile 2, and performs authentication control for the combination of the occupant and the automobile 2. Here, the occupant's account information 59 is generated in the occupant terminal 5 based on the occupant's operation so that the occupant can access the occupant information server device 4 using the occupant terminal 5. In this case, the occupant terminal 5 can access the occupant information server device 4 without being authenticated by the biometric authentication unit 71 and the combination authentication unit 74.
[0078] In step ST21, the CPU 45 as the combination authentication unit 74 determines whether or not new combination authentication information has been received from the automobile 2. If new combination authentication information has not been received from the automobile 2, the CPU 45 repeats this process. If new combination authentication information has been received from the automobile 2, the CPU 45 proceeds to step ST22.
[0079] In step ST22, the CPU 45 determines whether or not biometric information for authenticating the occupant is received in the received combined authentication information. If biometric information is received, the CPU 45 proceeds to step ST24. If biometric information is not received, the CPU 45 proceeds to step ST23.
[0080] In step ST23, the CPU 45 determines whether account information for authenticating the occupant is received in the received combined authentication information. The account information here may be generated in the occupant terminal 5 based on an occupant's operation to access the occupant information server device 4 using the occupant terminal 5, and then acquired and transmitted, for example, by the vehicle ECU 21. If account information has been received, the CPU 45 proceeds to step ST33. If account information has not been received, the CPU 45 proceeds to step ST30 because information that can be used to authenticate the occupant has not been obtained.
[0081] In step ST24, the CPU 45 compares the received occupant biometric information with the occupant biometric information of a plurality of occupants registered in the memory 47.
[0082] In step ST25, the CPU 45 determines whether or not occupant biometric information matching the received occupant biometric information is registered in the memory 47. If matching occupant biometric information is registered in the memory 47, the CPU 45 proceeds to step ST26. If matching occupant biometric information is not registered in the memory 47, the CPU 45 proceeds to step ST32.
[0083] In step ST26, the CPU 45 determines that the occupant can be authenticated, and starts a process of authenticating the combination of the occupant and the automobile 2.
[0084] In step ST27, the CPU 45 compares the vehicle identification information included in the received combined authentication information with the vehicle identification information included in the setting information for the occupant who has been registered in the memory 47 and who has been approved for authentication.
[0085] In step ST28, the CPU 45 determines whether the compared vehicle identification information matches. If the compared vehicle identification information matches, the CPU 45 proceeds to step ST29. If the compared vehicle identification information does not match, the CPU 45 proceeds to step ST30.
[0086] In step ST29, the CPU 45 authenticates the occupant and the automobile 2 included in the received combination authentication information as matching the combination pre-registered in the memory 47. Thereafter, the CPU 45 advances the process to step ST31.
[0087] In step ST30, the CPU 45 authenticates the occupant and the automobile 2 included in the received combination authentication information as not matching the combination registered in advance in the memory 47 (non-authentication).
[0088] In step ST31, the CPU 45 transmits the authentication result of the combination of the occupant and the automobile 2 to the automobile 2.
[0089] Step ST32 is a process that is executed, for example, when matching occupant biometric information is not registered in memory 47 in step ST25. The CPU 45 determines that the occupant cannot be authenticated and proceeds to step ST30. In this case, the combined authentication process of the occupant and the vehicle 2 from steps ST27 to ST28 is not executed. The CPU 45 rejects authentication of the occupant and the vehicle 2 included in the combined authentication information received in step ST30, and transmits a combined authentication result of rejection to the vehicle 2 in step ST31.
[0090] Step ST33 is a process executed when it is determined that the combined authentication information received in step ST23 includes account information. The CPU 45 compares the received occupant account information with the account information of multiple occupants registered in the memory 47.
[0091] In step ST34, the CPU 45 determines whether or not account information that matches the received occupant account information is registered in the memory 47. If matching account information is registered in the memory 47, the CPU 45 proceeds to step ST26. The CPU 45 executes the combined authentication process between the occupant and the vehicle 2 from steps ST27 to ST28, and transmits the combined authentication result to the vehicle 2. If matching account information is not registered in the memory 47, the CPU 45 proceeds to step ST32. The CPU 45 transmits a combination authentication result indicating authentication failure to the vehicle 2 without executing the combination authentication process between the occupant and the vehicle 2 from step ST27 to ST28.
[0092] In this way, when an occupant terminal 5 is connected to a short-range communication device 26 as a communication vehicle device, the CPU 45 as the second authentication unit or combination authentication unit 74 can obtain account information for access authentication to the occupant information server device 4 itself, which is stored in the occupant terminal 5 connected to the short-range communication device 26, along with occupant information from the automobile 2 and information about the automobile 2, and can authenticate the combination of the occupant in the automobile 2 and the automobile 2 in which they are riding. In this case, if the account information held in the occupant terminal 5 matches the account information recorded in the memory 47 of the occupant information server device 4, and further, the vehicle identification information associated with the matching account information matches the identification information obtained from the automobile 2, the CPU 45 authenticates the combination of the occupant riding in the automobile 2 and the automobile 2 they are riding in by combining the occupant terminal 5 and the automobile 2. Therefore, even if the CPU 45 cannot authenticate the combination of the occupant and the vehicle 2 using the occupant information authenticated by the biometric authentication unit 71 obtained from the vehicle 2 and the information about the vehicle 2, it can authenticate the combination of the occupant in the vehicle 2 and the vehicle 2 they are riding in using the combination of the occupant's own account information stored on the occupant's terminal 5. Furthermore, if the occupant terminal 5 of an occupant who is recognized as riding in the vehicle 2 with the occupant does not originally hold the occupant's account information for access authentication to the occupant information server device 4 itself, the CPU 45 cannot authenticate the combination of the occupant and the vehicle 2 based on the account information held on the occupant terminal 5.
[0093] As described above, in this embodiment, in order for a passenger in the vehicle 2 to set and use his / her occupant-specific setting information in the vehicle 2, the passenger must be authenticated by the biometric authentication unit 71, and the combination of the passenger and the vehicle 2 must be authenticated by the combination authentication unit 74. By using such multi-factor and multi-stage authentication that is not based solely on the authentication of the passenger, the security of the occupant-specific setting information recorded in the memory 47 of the occupant information server device 4 is enhanced. Furthermore, the combination authentication unit 74 authenticates at least the combination of the passenger authenticated by the biometric authentication unit 71 and the vehicle 2 in which the passenger is riding, and therefore can also authenticate the authenticity of the routing from the vehicle 2 to the occupant information server device 4. The combination authentication unit 74 of this embodiment is considered to make it more difficult for the occupant-specific setting information of the occupant information server device 4 to be fraudulently acquired or used, compared to, for example, a case in which the occupant information server device 4 authenticates the vehicle 2 based on authentication of the passenger by the biometric authentication unit 71. The security of the occupant-specific setting information of the occupant information server device 4 is enhanced. Moreover, in this embodiment, the combination authentication unit 74 in the occupant information server device 4, which authenticates the combination of the occupant riding in the vehicle 2 and the vehicle 2 they are riding in, can authenticate the combination of the occupant riding in the vehicle 2 and the vehicle 2 they are riding in, by combining the occupant's own account information stored in the occupant's occupant terminal 5 and the vehicle 2, even if it is not possible to authenticate the combination of the occupant and the vehicle 2 using the occupant's information authenticated by the biometric authentication unit 71 obtained from the vehicle 2 and the information of the vehicle 2. As a result, even if the occupant riding in the vehicle 2 cannot receive combination authentication using the occupant information and information of the vehicle 2 that can be obtained from the vehicle 2 due to, for example, the functions of the vehicle 2, the occupant can receive combination authentication by the combination authentication unit 74 by accessing the occupant information server device 4 with the occupant terminal 5 that he or she possesses. Then, by obtaining combined authentication between the occupant terminal 5 and the automobile 2, which is replaced with occupant information obtained from the automobile 2, the setting unit 75 of the automobile 2 can obtain setting information for each occupant currently riding in the automobile 2 from the memory 47 of the occupant information server device 4 and set it in the automobile 2. In this way, in this embodiment, it is possible to improve safety while ensuring convenience in authentic use of the setting information for each occupant used in the automobile 2.
[0094] The above-described embodiment is an example of a preferred embodiment of the present invention, but the present invention is not limited to this, and various modifications and changes are possible within the scope of the gist of the invention.
[0095] For example, in the above-described embodiment, the automobile 2 is provided with a setting unit 75 that executes settings to make settings appropriate for the occupants available in the automobile 2, as well as a biometric authentication unit 71 that authenticates the occupants in the automobile 2. In addition to this, for example, the automobile 2 may be provided with a setting unit 75, a biometric authentication unit 71, and a combination authentication unit 74 that authenticates the combination of the occupant authenticated by the biometric authentication unit 71 and the automobile 2 in which they are riding. The biometric authentication unit 71 may also be realized in the occupant information server device 4. [Explanation of symbols]
[0096] 1...vehicle setting system, 2...automobile (vehicle), 3...control system, 4...occupant information server device (server device), 5...occupant terminal, 6...occupant key, 7...base station, 8...communication network, 9...first service providing device, 10...second service providing device, 11...mth service providing device, 21...vehicle ECU, 22...vehicle memory, 23...vehicle timer, 24...vehicle GNSS receiver, 25...mobile communication device, 26...short-range communication device (vehicle communication device), 27...key approach sensor, 28...door opening / closing sensor, 29...acceleration sensor, 30...in-vehicle camera (biometric information acquisition unit), 31...occupant monitoring device (biometric information acquisition unit), 32...vehicle display device, 33...vehicle operation device, 34 ...Vehicle setting device, 35...Vehicle network, 40...Computer device, 41...Communication device, 42...Display device, 43...Operation device, 44...GNSS receiver, 45...CPU, 46...Timer, 47...Memory (server recording unit), 51...First occupant setting information, 52...Second occupant setting information, 54...Vehicle identification information, 56...First occupant setting information, 57...Second occupant setting information, 61...Second occupant service authentication information, 62...First occupant service authentication information, 63...First occupant service authentication information, 71...Biometric authentication unit (first authentication unit), 72...Device authentication unit, 73...Media connection unit, 74...Combined authentication unit (second authentication unit), 75...Setting unit
Claims
1. A vehicle setting system according to an occupant, comprising: a setting unit that executes setting of the vehicle so that a setting according to the occupant can be used in the vehicle; a server device having a server recording unit that records occupant-specific setting information for occupants riding in the vehicle; a first authentication unit in the vehicle that authenticates a passenger in the vehicle; a second authentication unit in the server device that, when an occupant riding in the vehicle has been authenticated by the first authentication unit, acquires information about the occupant and identification information of the vehicle from the vehicle and authenticates a combination of the occupant and the vehicle; and The second authentication unit Even if the combination of the occupant and the vehicle cannot be authenticated using the occupant information and the vehicle identification information acquired from the vehicle, the occupant terminal of the occupant riding in the vehicle authenticates the combination of the occupant and the vehicle using a combination of the occupant's account information and the vehicle identification information that are held in order to access the server device. Vehicle configuration system tailored to the occupant.
2. The second authentication unit If the occupant terminal of the occupant does not hold occupant account information for access authentication to the server device, the combination of the occupant and the vehicle using the account information is not authenticated. The vehicle occupant-dependent setting system according to claim 1.
3. the server recording unit of the server device associates and records the combination information of the identification information of the occupant and the identification information of the vehicle by the second authentication unit with the setting information for each occupant riding in the vehicle, and the account information of the occupant for access authentication to the server device; The second authentication unit If the account information stored in the occupant terminal of the occupant riding in the vehicle for access authentication to the server device matches the account information recorded in the server recording unit of the server device, and further, if the vehicle identification information associated with the matching account information matches the vehicle identification information acquired from the vehicle, the combination of the occupant and the vehicle is authenticated.
3. The vehicle setting system according to claim 1 or 2.
4. the vehicle includes a vehicle communication device connectable to the passenger terminal of the passenger riding in the vehicle; The second authentication unit When the occupant terminal is connected to the vehicle communication device, the occupant information from the vehicle and the vehicle identification information are acquired, along with the account information for access authentication to the server device, which is stored in the occupant terminal connected to the vehicle communication device, and the combination of the occupant and the vehicle is authenticated. The vehicle setting system according to any one of claims 1 to 3.
5. the vehicle communication device is connectable to the occupant terminal of the occupant by a wire; 5. The vehicle setting system according to claim 4.
6. The vehicle has at least the setting unit among the setting unit, the first authentication unit, and the second authentication unit. The vehicle occupant-dependent setting system according to any one of claims 1 to 5.
Citation Information
Patent Citations
Specific information management system
JP2004243825A
Vehicle user information management system
JP2017043268A
Authentication system and authentication device
JP2019113947A
Fleet management system
WO2016194118A1