Information processing device, information processing method, and vehicle control device

The information processing system generates digital keys with usage rules to flexibly set vehicle access, addressing the inconvenience of restrictive key management systems by allowing controlled and convenient vehicle operation.

JP7861497B2Active Publication Date: 2026-05-19SONY GROUP CORP
View PDF 10 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
SONY GROUP CORP
Filing Date
2022-05-13
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing vehicle key management systems restrict all driving functions, leading to reduced convenience.

Method used

An information processing system that generates digital keys with usage rules, allowing flexible setting of vehicle usage ranges, and transmits these keys to terminals and vehicles for controlled access and operation.

Benefits of technology

Enables flexible and convenient vehicle usage by allowing specific functions to be unlocked based on predefined rules, enhancing user experience and functionality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007861497000001
    Figure 0007861497000001
  • Figure 0007861497000002
    Figure 0007861497000002
  • Figure 0007861497000003
    Figure 0007861497000003
Patent Text Reader

Abstract

To easily and flexibly set a use range of a vehicle.SOLUTION: An information processing device comprises: a key management unit which generates a digital key for using a vehicle; a use rule management unit which sets a use rule indicating a use range of the vehicle to the digital key; and a communication unit which transmits the digital key to at least one of the vehicle and an information processing terminal using the digital key and transmits use rule information indicating the use rule to at least one of the vehicle and the information processing terminal. This technique can be applied to, for example, a server that manages a digital key of a vehicle.SELECTED DRAWING: Figure 8
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present technology relates to an information processing apparatus, an information processing method, And, and a vehicle control apparatus to and, in particular, to an information processing apparatus, an information processing method, And, and a vehicle control apparatus to that enable the use range of a vehicle to be set easily and flexibly.

Background Art

[0002] Conventionally, when distributing key information of a vehicle equipped with a content providing apparatus to a user's mobile terminal, it is possible to lock and unlock the vehicle and make the content providing apparatus available for the key information, but it has been proposed to add function restriction information that makes it impossible to put the vehicle in a drivable state (see, for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in the invention described in Patent Document 1, since all driving of the vehicle is restricted, convenience is reduced.

[0005] The present technology has been made in view of such a situation, and enables the use range of a vehicle to be set easily and flexibly.

Means for Solving the Problems

[0006] The first aspect of this technology is an information processing device comprising: a key management unit that generates a digital key for using a vehicle; a usage rule management unit that sets usage rules indicating the usage range of the vehicle for the digital key; and a communication unit that transmits the digital key to at least one of the vehicle and an information processing terminal that uses the digital key, and transmits usage rule information indicating the usage rules to at least one of the vehicle and the information processing terminal.

[0007] The first aspect of the information processing method of this technology involves an information processing device generating a digital key for using a vehicle, setting usage rules for the digital key that indicate the range of use of the vehicle, transmitting the digital key to at least one of the vehicle and the information processing terminal that uses the digital key, and transmitting usage rule information indicating the usage rules to at least one of the vehicle and the information processing terminal.

[0008] The second aspect of this technology is a vehicle control device which includes a key management unit that controls the range of vehicle use based on usage rules set by the information processing device that generated the digital key, in response to a digital key received from an information processing terminal.

[0009] The third aspect of this technology, the information processing terminal, includes a key management unit that acquires a digital key from an information processing device, on which usage rules indicating the vehicle's usage range are set, and a communication unit that transmits the digital key to the vehicle when the vehicle is to be used.

[0010] In the first aspect of this technology, a digital key for using a vehicle is generated, usage rules indicating the scope of use of the vehicle are set for the digital key, the digital key is transmitted to at least one of the vehicle and the information processing terminal that uses the digital key, and usage rule information indicating the usage rules is transmitted to at least one of the vehicle and the information processing terminal.

[0011] In the second aspect of this technology, the usage range of a vehicle is controlled based on usage rules set by the information processing device that generated the digital key, with respect to the digital key received from the information processing terminal.

[0012] In a third aspect of this technology, a digital key with usage rules indicating the vehicle's usage range is acquired from an information processing device, and when the vehicle is to be used, the digital key is transmitted to the vehicle. [Brief explanation of the drawing]

[0013] [Figure 1] This is a block diagram showing one embodiment of an information processing system to which this technology is applied. [Figure 2] This figure shows an example of a cloud system configuration and an example of an interface between a vehicle and a mobile device. [Figure 3] This is a block diagram showing an example of a cloud system configuration. [Figure 4] This is a block diagram showing an example configuration of a vehicle control system. [Figure 5] This is a block diagram showing examples of mobile device configurations. [Figure 6] This figure shows examples of user types in an information processing system. [Figure 7] This diagram shows the relationship between user accounts, roles, and usage rules. [Figure 8] This is a flowchart to explain the share key generation process. [Figure 9] This figure shows an example of a digital key list screen. [Figure 10] This figure shows an example of a digital key list screen when no digital key exists. [Figure 11] This diagram shows an example of a digital key reset screen. [Figure 12] This diagram shows an example of the key mode settings screen for ShareKey. [Figure 13] This figure shows an example of the screen for setting the validity period of a share key. [Figure 14] It is a diagram showing an example of a screen for generating a shared key. [Figure 15] It is a diagram showing an example of a shared key provision screen. [Figure 16] It is a sequence diagram for explaining the process of registering an unregistered pair key and usage rules in a vehicle. [Figure 17] It is a sequence diagram for explaining the unlocking process of the driver's seat door handle. [Figure 18] It is a sequence diagram for explaining the unlocking process of the trunk. [Figure 19] It is a block diagram showing an example of the configuration of a computer.

Embodiments for Carrying Out the Invention

[0014] Hereinafter, embodiments for carrying out the present technology will be described. The description will be made in the following order. 1. Embodiment 2. Variation 3. Others

[0015] <<1. Embodiment>> Embodiments of the present technology will be described with reference to FIGS. 1 to 18.

[0016] <Configuration Example of Information Processing System 1> FIG. 1 shows an embodiment of an information processing system 1 to which the present technology is applied.

[0017] The information processing system 1 is a system for managing digital keys for using the vehicle 12 and the like. FIG. 1 schematically shows a configuration example of the information processing system 1.

[0018] The information processing system 1 includes a cloud system 11, a vehicle 12, a mobile device 13, and a FOB 14.

[0019] For the sake of simplicity, this diagram shows one vehicle 12, one mobile device 13, and one FOB 14; however, in reality, multiple vehicles 12, mobile devices 13, and FOB 14 are provided.

[0020] Furthermore, the relationship between a vehicle 12 and a mobile device 13 is not necessarily one-to-one; it is possible to provide multiple mobile devices 13 to a single vehicle 12. In other words, it is possible to use one vehicle 12 using multiple mobile devices 13. Similarly, the relationship between a vehicle 12 and an FOB 14 is not necessarily one-to-one; it is possible to provide multiple FOBs 14 to a single vehicle 12. In other words, it is possible to use one vehicle 12 using multiple FOBs 14. Conversely, it is possible to use multiple vehicles 12 using one mobile device 13.

[0021] The cloud system 11 generates a digital key for using the vehicle 12, and a pair key that corresponds to the digital key. The pair key includes, for example, authentication information for authenticating the digital key in the vehicle 12. The cloud system 11 also generates usage rules that indicate the scope within which the vehicle 12 can be used with the digital key, and sets usage rules for the digital key and the pair key. The cloud system 11 manages the relationships between the vehicle 12, the user (account), the digital key, and the usage rules.

[0022] The cloud system 11 transmits the digital key and information indicating usage rules (hereinafter referred to as usage rule information) to the mobile device 13. The cloud system 11 transmits the paired key and usage rule information to the vehicle 12.

[0023] Vehicle 12 stores pair key and usage rule information received from the cloud system 11 and manages the relationship between pair key and usage rule. Based on the pair key, vehicle 12 performs authentication processing for the digital key transmitted from the mobile device 13 or FOB 14. If the digital key authentication is successful, vehicle 12 controls the scope of use of vehicle 12 based on the usage rule set for the digital key (and its corresponding pair key).

[0024] The mobile device 13 is comprised of a user-portable information processing terminal, such as a smartphone. The mobile device 13 stores digital key and usage rule information received from the cloud system 11 and manages the relationship between the digital key and the usage rule. For example, a user can use the mobile device 13 to send a digital key to the vehicle 12, and if the digital key is successfully authenticated, the user can use the vehicle 12 within the usage scope based on the usage rule set for the digital key.

[0025] FOB14 is a device dedicated to vehicle 12 and holds a digital key in advance. For example, a user can send a digital key to vehicle 12 using FOB13, and if the digital key is successfully authenticated, the user can use vehicle 12 without restriction based on the usage rules set for the digital key.

[0026] Figure 2 shows a more detailed configuration example of the information processing system 1 than Figure 1. In particular, Figure 2 shows a configuration example of the cloud system 11, and a configuration example of the interface between the vehicle 12 and the mobile device 13.

[0027] The mobile device 13 is divided into, for example, an owner device 13A and a guest device 13B.

[0028] The owner device 13A is a mobile device used by a user who uses or manages the vehicle 12 on a daily or periodic basis, such as the owner of the vehicle 12.

[0029] The guest device 13B is, for example, a mobile device used by a user who is temporarily using the vehicle 12.

[0030] In the following, when it is not necessary to distinguish between the owner device 13A and the guest device 13B individually, they will simply be referred to as the mobile device 13.

[0031] The cloud system 11 includes a cloud server 31 and a key tracking server 32.

[0032] The cloud server 31 is a server that manages information about the vehicle 12 and the user. The cloud server 31 communicates directly with the vehicle 12 and the mobile device 13.

[0033] The key tracking server 32 is a server that generates and manages digital keys, paired keys, and usage rules.

[0034] Vehicle 12 includes, for example, a door NFC (Near Field Communication) reader 51, a console NFC reader 52, a BLE (Bluetooth Low Energy) module 53, and a UWB (Ultra-Wide Band) module 54.

[0035] The door NFC reader 51 is provided, for example, on each door of the vehicle 12.

[0036] The console NFC reader 52 is installed, for example, on the console inside the vehicle 12.

[0037] The mobile device 13 includes, for example, an NFC module 71, a BLE module 72, and a UWB module 73.

[0038] The NFC module 71 can communicate with the door NFC reader 51 and the console NFC reader 52.

[0039] For example, when a mobile device 13 is brought close to the door of the vehicle 12 to unlock it, the NFC module 71 communicates with a door NFC reader 51 located near the door and transmits a digital key to the vehicle 12. If the digital key is authenticated successfully and unlocking the door is permitted according to the usage rules set for the digital key, the door is unlocked.

[0040] For example, when a mobile device 13 is brought close to the console to start the vehicle 12, the NFC module 71 communicates with the door NFC reader 51 located near the console and transmits a digital key to the vehicle 12. If the digital key authentication is successful, the vehicle 12 is started based on the usage rules set for the digital key, and the vehicle 12 becomes usable within the set usage range.

[0041] The BLE module 72 transmits a digital key to the vehicle 12 by communicating with the BLE module 53 of the vehicle 12, for example. If the digital key authentication is successful, the vehicle 12 becomes usable within the set usage range based on the usage rules set for the digital key.

[0042] The UWB module 73 transmits a digital key to the vehicle 12, for example, by communicating with the vehicle's UWB module 54. If the digital key authentication is successful, the vehicle 12 becomes usable within the set usage range based on the usage rules set for the digital key.

[0043] <Example configuration of Cloud System 11> Figure 3 shows an example configuration of the cloud system 11 in Figure 1.

[0044] The cloud system 11 comprises an account management unit 101, a vehicle management unit 102, a key management unit 103, a usage rule management unit 104, and a communication unit 105. The account management unit 101 and the vehicle management unit 102 are implemented, for example, by a cloud server 31. The key management unit 103 and the usage rule management unit 104 are implemented, for example, by a key tracking server 32. The communication unit 105 is implemented, for example, by the cloud server 31 or another server.

[0045] The account management unit 101 manages each user's account. For example, the account management unit 101 creates, updates, and deletes each user's account, as well as creates, updates, and deletes user information contained in each user account.

[0046] The vehicle management unit 102 manages information related to each vehicle 12.

[0047] The key management unit 103 manages digital keys. For example, the key management unit 103 generates, maintains, and deletes digital keys and pair keys that correspond to digital keys. For example, the key management unit 103 provides a website to the mobile device 13 for generating and managing digital keys.

[0048] The usage rule management unit 104 manages the usage rules. For example, the usage rule management unit 104 generates and modifies usage rules, and generates, updates, and deletes usage rule information that indicates the generated or modified usage rules.

[0049] The account management unit 101, the vehicle management unit 102, the key management unit 103, and the usage rule management unit 104 manage user accounts, vehicles 12, digital keys, paired keys, and usage rules in relation to each other. This management may be performed in cooperation with the account management unit 101, the vehicle management unit 102, the key management unit 103, and the usage rule management unit 104, or by some of them.

[0050] The communication unit 105 communicates with the vehicle 12, the mobile device 13, and the FOB 14. For example, the communication unit 105 transmits the digital key and usage rule information to the mobile device 13. For example, the communication unit 105 transmits the pair key and usage rule information to each vehicle 12.

[0051] <Example configuration of vehicle control system 201> Figure 4 is a block diagram showing an example configuration of the vehicle control system 201 installed in the vehicle 12 shown in Figure 1.

[0052] The vehicle control system 201 performs processing related to driving assistance and autonomous driving of the vehicle 12.

[0053] The vehicle control system 201 includes a vehicle control ECU (Electronic Control Unit) 21, a communication unit 212, a map information acquisition unit 213, a location information acquisition unit 214, an external recognition sensor 215, a storage unit 216, a key management unit 217, an HMI (Human Machine Interface) 218, a driving assistance / automatic driving control unit 219, and a vehicle control unit 220.

[0054] The vehicle control ECU 211, communication unit 212, map information acquisition unit 213, location information acquisition unit 214, external recognition sensor 215, memory unit 216, driving support / automatic driving control unit 219, human-machine interface (HMI) 218, and vehicle control unit 220 are interconnected via a communication network NW to enable communication with each other. The communication network NW consists of an in-vehicle communication network or bus that conforms to digital bidirectional communication standards such as CAN (Controller Area Network), LIN (Local Interconnect Network), LAN (Local Area Network), FlexRay (registered trademark), and Ethernet (registered trademark). The communication network NW may be used differently depending on the type of data being transmitted. For example, CAN may be applied to data related to vehicle control, and Ethernet may be applied to large-capacity data. In addition, each part of the vehicle control system 201 may be directly connected using wireless communication intended for relatively short-range communication, such as near-field communication (NFC) or Bluetooth (registered trademark), without going through the communication network NW.

[0055] In the following, when each part of the vehicle control system 201 communicates via the communication network NW, the description of the communication network NW will be omitted. For example, when the vehicle control ECU 211 and the communication unit 212 communicate via the communication network NW, it will simply be described as the vehicle control ECU 211 and the communication unit 212 communicating.

[0056] The vehicle control ECU 211 is composed of various processors, such as a CPU (Central Processing Unit) and an MPU (Micro Processing Unit). The vehicle control ECU 211 controls the functions of the entire vehicle control system 201 or a part of it.

[0057] The communication unit 212 communicates with various devices inside and outside the vehicle, other vehicles, servers, base stations, etc., and transmits and receives various types of data. At this time, the communication unit 212 can communicate using multiple communication methods. For example, the communication unit 212 includes the door NFC reader 51, console NFC reader 52, BLE module 53, and UWB module 54 shown in Figure 2.

[0058] A brief explanation will be given regarding the external communication capabilities of the communication unit 212. The communication unit 212 communicates with servers located on an external network (hereinafter referred to as "external servers") via a base station or access point using wireless communication methods such as 5G (fifth-generation mobile communication system), LTE (Long Term Evolution), and DSRC (Dedicated Short Range Communications). The external network with which the communication unit 212 communicates is, for example, the internet, a cloud network, or a network specific to a carrier. The communication method used by the communication unit 212 to the external network is not particularly limited, as long as it is a wireless communication method that enables digital two-way communication at a predetermined communication speed and over a predetermined distance.

[0059] Furthermore, for example, the communication unit 212 can communicate with terminals located near the vehicle using P2P (Peer To Peer) technology. Terminals located near the vehicle include, for example, terminals worn by mobile bodies moving at relatively low speeds such as pedestrians and cyclists, terminals installed in fixed locations such as stores, or MTC (Machine Type Communication) terminals. In addition, the communication unit 212 can also perform V2X communication. V2X communication refers to communication between the vehicle and other vehicles, such as vehicle-to-vehicle communication with other vehicles, vehicle-to-infrastructure communication with roadside devices, etc., vehicle-to-home communication with homes, and vehicle-to-pedestrian communication with terminals carried by pedestrians, etc.

[0060] The communication unit 212 can, for example, receive programs from an external source (over the air) to update the software that controls the operation of the vehicle control system 201. The communication unit 212 can also receive map information, traffic information, information about the vehicle 12's surroundings, etc. from an external source. Furthermore, the communication unit 212 can transmit information about the vehicle 12 and information about the vehicle 12's surroundings to an external source. Information about the vehicle 12 that the communication unit 212 transmits to an external source includes, for example, data indicating the status of the vehicle 12 and recognition results from the analysis unit 241. Furthermore, the communication unit 212 can also perform communications corresponding to vehicle emergency notification systems such as e-Call.

[0061] For example, the communication unit 212 receives electromagnetic waves transmitted by road traffic information communication systems (VICS (Vehicle Information and Communication System) (registered trademark)) such as radio beacons, optical beacons, and FM multiplex broadcasting.

[0062] A brief overview of the communication capabilities of the communication unit 212 with the vehicle interior will be provided. The communication unit 212 can communicate with various devices in the vehicle, for example, using wireless communication. The communication unit 212 can communicate wirelessly with devices in the vehicle using communication methods that enable digital bidirectional communication at a predetermined or higher communication speed via wireless communication, such as Wi-Fi, Bluetooth, NFC, and WUSB (Wireless USB). Not limited to these, the communication unit 212 can also communicate with various devices in the vehicle using wired communication. For example, the communication unit 212 can communicate with various devices in the vehicle via wired communication through a cable connected to a connection terminal (not shown). The communication unit 212 can communicate with various devices in the vehicle using communication methods that enable digital bidirectional communication at a predetermined or higher communication speed via wired communication, such as USB (Universal Serial Bus), HDMI (High-Definition Multimedia Interface) (registered trademark), and MHL (Mobile High-definition Link).

[0063] Here, "devices inside the vehicle" refers to devices that are not connected to a communication network (NW) inside the vehicle. Examples of devices inside the vehicle include mobile devices and wearable devices carried by passengers such as the driver, and information devices that are brought into the vehicle and temporarily installed.

[0064] The map information acquisition unit 213 stores either or both maps provided externally and maps created by the vehicle 12. For example, the map information acquisition unit 213 stores three-dimensional high-precision maps, global maps with lower precision than high-precision maps but covering a wide area, and so on.

[0065] High-precision maps include, for example, dynamic maps, point cloud maps, and vector maps. A dynamic map is, for example, a map consisting of four layers: dynamic information, semi-dynamic information, semi-static information, and static information, and is provided to the vehicle 12 from an external server. A point cloud map is a map composed of point clouds (point cloud data). A vector map is, for example, a map that maps traffic information such as the location of lanes and traffic lights to a point cloud map, making it suitable for ADAS (Advanced Driver Assistance System) and AD (Autonomous Driving).

[0066] The point cloud map and vector map may be provided from, for example, an external server, or they may be created by the vehicle 12 as maps for matching with the local map described later, based on sensing results from the camera 231, radar 232, LiDAR 233, etc., and stored in the map information acquisition unit 213. In addition, if high-precision maps are provided from an external server, in order to reduce communication capacity, map data of, for example, several hundred square meters relating to the planned route that the vehicle 12 will travel will be acquired from the external server.

[0067] The location information acquisition unit 214 receives GNSS (Global Navigation Satellite System) signals from GNSS satellites and acquires location information of the vehicle 12. The acquired location information is supplied to the driving support / automatic driving control unit 219. The location information acquisition unit 214 is not limited to using GNSS signals; for example, it may acquire location information using beacons.

[0068] The external recognition sensor 215 is equipped with various sensors used to recognize the external conditions of the vehicle 12 and supplies sensor data from each sensor to various parts of the vehicle control system 201. The types and number of sensors equipped with the external recognition sensor 215 are arbitrary.

[0069] For example, the external recognition sensor 215 includes a camera 231, a radar 232, a LiDAR (Light Detection and Ranging, Laser Imaging Detection and Ranging) 233, and an ultrasonic sensor 234. However, the external recognition sensor 215 may also be configured to include one or more of the cameras 231, radar 232, LiDAR 233, and ultrasonic sensor 234. The number of cameras 231, radar 232, LiDAR 233, and ultrasonic sensors 234 is not particularly limited as long as it is a number that can be realistically installed in the vehicle 12. Furthermore, the types of sensors included in the external recognition sensor 215 are not limited to this example, and the external recognition sensor 215 may include other types of sensors. Examples of the sensing areas of each sensor included in the external recognition sensor 215 will be described later.

[0070] The shooting method of camera 231 is not particularly limited. For example, various types of cameras capable of distance measurement, such as ToF (Time Of Flight) cameras, stereo cameras, monocular cameras, and infrared cameras, can be applied to camera 231 as needed. However, camera 231 may also be used simply for acquiring images, regardless of distance measurement.

[0071] Furthermore, for example, the external recognition sensor 215 may include an environmental sensor for detecting the environment relative to the vehicle 12. The environmental sensor is a sensor for detecting the environment such as weather, climate, and brightness, and may include various sensors such as a raindrop sensor, fog sensor, sunshine sensor, snow sensor, and illuminance sensor.

[0072] Furthermore, for example, the external recognition sensor 215 includes a microphone used for detecting sounds around the vehicle 12 and the location of sound sources.

[0073] The storage unit 216 includes at least one of a non-volatile storage medium and a volatile storage medium, and stores data and programs. The storage unit 216 can be used as, for example, an EEPROM (Electrically Erasable Programmable Read Only Memory) and a RAM (Random Access Memory), and the storage medium can be a magnetic storage device such as an HDD (Hard Disk Drive), a semiconductor storage device, an optical storage device, or a magneto-optical storage device. The storage unit 216 stores various programs and data used by each part of the vehicle control system 201. For example, the storage unit 216 includes an EDR (Event Data Recorder) and a DSSAD (Data Storage System for Automated Driving), and stores information about the vehicle 12 before and after an event such as an accident, as well as information acquired by various sensors for detecting information inside the vehicle.

[0074] The memory unit 216 stores the pair key and usage rule information received from the cloud system 11 in association with each other. The memory unit 218, when it receives pair key and usage rule information corresponding to multiple digital keys from the cloud system 11, stores each of the multiple pairs of pair key and usage rule information.

[0075] The key management unit 217 manages the digital keys and controls the range of use of the vehicle 12 using the digital keys. For example, when the key management unit 217 receives a digital key from the mobile device 13, it retrieves a pair key to match the received digital key from the storage unit 218 and performs digital key authentication. If the digital key authentication is successful, the key management unit 217 retrieves usage rule information associated with the pair key from the storage unit 218 and controls the range of use of the vehicle 12 based on the usage rule information.

[0076] The HMI218 handles the input of various data and instructions, and presents various data to the driver or other personnel.

[0077] A brief explanation of data input by HMI218 is provided. HMI218 is equipped with an input device for human data input. HMI218 generates input signals based on data and instructions input by the input device and supplies them to various parts of the vehicle control system 201. HMI218 is equipped with operators such as a touch panel, buttons, switches, and levers as input devices. However, HMI218 may also be equipped with input devices that allow information to be input by methods other than manual operation, such as voice or gestures. Furthermore, HMI218 may use external connected devices such as a remote control device using infrared or radio waves, or a mobile device or wearable device that corresponds to the operation of the vehicle control system 201, as input devices.

[0078] This section provides a brief overview of how HMI218 presents data. HMI218 generates visual, auditory, and tactile information for the occupant or for those outside the vehicle. HMI218 also performs output control, managing the output, content, timing, and method of each generated piece of information. As visual information, HMI218 generates and outputs information indicated by images and light, such as operation screens, vehicle status displays, warning displays, and monitor images showing the surroundings of vehicle 12. As auditory information, HMI218 generates and outputs information indicated by sound, such as voice guidance, warning sounds, and warning messages. Furthermore, as tactile information, HMI218 generates and outputs information that is perceived by the occupant's sense of touch through force, vibration, movement, etc.

[0079] As output devices for visual information output by HMI218, for example, a display device that presents visual information by displaying images itself, or a projector device that presents visual information by projecting images, can be applied. In addition to display devices with ordinary displays, the display device may also be a device that displays visual information within the passenger's field of view, such as a head-up display, a transparent display, or a wearable device with AR (Augmented Reality) functionality. Furthermore, HMI218 can also use display devices such as navigation devices, instrument panels, CMS (Camera Monitoring System), electronic mirrors, and lamps installed in the vehicle 12 as output devices for visual information output.

[0080] For HMI218, output devices that output auditory information can include, for example, audio speakers, headphones, and earphones.

[0081] As an output device for HMI218 to output tactile information, for example, a haptic element using haptic technology can be applied. The haptic element is installed in parts of the vehicle 12 that are in contact with by the occupants, such as the steering wheel and the seats.

[0082] The driving assistance / automatic driving control unit 219 controls the driving assistance and automatic driving of the vehicle 12. For example, the driving assistance / automatic driving control unit 219 includes an analysis unit 241, an action planning unit 242, and an operation control unit 243.

[0083] The analysis unit 241 performs analysis processing on the vehicle 12 and the surrounding conditions.

[0084] For example, the analysis unit 241 estimates the vehicle's position based on sensor data from the external recognition sensor 215 and a high-precision map stored in the map information acquisition unit 213. For example, the analysis unit 241 generates a local map based on sensor data from the external recognition sensor 215 and estimates the vehicle's position by matching the local map with the high-precision map. The position of the vehicle 12 is based on, for example, the center of the rear wheel relative to the axle.

[0085] Local maps are, for example, three-dimensional high-precision maps created using technologies such as SLAM (Simultaneous Localization and Mapping), or occupancy grid maps. Three-dimensional high-precision maps are, for example, the point cloud maps mentioned above. Occupancy grid maps divide the three-dimensional or two-dimensional space around the vehicle 12 into grids of a predetermined size and show the occupancy status of objects on a grid-by-grid basis. The occupancy status of objects is indicated, for example, by the presence or absence of an object or its probability of existence. Local maps are also used, for example, in the detection and recognition processing of the external conditions of the vehicle 12 by the analysis unit 241.

[0086] The analysis unit 241 may also estimate the vehicle's own position based on the position information acquired by the position information acquisition unit 214 and sensor data from various sensors for detecting the state of the vehicle 12.

[0087] The analysis unit 241 performs sensor fusion processing to obtain new information by combining multiple different types of sensor data (for example, image data supplied from camera 231 and sensor data supplied from radar 232). Methods for combining different types of sensor data include integration, fusion, and union.

[0088] The analysis unit 241 performs a detection process to detect the external conditions of the vehicle 12, and a recognition process to recognize the external conditions of the vehicle 12.

[0089] For example, the analysis unit 241 performs detection and recognition processing of the external conditions of the vehicle 12 based on information from the external recognition sensor 215, etc.

[0090] Specifically, for example, the analysis unit 241 performs detection and recognition processing of objects around the vehicle 12. Object detection processing includes, for example, detecting the presence, size, shape, position, and movement of objects. Object recognition processing includes, for example, recognizing attributes such as the type of object or identifying a specific object. However, detection processing and recognition processing are not necessarily clearly separated and may overlap.

[0091] For example, the analysis unit 241 detects objects around the vehicle 12 by performing clustering, which classifies the point cloud based on sensor data from radar 232 or LiDAR 233 into clusters of points. This allows the presence, size, shape, and position of objects around the vehicle 12 to be detected.

[0092] For example, the analysis unit 241 detects the movement of objects around the vehicle 12 by performing tracking that follows the movement of clusters of points classified by clustering. This allows the velocity and direction of travel (movement vector) of objects around the vehicle 12 to be detected.

[0093] For example, the analysis unit 241 detects or recognizes vehicles, people, bicycles, obstacles, structures, roads, traffic lights, traffic signs, road markings, etc., based on image data supplied from the camera 231. The analysis unit 241 may also recognize the types of objects around the vehicle 12 by performing recognition processing such as semantic segmentation.

[0094] For example, the analysis unit 241 can perform traffic rule recognition processing around the vehicle 12 based on the map stored in the map information acquisition unit 213, the self-position estimation results, and the recognition results of objects around the vehicle 12. Through this processing, the analysis unit 241 can recognize the location and status of traffic signals, the content of traffic signs and road markings, the content of traffic regulations, and the lanes that can be driven on.

[0095] For example, the analysis unit 241 can perform recognition processing of the environment surrounding the vehicle 12. The surrounding environment that the analysis unit 241 is expected to recognize includes weather, temperature, humidity, brightness, and road surface conditions.

[0096] The action planning unit 242 creates an action plan for the vehicle 12. For example, the action planning unit 242 creates an action plan by performing route planning and route following processes.

[0097] Global path planning is the process of planning the general route from the start to the goal. This path planning also includes a process called local path planning, which involves generating a track that allows the vehicle 12 to move safely and smoothly in its vicinity, taking into account the vehicle's motion characteristics along the planned route.

[0098] Route following is the process of planning actions to safely and accurately travel along the route planned by the route planner within the planned time. The action planning unit 242 can, for example, calculate the target speed and target angular velocity of the vehicle 12 based on the results of this route following process.

[0099] The motion control unit 243 controls the operation of the vehicle 12 in order to realize the action plan created by the action planning unit 242.

[0100] For example, the motion control unit 243 controls the steering control unit 251, brake control unit 252, and drive control unit 253, which are included in the vehicle control unit 220 described later, to perform acceleration / deceleration control and direction control so that the vehicle 12 moves along the trajectory calculated by the trajectory plan. For example, the motion control unit 243 performs cooperative control for the purpose of realizing ADAS functions such as collision avoidance or impact mitigation, follow driving, vehicle speed maintenance driving, collision warning for the vehicle, and lane departure warning for the vehicle. For example, the motion control unit 243 performs cooperative control for the purpose of autonomous driving, such as driving autonomously without driver operation.

[0101] The vehicle control unit 220 controls various parts of the vehicle 12. The vehicle control unit 220 includes a steering control unit 251, a brake control unit 252, a drive control unit 253, a body system control unit 254, a light control unit 255, and a horn control unit 256.

[0102] The steering control unit 251 detects and controls the state of the steering system of the vehicle 12. The steering system includes, for example, a steering mechanism with a steering wheel, electric power steering, etc. The steering control unit 251 includes, for example, a steering ECU that controls the steering system, an actuator that drives the steering system, etc.

[0103] The brake control unit 252 detects and controls the state of the vehicle's brake system. The brake system includes, for example, a brake mechanism including a brake pedal, an ABS (Antilock Brake System), a regenerative braking mechanism, etc. The brake control unit 252 also includes, for example, a brake ECU that controls the brake system, an actuator that drives the brake system, etc.

[0104] The drive control unit 253 detects and controls the state of the vehicle 12's drive system. The drive system includes, for example, an accelerator pedal, a drive force generating device for generating driving force such as an internal combustion engine or drive motor, and a drive force transmission mechanism for transmitting driving force to the wheels. The drive control unit 253 also includes, for example, a drive ECU for controlling the drive system and actuators for driving the drive system.

[0105] The body system control unit 254 detects and controls the state of the body system of the vehicle 12. The body system includes, for example, a keyless entry system, a smart key system, power window devices, power seats, air conditioning devices, airbags, seat belts, a shift lever, etc. The body system control unit 254 also includes, for example, a body system ECU that controls the body system, actuators that drive the body system, etc.

[0106] The light control unit 255 detects and controls the status of various lights on the vehicle 12. Examples of lights to be controlled include headlights, taillights, fog lights, turn signals, brake lights, projections, and bumper displays. The light control unit 255 includes a light ECU for controlling the lights and actuators for driving the lights.

[0107] The horn control unit 256 detects and controls the status of the vehicle's car horn. The horn control unit 256 includes, for example, a horn ECU for controlling the car horn, an actuator for driving the car horn, and so on.

[0108] <Example configuration of mobile device 13> Figure 5 shows an example of the configuration of the functions of the mobile device 13.

[0109] The mobile device 13 comprises a control unit 311, an input unit 312, a sensing unit 313, a key management unit 314, an output unit 315, a communication unit 316, and a storage unit 317. The control unit 311, input unit 312, sensing unit 313, key management unit 314, output unit 315, communication unit 316, and storage unit 317 are connected to each other via a bus.

[0110] The control unit 311 controls each part of the mobile device 13.

[0111] The input unit 312 includes input devices for inputting various types of information into the mobile device 13. For example, the input unit 312 includes operating devices such as buttons, switches, and touch panels.

[0112] The sensing unit 313 is equipped with various sensors. For example, the sensing unit 313 includes a camera, an IMU (Inertial Measurement Unit), etc. Each sensor in the sensing unit 313 outputs sensor data indicating the sensing result to the bus.

[0113] The key management unit 314 manages the digital keys. For example, the key management unit 314 requests the cloud system 11 to generate a digital key via the communication unit 316 in accordance with user operations. For example, the key management unit 314 receives the digital key and usage rule information from the cloud system 11 via the communication unit 316 and stores them in association with the storage unit 317. For example, the key management unit 314 retrieves the digital key from the storage unit 317 and transmits it to the vehicle 12 via the communication unit 316.

[0114] The output unit 315 includes an output device that outputs various types of information, such as visual information, auditory information, and tactile information. For example, the output unit 315 includes a display device that outputs visual information. For example, the output unit 315 includes an audio output device that outputs auditory information. For example, the output unit 315 includes a haptic device that outputs tactile information.

[0115] The communication unit 316 includes the NFC module 71, BLE module 72, and UWB module 73, etc., as described above (see Figure 2), and communicates with the cloud system 11 and the vehicle 12. The communication method of the communication unit 316 is not particularly limited. Furthermore, the communication unit 316 can employ multiple communication methods.

[0116] The memory unit 317 stores various programs and data necessary for processing the mobile device 13. For example, the memory unit 218 stores digital keys and usage rule information received from the cloud system 11 in association with each other.

[0117] <Example of a user of Information Processing System 1> Next, with reference to Figure 6, an example of a user of Information Processing System 1 will be described.

[0118] Users of Information Processing System 1 can be broadly divided into owners, regular users, and guests.

[0119] The owner is a natural person or legal entity that owns vehicle 12.

[0120] For example, an owner includes an individual owner who personally owns the vehicle 12. An individual owner can, for example, use the information processing system 1 to grant the right to use the vehicle 12 to a family member or to temporarily grant the right to use the vehicle 12 to another person (a guest).

[0121] For example, the owner includes a company that owns company vehicles, or the owner of such a company. For example, the owner includes a company that provides a service for sharing vehicles 12, such as rental cars or car sharing, or the owner of such a company. A company or company owner can, for example, use an information processing system 1 to perform fleet management or to ensure that each user makes appropriate use of the vehicles 12.

[0122] Furthermore, the owner can manage the vehicle 12 and set the usage range of the vehicle 12, for example, using the information processing system 1. The usage range of the vehicle 12 includes, for example, the locations where the vehicle 12 can be unlocked, the driving range (geofence), the maximum speed, and the content available inside the vehicle.

[0123] A typical user is, for example, a user who uses vehicle 12 on a daily or regular basis. For example, if the owner is a natural person, the owner themselves may also be a typical user. A typical user includes, for example, the driver and passengers.

[0124] The driver is, for example, a user who drives the vehicle 12 on a daily or regular basis. For example, the driver could be the individual owner and their family members.

[0125] For example, the information processing system 1 can optimize driving settings for each driver, as well as the navigation system, operational support, and other functions.

[0126] A passenger is, for example, a user who rides in the vehicle 12 on a daily or regular basis without driving it themselves. For example, a passenger could be a family member of the individual owner.

[0127] For example, the information processing system 1 makes it possible for passengers to properly access the vehicle 12 and optimize the entertainment they can enjoy inside the vehicle 12.

[0128] A guest is, for example, a user who will temporarily use vehicle 12. For example, guests could include acquaintances of the personal owner, employees using company cars, or users of rental cars or car-sharing services.

[0129] For example, the information processing system 1 enables guests to use the vehicle 12 appropriately within its usable range. Furthermore, the information processing system 1 makes it possible to clarify who is responsible in the event of an accident while a guest is using the vehicle 12.

[0130] Here, there are at least two types of digital keys for using vehicle 12: a master key and a shared key.

[0131] A master key is, for example, a digital key used for the daily or periodic use of vehicle 12. A master key is typically held by the user.

[0132] A shared key is a digital key used, for example, to temporarily use vehicle 12. A shared key is held, for example, by a guest.

[0133] <Relationship between accounts, roles, and usage rules> Figure 7 shows the relationship between accounts, roles, and usage rules.

[0134] In Information Processing System 1, a role is assigned to each account, and the usage rules set for each role are applied to each account. In other words, the usage rules are indirectly applied to users who have accounts, through their roles. More specifically, the usage rules set for the role assigned to a user who has an account are set for the digital key granted to the user.

[0135] For example, roles that can be assigned to owners in Figure 6 include individual owner, fleet manager, and car-sharing owner. These roles are owner-level roles, and users assigned owner-level roles (hereinafter referred to as owner-level users) are able to set usage rules themselves.

[0136] For example, an owner-user can set the subjects for whom the right to use the vehicle 12 is set by making a request to the cloud system 11 using a mobile device 13. For example, the rights to be set may include the right to unlock the front right door of the vehicle 12, the right to unlock the front left door, the right to unlock the trunk, the right to unlock the glove box, etc.

[0137] For example, an owner user can configure the usage rules set for each role by making a request to the cloud system 11 using a mobile device 13. For example, by changing the usage rules set for each role, the scope of vehicle 12 usage for users to whom each role is assigned is changed.

[0138] For example, roles that can be assigned to a typical user in Figure 6 include driver, passenger (owner), etc.

[0139] In this example, the driver is given usage rules that include unlimited driving rights.

[0140] In this example, usage rules are set for the passenger (owner), including access to content, permission to view the navigation system's history, and permission to set Points of Interest (POIs) in the navigation system.

[0141] For example, possible roles assigned to the guest in Figure 6 include passenger (guest), valet driver, etc.

[0142] In this example, usage rules are set for passengers (guests), including their access to content and their right to set points of interest (POIs) in the navigation system.

[0143] In this example, usage rules are set for the valet driver, including limited driving rights, a maximum speed limit, and restrictions on the range of movement.

[0144] Here, we will explain specific examples of usage rules in more detail.

[0145] As described above, the usage rules are rules that indicate the scope of use of vehicle 12. For example, the usage rules indicate at least one of the following: the functional scope of use of vehicle 12, the temporal scope of use of vehicle 12, and the spatial scope of use of vehicle 12.

[0146] The functional scope of use of vehicle 12 includes, for example, the scope of locking and unlocking permitted for vehicle 12 doors, the scope of use of vehicle 12 driving functions, the scope of use of vehicle 12 HMI218 functions, the scope of content accessible inside the vehicle, the scope of use of vehicle 12 maintenance functions, and the scope of disclosure of vehicle 12 driving status.

[0147] Specifically, for example, usage rules define the range of vehicle doors 12 that are permitted to be locked and unlocked. For instance, usage rules might permit only the driver's side door to be locked and unlocked, or prohibit the locking and unlocking of the rear passenger doors and trunk.

[0148] For example, usage rules define the range of operation for the vehicle 12's driving functions. For instance, usage rules may disable driving functions or limit the vehicle 12's maximum speed.

[0149] For example, usage rules define the scope of use for the functions of the HMI218 in vehicle 12. For instance, usage rules may permit or restrict access to the navigation system history of the HMI218, or permit or restrict the setting of Points of Interest (POIs) for the navigation system.

[0150] For example, usage rules may define the range of content that can be accessed within the vehicle. For example, usage rules may prohibit access to R18 content within the vehicle.

[0151] For example, usage rules define the scope of use for the vehicle 12's maintenance functions. For example, usage rules may prohibit or restrict the use of over-the-air (OTA) software updates or remote diagnostics.

[0152] For example, usage rules can set the scope of disclosure of the vehicle 12's driving status. For example, usage rules can permit driving in stealth mode (privacy mode). Stealth mode is a mode that prevents logs related to driving from being uploaded to the cloud system 11, etc.

[0153] For example, usage rules define the time range for which vehicle 12 can be used, including the period, time of day, and day of the week.

[0154] For example, according to the usage rules, a geofence is set as the spatial usage area of ​​vehicle 12, and the movement range of vehicle 12 is restricted to within the geofence.

[0155] Furthermore, the usage range of vehicle 12, as indicated by the usage rules, may be modified to change depending on the surrounding conditions of vehicle 12. For example, the functions of vehicle 12 may be restricted based on the number of pedestrians around vehicle 12 recognized by the external recognition sensor 215. Specifically, for example, the maximum speed of vehicle 12 may be restricted based on the number of pedestrians recognized at an intersection or the like.

[0156] <Processing by Information Processing System 1> Next, the processing of the information processing system 1 will be explained with reference to Figures 8 to 18.

[0157] <Share key generation process> First, we will explain the share key generation process performed by the information processing system 1, referring to the flowchart in Figure 8.

[0158] Hereafter, the user of owner device 13A will be referred to as the owner, and the user of guest device 13B will be referred to as the guest.

[0159] In step S1, the owner device 13A requests the cloud system 11 to generate a share key.

[0160] Specifically, the output unit 315 of the owner device 13A displays a settings screen for requesting the generation of a share key, under the control of the key management unit 314.

[0161] In response, the owner requests the generation of a share key by performing a predetermined operation using the input unit 312.

[0162] Here, with reference to Figures 9 through 14, we will describe specific examples of operations for requesting the generation of a share key.

[0163] Figure 9 shows an example of a digital key list screen.

[0164] This screen displays a list of information regarding users who possess digital keys (master keys and share keys).

[0165] Specifically, this screen displays Master Key fields 401-1 and 401-2, Master Key Add button 402, Share Key fields 403-1 through 403-4, and Share Key Add button 404.

[0166] Master Key fields 401-1 and 401-2 display information about each master key. Specifically, master key fields 401-1 and 401-2 display the thumbnail image and name of the user who possesses each master key.

[0167] When the Add Master Key button 402 is pressed, a screen for generating a new master key will be displayed.

[0168] Information about each share key is displayed in share key fields 403-1 through 403-4.

[0169] Specifically, the share key field 403-1 displays the thumbnail image and username of the user who possesses the share key, the status of the share key, and the slider 403A-1. Here, the share key status is displayed as "Before Start," which indicates that the share key has not yet been used. When the slider 403A-1 is set to the right, the share key becomes active, and when it is set to the left, the share key becomes inactive.

[0170] The Share Key field 403-2 displays the Share Key's key mode, expiration date (end date of validity), status, and slider 403A-2. Specifically, it shows that the key mode is set to Share, the expiration date is set to December 12, 2020, and it is currently suspended. Slider 403A-2, like slider 403A-1, is used to switch the Share Key on and off.

[0171] Please note that since there are currently no users who possess the corresponding share key, no user information is displayed in the share key field 403-2.

[0172] The Share Key field 403-3 displays the Share Key's key mode, expiration date (end date of validity), status, and slider 403A-3. Specifically, it indicates that the key mode is set to Full Control, the expiration date is set to December 12, 2020, and the key has not yet been received by the user. Slider 403A-3, like slider 403A-1, is used to switch the Share Key between enabled and disabled.

[0173] Please note that since there are currently no users who possess the corresponding share key, no user information is displayed in the share key field 403-3.

[0174] The Share Key field 403-4 displays the Share Key's key mode, expiration date (end date of validity), and status. Specifically, it shows that the key mode is set to Non Driver, the expiration date is set to November 9, 2020, and the key has expired.

[0175] When the Add Share Key button (404) is pressed, a screen for generating a new share key will be displayed.

[0176] Figure 10 shows an example of a digital key list screen when no digital key exists.

[0177] This screen indicates that no digital key exists and displays the digital key generation button 421.

[0178] When the digital key generation button 421 is pressed, a screen for generating a new digital key is displayed.

[0179] Figure 11 shows an example of the digital key reset screen.

[0180] On this screen, window 441 is displayed above the list of digital keys.

[0181] Window 441 is for performing the operation to delete all digital keys, and displays the delete button 442 and the cancel button 443.

[0182] When the delete button 442 is pressed, all digital keys for the target vehicle 12 are deleted.

[0183] When the cancel button 443 is pressed, the digital key deletion operation is canceled.

[0184] Figures 12 and 13 show examples of the share key generation screen.

[0185] Figure 12 shows an example of the key mode settings screen for ShareKey.

[0186] This settings screen displays the key mode setting field 461. For example, in this example, it is possible to select a key mode from three types: full control mode, share mode, and non-driver mode.

[0187] In this example, the user to whom the share key is assigned is the guest (Figure 6). In this example, a role is set based on the combination of this guest user type and the key mode. The usage rules set for the role are then applied to the share key (guest).

[0188] For example, if a share key is set to full control mode, it becomes possible to use vehicle 12 without restrictions.

[0189] For example, when using a share key set to share mode, it is possible to drive vehicle 12, but the range of use of vehicle 12 is partially restricted.

[0190] For example, if a share key is set to non-driver mode, driving vehicle 12 is prohibited, and the range of use of vehicle 12 is partially restricted.

[0191] Figure 13 shows an example of the screen for setting the validity period of a share key.

[0192] This screen displays the validity period setting field 481. For example, in this example, the validity period setting field 481 displays a calendar for setting the start and end dates of the validity period. Also displayed are the OK button 482 and the Cancel button 483. When the OK button 482 is pressed, the validity period is confirmed, and the screen transitions to, for example, the screen shown in Figure 14. When the Cancel button 483 is pressed, the validity period setting is canceled, and the screen transitions to, for example, the screen shown in Figure 14.

[0193] Figure 14 shows an example of the share key generation screen. This screen displays the key mode field 501, the start date field 502, the end date field 503, and the key generation button 504.

[0194] The key mode field 501 displays the key mode setting. When the key mode field 501 is selected, the settings screen shown in Figure 12, for example, is displayed.

[0195] The Start Date field 502 displays the set start date for the share key's validity period. When Start Date field 502 is selected, the settings screen shown in Figure 13, for example, will be displayed.

[0196] The end date field 503 displays the set end date for the share key's validity period. When the end date field 503 is selected, the settings screen shown in Figure 13, for example, will be displayed.

[0197] When the key generation button 504 is pressed, the cloud system 11 is requested to generate a share key with the configured key mode and validity period.

[0198] Specifically, the key management unit 314 generates share key generation request information that requests the generation of a share key. The share key generation request information includes, for example, the account information of the user who will use the share key, the identification information of the vehicle 12 that will use the share key, the key mode, and the validity period. The key management unit 314 transmits the share key generation request information to the cloud system 11 via the communication unit 316.

[0199] Returning to Figure 8, in step S2, the cloud system 11 generates a share key, a pair key, and usage rules.

[0200] Specifically, the communication unit 105 receives share key generation request information from the owner device 13A. The key management unit 103 generates a share key and a pair key that corresponds to the share key based on the share key generation request information. The usage rule management unit 104 sets usage rules for the share key and pair key based on the share key generation request information and generates usage rule information indicating the set usage rules. The account management unit 101, vehicle management unit 102, key management unit 103, and usage rule management unit 104 store the generated share key, pair key, usage rule information, user account, and vehicle 12 in association with each other.

[0201] In step S3, the cloud system 11 transmits the URL from which the share key can be obtained. Specifically, the key management unit 103 generates download information that includes the URL of the website from which the share key can be obtained. The key management unit 103 transmits the download information to the owner device 13A via the communication unit 105.

[0202] In step S4, the owner device 13A receives the URL from which to obtain the share key. Specifically, the key management unit 314 of the owner device 13A receives download information from the cloud system 11 via the communication unit 316.

[0203] In step S5, the owner device 13A notifies the user of the URL from which to obtain the share key. For example, the output unit 315 displays the share key provision screen shown in Figure 15 under the control of the key management unit 314, in accordance with the user's operation.

[0204] The share key provision screen displays a QR code 521, an expiration date field 522, a key mode field 523, a start date field 524, an end date field 525, and a share button 526.

[0205] QR code 521 indicates the URL of the website from which the share key can be obtained. QR code 521 is generated, for example, by the key management unit 314 converting the URL shown in the download information.

[0206] The expiration date column 522 indicates the expiration date by which the share key can be obtained from the website accessible via the URL shown by the QR code (registered trademark). For example, in this example, it shows that the expiration date is November 5, 2020, at 7:45 PM.

[0207] The key mode column 523 indicates the key mode set for the share key.

[0208] The "Start Date" column, 524, indicates the start date of the share key's validity period.

[0209] The "End Date" column, 525, indicates the end date of the share key's validity period.

[0210] When the share button 526 is pressed, a screen will appear, for example, to send the URL for obtaining the share key to the guest device 13B.

[0211] In step S6, the guest device 13B obtains the URL from which to retrieve the share key. For example, the guest uses the camera included in the sensing unit 313 of the guest device 13B to photograph the QR code 521 on the share key provision screen in Figure 15. The key management unit 314 of the guest device 13B converts the QR code 521 into a URL.

[0212] In step S7, the guest device 13B obtains the share key and usage rules.

[0213] In response, in step S8, the cloud system 11 transmits the share key and usage rules.

[0214] Specifically, for example, the guest uses the input unit 312 of the guest device 13B to access the website indicated by the URL obtained in step S6 and downloads the share key.

[0215] In response, the key management unit 314 of the guest device 13B accesses the website indicated by the acquired URL via the communication unit 316.

[0216] In response, the communication unit 105 of the cloud system 11 transmits the share key and usage rule information to the guest device 13B.

[0217] Then, the key management unit 314 of the guest device 13B downloads the share key and usage rule information from the cloud system 11 via the communication unit 316. The key management unit 314 associates the acquired share key and usage rule information and stores it in the storage unit 317.

[0218] This enables the use of a shared key on guest device 13B.

[0219] In step S9, the communication unit 105 of the cloud system 11 transmits the pair key and usage rule information to the vehicle 12.

[0220] In response to this, in step S10, the key management unit 217 of the vehicle 12 receives the pair key and usage rule information via the communication unit 212. The key management unit 217 associates the received pair key and usage rule information and stores it in the storage unit 216.

[0221] As a result, a pair key and usage rules corresponding to the new shared key are registered in vehicle 12.

[0222] The process in step S9 is executed after the process in step S2, when communication between the cloud system 11 and the vehicle 12 becomes possible. Therefore, the process in step S9 may be executed, for example, before the process in step S3, or before the process in step S8.

[0223] As described above, the owner can easily generate a share key and provide it to the guest. Furthermore, the owner can easily set usage rules for the share key and define the scope of vehicle 12 usage for the guest.

[0224] <Unregistered pair key and usage rule registration process> Next, referring to the sequence diagram in Figure 16, the process of registering unregistered pair keys and usage rules in vehicle 12 will be explained.

[0225] Referring to Figure 8, if the vehicle 12 is not started and cannot communicate with the cloud system 11 when the share key is generated in the process described above, the pair key and usage rules corresponding to the generated share key cannot be registered with the vehicle 12. In contrast, this process registers the unregistered pair key and usage rules with the vehicle 12 when the vehicle 12 is started and able to communicate.

[0226] In step S101, the user uses a mobile device 13 or FOB 14 that holds a digital key (master key or share key) in which the pair key and usage rules are already registered in the vehicle 12 to perform an operation to use the vehicle 12. Here, an operation to use the vehicle 12 is, for example, an operation to unlock the doors and start the vehicle 12.

[0227] In response, the body control unit 254 of the vehicle 12 unlocks the doors and starts the vehicle 12.

[0228] In step S102, the mobile device 13 or FOB 14 sends a usage request to the cloud system 11. For example, the key management unit 314 of the mobile device 13 sends a usage request to the cloud system 11 via the communication unit 316. Alternatively, for example, FOB 14 sends a usage request to the cloud system 11.

[0229] In step S103, the cloud system 11 identifies unregistered pair keys and usage rules. Specifically, the communication unit 105 receives usage requests sent from the mobile device 13 or FOB 14. The key management unit 103 identifies pair keys and usage rules that are not registered in the vehicle 12 from among the pair keys and usage rules corresponding to the generated share keys.

[0230] In step S104, vehicle 12 registers an unregistered pair key and usage rules.

[0231] Specifically, the communication unit 105 of the cloud system 11 transmits the pair key identified in step S103 and the usage rule information corresponding to the usage rule to the vehicle 12.

[0232] In response, the key management unit 217 of the vehicle 12 receives paired keys and usage rule information from the cloud system 11 via the communication unit 212. The key management unit 217 associates the received paired keys and usage rule information and stores them in the storage unit 216.

[0233] As a result, when vehicle 12 becomes able to communicate, unregistered pair keys and usage rules are automatically registered with vehicle 12.

[0234] For example, the key management unit 217 of vehicle 12 may query the cloud system 11 when vehicle 12 is started to see if any unregistered key pairs and usage rules exist. If unregistered key pairs and usage rules exist, the key management unit 217 of vehicle 12 may receive them from the cloud system 11.

[0235] <Driver's side door unlocking process> Next, referring to the sequence diagram in Figure 17, we will explain the process when unlocking the driver's side door of vehicle 12 using a shared key that has a usage rule set to allow only the locking and unlocking of the driver's side door.

[0236] In step S121, the guest uses the guest device 13B to unlock the driver's side door.

[0237] In response, the key management unit 314 of the guest device 13B transmits the share key to the vehicle 12 via the communication unit 316.

[0238] In step S122, the key management unit 217 of the vehicle 12 verifies the user (guest) and requests usage rules. Specifically, the key management unit 217 receives the share key from the guest device 13B via the communication unit 212. The key management unit 217 searches for a pair key that corresponds to the share key in the storage unit 216. If the key management unit 217 finds a pair key that corresponds to the share key, it verifies the user (guest) by performing authentication processing of the share key using the pair key. If the authentication of the share key is successful, the key management unit 217 requests usage rule information associated with the pair key from the storage unit 216.

[0239] In step S123, the storage unit 216 returns the usage rule. Specifically, the storage unit 216 supplies the usage rule information associated with the pair key to the key management unit 217.

[0240] In step S124, the key management unit 217 of the vehicle 12 interprets the usage rules based on the usage rule information. As a result, the key management unit 217 recognizes that only the driver's side door can be unlocked.

[0241] In step S125, the vehicle 12 is set to a state where only the driver's door can be unlocked. Specifically, the key management unit 217 instructs the body control unit 254 to set the vehicle to a state where only the driver's door can be unlocked. In response, the body control unit 254 sets the vehicle to a state where only the driver's door can be unlocked.

[0242] In step S126, the body control unit 254 of the vehicle 12 unlocks the driver's side door.

[0243] In step S127, the guest confirms that the driver's side door is unlocked.

[0244] In this way, guests can easily unlock the driver's side door using the shared key.

[0245] <Trunk unlocking process> Next, referring to the sequence diagram in Figure 18, we will explain the process when unlocking the trunk of vehicle 12 using a shared key that has usage rules set to allow locking and unlocking of the trunk.

[0246] In step S141, the guest uses the guest device 13B to unlock the trunk.

[0247] In response, the key management unit 314 of the guest device 13B transmits the share key to the vehicle 12 via the communication unit 316.

[0248] In step S142, similar to the process in step S122 in Figure 19, the key management unit 217 of the vehicle 12 confirms the user (guest) and requests the storage unit 216 to use the usage rules.

[0249] In step S143, the usage rule is returned from the storage unit 216 of the vehicle 12 to the key management unit 217, similar to the process in step S123 in Figure 19.

[0250] In step S144, the key management unit 217 of the vehicle 12 interprets the usage rules based on the usage rule information. As a result, the key management unit 217 recognizes that the trunk can be unlocked.

[0251] In step S145, the vehicle 12 sets the trunk to an unlockable state. Specifically, the key management unit 217 instructs the body system control unit 254 to set the trunk to an unlockable state. In response, the body system control unit 254 sets the trunk to an unlockable state.

[0252] In step S146, the body control unit 254 of the vehicle 12 unlocks the trunk.

[0253] In step S147, the user confirms that the trunk is unlocked.

[0254] In this way, guests can easily unlock the trunk using the shared key.

[0255] Furthermore, when vehicle 12 is started using a digital key (master key or share key), the usage rules set for the digital key remain in effect until, for example, vehicle 12 is stopped (power turned off). In other words, after vehicle 12 is started, the digital key used to start vehicle 12 remains in effect until vehicle 12 is stopped (power turned off), and other digital keys cannot be used.

[0256] <How to set the types and content of usage rules> Next, we will explain examples of how to set up the types and content of usage rules.

[0257] The above explanation showed an example where three types of usage rules are set on a share key to correspond to three types of key modes. However, for example, the information processing system 1 can increase or decrease the number of types of usage rules.

[0258] For example, an owner user may use the owner device 13A to request the cloud system 11 to add or delete a type of usage rule. In response, the usage rule management unit 104 of the cloud system 11 adds or deletes the type of usage rule according to the owner user's request.

[0259] For example, the information processing system 1 can appropriately change the content of the usage rules, that is, the scope of use of the vehicle 12 as indicated by the usage rules.

[0260] For example, an owner user may use the owner device 13A to request a change to the usage rules from the cloud system 11. In response, the usage rule management unit 104 of the cloud system 11 changes the usage rules according to the owner user's request.

[0261] For example, the information processing system 1 can change the items subject to the usage rules as appropriate. For example, the information processing system 1 can change the target to whom the right to use vehicle 12 is set.

[0262] For example, an owner user may use the owner device 13A to request the cloud system 11 to change (e.g., add or delete) items subject to the usage rules. In response, the usage rule management unit 104 of the cloud system 11 changes the items subject to the usage rules according to the owner user's request.

[0263] <How to delete digital keys and usage rules> Next, we will explain an example of how to delete digital keys and usage rules.

[0264] For example, digital keys and usage rule information with a set usage period are automatically deleted from the mobile device 13 when the usage period expires. Alternatively, for example, the digital keys and usage rule information may not be deleted but simply disabled.

[0265] Similarly, for example, paired keys and usage rule information corresponding to a digital key with a set usage period are automatically deleted from the vehicle 12 when the usage period expires. Alternatively, for example, the paired keys and usage rule information may not be deleted but simply deactivated.

[0266] For example, to delete or disable a share key for which no usage period has been set, the owner user, for instance, uses the owner device 13A to request the cloud system 11 to delete or disable the share key.

[0267] In contrast, for example, the usage rule management unit 104 of the cloud system 11 requests the guest device 13B to delete or invalidate the share key and usage rules via the communication unit 105 according to the request of the owner-level user. Also, the usage rule management unit 104 of the cloud system 11 requests the vehicle 12 to delete or invalidate the pair key and usage rules via the communication unit 105 according to the request of the owner-level user.

[0268] In contrast, the key management unit 314 of the guest device 13B deletes or invalidates the share key and usage rule information. The key management unit 217 of the vehicle 12 deletes or invalidates the pair key and usage rule information.

[0269] In this way, the usage range of the vehicle 12 can be set easily and flexibly. That is, for each user, the usage range of the vehicle 12 can be set easily and in detail.

[0270] Thereby, for example, users who are permitted to drive the vehicle 12 can be easily managed. For example, users who are permitted valet parking, users who can drive company cars, etc. can be easily managed.

[0271] <<2. Modified Example>> Hereinafter, a modified example of the above-described embodiment of the present technology will be described.

[0272] <Modified Example Regarding Usage Rules> In the above description, an example of indirectly setting usage rules for each user (account) via a role has been shown, but usage rules may be directly set for each user.

[0273] For example, when an emergency such as an accident occurs, the key management unit 217 of the vehicle 12 may change the content of the usage rules. For example, the key management unit 217 may change the content of the usage rules and expand the usage range of the vehicle 12 so as to be able to quickly respond to an emergency such as an accident.

[0274] For example, usage rules applied to a user may be set based on the user's driving experience and driving skills.

[0275] For example, usage rules applied to a user may be set based on the driving experience of the user grasped by an insurance company or the like. Specifically, for example, the usage rules applied to the user may be set such that the usage range of the vehicle 12 expands as the driving experience of the user increases, and the usage range of the vehicle 12 narrows as the driving experience of the user decreases.

[0276] For example, usage rules applied to a user may be set based on the remaining points of the driver's license. Specifically, for example, the usage rules applied to the user may be set such that the usage range of the vehicle 12 narrows as the remaining points of the driver's license decrease.

[0277] <Variation Example Regarding Transfer of Digital Key and Usage Rules> For example, a digital key may be supplied from the cloud system 11 to the mobile device 13 via the vehicle 12. That is, the digital key may be transmitted from the cloud system 11 to the vehicle 12 and then from the vehicle 12 to the mobile device 13.

[0278] For example, usage rule information may be supplied from the cloud system 11 to the vehicle 12 via the mobile device 13. That is, the usage rule information may be transmitted from the cloud system 11 to the mobile device 13 and then from the mobile device 13 to the vehicle 12.

[0279] For example, a pairing key may be supplied from the cloud system 11 to the vehicle 12 via the mobile device 13. That is, the pairing key may be transmitted from the cloud system 11 to the mobile device 13 and then from the mobile device 13 to the vehicle 12.

[0280] Furthermore, the mobile device 13 does not necessarily need to obtain usage rule information from the cloud system 11.

[0281] Furthermore, for example, if vehicle 12 already possesses information that can authenticate a digital key, it does not necessarily need to obtain a paired key from the cloud system 11.

[0282] <Other variations> For example, if a user uses vehicle 12 with a digital key, vehicle 12 may perform user authentication in addition to digital key authentication, if necessary. If both digital key and user authentication are successful, the authenticated user may be allowed to use vehicle 12 according to the usage rules.

[0283] For example, if multiple guests share vehicle 12 using a share key, it is possible to aggregate the mileage for each share key. Conversely, if vehicle 12 is a company car, for example, expense reimbursement can be performed for each user to whom a share key is assigned. For example, if vehicle 12 is a car-sharing vehicle, charges can be billed based on the mileage traveled by each user to whom a share key is assigned.

[0284] <<3.B>> <Example of computer configuration> The series of processes described above can be executed by hardware or by software. When the series of processes are executed by software, the programs that make up that software are installed on a computer. Here, a computer includes computers built into dedicated hardware, as well as general-purpose personal computers that can perform various functions by installing various programs.

[0285] Figure 19 is a block diagram showing an example of the hardware configuration of a computer that executes the series of processes described above by a program.

[0286] In computer 1000, the CPU (Central Processing Unit) 1001, ROM (Read Only Memory) 1002, and RAM (Random Access Memory) 1003 are interconnected by a bus 1004.

[0287] An input / output interface 1005 is further connected to the bus 1004. An input / output interface 1005 is connected to an input unit 1006, an output unit 1007, a storage unit 1008, a communication unit 1009, and a drive 1010.

[0288] The input section 1006 consists of input switches, buttons, a microphone, an image sensor, etc. The output section 1007 consists of a display, a speaker, etc. The storage section 1008 consists of a hard disk or non-volatile memory, etc. The communication section 1009 consists of a network interface, etc. The drive 1010 drives removable media 1011 such as a magnetic disk, optical disk, magneto-optical disk, or semiconductor memory.

[0289] In the computer 1000 configured as described above, the CPU 1001 loads, for example, a program stored in the memory unit 1008 into the RAM 1003 via the input / output interface 1005 and the bus 1004, and executes it, thereby performing the series of processes described above.

[0290] The program executed by computer 1000 (CPU 1001) can be provided by recording it on removable media 1011, such as a packaged media. The program can also be provided via wired or wireless transmission media, such as a local area network, the internet, or digital satellite broadcasting.

[0291] In the computer 1000, the program can be installed in the storage unit 1008 via the input / output interface 1005 by mounting the removable media 1011 on the drive 1010. Also, the program can be received by the communication unit 1009 via a wired or wireless transmission medium and installed in the storage unit 1008. Additionally, the program can be pre-installed in the ROM 1002 or the storage unit 1008.

[0292] Note that the program executed by the computer may be a program whose processing is performed in time series in accordance with the order described in this specification, or may be a program whose processing is performed in parallel or at a necessary timing such as when a call is made.

[0293] Also, in this specification, a system means a collection of a plurality of components (devices, modules (parts), etc.), regardless of whether all the components are in the same housing. Therefore, a plurality of devices housed in separate housings and connected via a network, and a single device in which a plurality of modules are housed in one housing are both systems.

[0294] Furthermore, the embodiments of the present technology are not limited to the above-described embodiments, and various modifications are possible without departing from the gist of the present technology.

[0295] For example, the present technology can take a configuration of cloud computing in which one function is shared and jointly processed by a plurality of devices via a network.

[0296] Also, each step described in the above flowchart can be executed by one device, or can be shared and executed by a plurality of devices.

[0297] Furthermore, when a single step includes a plurality of processes, the plurality of processes included in that single step can be executed by one device, or can be shared and executed by a plurality of devices.

[0298] <Examples of configuration combinations> This technology can also be configured as follows:

[0299] (1) A key management unit that generates digital keys for using the vehicle, A usage rule management unit sets usage rules for the digital key that indicate the scope of use of the vehicle, A communication unit that transmits the digital key to at least one of the vehicle and the information processing terminal that uses the digital key, and transmits usage rule information indicating the usage rules to at least one of the vehicle and the information processing terminal. An information processing device equipped with the following features. (2) The usage rule management unit sets the usage rules set for the role assigned to the first user for the digital key to be assigned to the first user. The information processing device described in (1) above. (3) The usage rule management unit sets the usage rules associated with the owner role in response to a request from a second user to whom the owner role has been assigned. The information processing device described in (2) above. (4) The aforementioned usage rules indicate at least one of the following: the functional range of use of the vehicle, the temporal range of use of the vehicle, and the spatial range of use of the vehicle. The information processing device described in any of (1) to (3) above. (5) The functional scope of use of the vehicle includes at least one of the following: the scope of the vehicle's doors that can be locked and unlocked; the scope of the vehicle's driving functions; the scope of the vehicle's HMI (Human Machine Interface) functions; the scope of content accessible in the vehicle; the scope of the vehicle's maintenance functions; and the scope of disclosure of the vehicle's driving status. The information processing device described in (4) above. (6) The temporal scope of use of the said vehicle includes the period during which the said vehicle can be used. The information processing apparatus described in (4) or (5) above. (7) The spatial range of use of the vehicle includes the range in which the vehicle can move. The information processing device described in any of (4) to (6) above. (8) The aforementioned usage rule management unit sets the content of the usage rules in response to requests from users. An information processing device according to any one of (1) to (7) above. (9) The communication unit transmits the digital key to the information processing terminal and transmits the usage rule information to the vehicle. An information processing device according to any one of (1) to (8) above. (10) The communication unit further transmits the usage rule information to the information processing terminal. The information processing device described in (9) above. (11) The key management unit generates a pair key containing authentication information used for authenticating the digital key, The communication unit transmits the pair key to the vehicle. The information processing apparatus described in (9) or (10) above. (12) Information processing device, Generate a digital key to use the vehicle, A usage rule indicating the scope of use of the vehicle is set for the digital key, The digital key is transmitted to at least one of the vehicle and the information processing terminal that uses the digital key, and usage rule information indicating the usage rules is transmitted to at least one of the vehicle and the information processing terminal. Information processing methods. (13) A key management unit controls the vehicle's usage range based on usage rules set by the information processing device that generated the digital key, for digital keys received from an information processing terminal. A vehicle control system that is equipped with this system. (14) The key management unit includes authentication information used for authenticating the digital key, and authenticates the digital key based on the pair key generated by the information processing device. If the authentication of the digital key is successful, it controls the usage range of the vehicle based on the usage rules set for the digital key. The vehicle control device described in (13) above. (15) The key management unit receives usage rule information indicating the usage rules from the information processing device. The vehicle control device described in (13) or (14) above. (16) The aforementioned usage rules indicate at least one of the following: the functional range of use of the vehicle, the temporal range of use of the vehicle, and the spatial range of use of the vehicle. A vehicle control device according to any of (13) to (15) above. (17) The functional scope of use of the vehicle includes at least one of the following: the scope of the vehicle's doors that can be locked and unlocked; the scope of the vehicle's driving functions; the scope of the vehicle's HMI functions; the scope of content accessible in the vehicle; the scope of the vehicle's maintenance functions; and the scope of disclosure of the vehicle's driving status. The vehicle control device described in (16) above. (18) The temporal scope of use of the said vehicle includes the period during which the said vehicle can be used. The vehicle control device described in (16) or (17) above. (19) The spatial range of use of the vehicle includes the range in which the vehicle can move. A vehicle control device according to any one of (16) to (18) above. (20) A key management unit that obtains a digital key from an information processing device, which has usage rules set to indicate the scope of vehicle use, When the vehicle is used, a communication unit transmits the digital key to the vehicle. An information processing terminal equipped with the following features.

[0300] Furthermore, the effects described herein are merely illustrative and not limiting; other effects may also occur. [Explanation of symbols]

[0301] 1 Information Processing System, 11 Cloud System, 12 Vehicle, 13 Mobile Device, 13A Owner Device, 13B Guest Device, 14 FOB, 31 Cloud Server, 32 Key Tracking Server, 101 Account Management Unit, 102 Vehicle Management Unit, 103 Key Management Unit, 104 Usage Rule Management Unit, 105 Communication Unit, 211 Vehicle Control ECU, 216 Memory Unit, 217 Key Management Unit, 218 HMI, 220 Vehicle Control Unit, 254 Body System Control Unit, 313 Sensing Unit, 314 Key Management Unit, 316 Communication Unit, 317 Memory Unit

Claims

1. A key management unit that generates digital keys for using the vehicle, A usage rule management unit sets usage rules for each role that indicate the scope of use of the aforementioned vehicle, and sets the usage rules set for the role assigned to the user to the digital key assigned to the user, A communication unit that transmits the digital key to at least one of the vehicle and the information processing terminal that uses the digital key, and transmits usage rule information indicating the usage rules to the vehicle. An information processing device equipped with the following features.

2. The roles include roles assigned to the owner of the vehicle, roles assigned to regular users who use the vehicle on a daily or regular basis, and roles assigned to guests who use the vehicle on a temporary basis. The information processing apparatus according to claim 1.

3. The usage rule management unit sets or modifies the usage rules for the role in response to a request from a user to whom the owner role has been assigned. The information processing apparatus according to claim 1.

4. The aforementioned usage rules indicate at least one of the following: the functional range of use of the vehicle, the temporal range of use of the vehicle, and the spatial range of use of the vehicle. The information processing apparatus according to claim 1.

5. The functional scope of use of the vehicle includes at least one of the following: the scope of the vehicle's doors that can be locked and unlocked; the scope of the vehicle's driving functions; the scope of the vehicle's HMI (Human Machine Interface) functions; the scope of content accessible in the vehicle; the scope of the vehicle's maintenance functions; and the scope of disclosure of the vehicle's driving status. The information processing apparatus according to claim 4.

6. The temporal scope of use of the said vehicle includes the period during which the said vehicle can be used. The information processing apparatus according to claim 4.

7. The spatial range of use of the vehicle includes the range in which the vehicle can move. The information processing apparatus according to claim 4.

8. The communication unit transmits the digital key to the information processing terminal. The information processing apparatus according to claim 1.

9. The communication unit further transmits the usage rule information to the information processing terminal. The information processing apparatus according to claim 8.

10. The key management unit generates a pair key containing authentication information used for authenticating the digital key, The communication unit transmits the pair key to the vehicle. The information processing apparatus according to claim 8.

11. Information processing device, To generate a digital key for using the vehicle, The usage rules indicating the scope of use of the aforementioned vehicle are set for each role, The usage rules set for the role assigned to the user are set for the digital key granted to the user, The digital key is transmitted to at least one of the vehicle and the information processing terminal that uses the digital key, and usage rule information indicating the usage rules is transmitted to the vehicle. Information processing methods including

12. The information processing device that generated the digital key receives a digital key from the information processing terminal and receives usage rule information from the information processing device that generated the digital key, which indicates usage rules set based on the role assigned to the user to whom the digital key is assigned. Based on the usage rule information, the key management unit controls the range of vehicle use. A vehicle control system that is equipped with this system.

13. The key management unit includes authentication information used for authenticating the digital key, and authenticates the digital key based on the pair key generated by the information processing device. If the authentication of the digital key is successful, it controls the usage range of the vehicle based on the usage rules set for the digital key. The vehicle control device according to claim 12.

14. The key management unit changes the content of the usage rules in the event of an emergency. The vehicle control device according to claim 12.

15. The aforementioned usage rules indicate at least one of the following: the functional range of use of the vehicle, the temporal range of use of the vehicle, and the spatial range of use of the vehicle. The vehicle control device according to claim 12.

16. The functional scope of use of the vehicle includes at least one of the following: the scope of the vehicle's doors that can be locked and unlocked; the scope of the vehicle's driving functions; the scope of the vehicle's HMI functions; the scope of content accessible in the vehicle; the scope of the vehicle's maintenance functions; and the scope of disclosure of the vehicle's driving status. The vehicle control device according to claim 15.

17. The temporal scope of use of the said vehicle includes the period during which the said vehicle can be used. The vehicle control device according to claim 15.

18. The spatial range of use of the vehicle includes the range in which the vehicle can move. The vehicle control device according to claim 15.