In-vehicle devices, servers, and computer programs

The in-vehicle device communicates with a server to authenticate passengers and adjust vehicle settings, ensuring a consistent experience across different vehicles by utilizing learned preferences.

JP7861867B2Active Publication Date: 2026-05-19SUMITOMO ELECTRIC INDUSTRIES LTD +2
View PDF 7 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
SUMITOMO ELECTRIC INDUSTRIES LTD
Filing Date
2023-12-25
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing in-vehicle systems fail to utilize learning results across different vehicles, leading to inconsistent passenger experience due to different notification models.

Method used

An in-vehicle device that communicates with a server to acquire and process information, authenticates passengers, and adjusts vehicle settings based on individual preferences, allowing seamless adaptation across vehicles.

Benefits of technology

Enables passengers to enjoy a personalized environment regardless of the vehicle they are in, enhancing security and convenience through adaptive equipment adjustments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007861867000001
    Figure 0007861867000001
  • Figure 0007861867000002
    Figure 0007861867000002
  • Figure 0007861867000003
    Figure 0007861867000003
Patent Text Reader

Abstract

This vehicle-mounted device for providing a vehicle-mounted device that makes it possible for a passenger to enjoy an environment that is appropriate for the passenger, regardless of a vehicle in which the passenger is riding, includes: an information acquiring unit for acquiring information associated with the passenger of the vehicle by means of communication with a server; and a processing execution unit which is connected to a vehicle-mounted network of the vehicle and which uses a resource that can communicate via the vehicle-mounted network to execute processing in accordance with the information acquired by the information acquiring unit.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to in-vehicle devices, driving support systems, servers, and computer programs. This application claims priority based on Japanese Patent Application No. 2023-002768 filed on January 12, 2023, and incorporates all the descriptions set forth in the said Japanese application.

Background Art

[0002] In order to strengthen regulations regarding automobiles in various countries, address environmental issues, and further meet user needs, the functions required for automobiles are increasing, and the digitalization of automobiles is progressing to address such issues. The digitalization of vehicles is used not only for the safe driving functions of vehicles but also to provide comfort to passengers such as drivers.

[0003] A proposal for this is disclosed by Patent Document 1 below. The technology disclosed in Patent Document 1 is a technology for notifying appropriate recommendations regarding rest during driving in consideration of individual differences among passengers. The device disclosed in Patent Document 1 authenticates the passengers of the vehicle in which the device is installed and detects the biometric information of the passengers. Further, for each authenticated passenger, this device obtains action information corresponding to the biometric information based on a notification model and notifies the passenger of the notification content (recommendation content) including the action information. This device further learns the notification model based on the action results of the passengers with respect to the notification.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

[0005] An in-vehicle device according to one aspect of the present disclosure includes an information acquisition unit that acquires information associated with a vehicle occupant by communication with a server, and a processing execution unit that is connected to the vehicle's in-vehicle network and performs processing according to the information acquired by the information acquisition unit using resources that can communicate via the in-vehicle network.

[0006] This disclosure can be implemented not only as an in-vehicle device equipped with such characteristic processing, but also as an operating method for an in-vehicle device with such characteristic processing as a step, or as a program for causing a computer to execute such steps. Furthermore, it can be implemented as a semiconductor integrated circuit that realizes part or all of the in-vehicle device, or as a driver assistance system including the in-vehicle device. [Brief explanation of the drawing]

[0007] [Figure 1] Figure 1 is a hardware block diagram showing the configuration of a driver assistance system including a functional extension ECU (Electronic Control Unit) according to the first embodiment of this disclosure. [Figure 2] Figure 2 is a block diagram showing the hardware and software configuration of the function-enhancing ECU shown in Figure 1. [Figure 3] Figure 3 is a block diagram showing the hardware configuration of the processor shown in Figure 2. [Figure 4] Figure 4 is a block diagram showing the relationships between the various functions realized by the function-enhancing ECU shown in Figure 1. [Figure 5] Figure 5 shows the configuration of the adjustment instruction unit shown in Figure 4. [Figure 6] Figure 6 is a block diagram showing the hardware configuration of the server shown in Figure 5. [Figure 7] Figure 7 is a block diagram showing the functional configuration of the server shown in Figure 5. [Figure 8] Figure 8 is a flowchart showing the control structure of the program executed by the function enhancement ECU of the driver assistance system shown in Figure 1. [Figure 9]Figure 9 is a flowchart showing the control structure of the program that implements the change information transmission unit shown in Figure 4, which is executed by the function enhancement ECU shown in Figure 1 when it is detected that a vehicle occupant has made adjustments to the onboard equipment. [Figure 10] Figure 10 is a flowchart showing the control structure of the program that implements the information transmission request receiving unit, setting information retrieval unit, and setting information transmission unit shown in Figure 7, which are executed when the server shown in Figure 5 receives an information transmission request from the function extension ECU. [Figure 11] Figure 11 is a flowchart showing the control structure of a program that implements the processing performed when the server shown in Figure 5 receives a request to update configuration information from the function expansion ECU. [Figure 12] Figure 12 is a block diagram showing the functional configuration of a personalized driver assistance system according to a second embodiment of this disclosure. [Figure 13] Figure 13 is a block diagram showing the relationships between the various functions realized by the function-enhanced ECU according to the second embodiment shown in Figure 12. [Figure 14] Figure 14 is a flowchart showing the control structure of the program that the function-enhanced ECU shown in Figure 12 executes upon completion of passenger authentication, and which realizes the functions of the information acquisition unit shown in Figure 13. [Figure 15] Figure 15 is a functional block diagram showing the relationships between the various functions implemented by the server shown in Figure 12. [Figure 16] Figure 16 is a flowchart showing the control structure of a program that implements the key information transmission request receiving unit, configuration information retrieval unit, key information extraction unit, and key information transmission unit shown in Figure 15, which are executed on the server shown in Figure 12. [Figure 17] Figure 17 is a functional block diagram showing the relationships between the functions realized by the functional extension ECU according to a modified example of the second embodiment shown in Figure 12. [Figure 18] Figure 18 is a flowchart showing the control structure of the program for realizing each function of the function-enhancing ECU shown in Figure 17. [Figure 19]FIG. 19 is a functional block diagram showing the relationships of the respective functions realized by the server according to a modification of the second embodiment. [Figure 20] FIG. 20 is a flowchart showing the control structure of a program that is executed when the server according to a modification of the second embodiment receives a request for adding key information from a third party, and that realizes the key information update unit shown in FIG. 19. [Figure 21] FIG. 21 is a block diagram showing the configuration of a personalized driving support system according to a third embodiment of this disclosure. [Figure 22] FIG. 22 is a block diagram showing the relationships of the respective functions realized by the function expansion ECU according to the third embodiment shown in FIG. 21. [Figure 23] FIG. 23 is a flowchart showing the control structure of a program that realizes the functions of the function expansion EC according to the third embodiment shown in FIG. 21. [Figure 24] FIG. 24 is a flowchart showing the control structure of a program that is executed by the function expansion ECU according to the third embodiment shown in FIG. 2, and that realizes the physical condition recognition unit shown in FIG. 22. [Figure 25] FIG. 25 is a flowchart showing the control structure of a program that is executed by the function expansion ECU according to the third embodiment shown in FIG. 21, and that realizes the scheduling unit 1 shown in FIG. 22. [Figure 26] FIG. 26 is a state transition diagram showing the state transition in a program that is executed by the function expansion ECU according to the third embodiment shown in FIG. 21. [Figure 27] FIG. 27 is a block diagram showing the relationships of the respective functions realized by the server according to the third embodiment shown in FIG. 21. [Figure 28] FIG. 28 is a flowchart showing the control structure of a program that is executed by the server according to the third embodiment shown in FIG. 21, and that realizes the facility control unit shown in FIG. 27. MODE FOR CARRYING OUT THE INVENTION

[0008] [Problems to be Solved by the Present Disclosure] It is considered that there is still room for improvement in the technology disclosed in Patent Document 1. For example, even if learning of a notification model is performed, the result is reflected only in the vehicle equipped with this device and not in other devices. When the same passenger drives a vehicle equipped with another device, a different notification model is used. Therefore, there is a possibility that the learning result may not be utilized.

[0009] An object of this disclosure is to provide an in-vehicle device, a driving support system, a server, and a computer program that enable an individual to enjoy an appropriate environment for the individual regardless of the vehicle the individual rides in.

[0010] [Effects of the Present Disclosure]

[0011] As described above, according to this disclosure, it is possible to provide an in-vehicle device, a driving support system, a server, and a computer program that enable a passenger to enjoy an appropriate environment for the passenger regardless of the vehicle the passenger rides in. [Description of Embodiments of the Present Disclosure] In the following description and drawings, the same parts are denoted by the same reference numerals. Therefore, detailed descriptions thereof will not be repeated. Note that at least a part of the embodiments described below may be arbitrarily combined.

[0012] (1) The in-vehicle device according to the first aspect of this disclosure includes an information acquisition unit that acquires information associated with a passenger of a vehicle through communication with a server, and a processing execution unit that is connected to an in-vehicle network of the vehicle and executes processing according to the information acquired by the information acquisition unit using a resource communicable via the in-vehicle network. With this configuration, it is possible to provide an in-vehicle device that enables an individual to enjoy an appropriate environment for the individual regardless of the vehicle the individual rides in.

[0013] (2) In the above (1), the in-vehicle device further includes a passenger authentication unit that authenticates the passenger. By performing passenger authentication, the security of the in-vehicle device can be enhanced.

[0014] (3) In (2) above, the passenger authentication unit may include a facial image authentication unit provided in the vehicle that authenticates the passenger using a facial image. This configuration provides an in-vehicle device that allows an individual to enjoy an appropriate environment regardless of the vehicle they are riding in.

[0015] (4) In any one of (1) to (3) above, the information may include adjustment information relating to the adjustment of equipment inside the vehicle when the passenger boards the vehicle, and the processing execution unit may include an adjustment instruction unit that instructs other devices via the in-vehicle network to automatically adjust the position of the parts used by the passenger in the vehicle equipped with the in-vehicle device using the adjustment information. This configuration makes it possible to provide an in-vehicle device that allows an individual to use equipment that is appropriately adjusted for that individual, regardless of the vehicle they are riding in.

[0016] (5) In (4) above, the adjustment information may include state specification information that specifies the state of the equipment when the passenger boards the vehicle, and the adjustment instruction unit may include a state identification unit that identifies the state closest to the state specified by the state specification information among the states that the equipment can take in the vehicle on which the in-vehicle device is installed, and an equipment adjustment instruction unit that instructs the other device to adjust the state of the equipment used by the passenger to the state identified by the state identification unit. With this configuration, an in-vehicle device can be provided that allows an individual to enjoy an environment in which the vehicle's equipment is set to a state appropriate for that individual, regardless of the vehicle they are riding in.

[0017] (6) In the above (5), the in-vehicle device may further include a change information transmission unit that, in response to the passenger manually changing the state of the equipment used by the passenger after the state of the equipment used by the passenger has been adjusted by the other device, transmits information identifying the passenger and the state of the equipment after the change to the server. This configuration provides an in-vehicle device that allows an individual to use equipment that has been appropriately adjusted for that individual, regardless of the vehicle they are riding in, based on the results of adjusting the equipment in a certain vehicle.

[0018] (7) In the above (5), the in-vehicle device may further include a change information transmission unit that, in response to the passenger manually changing the state of the equipment used by the passenger after the state of the equipment used by the passenger has been adjusted by the other device, transmits information identifying the passenger, the state of the equipment after the change, and information regarding the type of vehicle to the server. This configuration provides an in-vehicle device that allows an individual to use equipment that has been appropriately adjusted for that individual, even if the vehicle is not of the same type as the vehicle they are riding in, as long as it is of the same type.

[0019] (8) In any one of (5) to (7) above, the equipment may include at least one of the following: a seat position adjustment device for the seat used by the passenger among the seats of the vehicle, an electric mirror device for the vehicle, and an air conditioning system installed in the vehicle. This configuration provides an in-vehicle device that allows an individual to enjoy an environment in which the equipment has been appropriately adjusted for that individual, even if the vehicle is not of the same make and model as the vehicle in question, as long as it is of the same type.

[0020] (9) In any one of (1) to (3) above, the information may include key information for an automatic garage opening and closing device used by the passenger, and the processing execution unit may include an opening and closing instruction unit that, in response to the fulfillment of predetermined conditions, instructs other devices via the in-vehicle network to operate the automatic opening and closing device using the key information. This configuration provides an in-vehicle device that allows an individual to use the automatic garage opening and closing function regardless of the vehicle they are riding in.

[0021] (10) In (9) above, the information may further include validity control information that controls the validity of the key information included in the information, and the processing execution unit may further include a validity determination unit that prohibits the opening / closing instruction unit from using key information that has been determined to be invalid by referring to the validity control information among the key information included in the information. With this configuration, an in-vehicle device can be provided that allows an individual to use the automatic opening / closing function even in a garage other than their own, as long as it is within the validity period, regardless of the vehicle they are riding in.

[0022] (11) In any one of (1) to (3) above, the information may include information relating to externally controllable equipment located at the residence used by the passenger after using the vehicle, and the processing execution unit may include a physical condition recognition unit that recognizes the physical condition of the passenger, and a scheduling unit that selects at least one of the functions of the equipment at the passenger's residence according to the physical condition recognized by the physical condition recognition unit and schedules the activation of that function. With this configuration, an in-vehicle device can be provided that allows an individual to have an environment prepared in advance to restore their physical condition when they return to their residence, regardless of the vehicle they are riding in.

[0023] (12) In (11) above, the scheduling unit may include a scheduling unit that selects at least one of the functions of the equipment at the passenger's residence according to the physical condition recognized by the physical condition recognition unit and creates a schedule for activating that function, and a request unit that transmits the schedule created by the scheduling unit to the server and requests that the equipment at the passenger's residence be controlled according to the schedule. With this configuration, an in-vehicle device can be provided in which an environment is prepared in advance for each piece of equipment so that an individual can adjust their physical condition when they return to their residence, regardless of the vehicle they are riding in.

[0024] (13) In (11) above, the scheduling unit may include a scheduling unit that selects at least one of the functions of the equipment at the passenger's residence according to the physical condition recognized by the physical condition recognition unit and creates a schedule for activating that function, and a request unit that transmits the schedule created by the scheduling unit to a home server in the residence and requests that the equipment at the residence be controlled according to the schedule. With this configuration, an in-vehicle device can be provided in which each piece of equipment is pre-adjusted so that the individual can adjust their physical condition when they return to their residence, regardless of the vehicle the individual is riding in.

[0025] (14) In any one of the above (1) to (13), the passenger may also be the driver of the vehicle. With this configuration, the above effects can be obtained even when an individual is the driver.

[0026] (15) In any one of (1) to (14) above, the in-vehicle device may further include a storage unit for storing the information acquired by the information acquisition unit, and the information acquisition unit may include a search unit for searching for information associated with the passenger in the storage unit, an information storage unit for acquiring information associated with the passenger by communication with the server and storing it in the storage unit in response to the search by the search unit failing, and a selection unit for selectively outputting the output of the search unit and the information acquired by the information storage unit to the processing execution unit, depending on whether the search by the search unit was successful or not. With this configuration, an in-vehicle device can be provided in which only individuals whose information is stored in the information acquisition unit can enjoy the various effects described above.

[0027] (16) A driver assistance system relating to a second aspect of this disclosure is a personalized driver assistance system including a server and sensors and in-vehicle devices mounted on a vehicle, wherein the server includes a storage unit that stores an individual's identification information and information related to the individual in association with each other, and an information transmission unit that, in response to receiving an information transmission request from the in-vehicle device specifying the individual's identification information, reads the information associated with the identification information from the storage unit and transmits it to the in-vehicle device, the in-vehicle device includes an information acquisition unit that acquires the information associated with the passenger from the server by requesting the information transmission unit of the server to transmit the information associated with the passenger of the vehicle, and a processing execution unit connected to the vehicle's in-vehicle network that performs processing according to the information acquired by the information acquisition unit using resources that can communicate via the in-vehicle network. This configuration makes it possible to provide a driver assistance system that allows an individual to enjoy an appropriate environment for that individual, regardless of the vehicle they are riding in.

[0028] (17) The server relating to the third aspect of this disclosure includes a storage unit that stores an individual's identification information and information related to that individual in relation to each other, and an information transmission unit that, in response to receiving an information transmission request from an external in-vehicle device specifying an individual's identification information, reads the information associated with the identification information from the storage unit and transmits it to the in-vehicle device. This configuration provides a function that allows an individual to enjoy an appropriate environment regardless of the vehicle they are riding in.

[0029] (18) In paragraph (17) above, the information may include at least one of the following: adjustment information relating to the adjustment of equipment inside the vehicle when the individual boards the vehicle; key information for an automatic opening and closing device of a garage used by the individual; and information relating to externally controllable equipment located in a residence used by the individual after using the vehicle. This configuration allows the individual to enjoy a suitable environment for controlling equipment inside the vehicle, an automatic opening and closing device of the garage, or equipment at their residence, regardless of the vehicle they are boarding.

[0030] (19) In the above (17) or (18), the server may further include an update unit that, in response to receiving an individual's identification information and information related to that individual from the external in-vehicle device, adds the combination of the identification information and the information to the storage unit if it is not already stored therein, and updates the stored information about the individual using the information about the individual received from the external in-vehicle device if the combination is already stored therein. This configuration allows for the provision of a service in which only individuals whose information is stored in the information acquisition unit can enjoy the various effects described above.

[0031] (20) In (18) above, the information may include information relating to externally controllable equipment located at the residence used by the individual after using the vehicle, and the server may further include an equipment control unit that, in response to receiving the individual's identification information and a scheduling request relating to the controllable equipment relating to the individual from the external in-vehicle device, performs control of the equipment relating to the individual based on the control instructions. This configuration makes it possible to provide a service in which each piece of equipment is pre-adjusted so that the individual can get back in shape when they return to their residence, regardless of the vehicle they are riding in.

[0032] (21) The computer program relating to the fourth aspect of this disclosure causes the computer to function as an information acquisition unit that acquires information associated with a vehicle occupant by communication with a server, and a processing execution unit that is connected to the vehicle's in-vehicle network and executes processing according to the information acquired by the information acquisition unit using resources that can communicate via the in-vehicle network. This configuration provides a function that allows an individual to enjoy an appropriate environment regardless of the vehicle they are riding in.

[0033] [Details of the embodiments of this disclosure] Specific examples of in-vehicle devices, driver assistance systems, servers, and computer programs according to embodiments of this disclosure will be described below with reference to the drawings. However, this disclosure is not limited to these examples and is intended to include all modifications within the meaning and scope of the claims as indicated by the claims.

[0034] 1. First Embodiment A.Configuration A1. Overall structure Figure 1 shows a hardware block diagram of a driver assistance system 50 according to the first embodiment of this disclosure. Referring to Figure 1, the driver assistance system 50 includes an in-vehicle system 60 and a server 62. The in-vehicle system 60 is wirelessly connected to the Internet and can communicate with the server 62 via the Internet.

[0035] A2. Configuration of the in-vehicle system 60 The in-vehicle system 60 includes an autonomous driving ECU 70 for processing the autonomous driving of the vehicle on which the in-vehicle system 60 is installed, numerous other ECUs (not shown) for controlling various parts of the vehicle, and a function enhancement ECU 72 equipped with functions that can realize various functions for driver assistance. The function enhancement ECU 72 is connected to ECUs such as the autonomous driving ECU 70 by an in-vehicle network (not shown). Among the various ECUs and other functional units described later, the functional units connected to the in-vehicle network can communicate with each other via the in-vehicle network.

[0036] As described later, the function-enhancing ECU 72 can execute various applications and run multiple applications in parallel. Therefore, while it is difficult for the function-enhancing ECU 72 to provide core functions of safe driving such as driving, stopping, and turning, it can provide various functions by switching and running various applications. For example, by transferring some of the functions from the autonomous driving ECU 70 to the function-enhancing ECU 72, the load on the autonomous driving ECU 70 can be reduced. In addition, compared to using dedicated ECUs to realize those functions, the number of ECUs can be reduced, and the harness for connecting the ECUs to the network can also be reduced. Furthermore, the function-enhancing ECU 72 according to this embodiment is equipped with various input / output interfaces, and can receive data necessary for executing applications from other devices via these interfaces.

[0037] The in-vehicle system 60 further includes a biosensor 76 connected to a function-enhancing ECU 72 for acquiring and outputting biometric information for biometric authentication of an occupant attempting to board the vehicle. The function-enhancing ECU 72 has the function of performing facial recognition processing of the occupant using the output of the biosensor 76, as described later. In this embodiment, the authentication process is performed by the function-enhancing ECU 72 installed in the vehicle. However, this disclosure is not limited to such an embodiment. For example, the occupant may be authenticated by an authentication device installed outside the vehicle (such as in a garage), and the in-vehicle system 60 may receive the authentication result from the authentication device. Furthermore, authentication may be performed not only by facial recognition, but also by biometric authentication such as fingerprints, veins, iris, gait, voice, or signature, or by using an authentication mechanism other than biometric authentication (for example, a password, an authentication IC (Integrated Circuit) card, or authentication by a smartphone equipped with an authentication function). In addition, combinations of multiple types of biometric authentication, or combinations of biometric authentication and non-biometric authentication mechanisms can be used.

[0038] The in-vehicle system 60 is further connected to a function-enhancing ECU 72 via an in-vehicle network and includes a TCU (Telematics Control Unit) 74 for wireless communication using various communication standards, and a BCU (Body Control Unit) 78 for adjusting various parts of the vehicle body, which is also connected to the function-enhancing ECU 72 via an in-vehicle network. The BCU 78 is connected to a seat adjustment unit 80 for adjusting the seat position according to the control of the BCU 78, and a mirror adjustment unit 82 for adjusting the position (attitude, angle) of electric mirrors such as the interior mirror and the side door mirrors according to the control of the BCU 78. The BCU 78 is further connected to an air conditioning adjustment unit 84 for controlling the air conditioner (hereinafter simply referred to as "air conditioner") mounted in the vehicle according to the control of the BCU 78, a lighting adjustment unit 86 for turning the interior lights on and off and adjusting the brightness according to the control of the BCU 78, and various other adjustment units 88 for adjusting other parts.

[0039] Figure 2 shows the hardware and software configuration of the function-enhancing ECU 72. Referring to Figure 2, the function-enhancing ECU 72 includes a hardware layer 130 that provides the resources underlying various functions, a foundational software layer 132 that runs using the resources provided by the hardware layer 130 and provides an execution environment for various applications by utilizing the resources provided by the hardware layer 130, and an application layer 134 that includes multiple applications that can be executed in parallel by the hardware layer 130 via services provided by the foundational software layer 132.

[0040] The hardware layer 130 includes an ECU, which is a basic hardware resource; a processor mounted on the ECU; a dedicated image compression processor used when transmitting images; and various communication I / Fs, which are interfaces (I / Fs) between the processor and the dedicated image compression processor and various external devices and networks.

[0041] The underlying software layer 132 includes an OS (Operating System) similar to that used in a normal computer, a security system, I / F drivers, and OTA (Over-The-Air) that operate on top of the OS, and middleware for determining the timing of the start and end of each application's operation based on the vehicle's status, and for launching and shutting down each application.

[0042] As described above, application layer 134 includes multiple applications. Each application performs various functions individually or in cooperation with others. These applications can be replaced and updated at any time via OTA (Over-the-Air).

[0043] Figure 3 shows the hardware configuration of the processor 180 shown in Figure 2. Referring to Figure 3, this processor includes an MPU (Micro Processing Unit) 202, a high-speed bus 200 to which the MPU 202 is connected, an SRAM (Static Random Access Memory) 204 connected to the high-speed bus 200, a flash memory 206 connected to the high-speed bus 200, and a ROM (Read-Only Memory) 208 connected to the high-speed bus 200. The SRAM 204 holds data necessary for program execution. The flash memory 206 stores a program 226 for realizing the functions realized by the underlying software layer 132. The ROM 208 stores the boot-up program for the MPU 202, etc.

[0044] The processor further includes a slow bus 210 connected to the high-speed bus 200 via a bridge 212, and a serial interface 214, an analog-to-digital converter (ADC) 216, a timer / counter 218, a clock generator 220, a power supply control unit 222, and a general-purpose interface 224, all connected to the slow bus 210.

[0045] Since the operation of the processor is well known, and what is meaningful in the embodiments is the functionality of the program it executes, the operation of the processor itself will not be described below.

[0046] Figure 4 is a block diagram showing the relationships between the various functions implemented by the function-enhanced ECU 72 shown in Figure 1. Referring to Figure 4, each function implemented by the function-enhanced ECU 72 includes: a passenger identifier storage unit 276 that stores an identifier that uniquely identifies the individual subject to biometric authentication (vehicle occupant, such as the driver); a biometric authentication unit 274 that performs biometric authentication of an individual using the output of the biometric sensor 76 shown in Figure 1, and when authentication is successful, reads the authenticated individual's identifier from the passenger identifier storage unit 276 and outputs it; and an information acquisition unit 278 that sends an information transmission request including the passenger identifier output by the biometric authentication unit 274 to the server 62 shown in Figure 1, and receives setting information regarding the authenticated occupant from the server 62.

[0047] In this embodiment, the setting information includes the seat position when a specific individual boards the vehicle, the position (position and angle) of the electric mirrors, the on / off status of the air conditioner and the set temperature when it is on, and the illuminance of the interior lighting, and is maintained by the server 62 shown in Figure 1. This setting information is stored and maintained in the server 62 in association with the passenger's identifier and, for example, the vehicle type information of vehicles that the specific passenger has previously boarded.

[0048] Referring again to Figure 4, the function-enhancing ECU 72 further includes a processing execution unit 280 for executing predetermined processing based on the setting information acquired by the information acquisition unit 278. In this embodiment, the processing execution unit 280 includes an adjustment instruction unit 300 for sending setting information to the BCU 78 to adjust the seat adjustment unit 80, mirror adjustment unit 82, air conditioning adjustment unit 84, lighting adjustment unit 86, etc., using the setting information acquired by the information acquisition unit 278, and instructing the BCU 78 to perform the adjustment of each unit. The BCU 78 performs the adjustment of each unit according to this instruction.

[0049] The enhanced ECU 72 further includes a vehicle information storage unit 282 that stores vehicle information indicating the vehicle type of the vehicle in which the enhanced ECU 72 is installed, and a change information transmission unit 284 that, in response to receiving information from the BCU 78 indicating that the passenger has readjusted the settings of each part after the BCU 78 has made adjustments to each part, transmits the settings after the passenger's readjustment along with the vehicle information stored in the vehicle information storage unit 282 and the passenger's identifier as an update request to the server 62, requesting that the settings information for this passenger be updated.

[0050] Figure 5 shows the configuration of the adjustment instruction unit 300. The adjustment instruction unit 300 shown in Figure 5 shows the configuration for adjusting, for example, the seat adjustment unit 80. In addition to this, the adjustment instruction unit 300 has separate configurations for the mirror adjustment unit 82, the air conditioning adjustment unit 84, the lighting adjustment unit 86, and so on.

[0051] Referring to Figure 5, the adjustment instruction unit 300 includes a configurable information storage unit 352 for storing configurable information indicating what values ​​can be set as the seat position in a vehicle equipped with the in-vehicle system 60, a state identification unit 350 for comparing the seat setting information received from the information acquisition unit 278 (see Figure 4) with the configurable information stored in the configurable information storage unit 352, and if the received seat setting information and the configurable information are different, for determining the seat setting so that it is in a state closest to the position determined by the received seat setting information among the configurable values, and an equipment adjustment instruction unit 354 for instructing the BCU 78 to adjust the seat position according to the seat setting identified by the state identification unit 350.

[0052] A3. Server 62 Configuration Figure 6 is a block diagram showing an example of the hardware configuration of the server 62 shown in Figure 1. Referring to Figure 6, this server 62 includes a computer 470 having a DVD (Digital Versatile Disc) drive 502, and a keyboard 474, a mouse 476, and a monitor 472, all connected to the computer 470, for user interaction. Of course, these are just one example of a configuration for when user interaction is required, and any general hardware and software available for user interaction (e.g., touch panels, voice input, pointing devices in general) can be used.

[0053] Computer 470 includes, in addition to the DVD drive 502, a CPU (Central Processing Unit) 490, a GPU (Graphics Processing Unit) 492, a bus 510 connected to the CPU 490, GPU 492, and DVD drive 502, a ROM 496 connected to the bus 510 that stores the computer 470's boot-up program and the like, a RAM (Random Access Memory) 498 connected to the bus 510 that stores program instructions, system programs, and work data, and a non-volatile memory SSD (Solid State Drive) 500 connected to the bus 510. The SSD 500 is for storing programs executed by the CPU 490 and GPU 492, as well as data used by programs executed by the CPU 490 and GPU 492. The computer 470 further includes a network interface 508 that provides connectivity to the network 486, and a USB port 506 that allows for the insertion and removal of a USB (Universal Serial Bus) memory 484 and provides communication between the USB memory 484 and various parts within the computer 470. In this embodiment, the network 486 is the internet.

[0054] Computer 470 further includes an audio interface 504 connected to a microphone 482, a speaker 480, and a bus 510, which reads audio signals, video signals, and text data generated by the CPU 490 and stored in RAM 498 or SSD 500 according to the instructions of the CPU 490, performs analog conversion and amplification processing to drive the speaker 480, and digitizes the analog audio signal from the microphone 482 and stores it in RAM 498 or SSD 500 at any address specified by the CPU 490.

[0055] The computer programs that enable the server 62 to perform the functions described later are stored on a DVD 478 inserted into the DVD drive 502 and transferred from the DVD drive 502 to the SSD 500. Alternatively, these programs are stored on a USB memory 484, the USB memory 484 is inserted into the USB port 506, and the programs are transferred to the SSD 500. Alternatively, these programs may be transmitted to a computer 470 via the network 486 and stored on the SSD 500.

[0056] The program is loaded into RAM 498 at runtime. Of course, the source program can also be input using the keyboard 474, monitor 472, and mouse 476, and the compiled object program can be stored in SSD 500. In the case of a program that runs in a virtual machine, the program that functions as a virtual machine must be installed on computer 470 beforehand. Furthermore, if it is anticipated that there will be a large number of in-vehicle systems 60 that connect to server 62 as clients, it is desirable to distribute the load by configuring server 62 as a distributed system.

[0057] The CPU 490 reads and executes the program from the RAM 498 and stores the execution result data at a predetermined address. The computer program may also be loaded directly into the RAM 498 from the DVD 478, from the USB memory 484, or via the network.

[0058] The programs that implement the functions of each server component according to the embodiments described below include a plurality of instructions written and arranged to operate the computer 470 to implement those functions. These programs only need to include instructions that execute the desired functions by statically or dynamically linking appropriate functions or program routines to obtain the desired results. The methods for operating the computer 470 for this purpose are well known and will not be repeated here.

[0059] Figure 7 is a functional block diagram showing the functional configuration of server 62. Referring to Figure 7, server 62 includes a configuration information DB (Database) 566 that stores various personal identifiers associated with configuration information of the in-vehicle system related to those individuals, and an information transmission request receiving unit 560 for receiving information transmission requests from the in-vehicle system 60 and the like. Server 62 further includes a configuration information retrieval unit 562 that searches the configuration information DB 566 using the personal identifier included in the information transmission request received by the information transmission request receiving unit 560 and retrieves the configuration information corresponding to that identifier from the configuration information DB 566, and a configuration information transmission unit 564 that transmits the configuration information retrieved by the configuration information retrieval unit 562 to the in-vehicle system 60, which is the source of the information transmission request.

[0060] The server 62 further includes an update request receiving unit 568 for receiving update requests for configuration information from the in-vehicle system 60, and a configuration information update unit 570 for updating configuration information stored in the configuration information DB 566 that is associated with identifiers included in the update requests received by the update request receiving unit 568, using the configuration values ​​included in the update requests.

[0061] A4. Program configuration of the in-vehicle system 60 Figure 8 is a flowchart showing the control structure of the program executed by the in-vehicle system 60. The functions implemented by this program correspond to the biometric authentication unit 274 and the information acquisition unit 278 shown in Figure 4. Referring to Figure 8, this program includes a step 620 in which facial image authentication is performed based on the output of the biometric sensor 76, and a step 622 in which the control flow is branched depending on whether the facial image authentication in step 620 was successful or not. If facial image authentication fails, the process is terminated in step 632 by notifying the authentication failure. In this case, "notification" may be, for example, an audible notification to a person attempting to enter the vehicle, or it may simply be logging a record of the authentication failure within the system.

[0062] This program further includes step 624, which is executed in response to the determination in step 622 being affirmative, and which sends a setting information transmission request to the server 62 regarding setting information corresponding to a combination of an individual identifier obtained as a result of authentication and vehicle type information of the vehicle on which the in-vehicle system 60 is installed; and step 626, which receives a reply from the server 62 to the setting information transmission request sent in step 624, and branches the control flow according to whether or not the setting information was available at the server 62. This program further includes step 630, which, in response to the determination in step 624 being affirmative, sends the setting information received from the server 62 to the adjustment instruction unit 300 shown in Figure 4 and terminates the execution of this program; and step 628, which, in response to the determination in step 624 being negative, notifies the adjustment instruction unit 300 that there is no setting information and terminates the execution of this program.

[0063] Figure 9 shows the control structure of the program that implements the processing corresponding to the change information transmission unit 284 shown in Figure 4. As mentioned above, after the seat position is automatically adjusted by the adjustment instruction unit 300, when the passenger readjusts the seat position, information regarding the readjusted seat position is output from the BCU 78 to the change information transmission unit 284. The program shown in Figure 9 is activated when this information regarding the readjusted seat position is input from the BCU 78 to the function extension ECU 72.

[0064] Referring to Figure 9, this program includes step 690, in which the information acquisition unit 278 compares the original setting information received from the server 62 with the modified setting information received from the BCU 78; step 692, in which the control flow is branched depending on whether the two are identical as a result of step 690; and step 694, in which, if the determination in step 692 is negative, the modified setting information is sent to the server 62 with the passenger (driver) identifier and the vehicle type information stored in the vehicle type information storage unit 282 attached, and the execution of this program ends. If the determination in step 692 is positive, the execution of this program ends immediately.

[0065] Even if a user resets their seat position, they may eventually revert to the original seat position after repeating the setting process several times. In such cases, sending the reset setting to server 62 is meaningless, so a check is provided in step 692. If the information about the reset seat position is sent to server 62 in step 694, server 62 uses that information to update the passenger's setting information. This point will be explained later.

[0066] Figure 10 is a flowchart showing the control structure of a program that implements the information transmission request receiving unit 560, setting information retrieval unit 562, and setting information transmission unit 564 of the server 62 shown in Figure 7. Referring to Figure 10, this program includes a step 720 that extracts the passenger identifier and vehicle type information from the received information transmission request, a step 722 that searches the setting information DB 566 (see Figure 7) using the extracted identifier and vehicle type information as keys, and a step 724 that branches the control flow according to whether or not there is a record corresponding to the key as a result of step 722.

[0067] This program further includes step 732, which, if the determination in step 724 is positive, transmits the setting information retrieved from the search result setting information DB566 to the in-vehicle system 60 and terminates the execution of this program.

[0068] This program further includes, if the determination in step 724 is negative, step 726, which replaces the vehicle information with information about vehicle types similar to the vehicle type identified by the vehicle information retrieved and extracted in step 722, and searches the configuration information DB566 using the identifier and its vehicle information as keys, and step 728, which branches the control flow depending on whether or not there is a matching record as a result of the processing in step 726. If the determination in step 728 is negative, the control proceeds to step 732, as in the case of a positive determination in step 724.

[0069] This program further includes step 730, which, if the determination in step 728 is negative, sends a reply to the in-vehicle system 60 indicating that no configuration information corresponding to the information transmission request exists, and terminates the execution of this program. In step 728, if multiple matching records are found, one of them may be selected according to some criterion and sent to the in-vehicle system 60. For example, methods such as prioritizing models from the same manufacturer, or prioritizing models of the same grade regardless of the manufacturer, can be used.

[0070] Figure 11 is a flowchart showing the control structure of a program that implements the processing executed when the server 62 receives a request to update configuration information from the in-vehicle system 60. The functions implemented by this program correspond to the update request receiving unit 568 and the configuration information update unit 570 in Figure 7.

[0071] This program includes step 760, which extracts the passenger identifier, vehicle type information, and adjustment information from the update request; step 762, which searches the configuration information DB566 (Figure 7) using the identifier and vehicle type information obtained in step 760 as keys; and step 764, which branches the control flow according to whether or not a matching record exists as a result of the processing in step 762.

[0072] The program further includes, when the determination in step 764 is positive, step 768 which updates the setting information DB566 with the received setting information using the passenger identifier and vehicle type information as keys; when the determination in step 764 is negative, step 766 which adds setting information to the setting information DB566 using the passenger identifier and vehicle type information as keys; and step 770 which branches the control flow after the processing in steps 766 and 768 depending on whether or not any error occurred in the setting information DB566 as a result of these processes.

[0073] The program further includes step 774, which notifies the in-vehicle system 60 of the completion of the configuration information update and terminates the program execution when the determination in step 770 is negative, i.e., when the configuration information update or addition has been successfully performed; and step 772, which notifies the in-vehicle system 60 of the failure to update the configuration information and terminates the program execution when the determination in step 770 is positive, i.e., when the configuration information update or addition has not been successfully performed.

[0074] B. Operation The driver assistance system 50 according to the first embodiment, whose configuration has been described above, operates as follows. Referring to Figure 4, the passenger identifier storage unit 276 stores in advance an identifier that uniquely identifies the individual to be biometrically authenticated (a passenger in the vehicle, such as a driver). The biometric authentication unit 274 performs biometric authentication of the individual using the output of the biosensor 76 shown in Figure 1, and when authentication is successful, it reads the identifier of the authenticated individual from the passenger identifier storage unit 276 and outputs it to the information acquisition unit 278. If authentication fails (the judgment in step 622 in Figure 8 is negative), the authentication failure is notified to the individual. A person cannot use this vehicle unless they are authenticated.

[0075] If authentication is successful, the information acquisition unit 278 sends an information transmission request to the server 62 shown in Figure 1, which includes the passenger identifier output by the biometric authentication unit 274 and the vehicle type information.

[0076] Referring to Figure 7, the information transmission request receiving unit 560 of the server 62 receives an information transmission request from the in-vehicle system 60 and provides it to the setting information retrieval unit 562. The setting information DB 566 stores various personal identifiers and the setting information of the in-vehicle system related to those individuals in advance. The setting information retrieval unit 562 searches the setting information DB 566 using the personal identifier included in the received information transmission request, retrieves the setting information corresponding to that identifier from the setting information DB 566, and provides it to the setting information transmission unit 564. If the setting information retrieved by the setting information retrieval unit 562 contains setting information that includes the specified vehicle type information, the setting information transmission unit 564 transmits that information to the information acquisition unit 278 (Figure 4) of the in-vehicle system 60, which is the source of the information transmission request. If the setting information retrieval unit 562 does not find setting information corresponding to the specified identifier and vehicle type information (the determination in step 724 of Figure 10 is negative), a re-search is performed using identifiers of similar vehicle types (step 726 of Figure 10). If a matching record is found in this search (positive in step 728 of Figure 10), the setting information is transmitted from the setting information transmission unit 564 to the information acquisition unit 278 of the in-vehicle system 60 (step 732 of Figure 10). If the determination in step 728 is negative, the absence of setting information is transmitted to the information acquisition unit 278 (step 730 of Figure 10).

[0077] Referring to Figure 4, the information acquisition unit 278 receives setting information about the authenticated passenger from the server 62 and provides it to the adjustment instruction unit 300 of the processing execution unit 280. The adjustment instruction unit 300 uses the setting information acquired by the information acquisition unit 278 to send setting information to the BCU 78 for adjusting the seat adjustment unit 80, mirror adjustment unit 82, air conditioning adjustment unit 84, lighting adjustment unit 86, etc., and instructs the BCU 78 to perform the adjustments to each unit. The BCU 78 performs the adjustments to each unit according to these instructions.

[0078] As a result, when a passenger boards the vehicle, the seat position, the position and angle of the power mirrors, the air conditioning, and the lighting are all adjusted to their usual settings. Therefore, passengers can usually start driving comfortably without making any further adjustments.

[0079] However, human perception is not always the same, and sometimes the settings may need to be changed (readjusted). In that case, after the adjustment of each part by the BCU 78, the change information transmission unit 284 receives information from the BCU 78 indicating that the passenger has readjusted the settings of each part after boarding, and sends the readjusted settings information by the passenger to the server 62 as a setting information update request, along with the vehicle information stored in the vehicle information storage unit 282 and the passenger's identifier.

[0080] Referring to Figure 5, for example, the state identification unit 350 of the adjustment instruction unit 300 compares the sheet setting information received from the information acquisition unit 278 (see Figure 4) with the configurable information stored in the configurable information storage unit 352. If the received sheet setting information and the configurable information are different, the unit determines the sheet setting to be the closest to the position determined by the received sheet setting information among the configurable values. The equipment adjustment instruction unit 354 instructs the BCU 78 to adjust the sheet position according to the sheet setting identified by the state identification unit 350.

[0081] On the other hand, the server 62, upon receiving an update request from the change information transmission unit 284, operates as follows. Referring to Figure 7, the update request receiving unit 568 receives a setting information update request from the in-vehicle system 60. The setting information update unit 570 updates the setting information stored in the setting information DB 566, which is associated with the identifier and vehicle type information included in the update request received by the update request receiving unit 568, using the setting values ​​included in the update request. As a result, the setting information stored in the server 62 is updated with the latest information. If such information does not exist, the setting information update unit 570 adds that information to the setting information of the corresponding identifier.

[0082] As described above, according to this first embodiment, passenger setting information is stored in the server 62 in association with the passenger identifier along with vehicle type information. When a passenger is authenticated by biometric information when using the vehicle, setting information for each part of the vehicle for that vehicle and passenger combination is downloaded from the server to the vehicle, and each part of the vehicle is set to the state that the passenger frequently uses according to that setting information. Therefore, no matter which vehicle the passenger uses, they can use the vehicle in the setting state that they most frequently use when using that vehicle. If the passenger changes the settings, information about the changes is sent to the server, and the information stored on the server is updated using that information. Therefore, the passenger can always use a vehicle set according to the latest setting information. This has the effect of eliminating the need to set each vehicle separately as before.

[0083] 2. Second Embodiment A.Configuration A1. Overall structure The functional configuration of the driver assistance system 810 according to this second embodiment is shown in Figure 12. Referring to Figure 12, the driver assistance system 810 includes an in-vehicle system 820 and a server 822. The in-vehicle system 820 and the server 822 are able to communicate with each other. The driver assistance system 810 according to this embodiment relates to a system that can automatically open and close the door of, for example, the garage door of a passenger's home, even if the vehicle the passenger is in is a different vehicle than usual.

[0084] Referring to Figure 12, the in-vehicle system 820 includes a biosensor 76, an autonomous driving ECU 70, a TCU 74, a function extension ECU 840 according to this second embodiment, and a garage opening / closing unit 842 connected to the function extension ECU 840, which uses garage key information received from the function extension ECU 840 to communicate wirelessly with a nearby garage and to open and close the garage using an automatic opening / closing device controllable by the key information. In this embodiment, the function extension ECU 840 can store multiple key information entries up to a predetermined upper limit for a given occupant identifier. The function extension ECU 840 has the function of adding and storing new key information when it is stored, and deleting the oldest stored key information or the oldest used key information in its place.

[0085] Figure 13 is a block diagram showing the relationships between the various functions realized by the function-enhancing ECU 840 of the in-vehicle system 820 shown in Figure 12. Referring to Figure 13, the function-enhancing ECU 840 includes, in addition to the biometric authentication unit 274 and the passenger identifier storage unit 276, a key information storage unit 872 for storing key information available for each authenticated passenger identifier, and an information acquisition unit 870 that, when biometric authentication by the biometric authentication unit 274 is successful, outputs the key information if the key information corresponding to the authenticated passenger identifier is in the key information storage unit 872, or if not, sends a request to transmit information about the key information associated with that passenger identifier to the server 822 shown in Figure 12, receives the corresponding key information, and adds it to the key information storage unit 872. The information acquisition unit 870 outputs the acquired key information.

[0086] The function-enhanced ECU 840 further includes a processing execution unit 874 that performs predetermined processing using key information output from the key information storage unit 872. In this embodiment, the processing execution unit 874 includes an opening / closing instruction unit 900 that transmits the key information output by the key information storage unit 872 to a garage opening / closing unit 842, which is an automatic opening / closing device for a garage, thereby instructing the unit to open and close the door of a nearby garage using that key information.

[0087] Figure 14 shows the control structure of the program for realizing the information acquisition unit 870 shown in Figure 13. Referring to Figure 14, this program includes a step 620 for performing biometric authentication and a step 920 for branching the control flow depending on whether the biometric authentication in step 620 was successful or not. If the determination in step 920 is negative, the control proceeds to step 936, where the passenger is notified that there is no available key information and the execution of this program ends.

[0088] The program includes, if the determination in step 920 is positive, step 924, which searches for key information corresponding to the passenger identifier obtained as a result of authentication in the key information storage unit 872 shown in Figure 13; step 926, which branches the control flow according to whether or not key information corresponding to this identifier was found as a result of the search in step 924; and if the determination in step 926 is positive, the garage opening / closing unit 842, which transmits the key information found in the key information storage unit 872 in relation to this identifier to the garage opening / closing unit 842 shown in Figure 13 to terminate the execution of this program.

[0089] The program further includes step 928, which, in response to a negative determination in step 926, requests server 822 to send key information corresponding to this identifier; step 930, which branches the control flow depending on whether valid key information exists at server 822 and whether that key information has been received as a result of the processing in step 928; and step 932, which, if the determination in step 930 is positive, stores the key information received in step 930 in the key information storage unit 872 shown in Figure 13, associating it with the identifier being processed. After step 932, control proceeds to step 934, where the program sends this key information to the garage opening / closing unit 842 shown in Figure 13 and terminates execution.

[0090] The program further includes step 936, which, if the determination in step 920 is negative, or if the determination in step 930 is negative, notifies the passenger that no key information is available and terminates the execution of the program.

[0091] Figure 15 is a functional block diagram showing the relationships between the various functions implemented by the server 822. Referring to Figure 15, the server 822 includes a configuration information DB 958 that stores the identifier of a garage user in association with the key information of the garages it can use, a key information transmission request receiving unit 950 that receives a key information transmission request from the information acquisition unit 870 of the function extension ECU 840 shown in Figure 13, and a configuration information search unit 952 that, in response to the key information transmission request receiving unit 950 receiving a key information transmission request, searches the configuration information DB 958 using the identifier as a key, retrieves the configuration information from the configuration information DB 958 if it finds any matching configuration information, and outputs information indicating that the search failed if it does not. Server 822 further includes a key information extraction unit 954 that extracts key information from the configuration information DB 958 when the search by the configuration information search unit 952 is successful, and a key information transmission unit 956 that selects the key information extracted by the key information extraction unit 954 when the search by the configuration information search unit 952 is successful, and selects information indicating that the search failed otherwise, and sends it to the function extension ECU 840.

[0092] Server 822 further includes a key information addition request 960 for receiving a key information addition request from another device, such as a garage user, requesting that new key information be stored in the configuration information DB 958, and a key information update unit 962 for causing the key information addition request 960 to add and store configuration information associated with the user identifier attached to the key information addition request in the configuration information DB 958 in response to the key information addition request 960 receiving the request.

[0093] Figure 16 is a flowchart showing the control structure of a program for implementing the key information transmission request receiving unit 950, setting information retrieval unit 952, key information extraction unit 954, and key information transmission unit 956 shown in Figure 15. Referring to Figure 16, this program includes a step 990 for extracting the passenger identifier from the key information transmission request, a step 992 for searching the setting information DB 958 using the identifier extracted in step 990 as a key, and a step 994 for branching the control flow depending on whether the search in step 992 was successful and whether or not there was a record of setting information corresponding to the identifier.

[0094] This program further includes, in response to a positive determination in step 994, step 996 extracts key information from the configuration information of the retrieved record if any exists; step 998 branches the control flow according to whether or not key information was found as a result of the processing in step 996; step 1000 transmits the key information to the function extension ECU 840 and terminates the execution of this program if the determination in step 998 is positive; and step 1002 transmits to the function extension ECU 840 that there is no key information corresponding to the received identification information and terminates the execution of this program if the determination in step 994 or the determination in step 998 is negative.

[0095] B. Operation The driver assistance system 810 according to this second embodiment operates as follows. According to the driver assistance system 810 according to this embodiment, even if the vehicle in which the passenger is riding is different from the usual vehicle, it is possible to automatically open and close, for example, the garage door of the passenger's home.

[0096] Referring to Figure 12, the function-enhancing ECU 840 of the in-vehicle system 820 according to this second embodiment pre-stores multiple key information entries up to a predetermined upper limit for a given passenger identifier. The function-enhancing ECU 840 has the function of adding and storing new key information when it is stored, and deleting the oldest stored key information or the oldest used key information in its place.

[0097] Referring to Figure 13, the key information storage unit 872 of the function-enhancing ECU 840 stores available key information for each authenticated passenger identifier. When biometric authentication by the biometric authentication unit 274 is successful, the information acquisition unit 870 outputs the key information if it is stored in the key information storage unit 872 and corresponds to the authenticated passenger identifier. If no such key information is found, the information acquisition unit 870 sends a request to the server 822 shown in Figure 12 to transmit information about the key information associated with that passenger identifier, receives the relevant key information, and adds it to the key information storage unit 872.

[0098] Referring to Figure 15, the server 822's configuration information DB 958 stores pre-associated identifiers of garage users with key information for the garages they can use. When the key information transmission request receiving unit 950 receives a key information transmission request from the information acquisition unit 870 of the function extension ECU 840, the configuration information search unit 952 searches the configuration information DB 958 using the identifier as a key. If it finds matching configuration information, it retrieves it from the configuration information DB 958. If not, it outputs information indicating that the search failed. If the search by the configuration information search unit 952 is successful, the key information extraction unit 954 further extracts key information from the configuration information retrieved from the configuration information DB 958. The key information transmission unit 956 selects the key information extracted by the key information extraction unit 954 when the search by the configuration information search unit 952 is successful, and selects information indicating that the search failed otherwise, and transmits it to the function extension ECU 840.

[0099] When the key information storage unit 872 receives the relevant key information from the server 822, it adds that key information to the key information storage unit 872. The processing execution unit 874 uses the key information output from the key information storage unit 872 to perform predetermined processing. Specifically, the opening / closing instruction unit 900 of the processing execution unit 874 transmits the key information output by the key information storage unit 872 to the garage opening / closing unit 842. As a result, the garage opening / closing unit 842 can use that key information to open and close the door of a nearby garage.

[0100] As described above, according to this second embodiment, the key information for the garage used by the passenger is stored in the server 822 along with the passenger's identifier, and when the passenger's authentication is successful, the key information is automatically downloaded from the server 822 to the vehicle. As a result, even if the passenger is in a different vehicle, they can always use the key information for the garage they use, eliminating the need to register the same key information for each vehicle.

[0101] C. Variations C1.Configuration Figure 17 is a functional block diagram showing the relationships between the functions realized by the functional extension ECU 1030 according to a modified example of the second embodiment described above. Referring to Figure 17, in addition to the biometric authentication unit 274 and the passenger identifier storage unit 276, the functional extension ECU 1030 includes a key information storage unit 1040 that stores the passenger identifier, garage key information that the passenger can use, and information on restrictions on the use of that key information, and an information acquisition unit 870 that receives the authentication result from the biometric authentication unit 274, searches the key information storage unit 1040 for key information corresponding to the authenticated passenger identifier, retrieves the key information if it is stored, and if not, obtains key information by sending an information transmission request to a server (not shown) requesting the transmission of key information corresponding to the passenger identifier.

[0102] The enhanced ECU 1030 further includes a processing execution unit 1042 that receives key information from the information acquisition unit 870 and, only if the key information is available, instructs the garage door opening / closing unit 842 to use the key information to open and close the garage door.

[0103] The processing execution unit 1042 includes a validity determination unit 1060 that determines whether or not usage restriction information is attached to the key information received from the information acquisition unit 870, and if so, whether or not the restriction has been cleared; an opening / closing instruction unit 900 that instructs the garage opening / closing unit 842 to open or close the garage door using the key information when it receives valid key information from the validity determination unit 1060; and an update unit 1062 that, when the opening / closing instruction unit 900 has instructed the garage opening / closing unit 842 using the key information, updates the key information stored in the key information storage unit 1040 to indicate that the key information has been used, and also sends information to the server indicating that the key information has been used, and requests the server to similarly update the information regarding the use of the key information.

[0104] The processing execution unit 1042 has two specific functions, which are as follows:

[0105] In relation to the first function, the key information storage unit 1040 in this embodiment stores only a limited number of key information entries. For example, the upper limit is three. When it is requested to store more than the upper limit of key information entries, the oldest used key information entry is deleted, and the most recently used key information is stored instead. Therefore, each time key information is used, it is necessary to store the date and time when the key information was last used. This is the first function of the processing execution unit 1042, and in practice, the update unit 1062 implements this function.

[0106] The second function relates to usage restrictions that can be added to key information in this embodiment. For example, if you want to temporarily borrow someone else's vehicle and store it in your own garage, or conversely, if you want to temporarily allow someone else to store their vehicle in your garage, you need to make the garage key information available for use in that person's vehicle. This is also true when using vehicle rental or so-called car sharing. However, you cannot store your own key information in that vehicle without any restrictions; some kind of restriction is necessary. Therefore, in this embodiment, it is possible to set restrictions on the number of times the key information can be used or on the period during which the key information can be used. The second function of the processing execution unit 1042 is the function necessary for this. For example, if a restriction is set on the number of times the key information can be used, it is necessary to add a note to the key information indicating that it has been used each time it is used. This function is specifically implemented by the update unit 1062. Also, if a restriction is set on the period during which the key information can be used, when using the key information, it is necessary to determine whether the date and time at that time is within the period of use, and to allow use only if it is within the period of use. This function is specifically implemented by the validity determination unit 1060.

[0107] Figure 18 is a flowchart showing the control structure of a program for realizing the functionally enhanced ECU 1030 according to this modified example. Referring to Figure 18, this program includes a step 620 for performing biometric authentication, a step 922 for branching the control flow according to whether the authentication was successful or not, a step 924 for searching for key information corresponding to the authenticated passenger's identifier in the key information storage unit 1040 shown in Figure 17 when the determination in step 922 is positive, and a step 926 for branching the control flow according to whether or not key information corresponding to the identifier was found as a result of the search.

[0108] The program further includes, when the result of the determination in step 926 is negative, step 928, which sends key information associated with the identifier to the server and receives the result; step 930, which branches the control flow according to whether or not the server had key information corresponding to the identifier being processed as a result of the processing in step 928; and step 932, when the determination in step 930 is positive, which associates the key information and identifier received from the server with each other and adds them to the key information storage unit 1040 shown in Figure 17 for storage.

[0109] This program further includes step 1090, which is executed when the determination in step 926 is positive, and when the determination in step 926 is negative and the processing in step 932 is completed, and which branches the control flow according to whether or not restriction information is attached to the key information corresponding to the identifier; step 1092, which, when the determination in step 1090 is positive, branches the control flow according to whether or not the restriction information has been cleared; step 936, which, when the result of the determination in step 1092 is negative, and when authentication is determined to have failed in step 922, notifies that there is no available key information and terminates the execution of this program; and step 934, when the determination in step 1090 or step 1092 is positive, transmits the key information retrieved in step 924, or the key information received from the server in step 928, to the garage opening / closing unit 842 shown in Figure 7 and terminates the execution of this program.

[0110] Figure 19 is a functional block diagram showing the relationships between the various functions implemented by the server 1032 used in this modified driver assistance system. Referring to Figure 19, the server 1032 includes a configuration information DB 1150 that stores configuration information including key information associated with an identifier of an individual who has the authority to use the garage corresponding to that key information; a key information transmission request receiving unit 950; a configuration information search unit 952 that retrieves configuration information corresponding to the key information from the configuration information DB 1150 by searching the configuration information DB 1150 using the identifier included in the key information transmission request received by the key information transmission request receiving unit 950 as a key; a key information extraction unit 954 that extracts and outputs key information from the configuration information retrieved from the configuration information DB 1150 by the configuration information search unit 952; and a key information transmission unit 956 that transmits the key information output by the key information extraction unit 954 to the function extension ECU 1030 (Figure 17). If the key information transmission unit 956 finds that there is no setting information corresponding to the identifier in the setting information search unit 952, or if there is setting information corresponding to the identifier but no key information is present in it, it notifies the function extension ECU 1030 that there is no key information corresponding to the identifier.

[0111] Server 1032 further includes a key information addition request receiving unit 1152 that receives key information addition requests that specify an identifier and request the addition of new key information, and a key information update unit 1154 that adds the key information included in the key information addition request received by the key information addition request receiving unit 1152 to the configuration information DB 1150, associating it with the passenger identifier included in the key information addition request. In this embodiment, as described above, the key information addition request received by the key information addition request receiving unit 1152 may include usage restriction information for the key information in addition to the passenger identifier and key information. The key information update unit 1154 registers the identifier and key information, including this usage restriction information, in the configuration information DB 1150.

[0112] Server 1032 further includes a key information usage restriction update request receiving unit 1156 that receives a key information usage restriction update request from the update unit 1062 of the function extension ECU 1030 requesting an update to the key information usage restriction information, and a key information usage restriction update unit 1158 that updates the key information usage restriction information contained in the configuration information DB 1150 corresponding to the identifier contained in the key information usage restriction update request. In this embodiment, the update of the key information usage restriction information by the key information usage restriction update unit 1158 is to update the date and time of the last use to the latest date and time, and to add 1 to the number of times the key information has been used.

[0113] Figure 20 is a flowchart showing the control structure of a program for implementing the key information update unit 1154 shown in Figure 19. Referring to Figure 20, this program includes a step 1200 for extracting from a key addition request the identifier of the individual who owns the key, the identifier of the garage that can be controlled by the key information, and, if any, key usage restriction information; a step 1202 for searching the configuration information DB 1150 using the identifier extracted in step 1200 as a key; and a step 1204 for branching the control flow according to whether or not a target record was found as a result of the search in step 1202.

[0114] The program further includes, when the determination in step 1204 is positive, step 1206 which attempts to extract key information for a specified garage identifier from the retrieved configuration information, and step 1207 which branches the control flow in step 1206 depending on whether the specified key information exists or not. The program further includes, when the determination in step 1206 is positive, step 1208 which extracts the identifier of the person to whom the key information is to be added from the key addition request, step 1210 which searches the configuration information DB 1150 using the personal identifier extracted in step 1208 as a key, and step 1211 which branches the control flow depending on whether the search in step 1210 has resulted in the target record being in the configuration information DB 1150.

[0115] This program further includes, if the determination in step 1211 is positive, step 1212, which adds the key information to the record of the configuration information that uses the identifier retrieved in step 1210 as the key, updates that record in the configuration information DB 1150, and terminates the execution of this program; and step 1214, if the result of the determination in step 1211 is negative, which notifies the function extension ECU 1030 that the corresponding key information cannot be added, and terminates the execution of this program.

[0116] C2.Operation The modified functional extension ECU 1030 and server 1032 according to this second embodiment operate as follows. Referring to Figure 17, the key information storage unit 1040 of this functional extension ECU 1030 stores in advance an individual's identifier, garage key information that the individual can use, and information on restrictions on the use of that key information. The information acquisition unit 870 receives the authentication result from the biometric authentication unit 274, searches the key information storage unit 1040 for key information corresponding to the authenticated passenger's identifier, and retrieves the key information if it is stored there. If no such key information exists in the key information storage unit 1040, the information acquisition unit 870 obtains the key information by sending an information transmission request to the server 1032 shown in Figure 19, requesting the transmission of key information corresponding to the passenger's identifier.

[0117] Referring to Figure 19, when the server 1032 receives an information transmission request from the information acquisition unit 870, it operates as follows. The server 1032's configuration information DB 1150 stores configuration information, including key information, associated with individual identifiers. Some of this key information includes usage restriction information. When the key information transmission request receiving unit 950 receives a key information transmission request, the configuration information search unit 952 searches the configuration information DB 1150 using the identifier included in the key information transmission request received by the key information transmission request receiving unit 950 as a key, and retrieves the configuration information corresponding to that key information from the configuration information DB 1150. The key information extraction unit 954 extracts and outputs the key information from the configuration information retrieved by the configuration information search unit 952 from the configuration information DB 1150. The key information transmission unit 956 transmits the key information output by the key information extraction unit 954 to the function extension ECU 1030 (Figure 17). If the key information transmission unit 956 finds that there is no setting information corresponding to the identifier in the setting information search unit 952, or if there is setting information corresponding to the identifier but no key information is present in it, it notifies the function extension ECU 1030 that there is no key information corresponding to the identifier.

[0118] The processing execution unit 1042 of the function-enhancing ECU 1030 receives key information from the information acquisition unit 870 and, only if the key information is available, instructs the garage door opening / closing unit 842 to use the key information to open and close the garage door. If the key information has usage restriction information attached to it, the key information can be used if the usage restriction information has been cleared, but otherwise the key information cannot be used.

[0119] The validity determination unit 1060 of the processing execution unit 1042 determines whether or not usage restriction information is attached to the key information received from the information acquisition unit 870, and if usage restriction is attached, whether or not that restriction has been cleared. The opening / closing instruction unit 900 receives the determination result from the validity determination unit 1060 and instructs the garage opening / closing unit 842 to open or close the garage door using the key information when valid key information is received. The update unit 1062 updates the key information stored in the key information storage unit 1040 to indicate that the key information has been used when the opening / closing instruction unit 900 has instructed the garage opening / closing unit 842 using the key information. The update unit 1062 further transmits information indicating that the key information has been used to the server 1032 and requests that the server 1032 also update the information regarding the use of the key information.

[0120] Referring to Figure 19, when it is necessary to add new key information to server 1032, a key information addition request must be sent to server 1032, which includes the key information and the identifier of the garage corresponding to that key information. If a third party is permitted to use the garage, the identifier of that third party and, if any usage restrictions are imposed, information specifying those restrictions must also be included in the key information addition request.

[0121] When the key information addition request receiving unit 1152 of server 1032 receives this key information addition request, it provides the key information to the key information update unit 1154. The key information update unit 1154 adds the key information included in the key information addition request to the configuration information DB 1150, associating it with the passenger identifier included in the key information addition request. If the key information addition request is accompanied by usage restriction information for the key information, the identifier and key information, including this usage restriction information, are registered in the configuration information DB 1150.

[0122] The key information usage restriction update request receiving unit 1156 of server 1032 receives a key information usage restriction update request from the update unit 1062 of the function extension ECU 1030, and uses that key information usage restriction information to update the key information usage restriction information contained in the configuration information DB 1150, which corresponds to the identifier contained in the key information usage restriction update request. In this embodiment, the key information usage restriction update by the key information usage restriction update unit 1158 is to update the date and time of the last use to the latest date and time, and to add 1 to the number of times the key information has been used, as described above.

[0123] As described above, according to this embodiment, the garage owner can not only use common key information for any of their vehicles, but can also lend the key information for their garage to a third party. In this case, it is possible to set restrictions on the period or number of times the information can be used. Conversely, when storing a vehicle used for rental or car sharing in one's own garage, the owner can download the key information to use their own garage and use it. In this case as well, if usage restrictions are placed on the key information, even if the key information remains in the vehicle after its return, there is no risk that the owner's garage will be used by a third party using that key. Therefore, it is possible to share the key information for using one's own garage with multiple vehicles, including vehicles that are not owned by the owner, while preventing third parties from using the garage, and simplifying the management of garage key information.

[0124] 3. Third Embodiment A.Configuration A1. Overall structure Figure 21 shows the configuration of the driver assistance system 1220 according to the third embodiment of this disclosure in block diagram form. Referring to Figure 21, the driver assistance system 1220 includes an in-vehicle system 1230 that recognizes the passenger's physical condition and, accordingly, schedules the operation of equipment in the passenger's room for relaxation when the passenger returns to their room (e.g., home), and transmits a schedule request to the outside when the user instructs such scheduling; a server 1232 that, according to the schedule request received from the in-vehicle system 1230, sets the scheduling settings for various equipment in the passenger's room of the vehicle equipped with the in-vehicle system 1230, and requests such scheduling from a home computer that controls the passenger's room; and a home server system 1234 installed in the passenger's home.

[0125] The in-vehicle system 1230 includes an ECU such as an autonomous driving ECU 70, a biosensor 76, and a TCU 74, as well as a driver monitor 1240 for acquiring information to know the passenger's physical condition, a function extension ECU 1242 that pre-generates a schedule for controlling the operation of various equipment of the home server system 1234 based on the output of the biosensor 76 and the driver monitor 1240, and performs a process to recommend to the passenger and obtain instructions from the passenger, and an IVI (In-Vehicle Infotainment system) 1244 for presenting the recommendations from the function extension ECU 1242 to the passenger and receiving input such as acceptance or modification instructions from the passenger.

[0126] In this embodiment, the driver monitor 1240 includes a camera 1250 for acquiring an image of the passenger's face and a biosensor 1252 for acquiring the passenger's biometric information. The biosensor 1252 can be, for example, a wearable device worn on the wrist that can measure the wearer's pulse, heart rate variability, and skin temperature. Alternatively, a device capable of detecting body temperature, such as a thermal camera, may be used instead of, or in addition to, the camera 1250.

[0127] In this embodiment, the home server system 1234 includes a home server 1300 installed in the passenger's room, a home network 1302 to which the home server 1300 is connected, and a water heater 1304, an air conditioner 1306, lighting 1308, and underfloor heating 1310, all of which can communicate with the home server 1300 via the home network 1302. In this embodiment, the water heater 1304, air conditioner 1306, lighting 1308, and underfloor heating 1310 are all capable of operating according to control from the home server 1300.

[0128] In this embodiment, the home server 1300 has the function of operating the water heater 1304, air conditioner 1306, lighting 1308, and floor heating 1310 via the home network 1302 according to the schedule, and according to the settings specified in the schedule. For example, the home server 1300 has the function of controlling the water heater 1304 so that the bath becomes available at the time specified in the schedule. In addition, the home server 1300 operates the air conditioner 1306, lighting 1308, and floor heating 1310 according to the schedule.

[0129] Of course, this disclosure is not limited to such embodiments. For example, if the water heater 1304, air conditioner 1306, floor heating 1310, etc., are capable of operating according to a specified schedule, the home server 1300 only needs to provide the function of setting schedules for them. Furthermore, even if the home server 1300 does not exist, if the water heater 1304, etc., can communicate directly with the outside, the server 1232 can also individually control these devices or set individual schedules for them.

[0130] A2. Configuration of the function-enhancing ECU1242 Figure 22 is a block diagram showing the relationships between the various functions realized by the function-enhanced ECU 1242. Referring to Figure 22, the function-enhanced ECU 1242 includes a passenger identifier storage unit 276 and a setting information storage unit 1352, and an information acquisition unit 1350 that receives the passenger identifier as an authentication result from the biometric authentication unit 274, acquires the setting information corresponding to that identifier by transmitting it to the server 1232, and stores it in the setting information storage unit 1352. The setting information storage unit 1352 stores information about various facilities installed at the passenger's residence that can be controlled directly or indirectly from the outside, corresponding to the passenger's identifier. The server 1232 also stores the same type of information, and the information acquisition unit 1350 has the function of downloading that information from the server 1232 and storing it in the setting information storage unit 1352.

[0131] The function-enhanced ECU 1242 further includes a processing execution unit 1354 that predicts the passenger's physical condition (such as fatigue level) based on various sensor outputs from the driver monitor 1240 shown in Figure 21, the passenger's room equipment information stored in the setting information storage unit 1352, and the passenger's driving schedule. If the prediction result meets predetermined conditions, it creates a schedule for operating various parts of the home server system 1234 and recommends it to the passenger. The processing execution unit 1354 presents the recommendation content via the in-vehicle navigation system through the IVI 1244, and after obtaining instructions from the passenger to accept, reject, or modify and accept the schedule, it requests the server 1232 to operate various parts of the home server system 1234 based on that schedule once the passenger has given their consent to proceed with the processing based on the schedule.

[0132] More specifically, the processing execution unit 1354 includes a health recognition unit 1370 for predicting the passenger's health condition based on various sensor outputs from the driver monitor 1240, and a scheduling unit 1372 that, if the passenger's health condition predicted by the health recognition unit 1370 satisfies predetermined conditions, recommends an operation schedule for various equipment in the passenger's home based on the equipment information of the passenger's room and the driving schedule stored in the setting information storage unit 1352, and receives instructions from the passenger.

[0133] The scheduling unit 1372 includes a scheduling unit 1400 that creates a schedule for operating various equipment so that when the passenger's physical condition, as predicted by the physical condition recognition unit 1370, meets predetermined conditions, the passenger can relax and recover from fatigue without having to perform any cumbersome tasks upon returning home. The scheduling unit 1400 reads equipment information corresponding to the passenger's identifier from the setting information storage unit 1352 and creates the above-mentioned schedule based on this equipment information and the travel schedule.

[0134] The scheduling unit 1372 further includes a schedule recommendation unit 1402 that displays the schedule on a display device connected to the IVI 1244 by passing information about the schedule created by the schedule creation unit 1400 to the IVI 1244, and receives instructions from passengers to approve, reject, or modify the scheduling via an input device connected to the IVI 1244, and a scheduling request unit 1404 that receives the schedule approved by the passenger from the schedule recommendation unit 1402 and sends it to the server 1232 as a schedule request. The schedule includes a passenger identifier and a list of the status of each piece of equipment in the passenger's room at what time.

[0135] Figure 23 is a flowchart showing the control structure of a program that implements the functions of the function-enhanced ECU 1242 shown in Figure 21. Referring to Figure 23, this program includes a step 620 that performs biometric authentication and a step 1450 that branches the control flow depending on whether the biometric authentication was successful or not. If the determination in step 1450 is negative, the execution of this program ends.

[0136] The program further includes step 1452, which activates the physical condition recognition unit 1370 shown in Figure 22 if the determination in step 1450 is positive; step 1454, which activates the scheduling unit 1372 shown in Figure 22 after step 1452; and step 1456, which executes a separate routine process in a loop after step 1454. Steps 1452 and 1454 are activated when passenger authentication is successful and continue to operate until a predetermined termination condition is met.

[0137] Figure 24 is a flowchart showing the control structure of the program that implements the physical condition recognition unit 1370 shown in Figure 22. Referring to Figure 24, the program includes, upon startup, a step 1500 that clears the memory that stores the sensor outputs used for calculating fatigue level, and a step 1502 that reads various sensor outputs from the driver monitor 1240 and stores the values ​​of those outputs for the most recent predetermined time in memory. The values ​​stored in memory at this time are the sensor outputs for the most recent, for example, one minute. The sampling of sensor outputs does not have to be at such a short interval; for example, it may be every one second, every two seconds, etc. Regarding face images, it is preferable to use a filter consisting of a neural network that outputs the presence or absence of blinking, gaze movement, pupil dilation, etc. from the image, rather than using the image output directly.

[0138] The program further includes step 1504, which branches the control flow depending on whether a predetermined time (e.g., 1 minute) has elapsed; and step 1506, which, if the determination in step 1504 is positive, outputs the passenger's fatigue level (one of 0 (no fatigue), 1 (mild fatigue), and 2 (fatigue)) using the values ​​stored in memory, adds it to an array for storing fatigue levels in memory, stores it, and returns control to step 1502. If the determination in step 1504 is negative, control skips step 1506 and returns to step 1502. The array for storing fatigue levels is for storing, for example, the fatigue level values ​​calculated in step 1502 over the most recent 60 minutes. If the time for accumulating fatigue levels exceeds 60 minutes, the oldest values ​​are overwritten with the newest fatigue levels in order.

[0139] In step 1502, a pre-trained neural network is used, which takes as input a vector formed by concatenating vectors of time series outputs from various sensors over one minute, and has three outputs corresponding to whether the passenger's fatigue level is 0, 1, or 2. Each of these three outputs represents the probability that the passenger's fatigue level is 0, 1, or 2. The fatigue level corresponding to the output with the highest probability is adopted as the fatigue level at that time. In this embodiment, since the fatigue level is limited to three stages, there is little risk of difficulty in collecting training data.

[0140] Figure 25 is a flowchart showing the control structure of a program that implements the scheduling unit 1372 shown in Figure 22. Referring to Figure 25, this program includes a step 1550 of reading the fatigue level sequence for the most recent predetermined time from the fatigue level sequence in memory, and a step 1552 of calculating the previous fatigue level F0 and the current fatigue level F1. In this embodiment, the previous fatigue level F0 uses the average value of the first half of the fatigue level sequence, and the current fatigue level F1 uses the average value of the second half of the fatigue level sequence. Of course, the fatigue level calculated in the previous process may also be stored and used as the previous fatigue level F0.

[0141] This program further includes step 1554, which calculates a state transition according to a predetermined state transition diagram based on the previous fatigue level F0 and the current fatigue level F1, and step 1556, which branches the control flow according to whether or not a state transition occurred as a result of the processing in step 1554.

[0142] Figure 26 shows an example of a state transition diagram used in step 1554. Referring to Figure 26, this state transition diagram includes state node 1600 corresponding to fatigue level 0, state node 1602 corresponding to fatigue level 1, and state node 1604 corresponding to fatigue level 2. Between these three nodes, there are two unidirectional edges representing state transitions. For these unidirectional edges, the base of the arrow will be called the "head" and the tip of the arrow the "tail". Each of these edges is assigned a threshold value, and each threshold value indicates that when the current state (which corresponds to the previous fatigue level F0 calculated in step 1554) is at the head of that edge, the state transition indicated by that edge will occur if the value of the current fatigue level F1 calculated in step 1554 in Figure 25 is greater than the threshold value of that edge. However, in this embodiment, for example, there is an edge from state node 1600 to state node 1602 (threshold value 0.7) and an edge to state node 1604 (threshold value 1.6). In such cases, the state transition is calculated so that the higher threshold is tested first, and only if that test is negative is the lower threshold tested. The reverse is also true. That is, from state node 1604 there are edges leading to state node 1602 (threshold 1.4) and edges leading to state node 1600 (threshold 0.3). In such cases, the state transition is first tested for the edge with the lower threshold, and only if that test is negative is the state transition tested for the edge with the higher threshold.

[0143] In Figure 26, for example, the threshold for the edge transition from state node 1600 to state node 1602 is 0.7, while the threshold for the edge transition from state node 1602 to state node 1600 is 0.3, which is lower than 0.7. This is to prevent frequent state transitions from occurring near the thresholds if both thresholds were equal. The same applies to transitions between other state nodes.

[0144] Referring again to Figure 25, the program further includes step 1560, which, when the determination in step 1556 is positive, recommends to the passenger and obtains the passenger's instructions by passing a plan corresponding to the transition state to IVI 1244. In this embodiment, as described above, only three fatigue states are assumed, and predetermined recommendation content is prepared in advance for each of these states. The schedule creation unit 1400 applies the passenger's room equipment information to these recommendation contents to create recommendation content suitable for the passenger.

[0145] The program further includes step 1562, in which the program receives instructions from the passenger in step 1560 (approval, rejection, or approval with modification); step 1564, which branches the control flow depending on whether the passenger's instructions indicate the execution of the schedule; step 1566, if the determination in step 1564 is positive, which sends the schedule to the server 1232 (see Figure 21) and requests that the schedule be implemented; and step 1558, which waits for a predetermined time after step 1566 and then returns control to step 1550. If the result of the determination in step 1556 or step 1564 is negative, control proceeds to step 1558.

[0146] A3. Configuration of Server 1232 Figure 27 shows the relationships between the various functions implemented by the server 1232 shown in Figure 21. Referring to Figure 27, the server 1232 includes a configuration information DB 1660 that stores various configuration information, including equipment information about the equipment of each individual's residence, in association with each individual's identifier; an equipment information update request receiving unit 1656 that receives equipment information update requests, such as adding, modifying, or deleting equipment information about an individual's room, by specifying the individual's identifier to the configuration information DB 1660; an equipment information update unit 1658 that, in response to the equipment information update requests received by the equipment information update request receiving unit 1656, adds, changes, or deletes equipment information related to that identifier in the configuration information DB 1660; and an equipment specification information DB 1662 that stores specification information about various types of equipment in advance.

[0147] Server 1232 further includes an information transmission request receiving unit 1650 for receiving an information transmission request from the information acquisition unit 1350 shown in Figure 22, which requests the transmission of equipment information specifying an individual identifier; a configuration information search unit 1654 for searching the configuration information DB 1660 using the received identifier as a key in response to the information transmission request receiving unit 1650, retrieving the corresponding configuration information, and further extracting equipment information from there; and an information transmission unit 1652 for transmitting the configuration information, including the equipment information extracted by the configuration information search unit 1654, to the information acquisition unit 1350.

[0148] Server 1232 further includes a scheduling request receiving unit 1664 to receive scheduling requests from the scheduling request unit 1404 shown in Figure 22, an equipment control unit 1666 which, in response to the scheduling request receiving unit 1664 receiving a scheduling request, reads details of various equipment included in the scheduling request from the setting information search unit 1654 and further reads the specifications of those various equipment from the equipment specification information DB 1662, thereby generating a sequence of commands for each of the various pieces of equipment in the passenger's room to operate individually according to the schedule received by the scheduling request receiving unit 1664, or a sequence of commands for the home server in the passenger's room to operate those pieces of equipment according to the schedule, and a control information transmission unit 1668 to transmit the sequence of commands generated by the equipment control unit 1666 to a specified address of each piece of equipment in the passenger's room or home computer stored in the setting information search unit 1654.

[0149] Figure 28 is a flowchart showing the control structure of a program executed by the server according to the third embodiment shown in Figure 21, for realizing the equipment control unit 1666 shown in Figure 27. Referring to Figure 28, this program includes a step 1700 which extracts the passenger identifier, equipment identifier, and schedule details (operation details and times for each piece of equipment) from a scheduling request received from the scheduling request unit 1404 (Figure 22); a step 1702 which executes step 1704 for each piece of equipment extracted in step 1700; and a step 1706 which, after the completion of step 1702, transmits the results of the schedule execution to the scheduling request unit 1404.

[0150] Step 1704 includes step 1720, which searches the equipment specification information DB1662 shown in Figure 27 using the identifier of the equipment to be processed in the schedule as the key; step 1722, which branches the control flow according to whether or not corresponding equipment specification information exists as a result of the search in step 1720; and step 1724, which generates control information for that equipment based on the schedule information and the retrieved equipment specification, if the determination in step 1722 is positive. If the determination in step 1722 is negative, the equipment cannot be operated, and the execution of step 1704 is terminated.

[0151] Step 1704 further includes step 1726, which terminates step 1704 by sending the control information created in step 1724 to the destination address for sending commands to each piece of equipment, which is included in the configuration information corresponding to the passenger's identifier. If there is no home server at the passenger's residence, this address may be a separate address for controlling each piece of equipment. If there is a home server at the passenger's residence and that server can control the outer casing equipment, this destination address may be the address of the home server.

[0152] B. Operation The driver assistance system 1220 according to the third embodiment described above operates as follows.

[0153] Referring to Figure 27, the equipment information update request receiving unit 1656 of server 1232 receives an equipment information update request to the configuration information DB 1660, specifying an individual's identifier, for adding, modifying, or deleting equipment information related to that individual's room. In response to this equipment information update request, the equipment information update unit 1658 adds equipment information related to that identifier to the configuration information DB 1660, modifies stored equipment information, or deletes equipment information. As a result, the configuration information DB 1660 stores in advance an association between each individual's identifier and various configuration information, including equipment information related to the equipment at that individual's residence.

[0154] Furthermore, the equipment specification information DB1662 stores specification information for various types of equipment in advance. This specification information should be obtained from the manufacturers or distributors of each type of equipment, rather than from individuals.

[0155] Referring to Figure 21, each sensor (camera 1250 and biosensor 1252) included in the driver monitor 1240 of the in-vehicle system 1230 acquires information to determine the passenger's physical condition and inputs it to the function expansion ECU 1242. The function expansion ECU 1242 pre-generates a schedule for controlling the operation of various equipment in the home server system 1234 based on the output of the biosensor 76 and the output of the driver monitor 1240, and performs the process of recommending to the passenger and obtaining the passenger's instructions as follows. The IVI 1244 presents the recommendations from the function expansion ECU 1242 to the passenger, receives input such as acceptance or modification from the passenger, and provides the result to the function expansion ECU 1242.

[0156] Referring to Figure 22, the configuration information storage unit 1352 stores information about various facilities located at the passenger's residence that can be controlled directly or indirectly from the outside, corresponding to the passenger's identifier. The information acquisition unit 1350 of the function expansion ECU 1242 receives the passenger's identifier as an authentication result from the biometric authentication unit 274 and sends a request to the server 1232 to transmit configuration information corresponding to that identifier (information transmission request).

[0157] Referring to Figure 27, the information transmission request receiving unit 1650 of server 1232 receives an information transmission request from the information acquisition unit 1350. In response to the information transmission request receiving unit 1650 receiving the information transmission request, the configuration information search unit 1654 searches the configuration information DB 1660 using the received identifier as a key to retrieve the corresponding configuration information and further extracts equipment information from it. The information transmission unit 1652 transmits the configuration information, including the equipment information extracted by the configuration information search unit 1654, to the information acquisition unit 1350.

[0158] Referring again to Figure 22, the information acquisition unit 1350 receives setting information from the server 1232 and stores it in the setting information storage unit 1352. The processing execution unit 1354 of the function expansion ECU 1242 predicts the passenger's physical condition (fatigue level, etc.) based on the various sensor outputs from the driver monitor 1240 shown in Figure 21, the equipment information of the passenger's room stored in the setting information storage unit 1352, and the passenger's driving schedule. If the prediction result meets predetermined conditions, it creates a schedule for operating each part of the home server system 1234 and recommends it to the passenger. The processing execution unit 1354 presents the recommendation content via the IVI 1244 to a display device such as an in-car navigation system, and obtains instructions from the passenger to accept, reject, or modify and accept the schedule via an input device such as an in-car navigation system. When the passenger has agreed to process the schedule, it requests the server 1232 to operate each part of the home server system 1234 based on that schedule.

[0159] More specifically, the physical condition recognition unit 1370 of the processing execution unit 1354 predicts the passenger's physical condition based on various sensor outputs from the driver monitor 1240. If the passenger's physical condition predicted by the physical condition recognition unit 1370 satisfies predetermined conditions, the scheduling unit 1372 recommends an operating schedule for various equipment in the passenger's home based on the equipment information of the passenger's room and the driving schedule stored in the setting information storage unit 1352, and receives instructions from the passenger.

[0160] The scheduling unit 1372's schedule creation unit 1400 creates a schedule for operating various equipment so that when the passenger's physical condition, as predicted by the physical condition recognition unit 1370, meets predetermined conditions, the passenger can relax and recover from fatigue without having to perform any cumbersome tasks upon returning home. At this time, the schedule creation unit 1400 reads equipment information corresponding to the passenger's identifier from the setting information storage unit 1352 and uses this equipment information and the travel schedule.

[0161] The schedule recommendation unit 1402 of the scheduling unit 1372 passes information about the schedule created by the schedule creation unit 1400 to the IVI 1244, thereby displaying the schedule on a display device connected to the IVI 1244. The schedule recommendation unit 1402 further receives instructions from passengers to approve, reject, or modify the scheduling via an input device connected to the IVI 1244. The scheduling request unit 1404 receives the schedule approved by the passenger from the schedule recommendation unit 1402 and sends it to the server 1232 as a schedule request. The schedule includes the passenger's identifier and a list of the status of each piece of equipment in the passenger's cabin at what time.

[0162] Referring to Figure 24, the passenger's physical condition recognition process by the physical condition recognition unit 1370 will be explained. Upon startup, in step 1500, this program clears the memory that stores the sensor outputs used for calculating fatigue levels. In the following step 1502, it reads various sensor outputs from the driver monitor 1240 and stores the values ​​of those outputs for the most recent predetermined time in memory. The values ​​stored in memory at this time are the sensor outputs for the most recent 1 minute.

[0163] In the following step 1504, it is checked whether a predetermined time has elapsed. If the predetermined time has elapsed, in step 1506, the passenger's fatigue level (either 0 (no fatigue), 1 (mild fatigue), or 2 (fatigue)) is output using the values ​​stored in memory and added to the fatigue level memory array in memory. In other words, a value (0, 1, or 2) indicating the passenger's fatigue level is stored every minute. The fatigue level memory array stores, for example, the fatigue level values ​​calculated in step 1502 for the most recent 60 minutes. If the fatigue level storage time exceeds 60 minutes, the oldest values ​​are overwritten with the newest fatigue levels in order.

[0164] Referring to Figure 25, when the program implementing the scheduling unit 1372 shown in Figure 22 is executed, in step 1550 the fatigue level sequence for the most recent predetermined time is read from the fatigue level sequence in memory. Subsequently, in step 1552, the previous fatigue level F0 and the current fatigue level F1 are calculated. In this embodiment, the previous fatigue level F0 uses the average value of the first half of the fatigue level sequence, and the current fatigue level F1 uses the average value of the second half of the fatigue level sequence.

[0165] In step 1554, a state transition is calculated based on the previous fatigue level F0 and the current fatigue level F1, according to the state transition diagram shown in Figure 26. In step 1556, it is determined whether or not a state transition occurred as a result of the processing in step 1554. If a state transition occurred, in step 1560, a plan corresponding to the transitioned state is passed to IVI1244 to recommend a plan to the passenger and obtain the passenger's instructions. Furthermore, in step 1562, the program receives instructions from the passenger (approval, rejection, or approval with modifications). If the passenger's instructions indicate the execution of the schedule (deterministic in step 1564), in step 1566, the schedule is sent to server 1232 (see Figure 21) to request its execution, and in step 1558, control is returned to step 1550 after waiting for a predetermined time for the program to execute. If the result of the determination in step 1556 or step 1564 is negative, nothing is done, and after waiting for a predetermined time for the program to execute in step 1558, control is returned to step 1550.

[0166] Through the above process, for example, if the average fatigue level exceeds 0.7 after being 0.7 or less for a predetermined period of time, the fatigue level transitions from 0 to 1, as shown in Figure 26. Furthermore, if the fatigue level is 0.3 or higher and 1.4 or less in that state, the fatigue level = 1 state is maintained. If the average fatigue level over the predetermined period falls below 0.3, the fatigue level transitions to 0. On the other hand, if the average fatigue level over the predetermined period exceeds 1.6 while the fatigue level is 1, the fatigue level becomes 2.

[0167] The principle of state transitions after fatigue level reaches 2 is the same as when fatigue level is 1. However, the threshold in this case is different from that when fatigue level is 1.

[0168] In the state transition diagram shown in Figure 26, the thresholds assigned to the two edges between a pair of state nodes are different. These values ​​are chosen so that after a state transition from one to the other, it becomes difficult for the state to transition in the reverse direction. As a result, the calculation of fatigue level becomes stable, and the situation where recommendations are displayed repeatedly is prevented.

[0169] Referring to Figure 27, the scheduling request receiving unit 1664 in server 1232 receives a scheduling request from the scheduling request unit 1404 shown in Figure 22. In response to the scheduling request receiving unit 1664 receiving the scheduling request, the equipment control unit 1666 reads the details of the various equipment included in the scheduling request from the setting information retrieval unit 1654. The equipment control unit 1666 further reads the specifications of these various pieces of equipment from the equipment specification information DB 1662. Using this information, the equipment control unit 1666 generates a sequence of commands to individually operate the various pieces of equipment in the passenger's room, or a sequence of commands to the home server in the passenger's room to operate those pieces of equipment according to the schedule received by the scheduling request receiving unit 1664. The control information transmission unit 1668 transmits the sequence of commands generated by the equipment control unit 1666 to the specified addresses of each piece of equipment in the passenger's room or the home computer stored in the setting information retrieval unit 1654.

[0170] In the home server system 1234 shown in Figure 21, for example, when the home server 1300 receives the above-mentioned command sequence, it operates each piece of equipment connected to the home network 1302 according to the schedule indicated by that command sequence. Alternatively, when an individual piece of equipment connected to the home network 1302 receives the above-mentioned command sequence, that piece of equipment executes the process specified by the schedule at the time specified by the schedule. As a result, when the occupant of the vehicle returns to their room, each part connected to the home network 1302 is in a predetermined state according to the fatigue experienced during vehicle operation. For example, by returning to a room adjusted to a suitable temperature and appropriate lighting, and taking a bath in water at a suitable temperature, the occupant can efficiently recover from fatigue.

[0171] Each process (each function) of the above-described embodiment is implemented by a processing circuit (Circuitry) including one or more processors. The processing circuit may consist of one or more memories, various analog circuits, various digital circuits, and other integrated circuits in addition to the one or more processors. The one or more memories store programs (instructions) that cause the one or more processors to execute each of the above processes. The one or more processors may execute each of the above processes according to the programs read from the one or more memories, or they may execute each of the above processes according to logic circuits that have been pre-designed to execute each of the above processes. The processors may be various processors suitable for computer control, such as CPUs, GPUs, DSPs (Digital Signal Processors), FPGAs (Field-Programmable Gate Arrays), and ASICs (Application Specific Integrated Circuits). The multiple processors, which are physically separated, may cooperate with each other to execute each of the above processes. For example, the processors installed in each of the multiple physically separated computers may cooperate with each other via a network such as a LAN (Local Area Network), WAN (Wide Area Network), or the Internet to execute each of the above processes. The above program may be installed in the memory via the network from an external server device, or it may be distributed on a recording medium such as a CD-ROM (Compact Disc Read-Only Memory), DVD-ROM (Digital Versatile Disc Read-Only Memory), or semiconductor memory, and then installed from the recording medium to the memory.

[0172] In the above embodiment, the occupant is primarily assumed to be the driver. However, this disclosure is not limited to such embodiments. It can also target the passenger in the front passenger seat. Furthermore, by providing facial recognition devices in both the driver's seat and the front passenger seat, the occupants in the driver's seat and the front passenger seat can be recognized separately. Using this information, the in-vehicle device can process setting information for these two individuals separately. In this case, if the settings for the two individuals conflict, the conflict can be resolved according to some criterion. For example, the settings for the driver's seat occupant can be prioritized for settings related to vehicle control. Moreover, instead of managing the settings for the two individuals separately, setting information for specific combinations of occupants in the driver's seat and front passenger seat can be stored on a server, and when that specific combination occurs, the vehicle can be configured according to different setting information than when each occupant is alone.

[0173] The embodiments disclosed herein should be considered in all respects to be illustrative and not restrictive. The scope of this disclosure is not defined by the description in the detailed disclosure but by the claims, and all modifications within the meaning and scope equivalent to the wording of the claims are intended. [Explanation of symbols]

[0174] 50, 810, 1220 Driver assistance systems 60, 820, 1230 In-vehicle systems 62, 822, 1032, 1232 servers 70 Autonomous Driving ECU 72, 840, 1030, 1242 Function Enhancement ECU 74 TCU 76, 1252 biosensors 78 BCU 80 Seat adjustment section 82 Mirror adjustment section 84 Air Conditioning Adjustment Unit 86 Lighting adjustment unit 88 Other adjustment parts 130 Hardware Layers 132 Underlying Software Layer 134 Application Layer 180 processors 200 express buses 202 MPU 204 SRAM 206 Flash Memory 208,496 ROM 210 Slow Bus 212 Bridge 214 Serial I / F 216 ADC 218 Timer Counter 220 Clock Generator 222 Power Control Unit 224 General-purpose I / F 226 Programs 274 Biometrics Department 276 Passenger Identifier Storage Unit 278, 870, 1350 Information acquisition section 280, 874, 1042, 1354 Processing Execution Unit 282 Vehicle Information Storage Unit 284 Change Information Transmission Unit 300 Adjustment instruction section 350 State Identification Unit 352 Configurable information storage section 354 Equipment Adjustment Instruction Department 470 Computers 472 monitors 474 keyboard 476 mice 478 DVD 480 speakers 482 Microphone 484 USB flash drives 486 Network 490 CPU 492 GPU 498 RAM 500 SSD 502 DVD drive 504 Audio Interface 506 USB ports 508 Network Interface 510 Bus 560, 1650 Information transmission request receiving unit 562, 952, 1654 Configuration Information Search Unit 564 Configuration Information Transmission Unit 566, 958, 1150, 1660 Configuration Information Database 568 Update Request Receiving Unit 570 Setting information update section 842 Garage opening / closing unit 872, 1040 Key information storage unit 900 Open / Close Indicator 950 Key Information Transmission Request Receiving Unit 954 Key information extraction part 956 Key Information Transmission Unit 960 Key information addition request 962, 1154 Key information update section 1060 Effectiveness determination unit 1062 Update Department 1152 Key Information Addition Request Receiving Unit 1156 Key Information Usage Restriction Update Request Receiving Unit 1158 Key Information Usage Restriction Update Section 1234 Home Server System 1240 Driver Monitor 1244 IVI 1250 Camera 1300 Home Servers 1302 Home Network 1304 Water heater 1306 Air conditioner 1308 Lighting 1310 Underfloor heating 1352 Configuration Information Storage Unit 1370 Health Awareness Department 1372 Scheduling Department 1400 Schedule Creation Department 1402 Schedule Recommendation Department 1404 Scheduling Request Department State nodes 1600, 1602, 1604 1652 Information Transmission Department 1656 Equipment Information Update Request Receiving Unit 1658 Equipment Information Update Department 1662 Equipment Specifications Information Database 1664 Scheduling Request Receiving Unit 1666 Equipment Control Unit 1668 Control Information Transmission Unit

Claims

1. An information acquisition unit that obtains information associated with the vehicle's occupants through communication with a server, It includes a processing execution unit that is connected to the vehicle's in-vehicle network and performs processing according to the information acquired by the information acquisition unit using resources that can communicate via the vehicle network, The aforementioned information includes key information for the automatic opening and closing device of the garage used by the passenger, An in-vehicle device in which the processing execution unit includes an opening / closing instruction unit that, in response to predetermined conditions being met, instructs other devices via the in-vehicle network to operate the automatic opening / closing device using the key information.

2. The in-vehicle device according to claim 1, further comprising a passenger authentication unit for authenticating the aforementioned passenger.

3. The in-vehicle device according to claim 2, wherein the passenger authentication unit is provided in the vehicle and includes a facial image authentication unit that performs authentication using the passenger's facial image.

4. The aforementioned information further includes validity control information that controls the validity of the key information contained in the aforementioned information, The in-vehicle device according to any one of claims 1 to 3, wherein the processing execution unit further includes a validity determination unit that prohibits the opening / closing instruction unit from using key information among the key information included in the information that has been determined to be invalid by referring to the validity control information.

5. An information acquisition unit that obtains information associated with the vehicle's occupants through communication with a server, It includes a processing execution unit that is connected to the vehicle's in-vehicle network and performs processing according to the information acquired by the information acquisition unit using resources that can communicate via the vehicle network, The aforementioned information includes information regarding externally controllable equipment located at the residence used by the passenger after using the vehicle, The processing execution unit, A health condition recognition unit that recognizes the health condition of the passenger, An in-vehicle device including a scheduling unit that, in accordance with the physical condition recognized by the physical condition recognition unit, selects at least one of the functions of the equipment at the passenger's residence and schedules the activation of that function.

6. The in-vehicle device according to claim 5, further comprising a passenger authentication unit for authenticating the aforementioned passenger.

7. The in-vehicle device according to claim 6, wherein the passenger authentication unit is provided in the vehicle and includes a facial image authentication unit that performs authentication using the passenger's facial image.

8. The scheduling unit is A schedule creation unit selects at least one of the functions of the equipment at the passenger's residence and creates a schedule for activating that function, in accordance with the physical condition recognized by the physical condition recognition unit. The in-vehicle device according to any one of claims 5 to 7, further comprising: a request unit that transmits the schedule created by the schedule creation unit to the server and requests that the server control the equipment at the residence according to the schedule.

9. The scheduling unit is A schedule creation unit selects at least one of the functions of the equipment at the passenger's residence and creates a schedule for activating that function, in accordance with the physical condition recognized by the physical condition recognition unit. The in-vehicle device according to any one of claims 5 to 7, further comprising: a request unit that transmits the schedule created by the schedule creation unit to a home server in the residence and requests that the equipment in the residence be controlled according to the schedule.

10. An information acquisition unit that obtains information associated with the vehicle's occupants through communication with a server, It includes a processing execution unit that is connected to the vehicle's in-vehicle network and performs processing according to the information acquired by the information acquisition unit using resources that can communicate via the vehicle network, Furthermore, it includes a storage unit that stores the information acquired by the information acquisition unit, The aforementioned information acquisition unit, A search unit that retrieves information associated with the passenger in the storage unit, In response to the search by the search unit failing, an information storage unit obtains information associated with the passenger through communication with the server and stores it in the storage unit. An in-vehicle device including a selection unit that selectively outputs to the processing execution unit the output of the search unit and the information acquired by the information storage unit, depending on whether the search by the search unit was successful or not.

11. The in-vehicle device according to claim 10, further comprising a passenger authentication unit for authenticating the aforementioned passenger.

12. The in-vehicle device according to claim 11, wherein the passenger authentication unit is provided in the vehicle and includes a facial image authentication unit that performs authentication using the passenger's facial image.

13. The aforementioned information includes adjustment information relating to the adjustment of equipment inside the vehicle when the passenger boards the vehicle, The in-vehicle device according to any one of claims 10 to 12, wherein the processing execution unit includes an adjustment instruction unit that instructs other devices via the in-vehicle network to automatically adjust the equipment used by the passenger of a vehicle equipped with the in-vehicle device using the adjustment information.

14. The adjustment information includes status specification information that specifies the state of the equipment when the passenger boards the vehicle, The adjustment instruction unit is, A state identification unit identifies the state that is closest to the state specified by the state specification information among the states that the equipment can take in the vehicle equipped with the vehicle device, The in-vehicle device according to claim 13, further comprising an equipment adjustment instruction unit that instructs the other device to adjust the state of the equipment used by the passenger to a state specified by the state specification unit.

15. Furthermore, the in-vehicle device according to claim 14, further comprising a change information transmission unit that, in response to the passenger manually changing the state of the equipment used by the passenger after the state of the equipment used by the passenger has been adjusted by the other device, transmits information identifying the passenger and the state of the equipment after the change to the server.

16. The in-vehicle device according to claim 14, further comprising a change information transmission unit that, after the state of the equipment used by the passenger has been adjusted by the other device, transmits to the server information identifying the passenger, the state of the equipment after the change, and information regarding the type of vehicle, in response to the passenger manually changing the state.

17. The in-vehicle device according to any one of claims 1, 2, 5, 6, 10, and 11, wherein the passenger is the driver of the vehicle.

18. A memory unit that stores personal identification information and information related to that individual in relation to each other, A server including an information transmission unit that, in response to receiving an information transmission request from an external in-vehicle device specifying an individual's identification information, reads information associated with said identification information from the storage unit and transmits it to the in-vehicle device, The aforementioned information includes information about externally controllable equipment located at a residence used by an individual after using a vehicle equipped with the aforementioned in-vehicle device, The server further includes an equipment control unit that, in response to receiving an identification information of an individual and a scheduling request relating to the controllable equipment relating to the individual from the external in-vehicle device, performs control over the equipment relating to the individual based on the scheduling request.

19. Computers, An information acquisition unit that obtains information associated with the vehicle's occupants through communication with a server, A computer program that is connected to the vehicle's in-vehicle network and functions as a processing execution unit that executes processing according to the information acquired by the information acquisition unit using resources that can communicate via the vehicle network, The aforementioned information includes key information for the automatic opening and closing device of the garage used by the passenger, The processing execution unit includes a computer program that, in response to predetermined conditions being met, instructs other devices via the in-vehicle network to operate the automatic opening and closing device using the key information.

20. Computers, An information acquisition unit that obtains information associated with the vehicle's occupants through communication with a server, A computer program that is connected to the vehicle's in-vehicle network and functions as a processing execution unit that executes processing according to the information acquired by the information acquisition unit using resources that can communicate via the vehicle network, The aforementioned information includes information regarding externally controllable equipment located at the residence used by the passenger after using the vehicle, The processing execution unit, A health condition recognition unit that recognizes the health condition of the passenger, A computer program comprising: a scheduling unit that, in accordance with the physical condition recognized by the physical condition recognition unit, selects at least one of the functions of the equipment at the passenger's residence and schedules the activation of said function.

21. Computers, An information acquisition unit that obtains information associated with the vehicle's occupants through communication with a server, A processing execution unit connected to the vehicle's in-vehicle network, which performs processing according to the information acquired by the information acquisition unit using resources that can communicate via the vehicle network, A computer program that causes the information acquisition unit to function as a storage unit for storing the information acquired by the information acquisition unit, The aforementioned information acquisition unit, A search unit that retrieves information associated with the passenger in the storage unit, In response to the search by the search unit failing, an information storage unit obtains information associated with the passenger through communication with the server and stores it in the storage unit. A computer program including a selection unit that selectively outputs to the processing execution unit the output of the search unit and the information acquired by the information storage unit, depending on whether the search by the search unit was successful or not.