Authentication system and authentication application program

The authentication system addresses the management and security issues of vehicle authentication by using separate information processing devices for secure, contactless device identification information exchange, reducing costs and simplifying the management of license codes.

JP7877029B2Active Publication Date: 2026-06-22DAIHATSU MOTOR CO LTD

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
DAIHATSU MOTOR CO LTD
Filing Date
2022-03-22
Publication Date
2026-06-22

AI Technical Summary

Technical Problem

Existing vehicle authentication systems require significant management effort and cost at the manufacturing plant to manage license codes, and HMI-based authentication methods are costly and insecure, especially in vehicles without displays.

Method used

An authentication system using separate information processing devices and in-vehicle communication devices with unique identification information, enabling secure, contactless communication and eliminating the need for license codes through device identification information exchange.

Benefits of technology

Reduces the burden and cost of managing license codes on manufacturers and enhances security by eliminating the need for visible license codes, allowing easy authentication via device identification information exchange.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007877029000001
    Figure 0007877029000001
  • Figure 0007877029000002
    Figure 0007877029000002
  • Figure 0007877029000003
    Figure 0007877029000003
Patent Text Reader

Abstract

To provide an authentication system capable of reducing the cost or burden on a manufacturer of a vehicle for managing license codes.SOLUTION: An authentication system 1 includes: an information processing apparatus 20; and an in-vehicle information communication device 10 with unique communication device identification information. The in-vehicle information communication device 10 includes: a first communication unit 11 which can transmit, to the information processing apparatus 20, vehicle-side transmission information including vehicle identification information and the communication device identification information; and a second communication unit 12 which can transmit, to a communication terminal device 30, authentication information including the communication device identification information. The information processing apparatus 20 includes: a third communication unit 21 capable of information communication related to the authentication information with the communication terminal device 30; a fourth communication unit 22 capable of information communication related to the vehicle-side transmission information with the first communication unit 11; and an authentication unit 24 which authenticates the communication terminal device 30 as an authorized terminal, on condition that the communication device identification information acquired from the communication terminal device 30 is coincident with the communication device identification information acquired from the in-vehicle information communication device 10.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an authentication system and an authentication application program that can be used in vehicle connectivity services and the like.

Background Art

[0002] Conventionally, vehicles called connected cars that can be connected to the Internet are known. Connected cars are used in various services such as vehicle sellers. A connected car is used, for example, in a vehicle monitoring system that notifies a user's mobile terminal of abnormal information in the vehicle (for example, Patent Document 1). Also, a connected car is used, for example, in a parking position notification system that notifies a user's mobile terminal of the parking position of the vehicle (for example, Patent Document 2).

[0003] The vehicle monitoring system described in Patent Document 1 mentioned above acquires abnormal information such as forgetting to lock the door in the vehicle, transmits the abnormal information to a data server by an in-vehicle device, and notifies the user's mobile phone of the abnormality of the vehicle via the data server. Further, the vehicle parking position notification system described in Patent Document 2 mentioned above connects a driver terminal, an automatic driving control device of the vehicle, and a management server via a network, and notifies the driver terminal of the vehicle parking position via the network when the vehicle stops.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0005] By the way, in the systems (connected cars) described in Patent Documents 1 and 2, authentication is required between the user's terminal device and the in-vehicle communication device in order to associate the vehicle with the user. The authentication is said to be performed, for example, in the following steps. First, the vehicle manufacturer assigns a vehicle-specific license code to the vehicle and registers the said license code with the management server. Next, the user inputs the license code assigned to the in-vehicle information communication device into the user terminal device. The input license code is transmitted to the management server via the user terminal device. The management server authenticates the user terminal device as a legitimate terminal on the condition that the license code transmitted from the user terminal device matches the license code that has been registered in advance.

[0006] However, the authentication methods described above require the vehicle manufacturing plant to issue and manage license codes. Therefore, these authentication methods have the problem of requiring management effort at the vehicle manufacturing plant to manage the license codes. In addition, the resulting management effort leads to high costs.

[0007] Furthermore, with the recent spread of autonomous driving technology for vehicles, the number of vehicles employing human-machine interfaces (HMIs) is increasing. HMIs are considered to act as intermediaries between humans and machines and include devices such as operating devices, display devices, and voice output devices in vehicles. Here, it is conceivable to use HMIs as an authentication method different from the authentication method described above. Authentication using HMIs utilizes information communication between the in-vehicle information communication device and the management server. Specifically, first, a license code is sent from the in-vehicle information communication device to the management server, establishing a communication connection between the in-vehicle information communication device and the management server. The user then verifies the aforementioned license code (pairing code) on the display of the in-vehicle information communication device or on an attached sticker. Next, the user enters the verified license code into a user terminal device and sends it to the management server via the user terminal device. The management server authenticates the user terminal device as a legitimate terminal if the license code sent from the user terminal device matches the license code sent from the in-vehicle information communication device.

[0008] However, with HMI-based authentication, if the vehicle does not have a display to show the license code, it is necessary to affix a sticker or similar document with the license code printed on it to the in-vehicle information and communication device or the vehicle itself. This results in high costs and the inability to use the system in vehicles that do not employ an HMI. Furthermore, there is a concern that the license code will be visible to others, which is undesirable from a security standpoint.

[0009] Therefore, in order to solve the above-mentioned problems, the present invention aims to provide an authentication system that can reduce the burden and cost of managing license codes on the manufacturer side, such as for vehicles. Furthermore, the present invention aims to provide an authentication application program that facilitates the use of the above-mentioned authentication system. [Means for solving the problem]

[0010] (1) The authentication system of the present invention, provided to solve the above-mentioned problems, comprises an information processing device provided separately from the vehicle, and an in-vehicle information communication device mounted on the vehicle and to which unique communication device identification information is assigned, wherein the in-vehicle information communication device comprises a first communication unit capable of transmitting information including vehicle identification information assigned to the vehicle and the communication device identification information to the information processing device as vehicle-side transmitted information, and a second communication unit that transmits information including at least the communication device identification information among the vehicle identification information assigned to the vehicle and the communication device identification information to the communication terminal device as authentication information through information communication with an arbitrary communication terminal device. The information processing device is characterized by comprising: a third communication unit that enables information communication relating to at least the authentication information with the communication terminal device; a fourth communication unit that enables information communication relating to at least the vehicle-side transmitted information with the first communication unit of the in-vehicle information communication device; and an authentication processing unit that authenticates the communication terminal device as a legitimate terminal associated with the vehicle, on the condition that the communication device identification information included in the authentication information obtained from the communication terminal device by the third communication unit matches the communication device identification information included in the vehicle-side transmitted information obtained from the in-vehicle information communication device by the fourth communication unit.

[0011] The authentication system described above allows the authentication processing unit in the information processing unit to authenticate a communication terminal device as a legitimate terminal associated with a vehicle, provided that the communication device identification information contained in the authentication information obtained from the communication terminal device matches the vehicle-side transmission information obtained from the in-vehicle information communication device. In other words, the communication terminal device can be authenticated as a legitimate terminal associated with the vehicle (in-vehicle information communication device) through information communication regarding communication device identification information between the in-vehicle information communication device, the information processing unit, and the communication terminal device. Therefore, the authentication system described above can eliminate the process of assigning license codes to in-vehicle information communication devices, etc., and the process of managing license codes at vehicle manufacturing plants, etc. Therefore, the authentication system described above can reduce the burden and cost of managing license codes on the manufacturer side of vehicles, etc. Here, the communication terminal device is assumed to be, for example, a mobile terminal such as a smartphone owned by the vehicle user. Therefore, since the user's communication terminal device can easily obtain authentication information through information communication with the in-vehicle information communication device, the burden on the user side can also be reduced.

[0012] (2) The authentication system of the present invention described above may be such that either or both of the communication device identification information and the vehicle identification information are encrypted by encryption processing.

[0013] The authentication system described above can be made more secure by adopting this configuration. Here, the encryption process can utilize, for example, a hash function that converts communication device identification information or vehicle identification information into hash values.

[0014] (3) In the authentication system of the present invention described above, it is preferable that the information communication in the second communication unit is performed by short-range communication.

[0015] The authentication system described above, with this configuration, enables contactless connection between the second communication unit of the in-vehicle information and communication device and the user's communication terminal device. Furthermore, since the authentication system described above connects the second communication unit and the communication terminal device via short-range communication, the connection can be established in a short time. For example, Wi-Fi and Bluetooth® can be used for short-range communication. In addition, communication in the second communication unit may be established not only by Wi-Fi etc. from the in-vehicle information and communication device side, but also by Wi-Fi tethering etc. from the communication terminal device side.

[0016] (4) The authentication system of the present invention described above is preferably configured such that a connection is automatically established between the communication terminal device and the second communication unit by communication, provided that the communication terminal device is located within a range that allows it to communicate with the second communication unit.

[0017] The authentication system described above, with this configuration, allows for easy communication between the communication terminal device and the second communication unit of the in-vehicle information and communication device. Therefore, the authentication system described above can reduce the operational burden on the user of the communication terminal device.

[0018] (5) The authentication system of the present invention described above is preferably such that the in-vehicle information communication device is capable of acquiring vehicle information in the vehicle and transmitting the acquired vehicle information to the fourth communication unit of the information processing device via the first communication unit, and the communication terminal device is capable of acquiring the vehicle information transmitted to the fourth communication unit via the third communication unit.

[0019] The authentication system described above, with this configuration, allows the user's communication terminal to acquire vehicle information transmitted to the information processing device, enabling the user to check vehicle information in a timely manner. Here, vehicle information is defined to include, for example, information such as the vehicle's mileage and the operating status of various sensors. Therefore, by enabling vehicle manufacturers, dealers, service factories, etc. (also simply referred to as vehicle manufacturers, etc.) to obtain vehicle information via the information processing device, it is expected that various services such as connected services utilizing vehicle information (for example, maintenance information) can be provided.

[0020] (6) In the authentication system of the present invention described above, the information processing device is preferably a server.

[0021] The authentication system described above can be centrally managed by a server through this configuration. Therefore, the authentication system can be configured simply. Furthermore, the authentication system described above can reduce the load on in-vehicle information and communication devices and user communication terminal devices.

[0022] (7) An authentication application program of the present invention provided to solve the above-described problems is an authentication application program used in the above-described authentication system, comprising: a vehicle identification information reception process that receives the vehicle identification information input in the communication terminal device and transmits the vehicle identification information to the information processing device via the third communication unit; an activation process that enables the information communication process in the in-vehicle information communication device in the information processing device; a vehicle-side transmission information communication process that transmits the vehicle-side transmission information to the fourth communication unit via the first communication unit; an information registration process that registers the communication device identification information included in the vehicle-side transmission information as registered communication device identification information in the information processing device; a communication connection process that enables information communication between the in-vehicle information communication device and the communication terminal device; and the communication device being transmitted to the communication terminal device by information communication between the in-vehicle information communication device and the communication terminal device. The system is capable of performing a communication device identification information communication process that transmits device identification information; an authentication information communication process that transmits the communication device identification information obtained by the communication device identification information communication process as authentication information to the information processing device via the third communication unit; and an authentication determination process that compares the communication device identification information contained in the authentication information transmitted in the authentication information communication process with the registered communication device identification information. The system is characterized in that, in the authentication determination process, if the communication device identification information contained in the authentication information obtained from the communication terminal device and the registered communication device identification information match, the communication terminal device is authenticated as a legitimate terminal associated with the vehicle. If, in the authentication determination process, the communication device identification information contained in the authentication information obtained from the communication terminal device and the registered communication device identification information do not match, the authentication process is not performed.

[0023] The above authentication application program can capture communication device identification information in the communication terminal device by executing communication device identification information communication processing. Therefore, when a connection is established through communication between the communication terminal device on the user side and the in-vehicle information communication device, the communication terminal device can easily obtain the communication device identification information. Also, the above authentication application program can capture vehicle-side transmitted information in the information processing device by executing vehicle-side transmitted information communication processing. Therefore, when a connection is established through communication between the information processing device and the in-vehicle information communication device, the information processing device can easily obtain the vehicle-side transmitted information. Further, the above authentication application program can transmit, as authentication information, the vehicle identification information received by the vehicle identification information input reception processing and the communication device identification information obtained by the communication device identification information communication processing from the communication terminal device to the information processing device. Thereby, the information processing device can smoothly execute an authentication determination process of comparing the communication device identification information included in the authentication information with the registered communication device identification information.

[0024] That is, the above authentication application program can authenticate the communication terminal device as a legitimate terminal associated with the vehicle (in-vehicle information communication device) through information communication regarding the communication device identification information among the in-vehicle information communication device, the information processing device, and the communication terminal device. Therefore, the above authentication application program can eliminate the process of assigning a license code to the in-vehicle information communication device, etc. and the process of managing the license code at a vehicle manufacturing factory, etc. Therefore, the above authentication application program can reduce the management burden and cost of the license code on the producer side of the vehicle, etc. Therefore, since the communication terminal device on the user side can easily obtain the authentication information through information communication with the in-vehicle information communication device, the burden on the user side can also be reduced.

Effects of the Invention

[0025] The present invention can provide an authentication system capable of reducing the management burden and cost of license codes on the producer side of vehicles and the like. Further, the present invention can provide an authentication application program that facilitates the use of the above authentication system.

Brief Description of the Drawings

[0026] [Figure 1] It is a configuration diagram of an authentication system according to an embodiment of the present invention. [Figure 2] (a) is an explanatory diagram of information communication between an information processing device and an in-vehicle information and communication device in the authentication system of the present invention, and (b) is an explanatory diagram of information communication between a communication terminal device and an in-vehicle information and communication device in the authentication system of the present invention. [Figure 3] (c) is an explanatory diagram of information communication between an information processing device and a communication terminal device in the authentication system of the present invention. [Figure 4] It is a schematic explanatory diagram of an authentication system according to an embodiment of the present invention. [Figure 5] It is a flowchart of an authentication system and an authentication application program according to an embodiment of the present invention.

Modes for Carrying Out the Invention

[0027] Hereinafter, an authentication system 1 according to an embodiment of the present invention will be described with reference to FIGS. 1 to 4. In this embodiment, a connect service provided between an information processing device 20, an in-vehicle information and communication device 10, and an arbitrary communication terminal device 30 held by a user will be described as an example.

[0028] As shown in Figure 1, the authentication system 1 includes an in-vehicle information and communication device 10 mounted on the vehicle 2, and an information processing device 20 provided separately from the vehicle 2. In this embodiment, the in-vehicle information and communication device 10 is composed of a communication device called a TCU (Telematics Control Unit) and is capable of communicating with the information processing device 20, which will be described later. The in-vehicle information and communication device 10 is also capable of communicating with any communication terminal device 30 owned by the user, such as a smartphone. Furthermore, the in-vehicle information and communication device 10 is assigned unique communication device identification information (see Figure 2).

[0029] As shown in Figure 4, communication device identification information is assigned to the in-vehicle information communication device 10 as a unique BSSID (MAC address). Therefore, the in-vehicle information communication device 10 can be identified from other communication devices by its BSSID. The in-vehicle information communication device 10 also includes a first communication unit 11, a second communication unit 12, etc. (see Figure 1).

[0030] Furthermore, vehicle 2 is assigned unique vehicle identification information. This vehicle identification information is assigned as a unique vehicle identification number (VIN) to vehicle 2. Therefore, vehicle 2 can be identified from other vehicles by its VIN.

[0031] As shown in Figures 1 and 2(a), the first communication unit 11 is configured as a wireless communication device and is capable of communicating information with the information processing device 20 through communication. The first communication unit 11 is capable of connecting with the fourth communication unit 22 of the information processing device 20, which will be described later. The first communication unit 11 can transmit information including vehicle identification information and communication device identification information assigned to the vehicle 2 to the information processing device 20 as vehicle-side transmitted information via the fourth communication unit 22. In this embodiment, the communication device identification information is encrypted by the in-vehicle information communication device 10 or the information processing device 20 (including the authentication application program described later) before being transmitted to the information processing device 20. In this embodiment, the communication device identification information is encrypted, but the encryption process can be applied to either or both the vehicle identification information and the communication device identification information, as needed. Here, the encryption process is performed, for example, by converting the communication device identification information and the vehicle identification information into hash values ​​using a hash function. Thus, the authentication system 1 of the present invention can improve security by employing a configuration that encrypts vehicle identification information and communication device identification information.

[0032] As shown in Figures 1 and 2(b), the second communication unit 12 is configured as a wireless communication device capable of short-range communication such as WiFi and Bluetooth (registered trademark). The second communication unit 12 is capable of information communication with the communication terminal device 30, which will be described later, through communication with the communication terminal device 30. Therefore, the connection between the second communication unit 12 and the user-side communication terminal device 30 can be made contactless. Furthermore, since the authentication system 1 of the present invention connects the second communication unit 12 and the communication terminal device 30 by short-range communication, the connection can be made in a short time.

[0033] Furthermore, the second communication unit 12 can transmit to the communication terminal device 30, through information communication with the communication terminal device 30, information including at least the communication device identification information among the vehicle identification information and communication device identification information assigned to the vehicle 2, as authentication information. Note that communication in the second communication unit 12 may be established not only by connecting from the in-vehicle information communication device 10 side via WiFi, etc., but also by connecting from the communication terminal device 30 side via WiFi tethering, etc.

[0034] As shown in Figure 1, the information processing device 20 is composed of a computer capable of performing various calculations and information processing. In this embodiment, the information processing device 20 is provided as a server. The information processing device 20 includes a third communication unit 21 and a fourth communication unit 22. In addition to the above, the information processing device 20 also includes a storage unit 23 and an authentication processing unit 24, etc.

[0035] The third communication unit 21 is configured as a wireless communication device and is capable of communicating information with the communication terminal device 30 through communication. As shown in Figure 3(c), the third communication unit 21 is capable of communicating information with the communication terminal device 30, at least concerning authentication information. That is, authentication information is transmitted from the communication terminal device 30 to the information processing device 20 via the third communication unit 21. The authentication information is to be encrypted as described above by an authentication application program or the information processing device 20, as needed, before being transmitted to the information processing device 20. In this way, the authentication system 1 described above can improve security by adopting a configuration that encrypts the authentication information (either one or both of the communication device identification information and the vehicle identification information).

[0036] As shown in Figures 1 and 2(a), the fourth communication unit 22 is configured as a wireless communication device and is capable of communicating information with the in-vehicle information communication device 10 by connecting with the first communication unit 11 of the in-vehicle information communication device 10. The fourth communication unit 22 is capable of communicating information with the first communication unit 11 of the in-vehicle information communication device 10, at least regarding information transmitted from the vehicle side.

[0037] As shown in Figure 1, the storage unit 23 is composed of a storage medium such as memory or a hard disk, and can store vehicle-side transmission information received via the fourth communication unit 22. Specifically, the storage unit 23 can perform information registration processing to register communication device identification information included in the vehicle-side transmission information as registered communication device identification information. Note that the storage unit 23 may be capable of storing not only communication device identification information, but also vehicle identification information, vehicle information, etc.

[0038] The authentication processing unit 24 performs an authentication determination process to determine whether the communication device identification information (registered communication device identification information) included in the authentication information obtained from the communication terminal device 30 in the third communication unit 21 matches the communication device identification information included in the vehicle-side transmission information obtained from the in-vehicle information communication device 10 in the fourth communication unit 22. In the authentication determination process, if the communication device identification information included in the authentication information obtained from the communication terminal device 30 and the registered communication device identification information match, the authentication processing unit 24 performs an authentication process to determine whether the communication terminal device 30 is a legitimate terminal. On the other hand, if the communication device identification information included in the authentication information obtained from the communication terminal device 30 and the registered communication device identification information do not match, the authentication processing unit 24 does not perform an authentication process to determine whether the communication terminal device 30 is a legitimate terminal.

[0039] The communication terminal device 30 is composed of any mobile terminal (for example, a smartphone) owned by the user. As shown in Figure 2(b), the communication terminal device 30 can communicate information with the second communication unit 12 of the in-vehicle information communication device 10 through the short-range communication described above. Through information communication with the second communication unit 12, the communication terminal device 30 can receive information including vehicle identification information and communication device identification information, at least of which includes communication device identification information, as authentication information.

[0040] Furthermore, in this embodiment, the connection between the communication terminal device 30 and the second communication unit 12 is automatically established by communication, provided that the communication terminal device 30 is located within communication range of the second communication unit 12. This allows the authentication system 1 described above to easily establish a communication connection between the communication terminal device 30 and the second communication unit 12 in the in-vehicle information communication device 10. Therefore, the authentication system 1 described above can reduce the operational burden on the user of the communication terminal device 30.

[0041] As shown in Figure 3(c), the communication terminal device 30 can connect to the third communication unit 21 of the information processing device 20 via a network such as the Internet. By connecting to the third communication unit 21, the communication terminal device 30 can communicate information with the information processing device 20, at least regarding authentication information. As described above, the communication terminal device 30 transmits authentication information to the information processing device 20 via the third communication unit 21.

[0042] The above describes the configuration of the authentication system 1 according to one embodiment of the present invention. Next, the effects and benefits of the authentication system 1 will be explained.

[0043] The authentication system 1 described above can authenticate the communication terminal device 30 as a legitimate terminal associated with vehicle 2, provided that the communication device identification information included in the authentication information obtained from the communication terminal device 30 matches the vehicle-side transmission information obtained from the in-vehicle information communication device 10. In other words, the communication terminal device 30 can be authenticated as a legitimate terminal associated with vehicle 2 (in-vehicle information communication device 10) through information communication regarding communication device identification information between the in-vehicle information communication device 10, the information processing device 20, and the communication terminal device 30. Therefore, the authentication system 1 described above can eliminate the process of assigning license codes to the in-vehicle information communication device 10, etc., and the process of managing license codes at the manufacturing plant of vehicle 2, etc. Therefore, the authentication system 1 described above can reduce the burden and cost of managing license codes on the manufacturer side of vehicle 2, etc. Here, the communication terminal device 30 is assumed to be, for example, a mobile terminal such as a smartphone owned by the user of vehicle 2. Therefore, the user's communication terminal device 30 can easily obtain authentication information through information communication with the in-vehicle information communication device 10, thus reducing the burden on the user.

[0044] Furthermore, in this embodiment, the information processing device 20 is configured as a server. Therefore, the authentication system 1 described above can be centrally managed by the server, simplifying the configuration. In addition, the authentication system 1 described above can reduce the load on the in-vehicle information communication device 10 and the user's communication terminal device 30.

[0045] The above describes the operation and effects of the authentication system 1 of the present invention. Next, a modified example of the authentication system 1 of the present invention will be described.

[0046] ≪Variations≫ The modified authentication system 1 has the same configuration as the embodiment described above, except that it allows for the exchange of vehicle information in vehicle 2, so the explanation of the similar parts will be omitted.

[0047] Although not shown in the diagram, the modified authentication system 1 is configured such that the in-vehicle information communication device 10 can acquire vehicle information from the vehicle 2. Here, the aforementioned vehicle information includes, for example, information such as the mileage traveled by the vehicle 2 and information such as the operating status of various sensors. The in-vehicle information communication device 10 can transmit the acquired vehicle information to the fourth communication unit 22 of the information processing device 20 via the first communication unit 11. Furthermore, the communication terminal device 30 can acquire the vehicle information transmitted to the fourth communication unit 22 via the third communication unit 21.

[0048] As described above, the modified authentication system 1 allows the user's communication terminal device 30 to acquire vehicle information transmitted to the information processing device 20, enabling the user to check vehicle information in a timely manner. Furthermore, by enabling vehicle manufacturers, dealers, service factories, etc. (also simply referred to as vehicle manufacturers, etc.) to obtain vehicle information via the information processing device 20, it is expected that various services such as connected services utilizing vehicle information (for example, maintenance information) can be provided.

[0049] The above describes the configuration and effects of the modified authentication system 1 of the present invention. Next, an authentication application program (hereinafter also referred to as an authentication app) using the authentication system 1 of the present invention will be described below.

[0050] The authentication application of the present invention is incorporated into the in-vehicle information and communication device 10, the information processing device 20, and the communication terminal device 30, and each of the in-vehicle information and communication device 10, the information processing device 20, and the communication terminal device 30 operates in cooperation with each other (see Figures 2 and 3).

[0051] As shown in Figure 5, when the authentication application is started in the communication terminal device 30, the process of receiving vehicle identification information (VIN) input from the user begins. The user inputs the vehicle identification information through the authentication application. The input vehicle identification information is then transmitted to the information processing device 20 via the third communication unit 21 (vehicle identification information reception process: step S1).

[0052] Next, the information processing device 20 activates the information communication processing in the in-vehicle information communication device 10 (activation process: step S2).

[0053] Next, the in-vehicle information communication device 10 is activated (for example, the ignition of vehicle 2 is turned on), and encrypted communication device identification information (hash value of BSSID: see Figure 4) is transmitted to the fourth communication unit 22 of the information processing device 20 as vehicle-side transmitted information (vehicle-side transmitted information communication processing: step S3). At the same time, the information processing device 20 also performs an information registration process to register the communication device identification information included in the vehicle-side transmitted information as registered communication device identification information.

[0054] Next, the in-vehicle information communication device 10 and the communication terminal device 30 are connected via the authentication application. This enables information communication between the in-vehicle information communication device 10 and the communication terminal device 30 (communication connection process: step S4). In step S4, a process is performed to transmit communication device identification information to the communication terminal device 30 based on the information communication between the in-vehicle information communication device 10 and the communication terminal device 30 (communication device identification information communication process).

[0055] Next, the communication device identification information obtained through the communication device identification information communication processing is transmitted to the information processing device 20 via the third communication unit 21 as authentication information (authentication information communication processing: step S5). At this time, at least the communication device identification information in the authentication information is converted into a hash value by encryption processing (processing using a hash function).

[0056] Next, a process related to authentication determination is performed, which compares the communication device identification information contained in the authentication information transmitted in the authentication information communication process with the registered communication device identification information (authentication determination process: step S6).

[0057] In the authentication determination process, if the communication device identification information included in the authentication information obtained from the communication terminal device 30 matches the registered communication device identification information, the communication terminal device 30 is authenticated as a legitimate terminal associated with the vehicle 2 (authentication successful: step S7).

[0058] On the other hand, in the authentication determination process, if the communication device identification information included in the authentication information obtained from the communication terminal device 30 and the registered communication device identification information do not match, the authentication process will not be performed on the communication terminal device 30 as a legitimate terminal (authentication failure: step S8).

[0059] When step S7 or step S8 is completed, the authentication process (authentication application) is terminated. If the connection between the communication terminal device 30 and the in-vehicle information communication device 10 is resumed after the authentication application has terminated, the process from step S1 should be executed again.

[0060] The above describes one embodiment of the operation flow of the authentication application program of the present invention. Next, the effects of the authentication application program will be described below.

[0061] The authentication application described above can acquire communication device identification information into the communication terminal device 30 by executing communication device identification information communication processing. Therefore, once a communication connection is established between the user-side communication terminal device 30 and the in-vehicle information communication device 10, the communication terminal device 30 can easily acquire the communication device identification information. Furthermore, the authentication application described above can acquire vehicle-side outgoing information into the information processing device 20 by executing vehicle-side outgoing information communication processing. Therefore, once a communication connection is established between the information processing device 20 and the in-vehicle information communication device 10, the information processing device 20 can easily acquire vehicle-side outgoing information. In addition, the authentication application described above can transmit the vehicle identification information received through the vehicle identification information input acceptance processing and the communication device identification information acquired through the communication device identification information communication processing as authentication information from the communication terminal device 30 to the information processing device 20. This allows the information processing device 20 to smoothly perform authentication determination processing, which compares the communication device identification information included in the authentication information with the registered communication device identification information.

[0062] As described above, the authentication application of the present invention can authenticate the communication terminal device 30 as a legitimate terminal associated with the vehicle 2 (in-vehicle information communication device 10) through information communication related to communication device identification information between the in-vehicle information communication device 10, the information processing device 20, and the communication terminal device 30. Therefore, the authentication application described above can eliminate the process of assigning license codes to the in-vehicle information communication device, etc., and the process of managing license codes at the vehicle manufacturing plant, etc. Therefore, the authentication application described above can reduce the burden and cost of managing license codes on the manufacturer side of vehicles, etc. Therefore, the user's communication terminal device 30 can easily obtain authentication information through information communication with the in-vehicle information communication device 10, thus reducing the burden on the user side.

[0063] The above describes embodiments of the authentication system 1 and authentication application program of the present invention. However, the authentication system 1 and authentication application program of the present invention are not limited to the embodiments described above, and can be modified in various ways.

[0064] In this embodiment, the case where the information processing device 20 is a server is illustrated, but the information processing device 20 is not limited to a server, and various types of information processing equipment can be used. Also, the information processing device 20 can be placed in various locations. Furthermore, the in-vehicle information communication device 10 is not limited to a TCU, and for example, a navigation device can be used. In such cases, information communication with the information processing device 20 may be performed using a communication line (such as WiFi tethering) provided by the user's communication terminal device 30. In addition, in this embodiment, BSSID (MAC address) is used as communication device identification information, but various types of identification information can be used as long as they can identify the communication device. Furthermore, in this embodiment, the in-vehicle information communication device 10 has a first communication unit 11 and a second communication unit 12, but the first communication unit 11 and the second communication unit 12 may be common to each other. Similarly, the third communication unit 21 and the fourth communication unit 22 in the information processing device 20 may be common to each other. Furthermore, in this embodiment, communication device identification information and vehicle identification information are transmitted from the in-vehicle information communication device 10 to the information processing device 20. However, if authentication can be performed using either one of them, it is sufficient to transmit only one of them. In such cases, the authentication information and the authentication processing in the authentication processing unit 24 can also use either the corresponding communication device identification information or vehicle identification information.

[0065] In this embodiment, we have illustrated a case where either or both of the communication device identification information and the vehicle identification information are converted into a hash value using a hash function. However, encryption is not limited to conversion into a hash value using a hash function; it can also be encrypted using various encryption methods. For example, encryption methods such as symmetric-key cryptography or public-key cryptography may be used.

[0066] Furthermore, although this embodiment illustrates an example where information communication in the second communication unit 12 is performed by short-range communication, information communication in the second communication unit 12 is not limited to short-range communication, and various types of communication means can be used. For convenience, it is preferable that the communication means be performed wirelessly.

[0067] Furthermore, in this embodiment, the connection between the communication terminal device 30 and the second communication unit 12 is automatically established by communication, provided that the communication terminal device 30 is located within communication range of the second communication unit 12. However, this is not the only limitation. For example, the connection between the communication terminal device 30 and the second communication unit 12 may be established manually.

[0068] Furthermore, in this modified example, the in-vehicle information communication device 10 is capable of acquiring vehicle information in the vehicle 2 and transmitting the acquired vehicle information to the fourth communication unit 22 of the information processing device 20 via the first communication unit 11. However, the vehicle information can be transmitted to the information processing device 20 only when necessary.

[0069] In this embodiment, vehicle identification information is input to the communication terminal device 30, but the vehicle identification information may be automatically input to the communication terminal device 30 and transmitted to the information processing device 20. In this case, it is preferable to transmit the vehicle identification information from the in-vehicle information communication device 10 to the communication terminal device 30. Also, in this embodiment, an activation process is performed in the information processing device 20 to activate the information communication processing in the in-vehicle information communication device 10, but the activation process may be performed only as needed and may be omitted. Also, in this embodiment, an information registration process is performed to register communication device identification information in the information processing device 20, but the information registration process may be performed only as needed and may be omitted. In this case, the communication device identification information transmitted to the information processing device 20 and the communication device identification information transmitted from the communication terminal device 30 to the information processing device 20 can be directly compared. Also, in the authentication application of the present invention, the communication terminal device 30 is authenticated using the communication device identification information and the vehicle identification information, but if authentication is possible with either the communication device identification information or the vehicle identification information, the authentication process may be performed with either one. Furthermore, authentication applications can be used in various forms, including those installed on the communication terminal device 30, those accessed via the internet or other networks, or those installed on the information processing device 20 or the in-vehicle information communication device 10 and accessed via the network.

[0070] The above describes various embodiments and modifications of the authentication system 1 and authentication application program according to the present invention. However, the present invention is not limited to those exemplified in the embodiments and modifications described above, and it will be readily apparent to those skilled in the art that other embodiments may exist in the spirit and teachings thereof, without departing from the scope of the claims. [Industrial applicability]

[0071] The authentication system and authentication application program of the present invention can be used for authentication between an in-vehicle information and communication device such as a TCU in a vehicle and a communication terminal device such as a smartphone owned by the vehicle user. [Explanation of symbols]

[0072] 1: Authentication System 10: In-vehicle information and communication device 11: First Communications Department 12: Second Communications Department 20: Information Processing Device 21: Third Communications Department 22:Fourth Communication Department 23: Storage section 24: Authentication Processing Unit 30: Communication terminal equipment

Claims

1. An information processing device installed separately from the vehicle, An in-vehicle information communication device installed in the aforementioned vehicle and assigned unique communication device identification information, Any communication terminal device, An authentication application program used in an authentication system having, The authentication application program is incorporated into the in-vehicle information communication device, the information processing device, and the communication terminal device, and each of the in-vehicle information communication device, the information processing device, and the communication terminal device operates in cooperation with each other. The in-vehicle information and communication device is A first communication unit capable of transmitting information including vehicle identification information assigned to the vehicle and communication device identification information to the information processing device as vehicle-side transmitted information, A second communication unit transmits to the communication terminal device, as authentication information, vehicle identification information assigned to the vehicle and information including at least the communication device identification information among the communication device identification information, through information communication with an arbitrary communication terminal device. It has the following characteristics: The aforementioned information processing device is A third communication unit that enables information communication with the aforementioned communication terminal device, at least regarding the authentication information, A fourth communication unit that enables information communication with at least the vehicle-side transmitted information between the first communication unit of the in-vehicle information communication device and the fourth communication unit, An authentication processing unit authenticates the communication terminal device as a legitimate terminal associated with the vehicle, provided that the communication device identification information included in the authentication information obtained from the communication terminal device in the third communication unit matches the communication device identification information included in the vehicle-side transmission information obtained from the in-vehicle information communication device in the fourth communication unit. It has the following characteristics: The communication terminal device is capable of transmitting the authentication information to the information processing device via the third communication unit, and is also capable of receiving the authentication information through information communication with the second communication unit. The communication terminal device includes a vehicle identification information receiving process that receives the input vehicle identification information and transmits the vehicle identification information to the information processing device via the third communication unit, The information processing device includes an activation process for activating the information communication processing in the in-vehicle information communication device, In the in-vehicle information communication device, the vehicle-side transmission information communication process transmits the vehicle-side transmission information to the fourth communication unit via the first communication unit, The information processing device includes an information registration process that registers the communication device identification information included in the vehicle-side transmission information as registered communication device identification information, In the in-vehicle information communication device and the communication terminal device, a communication connection process is provided to enable information communication between the in-vehicle information communication device and the communication terminal device. A communication device identification information communication process is performed in the in-vehicle information communication device and transmits the communication device identification information to the communication terminal device through information communication between the in-vehicle information communication device and the communication terminal device, In the aforementioned communication terminal device, the communication device identification information obtained by the communication device identification information communication process is transmitted as authentication information to the information processing device via the third communication unit, and the authentication information communication process is performed. The information processing device is capable of performing an authentication determination process which involves comparing the communication device identification information contained in the authentication information transmitted in the authentication information communication process with the registered communication device identification information. In the authentication determination process described above, if the communication device identification information included in the authentication information obtained from the communication terminal device and the registered communication device identification information match, the communication terminal device is authenticated as a legitimate terminal associated with the vehicle. An authentication application program characterized in that, in the authentication determination process, if the communication device identification information included in the authentication information obtained from the communication terminal device and the registered communication device identification information do not match, the authentication process is not performed.

2. The authentication application program according to claim 1, characterized in that either or both of the communication device identification information and the vehicle identification information are encrypted by an encryption process.

3. The authentication application program according to claim 1 or 2, characterized in that the information communication in the second communication unit is performed by short-range communication.