Information processing device

The information processing apparatus addresses the challenge of inappropriate setting application in vehicles by using reliable user recognition to selectively apply settings, ensuring privacy and safety considerations are met.

JP7896649B2Active Publication Date: 2026-07-29TOYOTA JIDOSHA KK
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
TOYOTA JIDOSHA KK
Filing Date
2024-02-08
Publication Date
2026-07-29

AI Technical Summary

Technical Problem

Existing technologies fail to appropriately select and apply user-specific settings to in-vehicle devices, particularly those with high privacy concerns or significant impact on vehicle safety, due to unreliable user recognition methods.

Method used

An information processing apparatus that recognizes users using multiple methods and selectively applies settings based on the reliability of the recognition method, ensuring privacy and safety considerations are met.

Benefits of technology

Enables flexible and appropriate application of user-specific settings to in-vehicle devices, enhancing user convenience while protecting privacy and ensuring vehicle safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007896649000001
    Figure 0007896649000001
  • Figure 0007896649000002
    Figure 0007896649000002
  • Figure 0007896649000003
    Figure 0007896649000003
Patent Text Reader

Abstract

To appropriately select a setting item applied to an on-vehicle device.SOLUTION: An information processor 100 for applying setting related to a user to an on-vehicle device includes a control part 110 for executing to recognize a user by one of a plurality of different recognition methods, and to select a setting item applied to an on-vehicle device, among a plurality of setting items indicating the setting related to the user, according to the type of the recognition method having recognized the user.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a device for managing settings of in-vehicle devices.

Background Art

[0002] Techniques for identifying a user and reflecting settings suitable for the user in an in-vehicle device or the like are known. In this regard, for example, Patent Document 1 discloses an electronic key system that identifies a user getting into a vehicle by the user's mobile terminal and adjusts the seat position via a seat device so as to correspond to the user.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] An object of the present disclosure is to appropriately select setting items to be applied to in-vehicle devices.

Means for Solving the Problems

[0005] One aspect of an embodiment of the present disclosure is an information processing apparatus that applies settings related to a user to an in-vehicle device, the apparatus including a control unit configured to recognize the user by one of a plurality of different types of recognition methods, and select, according to the type of the recognition method by which the user is recognized, a setting item to be applied to the in-vehicle device from among a plurality of setting items indicating the settings related to the user. The information processing apparatus.

[0006] Other embodiments include a method performed by the above-mentioned device, a program for causing a computer to perform the method, or a computer-readable storage medium that non-temporarily stores the program. [Effects of the Invention]

[0007] According to this disclosure, it is possible to appropriately select the setting items to be applied to in-vehicle equipment. [Brief explanation of the drawing]

[0008] [Figure 1] A diagram showing an overview of the process performed by the authentication device according to the first embodiment. [Figure 2] A diagram illustrating the components of an authentication device according to the first embodiment. [Figure 3] A flowchart of the process performed by the control unit of the authentication device according to the first embodiment. [Figure 4] A table showing the reliability of the user recognition method according to the first embodiment. [Figure 5] A table showing the level of privacy of the setting items according to the first embodiment. [Figure 6] A table showing the magnitude of the impact of the setting items according to the second embodiment on vehicle safety. [Modes for carrying out the invention]

[0009] (overview) It is envisioned that the system will identify the user riding in the vehicle and apply settings tailored to that user to the in-vehicle equipment. In this case, the settings applied to the in-vehicle equipment (hereinafter referred to as "setting items") will include settings that have a high degree of user privacy or settings that have a significant impact on vehicle safety. For example, user name, destination history, driver's seat position. The settings items, such as those related to vehicle placement, are either highly sensitive to user privacy or have a significant impact on vehicle safety. Therefore, applying these settings to others by mistake is undesirable from a privacy and safety standpoint. Accordingly, the application of these settings to in-vehicle devices is handled cautiously, and is only permitted when user recognition is performed using a highly accurate recognition method.

[0010] However, in conventional technology, when user recognition was performed using an unreliable method, not only were settings that required careful application prevented from being applied to in-vehicle devices, but even settings that posed little problem when applied were prevented from being applied. In other words, when user recognition was performed using an unreliable method, settings with low privacy concerns or settings that had little impact on vehicle safety could not be uniformly applied to in-vehicle devices. However, when user recognition was performed using an unreliable method, it is desirable that settings with low privacy concerns or settings that had little impact on vehicle safety could be applied. To solve this problem, it is desirable that the device be able to flexibly select the settings that can be applied to in-vehicle devices, etc., according to the reliability of the user recognition method.

[0011] An information processing device relating to one aspect of this disclosure is: An information processing device for applying user settings to an in-vehicle device, comprising a control unit that performs the following: recognize the user using one of a plurality of different types of recognition methods; and, according to the type of recognition method used to recognize the user, select a setting item to be applied to the in-vehicle device from a plurality of setting items indicating the user settings.

[0012] The method of user recognition refers to the method by which the information processing device related to this disclosure recognizes who the user is who is riding in the vehicle. Typically, user recognition is performed using a smartphone associated with the user, the electronic key of the vehicle on which the information processing device related to this disclosure is installed, or the like.

[0013] Settings related to a user are settings individually determined for each user and applied to various equipment provided in a vehicle such as in-vehicle devices or seats. Specifically, settings related to a user are display settings of in-vehicle devices, or the position of the driver's seat or steering wheel, etc. Settings related to a user include a plurality of setting items.

[0014] When recognizing a user, the control unit selects setting items to be applied to in-vehicle devices and the like according to the type of recognition method used. For example, when a higher-precision recognition method is used, it is possible to select setting items with high privacy or setting items that affect safety. On the contrary, when a lower-precision recognition method is used, select setting items with low privacy or setting items that do not affect safety.

[0015] Thereby, the information processing apparatus according to the present disclosure can flexibly select setting items to be applied to in-vehicle devices and the like according to the user's recognition method. That is, the information processing apparatus according to the present disclosure can improve the convenience of the user in applying settings in a vehicle including in-vehicle devices and the like.

[0016] In addition, a reliability is associated with each of a plurality of different recognition methods when the recognition method is used for the user's recognition, and the control unit may select the setting items to be applied to the in-vehicle device among the plurality of setting items based on the reliability of the recognition method.

[0017] Reliability is a value indicating the probability (that is, the high recognition accuracy) that the user identified by the recognition method is the person who faced user recognition when a certain user's recognition method is used. The higher the reliability, the higher the possibility that the user identified by the user's recognition method is the person who faced user recognition.

[0018] Thereby, the information processing apparatus according to the present disclosure can select appropriate setting items according to the reliability of the recognition method used for user recognition.

[0019] Further, the control unit may determine to apply, to the in-vehicle device, a setting item that has a greater impact on the privacy of the user among the plurality of setting items as the reliability of the recognition method is higher.

[0020] Thereby, the information processing apparatus according to the present disclosure can select a setting item having an appropriate level of privacy according to the reliability of the user's recognition method. For example, when the reliability of the user's recognition method is low, a person different from the identified user may be riding in the vehicle. In that case, it is possible to prevent the personal information of the identified user from being inadvertently leaked to a third party because a setting item related to the privacy of the identified user is applied to an in-vehicle device or the like.

[0021] Further, the control unit may determine to apply, to the in-vehicle device, a setting item that has a greater impact on the safety of the vehicle in which the in-vehicle device is mounted among the plurality of setting items as the reliability of the recognition method is higher.

[0022] Thereby, the information processing apparatus according to the present disclosure can select a setting item having an appropriate level of impact on the safety of the vehicle according to the reliability of the user's recognition method. For example, when the reliability of the user's recognition method is low, a person different from the identified user may be riding in the vehicle. In that case, it is possible to prevent a problem from occurring in the operation of the vehicle because a setting specialized for the identified user is applied to an in-vehicle device or the like.

[0023] Further, the recognition method may be any one of recognition by an electronic key, recognition by a digital key, recognition by a Bluetooth ( registered trademark) device, biometric recognition, and recognition based on an input operation by the user.

[0024] An electronic key is typically a key fob associated with a vehicle. A digital key is typically authentication data transmitted from a mobile device to a vehicle. Digital keys may be transmitted via a Bluetooth® device. User input operations are typically... This is an operation in which the user sets the driver themselves. The user may also set a password associated with their account and enter it during user recognition.

[0025] The following describes specific embodiments of this disclosure with reference to the drawings. Unless otherwise specified, the hardware configurations, module configurations, functional configurations, etc., described in each embodiment are not intended to limit the technical scope of the disclosure to those described therein.

[0026] (First embodiment) <Overview of Authentication Device Processing> The outline of the processing performed by the authentication device according to the embodiment will be explained with reference to Figure 1. Figure 1 shows an outline of the processing performed by the authentication device 100 according to the first embodiment. Here, the authentication device 100 is an example of an information processing device according to the present disclosure. The authentication device 100 identifies the user who has boarded the vehicle 10 and applies the settings associated with that user to the in-vehicle equipment, etc. The authentication device 100 also communicates with a database (described later) and applies the settings associated with the user Information regarding the settings may be obtained. The authentication device 100 is typically implemented as an in-vehicle device mounted on the vehicle 10. The authentication device 100 may be controlled by multiple in-vehicle devices or multiple ECUs mounted on the vehicle 10.

[0027] First, when a user boards the vehicle 10, the authentication device 100 performs user recognition using one of several user recognition methods. For example, the user recognition methods include recognition by electronic key, recognition by digital key, recognition by Bluetooth® device, biometric recognition, and This includes recognition based on user input.

[0028] Next, the authentication device 100 selects a setting to apply to the in-vehicle equipment, etc., according to the user recognition method. For example, the authentication device 100 selects a setting that applies different levels of privacy depending on the reliability of the user recognition method. Here, the reliability of the user recognition method is a value that indicates the probability that the person identified as a user when user recognition is performed is the person who underwent the user recognition (i.e., recognition accuracy).

[0029] For example, let's consider the case where user recognition is performed using an electronic key. An electronic key is typically a key fob corresponding to vehicle 10. For example, if multiple people use vehicle 10, each person may have their own electronic key. In this case, the user who boarded the vehicle can be estimated based on the identifier of the electronic key. However, it is possible that the electronic key held by one user may belong to another user. In other words, recognition using an electronic key is a recognition method with a low or moderate degree of accuracy in identifying the person who is undergoing user recognition using the electronic key. When user recognition is performed using an electronic key, the authentication device 100 selects settings with low privacy and settings with moderate privacy as settings to be applied to the in-vehicle equipment, etc. Conversely, when user recognition is performed using an electronic key, the authentication device 100 does not select settings with high privacy as settings to be applied to the in-vehicle equipment, etc.

[0030] In other words, if user recognition is performed using a recognition method with low or moderate reliability, the authentication device 100 will not apply highly private settings to the in-vehicle equipment, etc., from among the settings associated with the user identified by user recognition. This is because, if there is a certain degree of possibility that the identified user is not the person who boarded the vehicle 10, applying highly private settings to the in-vehicle equipment, etc., is undesirable from the standpoint of protecting the user's privacy. The authentication device 100 then applies the selected settings to the in-vehicle equipment, etc.

[0031] Thus, in the first embodiment, the authentication device 100 is configured to extract highly private settings and not apply them to in-vehicle equipment, etc., when there is a possibility that the user identified by user recognition is not the person who performed the recognition. The settings that are applied to in-vehicle equipment, etc., vary depending on the reliability of the method used for user recognition. With this configuration, the authentication device 100 can flexibly select the settings to be applied to in-vehicle equipment, etc., according to the reliability of the user recognition method.

[0032] <Configuration of the authentication device> Figure 2 is a diagram illustrating the components of the authentication device 100 according to the first embodiment. In Figure 2, the authentication device 100 may be implemented as a computer installed in one or more in-vehicle devices mounted on the vehicle 10.

[0033] The authentication device 100 according to this embodiment comprises a control unit 110, a storage unit 120, and a communication unit 130. The authentication device 100 is mounted on the vehicle 10. The authentication device 100 may also be incorporated into a device mounted on the vehicle 10 that can perform settings related to driving assistance for the vehicle 10, provide route guidance, adjust the in-vehicle environment, etc. The authentication device 100 is located in the driver's seat. It may also be a terminal for a car navigation system installed in the vehicle. The authentication device 100 may include a display, an input unit, and an audio output unit. Alternatively, the authentication device 100 may include an audio output unit and a touch panel display to accept input from the user. Alternatively, the authentication device 100 may be any in-vehicle terminal other than a car navigation terminal.

[0034] The control unit 110 is implemented using a processor such as a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit) and memory. The control unit 110 includes a recognition unit 111, a determination unit 112, a selection unit 113, and an application unit 114 as functional modules. These functional modules may be implemented by executing a program using the control unit 110.

[0035] The recognition unit 111 recognizes the user using the vehicle 10. The recognition unit 111 recognizes the user using one of several existing recognition methods. Alternatively, the recognition unit 111 may perform user recognition by combining several of the existing recognition methods. These existing recognition methods include, for example, recognition using an electronic key, recognition using a digital key, and Bluetooth (registration). Recognition may be by a device (trademark), biometric recognition, or user input. A digital key is authentication data transmitted to the authentication device 100 from a mobile terminal or the like that the user possesses. Mobile terminals are considered to be relatively more reliable than electronic keys because they are more likely to be carried by their owners. In addition, Bluetooth® devices are, for example, smart Bluetooth devices are information terminals such as smartphones or tablet devices. Although it is highly likely that the user of vehicle 10 is carrying it, vehicle 10 does not necessarily detect the Bluetooth® device that the user is carrying. For example, vehicle 10 may also detect a Bluetooth® device carried by another person in the vicinity, who is not the user riding in vehicle 10. Therefore, the reliability of the Bluetooth® device is considered to be equivalent to the reliability of the electronic key (low to medium).

[0036] The determination unit 112 determines the reliability of the method used by the recognition unit 111 for recognition. Here, the reliability of the method used for recognition is a value that indicates the probability that the recognition unit 111 has correctly identified the person undergoing user recognition. The reliability of the method used for recognition may be the probability itself of correctly identifying the person undergoing user recognition, or it may be a numerical value or string that represents the degree to which the person undergoing user recognition has been correctly identified using a multi-level evaluation. The determination unit 112 makes the above determination by referring to predetermined reliability data for each of the recognition methods that the recognition unit 111 can use for recognition. For example, the determination unit 112 may refer to reliability data stored in the storage unit 120, or reliability data stored in the storage unit 320 of the database 300. Alternatively, the determination unit 112 may refer to reliability data stored in an external storage device other than those mentioned above.

[0037] The selection unit 113 selects setting items to be applied to in-vehicle equipment, etc., according to the reliability of the recognition method determined by the determination unit 112. For example, if the reliability of the recognition method is high, the selection unit 113 selects setting items with high privacy in addition to setting items with low privacy as setting items to be applied to in-vehicle equipment, etc. Conversely, if the reliability of the recognition method is low, the selection unit 113 selects only setting items with low privacy as setting items to be applied to in-vehicle equipment, etc.

[0038] The application unit 114 applies the settings indicated by the setting items selected by the selection unit 113 to the in-vehicle equipment, etc. The application unit 114 communicates with the in-vehicle equipment, etc., transmits information about the setting items to be applied to the in-vehicle equipment, etc., and instructs the in-vehicle equipment to apply those settings. The in-vehicle equipment may be an in-vehicle terminal 13 that provides information to the user, or an ECU 12 that controls the vehicle.

[0039] The memory unit 120 is a main memory device such as RAM or ROM, an EPROM, a hard disk drive, and an auxiliary memory device such as removable media. The auxiliary memory device stores the operating system (OS), various programs, various tables, etc., and by executing the programs stored therein, each function that matches the predetermined purpose of each part of the control unit 110 can be realized. However, some or all of the functions may be realized by hardware circuits such as ASICs or FPGAs.

[0040] The storage unit 120 stores data used or generated in the processing performed by the control unit 110. The storage unit 120 may also store information such as the reliability of the recognition method, the level of privacy of the setting items, and the magnitude of the impact of the setting items on vehicle safety.

[0041] The communication unit 130 is composed of a communication circuit that performs wireless communication. The communication unit 130 may be, for example, a communication circuit that performs wireless communication using 4G (4th Generation), or a communication circuit that performs wireless communication using 5G (5th Generation). Alternatively, the communication unit 130 may be a communication circuit that performs wireless communication using LTE (Long Term Evolution), or LPWA (Low Power Wide Area). The communication circuit may perform communication using Area (Wi-Fi). Alternatively, the communication unit 130 may be a communication circuit that performs wireless communication using Wi-Fi (registered trademark).

[0042] Next, we will describe the components other than the authentication device 100 that are installed in the vehicle 10.

[0043] The drive unit 11 is a means for moving the vehicle 10. The drive unit 11 may consist of, for example, a motor and inverter for driving the wheels, brakes, and a steering mechanism. The drive unit 11 may be powered by electricity supplied from a drive battery.

[0044] ECU12 is an electronic control unit, which is a computer for realizing various functions necessary for the operation of the vehicle 10. Multiple ECUs 12 may be installed. ECU12 may receive instructions from the authentication device 100 and execute some of the operations performed by the authentication device 100. For example, ECU12 may receive instructions from the determination unit 112 and determine the reliability of the user's recognition method. ECU12 may also be a control unit (such as a body ECU) that controls equipment (such as a seat actuator) of the vehicle 10. In this case, ECU12 may receive instructions from the application unit 114 to apply the settings indicated by the setting item selected by the selection unit 113, among the in-vehicle settings related to driving, such as the position of the driver's seat or the position of the steering wheel, to the equipment of the vehicle 10 related to said settings.

[0045] The in-vehicle terminal 13 is a terminal that receives input for settings necessary for driving the vehicle 10 and provides the driver with a car navigation system. The in-vehicle terminal 13 may also have a display. The in-vehicle terminal 13 receives from the application unit 114 the application of various settings in the car navigation system selected by the selection unit 113, the air conditioning settings of the vehicle 10, the volume settings of the in-vehicle terminal 13, etc., and reflects them in the corresponding various devices.

[0046] <Devices other than authentication devices> Next, I will explain database 300.

[0047] The database 300 is a storage device that stores information representing user-specific settings, which is referenced by the authentication device 100. The database 300 comprises a control unit 310, a storage unit 320, and a communication unit 330.

[0048] The control unit 310 is implemented using a processor such as a CPU or GPU and memory. Each functional module included in the control unit 310 may be implemented by the control unit 310 executing a program. The control unit 310, for example, in response to a request from the authentication device 100, retrieves setting items corresponding to a specified user from the storage unit 320 and transmits them to the authentication device 100.

[0049] The memory unit 320 stores the information representing the user-specific settings, as described above. The memory unit 320 is a main memory device such as RAM or ROM, an EPROM, a hard disk drive, and an auxiliary memory device such as removable media. The auxiliary memory device stores the operating system (OS), various programs, various tables, etc., and by executing the programs stored therein, each function that matches the predetermined purpose of each part of the control unit 310 can be realized. However, some or all of the functions may be realized by hardware circuits such as ASICs or FPGAs.

[0050] The communication unit 330 is composed of a communication circuit that performs wireless communication. The communication unit 330 may be, for example, a communication circuit that performs wireless communication using 4G, or a communication circuit that performs wireless communication using 5G. Alternatively, the communication unit 330 may be a communication circuit that performs wireless communication using LTE, or a communication circuit that performs communication using LPWA. Furthermore, the communication unit 330 may be a communication circuit that performs wireless communication using Wi-Fi (registered trademark).

[0051] <Operation of the authentication device> Next, we will explain the specific details of the processing performed by the authentication device 100. Figure 3 is a flowchart of the processing performed by the control unit 110 of the authentication device 100 according to the first embodiment.

[0052] Before the illustrated process begins, the recognition unit 111 of the authentication device 100 is in a standby state and is always in a state where it can detect wireless signals, etc., used for user recognition. When the recognition unit 111 detects wireless signals, etc., used for user recognition, or when there is any input related to user recognition from an input device mounted on the vehicle 10, the process of step S10 begins.

[0053] First, in step S10, the recognition unit 111 recognizes the user. The recognition unit 111 recognizes the user using an electronic key, a digital key, or a Bluetooth® device. It supports multiple recognition methods, including biometric recognition and recognition based on user input. The recognition unit 111 detects wireless signals used in the above recognition methods, or input signals from a corresponding input device, and identifies the user who is trying to use the vehicle 10. Recognition based on user input refers to a recognition method that identifies the user based on the content entered by the user themselves on a predetermined user interface screen.

[0054] Next, in step S11, the recognition unit 111 determines whether or not it was able to identify the user. The recognition unit 111 determines whether or not it was able to identify the user as a specific user, based on the recognition of the user in step S10. This step results in an affirmative determination if the recognition unit 111 determines that it was able to identify the user.

[0055] If the result in this step is positive, the process proceeds to step S12.

[0056] If the result in this step is negative, the process terminates.

[0057] If the process proceeds to step S12, the determination unit 112 determines whether the reliability of the means (recognition method) used by the recognition unit 111 to recognize the user is equal to or greater than a predetermined value. Here, reliability is a value that indicates the degree to which the person being recognized can be identified without fail when a certain user recognition method is used to recognize the user. The determination unit 112 has determined in advance The determination unit 112 determines whether the reliability of a given recognition method is equal to or greater than a predetermined value by referring to a predetermined memory area or the like where the reliability of the recognition method is recorded. The determination unit 112 may refer to information about the reliability of the user's recognition method stored in the memory unit 120, or it may communicate with the database 300 and refer to information about the reliability of the user's recognition method stored in the memory unit 320 of the database 300. This step results in an affirmative determination if the determination unit 112 determines that the reliability of the method used by the recognition unit 111 for recognition is equal to or greater than a predetermined value.

[0058] If the result in this step is positive, the process proceeds to step S13.

[0059] If the result in this step is negative, the process proceeds to step S14.

[0060] Figure 4 is a table showing the reliability of the user recognition method according to the first embodiment. As shown in Table 1, for example, the reliability of an electronic key is set to medium to low. In the case of user recognition using an electronic key, since there are only a few electronic keys, there is a high probability that the user identified by the recognition unit 111 is actually using that electronic key. However, the possibility that someone other than the user identified by the recognition unit 111 is using the electronic key cannot be ruled out. For this reason, the reliability of the electronic key is set as shown in Figure 4. On the other hand, in the case of biometric authentication, since it identifies the face, voiceprint, iris, or fingerprint, the probability that the user undergoing user recognition is the user identified by the recognition unit 111 is extremely high. For this reason, as shown in Figure 4, the reliability of biometric authentication is set to high. Other user recognition methods are set as shown in Figure 4 based on a similar approach.

[0061] If the process transitions to step S13, the selection unit 113 sets the upper limit of the privacy level of the selected setting item to be equal to or greater than a predetermined value. Here, for example, the privacy level may be expressed in three stages: high, medium, and low, or it may be expressed in more stages. The selection unit 113 may refer to information regarding the privacy level of the setting item stored in the storage unit 120. Alternatively, the selection unit 113 may communicate with the database 300 and refer to information regarding the privacy level of the setting item stored in the storage unit 320 of the database 300. As a result, if the reliability of the method used to recognize the user is higher than a predetermined value, the selection unit 113 will be able to select setting items with a certain level of privacy as setting items to be applied to the in-vehicle equipment, etc. In other words, the higher the reliability of the method used to recognize the user, the more the selection unit 113 will be able to select setting items that have a greater impact on the user's privacy as setting items to be applied to the in-vehicle equipment, etc.

[0062] Figure 5 is a table showing the level of privacy of the setting items according to the first embodiment. As shown in Figure 5, for example, items related to personal information are designated as setting items with high privacy. For example, the username (e.g., the person's name, etc.) and icon image (e.g., the person's face image, etc.) are designated as setting items with high privacy. In addition, locations stored in the memory of in-vehicle equipment that provides a car navigation system, etc. (e.g., the user's favorite locations, the user's home, etc.) and the history of locations registered as the user's destination are also designated as setting items with high privacy. Furthermore, items related to privacy such as behavioral history or preferences are designated as setting items with moderate privacy. For example, information regarding the setting of detour routes in a car navigation system, or information regarding the setting of surrounding facilities guided at the driving location, are designated as setting items with moderate privacy. The remaining items are designated as setting items with low privacy. As an example, this includes language settings for the user interface (UI) or sound settings (volume or sound type, etc.) in an in-vehicle terminal including an authentication device 100, and VICS (registered trademark) in a car navigation system. Information and Communication System) Interrupt Settings such as [specific settings] are designated as settings items with low privacy concerns.

[0063] If the process proceeds to step S14, the selection unit 113 sets the upper limit of the level of privacy of the selected setting item to a predetermined value or less. As a result, the selection unit 113 is unable to select setting items with a level of privacy above a certain level as setting items to be applied to in-vehicle equipment, etc.

[0064] Next, in step S15, the selection unit 113 selects a setting item according to the privacy limit set in step S13 or step S14. In other words, the selection unit 113 selects a setting item according to the magnitude of the impact that the setting item has on the user's privacy.

[0065] Next, in step S16, the application unit 114 applies the setting item selected by the selection unit 113 in step S15 to the in-vehicle equipment, etc. (for example, the in-vehicle terminal 13). With respect to the setting item selected by the selection unit 113, the application unit 114 applies the content of the setting, which is determined in accordance with the user identified by the recognition unit 111 for that setting item, to the vehicle's equipment or in-vehicle equipment, etc.

[0066] As a result, in the first embodiment, the authentication device 100 can select setting items with higher privacy as settings items to be applied to the in-vehicle equipment, depending on the reliability of the user recognition method. In other words, if the reliability of the user recognition method is low, only setting items with low privacy can be selected, and if the reliability of the user recognition method is high, in addition to setting items with low privacy, setting items with high privacy can also be selected.

[0067] Therefore, the authentication device 100 is more likely to be able to appropriately apply settings for in-vehicle equipment, etc., which are individually configured for each user, while taking privacy into consideration. Accordingly, when the reliability of the user's recognition means is low, the authentication device 100 does not uniformly prohibit the selection of settings that are less private as well as settings that are more private, but rather allows the user to select only settings that are less private. In other words, the authentication device 100 can flexibly select the settings that will be reflected in the in-vehicle equipment, etc.

[0068] (Second embodiment) <Selection of settings items with safety in mind> In the first embodiment, the authentication device 100 selected settings that have a higher degree of privacy as settings to be applied to in-vehicle equipment, etc., the higher the reliability of the user recognition method. However, if the reliability of the user recognition method is not high, not only settings that have a high degree of privacy, but also settings that have a significant impact on vehicle safety may not be suitable as settings to be applied to in-vehicle equipment, etc. For example, if a seat position or mirror position that is not suitable for the driver is set, the driving safety of the vehicle may decrease. Therefore, in the second embodiment, the authentication device 100 selects settings that have a greater impact on the safety of the vehicle 10 as settings to be applied to in-vehicle equipment, etc., the higher the reliability of the user recognition method.

[0069] Similar to step S12 as described in Figure 3, the determination unit 112 determines whether the reliability of the method used by the recognition unit 111 to recognize the user is above a predetermined value. The reliability is determined based on, for example, the reliability of the recognition method shown in Figure 4. If the determination unit 112 determines that the reliability of the method used by the recognition unit 111 to recognize the user is above a predetermined value, the selection unit 113 sets the upper limit of the magnitude of the impact of the selected setting item on the safety of the vehicle 10 to above a predetermined value. Here, for example, the magnitude of the impact on the safety of the vehicle 10 may be expressed in three stages: large, medium, and small, or it may be expressed in more than one stage. The selection unit 113 may refer to information about the magnitude of the impact of the setting item on the safety of the vehicle 10 stored in the storage unit 120. The selection unit 113 also communicates with the database 300 and accesses the database 3 The system may also refer to information regarding the magnitude of the impact of the setting items on the safety of the vehicle 10, which is stored in the memory unit 320 of 00. This allows the selection unit 113 to select setting items that have a significant impact on the safety of the vehicle 10 to a certain extent as setting items to be applied to in-vehicle equipment, etc. In other words, the more reliable the user's recognition method is, the more the selection unit 113 will be able to select setting items that have a greater impact on the safety of the vehicle 10 as setting items to be applied to in-vehicle equipment, etc.

[0070] Figure 6 is a table showing the magnitude of the impact of setting items according to the second embodiment on vehicle safety. As shown in Figure 6, for example, items that are likely to affect driving operations and judgments are defined as setting items that have a significant impact on the safety of vehicle 10. For example, information indicating the position of driving equipment such as the position of the driver's seat or the steering wheel in vehicle 10 is defined as a setting item that has a significant impact on the safety of vehicle 10. Also, driving assistance functions, including turning on or off the function that warns of drifting out of the driving lane, or turning on or off the collision avoidance function, are defined as setting items that have a significant impact on the safety of vehicle 10. In contrast, items related to driving guidance are defined as setting items that have a moderate impact on the safety of vehicle 10. For example, settings related to guidance items in a car navigation system, such as map display settings, or turning on or off stop line guidance or railroad crossing guidance, are defined as setting items that have a moderate impact on the safety of vehicle 10. The other items are defined as setting items that have a small impact on the safety of vehicle 10. For example, settings such as the temperature and airflow of the air conditioner, as well as settings related to the charging of the vehicle 10, are designated as settings that have little impact on the safety of the vehicle 10.

[0071] If the determination unit 112 determines that the reliability of the method used by the recognition unit 111 to recognize the user is below a predetermined value, the selection unit 113 sets the upper limit of the magnitude of the impact of the selected setting item on the safety of the vehicle 10 to below a predetermined value. As a result, the selection unit 113 is prevented from selecting setting items that have a significant impact on the safety of the vehicle 10 above a certain level as setting items to be applied to in-vehicle equipment, etc.

[0072] Next, the selection unit 113 selects a setting item according to the upper limit of the magnitude of its impact on the safety of the vehicle 10. In other words, the selection unit 113 selects a setting item according to the magnitude of its impact on the safety of the user's vehicle 10.

[0073] Next, the application unit 114 applies the selected setting item to the in-vehicle equipment, etc. With respect to the setting item selected by the selection unit 113, the application unit 114 applies the content of the setting, which is determined in accordance with the user identified by the recognition unit 111 for that setting item, to the vehicle's equipment or in-vehicle equipment, etc.

[0074] As a result, in the second embodiment, the authentication device 100 can select settings that have a greater impact on the safety of the vehicle 10 as settings to be applied to the in-vehicle equipment, depending on the reliability of the user recognition method. Therefore, the authentication device 100 is more likely to be able to appropriately apply settings for in-vehicle equipment, etc., which are set individually for each user, taking into consideration the safety of the vehicle 10.

[0075] (Third embodiment) <Selecting settings that consider both privacy and security> In the first embodiment, the authentication device 100 considered the level of privacy of the setting item as a criterion for selecting the setting item. In the second embodiment, the authentication device 100 considered the magnitude of the impact of the setting item on the safety of the vehicle 10 as a criterion for selecting the setting item. In contrast, in the third embodiment, the authentication device 100 considered the level of privacy of the setting item as a criterion for selecting the setting item. We will take into account both the level of privacy required for the settings and the magnitude of their impact on the safety of vehicle 10.

[0076] Similar to step S12 as described in Figure 3, the determination unit 112 determines whether the reliability of the method used by the recognition unit 111 to recognize the user is above a predetermined value. The reliability is determined based on, for example, the reliability of the recognition method shown in Figure 4. If the determination unit 112 determines that the reliability of the method used by the recognition unit 111 to recognize the user is above a predetermined value, the selection unit 113 sets the upper limit of the evaluation value of the selected setting item to above a predetermined value. Here, the evaluation value is a value obtained by evaluating the setting item considering both the level of privacy of the vehicle 10 and the magnitude of its impact on safety. The evaluation value is highest when the level of privacy is high and when the impact on the safety of the vehicle 10 is large. For example, the magnitude of the evaluation value may be expressed in three stages: large, medium, and small, or it may be expressed in more stages.

[0077] The selection unit 113 may refer to information regarding the evaluation values ​​of setting items stored in the storage unit 120, or it may communicate with the database 300 and refer to information regarding the evaluation values ​​of setting items stored in the storage unit 320 of the database 300. This allows the selection unit 113 to select setting items that have a certain degree of privacy and setting items that have a significant impact on the safety of the vehicle 10 as setting items to be applied to in-vehicle equipment, etc. In other words, the more reliable the user's recognition method is, the more the selection unit 113 can select setting items that have a higher degree of privacy and setting items that have a greater impact on the safety of the vehicle 10 as setting items to be applied to in-vehicle equipment, etc.

[0078] If the determination unit 112 determines that the reliability of the method used by the recognition unit 111 to recognize the user is below a predetermined value, the selection unit 113 sets the upper limit of the evaluation value of the selected setting item to below a predetermined value. As a result, the selection unit 113 is prevented from selecting setting items that have a high degree of privacy or a significant impact on the safety of the vehicle 10 as setting items to be applied to in-vehicle equipment, etc.

[0079] Next, the selection unit 113 selects a setting item according to the upper limit of the evaluation value set as described above. In other words, the selection unit 113 selects a setting item according to the level of privacy of the setting item and the magnitude of the impact that the setting item has on the safety of the user's vehicle 10.

[0080] Next, the application unit 114 applies the selected setting item to the in-vehicle equipment, etc. With respect to the setting item selected by the selection unit 113, the application unit 114 applies the content of the setting, which is determined in accordance with the user identified by the recognition unit 111 for that setting item, to the vehicle's equipment or in-vehicle equipment, etc.

[0081] As a result, in the third embodiment, the authentication device 100 can select settings that are highly private and settings that have a significant impact on the safety of the vehicle 10 as settings to be applied to the in-vehicle equipment, depending on the reliability of the user recognition method. Therefore, the authentication device 100 is more likely to be able to appropriately apply settings for in-vehicle equipment, etc., which are set individually for each user, taking into consideration both privacy and safety.

[0082] (Other variations) The embodiments described above are merely examples, and this disclosure may be modified as appropriate without departing from its essence.

[0083] The level of privacy of the setting items, the magnitude of their impact on the safety of the vehicle 10, and the evaluation values ​​that take these into consideration do not have to be fixed values. If these values ​​are changed according to the situation, the user will communicate with an external server device via the communication unit 130 of the authentication device 100. The authentication device 100 may communicate with a database (typically 300) and download information about the changed values. Alternatively, the user may install information about the changed values ​​from external media (such as a USB memory stick) onto the authentication device 100.

[0084] Furthermore, in the above embodiment, the determination of the reliability of the user recognition method is performed when the user is recognized for the first time by the authentication device 100. However, the determination of the reliability of the user recognition method is not limited to when the user is recognized for the first time. The user may be recognized again periodically at predetermined intervals while the vehicle 10 is in motion, and if the user is recognized by a different method than the previous time, the determination of the reliability of the user recognition method may also be updated.

[0085] Alternatively, if a user attempts to apply a specific setting to an in-vehicle device, user authentication may be performed again, and the setting that can be applied to the in-vehicle device may be re-selected based on the reliability of the user's recognition method. Here, specific setting items are those with high privacy considerations, those with a significant impact on the safety of the vehicle 10, or setting items with a high evaluation value considering these factors.

[0086] The present disclosure can also be realized by supplying a computer program implementing the functions described in the embodiments above to a computer, and having one or more processors in the computer read and execute the program. Such a computer program may be provided to the computer by a non-temporary computer-readable storage medium that can be connected to the computer's system bus, or it may be provided to the computer via a network. Non-temporary computer-readable storage mediums include, for example, any type of disk such as magnetic disks (floppy disks, hard disk drives (HDDs), etc.), optical disks (CD-ROMs, DVDs, Blu-ray discs, etc.), read-only memory (ROM), random access memory (RAM), EPROM, EEPROM, magnetic cards, flash memory, optical cards, and any type of medium suitable for storing electronic instructions. [Explanation of Symbols]

[0087] 10.. Vehicles 11. Drive unit 12···ECU 13. In-vehicle terminals 100... Authentication device 110, 310... Control Unit 111...Recognition section 112...Judgment section 113...Selection section 114...Applicable part 120, 320...Storage section 130, 330... Communications Department 300... Database

Claims

1. An information processing device that applies user settings to in-vehicle equipment, The user is recognized using one of several different types of recognition methods, The control unit performs the following actions: selecting a setting item to apply to the in-vehicle device from among a plurality of setting items indicating the settings for the user, according to the type of recognition method used to recognize the user. Information processing device.

2. Each of the multiple different recognition methods is associated with a confidence level when the recognition method is used to recognize the user. The control unit, Based on the reliability of the recognition method, select the setting item to be applied to the in-vehicle device from among the plurality of setting items. The information processing apparatus according to claim 1.

3. The control unit The higher the reliability of the recognition method, the more likely it is that the setting item among the multiple setting items that has a greater impact on the user's privacy will be applied to the in-vehicle device. The information processing apparatus according to claim 2.

4. The control unit The higher the reliability of the recognition method, the more likely it is that the setting item among the multiple setting items that has a greater impact on the safety of the vehicle on which the in-vehicle device is installed will be applied to the in-vehicle device. The information processing apparatus according to claim 2.

5. The aforementioned recognition method includes recognition by electronic key, recognition by digital key, and Bluetooth (registered trademark). (Standard) Recognition by a device, biometric recognition, and recognition based on input operations by the user. The information processing apparatus according to any one of claims 1 to 4.