Information processing device
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- TOYOTA JIDOSHA KK
- Filing Date
- 2023-10-23
- Publication Date
- 2026-08-04
AI Technical Summary
【0008】 本開示によれば、車両に対する不正行為の発生を検知することができる。
Smart Images

Figure 0007899797000001 
Figure 0007899797000002 
Figure 0007899797000003
Abstract
Description
Technical Field
[0001] This disclosure relates to vehicles.
Background Art
[0002] A number of technologies for preventing vehicle theft have been devised. In this regard, for example, Patent Document 1 discloses a system that warns a driver when the position where the vehicle is parked is within an area where vehicle theft frequently occurs.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] This disclosure aims to detect the occurrence of improper acts against a vehicle.
Means for Solving the Problems
[0005] One aspect of an embodiment of this disclosure is receiving a heartbeat signal transmitted from a first vehicle at a predetermined period, and determining that there is a suspicion that an improper act has been performed on the first vehicle when the heartbeat signal is not received from the first vehicle at the timing according to the predetermined period, and an information processing device having a control unit that executes the above.
[0006] One aspect of an embodiment of this disclosure is an in-vehicle device mounted on a first vehicle and capable of communicating with a predetermined information processing device, the in-vehicle device having a control unit that transmits a heartbeat signal to the information processing device at a predetermined period via a predetermined communication module, and executes a predetermined authentication process when the transmission of the heartbeat signal fails.
[0007] Other embodiments include a method performed by the above-mentioned device, a program for causing a computer to perform the method, or a computer-readable storage medium that non-temporarily stores the program. [Effects of the Invention]
[0008] According to this disclosure, it is possible to detect the occurrence of fraudulent activity against a vehicle. [Brief explanation of the drawing]
[0009] [Figure 1] A schematic diagram of the vehicle system according to the first embodiment. [Figure 2] A diagram showing the configuration of the devices included in the system. [Figure 3] A sequence diagram of the process for sending vehicle messages to the management server. [Figure 4] A flowchart of the processes performed by the management server in the first embodiment. [Figure 5] A flowchart of the processes performed by the management server in the second embodiment. [Figure 6] A flowchart of the processes performed by the in-vehicle device in the third embodiment. [Modes for carrying out the invention]
[0010] In recent years, numerous anti-theft technologies have been proposed in the automotive sector. For example, equipping vehicles with communication modules and GPS modules to periodically upload location information. Technologies that allow for the tracking of specific vehicles from the outside are known.
[0011] However, even with such methods, it may not always be possible to detect that a theft has occurred. In particular, if the vehicle network is accessed from the outside and the vehicle system is started in a way that is mistaken for a legitimate procedure, the security alarm may not activate, and the theft may not be recognized until later. The information processing device described in this disclosure solves the aforementioned problems.
[0012] An information processing device according to one aspect of the present disclosure includes a control unit that performs the following actions: receiving a heartbeat signal transmitted from a first vehicle according to a predetermined period; and determining that there is suspicion of fraudulent activity against the first vehicle if the heartbeat signal is not received from the first vehicle at a timing according to the predetermined period.
[0013] A heartbeat signal is a signal periodically transmitted from a first vehicle. The heartbeat signal may contain any information as long as it indicates that the first vehicle is functioning properly. For example, the heartbeat signal may contain a vehicle identifier, or information about the surrounding conditions of the first vehicle, such as location information. The transmission of the heartbeat signal may be triggered by polling, or it may be initiated spontaneously by the vehicle.
[0014] The control unit determines that there is suspicion of fraudulent activity against the first vehicle if the heartbeat signal is not received at a timing according to a predetermined period. This is because it can be presumed that an action has been taken that renders the communication module unusable, such as disconnecting the communication module.
[0015] The heartbeat signal may also include location information of the first vehicle, and the control unit may transmit the location information contained in the last received heartbeat signal to a predetermined device if there is suspicion that fraudulent activity has occurred with respect to the first vehicle. This system makes it possible to notify relevant parties of the location of the first vehicle, along with the suspicion of fraudulent activity.
[0016] Furthermore, the control unit may be capable of receiving a second heartbeat signal from one or more second vehicles located near the first vehicle. In addition, when the heartbeat signal transmitted from the first vehicle is not received at the timing according to a predetermined period and the second heartbeat signal is received from one or more second vehicles, it may be determined that there is a suspicion that an illegal act has been committed against the first vehicle.
[0017] If the determination is made only based on whether the heartbeat signal is received or not, it cannot be determined whether an abnormality has occurred in the vehicle or the vehicle is simply in an environment where communication is not possible (such as outside the communication service area). Therefore, the determination may be made based on whether a heartbeat signal is normally received from a vehicle (second vehicle) located near the first vehicle. For example, this is because when a heartbeat signal is normally received from a second vehicle located near the first vehicle but the heartbeat signal is not received from the first vehicle, it can be presumed that it is not due to the communication environment.
[0018] An in-vehicle device according to one aspect of the present disclosure is an in-vehicle device mounted on a first vehicle and capable of communicating with a predetermined information processing device. Specifically, it has a control unit that transmits a heartbeat signal to the information processing device according to a predetermined period via a predetermined communication module, and executes a predetermined authentication process when the transmission of the heartbeat signal fails.
[0019] The in-vehicle device can be, for example, a device capable of communicating with the above-described information processing device. The in-vehicle device transmits a heartbeat signal via a predetermined communication module. On the other hand, when the transmission of the heartbeat signal fails, a predetermined authentication process is executed. When the transmission of the heartbeat signal fails, it can be presumed that some illegal act (such as theft) has been committed against the first vehicle. Therefore, by the control unit executing a predetermined authentication process in such a case, security can be ensured. The predetermined authentication process can be, for example, a process of additionally requiring driver authentication. If the predetermined authentication process is not performed, the first vehicle may be made unable to start.
[0020] The following describes specific embodiments of this disclosure with reference to the drawings. Unless otherwise specified, the hardware configurations, module configurations, functional configurations, etc., described in each embodiment are not intended to limit the technical scope of the disclosure to those described therein.
[0021] (First embodiment) [System Overview] An overview of the vehicle system according to the first embodiment will be described. The vehicle system according to this embodiment consists of a vehicle 1, a management server 2, and an MQTT server 3. Vehicle 1 is a connected vehicle that can access a wireless communication network. Vehicle 1 can communicate with the management server 2 and the MQTT server 3 via a wireless communication network (e.g., a mobile communication network).
[0022] Vehicle 1 is equipped with an on-board device 10 and a DCM 20. The in-vehicle device 10 is a computer that provides predetermined functions to the occupants of the vehicle 1. The in-vehicle device 10 may be, for example, a car navigation system or a head unit. In this embodiment, the in-vehicle device 10 has the function of periodically generating information about the vehicle 1 and transmitting it as a message to an external device. In the following description, the message transmitted from the in-vehicle device 10, which contains information about the vehicle 1, will also be referred to as a "vehicle message". A vehicle message is an example of a "heartbeat signal".
[0023] DCM20 is a data communication module for connecting vehicle components (e.g., in-vehicle devices 10 and other ECUs) to a network. In this embodiment, the in-vehicle device 10 can provide various services by communicating with external devices via the DCM 20. Examples of such services include navigation services, remote control services (e.g., remote air conditioning), in-vehicle Wi-Fi® services, emergency call services, and security services.
[0024] The management server 2 is a management device configured to communicate with multiple vehicles 1 via a network. The management server 2 receives vehicle messages from each of the multiple vehicles 1 under its management at predetermined intervals, and if no vehicle messages are received from any vehicle 1 for a certain period of time or longer, it presumes that an unauthorized act has been committed against that vehicle 1. In this embodiment, the unauthorized act is theft, but the management server 2 may detect other types of unauthorized acts.
[0025] In this embodiment, the management server 2 and the in-vehicle device 10 send and receive messages using a publisher / subscriber communication model. In this embodiment, the in-vehicle device 10 is the publisher, and the management server 2 is the subscriber. This will be a (Subscriber). In this embodiment, it is assumed that the information generated by the in-vehicle device 10 is transmitted asynchronously to the management server 2. In Figure 1, only one vehicle 1, in-vehicle device 10, DCM 20, management server 2, and MQTT server 3 are shown, but the vehicle system in this embodiment may include multiple of these elements.
[0026] Furthermore, in this embodiment, the MQTT protocol is adopted as the protocol for publishing-subscription type communication. In the MQTT protocol, the subscriber, who is the recipient of the message, subscribes to the MQTT broker to receive the message sent by the sender. The sender then delivers any message to the MQTT broker. (Publish). The MQTT broker has requested delivery of the message. Identify subscribers and send messages to them. In this embodiment, the subscriber corresponds to the management server 2, and the distributor corresponds to the in-vehicle device 10. The MQTT broker corresponds to the MQTT server 3.
[0027] Management Server 2 pre-registers with MQTT Server 3 which vehicles' vehicle messages it will subscribe to. The registered vehicles are one or more vehicles managed by Management Server 2. Vehicle 1 (in-vehicle device 10) sends the generated vehicle message to MQTT Server 3. When MQTT Server 3 receives the vehicle message from In-vehicle Device 10, it identifies the destination device (i.e., Management Server 2 which has subscribed to the message) and forwards the vehicle message to Management Server 2. This allows the management server 2 to receive vehicle messages from one or more vehicles 1 that it manages.
[0028] If the management server 2 loses the ability to receive vehicle messages from one or more vehicles under its management, it determines that there is suspicion that the vehicle has been stolen and executes a predetermined process.
[0029] [Device configuration] Next, the configuration of each device that makes up the system will be described. Figure 2 is a schematic diagram showing an example of the configuration of each device in the vehicle system according to this embodiment. The vehicle system according to this embodiment comprises a vehicle 1, a management server 2, and an MQTT server 3.
[0030] First, let's describe the components of Vehicle 1. Vehicle 1 consists of an on-board device 10 and a DCM 20. The in-vehicle device 10 can be configured as a computer having a processor (CPU, GPU, etc.), main memory (RAM, ROM, etc.), and auxiliary storage (EPROM, hard disk drive, removable media, etc.). The auxiliary storage contains an operating system (OS), various programs, various tables, etc., and by executing the programs stored therein, various functions (software modules) that match a predetermined purpose, as described later, can be realized. However, some or all of the functions may be realized as hardware modules by hardware circuits such as ASICs and FPGAs.
[0031] The in-vehicle device 10 is comprised of a control unit 11, a storage unit 12, a communication unit 13, and a location information acquisition unit 14.
[0032] The control unit 11 is a computing unit that realizes various functions of the in-vehicle device 10 by executing a predetermined program. The control unit 11 can be implemented by a hardware processor such as a CPU. The control unit 11 may also be configured to include RAM, ROM (Read Only Memory), cache memory, etc.
[0033] The control unit 11 is composed of two software modules: a message transmission unit 111 and a function provision unit 112. Each software module may be implemented by the control unit 11 (CPU, etc.) executing a program stored in the storage unit 12, which will be described later. stomach.
[0034] The message transmission unit 111 periodically generates vehicle messages and sends them to the MQTT server 3. In this embodiment, the vehicle message includes the identifier of vehicle 1, the date and time the vehicle message was generated, and the location information of vehicle 1. The vehicle message is sent to the management server 2 via the MQTT server 3.
[0035] The function-providing unit 112 performs various functions provided by the in-vehicle device 100. Examples of functions provided by the in-vehicle device 100 include the following: • Terminal link function This function connects to devices (such as smartphones) carried by the vehicle's occupants, enabling playback of music and videos, screen mirroring, and other similar functions. • Audio function This function allows you to play music stored on a storage device. • TV / radio function This function allows you to receive radio broadcasts and digital television broadcasts. • Navigation function This function provides route navigation based on map data stored in a memory device. These functions can be provided, for example, through input / output devices (such as touch panels).
[0036] The memory unit 12 is a means for storing information and is composed of storage media such as RAM, magnetic disks, and flash memory. The memory unit 12 stores programs executed by the control unit 11, data used by those programs, and so on.
[0037] The communication unit 13 is a communication interface with the in-vehicle network provided in vehicle 1. The communication unit 13 communicates via a CAN (Controller Area Network) network. The in-vehicle device 10 can communicate with the DCM 20 (and other ECUs, etc.) via the in-vehicle network.
[0038] The location information acquisition unit 14 acquires the location information of the vehicle 1. The location information acquisition unit 14 includes a GPS antenna and a positioning module for determining the location information. The GPS antenna is an antenna that receives positioning signals transmitted from positioning satellites (also called GNSS satellites). The positioning module is a module that calculates location information based on the signals received by the GPS antenna.
[0039] The DCM20 is a device that performs wireless communication with a predetermined network in order to connect components of the vehicle 1 (e.g., an in-vehicle device 10) with an external device (e.g., an MQTT server 3). In this embodiment, the DCM20 is configured to be connectable to a predetermined cellular communication network. The DCM20 is configured to have an eUICC (Embedded Universal Integrated Circuit Card) for identifying the user. The eUICC may be a physical SIM card or an eSIM, etc.
[0040] Next, we will describe the management server 2. The management server 2 can be configured as a computer having a processor (CPU, GPU, etc.), main memory (RAM, ROM, etc.), and auxiliary storage (EPROM, hard disk drive, removable media, etc.), similar to the in-vehicle device 10.
[0041] The management server 2 is comprised of a control unit 21, a storage unit 22, and a communication unit 23.
[0042] The control unit 21 is a computing unit that implements various functions of the management server 2 by executing a predetermined program. The control unit 21 can be implemented by a hardware processor such as a CPU. The control unit 21 may also be configured to include RAM, ROM (Read Only Memory), cache memory, etc.
[0043] The control unit 21 is configured with two software modules: a message receiving unit 211 and a determination unit 212. Each software module may be implemented by the control unit 21 (CPU, etc.) executing a program stored in the storage unit 22, which will be described later.
[0044] The message receiving unit 211 receives vehicle messages transmitted from the in-vehicle device 10 via the MQTT server 3 and stores them in the storage unit 22, which will be described later. The message receiving unit 211 may also pre-register (subscribe) with the MQTT server 3 which vehicles' vehicle messages it will receive (subscribe) from.
[0045] The determination unit 212 determines, based on the vehicle messages stored in the memory unit 22, that an illegal act (theft) has been committed against one or more vehicles under its management.
[0046] The memory unit 22 is a means for storing information and is composed of storage media such as RAM, magnetic disks, and flash memory. The memory unit 22 stores programs executed by the control unit 21, data used by those programs, and so on.
[0047] The communication unit 23 is a communication interface for connecting the management server 2 to the network. The communication unit 23 is configured to communicate with the network via, for example, Ethernet (registered trademark), wireless LAN, or mobile communication services.
[0048] Next, we will explain MQTT server 3. The MQTT server 3 can be configured as a computer having a processor (CPU, GPU, etc.), main memory (RAM, ROM, etc.), and auxiliary memory (EPROM, hard disk drive, removable media, etc.), similar to the in-vehicle device 10.
[0049] The MQTT server 3 is comprised of a control unit 31, a storage unit 32, and a communication unit 33.
[0050] The control unit 31 is a computing unit that implements various functions of the MQTT server 3 by executing a predetermined program. The control unit 31 can be implemented by a hardware processor such as a CPU. The control unit 31 may also be configured to include RAM, ROM (Read Only Memory), cache memory, etc.
[0051] The control unit 31 is configured to include a message relay unit 311 as a software module. This software module may be implemented by the control unit 31 (CPU, etc.) executing a program stored in the storage unit 32, which will be described later.
[0052] The message relay unit 311 relays vehicle messages to designated subscribers based on pre-registered subscription information. First, the message relay unit 311 receives subscription information from the management server 2. The subscription information includes the identifier of the vehicle 1 that wishes to subscribe to vehicle messages. If there are multiple messages sent from vehicle 1, the subscription information may also include an identifier that identifies the message to be subscribed to. The subscription information is stored in the storage unit 32.
[0053] Furthermore, the message relay unit 311 receives vehicle messages from vehicle 1 (in-vehicle device 10) and relays the vehicle messages to designated subscribers based on the stored subscription information. If there are multiple management servers 2 and one of them receives a vehicle message that it wishes to subscribe to, the message relay unit 311 sends the vehicle message to the corresponding management server 2.
[0054] The memory unit 32 is a means for storing information and is composed of storage media such as RAM, magnetic disks, and flash memory. The memory unit 32 stores programs executed by the control unit 31, data used by those programs, and so on.
[0055] The communication unit 33 is a communication interface for connecting the MQTT server 3 to a network. The communication unit 33 is configured to communicate with the network via, for example, Ethernet (registered trademark), wireless LAN, or mobile communication services.
[0056] Note that the configuration shown in Figure 2 is just one example, and all or part of the illustrated functions may be performed using specially designed circuits. Furthermore, program storage and execution may be performed using combinations of main memory and auxiliary memory other than those shown.
[0057] [Vehicle message sending and receiving process] Next, we will explain how the in-vehicle device 10 sends a vehicle message and how the management server 2 receives it. Figure 3 is a sequence diagram of the process of sending a vehicle message from the in-vehicle device 10 to the management server 2.
[0058] First, the management server 2 registers (Subscribes) vehicle 1, which is the target of the vehicle message subscription, with the MQTT server 3 (message relay unit 311) (step S11). The target vehicle 1 is, for example, determined by its vehicle identifier (Vehicle Identification Number, etc.) You can specify it this way. As a result, subscription information is generated and stored by MQTT server 3. Subscription information is information that links the issuer of a vehicle message with the subscriber.
[0059] In parallel with this, the in-vehicle device 10 generates a vehicle message at a predetermined timing and sends (publishes) it to the MQTT server 3 (step S12). This may be done at a periodic interval (for example, every 5 minutes). Vehicle messages are generated and transmitted even when the vehicle 1's driving system is not running.
[0060] In this step, the in-vehicle device 10 (message transmission unit 111) generates a vehicle message that includes the identifier of vehicle 1, the date and time the message was generated, and the location information of vehicle 1. The location information of vehicle 1 can be obtained, for example, via the location information acquisition unit 14. The generated vehicle message is sent to the MQTT server 3 via the DCM 20.
[0061] In step S13, the MQTT server 3, upon receiving the vehicle message, identifies the management server 2 that has registered a subscription to the vehicle message based on the stored subscription information. The vehicle message is then sent to the management server 2 that has registered the subscription.
[0062] In step S14, the management server 2 (message receiving unit 211) that received the vehicle message stores the vehicle message in the storage unit 22. By executing the process shown in Figure 3, vehicle messages will be periodically sent from vehicle 1 (in-vehicle device 10) to management server 2.
[0063] [Decision process executed by management server 2] Next, we will describe in detail the processes that the management server 2 performs based on the received vehicle messages. Figure 4 is a flowchart of the processes performed by the management server 2. This process is periodically executed by the control unit 21 (determination unit 212) after the management server 2 begins receiving vehicle messages from the in-vehicle device 10.
[0064] The illustrated process is executed for each of the multiple vehicles 1 under the management of the management server 2. First, in step S21, the most recent reception date and time of the vehicle message received from the target vehicle is obtained. Next, in step S22, it is determined whether the elapsed time since the last vehicle message was received is greater than or equal to a predetermined time. For example, if vehicle messages are sent every 5 minutes, this step may result in a positive determination if no vehicle message has been received for 30 minutes or more, or for 1 hour or more. The predetermined time may be determined as appropriate. If the determination in this step is positive, the process moves to step S23. If the determination is negative, the process moves to the next target vehicle.
[0065] In step S23, it is determined that the vehicle in question is suspected of being stolen. In this step, for example, notifications may be sent to a designated device. The management server 2 may, for example, send a message to a terminal associated with the vehicle in question (for example, a terminal owned by the owner of the vehicle in question) notifying that it has lost access to vehicle messages from the vehicle in question, or a message notifying that the vehicle in question is suspected of being stolen.
[0066] Furthermore, the message may include information related to the last vehicle message received from the target vehicle. For example, if the vehicle message includes the location information of the target vehicle, the message may also provide the date and time the vehicle message was generated and a map on which that location information is mapped.
[0067] As described above, in the vehicle system according to this embodiment, an on-board device installed in the vehicle transmits vehicle messages (heartbeat signals) according to a predetermined cycle. The management server receives vehicle messages for each vehicle, and if there is a vehicle for which the vehicle message has not been received at the predetermined time, it determines that the vehicle is suspected of being stolen and sends a notification. With this configuration, even if a communication module is maliciously removed from the vehicle, it becomes possible to detect this and send a notification.
[0068] In this embodiment, vehicle messages were transmitted wirelessly using the MQTT protocol. However, the transmission protocol and communication medium are not limited to any specific one, as long as the management server 2 can receive vehicle messages from multiple vehicles 1 under its management. Also, in this embodiment, the in-vehicle device 10 triggered the transmission of vehicle messages, but the transmission of vehicle messages may also be triggered by the management server 2 (for example, by polling).
[0069] (Second Embodiment) In the first embodiment, the management server 2 estimated that the target vehicle was suspected of being stolen if a vehicle message was not received at a predetermined interval. On the other hand, there may be cases where vehicle messages cannot be sent due to the wireless communication environment. For example, this could happen if vehicle 1 moves outside the service area of cellular communication.
[0070] In such cases, the management server 2 cannot determine whether the communication module of the target vehicle has been removed or whether the target vehicle has simply moved out of the communication service area. In the second embodiment, the management server 2 makes a determination in conjunction with vehicle messages received from surrounding vehicles to address such cases. In this embodiment, "surrounding vehicles" refer to vehicles located near the target vehicle and traveling along the same or a similar route (a route that partially overlaps) as the target vehicle. Vehicles traveling along the same or similar routes can be identified, for example, based on location information included in vehicle messages. Vehicles traveling on the same road in the same direction near the target vehicle can be considered surrounding vehicles.
[0071] Figure 5 is a flowchart of the processes performed by the management server 2 in the second embodiment. The steps shown by the dotted lines are the same as in the first embodiment, so a detailed explanation is omitted.
[0072] In step S22A, it is determined whether or not vehicle messages are being received from surrounding vehicles. In this step, for example, surrounding vehicles traveling along the same or similar route as the target vehicle are extracted, and it is determined whether or not vehicle messages are being continuously received from surrounding vehicles near the point where the reception of vehicle messages from the target vehicle was interrupted. If the reception of vehicle messages from surrounding vehicles is not interrupted (step S22B-No), the process proceeds to step S23. If the reception of vehicle messages from surrounding vehicles is also interrupted (step S22B-Yes), it is determined that the cause lies in the communication environment, and the process terminates.
[0073] According to the second embodiment, it is possible to infer that the transmission of a vehicle message has failed due to the communication environment. In other words, it is possible to prevent notifications from being sent even when no theft has occurred.
[0074] (Third embodiment) In the first and second embodiments, the management server 2 detects that there is a suspicion of theft regarding the target vehicle. In contrast, the third embodiment is an embodiment in which an on-board device 10 installed in the vehicle 1 detects that there is a suspicion of theft regarding its own vehicle and takes predetermined measures.
[0075] As explained with reference to the diagram, the management server 2 can detect when the DCM 20 is removed from vehicle 1. On the other hand, if the DCM 20 is removed from vehicle 1, communication between the in-vehicle device 10 and the DCM 20 is interrupted. If the in-vehicle device 10 can detect this, measures such as applying a security lock can be taken on the vehicle system side.
[0076] In the third embodiment, after the in-vehicle device 10 generates a vehicle message in step S12, the in-vehicle device 10 determines whether or not communication with the DCM 20 was successful. Figure 6 is a flowchart of the processes that the in-vehicle device 10 executes after the execution of step S12. As mentioned above, the vehicle message generated by the in-vehicle device 10 (message transmission unit 111) is transmitted via the DCM 20.
[0077] In step S12A, it is determined that a predetermined number of communication failures have occurred. Here, "communication" refers to communication between the in-vehicle device 10 and the DCM 20. In this step, it is determined that the in-vehicle device 10 is unable to communicate with the DCM 20 via the in-vehicle network. If a predetermined number of communication failures have occurred, the process proceeds to step S12B. If communication with the DCM 20 is successful, the process ends.
[0078] In step S12B, the in-vehicle device 10 requests a predetermined authentication process. The predetermined authentication process is a process that requests the vehicle occupant to prove that they are a legitimate user. Examples of such processes include a process that requests the input of pre-set authentication information (such as a password), a process that requests authentication using biometric information, and a process that requests the presentation of a key fob. Authentication information and biometric information may be obtained using sensors or interfaces connected to the in-vehicle device 10. The predetermined authentication process can be performed at any time. For example, the in-vehicle device 10 may request the authentication process the next time the vehicle system is started, and if authentication is correct If the process does not complete properly, a signal may be sent to the ECU to lock the vehicle system.
[0079] According to the third embodiment, the vehicle can also detect that the DCM20 has been removed, making it possible to prevent the vehicle from moving.
[0080] (modified version) The embodiments described above are merely examples, and this disclosure may be modified as appropriate without departing from its essence. For example, the processes and means described in this disclosure can be freely combined and implemented, as long as no technical inconsistencies arise.
[0081] Furthermore, while theft was used as an example of an illegal act committed against a vehicle in this embodiment, other illegal acts (such as illegal modifications) can also be detected, as long as they involve the removal of a communication module. Furthermore, while the embodiment shows an example where the vehicle message includes the vehicle's location information, other information related to the vehicle's surroundings may also be included in the vehicle message. For example, an image captured by an onboard camera may be included in the vehicle message.
[0082] Furthermore, a process described as being performed by a single device may be divided and executed by multiple devices. Conversely, a process described as being performed by different devices may be executed by a single device. In a computer system, the hardware configuration (server configuration) by which each function is implemented can be flexibly changed.
[0083] The present disclosure can also be realized by supplying a computer program implementing the functions described in the embodiments above to a computer, and having one or more processors in the computer read and execute the program. Such a computer program may be provided to the computer by a non-temporary computer-readable storage medium that can be connected to the computer's system bus, or it may be provided to the computer via a network. Non-temporary computer-readable storage mediums include, for example, any type of disk such as magnetic disks (floppy disks, hard disk drives (HDDs), etc.), optical disks (CD-ROMs, DVDs, Blu-ray discs, etc.), read-only memory (ROM), random access memory (RAM), EPROM, EEPROM, magnetic cards, flash memory, optical cards, and any type of medium suitable for storing electronic instructions. [Explanation of Symbols]
[0084] 10...In-vehicle equipment 11. Control Unit 12...Storage section 13. Communications Department 14...Location information acquisition unit 2. Management Server 21... Control Unit 22...Storage section 23. Communications Department 3. MQTT Server 31. Control Unit 32...Storage section 33. Communications Department
Claims
1. Receiving a heartbeat signal transmitted from the first vehicle according to a predetermined period, If the heartbeat signal is not received from the first vehicle at a timing according to the predetermined period, it is determined that there is suspicion that fraudulent activity has occurred against the first vehicle. It has a control unit that performs the following: The control unit is configured to receive a second heartbeat signal from one or more second vehicles located near the first vehicle. If the heartbeat signal transmitted from the first vehicle is not received at the timing according to the predetermined period, and the second heartbeat signal is received from one or more second vehicles, it is determined that there is suspicion that fraudulent activity has occurred with respect to the first vehicle. Information processing device.
2. The heartbeat signal includes the location information of the first vehicle, The control unit, when it suspects that an illegal act has been committed against the first vehicle, transmits the location information included in the last received heartbeat signal to a predetermined device. The information processing apparatus according to claim 1.